Effective Date: August 18, 2022
Introduction and Scope
Acknowledgement and Consent
If you are a citizen or resident of the European Economic Area (“EEA“), United Kingdom, or Switzerland, the definition of personal information is defined under the General Data Protection Regulation (“GDPR”) and you have certain rights; therefore, please see the section below entitled “GDPR”.
Personal Information does not include your Personal Information that has been deidentified, pseudonymized, anonymized, aggregated, and/or otherwise processed so as to be unidentifiable in such a way that the data can no longer be attributed to a specific individual (by reasonable means) without the use of additional information, and where such additional information is kept separate and under adequate security to prevent unauthorized re-identification of a specific individual such that one could not, using reasonable efforts, link such information back to a specific individual (collectively, all of the foregoing in this sentence being referred to as “De-Identified Personal Information”).
Individuals under the Age of 13
We do not knowingly collect, solicit or maintain Personal Information from anyone under the age of 13 or knowingly allow such persons to register for or use our Services. If you are under 13, please do not send any Personal Information about yourself (such as your name, address, telephone number, or email address) to us. In the event that we learn that we have collected Personal Information from a child under age 13 without verification of parental consent, we will use commercially reasonable efforts to delete that information from our database. Please contact us if you have any concerns.
California residents under 16 years of age have additional rights regarding the collection and sale of their personal information. Please see the section below entitled “Privacy Notice for California Residents” for more information.
Personal Information We Collect
We may collect several categories of Personal Information from and about you as summarized in the following table:
|Category||Specific Items of Personal Information|
· first and last name
· user name (which may include first and last name)
· email address
· unique personal identifier, e.g.: customer/account name or number, phone number, mobile device identifier
|Demographic||· birth date, national origin, country of residence|
|Internet or other electronic network activity; device information||
· type and manufacturer of device and its ID/UDID or similar device-specific code
· operating system and platform
· screen resolution
· Internet service provider or mobile carrier’s name, connection speed, and connection type
· browsing, session, interaction, and search history related to our Website
· Internet Protocol (or IP) address, protocol, and sequence information
· pixel tags
· browser type, language, and version
· domain name system requests
· mobile device advertising identifier
· material and pages viewed
· time and date of access to the Website
· number of bytes transferred
· number of clicks per visit
· IP address
· date stamp and URL of the last webpage visited before visiting our Website, and URL of the first page visited after leaving our Website
· pages viewed, time spent on a page, click-through and clickstream data, queries made, search results selected, comments made
|Inferences drawn from any of the above to create a profile of a consumer||· a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes|
|Other information||· bank account numbers|
How We Collect Personal Information and from What Sources
Information You Provide Us. The Personal Information we collect through our Website, or from our distributors, resellers, representatives, business partners, and service providers may include the following:
- Information that you provide by filling in webforms on our Mobile App or Website. This includes information provided when creating an online account, subscribing to our e-newsletters or other communications, requesting information from us, submitting or posting material (where permitted) on our forums, or interacting with customer support or service, report a problem with our Mobile App or Website or otherwise communicating with us.
- Records and copies of your correspondence (including email addresses), if you contact us
- Registering for an event
- Your responses to surveys that we or our service providers might ask you to complete for research purposes
- Your search queries on the Website
- In stores (parent, subsidiary and affiliate brands)
- When communicating with customer service/support
- Through participation in loyalty/rewards programs
- Third party websites and mobile applications (e.g., websites that share information with us or advertising partners regarding online activities)
- Data suppliers (e.g., companies that provide demographics and other information regarding consumers)
- On mobile applications (parent, subsidiary and affiliate brands)
- Joint marketing partners
- Online advertising companies
- Fulfillment and delivery service providers
- Social media companies
- Other service providers
- Responding to employment opportunities
Information We Collect Through Automatic Data Collection Technologies. As you navigate through and interact with our Website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions and patterns, including the following:
- Details of your visits to our Website, including, but not limited to, traffic data, geolocation data, logs, and other communication data and the resources that you access and use on the Website.
- Information about your computer, mobile device, and internet connection, including your IP address, operating system, browser type, clickstream patterns, the URL of the most recent website you visited before coming to our Website, the amount of time you spent on our Website, and the pages you viewed while on our Website.
Behavioral Tracking. We also may use these technologies to collect information about your online activities over time and across third-party websites or other online services, or associate Personal Information with other information collected in this manner.
Cookie Notice and Policy. The technologies we use for this automatic data collection may include cookies, local storage cookies, web beacons, pixel tracking, GIF, IP address, and other technologies. Each of these is discussed below.
