California Privacy Rights

Privacy Notice for California Residents

This Privacy Notice for California Residents supplements the information contained in our general Privacy Policy and applies solely to all visitors, users, and others who reside in the State of California ("consumers" or "you"). We adopt this notice to comply with the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act (CPRA). Any terms defined in the CCPA/CPRA have the same meaning when used in this notice.

1. Information We Collect

Our Website collects information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device ("personal information").

In particular, we have collected the following categories of personal information from consumers within the last twelve (12) months:

Category

Examples of Personal Information Collected

Collected

A. Identifiers.

Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, phone number.

YES

B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).

Name, telephone number, credit card number, debit card number (processed by our third-party payment provider, we do not store this information).

YES

C. Protected classification characteristics under California or federal law.

Sex (if provided by the user).

YES

D. Commercial information.

N/A (We do not directly collect information regarding products or services purchased, obtained, or considered beyond what is necessary to fulfill your order and provide customer service. However, our third-party analytics and advertising partners may collect this type of information.)

NO

E. Biometric information.

N/A

NO

F. Internet or other similar network activity.

Browse history, search history, information on a consumer's interaction with a website, application, or advertisement (collected via cookies, tracking technologies, and analytics tools, which may be operated by us or by third parties like Shopify, Google, and Facebook).

YES

G. Geolocation data.

Precise physical location or movements, if provided by the customer for shipping purposes.

YES

H. Sensory information.

N/A

NO

I. Professional or employment-related information.

N/A

NO

J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).

N/A

NO

K. Inferences drawn from other personal information.

We may draw inferences from the personal information listed above to create a profile about a consumer reflecting the consumer's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. This is often done by our third-party analytics and advertising partners to personalize your experience and show you relevant ads.

YES

 

Sensitive Personal Information: We collect certain "sensitive personal information" as defined under the CPRA, specifically: precise geolocation data (from your shipping address and billing address) and potentially information related to your sex (if you choose to provide it). We do not use or disclose sensitive personal information for purposes other than those permitted by CPRA (e.g., to perform services requested by you, for security and integrity purposes, to prevent fraud, or for legal compliance).

2. Sources of Personal Information

We obtain the categories of personal information listed above from the following categories of sources:

  • Directly from you. For example, from forms you complete on our website, when you sign up for an account, make a purchase, or communicate with us.
  • Indirectly from you. For example, from observing your actions on our Website through cookies, tracking technologies, and analytics tools.
  • Third-party partners. Including, but not limited to, Shopify (our e-commerce platform), Google (for analytics and advertising), Facebook/Meta (for advertising), and other marketing partners. These entities may collect information directly from your browser or device when you interact with our website.
  • Publicly available databases. (Less common for your business type, but worth mentioning if you ever cross-reference information).

3. Use of Personal Information

We may use or disclose the personal information we collect for one or more of the following business and commercial purposes:

  • To fulfill or meet the reason you provided the information. For example, if you provide your name your shipping address and billing address to make a purchase, we will use that information to process your order and deliver the products.
  • To provide, support, personalize, and develop our Website, products, and services.
  • To create, maintain, customize, and secure your account with us.
  • To process your requests, purchases, transactions, and payments and prevent transactional fraud.
  • To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.
  • To personalize your Website experience and to deliver content and product and service offerings relevant to your interests, including targeted offers and ads through our Website, third-party sites, and via email or text message (with your consent, where required by law).
  • For testing, research, analysis, and product development, including to develop and improve our Website, products, and services.
  • To help maintain the safety, security, and integrity of our Website, products and services, databases, and other technology assets and business.
  • To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
  • As described to you when collecting your personal information or as otherwise set forth in the CPRA.
  • To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us about our Website users is among the assets transferred.

4. Sharing Personal Information

We may disclose your personal information to a third party for business or commercial purposes. When we disclose personal information for a business purpose, we enter into a contract that describes the purpose and requires the recipient to keep that personal information confidential and not use it for any purpose except performing the contract.

We share your personal information with the following categories of third parties:

  • Service Providers: Entities that provide services on our behalf, such as payment processing, order fulfillment, shipping, customer service, and data analytics.
  • Third-Party Marketers and Advertising Partners: Companies like Google, Facebook/Meta, and others that assist us with marketing, advertising, and understanding user behavior. These partners may use cookies and tracking technologies to collect information about your activity on our website and other sites to deliver targeted advertisements.
  • Analytics Providers: Companies like Google Analytics that help us understand how users interact with our website to improve its functionality and user experience.
  • Affiliates: Other companies within the Diamond Wholesale Inc. family of businesses.
  • Government entities: When required for legal compliance or in response to a valid legal request.

