Privacy Policy
Effective Date: January 16, 2024.
- Introduction.
This Privacy Policy describes how Sarah J Maas (“Sarah Maas,” “we,” “our,” or “us”) collects, uses, and discloses information about you as well as your choices regarding such information. For purposes of this Privacy Policy, unless otherwise stated, “information” or “personal information” means information relating to an identified or identifiable individual, and does not include aggregate information or information that does not identify you.
This Privacy Policy applies to information we collect where we control the purposes and means of processing. Specifically, it applies to information we collect through any of our websites, emails, and other online services that link to this Privacy Policy (the “Service”). It does not apply to information collected by third parties or information collected in the context of your employment with us.
Please note that your use of the Service is subject to our Terms of Use.
Some regions provide additional rights by law, as described below:
- California
- Colorado, Connecticut, Utah, and Virginia
- Nevada
- European Economic Area, Switzerland, and United Kingdom
For our contact details, see the Contact Us section below.
2. How We Collect Information.
We collect information about you in a variety of contexts, as described below.
Information You Provide through the Service.
When you use the Service, you may be asked to provide information to us, such as when you make a purchase, sign up for our newsletters or loyalty programs, participate in a promotion, respond to our surveys, contact support, or apply for a job. The categories of information we collect include:
- Contact Identifiers, including your name, email address, postal address, and phone number.
- Characteristics or demographics, including your age and country.
- Commercial or transactions information, including records of products or services you purchased, obtained, or considered.
- Payment information, including your payment instrument number (such as a credit or debit card number), expiration date, and security code as necessary to process your payments. This information is processed by our payment processors.
Please do not provide any information that we do not request.
Information from Your Browser or Device.
When you use the Service, we and third parties we work with automatically collect information from your browser or device. The categories of information we automatically collect include:
- Device identifiers, including your device’s IP address.
- Device information, including your device’s operating software and browser (e.g., type, version, and configuration), internet service provider, and regional and language settings.
- Internet activity, including information about your browsing history and interactions, such as the features you use, pages you visit, content you view, purchases you make or consider, time of day you browse, and referring and exiting pages.
- Non-precise location data, such as location derived from an IP address or data that indicates a city or postal code level.
This information is automatically collected through cookies and other tracking technologies incorporated into our Service, as described below:
- Cookies. Cookies are browser-based text files which are dropped on your browser when you visit a website, open or click on an email, or interact with an advertisement. There are various types of cookies, including session cookies (which are cookies that expire when you close your browser) and persistent cookies (which are cookies that do not expire until a set expiration date or you manually delete them). Cookies may be first party (which are cookies served directly by us) or third party (which are cookies served by third parties we work with).
- Pixels. Pixels (also known as web beacons) are code embedded in a service. There are various types of pixels, including image pixels (which are one-pixel transparent images) and JavaScript pixels (which contain JavaScript code). Pixels are often used in conjunction with cookies. When you access a service that contains a pixel, the pixel may permit us or a third party to collect information from your browser or device, or to drop or read cookies on your browser.
We use these tracking technologies for a variety of purposes, including to help make our Service work, personalize your browsing experience, prevent fraud and assist with security, perform measurement and analytics, and provide advertising.
For details on your choices around cookies and other tracking technologies, see the Your Privacy Choices section below.
Information from Other Sources.
We also collect information from other sources. The categories of other sources from which we collect information include:
- Business partners that offer co-branded services, sell or distribute our products, or engage in joint marketing or promotional activities.
- Third party vendors and related parties we work with in connection with receiving analytics, advertising, security, and fraud prevention services.
- Social media platforms with which you interact. For example, when you engage with our content on social media (such as through our brand page or direct messages), we may collect information such as your contact identifiers and any comments you provide. We may also receive additional information from the social media platform that you have authorized the platform to disclose to us. If you publicly reference our Service on social media (such as by tagging us or using a hashtag associated with us in a post), we may use your reference on or in connection with our Service.
- Data providers, such as licensors of private and public databases.
- Public sources, such as information in the public domain.
Sensitive Information.
To the extent any of categories of information we collect are sensitive categories of information under applicable law, we process such information only for the limited purposes permitted by applicable law.
3. How We Use Information.
We collect and use information in accordance with the practices described in this Privacy Policy. Our purposes for collecting and using information include:
- Providing services. We use information to provide services to you, including to operate the Service and provide support.
- Personalizing your experience. We use information to personalize your experience and show you content we believe you will find interesting.
