Welcome to Asbury Apothecary. Asbury Apothecary and all affiliated websites are owned and operated by The Clever Ideas Lab, LLC and based in Atlanta, Georgia in the United States. The Asbury Apothecary Platform is a media platform dedicated to emerging and indie brands in home interiors, home entertaining, fashion, skincare, fragrance and design. Asbury Apothecary brings together retailers, products, manufacturers, brands and design enthusiasts to explore, discover, be entertained and enjoy.
We collect information (i) from you directly; (ii) from third parties, and (iii) automatically when you use our Site. In general, we collect information as follows:
This type of information is individually identifiable information (“Personal Information”). This information may identify an individual or may be of a private and/or sensitive nature. Personal information which is being gathered consists of any personal details provided consciously and voluntarily by you including name, email, address, IP address and other unique identifiers and any other information you choose to provide to Asbury Apothecary.
This type of information is non-identifiable and anonymous information (“Non-personal information”). We are not aware of the identity of the User from which we have collected Non-Personal Information. Non-Personal Information is any unconcealed information which is available to us while Users are using the Asbury Apothecary Platform. Non-personal Information which is being gathered consists of technical information and behavioral information, including, but not limited to, your use of the Site (including our mobile applications), such as your search activity, the pages you view, and the date and time of your visit. We also collect and may store information that your computer or mobile device provides to us in connection with your use of the Site, such as your browser type, type of computer or mobile device, browser language, IP address, mobile carrier, unique device identifier, location, and requested and referring URLs.
Data Collection for Marketing Purposes. We also use the information for marketing and advertising purposes. Where you have told us that you would like to receive marketing communications or when you have made a purchase using our services, we and our partner boutiques will use your personal information (including your name, email address and address) to occasionally send you updates, news, and offers via email, posts or other forms of media. We may use your information (including supplemental information received from partners that we append to our existing customer information as described below), to tailor these messages to you. You may unsubscribe from email marketing communications by modifying your preferences in your account’s profile management section, or by following the opt out instructions in the promotional emails we send you.
Data Collection for Statistical Purposes. We also carry out research, analysis, and surveys on your use of our Website, and views. We keep tracking of your purchase history on our Website to see if you can benefit from our exclusive loyalty programs. And finally, we use your information to confirm your identity and perform credit checks or anti-fraud checks, in order to ensure your, and our, financial security.
Selling of Data. Please note that we do not sell your information without your consent (whether your name, address, emails address, financial information, or otherwise) to any third party.
Please scroll down to find out the detailed purposes for which we collect your information, what specific information is collected and the legal basis for which we purpose that data:
The data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (“EEA”). It may also be processed and used by staff operating outside the EEA who work for us or by one of our suppliers. Such staff may be engaged in, among other things, the fulfilment of your request, the processing of your payment details and the provision of support services. By submitting your personal data, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Notice.
Data Storage.All information you provide to us is hosted and stored on Amazon Web Services cloud-based services in Ireland which is also in compliant with ISO27001 standard. For further information on the measures taken by Amazon to protect the security of their servers and your personal data, please see: http://aws.amazon.com/security/. If you are not satisfied with the levels of security offered by our cloud provider, you should restrict the nature and amount of personal data or confidential information which you include in your log data or not use the Services. Any payment transactions will be encrypted using Secure Socket Layer (SSL) technology. Where we have given you (or where you have chosen) a password which enables you to access certain parts of the Asbury Apothecary Platform, you are responsible for keeping this password confidential. You must not share a password with anyone.
To provide the Website and our services, we work with a number of carefully selected third parties. To do this, we may share your information with these third parties in the following limited circumstances. We share your Personal Information only as described in this Notice and require commercial entities with which we share your Personal Information to agree to keep your information confidential.
To provide our Website and our services, in accordance with the purposes set out above, we may transfer and store the personal information that we collect from you to a destination outside of the European Economic Area (“EEA”), mostly to the United States, either to one of our Group Companies, to one of our partner boutiques or to one of the third parties with which we work, as stated below:
Data Transfer Security.When transferring personal information to one of our Partner Companies outside the EEA, which may be the USA, India, Russia, Japan or China, we rely on the Commission’s model contracts for the transfer of personal data to third countries (i.e. the standard contractual clauses) pursuant to Decision 2010/87/EU; We transfer the personal information to one of our partner boutiques outside the EEA, to the extent such transfer is needed to fulfil the contract between you and the boutique which you are ordering the products from. When transferring personal information to one of our third-party services’ providers set out above, we rely on different adequacy measures, as set out below:
The personal data in the Asbury Apothecary account you have with us is protected by a password for your privacy and security. You need to ensure that there is no unauthorized access to your account and personal data by selecting and protecting your password appropriately and limiting access to your computer and browser by signing off after you have finished accessing your account. You are responsible for safeguarding the password that you use to access the Services and for any activities or actions under your password. Asbury Apothecary encourages you to use “strong” passwords (passwords that use a combination of upper and lowercase letters, numbers and symbols) with your account. Asbury Apothecary cannot and will not be liable for any loss or damage arising from your failure to comply with the above requirements.
