Privacy Policy

1. Our Approach

This Privacy Policy (the “Policy”) sets out how we, Waldencast UK Limited (trading under the name WHIND) (“Waldencast”, “us”, “our” or “we”) process personal information about you (the “Customer” or “you”) when you use our website www.whind.com, and when you place an order with us via our website www.whind.com (the “Site”). We are a data controller of the personal information we process and are therefore responsible for ensuring our systems, processes, suppliers and staff comply with data protection laws in relation to the information we handle. If you do not agree with this Policy, you should not submit information to us.

You can find out more about our responsibilities and about how and why we collect and use your personal information by reading this Policy. If anything is unclear or if you have any questions about this Policy, please contact us at privacy@whind.com.

Cookies and Pixels

Cookies are small text files that are placed on your computer by websites that you visit. They are commonly used across the internet in order to make websites work, improve their personalisation, or to provide information to the owners of the site about how it is working. A cookie often contains a unique identifier, which can be used to recognise your computer when it returns to a website that it has visited before.

Pixels work with cookies to help us understand how you use our website and to improve our advertising, similar to cookies. Pixels are different from cookies because they do not stay on your computer, they are temporary while you browse our Site and are ‘removed’ when you close our Site.

Cookies are commonly classified into ‘first party’ and ‘third party’ cookies, and this changes whether we or one of our partners serves you the cookie. First party cookies are served by us and are more likely used to ensure performance of our Site, while third party cookies are hosted by one of our partners and more likely used for analytics and measurement of marketing performance.

Cookies may also have different lifetimes – this means that they stay on your computer for a defined period before being automatically removed. Another common cookie type is a ‘session cookie’, these cookies are automatically removed when you close your browser.

2. The information we collect from others

When using our Ste, you may be linked to third-party services that will collect certain personal information from you. This information is not collected or used by us and it is a subject to privacy policies of such third parties.

We are not responsible for the privacy policies and practices of other websites even if you accessed the third-party website using links from our Site or have access to them otherwise through our Site. We recommend that you check the policy of each website you visit before deciding whether to proceed and contact the owner or operator of such website if you have concerns or questions.

Payment Services

When using our Site for placing an order, you will be redirected to third-party websites or platforms for completing financial transaction. These websites and platforms will request certain information from you (including your credit card information) in order to carry out the payment. As we are receiving party to this financial transaction, we will receive information about transaction from third-party payment providers.

Embedded Content

The Site may include embedded content (e.g., images, videos, articles, etc.) from third-party websites (such as YouTube, Vimeo, Google Web Fonts, SoundCloud, etc.). Accessing to this embedded content makes the same effect as you are accessing third-party websites from which embedded content is provided. These third-party websites, therefore, may collect certain information about you in accordance with their own privacy policy. Please note that if you have an account on such third-party website and you are logged-in while accessing embedded content, such accessing will be attributed to your account. For example, interactions that you may make with embedded content will be traced by third-party website and the same may influence the user experience that you will have on such website.

3. The information we collect and how we collect it

Personal data, or personal information, means any information about a person from which they can be identified.  We may collect, store, and use some or all of the following categories of information:

System Information (Website Visitors, Account Holders and Customers)

When you visit our Site, we automatically collect information about your use of the platform including details of your visits such as pages viewed and the resources that you access. This information may include website traffic data, IP address, pages viewed, location data, browser, operating system, referral source, length of visit, clickstream data and other communication data. This information is not normally personally identifiable from the methods and systems we use. In some situations, this information could be combined with other sources to make it personally identifiable, however we limit access to ensure that this information remains anonymous.

We collect System Information when you interact with our platform, through our Site or otherwise.

Identity Information (Registered Users and Customers)

When creating a user account on our Site, logging into or updating an existing account, or placing an order, we will collect the following information:

  • personal contact details such as name, title, addresses, telephone numbers, and email addresses;
  • date of birth and other physical characteristics such as your age, weight and gender;
  • billing information and account settings.

Please note that some information may be optional, while information that are necessary for certain actions (e.g., creation of user account or placing an order) will be clearly marked as required fields.

We collect Identity Information provided voluntarily by you or provided through a partner. For example, when you use Google to login to our Site, or when you register with or use our platform to buy products.

Cookies and Pixels

We use cookies to enhance our Site, to better understand how our Site is used and to monitor how our advertisements perform. Cookies may tell us, for example, which adverts you have been shown and whether you have visited our site before or are a new visitor.

You have the right to choose whether to accept these cookies and can exercise this right by amending or setting the controls on your browser. Please note that if you choose to refuse all cookies you may not be able to use the full functionality of our Site, for example you may need to re-enter login information multiple times to complete checkout.

