If you are a consumer in the United States, this privacy policy (“Privacy Policy“) explains how MELT NATURALS LLC. (“MELT,” “we,” “us,” or “Data Controller”) collects, uses, processes, discloses, and retains your personal data when you access or use our websites, mobile applications or any other applications or services that display this Privacy Policy (collectively, the “Services”), shop in our stores, visit or otherwise engage with our Guest Education Centre, register for and attend our events, engage with us on social media, or otherwise interact with us. Please review this Privacy Policy carefully.
Please note that we provide different or additional privacy notices in connection with certain activities, programs, and offerings. For more information about our privacy practices in another jurisdiction, please refer to the privacy policy available in our stores, or posted on our website, for that jurisdiction. Our privacy practices are subject to applicable laws in the places in which we operate, which means we engage in the practices described in this notice in a particular country or region only as permitted under the laws of such jurisdictions.
Also, we may provide additional “just-in-time” disclosures or information about our data processing practices. These notices may supplement or clarify our privacy practices or may provide you with additional choices about how we process your personal data.
REVISIONS TO THIS PRIVACY POLICY
MELT reserves the right to change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of this Privacy Policy. If we make material changes to this Privacy Policy, we will provide you with additional notice (such as adding a statement to our websites’ homepages or sending you a notification).
In this Privacy Policy, “personal data” means any information that is related to an identified or reasonably identifiable natural person, or as otherwise defined under applicable law. The types of personal data we collect about you depend on your interactions with us and are described in more detail below.
PERSONAL DATA YOU PROVIDE DIRECTLY TO US
We collect personal data directly from you when you interact with us or use our Services. The types of personal data we collect depends on how you interact with us or use our Services. We may collect the following categories of personal data.
Profile Data. We collect any information or content you provide to us when you register for an account, create a profile, or participate in or register for our ambassador or membership programs. Examples of the information we collect include your name, email, phone number, login name and password, address, payment or banking information, birthday, and classes you teach or attend in connection with our ambassador program.
Demographic Data. We may collect specific or general demographic data when you fill out forms or surveys on our Services or in our stores or sign up for and participate in events, contests, sweepstakes, promotions, and special programs that we provide. Examples of such information include age, gender, zip code, state, and country.
Transaction Data. We collect transaction information related to the use of our Services or your purchases. Examples of information collected include the type of products or services requested or provided, order details, delivery information, amount charged, payment method, billing or shipping information, customization services, and information about any products or services you returned or exchanged with us.
Communications Data. We collect information when you communicate with us or others on our Services, such as when you request additional information about products or services, interact with our customer service team or store associates, or sign up to receive our e-mail newsletters or marketing messages. We also collect communications data when you interact with us on social media, such as by tagging us and/or our products or permitting us to follow your social media profile. Examples of such data may include your contact information, the date and time of your communications, online identifiers, social media profile, and the content of your communications.
User Content Data. We collect any other information or content you provide to us, such as when you provide design or product feedback or make other submissions to us, participate in any of our experiential offerings in our stores or at other locations sponsored by us, or use other features of our Services that may be offered from time to time, which may require the collection of certain personal data in order to utilize the features. Examples of user content data may include information about your size, fit, goals, opinions, feedback, preferences, and any other personal data you choose to provide in your interactions with us.
PERSONAL DATA WE COLLECT AUTOMATICALLY
We automatically collect certain personal data when you access and use our Services or shop in our stores. The types of information we collect may include:
Device and Network Data. We collect certain information about the device you use to access our Services. Examples of such data include your device’s hardware model, browser type, IP address, operating system version, language settings, unique device identifiers, advertising identifiers, serial numbers, device motion data, and mobile network data.
Usage Data. We collect information about your activity on our Services via log files, cookies, web beacons, and other tracking technologies. Examples of such data include your access times, pages viewed, the routes by which you access our Services, app crashes and other system activity, your use of any hyperlinks available within our Services, your Internet service provider (ISP), Mobile Advertising ID, media access control (MAC) address, and identifiers associated with browser cookies, web beacons, and similar technologies we deploy on our Services (for more information about cookies and how to disable them, see the COOKIES section below).
Audio, Video or Sensory Data. We collect audio, video or sensory information from you. Examples of such data include video recording when you physically visit our stores, sensory data collection when you participate in a product test requiring sensory data, or audio recording when you call our Guest Education Centre.
