Privacy policy

Introduction

Here at PrettyLittleThing.com Ltd (‘PLT’) we are committed to protecting and respecting the privacy of your personal data. This privacy notice explains how your data is collected, used, transferred and disclosed by PLT. It applies to data collected when you use our websites, iOS and android applications, when you interact with us through social media, email, or phone, or when you participate in our competitions or events. It also applies to the extent that someone has nominated you through our "refer a friend" function or purchased an e-gift card on your behalf. It covers:
  • The personal data we collect
  • How we collect your data
  • How we use your data
  • Marketing preferences, adverts and cookies
  • Links to other websites and third parties
  • How we share your data
  • Your rights
  • Changes to this privacy notice
  • How to contact us

Who is PLT

PLT is a leading online fashion retail company known for taking over your social media feeds with our killer looks and next-level aesthetic that’ll have you double tapping. We design, source, market and sell clothing, shoes, accessories and beauty products to consumers in almost every country in the world.
PrettyLittleThing.com Limited (registered number: 7352417) of 49-51 Dale Street, Manchester, M1 2HF (collectively referred to as “PLT”, “we”, “us” and “our” in this Privacy Policy) is the controller and responsible for your personal data collected through the www.prettylittlething.com website (the “website”), www.pltmarketplace.com (the "marketplace") (together, the "websites"), PLT app (the “app”) and PLT Marketplace app (the “Marketplace app”).
Details of our Data Protection Officer responsible for overseeing questions in relation to this privacy notice, and our details are set out in the “Say Hey and Contact Us” section at the end of this notice.


Our commitment to you

We take the protection of your personal data seriously and will process your personal data fairly, lawfully and transparently.
We will only collect and use your personal data for the following purposes, to:
  • fulfil your order(s)
  • fulfil orders made on your behalf (e.g. e-gift card orders)
  • keep you up to date with the latest offers and trends
  • give you a better shopping experience
  • help us to make our marketing more relevant to you and your interests
  • improve our services
  • meet our legal responsibilities

How we keep your data safe and secure

We have appropriate organisational safeguards and security measures in place to protect your data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
The communication between your browser and our website uses a secure encrypted connection wherever your personal data is involved.
We require any third party who is contracted to process your personal data on our behalf to have security measures in place to protect your data and to treat such data in accordance with the law.
In the unfortunate event of a personal data breach, we will notify you and any applicable regulator when we are legally required to do so.


How we collect your data

We may collect personal data about you in the following ways:
Direct interactions you may give us your Identity, Contact, Financial, Transaction, Profile, and Marketing and Communications data (as described above) by filling in forms, entering information online or by corresponding with us by post, phone, email, telephone or otherwise. This includes personal data you provide, for example, when you:
  • Create an account or purchase products on our website;
  • Subscribe to our newsletter, discussion boards, social media sites or create wish lists;
  • Enter a competition;
  • Join a PLT loyalty programme;
  • Complete a voluntary market research survey;
  • Contact us with an enquiry or to report a problem (by phone, email, social media, or messaging service);
  • Use the “refer a friend” function on our website; or
  • When you log in to our website via social media.
Automated technologies or interactions – as you interact with our website, we may automatically collect the following types of data (all as described above): Technical Data about your equipment, Usage Data about your browsing actions and patterns, and Contact Data where tasks carried out via our website remain uncompleted, such as incomplete orders or abandoned baskets. We collect this data by using cookies, server logs and other similar technologies. Please see our Cookie Policy for further details.
Third parties – we may receive personal data about you from various third parties, including:
  • Identity and Contact data from another individual when they purchase an e-gift card for you or use the "refer a friend" function on our website;
  • Technical Data from third parties, including analytics providers such as Google. Please see further information in the section entitled ‘Marketing preferences, adverts and cookies’.
  • Technical Data from affiliate networks through whom you have accessed our website;
  • Identity and Contact Data from social media platforms when you log in to our website using such social media platforms;
  • Identity and Contact data from third parties, including organisations (including law enforcement agencies), associations and groups, who share data for the purposes of fraud prevention and detection and credit risk reduction; and
  • Contact, Financial and Transaction Data from providers of technical, payment and delivery services.

