PRIVACY POLICY

CRYSTALS.COM, INC. PRIVACY POLICY 

Last Updated: March 25, 2020

This Privacy Policy explains how Crystals.com, Inc. (“Crystals”) collects, uses, and discloses information about you through its website, mobile application, and other online products and services that link to this Privacy Policy (collectively, the “Services”) or when you otherwise interact with us.

We may change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of the policy and, in some cases, we may provide you with additional notice (such as adding a statement to our homepage or sending you a notification). We encourage you to review the Privacy Policy whenever you access the Services or otherwise interact with us to stay informed about our information practices and the choices available to you.

Collection of Information

Information You Provide to Us

Crystals collects information from you when you choose to provide it to us, such as when you make a purchase, create an account, sign up for our email list, provide a product review or rating, or otherwise contact us. As described in more detail below, the information we collect may include your name, billing and shipping address(es), email address, payment card information, phone number, birthdate, account username and password, and product rating or review. If you refuse to provide any requested information (whether or not required), you may not be able to take full advantage of any in-store services, the website or its features.

  • Make a Purchase: Through the website at any of our retail locations, you will be able to purchase Crystals’ products. We may ask for your name, billing and shipping address(es), telephone number, email address, and payment card information in order to process and confirm your order and ship your item(s) to you.
  • Create an Account: Through the website, you may create a personal shipping account with Crystals, which can make the shipping process faster and easier. Crystals will store the following information in your account, should you choose to provide it to us: your name, billing and shipping address(es), email address, phone number, and birthdate. Crystals (or its third-party provider) may also store your credit card information should you chose to enable this feature. To establish an account, you will need to create a username and a password that will allow access to the account, where you can add, delete, or change the information you have provided. If you elect to use a public computer to access your account, please remember to log out at the conclusion of your session.
  • Email List: Through the website or at any retail location, you may add your email address to the Crystals email list. Crystals will never share your email address with, or sell your email address to, a third party that is not a Preferred Provider (as defined below) or that is otherwise directly or indirectly affiliated with Crystals. You may opt out of receiving marketing emails from Crystals at any time by selecting the “unsubscribe” option within the email or contacting us at info@crystals.com
  • Ratings and Reviews: Through the website, you may provide a public rating or review of a product you purchased. You are required to provide your email address when you provide a public rating or review. We will not publish your email address, but please remember that any information you may disclose in these public areas of the website becomes public information. As a result, please exercise caution when disclosing personal information in these public areas.
  • Customer Service: If you engage with our customer service center by email at info@crystals.com, you may be asked for information such as your name, email address, billing and shipping address(es), telephone number, and order number (if you have made a purchase). We use this information to assist you and address your needs.

Information About Your Use of the Services

Automatically Collected Information

When you access or use our Services, we automatically collect information about you, including:

  • Log Information: We collect log information about your use of the Services, including the type of browser you use, app version, access times, pages viewed, your IP address and the page you visited before navigating to our Services.
  • Device Information: We collect information about the computer or mobile device you use to access our Services, including the hardware model, operating system and version, unique device identifiers, and mobile network information.
  • Information Collected by Cookies and Other Tracking Technologies: We use various technologies to collect information, including cookies and web beacons. Cookies are small data files stored on your hard drive or in device memory that help us improve our Services and your experience, see which areas and features of our Services are popular and count visits. Web beacons are electronic images that may be used in our Services or emails and help deliver cookies, count visits and understand usage and campaign effectiveness. For more information about cookies and how to disable them, please see “Your Choices” below.

Information We Collect from Other Sources: We may obtain information from other sources and combine that with information we collect through our Services. For example, we may collect information about you from third parties, including but not limited to identity verification services, credit bureaus, mailing list providers and publicly available sources. Additionally, if you create or log into your account through a social media site, we will have access to certain information from that site, such as your name, account information and friends lists, in accordance with the authorization procedures determined by such social media site. We also work with third-party business partners (“Preferred Providers”) that use tracking technologies to deliver advertisements on our behalf both online and offline. These companies may collect information about your visits to our website and your interaction with our advertising and other communications.

