Effective February 1, 2020
This Privacy Notice applies to your use of The Companies' websites, our mobile applications, and all other digital and online services provided by The Companies (collectively, the "Services") and describes our privacy practices relating to the Services. It does not apply to information collected by The Companies offline, or to third party websites, applications, or services (including any other affiliates' or organizations not named above).
1. Contact Information and Data Protection Officer
Roll and Company, Inc.
1365 Obispo Ave
Long Beach, CA 90804
If you have any comments or questions about how we collect and use your personal data , communications can be directed to our postal address, via email to email@example.com or by telephone to 562-248-5087.
European Union or EEA Member States
We have appointed a Data Protection Officer who is responsible for overseeing questions about this privacy notice. If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact our Data Protection Officer using the details set out below.
Data Protection Officer
2. Applicability & Eligibility
We need to process your personal data to operate our organization and provide you with certain Services. Before accessing, using, or interacting with the Services you should carefully review the terms and conditions of this Privacy Notice. Your use of the Services is further governed by our Terms of Service, which is also incorporated into your agreement with The Companies by this reference.
By accepting our Privacy Notice and Terms of Service, you are confirming that you have read and understood these policies, including how and why we use your information. If you don't want us to collect or process your personal data in the ways described in this Privacy Notice, you should not use the Services. Please note we are not responsible for the content or the privacy policies or practices of any third party organization or service.
The Services are not directed to children under the age of 16. You may not use the Services if you are under the age of 16. If you are under the age of 18, you should not provide any information on our Services.
3. Information Collection, Use & Sharing
The Companies collect information about you and your use of the Services through various means, including when you provide information to us and when we automatically collect information about you when you access, use, or interact with the Services. Such processing is performed to provide you with the Services. In some instances, you may be able to choose what information to provide, but sometimes we require certain information for you to use and for us to provide you the Services.
Where we process your information on the basis of consent, we will clearly obtain your opt-in consent. Where given, you may withdraw your consent at any time by contacting us at firstname.lastname@example.org. Where we process your information on the basis of legitimate interests, we do so where the processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests.
The types of information The Companies may collect about you include:
3.1 Information You Provide To Us:
We generally process information you provide to us on the legal basis of The Companies' legitimate interests in performing the function or service you requested. Where appropriate, we may rely on alternate legal bases, such as your consent to certain types of processing.
Account Information: Certain Services users may register for an account (a "Services Account"). We do not require you to register to use our Services. However if you do register a Services Account, you will gain access to those areas and features of the Services that require registration. The Companies will collect certain information about you in connection with your registration for a Services Account, which may include personal data and other information such as a username and password.
Payment Transaction Information: We may collect and store information related to purchases of the Services. You may be required to provide certain information to complete payments via the Services, including your credit or debit card number, card expiration date, CVV code, and billing address (collectively, "Payment Information"), along with your name and billing, delivery and shipping address, to complete payment transactions through certain services. The Companies store your encrypted Payment Information in compliance with the industry standards.
Please note The Companies work with Service Providers (as defined below) to handle payment transactions. You are subject to the Privacy Policies and Terms and Conditions of our Service Providers when utilizing a third party service through The Companies' Services. Please review the Service Providers' Privacy Policies and Terms and Conditions before using their services.
Correspondence Information: If you sign up, email us, subscribe to our blog, newsletters, sweepstakes, or mailing lists, we may keep your message, email address, and contact information to respond to your requests, provide the requested products or Services, and to provide notifications or other correspondences to you.
If you do not want to receive communications from us in the future, please let us know by sending us an e-mail requesting the same to email@example.com by following the unsubscribe instructions found in any e-mail we send.
If you supply us with your postal address, you may receive periodic mailings from us with information on new products and services or upcoming events. If you do not wish to receive such mailings, please let us know by contacting us at firstname.lastname@example.org or by calling our phone number provided above.
Please note requests to remove your email address from our lists may take some time to fulfill. We may also still contact you as needed to provide important announcements or notifications regarding the Services.
Sponsorship Information: Users may have the option to fill out an application for sponsorship via the Services, thus, we may collect your personal data such as your first and last name, email, phone number, address, resume, and age to assist with sponsorship requests.
Clip-on Recall Registration: We collect personal data from you when you request information from The Companies or register your clip-ons for recall via the Services. We use this information in order to communicate with you regarding your clip-on, to communicate with you regarding your inquiry, and respond to your questions.
