Introduction
Choosing to shop with Glowsyou means you’ve placed trust in us to handle your personal data responsibly. In sharing your personal data we hope you in return benefit from a tailored and convenient shopping experience. With trust comes responsibility and we take this responsibility very seriously.
This privacy policy helps you to understand how we use your personal data and who we share it with. It applies if you shop on our websites, use our apps, shop in our stores or if you otherwise share your personal data with us; for example if you contact us with a query or where you tell us that you would like to receive marketing communications from us.
We change the terms of this privacy policy from time to time and you should check it regularly. The last updated date is shown at the beginning of the document. If we make any material changes we will take steps to bring it to your attention.
Who we are
When we say “we”, “our” or “us” in this policy we are referring to the companies that make up the Glowsyou.
The company named within the Glowsyou on the website or app is the data controller of your personal data, which means we are responsible for deciding how and why your personal data is used. We are also responsible for making sure it is kept safe, secure and handled legally.
We sometimes work with other organisations in connection with some of the processing activities described in this privacy policy, such as social media platforms. Where that data is collected and sent to other organisations for processing that is for a common purpose, we will be making decisions together in relation to that particular processing and will be ‘joint data controllers’ with the organisations involved. As joint data controllers, we and the other organisations involved in making these decisions will be jointly responsible to you under data protection laws for this processing.
We operate to the highest standards when protecting your personal data and respecting your privacy. If you have any questions about your personal data, or how we use it, you can contact our Data Protection :
Your rights
You have a number of “Data Subject Rights”, we have explained below what they are and how you can exercise them. You can read more about these rights on the UK Information Commissioner’s Office website at ico.org.uk/for-the-public, or on your local Data Protection Authority website.
- Right of access – You have the right to request a copy of the personal data that we hold about you.
- Right to rectification – If you think any of your personal data that we hold is inaccurate, you have the right to request it is updated. We may ask you for evidence to show it is inaccurate.
- Right to erasure (also known as the right to be forgotten) – You have the right to request that we delete your personal data that we hold. This right is not absolute and only applies in certain circumstances.
- Right to restriction of processing – You have the right to request we restrict or suppress the personal data we hold about you.
- Right to data portability – You have the right to ask us to electronically transfer your personal data to another organisation in certain circumstances.
- Rights with regards to automated decision making, including profiling – You have the right not to be subject to a decision that is based solely on automated processing if the decision affects your legal rights or other equally important matters and to object to profiling in certain situations, including for direct marketing.
- Right to withdraw Consent – Where we are relying on your consent for processing you can withdraw or change your consent at any time.
The above rights may be limited in some circumstances, for example, if fulfilling your request would reveal personal data about another person, if you ask us to delete data which we are required to have by law, or if we have compelling legitimate interests to keep it. We will let you know if that is the case and will then only use your data for these purposes. You may also be unable to continue using our services if you want us to stop processing your personal data.
If you have any general questions or want to exercise any of your rights, please send an email to: order@glowsyou.com . In order to maintain the security of our customers’ personal details, we may need to request proof of identity before we disclose personal data to you in response to any request.
We encourage you to get in touch if you have any concerns with how we collect or use your personal data. You have the right to lodge a complaint directly with a Data Protection Authority. The Data Protection Authority in the UK, where we are based, is the Information Commissioner’s Office (ICO), you can contact the ICO here: ico.org.uk/make-a-complaint. Our main supervisory authority in the EU is the Data Protection Commission (DPC) based in the Republic of Ireland, you can contact the DPC here: forms.dataprotection.ie/contact.
The lawful bases we use to process data
We will only ever process your data if we have a lawful basis to do so. The lawful bases we rely on are:
- Contract – This is where we process your data to fulfil a contractual arrangement we have made with you or because you have asked us to carry out a service before entering into a contract.
- Consent – This is where we have asked you to provide permission to process your data for a particular purpose.
