your privacy rights, our Privacy Policy, and Terms of USe

  1. INTRODUCTION: Chroma, LLC (“Chroma,” “we” or “us”) respects your privacy. Chroma has adopted this Privacy Policy to let you know how we treat the information that we collect from you online and offline. This Privacy Policy explains the collection, use, and sharing of information from or about you, including personal information, in connection with your use of Chroma’s website, online booking tool, and services. By using Chroma’s website, online booking tool, or using Chroma’s services, you consent to the collection and use of information from or about you as explained in the Privacy Policy.

  2. INFORMATION WE GATHER

    1. Information You Provide to Us: We collect information you provide directly to us or through our service providers. For example, we, or a third party acting on our behalf, collect information when you create an account, fill out a form, inquire about services, engage with us via third party social media sites, or otherwise communicate with us.
      The types of information we may collect include:

      1. Your name, email address, phone number, postal address, ZIP code, and birth date, and in the case of spa services, some health history;

      2. If you are applying for employment, your résumé information, such as employment and education history;

      3. Any other information you choose to provide

    2. We may collect and store information about your transaction when you make a purchase in our stores, such as the items or services purchased, the transaction amount, the date and location of the store of your purchase, and limited payment information, such as payment card type, expiration date, and the last four digits of your card number; however, we do not collect or store full payment card numbers and all payment card transactions are processed by our third-party payment processors.

    3. Information We collect Automatically When You Use our Services:

      1. Information Collected by Cookies and Similar Technologies: We and our service providers use various technologies, including cookies, web beacons, embedded scripts, location-identifying technologies, device recognition technologies, and other tracking technologies now and hereinafter developed (“Tracking Technologies”) to collect information about you and our interaction with our Services or e-mails, including information about your browsing and purchase behavior, and as otherwise described in this Privacy Policy.

        1. Cookies: Cookies are small text files placed in visitor’s computer browsers to store their preferences. Most browsers allow you to block and delete cookies, however, the Site may not work properly.

        2. Pixel Tags/Web Beacons: A pixel tag is a piece of code embedded on the website that collects information about users’ engagement on that web page. The use of a pixel allows us to record, for example, that a user has visited a particular web page or clicked on a particular advertisement.

        3. Social Media Widgets: The Site includes social media features such as links to Facebook, Instagram, Twitter, YouTube and Vimeo (that might include widgets, such as, the share this button or other interactive mini-programs). These features may collect your IP address, which page you are visiting on the Site and may set a cookie to enable the feature to function properly. These social media features are either hosted by a third party or hosted directly on the Site. Your interactions with these features are governed by the privacy policy of the company providing it.

        4. Analytics: We may also use Google Analytics and Google Analytics Demographics and Interest Reporting to collect information regarding visitor behavior and visitor demographics on some of our Services and to develop website content. This analytics data is not tied to any Personal Information. For more information about Google Analytics, please visit www.google.com/policies/privacy/partners/. You can opt-out of Google’s collection and Processing of data generated by your use of the Services by going to https://tools.google.com/dlpage/gaoptout.

      2. Third-Party Payment Processing: When you make purchases through the Services, either online or in-person, we process your payments via a Third-Party payment processor. In these instances, the third party payment processor may collect certain Financial Information from you to Process a payment on behalf of Chroma, including your name, email address, address and other billing information in which case the use and storage of your Financial Information is governed by the third party app’s terms, conditions and privacy policies. Our treatment of any Financial Information that we may Process on your behalf, or that we receive from our payment processors, is subject to this Privacy Policy. For more information on our use of third party payment processors, including the name(s) of the entities that we partner with, please email info@chromaseattle.com.

      3. In-store Cameras: We use in-store cameras for security purposes and for operational purposes such as improving the customer experience.

      4. Chatbot: When you interact with the chatbot on our website, please note the following:

        1. The chatbot collects and retains the information you provide during the conversation to assist with support, inquiries, and improving the chatbot's functionality.

        2. Any personal information you share with the chatbot is subject to this Privacy Policy.

        3. The chatbot is powered by ChatGPT, an AI language model developed by OpenAI. By interacting with the chatbot, you acknowledge and agree to the collection and processing of your information in accordance with this Privacy Policy.