Browser cookies are small files placed on the hard drive of your computer or mobile device. They may contain certain data, including, but not limited to: the name of the server that has placed it there, an identifier in the form of a unique number, and, an expiration date (some cookies only). Browser cookies are managed by the web browser (Internet Explorer, Firefox, Safari, Google Chrome, etc.) on your computer or mobile device. Different types of cookies which have different purposes are used on our Website.
Essential cookies are essential to allow you to browse our Website and use its functions. Without them, services such as shopping baskets and electronic invoicing would not be able to work.
Performance cookies collect information on the use of our Website, such as which pages are consulted most often. This information enables us to optimize our Website and simplify browsing. Performance cookies also enable our affiliates and partners to find out whether you have accessed one of our Website pages from their site and whether your visit has led to the use of a Service from our Website, including the references for the Service used. These cookies do not collect any information which could be used to identify you. All the information collected is aggregated, and therefore anonymous.
Functionality cookies enable our Website to remember the choices you have made when browsing. For example, we can store your geographical location in a cookie so that the Website corresponding to your area is shown. We can also remember your preferences, such as the text size, font and other customizable aspects of the Website. Functionality cookies also may be able to keep track of the products or videos consulted to avoid repetition. The information collected by these cookies cannot be used to identify you and cannot monitor your browsing activity on sites which do not belong to us.
It is possible that you will come across third-party cookies on some pages of sites that are not under our control.
Local Storage Cookies
Certain features of our Website may use local stored objects (to collect and store information about your preferences and navigation to, from and on our Website. Local storage cookies are not managed by the same browser settings as are used for browser cookies.
Web Beacons. Pages of our Website and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags and single-pixel gifs) that permit us, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of certain website content and verifying system and server integrity).
Pixel Tracking. In addition to using cookies, the Website may employ “pixel tracking”, a common process which may be used in connection with advertisements on other sites. Pixel tracking involves the use of pixel tags that are not visible to the user and consist of a few lines of computer code. Pixel tracking measures the effectiveness of advertisements and compiles aggregate and specific usage statistics. A “pixel tag” is an invisible tag placed on certain pages of websites that is used to track an individual user’s activity. We may access these pixel tags to identify activity and interests that may allow us to better match our Services, and offers with your interests and needs. For example, if you visit our Website from an advertisement on another website, the pixel tag will allow the advertiser to track that its advertisement brought you to the Website. If you visit our Website, and we link you to another website, we also may be able to determine that you were sent to and/or transacted with a third-party website. This data is collected for use in our marketing, research, and other activities.
GIF. We may use tiny images known as clear GIFs to track behavior of users, including statistics on who opens our emails.
IP Address. Our servers (or those of our service providers) automatically record certain log file information reported from your browser when you access the Website. These server logs may include information such as which pages of the Website you visited, your internet protocol (“IP”) address, browser type, and other information on how you interact with the Website. These log files are generally deleted periodically.
Information We Collect from Third Parties
We may collect information that others provide about you when you use the Website, or obtain information from other sources and combine that with information we collect through the Website.
- Third Party Services. If you link, connect, or login to your account with a third party social media service (e.g., Facebook, Google, Instagram, Yelp, etc.), the third party service may send us information such as your registration and profile information from that service. This information varies and is controlled by that service or as authorized by you via your privacy settings at that service.
- Other Sources. To the extent permitted by applicable law, we may receive additional information about you, such as demographic data or fraud detection information, from third party service providers and/or partners, and combine it with information we have about you. For example, we may receive background check results or fraud warnings from service providers like identity verification services for our fraud prevention and risk assessment efforts. We may receive information about you and your activities on and off the Website through partnerships, or about your experiences and interactions from our partner ad networks. Other examples of such providers include, but are not limited to, backend processing, fulfillment, and automation, certification, video hosting platform, email management, authentication, form processing, website usage tracking, managing calendar invites and scheduling, and database hosting and management.
Some content or applications on the Mobile App or Website are served by third parties, including advertisers, ad networks and servers, content providers and application providers. First-party or third-party cookies may be used alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our Website. A first-party cookie is a cookie set by the domain name that appears in the browser address bar. A third-party cookie is a cookie set by (and on) a domain name that is not the domain name that appears in the browser address bar. It might be set as part of a side resource load (image, JS, iframe, etc., from a different hostname) or an AJAX HTTP request to a third-party server. The information that first-party and third-party cookies collect may be associated with your Personal Information or they may collect information, including Personal Information, about your online activities over time and across different websites and other online services (i.e., tracking such activities). They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.
We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly. More information on how to opt-out of third-party advertiser tracking mechanisms here.
Google Tools. We use tools provided by Google as described below.
Google AdSense Advertising. We use Google AdSense Advertising (or other search engine or display network advertising) on our website. Google’s advertising requirements and principles are available here. They are put in place to provide a positive experience for users. We have implemented the following: (a) Remarketing with Google AdSense and (b) Google Display Network Impression Reporting.
