Privacy Policy

Overview

Alshaya Group.com is strongly committed to respecting the privacy of all persons using our websites and mobile applications ("the Web Sites/Apps") and the protection of any personally identifiable information which we may collect on our Websites/Apps and/ or use as part of our data collection process and/ or which you may choose to share with us in our stores or via telephone, email or otherwise (“the Other Channels”). Such personal information will be collected and/ or used in accordance with the terms and conditions of this Privacy Policy, which is part of and incorporated into the Terms of Use of the Web Site.

Your Express Consent to Collection and Use of Information

Alshaya Group reserves the right to collect such personally identifiable information as, name, address, telephone number, e-mail address, etc., as well as demographic, transactional and profile data such as IP address, internet domain or browser, referrer or user agent information or other relevant information that we use as part of our data collection process on the Web Sites/Apps or via the Other Channels, such as the use of cookies or certain other information you may provide to us, etc. ("Personal Information") as set forth in this Privacy Policy. We hold all such Personal Information on secure servers and treat it as fully confidential.

BY CHOOSING TO ACCESS OUR WEB SITES/APPS AND/OR COMMUNICATING WITH US THROUGH THE OTHER CHANNELS, YOU ARE INDICATING YOUR EXPRESS CONSENT AND AGREEMENT TO THE COLLECTION, TRANSFER, PROCESSING, USE AND STORAGE IN ACCORDANCE WITH THIS PRIVACY POLICY OF ANY PERSONAL INFORMATION WHICH MAY BE OBTAINED FROM YOU AS A RESULT. If you do not agree with any of the terms and conditions set forth in the Privacy Policy, or have any questions, please contact us directly at [email protected], and we will be pleased to assist you with your concerns. By accessing or using the Web Sites/Apps and/or communicating with us through the Other Channels, you grant Alshaya Group a non-exclusive, worldwide, royalty-free perpetual license to use your Personal Information for the purposes set forth herein.

We will not sell your Personal Information to third parties. We may, however, share selected customer information with the following third parties:

• our group companies;

• our franchisors;

• companies such as payment service providers, warehousing service providers and delivery companies for the purposes of processing your payment and managing your order, including delivery and returns;

• concessions and cosmetics partners who are responsible for delivering their products directly to you or providing services, such as makeovers, in our stores;

• purchasers and their advisors following a sale of all or part of our business, so that they can continue to provide services to you;

• third party databases to which Alshaya Group and/or one of our brands subscribes;

• government bodies or other authorities if necessary to comply with regulations or law or to assist with law enforcement, or to protect our property and other rights;

• agencies who help us collate statistics about site traffic, sales, demographics and other commercial information to enable us to tailor the services we provide to you and other customers.

We will retain your Personal Information for as long as it is legally required, and to support the business purposes for which it was obtained - we will then dispose of it promptly and securely.

Depending on your country of residence, we may transfer your Personal Information both inside and outside the European Economic Area.  When we transfer your Personal Information, we ensure a similar degree of protection is afforded to it by ensuring we only transfer it to countries that are deemed to provide an adequate level of protection for personal data and under contractual terms that provide appropriate data protection.

You have the following rights which you may exercise in relation to the Personal Information we process about you:   

  • to access a copy of your Personal Information;

  • to require us to correct inaccurate Personal Information;

  • to require us to delete your Personal Information;

  • to restrict our use of your Personal Information;

  • to object to our use of your Personal Information.

Where you wish to exercise any of these rights, you must first verify your identity to our satisfaction.

Social Media Data Collection

When using the social media login on our websites and mobile apps, we capture the following details:

  1. First Name & Last Name We capture the First & Last Names to display them under the Profile Section.
  2. Profile Picture Any image used as a profile picture is not stored on our servers, Will only be used as a customer display picture.
  3. Email Address Any email address used is captured to display under the Profile Section. We also use it to send through our optional promotional campaigns and/or assisting the customer in case of any queries they might have with the websites/apps.
  4. Facebook/Google ID The social media ID is captured to only identify that the user has logged into the websites/apps using their respective login(s). If a customer wishes to delete these details that we’ve captured, they can reach out to our Customer Care team here by submitting a request or through live chat which will be processed within 24 hours.

