Privacy Policy

INTRODUCTION

This website www.itcosmetics.co.uk is owned and run by L’Oréal (U.K.) Limited (“L’Oréal” or “We”).

At L’Oréal, we are committed to protecting and respecting your privacy. This Privacy Policy explains the types of personal information we collect, how we use that information, who we share it with, and how we protect that information.

This policy (together with our terms of use and any other documents referred to on it) sets out the basis on which any personal information we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal information, and how we will treat it. By continuing to use this website, www.itcosmetics.co.uk you are accepting and consenting to the practices described in this policy.

  1. WHO WE ARE
  2. INFORMATION COVERED BY THIS POLICY
  3. WHAT INFORMATION DO WE COLLECT FROM YOU?
  4. HOW DO WE USE YOUR PERSONAL INFORMATION?
  5. DO WE SHARE YOUR PERSONAL INFORMATION?
  6. WHERE WE STORE YOUR PERSONAL INFORMATION
  7. IS MY PERSONAL INFORMATION SECURE?
  8. LINKS TO THIRD PARTY SITES AND SOCIAL LOGIN
  9. SOCIAL MEDIA AND USER GENERATED CONTENT
  10. YOUR CHOICES
  11. COOKIES
  12. CHANGES TO OUR PRIVACY POLICY

WHO WE ARE

For the purpose of the Data Protection Act 1998 (the Act), the data controller is L’Oréal (U.K.) Limited of 255 Hammersmith Road, London, W6 8AZ, United Kingdom. For further information about L’Oreal, and the different divisions and brands within it, please visit www.loreal.co.uk.

INFORMATION COVERED BY THIS POLICY

This policy covers all personal information collected and used by L’Oreal. In this policy, “personal information” means information or pieces of information that could identify you. This includes information such as your name, address, username, profile pictures, or email address, but could also include information such as your IP address, or information about your preferences and shopping habits.

WHAT INFORMATION DO WE COLLECT FROM YOU?

We may collect information about you from different sources detailed below.
Information you give us:
You may choose to provide personal information to us, for example by filling in forms on our website or at one of our stores or counters, entering competitions and prize draws, creating an account on our website or via a mobile app, contributing on one of our social platforms, or contacting us by email, phone, live chat, or otherwise. The information you give us may include your name, address, e-mail address and phone number, financial and credit card information, personal description and photograph, health information, and user-generated content. If you login to one of our sites using social login, you will also be giving us access to your social data on the relevant social network.
Information we collect about you:
When you visit our site we may use cookies and other technologies to automatically collect the following information:

  • Technical information, including your IP address, your login information, browser type and version, device identifier, location and time zone setting, browser plug-in types and versions, operating system and platform, page response times, and download errors;
  • Information about your visit, including the websites you visit before and after our site and products you viewed or searched for;
  • Length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.

Emails that we send as part of our marketing programmes use clear gifs (web beacons). These tell us whether the email has been opened. Web beacons can be turned off by not “enabling images” in an email.
We also collect information using cookies to understand how you interact with our advertising content, to make sure we’re delivering this is the most relevant way. We do this on our sites and on third party sites. See our Cookies Policy below for more information.
If you are using one of our mobile apps, we may also collect information about the way you use our app.

Information we receive and collect from other sources:
We may receive information about you if you use any of the other websites we operate (for example a website for another L’Oréal brand) or the other services we provide. We also work closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, and credit reference agencies) and may receive information about you from them. We may also collect information about you from publicly available sources, including publically available content on social media.

HOW DO WE USE YOUR PERSONAL INFORMATION?

We may use your personal information…
To get in touch and provide you with services you have asked for. We may:

  • Send you information about products and surveys that may be of interest to you (where you have consented to this), or offer you opportunities to participate in competitions or surveys;
  • Contact you about a particular type of product where you have started a transaction but not finalised your purchase;
  • Provide you with products or services that you request from us, including carrying out any actions required from your request e.g. process an order that you make (including payment and delivery), or setting up an account with us;
  • Reach you on social media, either directly or through tailored advertising content;
  • Give you updates on any changes to our service;
  • Keep an up to date suppression list where you have asked not to be contacted, so we do not inadvertently re-contact you;
  • Process your payments and protect against fraudulent transactions.
To provide you with a tailored and relevant experience. We may:
  • Deliver relevant advertising tailored to your preferences to you directly on our website or when you visit other websites or social media channels, and measure the effectiveness of that advertising;
  • Combine information we receive and collect from all sources to understand your interests and preferences, and provide you with an experience that is tailored to those interests and preferences e.g. by offering you products you are interested in first on our website, or sending you personalised offers or promotions by email (where you have agreed to receiving our emails), or offering you advertising content that is relevant to your interests;
  • Offer you content that is relevant to your location e.g. invitations to events;
  • Ensure our website, social media pages, and email content and is presented in the most efficient and effective manner for you, including remembering your preferences and interests.
To improve our site and content. We may:
  • Administer, monitor, and improve our site, social media pages, and email content, including troubleshooting, analysis, testing of functions and different site design ideas;
  • As part of our efforts to keep our site safe and secure;
  • Otherwise as required or permitted by law.

