Grande Cosmetics, LLC Privacy Policy

Effective Date: May 20, 2020

Introduction

The website www.grandecosmetics.eu and any other website or application on which we have posted a link to this page (the “Site”) is owned and operated by Grande Cosmetics, LLC or one of its affiliates (“Grande Cosmetics,” “we,” “our,” or “us”). This Privacy Policy applies to our collection, storage, use and dissemination of information gathered from online visitors to our Site and other individuals whose data we may obtain as a result of the use of our Site. By visiting our Site, you agree that your visit and any dispute over our online privacy practices is governed by, applicable law (including GDPR, where applicable) this Privacy Policy and our Terms and Conditions of Use (“Terms”), which can be found here: Terms of Use

This Privacy Policy applies to “Personally Identifiable Information” or “PII,” that Grande Cosmetics collects, stores and uses in connection with your use of our Site.  Personally Identifiable Information is information that can be used to identify you, such as your first and last name, e-mail address, mailing ‎and billing addresses, telephone number, and payment information‎.  Reference in this policy to “information” are to such PII.

If you are in the European Union (“EU”) or (following Brexit) the United Kingdom (“UK”), then we may, as a result be subject to the General Data Protection Regulation (EU) 2016/679 or equivalent UK law (“GDPR”) on the protection of natural persons with regard to the processing of personal data in relation to you.  Where that is the case, we refer to you in this Privacy Policy as an “EU Individual” and as such this Privacy Policy provides you with the information required by GDPR.  Grande Cosmetics is the data controller of your PII for GDPR purposes, which is “personal data” as defined in GDPR.

BY PROVIDING INFORMATION TO GRANDE COSMETICS VIA THIS SITE, YOU ARE DEEMED TO CONSENT TO THE COLLECTION, STORAGE, USE AND DISSEMINATION OF SUCH INFORMATION AS DESCRIBED IN THIS PRIVACY POLICY, SAVE WHERE YOU ARE AN EU INDIVIDUAL AND GDPR DOES NOT ENABLE US TO OBTAIN YOUR CONSENT IN THIS WAY.

If you are an EU Individual, you can contact us at: 180 S Broadway Suite 102 White Plains, NY 10605, or policy@grandecosmetics.com in relation to our processing of your PII or any other data protection or data privacy matters and our designated representative under the GDPR is Biorius, Rue Joseph Wauters 113, 7170 Fayt-lez-Manage, Belgium. For these purposes, processing means any operation, including collection, organization, storage, use, disclosure and erasure.

What Information Do We Collect?

  • We collect information, including PII, from you when you register on the Site, place an order, enter a contest or sweepstakes, respond to a survey or communication such as e-mail, or participate in other Site features.
  • When ordering or registering, we may ask you for your name, e-mail address, mailing address, phone number, credit card information or other information. You may, however, visit our Site anonymously.
  • We also collect information names and delivery addresses about gift recipients so that we can fulfill gift purchases. The information we collect about gift recipients is not used for marketing purposes.
  • ‎Like many websites, we use various tracking technologies (including “cookies”) to enhance your experience and gather information about visitors and visits to our Site. See below for more information about our automatic collection practices.  This information is collected from you primarily by you providing it to us.  For example, when you complete forms on our Site or elsewhere in order to register, place orders for our products and services, enter contests or promotions or respond to surveys or marketing communications and in email or telephone correspondence with us.  It is collected automatically in the case of information stored in “cookies,” for example when you surf the Site or use certain other Site features.  We may also obtain information about you from other people, such as your name and delivery address where they purchase products for you.
  • If you are an EU Individual, please review our sections below for additional information about the legal bases and other details regarding the collection and processing your PII.

How Do We Use the Information Collected?

