CardBoss Privacy Policy

Updated May 23, 2021 What does this policy cover Welcome to CardBoss, the online and mobile service of CardBoss (“CardBoss,” “we,” or “us”). Our Privacy Policy explains how we collect, use, disclose, and protect information that applies to our Service, and your choices about the collection and use of your information. Capitalized terms that are not defined in this Privacy Policy have the meaning given to them in our Terms of Use. If you do not want your information processed in accordance with this Privacy Policy in general or any part of it, you should not use our online or mobile services. 1. Information we collect and its use We collect the following types of information about you: (a) Information you provide us directly We may ask for certain information when you register for a CardBoss account or correspond with us (such as a username, your first and last names, birthdate, phone number, postal code and e-mail address). We also collect any messages you send us through the Service, and may collect information you provide in User Content you post to the Service (such as text and photos you upload to use in your designs or posts in our Community). We use this information to operate, maintain, and provide the features and functionality of the Service to you, to correspond with you, and to address any issues you raise about the Service. If you don’t provide your personal information to us, you may not be able to access or use our Service or Community or your experience of using our Service or Community may not be as enjoyable. (b) Information we receive from third parties We may receive information about you from third parties. For example, if you access our websites or Service through a third-party connection or log-in, for example, through Facebook Connect, by “following,” “liking,” adding the CardBoss application, linking your account to the CardBoss Service, etc., that third party may pass certain information about your use of its service to CardBoss. This information could include, but is not limited to, the user ID associated with your account (for example, your Facebook UID), an access token necessary to access that service, any information that you have permitted the third party to share with us, and any information you have made public in connection with that service. You should always review, and if necessary, adjust your privacy settings on third-party websites and services before linking or connecting them to the CardBoss Service. You may also unlink your third party account from the Service by adjusting your settings on the third party service. If you unlink your third party account, we will no longer receive information collected about you in connection with that service. (c) Information we collect from you automatically We will directly collect analytics data, or use third-party analytics tools, to help us measure traffic and usage trends for the Service. These tools collect information sent by your browser or mobile device, including the pages you visit and other information (in respect of which, please see the paragraph on log file information below) that assists us in improving the Service. For more information on the analytics cookies we use and how to opt out of third parties collecting this information, please see our Cookies Policy. (d) Cookies information and information taken from similar technologies When you visit the Service, we will send cookies — small text files containing a string of alphanumeric characters — to your computer that uniquely identifies your browser and lets CardBoss help you log in faster and enhance your navigation through the site. A cookie may also convey information to us about how you use the Service (e.g., the pages you view, the links you click and other actions you take on the Service), and allow us or our business partners to track your usage of the Service over time. You can control or reset your cookies and similar technologies through your web browser, which will allow you to customise your cookie preferences and to refuse all cookies or to indicate when a cookie is being sent. However, some features of the Service may not function properly if the ability to accept cookies is disabled. For more information on how we use cookies and other technologies and how you can control them, please read our Cookies Policy. (e) Log file information Log file information is automatically reported by your browser or mobile device each time you access the Service. When you use our Service, our servers automatically record certain log file information. These server logs may include anonymous information such as your web request, Internet Protocol (“IP”) address, browser type, referring / exit pages and URLs, number of clicks and how you interact with links on the Service, domain names, landing pages, pages viewed, and other such information. (g) Device identifiers When you access the Service by or through a mobile device (including but not limited to smart-phones or tablets), we may access, collect, monitor and/or remotely store one or more “device identifiers,” such as a universally unique identifier (“UUID”). Device identifiers are small data files or similar data structures stored on or associated with your mobile device, which uniquely identify your mobile device. A device identifier may be data stored in connection with the device hardware, data stored in connection with the device’s operating system or other software, or data sent to the device by CardBoss. A device identifier may convey information to us about how you browse and use the Service. A device identifier may remain persistently on your device, to help you log in faster and enhance your navigation through the Service. Some features of the Service may not function properly if use or availability of device identifiers is impaired or disabled. Device Identifiers used by CardBoss include the Android Advertising ID and iOS Advertising Identifier. (h) Location data You may enter your location in your profile when you sign up for a CardBoss account or join the Community. Location data will convey to us information about how you browse and use the Service and enable us to offer you localised content. 