Privacy Policy

Updated 19 April 2024

Introduction


This policy describes the types of information that Careismatic Brands, LLC and its affiliated entities and brands (collectively, "Company" or "We") may collect from you or that you may provide when you visit the websites https://www.allheart.com/, https://www.cherokeeuniforms.com/, https://www.healinghandsscrubs.com/, https://www.infinityscrubs.com/, https://www.heartsoulscrubs.com/, https://www.wearebala.com/, https://www.dickiesmedical.com/, https://www.medelita.com/ and https://www.cbicentral.com/ individually and collectively, our "Websites") and our practices for collecting, using, maintaining, protecting, and disclosing that information.

This policy applies to information we collect:

  • On these Websites;
  • In email, text, and other electronic messages between you and the Websites;
  • Through mobile and desktop applications you download from or access via the Websites, which provide dedicated non-browser-based interaction between you and this Websites;
  • When you interact with our advertising and applications on third-party websites and services, if those applications or advertising include links to this policy;
  • When you register for an account;
  • When you sign up for a mailing list; and/or
  • When you sign up and participate in our Brand Ambassador program..

It does not apply to information collected by:

  • The Company offline or through any other means, including on any other website operated by any third party ; or
  • Any third party, including through any application or content (including advertising) that may link to or be accessible from or on the Websites.
Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Websites. By accessing or using the Websites, you agree to this Privacy Policy. This policy may change from time to time (see Changes to Our Privacy Policy). Your continued use of the Websites after we make changes is deemed to be acceptance of those changes, so please check the policy when using the Websites for updates..

Children Under the Age of 18

Our Websites is not intended for children under eighteen (18) years of age. The Websites and the services, content, information and programs provided or made available on and/or through the Websites may not be accessed or used by any individuals that are not at least 18 years of age. No one under age 18 may provide any information to the Websites. We do not knowingly collect personal information from children under 18. If you are under 18, do not use or provide any information on this Websites, register on the Websites, make any purchases through the Websites, or provide any information about yourself to us, including your name, address, telephone number, email address, or any user name you may use. If we learn we have collected or received personal information from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 18, please contact us at privacy@shop.careismatic.com. California residents under 16 years of age may have additional rights regarding the collection and sale of their personal information. Please see Your California Privacy Rights for more information.

Transfer of Information to the U.S. and other Countries

We are based in the United States, and the information we collect is governed by U.S. law. By accessing or using the Websites, or otherwise providing information to use, you consent to collection, processing, transfer and storage of information about you in and to the United States and other applicable territories in which the privacy law may not be as comprehensive as or equivalent to the law in your country of residence. Please use the contact information below if you have a question or concern about the policies or manner in which we treat your personal information.

Information We Collect About You and How We Collect It

We collect several types of information from and about users of our Websites, including information:

By which you may be personally identified, such as name, postal address, e-mail address, telephone number and any other identifier by which you may be contacted online or offline ("personal information");

  • That is about you but individually does not identify you; and
  • About your internet connection, the equipment you use to access our Websites, and usage details.

We collect this information:

  • Directly from you when you provide it to us;
  • Automatically as you navigate through the sites (information collected automatically may include usage details, IP addresses, and information collected through cookies, web beacons, and other tracking technologies); and/or
  • From third parties, for example, our business partners.

Information You Provide to Us

Information that you provide by filling in forms on our Websites (This includes information provided at the time of registering to use our Websites or signing up for our mailing list. We may also ask you for information when you enter a contest or promotion sponsored by us, and when you report a problem with our Websites);

  • Records and copies of your correspondence (including email addresses), if you contact us;
  • Information provided through email, text message, and postal mailing list sign ups;
  • Information provided through our Brand Ambassador programs which includes information posted on social media and from surveys;
  • Your responses to other surveys that we might ask you to complete for research purposes;
  • Details of transactions you carry out through our Websites and of the fulfillment of your orders; and/or
  • Your search queries on the Websites.

