FREE SHIPPING ON ORDERS $45+

LASH ARTISTS & EDUCATION >

BORBOLETA PRIVACY POLICY

This Privacy Policy describes how Borboleta Beauty Inc. (“Borboleta,” “we,” “us,” and/or “our”) handle personal data we collect online (through our websites) and offline (through customer support channels, and in-person promotional activities). We call all of these the “Services”. This Privacy Policy explains the types of personal data we collect and process, how we may use and share the data, and the choices that are available to you with respect to our handling of your personal data.

Information We Collect

Information we collect directly from you

We collect the information you provide directly to us, such as when you open an account, place an order, ask to receive emails, contact customer service, or interact with us on social media. The types of personal data we may collect directly from you include:

- Information that you provide by filling in forms on our websites;
- Contact information, such as your name, email address, mailing address, and phone number;
- Account information, such as your username and password;
- Billing information, such as credit card details and billing address;
- Details of transactions you carry out through our Website and of the fulfillment of your orders--you may be required to provide financial information before placing an order through our Website;
- Records and copies of your correspondence (including email addresses), if you contact us;
- Optional information you may choose to provide, such as your social handles, makeup and color preferences, age range, gender;
- Any other information you choose to provide, such as product reviews, responses to surveys or quizzes or to receive customer support; and
- Your search queries on our websites.

Information about your use of our Services

We collect information about your use of the Services, such as the products you buy or express interest in.

Information we collect from other sources

 We may collect information about you from other sources, including:

- Other users, such as through our referral program or e-gift card offerings. If you choose to participate in our referral program or purchase an e-gift card for someone else, we will collect information about your friend (such as a name and email address) in order to invite your friend to shop with us or send them their e-gift card.
- Third-party social media services. When you access the Services through a social network, we collect information about you from the social network in accordance with your settings on the social network. If you interact with us on social media, we will collect information about those interactions. The information we may collect includes your name and email address.
- Other unaffiliated third parties, such as advertising networks, media monitoring companies, and publicly available sources.

Location information

We may derive information or draw inferences about you based on the information we collect. For example, we may make inferences about your location based on your IP address or infer that you are looking to purchase certain products based on your browsing behavior and past purchases.

Information we collect by automated means

When you visit our sites, interact with our communications, we collect certain information automatically. To collect this information, we may use cookies, web beacons, and similar technologies. A “cookie” is a text file that websites send to a visitor‘s computer or other internet-connected device to uniquely identify the visitor’s browser or to store information or settings in the browser. A “web beacon,” also known as a pixel tag or clear GIF, is used to transmit information back to a web server. We may also collect information about your online activities over time and across third-party websites. The information we collect automatically may include:

- URLs that refer visitors to our websites;
- Search terms used to reach our websites;
- Details about the emails we send, such as opens, clicks, and unsubscribes;
- Details about the devices that are used to access our websites (such as IP address, browser information, device information, and operating system information);
- Details about your interaction with our websites (such as the date, time, length of stay, and specific pages accessed during your visits to our websites, referral activity, and which emails you may have opened);
- Usage information (such as the number and frequency of visitors to our websites).

We may associate this information with your Borboleta account if you have one, the device you use to connect to our Services, or email or social media accounts that you use to engage with Borboleta.

What are Cookies?

Like most websites, we use cookies and similar technologies to remember things about you so that we can provide you with a better experience.

Cookies are small data files stored on your browser or device. They may be served by the entity that operates the website you are visiting (“first-party cookies”) or by other companies (“third-party cookies”). For example, we partner with third-party analytics providers, like Google, which set cookies when you visit our websites. This helps us understand how you are using our Services so that we can improve them.

- Pixels are small images on a web page or in an email. Pixels collect information about your browser or device and can set cookies.
- Local storage allows data to be stored locally on your browser or device and includes HTML5 local storage and browser cache.

How We Use Cookies

We use cookies for a number of reasons, like helping us see which features are most popular, counting visitors to a page, improving our users’ experience, keeping our services secure, and generally providing you with a better experience. The cookies we use generally fall into one of the following categories.

