- PERSONAL INFORMATION WE COLLECT
Personal information you provide to us.
Personal information you may provide to us through the Service or otherwise includes:
Contact data, information such as your first and last name, email and mailing addresses, phone number, professional title, and company name.
Registration data, such as information that you provide to register for an account including the day and month of your birth.
Data about others for whom you purchase an item or gift, such as name, delivery address and phone number. (Please do not purchase a gift for someone or share their contact information with us unless you have their permission to do so).
Profile data, such as your username and password that you may set to establish an online account with us and your interests and preferences.
Communications, such as information you provide when you contact us with questions, feedback, survey responses, or otherwise correspond with us.
Information from customer surveys and feedback forms in respect of any of our products you may have purchased.
Marketing data, such as the email address or contact details that we use to send marketing communications and your preferences for receiving communications about our activities, events, sweepstakes, and contests.
Purchase data, including your order history and information needed to process and fulfill your order, including order details, billing address, and delivery address.
Financial details about any services bought from us including addresses for invoices/billing and bank payment details (including credit card payment details)
Details of your visits to our website including but not limited to traffic data, location data.
Data from other sources.
We may also collect information about you from:
Business partners, such as advertising and joint marketing partners.
Data providers, such as information services and data licensors.
Public sources, such as blogs, forums, or social media platforms.
Information we obtain from third party platforms.
If you choose to login to our Platform via a third-party website, such as Google or Facebook, or otherwise connect your account on the third-party platform or network to your account through the Sites, we may collect information from that platform or network. You may also have the opportunity to provide us with additional information via the third-party platform or network, such as a list of your friends or connections and your email address.
We and our service providers may automatically log information about you, your computer or mobile device, and your activity occurring on or through our service, such as:
Device data, such as your computer or mobile device operating system type and version number, manufacturer and model, browser type, screen resolution, IP address, the website you visited before browsing our site, and general location information such as city, state or geographic area.
Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, navigation paths between pages or screens, information about your activity on a page or screen, access times, and duration of access.
- WHEN DO WE COLLECT YOUR PERSONAL DATA?
When you visit our website, and use your account to buy products and services, or redeem vouchers on the phone, in a shop or online.
When you make an online purchase and check out as a guest (in which case we just collect transaction-based data).
When you create an account with us.
When you shop online, we capture information through cookies and similar technologies, you can manage these when you visit our site.
When you purchase a product or service in store or by phone but don’t have (or don’t use) an account.
When you engage with us on social media.
When you download or install one of our apps.
When you join our loyalty programme (such as my Angelify Beauty loyalty membership).
When you contact us by any means with queries, complaints etc.
When you ask one of our Partners to email you information about a product or service.
When you enter prize draws or competitions.
When you book any kind of appointment with us or book to attend an event.
When you choose to complete any surveys we send you.
When you comment on or review our products and services.
When you fill in any forms.
When you’ve given a third party permission to share with us the information they hold about you.
We collect data from publicly-available sources (such as Land Registry) when you have given your consent to share information or where the information is made public as a matter of law.
- HOW WE USE YOUR PERSONAL INFORMATION
The personal information we hold about you will be held solely for the following purposes:
To maintain records of your use of our services and administering those services;
To communicate with you regarding any transactions with you.
To make suggestions that may be of interest to you keeping you up to date regarding our services and activities whether by newsletter, email, or otherwise.
To facilitate payments in respect of any services requested by you.
To comply with our regulatory and legal obligations.
For credit and identity verification and fraud detection in respect of transactions with you.
To establish, exercise or defend any complaints made by or against you or any claims or litigation process raised by either of us against the other including in respect of us resorting to debt recovery or enforcing our terms of business.
To administer our website and business (including webhosting and support) and to ensure that content from our website is relevant to you and is presented in the most effective manner for you including seeking your views on our products and service.
For research and development purposes, including to analyze and improve the website and our business.
