Skip to content

20% OFF SITEWIDE with code: SPRING20

Privacy Policy


Privacy Policy

Hollywood Glow Girl Enterprises, Inc. d/b/a Angela Caglia Skincare

Last Updated and Effective: March 19, 2026

1. Introduction and Scope

This Privacy Policy describes how Hollywood Glow Girl Enterprises, Inc. d/b/a Angela Caglia Skincare ("Angela Caglia Skincare," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit www.angelacaglia.com (the "Site"), make a purchase, or interact with our marketing programs.

This Policy applies to all users of our Site, regardless of location. We have structured this Policy to address the specific rights available to residents of California, Virginia, Colorado, Connecticut, Texas, Florida, Oregon, and other US states with active privacy legislation. If you are a resident of one of those states, please see Section 9 for your specific rights.

By using our Site, you acknowledge this Privacy Policy. Please also review our Terms of Service, which governs your use of the Site and is incorporated herein by reference.

2. Information We Collect

2.1 Information You Provide Directly

  • Contact and account information: name, email address, phone number, shipping and billing address
  • Purchase information: products ordered, payment method type (we do not store full card numbers), transaction history
  • Communications: customer service inquiries, product reviews, and User Content you submit
  • Marketing preferences: email and SMS opt-in choices and timestamps; direct mail suppression requests

2.2 Information Collected Automatically

When you visit our Site, our service providers and we automatically collect certain technical information, subject to your cookie consent choices:

  • Device and browser information: IP address, browser type and version, operating system, device identifiers
  • Usage data: pages viewed, search queries entered on the Site, time spent, referring URLs, clickstream data
  • Location data: general geographic location derived from IP address
  • Cookie and tracking data: as described in Section 4

2.3 Information from Third Parties

  • Ad platforms (Meta, Google, Pinterest, TikTok): may provide us with matched audience data or conversion event data when you interact with our ads
  • Rebuyengine: behavioral data used for personalization and product recommendations on our Site
  • Klaviyo: email engagement data (opens, clicks) linked to your profile
  • PostPilot: SiteMatch browsing behavior data (when cookies accepted) and mailing address data for direct mail campaigns
  • Conversions API (CAPI): server-side event data shared with Meta and other ad platforms to improve ad measurement accuracy

3. How We Use Your Information

Fulfillment and Customer Service

  • Processing and fulfilling your orders
  • Communicating about your purchases, returns, and warranty claims
  • Providing customer support

Marketing and Advertising

  • Sending email marketing via Klaviyo (where you have opted in or as permitted by applicable law)
  • Sending SMS/MMS marketing messages via Postscript (where you have opted in)
  • Sending direct mail via PostPilot — both SiteMatch anonymous retargeting (cookie-consent gated) and campaigns to existing customers (see Section 5.4)
  • Serving targeted and retargeted advertising on Meta (Facebook/Instagram), Google, Pinterest, and TikTok
  • Using Conversions API (CAPI) to send server-side conversion events to ad platforms for measurement and optimization
  • Building lookalike audiences on ad platforms using hashed customer data

Site Improvement and Analytics

  • Analyzing Site traffic and usage patterns through Google Analytics
  • Personalizing your Site experience through Rebuyengine
  • Testing and improving our products, services, and marketing effectiveness

Legal and Compliance

  • Complying with applicable laws and regulations
  • Enforcing our Terms of Service
  • Protecting against fraud, security threats, and misuse of our Site

4. Cookies and Tracking Technologies

4.1 How We Use Cookies

We use cookies, pixel tags, web beacons, and similar technologies to operate and improve our Site and to serve relevant advertising. These technologies fall into the following categories:

  • Strictly Necessary: Required for the Site to function. These include session cookies, cart functionality, checkout security, and fraud prevention. These are always active and cannot be disabled through our cookie banner.
  • Analytics and Performance: Allow us to understand how visitors use our Site. Provided by Google Analytics and Google Tag Manager.
  • Advertising and Retargeting: Enable us to show you relevant ads on third-party platforms and measure ad effectiveness. Provided by Meta Pixel, Google Ads, Pinterest Tag, and TikTok Pixel.
  • Personalization: Used to customize your Site experience and product recommendations. Provided by Rebuyengine.
  • Email Marketing: Track email opens and clicks to measure campaign effectiveness. Provided by Klaviyo.

