PRIVACY POLICY

INTRODUCTION AND OVERVIEW

This Privacy Policy explains what information Vrai & Oro, LLC ("VRAI", "we", "our" or "us") collects, why we collect this information, and how we use the information we collect as well as your rights and choices regarding such information. Our Privacy Policy applies to our collection of your information in our stores, on our website, our collection of your information via any channel that you may interact with us, including but not limited to, postal mail, email, phone, live chat, SMS/MMS/text, social media platforms and your use of any online service location that posts a link to this Privacy Policy and all features, content, and other services that we own, control, or make available via any channel (collectively, the "Service").  

  

VRAI encourages you to periodically review this Privacy Policy to learn about our privacy practices.

SPECIFIC PROVISIONS FOR RESIDENTS OF CALIFORNIA

If you are a California resident, California law may provide you with additional rights regarding our use of your personal data - please see the "Additional Disclosures for California Residents". 

SPECIFIC PROVISIONS FOR RESIDENTS OF NEVADA

If you are a resident of Nevada, the law of Nevada may provide you with additional rights regarding our use of your personal data - please see the "Additional Disclosures for Nevada Residents".

PROVISIONS FOR RESIDENTS OF THE EU

If you are a resident of the European Union, the General Data Protection Regulation (“GDPR”) applies to the processing of your personal data - please see the "Additional Disclosures for Residents of the EU".

If you have questions or concerns about our privacy policy, please contact VRAI as set forth in the section entitled "Contact Us" below.

INFORMATION WE COLLECT

INFORMATION YOU PROVIDE

We collect information you provide directly via the Service, including but not limited to when you register an account, update your profile, access our content, make a purchase, participate in a sweepstakes, contest, survey, or other promotion ("Promotion"), contact customer support, or apply for a job. We may use Service Providers (defined below) to collect this information.

  

The information we collect includes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to you. The following is a list of the categories of information we collect and have collected in the last 12 months:  

  

Contact Data 

We collect your first and last name, e-mail address, postal address, phone number, and other similar contact data.  

  

Credentials 

We collect passwords and other information for authentication and account access.  

  

Demographic Data 

We collect demographic information including your age, gender, and country.  

  

Payment Data 

We collect data necessary to process your payment if you make a purchase, including your credit card number, and the security code and expiration date associated with your payment instrument. We do not store payment information after purchase.  

  

Profile Data 

We collect your interests, favorites, wish lists, ring size preferences, and other profile data.  

   

Contacts 

We collect data about your contacts in order to fulfill a request by you. For example, when you e-mail a product to a friend or refer a friend through the Service, we request that you provide names and e-mail addresses for you and your friend. This helps ensure that your friend will know that you have requested that VRAI send them an e-mail. The information VRAI collects from you and your friend will only be used in ways as set forth in this Privacy Policy. By using this functionality, you acknowledge and agree that you have your contacts' consent for us to use their contact information to fulfill your request.  

  

Content 

We collect the content of messages you send to us, such as feedback and product reviews you write, questions and information you provide to customer support or comments and content that you may post on social media channels. For example, if you contact a customer service representative or jewelry consultant and provide information to the consultant or submit a request through our Service, we will use your information to respond to your request and to provide you with additional information that we believe may be helpful to you. We may also collect content such as photos, videos or other content that you submit to us.

  

Employment Data 

We collect data as necessary to consider you for a job opening if you submit an application to us, including your employment history, resume, transcript, responses to questions listed on our job applications or other forms related to your application for employment, writing samples and references.  

  

Government Identification Data 

You may provide to us other personal identifying information such as an image of your driver's license or other government issued identification for fraud prevention purposes. You may also provide government issued identification numbers such as your social security number for tax reporting purposes in the event that you win a sweepstakes prize.  

  

You may choose to voluntarily submit other information to us through the Service that we do not request, and, in such instances, you are solely responsible for such information.

COOKIES

VRAI collects data through the use of cookies, web logs, web beacons, pixels and other tracking technologies (now and hereafter developed) ("Tracking Technologies").  The cookies we use fall into three categories:  

  

Required Cookies 

These cookies are required to enable core platform functionality and are therefore always enabled. This includes remembering your selected country and language, tracking your movement on and usage of our services for statistical purposes, storing whether you are logged in or not and storing your shopping bag and wish list items. We won’t ask for your consent to place those cookies because we have a legitimate purpose for setting them, but you can find a list of the cookies in our third party cookie list (linked below).  

  

Analytic Cookies

These cookies are optional and allow us to track and analyze your experience on the Services, to optimize your shopping experience, to invite you to provide feedback, and to allow you to interact with product reviews.  