To create anonymous data records from your personal information by excluding information (such as your name) that makes the data personally identifiable to you. We may use this anonymous data and share it with third parties for our lawful business purposes, including to analyze and improve the Service and promote our business.
- LEGAL BASIS FOR PROCESSING PERSONAL DATA UNDER GDPR
We may process Personal Data under the following conditions:
Consent: You have given Your consent for processing Personal Data for one or more specific purposes.
Performance of a contract: Provision of Personal Data is necessary for the performance of an agreement with You and/or for any pre-contractual obligations thereof.
Legal obligations: Processing Personal Data is necessary for compliance with a legal obligation to which the Company is subject.
Vital interests: Processing Personal Data is necessary in order to protect Your vital interests or of another natural person.
Public interests: Processing Personal Data is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Company.
Legitimate interests: Processing Personal Data is necessary for the purposes of the legitimate interests pursued by the Company.
We will generally not collect sensitive data from you via our Platform. Sensitive data is personal information which includes your racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic or biometric data, or information concerning your health or mental wellbeing or sexual orientation. Much of the additional specific information referred to above will be sensitive data. Given the nature of the products and services we sell it is extremely unlikely that we will require to collect any sensitive data about you. Where we do require to process such sensitive data to provide services to you we will notify you in advance and will request your express consent in writing to process such sensitive data.
If you do not wish us to collect any of the personal data stated above, you should discuss this with us. We can explain the reasons for collection and discuss the consequences of not providing the information or of providing partial or incomplete information and the effect this may have on our ability to provide our services.
- HOW WE SHARE YOUR PERSONAL DATA
Companies and individuals that provide services on our behalf or help us operate the Service or our business (such as order fulfillment, shipping, payment processing, customer support, hosting, analytics, email delivery, database management services, returns processing and risk and fraud mitigation) and marketing services providers (which includes Shopify as the online ecommerce platform through which we operate our website. You can read more about how Shopify use your personal data at https://shopify.com/legal/privacy/ ).
Third party advertising companies that collect information about your activity on our Platform to help us advertise our services, and/or use hashed customer lists that we share with them to deliver ads to them and similar users on their platforms.
Third party platforms
Social media and other third party platforms that you connect to the Service, such as when you use options to access the Service by logging into a social media platform. Please note, we do not control the third party’s use of your personal information.
Other users of our Platform and the public, when you disclose personal information for public use. For instance, you may be able to review a product that you purchased, and we will display your name along with the content you submit. We do not control how other users or third parties use any personal information that you make available to them. Please be aware that any information you post publicly can be cached, copied, screen captured or stored elsewhere by others (e.g., search engines) before you have a chance to edit or remove it.
Professional advisors, such as lawyers, bankers, auditors and insurers, where necessary in the course of the professional services that they render to us.
Authorities and others
Law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate to comply with law or for the compliance, fraud prevention and safety purposes described above.
We may sell, transfer, or otherwise share some or all of your personal information in connection with or during negotiation of any merger, financing, acquisition or dissolution, transaction or proceeding involving sale, transfer, divestiture, or disclosure of all or a portion of our business or assets, or in the event of an insolvency, bankruptcy, or receivership.
Note that all third parties with whom we share your data are required to protect your personal data, treat it confidentially and to process it in accordance with the law. Where we use third parties we will take all reasonable steps to ensure that they are GDPR compliant and in particular that:
- they have adequate technical and other measures in place to ensure the security of your personal information;
- that they only use it for specified purposes;
- that any employees or contractors who have access to the information are adequately trained and deal with it on a need to know basis only;
- that they act only in accordance with our instructions.
- RETENTION OF YOUR PERSONAL DATA
We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods
- TRANSFER OF YOUR PERSONAL DATA
Your information, including Personal Data, is processed at our operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to and maintained on computers located outside your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.
