Effective: June 2022
PERSONAL DATA WE COLLECT
YOUR RIGHTS REGARDING PERSONAL DATA
PROTECTING PERSONAL DATA
RETENTION OF PERSONAL DATA
OTHER IMPORTANT INFORMATION ABOUT PERSONAL DATA AND THE SERVICES
MODIFICATIONS AND UPDATES TO THIS PRIVACY NOTICE
APPLICABILITY OF THIS PRIVACY NOTICE
ADDITIONAL INFORMATION AND ASSISTANCE
Rag & Bone Holdings, LLC, and its subsidiaries and affiliates (collectively, “Rag & Bone,” “we,” “us,” “our”) respect your privacy and are committed to protecting the personal data we hold about you. If you have questions, comments, or concerns about this Privacy Notice or our processing of personal data, please see the bottom of this Privacy Notice for information about how to contact us. Rag & Bone Holdings, LLC is the data controller of the personal data collected, and is responsible for the processing of your personal data.
This Privacy Notice explains our practices with respect to personal data we collect and process about you. This includes information we collect through, or in association with, our website with a home page located at www.rag-bone.com, our apps that we may provide, our products and services that we may offer from time to time via our website and/or related apps, our retail stores, our related social media sites, or otherwise through your interactions with us (the website, apps, products, services, stores, and social media pages, collectively, the “Services”).
Please review the following to understand how we process and safeguard personal data about you. By using any of our Services, whether by visiting our website or otherwise, and/or by voluntarily providing personal data to us, you acknowledge that you have read and understand the practices contained in this Privacy Notice. This Privacy Notice may be revised from time to time, so please ensure that you check this Privacy Notice periodically to remain fully informed.
2. PERSONAL DATA WE COLLECT
We collect information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household (“personal data”). In addition, we may collect data that is not identifiable to you or otherwise associated with you, such as aggregated data, and is not personal data. To the extent this data is stored or associated with personal data, it will be treated as personal data; otherwise, the data is not subject to this notice.
a. Categories of Personal Data We Collect
The types of personal data we collect about you depends on your interactions with us and your use of the Services. We collect the following categories of personal data:
1. Identifiers, such as name, email address, social media account handle, phone number, account name, birthday (month and year only), IP address, device identifiers, or other similar identifiers.
2. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code 1798.80(e)), including signature, billing address, shipping address, credit and/or debit card number and expiration date.
3. Characteristics of protected classifications, such as age and gender.
4. Commercial information, including records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies, including transaction history and order number.
5. Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding how our users use, interact with, and navigate the Services (such as website activity, clickstream information, browser information, reference site domain name).
6. Geolocation data, such as through the use of tracking technologies, or when you use our store locator.
a. See the section captioned “Your Choices” for more information about how to disable or limit the collection of location information.
7. Audio, electronic, visual, thermal, olfactory, or similar information, such as photos and/or videos you share when leaving a review, photos of products with issues you provide to customer service or CCTV footage if you visit our stores. If you participate in our market research surveys or studies, we may ask to record or monitor interviews conducted online, by phone, or in-person.
8. Professional or employment-related information (such as in resumes you provide).
9. Inferences drawn from any of the information above to create a profile about a consumer reflecting the consumer’s preferences, characteristics, or behavior (such as purchasing preferences).
We will not collect additional categories of personal data other than those categories listed above. If we intend to collect additional categories of personal data, we will provide you with a new notice at or before the time of collection.
b. How We Use Your Personal Data
We collect and process your personal data for the following purposes:
1. Providing, predicting, or performing, including creating, maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, and processing payments.
2. Marketing our products and services to you, including sending you messages about the products and services we offer, which may include contests, rewards, sweepstakes, loyalty programs, events, and special offers for products and services. These communications may be tailored based on the communications preferences you select when providing us with your information or your activity on the Services, such as an abandoned cart, and will only occur with your prior consent, if such consent is required in accordance with applicable laws.
3. Promoting, advertising, and personalizing your online experience and the advertisements you see when you use the Services or third-party platforms based on your preferences, interests, purchasing history and browsing behavior.
a. Profiling and Automated Decisionmaking. Except to the extent personal data is used by third-party ad networks for online behavioral advertising, neither we, nor service providers on our behalf, engage in profiling or automated decisionmaking activities that produce legal and/or similarly significant effects upon you.
4. Conducting or administering surveys and studies for market research purposes, including contacting you about responding to or participating in our surveys or studies.
5. Communicating with you by email mail, text message (SMS, MMS), telephone, push notification, and other methods of communication, about products, services, new website features, order status, market research opportunities, and information tailored to your requests, comments, suggestions or inquiries.
