Privacy Policy

KORRES ("KORRES," "we," "us") collects, stores, and processes information from members, visitors to the KORRES website (the "Site"), and users ("you") of our Services. We value your privacy. This Privacy Policy (the "Policy") explains what we collect, how we use and share it, and the choices you have when you interact with our website, the websites of any of our affiliates or subsidiaries (the "Affiliates"), or visit our physical locations (collectively, the "Services"). If you do not want us to collect or use your information as described in this Policy, please do not use the Services. We may update this Policy periodically. When we do, we will post the revised version on the Site with a new effective date. The updated Policy will apply to all current and past users as of its effective date and will replace prior versions. By accessing the Services on or after the effective date, you consent to the then-current Policy. This Site is not directed toward or intended for use by children or anyone under the age of 18. We do not knowingly collect information from anyone under the age of 13. The Services are operated in, and governed by the laws of the United States and are intended for U.S. users.
If you access the Services from outside the U.S. (including the European Union), your information will be collected, processed, and stored in the U.S.,
where data protection laws may differ from those in your country.

Scope. This Policy applies to visitors and customers of our consumer Services. It does not cover job applicants, employees, contractors, or other personnel; those are addressed in separate notices where applicable.

1. Summary

Our Privacy Policy is written to clearly explain and describe to you how we collect, use, share, and disclose the information collected by KORRES through our Services. We have divided our Policy into two different sections: (1) this succinct summary section that provides a general overview of our privacy practices; and (2) a more comprehensive policy outlining the specifics of what information we collect, how and why we collect that information, and your rights in regard to your data. In the bullet points below, you will find key areas of our Policy of which you should be aware. We encourage you to read the full policy before providing us with your information. 

  • We collect personal information in a few principal ways, including information you provide directly to us, information we gather from your use of our Services, and information we receive from third parties. 
  • We may share your information from time to time with third parties, including information necessary to provide you with our Services. 
  • You may request access, deletion, correction, restriction, objection, data portability, or opt out of targeted advertising and the sale/sharing of personal information using Do Not Sell My Information (site footer) or by emailing support@korres.com
  • While it is not possible to guarantee that your information will remain entirely secure, we use commercially reasonable efforts to secure your information. 

  

This website is not directed toward or intended for use by children or anyone under the age of 18. We do not knowingly collect information from anyone under the age of 13. 
 

The Services are governed by and operated in accordance with the laws of the United States and are intended for users located in the United States. KORRES makes no representation that the Site is governed by or operated in accordance with the laws of any other country. If you are located outside of the U.S., including the European Union, since our Services are intended for users located in the U.S., information we collected will be collected, processes and stored in the U.S. The data protection laws in the U.S. may differ from those of the country in which you are located, and you waive any claims that may arise under those laws. You understand that your Personal Information may be subject to access requests from governments, courts, or law enforcement in the U.S. according to the laws of the U.S.  

 

By using the Services or providing us with any information, you consent to the collection, transfer, processing, and storage of your information in and to the U.S. You are also consenting to the application of the U.S. federal and New York state Law in all matters concerning the Services and Privacy Policy. 
 

By accessing and using our Services, you accept all terms and conditions set out in this Policy. Before using our Services, you should read the Policy in its entirety and return to this page periodically to review any changes. We may update this policy from time to time and by continuing to use our Services after such updates you consent to those changes. 

  

Text Messages. We use cookies to help keep track of items you put into your shopping cart, including when you have abandoned your cart, and this information is used to determine when to send cart reminder messages via SMS. 

2. Consent to Data Collection

By using the Services or providing us ith any information, you consent to the ollection, transfer, processing, and storage of your information in and to the U.S. You are also consenting to the application of U.S. federal law and New York State law in all matters concerning the Services and this Policy.

By accessing and using our Services, you accept all terms and conditions set
out in this Policy. Before using our services, you should read the Policy in its entirety and return to this page periodically to review any changes. We may update this policy from time to
time and by continuing to use our Services after such updates you consent to those changes.