Technical

These cookies are essential for our services to function properly. Like the other cookes we use, technical cookies may be either first-party cookies or third-party cookies.

Preferences

We use these cookies to remember your settings and preferences. For example, we may use these cookies to remember your language preferences.

Security

We use these cookies to help identify and prevent security risks.

Performance

We use these cookies to collect information about how you interact with our services and to help us improve performance. For example we may use cookies to determine if you have interacted with a certain page.

Analytics

We use cookies to help us understand how to improve our services. For example we can use cookies to learn more about which features are the most popular with our users and where we may need to make improvements.

Advertising

We and our advertising partners use these cookies to deliver advertisements, to make them more relevant and meaningful to visitors to our website, and to track the efficiency of our advertising campaigns, both on our services and on other websites.

Third-party Cookies

Some content or applications, including advertisements, on our websites are served by third-parties, including advertisers, ad networks and servers, content providers, and application providers. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our websites. The information they collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.

We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly. For information about how you can opt out of receiving targeted advertising from many providers, see Your Choices.

We do not control third parties’ collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. You can opt out of receiving targeted ads from members of the Network Advertising Initiative (“NAI”) on the NAI’s website.

California residents may have additional personal information rights and choices. Please see Your California Privacy Rights for more information.

Nevada residents who wish to exercise their sale opt-out rights under Nevada Revised Statutes Chapter 603A may submit a request to this designated address:

353 Pierpont Avenue

Salt Lake City, UT 84101

Email: support@borboleta.com

However, please know we do not currently sell data triggering that statute’s opt-out requirements.

Your Choices

You have a number of options to control or limit how we and our partners use cookies and similar technologies, including for advertising. Although most browsers and devices accept cookies by default, their settings usually allow you to clear or decline cookies. If you disable cookies, however, some of the features of our services may not function properly.

- To prevent your data from being used by Google Analytics, you can install Google’s opt-out browser add-on.
- For information on how our advertising partners allow you to opt out of receiving ads based on your web browsing history, please visit http://optout.aboutads.info/. European users may opt out of receiving targeted advertising through the European Interactive Digital Advertising Alliance.

Advertising and Analytics Services Provided by Others

We may allow others to provide analytics services and serve advertisements on our behalf across the internet and in mobile applications. They may use cookies, web beacons, and other technologies to collect information about your use of the Services and other websites and applications, including your IP address, device ID, web browser, mobile network information, pages viewed, time spent on pages or in apps, links clicked, and conversion information. This information may be used by Borboleta and others to, among other things, analyze and track data, determine the popularity of content, deliver advertising and content targeted to your interests on our Services and other websites, and better understand your online activity. For more information about interest-based ads, or to opt out of having your web browsing information used for interest-based advertising purposes, please visit www.aboutads.info/choices. European users may opt out of receiving targeted advertising through the European Interactive Digital Advertising Alliance.

We may also work with third parties to serve ads to you as part of a customized campaign on third-party platforms (such as Facebook or Google). As part of these ad campaigns, we or third-party platforms may convert information about you, such as your email address, into a unique value that can be matched with a user account on these platforms to allow us to learn about your interests and to serve you advertising that is customized to your interests. Note that the third-party platforms may offer you choices about whether you see these types of customized ads.

How We Use Your Information

We may use the information we collect to deliver the products and Services you request, to maintain and customize your account and our interactions with you (such as on our digital properties), and to provide, maintain, and improve our Services. We also use the information we collect to:

- Create and manage your online accounts and profiles;
- Communicate with you about our Services, including to tell you about products and services that may be of interest to you;
- Complete the transactions you request, perform our contractual obligations, and use as otherwise anticipated within the context of our ongoing business relationship;
- Respond to your requests, inquiries, comments, and suggestions;
- Facilitate your engagement with the Services, including to enable you to post comments and reviews, to engage with other customers, and to post on social media;
- Offer contests, sweepstakes, loyalty programs or other promotions;
- Personalize your online experience and the advertisements you see when you use the Services or third-party platforms based on your preferences, interests, purchasing history and browsing behavior;
- Monitor, audit and analyze trends, usage, and activities in connection with our Services;
- Carry out short-term activities and other internal uses related to the products or services you purchase from us or your ongoing relationship with us;
- Conduct internal research and development;
- Detect, investigate, and respond to security incidents and protect against illegal or objectionable activities, including the unauthorized use of the Services, and protect the rights and property of Borboleta and others;
- Debug, identify and repair errors that impair existing intended functionality of our Services;
- Comply with our legal obligations, including those required for you to benefit from rights recognized by law, or any regulatory requirements or provisions; and
- Conduct or administer surveys and other market research.

