PRIVACY POLICY

Last Updated: 11/20/2023

Gemma Grace Jewelry (“GGJ,” “Company,” “we,” or “us”) respects your privacy. This Privacy Policy is intended to describe how GGJ collects, uses, and shares personal information that you provide to us or that we collect through our website, gemmagracejewelry.com, any future Gemma Grace Jewelry mobile application (collectively, “Site” or “Website”), and our stores and your rights in connection with that information.

 

SECTION 1 - INFORMATION WE COLLECT

“Personal information,” for purposes of this Privacy Policy, generally includes information that may be used to identify you. As described in this Privacy Policy, we may collect certain personal information from or about you in connection with your use of, or submissions to, our website and through your purchase of products from our website or stores, including:

  • Contact and account information, such as your first and last name, address, email address, and phone number. If you create an account with us, we will also collect your username and password.
  • Transaction information, such as payment amount for products you purchase and limited payment information. Please note, when you make a purchase from our Site, we utilize third-party payment processors to manage and administer the payment process (“Payment Processors”). When you make purchases from us, the processing of payment information is governed by the respective Payment Processor’s privacy policy. Gemma Grace Jewelry does not collect or store your complete bank account number or credit/debit card number; however, we may collect or receive limited information regarding your transaction and payment, such as your payment card type and last four digits of your payment card number.
  • Usage and Device Information, such as browser type and version, the operating system of your device and language, country, as well as areas in the website you visit most frequently and when. We also automatically collect the Internet Protocol (“IP”) address associated with your device when you visit our Website and may collect other information about your device, such as the browser ID and device ID. If you use our mobile app or access the Site from a mobile device, we may collect additional information, such as device information (such as your mobile device ID, model, and manufacturer), operating system, version information, carrier-related information, including the name of your wireless carrier, and IDs related to the cell phone hardware in your phone as well as the network to which the device is connected, mobile phone number, application-specific and instance-specific identifiers, and location information, as further described in this Privacy Policy. In the event we may collect precise information about the location of your device, we will obtain your consent as required by law. Once you have consented to the collection of the precise location of your device, you may revoke this consent by managing your location services preferences through the settings of your device. For more information on our collection of device and usage information and use of cookies and similar technologies, see the “Usage Information and use of Cookies and Similar Technologies” section of this Privacy Policy.

  • When you visit our website, log in, register or open an email, cookies, ad beacons, and similar technologies may be used by our online data partners or vendors to associate these activities with information they or others have about you, including your email address. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout.

We may create de-identified data from personal information by removing data components that makes the data personally identifiable to you, through obfuscation, or through other means. Subject to applicable law, our use of de-identified data is not subject to this Privacy Policy.

 SECTION 2 - HOW WE COLLECT AND USE PERSONAL INFORMATION

We may collect personal information as follows:

  • Interactions with the Site and communications with us. We collect personal information when you use or interact with the Site, create an account, make purchases, or otherwise utilize our services.We also collect personal information when you communicate with or submit information to us, including when you submit inquiries or request information, chat with our styling experts, and when you subscribe or sign up to receive communications, materials, or other information from us.

  • Online communities and forums. We may collect personalinformation when you engage with our online communities, blogs, and forums, including any information you may provide through your interaction with or participation in our social media pages and groups. Please note that online forums may be publicly accessible and other users may view information you post in the forums. We encourage you to exercise care in deciding what information and content you wish to disclose on the areas of the Site that are accessible to the general public.

  • Cookies and Similar Technologies. We may collect certain personal information using cookies and other technologies, such as web beacons, device IDs, geolocation, HTML5 local storage, and IP addresses, as further described in this Privacy Policy. The “Usage Information and use of Cookies and Similar Technologies” section of this Privacy Policy contains more information and options to control or opt-out of certain data collection or uses related to cookies and similar technologies.

We use the personal information we collect as described in this Privacy Policy, including for the following purposes:

  • to maintain, administer, and service the Site and to offer and provide the services;

  • to process transactions and fulfill orders;
  • to provide customer service, including to contact and communicate with you in connection with the services and to address and respond to inquiries or requests;

  • to develop and improve the Site and services, including to better tailor the features, performance, and support of our Site and services, for research, statistical, and analytics purposes, and for marketing and advertising purposes, including to send you marketing communications;
  • to make inferences drawn from your use of the Website, which may be used to enable interest-based advertising;
  • for security purposes and for fraud, loss, and other crime prevention purposes, to assist in the investigation of suspected illegal or wrongful activity, and to protect and defend our rights, interests, and property, or the rights or safety of third parties;
  • for debugging purposes to maintain and improve the Site;

  • to enforce agreements or to comply with laws, regulators, court orders, or other legal obligations, or pursuant to legal process.

