Last Revised and Effective Date: January 1, 2023
Michiboowhite, LLc. and our subsidiaries and affiliates (collectively, “MICHIBOOWHITE “we”, “us” or “our”) care about the processing, confidentiality, and safety of your personal data.
The aim of this Privacy Policy is to provide you with information about how we collect, use, share, and safeguard your personal data. This Privacy Policy also tells you about your rights and choices with respect to your personal data, and how you can reach us to get answers to your questions. You can jump to particular topics by going to the headings below:
I. What is personal data?
The term “personal data” refers to any information about an identified physical person or a physical person that may be directly or indirectly identified.
II. What personal data do we collect and when do we collect it
We collect information about you in a variety of ways depending on how you interact with us and our products and services, including through our websites, media channels, online and mobile applications, advertisements, and in selected stores.
Context | Information We Collect | Primary Purpose for Collection and Use of Information |
---|---|---|
Create a customer account | If you create a customer account on one of our websites, apps, or in one of our stores, we collect your name, email address, and the month and day of your birthday, if you choose to provide it. Within your customer account, you can also store additional information such as mailing address, phone number, and payment methods. We also collect information relating to the actions that you perform while you are logged into your account. | We have a legitimate interest in providing account related functionalities to our customers and managing access to customer accounts. Customer accounts can be used for faster and simpler checkout, to save your personal preferences and order history, and receive updates about your order details |
Order goods from our websites | If you place an order on one of our websites, we collect your name, email address, phone number, shipping address, billing address and payment details (payment card number, expiration date, CVV/CVC, etc.). | We use your information to perform our contract with you to process your orders and to provide you with the products or services you have requested. |
Make purchases in our stores | If you make a purchase in one of our stores, we may collect your name, email address, billing address and payment details (payment card number, expiration date, CVV/CVC, etc.). | We use your information to perform our contract with you to provide you with the products you have requested. |
Shade finder and other similar online beauty services | You may choose to upload a photo or video (via your webcam). Unless otherwise noted, we only use photographs to identify skin tone and/or make cosmetic recommendations. | We share information about our products, services, offers, news and events with those individuals that consent to receive such information. We also have a legitimate interest in sharing information about our products or services |
Sign up for our mailing list | When you sign up for one of our mailing lists, we collect your email address, phone number, or postal address, depending on your selection. | We share information about our products, services, offers, news and events with those individuals that consent to receive such information. We also have a legitimate interest in sharing information about our products or services. |
Participate in surveys | If you choose to participate in a survey or satisfaction questionnaire, we collect information that you provide through the survey. If the survey is provided by a third-party service provider, the third party’s privacy policy applies to the collection, use, and disclosure of your information. | We have a legitimate interest in understanding your opinions, and collecting information relevant to our organization. |
Contact us | If you contact us, such as via our website, customer service center, or social network pages, we collect your name, contact information (email and/or phone number) as well as any other information you provide to us in order to reply. | We have a legitimate interest in managing customer relations with respect to any requests for information or complaints that we receive. We also have a legitimate interest in responding to inquiries related to support, employment opportunities, and other requests. |
Report potential adverse reactions | If you contact us to notify us of an undesirable reaction concerning any of our products, we collect your name, contact information, as well as any other information you provide to us, including specific health data if you choose to provide it. | We have a legitimate interest in receiving, processing, following up, and responding to, your reports as part of our cosmetic vigilance obligations. In some jurisdictions, we are also required by law to record information related to product safety and adverse event reports. We have a legitimate interest in complying with all legal requirements to collect information in the countries in which we operate. |
Interact with us on social networks | If you interact with us through our official page on social networks, or if you publish content on a social network or participate in online forums, we collect any content that you choose to provide, which may include your social media handle or account profile. | We have a legitimate interest in communicating with you, understanding your opinions, and providing tailored services and products. |
Take part in an event, sweepstakes, contest, or promotion | If you take part in an event, sweepstakes, contest, or other similar promotion, we collect information about you including your name and contact information. | We have a legitimate interest in operating and managing participation in our events, sweepstakes, contest, and other similar promotions. In some jurisdictions, we are also required by law to collect information about those that enter into our sweepstakes. We have a legitimate interest in complying with all legal requirements to collect information in the countries in which we operate. |
Context | Information We Collect | Primary Purpose for Collection and Use of Information |
---|---|---|
Cookies and First Party Tracking | We use cookies and other technologies to understand how people use our websites. For more information about cookies, please see the COOKIES AND SIMILAR TRACKING TECHNOLOGY” section below. | We have a legitimate interest in making our websites operate efficiently. We also have a legitimate interest in serving you targeted advertisements. Where required by law, we will obtain your consent for the deployment of cookies on our websites. |