- Legitimate Interests – This is where we rely on our interests as a basis for processing. Generally this is to provide you with the best products and services in the most secure and appropriate way, but not where our interests are overridden by your interests.
- Legal Obligation – This is where we have a statutory or other legal obligation to process the data, such as to comply with regulatory requirements and/or requests.
- Vital interests – This is where the processing of personal data is necessary to protect someone’s life.
The data we collect and how we use it
We collect and use the data that you provide to us directly, for example; when you register for an account; we use cookies and other similar technologies to collect data from your devices when you interact with our advertising or use our website (you can find out more information in the “Cookie Policy” section below); we keep records when you speak to our customer service teams; we take personal data from a number of third parties to help us manage your account and improve your shopping experience.
To process any orders that you place with us and to facilitate any returns
Lawful basis: Contract
- We take payment details to process payment for any credit or debit card orders you place with us. We share these details with our chosen payment processors.
- We use your account data plus your chosen delivery address details to; deliver your purchases and keep you informed of their status, and to process any returns including (where appropriate) collecting the item from you.
- Additionally, where you consent our chosen payment processors may store your payment card details at your request to speed up your checkout in the future.
To provide you with access to an account
Lawful basis: Contract
- To register an account with us we capture data such as your name, contact and delivery information, and a password to protect your account (account data). We use the same data on an ongoing basis to manage and provide secure access to your account, and provide you with the services you request.
To provide customer service to you
Lawful basis: Legitimate Interest in providing customer support
- We record calls and and keep correspondence (customer service records) when you contact our customer service teams or interact with us on social media. Using these customer service records is necessary to manage your queries or complaints effectively, for quality monitoring, for the defence of any claims and to continually improve our services.
- We may use automated machine learning systems to generate responses when you communicate with our customer contact centres. This helps us to resolve common queries quickly, provide you with a more efficient service and reduce the average response time for our customers.
To offer and manage any credit we provide to you
Lawful basis: Contract/Legitimate Interest in ensuring product suitability and managing debts
- When you apply for and use credit with us we will use your account data to make searches with third parties who will give us data about you, such as your financial history. We do this as it is necessary to assess your creditworthiness and product suitability.
- We use purchase and payment history, along with your account data on a cyclical basis as it is necessary to manage your credit facility with us.
- We use your account data, purchase history, payment history and third party data as it is necessary to collect and recover money that is owed to us (debt recovery) should your account fall into arrears. Please see the section on “third parties we share data with and receive data from” below for more information.
To personalise and improve your experience when you shop
Lawful basis: Consent/Legitimate Interest in providing relevant and personalised experiences when you shop with us
- We keep a record of how you interact with our website and any marketing you are exposed to. We use this data, along with purchase history across the Glowsyou demographics, account data and third party data. We do this so we can create a profile about you, which helps us to tailor your shopping experience, to show you products and offers from across our brands that we think you will be most interested in, and find ways to improve our stores, apps and websites.
- We use your account data, information about the devices you use to access our sites and your interactions with us to operate personalised features across our websites, apps and communication.
- In our stores we use CCTV footage for market research purposes so that we can best arrange our stores and stock the ranges our customers will be most interested in.
- We record your purchases made in one of our stores using tokenised data from your payment card. Your payment card(s) have a unique tokenised reference number and this is used to match it to your profile.
- We will send you a receipt by email if you have requested this when you shop in one of our stores.
To inform you about products and services that may interest you
Lawful basis: Consent
- We use technologies such as cookies within digital marketing networks, ad exchanges and social media networks such as Facebook’s Custom Audience to get relevant marketing messages across to you and other customers. We share aggregated and anonymised data about the customer segments we are interested in reaching with advertising partners, so they can focus on showing adverts to those who are most likely to be interested in our products, services and offers, and to prevent them showing you irrelevant or repetitive advertisements.
- We share limited data with selected suppliers to enable them to identify new prospective customers on our behalf and to prevent us repeatedly advertising products or services you have already bought.
