PERSONAL DATA YOU PROVIDE DIRECTLY TO US
We collect personal data directly from you in a variety of ways, including when you:
- Register for an account, create a profile, participate in interactive areas of our Services, or fill out forms on our Services or in our stores;
- Request additional information about our products or services or sign up to receive our e-mail newsletters, marketing messages or coupons;
- Interact with us on social media, such as by tagging us and/or our products or permitting us to follow your social media profile;
- Purchase any product or service from us;
- Provide design or product feedback or make other submissions to us;
- Request information or assistance from us, including correspondence with our customer service team or our store associates for personalized styling;
- Participate in or respond to surveys or requests for opinions, feedback and preferences;
- Participate in any of our experiential offerings in our stores or at other locations, sponsored by us;
- Participate in or register for our ambassador or membership programs;
- Using other features of our websites that may be offered from time to time, which may require information in order to utilize the features; and
- Sign up for and participate in events, contests, sweepstakes, promotions and special programs that we provide.
The types of personal data we collect directly from you may include: your name, username, password, e-mail address, address, telephone number, credit card and debit card numbers (with expiration dates), demographic information, personal preferences, clothing size, goals, classes you teach or attend in connection with our Ambassador and Membership Programs, and any other personal data that you choose to include in your profile or in other communications with us.
PERSONAL DATA WE COLLECT AUTOMATICALLY
We automatically collect personal data when you access and use our Services or shop in our stores. The types of
information we collect may include:
- Networking and device information, such as your browser type, IP address, and operating system version, language settings;
- Information about your activity on our Services, such your access times, pages viewed, the routes by which you access our Services, your use of any hyperlinks available within our Services;
- Information about your purchases or transactions with us, including records of products or services you have purchased, returned or are considering purchasing from us;
- Information collected via cookies, web beacons, and other tracking technologies, including Internet service provider (ISP), Mobile Advertising ID, media access control (MAC) address, or identifiers associated with browser cookies, web beacons and similar technologies we deploy on our Services;
- Video monitoring and recording we deploy in our retail stores; and
- Location information in accordance with your device permissions. For more details, please see “YOUR CHOICES” below. We may also use technology in our retail locations to collect data about the presence of your device.
PERSONAL DATA WE COLLECT FROM OTHER SOURCES
We may collect personal data about you from other sources. For example, we may collect personal data about you from:
- Fitness studios and providers of online booking tools when you sign up for and participate in classes offered by us;
- Our other customers, including when they bring you as a guest to one of our events or list you as an emergency contact;
- Third parties hosting events, including those sponsored by lululemon, when they share event attendance or participation information with us;
- Third-party social media and communication services, such as Facebook, Twitter, Google and Instagram, that you use to interact with our Services (e.g., to create an account) or that allow you to share information (e.g., via plugins, widgets or other tools), but always in accordance with the authorization procedures and privacy settings you establish with such services; and
- Unaffiliated parties, such as service providers that we use, analytics companies, advertising networks, consumer data resellers, and other third parties that provide us with information, so we can better understand you and provide you with information and offers that may be of interest to you.
We may derive information or draw inferences about you based on the other types of personal data we collect. For example, we may infer your location based on your IP address, or that you are interested in purchasing women’s yoga tops based on your browsing behavior on our Services.
USE OF PERSONAL DATA
We collect and use personal data for business and commercial purposes, including to:
- Develop, provide and improve our products, events and services;
- Complete the transactions you request, perform our contractual obligations, and as otherwise anticipated within the context of our ongoing business relationship;
- Create and manage your online accounts, profiles and lululemon memberships;
- Send notifications related to your account, purchases, exchanges and returns;
- Respond to your requests and any other communications from you, including to provide customer service;
- Send advertising or marketing communications about products, services, offers, promotions, rewards and events offered by lululemon and others, and provide news and information that we believe may be of interest to you;
- Offer and administer events, classes, contests, prize draws, sweepstakes and other promotions;
- Conduct internal research and development;
- Analyze your engagement with our brand and your use of our Services to better understand your interests and behaviors and customize your experience;
- Detect security incidents and protect against malicious, deceptive, or illegal activity, including fraudulent transactions, error, negligence, and breach of contract, and to protect against harm to the rights, property or safety of lululemon and our users, customers, employees or the public;
- Debug, identify and repair errors that impair existing intended functionality of our Services;
- Comply with our legal obligations, including our tax obligations and those related to the prevention of fraud and money laundering, and those required for you to benefit from rights recognized by law, or any regulatory requirements or provisions; and
- Carry out certain short-term activities and other reasonable internal purposes related to the products or services you purchase from us or your ongoing relationship with us.
