To download a printable pdf version of this Privacy Policy, click here.
Effective Date: June 28, 2024
This Bombas Washington Health Data Privacy Policy (this “WA Health Data Privacy Policy”) is intended solely for “consumers” under the Washington My Health My Data Act (“WA MHMDA”) and covers includes information required to be disclosed in a separate and distinct privacy policy under that law.
Please click HERE to see the Bombas Privacy Policy and Cookie Policy, which describes our general privacy and data protection practices regarding the collection, use, and disclosure of information when you use the www.bombas.com website and our other digital properties that contain a link to that privacy policy (collectively, our “Site”), and the choices you have with respect to that information.
Consumer Health Data
Bombas does not believe that it collects or shares “consumer health data” – defined by the WA MHMDA as “personal information that is linked or reasonably linkable to a consumer and that identifies the consumer’s past, present, or future physical or mental health status”. However: (i) we do collect and share information, including personal information that is linked or reasonably linkable to a consumer(s), with respect to our compression socks; and (ii) we believe that there is a possibility that such compression sock related information may be considered “consumer health data” under the WA MHMDA.
In the event that our compression sock-related information is considered “consumer health data” under the WA MHMDA (“Consumer Health Data”): (1) the following table sets forth, with respect to such information, (a) the categories of Consumer Health Data we collect and the purposes for which the data is collected, including how the data will be used, (b) the categories of sources from which the Consumer Health Data is collected, (c) the categories of Consumer Health Data that are shared, and (d) a list of the categories of third parties and specific affiliates with which we share the Consumer Health Data; and (2) we undertake measures designed to ensure that, to the extent possible, we use and share Washington consumers’ personal information that is associated with compression socks only in connection with the provision of compression socks. In the table below, each “Category of Consumer Health Data” means the applicable category of personal information when associated with compression socks.
Category of Consumer Health Data: Identifiers (such as a real name, postal address, email address, an online identifier, or an internet protocol address)
Categories of Sources: We receive such information directly from consumers (such as when they complete a purchase on our Site) and/or from third-party vendors (such as vendors that use cookies, pixels, and other similar online technologies on our Site)
Purposes for Sharing: in connection with the provision of compression socks
Categories of Third Parties with Which We Share: third-party vendors who provide services in connection with the provision of compression socks, including our e-commerce platform provider
Category of Consumer Health Data: Commercial information (such as records of the products a consumer purchased)
Categories of Sources: We receive such information directly from consumers (based on the purchase activities of those consumers on our Site)
Purposes for Sharing: in connection with the provision of compression socks
Categories of Third Parties with Which We Share: third-party vendors who provide services in connection with the provision of compression socks, including our e-commerce platform provider
Category of Consumer Health Data: Internet or other electronic network activity information (such as browsing history, search history, and information regarding interactions with our Site and our advertising)
Categories of Sources: We receive such information from third-party vendors, including ad platforms and vendors that use cookies, pixels, and other similar online technologies on our Site and in third-party services (including in emails and advertisements)
Purposes for Sharing: in connection with the provision of compression socks
Categories of Third Parties with Which We Share: third-party vendors who provide services in connection with the provision of compression socks, including our e-commerce platform provider
Category of Consumer Health Data: Audio, electronic, visual, thermal, olfactory, or similar information
Categories of Sources: We receive such information (which may include a photo or a video) directly from consumers when they provide it to us
Purposes for Sharing: we do not share such Consumer Health Data other than Volunteered Consumer Health Data (see below)
Categories of Third Parties with Which We Share: other than Volunteered Consumer Health Data shared with our third-party customer support technology (including chatbot) vendor (see below), we do not share such Consumer Health Data
We may also collect and share any category of Consumer Health Data that you voluntarily provide to us in a communication (such as an email or via our customer service chatbot) (“Volunteered Consumer Health Data”). If you provide us Volunteered Consumer Health Data, we may use such Volunteered Consumer Health Data for our customer-service purposes and other operational and commercial purposes, and we may share such Volunteered Consumer Health Data with our third-party customer support technology (including chatbot) vendor (currently, Gladly), which may use it to train its automated systems and inform its services that utilize the output of such automated systems; to learn more about Gladly’s processing of information, please visit https://www.gladly.com/privacy-policy/.
Consumer Rights
If you are a Washington consumer, you have the following rights under the WA MHMDA with respect to your Consumer Health Data:
Right to Know/Access. You have the right, following your authenticated request, to: o Confirm whether we are collecting, sharing, or selling Consumer Health Data concerning you; and
Access such Consumer Health Data, including:
A list of all third parties and affiliates with whom we have shared or sold such Consumer Health Data; and
An email address or other online mechanism that you may use to contact those third parties.
Right to Delete. You have the right to request that we delete, following your authenticated request, the Consumer Health Data we have collected about you.
Right to Withdraw Consent. We do not currently rely on consent for the collection or sharing of Consumer Health Data that we collect from you (other than with respect to Volunteered Consumer Health Data, for which you are consenting when you voluntarily provide such data to us in a communication); if, following the effective date of this WA Health Data Privacy Policy, we do seek and obtain such consent from you for the collection or sharing of your Consumer Health Data, then you will have the right to withdraw such consent.
Please note the following:
The process we currently use to verify or authenticate “requests to know/access” and “requests to delete” requires you to provide your email address, your postal address, and information about your purchase history with respect to Bombas compression socks.
If you submit a “request to delete”, we may have a reasonable need to retain certain of your Consumer Health Data, including for purposes of Bombas’s guarantees (such as our lifetime Happiness Guarantee), for security, fraud prevention, or legal purposes, on account of technical limitations, and for certain other limited purposes permitted by the WA MHMDA. Therefore, if you submit a “request to delete”, we may not delete Consumer Health Data that we reasonably need to retain.
If we utilize “deidentification” to comply with a “request to delete” or similar legal obligation with respect to Consumer Health Data, we will maintain and use such data in deidentified form and will not attempt to reidentify such deidentified data.
Methods of Submitting Consumer Rights Requests under the WA MHMDA
If you are a Washington consumer, you may submit requests under the WA MHMDA to exercise your “right to know/access” and your “right to delete” by emailing us at privacy@bombas.com. If, following the effective date of this WA Health Data Privacy Policy, we revise our practices to rely on consent for the collection or sharing of Consumer Health Data (other than Volunteered Consumer Health Data), we will update this WA Health Data Privacy Policy to provide a method or mechanism to enable Washington consumers to exercise the “right to withdraw consent”.
Please note that if we notify you that we were unable to authenticate your “request to know/access”, or “request to delete”, you may appeal our determination by emailing us at privacy@bombas.com and indicating why you disagree with our determination (including by providing additional information to support your request).
Changes to this WA Health Data Privacy Policy
We may update this WA Health Data Privacy Policy from time to time. You are advised to review this WA Health Data Privacy Policy periodically for any changes. Changes to this WA Health Data Privacy Policy are effective when they are posted on this page, and we will update the “Effective Date” at the top of this WA Health Data Privacy Policy.
Contact Us
If you have any questions about this WA Health Data Privacy Policy or our practices with respect to Consumer Health Data in connection with the WA MHMDA, please feel free to contact us by email to privacy@bombas.com , by phone (1-800-314-0980), or by postal mail to the following address: Bombas LLC, 881 Broadway, 2nd Floor, New York, NY 10003, USA. If you experience difficulty in accessing any part of our services or this WA Health Data Privacy Policy, please feel free to call us at 1-800-314-0980 or to email us at hello@bombas.com.