Scentsy’s General Data Protection Regulation Policy
Updated 21 May 2018
I. Collection and use of personal information
Scentsy, Inc. (“Scentsy”) may collect personal information from you. Personal information is any data relating to an identifiable person who can, by virtue of such information, be directly or indirectly identified. You may be asked to provide your personal information anytime you are in contact with Scentsy or a Scentsy-affiliated company. Scentsy and its affiliates may share this personal information with each other and use it as consistent with its General Data Protection Regulation (GDPR) Policy. They may also combine it with other information to provide and improve our products, services, content and advertising. You are not required to provide the personal information that we request, but, if you chose not to, we may not be able to provide you with our products or services, or respond to queries you may have.
II. What personal information we collect
When you create a Scentsy Consultant account, purchase a product or contact Scentsy, we collect a variety of information, including your name, mailing address, phone number, email address and contact preferences. When you make a purchase, we also collect payment information from you.
If you are a Scentsy Independent Consultant and acquire information regarding your customers and then upload that information to Scentsy, Scentsy will store whatever personal information regarding your customers that you have uploaded on Scentsy servers. If you are a customer and submit your personal information on a Scentsy website, Scentsy will store whatever personal information you submitted on Scentsy servers.
III. How we use your personal information
The personal information we collect allows us to keep you informed of Scentsy product announcements, software updates, upcoming events and more. If you don’t want to be on our mailing list, you can opt out anytime by navigating to the unsubscribe link in the last email you received from Scentsy. You will have the option to unsubscribe from an individual list or from all Scentsy lists.
We also use personal information to help us create, develop, operate, deliver and improve our products, services, content and advertising, and for loss prevention and anti-fraud purposes.
We may use your personal information, including date of birth, to verify identity, assist with identification of users and to determine appropriate services. For example, we may use date of birth to determine the age of Scentsy Consultants or customers.
If you are a Consultant, we may use your personal information to send important notices, such as communications about purchases and changes to our terms, conditions and policies. Because this information is important to your interaction with Scentsy, you may not opt out of receiving these communications.
We may also use personal information for internal purposes such as auditing, data analysis and research to improve Scentsy’s products, services and customer communications.
IV. Collection and use of non-personal information
We also collect data in a form that does not identify any specific individual. We may collect, use, transfer and disclose non-personal information for any purpose. Here are some examples of non-personal information that we collect and how we may use it:
We may collect information such as language preference, ZIP code, area code, unique device identifier, referrer URL and the time zone where a Scentsy product is used so we can better understand customer behaviour and improve our products, services and advertising.
We may collect non-personal information regarding customer activities on any of our websites. This information is aggregated and used to help us provide more useful information to our customers and to understand which parts of our website, products and services are of most interest.
We may collect and store details of how you use our services. This information may be used to improve the relevancy of results provided by our services.
V. Cookies and other technologies
We gather some information automatically and store it in log files. This information includes Internet Protocol (IP) addresses, browser type and language, internet service provider (ISP), referring and exit websites and applications, operating system, date/time stamp and clickstream data. We use this information to administer the site, to learn about user behaviour on the site, to improve our product and services, and to gather demographic information about our user base as a whole. Scentsy also may use this information in our marketing and advertising services.
In some cases, we use a “click-through URL” linked to content on the Scentsy website. When customers click one of these URLs, they pass through a separate web server before arriving at the destination page on our website. We track this click-through data to help us determine interest in particular topics and measure the effectiveness of our marketing communications.
VI. Disclosure to third parties
At times, Scentsy may make certain personal information available to strategic partners that work with Scentsy to provide products and services, or that help Scentsy market to customers. Personal information will be shared by Scentsy only to provide or improve our products, services and advertising; it will not be shared with third parties for their marketing purposes.
Upline and Downline Consultants. If you are a Scentsy Consultant, Scentsy will provide your name, email address, phone number and mailing address to Consultants on your team and group so that you can receive the benefits of team and group training and fun events, and so you can provide support to your team and group.
Service providers. Scentsy shares personal information with companies who provide services such as information processing, fulfilling customer orders, delivering products to you, managing and enhancing customer data, providing customer service and assessing your interest in our products and services. Scentsy also shares your information with financial institutions who provide payment services for Consultants and customers. These companies are obligated to protect your information and may be located wherever Scentsy operates.
Legal. It may be necessary — by law, litigation or requests from government authorities within or outside your country of residence − for Scentsy to disclose your personal information. We may also disclose information about you if we determine that for purposes of national security, law enforcement or other issues of public importance, disclosure is necessary or appropriate. We may also disclose information about you if we determine that disclosure is reasonably necessary to enforce our terms and conditions or protect our operations or users.
Corporate change. Additionally, in the event of a reorganisation, merger or sale of Scentsy we may transfer any and all personal information we collect to the relevant third party.
VII. Protection of personal information
Scentsy takes the security of your personal information very seriously. When your personal data is stored by Scentsy, we use computer systems with limited access housed in facilities using physical security measures. When you use some Scentsy products and services that by their nature are public facing, such as when you post on a social media forum (including, for example, a Scentsy Facebook group), the personal information and content you share is visible to other users and can be read, collected or used by them. You are responsible for the personal information you choose to share or submit in these instances. For example, if you list your name and email address in a forum posting, that information is public. Please take care when using these features.
