PRIVACY POLICY
1. ABOUT THIS PRIVACY POLICY

Thank you for visiting our website “Material Girl“. The Website is operated by Iconix Brand Group, Inc., of 1450 Broadway, 3rd Floor, New York, NY 10018 (“we”, “us”, “our” and “ourselves”). The Website is not intended for children under the age of 13 and we do not knowingly collect Personal Information relating to children.

We take the privacy of our Website users and customers seriously. This privacy policy (“Privacy Policy”), which we may update from time to time, explains what personal information (“Personal Information“) is collected from and about you via the Website, what we do with that information and how we protect it. It will also tell you about the rights you have in respect of the Personal Information we retain. We are the data controller and responsible for your Personal Information.
This policy was last updated on 12 November 2020.

You can contact us with any queries about this policy or how we use your Personal Information by writing to us at [email protected]. You can also contact our data protection manager at [email protected].

When you register as a user of the Website or otherwise submit your Personal Information via the Website, including by uploading any content containing your Personal Information (for example by submitting an enquiry to us or completing a form to request we contact you), we shall process your Personal Information only for the purposes and by the means set out in this Privacy Policy. You should ensure that you have read and understood this Privacy Policy together with the Website Terms (of which this Privacy Policy forms part) before submitting your Personal Information to us.

2. INFORMATION COLLECTED
We may collect your name and contact details if you use certain features on our Website. We may also collect your card/payment details if you place an order with us. We do not collect any sensitive personal data (data relating to your racial or ethnic origin, political opinion, religious beliefs, health etc.). Further details of the information we collect and when/how we collect this is set out in the table below.

We collect Personal Information about you via the Website when:

Collection Method Personal Information Collected
You create an account with us using the Website. Name, title, phone number (if provided), email address, home address and details of products you have purchased from us.
You upload content to the Website. Any Personal Information included in such uploaded content (including your name, image etc.).
You submit online forms to us, including by the “Contact Us” page. Name, email address, phone number and any Personal Information contained in your message.
You make any purchases through the Website. Name, email address, billing address, postal address, clothing/shoe size, payment details and details of the products you have purchased from us.
You take part in online surveys or competitions on the Website or any third party site affiliated with us. Name, email address and any other Personal Information required for entry.
Every time you email us your details or correspond with us in other ways. Name, email address, address and any other Personal Information contained in such communication(s).
You subscribe to our newsletter using the Website. Name and email address.
You browse our Website. IP address, login data (to the extent you create an account with us), browser type and version, time zone setting and location, browser plug-in types and versions and operating system and platform.

You should ensure that any Personal Information you provide to us via the Website is true, accurate, current and complete. Please let us know if any of your Personal Information changes by using the contact details above.

When you submit your Personal Information via the Website we will process and store your Personal Information in accordance with this Privacy Policy.

3. WHAT WE DO WITH YOUR PERSONAL INFORMATION
We use your name, contact details and any card/payment details you give to us to provide our products/services to you. We may also use your name and contact details to send you details of our products, events and services we think may be of interest to you. Further details of how we use your Information and our lawful basis for doing so is set out in the table below.

By disclosing your Personal Information to us, you confirm that you agree to the terms of this Privacy Policy. We may obtain, hold and use the Personal Information you provide to us (as set out above) for the following reasons (and have set out next to each reason our lawful basis for such processing):

Personal Data Purpose of Processing Lawful Basis
Name, title, phone number (if provided), email address and home address. To register your Personal Details for an account with us and notify you when we update our privacy policy or terms and conditions. Our performance of our contract with you.
Any Personal Information included in content you upload to the Website (including your name, image etc.). To enable you to use any interactive features of the Website, including uploading content, when you choose to do so. Your consent, unless we notify you that another lawful basis applies for a particular feature.
Name, email address, phone number and any other Personal Information contained in your enquiry/request. To deal with your enquiries and requests. Necessary for our legitimate interests of providing high quality customer service to you and dealing with your requests.
Name, email address, clothes/shoe size, billing address, postal address, payment details and details of the products you have purchased from us. To enable us to process any orders you place using the Website and fulfil, or to allow our third party licensees (see below) to fulfil, your order for products and services. We will also use these details to process payment. Our performance of our contract with you.
IP address, login data (to the extent you create an account with us), browser type and version, time zone setting and location, browser plug-in types and versions and operating system and platform. For quality control, administration of the Website and to ensure that we can provide you with the best possible service. Necessary for our legitimate interests of managing, maintaining and improving our Website and business and, where necessary pursuant to applicable laws, your consent.
IP address, login data (to the extent you create an account with us), browser type and version, time zone setting and location, browser plug-in types and versions and operating system and platform. To use data analytics to measure the effectiveness of and improve our Website and to share aggregated (anonymised) data with our third party licensees to assist them in improving their sales channels. Necessary for our legitimate interests of managing, maintaining and improving our Website and business and, where necessary pursuant to applicable laws, your consent.
Name, email address and any other Personal Information required for entry to such research, survey or competition. To carry out market research, surveys and competitions. Necessary for our legitimate interests of evaluating our business strategy, getting to know our customers and target market and improving our business (and Website).
Name, email address and details of products/services purchased by you. To provide you with information, by email and SMS, about products/services that we think may be of interest to you. Necessary for our legitimate interests of communicating with our customers and providing updates in respect of new products/services we offer.
Name and email address. To send you our newsletter by email. Your consent.

