Last updated 5.21.21
Thank you for choosing to be part of our community at Kristin Ess Hair (“company”, “we”, “us”, or “our”). We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about our policy, or our practices with regards to your personal information, please contact us at firstname.lastname@example.org.
Table of contents
- WHAT INFORMATION DO WE COLLECT?
- HOW DO WE USE YOUR INFORMATION?
- WILL YOUR INFORMATION BE SHARED WITH ANYONE?
- HOW DO WE HANDLE YOUR SOCIAL LOGINS?
- IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
- WHAT IS OUR STANCE ON THIRD-PARTY WEBSITES?
- HOW LONG DO WE KEEP YOUR INFORMATION?
- HOW DO WE KEEP YOUR INFORMATION SAFE?
- DO WE COLLECT INFORMATION FROM MINORS?
- WHAT ARE YOUR PRIVACY RIGHTS?
- ARE THERE ADDITIONAL RIGHTS AND DISCLOSURES REQUIRED FOR CALIFORNIA RESIDENTS?
- DO WE MAKE UPDATES TO THIS POLICY?
- HOW CAN YOU CONTACT US ABOUT THIS POLICY?
WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect personal information that you provide to us such as name, address, gender, age, location, and contact information.
We collect personal information that you voluntarily provide to us when you are: (I) using our Site(s), (ii) expressing an interest in obtaining information about us or our products and services, (iii) purchasing a product or service and/or participating in activities on the Site(s) (such as entering competitions, contests or giveaways or responding to a survey), or (iv) otherwise contacting or communicating with us, including through our social media pages. The personal information that we collect depends on the context of your interactions with us and the Site(s), the choices you make and the products and features you use.
We may collect the following categories of information. It is possible that the information we collect may fall within more than one category.
- Contact information and personal identifiers, such as your name, address, email address, telephone number, and username or social media handle.
- Demographic information, such as your age, sex, and gender (some of which may be protected by applicable law).
- Physical characteristics, such as your hair type and color.
- Commercial information, such as the products or services you have purchased, returned or considered, and your product preferences.
- Payment information, such as your method of payment and payment card information (including payment card number, expiration date, delivery address and billing address).
- User Content, such as your communications with us and any other content you provide (including photographs, videos, reviews, articles, survey responses and comments).
- Identity verification information, such as loyalty member ID and other authentication information like passwords.
Information automatically collected
In Short: Some information – such as IP address and/or browser and device characteristics – is collected automatically when you visit our websites.
We may automatically collect or may have automatically collected the following categories of information about you when you visit, use or navigate the Site(s) and when you open or click on emails we send you. In some cases, the information we collect may fall within more than one category.
- Device identifiers, such as information about your device like your MAC address, IP address, or other online identifiers.
- Online or network activity information, such as information regarding your interaction with our website and advertisements, information about your browsing and search history on our Site(s) or mobile applications, and log file information which includes, but may not be limited to, your browser type, webpages you visit, and other electronic network activity.
- Geolocation information, such as information that can help identify your physical location like your GPS coordinates or the approximate location of your mobile device.
- Inferences drawn from or created based on any of the information identified above.
Information collected from other Sources
In Short: We may collect limited data from public databases, marketing partners, social media platforms, and other outside sources.
We may obtain information about you from other sources, such as public databases, joint marketing partners, analytics providers, social media platforms (such as Facebook, Instagram and Twitter), as well as from other third parties, [including our affiliates that you have interacted with]. Examples of the information we receive from other sources include: social media profile information (your name, gender, birthday, email, current city, state and country, user identification numbers for your contacts, profile picture URL and any other information that you choose to make public); marketing leads and search results and links, including paid listings (such as sponsored links).
HOW DO WE USE YOUR INFORMATION?
In Short: We process your information for purposes based on legitimate business interests, contractual purposes, compliance with our legal obligations, and/or your consent.
We use the information we collect or receive:
- To provide products and services to you for Business Purposes. We may use your information to fulfill orders, process payments, provide receipts and provide order updates, as well as to maintain your account with us and manage current or past purchases.
- To send you marketing and promotional communications for Business Purposes. We and/or our third party marketing partners may use the personal information you provide us for our marketing purposes, if such use is in accordance with your marketing preferences. You can opt-out of our marketing emails at any time (see the "What Are Your Privacy Rights" section below).
- To send administrative information to you for Business Purposes, Legal Reasons and/or possibly to comply with Contractual Obligations. We may use your personal information to send you product, service and new feature information and/or information about changes to our terms, conditions, and policies.
