Privacy Policy
PRIVACY POLICYEmpty heading
ONLINE PRIVACY POLICY AGREEMENT
BGSun, Inc.
Last Updated Date: Sept 15th, 2025
Thank you for doing business with BGSun, Inc. (“Company,” “we,” “our,” or “us”). We welcome you and hope you find our websites, web applications, products, and our subscription services and tools (collectively, the “Services”) helpful and useful. For those of you who are current or potential employees or business partners, we hope your interaction with us is pleasant and helpful. We have adopted this privacy policy (“Privacy Policy”) to help our current and potential customers, clients, their employees, our employees, and other business partners (“you” or “your,”) understand what Data we process, how and why we do so, and what your rights are regarding that Data.
We always seek to improve our Services to you, and that requires that we process information about you and your usage preferences. As we do so, we are absolutely committed to protecting your privacy and the security of your personal information.
In this Privacy Policy, we use the word “Data” to describe all the information we process that relates to you and your use of our Services. “Data” is broken into different categories, which are defined in the “Data We Process” section of this Privacy Policy. We may refer to the different categories separately, but when we use the word “Data,” we mean all the different categories described in this Privacy Policy. The term “Data” does not apply to information which does not relate to an identified or identifiable individual or to personal information or data rendered anonymous in such a manner that the individual is not or no longer identifiable, (“AnonymizedData”). We may use Anonymized Data for our own purposes in any manner and without attribution or compensation to any person.
When we have a separate agreement with you and that agreement addresses how we handle Data, the terms of that separate agreement will control over any conflicting provisions of this Privacy Policy. The definition of “Data” in that separate agreement, if there is one, may differ from the definition we use in this Privacy Policy, because the agreement will address particular interactions with a particular party.
With that exception, this Privacy Policy applies to everybody who interacts with us online or otherwise. Because different portions of the Privacy Policy will apply differently to the various groups who interact with us, we have tried to clearly categorize the types of Data we process and how we do so. If you have any questions about this Privacy Policy or how we handle your Data, please email us at customerexperience@blackgirlsunscreen.com.
DESCRIPTION OF SERVICES
We provide sun protection products and associated accessories for every day use. In this Privacy Policy, all the products or functions made available on our website, including any other services we provide directly, are included in the term “Services.”
LAWFUL BASIS FOR PROCESSING
Many jurisdictions require that we disclose to you the lawful basis for our processing of your Data. We do that throughout this Privacy Policy. In general, our lawful basis for processing your Data is based on your specific consent or your contract with us.
By accessing or using any of the Services or by otherwise interacting with us online, you consent to our processing of your Data as described in this Privacy Policy. If our processing of your Data is based on your consent, you may withdraw your consent at any time, and we will cease processing your Data. However, in some cases, this may result in your inability to receive partial or full access to the Services, and your withdrawal of consent does not limit our ability to processAnonymized Data for use by us in connection with our legitimate business efforts in the future. In addition, your withdrawal of consent does not prevent us from processing Data if we are required to do so by applicable law or to preserve legal claims. It also doesn’t prevent us from processing Data that is processed pursuant to a different lawful basis. For example, if you give your consent for us to process your Data, but we are also required by law to keep your Data, that separate “lawful basis” will still apply, even if you withdraw your consent.
When you enter into an agreement with us, either by accessing the Services, by executing an agreement in hard copy or by clicking “I Accept” or similar language online, we will process your Data for the purposes of fulfilling the terms of our contract with you. In that case, our processing of your Data is based on the contract, so your withdrawal of consent will only be effective after the purposes for processing that Data have been fulfilled and after we no longer have a legal obligation to keep that Data.
In all cases, we will comply with applicable law and we will cease processing your Data after the legal right, obligation, or other lawful basis expires.
INTENDED USERS
The Services are directed solely to persons 13 years of age or older or of children under 18 who are supervised by a parent, guardian, or other caregiver. Other than for Data processed for the specific purpose of providing the Services to users, we do not knowingly process Data from users who are under 13. If we become aware that we have processed Data from a person under 13, except to provide the Services to such person and to the extent allowed or required by law, then we will attempt to delete such Data as soon as possible, subject to our obligations under applicable law. If you believe that we have processed Data from a person under 13 in contravention of this policy, please contact us at customerexperience@blackgirlsunscreen.com.