6. Facilitating your engagement with the Services, including to enable you to post comments and reviews, to engage with other customers, and to post on social media.
7. Auditing related to a current interaction with the consumer and concurrent transactions, including, but not limited to, counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards.
8. Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
9. Debugging to identify and repair errors that impair existing intended functionality.
10. Short-term, transient use, including, but not limited to, the contextual customization of ads shown as part of the same interaction.
11. Undertaking internal research for technological development and demonstration.
12. Undertaking activities to verify or maintain the quality or safety of the services or devices owned, manufactured, manufactured for, or controlled by us, and to improve, upgrade, or enhance the services or devices owned, manufactured, manufactured for, or controlled by us.
13. Complying with applicable laws, regulations, rules and requests of relevant law enforcement and/or other governmental agencies, or for other purposes, as permitted or required by law.
14. As necessary or appropriate to protect the rights, property, health and safety of our users, store visitors, us, and other third parties.
We will not use the personal data we collected for materially different, unrelated, or incompatible purposes without providing you with notice.
c. How We Obtain Your Personal Data
• Directly from you. When you provide it to us directly whether online, by email, phone, or in-person, for example, when you create an account, sign-up to receive emails from us, contact us, or participate in our market research surveys or studies;
• Automatically or indirectly from you. For example, through logging and analytics tools, cookies, pixel tags (such as Google Analytics, Smarter IQ, Action IQ), and as a result of your use of and access to the Services, or through your interactions with us on social media websites.
• From our Service Providers. For example, order processing and fulfillment services, customer service, commercial email providers, security consultants, market research, and other Service Providers we engage.
d. Legal Bases for Processing
We process personal data for, or based on, one or more of the following legal bases:
• Performance of a Contract. We may process personal data to enter into, or perform under, the Terms and Conditions, this Privacy Notice and/or other agreement between us, including processing payment information as part of a purchase or sale and providing customer service and support.
• Legitimate Interests. We may process personal data for our legitimate interests, including providing information about our products and/or services; to the extent necessary and proportionate for the purposes of ensuring the security of our network and information; and for administrative, fraud detection, and legal compliance purposes.
• Compliance with Legal Obligations and Protection of Individuals. We may process personal data to comply with the law and our legal obligations, as well as to protect you and other individuals from certain harms.
• Your Consent. We may process your personal data because you have given us your consent to process it in that manner.
e. Who We Share Your Personal Data With
We share personal data with the following categories of third parties:
• Our Service Providers (further described in the section in this Privacy Notice captioned “How We Obtain Your Personal Data”).
• Our affiliated entities.
• Third parties, such as social media networks and advertising networks (further described in the section in this Privacy Notice captioned “How We Obtain Your Personal Data”).
• Government agencies or regulators when permitted or required to do so by law; in response to a request from a law enforcement agency or authority or any regulatory authority; and/or to protect the integrity of the Services or our interests, rights, property, health or safety, and/or that of our users, visitors and others.
3. YOUR RIGHTS REGARDING PERSONAL DATA
You have certain rights regarding the collection and processing of personal data. You may exercise these rights, to the extent they apply to you, by contacting us at the information provided at the end of this Privacy Notice, or by following instructions provided in this Privacy Notice or in communications sent to you.
Your rights vary depending on the laws that apply to you, but may include:
• The right to know whether, and for what purposes, we process your personal data;
• The right to be informed about the personal data we collect and/or process about you;
• The right to learn the source of personal data about you we process;
• The right to access, modify, and correct personal data about you (see the “Accessing, Modifying, Rectifying, and Correcting Collected Personal Data" section below for more information);
• The right to know with whom we have shared your personal data with, for what purposes, and what personal data has been shared (including whether personal data was disclosed to third parties for their own direct marketing purposes);
• The right to withdraw your consent, where processing of personal data is based on your consent; and
• The right to lodge a complaint with a supervisory authority located in the jurisdiction of your habitual residence, place of work, or where an alleged violation of law occurred.
a. Accessing, Modifying, Rectifying, and Correcting Collected Personal Data
We strive to maintain the accuracy of any personal data collected from you, and will try to respond promptly to update our records when you tell us the information in our records is not correct. However, we must rely upon you to ensure that the information you provide to us is complete, accurate, and up-to-date, and to inform us of any changes. Please review all of your information carefully before submitting it to us, and notify us as soon as possible of any updates or corrections.
If you have an account with us, you may also review, update, modify, and delete your account information, including profile, contact, payment and shipping information, at any time by logging into your account. You may also deactivate your account by emailing firstname.lastname@example.org.
