PRIVACY POLICY

&BACK PRIVACY POLICY

1. Introduction

This Privacy Policy (the “Policy”) sets out the Personal Information practices for &BACK, including when you use any site it owns and operates (including www.andback.com) (collectively, the “Sites”). These practices seek to balance an individual’s right to the privacy of his or her Personal Information and the
need for &BACK to collect, use, disclose, retain and otherwise manage the Personal Information provided through the use of &BACK’s Sites and Personal Information submitted to &BACK for various services offered by us. We may update this Policy from time to time. If we make changes to this Policy we will
publish an updated version of the Policy on the Sites. You are responsible for reviewing the most current version of the Policy. This Policy was last amended on the date shown at the end of the Policy. By continuing to use the Sites, you accept any updates to this Policy.

2. What Is Personal Information

Personal information is any information that can be used to identify you as an individual, including your name, address, credit card details, phone number, age, passport information, medical history and any other personally identifiable information you choose to provide to &BACK.

3. Your Consent

If you use the Sites, register as a &BACK visitor on the Sites, apply for or request information about Services offered by &BACK (as applicable), &BACK will use this information to fulfill your request, respond to your inquiries and ensure that you are kept up-to-date on information that you have identified as important to you. By providing your Personal Information, you consent to the collection, use, disclosure and management of your Personal Information in accordance with this Policy.

When you create an account for any of our digital platforms and authenticate with a third-party service (like Google or Facebook) we may collect, store, and  periodically update information associated with that third-party account. &BACK is not responsible for the privacy practices of such third-party services and it is your sole obligation to review and understand the privacy practices and policies of these third-party services. We will only use the information associated with a third-party account to make it easier for you to sign-in to our digital platforms and we will never publish something through one of your third-party accounts without your express permission.

4. How Does &BACK Collect My Personal Information

&BACK collects Personal Information from you by asking you to provide Personal Information such as your name, age, address and email address when you register as a visitor on the Sites, apply to receive e-updates or other &BACK products or Services. &BACK collects Personal Information such as your name, address and credit card details when you make a purchase through the Sites.

&BACK collects information from you by asking you to provide Personal Information such as your email address when you register to receive correspondence. We also collect Personal Information such as your name, age, address, email address, credit card details, passport information and medical information where required, when you request Services offered by &BACK.

If you are under 18, please obtain your parent or guardian’s permission before you send any Personal Information to &BACK, or anyone else, over the Internet. We strongly encourage parent or guardian participation and understanding of their children’s online usage and awareness of the activities in which their children are participating.

We do not knowingly collect Personal Information of visitors to the Sites who are under the age of 13. If you are under the age of 13, you must disable cookies in your browser and use the Google Analytics Opt-Out Browser Add-on to disable tracking by Google Analytics. If a child under the age of 13 has provided us with Personal Information, we ask that a parent or guardian contact us at info@andback.com.

Certain other Personal Information may be collected on the Sites without you actively providing the information by using various technologies, as described below:

a. Web Beacons

Pages of the Sites and our emails to you may contain small electronic files known as web beacons (also referred to as clear gifs. pixel tags and single-pixel gifs) that permit us, for example, to count how many times those pages have been visited and for other related Sites statistics.

b. Server Logs

While you use the Sites, certain information is collected without you actively providing it, including information about your IP address and type of operating system, the time you spent on the Sites and which pages you visited. This helps us improve our Sites. This data is not used to identify individuals. We track IP addresses for: (i) troubleshooting issues; (ii) voting events, confirm people are not voting for an individual more than once; and (iii) for all people who are filling out online forms, for the purpose of spam filtering.

c. Demographic and Interest Reporting

We have implemented Google Analytics features based on Display Advertising (Google Analytics Demographics and Interest Reporting) that allows for the collection of non-personally identifiable aggregated user data; this includes aggregated gender, age and interest-behavior data. We will use the data provided by Google Analytics Demographics and Interest Reporting to develop the site and content around our users’ interests. You can opt-out of Google Analytics for Display Advertising and customize Google Display Network ads using the Ads Settings. In addition, you can use the Google Analytics Opt-Out Browser Add-on to disable tracking by Google Analytics.