3. What Information We Collect

KORRES collects both Personal Data and Anonymous Data 
 

Personal Data. “Personal Data” is data that someone could use to individually identify or contact you. This includes information like your name, email address, telephone number, or address. It can also include non-public information of yours that is either associated with or linked to any of the data mentioned above. 

Sensitive Personal Information. “Sensitive Personal Information” is a specific subset of Personal Data that includes certain government identifiers (such as social security numbers), an account log-in, debit or credit card numbers in combination with any required access code/password, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of mail or emails, text messages unless business is the intended recipient of the communication, and genetic data.   

Anonymous Data. “Anonymous Data” is data that is neither associated with nor linked to your Personal Data. Anonymous Data on its own cannot identify you individually. 

Categories of personal information we collect that you voluntarily provide include your name, shipping/billing address, telephone number, email address, and social media username. 

Account Information. When you sign up for an account, we collect certain information about you. This includes basic information such as your email address, name, phone number, and address. If you fill out any surveys through your account, we keep that information as well. We may also collect information about your interest in and use of various products, services, and content you access through our Services. 

If you choose not to provide Personal Information to us, you may be unable to purchase products, take advantage of offers and content on our Site or otherwise access certain aspects of the Services.  

We collect this information for the following business purposes: to enable you to purchase or order a product, to enable you to join our customer loyalty program the “Circle Rewards Program”, to submit a product review or to otherwise engage with our Services. 

Social Media. You may be able to link some social media accounts to our Services. If you link such social media accounts, we may access surface level profile information from your account including your name, profile picture, contact list, username, pictures and videos, gender, birthday, location, people you follow and/or who follow you, and the posts you make or posts you “like.” By linking your account, you consent to KORRES collecting any linked information in accordance with this privacy policy. If you do not wish to share certain information from another social media account, you should change your preferences on that account. Any information from another social media service is subject to the data protection practices of the social media network itself and is not controlled by KORRES. As such, you should read through the privacy policy of any social media service you wish to link to before linking the account with our Services. 

Device and Technical Information. As is true of most websites, when you access our Services through your computer or smartphone, we automatically collect information about the device you are using, including: your browser type, your operating system, your IP address, your Internet service provider or mobile carrier, IDFA, MAC address, and unique device identifier. We also collect crash logs, reports on bugs, feedback on our services, support requests, and certain device usage information. You can deactivate cookies through your own browser settings. Each browser is unique, therefore look at your browser’s Help menu to learn the correct way to modify your cookies. Remember, many of our Services may not function properly if your cookies are disabled. 

Financial Information. When you purchase a product through our Services, we save your purchase for internal audit purposes or to send you additional content and product offerings in order to complete your transaction. However, we do not collect or retain the card information. We use third-party services for payment processing (e.g. payment processors). We will not store or collect your payment card details. That information is provided directly by you to our third-party payment processors whose use of your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information. The payment processors we work with are: 
- Shopify.com 

Location Information. We may collect precise or approximate location information, such as country or address, when you either provide it to us directly, through device information, or other means. For instance, if you access our Services through your computer or mobile device, we may collect your precise device location through your IP address for security, regulation, and performance considerations. You can restrict what location information you provide to KORRES through your device settings. When you make a purchase at one of our physical locations, we will have a record of your location fir that purchase. You may set your web browser software to reject tracking technologies. Please note that the opt-out is cookie-based and will only affect the specific computer and browser on which the opt-out is applied. 

  

Information From Other Sources. We may collect information from other sources such as companies and sponsors for co-branding events to give you access to promotions, sweepstakes, and other specific event information. 

4. How We Collect Your Information

  • Directly from you when you create an account, make a purchase, contact support, subscribe to emails/SMS, participate in promotions, or otherwise interact with us.
  • Automatically through cookies, web beacons, pixels (including TikTok, Meta, Google), SDKs, and similar technologies when you use the Services.
  • From third parties such as payment processors, e‑commerce platforms (e.g., TikTok Shop, Shopify), marketing/analytics providers (e.g., Google Analytics, Hotjar, Microsoft
    Clarity), and social media if you link accounts.

