When you browse our store, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.
Email marketing (if applicable): With your permission, we may send you emails about our store, new products and other updates.
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no.
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at email@example.com or firstname.lastname@example.org.
Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
As an example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
SECTION 8 - AGE OF CONSENT
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
LimeSpot shall require that its Store-based Clients, as part of its engagement therewith, provide the means for Shoppers to inquire from LimeSpot, through the Store-based Clients, regarding their personal data, and to withdraw consent (including by deleting all identifying personal information), or to inquire from LimeSpot or its Data Protection Officer (“DPO”);
LimeSpot shall provide a secure means in which to store data, as well as to transfer data to LimeSpot via the Products from the Store-based Client; and
LimeSpot shall notify the applicable Store-based Client in the event of any breach of security or other unauthorized processing of any of their Shoppers’ information.
Our Relationship to Our Clients and Their Shoppers
LimeSpot provides its Services to help its approved and contracted store-based clients (hereinafter “Store-based Clients”) to achieve the Purposes, as defined above. LimeSpot, at the written direction and authorization of our Store-based Clients, may obtain certain information regarding Shoppers as they use and provide information to our Store-based Clients. No matter who provides us with personal information, however, our commitment to privacy remains strong.
How We Collect Shopper Information
The Types of Information We May Collect
We collect two types of information. Both types of information are required to provide the LimeSpot Purposes that are offered via a LimeSpot-enabled Store-based Client’s eCommerce platform, or through related channels (e.g. Emails, Messages, Advertising, etc.).
The first type of information is Personally Identifying Information (“PII”). The other type of information is Non-Personally Identifying Information (“NPII”).
PII includes information that is uniquely associated with an identifiable Shopper, or that identifies a Shopper, and may specifically include age, gender, location, email address, phone number, and, in some cases, IP address.
NPII may include information that is collected directly from a Shopper, during a Shopper’s interaction with the site, or from information provided to a third-party, and which does not identify, or is not uniquely associated with, an identifiable Shopper. NPII includes, but is not limited to, a Store-based Client’s name and location, Store-based Client product and collections information, non-identifying order information, Store-based Client CRM/Loyalty programs, age range, association with a geographical or network area, Shoppers’ general interests as indicated by their interaction with an e-Commerce Platform (such as selections thereon), Shoppers’ shopping behavior, and Shoppers’ choices within LimeSpot enabled e-Commerce Platforms. NPII may also include information that is non-personally identifying but was generated from PII, such as by aggregation with other PII or anonymization.
How We Use and Disclose Information
Performance of Services. We may use Shoppers’ PII and NPII to fulfil the Purposes. We may also use Shoppers’ NPII in connection with other services and features we provide to third-parties or other Store-based Clients. This includes by assessing information relating to, and historical patterns associated with, Shoppers, and/or profiles or categories of classes of Shoppers, such as by observing shopping choices and activities of Shoppers (or Shoppers fitting characteristics relating to such profiles or categories, but not necessarily any information relating to an identifiable Shopper). We may also process Shoppers’ data in association or combination with information relating to that Shopper, or information relating to Shoppers belonging to the same profile or category, from other Store-based Clients. We will also use this information to improve the quality of our Products and Services.
Performance of Services Associated With Third-Party Platforms:
- Advertising Customization: In order to provide personalized advertising on Third-Party Platforms, LimeSpot pushes certain NPII information relating to a Shopper (e.g. non-personally identifying shopping preferences profile information) to such Third-Party Platform which then selectively provides advertising. Except as provided below, none of a Shopper’s PII or NPII information is provided to LimeSpot from any Third-Party Platform.
- Authentication: In some cases, LimeSpot uses authentication services provided by Third-Party Services to authenticate a Shopper with their LimeSpot data.
- Investigations and Protection. LimeSpot may release Shopper information: when we believe it is appropriate or required in order to comply with the law; to investigate, prevent, or take action regarding illegal activities; to detect or investigate suspected fraud; in situations involving potential threats to the physical safety of any person or other similar exigent circumstances; to prevent violations of LimeSpot’s Customer Terms of Service, or to enforce the provisions thereof; to comply with any other agreement that we may have entered into with you; or to protect the rights, property or safety of LimeSpot and others. This may include exchanging information with other companies and organizations for fraud prevention and credit risk reduction. LimeSpot may cooperate with and disclose information to any authority, government official or third-party, without giving any notice, in connection with any investigation, proceeding or claim arising from an asserted illegal action or infringement.
- Third-Party Service Providers. LimeSpot may employ or engage other companies to perform tasks on our behalf and may need to share some of your information with them to provide products and services to you. Examples of this may include data storage and analysis. These third-parties have access to information needed to perform their functions but may not use it for any other purpose.
Granting us this permission not only allows us to provide our Products and Services as they exist today, but also allows us to provide innovative features, products, software and services we may develop in the future that use the information we receive about Shoppers in new ways.
