lululemon privacy policy
Last updated: May 24. 2018
If you are a consumer in the European Economic Area ("EEA") or Switzerland, this privacy policy ("Privacy Policy") explains how we process your personal data when you shop in our stores, access or use our websites, register for and attend events, engage with us on social media or otherwise interact with us. lululemon athletica UK Ltd, located at Garden House, 57-59 Long Acre, London, WC2E 9JL, and our corporate affiliates and subsidiaries, including lululemon athletica inc.,lululemon usa inc. and lululemon athletica canada inc. (collectively, "lululemon," "we," or "us"), are the data controllers for the personal data we process about you.
Please note that we provide different or additional privacy notices in connection with certain activities, programs, and offerings. For example, this Privacy Policy does not apply to consumers located outside the EEA and Switzerland. For more information about our privacy practices in another jurisdiction, please refer to the privacy policy available in our stores, or posted on our website, for that jurisdiction.
Please read this Privacy Policy from time to time to make sure you understand how we process your personal data and the choices you have with respect to such processing.
lululemon reserves the right to change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of this Privacy Policy. If we make material changes to this Privacy Policy, we will provide you with additional notice (such as adding a statement to our websites’ homepages or sending you a notification).
In this Privacy Policy, "personal data" means any information about an individual whose identity is apparent or can be ascertained, directly or indirectly.
We collect personal data from you in connection with your access to and use of our websites, your in-store or online purchases of our products or services, or if you provide us with personal data through other channels or media, such as social media or an event registration service.In particular, we collect personal data directly from you in connection with the following activities:
We collect the following types of personal data in connection with the activities described above: your name, username, password, e-mail address, address, telephone number, credit card and debit card numbers (with expiration dates), personal preferences, goals, and any other personal data that you choose to include in your profile or in other communications with us.
When you access and use our websites, we also automatically collect data, including personal data, using cookies, pixels and local storage. The data we automatically collect includes your IP address, browser type, access times, pages viewed, the frequency of your visits to our websites, the routes by which you access our websites, and your use of any hyperlinks available on our websites. This helps us to provide you with a good experience when you browse our websites and allows us to improve our websites. For detailed information on the cookies we use and the purposes for which we use them, see our Cookie Policy.
You may have the option to link your social media account to our social media account (such as on Facebook). If you do link your social media account to our social media account, the social media service may share certain data about you and your activities with us in accordance with their privacy policies and your privacy settings on their services. If we receive data about you in this manner, we combine that data with the personal data we collect directly from you.
In general, we use your personal data to respond your requests, conduct your requested transactions, maintain and customize your account and our interactions with you and provide, maintain and improve our products and services. The specific purposes for which we process your personal data are set out below:
We do not share personal data about you with third parties except as follows:
a. Our affiliates and subsidiaries. We disclose your personal data to our holding company, subsidiaries and affiliates, including lululemon athletica inc.lululemon usa inc. and lululemon athletica canada inc., for the purposes described in the “Use of Your Personal Data” section above. Since our holding company, subsidiaries and affiliates are located around the world, please note that these disclosures involve cross-border transfers of your personal data as described in the “Data Transfers” section below.
b. Our Service Providers.We share personal data with third parties that perform services for us, including customer support, web hosting, information technology, payment processing, product fulfilment, fraud control, direct mail and email distribution, contest, event, sweepstakes and promotion administration, and analytics services. We only share with service providers the personal data that they need to perform services for us. Since our service providers are located around the world, please note that these disclosures involve cross-border transfers of your personal data as described in the “Data Transfers” section below.
c. Corporate Transactions. Personal data may be disclosed or transferred as part of, or during negotiations of any purchase, sale, lease, merger, amalgamation or any other type of acquisition, disposal, securitisation or financing involving lululemon.
d. Professional Advisors. We share personal data with our legal, financial, insurance and other advisors in connection with the kinds of corporate transactions described above or in connection with the management of all or part of lululemon’s business or operations.
e. Compliance with Law. We disclose personal data when we believe doing so is reasonably necessary to comply with applicable law or legal process (including requests from authorities), to respond to claims (including inquiries by you in connection with your purchases from lululemon), or to protect the rights, property or personal safety of lululemon, our users, employees or the public.
f. Consent. We share personal data with third parties when we have your consent to do so. For example, if you decide to participate in certain interactive areas or features of our websites, such as creating a public profile and posting your goals, you consent to the disclosure of this information to other users of our websites.
We have physical, technical and administrative measures in place to help protect personal data from loss, unauthorised access or processing, modification, disclosure, damage, alteration, destruction or other misuse. Unfortunately, the transmission of information via the internet is not completely secure or private. You understand that any messages or information you send to our websites may be read or intercepted by others. If you have any questions about the security of personal data collected by lululemon, please contact us here.
For the reasons set forth in this Privacy Policy, the personal data that we collect may be transferred to and stored or otherwise processed by our holding company, corporate affiliates, subsidiaries, and service providers outside of Switzerland and the EEA, including (but not limited to) in the United States, Canada or Australia. We also transfer personal data to service providers that process personal data for us in the United States, Canada and other locations (as an example, Amazon Web Services process information for us in various data center locations, including those listed at https://aws.amazon.com/about-aws/global-infrastructure/). While in another jurisdiction for processing, your personal data may be accessed by the courts, law enforcement, and national security authorities of that jurisdiction. These jurisdictions may not provide the same level of data protection as your home jurisdiction and may not be considered by the European Commission to offer adequate protections for personal data.
We ensure, with the signature of Standard Contractual Clauses adopted by the European Commission, that personal data transferred outside the EEA and Switzerland is maintained with at least the same level of security and protection for personal data that is required under applicable law. Copies of the Standard Contractual Clauses we use to facilitate this transfer of data are available here and here. Transfers to Canada are made pursuant to European Commission decision 2002/2/EC of 20 December 2001.
Retention of Your Personal Data
We retain personal data only for as long as necessary to achieve the purpose for which such personal data was collected, unless a different retention period is required under applicable law. We also retain personal data for as long as you have your account, or as long as is needed to be able to provide the services or products to you, or (in the case of any contact you may have with our Guest Education Centre) for as long as is necessary to provide support-related reporting and trend analysis. If reasonably necessary or required to meet legal or regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions, lululemon may also keep personal data as required, after an account is closed or is no longer necessary to provide services. Unless otherwise required by applicable law, lululemon will take reasonable steps to destroy or permanently de-identify personal data it holds if such personal data is no longer needed for the purpose for which it was collected.
Please note that our websites contain links to third-party websites that are not controlled or operated by lululemon. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that lululemon does not accept any responsibility or liability for these policies.Please review these policies before you disclose any personal data when visiting such third-party websites.
Your Personal Data Rights
Subject to certain limitations and exceptions, you have the following legal rights regarding our processing of your personal data:
If you would like to exercise any of these rights or if you have any questions or enquiries relating to our privacy practices or procedures, you may write to the Privacy Officer at the addresses provided below.
Questions or comments about this Privacy Policy and or data protection practices should be directed here.