  

Social media and Advertising Cookies 

These cookies are used by advertising companies to serve ads that are relevant to your interests and to personalize marketing both within and beyond our Services including social media. Those partners (e.g. Facebook and Google) may combine that information with other information they have collected from you. These partners collect data directly from your web browser and the processing is subject to their own privacy policies.  

INFORMATION FROM OTHER SOURCES

VRAI obtains information about you from other sources. To the extent we combine the information you provide to VRAI through the Service with information we have obtained from other sources, we will treat the combined information in accordance with the practices described in this Privacy Policy, plus any additional restrictions imposed by the source of the data. The following are the categories of other sources we collect information from:  

  

Data brokers 

Data brokers from which we purchase demographic data to supplement the data we collect. We collect your first and last name, e-mail address, postal address, phone number, and other similar contact data.  

  

Social networks 

Social networks when you reference our Service or grant permission to VRAI to access your data on one or more of these services.  

  

Financing providers 

Financing providers with which we offer financing for purchases, and financial services providers used for processing payments.  

  

Partners, including advertising and marketing partners 

Partners with which we offer co-branded services, sell or distribute our products, or engage in joint marketing activities.  

  

Publicly-available sources 

Publicly-available sources such as open government databases or other data in the public domain.  

USE OF INFORMATION

We collect and use information about you for the business and commercial purposes described in this Privacy Policy. Our business purposes for collecting and using information, include to:  

  

  • Manage our Service, including your registration, account, and transactions.  
  • Perform services requested by you, such as to process and fulfill your order, to respond to your comments, questions, and requests, and provide customer service.  
  • Send appointment reminders and otherwise assist in confirming or scheduling interactions with us.  
  • Send you technical notices, updates, security alerts, information regarding changes to our policies, and support and administrative messages.  
  • Prevent or take action regarding illegal activities, including suspected fraud.  
  • Monitor and analyze trends, usage, and activities.  
  • Conduct surveys and/or research on our users' demographics, interests, behavior.  
  • Improve our marketing and promotional efforts, Service content and product and service offerings.  
  • Develop and send you direct marketing, including advertisements and communications about our and other party products, offers, promotions, rewards, events, and services.  
  • Verify your eligibility and deliver prizes in connection with Promotions you have entered.  
  • Provide and serve advertising on our Service and unaffiliated websites and services.  
  • Comply with any applicable law, regulation, legal process or governmental request.  
  • Fulfill any other business or commercial purposes disclosed to you at your direction or with your consent.

SHARING OF INFORMATION

We share your information in accordance with the practices described in this Privacy Policy. The types of entities to whom we disclose and have disclosed information within the last 12 months include the following:  

  

Service Providers 

We share your information with agents, contractors, and other service providers in connection with their work on our behalf (collectively "Service Providers"). Our Service Providers only receive your information if such information is needed to perform their function(s), and they are not authorized to use such information for any other purpose(s) other than the purpose(s) set forth by VRAI. We only provide Service Providers with the information necessary to complete the requested service, product or transaction and contractually prohibit them from retaining, using, or disclosing information about you for any purpose other than performing the services for us.  

  

Affiliates 

We share your information with our related entities including our parent and sister companies. For example, we share your information with our affiliates for business purposes such as customer support, marketing, and technical operations.  

  

Business partners 

We share your information with our business partners in connection with offering you co-branded services, selling or distributing our products, or engaging in joint marketing activities. For example, we share information about you with a business partner for purposes of providing you with co-branded products or services that we may offer.  

  

Special events 

If you choose to participate in a special event (for example, a Promotion), VRAI will share your information with those organizations participating in the applicable event. Typically, these other parties do not use your information for any other purpose other than to manage the event. In some cases, these promotional partners will send you promotional materials regarding their products and services.  

  

Feedback, Testimonials and User Provided Content 

If you provide feedback or testimonials on the Service or on VRAI products or services, or provide other user provided content (such as photos or videos), we will post and share this feedback, testimonial or other user provided content, including your information, on the Service, with partners, or in marketing and promotional materials.   

  

Facilitating Requests 

We will share your information with other parties for purposes of facilitating your requests (such as when you choose to share information with a social network about your activities on the Service).  