2. How we use your information We use the information we collect about you for the purposes set out above which we have described in more detail below: Providing you with the Service: We use the information that you provide us to provide the Service to you. This includes allowing you to log in to CardBoss, operating and maintaining the Service, giving you access to your designs and billing you for transactions that you make via the Service. We also use information we collect about you automatically to remember information about you so that you will not have to re-enter it during your visit or the next time you visit the site. Allowing you to participate in our Community of CardBoss Users so that you can view and share information in a forum about the Services and connect with other Users. For data analytics: We use information about you to help us improve the CardBoss Service and our users’ experience, including by monitoring aggregate metrics such as total number of visitors, traffic, and demographic patterns. For data labelling and machine learning to improve our services: We use content and media in user’s private accounts (such as photos, videos and audio) to train our models to apply machine learning to new unseen media and improve our service for users. This could include: components (ie background, eyes);labelling raw individual data (ie “man with dog”);detecting content prohibited by our terms of use for moderation and security purposes (i.e. pornographic or copyright protected material);translating audio soundtracks; This improves our service to users by for example, allowing our photo editing tools to rectify red eye and blemishes, recolour or erase components and remove backgrounds from photos and video. Customising the Service for you: We use information you provide us and information about you to make sure that your use of the Service is customised to your needs. For example, if you tell us your profession to recommend designs that are likely to be relevant to you. To communicate with you about the Service: We use your contact information to get in touch with you and to send communications about critical elements of the Service. For example, we may send you emails about technical issues, security alerts or administrative matters. To promote and drive engagement with the CardBoss Service: We use your contact information to get in touch with you about features and offers relating to the Service that we think you would be interested in. We also use information we collect about you to make sure that you get the most relevant offers and promotions based on your use of the Service, and your preferences. You can opt-out of getting these communications as described below. Customer happiness: We use information about you, information that you provide to our customer happiness team, and information about your interactions with the Service to resolve technical issues you experience with the Service, and to ensure that we can repair and improve the Service for all CardBoss users. For security measures: We use information about you to monitor activity that we think is suspicious or potentially fraudulent, and to identify violations or this Privacy Policy or our Terms of Service. For matters that you have specifically consent to: From time to time CardBoss may seek your consent to use your information for a particular purpose. Where you consent to our doing so, we will use it for that purpose. Where you no longer want us to use your information for that purpose you may withdraw your consent to this use. For matters that we are required to use your information by law: CardBoss will use or disclose your information where we reasonably believe that such action is necessary to (a) comply with the law and the reasonable requests of law enforcement; (b) to enforce our Terms of Use or to protect the security or integrity of our Service; and/or (c) to exercise or protect the rights, property, or personal safety of CardBoss, our Users or others. Legal bases for processing information under the GDPR (for users in the EEA) For CardBoss users in the European Economic Area (EEA) CardBoss processes your information in accordance with European laws and regulations such as the General Data Protection Regulation (GDPR). The GDPR governs how CardBoss may process your information, and the rights that EEA users have in relation to it. This means that CardBoss will collect and use your information only where: We need it to provide you the Service and fulfil our obligations to you under our Terms of Service. This includes providing you with access to the information that you create in your designs. It is in our legitimate interests to do so. Our legitimate interests include providing a useful Service, obtaining payment for our Service (if applicable), sending you marketing and enhancing our Service via research and development, data analytics, data labelling and machine learning. We do not rely on this lawful basis where our legitimate interest is overridden by your interest in protecting your data. You consent to us or have a reasonable expectation of us using your information in a certain way – for example, to hear about new features or offers. It is necessary for compliance with our legal obligations. If you have consented to our use of your information you can withdraw that consent at any time. Depending on the situation you can either withdraw your consent by emailing admin@card-boss.com, or through your account settings page. Where we are using your information because of a legitimate interest to do so, you have the right to object to that use. However, if you do so it may mean that it is not possible for you to continue using the Services. Admin 3139 Abbey Knoll Ct Lewis