4.2 Your Cookie Choices

When you first visit our Site, you will see a cookie consent banner. You may:

  • Click Accept to enable all cookie categories, including analytics, advertising, and personalization.
  • Click Reject to disable all non-essential cookies. Only strictly necessary cookies will remain active. No analytics, advertising, or personalization scripts — including search bar query data — will be transmitted to external services.
  • Click Learn More and Customize to make granular choices by cookie category.

You may change your cookie preferences at any time by clicking "Your Privacy Choices" in the footer of our Site.

4.3 Conversions API (CAPI)

In addition to browser-based pixel tracking, we use server-side Conversions API (CAPI) integrations with Meta and other ad platforms. CAPI transmits conversion event data (such as purchases and add-to-cart events) directly from our servers to ad platforms, independent of browser cookie settings. This data is used solely to measure and optimize our advertising campaigns and is transmitted only in hashed, privacy-preserving formats when technically available.

Note on CAPI and cookie rejection: CAPI operates server-side and may transmit certain conversion event data even when you have rejected cookies in your browser. If you wish to opt out of this data sharing entirely, please submit a Do Not Sell or Share request as described in Section 9. We will honor such requests by suppressing your data from CAPI transmissions within 15 business days.

5. How We Share Your Information

5.1 We Do Not Sell Your Personal Information

We do not sell your personal information to third parties for their own independent use or monetization. We share personal information only as described in this Policy.

5.2 Sharing with Service Providers

We share personal information with service providers who process data on our behalf and under our instructions. These providers are contractually obligated to protect your data and may not use it for their own purposes.

Service Provider Purpose Data Shared How to Opt Out
Google Analytics / GTM Site analytics and tag management Usage data, device info, IP address Cookie banner or myaccount.google.com
Meta Pixel + CAPI Ad targeting, retargeting, and conversion measurement Purchase events, page views, hashed email/phone Cookie banner; Facebook Ad Preferences; or DNSMS request (see Sec. 9)
Pinterest Tag Ad targeting and conversion measurement Page views, purchase events, hashed identifiers Cookie banner or Pinterest Privacy Settings
TikTok Pixel Ad targeting and conversion measurement Page views, purchase events, hashed identifiers Cookie banner or TikTok Ad Settings
Klaviyo Email marketing platform Email, name, purchase history, engagement data Unsubscribe link in every email
Postscript SMS marketing platform Phone number, purchase history Reply STOP to any SMS
PostPilot Direct mail retargeting (SiteMatch) and direct mail marketing Anonymized browsing behavior (SiteMatch, cookie-consent gated); name and mailing address for direct mail campaigns (customers only) Cookie banner (controls SiteMatch); email rob@angelacaglia.com to opt out of direct mail
Rebuyengine On-site personalization and product recommendations Browse and purchase behavior, session data Cookie banner
Shopify E-commerce platform All transaction and account data Shopify Privacy Policy

5.3 Sharing with Ad Platforms — State Privacy Law Disclosure

Although we do not "sell" personal data, sharing personal information with Meta, Google, Pinterest, and TikTok for cross-context behavioral advertising may constitute "sharing" under California's CPRA and "targeted advertising" under Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, and other state laws. You have the right to opt out of this sharing as described in Section 9.

