Privacy Statement
INTRODUCTION
Strands Hair Care, Inc., including our subsidiaries, brands, and affiliates, (“Strands”) provides hair products and services that are scientifically formulated to meet the unique hair needs of individuals. To help deliver our exceptional hair care products and services most effectively, we gather information about our customers and their preferences.
When you interact with Strands, you trust us with your personal information (“Personal Data”). We want to keep that trust by being transparent about our privacy practices - including how and why we collect, use, store and share your Personal Data. We also want you to understand the choices you have regarding your Personal Data.
To make this Privacy Statement easier to understand, we have provided a summary below each section title. We also encourage you to contact us (see “How to Contact Us” below) if you have any questions or concerns.
SCOPE OF THIS PRIVACY STATEMENT
This Privacy Statement applies to Individuals who interact with us or use Strands Products and Services.
This Privacy Statement covers our privacy and information practices and applies to our Products and Services, including our websites (including www.strandshaircare.com, www.thehairlab.com and www.thebodylab.com), hair care products, applications, marketing efforts, physical facilities, and any related services. Please remember that our Terms of Use may also govern your use of our Products and Services.
Strands may process the Personal Data of customers, partners, vendors, employees, applicants, visitors, or other individuals (“Individuals”) who are affiliated with or seeking an affiliation with us, our affiliates, subsidiaries and brands. This Privacy Statement applies to these Individuals regardless of their geographic location during their interactions with Strands.
YOUR RIGHTS AND PREFERENCES
Strands allows you to exercise your privacy rights and manage how we use your information.
Privacy and data protection laws in different geographic regions give Individuals certain rights in relation to their Personal Data. We conduct our privacy practices according to this Privacy Statement and the relevant laws of the geographic regions in which we interact with you. Strands encourages you to Contact Us to learn more about your privacy rights and how we collect and use your Personal Data.
TYPES OF INFORMATION WE COLLECT
We collect information that relates to you and your interactions with Strands.
- Personal Data You Provide:
- When you interact with us through our Products or Services, we may collect Personal Data, such as your name, gender, birthdate, government identification number, shipping/billing address, email address, phone number, device IDs, username and password.
- You may be invited to provide additional Personal Data to personalize your interactions with us and your use of our Products and Services. For instance, in order for us to advise on your hair needs, you may need to provide us with biological information (e.g., hair samples, descriptions of your hair and scalp conditions, etc.) that we will use to create customized hair product recommendations for you. Please note that these are not biometric data and cannot alone be used to identify you.
- Providing us with some Personal Data may be required in order for you to interact with us or to use our Products and Services.
- You also may provide information that is published or displayed (“posted”) on public areas of websites belonging to Strands or other third parties, or which may be transmitted to other users of same (“User Content”). Your User Content is posted on and transmitted to others at your own risk. Strands is not responsible for the actions of others with respect to your User Content.
- If you work at Strands or are applying to work with us, Personal Data will be required in order for you to apply for, be considered for, and maintain employment with Strands.
- Personal Data from Third Parties.
- If you interact with Strands through a third party, we may receive Personal Data from that third party when you have consented for them to share it with us.
- We may use third party services to supplement, validate or increase the accuracy of Personal Data that you give to Strands.
- The Personal Data that you share with third parties is not controlled by Strands or covered by our privacy practices. We encourage you to review third party policies and privacy settings so that you understand how the Personal Data you share with them may be used or shared with others.
- Automatic Functional Information.
We may automatically collect some usage information when you interact with us. For instance, we use cookies and other tracking technologies to automatically collect technical information, such as URL, cookie data, IP address, device type, unique device IDs, device attributes, network connection type (e.g., WiFi, 3G, LTE, Bluetooth) and provider, network and device performance, browser type, language, operating system, and other functional information.
- Derived Information.
Strands may use information we have about you to draw inferences about you and we may then use those inferences to gain a more complete understanding of your preferences. We use preference data in order to offer you potential choices, make recommendations, or to alert you to our Products and Services that may be of interest to you.
- Children’s Information.
Strands Products and Services are intended for and directed to adults, not children. If you are under 18, do not supply any Personal Data to Strands for the purposes of analyzing your hair and scalp conditions or purchasing or using our Products or Services. If you are under 18 and wish to purchase a Strands Product or use our Services, please ask your parent or guardian to handle these transactions for you. If you are aware that we have unintentionally collected information from someone who is underage, please notify us immediately by sending an email to hello@strandshaircare.com.
HOW WE USE YOUR INFORMATION
We use your Personal Data to develop and provide our Products and Services and to personalize, improve and promote our interactions with you.
Unless we specifically disclose otherwise, you understand that we may use any of your collected Personal Data for any of the purposes described in this Privacy Statement (as permitted by applicable law), including:
- For Account Registration and Servicing.
