Last Updated Date: July 7, 2022

Nécessaire, Inc. (“Nécessaire”) has prepared this Privacy Policy to describe our practices regarding the personal data we collect through our website at Nécessaire.com (the “Website") and our other online services that link to this Privacy Policy (together with the Website, the "Services"), in connection with our marketing activities, through social media and as otherwise described in this Privacy Policy.

1. Questions; Contacting Nécessaire, Reporting Violations. If you have any questions, concerns or complaints about our Privacy Policy or our data collection or processing practices, or if you want to report any security incidents to us, please contact us at [email protected].

2. User Content. By submitting personal data through the Services, you agree to this Privacy Policy and you expressly consent to the collection, use and disclosure of your personal data in accordance with this Privacy Policy.

3. A Note About Children. We do not intentionally gather personal data from visitors who are under the age of 16. If a child under 16 submits personal data to Nécessaire through the Services and we learn that the personal data is the information of a child under 16, we will attempt to delete the information as soon as possible. If you believe that we might have any personal data from a child under 16, please contact us at [email protected].

4. A Note to Users Outside of the United States. If you are a non-U.S. user of the Services, you acknowledge that we are based in the United States and agree that your personal data may be processed in the the United States and other countries, where laws regarding processing of personal data may be less stringent than those in your country.

5. Types of Data We Collect.

(a) Information You Provide to Us.

  • Contact Details. We may collect personal data from you, including but not limited to your first and last name, phone number, and e-mail address.
  • Account Information. We may collect profile data, such as your username and password that you may set to establish an online account with us.
  • Payment and Transactional Data. When you order products on our Website, we will collect information necessary to complete the transaction, including your name, payment card information, billing information and shipping information. We do not store this information directly on our servers, but this information may be shared with third parties who help process and fulfill your purchases.
  • Feedback/Support. If you provide us feedback or contact us, we will collect your name and e-mail address, as well as any other content included in your correspondence.
  • Research Data. We may collect research data that you provide when you agree to participate in our surveys, promotions, or contents, such as your survey responses.
  • Marketing Data. We may collect marketing data, such as your preferences for receiving our marketing communications, and details about your engagement with them.
  • Other Data. We may also collect other categories of personal data for uses described at the time of collection.

(b) Personal Data Collected via Technology.

  • Device and online activity data. We may collect identifying information about your device and your activity on the Services, including IP addresses, unique device identifiers browser type, Internet service provider ("ISP"), referring/exit pages, operating system, date/time stamp, and clickstream data.
  • Cookies. Like many online services, we may use cookies to collect information. "Cookies" are small pieces of information that a website sends to your computer’s hard drive while you are viewing the website. We may use both session Cookies (which expire once you close your web browser) and persistent Cookies (which stay on your computer until you delete them) to provide you with a more personal and interactive experience on our Website and to facilitate online advertising.
  • Pixel Tags. In addition, we may use "Pixel Tags" (also referred to as clear Gifs, Web beacons, or Web bugs). Pixel Tags are tiny graphic images with a unique identifier, similar in function to Cookies, that are used to track online activity. In contrast to Cookies, which are stored on a user’s computer hard drive, Pixel Tags are embedded invisibly in web pages. Pixel Tags also allow tell us whether e-mails have been opened and whether links in them have been clicked to assess recipients’ interest in our emails.
  • Session Replay Technologies. We use third party services provided by Lucky Orange that employ software code to record users' interactions with the Services in a manner that allows us to watch DVR-like replays of those user sessions. The replays include users' clicks, mobile app touches, mouse movements, scrolls and keystrokes during those sessions. These replays help us diagnose usability problems and identify areas for improvement. You can learn more about Lucky Orange at https://www.luckyorange.com/.

6. Use of Your Personal Data

(a) General Use. In general, we use your personal data in the following ways:

  • identify you as a user in our system;
  • provide, operate and improve our Services;
  • send you the products that you order;
  • improve the quality of experience when you interact with our Services;
  • send you a welcome e-mail to verify ownership of the e-mail address provided during the host application process;
  • send you administrative e-mail notifications, such as confirmation of your scheduled appointments; and
  • send Nécessaire marketing communications.

(b) User Testimonials and Comments. We may post testimonials and comments from users who have had positive experiences with our Services and identify those users by their first and last name with their consent. If you make any comments on a blog or forum associated with your Services, you should be aware that any personal data you submit there can be read, collected, or used by other users of these forums, and could be used to send you unsolicited messages. We are not responsible for the personal data you choose to submit in these blogs and forums.

