Privacy Policy

Updated: Effective as of April 28, 2026

Please also visit our Terms of Use section that explains other terms governing the use of our website.

This Privacy Notice applies to personal information collected when you use websites managed by TOMS Shoes, LLC or TOMS EMEA B.V. See the section titled 'Questions and Feedback' for the full list of Sites, applicable TOMS entity (as data controller), and contact details.

At TOMS, we are committed to protecting the privacy and security of your personal information in accordance with local law in the places where we operate (see details below). To learn more, please read this Privacy Notice.

This Privacy Notice describes the types of personal information we collect and our data processing practices including how we use this information and when (under certain circumstances) we disclose this information. This Privacy Notice also describes your data protection rights, including a right to object to some of the processing which we carry out. For more information on your rights, please see the "Your Rights" section below.

Our Sites contain links to other websites which are not included in the Questions and Feedback section below and are not managed by us. We are not responsible for the content on, or privacy practices of, any non-TOMS website to which this Site links. We advise you to read those websites' privacy notices to find out more about their privacy practices.

1. Personal Data We Collect

We collect and process the following personal information about you:

Category Details
Identification Data Your name, user credentials, country of residence
Contact Data Your email address, telephone number and postal address
Transaction Data Information about your purchases, your billing and shipping addresses and payment details
Preference Data If you provide these, your communication preferences (for example, whether you are interested in women's, men's or kid's shoes, or whether you are interested in hearing about sustainability & vegan styles, or TOMS impact). We also collect your gender and the month and year of your birthday.
Communications Data Information you provide when you contact us directly or provide feedback, comments or suggestions about our products and services. This includes transcripts of Live Chat conversations and call recordings when you contact our customer support teams.
Technical Data Information about your device or browser when you use our Sites, including your internet protocol (IP) address, device ID, browser type and version and time zone setting.
Usage Data Information about how you use our Sites including the pages and products that you view.
Social Network Data Basic profile information including name, email address, gender, birthday, current city, profile picture, user ID, contact lists, etc. and other information you allow to be shared.
Review Data TOMS will require a valid registered email address and a review name when it comes to completing the review form on the Sites in relation to a specific TOMS product. Following the moderation process, your review, alongside your review name and date, may be posted on the Sites.

2. How We Collect Personal Information About You

We collect personal information: (i) directly from you when you interact with our Sites, complete registration forms, or purchase products; (ii) automatically through cookies, pixels and similar tracking technologies when you use our Sites (see Section 6 — Cookies); and (iii) from third-party social networks and other sources described below.

We also receive data from third party social networks: This includes from Meta (Facebook and Instagram), TikTok, YouTube, Pinterest, Snapchat, and X (formerly Twitter).

If you fail to provide us with necessary personal information that we have requested: Data that is mandatory is indicated on relevant forms that you complete. If mandatory data is not provided, we cannot fulfil your registration or other requests. All other fields are optional.

3. Information Use and the Legal Bases for Such Use

In this section we explain for which purposes we collect and use your personal information. Where we use your personal information for a particular purpose, we must ensure that we have a 'legal basis' under data protection law. We have set out below a description of the legal bases on which we rely under data protection law to use such information.

Purpose Categories of Personal Data Legal Basis
To process your orders and communicate with you about your orders and deliveries (including, by sending you a confirmation email when you register/place an order with us). Identification Data, Contact Data, Transaction Data, Communications Data Contractual necessity: to the extent the processing is necessary to fulfil our contract with you.

Legitimate interests: where this processing is not strictly necessary to fulfil our contract with you.
To deliver products to you. Identification Data, Contact Data, Transaction Data Contractual necessity: to fulfil our contract with you.
If you open a TOMS account, we will use this information to effectively manage your account (e.g. send you an account activation email or process any changes you make to your account). Identification Data, Contact Data, Transaction Data, Preference Data, Communications Data Contractual necessity: to the extent the processing is necessary to fulfil contractual obligations relating to your TOMS account.

Legitimate interests: i.e. to effectively manage your account and enable account features (e.g. order tracking) where this is not strictly necessary to fulfil our contractual obligations.
To manage our relationship with you including to review feedback from you and to respond to your queries and complaints and otherwise assist you. Identification Data, Contact Data, Transaction Data, Preference Data, Communications Data Contractual necessity: to the extent the processing is necessary to perform our contract with you.

