Company
Privacy Policy
Grande Cosmetics® Privacy Policy
Last updated: 11.14.24
Thank you for using Grande Cosmetics’ website. We are committed to protecting your privacy and, for that reason, we have adopted this Privacy Policy to explain our data collection, use, and disclosure practices for the Grande Cosmetics services (including any Grande Cosmetics website, and mobile and web-based applications, and any other tools, products, or services provided by Grande Cosmetics that link to or reference this Privacy Policy) (collectively, the “Services”). The Services are owned and operated by Grande Cosmetics, LLC, a New York limited liability corporation (“Grande Cosmetics,” “we,” “us” or “our”).
By accessing or using our Services, you agree that your visit and any dispute over our online privacy practices is governed by, applicable law, this Privacy Policy, and our Terms and Conditions of Use. Our Terms and Conditions of Use is hereby incorporated into this Privacy Policy by reference.
YOU ACKNOWLEDGE AND AGREE THAT OUR Terms and Conditions of Use CONTAINS A BINDING ARBITRATION PROVISION IN SECTION 19 THAT AFFECTS YOUR RIGHTS UNDER THIS PRIVACY POLICY TERMS WITH RESPECT TO THE SERVICES.
If you reside in the State of California, please click here to learn more about your privacy rights. To the extent that there is a conflict between this Privacy Policy and the Privacy Notice for California Residents, the Privacy Notice for California Residents will prevail with respect to California Residents (as defined below) only.
If you reside in a country in the European Economic Area or in Switzerland, please click here to learn more about your privacy rights. To the extent that there is a conflict between this Privacy Policy and the Privacy Notice for European Residents, the Privacy Notice for European Residents will prevail with respect to European Residents (as defined below) only.
This Privacy Policy applies to information Grande Cosmetics collects through the Services, as well as other information provided to us online or offline by third parties, when we associate that information with customers or users of the Services; however, it does not apply to information collected from our employees, contractors, or vendors. It also does not apply to information that you ask us to share with third parties or that is collected by certain other third parties whose software or services are featured or included in the Services (as further described below).
This Privacy Policy describes, among other things:
- Personal and other information we collect about you;
- How we use your information;
- How we may share your information with third parties; and
- Your choices regarding the personal information we collect about you.
1. Consent
By accessing or using the Services, you consent to this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Services. Information gathered through the Services may be transferred, used, and stored in the United States, Canada or in other countries where our service providers or we are located. If you use the Services, you agree to the transfer, use, and storage of your Personal Information (as defined below) in those countries. The data protection and other laws of the United States, Canada and other countries might not be as comprehensive as those in your country. You agree that all transactions relating to the Services or Grande Cosmetics are deemed to occur in the United States, where our servers are located.
2. Collection of Your Personal and Other Information
When you register for or use our Services, including when you participate in or enroll in our loyalty program, we collect Personal Information. By “Personal Information” we mean information that can identify or reasonably be linked to an individual, such as:
- Names;
- Personal or business addresses;
- Email addresses;
- Birth date;
- Phone number;
- Credit card or debit card information (which you submit for payment purposes and which is collected by our third party payment gateway service providers (Shopify, Afterpay, Authorize.net, and Klarna)
- Information contained in any image, photograph or profile you submit to us.
Our Services may integrate with social media platforms, including Meta, Instagram, TikTok, X Corp., Snapchat, and Pinterest. When you connect a social media account to our Services, then we may collect information about that social media account and share information with that social media account as described in the connection process. This collected information may include, but is not limited to, your name, email address, demographic information from your profile, friend lists, postings or other content, and your profile picture. You acknowledge and agree that Grande Cosmetics is not responsible for the data collection or use practices of any such connected social media platform. You should read each social media platform’s privacy policy before connecting that social media account.
We also may use technology from our third-party service provider to collect user experience recordings, which include a graphical representation of your interactions with the Services, including mouse movements, page scrolling, and information you type (including Personal Information). Reproduced data may include technical and usage data, as well as visual representations of actions you take while using the Services. We use these recordings to help us understand how users interact with our Services and to design a better user experience for you.