Marketing - Your preferences

We may send you marketing communications and promotional offers:
  • if you have opened an account with us or purchased goods from us, or registered for a promotion or event, and you have not opted out of receiving that marketing (in accordance with your preferences, as explained below);
  • by email if you have signed up for email newsletters;
  • if you have provided us with your details when you entered a competition and you have consented to receiving such marketing (in accordance with your preferences, as explained below).
We may use your Identity, Contact, Technical, Transactional, Usage, Profile Data and Marketing and Communications Data to form a view on what we think you may like, or what may be of interest to you, and to send you details of products and offers which may be relevant for you.
We will ask you for your preferences in relation to receiving marketing communications by email, post, SMS and other communication channels.
From time to time we may also include with your order, inserts advertising goods, services or offers from other third-party companies that you may be interested in.
In respect of third party marketing communications, we will obtain your express opt-in consent before we share your personal data with any third party for marketing purposes.
You will always have full control of your marketing preferences. If you do not wish to continue receiving marketing information from us (or any third party, if applicable) at any time:
  • you can unsubscribe or ‘opt-out’ by using the unsubscribe button and following the link included in the footer of any marketing email; or
  • account holders may withdraw their consent by simply logging in to My Account and editing your ‘Contact Preferences’.
We will process all opt-out requests as soon as possible, but please note that due to the nature of our IT systems and servers it may take a few days for any opt-out request to be implemented.


Cookies

Our website uses cookies to distinguish you from other users of our website and to keep track of your visits. They help us to provide you with the very best experience when you browse our website and to make improvements to our website. They also help us and our advertising networks to make advertising relevant to you and your interests.
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of our website may become inaccessible or not function properly.
For detailed information on the cookies which we and our third-party providers use and the reasons why we use them, please refer to our Cookie Policy.


Online Ads

We use online advertising to keep you aware of what we’re up to and to help you find our products. Like many companies, we may target PLT banners and ads to you when you use other websites and apps, based on your Contact, Technical, Usage and Profile Data. We do this using a variety of digital marketing networks and ad exchanges, and a range of advertising technologies such as web beacons, pixels, ad tags, cookies, and mobile identifiers, as well as specific services offered by some sites and social networks, such as Facebook’s Custom Audience Service.


Our use of analytics & targeting advertising tools

We use a range of analytics and targeted advertising tools to display relevant website content on our website and online advertisements on other websites and apps (as described above) to you, deliver relevant content to you in marketing communications (where applicable), and to measure the effectiveness of the advertising provided. For example, we use tools such as Google Analytics to analyse Google's interest-based advertising data and/or third-party audience data (such as age, marital status, life event, gender and interests) to target and improve our marketing campaigns, marketing strategies and website content. We may also use tools provided by other third parties, such as Facebook, Content Square, Adroll, Responsys, Criteo and Bing to perform similar tasks, using your Contact, Technical, Usage and Profile Data.
In order to opt out of targeted advertising you need to disable your ‘cookies’ in your browser settings (see Cookie Policy for details) or opt-out of the relevant third-party Ad Settings.
For example, you can opt-out of the Google Display Advertising Features. As an added privacy measure, you can also use The Digital Advertising Alliance (which includes companies such as Google, Responsys and Facebook) provides a tool called WebChoices that can perform a quick scan of your computer or mobile devices, find out which participating companies have enabled customised ads for your browser, and adjust your browser preferences accordingly.
If you would like any further information about the data collected by these third parties or the way in which the data is used, please contact us.


Links to other websites and third parties

Our website may include links to and from the websites of our partner networks, advertisers and affiliates, or to social media platforms. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to their websites.


How we share your data

We may disclose and share your personal data with the parties set out below:
where you have consented for us to do so. For example, if you have consented to receive marketing materials from third parties, or in respect of third parties’ (including co-branded or jointly promoted) products and services, we may pass your data on to the relevant third parties for the purpose of sending you such marketing communications;

to business partners, suppliers, sub-contractors and other third parties that we use in connection with the running of our business for the purposes set out in the table above in the section ‘How we use your data’, such as:
  • third party service providers that we engage to provide IT systems and software, and to host our website;
  • third party payment processing services (including Worldpay, Adyen, Paypal, and in certain regions, Klarna, Laybuy and Clearpay (please see T&C’s Klarna / Clearpay / Laybuy for more information) ) to process your payment to us. PLT does not store your payment information. Your payment details are provided to the payment processing service you have selected, who are required to comply with applicable regulations and data protection laws. Please refer to the privacy policy of the relevant provider for details of how they process your personal data;
  • services and to provide marketing and advertising services;
  • third party service providers that we engage to deliver and process your e-gift card orders and e-gift card payment (including Jigsaw Business Solutions Ltd and Stripe Payments UK Ltd)
  • third party service providers that we engage to deliver goods you have ordered and to manage any returns;
  • third party service providers that we engage to send emails and postal mail on our behalf including in relation to incomplete orders or abandoned baskets, or marketing communications, to provide data cleansing services and to provide marketing and advertising services;
  • analytics and search engine providers that assist us in the improvement and optimisation of our website;
  • affiliate networks through whom you have accessed our website;
to any third party to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.