DATA WE PROCESS
In the course of our relationship with you, we process different categories of Data. We never sell your Data and we always have a lawful basis for processing the Data, but that lawful basis might be different for different categories. Regardless, we never process the Data for any purpose other than the purpose for which we processed the Data in the first place, unless we get your explicit consent. This section of our Privacy Policy describes the categories of Data we process, the lawful basis for processing that Data, and the uses we make of each category of Data.
A. Registration Data
1. Data Description: Registration Data consists of the name, email address, and other contact information you provide us using the Services, both when you register your account and thereafter. Further, Registration Data may include information processed when you sign up, login to your account, or otherwise link to your account through a third-party or social media platform, including registration and profile information. When you link third-party platforms to the Services, you authorize us to process any Data the third-party platform may give us (i.e. email address, username, etc.); and, all of such data is considered Registration Data. Please note that any third-party platform you link to the Services likely has its own privacy policy that governs its processing of your Data. Please refer to any applicable third-party privacy policy for information regarding their processing of your Data.
2. Lawful Basis for Processing: Our lawful basis for processing Registration Data is our contract with you or your consent. We can only provide certain of the Services to you if we have the Registration Data, so we need to process that Registration Data during the term of our contract or for the purposes of of your consent. Even when the Registration Data is not critically necessary to the provision of the Services, we may still process that Registration Data to facilitate our interactions with you.
3. How We Process It and Who We Share It With: Registration Data is generally accessible only to you and to us. We process Registration Data only to provide the Services to you. In limited circumstances we may transfer Registration Data to our service providers which parties help us provide the Services and are under obligations to protect the confidentiality of your Registration Data. Further, we will never sell your sensitive personal information without your written consent. Finally, we may share your Registration Data to our partners for advertising and analytical purposes and such partners may deliver advertisements to you. If you choose to opt out of us sharing your Data for such purposes, you may change your cookie preferences on your device or opt out by filling out a form at this link.
B. Engagement Data
1. Data Description: Engagement Data consists of all the information you input or record using the Services, except as otherwise stated in this Privacy Policy. Engagement Dataalso includes all information that is proprietary to you regarding your use of the Services (other than the data that qualifies as “Usage Data” below) that is processed by the Services.
2. Lawful Basis for Processing: Our lawful basis for processing Engagement Data is (1) our contract with you and (2) our legitimate interest in improving our Services based on the Engagement Data we receive from you.
3. How We Process It and Who We Share It With: Your Engagement Data is generally accessible only to us and to you. In limited circumstances we may transfer Engagement Data to our service providers which parties help us provide the Services and are under obligations to protect the confidentiality of your Engagement Data. We do not sell Engagement Data to other third parties, except at your specific request, but we may process Engagement Data to make inferences that help us provide and improve the Services, to prevent or identify fraud, or other illegal activities, and to comply with applicable law. Finally, we may share your Engagement Data to our partners for advertising and analytical purposes and such partners may deliver advertisements to you. If you choose to opt out of us sharing your Data for such purposes, you may change your cookie preferences on your device or opt out by filling out a form at this link.
Both during the term of our agreement with you and thereafter, we may also convert Engagement Data to Anonymized Data, and that Anonymized Data belongs solely to us to use in our sole discretion. To the extent we are required to delete any Engagement Data about you, we may still retain any Anonymized Data that may have originated as your Engagement Data.
C. Usage Data
1. Data Description: Usage Data consists of the following and similar information:
o Information about your interactions with the Services, most commonly our website, which includes the date and time of any requests you make. This also may include details of your use of third-party applications and any advertising you receive via the Services.
o The timing of the information you post to the Services including messages you send or receive via the Services and your interactions with our customer service team, but not including the content of those interactions and messages, which would be included as Engagement Data.
o Technical data which may include URL information, cookie data, your IP address, the types of devices you are using to access or connect to the Services, unique device IDs, device attributes, network connection type (e.g. WiFi, 4G, LTE, Bluetooth) and provider, network and device performance, browser type, language, information enabling digital rights management, operating system, and application version.
o Motion-generated or orientation-generated mobile sensor data (e.g. accelerometer or gyroscope), if any, required for the purposes of providing specific features of the Services to you.
2. Lawful Basis for Processing: Our lawful basis for processing Usage Data is (1) our contract with you and (2) our legitimate interest in improving our Services based on the Usage Data we receive from you.