Cookies

As part of our normal data collection process on our Web Sites, the Web Site may deposit "cookies" in your device in order to identify you and/ or as a means of tracking the validity of sessions as well as enhancing your browsing experience. Cookies are small pieces of data that a website automatically sends to your computer, tablet or mobile phone while you are viewing the website.

We use two types of cookies on our website:

• “Session” cookies, which are used to allow you to:

• carry information from one page of our website to another without having to re-enter information; and

• access stored information when you are logged in to your online account.

• “Persistent” cookies, which allow us to offer you tailored content on our website by helping us to remember:

• any personal information that you have provided on previous visits to our website;

• the number of visits that you have made to our website; and

• your preferences

Third parties are not able to identify customers using cookies.

We also reserve the right to use an outside advertising company to display ads on our Web Sites. These ads may also contain cookies. While we may use cookies in other parts of our Web sites, cookies received with banner ads or from other third-party sources may be collected by any such third-party companies, and we do not have direct access to or control over such processes. No cookies used by Alshaya Group are stored permanently on your device. All cookies are automatically removed from your device either when you close your browser or your session times out.

By using our Websites, you agree to the placing of cookies on your device. However, if you do not want to receive a cookie from our Website, you may set your browser to refuse cookies or to notify you when you receive a cookie (to find out how to do this, please consult your browser’s help section). If cookies aren’t enabled on your device, it may limit your enjoyment of the Web Site.

To enable cookies:

If you're not sure of the type and version of web browser you use to access the Internet:

For PCs: click on 'Help' at the top of your browser window and select the 'About' option

For Macs: with the browser window open, click on the Apple menu and select the 'About' option

If you'd like to learn more about cookies in general and how to manage them, visit aboutcookies.org.

If you'd like to opt out of cookies, please go to the Network Advertising Initiative website.

Please note that we're not responsible for the content of external websites.

Protection of Personal Information Against Third-Party Access or Use

We store all Personal Information on a secure server and we seek to use procedures designed to protect Personal Information from accidental or unauthorised access, destruction, use, modification or disclosure. We will seek to ensure that your Personal Information is kept confidential and secure in accordance with this Privacy Policy, and that the appropriate technical and organisational measures to prevent unlawful or accidental destruction, accidental loss, unauthorised disclosure or access or other unlawful forms of processing are implemented. Although we will strive to take commercially reasonable security precautions regarding all Personal Information, visitors or users to the Web Sites/Apps acknowledge and agree that Alshaya Group does not control the transfer of information or data via the Web Sites/Apps or over any other electronic facilities or media.

Changes to Privacy Policy

Since we are constantly making changes and upgrades to our systems and services in order to better serve you, we anticipate updating this Privacy Policy from time-to-time. Therefore, we reserve the right to revise or alter the content of this Privacy Policy in any manner and at any time, without notice. Your subsequent and/ or continued use of the Web Sites/Apps and the other Channels following a posting of changes to the Privacy Policy will constitute your acceptance of such changes.

Third Party Web Sites

You may be able to access certain third-party websites through links on our Web Sites/Apps. We are not, however, responsible for any other websites, their respective privacy policies or other content nor how they treat information about their visitors or users. We strongly advise you to check their privacy policies to find out how they are treating your Personal Information.

All credit/debit cards details and personally identifiable information will NOT be stored, sold, shared, rented or leased to any third parties.