- SECURITY OF YOUR PERSONAL DATA
The security of Your Personal Data is important to us, however, we cannot guarantee a 100% secure transmission of data over the Internet. While We strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
- WHERE YOUR PERSONAL DATA MAY BE PROCESSED
Angelify Beauty is a UK based company and so we will transfer your data to the UK, which is outside of the EU. We may also need to share your personal data with third parties and suppliers outside the European Economic Area (EEA).
- PROTECTING YOUR DATA OUTSIDE THE UK
We may transfer personal data that we collect from you to third-party data processors in countries that are outside the UK. For example, this might be required in order to fulfill your order, process your payment details or provide support services. If we do this, we have procedures in place to ensure your data receives the same protection as if it were being processed in the UK. For example, our contracts with third parties stipulate the standards they must follow at all times. If you wish for more information about these contracts please contact our Data Protection Officer at firstname.lastname@example.org. Any transfer of your personal data will follow applicable laws and we will treat the information under the guiding principles of this Privacy Notice.
- TRACKING TECHNOLOGIES AND COOKIES
Cookies or Browser Cookies
- YOUR RIGHTS UNDER THE GDPR
We undertake to respect the confidentiality of your personal data and we guarantee that you can exercise your rights.
Request access to your personal data. This includes the right to access, update or delete the information we have on you and also to receive a copy of the personal data we hold about you.
Request correction of the personal data that we hold about you
You have the right to have any incomplete or inaccurate information We hold about You corrected.
Object to processing of your personal data.
This right exists where we are relying on a legitimate interest as the legal basis for our processing and there is something about your particular situation, which makes you want to object to our processing of your personal data on this ground. It also includes the right to object where we are processing your personal data for direct marketing purposes.
Request erasure of your personal data.
You have the right to ask us to delete or remove personal data when there is no good reason for us to continue processing it.
Request the transfer of your personal data.
This right enables you to request a transfer of your personal data to you, or to a third-party you have chosen in a structured, commonly used, machine-readable format. Please note that this right only applies to automated information which you initially provided consent for us to use or where We used the information to perform a contract with you.
Withdraw Your consent.
You have the right to withdraw your consent on using your personal data. If you withdraw your consent, We may not be able to provide you with access to certain specific functionalities of the Service.
Additional information about these rights can be found on the Information Commissioner’s website at www.ico.org.uk/for-organisation/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/
- EXERCISING OF YOUR GDPR DATA PROTECTION RIGHTS
You may exercise your rights of access, rectification, cancellation and opposition by contacting us by filling an online form or by send an email to email@example.com. Please note that we may ask you to verify your identity before responding to such requests in order to protect the confidentiality of your data. If you have authorized a third party to submit a request on your behalf, we will ask them to prove they have your permission to act.
You have the right to complain to a Data Protection Authority about our collection and use of your personal data. If you are a resident of the UK, you can lodge your complaint to ico.org.uk. If You are in the European Economic Area (EEA), please contact Your local data protection authority in the EEA.
- CATEGORIES OF PERSONAL INFORMATION COLLECTED
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or Device. The following is a list of categories of personal information which we may collect or may have been collected from California residents within the last twelve (12) months.
PLEASE NOTE THAT THE CATEGORIES AND EXAMPLES PROVIDED IN THE LIST BELOW ARE THOSE DEFINED IN THE CCPA. THIS DOES NOT MEAN THAT ALL EXAMPLES OF THAT CATEGORY OF PERSONAL INFORMATION WERE IN FACT COLLECTED BY US, BUT REFLECTS OUR GOOD FAITH BELIEF TO THE BEST OF OUR KNOWLEDGE THAT SOME OF THAT INFORMATION FROM THE APPLICABLE CATEGORY MAY BE AND MAY HAVE BEEN COLLECTED. For example, certain categories of personal information would only be collected if you provided such personal information directly to us.
Category A: Identifiers.
Examples: A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, driver's license number, passport number, or other similar identifiers.
Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
Examples: A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.
Category C: Protected classification characteristics under California or federal law.
Examples: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
Category D: Commercial information.
Examples: Records and history of products or services purchased or considered.