You may choose not to provide Personal Information, (subject to the controls offered by your mobile device’s operating system), but this may prevent you from receiving certain features of the Services.
We also collect non-Personal Information relating to the Services, that is, information that does not personally identify an individual. The non-Personal Information we collect includes how you interact with the Services, information generally collected or “logged” by Internet websites or Internet services when accessed or used by users, and information about your web browser or device accessing or using the Services.
Examples of the non-Personal Information we collect are:
- The pages of our website that you viewed during a visit;
- What information, content or advertisements you view or interact with using the Services;
- Language preferences;
- The city and state in which you are located (but not your precise geographic location); and
- Unique identifiers that are not connected and cannot reasonably be connected to your identity.
We will not use non-Personal Information to try to identify you, and if we associate any non-Personal Information with information that personally identifies you, then we will treat it as Personal Information. As discussed in more detail below, we sometimes use cookies and other automatic information gathering technologies to gather Personal Information and non-Personal Information.
Information collected by the Services may be collected by us or one of the third parties we utilize in providing the Services (as further described below).
3. Use of Your Information
We may use the information we collect to:
- Assist us in providing, maintaining, and protecting the Services;
- Set up, maintain, and protect accounts to use the Services;
- Improve our online operations;
- Process transactions;
- Provide customer service;
- Communicate with you, such as provide you with account- or transaction-related communications, or other newsletters, RSS feeds, and/or other communications relating to the Services;
- Send or display offers and other content that is customized to your interests or preferences;
- Perform research and analysis aimed at improving our products and services and developing new products or services; and
- Manage and maintain the systems that provide the Services.
4. Disclosure of Your Information
We may disclose your Personal Information to third parties as described below.
We may disclose Personal Information to provide the Services, or when you authorize or instruct us to do so, for example, when you use the Services to submit content or profile information. We may also disclose Personal Information and non-Personal Information to Service Providers. By “Service Providers” we mean companies, agents, contractors, service providers, or others engaged to perform functions on our behalf (such as processing of payments, provision of data storage, hosting of our website, marketing of our products and services, and conducting audits). When we use a Service Provider, we require that the Service Provider use and disclose the Personal Information received from us only to provide their services to us or as required by applicable law.
We may also disclose Personal Information and non-Personal Information to Online Tool Providers. By “Online Tool Provider” we mean a licensor of software that we include in, or use with, the Services, including an API or SDK, that provides a specialized function or service to us and that requires the transmission of Personal Information and/or non-Personal Information to the Online Tool Provider. Online Tool Providers may have the right to use Personal Information and non-Personal Information about you for their own business purposes. Use and disclosure of Personal Information and non-Personal Information by an Online Tool Provider is described in its privacy policy. See Section 5 below for some of the key Online Tool Providers we use.
We may partner with advertisers to provide you with special offers, or to advertise products or services to you. If you redeem or respond to an offer, we may provide your Personal Information to the advertiser, including your name, email address, gender, and year of birth. If you answer questions or fill out surveys from an advertiser, we may share information with that advertiser. The advertiser’s privacy policy will govern their use of your information, which may include marketing of other products or services to you. For example, we advertise through the following platforms: Meta, Pinterest, TikTok, Snapchat, Google, Criteo, Amazon, PostPilot, and Microsoft. You should read each advertiser’s privacy policy before providing information to that advertiser.
We may also disclose your Personal Information to third parties when we believe, in good faith and in our sole discretion, that such disclosure is reasonably necessary to (a) enforce or apply the terms and conditions of the Services, including investigation of potential violations thereof, (b) comply with legal or regulatory requirements or an enforceable governmental request, (c) protect the rights, property or safety of us, our users or other third parties, (d) prevent a crime or protect national security, or (e) detect, prevent or otherwise address fraud, security or technical issues.
Finally, we reserve the right to transfer information (including your Personal Information) to a third party in the event of a sale, merger, or transfer of all or substantially all of the assets of our company relating to the Services, or in the unlikely event of a bankruptcy, liquidation, or receivership of our business.
