Puffy LLC (d/b/a Puffy Mattress) is the owner of this website ("puffy.com"). Puffy Mattress can be contacted by mail at Puffy LLC, 13070 Saticoy St., North Hollywood, CA 91605, by phone at +1 (800) 430-8380, or by e-mail at support@puffy.com. This online privacy notice discloses Puffy Mattress' information practices for this Website, including what type of personally identifiable information is requested in order to make a purchase, how the information is used, and with whom the information is shared.
Section 1
What Do We Do With Your Information?
When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us, such as your name, address, and email address. When you browse our store, we also automatically receive your computer's internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system. Email marketing (if applicable): With your permission, we may send you emails about our store, new products, and other updates.
Text Marketing and Notifications:
By entering your phone number in the checkout and/or initializing a purchase, subscribing via our subscription form or a keyword, you agree that we may send you text notifications (for your order, including abandoned cart reminders) and text marketing offers, including recurring automated messages. Text marketing messages will not exceed 3 per day [this does not include messages related to your order]. You acknowledge that consent is not a condition for any purchase.
If you wish to unsubscribe from receiving text marketing messages and notifications, reply with STOP to any mobile message sent from us or use the unsubscribe link we provided you within any of our messages. Message and data rates may apply. Message frequency varies.
For any questions, please text HELP to the number you received the messages from. You can also contact us for more information. If you wish to opt-out, please follow the procedures above.
Section 2
Consent
How do you get my consent? When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery, or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only. If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent or provide you with an opportunity to say no.
How do I withdraw my consent? If, after you opt-in, you change your mind, you may withdraw your consent for us to contact you for the continued collection, use, or disclosure of your information at any time by contacting us at support@puffy.com or mailing us at: Puffy LLC 13070 Saticoy St. North Hollywood, CA 91605
How do I update my Personal Information? Help Puffy Mattress to keep your personal information accurate. If your personal information changes, or if you note an error upon review of customer information that Puffy Mattress has on file, please promptly e-mail support@puffy.com and provide the new or correct information.
Section 3
Disclosure
Mergers and Acquisitions
Circumstances may arise where, for business reasons, Puffy Mattress decides to sell, buy, merge, or otherwise reorganize its businesses in the United States or some other country. Such a transaction may involve the disclosure of personal identifying information to prospective or actual purchasers and/or receiving such information from sellers. It is Puffy Mattress' practice to seek appropriate protection for information in these types of transactions.
Agents
Puffy Mattress employs or engages, or may do so, other companies and individuals to perform business functions on behalf of Puffy Mattress. These persons are provided with personal identifying information required to perform their functions, but are prohibited by contract from using the information for other purposes. These persons engage in a variety of functions, which include, but are not limited to, fulfilling orders, delivering packages, removing repetitive information from customer lists, analyzing data, providing marketing assistance, processing credit card payments, and providing customer services.
Disclosure to Governmental Authorities
Under certain circumstances, personal information may be subject to disclosure pursuant to judicial or other government subpoenas, warrants, or orders.
Section 4
Shopify
Our store is hosted on Shopify Inc. They provide us with an online e-commerce platform that allows us to sell our products and services to you. Your data is stored through Shopify's data storage, databases, and the general Shopify application. They store your data on a secure server behind a firewall.
Payment: If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted. All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express, and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers. For more insight, you may also want to read Shopify's Terms of Service (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).
Section 5
Third-Party Services
In general, the third-party providers used by us will only collect, use, and disclose your information to the extent necessary to allow them to perform the services they provide to us. However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy statements/policies and terms of use/service with respect to the information we are required to provide to them for your purchase-related transactions. For these providers, we recommend that you read their privacy statements/policies and terms of use/service so you can understand the manner in which your personal information will be handled by these providers. In particular, remember that certain providers may be located in or have facilities that are located in a different jurisdiction than either you or us. So, if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located. As an example, if you are located in Canada, and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under the laws of the United States, including the Patriot Act. Once you leave our store's website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website's Terms of Service.