We may use your information for the following purposes:

  • to personalize your Site experience and to allow us to deliver the type of content and product offerings in which you are most interested;
  • to develop and improve our products and services;
  • to allow us to better service you in responding to your customer service requests;
  • to process your transactions and provide you with goods and services;
  • to administer a contest, promotion, survey or other Site features;
  • ‎to understand your needs or wishes;‎
  • for security and to check your identity;‎
  • for training and internal record keeping;‎
  • making changes to our business, including its structure or organization and informing you of those changes‎;
  • administering surveys, loyalty programs, contests and events;‎
  • to comply with our legal or regulatory obligations or with good practice in our industry;‎
  • account management, quality control, website and system administration and ‎security, disaster recovery and fraud prevention;
  • to communicate with you for any of the above purposes;
  • sending you emails and newsletters about new products, special offers or other information, which ‎we think you may find interesting (unless you have opted out); and
  • contacting you for market research purposes, by email, phone or mail (unless ‎you have opted out).

What are Legal Bases for our Collection and Processing of EU Individuals’ PII?

We only collect and further process the Personal Data of EU Individuals when we have a legal basis to do so. 

Depending on the purpose of collection and use, the legal basis for processing your information is either that ‎it’s necessary:‎

  1. to perform a contract to which you are party or take steps at your request before ‎entering into a contract (Contract);
  2. to comply with our legal obligations (Legal Obligations);
  3. for our legitimate interests or those of a third-party, which are not overridden by ‎your interests or fundamental rights and freedoms (Legitimate Interests);‎ and/or
  4. because we have obtained your specific, informed, unambiguous consent (Consent).‎

Our legitimate interests and those of relevant third-parties include the operation and ‎development of the applicable businesses, including, direct marketing and maintaining ‎security and integrity.‎

  • Contract. We will often need to process your PII to perform a contract we have with you, such as a contract to purchase our products or services, to use our Site, to use another service we provide that is described in our Terms such as a rewards or reseller program, to take steps at your request prior to entering into a contract, or to perform any other service, current or future, in connection with our Terms or this Privacy Policy.‎
  • Legitimate Interest. In many cases, the purposes we have described simply represent our legitimate business interests and the processing is proportionate and reasonable to achieve them and does not override your interests, fundamental rights or freedoms.  This includes the interests described throughout this policy among others such as our use of your PII for: management of the customer relationship; improving and managing your use and the experience of using our Site, products, and services; personalizing the user experience of our Site; ensuring the security of our Site; providing you with services, products, and information through combining data we collect from you with other data that we receive from you and other sources; ensuring the efficiency of our customer service; communicating with you about products, services, offers, benefits, events, carrying out studies and statistics; and letting you know about topics that interest you; and communicating important information to you about fraud.
  • Legal Obligations. We process certain of your PII in order to comply with laws and in the event of litigation or other legal actions.
  • Consent. In some cases we collect PII based on your freely given consent.  When doing so, we will inform you of the purpose of the processing and you are free to withdraw consent at any time.

How We Automatically Collect Information

In addition to the information that users of our Site provide voluntarily, Grande Cosmetics may automatically collect certain information when you visit or use our Site.  This information may include your IP address (or other unique device identifier, including one that we may assign); certain details about your browser, operating system, and hardware; your location, if available; the URL that referred you to our Site; your activities on our Site, including your preferences; and other logging information, such as the date and time of your visit.  We may use a variety of tracking technologies to automatically collect information, such as cookies, web beacons, embedded scripts, browser fingerprinting, GPS, iBeacons, and ETags (or “entity tags”).

All web servers log certain technical information from visitors each time they request a page.  We may aggregate such logged information anonymously to assist in designing enhanced user experiences and easier access to our information and services.

How we use Cookies

“Cookie” technology helps Grande Cosmetics to simplify visitors’ interactions with our Site. A cookie is a very small amount of information that is placed on your computer's hard drive by your browser on our behalf.  It is sent by your browser back to us when you return to our Site.

Cookies are used for various aspects of functionality such as keeping track of the items in your shopping bag, learning more about how you arrived at our Site, and to store your preferences so you don’t have to enter them each time you visit.  See below for the types of cookies we use and the functionality they support.

