Grove Collaborative Privacy Policy

Effective Date: March 11, 2023

Grove Collaborative operates an ecommerce service and related services through grove.com, grove.co, mobile applications, and related sites accessible to mobile devices, tablets, and other connected devices (collectively, the “Grove Collaborative Service” or “Service”). As used in this policy, “Grove Collaborative” refers to Grove Collaborative, Inc. and its subsidiaries. We may refer to Grove Collaborative as “we”, “us”, or “our”. We may refer to you as “customer”, “you”, or “your”.

This privacy policy describes the personally identifiable information from or about an individual ("Personal Information") that we gather from you, how we use and disclose that information, and the ways in which you can control how we use and share it. By using our Service, you acknowledge that you have read, understood and agreed to the terms of this privacy policy.

This privacy policy is incorporated into and is subject to the Grove Collaborative Terms of Use. Please make sure that you have carefully read and understand the Grove Collaborative Terms of Use before you use our Service. Capitalized terms that are not defined in the privacy policy have the meaning given to them in the Grove Collaborative Terms of Use.

Residents of California, Virginia and Nevada may have additional rights. Please see our Privacy Notice for each of these states following the main Privacy Policy.

TYPE OF INFORMATION WE COLLECT

Information That You Give Us Directly

We receive and store any information you enter into the Service. You may choose not to provide certain information, but then you might not be able to use the Service or take advantage of many of our features. You provide most of this information when you interact with the Service. Some examples of this type of information are below.

  • When you create an account or login to your account, the information that we request such as your first and last name, email address, shipping address, billing address, phone number, and password.
  • When you order products on our Service, the information necessary to complete the transaction, such as your name, items purchased, special instructions, date and time of order, purchase price information, limited credit card information (last four digits and expiration date), billing information and shipping information.
  • When you interact with certain Service features, the information that you provide during that interaction, such as (i) product reviews, (ii) information required to participate in one of our sweepstakes, giveaways, contests, customer panels, or other programs, (iii) information that you submit or provide if you choose to participate in one of our surveys, quizzes, or other questionnaries - including the Grove Wellness quiz, and (iv)information required to verify your identity. Please do not post or add Personal Information in your reviews.
  • When you contact us, the information that you provide and the information that we need to respond, such as your name, email address, your message to us, and our response.
  • When you visit us at our offices or locations, information that you provide, such as your name and email address and information gathered from security surveillance.

Information Collected Automatically

When you use the Service, we collect information automatically to help us operate and improve the Service, such as the Internet protocol (IP) address used to connect your computer to the Internet; device data, login; email address; password; computer and connection information such as browser type, version, and time zone setting, browser plug-in types and versions, operating system, and platform; the full Uniform Resource Locator (URL); clickstream to, through, and from any of our Internet web sites, including date and time; cookie number; products you viewed or searched for; and the phone number you used to call our 800 number. We may also use browser data such as cookies or similar technologies on certain parts of our website for business processes, fraud prevention and other purposes. For details about how we use these technologies, and your opt-out opportunities and other options, please see our Cookie Policy. We receive information from you and third-parties that helps us approximate your location. During some visits we may use software tools such as JavaScript to measure and collect session information, including page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page. We may also collect technical information to help us identify your device for fraud prevention and diagnostic purposes.

Information from Other Sources

We may receive or collect information about you from third parties and combine and store it on our servers with other information we may have already received or collected from you. We may store this information or combine it with information we collect in other ways. Some examples include:

  • Service partners that provide or make available advertising, features and functionality, and content on or through the Service.
  • Partners that collect and maintain information on their customers. These partners may provide Grove Collaborative with certain information about those customers for the purposes of serving advertisements and/or marketing offers to their customers.
  • Marketing companies and data providers that create, maintain, and distribute professional marketing lists or segments, or maintain and distribute other marketing, or similar information.
  • Governmental or quasi-governmental agencies or organizations that provide or make available, to the public, census and demographic data.
  • Third-party social media websites, applications, or services that you use, when we allow those websites, applications, or services to interact through the Service to provide personalized services to you. In some cases, those websites, applications, or services may automatically provide us with information about you to facilitate personalization unless you use the controls available on those websites, applications, or services to opt-out of such sharing.