 

SECTION 3 - HOW WE MAY SHARE INFORMATION

We may share personal information as described in this Privacy Policy, including with the following third parties:

    • Vendors and Partners: We share personal information with our vendors, consultants, payment processors, and other technology and service providers who need access to such information to carry out work on our behalf in the provision of the services, including for technical and processing functions, technical and customer support and communications, analytics, and for our direct marketing and advertising purposes.
    • Social Networks and Advertising Networks: We may share your personal information, specifically your IP address, device ID or similar online identifier, with certain third parties, such as social networks and advertising networks. We use this information to personalize advertising you see after you have visited our Website. For more information regarding our advertising practices, see the “Usage Information and use of Cookies and Similar Technologies” section of this Privacy Policy.
    • Legal and Compliance: We may share personal information with government entities and agencies, regulators, law enforcement, and other third parties, including to comply with applicable laws and regulations, to respond to a subpoena, search warrant, or pursuant to legal process, and to establish or exercise our legal rights or for fraud- or crime-prevention purposes.

    • Protection of Rights and Interests. We may share personal information if we believe disclosure is necessary or appropriate to protect the rights, property, or safety of our company or other third parties, and to investigate, detect, or prevent against fraud or other illegal activity.

  • Corporate Transactions:Subject to applicable law, we reserve the right to transfer some or all personal information in our possession to a successor organization in the event of a merger, acquisition, bankruptcy, or other sale or transfer of all or a portion of our assets, including for the purpose of permitting the due diligence required to decide whether to proceed with such a transaction. If any such transaction occurs, the purchaser will be entitled to use and disclose the personal information collected by us in the same manner that we are able to, and the purchaser will assume the rights and obligations regarding personal information as described in this Privacy Policy.


SECTION 4 – USAGE INFORMATION AND USE OF COOKIES AND SIMILAR TECHNOLOGIES

We automatically collect the Internet Protocol (“IP”) address associated with your computer when you visit our Website, and we also collect device information and usage information, as described above. This information is used to help us administer the Website, remember your preferences, and diagnose technical problems. We also analyze the information for aggregate trends about how our Website is used and to help improve our Website.

To collect this information, we use cookies. Cookies are small data files sent by a website and stored on the browser of the computer or device at the request of that site. Cookies store information related to a user's browser to enable us to recognize the browser on return visits to our Website and to remember your preferences. In those jurisdictions that require it, we allow the data subject to give explicit permission or to deny the use of certain categories of cookies.

Cookies, as well as other tracking technologies, such as HTML5 local storage and similar mechanisms, may record information such as a unique identifier, information you enter in a form, IP address, and other categories of data. We may also use web beacons or “pixels,” and in certain circumstances may collect IP address, screen resolution, browser software, and operating system types, clickstream patterns, dates and times that our site is accessed, the referring site from which you linked to our Website, and other categories of data related to interactions with our Website.

We use third parties, including Google Analytics, to assist us in collecting and understanding usage information. For more information about Google Analytics, see the Google Analytics Terms of Service and the Google Privacy Policy. You can prevent Google Analytics from collecting information about you and recognizing you on return visits to our website by disabling cookies on your browser or by installing the Google Analytics opt out plug in. Note that we are not responsible for the Google Analytics opt-out tools.

Third Party Cookies and Tracking

We use third-party service providers to assist us in collecting and understanding usage information and serving advertising. Most browsers can be set to detect browser cookies and to let a user reject them, but refusing cookies may affect usability and functionality of our Website. To learn more about browser cookies, including how to manage or delete them, refer to the “Tools,” “Help,” or similar section of your web browser.

We and our third parties, as well as other companies not affiliated with us, including ad networks, web analytics companies, and social networking platforms, may use tracking technologies, such as those described above, to collect information about your online activities over time and across our and other websites. We and they may use this information to infer your interests, to deliver targeted advertisements, such as those based on your browsing activities, and to measure the effectiveness of our advertising.

