PRIVACY POLICY
This privacy policy applies to the processing of personal data that we collect, or you submit when you visit our website, use our mobile apps, or communicate with us. This Privacy Policy does not apply to information that you submit to the websites or apps of our business partners or any other third parties or that are collected by them from you, even if those third-party websites or apps are linked to our website or listed in our Cookie Policy. Please note that countries in the European Economic Area and certain U.S. states provide their residents additional rights regarding the use of their personal data. See the Information for Specific Jurisdictions section below for more information that may apply to you.
OVERVIEW
- Our statement on privacy
- Collecting & using your personal data
- Sharing personal data
- Transferring data outside the EU
- How long do we store your data?
- Your rights
1. OUR STATEMENT ON PRIVACY
It is our mission to give you a great fashion experience right from the moment you start browsing the many styles, to the time that you receive your order. As part of your shopping experience with us, we want to assure you that we recognize the importance of protecting the privacy of personal data. We uphold the following principles when handling your personal data: • We collect and store personal data for these main purposes: • Completing, fulfilling, packing and delivering your order • Customer service • Improving your user experience • Marketing and advertising • Fraud prevention • Regulatory requirements • We only collect personal data that we need for the purposes mentioned above • We delete your personal data when the purpose for collecting it ends • We do not sell your personal data • We take reasonable steps to keep your personal data secure Below you can read more about how and why we collect and store your personal data – and who we share it with. You can also read about how you can exercise your privacy rights, e.g. how to request access to your personal data.
2. COLLECTING & USING YOUR PERSONAL DATA
We collect and store the following personal data through our website, mobile apps, and communications and use it for typical business purposes (including security and anti-fraud purposes) and as described more specifically below:
FULFILLMENT OF YOUR ORDER
To accept, handle, fulfill, or deliver your order, we need some information from you. When you place an order with us, you provide us with your personal identifiers (such as your name, address, email, and phone number), and, of course, commercial information (such as your payment method, confirmation of completed transactions, and which products you wish to purchase). We use the information to fulfill your order including sending an order confirmation and packing and delivering your order. We do not collect or store payment card or other financial account information.
CUSTOMER SERVICE
When you contact our customer service via email, chat, online forms, or phone etc., we will receive the personal data that you provide to us, including your personal identifiers and the content of your requests. Our customer service team has access to all information about your orders, so we can help you in the best possible way, whether you have questions about the status of your orders, or if you need to return an item, e.g. via an online return portal. Our customer service team is also able to see any previous correspondence with you. We use this information to respond to your requests and to provide you with a better products and services.
If you use our “Notify Me”-service, we will use your personal identifiers (such as your email address), in accordance with your request, to notify you by email when a certain item is back in stock.
IMPROVEMENT OF YOUR USER EXPERIENCE
We constantly strive to give you the very best user and shopping experience on our website and mobile apps, such as to enable certain features of the website and mobile apps, preserve your preferences and customize your experience when you visit and return to the website and mobile apps, and study, enhance and improve the use and capabilities of the website, mobile apps, content, and advertising. We and our partners do that in different ways, but an important part of it is by automatically tracking your Internet activity and browsing behaviour on our website and mobile applications as well as our social media platforms and drawing inferences from the information we collect in order for us to improve the user friendliness, layout, functionalities, and overall experience of the site. We do that by using cookies and similar technology to automatically record personal identifiers (such as your IP address and device identifiers), information about your device (such as your browser type, locale preferences, and mobile carrier) and information concerning your usage activity on the website and mobile apps (such as your interaction with the website or mobile apps, the link you used to reach them, and the content and advertising displayed on them and our content and advertising on other websites and online services) and generating inference data. You can read more about our use of this technology HERE . We also use your browsing data to recommend products that we think you might like. Some of the information we collect, such as IP addresses, may be used to estimate an approximate, imprecise location of the device you are using to access our website or mobile apps in order to automatically direct you to the relevant local website or content
These third-party partners also may collect and combine information about your online activities over time, on other devices, and on other websites or online services, if those websites and online services also use the same partners.
MARKETING AND ADVERTISING
In order for us to present you with the best possible fashion advice and most relevant news and marketing, we and our advertising partners use personal data to personalize the recommendations and promotions on our website, mobile apps, and communications (such as email) and to show you relevant advertising on other websites, social media networks and apps. Doing this, we use information about your use of our websites, mobile apps, communications, and services including information such as Internet activity on our website and mobile apps, commercial data (e.g., order history), past correspondence and personal identifiers (such as contact information, IP address, and device identifiers). This information may be combined with other information which you have provided to our advertising partners or which they have collected themselves. We and our partners may also generate inferences from the information we collect. Our partners may use cookies and similar technologies (all of which, we call “cookies”) to collect information when you visit our website. Read more about the cookies used on our website and mobile apps HERE . You can always object to our processing of your personal data for direct marketing purposes, including profiling, by using our request form, which can be found HERE . Some laws and government agencies may consider the use of third parties to perform personalized advertising and website and mobile app analytics as a “sale” of personal data if users do not consent. We allow third parties to use cookies and other technology to perform personalized advertising and analytics with your consent, and so we do not sell your personal data. Below you can read more about how we personalize our marketing towards our users of our apps and through our marketing cookies.
