Virginia Privacy Notice

Last Updated Date: January 31, 2023

Unless otherwise defined in this Virginia Privacy Notice (this “Notice”), all terms defined in the Privacy Policy and all other terms defined in the Virginia Consumer Data Protection Act of 2021 (“VCDPA”) retain the same meaning when used in this Notice.  

SCOPE

This Notice supplements the information contained in our Privacy Policy and applies solely to individual residents of Virginia (“consumers” or “you”).

This Notice describes how we collect, use, disclose and otherwise process personal data of individual residents of Virginia, within the scope of the VCDPA.

PERSONAL DATA DISCLOSURES

When we use the term “personal data” in this Notice, we mean information that is linked or reasonably linkable to an identified or identifiable natural person.

For the purposes of this Notice, personal data does not include:

  • Deidentified data that is maintained in a form that cannot reasonably be used to link to an identified or identifiable person, or a device linked to such person.
  • Publicly available information from federal, state or local government records or information that we have a reasonable basis to believe was lawfully made available to the general public through widely distributed media by the consumer or a person to whom the consumer disclosed the information without restrictions.
  • Information about job applicants, employees and other personnel.
  • Information about the employees and other representatives of third-party entities who we may interact with in a commercial context.

We process the categories of personal data further described in the “Types of Personal Information We Collect” section of the Privacy Policy and as shown in the table below.

As described further in the “How We Share Your Personal Information” section of the Privacy Policy, we share personal data internally among the Health & Wellbeing Group of Companies and Brands in the United States and with service providers or processors that help us operate our Platform and business. We may also share personal data with a variety of third parties, including for marketing purposes; if we are subject to certain corporate transactions or reorganizations; with third parties to comply with law or to protect our rights or the rights and safety of others; or for purposes otherwise disclosed or for which you have consented.

For purposes of this Notice, when we use the term “third party” we mean entities that are not a Health & Wellbeing affiliate or processors providing services on behalf of Health & Wellbeing and that are not entities with whom you interact with directly.

We have collected each of the categories of personal data noted in the table below and disclosed it to the categories of third parties listed below. The table also indicates when we sold the personal data to third parties or processed such information for targeted advertising.

Category of Personal Data

Categories of Third Parties to Whom Personal Data is Disclosed for Specific Processing Purposes

Sold or Shared with Third Parties for Targeted Advertising

Categories of Third Parties to Whom Personal Data Is Sold or Shared for Targeted Advertising

Identifiers, such as name, email address and other information.

Service Providers and Business Partners

Yes

Business Partners, Online Advertising Networks, Analytics Vendors, and Social Media Networks

Protected Classification Characteristics, such as age, ethnicity and gender.

Service Providers and Business Partners

Yes

Business Partners, Online Advertising Networks, Analytics Vendors, and Social Media Networks

Commercial Information, such as Shopping History and other information relating to your hobbies, interests and shopping behavior.

Service Providers and Business Partners

Yes

Business Partners, Online Advertising Networks, Analytics Vendors, and Social Media Networks

Biometric Data, such as fingerprint, voiceprint, eye retinas or other unique biological patterns generated by automatic measurements when used to identify a specific individual.

Service Providers and Business Partners

No

N/A

Internet/Network Information, such as IP address, Device Information, and Log and Analytics Data.

Service Providers and Business Partners

Yes

Business Partners, Online Advertising Networks, Analytics Vendors, and Social Media Networks

Geolocation Data, such as Location Information from your device or estimated based on your IP address.

Service Providers and Business Partners

Yes

Business Partners and Online Advertising Networks

Sensory Information, such as recordings of phone calls between you and us, where permitted by law.

Service Providers and Business Partners

No

N/A

Other Personal Information, such as information you post on our Platform or on social media pages, and information you submit to us.

Service Providers and Business Partners

Yes

Business Partners, Online Advertising Networks, Analytics Vendors, and Social Media Networks

Profiles, such as information generated by automated processes performed on personal data to evaluate, analyze or predict your interests, economic situation, health, behavior, location, reliability, movements or preferences.

Service Providers and Business Partners

Yes

Business Partners, Online Advertising Networks, Analytics Vendors, and Social Media Networks

Sensitive Data, such as data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data for the purpose of identifying you individually, or precise geolocation data.

Service Providers and Business Partners

No

N/A

We sell personal data and process it for targeted advertising purposes.  Targeted advertising means when we display advertisements to you based on information we obtain about you through nonaffiliated websites or online applications to predict your interests.  Please see your rights to opt out from these activities listed in the How to Exercise Your Privacy Rights Section below. 

We process personal data for different purposes, depending on how you interact with the Platform.  We process personal data about you for the purposes described in the “How We Use Your Personal Information” section of the Privacy Policy.

We sell or share your personal data for the purposes further described in the “How We Share Your Personal Information” section of the Privacy Policy.

