1. Types of Data We Collect
We collect Non-Personal Information and Personal Information and the information we collect from you depends on how you use the Services. “Non-Personal Information” includes information that cannot be used to personally identify you, such as anonymous usage data, general demographic information we may collect, referring/exit pages and URLs, platform types, preferences you submit and preferences that are generated based on the data you submit and number of clicks. “Personal Information” means data that allows someone to identify or contact you, including, for example, your name, address, telephone number, email address, as well as any other non-public information about you that is associated with or linked to any of the foregoing data. This includes:
|Context||Types of Personal Information||Primary Purpose for Collection and Use of Personal Information|
|User Information||We collect your name, email address, city and state, birth date, time zone and gender of our customers.||We have a legitimate interest in contacting our customers and communicating with them in relation to the Services.|
|User Account information||We collect information you provide to create an account, specifically your name, email address, city, state, birth date, time zone, gender and payment information.||We have a legitimate interest in providing certain account-related functionalities to our users, monitoring account log-ins, and detecting potential fraudulent logins or account misuse. Additionally, we use this information to fulfill our obligation to provide you with Services.|
|Cookies and Third Party Tracking||We participate in behavior-based advertising, this means that a third party uses technology (i.e.: a cookie) to collect information about your use of the Services.||We have a legitimate interest in capturing website analytics and engaging third parties to assist with providing Services to you.|
|Email Interconnectivity||If you receive email from us, we use certain tools to capture data related to when you open our message, click on any links or banners it contains and make purchases.||We have a legitimate interest in understanding how you interact with our communications to you.|
|Feedback/Support||We collect personal data from you contained in any inquiry you submit to us regarding the Services, such as completing our online forms, or emailing for the purposes of general inquiries, support requests, or to report an issue.||We have a legitimate interest in receiving, and acting upon, your feedback, issues, or inquiries.|
|Mailing List||When you sign up for one of our mailing lists, we collect your email address.||We share information about our products and services with individuals that consent to receive such information. We also have a legitimate interest in sharing information about our products and services.|
|Mobile Devices||We collect information from your mobile device such as unique identifying information broadcast from your device when using the Services.||We have a legitimate interest in identifying unique visitors, and in understanding how users interact with us on their mobile devices.|
|Website & Application Interactions||We use technology to monitor how you interact with the Services. This may include: IP addresses, preferences, web pages you visited prior to using the Services, information about your browser, network or device (such as browser type and version, operating system, internet service provider, preference settings, unique device IDs and language and other regional settings), information about how you interact with the Services (such as timestamps, clicks, scrolling, browsing times, searches, transactions, referral pages, load times, and problems you may encounter, such as loading errors).||We have a legitimate interest in understanding how you interact with the Services to better improve the Services, and to understand your preferences and interests and to select offerings that you might find most useful. We also have a legitimate interest in detecting and preventing fraud.|
|Web logs||We collect information, including your browser type, operating system, Internet Protocol (“IP”) address (a number that is automatically assigned to a computer when the Internet is used), domain name, click-activity, referring website, and/or a date/time stamp for visitors.||We have a legitimate interest in monitoring web logs to provide the Services and enhance the Services.|
2. Children’s Online Privacy Protection Act
Our Services are not designed for children under 13, and we do not intentionally or knowingly collect Personal Information from users who are under the age of 13 or from other websites or services directed at children. If we discover that a child under 13 has provided us with Personal Information, we will delete such information.
3. Information You Provide to Us
- We may collect Personal Information from you, such as your first and last name, email and mailing address, phone, and password when you create an account to log in to the Services (“Account”).
- When you engage us to provide Services, our payment processor will collect all information necessary to complete the transaction, including your name, credit card information, billing information, and direct deposit information.
- If you provide us feedback or contact us via email, we will collect your name and email address, as well as any other content included in the email, in order to send you a reply.
- When you participate in one of our surveys, we may collect additional information that you knowingly provide.
- We will maintain the information you send via email in accordance with applicable federal law.
- In compliance with the CAN-SPAM Act, all emails sent from our organization will clearly state who the email is from and provide clear information on how to contact the sender. In addition, all email messages will also contain concise information on how to remove yourself from our mailing list so that you receive no further e-mail communication from us.
4. Information Collected via Technology
- We reserve the right to use technological equivalents of cookies, including social media pixels. These pixels allow social media sites to track visitors to outside websites so as to tailor advertising messages users see while visiting that social media website. We reserve the right to use these pixels in compliance with the policies of the various social media sites.
