INTRODUCTION
This Privacy Policy (“Policy “) outlines Nikki Beach Group’s (“Nikki Beach“, “we”, “us” or “our”) processing of Personal Information for users of our website shop.nikkibeach.com (the “Website”) and customers of our e-commerce and boutique services (collectively, “Services” and “Users” respectively).
Your privacy is important to us. We keep your Personal Information private. We will not use, sell, rent, share, or otherwise disclose your Personal Information to anyone except as necessary to provide our Services or as otherwise described in this Policy.
This Policy together with the Cookie Policy and any other document referred to herein, constitutes an integral part of our Terms of service, all of which are incorporated herein by reference.
If you do not agree to this Policy, please discontinue, and avoid using our Services. You have the right to cease using the Services at any time, pursuant to this Policy, our Cookie Policy and Terms.
COLLECTED INFORMATION
Nikki Beach may collect the following types of information from its Users:
Personal Information
We may collect information related to Users that identifies an individual or may with reasonable effort identify an individual (“Personal Information” or “Personal Data”), including the following:
- Contact Information: When you place an order, create an account, subscribe to email communications, or shop at one of our boutiques, we collect your name, address, phone number, email, and contact preferences.
- Preferences: To personalize our websites, services or communications, we may also ask you to provide us with information regarding your interests, demographics, and experiences with our Services. Providing this additional information is optional.
- Communications information: we will also collect your Personal Information when you interact with us through the Services, for example, when you purchase our Services, respond to communications from us, contact our support, communicate with us via email, website and through any online platform.
- Candidate Information: we collect your Personal Information when you apply for a job through our website. Please note that you may be required to share with us your CV and other required information.
- Payment Information: We collect billing and shipping addresses and payment details (processed through third-party payment providers). For in-store purchases, we process card transactions through our Point of Sale (POS) systems.
- Order and Purchase History: Details of products you purchase, transaction history, and preferences both online and in our boutiques.
- Device Information: we may also collect Personal Information from your device, such as geolocation data, IP address and other online identifiers (i.e. online data collected from User’s devices, applications and protocols which leave traces which may be used to identify Users).
- Legal Matters: We may use certain Personal Information to prevent potentially prohibited or illegal activities, fraud, misappropriation, infringements, identity thefts and any other misuse of the Services, to enforce our legal terms and conditions, to protect the security or integrity of our databases, and to take precautions against legal liability.
- Customer Support Communication: When you contact us for assistance, we may collect related communications and support details.
You have no legal obligation to provide us with Personal Information and the submission of such information is subject to your sole discretion. However, if you will not provide us with certain required Personal Information we may not be able to provide you with the full range of, or the best experience while using our Services.
LEGAL BASES FOR PROCESSING
Our legal bases for collecting and using your Personal Information will depend on the jurisdiction in which you reside, and the particular purpose for which your Personal Information is being processed. We rely on the following legal bases:
- Performance of a Contract: we will rely on this basis (for example, our contract with a guest of our Services) for processing which is necessary for the provision of our Services, including the processing of payments, to provide support, and to send you service communications.
- Consent: in limited cases (for example, where you choose to sign up to receive direct marketing emails, and where you accept cookies on our website) we will process your Personal Information based on your consent. You can withdraw your consent at any time by contacting us using the details provided below, or, in the case of cookies and other tracking technologies, via our cookie preferences menu.
- Legitimate Interests: in some jurisdictions, where it is a permissible legal basis, we will process your Personal Information based on our legitimate interests in maintaining and improving our Services, such as for the purpose of understanding how our Services are used and improving them, our customer service and support operations, and protecting and securing our users, ourselves and our Services. When we rely on our legitimate interests to process your Personal Information, in some jurisdictions you have the right to object.
- Legal Obligation: in limited cases we may process your Personal Information where we need to do so to comply with a legal obligation e.g. which is set out in an applicable law, or if we receive an order from a court or regulatory body.
If you have any questions about or need further information concerning the legal basis on which we collect and use your Personal Information, please contact us through the contact details available below.