No Warranty

YOU UNDERSTAND THAT ALSHAYA GROUP DOES NOT PROVIDE ANY WARRANTY, GUARANTEE OR REPRESENTATION OF ANY KIND CONCERNING OUR ABILITY TO CONTROL, COLLECT, CORRECT, ACCESS, PROCESS, USE, STORE, PROTECT OR TRANSFER ANY PERSONAL INFORMATION OR CONCERNING THE EXISTENCE OR EFFECTIVENESS OF ANY SECURITY MEASURES UNDERTAKEN BY US. YOU AGREE THAT ALSHAYA GROUP WILL NOT BE LIABLE FOR ANY CLAIMS, LOSSES, OR DAMAGES OF ANY KIND WHATSOEVER WHICH MAY RESULT FROM THE ACCESS, DISCLOSURE, USE OR MODIFICATION BY ANY PARTY NOT AUTHORISED OR AUTHORISED BY US, OR THE INTRODUCTION OF VIRUSES, WORMS, OR OTHER HARMFUL ELEMENTS INTO THE SYSTEM AND THEIR POSSIBLE EFFECTS ON YOUR PERSONAL INFORMATION.

Limitation of Liability

IN NO EVENT WILL ALSHAYA GROUP , ITS AFFILIATES, PARTNERS, AND THEIR RESPECTIVE EMPLOYEES, OFFICERS, DIRECTORS OR INSURERS BE LIABLE TO YOU OR TO ANY OTHER PERSON FOR ANY COSTS, DAMAGES (INCLUDING ANY SPECIAL, INCIDENTAL, EXEMPLARY, INDIRECT OR CONSEQUENTIAL DAMAGES), OR LIABILITY OF ANY NATURE, ARISING OR RESULTING FROM THE COLLECTION, USE, TRANSFER, PROCESSING OR STORAGE OF PERSONAL INFORMATION OBTAINED BY US AND RESULTING FROM YOUR ACCESS TO AND USE OF THE WEB SITES/APPS OR COLLECTED VIA THE OTHER CHANNELS.

Governing Law; Jurisdiction

This Privacy Policy will be governed by the laws of the relevant country in which your Personal Information is first registered with Alshaya Group (“the Applicable Territory”).   For the avoidance of doubt, the relevant Applicable Territory may only include those countries in which Alshaya Group operates stores or the Websites/Apps as the case may be.The exclusive jurisdiction for any claim, action or dispute with Alshaya Group under this Privacy Policy will be in the appropriate courts of the Applicable Territory.

TERMS & CONDITIONS #HMXME 

By responding to our request with the hashtag #yesHM you agree to the following:

You grant H&M, through H & M Hennes & Mauritz GBC AB [556070-1715], and Alshaya, through Alshaya Trading Co. WLL, (together hereinafter referred to as “H&M” a non-exclusive, royalty free worldwide license to use any photos and moving content in relation to which you have responded #yesHM, hereinafter referred to as “Photos and Moving Content” for its marketing and/or in its advertising, including the online store, emails, social media – H&M channels and paid social media, store materials and other customer communications. H&M may use, reproduce, distribute, combine with other materials, alter and/or edit your Photos and Moving Content in its sole discretion.

You hereby represent and warrant that (i) you own all rights in and to your Photos, (ii) you have permission from any person(s) appearing in your Photos to grant the rights herein, and (iii) H&M’s use of your Photos will not violate the rights of any third party or any law. You hereby release and discharge H&M from all and any obligation to pay you for any use of your Photos and any of the intellectual property rights contained therein in connection with the uses described above; and You hereby release, discharge and agree to hold H&M and any person acting on H&M’s behalf harmless from all claims, demands, and liabilities whatsoever in connection with use of the Photos as described above.

To read these Terms and Conditions or Privacy Notice in your own language, please visit your local HM.com site. You can find the Privacy Notice in English below and in your own language on your local HM.com site.

If you want to remove Photos or Moving Content, please visit the Photo or the Moving Content were its placed on hm.com and press "report photo" or contact customer service.

PRIVACY NOTICE - HMXME

Data privacy is very important for H&M, and we want to be open and transparent about how we process your personal data. 

We therefore have a policy that establishes how your personal data will be processed and protected.

Who is the controller of your personal data?
The Swedish company, H & M Hennes & Mauritz GBC AB (“H&M”), is the controller of the personal data you submit to us, and it is responsible for your personal data under applicable data protection law. 