We, along with third-party vendors such as Google, use first-party cookies (such as the Google Analytics cookies) and third-party cookies (such as the DoubleClick cookie) or other third-party identifiers together to compile data regarding user interactions with ad impressions and other ad service functions as they relate to our Website.
Google reCAPTCHA. We use Google reCAPTCHA, which identifies bots by collecting hardware and software information and sending that data to Google for analysis. More about Google reCAPTCHA is available here.
Users can set preferences for how Google advertises to you using the Google Ad Settings page. Alternatively, you can opt out by visiting the Network Advertising Initiative Opt Out page or by using the Google Analytics Opt Out Browser add-on.
You also may submit information, such as comments, reviews, testimonials, etc., to be published or displayed (“posted”) on public areas of the Website, or transmitted to other users of the Website or third parties (collectively, “Content”). Your Content is posted and transmitted to others at your own risk. We cannot control the actions of other users of the Website with whom you may choose to share your Content. Therefore, we cannot and do not guarantee that your Content will not be viewed by unauthorized persons. By posting any Content or submitting Content for posting you agree to and do hereby grant us and our licensors, affiliates, partners, successors and assigns, a nonexclusive, perpetual, irrevocable, worldwide, sublicensable, transferrable, royalty-free right and license to use, store, display, publish, transmit, transfer, distribute, reproduce, rearrange, edit, redact, modify, aggregate, summarize, adapt, create derivative works of and publicly perform the Content that you post or otherwise submit to us for any purpose, in any form, medium, or technology now known or later developed (“Right to Use”).
The Right to Use you grant us above also extends to any Content that you have posted to our Facebook or other social media account pages, or on other websites, e.g., Google, Yelp, Trip Advisor, Instagram, etc. The term “Use” includes, but is not limited to, use, reproduce, modify, publish, list information regarding, edit, delete, translate, distribute, publicly display, publicly perform, and make derivative works of the content.
If we permit you to post Content, by posting any Content, or submitting Content for posting, you agree to with the following “User Content Posting Guidelines”:
To the extent our Website contains areas where you can post or submit to be posted such as comments, product reviews, testimonials, etc., you agree to post Content that is proper and related to the general theme of the Website. Content also includes that which you send to us by email, text, mail, or other means. You agree not to post or submit any Content that:
- Is off-topic, false, inaccurate, misleading, defamatory, libelous, stalking, threatening, obscene, pornographic, indecent, vulgar, offensive, which contains unlawful material or information, or which otherwise violate the legal rights (such as rights of privacy and publicity) of others;
- Harasses, degrades, intimidates, or is hateful toward an individual or group of individuals on the basis of religion, gender, sexual orientation or identity, race, ethnicity, age, or disability;
- Is not your own original creation or that you do not have permission to use or that infringes the copyright, trademark, patent, or other proprietary right of any person or that is used without the permission of the owner;
- Is intended to provide professional advice, including but not limited to, the provision of medical treatment, or legal, financial or investment advice;
- Promotes or provides instructional information about illegal or illicit activities;
- Purports to be from any person or entity, including but not limited to one of our employees, or falsely states or otherwise misrepresents your affiliation with a person or entity;
- Includes personal or identifying information about another person without that person’s explicit consent, or is doxxing;
- Contains malicious software code of any kind, including, but not limited to, code that contain viruses, malware, corrupted files, or any other similar software or programs designed to or that may interrupt, lock up, destroy, damage or limit the operation of another person’s computer or network or telecommunications equipment;
- Disrupts the normal flow of dialogue with an excessive number of messages (flooding attack) to the Website, or that otherwise negatively affects the ability of others to use the Website; or,
- Advertises or offers to sell any goods or services, or engage in surveys, contests, chain letters, or for any commercial purpose.
How We Use Your Information
We use information that we collect about you or that you provide to us, including any Personal Information, for one or more of the following purposes:
- To present our Mobile App and Website and its contents to you.
- To provide you with information and respond to your questions on Services that you request from us and information on new products and services, discounts, special promotions or upcoming events, and features or offers that we believe will be of interest to you.
- To provide you with the Services or information that you have requested.
- To process transaction payments, including, but not limited to, Service fees, subscription fees, professional fees, membership dues, registration fees, and payments, refunds and reimbursements for any products or services that you choose to purchase from us (though we do not receive your credit or debit card number).
- To provide you with notices about your account, including expiration and renewal notices.
- To notify you about information regarding or changes to our Website, our policies, terms, or any Services we offer or provide, or regarding your account.
- To process your account application and any changes to your account information.
- To process Personal Information or other information that you submit through to us.
- To allow you to participate in interactive features on our Website.
- To contact you about our own and third-parties’ products and services that may be of interest to you.