DO WE SHARE YOUR PERSONAL INFORMATION?

We may share your personal information within L’Oréal, and with any member of the L’Oréal Group, which means our subsidiaries, and our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006. Please visit www.loreal.com for further details on the L’Oréal Group.
We may also share your information with trusted third parties. We rely on trusted third parties to perform a range of business operations on our behalf. We only provide them with the information they need to perform the service, and we require that they don’t use your information for any other purpose. We will always use our best efforts to ensure that all third parties we work with will keep your personal information secure. We may share your personal information with:

  • Advertising, marketing, digital and social media agencies to help us to deliver advertising, marketing, and campaigns, to analyse their effectiveness, and to manage your contact and questions;
  • Third parties required to deliver a product to you e.g. postal/delivery services;
  • Analytics and search engine providers that assist us in the improvement and optimisation of our site; and
  • Credit reference agencies for the purpose of assessing your credit score and verifying your details where this is a condition of entering into a contract with you.
We may also disclose your personal information to third parties:
  • In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
  • If L’Oréal or a part of its assets are acquired by a third party, in which case personal data held by it about its customers relating to those assets will be one of the transferred assets.
  • If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of use and other agreements; or to protect the rights, property, or safety of L’Oréal, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
  • In other circumstances if we have your consent or we are permitted to do so by law.

We will not sell your personal information.

WHERE WE STORE YOUR PERSONAL INFORMATION

The data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area ("EEA"). It may also be processed by staff operating outside the EEA who work for us or for one of our service providers. By providing us with your personal information, you agree to this transfer, storing or processing. L’Oréal will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy and the Act.

IS MY PERSONAL INFORMATION SECURE?

We are committed to keeping your personal information secure, and take all reasonable precautions to keep your personal information secure, and require that trusted third parties who handle your personal information for us do the same.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal information, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.

LINKS TO THIRD PARTY SITES AND SOCIAL LOGIN

Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

We may also offer you the opportunity to use social login. If you chose to use social login, please be aware that the social platform will share your profile information with us. The information that is shared will depend on your social platform settings.

SOCIAL MEDIA AND USER GENERATED CONTENT

Some of our sites and apps allow users to submit their own content. Please remember that any content submitted to one of our social platforms can be viewed by the public, and you should be cautious about providing certain personal information e.g. financial information or address details via these platforms. We are not responsible for any actions taken by other individuals if you post personal information on one of our social media platforms.

COOKIES

What are they?
A cookie is a small file that a website transfers to the cookie file of the browser on your device so that the website can remember who you are.

We use cookies to help you navigate our website efficiently and to perform certain functions, including site traffic analysis. Cookies may also recognize you on your next log-in and offer you content tailored to your preferences and interests. Cookies do not compromise the security of a website.

Some cookies can collect personal information, including information you disclose like your username, or where cookies track you to deliver more relevant advertising content. For further details on how we use your personal information, please see our Privacy Policy.

There are two types of cookies on our sites – “session” cookies that are temporary cookies that remain on your browser only while you’re on our site, and “persistent” cookies, that remain on your browser for much longer.

Do I want to stop them?
Many cookies are used to enhance the usability or functionality of a website; therefore disabling cookies may prevent you from using certain parts of this website. We explain the cookies we use in the table below and give you a button by which you can block the optional cookies.

If you do not make either choice then you will be treated as having accepted all cookies on this site. You can change your mind in subsequent visits and use the buttons below to change your cookie status for our site.

If you wish to restrict or block all the cookies which are set by our website (which as we say may prevent you from using certain parts of the site), or indeed any other website, you can do this through your browser settings. The Help function within your browser should tell you how. For more information go to www.aboutcookies.org

Which cookies are being used on this site?
We use four different types of cookies on this site – those that are strictly necessary for the website to function, functionality cookies, performance/analytics cookies, and targeted/advertising cookies. 