    4. Information We Collect from Other Sources: Certain functionalities on the Services permit interactions that you initiate between the Service and certain third-party services, such as third-party social networks (“Social Features”). Examples of Social Features include: enabling you to send content such as contacts and photos between the Services and a Third-Party Service; “liking” or “sharing” Chroma’s content; logging in to the Services using your third-party service account (e.g., using Facebook Connect to sign-in to the Service); and to otherwise connect the Service to a Third-Party Service (e.g., to pull or push information to or from the Service). If you use Social Features, and potentially other third-party services, information you post or provide access to may be publicly displayed on the Services or by the third-party service that you use. Similarly, if you post information on a third-party service that references the Services (e.g., by using a hashtag or handle associated with Chroma in social media post), your post may be used on or in connection with the Services or otherwise by Chroma. Also, both Chroma and the third party may have access to certain information about you and your use of the Services and any third-party service.

    5. Information We Collect About Others: In some cases, we may also collect information you provide about others, such as when you refer someone to our Services (such as for certain promotions), or when you make a purchase for others or specify items for others in your party. We will use this information to fulfill your requests and will not send marketing communications to your contacts unrelated to your requests, unless they separately consent to receive these communications from us.

  3. USE OF INFORMATION

    1. To Provide products, services, or information requested: Chroma may use information about you to fulfill requests for products, services, or information about potential or future services, including to:

        1. Generally manage individual information;

        2. Respond to questions, comments, and other requests;

        3. Communicate with you about logistical matters, including appointment inquiries and employment opportunities;

        4. Provide services to you

    2. Administrative Purposes: Chroma may use Personal Information about you for its administrative purposes, including to:

        1. Ensure quality control;

        2. Send emails or text messages to the email address or telephone number you provide to us for informational and operational purposes, such as sending appointment reminders, confirming appointment requests, or sending ‘thank you’ cards;

        3. Process applications and transactions;

        4. Maintain and administer our Services.

  4. INFORMATION WE SHARE: Chroma will not reveal to any third party a user’s information provided to us through use of the Services except in the following circumstances:

    1. We have your permission to share the information;

    2. We need to share your information to provide the product or service you requested;

    3. In response to a request for information if we believe such disclosure is required to comply with any applicable law, rule, regulation or legal process;

    4. To protect and defend our rights and property

    5. We sell or acquire another business, or are acquired by another business, in which case such information may be one of the business assets transferred.

  5. SOCIAL SHARING FEATURES: The Services may offer social sharing features and other integrated tools (such as the Facebook “Like” button), which let you share actions you take on our Services with other media, and vice versa. Your use of such features enables the sharing of information with your friends or the public, depending on the settings you establish with the entity that provides the social sharing feature. For more information about the purpose and scope of data collection and processing in connection with social sharing features, please visit the privacy policies of the entities that provide these features.

  6. THIRD PARTY LINKS AND CONTENT: There may be links on Chroma’s website that let you leave the particular Chroma Service you are accessing in order to access a linked site that is operated by a third party. Chroma neither controls nor endorses these sites, nor has Chroma reviewed or approved the content that appears on them. Chroma is not responsible for the legality, accuracy or inappropriate nature of any content, advertising, products or other materials on or available from any such third party sites. You acknowledge and agree that Chroma is not responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the access or use of any of the links, content, goods or services available on or through these third party sites.

  7. ADVERTISING AND ANALYTICS SERVICES PROVIDED BY OTHERS

    1. We may allow others to provide analytics services. Some information about your use of the Services and certain third-party services may be collected using Tracking Technologies across time and services, and used by Chroma and third parties (including our service providers) for purposes such as to associate different devices you use, and deliver relevant ads and/or other content to you on the Services and certain third-party services. These entities may use Tracking Technologies to collect information about your use of the Services and other websites, including your IP address, web browser, pages viewed, time spent on pages, links clicked and conversion information. This information may be used by Chroma and others to, among other things, analyze and track data, determine the popularity of certain content, deliver advertising and content targeted to your interests on our Services and other websites and better understand your online activity. For more information about interest-based ads, or to opt out of having your web browsing information used for behavioral advertising purposes, please visit aboutads.info/choices.

    2. We may also work with third parties to serve you ads as part of a customized campaign on third-party platforms (such as Facebook or Twitter). Note that the third-party platforms may offer you choices about whether you see these types of customized advertisements.