HOW WE USE THE INFORMATION THAT WE COLLECT

We use your Personal Information in ways that help us operate and improve the Service. Some examples include:

  • To fulfill your requests or to meet the reason you provided the information. For example, if you share your name and contact information to ask a question about our products or Service, we will use that Personal Information to respond to your inquiry. If you provide your Personal Information to purchase a product or service, we will use that information to process your payment and facilitate delivery. We may also save your information to facilitate new product orders or process returns. If you choose to provide responses to the Grove Wellness quiz to help you identify which products might meet you needs, we will use this information such as your email, nutritional needs, health concerns, dietary preferences, and other health-related information to display, email and offer product information.
  • To personalize and provide the Service, such as to identify you as a customer, to establish and maintain your account, to remember your information so that you do not have to re-enter it, to provide the transactions that you request, to assess the current and future needs of your household, to process and fulfill your orders, provide refunds.
  • To contact you for administrative purposes, legal purposes, and certain Service-related purposes, such as to send you emails, text messages, or other communications about your orders, customer support requests, and products and services that we believe may interest you.
  • For marketing and advertising purposes, such as providing promotional and advertising materials (either directly or through our service providers) about our products and Services, including relevant product information based on your responses to our Wellness Quiz. You may opt-out of our marketing communications by sumitting a request by clicking here.
  • To contract or partner with third parties to provide specialized services on our behalf, such as development, hosting, analytics, maintenance, payment processing, products, shipping, message delivery, payment processors, customer support, ad servers or other providers of advertising services, platform technology providers, bulk email processors, parties who assist us with sweepstakes management and prize fulfillment, and other services relating to the operation of the Service.
  • To test, research, and analyze our Services.
  • To help maintain the safety, security, and integrity of our Service, databases and other technology assets, and business.
  • To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
  • To execute any other purpose disclosed to you at the time we collect or receive the information, or otherwise with your consent.

WHEN WE DISCLOSE THE INFORMATION THAT WE COLLECT

We disclose your Personal Information for business purposes, which may include disclosure to third parties that help us perform the Service, are necessary to our business operations or that you designate to receive such information, including other websites, social media platforms, other individuals, and other businesses. For example, we may disclose your Personal Information to:

  • Service providers who provide specialized services on our behalf such as development, hosting, analytics, maintenance, payment processing, products, shipping, message delivery, text messaging, customer support, ad servers or other providers of advertising services, platform technology providers, bulk email processors, parties who assist us with sweepstakes management and prize fulfillment, and other services relating to the operation of the Service.
  • Third party payment processors who process your payment when you make a purchase on the Service. We rely on these third parties (such as Paypal and Stripe) to collect and process directly payment and financial information you provide to pay for your purchases. The terms and policies regarding the security practices of and use of your information by the payment processors is governed by the terms and conditions of these third parties, and we encourage you to read their terms carefully before submitting your information.
  • Other parties that we think are necessary to: (i) take precautions against liability; (ii) protect Grove Collaborative and others from fraudulent, abusive, or unlawful uses or activity; (iii) investigate and defend ourselves against any third party claims or allegations; (iv) protect the security or integrity of the Service; and/or (v) protect the rights, property, or personal safety of Grove Collaborative, our users, or others. We may also disclose your information if required to do so by law or if we believe that such action is necessary to comply with state and federal laws; in response to a court order, judicial or other government subpoena or warrant; or to otherwise cooperate with law enforcement activity.

We can also share your personal data as part of a sale, merger or change in control, or in preparation for any of these events. Any other entity which buys Grove Collaborative or part of our business will have the right to continue to use your information, but only in the manner set out in this privacy policy unless you agree otherwise.

Data Retention

We retain information from or about you for so long as necessary to fulfill the purposes outlined in this Privacy Policy. When the information is no longer necessary for these purposes, we may delete it or keep it in a form that does not identify you, unless we are required by law to keep this information for a longer period. When determining the retention period, we take into account various criteria, such as the type of products and services requested by or provided to you, the nature and length of our relationship with you, possible re-enrolment with our products or services, the impact on the services we provide to you if we delete some information from or about you, mandatory retention periods provided by law and the statute of limitations.