Legitimate interest: to manage our business and customer relationships where this is not strictly necessary to fulfil our contract with you.
Where you contact our customer support team by telephone call, we record telephone calls. Identification Data, Contact Data, Transaction Data, Preference Data, Communications Data Legitimate interests: in order to ensure we provide high quality customer support services to our customers and to train our customer support team.
To notify you of changes to our terms and conditions or privacy notice. Identification Data, Contact Data To comply with a legal obligation: for example, where consumer or data protection law requires us to notify you of changes.

Legitimate interests: to communicate changes to manage our customer relationships where this is not strictly required by law.
To send you marketing communications about TOMS, including offers about our products and services, or to send you our newsletter when you sign up to receive this and to monitor whether you open our emails and/or click on URLs in our emails. Identification Data, Contact Data, Transaction Data, Preference Data, Usage Data, Technical Data Your consent where this is required by law. Otherwise, we rely on our legitimate interest to keep you informed of TOMS products and services, when we are allowed by law to do so.
To create marketing profiles about our customers and understand their preferences in relation to our products and services and to personalise marketing communications based on those profiles. Identification Data, Contact Data, Transaction Data, Preference Data, Usage Data Your consent when the processing involves use of cookies (for example, where we collect information about recently viewed products).

Legitimate interests: to understand our customers and deliver marketing communications which are more relevant to them.
To display our advertisements to you on other platforms, such as social media platforms. For example, we provide Meta with hashed identifiers (e.g. hashed email addresses) of our customers which Meta then matches with those customers' Facebook and Instagram profiles and displays our advertisements to them. Identification Data, Contact Data Your consent where this is required by law. Otherwise we rely on our legitimate interests to carry out marketing activities and inform you of TOMS products and services when we are allowed by law to do so.
We also use personal information of our customers to allow social media platforms (e.g. Meta) to find individuals who have a similar profile to our customers and who we expect are interested to find more about our products and services, so as to display our ads to them ("Lookalike matching"). Identification Data, Contact Data Your consent where this is required by law. Otherwise we rely on our legitimate interests to carry out marketing activities and promote TOMS products and services when we are allowed by law to do so.
If you use our Live Chat function, we will use your information for dealing with your query, training and customer service purposes. Identity Data, Contact Data, Communications Data Contractual necessity: to the extent the processing is necessary to fulfil our contract with you (e.g. to complete and process your order).

Legitimate interests: to handle your queries and provide you with requested information, to ensure high customer service quality and to train staff in responding to such requests where this is not strictly necessary to perform our contract with you.
To operate our pages on social media platforms. Identity Data, Social Network Data Legitimate interests: to promote our brand on social media platforms and interact with customers and prospective customers on those platforms.
To compile statistics and analysis about the use of our Site and related services (e.g. product orders), and use such statistics to enable us to provide a better service, features and functionality to you and other Site users. Identification Data, Contact Data, Transaction Data, Technical Data, Usage Data Your consent: where we obtain this information by using cookies or similar technologies.

Legitimate interests: to ensure the smooth and effective functioning of our Site and services, to make sound business decisions about our products and services and to design, inform and deploy our business strategies.
To create aggregated and anonymous statistics relating to our business (e.g. sales figures for a particular region). Identification Data, Contact Data, Transaction Data Legitimate interests: To obtain metrics relating to our business.
To protect the security of our Sites, information systems and assets, to monitor compliance with our Terms & Conditions, to prevent fraud and other prohibited or illegal activities in relation to our products and our Sites. Identification Data, Contact Data, Transaction Data, Technical Data, Usage Data To comply with a legal obligation: where the processing is necessary to comply with security requirements under data protection law, or cyber and information security law.

Legitimate interests: to protect our business assets against fraud and illegal activities or security threats where this is important but not strictly required by data protection or cyber and information security law.
Third party social networks: We use your personal data when you interact with third party social networking features, such as "Like" functions to serve you with advertisements and engage with you on third party social networks. You can learn more about how these features work, the profile data that we obtain about you, and find out how to opt out by reviewing the privacy notices of the relevant third party social networks. Your account information (e.g. name, email address, gender, birthday, current city, profile picture, user ID, contact list, etc.) and any other information or activities that you permit the third party social network to share with us Your consent: where required by law.