- To enhance and improve our Services, for example, by performing internal research, analyzing user trends, and measuring demographics and interests.
- For internal purposes, such as Website or Service and system operation, administration, maintenance, internal audits and reviews, diagnosing technical problems, and maintaining security.
- To provide statistics about the usage levels of the Website and other related information to our service providers.
- To notify you of data privacy incidents or provide you with legally required information.
- To contact you regarding a promotion, contest, or sweepstakes in which you have participated.
- To request your participation in ratings, reviews, surveys, focus groups, or other initiatives which help us to gather information used to develop and enhance our Mobile App, Website, and Services.
- To determine eligibility for membership, credentials, designations, or volunteer opportunities.
- To fulfill any other purpose for which you provide Personal Information.
- In any other way we may describe and for which we obtain your consent when you provide the information and you give your consent.
We may use your Personal Information you provide us and which we obtain from other sources to better understand your interests so we can try to predict what other products, services and information you might be most interested in. This practice involves making automated decisions about you based on this information in order to better enable us to tailor our interactions with you to make them more relevant and interesting. You may object to our doing this at any time by contacting us (see Contact Information/User Rights below).
We may use the information we have collected from you to enable us to display advertisements to our advertisers’ target audiences. Even though we do not disclose your Personal Information for these purposes without your consent, if you click on or otherwise interact with an advertisement, the advertiser may assume that you meet its target criteria.
Our Services may include sending you Short Message Service (“SMS”) messages, which may deliver up to two messages per day to your wireless device (unless you communicate further with us), but message frequency may vary. We may use your information to contact you about your purchases, returns (if available), Website updates, conduct surveys, or informational and service-related communications, including important security updates. You may remove your information by replying “STOP” to the SMS text message you received. After you send the SMS message “STOP” to us, we will send you an SMS message to confirm that you have been unsubscribed. Alternatively, you may submit your request by email to us, including the email address and phone number you registered with us, or by any reasonable means. After this, you will no longer receive SMS messages from us. If you want to join again, just sign up as you did the first time and we will start sending SMS messages to you again. For help, please reply to a text with HELP. Message and data rates may apply, depending on your cell phone plan. Carriers are not liable for delayed or undelivered messages.
Social Media Plugins
We integrate social media application program interfaces or plug-ins (“Plug-ins”) from social networks, including Facebook, Google+, LinkedIn, Xing, Twitter, Instagram, Tumblr, Pinterest and/or possibly other companies, into the Website. In order to register as a user with us, you may have the option to sign in using your Facebook or other social media site login.
For example, when you visit our Website, the plugin creates a direct connection between your browser and the Facebook server. This allows Facebook to receive information about your visit to our Website with your IP address. If you click the Facebook “Like” button while you are logged on to your Facebook account, you can link the contents of our Website to your Facebook profile. This allows Facebook to assign your visit to our Website to your user account. Please note that as provider of the Website, we receive no notification about the contents of the transmitted data or their use by Facebook. If you do not want Facebook to assign your visit to our Website to your Facebook user account, please log out of your Facebook user account.
How We Share Your Personal Information
We may or do disclose your Personal Information, in whole or in part, to the following types of third parties, and for one or more of the following purposes:
- Data storage or hosting providers for the secure storage and transmission of your data
- Database and software service providers for the management and tracking of your data
- Technology providers who assist in the development and management of our Mobile App and Website
- Identity management providers for authentication purposes
- Legal and compliance consultants, such as external counsel, external auditors, or tax consultants
- Payment solution providers for the secure processing of payments you provide to us
- Manufacturers, retailers, and wholesalers for submission, processing, and management of rebates, discounts, offers, loyalty rewards, and the like
- Outbound call center providers, who may perform outreach on our behalf regarding our Services
- Fulfillment and shipping vendors for the fulfillment of our products and Services
- Survey and research providers who perform studies on our behalf
- Advertising partners, including social media providers, for the delivery of targeted advertisements
Disclosures to Service Providers. We may share your Personal Information with third parties for the purpose of providing or improving the Services to you. We may share your Personal Information with third party service providers which perform services on our behalf (“Service Providers”). This includes, without limitation, Service Providers which provide services relating to: outbound and/or inbound communications, data analysis, credit checks, screening checks, collection services, marketing assistance, managing customer information, creating, hosting, and/or providing customer or support services on our behalf, fulfilling orders, delivering packages, sending postal mail and email, removing repetitive information from customer lists, providing search results and links (including paid listings and links), processing credit card payments, or managing our conferences and other events. These Service Providers may have access to your Personal Information in order to provide these services to us or on our behalf. If we engage Service Providers for any of the foregoing, use of your Personal Information will be bound by obligations of confidentiality and their use of Personal Information will be restricted to providing their services to us. We may store Personal Information in locations outside our direct control (for instance, on servers or databases located or co-located with hosting Service Providers).