5. Use of Your Personal Information
In general, Personal Information you submit to us is used either to respond to requests that you make, or to aid us in serving you better. We use your Personal Information in the following ways:
- to facilitate the creation of and secure your Account;
- to identify you as a user in our system;
- to provide improved administration of the Services;
- to provide the Services you request;
- to improve the quality of experience when you interact with the Services;
- to send you a welcome email to verify ownership of the email address provided when your Account was created;
- to send you administrative email notifications, such as security or support and maintenance advisories;
- to respond to your inquiries related to employment opportunities or other requests;
- to periodically send newsletters, surveys, offers, and other promotional materials related to our Services and for other marketing purposes including those of third parties;
- to perform marketing or data analysis;
- to comply with legal obligations, as part of our general business operations, and for other business administration purposes; and
6. Use of Non-Personal Information
7. How We Share Your Personal Information
Third Party Service Providers. We may share your Personal Information with third party service providers to provide you with the Services that we offer you; to conduct quality assurance testing; to perform marketing; to run data analysis; to facilitate creation of Accounts; to provide technical support; and/or to provide future services to you. The third party service providers we are engaged with to provide the Services include without limitation Google Analytics, Twilio, SendGrid, and Stripe and the terms and policies are set forth on such third party’s website.
Process Payments. We transmit your Personal Information via an encrypted connection to our payment processor. To learn more about the payment processor we use and their policies related to privacy, learn more at Stripe.
Business Transfers. If (i) we or our affiliates are or may be acquired by, merged with, or invested in by another company or (ii) if any of our assets are or may be transferred to another company, whether as part of a bankruptcy or insolvency proceeding or otherwise, we may transfer the information we have collected from you to the other company. As part of the business transfer process, we may share certain of your Personal Information with lenders, auditors, attorneys and consultants.
8. Links to Third Party Websites and Third Party Providers
9. Your Rights Regarding the Use of Your Personal Information
10. Your Rights and Choices
If applicable privacy laws allow, you may have rights over your Personal Information. This includes, but is not limited to:
- Right to Know. You have the right to request disclosure about our Personal Information collection practices during the prior 12 months, including the categories of Personal Information we collected, the sources of the information, our business purposes for collecting or sharing the information and the categories of third parties with whom we shared such information. You may request a copy of the specific pieces of Personal Information we may have collected about you in the last 12 months.
- Right to Delete. You may request that we delete (and direct our service providers to delete) your Personal Information, subject to certain exceptions.
- Right to Opt-Out. You have the right to opt-out of any ‘sales’ of your Personal Information, if a business is selling your information.
- Non-Discrimination. You have the right to not be discriminated against for exercising these rights.
You can make the following choices regarding your Personal Information:
- Access To Your Personal Information. You may request access to your Personal Information by contacting us at the address below. If required by law, upon request, we will grant you reasonable access to the Personal Information that we have about you. We will provide this information in a portable format, if required. Note that California residents may be entitled to ask us for a notice describing what categories of Personal Information (if any) we share with third parties or affiliates for direct marketing.
- Changes To Your Personal Information. We rely on you to update and correct your Personal Information. Please contact us at the address below immediately if there are any changes to your Personal Information. Note that we may keep historical information in our backup files as permitted by law.
- Objection to Certain Processing. You may object to our use or disclosure of your Personal Information by contacting us at the address below.
- Online Tracking. We do not currently recognize automated browser signals regarding tracking mechanisms, which may include ‘Do Not Track’ instructions.
- Promotional Emails. You may choose to provide us with your email address for the purpose of allowing us to send free newsletters, surveys, offers, and other promotional materials to you, as well as targeted offers from third parties. You can stop receiving promotional emails by following the unsubscribe instructions in e-mails that you receive. If you decide not to receive promotional emails, we may still send you Service-related communications.
- Revocation Of Consent. If you revoke your consent for the processing of Personal Information, then we may no longer be able to provide you Services. In some cases, we may limit or deny your request to revoke consent if the law permits or requires us to do so, or if we are unable to adequately verify your identity. You may revoke consent to processing (where such processing is based upon consent) by contacting us at the address below.
11. Security of Your Personal Information and Personal Data
We implement security measures designed to protect your information from unauthorized access, alteration, disclosure and/or destruction. Because the internet is not a completely secure environment, we cannot warrant the security of any information a user transmits to us or guarantee that information on the Services may not be accessed, disclosed, altered, and/or destroyed by breach of any of our physical, technical and/or managerial safeguards. Any account you have on the Services is protected by your account password and we urge you to take steps to keep your Personal Information safe by not disclosing your password and by logging out of your account after each use. We further protect your information from potential security breaches by implementing certain technological security measures; however, these measures do not guarantee that your information will not be accessed, disclosed, altered or destroyed by breach of such firewalls and secure server software. While we use reasonable efforts to protect your Personal Information, we cannot guarantee its absolute security.
12. How we Retain Your Personal Information
We will retain your Personal Information for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. The precise periods for which we keep your Personal Information vary depending on the nature of the information and why we need it. To determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorized use and/or disclosure of your Personal Information, the purposes for which we process your Personal Information and whether we can achieve those purposes through other means, and the applicable legal requirements.
In some circumstances we may anonymize your Personal Information (so that it can no longer be associated with a user) for research or statistical purposes in which case we may use this information indefinitely without further notice. We may retain information (including without limitation your personally identifiable information) for a commercially reasonable time for backup, archival, audit purposes, and/or to comply with legal obligations, resolve disputes and enforce agreements. In some cases, if you choose not to provide us with requested information, you may not be able to use the Services. You can request further details of retention periods for different aspects of your Personal Information by contacting us.
Please note that in the course of providing the Services, we collect and maintain aggregated, anonymized, or de-personalized information which we may retain indefinitely.
