[Last Updated and Effective as of January 1, 2020]
Categories of Personal Information We Collect
- Information You Voluntarily Provide:
Categories of personal information we collect that you voluntarily provide may include your name, shipping/billing address, telephone number, email address, social media user name, credit card or other payment information, birth date, gender, personal interests, purchase history, beauty and skin/hair care preferences and other information (collectively, “Personal Information”). We receive information you provide to us when you: (1) create an account with us (including a shopping
account online, an account to review products, a customer loyalty account or any other type
of account); (2) make a purchase; (3) contact us via any customer service method; (4) subscribe for email, text, or other messages; (5) participate in customer research, surveys, sweepstakes or promotions; (6) submit user-generated content via the Website or Services; (7) apply for employment opportunities; (8) work with our associates who provide you with in-store or online Services or otherwise assist you with your product needs and purchases; (9) download or use our Website; or (10) otherwise communicate information to us. The business purposes for which we collect this information is to enable you to purchase or order a product, subscribe to a Service, register to receive emails or newsletters, join our VIP or other loyalty program, participate in a survey, submit a product review or register for a contest, sweepstakes or promotion or otherwise engage with our Services.
If you choose not to provide Personal Information to us, you may be unable to purchase products, take advantage of offers and content on our Website or otherwise access certain aspects of the Services.
- Information Collected from Third Parties:
We may receive information you provide on behalf of third parties, or third parties provide on your behalf, including but not limited to gift recipients, online registrations/purchases, or in-store pick-up. We also may acquire information about you from third parties with whom we have a relationship or otherwise contract with to obtain such information where such third parties have been duly authorized to share such information in accordance with applicable data protection laws. In the event we acquire a business, we may receive information from the seller of such business. Additionally, we may receive information from various consumer reporting agencies and related service providers.
- parties, such as partners, sponsors or advertisers whose services are promoted or advertised in connection with the Services may request that you provide personal information in order to participate in such offers.
- may combine such third-party data with other information we receive from or about you. L’Occitane may share your Personal Information with third-party partners and may collect Personal Information about you that L’Occitane receives from other sources when you have authorized us to do so or where permitted by applicable laws.
- Information Collected Through Automated Means:
We automatically receive and store certain types of information when you interact with our Website and our Services. The business purpose behind the collection of such automated information is to help make the Website operate more efficiently and to provide analytical information about marketing campaigns. Categories of personal information that we may automatically collect when you use the Services include the Internet Protocol address used to visit the Website along with other electronic markers, identifiers and information about your use of the Services, such as cookies and web beacons. Among the business purposes for which we collect such information is to analyze this data for preferences, trends, Website-usage statistics and to recognize you on return visits. Other information collected through automated means may encompass usage data from your mobile phone or any other device you use to access the Services, including location data if you have provided express consent, which we may also combine with other information about you in order to enhance your experience using the Website and Services.
- may use some technologies (collectively, “Tracking Technologies”), to gather Personal Information and non-personal information (which is any information that does not reveal your specific identity) automatically (or passively) whenever you visit or interact with the Services. Some of the Tracking Technologies we use include:
- IP Address Tracking and Clickstream Data - In addition to cookies, our servers automatically collect data about your server’s Internet address when you visit our Website. This information, known as an Internet Protocol address, or “IP Address”, is a number that is automatically assigned to your device by your Internet service provider whenever you are on the Internet. When you view pages from our Website, our servers may record or “log” your IP Address and sometimes your domain name. Our server also may record the page that linked you to us and related information including any ads you may have clicked on. Such information is known as “Clickstream Data”.
- Device Information - We also automatically collect an IP address or other unique identifier information ("Device Identifier") for the computer, mobile device, technology or other device (collectively, "Device") you use to access the Website, Services or on third-party websites that publish our advertising. A Device Identifier is a number that is automatically assigned to your Device when you access a website or its servers, and our computers identify your Device by its Device Identifier. For mobile devices, a Device Identifier is a unique string of numbers and letters stored on your mobile device that identifies it. We may collect certain, non-personal information about the Device you use to access the Services, including but not limited to IP addresses for your Devices, Device identifiers, browser types, browser language and other transactional information that does not personally identify you to, among other things, administer the Website, help diagnose problems with our servers, analyze trends, track users’ web page movements, help identify you and your shopping cart, deliver advertising and gather broad demographic information as well as for fraud prevention purposes.