5. How We Use Your Information

Service communications. We use your information to communicate about your account and orders (e.g., confirmations, shipping updates, returns/exchanges, and important service or policy notices) by email, phone, SMS, or postal mail.

Marketing & promotions. We use your contact details (e.g., email, SMS number, postal address) to send promotional messages about our products, services, offers, and events. You can opt out at any time by clicking Unsubscribe in an email, replying STOP to an SMS, adjusting Cookie Settings, or emailing support@korres.com. Opting out of marketing does not affect service communications.

Personalization, measurement & targeted advertising. We use identifiers, device/technical data, interaction data, and inferences to personalize content and offers, measure performance, and deliver/limit ads on our Services and on third‑party platforms. This may involve sharing certain identifiers and event data with advertising/measurement partners —including integrations with TikTok and Shopify—and may be considered a sale or sharing of personal information, or targeted advertising, under applicable U.S. state laws. You can opt out via Do Not Sell My Information (site footer). Where required, we honor Global Privacy Control (GPC) signals. See our Cookie Policy for details.

Analytics & improvements. We analyze usage to maintain, troubleshoot, and improve the Services; conduct research and A/B testing; enhance speed, reliability, and user experience; and develop new features and products.

Security, fraud prevention & compliance. We use information to protect the Services and our users; detect, investigate, and prevent fraud, abuse, and security incidents; comply with legal obligations; and enforce our Terms and other policies.

Social commerce (TikTok Shop & Shopify). We use personal information exchanged with TikTok Shop and Shopify to process and fulfill orders, provide customer service, manage returns/exchanges, enable marketplace features, and perform measurement/attribution and analytics related to those transactions (including via pixels/SDKs, as described in our Cookie Policy). We do not receive or store full payment card details; payment data is handled by our processors (e.g., Shopify Payments) in accordance with PCI‑DSS.

Aggregated/de‑identified data. We may create and use aggregated or de‑identified information for research, analytics, and business purposes. We will not attempt to re‑identify such information.

6. Cookies & Similar Technologies

We use cookies, pixels, SDKs, and similar technologies to operate the Site, remember your preferences, analyze performance, and personalize/measure advertising. Where required by law, non‑essential cookies are not set unless you consent.

For the complete list of cookies/partners we use, their purposes, and typical retention periods—and to learn how to change your choices—please see our Cookie Policy. You can update your
preferences at any time via Cookie Settings in the site footer. We also honor Global Privacy Control (GPC) signals as a request to opt out of sale/sharing and targeted advertising for the browser that sends the signal (where required by law). Industry opt‑out tools are also available (e.g., DAA and NAI).

Our consent management platform (CMP) records your choices and places a functional consent cookie to remember them. If you clear cookies or use a different browser/device, you may need to re‑apply preferences. Some cookies are set by third parties that provide features on our Site; those parties’ use of cookies is governed by their own privacy policies. You can also manage advertising settings directly with platforms (e.g., Google, TikTok, Pinterest, Microsoft/Bing).

7. Why We Collect and Use Your Information

We collect and use information to:

  • Deliver and fulfill the Services (contract performance): create and manage accounts; process payments and deliver orders (including via TikTok Shop and Shopify); provide customer support; handle returns/exchanges; and communicate about your transactions.
  • Personalize, measure, and improve: tailor content and product recommendations; run analytics and A/B tests; measure performance; and develop new features and offerings.
  • Marketing (with your choices): send emails, SMS, and other promotional messages about products, services, offers, and events. You can opt out at any time.
  • Security, fraud prevention, and enforcement: protect our users and Services; detect, investigate, and prevent fraud, abuse, and security incidents; and enforce our Terms.
  • Compliance and recordkeeping: meet tax, accounting, consumer‑request, and other legal obligations.
  • Legal bases (where a legal basis is required by your jurisdiction):
  • Contract (to provide the Services you request);
  • Consent (e.g., non‑essential cookies/trackers, targeted advertising where required, and marketing communications);
  • Legitimate interests (e.g., to secure and improve the Services and prevent fraud), balanced against your rights; and
  • Legal obligations (e.g., tax, accounting, responding to legally required requests).

