Table of Contents
- How We Collect Information
- What Information We Collect
- How We Use Information
- How We Disclose Information
- International Transfers
- Security of Your Information
- Data Retention
- Your Privacy Rights
- Privacy of Children
- Your Marketing Choices
- Third Party Links
- Questions and Complaints
- Cookies Policy
- Changes to this Policy
- Schedule 1: California Residents
Quay Eyeware Inc. is a sunglasses retailer with worldwide operations. This policy (the “Policy”) sets out how Quay (“Quay,” “We,” “Us,” or “Our”), processes personal information about you both online, when you visit our sites, or when you engaged with us in person, like when you visit our retail locations (collectively, the “Services”).
How We Collect Information
- From you.We may collect personal information and other information that you provide when you use our Services, visit our retail locations, and any other data that you may choose to provide. With your permission, we may also collect data from another source like your vision care provider or social media account.
- From public or third-party sources.We may collect data from public sources including, but not limited to, social media and other websites that enable social sharing. Personal information may also be available from government agencies, public or third-party information sources, third party service providers, or business partners. We also may collect information from industry groups and associations, or combine information we have collected from multiple sources.
- Automatically when you engage with us online. Quay collects data through our websites and apps and automatically from devices you use to connect to our services.
- Referrals. We may collect your information through our referral program. If you choose to submit any personal information relating to other people, you represent that you have the authority to do so and permit us to use the information in accordance with this Policy.
What Information We Collect
We may collect different types personal information when you interact with our services or purchase or products, including:
- Contact information, such as your name, telephone or mobile phone number, email address, and postal and billing addresses;
- Biographical and demographic information, such as your date of birth, age, and gender;
- Account information, such as username and password, profile details you choose to provide, and feedback and reviews you may leave on our products or services;
- Financial information to fulfill your order(s), such as banking details, credit or debit card information; details of transactions you conduct through our website or through other channels and of the fulfilment of your orders,
- Information about your eyes, vision, and vision health, such as your eyeglass prescription, pupillary distance (PD), and facial measurements;
- Other personal information you or a person authorized by you submit;
- Internet usage information, such as details of your visits to our website and information collected through cookies and other tracking technologies including your IP address and domain name, your browser version and operating system, traffic data, location data, web logs and other communication data, and the resources that you access;
- Geolocation information; and
- Inferences, such as inferences drawn from any of the information above so we may better understand your preferences.
Note, when using the Virtual Try-On tool on our website or your mobile device, we will use your camera to look at and measure your facial geometry, so you can view how our products look on your face. We do not store any of these scans or measurements and only collect and use that data while you are using the Virtual Try-On tool. Please note, this tool is powered by a third-party service provider.
How We Use Information
We may process personal information in a number of ways for the primary purpose of conducting our business, including:
- Completing your transactions or purchases;
- Filling and shipping your orders;
- Administering contests, promotions, and sweepstakes;
- Providing customer support, respond to your questions or requests, and otherwise communicating with you, including providing email and SMS notifications.;
- Sending you marketing communications;
- Managing our relationship with you;
- Sending you information about our products and services.
- Collecting and disclosing personal information to our related companies in connection with our operations;
- In the case of a potential employee, assessing your application for employment with us, and verifying your details and contacting your references;
- Researching and assessing our services and products to identify possible improvements, including collecting, using, and disclosing details about your usage patterns and interests;
- Fulfilling obligations to, and cooperating with, government authorities, courts, regulators or law enforcement agencies in connection with enquiries, proceedings or investigations by such parties anywhere in the world or in order to enable us to comply with our regulatory requirements or to respond to regulators;
- Resolving disputes or addressing complaints;
- Protecting our property, rights, and security, and the rights, property, and security of third parties or the public in general;
- To audit or provide reporting related to particular transactions and interactions you have with us or others on our behalf;
- Disclosing business-related data and information (including personal information) to potential buyers or other successors (and their advisors) in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, insolvency, liquidation, or similar proceedings;
- Pursuing our legitimate interests, such as direct marketing, research and development (including marketing research), network and information security, and fraud prevention;
- Ensuring the quality or safety of our products and services;
- Where you otherwise provide your consent; and
- Where otherwise required by law.
How We Disclose Information
We may share your information with our service providers, who act on our behalf, our partners and collaborators, and at your direction.
Below are more details on who we share information with:
- Our Affiliates and Subsidiaries.
- Service Providers. We may provide your personal information to our vendors, contractors, business and service partners, or other third parties. Examples of service providers include advertisers, ecommerce and platform providers, payment processors, customer service and support providers, email, IT services and SMS vendors, loyalty program administrators, web hosting and development companies and shipping and fulfillment companies.
- Professional Services. To firms that provide professional consultancy services on our behalf, such as our auditors or accountants.
