Privacy

LAST UPDATED AND EFFECTIVE DATE: FEBRUARY 1, 2023

This privacy policy describes how Tiber River Naturals Incorporated, and Tiber River USA, Incorporated (collectively, “Tiber River”, “we”, “us” or “our”) collect, use, share, and protect our customers’ personal information. It also tells you about the rights and choices you have with respect to your personal information, and how you can reach us to get answers to your questions. Please note, our privacy practices are subject to the applicable laws of the places in which we operate. You will see additional region-specific terms that only apply to customers located in those geographic regions, or as required by applicable laws.

 

1. What Our Privacy Policy Covers

This privacy policy covers Tiber River’s customer facing operations in the United States and Canada, and applies to the personal information Tiber River obtains in various contexts, both online and offline, including when you access or use our websites, native mobile applications (“Tiber River Mobile Apps”) or any other applications or services that link to this privacy policy, visit us in our stores, communicate with us, shop with our third-party partners, engage with us on social media, or participate in any of our programs or events.

We may provide different or additional privacy notices in connection with certain activities, programs, and offerings. We may also provide additional “just-in-time” notices that may supplement or clarify our privacy practices or provide you with additional choices regarding your personal information.
Our websites may include links to websites and/or applications operated and maintained by third parties. Please note that we have no control over the privacy practices of websites or applications that we do not own. We encourage you to review the privacy practices of those third parties.

 

2. What Personal Information We Collect

The types of personal information we obtain about you depends on how you interact with us and our products and services. When we use the term “personal information,” we are referring to information that identifies, relates to, describes, or can be associated with you. The following are the categories and specific types of personal information that we collect:

Basic Identifying Information
Including your full name, alias, postal address, e-mail address, phone number, date of birth, account name, signature, username or social media handle, or other similar identifiers.

Device Information and Other Unique Identifiers
Including device identifier, internet protocol (IP) address, cookies, beacons, pixel tags, mobile ad identifier, or similar unique identifiers.

Internet or Other Network Activity
Including browsing or search history, and information regarding your interactions with our websites, mobile applications, emails, or advertisements.

Geolocation Data
Including information that permits us to determine your location, such as if you manually provide location information or enable your mobile device to send us precise location information.

Payment Information
Including credit or debit card number.

Commercial Information
Including products or services you have purchased, returned, exchanged, or considered, preferences, and rewards activity related to Beauty Insider membership.

Physical Characteristics
Including skin tone and type, hair color and type, eye color, and other beauty profile information you provide.

Health and Medical Information
Including information, you choose to provide regarding skin conditions or medications in connection with a beauty service, in-store digital experience, or product recommendation.

Demographic Data
Including age, gender, race, ethnicity, estimated income, and household information, some of which may include characteristics of protected classifications under state or federal law.

User Content
Including your communications with us and any other content you provide (such as social media profiles, photographs, images, videos, survey responses, comments, product reviews, testimonials, and other content).

Audio and Visual Information
Including photographs, images, videos, and recordings of your voice (such as when we record customer service calls for quality assurance).

Inferences
Inferences drawn from or created based on any of the information identified above.

Job Applicant Information
Including professional or employment-related information (such as education and employment history) and any other information you provide in connection with applying and interviewing for employment at Tiber River. If we retain you as an employee, this may include, among other things, your Social Insurance number, Social Security number or taxpayer ID.

 

3. How We Collect Your Personal Information

We collect personal information about you from various sources. For example, we collect and obtain information:

Directly from you
We collect personal information you provide, such as when you make a purchase, register for an account or create a profile, sign up for any of our customer loyalty programs, contact us, respond to a survey, book a reservation, make an appointment for in-store services, RSVP for an event, interact with us in store, participate in a sweepstakes, contest, or other similar campaign or promotion, respond to a survey, apply for a job, or sign up to receive emails, text messages, and/or postal mailings.

Using cookies and other automatic data collection technologies
When you visit our websites, use our Tiber River Mobile Apps, open or click on emails we send you, or interact with our advertisements, we or third parties we work with automatically collect certain information using technologies such as cookies, web beacons, clear GIF, pixels, internet tags, web server logs, and other data collection tools. For more information, please see “Cookies and Similar Tracking Technologies” section below.