H & M Hennes & Mauritz GBC AB
Mäster Samuelsgatan 46
106 38 Stockholm
Sweden

Companies Register: Bolagsverket/Swedish Companies Registration Office
Corporate Identity Number: 556070-1715
Authorised Representative: Karl-Johan Persson
VAT Registration Number: VAT NO. SE556070171501

Why do we use your personal data?

We want to share and inspire different ways of wearing H&M products. We will use your personal data to share user-generated content by uploading the pictures you submit to us on all our platforms.

What types of personal data do we process?

We will process the following categories of personal data:

  • Instagram account name

  • photo

  • video

Who has access to your personal data?
Data that is forwarded to third parties is only used to provide you with the service mentioned above; third-party media agencies and technical suppliers use the data to upload the pictures you submit to us.

We never pass on to, sell to or swap your data with third parties outside the H&M group for marketing purposes.

On what legal grounds may we process your personal data?
We need to process your personal data to fulfill the service of HMxME.

We need to collect your personal data when uploading your pictures to HMxME to fulfill our commitments according to the terms and conditions for HMxME.

If you do not submit your personal data, we will not be able to upload your pictures to HMxME.

How long do we save your data?
We will keep your personal data for 24 months or until the agreement with H&M is terminated.

Where do we store your data?
The data that we collect from you is stored within the European Economic Area (“EEA”) but may also be transferred to and processed in a country outside of the EEA. Any such transfer of your personal data will be carried out in compliance with applicable laws.

For transfers outside the EEA, H&M will use standard contractual clauses and shields as safeguards in countries without adequacy decisions from the European Commission.

Who can access your data?
Your data may be shared within the H&M group (for details on the companies within the H&M group, please refer to our annual report, which is available at about.hm.com). We never pass on to, sell to or swap your data with third parties outside the H&M group for marketing purposes.

The local H&M company will only act as the personal data processor and process the personal data on behalf of the Swedish company.

Data that is forwarded to third parties is only used to provide you with our services. You will find categories of third parties under every specific process below.

What are the legal grounds for processing?
For every specific process from personal data we collect from you, we will inform you about whether the provision of personal data is statutory or required to enter a contract, whether it is an obligation to provide the personal data and the possible consequences if you choose not to.

What are your rights?
Right to access:
You have the right to request information about the personal data we hold about you at any time. You can contact H&M, and we will provide you with your personal data via email.

Right to portability: 
Whenever H&M processes your personal data by automated means either based on your consent or based on an agreement, you have the right to get a copy of your data transferred to you or to another party. This only includes the personal data you have submitted to us.

Right to rectification: 
You have the right to request rectification of your personal data if the information is incorrect, including the right to have incomplete personal data completed.

If you have an H&M account or are an H&M member, you can edit your personal data in your account and on membership pages.

Right to erasure:
You have the right to erase any personal data processed by H&M at any time except for the following situations:

  • you have an ongoing matter with Customer Service

  • you have an open order which has not yet been shipped or partially shipped

  • you have an unsettled debt with H&M, regardless of the payment method

  • you are suspected of misusing or have misused our services within the past four years

  • your debt has been sold to a third part within the past three years or one year for deceased customers

  • your credit application has been rejected within the past three months

  • if you have made a purchase, we will keep the personal data linked to your transaction for bookkeeping purposes. 

Your right to object to processing based on legitimate interest:  
You have the right to object to processing of your personal data that is based on H&M's legitimate interest. H&M will not continue to process the personal data unless we can demonstrate either legal claims or legitimate grounds for the process which overrides your interest and rights.

Your right to object to direct marketing:
You have the right to object to direct marketing, including profiling analysis made for direct marketing purposes.

