Last Updated: February 9th, 2023
We may change this Policy from time to time. If we make changes to this Policy, we will notify you by revising the date at the top of the Policy. If we make material changes, we will provide you with additional notice (such as by adding a statement to the Services or sending you a notification). We encourage you to review this Policy regularly to stay informed about our information practices and the choices available to you.
COLLECTION OF PERSONAL INFORMATION
The categories of personal information we collect and the sources from which we collect it depend on your interactions with us and are described in more detail below.
PERSONAL INFORMATION YOU PROVIDE DIRECTLY TO US
We collect personal information directly from you, including when you engage in any of the activities listed below:
- Place an order from our website;
- Make a purchase at one of our stores;
- Return an item or make an exchange from a previous purchase;
- Inquire about our products or services;
- Contact us to request assistance or provide feedback, including communication with customer service;
- Interact with our store associates, such as via our personal shopper or chat with a stylist services;
- Create an online account and profile;
- Subscribe to receive our emails or text messages;
- Enter a contest or sweepstakes;
- Participate in a survey, promotion, or event; and
- Interact with us on social media, including by posting content and tagging us.
The types of personal information we collect directly from you may include your name, email address, postal address, phone number, birthday, marketing preferences, product, style, and budget preferences, size information, account information, information provided in your survey responses (such as name, city, state, age range, height, and body type), and any other information you choose to provide.
If you make a purchase from us, we work with third-party payment processors and financing partners to collect and process your payment information.
PERSONAL INFORMATION WE COLLECT AUTOMATICALLY
We automatically collect personal information when you access and use our Services or shop in our stores, including:
- Device and Usage Information: We collect information about how you access and use our Services, including device information, such as your browser type, hardware model, operating system version, IP address, unique device identifiers, and language settings. We also collect information about your activity on our Services, such as items placed in your shopping cart, your access times, pages viewed, the routes by which you access our Services, and your use of any hyperlinks available within our Services.
- Transaction Information: When you make a purchase or return, we collect information about your transactions, including records of products or services you purchased, returned, or are considering purchasing from us, the purchase price, and the date and location of the transaction.
- Video, Images, and Audio: We collect video recordings and photographs in our stores for security, fraud, and loss prevention purposes, and we may record calls you place to customer service.
PERSONAL INFORMATION WE COLLECT FROM OTHER SOURCES
We may collect personal information about you from other sources. For example, we may collect personal information about you from:
- Other customers who provide information about you, such as to send you a gift;
- Order processing partners, such as fraud prevention partners, shipping partners, and fulfillment partners;
- Marketing and advertising companies, data co-ops and mailing list providers, and market research companies; and
- Third party single sign on providers (such as Amazon).
The types of personal information we collect from other sources may include name, email address, mailing address, billing address, birthday, product preferences, and product purchases.
PERSONAL INFORMATION WE DERIVE
We may derive information or draw inferences about you based on the information we collect. For example, we may infer your approximate location based on your IP address or that you are interested in purchasing certain types of products based on your browsing behavior on our Services.
USE OF PERSONAL INFORMATION
We use the personal information we collect to provide, maintain, and improve our products and services. We also use personal information to:
- Communicate with you about products, services, contests, promotions, and other information that we think will interest you unless you have opted out of such communications (see "Opting Out of Marketing Communications" for more information);
- Administer and fulfill our contests, sweepstakes, and other promotions and deliver rewards;
- Identify, report, and repair errors that impair the functionality of our Services;
- Analyze trends and statistics, learn more about your shopping preferences and your interaction with our Services, and improve your shopping experience;
- Detect, investigate, and prevent security incidents and protect against malicious, deceptive, fraudulent, or illegal activity;
- Respond to your comments, questions, and requests and provide customer service;
- Personalize and improve the Services and provide content or features that match your profile and interests;
- Target advertisements to you on third-party platforms and websites unless you have opted out (see the Opting Out of Targeted Advertising, Sharing, and Sales" for more information); and
- Comply with our legal and financial obligations.