- In connection with a merger, acquisition, or business transfer. If Quay sells all or part of one of its product lines or divisions, your information may be transferred to the buyer.
- Government, regulatory and law enforcement agencies. Quay reserves the right to disclose your information to respond to authorized information requests from government authorities, to respond to valid judicial requests, to address national security situations, to provide security and investigate potential fraud, or when otherwise required by applicable law. We may also disclose your personal information as required by law to any competent law enforcement body, regulatory or government agency, court or other third party where we believe the disclosure is necessary or appropriate to comply with a regulatory requirement, judicial proceeding, court order, government request or legal process served on us, or to protect the safety, rights, or property of our customers, the public, Quay or others, and to exercise, establish or defend our legal rights.
We take reasonable steps to ensure that any third parties that access your personal information are subject to confidentiality requirements and to obligations to process personal information in accordance with the representations made in this Policy.
Quay does not sell personal information to third parties to use for their own benefit; however, we allow certain companies to place tracking technologies like cookies on our websites. Those companies receive information about your interaction with our websites that is associated with your browser or device and may use that data to serve you relevant ads on our websites or others. Except for this kind of sharing, we do not sell any of your information. If you would like to opt-out of this practice, please click here.
At our discretion, we may also disclose aggregated, anonymized or de-identified information that is not personally identifiable.
From time to time, we may transfer your personal information to overseas recipients (including our related companies and any relevant third parties) if it is necessary to conduct our business. We currently have operations in Australia, the United States, and Europe. Your personal information may be stored and disclosed to recipients in those jurisdictions. We also use cloud-based solutions such as Shopify, NetSuite, and EDI that store personal information securely primarily in the United States and Europe. We may from time to time expand our operations and/or change the cloud-based or other solutions used to store personal information. We will handle your personal information in accordance with this Policy regardless of where your information is stored or accessed.
We take reasonable steps to ensure that our service providers provide commitments relating to privacy and confidentiality which require the service provider to limit its use of your personal information and to protect your personal information against misuse, loss and unauthorized access. Where required by certain jurisdictions, we will transfer your personal information subject to jurisdiction-approved safeguards and in accordance with applicable law, such as standard contractual clauses. For example, if you are based in the UK or elsewhere in the European Economic Area (EEA), and we transfer your personal information outside of the UK or EEA, we will impose the same data protection safeguards that we deploy inside the UK or EEA on applicable third parties.
Security of Your Information
We will take reasonable steps to ensure that the information is secure and may only be accessed by authorized persons. Please notify us immediately if you believe there has been any unauthorized access to your information.
We keep personal information as long as it is reasonably necessary for the purposes described in this Policy or otherwise in compliance with our or our service providers’ data retention policies. We will retain the information you choose to upload to your account, but you may login and delete it at any time. Please note after extended periods of inactivity, we reserve the right to delete your account or information from your account such as your PD measurement.
Certain information may be retained until the time limit for any legal challenges has expired or in order to comply with regulatory requirements regarding the retention of such personal information. If you have provided us with personal information in the course of applying for employment with us, and your application has not been successful, we may keep your personal information in case a suitable role becomes available. Where applicable, if any personal information that we hold is no longer required for the purpose for which it was collected and no applicable law requires us to retain that information, we will take reasonable steps to de-identify or destroy the information.
Your Privacy Rights
Depending on where you reside, applicable data protection laws may give you the right to:
- Know the categories and/or specific pieces of personal information collected about you, including whether your personal information is sold or disclosed, and with whom your personal information was shared;
- Access a copy of the personal information we retain about you;
- Request deletion of your personal information; Correct or update your personal information;
- Opt-out of sales or sharing of your personal information for cross context behavioral advertising purposes..
You or your authorized representative may request to access, receive a copy of, correct, or delete the personal information we hold about you by contacting our Privacy Officer at email@example.com. To help protect the security of your personal information, we will verify your identity in connection with any requests. Also, we take steps to ensure that only you or your authorized representative can exercise rights with respect to your information. If you are an authorized agent making a request, we may require and request additional information to protect the personal information entrusted to us, including information to verify that you are authorized to make that request or proof of power of attorney.
There may be situations where we cannot grant your request, for example if you make a request and we cannot verify your identity, we will not be able to comply with the request. We may also be unable to comply with your request if we have a legal or regulatory obligation to keep your personal information. Other reasons your request may be denied are if it jeopardizes the privacy of others, or would be extremely impractical to honor.
Where we deny your request in whole or in part, we will take steps to inform you of the denial and provide an explanation of our actions and the reasons for the denial.
We will not restrict or deny you access to our services because of choices and requests you make in connection with your personal information. Please note, certain choices may affect our ability to deliver our Services. For example, if you sign up to receive marketing communications by email, then ask us to delete all of your information, we will be unable to send you marketing communications.