Links to Third Party Services

The Service may also contain features or links to websites and services provided by third parties that we do not operate and are outside of our control. Any Personal Information you provide on these third party sites or services is provided directly to that third party and is subject to that third party's policies, if any, governing privacy and security, even if accessed through the Service. Please exercise caution and review their applicable privacy and security policies before providing them with Personal Information. We are also not responsible for any products or services you may purchase from these third-party sites. We do not and will not provide any representations or recommendations in relation to any of the information and suggestions comprised within the services. We do not guarantee or endorse the products or services offered by the third party. You are deemed to be responsible for and shall use your own skill and judgment as to, the quality, value and suitability of such information and suggestions and in deciding whether to enter into any contract with any third party for the supply of services or sale of goods.

Our Commitment To Children's Privacy

We do not knowingly allow children under 13 years of age to use the Service or knowingly collect or maintain Personal Information from persons under 13 years of age. If you are under 13 years of age, then please do not use or access the Service at any time or in any manner. If a child under 13 submits Personal Information to Grove Collaborative and we learn that the Personal Information is the information of a child under 13, we will attempt to delete the information as soon as possible. If you believe that we might have any Personal Information from a child under 13, please contact us at [email protected].

Our Commitment To Data Security

We use certain physical, managerial, and technical controls that are designed to improve the integrity and security of your Personal Information. We cannot, however, ensure or warrant the security of any information you transmit to us over the internet or store on the Service and you do so at your own risk. We also cannot guarantee that such information will not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial controls.
If we learn of a security systems breach, then we may attempt to notify you electronically so that you can take appropriate protective steps. We may post a notice through the Service if a security breach occurs. Depending on where you live, you may have a legal right to receive notice of a security breach in writing. To receive a free written notice of any security breaches, you should notify us at [email protected].

International visitors

The Service is hosted in the United States and is intended solely for consumers located within the United States. If you choose to use the Service from the European Union or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your personally identifiable information outside of those regions to the United States for storage and processing, and by providing your personally identifiable information on the Service you consent to that transfer, storage, and processing. Please note that the United States does not have the same data protection laws as the European Union and other regions.

Changes and updates to this Privacy Policy

Please revisit this page periodically to stay aware of any changes to this Privacy Policy. If we modify this Privacy Policy, we will make the modified version available through the Service and update the last updated data above. In the event that the modifications materially alter your rights or obligations hereunder, we will make reasonable efforts to notify you of the change. Our amended Privacy Policy will automatically take effect 30 days after it is made available through the Service, and if you do not agree with any changes to the Privacy Policy, you may terminate your account and stop using the Service. Your continued use of the Service after the revised Privacy Policy has become effective indicates that you have read, understood and agreed to the then-current version of the Privacy Policy.

Our contact information

Please contact us with any questions or comments about this Privacy Policy, your Personal Information, our use and disclosure practices, or your consent choices by e-mail at [email protected]. You may also contact us at the following address:

Grove Collaborative, Inc.
1301 Sansome Street
San Francisco, CA 94111

PRIVACY NOTICE FOR CALIFORNIA RESIDENTS

California Residents

If you are a California resident, the California Consumer Privacy Act (“CCPA”) as amended and updated by the California Privacy Rights Act (“CPRA”) grants you certain rights related to your information. The CCPA and CPRA may be referred to collectively, as “California Privacy Law”. The applicable rights under California Privacy Law are summarized below.

