Last Updated: 12/01/2023
Effective Date: 12/01/2023
- Personal Data We Collect
- Sources from Which Personal Data is Collected
- Purposes for Collecting Personal Data
- Legal Grounds for Collecting and Processing Personal Data
- Third-Party Recipients of Personal Data
- Cookies & Similar Technologies
- Interest-Based Advertising
- Third-Party Privacy Practices
- Cross-Border Transfers of Personal Data
- Children’s Privacy
- Retention of Personal Data
- Protecting Your Personal Data
- GDPR Rights
- Privacy Shield Rights
- Other Rights
- Updating Account Information and Unsubscribing from Emails
- Exercising Privacy Rights
- Data Controller
- How to Contact Us
We may collect the following categories of personal data:
- Personal Identifiers/Contact Information, such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol ("IP") address, email address, phone number (including mobile numbers), date of birth, gender, account name, signature, or other similar identifiers.
- Financial Information/Payment Data, such as credit card number, debit card number, or other similar information.
- Purchase Histories and Other Commercial Information, such as products purchased, obtained, or considered, and other purchasing or consuming histories or tendencies.
- Internet or Other Similar Network Activity, such as browsing history, search history, and information concerning your interactions with a website, application, or advertisement.
- Biometric Data, such as height, body type, or other sizing information if you choose to complete a product review.
- Sensory Data, such as audio, electronic, visual, or similar information.
- Professional or Employment-Related Information, such as occupation if you choose to complete a product review.
- Your Correspondence and Communications with Peruvian Connection including your comments sent to us via email, chat, phone, or on social media.
- Communication and Marketing Preferences such as your preferred channels of communication, and whether or not you opt in to receive marketing materials.
- Publicly Available Personal Data, including personal data you have shared via a social media platform (e.g., a public Facebook page).
- Information Concerning an Individual’s Preferences and Interests and Inferences Drawn from an Individual’s Personal Data to create a profile about an individual reflecting his/her preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, or aptitudes.
We may collect the above-described categories of personal data from one or more of the following sources:
- Information You Provide. We collect personal data that you provide to us, such as when you create an account on our Sites, purchase a product from us, leave a review on a product, agree to receive our newsletter, or participate in a survey that we offer.
- In-Store Technologies. We may use cameras in and around our stores for fraud, theft prevention, and security purposes.
- Automated Information Collection. We also collect personal data, such as your browsing history and shopping activity, through our use of automated information collection technologies. We may use such data for various purposes, including marketing and advertising purposes and reporting and analytics purposes. For example, we consider metrics such as how you and others shop on our website, how easy our website is to navigate, and the performance of our marketing efforts. For additional information, see the Cookies & Similar Technologies and Interest-Based Advertising sections of this Policy.
- Your Friends. We may receive information about you from your friends and other third parties that use our Sites, and we may combine or link that information with other information we have concerning you (e.g., fulfillment of a wish list).
- Third-Party Service Providers. We may receive personal data about you from our third-party service providers, such as marketing networks and cooperatives, analytics providers, and online chat service providers.
- Other Third Parties. We may collect personal data about you from other sources to enhance the personal data that we already maintain about you and to improve the accuracy of our records. This improves our ability to contact you and increases the relevance of our marketing. We also may collect personal data from third parties or from publicly available sources.
We may collect the above-described categories of personal data for one or more of the following business or commercial purposes:
- To provide you with requested products and services, including processing and shipping orders; verifying your payment information; processing payments, refunds, and chargeback claims; maintaining and servicing your account(s); providing you with catalogs; and providing you with product recommendations.
- To manage your orders and returns, including creating, modifying, and canceling orders and returns and verifying your identity and payment information.
- To manage your account with us if you choose to create one.
- To complete a credit check if you choose to pay by accounts receivable.
- To communicate with you, such as when you place an order, contact or chat with us, make a request or inquiry, or share comments or concerns; or to send you coupons, emails, and newsletters or otherwise inform you of promotions, product rating opportunities, competitions, drawings, and sweepstakes.
- To administer promotions, competitions, drawings, sweepstakes, and surveys.
- To personalize your experience with us, including to retain information about your interests and preferences; customize the products and services we share with you; facilitate your interactions with our stylists and salespeople; and enrich your experience in our stores and on our Sites.
- For marketing and advertising purposes, such as to send you marketing and advertising communications, and to customize the specific advertisements and promotions that we send or otherwise show to you. For additional information, please review the sections of this Policy on Cookies & Similar Technologies and on Interest-Based Advertising.
