Megan Mae Beauty Products, LLC (“MEGAN MAE,” “us” or “we” or “our”) values privacy, and we want you (“user,” “you”) to have the information you need to make your own decisions about your privacy.
Please note that the website, www.meganmae.com (referred to herein as the “site”), contains links to other sites. Unless otherwise stated, the collection and use of your Personal Information, as defined below, on other sites, not owned or controlled by Megan Mae, even if linked to www.meganmae.com are not governed by this Notice. Your use of a third-party website is governed by that site’s privacy notice and MEGAN MAE has no control over those privacy practices. In addition, the MEGAN MAE site is not intended for individuals under the age of 18, and MEGAN MAE does not knowingly collect or use Personal Information from individuals under the age of 18. If you are under 18 years old, you may not use the site.
Please also note that MEGAN MAE complies with the California Consumer Privacy Act of 2018 (“CCPA”), data privacy laws enacted in the states of Nevada, Virginia, Colorado, the European Union’s General Data Protection Regulations (“GDPR”) and Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”).
In addition, this Notice only applies to information that can be used to identify a specific individual (“Personal Information”) and which we collect through various channels, both online and offline, in the context of our sales and marketing activities and our service offerings (“Service Offerings”). This Notice also tells you how we verify the accuracy of your Personal Information and how you can request that we delete or update it. More specifically, and as used in this Privacy Notice, Personal Information means information that can, may or is likely to identify a particular individual because it relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, to that particular individual consumer, including, among other things:
Personal Information does not include (i) publicly available information (ii) aggregate information, meaning data about a group or category of services or users from which individual identities and other Personal Information has been removed; or (iii) deidentified information that cannot be easily linked back to an individual or that does not identify any specific individual; (iv) information that does not identify a particular individual; or (v) any information for which you expressly waive the right to maintain the personal information as private.
By visiting the site, interacting with us online or at events, or downloading or using any of our Service Offerings, you consent to this Privacy Notice and the collection and use of information as described herein. If you do not agree with this Privacy Notice, do not access or use the site or our Service Offerings. We follow privacy laws and regulations that are applicable to our company and our services in the areas where we do business.
Please read the following to learn more about our privacy practices before providing us with any Personal Information. If you have questions about this Notice, please e-mail us at firstname.lastname@example.org.
TYPES OF PERSONAL INFORMATION WE COLLECT
1. MEGAN MAE Website
There are two ways in which we collect your Personal Information for uses related to our marketing activities.
Information You Provide
When you access, use and/or interact with us through any of the channels detailed below, or in connection with activities that require sign-in or subscription, we collect business information and Personal Information you voluntarily provide us. This includes but is not limited to:
Providing this information is completely voluntary. Though you will still have access, to the site without providing the requested Personal Information, you may not be able to use certain services or features that require such information to function.
Below is a list of the ways in which you may interact with us. This list contains examples only and is not unlimited.
Information We Automatically Collect
Collecting this information enables us to better understand the visitors who come to our site, where they come from, and what content on our site is, or may be, of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our site and our Service Offerings to our visitors.
Information Collected Through Third Party Sources
We also obtain Personal Information about you from third party sources as permitted by applicable law, such as:
2. MEGAN MAE Service Offerings
MEGAN MAE facilitates the transfer of information for our customers in connection with our Service Offerings. MEGAN MAE customers may have individual users and/or individual employees and/or customers. MEGAN MAE may have no direct relationship with the individual users and/or individual employees of our customers. As a result, the type of information that is received and processed by MEGAN MAE’s Service Offerings is at the sole discretion of our customers. MEGAN MAE customers may or will request, require or encourage their individual users and/or individual employees and/or customers information to provide MEGAN MAE with the user, employee or customer (of the customers) Personal Information. In all such cases, the individual users and/or individual employees and/or customers of MEGAN MAE’s customer’s are voluntarily providing their Personal Information to MEGAN MAE. MEGAN MAE will then use this Personal Information in providing our Service Offerings.
By way of example, MEGAN MAE’s customers may create and/or add individual profiles within MEGAN MAE’s Service Offerings. In such cases, MEGAN MAE’s customer will voluntarily provide that employees Personal Information to MEGAN MAE and that Personal Information may be stored or maintained by MEGAN MAE as part of the Service Offerings. While MEGAN MAE may store the employee’s personal information, the MEGAN MAE customer has the control to access, modify or remove such Personal Information. MEGAN MAE will only utilize such Personal Information as permitted by this Notice.
