Privacy Policy of Pai Skincare

This Website collects some Personal Data from its Users.

Personal Data processed for the following purposes and using the following services:

    • Access to third party services' accounts

      • Facebook account access

        Permissions: Contact email

      • Access to the Twitter account and Stripe account access

        Personal Data: various types of Data as specified in the privacy policy of the service

    • Advertising

      • Google Ads conversion tracking, Meta ads conversion tracking (Meta pixel), X Ads conversion tracking and Hotjar Form Analysis & Conversion Funnels

        Personal Data: Trackers; Usage Data

      • Microsoft Advertising Universal Event Tracking

        Personal Data: Trackers; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); Universally unique identifier (UUID); Usage Data

      • Facebook Lookalike Audience, Google Ads Similar audiences and Google Ad Manager

        Personal Data: Cookies; Usage Data

      • Criteo

        Personal Data: Tracker; Usage Data

      • Pinterest Ads

        Personal Data: device information; email address; Tracker; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); Usage Data; User ID

      • Pinterest Conversion Tag

        Personal Data: device information; Trackers; Usage Data

      • AdMob

        Personal Data: Tracker; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); Usage Data

      • Google Campaign Manager 360

        Personal Data: geographic position; Tracker; Usage Data

    • Analytics

      • Google Analytics, Wordpress Stats and Analytics collected directly

        Personal Data: Cookies; Usage Data

      • Google Analytics Advertising Reporting Features

        Personal Data: Cookies; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); various types of Data as specified in the privacy policy of the service

      • User ID extension for Google Analytics

        Personal Data: Cookies

      • Sweet Analytics

      • Google Analytics 4

        Personal Data: number of Users; session statistics; Trackers; Usage Data

    • Backup saving and management

      • Backup on Google Drive and Backup on Dropbox

        Personal Data: various types of Data as specified in the privacy policy of the service

    • Commercial affiliation

      • ReferralCandy

        Personal Data: Cookies; email address; first name; last name; Usage Data

    • Connecting Data

      • Zapier

        Personal Data: city; company name; country; Data communicated while using the service; date of birth; device information; email address; first name; gender; geographic position; language; last name; phone number; Usage Data

    • Contacting the User

      • Contact form

        Personal Data: email address; first name; last name; phone number; User ID; various types of Data

      • Mailing List or Newsletter

        Personal Data: address; city; company name; Cookies; country; date of birth; email address; first name; gender; last name; phone number; profession; province; state; Usage Data; ZIP/Postal code

      • Phone contact

        Personal Data: phone number

    • Content commenting

      • Yotpo

    • Content performance and features testing (A/B testing)

      • Optimizely

        Personal Data: Tracker; Usage Data

    • Data transfer outside of the UK

      • Data transfers according to a UK adequacy regulation and Data transfer abroad based on standard contractual clauses (UK)

        Personal Data: various types of Data

    • Data transfer outside the EU

      • Data transfer abroad based on consent, Data transfer abroad based on standard contractual clauses, Data transfer from the EU and/or Switzerland to the U.S based on Privacy Shield, Data transfer to countries that guarantee European standards and Other legal basis for Data transfer abroad

        Personal Data: various types of Data

    • Displaying content from external platforms

      • Adobe Edge Web Fonts, Fonts.com Web Fonts, Google Fonts, MyFonts and Adobe Fonts

        Personal Data: Usage Data; various types of Data as specified in the privacy policy of the service

      • Google Calendar widget, Google Maps widget, Instagram widget, JWPlayer widget and YouTube video widget

        Personal Data: Cookies; Usage Data

      • Getty Images widget

        Personal Data: Tracker; Usage Data

      • Klevu

    • Handling payments

      • Apple Pay, Amazon Payments, PayPal, Stripe, Chargify, GoCardless, Google Pay and Klarna

        Personal Data: various types of Data as specified in the privacy policy of the service

    • Handling productivity related activity

      • Gmail

        Personal Data: Data communicated while using the service; Tracker

    • Heat mapping and session recording

      • Hotjar Heat Maps & Recordings

        Personal Data: Cookies; Usage Data; various types of Data as specified in the privacy policy of the service

    • Hosting and backend infrastructure

      • Amazon Web Services (AWS), Google Cloud Storage and Google App Engine

        Personal Data: various types of Data as specified in the privacy policy of the service