Event-Related Disclosure. From time to time, we may conduct events, run contests, make special offers, or other activities (“Events”), possibly together with an exhibitor, sponsor or other Service Provider. If you provide information to such third parties, you give them permission to use it for the purpose of that Event and any other use to which you consent. We cannot control such third parties’ use of your information. If you do not want your information to be collected by or shared with such third parties, you can choose not to participate in these Events.
We will attempt to notify you, where practicable, about these requests unless: (i) providing notice is prohibited by the legal process itself, by court order we receive, or by applicable law, or (ii) we believe that providing notice would be futile, ineffective, create a risk of injury or bodily harm to an individual or group, or create or increase a risk of fraud upon us, our users, our Website, or our Services. In instances where we comply with legal requests without notice for these reasons, we will attempt to notify that user about the request after the fact if we determine in good faith that we are no longer legally prohibited from doing so and that no risk scenarios described in this paragraph apply.
SALE/DISCLOSURE OF PERSONAL INFORMATION
Disclosures to Marketing Partners.
From time to time we might establish a business relationship with other persons or entities whom we believe trustworthy and whom we have asked to confirm that their privacy policies are consistent with ours (“Partners”). In such cases we might rent, exchange, share, and/or cross-reference information, including your Personal Information that will enable such Partners to contact you regarding their products and services that may be of interest to you.
Disclosure of De-Identified Personal Information. We may share De-Identified Personal Information with third parties for any purpose. De-Identified Personal Information or non-Personal Information may be aggregated for system administration and to monitor usage of the Website. It may be utilized to measure the number of visits to our Website, average time spent, number of pages viewed and to monitor various other Website statistics. This monitoring helps us evaluate how visitors use and navigate our Website so we can improve the content. We may share De-Identified Personal Information or anonymous information (including, but not limited to, anonymous usage data, referring/exit pages and URLs, IP address, platform types, number of clicks, etc.) with interested third parties in any way we choose and for any purpose. We may disclose, sell, rent, etc., your De-Identified Personal Information to third parties and we may receive valuable consideration for doing so.
Your Consent to Disclosure/Transfer/Sale of Your Personal Information. You consent to our disclosure of your Personal Information, De-Identified Personal Information, and other information you provide to us (collectively, “Transferred Information”) to a potential or actual buyer or acquirer of our company or other successor for the purpose of considering or undergoing a merger, divestiture, restructuring, reorganization, dissolution, change in control, or sale or transfer of some or all of our assets (each of the foregoing referred to as a “Transfer”), whether as a going concern or as part of bankruptcy, liquidation or other court proceeding, in which Personal Information held by us is among the assets transferred. You agree to and do hereby consent to (and shall not object to) our assignment, conveyance, transfer, and/or license (whether by contract, merger, or operation of law) as part of a Transfer, of any or all of our rights, in whole or in part, in or to Transferred Information and your consents, with or without notice to you and without your further consent. We cannot make any representations regarding the use or transfer of Transferred Information that we may have in the event of our bankruptcy, reorganization, insolvency, receivership, or an assignment for the benefit of creditors. By providing any Personal Information, you expressly agree and consent to the use and/or transfer of Transferred Information or other information in connection with a Transfer. Furthermore, except as required by law, we are not and will not be responsible for any breach of security by any third parties or for any actions of any third parties that receive any of the Transferred Information that is disclosed to us.
We have implemented measures designed to secure your Personal Information from accidental loss and from unauthorized access, use, alteration and disclosure. Your Personal Information is contained behind secured networks and a firewall and is only accessible by our personnel and by a limited number of Service Providers who have special access rights to our systems, and who are required to keep the information confidential. Our Website and Mobile App are scanned on a regular basis for security holes and known vulnerabilities in order to make your visit to our Mobile App and Website safe.
Unfortunately, the transmission of information via the internet is not completely secure. Although we do use security measures designed to protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted to us or which we obtain. Any transmission of Personal Information is at your own risk. Unauthorized entry or use, or hardware or software failure, and other factors, may compromise the security of user information at any time. We are not responsible for circumvention of any privacy settings or security measures contained on the Website or used with our Services.
The time period for which we retain your Personal Information depend on the purposes for which we use it. We will retain your Personal Information for as long as your account is active, or as long as you are a registered account holder or user of our Services or for as long as we have another business purpose to do so (such as, but not limited to, for business, tax, or legal purposes) and, thereafter, for no longer than is required or permitted by law, or our records retention policy, reasonably necessary for internal reporting and reconciliation purposes, or to provide you with feedback or information you might request. This period of retention is subject to our review and alteration.
