Privacy Policy
California Privacy Notice
Notice Of Financial Incentive
Virginia Privacy Notice
Information We Collect
Information you provide to us
We collect the personal information you provide to us when you purchase our products or visit our website. The categories of information we may collect include:
- Personal Identifiers, including name, email address, postal address, and telephone number
- Commercial and Financial Information, including purchases and credit card or debit card number
- Inferences, including inferences from other data
To the extent we process deidentified personal information, we will make no attempt to reidentify such data.
Information collected automatically
We automatically collect internet or other electronic information about you when you visit our website, such as IP address, browsing history and interactions with our website. We also collect geolocation data. This data may be collected using browser cookies and other unique personal identifiers.
Browser Cookies. We use cookies to create a better experience for you on our site. For example, cookies prevent you from having to login repeatedly, and they help us remember items you've added to your cart. We also use third-party cookies, which are cookies placed by third parties for advertising and analytics purposes. You can control these cookies through your browser settings.
Information from other sources
We may collect personal information about you from third-party sources, including Other consumers (e.g., referrals) and Retail Partners.
Other consumers (e.g., referrals)
- Personal Identifiers, including Name and Email address
Retail Partners
- Personal Identifiers, including Name, Email address, Postal address, and Telephone number
How long we keep your data
We do not retain data for any longer than is necessary for the purposes described in this Policy.
We generally retain data according to the guidelines below.
Type of Data | Retention Period |
---|---|
Cookies and online data we collect while you use our website, including Name, Email address, Online Identifiers, Internet Activity, Geolocation data | We delete or anonymize data concerning your use of our website within 7 years of collecting it. |
Data we collect in order to process and ship orders you place with us, including Name, Email address, Postal address, Telephone number, Purchases, Credit card or debit card number | We keep personal information related to products and services you purchase for as long as the personal data is required for us to fulfill our contract with you, and for 7 years from your last purchase with us. We may keep data beyond this period in anonymized form. |
Data we collect when you contact us for customer support and other inquiries, including Name, Email address, Postal address, Telephone number, Purchases, Credit card or debit card number, Inferences from other data | We keep customer feedback and correspondence with our customer service for up to 7 years to help us respond to any questions or complaints. We may keep data beyond this period in anonymized form. |
Data we collect when you sign up for promotional and marketing communications, including Name, Email address, Telephone number, Purchases, Inferences from other data | Where you have signed up to receive promotional and marketing communications from us, we will retain any data collected until you opt out or request its deletion. We may keep data beyond this period in anonymized form. We will further retain a record of any opt-outs in order to prevent sending you future communications. |
Data we collect when you review our products, answer surveys, or send feedback, including Name, Email address, Purchases | We retain review, survey, and feedback data for up to 7 years following your last contact with us. We may keep data beyond this period in anonymized form to help improve our products and services. |
Data we collect in connection with privacy requests, including Name, Email address, Postal address, Telephone number, Inferences from other data | We retain records related to privacy requests for a minimum of 24 months following the completion of the request. |
Data we collect for security purposes, including Name, Email address, Postal address, Telephone number, Online Identifiers, Internet Activity | We retain security-related data as long as necessary to comply with our legal obligations and to maintain and improve our information security measures. |
How we share and disclose information
Information Disclosed for Business or Commercial Purposes in the Last 12 Months, and Categories of Parties Disclosed To
We may disclose the following personal information about you when you purchase our products or visit our website:
Personal Information Disclosed | Recipient (by Category) |
---|---|
Personal Identifiers | Ad Networks, Business Operations Tool, Business Partners, Collaboration & Productivity Tools, Commerce Software Tools, Customer Support Tools, Data Analytics Providers, Governance, Risk & Compliance Software, Marketing Agency, Payment Processors, Sales & Marketing Tools, and Shipping Services |
Online Identifiers | Ad Networks, Commerce Software Tools, Data Analytics Providers, Marketing Agency, and Sales & Marketing Tools |
Internet Activity | Ad Networks, Business Partners, Commerce Software Tools, Data Analytics Providers, Governance, Risk & Compliance Software, Marketing Agency, Payment Processors, and Sales & Marketing Tools |
Commercial and Financial Information | Ad Networks, Business Operations Tool, Commerce Software Tools, Customer Support Tools, Data Analytics Providers, and Payment Processors |
Geolocation Information | Commerce Software Tools and Marketing Agency |
California Privacy Notice
This section provides additional information for California residents under the California Consumer Privacy Act (CCPA). The terms used in this section have the same meaning as in the CCPA. This section does not apply to information that is not considered "personal information," such as anonymous, deidentified, or aggregated information, nor does it apply to publicly available information as defined in the CCPA.
