Revision Date: August 2024
Privacy Notice and Policy
Overview
Rustan Commercial Corporation (“Rustan’s"), as the premier upscale and luxury retail destination in the Philippines, takes great pride in safeguarding your personal data you have entrusted us with.
This Privacy Policy and Notice (“Policy”) explains how Rustan’s will use the personal data that you provided us when you purchase or avail of Rustan’s products or services, when you communicate with us through our official communication channels, social media accounts, and when you visit or transact on our websites. Rustan’s collection, use, and retention of your personal data are compliant with Philippine Data Privacy Act (“DPA”), National Privacy Commission (“NPC”) issuances, and other relevant data privacy and protection laws and standards.
The displayed Seal of Registration hereon was issued by the NPC indicating Rustan’s registration as a personal information controller, and of its data protection officer and data processing systems.
Revision Date: August 2024
Overview
Rustan Commercial Corporation (“Rustan’s"), as the premier upscale and luxury retail destination in the Philippines, takes great pride in safeguarding your personal data you have entrusted us with.
This Privacy Policy and Notice (“Policy”) explains how Rustan’s will use the personal data that you provided us when you purchase or avail of Rustan’s products or services, when you communicate with us through our official communication channels, social media accounts, and when you visit or transact on our websites. Rustan’s collection, use, and retention of your personal data are compliant with Philippine Data Privacy Act (“DPA”), National Privacy Commission (“NPC”) issuances, and other relevant data privacy and protection laws and standards.
The displayed Seal of Registration hereon was issued by the NPC indicating Rustan’s registration as a personal information controller, and of its data protection officer and data processing systems.
I. How Rustan's collects your personal data
Based on your consent, Rustan’s legitimate interests, or other lawful grounds for processing of personal data, Rustan’s collects, uses, or processes your personal data when you:
-
- Visit, sign-up, transact, and/or communicate to us through Rustans.com, Rustan’s The Beauty Source, and Adora.PH (the “Rustan’s Sites”);
- Purchase or avail of any of our products or services, or avail of or join promotions at Rustan or Adora Department Stores, and other retail outlets (collectively referred as “Rustan’s Stores”) or participate in Rustan’s events or promotions;
- Visit, consult, and avail skin or body care treatment at Rustan’s Stores spas;
- Apply and sign-up as a member of Frequent Shoppers Program, Beauty Addict Loyalty Program, L’Occitane VIP Rewards Program, Adora Rewards Program, and other special membership programs (collectively referred as “Customer Membership Programs”) through Rustan’s Stores, Rustans’s Sites, or web or mobile application channels (collectively referred as “Member Sites”), or when you use and update your profile therein;
- Communicate with us through our official social media accounts and instant messaging applications regarding products or services; and
- Communicate with our Store’s Staff, Customer Service Officers, and Personal Shoppers regarding your product/service inquiries, confirmation of orders and payment, or delivery/pick-up of your orders by calling Rustan’s telephone lines, email, and/or contacting them through their official work phones or instant messaging applications.
- Visit, sign-up, transact, and/or communicate to us through Rustans.com, Rustan’s The Beauty Source, and Adora.PH (the “Rustan’s Sites”);
II. What personal data Rustan's collects
Depending on the mode of personal data collection, the personal data we collect may include your:
-
- Name.
- Billing and shipping (office/residential) addresses.
- Email address.
- Telephone number.
- Mobile number.
- Age, birthdate, marital status and or other government identification numbers, if required.
- Face and skin information and history necessary assessment and application of treatments or beauty products.
- Foot traffic via the closed-circuit television for security monitoring when you visit any of Rustan’s Stores and offices, and any photographs taken when you participate in events (within or outside store premises) hosted by Rustan’s.
- Payment information, which will be processed by our payment gateway providers.
- Location and activity information that may be transmitted from your device (smartphones or computer) or other location-aware devices when you visit or use the Sites, such as but not limited to, browser type, webpage you were visiting, device used, the pages within the Sites you visited, the time you spent on those pages, items, and information searched for on our Sites, access times and dates, and other statistics.
- Your actions on the Sites through our third parties’ cookies to create segmentation, analytics, statistics, conversion tracking, and display marketing.
- Consumer Feedback and information that you voluntarily share with Rustan’s about your experience of using our products and services.
- Any personally identifiable information, which you have provided us in any form you may have submitted to us in relation to the transaction or services you have made on Sites, Member Sites, or at Rustan’s Stores including pieces of personal data about your fiancé, spouse, children, relatives, or friends in our gift registry services or other in-store services, which by voluntarily providing their personal data to us you warrant that you have obtained their consent.
- Name.
III. Collection of computer data
Rustan's or our authorized service providers may use cookies, web beacons, and other similar technologies for storing information to help provide you with a better, faster, safer, and personalized experience when you use the services and/or access the platform.
When you visit our Sites, our company servers will automatically record information that your browser sends whenever you visit a website. This data may include:
-
-
Browser type
- Webpage you were visiting before you came to our site
- Device used
- The pages within Sites you visit
- The time spent on those pages, items, and information searched for on our Sites, access times and dates, and other statistics
-
Browser type
This data will not be used in association with any other personal information.
