Introduction and Overview

This Privacy Policy ( “Policy” ) explains how your personal information is collected, used, shared, and processed when you access this website, located at ChantingCrystal.com (the “Site” ), including any written, electronic, and oral communications, online or offline, and purchases performed (collectively, the “Services” ) as well as the rights and choices you have associated with that information. The Policy also describes your rights regarding your personal data and explains how you can contact us to learn more about our data practices or to exercise your rights.

The Site and the App are provided by ChantingCrystal, ChantingCrystal is responsible for collecting, processing, and protecting your personal data. In this Policy, the terms “ChantingCrystal,” “Company,” “we,” “us,” and “our” refer to ChantingCrystal.

Please read our Terms and Conditions and this Policy before accessing or using our Services. If you cannot agree with this Policy or the Terms and Conditions, please do not access or use our Services.

Policy Modification: SHEIN may change this Policy from time to time, to reflect how we process your data, and if we make changes, we will revise the effective date or last modified date at the top of this Policy. If we make changes that materially affect your privacy rights, we will attempt to provide advanced notice (including via real- or near real-time disclosures) or otherwise via the Site, or by some other means of contact so that you have a reasonable opportunity to review the changes before you continue to use the Site or the Services.

If you do not agree with the modified Policy, please stop using the Site, or the Services.

CONTENTS

How We Collect and Use Your Personal Data

  • We respect the privacy of the visitors to our digital properties and the users of our products and Services, and we are committed to protecting it through our compliance with this Policy. We collect personal information when you use our Services.
  • Personal information is any information that identifies or makes an individual identifiable. The definition of personal information (used interchangeably in this Privacy Policy with the term “personal data”) depends on where you are a resident.
  • Personal Information does not include data that has been effectively irreversibly anonymized or aggregated so that it can no longer enable us or others, whether in combination with other information or otherwise, to identify an individual.
  • Your personal data is collected and used by us to support a range of different business purposes. The purposes and types of information we collect are listed in the chart below and should be understood to include uses of your personal data that are compatible with the purposes listed.
    • To create an account with us, to manage your account, and to provide you with our Services;
      • Contact information, including email address and password, to register with our Site or App;
      • Profile data, including your style preference, if you voluntarily choose to provide it for personalization purposes.
    • To fulfill or process orders;
      • Identity and contact information such as name, phone number, and shipping address, as well as financial information or payment account information, for delivery, returns, refund, sales tax determinations, and payment operations.
      • Transaction details, such as return and refund details, gift card number, and order history, in our Services, in order to fulfill basic functions, including processing your payment and return requests, and keeping you informed of the order status and shipping logistics.
      • Location data at an IP address-based level, to tailor your experience in terms of displaying the appropriate local website, language, or user experience.
      • Additional identity information that you provide if you take part in our “college campus ambassador program,” such as your school, name, email address, PayPal account, and city, for identity authentication purposes.
    • To provide customer service and support, or to provide you with service-related communications;
      • Your communication history with us via various channels, such as email, phone, social media, mail, instant chat, and our customer service platform, to respond to your requests, as well as to keep you updated about your account and the Services.
      • Photographs you upload to our Services in accordance with our Terms and Conditions, to provide product advice, and to allow you to voluntarily show other potential customers what items may look like when purchased or worn.
    • To undertake marketing, advertising or other promotional activities;
      • Contact information, such as phone number and email address, for telemarketing and email marketing purposes.
      • Non-directly identifiable device identifiers, operating system information, and cookie information, to direct and measure the effectiveness of the advertising we offer.
      • Data about how you engage with our Services, such as browsing, adding to your shopping cart, saving items, placing an order, and returns) for market research, statistical analysis, and the display of personalized advertising based on your activity on our site and inferred interests.
      • Contact and identity information, such as name, email address, and phone number, when you voluntarily enter into a competition, market survey, event, or other marketing campaigns organized by us.
      • To share your personal data with third-party service providers to advertise our Services and/or products on our Site.
    • To improve our product or service, or for personalization;
      • Collect your device information, and usage data on our Site or App for fault analysis, troubleshooting, and system maintenance, as well as setting default options for you, such as language and currency.
      • When you optionally provide such information, we may collect general personal data that cannot identify you, such as body shape, personal height, chest/waist/hip circumference, and weight. For example, this information may be used by us to recommend clothing sizes or styles, personalization, or to provide fit prediction services for you.
      • To share your personal data within and across our corporate organization for our business needs and personalization.
      • Collection of your “like” records and votes when prompted as to your preference between two items, to provide preference setting options.
      • The display of information you choose to post on public areas of the Services, for example a customer review.
    • To prevent and investigate fraud and other illegal activities;
      • Information automatically collected through the Services, such as browser type, device information, operating system, and account setting information for fraud prevention and detection and credit risk reduction.
      • Log-in data for risk control and fraud reporting.
      • Billing address to verify payment information.
    • To comply with legal or compliance requirements;
      • Identity information, such as ID- or passport-related information, for customs clearance purposes.
      • Transaction history and certain identifying information to handle and resolve legal disputes, for regulatory investigations purposes, and to comply with lawful requests from a competent law enforcement agency or court.
    • Other Purposes.
      • We may use your information for any other purpose disclosed to you prior to you providing us your personal information or which is reasonably necessary to provide the Services or other related products and/or services requested, with your permission or upon your direction.
  • Please note: When communicating with us by email or through forms on our Services, or when you publicly share content through our Services, we ask that you please do not send us any sensitive information pertaining to yourself or to others. We do not collect or store sensitive information or special categories of information.