Links: When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices or the terms of use/service of other sites and encourage you to read each site's privacy statements/policies and their terms of use/service.
Google Analytics: Our store uses Google Analytics to help us learn about who visits our site and what pages are being looked at.
Section 6
Security
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered, or destroyed. Puffy Mattress employs physical, electronic, and managerial procedures to safeguard the security and integrity of personal information. Billing and payment data is encrypted whenever transmitted or received online. Personal information is accessible only by staff designated to handle online requests or complaints. If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with AES-256 encryption. Although no transmissions protected by industry-standard security technology implemented by human beings cannot be made, transmission over the internet or electronic storage is 100% secure; we follow all PCI-DSS requirements and implement additional generally accepted industry standards. Consequently, Puffy Mattress shall not be liable for unauthorized disclosure of personal information due to no fault of Puffy Mattress, including, but not limited to, errors in transmission and unauthorized acts of Puffy Mattress staff or third parties.
Section 7
Use of Computer Tracking Technologies
Cookies
Puffy Mattress (directly or via third party vendors) deploys cookies, pixels, web beacon, software development kits (“SDKs”), and comparable tracking technologies (collectively, “Cookies”) on www.puffy.com,
that collect non-identifiable and personal information through the use of various technologies, to enable core Site functionality and security, analyse Site performance and usage and personalise marketing, including interest-based advertising.The full details of our Cookie practices—including the specific cookie categories we use, the third-party services that set them, their retention periods, and the on-site preference centre—are contained in our standaloneCookie Policy
maintained by our privacy-compliance vendor.The Cookie Policy is expressly incorporated into—and made part of—this Privacy Policy by reference. Capitalised terms used but not defined in the Cookie Policy have the meanings assigned in this Privacy Policy.Managing your preferences
You may decide at any time whether to accept or reject non-essential Cookies by visiting
and recording your preferences, or by adjusting your browser settings. Disabling strictly-necessary Cookies may affect site functionality (e.g., cart and checkout). Section 8
Age of Consent
By using this site, you represent that you are at least the age of majority in your state or province of residence or that you are the age of majority in your state or province of residence, and you have given us your consent to allow any of your minor dependents to use this site. Puffy Mattress will not collect or post information from a child under the age of 16 or the age of majority in your State of residence [whichever may apply], will not use personally identifying information collected from children for marketing or promotional purposes, and will not disclose such information to any third party for any purpose whatsoever.
Section 9
Changes to This Privacy Policy
This privacy notice was last updated on October 18, 2023. We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.
Terms of Use
If Customer chooses to enter into a purchase order, Customer's action is hereby deemed acceptance of Puffy Mattress' practices described in this policy statement. Any dispute over privacy between the customer and Puffy Mattress is subject to the provisions of this notice and to Puffy Mattress' Terms and Conditions, which are hereby incorporated herein and which can be read at https://puffy.com/pages/terms-and-conditions.
Questions and Contact Information
If you would like to access, correct, amend, or delete any personal information we have about you, register a complaint, or simply want more information, contact our Privacy Compliance Officer at support@puffy.com.
Information We Collect
Information You Provide to Us
We collect the personal information you provide to us when you are Customers. The categories of information we may collect include:
Personal Identifiers, including name, email address, postal address, telephone number, social security number, driver's license number, State ID card number, and tax ID number
Commercial and Financial Information, including purchases, other purchasing behavior, credit card or debit card number, bank or other financial account number, account security or access credentials, account name, signature, and other financial information
Physical and Audio Data, including visual information
Characteristics of Protected Classifications, including age, sex or gender, gender identity or expression, marital status, medical condition, disability, and military or veteran status
Inferences, including inferences from other data
We collect the personal information you provide to us when you are Newsletter Subscribers. The categories of information we may collect include:
Personal Identifiers, including name, email address, and telephone number
We collect the personal information you provide to us when you are Website Visitors. The categories of information we may collect include:
Personal Identifiers, including name, email address, postal address, and telephone number
Commercial and Financial Information, including purchases, other purchasing behavior, credit card or debit card number, bank or other financial account number, account name, and other financial information
Inferences, including inferences from other data
To the extent we process de-identified personal information, we will make no attempt to reidentify such data.
