Privacy policy.

Thicket Privacy Policy

Last updated: September 23, 2024

This Privacy Policy sets out how Thicket Labs LLC doing business as Thicket (“Thicket”, “we”, “our” or “us”) uses and protects any information that you, the user, provide when you visit the websites www.jointhicket.com and www.jointhicket.agency (“Websites”), or use our Thicket mobile application (“App”) (collectively, “Service”). Except as otherwise provided herein, this Privacy Policy applies to all services offered by us through our Service. Except as otherwise provided herein, this Privacy Policy applies only to information collected through our Service and not to information collected offline.

This Privacy Policy does not cover the information practices of third parties, including other companies that may advertise on our Service. In addition, the Service may contain links to third-party websites. Please note that once you click on such a link, you will have left our Service and should be aware that we do not have any control over third-party websites. Use of third-party websites, and collection of information by those parties, are governed by their privacy policies. We encourage you to exercise caution and review their privacy policies before using their websites. Nonetheless, we seek to protect the integrity of our Service and welcome any feedback about these third-party websites.

Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, do not use our Service. By accessing or using our Service, you agree to this Privacy Policy. We may revise and update our Privacy Policy from time to time, and all updates will be posted on this page. Unless otherwise required by law, your continued use of our Service after we make changes is deemed to be acceptance of those changes, so please check the Privacy Policy periodically for updates.

Please also visit our Terms and Conditions establishing the use, disclaimers and limitations of liability governing the use of our Service here.

1. INFORMATION WE COLLECT

The categories of information we collect can include:

  • Information you provide to us directly. We may collect personal information, such as your name, phone number, mailing address, location, payment information, and e-mail address when you register for our Service, take our personalized haircare survey, order products, or otherwise communicate with us. We may also collect any communications between you and Thicket and any other information you provide to Thicket.

  • Data collected through the use of the Service. We collect information about how you use the Service and your actions on the Service.

  • Location Information.We collect your unique user identifier and your location through GPS, WiFi, or wireless network triangulation in order to obtain your location for the purposes of providing our Service. We maintain location information only so long as it is reasonable to provide the Service and then delete location data tied to your personal information. We may maintain de-identified location data for a longer period of time in order to analyze aggregate trends and metrics. If you want to opt-out of the collection of your location data, please adjust your settings in your mobile device to limit the Service's access to your location data. Please see “Control Over Your Information” below to learn more.

  • Information we receive from third parties.From time to time, we may receive information about you from third party information providers, or through mergers and acquisitions, and combine this with information previously collected. In these cases, this Privacy Policy governs the handling of the combined personal information.

We use this information to operate, maintain, and provide to you the features and functionality of the Service, as well as to communicate directly with you, such as to send you email messages and push notifications, and invite others to join the Service. We may also send you Service-related emails or messages (e.g., account verification, change or updates to features of the Service, technical and security notices). For more information about your communication preferences, see "Control Over Your Information" below.

2. HOW WE USE THE INFORMATION WE COLLECT

Your information, whether public or private, will not be sold, exchanged, transferred, or given to any other company without your consent, other than as specified in this Privacy Policy.

We will use your Personal Information for our legitimate interests, meaning our interests in conducting our business, fulfilling orders and processing transactions, and managing and providing services to you, which include the following:

  • Providing, maintaining and improving our business;

  • Fulfilling orders and processing transactions;

  • Managing and providing services to you;

  • Responding to your questions, concerns, and other requests for assistance;

  • Customizing your browsing and shopping experience on the Service. We use information about your browsing and shopping activities to bring you a custom shopping experience, by offering products and advertisements tailored to your interests (please see our Cookies section below);

  • Keeping you informed of administrative changes to our Service, including changes to our terms and conditions and other policies, and other information regarding our Service;

  • Analyzing Service statistics, such as usage and experiences impacting your browsing experience. We use this information to patch bugs and resolve other issues to present you with the best possible browsing experience. We also use cookies and other technologies to analyze how our customers interact with our Service, which helps us improve its functionality;

