Customer commitment to data protection and privacy  

Protecting personal data and your privacy is of greatest concern for All In Equestrian.  
In this Privacy Notice we want to give a clear, concise, and transparent communication on the collection, use, processing, storing etc. of personal data relating to customers of All In Equestrian.  

All In Equestrian is a brand within the H&M Group. The H&M Group consists of company affiliates of H & M Hennes & Mauritz AB.  

Within the meaning of this Privacy Notice “customer of All In Equestrian” means former, current and potential customer or user and recipients of a product or service offered by All In Equestrian, and visitors to our official websites.  

All In Equestrian manifests its commitment to privacy and data protection by embracing the following principles.  

All In Equestrian uses personal data lawfully, fairly, correctly and in a transparent manner.  
All In Equestrian collects no more personal data than necessary, and only for a legitimate purpose.  
All In Equestrian retains no more data than necessary or for a longer period than needed.  
All In Equestrian protects personal data with appropriate security measures.  

 

Who is responsible for processing of your personal data?  
The Swedish company, All In Equestrian AIE AB (Reg no: 556023-1663), Mäster Samuelsgatan 46, 106 38 Stockholm, Sweden is responsible for the processing of personal data within the scope of this Privacy Notice.  

 
 

Where do we process your data?  
The personal data that we collect from you is generally stored within a country of the European Union or the European Economic Area (“EU/EEA”) but may also, whenever necessary, be transferred to and processed in a country outside of the EU/EEA. Any such transfer of your personal data will be carried out in compliance with applicable laws and without undermining your statutory rights.  

From time to time, we may transfer personal data from the EU/EEA to a third country not being approved by European commission as a safe country for such transfer (adequacy decision). Whenever applicable All In Equestrian will use Standard Contractual Clauses to ensure an equivalent level of protection as granted within the EU/EEA or other lawful grounds for transfer.  

 

Who has access to your data?  
Your personal data is available and accessible only by those who need the data to accomplish the intended processing purpose. To the extent necessary, your personal data may be shared between the companies and brands within the H&M Group, with suppliers, sub-contractors and independent third parties (acting as processors and sub-processors) carrying out certain tasks on All In Equestrian’s behalf.  

In addition, we may also disclose personal data to third parties, if we have reason to believe that using or disclosing such information is necessary or advisable to: (i) conduct investigations of possible breaches of law; (ii) identify, contact, or bring legal action against someone who may be violating an agreement they have with us; (iii) investigate security breaches or cooperate with government authorities pursuant to a legal matter; or (iv) to protect our rights, safety or property, including the prevention of fraud.  

Except as explicitly stated herein, we never pass on, sell or swap your data with any third parties. General Information  

We reserve the right to transfer any personal data we have about you in the event that we merge with or are acquired by a third party, undergo another business transaction such as a reorganization, or should any such transaction be proposed.  

 

Why do we process your personal data?  

All In Equestrian is not allowed to collect, process, use, store etc. personal data without a valid legal ground. Lawfulness may be derived from your consent, by contract, statutory obligations or from our legitimate interest as a business. For each specific purpose of processing of personal data, we will inform you about which legal ground that will apply, what rights you are entitled to exercise, whether the provision of personal data is statutory or required to enter a contract and whether it is an obligation to provide the personal data and possible consequences if you choose not to.  

 

What are your rights?  

Right to access: 
You have the right to request information about the personal data we hold on you at any time.  

Right to portability:  
Whenever All In Equestrian processes your personal data, by automated means based on your consent or based on an agreement, you have the right to get a copy of your data transferred to you or to another party. This only includes the personal data you have submitted to us.  

Right to rectification:  
You have the right to request rectification of your personal data if the information is incorrect, including the right to have incomplete personal data completed.  