You can opt out of direct marketing by the following means:
following the instructions in each marketing email
editing the settings of your H&M account

Right to restriction:
You have the right to request that H&M restrict the processing of your personal data under the following circumstances:
if you object to processing based H&M’s legitimate interest, H&M must restrict all processing of such data pending the verification of the legitimate interest.
if you have asserted that your personal data is incorrect, H&M must restrict all processing of such data pending the verification of the accuracy of the personal data.
if the processing is unlawful, you may oppose the erasure of personal data and instead request the restriction of the use of your personal data.
if H&M no longer needs the personal data, but you require the data to defend legal claims.

How can you exercise your rights?
We take data protection very seriously; therefore, we have dedicated customer service personnel available to handle your requests in relation to your rights stated above. You can always reach them at [email protected].

Data Protection Officer:
We have appointed a Data Protection Officer to ensure that we continuously process your personal data in an open, accurate and legal manner. You can contact our Data Protection Officer at [email protected]. Write DPO in the Subject line.

Right to complain to a supervisory authority: 
If you consider H&M to be processing your personal data incorrectly, you can contact us. You also have the right to submit a complaint to a supervisory authority.

Updates to our Privacy Notice:
We may need to update our Privacy Notice. The latest version of the Privacy Notice is always available on our website. We will communicate any material changes to the Privacy Notice, for example the underlying purpose for processing your personal data, the identity of the Data Controller or your rights.

To read these Terms and Conditions or Privacy Notice in your own language, please visit your local HM.com site.

If you want to remove Photos or Moving Content, please visit the Photo or the Moving Content were its placed on hm.com and press "report photo" or contact Customer Service.

 

H&M MEMBER PRIVACY NOTICE

Last Revised: June 2022

Overview

Protecting personal data and your privacy is of greatest concern for the H&M Group. In this Privacy Notice we want to give a clear, concise, and transparent communication on the collection, use, processing, storing etc. of personal data relating to customers of the H&M Group.

1. Applicability and Scope

The H&M loyalty programme is operated by M.H. Alshaya Co. W.L.L., a company registered in Kuwait with its registered office at P.O. Box 181, Safat 13002, Kuwait (“We” or “Us” as the case may be). 
For the purposes of the Privacy Notice, the terms "We" and "Us" refer to Alshaya or to one of its affiliated companies in your territory of residence and “customer of H&M Group” means former, current and potential customer or user of a product or service offered by an H&M Group affiliate and brand, visitors to one of our official websites or stores in the United Arab Emirates, Kuwait, Saudi Arabia, Qatar, Jordan, Bahrain or Egypt, in these countries domiciled member of a loyalty program or community. 
H & M Hennes & Mauritz GBC AB ("H&M") - Mäster Samuelsgatan 46, 106 38 Stockholm, Sweden - and Alshaya International Co. L.L.C. (“Alshaya”) - Burj Alshaya Al Soor Street, Al Mirqab P.O Box 181, Safat 13002, Kuwait are separate controllers in relation to information collected on the Website, Application and In-store. Alshaya has appointed a Data Protection Office who can be contacted at [email protected]

2. Updates to this Privacy Statement

This Statement went into effect on the "Last Revised" date noted near the top of this page. This Statement may be updated from time to time. When this is the case, you will be notified of any modifications to this Statement that might materially affect your rights or the way that we use or disclose your personal data prior to the change becoming effective by means of a message e.g., on the Website. We encourage you to look for updates and changes to this Statement by checking the "Last Revised" date when you access the Website and Application. 

3. Why do we use your Personal Data?

We use your personal data, such as your Member ID, to create and manage your H&M Membership account and to give you all the granted benefits and rewards. 

The H&M Membership is as further described in the Terms & Conditions and on our official website. We process your personal data to keep your membership account up-to-date and always current. By doing so we will be able to provide you with your shopping history, details about your orders, and your status as a member.

Furthermore, we will use your personal data to serve you with personalized information, ads, promotions, recommendations, rating services etc. Any member will also receive invitations for upcoming events, competitions and customer surveys.  

(a) Personal Data You Voluntarily Provide Us

Some information we collect is provided when you use our services, such as when you create an account, join H&M Membership loyalty program; pay for products; or submit online forms.