      • Akamai Content Delivery Network

        Personal Data: Cookies; Usage Data

      • Netsuite

      • iubenda Consent Solution

        Personal Data: Data communicated while using the service

    • Infrastructure monitoring

      • Raygun

        Personal Data: various types of Data as specified in the privacy policy of the service

    • Interaction with data collection platforms and other third parties

      • Wufoo Widget

        Personal Data: Cookies; Usage Data

      • Mailchimp widget

        Personal Data: Cookies; email address; first name; last name; Usage Data

      • Hotjar Recruit User Testers

        Personal Data: Cookies; Usage Data; various types of Data

    • Interaction with external social networks and platforms

      • Google+ +1 button and social widgets, Twitter Tweet button and social widgets and AddThis

        Personal Data: Cookies; Usage Data

    • Interaction with live chat platforms

      • Zopim Widget

        Personal Data: Cookies; Usage Data

      • Zendesk Chat

        Personal Data: address; company name; country; Data communicated while using the service; email address; first name; last name; phone number; Tracker; Usage Data

    • Interaction with online survey platforms

      • SurveyMonkey Widget

        Personal Data: Cookies; Usage Data

      • Hotjar Poll & Survey widgets

        Personal Data: Cookies; Usage Data; various types of Data

    • Interaction with support and feedback platforms

      • Zendesk Widget

        Personal Data: Cookies; Usage Data

    • Location-based interactions

      • Non-continuous geolocation

        Personal Data: geographic position

    • Managing contacts and sending messages

      • Mailchimp and Amazon Simple Email Service

        Personal Data: email address

      • Ometria

    • Managing data collection and online surveys

      • SurveyMonkey

        Personal Data: address; company name; Cookies; country; Data communicated while using the service; date of birth; email address; first name; gender; geographic position; last name; phone number; profession; state; Usage Data; username

      • Facebook lead ads and Hotjar surveys

        Personal Data: Data communicated while using the service; email address; first name; last name; Tracker

    • Managing support and contact requests

      • Zendesk

        Personal Data: various types of Data as specified in the privacy policy of the service

    • Platform services and hosting

      • WordPress.com and Shopify

        Personal Data: various types of Data as specified in the privacy policy of the service

    • Registration and authentication

      • Facebook Authentication, Google OAuth, Instagram Authentication, Linkedin OAuth, Log In with PayPal, Login with Amazon, Pinterest OAuth and Twitter OAuth

        Personal Data: various types of Data as specified in the privacy policy of the service

      • Sign in with Apple

        Personal Data: email address; first name; last name; phone number; User ID

    • Registration and authentication provided directly by this Website

      • Direct registration

        Personal Data: address; billing address; country; date of birth; email address; first name; gender; language; last name; Tracker; Usage Data; User ID; various types of Data

    • Remarketing and behavioral targeting

      • Twitter Tailored Audiences and Facebook Custom Audience

        Personal Data: Cookies; email address

      • Twitter Remarketing, Remarketing with Google Analytics, Facebook Remarketing, Google Ads Remarketing, AdRoll, Google Signals and Google Ad Manager Audience Extension

        Personal Data: Cookies; Usage Data

      • Criteo Dynamic Retargeting

        Personal Data: Tracker; Usage Data

      • Yieldify

    • Social features

      • Inviting and suggesting friends

        Personal Data: various types of Data

    • SPAM protection

      • Google reCAPTCHA

        Personal Data: Cookies; Usage Data

    • Tag Management

      • Google Tag Manager

        Personal Data: Usage Data

      • Segment

        Personal Data: Tracker; Usage Data

    • Traffic optimization and distribution

      • Cloudflare

        Personal Data: Cookies; various types of Data as specified in the privacy policy of the service

    • User database management

      • HubSpot CRM

        Personal Data: email address; phone number; various types of Data as specified in the privacy policy of the service

      • HubSpot Lead Management

        Personal Data: various types of Data as specified in the privacy policy of the service

      • Intercom

        Personal Data: Cookies; email address; Usage Data; various types of Data as specified in the privacy policy of the service

Information on opting out of interest-based advertising

In addition to any opt-out feature provided by any of the services listed in this document, Users may learn more on how to generally opt out of interest-based advertising within the dedicated section of the Cookie Policy.

