Cookie Policy of beautyblender.com
This document informs Users about the technologies that help this Application to achieve the purposes described below. Such technologies allow the Owner to access and store information (for example by using a Cookie) or use resources (for example by running a script) on a User’s device as they interact with this Application.
For simplicity, all such technologies are defined as "Trackers" within this document – unless there is a reason to differentiate.
For example, while Cookies can be used on both web and mobile browsers, it would be inaccurate to talk about Cookies in the context of mobile apps as they are a browser-based Tracker. For this reason, within this document, the term Cookies is only used where it is specifically meant to indicate that particular type of Tracker.
Some of the purposes for which Trackers are used may also require the User's consent, depending on the applicable law. Whenever consent is given, it can be freely withdrawn at any time following the instructions provided in this document.
This Application uses Trackers managed directly by the Owner (so-called “first-party” Trackers) and Trackers that enable services provided by a third-party (so-called “third-party” Trackers). Unless otherwise specified within this document, third-party providers may access the Trackers managed by them.
The validity and expiration periods of Cookies and other similar Trackers may vary depending on the lifetime set by the Owner or the relevant provider. Some of them expire upon termination of the User’s browsing session.
In addition to what’s specified in the descriptions within each of the categories below, Users may find more precise and updated information regarding lifetime specification as well as any other relevant information — such as the presence of other Trackers — in the linked privacy policies of the respective third-party providers or by contacting the Owner.
Activities strictly necessary for the operation of this Application and delivery of the Service
This Application uses so-called “technical” Cookies and other similar Trackers to carry out activities that are strictly necessary for the operation or delivery of the Service.
Third-party Trackers
-
Tag Management
This type of service helps the Owner to manage the tags or scripts needed on this Application in a centralized fashion.
This results in the Users' Data flowing through these services, potentially resulting in the retention of this Data.
Google Tag Manager (Google LLC)
Google Tag Manager is a tag management service provided by Google LLC.
In order to understand Google's use of Data, consult Google's partner policy.
Personal Data processed: Trackers.
Place of processing: United States – Privacy Policy.
-
Handling payments
Unless otherwise specified, this Application processes any payments by credit card, bank transfer or other means via external payment service providers. In general and unless where otherwise stated, Users are requested to provide their payment details and personal information directly to such payment service providers. This Application isn't involved in the collection and processing of such information: instead, it will only receive a notification by the relevant payment service provider as to whether payment has been successfully completed.
PayPal (PayPal Inc.)
PayPal is a payment service provided by PayPal Inc., which allows Users to make online payments.
Personal Data processed: Trackers.
Place of processing: See the PayPal privacy policy – Privacy Policy.
Storage duration:
- __paypal_storage__: indefinite
- akavpau_ppsd: duration of the session
- enforce_policy: duration of the session
- l7_az: duration of the session
- nsid: duration of the session
- ts: duration of the session
- tsrce: duration of the session
- x-cdn: duration of the session
- x-pp-s: duration of the session
-
Platform services and hosting
These services have the purpose of hosting and running key components of this Application, therefore allowing the provision of this Application from within a unified platform. Such platforms provide a wide range of tools to the Owner – e.g. analytics, user registration, commenting, database management, e-commerce, payment processing – that imply the collection and handling of Personal Data.
Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
Shopify
Shopify is a platform provided by Shopify Inc., Shopify Commerce Singapore Pte. Ltd or by Shopify International Limited, depending on how the Owner manages the Data processing, that allows the Owner to build, run and host an e-commerce website.
Personal Data processed: billing address, device information, email address, first name, last name, phone number, shipping address, Trackers and Usage Data.
Place of processing: Canada – Privacy Policy; Singapore – Privacy Policy; Ireland – Privacy Policy.
