Privacy policy

YOM Beauty

Privacy Policy

Last updated: 12th June 2026

1.  Introduction

At YOM Beauty, we are committed to protecting your personal information and respecting your privacy.

This policy explains how we collect, use, disclose, and protect personal information when you visit our websites, create an account, purchase products, contact support, engage with marketing, or interact with us on social platforms. It applies globally, with region-specific rights and notices provided below.

To purchase our products or create an account, you must be old enough to enter into a binding contract in your country of residence. Our services are a general-audience service and are not directed to children. We do not knowingly collect personal information from children under 13, or the minimum age set by your local law (see Section 13).

2.  Who we are

YOM Beauty (“YOM”, “we”, “us”, “our”) provides beauty and personal care products through our websites and online channels.

YOM Beauty Ltd is the controller of your personal information. We are established in the United Kingdom and process personal data under the UK GDPR as our home regime. Because our website is open to, and our products are offered to, people outside the UK, we are also subject to the EU GDPR in respect of individuals in the EU and EEA, and to applicable state privacy laws in respect of residents of the United States. Section 12 explains how these regional rights apply.

  • Legal entity: YOM Beauty Ltd (company number 15912786), registered in England and Wales.
  • Registered office: 94-96 Seymour Place, London W1H 1NB, United Kingdom.

3.  Contact us

If you have questions, want to exercise your rights, or have a complaint, you can contact us using the details below.

  • Email: hello@yombeauty.com
  • Post: 94-96 Seymour Place, London W1H 1NB, United Kingdom
  • Data Protection Lead / Privacy Officer: Euverify Ltd. gdpr@euverify.com
  • EU / EEA representative (Article 27 GDPR): Because we offer products to individuals in the EU and EEA without an establishment there, we have appointed an EU representative. Euverify Ltd Ireland, company no. 781168, Unit 3D, North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P. gdpr@euverify.com (EU Representative)

If you make a complaint to us directly, we will acknowledge it and respond. You can reach us at hello@yombeauty.com or gdpr@euverify.com.

4.  Changes to this policy

We may update this policy from time to time. Changes will be posted here with a new “Last updated” date. For material changes, we may provide additional notice (e.g., email or on-site).

5.  Personal information we collect

  • Identity: name, title, date of birth (if provided).
  • Contact: email, phone, billing and shipping addresses.
  • Account: credentials, preferences, wishlist, purchase history.
  • Transaction: orders, pricing, discounts, returns, support tickets.
  • Payment: processed by our payment providers; we do not store full card numbers.
  • Technical: IP address, device IDs, browser/OS, language, time zone, cookie identifiers, referrers.
  • Usage: pages viewed, clicks, session duration, site interactions, error logs.
  • Marketing: subscription status, campaign engagement, ad interaction data.
  • User-generated content: reviews, ratings, photos, survey responses, messages to us.
  • Social / Third-party: if you connect or log in via third-party services, we receive basic profile info as permitted by those services.

Where your information comes from

  • Directly from you (checkout, account creation, support).
  • Automatically via cookies, pixels, SDKs, and server logs.
  • From service providers and partners (payments, analytics, advertising, fraud prevention, delivery).
  • From publicly available sources where lawful (e.g., social media handles you make public).

6.  How we use your personal information and legal bases

The table below summarises why we use your personal information and the legal bases we rely on. Where we rely on legitimate interests, we balance them against your rights and expectations.

Purpose

What this involves

Legal basis

Provide services

Process and deliver orders, manage accounts, and provide support.

Contract / performance; legitimate interests.

Personalise

Recommend products, tailor content and ads, and remember preferences.

Consent where required; legitimate interests elsewhere.

Marketing

Send newsletters, offers, and updates by email, SMS, or push. You can opt out anytime.

Consent, or our legitimate interest in marketing similar products to our existing customers (the PECR “soft opt-in”), with an opt-out in every message.

Improve and secure

Analytics, research, A/B testing, troubleshooting, fraud and abuse prevention, and service protection.

Legitimate interests; consent for certain analytics/advertising cookies where required.

Compliance

Tax, accounting, reporting, product safety and recalls, and responding to lawful requests.

Legal obligations; legitimate interests.

Promotions

Administer contests, surveys, and loyalty programmes.

Consent; contract.


7.  Cookies and similar technologies

We use:

  • Necessary cookies: for core functionality (checkout, security).
  • Performance / analytics cookies: to understand site usage.
  • Functional cookies: to remember preferences.
  • Advertising / retargeting: pixels and SDKs.