Lastly, we may also disclose non-Personal Information, aggregated with information about our other users, to our clients, business partners, merchants, advertisers, investors, potential buyers and other third parties if we deem such disclosure, in our sole discretion, to have sound business reasons or justifications.
5. Cookies and Automatic Information Gathering Technologies
Every time you use the Services (e.g., access a Service webpage, or navigate to a specific location within the Service mobile app), we collect Personal Information and non-Personal Information (discussed above in Section 2) regarding that use. For example, to improve our Services, we collect how, when, and which parts of the Services or their features you use, which social media platforms you connect to the Services, and when, how, and what you post to the social media platforms through the Service app. Also, we may use your device’s unique identifier (UDID) or other unique identifiers to assist us in collecting and analyzing this data.
To assist us in collecting and storing this non-Personal Information, we may employ a variety of technologies, including “Cookies,” local browser storage, and “web beacons,” “pixels,” or “tags.” A “Cookie” is a small amount of data a website operator, or a third party whose content is embedded in that website, may store in your web browser and that the website operator or, as applicable, the third party, can access when you visit the website. A web beacon, pixel or tag is a small, usually-transparent image placed on a web page that allows the operator of that image, which may be the operator of the website you visit or a third party, to read or write a Cookie. We use both our own and third-party cookies, web beacons and pixels on our website.
Your operating system and web browser may allow you to erase information stored in Cookies and local browser storage. But if you do so, you may be forced to login to the Services again, and you may lose some preferences or settings. You may also be able to set your browser to refuse all website storage or to indicate when it is permitted, but some features of our Services may not function properly without it. We may use Cookies to keep you logged in, save your preferences for the Services, and to collect information about how you use our Services.
More information about managing Cookies is available here. To learn how to manage privacy and storage settings for your local browser storage, please refer to the end user documentation for your browser.
An Online Tool Provider may collect information automatically, in which case Personal Information and non-Personal Information it receives are subject to the Online Tool Provider’s privacy policy. Some Online Tool Providers may allow you to opt out of certain collection and/or uses of your information. You can read more here.
6. Transparency and Choice; Do Not Track Signals; Global Privacy Controls
You may request access to your Personal Information by sending an email to privacy@grandecosmetics.com. We will try to locate and provide you with your Personal Information and give you the opportunity to correct this data, if it is inaccurate, or to delete it, at your request. But, in either case, we may need to retain it for legal reasons or for legitimate business purposes. You may also remove any content that you post to the Services using the deletion or removal options within the Services. However, we (and you) are not able to control information that you have already shared with other users or made available to third parties through the Services.
If you need further assistance with removing any content you posted through the Services, you can email us at privacy@grandecosmetics.com. Removal of your posted content may not ensure complete or comprehensive removal from our computer systems.
We ask individual users to identify themselves and the information requested to be accessed, corrected, or removed before processing such requests, and we may decline to process requests that are unreasonably repetitive or systematic, require disproportionate technical effort, jeopardize the privacy of others, would be extremely impractical (for instance, requests concerning information residing on backups), or relate to information that is not associated with your Personal Information. In any case, where we provide information access and correction, we perform this service free of charge, except if doing so would require a disproportionate effort. We may also require you to verify your identity to our satisfaction before providing you with access to Personal Information.
Please note that, in our mobile app, you can choose to delete your account by navigating to “Delete Account” in the settings of the mobile app. Please be aware that if you request us to delete your Personal Information, you may not be able to continue to use the Services. Also, even if you request that we delete your Personal Information, we may need to retain certain information for a limited period of time to satisfy our legal, audit and/or dispute resolution requirements.
We may use third-party service providers that collect information for interest-based advertising purposes (advertisements that are tailored to your likely interests, based on categories in which you have shown an interest). To learn more about these third parties and the choices they offer users, please visit the Network Advertising Initiative’s choices page or the Digital Advertising Alliance’s choices page. If you are reading this Privacy Policy from a mobile device, you can learn more about the DAA's mobile choices program here.