(c) Interest-Based Advertising. We may engage third party advertising companies and social media companies to display ads on our Services and other online services. These companies may use cookies and similar technologies to collect information about your interaction (including the data described in the Personal Data Collected via Technology section above) over time across the Services, our communications and other online services, and use that information to serve online ads that they think will interest you. This is called interest-based advertising. We may also share information about our users with these companies to facilitate interest-based advertising to those users on other online platforms. You can learn more about your choices for limiting interest-based advertising in the Advertising Choices section below.

(d) Compliance and Protection. We may use your personal data to:

  • comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities;
  • protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims);
  • audit our internal processes for compliance with legal and contractual requirements and internal policies;
  • enforce the terms and conditions that govern the Services; and
  • prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft.

(e) Research and Development. We may use your personal data for research and development purposes, including to analyze and improve the Services and our business. As part of these activities, we may create aggregated, de-identified or other anonymous data from personal data we collect. We make personal data into anonymous data by removing information that makes the data personally identifiable to you. We may use this anonymous data and share it with third parties for our lawful business purposes, including to analyze and improve the Services and promote our business.

7. Disclosure of Your Personal Data. We disclose your personal data as described below and as described elsewhere in this Privacy Policy.

(a) Third Parties Designated by You. When you use the Services, the personal data you provide may be shared with the third parties that you designate to receive such information, including other websites.

(b) Service Providers. We may share your personal data with companies and individuals that provide services on our behalf or help us operate the Services or our business (such as information technology, hosting, customer relationship management and support, shipping, communications delivery, marketing, advertising, and online service analytics).

(c) Payment Processors. For online payments and/or Automated Clearing House (ACH) payouts, we use the payment services of Shopify (https://www.shopify.com/legal/privacy). We do not process, record or maintain your payment card or bank account information. For more information on how payments are handled, or to understand the data security and privacy afforded such information, please refer to the privacy policy of Shopify.

(d) Affiliates. We may share some or all of your personal data with our parent, subsidiaries, joint ventures, or other companies under a common control (“Affiliates”) for use consistent with this Privacy Policy.

(e) Corporate Restructuring. We may share some or all of your personal data in connection with or during negotiation of any merger, financing, acquisition or dissolution transaction or proceeding involving sale, transfer, divestiture, or disclosure of all or a portion of our business or assets. In the event of an insolvency, bankruptcy, or receivership, personal data may also be transferred as a business asset. If another party acquires our business, or assets, that party will possess the personal data collected by us and will assume the rights and obligations regarding your personal data as described in this Privacy Policy.

(f) Advertising Partners. We may share some of your personal data to third party advertising companies for the interest-based advertising purposes described above in section 6(c).

(g) Professional Advisors. Professional advisors, such as lawyers, auditors, bankers and insurers, where necessary in the course of the professional services that they render to us.

(h) Co-brand Partners. Third parties with whom we co-sponsor events or promotions, with whom we jointly offer products or services, or whose products or services may be of interest to you.

(i) Other Website Visitors. Your user-generated content may be visible to other users of the Services and the public. For example, other users of the Service or the public may have access to your information if you choose to make your personal data available to them through the Service, such as when you provide comments, reviews, or share other content. This information can be seen, collected and used by others, including being cached, copied, screen captured or stored elsewhere by others (e.g., search engines), and we are not responsible for any such use of this information.

(j) Other Disclosures. We may disclose personal data to law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described in the Compliance and Protection section above in section 6(d).

8. Third Party Websites. Our services may contain links to online services operated by third parties. When you click on a link to any other website or location, you will leave our Services and go to another online service, and another entity may collect personal data from you. We have no control over, do not review, and cannot be responsible for, these outside services or their content. Please be aware that the terms of this Privacy Policy do not apply to these outside services, or to any collection of your personal data after you click on links to such outside services. We encourage you to read the privacy policies of the online services you visit. The links to third party services are for your convenience and do not signify our endorsement of such third parties or their products, content or websites.

9. Your Choices

(a) Access or Update Your Information. If you have registered for a Services account, you may review and update certain account information by logging into the account.

(b) Opt-out of Marketing Communications. We may periodically send you emails that promote the Services. You can opt-out of receiving further marketing communications from us by following the unsubscribe instructions provided in the e-mail. We may continue to send you Service-related communications.