You also may provide information to be published or displayed (hereinafter “posted”) on the Company’s social media accounts (“User Contributions”). Your User Contributions are posted on and transmitted to others at your own risk. We cannot control the actions of the social media platforms on which you choose to provide User Contributions, and we cannot control other users of the social media pages that are able to access your User Contributions or with whom you may choose to share your User Contributions. Therefore, we cannot and do not guarantee that your User Contributions will not be viewed by unauthorized persons. Any User Contributions will also be subject to the privacy policies, terms of use, disclosures and related documents of the platform on which they are posted.

Information We Collect Through Automatic Data Collection Technologies

As you navigate through and interact with our Websites, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:

  • Details of your visits to our Websites, including traffic data, location data, logs, and other communication data and the resources that you access and use on the Websites; and
  • Information about your computer and internet connection, including your IP address, operating system, and browser type.

The information we collect automatically may include personal information. It helps us to improve our Websites and to deliver a better and more personalized service, including by enabling us to:

  • Estimate our audience size and usage patterns;
  • Store information about your preferences, allowing us to customize our Websites according to your individual interests;
  • Speed up your searches; and
  • Recognize you when you return to our Websites.

The technologies we use for this automatic data collection may include:

  • Cookies (or browser cookies). A cookie is a small file placed on the hard drive of your computer. You may refuse to accept browser cookies by activating the appropriate setting on your browser. However, if you select this setting you may be unable to access certain parts of our Website. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Websites.
  • Web Beacons. Pages of our Websites and our e-mails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of certain website content and verifying system and server integrity).

Third-Party Use of Cookies and Other Tracking Technologies

Some content or applications on the Websites are served by third-parties, including application providers. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our Websites. The information they collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites and other online services. We do not control third parties' tracking technologies or how they may be used.

Mobile Terms of Service

The Careismatic Brands mobile message service (the "Service") is operated by Careismatic Brands (“Careismatic Brands”, “we”, or “us”). Your use of the Service constitutes your agreement to these terms and conditions (“Mobile Terms”). We may modify or cancel the Service or any of its features without notice. To the extent permitted by applicable law, we may also modify these Mobile Terms at any time and your continued use of the Service following the effective date of any such changes shall constitute your acceptance of such changes.

By consenting to Careismatic Brands’s SMS/text messaging service, you agree to receive recurring SMS/text messages from and on behalf of Careismatic Brands through your wireless provider to the mobile number you provided, even if your mobile number is registered on any state or federal Do Not Call list. Text messages may be sent using an automatic telephone dialing system or other technology. Service-related messages may include updates, alerts, and information (e.g., order updates, account alerts, etc.). Promotional messages may include promotions, specials, and other marketing offers (e.g., cart reminders).

You understand that you do not have to sign up for this program in order to make any purchases, and your consent is not a condition of any purchase with Careismatic Brands. Your participation in this program is completely voluntary. We do not charge for the Service, but you are responsible for all charges and fees associated with text messaging imposed by your wireless provider. Message frequency varies. Message and data rates may apply. Check your mobile plan and contact your wireless provider for details. You are solely responsible for all charges related to SMS/text messages, including charges from your wireless provider.

You may opt-out of the Service at any time. Text the single keyword command STOP to +18333662320 or click the unsubscribe link (where available) in any text message to cancel. You'll receive a one-time opt-out confirmation text message. No further messages will be sent to your mobile device, unless initiated by you. If you have subscribed to other Careismatic Brands mobile message programs and wish to cancel, except where applicable law requires otherwise, you will need to opt out separately from those programs by following the instructions provided in their respective mobile terms.

For Service support or assistance, call 1-800-372-2201 or email help@shop.careismatic.com.

We may change any short code or telephone number we use to operate the Service at any time and will notify you of these changes. You acknowledge that any messages, including any STOP or HELP requests, you send to a short code or telephone number we have changed may not be received and we will not be responsible for honoring requests made in such messages.

The wireless carriers supported by the Service are not liable for delayed or undelivered messages. You agree to provide us with a valid mobile number. If you get a new mobile number, you will need to sign up for the program with your new number.

To the extent permitted by applicable law, you agree that we will not be liable for failed, delayed, or misdirected delivery of any information sent through the Service, any errors in such information, and/or any action you may or may not take in reliance on the information or Service.