Cookies and Third Party Tracking | We may place tracking technology on our website that collects analytics, records how you interact with our website, or allows us to participate in behavior-based advertising. This means that a third party uses technology (e.g., a cookie) to collect information about your use of our website so that they can report analytics to us or provide advertising about products and services tailored to your interests. That third party might also collect information over time and across different websites in order to serve advertisements on our website, or on other websites. For more information about cookies, please see the “COOKIES AND SIMILAR TRACKING TECHNOLOGY” section below. | We have a legitimate interest in engaging in behavior-based advertising and capturing website analytics. Where required by law, we will obtain your consent for the deployment of cookies on our websites. |
Web beacons, clear pixels, or pixel tags | A “web beacon” (also called a pixel tag or a clear GIF) is a small graphic image placed on website pages, e-mails, advertising, and other marketing communications that can be used for such things as recording the pages and advertisements clicked on by users or tracking the performance of e-mail marketing campaigns. This may also include information about your device or browser. | We have a legitimate interest in understanding how you interact with our websites to better improve them, and to understand your preferences and interests in order to select offerings that you might find most useful. We have a legitimate interest in understanding the effectiveness of our features and advertising, as well as interactions with our e-mail and advertising. We also have a legitimate interest in detecting and preventing fraud. |
Web logs | We collect information, including your browser type, operating system, Internet Protocol (IP) address (a number that is automatically assigned to a computer when the Internet is used), domain name, click-activity, referring website, and/or a date/time stamp for visitors. | We have a legitimate interest in monitoring our networks and the visitors to our websites. Among other things, it helps us understand which of our services is the most popular. |
III. For what purpose is your personal data collected and used?
In addition to the purposes and uses described above, we use data in the following ways:
Although the sections above describe our primary purpose in collecting your personal data, in many situations we have more than one purpose. For example, if you complete an online purchase, we collect your personal data to perform our contract with you, but we also collect your personal data as we have a legitimate interest in maintaining your information after your transaction is complete so that we can quickly and easily respond to any questions about your order. As a result, depending on the requirements of applicable privacy laws, our collection and processing of your personal data is based in different contexts upon your consent, our need to perform a contract, our legal or regulator obligations, and/or our legitimate interest in conducting our business.
IV. Who are the recipients of your personal data
In addition to the specific situations discussed elsewhere in this Privacy Policy, we share personal data in the following situations:
V. International transfers of personal dat
As a multi-national company, we transmit information between and among our affiliates and may also use service providers that are located outside of your country of residence. As a result, your personal data may be processed in a foreign country where privacy laws may be less stringent than the laws in your country. Nonetheless, where possible we take steps to treat personal data using the same privacy principles that apply pursuant to the law of the country in which we first received your information. By submitting your personal data to us you agree to the transfer, storage and processing of your information in a country other than your country of residence including, but not necessarily limited to, the United States.
All data transfers are subject to appropriate safeguards to ensure compliance with applicable regulations relating to the protection of personal data. For example, all transfers of personal data to our affiliates outside of the EEA are based on the EU Commission’s standard contractual clauses. If you would like more information concerning our attempts to apply the privacy principles applicable in one jurisdiction to data when it goes to another jurisdiction you can contact us using the contact information below.
VI. How do we protect your personal data
No method of transmission over the Internet, or method of electronic storage, is fully secure. While we use reasonable efforts to protect your personal data from unauthorized access, use, or disclosure, we cannot guarantee the security of your personal data. In the event that we are required by law to inform you of a breach to your personal data we may notify you electronically, in writing, or by telephone, if permitted to do so by law.
Some of our websites permit you to create an account. When you do you will be prompted to create a password. You are responsible for maintaining the confidentiality of your password, and you are responsible for any access to or use of your account by someone else that has obtained your password, whether or not such access or use has been authorized by you. You should notify us of any unauthorized use of your password or account.
VII. How long do we retain your personal data
Typically, we retain your personal data for the period necessary to fulfill the purposes outlined in this Privacy Policy, including for the purposes of satisfying any legal, accounting, or reporting requirements, unless a longer retention period is required or permitted by law. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure of the information, the purposes for which we obtained the information and whether we can achieve those purposes through other means, as well as applicable legal requirements.
VIII. What are your choices and how can you exercise them
You may have the following choices regarding your personal data:
Please note that not all of the rights described above are absolute, and they do not apply in all circumstances. In some cases, we may limit or deny your request if the law permits or requires us to do so, or if we are unable to adequately verify your identity. We will not discriminate against individuals who exercise any of their privacy rights under applicable law. If you disagree with how we handled a request, you may appeal our decision by contacting us at the address described in the CONTACT DETAILS section below with the subject line "Appeal."