Promotions & Sweepstakes Information: If you register for our promotions or sweepstakes, The Companies and our partners may send you emails or other correspondence regarding the contest for which you registered, and other contests, promotions, and sweepstakes.
Support Information: You may provide information to us via a support request submitted through the Services. We will use this information to assist you with your support request and may maintain this information to assist you or other users with support requests. Please do not submit any information to us via a support submission, including confidential or sensitive information that you do not wish for The Companies or our Service Providers to have access to or use in the future.
Form Information: We may use forms to request certain information from you on the Services, such as your contact information to assist with contacts or service requests. This information may include personal data.
3.2 Information We Collect Automatically:
We use automatic data collection and analytics technologies to collect aggregate and user-specific information about your equipment, domain name, patterns of use, communication data and the resources that you access and use on the Services, including your IP address, browsing and navigation patterns. This information is used to improve our Services.
We generally process information collected automatically on the legal basis of The Companies' legitimate interests in assessing the use of its Services. Where appropriate, we may rely on alternate legal bases, such as your consent to certain types of processing.
Information we collect automatically through your use of the Services includes:
Social Login Data: Certain Services may allow you to log in using social media accounts, such as those available via Facebook, Twitter, and Google. For those Services users that choose social login, The Companies may receive information from your social account which makes it easier for you to create a Services Account or login, such as your email address. We currently also collect first name, last name, and profile photos for all social logins, as well as gender and birthdate from those using Facebook as a social login. We use the information to help you connect and share public content with your friends and followers, to register you for a Services Account, and to contact you via our newsletters if you opt-in.
IP Addresses: We automatically collect the IP addresses of users of certain Services, such as website visitors, those that log in to the Services, and those who post messages to the communities and forums. We process this information on the basis of our legitimate interests in protecting the Services and providing the Services to you.
Unique Identifiers: When you use or access the Services, we may access, collect, monitor, store on your device, and/or remotely store one or more "Unique Identifiers," such as a universally unique identifier ("UUID"). A Unique Identifier may remain on your device persistently, to help you log in faster and enhance your navigation through the Services. Some features of the Services may not function properly if use or availability of Unique Identifiers is impaired or disabled.
Analytics Information: We use data analytics to ensure site functionality and improve the Services. We use analytics software to allow us to understand the functionality of the Services on your phone. This software may record information such as how often you use the Services, what happens within the Services, aggregated usage, performance data, app errors and debugging information, and where the Services were downloaded from. We do not link the information we store within the analytics software to any personally identifiable information that you submit within the mobile application.
Log File Information: When you use our Services, we may receive log file information such as your IP address, browser type, access times, domain names operating system, the referring web page(s), pages visited, location, your mobile carrier, device information (including device and application IDs), search terms, and cookie information. We receive log file data when you interact with our Services, for example, when you visit our website, sign into our Services, or interact with our email notifications. The Companies uses log file data to provide, understand, and improve our Services, and to customize the content we show you. The Companies may link this log file to other information The Companies collects about you via the Services.
Public Information: The Companies may also collect information about you from publicly available sources. Information you make publicly available in any public or open forum, such as on a social network, may be considered public information for the purposes of this Privacy Notice, and may be accessed and collected by The Companies. Please be aware that any content or information you share with or provide to third parties using or related to your use of the Services are neither private, nor confidential. The Companies is not responsible for any content or information you post or share with third parties. If you do not wish for certain information to be public, please do not share it publicly.
3.3 Information Use
The Companies uses the information we receive about you for the purposes described in this Privacy Notice. We generally process personal data received about you through our Services on the legal basis of The Companies' legitimate interests in providing the Services and their functionality to you where such processing is necessary for the purposes of the legitimate interests pursued by The Companies or by our Service Providers related to the Services. Where appropriate, we may rely on alternate legal bases, such as your consent to certain types of processing.
The Companies will generally use your information in the following circumstances on the legal basis of legitimate interests to provide the Services requested:
Providing and Improving Our Services: We may use your information to improve and customize our Services, including sharing of your information for such purposes, and we do so as it is necessary to pursue our legitimate interests of improving our Services for our users. This is also necessary to enable us to pursue our legitimate interests in understanding how our Services are being used, and to explore and unlock ways to develop and grow our business. It is also necessary to allow us to pursue our legitimate interests in improving our Services, efficiency, interest in Services for users and obtaining insights into usage patterns of our Services. We use your information to provide and improve the Services and our products, to provide and service Services Accounts, for billing and payments, for identification and authentication, for targeted online and offline marketing including through tools like Facebook Custom Audience and Google Customer Match, to contact users or interested parties, and for general research and aggregate reporting.
