1. Purpose
Effective Date: June 28th, 2023
This Privacy Policy describes our data practices with regard to your Personal Information, including the kinds of information we collect, how we collect, use, disclose, and retain that information, and how you can exercise choice regarding that information. “Personal Information” means any information relating, or reasonably capable of being linked, to you.
This Privacy Policy applies to kosmu.co and all other websites, applications, products, services, and other offerings (collectively, the “Service” or “Services”) owned and operated by Kosmu, Co. and our affiliates and subsidiaries (“Kosmu,” “we,” “our,” or “us”) that link to this Privacy Policy or offline locations that makes this Privacy Policy available to you. It does not apply to information collected by third parties or information collected in the context of your employment with us.
Some regions provide additional rights by law. Please visit the relevant region-specific section at the end of this Privacy Policy or through the links below:
CALIFORNIA
COLORADO, CONNECTICUT, UTAH, AND VIRGINIA
NEVADA
If you have any questions, please contact us as set out in the “Contact Us” section below.
2. Types of Personal Information We Collect and How We Collect It
When you use the Services, you may be asked to provide Personal Information to us, such as when you register an account, make a purchase, sign-up for our newsletters, participate in a promotion, respond to our surveys, contact support, or apply for a job. The categories of Personal Information we collect include:
- Information You Provide through the Services
- Contact identifiers, including your name, email address, mailing address, and phone number.
- Characteristics or demographics, such as your age and gender.
- Commercial or transactions information, including records of products or services you purchased, obtained, or considered.
- Account credentials, including your username, password, password hints, and other information for authentication or account access.
- Payment information, including your payment instrument number (such as a credit or debit card number), expiration date, and security code as necessary to process your payments. This information is processed by our payment processors. We do not have access to your full payment instrument number.
- User-generated content, including content within any messages you send to us (such as feedback, questions, or survey responses) or publicly post on the Services (such as in product reviews or blog comments).
- Contact identifiers relating to other consumers. If you choose to use our referral service to tell a friend about Kosmu, we may collect your friend's personal information, such as their email address. We will automatically send your friend a one-time email inviting him or her to purchase a Kosmu product. We store your friend’s information in order to send this one-time email and to track the success of our referral program. Do not provide us with any information relating to other consumers unless you have their express consent.
- Professional, employment, or education-related information, including your employment and work history, transcripts, writing samples, references, and other information necessary to consider you for a job.
Please do not provide any information that we do not request.
2. Information Collected When You Visit Our Stores
We collect information about you when you visit our stores in person. For example, we deploy security cameras to capture video for security purposes. In some stores, we deploy video cameras with software that allows us to count the number of users who enter our stores and track their physical movement within our stores. The software does not engage in any facial scanning, make determinations regarding user age, ethnicity, or gender, or otherwise use information with the intent to identify a specific individual. We do not deploy the software in our stores located in Illinois.
3. Information Collected from Your Device or Browser
When you use the Services, we and third parties we work with automatically collect information from your browser or device. The categories of information we automatically collect include:
- Device identifiers, including your device’s IP address.
- Device information, including your device’s operating software and browser (e.g., type, version, and configuration), internet service provider, and regional and language settings.
- Internet activity, including information about your browsing history and interactions, such as the features you use, pages you visit, content you view, purchases you make or consider, time of day you browse, and referring and exiting pages.
- Non-precise location data, such as location derived from an IP address or data that indicates a city or postal code level.
- Heat Maps. We work with analytics service providers, such as Hotjar, to collect information through tracking technologies and generate heat maps about user behavior on the Services, including user clicks, taps, mouse movement, scrolling, and hot zones. Details on how to opt-out of Hotjar analytics is available at https://www.hotjar.com/policies/do-not-track/.
This information is automatically collected through cookies and other tracking technologies incorporated into our Service, as described below:
- Cookies. Cookies are small text files which are placed on your browser when you visit a website, open or click on an email, or interact with an advertisement. Our Service uses session cookies (which expire when you close your browser) and persistent cookies (which expire at a set expiration date or when you manually delete them). We incorporate both first party cookies (which are cookies served directly by us) and third party cookies (which are cookies served by third parties we work with). We use cookies for a variety of purposes, including to help make our website work, personalize your browsing experience, prevent fraud and assist with security, perform measurement and analytics, and provide advertising (including targeted advertising).