- We may use your Personal Data to create, maintain, supplement, service, change or delete your customer account with us.
- If you have a customer account with us, we may collect certain Personal Data for security purposes in order to verify your authorized access to your accounts with us.
- We may use your Personal Data to resolve customer service questions you may have about our Products and Services and to follow up with you about your experience.
- To Communicate with You.
- We may use your Personal Data to communicate with you about our Products and Services.
- We may use your Personal Data to identify and share offers for third party products and services that we think you may find useful.
- To Improve and Develop New Products and Services.
- We may use your Personal Data to personalize your interactions and experiences with us.
- We may use your Personal Data to improve the quality of and to develop new products and services.
- We may use any information you give to us in surveys or other forms of feedback.
- We may combine your information with that from other Individuals in order to better understand our Products and Services and how we may improve them.
- To Provide Our Products and Services and Operate Our Business.
- We may use your Personal Data to operate our business, including fulfilling your requests, providing you with technical or customer support, and to help us protect our Products and Services, including to combat fraud and protect your information.
- We may conduct research using your Personal Data, alone or in combination with that of other Individuals. When we share that research outside of Strands for research, academic, marketing and/or promotional purposes, we do so in an aggregated or deidentified way such that no individual or household is identifiable.
- No Sale of Your Information.
- Strands does not sell and has not within the past 12 months sold the Personal Data we collect, process or store about Individuals.
- We also do not permit our authorized third party partners to sell the Personal Data we collect, process, store or share about Individuals.
HOW WE SHARE YOUR INFORMATION
- Third Party Service Providers.
With your permission or at your direction, we may disclose, share or sell your Personal Data with third party service providers who we contract with to help us provide our Products and Services and to operate our business. For example, your personal data may be shared when you authorize a third party application to access your account. We share Personal Data to fulfill your requests, provide you with technical or customer support, and to help us protect our Products and Services, including to combat fraud and to protect your information.
- Information Sharing Between Strands’ Entities.
This Privacy Statement applies to all of your interactions with Strands, regardless of geography, corporate entity, or brands, meaning that your information is shared with and among our affiliates and subsidiaries. Except where prohibited by law, regulation, or contractual obligation, we share your information across Strands to support our business operations, to enhance your experiences with our Products and Services, to improve your interactions with us, and to help detect and prevent fraud. When we share information between Strands’ entities, we do so with your consent and using adequate technological and data minimization and protection measures to safeguard Personal Data during collection, processing and transfer.
- Following the Law and Protecting Strands.
We may share your information with courts, law enforcement or regulatory agencies, or other government bodies when we have a good faith belief we are required or permitted to do so by applicable law, regulation, or legal process. We may also disclose your information if we believe it is appropriate to enforce our Terms of Use, to protect the rights, property or safety of Strands and our Products and Services, or to protect or assist others as required by law or contract.
- Credit Reporting.
We may share information about your creditworthiness with credit bureaus, consumer reporting agencies, and card associations. Late payments, missed payments, or other defaults on your account may be reflected in your credit report and consumer report. We may also share your Personal Data with other companies, lawyers, credit bureaus, agents, government agencies, and card associations in connection with issues related to fraud, credit, or debt collection.
- Sale of Our Business.
If we sell, merge, or transfer any part of our business, information about you may be shared, sold or transferred as part of that transaction. We may also share your information with current or future corporate parents, to our subsidiaries, between our brands, or with our affiliates.
- De-identified or Aggregated Data.
We may de-identify or aggregate your information, alone or in combination with other individuals’ information. Such de-identified or aggregated information will not contain Personal Data and may be shared freely by Strands.
- With your Consent.
Other than as set out above, we may also share your Personal Data and your other information for additional purposes with your consent or at your direction.
DATA TRANSFERS
Strands uses appropriate data transfer mechanisms and protection measures.
Strands is based in and conducts its business within the United States. We have adopted a broad view on privacy with the intent of providing our customers with strong privacy rights regardless of where they reside geographically. We have attempted to recognize and implement high standards for privacy rights compliance and our use of terminology in this Privacy Statement should be interpreted to reflect that intent. Strands has taken appropriate measures to ensure that your Personal Data is safeguarded when it is being transferred, processed, or stored by us or our authorized affiliates.
Where permitted by applicable law, we may transfer, process or store your Personal Data in any geographic region where we have facilities, business operations, affiliates, or in which we engage service providers. By using our Products and Services, you consent to the transfer of your Personal Data to and the processing and storage of your Personal Data in geographies outside of your place of residence or the point of collection.
Please Contact Us to learn more about your rights with respect to data transfers and to request access to, limit the use of, or limit the disclosure of, your Personal Data. If you make a request to Strands that involves Personal Data, you will need to provide certain authentication and verification information in order for us to respond to your request.