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. DNT is a way for users to inform websites and online services that they do not want certain information about their webpage visits collected over time and across websites or online services. Please note that we do not respond to or honor DNT signals.
Global Privacy Control (“GPC”) is a browser setting that allows you to notify websites you visit about your privacy preferences, which you can learn more about at https://globalprivacycontrol.org/. We honor website visitors’ GPC signals.
You can opt out of receiving marketing e-mails from us by clicking on the “unsubscribe” link in the e-mails. Please note that it may take up to ten (10) business days for your opt-out request to be processed. Also, even if you opt out of marketing e-mails, we may continue to send you certain account-related e-mails, such as notices about your account and confirmations of transactions you have requested.
7. Certain State Residents
You may have heard of the certain state laws including the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), Virginia Consumer Data Protection Act (CDPA), Colorado Privacy Act (CPA), Utah Consumer Privacy Act (UCPA), Connecticut Data Privacy Act (CTDPA), Florida Bill of Digital Rights (FBDR), Indiana Consumer Data Protection Act (INCDPA), Iowa Consumer Data Protection Act (IACDPA), Montana Consumer Data Privacy Act (MTCDPA), Tennessee Information Protection Act (TIPA), Texas Data Privacy and Security Act (TDPSA), Oregon Consumer Privacy Act (OCPA), and Delaware Personal Data Privacy Act (DPDPA) which provide certain rights to California, Virginia, Colorado, Utah, Connecticut, Florida, Indiana, Iowa, Montana, Tennessee, Texas, Oregon, and Delaware residents in connection with their Personal Information. Our Services are not currently subject to CDPA, CPA, UCPA, CTDPA, FBDR, INCDPA, IACDPA, MTCDPA, TIPA, TDPSA, OCPA or DPDPA. However, we do provide notice and transparency about our collection and use of Personal Information as described in Privacy Policy.
8. Residents of Canada
If you have an objection to the use of your Personal Information as described in this Privacy Policy, you may file a complaint by sending an email to privacy@grandecosmetics.com. We will attempt to accommodate your objection or complaint, but you understand that, to the extent you object to our processing of Personal Information that is necessary for us to provide the Services to you, certain features and functionalities of the Services may no longer be available to you. Nothing in this Privacy Policy prejudices your rights to file a complaint with the Office of the Privacy Commissioner of Canada, and/or with any other applicable data protection authorities.
9. Residents of Nevada
We do not sell your Personal Information. However, you may contact us at privacy@grandecosmetics.com with questions.
10. Children
The Services are not intended for users under 18 years of age. We do not knowingly collect Personal Information from users under 18 years of age. We do not authorize users under 18 years of age to use the Services.
11. Information Security
We utilize reasonable information security measures to safeguard your Personal Information against unauthorized access, modification, or destruction. For example, we utilize Secure Socket Layer (SSL), Transport Layer Security (TLS), or similar encryption technology when sensitive data is transmitted over the Internet, and use firewalls to help prevent external access into our network. However, no data transmission over the Internet and no method of data storage can be guaranteed to be 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its security.
We restrict access to Personal Information in our possession to our employees, Service Providers, and Online Tool Providers who need to know that information in order to operate, develop, improve or support our Services.
12. Third Party Websites
Please note that the Services may link or integrate with third-party sites, services or apps. We are not responsible for the privacy or security policies or practices or the content of such third parties. Accordingly, we encourage you to review the privacy and security policies and terms of service of those third parties so that you understand how they collect, use, share and protect your information.
13. Changes to this Policy
We may modify or update this Privacy Policy periodically with or without prior notice by posting the updated policy on this page. You can always check the “Last Updated” date at the top of this document to see when the Privacy Policy was last changed. If we make any material changes to this Privacy Policy, we will notify you by reasonable means, which may be by e-mail or posting a notice of the changes on our website prior to the changes becoming effective. We encourage you to check this Privacy Policy from time to time. IF YOU DO NOT AGREE TO CHANGES TO THIS PRIVACY POLICY, YOU MUST STOP USING THE SERVICES AFTER THE EFFECTIVE DATE OF SUCH CHANGES (WHICH IS THE “LAST UPDATED” DATE OF THIS PRIVACY POLICY).