Who May Have Access to Your Information

Within Borboleta: We may disclose certain of your personal data to Borboleta affiliates and personnel who need to know the information for the purposes described above, including personnel in the customer service and information technology departments.

Third-Party Service Providers: We may use third party service providers acting on Borboleta’s behalf to perform some of the services described above. For example, we share certain information with service providers who assist with the processing of credit cards and payments, hosting, managing and servicing our data, distributing emails, conducting research and analysis, advertising, analytics, or administering certain services and features. We also may share information about you with our professional advisors, including accountants, auditors, lawyers, insurers and bankers, if needed. These service providers may change over time, but we will always use trusted service providers who we require to take appropriate security measures to protect your personal data in line with our policies. We only permit them to process your personal data for specified purposes and, as appropriate, in accordance with our instructions and the provisions of this Policy and applicable law.

Other Third Parties: In certain limited circumstances, we share and/or are obligated to share your personal data with other third parties, including (a) to comply with our obligations, to protect the rights and property of Borboleta, our customers and the public, to cooperate with law enforcement investigations, and to detect and respond to suspected illegal activity and threats to the health or safety or any person or of our systems or services; (b) in connection with, or during negotiations of, any merger, joint venture, sale of company assets, financing, or acquisition of all or a portion of our business, assets or stock by another company (including in connection with any bankruptcy or similar proceedings); and/or (c) with your consent and at your direction.

When you provide a product review or post other user content, that content may be publicly posted. Other users may be able to see your name or other information about you that you post. In certain instances, we may also share aggregated or de-identified information that cannot reasonably be used by those third parties to identify you.

Your Rights and Choices

We strive to provide you with choices regarding the personal information you provide to us. We have created mechanisms to provide you with the following control over your information:

Managing or deactivating your Borboleta account

You may review, update, or modify your account information, including profile, contact, payment and shipping information, at any time by logging into your Borboleta account. You may also deactivate your Borboleta account by emailing support@borboleta.com.

Opting out of email marketing

You may unsubscribe from our promotional emails at any time by following the instructions included in those emails. If you opt out of receiving such communications, note that we may continue to send you non-promotional emails (such as order confirmation emails or emails about changes to our legal terms).

Restricting cookies

Most web browsers are set to accept cookies by default. You can usually choose to set your browser to remove or reject browser cookies. Please note that if you choose to remove or reject cookies, this could affect the availability and functionality of our websites.

Web Push Notifications/Alerts

With your consent, we may send promotional and non-promotional push notifications or alerts to your browser. You can deactivate these messages at any time by changing the notification settings on your browser.

Children

Our Website is not designed or intended for children under 16 years of age. Our Website is intended for persons who are 18 or older. If you have reason to believe that a child has provided personal data to us, please contact us. We do not knowingly collect personal information from children under 16. If you are under 16, do not use or provide any information on this Website or on or through any of its features. If we learn we have collected or received personal information from a child under 16 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 16, please contact us at:

353 Pierpont Avenue
Salt Lake City, UT 84101

Phone: (888) 850-8963
Email: support@borboleta.com

California residents under 16 years of age may have additional rights regarding the collection and sale of their personal information. Please see Your California Privacy Rights for more information.

Data Transfers and Privacy Shield

Borboleta is headquartered in the United States, and we have operations in the United States and other countries. As such, we may transfer your personal data to, or store or access it in, jurisdictions that may not provide equivalent levels of data protection as your home jurisdiction. We will take steps to ensure that your personal data receives an adequate level of protection in the jurisdictions in which we process it.