Use of Information

We may use the information we collect from and about you for various purposes, such as to provide services, process transactions, improve customer experience and engagement, and develop the website. We will have a lawful basis for processing your information if:

  • We need to process your information to provide you with products or service you have requested or to enter into a contract;
  • You have consented to such processing;
  • We have a legitimate interest for processing your data, like analytics, fraud prevention, improving the website and our business, and direct marketing; and/or we are legally required to process it.

We may use the information we collect from and about you for business purposes including but not limited to the following:

  • Provide services and communicate with website visitors;
  • Process transactions;
  • Respond to your inquiries;
  • Contact you when necessary;
  • Prevent and detect fraud and abuse; and/or as described to you at the point of collection.

We may also use the information we collect from and about you for commercial purposes including but not limited to the following:

  • Improve our website and your customer shopping experience; and/or
  • Send communications about our products, services, and promotions.

We may store this information for as long as is reasonably necessary to accomplish these tasks, unless the law permits or requires a longer period. For example, if you create an account, we may store any information associated with your account even after cancellation of your account. If you make a purchase, we will store any personal information associated with that purchase for as long as necessary to fulfill the order and process any returns.

Sharing of Information

We may disclose the information we collect from and about you (1) to our Preferred Providers, if the disclosure will enable them to perform a business, commercial, professional, or technical support function for us; (2) as necessary if we believe that there has been a violation of our rights or the rights of any third party; (3) to respond to judicial process or provide information to law enforcement or regulatory agencies or in connection with an investigation on matters related to public safety, as permitted by law, or otherwise as required by law; and (4) as described to you at the point of collection.

Crystals may sell or purchase assets during the normal course of our business. If another entity acquires us or any of our assets, information we have collected about you may be transferred to such entity. In addition, if any bankruptcy or reorganization proceeding is brought by or against us, such information may be considered an asset of ours and may be sold or transferred to third parties. Should such a sale or transfer occur, we will use reasonable efforts to try to require that the transferee use the information provided through the website in a manner that is consistent with this Privacy Policy.

Social Sharing Features

The Services may offer social sharing features and other integrated tools (such as the Facebook “Like” button), which let you share actions you take on our Services with other media, and vice versa. Your use of such features enables the sharing of information with your friends or the public, depending on the settings you establish with the entity that provides the social sharing feature. For more information about the purpose and scope of data collection and processing in connection with social sharing features, please visit the privacy policies of the entities that provide these features.

Advertising and Analytics Services Provided by Others

We may allow others to provide analytics services and serve advertisements on our behalf across the internet and in applications. These entities may use cookies, web beacons, device identifiers and other technologies to collect information about your use of the Services and other websites and applications, including your IP address, web browser, mobile network information, pages viewed, time spent on pages or in apps, links clicked and conversion information. This information may be used by Crystals and others to, among other things, analyze and track data, determine the popularity of certain content, deliver advertising and content targeted to your interests on our Services and other websites and better understand your online activity. For more information about interest-based ads, or to opt out of having your web browsing information used for behavioral advertising purposes, please visit www.aboutads.info/choices. Your device may also include a feature (“Limit Ad Tracking” on iOS or “Opt Out of Interest-Based Ads” or “Opt Out of Ads Personalization” on Android) that allows you to opt out of having certain information collected through apps used for behavioral advertising purposes.

Security

Crystals takes reasonable measures to help protect information about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction.

Data Retention

We store the information we collect about you for as long as is necessary for the purpose(s) for which we originally collected it, or for other legitimate business purposes, including to meet our legal or other regulatory obligations.

Transfer of Information to the U.S. and Other Countries

Crystals is based in the United States and we process and store information in the U.S. and other countries. As such, we and our service providers may transfer your information to, or store or access it in, jurisdictions that may not provide equivalent levels of data protection as your home jurisdiction. We will take steps to ensure that your personal data receives an adequate level of protection in the jurisdictions in which we process it.

Residents of the European Economic Area 

If you are a resident of the European Economic Area (“EEA”), you have certain rights and protections under the law regarding the processing of your personal data.