14. Questions
To ask questions about our Privacy Policy or to lodge a complaint, contact us at:
Grande Cosmetics, LLC
420 Columbus Ave, Suite 100
Valhalla, NY 10595
Email: privacy@grandecosmetics.com
Privacy Notice for California Residents
This Privacy Notice for California Residents (the “Notice”) supplements the information contained in our Privacy Policy and applies only if you reside in the State of California (you are a “California Consumer”).
For purposes of this Notice “Sell,” “Selling,” “Sale,” or “Sold,” means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, Personal Information to another business or a third party for monetary or other valuable consideration.
“Share”, “Shared,” or “Sharing” means sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, Personal Information to a third party for Cross-context Behavioral Advertising, whether or not for monetary or other valuable consideration.
“Cross-context Behavioral Advertising” means the targeting of advertising to a consumer based on that consumer’s Personal Information obtained from activity across businesses or distinctly-branded websites, applications, or services, other than the business or distinctly-branded website, application, or service with which the consumer intentionally interacts. (In other words, if we send you an ad based solely on your interaction with us or our Services, this is not Cross-context Behavioral Advertising.)
“Sensitive Personal Information” means Personal Information that is not publicly available and reveals one or more of the following:
- A consumer’s Social Security, driver’s license, state identification card, or passport number;
- A consumer’s account log-in, financial account, debit card or credit card number in combination with any required security or access code, password, or credentials allowing access to an account;
- A consumer’s precise geolocation;
- A consumer’s racial or ethnic origin, religious or philosophical beliefs, or union membership;
- The contents of a consumer’s mail, email, and text messages unless we are the intended recipient of the communication;
- A consumer’s genetic or biometric data; or
- Personal Information collected and analyzed concerning a consumer’s health, sex life, or sexual orientation.
“Verifiable Request” means that the identifying information provided by a consumer in connection with a request matches the Personal Information of the consumer already maintained by us or a third party identity verification service. Identifying information you can submit in order to permit Grande Cosmetics to verify your Verifiable Request may include your first and last name, the email address and phone number that is associated with your account.
- Information We Collect
In the past twelve (12) months, Grande Cosmetics has collected the following categories of Personal Information from California residents:
- Identifiers (names, personal or business addresses, email addresses, and IP addresses).
- Other information which is not required to use our Services but that you choose to provide to us through an online form.
In the past twelve (12) months, Grande Cosmetics has not collected Sensitive Personal Information from California residents.
Grande Cosmetics obtains Personal Information from the following types of sources:
- Directly from you. For example, from forms you complete or products and services that you purchase.
- Indirectly from you. For example, from information automatically sent by your web browser or from analyzing data about your actions on our website.
- Use of Personal Information
Grande Cosmetics may use, Share, or disclose the Personal Information we collect for one or more of the following “Business Purpose(s):”
- To fulfill or meet the reason you provided the information;
- To provide our website, online services;
- To facilitate Cross-context Behavioral Advertising;
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations;
- To respond to your requests under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, “CCPA");
- For any other purpose described to you when we collect your Personal Information; and
- For any other acceptable purposes as set forth in the CCPA.
Unless we notify you otherwise, we will not collect additional categories of Personal Information, nor use the Personal Information we collect for any other materially different, unrelated, or incompatible purposes.
- Retention of Personal Information
We retain each category of your Personal Information for no longer than is reasonably necessary for one or more Business Purposes, subject to your right to request we delete your Personal Information. Due to the nature of the services, it is not possible to predict the length of time that we intend to retain your Personal Information. Instead, we use the following criteria to determine whether it remains reasonably necessary to retain your Personal Information for one or more disclosed Business Purpose(s):
- Whether not there is a retention period required by statute or regulations;
- Pendency of any actual or threatened litigation for which we are required to preserve the information;
- Generally accepted best practices in our industry; and/or
- Pendency of applicable statutes of limitations for potential legal claims.