You may withdraw consent at any time using the controls above or by contacting support@korres.com.

8. Data Transfers

We and our service providers (including Shopify and TikTok Shop) may transfer your personal information to, and process it in, countries other than your own (including the United States).
Those countries may have different—and in some cases less protective—data
protection laws.

Where a cross‑border transfer is subject to legal restrictions (e.g., EU/EEA, UK), we implement appropriate safeguards, such as:

  • contract terms requiring recipients to protect the information and use it only as instructed (including, where applicable, Standard Contractual Clauses and the UK Addendum);
  • technical and organizational measures (e.g., encryption in transit/at rest, access controls,
    audit logging); and
  • vendor due diligence and ongoing oversight.

Copies or a description of the relevant transfer safeguards can be requested via support@korres.com, subject to reasonable redactions to protect confidentiality. Note that Shopify and TikTok also act under their own privacy policies and may conduct separate international transfers.

9. Sharing Your Information

We disclose personal information to the categories of recipients below, for the purposes described in this Policy or as otherwise disclosed at the time of collection.

With your consent. We disclose information when you ask us or clearly consent to a specific disclosure.

Legal, safety, and compliance. We disclose information to courts, law‑enforcement, regulators, and other third parties when we believe disclosure is necessary to: (i) comply with law or legal process; (ii) detect, investigate, and help prevent fraud, abuse, or security incidents; (iii) protect the rights, property, and safety of KORRES, our users, or others; or (iv) enforce our Terms and policies. Where legally permitted, we will require valid legal process.

Service providers (contracted processors). We provide information to vendors that perform services for us—e.g., website hosting and maintenance, platform and data storage, order fulfillment and delivery, payment processing, fraud prevention, customer support, email/SMS and direct‑mail distribution, analytics, A/B testing, product customization, and ad delivery/measurement. We require service providers by written contract to: (a) use the information only to perform services for us; (b) protect it with appropriate security; and (c) not sell or share it for their own purposes.

Business partners, affiliates, and third‑party marketplaces (TikTok Shop & Shopify). We disclose information to business partners and our affiliates for operational purposes and joint activities. We also disclose information to third‑party marketplace platforms—such as TikTok Shop and Shopify—to fulfill and support your orders, manage returns/exchanges, and ensure delivery and quality control. These platforms may also collect and use information independently under their own privacy policies (including for advertising, analytics, and personalization). Please review their privacy policies for details.

Advertising and measurement partners. We share certain identifiers and event data with ad tech and measurement partners to personalize, deliver, and measure ads (including via TikTok and Shopify integrations, pixels, and SDKs). Under California law, some of this activity may be considered a “sale” or “sharing” of personal information or targeted advertising. You can opt out via Do Not Sell My Information (site footer). We honor Global Privacy Control (GPC) where required.

Affiliates. We disclose information to our corporate affiliates for purposes consistent with this Policy. Our affiliates are required to protect personal information and use it only as instructed.

Sponsors and co‑promotions. When we run sponsored or co‑branded programs, the sponsor/co‑branding party may receive information about participants. Their use is governed by their own privacy policies. Please review those policies before you participate.

Corporate transactions. We may disclose or transfer information in connection with a proposed or completed merger, acquisition, asset sale, financing, reorganization, bankruptcy, or similar transaction. We will require any successor entity to use personal information in a manner consistent with this Policy.