- Pixels. Pixels (also known as web beacons) are code embedded within a service. There are various types of pixels, including image pixels (which are one-pixel transparent images) and JavaScript pixels (which contain JavaScript code). Pixels are often associated with cookies and are used for similar purposes. When you access a service that contains a pixel, the pixel may permit us or a third party to drop or read cookies on your browser, or collect other information about your browser or device.
- App technologies. App technologies are technologies included in our apps that are not browser-based like cookies and cannot be controlled by browser settings. For example, our apps may include Software Development Kits (SDKs), which are pieces of code released by third parties that provide certain functionality. App technologies are used for purposes similar to cookies and pixels, and may permit us or a third party to collect information from your browser or device.
For details on your choices around cookies and other tracking technologies, see the “Your Privacy Choices” section below.
4. Information Collected When You Use Glow
When you use our Glow light and accompanying application, we collect information about how you use Glow, such as when you turn it on, off, or change the brightness setting; your device type; and information about the light levels in the room you’re in to provide the right light settings.
- Information Collected from Other Sources
We also collect information from other sources. The categories of sources from which we collect information include:
- Business partners that offer co-branded services, sell or distribute our products, or engage in joint marketing or promotional activities.
- Third party vendors and related parties we work with in connection with receiving analytics, advertising, security, and fraud prevention services.
- Social media platforms with which you interact. For example, when you “like,” “follow”, or otherwise engage with our content on social media (such as through our brand page or direct message), we may collect information such as your contact identifiers and any comments you provide. If you publicly reference our Service on social media (such as by using a hashtag associated with us in a tweet or post), we may use your reference on or in connection with our Service.
- Data providers, such as licensors of private and public databases.
- Public sources, including where information is in the public domain.
5. Information We Infer
We infer new personal information from other information, including to generate personal information about your likely preferences or other characteristics.
6. Sensitive Information
To the extent any of categories of information we collect are sensitive categories of personal information under applicable law, we process such information only for the limited purposes permitted by applicable law. We do not sell or use sensitive categories of personal information for purposes of targeted advertising or to make inferences.
3. How We Use Your Information
We collect and use personal information in accordance with the practices described in this Privacy Policy, including in the following ways:
- Providing services. We use information to provide services to you, including to operate the Service, establish and maintain your account, and provide support.
- Personalizing your experience. We use information to personalize your experience and show you content we believe you will find interesting.
- Communications. We use information to communicate with you about updates, security alerts, changes to policies, and other transactional messages. We also use information to personalize and deliver marketing communications to you. Communications may be by email, and, where you opt-in, text messages.
- Analytics. We use information to understand trends, usage, and activities, for example through surveys you respond to and tracking technologies that we incorporate into the Service (such as Google Analytics). We also use information for research and development purposes, including to improve our services and make business and marketing decisions.
- Advertising. We work with agencies, ad networks, technology providers, and other third parties to place ads about our products and services on other websites and services. For example, we place ads through Google and Facebook that you may view on their platforms as well as on other websites and services. As part of this process, we incorporate tracking technologies into our own Service as well as into our ads displayed on other websites and services. Some of these tracking technologies may track your activities over time and across non-affiliated services and obtain or infer information about you for purposes of showing you relevant advertising based on your preferences and interests (“targeted advertising”). We also use audience matching services (which is a type of targeted advertising) to reach people (or people similar to people) who have visited our Service or are identified in one or more of our databases (“matched ads”). This is done by us providing a list of hashed email addresses to a third party or incorporating a pixel from a third party into our own Service, and the third party matching common factors between our data and their data. For instance, we incorporate the Facebook pixel on our Service and may disclose your hashed email address to Facebook as part of our use of Facebook Custom Audiences.
