SECTION 1 - WHAT DO WE DO WITH YOUR INFORMATION?
When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address and email address.
When you browse our store, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.
Email marketing (if applicable): With your permission, we may send you emails about our store, new products and other updates.
SECTION 2 - CONSENT
How do you get my consent?
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no.
How do I withdraw my consent?
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at email@example.com.
SECTION 3 - DISCLOSURE
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.
SECTION 4 - Bigcommerce
Our store is hosted on Bigcommerce. They provide us with the online e-commerce platform that allows us to sell our products and services to you. Your data is stored through Bigcommerce’s data storage, databases and the general Bigcommerce application. They store your data on a secure server behind a firewall.
If you choose a direct payment gateway to complete your purchase, then Bigcommerce stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service here or Privacy Statement here.
SECTION 5 - THIRD-PARTY SERVICES
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
As an example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
SECTION 6 - SECURITY
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
SECTION 7 - COOKIES
Here is a list of cookies that we use. We’ve listed them here so you that you can choose if you want to opt-out of cookies or not.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
SECTION 8 - AGE OF CONSENT
By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
QUESTIONS AND CONTACT INFORMATION
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at firstname.lastname@example.org.
PRIVACY NOTICE FOR ADROLL
1. About AdRoll Group's Services
AdRoll Group provides targeted advertising and marketing services for our advertiser clients ("Advertisers").
Our products help show our customers’ ads to the people that are most likely to find them interesting. We aim to make advertising more useful and relevant to consumers by showing ads that are best tied to their specific interests. And we show these ads on websites which rely on advertising revenue to support the content we all consume each day, often for free.
To do this, when you visit a website or a mobile application operated by an Advertiser (collectively “Digital Properties”) or we serve you an ad on behalf of an Advertiser on a third party site, we may collect some or all of the data described in this Privacy Notice. Our platform uses that data, as well as other data described below, to help Advertisers provide ads to you that are more relevant to you.
For example, let’s say you just joined a local soccer club and are in the market for a new soccer ball. If you visit ACME Soccer Ball Co.’s website in search of the perfect soccer ball, but don’t purchase one just yet because you are still looking, we may later show you ACME Soccer Ball Co. ads to encourage you to come back and purchase one of their soccer balls, perhaps even with a discount offer or notice of an upcoming sale. We may also show you ads from ACME Soccer Ball Co. or other companies with additional product recommendations you may be interested in, such as for soccer cleats, or tickets to an upcoming soccer match, as you browse the internet. If you gave ACME Soccer Ball Co. your email address for marketing purposes, we may also serve ACME Soccer Ball Co. ads to you through other channels, such as by email.
2. What data we collect
We collect the following categories of information for the purposes explained below.
- Activity on Advertisers’ Digital Properties: This is data about your browsing activity on the Advertiser's website or app. For example, which pages you visited and when, what items were clicked on a page, how much time was spent on a page, whether you downloaded a white paper on a business to business website, what items you placed into your online shopping cart, what products were purchased and how much was paid.
- Device and browser information: This is technical information about the device or browser you use to access the Advertiser's website. For example, your device's IP address, cookie string data, operating system, and (in the case of mobile devices) your device type and mobile device's unique identifier such as the Apple IDFA or Android Advertising ID.
- Ad data: This is data about the online ads we have served (or attempted to serve) to you. It includes things like how many times an ad has been served to you, what page the ad appeared on, and whether you clicked on or otherwise interacted with the ad.
- Data from Advertising Partners: This is data that we lawfully receive from other digital advertising companies that we work with (“Advertising Partners”) to help us deliver ads to you and recognize you across browsers and devices. This may include pseudonymous advertiser identifiers (meaning identifiers that help identify your browser or device, but do not directly identify you as a person) which some Advertisers or other third party Advertising Platforms choose to share with us – for example, your "Customer ID" with an Advertiser, an identifier (such as a cookie) associated with a hashed version of your email address, or demographic data such as age range. We may work with our Advertisers and Advertising Partners to synchronize their unique, anonymous identifiers to our own to enable us to more accurately recognise a particular unique browser or device and the advertising interests associated with it.
- Email from Advertisers: Some Advertisers choose to share actual email addresses from their customers with us, so that (with the help of Advertising Partners) we can help the Advertiser serve targeted ads to customers. For example, if you have given ACME Soccer Ball Co. your email address, through our service, ACME Soccer Ball Co. may send you a promotional email for a soccer ball you looked at but did not purchase. Similarly if you provided your email to a software website when you downloaded a white paper, through our services the software company may send you a follow up email providing you with more information about the software company’s products or services. We use clear emails supplied by Advertisers only for the purpose of assisting that particular Advertiser with their own advertising efforts and, in some cases, so we can report performance data back to the Advertiser’s CRM / reporting system. – we do not share email addresses with other third parties for their advertising purposes.