The above excludes text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Careismatic Brands uses cookies to help keep track of items you put into your shopping cart including when you have abandoned your cart and this information is used to determine when to send cart reminder messages via SMS.

We respect your right to privacy. To see how we collect and use your personal information, please see the rest of this policy.

How We Use Your Information

We use information that we collect about you or that you provide to us, including any personal information:

  • To fulfill or meet the reason you provided the information (For example, if you share your name and contact information to ask a question about our products or services, we will use that personal information to respond to your inquiry);
  • To provide, support, personalize, and develop our Websites, products, and services;
  • To create, maintain, customize, and secure your account with us;
  • To process your requests, purchases, transactions, and payments and prevent transactional fraud;
  • To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses;
  • To personalize your Websites experience and to deliver content and product and service offerings relevant to your interests, including targeted offers and ads through our Websites, and via email or text message (with your consent, where required by law);
  • To help maintain the safety, security, and integrity of our Websites, products and services, databases and other technology assets, and business;
  • For testing, research, analysis, and product development, including to develop and improve our Websites, products, and services;
  • To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations;
  • To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of the Company’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by the Company about our Websites’ users is among the assets transferred;
  • In any other way we may describe when you provide the information; and
  • For any other purpose with your consent.

We may also use your information to contact you about our own goods and services that may be of interest to you. If you do not want us to use your information in this way, you may opt-out by emailing your request t Disclosure of Your Information

We may disclose aggregated information about our users, and information that does not identify any individual, without restriction.
We may disclose personal information that we collect or that you provide as described in this privacy policy:

  • To our subsidiaries and affiliates;
  • To contractors, service providers, and other third parties we use to support our business;
  • To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of the Company’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by the Company about our Website users is among the assets transferred;
  • To fulfill the purpose for which you provide it;
  • For any other purpose disclosed by us when you provide the information; and
  • With your consent.
  • We do not control third parties' collection or use of your information to serve interest-based advertising. However these third parties may provide you with ways to choose not to have your information collected or used in this way. You can opt out of receiving targeted ads from members of the Network Advertising Initiative ("NAI") on the NAI's website.

    Your State Privacy Rights

    Residents of certain states, such as California, Nevada, Colorado, Connecticut, Virginia, and Utah may have additional personal information rights and choices.

    If you are a California, Nevada, Colorado, Connecticut, Virginia, or Utah resident, your state’s laws may provide you with additional rights regarding our use of your personal information. To learn more about your California privacy rights, see below for our Privacy Statement - California
    Colorado, Connecticut, Virginia and Utah each provide their state residents with rights to:

    • Confirm whether we process their personal information.
    • Access and delete certain personal information.
    • Data portability.
    • Opt-out of personal data processing for targeted advertising and sales.
    • Colorado, Connecticut and Virginia also provide their state residents with rights to:
    • ·
    • Correct inaccuracies in their personal information, taking into account the information’s nature processing purpose.
    • Opt-out of profiling in furtherance of decisions that produce legal or similarly significant effects.

    To exercise any of these rights please send an email to privacy@shop.careismatic.com or visit https://www.allheart.com/privacy-request.html. To appeal a decision regarding a consumer rights request, please send another email to privacy@shop.careismatic.com asking that our legal department review the decision. We will respond to you within two weeks with the decision regarding your appeal. This email will contain information and reasoning supporting the appeal decision.

    Nevada residents who wish to exercise their sale opt-out rights under Nevada Revised Statutes Chapter 603A may submit a request to this designated address: privacy@shop.careismatic.com. However, please know we do not currently sell data triggering that statute’s opt-out requirement.

    Accessing and Correcting Your Information

    You may send us an email at privacy@shop.careismatic.com to request access to, correct or delete any personal information that you have provided to us. We may not be able to delete your personal information except by also deleting your user account. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.
    California residents may have additional personal information rights and choices. Please see Your California Privacy Rights for more information.

    Data Security

    We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. All information you provide to us is stored on our secure servers behind firewalls.
    The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Websites, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
    Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Websites. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Websites.

