The Good Apparel Privacy Policy

Effective date: 31 October 2019

In this privacy policy, we explain in detail how we collect, use and disclose your personal data, and what choices you have with respect to your personal data. Please read this Privacy Policy carefully. If, after reading it, you still have any questions, please contact us. 

  1. GENERAL INFORMATION 
  2. THE TYPES AND PURPOSES OF PERSONAL DATA 
  3. NON-PERSONAL DATA 
  4. MARKETING COMMUNICATION 
  5. RETENTION PERIOD 
  6. SHARING AND DISCLOSING DATA 
  7. TRANSFER OF PERSONAL DATA OUTSIDE THE EEA 
  8. SECURITY 
  9. PRIVACY OF CHILDREN 
  10. YOUR RIGHTS REGARDING PERSONAL DATA 
  11. THIRD-PARTY LINKS 
  12. TERM, TERMINATION AND AMENDMENTS 
  13. CONTACT 

 

1. GENERAL INFORMATION
    1.1. Applicability of the Privacy Policy. This The Good Apparel privacy policy (the “Privacy Policy”) governs the processing of personal data collected from individual users and business entities (the “user”, “you” and “your”) through the e-commerce platform available at https://thegoodapparel.com and the related services (collectively, “The Good Apparel”). This Privacy Policy does not apply to any third-party applications or software that integrate with The Good Apparel or any other third-party products, services or businesses.
    1.2. About The Good Apparel. The Good Apparel is an online marketplace for ethical fashion brands that allows consumers (the “Customers”) to purchase clothing items, shoes, and accessories sold by third-party vendors (the “Sellers”).
    1.3. Responsible entity (data controller). The entity that is responsible for the processing of your personal data through The Good Apparel is The Good Apparel LTD having a registered place of business at International House, 24 Holborn Viaduct, London, EC1A 2BN, the United Kingdom, and a business registration number 12130286 (“we”, “us”, and “our”).
    1.4. Definitions. In this Privacy Policy, you will encounter recurrent terms. For your convenience, we would like to explain what such terms mean:
    • Consent” means a freely given, specific, informed and unambiguous agreement to the processing of personal data;
    • Data controller” means the entity that determines the purposes and means of the processing of personal data;
    • Data processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller;
    • Personal data” means any information relating to a natural person who can be identified, directly or indirectly, by using such information (e.g., name, address, email, phone number, and IP address); and
    • Processing” means the use of personal data in any manner, including, but not limited to, collection, storage, erasure, transfer, and disclosure of personal data.
        1.5. Cookies. We use cookies on The Good Apparel. For more information on the types and purposes of the cookies used by us, please refer to our cookie policy available at  https://thegoodapparel.com/pages/cookie-policy
        1.6. Applicable laws. We process personal data in accordance with applicable data protection laws, including, but not limited to, the United Kingdom Data Protection Act 2018 and the EU General Data Protection Regulation (GDPR)
        1.7. Your consent to the Privacy Policy. Your use of The Good Apparel is subject to this Privacy Policy. We encourage you to review the Privacy Policy before submitting any personal data through The Good Apparel. In some cases, we may seek to obtain your consent. For example, we may seek your prior consent in the following situations:
        • If we are required by law to do so;
        • If we intend to collect other types of personal data that are not mentioned in this Privacy Policy and we cannot rely on other lawful grounds;
        • If we intend to use your personal data for the purposes that are not indicated in this Privacy Policy;
        • If we would like to disclose or transfer your personal data to third parties that cannot guarantee an adequate level of protection; or
        • If we significantly amend this Privacy Policy. 

         2. THE TYPES AND PURPOSES OF PERSONAL DATA

        2.1. Types of personal data that we collect. We comply with data minimisation principles and collect only a minimal amount of personal data that is necessary to ensure your proper use of The Good Apparel. The types of personal data that we collect are listed in the table below.

        2.2. Purposes of personal data. We respect strictest data protection principles. Thus, we process your personal data only for specified and legitimate purposes explicitly mentioned in this Privacy Policy. In short, we will use your personal data only for the purposes of enabling you to use the full functionality of The Good Apparel, processing your orders, performing our contractual obligations, maintaining and improving The Good Apparel, conducting research about our business activities, administrative purposes, and replying to your enquiries. The detailed description of the purposes and lawful bases for processing of your personal data is provided in the table below.