- Hashed email addresses: If an Advertiser allows, we may collect hashed versions of the emails that are entered on that Advertiser’s site. Hashing is a “one-way function” that effectively pseudonymizes email addresses. For instance, when email@example.com is run through a typical hashing function, it becomes the following string of code: 0F0B7B1A1A7E8BDBBC6AA545F8CCD6F83671B32479271BFCB6CC8498912058D5.
- We take this step to de-identify data and protect email addresses, while being able to use an identifier to better connect devices and browsers. We describe how this helps us better provide our services in “How we use the data we collect” below.
3. How we use the data we collect
We use this data to help our Advertisers identify and serve ads to you that are more relevant to you. We also use this data to operate, improve and enhance our services including enhancing the data points we or our Advertising Partners have about a particular user, browser, or device to serve the most relevant ads to you and, in turn, improve performance of an Advertiser’s ad campaigns. Specifically, we use this data for:
- Targeting: Selecting ads that are more likely to be relevant to you based on the interests previously associated with your device and the time of day you may be most interested in viewing these specific ads. For example, we may show you ads for your favorite shopping site (or similar sites we think you may like) during lunch or commute hours.
- Frequency capping: Making sure that you don't see the same ad too many times.
- Sequencing: If you are being served a sequence of ads, making sure we show you the right ad next in the sequence.
- Cross-device matching: Identifying all devices that are likely to be associated with you so that ads can be targeted, capped and sequenced across those devices. For example, cross-device matching helps us NOT show you ads for the shoes you were looking at on your phone but that already purchased on your tablet. Instead we’ll try to show you ads for an upcoming triathlon where you can put those shoes to work. It also helps us match devices so we can honor your opt-out choices across all devices we know are connected to the opted-out cookie.
- Attribution: Monitoring when, where, and at what price we served certain ads on behalf of an Advertiser so that we can measure our influence on the marketing result of the Advertiser’s campaigns and overall marketing strategy. For example, being able to measure if a certain ad campaign (the ads shown and to whom they were shown) actually sold more soccer balls for ACME Soccer Ball Co.
- Reporting: Providing Advertisers insights into how their ads are performing and gain insights into their customers. Reporting may include ad metrics such as impressions, clicks, and conversions (however the Advertiser may define a “conversion,” for example, a sale or a white paper download). For example, if an ad is not performing well (customers aren’t clicking on it), the Advertiser will be able to see that data and update the ad (perhaps with a better deal!). With respect to specific cookie data, we limit reporting to cookie activity on the specific Advertiser’s website and which ads were shown whether there was engagement with those ads.
Data is reported in the aggregate for the campaign and, at times, at the cookie level. For some customers, ad metrics are reported at the domain level at the contact level. For some customers, ad metrics such as impressions, clicks, conversions etc. are aggregated at the domain level (the domain representing the company/account the Advertiser wanted to target) as well as at the contact level (the individual to whom the ad is being targeted) represented with an email address that was initially provided by the Advertiser.
4. Our legal basis for processing personal data (European Territory Visitors only)
We provide the representations and information in this Section 4 in compliance with European privacy laws, in particular the European General Data Protection Regulation (GDPR). They are specific to persons located in EEA countries or Switzerland, so please don’t rely on the below, if you’re not in one of those countries.
If you are a visitor from the European Territories, our legal basis for collecting and using the personal data described above will depend on the personal information concerned and the specific context in which we collect it. "European Territories" mean the European Economic Area and Switzerland. For the purpose of this Privacy Notice, the term "European Territories" shall continue to include the United Kingdom, even after the United Kingdom leaves the European Economic Area following Brexit.
However, we will normally collect personal data from you where the processing is in our legitimate business interests to, for example, administer our platforms and services and fulfil our contractual obligations as a service provider.
In some cases we may collect and process personal data based on consent. To the extent our clients and Advertising Partners need to collect and share, or allow us to facilitate collection and sharing of personal data to enable our services, it is the responsibility of these parties to provide necessary privacy notices and obtain required consent(s).
If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, including if you would like to better understand how our legitimate interests to process your data are balanced against your data protection rights and freedoms, then please contact us using the contact details provided under the “Contact us” heading below.
Finally, please note that when an Advertiser sends us email addresses to be used for targeted advertising purposes, we process that data only on behalf of the relevant Advertiser as its processor. If you have any questions about the use of this data by an Advertiser for the purpose of serving targeted advertising to you, please contact the relevant Advertiser.
