GDPR PRIVACY NOTICE
YETI UK Limited
Last updated: 11 March 2021
This General Data Protection Regulation (“GDPR”) Privacy Notice (“Notice”) describes how YETI UK Limited (“YETI”, “We” or “Us”) collects and uses information, including personal information (also known as personal data) about you through the use of our services, and through email and other electronic communications between you and YETI. This Notice applies to our practices in connection with information that we collect through:
- Any website operated by us from which you are accessing this Notice (collectively, the "Websites”); and
- Email, telephone and other electronic messages between you and us.
This Notice does not apply to information collected by:
- any third party, including through any application or content (including advertising) that links to or is accessible from or on any Website.
Collectively, we refer to the operation of the Websites, fulfillment of orders, and email and other electronic communications as the “Services.”
“Personal Information” is information that identifies you as an individual or relates to an identified or identifiable individual, including information that is about you individually and can be attributed to you even if it does not directly identify you, and information about your internet connection, the equipment you use to access our Services and usage details.
This Notice may change from time to time (see the “UPDATES TO THIS NOTICE” Section of this Notice), and we will notify you in advance of any material changes, by posting the changes on the relevant Websites, and emailing you where feasible.
Our affiliates are YETI Holdings, Inc., YETI Coolers, LLC, YETI Canada Limited, and YETI Australia Pty Ltd. (“Affiliates”).
YETI UK Limited is the data controller of the Personal Information collected through our Services. Its registered office is at 100 New Bridge Street, London, England, EC4V 6JA UK. YETI UK Limited is registered with the UK Information Commissioners Office as a Data Controller. Our registration number is ZA862884.
Our representative in the EU is First European Data Rep BV. Its registered office is at Schiphol Boulevard 195, 1118 BG Schiphol, The Netherlands.
YETI and our representative in the EU may be contacted per the “CONTACT INFORMATION” section of this Notice.
INFORMATION WE COLLECT ABOUT YOU AND HOW WE COLLECT IT
We collect different types of information about you, Personal Information and aggregated information about you that we combine with aggregated information about other users. This includes information that we collect directly from you or through automated collection technologies.
The Services collect your Personal Information:
- Postal address (including billing and shipping addresses);
- Telephone number;
- Email address;
- IP address (this also enables us to derive your approximate location from your IP address);
- Account information, such as username and password;
- Demographic information and other information provided by you that does not reveal your specific identity; and
- Website traffic data, location data, logs, referring/exit pages, date and time of your visit to our Services, error information, clickstream data, and other communication data and the resources that you access and use on the Services;
- Information collected through cookies, pixel tags and other technologies; and
- Information about your Internet connection, the equipment you use to access our Services and usage details.
If you disclose any Personal Information relating to other people to us or to our service providers in connection with the Services, you represent that you have the authority to do so and that you gave them sufficient information about this disclosure and YETI’s subsequent processing of the information. If this is not the case, please ask for their authority to do so and make this Notice available to them.
Collection of Personal Information
We and our service providers collect Personal Information in a variety of ways, as follows:
Through the Services.
We collect Personal Information on or through the Services, for example, when you sign up to receive updates, special promotions or newsletters from us, register an account to access the Services, contact customer service, or make a purchase. We inform you when the provision of information is mandatory (in particular because of a legal, regulatory or contractual obligation or simply in order to be able to process your request or respond to you). If you do not provide this "mandatory" information, YETI may not be able to provide you with certain services, or respond to the request or form in question. The fields of a form that are not filled in as mandatory are left to your discretion. It is up to you to choose whether or not to complete them.
Automatically through our Website.
Location Information. This Website collects real-time information about the location of your device. You can choose whether or not to allow the Website to collect and use real-time information about your device’s location through the device’s privacy settings. If you block the use of location information, some parts of the Website may then be inaccessible or not function properly. For more information, see the “CHOICES ABOUT HOW WE USE AND DISCLOSE YOUR INFORMATION” Section below.
The information we collect automatically may include Personal Information or we may maintain it or associate it with Personal Information we collect in other ways or receive from third parties. It helps us to improve our Website and to deliver a better and more personalized service by enabling us to estimate our audience size and usage patterns, store information about your preferences, allowing us to customize our Website according to your individual interests, and to recognize you when you return to our Website.
