Effective as of May 22, 2018
At e.l.f. Cosmetics, Inc. (“e.l.f. Cosmetics,” or “we”), we believe in being clear and open about how we collect and use information related to you. In the spirit of transparency, this Privacy Notice provides information about the types of information we collect, how we use such information and to whom and under what circumstances we may disclose it.
This Privacy Notice applies to your use of our current websites (www.elfcosmetics.com and www.elfcosmetics.co.uk) as well as to any new websites or apps that we may offer as we expand our offerings (each are referred to as a “Site”). Please note that some provisions in this Privacy Notice only apply to www.elfcosmetics.co.uk or visitors that reside in the United Kingdom.
Information We Collect and How We Collect It
Information That You Give Us
We collect personal data from you when you submit it to us, including by:
- registering on the Site;
- placing an order;
- signing up for emails regarding special offers, products and services;
- contacting us (including by sending comments or leaving feedback);
- reviewing products; or
- participating in a Site promotion or survey.
The personal data you provide may include your name, email address, mailing address, billing address, telephone number, date of birth, and payment information. We may combine the personal data we collect from you with information we receive about you from other sources, such as address update services.
When and if permitted by applicable law (including any relevant data protection law), we may allow our Beauty Squad Loyalty Program members to provide us with their friends’ email addresses through our Beauty Squad Loyalty Program’s refer-a-friend feature, so that information about our products and promotions can be sent to those friends.
While we may collect personal data from you when you write a review on our Site, we do not ask for, and you should not enter, your full name anywhere in your review.
Please note that if you voluntarily submit any personal data for posting on the Site, such as a review or a blog post, the information becomes publicly available and can be collected and used by others, so you should use care before posting information about yourself online.
Information We Collect Automatically
When you visit the Site, we, and service providers acting on our behalf, may collect certain information from you, including your:
- Internet Protocol (IP) address;
- MAC address;
- browser type;
- operating system;
- device identifying information;
- the specific web pages visited during your connection;
- the domain name from which you accessed the Site; and
- your browsing behavior, such as the date and time you visit the Site, the areas or pages of the Site that you visit, the amount of time you spend viewing the Site, the number of times you return to the Site and other clickstream data.
We may also use non-personal or aggregated information for statistical analysis, research, and other purposes.
Cookies, Analytics and Traffic Data
Like many commercial websites, we analyze how visitors use the Site through cookies and other technologies, such as web beacons. A cookie is a small text file that is placed on your computer or device when you access the Site and allows us to recognize you each time you visit the Site. A web beacon is a tiny graphic that is used to collect information about your Site visit, such as the pages you view and the features you use, as well as information about whether you open and/or act upon one of our emails or advertisements.
We may combine the information we collect through cookies and web beacons with other information we have collected from you or information from other sources.
Certain cookies and web beacons that we employ are necessary for the operation of the Site. Other cookies that we employ are not necessary for the operation of the Site but are employed to enhance your use of the Site and shopping experience.
Our cookies may be session cookies (temporary cookies that identify and track users within the Site which are deleted when you close your browser or leave your session) or persistent cookies (cookies which enable the Site to “remember” who you are and to remember your preferences within the Site and which will stay on your computer or device after you close your browser or leave your session).
We use the following different types of cookies:
These are cookies which are needed for the Site to function properly, for example, these cookies allow you to access secure areas of our website or to remember what you have put into your shopping basket.
These cookies allow the Site to remember choices you make (such as your user name, language or the region you are in) and provide enhanced, more personal features. These cookies allow the provision of enhance functionality and personalization, such as chats. They may be set by us or by third party providers whose services we have added to our pages.
These cookies are set through the Site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant ads on other sites.
Performance, Analytics and Research
These cookies allow us to keep a record of traffic data, count visits, traffic sources, access rates, page hits and page views so we can measure and improve the performance of the Site. They help us know which pages are the most and least popular and see how visitors move to and from and around the Site.
You can find out more about the individual cookies and analytics technologies that we use here.
For more information on opting-out of cookie and web beacon tracking, please see the “Opting Out of Cookie Tracking” section.
For more information on our advertising, please see the “Interest-Based Advertising” section.
How We Use the Information We Collect
We primarily use the information that we collect to provide you with products, information, and services. Specifically, we may use the information we collect from, and about, you (including your personal data) for any of the following purposes:
- to fulfill your requests and orders for products;
- to respond to your inquiries;
- to operate, improve and optimize the Site, our business or our services;
- to review Site usage and operations;
- to address problems with the Site, our business or our services;
- to protect the security or integrity of the Site and our business;
- to notify you of new products, Site updates, newsletters and other informational and promotional materials from us and third-party marketing offers from our trusted partners, as well as from other companies;
- to enhance your shopping experience while on the Site;
- to comply with our legal obligations, resolve any disputes we may have with you or others, and to enforce our agreements with third parties; and
- to conduct research; and
- to provide interest-based advertising to you based on the way you browse and shop on the Site and other platforms.