5. Data Sharing
We may disclose information about you:
- With an Advertiser whose Digital Properties you have visited: We may share information about how you have interacted with that Advertiser’s Digital Properties or its Ads.
- With our service providers: We contract with companies who help with parts of our business operations (e.g., for example, website and data hosting, fraud prevention, viewability reporting, data hygiene, marketing, and email delivery), as well as billing, collections, tech, customer and operational support.
- With service providers to our Advertisers: Our Advertisers may contract with companies who handle data (such as managing Advertisers’ customer lists) for them.
- With our subsidiaries and related companies: But they will only process your data for the purposes already explained in this Privacy Notice. Our subsidiaries are AdRoll Advertising Limited (Ireland), AdRoll Holdings Limited (Ireland), AdRoll Limited (UK), AdRoll K.K. (Japan), and AdRoll Pty Limited (Australia).
- In connection with legal proceedings: When we are under a legal obligation to do so, for example to comply with a binding order of a court, or where disclosure is necessary to exercise, establish or defend the legal rights of AdRoll Group, our Advertisers or any other third party.
- To Comply with legal process: To satisfy in good faith any applicable law, legal process, or proper governmental request, such as to respond to a subpoena (whether civil or criminal) or similar process.
- To Investigate Wrongdoing and Protect Ourselves or Third Parties: To enforce our Terms of Service or other policies or investigate any potential violation of those Terms and policies, any potential violation of the law, or to protect ourselves, our customers, or any third party from any potential harm (whether tangible or intangible).
- In connection with a sale of our business: If a third party acquires some or all of our business or assets, we may disclose your information in connection with the sale (including during due diligence in preparation for the sale).
We also share hashed email addresses (or other pseudonymous identifiers associated with those hashes), technical data that we collect about your browsing habits and your device (such as data relating to our cookies, tracking pixels and similar technologies) with other advertising companies in the digital advertising ecosystem. This enables them and us to better target ads to you.
6. Cookies and related technologies
Tracking cookies enable us to identify your device when you move between different Digital Properties, so that we can serve targeted advertising to you.
Specifically, the AdRoll cookie we serve through the AdRoll platform for this purpose is named “__adroll”.
We may also drop cookies from our Advertising Partners for the purposes described above. The Advertising Partner cookies dropped will vary depending on who the Advertisers are.
Additionally, we use non-tracking cookies (not unique) to store user decisions in terms of your ad and opt-out choices
- We may drop an __adroll cookie with value opt-out if you opt-out as described below and an AdRoll consent cookie to track your consent choices.
- We may drop a __consent cookie that stores the choices you have made regarding data processing and advertising by AdRoll.
7. Your choices and opting-out
We recognize how important your online privacy is to you, so we offer the following options for controlling the targeted ads you receive and how we use your data:
- You can opt out of receiving personalized ads served by us or on our behalf by clicking on the blue icon that typically appears in the corner of the ads we serve and following the instructions provided or by clicking here. Please note that this “opt out” function is browser-specific and relies on an “opt out cookie”: thus, if you delete your cookies or upgrade your browser after having opted out, you will need to opt out again.
- In some cases we may link multiple browsers or devices to you. If you opt out of on a browser or device and we have more linked to you, we will extend your opt out decision to the other linked browsers and devices. Since we only link users across browsers on devices in some conditions, there could be cases where you are still being tracked in a different browser or device we have not linked, and where we are treating you as a different user.
- AdRoll Group is also a member of the Network Advertising Initiative (NAI) and adheres to the NAI Codes of Conduct. You may use the NAI opt out tool here, which will allow you to opt out of seeing personalized ads from us and from other NAI approved member companies.
- We also comply with the Self-Regulatory Principles for Online Behavioral Advertising as managed by the Digital Advertising Alliance (DAA). You may opt out of receiving personalized ads from other companies that perform ad targeting services, including some that we may work with as Advertising Partners via the DAA website here.
- We also comply with the Canadian Self-regulatory Principles for Online Behavioral Advertising as managed by the Digital Advertising Alliance of Canada (DAAC). You may opt out of receiving personalized ads from other companies that perform ad targeting services, including some that we may work with as Advertising Partners via the DAAC website here.
- We also adhere to the European Interactive Advertising Digital Alliance (EDAA) guidelines for online advertising and you may opt out via their Your Online Choices website.
- Please note that when using the ad industry opt-out tools described above:
- If you opt-out your browser may still send us data, for example your IP address. However, we isolate this data and do not use it other than for accounting and, in some cases, for fraud prevention. If you have opted-out on that browser, we do not use this data to personalize ads or to track you.
- If you use multiple browsers or devices we will additionally opt out those we have linked to you. Since we may not have all your browsers or devices connected back to your user, you may need to execute this opt out on each browser or device.