Depending on the laws that apply to you, you may obtain from us certain personal data in our records. If you wish to access, review, or make any changes to personal data you have provided to us through the Services, please contact us at the information provided at the end of this Privacy Notice. We reserve the right to deny access as permitted or required by applicable law.
b. Your California Privacy Rights
California residents, see our “California Privacy Notice” for more information about certain legal rights.
c. Your Nevada Privacy Rights
Nevada law permits our users who are Nevada consumers to request that their personal data not be sold (as defined under applicable Nevada law), even if their personal data is not currently being sold. Requests may be sent to the email to email@example.com, and are free of charge.
d. Your European Union and United Kingdom Privacy Rights
In addition to the above-listed rights, European Union and United Kingdom privacy law provides individuals with enhanced rights in respect of their personal data. These rights may include, depending on the circumstances surrounding the processing of personal data:
• The right to object to decisions based on profiling or automated decisionmaking that produce legal or similarly significant effects on you;
• The right to request restriction of processing of personal data or object to processing of personal data carried out pursuant to (i) a legitimate interest (including, but not limited to, processing for direct marketing purposes) or (ii) performance of a task in the public interest;
• In certain circumstances, the right to data portability, which means that you can request that we provide certain personal data we hold about you in a machine-readable format; and
• In certain circumstances, the right to erasure and/or the right to be forgotten, which means that you can request deletion or removal of certain personal data we process about you.
Note that we may need to request additional information from you to validate your request. To exercise any of the rights above, contact us at firstname.lastname@example.org. If you have an account with us, you may also review, update, and delete certain personal data by logging into your account.
e. Your Canadian Privacy Rights
Residents of Canada are permitted to request and obtain from us information respecting the existence, use, and disclosure of their personal data as well as access to that information (subject to certain exceptions pursuant to applicable laws). Without limiting the above, residents of Canada will, upon request:
• Be informed of whether we hold personal data about you;
• Be provided with an account of third parties to which we have disclosed your personal data;
• Be able to challenge the accuracy and completeness of your personal data and have it amended as appropriate; and
• Be provided with information about our policies and practices with respect to the management of personal data, including: the name or title, and address, of the person who is accountable for our privacy policies and practices; the means of gaining access to personal data; a description of the type of personal data held by us, including a general account of its use; a copy of any brochures or other information that explain our policies, standards, or codes; and what personal data is made available to related organizations.
4. YOUR CHOICES
You have choices about certain information we collect about you, how we communicate with you, and how we process certain personal data. When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services. In addition, it is possible to change your browser settings to block the automatic collection of certain information.
a. Communications Opt-Out. You may opt out of receiving marketing or other communications from us at any time through a given communications channel (such as email or telephone) by following the opt-out link or other unsubscribe instructions provided in any email message received, by contacting us as provided at the end of this Privacy Notice. If you wish to opt out by sending us an email to the address provided below, please include “Opt-Out” in the email’s subject line and include your name and the email address you used to sign up for communications in the body of the email.
Note that if you do business with us in the future, you may not, subject to applicable law, opt out of certain automated notifications, such as order or subscription confirmations, based on business transactions (e.g., e-commerce).
b. Text Message Opt-Out. If you choose, you can provide your mobile phone number to receive text message alerts from us to receive product and/or event information, promotional offers and more. These messages may use information automatically collected based on your actions while on our sites and may prompt messaging such as cart reminders. To the extent you voluntarily opt to have text message notifications sent directly to your mobile phone, we receive and store the information you provide, including your telephone number or when you read a text message. Consent is not required to purchase goods or services.
You can opt out from further text marketing communications at any time by texting “STOP” to our text messages. Please see our Terms & Conditions for additional information and terms that apply to our text message program.
c. Location Information. If you want to limit or prevent our ability to receive location information from you, you can deny or remove the permission for certain Services to access location information or deactivate location services on your device. Please refer to your device manufacturer or operating system instructions for instructions on how to do this.
d. Cookies, Web Tracking, and Advertising. Consult our Cookie Notice for more information about how to control and/or opt out of certain web tracking technologies and/or advertising providers from collecting information about you.
5. PROTECTING PERSONAL DATA
We use reasonable and appropriate physical, technical, and organizational safeguards designed to promote the security of our systems and protect the confidentiality, integrity, availability, and resilience of personal data. Those safeguards include: (i) the pseudonymization and encryption of personal data where we deem appropriate; (ii) taking steps to ensure personal data is backed up and remains available in the event of a security incident; and (iii) periodic testing, assessment, and evaluation of the effectiveness of our safeguards.