         

        Situation/Personal data

        Purpose

        Lawful basis

        When you create a user account as the Customer, we collect your:

        • First name
        • Last name
        • Email address
        • Password
        • To create and maintain your user account
        • To provide access to The Good Apparel
        • To contact you, if necessary
        • To send you notifications about your orders
        • To ensure security of The Good Apparel
        • To maintain administrative records
        • Performing a contract with you
        • Pursuing our legitimate business interests (to ensure security and administer our business)

        When you integrate your products as the Seller through https://jetti.io, we have access to your:

        • First name
        • Last name
        • Company name
        • Email address

         

        • To enable you to sell your products through The Good Apparel
        • To process Customers’ orders
        • To contact you, if necessary
        • To send you notifications about orders
        • To ensure security of The Good Apparel
        • To maintain administrative records
        • Performing a contract with you
        • Pursuing our legitimate business interests (to ensure security and administer our business)

        When you place an order as the Customer, we collect your or recipient’s:

        • Full name
        • Shipping address
        • Billing address
        • Payment details of the chosen payment method (e.g., credit card number, expiration date, and CVC or PayPal account information)
        • To process your payments
        • To inform the Seller about your order
        • To arrange the delivery of the purchased goods
        • To administer our business
        • Performing a contract with you
        • Pursuing our legitimate business interests (accounting and administration)

        When you contact us by email, we collect your:

        • Name
        • Email address
        • Information you provide in your message
        • To respond to your enquiries
        • To provide you with the requested information
        • Pursuing our legitimate business interests (to grow and promote our business)
        • Your consent (for optional personal data)

        When you subscribe for our newsletter, we collect your:

        • Email address
        • To send you the requested newsletter
        • Your consent (optional personal data)

        When you use The Good Apparel, we collect your:

        • IP address
        • To analyse, improve, and evaluate our business activities
        • To personalise The Good Apparel for your location
        • Performing a contract with you
        • Pursuing our legitimate business interests (to analyse and improve our business activities)

         

         2.3. Payment processing. When you make payments through The Good Apparel, the payments are processed by our third-party payment processors Visa, MasterCard, Maestro, American Express, Shopify Pay, Google Pay, Apple Pay, PayPal, TransferWise, and others (collectively, the “Payment Processors”). The Payment Processors are solely responsible for handling your payments. You agree not to hold us liable for payments that do not reach us because you have quoted incorrect payment information or the Payment Processor chosen by you refused the payment for any other reason. Please note that the Payment Processors may collect some personal data from you, which allows them to process your payments (e.g., your email address, address, credit card details, and bank account number). The Payment Processors handle all the steps in the payment process through their systems, including data collection and data processing. We do not store your payment details in our systems, unless it is necessary for accounting and administrative purposes. For more information on the privacy and security practices of the Payment Processors, please refer to the website of the respective Payment Processor.

        2.4. Additional data. We may receive certain additional data when submitted through The Good Apparel if you participate in a focus group, contest, activity or event, request support, interact with our social media accounts, submit your feedback and reviews, or otherwise communicate with us. Please note that the provision of such data is optional and you may choose what personal data you would like to share with us. We kindly request you to exercise your due diligence when making your personal data publicly available. We will use such personal data to reply to you, provide you with the requested services, or for pursuing our legitimate business interests (i.e., to analyse and improve our business).

        2.5. Personal data obtained from third parties. When using The Good Apparel, you can choose to permit or restrict services, functionalities, and integrations provided by third parties, including, but not limited to, third-party payment gateways (the “Third-Party Services”). Once enabled, the providers of the Third-Party Services may share certain information with us, subject to the privacy policy of the Third-Party Services. You are strongly encouraged to check carefully the privacy settings and notices of the Third-Party Services to understand what information may be disclosed to us.

        2.6. Sensitive data. We do not intentionally collect special categories of personal data, such as opinions about your religious and political beliefs, racial origins, membership of a professional or trade association, or information about sexual orientation.