Manage preferences via our Cookie Banner/Settings and your browser/device controls. Region-specific consent is applied where required. See our Cookie Notice for details of specific cookies, providers, and lifespans.

To opt out of advertising and retargeting cookies, use our Cookie Settings or the industry opt-out tools at youronlinechoices.com (UK and EU) and optout.aboutads.info (US). Adjusting settings on one browser or device will not necessarily opt you out on others.

8.  Sharing your personal information

We share limited data with:

  • Payment processors: Shopify Payments, PayPal, Google Pay, ApplePay
  • E-commerce / hosting: Shopify,
  • Fulfilment / couriers: DPD, Royal Mail.
  • Analytics / personalisation: Google Analytics, Meta, TikTok, Klaviyo.
  • Customer support / communications: Klaviyo.
  • Marketing/advertising partners and social platforms (subject to consent/opt-out where required).
  • Professional advisers and authorities where legally required.
  • Corporate transactions: auditors and counterparties under appropriate safeguards if we undergo a merger, acquisition, or asset sale.

We require service providers to process personal information only on our instructions and to protect it appropriately.

9.  International data transfers

We operate globally and may transfer personal information to countries different from your own. Where required, we use appropriate safeguards, such as:

  • EU / EEA / UK: adequacy decisions (where applicable), Standard Contractual Clauses (SCCs) and UK IDTA/Addendum, and supplemental measures.
  • Other regions: contractual protections and security measures consistent with local law.

Details of transfer mechanisms are available on request.

10.  Security and data retention

Security

We implement technical and organisational measures appropriate to the risk, including encryption in transit, access controls, network segmentation, vulnerability management, and secure development practices. No method of transmission or storage is 100% secure.

Retention

We retain personal information only as long as necessary for the purposes described or as required by law:

  • Orders / transactions: typically 6 to 7 years for tax/accounting (varies by country).
  • Accounts: for the life of the account; if inactive, deletion or anonymisation after 24 months, unless legal requirements justify longer retention.
  • Marketing: until you unsubscribe or after 24 months of inactivity, then minimised or anonymised.
  • Logs / analytics: typically 12 to 24 months, unless needed for security or legal reasons.

11.  Your rights and choices

Your privacy rights depend on your location. Subject to applicable law, you may have the right to:

  • Access, correct, or delete your personal information.
  • Object to or restrict processing.
  • Data portability.
  • Withdraw consent, including for marketing and cookies, at any time.
  • Opt out of targeted advertising and certain profiling/automated decision-making.

How to exercise your rights

Use “My Account” settings, unsubscribe links, Cookie Settings, or contact us at hello@yombeauty.com. We may request verification of your identity and location to process your request. If you raise a complaint with us, we will acknowledge and respond to it.

12.  Region-specific notices

  • EU / EEA and UK: We process personal data under GDPR/UK GDPR legal bases listed above. You may lodge a complaint with your local supervisory authority (e.g., ICO in the UK or your EU DPA), though we ask that you contact us first so we can try to resolve the matter. If we rely on legitimate interests, we balance them against your rights and expectations. For ePrivacy/PECR, we obtain consent for non-essential cookies and certain electronic marketing.
  • United States: Depending on your state (e.g., California, Virginia, Colorado, Connecticut, Utah), you may have rights to know/access, correct, delete, and opt out of “sale,” “sharing,” or targeted advertising, and to limit use of sensitive personal information. We do not sell personal information for money, but we may engage in data “sharing” for cross-context behavioural advertising. Use the “Do Not Sell or Share My Personal Information” link and Cookie Settings to opt out. We also recognise and honour Global Privacy Control (GPC) browser signals as a valid opt-out of “sharing” and targeted advertising. Authorised agents may submit requests subject to verification.
  • Canada: We process your information under PIPEDA/provincial laws. You may access and correct your data and withdraw consent subject to legal/contractual restrictions.
  • Australia / New Zealand: We handle personal information under the Privacy Act 1988 (Cth)/APPs and NZ Privacy Act. You may access and correct your information and complain to the OAIC/NZ Privacy Commissioner.
  • Other regions: We honour rights available under local laws. Contact us for region-specific details.

13.  Children

Our services are a general-audience service and are not directed to children under 13, or the minimum age required in your jurisdiction. We do not knowingly collect data from children. If you believe a child provided data, contact us to delete it.

14.  Automated decision-making

We may use automated tools for fraud detection and risk scoring. Where such decisions have legal or similarly significant effects, you may request human review and contest the decision, where provided by law.

15.  Third-party links and services

Our websites may link to third-party sites or integrate third-party services (including social media widgets). Those services have their own privacy practices.