Data Protection Policy

This Policy describes how Moroccanoil collects, uses, and shares your personal data in connection with our products and services.

We are deeply committed to complying with all relevant privacy laws, including the General Data Protection Regulation (GDPR).

Moroccanoil prioritize the protection of personal information and continually strive to uphold the highest standards of data privacy and security in alignment with these regulations.


What Data Do We Collect

We collect personal data about you when you visit our website, purchase products from us, or otherwise interact with us. The personal data we collect may include:


How will we use your data?

We use your data for the following purposes:


Our legal Bases for Processing your Personal Data

The legal bases we rely on for processing your personal data may include:

We will only process your personal data for the purposes for which we collected it, and we will not use it for any other purpose without your consent or a valid legal basis. If we need to use your personal data for a new purpose that is not compatible with the original purpose, we will inform you and seek your consent or a new legal basis for the processing.

If you have any questions or concerns about our legal bases for processing your personal data, please contact us using the information provided at the end of this policy.


How will we store your data?

Your data is stored on Shopify's secure servers. Shopify uses industry-standard security measures to protect your data, including encryption, firewalls, and regular security audits.

We do not share your personal information with third parties for marketing purposes. However, we may share your information with service providers who help us process payments, fulfill orders, and provide customer support. These service providers are contractually obligated to keep your information confidential and secure.

If you have any concerns about how your data is being stored or processed, please contact us at dpo@moroccanoil.com. We will do our best to address your concerns and provide you with the information you need.


Children Privacy

This site is not intended for children, and you must be aged 14 or over to use our website. We do not solicit or knowingly collect personal information from children under the age of 14 without the specific consent of at least one of the parents or the legal guardian. If we are made aware that we have received such information or any information in violation of our policy, we will use reasonable efforts to locate and remove that information from our records.


What are cookies?

Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site.

Cookies are small data files that are placed on your device or computer when you browse a website. They are widely used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site.


How do we use cookies?

We use cookies to:


What types of cookies do we use?

We use the following types of cookies:


How can you control cookies?

We use a cookie management solution to obtain your consent before placing any non-essential cookies on your device. The cookie management solution allows you to manage your cookie preferences and withdraw your consent at any time.


Retention Period

We will only retain your personal data for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means, and the applicable legal requirements.

When we no longer need to retain your personal data, we will securely delete or anonymize it.


Disclosure of your Data

Moroccanoil may disclose your personal data to third-party service providers as necessary to facilitate your interactions with us.

These third parties are obligated to safeguard your information and are only permitted to use it for the purposes of providing services on our behalf. In accordance with our policies, they will dispose of your information appropriately once it is no longer required for the provision of such services.

If we intend to disclose any sensitive personal data to a third party, we will only do so in accordance with the bases for processing your personal data that were previously described.

The following third parties may receive your personal data as part of our processing activities, as specified below:

  Vendor        |   Our Use

Klarna           |   Payment gateway (instalments)

Klaviyo          |   Email Service Provider

Onetrust        |   Privacy Management

PayPal           |   Payment gateway

Yotpo            |  Product Review

Zendesk        |  Help desk management

Sufio             | Generate invoices


Complaints

In the event that you wish to make a complaint about how your personal data is being processed by Moroccanoil, or how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority and Moroccanoil’s Data Protection Officer.

See our contact details below.


Data Security

We are committed to protecting the security of your personal data. We use appropriate technical and organizational measures to protect your personal data from unauthorized access, use, disclosure, alteration, or destruction.

Some of the measures we take to protect your personal data include:

In the event of a personal data breach, we will promptly notify the appropriate EU supervisory authority and the affected individuals within 72 hours, in compliance with the General Data Protection Regulation (GDPR)

In the event of a personal data breach, we will promptly notify the Information Commissioner's Office (ICO) and any affected individuals within 72 hours, as mandated by the General Data Protection Regulation (GDPR).

While we take reasonable steps to protect your personal data, no method of transmission or storage is completely secure, and we cannot guarantee its absolute security. You are responsible for keeping your login credentials, if any, confidential and for not sharing them with anyone.


Data Sharing

We do not share your personal data with third parties for marketing purposes. However, we may share your personal data with service providers who help us fulfill your orders and provide our products and services to you. These service providers are bound by data protection agreements and are not permitted to use your personal data for any other purposes.

We may also share your personal data with law enforcement or other government agencies when required by law or in response to a valid legal request.


Your Rights

Moroccanoil would like to make sure that you are fully aware of all your data protection rights.

You are entitled to the following:

If you make a request, we have one month to respond to you. Please see our contact details below.


International Data Transfer

We may transfer your personal data to third countries outside of the European Economic Area (EEA) for the purposes of providing our services to you and processing your data in accordance with this Privacy Policy.

We will only transfer your personal data to third countries that have been determined to have an adequate level of data protection by the European Commission, or if the data transfer is subject to appropriate safeguards.

The appropriate safeguards that we use for international data transfers include:
• Standard contractual clauses (SCCs) approved by the European Commission
• Binding corporate rules (BCRs)
• Codes of conduct approved by a supervisory authority
• Ad hoc contractual clauses
• Administrative arrangements between public authorities or bodies

We will take all reasonable steps to ensure that your personal data is protected when it is transferred to third countries.


Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes to this Privacy Policy by posting a notice on our website or by sending you an email.


Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at. If you would like to exercise any of these rights, please Contact us by email: dpo@moroccanoil.com