Keeping Your Data Secure.Keeping you and your personal information secure is very important to us. We take a number of reasonable steps to try to protect the personal information that you provide, including:
Guarantee. Unfortunately, the transmission of information via the Internet is not completely secure. Asbury Apothecary endeavors to protect personal data but Asbury Apothecary cannot guarantee the security of your data transmitted to our Services. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our platform; any transmission of data is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access. In particular, please keep in mind that if you voluntarily disclose personal information through other means of communication than the Website in a non-protected environment (such as through email, SMS, online messages) then that information can be collected and used by others outside of our or your control.
Asbury Apothecary will take care to maintain appropriate safeguards to ensure the security, integrity and privacy of the information you have provided us with. We encrypt your information to protect it from unauthorized use. In addition, we will take reasonable steps to ensure that third party business partners to whom we transfer any data will provide sufficient protection of that personal data.
To help ensure that your shopping experience is safe, simple, and secure, we use Secure Socket Layer (SSL) technology.
Asbury Apothecary allows you to access the following information about you for the purpose of viewing, and in certain situations, updating that information: your name; user email address; username and password; profile picture; bio; website; user preferences; zip- and/or post-codes, billing address, and payment information.
The information you can access will change as the Services change. If you are a registered user of Asbury Apothecary, you can change or delete any saved payment card details and add or edit shipping and billing address information.
In the EU, the General Data Protection Regulation (the "GDPR") gives you the right to access information held about you. For any request or question regarding obtaining a copy of personal data we hold relating to you, and/or correction or deletion of your personal data, and/or object to any processing of your personal data, you can submit a Subject Access Request by contacting us at firstname.lastname@example.org/ We will respond to your access and/or correction request within 30 days.
However, please note that although your Personal Information may be removed from our databases, Asbury Apothecary will retain the anonymous information contained in the data you provided, and such information will continue to be used by us for statistical purpose.
As set out above, you can always opt not to disclose information, even though it may be needed to take advantage of the Services.
You are able to add or update certain information on pages, such as those listed above. When you update information, however, we often maintain a copy of the unrevised information in our records.
Once Asbury Apothecary accounts are activated, you may request deletion of your account by following the instructions at the Account Settings section of the Asbury Apothecary Platform. Please note that some information may remain in our records after deletion of your account.
Controlling Asbury Apothecary Communications.When you join the Asbury Apothecary Platform by signing up for an account or creating a profile, as part of the service you will receive the Asbury Apothecary newsletter about the offerings and features on the Site. As permitted by law, you are also opting to receive other emails from us that may be of interest to you as a member of the Asbury Apothecary community. You can manage your email and notice preferences in account settings, but note that you cannot opt out of receiving certain administrative or legal notices from us. If you opt-out of receiving emails about recommendations or other information we think may interest you, we may still send you transactional e-mails about your account or any services you have requested or received from us. However, you may opt out entirely of receiving any text messages – promotional, transactional or otherwise – from us. You can however change the type and frequency of the emails you receive from us at any time by changing your email settings here or by unsubscribing from such emails.
Disabling Location Services.Most mobile devices provide users with the ability to disable location services. These controls are usually located in the device's settings menu. Please contact your mobile service carrier or device manufacturer if you have questions about how to disable your device's location services.
Please note that if you choose not to receive legal notices from us, such as this Notice, those legal notices will still govern your use of the Services, and you are responsible for reviewing such legal notices for changes.
Protecting Yourself.Additionally, by joining, you are agreeing to receive feedback and communications from third-parties within the Site, including third-party providers of products or services who may comment on your postings within the Site. If you don’t want third parties to see such information, you should not post it to your profile or the Site.
You may opt-out of tracking by third parties for certain advertising purposes (as discussed) which can help you control targeted advertising by third-parties that track your activities across sites. It may be possible to disable certain Cookies through your device or browser settings. The method for disabling cookies may vary by device and browser but can usually be found in preferences or security settings. However, doing so may affect your ability to use the Site. If you are not comfortable with the above uses of Cookies, please do not use this Site.
Do-Not-Track Signals.Please note we do not change system behavior within the Site in response to browser requests not to be tracked. You may, however, disable certain tracking as discussed in this section (e.g., by disabling cookies or opting out of ad networks).
As noted, we work with third parties such as network advertisers to serve advertisements on third-party websites or other media, and to evaluate the success of our advertising campaigns, including Facebook, Google, and others (both Facebook and Google offer additional ways to opt out of certain advertising activities, and maintain their own privacy policies that address their interest-based advertising services). We also may work with third parties to display ads on our Site.