    Changes to Our Privacy Policy

    It is our policy to post any changes we make to our privacy policy on this page. If we make material changes to how we treat our users' personal information, we will notify you by email if you are a registered user to the primary email address specified in your account, or by notice posted on the website requesting click-through consent. The date the privacy policy was last revised is identified at the top of the page. Users are responsible for periodically visiting our Websites and this privacy policy to check for any changes.

    Contact Information

    To ask questions or comment about this privacy policy and our privacy practices, contact us at:

    Careismatic Brands, LLC
    Privacy Policy
    15301 Ventura Blvd, Building D, Suite 300
    Sherman Oaks, CA 91403

    privacy@shop.careismatic.com

    Your California Privacy Rights

    If you are a California resident, California law may provide you with additional rights regarding our use of your personal information. To learn more about your California privacy rights, please review the following section: Your California Privacy Rights

    Privacy Notice for California Residents

    Last Modified: 1 September 2023

    The Privacy Notice below supplements the information contained in the general privacy policy above and applies solely to all visitors, users, and others who reside in the State of California ("consumers" or "you"). We have adopted this notice to comply with the California Consumer Privacy Act of 2018 and the California Privacy Rights Act of 2020 (collectively the “CCPA”), and any terms defined in the CCPA have the same meaning when used in this notice.

    Information We Collect

    Our Websites collects information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device ("personal information"). In particular, our website has collected the following categories of personal information from its consumers within the last twelve (12) months and we keep this information only for so long as we need it to perform a contract or transaction with you or maintain an ongoing business relationship with you, comply with any legal obligations and/or to bring or defend any legal claims:

    CategoryExamplesCollected
    A. Identifiers.A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers.YES
    B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.YES
    C. Protected classification characteristics under California or federal law.Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).YES
    D. Commercial information.Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.YES
    E. Biometric informationGenetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.NO
    F. Internet or other similar network activity.Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.YES
    G. Geolocation data.Physical location or movements.YES
    H. Sensory dataAudio, electronic, visual, thermal, olfactory, or similar informationNO
    Professional or employment-related information.Current or past job history or performance evaluations.NO
    Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.NO
    K. Inferences drawn from other personal information.Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.YES
    L. Sensitive Personal InformationSensitive personal information” means: (1) personal information that reveals (A) a consumer’s social security, driver’s license, state identification card, or passport number; (B) a consumer’s account log-In, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; (C) a consumer’s precise geolocation; (D) a consumer’s racial or ethnic origin, religious or philosophical beliefs, or union membership; (E) the contents of a consumer’s mall, email and text messages, unless the business is the intended recipient of the communication; (F) a consumer’s genetic data; and (2)(A) the processing of biometric information for the purpose of uniquely identifying a consumer; (B) personal information collected and analyzed concerning a consumer’s health; or (C) personal information collected and analyzed concerning a consumer’s sex life or sexual orientation.NO

    For the purposes of this Privacy Notice for California Residents, personal information does not include:

    • Publicly available information from government records.
    • Deidentified or aggregated consumer information.
    • Information excluded from the CCPA's scope, like:
      • health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data;
      • personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994.

    Our websites obtain the categories of personal information listed above from the following categories of sources:

    • Directly from you when you provide it to us;
    • When you sign up for a mailing list;
    • When you sign up and participate in our Brand Ambassador program;
    • Automatically as you navigate through the site (information collected automatically may include usage details, IP addresses, and information collected through cookies, and other tracking technologies); and
    • From third parties, for example, our business partners.

    Use of Personal Information

    We may use or disclose the personal information we collect for one or more of the following purposes:

    • To fulfill or meet the reason you provided the information (for example, if you share your name and contact information to ask a question about our products or services, we will use that personal information to respond to your inquiry);
    • To process payment transactions and fulfill orders you carry out through our Websites;
    • To provide, support, personalize, and develop our Websites, products, and services;
    • To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses;
    • To personalize your experience and to deliver content and product and service offerings relevant to your interests, including targeted offers and ads through our Websites, and via email or text message (with your consent, where required by law);
    • To help maintain the safety, security, and integrity of our Websites, products and services, databases and other technology assets, and business;
    • For testing, research, analysis, and product development, including to develop and improve our Websites, products, and services;
    • To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations;
    • As described to you when collecting your personal information or as otherwise set forth in this Privacy Notice for California Residents; and/or
    • To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of the Company’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by the Company about our Websites’ users is among the assets transferred.

