Privacy policy
PRIVACY STATEMENT
----
SECTION 1 - WHAT DO WE DO WITH YOUR INFORMATION?
When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address and email address.
When you browse our store, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.
Email/SMS marketing (if applicable): With your permission, we may send you emails about our store, new products and other updates.
SECTION 2 - CONSENT
How do you get my consent?
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no.
How do I withdraw my consent?
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at orders@chipcookies.co or mailing us at:
chip cookies
4752 West California Avenue Suite A100
Salt Lake City, UT 84104 USA
SECTION 3 - DISCLOSURE
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.
SECTION 4 - SHOPIFY
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
Payment:
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).
SECTION 5 - THIRD-PARTY SERVICES
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
As an example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.
Once you leave our store’s website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s Terms of Service.
Links
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
Google analytics:
Our store uses Google Analytics to help us learn about who visits our site and what pages are being looked at
SECTION 6 - SECURITY
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
SECTION 7 - COOKIES
Here is a list of cookies that we use. We’ve listed them here so you that you can choose if you want to opt-out of cookies or not.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
PREF, persistent for a very short period, Set by Google and tracks who visits the store and from where
SECTION 8 - AGE OF CONSENT
By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.
SECTION 9 - CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
California Residents
If you are a California resident, this section applies to you. The capitalized terms and phrases used under this section shall have the same definition as under the California Consumer Privacy Act, as amended and inclusive of its implementing regulations (“CCPA”).
Definitions
* Personal information. Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to you or your household.
* Sensitive personal information. Social security number, driver’s license number, state identification card, passport number, account log-in and password, financial account and password, debit or credit card number and access code, precise geolocation information, race, ethnic origin, religious or philosophical beliefs, union membership, the content of your mail, email or texts other than those communications with us, genetic data, biometric information, health information, and information that concerns your sex life or sexual orientation.
* Sell, sale, or sold. Selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or other means, your personal information to a third party for money or other valuable consideration.
* Share, shared, or sharing. Shearing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or other means, your personal information to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration.
Notice of Financial Incentive
Material Terms of Incentive
From time to time, we may offer discounts on our Products in exchange for you providing your personal information, such as your contact information. We may use the information you provide to send Communications to you, and to market future Products and Sites.
How The Incentive Is Reasonably Related To The Personal Information Provided
The discounts we provide (i.e., financial incentive) are based in part on our reasonable but sole determination of the estimated value of the personal information you provide, taking into account, without limitation, estimates regarding the anticipated revenue generated from such information, the anticipated expenses which might be incurred in the collection, storage, and use of such information in the operation of our business, and other relevant factors related to the estimated value of such information to our business, as permitted under applicable law.
Opt-In
By providing your personal information in exchange for a discount, you are affirmatively opting-in to our financial incentive program as described above. If you wish to opt-out of the program, do not submit the personal information.
Right to Withdraw
If you wish to withdraw from receiving a discount in exchange for the personal information you provided, please send an e-mail to privacy@chipcookies.co before any such discount it utilized.
Your Rights
To submit any of the requests below, or have a request submitted by your representative, please submit your request to privacy@chipcookies.co or call us to submit a request. you can designate an authorized agent to make the below requests on your behalf. When you use an authorized agent, you must provide the authorized agent with written permission to do so, and, in certain circumstances, we may ask you to verify your own identity directly with us. We may deny a request from an authorized agent that does not submit proof that they have been authorized by you to act on your behalf.
We may take steps to verify your identity by matching the information you provide with your request with the information we have on file about you. Depending on the sensitivity of the information at issue, we may utilize more stringent verification methods, including but not limited to requiring you to sign a declaration under penalty of perjury.
* Right of Access: You have a right to request that we disclose to you the categories and in some cases specific personal information we have collected about you, including information about from where we collected your information and how it has been disclosed, sold, or shared.
* Right to Delete. You have a right to request deletion your personal information, subject to certain exceptions.