VIII. Retention of personal information
If you are a Scentsy Consultant, Scentsy will retain your personal information for as long as you have a Scentsy account. After your Scentsy account is terminated, or if you are a Scentsy customer (not a Consultant), we will retain your personal information for as long as necessary to fulfill the purposes outlined in this GDPR Policy, unless a longer retention period is required or permitted by law.
IX. Access to personal information
As a Consultant, you can help ensure that your contact information and preferences are accurate, complete and up to date by going to the Account tab of your Workstation.
For other personal information we hold, we will provide you with access (including a copy) upon your request. We may decline to process requests that are frivolous, vexatious, jeopardise the privacy of others, are extremely impractical or for which access is not otherwise required by local law. To access, correct or delete information, please email firstname.lastname@example.org.
X. Children and education
We understand the importance of taking extra precautions to protect the privacy and safety of children using Scentsy products and services. Children under the age of 18 are not permitted to create their own Scentsy IDs; instead, a parent must obtain the account and provide the parent’s information to Scentsy. If we learn that we have collected the personal information of a child under 18 we will delete the information as soon as possible.
XI. Third-party sites and service
Scentsy websites, products, applications and services may contain links to third-party websites, products and services. Our products and services may also use or offer products or services from third parties. Information collected by third parties is governed by their privacy practices. We encourage you to learn about the privacy practices of those third parties.
XII. Your rights under the GDPR
If you are a citizen or a resident of a country in the European Union, the GDPR grants you the following rights:
Access to your personal data. You have the right to receive a copy of your personal data that is subject to processing by Scentsy. Ordinary requests will be granted without charge to you within one calendar month of when you make the request. In cases of excessive, unreasonable or repeated requests, Scentsy may charge you a reasonable fee and may require additional time to grant your request. Also, Scentsy may use reasonable means to confirm your identity before granting any request for data to prevent granting fraudulent requests. To request a copy of your personal data, please email email@example.com
To have your data corrected. If your personal data is erroneous or outdated, you have the right to have it corrected. To do so, please email firstname.lastname@example.org, or, if you are a Consultant, you may update your information on the Account tab of your Workstation.
To have your data forgotten. You have the right to have your data forgotten by Scentsy. To exercise this right, please email email@example.com. We will comply with your request, at no charge to you, within one calendar month by deleting your account, along with all of your data that is subject to any Scentsy processing. Naturally, after we grant your request, you will not have access to any Scentsy products or services unless and until you open a new Scentsy account. Scentsy may use reasonable means to confirm your identity before granting any request for data to prevent the granting of fraudulent requests.
To restrict processing of your data. You may request that your data not be processed via Scentsy partners. To make that request, please email firstname.lastname@example.org. You can even specify which third parties to restrict from processing your data. We will respond to your request, at no charge to you, within 30 days from when you make your request. Please be advised that some of our partners are essential to Scentsy services, so if you block processing by them, Scentsy’s services may be unavailable to you.
Portability. You have the right to receive a copy of your personal data that is subject to processing by Scentsy in a portable format, or to have it transferred directly from Scentsy to another party. Ordinary requests will be granted without charge to you within one calendar month of when you make the request. Scentsy may use reasonable means to confirm your identity before granting any request to transfer data to you or another party to prevent granting fraudulent requests. To request a copy of your personal data in a portable format, or to request a direct transfer of your data, please email email@example.com.
Your responsibility under GDPR: If you are a Scentsy Consultant, you are a business owner selling Scentsy goods to your customers. With respect to the customer data that you provide to Scentsy, Scentsy is a data processor and will comply with its obligations under the GDPR; but with respect to your customers, you are probably a data controller, and if any of your customers are citizens or residents of a country in the European Union, then you must ensure that you comply with your obligations as a data controller under the GDPR; namely, that if you retain any customer information in any place other than on Scentsy servers, you must ensure that you afford your customers the rights identified in the GDPR Policy. The simplest way for you to comply with the GDPR is to store all customer data with Scentsy, via your Workstation, but if you choose to store customer data elsewhere, please consultant legal counsel of your own choosing for advice on what you need to do to comply with GDPR.
XIII. Our companywide commitment to your privacy.
To make sure your personal information is secure, we communicate our privacy and security guidelines to Scentsy employees and strictly enforce privacy safeguards within the company.
XIV. Privacy questions.
If you have any questions or concerns about Scentsy’s GDPR Policy or data processing or if you would like to make a complaint about a possible breach of local privacy laws, please email firstname.lastname@example.org. When a privacy question or an access or download request is received, our dedicated team will address your specific concern or query. To respond to your request, we may need more information from you. If you are unsatisfied with the response you receive, you may refer your complaint to the relevant regulator in your jurisdiction. If you ask us, we will endeavor to provide you with information about relevant complaint avenues that may be applicable to your circumstances. If you live in the European Economic Area and you wish to contact us regarding questions or to exercise your statutory rights, please contact our EU representative:
Scentsy UK, PTY LTD
11th Floor, Two Snowhill
Birmingham, West Midlands
England B4 6WR
UK 080 0917 6204