PRIVACY POLICY

www.barbieboules.com

Last Updated: October 15, 2024

NYOUTRITION, Inc. ("Company," "we," "us," or "our") operates the website www.barbieboules.com (the “Site”) and provides various services, including subscription meal plans, educational ebooks, and community membership via the Brain Space platform (collectively, the "Services"). We are committed to protecting your privacy and complying with applicable privacy laws and regulations, including U.S. federal law, Illinois state law, and the California Consumer Privacy Act (CCPA).

This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit our Site or use our Services. By accessing or using the Site, you agree to the terms of this Privacy Policy. If you do not agree with this policy, please do not use our Site or Services.

1. Introduction

At NYOUTRITION, Inc., your privacy is of paramount importance. This Privacy Policy outlines our practices regarding the collection, use, and sharing of your personal information when you interact with our Site and Services.

By using our Site or Services, you agree to the collection and use of information in accordance with this Privacy Policy. This policy applies to all visitors, users, and others who access or use the Site and Services ("Users"). Please review this policy carefully to understand how we handle your personal information.

This Privacy Policy is incorporated into our Terms and Conditions. If you have any questions regarding this policy, please contact us at connect@barbieboules.com.

2. Information We Collect

NYOUTRITION, Inc. collects various types of information from Users when they visit our Site, interact with our Services, or communicate with us. This includes both personal information that directly identifies you and non-personal information that does not directly identify you.

2.1 Personal Information

Personal information refers to data that identifies, relates to, describes, or could reasonably be linked to an individual. We collect the following categories of personal information:

  • Contact Information: Your name, email address, phone number, and mailing address.

  • Payment Information: Payment details, such as your credit card number, billing address, and other payment-related information.

  • Account Information: Username, password, and account preferences.

  • Health Information: Any health-related information you voluntarily provide as part of using our meal plans or wellness services (e.g., dietary preferences or restrictions).

  • Communications: Any information you provide when you contact us via email, customer support, or participate in community discussions.

2.2 Automatically Collected Information

We collect certain information automatically when you visit our Site or interact with our Services. This information may include:

  • IP Address: Your device’s IP address, which identifies the device you use to access the Site.

  • Device Information: Type of device, operating system, browser type, and version.

  • Usage Data: Information about your interaction with our Site, such as pages viewed, time spent on the Site, links clicked, and other activities.

  • Cookies and Tracking Technologies: Data collected through cookies, web beacons, and similar technologies (see Section 12 for more details).

2.3 Sensitive Information

We do not intentionally collect or process sensitive personal information (e.g., race, religion, sexual orientation, genetic data) unless you voluntarily provide it as part of your interaction with our Services (e.g., health-related information for meal planning).

2.4 Non-Personal Information

We may also collect non-personal information that cannot be used to directly identify you. This includes aggregated data about website traffic, user behavior, and preferences. This information is used for statistical purposes and to improve our Services.

3. How We Collect Information

We collect information from Users in various ways, including information you provide directly, information collected automatically, and information obtained from third parties.

3.1 Information You Provide

You may provide us with personal information in several ways, including:

  • When you create an account on the Site.

  • When you subscribe to our meal plans or other Services.

  • When you participate in the Brain Space community or other interactive features on the Site.

  • When you contact customer support or otherwise communicate with us.

  • When you submit feedback or respond to surveys.

3.2 Information Collected Automatically

When you interact with our Site, we automatically collect certain data using cookies, server logs, and other tracking technologies. This data includes your IP address, browser type, referring/exit pages, and other interaction details. We also collect device-specific information, such as your device type and operating system.

3.3 Information from Third Parties

We may also receive information about you from third-party platforms and services, including:

  • Third-Party Platforms: If you interact with us on third-party platforms (e.g., Zoom for virtual sessions, Circle for community discussions), we may collect information such as your profile details or engagement data from those platforms.

  • Social Media: Information collected through social media platforms when you link or engage with our content on sites like Facebook, Instagram, or others.

We may combine this information with the data we collect directly from you to better understand your preferences and improve our Services.

4. How We Use Your Information

NYOUTRITION, Inc. uses your personal information for a variety of purposes related to operating and improving our Site and Services. The specific uses include:

4.1 Provide and Manage Our Services

We use your personal information to:

  • Process your subscription and payment for meal plans, ebooks, and other Services.

  • Deliver digital content and services, such as meal plans and access to the Brain Space community.

  • Facilitate communication, including account-related information, order confirmations, and customer support.

4.2 Improve and Personalize Services

We use the information collected to:

  • Analyze and improve the functionality of our Site and Services.

  • Personalize your experience by tailoring content, product recommendations, and features based on your preferences and activity.

  • Optimize our marketing efforts and deliver targeted advertisements (with appropriate consent where required).