to protect our customers, boohoo group companies and website from fraud and theft, we may share personal data that is required to make identity checks and personal data that we obtain from making identity checks (including data relating to your age, name and location), together with account information, with other boohoo group companies and with third party organisations (including law enforcement agencies), involved in fraud prevention and detection and credit risk reduction. Please note that the other boohoo group companies and these third parties may retain a record of the information that we provide to them for this purpose;

we may share your personal data with Ravelin and/or Risk Guardian and/or other fraud prevention and analysis service providers, in order to carry out fraud prevention checks on our behalf. If personal data is provided to Ravelin, Ravelin will also use this personal data to improve its service and machine learning to improve its automated processing. A copy of Ravelin's privacy notice can be found at: ravelin.com which explains how Ravelin will use your personal data for these purposes; and

we may further share personal data that is required to make identity checks and personal data that we obtain from making identity checks (including data relating to your age, name and location), together with account information, with organisations (including law enforcement agencies), involved in fraud prevention and detection and credit risk reduction. Please note that these third parties may retain a record of the information that we provide to them for this purpose;

if we are under a duty to disclose or share your personal data in order to comply with any legal obligation; or

to our professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.

Worldpay
Worldpay are the data controller in respect of the Personal Information that you give to them (and which they hold about you) when you sign up for, access, or use services, features, technologies or functions offered on the Worldpay website (including when using Worldpay to pay for goods or services offered on the PLT website) and in relation to Personal Information collected during the course of business as set out in their Privacy Policy which can be found on their website at worldpay.com


DO NOT TRACK SIGNALS

We also may use automated data collection technologies to collect information about your online activities over time and across third-party websites or other online services (behavioral tracking). Some web browsers permit you to broadcast a signal to websites and online services indicating a preference that they “do not track” your online activities. At this time, we do not honor such signals and we do not modify what information we collect or how we use that information based upon whether such a signal is broadcast or received by us.


ACCESSING, CORRECTING AND DELETING YOUR PERSONAL DATA

You can review and change your personal data by logging into your account and visiting your account profile page. You may also send us an email at support@helpall0rder.com to request access to, correct or delete any personal data that you have provided to us. We cannot delete your personal data except by also deleting your user account. We may not accommodate a request to change or delete your personal data if we believe the change or deletion would violate any law or legal requirement or cause the information to be incorrect.

JURISDICTION-SPECIFIC PRIVACY RIGHTS

The law in some jurisdictions may provide you with additional rights regarding our use of personal data. To learn more about any additional rights that may be applicable to you as a resident of one of these jurisdictions, please see the privacy addendum for your state that is attached to this privacy notice.


USE OF CHAT TRANSCRIPT

We use transcriptions we record and retain from your chat session to provide you with support and respond to your inquiries, and to help develop and improve our products and services. Our chat service may be provided by a third-party service, however we do not control these third parties’ technology. If you have questions about the use of the chat service, you should contact the chat provider directly. Your chat transcript will be made available to you and we may also share for the above purposes with our subsidiaries and affiliates, and with contractors, service providers, and other third parties we use to support our business.


YOUR CALIFORNIA PRIVACY RIGHTS

If you are a resident of California, you have the additional rights described in the Privacy Notice Addendum for California Residents.


YOUR GDPR PRIVACY RIGHTS

If you are a resident of the European Economic Area, Switzerland, or the United Kingdom, you have the additional rights described in our GDPR Privacy Addendum.


CHANGES TO THIS PRIVACY NOTICE

From time to time we may change this privacy notice. If there are any significant changes we will post updates on our website, applications or let you know by email.


HOW TO CONTACT US

If you have any questions or concerns, please do not hesitate to contact us.
We would love to hear from you, contact us on:
Email:support@helpall0rder.com
Address: 709 53RD ST BROOKLYN,NY 11220