TARGETED ADVERTISING AND ANALYTICS
You can also learn more about interest-based ads and opt out of having your web browsing information used for behavioral advertising purposes by companies that participate in the Digital Advertising Alliance, by visiting www.aboutads.info/choices, or, if you reside in the European Union, by visiting www.youronlinechoices.eu.
DISCLOSURES OF PERSONAL INFORMATION
In certain circumstances, we may disclose the personal information we collect about you. We disclose the categories of personal information described in "Collection of Personal Information" above in the following ways:
- Corporate Affiliates. We may disclose personal information to our holding company, subsidiaries, and corporate affiliates for the purposes described in the "Use of Personal Information" section above.
- Vendors and Service Providers. We make personal information available to our vendors, service providers, and contractors who perform services on our behalf, such as companies that assist us with web hosting, shipping and delivery, fraud prevention, customer service, surveys, financing and payment processing, analytics, and marketing and advertising.
- For Marketing Purposes. We may share your personal information with third parties for their own marketing purposes or to expand the reach and effectiveness of our own marketing campaigns. Depending on where you live, these activities may constitute “sales” and you may opt out of these disclosures by filling out our web form located here.
- Corporate Transactions. Personal information may be disclosed or transferred as part of, or during negotiations of any purchase, sale, lease, merger, amalgamation or any other type of acquisition, disposal, securitization, or financing involving Johnny Was.
- Professional Advisors. We disclose personal information to our legal, financial, insurance and other advisors in connection with the kinds of corporate transactions described above or in connection with the management of Johnny Was’s business or operations.
- Law Enforcement Authorities and Individuals Involved in Legal Proceedings. We may disclose personal information about you, if necessary, in our good faith judgment, to comply with laws or regulations or in response to a valid subpoena, order, or government request, or to protect the rights, property, or safety of Johnny Was or others.
- Consent. We make personal information available to third parties when we have your consent, or you intentionally direct us, to do so.
We also disclose aggregated or de-identified information that cannot reasonably be used to identify you. Johnny Was processes, maintains, and uses this information only in a de-identified fashion and will not attempt to re-identify such information, except as permitted by law.
YOUR PRIVACY RIGHTS AND CHOICES
Access, Correction, and Deletion
Depending on where you reside, you may have the right to (1) request to know more about and access your personal information, including in a portable format, (2) request deletion of your personal information, and (3) request correction of inaccurate personal information. To request access, deletion, or correction of your personal information, please fill email us at firstname.lastname@example.org. You may also call 1.866.942.8860 to submit a request. Once we receive the request, we will validate the information that you provide and send a message to the email address you provided in the request. Please follow the instructions in that email to verify your email address and/or provide any additional information that may be needed to process your request. If we deny your request, you may have the right to appeal our decision by contacting us at email@example.com. If you have concerns about the result of an appeal, you may contact the attorney general in the U.S. state where you reside
You can also review and modify your online account information at any time. To access your online account, simply click "My Account" at the top of any web page and sign in when prompted. You can also update your account information by calling customer service at 1.866.942.8860.
We may share Device Identifier and Usage Data about visitors with third party advertising companies, analytics providers and other vendors for similar purposes. While we may use a variety of service providers to perform advertising and analytics services, some of these companies may be members of the Network Advertising Initiative ("NAI”) or the Digital Advertising Alliance ("DAA") Self-Regulatory Program for Online Behavioral Advertising.
Opting Out of Targeted Advertising, Sharing, and Sales
As described in the "Targeted Advertising and Analytics" section above, we process personal information to serve you advertisements on third-party properties. Some of these activities may be considered “sales” or “sharing” of your personal information or “targeted advertising” under the law that applies to you. You may opt out of these activities by following the prompts here.
In addition, we disclose your information to other entities for marketing purposes as described in "Disclosures of Personal Information" above. Such disclosures may constitute “sales” of your personal information in California and Virginia and Connecticut, Colorado, and Utah. If you live in one of these U.S. states, you may opt out of such activities here.