  • Essential Cookies. These are cookies that our Site needs in order to function and if they are not accepted by you, parts of the Site won’t be usable.  Examples of where these cookies are used include: to store how many items are in your shopping bag, to anonymously determine when you are signed in, and to determine which currency we should use based on your preferred delivery location when displaying prices to you.
  • Third-Party Cookies. Aside from setting cookies ourselves, we also allow carefully-selected third-parties to set cookies during your visit to our Site.  These organizations provide us with information on how you use our Site.  They may also use cookies to promote our newest products and latest offers to you on other websites based on your activity at our Site.  For example, you may see products that you viewed at our Site presented on other Sites as you move around the Internet.  Some of our partners will use your location to provide more relevant messaging.  Disabling these cookies will allow you to switch this feature off.
  • Analytics Cookies. We use various software tools that allow us to study, and then improve, how customers interact with our Site - this is known as website analytics.  Examples of analytical tools that we use are: Google Analytics and Adobe Analytics.  Analytics cookies allow us to understand more about how many visitors we have to the Site, how many times they visit our Site and how many times a user viewed specific webpages within our Site.  Although analytics cookies allow us to gather specific information about the pages that you visit and whether you have visited our Site multiple times, we cannot use them to find out details such as your name or address.

How Can I Manage My Cookies?

 

If you do not want to accept cookies from our Site, you can change your browser settings so that cookies are not accepted. If you choose to do this, please be aware our Site may no longer function as intended.

For further information about cookies and how to disable them please go to the Information Commissioner’s webpage on cookies; https://ico.org.uk/for-the-public/online/cookies/.

All popular Internet browsers (e.g. Chrome, Internet Explorer, Edge and Safari) allow you to amend your cookie settings so that cookies are no longer enabled across all websites that you visit. You can find information explaining how to disable cookies for the main browsers in the ‘Where to find information about controlling cookies’ section at the Information Commissions Site; https://ico.org.uk/for-the-public/online/cookies/.

You may always choose not to receive a cookie by enabling your web browser to refuse cookies or to prompt you before your browser accepts a cookie. By refusing to accept a cookie, you may be asked to enter certain information each time you access certain areas of our Site. In addition, for marketing purposes, we may review specific paths that you or an aggregate of customers have traveled through our Site.

If you wish to contact us to exercise your data rights, or ask about our data processing, you may do so using the following methods:

If you’re based in the EU/EEA or UK and wish to contact us via our GDPR Representative, DataRep, you may do so at:

Third-Party Sites & Services

Interactions with Other Sites and Services.  Our Site may include features from third-parties that allow you to interact with other online services, including social media.  For example, we may use third-parties to allow you to send messages, or make postings on social media sites, like Twitter and Instagram.  If you use these features, then we may share information about you with those third-parties, and they may collect additional information.  You should review the privacy policies for such third-parties to understand how they collect and use information.

Links to Third-Party Sites.  Our Site may include links to third-party websites or other online services.  We are not responsible for these other sites and services, and they may collect and use information about you.  You should review the privacy policies for such third-parties before using their sites or services to understand how they collect and use information.

Third-Party Tracking and Do Not Track

Third parties may use tracking technologies in connection with our Site, which may include the collection of information about your online activities over time and across third-party Sites.  This Privacy Policy does not apply to these third-party technologies because we may not control them and we are not responsible for them. 

Do Not Track is a technology that enables users to opt out of tracking by websites they do not visit.  Currently, we do not monitor or take any action with respect to Do Not Track technology.

Additional ways your PII may be used and shared

As Required by Law or Similar Process.  Grande Cosmetics may disclose your PII, the contents of your communications with us, and/or other information you have provided to us if required to do so by law, with your consent, or in the good faith belief that such action is necessary:

  1. to conform to applicable law or comply with legal process served on Grande Cosmetics;
  2. to protect or defend the rights or property of Grande Cosmetics or others;
  3. to assist, under exigent circumstances, in the investigation of possible violations of law or other investigations; and/or
  4. to assist law enforcement in preventing harm to anyone.  If you are an EU Individual, the above will only apply to legal obligations imposed on us under UK or EU law.
  

Sale or rental or other transfer of your PII.  We do not sell, trade, or otherwise transfer your PII to outside parties unless we provide you with advance notice, except as described herein.  The term “outside parties” does not include Grande Cosmetics, LLC or its affiliates. 

