- Visit our website
at hellotushy.com
- Engage with us in other related ways, including any sales, marketing, or events
SUMMARY OF KEY POINTS
TABLE OF CONTENTS
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.-
names
-
phone numbers
-
email addresses
-
mailing addresses
-
usernames
-
passwords
-
contact preferences
-
contact or authentication data
-
billing addresses
-
debit/credit card numbers
All payment data is handled and stored by Shopify, Apple Pay, PayPayl, Google Payments, Venmo, Afterpay, Cash App and Truemed. You may find their privacy notice link(s) here: https://www.shopify.com/legal/privacy, https://www.apple.com/legal/privacy/data/en/apple-pay/, https://www.paypal.com/us/legalhub/paypal/privacy-full, https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt=privacynotice&ldl=en-GB, https://venmo.com/legal/us-privacy-policy/, https://help.afterpay.com/hc/en-us/articles/4406413632921-Privacy-at-Afterpay, https://cash.app/legal/us/en-us/privacy and https://www.truemed.com/legal/privacy.
Information automatically collected
In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.- Log and Usage Data. Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type, and settings and information about your activity in the Services (such as the date/time stamps associated with your usage, pages and files viewed, searches, and other actions you take such as which features you use), device event information (such as system activity, error reports (sometimes called
"crash dumps" ), and hardware settings).
- Device Data. We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services. Depending on the device used, this device data may include information such as your IP address (or proxy server), device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information.
- Location Data. We collect location data such as information about your device's location, which can be either precise or imprecise. How much information we collect depends on the type and settings of the device you use to access the Services. For example, we may use GPS and other technologies to collect geolocation data that tells us your current location (based on your IP address). You can opt out of allowing us to collect this information either by refusing access to the information or by disabling your Location setting on your device. However, if you choose to opt out, you may not be able to use certain aspects of the Services.
Information collected from other sources
In Short: We may collect limited data from public databases, marketing partners,2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.- To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order.
- To request feedback. We may process your information when necessary to request feedback and to contact you about your use of our Services.
-
To send you marketing and promotional communications. We may process the personal information you send to us for our marketing purposes, if this is in accordance with your marketing preferences. You can opt out of our marketing emails at any time. For more information, see
" WHAT ARE YOUR PRIVACY RIGHTS? " below.
- To deliver targeted advertising to you. We may process your information to develop and display
personalized content and advertising tailored to your interests, location, and more. For more information see our Cookie Notice: hellotushy.com/pages/cookie-policy .
-
To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
-
To identify usage trends. We may process information about how you use our Services to better understand how they are being used so we can improve them.
- To determine the effectiveness of our marketing and promotional campaigns. We may process your information to better understand how to provide marketing and promotional campaigns that are most relevant to you.
-
To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e.-
Consent. We may process your information if you have given us permission (i.e.
, consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
- Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
- Send users information about special offers and discounts on our products and services
- Develop and display
personalized and relevant advertising content for our users
Analyze how our Services are used so we can improve them to engage and retain users
- Support our marketing activities
- Diagnose problems and/or prevent fraudulent activities
- Understand how our users use our products and services so we can improve user experience
- Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
-
Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
- If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
- For investigations and fraud detection and prevention
-
For business transactions provided certain conditions are met
-
If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim
-
For identifying injured, ill, or deceased persons and communicating with next of kin
- If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse
- If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province
- If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
- If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced
- If the collection is solely for journalistic, artistic, or literary purposes
- If the information is publicly available and is specified by the regulations
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
Google Analytics
We may share your information with Google Analytics to track and analyze the use of the Services. The Google Analytics Advertising Features that we may use include: . To opt out of being tracked by Google Analytics across the Services, visit https://tools.google.com/dlpage/gaoptout. You can opt out of Google Analytics Advertising Features through Ads Settings and Ad Settings for mobile apps. Other opt out means include http://optout.networkadvertising.org/ and http://www.networkadvertising.org/mobile-choice. For more information on the privacy practices of Google, please visit the Google Privacy & Terms page.6. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.7. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through a system of organizational and technical security measures.8. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to children under 18 years of age.9. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: Depending on your state of residence in the US or in some regions, such as the European Economic Area (EEA), United Kingdom (UK), Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time, depending on your country, province, or state of residence.Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:-
Contact us using the contact information provided.
-
Log in to your account settings and update your user account.
10. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.11. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. More information is provided below.Categories of Personal Information We Collect
We have collected the following categories of personal information in the past twelve (12) months:Category | Examples | Collected |
A. Identifiers
|
Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name
|
|
B. Personal information as defined in the California Customer Records statute
|
Name, contact information, education, employment, employment history, and financial information
|
|
-
-
Category A - As long as the user has an account with us
-
Category B - As long as the user has an account with us
-
Category C - As long as the user has an account with us
-
Category D - As long as the user has an account with us
-
Category F - As long as the user has an account with us
-
Category G - As long as the user has an account with us
-
Category H - As long as the user has an account with us
-
Sources of Personal Information
Learn more about the sources of personal information we collect in "WHAT INFORMATION DO WE COLLECT?"How We Use and Share Personal Information
Learn more about how we use your personal information in the section, "HOW DO WE PROCESS YOUR INFORMATION?"