(c) Cookies. You can instruct your browser, by changing its settings, to stop accepting cookies or to prompt you before accepting a cookie from the websites you visit. If you do not accept cookies, however, you may not be able to use all functionality of the Services. We use Google Analytics to help us understand user activity on the Services. You can learn more about Google Analytics cookies at https://developers.google.com/analytics/resources/concepts/gaConceptsCookies and about how Google protects your data at http://www.google.com/analytics/learn/privacy.html. You can prevent the use of Google Analytics relating to your use of our sites by downloading and installing a browser plugin available at https://tools.google.com/dlpage/gaoptout?hl=en.

(d) Advertising Choices. You can limit use of your information for interest-based advertising by:

  • Browser settings. Blocking third party cookies in your browser settings.
  • Privacy browsers/plug-ins. By using privacy browsers or ad-blocking browser plug-ins that let you block tracking technologies.
  • Ad industry tools. Opting out of interest-based ads from companies participating in the following industry opt-out programs:

You will need to apply these opt-out settings on each device and in each browser from which you wish to opt-out.

(e) How We Respond to Do Not Track Signals. We do not currently respond to “do not track” signals. To find out more about "Do Not Track", please visit http://www.allaboutdnt.com

(f) Privacy Rights. Residents of certain states have the additional rights under applicable state privacy laws described below in “Your Privacy Rights.”

10. Security. We employ a number of technical, organizational and physical safeguards designed to protect the personal information we collect. However, security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information.

11. Changes to This Privacy Policy. This Privacy Policy may be updated from time to time for any reason. We will notify you of any changes to our Privacy Policy by posting the new Privacy Policy on the Website, and we will change the “Last Updated” date above. You should consult this Privacy Policy regularly for any changes.

12. Your Privacy Rights.

This section applies to residents of California, Virginia and other states, to the extent they have privacy laws applicable to us that grant their residents the rights described below. Privacy laws change frequently so if you have questions about whether residents of your state have the rights described below, contact us at [email protected]. For purposes of this section, “personal data” has the meaning given to “personal data”, “personal information” or similar terms under the applicable privacy laws of the state in which you reside.

Your Privacy Rights

  • Information/Know. You can request certain information about whether, and in some cases how, we have collected and used your personal data. For example, if you live in California, you may be able to request information about the categories of personal data that we have collected, the categories of sources from which we collected personal data, the business or commercial purpose for collecting, sharing and/or selling personal data, the categories of third parties with whom we share personal data, the categories of personal data that we sold or disclosed for a business purpose, and the categories of third parties with whom the personal data was sold or disclosed for a business purpose.
  • Access. You can request a copy of certain personal data that we have collected about you.
  • Deletion. You can ask us to delete certain personal data that we maintain about you.
  • Correction. You can ask us to correct inaccurate personal data that we have collected about you.
  • Opt-out
    • Opt-out of tracking for targeted advertising purposes. You can opt-out of certain tracking activities for targeted advertising purposes. Like many companies, we use the interest-based advertising services described above. California law may classify our use of some of these services as “selling” or “sharing” your personal data with the advertising partners that provide the services. You can request to opt-out of this activity here.
    • Opt-out of other sales of personal data. You can opt-out of other sales of your personal information.

Nondiscrimination. You are entitled to exercise the rights described above free from discrimination as prohibited by the privacy laws of the state where you reside.

How to Exercise Your Rights. You may submit requests to exercise your right to information/know, access, deletion or correction via email to [email protected] or via phone by calling 213-342-1403. You may submit requests to opt-out of tracking for targeted advertising purposes or other sales of personal data via email to [email protected] or via phone by calling 213-342-1403.

Verification of Identity; Authorized Agents. We may need to verify your identity to process your information/know, access, deletion, and correction requests, and we reserve the right to confirm your residency. To verify your identity, we may require authentication into your Service account, government identification, a declaration under penalty of perjury or other information, where permitted by law. Furthermore, your authorized agent may make a request on your behalf upon our verification of the agent’s identity and our receipt of a copy of a valid power of attorney given to your authorized agent pursuant to applicable state law. If you have not provided your agent with such a power of attorney, we may ask you and/or your agent to take additional steps permitted by law to verify that your request is authorized, such as information required to verify your identity and that you have given the authorized agent permission to submit the request.

