Effective Date: December 19, 2023
This is the website ("Site") of Sally Beauty Holdings, Inc. This Privacy Policy (“Policy”) applies to the Site and describes how Sally Beauty Holdings, Inc. and its affiliates (collectively, “Sally”, “we”, “our”, “us”) gather information about you, how we use that information, and what steps we take to protect that information.
If you interact with us as a customer or employee, or in another capacity through our stores or consumer-facing websites, this Policy does not apply to such interactions. Please visit the applicable website of the business you interact with, or if you’re an employee, contact your HR business partner.
By using this Site, you consent to the terms of this Policy as well as the Site Terms of Use. Sally may change this Policy from time to time. Please check back periodically for up-to-date information about our privacy practices.
California residents: click here to read Your California Privacy Rights; the terms of which, in addition to those contained in this Policy, will govern the collection, use, disclosure and storage of personal information through this Site for those residents.
Information Collection and Use
We may collect, store, and use the following types of information and personal information:
- Information You Give Us: Name, address, email, phone number, and other data points you choose to provide, when you contact us; interactions with Sally’s social media accounts; sign up to receive emails, text messages, and/or postal mailings; and content of communications with our customer service team, offices, or investor relations via email and online chat, which is recorded.
- Automatic Information: Your use of the Site; your interaction with features on the Site; your internet protocol (IP) address; your location; your device operating system and browser type; your referring website’s address; information on your interaction with a website or application including mouse movements, clicks, user inputs, scrolling, access times, visit duration, pages viewed, and page reloading; your clickstream through the Site. Also, see our section titled Cookies below.
- Offline Technologies: We may record calls into our offices and with our customer service team and investor relations.
- Information from Other Sources: Updated address information from delivery services; online data aggregators; data analytic providers; and information from third parties to prevent fraud.
This Site is directed to adults, and Sally does not knowingly collect personal information online from children under the age of 16.
We may collect information that is not considered “personal information” (subject to the law(s) that apply to you, as a data subject), publicly available information or lawfully obtained truthful information that is a matter of public concern; de-identified or aggregated information; or information covered by other specific privacy laws. We collect, disclose and use this information in accordance with applicable law.
Information Disclosure and Purpose
We may disclose information about you with our service providers or other processors to perform services on our behalf.
- We use a variety of service providers to help us perform routine business functions. Those include, but are not limited to: printers; delivery services and couriers; software and technology providers; staff augmentation; and data processing and analytics companies.
- Companies with whom we have marketing agreements.
- Companies who help us improve the efficiency and quality of our Site, products, and services; debug, identify, and repair errors that impair the intended functionality of our Site.
For your protection we require, or these companies are otherwise obligated, to keep all personal information confidential.
We may disclose some or all of the information that we collect (described in the Information Collection and Sources) as permitted by law. For example, we may share personal information:
- With regulatory authorities and law enforcement officials.
- With our affiliates to provide shared business services.
- When we believe in good faith that the disclosure is required to prevent harm or injury, or a perceived physical threat to any individual (such as product recalls, claims, or other liability).
- Delivery service providers (e.g. USPS or UPS) to send you mail.
- For physical security, cybersecurity, incident response, and risk reduction purposes.
- To respond to a subpoena or other valid legal inquiry
- To provide you with services you requested.
- As part of a merger, acquisition, or sale of business involving Sally.
- To investigate a breach of an agreement or contravention of law; to detect, suppress or prevent fraud; and where otherwise necessary for the establishment, exercise or defense of legal claims.
- Other parties and purposes communicated to you at the time of collection.
Protection of Information
We have appropriate physical, electronic, and procedural security safeguards to protect and secure the information we collect. However, no website, mobile app or the systems they depend on are completely secure. You are also responsible for taking steps to protect your personal information against unauthorized disclosure or misuse.
- We work to protect the security of your personal information during transmission by using encryption protocols and software.
- We maintain physical, electronic, and procedural safeguards in connection with the collection, storage, and disclosure of personal information. Our security procedures mean that we may occasionally request proof of identity before we disclose personal information to you.
Cookies
Our Site uses cookies, web server logs, tags, SDKs, tracking pixels, local storage, JavaScript, APIs, and other similar technologies from time to time.
- Cookies are small data files a website can send to your browser, which may then be stored on your device, sometimes with a code unique to your device. They may be served by the entity that operates the website you are visiting (“first-party cookies”) or by other companies (“third-party cookies”). Cookies enable us and our vendors to recognize your computer; store your preferences, settings, and other data; understand the web pages you have visited on our Site and elsewhere; enhance your user experience by delivering and measuring the effectiveness of content and advertising tailored to your interests; perform searches and analytics; and assist with security and administrative functions.
- A web server log is a file where online activity is stored. It may be used for similar purposes.
- An SDK is a set of tools and/or code that we embed in our applications and software to perform certain functions, such as allowing us or third parties to collect information about how users interact with our Site.
- Tags or tracking pixels (sometimes also referred to as web beacons or clear GIFs) are small code (sometimes containing, generating, or detecting a unique identifier) embedded in websites, online ads, and email, that can be used for purposes such as generating web server logs or reading or writing cookies for the purposes described above.
