YOUR PRIVACY: OVERVIEW
Collection of Personal Data
We collect personal data from you in connection with your access to and use of our websites, your in-store or online purchases of our products or services, or if you provide us with personal data through other channels or media, such as social media or an event registration service.In particular, we collect personal data directly from you in connection with the following activities:
Registering for an account or filling in forms on our websites or in our stores (this includes information you provide when you request additional information, in writing or verbally, about our products or services or sign up to receive our e-mail newsletters, marketing messages or coupons);
Completing a profile or uploading goals to our websites;
Interacting with us on social media, such as by tagging us and/or our products, or permitting us to follow your social media profile;
Purchasing any product or service from us;Providing design or product feedback or making other submissions to us;
Requesting information or assistance from us, including correspondence with our customer service team and through social media;
Participating in or responding to surveys or requests for opinions, feedback and preferences regarding our products and services;
Participating in or registering for events, consumer contests, sweepstakes and other promotions;
Using other features of our websites that may be offered from time to time, which may require such information in order to utilise the feature.
We collect the following types of personal data in connection with the activities described above: your name, username, password, e-mail address, address, telephone number, credit card and debit card numbers (with expiration dates), personal preferences, goals, and any other personal data that you choose to include in your profile or in other communications with us.
You may have the option to link your social media account to our social media account (such as on Facebook). If you do link your social media account to our social media account, the social media service may share certain data about you and your activities with us in accordance with their privacy policies and your privacy settings on their services. If we receive data about you in this manner, we combine that data with the personal data we collect directly from you.
Use of Your Personal Data
In general, we use your personal data to respond your requests, conduct your requested transactions, maintain and customize your account and our interactions with you and provide, maintain and improve our products and services. The specific purposes for which we process your personal data are set out below:
To administer your online account and profile (the legal basis for this processing is our legitimate interest in better understanding user needs and expectations and improving our website);
To provide products and services to you, which includes processing payments, sending notifications related to your purchases, and processing exchanges and returns (the legal basis for this processing is the performance of the purchase agreement between you and lululemon);
To conduct or administer events, contests, prize draws, sweepstakes or other promotions in which you have participated (the legal basis for this processing is the performance of the agreement between you and lululemon related to such contest, prize draw, sweepstakes or other promotion);
To respond to any communications from you, including to troubleshoot problems with our websites (the legal basis for this processing is our legitimate interest in providing you with a functional website);
To analyse your use of and customise your experience on our websites (the legal basis for this processing is our legitimate interest in better understanding user needs and expectations and improving our websites);
To develop and manage lululemon's business and operations (the legal basis for this processing is our legitimate interest in understanding shopping behaviour, improving our selection of products and services, and exploring ways to develop and enhance our business);
To measure your social media engagement with our brand (the legal basis for this processing is our legitimate interest in understanding the efficacy of our marketing strategies);
To detect, investigate and prevent fraudulent transactions, error, negligence, breach of contract, and other illegal activities and protect against harm to the rights, property or safety of lululemon and our users, customers, employees or the public, including by using video surveillance systems (the legal basis for this processing is our legitimate interest in preventing fraud, error, negligence, contractual breach and other illegal activities and protecting and securing our premises,customers, employees and the public);
To comply with our legal obligations, including our tax obligations, those related to the prevention of fraud and money laundering, and those required for you to benefit from rights recognized by law, or any regulatory requirements or provisions (the legal basis for this processing is compliance with our legal obligations under laws in the EEA and Switzerland related to, for instance, taxation, money-laundering and terrorism financing and consumer protection law);
To offer you opportunities to purchase products or services that we believe may be of interest to you, by supplementing the information we collect about you with information from third parties (the legal basis for this processing is our legitimate interest in providing information about products and services that may be of interest to you, unless applicable law requires us to obtain your consent, in which case we will do so).
DISCLOSURE OF PERSONAL DATA
We do not share personal data about you with third parties except as follows:
a.Our affiliates and subsidiaries. We disclose your personal data to our holding company, subsidiaries and affiliates, including lululemon athletica inc.lululemon usa inc. and lululemon athletica canada inc., for the purposes described in the “Use of Your Personal Data” section ABOVE. Since our holding company, subsidiaries and affiliates are located around the world, please note that these disclosures involve cross-border transfers of your personal data as described in the “Data Transfers” section BELOW.