Opting Out of Marketing Communications
If you would like to stop receiving promotional emails or text messages from us, please unsubscribe by following the instructions in those communications or log in to your account to manage your newsletter subscriptions. If you opt out, we may still send you non-promotional emails, such as those about your account or our ongoing business relations.
Cookies and Similar Tracking Technologies
CALIFORNIA PRIVACY INFORMATION & NOTICE AT COLLECTION
The California Consumer Privacy Act ("CCPA") requires us to explain some information using definitions and categories set out under the CCPA. If you are a California resident, this section applies to you.
We collect, and in the preceding 12 months we have collected, the following categories of personal information: Identifiers (such as your name, email address, or IP address), characteristics of protected classifications under California or U.S. law (such as your age), commercial information (such as records of products or services purchased), Internet and electronic network activity information (such as browsing history, search history, information about your activities on our Services), geolocation data (such as your city of residence), audio and visual information (such as phone recordings when you call customer service), inferences drawn about your preferences, and other categories of personal information that relate to or are reasonably capable of being associated with you. For more information about the precise data points we collect and the sources of such collection, please see "Collection of Personal Information" above. We collect personal information directly from you (for example, when you place an order from our website or make a purchase at one of our stores) automatically when you access or use our Services or shop in our stores, and from third-party sources such as other customers who provide information about you, each described in more detail in the "Collection of Personal Information" section above.
We collect personal information for the business and commercial purposes described in the "Use of Personal Information" section above.
In the preceding 12 months, we have disclosed the following categories of personal information for business purposes to the following categories of recipients:
|Categories of Personal Information||Categories of Recipients|
|Identifiers||Advertising and marketing partners, Internet service providers, data analytics providers, operating systems and platforms, social networks, payment processors, fulfilment partners, customer support partners, event partners, fraud prevention partners|
|Characteristics of protected classifications under California or U.S. law||Advertising and marketing partners, data analytics providers|
|Commercial information||Advertising and marketing partners, data analytics providers, operating systems and platforms, payment processors, fulfillment partners, customer support partners, event partners, fraud prevention partners|
|Internet and electronic network activity information||Advertising and marketing partners, Internet service providers, data analytics partners, operating systems and platforms, cloud service providers, fraud prevention partners|
|Geolocation data||Cloud service providers|
|Audio and visual information||Fraud prevention partners, customer support partners|
|Inferences||Advertising and marketing partners, data analytics providers|
We do not use or disclose sensitive personal information for the purpose of inferring characteristics about you.
We retain personal information for as long as necessary to carry out the purposes for which we originally collected it and for other purposes described in this Policy.
We “share” and “sell” personal information with third parties for the purpose of engaging in advertising and marketing activities, including to expand the reach and effectiveness of our own marketing campaigns and for third parties’ own marketing purposes. We share and sell the following categories of personal information to the following categories of third parties:
|Categories of Personal Information||Categories of Third Parties|
|Identifiers||Other retailers and advertising and marketing networks|
|Commercial information||Advertising and marketing networks|
|Internet and electronic network activity information||Advertising and marketing networks|
We do not knowingly sell or share personal information about consumers under the age of 16.
You have the right to opt out of any sharing or sales of your personal information, which you can exercise by following the instructions here or by visiting our Services with a legally-recognized opt-out preference signal enabled, such as the Global Privacy Control (see opt-out form for details).
Please see the "Your Privacy Rights and Choices" section above for more information about your privacy rights, how to exercise them (including as an authorized agent of someone else), and how we will verify requesters. We will not discriminate against you if you choose to exercise your rights under the CCPA.
If you are submitting a rights request as an authorized agent, you are required to submit proof of your authorization to make the request, such as a valid power of attorney or proof that you have signed permission from the individual who is the subject of the request. Please do not provide any sensitive personal information in connection with this request, such as a driver's license or other government-issued ID. In some cases, we may be required to contact the individual who is the subject of the request to verify their own identity or confirm you have permission to submit this request.