Storage duration:
- _ab: 3 years
- _cmp_a: 1 day
- _customer_account_shop_sessions: 1 month
- _landing_page: 14 days
- _orig_referrer: 14 days
- _pay_session: duration of the session
- _s: 30 minutes
- _secure_account_session_id: 1 month
- _secure_session_id: 1 day
- _shopify_country: duration of the session
- _shopify_d: duration of the session
- _shopify_evids: duration of the session
- _shopify_fs: 1 year
- _shopify_ga: indefinite
- _shopify_m: duration of the session
- _shopify_s: 30 minutes
- _shopify_sa_p: 30 minutes
- _shopify_sa_t: 30 minutes
- _shopify_tm: duration of the session
- _shopify_tw: duration of the session
- _shopify_y: 1 year
- _storefront_u: 1 minute
- _tracking_consent: duration of the session
- _y: 1 year
- c: 2 years
- card_update_verification_id: 20 minutes
- cart: 14 days
- cart_currency: 14 days
- cart_sig: 14 days
- cart_ts: 14 days
- cart_ver: 14 days
- checkout: 28 days
- checkout_prefill: 5 minutes
- checkout_queue_checkout_token: 2 years
- checkout_queue_token: 2 years
- checkout_session_lookup: 21 days
- checkout_session_token: 21 days
- checkout_session_token*: 21 days
- checkout_token: 2 years
- checkout_worker_session: 3 days
- customer_account_locale: 1 year
- customer_account_new_login: 20 minutes
- customer_account_preview: 7 days
- customer_auth_provider: indefinite
- customer_auth_session_created_at: indefinite
- customer_payment_method: 1 hour
- customer_shop_pay_agreement: 20 minutes
- discount_code: indefinite
- dynamic_checkout_shown_on_cart: 30 minutes
- hide_shopify_pay_for_checkout: indefinite
- identity-state: 1 day
- identity-state-*: 1 day
- identity_customer_account_number: 3 months
- keep_alive: 14 days
- localization: 14 days
- login_with_shop_finalize: 5 minutes
- master_device_id: 2 years
- order: 21 days
- pay_update_intent_id: 20 minutes
- preview_theme: indefinite
- previous_step: 2 years
- profile_preview_token: 5 minutes
- remember_me: 2 years
- secure_customer_sig: 1 year
- shopify-editor-unconfirmed-settings: 16 hours
- shopify_pay: 2 years
- shopify_pay_redirect: 1 hour
- source_name: indefinite
- storefront_digest: 3 years
- tracked_start_checkout: 2 years
-
Traffic optimization and distribution
This type of service allows this Application to distribute their content using servers located across different countries and to optimize their performance.
Which Personal Data are processed depends on the characteristics and the way these services are implemented. Their function is to filter communications between this Application and the User's browser.
Considering the widespread distribution of this system, it is difficult to determine the locations to which the contents that may contain Personal Information of the User are transferred.
Cloudflare (Cloudflare, Inc.)
Cloudflare is a traffic optimization and distribution service provided by Cloudflare Inc.
The way Cloudflare is integrated means that it filters all the traffic through this Application, i.e., communication between this Application and the User's browser, while also allowing analytical data from this Application to be collected.
Personal Data processed: Trackers.
Place of processing: United States – Privacy Policy.
-
Spam and bots protection
This type of service analyzes the traffic of this Application, potentially containing Users' Personal Data, with the purpose of filtering it from unwanted parts of traffic, messages and content that are recognized as spam or protecting it from malicious bots activities.
Cloudflare Bot Management (Cloudflare, Inc.)
Cloudflare Bot Management is a malicious bot protection and management service provided by Cloudflare, Inc.
Personal Data processed: app information, Application opens, browser information, browsing history, city, clicks, country, county, custom events, device information, device logs, geography/region, interaction events, IP address, keypress events, language, latitude (of city), launches, longitude (of city), metro area, motion sensor events, mouse movements, number of sessions, operating systems, page events, page views, province, scroll position, scroll-to-page interactions, search history, session duration, session statistics, state, touch events, Trackers, Usage Data, video views and ZIP/Postal code.