From Social Media Platforms and Networks
If you interact with us on social media or use features, such as plugins, widgets, or other tools made available by social media platforms or networks (including Instagram, Facebook, Twitter, Google, You Tube, and Pinterest) in connection with our websites or Tiber River Mobile Apps, we collect information that you share with us, or that the social media platforms share with us. For more information about the privacy practices of those social media platforms, please review the privacy policies and settings of the social media platforms and networks that you use.

From Other Sources
For example, we may obtain information about you from other sources, such as data analytics providers, marketing or advertising service providers, fraud prevention service providers, vendors that provide services on our behalf, or publicly available sources. We also create information based on our analysis of the information we have collected from you.

 

4. Cookies and Similar Tracking Technologies

We and our third-party partners (such as advertising and analytics providers) use cookies, web beacons, clear GIF, pixels, internet tags, and other similar tracking technologies (collectively, “tracking technologies”) to gather information when you interact with our websites, Tiber River Mobile Apps, and email communications. Some tracking technologies help us maintain the security of our websites and your account, prevent crashes, fix bugs, save your preferences, and assist with basic site functions.

We also permit third parties to use tracking technologies on our websites and Tiber River Mobile Apps for analytics and advertising, including to help manage and display advertisements, to tailor advertisements to your interests, or to send abandoned shopping cart reminders and/or browse abandonment reminders. The third parties use their technology to provide advertising about products and services tailored to your interests which may appear either on our websites or on other websites.

To the extent these tracking technologies are deemed to be a “sale”/ “sharing” under California law, you can opt-out of these tracking technologies by submitting a request at the following website URL: https://www.tiberriver.com/pages/ccpa-opt-out.

 

5. How We Use Your Personal Information

We collect and use personal information for various purposes, including:

Providing Products and Services
We use your personal information to provide products and services, such as to fulfill your orders and/or complete the transactions you request; process your payments; provide you receipts and order updates; send notifications to you related to your account, purchases, returns, exchanges, subscriptions, and reservations; and create, maintain, and otherwise manage your account, profile, or program membership, including offering functionalities such as easy checkout and the ability to save user preferences and transaction history and to provide a forum for discussion, asking questions, posting photos and reviews, and sharing experiences.

Depending on the products and/or services you request, the categories of information used for these purposes may include Basic Identifying Information, Payment Information, and Commercial Information. For certain services, such as online, Tiber River Mobile App, and in-store digital experiences, or consultations with one of our estheticians, you may choose to provide Physical Characteristics and/or Health and Medical Information (please note that Tiber River does not store Health and Medical information)

Communicating With You
We use your personal information to communicate with you, such as to respond to and/or follow-up on your requests, inquiries, issues or feedback, and to provide customer service.

Administering Tiber River Programs
We use your personal information to administer our programs. This may include setting up and verifying your account, communicating with you regarding the program, evaluating your application, tracking the rewards/points you earn for purchasing products; and providing a forum for discussion, asking questions, posting photos and reviews, and sharing experiences.

Marketing and Promotional Purposes
We use personal information for marketing and promotional purposes, such as to send marketing, advertising, and promotional communications by email, text message or postal mail (such as promotions, new product launches, and event invitations); to show you advertisements for products and/or services tailored to your interests on social media and other websites; and to administer our sweepstakes, contests, and other similar promotions.

Analytics and Personalization
We use personal information to conduct research and analytics, including to improve our services and product offerings; to understand how you interact with our websites, Tiber River Mobile Apps, advertisements, and communications with you to determine which of our products or services are the most popular, and to improve our websites, Tiber River Mobile Apps, and marketing campaigns; to personalize your experience, to save you time when you visit our websites and Tiber River Mobile Apps, and to customize the marketing and advertising that we show you; to understand how you use our Tiber River Mobile Apps; to create a more personalized experience for you when you visit our stores; to provide services, to better understand our customers’ needs, and to provide personalized recommendations about our products and services.

Security and Fraud Prevention
We use personal information to detect, investigate, prevent, or take action regarding possible malicious, deceptive, fraudulent, or illegal activity, including fraudulent transactions, attempts to manipulate or violate our policies, procedures, and terms and conditions, security incidents, and harm to the rights, property, or safety of Tiber River and our users, customers, employees, or others.

Legal Obligations
We use personal information to comply with our legal or regulatory obligations, to establish or exercise our rights, and to defend against a legal claim.