Lawful basis: Legitimate Interest in assessing how and where to place advertising
- We receive data on how you interact with our adverts and content on third party websites and social media platforms (such as Google or Facebook) which it is necessary to use to tailor and personalise the products and services that are displayed to you.
To personalise and engage with you on social media
Lawful basis: Consent/Legitimate Interest to personalise the marketing and services we provide to you
- We use your personal data to engage with you on social media.
- We place targeted advertising in social media. You may receive advertising based on data about you that we have provided to a social media platform, or allowed it to collect using cookies on our website or code in our applications (or a combination of the two). For some of our marketing campaigns, we may use this data to exclude you from receiving advertising, if we believe it will not be relevant to you.
- You may also receive advertising because, at our request, the platform has identified you as falling within a group whose attributes we have selected or a group that has similar attributes to the individuals whose details it has received from us (or a combination of the two).
- We view statistical data and reports regarding your interactions with the pages and accounts we administer on social media platforms.
- To find out more, please refer to the information provided in the help pages of the platforms on which you receive advertising from us. Please also see the section below for further information regarding our use of social media, including specific platforms and the arrangements we have in place with them.
To keep in touch with you
Lawful basis: Consent/Contract
- When you agree to receive marketing we will keep you up to date with news of products and services including store events, offers, promotions and sale data. We may send you marketing via email, SMS or post, depending on your preferences. You can unsubscribe from marketing at any time through the “my account” or using the link in every email that we send to you.
- If you enter or apply for a prize draw or competition we will collect your contact details so that we can inform you if you are a winner.
Lawful basis: Legitimate interest in marketing to you and keeping customers updated
- Where we are permitted to market to you without consent, we will update you on the latest similar products and services sold on our websites or in our stores that we think you will be interested in.
- When we send you communications we use records of how you interact with our website and any other marketing we have sent to you, along with purchase history, to personalise the marketing we send you so it is relevant and interesting.
- When we respond to any communications and queries from you if you contact us via any of our customer contact channels, including when we interact with you through the chat function on our websites or apps.
- We use your account data to notify you about important service messages, such as material changes to this policy, product recalls or information about your account.
To ensure the Website and the services we offer you operate properly
Lawful basis: Consent
- We use cookies and other similar technologies to keep track of your preferences when using our site.
- We use cookies and similar technologies to help us understand how you use the site, this allows us to optimise your shopping experience and continually improve our site.
Lawful basis: Legitimate Interest in planning and delivering efficient operations and to prevent and detect crime or fraudulent activity
- We use data for logistics planning, demand forecasting, management information, dealing with errors on our site, and general research and development as it is necessary to keep the business running efficiently.
- We gather data about the devices you use to access our sites (desktop and mobile) for example your IP address and device type, to ensure the site is secure and works across multiple platforms.
To develop and improve our products, range and services
Lawful basis: Legitimate Interest in understanding our customers’ needs and behaviours to provide a better experience
- We share insights about our customers (in an anonymised and aggregated format) with the companies whose products we sell. This is necessary to help them better understand the different profiles of our customers, focusing on those who buy their products or are interested in them.
- We may contact you to take part in customer satisfaction surveys, if you respond we collect your feedback and contributions (customer feedback). We use this data to develop the services we offer.
- We work with data providers that specialise in consumer profiling, such as Experian and Merkle. These organisations provide demographic or other data as it is necessary to help us better understand customers’ demographics, lifestyles or shopping behaviours, usually linked to the areas where people live. This helps us to understand our customers better and provide products and services that people will want to purchase.
You can view the privacy policy for Experian and Merkle, including the ways in which they use and share personal data here:
– experian.co.uk/privacy/privacy-policies
– merkle.com/privacy
- We use data about how you browse and engage with our website to improve our websites.
- We use all data, including third party data in the development of new products, services and systems to ensure they work as expected and will be useful to our customers.
To prevent and detect crime and other incidents
Lawful basis: Legitimate Interest in keeping our customers and staff safe, reducing theft and fraud
- When you register an account, apply for credit or contact our customer contact centres we use your account, application and purchase history data as they are necessary to confirm your identity.
