Cozy Earth is committed to protecting your online privacy while providing you with a useful web experience. This Privacy Policy (the “Policy”) describes how your personal information is collected, used and shared by Cozy Earth when you visit our online properties, including our website at https://cozyearth.com, our social media pages or handles, and any websites or mobile applications that link to it (the “Sites”). 

This Policy does not override any specific contracts agreed to by the parties and relationships that may be governed by further privacy agreements. If you are engaging with us on behalf of others in your company or otherwise providing the personal information of others, by engaging with us, you acknowledge and agree that you have the consent of those individuals. 

We may change this Policy from time to time. If we do, we will notify you by posting the updated version. With the use of our Site, you consent to the collection, use, and disclosure of your personal information by Cozy Earth in accordance with the terms of this Policy.

Notice at Collection

Cozy Earth may collect or process various categories of personal information, such as when you use our Sites. The Information we collect section contains information on the categories of personal information collected, which generally includes: personal and online identifiers; financial information; commercial information; internet or other electronic network activity information; and sensitive personal information such, as  precise geolocation information, your state ID card, or health information. We collect this information to provide, maintain, and improve our products and Sites, including your online ordering experience, and for other reasons listed in Purposes of Processing and How we share and disclose information. We will retain your information for as long as needed to fulfill the purpose for which it was collected and to comply with our legal obligations, resolve disputes, and enforce our agreements, as outlined in How long we keep your data. We only collect sensitive personal information to provide our Site or Solutions and we delete this information as soon as our Solutions are complete. We may disclose your personal information as outlined in the section How we share and disclose information. We may sell or share Commercial and Financial Information, Internet Activity, Online Identifiers, and Personal Identifiers. To exercise your right to opt-out of the sale or sharing of your personal information for targeted advertising, please click here, or contact us to limit our use of your sensitive personal information.

Information we collect

Information you provide to us

We collect the personal information you provide to us when you purchase our products or visit our website. The categories of information we may collect include:

  • Personal Identifiers, including name, email address, postal address, and telephone number
  • Commercial and Financial Information, including purchases and credit card or debit card number
  • Inferences, including inferences from other data

To the extent we process deidentified personal information, we will make no attempt to reidentify such data.

Information collected automatically

We automatically collect internet or other electronic information about you when you visit our website, such as IP address, browsing history and interactions with our website. This data may be collected using browser cookies and other unique personal identifiers.

Browser Cookies.

We use cookies to create a better experience for you on our site. For example, cookies prevent you from having to login repeatedly, and they help us remember items you've added to your cart. We also use third-party cookies, such as Google Analytics, which are cookies placed by third parties for advertising and analytics purposes. You can control these cookies through your browser settings. To opt-out of the vendors we use for cross-device linking, go to the Digital Advertising Alliance’s Choices page at www.aboutads.info/choices and perform a global opt-out on each browser and device that you would like to be opted out on. To opt-out of our interest-based advertising online and in third-party mobile applications, visit Digital Advertising Alliance’s Choices page here and perform a global opt-out.

The “Do Not Track” (DNT) privacy preference is an option that may be made available in some web browsers allowing you to opt-out of tracking by websites and online services. At this time, global standard DNT technology is not yet finalized and not all browsers support DNT. We therefore do not recognize DNT signals and do not respond to them.

Information from other sources

We may collect personal information about you from third-party sources, including Other consumers (e.g., referrals) and Retail Partners.

Other consumers (e.g., referrals)

  • Personal Identifiers, including Name and Email address

Retail Partners

  • Personal Identifiers, including Name and Postal address
  • Commercial and Financial Information, including Purchases

How long we keep your data

We do not retain data for any longer than is necessary for the purposes described in this Policy.

We generally retain data according to the guidelines below.