  • Conducting market research, which informs our marketing strategy and enables us to present you with a browsing experience tailored to your interests. For example, we create user profiles to enable personalized direct marketing communications;

  • Maintaining basic records, so that we may respond to and honor your requests to delete your data and prohibit future unwanted processing;

  • Preventing fraud, criminal activity, and misuses of our Service. We also use this information to block prohibited resellers from accessing our Service and to safeguard the security of our Service, as well as our infrastructural security;

  • Complying with legal obligations and process, and to safeguard our rights, privacy, safety, and property, as well as your rights, privacy, safety, and property, and that of our affiliates and third parties;

  • Administering special offers, including contests, promotions, surveys, and other interactive Service experiences;

  • Enabling us to publish your reviews, photos, videos and other content;

  • Communicating with you, including through email. We may use the email address which you provide for order processing to send you information and updates about your orders, as well as occasional news, updates, and information about our company and related products and services. If at any time you would like to unsubscribe from receiving future emails, please refer to the detailed unsubscribe instructions at the bottom of each email;

  • Notifying you about special offers and products or services available from us, our affiliates or our partners that may be of interest to you.

3. HOW LONG WE KEEP YOUR PERSONAL INFORMATION

We retain Personal Information for only as long as it is deemed necessary, to fulfill the purposes identified or as required by law. Please note that the retention period for Personal Information may extend beyond your relationship with us. We use the following criteria to determine retention periods:

  • Purchased products or participation in a promotional offer: Your Personal Information is retained for the duration of our contractual relationship with you;

  • Contact with us for general inquiries: Your Personal Information is retained for the duration needed to process your inquiry;

  • Creation of a Thicket account: Your Personal Information will be retained until you require us to delete it or after a reasonable period of inactivity;

  • Your subscription to our direct marketing: Where you have consented to direct marketing, we retain your Personal Information until you unsubscribe or require us to delete your information;

  • Personal Information collected through cookies: We keep cookies on your computer for as long as necessary to achieve their purposes (e.g., for the duration of a session for shopping cart cookies or session ID cookies).

Personal Information no longer necessary or relevant for its identified purposes or no longer required to be retained by law, shall be securely destroyed, erased, or made anonymous.

4. HOW WE PROTECT AND STORE YOUR INFORMATION

We are committed to making sure your privacy is protected when you use our Service and when we collect information from you. We take the security of your information seriously and implement a variety of security measures to maintain the safety of all Personal Information you provide. We also make sure that third parties we use to process your Personal Information also use appropriate security measures to protect your data.

When we collect sensitive information like your credit card information, that information is encrypted and securely transmitted. For example, we use a secure server for transmitting sensitive information. All supplied sensitive/credit card information is transmitted via Secure Socket Layer (SSL) technology and then encrypted into our payment gateway providers database only to be accessible by those authorized with special access rights to such systems and are required to keep the information confidential. You can verify that this sensitive information is being transmitted securely by looking for “https” at the beginning of the address of the webpage.

After a transaction is completed, your sensitive information will not be stored on our servers.

The safety and security of your information also depends on you. We urge you to be careful about entering information on public computers or on public networks.

Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted to or stored on our Service.

5. DO NOT TRACK (DNT) SIGNALS

We participate in interest-based advertising and use third-party advertising companies to serve you targeted advertisements based on your browsing history. For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

We may also work with third-party partners who employ tracking technologies or the application of statistical modeling tools to determine if two or more devices are linked to a single user or household so that content you see on one device can result in relevant advertising on another device, to perform analytics, and to measure the performance of our advertising campaigns.

Although we do our best to honor your privacy preferences, we are unable to respond to Do Not Track signals set by your browser.

6. COOKIES

Cookies are small files that a site or its service provider transfers to your computer’s hard drive through your web browser. Cookies enable websites or service providers’ systems to recognize your browser and capture and remember certain information. For example, you may use our cookies to stay logged in when you exit a browser window. You may read more about cookies at https://www.allaboutcookies.org/.

