Privacy Policy

Last Date Updated:  July 21, 2025

Applicability

This policy describes how we treat personal information gathered from our website (sunbum.com). It applies to practices on the websites or apps where it appears. It does not apply in other circumstances. That includes not applying to our employees or contractors.

Notice at Collection

Information We Collect

The type of information depends on your relationship with us. It also depends on how you interact with us.

California, Colorado and potentially other state laws require us to tell you if we share categories of information for targeted advertising such as cross-contextual behavioral advertising. For each category below we have indicated if we do this. (To modify your preferences, read the Notice of Right to Opt-out of Sharing for Cross-Contextual Behavioral Advertising below.) 

  • Contact information. We collect your name and email address. We may also collect your phone number or address. We may share this information for cross-contextual behavioral advertising.
  • Account information. We collect username and password if you create an account with us.
  • Purchase and interest information. We may collect information about your purchases. We also collect information about your interests. For example, if you prefer certain types of beauty products. We may share this information for cross-contextual behavioral advertising.
  • Job applicant Information. We collect employment information from job applicants. This includes education and work history. We may also ask you about your skills and qualifications. We may ask about your ability to perform the position.
  • Payment information. We use third parties to collect payment information when you make a purchase. This includes credit and debit card information.
  • Site and device information. We collect log and session data. This includes online activity and preferences. It also includes your browser or operating system. It may also include IP address or device ID. We may also collect language preference or general geolocation. This information may be shared for cross-contextual behavioral advertising.
  • Other information you submit. We collect personal information you provide to us. This may include comments or suggestions you submit to us online.

 

How We Use Your Information

We use information as disclosed and described here.

  • To communicate with you. We use your information to provide you with shipping information. We may also send you messages about your relationship with us. This includes information about this policy. It also includes communicating about job applications.
  • To provide or improve our products and services. We use your information to provide you with products or services you request. This includes fulfilling orders. It also includes providing The Bum Club loyalty program, if you have joined. We will also use information for troubleshooting or account maintenance. We use your information to customize your experience with us. This may include targeting offers or opportunities to you.
  • To comply with legal or regulatory obligations. We may use information to protect our company and customers. We also use information to protect our platforms. We may also use information for security purposes and to help avoid fraud.  
  • For marketing purposes. We use your information to update you on new products or offers. We may also tell you about new features or updates.
  • We use information as otherwise permitted by law. We also use information as we may notify you.

 

Sensitive Information

We do not use or disclose sensitive personal information, as defined by California law, for inferring characteristics or for purposes other than those permitted by law. In the event we do collect such information for any limited reason, we keep these categories of personal information as long as necessary or relevant for the purposes for which it was collected. We also keep information as required by law.

 

How Long We Keep Information

We keep these categories of information as long as necessary or relevant. We also keep information as required by law.

 

More Information About Our Privacy Practices

Please read the rest of this policy for more information about our practices.

How We Collect Information

We collect information directly from you. For example, we collect information when you contact us. This includes in our “live chat” area of the website. It also includes when you inquire about a job opportunity. We also collect information directly from you when you sign up for our newsletter or purchase product from us. 

We collect information indirectly. We may receive information about you from our third-party vendors or partners.

We collect information passively. We collect information about users over time and across different websites and apps. Our vendors may also collect information this way. We may use common tracking tools. These include cookies and web beacons. We may do this on our platforms and in our emails.

 

We Combine Information

We combine information that we have collected offline with information we collect online. We also combine information collected across devices. This might include information collected from computers with that collected on mobile devices. We also combine information that we get from others with information we already have. We may combine information that we have collected over time.

