RFRain LLC (“RFR”), together with RFR’s affiliates (collectively, “we”, “us” or “our”), is the controller of your personal data under this Privacy Notice and is a manufacturer and seller of perfume, accessories, cosmetics, jewelry and personal care items (the “Business”). As a part of our operations, we gather certain types of information from and about online visitors and users through our website.
This Privacy Notice explains our practices with respect to personal data we collect and process. It applies to information collected from and about visitors and users (“you”) through our website operated by us (either directly or through our service providers) the respective web pages, sub-domains, and any other websites (and subdomains thereof) that we operate and that link to this Privacy Notice (collectively, the “Website”). This Privacy Notice also applies to information collected from or about you through email and other electronic submissions and communications between you and us, as well as to information collected at by our Business.
This Privacy Notice does not apply to information collected by any other company or third-party site, application or content (including advertising) that may link to or be accessible from the Website, who may have their own policies that govern their use of your personal data; to the extent your personal data is transferred to us, depending on the purpose and basis on which it was transferred, it will be subject to this Privacy Notice or to the privacy terms of such service provider or partner. Certain transactions offered while using the Services may be processed or provided by service providers and other strategic partners, even though it appears that you may not have left the Website or our Business (e.g., service providers that provide payment processing).
Please read this Privacy Notice carefully. It explains how we process and safeguard personal data about you. By visiting and/or by voluntarily providing personal data to us through or through or in connection with the Business, you acknowledge that you have read and understand the practices contained in this Privacy Notice. If you are providing information through the Website for or on behalf of a third party you hereby represent that you have the right to do so and that you have provided that party with a copy of this Privacy Notice, and all references to “you” or “your” data or personal data herein refers to the data or information of both you and such individual, as applicable.
TYPES OF INFORMATION COLLECTED ABOUT YOU AND HOW IT IS COLLECTED
1. INFORMATION YOU SHARE WITH US
2. AUTOMATICALLY-COLLECTED INFORMATION
3. COOKIES AND OTHER TRACKING TECHNOLOGIES
4. INFORMATION OBTAINED FROM THIRD PARTIES
HOW WE PROCESS PERSONAL DATA
1. LEGAL BASES FOR PROCESSING
2. OPERATIONAL PROCESSING OF PERSONAL DATA
3. HOW WE SHARE PERSONAL DATA
RETENTION OF PERSONAL DATA
YOUR RIGHTS REGARDING PERSONAL DATA
1. ACCESSING, MODIFYING, RECTIFYING, AND CORRECTING COLLECTED PERSONAL DATA
2. YOUR PRIVACY RIGHTS
3. YOUR CALIFORNIA PRIVACY RIGHTS
HOW WE RESPOND TO DO NOT TRACK SIGNALS
INTERNATIONAL USE AND DATA TRANSFERS
CHANGES TO THIS PRIVACY NOTICE
· A. TYPES OF INFORMATION COLLECTED ABOUT YOU AND HOW IT IS COLLECTED
We and our service providers collect various types of information from and about you, including:
· “Personal data,” which is information about an identified or identifiable individual. This includes, for example, your name, email address, telephone numbers, company affiliation, title, physical address, screen names, credit card details (including the three or four digit security code on the back of your credit card), bank account or other payment information, credit information, birth date. Personal data also may include information that may not be personally identifiable standing alone (for example, your age), but which may become personally identifiable when combined with other personal data (for example, your age combined with your name).
· “Non-personal data” is information that is about you, but which does not, and cannot be used to, identify you individually and is not linked to any personal data, including: aggregated data, such as information regarding use of our Website (including clickstream data, your movement within and interaction with the Website, including what pages you look at, and the time, date, and duration of your visit to the Website) and traffic patterns relating to the Website. Non-personal data may include personal data that has been anonymized in such a manner that it cannot be used, alone or in connection with other information, to identify you. Non-personal data also may be aggregated with non-personal data about others to create aggregate data.
We may collect this information through various means, including: (a) directly from you when you provide it to us, for example, via forms that you fill out on the Website, through emails and other communications and information that you submit via the Website, and through your other activities on the Website; (b) automatically as you navigate through and interact with the Website, including via server logs, cookies, pixels, beacons, analytics, and other tracking technologies; and (c) from third parties, including without limitation our service providers, analytics providers, intermediaries, analytics providers, and through your interactions with us on or involving social media websites or accounts.