We may retain De-Identified Personal Information for as long as we deem appropriate.
Even if you delete your account, keep in mind that the deletion by our Service Providers may not be immediate and that the deleted information may persist in backup copies for a reasonable period of time. We may retain De-Identified Personal Information for as long as we deem appropriate.
What Information You Can Access, Change, or Delete
Through your user account settings page, you may access and, in some cases, edit, or delete certain information you have provided to us, such as name and password, email address, address, user profile information, etc. The information that you can view, update, and delete may change as the Mobile App, Website, Services or our practices change. If you have any questions about viewing or updating information we have on file about you, please contact us.
Privacy Notice for California Residents
The following in this section applies only to California residents.
California Online Privacy Protection Act (“CalOPPA”; Calif. Bus. & Prof. Code § 22575-22578, available here):
CalOPPA applies only to companies which collect Personal Information of California residents.
How We Respond to Do Not Track Signals.
CalOPPA requires us to let you know how we respond to web browser Do Not Track (“DNT”) signals. DNT is a privacy preference you can set in your web browser to indicate that you do not want certain information about your webpage visits collected across websites when you have not interacted with that service on the page. For details, including how to turn on DNT, see here. Because there currently isn’t an industry or legal standard recognizing or honoring DNT signals, we don’t respond to them at this time. We await the result of work by the privacy community and industry to determine when such a response is appropriate and what form it should take.
Visitors can visit our Website anonymously by adjusting the settings in your browser.
Third-Party Behavioral Tracking. We do not allow third-party behavioral tracking of Personal Information, though we may use De-Identified Personal Information to track users’ click or browsing patterns.
California Consumer Privacy Act of 2018 (“CCPA”, available here) and its successor, the California Privacy Rights Act of 2020 (“CPRA”, available here). If you are a California resident (occasionally referred to as “Consumer”), California law provides you with additional rights regarding our use of your Personal Information. For purposes of this California Consumer Privacy Notice and only for California residents, the term Personal Information means “personal information” as defined under CCPA.
This “Privacy Notice for California Residents” section does not apply (at least until January 1, 2023) to the Personal Information of California residents that we collect (or which our Service Providers collect on our behalf):
- which reflects a written or verbal communication or a transaction between the business and the consumer, where the consumer is a natural person who acted or is acting as an employee, owner, director, officer, or independent contractor of a company, partnership, sole proprietorship, non-profit, or government agency and whose communications or transaction with the business occur solely within the context of the business conducting due diligence regarding, or providing or receiving a product or service to or from such company, partnership, sole proprietorship, non-profit, or government agency; or,
- about you in the course of your acting as a job applicant to, an employee of, owner of, director of, officer of, medical staff member of, or independent contractor of, our company to the extent that your Personal Information is collected and used by us solely within the context of your role or former role as a job applicant to, an employee of, owner of, director of, officer of, medical staff member of, or an independent contractor of, our company.
California residents have the right to (a) access a copy of their Personal Information held by us, (b) request deletion of their Personal Information held by us, and, (c) opt-out of the sale of their Personal Information. These rights can be exercised by OPTION A: completing and submitting the webform available here ///OPTION B: contacting us.
Sale of Personal Information
In the preceding twelve (12) months, we have not sold any Personal Information.
Data Access and Portability Right
You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past 12 months. Once we receive and confirm your verifiable Consumer request, we will disclose to you:
- The categories of Personal Information we collected about you.
- The categories of sources for the Personal Information we collected about you.
- Our business or commercial purpose for collecting that Personal Information.
- The categories of third parties with whom we share that Personal Information.
- The specific pieces of Personal Information we collected about you (also called a data portability request) and provide a copy to you in an electronic or paper format.
- If we disclosed your Personal Information for a business purpose, a list disclosing disclosures for a business purpose, identifying the Personal Information categories that each category of recipient obtained.
Deletion Request Right
You have the right to request that we delete any of your Personal Information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable Consumer request, we will delete (and direct our service providers to delete) your Personal Information from our records, unless an exception applies (as described below).
As permitted by CCPA we may delete your Personal Information by (a) permanently and completely erasing the Personal Information on our existing systems with the exception of archived or back-up systems; (b) de-identifying the Personal Information; or, (c) aggregating the Personal Information.
We may deny your deletion request if retaining the information is necessary for us or our Service Provider(s) to:
- Complete the transaction for which we collected the Personal Information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Correct Services, our Mobile App, or our Website to identify and repair errors or issues that might impair existing or intended functionality.