b. Our Service Providers. We share personal data with third parties that perform services for us, including customer support, web hosting, information technology, payment processing, product fulfilment, fraud control, direct mail and email distribution, contest, event, sweepstakes and promotion administration, and analytics services. We only share with service providers the personal data that they need to perform services for us. Since our service providers are located around the world, please note that these disclosures involve cross-border transfers of your personal data as described in the “Data Transfers” section BELOW.
c. Corporate Transactions. Personal data may be disclosed or transferred as part of, or during negotiations of any purchase, sale, lease, merger, amalgamation or any other type of acquisition, disposal, securitisation or financing involving lululemon.
d. Professional Advisors. We share personal data with our legal, financial, insurance and other advisors in connection with the kinds of corporate transactions described above or in connection with the management of all or part of lululemon’s business or operations.
e. Compliance with Law. We disclose personal data when we believe doing so is reasonably necessary to comply with applicable law or legal process (including requests from authorities), to respond to claims (including inquiries by you in connection with your purchases from lululemon), or to protect the rights, property or personal safety of lululemon, our users, employees or the public.
f. Consent. We share personal data with third parties when we have your consent to do so. For example, if you decide to participate in certain interactive areas or features of our websites, such as creating a public profile and posting your goals, you consent to the disclosure of this information to other users of our websites.
Our third party partners currently include:
Facebook: Joint Controller: https://www.facebook.com/about/privacy
Rakuten: Independent Controller: https://go.rakutenadvertising.com/hubfs/Website-Privacy-Policy-English.pdf
Teads: Joint Controller: https://www.teads.com/privacy-policy/
Criteo: Joint Controller: https://www.criteo.com/privacy/
We have physical, technical and administrative measures in place to help protect personal data from loss, unauthorised access or processing, modification, disclosure, damage, alteration, destruction or other misuse. Unfortunately, the transmission of information via the internet is not completely secure or private. You understand that any messages or information you send to our websites may be read or intercepted by others. If you have any questions about the security of personal data collected by lululemon contact us HERE.
We ensure, with the signature of Standard Contractual Clauses adopted by the European Commission, that personal data transferred outside the UK, EEA and Switzerland is maintained with at least the same level of security and protection for personal data that is required under applicable law. Copies of the Standard Contractual Clauses we use to facilitate this transfer of data are available HERE and HERE. Transfers to Canada are made pursuant to European Commission decision 2002/2/EC of 20 December 2001 and recognized by the UK government.
Retention of Your Personal Data
We retain personal data only for as long as necessary to achieve the purpose for which such personal data was collected, unless a different retention period is required under applicable law. We also retain personal data for as long as you have your account, or as long as is needed to be able to provide the services or products to you, or (in the case of any contact you may have with our Guest Education Centre) for as long as is necessary to provide support-related reporting and trend analysis. If reasonably necessary or required to meet legal or regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions, lululemon may also keep personal data as required, after an account is closed or is no longer necessary to provide services. Unless otherwise required by applicable law, lululemon will take reasonable steps to destroy or permanently de-identify personal data it holds if such personal data is no longer needed for the purpose for which it was collected.
Third Party Sites
Please note that our websites contain links to third-party websites that are not controlled or operated by lululemon. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that lululemon does not accept any responsibility or liability for these policies.Please review these policies before you disclose any personal data when visiting such third-party websites.
YOUR PERSONAL DATA RIGHTS
Subject to certain limitations and exceptions, you have the following legal rights regarding our processing of your personal data:
A right to obtain information:You have the right to request information about how we process your personal data.
A right of access:You have the right to request access to, or a copy of, the personal data we process about you.
A right of rectification: You have the right to request that we correct or supplement inaccurate or incomplete personal data we process about you.
A right of erasure: You have the right to request that we delete personal data about you.
A right to restriction of processing: You have the right to request that we restrict processing of your personal data, so that we can store such data but not otherwise process it.
A right to data portability: In certain circumstances, you have the right to request that we provide the personal data which you provided to us in a structured, commonly used and machine-readable format, and you have the right to transmit such data to another controller without hindrance from lululemon.
A right to object to processing:You have the right to request that we stop processing personal data about you. For example, when your personal data is processed for email marketing purposes, you have the right to object to such processing at any time by clicking on the “unsubscribe” link at the bottom of such marketing communications.
A right to revoke your consent: When our processing is based on your consent, you have the right to revoke such consent at any time.
The right to file a complaint:You have the right to file a complaint regarding our data protection practices with a supervisory authority. You can do so by contacting your country’s supervisory authority.
If you would like to exercise any of these rights or if you have any questions or enquiries relating to our privacy practices or procedures, you may write to the Privacy Officer at the addresses provided below.
Questions or Comments