Linked sites and social features. Our Services may link to third‑party websites, social media, or features that are not owned or controlled by KORRES. Any information you provide to those third parties is governed by their privacy policies—not this Policy. Those third parties may use their own cookies and trackers.

Aggregated and de‑identified data. We may share aggregated or de‑identified information (which cannot reasonably be used to identify you) for research, analytics, and similar purposes. We will not attempt to re‑identify such data.

Your choices (California and other U.S. state laws). California residents (and residents of certain other U.S. states) may opt out of the sale or sharing of personal information and targeted advertising via Do Not Sell My Information. We do not knowingly sell or share the personal information of consumers under 16 without appropriate authorization.

Deletion requests—legal exceptions. We may deny or limit deletion where an exception applies (e.g., to complete a transaction you requested, detect security incidents, debug/repair, exercise free speech or comply with law, perform internal uses reasonably aligned with consumer expectations, or for legal claims and recordkeeping). See Your California Rights for details.

10. Marketing Communications — Choices & Opt-Out

We want to contact you only when you want to hear from us.

How to opt out by channel

  • Email: Click Unsubscribe in any marketing email or adjust preferences in your account settings.
  • SMS/Text: Reply STOP to any message (reply HELP for help). Message frequency varies; message and data rates may apply. Consent is not a condition of purchase. See our Mobile Terms.
  • Targeted advertising/cookies: Use Cookie Settings and Do Not Sell My Information (site footer). Where required by law, we honor Global Privacy Control (GPC) signals.
  • Postal mail: Email support@korres.com to opt out of direct‑mail promotions.

Opting out of marketing does not affect service communications (e.g., order confirmations, shipping updates, returns/exchanges, or policy notices).

Processing your choice. We may take up to 10 business days to process email opt‑outs and a short time for SMS. Unsubscribing from one channel (e.g., email) doesn’t automatically unsubscribe you from others (e.g., SMS).

Preference management & suppression. If you have an account, you can also update your preferences in your profile. We may retain limited contact information in a suppression list to ensure we respect your opt‑out.

Access, correction, deletion. To access or update your account information, sign in and edit your profile, or contact support@korres.com. For U.S. state privacy rights (including access, deletion, correction, portability, and opt‑out of sale/sharing/targeted advertising), see Your California Rights and use Do Not Sell My Information

11. Targeted Advertising(Cross‑ContextBehavioral Advertising)

We and our advertising/measurement partners use identifiers (e.g., cookie IDs, mobile/ad IDs, IP address), hashed email (where available), device and network information, and event data (e.g., pages viewed, items added to cart, purchases) to personalize, deliver, and measure ads on our Services and across other sites and apps. This may include cross‑device and cross‑context linking.

Some partners act as our service providers, while others use data independently under their own privacy policies. For details on cookies, pixels, SDKs, and partners, see our Cookie Policy.

TikTok & Shopify. Interactions with KORRES via TikTok Shop and our Shopify storefront (including pixel/SDK events such as views, adds to cart, and purchases) may also be used for interest‑based advertising and measurement on those platforms, subject to their privacy policies and your
settings with them.

Your choices. Under certain U.S. state laws (including California), sharing identifiers and event data for advertising/measurement may be considered a “sale” or “sharing” of personal information or targeted advertising.

You can opt out at any time via Do Not Sell My Information (site footer).

We also honor Global Privacy Control (GPC) signals where required. You can further manage ad preferences via:

  • Cookie Settings (site footer);
  • platform settings (e.g., Google, TikTok, Pinterest, Microsoft/Bing); and
  • industry tools: DAA (aboutads.info/choices) and NAI (optout.networkadvertising.org).

Opt‑outs are generally browser and device specific. If you clear cookies, switch browsers/devices, or use private browsing, you may need to reapply preferences.

We do not control—and are not responsible for—the independent practices of third‑party advertisers, ad networks, or exchanges. Please review their privacy policies for details.

12. Confidentiality& Security

We implement administrative, technical, and physical safeguards appropriate to the nature of the information we process and the risks involved. These measures include policies and training, access controls and least‑privilege, multi‑factor authentication for sensitive systems, encryption in transit (e.g., TLS) and where appropriate at rest, network and application security controls, logging/monitoring, vulnerability management, and regular backups.

We require our service providers (including e‑commerce and payment providers) by contract to protect personal information, use it only as instructed, and notify us of security incidents without undue delay. Payment card data is handled by PCI‑DSS–compliant processors; we do not store full card numbers.

You are responsible for keeping your account credentials confidential and for promptly notifying us at support@korres.com of any suspected unauthorized use.

While we work hard to protect personal information, no method of transmission or storage is 100% secure. If a data incident occurs, we will notify you and/or regulators as required by law. We retain personal information as described in this Policy and delete or de‑identify it when no longer needed or required to be kept.

13. Mobile Marketing& Notifications

The Korres USA text messaging program (the “Service”) is operated by KORRES (“we,” “us”). By opting in, you agree to receive recurring SMS/text messages from or on behalf of KORRES at the mobile number you provide, including promotional messages (offers, cart reminders) and service messages (order/account alerts). Messages may be sent using an automated system. Consent is not a condition of purchase.

What we collect & how we use it. We collect your mobile number, opt‑in/opt‑out status, and messaging preferences to manage the Service and send messages. We may use cookies/pixels to trigger messages based on your actions on our Site (e.g., cart events). See our Cookie Policy and this Privacy Policy for details.

How to opt out. You can opt out at any time by replying STOP to +1‑855‑788‑1650 or tapping the unsubscribe link (where available). You’ll receive one confirmation text and then no further marketing texts unless you opt in again. If you subscribe to multiple KORRES text programs, you must opt out of each separately (as required by law).

Help & support. For help, reply HELP or email support@korres.com. Message frequency varies. Message and data rates may apply. Check your plan for details.

Program terms & changes. See our Mobile Terms for full terms (including arbitration/dispute resolution, where applicable). We may modify or cancel the Service or update these terms; continued use after changes means you accept the updated terms.

Carriers & delivery. Wireless carriers are not liable for delayed or undelivered messages. If we change our short code or phone number, we’ll notify you; messages sent to an old number may not be received. Please provide a valid mobile number and update us if it changes.

Privacy & sharing. We use information collected via the Service consistent with this Privacy Policy. We do not sell or share text message opt‑in/consent data with third parties for their own marketing, except to our SMS platform providers and aggregators as needed to deliver the Service.

14. Health Information(HIPAA Notice)

KORRES is not a HIPAA covered entity or business associate. Our consumer Services are not intended to collect, receive, or store Protected Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA). Information you share with us through the Site, our apps, or SMS is treated as personal information under this Privacy Policy and applicable state laws—not as PHI.

Please do not submit PHI to us. This includes, for example, medical records, diagnoses, treatment information, prescription details, insurance member numbers, or any information from a healthcare provider. If we inadvertently receive PHI, we will delete or de‑identify it unless we are legally required to retain it.

If we ever handle PHI under a Business Associate Agreement (BAA). In limited cases where we expressly contract to support a HIPAA‑covered entity, those services would be governed by a written BAA. That PHI processing would be separate from the consumer‑facing Services covered by this Policy.

No medical advice. Our content and products are for cosmetic and informational purposes only and are not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional with questions about a medical condition.

15. Third‑Party Services & Platforms

We use third‑party vendors to operate and improve the Services—e.g., hosting/cloud, e‑commerce and marketplaces (including Shopify and TikTok Shop), payment processing, customer support, email/SMS delivery, analytics/experience tools (including Hotjar), advertising/measurement, fulfillment/logistics, fraud prevention, and security/IT. For the specific cookies, pixels, SDKs, partners, and retention periods we use, see our Cookie Policy.

We require service providers by contract to use personal information only to perform services for us and to implement appropriate security. Payment card data is processed by Shopify, a PCI‑DSS‑compliant processor; we do not store full card numbers.