Type of DataRetention Period
Cookies and online data we collect while you use our website, including Online Identifiers, Internet ActivityWe delete or anonymize data concerning your use of our website within 10 years of collecting it.
Data we collect in order to process and ship orders you place with us, including Name, Email address, Postal address, Telephone number, Online Identifiers, Internet Activity, Purchases, Credit card or debit card numberWe keep personal information related to products and services you purchase for as long as the personal data is required for us to fulfill our contract with you, and for 10 years from your last purchase with us. We may keep data beyond this period in anonymized form.
Data we collect when you contact us for customer support and other inquiries, including Name, Email address, Postal address, Telephone number, Purchases, Credit card or debit card numberWe keep customer feedback and correspondence with our customer service for up to 2 years to help us respond to any questions or complaints. We may keep data beyond this period in anonymized form.
Data we collect when you sign up for promotional and marketing communications, including Name, Email address, Postal address, Telephone number, Online Identifiers, Internet Activity, Purchases, Inferences from other dataWhere you have signed up to receive promotional and marketing communications from us, we will retain any data collected until you opt out or request its deletion. We may keep data beyond this period in anonymized form. We will further retain a record of any opt-outs in order to prevent sending you future communications.
Data we collect when you review our products, answer surveys, or send feedback, including Name, Email address, Internet Activity, Purchases, Inferences from other dataWe retain review, survey, and feedback data for up to 5 years following your last contact with us. We may keep data beyond this period in anonymized form to help improve our products and services.
Data we collect in connection with privacy requests, including Name, Email address, Online Identifiers, Internet ActivityWe retain records related to privacy requests for a minimum of 24 months following the completion of the request.
Data we collect for security purposes, including Name, Email address, Online Identifiers, PurchasesWe retain security-related data as long as necessary to comply with our legal obligations and to maintain and improve our information security measures.

How we share and disclose information

Information Disclosed for Business or Commercial Purposes in the Last 12 Months, and Categories of Parties Disclosed To

We may disclose the following personal information about you when you purchase our products or visit our website:

Personal Information DisclosedRecipient (by Category)
Personal IdentifiersAd Networks, Business Operations Tool, Cloud Computing & Storage Providers, Commerce Software Tools, Communications Tools, Contractors, Customer Support Tools, Data Analytics Providers, Governance, Risk & Compliance Software, IT Infrastructure Services, Payment Processors, Sales & Marketing Tools, Shipping Services, Web Hosting Services, and Website Operations Tool
Online IdentifiersAd Networks, Business Operations Tool, Commerce Software Tools, Communications Tools, Contractors, Cybersecurity Providers, Data Analytics Providers, IT Infrastructure Services, Sales & Marketing Tools, and Website Operations Tool
Internet ActivityAd Networks, Business Operations Tool, Commerce Software Tools, Communications Tools, Contractors, Cybersecurity Providers, Data Analytics Providers, Governance, Risk & Compliance Software, IT Infrastructure Services, Payment Processors, Sales & Marketing Tools, Web Hosting Services, and Website Operations Tool
Commercial and Financial InformationAd Networks, Business Operations Tool, Cloud Computing & Storage Providers, Commerce Software Tools, Communications Tools, Contractors, Customer Support Tools, Data Analytics Providers, Governance, Risk & Compliance Software, IT Infrastructure Services, Payment Processors, Sales & Marketing Tools, Shipping Services, and Website Operations Tool
InferencesData Analytics Providers and Sales & Marketing Tools

California Privacy Notice (CCPA)

This section provides additional information for California residents under the California Consumer Privacy Act (CCPA). The terms used in this section have the same meaning as in the CCPA. This section does not apply to information that is not considered "personal information," such as anonymous, deidentified, or aggregated information, nor does it apply to publicly available information as defined in the CCPA.

Collection and Disclosure of Personal Information

The personal information we collect is described above in Information we collect. The personal information we disclose for business or commercial purposes is described above in How we share and disclose information. The length of time for which we retain personal information is described above in How long we keep your data.

