Lilly Lashes, LLC (“we”, “us”, “our”) takes your privacy very seriously. Please read this privacy policy carefully as it contains important information on how and why we collect, store, use, and share your personal information in connection with your access to and use of our websites, www.lillylashes.com and www.lillylashescanada.com (the “sites”). It also explains your rights in relation to your personal information, your choices regarding the control of communications and the security procedures we use to protect your information.

CATEGORIES OF INFORMATION WE MAY COLLECT ABOUT YOU

We may collect “personal information” (meaning information that is, or is capable of being, linked to you) as well as non-personal information when you visit or use the sites. Following are examples of the types of information we may collect about you:

Contact Information
When you place an order, create an account, communicate with customer service, send us an email, or comment on our blog, you provide us with information that we collect. This information may include your name, address, phone number, credit card information, and purchase history.

Other Information We Receive and Store
We also receive information from you as a result of your visiting our sites including your IP address, your browser type and version, your operating system and platform, products you view, products you search for, length of visits to pages and other browser interaction information.

HOW INFORMATION IS COLLECTED

We collect most of your personal information directly from you—in person, by telephone, text or email and/or via our sites. Collection of this personal information is necessary to provide products to you. If you do not provide this personal information, it may delay or prevent us from providing products to you.

We may also collect your IP address when you visit our sites, and in certain cases we will associate that address with you to better understand your preferences and interests. We may also collect certain web analytics information, including, among other information, the number of visitors to the sites, session time, and browser version (“technical information”). This technical information is not collected in a manner in which it can be tied to a specific user (except as described above regarding IP addresses). In some cases, we may combine information we collect through our sites with information collected from other online and offline sources.

HOW AND WHY WE USE YOUR INFORMATION

Except as otherwise provided in this policy, we may use, share, or disclose all the information that we collect from you as a prospective, current or former customer:

- To fulfill orders placed by you.
- To respond to your requests, comments and questions and identify your interests so that we may assist you in finding products that may be of interest to you.
- To enforce any terms and conditions applicable to the sites.
- As required by law or valid legal process.
- In response to appropriate governmental requests.
- As we deem reasonably necessary to investigate, prevent or take other appropriate action, including in connection with the investigation of potential illegal or fraudulent activities or potential risk to the personal safety of any individual or the security of your information.
- To manage our business.
- To protect our interests.
- In the event that Lilly Lashes, LLC or a portion of its business is acquired by another company, including in bankruptcy, your information, including your personal information, may be transferred to the successor company.

PROMOTIONAL COMMUNICATIONS

We may use your personal information to send you updates (by email, text message, telephone or post) about our products, including exclusive offers, promotions or details about new products. We will always treat your personal information with the utmost respect and never sell or share it with other organizations outside of Lilly Lashes, LLC for marketing purposes.

You have the right to opt out of receiving promotional communications at any time by:

- Clicking the "unsubscribe" link at the bottom of any email from us or replying "STOP" to any mobile message sent from us
- Updating your marketing preferences in your account
- Contacting us by email at dataprivacy@lillylashes.com

We may ask you to confirm or update your marketing preferences if you purchase additional products from the sites in the future, or if there are changes in the law, regulation, or the structure of our business.

WHO WE SHARE YOUR PERSONAL INFORMATION WITH

We routinely share personal information with:

- Our subsidiaries and affiliates
- Service providers we use to help deliver our products to you, such as payment service providers, warehouses and delivery companies
- Other third-party service providers we use to help us run our business, such as marketing agencies or website hosts
- Third parties approved by you, including social media sites you choose to link your account to or third-party payment providers
- Our financial institutions

We only allow our service providers to handle your personal information if we are satisfied they take appropriate measures to protect your personal information. We also impose contractual obligations on service providers to ensure they can only use your personal information to provide services to us and to you. We may also share personal information with external auditors, e.g. in relation to an audit of our accounts.

We may disclose and exchange information with law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations.

We may also need to share some personal information with other parties, such as potential buyers of some or all of our business or during a re-structuring. We will typically anonymize information, but this may not always be possible. The recipient of the information will be bound by confidentiality obligations.

SAFEGUARDING YOUR INFORMATION 

Information transmitted over the Internet may find its way to recipients to whom it is not intended or persons you may not want to have such information. Under certain circumstances, this may be beyond our control, and you are advised that such transmission may not be secure. We comply with applicable laws regarding the safeguarding of your personal information, and we employ reasonable administrative, technical and physical safeguards to protect the security, confidentiality, and integrity of your information, as required by law. Further, we restrict access to nonpublic personal information about you (e.g., credit card or payment information) to those associates who need to know that information in order to provide products or services to you.

YOUR RIGHT TO CONTROL COMMUNICATIONS

We may provide you with an “opt-in” or “opt-out” mechanism depending on where you are located when we collect your personal data. An “opt-in” mechanism will provide you the opportunity to positively indicate that you would like or do not object to our use of your personal data for the designated purposes (such as sending you such further communications) and we will not make such use of your personal data unless you have “opted-in.” An “opt-out” mechanism will provide you the opportunity to indicate that you do not want us to use your personal data in certain ways (such as to send you such further communications), and if you “opt-out” we will not make such use of your personal data. Either way, opting-in or opting-out will be up to you. If you do not want us to use your personal data for a particular purpose or disclose it to a third party, you may “opt-out” at any time by contacting us at dataprivacy@lillylashes.com.