- To conduct analytics to understand how users use our Sites and shop with us; determine the methods and devices used to access our Sites; enhance our products; and make improvements to our Sites.
- For our business purposes, such as identifying and implementing improvements to our business operations, products, services, systems, supply chain, and store premises; creating and maintaining our programs, accounts, and records; collecting and managing consent; gaining insights into our customer preferences, expectations, and trends; and conducting market and other business-related research.
- To provide interactive features of our Sites, such as product reviews and live online chats.
- To provide you with technical support and customer service.
- To protect our customers, users, visitors, assets and business against violence, fraud, theft, misuse, and other malicious activities.
- To detect, analyze, and prevent safety risks, fraudulent activities, and other illegal and malicious activities (e.g., theft).
- To meet our regulatory reporting requirements and comply with our legal and regulatory obligations, including those that require businesses to maintain specified records.
- To respond to law enforcement requests, to meet obligations in legal proceedings and government investigations, and as otherwise required by applicable law, court order, or government regulations.
- To provide information pertinent to an actual or potential merger, acquisition, or other reorganization.
- As necessary or appropriate to protect the rights, property, or safety of Peruvian Connection, our customers, or others.
- As otherwise described to individuals when collecting their personal data.
- Consent. The legal ground for processing your personal data that we collect when you provide us with permission to do so is your consent, which you may withdraw at any time by clicking on any unsubscribe link that we provide or by emailing email@example.com without affecting the lawfulness of processing based on consent before its withdrawal.
- Contractual Necessity. We may process your personal data when it is necessary in order to take steps at your request prior to entering into a contract with you (e.g., processing personal data in order to respond to a question about a particular product) or when it is necessary for the performance of a contract to which you are a party (e.g., processing credit card details in order to effect payment).
- Compliance with Legal Obligations. We also may conduct certain personal data processing activities for purposes of meeting our legal obligations in the UK, the EU, and in EU member states (e.g., in order to meet our regulatory retention obligations). Under certain circumstances, we may also be legally obliged to assist with crime and fraud prevention efforts.
- Vital Interests. Under special circumstances (e.g., in connection with natural disasters or emergency situations), we may need to process your personal data in order to protect the vital interests of you or one or more persons.
- Legitimate Interests. The last legal ground for processing the personal data that we collect for other purposes identified above are Peruvian Connection’s legitimate interests in conducting business activities, including the following:
- Providing products and services to customers;
- Providing quality support to customers, potential customers, and Site users;
- Providing customers and potential customers with marketing materials to promote our services and products;
- Providing more relevant content for users of our Sites;
- Identifying and fixing problems with our Sites;
- Understanding how our customers interact with our products, services, and Sites so we can enhance the customer experience and functionality of our products, services, and Sites;
- Improving the overall user experience on our Sites;
- Administering promotions, competitions, drawings, sweepstakes, and surveys;
- Managing our network and store security;
- Operating our business, including by identifying and implementing improvements to our business operations; creating and maintaining our programs, accounts, and records; and conducting business-related research;
- Protecting the rights, property, or safety of Peruvian Connection, our customers, our employees, and/or others;
- Managing corporate transactions, including providing information pertinent to an actual or potential merger, acquisition, or other reorganization; and
- Maintaining compliance with applicable global laws and regulations.
- Social Media Platforms. Social Media Platforms (e.g., Facebook, Instagram, YouTube, and Pinterest) may offer functionalities, plugins, widgets, or tools in connection with our Sites (e.g., to share our products with your friends and followers on Social Media Platforms). If you choose to use these functionalities, plugins, widgets, or tools, your personal data may be shared with or collected by such Social Media Platforms, and is subject to such Social Media Platforms’ privacy practices and you should review such Social Media Platforms’ privacy notices.
- Your Friends. We share your wish list information with individuals that you designate when you use our Site’s wish list sharing functions. Additionally, if you choose to make your wish list public, individuals may find your wish list using our Site’s "find a friend’s wish list" function.
- Our Site Visitors and Online Trunk Show Participants. When you leave a product review on our Sites, your review is accessible by other members of the public when they visit our Sites. When you choose to participate in an online trunk show hosted by our stylists, your personal information may be shared with and viewed by other online trunk show participants.
- Third-Party Recipients of Customer Lists. We make our customer list (including names, customer IDs, mailing addresses, email addresses, and phone numbers) available to third-party service providers assisting us with marketing efforts.