- User History - L’Occitane may log and use certain usage information about your use of the Services, which may include a history of the Website pages you view, store visits, browsing and transaction history for the business purposes of evaluating the effectiveness of marketing and promotions and to improve your experience with the Website.
- Mobile/Location Information - We may collect additional information from you if you access the Services through a mobile device, for example your unique device identifier, device’s operating system, mobile carrier, or location when you opt in for us to do so. However, the degree to which your location can be identified depends on the device you are using (e.g., laptop, smartphone, tablet) and how you are connected to the internet (e.g., via cable broadband connection, Wi-Fi, etc.). If you enable location services for the online Services, we may collect geo-location data periodically as you use or leave open the Services and provide location-based content and services. We also may collect your location information from your IP address or zip code. We also may use location data internally or in conjunction with our third-party service providers to customize your experience and provide offers that may be relevant to you. Depending on the platform you use to access the online Services (e.g., Apple™ iOS, Google™ Android, Windows, etc.), you may be able to control from within the settings on your wireless Device whether location data is collected.
- In-Store Analytics - We may use certain in-store wireless services to automatically collect non-identifying information about visitors to our stores. If you utilize our Wi-Fi routers in our stores, please note they may capture certain data from mobile devices that interact with the router, including information about your mobile device. Data collected from these in-stores wireless services may be used to provide information about customer flow and visitor demographics.
- Email Interconnectivity - If you receive email from us, we may use certain tools, such as pixels, to capture data related to whether and when you open our emails, click on any links or banners it contains and make purchases. The business purposes are to improve our message content and frequency and gauge your interest in hearing from us.
- Turning Off Tracking Technologies. You can choose to have your computer warn you each time a persistent or session cookie is being sent, or you can choose to turn off such cookies through your browser settings. Each browser is a little different, so look at your browser’s Help menu to learn the correct way to modify your cookies. However, cookie management tools provided by your browser will not remove Flash cookies. To learn how to manage privacy and storage settings for Flash cookies, please click here. It is important to remember that many of L’Occitane’s services may not function properly if your cookies are disabled.
- Network Advertising Initiative. Some of our advertising service providers may be members of the Network Advertising Initiative, which offers a single location to opt out of ad targeting from member companies. However, if you opt-out of receiving targeted ads in this manner, you will continue to receive advertising messages from us after you opt-out, but other members of the Network Advertising Initiative will not be able to target you based on your use of the Services and/or third-party websites. If you would like more information about advertisers’ use of tracking technologies and about your option not to accept these cookies, please click here. If you would like to learn more about how personalized information is collected and to know your choices about not having information used in this manner, please click here.
- “Do Not Track” Signals. You may set your web browser software to reject Tracking Technologies, but, if you do so, certain functionality of the Website may be affected. Moreover, due to the lack of uniformity in the standard for “do not track” signals, we do not act upon or respond to browser “do not track” signals or other similar mechanisms. Go to here or here if you wish to learn more about your options to not accept tracking cookies for the purpose of receiving targeted personalized advertisements. Please note that the-opt out is cookie-based and will only affect the specific computer and browser on which the opt-out is applied.
- Third Parties. We also work with third parties to provide certain functionalities on the Services and to improve the effectiveness of the Services and its content. Separate and distinct from information L’Occitane shares with third parties, third-party companies also may use Tracking Technologies to independently collect and store information about you and your usage of the Services and may combine this information with information they collect from other sources. Please note, we do not control Tracking Technologies used by third parties, and their use may be governed by the privacy policies of the third parties employing the Tracking Technologies.
WHAT DOES L’OCCITANE DO WITH THE INFORMATION IT COLLECTS?