Please note that we do not alter our Site's data collection and use practices when we see a Do Not Track signal from your browser.
IV. How Rustan's uses your personal data
The personal data we collect from you will be used in some or all the following ways:
-
- To process your orders and to provide you with services and information offered through our Rustan’s Sites or Rustan’s Stores.
- To deliver the products you have purchased from the Rustan’s Sites and Rustan’s Stores.
- To update you on the delivery of the product and for customer support and services purposes.
- To provide you with relevant product or service information and promotions via email or SMS, if so allowed, or when you contact us in our official social media accounts or in our Rustan’s Sites.
- To manage or administer your account(s) with us, or our relationship with you, such as but not limited to: notifying you about changes to our terms and conditions, services, response to your comments, complaints, and other feedback on our services.
- To carry out earning and redemption of loyalty points, where appropriate.
- To verify and carry out secure financial transactions in relation to payments you make online.
- To audit the downloading of data from our website.
- To improve the layout and/or content of the pages of our website and customize them for users.
- To study visitors on our website.
- To carry out market research, and product and service development and improvement based on our users' demographics using Rustan’s analytics tools. You can unsubscribe from marketing information at any time by using the unsubscribe function.
- To manage customer loyalty programs, inventory, sales performance, and website performance.
- For compliance, audit, legal, and security purposes, such as but not limited to use of CCTV systems and card payment fraud detection and prevention systems.
- To process your orders and to provide you with services and information offered through our Rustan’s Sites or Rustan’s Stores.
Rustan’s also collects personal data of our employees and job applicants. The personal data of job applicants is collected through Rustan’s official forms, authorized email accounts, and job sites, and are being used in accordance with employment application processes. While the pieces of personal data of Rustan’s employees are collected and used based on their consent and compliance with labor laws and regulations and other applicable laws.
Rustan’s may collect the personal data of the minors in relation to the purchase of necessaries (e.g., clothing, etc). Consent of the minor’s parent or legal guardian may be required depending on the type of purchase of goods or services availed of and the categories of personal data involved unless the consent was warranted by the minor with sufficient proof.
V. How Rustan's proceses your personal data
Rustan’s process your personal data following the principles of legitimate purpose, proportionality, and transparency. Rustan’s consent forms (physical and electronic forms) are evidence of your voluntary decision to consent to Rustan’s collection, use, and processing of your personal data. Rustan’s may also process your personal information without your consent provided that such is within the scope of its legitimate interests. To communicate such, a privacy notice clause is available in the relevant Rustan’s forms and documents and this document.
The other grounds for Rustan’s to process your personal data are: for compliance with contractual obligations when you are a party such contract with Rustan’s; for compliance with Rustan’s legal obligation or when such is prescribed by existing laws and regulations; when it is necessary to protect your vitally important interests including your life and health; when it is necessary for Rustan’s to respond to national emergency or to comply with the requirements of public order and safety; when Rustan’s processing is necessary for the fulfillment of the mandates of a public authority e.g., law enforcers, courts; and other government agencies, or protection of lawful rights and interests.
Rustan’s implements reasonable and appropriate organizational, physical, and technical security measures to protect the privacy of your personal data. Only Rustan’s authorized employees and third-party service providers, who satisfy our data privacy and protection requirements, can process your data.
VI. Access and updating your Rustan's accounts
You may access your personal data by logging into your account on Rustans.com or Adora.PH. Here you can view the details of your orders that have been completed, those which are open, and those which are shortly to be dispatched, and administer your address details, bank details, and any newsletter to which you may have subscribed.
For Member Sites, you may access member information, points, and transactions, by logging into your account and entering your credentials. Do not share your Beauty Addict or Frequent Shopper’s card number and personal identification number. You are responsible for the confidentiality and integrity of your access credentials. We cannot assume any liability for loss or misuse of passwords. Please report immediately to our authorized representatives your lost or compromised credentials.
Some of your personal data may be updated and corrected by logging in to your account on the Rustan’s Sites and Member Sites. Should you experience difficulties, you may request to correct such information by talking to one of our Customer Service personnel.
VII. How Rustan's discloses your data
There are a variety of circumstances, depending on the services you have availed of, where Rustan’s may need to share or disclose your data to business partners or third-party service providers that you have provided to us. In these cases, our business partners or third-party service providers are contractually bound to securely use your personal data in accordance with the data processing or sharing agreements with them, and all laws and regulations applicable to their operations.
With your consent, your personal data may be shared with other members of Rustan’s Group of Companies for the use of your Rustan's loyalty customer account in other member-companies, and with other accredited partners and third parties, acting on our behalf, for necessary services.
In exceptional circumstances, Rustan's may be required to disclose personal data, such as when there are grounds to believe that the disclosure is necessary and with lawful grounds.
VIII. Your data privacy rights
Under the DPA, you have the following rights:
-
- Right to be informed. Rustan’s will inform you about how your personal data is being processed or have been processed, including the existence of automated decision making and profiling systems. At the very least, Section III summarizes how Rustan’s process your personal data.
