Privacy Notice

e.l.f. Cosmetics
Effective as of January 9, 2019

At e.l.f. Cosmetics, Inc. (“we” or “us”), we believe in being clear and open about how we collect and use personal information related to you. In the spirit of transparency, this Privacy Notice provides you with information about the types of personal information we collect, how we use such personal information and to whom and under what circumstances we may disclose it.

This Privacy Notice applies to personal information we collect from you, or that you provide to us, and communications from us, in connection with your use of our United States dedicated website(www.elfcosmetics.com),promotions in which we are involved, social media, and customer surveys. Please read this policy carefully so that you understand your rights in relation to your personal information, and how we will collect, use and process your personal information.

If you do not agree with this Privacy Notice in general or any part of it, you should not use our websites, request marketing material from us, or take part in our promotions, social media activity, or customer surveys, as applicable.

Who We Are

For purposes of data protection laws, regardless of where you reside, e.l.f. Cosmetics, Inc. is the controller of that personal information you provide to us, or that is collected or processed by or for us. Contact information for e.l.f. Cosmetics, Inc. can be found in the “Contact Us” section.

The address for e.l.f. Cosmetics, Inc. is:

e.l.f. Cosmetics, Inc.
570 10th Street
Oakland, CA 94607

How Do We Collect Your Personal Information and How Do We Use It?

In the table below, we explain:

  • what activity or scenario you are involved in when we use or collect your personal information.
  • what types of personal information we may collect when you take part in a particular activity.
  • what we do with your personal information, and the purposes for collecting and using it.
  • our legal basis for using your personal information. Whenever we use your personal information, we will have a legal basis to do this.

What We Collect

How We Use It

Our Legal Basis for Processing, Using, and Storing It

Purchases and Order Management

Personal information that we collect, or you give us, when you place an order, including:

  • your contact details including: your first and last name, billing address, mailing address, email address; and
  • the product(s) you purchased.

We use this personal information to:

  • fulfill your requests and orders for products;
  • take payment from or give you a refund;
  • help us ensure that our customers are genuine and to prevent fraud;
  • manage and keep your order history;
  • send you personalized offers, shopping ideas or other promotional materials; and
  • enhance your shopping experience while on our websites by showing you personalized content.
  • Performance of a contract—so we can perform our contract for the sale of our products to you and manage the associated logistics.
  • Your consent to the processing, using, and storing.
  • Our legitimate interests—we have a legitimate business interest in (i) improving our products and services; (ii) better engaging with you; (iii) preventing fraud; and (iv) securing our tools.
  • To comply with our legal obligations.

Account / Beauty Squad Loyalty Program Creation and Management

Personal information that we collect, or you give us, when you create an account or join our Beauty Squad Loyalty Program, including:

  • your first and last name;
  • your email address;
  • your account password; and
  • your birthdate.

We use this personal information to:

  • operate and manage our Beauty Squad Loyalty Program; and
  • send you personalized offers, shopping ideas or other promotional materials.
  • Performance of a contract—so you can create and manage your account and so that we can operate and manage our Beauty Squad Loyalty Program.
  • Your consent to the processing, using, and storing.

Marketing and Promotional Materials

Personal information that we collect, or you give us, when you sign up for our marketing and promotional materials:

  • your email address; and
  • your phone number

We use this personal information to:

  • notify you of new products or updates; and
  • send you offers, shopping ideas or other promotional materials.
  • Your consent to the processing, using, and storing.
  • Our legitimate interests—we have a legitimate business interest in (i) improving our products and services and (ii) better engaging with you.

Questions and Customer Service

Personal information that we collect, or you give us, when you communicate with us whether in person, through our websites or via email, over the phone, through social media or via any other medium, including:

  • your contact details including: your first and last name, mailing address, email address, social media account name, or whatever method you contact us using;
  • the details of your communications with us; and
  • the details of our messages to you.

We use this personal information to:

  • answer and manage your questions; and
  • run analytics, statistics, and research.
  • Our legitimate interests—we have a legitimate business interest in (i) improving our products and services; (ii) better engaging with you; and (iii) securing our tools.