- Communications. We use information to communicate with you about updates, security alerts, changes to policies, and other transactional messages. We also use information to personalize and deliver marketing communications to you. Communications may be by email.
- Analytics and improvement. We use information to understand trends, usage, and activities, for example through surveys you respond to and tracking technologies that we incorporate into the Service, such as Google Analytics. We also use information for research and development purposes, including to improve our services and make business and marketing decisions. For more information regarding how Google uses information, please see https://policies.google.com/technologies/partner-sites.
- Advertising. We work with agencies, ad networks, technology providers, and other third parties to place ads about our products and services on other websites and services. For example, we place ads through Google and Facebook that you may view on their platforms as well as on other websites and services.
- Promotions. When you voluntarily enter a promotion, we use information as set out in the official rules that govern the promotion as well as for administrative purposes and as required by law. By entering a promotion, you agree to the official rules that govern that promotion, and that, except where prohibited by applicable law, we, the sponsor, and related entities may use your name, voice and/or likeness in advertising or marketing materials.
- Security and enforcement. We use information to prevent, detect, investigate, and address fraud, breach of policies or terms, or threats or harm.
- Recruitment. We use information to make decisions about recruiting and in anticipation of a contract of employment.
- At your direction or with your consent. We use information for additional purposes where you direct us to use it in a certain way or with notice to you and your consent.
Sometimes we aggregate or de-identify information so it is no longer considered personal information. We may use non-personal information for any purpose to the extent permitted by applicable law. For details on your choices around use of your information, see the Your Privacy Choices section below.
4. How We Disclose Information.
We disclose the information we collect in accordance with the practices described in this Privacy Policy. The categories of persons to whom we disclose information include:
- Service providers. Many of the third parties we work are service providers that collect and process information on our behalf. Service providers perform services for us such as payment processing, data analytics, marketing and advertising, website hosting, and technical support. To the extent required by law, we contractually prohibit our service providers from processing information they collect on our behalf for purposes other than performing services for us, although we may permit them to use non-personal information for any purpose to the extent permitted by applicable law.
- Business partners. We disclose information to our business partners in connection with offering co-branded services, selling or distributing our products, or engaging in joint marketing or promotional activities.
- Affiliates. We disclose information to our affiliates and related entities, including where they act as our service providers subject to this Privacy Policy or use the information in accordance with their own privacy policies.
- Recipients in a merger or acquisition. We disclose information in connection with, or during negotiations of, any proposed or actual merger, purchase, sale or any other type of acquisition or business combination of all or any portion of our assets, or transfer of all or a portion of our business to another business.
- Recipients for security and enforcement. We disclose information to comply with the law or other legal process, and where required, in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We also disclose information to protect the rights, property, life, health, security and safety of us, the Service or anyone else.
- Recipients at your direction or with your consent. We disclose information where you direct us to or with notice to you and your consent.
Sometimes we aggregate or de-identify information so it is no longer considered personal information. We may disclose non-personal information for any purpose to the extent permitted by applicable law. For details on your choices around disclosure of your information, see the Your Privacy Choices section below.
5. Third Parties.
Our Service may link to, or be incorporated into, websites and online services controlled by third parties. In addition, we may integrate technologies into our Service, including those disclosed in the How We Collect Information section above, controlled by third parties. Except where third parties act as our service providers, they, and not us, control the purposes and means of processing any information they collect from you, and you should contact them directly to address any concerns you have about their processing. Third party data practices are subject to their own policies and disclosures, including what information they collect, your choices, and whether they store information in the U.S. or elsewhere. We encourage you to familiarize yourself with and consult their privacy policies and terms of use.
6. Your Privacy Choices.
We provide a variety of ways for you to exercise choice, as described below.
Region-Specific Rights.
Some regions provide additional rights by law. This subsection details how to exercise certain of those rights to the extent they apply to you. See your region-specific terms for further details.
- Data subject requests. Depending on your region, you may have the right to access, correct, delete, or exercise similar rights with respect to your information. To exercise your rights, please submit a data subject request by emailing us at privacy@sarahjmaas.com We will confirm receipt of and respond to your request consistent with applicable law. Please note these rights require verification and are subject to exceptions. To verify your identity, we may contact the email address that matches our records, and wait for your response. In some instances, we may ask for additional information. If we are unable to verify your identity, we may deny your request.
- Authorized agent. Depending on your region, you may have the right to designate an authorized agent to exercise rights on your behalf. Except for requests made by opt-out preference signal, we will require written and signed proof of the agent’s permission to do so and may verify your identity directly with you. To the extent permitted by applicable law, rights must be exercised through the designated methods listed above.