- OUR APP
In our apps you can choose to receive push notifications from us regarding marketing and advertising campaigns. At any time, you can deactivate the notifications in the settings on your mobile phone.
- COOKIE BASED MARKETING
Some of our marketing activities are based on cookies. Among other things, the marketing cookies that we and our partners use collect and store information about your style and size preference, device ID, approximate, imprecise location based on your IP address and your general browsing behavior on our websites. These cookies also track which ads you have already seen, how many times you have seen them, whether you have clicked on any of them and whether or not you have placed an order after clicking. Further, some of our partner cookies will be able to track you over time and when you visit other websites or social media networks when they also work with our partners. We use that information to personalize the recommendations and promotions on our websites and to show you relevant advertising on other websites such as social media networks and comparison-shopping engines as well as on other mobile applications. For instance, if you have looked at a specific pair of jeans, we may present you with ads for that pair of jeans or similar on your social media news feed. In addition, we may also combine the information collected by cookies with your order history, past correspondence and other information you have provided to us and generate inferences from the information for marketing purposes. You can read more about our use of cookies HERE .
You can also opt-out of personalized advertising by visiting the following websites: • HTTP://WWW.NETWORKADVERTISING.ORG/CHOICES/ • HTTP://WWW.YOURONLINECHOICES.COM/
MY ACCOUNT
If you choose to create a personal customer account (My Account), you must provide us with certain personal identifiers, such as your name
and email address. You can also choose to give us your phone number and address. My Account provides you with an overview of your shopping bag and your order history. You can update or delete your account at any time by logging in and following the instructions on the web pages and screens.
FRAUD PREVENTION
We use the personal data submitted by you when you place an order for fraud detection and fraud prevention purposes. For those purposes we may also receive additional information from our payment solution and processing partners.
REGULATORY REQUIREMENTS
We use and store your personal data in order to comply with regulatory requirements, e.g. bookkeeping regulations.
BUSINESS PURPOSES
We de-identify or aggregate data we receive and may use and disclose it for any business purposes. We will process such data only in a de-identified fashion and not attempt to re-identify such data.
3. SHARING PERSONAL DATA
In order to provide our services, we share personal data with our partners. We only share your data when this is allowed by law and all our partners are committed to keeping your data safe. Some of our partners are “data controllers” and others are “data processors” or “service providers”. We may provide partners with the personal data we collect (as described above) for our business and commercial purposes, such as to assist us in providing products and services to you, including to process transactions, deliver products at your request, help us market to consumers, and as otherwise described below. We do not sell your personal data to third parties.
DATA CONTROLLERS
The below-described partners are data controllers meaning that they are directly responsible for the processing of your data. We only share personal data to the extent it is required for performance of their services to us, e.g. shipping. For example, when you complete an order, your payment is handled by our payment solution partners. Some of our payment solution partners are data controllers. In order to be able to offer you these payment options, we will pass certain aspects of your personal data, such as personal identifiers (including contact information) and commercial data (including order details), in order for the payment providers to assess whether you qualify for their payment options and to tailor the payment options for you. You can find more information about these providers, including their terms and conditions and privacy policies on their websites. Your orders are sent to our warehouse partner. When your order is packed and ready to ship, we share your personal identifiers (e.g., your name, address, email and phone number) with our carrier partners to fulfil your delivery. For marketing purposes, we may share non-reversible and encrypted (hashed) information about you and your use of our websites and services with our advertising partners who may combine it with other information that you have provided to them directly or that they have collected themselves about you so they can show you personalized advertisements. We also share information such as your IP address and order information with our affiliate partners to settle commissions for their reference to our web shop. We also allow partners to use cookies to collect information from users of our website and mobile apps as described above in the Marketing and Advertising section.
