Lovepop (“Lovepop”, “we”, “us” or “our”) spends a lot of time thinking about what is important to you. We know that includes making the most of birthdays and holidays, spectacular paper sculptures, bloom-filled trees, and sharing unexpected Magical Moments with the people you love.
We also know your privacy is very important to you. It is to us, too.
LovePop Inc. of 125 Lincoln St. Boston, MA 02111, USA, is the data controller responsible for the Websites and any handling of Personal Information by Lovepop.
We have appointed as our representative pursuant to article 27 of the GDPR the French law firm Foley Hoag AARPI, Avocats au Barreau de Paris, 153 rue du Faubourg Saint Honoré, 75008 Paris, France. You can contact the personnel at LovePop Inc. responsible for the protection of personal data at the following email address: firstname.lastname@example.org.
Our Websites are directed to and structured to attract Users over age 18. If you are under age 18, you are not permitted to use our Websites. If you are a parent with concerns about children’s privacy issues in conjunction with the use of the Sites, please contact us at email@example.com.
To Jump to a section of this Policy, click a link below:
1. WHAT IS PERSONAL INFORMATION?
6. SMS/MMS MOBILE MESSAGING MARKETING PROGRAM
10. THIRD PARTY PRODUCTS AND SERVICES
11. YOUR CHOICES
1. WHAT IS PERSONAL INFORMATION?
“Personal Information” is information that, either alone or in combination with other information, identifies or relates to a particular individual. Examples of Personal Information include, among others, name, email address, phone number, mailing address, health information, test information, and online identifiers.
We collect a variety of information about our Users, in different ways.
A. Information You Provide To Us
We collect Personal Information that you provide to us by, for example, filling out a form, registering for an account, making a purchase, or contacting us. We collect Personal Information you provide to us in several ways, including:
· If you create an account on our Websites, we collect your name, email address, and password.
· If you place an order with us, we collect the Personal Information that you provide to us such as your shipping, billing, and payment information. See the ‘Payment Information’ section below to read more about how we and our partners handle your payment information.
· If you design and personalize a product, such as a wedding invitation, we collect the Personal Information you use to customize the product, such as the name of your partner, your RSVP information and event location.
· If you contact our Customer Happiness agents, you may provide us with Personal Information that we collect.
· If you participate in a sweepstakes, contest or survey on our Websites, we will collect certain Personal Information from you. Participation in these sweepstakes, surveys or contests is completely voluntary and you therefore have a choice whether or not to disclose the requested information.
· If you take the opportunity to review our products or participate in public forums associated with the Websites or engage with us on social media, we will collect Personal Information in any such reviews, posts, comments or photos. Note that reviews or posts on forums will be public so you should use care before posting information about yourself online.
B. Information Collected Automatically
When you visit our Websites, we may automatically collect certain information, namely:
· your usage of the Websites, such as the pages you visit and the products you search for;
· your transactions with us, for example, the type of product you purchased and the costs of each product;
· technical information, for example, your Internet Protocol (“IP”) address, time zone and location, and the type of operating system and web browser you use and related information; and
C. Information from Other Sources
From time to time, we may acquire additional information about our Users from third parties, such as the Postal Service and third parties that assist us in the provision of products and services requested by you. This may include third-party analytics providers and advertising networks.
We use the Personal Information that we collect for various purposes. We use it to generate your orders and fulfill the orders you place. We use Personal Information to carry out our legitimate interests, including, but not limited to:
· analyzing, administering, and improving our Websites;
· keeping our Websites safe and secure;
· providing information, products and services that you request and other transactional or administrative updates;
· offering our products to you;
· sending you product-related information and promotional materials;
· measuring the effectiveness of advertising we serve to you and others and to make our future marketing efforts and those of third parties more effective;
· protecting our rights or our property;
· meeting legal obligations; and
· other purposes related to the reasons for which you provided the Personal Information
We may also combine the information which you provide to us (such as your registration details) with information which we collect about you (such as information about your orders) and/or receive from other sources, and use this combined information for the purposes set out above.
Lovepop uses third party payment processors Shopify, Stripe, Amazon Pay, and PayPal to process payments made for products and services via the Websites. All online payments will be conducted in accordance with Payment Card Industry (PCI) data security standards. Your billing information (which is only used by these payment processors for fraud protection) is encrypted before being communicated to them. Subject to the below exceptions, your credit card details are communicated directly from your browser to these payment processors - Lovepop never sees your full Permanent Account Number (PAN).
Shopify, Inc. provides us with the online e-commerce platform that allows us to sell our products and services to you. Some of your Personal Information is stored through Shopify’s data storage, databases and the general Shopify application. Shopify stores your data on a secure server behind a firewall.