1. Information You Share With Us
The information we collect may include the following types of personal data that you share with us:
· Information you provide when you register for the Website, make a purchase, participate in an offering made available on the Website, including without limitation your contact information (such as your name, address, zip code, email address, and/or phone numbers), your screen name or username, and your payment information (such as your credit card details, bank and bank account routing information, or other information);
· Your demographic information, such as your age, gender, marital status, number of children, and nationality;
· Information that you share in response to surveys and other market research;
· Information that you include in an email, general comment, or recommendation sent through on our Website, as well as records and copies of that correspondence (including email addresses);
· If you choose to log into the Website through social sign ins (such as Facebook Connect), personal data collected from your social media account consistent with your settings within the applicable social media service, such as photos, name, gender, contact information, and other information; and
· Other personal data that you choose to provide to us.
Whether you provide this information is your choice; however, please bear in mind that in many instances certain personal data is necessary for you to participate in a particular activity, for us to provide a certain service or benefit to you, or for you to gain access to certain features, services or content on our Website. If you elect not to provide us with certain personal data, you may not be able to participate in a particular activity, realize a benefit we may offer, or gain access to certain content, functionalities or services.
2. Automatically-Collected Information
When you visit and as you navigate through and interact with the Website, we and third parties may automatically collect information about your visits to our Website, your equipment, and your browsing action and patterns and your activities on the Website. This information may include, but is not limited to:
· Details of your visits to our Website and the resources that you access, such as traffic data, location data, logs and other communication data, the third-party website from which your visit originated, clickstream data, the search terms you use on our Website, your movement within and interaction with the Website, including what pages you look at, and the time, date, and duration of your visit to the Website.
· Information about your computer or devices and Internet connection, such as your IP address, your general geographic location, your computer or device type and its capabilities and features, the operating system or platform you are using, your browser type, and your Internet Service Provider.
· Information about traffic patterns, number of visits to certain pages, visits from other websites or to third-party websites linked to the Website, and visitors’ use of particular services and interest in services, information or features of the Website.
Automatically-collected information often is processed to create aggregated statistical or demographic data. We may share such aggregated data with third parties as described in the “How We Share Your Information” section below. Automatically-collected information that contains or constitutes personal data, as well as non-personal data that we maintain or associate with personal data collected in other ways or received from third parties, is be treated as personal data and used and shared as disclosed in this Privacy Notice.
3. Cookies and Other Tracking Technologies
We and third parties may place “cookies” on our Website to collect certain information. A “cookie” or “browser cookie” is a small text file that can be stored on your computer’s hard drive or other device, if your web browser or device settings permit. Certain features of the Website also may use local stored objects (or Flash Cookies) to collect and store information, including information about your preferences and navigation to, from, and on our Website. Cookies allow us and our service providers, for example, to customize your experience and make your visit to the Website easier (for example, recognizing when you return, remembering your viewing preferences, enabling social media sign in functionality, facilitating social sharing, and, if you are a registered user, remembering your password), measure activity on the Website, track conversions, target ads, and provide analytics. While some cookies are deleted when you close your browser, others remain even after you close your browsing session.
We and other third parties also may use pixel tags, web beacons or clear gifs, which are tiny files with a unique identifier, similar in function to cookies that are placed in the code of a web page or an email. These technologies might be used, for example, to allow us and our service providers to track conversions, to send emails to you in a format you can read, to count users who have visited our Website, seen our ads, opened our emails or clicked on any links in our emails, to inform us what content and advertising is effective, to optimize the Website and its content, to reduce or eliminate messages sent to customers, to enhance Website usability, to provide you with ads and other promotions and content that may be of interest to you based on your online activities, and to collect other information about you and your visit when you use the Website. In addition, when you click on a link in an email, we or our service providers may record the individual response to allow us to customize our offerings to you.