4.3 Marketing and Communications

With your consent, we may use your personal information to:

  • Send you promotional offers, newsletters, and updates related to our Services.

  • Notify you about new services, events, or special offers that may interest you.

  • Communicate with you via email or other channels regarding changes to our policies, terms, or other important updates.

4.4 Compliance and Legal Obligations

We may use your information to:

  • Comply with applicable laws, regulations, or legal processes.

  • Investigate or prevent illegal activities, fraud, or security breaches.

  • Enforce our Terms and Conditions and other agreements with you.

  • Protect the rights, property, and safety of NYOUTRITION, Inc., our users, or the public.

5. Sharing of Personal Information

We take your privacy seriously and do not sell your personal information. However, we may share your information with certain third parties as outlined below.

5.1 Service Providers

We share your personal information with trusted third-party service providers who assist us in operating the Site and providing Services, including:

  • Payment Processors: To process payments for subscriptions.

  • Hosting Providers: To host our Site and ensure its functionality.

  • Marketing Partners: To help us send communications, promotions, and advertisements.

These service providers are bound by strict confidentiality agreements and are only permitted to use your data as necessary to provide services on our behalf.

5.2 Legal Compliance and Protection

We may disclose your information if we believe, in good faith, that such disclosure is necessary to:

  • Comply with any applicable law, regulation, or legal request.

  • Protect our rights, property, or safety, or the rights, property, or safety of others.

  • Enforce our agreements and policies, including investigation of potential violations.

  • Respond to claims that any content posted on the Site violates the rights of third parties.

5.3 Business Transfers

In the event of a merger, acquisition, bankruptcy, or other business transaction, your information may be transferred as part of the transaction. In such cases, you will be notified of any ownership changes or new uses of your personal information, and you may exercise your rights as described in this Privacy Policy.

5.4 With Your Consent

We may share your personal information with third parties when you give us explicit consent to do so. For example, if you agree to participate in a co-branded promotion, we may share your information with our promotional partners.

6. Your Rights and Choices

We respect your privacy rights and provide you with the following choices regarding your personal information:

6.1 Access and Correction

You have the right to request access to the personal information we hold about you and to request corrections if any information is inaccurate or incomplete. You can manage certain account details directly through your account settings or contact us for assistance.

6.2 Deletion Requests

You have the right to request the deletion of your personal information, subject to certain legal and contractual obligations. To request the deletion of your information, please contact us at connect@barbieboules.com. We will respond to your request within a reasonable timeframe, and we will notify you if we cannot fulfill your request due to legal requirements.

6.3 Opt-Out of Marketing Communications

You may opt out of receiving promotional communications from us at any time by following the unsubscribe instructions in the emails we send or by contacting us directly. Even if you opt out of promotional emails, you will still receive essential communications related to your account or the services you have purchased.

6.4 Do Not Sell My Information

NYOUTRITION, Inc. does not sell your personal information. However, under CCPA, California residents have the right to opt out of the "sale" of personal information. If our practices change, we will update this Privacy Policy accordingly and provide mechanisms for California residents to exercise this right.

7. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you specific rights regarding your personal information. This section describes those rights and how to exercise them.

7.1 Right to Know

You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the purposes for collecting such information, the sources from which the information was collected, and the third parties with whom we have shared your information.

7.2 Right to Delete

California residents have the right to request that we delete any personal information we have collected from you, subject to certain exceptions. If we are unable to comply with your deletion request, we will inform you of the reasons for such denial.

7.3 Right to Opt-Out of Sale

You have the right to direct us not to sell your personal information to third parties. As stated earlier, NYOUTRITION, Inc. does not sell your personal information. Should this practice change, we will provide you with a clear mechanism to opt out of the sale of your data.

7.4 Right to Non-Discrimination

You have the right to be free from discrimination for exercising your rights under the CCPA. We will not deny you services, charge you different prices, or provide a different level of service based solely on your exercise of your privacy rights.

7.5 How to Exercise Your Rights

To exercise any of the rights described above, you may submit a verifiable consumer request by contacting us at connect@barbieboules.com. We will verify your request by confirming your identity through your account or by other reasonable means. You may also designate an authorized agent to make these requests on your behalf.

8. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by law.

8.1 Retention Period

  • We will retain your information for as long as your account is active, as necessary to provide you with Services, or as needed to comply with legal obligations, resolve disputes, and enforce agreements.

  • For marketing purposes, we retain personal information until you withdraw consent or opt out of marketing communications.

8.2 Deletion and Anonymization

Once personal information is no longer necessary for the purposes for which it was collected, we will either delete it or anonymize it. Anonymized data may be retained indefinitely for analytical purposes.

8.3 Legal Obligations

We may be required to retain certain information to comply with legal requirements, such as tax and financial regulations, even after you have deleted your account or requested deletion of your personal information.