CONNECTING WITH THIRD PARTIES
In your interactions with Strands and our Products and Services, it may be necessary for us to sync, link or connect your information with third parties, including providing Personal Data necessary to identify or authenticate your requested interactions. Your consent for these interactions will be required by us, by the third party or by both. We encourage you to review the privacy practices of any third party that you choose to share your Personal Data with, as we are not responsible for the privacy practices of third parties.
MANAGING YOUR DATA AND PRIVACY
You may review and change your information, deactivate your account with us, manage the use of information that identifies you, decide what marketing communications you receive, and understand our use of Cookies. We may retain certain information and you may still receive other non-promotional messages from us.
- Managing Marketing Communications From Us.
Strands will honor your choices when it comes to receiving marketing communications from us. If you have received marketing communications from us that you no longer wish to receive, you may:
- Contact Us or adjust your customer account settings to manage your preferences regarding your Personal Data and your interactions with Strands.
- If you have received electronic promotional communications from us and no longer wish to receive them, click the "unsubscribe" link in the promotional communication you received.
- For SMS messages, reply "STOP" or follow the instructions in the message or settings to discontinue the communications.
- If you are receiving push notifications from us to your mobile device and no longer wish to receive these types of communications, you may turn them off at the device level.
- Remember that even if you choose not to receive marketing communications from us, we will continue to send you mandatory service or transactional communications, or communications related to the safe use of our Products or Services.
- If you do not have a customer account, you may Contact Us if you wish to adjust your Personal Data preferences and your interactions with us.
- Cookies and Similar Tracking Technologies.
We may use and allow others to use cookies, web beacons, pixels, local shared objects, device identifiers, and other similar technologies ("Cookies”) to collect information about you. We use this information to improve your experiences when you interact with us. You have control over some of the data we collect from Cookies and how we use it. You may learn more about Cookies and how to manage them at https://www.allaboutcookies.org/manage-cookies.
Please note that even if you elect not to enable Cookies or interest-based advertising and marketing, you may still receive advertisements, they just won't be tailored to your interests. Also, if you elect to receive Cookies and later delete them, use a different browser, update your systems, or use a different device, you may need to renew your choices.
- Do Not Track.
Like most other companies, Strands is not currently configured to respond to browser "Do Not Track" signals because, at this time, no formal "Do Not Track" standard has been adopted.
- Social Media Features.
Strands or our authorized third parties may use social media features to gather certain information about you. These features may collect your IP address, log which pages you are visiting, and may set a Cookie to enable the feature to function properly. Your interactions with these social media features are governed by the privacy policies and practices of the providing company and not by Strands.
YOUR DATA ACCESS RIGHTS
You may have the right to exercise certain data protection rights regarding your Personal Data. Strands will not discriminate against you for exercising your privacy rights.
- Data Retention.
Strands retains and uses your information in accordance with and as permitted by applicable law and regulations:
- We will retain your information as long as necessary to serve you, to maintain your account for as long as your account is active, or as otherwise needed to operate our business.
- If you decide not to receive promotional communications from Strands, your opt out will not apply to information provided by us as a result of a product purchase, warranty registration, product service experience or other transactions.
- We may also continue to use some of your information for our legitimate business purposes and to improve our Products and Services or to develop new ones.
- We will retain and use your information as required by applicable regulations and Strand’s records and information management practices, comply with our legal and reporting obligations, resolve disputes, enforce our agreements, complete any outstanding transactions, and for the detection and prevention of fraud.
- Responses from Strands.
We respond to all requests from individuals regarding the exercise of their data protection rights in accordance with applicable data protection laws. While your data protection rights may vary depending on your location, they generally include:
- Accessing, correcting, updating, or requesting deletion of your information.
- Objecting to or asking us to restrict the processing of your information.
- Requesting the portability of your information and providing the same in a timely manner and at no charge.
- Electing whether or not to receive marketing communications from us.
- Withdrawing your consent at any time for us to collect, process, store, or share your information (noting that such withdrawal will not affect the lawfulness of any processing that we conducted prior to your withdrawal, nor will it affect otherwise lawful processing or storage).
- Data Controller.
Strands is considered to be a “controller” of your information under data privacy regulations. Other entities may also act as controllers of your information and you should contact them if you have any questions about how they use your information.
SECURITY OF YOUR INFORMATION
We provide reasonable and appropriate security measures in connection with securing your Personal Data.
Keeping your Personal Data safe is important to us. We have implemented measures designed to safeguard your Personal Data from accidental loss and from unauthorized access, use, alteration and disclosure. At Strands, we:
- Work to review and update our security practices and implement accepted methods to protect your Personal Data.
- Store Personal Data on our secure servers behind firewalls and securely transmit such.