- Exercise free speech, ensure the right of another Consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal, regulatory or law enforcement obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
Exercising Access, Data Portability, and Deletion Rights
To exercise the access, data portability, and deletion rights described above, please submit a verifiable Consumer request to us by: sending an email to us at firstname.lastname@example.org, or by mailing a request to us at 312 South Alameda Street Los Angeles, CA 90013 USA. Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable Consumer request related to your Personal Information. You also may make a verifiable Consumer request on behalf of your minor child. You may only make a verifiable Consumer request for access or data portability twice within a 12-month period. The verifiable Consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you. Making a verifiable Consumer request does not require you to create an account with us. We will only use Personal Information provided in a verifiable Consumer request to verify the requestor’s identity or authority to make the request.
Email Verification Method: Upon receiving a data access or deletion request from you we will send an email to you at the email address we have for you on file. The email will ask you to respond to verify you as the Consumer making the request. Upon receipt of your verification we will match your information to that which is in our file. Upon verification of your identity we will proceed to process your request (subject to the exceptions stated above).
Response Timing and Format
We will confirm receipt of your request within ten (10) business days of receiving it. We will respond to a verifiable Consumer request within forty-five (45) calendar days of its receipt. If we require more time (up to an additional forty-five (45) calendar days), we will inform you of the reason and extension period in writing.
If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the 12-month period preceding the verifiable Consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable Consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Please note that this right does not apply to business-to-business customers, employment applicants, or independent contractors to us, or if the disclosure of Personal Information is for purposes consistent with the California resident’s reasonable expectations, when considering the submission’s circumstances.
Personal Information Sales Opt-Out and Opt-In Rights
If you are 16 years of age or older, you have the right to direct us to not sell your Personal Information at any time (the “right to opt-out”). We do not sell the Personal Information of Consumers we actually know are less than 16 years of age, unless we receive affirmative authorization (the “right to opt-in”) from either the Consumer who is between 13 and 16 years of age, or the parent or guardian of a Consumer less than 13 years of age. California Consumers who opt-in to Personal Information sales may opt-out of future sales at any time.
Once you make an opt-out request, we will wait at least twelve (12) months before asking you to reauthorize Personal Information sales. However, you may change your mind and opt back in to Personal Information sales at any time by sending an email to email@example.com.
You do not need to create an account with us to exercise your opt-out rights. We will only use Personal Information provided in an opt-out request to review and comply with the request.
We will not discriminate against you simply for your exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny you goods or services;
- Charge you different prices or rates for goods or services, including by refusing to gran discounts or other benefits, or imposing penalties;
- Provide you a different level or quality of goods or services; or,
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
We may not be able to comply with your request if (a) we are unable to verify your request, (b) if we are unable to match you with information in our database, or (c) if an exception under the law exists exempting us from complying with your request.
Privacy Rights Notice For Nevada Residents Only
Nevada residents have the right to opt-out of the sale of their Personal Information by emailing us at firstname.lastname@example.org, and including “NV Sale Opt Out Request” in the subject line. Please note we will take reasonable steps to verify your identity and the authenticity of the request. We will respond to your request within sixty (60) days and, once verified, we will maintain your opt-out request in the event our practices change. Please note that this right does not apply to business-to-business customers, employment applicants, or independent contractors to us, or if the disclosure of Personal Information is for purposes consistent with the Nevada resident’s reasonable expectations, when considering the submission’s circumstances.
Notices; Opting Out
By providing us with your email address (including by “following”, “liking”, linking your account to our Website or Service or other services, etc., on a third party website or network), you consent to our using the email address to send you Service-related notices by email, including any notices required by law (e.g., notice of data privacy or security incidents), in lieu of communication by postal mail. You also agree that we may send you notifications of activity regarding our Mobile App, Website, your Personal Information, or any aspect of our relationship, to the email address you give us, in accordance with any applicable privacy settings. We may use your email address to send you other messages or content, such as, but not limited to, newsletters, additions or changes to features of the Service, or special offers. If you do not want to receive such email messages, you may opt out by emailing us your opt-out request or, where available, by clicking “unsubscribe” at the bottom of our e-newsletter. Opting out may prevent you from receiving email messages regarding updates, improvements, special features, announcements, or offers. You may not opt out of Service-related emails. Please note that if you have opted not to receive legal notice emails from us (or you haven’t provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them.
You can add, update, or delete information as explained above. When you update information, however, we may maintain a copy of the unrevised information in our records. You may request deletion of your account by emailing us. It is your responsibility to maintain your current email address with us.
Where We Process and Store Personal Information
We have our headquarters in the United States. The Personal Information we or our service providers collect may be stored and processed in servers within or outside of the United States and wherever we and our service providers have facilities around the globe, and certain information may be accessible by persons or companies outside of the United States who provide services for us. You consent to our and our service providers’ transmission and/or transfer of your Personal Information to, or access it in, jurisdictions that may not provide equivalent levels of data protection as your home jurisdiction. We will take reasonable steps to ensure that your Personal Information receives an adequate level of protection in the jurisdictions in which we process it.