- Promotions. When you voluntarily enter a promotion, we use information as set out in the official rules that govern the promotion as well as for administrative purposes and as required by law. By entering a promotion, you agree to the official rules that govern that promotion, and that, except where prohibited by applicable law, we, the sponsor, and related entities may use your name, voice and/or likeness in advertising or marketing materials.
- Security and enforcement. We use information to prevent, detect, investigate, and address fraud, breach of policies or terms, or threats or harm.
- Recruitment. We use information to make decisions about recruiting and in anticipation of a contract of employment.
- At your direction or with your consent. We use information for additional purposes where you direct us to use it in a certain way or with notice to you and your consent.
Sometimes we aggregate or de-identify information so it is no longer considered personal information. We may use non-personal information for any purpose to the extent permitted by applicable law. For details on your choices around use of your information, see the “Your Privacy Choices” section below.
4. How We Disclose Your Information
Kosmu may disclose your information in the following ways:
- Service providers. Many of the third parties we work are service providers that collect and process information on our behalf. Service providers perform services for us such as payment processing, data analytics, marketing and advertising, website hosting, and technical support. To the extent required by law, we contractually prohibit our service providers from processing information they collect on our behalf for purposes other than performing services for us, although we may permit them to use non-personal information for any purpose to the extent permitted by applicable law.
- Third party vendors and related parties. Some of the third parties we work with to perform services act as our service providers in some contexts, but in other contexts independently control the purposes and means of processing your information. For example, we disclose information to ad networks, technology providers, and other third parties that help provide targeted advertising, but may also use information for their own purposes. For these third parties, we encourage you to familiarize yourself with and consult their policies and terms of use.
- Business partners. We disclose information to our business partners in connection with offering co-branded services, selling or distributing our products, or engaging in joint marketing or promotional activities.
- Affiliates. We disclose information to our affiliates and related entities, including where they act as our service providers subject to this Privacy Policy or use the information in accordance with their own privacy policies.
- The public. We disclose information you make public, such as information in your profile or that you post on public boards. Please think carefully before making information public as you are solely responsible for any information you make public. Once you have posted information, you may not be able to edit or delete such information, subject to any rights you have under applicable law.
- Recipients in a merger or acquisition. We disclose information in connection with, or during negotiations of, any proposed or actual merger, purchase, sale or any other type of acquisition or business combination of all or any portion of our assets, or transfer of all or a portion of our business to another business.
- Recipients for security and enforcement. We disclose information to comply with the law or other legal process, and where required, in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We also disclose information to protect the rights, property, life, health, security and safety of us, the Service or anyone else.
- Recipients at your direction or with your consent. We disclose information where you direct us to or with notice to you and your consent.
Sometimes we aggregate or de-identify information so it is no longer considered personal information. We may disclose non-personal information for any purpose to the extent permitted by applicable law. For details on your choices around disclosure of your information, see the “Your Privacy Choices” section below.
5. Third Parties
We may link to or offer parts of our Service through websites and services controlled by third parties. In addition, we may integrate technologies, including those disclosed in the “How we Collect Information” section above, controlled by third parties. Except where third parties act as our service providers, they, and not us, control the purposes and means of processing any information they collect from you, and you should contact them directly to address any concerns you have about their processing. Third party data practices are subject to their own policies and disclosures, including what information they collect, your choices, and whether they store information in the U.S. or elsewhere. We encourage you to familiarize yourself with and consult their privacy policies and terms of use.
6. Your Privacy Choices
We provide a variety of ways for you to exercise choice, as described below.
- Region-Specific Rights
Some regions provide additional rights by law, as described in our region-specific terms below. This subsection details how you may exercise some of those rights to the extent they apply to you.
- Data subject requests. To access, delete, or exercise similar rights available to you in your region with respect to your information, please email us at hello@kosmu.co.
- Opt-out of sales, shares, and targeted advertising. To opt-out of sales or shares (as those terms are defined by applicable law), or the processing of information for targeted advertising purposes, click the “Your Privacy Choices” link in our website footer, or turn on a recognized opt-out preference signal, such as Global Privacy Control, in your browser or extension. Please note that when you submit an opt-out through either method we do not know who you are within our systems, and your opt-out will apply only to information collected from tracking technologies on the specific browser from which you opt-out. If you delete or reset your cookies, or use a different browser or device, you will need to reconfigure your settings. If you are logged into your account when you submit the request, where required by law, we will apply the request to your account.