GDPR PRIVACY ADDENDUM

This GDPR Privacy Addendum (the “GDPR Privacy Addendum”) supplements the information contained in our privacy notice and applies solely to customers and users of our websites, iOS and android applications, individuals who interact with us through social media, email, or phone, and individuals that participate in our competition and events that are located in the European Economic Area, the United Kingdom, or Switzerland. We adopt this GDPR Privacy Addendum to comply with the European Union’s General Data Protection Regulation, and any laws implementing the foregoing by any member states of the European Economic Area, the United Kingdom (including the UK Data Protection Act and the UK-GDPR), and or Switzerland (collectively, the “GDPR”). Unless otherwise defined in this GDPR Privacy Addendum, any terms defined in the GDPR or our privacy notice have the same meaning when used in this GDPR Privacy Addendum. When this GDPR Privacy Addendum is applicable to you, it takes precedence over anything contradictory in our privacy notice.
Data Controller and Data Protection Officer
PrettyLittleThing.com Ltd, of 49-51 Dale Street, Manchester M1 2HF (collectively referred to as “PLT”, “we”, “us” and “our” in this privacy notice) is the controller and responsible for your personal data collected through the www.prettylittlething.com website (the “website”) and PLT app (the “app”). Details of our Data Protection Officer responsible for overseeing questions in relation to this privacy notice and our details are set out in the “How to Contact Us” section at the end of this notice.
Information We Collect About You and How We Collect It
The Personal Data we collect and the ways in which we collect it is described in our privacy notice.
The personal data we collect from you is required to enter into a contract with PLT, for PLT to perform under the contract, and to provide you with our products and services. If you refuse to provide such personal data or withdraw your consent to our processing of personal data (when appropriate), then in some cases we may not be able to enter into the contract or fulfill our obligations to you under it.
The legal basis for processing your personal data
We will only collect and process your personal data where we have a legal basis to do so. As a data controller, the legal basis for our collection and use of your personal data varies depending on the manner and purpose for which we collected it.
We will only collect personal data from you when:
we have your consent to do so, or
we need your personal data to perform a contract with you. For example, to process a payment from you, fulfil your order or provide customer support connected with an order, or
the processing is in our legitimate interests and not overridden by your rights, or
we have a legal obligation to collect or disclose personal data from you.

Your Rights
You have several rights under the GDPR. This includes, under certain circumstances, the right to:
request access to your personal data
request correction of your personal data
request erasure of your personal data
request restriction of processing of your personal data
request the transfer of your personal data
object to processing of your personal data
request human intervention for automated decision making
Brief details of each of these rights are set out below. If you wish to exercise any of these rights, please email us at DPO@prettylittlething.com.
Request access to your personal data
You have the right to obtain a copy of the personal data we hold about you and certain information relating to our processing of your personal data.
Request correction of your personal data
You are entitled to have your personal data corrected if it is inaccurate or incomplete. You can update your personal data at any time by logging into your account and updating your details directly, or by emailing us at DPO@prettylittlething.com.
Request erasure of your personal data
This enables you to request that PLT delete your personal data, where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Request restriction of processing of your personal data
You have a right to ask PLT to suspend the processing of your personal data in certain scenarios, for example if you want us to establish the accuracy of the data, or you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it. Where processing is restricted, we are allowed to retain sufficient information about you to ensure that the restriction is respected in future.
Request the transfer of your personal data
You have the right to obtain a digital copy of your personal data or request the transfer of your personal data to another company. Please note though that this right only applies to automated data which you initially provided consent for us to use or where we used the data to perform a contract with you.
Object to processing of your personal data
You have the right to object to the processing of your personal data where we believe we have a legitimate interest in processing it (as explained above). You also have the right to object to our processing of your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your data which override your rights and freedoms.
Request human intervention for automated decision making and profiling
You have the right to request human intervention where we are carrying out automated decision making when processing your personal data. This form of processing is permitted where it is necessary as part of our contract with you, providing that appropriate safeguards are in place or your explicit consent has been obtained.
We will try to respond to all legitimate requests within one month. Occasionally, it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated. We may need to request specific information from you to help us confirm your identity and ensure your right to exercise any of the above rights. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
Right to lodge a complaint
If you have any concerns or complaints regarding the way in which we process your data, please email us directly at DPO@prettylittlething.com. You also have the right to make a complaint to the ICO (the data protection regulator in the UK). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please do contact us in the first instance.
Your data and countries outside of Europe
The personal data we collect from you may be transferred to, and stored at, destinations outside the European Economic Area ("EEA") using legally-provided mechanisms to lawfully transfer data across borders. It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers. Such staff may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support services. We will take all steps necessary to ensure that your data is treated securely and in accordance with this privacy notice.
Whenever we transfer personal data outside the EEA, we will ensure a similar degree of protection is afforded to it by ensuring appropriate safeguards, as required by law, are in place. This may include using specific contractual clauses approved by the European Commission which give personal data the same protection as it has in Europe. More information about these is available at http://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:32010D0087
Please contact us if you want further information on the countries to which we may transfer personal data and the specific mechanism used by us when transferring your personal data outside the EEA.
How long we keep your data for
We will keep your personal data for no longer than is necessary for the purpose(s) it was provided for and to meet our legal obligations. Further details of the periods for which we retain data are available on request.
Changes to this GDPR Addendum
From time to time we may change this GDPR Addendum. If there are any significant changes we will post updates on our website, applications or let you know by email.
How to contact us
If you have any questions or concerns, please do not hesitate to contact us.
We would love to hear from you, contact us on:
Email:support@helpall0rder.com
Address: 709 53RD ST BROOKLYN,NY 11220