USE OF PERSONAL INFORMATION and LAWFUL BASIS FOR PROCESSING
We use your Personal Information for various purposes described below, including to:
- provide our Website to you;
- sell our products and Services to you;
- provide you with information you request from us;
- enforce our rights arising from contracts;
- notify you about changes; and
- provide you with notices about your account.
We have a lawful basis for our processing of your Personal Information, notably to fulfill our obligations to you under a contract with you or to take steps at your request in anticipation of entering a contract with you, for our legitimate interests (when balanced against your rights and freedoms), as required by applicable law, or with your consent.
We and our service providers use Personal Information that we collect about you or that you provide to us on the following lawful bases and for the following purposes:
- Lawful basis: To Fulfill Our Obligations to You under our Contract, or to Take Pre-contractual Measures at your Request. We process your Personal Information in order to fulfill our obligations to you pursuant to our contract with you, or your requests in anticipation of entering into a contract with us:
- To provide the Services’ functionality to you, such as arranging access to your registered account, and providing you with related customer service;
- To respond to your inquiries and fulfill your requests, when you contact us via one of our online contact forms or otherwise, for example, when you send us questions, suggestions, compliments, or complaints;
- To complete your transactions, verify your information, and provide you with related customer service;
- To send administrative information to you, such as changes to our terms, conditions, and policies; and
- To participate in a sweepstakes, contest, or other promotion. Some of these promotions have additional rules containing information about how we will use and disclose your Personal Information. Please read those additional rules before choosing to participate.
- Lawful basis: Legitimate Interests. We will process your Personal Information as necessary for our legitimate interests. Our legitimate interests are balanced against your rights and freedoms and we do not process your Personal Information if your rights and freedoms outweigh our legitimate interests. Our legitimate interests are to grow our business by continually improving our products and Services, while adhering to high ethical standards and complying with applicable laws in order to protect our reputation; where other legitimate interests are relevant we have stated them below linked to the respective purpose. The purposes for which we process Personal Information to further our legitimate interests are:
- to facilitate communication between YETI and you;
- to detect and correct bugs and to improve our Services;
- to safeguard our IT infrastructure and intellectual property;
- to detect and prevent fraud and other financial crime, by conducting fraud and security monitoring to detect and prevent cyberattacks or attempts to commit identity theft and by checking your credit and performing risk assessments (YETI has a legitimate interest in preventing fraud and other financial crime, detecting cyberattacks and attempts to commit identity theft in order to protect itself and others);
- to promote and market our business by better understanding your interests and preferences (such as by identifying usage trends, for example, understanding which parts of our Services are of most interest to users), so that we can personalize our interactions with you and provide you with information and/or offers tailored to your interests, and deliver content via our Services that we believe will be relevant and interesting to you; and
- to develop, enhance, improve, repair, maintain or modify our product and Services and to develop new products and services, such as by performing trade analyses, and analyzing or predicting our users’ preferences in order to prepare aggregated trend reports on how our digital content is used;
- to optimize the efficiency of our Websites and Services, processing of payments (via third parties) and performance of customer services;
- to determine the effectiveness of our promotional campaigns by measuring audience engagement, so that we can adapt our campaigns to the needs and interests of our users;
- to operating and expanding our business activities, by understanding which parts of our Services are of most interest to our users so we can focus our energies on meeting our users’ interests;
- to verify that our internal processes function as intended and to address legal, regulatory, or contractual requirements, such as by conducting audits of customer experience;
- To aggregate and/or anonymize Personal Information so that it will no longer be considered Personal Information. We do so to generate other data for our use, which we may use and disclose for any purpose, as it no longer constitutes Personal Information;
- to comply with government inspections, audits, and other valid requests from government or other public authorities outside the UK or EEA, as applicable;
- to respond to legal process such as subpoenas outside the UK or EEA, as applicable;
- to assess our quality and safety assurance measures;
- to maintain proper books and records, in particular of our sales of products, in compliance with laws outside the UK or EEA, as applicable;
- to protect our interests, rights, privacy, safety or property, and/or that of our affiliates, you or others or otherwise pursue our legal rights and remedies (for instance, when necessary to prevent or detect attacks against our network, or other criminal and tortious activities), defend litigation, and manage complaints or claims; and
- to disclose or transfer your Personal Information to a third party in the event of any financing, reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).
