Privacy and Security Statement
Last Updated and Effective Date: July 1, 2022
We value the privacy and security of your “personal information”, which – as used herein – means any information relating to an identified or identifiable natural person. Personal information does not include information that does not and cannot identify you, such as data that has been anonymized.
When you use our application or receive or deliver our HydraFacial services through a connected HydraFacial device, as described above, we may collect the following types of personal information:
- Contact/Account Information. Any information that you voluntarily provide us with – such as your name, email address, account username, account password, location, and/or any other information you wish to communicate to us (including, if you’re an aesthetician, the name of your business or employer, address, phone number). We collect this information to provide our various services to you, process your request to conduct business with us, provide customer service, and for business and marketing purposes.
- Payment Processing. Your name or company name, credit card or debit card information, other payment information, and billing address that you provide. We collect this information so that we can process your payment for orders and for other business and accounting purposes.
- Technical Data. Your Internet Protocol address and information regarding your operating system, device, and location. We collect this information to recognize you, to learn more about the users of our application and services, to customize and improve your experience on our application and with our services, and for business and marketing purposes.
- Biometric Data. When you use our application’s ‘Selfie Assessment Tool’, you have the option to provide a facial photograph, your age, and information about your skin and skincare concerns. We use this information to help provide you with a customized skin health assessment. In addition, you may have the opportunity to publish, transmit, submit, or otherwise post reviews, ratings, comments, feedback, Selfie Assessment information, or other materials on the application that may contain your personal information. Your Biometric Data will be used anonymously to train our skin assessment AI model to improve our customized skin health assessment.
By choosing to enter and submit the requested personal information when prompted, you are consenting to HydraFacial’s collection, use, and disclosure of such information for the purposes of providing the Services to you as outlined herein.
Also, location and app visitor behavior information is compiled in the aggregate (accordingly, it does not represent individually identifiable information).
- Collected User Data. Your email address, phone number, date of birth, first name, last name, postal code, personal image, and geo-location. We use this information for purposes such as account creation and management.
- Treatment History. When consumers use a HydraFacial device, consumers have the option to track and repeat their individual treatment history by scanning the Hydrafacial Nation mobile app QR on the device. By doing so, consumers can create a log of their treatment history within the application. Treatment history includes the type of treatment received, any add-ons or adjustments, and the products used (as applicable). Consumers have the option to share their treatment history with aesthetician providers. Likewise, when aesthetician providers use a HydraFacial device, providers have the option to sync their application account with the device, which also creates a log of the providers’ treatment history. We use this information for business and marketing purposes.
HOW WE USE YOUR PERSONAL INFORMATION
We do not sell your personal information to third parties. We may, however, share your personal information with service providers who assist us with our business functions — such as payment processing, packaging, and shipping.
In addition, we may share your personal information if necessary to: (1) comply with federal, state, or local laws; (2) comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities; (3) cooperate with law enforcement agencies concerning conduct or activity that we reasonably and in good faith believe may violate federal, state, or local laws; or (4) exercise or defend legal claims.
Lastly, with your consent, we may share your personal information with others, such as our subsidiaries, affiliates, sponsors, commercial partners, and/or authorized providers, to provide you with product information and promotional and other offers.
RETENTION OF PERSONAL INFORMATION
Your personal information will be retained for the time required to fulfill the purposes for which it was collected and processed, including for the purpose of satisfying:
- Reporting obligations
- Data-driven business decisions about new features and offerings
DELETION OF PERSONAL INFORMATION
If you close or request that we close your account, we will delete or anonymize your personal data so it no longer identifies you, unless required by law.
We use first-party cookies on this application. Cookies are small text files that a website transfers to your computer or other devices. They are used to make this application work or improve the efficiency. Cookies help with functionality and user experience because the application can read and write to these text files, enabling this application to recognize you and remember important information that will make your use of this application more convenient.
DO NOT TRACK NOTICE
This application does not currently support certain browser settings or otherwise respond to Do Not Track requests.
LINKED INTERNET WEB SITES
Our application provides hyperlinks, which are highlighted words or pictures within a hypertext document that, when clicked, take you to another place within the document or to another document altogether or to other websites not controlled by us. These hyperlinked websites may contain privacy provisions that are different from those provided herein. We are not responsible for the collection, use or disclosure of information collected through these websites, and we expressly disclaims any and all liability related to such collection, use, or disclosure.
SECURITY OF YOUR PERSONAL INFORMATION
We have implemented and maintain reasonable security procedures and practices, and commercially reasonable technical and organizational measures, to ensure a level of security appropriate to the risk in order to help protect your personal information from unauthorized access and exfiltration, theft, or disclosure. However, no security system is perfect. We will notify you if there is a breach of our security where required by law or deemed necessary.
In the event that another company acquires HydraFacial or its assets, we reserve the right to include personal information among the assets transferred to the acquiring company.
Our application is not intended for or directed at children under the age of 13. In addition, we do not knowingly collect information from children under the age of 13.
NOTICE TO CALIFORNIA RESIDENTS
California residents may exercise certain privacy rights under the California Consumer Privacy Act of 2018 (“CCPA”) regarding their personal information. We describe below the rights you may have if you are a California resident.
Right to Know About Personal Information Collected, Disclosed, or Sold
As a California resident, you may also have the right to request more information regarding the following topics for the preceding 12 months, to the extent applicable:
- The categories and specific pieces of personal information we have collected about you.
- The categories of sources from which we have collected your personal information.
- The business or commercial purpose why we collected or, if applicable, sold your personal information.
- The categories of third parties with whom we shared your personal information.
- The categories of personal information that we have shared with third parties about you for a business purpose.
- If applicable, the categories of personal information that we sold about you and the categories of third parties who received your personal information in the sale.
You may submit a request for the information above by:
- emailing us at Privacy@HydraFacial.com.
- calling us at (800) 603-4996.
Note: We will need to confirm your identity to process your request.
Right to Request Deletion of Your Personal Information
You have the right to request that we delete the personal information we collected or maintained about you. Once we receive your request, we will let you know what, if any, personal information we can delete from our records, and we will direct any service providers with whom we shared your personal information to also delete your personal information from their records.
There may be circumstances where we cannot delete your personal information or direct service providers to delete your personal information from their records. Some of these instances include, but are not limited to, if we need to: (1) retain your personal information to complete a transaction, provide a good or service, fulfill the terms of a written warranty or product recall, or to perform under a contract between us; (2) detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for that activity; and (3) comply with the law.
See above for how to call or email us for the information above.
Right to Opt-Out of the Sale of Personal Information
We do not sell your personal information to third parties. As such, there is no need to submit a request for us to not sell your personal information.
Right to Non-Discrimination For the Exercise of Your Privacy Rights
We will not discriminate against you for exercising any of your rights under the CCPA, as described above.
You may use an authorized agent to submit requests on your behalf to exercise the rights above. When contacting us through the methods above to exercise any of the CCPA rights, please indicate whether you are an authorized agent and we will provide you instructions on how we will verify and process your request.
YOUR ABILITY TO OPT-OUT OF FURTHER NOTIFICATIONS
Periodically, we notify our consumers of new products, announcements, and updates. If you would like to opt-out of being notified, please contact us at Privacy@HydraFacial.com.