Privacy Policy
Last Modified: December 6, 2023
WeStock, Inc. (“WeStock,” “we,” “us,” or “our”) is committed to protecting the privacy of our clients, individuals interested in our business, and visitors to our website, WeStock.io (the “Site”). This Privacy Policy explains our privacy practices and the types of information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, as defined by applicable privacy laws (“Personal Data”) that we may collect or receive from the Site; any of our affiliates and subsidiaries’ websites; any other web address, mobile site, or application controlled by WeStock that links to this Privacy Policy; or when you use the WeStock app(collectively, the “Services”).
By accessing and using the Services or otherwise providing information to WeStock, you have consented to the terms of this Privacy Policy, and consent to our privacy practices described herein including our use and disclosure of your Personal Data. If you do not agree to the terms and conditions of this Privacy Policy, then please do not provide us with your information. Please note, however, that if you choose to limit the information that you provide to us while using the Services, you may not be able to use or participate in certain features of the Services.
1. MODIFICATIONS AND REVISIONS
We may update this Privacy Policy from time to time to reflect changes to our privacy practices. We will notify you of any changes to this Privacy Policy by posting the revised or updated Privacy Policy and its “Last Modified” date on the Services. If the revision or modification is material, we will provide you notification via email or via the Site. Your continued use of the Services after the “Last Modified” date constitutes your acceptance of and agreement to the Privacy Policy and its revisions or updates. You should periodically read the Privacy Policy to learn of any revisions or updates.
2. COLLECTION OF PERSONAL INFORMATION
During your use of the Services, WeStock collects both Personal Data and non-personally identifiable information about you in various ways, including
- Directly from you when you provide it to us;
- Automatically as you use the Services; and
- From third parties.
a. Information Provided by You
We may collect the following types of Personal Data and other information directly from you when you use the Services to subscribe to our newsletter, download our brochure, make a purchase, fill in contact forms on the Services, or communicate with our team. We may collect the following types of Personal Data:
- Identifiers, including name, postal address, email address, phone number, date of birth;
- Information in Customer Records, including name, postal address, phone number, customer code; o You may be required to provide financial and bank information prior to purchasing the Services. Please note, we do not store financial and bank information; such information is securely processed and stored by Stripe, our payment processor. For more information on Stripe’s privacy practices, please visit: https://stripe.com/privacy •
- Shopping Data, regarding preferred shopping locations, products of interest, and products that you have purchased. •
- Sensitive Personal Data, including precise geolocation. Special Category Data Some of the information that we may collect as a result of providing the Services is particularly sensitive (e.g., precise geolocation). We only collect this information as provided by or consented by you.
Such sensitive information is only shared for the purpose of providing the Services or as consented for and will not be shared or used by us for any other purposes.
b. Information Automatically Collected by the Services
WeStock and third-party service providers may automatically collect information about you when you use the Services. Like many other websites or apps, WeStock and its providers may collect and store information that is generated automatically as you navigate through the Services. This information is primarily needed to maintain the security and operation of the Services, and for our internal analytics so that we can improve the Services. This information includes:
- Location Data, including Internet Protocol (“IP”) address, GPS coordinates, and precise geolocation (“Location Data”) as necessary to provide the Services’ full functionality. By using or activating any location-based services, you agree and consent to our collection, maintenance, publishing, processing and use of your Location Data in order to provide you with the Services. You may withdraw your consent to our use of your Location Data at any time by turning off the location-based services through the app you are using, or by not using any location-based features. Turning off or not using locationbased features may impact the functionality of the Services as delivered to you. Location Data provided by the Services is used for basic navigational purposes and is not intended to be relied upon in situations where precise location information is needed or where erroneous, inaccurate or incomplete Location Data may lead to death, personal injury, property or environmental damage. Any use of real-time route guidance via the Services is at your sole risk. You understand that Location Data provided by the Services may not be accurate. We do not guarantee the availability, accuracy, completeness, reliability or timeliness of Location Data displayed by the Services;
- Internet and Electronic Activity Data, including cookies, details of your visits to the Services, including traffic data, generalized location data, logs, and other communication data and the resources that you access and use on the Services, device's unique device identifier, operating system, browser type, mobile network information, device's telephone number, browsing history, browser and device information, advertising identifiers, clickstreams, search history, usage details, IP address, pixel tags, browser version, operating system, other tracking technologies.