As with most sites, we do not honor “do not track” signals transmitted by web browsers as there is no industry standard for implementing such programs. For more information about third-party advertisers and how to prevent them from using your information, visit the NAI’s consumer website at http://www.networkadvertising.org/choices or http://www.aboutads.info/choices/. If you do want to opt out using these tools, you need to opt out separately for each of your devices and for each web browser (such as Chrome, Edge Firefox, Safari or others) that you use on each device.


SECTION 5 – LINKS TO THIRD-PARTY SITES

Our Site may contain links or otherwise provide access to another website, mobile application, or Internet location (collectively “Third-Party Sites”). For example, we utilize third-party payment processors to manage and administer the payment process when you make purchases on our Site. In addition, the ambassador program is managed by a Third-Party Site not owned or operated by Gemma Grace Jewelry. If you sign up to become an ambassador, you are submitting information to a third party. Please note that we have no control over and are not responsible for Third-Party Sites, their content, or any goods or services available through the Third-Party Sites. Our Privacy Policy does not apply to Third-Party Sites. We encourage you to read the privacy policies of any Third-Party Site with which you choose to interact.


SECTION 6 - SOCIAL NETWORK WIDGETS

Our Sites may include social network sharing widgets that may provide information to their associated social networks or third-parties about your interactions with our web pages that you visit, even if you do not click on or otherwise interact with the plug-in or widget. Information is transmitted from your browser and may include an identifier assigned by the social network or third party, information about your browser type, operating system, device type, IP address, and the URL of the web page where widget appears. If you use social network tools or visit social networking sites, we encourage you to read their privacy disclosures to learn what information they collect, use, and share.


SECTION 7 – INFORMATION ABOUT CHILDREN

Our site is not intended for children under the age of 13, and we do not knowingly collect personal information from individuals under the age of 13 years. If you become aware that an individual under 13 years of age has provided us with their personal information please contact us at support@gemmagracejewelry.com. If we become aware that an individual under 13 years has provided us with their information we will take steps to promptly remove the data as permitted by law.


SECTION 8 - DATA SECURITY

To protect your personal information, we implement technical, and organizational measures to help protect against improper access, use, alteration, or destruction of personal information. Please note, however, that we cannot fully eliminate security risks associated with the storage and transmission of personal information.


SECTION 9 – UPDATING YOUR COMMUNICATIONS PREFERENCES AND WITHDRAWING CONSENT

If you have provided your consent for certain uses of your personal information, you may at any time withdraw the consent you provided for the purposes set forth in this Privacy Policy by contacting us at support@gemmagracejewelry.com, provided that we are not required by applicable law or professional standards to retain such information.

If you would like to stop receiving newsletters or other marketing or promotional messages, notifications, or updates, you may do so by following the unsubscribe instructions that appear in these e-mail communications. Please be advised that you may not be able to opt-out of receiving certain service or transactional messages from us, including legal notices. If you have opted-in to receiving SMS/text messages from Gemma Grace Jewelry, you may opt-out at any time by following the instructions in the message and texting “STOP.” For additional assistance with unsubscribing to these communications, you may also contact us as at support@gemmagracejewelry.com.

Please note that if you do not provide consent, if you withdraw your consent or object to processing, or if you choose not to provide certain personal information, we may be unable to provide some or all of the services.


SECTION 10 – DATA RETENTION

We retain personal information for as long as is necessary to fulfill the purposes for which we obtained the personal information, including to provide the services, or for such longer period as may be required or permitted by applicable law. We will also retain personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements and policies. We use the following criteria to set our retention periods: (i) the duration of our relationship with you; (ii) the purposes for processing your personal information and associated legal bases; (iii) the existence of a legal obligation as to the retention period; (iv) our contractual obligations; and (v) the advisability of retaining the information in light of our legal position (for example, applicable statutes of limitations, litigation, or regulatory investigations).


SECTION 11 – TRANSFER OF DATA TO U.S.

Please note that if you are visiting the Site from outside of the United States, your information may be transferred to, stored, and/or processed in the United States. The data protection and other laws of the United States and other countries might not be as comprehensive as those in your country. If you are located outside of the United States, the transfer of personal information may be necessary to provide you with the requested information and services and/or to perform any requested transaction. By accessing the Site, you acknowledge and consent to the transfer of your information to our facilities in the United States.

________________________________________________________________________

 

SECTION 12 - ADDITIONAL DISCLOSURES FOR CALIFORNIA RESIDENTS

The California Consumer Privacy Act (CCPA) provides California residents with certain rights regarding their personal information. This section provides additional information regarding our collection and sharing of personal information under the CCPA, describes your CCPA rights, and explains how to exercise them.