Our legitimate interests: where allowed by law in the alternative, in order to promote our products and services and to effectively manage our relationship with you as our customer.
To organize sweepstakes, contests and promotions and correspond with and about participants and winners. Depending on the nature of the prize draw, we may share winner details publicly. Identification Data, Contact Data, Communications Data Your consent where this is required by law. Otherwise we rely on our legitimate interests to run promotional activities to engage with our audience and to grow and develop our business.
To respond to complaints, to protect our legal rights and to establish, exercise or defend legal claims relating to our Sites and/or our products and services. All categories of data listed in section 1 to the extent necessary To comply with a legal obligation: where such processing is necessary to comply with legal obligations such as those relating to legal claims procedures.

Legitimate interests: to protect our legal rights and our business including to establish, exercise or defend legal claims where this is not strictly required by law.
To respond to legitimate requests for the disclosure of information, made by public authorities, law enforcement or governmental bodies or under a court order. All categories of data listed in section 1 to the extent necessary To comply with a legal obligation: where necessary to comply with our legal obligations which includes, for example, to access, retain or share certain personal data where we receive a valid request from a public authority, law enforcement or government body, or similar.

Legitimate interests: to assist legitimate investigations carried out by official authorities where this is not strictly required by law.
For tax, accounting, record keeping and audit purposes and to comply with our legal obligations. All categories of data listed in section 1 to the extent necessary To comply with a legal obligation: where necessary to comply with our accounting and tax obligations and to ensure we are complying with applicable consumer, advertising and data protection law.

Legitimate Interest: to effectively manage our business, audit our business processes and make informed business decisions where this is not strictly required by law.

We have carried out balancing tests for all the data processing we carry out on the basis of our legitimate interests, which we have described above. You can obtain information on any of our balancing tests by contacting us using the details set out in the 'Questions and Feedback' section below.

Where we rely on consent, you may withdraw it at any time without affecting prior lawful processing. We may retain other legal grounds for processing for the purposes set out above.

You have an absolute right to opt-out of direct marketing, or profiling we carry out for direct marketing purposes, at any time. You can do this by (i) clicking on the unsubscribe link in the relevant marketing communication, or (ii) emailing your opt-out request to newsletters@TOMS.com.

We do not use your personal information to take automated decisions relating to you.

4. Data Sharing

We share personal information with the following categories of recipients:

Category of Personal Information Category of Recipient Why?
All categories of personal information listed in section 1 to the extent necessary Personal data is shared between TOMS Shoes, LLC (U.S.) and TOMS EMEA B.V. (The Netherlands) To provide our products and services to you, as well as to support the other purposes described in section 3.
Identification Data, Contact Data, Transaction Data, Preference Data, Communications Data, Technical Data, Usage Data Third party service providers who assist us to provide you with our products and services. This includes a printer, mailing house, fulfilment/delivery company, IT service provider and web host. These third party providers assist us to provide you with our products and services. These companies will process this information to the extent necessary to perform their functions and are subject to confidentiality agreements. Unless otherwise required by law, they are not authorized to use any of the personal information we share with them for any other purpose.
Identification Data, Contact Data, Transaction Data and your payment card details Third party payment providers including Klarna, Shop Pay (by Shopify Inc.) / Shopify Payments (powered by Stripe), and PayPal. These third parties act as controllers in respect of the processing of your personal information and their processing is subject to their own privacy notices.
Identification Data, Contact Data, Transaction Data, Technical Data Signifyd (Commerce Protection Platform) We use Signifyd for fraud detection and prevention. When you place an order, Signifyd analyses transaction and device data to protect against fraudulent purchases. Signifyd operates a cross-merchant fraud prevention network and may act as an independent controller in respect of the data it processes for this purpose.
Identification Data, Contact Data, Transaction Data AfterShip Tracking (parcel tracking and delivery notifications) We use AfterShip to provide you with parcel tracking updates and delivery notifications, and to enable us to proactively monitor and resolve any delivery issues. AfterShip receives the information necessary to track your shipment and keep you informed about its status.
Identification Data, Contact Data, Transaction Data ZigZag Global Ltd (returns management) We partner with ZigZag Global Ltd to manage product returns. When you initiate a return, you interact directly with ZigZag's return portal, where you provide your order details. ZigZag retrieves the relevant order information from Shopify for the purpose of creating your return, issuing a returns shipping label, and processing your refund. Necessary information is also shared with parcel carriers for the purpose of shipping goods back to TOMS.
Technical Data, Usage Data Third party analytics providers. These companies assist us to carry out analytics on our Sites.
Identification Data, Contact Data, Communications Data, Preference Data Third parties who assist us to run sweepstakes, contests and promotions. These companies assist us to run sweepstakes, contests and promotions.
Identification Data, Contact Data Meta (Facebook and Instagram), Google, X (formerly Twitter), TikTok, and Pinterest. To enable us to advertise our products and services to you and those similar to you on these social networks.
All categories listed in section 1 to the extent necessary Business advisers (such as legal advisers, accountants, business consultants, insurers). To enable us to obtain advice as required to operate our business.
All categories listed in section 1 to the extent necessary Courts, public authorities, law enforcement or government bodies, fraud prevention agencies and other third parties involved in investigations, law enforcement or legal proceedings. To establish, exercise or defend legal claims, to deal with requests or otherwise communicate with public authorities, law enforcement or government bodies and fraud prevention agencies.
All categories listed in section 1 to the extent necessary Prospective Buyer/Seller/Investor and their advisers. In the event that the business receives investment, is sold or integrated with another business, we will share personal data where necessary to facilitate this process.

5. Where We Transfer Personal Information

Personal information that we collect from you may be transferred to and stored at a destination outside the UK and European Economic Area ("EEA"). In particular, due to the global nature of our business, your personal data will be disclosed to TOMS Shoes, LLC, located in the United States, which acts as a data controller in respect of certain processing activities described in this Privacy Notice.

For transfers of personal data within TOMS (between TOMS EMEA B.V. and TOMS Shoes, LLC), we ensure that appropriate safeguards are in place to protect your personal data, including through the implementation of internal data transfer policies and agreements designed to provide protections consistent with applicable data protection law.

Where we transfer personal data to third party business partners and service providers located outside the UK or EEA in countries that have not been granted an adequacy decision by the European Commission or the UK Secretary of State, we ensure that appropriate safeguards are in place. Depending on the nature of the relationship and the transfer, these safeguards may include:

  • transfers to business partners and service providers in the United States who participate in the UK Extension to the US Data Privacy Framework or the EU-US Data Privacy Framework, as applicable;
  • transfers subject to standard contractual clauses approved by the European Commission (Module 1 for controller-to-controller transfers, or Module 2 for controller-to-processor transfers, depending on the nature of the relationship); or
  • transfers to processors who have adopted Binding Corporate Rules approved by a competent EU or UK supervisory authority.

A copy of the relevant transfer mechanism applicable to any specific transfer may be obtained upon request by contacting us using the details set out in the Questions and Feedback section below.

6. Cookies

For more information about how we use cookies and similar technologies, please see our Cookie Notice below, which forms part of this Privacy Notice.

Cookie Notice

This Cookie Notice applies to all websites managed by TOMS Shoes, LLC and/or TOMS EMEA B.V. Please see the Questions and Feedback section below for a full list of Sites and to identify which TOMS entity controls the Site you use. For the purposes of data protection law in the UK and European Union, the listed TOMS entity is the data controller in respect of the processing of your personal information through cookies.

What Are Cookies?

A cookie is a very small text file, which often includes a unique identifier, that is stored on your device by your web browser when you load a website. Each time you return to that website, your browser retrieves and sends this file to the website's server. We also use other technologies that serve a similar purpose to cookies, such as web beacons, pixel tags, and flash cookies. When we refer to "cookies" in this Notice, we include these similar technologies unless otherwise stated.

Cookies allow websites to recognize your device, remember your preferences, keep track of your shopping cart, and deliver content and advertising tailored to your interests. Find out more about cookies generally at www.allaboutcookies.org.