HOW WE USE YOUR PERSONAL INFORMATION
We use your Personal Information to:
- Process transactions, fulfill online and in-store orders, and deliver purchased products.
- Provide customer support and manage returns or refunds (online and in-store).
- Send transactional communications, such as order confirmations and shipping updates.
- Personalize your shopping experience, including product recommendations and boutique loyalty programs.
- Conduct analytics and improve our Website and boutique shopping experience.
- Send commercial communications, in accordance with your communication preferences, such as providing you with information about products and related services, features, surveys, newsletters, offers, promotions, contests, and events;
- How to opt-out of receiving marketing communications: You may choose not to receive our promotional or marketing emails at any time, by clicking on the unsubscribe link in the emails that you receive from us. Please note that even if you unsubscribe from our newsletter, we may continue to send you service-related updates or notifications.
- Monitor and analyze trends, usage, and activities in connection with the Services and for marketing or advertising purposes.
- Detect and prevent fraudulent activities.
- Comply with legal obligations, exercising our legal rights, as well as investigating and preventing fraudulent transactions, unauthorized access to the Services, and other illegal activities.
- Reviewing and communicating with you regarding job applications.
TO WHOM WE DISCLOSE YOUR PERSONAL INFORMATION
We work with third parties who help us run our business (“Service Providers”). These Service Providers help us store information (such as cloud storage companies), deliver customer support, process payments, monitor and analyze the performance of our Services, manage and contact our existing customers as well as sales leads, provide marketing support, provide fraud prevention services, and otherwise operate and improve our Services. These Service Providers may only process Personal Information pursuant to our instructions and in compliance both with this Policy and other applicable confidentiality and security measures and regulations.
Specifically, we do not permit our Service Providers to use any Personal Information we disclose for their own purposes or for any other purpose except in connection with the services they provide to us.
In addition to disclosing Personal Information to Service Providers as described above, we may also disclose your Personal Information to others in the following circumstances:
- Service Providers (e.g., payment processors like Shopify, shipping companies, fraud detection services) under confidentiality agreements.
- Affiliated Companies within Nikki Beach Group for internal business purposes, as necessary for administrative, management or other business-relates purposes, to operate our websites, to communicate with you, to offer and provide our Services to you, etc.
- Boutique Locations to facilitate order pickups, returns, and in-store customer service.
- Marketing & Analytics Partners to improve customer experience (if consented to).
- In the event of a merger, sale, change in control, or reorganization of all our part of our business.
- When we are required to disclose Personal Information to respond to subpoenas, court orders, or legal process, or to establish or exercise our legal rights or defend against legal claims.
- Where we have a good-faith belief sharing is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our service agreement, or as otherwise required to comply with our legal obligations; or as you may otherwise consent from time to time.
TRACKING TECHNOLOGIES
We use cookies, pixels, beacons, scripts, tags, API, local storage and other similar tracking technologies ("Tracking Technologies")., when you access or interact with our Services. These Tracking Technologies allow us to automatically collect information about you, your device, and your online behavior, in order to enhance your use of our Services, improve our Services' performance, perform analytics, customize your experience and offer you tailored content.
Please note that once you choose to opt out or disable cookies, some features may not operate properly, and your online experience may be limited. In addition, even if you do opt-out, you may still receive some content and advertising, however it will not be targeted content or advertising.
Most browsers will allow you to erase cookies from your computer’s hard drive, block acceptance of cookies, or receive a warning before a cookie is stored. You may set your browser to block all cookies, including cookies associated with our website, or to indicate when a cookie is being used by us, by adjusting the privacy and security settings of your web browser. Below is a list of useful links that can provide you with more information on how to manage your cookies: Google Chrome; Mozilla Firefox; Safari (Desktop); Safari (Mobile); Android Browser; and Microsoft Edge.
You can learn more and turn off certain third party targeting and advertising cookies by visiting the following third-party webpages:
- The Interactive Advertising Bureau (US);
- The Interactive Advertising Bureau (EU); and
- European Interactive Digital Advertising Alliance (EU).
To learn more about our use of cookies and similar tracking technologies, please refer to our Cookie Policy.
