Updated: October 1, 2024
Protecting your privacy is important to Perfect365, Inc. (“Perfect365,” “us,” “our,” or “we”). This Privacy Policy contains important information on how and why we collect, store, use, and share your personal information or personal data (used interchangeably in this Privacy Policy). It also explains your rights in relation to your personal information and how to contact us or supervisory authorities in the event you have a complaint.
Please read this Privacy Policy before using the Perfect365 family of websites, mobile products, and services. BY USING ANY OF OUR PRODUCTS OR SERVICES OR COMMUNICATING WITH US, YOU CONSENT TO THE COLLECTION, TRANSFER, PROCESS, STORAGE, DISCLOSURE, AND USE OF YOUR INFORMATION AS DESCRIBED IN THIS PRIVACY POLICY. IF YOU DO NOT AGREE WITH THIS, PLEASE DO NOT USE AN USE OUR PRODUCTS OR SERVICES.
This Policy explains our online and offline information practices, the kinds of information we may collect, how we intend to use and share that information, and how you can opt-out of a use or correct or change such information. This Policy applies to information we may collect from you or that you may provide when you visit any of our mobile products or services, including but not limited to the mobile applications, Perfect365, Perfect365 Video, Perfect365 Studio, and Perfect365 SoREAL AI (each, an “Application” and collectively the “Applications”), the website perfect365.com and any other websites and subdomains provided by us on which a link to this Policy is displayed (the “Website”), or when you communicate with us through a “@perfect365.com” email address or otherwise provide us with information, including through a third party on your behalf (the “Communications”), and our practices for collecting, using, maintaining, protecting, and disclosing that information (Applications, Website, and Communications, collectively, the “Services”). This Policy does not apply to information collected by any third party, including through any application or content (including advertising), that may link to or be accessible from or through the Services.
Please read this Policy carefully to understand our policies and practices regarding your information and how we will treat it.
We may collect and use the following personal information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household that is commonly gathered and produced by automatic means, provided directly from you, and/or by your interactions with us or our Services.
Information you provide us directly
Information We Collect Automatically from Your Use of the Applications
Information We Collect from Your Use of the Website
We use cookies or other automatic data collection techniques, which are small data files stored on a visitor’s computer or internet-enabled device that serve a number of purposes such as enhancing your on-line experience when visiting our Website only.
You can control or set your cookies, you may also set your browser to block all cookies, including cookies associated with our Website, or to indicate when a cookie is being set by us. However, it’s important to remember that our Website and/or settings and preferences controlled by such cookies may not function properly if your cookies are disabled. For example, we may not remember your language preferences. Most web browsers automatically accept cookies but provide controls that allow you to turn off, block or delete them. Learn more at https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DAndroid&hl=en.
Generally, and without limiting the uses of information we describe in this Privacy Policy, including in Section 2 (Information We Collect), we may use information that we receive and the choices you make in your settings:
Perfect365 treats your personal information with care. We only pass personal information to our affiliates and third parties to the extent described here and within the scope of the purpose limitation under applicable data protection law.
Third-Party Service Providers
We use a variety of third-party service providers to help us provide the Services, including business analytics, marketing, payment processing, IT, artificial intelligence, and virtual currency providers. These providers have limited access to your information to perform these tasks on our behalf and are contractually obligated to use it consistent with this Privacy Policy.
For the SoREAL AI Application, we use neural network model Stable Diffusion powered by Stability.ai for the Perfect365 SoReal AI app that allows you to generate personalized SoREAL AI avatars. While we make best efforts to moderate the settings of the Perfect365 SoREAL AI app, it is still possible that you may encounter content that you or others may view as offensive or inappropriate. Please contact us at support@perfect365.com if you find any content to be offensive and/or inappropriate to you, and we will take action to assist in training the algorithm better. However, you acknowledge that your use of the SoReal AI app is at your own risk and that we disclaim any responsibility for the images generated by the Perfect365 SoReal AI app. For any and all important questions about Stable Diffusion, you can visit the Stability.ai website.
We have also integrated the consent management tool, “Consent Manager” (www.consentmanager.net) from Consent Manager AB (Håltgelvågen 1b, 72348 Västerås, Sweden, mail@consentmanager.net), in our Services to obtain consent for data processing and use of cookies or comparable functions. With the help of Consent Manager, you can provide your consent for certain functionalities of our Services, e.g. for the purpose of integrating external elements, integrating streaming content, statistical analysis, measurement and personalized advertising, and can grant or reject your consent for all functions or give your consent for individual purposes or individual functions. The settings you have made can also be changed afterwards.
The purpose of integrating Consent Manager is to let users of our Services make decisions about their information and, as part of the further use of our Services, to offer the option of changing settings that have already been made. By using Consent Manager, personal data and information from the end devices used, such as the IP address, are processed by Consent Manager. In addition, the processed information may also be stored on your device.
The legal basis for processing is Art. 6 Para. 1 S. 1 lit. c) in conjunction with Art. 6 para. 3 sentence 1 lit. a) in conjunction with Art. 7 para. 1 GDPR and, in the alternative, lit. f). By processing the data, Consent Manager helps us to fulfill our legal obligations (e.g. obligation to provide evidence). Our legitimate interests in processing lie in the storage of user settings and preferences with regard to the use of cookies and other functionalities. Consent Manager stores your data as long as your user settings are active. After two years after making the user settings, the consent will be asked again. The user settings made are then saved again for this period. You can object to the processing. You have the right to object to reasons arising from your particular situation. To object, please send an email to mail@consentmanager.net.
Third-Party Advertisers, Advertising Network, Agencies, Marketers, Cybersecurity Partners
We may share or disclose aggregated, usage information, geolocation information and/or device-level information (such as anonymous usage data, platform types, number of clicks, location data etc.) with unaffiliated partners and third parties (e.g. advertisers, advertising networks and platforms, agencies, other marketers, retailers, cybersecurity partners) that wish to market products or services to you, in order to improve connectivity and application experiences on wireless networks, or for cybersecurity purposes. You can control or disable the use of location services for the Services in the device’s settings menu. See Section 6 (Your Choices About Your Information) of this Privacy Policy for further instructions.
Additional privacy terms from select partners can be found here.
Other Users
Any information that you provide to other users, including beauty professionals, via the Services, are shared and disclosed to such other users. By sending your information to other users, you acknowledge and agree that they may contact you via the applicable Application.
Business Transfers and Affiliates
We may share your information with companies or organizations connected or affiliated with Perfect365. We may also transfer your information to an affiliate, a subsidiary or a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of Perfect365’s business, assets or stock, including, without limitation, in connection with any bankruptcy or similar proceeding.
Legal Disclosures
Notwithstanding anything to the contrary in this Privacy Policy, we may preserve or disclose your information if we believe that it is reasonably necessary to comply with a law, regulation, legal process, or governmental request; to protect the safety of any person; to address fraud, security or technical issues; or to protect our or our users’ rights or property. However, nothing in this Privacy Policy is intended to limit any legal defenses or objections that you may have to a third party’s, including a government’s, request to disclose your information.
During the last twelve (12) months, Perfect365 has sold or disclosed personal information, including some or all of the categories of information described in Section 2 (Information We Collect), to third parties for business and commercial purposes. More specifically, Perfect365 has sold or disclosed the above-described personal information with third parties as described in Section 4 (Information Sharing and Disclosure to Third Parties), including: (a) to our business partners for enabling and improving their marketing and advertising campaigns, from identifying potentially interested consumers to measuring the effectiveness of the marketing and advertising campaign, including marketing and user and data analytics; (b) to our service providers and cybersecurity business partners, for disease prevention, to improve connectivity and application experiences on wireless networks, and for cybersecurity purposes; and (c) to our service providers and contractors (e.g., cloud computing and storage vendors; security contractors, and consultants), for our operational business purposes.
Perfect365 does not sell personal information to individual consumers.
Perfect365 does not sell personal information about consumers younger than 18 for any purpose.
Perfect365 does not engage in profiling in furtherance of “decisions that produce legal or similarly significant effects.”
While we have sold or shared for a business purpose the above information in the last 12 months, you have the right under the CCPA and certain other privacy and data protection laws, as applicable, to opt-out of the sale of your personal information. See Section 6 (Your Choices About Your Information) and Section 12 (Additional State Privacy Rights) for more information. If you exercise your right to opt-out of the sale of your personal information, we will refrain from selling your personal information, unless you subsequently provide express authorization for the sale of your personal information. To opt-out of the sale of your personal information, visit the ‘Settings’ or ‘Me’ tab in each Application, click on ‘Privacy’, and slide the ‘Do Not Sell My Personal Information’ switch off.
Account Information
You may update or correct information you have provided to us by going into the settings screen (or “Me”) within the applicable Application. If you wish to deactivate your account, please delete the applicable Application, but note that we may retain your information as required by law and for business purposes. Refer below for additional information on your right to deletion and our deletion practices.
Promotional Communications
You may opt out of receiving promotional communications from us by following the instructions in those messages. If you opt out, please note that we may still send you Application-related communications, such as those about your account or our ongoing business relations, like notifications about updates to this Privacy Policy.
Interest-Based Advertising Services
You may opt-out from any interest-based advertising by turning on “Limit Ad Tracking” in your device settings.
To limit Ad Track on an Apple device, see instructions at: https://support.apple.com/en-us/HT202074
Apple has recently added a feature where, upon download of an Application, a popup stating “Allow Cross App Tracking” will appear that will allow the user to select their preferences for tracking and targeted advertising. The user can also go into their settings and disable or enable both tracking and location services for all applications.
To limit Ad Tracking on an Android device, see instructions at: https://support.google.com/ads/answer/2662922. Android has an option in Settings to “Opt Out of Personalized Ads.”
When you have opted out using this setting on a device, advertisers will not use in-app information collected from that device to infer your interests or serve ads to that device that are targeted based on your inferred interests. Please note, however, that opting-out will not block general advertisements that are sent at random, and not tied to the perceived interest of the user of a particular device.
Users may learn more about personalized and behavioral advertising and how to opt out of this type of advertising from the Digital Advertising Alliance at www.aboutads.info and Networking Advertising Initiative at www.networkadvertising.org/choices/.
Control or Disable the Collection of Geolocation Information
We do not collect geolocation information from you unless we obtain your explicit consent through the device’s settings (e.g., “Location Services”). You can also control the collection of certain precise location information by changing the preferences on your mobile device (certain services may lose functionality as a result).
Push Notifications
We may send push notifications to your mobile device. You can deactivate these messages at any time by changing the notification settings within the Applications or your device settings.
Third Party Use of Cookies and Other Tracking Technologies
Some content or applications related to the Applications are served by third-parties, including advertisers, ad networks and servers, content providers, service providers, and application providers. These third parties may use cookies, alone or in conjunction with web beacons or other tracking technologies, to collect information about you when you use the Applications. The information they collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.
We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly.
We will not retain your personal information for longer than is allowed under the applicable data protection laws and regulations or for longer than is justified for the purposes for which it was originally collected. We will delete the personal information when we no longer need it for the purposes for which it was collected, unless Perfect365 is required by law to keep data for a certain period of time.
YOU MUST BE SIXTEEN (16) YEARS OR OLDER IN ORDER TO USE ANY OF THE APPLICATIONS. WE DO NOT KNOWINGLY COLLECT OR SOLICIT ANY INFORMATION FROM ANYONE UNDER THE AGE OF 16 OR KNOWINGLY ALLOW SUCH PERSONS TO REGISTER FOR ANY APPLICATION. THE APPLICATIONS AND THEIR CONTENT ARE NOT DIRECTED AT CHILDREN UNDER THE AGE OF 16.
IF YOU ARE UNDER THE AGE OF SIXTEEN (16) YOU MAY NOT USE THE APPLICATIONS. IF YOU ARE BETWEEN SIXTEEN (16) AND EIGHTEEN (18) YEARS OLD, YOU MUST REVIEW THIS PRIVACY POLICY WITH YOUR PARENT OR GUARDIAN. IN THE EVENT THAT WE LEARN THAT WE HAVE COLLECTED PERSONAL INFORMATION FROM A CHILD UNDER AGE 16 WITHOUT PARENTAL CONSENT, WE WILL DELETE THAT INFORMATION AS QUICKLY AS POSSIBLE. IF YOU BELIEVE THAT WE MIGHT HAVE ANY INFORMATION FROM OR ABOUT A CHILD UNDER 16, PLEASE CONTACT US AT LEGAL@PERFECT365.COM AND WE WILL IMMEDIATELY TAKE STEPS REQUIRED TO DELETE THE INFORMATION AND OTHERWISE COMPLY WITH APPLICABLE LAW.
Perfect365 may transmit your information to its services, data centers, or service providers outside of the United States for storage and/or processing. As such, we and our service providers may transfer your personal data to, or access it in, jurisdictions that may not provide equivalent levels of data protection as your home jurisdiction. We will take steps to ensure that your personal data receives an adequate level of protection in the jurisdictions in which we process it, including through appropriate written data processing terms and/or data transfer agreements.
By registering for and using any Application, you consent to the transfer of information to any country in which Perfect365, its affiliates or service providers maintain facilities and the use and disclosure of information about you as described in this Privacy Policy.
We use commercially reasonable safeguards to help keep the information collected through the Services secure. However, Perfect365 cannot ensure the security of any information you transmit to any Services or guarantee that information on the Services may not be accessed, disclosed, altered, or destroyed. You are responsible for maintaining the secrecy of your unique passwords and account information at all times. Your privacy settings may also be affected by changes the social media services you connect to Perfect365 make to their services. We are not responsible for the functionality, privacy, or security measures of any other organization.
Perfect365 has implemented appropriate technical and organizational measures to ensure an appropriate security level for the risk involved. The risk analysis takes into account the risk of infringing against the rights of individuals concerned, the costs for implementation, as well as the type, extent, context and purposes of the data processing.
These measures include:
The Services may contain links to third party sites or online services. We are not responsible for the practices of such third parties, whose information practices are subject to their own policies and procedures, not to this Privacy Policy.
As described above, Perfect365 collects various categories of personal information when you use the Services, including identifiers, commercial information, internet or other electronic network or device activity information, geolocation data, and professional information. A detailed description of the categories of personal information we collect and how we use such personal information is provided above in Section 2 (Information We Collect) and Section 3 (How We Use Your Information). Section 4 (Information Sharing and Disclosure to Third Parties) and Section 5 ( Information Sold or Disclosed for a Business Purpose) describe the categories of third parties with whom we share personal information for a business purpose.
In the context of processing personal information of U.S. residents, certain states provide their residents with additional rights under consumer privacy laws if such laws are applicable to the data collector/processor. The following is a summary of some (but not all) of the rights you may have under various state laws.
California
If you are a California resident, you have the following rights (free of charge) under the California Consumer Privacy Act and the California Privacy Rights Act with respect to your Personal Information:
Please note that we are not required to: retain any personal information about you that was collected for a single one-time transaction if, in the ordinary course of business, that information about you is not retained; reidentify or otherwise link any data that, in the ordinary course of business, is not maintained in a manner that would be considered personal information; or provide the personal information to you more than twice in a 12-month period.
Please note that we may charge a different price or rate or provide a different level or quality of services to you, if that difference is reasonably related to the value provided to our business by your personal information.
We will work to process all verified requests within 45 days. If we need an extension for up to an additional 45 days in order to process your request, we will provide you with an explanation for the delay.
We are legally obligated to verify your identity when you submit a request. We may request additional information from you to verify your identity. If we are unable to confirm your identity, we may refuse your rights request.
You may use an authorized agent to submit a rights request. If you do so, the authorized agent must present signed written authorization to act on your behalf, and you will also be required to independently verify your own identity directly with us and confirm with us that you provided the authorized agent permission to submit the rights request. This verification process is not necessary if your authorized agent provides documentation showing that the authorized agent has power of attorney to act on your behalf.
Colorado
Colorado residents have rights under Colorado’s Consumer Privacy Act (“CPA”) regarding the collection, use, and sharing of their personal data. To the extent the CPA applies to Perfect365, Colorado residents also have the following rights, unless a CPA exception is available:
Connecticut
Under the Connecticut Data Privacy Act (“CTDPA”), Connecticut residents may have certain rights regarding the collection, use, and sharing of their personal data. To the extent the CTDPA applies to Perfect365, Connecticut residents also have the following rights, unless a CTDPA exception is available:
Illinois
The Illinois Biometric Information Policy (“BIPA”) provides Illinois residents with certain rights around the capture and retention of users’ biometric information. Pursuant to the BIPA, to the extent applicable, Perfect365 must inform you of how Perfect365 may collect and process Biometric Information (as defined under BIPA) as a result of the products and services provided to you. Perfect365 does not and will not use facial recognition or identification technology in providing you with any products or services. Perfect365 does not store any Biometric Information and therefore cannot disclose or disseminate any biometric data to any third party for any promotional purposes.
Montana
The Montana Consumer Data Privacy Act (“MCDPA”) provides its residents with certain rights regarding the collection, use, and sharing of their personal data. To the extent the MCDPA applies to Perfect365, Montana residents also have the following rights, unless a MCDPA exception is available:
Nevada
Under Nevada’s internet privacy law (SB 220), Nevada consumers may opt-out of the sale of certain information collected about them. If you wish to opt-out of any sale of covered information collected about you, you are able to make this request by emailing privacy@perfect365.com or by visiting “Settings” in the applicable Application and sliding the “Do Not Sell My Personal Information” switch off.
Oregon
Under the Oregon Consumer Privacy Act, Oregon residents are provided with certain rights regarding the collection, use, and sharing of their personal data. To the extent the Oregon Consumer Privacy Act applies to Perfect365, Oregon residents also have the following rights, unless an exception is available:
Virginia
Under the Virginia Consumer Data Protection Act (“VCDPA”), Virginia residents may have certain rights regarding the collection, use, and sharing of their personal data. To the extent the VCDPA applies to Perfect365, Virginia residents also have the following rights, unless an exception is available:
Texas
Under the Texas Data Privacy and Security Act (“TDPSA”), Texas residents are provided with certain rights regarding the collection, use, and sharing of their personal data. To the extent the TDPSA applies to Perfect365, Texas residents also have the following rights, unless an exception is available:
Utah
The Utah Consumer Privacy Act (“UCPA”) provides Utah residents with certain rights regarding the collection, use, and sharing of their personal data. To the extent the ICPA applies to Perfect365, Utah residents also have the following rights, unless an exception is available:
Virginia
Virginia residents are provided certain rights under the Virginia Consumer Data Protection Act (“VCDPA”) regarding the collection, use, and sharing of their personal data. To the extent the VCDPA applies to Perfect365, Virginia residents also have the following rights, unless an exception is available:
You can exercise the foregoing rights at any time by contacting us at privacy@perfect365.com (see additional contact details below).
For residents of the EU, Perfect365 provides you the following additional information about our data processing activities under the General Data Protection Regulation (“GDPR”). Terms used but not defined herein have the meanings ascribed to them in Art. 4 of the GDPR.
Legal Basis for Processing: In most instances, as further detailed in Sections 2 and 3, we process your Personal Data with your consent. In some instances, we may process your Personal Data to comply with our legal and regulatory obligations, for the performance of a contract with you or to take steps at your request before entering into a contract, or for legitimate purposes.
Transfers of Personal Data: Because of the international nature of our business, Personal Data collected and processed by us may be shared with, accessed by, and/or stored with our corporate office, affiliates, parents, subsidiaries and service providers, outside of the EEA and UK, including in the United States of America. Where personal data is transferred and/or stored outside of the EEA and the UK, appropriate safeguards are established to ensure an appropriate level of data protection outside the EEA as well. If we are transferring your Personal Data to another country outside of the EEA or UK, we will adhere to local requirements to implement safeguards in relation to the transer. We may implement any mechanism that is approved under data protection laws to ensure that your Personal Data is treated by those third parties in a way that is consistent with applicable laws. These measures could include ensuring that the recipient is certified under the EU-US Privacy Shield; and/or implementing GDPR standard contractual clauses with the recipient.
Rights of Data Subjects: EU residents have the following rights with respect to Perfect365’s collection and processing of their Personal Data:
Automated Decision-Making: Perfect365 does not use automated decision making in the sense of Art. 22 GDPR.
You can exercise the foregoing rights at any time by contacting us at privacy@perfect.com (see additional contact details below).
Do Not Track (DNT) is an optional browser setting that allows you to express your preferences regarding tracking by advertisers and other third-parties. We do not currently respond to DNT signals.
Perfect365 may modify or update this Privacy Policy from time to time, so please review it periodically. We may provide you additional forms of notice of modifications or updates as appropriate under the circumstances. Your continued use of Perfect365 or the Application after any modification to this Privacy Policy will constitute your acceptance of such modification.
The party responsible for the processing of personal data or information under this Privacy Policy is:
Perfect365, Inc.
Attn: Data Privacy Officer or Legal Department
101 Jefferson Drive
Menlo Park, CA 94025
If you have questions or concerns about Perfect365’s Privacy Policy or to submit a request for information or exercise any of your rights, please contact us at privacy@perfect365.com.