When we determine that it is no longer reasonably necessary to retain your Personal Information for one or more disclosed Business Purpose(s) based on the above criteria, we will delete your Personal Information.
- Disclosure of Personal Information
Within the last 12 months Grande Cosmetics has disclosed your Personal Information as described in this Notice.
Grande Cosmetics may disclose Personal Information to our contracted “service providers”, “contractors”, and “third parties” (each as defined by the CCPA) for a Business Purpose. When we disclose Personal Information for a Business Purpose, we enter into an agreement with the receiving party that describes the purpose for sharing the Personal Information, and that requires the receiving party to keep that Personal Information confidential. In the case of disclosures to our “service providers,” our “service providers” are obligated not to use the Personal Information for any purpose other than performing the services according to their agreement with us. In the case of our “contractors”, our “contractors’ are obligated not to use the Personal Information for any purpose unrelated to the business purpose for which we’ve engaged them.
We may disclose your Personal Information with the following categories of entities: (i) “Service Providers;” (ii) “contractors;” and (iii) “third party” advertisers.
In the past twelve (12) months, Grande Cosmetics has not Sold any Personal Information about its California Consumers.
We Share Personal Information, subject to your right to opt-out of those Sharing. In the past twelve (12) months, Grande Cosmetics has Shared the following categories of Personal Information about its California Consumers:
Category of personal information that is Shared |
Business Purpose for which it is Shared |
Types of entities to whom it is Shared |
Your identifiers (names, personal or business addresses, email addresses, and IP addresses). |
To facilitate Cross-context Behavioral Advertising |
Third party advertisers, Service Providers and contractors. |
Other information which is not required to use our Services but that you choose to provide to us through an online form. |
To facilitate Cross-context Behavioral Advertising |
Third party advertisers, Service Providers and contractors. |
- Your Rights and Choices
If you are a California Consumer, you may request information about our collection, use, disclosure and Sale of your Personal Information over the past twelve (12) months, whether or not it was collected electronically. If you submit a Verifiable Request, we will provide you with information regarding:
- the categories of Personal Information we have collected about you; the categories of sources from which your Personal Information was collected; our Business Purpose for collecting, Selling, or Sharing your Personal Information; the categories of third parties with whom we disclose that Personal Information; and the specific pieces of Personal Information we collected about you; and
- if we Sold, Shared, or disclosed your Personal Information for a Business Purpose: what categories of Personal Information we Sold or Shared, and to which categories of recipients we Sold or Shared it; and what categories of Personal Information we disclosed for a Business Purpose, and to which categories of recipients we disclosed it to.
You also have the right to request a copy of your Personal Information, and/or to request that we transmit your Personal Information to another entity. To the extent technically feasible, we will comply with your request and provide and/or transmit your Personal Information in a structured, commonly used, machine-readable format.
You also have the right to request that we delete any of your Personal Information that we collect or maintain by submitting a Verifiable Request. We may deny your deletion request if retaining your Personal Information is reasonably necessary for us or our “service providers” or “contractors” to:
- Complete the transaction for which we collected your Personal Information, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, provide goods or services that you requested, take actions reasonably anticipated by you within the context of our ongoing business relationship with you, or otherwise perform our contract with you;
- Help to ensure security and integrity to the extent the use of your personal information is reasonably necessary and proportionate for those purposes;
- Debug products to identify and repair errors that impair existing intended functionality;
- Exercise free speech, ensure the right of another consumer to exercise that consumer’s right of free speech, or exercise another right provided for by law;
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.);
- Engage in public or peer-reviewed scientific, historical, or statistical research that conforms or adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the ability to complete such research, if you previously provided informed consent;
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us and compatible with the context in which you provided the information; or
- Comply with a legal obligation.
You further have the right to request that we correct any of your Personal Information that is inaccurate by submitting a Verifiable Request. We will correct any inaccurate Personal Information pursuant to your request to the extent possible using commercially reasonable efforts. We may deny your correction request if the Personal Information is accurate. We may also delete your Personal Information instead of correcting it to the extent such deletion would not negatively impact you.