- To post testimonials with your Consent. We may post testimonials on our Sites that may contain personal information. Prior to posting a testimonial, we will obtain your Consent to use your name and testimonial. If you wish to update, or delete your testimonial, please contact us at email@example.com and be sure to include your name, testimonial location, and contact information.
- Deliver targeted advertising to you for our Business Purposes. We may use your information to develop and display content and advertising (and work with third parties who do so) tailored to your interests and/or location and to measure its effectiveness. For more information, see our .
- Administer prize draws and competitions for our Business Purposes and/or with your Consent. We may use your information to administer prize draws and competitions when you elect to participate in competitions.
- Request Feedback for our Business Purposes and/or with your Consent. We may use your information to request feedback and/or to contact you about your use of our Sites.
- To protect our Sites for Business Purposes and/or Legal Reasons. We may use your information as part of our efforts to keep our Sites safe and secure (for example, for fraud monitoring and prevention).
- To enforce our terms, conditions and policies for Business Purposes, Legal Reasons and/or possibly to comply with Contractual Obligations.
- To respond to legal requests and prevent harm for Legal Reasons. If we receive a subpoena or other legal request, we may need to inspect the data we hold to determine how to respond.
- For other Business Purposes. We may use your information for other Business Purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Sites, products, services, marketing and your experience. We may also use the information in other ways for which we provide specific notice at the time of collection.
WILL YOUR INFORMATION BE SHARED WITH ANYONE?
In Short: We share information to comply with laws, to protect your rights, to offer you tailored Site features and marketing, and to fulfill business obligations.
- Compliance with Laws. We may disclose your information to government officials, law enforcement authorities and other third parties where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process, such as in response to a court order or a subpoena (including in response to public authorities to meet national security or law enforcement requirements).
- Vital Interests and Legal Rights. We may disclose your information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person and illegal activities, or as evidence in litigation in which we are involved.
- Vendors, Consultants and Other Third-Party Service Providers. We may share your data with third party vendors, service providers, contractors or agents who perform services for us or on our behalf and require access to such information to do that work. Examples include: payment processing, order fulfillment, data analysis, email delivery, hosting services, customer service and marketing efforts. We may allow selected third parties to use tracking technology on the Sites, which will enable them to collect data about how you interact with the Sites over time. This information may be used to, among other things, analyze and track data, determine the popularity of certain content and better understand online activity. Unless described in this Policy, we do not share, sell, rent or trade any of your information with third parties for their promotional purposes.
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- Third-Party Advertisers. We may use third-party advertising companies to serve ads when you visit the Sites. These companies may use information about your visits to our Site(s) and other websites that are contained in web cookies and other tracking technologies in order to provide advertisements about goods and services of interest to you. See our for further information.
- Business Partners. We may share your information with our business partners to offer you certain products, services or promotions.
- With your Consent. We may disclose your personal information for any other purpose with your consent.
- Other Users. When you share personal information (for example, by posting comments, contributions or other content to the Sites) or otherwise interact with public areas of the Site, such personal information may be viewed by all users and may be publicly distributed outside the Site in perpetuity.
Do Not Track and Advertising Across Different Websites: We may not change our tracking practices in response to “do-not-track” signals or other similar mechanisms. Information about your browsing habits may be obtained by third parties that have content or services on our website as such third parties may not change their tracking practices in response to “do-not-track” signals from your web browser and we these parties are not obligated to honor “do-not-track” signals. For more information about browser tracking signals and “Do Not Track,” please visit http://allabountdnt.com.
Analytics Services: We may use analytics services, including Google Analytics, on our website and on our social media pages, among others, to help us determine how visitors use these platforms. For more information on how Google collects and uses information from our website or social media pages, you can visit: How Google Uses Data.
HOW DO WE HANDLE YOUR SOCIAL LOGINS?
In Short: If you choose to register or log in to our websites using a social media account, we may have access to certain information about you.
Our Sites offers you the ability to register an account and login using either the username and password you provide, or your third-party social media account details (like your Facebook or Twitter logins). Where you choose to do this, we will receive certain profile information about you from your social media provider. The profile Information we receive may vary depending on the social media provider concerned, but will often include your name, e-mail address, friends list, profile picture as well as other information you choose to make public. If you login using Facebook, we may also request access to other permissions related to your account, such as friends, check-ins, and likes, and you may choose to grant or deny us access to each individual permission.
IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
In Short: We may transfer, store, and process your information in countries other than the country in which the information was originally collected.
If you are accessing our Sites from outside the United States, please be aware that your information may be transferred to, stored, and processed by us in our facilities and by those third parties with whom we may share your personal information in other countries.
WHAT IS OUR STANCE ON THIRD-PARTY WEBSITES?