We use cookies and other technologies for different purposes. First, we use “Strictly Necessary Cookie” to carry out essential services of our website including, but not limited to, tracking sign-ups and processing payments. Second, we use “Analytics Cookies” to understand how users arrive to and use our site. Third, we use “Functional Cookies” to make our site more user-friendly and give visitors a better browsing experience, such as the opportunity to leave product reviews. Finally, we use “Marketing Cookies" to facilitate our direct marketing.

Some cookies (Strictly Necessary Cookies) are so essential to the functioning of our website that you cannot opt out of them. However, you can choose to accept, decline, or withdraw consent to other cookies. Be aware that disabling cookies may prevent you from using certain features or services on our Service.

Browser Opt-Out: Most browsers have a “help” button or section on the toolbar. If you click on this button or section, you will find information about turning on and off cookies and how to receive notifications when a new cookie is received.

Additionally, many advertising services allow you to opt out of targeted advertising. You may find more information in the resources available at the Network Advertising Initiative, http://www.networkadvertising.org.

Mobile devices: Note that these resources may not work to turn off cookies on mobile devices. Every mobile device is different. Here are some resources for turning off cookies for popular mobile browsers:

When you access our Service from a mobile device, we may collect unique identification numbers associated with your device or our App (including, for example, a UDID, Unique ID for Advertisers ("IDFA"), Google AdID, or Windows Advertising ID), mobile carrier, device type, model and manufacturer, mobile device operating system brand and model, phone number, and depending on your mobile device settings, your geographical location data, including GPS coordinates (e.g., latitude and/or longitude) or similar information regarding the location of your mobile device, or we may be able to approximate a device's location by analyzing other information, like an IP address.

Additionally, many advertising services allow you to opt out of targeted advertising. You may find more information in the resources available at the Network Advertising Initiative, http://www.networkadvertising.org, and may opt out of Facebook and Instagram, Google, and Bing target ads by visiting the links below:

7. CONTROL OVER YOUR INFORMATION

Profile and Data Sharing Settings: You may update your contact information, such as your name, and may change some of your data sharing preferences by emailing us at hello@jointhicket.com.

Access to your Device Information: You may control the App’s access to your device information through your “Settings” app on your device. For instance, you can withdraw permission for the App to access your address book, location, photo stream, and camera.

How to control your communications preferences: You can stop receiving promotional email communications from us by clicking on the “unsubscribe link” provided in such communications. We make every effort to promptly process all unsubscribe requests. You may not opt out of service-related communications (e.g., transactional communications, changes/updates to features of the Service, technical and security notices).

Modifying or deleting your information: If you have any questions about reviewing, modifying, or deleting your information, you can contact us directly at hello@jointhicket.com. We may not be able to modify or delete your information in all circumstances.

8. DISCLOSURE TO THIRD PARTIES

Other than as described herein, we do not sell, trade, or otherwise transfer to third parties your personally identifiable information. We may share your Personal Information with other companies and brands owned or controlled by Thicket Labs LLC (which also includes our subsidiaries (i.e., any organization we own or control) or our ultimate holding company (i.e., any organization that owns or controls us) and any subsidiaries it owns) for the purpose of operating our Service, conducting our business and servicing you, including providers of hosting, cloud services and other information technology services providers for the management or hosting of the Service; payment processors; order and subscription management and fulfillment services; e-commerce platforms; rating and reviews platforms; email communication and customer support services; and web analytics, marketing and digital advertising services, so long as those parties agree not to use the information for their direct marketing purpose, to keep this information confidential and use appropriate security measures to protect your data. We may also disclose your information as required under applicable law, to enforce the policies of our Service, or to protect our or others’ rights, property, or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses. In the event of a merger, acquisition, reorganization, bankruptcy, receivership, or sale or transfer of all or a portion of our assets, your Personal Information may be transferred to a successor or affiliate or other entity surviving out of the event.