2. Communications
You can opt-out of receiving certain communications from us, as described below. Your opt-out is limited to the email address, phone number, or device used and will not affect subsequent subscriptions.
- Emails. Through your account settings, by following the unsubscribe instructions near the bottom of such emails, or by emailing us at as set out in the “Contact Us” section below with the word UNSUBSCRIBE in the subject field of the email. Please note that you cannot opt out of transactional messages.
- Texts and calls. For texts, by texting “STOP” in response to any text message you receive from us or contacting us as set out in the “Contact Us” section below and specifying you want to opt-out of text messages. For calls, by requesting opt-out during any call you receive from us or contacting us as set out in the “Contact Us” section below and specifying you want to opt-out of calls.
- Push notifications. By adjusting your device settings or uninstalling our app.
3. Accounts
If you hold an account with us, you can delete your account through your account settings. We will address your request in accordance with our data retention practices.
4. Browser and Device Controls
- Cookies and pixels. You may be able to manage cookies through your browser settings. When you manage cookies, pixels associated with such cookies may also be impacted. Please note that cookie management only applies to our website. If you use multiple browsers, you will need to instruct each browser separately. If you delete or reset your cookies, you will need to reconfigure your settings. Your ability to limit cookies is subject to your browser settings and limitations.
- App technologies. For some platforms (like Apple iOS), we will only receive access to your device’s Ad ID if you provide consent. You can reset your device’s Ad ID through your device settings, which is designed to limit how the prior Ad ID can be used. You can also stop collection of information within an app by uninstalling the app.
- Preference signals. Your browser or extension may allow you to automatically transmit Do Not Track and other preference signals. Except as required by law, we do not respond to preference signals.
- Third party opt-out tools. Some third parties we work with offer their own opt-out tools related to information collected through cookies and pixels. To opt out of your information being used by Google Analytics, please visit https://tools.google.com/dlpage/gaoptout. We are not responsible for the effectiveness of any third party opt-out tools.
- Industry opt-out tools for targeted advertising. Some of the third parties we work with participate in programs that allow you to opt-out of receiving targeted advertising from participants. To opt-out of receiving targeted advertising from participants of the Digital Advertising Alliance (“DAA”) on your browser, visit https://www.aboutads.info/choices. To opt-out of receiving targeted advertising from participants of the Network Advertising Initiative (“NAI”) on your browser, visit https://www.networkadvertising.org/choices/. To opt-out of receiving targeted advertising from participants of the DAA on our apps, visit https://www.aboutads.info/appchoices. If you choose to opt-out of targeted advertising through these links, you should no longer see targeted advertising from the selected participants on the browser or device from which you opted-out, but the opt-out does not mean that the participants will not process your information for targeted advertising purposes or that you will not receive any advertising. We are not responsible for the effectiveness of any third party opt-out tools.
5. Matched Ads
To opt out of us disclosing your hashed email address to third parties for matched ads purposes, please click the “Your Privacy Choices Link” below to opt out of matched ads. We will remove your email address from any subsequent lists disclosed to third parties for matched ads purposes.
7. Data Security
We implement and maintain reasonable administrative, physical, and technical security safeguards to help protect information about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. Nevertheless, transmission via the internet is not completely secure and we cannot guarantee the security of information about you.
8. Retention
We retain information for the length of time that is reasonably necessary for the purpose for which it was collected, and as necessary to comply with our legal obligations, resolve disputes, prevent fraud, and enforce our agreements.
9. Children
The Service is not directed toward children under 13 years old, and we do not knowingly collect personal information (as that term is defined by the U.S. Children’s Privacy Protection Act, or “COPPA”) from children. If you are a parent or guardian and believe we have collected personal information from children, please contact us as set out in the “Contact Us” section below. We will delete the personal information in accordance with COPPA.
10. International Transfer
We are based in the U.S. If you are located outside the U.S., please be aware that your information may be transferred to and processed in the U.S. or another country where we operate.