We only keep your Personal Information for as long as is necessary and you have the right (in certain circumstances) to request that we delete such information.

You should be aware that any information or material you post in public areas on the Website (such as message boards) may be seen, collected and used by others, and may result in unsolicited messages from other users or parties. Alas, we cannot control this; you post at your own risk. Please see the Website Terms for further information.

We will only use your Personal Information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your Personal Information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your Personal Information without your knowledge or consent where this is required or permitted by law.

4. MARKETING
We may send you marketing communications by post, SMS, email and/or telephone about our products, services and events which we think may be of interest to you. You can unsubscribe from receiving these communications at any time by notifying us using the details below or following the link in our emails.

As set out above, we may use your Personal Information to provide you with marketing information that you request or that we feel may interest you. We will do this by post, SMS, email or telephone as set out in this Privacy Policy.

We may contact you by email and/or SMS with information about products and services that are similar to those we have previously provided to you.

You may ask us at any time not to use your Personal Information for marketing purposes by contacting us at [email protected] or texting “STOP” in the case of SMS.

If you wish to unsubscribe from emails and/or other communications sent by us, you may do so at any time by clicking on the “unsubscribe” link that appears in our email messages or by contacting us at [email protected].

5. DISCLOSURE OF YOUR PERSONAL INFORMATION
We do not sell any of your Personal Information. We may need to share your Personal Information with our group companies, licensees and service providers but will (subject to very limited exceptions) do so only for the purpose of our contract with you, including providing any requested products/services to you (please see below for further details). Any sharing of your Personal Information is carried out in a safe and secure way.

We may share or transfer your Personal Information and non-personally identifiable information to:

  1. Our group companies (and to our/their successors in title) who may be based overseas and who we need to share your Personal Information with in order to perform our contract to provide products/services to you and (in respect of aggregated data) to improve the business performance of our group;
  2. Our third party licensees who may be based overseas and who we need to share your Personal Information with in order to perform our contract to provide products/services to you;
  3. Third parties that provide services to us and/or who we engage to process Personal Information on our behalf (please see below for further details);
  4. Third parties if we buy or sell any company or assets;
  5. Our professional advisers including lawyers, bankers, auditors and insurers who provide professional services to us (or our group companies); and
  6. regulatory authorities (to the extent required by law or regulation).

We may share or transfer your Personal Information to the following categories of third party service providers/processors:

  1. Our IT service provider (who is based in the United States);
  2. Our email storage system/server provider (which is hosted in the United States);
  3. Our CMS application providers;
  4. Our payment processors;
  5. Our secure shredding providers; and
  6. Our marketing agencies.

We will not disclose your Personal Information to any other third parties except when:

  1. We believe in good faith that, amongst other things, disclosure is necessary to lessen or prevent:
    1. A serious and imminent threat to your life, health or safety; or
    2. A serious threat to public health or public safety; or
  2. Ub. unlawful activity has been, is being or may be engaged in; in such circumstances we may use or disclose your Personal Information as a necessary part of our investigation of the matter or in reporting our concern to relevant persons or authorities; or
  3. Enforcing or applying our Website Terms or any other agreements or to protect our rights or the rights of a third party; or
  4. Required or authorised by or under law (including, without limitation, Sarbanes Oxley Act audits),

In each case, we shall only disclose such Personal Information as is necessary to satisfy the purpose of such disclosure.

We will not sell or rent your Personal Information to third parties without your consent. We require all third parties to respect the security of your Personal Information and to treat it in accordance with the law. We do not allow our third party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

6. TRANSFERS OF YOUR PERSONAL INFORMATION OUTSIDE THE EUROPEAN ECONOMIC AREA
As we are a global organisation, we may transfer your Personal Information outside of the European Economic Area but only for the purpose of our contract with you, including providing our products/services to you and with appropriate safeguards in place.