INTERNATIONAL TRANSFERS OF PERSONAL INFORMATION
Please note that our businesses, as well as our trusted partners and Service Providers, are located around the world. Any Personal Information that we collect is stored and processed in various jurisdictions around the world (including without limitation in the United States), for the purposes detailed in this Policy.
For EEA and UK residents, please note that some data recipients may be located outside the EEA or the UK. In such cases we will transfer your Personal Information only to such countries as approved by the European Commission or the UK Information Commissioner’s Office, as applicable, as providing adequate level of data protection, or enter into the legal agreements or other permissible methods to ensure an adequate level of data protection.
In other jurisdictions where the applicable laws impose limitation on cross-border transfers, we will use only the permissible methods to ensure an adequate level of protection of your Personal Information.
DATA SUBJECT RIGHTS
Depending on your local data protection regulations, the law grants you with various rights with respect to your Personal Information. These rights vary between jurisdictions. We guarantee that your rights will be fully recognized.
If you are entitled to under the applicable data protection law in your jurisdiction, you may request to:
- Right of Access: receive confirmation as to whether or not Personal Information concerning you is being processed, and access your stored Personal Information, together with certain supplementary information.
- Right to Data Portability: Receive Personal Information you directly volunteer to us in a structured, commonly used and machine-readable format.
- Right to Correct: Request rectification of your Personal Information that is in our control.
- Right to Delete: Request erasure of your Personal Information.
- Right to Object: to the processing of Personal Information by us, or the use of your Personal Information for direct marketing.
- Right to Restriction of Processing: Request to restrict processing of your Personal Information by us.
- Right to Limit Use: Request to limit use and disclosure of your sensitive Personal Information. Right not to be subject to automated decision making.
- Right to Opt-Out: Right to opt-out of the sale or share of Personal Information. Please note that we do not sell your Personal Information.
- Right to non-discrimination: Right to be free from any discrimination for exercising your rights. Should you exercise any of your rights, we will not discriminate against you by offering you different pricing or products, or by providing you with a different level or quality of services, based solely upon your request. However, in some circumstances, for example where you have requested or consented to our Services that use your Personal Information, we may not be able to provide a service if you choose to delete your Personal Information.
If you wish to exercise your privacy rights under applicable law, please contact us by email at it.support@nikkibeach.com. Please be aware that only you, or someone legally authorized to act on your behalf, may make a request related to personal information collected about you. To designate an authorized agent, the authorized agent must provide sufficient information that allows us to reasonably verify that they have been authorized by you to act on their behalf.
In some jurisdictions, you have the right to appeal a rejection to your request. The appeal request shall be submitted to it.support@nikkibeach.com
Please note that these rights are not absolute, and may be subject to our own legitimate interests and regulatory requirements.
If you feel your rights have been prejudiced by us, you may also:
- If you are an EU resident, you may lodge a complaint with a supervisory authority.
-
If you are a resident of certain US states, you may lodge a complaint with the applicable Attorney General, as follows:
- If you are a Viginia resident, you can lodge a complaint through the contact information available here: https://www.oag.state.va.us/contact-us/contact-info or file the complaint at: https://www.oag.state.va.us/consumer-protection/index.php/file-a-complaint.
- If you are a Colorado resident, you can lodge a complaint with the Colorado Attorney at https://complaints.coag.gov/s/contact-us.
- If you are a Texas resident, you can lodge a complaint with the Texas Attorney General at https://consumerprotection.texasattorneygeneral.gov/consumercomplaintportal/s/flow/TCP_Complaint_Input_Data_Privacy.
- If you are an Oregon resident, you can lodge a complaint with the Oregon Department of Justice at https://justice.oregon.gov/consumercomplaints/OnlineComplaints/OnlineComplaintForm/en.
To opt-out of receiving communications you have expressly requested (such as e-mail newsletters, promotions, etc.), please select the e-mail “opt-out” or “unsubscribe” link included in each subscription communication or by contacting us directly.
RETENTION
We will retain your Personal Information for as long as necessary to provide our Services. We may also retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our policies.