Information Collected Automatically
We automatically collect internet or other electronic information about you when you visit our website, such as IP address, browsing history, and interactions with our website. We also collect geolocation data. This data may be collected using browser cookies and other unique personal identifiers.
Information From Other Sources
We may collect personal information about you from third-party sources, including Ad Networks and Data Analytics Providers.
How Long We Keep Your Data
We do not retain data for any longer than is necessary for the purposes described in this Policy.
Lost or Stolen Information
If a customer's credit card or password is lost or stolen, the customer should promptly notify Puffy Mattress in order to enable it to cancel the lost or stolen information and to update its records with a changed credit card or password.
How We Share and Disclose Information
Detailed Information on the Processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
A. Advertising
(1) Criteo (Criteo SA): Personal Data collected: Trackers; Usage Data.
(2) Google Ad Manager, Google AdSense, and Google Ads Optimized Targeting (Google LLC): Personal Data collected: Trackers; Usage Data; Gender.
(3) Impact (Impact Tech, Inc.): Personal Data collected: Trackers; Usage Data.
(4) LiveIntent (LiveIntent Inc.): Personal Data collected: Trackers; Usage Data.
(5) Meta Ads Conversion Tracking (Meta Pixel) (Meta Platforms, Inc.): Personal Data collected: Trackers; Usage Data.
(6) Microsoft Advertising (Microsoft Corporation): Personal Data collected: Trackers; Usage Data.
B. Analytics
(1)
FullStory (FullStory, Inc.): Personal Data collected: Trackers; Usage Data.
(2)
Google Analytics 4 (Google LLC): Personal Data collected: number of Users; session statistics; browsing history; clicks; page views.
(3)
Meta Events Manager (Meta Platforms, Inc.): Personal Data collected: Trackers; Usage Data; browsing history.
C. Heat Mapping and Session Recording
(1) Microsoft Clarity (Microsoft Corporation): Personal Data collected: clicks; interaction events; country of origin; time spent on page.
D. Managing Contacts and Sending Messages
(1)
Klaviyo (Klaviyo Inc.): Personal Data collected: email address; phone number; purchase history. (2)
Sendgrid (Sendgrid): Personal Data collected: email address.
E.Tag Management
(1)
Google Tag Manager (Google LLC): Personal Data collected: Trackers; Usage Data.
F. Infrastructure and Hosting
(1) Shopify (Shopify Inc.): Personal Data collected: device information; payment information; purchase history. (2)Amazon S3 (Amazon Web Services, Inc.) & Vercel (Vercel Inc.): Personal Data collected: Usage Data. (3)
Sentry (Functional Software, Inc.): Personal Data collected: various types of Data as specified in the privacy policy of the service (for infrastructure monitoring).
California Privacy Notice (CCPA)
This section provides additional information for California residents under the California Consumer Privacy Act (CCPA). The terms used in this section have the same meaning as in the CCPA. This section does not apply to information that is not considered "personal information," such as anonymous, de-identified, or aggregated information, nor does it apply to publicly available information as defined in the CCPA.
