Cookie Policy of Allure Beauty
This document informs Users about the technologies that help this Website to achieve the purposes described below. Such technologies allow the Owner to access and store information (for example by using a Cookie) or use resources (for example by running a script) on a User’s device as they interact with this Website.
For simplicity, all such technologies are defined as "Trackers" within this document – unless there is a reason to differentiate.
For example, while Cookies can be used on both web and mobile browsers, it would be inaccurate to talk about Cookies in the context of mobile apps as they are a browser-based Tracker. For this reason, within this document, the term Cookies is only used where it is specifically meant to indicate that particular type of Tracker.
Some of the purposes for which Trackers are used may also require the User's consent. Whenever consent is given, it can be freely withdrawn at any time following the instructions provided in this document.
This Website uses Trackers managed directly by the Owner (so-called “first-party” Trackers) and Trackers that enable services provided by a third-party (so-called “third-party” Trackers). Unless otherwise specified within this document, third-party providers may access the Trackers managed by them.
The validity and expiration periods of Cookies and other similar Trackers may vary depending on the lifetime set by the Owner or the relevant provider. Some of them expire upon termination of the User’s browsing session.
In addition to what’s specified in the descriptions within each of the categories below, Users may find more precise and updated information regarding lifetime specification as well as any other relevant information – such as the presence of other Trackers - in the linked privacy policies of the respective third-party providers or by contacting the Owner.
How this Website uses Trackers
Necessary
This Website uses so-called “technical” Cookies and other similar Trackers to carry out activities that are strictly necessary for the operation or delivery of the Service.
Trackers managed by third parties
-
SiteGround Hosting (SiteGround Spain S.L.)
SiteGround Hosting is a hosting service provided by SiteGround Spain S.L.
Personal Data processed: Trackers, Usage Data and various types of Data as specified in the privacy policy of the service.
Place of processing: Netherlands – Privacy Policy.
-
Stripe (Stripe Inc)
Stripe is a payment service provided by Stripe Inc or by Stripe Technology Europe Ltd, depending on how the Owner manages the Data processing.
Personal Data processed: billing address, email address, first name, last name, payment info, purchase history, Trackers, Usage Data and various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy; European Union – Privacy Policy.
Trackers duration:
- 1: indefinite
- __Host-LinkSession: 2 years
- __stripe_mid: 1 year
- __stripe_sid: 30 minutes
- _mf: indefinite
- dashboard.banner-dismissals: duration of the session
- link.auth_session_client_secret: duration of the session
- m: 2 years
- pay_sid: 1 year
-
PayPal (PayPal Inc.)
PayPal is a payment service provided by PayPal Inc., which allows Users to make online payments.
Personal Data processed: billing address, device information, email address, first name, last name, password, payment info, phone number, purchase history, Trackers, Usage Data, username and various types of Data as specified in the privacy policy of the service.
Place of processing: See the PayPal privacy policy – Privacy Policy.
Trackers duration:
- LANG: 8 hours
- __paypal_storage__: indefinite
- akavpau_ppsd: duration of the session
- enforce_policy: duration of the session
- l7_az: duration of the session
- nsid: duration of the session
- ts: duration of the session
- tsrce: duration of the session
- x-cdn: duration of the session
- x-pp-s: duration of the session
-
Google Pay (Google LLC)
Google Pay is a payment service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the Data processing, which allows users to make online payments using their Google credentials.
Personal Data processed: billing address, email address, first name, last name, payment info, phone number, purchase history, shipping address, Trackers, Usage Data and various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
-
Apple Pay (Apple Inc.)
Apple Pay is a payment service provided by Apple Inc., which allows Users to make payments using their mobile phones.
Personal Data processed: billing address, email address, first name, last name, payment info, phone number, purchase history, shipping address, Trackers and Usage Data.
Place of processing: United States – Privacy Policy.
-
Cloudflare (Cloudflare Inc.)
Cloudflare is a traffic optimisation and distribution service provided by Cloudflare Inc.
The way Cloudflare is integrated means that it filters all the traffic through this Website, i.e., communication between this Website and the User's browser, while also allowing analytical data from this Website to be collected.