Activities that involve sharing data with ad platforms for targeted advertising purposes include:

  • Meta Pixel and CAPI: purchase events, page views, and hashed contact information transmitted to Meta for ad targeting and measurement
  • Google Ads: conversion events and remarketing lists shared with Google
  • Pinterest Tag: conversion events and audience matching shared with Pinterest
  • TikTok Pixel: conversion events and audience matching shared with TikTok
  • Lookalike audiences: hashed customer lists uploaded to ad platforms to find similar users

5.4 PostPilot — SiteMatch Retargeting and Direct Mail

We use PostPilot for two distinct direct mail activities, each with different consent requirements:

SiteMatch Anonymous Postcard Retargeting

PostPilot's SiteMatch technology allows us to send postcards to anonymous Site visitors based on their browsing behavior. SiteMatch operates as a cookie-based tracker. If you accept cookies via our consent banner, the SiteMatch tracker may load and you may receive a retargeted postcard. If you reject cookies, the SiteMatch tracker will not load and you will not be targeted through this program. Your cookie preferences fully control this activity — no separate opt-out is required.

Direct Mail to Existing Customers

We may also send direct mail marketing to existing customers using purchase and contact information already on file. If you wish to opt out of direct mail from us at any time, email rob@angelacaglia.com with your name and mailing address and we will add you to our suppression list within 10 business days.

PostPilot does not use your information for its own independent marketing purposes.

5.5 Other Disclosures

We may also disclose personal information to comply with applicable law or legal process; to enforce our Terms of Service; to protect the rights, property, or safety of Angela Caglia Skincare, our customers, or others; or in connection with a merger, acquisition, or sale of substantially all of our assets.

6. Data Retention and Deletion

6.1 How Long We Keep Your Data

  • Purchase and transaction records: 7 years (tax and accounting requirements)
  • Customer account data: duration of account plus 3 years after last activity
  • Marketing consent records: 5 years from the date of consent or last interaction
  • Cookie and analytics data: as configured in each platform (typically 13–26 months)
  • Customer service communications: 3 years

6.2 How We Delete Your Data

When we receive a verified deletion request, we process deletion across all platforms where your personal information is held. This includes:

  • Shopify: We anonymize your customer record using Shopify's built-in data erasure tool. Your order totals are retained for accounting purposes but your name, email, address, and contact information are removed.
  • Klaviyo: We suppress and delete your profile, removing all contact information and engagement history.
  • Postscript: We delete your subscriber record and phone number from our SMS list.
  • PostPilot: We delete your customer record from direct mail lists and add you to our suppression list. For SiteMatch retargeting, rejection of cookies via our consent banner prevents the tracker from loading entirely.
  • Meta, Google, Pinterest, TikTok: We remove your hashed identifiers from all active Custom Audiences and Lookalike Audiences across each platform. Note: we cannot retroactively delete conversion events already transmitted via CAPI, but we suppress all future transmissions of your data.
  • Rebuyengine: We submit a deletion request to Rebuy on your behalf for all behavioral data associated with your profile.

We will confirm completion of your deletion request within 45 days. Some information may be retained in anonymized or aggregated form that cannot identify you, or where retention is required by law (for example, transaction records for tax purposes).

7. Data Security

We implement reasonable technical and organizational measures to protect personal information against unauthorized access, disclosure, alteration, and destruction. These measures include encrypted data transmission (SSL/TLS), access controls, and vendor security assessments.

No method of transmission over the internet or electronic storage is 100% secure. If you believe your information has been compromised, please contact us immediately at rob@angelacaglia.com. In the event of a data breach that affects your rights, we will notify affected individuals and applicable regulators as required by law.

8. Children's Privacy

Our Site is not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete it promptly. If you believe we have inadvertently collected information from a child under 13, please contact us at rob@angelacaglia.com.

9. Your Privacy Rights by State

Depending on where you live, you may have specific rights regarding your personal information. We honor all of the following rights for all US residents to the extent required by applicable law.