Location Data. We collect precise or approximate location information in accordance with your device permissions. You may use our Services without enabling us to collect location data from your device, however, this may affect some functionality available in the Services. For example, you may need to manually enter an address to find a store near you if you have not enabled location data collection. For more details, please see “YOUR CHOICES” below. We may also use technology in our retail locations to collect data about the presence of your device.
PERSONAL DATA WE COLLECT FROM OTHER SOURCES
We may collect personal data about you from other sources. For example, we may collect personal data about you from:
Fitness studios and providers of online booking tools when you sign up for and participate in classes offered or sponsored by us;
Our other customers, including when they bring you as a guest to one of our events, refer you, or list you as an emergency contact;
Third parties hosting events, including those sponsored by MELT, when they share event attendance or participation information with us;
Publicly available sources;
Other guests or third parties providing information in connection with a dispute;
Carriers or other third parties when they share your updated delivery and address information, which we use to correct our records and deliver your next purchase or communication;
Our holding company, subsidiaries and affiliates;
Third-party social media and communication services, such as Facebook, Twitter, Google, and Instagram, that you use to interact with our Services (e.g., to create an account) or that allow you to share information (e.g., via plugins, widgets or other tools), but always in accordance with the authorization procedures and privacy settings you establish with such services; and
Unaffiliated parties, such as service providers that we use, analytics companies, marketing or advertising service providers, fraud prevention service providers, consumer data resellers, and other third parties that provide us with information, so we can better understand you and provide you with information and offers that may be of interest to you.
PERSONAL DATA WE DERIVE
We may derive information or draw inferences about you based on the other types of personal data we collect. For example, we may infer your location based on your IP address, or your purchasing habits based on your browsing behavior on our Services.
We collect and use personal data for various purposes, including to:
Provide Products and Services. Provide, maintain, and improve our data, products, events, and services;
Complete Transactions. Complete the transactions you request, perform our contractual obligations, and as otherwise anticipated within the context of our ongoing business relationship;
Manage Accounts. Create and manage your online accounts, profiles, and lululemon program memberships;
Service Communications. Send notifications related to your account, purchases, exchanges, and returns;
Respond to You. Respond to your requests and any other communications from you, including to provide customer service;
Advertising and Marketing. Send advertising or marketing communications about products, services, offers, promotions, rewards, and events offered by lululemon and others, and provide news and information that we believe may be of interest to you. Our marketing and advertising will be conducted in accordance with your advertising marketing preferences and as permitted by applicable law;
Events and Offers. Offer, conduct and administer events, classes, contests, prize draws, sweepstakes, and other promotions;
Research and Development. Conduct research and development;
Personalize Your Experience. Monitor, analyze and audit your engagement with our brand and your interactions with our Services and online ads to better understand your interests and behaviors and customize your experience;
Safety and Security. Detect and protect against malicious, deceptive, or illegal activity, including fraudulent transactions, error, negligence, and breach of contract, security incidents, and harm to the rights, property or safety of lululemon and our users, customers, employees or others;
Troubleshooting. Debug, identify and repair errors that impair existing intended functionality of our Services;
Corporate Transactions. We may process personal data in the context of corporate acquisitions, mergers, or other corporate transactions;
Your Consent. We may process your personal data in accordance with your consent or instructions;
Comply with Legal Obligations. Comply with our legal or regulatory obligations, including our tax obligations and those related to the prevention of fraud and money laundering, and those required for you to benefit from rights recognized by law, or any regulatory requirements or provisions; and
Reasonable Other Purposes. As permitted by applicable law, carry out certain short-term activities and other reasonable purposes related to the products or Services you purchase from us or your ongoing relationship with us. Where required by applicable law, lululemon will provide a notice of such data processing prior to using your personal data for such purposes.
We share personal data for the purposes described below:
With our Affiliates and Subsidiaries. We share your personal data with our holding company, subsidiaries and affiliates for the purposes described in the “USE OF PERSONAL DATA” section above. Since our holding company, subsidiaries, and affiliates are located around the world, please note that these disclosures involve cross-border transfers of your personal data as described in the “DATA TRANSFERS” section below.
With our Service Providers. We share personal data with unaffiliated companies or individuals we hire or work with that perform services on our behalf, including customer support, web hosting, information technology, payment processing, product fulfilment, fraud control, direct mail and email distribution, events, contest, sweepstakes and promotion administration, and advertising and analytics services. These third-party service providers have access to personal data needed to perform their services but may not use it for other purposes. Since our service providers are located around the world, please note that these disclosures involve cross-border transfers of your personal data as described in the “DATA TRANSFERS” section below.