Service Offerings that you use may allow you to store Personal Information owned by you or owned by your individual users, employees and/or customers. These Service Offering may also allow you to set up an account and/or an individual profile. While MEGAN MAE may store Personal Information and other data that you and/or your individual users, employees and/or customers provide either directly to you or provide to MEGAN MAE, all such Personal Information and data is owned by you or by your individual users, employees and/or customers. Except as otherwise provided in this Policy, MEGAN MAE will not provide any of your or your individual users, employees and/or customers’ Personal Information or data to any third party absent a subpoena or court order requiring disclosure of same. MEGAN MAE may disclose your Personal Information or your individual users, employees and/or customers’ Personal Information pursuant to a subpoena, an order from a court of competent jurisdiction or formal request from a law enforcement or a governmental agency.
We may also collect Personal Information if you participate in a phone call or online chat with a member of our technical support and/or sales teams. We may record the call and/or otherwise preserve the communication. We engage in call recording and communication preservation for purposes of quality monitoring, troubleshooting, training, to improve our Service Offerings, and for other internal business purposes. You will be notified if your call is being recorded. By staying on the line after receiving the notification, you consent to the call recording. If you do not consent to call recording, you may end the call.
HOW WE USE PERSONAL INFORMATION & THE BASIS FOR PROCESSING
Unless otherwise provided, we will only use and share your Personal Information as described in this Notice. For Personal Information that you are asked to provide, the reasons why you are asked to provide it will be made clear to you at the time of request.
1. We Will Use and Process Personal Information:
More generally, we only collect your Personal Information (i) when applicable, with your consent, (ii) in our role as a service provider, (iii) if we have a legitimate interest in doing so, or (iv) as authorized or required by law. The types of Personal Information we collect about you and the manner of collection depends on how you interact with us. However, we only collect Personal Information as in our view is reasonable and necessary for the above stated purposes.
If you have questions about or need further information concerning the legal basis on which we collect and use your Personal Information, please contact us via email@example.com.
2. Purposes of Processing
The processing of your Personal Information is based on the country’s and/or state’s law where you reside (as determined by your country and/or state selection at the time of registration) and your underlying preferences are stored and exchanged between MEGAN MAE’s group entities as necessary to ensure compliance.
We use and process Personal Information for the following business purposes:
Customer Service & Marketing:
Service Improvement & Business Operations:
3. How We Share Your Personal Information
MEGAN MAE Service Providers: We rely on service providers to perform a variety of services on our behalf. In so doing, we may need to share your Personal Information with them. Please note that we only provide our service providers with the Personal Information they need to perform their services and we require that they protect this information and not use it for any other purpose. These service providers are also not permitted to use your Personal Information for their own promotional or business purposes.
Business Partners: We may share your business contact information with our trusted business partners with whom we have a strategic partnership, or our investors. We do not otherwise sell or rent information about you or your use of this site to other companies.
Third-Party Sponsors: Please also note that our sponsors, co-sponsors and/or exhibitors may directly request your information at their conference booths or presentations. You should review their privacy policies to learn how they use Personal Information.
Business Transactions: Your information may also be transferred to another company in connection with a corporate transaction, such as a divestiture, merger, acquisition, consolidation, or asset sale (or the negotiation thereof) of a substantial amount or all of the assets of MEGAN MAE, or in the unlikely event of bankruptcy. We may assign or transfer your information as part of the transaction.
Affiliates. We disclose the information we collect from you to our affiliates or subsidiaries. If we do disclose your Personal Information to our affiliates or subsidiaries, their use and disclosure of your Personal Information will be subject to this Privacy Notice.
Legal Compliance: In addition, MEGAN MAE may use or disclose any information available to it, if required to do so by law, or if necessary to conform with the requirements of the law or to comply with legal process served upon us, to protect or defend our legal rights, or to investigate, prevent, or take legal action regarding suspected fraud, threats to physical safety, or other illegal activity.
Aggregated and Deidentified Information. We reserve the right to share aggregated, anonymized, or deidentified information about any individuals with nonaffiliated entities for marketing, advertising, research or other purposes, without restriction.