Sharing Your Personal Data

  • We may disclose and share your personal information with the parties as described below.
    • Within Our Corporate Organization.
      • The Company is a part of a corporate organization that has several legal entities, business processes, management structures, and technical systems. We may share your personal information with our related group companies and, in some cases, other affiliates of our corporate group for business maintenance and personalization continuity purposes, for instance, so that you may enjoy a personalized user experience across our digital properties, to provide you with the Services, or to take actions based on your requests or preferences.
    • Third Party Sellers.
      • Where a third-party seller sells its’ products on the platform and the third-party seller will ship the products to you directly, we may share your personal data (name, address, and telephone number) with them so that they may fulfill your order and provide your personal data to a shipping logistics provider in order to ship the products to you.
    • Service Providers.
      • We may provide access to or share your personal information with the following types of third-party service providers as set out below:
        • IT system and software service provider
          • Website hosting services (including cloud storage), mobile app or software optimization services, customer relationship management software, email service providers, or system maintenance services.
        • Payment service provider
          • Third-party payment processing services.
        • Marketing and advertising services
          • Assistance in reaching potential new customers across multiple communications channels or sharing with affiliated companies that promote our products on their websites.
        • Order fulfillment service provider
          • Provision of logistics, warehousing, and distribution services, return and exchange services, and order status notification services for your purchased items.
        • Customer service provider
          • Assistance with customer services and support.
        • Fraud prevention and information security service provider
          • Identity verification, fraud prevention, or credit risk reduction services to protect our Site/App and our business.
        • Social media platform API provider
          • Share and receive data through the API connection of social media platforms (e.g., Instagram, YouTube, TikTok) that you selected to authenticate your eligibility to use our service or to participate in a separate ChantingCrystal program you applied for (e.g., the ChantingCrystal Affiliate Program).
          • To the extent your selected social media platform is operated by Google , we will adhere to Google API Services User Data Policy , including the Limited Use requirements.
        • Other Service providers selected by you
          • Share and receive data through the API connection of social media platforms (e.g., Instagram, YouTube, TikTok) that you selected to authenticate your eligibility to use our service or to participate in a separate ChantingCrystal program you applied for (e.g., the ChantingCrystal Affiliate Program).
          • To the extent your selected social media platform is operated by Google , we will adhere to Google API Services User Data Policy , including the Limited Use requirements.
        • Other Service providers selected by you
          • Other third parties, such as size recommendations and fit prediction services providers if you have chosen to help us provide you with product recommendations.
      • All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, excluding aggregators and providers of the text message services.
        We strive to ensure that our third-party service providers can only use your data for the purposes for which it was provided to them and to the extent necessary for such purposes, in accordance with our written instructions.
    • To Maintain Legal and Regulatory Compliance.
      • We have the right to disclose your personal information as required by law, or when we believe that disclosure is necessary to protect our rights and/or comply with a judicial proceeding, court order, request from a regulator or any other legal process served on us. We also may disclose your information where we reasonably believe that the disclosure is necessary to enforce our agreements or policies, or if we believe that disclosure will help us protect the rights, property, or safety of the Company or our customers.
    • Co-Branded Services and Features.
      • Portions of our Services may be offered as part of co-branded services and features. We will share your personal information with our co-branded partners based on your voluntary use of or participation in a co-branded service or feature. The co-branded partners will be identified on the co-branded feature or service, along with an applicable co-branded partner’s privacy policy. Use of your personal information by a co-branded partner will be subject to a co-branded partner’s privacy policy. If you wish to opt-out of a co-branded partner’s future use of your personal information, you will need to contact the co-branded partner directly.
    • Consent.
      • We may disclose your personal information for any purpose with your consent.
    • Corporate Transactions.
      • We may disclose personal information—including account information, Wallet balance or points information—to a buyer, prospective buyer, corporate affiliate, or other successors in the event of a merger, divestiture, restructuring, reorganization, dissolution, or sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding in which personal information held by us about our Services users is among the assets transferred. You acknowledge and agree to our assignment or transfer of rights to your personal information.
  • Please note that we may disclose, without restriction, aggregated or anonymized information about the users of our Services, which is information that does not identify any specific individual.