* Right to Correct. You have a right to ask that we correct the personal information we have about you, subject to certain exceptions.
* Right to Opt-Out of the Sale or Sharing of Your Personal Information. You have a right to opt-out of the sale or sharing of your personal information. The process for exercising this right is described at Do Not Sell or Share My Personal Information.
* Right to Non-Discrimination. You have a right to exercise the above rights without being discriminated against.
Notice of Collection
Below is a list of the categories of personal information we have collected about California residents in the 12 months preceding the date this Privacy Policy was last updated. This list includes information about: (1) the categories of sources from which the information was collected; (2) the business or commercial purpose for collecting, selling, or sharing the information; and (3) the categories of Third Parties with whom we share the information.
* Identifiers (Includes Sensitive Personal Information): Includes information such as your name, signature, alias, postal address, and telephone number, unique personal identifier, online identifier, IP address, account log-in, email address, account name, driver’s license number or other identifying information. Sensitive personal information within this category includes your driver’s license number or other identification number.
* Personal Characteristics (Includes Sensitive Personal Information): Includes information such as your age and gender.
* Financial Information (Includes Sensitive Information): Includes information such as your account name and log-in information, and credit card and debit card number and access code. Sensitive personal information in this category includes your account log-in and password and credit card and debit card number and access code.
* Internet or other Electronic Network Activity Information: Includes information described above as automatically collected.
* Commercial Information, such as records of your Products considered and purchased.
* Geolocation Information, such as your zip code and general location.
* Audio, Electronic, Visual, Thermal, and Related Information: Includes information such as photographs, video recordings, recorded messages, and other related information.
| DISCLOSURE | CATEGORIES | DESCRIPTION |
|---|---|---|
| How do we collect this information? | Identifiers* | We collect this category of information from you directly or automatically from your device(s). We also may collect this information from third parties such as financial institutions, payment processors, and social networks. |
| Personal characteristics* | We collect this category of information from you directly. We may also collect this information from third parties, such as social networks. | |
| Financial information* | We collect this information directly from you and in some cases our third party service providers. | |
| Internet or other electronic activity information | We collect this category of information from you or your device(s) when you provide it to us or interact with us online (such as through our Site, as defined above, or our social media). We also collect this information from third parties such as online advertising networks, online data aggregators, and social networks. | |
| Commercial information | We collect this category of information from you directly, from third parties, or automatically from your device(s). | |
| Geolocation information | We collect this category of information from you or your device(s) when you provide it to us or interact with us online (such as through our Site, as defined above, or our social media). | |
| Audio, electronic, visual, thermal and related information | We collect this category of information from you or your device(s) when you provide it to us or interact with us online (such as through our Site, as defined above, or our social media) or offline (such as through a retail location or over the phone). | |
| Inferences | We draw inferences about you from the information we collect from you or your device(s) when you provide it to us or interact with us online (such as through our Site, as defined above, or our social media) . We also draw inferences about you from the information we collect from third parties such as financial institutions, payment processors, and social networks. | |
| Does this include sensitive personal information? | Yes. * Denotes which categories may include sensitive personal information. The sensitive information we may collect includes your driver’s license number or other identification number, account information, and certain financial information. | |
| Is the information “sold” or “shared”? | Yes. We make available your IP address and other persistent online identifiers to our advertising partners. In some instances, this transaction may constitute a “sale” or “sharing” of your personal information under California law. | |
| What is our business purpose for collecting your information? | See How do we use your information? above. | |
| Who do we disclose this information to? | See How do we disclose your information? above. | |
| How long do we keep this information? | We keep the information identified above for so long as is reasonably necessary and proportionate to the original purpose for which we collected the information. We base our criteria in determining appropriate retention periods on regulatory and legal requirements, contractual requirements, business needs, and the expectations of you. | |
Notice of Disclosure for a Business Purpose
The following is a list of the categories of personal information we have disclosed about California residents for a business purpose in the 12 months preceding the date this Privacy Notice was last updated. For a list of the categories of third parties with whom we’ve disclosed the information, please see How do we disclose your information?.