We may analyze the information derived from cookies, pixels and other technologies and match or combine that information with data provided by you or another party. We engage various service providers who may use unique identifiers, cookies, pixels, beacons, and other technologies to provide us with analytics about how and in what ways you interact with us and use the Website, and to deliver advertisements and content that may be of interest to you (known as “interest-based advertising” or “online behavioral advertising”). To the extent third parties are using pixels, cookies, beacons, or other tracking technologies, we do not control the use of those technologies or the resulting information, and we are not responsible for the policies of those companies.
Please keep in mind, however, that you may not be able to access the full functionality of our Website if cookies are disabled.
4. Information Obtained from Third Parties
We receive personal data from third parties that provide web analytics and usage information to us. In addition, if you choose to interact with us on social media platforms by posting to our social media accounts or pages, tagging us (or using certain hashtags or other identifiers) in posts, or participating in activities, we may collect certain information from the social media account you use to interact with us depending on the social media platform and your account settings, including the name associated with the account, the account handle, recent activity, the content of any posts in which we are tagged, and other information that may be contained on your social media profile to allow us to respond to the posts and understand and engage with our audience.
For the purposes of this Privacy Notice, “partners” means licensors, franchisees, vendors, service providers, and other third parties] with which we have a business relationship.
· B. HOW WE PROCESS PERSONAL DATA
1. Legal Bases for Processing
We process personal data for, or based on, one or more of the following legal bases:
· Performance of a Purchase. We use personal data to enter into and to perform under, an agreement between us, such as when you make a purchase.
· Legitimate Interests. We use personal data for our legitimate interests, including contact information, buying history and inquiry history, and website usage data.
· Compliance with Legal Obligations and Protection of Individuals. We may use personal data to comply with the law and our legal obligations, as well as to protect you and other individuals from certain harms.
· Your Consent. We process certain personal data because you have given us your consent to process it in that manner.
2. Operational Processing of Personal Data
· To provide, track, and process the purchases and transactions that you request;
· To validate your identity, to verify communications from you, and to respond to your emails, questions, comments, requests for information, and complaints and to provide customer service;
· To send you updates and information, such as communications about purchases, programs you have joined, and changes to our terms, conditions and policies;
· To conduct customer satisfaction, market research or quality assurance surveys ;
· To conduct market research;
· To conduct and administer sweepstakes, prize draws and other contests;
· For marketing purposes, including without limitation interest-based advertising, other targeted promotions, sending you other promotional materials, and notifying you about special promotions, offers, events or opportunities, including for select marketing partners of ours;
· To send you marketing communications about the products, marketing partners and other third parties;
· To cross-reference, supplement and combine with other information that we have acquired about you or may acquire about you through other sources, except where prohibited by applicable law or regulation;
· To monitor, track, and analyze Website usage and trends, to personalize and improve the Website, and to increase the Website’s functionality;
· To send you confirmations, updates, security alerts, and support and administrative messages and otherwise facilitate your use of, and our administration and operation of, the Website;
· To protect the security or integrity of our network, systems, Website, and business;
· To prevent fraud and other prohibited or illegal activities, to investigate and resolve disputes and problems, and to otherwise comply with applicable laws and regulations;
· For any other purpose that is disclosed to you at the point of collection of the personal data;
· For any purpose for which you provide your prior consent; and
· In other ways naturally associated with the circumstances in which you provided the personal data, and for any other lawful purpose.
In addition, we use IP addresses for purposes of system administration, for Website optimization, Website security assessments, to report non-personal aggregate information to others, to track the use of our Website, and to get a sense of where our Website visitors are located. We also we use your IP address to personalize content on the Website and to identify you.
3. How We Share Your Information
We may share non-personal data with any third parties for any lawful purpose. Unless otherwise prohibited by law, we disclose personal data collected from or about you as described in this Privacy Notice to the following types of third parties and for the following purposes:
· Affiliated Companies: We may share your information with our affiliated companies and other business ventures that are licensed, owned, operated, and/or managed by us and other companies under common control, who may use personal data for any of the purposes disclosed in or consistent with the terms of this Privacy Notice
· Marketing Partners:We do not share your personal data with our co-promotional partners and other business partners with whom we have marketing or other relationships for joint marketing purposes, but in certain circumstances do allow you to opt-in or otherwise acknowledge or consent the direct provision of your personal data to such parties when you provide it to us.