L’Occitane uses Personal Information and non-personal information that it collects from you and about you for the purposes described below. For the avoidance of doubt, L’Occitane may use and disclose non-personal information for any purpose, except where L’Occitane is required to do otherwise under applicable law. If L’Occitane is required to treat non-personal information as Personal Information under applicable law, then L’Occitane may collect, use and disclose it for all the purposes for which L’Occitane collects, uses and discloses your Personal Information. L’Occitane shares customer information with service providers that perform services on its behalf for business purposes pursuant to written agreements and instructions specified by L’Occitane. By using the Website and other Services, you consent to our use of your Personal Information and non-personal information to target advertising to you. L’Occitane may use the information collected from one portion of the Services on or in connection with other portions of the Services, and L’Occitane may combine information gathered from multiple portions of the Services into a single record. L’Occitane also may use or combine information that L’Occitane collects offline or from third-party sources with your information collected from or through the Services. Additionally, data collected from a particular browser or Device may be used with another computer or Device that is associated with the browser or Device on which such data was collected or transferred to a third party who may be able to track your activity across Devices. L’Occitane may use this Personal Information and non-personal information for the following business purposes:
- Enable Usage: L’Occitane uses the Personal Information it gathers about you to enable and enhance your use of L’Occitane’s products and Services, including but not limited to accessing the Services, receiving emails and newsletters, registering for our VIP or other loyalty programs, purchasing products, receiving promotions, participating in forums, surveys and sweepstakes and receiving requested products and services.
- Data Enhancement: Where authorized under applicable laws, L’Occitane may acquire information from other trusted sources to update or supplement the information that you provided or we collected automatically, such as information to validate or update your address or other Personal Information.
- Customizing Your Experience with the Services: L’Occitane uses the information that it collects and acquires to customize your user experience with the Services, including delivering content to you that we think would be most relevant and of interest to you and providing you with an enhanced experience based on the type of Device you are using.
- Advertising. We use third-party ad servers and ad networks that use Tracking Technologies to collect information about your visits on other services and when you access the Services to send you targeted advertisements. They automatically receive your IP address or Device Identifier when this happens. They also may use Tracking Technologies to measure the effectiveness of advertisements and to personalize the advertising content and to serve you relevant advertisements. We also may use information collected using third-party cookies and beacons on the online Services and in our emails to deliver advertising about the Services displayed to you on third-party services. These cookies allow us to understand how you clicked to our Website and what pages you visit or click on during your visit to our Website. Understanding how you shop allows us to improve and personalize your shopping experience and speed your checkout process. We may use technologies such as cookies to provide you with enhanced online display advertising tailored to your interests. Google is one of the companies that we use to serve advertising and perform analytics on some of the online Services. We and our third-party vendors, including Google, may use a variety of technologies that passively or automatically collect information about how the Services are accessed and used ("Usage Information"), including but not limited to your browser type, device type, IP address, operating system, application version, the pages served to you, the time you browse, preceding page views, products you viewed or searched for, page interaction information (such as scrolling and mouse-overs) and your use of features or applications on the Website and otherwise as part of the Services to report how our ad impressions, other uses of ad services, and interactions with these ad impressions and ad services are related to your visits to the Website and use of the Services. To learn about Google Analytics’ currently-available opt-outs for the Web, click here.
- Google Features and Remarketing. Google is one of the companies that we use to serve advertising and perform analytics on some of the online Services. We also use companies like Facebook, Twitter, Instagram, Pinterest, as well as other third parties to help us engage with our customers across different platforms and channels, including for the purpose of targeting advertising toward you. We and third-party vendors, including Google, use first-party cookies created by the site you visit and third-party cookies created by other sites that own some of the content, like ads or images, you see on the webpage you visit to help implement the above uses of your information. We also use remarketing with Google Analytics (including Universal Analytics) and/or Google AdWords (collectively, “Remarketing”) to advertise online including after you've visited our Website. Remarketing may be based on your interests, location and other information collected about you in compliance with Google’s privacy policies. When ad personalization is on, you can choose any info – age and gender, an inferred interest, or a previous interaction with an advertiser – learn more about why it’s being used, turn it off, or deactivate personalized ads altogether. You can opt out of receiving personalized Google ads, or customize the ads Google shows you, by clicking here. You’ll still see ads, but they’ll most likely be less relevant.
- Statistical Analysis: L’Occitane may perform statistical, and marketing analyses of user behavior for a variety of purposes, such as to measure interest in the various areas of the Website and Services and L’Occitane products, to better understand purchasing patterns for marketing purposes. L’Occitane also uses third parties to provide L’Occitane with information, reports and analysis about the usage and browsing patterns of users of L’Occitane products and Services. Such third parties track and analyze non-personally identifiable usage and volume and statistical information about L’Occitane visitors and customers with respect to the Services and track and analyze anonymous usage and browsing patterns of users of the Services.