If you are a resident or citizen of the UK, European Economic Area (“EEA”), or Switzerland, please see the section below on GDPR compliance.
If you are a citizen or resident of the UK, EEA, Switzerland, or other regions with laws governing data collection and use that may differ from the laws in the United States, please note that we may transfer your information to a country or jurisdiction that does not have the same data protection laws as your jurisdiction. We may do so to process your information by staff operating outside the these countries who work for us or for one of our service providers.
If you are a resident of a country other than the United States, you acknowledge and consent to our collecting, transmitting, processing, transferring, and storing your Personal Information out of the country in which you reside.
GDPR: The Following Provisions Apply Only to Citizens and Residents of the United Kingdom, EEA, and Switzerland
We provide adequate protection for the transfer of Personal Information to countries outside of the UK, EEA, or Switzerland through one or more of the following methods: (a) a series of intercompany agreements based on or incorporating the Standard Contractual Clauses, (b) we may rely on the European Commission’s adequacy decisions about certain countries, as applicable, (c) we may obtain your consent for these data transfers from Europe to the United States to other countries, (d) we may adopt binding corporate rules, or (e) to the extent applicable, we may rely on derogations as set forth in GDPR Article 49 for the transfer and onward transfer of personal information collected from individuals in Europe to the United States and other countries that the EU views as not providing adequate data protection. Regarding method (e), we may transfer Personal Information to a third party to perform a contract with you, with your explicit consent or in a manner that does not outweigh your rights and freedoms. If this Personal Information is not processed and transferred, we will not be able to execute the contract with you or you will not have access to any or all the benefits and features associated with your transaction.
We also may need to transfer your information to other group companies or service providers in countries outside the EEA. This may happen if our servers or suppliers and service providers are based outside the UK, EEA, or Switzerland, or if you use our Mobile App and/or Services while visiting countries outside these areas.
Our Legal Basis for Processing Personal Data (UK, EEA, and Swiss Visitors Only)
If you are a visitor using our Website from the UK, EEA, or Switzerland, our legal basis for collecting and using the Personal Data described above will depend on the Personal Data concerned and the specific context in which we collect it. However, we will normally collect Personal Data from you only where we need the Personal Data to perform Services for you for which you have contracted with us, or where the processing is in our legitimate interests or rely upon your consent where we are legally required to do so and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we also may have a legal obligation to collect Personal Data from you or may otherwise need the Personal Data to protect your vital interests or those of another person.
The collection and processing of your personal information may be necessary for the purposes of our legitimate interests. Such legitimate interest purposes may include:
- fraud prevention
- ensuring network and information security
- when we are complying with legal obligations
- processing employee or visitor, member, attendee, or registrant data
- performing the function or service you requested of us
- providing our Services and their functionality to you where such processing is necessary for the purposes of the legitimate interests pursued by us or by our service providers related to the Services
- direct marketing
- the relevant and appropriate relationship we have with you
- analytics, e.g., assess the number of visitors, page views, use of the Website, etc., in order to understand how our Website, Mobile App, and Services are being used, to optimize the Website and/or future communications, and to develop new services and Website features
- updating your information and preferences
- offering and improving our Website, Mobile App, and Services
- enforcing legal claims, including investigation of potential violations of our Terms
Your Data Rights Under GDPR
If you are subject to GDPR, your rights include the following:
- The right to access – Upon request, we will confirm any processing of your Personal Information and, and provide you with a copy of that Personal Information in an acceptable machine-readable format.
- The right to rectification – You have the right to have us correct any inaccurate Personal Information or to have us complete any incomplete Personal Information.
- The right to erasure – You may ask us to delete or remove your Personal Information and we will do so in some circumstances, such as where we no longer need it (we may not delete your data when other interests outweigh your right to deletion).
- The right to restrict processing – You have the right to ask us to suppress the processing of your Personal Information but we may still store your Personal Information. See below for more information.
- The right to object to processing – You have the right to object to your Personal Information used in the following manners: (a) processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling); (b) direct marketing (including profiling); and, (c) processing for purposes of scientific/historical research and statistics. See below for more information.
- The right to data portability – You have the right to obtain your Personal Information from us that you consented to give us or that is necessary to perform fulfillment of member benefits with you. We will give you your Personal Information in a structured, commonly used and machine-readable format.
- Rights regarding automated decision making – You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except for the exceptions applicable under relevant data protection laws.
- The right to complain to a supervisory authority – You have the right to file a complaint with a supervisory authority, in particular in the European member state of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of Personal Information relating to you infringes upon your rights.
- The right to withdraw consent – If we are processing your Personal Information based on your consent to do so, you may withdraw that consent at any time.