A. The Services this Privacy Statement Covers

At eShopWord, we recognise that privacy and security is a concern for all our customers and we are committed to safeguarding your rights.

This Privacy Statement applies to your access to and use of our services, content, features, technologies or functions offered through our sites and all of our related sites (the “sites”), and applications (together these are called the “Services”) (this includes any information in relation to your use of the Services).

B. The Purpose of this Statement

The purpose of our Privacy Statement is to tell you, as clearly as possible:

1. How we will use your personal information so that you can decide whether you want to give your personal information to us, so we can provide the services you want; and

2. How eShopWorld will protect your personal information, and the guidelines we use in safeguarding the personal information you give us.

We recommend that you view, read, download and save this Privacy Statement.

In this Privacy Statement “eShopWorld”, “our”, “us” or “we” means U.S. Direct E-Commerce Limited (trading as ESW, eShopWorld), together with each of its group companies. U.S. Direct E-Commerce Limited is a company incorporated in Ireland with company registered number 479237 and having its registered office at South Block, The Concourse Building, 110-115 Airside Business Park, Swords, County Dublin, Ireland.

By ticking the consent box, you are consenting to eShopWorld collecting, processing, storing, disclosing and otherwise using your personal information in accordance with this Privacy Statement.

You can withdraw your consent at any time after you have given it and you can do so by contacting us in accordance with the information provided at Further Information – How to Contact Us below.

When you use our Services through any of the sites, we may ask for, hold and use the following information (the retailer may also store this information):
  • personal information such as name, postal address, phone number, email address, date of birth and (where required) I.D. number or other identification information;
  • information that the retailer sends to us;
  • banking card details in order to fulfil the order;
  • information to assist us in detecting, preventing, and/or remediating fraud or any other harmful actions, we will verify the personal information you provide (including, but not limited to your name, address, details of user funding instruments, and details of payment transactions) with the relevant payment processors and/or credit reference and fraud agencies. During such verification, we will receive personally identifiable information about you. eShopWorld will use card authorisation and fraud screening services to verify that your card information and address correspond with the information you supplied to eShopWorld, and that the card has not been reported as lost or stolen;
  • the web address of the site that you came from or are going to (eShopWorld automatically receives this information). We also collect information regarding the pages of our website that you view, IP addresses, your internet browser and the times at which you access our sites.
  • details of when we contact you and when you contact us. We keep a record of any e-mail correspondence you send us, so we can track any problems or concerns you’ve had with any of the retailer’s products or stores operated through the sites. (We may record, store and use that correspondence for future training or business purposes. This includes, without limitation, use in dispute resolution and/or complaints management);
  • demographic and basket details; and
  • we may place small data files on your computer or device (“Cookies”) whenever you visit the sites. These Cookies are sent back to the originating website on each subsequent visit, or to another website that recognises that Cookie. Cookies have a number of uses, such as remembering your preferences, and generally improving your online experience. If you would like to know more about how and why we use Cookies and how you can manage Cookies stored on your computer or device, please view our Cookie Policy.
eShopWorld keeps a record of the information you authorise us to collect and use. We keep a record of any purchase(s) you make from any of our retailers’ stores through eShopWorld and the sites. This means eShopWorld and (in some instances) the retailer can assist you in dealing with any questions or queries you may have, and to ensure that any information that we send you is relevant. We may also ask you questions and from time to time, that will give us information that will be used to improve your experience of shopping through our sites. You do not have to answer these questions, but if you do we can communicate with you via a medium of your choosing. If you would like to revise the information you have provided to us because you feel that what we currently have on record is incorrect, and/or you would like your information to be erased from our records, you can do so by contacting us in accordance with the information provided at Further Information – How to Contact Us below.
Depending on where the services are being provided to you, eShopWorld will store your personal information on servers located within the European Union (EU) or servers located at other locations outside of the EU in accordance with the applicable legislation. All the information we collect via your use of the Services and/or the sites, or through correspondence with you, is used to provide, operate and improve the Services we offer you and to personalise our Service. We are committed to using your personal information only for:
  • passing your order information to the retailer so they can supply the goods and services to eShopWorld;
  • using your information to complete the sale between us and you and to fulfil your order. We and/or the retailer may use subcontractors (including to assist with delivery and fulfilment) to process and provide your orders to you;
  • verification of your identity and your payment method or credit card account for the detection, prevention, and/or remediation of fraud, terrorism or any other harmful or criminal actions;
  • planning and managing eShopWorld’s business activities, including the analysis of customers’ shopping habits and customer profiling;
  • research and customer surveys (should you chose to take part); and
  • customer service and dispute resolution.
eShopWorld may use screening tools to identify potentially fraudulent orders, these tools may make automated decisions which result in your order being rejected. If you believe your order was rejected in error then please use the contact details below to send us a message and we will manually review your order.
eShopWorld will keep your information confidential and only share it with others for the purposes set out in this Privacy Statement. eShopWorld carefully selects third-party service providers which allow us to ultimately provide you with a faster, more efficient, and safer Service. We have engaged these third-party service providers under contract and are required to keep your personal information confidential and secure, only using it for the purposes that we allow. eShopWorld may share your information with the following entities:
  • any group company of, or individual employed by eShopWorld;
  • the retailer;
  • logistics and other shipping and delivery service providers;
  • business operations support;
  • payment processing services;
  • technology services;
  • agents and contractors of eShopWorld; and
  • external research companies who we may contact you directly (on our behalf) for your opinions on our Services (in which case we provide them with only the information they need to perform their function).
There are also specific instances where eShopWorld will be obliged to provide your personal details to third parties (set out below) and you acknowledge and consent to eShopWorld doing the following actions:
  • where eShopWorld is requested by a law enforcement agency or authority (or a regulatory authority or government authority) investigating illegal or suspicious activities to provide information (including without limitation the information recorded by fraud prevention agencies) concerning your activities; and
  • where eShopWorld is required to disclose necessary information to payment processors, auditors, customer service providers, fraud agencies, credit reference agencies, financial product providers, credit card associations, commercial partners, marketing and public relations partners, group companies or for legal proceedings (except as explicitly stated, these third parties are limited by law or by contract from using your personal information for any purpose other than the purpose for which it was shared).
Also, if our business is acquired by, or merged with another company (our data records form part of our business). If such an acquisition occurs, you consent to the successor company having access to your personal information maintained by eShopWorld, and such successor company would continue to be bound by this Privacy Statement unless and until it is amended.