From time to time, we also make our customer list (including names, customer IDs, mailing addresses) and purchasing history available to list brokers and retailers whose products we believe may be of interest to you. As one example, we work with Epsilon Abacus ("Epsilon"), a company that manages the Abacus Alliance on behalf of participating retailers active in the clothing, collectibles, food, wine, gardening, gadgets, entertainment, health, beauty, household goods, and home interiors categories. Retailers share customer information with Epsilon, which is then combined with information provided by other retailers, analyzed by Epsilon, and used for marketing purposes. Retailers can utilize this information to identify individuals who are likely to be interested in their products, and to tailor their communications to such individuals by providing them with offers likely to be of interest to them.
If you place an order with us, you will have the option to have your name, mailing address, and purchasing history shared with companies whose products may be of interest to you, as described above. If you would like to have your information shared with these companies, please tick the opt-in box when you place your order. If you do not want to have your information shared, please leave the opt-in box blank. Additionally, if at any point in time you decide that you do not want your information shared, you can request that we do not share information with these companies by contacting us using the contact methods described in the Exercising Privacy Rights section below.
- Third Parties in Connection with a Competition, Sweepstakes, or Drawing. If you choose to enter a competition, sweepstakes, or drawing that we offer on our Sites, your personal data may be disclosed to third parties or to the public in connection with the administration of such competition, sweepstakes, or drawing, including in connection with winner selection, prize fulfillment, and as required by law or permitted by the competition, sweepstakes, or drawing’s terms and conditions.
- Third-Party Service Providers, Partners, Suppliers, and Subcontractors that Perform Services on Our Behalf. We may share personal data with third-party service providers, partners, suppliers, and subcontractors that perform services on our behalf, including but not limited to billing and payment processing, marketing, advertising, data analysis and insight, research, web hosting, technical support, customer service, online text and video chat, shipping and fulfilment, printing, data storage, security, fraud prevention, and legal services.
- Governmental Entities and Third Parties in Connection with Legal Matters. We may disclose personal data to governmental entities, such as regulatory agencies, law enforcement, and judicial authorities, as well as other third parties under any of the following conditions: (a) if we have your valid consent to do so; (b) to comply with a valid subpoena, legal order, court order, warrant, legal process, or other legal obligation, including to meet national security or law enforcement requirements; (c) to enforce or apply any of our terms and conditions, policies, or other agreements; (d) to exchange information with other companies and organizations for the purposes of fraud protection and credit risk reduction; or (e) as necessary to pursue available legal remedies or defend legal claims.
- Third Parties in Connection with a Potential Reorganization. We may share personal data to a prospective seller or buyer in the event of a potential reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of Peruvian Connection’s assets or stock, including, without limitation, in connection with any bankruptcy or similar proceeding.
As you interact with our Sites, we, with assistance from third-party analytics service providers, collect personal data pertaining to your use of our Sites and the devices and programs from which you access our Sites ("Usage Data") using cookies and similar technologies.
- What are cookies?
- Cookies are small computer files sent or accessed from your browser on the hard drive of your computer, mobile device, or tablet that contain information about your computer, such as your user ID, user settings, browsing history, and activities conducted while browsing websites (e.g., pages viewed; navigation around a Site; and products purchased).
- Cookies are used to "remember" when your computer or devices access our Sites.
- The primary purposes for which cookies are used are: (1) For the effective operation of our Sites, especially in connection with Site navigation and online transactions; (2) For purposes of Interest-Based Advertising, which is addressed in the next section of this Policy; (3) To assist Peruvian Connection in detecting and preventing fraud; (4) To monitor the success of our advertising campaigns and marketing-related activities (e.g., promotions); and (5) To enable Peruvian Connection to meet its contractual obligations to third parties when one or more of our products are purchased by someone who has visited our Site from a site operated by such third parties.
- How can you manage cookies?
- To assist in controlling site-specific cookies, check the privacy and cookie settings in your preferred browser.
- If you are in the United Kingdom, the European Union, or another country that requires your consent before processing your Usage Data, we process your Usage Data based on the consent you provide when you click the box noting that you "agree" to the processing of your personal data obtained through cookies and other data collection tools. You may withdraw your consent by contacting us via email at firstname.lastname@example.org.