- Lawful basis: As Required by Law. We may also process your Personal Information when we are required by UK or EEA law, as applicable:
- to comply with government inspections, audits, and other valid requests from government or other public authorities;
- to respond to legal process such as court orders;
- quality and safety assurance measures; and
- to maintain proper books and records, in particular of our sales of products.
- Lawful basis: Consent. We may also process your Personal Information when we have received your consent to do so:
You can update your preferences at any time via the cookie banner.
The purpose of the processing of your personal data is notably to analyze and evaluate your behavior on our Sites. This helps us to constantly improve our own Sites and its user-friendliness.
- If you are a prospective customer, to send you our newsletter ; you can stop receiving newsletters via the unsubscribe option; and
- If you are a prospective customer, to send you marketing related emails, with information about our services, new products, and other news about our company; you can stop receiving emails via the unsubscribe option in each marketing email or by contacting us directly.
SHARING PERSONAL INFORMATION
We do not share, sell, or otherwise disclose your Personal Information for purposes other than those described in this Notice. We share your Personal Information with third parties on a need to know basis, as listed below:
- our Affiliates and third-party service providers that we use to support our business;
- our third-party marketing partners for marketing and advertising purposes;
- a company we merge with, acquire, or that buys us, or in the event of change in structure of our company of any form;
- public and government authorities to comply with our legal obligations;
- our Affiliates and third parties for their own commercial purposes with your consent;
- to enforce our rights.
We do not share, sell, or otherwise disclose your Personal Information for purposes other than those outlined in this Notice.
We share Personal Information as follows:
- With our Affiliates for the purposes described in this Notice.
- With our third-party service providers, contractors, and other third parties to support our business.
- These can include providers of services such as website hosting, data analysis, payment processing, order fulfillment, information technology and related infrastructure provision, customer service, email delivery, and auditing which are only authorized to process the Personal Information on documented instructions. For more information on our third-party payment providers see the “THIRD PARTY PAYMENT SERVICE” section below.
- With our third-party marketing partners for marketing and advertising purposes, which are only authorized to process the Personal Information on documented instructions.
- With third party sponsors of sweepstakes, contests, and similar promotions, which are only authorized to process the Personal Information on documented instructions.
- With your consent.
We may also share your Personal Information as necessary or appropriate, in particular:
- To comply with applicable law and regulations.
- This may include laws outside your country of residence.
- To cooperate with public and government authorities.
- To respond to a request or to provide information we believe is necessary or appropriate.
- These can include authorities outside your country of residence.
- To cooperate with law enforcement.
- For example, when we respond to law enforcement requests and orders or provide information we believe is important.
- For other legal reasons.
- To enforce our terms and conditions; and
- To protect our rights, privacy, safety or property, and/or that of our affiliates, you or others.
In connection with a sale or business transaction.
We have a legitimate interest in disclosing or transferring your Personal Information to a third party in the event of any financing, reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).
We are permitted to disclose aggregated information about our users, and information that does not identify any individual, without restriction as long as the aggregated information does not relate to any identified or identifiable person.
Information transmitted over the Internet is not completely secure, but we do our best to protect your Personal Information. You can help protect your Personal Information and other information by keeping your password to your account confidential.
We seek to use reasonable organizational, technical and administrative measures to protect Personal Information within our organization. All payment transactions are performed by our third-party payment processor (PayPal or Shopify), who must comply with appropriate industry standards to protect your payment information.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to your account, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
Unfortunately, the transmission of information via the Internet is not completely secure. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us per the “CONTACT INFORMATION” section below.
CHOICES ABOUT HOW WE USE AND SHARE YOUR INFORMATION
We offer you choices about opting in to our use of tracking technology, sharing your Personal Information with third parties that advertise to you, our advertising to you, and other targeted advertising. We may also ask you to opt-in to receive direct marketing from us, or if you are a customer, give you the choice of opting out of direct marketing.