As we are a US led company, our group companies, licensees, representatives (including clubs, sports people, spokespersons and related parties) and other third parties (to the extent we have identified at section 5 above) we may transfer your Personal Information to in accordance with this Privacy Policy may be located in countries both inside and outside the European Economic Area (the “EEA”).

Although countries outside the EEA may not require the same level of protection of Personal Information as countries within the EEA, we always demand that our group companies, licensees, partners and other third parties adhere to the same procedures that we follow ourselves with respect to your Personal Information, including this Privacy Policy. We do this by ensuring at least one of the following safeguards is implemented:

  1. The country to which the Personal Information is being transferred has been deemed to provide an adequate level of protection for Personal Information by the European Commission.
  2. We may use specific contracts (or certification schemes) approved by the European Commission which give Personal Information the same protection it has in Europe.

If you would like further information about the measures we take to protect your Personal Information when it is transferred outside of the EEA, please contact us using the details set out above.

7. USE OF COOKIES
The Website uses “cookies” to help improve your online experience by identifying you as a user without needing to ask for details each time you visit the Website.

A cookie is a text-only string of information that a website transfers to the cookie file of the browser on your computer’s hard disk so that the website can remember who you are. A cookie will typically contain the name of the domain from which the cookie has come, the “lifetime” of the cookie and a value, usually a randomly generated unique number. Cookies cannot be used to run programs or deliver viruses to your computer and are safe. Click here to find out more about cookies (www.allaboutcookies.org/cookies).

Cookies are uniquely assigned to you and can only be read by a web server in the domain that issued the cookie to you.

Our cookies do not collect or store Personal Information; we only store standard internet log data for our internal reporting purposes, which we do to find out things such as the number of visitors to the various parts of the Website. We collect this information in a way that does not identify anyone, keeping your privacy as well as allowing us to improve the Website and your experience wherever possible.

You have the ability to accept or decline cookies. Most browsers automatically accept cookies but you can modify your browser setting to decline cookies if you prefer. If you choose to decline cookies, you may not be able to fully experience the interactive features of the Website or our services. Unless you have adjusted your browser settings to decline cookies you are deemed to have consented to our use of cookies and the Website will issue cookies when you access it.

In order to enable you to keep browsing efficiently, we may use “session” cookies on the Website. “Session” cookies are temporary and are erased when you close your browser. We may use “session” cookies for the following purposes:

  1. To help us to recognise you when you move between pages on the Website;
  2. To note the pages that you visit on the Website;
  3. To allow us to enhance your experience of the Website; and/or
  4. To compile anonymous statistics about your browsing patterns and to build up a demographic profile (should we use cookies in this way, you will not be personally identified and any information collected will only be used in aggregate form for reporting purposes).

Advertisers on the Website may also use cookies.

8. PRIZE DRAWS AND COMPETITIONS
From time to time, we may run prize draws and competitions on the Website. Entry to these prize draws and competitions is entirely voluntary and you are under no obligation to enter. Should you choose to enter, we recommend that you read and print out the terms and conditions and any applicable privacy notice relating to the prize draw or competition in question, as these may include additional information about how we may use your Personal Information in relation to that particular prize draw or competition.

9. PARENTS
We are committed to the safety and privacy of children (under 18s) who visit and participate in our services. For those activities that require us to collect Personal Information (e.g. competitions), we will only collect Personal Information that is necessary to enable us to administer the relevant activity. We encourage parents and guardians to watch over their children’s online use. Please educate your children to always ask for your permission before they provide Personal Information.

10. CHILDREN
Children under the age of 13 should not use our Website. Remember to be smart and safe online. Always ask your parent or guardian for permission before you give out any Personal Information. This could include your name, email address, home address, telephone number, a photograph or video, your school or any other information about yourself that would enable someone to contact you either online or offline.

From time to time we run online competitions that you may be able to enter. Always remember to ask your parent or guardian for permission before entering any competition.

11. LINKS WITH THIRD PARTY WEBSITES
Links on the Website and other websites that we operate may lead to third party websites. Please note that we are not responsible for the privacy practices of other websites. This Privacy Policy only applies to the Personal Information we collect via the Website. We encourage you to read the privacy policies of other websites you link to from our Website or otherwise visit.

12. SECURITY OF INFORMATION
We take all reasonable measures to ensure that any Information you provide to us is stored securely. Please see below for further information.

We take reasonable steps to preserve the security of your Personal Information, both online and offline. All your Personal Information is stored on our secure servers (some of which are located outside of the EEA, please see section 6 above).