        2.7. Failure to provide personal data. If you fail to provide us with the personal data when requested, we may not be able to perform the requested operation and you may not be able to use the full functionality of The Good Apparel, make payments, receive your orders, or get our response.

         3. NON-PERSONAL DATA

        3.1. Types of non-personal data. When you use The Good Apparel, we may automatically collect certain technical non-personal data about your use of The Good Apparel and your device for analytics purposes. Such non-personal data does not allow us to identify you in any manner. The non-personal data collected by us includes information about:

        • The type of your device;
        • Operating systems and browsers used by you;
        • Your time zone;
        • Your browsing patterns (e.g., time spent and pages visited);
        • Log files; and
        • URL addresses of websites clicked from The Good Apparel and leading to The Good Apparel.
          3.2. Your feedback. If you contact us, we may keep records of any questions, complaints, suggestions, remarks, and compliments made by you and our response, if any. Where possible, we will de-identify your personal data. Please note that de-identified personal data is also considered to be non-personal data. We may use such de-identified data for any legitimate business purposes, including, but not limited to, improving our business activities and promoting The Good Apparel. 
          3.3. Purposes of non-personal data. We will use non-personal data in furtherance of our legitimate interests in operating The Good Apparel, conducting our business activities, and developing new products and services. More specifically, we collect the non-personal data for the following purposes:
          • To analyse what kind of users visit and use The Good Apparel;
          • To identify the channels through which The Good Apparel is accessed and used;
          • To examine the relevance, popularity, and engagement rate of the content available on The Good Apparel;
          • To identify and fix errors;
          • To investigate and help prevent security issues and abuse;
          • To develop and provide additional features to The Good Apparel; and
          • To personalise The Good Apparel for your specific needs.
            3.4. Aggregated data. In case your non-personal data is combined with certain elements of your personal data in a way that allows us to identify you, we will handle such aggregated data as personal data. If your personal data is aggregated or de-identified in a way that it can no longer be associated with an identified or identifiable natural person, it will not be considered personal data and we may use it for any business purpose.

            4. MARKETING COMMUNICATION

            4.1. Marketing messages. After you subscribe for a newsletter, register a user account, or place an order, we will, from time to time, send you marketing messages, such as newsletters, brochures, promotions and advertisements, informing you about new available products, our new services, or new features of The Good Apparel. We will send such marketing communication only if:

            • You provide your express (“opt-in”) consent to receive such marketing messages (your voluntary subscription to our newsletter constitutes such consent); or
            • We would like to inform you about goods similar to the goods already purchased by you.
              4.2. Opting-out. You can opt-out from receiving marketing messages at any time free of charge by clicking on the “unsubscribe” link contained in any of the messages sent to you or by contacting us directly.
              4.3. Informational notices. From time to time, we may send you informational notices, such as service-related, technical or administrative emails, information about your orders, The Good Apparel, your privacy and security, and other important matters. Please note that we will send such notices on an “if-needed” basis and they do not fall within the scope of direct marketing communication that requires your prior consent.


               5. RETENTION PERIOD

              5.1. Retention of personal data. We will store your personal data in our systems only: (i) as long as such personal data is required for the purposes described in this Privacy Policy; (ii) if we are obliged by law to store such data for certain period of time; or (iii) until you request us to delete personal data - whichever comes first. After the personal data is no longer necessary for its purposes and there is no other legal basis for storing it, we will immediately delete such personal data from our systems.

              5.2. Retention of non-personal data. We may retain non-personal data pertaining to you for as long as necessary for the purposes described in this Privacy Policy. This may include keeping non-personal data for the period that is necessary to pursue our legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes and enforce our agreements.

              5.3. Retention as required by law. Please note that, in some cases, we may be obliged by law to store personal data for a certain period of time (e.g., if we have to keep our accountancy records for the time period prescribed by law). In such cases, we will store personal data for the time period stipulated by the applicable law and delete the personal data as soon as the required retention period expires.