Online Browsing

Personal information that we collect through your use of our websites (which may be through cookies), including:

  • Internet Protocol (IP) address;
  • MAC address;
  • browser type;
  • operating system;
  • device identifying personal information;
  • the specific web pages visited during your connection;
  • the domain name from which you accessed our websites; and
  • your browsing behavior, such as the date and time you visit our websites, the areas or pages of the website that you visit, the amount of time you spend viewing our websites, the number of times you return to our websites, the products you selected to create your basket and other clickstream data.

For more personal information on cookies, see “Cookies and Traffic Data” Section.

We use this personal information to:

  • enhance your shopping experience while on our websites by showing you personalized content;
  • allow our websites to function properly;
  • ensure our websites are secure and safe, and to protect you against fraud or misuse of website or services (for example through performing troubleshooting);
  • run analytics, statistics, and research; and
  • deliver targeted advertising, that is to show you:

o   online advertisements for products which may be of interest to you, based on your previous behavior; and/or

o   ads and content on social media platforms or other websites.

  • Your consent to the processing, using, and storing.
  • Our legitimate interests—we have a legitimate business interest in (i) improving our products and services; (ii) better engaging with you; and (iii) securing our tools.

Third-Party Service Providers

Personal information that we collect from our third-party service providers, including:

  • payment processing companies; and
  • address update services.

We use this personal information to:

  • take payment from or give you a refund;
  • help us ensure that our customers are genuine and to prevent fraud
  • Performance of a contract—so we can perform our contract for the sale of our products to you.
  • Our legitimate interests—we have a legitimate business interest in preventing fraud.
  • To comply with our legal obligations.

Use of Social Media (1)

Personal information that we collect, or you give us, when you share or engage with our content through social media, including:

  • information about you that you have made publicly available through your social media profile (for example, your name, your photos or posts, and the photos, posts or the “likes” you make).

We use this personal information to:

  • use the content you have created and/or shared in accordance with the specific terms and conditions accepted by you; or
  • run analytics, statistics, and research.
  • Your consent to the processing, using, and storing.
  • Our legitimate interests—we have a legitimate business interest in (i) improving our products and services; (ii) better engaging with you; and (iii) securing our tools.

Promotions

Personal information that we collect, or you give us, when you participate in a sweepstakes, contest, or other promotion, including:

  • your name;
  • your contact details;
  • birthdate or age range;
  • address or country of residence;
  • personal information about you that you have made publicly available through your social media profile (if the promotion is run on a social media platform); and
  • user generated content.

We use this personal information to:

  • manage and operate the promotion;
  • use the content you have created and/or shared in accordance with the specific terms and conditions accepted by you; or
  • run analytics, statistics, and research.
  • Performance of a contract—so you may enter into the promotion and/or we can deliver the prize).
  • Your consent to the processing, using, and storing.
  • Our legitimate interests—we have a legitimate business interest in (i) improving our products and services; (ii) better engaging with you; and (iii) securing our tools.

User Generated Content

Personal information that we collect, or you give us, when you submit content (for example images or ratings and reviews) on our websites or social media platforms, or accept our re-use of any content you posted on social media platforms:

We use this personal information to:

  • use the content you have created and/or shared in accordance with the specific terms and conditions accepted by you; and
  • run analytics, statistics, and research.
  •   Your consent to the processing, using, and storing.
  •   Our legitimate interests—we have a legitimate business interest in (i) improving our products and services; (ii) better engaging with you; and (iii) securing our tools.
(1) Please note that you may be able to control what information you share through the privacy settings for your social media accounts—please refer to the applicable social media’s privacy policies and terms of use for more details and information.

Cookies and Traffic Data

Cookies

Certain cookies and web beacons that we employ are necessary for the operation of our websites. Other cookies that we employ are not necessary for the operation of our websites but are employed to enhance your use of our websites and shopping experience.