9. Security of Your Information

NYOUTRITION, Inc. is committed to ensuring that your personal information is kept secure. We implement various technical, administrative, and physical security measures to protect your data from unauthorized access, use, disclosure, or loss.

9.1 Security Measures

We use a variety of security measures, including:

  • Encryption: All personal and payment data is encrypted during transmission using secure socket layer (SSL) technology.

  • Access Controls: We limit access to your personal information to employees and service providers who need to know it for business purposes.

  • Data Storage Security: We store your data in secure environments that are protected against unauthorized access, including firewalls and multi-factor authentication systems.

9.2 No Absolute Security

While we strive to protect your personal information, no method of transmission over the internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee its absolute security. You are responsible for maintaining the confidentiality of your account credentials and for ensuring that your login information is not shared with others.

9.3 Incident Response

In the unlikely event of a data breach, we will take immediate steps to contain the breach and assess the scope of the incident. We will notify you and relevant authorities of any data breach as required by law and will provide information about the measures taken to mitigate any harm.

10. Children’s Privacy

10.1 COPPA Compliance

Our Services are not intended for children under the age of 13, and we do not knowingly collect personal information from children under 13 in compliance with the Children’s Online Privacy Protection Act (COPPA). If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at connect@barbieboules.com, and we will take steps to delete such information from our records.

10.2 Age Restrictions

If we become aware that a child under 13 has submitted personal information without verifiable parental consent, we will immediately delete the information and take steps to prevent further use of the Site by that child.

10.3 Parental Rights

If we collect information from children under 18 (but older than 13), parents or guardians may review their child’s information, request that we delete it, and refuse to allow further collection or use of the child’s information. Parents or guardians may exercise these rights by contacting us at connect@barbieboules.com.

11. International Data Transfers

Although NYOUTRITION, Inc. is based in the United States, our Services may be accessed by users outside the U.S. If you are using our Site or Services from outside the United States, please be aware that your personal information may be transferred to, stored, and processed in the United States or other locations where we, our service providers, or partners operate.

11.1 Cross-Border Data Transfers

By using our Site or Services and providing us with your personal information, you acknowledge and agree that your information may be transferred to the U.S., which may have different data protection laws from the country in which you reside.

11.2 Data Transfer Mechanisms

For users located in the European Economic Area (EEA) or other regions with data transfer restrictions, we ensure that personal information is transferred in accordance with applicable data protection laws. This includes entering into data transfer agreements that incorporate standard contractual clauses approved by the European Commission or other safeguards to ensure adequate protection for the transfer of personal data.

11.3 Your Rights with Cross-Border Transfers

If you are located in a jurisdiction that imposes specific data protection obligations, you may have additional rights concerning cross-border data transfers. If you have any questions about how your personal information is handled internationally, please contact us at connect@barbieboules.com.

12. Cookies and Tracking Technologies

NYOUTRITION, Inc. uses cookies and similar tracking technologies to enhance your experience on our Site and to collect information about your browsing behavior.

You can manage your cookie preferences by adjusting your browser settings to refuse or delete cookies. However, please note that if you choose to block or delete cookies, some features of the Site may not function properly.

For more information about our use of cookies and how to control them, please see our Cookie Policy.

13. Do Not Track Signals

13.1 DNT Requests

Some web browsers may offer "Do Not Track" (DNT) settings that allow you to signal to websites that you do not wish to have your online activities tracked.

13.2 Our Response to DNT

At this time, our Site does not respond to Do Not Track signals sent by your browser. However, we provide you with options to opt out of cookie tracking through our Cookie Policy and third-party opt-out tools.

13.3 Alternative Opt-Out Mechanisms

While we do not currently respond to DNT signals, we do offer other tools to control your online tracking. For more information about your choices related to cookies and advertising, please review Section 12 of this Privacy Policy and refer to third-party advertising opt-out tools, such as the Network Advertising Initiative (NAI) or Digital Advertising Alliance (DAA).

14. Third-Party Links

Our Site may contain links to third-party websites, products, or services that are not owned or controlled by NYOUTRITION, Inc. Please note that we are not responsible for the privacy practices of these third-party websites.

14.1 External Websites

If you click on a third-party link, you will be directed to that third party's website. We strongly encourage you to review the privacy policy of every website you visit, as their practices may differ from ours.

14.2 No Responsibility for Third-Party Practices

NYOUTRITION, Inc. has no control over, and assumes no responsibility for, the content, privacy policies, or practices of any third-party websites or services. Links to third-party sites do not imply endorsement of their services or content.

14.3 Social Media Links

Our Site may also include social media features, such as the "Like" button on Facebook or widgets from Instagram. These features may collect your IP address, track which page you are visiting on our Site, and may set a cookie to enable the feature to function properly. Your interactions with these features are governed by the privacy policy of the respective social media platform.