- Appeals. Depending on your region, you may have the right to appeal our decision if we deny your request. To appeal, please contact us at the email address set out in the Contact Us section below and specify what you wish to appeal. We will review and respond to your appeal in accordance with applicable law. If we deny your appeal, you may submit a complaint to your relevant regulatory authority through the links specified in your region-specific terms.
Emails. You can opt out of emails by emailing us at as set out in the Contact Us section below with the word UNSUBSCRIBE in the subject field of the email. Please note that you cannot opt out of transactional messages.
Browser and Device Controls.
- Cookies and pixels. You may be able to manage cookies through your browser settings. When you manage cookies, pixels associated with such cookies may also be impacted. Please note that cookie management only applies to our website. If you use multiple browsers, you will need to instruct each browser separately. If you delete or reset your cookies, you will need to reconfigure your settings. Your ability to limit cookies is subject to your browser settings and limitations.
- Preference signals. Your browser or extension may allow you to automatically transmit Do Not Track and other preference signals. Except as required by law, we do not respond to preference signals.
- Third party opt-out tools. Some third parties we work with offer their own opt-out tools related to information collected through cookies and pixels. To opt out of your information being used by Google Analytics, please visit https://tools.google.com/dlpage/gaoptout. We are not responsible for the effectiveness of any third party opt-out tools.
7. Children.
The Service is not directed toward children under 13 years old, and we do not knowingly collect personal information (as that term is defined by the U.S. Children’s Privacy Protection Act, or “COPPA”) from children. If you are a parent or guardian and believe we have collected personal information from children, please contact us as set out in the Contact Us section below. We will delete the personal information in accordance with COPPA.
8. Data Security.
We implement and maintain reasonable administrative, physical, and technical security safeguards to help protect information about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. Nevertheless, transmission via the internet is not completely secure and we cannot guarantee the security of information about you.
9. Retention.
We retain information for the length of time that is reasonably necessary for the purpose for which it was collected, and as necessary to comply with our legal obligations, resolve disputes, prevent fraud, and enforce our agreements.
10. International Transfer.
We are based in the U.S. If you are located outside the U.S., please be aware that your information may be transferred to and processed in the U.S. or another country where we operate.
11. Changes to this Privacy Policy.
We reserve the right to revise and reissue this Privacy Policy at any time. Any changes will be effective immediately upon posting of the revised Privacy Policy. Your continued use of our Service indicates your consent to the Privacy Policy then posted. If the changes are material, we may provide additional notice to you, such as through email or prominent notice on the Service.
12. Contact Us.
If you have any questions about or trouble accessing this Privacy Policy, please contact us:
By email: privacy@sarahjmaas.com
By mail: Sarah J. Maas 120 Broadway Fl. 22 New York, New York 10271
To exercise choice, use the methods described in the Your Privacy Choices section above or your region-specific terms below.
13. California.
These additional rights and disclosures apply only to California residents. Terms have the meaning ascribed to them in the California Privacy Rights Act (“CPRA”), unless otherwise stated.
Notice at Collection.
At or before the time of collection of your personal information, you have a right to receive notice of our data practices. Our data practices are as follows:
- For the categories of personal information we have collected in the past 12 month, see the How We Collect Information section above.
- For the categories of sources from which personal information is collected, see the How We Collect Information section above.
- For the specific business and commercial purposes for collecting and using personal information, see the How We Use Information section above.
- For the categories of third parties to whom information is disclosed, see the How We Disclose Information section above.
- For the criteria used to determine the period of time information will be retained, see the Retention section above.
We do not “sell” or “share” your personal information as those terms as defined by the CPRA. We do not knowingly sell or share the personal information of minors under 16 years old who are California residents.
Some of the personal information we collect may be considered sensitive personal information under the CPRA. For example, payment information. We collect, use, and disclose such sensitive personal information only for the permissible business purposes for sensitive personal information under the CPRA or without the purpose of inferring characteristics about consumers. We do not sell or share sensitive personal information.
Right to Know, Correct, and Delete.
You have the following rights under the CPRA:
- The right to know what personal information we have collected about you, including the categories of personal information, the categories of sources from which personal information was collected, the business or commercial purposes for collecting, selling, or sharing personal information, the categories of personal information that we sold, shared, or disclosed for a business purpose, the categories of third parties to whom we disclosed personal information, and the specific pieces of personal information we have collected about you.
- The right to correct inaccurate personal information that we maintain about you.
- The right to delete personal information we have collected from you.