Like many retailers, Peruvian Connection works with third parties ("Advertising Partners"), including Social Media Providers and search engines, such as Google (e.g., Google Ads), who serve or send advertisements on our behalf and assist us in delivering more relevant advertising to you. These Advertising Partners may place or recognize a cookie or similar technology on your computer, device, or directly in our emails/communications, and collect information, such as Usage Data and demographic or shopping information. We may share personal data (such as your email address) with such third parties, who may link this information to cookies and other proprietary IDs, which are used for purposes of predicting your preferences and sending interest-based advertising in order to show you ads that are more likely to be of interest to you. These third parties may use this information to recognize you across different channels and platforms over time to assist us with our operations including for advertising, analytics, attribution, and reporting purposes. These third parties Advertising Partners are responsible for all processing of personal data that they conduct as Controllers, including international transfers of personal data (if any).
Our Sites may provide links to other third-party Internet websites as a service to you. We are not responsible for the privacy practices of such other third-party Internet websites. If you link to such a site through our Sites, you should always review any privacy notice that is available for that site.
When you use our Sites or we otherwise receive your personal data, your personal data may be stored on servers located outside of the European Union/European Economic Area ("EU/EEA") and UK. Your personal data may be transferred to and processed by Peruvian Connection and its third-party service providers, partners, suppliers, and subcontractors not only in the EU/EEA and UK, but also in the United States. The data protection and privacy laws of the United States may not be as comprehensive as the laws of your country. For example, personal data transferred to the United States may be subject to lawful access requests by U.S. federal and state authorities. For transfers of UK and EU/EEA personal data to service providers in the United States, which has not been deemed to provide an adequate level of data protection for personal data by appropriate regulatory authorities, Peruvian Connection will rely on Standard Contractual Clauses as the lawful transfer mechanism to support such transfers.
Peruvian Connection is committed to subject to the Privacy Shield Principles all personal data received from the European Union or Switzerland pursuant to the Privacy Shield Principles. Peruvian Connection will remain responsible for any processing of personal data in a manner inconsistent with the Privacy Shield Principles by third-party agents to which Peruvian Connection has transferred personal data unless Peruvian Connection proves it is not in any way responsible for the event giving rise to any damage.
- Email: email@example.com
- Mail: Peruvian Connection, LLC
Tonganoxie, KS 66086
- Phone: 0800 072 14 14 (UK); or +44 (0)1235 515 497 (other European countries)
Peruvian Connection has further committed to refer unresolved Privacy Shield complaints to the JAMS Privacy Shield Program, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit the JAMS Privacy Shield Program for more information or to file an online complaint. You may also contact JAMS at firstname.lastname@example.org or file a complaint by mail at:
18881 Von Karman Ave.
Irvine, CA 92612
Attn: Sheri Eisner, General Counsel
The services of the JAMS Privacy Shield Program are provided at no cost to you. Additionally, under certain conditions you may invoke binding arbitration for Privacy Shield complaints that are not resolved by any of the other Privacy Shield dispute resolution mechanisms. For additional information, please see Privacy Shield Annex I.
Our Sites are not directed to individuals under the age of 16. We do not knowingly collect or use any personal information from users under 16 years of age. No personal information should be submitted to our Sites by visitors under 16 years of age. If we learn that we have collected personal information from someone under 16, we will take steps to delete the personal information as soon as possible.
Peruvian Connection will retain your personal data for the time period necessary to fulfill the purposes for which your personal data was originally collected or received and to meet our legal obligations.
We implement technical and organizational measures designed to assist in maintaining the security and confidentiality of personal data; safeguarding against anticipated threats to the confidentiality, integrity, and availability of personal data; and protecting your personal data against accidental or unlawful destruction, loss, alteration, and unauthorized access or disclosure.
However, whenever personal data is processed, there is always a risk that such information could be lost, misused, modified, hacked, breached, and/or otherwise accessed by an unauthorized third party. No system or online transmission of data is completely secure. In addition to the technical and organizational measures that we have in place to protect your personal data, you should use appropriate security measures to protect your personal data. If you believe that any personal data you provided to us is no longer secure, please notify us immediately by phone at 0800 072 14 14 (UK), 0800 181 6326 (Germany), or +44 (0)1235 515 497 (other European countries); or by email at email@example.com.
If you reside in the European Union or the United Kingdom, you have the following rights under the General Data Protection Regulation ("GDPR") or the UK GDPR (as applicable) regarding the processing of your personal data:
- Right to Request Access. You have the right to receive a copy of the personal data that we hold about you.
