PRIVACY POLICY

INTRODUCTION

 

Smashit Cosmetics (Registered brand under Ld Group AB) is committed to respecting and protecting your privacy. Our goal is to be clear about what information we collect and how we use and protect your personal information. 

The below Privacy Policy (together with our Terms & Conditions any other documents referred to in it and our Cookie Policy) outlines how we may collect, use, store and process your personal information.

We truly hope that you will take time to read it through as we have no other goal but to maintaining your privacy. Please remember that you can manage your information and protect your privacy anytime by, for instance, viewing and editing your information in your account or controlling what kind of cookies are used when you visit our website.

 

ABOUT SMASHIT COSMETICS PRIVACY POLICY

 

This Privacy Policy is for the website https://www.smashit.se, https://www.smashitcosmetics.com, https://www.smashitcosmetics.co.uk, https://www.smashitcosmetics.cn all its sub-domains and its official app (hereinafter, the “Website”), and is served by Ld Group AB, a company organized under the laws of Sweden, with registration number 556855-1773 and its registered address at Norra vallgatan 90, 21122 - Malmö, Sweden.

 

LAWS AND REGULATIONS

 

The information we gather, use and process are collected in accordance with:

  • The Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, or “GDPR”)
  • The Swedish Data Protection Act (Personuppgiftslag 1998:204).

 

PRINCIPLES

 

This Policy is based on the following principles:

  • Personal data shall be processed lawfully, fairly and transparently;
  • Personal data shall only be collected for specific, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
  • Personal data shall be adequate, relevant and limited to what is necessary for processing;
  • Personal data shall be accurate and, where necessary, kept up to date with every effort to erase or rectify without delay;
  • Personal data shall be kept in a form such that the data subject can be identified only as long as is necessary for processing;
  • Personal data shall be processed in a manner that ensures the appropriate security;
  • Personal data shall not be shared with third parties except when necessary in order for them to provide services upon agreement;
  • Data subjects must easily exercise their rights.

 

WHAT PERSONAL INFORMATION ARE COLLECTED?

 

Personal information is data that can be used to identify or contact you.

Under the EU’s General Data Protection Regulation (GDPR) personal data is defined as: “any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”.

If we do collect personal data, we will nevertheless never collect sensitive personal data about you. The EU’s General Data Protection Regulation (GDPR) defines sensitive personal data as “categories of personal data related to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation.”

When you use our website and/or purchase us from us, we may gather various information. In any event, we are committed to ensuring that the information we receive and use are appropriate for the below purposes.

 

  1. WHEN YOU SET UP AN ACCOUNT

INFORMATION WE MAY USE

PURPOSES

LEGAL BASIS FOR PROCESSING

Email address

To create an account

For the purposes of our legitimate interests*:

Smashit Cosmetics has to give you access to content and updates and facilitate the efficient running and operation of our website

Full name

Phone numbers

Billing address

Shipping address

To pre-register information that will be asked at the checkout

For the purposes of our legitimate interests*:

By pre-registering this info, it will facilitate, smooth and ease up your purchases.

You do not have to pre-register any of this info though!

Visited and Liked products

To manage your account, facilitate purchasing process

For the purposes of our legitimate interests*:

Being able to see what products you have visited and liked will improve your shopping experience

Order history

To check out your orders history

Performing the contract between you and Smashit Cosmetics:

It’s just a simple history of the purchases you have previously made

Information from Facebook account you link to your Smashit Cosmetics account

So you can quickly log into Smashit Cosmetics and not registered any account

To provide you with product you might like

For the purposes of our legitimate interests*:

So you can simply connect and use our website, as well as buy products you like!

  1. WHEN YOU MAKE A PURCHASE

INFORMATION WE MAY USE

PURPOSES

LEGAL BASIS FOR PROCESSING

Email address

Full name

Phone number

Shipping address

Billing address

So you can purchase and receive your order

Performing the contract between you and Smashit Cosmetics:

We cannot send your order if we do not get access to this information

 

To prevent and detect fraud

For the purposes of our legitimate interests*:

Security of your data is paramount to us. It will help us investigate and help prevent security issues and abuse.

Furthermore, we have a legal obligation to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of our processing of information about individuals

Phone numbers

Email address

To receive updates about your order via e-mail, SMS or our app

Performing the contract between you and Smashit Cosmetics:

Without updates, how will you know when your order arrives?

 

To receive marketing communications via e-mail or SMS

For the purposes of our legitimate interests*:

After your first purchase, you will start receiving newsletters about our offers. You will be able to easily opt-out at any moment.

Email address

To send you NPS surveys about our services

Performing the contract between you and Smashit Cosmetics:

Your opinion about your purchases matters to us. Our goal is to provide the best service possible and we won’t be able to do that if we do not know how we have done.

 

To notify you about changes to our services

For compliance with our legal obligations and our purposes of our legitimate interests*:

We must be able to warn you about changes affecting our Legal notices

Payment information details

Receive your payments and manage refunds and compensation

Performing the contract between you and Smashit Cosmetics:

We’ve got to be sure to send and refund the money to the right person!