Keeping Our Services Safe And Secure: We may also use your information for safety and security purposes, including sharing of your information for such purposes, and we do so because it is necessary to pursue our legitimate interests in ensuring the security of our Services, including enhancing protection of our community against spam, harassment, intellectual property infringement, crime, and security risks of all kind.
Third-Party Advertisements: The Companies may utilize the services of third-party advertising companies, including Google and others, to serve ads to you when you use our Services or other sites across the Internet, or to perform remarketing services. These third parties may collect information about your visits to certain pages of our Services and may use technology like cookies to store information about your use of the Services. The information collected may be reported back to us, and we may link this information to personal data we have collected about you. This information allows us to track which other websites have linked visitors to our Services, what pages of our Services are used by and are of interest to visitors, so we may provide better, more targeted advertising regarding our business and Services. More information about interest-based advertising and similar practices may be available at http://www.networkadvertising.org/consumer/opt_out.asp
3.4 Information Sharing
When you access or use the Services, we collect, use, share, and otherwise process your personal data as described in this Privacy Notice.
European Union or EEA Member States
If you are located in the European Union or EEA Member States, The Companies will not share, sell, rent, or otherwise disclose your personal data to third parties without your express consent.
Outside of the European Union or EEA Member States
The Companies will not share, sell, rent, or otherwise disclose your private personal data to third parties without your consent or another valid legal basis permitted by law. The Companies will share your information in the following circumstances on the legal basis of the legitimate interests of providing the requested Services:
Within The Companies: We may share and process information internally within The Companies and with our subsidiaries and affiliates. The Companies' personnel may have access to your information as needed to provide and operate the Services in the normal course of business. This includes information regarding your use and interaction with the Services.
Service Providers: The Companies work with various organizations and individuals to help provide the Services to you ("Service Providers"), such as website and data hosting companies and companies providing analytics information, like Google Analytics. The Companies need to engage such third-party Service Providers to help us operate, provide, and market the Services. These third parties have only limited access to your information and may use your information only to perform these tasks on our behalf. Information we share to our Service Providers may include both information you provide to us and information we collect about you, including personal data and information from data collection tools like cookies, web beacons, and log files.
The Companies take reasonable steps to ensure that our Service Providers are obligated to reasonably protect your information on The Companies' behalf. If The Companies become aware that a Service Provider is using or disclosing information improperly, we will take commercially reasonable steps to end or correct such improper use or disclosure.
We share personal data with our Service Providers on the legal basis of The Companies' legitimate interests in providing you with the Services. Our engagement of Service Providers is often necessary for us to provide the Services to you, particularly where such companies play important roles like helping us keep our Services operating and secure. In some other cases, these service providers aren't strictly necessary for us to provide the Services, but help us make it better, like by helping us conduct research into how we could better serve our users. In these latter cases, we have a legitimate interest in working with service providers to make our Services better.
Business Transactions: The Companies may purchase other businesses or their assets, sell our business assets, or be involved in a bankruptcy, merger, acquisition, reorganization or sale of assets (a "Business Transaction"). Your information, including personal data, may be among assets sold or transferred as part of a Business Transaction. In some cases, The Companies may choose to buy or sell assets. Such transactions may be necessary and in our legitimate interests, particularly our interest in making decisions that enable our organization to develop over the long term.
Safety and Lawful Requests: We may be required to disclose Services user information pursuant to lawful requests, such as subpoenas or court orders, or in compliance with applicable laws. We generally do not disclose user information unless we have a good faith belief that an information request by law enforcement or private litigants meets applicable legal standards. We may share your information when we believe it is necessary to comply with applicable laws, to protect our interests or property, to prevent fraud or other illegal activity perpetrated through the Services or using The Companies name, or to protect the safety of any person. This may include sharing information with other companies, lawyers, agents, or government agencies. Nothing in this Privacy Notice is intended to limit any legal defenses or objections that you may have to a third party's, including a government's, request to disclose your information.