- Right to Rectification. You have the right to correct or complete any inaccurate or incomplete personal data that we hold about you.
- Right to Deletion. In certain circumstances, you have the right to request that we erase the personal data that we hold about you.
- Right of Data Portability. In certain circumstances, you have the right to request that we supply you with the personal data that we hold about you in a structured, commonly used and machine-readable format and/or, where technically feasible, to transmit such personal data to another organization.
- Right to Restrict Processing. In certain circumstances, you have the right to restrict our processing of the personal data that we hold about you.
- Right to Bring a Complaint to Supervisory Authority. You have the right to lodge a complaint with the relevant supervisory data protection authority.
- Right to Withdraw Consent. If our lawful basis for processing your personal data is your consent, you have the right to withdraw your consent at any time.
- Right to Object. You have the right to object to the processing of your personal data for certain purposes, including:
- Processing for Direct Marketing Purposes. The right to object to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing; and
- Processing for Legitimate Interests. The right to object to the processing of your personal data that is based on our or a third party’s legitimate interests, including profiling related to such legitimate interests.
If you reside in the European Union or Switzerland, and if Peruvian Connection processes your personal data in the United States, you also have the following rights under the Privacy Shield:
- Right to Access, Correct, Amend, or Delete. You have the right to access and to correct, amend, or delete your personal data where it is inaccurate or where it has been processed in violation of the Privacy Shield Principles, except where the burden or expense of providing access would be disproportionate to the risks to your privacy or where the rights of other individuals would be violated.
- Right to Choose. You have the right to receive notice of the choices and means that Peruvian Connection offers you for limiting the use and disclosure of your personal data. Peruvian Connection provides you with the opportunity to choose how your personal data may be used under certain circumstances. If your personal data is to be used for a new purpose that is materially different from that for which your personal data was originally collected or subsequently authorized, or if your personal data is to be disclosed to a third-party controller, Peruvian Connection will provide you with an opportunity to choose whether to have your personal data so used or disclosed. When sharing your personal data with third-party processors that Peruvian Connection has retained to perform services on its behalf and pursuant to its instructions, Peruvian Connection may disclose your personal data without offering an opportunity to opt out.
- Rights Related to Sensitive Data
- "Sensitive Data" under the EU-U.S. Privacy Shield Framework is defined as personal data specifying medical or health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or information specifying the sex life of an individual.
- "Sensitive Data" under the Swiss-U.S. Privacy Shield Framework is defined as personal data specifying medical or health conditions, personal sexuality, racial or ethnic origin, political opinions, religious, ideological or trade union-related views or activities, or information on social security measures or administrative or criminal proceedings and sanctions, which are treated outside pending proceedings.
- If Peruvian Connection ever collected your Sensitive Data, Peruvian Connection would provide you with specific rights related to any Sensitive Data that Peruvian Connection may process. Additionally, if any such Sensitive Data were to be used for a new purpose that is different from that for which it was originally collected or subsequently authorized, or is to be disclosed to a third party, Peruvian Connection would obtain your affirmative express consent prior to such use or such disclosure.
In this section, we provide an explanation of our processes for permitting individuals to update their account information and opt out of marketing emails.
- Unsubscribing from Emails. You may opt-out of Peruvian Connection’s use of your personal data for purposes of marketing emails. Every marketing email you receive from Peruvian Connection will have an unsubscribe link at the bottom that enables you to opt-out of receiving future Peruvian Connection marketing email messages. Our customer service team can also assist with any requests to opt-out if you contact them using the contact information below.
- Submission Methods. You may submit requests to exercise your privacy right(s) by:
- Calling us at 0800 072 14 14 (UK); or +44 (0) 1235 515 497 (other European countries); or
- Emailing us at firstname.lastname@example.org.
- Submission Contents. Requests to exercise your privacy right(s) should include the following information:
- Your name;
- The country in which you currently reside;
- Which privacy right(s) you are exercising;
- Details that will assist us in responding to your request, including:
- If you are exercising access rights, the information to which you are requesting access;
- If you are exercising deletion rights, the information for which you are requesting deletion;
- Any other relevant information about your personal data and/or the right you are exercising; and
- A phone number and/or email address at which we can reach you.
Personal data used by Peruvian Connection for its business purposes, as well as personal data collected by and on behalf of Peruvian Connection, is controlled by:
Peruvian Connection, LLC
Tonganoxie, KS 66086