We share personal data for the purposes described below:
a. With our Affiliates and Subsidiaries. Disclosures of your personal data to our holding company, subsidiaries and affiliates for the purposes described in the “USE OF PERSONAL DATA” section above. Since our holding company, subsidiaries and affiliates are located around the world, please note that these disclosures involve cross-border transfers of your personal data as described in the “DATA TRANSFERS” section below.
b. With our Service Providers. We share personal data with unaffiliated companies or individuals we hire or work with that perform services on our behalf, including customer support, web hosting, information technology, payment processing, product fulfilment, fraud control, direct mail and email distribution, events, contest, sweepstakes and promotion administration, and analytics services. We only share with service providers the personal data that they need to perform services for us. Since our service providers are located around the world, please note that these disclosures involve cross-border transfers of your personal data as described in the “DATA TRANSFERS” section below.
c. In Connection with a Corporate Transaction. Personal data may be disclosed or transferred as part of, or during negotiations of any purchase, sale, lease, merger, amalgamation or any other type of acquisition, disposal, securitisation or
financing involving lululemon.
d. With our Professional Advisors. We share personal data with our legal, financial, insurance and other advisors in connection with the kinds of corporate transactions described above or in connection with the management of all or part of lululemon’s business or operations.
e. With Law Enforcement Authorities and Individuals Involved in Legal Proceedings. We disclose personal data when we believe doing so is reasonably necessary to comply with applicable law or legal process (including an enforceable request from authorities), to respond to claims (including inquiries by you in connection with your purchases from lululemon), or to
protect the rights, property or personal safety of lululemon, our users, employees or the public.
f. With Your Consent or at Your Direction. We share personal data with third parties when we have your consent to do so. For example, if you decide to participate in certain interactive areas or features of our events or Services, such as creating a public profile and posting your goals, you consent to the disclosure of this information to other users of our websites. We may also
share your personal data with third parties when you intentionally direct us to do so or when you use our Services to intentionally interact with third parties.
We may also share aggregated or de-identified information, which cannot reasonably be used to identify you.
ADVERTISING AND ANALYTICS SERVICES PROVIDED BY OTHERS
information about your use of the Services and other websites and applications. This information may be used by lululemon and others to, among other things, analyze and track data, determine the popularity of certain content, deliver advertising and content targeted to your interest on our Services and other websites, and better understand your online activity.
For detailed information on the cookies we use and the purpose for which we use them, see the section about Cookies below.
DATA SECURITY, TRANSFERS, AND RETENTION
The transmission of information via the internet is not completely secure or private. If you have any questions about the security of personal data collected by lululemon, please contact: PRIVACYOFFICER@LULULEMON.COM
We retain personal data in accordance with applicable law. Unless otherwise required by applicable law, lululemon will take reasonable steps to destroy or permanently de-identify personal data it holds if such personal data is no longer needed for the purpose for which it was collected.
THIRD PARTY SITES
Please note that our websites contain links to third-party websites that are not controlled or operated by lululemon. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that lululemon does not accept any responsibility or liability for these policies. Please review these policies before you disclose any personal data when visiting such third-party websites.
You have certain choices with respect to how we treat your personal data, as described below.
You may review and modify your account and profile information by logging into your online account at any time. You can request that we update your account or profile information.
You may opt out of receiving promotional communications from us by following the instructions in those communications or by logging into your online account and changing your communications preferences. If you opt out, we may still send you non-promotional communications, such as those about your account or our ongoing business relations.
When you first launch any of our mobile applications that collect precise location information, you will be asked to consent to the application’s collection of this information. If you initially consent to our collection of this location information, you can subsequently stop the collection of this information at any time by changing the preferences on your mobile device. If you do so, our mobile applications, or certain features thereof, may no longer function properly.