Core Business Functions
We use personal information to support core business functions, including to maintain records related to business process management; loss and fraud prevention, and to collect amounts owing to us; and to provide and maintain the functionality of our website and Tiber River Mobile Apps, including identifying and repairing errors or problems.

Applicant
We use Job Applicant Information to make decisions about recruitment and in anticipation of a contract of employment. Providing this information is required for employment.

 

6. How We Share Your Personal Information

In addition to the specific situations discussed elsewhere in this privacy policy, we disclose personal information in the following circumstances:

Corporate Affiliates
We may share personal information with our corporate affiliates, including our parent company, sister companies and subsidiaries including Tiber River Naturals Incorporated and Tiber River USA Incorporated. Such corporate affiliates process personal information on our behalf as our service provider, where necessary to provide a product or service that you have requested, including to administer various programs, or in other circumstances with your consent or as permitted or required by law.

Service Providers
We share certain personal information with third parties that perform services to support our core business functions and internal operations including: fulfilling orders, delivering packages, complying with your request for the shipment of products to or the provision of services by a third party intermediary, sending postal mail, e-mails and text messages, analyzing customer data, providing marketing assistance, administering our ratings and reviews, supporting beacons, processing credit card and debit card payments, investigating fraudulent activity, conducting customer surveys, and providing customer service.

Third Party Partners
We may share your personal information with third parties that we have partnered with to jointly create and offer a product, service, or joint promotion. If you decide to obtain a product or service that is offered by these third-party partners, the information you provide will be shared with us and them. Their use of your information is not governed by this privacy policy, but by their own respective privacy policies. Please note, we will not share text messaging or email opt-in data and consent with any third parties for their marketing purposes.

Social Media Platforms and Networks
Some of our websites have features such as, plugins, widgets, or and other tools made available by third parties that may result in information being collected or shared between us and the third party. For example, if you use Facebook’s “Like” feature, Facebook may register the fact that you “liked” a product and may post that information on Facebook. Their use of your information is not governed by this privacy policy.

Legal Process
We may disclose personal information in response to subpoenas, warrants, court orders, government inquiries or investigations, or to comply with relevant laws and regulations. We may also disclose information to establish, exercise, or protect the rights of our company, employees, agents, and affiliates; to defend against a legal claim; to protect the safety and security of our visitors; to detect and protect against fraud; and to take action regarding possible illegal activities or violations of our policies.

Business Transfers
We may share personal information with another company that buys some, or all, of the assets or stock of Tiber River, and that company may use and disclose personal information for purposes similar to what is described in this policy. Tiber River may also share personal information with prospective purchasers to evaluate the proposed transaction.

Other Instances
We may ask if you would like us to share your information with other third parties who are not described elsewhere in this privacy policy.

 

7. How We Protect Your Personal Information

Personal information is maintained on our servers or those of our service providers, and is accessible by authorized employees, representatives, and agents as necessary for the purposes described in this privacy policy.

We realize individuals trust us to protect their personal information. We maintain reasonable and appropriate physical, electronic and procedural safeguards designed to help protect your personal information. While we attempt to protect your personal information in our possession, no method of transmission over the internet, or security system is perfect, and we cannot promise that information about you will remain secure in all circumstances.

For your convenience, our websites and Tiber River Mobile Apps include functionality that allows you to remain logged in so that you do not have to re-enter your password each time you want to access your account. If you choose to remain logged in, you should be aware that anyone with access to your device will be able to access and make changes to your account and may be able to make purchases through your account. For that reason, if you choose to remain logged in, we strongly recommend that you take appropriate steps (such as enabling the “Passcode Lock” security feature on your mobile device) to protect against unauthorized access to and use of your account. Please also notify us as soon as possible if you suspect any unauthorized use of your account or password.

 

8. Your Rights

Consistent with applicable law, you may exercise the rights described in this section. Please note that some of the rights may vary depending on your country, province, or state of residence.

Accessing, Updating, Correcting, and Deleting Personal Information
You may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, update and correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law.

Access and Deletion
You can submit a request to access or delete your personal information, or withdraw consent, by:

Emailing us at customerservice@tiberriver.com; or by calling 1-855-962-1574

If you are a Canadian resident and want to withdraw consent to processing, please submit a deletion request by submitting an email or calling the number above.