Right to erasure: 
You have the right to erase your personal data processed by All In Equestrian at any time. Your request may be hindered if any of the following situation apply:  

  • you have an ongoing matter with Customer Service  
  • you have an open order 
  • you have an unsettled balance with us 

Right to object to processing based on legitimate interest:  
You have the right to object to processing of your personal data that is based on All In Equestrian’s legitimate interest. All In Equestrian will not continue to process the personal data unless we can demonstrate legitimate grounds for the process which overrides your interest and rights or due to legal claims.  

Right to restriction:  
You have the right to request that All In Equestrian restricts the process of your personal data under the following circumstances:  

  • if you object to a processing based All In Equestrian’s legitimate interest, All In Equestrian shall restrict all processing of such data pending the verification of the legitimate interest.  
  • if you have claim that your personal data is incorrect, All In Equestrian must restrict all processing of such data pending the verification of the accuracy of the personal data.  
  • if the processing is unlawful you can oppose the erasure of personal data and instead request the restriction of the use of your personal data instead  
  •  
    if All In Equestrian no longer needs the personal data but it is required by you to defend legal claims.  

Right to withdraw your consent:  

For each processing purpose you have given us your consent, you have the right to withdraw your consent at any time. If you do so, we will stop the processing of your personal data for that specific purpose. 

How do you exercise your rights?  
We take data protection very seriously. If you wish to exercise your rights as set out above or if you have any questions about our privacy policy or our processing of your data, you can contact us at any time at support@allinequestrian.com.  

 
Right to complain with a supervisory authority:  
If you have complaints about the way All In Equestrian processes and protects your personal data and privacy you have the right, at any time, to make a complaint to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten - IMY) or any other competent a supervisory authority in the country of residence.  

Updates to our Privacy Notice:  

We may need to update our Privacy Notice. The latest version of the Privacy Notice is always available on our website.  

 

How do we process your personal data and why?  

Depending on how you interact with us or what type of service you are using we will process your personal data for the following purposes: 

Online shopping 

Purpose for processing 

Type of personal data 

To be able to process your purchase order and handle payment transactions. 

 

To be able to manage your deliveries, claims, warranty matters, returns and refunds in a secure and effective manner and to be able to notify you of the details and the status of such matters.  

 

To be able to deliver and follow-up requested services including discount codes, on the website or app, identify and contact you when needed. 

 

  • Contact information (e.g., name, phone number, email address, delivery address) 
  • Customer number (when applicable) and transactional data 
  • Payment data 

 

Lawful basis: When making products and services available to you we will process your personal data necessary for fulfilment of a contract with you and to fulfil any obligations derived from that contract, whether the contract refers to a purchase order and payment, or the use of other services provided by us or by third parties. When you need to make a return or claim a consumer right, we will process your personal data to fulfil obligations derived from concluding a contract with us, whether the contract refers to a purchase transaction, or the use of other services provided by us or by third parties.  

For any other purpose referred to herein, the process of your personal data is based on our legitimate interest as a business. 

Retention time: We will keep and process your personal data no longer than necessary for us to perform our contractual and consumer obligations. 

 

 

Marketing and Promotions 

Purpose 

Type of personal data 

To be able to generate and distribute marketing materials, such as newsletters, including style and shopping recommendations through multiple communication channels where applicable. 

To be able to provide you with a personalized online experience. 

  • Contact information (e.g., name, phone number, email address) 
  • Customer Number (if applicable) 
  • user-generated data (e.g. product/style preference, purchase, click and browsing history). 

Further info. Marketing and promotions will be sent and displayed to you according to your preferences through email, text messages and postal mail as well as displayed in your social media channels or web browser.  

We also provide you with a personalized online experience by giving you personalized marketing based on your interactions with us and analytics of your customer behaviour on our websites, such as your purchase and browsing history. 

Advertising partners. To be more efficient in our marketing we collaborate with different social media, search engine and advertising network providers ("Advertising Partners"). 

We collaborate with advertising partners such as Facebook, Instagram, Snapchat, Pinterest, TikTok and YouTube for advertising on social networks and with Google for online advertising networks such as Google Ads and Google Marketing Platform. 

We also collaborate with Rakuten for affiliate (influencer) marketing and to drive traffic to our web sites. 

How this works: Advertising partners use data provided by us and collected from cookies and other tracking technologies to predict your preferences and interests and take this into account when creating your personalized ad. This is standard industry practice commonly known as "retargeting". Retargeting allows us to run relevant advertising campaigns to you and to measure the efficiency and reach of the advertising materials. It also helps us to measure the advertising partners’ performance and efficiency of campaigns.  

Advertising partners use cookies and similar technologies to trace your usage of our websites and services by accessing data stored on your device or in apps. 

Our Advertising Partners enable us to identify and engage with the right target audience, to create and distribute personalized marketing content across platforms and services. To be able to choose the content that fits your interests, we can use information obtained from you as a member, account holder, newsletter subscriber or if you have made a purchase with us. We may share this information and a customer identifier, e.g. an encrypted email address or device id, with our Advertising partners. The purpose is to show relevant ads to you on third party websites and apps. In order to do this, your data is matched with the database of the Advertising partner. If a match is found, you will receive relevant promotional content in your feed or search engine. If no match is found your data is securely destroyed.  Your personal data is handled in a secure manner using a technique called hashing.  This ensures your data is scrambled in a manner that makes it unreadable to anyone other than the recipient for the explicit given purpose. 

Each Advertising Partner is responsible for their part of the processing as controllers, including (if any) transfers of personal data to non-EEA countries. 

Lawful basis: We will obtain your consent when you sign up for personalized newsletters. 

We will also ask for your consent regarding marketing that is based on cookie data or other tracking technologies. When sharing your personal data with Advertising Partners for the purpose of optimizing ad targeting, we process your personal data based on our legitimate interest as a business. If you're an account holder or a subscriber you may hear from us in other channels, such as social media. For this processing we rely on our legitimate interest as business to promote our marketing to you. 

Retention time: We will process your data no longer than necessary to provide you with marketing and promotions. We will cease processing your data for marketing purposes once you have closed your customer account and/or actively rejecting further marketing communication from us. 

 

My Account  

Purpose 

Type of personal data 

To be able to create and administrate your account, such as identify and certify you as the user of the account. 

To be able to make your purchase information and history available to you and to bring you a seamless account experience and granted services. 

To be able to locate and authenticate your account. 

  • Contact information such as name, e-mail address and telephone number 
  • Purchase history 
  • User-generated data (e.g. purchase, click and browsing history). 

If you have signed-up to receive marketing and promotions, we will use your account data to make the marketing you receive from us more relevant to you. 

Lawful basis: The processing of your personal data for your account is based on your consent when you create your account. The processing of your personal data to provide you with granted services and features to improve your account experience such as product recommendations is based on our legitimate interest as a business. 

Retention time: We will use your personal data no longer than necessary for making the account available to you. Personal data solely collected and used for the purpose of providing you with an account will be erased upon termination. 

 

Customer Service 

Purpose 

Type of personal data 

To be able to manage your questions, handle complaints and warranty matters and to provide technical support as well as to improve customer experience. 

To be able to contact you, if needed, through email, telephone, Social Media or any other means in response to your enquiries regarding order, delivery or return questions or to request your participation in a customer survey. 

  • Contact information such as name, e-mail address and telephone number 
  • Customer number and internal interaction log 
  • User generated content, such as emails and chat transcript 

To resolve your case, we may also need to access and use transaction data such as order, payment, and delivery information. 

Lawful basis: The processing of your personal data to provide you with the best possible Customer Service is based on our legitimate interest as a business.  

Retention time: We will keep your data for as long as we need to be able to support you regarding your case and, to be able to handle potential legal claims from you as a customer. We may continue to keep and use your data if we have outstanding obligations to you or by any other reasons are prevented from erasure. 

 

Competitions & Events 

Purpose 

Type of personal data 

To be able to administrate and follow up on competitions and events, such as confirming participation, contact winners, deliver, and follow up on prize deliveries, reach out to you with relevant information about the competition and/or event and grant you access to the venue where the event is held. 

To be able to market our events improve our services, marketing, customer relationships and experiences and to plan better future events and attendee experience. 

 

  • Contact information such as name, address, e-mail address and telephone number 
  • information submitted in the contest 
  • Photo/video 

We sometimes film and photograph at our events, and the content will be used to market our services and to promote future events on our website, social media channels and in marketing materials. We will also use the content for internal use. You will be notified if we intend to photograph/film at an event. There will always be photo free zones for your convenience. 

Lawful basis: The processing of your personal data in order to make a competition or an event available to you is based on our legitimate interest as a business. 

Retention time: We will keep your personal data for as long as necessary for us to fulfil the purposes mentioned above and to fulfil any legal obligations connected.  

 

Business Development & Analytics 
 

Purpose 

Type of personal data 

To be able to evaluate, develop and improve our products, services, customer experience and supply chain. This includes analysis to make our services more user-friendly, such as modifying the user interface to simplify the flow of information or to highlight features that are commonly used by our customers.  

To be able to reach out to you to collect feedback or conduct surveys. In such case, any personal data used and obtained from you will only be processed for the specific purpose described therein. 

To be able to perform analytics and segmentation to provide you with improved shopping experience. 

To be able to share personal data with our Advertising Partners for the purpose of optimizing ad targeting.  

  • Delivery address  
  • Purchase history  
  • Customer number 
  • Order number  
  • User-generated data (eg purchase, click and browsing history).  

Any data used for the purpose of development and improvement have been collected for different objectives. We may for example use online transaction data for the purpose of developing our online order system. All analysis is carried out on an aggregated data level.  

 

 

Lawful basis: The processing of your personal data for the purpose to develop and improve our services and products, is based on our legitimate interest as a business. 

Retention time: We will process your personal data no more than necessary for us to fulfil the purpose. Thereafter the data will be immediately erased for this type of use. 

 

Compliance with Laws  

Purpose 

Type of personal data 

To comply with certain legal obligations. In order to comply with local law, we are obliged to process certain personal data. Such obligations may vary from country to country stipulated in for example tax, accounting, book-keeping, sanctions, and consumer legislations. 

What type of personal data we process are stipulated by the applicable law.  

Lawful basis: The processing of your personal data is necessary for All In Equestrian to fulfil its legal obligations of the country of operation. 

Retention time: The data retention time will vary depending on the purpose, context and specific local legal requirements. 

 

Security & Loss Prevention 

Purpose 

Type of personal data 

To be able to protect our customers, users, visitors, assets and business against fraud, theft, misuse and other malicious activities. 

  • order history 
  • payment data 
  • shopping behaviour  
  • IP address 

Lawful basis: Unless there is a specific legal obligation, the processing of your personal data for security and safety purposes is based on our legitimate interest. 

Retention time: We will keep your personal data no more than necessary for each purpose.  

 

Content shared by you 

Purpose 

Type of personal data 

To be able to provide you with a service for customer engaged marketing. 

To be able to share your photos and/or videos on our official websites, social media pages and in other promotional channels.  

  • Photo 
  • Video 
  • Username 

Lawful basis: The processing of your personal data is based on the contract of the service that you have agreed to.  

Retention time: We will keep your username and generated content for 24 months from the date of posting. If you want to remove the content, please go to the photo/video were its published by H&M Group and press "report photo" or contact the customer service of the relevant brand. Please note, by hash-tagging your picture or video clip you voluntarily share the content and other personal data with Instagram or other social media platforms. This relationship is outside of H&M's control and a matter between you and the social media service provider.