Our cookies may be session cookies (temporary cookies that identify and track users within our websites which are deleted when you close your browser or leave your session) or persistent cookies (cookies which enable our websites to “remember” who you are and to remember your preferences within our websites and which will stay on your computer or device after you close your browser or leave your session).

We use the following different types of cookies:

Category

Description

Strictly Necessary

These are cookies which are needed for our websites to function properly, for example, these cookies allow you to access secure areas of our website or to remember what you have put into your shopping basket.

Performance

These cookies allow us to keep a record of traffic data, count visits, traffic sources, access rates, page hits and page views so we can measure and improve the performance of our websites. They help us know which pages are the most and least popular and see how visitors move to and from and around our websites.

Functional

These cookies allow our websites to remember choices you make (such as your user name, language or the region you are in) and provide enhanced, more personal features. These cookies allow the provision of enhance functionality and personalization, such as chats. They may be set by us or by third party providers whose services we have added to our pages.

Targeting

These cookies are set through our websites by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant ads on other websites. They record a user’s visit to a website, the pages a user has visited and the links a user have followed. Companies will use this information to make the website more relevant to users. Companies may also share this information with third parties for this purpose.

You can find more general information about cookies and generally how to manage them at www.allaboutcookies.org.

For more information on opting-out of cookie and web beacon tracking, please see the “Opting Out of Cookie Tracking” section.

For more information on our advertising, please see the “Interest-Based Advertising” section.

Google Analytics

We use Google Analytics, which is a web analytics tool that helps us understand how users engage with our websites. Like many services, Google Analytics uses first-party cookies to track user interactions, as in our case, where they are used to collect details about how users use our websites. This information is used to compile reports and to help us improve our websites. The reports disclose trends without identifying individual visitors.

You can opt out of Google Analytics without affecting how you visit our websites – for more information on opting out of being tracked by Google Analytics across all websites you use, visit this Google page: https://tools.google.com/dlpage/gaoptout.

If you have consented to receiving communications from us and you do not wish to receive further communications from us about special offers and promotions, please see the “Opting Out of Promotional Emails” section and the "Opting Out of Third-Party Tailored Advertising" section.

For more information about interest-based advertising, including how you can opt-out or manage advertising, please see the “Interest-Based Advertising” section and “Opting Out of Third-Party Tailored Advertising” section.

How We Share Your Personal Information

We never sell, rent, or lease your personal information to any third-parties, though we may share your personal information as indicated in this Privacy Notice.

With Your Consent

We may disclose personal information collected from, and about, you (including your personal information) with companies, organizations or individuals with your express consent.

For External Processing

We rely on trusted third parties to perform a range of business operations on our behalf. We may provide to these service providers personal information collected from, and about, you (including your personal information), based on our instructions and in compliance with this Privacy Notice and any other appropriate confidentiality and security measures and we only provide them with the personal information they need to perform the service.

Examples include third parties that:

  • host or operate our websites and otherwise assist and help us in providing IT services, such as platform providers, hosting services, maintenance and support on our databases as well as on our software and applications;
  • process and deliver your orders (including warehouse logistics providers, transportation providers, payment processing providers, etc.);
  • assist and help us in managing our Beauty Squad Loyalty Program;
  • assist and help us in providing digital and e-commerce services such as social listening, social media, customer service, ratings and reviews, CRM, web analytics and search engine, user generated content curation tools; and
  • help us to deliver advertising, marketing, and campaigns and to analyze their effectiveness;
For Legal Reasons

We may share personal information collected from, and about you with third-parties if we are legally required to do so, or if we have a good-faith belief that access, use, preservation or disclosure of the personal information is reasonably necessary to:

  • meet any applicable law, regulation, legal process or enforceable governmental request;
  • respond to legal process (such as a search warrant, subpoena or court order);
  • enforce our Terms of Use (or other terms of service for our websites), including investigation of potential violations;
  • detect, prevent, or otherwise address fraud, security or technical issues; or
  • protect against harm to our rights, property or safety or the rights, property or safety of third-parties, our customers, or the public as required or permitted by law.
In Connection with a Sale or Merger

If we directly or indirectly undergo a business transition (including proposed transactions), like a merger, acquisition by another company, or sale of all or part its assets, we may disclose or transfer personal information collected from, and about, you (including your personal information), to the successor organization in the transition. We will make reasonable efforts to let you and others know (in the way described in the “Changes to This Privacy Notice” section) if your personal information has been disclosed or transferred in connection with a business transition.