Typically, we retain your personal information for the period necessary to fulfill the purposes outlined in this privacy policy, unless a longer retention period is required or permitted by law. Please note that in many situations we must retain all, or a portion, of your personal information to comply with our legal obligations, resolve disputes, enforce our agreements, to protect against fraudulent, deceptive, or illegal activity, or for another one of our business purposes.

Updates and Corrections
You can update information related to your account by:

Emailing us at customerservice@tiberriver.com; or by calling 1-855-962-1574.

If you have given Tiber River permission to store your credit card information and you don’t want merchants like Tiber River to receive your updated credit card information through your credit card issuer’s account updater service, please contact your card issuer.

Identity Verification
For us to process some requests, we will need to verify your identity to confirm that the request came from you. We may contact you by phone or e-mail to verify your request. Depending on your request, we will ask for information such as your name, and an e-mail address that you have used with Tiber River, or a phone number you have used with Tiber River. For certain requests, we may also ask you to provide details about the most recent purchase you made online or in store.

Managing Communication Preferences

Email:
You can stop receiving promotional e-mails at any time by:

Clicking on the “unsubscribe” link at the bottom of any promotional e-mail that you receive from us; or emailing us customerservice@tiberriver.com; or by calling us at 1-855-962-1574.

Text Messages:
You can opt-out of receiving text messages from us by replying “STOP” to the text message you receive from us.

In-App Push Notifications:
You can stop receiving in-app push notifications in Tiber River Mobile Apps by adjusting your Notification Settings in the Tiber River Mobile App.

Removing Content from Tiber River Public Forums:
You can request that we remove content or information that you have posted on a public page on some of our websites (such as product or service reviews) by e-mailing details to our Customer Experience team at customerservice@tiberriver.com. Please note that while we will endeavor to honor your request, our removal of your content or information does not ensure complete or comprehensive removal of that information from our website. For example, historical copies, or “caches,” may remain.

 

9. Transmission of Information to Other Countries

Tiber River USA Incorporated is located in the United States. Tiber River Naturals Incorporated is located in Canada and uses service providers and corporate affiliates that may be located outside of Canada, including in the United States or other countries.

If you submit personal information to Tiber River USA Incorporated or Tiber River Naturals Incorporated your personal information may be processed in a foreign country where privacy laws may be less stringent than the laws in your country. By submitting your personal information to us you agree to the transfer, storage, and processing of your personal information in a country other than your country of residence including, but not necessarily limited to, the United States.

 

10. Childrens Privacy

Our website is not intended for or directed to children under the age of 13. We do not knowingly collect personal information directly from children under the age of 13 without parental consent. If we become aware that a child under the age of 13 has provided us with personal information, we will delete the information from our records.

 

11. Communicating With Us

If you have any questions about our privacy or security practices, you can contact us by mail, telephone, or e-mail:

Tiber River Naturals Incorporated
Attn: Legal, Privacy
326 Saulteaux Crescent
Winnipeg, Manitoba R3J 3T2
1-855-962-1574
customerservice@tiberriver.com

Tiber River USA Incorporated c/o Tiber River Naturals Incorporated
Attn: Legal, Privacy
326 Saulteaux Crescent
Winnipeg, Manitoba R3J 3T2
1-855-962-1574
customerservice@tiberriver.com

If we need, or are required, to contact you concerning any event that involves your personal information we may do so by e-mail, telephone, or mail.

 

12. Changes To This Policy

We may revise this privacy policy from time to time and will post the date it was last updated at the top of this privacy policy. We will provide additional notice to you if we make any changes that materially affect your privacy rights.

 

13. Information for California Residents - California Privacy Rights

California law requires us to disclose the following information with respect to our privacy practices. If you are a California resident, this section applies to you in addition to the rest of the privacy policy.

California Shine the Light
Residents of the State of California (under California Civil Code Section 1798.83) have the right to request from companies conducting business in California a list of all third parties, if any, to which the company has disclosed personal information during the preceding year for direct marketing purposes (e.g., requests made in 2021 will receive information about 2020 sharing activities). We comply with this law by offering California residents the ability to tell us not to share your personal information with third parties for their direct marketing purposes. To make such a request, please contact us via post mail or email at:

Tiber River USA Incorporated c/o Tiber River Naturals Incorporated
Attn: Legal, Privacy
326 Saulteaux Crescent
Winnipeg, Manitoba R3J 3T2
1-855-962-1574
customerservice@tiberriver.com

You must include the name of this website and “California Resident” in your message, and your full name, e-mail address, and postal address in your message. Please note that any request under this paragraph will be limited to our use and disclosure of your personal information.