- Right to object. You may suspend, withdraw, and remove your personal data in certain further processing (e.g., direct marketing, analytics, survey, etc), upon demand, which include your right to opt-out to any communication from Rustan’s.
- Right to access. Upon written request, you may access information on the processing of your personal data which may include the following, contents and categories of personal data, the manner of processing, sources where they were obtained, recipients and reason of disclosure, if applicable.
- Right to rectification (dispute and/or correct). Upon written request, may dispute inaccuracy or error in your personal data and have Rustan’s to correct the same.
- Right to data erasure. Upon written request and based on reasonable grounds, you have the right to suspend, withdraw or order blocking, removal or destruction of your personal data from the Rustan’s filing system, without prejudice to the Rustan’s continuous processing for commercial, operational, legal, and compliance purposes.
- Right to data portability. You have the right to obtain from Rustan’s your personal data in an electronic or structured format that is commonly used and allows for further use.
- Right to be indemnified for damages. As data subject, you have every right to be indemnified for any damages sustained due to such violation of your right to privacy through inaccurate, false, unlawfully obtained or unauthorized use of your personal data.
- Right to file a complaint. You may file your complaint or any concerns with our Data Protection Officer and/or with the National Privacy Commission through www.privacy.gov.ph.
- Transmissibility of rights. Rustan’s can accommodate the processing of personal data on-behalf of an incapacitated or deceased data subject provided that there is a legal notice such as Special Power of Attorney or any evidence to back any claims.
- Right to be informed. Rustan’s will inform you about how your personal data is being processed or have been processed, including the existence of automated decision making and profiling systems. At the very least, Section III summarizes how Rustan’s process your personal data.
In exercising your data privacy rights, you may email Rustan’s Data Protection Officer at dpo@rustans.com.
Please make sure to include your name, username, and other details and supported with appropriate identification documents, if a lawful representative or heir is requesting on behalf of the data subject.
Rustan's reserves the right to refuse unreasonable requests. A request shall be complied with without undue delay, provided, that the period will not exceed thirty (30) working days after receipt of the request and/or the necessary supporting or additional documentation: provided further, that if a request is complex or numerous, compliance with such request may be extended, with notice to the data subject, for a period not exceeding another fifteen (15) working days.
IX. Data risk and security
Rustan’s strictly enforces data privacy and information security policies. It implements technical, organizational and physical security measures to protect your personal data against loss, misuse, modification, unauthorized or accidental access or disclosure, alteration or destruction.
However, this does not guarantee absolute protection against certain risks involving the processing of personal data, such as when systems are exposed to targeted cyberattacks, malware, ransomware, and computer viruses or when manual records are accessed without authority. To ensure appropriate security incident management in line with existing NPC policies, circulars, and other issuances, we put safeguards such as the following:
-
- Maintaining or engaging partners with technology products to prevent unauthorized computer access such as PCI Level 1 security compliance and ISO certification;
- Securely destroying your personal information when it is no longer needed for record retention purposes; and
- Using physical, technical, and organizational procedures and security features to protect your information.
- Limiting access to your personal data among our employees and agents on a need-to-know basis and subject to strict contractual confidentiality obligations when processed by third-parties.
- Maintaining or engaging partners with technology products to prevent unauthorized computer access such as PCI Level 1 security compliance and ISO certification;
Note, however, that Rustan's cannot guarantee the security of the internet or telecommunications network used to access the Site.
X. Data retention and disposal
Rustan’s keep your data as long as it is necessary: a) for the fulfillment of the declared, specified, and legitimate purposes, or when the processing relevant to the purposes has been terminated; b) for the establishment, exercise or defense of legal claims; or c) for legitimate business purposes, which shall be in accordance with the standards of the NPC.
Financial data and documents which indicate taxable transactions, data shall be preserved for ten (10) years per BIR regulation.
Pursuant to Section I until the termination of your account to Rustans, the retention period of five (5) years from the date of termination of your account or your last transaction, relationship, or communication with Rustans. All other transactions and accounts that are defined here in, the retention period of five (5) years from the date of from the termination of your account or your last transaction, relationship, or communication, except where specific laws and/or regulations require a different retention period, in which case, the longer retention period is observed.
XI. Contact our Data Protection Officer
For inquiries and concerns, you may address them to Rustan’s Data Protection Officer through email at dpo@rustans.com.
Emails and letters should clearly state that you are making a data protection query, request, or complaint in the subject line to ensure the matter is dealt with urgency. We will strive to deal with any query, request, or complaint promptly and fairly.
XII. Changes to the Privacy Policy
Rustan's reserves the right to modify and change the Policy. Any changes to this policy will be published on our Site.
By clicking "Agreed" on our Cookie and Policy pop-up; ticking any web form referring to the current Policy on any of our online platforms; submitting your personal data to us such as in signing up for an account on the Sites or in making requests, or ordering any of our products and services; or when you provide your personal information by filling-out In-store forms, you are agreeing to the terms of the Policy.
You are encouraged to visit the Sites from time to time to ensure that you are well-informed of our latest data protection and privacy policies.
This Policy and your use of this Site shall be governed in all respects by the laws of the Philippines.