COOKIES AND INTEREST-BASED ADVERTISING

We may use cookies and other devices on our sites. Using cookies on our sites provides benefits to you, such as allowing you to maintain your account login information between visits. The use of cookies also allows us to measure site activity to provide a better user experience. Cookies and other devices may also be used to tell us additional information about the use of the sites, including, without limitation, the time and length of your visit, the pages you look at on our sites, the website you visited just before coming to ours, and the name of your Internet service provider. We may use third parties, such as Google Analytics, Shopify, and Hotjar to collect such data. Each service provider identified on, or accessed from the site has its own policies on the collection and use of technical information and the use of cookies. To learn more about how these third parties collect and process data and the choices they may offer to control these activities, you can view their privacy policies.  Google Analytics’ policy can be found here; Shopify’s policy can be found here; Hotjar’s policy can be found here.

YOUR CALIFORNIA PRIVACY RIGHTS

California consumers have the right to request any of the following information from us regarding personal information collected about you during the preceding 12 months:

- The categories of personal information collected about you.
- The categories of sources from which the personal information is collected.
- The business or commercial purpose for collecting or selling personal information.
- The categories of third parties with whom we share personal information, if any.
- The specific personal information collected about you.
- For personal information sold or disclosed to a third party for a business purpose, you have a right to know the categories of personal information about you that we sold and the categories of third parties to whom the personal information was sold; and the categories of personal information that we disclosed about you for a business purpose.

We will provide this information free of charge up to two (2) times in any twelve (12) month period within 45 days of receiving your verifiable request (including verification of your identity and your California residency), subject to delays and exclusions permitted by law.  Specific personal information about you or your account that is categorized as sensitive or confidential may be redacted.   

California consumers have the right to request that we delete any personal information that we have collected regarding the consumer.  We will honor this request subject to the range of exclusions permitted by law.  For example, we are not required to delete personal information if it is necessary to complete a transaction or reasonably used for an ongoing business relationship or if it is used internally in a lawful manner that is compatible with the context in which the consumer provided the information. 

California consumers also have the right to opt out of the sale of your personal information to third parties. If you opt out, we will not sell or transfer your information to any third party except as otherwise authorized by law.  We are permitted to transfer data to a service provider even if you opt out. A “service provider” is a business that agrees not to use your information for any purpose other than providing the services specified in our contract. We are also allowed to transfer your data to a third party where you direct the transfer or direct us to interact with the third party. For example, if you direct us to use a specific payment method to pay for your order, even if you have opted out, we will still transfer the data necessary to process your order.

We will not discriminate against you if you choose to exercise any of these rights. California residents may exercise the rights described above by contacting us as follows:

- By email: dataprivacy@lillylashes.com (please use “California Privacy” in the subject line

Please note that in order for a request to be verifiable, the you may be required to confirm information that we have on file for you; including email address, phone numbers, full names, addresses and other information.  We reserve the right to deny a consumer request if the identity of the requesting party cannot be confirmed.

PERSONAL INFORMATION WE DISCLOSED FOR A BUSINESS PURPOSE

In the preceding 12 months we have disclosed for a business purpose to one or more third parties the following categories of personal information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household:

- Identifiers (e.g., a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers);
- Information that identifies, relates to, describes, or is capable of being associated with, a particular individual, including, but not limited to, his or her name, signature, physical characteristics or description, address, telephone number, bank account number, credit card number, debit card number, or any other financial information;
- Internet or other electronic network activity information (e.g., browsing history, search history, and information regarding a consumer’s interaction with an Internet website, application, or advertisement);
- Geolocation data;
- Inferences drawn from any of the information identified above to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

We do not sell your information to third parties.

PRIVACY RIGHTS IN OTHER JURISDICTIONS

You may have rights, under applicable data privacy laws, to request information about or access to the personal information that we hold about you, to require that information to be corrected it is inaccurate or, in some circumstances, to object to our processing of your personal information. If you wish to exercise those rights, please send a written request to dataprivacy@lillylashes.com.

FORMER CUSTOMERS

Our policy for sharing nonpublic personal information about former customers is the same as our policy for current customers.

CHILDREN'S INFORMATION

The sites are not directed at or intended to be used by children, and we will not intentionally collect or maintain personal information about anyone under the age of 13, except for information provided by the relevant parent(s) or guardian(s). If we discover that we have collected any other personal information about anyone under the age of 13, we will take reasonable steps to promptly delete such information from our systems.

CHANGES TO THIS PRIVACY POLICY

This policy is effective as of the date listed above. We may change this policy from time to time–when we do we will inform you via a notice on our website or by email.

CONTACT US

Please contact us by post, email or telephone if you have any questions about this policy or the information we hold about you. Our contact details are shown below:

300 N Pacific Coast Highway
Suite 2070
El Segundo, CA 90245

Email: dataprivacy@lillylashes.com
Phone: (424) 398-7111