CALIFORNIA CONSUMER PRIVACY ACT


This California Consumer Privacy Act Disclosure (“CCPA Disclosure”) supplements the LuluCustom Privacy Policy.The CCPA Disclosure applies to all visitors and customers of our website who reside in the state of California.We adopt this notice to comply with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CPRA”) and any terms defined in the CPRA or the applicable regulations have the same meaning when used in this notice.

A.Categories of Personal Information We Collect

The information that LuluCustom collects or has collected within the last twelve months falls into the following categories established by the California Consumer Privacy Act:

Category A: Identifiers.

Examples: A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers.

Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).

Examples: A name, address, telephone number, credit card number, debit card number, or any other financial information provided while making a purchase or interacting via chat or over the phone with us. Some personal information included in this category may overlap with other categories.

Category C: Protected classification characteristics under California or federal law.

If used as part of a User’s design, personal information collected may include: age, race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex, sexual orientation, veteran or military status.

Category D: Commercial information.

Records and history of products or services purchased or considered.

Category E: Biometric information.

N/A

Category F: Internet or other similar network activity.

Site browsing history, search history, any information related to a user’s interaction with our site, the device they used, and how they were navigated to us.

Category G: Geolocation data.

Approximate physical location.

B.Under CCPA, personal information does not include:

Publicly available information from government records

Deidentified or aggregated consumer information

Information excluded from the CCPA's scope, such as:

Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data

Personal Information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994

C.Sources of Personal Information

We obtain the categories of personal information listed above from the following categories of sources:

Directly from You. For example, when you save a design or make a purchase.

Indirectly from You. For example, from observing your activity on our site.

D.Use of Personal Information for Business Purposes or Commercial Purposes

We may use or disclose personal information We collect for "business purposes" or "commercial purposes" (as defined under the CCPA), which may include the following examples:

To operate, support, personalize, and improve our services.

To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our service.

To fulfill or meet the reason you provided the information. For example, if you asked for a quote, we’ll use that information provided to respond to your inquiry. If you provide your personal information to make a purchase a product, we will use that information to process your payment and facilitate delivery of your order. We may use that information to facilitate new orders or process refunds.

For marketing, advertising, and testing purposes.

To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.

As described to you when collecting your personal information or as otherwise set forth in the CCPA.

For internal administrative and auditing purposes.

To detect security incidents and protect against malicious, deceptive, fraudulent or illegal activity, including, when necessary, to prosecute those responsible for such activities.

Please note that the examples provided above are illustrative and not intended to be exhaustive.

If we decide to collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes, we will update this Privacy Policy.

E.Use of Personal Information

The personal information that LuluCustom has collected in the past twelve months is used for the following business purposes and categories:

To fulfill or meet the reason you provided the information. For example, if you share your name and contact information to request a price quote or ask a question about our services, we will use that personal information to respond to your inquiry. If you provide your personal information to purchase our products and services, we will use that information to process your payment and facilitate delivery of products. We may also save your information to facilitate new product orders or process refunds.

To provide, support, personalize, and develop our services.

To create, maintain, customize, and secure your account with us, as applicable.

For marketing and advertising purposes.

To process your requests, purchases, transactions, and payments and prevent transactional fraud.

To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.

To personalize your experience of our services and to deliver content and product and service offerings relevant to your interests, including targeted offers and ads through our website, third-party sites, and via email or text message (with your consent, where required by law).

To help maintain the safety, security, and integrity of our services, databases and other technology assets, and business.

For testing, research, analysis, and product development, including to develop and improve our services.

To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.

As described to you when collecting your personal information or as otherwise set forth in the CPRA.

To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of LuluCustom’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by LuluCustom about users of our services is among the assets transferred.

As may be otherwise set forth in LuluCustom’s Privacy Policy, in particular in the sections: “How we use your information,” “How we share your information” and “Cookies and other tracking mechanisms.”

LuluCustom will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.