Categories of Personal Information We Collect and Our Purposes for Collection and Use
You can find a list of the categories of personal information that we collect in the “What Personal Information We Collect” section above. For details regarding the sources form which we obtain personal information, please see the “How We Collect Your Personal Information” section above. We collect and use personal information for the business or commercial purposes described in the “How We Use Your Personal Information” section above.

Categories of Personal Information Disclosed and Categories of Recipients
We disclose the following categories of personal information for business or commercial purposes to the categories of recipients listed below:

  • We share Basic Identifying Information with: Service Providers, Third Party Partners, advertising networks, and social media networks.
  • We share Device Information and Other Unique Identifiers with: Service Providers, Third Party Partners, advertising networks, and social media networks.
  • We share Internet or Other Network Activity with: Service Providers, Third Party Partners, advertising networks, and social media networks.
  • We share Geolocation Data with: Service Providers and Third-Party Partners.
  • We share Payment Information with: Service Providers who process payments.
  • We share Commercial Information with: Service Providers, Third Party Partners, advertising networks, and social media networks.
  • We share User Content with: Service Providers who help administer our programs, such as social media networks.
  • We share Audio and Visual Information with: Service Providers who help administer customer service and fraud or loss prevention services.
  • We share Inferences with: Service Providers who help administer marketing and personalization.

For more information on how your information is shared, please see the “How We Share Your Personal Information" section, which provides more detail on our Service Providers and Third Party Partners. We may also need to share any of the above categories of information pursuant to Legal Process or as a result of a Business Transfer as described in the “How We Share Your Personal Information” section.

California Privacy Rights
If you are a California resident, you may have certain additional rights under the CCPA as described below:

1. You have the right to know:
a. The California Consumer Privacy Act (CCPA) sets forth certain obligations for businesses that “sell” personal information. Based on the definition of “sell” under the CCPA and under current regulatory guidance, we do not believe we engage in such activity and have not engaged in such activity in the past 12 months.
b. Tiber River does not sell your personal information to any third party.
c. In the 12 months preceding the revision date of this Privacy Policy, we have not sold any personal information.
d. We do not discriminate against consumers as a result of a consumer’s exercise of any of his or her rights listed in this section. For example, we will not, as a result of a consumer’s exercise of any rights listed in this section:
i. Deny goods or services to the consumer;
ii. Charge different prices or rates for goods or services;
iii. Provide a different level or quality of goods or services; or
iv. Suggest in any way that a consumer will receive a different price or rate for goods or services or a different level or quality of goods or services.
e. Notice of financial incentive:
i. We may provide discounts or other incentives to customers who provide us with certain of their personal information. For example, we may offer a discount to a consumer who provides her contact information and payment information in order to register with us.
ii. We offer our customers a loyalty program that provides certain perks, such as rewards and exclusive offers. We may also provide other programs, such as sweepstakes, contest, or other similar promotional campaigns (collectively, the “Programs”). When you sign up for one of these Programs, we typically ask you to provide your name and contact information (such as email address and/or telephone number). Because our Programs involve the collection of personal information, they might be interpreted as a “financial incentive” program under California law. The value of your personal information to us is related to the value of the free or discounted products or services, or other benefits that you obtain or that are provided as part of the applicable Program, less the expense related to offering those products, services, and benefits to Program participants. You may withdraw from participating in a Program at any time by contacting us using the designated method set forth in the applicable Program rules. Visit the terms and conditions page of each Program to view full details, including how to join.

2. You may request the following:
a. A description of the categories of personal information we collect and the reasons we collect this information.
b. All personal information we have about you.
c. If your Ambassador or customer agreement is cancelled for any reason, once four years have passed you may request that we delete your personal information.
d. A description of the categories of personal information we collect and the categories of third parties to which we disclose your personal information.
e. A list of third parties to which we have provided your personal information for business purposes, and the corresponding purpose for which we have disclosed your information.

To exercise any of your rights under this section, contact us by telephone at 1-855-962-1574 or email us at customerservice@service.com, or via https://www.tiberriver.com/pages/ccpa-opt-out. You will be required to provide us with your name, address, email address, and the last four digits of the credit card that you have on file with us so that we can verify your identity.