  • Right to Know: You may ask us for a copy of your personal data collected over the past 12 months and for information about how we collect, use, disclose, and sell it.
  • Right to Deletion: You may ask us to delete any personal data. If you delete your personal data, you will permanently lose access to your account and the information in your account. We may save personal data when permitted by applicable law or for business purposes including, without limitation, when the information is needed to comply with our legal obligations (including law enforcement requests), meet regulatory requirements, meet requirements of our business operations, resolve disputes, maintain security, prevent fraud and abuse, enforce our Terms of Service, fulfill your request to “unsubscribe” from further messages from us, or confirm that we have deleted your data. We retain de-personalized information after your account has been closed. Any information that you posted in product reviews, including your first name and last initial will remain visible on the Service. We cannot disclose or delete specific pieces of Personal Information if the disclosure would create a substantial, articulable, and unreasonable risk to the security of the personal information, your account with us or the security of our systems.
  • Right to Correction: You may modify certain details of your Personal Information by logging into our Service and using your username and password and visiting “Settings” on the “Account” page. If there are additional details of your Personal Information that need to be corrected, you may submit a request by completing this Privacy Request Form or contacting [email protected]
  • Do Not Sell: Notice of Sale and Right to Opt-Out of the Sale or Sharing of Your Personal Information: Grove Collaborative does not sell, in the traditional sense of the word, or rent Personal Information to third parties. We do, however, share your Personal Information as we describe in this privacy policy to make the Service available to you. Some of the disclosures we have made over the past 12 months may be considered a "sale" under the CCPA. For example, we may disclose information to advertising partners, advertising technology companies, and companies that perform advertising-related services in order to improve the relevance of our advertising and marketing.
  • Opting-Out You have the Right to Opt-Out of certain disclosures as afforded by California Privacy Law. To exercise this right, please submit a request by clicking here. Please note that any request to opt-out may take a few days to become effective, but will be handled within the timeframe permitted by law. Once your opt out request is processed, it will apply on a going forward basis with respect to our disclosure of information. Although we will not sell your personal data (as those terms are defined in California Privacy Law) after you submit a “Right to Opt Out”, we will continue to share some personal data with service providers. These service providers help us perform a host of services, including, but not limited to, analytic-related functions such as measuring our website performance, ensuring services are working correctly and securely, providing aggregate statistics and analytics, communicating directly with users and/or reducing fraud.
  • Right to Limit Use of Sensitive Personal Information: California consumers have the right to limit the use of each type of Sensitive Personal Information (as defined below) for each purpose with each type of third-party partner. Consumers can revoke this permission at any time. Please note that Grove only collects very limited Sensitive Personal Information as that term is defined by California Privacy Law and only uses or discloses Sensitive Personal Information to provide to you our products and/or Services and related information. Grove collects and stores (i) your account login information for the business purpose required (to permit and process your account access); and (ii) health related information you choose to provide in response to the Grove Wellness quiz to display, email and offer product information. At this time, we do not provide your Sensitive Personal Information to any third parties other than those service providers that are necessary for us to provide our Services to you, including in your capacity as an employee.
  • Right to Non-Discrimination: Grove Collaborative will not discriminate against customers who exercise their rights. Specifically, if you exercise your rights, we will not deny you access to the site or Services, charge you different prices or rates for products or Services or provide you a different level or quality of products or Services. However, as permitted by California Privacy Law, we may offer you certain financial incentives that can result in different prices, rates, or quality levels. Any permitted financial incentive we offer will reasonably relate to the value of your Personal Information, for instance, if you sign up for a newsletter with us, we may provide you with discounts for future Services. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.

You can learn more about how to make these requests by visiting the Password & Privacy section of your Account Settings, or contacting us at [email protected], and we will consider your request in accordance with applicable laws. In order to complete your request, you must confirm your identity. If you request to opt-out of sales of your Personal Information under California Privacy Law, you will be directed to verify your identity before completing your request. If you choose to exercise another right under California Privacy Law, you will be directed to verify your identity by logging into your account.

Below is a summary of the Personal Information we collected from consumers over the past 12 months, the reason we collected the Personal Information, where we obtained the Personal Information we collected, and the third parties with whom we may share consumer Personal Information. The section references relate to the sections above in this Policy.

Type of Information Sources of Information How We Use Information How We Share Information
Identifiers (such as a name, address, unique personal identifier, email, phone number) Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description Data Retention When We Disclose The Information That We Collect Links to Third Party Services
Customer records such as account and password Information Type Of Information We Collect How We Use The Information That We Collect Data Retention When We Disclose The Information That We Collect Links to Third Party Services
Commercial information such as records of products or services purchased, obtained, or considered Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description Data Retention When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies
Internet/electronic activity Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description Data Retention When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies
Geolocation (outside of 1750 feet) Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description Data Retention When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies
Demographic Information Type Of Information We Collect How We Use The Information That We Collect Data Retention When We Disclose The Information That We Collect Links to Third Party Services
Sensory data, such as audio, electronic, visual, or other similar information Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description Data Retention When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies
Inferences about preferences, characteristics Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies
Sensitive Information which consists of account login data and possible health data Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description Data Retention When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies

California “Shine the Light” disclosure

The California “Shine the Light” law gives residents of California the right under certain circumstances to opt out of the sharing of certain categories of personal information (as defined in the Shine the Light law) with third parties for their direct marketing purposes, or in the alternative, that we provide a cost-free means for consumers to opt out of any such sharing. We do not currently share your Personal Information with third parties for their own direct marketing purposes.

PRIVACY NOTICE FOR NEVADA RESIDENTS

Nevada residents may have the right to request opt-out of the sale of Personal Information that we may collect through our websites or online applications. If you are a Nevada resident and wish to make this request, contact [email protected].