Further information about the processing of Personal Data

    • Websites covered by these policies

      Pai Skincare Ltd. operates e-commerce websites in the following regions: paiskincare.com (UK), paiskincare.us (USA), paiskincare.com.au (Australia), including subdomains such as blog.paiskincare.com.

      Pai Skincare Canada operates an e-commerce website in Canada.

      Unless otherwise stated, orders are shipped by Pai Skincare from its facility in London UK or from a 3PL (3rd Party Logistics) warehouse under contract with Pai Skincare located closer to the customer's delivery address.

      Pai Skincare Canada is a subsidiary of Pai Skincare Ltd UK.

    • Selling goods and services online

      The Personal Data collected are used to provide the User with services or to sell goods, including payment and possible delivery.
      The Personal Data collected to complete the payment may include the credit card, the bank account used for the transfer, or any other means of payment envisaged. The kind of Data collected by this Website depends on the payment system used.

    • The Service is not directed to children under the age of 13

      Users declare themselves to be adult according to their applicable legislation. Minors may use this Website only with the assistance of a parent or guardian. Under no circumstance persons under the age of 13 may use this Website.

    • Personal Data collected through sources other than the User

      The Owner of this Website may have legitimately collected Personal Data relating to Users without their knowledge by reusing or sourcing them from third parties on the grounds mentioned in the section specifying the legal basis of processing.
      Where the Owner has collected Personal Data in such a manner, Users may find specific information regarding the source within the relevant sections of this document or by contacting the Owner.

    • Automated decision-making

      Automated decision-making means that a decision which is likely to have legal effects or similarly significant effects on the User, is taken solely by technological means, without any human intervention. This Website may use the User's Personal Data to make decisions entirely or partially based on automated processes according to the purposes outlined in this document. This Website adopts automated decision-making processes as far as necessary to enter into or perform a contract between User and Owner, or on the basis of the User’s explicit consent, where such consent is required by the law.
      Automated decisions are made by technological means – mostly based on algorithms subject to predefined criteria – which may also be provided by third parties.
      The rationale behind the automated decision making is:

      • to enable or otherwise improve the decision-making process;
      • to grant Users fair and unbiased treatment based on consistent and uniform criteria;
      • to reduce the potential harm derived from human error, personal bias and the like which may potentially lead to discrimination or imbalance in the treatment of individuals etc.;
      • to reduce the risk of User's failure to meet their obligation under a contract. To find out more about the purposes, the third-party services, if any, and any specific rationale for automated decisions used within this Website, Users can check the relevant sections in this document.

      Consequences of automated decision-making processes for Users and rights of Users subjected to it

      As a consequence, Users subject to such processing, are entitled to exercise specific rights aimed at preventing or otherwise limiting the potential effects of the automated decisions taken.
      In particular, Users have the right to:

      • obtain an explanation about any decision taken as a result of automated decision-making and express their point of view regarding this decision;
      • challenge a decision by asking the Owner to reconsider it or take a new decision on a different basis;
      • request and obtain from the Owner human intervention on such processing.

      To learn more about the User’s rights and the means to exercise them, the User is invited to consult the section of this document relating to the rights of the User.

    • Analysis and predictions based on the User’s Data (“profiling”)

      The Owner may use the Personal and Usage Data collected through this Website to create or update User profiles. This type of Data processing allows the Owner to evaluate User choices, preferences and behaviour for the purposes outlined in the respective section of this document.
      User profiles can also be created through the use of automated tools like algorithms, which can also be provided by third parties. To find out more about the profiling activities performed, Users can check the relevant sections of this document.
      The User always has a right to object to this kind of profiling activity. To find out more about the User's rights and how to exercise them, the User is invited to consult the section of this document outlining the rights of the User.

    • Privacy Shield participation: data transfers from the EU and Switzerland to the United States

      The Owner participates in and complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of Personal Data transferred from the European Union and Switzerland to the United States. The policies and rights outlined below are therefore equally and explicitly applicable to Users from Switzerland, except if stated otherwise. The Owner has certified to the Department of Commerce that it adheres to the Privacy Shield Principles.

      If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view the Owner’s certification, please visit https://www.privacyshield.gov/ (or find the direct link to the certification list of Privacy Shield participants maintained by the Department of Commerce https://www.privacyshield.gov/list).

      What does this mean for the European User?

      The Owner is responsible for all processing of Personal Data it receives under the Privacy Shield Framework from European Union individuals and commits to subject the processed Personal Data to the Privacy Shield Principles.