If you have a username, password or other login details that enable you to access certain parts of the Website you must not allow any other person to use them and must treat them as confidential; you should not share this information with anyone. You are responsible for all use and communications with the Website that take place using your registration or password. If you believe or suspect that someone else knows your login details you must contact us at [email protected] as soon as possible.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will apply our normal procedures and comply with legal requirements to protect your Personal Information, we cannot guarantee the security of information transmitted to the Website and any transmission is at your own risk. Once we have received your Personal Information we will use strict procedures and security features to try to prevent unauthorised access (including virus/spam/malware protection software, technical and physical security measures and confidential waste disposal). We also ensure that access to your Personal Information is limited only to those employees, agents, contractors, licensees and other partners who have a business need to know such information and they will only process your Personal Information on our instructions and subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected Personal Information breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

13. RETENTION OF PERSONAL INFORMATION
Data protection laws mean that we should not keep your Information for longer than is required to complete the purpose for which it was collected. We have set out below the period for which we hold your Information (which will vary depending on why we are holding your Information).

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting or reporting requirements.

To determine our retention periods, we have considered the amount, nature and sensitivity of your Personal Information, the potential risk of harm from unauthorised use or disclosure of your Personal Information, the purposes for which we process your Personal Information and whether we can achieve those purposes through other means, and the applicable legal requirements.

By law, we have to keep basic Personal Information about our customers (including your name, contact details, payment details and purchase history) for seven years after your previous order with us.

Where you have provided your Personal Information to sign up for our newsletter, or create an account with us, we will retain your information for such time as you wish to continue receiving such newsletter/holding an account with us or, if earlier, you have not engaged with us for at least 2 years.

Where you have provided your Personal Information in the course of completing any market research, survey or competition, we will retain your Personal Information for 12 months.

Where you upload Personal Information to our Website as part of any interactive feature available, we will retain your Personal Information for such time as such Personal Information continues to be included on our Website.

Where you provide your Personal Information to us in the course of making an enquiry, we will retain such Personal Information for 12 months.

In some circumstances, you may be able to ask us to delete your Personal Information (please see section 15).

14. NOTIFICATION OF CHANGES TO OUR PRIVACY POLICY
This is our current Privacy Policy. It replaces any other Privacy Policy for the Website. We reserve the right to change this Privacy Policy by publishing the amended Privacy Policy on the Website without notifying you. Our rights to use your Personal Information will be based on the Privacy Policy in effect at the time the information is used. If the preceding sentence is deemed to violate applicable law, the Privacy Policy in effect at the time your Personal Information was collected will apply.

15. DATA PROTECTION INFORMATION AND YOUR LEGAL RIGHTS
You have various rights relating to your Information, details of which are set out below. You should contact our Data Protection Manager at [email protected] if you would like to exercise or discuss any of these rights.

In the UK, the General Data Protection Regulation and Data Protection Bill (along with any applicable e-privacy laws and regulations) provide the framework for the safety and security of personal data and the uses to which such personal data is put. The Information Commissioner is the UK’s supervisory authority for data protection issues and was set up to protect personal information and provide information to individuals and organisations. Please see www.ico.gov.uk for more information.

You have the following rights in respect of your Personal Information:

  1. A right to request access to the Personal Information we are holding about you;
  2. A right to request that your Personal Information be rectified;
  3. A right (in certain circumstances) to object to the processing of your Personal Information;
  4. A right (in certain circumstances) to request deletion of your Personal Information;
  5. A right (in certain circumstances) to restrict our processing of your Personal Information;
  6. A right (in certain circumstances) to portability of your Personal Information; and
  7. A right to withdraw your consent to our processing of your Personal Information.

To exercise any of these rights, please contact us at [email protected]. To enable us to comply with your request, we may require proof of your identity or additional information to confirm your right to make the request or to help us respond to your request more quickly. We try to respond to all legitimate requests within one month of receipt but occasionally it may take us longer if the request is particularly complex or involves a large volume of Personal Information.

If you believe the Personal Information we hold about you to be out of date or inaccurate or you have any comments or questions about this Privacy Policy, please email us at [email protected].

If you have a complaint about how we have used your Personal Information you have the right to complain to the Information Commissioner’s Office, although we request that you contact us first before escalating your complaint.

16. JURISDICTION
We are based in the United States and are governed by U.S. law. By accessing or using our Website, or otherwise providing information to us, you acknowledge that we collect, process, transfer and store your Personal Information in the United States and other applicable territories in which the privacy laws may not be as comprehensive as or equivalent to those in the country where you reside and/or are a citizen. We will however make sure that your Personal Information is as safe as in the country where you reside.