  

Vendors and Other Parties 

We share information with vendors and other parties for business and commercial purposes. For example, if we need to ship something to you, we must share your name and address with a shipping company. Vendors also include: web hosting companies, shipping and fulfillment companies (e.g., companies that ship or fulfill product orders), diamond or gemstone suppliers, jewelers, assemblers, insurance companies, data analysis firms, analytics and advertising technology companies, affiliates, customer service providers, consulting or marketing firms/providers, accounting, bookkeeping or legal firms, financial services firms, technology companies including, but not limited to, enterprise application firms, firms which provide technologies to enable electronic communications and data storage providers. Additionally, if you use a credit card or other financing alternative to place an order with VRAI, we will use a payment processor to process your information in association with the transaction. We will also share information with other companies and organizations for credit fraud protection and risk reduction. Vendors and other parties may act as our service providers, or in certain contexts, independently decide how to process your information. Information will be disclosed to vendors and other parties in connection with tailoring advertisements, measuring and improving our Service and advertising effectiveness, and enabling other enhancements.  

  

Business Transfer 

Your information will be disclosed as part of, or in connection with, any investment in the company, any merger, sale of company assets, or acquisition, as well as in the event of an insolvency, bankruptcy or receivership, in which information would be transferred as one of the business assets of VRAI.  

  

Security, Compliance with Law, and Fraud Protection 

We will disclose your information as we deem necessary, in our sole discretion, to comply with any applicable law, regulation, legal process or governmental request. We will also share your information in order to investigate, prevent or take action regarding illegal activities, including suspected fraud, or as otherwise required by law. We will also share your information to protect the rights, property, life, health, security and safety of us, the Service or any person or party.

CHILDREN

VRAI does not knowingly collect personal information from children under the age of thirteen (13) – in the EU sixteen (16). In the event that VRAI ever does so, we will strictly comply with the Children's Online Privacy Protection Act ("COPPA") or other legislation. If you are a parent or guardian and believe VRAI has collected such information in a manner not permitted by COPPA or other relevant legislation, please contact us as set forth in the section entitled "Contact Us" below, and we will remove such data to the extent required by COPPA or other relevant legislation. In addition, we do not sell the personal information of minors under 16 years old who are California residents.

    OTHER PARTIES

    OTHER PARTY WEBSITE AND SERVICES

    Our Service provides links to websites, locations, platforms, and services operated and owned by other parties which are outside our control and not covered by this Privacy Policy. We encourage you to review the privacy policies posted on these (and all) websites and services. There may be Tracking Technologies on unaffiliated websites and services used to independently collect information about you and may solicit information from you. The information collected and stored by other parties, whether through our Service, or their services or Social Features (defined below), remains subject to their own policies and practices, including what information they share with us, your rights and choices on their services and devices, and whether they store information in the U.S. or elsewhere. We encourage you to familiarize yourself with and consult their privacy policies and terms of use.

      YOUR RIGHTS AND CHOICES

      REVIEW AND UPDATES OF ACCOUNT INFORMATION

      You may access, update, or remove certain account information that you have voluntarily submitted to us through the Service. If you would like to update or revise information in your account, you may do so through your account or by contacting us as set forth in the section entitled "Contact Us" below. We may require additional information from you to allow us to confirm your identity. Please note that we will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. California residents and data subjects in EU have additional rights as set forth in the sections entitled "Additional Disclosures for California Residents" and "Additional Disclosures for Data Subjects in Europe" below.

        COMMUNICATIONS

        To opt-out of receiving e-mail promotions from VRAI, please follow the unsubscribe instructions in our promotional e-mail correspondence or contact us as set forth in the section entitled "Contact Us" below. Please note that opting out of promotional communication received from VRAI does not affect our non-promotional communications with you, service messages, orders placed with VRAI, or our ongoing business relations.

          DATA SECURITY

          We implement and maintain reasonable administrative, physical, and technical security safeguards to help protect your information from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction.  

            

          Despite the measures we take, transmission via the Internet is not completely secure and we cannot guarantee the security of your information.

          INTERNAL TRANSFER

          VRAI is based in the U.S. and the information we collect is governed by U.S. law. Your information will be stored and processed in the United States or any other country in which VRAI or its partners, affiliates, service providers, subsidiaries or agents maintain facilities and by using this Website, you consent to any such transfer of information outside of your country – however not applicable to EU residents. Data protection laws in the U.S. and other jurisdictions may be different from those of your country of residence. Your use of the Service or provision of any information therefore constitutes your consent to the transfer to and from, processing, usage, sharing, and storage of your information in the U.S. and other jurisdictions as set forth in this Privacy Policy. If you are an EU resident and your data is collected in Europe, we will transfer your personal data subject to the section "Additional Disclosures for Residents of the EU". 

            CHANGES TO THE PRIVACY POLICY

            This is our entire and exclusive Privacy Policy and it supersedes any earlier version. We may occasionally update this Privacy Policy to reflect changes in our practices and services, and we reserve the right to do so at any time. When a revision is made, we will revise the "Effective Date" on this page and any changes will be effective immediately upon posting of the revised Privacy Policy. VRAI encourages you to periodically review this Privacy Policy to learn how we are protecting your information. Your continued use of our Service indicates your consent to the Privacy Policy then posted – however not applicable to EU residents. If any changes are material, we may provide you additional notice to your e-mail address.