Aggregated Non-Personal Data : We may disclose aggregated, non-personal data received from providing the Services, including information that does not identify any individual, without restriction. The Companies may share demographic information with business partners, but it will be aggregated and de-personalized, so that personal data is not revealed.
4. Public Forums & Community
The Companies offer various communities and forums across the Services. We offer several features that allow users to connect and communicate in public or semi-public spaces as part of these Services. You don't have to use these features, but if you do, please use common sense and good judgment when posting in these community spaces or sharing your personal data with others through the Services.
Please be aware that any personal data that you choose to submit there can be read, collected, or used by others, or could be used to send unsolicited messages to you. We may engage certain third parties and Service Providers to assist in providing community services to you and, in the context of that relationship, we need to share some of your information with such third parties in order to provide that service. The Companies generally does not control or remove content from public Services spaces, and your posts may remain public after your account is closed. You are responsible for the personal data that you choose to post in public Services spaces
Please also note we may automatically collect certain information about you when you browse or post to the communities and forums, such as your computer's IP address or a device identification number.
5. Your Rights & Choices Regarding Your Information
5.1 Your Rights
The Companies seek to ensure all individuals are provided with the rights mandated by their governing jurisdiction. Not all of the rights discussed in this Privacy Notice will apply to each individual data subject and may not apply to you depending upon your jurisdiction.
You may benefit from a number of rights in relation to your information that we process. Some rights apply only in certain limited cases, depending on your location. If you would like to manage, change, limit, or delete your personal data, you can do so by contacting us. Upon request, The Companies will provide you with information about whether we hold any of your personal data. In certain cases where we process your information, you may also have a right to restrict or limit the ways in which we use your personal data. In certain circumstances, you also have the right to request the deletion of your personal data, and to obtain a copy of your personal data in an easily accessible format.
To the extent that such rights are mandated by the laws applicable to the individual data subject, such as all data subjects residing in the European Union ("EU"), the following rights may apply: the right to access (GDPR, Article 15); the right to rectification (GDPR, Article16); the right to erasure (GDPR, Article 17); the right to restrict processing (GDPR, Articles 18); the right of object (GDPR, Article 21); and if applicable, the right to data portability (GDPR, Article 20). You may also have a right to lodge a complaint with an appropriate data privacy regulatory authority (GDPR, Article 77).
If we process your information based on our legitimate interests as explained in this Privacy Notice, or in the public interest, you can object to this processing in certain circumstances. In such cases, we will cease processing your information unless we have compelling legitimate grounds to continue processing or where it is needed for legal reasons. Where we use your data for direct marketing purposes, you can always object using the unsubscribe link in such communications or changing your account settings.
Where you have provided consent to certain data processing, you have the right to withdraw that consent at any time by contacting email@example.com. A withdrawal of consent will not affect the validity of our use of your personal data up until the point you have withdrawn your consent.
If you no longer wish to use the Services or receive service-related messages (except for legally required notices), then you may contact us using the information above.
5.2 Access To The Information The Companies Has Collected About You
The Companies provides certain tools and settings within the Services to help you access, correct, delete, or modify your personal data associated with the Services. The Companies welcomes you to contact us regarding the information we have collected about you, including regarding the nature and accuracy of the data that has been collected about you, to request an update, modification, or deletion of your information, to opt-out of certain Services uses of your information, or to withdraw any consent you may have granted to The Companies.
Please note requests to delete or remove your information do not necessarily ensure complete or comprehensive removal of the content or information posted, and removed information may persist in backup copies indefinitely. Please note that if you choose to delete your information or opt-out of the collection and use of your information, you understand that certain features, including but not limited to access to the Services, may no longer be available to you.
5.3 Data Retention
The Companies will retain your information only for as long as is necessary for the purposes set out in this Privacy Notice, for as long as an account is active, as described in this Privacy Notice, or as needed to provide the Services to you. The Companies will retain and use your information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your information to comply with applicable tax/revenue laws), resolve disputes, enforce our agreements, and as otherwise described in this Privacy Notice. In addition, The Companies sellers may also be required to retain and use your information in order to comply with certain legal obligations. We also retain log files for internal analysis purposes. These log files are generally retained for a brief period of time, except in cases where they are used for site safety and security, to improve site functionality, or we are legally obligated to retain them for longer time periods. We may delete your personal data from our systems as part of a data retention plan. Following termination or deactivation of a Services Account, The Companies may retain your information and content for a commercially reasonable time for backup, archival, and audit purposes.