Our pixels help our partners understand how our marketing campaigns should be run efficiently. We may share some of your personal details in an encrypted format with the pixel partners, for use exclusively for managing advertisements on their platforms. We do not share financial or address details with these partners.

Based on the functionalities of your browser, you should be able to view the cookies that are stored for a website and to also change your preferences for which cookies are allowed. This is done on a site-specific basis and can be reset back to defaults through the same process. It is also possible to switch into “Private” or “Incognito” browser mode in order to reduce the amount of tracking that is carried out by your browser. This will not have the same effect as blocking cookies but provides an alternative method of reducing the performance of them.

To help you understand how we use cookies, we may from time to time provide a list of cookies used on our website. Such list can be occasionally updated and we endeavour to keep this list updated but cannot guarantee it. 

 

We also collect Identity Information when you contact us (by email, telephone or otherwise) to ask a question or request information.  

4. How we will use your personal data

Providing our Services

As part of the provision of our services, we use the personal information that we collect from you to:

  • register you as a user of our service
  • process your orders and provide your details to third parties (e.g., postal or delivery service) in order to successfully process such orders
  • manage our relationship with you (for example by notifying you about changes to our terms or asking for feedback on our service)

Monitoring, administering and improving

We use your personal information to help us to monitor our performance, administer and improve our service by:

  • tracking and analysing activity to identify patterns and help us improve our Site and communications
  • troubleshooting, conducting data analysis, testing, system maintenance, support, reporting and hosting of data
  • using data analytics to improve customer relationships and experiences
  • analysing information so that we can prioritise features that are relevant and popular
  • educating, training and developing our staff’s performance
  • ensuring network and information security, including preventing unauthorised access to our computer and electronic communications systems and preventing malicious software distribution
  • preventing fraud
  • other business administration such as management and planning, including accounting and auditing

Other uses

  • With your prior explicit consent and occasionally under legitimate Interest, we may use your data to send you specialist information about goods and services offered by us which may be of interest to you. If you wish to withdraw your consent at any time, please contact us at privacy@whind.com or click Unsubscribe in any of our emails.
  • Protect the rights and property of Waldencast UK Ltd and others and comply with our legal obligations, including to detect, investigate and prevent fraud and other illegal activities and to enforce our agreements to which you are a party
  • Carry out any other purpose described to you at the time the personal information was collected

5. The sharing of personal information 

We may share personal information about you as follows or as otherwise described in this Privacy Policy and to the extent necessary for performance of particular task:

  • With other companies within Waldencast UK Ltd to enable us to run data analysis, develop new products or services, and for other business development purposes. We may also share personal information to allow another Waldencast UK Ltd company to perform services on our behalf
  • With our vendors and service providers, who are trusted third parties we hire or work with, to allow us to provide our products and services to you. These service providers need access to your personal information in order to perform services on our behalf, including but not limited to web hosting, payment processing, email distribution, marketing and advertising, customer support, information technology and analytics services.
  • With our partners, such as organisations with whom we organise contests or events and our retail partners
  • With other website visitors when you choose to participate in certain interactive areas of our website, such as by posting a product review
  • In connection with a corporate transaction, such as any purchase, sale, lease, merger or other type of acquisition, disposal or financing involving Waldencast UK Ltd
  • With our professional advisors, such as our legal, financial, insurance and other advisors in connection with the corporate transactions described above or the management of our business and operations
  • With law enforcement and individuals involved in legal proceedings, when it’s necessary for us to comply with applicable law or legal process, to respond to legal claims, or to protect the rights, property or personal safety of Waldencast UK Ltd, our users, employees or the public
  • When you write product reviews on our website
  • With your consent or at your discretion

6. Our grounds for processing 

Data protection law says we only have the right to use your personal information where we can identify a lawful basis for doing so. Your consent to the processing as specified in this Policy is our primary lawful basis. In some circumstance we may also rely on another lawful basis. Most commonly, these will be:

  • where we need to use the information to perform the contract we have entered into with you
  • where it is necessary for our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests
  • where we need to comply with a legal or regulatory obligation

7. Information security and retention

The Internet is not a secure medium. However, we have put in place various security procedures as set out in this Policy.

Please be aware that communications over the Internet, such as emails and online messages are not secure unless they have been encrypted. Your communications may route through a number of countries before being delivered – this is the nature of the Internet. We cannot accept responsibility for any unauthorised access or loss of personal data that is beyond our control.

We believe that we have appropriate policies, rules and technical measures to protect the personal data that we have under our control (having regard to the type and amount of that personal data) from unauthorised access, improper use or disclosure, unauthorised modification, unlawful destruction or accidental loss.

We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.  We also have procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.