In Short: We are not responsible for the safety of any information that you share with third-party providers who advertise, but are not affiliated with, our Sites.
HOW LONG DO WE KEEP YOUR INFORMATION?
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented reasonable and appropriate technical and organizational security measures designed to protect the security of any personal information we process. However, please also remember that we cannot guarantee that the internet itself is 100% secure. Although we will do our best to protect your personal information, transmission of personal information to and from our Sites is at your own risk. You should only access the services within a secure environment.
DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly solicit or collect data from or market to children under 18 years of age. BY USING THE SITES, YOU REPRESENT THAT YOU ARE AT LEAST 18 OR THAT YOU ARE THE PARENT OR GUARDIAN OF SUCH A MINOR AND CONSENT TO SUCH MINOR DEPENDENT’S USE OF THE SITE. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we have collected from children under age 18, please contact us at firstname.lastname@example.org
WHAT ARE YOUR PRIVACY RIGHTS?
In Short: In some regions, such as the European Economic Area, you may have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.
In some regions (like the European Economic Area), you may have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information that we maintain, (ii) to request rectification or erasure of your personal information that we maintain; (iii) to restrict the processing of your personal information; and (iv) if applicable, to request that we transfer the personal information that we’ve collected to another organization, or directly to you. In certain circumstances, you may also have the right to object to the processing of your personal information. To make such a request, please contact email@example.com. We will consider and act upon any request in accordance with applicable data protection laws. We may take reasonable steps to verify your identity before granting access or making corrections. You may request to access, change or delete your personal information by contacting firstname.lastname@example.org.
If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. Please note however that this will not affect the lawfulness of the processing before its withdrawal.
If you are resident in the European Economic Area and you believe we are unlawfully processing your personal information, you also have the right to complain to your local data protection supervisory authority. You can find their contact details here: http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm
Cookies and similar technologies: Most Web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of our Sites. For further information, please see our
Opting out of email/text message marketing: You can unsubscribe from our marketing email/text message list at any time by clicking on the unsubscribe link in the emails that we send, by texting [STOP] to text message marketing, or by contacting us using the details provided below. You will then be removed from the marketing email/text message list – however, we may still need to send you service-related emails that are necessary for the administration and use of your account. You can also opt-out by:
- Noting your preferences at the time you register your account with the Sites.
- Logging into your account settings and updating your preferences.
- Contacting us using the contact information provided below.
ARE THERE ADDITIONAL RIGHTS AND DISCLOSURES REQUIRED FOR CALIFORNIA RESIDENTS?
In Short: Yes, the California Consumer Privacy Act (“CCPA”) provides California residents with specific rights regarding their personal information that is collected.
Collection and Disclosure of Personal Information
Access to Information and Privacy Rights
As a California resident, you have the right to (i) request additional information pertaining to your personal information that we have collected (including the sources from which such information has been collected), used, disclosed, and sold in the preceding 12 months, and our business purpose for collecting that personal information, (ii) request that we delete some or all of your personal data (subject to certain exceptions), and (iii) opt-out of any disclosure of storage, use, or sale of your personal data. If you have any questions, or if would like to exercise your individual data rights under the CCPA, please contact us . Note that we may ask that you provide certain information relating to your request in order to verify your identity.
You may designate an agent to submit such requests on your behalf. The agent will need to provide us with your signed permission to act on your behalf. We may require you to verify your identity directly and confirm that the agent has your permission to submit the request on your behalf.
We may offer financial incentives such as discounts and promotional offers when you provide us with contact information. When you sign-up for our email list or other discounts and promotional offers, you opt-in to a financial incentive. You may withdraw from a financial incentive by opting out from our emails or closing your account at any time. While we do not generally assign monetary or other value to personal information, California law requires that we assign value in the context of financial incentives. For such purposes, the value of the personal information provided is connected to the estimated cost of providing the relevant financial incentive(s) for which the information was collected.
Sales of Personal Information
We do not sell your personal information for monetary consideration. Applicable law, including the CCPA, may however deem our sharing of your personal information with third party service providers (including marketing services), as “sales” for purposes of the CCPA. We therefore may “sell” your personal information by means of disclosure in exchange for valuable consideration.
Your exercise of any of your rights under the CCPA will not be used against you, or to discriminate against you in any way.
DO WE MAKE UPDATES TO THIS POLICY?
In Short: Yes, we may update this policy to stay compliant with relevant laws.
HOW CAN YOU CONTACT US ABOUT THIS POLICY?
If you have questions or comments about this policy, email our Data Protection Officer at email@example.com, or by post to:
Kristin Ess Hair
225 Liberty Street, Suite 2301
New York, NY 10281