Extensive Personal Data Collection
Collects identification, contact, payment, browsing, location, and social network data from multiple sources.
🌐 www.sephora.it
Comprehensive data collection described, but extensive sharing with partners and third parties. Security measures mentioned but some data transfers outside EU.
Clearly references GDPR, user rights, legal bases, retention periods, and provides contact for data protection authority. Some automated decision-making with right to contest.
Provides user rights and opt-out mechanisms, but some clauses favor Sephora (e.g., data sharing with many partners, automated fraud decisions).
Detailed but very long and complex structure with marketing content mixed in. Plain language used in parts but overall overwhelming for non-lawyers.
- The document is a privacy policy and cookie notice for Sephora's Italian website and services, but it is presented in a highly fragmented and disorganized manner with excessive whitespace and formatting issues, making it difficult to read and analyze coherently.
- The policy states it applies to the website www.sephora.it, its mobile version, mobile app, in-store purchases, and communications, but the initial presentation is chaotic.
- It collects a wide range of personal data, including identification details, contact information, payment data, purchase history, browsing data, location data, and data from social networks and partners.
- The legal bases for processing include contract performance, legitimate interests, legal obligations, and consent, but the mixing of bases for single purposes (e.g., for the loyalty program, both contract performance, consent, and legitimate interest are listed) could be problematic for transparency.
- It mentions automated decision-making, including profiling for fraud prevention, which can affect a user's ability to order, and while it notes the right to human intervention, the process or criteria for such automated decisions are not clearly detailed.
- Data is shared with numerous third parties: service providers, payment processors, banks, advertising partners, social networks, credit collection agencies, and commercial partners for personalized offers, with transfers outside the EU.
- The policy states that creating an online account is reserved for individuals aged 18 or over, but it does not explicitly detail how it verifies age or handles data of minors if collected inadvertently.
- Cookie usage is extensive, including technical, security, audience measurement, advertising, and social network cookies, with some like payment security cookies being difficult to refuse without impacting order processing.
- While options to manage cookies and marketing communications are provided, the initial consent mechanism (a cookie banner) is only briefly mentioned, and the policy relies heavily on user self-service through account settings or browser controls.
- Data retention periods vary: account data is kept until deletion or 3 years of inactivity, transaction history while the loyalty account is active, connection data for 6 months, and cookies up to 24 months, but some specifics are vague.
- The document references a separate privacy policy for adverse reaction reporting (www.wearesephora.it), indicating a potential fragmentation of data handling policies across different services.
- The contact details for privacy inquiries and rights requests are provided (email, form, phone), and the right to lodge a complaint with the Italian data protection authority is mentioned.
- The policy was last updated on November 20, 2024, but the document's structure makes it challenging for users to locate and understand key information about their rights and data usage.
Collects identification, contact, payment, browsing, location, and social network data from multiple sources.
Uses automated profiling for fraud prevention, affecting user orders, with unclear criteria for human intervention.
Shares data with service providers, advertisers, social networks, and partners, including transfers outside the EU.
Uses extensive technical, advertising, and social cookies; some are difficult to refuse without impacting service.
Retention periods vary and are sometimes vague, e.g., account data until deletion or after 3 years inactive.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free