 Categories and Sources of Personal Information We Collect and Share

We collect and process personal information as set forth in this Privacy Policy. The following chart provides additional information regarding the categories and sources of personal information we collect and process:

Categories of personal information we collect

  • Online identifier, Internet Protocol address
  • Personal information under subdivision (e) of California Business and Professions Code Section 1798.80 that we may collect includes your name, address, phone number, and credit card number
  • Internet or other electronic network activity information related to your use of our website
  • If you call us or create an account, we will collect identifiers such as your name, email address, and phone number
  • If you choose to send us a question regarding our products, we will collect your name and email address
  • Commercial information, including records of products purchased or considered, and purchasing histories or tendencies

Categories of sources from which the personal information is collected

We collect the personal information directly from you. We may also collect information from cookies or similar technologies as further described in the “Usage Information and use of Cookies and Similar Technologies” section of this Privacy Policy.

Business or commercial purpose for collecting or selling personal information

We collect your personal information to operate the website, respond to your requests, and for our business and commercial purposes as set forth in the “How We Collect and Use Personal Information” section of this Privacy Policy.

Categories of third parties with whom we share personal information

We may disclose your personal information with our vendors and partners, social networks and advertising networks, government entities and other third parties for legal compliance purposes and for the protection of our rights and interests, and with a successor organization in the event of a corporate transaction, as further described in the “How We May Share Information” section of this Privacy Policy.

Specific pieces of personal information we have collected

We collect the following personal information, as further described in the “Information We Collect” section of this Privacy Policy:

  • Name, address, email address, and phone number if you choose to provide them
  • Username and password, if you create an account with us
  • Limited payment card information if you choose to make a purchase
  • Internet Protocol address and device ID
  • Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding your interaction with our website, including inferences drawn from that information

 

Sale of Personal Information

The CCPA requires businesses to disclose to California consumers if their personal information is “sold” as defined under the CCPA and to provide a mechanism for those consumers to opt-out of the sale of their personal information. We may share certain information such as a unique identifier (e.g., your device ID) with third parties for targeted advertising and online behavioral advertising purposes, which may be interpreted to be a “sale” as it is broadly defined under the CCPA. You can opt-out of the “sale” of your personal information by submitting an email to support@gemmagracejewelry.com. For additional information regarding your rights under the CCPA, see the following CCPA Privacy Rights section.

CCPA Privacy Rights

California residents have certain rights with respect to their personal information. You may be entitled by applicable law to exercise the following rights with respect to your personal information:

    • Right to Know and Access Information: You have the right to request what personal information we maintain about you. If we grant your request, we will provide you with a copy of the personal information we maintain about you in the ordinary course of business. This may include what personal information we collect, use, or disclose about you. We may not fulfill some or all of your request to access as permitted by applicable law.
    • Deletion of Information: You have the right to request that we delete your personal information. Depending on the scope of your request, we may refrain from granting your request, as permitted by applicable law. For example, we may be legally required to retain your information in our business records. You may submit a deletion request using the methods provided below.
  • Notice of Right to Opt-Out of Sales of Personal Information: You have the right to direct us not to sell your personal information and to refrain from doing so in the future. To opt-out of the sale of your personal information, submit an email to support@gemmagracejewelry.com.
  • Right to Non-Discrimination: You have the right not to receive discriminatory treatment by us for the exercise of the privacy rights described above.
  • Authorized Agent: California residents may use an authorized agent to exercise a privacy right on their behalf. If you are an authorized agent acting on behalf of a California resident to communicate with us or to exercise a privacy right listed above, you must be able to demonstrate that you have the requisite authorization to act on behalf of the resident and have sufficient access to their laptop, desktop, or mobile device to exercise these rights digitally. To exercise rights on behalf of one of our users, please contact us at the contact information with supporting verification information, which includes a valid Power of Attorney in the State of California, proof that you have access to the consumer’s interface, and proof of your own identify.