(b) Personal Data We Collect Automatically

Some information is collected automatically by us or by service providers performing business functions at our direction, including when you access our websites, download and use our H&M Membership mobile applications, open emails we send or click certain links within them, or otherwise interact with our services.

For example:
Purchasing Information – We collect information about your transactions in our stores, on our websites or via our H&M mobile applications including what products you purchase, how frequently you purchase them, any Rewards or promotions associated with a purchase, and the products you have placed on your “Wishlist" or “My Bag" for future purchase.

Device Usage and Location Information – We collect certain information using cookies to enable our systems to recognize your browser or device and to provide our services to you. For more information about cookies and how we use them, please read our Cookies Notice.

c) Personal Data We Collect from Other Sources

Some information we collect is from unaffiliated sources, including in some cases information that is publicly available, provided by or purchased from marketing business partners, or present on social media platforms.
For example, we may collect information you submit to a blog, a chat room, or a social network like Facebook, Apple, or Google. We may also collect or license information about you from other companies and organizations, such as information aggregators or event or promotion co-sponsors, including to supplement information that we receive from you. In some cases, we receive information about you from affiliated entities, which we handle in accordance with this Privacy Statement. By gathering additional information about you, we can correct inaccurate information, enhance the security of your transactions and help prevent fraud, and give you product recommendations and special offers that are more likely to interest you.

 
4. How We Use Your Personal Data

We use your information for business and commercial purposes, including to provide the products and services you request, to perform customer service functions, for security and fraud prevention, for marketing and promotional purposes, and to perform website and mobile application analytics. 
We rely on the following legal bases to process personal information:

(a) To Conclude or Perform Our Contract with You. 

We process certain personal information when you access or use our services, for example, to:
Processing your purchases of products and services or requesting them;
Registration and verification of user accounts;
Promote our customer loyalty programs, such as H&M Membership®;
Promote the functionality of the Website and the Application, including payment-related functionality.
If you do not provide us with certain mandatory personal data when using our services, we will not be able to perform our contract with you (for example, if you do not provide us with your payment details, we will not be able to complete a purchase).

(b) For our Legitimate Business Purposes. We process certain personal information in our legitimate business interests, for example:

To Communicate With You.  We process certain information in order to communicate with you in relation to your accounts, our services, our marketing, and your requests, including to communicate with you about orders, purchases, returns, services, accounts, programs, contests, and sweepstakes, respond to your customer service inquiries and requests for information, post your comments or statements on our websites, send you personalized promotions, content, and special offers, communicate with you about our brands, products, events, or other promotional purposes, implement your communications preferences, such as sharing information with business partners so that they may email you about their promotions, products and initiatives; and provide important product safety information and notice of product recalls.

For Research, Development, and Improvement of Our Services.  We want to ensure that our website, mobile applications, and services are continually improving and expanding so that we meet and exceed your needs and expectations.  To do so, we process certain personal information, including to:

maintain, improve, and analyze our websites, mobile applications, ads, and the products and services we offer; and detect, prevent, or investigate suspicious activity or fraud.

To Enforce our Terms, Agreements, or Policies.  To maintain a safe, secure, and trusted environment for you when you use our websites, mobile applications, and other services, we use your personal information to ensure our terms, policies, and agreements with you and any third parties are enforced.

(c) To Comply with Applicable Laws.  We are required to process certain personal information under certain laws and regulations, such as tax laws, as well as to:

maintain appropriate records for internal administrative purposes as required by applicable law; and
comply with applicable legal and regulatory obligations such as to provide important product safety information and notice of product recalls), and to respond to lawful governmental requests, as needed. 

(d) With Your Consent.  If we have your consent to do so, we will process certain personal information, including to:
send you personalized promotions and special offers via email and other electronic means; and/or
to inform you about our brands, products, events, or other promotional purposes.  

You can withdraw your consent at any time by modifying your promotional preferences in your H&M  app under “My Account”, or by contacting us as described in the "Contact Us" section below. Withdrawing your consent does not affect the lawfulness of the processing prior to the withdrawal. 