We have created mechanisms to provide you with control over your Personal Information:
- Promotional Offers from YETI. We give you choices regarding our use and sharing of your Personal Information for marketing purposes. If you are a customer, you may opt out from receiving marketing-related emails from us. If you are a potential customer, we will only send marketing-related emails if you opt-in to receive them. If you receive marketing-related emails from us but want to opt-out on a going-forward basis, you may use the opt-out mechanism contained in each such email. We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt out of receiving marketing related emails from us, we may still send you important administrative messages (such as in relation to a purchase you have made from us), from which you cannot opt out.
- Cookies, Tracking Technologies and Advertising. Some content or applications, including advertisements, on our Websites are served by third-parties, including advertisers, ad networks and servers, content providers, application providers, and social media sites. We will ask you to accept cookies to receive this content.
You can learn more about interest-based advertisements and your opt-in rights and options:
- at YourOnlineChoices.eu - Your ad choices;
- from members of the Network Advertising Initiative (“NAI”) on its website (www.networkadvertising.org);
from members of the Digital Advertising Alliance on its website (www.aboutads.info).
YOUR RIGHTS REGARDING YOUR PERSONAL INFORMATION
You have rights under applicable data protection laws, including the right to access and update your Personal Information, restrict how it is used, transfer certain Personal Information to another controller, withdraw your consent at any time, and have us erase certain Personal Information about you. You also have the right to complain to a supervisory authority about our processing of your Personal Information.
In accordance with the United Kingdom General Data Protection Regulation (UK GDPR) and the European Union General Data Protection Regulation (EU GDPR) you have the following rights, in some cases subject to specific conditions as set forth in the UK GDPR and EU GDPR:
- Right to Access. You have the right to obtain information from YETI as to whether or not personal data concerning you are being processed, and a copy of that personal data (also referred as ‘data subject access rights’).
- Right to Rectification. You have the right to have inaccurate or incomplete Personal Information corrected without undue delay by notifying us in any manner set forth below in the “CONTACT INFORMATION” section of this Notice to ensure that data is accurate and as current as possible. Additionally, you can review and change your Personal Information by logging into the Services and visiting your “My Account” page. This includes first name, last name, company, address, and phone number when securely logged in.
- Right to Erasure (or to be Forgotten). You have the right to request that we delete all of your Personal Information under certain conditions, for example when our processing of that Personal Information is no longer necessary, or when your Personal Information was unlawfully processed. If we delete all your Personal Information, we will also delete your user account. We may not accommodate a request to erase information notably if processing is required to comply with a legal obligation, or to establish, exercise or defend a legal claim.
- Withdrawing Consent. To the extent that our processing of your Personal Information is based on your consent, you have the right to withdraw consent at any time. Withdrawing your consent will not, however, affect the lawfulness of the processing based on your consent before its withdrawal, and will not affect the lawfulness of our continued processing that is based on any other lawful basis for processing your Personal Information.
Right to Restriction of Processing. You have the right to restrict our processing of your Personal Information (that is, storing your Personal Information without otherwise processing it) under certain circumstances. In particular, you can request we restrict our use of it if you contest its accuracy, if the processing of your Personal Information is determined to be unlawful.
Right to Object. You have the right to object to the processing of your Personal Information for direct marketing purposes. You also have the right to object, on grounds relating to your particular situation, to processing based on our legitimate interests (or those of a third party). We will stop processing your Personal Information unless we can demonstrate compelling legitimate grounds for the processing, which override your interests, rights and freedoms, or for the establishment, exercise or defense of legal claims.
Right to Data Portability. To the extent the Personal Information you provide YETI is processed based on your consent or to perform a contract, you have the right to request that we provide you a copy of all or part of such Personal Information in structured, commonly used and machine-readable format. You also have the right to request that we transmit this Personal Information to another controller where technically feasible.
Please note that if you make a manifestly unfounded or excessive request (as determined in our reasonable discretion), you may be charged a fee subject to a maximum set by applicable law.