Retention periods shall be determined taking into account the type of information that is collected and the purpose for which it is collected for, bearing in mind the requirements applicable to the situation and the need to destroy outdated, unused information at the earliest reasonable time.
DATA SECURITY
We have implemented appropriate administrative, technical, and physical safeguards to help prevent unauthorized access, use, or disclosure of your Personal Information.
While we seek to protect your information to ensure that it is kept confidential, we cannot guarantee the security of any information. You should be aware that there is always some risk involved in transmitting information over the internet and that there is also some risk that others could find a way to thwart our security systems. As a result, while we strive to protect your Personal Information, we cannot absolutely ensure or warrant the security and privacy of your Personal Information or other content you transmit using the Services, and you do so at your own risk. Thus, we encourage you to exercise discretion regarding the Personal Information you choose to disclose.
CHILDREN’S PRIVACY
Nikki Beach is committed to protecting the privacy needs of children and we encourage parents and guardians to take an active role in their children’s online activities and interests. Nikki Beach does not knowingly collect information from anyone under the age of majority (as determined under the applicable laws where the individual resides; “Minors“). By accessing, using or interacting with our Services, you certify to us that you are not a Minor. In the event that we have collected Personal Data from a Minor without verification of parental consent, we will delete that information upon discovery. If a parent or guardian becomes aware that a Minor has provided us with Personal Information, he or she should contact us using the details provided in this Policy immediately.
THIRD-PARTY SERVICES & LINKS
Our Services may contain links to other third-party websites or services, which are not governed by this Privacy Policy. We are not responsible for such third party websites' privacy practices, and encourage you to pay attention when you interact with any such website, service or application of such third parties, and to read their respective privacy policies. This Privacy Policy applies only to our Services.
DISCLOSURES FOR US RESIDENTS
In addition to the information provided under the "Data Subject Rights" section above, this part of the Policy addresses the specific requirements under the applicable laws in California, Colorado, Connecticut, Utah, Virginia, Texas, Oregon, Florida, Montana, Iowa, Delaware, New Jersey, New Hampshire, and Nebraska ("US Privacy Laws").
COLLECTION, DISCLOSURE AND SHARING OF PERSONAL INFORMATION
We do not sell, but we may share your Personal Information, as these terms are defined under US Privacy Laws.
In the 12 preceding months, we have collected the following categories of Personal Information:
CATEGORIES OF PERSONAL INFORMATION |
DATA TYPES |
Category A - Identifiers |
For example, name, surname, email, phone number. Online identifiers, IP address. |
Category B - Personal information categories listed in the California Customer Records Statute |
A name, physical characteristics or description, address, telephone number. |
Category D - Commercial information |
Records of services purchased, obtained or considered, purchasing history or tendencies. |
Category E - Internet or other electronic network activity information. |
Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement. |
Category F - Internet or other network activity information |
Your interactions with the Services, IP addresses, your geographic location, and other information derived from your interaction with our Services. |
Category G - Geolocation data (non-precise) |
Approximate location derived from IP address. |
Category I - Professional or employment-related information. |
Current or past job history or performance evaluations. |
IN THE PRECEDING TWELVE (12) MONTHS WE HAVE SHARED AND DISCLOSED YOUR PERSONAL INFORMATION AS DESCRIBED BELOW:
CATEGORIES OF THIRD PARTIES |
CATEGORIES OF PERSONAL INFORMATION |
DISCLOSED OR SHARED |
Advertisers |
Unique identifiers, IP address, user activity data (interaction with Ads) |
Shared |
Service Providers |
All types of Personal Information |
Disclosed |
Entities within Nikki Beach group |
All types of Personal Information |
Disclosed |
Legal and regulatory entities |
Subject to law enforcement or a competent authority request. |
Disclosed |
SOURCES OF PERSONAL INFORMATION:
- Directly and indirectly from your activity on our websites: For example, directly from you when you inquire about our Services or on the subscription process; or indirectly when we collect your usage data automatically from measurement tools.
- Indirectly from you: We track your activities across the internet, for example, when you view or interact with certain content, web page or ad.