Cookies, Interest-Based Advertising, Ad Choices

  • We may use cookies, tags, web pixels, and similar technologies to automatically collect information on our Services. Cookies or tags are bits of code that allow our technology partners to collect information that usually does not directly identify you. We will request your consent before using cookies or other tracking technologies. Information within this section describes our use of cookies and your ability to control the use of cookies for advertising-related purposes.
    • Cookies.
      • Cookies are small web files that a site or its provider transfers to your device’s hard drive through your web browser that enables the Site’s or provider’s system to recognize your browser and remember certain information.
        • “First-party cookies” are cookies set by us on the Site. “Third-party cookies” are cookies set by other companies whose functionality is embedded into our site (For example, those set by Google).
        • Generally, we use first-party and third-party cookies for the following purposes: to make our Services function properly; to provide a secure browsing experience during your use of our Services; to collect passive information about your use of our Services; to measure how you interact with our marketing campaigns; to help us improve our Services; and to remember your preferences for your convenience.
        • We use the following types of cookies on our Services:
          • Strictly Necessary Cookies. These cookies are essential because they enable you to use our Services. For example, strictly necessary cookies allow you to access secure areas on our Services. Without these cookies, some services cannot be provided. These cookies do not gather information about you for marketing purposes. This category of cookies is essential for our Services to work, and they cannot be disabled.
          • Functional Cookies. We use functional cookies to remember your choices so we can tailor our Services to provide you with enhanced features and personalized content. For example, these cookies can be used to remember your name or preferences on our Services. We do not use functional cookies to target you with online marketing. While these cookies can be disabled, this may result in less functionality during your use of our Services.
          • Performance or Analytics Cookies. These cookies collect passive information about how you use our Services, including webpages you visit and links you click. We use the information collected by such cookies to improve and optimize our Services. We do not use these cookies to target you with online marketing. You can disable these cookies as set forth below.
          • Advertising or Targeting Cookies. These cookies are used to make advertising messages more relevant to you. They perform functions like preventing the same ad from continuously reappearing, ensuring that ads are properly displayed for advertisers, and in some cases selecting advertisements that are based on your interests. Our third-party advertising partners may use these cookies to build a profile of your interests and deliver relevant advertising on other sites. You may disable the use of these cookies as set forth below.
    • Your Choices.
      • Your browser may provide you with the option to refuse some or all browser cookies. You may also be able to remove cookies from your browser. You can exercise your preferences in relation to cookies served on our Services by taking the steps outlined below.
        • First-Party Cookies. You can use the browser with which you are viewing this Site to enable, disable or delete cookies. To do this, follow the instructions provided by your browser (usually located within the “Help”, “Tools” or “Edit” settings). Please note, if you set your browser to disable cookies, you may not be able to access secure areas of the Site. Also, if you disable cookies other parts of the Services may not work properly. You can find more information about how to change your browser cookie settings at https://www.allaboutcookies.org.
        • Third-Party Cookies. If you wish to opt-in or opt-out of third-party advertising networks and similar entities that use advertising cookies, please click the “Manage Cookies” link in our Site footer or visit https://www.aboutads.info/choices. For more information about third-party advertising networks and similar entities that use these technologies, please see https://www.aboutads.info/consumers. You may withdraw your consent or update your preferences at any time by clicking the “Manage Cookies” link within the Site footer or within the App menu.