Types of Cookies We Use

We use the following categories of cookies on our Sites:

  1. Strictly Necessary Cookies — These cookies are essential to enable you to move around our Sites and use their features, including accessing secure areas and retaining items in your shopping cart. Without these cookies, services you have requested cannot be provided. These cookies cannot be disabled.
  2. Performance Cookies — These cookies help us improve and optimise the experience we provide. They collect information about how visitors use our Sites — for instance, which pages are visited most often, whether visitors encounter error messages, and how visitors interact with our email communications. All information collected by these cookies is aggregated and used solely to improve how our Sites work.
  3. Functional Cookies — These cookies allow our Sites to remember choices you make — such as your username, language, or region — and provide enhanced, more personalised features. The information these cookies collect may be anonymised and they cannot track your browsing activity on other websites.
  4. Targeting and Advertising Cookies — These cookies record your visits to our Sites, the pages you view, and the links you click. They are used to deliver advertisements more relevant to you and your interests, to limit the number of times you see a particular advertisement, and to measure the effectiveness of advertising campaigns. They are placed by advertising networks with our permission and, where required by law, with your consent. They remember that you have visited our Sites and this information may be shared with third parties such as advertisers. For example, we use Meta Custom Audiences and Meta Lookalike Audiences to deliver advertisements to Site visitors.
  5. Social Media Cookies — These cookies enable you to share content from our Sites on social media platforms such as Facebook, Instagram, X (formerly Twitter), TikTok and Pinterest. These cookies are operated by the relevant social media platforms and are not within our control. Please refer to the privacy and cookie policies of the relevant social media platform for information about how these cookies work and your options for managing them.

Third Party Cookie Providers

The following are our principal third party service providers that use cookies on our Sites, along with links to their privacy policies which describe how they handle your data and how you can opt out or withdraw consent. For a complete and always up-to-date list of every individual cookie, you can click the "Cookie Preferences" link in the footer of any page of our Sites.

Provider Category Purpose
Google / DoubleClick / YouTube Performance & Targeting Analytics, advertising measurement, ad delivery, and embedded video playback
Meta (Facebook / Instagram) Targeting Advertising, audience matching, and conversion tracking
Criteo Targeting Retargeting and personalised advertising
Taboola Targeting Content recommendation and advertising
AppLovin Targeting Mobile advertising and analytics
Pinterest Targeting Advertising and conversion tracking
X (formerly Twitter) Targeting Advertising and conversion tracking
TikTok Targeting Advertising and conversion tracking
Snapchat Targeting Advertising and conversion tracking
Microsoft Bing Targeting Advertising and conversion tracking
ID5 Targeting Identity resolution for advertising
Mediavine Targeting Programmatic advertising
Listrak Targeting Email marketing and personalisation
Attentive Targeting & Functional SMS marketing, personalisation, and checkout attribution
LTK (formerly LIKEtoKNOW.it) Functional & Targeting Influencer marketing and product recommendations
UNiDAYS Targeting Student discount verification and marketing
Yotpo Functional Product reviews and user-generated content
Searchspring Functional Site search functionality and product discovery
Shopify Strictly Necessary & Performance E-commerce platform functionality and analytics
OneTrust Strictly Necessary Cookie consent management
Cloudflare Strictly Necessary Content delivery network and security
Signifyd Strictly Necessary Fraud prevention
Addingwell (by Didomi) Strictly Necessary Server-side tagging and analytics routing

How to Manage Your Cookie Preferences

Strictly necessary cookies (category 1 above) are required for our Sites to function and cannot be disabled through our cookie management tools.

All other cookies are subject to your consent. You can adjust your preferences at any time by clicking the "Cookie Preferences" button at the bottom of any page on our Sites.

You can also manage or delete cookies through your browser settings. Most browsers allow you to refuse cookies, delete previously stored cookies, and receive notifications when a cookie is placed on your device. For guidance specific to your browser:

Please note that disabling strictly necessary cookies will prevent you from shopping on our Sites. Disabling performance cookies may affect your user experience. You may still place orders by telephone by contacting our customer service team.