9. SMS TEXT MESSAGING

We use Iterable, used in conjunction with Twilio, to manage text messaging. You may review Iterable’s privacy policy here, and Twilio’s privacy policy here. If you opt in to receive mobile text messages from us, you will receive messages at the phone number you provide at the time you opt in. For help, you may contact us at hello@jointhicket.com with “SMS Text Messaging” in the subject line. If you would like to stop receiving text messages, please log in to your Thicket account and visit your communication settings in your Account Settings, or reply STOP to any Thicket text message at any time. Message and data rates may apply. Data obtained through the short code program will not be shared with any third-parties for their marketing reasons/purposes.

10. CALIFORNIA CONSUMER PRIVACY ACT

Effective January 1, 2020, if you are a California resident, then you have the following rights:

  • You have the right to request that we disclose to you, not more than twice in a 12-month period, the personal information about you that we collect, use, and disclose during the 12-month period preceding your request, which shall include as follows:

  • The categories of personal information that we have collected about you

  • The categories of sources from which the personal information is collected

  • The business or commercial purpose for collecting or selling that personal information

  • The categories of third parties with whom we share that personal information

  • The specific pieces of personal information we have collected about you

  • The categories of personal information that we have disclosed about you for a business purpose.

You have the right to request the deletion of the personal information that we have collected from you.

You have the right not to be discriminated against because you exercised your rights under this section of the Privacy Policy, and we will not discriminate against you for doing so.

We do not sell and have not sold consumers’ personal information in the preceding 12 months.

For purposes of exercising your rights above, please note the following regarding how we collected and used your personal information during the 12-month period preceding the effective date of this Privacy Policy:

  • We collect the categories of personal information as recited in this Privacy Policy in the section entitled “Information We Collect.”

  • We disclose the following categories of personal information for a business purpose: Identifiers such as your first and last name, alias, postal address, IP address, and email address; payment information; commercial information; Internet or other electronic network activity information; visual or similar information.

We use the above categories of personal information for our legitimate interests, meaning our interests in conducting our business, fulfilling orders and processing transactions, and managing and providing services to you, which include the activities set forth in the above section of this privacy policy entitled “How We Use the Information We Collect.”

Effective January 1, 2020, if you wish to submit a request under the California Consumer Privacy Act, please email us at hello@jointhicket.com with the subject line “California Consumer Privacy Act Request.” You may have an authorized agent contact submit a request under the California Consumer Privacy Act on Your behalf; however, we require You (1) provide the authorized agent with signed permission to do so and (2) verify Your own identity. If the authorized agent is not an individual having power of attorney, We also require (3) You directly confirm that You provided the authorized agent permission to submit the request.

We will need to verify your identity to enable us to process your request. The verification process will include a two-step verification process, where you must enter the email address associated with your Thicket account (or, for non-account holders, the email address we have on file for you), receive an email with an authentication code, and enter the code when prompted to do so. Disclosure and deletion are subject to our receipt of a verifiable consumer request and exceptions or limitations established by applicable laws and regulations. Disclosure and/or deletion will not be completed if a consumer request cannot be verified.

11. CANADA’S PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT (PIPEDA)

If you are a Canadian resident, then you have the following rights:

  1. You have the right to request that we disclose to you, the personal information about you that we collect, use, and disclose, which shall include as follows:

    • The categories of personal information that we have collected about you

    • The categories of sources from which the personal information is collected

    • The business or commercial purpose for collecting or selling that personal information

    • The categories of third parties with whom we share that personal information

    • The specific pieces of personal information we have collected about you

    • The categories of personal information that we have sold about you and the categories of third parties to whom the personal information was sold

    • The categories of personal information that we have disclosed about you for a business purpose.

  2. You have the right to challenge the accuracy and completeness of the personal information that we have collected from you.