DATA PROCESSORS AND SERVICE PROVIDERS
The partners described below are data processors/service providers who are only allowed to process personal data on behalf of us and according to our instructions. We disclose personal data to data processors in connection with providing products and services to you, processing your transactions, our business and commercial purposes, and as otherwise described below. Our payment solution partner Adyen handles your payments as a data processor. Your payment details are sent directly to Adyen where it is handled and stored in accordance with their security measures in compliance with regulatory standards. Our technical service providers process your personal data when they have access to our databases or store personal data in their applications. These service providers include, for example, hosting providers, providers of our website platform and providers of message distribution tools. In addition, we have partners who provide tools related to customer service and customer experiences, e.g. a chat tool on our website or a customer experience feedback tool. Finally, as part of our marketing activities we share non-reversible and encrypted (hashed) customer information, including personal identifiers such as contact information with social media networks and with other partners who will make the campaigns available to you on their websites or in your social media news feed.
OTHER SITUATIONS WHERE WE SHARE DATA
If we believe we are obliged by law, a court decision, or a decision of another authority, we will access, preserve, and share personal data with the relevant authority or third party. We also report fraud incidents to the relevant law enforcement authorities. We also may access, preserve, and disclose information if we believe that such action is necessary in our judgment to protect and defend our rights or property, or those of others. In the event of a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another entity (whether by private sale, through operation of law, as part of a divestiture plan, or otherwise), we will provide personal data and transaction history associated with each such business unit to the persons and/or entities assuming control of such business unit or as otherwise necessary to complete the transaction as permitted by law or contract. The website and mobile apps may provide options allowing you to share information with social networking websites, such as Facebook. Their use of the information you share will be governed by the social media privacy policies, and we are not responsible for how they treat the information you share.
5. HOW LONG DO WE STORE YOUR DATA
We only store your personal data for as long as it is necessary to fulfill the purpose for which it was collected, to establish, defend or exercise legal claims or to comply with regulatory requirements, e.g. bookkeeping regulations in the countries where we operate. When this is no longer the case, the information will be deleted. There may also be residual information that will remain within our backup files, databases, and other records, which will not be removed or changed, except in accordance with retention policies. You can also request us to delete personal data as described in the Privacy Rights section below.
6. PROTECTING PERSONAL DATA
We employ reasonable security measures to protect the information we receive. Please remember, though, that no method of electronic transmission or storage is 100% secure.
7. LINKS
The website and mobile apps may contain links to other websites and mobile apps, and other websites may link to our websites and mobile apps. We are not responsible for the privacy practices of such other websites and mobile apps. Whenever you visit another website or mobile app – via a link from our website or mobile apps or otherwise – you should review the privacy policy of that other website or mobile pap. This Privacy Policy applies solely to information provided or obtained on our website or mobile apps.
8. NO USE BY CHILDREN UNDER 13
The website and mobile apps are not intended for use by children under the age of 13. If you are under the age of 13, you may not use our website or mobile apps. We do not knowingly collect, maintain, or use personal information from children under 13 years of age. If we believe that any information has been posted by a child under the age of 13, we will promptly delete that information. Parents may contact us using the methods set forth below to request that information concerning their child be removed from our websites and mobile apps.
9. QUESTIONS
Customer questions, comments, and feedback are very important to us. Upon request, we will allow you to access and change certain information about you (e.g., your contact information). To do so, contact us at:
Handels B.V. Koivistokade 1c, 1013AC Amsterdam, the Netherlands or by e-mailing us at customerservice@bestseller.com.
10. NOTIFICATION OF CHANGE TO THE PRIVACY POLICY
We reserve the right to modify this Privacy Policy. Whenever we decide to materially change this Privacy Policy, notice of the change will be posted on the website for a reasonable period of time or provided to you using other means. Nevertheless, you should review the Privacy Policy from time to time to be sure you are aware of the most recent version. We will only use information in accordance with the Privacy Policy in effect at the time the information was collected, unless we receive your consent.
11. PRIVACY RIGHTS
Certain jurisdictions, including in the EEA, UK, Switzerland, and U.S., impose specific legal requirements and privacy rights with respect to personal data, and we will comply with restrictions and any requests you submit as required by applicable law. For example, consumers may have one or more of the following privacy rights: to request additional information about our data collection, use, and disclosure practices in connection with the consumer’s personal information; to request access to the specific personal information collected about the consumer; to request the deletion of personal information we have about the consumer; to request a restriction on certain processing of personal information; and to request correction of inaccurate information. Also, certain consumers have the right not to receive discriminatory treatment if they exercise the rights list above. You may be able to use the website or mobile apps to access and update the information that you have provided to us through your use of the website or mobile apps or otherwise. If you would like to request access to such information or that we update, correct, or delete any such information, you may submit your request HERE . We will comply with requests you submit as required by applicable law.