11. Contact Us
Kosmu, Co.
11861 31st PL NE,
Seattle, WA 98125
To exercise choice, use the methods described in the “Your Privacy Choices” section above or your region-specific terms below.
12. Changes to our Privacy Policy
We reserve the right to revise and reissue this Privacy Policy at any time. Any changes will be effective immediately upon our posting of the revised Privacy Policy. Your continued use of our Services indicates your consent to the Privacy Policy posted. If the changes are material, we may provide you with additional notice to your email address.
CALIFORNIA
13. California
These additional rights and disclosures apply only to California residents. Terms have the meaning ascribed to them in the California Consumer Protection Act as amended by the California Privacy Rights Act (“CPRA”), unless otherwise stated.
- Notice at Collection
At or before the time of collection of your personal information, you have a right to receive notice of our data practices. Our data practices are as follows:
- For the categories of personal information we have collected in the past 12 month, see the “Types of Personal Information We Collect and How We Collect It” section above.
- For the categories of sources from which personal information is collected, see the “Types of Personal Information We Collect and How We Collect It” section above.
- For the specific business and commercial purposes for collecting and using personal information, see the “How We Use Your Information” section above.
- For the categories of third parties to whom information is disclosed, see the “How We Disclose Your Information” section above.
- For the criteria used to determine the period of time information will be retained, see the “Retention” section above.
Some of our disclosures of personal information may be considered a “sale” or “share” as those terms are defined under the CPRA. A “sale” is broadly defined under the CPRA to include a disclosure for something of value, and a “share” is broadly defined under the CPRA to include a disclosure for cross-context behavioral advertising. We collect, sell, or share the following categories of personal information for commercial purposes: contact identifiers, characteristics or demographics, commercial or transactions information, user-generated content, device identifiers, device information, internet activity, non-precise geolocation data, and inferences drawn from any of the above. The categories of third parties to whom we sell or share your personal information include, where applicable, vendors and other parties involved in cross-context behavioral advertising. We do not knowingly sell or share the personal information of minors under 16 years old who are California residents. For details on your rights regarding sales and shares, please see the “Right to Opt-Out of Sales and Shares” section below.
Some of the personal information we collect may be considered sensitive personal information under the CPRA. We collect, use, and disclose such sensitive personal information only for the permissible business purposes for sensitive personal information under the CPRA or without the purpose of inferring characteristics about consumers. We do not sell or share sensitive personal information.
- Rights to Know, Correct, and Delete
You have the following rights under the CPRA:
- The right to know what personal information we have collected about you, including the categories of personal information, the categories of sources from which personal information is collected, the business or commercial purposes for collecting, selling, or sharing personal information, the categories of third parties to whom we disclose personal information, and the specific pieces of personal information we have collected about you.
- The right to correct inaccurate personal information that we maintain about you.
- The right to delete personal information we have collected from you.
To exercise any of these rights, please follow the instructions for data subject requests in the “Your Privacy Choices” section above. Please note these rights are subject to exceptions. If you have an account with us, we may require you to use the account to submit the request. We will confirm receipt of your request within 10 business days and respond to your request within 45 days. We may require specific information from you to help us verify your identity and process your request. If we are unable to verify your identity, we may deny your request.
- Right to Opt-Out of Sales and Shares
To the extent we sell or share your personal information as those terms are defined under the CPRA, you have the right to opt-out of the sale or sharing of your personal information. To exercise this right, please follow the instructions for opting out of sales, shares, and targeted advertising in the “Your Privacy Choices” section above.
- Authorized Agent
You can designate an authorized agent to submit requests on your behalf. Requests from authorized agents must be submitted to hello@kosmu.co. Except for opt-out requests, we will require written proof of the agent’s permission to do so and may verify your identity directly.
- Right to Non-Discrimination
You have the right not to receive discriminatory treatment by us for the exercise of any your rights.