  3. You have the right to withdraw your consent to Our collection, use, and disclosure of your personal information.

The Service is governed by and operated in accordance with data privacy laws of the United States and Canada, and is intended for the enjoyment of residents of the United States and Canada. We make no representation that the Service is governed by or operated in accordance with the laws of any other nation. By using the Service, or providing us with any Personal Information, you (a) acknowledge that the Service is subject to data privacy laws of the United State and Canada, (b) consent to the collection, processing, maintenance, and transfer of such information to the United States and other applicable territories in which the privacy laws may not be as comprehensive as or equivalent to those in Canada, and (c) waive any claims that may arise under those laws.

If you are a Canadian resident, and provide your consent, your Personal Information will be transferred and stored outside of Canada to the United States for purposes described in this Privacy Policy. Whenever we store or transfer your Personal Information outside of Canada, we will do so in accordance with applicable U.S. law and will implement appropriate safeguards.

You have a right to access the Personal Information we have about you. Upon written request and authentication of identity, we will provide you with your Personal Information. We may charge you a reasonable fee for doing so. We will make the information available within a reasonable time, and in any event within the timelines established by PIPEDA. In some instances, we may not be able to provide access to certain personal information (e.g., if disclosure would reveal Personal Information about another individual, the personal information is protected by solicitor-client or litigation privilege). We may also be prevented by law from providing access to certain personal information. If we refuse an access request, we will notify you in writing and document the reasons for refusal.

We will make a reasonable effort to ensure that the Personal Information we use or disclose is accurate and complete. Since the Personal Information we collect is provided directly by users, we rely on you to provide accurate personal information about yourself. However, if you demonstrate that the Personal Information we have about you is inaccurate or incomplete, we will amend your Personal Information as required. If appropriate, we will send the amended information to third parties to whom the information has been disclosed.

We will use or disclose your personal information only for the purposes set out in this privacy policy and as authorized by law. We will destroy, erase, or make anonymous documents or other records containing Personal Information as soon as it is reasonable to assume that the original purpose is no longer being served by retaining the information, and retention is no longer necessary for a legal or business purpose. We will take due care when destroying personal information so as to prevent unauthorized access to the information.

If you are a Canadian and wish the exercise rights afforded to you under PIPEDA, please contact us at the following mailing and email addresses:

Email: hello@jointhicket.com, with “PIPEDA Privacy Request” in the subject line of your email. Mailing Address: 10 Grand Street Brooklyn, NY 11249

12. NEVADA ONLINE PRIVACY LAW

If you are a Nevada resident, you have the right to submit a request directing us not to make any sale of personally identifiable information we have collected or will collect about you. We do not sell your personal information. To request confirmation that we do not sell your personal information, please send an email to hello@jointhicket.com with “Nevada Privacy Information” in the subject line of your message.

13. PROTECTING CHILDRENS’ PRIVACY

We are a general audience site. Our Service, products, and services are all directed to people who are at least 13 years of age or older. We do not knowingly collect, use or disclose any information from anyone under 13 years of age. We understand and are committed to respecting the sensitive nature of children’s privacy online. If we discover that we have inadvertently collected information from anyone under 13 years of age, any information regarding that user will be promptly deleted. If you believe we might have any information from or about anyone under 13 years of age, please contact us by using the information below in the “Contact Us” section of this policy.

14. CHANGES TO OUR PRIVACY POLICY

Unless otherwise required by law, it is our policy to post any changes we make to our Privacy Policy on this page with a notice that the Privacy Policy has been updated on our Website home page. If we make material changes to how we treat the information collected from our users, we will notify you through a notice on our Website home page. The date the Privacy Policy was last revised is identified at the top of the page. We may also notify you of any material changes by sending an email to you. You are responsible for periodically visiting our Website and this Privacy Policy to check for any changes.

15. HOW TO CONTACT US

If you have any questions or concerns regarding this Privacy Policy or data processing, if you would like to change or access the Personal Information we have collected from you, or if you would like to make a complaint, you may contact us using the information below. You may also be able to refer a complaint to your local data protection regulator if you are not satisfied with the way we handled your complaint.

Email: hello@jointhicket.com Mailing Address: Thicket Labs LLC, 6311 Monterey Road, Apt 208, Los Angeles, CA 90042