5. How We Share Your Personal Data

We share your information as needed to fulfill the purposes described in this Privacy Statement and as permitted by applicable law. This includes sharing between H&M  and Alshaya among affiliated entities for internal business purposes, sharing with service providers to help perform business functions at our direction, sharing with your consent, sharing for marketing purposes, sharing as part of corporate transactions, and sharing to protect lawful interests.

We share personal information in the following circumstances:

(a) When We Work Together – We share information with subsidiaries and affiliated companies, for administering our loyalty programs, process orders and requests, and expand and promote our product and service offerings.

(b) When We Work on Business Providers – We share your personal data with the service providers found here. We contractually prohibit these service providers from storing, using or disclosing your personal data for purposes other than providing the agreed services to us.

(d) When We Work with Marketing Service Providers – We share information with marketing service providers to assess, develop and provide you with promotions and special offers that may interest you, administer contests, sweepstakes, and events or for other promotional purposes.

(e) When You Post on Our Websites – If you post information on a blog or another part of our websites, the information that you post may be seen by other visitors to our websites, including your username.

We also share personal data in a way that does not directly identify you. For example, in some cases we share information about your use of our websites and mobile applications in a manner that does not identify you or combine information about the nature or frequency of your transactions with similar information about other people and share the aggregated information for statistical analysis and other business purposes.

H&M App Mobile Applications

In certain locations, we may offer the H&M App mobile application (“Application”) for our customers’ use and enjoyment.  For more information on the H&M Membership® Application for iPhone® or Android™, please visit/ your device’s mobile app store.

Use of the Application entails information collection in accordance with the Information We Collect section above and includes ways for you (the “User”) to control Application functionality, such as location services, setting push notification and in-app message preferences. 

User Information -Through the use of an iOS, Android or other supported hardware device, some functionality of the Application requires the transmission of certain mandatory personal data provided by you to H&M App, including:

Type of Personal Data

Purpose & Activity

Legal Basis

Name and Surname

Enrollment and execution of the program

Contract of Services linked to the Terms of Use

Password

Enrollment and execution of the program

Contract of Services linked to the Terms of Use

E-mail Address

To communicate with under the scope of the ToS and for security reasons to verify your customer condition

Contract of Services linked to the Terms of Use

Phone Number

To process your purchases

Contract of Services linked to the Terms of Use

Financial Information, such as payment card numbers or account numbers

To process your purchases

Contract of Services linked to the Terms of Use

Information related to a H&M Membership stored value card (“H&M Membership Card”)

To process your purchases

Contract of Services linked to the Terms of Use

This User Information is needed to purchase H&M Membership products through the Application.  
As described further below, certain optional personal data is also processed by us shared with H&M Membership through the Application, including:

Type of Personal Data

Purpose & Activity

Legal Basis

GPS location and Bluetooth-enabled iBeacons

To monitor the effectiveness of our marketing efforts and offer the MOP feature

Consent

Advanced analytics information such as diagnostic, usage data, and user interactions

 

To understand your choices, habits and patters and deliver the right rewards to you

Consent

Phone Number

For communication purposes

Consent

Date of Birth

To reward you that day with additional benefits as a loyal customer

Consent

Billing Address

To process your purchases if you selected home delivery method

Consent

Face ID

Internal Usability

Consent

To enable our systems to recognize your browser or device and to provide the Application to you, we use cookies. For more information about cookies and how we use them, please read our Cookies Notice.

Controlling Application Functionality

Location Services - In order to use certain Application functionality, you must enable "Location Services" in the App - that is disabled by default in the Application - by going to your “Settings”.

Alternatively, you can set the permissions in your mobile device to allow communication of this information. More information about adjusting location services on iOS devices may be found here, and additional information on managing an Android device’s location settings may be found here.

Personal data collected using GPS or other location-based technologies is shared with us through the App on an optional basis.