PRIVACY NOTICE FOR VIRGINIA RESIDENTS

If you are a Virginia resident, you have the right under the Virginia Consumer Data Protection Act (‘VCDPA”), upon a verified request, to:

  • To confirm whether or not a controller is processing your personal data and to access such personal data;
  • To correct inaccuracies in your personal data;
  • To delete your personal data;
  • To obtain a copy of your personal data that you previously provided to us in a portable, and if technically feasible, readily usable format, if processing is carried out by automated means;
  • To opt out of the processing of your personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.

Right to Non-Discrimination: Grove Collaborative will not discriminate against customers who exercise their rights. Specifically, if you exercise your rights, we will not deny you access to the site or Services, charge you different prices or rates for products or Services or provide you a different level or quality of products or Services. However, as permitted by VCDPA, we may offer you certain financial incentives that can result in different prices, rates, or quality levels. Any permitted financial incentive we offer will reasonably relate to the value of your Personal Information, for instance, if you sign up for a newsletter with us, we may provide you with discounts for future Services. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.

Sensitive Information Opt-In: We must also obtain your express consent prior to collecting and processing certain categories of sensitive personal data such as precise geolocation data, data about protected characteristics and genetic or biometric data. We do not generally collect this type of information from consumers, except when you choose to provide specific health diagnosis (such as pregnancy) in your responses to the Grove Wellness quiz. submitting your information to the Grove Wellness quiz-you agree that we may use this information to display, email and offer Grove product information.

If you are a resident of Virginia and wish to exercise any of your rights under the VCDPA, you or your authorized agent may make a request to confirm, access, correct, delete, obtain a copy, or opt-out of the processing of your personal data for targeting advertising, sale, or profiling by submitting a Privacy Request Form here, or by emailing [email protected]

If you use an authorized agent to submit your request, we may require proof of the written authorization you have given. We also may require you to confirm your identity and your residency in order to obtain the information, and you are only entitled to make this request up to twice annually. For emails, please include “Virginia Privacy Rights” as the subject line. You must include your full name, email address, and attest to the fact that you are a Virginia resident. We will process your request within 45 days or let you know if we need additional time or cannot process your request. If you make this request by telephone, we may also ask you to provide the request in writing so that we may verify your identity. If we are unable to honor your request for any reason, we will notify you of the reason within the request time period.

If we decline to take action on your request, you can appeal our decision by submitting an email to [email protected] entitled “Virginia Privacy Rights Appeal” and we will review your request and respond within 60 days of the receipt of your appeal with a written explanation of the reasons for our decision. If your appeal is denied, you may contact the Virginia Attorney General to submit a complaint.

Below is a summary of the Personal Information we collected from Virginia consumers over the past 12 months, the reason we collected the Personal Information, where we obtained the Personal Information we collected, and the third parties with whom we may share consumer Personal Information. The section references relate to the sections above in this Policy.

Type of Information Sources of Information How We Use Information How We Share Information
Identifiers (such as a name, address, unique personal identifier, email, phone number) Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description When We Disclose The Information That We Collect Links to Third Party Services
Customer records such as account and password Information Type Of Information We Collect How We Use The Information That We Collect When We Disclose The Information That We Collect Links to Third Party Services
Commercial information such as records of products or services purchased, obtained, or considered Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies
Internet/electronic activity Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies
Geolocation (outside of 1750 feet) Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies
Demographic Information Type Of Information We Collect How We Use The Information That We Collect When We Disclose The Information That We Collect Links to Third Party Services
Sensory data including recordings of customer support calls and video clips Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies
Inferences about preferences, characteristics Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies
Sensitive Information which consists of account login data and possible pregnancy health diagnosis Type Of Information We Collect Category of Use of Cookies How We Use The Information That We Collect Description When We Disclose The Information That We Collect Links to Third Party Services Third Party Cookies

NOTICE CONCERNING DO NOT TRACK

Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. We are committed to providing you with meaningful choices about the information collected on our websites for third-party purposes, and that is why we provide the variety of opt-out mechanisms listed above, and in our Cookies Notice. Some web browsers offer users a “Do Not Track” privacy preference setting in the web browser. We do not currently recognize or respond to browser-initiated Do Not Track signals. Learn more about Do Not Track at allaboutdnt.com.