               6. SHARING AND DISCLOSING DATA

              6.1. Do we share your personal data? If necessary, we may disclose your personal data to the service providers with whom we cooperate and other third parties (our data processors). For example, we may share your personal and non-personal data with and entities that provide certain technical support services to us, such as hosting, web analytics, payment processing, advertising, shipping, and email distribution services, or if you explicitly request us to disclose the personal data. Moreover, some of your personal data will be disclosed to the Sellers for the purpose of processing your order and delivering you the products purchased by you.

              6.2. When do we share your personal data? The disclosure of your personal data is limited to the situations when such data is required for the following purposes:

              • Ensuring the operation of The Good Apparel;
              • Ensuring the delivery of the products purchased by you;
              • Providing you with the requested information;
              • Pursuing our legitimate business interests;
              • Enforcing our rights, preventing fraud, and security purposes;
              • Carrying out our contractual obligations;
              • Law enforcement purposes; or
              • If you provide your prior consent to such a disclosure.
                6.3. List of data processors. We will share your personal data only with the Sellers and third parties that agree to ensure an adequate level of protection of personal data that is consistent with this Privacy Policy and the applicable data protection laws. The third parties (data processors) that may have access to your personal data are listed below.

                Service

                Name

                Location

                More information

                E-commerce partner

                Shopify

                Canada

                https://www.shopify.com

                Drop-shipping automation service provider

                Jetti

                United Kingdom

                https://jetti.io

                Business analytics service providers

                Google Analytics

                United States

                https://analytics.google.com

                Google Search Console

                United States

                https://search.google.com/search-console/about

                Lucky Orange

                United States

                https://www.luckyorange.com

                Shopify

                Canada

                https://www.shopify.com

                Transactional email service provider

                Mailchimp

                United States

                https://mailchimp.com

                Email service provider

                Gmail

                United States

                https://mail.google.com

                Marketing service providers

                Refersion

                United States

                https://www.refersion.com

                Instagram

                United States

                https://www.instagram.com

                Facebook

                United States

                https://www.facebook.com

                Pinterest

                United States

                https://www.pinterest.com

                Payment processing partners

                PayPal

                United States

                https://www.paypal.com

                Visa

                United States

                https://usa.visa.com

                Mastercard and Maestro

                United States

                https://www.mastercard.us

                American Express

                United States

                https://www.americanexpress.com

                Shopify Pay

                United States

                https://pay.shopify.com

                Google Pay

                United States

                https://pay.google.com

                Apple Pay

                United States

                https://www.apple.com/apple-pay/

                Klarna

                Sweden

                https://www.klarna.com/

                Transfer Wise

                United Kingdom

                https://transferwise.com


                 6.4. Sharing of non-personal data. We may disclose non-personal data and de-identified data for any purpose. For example, we may share it with prospects or partners for business or research purposes, for improving The Good Apparel, responding to lawful requests from public authorities or developing new products and services.

                6.5 Legal requests. If necessary, we will to disclose information about the users of The Good Apparel, if requested by a public authority, to the extent necessary for pursuing a public interest objective, such as national security or law enforcement.

                6.6. Successors. In case our business is sold partly or fully, we will provide your personal data to a purchaser or successor entity and request the successor to handle your personal data in-line with this Privacy Policy.


                 7. 
                TRANSFER OF PERSONAL DATA OUTSIDE THE EEA

                7.1. Some of our data processors listed in Section 7 of this Privacy Policy are located outside the European Economic Area (EEA) and, if you reside in the EEA, we may need to transfer your personal data to jurisdictions outside the EEA. In case it is necessary to make such a transfer, we will make sure that the jurisdiction in which the recipient third party is located guarantees an adequate level of protection for your personal data (e.g., the country in which the recipient is located is white-listed by the European Commission or the recipient is a Privacy-Shield certified entity) or we conclude an agreement with the respective third party that ensures such protection (e.g., a data processing agreement based on the standard contractual clauses provided by the European Commission).


                 8. 
                SECURITY

                8.1. Our security measures. We put our best efforts to keep your personal data safe and secure. We implement organisational and technical information security measures to protect your personal data from unauthorised access and disclosure, loss, and misuse. The security measures taken by us include secured networks (we use SSL encryption), strong passwords, limited access to your personal data by our staff, anonymisation of personal data (when possible), and choosing reliable certified data processors. In order to ensure the security of your personal data, we kindly ask you to use The Good Apparel through a secure network only.

