The Costume Rag ("The Costume Rag") operates Thecostumerag.com and may operate other websites. It is The Costume Rag's policy to respect your privacy regarding any information we may collect while operating our websites.
Like most website operators, The Costume Rag collects non-personally-identifying information of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request. The Costume Rag's purpose in collecting non-personally identifying information is to better understand how The Costume Rag's visitors use its website. From time to time, The Costume Rag may release non-personally-identifying information in the aggregate, e.g., by publishing a report on trends in the usage of its website.
The Costume Rag also collects potentially personally-identifying information like Internet Protocol (IP) addresses for logged in users and for users leaving comments on Thecostumerag.com blogs/sites. The Costume Rag only discloses logged in user and commenter IP addresses under the same circumstances that it uses and discloses personally-identifying information as described below, except that commenter IP addresses and email addresses are visible and disclosed to the administrators of the blog/site where the comment was left.
Gathering of Personally-Identifying Information
Certain visitors to The Costume Rag's websites choose to interact with The Costume Rag in ways that require The Costume Rag to gather personally-identifying information. The amount and type of information that The Costume Rag gathers depends on the nature of the interaction. For example, we ask visitors who sign up at Thecostumerag.com to provide a username and email address. Those who engage in transactions with The Costume Rag are asked to provide additional information, including as necessary the personal and financial information required to process those transactions. In each case, The Costume Rag collects such information only insofar as is necessary or appropriate to fulfill the purpose of the visitor's interaction with The Costume Rag. The Costume Rag does not disclose personally-identifying information other than as described below. And visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent them from engaging in certain website-related activities.
The Costume Rag may collect statistics about the behavior of visitors to its websites. The Costume Rag may display this information publicly or provide it to others. However, The Costume Rag does not disclose personally-identifying information other than as described below.
Protection of Certain Personally-Identifying Information
The Costume Rag discloses potentially personally-identifying and personally-identifying information only to those of its employees, contractors and affiliated organizations that (i) need to know that information in order to process it on The Costume Rag's behalf or to provide services available at The Costume Rag's websites, and (ii) that have agreed not to disclose it to others. Some of those employees, contractors and affiliated organizations may be located outside of your home country; by using The Costume Rag's websites, you consent to the transfer of such information to them. The Costume Rag will not rent or sell potentially personally-identifying and personally-identifying information to anyone. Other than to its employees, contractors and affiliated organizations, as described above, The Costume Rag discloses potentially personally-identifying and personally-identifying information only in response to a subpoena, court order or other governmental request, or when The Costume Rag believes in good faith that disclosure is reasonably necessary to protect the property or rights of The Costume Rag, third parties or the public at large. If you are a registered user of an The Costume Rag website and have supplied your email address, The Costume Rag may occasionally send you an email to tell you about new features, solicit your feedback, or just keep you up to date with what's going on with The Costume Rag and our products. If you send us a request (for example via email or via one of our feedback mechanisms), we reserve the right to publish it in order to help us clarify or respond to your request or to help us support other users. The Costume Rag takes all measures reasonably necessary to protect against the unauthorized access, use, alteration or destruction of potentially personally-identifying and personally-identifying information.
If The Costume Rag, or substantially all of its assets, were acquired, or in the unlikely event that The Costume Rag goes out of business or enters bankruptcy, user information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, and that any acquirer of The Costume Rag may continue to use your personal information as set forth in this policy.
Our legal basis for using your personal data
Our use of your personal data as outlined above is subject to different legal bases for processing, including where necessary for:
- the purposes of the performance of any contract we enter into with you or to take steps at your request prior to entering into a contract with you;
- our legitimate interests, for example in providing our services to an entity you work for, managing and monitoring our website operation, preventing fraud and for our business compliance purposes; and
- compliance with our legal and regulatory responsibilities.
If you do not agree to provide your personal data to us we may not be able to provide you with our services or process your application for employment. Where our use of your data is not necessary for one of the purposes outlined above we may use it in a particular way with your consent. Where we ask for your consent you are free to refuse our use of your personal data for those purposes and you may withdraw your consent at any time by contacting us using the details set out below. This shall not affect the lawfulness of any processing that was based on your consent before you withdrew it
Storage and transfer of your personal data
The personal information that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (EEA). It may also be processed by staff operating outside the EEA who work for us or one of our suppliers or in circumstances where you have requested us to provide a product or service with international considerations and/or parties related to your request are located overseas. Before we transfer your personal data outside the EEA we will take all steps reasonably necessary to ensure that any such transfer is made securely and that there is adequate protection in place in order to protect your personal data, as required by the Act and Chapter V of the GDPR. Please contact us if you wish to obtain more information regarding relevant safeguards. By submitting your personal information you agree to this transfer, storing or processing outside the EEA.
Retention of your personal data
We will retain your personal information for a minimum of six years and so long as is reasonably necessary for the purpose for which it was obtained and in accordance with our legal obligations and follow our data destruction policy and processes thereafter. Your personal data may be retained by use for more than six years for the purposes of satisfying any legal, accounting or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Your personal information is protected under data protection law and you have a number of rights (see below) which you can seek to exercise. Please contact us in writing or by email using the details shown under ‘Contact’ below if you wish to do so, or if you have any queries in relation to your rights. Please note these rights do not apply in all circumstances.
Right of access – subject to certain exceptions, you have the right of access to your personal data that we hold (commonly known as a “data subject access request”).
Right to rectify your personal information – if you discover that the information we hold about you is inaccurate or incomplete, you have the right to have this information rectified (i.e. corrected).
Right to be forgotten – you may ask us to delete information we hold about you in certain circumstances. This right is not absolute and it may not be possible for us to delete the information we hold about you, for example, if we have an ongoing contractual relationship or are required to retain information to comply with our legal obligations.
Right to restriction of processing – in some cases you may have the right to have the processing of your personal information restricted. For example, where you contest the accuracy of your personal information, its use may be restricted until the accuracy is verified.
Right to object to processing – you may object to the processing of your personal information (including profiling) when it is based upon our legitimate interests. You may also object to the processing of your personal information for the purposes of direct marketing and for the purposes of statistical analysis. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
Right to data portability – you have the right to receive, move, copy or transfer your personal information to another controller when we are processing your personal information based on consent or on a contract and the processing is carried out by automated means.
Right to withdraw consent – you have the right to withdraw your consent where we are relying on consent to process your personal data. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.