3. How We Process It and Who We Share It With: Usage Data is generally accessible to us and to you. We do not sell it to third parties, except at your specific request, but we may process Usage Data to make improvements to the Services. We may share your Usage Data to our partners for advertising and analytical purposes and such partners may deliver advertisements to you. If you choose to opt out of us sharing your Personal Data for such purposes, you may change your cookie preferences on your device or opt out by filling out a form at this link. We may also convert Usage Data to Anonymized Data, and that Anonymized Data belongs solely to us. To the extent we are required to delete any Usage Data about you, we may still retain Anonymized Data that may have originated as your Usage Data.
D. Payment Data
1. Data Description: Payment Data is only processed when your use of the Services is subject to the payment of a fee or other charge. Payment Data is the information necessary for us to process your payments for Services. Payment Data will vary depending on the payment method you use (e.g. direct via your mobile phone carrier or by invoice) but may include information such as:
o Name;
o Date of birth;
o Credit or debit card type, expiration date, and certain digits of your card number;
o Address and postal code; and
o Phone number.
2. Lawful Basis for Processing: Our lawful basis for processing Usage Data is (1) our contract with you and (2) our legitimate interest in improving our Services based on the Payment Data we receive from you.
3. How We Process It and Who We Share It With: We only use Payment Data to facilitate payment, and we only communicate Payment Data to those parties who are strictly necessary for that purpose.
TRANSFERRING YOUR INFORMATION
Except where a specific limitation is noted above, we may transfer your Data as follows:
1. At Your Instruction. If you request us to make your Data available to a third party, and such request furthers the purposes of our Services, we will do so.
2. Vendors. In certain cases, we use the services of third-party vendors to assist us in providing the Services. We may transfer your Data to such vendors for processing solely for that purpose, and we will require those parties to abide by our privacy policies or privacy policies substantially in consonance with ours.
3. Third-Party Offers. We may allow other companies to offer you their products and services, including offers through our Services, co-branded pages hosted by the third parties, or via email. Whether or not you decide to participate in any such offers is up to you. If you purchase a product or service on a co-branded page or email, or via a third-party offer on our Services that requires you to submit financial and personal information, you are also consenting to our delivery of this information to that party. The offer will notify you if any financial or personally identifiable information will be shared. Such third party will be authorized to use this information in keeping with our contractual relationship with them and in accordance with their own privacy policy and information practices. We do not control these third parties and you agree that we are not liable for their acts, or any failure to act on their part.
4. Third-Party Advertising. We may use Anonymized Data to describe our membership and to establish advertising and other business relationships with third parties. We may serve you with targeted advertisements based on your personal or profile information, but we do not provide any of this personal or profile information to an advertiser or any third party with the exception of those uses expressly disclosed in this Privacy Policy. However, if you click or view an ad on our Services then you consent to the likelihood that the advertiser will assume that you meet the targeting criteria, if any, used to display such ad, and as described above, you will be subject to the advertiser’s privacy policy and information collection practices (if any).
5. Third-Party Ad Servers. We may share your Data to our partners for advertising and analytical purposes and such partners may deliver advertisements to you. If you choose to opt out of us sharing your Data for such purposes, you may change your cookie preferences on your device or opt out by filling out a form at this link. We may also allow third-party ad servers or ad networks to display advertisements on the Services. Some of these ad networks may place a persistent cookie on your computer or use other technologies such as JavaScript and web beacons. Doing this allows them to recognize your computer each time they send you an online advertisement. In this way, ad networks may compile information about where you, or others who are using your computer, saw their advertisements and determine which ads are clicked on. This information allows an ad network to deliver targeted advertisements that they believe will be of most interest to you. We do not have access to or control over the cookies that may be placed by these parties on your computer, and we have no control over these parties’ privacy policies or information collection practices (if any).
6. Service Providers. We may sometimes use a third party to provide specific Services on our behalf, including sending emails to you, conducting surveys, processing transactions,or performing statistical analysis of our Services. In these cases, we may provide certain Data, such as your name, email address, and other financial information necessary for the service to be provided. However, these third parties are required to maintain the confidentiality of this information and are prohibited from retaining, sharing, storing, or using this information for any other purposes.
7. Business Transitions. In the event that we go through a business transition, such as a merger, acquisition, liquidation, or sale of all or a portion of our assets, the information we have about you will, in most instances, be part of the assets transferred. We reserve the right to transfer that information in connection with such transactions without notice to you. We will not obtain your consent for such a transfer.
8. Legal Disclosure. We may disclose your Data if required to do so by law or in the good faith belief that such action is necessary to conform to applicable law, comply with a judicial proceeding, court order or legal process served on us, protect and defend our rights or property, or investigate, prevent or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, or violations of our terms of service.