If you use a credit card to make a purchase (with the exception of wedding and membership purchases, which are discussed below), then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service here or Privacy Statement here.
We use Stripe, Inc. to process payments for wedding or membership purchases. For Stripe payments, if on the payment page you have requested that your card details be remembered and the payment was successful, Lovepop stores the card type, a Masked PAN (only the first 6 and last 4 digits) and the card’s expiration date as well as an associated token. This information is stored by us so that you and we can identify your stored card and use it for further payments at Lovepop. This stored information can be deleted via the payment form on the Website should you wish to do so. We also store separately the last 4 digits and card type so that we can identify transactions made by a particular card.
Pay Pal, Amazon Pay and Apple Pay
If you choose to pay with PayPal, Amazon Pay or Apple Pay, we only store the tokens required to identify the transaction, issue refunds and identify transactions.
Cookies are text files containing small amounts of information which are downloaded to your personal computer, mobile or other device when you visit a website. Cookies are then sent back to the originating website on each subsequent visit, or to another website that recognizes that cookie. You can find more information about cookies generally at www.allaboutcookies.org and www.youronlinechoices.eu.
A. Types of Cookies We Use
We use the following categories of cookies on our Websites.
· Strictly Necessary Cookies
These cookies are essential to enable you to move around the Websites and use its features, such as accessing secure areas of the Websites. Without these cookies, services you have asked for, like check out, cannot be provided.
· Performance Cookies
These cookies collect information about how visitors use the Websites, for instance which pages visitors go to most often, and if they get error messages from web pages. These cookies don't collect information that identifies a visitor. All information these cookies collect is aggregated and therefore anonymous. It is only used to improve how the Websites work.
· Functional Cookies
These cookies allow the Websites to remember choices you make (such as your user name) and provide enhanced, more personal features. They may also be used to provide services you have asked for such as watching a video or commenting on a blog.
· Target Or Advertising Cookies
These cookies collect information about your browsing habits to make advertising delivered to you more relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising. They are usually placed by advertising networks with our permission. They remember what you have looked at on our site, and we may share this information with other organizations such as advertisers.
Not all advertising you may see from us is a result of target or advertising cookies. We purchase ad space in different places that you may come across, even if you have disabled target or advertising cookies.
More information on target and advertising cookies, including how you can disable these technologies, is available at www.aboutads.info/consumers.
· Third Party Cookies
When you use our Websites, your device or browser may be sent cookies from third parties, for example when using embedded content and social network links. We have no access to or control over cookies used by these companies or third party websites. We suggest you check the third party websites for more information about their cookies and how to manage them.
Advertising networks also have tools for opting out of targeted advertising. You can visit optout.networkadvertising.org/ or www.youronlinechoices.eu for more information.
B. How To Manage Cookies
The Help menu on the menu bar of most browsers will tell you how to enable or prevent your browser from accepting new cookies, how to have the browser notify you when you receive a new cookie and how to disable cookies altogether. Information on changing cookie setting for commonly used browsers can be found at www.allaboutcookies.org/manage-cookies/index.html.
6. SMS/MMS MOBILE MESSAGING MARKETING PROGRAM
We respect your privacy. We will only use information you provide through the Program to transmit your mobile messages and respond to you, if necessary. This includes, but is not limited to, sharing information with platform providers, phone companies, and other vendors who assist us in the delivery of mobile messages. WE DO NOT SELL, RENT, LOAN, TRADE, LEASE, OR OTHERWISE TRANSFER FOR PROFIT ANY PHONE NUMBERS OR CUSTOMER INFORMATION COLLECTED THROUGH THE PROGRAM TO ANY THIRD PARTY. Nonetheless, We reserve the right at all times to disclose any information as necessary to satisfy any law, regulation or governmental request, to avoid liability, or to protect Our rights or property. When you complete forms online or otherwise provide Us information in connection with the Program, you agree to provide accurate, complete, and true information. You agree not to use a false or misleading name or a name that you are not authorized to use. If, in Our sole discretion, We believe that any such information is untrue, inaccurate, or incomplete, or you have opted into the Program for an ulterior purpose, We may refuse you access to the Program and pursue any appropriate legal remedies.
Text marketing (if applicable): With your permission, we may send text messages about our store, new products, and other updates. Updates include Checkout Reminders. Webhooks will be used to trigger the Checkout Reminders messaging system.
We will not disclose Personal Information except as set forth in this
A. Business Operations
In order to carry out certain business functions, such as order fulfillment, payment processing, e-mail delivery, or marketing, we may hire other companies to perform services on our behalf (“Service Providers”). We may share Personal Information with our Service Providers to the extent necessary for them to facilitate our business purposes specified in Section 3 (Our Use of Information).