Right What It Means How to Submit a Request
Right to Know / Access Request a copy of the personal information we hold about you and how we use and share it. Email rob@angelacaglia.com We respond within 45 days.
Right to Delete Request deletion of your personal information across all platforms we use, subject to legal retention requirements. Email rob@angelacaglia.com. We confirm completion within 45 days.
Right to Correct Request correction of inaccurate personal information we hold about you. Email rob@angelacaglia.com with the corrected information.
Right to Opt Out of Sale / Sharing / Targeted Advertising Request that we stop sharing your data with ad platforms (Meta, Google, Pinterest, TikTok) for targeted advertising, including CAPI transmissions. Click "Your Privacy Choices" in our Site footer, or email rob@angelacaglia.com. Processed within 15 business days.
Right to Limit Use of Sensitive Data
(California CPRA)
Request that we limit processing of sensitive personal information to necessary purposes only. Email rob@angelacaglia.com.
Right to Non-Discrimination We will not deny you products, charge different prices, or provide lesser service because you exercised a privacy right. Automatic — no request needed.
Right to Appeal
(Virginia, Colorado, Connecticut)
If we deny your rights request, you may appeal. If your appeal is denied, you may contact your state attorney general. Email rob@angelacaglia.com within 30 days of receiving our denial.

9.1 California-Specific Rights (CPRA/CCPA)

California residents have all rights listed above, plus:

  • Right to Know Categories: You may request disclosure of the categories of personal information collected, sources, business purposes, and categories of third parties with whom we share information.
  • Shine the Light (Cal. Civil Code § 1798.83): We do not share personal information with third parties for their own direct marketing without your consent.
  • Do Not Sell or Share My Personal Information: Click "Your Privacy Choices" in our Site footer or email rob@angelacaglia.com.
  • Authorized Agents: You may designate an authorized agent to submit requests on your behalf. We require written authorization and may verify your identity directly.

9.2 Other State Residents (Virginia, Colorado, Connecticut, Texas, Florida, Oregon)

Residents of these states have rights to know, access, delete, correct, and opt out of targeted advertising substantially equivalent to those described above. We apply these rights to all US residents regardless of state. To submit a request, email rob@angelacaglia.com.

9.3 Identity Verification

To protect your privacy, we verify your identity before processing rights requests. We will ask you to confirm information that matches what we have on file, such as your name, email address, and order history. We will not discriminate against you for making a rights request and will not require you to create an account to submit one.

10. Do Not Track and Global Privacy Control

We currently do not respond to browser Do Not Track (DNT) signals as there is no uniform industry standard for DNT compliance.

We do honor Global Privacy Control (GPC) signals. If your browser transmits a GPC signal, we treat it as an opt-out of sale and sharing of your personal information for targeted advertising purposes under applicable state law. This is automatically applied and does not require a separate request.

11. Third-Party Links

Our Site may contain links to third-party websites. This Privacy Policy does not apply to those sites. We are not responsible for the privacy practices of third-party sites and encourage you to review their privacy policies before providing personal information.

12. International Users

Our Site is operated from the United States. If you access our Site from outside the United States, your personal information will be transferred to and processed in the United States, where privacy laws may differ from those in your country. By using our Site, you consent to this transfer and processing.

We do not currently maintain GDPR-compliant data processing agreements for EU or UK users. If you are an EU or UK resident, please contact us at rob@angelacaglia.com before providing personal information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised "Last Updated" date and, where practicable, communicated by email to registered users. Your continued use of the Site after any changes constitutes acceptance of the revised Policy. We encourage you to review this Policy periodically.

14. Contact Information

For privacy questions or to submit a rights request:

Angela Caglia Skincare — Privacy Hollywood Glow Girl Enterprises, Inc
153 W Rosecrans Ave., Unit 2
Gardena, California 90248

Privacy requests: rob@angelacaglia.com
General inquiries: rob@angelacaglia.com

For California residents with unresolved complaints, you may also contact the California Privacy Protection Agency at cppa.ca.gov.