We shall monitor and review communications between you and us solely for the purposes of ensuring that your orders are managed appropriately by our customer service team and the retailer, and in accordance with the terms and conditions that we have in place with the retailer.

The internet is not an entirely secure medium for communication and, accordingly, we cannot guarantee the security of any information you send to us (or we send to you) via the internet. We are not responsible for any damages which you, or others may suffer as a result of the loss of confidentiality of such information.

We take every precaution to protect your information. To this end all personal information stored by us is kept on a server in a secure environment. Secure Socket Layer (“SSL“) encryption technology is used for protection of information in transit for payments transactions.

Only our employees, the retailer and our third-party service providers who need the information to perform a specific job are granted access to personally identifiable information.

eShopWorld will retain the minimum amount of your personal information for the period necessary to fulfil the purposes outlined in this Privacy Statement unless a longer retention period is required or permitted by law. Please note that we have a variety of obligations to retain the Data that You provide to us, including to ensure that transactions can be appropriately processed, settled, refunded or charged-back, to help identify fraud and to comply with laws and rules that apply to us and to our financial service providers.
Our Services are not directed to persons under the age of thirteen (13). We request that such individuals do not directly provide us with any personal information through our Services on the sites.
Our Services are global, and your data may be stored and processed in any country where we have operations or where we engage service providers, this includes any countries outside of the European Economic Area (EEA) or the United States (US). eShopWorld is committed to the sufficient protection of your personal information regardless of where the data resides and to providing adequate protection for your personal information where such data is transferred outside of the EEA or the US. If you use any of our Services through the sites, you consent and authorise us to process data in this way.
For more information about how you can access, object, manage, correct any inaccuracies or delete any of your personal data or if you have any questions or complaints regarding our treatment of your personal data or our Privacy Statement, please contact us by email us at Privacy@eshopworld.com or post to: Head of Compliance eShopWorld c/o U.S. Direct E-Commerce Limited 3rd Floor, The Concourse Building 100-115 Airside Business Park Swords County Dublin Ireland You also have the right to lodge a complaint to a supervisory authority in the Member State of your residence, place of work or the pace of the alleged infringement. In Ireland the relevant supervisory authority is the Office of the Data Protection Commissioner. For Residents of the United Kingdom In respect of data subject in the United Kingdom, eShopWorld has appointed our UK affiliate to be its appointed representative. Full name of legal entity: U.S. Direct E-Commerce U.K. Limited (trading as eShopWorld) Email address: privacy@eshopworld.com Postal address: Eversheds House, 70 Great Bridgewater Street, Manchester, United Kingdom, M1 5ES For California Residents California residents may exercise their privacy rights by calling us toll free at 1-866-I-OPT-OUT (1-866-467-8688) and entering service code 841# to leave us a message. For purposes of California law: we do not share your personal information with third parties for their direct marketing purposes unless you have specifically requested and consented to such sharing. We also do not sell your personal information and have not done so in the past 12 months.