We will only retain your personal information for as long as is necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorised use or disclosure of your information, the purposes for which we process it and whether we can achieve those purposes through other means, and the applicable legal requirements.

8. Advertising and analytics services provided by others 

We may allow others to provide analytics services and serve advertisements on our behalf across the web. These entities may use cookies, web beacons, device identifiers and other technologies to collect information about your use of our Site and other websites and applications, including your IP address, web browser, mobile network information, pages viewed, time spent on pages or in apps, links clicked, and conversion information.

This information may be used by Waldencast and others to, among other things, analyze and track data, determine the popularity of certain content, deliver advertising and content targeted to your interests on our website and other websites, and better understanding your online activity. For more information about interest-based ads, or to opt out of having your web browsing activity used for behavioral advertising purposes, please visit www.aboutads.info/choices

We may also work with third parties to serve ads to you as part of a customized campaign on third-party platforms (such as Facebook, Snapchat or Instagram). As part of these ad campaigns, we or third-party platforms may convert information about you, such as your email address and phone number, into a unique value that can be matched with a user account on these platforms to allow us to learn about your interests and to serve you advertising that is customized to your interests. Please note that the third-party platforms may offer you choices about whether you see these types of customized ads.

Rakuten Advertising may collect personal information when you interact with our digital property, including IP addresses, digital identifiers, information about your web browsing and app usage and how you interact with our properties and ads for a variety of  purposes, such as personalization of offers or advertisements, analytics about how you engage with websites or ads and other commercial purposes. For more information about the collection, use and sale of your personal data and your rights, please use the below links.

9. International transfer of personal information

We may transfer the personal information we collect about you outside the country of origin in order to perform our contract with you or to fulfil other purposes in accordance with this Policy. Your information may, for example, be transferred or transmitted to, or stored and processed in countries outside of where you live for the purposes as described in this Policy. These data transfers are necessary to provide the services set forth in Terms of Use of our Site. We utilize standard contractual clauses, rely on the European Commission's adequacy decisions about certain countries, as applicable, and obtain your consent for these data transfers in accordance with applicable law. Where this occurs, we will ensure that your personal information receives an adequate level of protection and we will put in place appropriate measures to ensure that your personal information is treated in a way that is in line with applicable laws on data protection. If you require further information about these protective measures, you can request it by contacting us at privacy@whind.com.

10. Your rights in relation to your personal information 

Under certain circumstances, as prescribed in the applicable law you have the right to:

  • Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it
  • Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected
  • Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it
  • Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground
  • Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it
  • Request the transfer of your personal information to another party

You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.

If you wish to exercise your rights in relation to the processing of your information by any of our Partners, you should contact us via e-mail address privacy@whind.com.

11. Your California privacy rights 

If you are a California resident, you have the right to: (1) request a copy of the specific personal information we have collected about you within the previous twelve months, including personal information we have shared with another company for a business purpose, (2) request that we delete your personal information, and/or (3) request that we stop selling your personal information.

Such requests may be made up to two times in a rolling twelve-month period. When you make such a request, the personal information provided may be limited to personal information we collect about you in the previous twelve months. With respect to deletion requests, note that, if you choose to delete your personal information, then you may not be able to use certain functions of our Site that require personal information to operate.

With respect to selling requests, please note that we have not sold personal information for monetary consideration in preceding twelve months and we do not plan to do so in future unless you give us your consent or instruct us to do so. However, under some circumstances a transfer of personal information to a third party without monetary consideration may be considered a “sale” under California law. For purposes of California law, all categories of personal information, except for background and criminal information, biometric information, and government identifiers, may be transferred internally or to third parties. Such transfers under certain circumstances may be considered a sale. We will not discriminate against you choosing to exercise your right opt out of having your personal information sold as defined under California law.

If you are a California resident, you also have the right to ask us one time each year if we have shared personal information with third parties for their direct marketing purposes. We share personal information with third parties for the direct marketing of their products only if we have your affirmative consent (opt in).

California residents may make such requests in two ways: (1) by sending us an email at privacy@whind.com or (2) by writing to us at Waldencast UK LTD, Michelin House, 81 Fulham Road, Chelsea, London, SW3 6RD, UNITED KINGDOM.

12. Changes to this privacy policy 

We reserve the right to update this Policy at any time, and we will provide you with a new Policy when we make updates. We may also notify you in other ways from time to time about the processing of your personal information.

13. How to contact us 

You can learn more about how privacy works by contacting us. If you have questions about this Policy, you can contact us via below provided contacts. Additionally, we may also resolve any disputes you have with us in connection with our privacy policies and practices through direct contact.

privacy@whind.com

Date of Last Revision: May 5, 2021