Business and Commercial Purposes for Collection

We collect personal information for the following business purposes:

  • Conducting Surveys
  • Delivering Targeted Ads
  • Fulfilling Customer Orders
  • Operating our Website or Mobile Apps
  • Organizing & Managing Data
  • Processing Payments
  • Providing Customer Support
  • Sending Promotional Communications
  • Tracking Purchases & Customer Data

We also "share" and "sell" (as defined in the CCPA) personal information for commercial purposes, including to advertise and market our products.

Information “Sharing” and “Selling”

We “share” certain personal information with third party ad networks for purposes of behavioral advertising, including: Commercial and Financial Information, Internet Activity, Online Identifiers, and Personal Identifiers. This allows us to show you ads that are more relevant to you.

We use third party data analytics providers and this may be considered a “sale” of information under the CCPA.

You may opt-out of these data practices here.

We do not knowingly sell or share (for cross-context behavioral advertising) the personal information of consumers under 16 years of age.

CCPA Rights

Your CCPA rights are described below. You can make a Request to Know or a Request to Delete under the CCPA by submitting a Privacy Request at the top of this page, or by clicking here, or by emailing us at moc.htraeyzoc@ycavirp.

Right to Know

You have the right to request to know the following about the personal information we have collected about you in the past 12 months:

  • the categories and specific pieces of personal information we have collected about you
  • the categories of sources from which we collect personal information about you
  • the business and commercial purposes for which we collect personal information
  • the categories of third parties with whom we share the information
  • the categories of personal information about you that we disclosed for a business purpose, and the categories of third parties to whom we disclosed that information for a business purpose

The information we would provide to you in response to a Request to Know Categories is contained in this Privacy Notice. To access the specific personal information we have about you, submit a Request to Know via the link above. If you make a Request to Know more than twice in a 12-month period, we may require you to pay a small fee for this service.

Right to Delete

You have the right to request that we delete any personal information about you that you have provided to us. We will permanently delete from our records any personal information that is not necessary for our business operations and direct our service providers to do the same.

We consider information to be necessary for our business operations if it is used to:

  • Complete an obligation to you that you have requested
  • Detect and resolve issues related to security or functionality
  • Comply with legal obligations
  • Enable solely internal uses

Right to Non-Discrimination

If you exercise your CCPA consumer rights:

  • We will not deny goods or services to you
  • We will not charge you different prices or rates for goods or services, including through the use of discounts or other benefits or penalties
  • We will not provide a different level or quality of goods or services to you

Right to Opt-Out

You have the right to opt-out of any selling and sharing of your personal information.

You may exercise your right to opt-out here.

Opt-Out Preference Signals. Your browser settings may allow you to automatically transmit the Global Privacy Control (GPC) signal to online services you visit. When we detect such signal, we place a U.S. Privacy String setting in your browser so that any third party who respects that signal will not track your activity on our website. GPC is supported by certain internet browsers or as a browser extension. You can find out how to enable GPC here.

Right to Correct

You have the right to correct inaccuracies in your personal data, taking into account the nature of the data and our purposes for processing it.

Request Verification

Before we can respond to a Request to Know or Request to Delete, we will need to verify that you are the consumer who is the subject of the CCPA request. Verification is important for preventing fraudulent requests and identity theft. Requests to Opt-Out do not require verification.

Typically, identity verification will require you to confirm certain information about yourself based on information we have already collected. For example, we will ask you to verify that you have access to the email address we have on file for you. If we cannot verify your identity based on our records, we cannot fulfill your CCPA request.

For a request that seeks specific personal information, we ask that you sign a declaration stating that you are the consumer whose personal information is the subject of the request, as required by the CCPA.

In some cases, we may have no reasonable method by which we can verify a consumer's identity. For example:

  • If a consumer submits a request but we have not collected any personal information about that consumer, we cannot verify the request.
  • If the only data we have collected about a consumer is gathered through website cookies (i.e. the consumer visited our website but had no other interaction with us), we are unable to reasonably associate a requester with any data collected; therefore, we cannot verify the request.