 

To prevent and detect fraud

For the purposes of our legitimate interests*:

Security of your data is paramount to us. It will help us investigate and help prevent security issues and abuse.

Furthermore, we have a legal obligation to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of our processing of information about individuals

  1. WHEN YOU INTERACT WITH OUR WEBSITE AND/OR APP

INFORMATION WE MAY USE

PURPOSES

LEGAL BASIS FOR PROCESSING

Email address

To sign up for our newsletters and receive information, news and offers about our products

Your consent:

You give your consent to receive newsletters from us

 

To inform or remind you of any task carried out which remains uncompleted (incomplete orders, abandoned baskets)

For the purposes of our legitimate interests*:

It helps us improve your customer experience

Information gathered when you visit our website. Cookie Settings.

To provide, update, maintain, improve and protect our website, business and services

For the purposes of our legitimate interests*:

Security of your data is paramount to us. It will help us investigate and help prevent security issues and abuse in addition to giving you the best experience possible when using our website

We also have a legal obligation to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of our processing of information about individuals

In addition, such cookies will help us improve your shopping experience

 

To deliver relevant website content and online advertisements

For the purposes of our legitimate interests*:

To deliver you tailored services, improve your shopping experience and grow our business

  1. WHEN YOU CONTACT US

INFORMATION WE MAY USE

PURPOSES

LEGAL BASIS FOR PROCESSING

Name

Email address

Telephone number

Correspondences history

Order information

Shipping address

Payment information

To contact, communicate with you and manage all queries through e-mail, live chat, telephone and social media.

In other words: to give you the best customer care

Performing the contract between you and Smashit Cosmetics:

We will always be there to answer every of your questions and concerns about your orders.

And if you have not placed a purchase yet, it’s in our legitimate interests to gather such info in order help you out

ID Documentation

To verify your identity when you request further information based on your rights

We have a legal obligation to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of our processing of information about individuals. We must be able to verify identify before giving away your information. You would not want this information to fall into the wrong hands

  1. WHEN YOU ENTER OUR COMPETITIONS

INFORMATION WE MAY USE

PURPOSES

LEGAL BASIS FOR PROCESSING

Contact details such as email address, full name, telephone number, shipping address

To smoothly and perfectly manage the competitions (contact contestants, identify contestants, deliver prize deliveries)

Performing the contract between you and Smashit Cosmetics:

If we cannot use the information you give us, how can you win?!

Your written replies and information submitted in the contest

 

 

*When we rely on the ‘legitimate interests’ condition, Smashit Cosmetics will always meet the following requirements:

  • We must process the information for the purposes of our legitimate interests or for those of a third party to whom we disclose it;
  • The above interests must be balances against your interests. The “legitimate interests” condition will not be met if the processing is unwarranted because of its prejudicial effect on your rights and freedoms, or legitimate interests. Smashit Cosmetics legitimate interests do not need to be in harmony with those of the individual for the condition to be met. However, where there is a serious mismatch between competing interests, your legitimate interests will always come first.

 

MARKETING COMMUNICATIONS

 

If you happen to purchase or willingly give us your email address, you will receive marketing messages by email and/or SMS.

These marketing messages are only meant to warn you about our current and next offers.

You can of course decide to unsubscribe from us at any time.

How do you unsubscribe from marketing communications?

  1. SMS
  • By following instructions given at the end of the SMS message
  • By contacting our customer Service
  1. NEWSLETTER
  • By clicking on the unsubscribe link at the end of the email
  • By contacting our customer service

 

USE OF DATA FOR ADVERTISING PURPOSES

 

We happen to use data collected during your visit to create banners and ads when you visit other third websites. Those ads are created via pixels and are based on information we hold about you (such as search history) which explains why you will be able to see ads matching items that are similar to those you have checked out on our website.

All information used to create those ads are pseudonymized and we will never use data that clearly identify you.

 

SHARING YOUR INFORMATION

 

We will never sell your personal data to any third party.

However, we may share your personal information with companies who are experts in their field and assist us in operating the website, conducting our business or servicing you.

Each of our service providers have been selected by us for their ability to provide the particular services needed, including their ability to handle your personal information. All those providers provide sufficient guarantees to implement the technical and organizational measures necessary to meet the requirements of the GDPR and our own.

We share your personal information in the following cases:

  • To any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries;
  • In the event that we sell or buy any business or assets, data may be disclosed to the prospective seller or buyer of such business or assets;
  • If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our Terms & Conditions and other agreements; or to protect the rights, property, or safety of Smashit Cosmetics, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction;
  • If we are processing it on behalf of a customer;
  • To companies for the performance of any contract we enter into with you or them and that help us provide our services adequately such as, payment service providers, delivery companies or our warehouse.
  • To other professional services companies such website hosts, advertising/marketing agencies and analytics or search engine providers helping us run, improve and optimize the Website or helping us store your data.
  • With your express consent.

 

TRANSFERS OF YOUR INFORMATION OUTSIDE THE EUROPEAN ECONOMIC AREA

 

Where a third-party provider is located outside the European Economic Area, we will always ensure that the transfer of personal data will be protected by appropriate safeguards, namely the use of standard data protection clauses adopted or approved by the European Commission where the data protection authority does not believe that the third country has adequate data protection laws or with companies that are Privacy Shield Certified.