Collection and Disclosure of Personal Information
The personal information we collect is described above in Information we collect. The personal information we disclose for business or commercial purposes is described above in How we share and disclose information. The length of time for which we retain personal information is described above in How long we keep your data.
Business and Commercial Purposes for Collection
We collect personal information for the following business purposes:
- Conducting Surveys
- Creating Customer Profiles
- Data Storage
- Delivering Targeted Ads
- Fulfilling Customer Orders
- Meeting Compliance & Legal Requirements
- Operating our Website or Mobile Apps
- Organizing & Managing Data
- Preventing Fraud
- Processing Payments
- Providing Customer Support
- Sending Promotional Communications
- Tracking Purchases & Customer Data
We also "share" and "sell" (as defined in the CCPA) personal information for commercial purposes, including to advertise and market our products.
Information “Sharing” and “Selling”
We “share” certain personal information with third party ad networks for purposes of behavioral advertising, including: Commercial and Financial Information, Internet Activity, Online Identifiers, and Personal Identifiers. This allows us to show you ads that are more relevant to you.
We use third party data analytics providers and this may be considered a “sale” of information under the CCPA.
You may opt-out of these data practices here.
We do not knowingly sell or share (for cross-context behavioral advertising) the personal information of consumers under 16 years of age.
CCPA Rights
Your CCPA rights are described below. You can make a Request to Know or a Request to Delete under the CCPA by submitting a Privacy Request or by emailing us at CCPA@eczemacarecompany.com.
Right to Know
You have the right to request to know the following about the personal information we have collected about you in the past 12 months:
- the categories and specific pieces of personal information we have collected about you
- the categories of sources from which we collect personal information about you
- the business and commercial purposes for which we collect personal information
- the categories of third parties with whom we share the information
- the categories of personal information about you that we disclosed for a business purpose, and the categories of third parties to whom we disclosed that information for a business purpose
The information we would provide to you in response to a Request to Know Categories is contained in this Privacy Notice. To access the specific personal information we have about you, submit a Request to Know via the link above. If you make a Request to Know more than twice in a 12-month period, we may require you to pay a small fee for this service.
Right to Delete
You have the right to request that we delete any personal information about you that you have provided to us. We will permanently delete from our records any personal information that is not necessary for our business operations and direct our service providers to do the same.
We consider information to be necessary for our business operations if it is used to:
- Complete an obligation to you that you have requested
- Detect and resolve issues related to security or functionality
- Comply with legal obligations
- Enable solely internal uses
Right to Non-Discrimination
If you exercise your CCPA consumer rights:
- We will not deny goods or services to you
- We will not charge you different prices or rates for goods or services, including through the use of discounts or other benefits or penalties
- We will not provide a different level or quality of goods or services to you
Right to Opt-Out
You have the right to opt-out of any selling and sharing of your personal information.
You may exercise your right to opt-out here.
Opt-Out Preference Signals. Your browser settings may allow you to automatically transmit the Global Privacy Control (GPC) signal to online services you visit. When we detect such signal, we place a U.S. Privacy String setting in your browser so that any third party who respects that signal will not track your activity on our website. GPC is supported by certain internet browsers or as a browser extension. You can find out how to enable GPC here.
Right to Correct
You have the right to correct inaccuracies in your personal data, taking into account the nature of the data and our purposes for processing it.
Request Verification
Before we can respond to a Request to Know or Request to Delete, we will need to verify that you are the consumer who is the subject of the CCPA request. Verification is important for preventing fraudulent requests and identity theft. Requests to Opt-Out do not require verification.
Typically, identity verification will require you to confirm certain information about yourself based on information we have already collected. For example, we will ask you to verify that you have access to the email address we have on file for you. If we cannot verify your identity based on our records, we cannot fulfill your CCPA request.
For a request that seeks specific personal information, we ask that you sign a declaration stating that you are the consumer whose personal information is the subject of the request, as required by the CCPA.