  8. SECURITY: Chroma takes reasonable measures to help protect information about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. In certain areas of our website, we use SSL-encryption to protect data that is transmitted. SSL is a technology that secures the connection between your browser and our website. Chroma makes no claim, warranty or representation that even SSL level encryption is completely secure, and you provide such information at your own risk. SSL Provides three important security benefits:

    1. Privacy: Encrypts the connection between the browser and web server and securely transmit information to prevent unauthorized parties from eavesdropping.

    2. Data integrity: Prevents unauthorized parties from altering data during transmission

    3. Authentication: Protects against impersonation by requiring web server proof of identity.

  9. OPT-OUT (RIGHT TO OBJECT TO PROCESSING)

    1. General: You have the right to object to and opt-out of certain uses and disclosures of your Personal Information. Where you have consented to Chroma’s Processing of your Personal Information or Sensitive Personal Information, you may withdraw that consent at any time and opt-out to further Processing by contacting info@chromaseattle.com. Even if you opt-out, we may still collect and use non-Personal Information regarding your activities on our Service and/or information from the advertisements on third party websites for non-interest based advertising purposes, such as, to determine the effectiveness of the advertisements.

    2. Email, text, and telephone communications: You can unsubscribe from email, text and phone communications at any time. To stop receiving our promotional emails, follow the unsubscribe instructions in the email messages you receive from us or contact us as at info@chromaseattle.com. To opt-out of receiving text messages, follow the opt-out instructions in the text messages that you receive from us. We will process your request within a reasonable time after receipt, in accordance with applicable laws. Note that you will continue to receive transaction-related emails regarding products or services you have requested. We may also send you certain non-promotional communications regarding Chroma and our Services and, to the extent permitted by law, you will not be able to opt-out of those communications (e.g., communications regarding updates to our Terms or this Privacy Policy).
      We maintain “do-not-call” and “do-not-mail” lists as mandated by law. We process requests to be placed on do-not-mail, do-not-phone and do-not-contact lists within 60 days after receipt, or such shorter time as may be required by law.

    3. Do Not Track”: Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. DNT is a way for users to inform websites and services that they do not want certain information about their webpage visits collected over time and across websites or online services. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.

    4. Cookies and Interest-Based Advertising: As noted above, you may stop or restrict the placement of cookies on your computer or remove them from your browser by adjusting your web browser preferences. Please note that cookie-based opt-outs are not effective on mobile applications. However, on many mobile devices, application users may opt-out of certain mobile advertisements via their device settings.
      The online advertising industry also provides websites from which you may opt-out of receiving targeted ads from our data partners and our other advertising partners that participate in self-regulatory programs. You can access these, and also learn more about targeted advertising and consumer choice and privacy, at www.networkadvertising.org/managing/opt_out.asp, www.youronlinechoices.eu/ or www.youradchoices.ca/, and www.aboutads.info/choices/. You can also choose not to be included in Google Analytics.
      To be clear, whether you are using our opt-out or an online industry opt-out, these cookie-based opt-outs must be performed on each device and browser that you wish to have opted-out. For example, if you have opted-out on your computer browser, that opt-out will not be effective on your mobile device. You must separately opt-out on each device. Advertisements on third party websites that contain the AdChoices link, and that link to this Privacy Policy, may have been directed to you based on anonymous non-Personal Information collected by advertising partners over time and across websites. These advertisements provide a mechanism to opt-out of the advertising partners’ use of this information for interest-based advertising purposes.

    5. Rights of Access, Rectification, Erasure, and Restriction: Where permitted by applicable law, you may inquire as to whether Chroma is Processing Personal Information about you, request access to Personal Information, and ask that we correct, amend or delete your Personal Information where it is inaccurate or has been Processed in violation of your rights under data privacy laws that apply in the country where you live. Where otherwise permitted by applicable law, you may send an email to info@chromaseattle.com or use any of the methods set out in this Privacy Policy to request access to, receive, seek rectification, or request erasure of Personal Information held about you by Chroma. Please include your full name, email address associated with your account and a detailed description of your data request. Such requests will be processed in accordance with local laws.
      Although Chroma makes good faith efforts to provide Individuals with access to their Personal Information, there may be circumstances in which Chroma is unable to provide access, including but not limited to where the information contains legal privilege, would compromise others’ privacy or other legitimate rights, where the burden or expense of providing access would be disproportionate to the risks to the Individual’s privacy, in the case in question or where it is commercially proprietary. If Chroma determines that access should be restricted in any particular instance, we will provide you with an explanation of why that determination has been made and a contact point for any further inquiries. To protect your privacy, Chroma will take commercially reasonable steps to verify your identity before granting access to or making any changes to your Personal Information.