- We use device identifiers, IP addresses and account numbers in fraud prevention and investigation, as they are necessary to maintain network and data security.
To fulfil our legal obligations
Lawful basis: Legal obligation
- We use your data to ensure we comply with any requirements imposed on us by law or court order, including disclosure to law or tax enforcement agencies and authorities or pursuant to legal proceedings.
- We use your account data, order history and payment history to assist in monitoring for fraudulent transactions or suspected money laundering.
- We maintain a record of any health and safety incidents that occur in our stores or in our premises. We will share data with regulatory and other official bodies if they make formal requests.
- We will maintain records to meet regulatory and tax requirements.
- We will use your account data to contact you in connection with product recalls or other similar product quality issues and to comply with our legal obligations in connection with the sale of age restricted products.
Our use of social media
We use a number of different social media platforms to communicate with you and to promote products and services. We process your personal data using these platforms in a variety of ways, as follows:
- Pages/accounts. We use your personal data when you post content or otherwise interact with us on our official pages and accounts on Facebook, Instagram, Pinterest, Snapchat, TikTok, LinkedIn, X (formally Twitter) and other social media platforms. We also use the Page Insights service for Facebook, Instagram, Pinterest, TikTok, Snapchat and X to view statistical data and reports regarding your interactions with the pages and accounts we administer on those platforms and their content. Where those interactions are recorded and form part of the data we access through these page insights services, we and the relevant platform are joint data controllers of the processing necessary to provide that service to us.
- Cookies. We use cookies and similar technologies in our website to collect and send data to social media platforms about actions you take on our website and applications. In particular:
- Meta (who operates the Facebook and Instagram platforms) uses this data to provide services to us and also for further processing for its own business purposes. We and Meta are joint data controllers of the processing involved in collecting and sending your personal data to Meta using cookies and similar technologies as each of us has a business interest in Meta receiving this data. The services we receive from Meta that use this data are delivered to us through Meta Business Tools, which include Meta pixel, social plugins, code in our applications and website custom audiences. These tools allow us to target advertising to you within Meta’s social media platforms by creating audiences based on your actions on our website and applications and allow Meta to improve and optimise the targeting and delivery of our advertising campaigns for us.
- Our relationship with Meta and LinkedIn. As we are joint data controllers with these platforms for certain processing, we and each platform have:
- entered into agreements in which we have agreed each of our data protection responsibilities for the processing of your personal data described above;
- agreed that we are responsible for providing to you the information in this privacy policy about our relationship with each platform; and
- agreed that each platform is responsible for responding to you when you exercise your rights under data protection law in relation to that platform’s processing of your personal data as a joint data controller.
- Meta also processes, as our processor, contact information that we submit for the purposes of matching, online targeting, measurement, reporting and analytics purposes. These services include the processing Meta carries out when they display our advertisements to you in your news feed at our request after matching contact details for you that we have uploaded to the social media platforms they operate. Further information. The Meta company that is a joint data controller of your personal data is Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA (if you are a UK-registered user) or Meta Platforms Ireland Limited, Block J, Serpentine Avenue, Dublin 4, Ireland (if you are an EEA-registered user). The LinkedIn company that is a joint data controller of your personal data is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland For further information regarding these platforms and their use of your personal data, please see:
- Meta’s Controller Addendum for Page Insights and UK Controller Addendum for Business Tools (for users located in the UK) and Controller Addendum (for users located in the EEA), and LinkedIn’s Page Insights Joint Controller Addendum, which include information regarding how our and these platforms’ responsibilities to you are allocated as controllers of your personal data;
- Meta’s Privacy Center including its privacy policy at www.facebook.com/privacy and LinkedIn’s privacy policy at www.linkedin.com/legal/privacy-policy which include details of the legal reasons (known as ‘lawful bases’) on which each platform relies to process your personal data, together with details regarding your data protection rights.