d. Cookies

Cookies are small pieces of data that are stored on your computer, mobile phone or other device. &BACK may use cookies to provide, monitor and analyze how Services are used. Among other things, we use cookies to make the Sites easier to use, enable features and store information about you and your use of the Sites as well as to deliver, understand and improve advertising. Cookies can always be disabled by the browser you are using, but some functions of the Sites may not work if cookies are not enabled. Refer to your browser or device’s help material to learn what controls you can often use to remove or block cookies or block or remove other data stored on your computer or device (such as by using the various settings in your browser). If you do this, it may affect your ability to use the Sites or other websites and applications.

e. Use and Disclosure of Personal Information

We use the Personal Information we collect about you to provide services and features of the Sites to you
and other users. This includes using information to:

  • deliver quality services and features that you use on the Sites;
  • keep our services secure and safe;
  • provide you with location services;
  • protect &BACK or others’ rights or property;
  • conduct internal operations (data analysis, troubleshooting, testing and service improvements);
  • measure or understand the effectiveness of content;
  • offer opportunities that we think will be of interest to you, like causes to support, events to attend and opportunities and products of our supporters;
  • facilitate and process purchases you choose to make through the Sites;
  • make suggestions for you and other users of the Sites; and
  • comply with any legal obligations.

Personal information collected by &BACK will only be used or disclosed for purposes described in this Policy or for other purposes that we have informed you of at the time of collecting that information. Before your Personal Information will be used or disclosed for a new purpose, we will ask you for your consent, unless use or disclosure without your consent in the circumstances is otherwise permitted or required by law, regulation or court order.

We may use or disclose your Personal Information to enforce or apply the TOS of the Sites, to the extent that your Personal Information is required in order to determine whether the TOS have been violated. We use and disclose your Personal Information to fulfill your requests for certain products or Services or information about such products or Services, process purchases, contact you in response to requests for information and to respond to voluntary comments. We may also use Personal Information to customize the Sites to your preferences, to improve the content of our Sites, and to research Site usage patterns.

As discussed further in this Privacy Policy, we may share information we receive with our affiliates (corporations that are part of the same group as &BACK, or that become part of that group). Likewise, our affiliates may share information with us as well. This sharing is done in compliance with applicable laws including where such applicable laws require consent. &BACK and its affiliates may use shared information to help provide, understand, and improve their services.

We may also disclose your information to:

  • our affiliates;
  • parties that help us provide, understand and improve the Services we offer, for example, outside vendors to help host our website, serve photos and videos, process payments, analyze data, conduct and publish research, measure the effectiveness of ads, or provide search results, including parties who are located in countries or jurisdictions other than the one in which you reside. When this occurs, your information becomes subject to the laws of those jurisdictions; and
    parties to whom we have agreed to provide anonymized and/or aggregated data, though we will remove personal identifiers before we do so.
  • companies we partner with in providing the Services to help us personalize our Services and to fulfill marketing functions on our behalf.

In all of these cases, any third parties must agree to only use your information consistent with the agreement we enter into with them, as well as this Privacy Policy and our Terms of Service. To the extent any purchases are processed through a third-party service provider, our customers’ information will only be used for purposes necessary to process the purchase.

We will not sell or rent your Personal Information to anyone.

Please be assured that your Personal Information, trust and privacy are very important to us. Unless required by law to do so, we will never disclose your Personal Information to others unless we have (1) obtained your consent to do so, (2) notified you via this Policy that we will do so, or (3) removed your name and any personal identifiers from the information before disclosure.

Personal information that is no longer required to fulfil the identified purposes will be destroyed, erased, or made anonymous. &BACK will use reasonable care in the disposal or destruction of Personal Information, to prevent unauthorized parties from gaining access to the information.

We may access, preserve and share your information in response to a legal request (such as a search warrant, court order or subpoena) where we believe we are required to do so. We may also access, preserve and share information when we have a commercially reasonable belief it is necessary to: (1) detect, prevent and address fraud and other illegal activity, (2) to protect ourselves, you and others, including as part of investigations, and (3) to prevent death or imminent bodily harm. Information we receive about you may be accessed, processed and retained for an extended period of time when it is the subject of a legal request or obligation, governmental investigation, or investigations concerning possible violations of our terms or policies, or otherwise to prevent harm. We also may retain information from accounts disabled for violations of our terms for at least a year to prevent repeat abuse or other violations of our TOS.