 

How We Disclose Information to Others

Below are times when we may disclose your personal information. We have also indicated the categories of entities to whom we may disclose your personal information:

  • We disclose your information to vendors and others who perform services for us. We may disclose all categories of information with vendors and partners.  This includes website hosting with service providers like Shopify (see more in the Shopify section below). It also includes chat vendors, loyalty program partners and marketing. This also includes payment and shipping vendors.
  • We share information for cross-contextual behavioral advertising. This includes online ads targeted to your interests. The Notice at Collection (above) outlines which categories of information we share for this reason.
  • We disclose information to comply with the law. We will transfer all categories of information to respond to a court order or subpoena. We will also disclose in response to a government agency or investigatory body request. This includes US and non-US entities.
  • We disclose information for security purposes. This includes disclosing information to protect us. We will also disclose it to protect you or others.
  • We will transfer information to successors to all or part of our business. If all or part of our business is sold, we may transfer all categories of information as part of that transaction. We will also do this if there is a merger or acquisition.
  • We may disclose personal with our corporate affiliates, including our parent company, sister companies, and subsidiaries.
  • We may disclose information for other reasons we may describe to you. We will also disclose information as permitted by law.

 

 

Additional information for residents in certain states. California, Nevada, and Virginia law require that we tell you if we sell personal information with a third party for monetary or (in California) other valuable consideration. We do not do this. We also do not do this with information of minors under the age of 16.

Shopify-Powered Services on the Sun Bum Website


When you browse or shop on the Sun Bum website (www.sunbum.com), certain features and functions are powered by Shopify, a third-party ecommerce platform. This section explains how Shopify may collect and use your personal information, and how that relates to our use of cookies and your privacy rights.


How Shopify Uses Your Information


When you interact with our site, Shopify may act as either a data processor (service provider) or a data controller, depending on the feature.


1. Shopify as Our Service Provider (Processor)

In most cases—such as when you make a purchase, use the shopping cart, or check out—Shopify acts as a service provider to Sun Bum. That means it processes your personal information (like your name, email, shipping address, and payment info) only on our instructions, to:

  • Process and fulfill your orders
  • Provide secure checkout and payment services
  • Host and operate the Sun Bum website
  • Power our account and customer support tools


Sun Bum remains responsible for this data in these cases.


2. Shopify as an Independent Data Controller for Enhanced Services


Starting July 25, 2025, Shopify may also use some of your data collected on SunBum.com for its own purposes—like improving how products are recommended or preventing fraud. These “Enhanced Services” are powered by Shopify Network Intelligence, which uses information from across Shopify’s platform to:

  • Personalize your shopping experience
  • Improve platform-wide search and recommendations
  • Detect fraudulent activity
  • Support advertising and performance features


In this context, Shopify acts as a data controller and determines how that data is used. You can read more here: Shopify Privacy Policy - Shopify


3. Shopify as a Controller for Shopify Account Information


If you choose to create or log into a Shopify account (used across different Shopify-powered stores), Shopify independently controls and manages that account information—including your order history, login credentials, and account preferences.


How to Opt Out of Shopify’s Use of Your Data


If you’d like to opt out of Shopify using your personal data for Enhanced Services like personalized ads or platform-wide analytics, you can:

 

Your Rights and Choices

Marketing Choices

You may opt out of receiving marketing emails you receive from us. To do so follow the instructions in the message you receive. You will still receive our transactional communications.

Loyalty Program - The Bum Club

With respect to our loyalty program, if you ask us to delete your information or opt out of the use of your information, we will comply with your request, but you may lose some or all the benefits associated with the incentive program.  For example, if you ask us to delete your personal information, you will lose any accumulated loyalty program points (known as “bananas”).

 

Cookies and Tracking Tools

We collect personal information over time and across different websites. We also serve content based on your behaviors and interests. This may be on our platform or third party platforms. We also have vendors that do this. To do this, we use common tracking tools. These may include browser cookies or web beacons. We may also use flash cookies and similar technologies.