- Account Maintenance and Service Updates: L’Occitane may utilize the contact information you provided at registration, such as your telephone number, mailing address and email address, to contact you regarding your account, your subscriptions and other products or services that you have requested or in which you are currently enrolled. These may include order confirmations, notifications about credit card issues, security issues and information about L’Occitane products.
- Emails you send to us: If you send L’Occitane emails, you should be aware that any information provided in an email may not be secure or encrypted and therefore may be available to others. Please exercise caution if you decide to disclose any personal or confidential information in such email, and please be advised that you should not provide detailed credit card information directly to L’Occitane via an unsecure form (such as email). By emailing L’Occitane, you agree that L’Occitane representatives may use your email address to respond to any of your questions or comments.
WITH WHOM DOES L’OCCITANE SHARE THE PERSONAL INFORMATION IT COLLECTS?
L’Occitane may share Personal Information that you provide with select third parties and service providers for certain purposes, such as the following:
- Service Providers. We may contract with companies or persons to provide certain services including credit card processing, shipping, customer service, data analysis and management, promotional, marketing and research services, loyalty program administration, gift card management, administration of surveys and sweepstakes, marketing, detecting fraud or theft, and other services. We provide these service providers with the information necessary for them to perform these services for business purposes pursuant to written agreements and instructions specified by L’Occitane.
- Mobile Carriers. If you access the Services through a Device or app, we also may share your information with mobile carriers, operating systems and platforms.
Personal information about you may be shared, regardless of your “opt-out” status, in the following instances:
SOCIAL MEDIA SERVICES:
When you log into the Website through your social media accounts, link your social media accounts with the Services or engage with Services through third-party social media platforms, you understand that you may be allowing us ongoing access to certain information stored on those platforms. In addition, as you interact with the Services, you also may be providing information about your activities to the third-party social media platforms, as applicable. You should make sure that you are comfortable with the information such services may make available to us by visiting the applicable platforms’ privacy policies and/or modifying your privacy settings directly with those platforms.
LINKS TO OTHER WEBSITES
PROTECTION OF YOUR INFORMATION
To prevent unauthorized access, maintain data accuracy, and ensure the appropriate use of information, L’Occitane has put in place appropriate physical, electronic, and managerial procedures to protect the information L’Occitane collects online. Please understand, however, that while we try our best to safeguard your personally identifiable information once we receive it, no transmission of data over the Internet or any social media or other public network can be guaranteed to be 100% secure.
You need to help protect the privacy of your own information, including maintaining the confidentiality of any account information or access credentials. You must take precautions to protect the security of any personally identifiable information that you may transmit over any public or untrusted network by using encryption and other techniques to prevent unauthorized persons from intercepting or receiving any of your personally identifiable information. You are responsible for the security of your information when using unencrypted, open access, public or otherwise unsecured networks.
A SPECIAL NOTE ABOUT CHILDREN AND NON-U.S. USERS
Our Website and Services are not directed to children under the age of thirteen (13), and we do not knowingly collect Personal Information from children under the age of 13. We do not sell consumer Personal Information. Please contact us if you believe we may have collected information from your child through our Website or mobile services and we will work to delete it.
CALIFORNIA PRIVACY RIGHTS
If you are a California resident, the California Consumer Privacy Act of 2018 (“CCPA”) grants you the right to request that we disclose to you, upon our receipt from you of a verifiable request, the following:
(1) The categories of Personal Information we have collected about you.
(2) The categories of sources from which the Personal Information is collected.
(3) The business or commercial purpose for collecting or selling Personal Information.
(4) The categories of third parties with whom we share Personal Information.
(5) The specific pieces of Personal Information we have collected about you.
We do not sell consumer Personal Information. We may from time to time disclose consumer Personal Information for a business purpose, such as operational purposes, or other notified purposes, that are reasonably necessary and proportionate to achieve the operational purpose for which the Personal Information was collected or processed or otherwise is compatible with the context in which the Personal Information was collected.
If you are a California resident, you have the right to request that we disclose to you, upon our receipt from you of a verifiable request, the categories of Personal Information that we have disclosed about you for a business purpose.
If you are a California resident, you also have the right under the CCPA to request the deletion of your Personal Information that we collect. All such requests are subject to verification according to methods determined by us. You may submit a request for the deletion of your Personal Information by sending an email to us.
Even though we do not sell consumer Personal Information, if you are a California resident, you also have the right under the CCPA to opt-out of the sale of your Personal Information. All such requests are subject to verification according to methods determined by us. You may submit an opt-out request by sending an email to us or by clicking the “Do Not Sell My Info Request – California Residents” link on the Website.
Upon our receipt of a request by a California resident to exercise rights under the CCPA, we first must verify that the person making a request is the consumer about whom we have collected information. Accordingly, we will ask you to confirm your date of birth and postal address, and we also may request a copy of your valid government-issued identification.
You have the right not to receive discriminatory treatment for the exercise of the privacy rights conferred by the CCPA. However, nothing prohibits us from charging a consumer a different price or rate, or from providing a different level or quality of goods or services to the consumer, if that difference is reasonably related to the value provided to the consumer by the consumer’s data.
You may exercise any of the California Privacy Rights described in this section by sending such a request to us by email. We may ask you to verify your identity before taking further action on your request. Consistent with California law, you may designate an authorized agent to make a request on your behalf. In order to designate an authorized agent to make a request on your behalf, you must provide a valid power of attorney, a copy of your valid government-issued identification and your authorized agent’s valid government-issued identification.
Please note that we are not required to comply with a California resident’s request to delete Personal Information if it is necessary for us to maintain the Personal Information in order to:
(1) Complete the transaction for which the Personal Information was collected, provide a good or service requested by the consumer, or reasonably anticipated within the context of our ongoing business relationship with the consumer, or otherwise perform a contract between us and the consumer.
(2) Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity.
(3) Debug to identify and repair errors that impair existing intended functionality.
(4) Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law.
(5) Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code.
(6) Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when our deletion of the information is likely to render impossible or seriously impair the achievement of such research, if the consumer has provided informed consent.
(7) To enable solely internal uses that are reasonably aligned with the expectations of the consumer based on the consumer’s relationship with us.
(8) Comply with a legal obligation.
(9) Otherwise use the consumer’s Personal Information, internally, in a lawful manner that is compatible with the context in which the consumer provided the information.
If you are a California resident under 18 years old and a registered user on the Website, you can request that we remove content or information that you have posted to our Website or other online services. Note that fulfilment of the request may not ensure complete or comprehensive removal (e.g., if the content or information has been reposted by another user). To request removal of content or information, please call 866-464-3358 or email such request to UScustomerservice@erborian.com. If you would like to mail your request, please direct it to:
Attn: Legal Department
111 West 33rd Street, 20th Floor
New York, NY 10120
We will begin to process your request within 30 days of our receipt.
NEVADA PRIVACY RIGHTS
For Nevada residents, please note that we do not sell personal information as defined by Nevada law. Nevertheless, you have the right to submit a request directing us not to sell any of your personal information. To request email confirmation that we do not sell your personal information, please email your request to us at UScustomerservice@erborian.com and specify in the subject line: Nevada Privacy Information Request.
OPTING-OUT, CORRECTIONS AND CANCELLATIONS
To opt out of receiving marketing emails from us, follow the unsubscribe instructions located near the bottom of each email, or email your unsubscribe request to UScustomerservice@erborian.com. For the avoidance of doubt, it is important to understand that this opt-out shall not prohibit any disclosures made for non-marketing purposes.
Please note that even if you opt out of receiving marketing emails, we may continue to send you such communications by direct mail unless you opt out of direct mail, as specified below.
L’Occitane collects postal mailing address information from you so that L’Occitane may fulfill the orders you submit and to inform you of L’Occitane programs, products and services in which you may be interested. You have the right to opt out of receiving postal mailings from L’Occitane. If you do not wish to receive postal mailings, including printed offers, from L’Occitane in the future, please send an email to UScustomerservice@erborian.com or write to us at the address listed below.
Attn: Legal Department
111 West 33rd Street, 20th Floor
New York, NY 10120
If you have any questions or concerns about our privacy policies and practices, you may contact customer service by clicking here.