            CONTACT US

            If you have questions about this privacy policy, or the information practices, please contact us as follows:  

              

            By email: hello@vrai.com  

              

            By mail:  VRAI LLC, 322 East Grand Avenue, Ste 500, South San Francisco, CA 94080, USA  

              

            If you have a disability and would like to access this Privacy Policy in an alternative format, please email us at hello@vrai.com.

            ADDITIONAL DISCLOSURES FOR CALIFORNIA RESIDENTS

            These additional disclosures for California residents apply only to individuals who reside in California. The California Consumer Privacy Act of 2018 ("CCPA") provides additional rights to know, delete and opt out, and requires businesses collecting or disclosing personal information to provide notices and means to exercise rights.

            CALIFORNIA NOTICE OF COLLECTION

            In the past 12 months, we have collected the following categories of personal information enumerated in the CCPA:  

              

            • Identifiers, such as name, email address, phone number account name, IP address, and an ID or number assigned to your account.  
            • Customer records, such as billing and shipping address.  
            • Demographics, such as your age or gender. This category includes data that may qualify as protected classifications under other California or federal laws.  
            • Commercial information, such as products or services history and purchases.  
            • Internet activity, such as your interactions with our Service.  
            • Audio or visual data, such as photos or videos you share with us or post on the Service.  
            • Geolocation data.  
            • Employment and education data, such as data you provide when you apply for a job with us.  
            • Inferences, such as information about your interests, ring size preferences and favorites.  

              

            For more information on information we collect, including the sources we receive information from, review the "Information We Collect" section. We collect and use these categories of personal information for the business purposes described in the "Use of Information" section, including to provide and manage our Service.  

              

            We use and partner with different types of entities to assist with our daily operations and manage our Service. Please review the "Sharing of Information" section for more detail about the parties we have shared information with.  

              

            VRAI does not sell your personal information.

            RIGHT TO KNOW AND DELETE

            If you are a California resident, you have the rights to delete the personal information we have collected from you and know certain information about our data practices in the preceding 12 months. In particular, you have the right to request the following from us:  

              

            • The categories of personal information we have collected about you;  
            • The categories of sources from which the personal information was collected;  
            • The categories of personal information about you we disclosed for a business purpose or sold;  
            • The categories of third parties to whom the personal information was disclosed for a business purpose or sold;  
            • The business or commercial purpose for collecting or selling the personal information; and,  
            • The specific pieces of personal information we have collected about you.  

              

            To exercise any of these rights, please email a customer service representative at hello@vrai.com. In the request, please specify which right you are seeking to exercise and the scope of the request. We will confirm receipt of your request within 10 days. We may require specific information from you to help us verify your identity and process your request. If we are unable to verify your identity, we may deny your requests to know or delete.

            AUTHORIZED AGENT

            You can designate an authorized agent to submit requests on your behalf. However, we will require written proof of the agent's permission to do so and verify your identity directly.

            RIGHT TO NON-DISCRIMINATION

            You have the right not to receive discriminatory treatment by us for the exercise of any of your rights.

            SHINE THE LIGHT

            If you are a customer in California, in addition to the rights set forth above, you have the right to request information from VRAI regarding the manner in which VRAI shares certain categories of personal information as defined by California's "Shine the Light" with third parties and/or affiliates for their own direct marketing purposes. To receive this information, send us a request at the address set forth in the section entitled "Contact Us" above. Requests must include "California Privacy Rights Request" in the first line of the description and include your name, street address, city, state, and ZIP code. Please note that VRAI may provide this information in a standardized format that is not specific to you and is not required to respond to requests made by means other than through the provided e-mail address or mail address.

            POSTINGS

            Any California residents under the age of eighteen (18) who have registered to use the Service and posted content or information on the Service, can request that such information be removed from the Service by sending an e-mail to the e-mail address set forth in the section entitled "Contact Us" below. Requests must state that the user personally posted such content or information and detail where the content or information is posted. We will make reasonable good faith efforts to remove the post from prospective public view.

            ADDITIONAL DISCLOSURES FOR NEVADA RESIDENTS

            Nevada law (NRS 603A.340) requires each business to establish a designated request address where Nevada consumers may submit requests directing the business not to sell certain kinds of personal information that the business has collected or will collect about the consumer. If you are a Nevada consumer and wish to submit a request relating to our compliance with Nevada law, please contact us at hello@vrai.com.  