· Service Providers:We may share your information with our service providers who assist us by performing core services (such as hosting, billing, fulfillment, data storage, security, processing credit card payments, customer service, credit reporting, accounting, administering sweepstakes, surveys, email and mailing services, and delivering packages) related to the operation of the Business and the operation of the Website, the processing and fulfillment of product orders, and/or by making certain Website functionality available to our users.
· Transactions:In the event of a sale, merger, consolidation, change in control, transfer of substantial assets, bankruptcy, reorganization, or liquidation, we may transfer, sell, or assign to third parties information concerning your relationship with us, including, without limitation, personal data collected from or about you provide, and other information concerning your relationship with us. Any successor may use your information for the same purposes set forth in this Privacy Notice.
· Purpose Fulfillment: We disclose personal data to fulfill the purpose for which you provide it.
· Consent: We disclose personal data with your consent and/or when you request that we do so.
· C.RETENTION OF PERSONAL DATA
We retain personal data for as long is necessary or appropriate to fulfil the purpose for which it was collected, as well to the extent necessary or appropriate to carry out the processing activities described above, including but not limited to compliance with applicable laws, regulations, rules and requests of relevant law enforcement and/or other governmental agencies, and to the extent we reasonably deem necessary to protect our and our partners’ rights, property, or safety, and the rights, property, and safety of our users and other third parties. We consider multiple factors, including legal requirements, the scope and nature of the personal data, and potential risk of harm to data subjects from a data breach, in determining the appropriate retention period. If you have a specific question regarding retention of your personal data, you may contact us.
· D. YOUR RIGHTS REGARDING PERSONAL DATA
You have a variety of legal rights regarding the collection and processing of personal data. You may exercise these rights, to the extent they apply to you, by contacting us, or by following instructions provided in this Privacy Notice or in communications sent to you. Please be prepared to provide reasonable information to identify yourself and authenticate your requests.
Note, however, that we may request certain reasonable additional information (that may include personal data) to help us authenticate the request and/or to clarify or understand the scope of such requests.
These rights vary depending on the particular laws of the jurisdiction applicable to you, but may include:
· The right to know whether, and for what purposes, we process personal data about you;
· The right to be informed about the personal data we collect and/or process about you;
· The right to learn the source of personal data about you we process, where we obtain that personal data from a source other than you.
· The right to access, modify, and correct personal data about you.
· The right to know with whom we have shared personal data about you, for what purposes, and what personal data has been shared (including whether personal data was disclosed to third parties for their own direct marketing purposes);
· Where processing of personal data about you is based on consent, the right to withdraw your consent to such processing; and
· The right to lodge a complaint with a supervisory authority located in the jurisdiction of your habitual residence, place of work, or where an alleged violation of law occurred.
1. Accessing, Modifying, Rectifying, and Correcting Collected Personal data
We strive to maintain the accuracy of any personal data collected from you, and will use commercially reasonable efforts to respond promptly to update our database when you tell us the information in our database is not accurate. However, we must rely upon you to ensure that the information you provide to us is complete, accurate, and up-to-date, and to inform us of any changes. Please review all of your information carefully before submitting it to us, and notify us as soon as possible of any updates or corrections.
In accordance with applicable law, you may obtain from us certain personal data in our records. You can contact us as described below to access, review, update, or correct certain personal data. Please note, however, that we reserve the right to deny access as permitted or required by applicable law.
2. Your Privacy Rights
In addition to the above-listed rights, certain laws provide individuals with enhanced rights in respect of their personal data. These rights may include, depending on the facts and circumstances surrounding, and in certain cases the legal basis for, the processing of personal data, following:
· The right to be informed of whether we hold personal data about you.
· The right to object to decisions based on profiling or automated decisionmaking that produce legal or similarly significant effects on you;
· The right to request restriction of processing of personal data or object to processing of personal data carried out pursuant to (a) a legitimate interest (including, but not limited to, processing for direct marketing purposes) or (b) performance of a task in the public interest;
· The right to challenge the accuracy and completeness of your personal data and have it amended as appropriate;
· The right to be provided with information about our policies and practices with respect to the management of personal data, including: (a) the name or title, and address, of the person who is accountable for our privacy policies and practices; (b) the means of gaining access to personal data; (c) a description of the type of personal data held by us, including a general account of its use; (d) a copy of any brochures or other information that explain our policies, standards, or codes; and (e) what personal data is made available to related organizations;
· The right to data portability, which means that you can request that we provide certain personal data we hold about you in a machine-readable format; and
· The right to erasure and/or the right to be forgotten, which means that you can request deletion or removal of certain personal data we process about you.