YOUR PRIVACY RIGHTS

As a Virginia resident, you may be able to exercise the following rights in relation to the personal data that we have collected about you (subject to certain limitations at law):

Right to Know

The right to confirm whether or not we are processing your personal data.

Right to Access / Data Portability

The right to access and obtain a copy of personal data you previously provided to us, in a readily usable format that allows you to transmit the information to another entity without hindrance, to the extent technically feasible.

Right to Correct

The right to request us to correct inaccuracies in the personal data we maintain about you.  

Right to Request Deletion

The right to request the deletion of personal data we have collected from or about you, subject to certain exceptions.

Right to Opt Out

The right to direct us not to process your personal data for certain types of targeted advertising, to sell your personal data, or to process your personal data for profiling in furtherance of decisions that produce legal or similarly significant effects on you.

DO NOT SELL OR SHARE MY PERSONAL DATA

Right to Appeal

The right to submit an appeal if your request is denied.

HOW TO EXERCISE YOUR PRIVACY RIGHTS

To Exercise Your Rights to Know, Access / Data Portability, Correct, or Delete

Please submit a request by filling out our Privacy Rights Request Form or by calling 1-844-HEY-OLLY (1-844-439-6559) (Monday through Friday, 9:00 AM – 5:00 PM PT).

We will need to verify your identity and confirm you are a resident of the Commonwealth of Virginia before processing most requests, which may require us to request additional personal data from you. In order to verify your identity, we will generally require either the successful authentication of your account, or the matching of sufficient information you provide us to the information we maintain about you in our systems. Please provide your name, email address and mailing address in the original request, as well as an explanation of the rights you wish to exercise. We will only use the personal data provided in connection with a Virginia Privacy Rights Request to review and comply with the request. If you do not provide this information, we may not be able to verify or complete your request in all circumstances.

If you wish to submit a verifiable consumer request on behalf of a minor child, we will also need sufficient information to verify that the individual is the person about whom we collected personal data and that you are authorized to submit the request on their behalf.

In certain circumstances, we may decline a request to exercise the rights described above. If your request is denied, we will provide an explanation for the denial and instructions on how you may appeal a denied request. You may appeal a denied request by contacting us at hello@OLLY.com.

To Exercise Your Right to Opt Out of Targeted Advertising, Sales, or Profiling

You do not need to create an account with us to exercise your Right to Opt Out of Targeted Advertising, Sales or Profiling. However, we may ask you to provide additional personal data (including your name, email address and mailing address) so that we can properly identify you in our dataset to facilitate the opt-out request. If you choose not to provide this information, we may only be able to process your request to the extent we are able to identify you in our data systems.

Once you make an opt-out request, you may change your mind and opt back in to personal data sales at any time by contacting us at hello@OLLY.com.

To exercise your right to opt-out of targeted advertising, personal data sales, or profiling, please submit a request by clicking the button below:

DO NOT SELL OR SHARE MY PERSONAL DATA

In addition, as is common practice among companies that operate online, we permit third party advertising networks, social media companies and other third party businesses to collect personal data directly from your browser or device through cookies or similar online tracking technologies when you visit or interact with our websites, use our apps or otherwise engage with us. For example, they may collect Internet/Network information, such as a cookie or device ID, browsing history and website usage, geolocation data, commercial information related to your transactions, and inferences generated from your browsing history and interactions with our service as well as other sites and services. These third parties use this information for the purposes of serving ads that are more relevant and targeted, for ad campaign measurement and analytics, and for fraud detection and reporting and may sell or share that information with other businesses for advertising and other purposes.  By visiting the bottom of a Health & Wellbeing brand homepage that links to this Notice and clicking on “AdChoices – Do Not Sell or Share” at the bottom of the page, you will be taken to a tool which will allow you to opt out of certain online, targeted advertising and tracking activities. Please see the section entitled “Online Advertising and Third Party Tracking” in our Privacy Policy to learn how you may exercise your choice over this data collection for advertising purposes.

Sensitive Data and Personal Data of Children Under Age 13

We will only process your Sensitive Data in accordance with applicable law, including obtaining your consent prior to processing. We will not process personal data of consumers we know to be less than 13 years of age unless we receive affirmative authorization from the parent or guardian of a child less than 13 years of age. If a parent, guardian or child has provided affirmative authorization, they may opt out of future processing at any time by contacting us at hello@OLLY.com.

NONDISCRIMINATION

We do not discriminate against you in processing your data in accordance with applicable laws or for requesting any of the rights noted above. We are permitted to deny or limit your request in accordance with applicable laws.

HOW TO CONTACT US

If you have any questions, comments or concerns with respect to our privacy practices or this Notice, or wish to update your information, please feel free to contact us at hello@OLLY.com or by telephone at 1-844-HEY-OLLY (1-844-439-6559) (Monday through Friday, 9:00 AM – 5:00 PM PT).

 

CHANGES IN NOTICE

From time to time, we may change our Notice. We will notify you of any material changes to our Notice as required by law. We will also post an updated copy of this Notice on our Platform. Please check our Platform periodically for updates.