If you do not wish to receive communications from us about special offers and promotions, please see the “Opting Out of Promotional Emails” section for more information about interest-based advertising, including how you can opt-out or manage advertising, please see the “Interest-Based Advertising” section and “Opting Out of Third-Party Tailored Advertising” section.
How We Share Your Information
We never sell your personal data to any third-parties, though we may share your personal data as indicated below.
With Your Consent
We may disclose information collected from, and about, you (including your personal data) with companies, organizations or individuals outside of e.l.f. Cosmetics with your express consent. We may share aggregate, non-personally identifiable information about Site users with third parties.
For External Processing
We may disclose information collected from, and about, you (including your personal data) with companies, organizations or individuals outside of e.l.f. Cosmetics to process it for us, based on our instructions and in compliance with this Privacy Notice and any other appropriate confidentiality and security measures. Such disclosures may be made (i) to companies, individuals, and service providers that host or operate the Site, analyze data, manage our Beauty Squad Loyalty Program, provide customer service, manage our product reviews, manage payments, or perform other business, professional or technical support functions for us, or (ii) to our marketing partners, advertisers or other third parties, who may contact you with their own offers.
For Legal Reasons
We may share information collected from, and about you (including your personal data) with companies, organizations or individuals outside of e.l.f. Cosmetics if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to:
- meet any applicable law, regulation, legal process or enforceable governmental request;
- respond to legal process (such as a search warrant, subpoena or court order);
- enforce our Terms of Service, including investigation of potential violations;
- detect, prevent, or otherwise address fraud, security or technical issues; or
- protect against harm to the rights, property or safety of e.l.f. Cosmetics, third parties, our customers, or the public as required or permitted by law.
In Connection with a Sale or Merger
If e.l.f. Cosmetics directly or indirectly undergoes a business transition (including proposed transactions), like a merger, acquisition by another company, or sale of all or part its assets, we may disclose or transfer information collected from, and about, you (including your personal data), to the successor organization in the transition. We will make reasonable efforts to let you and others know (in the way described in the “Changes to This Privacy Notice” section) if your personal data has been disclosed or transferred in connection with a business transition.
How Long We Keep Your Information
How long we retain your information depends on why we collected it and how we use it. We will not retain your personal data for longer than is necessary to fulfill the purposes for which it was collected or as required by applicable laws or regulations (unless otherwise agreed to by you and e.l.f. Cosmetics). For instance, we may retain some information for a few years after you have closed your account with us if this is necessary to meet our legal obligations or to exercise, defend or establish legal rights. Personal information that is no longer required to fulfill the identified purposes will be destroyed, erased or made de-identified.
How to Access, Update and Manage Your Information
Access, Correction, and Management
We respect your right to access, correct, and manage your personal data.
You may access your personal data by signing into your account. From there, you can correct, modify, or delete your information.
If you need assistance accessing, correcting, updating, or deleting your personal data or if you have questions about the collection of your personal data, please contact us using the contact information detailed in the “Contact Us” section.
California Privacy Rights
California law permits our customers who are California residents to request certain information about our disclosure of personal data to third parties for their own direct marketing purposes during the preceding calendar year. This request is free and may be made once a year.
To make such a request, please write to us at the following address:e.l.f. Cosmetics, Inc.
570 10th Street
Oakland, CA 94607
ATTN: Legal Department
RE: California Privacy Info
If you are under 18 years of age, reside in California, and have a registered account with us, you have the right to request removal of unwanted information that you publicly post on the Site. To request removal of such information, please contact us using the contact information detailed in the “Contact Us” section. Upon receiving such a request, we will make sure that the information is not publicly available on the Site, but the information may not be completely or comprehensively removed from our systems and databases.
How to Opt-Out of Certain Features
Opting Out of Promotional Emails
If you do not wish to receive communications from us about special offers and promotions, you can opt-out of receiving these communications by following the instructions contained in the messages you receive. Even if you opt-out of receiving these messages, we reserve the right to send you certain communications relating to the services we provide, and we may send you service announcements and administrative messages. We do not offer you the opportunity to opt-out of receiving those communications.