 

WHAT ARE YOUR RIGHTS?

 

At any point while we are in possession of or processing your personal data, your rights are as follows:

YOUR RIGHTS

HOW WE UPHOLD YOURS RIGHTS

Right to be informed

Our goal is to be as clear as possible about how we use and process your data. You will be able to easily find this Privacy Notice on various locations on our website and app. You can request a pdf. copy of this Notice by contacting us at customerservice@smashitcosmetics.com.

Right to access

You have the right to request a copy of the information that we hold on you. Please note that there are exceptions to this right. We may be unable to make all information available to you if, for example, making the information available to you would reveal personal data about another person, if we are legally prevented from disclosing such information, or if your request is manifestly unfounded or excessive.

Right to rectification

You have the right to correct data that we hold about you that is inaccurate or incomplete. You will be able to rectify/edit the information we hold about you in your Account settings.

Right to be forgotten

In certain circumstance (i.e if we do not have a legal reason to continue to store your data), you can ask for the data we hold about you to be erased from our records.

Right to restrict processing

Under certain conditions, you have the right to restrict the processing of your data.

Right to portability

You have the right to have the data we hold about you transferred to another organisation in a safe and secure way.

This right only applies to personal data that Smashit Cosmetics holds and must be held by Smashit Cosmetics by consent or for the performance of a contract, and processing is carried out by automated means.

Right to object

You have the right to object to certain types of processing such as direct marketing. You can unsubscribe from our newsletters at any time, by for instance, clicking on the unsubscribe link at the end of our newsletters.

Right to withdraw consent

If you have given Smashit Cosmetics your consent to process your data, you have the right to withdraw your consent at any time.

Right to complain to a Supervisory Authority

In the event that Smashit Cosmetics has not correctly responded to your request, you have the right to lodge a complaint to a Supervisory Authority. Smashit Cosmetics Supervisory Authority is The Swedish Data Protection Authority (DPA). You will find their contact information here: https://www.datainspektionen.se/in-english/contact-us/

You can also complain to the ICO. You will find their contact information here: https://ico.org.uk/concerns/

 

TO ACCESS WHAT PERSONAL INFORMATION IS HELD IDENTIFICATION WILL BE REQUIRED

 

Where you request access to your information, we are required to use all reasonable measures to verify your identity before doing so. These measures only exist to protect your information and to reduce risk of identity fraud, theft or unauthorized access to your information.

We therefore kindly ask you to send us original or certified copies of the following documentation: passport, identity card, birth certificate or driving licence. One of those above documents is required in order to request personal information.

We will endeavour to respond within one month. If you want to exercise one of the above rights, please contact us either via our form or using the contact details provided below in the paragraph "How to contact us".

 

HOW LONG DO WE KEEP YOUR INFORMATION?

 

We will hold your personal data for as long as you are you have an account and for as long as is necessary to comply with our legal/ regulatory obligations, resolve disputes, prevent fraud and abuse or enforce our terms and conditions.

When we no longer need to retain your personal data, it will be deleted or be anonymised so that you can no longer be identified from it.

We securely destroy all financial information once we have used it and no longer need it.

 

HOW YOUR PERSONAL INFORMATION IS SECURED?

 

Smashit Cosmetics will use all reasonable efforts to protect your personal information. We are using the latest industry standards and security measures such SSL/TLS encryption for protection of user data and personal information.

Our goal is to have all appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing and using personal data. We have safeguard processes in place in order to ensure the ongoing confidentiality, integrity, availability and resilience of our or third parties processing systems and services as well as the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.

Your data is always store in secure environments and we provide training to our Staff on data protection best practices and require them to enter into a confidentiality agreement.

You can access and edit personal information after signing into your account. To sign in, you are required to know your login credentials - email address and password. There is no way to access personal information without knowing the login credentials, therefore no unauthorized party can access it. We therefore ask you to keep your password secret and to not share it with any person (even a friend!). Please, immediately inform us if you know or suspect to have lost your login or that someone else is accessing your account.

 

LINKS TO OTHER WEBSITES OR SOCIAL MEDIA

 

Our site or newsletters may contain on occasion links to and from other websites of our partners, advertisers and affiliates. Please note that this Privacy Policy only applies to this website. If you visit any of these websites, we therefore suggest you to read their own privacy policy as we do not accept any responsibility or liabilities for these policies.

 

HOW TO CONTACT US

 

If you have any questions about this Privacy Policy and/or have any enquiry relating to your Personal Data, please contact us online via this form or send us a letter to Data Privacy, Smashit Cosmetics co. Ld Group AB, Box 2252, 55002 - Jönköping, Sweden.

 

CHANGES TO OUR PRIVACY POLICY

 

We keep our Privacy Policy under regular review. We will post any updates on this webpage. If significant changes are made, we will directly contact you by email so you can review the changes. Please check back frequently to see any updates or changes to our Privacy Notice.

 

The Privacy Policy was last updated August 18th, 2018.