        • Mobile Applications. To opt-out of data collection for interest-based advertising across mobile applications by participating companies, download the Digital Advertising Alliance’s AppChoices mobile application opt-out offering here: https://youradchoices.com/appchoices.
      • We do not control third parties’ collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. In addition, most web browsers provide help pages relating to setting cookie preferences. More information may be found for the following browsers here: Google Chrome , Internet Explorer , Mozilla Firefox , Safari (Desktop) , Safari (Mobile) , Android Browser , Opera Mobile.
      • ChantingCrystal adheres to the Digital Advertising Alliance’s Self-Regulatory Principles.
    • Web Pixels.
      • To see how successful our marketing campaigns or other goals of the Services are performing we sometimes use conversion pixels, which fire a short line of code to tell us when you have clicked on a particular button or reached a particular page (e.g. a thank you page once you have completed the procedure for subscribing to one of our services or have completed one of our forms). We also use web pixels to analyze usage patterns on our Services. The use of a pixel allows us to record that a particular device, browser, or application has visited a particular webpage.
    • Analytics.
      • We may use third-party service providers to monitor and analyze the use of our Services. Presently, we use Google Analytics. Google Analytics is a web analytics service that tracks and reports Site traffic. For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy?hl=en. Google Analytics Opt-out Browser Add-on provides visitors with the ability to prevent their data from being collected and used by Google Analytics, available at: https://tools.google.com/dlpage/gaoptout.
    • Facebook ads.
      • We also use Facebook Business Tools and we may display interest-based ads to you when using Facebook. To modify your preferences or turn off personalization for ads served by Facebook, you can visit Facebook’s Ad Preferences in addition to the Your Choices section below. We may also show ads to audiences that share similar characteristics as you. To do so, a list of email addresses is irreversibly encrypted through hashing and uploaded or transmitted from our site, and Facebook matches the hashed data against its own users, generating a lookalike audience and deleting the uploaded list. We do not have access to the identity of anybody in the “lookalike” audience unless they choose to click on one of our advertisements.
    • Java Script.
      • Pages of our Site may also use Java scripts, which are code snippets embedded in various parts of websites and applications that facilitate a variety of operations including accelerating the refresh speed of certain functionality or monitoring usage of various online components; entity tags, which are HTTP code mechanisms that allow portions of websites to be stored or “cached” within your browser to accelerate website performance; and HTML5 local storage, which allows data from websites to be stored or “cached” within your browser to store and retrieve data in HTML5 pages when the website is revisited.
    • Other Tracking Technologies.
      • We may also use Tracking Technologies to collect “clickstream” data, such as the domain name of the service providing you with Internet access, your device type, IP address used to connect your computer to the Internet, your browser type and version, operating system and platform, the average time spent on our Site, webpages viewed, content searched for, access times and other relevant statistics, and assign unique identifiers to the device or other credentials you use to access the Site for the same purposes.
    • Do Not Track.
      • Some Internet browsers, such as Internet Explorer, Firefox, and Safari, include the ability to transmit “Do Not Track” or “DNT” signals. Since uniform standards for “DNT” signals have not been adopted, our Site does not currently process or respond to “DNT” signals.
    • Location Information.
      • You may be able to adjust the settings of your device so that information about your physical location is not sent to us or third parties by (a) disabling location services within the device settings; or (b) denying certain websites or mobile applications permission to access location information by changing the relevant preferences and permissions in your mobile device or browser settings.