By way of example, information relating to your order which we have combined with other Personal Information (as explained above) may be shared with our Service Providers that assist us with our marketing efforts. We do not disclose to Service Providers more Personal Information than is necessary to carry out the service that they provide and require Service Providers to keep Personal Information confidential.
B. Third Party Partners
We may partner with third parties, such as third party marketing partners, to provide you with information about our products that we feel may be of interest to you, services that we offer through our Websites, and for commercial purposes, including targeted advertising.
We will only disclose your Personal Information to such third parties to the extent necessary for them to facilitate our business purposes outlined in Section 3 (Our Use of Information).
C. Law Enforcement, Protection of Lovepop, Users, and Others
We may also disclose Personal Information in other circumstances as required by law. We also reserve the right to disclose your Personal Information when we believe such disclosure is appropriate to cooperate with an investigation of activities claimed to be unlawful, to enforce our Terms of Service, or to protect the rights or property of Lovepop or others.
D. Companies Involved in Mergers and Acquisitions.
It is possible that in the future another company may acquire Lovepop or its assets or that Lovepop may partner with or purchase another company to continue to do business as a combined entity. In the event that any such transaction occurs, it is possible that Personal Information, may be transferred to the new business entity as one of Lovepop’s assets. In such an event, we will update this policy to reflect any change in ownership or control of your Personal Information.
If you do not want Lovepop to collect information about you or if you would like to opt-out of Lovepop disclosing your information to third parties, please contact (or have your authorized agent contact) us at firstname.lastname@example.org or by calling our toll-free 1-888-687-9589.
Lovepop transfers, processes and stores data about you on servers located in the United States. We use data processors, however, that may store or process your data in a different country. Your Personal Information may therefore be transferred to, processed and stored in a country different from your country of residence, and be subject to privacy laws that are different from those in your country of residence. Information collected within the European Economic Area (“EEA”) and Switzerland may, for example, be transferred to and processed by third parties located in a country outside of the EEA and Switzerland, where you may have fewer rights in relation to your Personal Information. By using the Website and providing us with your Personal Information, you are consenting to the transfer, processing and storage of your Personal Information in countries outside of your country of residence.
10. THIRD PARTY PRODUCTS AND SERVICES
While you are visiting or using the Websites, you may be presented with an opportunity to purchase third party products or services. These products and services are offered and supplied by independent companies. If you click on one of the presented offers, you will be redirected to the site of the third party, and any information you provide in response to the offer will be governed by the privacy and other policies of that third party. We do not guarantee the security of your Personal Information when using such third-party sites or that the operator of such third party sites will comply with applicable data protection laws and regulations.
A. Communications from Lovepop
If you do not want to receive email communications from Lovepop about our own or third-party products and services that may be of interest to you, you can update your preferences in the My Account section of our Websites. You can also click on the unsubscribe link at the bottom of one of our emails. We may still contact you via mail or phone, unless you request to be added to our Do-Not-Call list, and/or our Do-Not-Mail list by contacting us using the below details and indicating your preferences. Please be sure to provide your exact name, e-mail address, mailing address and telephone number(s) and the list or lists you would like to be included on (Do-Not-Call, and/or Do-Not-Mail).
Even if you opt-out of email marketing or choose to be placed on one of these lists, we may still communicate with you using any of these methods for those non-marketing purposes set out above in the ‘Our Use of Information’ section.
B. Deactivation Of Your Account
You may request deactivation of your Lovepop account by contacting us using the contact information below and requesting deactivation. Please note that you Personal Information may remain in our archived records after your account has been deactivated, but we will not keep it for longer than necessary to fulfill the purposes described above.
C. Retention and Deletion
We retain Personal Information for as long as useful or permitted to further the purposes of collection. You can request deletion of your Personal Information. We provide information on how to do that below. Remember, though, that even if you request deletion of your information, we may keep certain information for a time after your deletion request to comply with legal or recordkeeping requirements. Also, we may not always be able to delete all of your information because of technical or other constraints.
D. Updating And Access To Your Personal Information
If you wish to change your name, e-mail address, password, and/or communication preferences after you have registered, you can access your account in the My Account section of the Websites. You may also request these changes by contacting us using the below details.
E. For European Union Residents
The European Union provides data subjects within the EU certain rights concerning their personal data. This section describes how data subjects may exercise their rights concerning personal data that we collect through the Websites or offline.
As outlined in Section 2 (Information We Collect), we, and our Service Providers and third party partners, may collect personal data from you when you use the Websites.