MOBILE PUSH NOTIFICATIONS/ALERTS
With your consent, we may send promotional and non-promotional push notifications or alerts to your mobile device. You can deactivate these messages at any time by changing the notification settings on your mobile device.
Like many websites, lululemon uses “cookies” to analyze visits to our website and help us improve our website and services. Most web browsers are set to accept cookies by default. If you prefer, you can usually set your browser to remove or reject cookies. Please follow your browser’s process for doing so. Please note that if you choose to remove or reject cookies, this could affect the availability and functionality of our websites.
TECHNOLOGIES IN OUR RETAIL STORES
We have deployed WiFi access points in some of our stores, and we receive aggregate reports (none of which identify any individual or device) regarding store traffic that relies in part of information collected from the WiFi access points to track traffic patterns in our stores. Where such technology is used, we will provide a prominent notice at the location. If you wish to exclude your device from such in-store mobile analytics, you can opt out at any time by turning off WiFi on your device. We do not use facial recognition technology.
INFORMATION FOR CALIFORNIA CONSUMERS: YOUR CALIFORNIA PRIVACY RIGHTS
ADDITIONAL DISCLOSURES RELATED TO COLLECTION, USE AND DISCLOSURE OF PERSONAL DATA
If you are a California resident, the California Consumer Privacy Act (“CCPA”) requires us to disclose the following information with respect to our collection, use and disclosure of personal data.
- Categories of Personal Data Collected: In the preceding 12 months, we have collected the following categories of personal data: identifiers, characteristics of protected classifications under California or U.S. law, commercial information, internet and electronic network activity, geolocation data, audio and visual information, inferences drawn about your preferences, and other categories of personal data that relates to or is reasonably capable of being associated with you. For examples of the precise data points we collect, please see “COLLECTION OF PERSONAL DATA” above.
- Business or Commercial Purpose for Collecting and Using Data: We collect personal data for the business purposes described in the “USE OF PERSONAL DATA” section above.
- Categories of Sources of Personal Data: We collect personal data from you and the sources described in the “PERSONAL DATA WE COLLECT FROM OTHER SOURCES” section above.
- Categories of Personal Data Disclosed: In the preceding 12 months, we have disclosed the following categories of personal data for business or commercial purposes: identifiers, internet and electronic network activity information, commercial information, audio and visual information, geolocation data, demographic information, inferred information, and other information that we have derived or inferred about you or that relates to or is reasonably capable of being associated with you.
- Categories of Third Parties With Whom We Share Personal Data: We may share your personal data with the third parties as described in the “DISCLOSURE OF PERSONAL DATA” section above.
- Sale of Personal Data: lululemon does not sell your personal data.
YOUR CONSUMER RIGHTS
California consumers have the right to request access to their personal data, additional details about our information practices and deletion of their personal data (subject to certain exceptions). California consumers also have the right to opt out of sales of personal data, if applicable. We describe how California consumers can exercise their rights under the CCPA below. Please note that you may designate an authorized agent to exercise these rights on your behalf by providing written materials demonstrating that you have granted the authorized agent power of attorney. Please note that if an authorized agent submits a request on your behalf, we may need to contact you to verify your identity and protect the security of your personal data. We will not discriminate against you if you choose to exercise your rights under the CCPA.
Right to Know: You may request access to the specific pieces of personal data we have collected about you in the last 12 months. You may also request additional details about our information practices, including the categories of personal data we have collected about you, the sources of such collection, the categories of personal data we share for a business or commercial purpose, and the categories of third parties with whom we share your personal data. You may make these requests by calling 1-844-455-8903 or visiting THIS PAGE. After submitting your request, please monitor your email for a verification email. We are required by law to verify your identity prior to granting access to your data in order to protect your privacy and security.
Deletion: You may request that we delete the personal data we have collected about you. Please note that we may retain certain information as required or permitted by applicable law. You may make these requests by calling 1-844-455-8903 or visiting THIS PAGE. After submitting your request, please monitor your email for a verification email. We are required by law to verify your identity prior to deleting your data in order to protect your privacy and security. If you request to delete your personal data, certain of our products and services may no longer be available to you.