User Responsibility

Email Communications, Push Notifications, and In-App Messages

The Application allows all users to set preferences for receiving promotional email communications from H&M Membership, receiving push notifications on your device, and receiving inbox messages.  Email communications can be adjusted by you going to “Settings” > “Communication Preferences” > “Email Newsletter”. Additionally, In-App messages can be adjusted also at “Settings” > “Push Notifications” > “Enable news updates from H&M”.
Promotional Communication Choices

You have control over your promotional communications preferences, mobile application functionality, cookie settings, and interest-based advertising preferences.  You can opt out of receiving promotional emails and mailings by informing us of your preference at the time you sign up for a H&M Membership account, by modifying your promotional preferences online in your account’s profile management section, or by following the “unsubscribe” instructions in the promotional emails we send you. Similarly, you may opt in to receive text messages, telephone calls and mailings. 

Please note that if you opt out of receiving promotional communications from us, we may still send you transactional communications, including emails about your H&M Membership accounts or purchases.

6. Your Data Protection Choices and Rights

Under certain circumstances, you have the right to:

Request Access 

to obtain from us confirmation in writing as to whether or not personal data relating to you is being processed and information to the purposes of the processing, the categories of personal data concerned and the recipients or categories of recipients to whom the personal data are disclosed.

Request Rectification

of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

Request Erasure 

of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

Request Object to processing 

where your personal data is processed for direct marketing purposes, including profiling to the extent that it is related to such direct marketing. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

Request the Restriction of processing  

that enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data's accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Personal Data Portability 

We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Exercise your Rights

If you wish to exercise any of the rights set out above, please contact, at [email protected] or post at Burj Alshaya Al Soor Street, Al Mirqab P.O Box 181, Safat 13002, Kuwait.

Lodge a Complaint 

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint if you contend that there has been a contravention of the data protection legislation or an alleged breach of your rights under the law with the correspondent supervisory authority described here. We would appreciate the opportunity to first address your concerns and would welcome you directing an inquiry first to us here.

7. How We Protect Your Personal Data

We protect your information using technical, physical, and administrative security measures to reduce the risk of loss, misuse, unauthorized access, disclosure, or modification of your information. When you transmit highly sensitive information (such as a credit card number) through our website or in one of our mobile applications, we encrypt the transmission of that information using the Secure Sockets Layer (SSL) protocol. You are responsible for protecting your password(s) and maintaining the security of your devices. 

8. Retention and Disposal of Your Personal Data

We store personal data as needed to accomplish the purposes identified in this Statement and to meet legal requirements, including record retention, resolving disputes, and enforcing our agreements. Our retention of your personal data is governed by applicable law. This storage period may extend beyond the term of your relationship with us. 

As a general rule, we keep your personal data for only as long as it is needed to complete the purpose for which it was collected or as required by law. We may need to keep your personal data for longer than our specified retention periods to honor your requests or to comply with legal, regulatory, accounting, or other obligations. When personal data is no longer needed, or in any event, after legal authority to retain it has expired, personal data will be destroyed, in accordance with local law and pursuant to procedures established in relation to the relevant system or process. 

9. Children

We do not intend for our websites or online services to be used by anyone under the age of 18 however we cannot prevent certain users, including children, from fraudulently representing their age in order to gain access to the Site or an App. If you are a parent or guardian and believe we may have collected information about your child, please contact us immediately as described in the “Contact Us" section of this Statement.  For more information, please see our Terms of Use.

10. International Transfers

Your personal data may be transferred to, stored, and processed by H&M Membership in a country other than the one in which it was collected. It may also be processed by staff operating outside the UAE who works for Alshaya in the State of Kuwait or India, H&M Membership or for our third-party service providers. In such cases, we will take appropriate steps to ensure an adequate level of data protection of the recipient as required under the correspondent data protection regulation, including by putting in place standard contractual clauses that have been approved by the Supervisory Authority. You may obtain a copy of these clauses by directly contacting us at [email protected] 

11. Contact Us

We welcome your questions, comments, and concerns about privacy. Alshaya Customer Care can be contacted here.