5.4 Opting-Out Of Communications From The Companies
Users may opt-out of receiving certain communications from The Companies by sending us an e-mail requesting the same to firstname.lastname@example.org, following the unsubscribe process described in an email communication, or by contacting us using the contact information provided above. However, please note you may not opt-out of certain Services-related communications, such as account verification, changes or updates to features of the Services, or technical and security notices.
5.5 Do Not Track
The Companies do not currently employ a process for automatically responding to "Do Not Track" (DNT) signals sent by web browsers, mobile devices, or other mechanisms. Per industry standards, third parties may be able to collect information, including personal data, about your online activities over time and across different websites or online services when you use Services. You may opt out of online behavioral ads at http://www.aboutads.info/choices/ . You also may limit certain tracking by disabling cookies in your web browser.
6. Information Security
The security of your personal data is important to us. The Companies takes reasonable efforts to secure and protect the privacy, accuracy, and reliability of your information and to protect it from loss, misuse, unauthorized access, disclosure, alteration and destruction. The Companies implements security measures as we deem appropriate and consistent with industry standards. As no data security protocol is impenetrable, The Companies cannot guarantee the security of our systems or databases, nor can we guarantee that personal data we collect about you will not be breached, intercepted, destroyed, accessed, or otherwise disclosed without authorization. Accordingly, any information you transfer to or from Services are provided at your own risk.
Please do your part to help us keep your information secure. Services Account information is protected by a password. It is important that you protect against unauthorized access to your account and information by choosing your password carefully and by keeping your password and computer secure, such as by signing out after using the Services. You are responsible for maintaining the confidentiality of your password and Services Account, and are fully responsible for all activities that occur under your password or Services Account. The Companies specifically reserves the right to terminate your access to the Services and any contract you have with The Companies related to the Services in the event it learns or suspects you have disclosed your Services Account or password information to an unauthorized third party.
7. Additional Provisions Regarding The Services & Your Information
7.1 Transfer And Storage Of Your Information
The United States, European Economic Area ("EEA") Member States, and other countries all have different laws relating to privacy and data protection. When your information is moved from your home country to another country, the laws and rules that protect your personal data in the country to which your information is transferred may be different from those in the country in which you live. For example, the circumstances in which law enforcement can access personal data may vary from country to country. In particular, if your information is in the United States, it may be accessed by government authorities in accordance with U.S. law.
Please be advised information The Companies collects about you via the Services may be transferred, processed and/or accessed by us in the United States, or another country where we, or our Service Providers operate.
Please be aware that the privacy laws and standards in certain countries, including the rights of authorities to access your personal data, may differ from those that apply in the country in which you reside.
If you are located outside the United States and choose to allow us to collect information about you, please be aware that The Companies may transfer your personal data to the United States and process and store it there.
We will transfer personal data only to those countries to which we are permitted by law to transfer personal data, and we will take steps to ensure that your personal data continues to enjoy appropriate protections.
7.2 Processing Necessary For The Performance Of The Contract
7.3 Safely Using The Companies' Services
Despite The Companies' safety and privacy controls, we cannot guarantee the Services are entirely free of illegal, offensive, or otherwise inappropriate material, or that you will not encounter inappropriate or illegal conduct from other users when using the Services. You can help The Companies by notifying us of any unwelcome contact by contacting us using the information below.
7.4 Your California Privacy Rights
Under California Civil Code Section 1798.83 (known as the "Shine the Light" law), The Companies Services users and customers who are residents of California may request certain information about our disclosure of personal data during the prior calendar year to third parties for their direct marketing purposes. To make such a request, please write to us at the address below or at email@example.com with "Request for California Privacy Information" on the subject line and in the body of your message. We will comply with your request within thirty (30) days or as otherwise required by the statute. Please be aware that not all information sharing is covered by the "Shine the Light" requirements and only information on covered sharing will be included in our response.
8. Changes to Our Privacy Notice
The Companies may modify this Privacy Notice from time to time. The most current version of this Privacy Notice will govern our use of your information and will be located at /privacy-notice. You may contact us to obtain prior versions. We will notify you of material changes to this policy by posting a notice at the Services or by emailing you at an email address associated with your Services Account, if applicable, and provide an "at a glance" overview of any changes.