We may transfer or disclose your PII to:

  • Site hosting partners;
  • other parties, our service providers, sub-contractors and agents, to assist us in operating our Site, conducting our business, or servicing you;
  • to applicable authorities, agencies and other bodies or person, when appropriate to comply with the law, enforce our Site policies, or protect ours or others' rights, property, or safety;
  • our affiliates, including our subsidiaries in other countries;‎
  • anyone to whom we may transfer any part of our business, rights, obligations or ‎assets or our shares;‎ and
  • credit reference agencies and fraud prevention agencies.‎

Non-personally identifiable visitor information may, however, be provided to other parties for marketing, advertising, or other uses.

Use of Analytics Services.  We may use third-party analytics services (such as Google Analytics or Adobe Analytics) that track details about your online activities ‎over time and across different sites.  These services help us to improve our Site, products, and services.  These services may also allow ‎us and others to provide you with targeted advertisements or other content that you may be interested in based on ‎your online activities.  If you would like to learn more about targeted ads that may be based on your online activities, ‎and the choices that you may exercise for certain sites and advertisers, you may wish to visit the Network ‎Advertising Initiative or the Digital Advertising Alliance.  Those websites can be found here: https://www.networkadvertising.org/ and here: https://digitaladvertisingalliance.org/ respectively.  To opt out of being tracked by Google Analytics across all ‎Web sites, visit: https://tools.google.com/dlpage/gaoptout.

Using our Site for purchases.  In order to make purchases on the Site, you will need to go through our checkout process and provide your payment information, such as your credit card or debit card number and expiration date.  If you choose to make a payment online, you will be redirected to one of our PCI-compliant third-party payment processors, such as Authorize.net, PayPal, or Afterpay.  Grande Cosmetics strives to ensure that all of its partners and affiliates maintain industry-standard privacy policies and practices.  Please be aware, however, that Grande Cosmetics does not directly collect or store any of your payment information, and it does not control the privacy policies and practices of its third-party payment processors.  To understand how a third-party payment processor collects, processes and stores your payment and other information, please review the privacy policy of our payment processors.  For example, the Privacy Policy for Authorize.net can be found here: https://usa.visa.com/legal/privacy-policy.html, the Privacy Policy for PayPal can be found here: https://www.paypal.com/us/webapps/mpp/ua/privacy-full, and the Privacy Policy for Afterpay can be found here: https://www.afterpay.com/privacy-policy.

Notice to non-U.S. Site users

If you are from a non-U.S. country, please be aware that the information you submit to us is being sent by you directly to a location operated by us in the United States for collection and further processing by us.  The data protection laws in the United States may differ from those of the country in which you are ‎located‎.

If you are an EU Individual, please note that since we are collecting the information directly from you (or from individuals who purchase goods for you for personal purposes), this does not involve our transferring your information to the United States. 

Statutory Rights of EU Individuals

If you are an EU Individual, upon request, free of charge, you have the right to: 

  1. obtain confirmation as to whether we process your PII;
  2. access and obtain a copy of the PII we hold about you;
  3. obtain information about the purposes for which we process your PII and the categories of PII concerned;
  4. obtain information on the recipients or categories of recipients (including international recipients) to whom your PII has been or will be disclosed;
  5. request the correction of inaccurate PII we hold about you;
  6. request that we delete your PII, or stop processing it or collecting it, in some circumstances;
  7. request the transfer of your PII from us to another data controller;
  8. lodge a complaint to the supervisory authority in your jurisdiction in respect of our collection or use of your PII; and
  9. withdraw your consent to our collection, use, storage, and dissemination of your data at any time.

Please be aware that any request for withdrawal of consent under item (9) above will not affect the lawfulness of PII collected, processed, and transferred prior to the date of such withdrawal of consent. 

To make any of the requests above, contact us at policy@grandecosmetics.com.

How You Can Control the Use of Your PII

You may indicate certain preferred restrictions on our use of your PII, such as opting-out of or unsubscribing from our marketing communications, newsletters or e-mails by using the “unsubscribe” feature included in such messages or by contacting us by e-mail at policy@grandecosmetics.com.  In that e-mail, you should indicate which of the following options you prefer:

  • Grande Cosmetics should not send me physical mail with newsletters or other information that may be of interest to me;
  • Grande Cosmetics should not send me electronic mail with newsletters or other information may be of interest to me;
  • I understand that Grande Cosmetics may send me any information about third-party or other products and services, subject to my having opted in to this where I am an EU Individual.