      This, most importantly, includes the right of individuals to access their personal data processed by the Owner.

      The Owner also complies with the Privacy Shield Principles for all onward transfers of Personal Data from the EU, which means that it remains liable in cases of onward transfers to third parties.

      With respect to Personal Data received or transferred pursuant to the Privacy Shield Framework, the Owner is subject to the investigatory and regulatory enforcement powers of the FTC, if not stated otherwise in this privacy policy.

      The Owner is further required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

      Dispute resolution under the Privacy Shield

      In compliance with the Privacy Shield Principles, the Owner commits to resolve complaints about its collection or use of the User’s Personal Data. European Union individuals with inquiries or complaints regarding this Privacy Shield policy should first contact the Owner at the contact details supplied at the beginning of this document referring to “Privacy Shield” and expect the complaint to be dealt with within 45 days.

      In case of failure by the Owner to provide a satisfactory or timely response, the User has the option of involving an independent dispute resolution body, free of charge.

      In this regard, the Owner has agreed to cooperate with the panel established by the EU data protection authorities (DPAs) and comply with the advice given by the panel with regard to data transferred from the EU. The User may therefore contact the Owner at the email address provided at the beginning of this document in order to be directed to the relevant DPA contacts.

      Under certain conditions – available for the User in full on the Privacy Shield website (https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint) – the User may invoke binding arbitration when other dispute resolution procedures have been exhausted

    • Site specific TCF v2 Cookie (euconsent-v2)

      Site specific TCF v2 Cookie (euconsent-v2) stores User advertising tracking preferences in the local domain.

    • sessionStorage

      sessionStorage allows this Website to store and access data right in the User's browser. Data in sessionStorage is deleted automatically when the session ends (in other words, when the browser tab is closed).

    • Rights for registered California Users under the age of 18

      California's "Online Eraser" law, part of California's Business and Professions Code Sections 22580-22582, requires operators of certain websites and online services targeting minors to allow registered Users who are under the age of 18 and residents of California to request removal of content they post.

      If a registered User fits that description and posted content on this Website, they may request removal of such content by contacting the Owner or its privacy policy coordinator at the contact details provided in this document.

      In response to this request, the Owner may make content posted by the registered User invisible to other registered Users and the public (rather than deleting it entirely), in which case the content may remain on the Owner's servers. It may also be publicly available elsewhere if a third party copied and reposted this content.

    • Preference Cookies

      Preference Cookies store the User preferences detected on this Website in the local domain such as, for example, their timezone and region.

    • iubenda Cookie Solution (remote consent Cookie)

      Remote iubenda consent Cookie (_iub_cs-X) is set by the iubenda Cookie Solution and stores User preferences related to Trackers under the .iubenda.com domain.

    • iubenda Cookie Solution (consent Cookie)

      iubenda consent Cookie (_iub_cs-X) is set by the iubenda Cookie Solution and stores User preferences related to Trackers in the local domain.

    • iubenda CCPA Cookie (usprivacy)

      iubenda CCPA Cookie (usprivacy) is set by the iubenda Cookie Solution and stores California consumer opt-out choices in the local domain.

    • Global TCF v2 Cookie (euconsent-v2)

      Global TCF v2 Cookie (euconsent-v2) stores User advertising tracking preferences under the .consensu.org domain. When a Global TCF v2 Cookie (euconsent-v2) is set by the iubenda Cookie Solution, also a local 'cache' Cookie is stored in the local domain.

    • CCPA: Collection of personal information about minors

      We do not knowingly collect personal information of consumers who are below the age of 16.

Contact information

    • Owner and Data Controller

      Pai Skincare Ltd, a Limited Company registered in England & Wales (Company Number: 05887401) whose registered address is Milton House Gatehouse Road, Aylesbury HP19 8EA, UK and whose Head Office is 18 Colville Road, London W3 8BL, UK and operating websites at www.paiskincare.com, www.paiskincare.us and www.paiskincare.com.au.

      Pai Skincare Canada (Corporation Number: 905680-7) is a Federal Corporation in Canada and a subsidiary of Pai Skincare Ltd (UK). Its registered office is at 178 Main Street, Suite 202, Unionville ON L3R 2G9, Canada. Pai Skincare Canada operates a website at www.paiskincare.ca.

      Owner contact email: support@paiskincare.com