    6. Data Retention: Chroma retains the Personal Information we receive as described in this Privacy Policy for as long as you use our Services or as necessary to fulfill the purpose(s) for which it was collected, provide our Services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements and comply with applicable laws. Legal requirements, however, may require us to retain some or all of the Personal Information we hold for a period of time that is longer than that for which we might otherwise hold it.

    7. Your California Privacy Rights: We provide California residents with the option to opt-out of sharing “personal information” as defined by California’s “Shine the Light” law with third parties, including Chroma affiliates or our authorized operators, for such third parties’ own direct marketing purposes. California residents may exercise that opt-out, and/or request information about Chroma’s compliance with the Shine the Light law, by sending a letter to Chroma at PO Box 31009, Seattle, WA 98103 (Attention: Customer Service). Requests must include “California Privacy Rights Request” in the first line of the description and include your name, street address, city, state, and ZIP code. Please note that Chroma is only required to respond to one request per customer each year.
      In addition to the rights in this section, California residents have certain rights under the California Consumer Privacy Act.
      Any California residents under the age of eighteen (18) who have registered to use the Services, and who posted content or information on the Services, can request removal by contacting Chroma at PO Box 13009, Seattle, WA 98103 (Attention: Customer Service). Requests must include “California Privacy Rights Request” in the first line of the description and include your street address, city, state, and ZIP code. Requests must detail where the content or information is posted and attesting that you posted it. Chroma will then make reasonable good faith efforts to remove the post from prospective public view or anonymize it so the minor cannot be individually identified to the extent required by applicable law. This removal process cannot ensure complete or comprehensive removal. For instance, third-parties may have republished or archived content by search engines and others that Chroma does not control.

    8. Your Nevada Privacy Rights: Under Nevada law, Nevada residents may opt out of the sale of certain “covered information” collected by operators of websites or online services. We currently do not sell covered information, as “sale” is defined by such law, and we don’t have plans to sell this information. However, if you would like to be notified if we decide in the future to sell personal information covered by the Act, please contact info@chromaseattle.com and provide your name and email address, in an e-mail with “Nevada Data Privacy” in the subject. You are responsible for updating any change in your email address by the same method and we are not obligated to cross-reference other emails you may have otherwise provided us for other purposes. We will maintain this information and contact you if our plans change. At that time we will create a process for verifying your identity and providing an opportunity to verified consumers to complete their opt-out. Please become familiar with our data practices as set forth in this Privacy Policy. We may share your data as explained in this Privacy Policy, such as to enhance your experiences and our services, and those activities will be unaffected by a Nevada do not sell request. You may also have other choices regarding our data practices as set forth elsewhere in this Privacy Policy.

    9. Non-U.S. Users: Chroma is based in the United States and the information we collect is maintained and processed in the U.S. and governed by U.S. law. If you are located in the European Economic Area (EEA), please note that Chroma does not intend to offer goods and services to EEA individuals. By accessing or using our website and services or otherwise providing information to us, you consent to the processing and transfer of information in and to the U.S., where you may not have the same rights as you do under the law of the jurisdiction from which you access the website and services. Chroma is not responsible for, and makes no representations regarding, the policies or business practices of third parties (including where information is maintained and processed), including, without limitation, service providers and third-party services (including Social Features) associated with the website and services.

    10. TERMS OF USE, NOTICES, AND CHANGES TO PRIVACY POLICY: If you choose to visit the website or use our services, your visit and any dispute relating to privacy is subject to this privacy policy and our terms of use, including limitations on damages, arbitration of disputes, and application of the law of the State of Washington. Chroma reserves the right to change this privacy policy, the website, and the terms, conditions and notices under which the website is offered. You are responsible for regularly reviewing these terms and conditions.

    11. OUR ADDRESS
      Please send any questions or comments regarding this site to:
      Chroma, LLC, PO Box 31009, Seattle, WA 98103