Do Not Track and Global Privacy Control

Our Sites do not respond to "Do Not Track" signals transmitted by web browsers.

Residents of certain jurisdictions may opt out of certain data processing activities by broadcasting an Opt-Out Preference Signal, such as the Global Privacy Control (GPC). Where required by applicable law, we will treat a valid GPC signal received from your browser as a request to opt out of the use of non-essential cookies and similar tracking technologies on the Site you are visiting at the time the signal is received. The GPC signal is browser- and device-specific — if you use multiple browsers or devices, you will need to enable the GPC signal on each separately. To find browsers and extensions that support the GPC signal, visit https://globalprivacycontrol.org.

Please note that opting out via GPC does not affect processing of your personal information that is not conducted through cookies or similar tracking technologies, and does not constitute a general objection to all processing under this Privacy Notice. To exercise your broader data protection rights, please see Section 9 (Your Rights) below.

7. Children's Privacy

We do not intentionally collect personal information from children under the age of sixteen. If we become aware that we have collected personal information from a user of the Site who is under the age of sixteen, we will remove that child's personal information from our files.

8. Data Retention

We retain your personal information for as long as this is necessary to allow us to fulfil the purposes for which we use your information. We provide below further detail on the retention periods of specific types of personal information we process.

  • If you have an account with us, we will retain and use your personal information associated to that account for as long as your account is active, and for such further period after the closure of your account as needed to provide you with the products you have ordered and respond to queries, to document our business relationship with you, and as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
  • Where you have provided a product review, we will retain this information for a minimum period of 1 year and for no more than 2 years from the date of publication of the review.
  • Where we process your personal information for marketing purposes, we process the data until you ask us to stop and for a short period after this (to allow us to fulfil your requests). If you object to direct marketing or withdraw your marketing consent, we will keep a record of your contact details and the fact that you have asked us not to use your information for direct marketing purposes indefinitely, so that we can respect your request in future.
  • Where we process personal information in connection with performing our contract with you (for example, your purchase orders) or for a competition, we keep such information for 6 years from your last interaction with us in relation to that contract or competition.
  • Where we process personal information to monitor and compile statistics about the use of our Site, we keep the personal information for 13 months.
  • Where we process personal information to meet legal requirements, we hold this information for as long as necessary to allow us to comply with these legal obligations.

9. Your Rights

You have the following rights:

Right Summary
Right of access Enables you to receive a copy of your personal information.
Right to rectification Enables you to correct any inaccurate or incomplete personal information we hold about you.
Right to erasure Enables you to ask us to delete your personal information in certain circumstances.
Right to restrict processing Enables you to ask us to halt the processing of your personal information in certain circumstances.
Right to object Enables you to object to us processing your personal data on the basis of our legitimate interests (or those of a third party), including processing for direct marketing purposes or profiling for purposes of direct marketing — your objection will be upheld, and we will cease processing your personal data, unless the processing is based on compelling legitimate grounds or is needed for the exercise or defence of legal claims that may be brought by or against us.
Right to data portability Enables you to request us to transmit personal data that you have provided to us, to a third party without hindrance, or to give you a copy of it so that you can transmit it to a third party, where technically feasible.

These rights may be limited, for example if fulfilling your request would reveal personal information about another person, or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping.

How to Exercise Your Rights

To exercise any of the rights described above, please submit a request through our Privacy Request Form. For general enquiries, you can also contact the relevant data controller using the contact details set out in the Questions and Feedback section below. When submitting a request, please: (i) clearly identify yourself; (ii) specify which right you wish to exercise; and (iii) provide sufficient information to allow us to locate and verify your identity. We may ask you to provide proof of identity before we are able to process your request.

We will respond to your request within one (1) month of receipt. In cases of complexity or where we receive a high volume of requests, we may extend this period by a further two (2) months, in which case we will notify you of the extension and the reasons for it within one month of receiving your request. Where we are unable to act on your request, we will explain why.

There is no charge for making a rights request. However, if a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee or refuse to act on the request. In either case, we will explain our reasons.

Alternatively, if you prefer not to use the Privacy Request Form, you may contact the relevant data controller directly:

Please note that requests submitted by email are typically processed more slowly than those submitted through the Privacy Request Form, and in certain cases we may still ask you to complete the form so that we can properly verify your identity and action your request.