Authorized Agent

A California resident's authorized agent may submit a Request to Know or a Request to Delete under the CCPA by emailing us at moc.htraeyzoc@ycavirp. Requests submitted by an authorized agent will still require verification of the person who is the subject of the request in accordance with the process described above. We will also ask for proof that the person who is the subject of the request authorized an agent to submit a privacy request on their behalf. An authorized agent that has power of attorney pursuant to California Probate Code section 4121 to 4130 must submit proof of statutory power of attorney, but consumer verification is not required.

If you have trouble accessing this notice, please contact us at moc.htraeyzoc@ycavirp.

Contact Us

If you have any privacy-related questions, please send them to moc.htraeyzoc@ycavirp.

Information Collected from Children

The Sites are intended for users aged sixteen and older. We do not knowingly collect information from children and if we discover that we have inadvertently collected information from individuals under the age of sixteen, we will delete that information. Please contact us with any concerns.

“Shine the Light” Law

Separate from the CCPA, California’s Shine the Light law gives California residents the right to ask companies what personal information they share with third parties for those third parties’ direct marketing purposes. We do not disclose your personal information to third parties for the purpose of directly marketing their goods or services to you unless you request such disclosure. If you have any questions regarding this policy, or would like to change your preferences, you may contact us at privacy@cozyearth.com.

Information Collected from Job Applicants

When you apply for an Influencer collaboration with Cozy Earth, we may collect information from you, including: 

  • Employment Iinformation such as your current employer, job title, or job description;
  • Education Iinformation, such as your education transcripts and level of education; 
  • Health Iinformation if you share your health or disability status;
  • Publicly available information that you make available in your social media accounts or that is otherwise available publicly; 
  • Sensitive personal information such as a state identification card or driver’s license, and racial or ethnic origin; and/or
  • Other information, such as information that you authorize us to collect via third parties, including former employers or references.

Notice of Financial Incentive

Consumers who sign up for our marketing emails receive $50 off their first purchase. A consumer provides their email address and consents to receive emails in exchange for a dollar amount provided via coupon code. To opt in, a consumer must enter their email address into the form and submit it. A consumer may unsubscribe from our marketing emails by using the unsubscribe link in the email footer at any time. We calculate the value of the offer and financial incentive by using the expense related to the offer.

Virginia Privacy Notice (VCDPA)

This section provides additional information for Virginia residents under the Virginia Consumer Data Protection Act (VCDPA). ​​The terms used in this section have the same meaning as in the VCDPA. This section does not apply to information that is not considered "personal data," such as deidentified or publicly available information as defined in the VCDPA.

Collection and Disclosure of Personal Information

The personal data we collect is described above in Information we collect. The personal data we disclose to third parties and the categories of third parties to whom we disclose personal data is described above in How we share and disclose information. The length of time for which we retain personal information is described above in How long we keep your data.

Purposes for Processing

We process personal information for the following purposes:

  • Conducting Surveys
  • Delivering Targeted Ads
  • Fulfilling Customer Orders
  • Operating our Website or Mobile Apps
  • Organizing & Managing Data
  • Processing Payments
  • Providing Customer Support
  • Sending Promotional Communications
  • Tracking Purchases & Customer Data

Data “Selling” and Targeted Advertising

We process personal data for purposes of targeted advertising (as defined in the VCDPA), including online identifiers and internet activity. This allows us to show you ads that are more relevant to you.

You may opt-out of these data practices here.

Profiling

The VCDPA gives consumers the right to opt out of automated profiling that produces legal or similarly significant effects, such as approval for a loan, employment, or insurance.

We do not profile consumers in furtherance of decisions that produce legal or similarly significant effects.

VCDPA Rights

Your VCDPA rights are described below. You can make a Privacy Request by clicking the link at the top of this page, or by clicking here.

Right to Access

You have the right to confirm whether we are processing personal data about you and to access such data. Where processing is carried out by automated means, you have a right to receive a copy of your personal data in a portable and readily usable format that allows you to transmit your data to another controller.

If you make a Request to Know more than twice in a 12-month period, we may require you to pay a small fee for this service.