Personal Data processed: Trackers and various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
Trackers duration:
- _cfuvid: indefinite
- cf_clearance: 30 minutes
-
Google Tag Manager (Google LLC)
Google Tag Manager is a tag management service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the Data processing.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
-
iubenda Privacy Controls and Cookie Solution (iubenda srl)
The iubenda Privacy Controls and Cookie Solution allows the Owner to collect and store Users’ preferences related to the processing of personal information and in particular to the use of Cookies and other Trackers on this Website.
Personal Data processed: IP address and Trackers.
Place of processing: Italy – Privacy Policy.
Trackers duration:
-
Cloudflare Bot Management (Cloudflare Inc.)
Cloudflare Bot Management is a malicious bot protection and management service provided by Cloudflare Inc.
Personal Data processed: app information, Application opens, browser information, browsing history, city, clicks, country, county, custom events, device information, device logs, geography/region, interaction events, IP address, keypress events, language, latitude (of city), launches, longitude (of city), metro area, motion sensor events, mouse movements, number of sessions, operating systems, page events, page views, province, scroll position, scroll-to-page interactions, search history, session duration, session statistics, state, touch events, Trackers, Usage Data, video views and ZIP/Postal code.
Place of processing: United States – Privacy Policy.
Trackers duration:
- __cf_bm: 3 seconds
- __cfruid: duration of the session
- _cfuvid: indefinite
- cf_clearance: 30 minutes
- cf_ob_info: 3 seconds
- cf_use_ob: 3 seconds
- cfmrk_cic: 3 months
Functionality
This Website uses Trackers to enable basic interactions and functionalities, allowing Users to access selected features of the Service and facilitating the User's communication with the Owner.
Trackers managed directly by the Owner
-
Contact form (this Website)
By filling in the contact form with their Data, the User authorises this Website to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form’s header.
Personal Data processed: city, company name, country, county, email address, field of activity, first name, last name, phone number, physical address, profession, state, Trackers, Usage Data, User ID, various types of Data, VAT Number, website and ZIP/Postal code.
-
Mailing list or newsletter (this Website)
By registering on the mailing list or for the newsletter, the User’s email address will be added to the contact list of those who may receive email messages containing information of commercial or promotional nature concerning this Website. Your email address might also be added to this list as a result of signing up to this Website or after making a purchase.
Personal Data processed: email address, first name and Trackers.
Trackers managed by third parties
-
Crisp Widget (Crisp IM SARL)
The Crisp Widget is a service for interacting with the Crisp live chat platform provided by Crisp IM SARL.
Personal Data processed: Data communicated while using the service, Trackers, Usage Data and various types of Data as specified in the privacy policy of the service.
Place of processing: France – Privacy Policy.
Experience
This Website uses Trackers to improve the quality of the user experience and enable interactions with external content, networks and platforms.
Trackers managed by third parties
-
Vimeo video (Vimeo, LLC)
Vimeo is a video content visualisation service provided by Vimeo, LLC that allows this Website to incorporate content of this kind on its pages.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy.
Trackers duration:
- player: 1 year
- sync_active: duration of the session
- vuid: 2 years
-
Google Fonts (Google LLC)
Google Fonts is a typeface visualisation service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the Data processing, that allows this Website to incorporate content of this kind on its pages.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
-
Font Awesome (Fonticons, Inc. )
Font Awesome is a typeface visualisation service provided by Fonticons, Inc. that allows this Website to incorporate content of this kind on its pages.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy.
-
Instagram widget (Meta Platforms, Inc.)
Instagram is an image visualisation service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the Data processing, that allows this Website to incorporate content of this kind on its pages.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
-
PayPal button and widgets (PayPal Inc.)
The PayPal button and widgets are services allowing interaction with the PayPal platform provided by PayPal Inc.
Personal Data processed: Trackers and Usage Data.
Place of processing: See the PayPal privacy policy – Privacy Policy.
Trackers duration:
- LANG: 8 hours
- akavpau_ppsd: duration of the session
- ts: duration of the session
-
Facebook Like button and social widgets (Meta Platforms, Inc.)