However, no method of safeguarding information is completely secure. While we use measures designed to protect personal data, we cannot guarantee that our safeguards will be effective or sufficient. In addition, you should be aware that Internet data transmission is not always secure, and we cannot warrant that information you transmit utilizing the Services is or will be secure.
6. RETENTION OF PERSONAL DATA.
We retain personal data to the extent we deem necessary to carry out the processing activities described above, including but not limited to compliance with applicable laws, regulations, rules and requests of relevant law enforcement and/or other governmental agencies, and to the extent we reasonably deem necessary to protect our and our partners’ rights, property, or safety, and the rights, property, and safety of our users and other third parties.
Your personal data will not be kept in a form that allows you to be identified for any longer than we reasonably consider necessary to accomplish the purposes for which it was collected or processed, or as permitted or required by applicable laws related to data retention. Thereafter, as a general matter, your personal data will be archived and stored to be used and otherwise processed in the event of legal or regulatory requirements, statutes of limitations, disputes, or actions, and will be stored and, if applicable, used and otherwise processed until reasonably after the end of any such requirement, limitation, dispute, or action, including any potential periods of review or appeal.
Thereafter, your personal data will be anonymized, deleted or archived as permitted by applicable law.
7. OTHER IMPORTANT INFORMATION ABOUT PERSONAL DATA AND THE SERVICES.
a. Collection of Personal Data from Children. Children under 16 years of age are not permitted to use the Services, and we do not knowingly collect information from children under the age of 16. By using the Services, you represent that you are 18 years of age or older, or are 16 years of age or older and have valid parental consent to do so.
b. Third-Party Websites and Services. As a convenience, we may reference or provide links to third-party websites and services, including those of unaffiliated third parties, our affiliates, service providers, and third parties with which we do business. When you access these third-party services, you leave our Services, and we are not responsible for, and do not control, the content, security, or privacy practices employed by any third-party websites and services. You access these third-party services at your own risk. This Privacy Notice does not apply to any third-party services; please refer to the Privacy Notices or policies for such third-party services for information about how they collect, use, and process personal data.
c. Business Transfer. We may, in the future, sell or otherwise transfer some or all of our business, operations or assets to a third party, whether by merger, acquisition or otherwise. Personal data we obtain from or about you via the Services may be disclosed to any potential or actual third-party acquirers and may be among those assets transferred.
d. Do Not Track. We use analytics systems and providers and participate in ad networks that process personal data about your online activities over time and across third-party websites or online services, and these systems and providers may provide some of this information to us. We do not currently process or comply with any web browser’s “do not track” signal or similar mechanisms.
Note, however, that you may find information about how to opt out of and/or block or reject certain tracking technologies in our Cookie Notice.
e. International Use. Your personal data will be stored and processed in the United States and other locations where we have engaged service providers. If you are using the Services from outside the United States, by your use of the Services you acknowledge that we will transfer your data to, and store your personal data in, the United States, which may have different data protection rules than in your country, and personal data may become accessible as permitted by law in the United States, including to law enforcement and/or national security authorities in the United States. For transfers of data into and out of the European Economic Area and/or the United Kingdom, pursuant to Article 46 of the General Data Protection Regulation, we use standard contractual clauses to provide appropriate safeguards.
8. MODIFICATIONS AND UPDATES TO THIS PRIVACY NOTICE
This Privacy Notice replaces all previous disclosures we may have provided to you about our information practices with respect to the Services. We reserve the right, at any time, to modify, alter, and/or update this Privacy Notice, and any such modifications, alterations, or updates will be effective upon our posting of the revised Privacy Notice. We will use reasonable efforts to notify you in the event material changes are made to our processing activities and/or this Privacy Notice, such as by posting a notice on the Services or sending you an email. Your continued use of the Services following our posting of any revised Privacy Notice will constitute your acknowledgement of the amended Privacy Notice.
9. APPLICABILITY OF THIS PRIVACY NOTICE
This Privacy Notice is subject to any agreements, including the Terms and Conditions that govern your use of the Services. This Privacy Notice applies regardless of the means used to access or provide information through the Services.
This Privacy Notice does not apply to information from or about you collected by any third-party services, applications, or advertisements associated with, or websites linked from, the Services. The collection or receipt of your information by such third parties is subject to their own privacy policies, statements, and practices, and under no circumstances are we responsible or liable for any third party’s compliance therewith.
10. ADDITIONAL INFORMATION AND ASSISTANCE
If you have any questions or concerns about this Privacy Notice and/or how we process personal data, please contact us at:
Rag & Bone
425 W.13th Street
New York, NY 10014
If you are located in the European Union, European Economic Area or the United Kingdom, and you wish to raise a concern regarding our use of your personal data, you have the right to do so with your local supervisory authority.