LimeSpot owns the databases and all rights to our applications and software. While Store-based Clients and Shoppers allow us to process the information we receive, such Store-based Clients and Shoppers using LimeSpot enabled stores always own all of their own personally identifiable information.
How We Keep Your Information Secure
The security of Shopper information is important to us. We implement reasonable security measures to protect the security of your information both online and offline, and we are committed to the protection of Shopper information. Only those individuals at LimeSpot that have an obligation to maintain confidentiality may access Shopper PII.
When we handle Shopper information on the Internet we encrypt the transmission of that information using secure socket layer technology (“SSL”). Shopper information is pseudonymized and rendered as NPII. LimeSpot has redundant and distributed systems, and other system measures, that provide for ongoing confidentiality, integrity, availability and resilience. Our systems are routinely tested or assessed for their measures to ensure the security of Shopper Data.
However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to use commercially acceptable means to protect Shopper information, we cannot guarantee that unauthorized access, hacking, data loss or other breaches will never occur.
We will notify the Store-based Client, who is ultimately the data controller, from whom we obtain information in the event of an unauthorized access or disclosure of such information. We will take reasonable administrative steps, by making it a condition of our terms of services with them, to ensure that such Store-based Client take steps to inform the affected Shopper to the extent that it is required under applicable law.
If you have any questions about how we strive to keep information secure, you can contact us at email@example.com.
Storage and Transfer of Your Information
We may transfer, store and process Shoppers’ information, both PII and NPII, to or on computers located in the United States, Europe, or Canada. Accordingly, such information may be subject to the laws of these relevant jurisdictions.
LimeSpot’s technical infrastructure relies on data centers and cloud service providers that are located outside Europe on Microsoft’s Azure platform. Microsoft became the first global cloud service provider to appear on the Department of Commerce’s list of Privacy Shield certified entities as of August 12th 2016. The European Commission adopted the EU-US Privacy Shield Framework on July 12th 2016, replacing the International Safe Harbor Privacy Principles as the mechanism for allowing companies in the EU and the US to transfer personal data across the Atlantic in a manner compliant with the EU data protection requirements, as stated on PrivacyShield.gov. See also https://azure.microsoft.com/en-us/blog/microsoft-cloud-is-first-csp-behind-the-privacy-shield.
Canada has been recognized as ensuring an adequate level of protection for personal data. See https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en.
There is no fixed period for storage of Shoppers’ PII. We will remove Shoppers’ PII upon any of the following:
A request from the Shopper via our Shopper Rights Access Portal (see below);
A request from the applicable Store-based Client from which the Shopper, whose data is being deleted, was obtained, or such Shopper notifies LimeSpot in writing that their consent has been withdrawn;
An objection from a Shopper, via a Shopper or an applicable Store-based Client, is received by LimeSpot in writing relating to the processing of any Shopper PII;
If LimeSpot learns that any PII has been collected unlawfully;
A request from any supervisory authority or legal authority (e.g. police, third-party having an applicable court order) having sufficient legal authorization or LimeSpot being made aware that PII should be deleted to ensure compliance with an applicable legal obligation.
The storage period for any NPII that does not relate to, or uniquely identify, a Shopper is indefinite.
LimeSpot supports Shoppers’ rights in the following ways:
Accountability and DPO. While LimeSpot is not a controller of Shopper data, LimeSpot nevertheless encourages Shoppers to contact the LimeSpot DPO (firstname.lastname@example.org) for issues relating to Shopper information that is collected or processed by LimeSpot via a Store-based Client (although LimeSpot reserves the right to take no action, and/or to forward Shopper’s concerns to the applicable Store-based Client, in cases where the issue relates to Shopper data collected or processed by the Store-based Client). Furthermore, the Shopper has the right to lodge a complaint about LimeSpot’s data protection with an applicable supervisory authority with jurisdiction to receive such a complaint. We note that for European Shoppers, there is no requirement for LimeSpot to have a European representative (as LimeSpot is not a controller); however, the applicable Store-based Client may, if applicable law requires such a representative, may be contacted regarding the processing of any data relating to a European person, if that requirement applies to such Store-based Client.
Access, Rectification, and Deletion. LimeSpot provides the Shopper Rights Access Portal, via its Store-based Clients, or directly from our Privacy Tool, which is an automated tool for viewing the PII and NPII that LimeSpot may have in data storage. The Shopper Rights Access Portal further allows any Shopper to delete all PII in LimeSpot storage upon request. See our Privacy Tool If any information is incorrect or is incomplete, please direct any requests for rectification to email@example.com after which they shall be addressed as is practicable.
Breaches. LimeSpot shall notify the Store-based Client that collected the information in the event of any breach or unauthorized access to Shoppers’ PII of the following information: the existence and nature of such breach, our DPO, possible or likely consequences, and measures taken to address or, where possible, mitigate the breach. Our standard terms with our Store-based Clients require them to comply with this requirement, where required by applicable law.
Questions and Concerns