                8.2. Handling security breaches. Although we put our best efforts to protect your personal data, given the nature of communications and information processing technology and the Internet, we cannot be liable for any unlawful destruction, loss, use, copying, modification, leakage, and falsification of your personal data caused by circumstances that are beyond our reasonable control. In case a personal data breach occurs, we will immediately take reasonable measures to mitigate the breach, as required by the applicable law. Our liability for any security breach will be limited to the highest extent permitted by the applicable law.


                 9. 
                PRIVACY OF CHILDREN

                9.1. We do not allow anyone younger than 18 years old to use The Good Apparel. Thus, we do not knowingly and directly collect personal data of persons below the age of 18. If you learn that anyone younger than 18 has unlawfully provided us with personal data and you are a parent or legal guardian of that person, please contact us and we will take immediate steps to delete such personal data.

                9.2. To protect children’s privacy, we encourage parents and legal guardians to monitor their children’s Internet usage and instruct their children not to submit any personal data through The Good Apparel.

                 10. YOUR RIGHTS REGARDING PERSONAL DATA

                10.1. What rights do you have? Individuals located in certain countries, including the EU, have certain statutory rights in relation to their personal data. You may ask us to:

                • Get a copy of your personal data that we store;
                • Get a list of purposes for which your personal data is processed;
                • Rectify inaccurate personal data;
                • Move your personal data to another processor;
                • Delete your personal data from our systems;
                • Object and restrict processing of your personal data;
                • Withdraw your consent; or
                • Process your complaint regarding your personal data.
                    10.2. How to exercise your rights? If you would like to exercise your rights, please contact us by email at help@thegoodapparel.com and explain in detail your request. In order to verify the legitimacy of your request, we may ask you to provide us with an identifying piece of information, so that we could locate you in our system. We will answer your request within a reasonable timeframe but no later than 2 weeks. Your requests can be submitted free of charge once per calendar year. If you submit your requests more than once per year, we reserve the right to charge a small administrative fee for providing the requested information.
                    10.3. How to launch a complaint? If you would like to launch a complaint about the way in which we handle your personal data, we kindly ask you to contact us first and express your concerns. After you contact us, we will investigate your complaint and provide you with our response as soon as possible (no later than 2 weeks). If you are not satisfied with the outcome of your complaint, you have the right to lodge a complaint with your local data protection authority.


                     11.
                     THIRD-PARTY LINKS

                    11.1. The Good Apparel contains links to websites and services that are owned, operated and controlled by third-party service providers. Please note that we are not responsible for the privacy and security practices employed by such third parties. We encourage you to be aware when you leave The Good Apparel and read carefully the privacy statements of each and every website or service that you access.

                    11.2. We advise you to carefully scan every link before clicking on it to ensure the link is not infected and free of any kind of virus or malware that can damage your operating system or device. Even if you did scan the links you should take extra safety and security precautions before accessing those links and carefully assess the security of the website or service that you intend to use. 

                     12. TERM, TERMINATION AND AMENDMENTS

                    12.1. Term and termination. This Privacy Policy enters into force on the effective date indicated at the top of the Privacy Policy and remains valid until terminated or updated by us.

                    12.2. Amendments. We may change this Privacy Policy from time to time to address the changes in laws, regulations, and industry standards. The amended version of the Privacy Policy will be posted on this page with a new effective date and, if we have your email address, we will send you a notice about all the changes implemented by us. We encourage you to review our Privacy Policy to stay informed.

                    12.3. Consent to amendments. For significant material changes in the Privacy Policy or, where required by the applicable law, we may seek your consent. If you disagree with the changes to the Privacy Policy, you should cease using The Good Apparel.

                     13. CONTACT

                    13.1.Please feel free to contact us if you have any questions about the Privacy Policy, our privacy and security practices, or would like to exercise your rights listed in Section 11 of the Privacy Policy. The easiest and quickest way to contact us is by email at help@thegoodapparel.com.

                     

                    ***