If you wish to deactivate your account to prevent any future purchases, please submit a request to the relevant TOMS customer service team using the contact details below. Our e-commerce platform does not currently offer self-service account deletion; we will process your request and confirm once your account has been deactivated. Please note that in case of account deactivation, we will still retain certain information (including but not limited to personal information) to the extent necessary to fulfil our legal, tax and accounting obligations, for business purposes and to protect TOMS' interests (e.g. invoices, payment transaction details, shipping and transactional information, etc.).

To request account deactivation in relation to Sites controlled by TOMS Shoes, LLC (www.toms.com and ca.toms.com), please contact: customerservice@toms.com.

To request account deactivation in relation to Sites controlled by TOMS EMEA B.V. (eu.toms.com and uk.toms.com), please contact: eucustomerservice@toms.com.

You also have the right to complain to a data protection authority where you normally reside, or where you work or where you believe a breach has occurred. In the UK, this is the Information Commissioner's Office. For a list of authorities in the European Union, see here.

10. Offline Collection, Use and Disclosure of Information

The majority of information that we collect is obtained through our Sites, and this Privacy Notice applies to that online collection of personal information. We also collect information offline: for example, when we receive a call to our Customer Support department, we will collect certain information, such as the caller's telephone number, and any further information required to place an order via phone or respond to a query. We will also record calls with our Customer Support department and store the recording for as long as necessary for training and customer service purposes and, where relevant, to keep evidence of transactions. When we need to store information (such as order information), we will enter it into our database using standard industry practice (SSL) encryption.

11. Security of Your Personal Information

We take the security of your personal information seriously. TOMS has implemented appropriate technical and organizational measures designed to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. These measures include, as appropriate: physical access controls at our facilities; administrative safeguards including staff training and confidentiality obligations; and technical measures including encryption of data in transit using industry-standard protocols (SSL/TLS).

Where we share personal information with third party service providers, we require those providers to maintain appropriate security measures consistent with this Privacy Notice and applicable law.

Please be aware that no method of transmission over the internet or method of electronic storage is completely secure. While we strive to use commercially reasonable means to protect your personal information, we cannot guarantee its absolute security. You are responsible for maintaining the confidentiality of any account credentials and for limiting access to your devices. If you believe your account has been compromised, please contact us using the details in the Questions and Feedback section below.

12. Policy Changes

We may change our Privacy Notice from time-to-time, for example when the way we use personal information changes or where necessary to comply with the law. We encourage you to refer to this Privacy Notice on an ongoing basis so that you are aware of our current Privacy Notice.

Any substantive or material change to the Privacy Notice will be brought to your attention — for example, by including a pop-up notice on our Sites.

13. Questions And Feedback

We welcome your questions, comments and feedback in relation to this Privacy Notice and the way we use personal information.

Site Company Contact information
eu.toms.com TOMS EMEA B.V. Danzigerkade 9 C, 1013 AP Amsterdam (The Netherlands) — eucustomerservice@toms.com
uk.toms.com TOMS EMEA B.V. Danzigerkade 9 C, 1013 AP Amsterdam (The Netherlands) — eucustomerservice@toms.com
www.toms.com TOMS Shoes, LLC 5800 Uplander Way, Culver City, California 90230 (USA) — customerservice@toms.com
ca.toms.com TOMS Shoes, LLC 5800 Uplander Way, Culver City, California 90230 (USA) — customerservice@toms.com

If the controller of your personal information is TOMS EMEA B.V. (as per the above table) and you have unresolved concerns relating to how we use your personal information, or do not believe that we have complied with this Privacy Notice, you have the right to complain to an EU data protection authority where you live, work, or where you believe a breach may have occurred.

In accordance with Article 27 of the UK GDPR, TOMS EMEA B.V. has designated TOMS Shoes UK Limited (company number 07410842), Studio 1.07, Islington Tradestars, 4-10 North Road, London, N7 9EY, United Kingdom, as its representative for the United Kingdom. UK customers and data subjects may contact our UK representative at uk.privacy@toms.com in relation to any matters arising under this Privacy Notice.