Ad Networks, Data Analytics Providers, and Payment Processors
Internet Activity
Business Operations Tool, Commerce Software Tools, Communications Tools, and Sales & Marketing Tools
Ad Networks and Data Analytics Providers
Commercial and Financial Information
Business Operations Tool, Commerce Software Tools, Communications Tools, Customer Support Tools, Fraud Prevention Tools, and Sales & Marketing Tools
Ad Networks and Payment Processors
Physical and Audio Data
Business Operations Tool
None
Characteristics of Protected Classifications
None
None
We may disclose the following personal information about you when you are Newsletter Subscribers:
Personal Information Category
Categories of Service Providers
Categories of Third Parties
Personal Identifiers
Business Operations Tool, Commerce Software Tools, Communications Tools, Governance, Risk & Compliance Software, and Sales & Marketing Tools
Ad Networks
Online Identifiers
Commerce Software Tools and Governance, Risk & Compliance Software
Ad Networks and Data Analytics Providers
Internet Activity
Communications Tools and Sales & Marketing Tools
Data Analytics Providers
We may disclose the following personal information about you when you visit our website:
Personal Information Category
Categories of Service Providers
Categories of Third Parties
Online Identifiers
Commerce Software Tools, Data Analytics Providers, Governance, Risk & Compliance Software, and IT Infrastructure Services
Ad Networks and Data Analytics Providers
Internet Activity
Commerce Software Tools, Data Analytics Providers, IT Infrastructure Services, and Sales & Marketing Tools
Ad Networks and Data Analytics Providers
Information “Sharing” and “Selling”
We “share” certain personal information with third-party ad networks for purposes of behavioral advertising, including: Commercial and Financial Information, Geolocation Information, Inferences, Internet Activity, Online Identifiers, and Personal Identifiers. This allows us to show you ads that are more relevant to you.
We use third-party data analytics providers, and this may be considered a “sale” of information under the CCPA.
You may opt out of these data practices .
We do not knowingly sell or share (for cross-context behavioral advertising) the personal information of consumers under 16 years of age.
CCPA Rights
Your CCPA rights, as amended by the California Privacy Rights Act of 2020 (CPRA), are described below. You can make a Request to Know or a Request to Delete under the CCPA by submitting a Privacy Request by clicking here, or by emailing us at privacy@puffy.com.
Right to Know
You have the right to request to know the following about the personal information we have collected about you in the past 12 months:
the categories and specific pieces of personal information we have collected about you
the categories of sources from which we collect personal information about you
the business and commercial purposes for which we collect personal information
the categories of third parties with whom we share the information
the categories of personal information about you that we disclosed for a business purpose and the categories of third parties to whom we disclosed that information for a business purpose
The information we would provide to you in response to a Request to Know Categories is contained in this Privacy Notice. To access the specific personal information we have about you, submit a Request to Know via the link above. If you make a Request to Know more than twice in a 12-month period, we may require you to pay a small fee for this service.
Right to Delete
You have the right to request that we delete any personal information about you that you have provided to us. We will permanently delete from our records any personal information that is not necessary for our business operations and direct our service providers to do the same.
We consider information to be necessary for our business operations if it is used to:
Complete an obligation to you that you have requested
Detect and resolve issues related to security or functionality
Comply with legal obligations
Enable solely internal uses
Right to Non-Discrimination
If you exercise your CCPA consumer rights:
We will not deny goods or services to you
We will not charge you different prices or rates for goods or services, including through the use of discounts or other benefits or penalties
We will not provide a different level or quality of goods or services to you
Right to Opt-Out
You have the right to opt out of any selling and sharing of your personal information.
You may exercise your right to opt out .
Opt-Out Preference Signals. Your browser settings may allow you to automatically transmit the Global Privacy Control (GPC) signal to online services you visit. When we detect such signal, we place a U.S. Privacy String setting in your browser so that any third party who respects that signal will not track your activity on our website. GPC is supported by certain internet browsers or as a browser extension. You can find out how to enable GPC here.
Right to Limit Use of Sensitive Personal Information
You have the right to limit the use and disclosure of your sensitive personal information to the use which is necessary to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services.
Right to Correct
You have the right to correct inaccuracies in your personal data, taking into account the nature of the data and our purposes for processing it.
Request Verification
Before we can respond to a Request to Know or Request to Delete, we will need to verify that you are the consumer who is the subject of the CCPA request. Verification is important for preventing fraudulent requests and identity theft. Requests to opt out do not require verification.