    We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.

    Sharing Personal Information

    We do not sell or share your personal information with third parties and receive payments for it. However, given the way that the CCPA defines a “sale” or “sharing” of personal information, some of our uses of your personal information, for example with third party platforms that collect our customers information and help us with our marketing and retargeting purposes, would be considered a “sale” or “share” that gives rise to opt-out rights (discussed further below).

    We may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we enter into a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.

    We share your personal information with the following categories of third parties:

    • Our subsidiaries and affiliates; and
    • Contractors, service providers, and other third parties we use to support our business.
    • In the preceding twelve (12) months we have disclosed the following categories of personal information for a business purpose:
    Personal Information CategoryCategory of Third-Party Recipients
    Business Purpose DisclosuresSales
    A: Identifiers.Yes, to service providersYes, to companies such as Google Analytics
    B: California Customer Records personal information categoriesYes, to service providersYes, to companies such as Google Analytics
    C: Protected classification characteristics under California or federal law.Yes, to service providersYes, to companies such as Google Analytics
    D: Commercial information.Yes, to service providersYes, to companies such as Google Analytics
    D: Commercial information.Yes, to service providersYes, to companies such as Google Analytics
    E: Biometric information.NoNo
    F: Internet or other similar network activity.Yes, to service providersYes, to companies such as Google Analytics
    G: Geolocation data.Yes, to service providersYes, to companies such as Google Analytics
    H: Sensory data.NoNo
    I: Professional or employment-related information.NoNo
    J: Non-public education information.NoNo
    K: Inferences drawn from other personal information..Yes, to service providersYes, to companies such as Google Analytics
    L: Sensitive Personal Information.NoNo

    Your Rights and Choices

    The CCPA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.

    Access to Specific Information and Data Portability Rights

    You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we receive and confirm your verifiable consumer request (see Exercising Access, Correction, Data Portability, and Deletion Rights), we will disclose to you:

    • The categories of personal information we collected about you;
    • The categories of sources for the personal information we collected about you;
    • Our business or commercial purpose for collecting that personal information;
    • The categories of third parties with whom we share that personal information;
    • The specific pieces of personal information we collected about you (also called a data portability request); and
    • If we sold or disclosed your personal information for a business purpose, two separate lists disclosing:
      • sales, identifying the personal information categories that each category of recipient purchased; and
      • disclosures for a business purpose, identifying the personal information categories that each category of recipient obtained.

    Deletion Request Rights

    You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request (see Exercising Access, Data Portability, and Deletion Rights), we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.

    We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:

    • Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you;
    • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities;
    • Debug products to identify and repair errors that impair existing intended functionality;
    • Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law;
    • Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.);
    • Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may likely render impossible or seriously impair the research's achievement, if you previously provided informed consent;
    • Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us;
    • Comply with a legal obligation; and/or
    • Make other internal and lawful uses of that information that are compatible with the context in which you provided it.

    Right to Correct

    You have a right to correct data that we hold about you that is inaccurate.

    Personal Information Sales and Sharing Opt-Out and Opt-In Rights

    If you are age 16 or older, you have the right to direct us to not sell or share your personal information at any time (the "right to opt-out"). We do not sell or share the personal information of consumers we actually know are less than 16 years old, unless we receive affirmative authorization (the "right to opt-in") from either the consumer who is between 13 and 15 years old, or the parent or guardian of a consumer less than 13 years old. Consumers who opt-in to personal information sales or sharing may opt-out of future sales at any time.

    To exercise the right to opt-out, you (or your authorized representative) may submit a request to us by visiting the following Internet Web page link:

    https://www.allheart.com/privacy-request.html

    Once you make an opt-out request, we will wait at least twelve (12) months before asking you to reauthorize personal information sales. However, you may change your mind and opt back into personal information sales at any time by:

    https://www.allheart.com/privacy-request.html

    You do not need to create an account with us to exercise your opt-out rights. We will only use personal information provided in an opt-out request to review and comply with the request.