When you make a request, we may require that you provide information (such as your name, email address and/or zip code) and follow procedures so that we can verify a request you make and your jurisdiction before responding to it. The verification steps we take may differ depending on your jurisdiction and the request you make. We will match the information that you provide in your request to information we already have on file to verify your identity. If we can verify your request, we will process it. If we cannot verify your request, we may ask you for additional information to help us verify your request. We will respond to your request within the time period required by applicable law. However, we may not always be able to fully comply with your request, and we will notify you in that event. Certain privacy laws permit consumers to use an authorized agent to make privacy rights requests. We require the authorized agent to provide us with proof of the consumer’s written permission (for example, a power of attorney) that shows the authorized agent has the authority to submit a request for the consumer. An authorized agent must follow the process described below to make a request, and we will additionally require the authorized agent to verify his/her own identity and we will confirm the agent’s authority with the consumer about whom the request was made.
12. INFORMATION FOR SPECIFIC JURISDICTIONS
- Information for individuals located in the European Economic Area, the UK, and Switzerland
- Controller BESTSELLER Handels B.V., Koivistokade 1c, 1013 AC Amsterdam, the Netherlands, is the data controller of the personal data covered by this Privacy Policy.
- Legal Bases for Collecting and Using your Personal Data We collect and use your personal data on the following legal bases:
- Our performance of a contract, cf. GDPR article 6, 1 (b)
• Fulfilment of your order, including returns handling
- Our legitimate interest, cf. GDPR article 6, 1 (f)
• Customer service • Improvement of your user experience • Fraud detection and prevention • Analysis, user experience and development based on cookies
- Your consent, cf. GDPR article 6, 1 (a)
• Customer clubs • My Account • Marketing through push messages in apps • Cookie-based marketing
- Our legal obligations, cf. GDPR article 6, 1 (c)
• Regulatory requirements
- Transferring Data outside the EU
Some of our partners handle your personal data outside the EU. In such case we will take steps to transfer your personal data with an adequate level of data protection. Unless otherwise stated, the data transfer is safeguarded by the EU Commission’s Standard Contractual Clauses. The partners listed below are entities located outside the EU:
• Google, USA
• Facebook, USA
• Zendesk, USA
• Atlassian, USA
• Mailjet, USA
In addition, some of our partners may use external subcontractors (sub-processors) located outside the EU. In such case, our partner is obligated to keep your personal data safeguarded. If you want specific information about these external sub-processors, please contact customerservice@bestseller.com.
- Privacy Rights
Residents of the European Economic Area, the UK, and Switzerland have the following rights: RIGHT OF ACCESS One of the most important rights that you have is the right to request access to the data that we have registered on you. If you request access, we will provide you with a copy of your personal data. RIGHT TO BE FORGOTTEN Another important right in terms of your relationship with us is that you have the right to be forgotten, meaning you can file a request asking that we delete the data that we have registered on you. We may not be able to delete all your personal data as we are required to continue to store certain data in order to comply with legal requirements or to establish, defend or exercise legal claims. RIGHT TO OBJECT You are entitled to object to the processing of your personal data on certain grounds. For example, you can object to the processing of your personal data for direct marketing purposes, including profiling. RIGHT TO RECTIFICATION If you believe that the data we have registered on you is inaccurate or incomplete, please let us know and we will make sure to update your information. RIGHT TO RESTRICTION In combination with some of your other rights you can also request that we restrict the use of your personal data, e.g. instead of full erasure or during our assessment of your objection. RIGHT TO DATA PORTABILITY You can file a request asking us to supply you with the personal data that you have provided to us in a structured, commonly used and machine-readable format and to transmit the data directly to a specific recipient. COMPLAINTS If you wish to lodge a complaint about how we handle your personal data, you can always contact our customer service team. You can also file a complaint with your local DATA SUPERVISORY AUTHORITY.
- Information for individuals located in California
We are not currently “selling” (as defined by the California Consumer Privacy Act) and do not “sell” your personal data without your consent. We also do not rent, sell, or share personal information (as defined by California Civil Code §1798.83) with other people or unaffiliated companies for their direct marketing purposes. California consumers have the right to request the deletion of their personal data, additional information about our use and disclosure of their personal data, and the specific pieces of personal data we have about them. California consumers also have the right not to receive discriminatory treatment if they exercise the rights list above. To make privacy requests, California consumers may contact us HERE , or email us at: [insert email address]. Consumers will be required to submit their email address, and may also be asked to provide their name, location, and telephone number so that we can verify the request. California law permits California consumers to use an authorized agent to make privacy rights requests. We require an authorized agent to provide us with proof of the California consumer’s written permission (for example, a power of attorney) that shows the authorized agent has the authority to submit a request for the California consumer. Authorized agents must follow the process described above to make a request, and we may additionally require authorized agents to verify their identity and registration to do business in California and we may confirm the agents’ authority with the California consumer about whom the request was made.