- From third parties: For example, from vendors who assist us in performing services for consumers, advertising networks, data analytics providers, social networks, and data brokers.
PURPOSES FOR COLLECTION AND DISCLOSING OF PERSONAL INFORMATION
In addition to the practices detailed under the section “How We Use Your Information” above, we also use and disclose the Personal Information we collect for the following commercial and business purposes:
- Auditing related to our interactions with you;
- Legal compliance;
- Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and necessary prosecution;
- Debugging;
- Performing services (for us or our service provider);
- Internal research for technological improvement;
- Internal operations;
- Activities to maintain and improve our services; and
- Other one-time or short-term uses.
- Notice of financial incentive
We do not offer financial incentives to consumers for providing Personal Information.
ADDITIONAL DISCLOSURES FOR CALIFORNIA RESIDENTS
· Direct Marketing Requests: California Civil Code Section 1798.83 permits you, if you are a California resident, to request certain information regarding disclosure of Personal Information to third parties for their direct marketing purposes. To make such a request, please contact us at it.support@nikkibeach.com
· “Do Not Track” Settings: Cal. Bus. & Prof. Code Section 22575 also requires us to notify you how we deal with the “Do Not Track” settings in your browser. As of the effective date listed above, there is no commonly accepted response for Do Not Track signals initiated by browsers. Therefore, we do not respond to the Do Not Track settings. Do Not Track is a privacy preference you can set in your web browser to indicate that you do not want certain information about your web page visits tracked and collected across websites. For more details, including how to turn on Do Not Track, visit: www.donottrack.us.
· Designating Agents: If you are a California resident, you can designate an authorized agent to make a request on your behalf if: (i) The authorized agent is a natural person or a business entity registered with the Secretary of State of California; and (ii) you sign a written declaration that you authorize the authorized agent to act on your behalf.
The request must: (i) provide sufficient information to allow us to reasonably verify you are the person about whom we collected Personal Information or an authorized agent. We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you, and (ii) describe your request with sufficient details to allow us to properly understand, evaluate, and respond to it. We will only use Personal Information provided in a verifiable consumer request to verify the requestor's identity or authority to make the request.
CHANGES TO OUR PRIVACY POLICY
We reserve the right to change this Policy at any time, so please re-visit this page frequently. All changes to this Policy are effective as of the stated “Last Updated” date, and your continued use of the Services after the "Last Updated" date will constitute acceptance of, and agreement to be bound by, those changes. We will make our best efforts to provide notice of substantial changes of this Policy through our websites, or when we have you contact information, attempt to notify you via e-mail regarding such changes.
DATA PROTECTION OFFICER
We have a “Data Protection Officer” who is responsible for matters relating to privacy and data protection. If you have any questions about this Policy, please contact our Data Protection Officer at dataprotection@nikkibeach.com
CONTACTING US
If you have any questions about this Policy, or your dealings with our Services, you can contact us using the following contact details:
- Email: it.support@nikkibeach.com
- Our address: Penrod Management Group Inc.1 Ocean Drive, Miami Beach, FL 33139. USA
If you reside in the EU, you may also contact our EU representative:
- Email: it.support@nikkibeach.com
- Our address: Rambla de Cataluña 62, 2º-1ª, 08007 Barcelona, Spain.
As described in our Privacy Policy, we collect personal information from your interactions with us and our website, including through cookies and similar technologies. We may also share this personal information with third parties, including advertising partners. We do this in order to show you ads on other websites that are more relevant to your interests and for other reasons outlined in our privacy policy.
Sharing of personal information for targeted advertising based on your interaction on different websites may be considered "sales", "sharing", or "targeted advertising" under certain U.S. state privacy laws. Depending on where you live, you may have the right to opt out of these activities. If you would like to exercise this opt-out right, please follow the instructions below.
If you visit our website with the Global Privacy Control opt-out preference signal enabled, depending on where you are, we will treat this as a request to opt-out of activity that may be considered a “sale” or “sharing” of personal information or other uses that may be considered targeted advertising for the device and browser you used to visit our website.