Aggregated, Non-Personally Identifiable Information

We share aggregate, non-personally identifiable information with our service providers in order for those service providers to enhance and optimize their services and for statistical analysis, research, and other purposes.

How Long We Keep Your Personal Information

How long we retain your personal information depends on why and how we collected it and how we use it. We will keep your personal information for as long as we need it to provide you with your requested service(s) or to meet our commercial or legal obligations.

Unless our legal obligations require otherwise, we will keep your personal information collected by, or provided to us:

  • in connection with orders for seven years (though some of your personal information may be deleted earlier); and
  • in connection with your online browsing, for three years (though some of your personal information may be deleted earlier).

To determine the retention period of your personal information, we consider several criteria to make sure that we do not keep your personal information for long than is necessary or appropriate. These criteria include:

  • the purpose for which we hold your personal information;
  • our legal and regulatory obligations in relation to that personal information, for example any financial reporting obligations;
  • whether our relationship with you is ongoing;
  • any specific requests from you in relation to the deletion of your personal information; and
  • our legitimate business interests in relation to managing our own rights, for example the defense of any claims.

When we no longer need to retain your personal information, it will be deleted or be anonymized so that you can no longer be identified from it.

Please note, that, other than in response to a request to delete your personal information, we have no obligations to notify you when deleting your personal information and can do it at our sole discretion.

Security of Your Personal Information

We maintain reasonable and appropriate measures designed to maintain personal information we collect in a secure manner. We have taken certain physical, electronic, and administrative steps to safeguard and secure the personal information we collect. Even though we follow reasonable procedures to try to protect the personal information in our possession, no security system is perfect, and we cannot promise, and you should not expect, that your personal information will be secure in all circumstances. Please note that any transmission of personal information to us is at your own risk.

Your Privacy Rights

We respect your right to privacy and believe is important that you are able to control your personal information.

Accessing, Correcting, and Updating Your Personal Information

You may access your personal information by signing into your account. From there, you can correct, modify, or delete your personal information.

If you need assistance accessing, correcting, updating, or deleting your personal information or if you have questions about the collection of your personal information, please contact us using the contact information detailed in the “Contact Us” section.

California Privacy Rights

California law permits our customers who are California residents to request certain information about our disclosure of personal information to third parties for their own direct marketing purposes during the preceding calendar year. This request is free and may be made once a year.

To make such a request, please write to us at the following address:

e.l.f. Cosmetics, Inc.
570 10th Street
Oakland, CA 94607
ATTN: Legal Department
RE: California Privacy Info

If you are under 18 years of age, reside in California, and have a registered account with us, you have the right to request removal of unwanted information that you publicly post on our websites. To request removal of such information, please contact us using the contact information detailed in the “Contact Us” section. Upon receiving such a request, we will make sure that the information is not publicly available on our websites, but the information may not be completely or comprehensively removed from our systems and databases.

Complaints

We are transparent about the ways in which we collect and use personal information and welcome your questions and concerns. If you have any concern or complaint about the way we handle your personal information, please contact us as described below.

To the extent you believe we have not addressed your concerns or otherwise choose to do so, you have the right to complain to a supervisory authority in the country where you reside. Within the United States, you may contact the US Federal Trade Commission regarding your concerns. For more information, please see https://www.ftc.gov/faq/consumer-protection/submit-consumer-complaint-ftc.