In Connection with a Corporate Transaction. Personal data may be disclosed or transferred as part of, or during negotiations of any purchase, sale, lease, merger, amalgamation, or any other type of acquisition, disposal, securitisation or financing involving lululemon.
With our Professional Advisors. We share personal data with our legal, financial, insurance, and other advisors in connection with the kinds of corporate transactions described above or in connection with the management of all or part of lululemon’s business or operations.
With Law Enforcement Authorities and Individuals Involved in Legal Proceedings. We disclose personal data when we believe doing so is reasonably necessary to comply with applicable law or legal process (including an enforceable request from authorities), to respond to claims (including inquiries by you in connection with your purchases from lululemon), enforce or apply our TERMS OF USE, or to protect the rights, property, or personal safety of lululemon, our users, employees, or others.
With Your Consent or at Your Direction. We share personal data with third parties when we have your consent to do so. For example, if you decide to participate in certain interactive areas or features of our events or Services, such as creating a public profile and posting your goals, you consent to the disclosure of this information to other users of our websites. We may also share your personal data with third parties when you intentionally direct us to do so or when you use our Services to intentionally interact with third parties.
Aggregated, Anonymized or De-identified Data. We may also share aggregated, anonymized or de-identified information, which cannot reasonably be used to identify you.
We may allow others to provide analytics services and serve advertisements on our behalf across the web and in mobile applications. These entities may use cookies, web beacons, device identifiers, and other tracking technologies which collect information about your use of the Services and other websites and applications. This information may be used by lululemon and others to, among other things, analyze and track data, determine the popularity of certain content, deliver advertising and content targeted to your interest on our Services and other websites, and better understand your online activity. For more information about interest-based ads, or to opt out of having your web browsing information used for behavioral advertising purposes, please visit WWW.ABOUTADS.INFO/CHOICES. For advertisements on any third party platforms, please refer to the particular third party platform’s Privacy Policy to learn more about your choices.
For the reasons and purposes set forth in this Privacy Policy, the personal data that we collect may be transferred to and stored or otherwise processed in the United States, Canada, and other locations. We also transfer personal data to service providers that process personal data for us in the United States, Canada and other locations (as an example, Amazon Web Services processes information for us in various data center locations, including those listed at HTTPS://AWS.AMAZON.COM/ABOUT-AWS/GLOBAL-INFRASTRUCTURE/). While in another jurisdiction for processing, your personal data may be accessed by the courts, law enforcement, and national security authorities of that jurisdiction. These jurisdictions may not provide the same level of data protection as your home jurisdiction.
RETENTION OF PERSONAL DATA
We retain personal data in accordance with applicable law. Unless otherwise required by applicable law, lululemon will take reasonable steps to destroy or permanently de-identify personal data we hold if such personal data is no longer needed for the purpose for which it was collected.
Please note that our websites contain links to third-party websites that are not controlled or operated by lululemon. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that lululemon does not accept any responsibility or liability for these policies. Please review these policies before you disclose any personal data when visiting such third-party websites.
Consistent with applicable law, you may exercise any of the choices described in this section. As further explained below, some of your choices may be submitted via our PRIVACY PORTAL. Please note that we may ask you to verify your identity and request before taking further action on your request.
ACCESS & DATA PORTABILITY
In certain jurisdictions, applicable law may entitle you to request access to or copies of your personal data stored by lululemon via the Privacy Portal. You may also be entitled to request copies of personal data that you have provided to us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible).
CORRECTION
You may review and modify your account and profile information by logging into your online account at any time. If you cannot update the information yourself, you can also contact the GUEST EDUCATION CENTRE and request that we update your account or profile information.
DELETION
In certain jurisdictions, applicable law may entitle you to request deletion of your personal data stored by MELT via the Privacy Portal. Please note that if you request the erasure of your personal data, we may retain and/or use your personal data to:
Exercise our legitimate business interests, such as fraud detection and prevention and enhancing safety against malicious, deceptive, fraudulent or illegal activity, and/or to prosecute those responsible for such activity;
Establish, exercise or defend legal claims, or comply with applicable law;
Perform our contract to which you are a party or in order to take steps at your request prior to entering into a contract;
Perform a task carried out in the public interest or in the exercise of official authority vested in lululemon;
Identify, debug and/or repair errors that impair intended functionality;
Exercise free speech, and ensure the right of others to exercise their free speech or another right provided by law;
Complete a transaction and/or provide a good or service requested by you or reasonably anticipated by you within the context of the business relationship, or to otherwise perform the contract;
Protect your vital interests, or the vital interests of others; and,
As otherwise permitted under applicable law.