F.Sales of Personal Information

In the twelve months prior to the effective date of this CCPA Disclosure, LuluCustom has not sold any personal information of consumers and has no intent to do so.

G.Share of Personal Information

We may share Your personal information identified in the above categories with the following categories of third parties:

Service Providers

Payment processors

Our affiliates

Our business partners

Third-party vendors to whom you or your agents authorize us to disclose your personal information in connection with products or services we provide to you

H.Your Rights under the CCPA

The CCPA provides California residents with specific rights regarding their personal information. If you are a resident of California, you have the following rights:

The right to notice. You have the right to be notified which categories of Personal Data are being collected and the purposes for which the Personal Data is being used.

The right to request. Under CCPA, you have the right to request that we disclose information to you about our collection, use, sale, disclosure for business purposes and share of personal information. Once We receive and confirm your request, we will disclose to you:

1.The categories of personal information we collected about you

2.The categories of sources for the personal information we collected about you

3.Our business or commercial purpose for collecting or selling that personal information

4.The categories of third parties with whom we share that personal information

5.The specific pieces of personal information we collected about you

6.If we sold your personal information or disclosed your personal information for a     business purpose, we will disclose to You:

7.The categories of personal information categories sold

8.The categories of personal information categories disclosed

The right to say no to the sale of Personal Data (opt-out). You have the right to direct us to not sell your personal information. To submit an opt-out request please contact Us.

The right to delete Personal Data. You have the right to request the deletion of your personal data, subject to certain exceptions. Once we receive and confirm your request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies. We may deny your deletion request if retaining the information is necessary for us or our service providers to:

1.Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.

2.Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.

3.Debug products to identify and repair errors that impair existing intended functionality.

4.Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.

5.Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).

6.Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may likely render impossible or seriously impair the research's achievement if you previously provided informed consent.

7.Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.

8.Comply with a legal obligation.

9.Make other internal and lawful uses of that information that are compatible with the context in which you provided it.

The right not to be discriminated against. You have the right not to be discriminated against for exercising any of your consumer's rights, including by:

1.Denying goods or services to you

2. Charging different prices or rates for goods or services, including the use of discounts or other benefits or imposing penalties

3.Providing a different level or quality of goods or services to you

4.Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services

Correction Rights you have the right to request that LuluCustom correct any inaccurate personal information about you, taking into account the nature of the personal information and the purposes of the processing of the personal information.

I.Exercising Your CCPA Data Protection Rights

In order to exercise any of your rights under the CCPA, and if you are a California resident, you can contact us at [email protected] or call us at 508-603-9448

Your request to us must:

Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative

Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it

We cannot respond to your request or provide you with the required information if we cannot:

Verify your identity or authority to make the request

And confirm that the personal information relates to you

We will disclose and deliver the required information free of charge within 45 days of receiving your verifiable request. The time period to provide the required information may be extended once by an additional 45 days when reasonably necessary and with prior notice.

Any disclosures we provide will only cover the 12-month period preceding the verifiable request's receipt.

For data portability requests, we will select a format to provide your personal information that is readily usable and should allow you to transmit the information from one entity to another entity without hindrance.

J.Non-Discrimination

We will not discriminate against you for exercising any of your CPRA rights. Unless permitted by the CPRA, we will not:

Deny you goods or services.

Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.

Provide you a different level or quality of goods or services.

Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

However, we may offer you certain financial incentives permitted by the CPRA that can result in different prices or rates. Any CPRA-permitted financial incentive we offer will reasonably relate to your personal information's value and contain written terms that describe the program's material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.

K.Children's Privacy

Our Service does not address anyone under the age of 18. Unless you must have the permission and accompaniment of an adult.If we become aware that we have collected personal data from anyone under the age of 18 without verification of parental consent, we take steps to remove that information from our servers.

L.Contact Us

If you have any questions about this privacy policy, you can contact us at [email protected] or call us at 508-603-9448