15. Social Media and Plug-ins

Our Site may include social media features and plug-ins, such as the Facebook “Like” button, Instagram widgets, or other interactive mini-programs that run on our Site.

15.1 Social Media Interaction

When you interact with these features, the third-party social media companies may collect information about you, such as your IP address, which page you are visiting on our Site, and may set a cookie to enable the feature to function properly. These interactions are governed by the privacy policies of the respective social media platforms.

15.2 Information Collected via Plug-ins

We may collect data from your interactions with social media widgets and plug-ins, which may include:

  • Your interactions with the widget (e.g., clicking a "Like" button).

  • Any personal information shared on your social media profile that is public or that you provide consent for us to access.

  • Analytics about the use of the social media features on our Site.

15.3 Social Media Privacy Policies

Please review the privacy policies of the social media platforms you interact with for more information about how they handle your data. NYOUTRITION, Inc. is not responsible for the privacy practices of these third-party platforms.

15.4 Data Sharing via Social Media

If you choose to interact with our content via social media, we may collect information from your social media profiles based on your privacy settings. For example, if you tag us or use a specific hashtag, we may collect that content and display it on our Site or use it in our marketing materials.

16. Data Subject Rights (For Illinois Residents and Beyond)

In addition to the rights outlined for California residents under the CCPA (Section 7), residents of other U.S. states, including Illinois, may have additional rights related to the collection and use of their personal data.

16.1 Illinois Biometric Information Privacy Act (BIPA) 

If we collect biometric data (such as fingerprints or facial recognition data), we will do so in compliance with the Illinois Biometric Information Privacy Act (BIPA). At this time, we do not collect biometric information. If our practices change, we will notify users and update this Privacy Policy accordingly.

16.2 Other State-Specific Privacy Rights

Other states, including Virginia, Colorado, and Connecticut, have passed or are passing comprehensive privacy laws that provide users with rights similar to those provided by the CCPA. We comply with all applicable state privacy laws, and users from these states may:

  • Request Access to the personal data we have collected about them.

  • Request Deletion of their personal data.

  • Request Correction of inaccuracies in their personal data.

  • Opt-Out of Data Sharing for targeted advertising or marketing purposes.

16.3 Exercising Your Rights

If you reside in a state that provides additional privacy protections or you believe that state-specific laws apply to you, please contact us at connect@barbieboules.com to exercise your rights. We will review and respond to requests as required by law.

17. Data Breach Notification

We take the security of your personal information seriously and have implemented robust measures to protect it. However, in the event of a data breach, we will act promptly to mitigate any harm and comply with applicable data breach notification laws.

17.1 Data Breach Response

In the event of a security breach that compromises your personal information, NYOUTRITION, Inc. will:

  • Identify the Scope: Immediately work to determine the scope and severity of the breach.

  • Contain the Breach: Take steps to stop the unauthorized access and protect your data from further exposure.

  • Notify You Promptly: Notify you of the breach as soon as possible, but no later than required by applicable laws, including details about the breach and steps you can take to protect yourself.

17.2 Legal Notification Requirements

Depending on the nature of the breach and the jurisdictions involved, we will also notify any applicable regulators and comply with all legal reporting obligations.

17.3 Your Rights in the Event of a Breach

If your personal information is affected by a data breach, you may have additional rights under certain state laws (e.g., the California Consumer Privacy Act or Illinois breach notification laws). These rights may include:

  • Right to Know: Information about the breach and the categories of personal data affected.

  • Right to Remedies: Access to free credit monitoring or other remediation services, depending on the nature of the breach.

18. Changes to This Privacy Policy

NYOUTRITION, Inc. reserves the right to update or change this Privacy Policy at any time. Any changes will be effective immediately upon posting of the revised Privacy Policy on the Site, and we will provide appropriate notice of significant changes.

18.1 Notification of Changes

If we make material changes to this Privacy Policy, we will notify you by:

  • Email: Sending a notification to the email address associated with your account.

  • Site Notification: Posting a prominent notice on the Site to inform users of significant changes.

18.2 Effective Date of Changes

The effective date of any updates to this Privacy Policy will be indicated at the top of this page ("Last Updated" date). It is your responsibility to review this Privacy Policy periodically to ensure you are informed about how we are protecting your data.

18.3 Continued Use

By continuing to access or use the Site or our Services after any changes to this Privacy Policy have been posted, you agree to be bound by the updated Privacy Policy. If you do not agree with the updated terms, you must stop using the Site and Services.

19. Contact Information

If you have any questions or concerns about this Privacy Policy, your personal information, or your rights under applicable privacy laws, please contact us at:

  • Email: connect@barbieboules.com