Where required by applicable law, we will respond to a valid request relating to your rights within one month of receipt, or within three months where a request is complex or challenging. Note that we may need to request additional information from you to validate your request.
3. Your California Privacy Rights
California Civil Code Section 1798.83 permits residents of the State of California to request from certain businesses with whom the California resident has an established business relationship a list of all third parties to which the business, during the immediately preceding calendar year, has disclosed certain personal data for direct marketing purposes
We are only required to respond to a customer request once during any calendar year per person. To make such a request you should send an email to email@example.com with the subject heading “California Privacy Rights.” In your request, please attest to the fact that you are a California resident and provide a current California address for our response. Requests are free of charge.
Please be aware that not all information sharing is covered by the California privacy rights requirements and only information on covered sharing will be included in our response. We reserve our right not to respond to requests submitted to addresses other than the addresses specified in this paragraph.
· E. YOUR CHOICES
In certain instances, we may provide you with the option to set your preferences for receiving email communications from us; that is, you can agree to receive some communications but not others. At any time, you also may opt-out of receiving future commercial emails from us by following the “Unsubscribe” instructions contained in any commercial emails that you receive from us. You also may contact us if you want to opt-out from receiving future commercial correspondence, including marketing emails, from us. If applicable and appropriate, make the requested change in our active databases within a reasonable timeframe in compliance with applicable law. Please remember that we may not be able to fulfill certain requests while allowing you access to certain benefits and features. Even if you unsubscribe from our marketing communications, you may continue to receive certain communications from us, such as transactional, customer service or other relationship messages, messages about your account and profile, and emails in response to communications or requests for information that we receive from you.
If you want to limit or prevent our ability to collect location information from you, you can deny or remove the permission for the Website to access location information or deactivate location services on your device. Please refer to your device manufacturer or operating system instructions for instructions on how to do this.
Finally, consult our Cookie Notice for more information about how to control and/or opt out of certain web tracking technologies.
· F. INTEREST-BASED ADVERTISING
We may allow third parties to collect information about your online activities on our Website through unique identifiers, cookies, pixels, beacons and other technologies (as described above). These third parties include advertising networks that may use unique identifiers, cookies, pixels, beacons, and other technologies to track and collect information about your interests when you visit our Website and other websites or view or interact with one of the advertisements they place on various websites or mobile platforms. The information gathered by these third parties is used to make predictions about your characteristics, interests or preferences and to display advertisements on our Website and across the Internet tailored to your apparent interests.
Consult our Cookie Notice for more information about interest-based advertising, as well as how to control and/or opt out of certain web tracking technologies, including cookies and certain interest-based advertising providers.
· G. ANALYTICS
Consult our Cookie Notice for more information about analytics, as well as how to control and/or opt out of certain web tracking technologies, including cookies and certain analytics providers.
· H. PUBLIC FORUMS
We may offer blogs, message boards, bulletin boards, or similar public forums where you and other users of our Website can communicate. Unless otherwise required by applicable law or regulation, the protections described in this Privacy Notice do not apply to information (including personal data) that you post to these public forums.
We may use personally identifiable and non-personal data about you to identify you through your postings in a public forum. Any information you share in a public forum is public information and may be seen or collected by anyone, including third parties that do not adhere to our Privacy Notice. We are not responsible for events arising from the distribution of any information you choose to publicly post or share through our Website.
· I. CHILDREN
The Website is a general audience site, and the features, programs, promotions and other aspects of our Website requiring the submission of personal data are not intended for anyone under 18 years of age. If you are under 18, you may not access, use or register on the Website. We do not knowingly collect personal data from individuals under 18. If you are a parent or guardian of an individual under 18 and believe he or she has disclosed personal data to us without your permission, please contact us at firstname.lastname@example.org. A parent or guardian of a child under the age of 18 may request deletion of such child’s personal data as well as prohibit the use thereof.