Right to lodge a complaint. You have the right to lodge a complaint with the applicable supervisory authority in the country where you live or work, or the country where you believe your rights under applicable data protection laws have been violated. A list of data protection authorities is available here. However, before doing so, we request that you contact us directly in order to give us an opportunity to work directly with you to resolve any concerns about your privacy.
We retain Personal Information for as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with applicable law. The criteria used to determine our retention periods are:
- The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services) plus a reasonable period in light of the applicable statute of limitations;
- Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them); or
Whether retention is advisable in light of our legal position (such as in regard to current or reasonably foreseeable litigation or regulatory investigations).
THIRD PARTY SERVICES
This Notice does not apply to information collected by third party websites accessible through the Services.
This Notice does not address, and we are not responsible for, the privacy, information, or other practices of any third parties, including any third party operating any website or service to which the Services link. The inclusion of a link on the Services does not imply endorsement of the linked site or service by us or by our affiliates.
AUTOMATED DECISION MAKING
We generally do not use your Personal Information with any automated decision-making processes that produce legal or similarly significant effects.
Our service providers may use techniques like machine learning to help us improve our services. When our service providers use such machine learning, it either: (1) still has a human being involved in the process (and so is not fully automated); or (2) uses machine learning in ways that do not have significant privacy implications, for example, reordering how apps might appear when you visit the online store (and so does not produce legal effects or similarly significant effects).
USE OF SERVICES BY MINORS
Our Services are not intended for children under the age of 18 and children under the age of 18 are not permitted to use our Services. We will remove any information about a child under the age of 18 if we become aware of it.
The Services are not intended for individuals under the age of 18, and we do not knowingly collect Personal Information from individuals under 18. If you are under 18, do not register for Services, make any purchases through the Services or provide any information about yourself to us, including your name, address, telephone number, email address, or any screen name or user name you may use. If we learn we have collected or received Personal Information from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from a child under 18, please contact us per the “CONTACT INFORMATION” section of this Notice.
JURISDICTION AND INTERNATIONAL TRANSFERS
We may process your Personal Information outside of your home country, including transferring it to or from the United States. When we transfer Personal Information outside of your home country, we provide appropriate safeguards to protect your Personal Information.
Your Personal Information may be stored and processed in the United States, where we have facilities and in which we engage service providers, and, which does not provide an equivalent level of protection for your Personal Information. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in the United States may be entitled to access your Personal Information.
Your Personal Information is transferred by YETI to another country as permitted under applicable data protection law and provided that there are appropriate safeguards in place to protect your Personal Information. For transfers from the EEA or UK to countries not considered adequate by the European Commission, such as the United States, we have entered into EU standard contractual clauses approved by the European Commission prior to such transfer to ensure the required level of protection for the transferred Personal Information. You may request additional information in this respect and obtain a copy of the relevant safeguard we have put in place by contacting us in accordance with the “CONTACT INFORMATION” section of this Notice.
We do not request you provide and do not process any special categories of Personal Information.
YETI does not ask you to provide, and we do not knowingly collect, any special categories of Personal Information from you. You are prohibited from sending us, or otherwise disclosing to us, any sensitive Personal Information (e.g., information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background, or trade union membership) on or through the Services or in any other manner.
THIRD PARTY PAYMENT SERVICE
UPDATES TO THIS NOTICE
We will post any changes to our Notice on our Website. If we make material changes to our Notice, we will post the changes ahead of time, and notify you of such changes through your contact information and invite you to review (and consent to) the changes.
We may change this Notice at any time. The “LAST UPDATED” legend at the top of this Notice indicates when this Notice was last revised. If we materially change this Notice, we will use reasonable efforts to notify you of the changes in advance (e.g. by email to the email address specified in your account).
Please feel free to contact us with any questions or comments you have about this Notice or our privacy practices.
If you have any questions, concerns, complaints or suggestions about this Notice, have any requests related to your Personal Information pursuant to applicable laws, or otherwise need to contact us, please contact us at the below. Email communications are not always secure, so please do not include credit card or other sensitive information in your emails to us.
To exercise your data protection rights:
Contact details if you are in the UK:
Telephone: 0808 1697080
Contact details if you are in the EU/EEA: