Privacy policy

INTRODUCTION


OATLY, INC. (“OATLY”) respects your privacy and are committed to protecting it through our compliance with this policy. This Privacy Policy describes how we collect and use the personal information you provide to us on our website, us.oatly.com, or when you engage with us via our social media (collectively the “Site”), and how we use that information, including with whom we share it, and your choices regarding our use of the information. We also describe how you can contact us with questions and requests pertaining to your privacy. This Policy is specific to the US-based Site and US-based users.

By using the Site, you agree to the collection and use of your personal information in accordance with this Policy.


COLLECTION AND USE OF PERSONAL AND NON-PERSONAL INFORMATION


We collect personal and non-personal information from you to provide and improve our products and services. “Personal Information” means information that personally identifies you, such as your name, email address, shipping and billing address, phone number, and credit card number or other financial information used to pay or process payment. “Non-Personal Information” means information that relates to you but does not directly identify you such as type of technology or browser you are using to access our Site (mobile, desktop, tablet, etc.).

We may collect the following personal information about you:

  • Contact Information such as your name, email address, mailing address and phone number
  • Date of birth
  • Billing Information such as your credit card number and billing address, though we do not maintain this information on our servers.
  • Unique Identifiers such as user name, account number and password
  • Information provided to us through social media networks when you access our Site via said networks (this could include your name, profile picture, and other personal information, as well as non-personal information).

We collect the following non-personal information about you:

  • Information about your computer or device, including IP address, time and date of visit, browser type and version, operating system, device make and model
  • The pages of our Site you visit, the time spent on our Site, referring and exit pages
  • Information such as product wish lists/shopping carts, order history, searches on the Site, product and marketing preferences, browsing habits, and other available data points and statistics, including information in survey responses or feedback you provide to us
  • Contact information of friends or other people you would like us to contact or connect with
  • Information provided to us through social media networks when you access our Site via said networks (this could include your “likes” and other online engagement activity, location, friends list, and other information depending on the social network).

We obtain personal and non-personal information in the following ways:

  • Directly from you, including via the Site, email, text, and other electronic messages between you and us
  • Indirectly from you, via automated means (such as our servers logging your IP address and related information)
  • From third parties and through technologies like cookies and web beacons


INFORMATION WE COLLECT BY AUTOMATED MEANS


When you visit the Site, or view or click on our online advertisements (including our advertisements on third party websites), we also collect certain information about you, your device, your online activity, and your usage of the Site by automated means via third-party technologies such as cookies, web server logs and web beacons. For example, when you visit our Site, we may collect your IP address, your unique device identifier (or other device identifier) and/or geolocation data in order to offer you certain features or functionalities. As set forth in more detail below, we may also collect information about your usage and browsing habits using various web-based technologies, including cookies and web beacons. We also may use these technologies to collect information about your online activities over time and across third-party websites or other online services (behavioral tracking). While the information we collect automatically may only be statistical data and may not include personal information, we may maintain it or associate it with personal information we collect in other ways or receive from third parties for any of the purposes expressed in this policy.


TECHNOLOGIES WE USE: COOKIES, WEB SERVER LOGS AND WEB BEACONS


Cookies are small text files that websites send to your computer or other Internet-connected device to uniquely identify your browser or to store information or settings in your browser. Your browser may tell you how to be notified when you receive certain types of cookies and how to restrict or disable certain cookies. Please note, however, that without cookies you may not be able to use all of the features of the Site.

In conjunction with obtaining information through cookies, our web servers may log details such as your operating system type, browser type, domain, and other system settings, as well as the language your system uses and the country and time zone in which your device is located. The web server logs also may record information such as the address of the web page that linked you to the Site and the IP address of the device you use to connect to the Internet.

To control which web servers collect this information, we may place tags on our web pages, emails, advertisements, or content called “web beacons.” These are computer instructions that link web pages to particular web servers and their cookies. Web beacons are sometimes known as clear gifs, pixel tags, and single-pixel gifs and also track engagement, visitor counts, and other statistics.

Our website is powered by Shopify. Information on Shopify cookies is available here: https://www.shopify.com/legal/cookies.


THIRD PARTY WEB ANALYTICS SERVICES


We may use third party web analytics services on the Site, such as Google Analytics. The service providers that administer these services use technologies such as cookies, web server logs and web beacons to help us analyze how visitors use the Site.

The information collected through these means (including IP address) is disclosed to these service providers, who use the information to evaluate use of the website. You may deactivate the ability of these analytics services to analyze your browsing activities on the Site. These providers of third-party web analytics services have their own terms and conditions and privacy policies. OATLY does not control what these providers do with information they collect.


TARGETED ADVERTISING


We also may contract with third-party advertising networks that collect information about you through the use of cookies, web server logs and web beacons on our websites and emails; on third-party websites and emails; and on our advertising placed on third-party websites. They use this information to provide advertisements about products and services tailored to your interests (including for companies not affiliated with us). You may see these advertisements on the Site and other websites or on social media. This process also helps us manage and track the effectiveness of our marketing efforts. To learn more about advertising networks and to opt out of interest-based advertising, visit the Digital Advertising Alliance at www.aboutads.info/choices or the Network Advertising Initiative at www.networkadvertising.org/choices.


DO NOT TRACK REQUESTS


There is no industry standard approach to sending, processing, and addressing Do Not Track requests from browsers, and please note that the Site does not respond to these Do Not Track requests at this time. More information on “Do Not Track” requests is available here: https://allaboutdnt.com/


HOW WE USE AND SHARE INFORMATION


We use the information we obtain to provide you with the Site; our products and services; identify and communicate with you (including marketing and promotional communication) through various channels and mediums, including when you return to the Site; respond to your requests and inquiries; notify you about the Site our services, including your order or your account; service your purchase orders; and monitor, analyze, and improve the Site and our products and services. We also use the information to tailor ads displayed to you on our site and elsewhere. We use information to operate, evaluate, and improve our business and to comply with legal requirements, relevant industry standards, and our policies, and enforcing this policy and our Terms of Service. We may use your personal information if we need to collect a debt from you, as well. If we use your information in other ways, we will provide notice to you at the time we collect that information.

We may disclose aggregated information about our users or visitors to the Site, and information that does not directly identify any individual.

We may disclose personal information that we collect or you provide as described in this privacy policy:

  • Without our company and to our subsidiaries and affiliates.
  • To contractors, service providers, and other third parties we use to support our business and who are bound by contractual obligations to keep personal information confidential and use it only for the purposes for which we disclose it to them.
  • To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Oatly's assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by Oatly about our Website users is among the assets transferred.
  • To fulfill the purpose for which you provide it.
  • For any other purpose disclosed by us when you provide the information.
  • With your consent.
  • If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of Oatly, our customers, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.

If you do not wish to have your email address/contact information used by the Company to promote our own or third parties' products or services, you can opt-out by checking the relevant box located on the form on which we collect your data (the order form) or at any other time by logging into the Site and adjusting your user preferences in your account profile by checking or unchecking the relevant boxes or by sending us an email stating your request to info.us@oatly.com. If we have sent you a promotional email, you may send us a return email asking to be omitted from future email distributions. This opt out does not apply to information provided to OATLY as a result of a product purchase, warranty registration, product service experience or other transactions. Also, you may still receive certain operational emails regarding your account, orders, or other non-promotional materials.

California residents may have additional personal information rights and choices. Please know we do not sell your personal information and see the section below pertaining to California residents.

Nevada residents who wish to exercise their sale opt-out rights under Nevada Revised Statutes Chapter 603A may submit a request to this designated address: info.us@oatly.com. However, please know we do not currently sell data triggering that statute's opt-out requirements.

Note that if you delete your User Contributions from the Website, copies of your User Contributions may remain viewable in cached and archived pages, or might have been copied or stored by other Website users. Proper access and use of information provided on the Site, including User Contributions, is governed by our Terms of Service, available here: https://us.oatly.com/pages/terms-of-service.


TRANSFER OF PERSONAL INFORMATION TO OTHER JURISDICTIONS


OATLY is located in the United States, and if you are located outside of the United States, your personal information may be transferred and proceed within the United States as part of our normal business operations. Data protection laws vary from country to country, and may be different from the country from where you access the Site. By using our Site or services, you consent to the transfer and processing of personal information by OATLY and our third party service providers who perform services on our behalf based on our instructions.


ACCESSING AND CORRECTING YOUR INFORMATION


You can review and change your personal information by logging into the Site and visiting your account profile page. You may also send us an email at info.us@oatly.com to request access to, correct or delete any personal information that you have provided to us. We may not be able to delete your personal information except by also deleting your user account. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect. If we cannot verify that the request for information, or to change or delete information, can from you and you are authorized to make such a request, we may not be able to comply with your request.


CHILDREN’S PRIVACY


The Site is not directed at children under the age of thirteen and we do not knowingly collect personal information from children under the age of thirteen. If we become aware that we have inadvertently received personal information from a visitor under the age of thirteen on the site, we will delete the information from our records. If you are between 13 and 16 years old, you are required to get consent from your parent(s) or guardian(s) before accessing the site. If we become aware that we have inadvertently received personal information from a visitor aged 13-16 without parental consent, we will delete the information from our records.

You may request to review, change or delete your personal information or that of your minor child.

To make such a request, please email us at info.us@oatly.com

 

ADDITIONAL INFORMATION FOR CALIFORNIA RESIDENTS - CALIFORNIA PRIVACY RIGHTS


If you are a California resident, California law may provide you with additional rights regarding our use of your personal information. To learn more about your California privacy rights, visit https://oag.ca.gov/privacy/ccpa.

The California Consumer Privacy Act (“CCPA”) provides California residents with the additional rights listed below, subject to certain exceptions. This section applies only to those California residents to whom the CCPA applies (“California Resident” or “You”) and does not apply to any Personal Information, as defined in the CCPA (“PI”), that is excepted from the CCPA. All capitalized words in this section have the definitions given to them in the CCPA unless noted.

California Residents have the right to:

  1. Request disclosure of our data Collection and sales practices in connection with you, including the categories of PI we have collected, the source of that PI, our use of that PI and, if the disclosed or Sold to third parties, the categories of PI disclosed or Sold to third parties and the categories of third parties to whom such PI was disclosed or Sold;
  2. Request a copy of the specific PI collected about you during the 12 months before your request made under the previous paragraph;
  3. Have such PI deleted (with exceptions);
  4. Request that your PI not be Sold to third parties, if applicable (Right to Opt Out); and
  5. Not be discriminated against because you exercised any of these rights.

Right to Request and Right to Know. You have the right to know and what PI we have Collected about you over the past 12 months, and the right to request that PI, including:

  • The categories of PI we have collected about you;
  • The categories of sources from which the PI is collected;
  • The Business purpose or Commercial purpose for Collection of your PI;
  • The categories of Third parties with whom we have shared your PI; and
  • The specific PI we have Collected about you.
  • You may exercise the Right to Request no more than twice a year.
CategorySource
1.Identifiers (such as contact information, government IDs, cookies, etc.)A, B, C
2.Information protected against security breaches (such as your name and financial account, driver’s license, social security number, user name and password, health/medical information)[NOT COLLECTED]
3.Protected classification information (like race, gender, ethnicity, etc.)[NOT COLLECTED]
4.Commercial information[NOT COLLECTED]
5.Internet/electronic activityA, B, C
6.GeolocationC (based on IP address)
7.Audio/video data[NOT COLLECTED]
8.Professional or employment related information[NOT COLLECTED]
9.Education information[NOT COLLECTED]
10.Biometrics[NOT COLLECTED]
11.Inferences from the foregoingA, B, C

Key to Sources:

Source
AIndividual submitting the information
BThird party from whom we receive the information
CObserving activities and recording the information (i.e., through cookies) Please see our Cookie Policy – available here: https://us.oatly.com/pages/cookie-policy.

We collect Personal Information for one or more of the following commercial and business purposes, in addition to what is otherwise disclosed in this Privacy Policy:

  • Providing you with our products and services, including the Site;
    Auditing related to a current interaction with the consumer and concurrent transactions, including, but not limited to, counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with laws and other standards;
  • Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity;
  • Performing services on behalf of the business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, or providing similar services on behalf of the business;
  • Marketing and advertising our products and services to you based on your advertising preferences;
  • Debugging to identify and repair errors that impair existing intended functionality;
  • Undertaking internal research for technological development and demonstration; and
  • Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the company, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business.
  • If we collect any additional PI for any other purpose, we will notify you of that purpose at the time we collect the PI for that purpose.

If we disclose PI for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that PI confidential and not use it for any purpose except performing the contract. We share PI with the following categories of Third parties: payment processors and shipment vendors, business consultants, select marketing and advertising providers, and other service providers. We do not sell PI.

Right to Opt Out. We do not Sell PI. If we do engage in an activity determined to be a Sale of your PI, you have the right to direct us to not Sell your PI and we will place a “Do Not Sell My Information” link in the bottom footer of the Site which you will be able to use to submit a form for this purpose.

Right to Delete. You have the right to request that we delete the PI we have Collected from you (and direct our service providers to do the same). There are a number of exceptions, however, that include, but are not limited to, when the PI is necessary for us or a Third party to do any of the following:

  • Complete your transaction;
  • Provide you a good or service;
  • Perform a contract between us and you;
  • Protect your security and prosecute those responsible for breaching it;
  • Fix our system in the case of a bug;
  • Protect the free speech rights of you or other users;
  • Comply with the California Electronic Communications Privacy Act;
  • Engage in public or peer-reviewed scientific, historical, or statistical research in the public interests that adheres to all other applicable ethics and privacy laws;
  • Comply with a legal obligation; or
  • Make other internal and lawful uses of the information that are compatible with the context in which you provided it.

Other Rights. You can request certain information about our disclosure of PI to third parties for their own direct marketing purposes during the preceding calendar year. This request is free and may be made once a year. You also have the right not to be discriminated against for exercising any of the rights listed above. If you are a California Resident, California Civil Code Section 1798.83 permits you to request information regarding the disclosure of your PI to third parties for the third parties’ direct marketing purposes. To make such a request, please send an email to info.us@oatly.com. Pursuant to California Civil Code Section 1798.83(c)(2), we do not share your PI with third parties’ direct marketing use without your consent.

Exercising Your California Privacy Rights. To request access to or deletion of your PI, or to exercise any other data rights under California law, please contact us using one of the following methods:

Email: You may email us at info.us@oatly.com to exercise your California rights. Please include your full name, email address, and other identifying information such that we will be able to verify your identity, along with why you are writing, so that we can properly process your request. We are only able to handle your request if you provide the requested information needed to verify your identity.

Before we take any action on any request exercising a CCPA right, we must reasonably verify your identity. If we attempt to, but cannot do so, we will not be obligated to you under the CCPA. We will reach out to you by the method of communication through which you reached out to us, and let know that we are unable to verify your identity.

Any subsequent interaction with the Site after a request for deletion, or deletion, of PI will require new requests for action on your data.

Response Timing and Format. We aim to respond to a consumer request for access or deletion within 45 days of receiving that request. If we require more time, we will inform you of the reason and extension period in writing.


DATA SECURITY


We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. All information you provide to us is stored on our secure servers behind firewalls. Any payment transactions and website traffic will be encrypted using SSL technology.

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Website, you are responsible for keeping this password confidential. Do not share your password with anyone. We urge you to be careful about giving out information in public areas of the Site like the comments section. The information you share in public areas may be viewed by any user of the Site.

Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to the Site. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Site.


LINKS TO OTHER WEBSITES


The Site may provide links to other websites for your convenience and information. These websites may operate independently from us. Linked sites may have their own privacy notices or policies, which we strongly suggest you review if you visit any linked websites. To the extent any linked websites you visit are not owned or controlled by us, we are not responsible for the sites’ content, any use of the sites, or the privacy practices of the sites.


CHANGES TO OUR PRIVACY POLICY


We reserve the right to make changes to this policy at any time, so please review it frequently. It is our policy to post any changes we make to our privacy policy on this page. Changes to this policy will take effect immediately unless otherwise noted. If we make material changes to how we treat your personal information, we will notify you by email to the email we have on file. The date the privacy policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date, active, and deliverable email address for you, and for periodically visiting our Site and this privacy policy to check for any changes. Your continued use of the Site after being notified of, or becoming aware of, a chance in this policy, is your affirmation that you have read and understood this policy, agree to it, and agree to be bound by it.


CONTACT INFORMATION


To ask questions or comment about this privacy policy and our privacy practices, contact us:

By email: info.us@oatly.com
By mail: Oatly
220 E 42nd St, Ste. 409A
New York NY 10017
United States

 


Last modified: January 27, 2021