Notice of Financial Incentives
We offer various financial incentives. For example, we may provide discounts or other benefits to customers who sign up to receive our marketing emails or marketing text messages. When you participate in a financial incentive, we collect personal information from you, such as identifiers (like your email address or phone number), commercial information (like your purchase preferences and interests or purchase history), professional, inferences drawn about your preferences, and other categories of personal information that relate to or are reasonably capable of being associated with you. You can opt into a financial incentive by following the sign-up or participation instructions provided. If you later decide to opt out, you may do so at any time, such as by following the unsubscribe instructions in the applicable program’s terms and conditions, promotional emails, or contacting us. In some cases, we may provide additional terms and conditions for a financial incentive, which we will provide to you when you sign up. The value of your personal information is reasonably related to the value of the offer or discount presented to you.
Shine the Light Law
California's "Shine the Light" law requires certain businesses to respond to requests from California customers asking about the businesses' practices related to disclosing personal information to third parties for the third parties' direct marketing purposes. Alternately, such businesses may have in place a policy not to disclose personal information of customers to third parties for the third parties' direct marketing purposes if the customer has exercised an option to opt-out of such disclosures. We have such a policy. If you want to opt out of these disclosures of your information please submit your request here.
If you are located in the European Economic Area (“EEA”), the United Kingdom, or Switzerland, you have certain rights and protections under the law regarding the processing of your personal data, and this section applies to you.
Legal Basis for Processing
When we process your personal data, we will do so in reliance on the following lawful bases:
- To perform our responsibilities under our contract with you (e.g., providing the products and services you requested).
- When we have a legitimate interest in processing your personal data to operate our business or protect our interests (e.g., to provide, maintain, and improve our products and services, conduct data analytics, and communicate with you).
- To comply with our legal obligations (e.g., to maintain a record of your consents and track those who have opted out of marketing communications).
- When we have your consent to do so (e.g., when you opt in to receive marketing communications from us). When consent is the legal basis for our processing your personal data, you may withdraw such consent at any time.
We store other personal data for as long as necessary to carry out the purposes for which we originally collected it and for other legitimate business purposes, including to meet our legal, regulatory, or other compliance obligations. For example, we retain a record of your transaction to protect ourselves in the event of a legal dispute; consequently, we generally retain this data for at least the statutory limitation period on contractual claims.
You may be presented with an opportunity to receive information and/or marketing offers from Johnny Was and our affiliated businesses, partners and agents. If you agree at that time to receive such communications, your Personal Information will be disclosed to that third party (or parties). For more information, please refer to the Marketing Communications section VIII., D.
Processing in the United States
Johnny Was is a U.S. company, and so your personal data will be processed by us in the United States. The privacy laws in the U.S. may not be as protective as those in your country of residence. Wherever your personal data is processed, we will handle it in accordance with this Policy. Where required by law, we provide adequate protection for the transfer of personal data, such as by executing Standard Contractual Clauses. You may contact us at firstname.lastname@example.org if you have any questions about the safeguards we implement.
Data Subject Requests
Subject to certain limitations, you have the right to request access to the personal data we hold about you and to receive your data in a portable format, the right to ask that your personal data be corrected or erased, and the right to object to, or request that we restrict, certain processing. If you would like to exercise any of these rights, please contact us at email@example.com. In addition, please review the options we offer in the Your Privacy Rights and Choices section.
If you have a concern about our processing of personal data that we are not able to resolve, you have the right to lodge a complaint with the Data Protection Authority where you reside. Contact details for your Data Protection Authority can be found using the links below:
For individuals in the EEA: https://edpb.europa.eu/about-edpb/board/members_en
For individuals in the UK: https://ico.org.uk/global/contact-us/
For individuals in Switzerland: https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact.html
If you have any questions about this Policy or our information practices, please contact us at:
Attn: E-Commerce Department
2423 E. 23rd Street
Los Angeles, California 90058.