If we ever plan to process any Data in the future for any other purposes not identified above and we do not have a separate lawful basis for that processing, we will only do so after obtaining your specific consent.
Please note that we DO NOT sell your Data for any purpose.
TECHNOLOGIES WE USE
The technologies we may use for automatic Data processing may include the following:
• Cookies (or browser cookies). A cookie is a small file placed on the hard drive of your computer. Our website issues cookies when you direct your browser to our Services. Our website uses “strictly necessary” or “operational” cookies to function properly, including cookies that help you sign up for, or login to, the Services, that provide core services and features. These cookies also assist us in detecting fraud or crime. We do not ask your permission to store these cookies on your browser or device. Further, when you access our Services, including our website, we may use additional cookies for marketing, advertising, analytics, and other lawful purposes.
• Web Beacons. Pages of the Services and our emails may contain small electronic files known as web beacons (also referred to as clear gifs. pixel tags and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of certain website content and verifying system and server integrity).
• Geolocation. We may use GPS (or other similar) technology when you use our Services, and more specifically any mobile application, to determine your current location. If you do not want us to use your location to provide you the Services, you can turn off your location services on your mobile device in your device’s account settings.
• Other Technologies. We may also use device identifiers, local storage, html modifiers, and different types of caching to help us understand the devices and users who access the Services. Those methods include device identifiers that are either hardware-based or software-based, persistent or non-persistent, and which may identify either a device or a software module within a device (such as a web browser).
“Do Not Track” Options
Your web browser(s) may offer a “Do Not Track” option, which allows the individual to signal to operators of websites and web applications and services (including behavioral advertising services) that he or she does not wish such operators to track certain of his or her online activities over time and across different websites. We do our best to support Do Not Track requests but cannot guarantee full support based on the variety of internet browsers and technologies which means which means that we may process information about your online activity both while you are using the Services and after your use of the Services.
YOUR RIGHTS REGARDING YOUR DATA
Under applicable data privacy, protection, and other laws, you have certain rights related to your access and control of your Data. Such rights may include the following:
1. The right to access, correct, update, or request deletion of your Data.
2. The right to object to processing or restrict the processing of your Data. Please note that if you exercise this right, it may limit or eliminate our ability to provide you the Services.
3. The right to request portability of your Data.
4. The right to opt-out of marketing communications we send you. You can exercise this right by clicking the “Unsubscribe” or “Opt-Out” link found in these communications.
5. The right to not be subject to a decision based solely on automated processing, including profiling, known as Automatic Decision Making.
6. The right to submit a complaint to any applicable regulatory authority about our processing activities.
7. The right to opt-out of us sharing (as defined in the CPRA) your Data, including for direct marketing purposes, subject to certain legal exceptions.
8. The right to limit use, disclosure, and restrict sensitive personal information (as defined in the CPRA).
We may use additional processes to verify your identity before we reveal or delete any of your Data, including two-factor or two-step authentication measures to ensure we can identify you.
This list may not include all of your rights under applicable laws. If you believe you have additional rights, please contact us using the methods in this Privacy Policy.
Further, although we currently do not process Data without consent, if we at any time in the future process Data without your express consent, you may opt-out or withdraw consent at any time.
Please note that exercising any of the above rights may limit or eliminate our ability to provide you the Services. If so, we may terminate the Services due to such requests.
We will try to comply with your request(s) as soon as reasonably practicable. Upon receipt of your written request, we will provide you with a copy of your information, although in certain limited circumstances we may not be able to make all relevant information available to you, such as where that information also pertains to another user. In such circumstances we will provide reasons for the denial to you upon request.
Please also note that if you do opt-out of receiving marketing-related emails from us, we may still send you messages for administrative or other purposes directly relating to your use of the Services, and you cannot opt-out from receiving those messages while continuing to use the Services.
To exercise any of these rights, or if you have any questions about our processing of your Data, please contact us at customerexperience@blackgirlsunscreen.com or at (833) 247-4968.
A. Privacy for EU/UK Residents
The Regulation (EU) 2016/679 (General Data Protection Regulation) made effective in Europe on May 25, 2018 (“GDPR”) requires that we clearly describe to data subjects the data we process and how we process that data. This Privacy Policy does that and if you have any questions for us regarding our data processing, please contact us at customerexperience@blackgirlsunscreen.com.
We are based in the United States. By accessing or using the Services or otherwise providing information to us, you understand that your information will be subject to processing, transfer, and storage in and to the United States.