Disclosure of Personal Information for a Business Purpose: In the preceding twelve (12) months, we have disclosed the following categories of personal information for a business purpose:

  • Category A: Identifiers
  • Category B: California Customer Records personal information categories
  • Category C: Protected classification characteristics
  • Category F: Internet or other similar network activity
  • Category G: Geolocation data
  • Category K: Inferences drawn from other personal information

"Selling" and "Sharing" Personal Information for Cross-Context Behavioral Advertising: We do not sell your personal information in exchange for monetary compensation. However, we may "share" your personal information (including categories A, F, and K, as listed above) with third parties for cross-context behavioral advertising purposes. This means that certain information about your activity on our website may be shared with advertising partners to show you targeted advertisements on other websites or platforms.

We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.

5. Your California Privacy Rights

The CPRA provides California residents with specific rights regarding their personal information. This section describes your CPRA rights and explains how to exercise those rights.

A. Right to Know and Access Specific Pieces of Information You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:

  • The categories of personal information we collected about you.
  • The categories of sources for the personal information we collected about you.
  • Our business or commercial purpose for collecting, selling, or sharing that personal information.
  • The categories of third parties with whom we disclose that personal information.
  • The specific pieces of personal information we collected about you.
  • If we sold or shared your personal information for a business purpose, two separate lists disclosing:
    • Sales or sharing, identifying the personal information categories that each category of recipient purchased or received.
    • Disclosures for a business purpose, identifying the personal information categories that each category of recipient obtained.

B. Right to Delete You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.

We may deny your deletion request if retaining the information is necessary for us or our service providers to:

  1. Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
  2. Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for that activity.
  3. Debug products to identify and repair errors that impair existing intended functionality.
  4. Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
  5. Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
  6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may seriously impair or render impossible the research's achievement, if you previously provided informed consent.
  7. Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
  8. Comply with a legal obligation.
  9. Make other internal and lawful uses of that information that are compatible with the context in which you provided it.

C. Right to Correct Inaccurate Personal Information You have the right to request that we correct inaccurate personal information that we maintain about you. Once we receive and confirm your verifiable consumer request, we will use commercially reasonable efforts to correct the inaccurate personal information as directed.

D. Right to Opt-Out of the Sale or Sharing of Personal Information You have the right to direct us to not sell your personal information or share it for cross-context behavioral advertising at any time. We will respect your choice and place you on a "do not sell or share" list.

E. Right to Limit the Use and Disclosure of Sensitive Personal Information You have the right to direct us to limit the use and disclosure of your sensitive personal information to that which is necessary to perform the services or provide the goods reasonably expected by an average consumer. As noted above, we already limit our use of sensitive personal information to these permitted purposes.

F. Non-Discrimination We will not discriminate against you for exercising any of your CPRA rights. Unless permitted by the CPRA, we will not:

  • Deny you goods or services.
  • Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
  • Provide you a different level or quality of goods or services.
  • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

6. Exercising Your California Privacy Rights

To exercise the rights described above, please submit a verifiable consumer request to us by:

  • Filling out our dedicated Privacy Rights Request Web Form: Contact US
  • Emailing us at: contact@shopstyleandmore.com

Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.

Your request must:

  • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative. This may include, but is not limited to, your name, email address on file, postal address, and details about a recent purchase.
  • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

7. "Do Not Sell or Share My Personal Information" and Global Privacy Control

As mentioned above, we may share your personal information for cross-context behavioral advertising purposes. To opt-out of the "selling" or "sharing" of your personal information, please:

We also recognize and respond to Global Privacy Control (GPC) signals. If our website detects a GPC signal from your browser, we will treat that as a request to opt-out of the sale and sharing of your personal information.

8. Limit the Use of My Sensitive Personal Information

As noted, we only use sensitive personal information for purposes permitted by CPRA, such as providing requested services, ensuring security, and legal compliance. Therefore, a separate option to limit its use beyond these purposes is not necessary. However, if our practices change, this section will be updated.

9. Data Retention

We retain each category of personal information collected for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Generally, we retain your personal information for 24 months following your last interaction with us or your last purchase, to facilitate customer service, process returns, fulfill warranty obligations, and for analytical purposes to improve our services. For example:

  • Identifiers (Name, Email, Address): Retained for 24 months to manage your account, fulfill orders, and send marketing communications (if consented).
  • Internet/Network Activity: Retained for 24 months for analytics, security, and to improve website functionality.
  • Geolocation Data: Retained for 24 months for shipping records and fraud prevention.
  • Customer Records (Phone, partial Credit Card info from payment provider): Retained for 24 months for customer service and transaction records.

In some circumstances, you can ask us to delete your data (see "Right to Delete" above).

10. Data Security

We implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information we collect and process, designed to protect against unauthorized access, destruction, use, modification, or disclosure of your personal information. We rely on the security measures provided by Shopify for our e-commerce platform and our security practices are reviewed by TrustedSite.