              

            VRAI does not sell your personal information.

            ADDITIONAL DISCLOSURES FOR RESIDENTS OF THE EU

            DATA CONTROLLER

            VRAI, located at the address in the section entitled "Contact Us" above, is the controller with respect to information you provide through the Service.

            LAWFUL BASIS

            We use personal data collected through our Services only when we have a valid reason and the legal grounds to do so. We determine the legal grounds based on the purposes for which we have collected your personal data.  

              

            The legal ground may be one of the following:  

              

            Consent, GDPR art. 6 (1) (a): For example, where you have provided your consent to receive marketing emails from us. You can withdraw your consent at any time. In the case of marketing e-mails you can withdraw your consent by clicking on the “unsubscribe” link at the bottom of the email or by contacting us.  

              

            Performance of a contract with you (or in order to take steps prior to entering into a contract with you) GDPR art. 6 (1) (b): For example, where you have purchased products or services from us and we need to use your contact details and payment data in order to process your order and deliver your product or services.  

              

            Compliance with law GDPR art. 6 (1) (c): In some cases, we may have a legal obligation to use or keep your personal data. For example, where we need to keep payment information as tax documentation or when handling VAT issues.  

              

            Our legitimate interests GDPR 6 (1) (f): Where it is necessary for us to understand our customer, promote our product and operate our Services efficiently for the creation, publication and distribution of product and marketing content both online and offline, globally. Examples of when we rely on our legitimate interests to use your personal data include:  

              

            • when we analyse what content has been viewed on our Services, so that we can understand how they are used and improve our content.  
            • to carry out marketing analyses to better understand your interests and preferences so that we can make our marketing more relevant to your interests and preferences. This includes when we promote our own products and services. For example, we look at what you have viewed on our Services and what products and services you have bought (including what you have looked at and what products or services you have bought on Services, for example VRAI Jobs).   
            • to show you personalised advertising by identifying your interests and to create “segments” of particular types of audiences so that we may show you advertisements that may be more relevant to your interests and the ‘’segments’’ you may be in. These ‘’segments’’ are also used to inform the building of custom audiences so that we can identify our audience across third party websites, such as social media platforms like Facebook.  
            • for internal administrative purposes related to when you use our Services - such as our accounting and records - and to make you aware of any changes to our Services. 
            • to collect and log IP addresses to improve the Services and monitor Service usage. 
            • to personalise our Services (for example, so you can sign in) by remembering your settings, and recognising you when you sign in on different devices. 
            • enabling you to share our content with others using social media or email. 
            • when responding to your queries and to resolve complaints. 
            • for security and fraud prevention, and to ensure that our Services are safe and secure and used in line with our terms of use.  

              

            Where we rely on cookies to collect any personal data please see our Section on Cookies policy for more information and how to manage your cookie choices.

            DATA TRANSFERS

            Whenever we transfer your personal data out of the EU, we ensure similar protection and put in place at least one of these safeguards:  

              

            • We will only transfer your personal data to countries that have been found by the EU Commission to provide an adequate level of protection for personal data.  
            • We may also use specific approved contracts that use Standard Contractual Clauses for the protection of personal data where appropriate, with our service providers that are based in countries outside the EU, including those based in the US and Australia. These contracts give your personal data the same protection it has in the EU.  

                

            If you are located in the EEA, you may contact us for a copy of the safeguards which we have put in place for the transfer of your personal data outside the EU.

            DATA SUBJECT RIGHTS

            If you are a data subject in the EU, you have the following rights:  

              

            • You are entitled to request access to, rectification or erasure of your personal data.  
            • You are also entitled to oppose the processing of your personal data and to request restriction of the processing of your personal data. 
            • You have in particular an unconditional right to oppose the processing of your personal data for direct marketing purposes.  
            • If the processing of your personal data is based on your consent, you are entitled to revoke such consent at any time. Revocation of your consent will not affect the lawfulness of the processing carried out prior to your revocation of consent. 
            • You are entitled to receive personal data which you have provided to us in a structured, commonly used and machine-readable format (data portability). 
            • You can always lodge a complaint with an EU data protection authority.  

              

            Your rights may be subject to conditions or restrictions. Accordingly, there is no certainty that you will be entitled to for example data portability in the specific situation; it will depend on the circumstances of the processing.  

              

            To exercise any of these rights, contact us as set forth in the section entitled "Contact Us" above and specify which right you intend to exercise.  

              

            We will respond to your request within 30 days and we may require additional information from you to allow us to confirm your identity.

            Have a question or concern?

            *Privacy Policy Effective Date: February 2, 2021*