Legal Basis for Processing

If you are a resident of the EEA, when we process your personal data we will only do so in the following situations:

  • We need to use your personal data to perform our responsibilities under our contract with you (e.g., processing payments for product purchases you have made).
  • We have a legitimate interest in processing your personal data. For example, we may process your personal data to send you marketing communications, to communicate with you about changes to our Services, and to provide, secure, and improve our Services.
  • You have consented to the processing of your personal data for one or more specific purposes.

Data Subject Requests

If you are a resident of the EEA, you have the right to access personal data we hold about you and to ask that your personal data be corrected, erased, or transferred. You may also have the right to object to, or request that we restrict, certain processing. If you would like to exercise any of these rights, you may contact us as indicated below.

Questions or Complaints

If you are a resident of the EEA and have a concern about our processing of personal data that we are not able to resolve, you have the right to lodge a complaint with the data privacy authority where you reside. For contact details of your local Data Protection Authority, please see: http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htmhttp://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm.

Your Choices

Account Information

You may update, correct or delete information about you at any time by logging into your online account or emailing us at info@crystals.com. If you wish to delete or deactivate your account, please email us at info@crystals.com, but note that we may retain certain information as required by law or for legitimate business purposes. We may also retain cached or archived copies of information about you for a certain period of time

Cookies

Most web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove or reject browser cookies. Please note that if you choose to remove or reject cookies, this could affect the availability and functionality of our Services.

Promotional Communications

You may opt out of receiving promotional emails or text messages from Crystals by following the instructions in those emails or text messages or by contacting us at info@crystals.com. If you opt out, we may still send you non-promotional emails, such as those about your account or our ongoing business relations.

Mobile Push Notifications/Alerts

With your consent, we may send promotional and non-promotional push notifications or alerts to your mobile device. You can deactivate these messages at any time by changing the notification settings on your mobile device.

Your California Privacy Rights

California residents may take advantage of the following rights under the California Consumer Privacy Act (CCPA):

  • You may request, up to two times each year, that we disclose to you the personal information that we have collected about you, the categories of sources from which your personal information is collected, the business or commercial purpose for collecting your personal information, the categories of personal information that we disclosed for a business purpose, any categories of personal information that we sold about you, the categories of third parties with whom we have shared your personal information, and the business or commercial purpose for selling your personal information, if applicable.
  • You may request that we delete any personal information that we have collected from or about you. Note that there are some reasons we will not be able to fully address your request, such as if we need to complete a transaction for you, to detect and protect against fraudulent and illegal activity, to exercise our rights, or to comply with a legal obligation.
  • You may request to opt out of the “sale” of your personal information by clicking on the Do Not Sell My Personal Information link on our website footer. When you opt out, you will still receive cookies, pixels, or other technologies that are essential to the function of our website. You may still see some tailored advertising based on information third parties may have previously collected, unless you opt out of all interest-based advertising (as described above in this Privacy Policy). Your request may not persist if you clear your cookies, switch devices, or switch browsers.

You can make a CCPA request to opt out of the sale of your personal information by clicking here. To opt out of tracking technologies that advertise to you, please see the paragraph in this Privacy Policy titled “Tracking Options and California Do Not Track Disclosures” for opt-out instructions.

Alternatively, to take advantage of any of these rights, you may contact us by email at info@crystals.com.

In each case, we may need to request additional information from you for verification purposes. We value your privacy and will not discriminate in response to your exercise of your privacy rights. We will respond to your request within the timeframe required by the CCPA, after proper verification, unless we need additional time, in which case we will let you know.

For purposes of compliance with the CCPA, in addition to the further details as described throughout this Privacy Policy, we make the following disclosures:

  • We collect the following categories of personal information: Identifiers/Contact Information, characteristics of protected classifications under California or federal law, payment card information associated with you, commercial information, Internet or other electronic network activity information, and inferences drawn from the above.
  • We may, under the CCPA’s definition of “sale”, be deemed to sell the following categories of personal information: Identifiers/Contact Information, Internet or other electronic network activity information, and inferences drawn from the above.
  • We disclose the following categories of personal information for a business purpose: Identifiers/Contact Information, characteristics of protected classifications under California or federal law, payment card information associated with you, commercial information, Internet or other electronic network activity information, and inferences drawn from the above.

Contact Us

If you have any questions about this Privacy Policy, please contact us.