Right to Delete

You have the right to request that we delete any personal data provided by or obtained about you. We will permanently delete any such personal data from our records and direct our processors to do the same. However, we may retain your personal data if it is necessary for certain purposes, including the following:

  • To comply with legal obligations
  • To comply with an official investigation or cooperate with law-enforcement agencies
  • To establish or defend legal claims
  • To complete an obligation to you that you have requested
  • To respond to security incidents, fraud, harassment, and other similar activity
  • To identify and repair technical errors
  • To conduct internal research to develop, improve, and repair our products and services
  • For internal operations that are reasonably aligned with your expectations

Any personal data retained for these purposes will not be processed for other purposes.

Right to Non-Discrimination

If you exercise your VCDPA consumer rights:

  • We will not deny goods or services to you
  • We will not charge you different prices or rates for goods or services
  • We will not provide a different level or quality of goods or services to you

However, we may offer a different price, rate, level, quality, or selection of products or services if your personal data is required in order to provide those products or services and you have exercised your right to opt out, or the offer is related to a voluntary loyalty or rewards program.

Right to Opt-Out

You have the right to opt-out of any selling of your personal data, processing of your personal data for purposes of targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects for you.

You may exercise your right to opt-out here.

Right to Correct

You have the right to correct inaccuracies in your personal data, taking into account the nature of the data and our purposes for processing it.

Right to Appeal

If we decline to take action in response to any of your privacy requests, you have the right to appeal that decision within a reasonable amount of time.

If you believe your rights have been violated and you are not able to resolve the issue directly with us, you may file a complaint with the Virginia Attorney General’s Office.

Submitting Requests and Request Verification

You may send your request by email to  privacy@cozyearth.com or by clicking here

Before we can respond to a Request to Confirm Processing, Request to Access, Request to Delete, or to obtain a copy of your data, we will need to verify that you are the consumer who is the subject of the rights request. Verification is important for preventing fraudulent requests and identity theft. Requests to Opt-Out do not require verification.

Typically, identity verification will require you to confirm certain information about yourself based on information we have already collected. For example, we will ask you to verify that you have access to the email address we have on file for you. If we cannot verify your identity based on our records, we cannot fulfill your rights request.

For a request that seeks specific personal information, we ask that you sign a declaration stating that you are the consumer whose personal information is the subject of the request. 

We may have a reason under the law why we do not have to comply with your request, or why we may comply with it in a more limited way than you anticipated. If we do, we will explain that to you in our response.

For example, we may have no reasonable method by which we can verify a consumer's identity if:

  • A consumer submits a request but we have not collected any personal information about that consumer, we cannot verify the request.
  • The only data we have collected about a consumer is gathered through website cookies (i.e. the consumer visited our website but had no other interaction with us), we are unable to reasonably associate a requester with any data collected; therefore, we cannot verify the request.

Nevada Privacy Notice

Residents of the State of Nevada have the right to opt-out of the sale of certain pieces of their information to third parties. Currently, we do not engage in such sales. If you are a Nevada resident and would like more information about our data sharing practices, please contact us by sending your request via email to moc.htraeyzoc@ycavirp.

EEA/UK Privacy Notice (GDPR)

This section provides additional information for people in the European Economic Area (EEA) or United Kingdom (UK). ​​The terms used in this section have the same meaning as in the General Data Protection Regulation and the UK Data Protection Act (GDPR). The term “personal information” as used in this notice has the same meaning as “personal data” in the GDPR.

Collection and Disclosure of Personal Data

The personal data we collect is described above in Information we collect. The personal data we disclose for business or commercial purposes is described above in How we share and disclose information. The length of time for which we retain personal data is described above in How long we keep your data.

We may disclose your personal information to the following third party controllers for business purposes: Pinterest Ads, Instagram Ads, PayPal - Pay with PayPal, Venmo, Pay Later, Apple Pay, Amazon Pay, Shopify, QuickBooks, Shop Pay, Facebook Ads, ShareASale, Google Ads. To understand how these parties handle your data, please refer to their respective privacy policies.