    Exercising Access, Correction, Data Portability, and Deletion Rights

    To exercise the access, data portability, correction and deletion rights described above, please submit a verifiable consumer request to us by either:

    • Emailing privacy@shop.careismatic.com.
    • Visiting https://www.allheart.com/privacy-request.html . Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.

    DELETE ME

    You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:

    • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
    • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

    We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you.

    Making a verifiable consumer request does not require you to create an account with us. However, we do consider requests made through your password protected account sufficiently verified when the request relates to personal information associated with that specific account.

    We will only use personal information provided in a verifiable consumer request to verify the requestor's identity or authority to make the request.

    Response Timing and Format

    We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt or within fifteen (15) days for opt-out requests. If we require more time, we will inform you of the reason and extension period in writing.

    If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.

    Any disclosures we provide will only cover the twelve (12) month period preceding the verifiable consumer request's receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.

    We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

    Non-Discrimination

    We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:

    • Deny you goods or services;
    • Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties;
    • Provide you a different level or quality of goods or services; or
    • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

    However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your personal information's value and contain written terms that describe the program's material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time. We currently provide the following financial incentives: We offer our customers a loyalty program (Careismatic Rewards) that provides certain perks, such as rewards and exclusive offers. We may also provide other perks, such as sweepstakes, contests, or other promotional campaigns. When you sign up for one of these programs, we typically ask you to provide your name and contact information (such as email address and/or telephone number). Because these programs involve the collection of personal information, they might be interpreted as a “financial incentive” under California law. The value of your personal information to us is related to the value of the free or discounted products or services, or other benefits that you obtain or that are provided as part of the loyalty program, less the expense related to offering those products, services, and benefits to participants. You may withdraw from participating in our loyalty program at any time by using the contact information set forth in our Terms of Use and Conditions. Visit our rewards page to view full details on the program.

    Other California Privacy Rights

    California's "Shine the Light" law (Civil Code Section § 1798.83) permits users of our Website that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email to privacy@shop.careismatic.com.

    Canadian Privacy Notice

    Effective Date: 1 September 2023

    This Privacy Notice for Canadian residents only ("Canadian Notice") and supplements the General Privacy Policy above as well as any other agreement you may have with us. Any terms we use in this Canadian Notice that aren’t defined will have the meaning we provide in the General Privacy Policy or other agreements.

    International Data Transfers. We are based in the United States and any information collected through the Websites is stored and processed in the United States. If you are located in Canada, you understand that in using the Websites your personal information will be transferred to and processed in the United States and other countries where our third-party service providers and partners operate. These countries may have data protection laws that are different to the laws of your country and, in some cases, may not be as protective.

    Profiling Activities. Company uses standard tracking technologies like cookies to distinguish you from other users and to collect certain information about how you use and interact with the Websites (as described in our General Privacy Policy https://www.allheart.com/privacy-policy.html. This helps us to provide you with a positive user experience and allows us to provide and improve our services. In addition, our general privacy policy makes clear what personal information we will collect, how we plan to use or disclose that information, and for what purposes. We undertake such activities only with your express or implied consent to do so. If you object to any of the foregoing, or if you do not wish to receive marketing communications (such as emails) from us or our third-party partners, then you may contact us to let us know your objection at any time.


    Your Rights and Choices. You may be able to exercise certain rights with respect to your personal information that we collect and control:

    • Access. You may ask us in writing whether we have collected personal information about you and to obtain access to that personal information.
    • Correction. If you believe the personal information we have about you is inaccurate or incomplete, you can ask us to correct it.
    • Deletion. We will delete personal information when we no longer have a lawful basis to retain it. You can ask us to delete personal information that you believe we no longer are required to retain.

    You may submit a request to exercise your rights by emailing privacy@shop.careismatic.com or visiting https://www.allheart.com/privacy-request.html.

    We may need to verify your identity before processing your request, which may require us to request additional personal information from you or require you to log into your account, if you have one. In certain circumstances, we may decline or limit your request, particularly where we are unable to verify your identity or locate your information in our systems, or as permitted by law.

    Changes to this Canadian Notice. Company may modify or update this Canadian Notice from time to time so you should review this Canadian Notice periodically.