How to Exercise Your Rights

To exercise the rights described above, you may submit your request at the below link or by contacting us using one of the following methods:

  • Submit Your Request Online to: support@gemmagracejewelry.com
  • Mailing Address: Gemma Grace Jewelry, 7580 NW 5 Street, Plantation FL 33318, United States

Your exercise of the rights described in this section is subject to certain exemptions and exclusions under the law. We will respond to authorized and verified requests as soon as practicable and as required by law. To protect your privacy and security, we may take steps to verify your identity in order to respond to your request. Should we need to collect additional personal information from you in order to verify your identity, we will only use that information for identity verification purposes, and shall delete it as soon as practicable after processing the request. Requests to exercise these rights may be granted in whole, in part, or not at all, depending on the scope and nature of the request and applicable law. Where required by applicable law, we will notify you if we deny or restrict your request and notify you of any reasons why we are unable to honor your request.

California “Shine the Light” Rights

 

If you are a resident of California, you may request certain information regarding our disclosure of personal information (if any) to third parties for those third parties' direct marketing purposes. To make such a request, please contact us at Gemma Grace Jewelry, 7580 NW 5 Street, Plantation FL 33318, United States.

________________________________________________________________________


SECTION 13 - ADDITIONAL EU/EEA/UK DISCLOSURES

Subject to applicable law, individuals in the European Union (EU), European Economic Area (EEA), and United Kingdom (UK) have certain rights regarding your personal information, including the right to request confirmation from us as to whether or not we are processing your personal information. Where we are processing your personal information, subject to applicable law, you may also have the right to:

  • Request access to, modification of, or correction of your personal information. You have the right to request access to, modification of, or correction of your personal information. If you have registered for an account, you can also make changes to your personal information within your account settings.
  • Request deletion of your personal information. You have the right to request that we delete the personal information that we have collected about you.
  • Request restriction of processing. You have the right to request that we restrict processing of your personal information in certain circumstances, such as where you believe that the personal information we hold about you is inaccurate or our processing is unlawful.
  • Object to processing. In certain circumstances, you may have the right to request that we stop processing your personal information, such as a request to stop sending you direct marketing communications. To opt-out of direct marketing communications, please see the instructions in the “Updating Your Communications Preferences and Withdrawing Consent” section of this Privacy Policy.
  • Data portability. In certain circumstances, you may have the right to receive the personal information concerning you that you provided to us or to request that we transmit your personal information to another data controller.

Lodge a Complaint. You have the right to lodge a complaint with a supervisory authority.

 

To exercise your rights, send us an email to support@gemmagracejewelry.com. Your exercise of the rights described in this section is subject to certain exemptions and exclusions under the law. We will respond to authorized and verified requests as soon as practicable and as required by law. To protect your privacy and security, we may take steps to verify your identity in order to respond to your request. Requests to exercise these rights may be granted in whole, in part, or not at all, depending on the scope and nature of the request and applicable law. Where required by applicable law, we will notify you if we deny or restrict your request and notify you of any reasons why we are unable to honor your request.

Basis for Processing Personal Information

If you are located in the EU, EEA, or UK, our legal basis for collecting and processing the personal information described above will depend on the personal information involved and the specific context in which we collect it. We generally collect and process personal information to perform our contractual obligations to you, including to fulfil your request for products or services, or to take steps in response to information or inquiries you may submit prior to entering into a contract with us, and for our legitimate interests, where those interests are not overridden by your data protection interests or fundamental rights and freedoms. Our legitimate interests are described in more detail in this privacy policy, including in “How We Collect and Use Personal Information” section of this Privacy Policy, but these typically include improving, maintaining, providing, offering, and enhancing our technology, products, and services, ensuring the security and functionality of the Site and services, and supporting our marketing activities.

In some limited cases, we may collect and process personal information to comply with laws, regulators, court orders, or other legal obligations, or pursuant to legal process, or where we believe disclosure is necessary to protect the vital interests of you or another person. Where required by law, we will obtain consent to collect personal information. For additional information regarding your right to withdraw your consent, please see the “Updating Your Communications Preferences and Withdrawing Consent” section of this Privacy Policy.

 

________________________________________________________________________


SECTION 14 - UPDATES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. The most recent version of the Privacy Policy is reflected by the version date located at the top of this Privacy Policy. We encourage you to review this Privacy Policy often to stay informed of how we may process your information.


SECTION 15 - QUESTIONS AND CONTACT INFORMATION

For more information or if you have questions or concerns about our privacy practices, contact our Privacy Compliance Officer at support@gemmagracejewelry.com or by mail at:

Gemma Grace Jewelry
Re: Privacy Compliance Officer

7580 NW 5 Street

Plantation FL 33318

United States