To request access to, or notify us of changes to, PII we have collected, contact us at policy@grandecosmetics.com.              

How Your PII is Secured and Protected

Grande Cosmetics implements reasonable administrative, technical and physical safeguards designed to protect your PII from accidental loss and from unauthorized access, use, alteration or disclosure.  Your PII is contained behind reasonably secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential.  Regardless of any such precautions taken in good faith by visitors or by us, security on the Internet is imperfect, and we cannot warrant the protection of any information visitors transmit to us, which visitors do voluntarily and at their own risk.

For How Long do we Store your Information?

If you are an EU Individual, we will delete your PII once it is no longer proportionate for us to store it for the purposes of the processing in accordance with our applicable data record retention period. 

Where your PII relates to a contract, we will retain it for six years from the end of the contract, being the period when the time limit for ‎claims has expired (unless a claim is made and the information is required for the ‎claim).

Otherwise, if you are a customer, we will retain it for three 3 years since our last communication from you. 

If you are not a customer, we will retain it for eighteen (18) months.

This is subject to any legal or regulatory requirement to retain the information for a minimum period.

Linking to Other Sites

Our Site links to third-party Sites.  Grande Cosmetics does not control those Sites and this Privacy Policy does not apply to such third-party Sites.  Visitors should examine the privacy statements for all third-party Sites to understand their procedures for collecting, using, and disclosing visitors' information.  While we have no responsibility or liability for the content or activities of these linked sites, we seek to protect the integrity of our Site and welcome any feedback about these linked sites (including if a specific link does not work).

About Children's Privacy

The Site is intended for general audiences, and we do not knowingly seek or collect PII from children under the age of eighteen (18).  In accordance with the Child Online Privacy Protection Act, in the event that we learn that we have collected PII from a child under age thirteen (13) without verification of parental consent, we will delete that information as quickly as possible.  If you believe that we might have any PII from or about a child, please contact us at policy@grandecosmetics.com.

Your California Privacy Rights

We may from time to time elect to share certain information about ‎you collected by us on the Site with third-parties for those third-parties’ direct marketing purposes.  California Civil Code Section 1798.83 permits California residents who have supplied personal ‎information, as defined in the statute, to us to, under certain circumstances, request and obtain ‎certain information regarding our disclosure, if any, of PII to third-parties for their ‎direct marketing purposes. If this applies, you may obtain the categories of PII ‎shared and the names and addresses of all third-parties that received PII for their ‎direct marketing purposes during the immediately prior calendar year (e.g., requests made in 2019 will ‎receive information about 2018 sharing activities) or to request to opt-out of such future sharing.  ‎To make such a request, please provide sufficient information for us to determine if this applies to ‎you, attest to the fact that you are a California resident and provide a current California address for ‎our response.  You may make this request in writing at: consumer@grandecosmetics.com.

Sweepstakes, Contests and Promotions

We may offer sweepstakes, contests, and other ‎promotions (any, a “Promotion”) through the Site that may require registration.  By ‎participating in a Promotion, you are agreeing to the official rules that govern that Promotion which are separate from this Privacy Policy, and which ‎may contain specific requirements of you, including, allowing the sponsor of the Promotion to use ‎your name, voice, and/or likeness in advertising or marketing associated with the Promotion.  If ‎you choose to enter a Promotion, certain PII may be disclosed to third-parties or the ‎public in connection with the administration of such Promotion, including, in connection with ‎winner selection, prize fulfillment, and as required by law or permitted by the Promotion’s official ‎rules, such as on a winners list.

Changes to this Privacy Policy

Grande Cosmetics reserves the right to modify or amend this Privacy Policy at any time and for any reason.  If we make any significant changes to our information privacy practices, we will post notice of the change on our homepage for a reasonable period of time after any such significant change is implemented or e-mail you about these changes.

Questions

Questions about this Privacy Policy will be answered if submitted to us at policy@grandecosmetics.com.