Due to the nature of our Services, we typically act as a “Controller” as defined under the GDPR. If you believe that this role should be defined differently, please contact us at customerexperience@blackgirlsunscreen.com.
Pursuant to the GDPR, residents of Europe have the right to obtain our confirmation of whether we maintain personal information relating to them in the United States. If you are a resident of Europe, upon request from you, we will provide you with access to the Data that we hold about you. Please contact us if you have any questions.
Further, if you are a resident of the United Kingdom (“UK”), to the extent the GDPR as incorporated into UK law pursuant to s.3 of the European Union (Withdrawal Act) 2018 (as amended, the “UK GDPR”) is different than the GDPR, we will follow all supplemental requirements under the UK GDPR and you have all rights as a UK citizen under the UK GDPR.
B. Privacy for California Residents
California adopted the California Consumer Privacy Act (“CCPA”), which took effect at the beginning of 2020 and the California Privacy Rights Act (“CPRA”), which fully took effect January 1, 2023. We comply with the requirements of the CCPA and CPRA to the extent they apply to us.
If you are a California resident, you may request to exercise your rights for any Data we have processed in the 12 months prior to your request. Such request covers any categories, sources, purposes, and, if applicable, third parties to whom we share the Data. Further, you can exercise any of your rights free of discrimination, for example, we cannot increase the price of the Services or decrease the quality of the Services because you exercise your rights.
Due to the nature of our Services, we typically act as a “service provider”” as defined under the CCPA and CPRA. If you believe that this role should be defined differently, please contact us at customerexperience@blackgirlsunscreen.com or at our toll-free number: (833) 247-4968.
For more information, please direct your questions to us at customerexperience@blackgirlsunscreen.com or at our toll-free number: (833) 247-4968.
C. Privacy for Other Jurisdictions
We strive to comply with all data protection and privacy laws in applicable jurisdictions, to the extent such laws apply to us and our Services. We strive to be transparent about our data processing activities and have disclosed our practices throughout this Privacy Policy. If you have any questions about your rights under any applicable data protection and privacy laws, please contact us at customerexperience@blackgirlsunscreen.com or at our toll-free number: (833) 247-4968.
SECURITY
The security of your Data is important to us. We use commercially reasonable efforts to processyour Data in a secure environment. We take technical, contractual, administrative, and physical security steps designed to protect Data that you provide to us. We have implemented procedures designed to limit the dissemination of your Data to only such designated staff as are reasonably necessary to carry out the stated purposes we have communicated to you.
THIRD-PARTY POLICIES
You may be able to access third-party websites and other tools and services or products via a link, or via our other tools. The privacy policies of these third parties are not under our control and may differ from ours. The use of any Data that you may provide to any third parties will be governed by the privacy policy of such third party or by your independent agreement with such third party, as the case may be. If you have any doubts about the privacy of the information you are providing to a third party, we recommend that you contact that third party directly for more information or to review its privacy policy.
This Privacy Policy does not address, and we are not responsible for, the privacy, information or other practices of any third parties, including any third party operating any offering, site or other products and Services used in connection with the Services. The inclusion of a link does not imply endorsement of the linked site or service by us or by our affiliates.
DATA RETENTION
We will process your Data for as long as it remains necessary for the identified purpose or as required by law, which may extend beyond the termination of our relationship with you. We may retain certain data as necessary to prevent fraud or future abuse, or for legitimate business purposes, such as analysis of Anonymized Data, account recovery, or if required by law. All retained Data will remain subject to the terms of this Privacy Policy. Please note that if you request that your Data be removed from our databases, it may not be possible to completely delete all of your Data due to technological and legal constraints.
AMENDMENT OF THIS PRIVACY POLICY
We reserve the right to change this Privacy Policy at any time. If we decide to change this Privacy Policy in the future, we will post or provide appropriate notice. Any change to this Privacy Policy will become effective on the date posted at the top of this Privacy Policy. Unless stated otherwise, our current Privacy Policy applies to all Data that we process about you and your account. We recommend that you print a copy of this Privacy Policy for your reference and revisit this policy from time to time to ensure you are aware of any changes. Your continued use of the Services signifies your acceptance of any changes.
CONTACT US
You can help by keeping us informed of any changes such as a change of your personal contact information. If you would like to access your information, if you have any questions, comments or suggestions of if you find any errors in our information about you, please contact us at customerexperience@blackgirlsunscreen.com or at (833) 247-4968. If you have a complaint concerning our compliance with applicable privacy laws, we will investigate your complaint and if it is justified, we will take appropriate measures.