The Facebook Like button and social widgets are services allowing interaction with the Facebook social network provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the Data processing,
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
Trackers duration:
- _fbp: 3 months
- datr: 2 years
- lastExternalReferrer: duration of the session
-
Twitter Tweet button and social widgets (X Corp.)
The Twitter Tweet button and social widgets are services allowing interaction with the Twitter social network provided by Twitter, Inc.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy.
Trackers duration:
- personalization_id: 2 years
Measurement
This Website uses Trackers to measure traffic and analyze User behavior to improve the Service.
Trackers managed by third parties
-
Google Analytics 4 (Google LLC)
Google Analytics 4 is a web analysis service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the Data processing, (“Google”). Google utilizes the Data collected to track and examine the use of this Website, to prepare reports on its activities and share them with other Google services.
Google may use the Data collected to contextualize and personalize the ads of its own advertising network.
In Google Analytics 4, IP addresses are used at collection time and then discarded before Data is logged in any data center or server. Users can learn more by consulting Google’s official documentation.
In order to understand Google's use of Data, consult Google's partner policy.
Personal Data processed: browser information, city, device information, latitude (of city), longitude (of city), number of Users, session statistics, Trackers and Usage Data.
Place of processing: United States – Privacy Policy – Opt Out; Ireland – Privacy Policy – Opt Out.
Trackers duration:
- _ga: 2 years
- _ga_*: 2 years
Marketing
This Website uses Trackers to deliver personalised ads or marketing content, and to measure their performance.
Trackers managed by third parties
-
Mailchimp (Intuit Inc.)
Mailchimp is an email address management and message sending service provided by Intuit Inc.
Personal Data processed: email address, first name, Trackers and various types of Data.
Place of processing: United States – Privacy Policy.
-
Meta ads conversion tracking (Meta pixel) (Meta Platforms, Inc.)
Meta ads conversion tracking (Meta pixel) is an analytics service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the Data processing, that connects data from the Meta Audience Network with actions performed on this Website. The Meta pixel tracks conversions that can be attributed to ads on Facebook, Instagram and Meta Audience Network.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy – Opt out; Ireland – Privacy Policy – Opt out.
Trackers duration:
- _fbc: 3 months
- _fbp: 3 months
- fr: 3 months
- lastExternalReferrer: duration of the session
- lastExternalReferrerTime: duration of the session
Activities that do not fit the above categorizations
-
AI-based Skin Evaluation (Skincare Analyst)
Nature of the Service
1.1. The Service provides automated skin analysis for cosmetic and informational purposes only.
1.2. This Service is not intended to diagnose, treat, or prescribe medical solutions. Users must consult licensed medical professionals for any health-related concerns.
Data Collection and Processing
2.1. By submitting any images or text content (“User Data”), you authorize us to collect and process such data solely for the purpose of providing the requested cosmetic analysis.
2.2. User Data is stored on secure servers located in the European Union and managed in accordance with the EU General Data Protection Regulation (“GDPR”).
2.3. All uploaded files are automatically deleted after a predefined interval, minimizing retention risks and ensuring privacy.
Third-Party AI Providers
3.1. We may employ external AI-based services for certain analytical or generative processes; for example, OpenAI or other equivalent providers.
3.2. These providers may process User Data outside the European Economic Area, subject to Standard Contractual Clauses or equivalent legal safeguards.
3.3. We endeavor to configure such providers so that any personal data is retained only to the extent necessary for performing the requested analysis; it will not be used for training or improving their models where contractual settings permit.
Non-Medical Disclaimer
4.1. The outputs and recommendations from the Service are non-professional and non-therapeutic in nature.
4.2. You agree that any reliance on the Service’s analyses or suggestions is at your own risk and does not substitute licensed clinical judgment.
Security Measures
5.1. We maintain industry-standard security protocols, including encryption, firewalls, and regular audits to prevent unauthorized access or data breaches.
5.2. Logging mechanisms track essential events (e.g., uploads, deletions, errors) to assist in security monitoring and compliance checks.