MARKETING COMMUNICATIONS
You may opt out of receiving promotional communications from us by following the instructions in those communications or by logging into your online account and changing your communications preferences. If you opt out, we may still send you non-promotional communications, such as those about your account or our ongoing business relations.
LOCATION DATA
When you first launch any of our mobile applications that collect precise location information, you will be asked to consent to the application’s collection of this information. If you initially consent to our collection of this location information, you can subsequently stop the collection of this information at any time by changing the preferences on your mobile device. If you do so, our mobile applications, or certain features thereof, may no longer function properly.
MOBILE PUSH NOTIFICATIONS/ALERTS
With your consent, we may send promotional and non-promotional push notifications or alerts to your mobile device. You can deactivate these messages at any time by changing the notification settings on your mobile device.
COOKIES AND SIMILAR TRACKING TECHNOLOGIES
Like many websites, lululemon uses cookies to analyze visits to our website and help us improve our website and services. Most web browsers are set to accept cookies by default. If you prefer, you can usually set your browser to remove or reject cookies. Please follow your browser’s process for doing so. Please note that if you choose to remove or reject cookies, this could affect the availability and functionality of our websites.
TECHNOLOGIES IN OUR RETAIL STORES
We have deployed WiFi access points in some of our stores, and we receive aggregate reports regarding store traffic that relies in part of information collected from the WiFi access points to track traffic patterns in our stores. Where such technology is used, we will provide a prominent notice at the location. If you wish to exclude your device from such in-store mobile analytics, you can opt out at any time by turning off WiFi on your device.
If you are a California resident, the California Consumer Privacy Act (“CCPA”) requires us to disclose the following information with respect to our collection, use, and disclosure of personal data. If you are a California resident, this section applies to you.
CATEGORIES OF PERSONAL DATA COLLECTED
In the preceding 12 months, we have collected the following categories of personal data: identifiers, characteristics of protected classifications under California or U.S. law, commercial information, internet and electronic network activity, geolocation data, audio and visual information, inferences drawn about your preferences, and other categories of personal data that relate to or are reasonably capable of being associated with you. For examples of the precise data points we collect and the categories of sources of such collection, please see “COLLECTION OF PERSONAL DATA” above.
BUSINESS OR COMMERCIAL PURPOSE FOR COLLECTING AND USING DATA
We collect personal data for the business or commercial purposes described in the “USE OF PERSONAL DATA” section above.
CATEGORIES OF PERSONAL DATA DISCLOSED AND CATEGORIES OF THIRD-PARTY RECIPIENTS
In the preceding 12 months, we have disclosed the following categories of personal data for business or commercial purposes to the following third parties:
We share identifiers with: advertising networks, Internet service providers, data analytics providers, operating systems and platforms, social networks, payment processors, fulfillment partners, customer support partners, events and promotions partners, and fraud prevention partners.
We share internet and electronic network activity information with: advertising partners, Internet service providers, data analytics providers, operating systems and platforms, internet service providers, customer support partners, and fraud prevention partners.
We share commercial information with: advertising partners, data analytics providers, payment processors, fulfillment partners, customer support partners, and fraud prevention partners.
We share audio and visual information with: customer support partners, events and promotions partners, and fraud prevention partners.
We share geolocation data, characteristics of protected classifications under California or U.S. law, and inferences with: advertising networks, internet service providers, data analytics providers, and fraud prevention partners.
Subject to certain limitations and in addition to the choices enumerated under the “Your Choices” section in the Privacy Policy, you have the right to (1) request to know more about the categories and specific pieces of personal data we collect, use, and disclose, (2) request deletion of your personal data, (3) opt out of any sales of personal data that may be occurring, and (4) not be discriminated against for exercising these rights. Please note that you may designate an authorized agent to exercise these rights on your behalf by providing the authorized agent signed permission to submit the request on your behalf. If an authorized agent submits a request on your behalf, we may need to contact you to verify your identity and protect the security of your personal data.
We will not discriminate against you if you choose to exercise your rights.