Applicable data protection laws may also give you the right to object to or restrict our processing of your personal information. Data subjects whose processing is based upon consent may withdraw that consent at any time; please note, withdrawal of consent will not be retroactive.
If you are located in the European Economic Area or the United Kingdom, you have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal information violates applicable law.
If you are a California resident, please review Schedule 1 of this Policy for additional information about the personal information we collect and the privacy rights provided to you by the California Consumer Privacy Act of 2018 (“CCPA”).
If you would like to opt-out of cross context behavioral advertising, please click here. Our sites are also equipped to respond to “Do Not Sell” signals.
Privacy of Children
Our websites are not intended for children under the age of 18. We do not knowingly collect any personal data from children under the age of 18. The children's products that we may offer for sale on our websites are intended for purchase by adults only. No-one under the age of 18 years should provide any personal data through our websites. If you are a parent or guardian and become aware that your child has provided us with information, please contact us at firstname.lastname@example.org. If we learn that we have collected personal information from a child, we will delete that information as soon as practicable.
Your Marketing Choices
When we ask for information from you for marketing purposes, you are given the opportunity to ‘opt-in’ to receive additional information, such as site announcements, product reviews, promotional information, product sampling opportunities and research requests from us and to allow us to share your contact information with certain of our trusted partners and customers. Where required by law, we will ask for your consent before conducting any of these types of marketing.
Marketing includes sending you updates about our products and offerings or shopping cart reminders. When we contact you, it may be by mail, telephone, email or SMS. SMS may be sent using an automatic telephone dialing system. Consent for SMS marketing is not required as a condition to purchase products or services. Message and data rates may apply. Where we use or disclose your personal information for the purpose of direct marketing, we will:
- inform you if we intend to use your information for such purposes (including by making available this Policy);
- allow you to ‘opt out’ or, in other words, allow you to request not to receive direct marketing communications; and
- comply with any such request by you to ‘opt-out’ of receiving further communications within a reasonable time frame.
Third Party Links
Our website may contain links to other third-party websites. If you follow a link to any of those third-party websites, please note that they have their own privacy policies and that we do not accept any responsibility or liability for their policies or processing of your personal information. Please check those policies before you submit any personal information to such third-party websites.
Questions and Complaints
Quay Eyeware Inc. is the data controller in respect of your personal information under this Policy.
If you have a question about how we handle personal information, wish to exercise any of the choices you may have in your personal information, or lodge a complaint about our management of personal information (including if you believe that we have managed your personal information in breach of applicable privacy laws), you may contact our Privacy Officer:
Attention: Privacy Officer
465 California Street
San Francisco, CA 94104
The Privacy Officer will coordinate the investigation of any complaint and any potential resolution of a complaint. In order to be sure that we understand the details and nature of your question or complaint, we may ask you to put your question or complaint in writing. We will aim to resolve all complaints as soon as practicable for us to do so.
For further information on the cookies we use and the purposes for which we use them, please contact our Privacy Officer.
Changes to this Policy
We may change this Policy at any time. Please refer back to this Policy periodically to review any updates. If we make material changes to this Policy we will notify you by publication on our website or as otherwise required by applicable law. The revised version of the Policy will be effective at the time we post it, which time will be indicated by the Last Updated date the top of this Policy.
ABN: 74 118 078 274
Schedule 1: California Residents
This Schedule 1 only applies to our collection and disclosure of personal information that is subject to the California Consumer Privacy Act of 2018 (“CCPA”). The CCPA provides California residents with the right to know what categories of personal information Quay Eyeware Inc. has collected about them and what categories of third parties Quay Eyeware Inc. has disclosed their personal information to for a business purpose in the preceding 12 months (e.g., to a service provider). The categories of sources from which we collect personal information and our business and commercial purposes for using personal information are set forth in the table below. Please note that our collection, use, and disclosure of your personal information will vary depending on the circumstances and nature of our interactions or relationship with you.
Categories of Personal Information Collected by Quay Eyeware Inc.
Disclosed by Quay Eyeware Inc. for a Business Purpose?
Categories of Third Parties to which Quay Disclosed Personal Information for a Business Purpose
Personal information categories listed in Cal. Civ. Code § 1798.80(e)
Internet activity or electronic network activity information
Professional or employment-related information
Inferences drawn from other personal information to create a profile
California residents have certain rights in their personal information which are covered above in the Your Privacy Rights section of the Policy above.
For purposes of the CCPA, we do not “sell” personal information, nor do we have actual knowledge of any “sale” of personal information of minors under 16 years of age. We will not discriminate against you for the exercise of the privacy rights provided by the CCPA, including by:
- Denying you our products or services;
- Charging you different prices or fees for our products or services;
- Providing you a different level or quality of our products or services; or
- Suggesting any of the above.
Last updated: April 3, 2023