Opting Out of Third-Party Tailored Advertising
If you are interested in more information about tailored advertising and your choices to prevent third parties from delivering tailored web and mobile web advertising you may visit the following websites:
- Network Advertising Initiative Consumer Opt-Out Page;
- Digital Advertising Alliance Opt-Out Page for U.S.-based advertising; and
- Your Online Choices UK website for EU-based advertising
These opt-out tools are provided by third parties, not e.l.f. Cosmetics. We do not control or operate these tools or the choices that advertisers and others provide through these tools.
Opting Out of Cookie Tracking
You can your browser to reject cookies, warn you about attempts to place cookies on your computer or device, or limit the type of cookies you allow. You can also manually delete individual or all of the cookies on your computer or device by following your browser’s or device’s help file directions. Please note that browser- and device-management tools for cookies are outside of our control and we cannot guarantee their effectiveness. Please also note that flash cookies operate differently than browser cookies and cookie management tools available may not remove flash cookies.
If you are a visitor to www.elfcosmetics.co.uk, you may turn off cookies that are not necessary for the operation of the Site. You may turn off these cookies as follows
- if you have an account with us, you may access the privacy settings in the “My Account” section of the Site and choose the applicable setting; or
- if you don’t have an account with us, you may choose the applicable setting on the cookie notice that you are presented with upon first accessing the Site (you will need to end your session on the Site, close and then reopen your browser to be presented with the cookie notice again if you have previously accepted the cookies).
Please note that if you turn off cookies that are not necessary for the operation of the Site, your browser or device is set to reject cookies, or you manually delete cookies, some or all of the features and functionality of the Site may not function properly (including features we may add to the Site in the future).
Interest Based Advertising
We may use third-party advertising companies that use tracking technologies to serve our advertisements across the Internet. These companies may collect information about your visits to the Site and other websites and your interaction with our advertising and other communications. These advertising companies serve ads on behalf of us and others on non-affiliated sites, and some of those ads may be personalized, meaning that they are intended to be relevant to you based on information collected about your visits to this Site and elsewhere over time. Other companies may also use such technology to advertise on our Site.
Security of Your Information
We maintain reasonable and appropriate measures designed to maintain information we collect in a secure manner. We have taken certain physical, electronic, and administrative steps to safeguard and secure the information we collect from Site visitors. Even though we follow reasonable procedures to try to protect the information in our possession, no security system is perfect and we cannot promise, and you should not expect, that your information will be secure in all circumstances.
Our Policies Concerning Children
The Site is not directed to children, nor do we knowingly collect any personal data from, children under the age of 13 without verifiable parental or legal guardian consent. If you believe that a child has provided personal data to us, please promptly contact us using the contact information detailed in the “Contact Us” section, and we will endeavor to investigate and delete such information from our systems.
California Online Privacy Protection Act Notice
There is currently no consensus among industry participants as to what “Do Not Track” browser signals mean and how to respond to “Do Not Track” browser signals (you can learn more about Do Not Track here). As such, we do not respond to such signals. Instead, to opt-out of cookie and web beacon tracking, please see the “Opting Out of Cookie Tracking” section, or to opt-out of website-based third-party interest-based or online behavioral advertising, please see the “Opting Out of Third-Party Tailored Advertising” section.
Third Party Websites
Visitors from Outside the United States—Cross-Border Transfer
The Site is hosted in the United States. If you are visiting the Site from outside the United States, your information may be transferred to, stored in, and processed in, the United States or any other country where e.l.f. or its affiliates, subsidiaries, or third-party service providers maintain facilities. UK customers who provide personal data to us consent to their personal data being transferred to, stored in, or processed in the United States and around the world.
Where we transfer, store, and process your personal data outside of the European Economic Area, we have ensured that appropriate safeguards are in place to ensure an adequate level of data protection. This may include executing agreements with third-parties regarding the transfer, storage, or process, of personal data outside of the European Economic Area using European Commission-approved Standard Contract Clauses and/or employ additional appropriate safeguards.
The data protection and other applicable laws of the United States or other countries may not be as comprehensive as those laws or regulations in your country or may otherwise differ from the data protection or consumer protection laws in your country. Your information may be available to government authorities under lawful orders and law applicable in such jurisdictions. By using the Site and/or providing personal data to us, you consent to transfer, storage, and processing of your information as described in this Privacy Notice.
Right to Lodge Complaints
We are transparent about the ways in which we collect and use personal data, and welcome your questions and concerns. If you have any concern or complaint about the way we handle your personal data, please contact us as described below.
To the extent you believe we have not addressed your concerns or otherwise choose to do so, you have the right to lodge a complaint with a supervisory authority in the country where you reside and/or the United States. Within the United States, you may contact the US Federal Trade Commission regarding your concerns. For more information, please see https://www.ftc.gov/faq/consumer-protection/submit-consumer-complaint-ftc. Within the United Kingdom, you may obtain more information about how to protect your rights and lodge a complaint by contacting the United Kingdom Information Commissioner’s Office, see https://www.gov.uk/data-protection/make-a-complaint.