- Cookies, are small data files that we transfer to your computer’s hard disk for record-keeping purposes. Cookies do not personally identify you; they merely identify the computer or device with which you access the Services. The Services use cookies to analyze trends, recognize you, tailor the Services to you, or to detect and prevent fraud. You can instruct your browser, by changing its options, to disable cookies or to prompt you before accepting a cookie from the Services. If you disable cookies, however, you may not be able to use all portions or functionality of the Services. o Third Party Cookies ▪ Google Analytics, we use Google Analytics on the Services to help us analyze the traffic on the Services. For more information on Google Analytics’ processing of Personal Data, please see http://www.google.com/policies/privacy/partners/ You may opt out of the use of Google Analytics here: https:// tools.google.com/dlpage/gaoptout.
c. Information Received from Third Parties
In some instances, WeStock may receive Personal Data and/or anonymous data about you from other parties, such as our affiliates, business partners, and service providers. That information may be obtained online, offline, or through publicly available resources. We may combine this information with the information you provide, and other data we already have about you.
We may also receive information about you from social media platforms, when you interact with us on those platforms, access our social media content, if you use a third-party account to sign-in to the Services, or link a third-party account to your account. Please note that the information we may receive from those third parties (such as Facebook, Twitter, LinkedIn, and Youtube) is governed by the privacy settings, policies and/or procedures of the applicable platform, and we strongly encourage you to review them before submitting any information using a social media platform.
3. PURPOSE OF COLLECTION
WeStock may process your Personal Data for the following lawful business and commercial purposes, in accordance with the practices described in this Privacy Policy, and based upon the legal justification set forth in the parenthetical:
- Provide the Services. We may use your Personal Data to provide the Services and any other Services or services you may request from us. (CONSENT; CONTRACT; LEGITIMATE INTEREST)
- Monitor the Services. We collect your Personal Data for monitoring purposes to help us diagnose problems with our servers, administer and troubleshoot the Services, calculate usage levels, analyze industry standards, and analyze transactions, trends, and statistics regarding the use of the Services. (CONSENT; LEGITIMATE INTEREST)
- Respond to Inquiries and Fulfill Requests. We may use your Personal Data to respond to your inquiries and to fulfill your requests for information. (CONSENT)
- Communicate with You. We may use your Personal Data to send you marketing information about the Services, special promotions, and other items that may be of interest to you. We may also contact you on behalf of our third-party business partners about a particular offering of theirs that may be of interest to you. (CONSENT; LEGITIMATE INTEREST)
- Improve the Services. We may use your Personal Data to make the Services more stable and user-friendly, to analyze service issues, improve the design and content of the Services, personalize your experience, analyze how the Services is used, offer new services, and to develop new marketing programs relating to the Services. (CONSENT, LEGITIMATE INTEREST)
- Customer Service. We may use your Personal Data when contacting you regarding customer service, the Services, or in response when you provide feedback. We may also use your information to send administrative emails regarding the Services or to inform you of any changes to this Privacy Policy, our Terms, or our third-party partner’s Terms. (CONSENT; LEGITIMATE INTEREST)
- Support Business Operations. We may use your Personal Data to support our internal and business operations, including marketing, security, and advertising. (CONSENT; LEGITIMATE INTEREST)
- Enforce Agreements. We may use your Personal Data to enforce separate agreements between you and us, enforce this Privacy Policy, our Terms of Use, or our third-party partner’s Terms of Use, or in connection with a transaction with a similar effect. (CONSENT; CONTRACT)
- Fulfill Other Purposes. We may use your Personal Data to fulfill: (a) any other purpose for which you provide it; (b) any legal or regulatory requirements and any of our internal policies; (c) other purposes disclosed at the time of collection; (d) any other purpose with your consent; and (e) any other purposes set forth in this Privacy Policy. (CONSENT; LEGITIMATE INTEREST)
a. Legal Basis for Processing
We process your Personal Data with your consent or subject to the performance of a contract to which you are a party or, alternatively, to take steps at your request to enter into an agreement. If our processing is based solely on your consent, you have the right to withdraw your consent at any time.
4. DISCLOSURE OF PERSONAL INFORMATION
Except as otherwise described in this Privacy Policy, we do not sell, share, rent, or otherwise disclose your Personal Data that we collect from the Services to any third parties for monetary or other valuable consideration, unless stated below or with your consent:
- Subsidiaries and Affiliates. We may disclose Personal Data about you to our subsidiaries and affiliates.
- Service Providers & Contractors. To help us provide superior service, your Personal Data may be shared with our service providers, contractors, and other third parties we use to support our business and who will safeguard it in accordance with this Privacy Policy. Such third parties may help us with order processing and fulfillment, providing customer service, maintaining and analyzing data, and sending customer communications on our behalf.
- Live Chat and Interactive Support. The Services may include “live chat” or other live interactive features. We may provide these features through technology provided by third parties, and you consent to the transfer of your Personal Data to these providers by using these features.