Strictly Necessary cookies: These are cookies that are essential for our website to work correctly. They may be required for system administration, to prevent fraudulent activity, or for a shopping cart function. These cookies cannot be switched off.

Functionality cookies: These cookies are used to enhance and simplify your user experience. For example, they may remember information about previous choices you have made, remember your password, or allow video or social media content to be properly viewed on the website. You can opt out of functionality cookies using the function below.

Analytics and Performance cookies: These are used for internal purposes to help us understand how you interact with our site, so we can provide you with an improved user experience e.g. to assess the performance of our website, or to test different design ideas for the website. We may work with third parties to perform these services for us, so these cookies may be set by a third party. You can opt out of these cookies using the function below.

Targeting and advertising cookies: These cookies are used to deliver relevant and tailored content (including advertising content) to you, and also to evaluate the effectiveness of that content. This content may be delivered on our websites, or on a third party website. We often work with third parties to deliver this content, so some of these cookies may be set by a third party. You can opt out of them using the function below. You can also opt out of targeted advertising by clicking on the “Ad Choices” logo on our advertising, or at www.youronlinechoices.com/uk/your-ad-choices. Note however by opting out of these cookies you do not opt out of receiving advertising content altogether; you will instead receive general content that does not take into account your interests and preferences.

We also use web beacons in combination with cookies.

Where we work with third parties, they may set cookies to deliver the services that they are providing (e.g. tailored advertising). We make every effort to identify these cookies and detail them below, so that you can choose to opt out.

a. Social Media Networks. On our website we may use social networking icons and sometimes embed video content from websites such as YouTube. As a result when you visit a page with content embedded from for example YouTube or click on a social network icon that takes you to a link to that social site, you will be presented with cookies from Youtube or that site as applicable. We do not control the dissemination of these cookies and you need to check with the applicable third party website for more information.

b. Advertisement. We may put our cookies on websites of our partners broadcasting advertisements for our brands and/or products. These cookies are mainly used to present you appropriate content, corresponding to your interests, and to evaluate the effectiveness of our content (including advertising).

If you wish to change you cookie settings, please use the function below:

Reject or accept optional cookies from the website

I accept the optional cookies on this site
I reject the optional cookies on this site

All cookies used on this website are detailed below

Cookie and status

Purpose

sid/dwsid (mandatory)

Session cookie (soft session killed at the application server level after 30 minutes if no keep alive, hard session killed at the web server level after 6 hours no matter what), sid is kept for backward compatibility reasons."Required to navigate from one page to another and to maintain the login/logout information during your visit. It collects information in an anonymous form by using a unique identifier. Expires after 30 minutes of inactivity or when you end your session."

dwsecuretoken (mandatory)

HTTPS session cookie (same duration as the dwsid i.e. the session duration).
"Required to navigate from one secured pages (https protocole) to maintain information during your visit. It collects information in an anonymous form by using a unique identifier. Expires after 30 minutes of inactivity or when you end your session."

dwanonymous (mandatory)

Anonymous customers tracking, enables the basket persistence, the corresponding ID is also stored in the basket object (6 months).
"Used to store the number of items of the basket when you are internet shopping with us. It collects information in an anonymous form by using a unique identifier. Duration : 6 months."

dwcustomer (optional)

Saved when the "remember me" check box is checked on logging (6 month).
"Related to 'Remenber me' (check box on login form) function that help to identify user after his session has expired. Duration : 6 months."

dwsourcecode (mandatory)

Basically the current source code (cookie duration can be set, 24 hours by default).
"Used when a campaign and promotion are activated on the website with a specific link. Only dropped if there is a promotion. Duration : 24 hours"

dwac (optional)

Analytics cookie (session duration).
"Used to track analytics information on website:
- Conversion report
- Traffic report
- Customer report
Expires when you end your session."

dw (optional)

Used to test whether the browser accepts cookies (session duration).

selectedCountry

Used for country selection and geoIP localization.

searchgridview

 

cookie_policy_acceptance

Records if you have accepted the use of cookies on the website. It does not contain any user information. This cookie remains on your computer after the session has closed.

Duration : 10 years

emailSignUpShown
newsletterPageViewsCounter

Used to show the newsletter popup

__cfduid

Set by the CloudFlare service to identify trusted web traffic

_cq_seg
_cq_bc
_cq_uuid

This cookie saves the click behavior of the user to present personalized product recommendations on the website.