- Transmit, store, protect, and access all cardholder information in compliance with the Payment Card Industry's Data Security Standards. Payment transactions are encrypted using SSL or other encryption technology, or will use our third party payment processors, who will use appropriate security procedures.
- Comply with applicable laws and security standards.
- Train applicable employees and contractors on data privacy and require them to safeguard your data.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain of our Products or Services (such as our websites or your customer account), you are responsible for keeping this password confidential. You should not share your password with anyone. We urge you to be careful about giving out information in public areas, like message boards or social media.
Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your Personal Data, we cannot guarantee its security during transmission to us. Any transmission of your information to us is at your own risk. Strands is not responsible for circumvention of any privacy settings or security measures.
CALIFORNIA CONSIDERATIONS
We provide our Products and Services from our base of operations in California.
Strands conduct our privacy practices according to this Privacy Statement and the relevant laws of the United States and the State of California, where our company is based and from where we engage in our interactions with you. Strands wants Individuals located in the State of California to understand the following additional privacy and data protection measures which may be applicable (“California Privacy Terms”). These California Privacy Terms apply to the processing by Strands of Personal Data related to identified or identifiable Individuals and households located in the State of California.
Controlling Law:
We include this additional information to comply with the California Consumer Privacy Act of 2018 (“CCPA”), and as of January 1, 2023 the California Privacy Rights Act of 2020 (“CPRA”). Any terms defined in the CCPA have the same meaning when used in this section. For purposes of this Privacy Statement and this section, the terms Personal Data and personal information are used as interchangeable.
Managing Your Data:
Strands has adopted internal policies and implemented measures to ensure that the applicable legal requirements are met and that your personal information is processed with respect and care using the appropriate technology.
- Strands may collect, process, store and disclose, including sell your personal information, for a disclosed business purpose or with your consent. If consent is required for us to process your personal information, you may withdraw or modify such consent at any time by contacting us.
- When we disclose personal information for a business purpose, we endeavor to execute contracts that describe the purpose and require the recipient to both keep that personal information confidential and not use it for any other purpose.
- In the preceding twelve (12) months, Strands has disclosed the following categories of personal information for a business purpose:
- Contact information that includes identifiers such as your first and last name, business entity name, e-mail address, and telephone number.
- Financial information (account or credit card numbers).
- Demographic information (address, age, or income level).
- Other unique identifiers such as your tax ID number, IP addresses, geolocation data.
- Internet or other similar network activity, including but not limited to, browsing history, search history, activity history, informational materials from our websites, location data, logs, language, date and time of access, frequency, http response code, and other communication data or information regarding your interaction with us.
- Commercial information, including our Products or Services with which you interact, including historical or trend information, and inferences or profiling information created therefrom.
- You have the right to:
- Request access to your personal information as it is processed and stored by us.
- Correct or delete your personal information that we hold unless Strands is legally required to retain it.
- Restrict or object to our processing of your personal information.
- Object to the sale of your personal information.
- You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we receive and confirm your request, we may disclose to you:
- The categories of personal information we collected about you.
- The categories of sources and third parties for the personal information we collected about you.
- Our business or commercial purpose for collecting or selling that personal information.
- The categories of third parties with whom we share that personal information.
- The specific pieces of personal information we collected about you (also called a data portability request).
We will respond to properly submitted and verified requests for access, disclosure, deletion, correction, or objection within 45 days.
Please Contact Us for more information or to exercise a request regarding your California data privacy rights. If you are concerned about Strand’s compliance with California laws relating to the privacy of your Personal Data (personal information), you may also contact the California Attorney General’s Office.
CHANGES TO OUR PRIVACY STATEMENT
We may make changes to our Privacy Statement or our supporting privacy procedures at any time.
From time to time we may change or update this Privacy Statement. We reserve the right to make changes or updates at any time and without prior notice to you.
If we make material changes to the way we process your Personal Data, we will provide you notice by posting the most current version of this Privacy Statement on our websites and we may also advise you of changes via our Products and Services information, or by other communication channels, such as by email, newsletters or community post. Please review any changes carefully.
If you object to any changes and no longer wish to use our Products and Services, you may close your accounts and cease use of our Products and Services. All changes to our Privacy Statement are effective immediately upon posting and your continued interaction with us or your use of our Products and Services after a posting of an updated Privacy Statement constitutes your consent to all changes.
HOW TO CONTACT US
If you have questions or comments about this Privacy Statement, you may contact us by email, telephone, or direct mail.
- Email at hello@strandshaircare.com is the fastest and most-preferred way to reach us with your data management or privacy-related questions and concerns.
- Via Telephone: (313) 509-7212
- Via Direct Mail:
Strands Hair Care, Inc.
606 W El Segundo Blvd, Suite C
Los Angeles, CA 90061