When we transfer personal data from the European Union, the United Kingdom or Switzerland to the United States, we do so in reliance on an approved data transfer mechanism, such as the Standard Contractual Clauses adopted by the European Commission. We also comply with the EU-U.S. Privacy Shield Framework and the Swiss - U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal data transferred from the European Union and Switzerland to the United States, respectively (collectively, the “Privacy Shield Principles”). Borboleta has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/.

In compliance with the Privacy Shield Principles, we are committed to resolving complaints about our processing of your personal data. EU, UK and Swiss individuals with inquiries or complaints regarding our compliance with the Privacy Shield program should first contact us. We have further committed to refer unresolved Privacy Shield complaints to JAMS, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit EU-US Privacy Shield and Safe Harbor Programs for more information or to file a complaint. The services of JAMS are provided at no cost to you.

Under certain conditions, you may be able to invoke binding arbitration to resolve your complaint. Borboleta is subject to the investigatory and enforcement powers of the Federal Trade Commission.

If we share personal data transferred to the U.S. under the Privacy Shield with a third-party service provider that processes such data on our behalf, then we will be liable for that third party’s processing in violation of the Privacy Shield Principles, unless we can prove that we are not responsible for the event giving rise to the damage.

European Residents

Data Subject Requests

If you are a European Resident, you have the right to access personal data we hold about you and to ask that your personal data be corrected, updated, or erased. You may also have the right to object to, or request that we restrict, certain processing. If you would like to exercise any of these rights, you may submit a request here. If you have a Borboleta account, you may also review, update, and delete certain personal data by logging into your account.

Legal Basis for Processing

If you are a European Resident, we process your personal data when:

- We need to use your personal data to perform our responsibilities under our contract with you (e.g., processing payments for and providing the Borboleta products you have ordered).

- We have a legitimate interest in processing your personal data. For example, we may process your personal data for performance marketing activities, to conduct data analytics and to provide, secure, and improve our Services.

- We need to do so to comply with a legal obligation to which we are subject.

- We need to do so to protect your vital interests or those of others.

- We have your consent to do so, which you may withdraw at any time.

Data Subject Requests

If you are a European Resident, you have the right to access personal data we hold about you and to ask that your personal data be corrected, updated, or erased. You may also have the right to object to, or request that we restrict, certain processing. If you would like to exercise any of these rights, you may submit a request here. If you have a Borboleta account, you may also review, update, and delete certain personal data by logging into your account.

Questions or Complaints

If you are a European Resident and have a concern about how we process personal data that we are not able to resolve, you have the right to lodge a complaint with the data privacy authority where you live. For contact details of your relevant local Data Protection Authority, please see http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm or, if you are a resident of Switzerland, https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact/.

Your California Privacy Rights

The California Consumer Privacy Act or “CCPA” (Cal. Civ. Code § 1798.100 et seq.) and the Shine the Light law (Cal. Civ. Code § 1798.83) afford consumers residing in California certain rights with respect to their personal data. If you are a California resident, this section applies to you.

California Consumer Privacy Act

The CCPA requires us to disclose the following information with respect to our collection, use, and disclosure of personal data. In the preceding 12 months, we have collected the following categories of personal data: identifiers; commercial information; demographic information (note that some demographic information may be considered characteristics of protected classifications under state or federal law); internet or electronic network activity; geolocation data; audio, electronic, visual, thermal, olfactory, or similar information; inferences; and other categories of personal data that relates to or is reasonably capable of being associated with you. For examples of the precise data points we collect, please see “Information We Collect” above. We collect personal data for the business or commercial purposes described in the “How We Use Your Information” section above. In the preceding 12 months, we have disclosed the following categories of personal data for business to the following categories of recipients:

Advertising networks, marketing partners, data analytics providers, market research platform, payment processors, fulfilment partners, customer support partners, Internet service providers, operating systems and platforms, other users, fraud prevention partners, cloud service providers, technical maintenance and system security providers Data analytics providers, advertising networks, marketing partners, market research platform, payment processors, fulfilment partners, customer support partners, and fraud prevention partners, cloud service provider Advertising networks, marketing partners, data analytics providers, Internet service providers, operating systems and platforms, cloud service providers, fraud prevention partners, technical maintenance and system security providers Advertising networks, marketing partners, data analytics providers, Internet service providers, operating systems and platforms Advertising networks, data analytics providers, customer support partners, fraud prevention partners, cloud service providers Customer support partners, market research platform, facility security partners Advertising networks, marketing partners, market research platform, other users, customer feedback platforms Category of Personal Data Identifiers Commercial Information Internet or other electronic network activity Geolocation data Inferences Audio, electronic, visual, or similar information Characteristics of Protected Classifications under state or federal law, such as age Categories of recipients

Borboleta does not sell your personal data. We do allow our advertising partners to collect certain device identifiers and electronic network activity via our Services to show ads that are targeted to your interests. To opt out of having your personal data used for targeted advertising purposes, please see the Advertising and Analytics Services Provided by Others section above.

Subject to certain limitations, California consumers have the right to (1) request to know more about the specific pieces and categories of personal data we collect, use, and disclose, (2) request deletion of their personal data, and (3) opt out of any “sales” of your personal data that may be occurring, and (4) not be discriminated against for exercising these rights. You may make a request to know more about or delete your personal data by emailing support@borboleta.com. Additionally, access requests can be made by calling (888) 850-8963. We will verify your request by contacting you after receiving your request to verify your identity. Please note that we may retain certain information as required or permitted by applicable law. If you request to delete your personal data, certain of our products and services may no longer be available to you.

If we receive your request from an authorized agent, we may ask for evidence that you have provided such an agent with a power of attorney or that the agent otherwise has valid written authority to submit requests to exercise rights on your behalf.

We offer various financial incentives. For example, we may provide discounts or other benefits to customers who sign up to receive our marketing emails. When you participate in a financial incentive, we collect personal data from you, such as identifiers like your name and email address. You can opt into a financial incentive by following the sign-up instructions, and you have the ability to opt-out of the incentive by contacting us. In some cases, we may provide additional terms and conditions for a financial incentive, which we will provide to you when you sign up. The value of your personal data is reasonably related to the value of the offer or discount presented to you.

Shine the Light

California law permits residents of California to request certain details about how their information is shared with third parties for direct marketing purposes or to opt out of such sharing. We do not share your personal data with third parties for their own direct marketing purposes.

Links to Other Websites and Third-Party Content

We may provide links to third-party websites, services, plug-ins and applications, such as Facebook and Google, that are not operated or controlled by Borboleta. This Privacy Policy does not apply to such third-party services, and we cannot take responsibility for the content, privacy policies, or practices of third-party services. We encourage you to review the privacy policies of any third-party services before providing any information to or through them.

The Services may offer social sharing features and other integrated tools (such as the Facebook "Like" or "Share" button or the Twitter “Tweet” button) which let you share actions you take on our Services with other media. Your use of such features enables the sharing of information with your friends or the public, depending on the settings you establish with the entity that provides the social sharing feature. For more information about the purpose and scope of data collection and processing in connection with social sharing features, please visit the privacy policies of the entities that provide these features.

Data Retention

Our retention periods for personal data are based on business needs and legal requirements. We retain personal data for as long as is necessary for the processing purpose(s) for which the data was collected, and any other permissible, related purpose. For example, we may retain certain transaction details and correspondence until the time limit for claims arising from the transaction has expired. When we no longer need to use your personal data, it is removed from our systems and records or anonymized so that you can no longer be identified from it.

Data Security

We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. All information you provide to us is stored on our secure servers behind firewalls. Any payment transactions will be encrypted using SSL technology.

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our websites, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our websites. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the websites.

Changes to Our Privacy Policy

We may change this Privacy Policy from time to time. If we do so, we will post the updated policy on our sites and will indicate when the Privacy Policy was last revised. If we make any material changes, we will provide you with additional notice. You should periodically review our current Privacy Policy to stay informed of our personal data practices.

Contacting Borboleta

If you have questions or concerns regarding this Privacy Policy, please contact us using the information provided below:

Customer Support

Phone: (888) 850-8963

Email: support@borboleta.com

Address:

Borboleta Beauty Inc.

353 Pierpont Avenue

Salt Lake City, UT 84101