- Shine the Light
Under California’s Shine the Light law, customers who are residents of California may request (i) a list of the categories of personal information disclosed by us to third parties during the immediately preceding calendar year for those third parties’ own direct marketing purposes; and (ii) a list of the categories of third parties to whom we disclosed such information. To make a request, please write us at the email or postal address set out in the “Contact Us” section above and specify that you are making a “California Shine the Light Request.” We may require additional information from you to allow us to verify your identity and are only required to respond to requests once during any calendar year.
COLORADO, CONNECTICUT, UTAH, AND VIRGINIA
14. Colorado, Connecticut, Utah, and Virginia
These additional rights and disclosures apply only to residents of Colorado, Connecticut, Utah, and Virginia. Terms have the meaning ascribed to them in the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), the Utah Consumer Privacy Act (“UCPA”), and the Virginia Consumer Data Protection Act (“VCDPA”), as applicable.
- Data Subject Requests
You may have the following rights under applicable law:
- To confirm whether or not we are processing your personal data
- To access your personal data
- To correct inaccuracies in your personal data
- To delete your personal data
- To obtain a copy of your personal data that you previously provided to us in a portable and readily usable format
To exercise any of these rights, please follow the instructions for data subject requests in the “Your Privacy Choices” section above. Please note these rights are subject to exceptions. We will respond to your request within 45 days. If you have an account with us, we may require you to use the account to submit the request. We may require specific information from you to help us confirm your identity and process your request. If we are unable to verify your identity, we may deny your request. We do not process personal data for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects concerning consumers.
- Right to Opt-Out of Sales and Targeted Advertising
You also may have the right to opt-out of the processing of personal data for purposes of targeted advertising or the sale of personal data. To exercise this right, please follow the instructions for opting out of sales, shares, and targeted advertising in the “Your Privacy Choices” section above.
- Authorized Agent
You can designate an authorized agent to submit requests on your behalf. Requests from authorized agents must be submitted to hello@kosmu.co. Except for opt-out requests, we will require written proof of the agent’s permission to do so and may verify your identity directly.
- Appeals
If we refuse to take action on a request, you may appeal our decision within a reasonable period time by contacting us at hello@kosmu.co and specifying you wish to appeal. Within 60 days of our receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied, you may submit a complaint as follows:
- For Colorado residents, to the Colorado AG at https://coag.gov/file-complaint/
- For Connecticut residents, to the Connecticut AG at https://www.dir.ct.gov/ag/complaint/
- For Virginia residents, to the AG at https://www.oag.state.va.us/consumercomplaintform
NEVADA
15. Nevada
If you are a Nevada consumer, you have the right to direct us not to sell certain information that we have collected or will collect about you. To exercise this right, please follow the instructions for opting out of sales, shares, and targeted advertising in the “Your Privacy Choices” section above.
16. EU Data Transfers
To the extent we receive personal data transferred from the European Union (EU), the United Kingdom (UK), and Switzerland, we will provide appropriate safeguards, such as through the use of Standard Contractual Clauses.
In addition, Kosmu participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework. Kosmu is committed to subjecting all personal data previously received from the EU, the UK, and Switzerland, respectively, in reliance on the Privacy Shield Frameworks, to the Framework’s applicable Principles. In light of the judgment of the Court of Justice of the European Union invalidating Privacy Shield, Kosmu will continue to process personal data transferred in reliance on Privacy Shield using appropriate safeguards in accordance with the Privacy Shield Principles. To learn more about the Privacy Shield Frameworks, and to view our certification, visit the U.S. Department of Commerce’s Privacy Shield List.
Under the Privacy Shield Framework, Kosmu is responsible for the processing of personal data subject to Privacy Shield that it receives and subsequently transfers to a third party acting as an agent on its behalf. Kosmu complies with the Privacy Shield Principles for all onward transfers of personal data from the EU, the UK, and Switzerland based on Privacy Shield, including the onward transfer liability provisions. With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, Kosmu is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Kosmu may be required to disclose personal data subject to Privacy Shield in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
If you have an unresolved privacy or data use concerns relating to Privacy Shield that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://www.jamsadr.com/eu-us-privacy-shield.
Under certain conditions, more fully described on the Privacy Shield website, you may invoke binding arbitration when other dispute resolution procedures have been exhausted.