We control or process your personal data subject to a number of legal bases, including on the basis of our legitimate business purposes as outlined in Section 3 (Our Use of Information), where it is necessary for the performance of a contract with you, or where you have consented to us doing so.
We may share your personal data with our service providers, or third party partners, on our behalf and in accordance with our instructions. Our service providers and third party partners are not permitted to use personal data for any purposes other than as required for performance of services on our behalf.
If you are a data subject within the European Union, you have several additional rights regarding personal information:
· You have the right to request an accounting of all Personal Information that we possess that pertains to you in an electronically portable format (e.g., electronic copies of information attached to an email).
· You have the right to request that we change any Personal Information that pertains to you.
· You have the right to request that we delete any Personal Information that pertains to you.
· You also have the right to lodge a complaint regarding our use or processing of your Personal Information with a national Data Protection Authority. Each European Union member nation has established its own Data Protection Authority, so please consult local authorities for details.
· You have the right to withdraw consent at any time where we are relying on consent to process your personal data.
If you would like to exercise your rights listed above, please contact us at email@example.com or call our toll-free number 1-888-687-9589.
12. FOR CALIFORNIA RESIDENTS
The state of California provides its residents with certain rights concerning their Personal Information. This section describes how California residents may exercise their rights concerning Personal Information that we collect through the Websites or offline.
A. Categories of Personal Information Collected, Used, and Disclosed
In accordance with California law, we collected the following categories of Personal Information within the preceding twelve months:
· Identifiers such as your name, email address, unique personal identifier, online identifier, and IP address.
· Certain categories of Personal Information described in subdivision (e) of California Civil Code Section 1798.80.
· Internet or other electronic network activity information, including information on your usage of our Websites.
· Information used to create a profile about you reflecting your online preferences or behavior.
· Commercial information, including records of products or services purchased or other purchasing histories.
We may share each of these categories of Personal Information with our Service Providers to the extent necessary for them to facilitate our business purposes (including any purpose specified in Section 7, above).
We have not sold Personal Information to a Service Provider within the past twelve months.
B. Your California Privacy Rights
If you are a resident of California, you have the following rights:
· Right to Access. You may have the right to request a copy of the Personal Information that we have collected about you in the prior twelve months.
· Right to Correct. You may have the right to request we correct or update the Personal Information that we have collected about you in the prior twelve months.
· Right to Notice. You may have the right to request information on the categories of personal information that we collected in the previous twelve months, the categories of sources from which the Personal Information was collected, the specific pieces of Personal Information we have collected about you, and the business purposes for which such personal information is collected and shared. You also have the right to request information on the categories of Personal Information which were disclosed for business purposes, and the categories of third parties in the twelve months preceding your request for your Personal Information.
· Right to Delete. You may have a right to request us to delete Personal Information that we collected from you.
· Right to Opt-Out. You have a right to opt-out of certain disclosures of Personal Information to third parties, if such disclosures constitute a “sale” under California law. As noted above, in the past twelve months we have not sold Personal Information to a service provider.
If you would like to exercise your rights listed above, please contact us at firstname.lastname@example.org or call our toll-free number 1-888-687-9589.
We must verify your identity before fulfilling your requests. If we cannot initially verify your identity, we may request additional information to complete the verification process. Any Personal Information you disclose to us for purposes of verifying your identity will solely be used for the purpose of verification.
The California Consumer Privacy Act (“CCPA”) prohibits discrimination against California consumers for exercising their rights under the CCPA and imposes requirements on any financial incentives offered to California consumers related to their personal information, unless the different prices, rates, or quality of goods or services are reasonably related to the value of the consumer’s data. We will not discriminate against anyone who elects to exercise their CCPA rights.
When you establish an account at Lovepop, you choose a password to help protect your account information. A password is only as strong as you make it: you should select a unique password and keep it safe. You may change your password as often as you wish by going to My Account section of the Website. You are responsible for keeping this password confidential. We ask you not to share a password with anyone. Our sign-in process is designed to help protect your privacy. If you have trouble signing in to our Websites, please ensure that you are using your registered e-mail address and correct password. If you are using your registered e-mail address and correct password, and you continue to have trouble signing in to our Website, please contact us using the details below.
Notwithstanding the above, unfortunately, the transmission of information via the internet is not completely secure. Although we employ commercially reasonable safeguards to protect your Personal Information, we cannot guarantee the security of your data transmitted to our Websites; any transmission is at your own risk.
If you need to contact Lovepop about privacy or this policy:
· email us at email@example.com ; call us toll-free at 1-888-687-9589 ; or write to us at:
125 Lincoln Street
Boston, MA 02111
When writing to us, please be sure to include your exact name, mailing address, telephone number and specific preferences or request.