5. Storage of Information

&BACK stores and transmits your digital information using modern security standards such as SSL Encryption. Your information is stored and protected with up-to-date username and passwords which are mandated to be secure, and use two-factor authentication where possible. Your data may transferred to and stored on a number of servers and storage locations including but not limited to the USA, Canada and UK. The transmission of this data is always secure and encrypted. These servers and cloud-providers are independently operated and secured. Any breaches or data loss as a result of a failure of these providers are not the responsibility of &BACK and its affiliates.

6. Visitor Profile Information

You are not required to register as a visitor (“Registering”) in order to access the Sites. Registering may, however, allow you to be registered as a user and access additional functions on the Sites. If you make a purchase without completing a visitor profile, information such as your billing, contact information and preferences will still be collected in order to execute the requested transaction but will not be stored on the Sites in a visitor’s profile.

As a registered visitor, &BACK give you the ability to decide whether or not you want to receive correspondence.

7. Refusal or Withdrawal of Consent

If you provide us with your email address and opt-in in your visitor profile, you may occasionally receive emails from &BACK. We may use your email address submitted through the Sites for the following purposes: (i) when you are registering for a program, we may sometimes confirm your email address is accurate and (ii) we will send a thank you email when you sign up, or register for an event or if you subscribe to our newsletter or weekly column. We hope you will find these emails interesting and informative. Of course, if you would rather not receive this information, you can unsubscribe. In addition, communications sent to you will also contain a message on how to opt-out of that type of communication in the future.

You may refuse to provide Personal Information to &BACK and may, subject to legal or contractual restrictions and reasonable notice, withdraw consent at any time to our continued use and disclosure of Personal Information previously collected. Please note that refusing or withdrawing your consent in respect of our handling of certain Personal Information may result in us being unable to provide you with certain &BACK products or Services. You can withdraw your consent at any time by writing to info@andback.com.

8. Security

When you provide Personal Information through the Sites, we protect your Personal Information by encrypting the Personal Information that is transmitted between you and the Sites.

We will employ security measures to protect Personal Information in our care appropriate to the level of sensitivity of the information. We will take reasonable steps to protect your information from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. However, you should understand that no transmission over the Internet is ever fully secure. Any breaches or data loss are not the responsibility of &BACK or any of its affiliates.

We will retain your Personal Information only for the time it is required for the purposes for which it was collected or as required by law.

9. Accessing Your Personal Information

You can ask to view Personal Information about you held by &BACK by writing to info@andback.com.

You can request that corrections be made where you can show that the Personal Information about you that we possess is incorrect or incomplete. Please note that under certain circumstances, you may not be permitted to view your records, such as where the disclosure of your records would cause security, legal or confidentiality concerns, and including where &BACK is prohibited by law to disclose that to you.

If you reside within the European Union, you also have the following rights:

a. You have the right to request that &BACK not subject your Personal Information to automated processing.
b. You have the right to obtain from &BACK the erasure or the restriction of processing of your Personal Information in certain circumstances, including when the data are no longer necessary in relation to the purposes for which they were collected or otherwise processed, except when &BACK is required by law to maintain or otherwise process your Personal Information, for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another person.
c. You may exercise these rights by contacting &BACK using the contact information provided above.
d. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of an alleged infringement of the applicable data protection law. However, we encourage you to contact us first at info@andback.com and we will try to resolve your concerns.

10. Links to Other Websites

The Sites may contain links to other websites. While we try to link only to websites that share our standards and respect for privacy, we are not responsible for the content or privacy practices of other websites. &BACK does not control these third parties’ use of cookies, collection of information, or how they manage such information. We strongly encourage all visitors to the Sites to review the privacy statements and policies of all external websites.

11. More Information About &BACK’s Privacy Practices

Please contact info@andback.com with any questions or concerns you have about this Policy or about &BACK’s handling of your Personal Information.

Effective: October 1, 2022