Place of processing: United States – Privacy Policy.
Storage duration:
- __cf_bm: 3 seconds
- __cfruid: duration of the session
- cf_ob_info: 3 seconds
- cf_use_ob: 3 seconds
- cfmrk_cic: 3 months
Other activities involving the use of Trackers
Experience
This Application uses Trackers to improve the quality of the user experience and enable interactions with external content, networks and platforms.
-
Interaction with data collection platforms and other third parties
This type of service allows Users to interact with data collection platforms or other services directly from the pages of this Application for the purpose of saving and reusing data.
If one of these services is installed, it may collect browsing and Usage Data in the pages where it is installed, even if the Users do not actively use the service.
Mailchimp widget (Intuit Inc.)
The Mailchimp widget is a service for interacting with the Mailchimp email address management and message sending service provided by Intuit Inc.
Personal Data processed: email address, first name, phone number and Trackers.
Place of processing: United States – Privacy Policy.
Storage duration:
- cookies.js: duration of the session
Measurement
This Application uses Trackers to measure traffic and analyze User behavior to improve the Service.
-
Analytics
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Google Analytics (Universal Analytics) (Google LLC)
Google Analytics (Universal Analytics) is a web analysis service provided by Google LLC (“Google”). Google utilizes the Data collected to track and examine the use of this Application, to prepare reports on its activities and share them with other Google services.
Google may use the Data collected to contextualize and personalize the ads of its own advertising network.
In order to understand Google's use of Data, consult Google's partner policy.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy – Opt Out.
Storage duration:
- AMP_TOKEN: 1 hour
- _ga: 2 years
- _gac*: 3 months
- _gat: 1 minute
- _gid: 1 day
Google Analytics 4 (Google LLC)
Google Analytics 4 is a web analysis service provided by Google LLC (“Google”). Google utilizes the Data collected to track and examine the use of this Application, to prepare reports on its activities and share them with other Google services.
Google may use the Data collected to contextualize and personalize the ads of its own advertising network.
In Google Analytics 4, IP addresses are used at collection time and then discarded before Data is logged in any data center or server. Users can learn more by consulting Google’s official documentation.
In order to understand Google's use of Data, consult Google's partner policy.
Personal Data processed: number of Users, session statistics, Trackers and Usage Data.
Place of processing: United States – Privacy Policy – Opt Out.
Storage duration:
- _ga: 2 years
- _ga_*: 2 years
Google Analytics Advertising Reporting Features
Google Analytics on this Application has Advertising Reporting Features activated, which collects additional information from the DoubleClick cookie (web activity) and from device advertising IDs (app activity). It allows the Owner to analyze specific behavior and interests Data (traffic Data and Users' ads interaction Data) and, if enabled, demographic Data (information about the age and gender).
Users can opt out of Google's use of cookies by visiting Google's Ads Settings.
In order to understand Google's use of Data, consult Google's partner policy.
Personal Data processed: Trackers, unique device identifiers for advertising (Google Advertiser ID or IDFA, for example) and various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy – Opt Out; Ireland – Privacy Policy – Opt Out.
Storage duration:
- IDE: 2 years
- _gcl_*: 3 months
- test_cookie: 15 minutes
Meta Events Manager (Meta Platforms, Inc.)
Meta Events Manager is an analytics service provided by Meta Platforms, Inc. By integrating the Meta pixel, Meta Events Manager can give the Owner insights into the traffic and interactions on this Application.
Personal Data processed: Trackers.
Place of processing: United States – Privacy Policy – Opt out.
Storage duration:
-
Heat mapping and session recording
Heat mapping services are used to display the areas of this Application that Users interact with most frequently. This shows where the points of interest are. These services make it possible to monitor and analyze web traffic and keep track of User behavior.
Some of these services may record sessions and make them available for later visual playback.