CookiesAccepted

Records if you have accepted the use of cookies on the website. It does not contain any user information. This cookie remains on your computer after the session has closed.

ONDEMANDAUTH

Required to navigate from one page to another and to maintain the login/logout information during your visit. It collects information in an anonymous form by using a unique identifier. Expires after 20 minutes of inactivity or when you end your session.

AdditionalParams

Used to store the number of items and total cost of the basket when you are internet shopping with us. It collects information in an anonymous form by using a unique identifier. Expires when you end your session.

JSESSIONID BIGipServerorderpage

When you are internet shopping with us these two cookies work in relation to the secure payments aspects of the transaction and collect information in an anonymous form using a unique identifier. JSESSIONID expires when you end your session and BIGipServerorderpage expires after two hours.

onetimehomepage

Records whether you have been shown the exclusive offer popup on the home page so as not to show it to you again. It collects information in an anonymous form using a unique identifier. Expires when you end your session.

UserAuthentication

Contains your country code and an anonymous unique identifier used during your previous visit to personalise the content of this website. This cookie remains on your computer after the session has closed.

NID

A persistent cookie set by Google Maps applications.

More info on Google, their cookies are and how to control them

http://www.google.com/policies/privacy/ads/
http://www.google.com/analytics/learn/privacy.html

_ga

This cookie is set up by Goolge company. This cookie is used by Google Analytics servers to calculate user, session, and campaign data.

Duration : 2 years.

-utma
-utmb
-utmc
-utmz

These cookies are used to collect information about how visitors use our site. They are placed on the site by Google, Inc an American Corporation. It collects information in an anonymous form , including the number of visitors to the site, where visitors have come to the site from and the pages they visited on the site. This information is then used by Google to make reports for us and to help us improve the site. For more information visit www.google.com/intl/en/policies/privacy/

bvgacef e.g. bvgacefRatingsAndReviews

Creates an event the first time Bazaar Voice is loaded for a user.

Bazaar Voice Cookie

pfv_(ID)
rfv_(ID),rhf_(ID),rif_(ID)
qfv_(ID),qhf_(ID),qif_(ID)
cfv_(ID),chf_(ID),cif_(ID)

Identifies and remembers user provided feedback through voting on helpfulness, innappropriate and voting/flagging icons. Cookies expires after session has finished.

Bazaar Voice Cookie

r-commented-(ID)s-commented-(ID)

Identifies the reviews on which the user has commented in order to customise display highlighting these comments. Cookies expires after session has finished.

Bazaar Voice Cookie

r-commented-(ID)
s-commented-(ID)

Identifies the reviews on which the user has commented in order to customise display highlighting these comments. Cookies expires after session has finished.

Bazaar Voice Cookie

displayTypePreferred(CODE)

Records whether a user has indicated a preference for Mobile or Desktop version of landing pages through search engines. Cookies expires after session has finished.

Bazaar Voice Cookie

BVSID
BVBRANDSID
BVID

Allows internal Bazaar Voice analytics to be correlated to the same user browsing session for interactions across the Bazaar Voice network. BVSID & BVBRANDSID Cookies expires after session has finished. BVID cookie expires after 18 months.

Bazaar Voice Cookie

Production: bvf_(client checksum)
Staging: bvf_(client checksum)s

Stores a session ID of the user after submission of a review. Cookies expires after session has finished.

Bazaar Voice Cookie

BVImpl{client site name}

Stores user configuration for a/B testing. Cookies expires after session has finished.

Bazaar Voice Cookie

prr-sip
qa-sip
sy-sip
cp-sip

Identifies a submission that is in progress, to enable maintaining of content in case of a refresh by the user.
Cookies expires after session has finished.

Bazaar Voice Cookie

goto
scroll-to-story-id
bvReturnPosition
bvOpenedQ(CODE)
bvProfileActiveTab_(ID)
bvScrollPositionX
bvScrollPostitionY
bvScrollToElementID
bvScrollToElementOffset)

Cookies retain the state of display across pages and/or reloads to enable consistent user experience.
Cookies expires after session has finished.

Bazaar Voice Cookie

mem

Memory widget cookie used to track ordered list of products that a user has visited. Remains on computer for 365 days.

Bazaar Voice Cookie

rm

Identifies users who have chosen to remember their credentials. Is removed upon sign out, or after 365 days.

Bazaar Voice Cookie

CHANGES TO OUR PRIVACY POLICY

Any changes we may make to our Privacy and Cookies Policy in the future will be posted on this page and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to our Privacy and Cookies Policy.

Last updated: September 2017