GDPR Compliance
6.1. We implement appropriate technical and organizational measures to protect personal data under GDPR requirements.
6.2. Users have the right to request access or erasure of their personal data, subject to applicable legal requirements, by contacting our Data Protection Officer or support team.
6.3. Where data is transferred outside the EEA (including any services provided by OpenAI or similar), it is done under adequate legal frameworks, such as Standard Contractual Clauses.
User Obligations
7.1. By using the Service, you represent that you have all necessary rights and authorizations to upload the data submitted.
7.2. You acknowledge that you will not provide data that is unlawful, infringing, or violates any third-party rights.
Liability and Warranties
8.1. The Service is provided “as is,” without warranties of any kind. We disclaim any liability for direct, indirect, incidental, or consequential damages arising from use of the Service.
8.2. Under no circumstance shall the Service be held responsible for decisions made based on its outputs or analyses.
Updates and Amendments
9.1. We reserve the right to modify or update these terms at any time. Any material changes will become effective upon posting the revised Disclaimer.
9.2. Continued use of the Service after such changes constitutes acceptance of any revised terms.
-
Telegram Bots
By interacting with our bots on Telegram, you consent to the collection and processing of your information in accordance with this policy. The files (images, videos, docs, etc) and messages (both audio and text) you send are processed and stored by Telegram's servers, over which we do not have control. For details on how Telegram handles your data, please review their privacy policy at Telegram Privacy Policy. The information you provide is used exclusively to deliver the services offered by the bots, and we do not store, process, or use your information for any other purposes.
How to manage preferences and provide or withdraw consent on this Website
Whenever the use of Trackers is based on consent, users can provide or withdraw such consent by setting or updating their preferences via the relevant privacy choices panel available on this Website.
With regard to any third-party Trackers, Users can manage their preferences via the related opt-out link (where provided), by using the means indicated in the third party's privacy policy, or by contacting the third party.
How to control or delete Cookies and similar technologies via your device settings
Users may use their own browser settings to:
- See what Cookies or other similar technologies have been set on the device;
- Block Cookies or similar technologies;
- Clear Cookies or similar technologies from the browser.
The browser settings, however, do not allow granular control of consent by category.
Users can, for example, find information about how to manage Cookies in the most commonly used browsers at the following addresses:
Users may also manage certain categories of Trackers used on mobile apps by opting out through relevant device settings such as the device advertising settings for mobile devices, or tracking settings in general (Users may open the device settings and look for the relevant setting).
How to opt out of interest-based advertising
Notwithstanding the above, Users may follow the instructions provided by YourOnlineChoices (EU), the Network Advertising Initiative (US) and the Digital Advertising Alliance (US), DAAC (Canada), DDAI (Japan) or other similar services. Such initiatives allow Users to select their tracking preferences for most of the advertising tools. The Owner thus recommends that Users make use of these resources in addition to the information provided in this document.
The Digital Advertising Alliance offers an application called AppChoices that helps Users to control interest-based advertising on mobile apps.
Consequences of denying consent
Users are free to decide whether or not to grant consent. However, please note that Trackers help this Website to provide a better experience and advanced functionalities to Users (in line with the purposes outlined in this document). Therefore, in the absence of the User's consent, the Owner may be unable to provide related features.
Owner and Data Controller
Allure Beauty d.o.o.
Barjanska 70,
Ljubljana 1000
Slovenia
as well as all websites and services owned or operated by ALLURE BEAUTY, including but not limited to: https://vivantskincare.eu
Any reference to ALLURE BEAUTY shall be understood to also include VIVANTSKINCARE.EU, unless otherwise specified.
Owner contact email: office@allurebeauty.eu
Since the use of third-party Trackers through this Website cannot be fully controlled by the Owner, any specific references to third-party Trackers are to be considered indicative. In order to obtain complete information, Users are kindly requested to consult the privacy policies of the respective third-party services listed in this document.
Given the objective complexity surrounding tracking technologies, Users are encouraged to contact the Owner should they wish to receive any further information on the use of such technologies by this Website.