Center, OH - 43035 3. Sharing your information We will not rent or sell your information to third parties outside CardBoss and its group companies (including any parent, subsidiaries and affiliates) without your consent, except as noted in this section: (a) Who we share your information with We share your information with third-party service providers for the purpose of providing the Service to you and to facilitate CardBoss’s legitimate interests in providing a service which is useful and safe to you. Those service providers will only be provided with access to your information as is reasonably necessary for the purpose that CardBoss has engaged the service provider, and we will require that such third parties comply with this Privacy Policy, appropriate data processing terms and any applicable laws. Some of the third parties that CardBoss may share your personal information with include providers who assist CardBoss with functions such as: Billing; Customer support and customer management; Email services; Hosting and storage; Analytics; Data labelling and machine learning; Security; and Delivery of physical products; (b) Who you can choose to share your User Content with Any information or content that you voluntarily disclose for posting to the Service, such as User Content (including Community Content as defined below), becomes available to be read, collected and used by the public. When you set your profile to public, join our Community or make User Content public, your information becomes publicly available globally, searchable by other Users and can be indexed by search engines. If you or CardBoss remove information that you posted to the Service, copies remain viewable in cached and archived pages of the Service, or if other Users have copied or saved that information. In the Community, your posts and other information will remain accessible (but with your profile information removed where possible – this may have been indexed by search engines or copied by other Users or included in the body of posts) to ensure the continued functioning of the Community. By default all content you post on CardBoss is not publicly available, except for on the Community. You may share your CardBoss designs to your social media accounts, including LinkedIn, Facebook, Twitter, Pinterest and Tumblr. You should ensure that you familiarise yourself with the privacy policies of each of these services and any privacy settings that may apply to the designs you choose to share on those accounts. (c) Sharing with other third parties CardBoss will also share your information with third parties in certain circumstances, such as where: we are required to do so as a result of a court order, subpoena or other legal requirement; we believe that it is necessary to protect you or CardBoss or other people from harm, such as where we consider that there is a need to investigate or warn of potentially fraudulent, malicious or criminal activity or remove malicious content. For example, this may involve sharing details of an account or website engaged in phishing or a breach of our Terms of Use with take down services, intelligence sharing services, law enforcement bodies or on public websites; you have consented to our sharing it with a third party for a particular purpose; you or your account administrator elects to install third party apps that interact with our Service. For example, you may install a third-party document sharing app in order to store, share and edit content through our Service. These third-party apps are not controlled by us, and this privacy policy does not cover how third-party apps use your information. You should review the terms and conditions of any third party apps before connecting them to the Service. If you object to information about you being shared with these third parties, do not install the app. CardBoss will also share your information with a third party in circumstances where we sell, divest or transfer CardBoss (including any shares in CardBoss), or any combination of its products, services, assets and/or businesses to a third party. Information such as customer names and email addresses, User Content and other user information related to the Service may be among the items sold or otherwise transferred in these types of transactions. We will also sell, assign or otherwise transfer such information in the event of corporate divestitures, mergers, acquisitions, bankruptcies, dissolutions, reorganisations, liquidations, similar transactions or proceedings involving all or a portion of CardBoss. You will be notified via email and/or a prominent notice on the Service if such a transaction takes place and be given notice of any material changes to the way we handle your data under this policy. We may also aggregate or otherwise strip data of all personally identifying characteristics and may share that aggregated, anonymized data with third parties. 4. Ads on CardBoss We may share certain information such as your location, browser and cookie data and other data relating to your use of our Service with our business partners to deliver personalized advertisements (“ads”) that may be of interest to you. Please see our Cookies Policy for more information. CardBoss may allow third-party ad servers or ad networks to serve personalized advertisements either on the Service or on third party websites, including Facebook and Google. These third-party ad servers or ad networks use technology to send, directly to your browser or mobile device, these personalized ads and ad links, and will automatically receive your IP address when they do so. They may also use other technologies (such as cookies, JavaScript, device identifiers, location data, and clear gifs, see above) to compile information about your browser’s or device’s visits and usage patterns on the Service, and to measure the effectiveness of their ads and to personalize the advertising content. CardBoss does not sell, rent, or share the information we collect directly from you or about you from third parties with these third-party ad servers or ad networks for such parties’ own marketing purposes. Please note that an advertiser may ask CardBoss to show an ad to a certain audience of Users (e.g., based on demographics or other interests). In that situation, CardBoss determines the target audience and CardBoss serves the advertising to that audience and only provides anonymous aggregated data to the advertiser. If you respond to such an ad, the advertiser or ad server may conclude that you fit the description of the audience they are trying to reach. The CardBoss Privacy Policy does not apply to, and we cannot control the activities of, third-party advertisers. Please consult the respective privacy policies of such advertisers or contact such advertisers for more information. 