Security Precautions

  • We maintain reasonable physical, electronic, and procedural safeguards designed to guard your personal data from unauthorized processing, use or disclosure. Our security measures include industry-standard physical, technical, and administrative measures to prevent unauthorized access to or disclosure of your information.
  • The Internet is not an absolutely secure environment, and we cannot guarantee that your personal data will be secure. We therefore strongly recommend that you use a secure method and use a complex password to help us ensure the security of your account. We also strongly advise that you neither share your password with others nor re-use passwords on our Services that you use on other sites or apps, as doing so increases the likelihood of your being the victim of a credential stuffing attack or other malicious cyber behavior. If you feel that the security of your account or personal data has been compromised, please immediately contact us at our dedicated Privacy Center or as otherwise described in the “Contact Us” section below.

Your Rights

  • Access, Correction, and Deletion of your Personal Information.
    • You have the right to access, correct, or delete the personal information that we collect. To protect the privacy and the security of your personal information, we may request data from you to enable us to confirm your identity and right to access such data, as well as to search for and provide you with the personal data we maintain. There are instances where applicable laws or regulatory requirements allow or require us to refuse to provide or delete some or all of the personal information that we maintain. To exercise your rights, you may make updates within your customer account on the Site or App, or you may contact us at our dedicated Privacy Center. We may not accommodate a request to delete or change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.
  • Unsubscribe from Our Marketing Communications.
    • If you do not want us to use your email account to send you marketing emails or non-transactional promotional materials, please directly click on the unsubscribe link at the bottom of any of our email messages to you or contact us at our dedicated Privacy Center.
  • Lodging Complaints.
    • If you believe we have infringed or violated your privacy rights, please contact us at our dedicated Privacy Center so that we may attempt to resolve any issues to your satisfaction.
  • Right to Opt-Out of Selling.
    • Residents of certain states, such as California and Virginia, have the right to opt-out of having their personal information sold. We do not sell your personal information as that term is generally understood but we recognize that certain privacy laws may define “sale” or “personal information” in such a way that making identifiers linked to you available to limited third parties for a benefit may be considered a “sale.” In the previous 12 months, we may have shared identifiers and inferences about you with our partners, third parties, and affiliates in such a way that, under such privacy laws, may be interpreted as “selling.” If your state allows you to opt-out from such “sales,” you may exercise your opt-out right by clicking the “Manage Cookies” link in our Site footer to load a consent tool that will allow you to opt-out of the cookies on our Site.

Retention

  • We will retain your personal data, including any correspondence you have with us only for as long as is necessary for the purposes set out in this Policy, including retaining Personal Data to comply with our legal obligations, to resolve disputes, for information security purposes, and to enforce our legal rights, terms, and policies.

Third-Party Websites

  • Our App or Site may contain links to third-party sites. This Policy does not apply to those third-party sites. We recommend that you read the privacy statements of any other sites that you visit as we are not responsible for the privacy practices of those sites.

Children

  • Our Services are not directed to, and we do not knowingly collect personal information from, children under the age of 16 or minors (as defined by applicable national laws). If you are a minor, please do not attempt to fill out our forms or send any personal information about yourself to us. If a minor has provided us with personal information without parental or guardian consent, the parent or guardian should contact us immediately to remove the relevant personal information and unsubscribe the minor.
  • If we become aware that a minor has provided us with personal information, we will take steps to promptly delete such information from our files. As described further in our Terms and Conditions , please do not upload photographs showing other people, in particular if they are minors.

Transfer of Your Personal Data

  • This Privacy Policy only applies to residents of the United States. If you are a resident of another country, please see the applicable ChantingCrystal Privacy Policy and Terms of Use that is specific to your jurisdiction, which is generally available on the local version of the App or Site. Please note as well that when you use our Services, your personal data may be accessed or transferred outside of the United States. Such countries may have data protection laws that are less protective than the laws of the jurisdiction in which you reside. For these transfers, we rely on appropriate safeguards as permitted under applicable law and standards. If you do not want your information transferred to, processed, accessed, or maintained outside of the United States, you should immediately stop accessing or using the Services.