* Identifiers (Includes Sensitive Personal Information): See above.
* Personal Characteristics (Includes Sensitive Personal Information): See above.
* Financial Information (Includes Sensitive Information): See above.
* Internet or other Electronic Network Activity Information: See above.
* Audio, Electronic, Visual, Thermal, and Related Information: See above.
* Inferences: See above.
Notice of Sale and Sharing
We “sell” and “share” your personal information through the use of digital advertising through our Sites. Specifically, we make available certain of your online identifiers and other persistent online identifiers with advertising and marketing partners that may be considered a “sale” or “sharing” of your personal information, as defined under California law. We don’t sell or share the personal information or sensitive personal information of any California resident who is 16 years or younger. To learn more, please see Do Not Sell or Share My Personal Information.
Notice of Use of Sensitive Personal Information
We do not use your sensitive personal information for purposes other than permitted under the CCPA. Specifically, we do not use your sensitive personal information to derive characteristics about you.
California’s “Shine in the Light” law
If you are a California resident and our customer, you have the right to request information from us once per calendar year regarding the customer information we share with third parties for the third parties’ direct marketing purposes. To request this information, please send an email to privacy@chipcookies.co with “Shine the Light Request” in the subject line and in the body of your message. We will provide the requested information to you via an email response.
Nevada Residents
If you are a Nevada resident, you have the right to submit a request directing us not to make any sale of your personal information. Chip does not sell your personal information for money. However, to request email confirmation that we will not sell your personal information in the future, please send an email to privacy@chipcookies.co with “Nevada Opt-Out” in the subject line and in the body of your message.
Virginia, Colorado, and Connecticut Residents
Definitions
* Personal data. Information that is linked or reasonably linkable to an identified or identifiable individual.
* Sensitive personal data. Information that includes data revealing racial or ethnic origin, the processing of genetic or biometric data for the purpose of uniquely identifying an individual or precise geolocation data.
* Sell, sale, or sold. The exchange of personal data for monetary or other valuable consideration.
* Targeted advertising. Displaying advertisements to a consumer where the advertisement is selected based on personal data obtained or inferred from that individual’s activities over time and across nonaffiliated Internet web sites or online applications to predict such individual’
Notice of Collection
To learn more about the categories of personal information we collect about you and how we use it, please see What information do we collect about you? and How do we use your information? To learn more about the categories of third parties with whom we may share your personal information, please see How we disclose your information.
Your Rights
* Right to Know and Access: You have a right to know whether Chip is processing your personal information, access such personal information subject to certain exceptions, and obtain a copy of the personal information in a portable format. The process for exercising this right is described above in Your Choices.
* Right to Delete. You have a right to request that we delete your personal information. The process for exercising this right is described in Your Choices.
* Right to Correct. You have a right to ask that Chip correct the personal information it has about you, subject to certain exceptions. The process for exercising this right is described above in Your Choices.
* Right to Opt-Out of the Sale or Targeted Advertising. You have a right to opt-out of the sale or use of your personal information for targeted advertising. The process for exercising this right is described at Do Not Sell or Share My Personal Information.
* Right to Non-Discrimination. You have a right not to be discriminated against for the exercise of your rights described herein.
* Right to Appeal. You have a right to appeal our denial of any request above. We will respond to your appeal within the timeframe required by law, and provide a written explanation in support of our response and provide additional information as required by law. You my exercise your right to appeal by clicking the links above or contact information below
QUESTIONS AND CONTACT INFORMATION
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at orders@chipcookies.co or by mail at
chip cookies
[Re: Privacy Compliance Officer]
4752 West California Avenue Suite A100
Salt Lake City, UT 84104 USA
----