5. How we transfer, store and protect your data Your information collected through the Service will be stored and processed in the United States, United Kingdom and any other country in which CardBoss or its subsidiaries, affiliates or service providers maintain facilities. CardBoss transfers information that we collect about you, including personal information, to affiliated entities, and to other third parties across borders and from your country or jurisdiction to other countries or jurisdictions around the world. As a result, we may transfer information, including personal information, to a country and jurisdiction that does not have the same data protection laws as your jurisdiction, and you consent to the transfer of information to the U.S. or any other country in which CardBoss or its parent, subsidiaries, affiliates or service providers maintain facilities and the use and disclosure of information about you as described in this Privacy Policy. 6. Cross-border transfers of information (for users in the EEA) For Users in the EEA, where we transfer your information to a third party provider that is not located in the EEA, and is not subject to an adequacy decision by the EU Commission, we will require those third party providers to enter into an agreement that provides appropriate safeguards for your information, including by using the EU Model Clauses. 7. Keeping your information safe CardBoss cares about the security of your information, and uses appropriate safeguards to preserve the integrity and security of all information collected through the Service. To protect your privacy and security, we take reasonable steps (such as requesting a unique password) to verify your identity before granting you access to your account. You are responsible for maintaining the secrecy of your unique password and account information, and for controlling access to your email communications from CardBoss, at all times. However, CardBoss cannot ensure or warrant the security of any information you transmit to CardBoss or guarantee that information on the Service may not be accessed, disclosed, altered, or destroyed. Your privacy settings may also be affected by changes to the functionality of third party sites and services that you add to the CardBoss Service, such as social networks. CardBoss is not responsible for the functionality or security measures of any third party. For more information about CardBoss security, please visit Security at CardBoss. 8. Compromise of information In the event that any information under our control is compromised as a result of a breach of security, CardBoss will take reasonable steps to investigate the situation and where appropriate, notify those individuals whose information may have been compromised and take other steps, in accordance with any applicable laws and regulations. 9. Your choices about your information (a) You control your account information and settings You may update your account information by logging into your account and changing your profile settings. You can also stop receiving promotional email communications from us by clicking on the “unsubscribe link” provided in such communications. We make every effort to promptly process all unsubscribe requests. You may not opt out of Service-related communications (e.g., account verification, purchase and billing confirmations and reminders, changes/updates to features of the Service, technical and security notices) although you can object to us providing these emails by emailing admin@card-boss.com. If you have any questions about reviewing or modifying your account information, you can contact us directly at admin@card-boss.com. (b) Opting out of collection of your information Please refer to your mobile device or browser’s technical information for instructions on how to delete and disable cookies, and other tracking/recording tools. Depending on your type of device, it may not be possible to delete or disable tracking mechanisms on your mobile device. Note that disabling cookies and/or other tracking tools prevents CardBoss or its business partners from tracking your browser’s activities in relation to the Service, and for use in targeted advertising activities by CardBoss, including via third parties’ websites. However, doing so may disable many of the features available through the Service. If you have any questions about opting out of the collection of cookies and other tracking/recording tools, please read our Cookies Policy or you can contact us directly at admin@card-boss.com. If you want us to stop collecting information about you, there may be some settings you can adjust in your browser or device. But CardBoss might be pretty boring without it. (c) Rights in respect of your Information The laws of some countries grant particular rights in respect of personal information. In certain circumstances, users in the EEA have the right to: Request a copy of your information; Request that we correct inaccuracies relating to your information; Request that your information be deleted or that we restrict access to it; Request a structured electronic version of your