Category E: Biometric information.
Examples: Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.
Category F: Internet or other similar network activity.
Examples: Interaction with our Service or advertisement.
Category G: Geolocation data.
Examples: Approximate physical location.
Category H: Sensory data.
Examples: Audio, electronic, visual, thermal, olfactory, or similar information.
Category I: Professional or employment-related information.
Examples: Current or past job history or performance evaluations.
Category J: Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).
Examples: Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.
Category K: Inferences drawn from other personal information.
Examples: Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes
Under CCPA, personal information does not include:
Publicly available information from government records
Deidentified or aggregated consumer information
Information excluded from the CCPA's scope, such as:
Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data.
Personal Information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994.
- 16. SOURCES OF PERSONAL INFORMATION
We obtain the categories of personal information listed above from the following categories of sources:
Directly from You
For example, from the forms you complete on our Service, preferences you express or provide through our Service, or from your purchases on our Service.
From Service Providers
For example, third-party vendors to monitor and analyze the use of our Service, third-party vendors for payment processing, or other third-party vendors that We use to provide the Service to You.
Indirectly from You
For example, from observing Your activity on our Service.
Automatically from You
For example, through cookies We or our Service Providers set on Your Device as You navigate through our Service.
- USE OF PERSONAL INFORMATION FOR BUSINESS PURPOSES OR COMMERCIAL PURPOSES
We may use or disclose personal information we collect for "business purposes" or "commercial purposes" (as defined under the CCPA), which may include the following examples:
To operate our Service and provide you with our Service.
To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our Service.
To fulfill or meet the reason you provided the information. For example, if You share your contact information to ask a question about our Service, We will use that personal information to respond to Your inquiry. If You provide Your personal information to purchase a product or service, We will use that information to process Your payment and facilitate delivery.
To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
As described to you when collecting Your personal information or as otherwise set forth in the CCPA.
For internal administrative and auditing purposes.
To detect security incidents and protect against malicious, deceptive, fraudulent or illegal activity, including, when necessary, to prosecute those responsible for such activities.
Please note that the examples provided above are illustrative and not intended to be exhaustive.
- DISCLOSURE OF PERSONAL INFORMATION FOR BUSINESS PURPOSES OR COMMERCIAL PURPOSES
We may use or disclose and may have used or disclosed in the last twelve (12) months the following categories of personal information for business or commercial purposes:
Category A: Identifiers
Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))
Category D: Commercial information
Category F: Internet or other similar network activity
Please note that the categories listed above are those defined in the CCPA. This does not mean that all examples of that category of personal information were in fact disclosed, but reflects our good faith belief to the best of our knowledge that some of that information from the applicable category may be and may have been disclosed.
When we disclose personal information for a business purpose or a commercial purpose, We enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
- PERSONAL INFORMATION OF MINORS UNDER 16 YEARS OF AGE
We do not collect the personal information of users we actually know are less than 16 years of age. If You have reason to believe that a child under the age of 13 (or 16) has provided us with personal information, please contact us with sufficient detail to enable us to delete that information.
20.YOUR RIGHTS UNDER THE CCPA
The CCPA provides California residents with specific rights regarding their personal information. If you are a resident of California, You have the following rights:
The right to notice
You have the right to be notified which categories of Personal Data are being collected and the purposes for which the Personal Data is being used.
The right to request
Under CCPA, You have the right to request that We disclose information to You about Our collection, use, sale, disclosure for business purposes and share of personal information.
The right to say no to the sale of Personal Data (opt-out)
You have the right to direct Us to not sell Your personal information
The right to delete Personal Data
You have the right to request the deletion of Your Personal Data, subject to certain exceptions.
The right not to be discriminated against
You have the right not to be discriminated against for exercising any of Your consumer's rights.
- EXERCISING YOUR CCPA DATA PROTECTION RIGHTS
In order to exercise any of your rights under the CCPA, and if you are a California resident, You can contact us by sending an email to firstname.lastname@example.org.