 

  • You can control cookies and tracking tools. Your browser may enable you to control cookies or other tracking tools. How you do so depends on the tool. Certain browsers can be set to reject browser cookies. If you block cookies, certain features on our website may not work. If you block cookies, not all the tracking described here will stop.
  • Our Do Not Track Policy. Some browsers have “do not track” features. These allow you to tell a website not to track you. These features are not all uniform. We do not currently respond to those signals except as described in the Notice of Right to Opt-Out of Sharing, below.
  • Notice of Right to Opt-out of Sharing for Cross-Contextual Behavioral Advertising: You can opt out of the sharing of your personal information for this purpose by visiting here. On that page, turn the cross-contextual behavioral advertising cookies to inactive. You can also configure certain browsers to tell websites not to share your information like this through the “global privacy control” signal. We will respond to this signal in a frictionless manner. If you configure this setting on your browser, certain features may not work. To learn how to configure this setting, view here.

 

Options you make are browser and device specific.

 

Specific Rights in Certain Jurisdictions

If you are a consumer who lives in the EU, the UK, California, Colorado, Connecticut, Virginia, Utah, or jurisdictions with similar laws, you may have additional rights. Those rights depend on our relationship. The rights are subject to certain limitations and are not absolute. This might include if a legal exception applies. If that is the case, we will not be able to process your request.

 

The Rights:

  • Access and portability. You have the right to learn the categories of information we collect and use. For those in California, you have the right to learn the sources of collection and the business purpose for the collection. You may also have the right to know if your information is disclosed. You may also have the right to a copy of all your personal information. This includes the specific pieces of the personal information we have collected.
  • Correction. You have the right to ask us to correct inaccurate personal information.
  • Deletion. You have the right to request that we delete your personal information.
  • Restrict or object to processing. UK and EU residents have the right to limit the way we use personal information. This can be done as an alternative to requesting we delete your personal information. You may also have the right to object to how we process information.

 

Nevada residents. You may opt out of the future sale of your information to a third party so that they may license or sell that information. To do this, email us at the contact information listed at the end of this privacy statement.

 

How it Works

To exercise your rights, submit the form here. You may also contact hey@sunbum.com. For verification purposes, we may request information you may have already given us. This might include your first and last name. It might also include your email address or physical address. We may also ask for a copy of your government-issued ID. We will let you know when or if a right does not apply to you. If you disagree with our decision, you can contact us as described at the end of this statement. We will not discriminate against you because you exercised your rights.

 

Third Party Agents

If you are submitting on someone else’s behalf, we may ask for additional verification. This may include a signed letter verifying your right to make this request.

 

Notice of Financial Incentive

California and Colorado require that we provide you with information about financial incentives. You can read this at our Notice of Financial Incentives.

 

Information Collected from Children

Our Sites and Apps are meant for adults. We do not knowingly collect personally identifiable information from children under thirteen. Contact us if you are a parent or legal guardian and think your child under 13 has given us information. You can contact us at the email or address provided at the end of this policy. Please mark your inquiries “COPPA Information Request.” Parents, you can learn more about how to protect children’s privacy on-line here.

 

We Use Standard Security Measures

We use reasonable security measures as required by relevant law. The Internet is not 100% secure. We cannot promise that your use of our Sites or Apps will be completely safe. We encourage you to use caution when using the Internet. This includes not sharing your passwords.

 

We Store Information Inside the United States

Information we collect may be stored in the United States. If you live outside of the United States and choose to use our platforms, you understand that it is at your own risk. You also understand that your information will be sent to the United States. The United States may not afford the same level of protection as laws in your own country.

 

Links to Third Party Sites

We may link to third-party sites or apps. Our Sites may also include third party content that collects information. We do not control these third parties. This policy does not apply to the privacy practices of these third-party websites or apps. Please read the privacy policies of other websites carefully. We are not responsible for the practices of these third-party sites or apps.

In addition, you agree to our Messaging Terms and Messaging Privacy Policy.

 

Contact Us

 If you have any questions about this Policy or our privacy practices, please email us at hey@sunbum.com.

You can also write to us or call us at:

444 S. Coast Highway 101, Encinitas, California 92024.

1-877-978-6286

 

Privacy Policy Updates

From time to time, we may change our privacy policies. We will notify you of any material changes to our Policy as required by law. We will also post an updated copy on the sites where this appears. Please check our site periodically for updates.