- We may also use certain third-party web and mobile app analytics services – including but not limited to Google Analytics – to help us understand and analyze how visitors use the Site.
You can control or limit how we and our partners use cookies and similar technologies, including for advertising.
- While most browsers and devices accept cookies by default, the settings usually allow you to clear or decline cookies. If you disable cookies, some of the features of our Site may not function properly. For example, if you do not allow cookies at all, you might not be able to view some of our Site or use certain features. At this time, our Site only uses cookies that are commonly categorized as strictly necessary or performance.
- On this Site, we do not use the services of third parties to collect and use information about your visits to and interactions with our website through cookies to personalize advertisements.
- For Google Analytics, you can opt-out through Google Ads Settings or install Google’s opt-out browser add-on.
Opt Out
If you would like to stop receiving email alerts, please click here. Please allow sufficient time for your request to be processed. It may take up to 10 days to process your request.
Even if you opt out of receiving alerts from us, we may still contact you for transactional purposes. For example, we may contact you to fulfill a request or respond to communication you initiated.
Text Messages
We do not collect phone numbers through this Site for the purpose of sending text messages.
Geolocation
Most browsers and mobile devices allow users to enable or disable geolocation using pop-ups or controls located in the settings menu. If you have permitted Sally to access your geolocation data, you may disable the access by adjusting the permissions in your browser or device.
Maintenance of Accurate Information
We have established commercially reasonable procedures designed to ensure that your personal information is as accurate and complete as possible. If you believe that our records contain inaccurate or incomplete information about you, please login here to correct it. If you don’t have a login or are having trouble accessing your account, contact us here.
Third Party Sites
Our Site may include links to websites or applications that are owned or operated by third parties. Please note that this Privacy Policy does not cover the practices of those websites. We encourage you to review the privacy practices of those third parties.
Do Not Track
Certain states require us to indicate whether we honor your browser’s “Do Not Track” settings concerning targeted advertising. Sally adheres to the standards set out in this Policy and does not monitor or respond to Do Not Track browser requests.
California, Virginia, Colorado, Connecticut, and Utah – Your Privacy Choices
You, or an authorized agent on your behalf, have the right to make requests regarding your personal information. These rights vary depending on where you reside, requiring our response in California, Virginia, Colorado, Connecticut, and Utah only at this time, except as noted below. A description and method(s) to submit each type are detailed below.
Right to Know, Access, and Portability
- That we’re processing your personal information and access the same;
- What categories and/or specific pieces of personal information we have about you;
- The categories of sources we from which we collected it; and
- Our business purpose for collecting, selling, or sharing it, including what categories of third parties we disclose it to.
If you request specific pieces of personal information we have about you, we reserve the right to take additional steps to verify your identity before responding.
We respond to all such requests in a portable format.
To submit a Right to Know request:
Click here; or
Call 833-505-0472.
Right to Delete
Delete personal information we’ve collected about you.
If you ask us to delete your personal information, we may not be able to honor that request to the extent the information is required to comply with tax, audit, legal, or regulatory requirements.
To submit a Right to Delete request:
Click here; or
Call 833-505-0472.
Right to Opt Out of Sale/Sharing or Profiling
We do not provide a right to opt out of the “sale” or “sharing” of your information, as we don’t sell or share personal information (as those terms are defined by applicable law) collected through this Site.
VA, CO, and CT consumers: We do not provide a right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you, as we don’t engage in such actions related to information collected through this Site.
Right to Correct
Correct inaccurate personal information we maintain about you.
To submit a Right to Correct request:
Click here; or
Call 833-505-0472.
Right to Limit – CA residents only
We do not provide a Right to Limit Request, as we do not use any provided sensitive personal information of consumers collected through this Site, except as permitted by the CPRA.
Authorized Agents
If you are an authorized agent, you must provide documentation (e.g. signed permission, power of attorney) showing you are authorized by the consumer, to act on the consumer’s behalf.
- We may also require the consumer to verify their own identity directly with us and directly confirm to us that they provided the authorized agent permission to submit the request.
- #1 does not apply if a consumer has provided the authorized agent with a power of attorney, consistent with applicable state law.
If you submit your request online, such documentation can be uploaded with the request. For security and legal reasons, we will reject requests that require us to access third-party websites or services.
Verification
When you submit a request, you will receive an email asking you to confirm your email. If you do not confirm your email, we may not be able to complete your request. If you request specific pieces of personal information we have about you, or deletion or correction of your information, we reserve the right to take additional steps to verify your identity before responding. We will contact you through the method you submitted the request.
Appeals
If you live in California, Virginia, Colorado, Connecticut,or Utah and we decline to fulfill one of the requests above, we’ll provide you instructions on how to appeal in such denial. You can also call us at 833-505-0472 to appeal.
Discrimination
We will not discriminate against you for exercising any of your rights described herein.
Nevada
Nevada law allows consumers to “opt out” of the sale of certain personal information, called “covered information.” Sally does not sell covered information as defined in the law.
Contact Us
If you have questions about this Privacy Policy, or to contact us as referenced above, Sally can be reached as follows:
Sally Beauty Supply LLC
Attn.: Web Privacy
3001 Colorado Blvd.
Denton, TX 76210
1-800-777-5706