- LINKS TO OTHER WEBSITES
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
- CONTACT US
- CONTACTING THE REGULATOR
If you feel that your data has not been handled correctly, or you are unhappy with our response to any requests you have made to us regarding the use of your personal data, you have the right to complain to the Information Commissioner’s Office. You can contact them by calling 0303 123 1113.
Or go online to ico.org.uk/concerns (please note we can't be responsible for the content of external websites)
If you are based outside the UK, you have the right to lodge your complaint with the relevant data protection regulator in your country of residence.
Sometimes we will need to transfer your personal data between countries to enable us to supply the goods or services you have requested. In the ordinary course of business, we will transfer your personal data to the UK and may also transfer your personal data to third parties located in the UK to your country of residence.
We shall endeavour to ensure that reasonable steps are taken to procure that all such third parties outside of your country of residence shall not use your personal data other than for the services they provide and for which they need the personal data, and to adequately protect the confidentiality and privacy of your personal data.
We will ensure that any third parties only process your personal data in accordance with their legitimate interests. These third parties may be subject to laws that differ from the laws which apply in the country where you reside. We do not actively take steps to ensure that any overseas recipient of your personal data complies with the laws which apply in your country.
If you have any questions, please contact our Data Protection Officer, and we will respond within your local timeframe response requirements. To complain about an alleged breach of this Privacy Notice or our privacy obligations at law, please provide us with as much detail as possible in relation to your complaint. We will take any privacy complaint seriously and any complaint will be assessed with the aim of resolving any issue in a timely and efficient manner.
For the purposes of this Privacy Notice, “personal data” means any information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information or opinion is true, or opinion is recorded in a material form.
If you are in Australia, you may submit a complaint to our Data Protection Officer
who will come back to you within 30 days. If we have not come back to you or
you are not happy with the response that you receive you may submit a complaint to the Office of the Australian Information Commissioner.
For information about our cookies and website ‘track’ or ‘do not track’ practices please refer to our Cookies Policy.
If you submit a request to stop direct marketing communications from us, it will
take no longer than 10 days. As your data may be transferred to third parties outside the country where you are located, local police or other enforcement, regulatory or Government bodies may have access to that data with or without the Partnership’s knowledge. The personal data we process may be accessed by persons within the Partnership, or our third party service providers, who require such access to carry out the purposes indicated in this Privacy Notice, or such other purposes as may be permitted or required by the applicable law. Personal data we collect is maintained primarily in the UK.
If you feel that your data has not been handled correctly, or you are unhappy with our response to any requests you have made to us regarding the use of your personal information, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada, or in some Canadian provinces, your local Privacy Commissioner.
Terms used in this Privacy Notice shall have the same meanings ascribed to them in the Personal Data Protection Act 2010 (“PDPA”). If you are in Malaysia you may submit any questions, comments or complaints to our Data Protection Officer who will come back to you within 21 days.
The transfer of data to enable the company to supply the goods or services a customer has requested can be deemed as a Delegation.
Terms used in this Privacy Notice shall have the meanings assigned to them by the Personal Data Protection Act 2010 (also known as the PDPA). By placing an order with us, opening an account, browsing our website and/or agreeing to receive digital direct marketing communications, you agree that we may process your personal data as described in this Privacy Notice and our Cookies Notice, including for analytics and research into website use.
EU AND EEA Countries
If you are sending us your personal data directly you do so within the sphere of your household or personal activity. If you want to purchase a Angelify Beauty product for your business please contact our [B2B service]. This Privacy Notice will apply to how any personal data you provide to us is processed.
For questions regarding a product enquiry or in-store purchase please fill in the form below.
Main Mobile: +1 585 902 0283 (Mon-Fri, 9:00 am-17:00pm)
Text Messages only: +1 (585) 332-5750 (24 Hours)
WhatsApp for Business:
Text Messages Only: 07305934651 (Mon-Fri, 9:00 am-17:00pm)