· J. SECURITY
We take reasonable steps to protect against the loss, misuse and alteration and protect the confidentiality, integrity, availability, and resilience of the information under our control, including Secure Sockets Layer (SSL) technology to encrypt the transmission of non-public personally identifiable financial and transaction information over the Internet, provided you are using an SSL-enabled device. We also utilize other reasonable security measures such as firewalls, security patches, and anti-virus programs, to protect non-public personal data. We also take steps to ensure personal data is backed up and remains available in the event of a security incident. We periodically test, assess, and evaluate the effectiveness of our safeguards and security controls.
Despite these efforts, please be advised that no security system or means of transmitting data over the Internet can be guaranteed to be entirely secure (including without limitation with respect to computer viruses, malicious software and hacker attacks), and we cannot and do not guarantee or warrant the security of any information you disclose or transmit to us via the Internet, and are not responsible for the theft, destruction, or inadvertent disclosure of your personal data. For your own privacy protection, we recommend that you do not include any non-public personal or sensitive personal data such as passwords, social security numbers, credit card details, or bank account information, in any emails that you send to us. We will not contact you by email or text message to ask for such information.
· K. HOW WE RESPOND TO DO NOT TRACK SIGNALS
The Website does not recognize web browser “do not track” signals at this time. We may work with third parties that use tracking technologies on the Website, including in order to serve tailored advertisements on our behalf and on behalf of other advertisers across the Internet. These companies may collect information about your activity on the Website and other websites over time, as well as your interaction with our advertising and other communications, and use this information to determine which ads you see on third-party websites and applications. For more information about this practice and to understand your options, please visit http://www.networkadvertising.org/ or http://www.aboutads.info.
· L. OTHER WEBSITES/LINKS
As a convenience, our Website may reference or provide links to third-party websites and/or services that we do not control or maintain. When you access these third-party websites or services, you leave our Website, and we are not responsible for, and do not control, the content, security, or privacy practices employed by any third-party websites and services. You access such third-party websites and services at your own risk. Be aware that those third-party websites collect information and operate according to their own privacy practices. We are not responsible for the privacy practices employed by any third-party website. We encourage you to note when you leave the Website and to read the privacy statements of all third-party websites to understand how they collect, use and disclose personal data before submitting any personal data to those websites.
· M. INTERNATIONAL USE AND DATA TRANSFERS
Your personal data will be stored and processed in the United States. If you are using the Website or other Services from outside the United States, by your use of the Website or other Services you acknowledge that we will transfer your data to, and store your personal data in, the United States, which may have different data protection rules than in your country, and personal data may become accessible as permitted by law in the United States, including to law enforcement and/or national security authorities in the United States. For transfers of data out of the European Economic Area, we use standard contractual clauses, and, as appropriate, other applicable mechanisms.
· N. CHANGES TO THIS PRIVACY NOTICE
This Privacy Notice replaces all previous disclosures we may have provided to you about our information practices with respect to the Website. We may change or update this Privacy Notice in the future. You can identify the date that this Privacy Notice was last updated by looking at the date at the top of this Privacy Notice. Any revisions to this Privacy Notice will take effect upon posting to the Website. We will notify you of any material changes to this Privacy Notice either by sending an email to the email address that you provided to us and/or by placing a notice on the homepage of the Website. We encourage you to regularly review the current version of this Privacy Notice on the Website. Your use or continued use of the Website following posted changes constitutes your acknowledgement of the revised Privacy Notice then in effect.
· O. CONTACT US
If you have any questions, comments or concerns about this Privacy Notice, or if you would like to exercise the choices discussed above, please contact us (a) by email at email@example.com, or (b) by postal mail in the U.S. at RFRain LLC, 2063 Main Street, Sarasota, Florida 34237.
If you are located in the European Economic Area, and you wish to raise a concern regarding our use of your personal data, you have the right to do so with our lead supervisory authority, the U.K. Information Commissioner’s Office (the “ICO”) at www.ico.org.uk , or your local supervisory authority. We would, however, appreciate the opportunity to deal with your concerns before you approach the ICO, so please contact us in the first instance.