eShopWorld reserves the right to revise its Privacy Statement at any time. We will notify you of such changes by uploading the revised Privacy Statement on the eShopWorld website. As of the effective date of the revised Privacy Statement, you will be considered as having consented to all changes to the Privacy Statement. If you do not agree with the terms of this Privacy Statement or any revised Privacy Statement, please do not use the Services. Please check the eShopWorld website here on a regular basis for the current version of our Privacy Statement.

eShopWorld accepts no liability for, nor does it warrant or guarantee that the privacy statement, policy or notice of any retailer, or any other entity, that your personal information is passed to in accordance with this Privacy Statement, comply with data protection legislation and privacy laws. eShopWorld is not responsible for any breach or loss of confidentiality of your personal information or any other damages which you or any others may suffer as a result. On placing an order with a retailer through any of the sites, the personal details that you submit will be, shared with, or received from, the retailer. It is your responsibility to read the retailer’s privacy policy carefully and to fully understand their practice regarding the treatment of your information. Should you have any queries regarding their privacy policy, please contact the retailer directly.

U.S. Direct E-Commerce Limited (trading as ESW) is one of several legal entities in a group of companies (together these form the “ESW Group”). This Data Privacy Notice is issued on behalf of the ESW Group. When we mention “ESW”, “we”, “us” or “our” in this Data Privacy Notice, we are referring to the relevant company in the ESW Group responsible for processing your data.

At ESW, we recognise that data protection is a priority for our customers, and we are committed to safeguarding your rights in this respect.

ESW is a data controller. This means that we are responsible for deciding how we hold and use personal data about you.

Our contact details are as follows:
ESW, South Block, The Concourse Building, 110 -115 Airside Business Park, Swords, County Dublin, Ireland, K67 NY94.

When you use our services through any of our retail partner websites, we may collect and process the following information:

  • Identity data includes first name, surname, username or similar identifier, marital status (where required), title (where required), date of birth (where required), gender (where required) and official identification information (passport, government ID etc.) and details (where required).
  • Contact data includes address, email address, telephone number.
  • Transaction data refers to the information generated and collected during a financial transaction between shopper and ESW. This includes but is not limited to:


Payment Information
: This includes credit card numbers, bank account details, and any other payment method information used for the transaction.

Purchase Details: Information about the items or services purchased, including product names, quantities, prices, and any applicable discounts or taxes.

Transaction Timestamp: The date and time when the transaction occurred.

Payer Information: Personal information about the payer making the purchase, such as name, email address, shipping address, and contact information.

Transaction ID: A unique identifier assigned to each transaction, which helps in tracking and referencing the transaction.

Authorization and Verification Data: Data related to the authorization and verification of the payment, such as authorization codes, security codes, and response codes.

  • Technical data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
  • Account data includes your username and password, purchases or orders made by you, your interests, preferences, feedback, survey responses and copies of any correspondence you may have with us.
  • Website usage data includes information about how you use our website, products, and services, where you have provided consent to the usage of cookies which tracks this information.
  • Communications data includes your communications with us (emails, chats etc.) and includes your communication preferences.

We will use your personal data under the following circumstances:

1) Where it is necessary to perform the contract of service that you have requested from us;

2) Where it is necessary for ESW to comply with a legal obligation;

3) Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;

4) Where you have provided your consent to the processing of your personal data.