In some cases, we may have no reasonable method by which we can verify a consumer's identity. For example:
- If a consumer submits a request but we have not collected any personal information about that consumer, we cannot verify the request.
- If the only data we have collected about a consumer is gathered through website cookies (i.e. the consumer visited our website but had no other interaction with us), we are unable to reasonably associate a requester with any data collected; therefore, we cannot verify the request.
Contact Us
If you have any privacy-related questions, please send them to CCPA@eczemacarecompany.com.
Notice Of Financial Incentive
Consumers who sign up for our marketing emails receive a 10% discount on their first purchase. A consumer provides their email address and/or text consents to receive emails in exchange for a discount provided via coupon code. To opt in, a consumer must enter their email address into the form and submit it. A consumer may unsubscribe from our marketing emails by using the unsubscribe link in the email footer at any time. We calculate the offer's value and financial incentive by using the expense related to the offer.
Virginia Privacy Notice
This section provides additional information for Virginia residents under the Virginia Consumer Data Protection Act (VCDPA). The terms used in this section have the same meaning as in the VCDPA. This section does not apply to information that is not considered "personal data," such as deidentified or publicly available information as defined in the VCDPA.
Collection and Disclosure of Personal Information
The personal data we collect is described above in Information we collect. The personal data we disclose to third parties and the categories of third parties to whom we disclose personal data is described above in How we share and disclose information. The length of time for which we retain personal information is described above in How long we keep your data.
Purposes for Processing
We process personal information for the following purposes:
- Conducting Surveys
- Creating Customer Profiles
- Data Storage
- Delivering Targeted Ads
- Fulfilling Customer Orders
- Meeting Compliance & Legal Requirements
- Operating our Website or Mobile Apps
- Organizing & Managing Data
- Preventing Fraud
- Processing Payments
- Providing Customer Support
- Sending Promotional Communications
- Tracking Purchases & Customer Data
Data “Selling” and Targeted Advertising
We process personal data for purposes of targeted advertising (as defined in the VCDPA), including online identifiers and internet activity. This allows us to show you ads that are more relevant to you.
You may opt-out of these data practices here.
Profiling
The VCDPA gives consumers the right to opt out of automated profiling that produces legal or similarly significant effects, such as approval for a loan, employment, or insurance.
We do not profile consumers in furtherance of decisions that produce legal or similarly significant effects.
VCDPA Rights
Your VCDPA rights are described below. You can make a Privacy Request or contacting us at CCPA@eczemacarecompany.com.
Right to Access
You have the right to confirm whether we are processing personal data about you and to access such data. Where processing is carried out by automated means, you have a right to receive a copy of your personal data in a portable and readily usable format that allows you to transmit your data to another controller.
If you make a Request to Know more than twice in a 12-month period, we may require you to pay a small fee for this service.
Right to Delete
You have the right to request that we delete any personal data provided by or obtained about you. We will permanently delete any such personal data from our records and direct our processors to do the same. However, we may retain your personal data if it is necessary for certain purposes, including the following:
- To comply with legal obligations
- To comply with an official investigation or cooperate with law-enforcement agencies
- To establish or defend legal claims
- To complete an obligation to you that you have requested
- To respond to security incidents, fraud, harassment, and other similar activity
- To identify and repair technical errors
- To conduct internal research to develop, improve, and repair our products and services
- For internal operations that are reasonably aligned with your expectations
Any personal data retained for these purposes will not be processed for other purposes.
Right to Non-Discrimination
If you exercise your VCDPA consumer rights:
- We will not deny goods or services to you
- We will not charge you different prices or rates for goods or services
- We will not provide a different level or quality of goods or services to you
However, we may offer a different price, rate, level, quality, or selection of products or services if your personal data is required in order to provide those products or services and you have exercised your right to opt out, or the offer is related to a voluntary loyalty or rewards program.
Right to Opt-Out
You have the right to opt-out of any selling of your personal data, processing of your personal data for purposes of targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects for you.
You may exercise your right to opt-out here.
Right to Correct
You have the right to correct inaccuracies in your personal data, taking into account the nature of the data and our purposes for processing it.
Right to Appeal
If we decline to take action in response to any of your privacy requests, you have the right to appeal that decision within a reasonable amount of time.
If you believe your rights have been violated and you are not able to resolve the issue directly with us, you may file a complaint with the Virginia Attorney General’s Office.