1. Information we collect
Log data
In the course of providing our services, we collect or receive your personal information in a few different ways. We obtain the categories of personal information listed below from the following sources: directly from you, for example, from forms you complete or during registration; indirectly from you based on your activity and interaction with our Services, or from the device or browser you use to access the Services; and from our vendors and suppliers that help provide Lucky Sweater services you may interact with (such as, for example, for payments or customer support). Often, you choose what information to provide, but sometimes we require certain information to provide you the Services. Lucky Sweater uses the personal information it receives and collects in accordance with the purposes described in this policy.
Device data
We may collect data about the device you’re using to access our website and app. This data may include the device type, operating system, unique device identifiers, device settings, and geo-location data. What we collect can depend on the individual settings of your device and software. We recommend checking the policies of your device manufacturer or software provider to learn what information they make available to us.
Personal information
We may ask for personal information, such as your:
Name
Email
Location
Social media profiles
Image information
We upload and collect image information when you add any images to the platform. We may use that information as part of providing our services to you.
2. Legal bases for processing
We will process your personal information lawfully, fairly and in a transparent manner. We collect and process information about you only where we have legal bases for doing so.These legal bases depend on the services you use and how you use them, meaning we collect and use your information only where:it’s necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract (for example, when we provide a service you request from us);it satisfies a legitimate interest (which is not overridden by your data protection interests), such as for research and development, to market and promote our services, and to protect our legal rights and interests;you give us consent to do so for a specific purpose (for example, you might consent to us sending you our newsletter); orwe need to process your data to comply with a legal obligation.Where you consent to our use of information about you for a specific purpose, you have the right to change your mind at any time (but this will not affect any processing that has already taken place).We don’t keep personal information for longer than is necessary. While we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use or modification. That said, we advise that no method of electronic transmission or storage is 100% secure and cannot guarantee absolute data security. If necessary, we may retain your personal information for our compliance with a legal obligation or in order to protect your vital interests or the vital interests of another natural person.
5. International transfers of personal information
The personal information we collect is stored and processed in United States, the Netherlands, and Brazil, or where we or our partners, affiliates and third-party providers maintain facilities. By providing us with your personal information, you consent to the disclosure to these overseas third parties.We will ensure that any transfer of personal information from countries in the European Economic Area (EEA) to countries outside the EEA will be protected by appropriate safeguards, for example by using standard data protection clauses approved by the European Commission, or the use of binding corporate rules or other legally accepted means.Where we transfer personal information from a non-EEA country to another country, you acknowledge that third parties in other jurisdictions may not be subject to similar data protection laws to the ones in our jurisdiction. There are risks if any such third party engages in any act or practice that would contravene the data privacy laws in our jurisdiction and this might mean that you will not be able to seek redress under our jurisdiction’s privacy laws.
6. Your rights and controlling your personal information. Choice and consent:
By providing personal information to us, you consent to us collecting, holding, using and disclosing your personal information in accordance with this privacy policy. If you are under 16 years of age, you must have, and warrant to the extent permitted by law to us, that you have your parent or legal guardian’s permission to access and use the website and they (your parents or guardian) have consented to you providing us with your personal information. You do not have to provide personal information to us, however, if you do not, it may affect your use of this website or the products and/or services offered on or through it.
Correction:
If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, please contact us using the details below. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading or out of date.
Complaints:
If you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact a regulatory body or data protection authority in relation to your complaint.
10. Changes to this policy
At our discretion, we may change our privacy policy to reflect current acceptable practices. We will take reasonable steps to let users know about changes via our website. Your continued use of this site after any changes to this policy will be regarded as acceptance of our practices around privacy and personal information.If we make a significant change to this privacy policy, for example changing a lawful basis on which we process your personal information, we will ask you to re-consent to the amended privacy policy. This policy is effective as of December 15, 2022.
10. Your rights & choices
Certain privacy laws around the world, including the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), provide users with rights related to their personal information. Consistent with those laws, Lucky Sweater gives you the choice of accessing, editing, or removing certain information, as well as choices about how we contact you. You may change or correct your Lucky Sweater account information through your account settings. You may also remove certain optional information that you no longer wish to be publicly visible through the services, such as your name. You can also request to permanently close your account and delete your personal information.
Depending on your location, you may also benefit from a number of rights with respect to your information. While some of these rights apply generally, certain rights apply in limited cases.
Right to Correction: You have the right to request that we rectify inaccurate information about you. By visiting your account settings, you can correct and change certain personal information associated with your account.
Right to Restrict Processing: In certain cases where we process your information, you may also have the right to restrict or limit the ways in which we use your personal information.
Right to Deletion: In certain circumstances, you have the right to request the deletion of your personal information, except information we are required to retain by law, regulation, or to protect the safety, security, and integrity of Etsy.
Right to Object: If we process your information based on our legitimate interests as explained above, or in the public interest, you can object to this processing in certain circumstances. In such cases, we will cease processing your information unless we have compelling legitimate grounds to continue processing or where it is needed for legal reasons. Where we use your personal data for direct marketing purposes, you can object using the unsubscribe link in such communications or changing your account email settings.
Right to Withdraw Consent: Where we rely on consent, you can choose to withdraw your consent to our processing of your information using specific features provided to enable you to withdraw consent, like an email unsubscribe link or your account privacy preferences. If you have consented to share your precise device location details but would no longer like to continue sharing that information with us, you can revoke your consent to the sharing of that information through the settings on your mobile device. This is without prejudice to your right to generally permanently close your account and delete your personal information.