For details on exercising these rights, see the “Data subject requests” subsection of the Your Privacy Choices section above.
Right to an Authorized Agent.
You have the right to designate an authorized agent to exercise your rights. For details on exercising this right, see the “Authorized agent” subsection of the Your Privacy Choices section above.
Right to Non-Discrimination.
You have the right not to receive discriminatory treatment by us for the exercise of any your rights.
Shine the Light.
Under California’s Shine the Light law, customers who are residents of California may request (i) a list of the categories of personal information disclosed by us to third parties during the immediately preceding calendar year for those third parties’ own direct marketing purposes; and (ii) a list of the categories of third parties to whom we disclosed such information. To make a request, please write us at the email or postal address set out in the Contact Us section above and specify that you are making a “California Shine the Light Request.” We may require additional information from you to allow us to verify your identity and are only required to respond to requests once during any calendar year.
14. Colorado, Connecticut, Utah, and Virginia.
These additional rights and disclosures apply only to residents of Colorado, Connecticut, Utah, and Virginia. Terms have the meaning ascribed to them in the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), the Utah Consumer Privacy Act (“UCPA”), and the Virginia Consumer Data Protection Act (“VCDPA”), as applicable.
Data Subject Requests.
You have the following rights under applicable law:
- To confirm whether or not we are processing your personal data
- To access your personal data
- To correct inaccuracies in your personal data
- To delete your personal data
- To obtain a copy of your personal data that you previously provided to us in a portable and readily usable format
For details on exercising these rights, see the “Data subject requests” subsection of the Your Privacy Choices section above.
Profiling.
We do not process personal data for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects concerning consumers.
Right to an Authorized Agent.
You have the right to designate an authorized agent to exercise your rights. For details on exercising this right, see the “Authorized agent” subsection of the Your Privacy Choices section above.
Right to Non-Discrimination.
You have the right not to receive discriminatory treatment by us for the exercise of any your rights.
Right to an Appeal.
You have the right to appeal our decision in response to your request. For details on exercising this right, see the “Appeals” subsection of the Your Privacy Choices section above. If your appeal is denied, you may submit a complaint as follows:
- For Colorado residents, to the Colorado AG at https://coag.gov/file-complaint/
- For Connecticut residents, to the Connecticut AG at https://www.dir.ct.gov/ag/complaint/
- For Utah residents, to the AG at https://attorneygeneral.utah.gov/contact/complaint-form/
- For Virginia residents, to the AG at https://www.oag.state.va.us/consumercomplaintform
15. Nevada.
If you are a Nevada consumer, you have the right to direct us not to sell certain information that we have collected or will collect about you. To exercise this right, please follow the instructions for submitting a data subject request in the Your Privacy Choices section above.
16. European Economic Area, Switzerland, and United Kingdom
These additional disclosures and rights apply only to individuals located in the European Economic Area, Switzerland, or the United Kingdom (“Europe”). Terms have the meaning ascribed to them in the General Data Protection Regulation or the UK Data Protection Act (“GDPR”).
Roles.
Sarah Maas acts as a controller with respect to personal data collected as you interact with our Service.
Lawful Basis for Processing.
Data protection laws in Europe require a “lawful basis” for processing personal data. Our lawful bases include where: (a) you have given consent to the processing for one or more specific purposes, either to us or to our service providers, partners; (b) processing is necessary for the performance of a contract with you; (c) processing is necessary for compliance with a legal obligation; or (d) processing is necessary for the purposes of the legitimate interests pursued by us or a third party, and your interests and fundamental rights and freedoms do not override those interests. Where applicable, we will transfer your personal data to third countries subject to appropriate or suitable safeguards, such as standard contractual clauses.
Data Subject Requests.
You have the right to access, rectify, or erase any personal data we have collected about you. You also have the right to data portability and the right to restrict or object to our processing of personal data we have collected about you. In addition, you have the right to ask us not to process your personal data (or provide it to third parties to process) for marketing purposes or purposes materially different than for which it was originally collected or subsequently authorized by you. You may withdraw your consent at any time for any data processing we do based on consent you have provided to us.
For details on exercising these rights, see the “Data subject requests” subsection of the Your Privacy Choices section above.
For details on our retention practices for personal data, see the Retention section above.
You have the right to lodge a complaint with the data protection regulator in your jurisdiction.
Want to be the first to know about goings on in the world of Sarah J. Maas? Subscribe to the newsletter for news, musings, and bonus content.
By signing up, you agree we can send you email updates and you agree to our Privacy Policy