How to Opt-Out of Certain Features

Opting Out of Promotional Emails

If you do not wish to receive communications from us about special offers and promotions, you can opt-out of receiving these communications by following the instructions contained in the messages you receive. Even if you opt-out of receiving these messages, we reserve the right to send you certain communications relating to the services we provide, and we may send you service announcements and administrative messages. We do not offer you the opportunity to opt-out of receiving those service or administrative communications.

Opting Out of SMS Text Messages

If you do not wish to receive communications from us about special offers and promotions, you can opt-out of receiving these communications by following the instructions in the SMS Text Messages Terms and Conditions.

Opting Out of Third-Party Tailored Advertising

If you are interested in more information about tailored advertising and your choices to prevent third parties from delivering tailored web and mobile web advertising, you may visit the following websites:

These opt-out tools are provided by third parties (and not by us). We do not control or operate these tools or the choices that advertisers and others provide through these tools.

Opting Out of Cookie Tracking

You can your browser to reject cookies, warn you about attempts to place cookies on your computer or device, or limit the type of cookies you allow. You can also manually delete individual or all the cookies on your computer or device by following your browser’s or device’s help file directions. Please note that browser- and device-management tools for cookies are outside of our control and we cannot guarantee their effectiveness. Please also note that flash cookies operate differently than browser cookies and cookie management tools available may not remove flash cookies.

Please note that if you turn off cookies that are not necessary for the operation of our websites, your browser or device is set to reject cookies, or you manually delete cookies, some or all the features and functionality of our websites may not function properly (including features we may add to the Site in the future).

Interest Based Advertising

We may use third-party advertising companies that use tracking technologies to serve our advertisements across the Internet. These companies may collect personal information about your visits to our websites and other websites/applications and your interaction with our advertising and other communications. These advertising companies serve ads on behalf of us and others on non-affiliated websites, and some of those ads may be personalized, meaning that they are intended to be relevant to you based on personal information collected about your visits to our websites and elsewhere over time. Other companies may also use such technology to advertise on our websites.

Our Policies Concerning Children

Our websites are not directed to children, nor do we knowingly collect any personal information from, children under the age of 13 without verifiable parental or legal guardian consent. If you believe that a child has provided personal information to us, please promptly contact us using the contact information detailed in the “Contact Us” section, and we will endeavor to investigate and delete such personal information from our systems.

California Online Privacy Protection Act Notice

There is currently no consensus among industry participants as to what “Do Not Track” browser signals mean and how to respond to “Do Not Track” browser signals (you can learn more about Do Not Track here). As such, we do not respond to such signals. Instead, to opt-out of cookie and web beacon tracking, please see the “Opting Out of Cookie Tracking” section, or to opt-out of website-based third-party interest-based or online behavioral advertising, please see the “Opting Out of Third-Party Tailored Advertising” section.

Third Party Websites

Our website may contain links to third-party websites, such as social media websites, such as Instagram, Facebook, YouTube, Pinterest, Twitter, and Snapchat, each of which may have privacy policies that differ from this Privacy Notice. We are not responsible for the activities and practices that take place on these websites. Accordingly, we recommend that you review the privacy policy or privacy notice/statement posted on any external website before disclosing any personal information. Please contact those websites directly if you have any questions about their privacy policies.

Existence of Automated Decision-Making

We use automated decision-making processes to personalize our websites to enhance your shopping and consumer experience (for example, by recommending certain products to you based on your order or browsing history) or to send you, if you have consented to receiving marketing materials from us, personalized promotional and marketing emails (for example, by highlighting certain products based on your order or browsing history).

Changes to This Privacy Notice

We may change this Privacy Notice from time to time, including as required to keep current with rules and regulations, new technologies and security standards. When we do, we will post the change(s) on the applicable website. If we change this Privacy Notice in a material manner, we will provide appropriate notice to you. If you wish to review a copy of the privacy notice effective prior to the effective date of this Privacy Notice, please contact us using the contact information detailed in the “Contact Us” section.

Contact Us

If you have questions or concerns about this Privacy Notice or how we collect and use the information of our customers, please contact us.

If we need, or are required, to contact you concerning any event that involves your information, we may do so by email, telephone, or mail.