The rights described above are not absolute, and, in certain cases, we may decline your request as permitted by law or where the laws in your state do not afford you these rights. We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it. You can ask to appeal any denial of your request in the same manner through which you may submit a request.

Personal Data that We Collect, Use and Disclose

The list below provides information to which you are entitled regarding - data we collect, the sources of that personal data, the purpose for which we collect it, the third parties with whom we disclose it, and the third parties with whom we otherwise share t for targeted advertising purposes. Information you voluntarily provide to us, such as in free-form webforms, may contain other categories of personal data not described below.

Contact Details

  • Sources: You
  • Purposes: Service delivery, Research and development, Marketing and advertising, Compliance and protection
  • Third parties with whom we disclose: Affiliates, Co-brand partners, Service providers, Website visitors (when you leave product feedback)
  • Third parties with whom we share for interest-based advertising: Advertising partners

Account Information

  • Sources: You
  • Purposes: Service delivery, Research and development, Marketing and advertising, Compliance and protection
  • Third parties with whom we disclose: Affiliates, Co-brand partners, Service providers, Website visitors (when you leave product feedback)
  • Third parties with whom we share for interest-based advertising: None

Payment and Transactional Data

  • Sources: You
  • Purposes: Service delivery, Research and development, Compliance and protection
  • Third parties with whom we disclose: Affiliates, Service providers
  • Third parties with whom we share for interest-based advertising: None

Feedback/Support

  • Sources: You
  • Purposes: Service delivery, Research and development, Marketing and advertising, Compliance and protection
  • Third parties with whom we disclose: Affiliates, Co-brand partners, Service providers, Website visitors (when you leave product feedback)
  • Third parties with whom we share for interest-based advertising: None

Research Data

  • Sources: You, Automatic collection
  • Purposes: Service delivery, Research and development, Marketing and advertising, Compliance and protection
  • Third parties with whom we disclose: Affiliates, Co-brand partners, Service providers, Advertising partners
  • Third parties with whom we share for interest-based advertising: Advertising partners

Marketing Data

  • Sources: You, Automatic Collection
  • Purposes: Service delivery, Research and development, Marketing and advertising, Compliance and protection
  • Third parties with whom we disclose: Affiliates, Co-brand partners, Service providers, Advertising partners
  • Third parties with whom we share for interest-based advertising: Advertising partners

Online Activity Data

  • Sources: You, Automatic collection
  • Purposes: Service delivery, Research and development, Marketing and advertising, Compliance and protection
  • Third parties with whom we disclose: Affiliates, Co-brand partners, Service providers, Advertising partners
  • Third parties with whom we share for interest-based advertising: Advertising partners

Device Data

  • Sources: You, Automatic collection
  • Purposes: Service delivery, Research and development, Marketing and Advertising, Compliance and protection
  • Third parties with whom we disclose: Affiliates, Service Providers, Advertising partners
  • Third parties with whom we share for interest-based advertising: Advertising partners

Data Derived from the Above Listed Information

  • May be derived from the information listed above
  • Purposes: Service delivery, Research and development, Marketing and advertising, Compliance and protection
  • Third parties with whom we disclose: Affiliates, Service Providers, Advertising partners
  • Third parties with whom we share for interest-based advertising: Advertising partners

California Notices

California Categories of Personal Information. California law requires that we describe to California residents the categories of personal data we collect by reference to certain categories described in California law. All categories described in this Privacy Policy include “identifiers” and “customer records”, Account Information and Payment and Transactional Data includes “commercial information”, Online Activity Data and Device Data include “internet or other electronic network activity information” and Data Derived from the Above Listed Information includes “inferences”, in each case, as described in in Cal. Civ. Code Section 1798.140(v)

California Shine the Light Law. Under California’s Shine the Light law (California Civil Code Section 1798.83), California residents may ask companies with whom they have formed a business relationship primarily for personal, family or household purposes to provide the names of third parties to which they have disclosed certain personal information (as defined under the Shine the Light law) during the preceding calendar year for their own direct marketing purposes, and the categories of personal information disclosed. You may send us requests for this information to [email protected]. In your request, you must include the statement “Shine the Light Request," and provide your first and last name and mailing address and certify that you are a California resident. We reserve the right to require additional information to confirm your identity and California residency. Please note that we will not accept requests via telephone, mail, or facsimile, and we are not responsible for notices that are not labeled or sent properly, or that do not have complete information.