Hotjar Heat Maps & Recordings (Hotjar Ltd.)
Hotjar is a session recording and heat mapping service provided by Hotjar Ltd.
Hotjar honors generic „Do Not Track” headers. This means the browser can tell its script not to collect any of the User's data. This is a setting that is available in all major browsers. Find Hotjar’s opt-out information here.
Personal Data processed: Trackers, Usage Data and various types of Data as specified in the privacy policy of the service.
Place of processing: Malta – Privacy Policy – Opt Out.
Storage duration:
- _hjAbsoluteSessionInProgress: 30 minutes
- _hjCachedUserAttributes: duration of the session
- _hjClosedSurveyInvites: 1 year
- _hjDonePolls: 1 year
- _hjFirstSeen: duration of the session
- _hjIncludedInSessionSample: 30 minutes
- _hjLocalStorageTest: duration of the session
- _hjLocalStorageTest: duration of the session
- _hjMinimizedPolls: 1 year
- _hjSession*: 30 minutes
- _hjSessionRejected: duration of the session
- _hjSessionResumed: duration of the session
- _hjSessionTooLarge: 1 hour
- _hjSessionUser*: 1 year
- _hjSessionUser_*: 2 years
- _hjShownFeedbackMessage: 1 year
- _hjTLDTest: duration of the session
- _hjUserAttributesHash: duration of the session
- _hjViewportId: duration of the session
- _hjid: 1 year
Marketing
This Application uses Trackers to deliver personalized marketing content based on User behavior and to operate, serve and track ads.
-
Advertising
This type of service allows User Data to be utilized for advertising communication purposes. These communications are displayed in the form of banners and other advertisements on this Application, possibly based on User interests.
This does not mean that all Personal Data are used for this purpose. Information and conditions of use are shown below.
Some of the services listed below may use Trackers to identify Users or they may use the behavioral retargeting technique, i.e. displaying ads tailored to the User’s interests and behavior, including those detected outside this Application.
For more information, please check the privacy policies of the relevant services.
Services of this kind usually allow Users to opt out of such tracking. Users may learn how to opt out of interest-based advertising more generally by visiting the relevant opt-out section in this document.
Amazon Advertising (Amazon)
Amazon Advertising is an advertising service provided by Amazon.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy – Opt out.
Storage duration:
- *sessionMarker/marker: indefinite
- ad-id: 10 months
- amzn-token: 7 days
- vendor-id: 1 month
Criteo (Criteo SA)
Criteo is an advertising service provided by Criteo SA.
As part of the operation of this Application, the Owner and Criteo SA are joint controllers for the Criteo advertising service.
For this purpose, the Owner has entered into a Data Processing Agreement (DPA) with Criteo SA which can be reviewed here.
Users may at any time withdraw their consent to the processing of their Personal Data by Criteo and opt out of personalized advertising by clicking the “Disable Criteo services” button in Criteo’s privacy policy.
Personal Data processed: Trackers and Usage Data.
Place of processing: France – Privacy Policy – Opt Out.
Storage duration:
- criteo_fast_bid: 7 days
- criteo_fast_bid_expires: 7 days
- cto_bundle: 2 years
- cto_bundle: indefinite
- cto_optout: 5 years
- cto_optout: indefinite
- optout: 5 years
- uid: 2 years
Hotjar Form Analysis & Conversion Funnels (Hotjar Ltd.)
Hotjar is an analytics service provided by Hotjar Ltd.
Hotjar honors generic Do Not Track headers. This means your browser can tell its script not to collect any of your data. This is a setting that is available in all major browsers. Find Hotjar’s opt-out information here.
Personal Data processed: Trackers and Usage Data.
Place of processing: Malta – Privacy Policy – Opt Out.