4. International Data Transfers
MEGAN MAE operates primarily in the United States and as a result, we, and/or our service providers that perform services on our behalf, may collect, process, and store your information in the United States and in other locations, including locations outside of the United States. By using the services, you acknowledge this, and understand that you may provide information, including Personal Information to MEGAN MAE employees, agents or representatives located in countries other than the U.S. Provided it is not otherwise prohibited by law, your Personal Information might be received in, transferred to, and processed in, countries other than the country in which you are resident. By providing Personal Information to MEGAN MAE or its employees, agents or representatives you consent to the above. If your individual users, employees and/or customers provide Personal Information to MEGAN MAE or its employees, agents or representatives each such individual also consents to the above.
If you or your individual users, employees and/or customers visit the site or use our Service Offerings from outside of the United States, Personal Information we collect about you or your individual users, employees and/or customers will be transferred to our servers in the United States and maintained there indefinitely. This may require the transfer of your Personal Information or the Personal Information of your individual users, employees and/or customers, out of your country of origin with laws governing data collection and use that may differ from or be more restrictive than U.S. law, or may result in governments, courts, law enforcement or regulatory agencies having access to or obtaining disclosure of your Personal Information or the Personal Information of your individual users, employees and/or customers pursuant to the laws of the applicable foreign jurisdiction. By allowing us to collect Personal Information about you and/or about your individual users, employees and/or customers, you and each of them consents to the transfer and processing of the Personal Information as described in this paragraph.
MEGAN MAE shares data with other entities within the MEGAN MAE group. We have implemented or will implement steps to comply with all with European Union data protection laws requiring all groups of companies to protect Personal Information they process from the EEA, including appropriate safeguards to require that your Personal Information will remain protected in accordance with this Notice when we share your Personal Information with third parties (as detailed above under “Sharing Your Personal Information”). These safeguards include transferring your Personal Information to third parties who are located in a country which the European Commission has determined has data protection laws that are at least as protective as those in Europe in order to ensure that your Personal Information is subject to a level of data protection which applies in Europe. For more information about these safeguards, please contact us at firstname.lastname@example.org.
You agree to indemnify, defend and hold harmless MEGAN MAE, our affiliates and our licensors, as well as the respective officers, directors, affiliates, employees, representatives or agents of ours or any such entities, from and against all losses, expenses, damages and costs, including reasonable attorneys’ and experts’ fees, arising from or related any claims made related to your use of the site or the Service Offerings or the use of the site or the Service Offerings by any of your individual users, employees and/or customers unless MEGAN MAE has failed to comply with this Notice. These indemnity obligations will survive termination of your relationship with us or your cessation of use of the site or the Service Offerings and survive termination of your individual users, employees and/or customers use of the site or the Service Offerings. MEGAN MAE reserves the right to assume the defense and control of any matter subject to indemnification by you, in which event you will cooperate with us in asserting any available defenses. If asked to do so, you agree that you will not attempt to access the site or the Service Offerings. Your obligation of indemnification herein shall survive termination or expiration of this Notice.
CUSTOMER SERVICE AND RECOURSE
If you have concerns about this Notice, its implementation, or other related inquiries or concerns, please contact us at email@example.com. Any improper collection or misuse of information in violation of this Notice should be reported by e-mail to firstname.lastname@example.org. MEGAN MAE takes seriously any reported violations and will investigate such violations and correct any misinformation.
If you are a resident of the EEA, you have the right to complain to a relevant data protection authority about our collection and use of your Personal Information. For more information, please contact your local data protection authority. Contact details for data protection authorities in the EEA and certain non-European countries (including the US and Canada) are available here.
CHANGES IN THIS NOTICE
We reserve the right to modify this Notice at any time, so please review it frequently. If we decide to change our Notice, we will post the changes to the Notice here and other places we deem appropriate. We will obtain your consent to any material changes if required by applicable law.
CONFIDENTIALITY AND SECURITY OF YOUR PERSONAL INFORMATION
MEGAN MAE uses reasonable and appropriate technical and organizational measures to ensure the security of the Personal Information users provide to us. We have implemented commercially reasonable information security policies, rules and technical measures to protect the Personal Information we have under our control from unauthorized access, improper use or disclosure, unauthorized modification, and unlawful destruction or accidental loss.
Among other things, any employees, contractors and/or data processors who have access to, and are associated with, the processing of your Personal Information are obligated to keep the information confidential and not use it for any other purpose than to carry out the services they are performing for us.
We retain Personal Information we collect from you only where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements).
When we have no ongoing legitimate business need to process your Personal Information, we will either delete or anonymize it, or, if this is not possible (for example, because your Personal Information has been stored in backup archives), then we will securely store your Personal Information and isolate it from any further processing until deletion is possible.