You may submit a Verifiable Request for the information listed above, or exercise any of your rights enumerated under this Notice, by calling us at 877-835-3010 or by completing a form on our website, available here. You may also submit a Verifiable Request on behalf of your minor child.
After we receive your Verifiable Request, we will provide to you, in writing and free of charge (unless your request is excessive, repetitive, or manifestly unfounded), the requested information for the 12-month period preceding your request (unless you specifically request disclosure beyond such 12-month period, in which case, we will process your request with respect to Personal Information we have collected during the time period you specify, provided that (a) the earliest date that your request may apply to is January 1, 2022, and (b) processing your request does not require disproportionate effort). You can choose to have this information delivered to you by postal mail, or electronically. We will try to respond to your verified request within forty-five (45) days of receipt, but if we require more time (up to another forty-five (45) days) we will inform you of the reason and extension period in writing. Please note that we are not required to comply with your request for information more than twice in any 12-month period. If applicable, our response will explain the reasons why we cannot comply with your request.
You have the right to direct us to stop Sharing your Personal Information to third parties at any time. You may opt-out here. However, if you change your mind, you may opt-in to Personal Information Sharing at any time by visiting here. Consumers who opt-in to Personal Information Sharing may opt-out of future Sharing at any time.
Grande Cosmetics does not and will not, without first obtaining your consent, Sell Personal Information.
Should you choose to exercise any of the rights enumerated under this Notice, we will not:
- Deny you goods or services;
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties;
- Provide you a different level or quality of goods or services; or
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
However, please be aware that it may be a functional necessity for our Services to have Personal Information about you in order to operate, and we may not be able to provide some or all of our Services to you if you direct us to delete your Personal Information.
PRIVACY NOTCIE FOR EUROPEAN AND UK RESIDENTS
If you reside in a country in the European Economic Area, the United Kingdom, or Switzerland (a “European Resident”) or the United Kingdom (a “UK Resident”), then information we collect from you may be subject to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “EU GDPR”), Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), as implemented by the UK Data Protection Act of 2018, and as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of Section 3 of the European Union (Withdrawal) Act 2018 (the “UK GDPR”), or the equivalent laws of the United Kingdom and Switzerland (collectively, “Data Protection Laws”), and the following additional information is provided for your benefit. For purposes of this Privacy Notice for European and UK Residents, in addition to the meaning set forth in the Privacy Policy, “Personal Information” shall also include “personal data” as that term is defined by the EU GPDR and UK GDPR, as well as “personal data” or similar terminology as defined by other applicable Data Protection Laws.
The controller of the Personal Information collected through the Services is:
Grande Cosmetics, LLC
420 Columbus Ave, Suite 100
Valhalla, NY 10595
If you use the Services, you acknowledge that your Personal Information is being processed pursuant to the lawful bases described below, and you specifically consent to your Personal Information gathered through the Services being transferred, used, and stored in the United States, Canada or other third party countries which do not have local privacy laws that are equivalent to the Data Protection Laws. You acknowledge and agree that the local laws in such countries may be materially different from, and provide for a lesser degree of protection regarding your Personal Information (including, but not limited to, with respect to governmental and law enforcement agencies’ ability to access your Personal Information under certain conditions) than, Data Protection Laws.
- Personal Information
If you use the Services, we may collect certain categories of Personal Information, as described in Section 2 of the Privacy Policy.
- https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.
- Lawful Bases for Processing
- Assist us in providing, maintaining, and protecting the Services;
- Set up, maintain, and protect accounts to use the Services;
- Improve our online operations;
- Process transactions;
- Provide customer service;
- Communicate with you, such as provide you with account- or transaction-related communications, or other newsletters, RSS feeds, and/or other communications relating to the Services;
- Send or display offers and other content that is customized to your interests or preferences;
- Perform research and analysis aimed at improving our products and services and developing new products or services;
- Manage and maintain the systems that provide the Services;
- Prevent and address fraud, unauthorized use of the Services, violations of our terms and policies, or other harmful or illegal activity; to protect ourselves (including our rights, property or products), our users or others, including as part of investigations or regulatory inquiries; or to prevent death or imminent bodily harm; and
- Operate of our day-to-day business and planning, including executing strategic corporate transactions, such as mergers.