The following table provides the purposes and legal bases we rely on for processing your personal data:

Purpose/Activity
Type of data
Lawful basis for processing personal data
To pass your order information to the retailer to enable the retailer to supply ESW with the goods and services you have requested.
Identity data Contact data
Performance of a contract with you.
To send data to payment services providers to facilitate your payment.
Identity data Transaction data
Performance of a contract with you.
To organise the delivery of your purchases to you (including customs purposes).
Identity data Contact data
Performance of a contract with you. Legal obligation.
To use your information to complete the sale between ESW and you, and to fulfil your order. We and/or the retailer may use subcontractors (including to assist with delivery and fulfilment) to process and provide your orders to you.
Identity data Contact data Transaction data Communications data
Performance of a contract with you.
Verification of your identity and your payment method or credit card account for the detection, prevention, and/or remediation of fraud, terrorism or any other harmful or criminal actions.
Identity data Transaction data Technical data
Necessary for our legitimate interests (to prevent fraud and safeguard the organisation’s business).
To use data analytics to improve our website, products, services, marketing, customer relationships and experiences, testing, research, and statistical analysis. This may include machine learning and artificial intelligence.
Technical data Transaction data Contact data Communications data
Necessary for our legitimate interests (to run and improve our business).
Customer service and dispute resolution.
Identity data Contact data Transaction data Communications data
Performance of a contract with you
To manage our relationship with you which may include asking you to leave a review or take a survey.
Identity data Contact data Profile data Communications data
Necessary for our legitimate interests (to run and improve our business).
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data).
Identity data Contact data Technical data
Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise).

Automated Decision-Making including Profiling

ESW may perform automated decision-making including profiling as part of its services. This may include the use of screening tools to identify potentially fraudulent orders, and sanctions screening processes to comply with our regulatory obligations relating to AML and KYC. These tools may make automated decisions that result in your order being declined.

ESW may also perform profiling and data analysis activities, for example, through the use of cookies, which may result in you receiving personalised advertisements or to improve website and product offerings.

Further processing of your personal data

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason, and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

We may collect your personal data through various means including the following:

Direct interactions

You may give us your personal information at the time you are placing an order through our retail partner websites. This also includes personal data you provide when:

  • Placing an order for a product through ESW;
  • You are registered with one of our retailers or brand partners and pre-populated information is sent to our checkout;
    • Subscribing to our service or publications;
    • Requesting marketing material to be sent to you;
    • Providing us with feedback.

 

Automated technologies or interactions

As you interact with our website, we may collect Technical data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see our cookie policy for further details.

Third parties or publicly available sources

We may receive personal data about you from various third parties such as:

Fraud, risk, and financial sanctions screening services.

ESW will keep your personal data confidential and only share it with others for the purposes set out in this Data Privacy Notice. ESW carefully selects third-party service providers that allow us to provide you with a faster, more efficient, and safer service. We have engaged these third-party service providers under contract, who are required to keep your personal data confidential and secure, only using it for the purposes that we allow.

ESW may share your information with the following parties where necessary and proportionate and by reliance on a valid legal basis:

  • Any ESW Group company, or individual employed by ESW;
  • The respective retailer / brand partner (the online store);
  • Logistics and other shipping and delivery service providers;
  • Business operations support;
  • Payment processing services;
  • Risk screening providers;
  • Technology services providers;
  • Agents and contractors of ESW; and
  • External research companies who may contact you directly (on our behalf) for your opinions on our Services (in which case we provide them with only the personal data they need to perform their function).


There are also specific instances where ESW may be obliged to provide your personal data to other third parties:

  • Where ESW is required to disclose necessary information to auditors, customer service providers, fraud agencies, credit reference agencies, financial product providers, credit card associations, commercial partners, marketing and public relations partners, or for legal proceedings (except as explicitly stated, these third parties are limited by law or by contract from using your personal data for any purpose other than the purpose for which it was shared); and
  • Where ESW is requested by a law enforcement agency, regulatory authority or government authority investigating illegal or suspicious activity to provide information concerning said activities.

As stated, we may need to share your personal data within the ESW Group and this may involve transferring it outside of the European Economic Area (EEA). Some of our external third-party service providers may also be based outside the EEA. Their processing of your personal data may involve a transfer of your data outside the EEA. Whenever we transfer your personal data outside of the EEA, we will employ legal mechanisms to ensure that a similar degree of protection is afforded to it by relying on at least one of the following safeguards:

ESW will retain your personal data for the minimum period necessary in order to fulfil the purpose(s) as outlined in this Data Privacy Notice, unless a longer retention period is required by law.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means.

Please note that we have a variety of obligations to retain the personal data that you provide to us, including the need to ensure that transactions can be appropriately processed, settled, refunded or charged-back, to help identify fraud, and to comply with laws (for example, tax and VAT laws) and regulations that apply to ESW and to our financial service providers.

Our services are not directed at children. We request that children’s personal data is not provided to us.