With regard to Personal Information processed as part of our Service Offerings, the MEGAN MAE retention periods are as follows:
For the avoidance of any doubt, these timelines shall not apply once you have (1) objected to MEGAN MAE’s use of your Personal Information in a situation where our use of your Personal Information is based on a legitimate interest; or (2) withdrawn your consent in a situation where our use of your Personal Information is based on your consent. In these cases, MEGAN MAE will retain and use the Personal Information only for so long as is necessary to provide our services, comply with our legal obligations, resolve disputes, and/or enforce our agreements.
In connection with our Service Offerings, the controller of your Personal Information is the customer providing the service to you. Otherwise, the controller of your personal information is MEGAN MAE. Please note, however, that in light of our GDPR obligations, we have appointed a Data Protection Officer (DPO) who can be contacted using the contact details listed below.
If you have questions specifically about this Notice, or to legal issues pertaining to the practices of the site or your use of the site, please contact us using the following details:
E-mail Address: email@example.com
76 Bowman Drive
Greenwich, CT 06831
Recommended Additions/Revisions to Specific Legislation Language
California Privacy Rights
This section provides residents of the State of California (“California Consumers”) with the disclosures and notices required under the California Consumer Privacy Act of 2018 (“CCPA”). The following paragraphs apply solely to California Consumers and describe the specific rights afforded under the CCPA.
Employee Data Exception. In many cases, the Personal Information we collect about you is in a business-to-business context when you are acting as an employee to a Customer or potential in the performance of your job duties. Please note that Personal Information collected and used in this context is not protected Personal Information under the CCPA.
Without limiting the foregoing, California Consumers may exercise the following rights over their Personal Information, subject to our receipt of a verifiable Consumer Privacy Request, as well as any exceptions and limitations that may apply.
We endeavor to respond to a verifiable Consumer Privacy Request from a California Consumer within 45 days of receipt. If we require more time, we will notify you in writing of the reason and extension period. We will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding receipt of the verifiable consumer request. If we cannot comply with part or all of your request, we will explain the reasons in our response.
To exercise your rights, please submit a verifiable consumer request to us by emailing firstname.lastname@example.org or in writing to:
76 Bowman Drive
Greenwich, CT 06831
Privacy Information for Nevada Residents
Under Nevada law, certain Nevada consumers may opt out of the sale of “personally identifiable information” for monetary consideration (as such terms are defined under Nevada law) to a person for that person to license or sell such information to additional persons. We do not engage in such activity; however, if you are a Nevada resident and you have purchased products or services from us, you may submit a request to opt out of any potential future sales under Nevada law by contacting us at email@example.com. Please note we may take reasonable steps to verify your identity and the authenticity of the request. Once verified, we will maintain your request in the event our practices change.
Privacy Information for Virginia Residents
This section provides residents of the State of Virginia (“Virginia Consumers”) with the disclosures and notices required under the Consumer Data Privacy Act (“CDPA”). The following paragraphs apply solely to Virginia Consumers and describe the specific rights afforded under the CDPA.
Without limiting the foregoing, Virginia Consumers may exercise the following rights over their Personal Information, subject to our receipt of a verifiable Consumer Privacy Request, as well as any exceptions and limitations that may apply.
European Union Privacy Rights
We adopted this section to comply with the European Union’s General Data Protection Regulations (“GDPR”). This section applies solely to residents of the European Union (“EU Residents”). MEGAN MAE provides the Service Offerings to individuals located in the EU in our capacity as a data processor to our Customers. However, if an EU resident interacts with MEGAN MAE as a Customer or potential Customer, MEGAN MAE collects and processes their Personal Information as a data controller. If you are an EU Resident, you have the following rights in relation to the Personal Information we hold about you:
Canadian Privacy Rights
We adopted this section to provide supplemental information in compliance with Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”). This section applies solely to residents of Canada where PIPEDA applies (“Canadian Consumers”). PIPEDA gives Canadian Consumers specific rights regarding Personal Information offering details on an identifiable person without the inclusion of name, title, telephone number and business address of an employee of a business or organization. The following paragraphs describe PIPEDA rights and explain how to exercise those rights.
Canadian Consumers may exercise the above rights over their Personal Information, subject to our receipt of a verifiable Consumer Privacy Request, as well as any exceptions and limitations that may apply.