Storage duration:
- _hjAbsoluteSessionInProgress: 30 minutes
- _hjCachedUserAttributes: duration of the session
- _hjClosedSurveyInvites: 1 year
- _hjDonePolls: 1 year
- _hjFirstSeen: duration of the session
- _hjIncludedInSessionSample: 30 minutes
- _hjLocalStorageTest: duration of the session
- _hjMinimizedPolls: 1 year
- _hjSession*: 30 minutes
- _hjSessionRejected: duration of the session
- _hjSessionResumed: duration of the session
- _hjSessionTooLarge: 1 hour
- _hjSessionUser*: 1 year
- _hjSessionUser_*: 2 years
- _hjShownFeedbackMessage: 1 year
- _hjTLDTest: duration of the session
- _hjUserAttributesHash: duration of the session
- _hjViewportId: duration of the session
- _hjid: 1 year
Pinterest Ads (Pinterest, Inc.)
Pinterest Ads is an advertising service provided by Pinterest, Inc. that allows the Owner to run advertising campaigns on the Pinterest advertising network.
Users may opt out of behavioral advertising features through their device settings, their Pinterest personalization settings.
Personal Data processed: Trackers.
Place of processing: United States – Privacy Policy – Opt out.
Storage duration:
- _pin_unauth: 1 year
- _pinterest_ct_ua: duration of the session
Pinterest Conversion Tag (Pinterest, Inc.)
Pinterest Conversion Tag is an analytics service provided by Pinterest, Inc. that connects data from the Pinterest advertising network with actions performed on this Application.
Users may opt out of behavioral advertising features through their device settings, their Pinterest personalization settings or by visiting the AdChoices opt-out page.
Personal Data processed: device information, Trackers and Usage Data.
Place of processing: United States – Privacy Policy – Opt out.
Storage duration:
- _pin_unauth: 1 year
- _pinterest_ct_ua: duration of the session
TikTok conversion tracking (TikTok Inc.)
TikTok conversion tracking is an analytics and behavioral targeting service provided by TikTok Inc. that connects data from the TikTok advertising network with actions performed on this Application. The TikTok pixel tracks conversions that can be attributed to TikTok ads and enables to target groups of Users on the base of their past use of this Application.
Personal Data processed: Trackers.
Place of processing: United States – Privacy Policy.
Meta ads conversion tracking (Meta pixel) (Meta Platforms, Inc.)
Meta ads conversion tracking (Meta pixel) is an analytics service provided by Meta Platforms, Inc. that connects data from the Meta Audience Network with actions performed on this Application. The Meta pixel tracks conversions that can be attributed to ads on Facebook, Instagram and Meta Audience Network.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy – Opt out.
Storage duration:
- _fbp: 3 months
- fr: 3 months
-
Commercial affiliation
This type of service allows this Application to display advertisements for third-party products or services. Ads can be displayed either as advertising links or as banners using various kinds of graphics.
Clicks on the icon or banner posted on the Application are tracked by the third-party services listed below, and are shared with this Application.
For details of which data are collected, please refer to the privacy policy of each service.
Amazon Affiliation (Amazon)
Amazon Affiliation is a commercial affiliation service provided by Amazon.com Inc.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy.
-
Managing contacts and sending messages
This type of service makes it possible to manage a database of email contacts, phone contacts or any other contact information to communicate with the User.
These services may also collect data concerning the date and time when the message was viewed by the User, as well as when the User interacted with it, such as by clicking on links included in the message.
Klaviyo (Klaviyo Inc.)
Klaviyo is an email address management and message sending service provided by Klaviyo Inc.
To take advantage of the service provided by Klaviyo, the Owner typically shares information about (purchasing) Users, such as for example contact details and shopping histories. Check the indication at “Personal Data processed“ below for an explanation of the extent of the sharing.
Personal Data processed: Trackers.
Place of processing: United States – Privacy Policy – Opt out.
Storage duration:
-
Remarketing and behavioral targeting
This type of service allows this Application and its partners to inform, optimize and serve advertising based on past use of this Application by the User.