Under data protection law you have the following rights:

  • Access to your personal data (commonly known as a “data subject access request”). This includes confirmation as to whether your personal data is being processed by ESW and if so, to obtain a copy of your personal data.
  • Rectification of the personal data that we hold about you. This enables you to have incomplete or inaccurate personal data we hold about you corrected.
  • Erasure of your personal data. This enables you to ask us to delete or remove personal data where there are no grounds for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have exercised your right to object to processing (see below).
  • Object to processing of your personal data, unless we can demonstrate that there are compelling legitimate grounds for the processing. You also have the right to object where we are processing your personal information for direct marketing purposes.
  • Object to automated decision-making including profiling. You have the right not to be subject to a decision based solely on automated processing Including profiling which produces legal or significant effects.
  • Restriction of processing of your personal data. This enables you to ask us to suspend the processing of personal data about you under certain circumstances, for example if you want us to establish its accuracy or the reason for processing it.
  • Right to data portability or request the transfer of your personal information to another party under certain circumstances. This right only applies to personal data that is being processed on the basis of your consent or for the provision of a contract with you.

 

For California Residents

  • Right to Opt-Out of Sale or Sharing of personal data: Once such a request is made, no data that is collected about you may be shared or sold to a third party.
  • Right of No Retaliation Following Opt-Out or Exercise of Other Right: In the case of the website selling a product, your choice to exercise any of your consumer rights under the CPRA must not result in you receiving an inferior product. Restricting your access to coupons or discounts is also prohibited.

 

The rights set out above are not absolute. There may be times or circumstances when these rights may be lawfully restricted.

You will benefit from any mandatory provisions of the law of the country in which you are resident. Nothing in this document affects your rights as a data subject to rely on such mandatory provisions of local law.

If you want to exercise any of your rights, please email privacy@esw.com.

No Fee usually required

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

What we may need from you

We may need to request specific information from you to help us confirm your identity and verify your right to access the personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.

Time limit to respond

We will respond to all legitimate data subject rights requests within one month. Occasionally, it may take us longer than this, if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated. If we do not respond to you within the stipulated time frame, you have the right to lodge a complaint to the relevant supervisory authority.  

Keeping us up to date

It is important that the personal data we hold about you is accurate and up to date. Please keep us informed if your personal data changes during your relationship with us.

If you have any questions regarding our handling of your personal data or in relation to this Data Privacy Notice, please contact our Data Protection Officer by email at privacy@esw.com, or by post to:

Data Protection Officer,
ESW,
3rd Floor, The Concourse Building,
100-115 Airside Business Park,
Swords,
County Dublin,
Ireland, K67 NY94.

For Residents of the United Kingdom
In respect of data subjects residing in the United Kingdom, ESW has appointed its UK affiliate to be its’ appointed representative:

Full name of legal entity: U.S. Direct E-Commerce U.K. Limited (trading as ESW)
Email address: privacy@esw.com

Postal address:
Ground Floor, Egerton House, 68 Baker Street, Weybridge, Surrey, United Kingdom, KT13 8AL 

For California Residents

California residents may exercise their data privacy rights by calling us toll free at 1-866-I-OPT-OUT (1-866-467-8688) and entering service code 841# to leave us a message.

For the purposes of Californian State privacy law (CCPA): ESW does not share your personal data with third parties for their direct marketing purposes unless you have specifically consented to such sharing. We also do not sell your personal data.

If you wish to raise a complaint about how ESW has handled your personal data, please contact our Data Protection Officer at privacy@esw.com

You also have the right to lodge a complaint to the relevant supervisory authority. The Lead Supervisory Authority for ESW is the Irish Data Protection Commission (www.dataprotection.ie).

ESW reserves the right to revise its Data Privacy Notice at any time. Please check the ESW website here on a regular basis for the current version of our Data Privacy Notice.

ESW accepts no liability for the Data Privacy Notice of any third party. ESW also does not warrant or guarantee that the data privacy statement, policy or notice of any retailer, or any other entity, that your personal data is passed to, in accordance with this Data Privacy Notice, complies with data protection legislation and privacy laws. ESW is not responsible for any breach or loss of confidentiality of your personal data or any other damages that you or any others may suffer as a result.

On placing an order with a retailer through any of our websites, the personal data that you submit will be shared with, or received from, the retailer. It is your responsibility to read the retailer’s own data privacy notice, statement or policy carefully and to fully understand their practices regarding the handling of your personal data. Should you have any queries regarding their data privacy notice, statement or policy, please contact the retailer directly.