- Category B. Personal information as defined in the California Customer Records law
Your Rights
You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:- Right to opt out of the processing of your personal data if it is used for targeted advertising (or sharing as defined under California’s privacy law), the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
- Right to access the categories of personal data being processed (as permitted by applicable law, including Minnesota’s privacy law)
- Right to obtain a list of the categories of third parties to which we have disclosed personal data (as permitted by applicable law, including California's and Delaware's privacy law)
- Right to obtain a list of specific third parties to which we have disclosed personal data (as permitted by applicable law, including Minnesota's and Oregon's privacy law)
- Right to review, understand, question, and correct how personal data has been profiled (as permitted by applicable law, including Minnesota’s privacy law)
- Right to limit use and disclosure of sensitive personal data (as permitted by applicable law, including California’s privacy law)
- Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including Florida’s privacy law)
How to Exercise Your Rights
To exercise these rights, you can contact us by submitting a data subject access request, by emailing us at , or by referring to the contact details at the bottom of this document.Request Verification
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes.Appeals
Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us at . We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may submit a complaint to your state attorney general.California "Shine The Light" Law
California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us by using the contact details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?"12. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: You may have additional rights based on the country you reside in.Republic of South Africa
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us by using the contact details provided in the section "HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?"13. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.14. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may email us at privacy@hellotushy.com or contact us by post at:
15. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, please fill out and submit a data subject access request.16. SMS/MMS MOBILE MESSAGING MARKETING PROGRAM
16. Mobile Messaging Privacy Policy
This Mobile Messaging Privacy Policy (“Messaging Policy”) explains how TUSHY (“we,” “us,” or “our”) collects, uses, and shares personal information in connection with our mobile messaging program (the “Program”). This Messaging Policy supplements our Privacy Policy. By participating in our Program, you agree to the terms set forth herein. In the event of any conflict, our Privacy Policy shall control.
16.1. Changes to the Policy
We reserve the right to modify this Messaging Policy at any time in our sole discretion. If we make any material changes, we will notify you as required by applicable law. Your continued participation in the Program following the effective date of any changes constitutes your acceptance of the updated Messaging Policy.
16.2. Personal Information We Collect
When you sign up for our Program, we collect personal information such as your name, phone number, and email address. In addition, when you use the Service to send or receive messages, we collect communications metadata (for example, the date and time a message is sent or received) and, in some cases, the content of those messages. We may also collect information using cookies or similar technologies on our website or digital platforms to enhance your experience.
16.3. Use of Personal Information
We will use the information you provide solely for the purposes of transmitting mobile messages and responding to your inquiries. This may include:
-
Delivering transactional messages (such as order updates or account alerts);
-
sending promotional communications and marketing offers, where applicable; and
-
analyzing and improving the Program.
We may also use your information to generate aggregated or de-identified data for internal analytics. Such data is not considered personal information and may be shared with third parties.
16.4. Sharing of Personal Information
We may share your personal information with trusted third parties that help us provide the Program (for example, platform providers and wireless carriers). In addition, we may disclose your information if required by law, regulation, or a governmental request, or if necessary to protect our rights or property, or to avoid liability.
16.5. Our Commitment to Your Privacy
We respect your privacy. We will use the information you provide solely to operate the Program and respond to your communications. WE DO NOT SELL, RENT, LOAN, TRADE, LEASE, OR OTHERWISE TRANSFER FOR PROFIT ANY PHONE NUMBERS OR CUSTOMER INFORMATION COLLECTED THROUGH THE PROGRAM TO ANY THIRD PARTY.
16.6. Accurate Information
When you provide us with information—whether through online forms or other means—you agree to provide accurate, complete, and truthful information. You further agree not to use a false or misleading name or any name for which you are not authorized. If, in our sole discretion, we determine that any information is inaccurate or incomplete, or that you have opted into the Program for an ulterior purpose, we may refuse you access to the Program and pursue any appropriate legal remedies.
16.7. Choices and Controls
Participation in our Program is voluntary. Consent to receive automated mobile messages is not a condition of any purchase. You may opt out of receiving further messages by replying with STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to any message from us. After opting out, you will receive a one-time confirmation message, and no further messages will be sent unless you opt in again. If you participate in multiple messaging programs, you may need to opt out of each separately.
16.8. Customer Care
If you experience any issues or have questions regarding the Program, please contact our support team by texting HELP or emailing hello@hellotushy.com.
16.9. Supplemental California Privacy Notice
For California residents, this Policy is supplemented by additional rights under the California Consumer Privacy Act of 2018 (“CCPA”). Under the CCPA, California residents have the right to request information regarding our disclosure of their personal information to third parties for direct marketing purposes. To make such a request, please contact us at:
TUSHY Inc.
20 Jay St, Brooklyn, NY 11201
Email: hello@hellotushy.com
16.10. Relationship to Primary Privacy Policy
This Mobile Messaging Program Privacy Policy is strictly limited to our Program and does not affect any other privacy policy that governs your relationship with us in other contexts. By signing up for our Program, you also agree to our Privacy Policy.
By opting into or participating in TUSHY’s SMS/MMS Mobile Messaging Program, you acknowledge that you have read, understood, and agree to be bound by these Terms and Conditions, including the detailed Dispute Resolution provisions.