This activity is facilitated by tracking Usage Data and by using Trackers to collect information which is then transferred to the partners that manage the remarketing and behavioral targeting activity.
Some services offer a remarketing option based on email address lists.
Services of this kind usually allow Users to opt out of such tracking. Users may learn how to opt out of interest-based advertising more generally by visiting the relevant opt-out section in this document.
Adobe Audience Manager (Adobe Systems Incorporated)
Adobe Audience Manager is a remarketing and behavioral targeting service provided by Adobe Systems Incorporated.
Adobe Audience Manager makes use of tracking technologies to monitor User behavior. This Data is then used to personalize the User's experience and to provide targeted advertising. Adobe Audience Manager may also connect the collected Data with other networks, including advertising networks, and enable these parties to track and target the User. The Owner, unless otherwise specified in this document, has no direct relationship with the third parties that Adobe Audience Manager may be including.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy – Opt Out.
Storage duration:
- demdex: 6 months
- dextp: 6 months
- dst: 6 months
TikTok Remarketing ( TikTok Information Technologies UK Limited )
TikTok Remarketing is a remarketing and behavioral targeting service provided by TikTok Information Technologies UK Limited that connects the activity of this Application with the TikTok advertising network.
Personal Data processed: Trackers.
Place of processing: United Kingdom – Privacy Policy.
How to manage preferences and provide or withdraw consent
There are various ways to manage Tracker related preferences and to provide and withdraw consent, where relevant:
Users can manage preferences related to Trackers from directly within their own device settings, for example, by preventing the use or storage of Trackers.
Additionally, whenever the use of Trackers is based on consent, Users can provide or withdraw such consent by setting their preferences within the cookie notice or by updating such preferences accordingly via the relevant consent-preferences privacy widget, if available.
It is also possible, via relevant browser or device features, to delete previously stored Trackers, including those used to remember the User’s initial consent preferences.
Other Trackers in the browser’s local memory may be cleared by deleting the browsing history.
With regard to any third-party Trackers, Users can manage their preferences via the related opt-out link (where provided), by using the means indicated in the third party's privacy policy, or by contacting the third party.
Locating Tracker Settings
Users can, for example, find information about how to manage Cookies in the most commonly used browsers at the following addresses:
Users may also manage certain categories of Trackers used on mobile apps by opting out through relevant device settings such as the device advertising settings for mobile devices, or tracking settings in general (Users may open the device settings and look for the relevant setting).
How to opt out of interest-based advertising
Notwithstanding the above, Users may follow the instructions provided by YourOnlineChoices (EU and UK), the Network Advertising Initiative (US) and the Digital Advertising Alliance (US), DAAC (Canada), DDAI (Japan) or other similar services. Such initiatives allow Users to select their tracking preferences for most of the advertising tools. The Owner thus recommends that Users make use of these resources in addition to the information provided in this document.
The Digital Advertising Alliance offers an application called AppChoices that helps Users to control interest-based advertising on mobile apps.
Consequences of denying the use of Trackers
Users are free to decide whether or not to allow the use of Trackers. However, please note that Trackers help this Application to provide a better experience and advanced functionalities to Users (in line with the purposes outlined in this document). Therefore, if the User chooses to block the use of Trackers, the Owner may be unable to provide related features.
Owner and Data Controller
Eric Haydt
Rea.Deeming Beauty, Inc dba Beautyblender
2020 Highland Ave
Bethlehem, PA. 18020
Owner contact email: eric.haydt@beautyblender.com
Since the use of third-party Trackers through this Application cannot be fully controlled by the Owner, any specific references to third-party Trackers are to be considered indicative. In order to obtain complete information, Users are kindly requested to consult the privacy policies of the respective third-party services listed in this document.
Given the objective complexity surrounding tracking technologies, Users are encouraged to contact the Owner should they wish to receive any further information on the use of such technologies by this Application.