LAST UPDATED: Aug 31, 2018
SECTION 1 – PERSONAL INFORMATION WE COLLECT
When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address and email address, payment information, and phone number. We refer to this information as “Order Information”.
When you browse our store, we also automatically receive certain information about your device, including information about your web browser, time zone, and some of the cookies that are installed on your device. We also collect your computer’s Internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system. We refer to this automatically-collected information as “Device Information”.
With your permission, we may collect your email address in order to send you emails about our store, new products and other updates.
We collect Device Information using the following technologies:
-“Cookies” that we use are listed below. We’ve listed them here so you that you can choose if you want to opt-out of cookies or not. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
- “Log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- “Web beacons”, “tags”, and “pixels” are electronic files used to record information about how you browse the Site.
SECTION 2 - HOW DO WE USE YOUR PERSONAL INFORMATION?
We use the Order Information that we collect generally to fulfill any orders placed through the Site (including processing your payment information, arranging for shipping, and providing you with invoices and/or order confirmations). Additionally, we use this Order Information to:
- Communicate with you
- Screen our orders for potential risk or fraud
-Sending you technical notices, updates, security alerts, and support,
-Responding to your comments, questions, and requests, and providing customer service
- With your permission, we may send you emails about our store, new products, services, offers, promotions, rewards, and events offered by Canoe Club
We use the Device Information that we collect to help us screen for potential risk and fraud (in particular, your IP address), and more generally to improve and optimize our Site (for example, by generating analytics about how our customers browse and interact with the Site, and to assess the success of our marketing and advertising campaigns).
SECTION 3 – COLLECTION OF INFORMATION AND CONSENT
HOW DO YOU GET MY CONSENT?
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that SPECIFIC REASON ONLY.
If we ask for your personal information for a secondary reason, like marketing, we will ask you directly for your expressed consent.
We collect only that information you provide directly to us.
When you visit the Services from your mobile device, we may collect and store your location information if you enable your device to send it to us.
We may also obtain information from other sources, such as third party social web-forums connected to Canoe Club that you have made publicly available through that network and combine that information collected through our Services.
Canoe Club is based in the United States and the information we collect is governed by United States law with every effort made to comply with GDPR . By accessing or using the Services or otherwise providing information to us, you consent to the processing and transfer of information in and to the United States. If you are visiting from a different country with laws governing data collection and use, please note that you are agreeing to the transfer of your information to the United States.
HOW DO I WITHDRAW MY CONSENT?
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at email@example.com or mailing us at:
777 Pearl Street
Boulder, CO 80302
You may update, correct, delete information about yourself, or deactivate your account at any time by accessing your account on our site or through email. However, we may retain your account information if required by law. We may also retain cached or archived copies of information about you if information has been publicly shared.
SECTION 4 – SHARING INFORMATION AND THIRD-PARTY SERVICES
We share your Personal Information with third parties to help us use your Personal Information, as described above. For example, we use Shopify to power our online store--you can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy. We also use Google Analytics to help us understand how our customers use the Site -- you can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
Your data may also be shared with consultants and other service providers who need access to such information to carry out work on our behalf, such as our payment processing providers.
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover.
PCI-DSS requirements help to ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).
We may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.
You can opt out of targeted advertising by using the links below:
- Facebook: https://www.facebook.com/settings/?tab=ads
- Google: https://www.google.com/settings/ads/anonymous
- Criteo: http://optout.networkadvertising.org/?c=1#!/
For EU- http://www.youronlinechoices.com/uk/your-ad-choices
- Klaviyo: opt-out links are on included on every email that goes out
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/.
SOCIAL SHARING FEATURES
The Services may offer social sharing features and other integrated tools which let you share actions you take on our Services with other media, and vice versa. The use of such features enables the sharing of information with your friends or the public, depending on the settings you establish with the entity providing the social setting features. For more information about the purpose and scope of data collection and processing in connection with social sharing, please visit the Privacy Policies of the entities providing those services. Please note that:
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
DO NOT TRACK
Please note that we do not alter our Site’s data collection and use practices when we see a Do Not Track signal from your browser.
SECTION 5 – SUBGROUP PRIVACY
CALIFORNIA RESIDENT PRIVACY RIGHTS
California law permits residents of California to request certain details about our disclosure of their personal information to third parties for direct marketing purposes. If you are a California resident and would like to make such a request, please contact us at firstname.lastname@example.org
EUROPEAN RESIDENT PRIVACY RIGHTS
If you are a European resident, you have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us through the contact information below.
Additionally, if you are a European resident we note that we are processing your information in order to fulfill contracts we might have with you (for example if you make an order through the Site), or otherwise to pursue our legitimate business interests listed above. Additionally, please note that your information will be transferred outside of Europe, including to Canada and the United States.
We do not knowingly collect personal information from children under 13 years of age. If we become aware that a child under 13 years of age has provided us with personal information, we will take steps to remove that information and terminate the child’s account. In addition, if you learn that your child who is under 18 years of age has provided us with personal information without your consent, please contact us at email@example.com
SECTION 6 - SECURITY
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
SECTION 7 - AGE OF CONSENT
By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
SECTION 9 - CURRENCY CONVERSION
By using our website, you (the visitor) agree to allow third parties to process your IP address, in order to determine your location for the purpose of currency conversion. You also agree to have that currency stored in a session cookie in your browser (a temporary cookie which gets automatically removed when you close your browser). We do this in order for the selected currency to remain selected and consistent when browsing our website so that the prices can convert to your (the visitor) local currency.
QUESTIONS AND CONTACT INFORMATION
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at firstname.lastname@example.org or by mail at
[Re: Privacy Compliance Officer]
777 Pearl Street
Boulder, CO 80302
It’s a bunch of legalese, but be secure in knowing that we have your back and we’ll treat you right.