You can also manage many opt-out of receiving behaviorally-targeted ads from many companies via the consumer choice tools created under self-regulation programs in many countries, such as the US-based aboutads.info choices page or the EU-based
Opting out from one or more companies listed on the respective opt out pages noted above, will opt you out from those companies’ delivery of interest-based content or ads to you based upon your activities on multiple websites, but it does not mean you will no longer receive any advertising through our Site or on other websites. You may continue to receive advertisements, for example, based on the particular website that you are viewing (i.e., contextually based ads). Also, if your browsers are configured to reject cookies, or you subsequently delete your cookies, your opt out may not be effective. Additional information is available on the websites listed above.
We retain the data you provide to us for as long as you have your account with us and thereafter for such period as you may have questions or a claim in relation to our services, notwithstanding any superior retention period that we may be obliged to observe in accordance with legal requirements applicable to us.
In some circumstances you can ask us to delete your data as set out below.
After you have terminated your use of our services, we may store your information in an aggregated and anonymized format.
After a request from a User to delete any data, an automated process will begin that permanently deletes the relevant data. Once begun, this process cannot be reversed and data will be permanently deleted. Any data which is not deleted shall be kept in an anonymized manner.
As a registered User you can always view, access, change and delete your information by logging into your account.
Similarly, Asbury Apothecary collects and retains usage data, other metadata and statistical information concerning the use of the Service are not subject to the deletion procedures in this Notice and may be retained by Asbury Apothecary. Some data may be retained also on our third-party service providers’ servers.
The Site is intended for general audiences and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information without parental consent, please contact us at email@example.com, and we will take steps to remove such information and terminate the child's account.
You have certain rights in relation to the personal data we hold about you, which we detail below. Some of these only apply in certain circumstances as set out in more detail below. We also set out how to exercise those rights. Please note that we will require you to verify your identity before responding to any requests to exercise your rights and that can include asking a set of security questions to ensure it is you. When you have appointed someone else to do the request on your behalf, that person and/or organization needs to show a valid power of attorney issued by you. We must respond to a request by you to exercise those rights without undue delay and at least within one month (although this may be extended by a further two months in certain circumstances). To exercise any of your rights, please contact us at firstname.lastname@example.org or by writing to:
Data Protection Officer, at Asbury Apothecary, 859 Spring St. NW, Atlanta GA, 30308.
Access.You have the right to know whether we process personal data about you, and if we do, to access data we hold about you and certain information about how we use it and who we share it with (including the categories of personal data we share with businesses for their direct marketing uses and the names and addresses of those businesses). Please note that in “My Account” dashboards, you can see information about you, namely your account details (such as name, email, phone number, date of birth), the addresses you use for billing and shipping, your order history and shopping preferences.
Requesting Your Information.You can also request a copy of your information. If you require more than one copy of the data we hold about you, we may charge a reasonable administration fee. We may not provide you with certain personal data if providing it would interfere with another’s rights (e.g. where providing the personal data we hold about you would reveal information about another person) or where another exemption applies.
Portability. You have the right to receive a subset of the personal data we collect from you in a structured, commonly used and machine-readable format and a right to request that we transfer such personal data to another party. The relevant subset of personal data is data that you provide us with your consent or for the purposes of performing our contract with you.
If you wish for us to transfer the personal data to another party, please ensure you detail that party and note that we can only do so where it is technically feasible. We are not responsible for the security of the personal data or its processing once received by the third party. We also may not provide you with certain data if providing it would interfere with another’s rights (e.g. where providing the personal data we hold about you would reveal information about another person or our trade secrets or intellectual property).
Correction.You have the right to correct any personal data held about you that is inaccurate. You can edit your personal information in “My Account” settings. You can also request the correction by emailing us. Please note that in some cases we can ask you to explain in detail why you believe the personal data we hold about you to be inaccurate or incomplete so that we can assess whether a correction is required. Please note that whilst we assess whether the personal data we hold about you is inaccurate or incomplete, you may exercise your right to restrict our processing of the applicable data as described below.
Erasure. You may request that we erase the personal data we hold about you in the certain circumstances. Please scroll below to know what those are:
Also note that you may exercise your right to restrict our processing the data whilst we consider your request as described below.
Please provide as much detail as possible on your reasons for the request to assist us in determining whether you have a valid basis for erasure. Please note, however, that we may retain the personal data if there are valid grounds under law for us to do so (e.g., for the defense of legal claims or freedom of expression) but we will let you know if that is the case.
Where you have requested that we erase data that we have made public and there are grounds for erasure, we will use reasonable steps try to tell others that are displaying the data or providing links to the data to erase the data too.
Restriction of Processing to Storage Only.You have a right to require us to stop processing the personal data we hold about you other than for storage purposes in certain circumstances. Please note, however, that if we stop processing the personal data, we may use it again if there are valid grounds under data protection law for us to do so (e.g. for the defense of legal claims or for another’s protection).
Please scroll below to know the cases where you may request we stop processing and just store the personal data we hold about you.
You also have the right to object to our processing of data about you and we will consider your request in other circumstances as detailed below:
Withdrawal of Consent.You can withdraw your consent at any time by changing your marketing preferences in “My Account” or by unsubscribing at the bottom of each email received or by writing emailing us as set out below.
Last updated May 30, 2018