Data Privacy Rights Disclosure

Black Girls Hair Rocks, LLC

Effective Date: December 6, 2025

Introduction

Black Girls Hair Rocks, LLC (“Company,” “we,” “us,” or “our”) is committed to protecting your privacy and ensuring transparency about how we collect, use, and share your personal information. This Data Privacy Rights Disclosure supplements our Privacy Policy and provides additional information for residents of California (under the California Consumer Privacy Act, or CCPA, as amended by the California Privacy Rights Act, or CPRA) and the European Economic Area, the United Kingdom, and Switzerland (under the General Data Protection Regulation, or GDPR).

For California Residents (CCPA/CPRA)

Categories of Personal Information Collected

In the preceding 12 months, we may have collected the following categories of personal information: identifiers (name, email address, phone number, mailing address, IP address); commercial information (products purchased, purchase history, payment information); internet or other electronic network activity (browsing history, interactions with our website, device information); geolocation data (approximate location based on IP address); and audio or visual information (voice recordings from interactions with Michelle, our AI voice assistant).

Sources of Personal Information

We collect personal information directly from you (when you make a purchase, create an account, or interact with Michelle); automatically through your use of our website (via cookies and similar technologies); and from third-party service providers (payment processors, analytics providers).

Purposes for Collection

We collect and use personal information to provide, maintain, and improve our services; process transactions and fulfill orders; communicate with you about your orders and our services; personalize your experience; analyze usage and improve our website; improve and train our AI systems; and comply with legal obligations.

Disclosure and Sale of Personal Information

We do not sell your personal information as defined under the CCPA/CPRA. We do not share your personal information for cross-context behavioral advertising. We may disclose personal information to service providers who assist us in operating our business, as described in our Privacy Policy.

Your California Privacy Rights

As a California resident, you have the following rights: the right to know what personal information we collect, use, disclose, and sell; the right to delete your personal information (subject to certain exceptions); the right to correct inaccurate personal information; the right to opt out of the sale or sharing of your personal information (though we do not sell or share your information); the right to limit the use of sensitive personal information (though we do not use sensitive personal information beyond what is necessary to provide our services); and the right to non-discrimination for exercising your privacy rights.

How to Exercise Your Rights

To exercise any of these rights, please submit a request by emailing us at hello@bghrs.com or calling us at 267-225-3873. We will confirm your identity by matching the information you provide with our records before processing your request. You may designate an authorized agent to request on your behalf by providing written authorization.

For European Economic Area, UK, and Swiss Residents (GDPR)

Legal Basis for Processing

We process your personal data based on the following legal grounds: contract performance (to fulfill orders and provide services you have requested); legitimate interests (to improve our services, prevent fraud, and communicate with you); consent (for marketing communications and specific uses of cookies); and legal obligation (to comply with applicable laws and regulations).

Your GDPR Rights

If you are located in the EEA, UK, or Switzerland, you have the following rights: the right to access your personal data; the right to rectification of inaccurate or incomplete data; the right to erasure (the “right to be forgotten”); the right to restrict processing; the right to data portability; the right to object to processing; the right to withdraw consent at any time (where processing is based on consent); and the right to complain to a supervisory authority.

International Data Transfers

The United States, where our servers and service providers are located, may receive and process your personal data. We implement appropriate safeguards for such transfers, including standard contractual clauses approved by the European Commission.

Data Retention

We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. We will securely delete or anonymize your personal data when no longer needed.

Contact Us

If you have questions about your privacy rights or wish to exercise any of the rights described above, please get in touch with us at

Black Girls Hair Rocks, LLC

Email: hello@bghrs.com

Phone: 267-225-3873

Mail: 701 E Cathedral Rd, Ste 45 PMB 311, Philadelphia, PA 19128

We will respond to your request within the timeframes required by applicable law (generally within 45 days for CCPA requests and 30 days for GDPR requests).

b