When you interact with KORRES on TikTok Shop or Shopify, those platforms may also collect and use information independently under their own privacy policies. See their privacy policies and our Cookie Policy for details about platform integrations (including pixels/SDKs).

Sharing certain identifiers and event data with advertising/measurement partners (including some TikTok/Shopify integrations) may be considered a “sale” or “sharing” of personal information or targeted advertising under U.S. state laws. You can opt out at any time via Do Not Sell My Information (site footer). Where required, we honor Global Privacy Control (GPC) signals.

You can update non‑essential tracking preferences anytime via Cookie Settings (site footer).

16. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights regarding your personal information.

  • Your rights Right to Know/Access & Portability – Request (a) the categories and specific pieces of
    personal information we collected about you; (b) the categories of sources; (c) the business/commercial purposes; (d) the categories of third parties to whom we disclosed it; (e) the categories of personal information “sold,” “shared,” or disclosed for a business purpose; and (f) our retention periods or criteria.
  • Right to Correct – Request that we correct inaccurate personal information we maintain about you.
  • Right to Delete – Request deletion of personal information we collected from you (subject to legal
    exceptions).
  • Right to Opt Out of “Sale”/“Sharing” & Targeted Advertising – Opt out of the sale or sharing of personal information (as defined by California law) and of cross‑context behavioral/targeted advertising.
  • Right to Limit Use of Sensitive Personal Information (SPI) – Limit our use and disclosure
    of SPI to what is necessary to provide requested services. We do not use SPI for purposes that trigger this right (e.g., to infer characteristics). If that changes, we will provide a mechanism to limit use.
  • Right to Non‑Discrimination – We will not discriminate against you for exercising your rights.

How to exercise your rights

  • Use Do Not Sell My Information (site footer) to opt out of sale/sharing and targeted advertising. We honor Global Privacy Control (GPC) signals where required.
  • To submit access, correction, deletion, or portability requests: email support@korres.com. If you have an account, you may also verify and manage certain information in your profile.

Verification & authorized agents

  • We will verify your request by matching information you provide with our records or via account login. If you use an authorized agent, we may require proof of authorization (e.g., signed permission or power of attorney) and may ask you to verify your identity directly with us.

Appeals

  • If we deny your request, you may appeal by emailing support@korres.com with the subject line “Privacy Request Appeal.” We will review and respond within 45 days.

Response timing

  • We aim to respond within 45 days of receiving a verifiable request; we may extend once by up to 45 additional days with notice explaining the reason for the extension.

Minors under 16

  • We do not knowingly sell or share the personal information of consumers under 16. If we become aware that we have such information, we will obtain the required opt‑in authorization (from the minor aged 13–16, or from a parent/guardian if under 13) or cease such activities.

“Shine the Light” (Cal. Civ. Code §1798.83)

  • California residents may request information regarding our disclosure of personal information to third parties for their direct marketing purposes. To submit such a request, email support@korres.com with the subject line “Your California Privacy Rights.”

Financial incentives (California
loyalty programs).
If you choose to participate in our Circle Rewards
Program
or similar offers, we may provide discounts, perks, or other
benefits in exchange for collecting and using personal information (e.g.,
identifiers, purchase history, engagement). Participation is optional, and you may withdraw at any time via account settings or by emailing support@korres.com.
The value of the program is reasonably related to the value of the personal
information collected, as reflected by the good‑faith estimated value of
discounts, perks, and increased engagement. Material terms (what data is collected; how to opt in/out; and a non‑discrimination commitment) are
presented at sign‑up and may be updated from time to time.

17. Contact

If you have any questions regarding this Privacy Policy, please contact our Privacy Team by email at support@korres.com or by mail.

KORRES
80 Maiden Lane
New York, NY 10038

Accessibility: If you need this Policy in an alternative format, please contact support@korres.com.

Last reviewed: September 1, 2025.