To protect your personal data, we must be able to verify your identity before we can process your request to exercise any of the choices described in this section. We may conduct the verification process by email or phone, and we will ask you to provide information such as your name, contact information, and any additional relevant information based on your relationship. We will then match this to the information we maintain in our records.
In some circumstances, certain individuals may designate an authorized agent to submit requests to access or delete personal data. We will require verification that the authorized agent has permission to make such a request.
IX. Cookies and Similar Tracking Technologie
We use a variety of technologies such as cookies, web beacons, clear GIF, pixels, internet tags, and browser/web logs to gather information when you visit or interact with our websites, mobile apps, and email communications. Cookies are small text files that are placed on your computer or mobile device by websites you visit. We use this information for a variety of purposes, such as to make our websites work properly, to make a user’s experience more efficient, to understand how visitors interact with our websites, and to for advertising purposes.
X. Contact Details
You can exercise any of the rights described above in the “What are your choices and how can you exercise them?” section above directly with MICHIBOOWHITE by sending an email to by mailing a non-registered letter with a document proving your identity to the below address:
LEAGALINC CORPORATE SERVICE, Inc.
Legal Department, Privacy
1967 WEHRLE DRIVE, SUITE1-086
BUFFALO, NY14221
If you are submitting a request on behalf of another person, you must provide proof that you have been authorized by the individual to act on his or her behalf. In certain circumstances, we may ask the individual to verify his or her own identity directly with us. Please note, we may deny a request from an authorized agent that does not submit proof that they have been authorized by you to act on your behalf.
For all questions relating to the collection and processing of your data by MICHIBOOWHITE, you can contact our Data Protection Officer at MICHIBOOPERFECTWHITE.com. If you are not satisfied with our response and are in the European Union or Canada, you may have a right to lodge a complaint with your local supervisory authority or privacy commissioner, as applicable.
If you are a customer in Canada, MICHIBOOWHITE.COM controls your personal information.
XI. Additional Information for California Residents
XII. Miscellaneous
The following additional information relates to our privacy practices:
CALIFORNIA INFORMATION COLLECTION AND SHARING DISCLOSURE
The following table describes the categories of personal data we collect, disclose for business purposes, and “share” for purposes of cross-context behavioral advertising (as those terms are defined by California law). Please note that because this list is comprehensive, it may refer to types of information that we collect and share about people other than yourself. For example, while we transfer credit card or debit card numbers for our business purpose in order to process payments for orders placed with us, we do not collect or disclose credit card or debit card numbers of individuals that submit questions through our website’s “contact us” page.
Note that we do not sell personal information for money. As discussed elsewhere in our Privacy Policy, we use cookies and similar tracking technologies for purposes of targeted advertising. For more information, please see the COOKIES AND SIMILAR TRACKING TECHNOLOGIES section of the Privacy Policy.
Category of Personal Data We Collect | Examples of Categories of Recipients. Disclosures for business purposes | Sharing for Cross-Context Behavioral Advertising |
---|---|---|
Identifiers— such as name, postal address, phone number, unique personal identifier, online identifier, device ID, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers. | Advertising Networks Data analytics providers Operating systems and platforms Product and service fulfilment companies Payment Processors and financial institutions Social Networks Government entities, law enforcement, lawyers, auditors, consultants and other parties as required by law | Advertising Networks |
Cookies and Third Party Tracking | Payment Processors and financial institutions Government entities, law enforcement, lawyers, auditors, consultants and other parties as required by law | None |
Protected Characteristics — such as age, race, gender, physical or mental disability. | Data analytics providers Government entities, law enforcement, lawyers, auditors, consultants and other parties as required by law | None |
Commercial Information — such as information about products or services purchased, or other purchasing or consuming histories or tendencies. | Advertising Networks Data analytics providers Operating systems and platforms Product and service fulfilment companies Payment Processors and financial institutions Social Networks Government entities, law enforcement, lawyers, auditors, consultants and other parties as required by law | Advertising Networks |
Network activity data — internet or other electronic network activity information, such as browsing history, search history, and information regarding an individual’s interaction with an internet website, application, or advertisement. | Advertising Networks Data analytics providers Operating systems and platforms | Advertising Networks |
Geolocation information— such as your physical location. | Advertising Networks Data analytics providers Operating systems and platforms | Advertising Networks |
Electronic and sensory data— such as audio, electronic, visual, thermal, olfactory, or similar information (e.g., pictures, a recording of a customer service call, security video surveillance footage). | Advertising Networks Data analytics providers Operating systems and platforms | Advertising Networks |
Professional/employment information— such as occupation and professional references. | Data analytics providers Government entities, law enforcement, lawyers, auditors, consultants and other parties as required by law | None |
Inferences — drawn from any of the information identified above. | Advertising Networks Data analytics providers | Advertising Networks |
a b c d e f g h i j k l m n o - Do not remove from template!!! it is important to support different fonts