Lawful Bases and Legitimate Interests

We process personal data on the following lawful bases:

  • Complying with legal obligations
  • Fulfilling contracts
  • Consent
  • Legitimate interests

Where we process personal data on the basis of our legitimate interests, we pursue the following interests: Organizing & Managing Data, Processing Payments, Providing Customer Support, Conducting Surveys, Delivering Targeted Ads, Fulfilling Customer Orders, Operating our Website or Mobile Apps, Sending Promotional Communications, and Tracking Purchases & Customer Data.

International Data Transfers

We may send the personal data of individuals in the EEA/UK to third countries, including the United States, where it may be stored or processed, for example on our service providers’ cloud servers. When we transfer personal data, we rely either on Adequacy Decisions as adopted by the European Commission (EC) on the basis of Article 45 of Regulation (EU) 2016/679 (GDPR), Standard Contractual Clauses (SCCs) issued by the EC or International Data Transfer Agreements (IDTAs) approved by the UK Information Commissioner’s Office. Data protection authorities have determined that the SCCs and IDTAs provide sufficient safeguards to protect personal data transferred outside the EEA/UK. You may read more about the SCCs and IDTAs at the following links:

Privacy Rights

Individuals in the EEA/UK have the following rights regarding their personal data. You can exercise your rights using the request form at the top of this page, or by clicking here. Once you submit a request, we will verify your identity and process your request in most cases within 30 days.

Right to access. You have the right to request a copy of the personal data we hold about you.

Right of portability. You have the right to ask us to transfer your data to another party.

Right to rectification. You have the right to request that we rectify any incorrect information we have about you.

Right of erasure. You have the right to request that we erase (delete) any personal information we hold about you.

Right to lodge a complaint with a supervisory authority. You have a right to lodge a complaint with a supervisory authority. For more information, you can visit the Information Commissioner’s Office website at https://ico.org.uk/, or see a list of EU Data Protection Authorities at https://www.gdprregister.eu/gdpr/dpa-gdpr/.

Inquiries

Controller contact information

Cozy Earth

moc.htraeyzoc@ycavirp

Our Blog and Social Media Posts

Please note that any information you include in a message you post to any public posting area, such as the comment section of our blog or social media pages, is available to anyone with Internet access. If you don't want people to know your email address, for example, don't include it in any message you post publicly. PLEASE BE EXTREMELY CAREFUL WHEN DISCLOSING ANY INFORMATION IN PUBLIC POSTING AREAS. WE ARE NOT RESPONSIBLE FOR THE USE BY OTHERS OF THE INFORMATION THAT YOU DISCLOSE IN PUBLIC POSTING AREAS.

Chatbox Features and Session Replay Technology

We may use technology to monitor how you interact with our Sites. This may include without limitation which links you click on, information that you type into our online forms, and about your device or browser. Further, we utilize session replay spyware to monitor and record mouse clicks and movements, keystrokes, and pages and content viewed by you. Please discontinue use of the Sites if you do not consent to our collection of such information.

Security

We take reasonable physical, technical, and organizational measures to safeguard and secure any personal information you provide to us. Please understand, however, that no data transmissions over the internet can be guaranteed to be 100% secure due to the inherent risks of data transmission over the internet. Consequently, we cannot ensure or warrant the security of any information you transmit to us, and you understand that any information that you transfer to us is done at your own risk. If we learn of a security system breach we may attempt to notify you electronically so that you can take appropriate protective steps. By using the Site or providing personal information to us, you agree that we can communicate with you electronically regarding security, privacy and administrative issues relating to your use of the Site. We may post a notice via our Site if a security breach occurs. We may also send an email to you at the email address you have provided to us in these circumstances. Depending on where you live, you may have a legal right to receive notice of a security breach in writing.

If you register with our Sites, you are responsible for maintaining the security of your password at all times and you are responsible for activity occurring while logged into your account. You may gain access to and review your personal information by accessing your account.