- Other ad companies’ opt-outs may function differently than our opt-out.
- To opt out of receiving targeted ads that are based on your behavior across different mobile applications follow the below instructions, for iOS and Android devices:
- iOS 7 or Higher: Go to your Settings > Select Privacy > Select Advertising > Enable the “Limit Ad Tracking” setting
- For Android devices with OS 2.2 or higher and Google Play Services version 4.0 or higher: Open your Google Settings app > Ads > Enable “Opt out of interest-based advertising”
Opting out will not prevent you from seeing ads, but those ads will likely be less relevant because they won’t be tailored to your interests. The ads might, for instance, be randomly generated or based on the web page you are visiting.
Some internet browsers allow users to send a "Do Not Track" signal to websites they visit. We do not respond to this signal at the present time.
In addition, if you are located in a European Territory you will also have additional data protection rights. These are described under the heading "Additional data protection rights for European Territory residents" below.
8. Data retention
We retain personal data we collect directly for targeting purposes for no more than 12 months, after which time we employ measures to delete it. However for identifiable data that we hold on behalf of an Advertiser such as their email address list, we will retain until the Advertiser asks us to delete it.
Personal data collected for other purposes is held no longer than necessary for our business purposes but is anonymized. For example, we retain anonymized impression and click data to ensure we can meet auditing requirements related to services provided or to meet legal requirements.
We apply technical, administrative and organizational security measures to protect the data we collect against accidental or unlawful destruction and loss, alteration, unauthorized disclosure or access, in particular where the processing involves the transmission of data over a network, and against other unlawful forms of processing.
10. International transfers
We may transfer the information we collect about you to countries (including the United States of America) other than the country where we originally collected it for the purposes of storage and processing of data and operating our services. In general, these countries will be the countries in which we, our Advertisers, or our or their service providers operate.
Those countries may not have the same data protection laws as your country. However, when we transfer your information to other countries, we will protect that information as described in this Privacy Notice and take steps, where necessary, to ensure that international transfers comply with applicable laws.
For example, when we transfer your information from a European Territory to our parent company in the United States, we do so under the European Commission's Standard Contractual Clauses. These Standard Contractual Clauses are incorporated in the AdRoll Data Processing Addendum here.
11. Additional data protection rights for EEA residents
If you are a resident of a European Territory, you have the following enhanced rights under EU data protection law:
- If you wish to access, correct, update or request deletion of your personal information, you can contact us using the contact details provided under the “Contact us about questions or concerns” heading below.
you can object to processing of your personal information, ask us to restrict processing of your personal information. Again, you can exercise these rights by contacting us using the contact details provided under the “Contact us about questions or concerns” heading below.
- Similarly, if we have collected and process your personal information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent. Specifically, you can withdraw consent for us or our partners to drop our __adroll cookie and our partners’ cookies by clicking here or by withdrawing consent for AdRoll when you see a “consent banner” on a publisher or advertiser site which lists AdRoll as a vendor.
- You have the right to complain to a data protection authority about our collection and use of your personal information. For more information, please contact your local data protection authority. (Contact details for data protection authorities in the European Territories are available here.) However, if you have any questions about our collection and use of your personal information, please contact us first at firstname.lastname@example.org or email@example.com. If you are unable to obtain the information or resolution that you seek, you may also contact our Data Protection Officer at firstname.lastname@example.org.
Please note that we have no direct relationship with the individuals whose personal data we process on behalf of our clients and partners. Where we act as a processor for our clients and partners (for example, with respect to our email products), you should direct any requests to access, correct, update, or delete your personal data to the respective client or partner. We will respond to any requests by a client or partner to provide assistance with such requests within 30 days.
12. Changes to this Privacy Notice
Changes to this Privacy Notice will be posted on this page. If we make a material change to our privacy practices, we will provide notice on the site or by other means as appropriate.
If we are required by applicable data protection laws to obtain your consent to any material changes before they come into effect, then we will do so in accordance with law.
13. Contact us about questions or concerns
If you have any questions about this Privacy Notice or our privacy practices, you can contact email@example.com.
If you are located in a European Territory and we are processing your data as a data controller, AdRoll Advertising Limited is the data controller of your information. To contact AdRoll Advertising Limited please email firstname.lastname@example.org or write to us at the following address:
AdRoll Advertising Limited
1, Burlington Plaza
Dublin 4, Ireland
If you wish to escalate your inquiry after contacting the support team, you are welcome to contact email@example.com or our Data Protection Officer: Lucid Privacy Group
Attn: AdRoll Data Protection Officer
Lucid Privacy Group
1556 Shrader Street
San Francisco, CA 94117