information; and Object to our use of your information. Should you wish to make a request in respect of your personal information please contact us at admin@card-boss.com. You also have the right to object to our processing of personal data about you in order to send you marketing and we will stop processing data for that purpose. In some circumstances CardBoss will not be able to comply with a request that you make in respect of your personal data. If we are unable to remove any of your information, we will let you know why. For example, we may not be able to provide a copy of your information where it infringes on the rights of another User. For our Community, we will remove your profile information where possible , but this may have been indexed by search engines or copied by other Users or included in the body of posts. We may also be required to retain certain information that you ask us to delete for various reasons, such as where there is a legal requirement to do so. In some cases, you may have shared your information with third parties, such as by publishing a design on a third party’s website. In that case CardBoss will not be able to delete the information, and you will need to contact that third party directly. If we are unable to resolve your request, or if you are concerned about a potential violation, you also have the option to report the issue or make a complaint to the data protection authority in your jurisdiction. Where you have provided your consent to certain processing and no longer want us to use your information for that purpose, you may withdraw your consent to this use, although this will not affect the lawfulness of processing based on consent before its withdrawal. Please see paragraph “You control your account information and settings” for more options on how to opt-out of marketing communications. 10. How long we keep your information Following termination or deactivation of your User account, CardBoss will retain your profile information and User Content for a commercially reasonable time, and for as long as we have a valid purpose to do so. In particular, CardBoss will retain your information for the purpose of complying with its legal and audit obligations, and for backup and archival purposes. 11. Children’s privacy CardBoss under the age of 18 are not permitted to sign up themselves for CardBoss Services or the Community (set out below). CardBoss does not knowingly collect or solicit personal information from children under the age of 13 and the Service, Community and its content are not directed at children under the age of 13. In the event that we learn that we have collected personal information from a child under age 13 without verification of parental consent, we will delete that information as quickly as possible. If you believe that we might have any information from or about a child under 13, please contact us at admin@card-boss.com. 12. Links to other websites and services We are not responsible for the practices employed by websites or services linked to or from the Service, including the information or content contained therein. Please remember that when you use a link to go from the Service to another website, our Privacy Policy does not apply to third-party websites or services. Your browsing and interaction on any third-party website or service, including those that have a link or advertisement on our website, are subject to that third party’s own rules and policies. In addition, you acknowledge that we are not responsible for and we do not exercise control over any third-parties that you authorize to access your User Content. If you are using a third-party website or service (like Facebook) and you allow such a third-party access to your User Content you do so at your own risk. This Privacy Policy does not apply to information we collect by other means (including offline) or from other sources other than through the Service. 13. California users’ Privacy Rights Californian users of CardBoss have additional rights afforded to them under the California Consumer Privacy Act (CCPA). Categories of personal information collected by CardBoss For more details about the personal information CardBoss has collected in the past year, please see section 1 “Information we collect and its use”. For details on how we use that information, and who we share it with, please see section 2 “How we use your information” and section 3 “Sharing your information”. CardBoss does not “sell” the personal information of CardBoss users. Making a request in relation to your personal information The CCPA gives California consumers various rights with respect to the personal information we collect, including the right to (subject to certain limitations): Request to access the personal information CardBoss has about you; and Request that CardBoss delete all of your personal information. California users may make a request by contacting us at admin@card-boss.com. We will authenticate your request using the email address associated with your CardBoss account and if necessary, proof of residency. 14. Changes to this Policy We may update this policy from time to time to reflect our current practice and ensure compliance with applicable laws. When we post changes to this policy, we will revise the “Last Updated” date at the top of this policy. If we make any material changes to the way we collect, use, store and/or share your personal information, we will notify you with a notice on our website and/by sending an email to the email address associated with your CardBoss account. We recommend that you check this page from time to time to inform yourself of any changes. 15. How to contact us If you have any questions about this Privacy Policy or the Service, or wish to make a complaint please contact us at: Email: admin@card-boss.com Write: Admin CardBoss 3139 Abbey Knoll Ct Lewis Center, OH - 43035 Your privacy is important to us and we are happy to answer any questions you may have.