General Data Protection Regulation Notices
e.l.f. Cosmetics, Inc. is the controller of your personal data provided to, or collected by or for, or processed in connection with, your use of the Site. Please see the “Visitors from Outside the United States—Cross-Border Transfer” section for more information about the transfer of your personal data to the United States or other countries. Contact information for e.l.f. Cosmetics, Inc. can be found in the “Contact Us” section.
The address for e.l.f. Cosmetics, Inc. ise.l.f. Cosmetics, Inc.
570 10th Street
Oakland, CA 94607
Legal Bases for Processing, Use, and Storage
We (or service providers engaged on our behalf) use, process, and store your personal data, including the date listed in the “Information We Collect and How We Collect It” section:
- with your consent (for example, you may provide us with your email address for promotional emails or write a review of our products);
- for the pursuit of our legitimate interests (for example, performing the contract for the sale of our products to you (processing payment information, shipping products to you, etc.), handling customer contacts, queries, complaints or disputes, providing reviews of our products on the Site, etc.); and
- in connection with establishing, exercising or defending legal claims.
When we process your personal data based for the pursuit of our legitimate interests, we don’t believe that our interests are overridden by your interests or fundamental rights or freedoms which require protection of personal data. We believe our processing of your personal data helps us offer you a more personal and enhanced customer experience.
In some limited cases, we may process your personal data to protect your vital interests or those of another person.
GDPR Privacy Rights
The General Data Protection Regulation requires that we inform our U.K. users about certain specific rights:
- The General Data Protection Regulation requires that we inform our U.K. users about certain specific rights:
- the right to object, for legitimate purposes, to the processing of personal data;
- the right to request copies of your personal data held by us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible);
- the right to request that we delete your personal data; and
- the right to lodge a complaint with a supervisory authority.
If you wish to withdraw your consent, please follow the applicable procedure in the “How to Opt-Out of Certain Features” section or, if not addressed, please contact us using the contact information detailed in the “Contact Us” section. Please note that if you withdraw consent, we may not be able to provide or continue to provide certain services or marketing communications to
Objection and Requests for Copies
If you wish to (i) object, for legitimate purposes, to the processing of personal data as provided under applicable law, or (ii) to request copies of your personal data held by us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible), please write to us at the following address:e.l.f. Cosmetics, Inc.
570 10th Street
Oakland, CA 94607
ATTN: Legal Department
RE: GDPR Privacy Info
Requests for Deletion
If you wish to request that we delete your personal data, please click here and fill in the “Contact Us” Form (please enter your name and email address and select “Delete My Information” for the My Question field). We will promptly send you a verification email (to the email address provided to us in the “Contact Us” Form) to ensure that the request was not made in error. We will respond to your request to delete your information within one month of receipt of your verification. Our response period may be extended by 60 additional days where necessary, taking into account the complexity and number of requests we receive. We may need to retain certain records, for example those relating to open orders, payments, or customer service matters, for legal and accounting purposes. Please note that if you are a member of our Beauty Squad Loyalty Program and you request that your personal data is deleted, you may be removed from our Beauty Squad Loyalty Program.
Please note that if you make a data deletion request, you must enter in the “Contact Us” Form the email address that you have linked to your account (or that you used in connection with aa purchase) for us to delete your personal data as we link your personal data to your email address. If you have multiple email addresses linked to your account (or you used multiple email addresses in connection purchases) you may need to make a data deletion request with respect to each email address in order for us to fully delete your personal data.
If you wish to lodge a complaint with a supervisory authority, please follow the applicable procedure in the “Right to Lodge Complaints” section.
Existence of Automated Decision-Making
We may use automated decision-making processes to personalize the Site to enhance your shopping and consumer experience on the Site (for example, by recommending certain products to you) or, if you have opted into receiving promotional material from us, to send you personalized promotional emails. We do not believe any of these automated decision-making processes will produce legal effects concerning our users or similarly significantly affects our users.
Changes to This Privacy Notice
We may change this Privacy Notice from time to time, including as required to keep current with rules and regulations, new technologies and security standards. When we do, we will post the change(s) on our website. If we change this Privacy Notice in a material manner, we will provide appropriate notice to you. If you wish to review a copy of the privacy notice effective prior to the effective date of this Privacy Notice, please contact us using the contact information detailed in the “Contact Us” section.
If you have questions or concerns about this Privacy Notice or how we collect and use the information of our customers, please contact us here.
If we need, or are required, to contact you concerning any event that involves your information, we may do so by email, telephone, or mail.