15. Other Jurisdictions
Personal information that you submit through the Services may be transferred outside of the jurisdiction in which you live. We also store Personal Information locally on the devices you use to access the Services. Your Personal Information may be transferred to other jurisdictions that do not have the same data protection laws as the jurisdiction in which you initially provided the information. The following provisions may apply to you depending on where you are located.
This notice is provided to you pursuant to state law. Nevada state privacy laws permit us to make marketing calls to existing customers, but if you prefer not to receive marketing calls, you may be placed on our internal opt-out list by emailing us firstname.lastname@example.org or you may also contact the Nevada Bureau of Consumer Protection, Office of the Nevada Attorney General, 555 E. Washington St., Ste 3900, Las Vegas, NV 89101; telephone 702-486-3132; email: AGCinfo@ag.nv.gov.
In accordance with Vermont law, we will not share information we collect about you with companies outside of ours except as described herein, otherwise required or permitted by law.
This Section is only applicable to you if you are a resident of the state of Virginia (“Virginia Residents”). If you have a complaint, first contact us at email@example.com. We will respond within 45 days after receipt of your request, and such time may be extended for an additional 45 days if it is reasonably necessary. We will notify you of any extension within the initial 45-day period. If you are not satisfied with our responses, you have the right to appeal. We will respond within 60 days after our receipt of your appeal. If you still have an unresolved complaint, please direct your complaint to the Virginia Attorney General at firstname.lastname@example.org or call (804)786-2071.
This Section is only applicable to you if you are a resident of the state of California (“California Residents”) and only applies to Personal Information for which Company is a “Business” (as defined in the California Consumer Privacy Act (“CCPA”), but does not apply to Personal Information we collect from you in the course of our provision of services to you where you are an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, non-profit or government agency. It applies to Personal Information we collect from California Residents on or through our Services and through other means (such as information collected offline or in person).
Exercising Your Rights. If you’re a California resident and desire to exercise your data protection rights, please contact us at email@example.com. You may be required to provide additional information necessary to confirm your identity before we can respond to your request, and we will use that information only for that purpose. We may request that you submit a signed statement under penalty of perjury that you are the individual you claim to be. We will acknowledge receipt of your request within 10 days from receipt of such request and will endeavor to respond within 45 days after receipt of your request, but if we require more time (up to an additional 45 days) we will notify you of our need for additional time. For requests that we not sell your information we will comply with your request within 15 days after receipt of such request. We cannot respond to your request or provide you with Personal Information if we cannot verify your identity and confirm that the Personal Information relates to you. You may make a request for disclosure of our information collection practices, the information we collected about you, or our sharing practices up to twice within a 12-month period. You may make a request that we not sell information or for deletion of your information at any time. For requests for a copy of the Personal Information we have collected during the 12 months prior to your request we will endeavor to provide the information in a format that is readily useable, including by mailing you a paper copy or providing an electronic copy to your registered account, if you have registered an account with us. For requests for deletion of your information, please understand that California law permits us to retain certain information and not to delete it under certain circumstances. By way of example, we are not required to comply with a request to delete information if (1) the information is necessary for us to (a) complete a transaction for you or otherwise perform a contract; or (b) detect, protect against, or prosecute security incidents, fraud or illegal activity; (2) we use the information only internally in ways reasonably aligned with your expectations as our customer, and (3) we are required to retain the information to comply with legal obligations. If we receive such a request from you, we will notify any service providers we have engaged and provided your information to delete your information as well.
Using an Authorized Agent. You may submit a request through someone holding a formal ‘Power of Attorney’. Otherwise, you may submit a request using an authorized agent only if (1) the person is registered with the Secretary of State to do business in California, (2) you provide the authorized agent with signed written permission to make a request, (3) you verify directly with us that you have authorized the person to make the request on your behalf, (4) you verify your own identity directly with us, and (5) your agent provides us with proof that they are so authorized. We will require the agent to submit proof to us that they have been authorized to make requests on your behalf.
Categories of Information Collected. During the past 12 months we may have collected the following categories of information about California residents from the listed sources, used it for the listed business purposes and shared it with the listed categories of third parties. This includes information about visitors, users that have engaged a stylist, stylists, employees, vendors, suppliers, and any other person interacting with us either online or offline. Not all information is collected about individuals. For instance, we may collect different information from applicants for employment than from customers. Please see more information below:
|Categories of Personal Information That We Collect||To Whom We Disclose Personal Information for Business Purpose|
|Identifiers – this may include name, unique personal identifier, online identifier, IP address, device ID, email address or other similar identifiers.|
|Financial information – this may include bank account number, credit or debit card number, or other financial information.|
|Commercial information – this may include information about Services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.|
|Network activity data – this may include internet or other electronic network activity information, such as browsing history, search history, and information regarding an individual’s interaction with an internet website, application, or advertisement.|
European Union and United Kingdom
For more information on our practices and the European Union General Data Protection Regulation and United Kingdom General Data Protection Regulation, navigate to the bottom of our landing page at and refer to our “GDPR Notice”.
16. Contact Information