California Privacy Rights

  • This section applies only to California residents. Pursuant to the California Consumer Privacy Act of 2018, as amended and pursuant to its regulations and successors (together, “CCPA”), below is a summary for the last twelve (1months of the personal information categories, as identified and defined by the CCPA (see California Civil Code section 1798.140 (o)), that we collect, the reason we collect the personal information, where we obtain the personal information, and the third parties with whom we may share the personal information.
  • We generally collect the following categories of personal information when you use our Services:
    • identifiers such as a name, address, unique personal identifier, email, phone number, your device’s IP address, and non-directly identifiable alphanumerical numbers associated with your devices;
    • commercial information such as records of products or services purchased, obtained, or considered by you;
    • Internet or other electronic information regarding your browsing activity, length of visit and number of page views, click-stream data, locale preferences, your mobile carrier, date and time stamps associated with transactions, and system configuration information;
    • audio recordings of your voice to the extent you call us, as permitted under applicable law;
    • employment-related information; and
    • inferences about your preferences, characteristics, behavior and attitudes.
  • We generally do not collect protected classifications about our users, biometric information, or education-related information. For more information about the personal information we collect and the purposes for which we use it, please refer to section 1 above. The categories of third parties with whom we may share your personal information are listed above in section 2.
  • If you are a California resident, you have rights in relation to your personal information; however, your rights are subject to certain exceptions. For instance, we cannot disclose specific pieces of personal information if the disclosure would create a substantial, articulable, and unreasonable risk to the security of the personal information, your account with us or the security of our network systems. To assert your right to know or your right to delete your personal information, please see the “Contact Us” section below. To confirm your identity, we may ask you to verify personal information we already have on file for you or other documentation that verifies that you are whom you claim to be. If we cannot verify your identity based on the information we have on file, we may request additional information from you, which we will only use to verify your identity, and for security or fraud-prevention purposes.
    • Right Against Discrimination. You have the right not to be discriminated against for exercising any of the rights described in this section. We will not discriminate against you for exercising your right to know, delete or opt-out of sales.
    • Right to Know. You have the right to request in writing a list of the information we have collected or disclosed about you, the business purposes involved, and the sources of such information. You have the right to request a copy of the specific personal information we collected about you during the 12 months before your request.
    • Right to Delete. You have the right to request that we delete any personal information we have collected from you or maintain about you, subject to certain exceptions.
    • CCPA Right to Opt-Out of Selling. You have the right to opt-out of having your personal information sold. To exercise this right, please see the “Cookies and Other Tracking Technologies” section above for a description of opting out of cookies and controlling browser settings, in addition to clicking the “Manage Cookies” link in our Site footer to load a consent tool that will allow you to opt-out of the cookies on our Site.
    • Use of an Authorized Agent to Submit a Request. Only you or a person you formally authorize to act on your behalf may make a verifiable consumer request related to your personal information as a California consumer. If you use an authorized agent to submit such a request, we will require written proof that the authorized agent has been authorized to act on your behalf or a copy of the power-of-attorney document granting that right.
  • In addition, California’s Shine The Light law permits customers who are residents of California to request information regarding our disclosure of certain personal information to third parties for their own direct marketing purposes (see California Civil Code section 1798.83 (e)(7) for a list of personal data categories). You can submit a disclosure request using the contact information provided below once a year and free of charge. However, we do not share any personal information protected under the Shine The Light law with third parties, other corporate family entities, or affiliate businesses for their direct marketing purposes.

Nevada Privacy Rights

  • This section applies only to Nevada residents. Although we do not “sell” “covered information” of Nevada “consumers” as those terms are defined by Chapter 603A of the Nevada Revised Statutes, if you are a Nevada consumer, please go to our Privacy Center and inform us that you would like us to provide you notice in the event we should do so in the future, at which point you will have an opportunity to be verified and exercise your opt-out rights under that law. You may contact us as described below. It is your responsibility to keep your notice contact information current.

Contact Us

  • If you have questions or concerns regarding any information in this Privacy Policy, please contact us at our dedicated Privacy Center.
  • Our Privacy Office can be contacted via the email address below:
  • Email: chantingcrystal@gmail.com