- We need to process your Personal Information when applicable law requires it, including, for example, if there is a valid legal request for certain data.
- Disclosures of Your Information
- Retention of Your Information
- Questions and Complaints
Under applicable Data Protection Laws, companies must have a legal basis to process data. You have particular rights available to you depending on which legal basis we use, as explained in this Privacy Notice for European Union and UK Residents. You always have the right to request access to, rectification of, and erasure of your data under applicable Data Protection Laws. To exercise your rights, please email us at privacy@grandecosmetics.com.
Pursuant to a contract with you:
We may process data as necessary to perform our contracts with you. We describe the contractual services for which this data processing is necessary throughout this Privacy Policy and in our Terms and Conditions of Use. The main uses of your data necessary to provide our contractual services are described in the Use of Your Information section of the Privacy Policy:
We'll use the Personal Information we have to provide the Services and as otherwise described in our Privacy Policy if you choose not to provide certain data, the quality of your experience using the Services may be negatively impacted.
When we process data you provide to us as necessary to perform our contracts with you, you have the right to receive a portable copy of it (meaning to receive a copy of your data in a structured, commonly used and machine-readable format) under applicable Data Protection Laws. To exercise your rights, please email us at privacy@grandecosmetics.com.
The other legal bases we rely on in certain instances when processing your data are:
Your Consent:
We may process your Personal Information on the lawful basis of consent. When we process data you provide to us based on your consent, you have the right to withdraw your consent at any time and to receive a portable copy of the data you provide to us, under applicable Data Protection Laws. To exercise your rights, please email us at privacy@grandecosmetics.com.
Legitimate Interests:
We may process your Personal Information where our legitimate interests, or the legitimate interests of a third party, are not outweighed by your interests or fundamental rights and freedoms.
The legitimate interests for our processing of Personal Information are to:
You have the right to object to, and seek restriction of, such processing; to exercise your rights, please email us at privacy@grandecosmetics.com.
We will consider several factors when assessing an objection to our processing in furtherance of Grande Cosmetics’ legitimate interests, including: (i) our users' reasonable expectations; (ii) the benefits and risks to you, us, other users, or third parties; and (iii) other available means to achieve the same purpose that may be less invasive and do not require disproportional effort. Your objection will be upheld, and we will cease processing your information, unless the processing is based on compelling legitimate grounds or is needed for legal reasons.
Compliance with a legal obligation:
“Processors” means our Service Providers and their respective service providers.
We may also disclose your Personal Information, (as well as non-Personal Information, without the same restrictions that apply to your Personal Information) to our Processors who we engage to perform certain functions for us, or on our behalf (including, but not limited to, processing of payments, provision of data storage, hosting of our website, marketing of our products and services, conducting audits, and performing web analytics). A list of our Processors and a description of the services that they perform for us follows. We establish data processing agreements that govern our Processors’ use of your Personal Information, but our Processors’ use of your Personal Information may also be subject to the Processors’ own privacy policies. Click here to review the links to our Processors’ privacy policies.
We retain each category of your Personal Information for no longer than is reasonably necessary for one or more of the above lawful bases for processing, subject to your right to request we delete your Personal Information. Due to the nature of the services, it is not possible to predict the length of time that we intend to retain your Personal Information. Instead, we use the following criteria to determine whether it remains reasonably necessary to retain your Personal Information for one or more disclosed lawful bases for processing: we will retain and use your Personal Information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
When we determine that it is no longer reasonably necessary to retain your Personal Information for one or more disclosed lawful bases for processing based on the above criteria, we will delete your Personal Information.
If you have any questions or complaints regarding our use of your Personal Information, please contact us at privacy@grandecosmetics.com. You also have the right to submit a complaint to your applicable Data Protection Authority.