Typically, identity verification will require you to confirm certain information about yourself based on information we have already collected. For example, we will ask you to verify that you have access to the email address we have on file for you. If we cannot verify your identity based on our records, we cannot fulfill your CCPA request.
For a request that seeks specific personal information, we ask that you sign a declaration stating that you are the consumer whose personal information is the subject of the request, as required by the CCPA.
In some cases, we may have no reasonable method by which we can verify a consumer's identity. For example:
If a consumer submits a request, but we have not collected any personal information about that consumer, we cannot verify the request.
If the only data we have collected about a consumer is gathered through website cookies (i.e., the consumer visited our website but had no other interaction with us), we are unable to reasonably associate a requester with any data collected; therefore, we cannot verify the request.
Authorized Agent
A California resident's authorized agent may submit a Request to Know or a Request to Delete under the CCPA by emailing us at privacy@puffy.com. Requests submitted by an authorized agent will still require verification of the person who is the subject of the request in accordance with the process described above. We will also ask for proof that the person who is the subject of the request authorized an agent to submit a privacy request on their behalf. An authorized agent that has power of attorney pursuant to California Probate Code section 4121 to 4130 must submit proof of statutory power of attorney, but consumer verification is not required.
If you have trouble accessing this notice, please contact us at privacy@puffy.com.
Contact Us
If you have any privacy-related questions, please send them to privacy@puffy.com.
Scope: This section applies to residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and Montana.
To review the categories of personal data we collect, the purposes for which we process it, and the categories of third parties with whom we share it, please refer to the “Detailed Information on the Processing of Personal Data” and “California Privacy Notice (CCPA)” sections above. These disclosures apply to the extent required by the laws of your state.
1. Your Privacy Rights.Under the applicable laws in these states, you have the following rights regarding your personal data:
Right to Confirm and Access: You have the right to confirm whether we are processing your personal data and to access such data.
Right to Correct: You have the right to request that we correct inaccuracies in your personal data, taking into account the nature of the data and our purposes for processing it.
Right to Delete: You have the right to request that we delete personal data provided by or obtained about you.
Right to Portability: You have the right to obtain a copy of your personal data in a portable and, to the extent technically feasible, readily usable format.
Right to Opt-Out: You have the right to opt out of the processing of your personal data for the purposes of:
Targeted Advertising (displaying ads based on your activities across non-affiliated sites).
The "Sale" of Personal Data (exchanging data for monetary or other valuable consideration).
Profiling (where such profiling produces legal or similarly significant effects concerning you).
Right to Non-Discrimination: We will not discriminate against you (e.g., by denying goods or charging different prices) for exercising your privacy rights.
2. Sensitive Personal Data. We will not process your "Sensitive Data" (which includes data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship status) without your affirmative consent.
Note for Iowa and Utah Residents: In accordance with state law, we may process your sensitive data if we have provided you with clear notice and an opportunity to opt out, which you may exercise at any time.
3. Additional Rights for Minnesota Residents. If you are a resident of Minnesota, you have the specific right to question the results of any automated profiling that produces legal or significant effects, to be informed of the reason for the result, and to review the data used in that profiling.
4. How to Exercise Your Rights.
To Opt-Out of Targeted Advertising/Sale: Please click the "Your Privacy Choices" link in the footer of our website. We also honor the Global Privacy Control (GPC) signal.
To Access, Correct, or Delete: Please contact us at support@puffy.com or submit a request through our privacy portal. We will verify your identity by matching the information you provide with our existing records.
5. Appeals Process.If we decline to take action on your request, we will notify you of the justification. You have the right to appeal our decision within a reasonable time by replying to our denial email or contacting privacy@puffy.com. If you are unsatisfied with the result of an appeal, you may contact the Attorney General of your state.
We use cookies and third-party technologies on our site to enhance your browsing experience, analyze traffic, provide communication tools, and personalize content and ads. By continuing to use this site or by clicking 'Okay,' you agree to the use of these technologies and the processing of your information as described in our Privacy Policy.