- Marketing Partners. We may share your Personal Data with entities that perform marketing or data aggregation services on our behalf, or with which WeStock or an affiliate has joint marketing arrangements
- Advertising Partners. We may share your Personal Data with third party advertising partners, including but not limited to Google Display Advertising and Remarketing services. These advertising partners may use first- and third-party cookies together to inform, optimize, and serve ads based on your past visits to the Services. You can opt out of these services using the Ads Preferences Manager or you can use the Google Analytics opt-out browser add-on. These advertising partners may use this information (and similar information collected from other services) for purposes of delivering personalized advertisements to you when you visit digital properties within their networks, commonly referred to as “interest-based advertising.”
- Analytics Partners. We may use analytics-based technologies to assist with personalization, advertising, and marketing. These technology capture how you interact with out website through behavioral metrics, heatmaps, and session replay to improve and market our products and services. •
- Financial institutions. We may disclose certain Personal Data to financial institutions as necessary for the Services.
- Authorized Representatives. If another individual is managing your account with us or your email account which the Services connect to on your behalf (for example, a wife managing the account of a husband), as authorized by you or as a personal representative under applicable law, that person can view all Personal Data about you on the Services.
- In the Event of Merger, Sale, Divestitures, or Change of Control. WeStock reserves the right to transfer Personal Data to a buyer or other successor in interest that acquires rights to that information as a result of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of WeStock or substantially all of its assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by us about you is among the assets transferred.
- With Your Consent. We may share your information for other purposes pursuant to your consent or at your direction.
- Other Disclosures. We may disclose your Personal Data if we have a good faith belief that disclosure of such information is helpful or reasonably necessary to: (i) conform to legal requirements and comply with any court order, law, or legal process, including responding to any government, law enforcement, or regulatory request; (ii) enforce the Terms of Use, other agreements, including between you and us, and any other documents included or referenced therein (all of which are incorporated into and made a part of this Privacy Policy by reference); (iii) fulfill the purpose for which you provide it; (iv) detect, prevent, or otherwise address fraud or security issues; or (v) protect against harm to our, your, or third parties’ rights, property, or safety.
We may share and disclose de-identified and/or aggregate analytics with third-party partners for the purposes described in this Privacy Policy or where it is collected, or any other legal purpose, including, when and where applicable, sharing and disclosing non-personally identifiable information combined with Personal Data.
5. CHOICES
We strive to provide you with choices regarding how we use the Personal Data you provide to us. Please understand that if you choose not to disclose information to us, it may affect your ability to use some features of the Services. We have created mechanisms to provide you with the following control over your information:
a. Account Profile
To update your information or discontinue the Services, please contact us as specified in the Contact Information section below. You also may be able to update your information by logging into your Account.
b. Advertising
We may also use third-party advertisers, ad networks, and other advertising, marketing, and promotional companies, to serve advertisements about the Services. Such third parties may gather information about your visit to the Services, monitor your access or market the Services to you, monitor the ads you view, click-on, or interact with, when they were delivered, and the screens and pages that they are on. If you wish to not have this information used for the purpose of serving you targeted ads, you may opt out by clicking here. Please note this does not opt you out of being served advertising. You will continue to receive generic ads.
We and our service providers may use information about your interactions with the Services to predict your interests and select the ads you see on and off the Services. This is known as interest-based advertising. In providing interest-based ads, we follow the Self-Regulatory Principles for Online Behavioral Advertising developed by the Digital Advertising Alliance. For more information about interest-based advertising and how you can opt out, visit:
- Digital Advertising Alliance: http://www.aboutads.info/choices
- Network Advertising Initiative (NAI): http://www.networkadvertising.org/ choices/
c. Marketing
From time to time if you have supplied your email address, we may send you marketing or informational emails. If you prefer not to receive any or all of our marketing and promotional communications, you may opt-out of these communications by following the opt-out prompts on these communications. You also may ask us not to send you other marketing or informational communications by contacting us as specified in the Contact Information section below, and we will honor your request. Please note that even after you are removed from our marketing lists, we may still send you non-promotional communications, such as responding to your support requests.
d. Do Not Track
Some browsers have a “Do Not Track” (“DNT”) feature that lets you tell websites and online services that you do not want to have your online activities tracked. Such browser features and industry standards are not uniform. As such, WeStock does not monitor or respond to DNT browser requests. If a standard is adopted that we must follow in the future, then we will inform you about that practice in a revised version of this Privacy Policy.
6. THIRD-PARTY LINKS AND WEBSITE
The Services may contain links to third-party services, websites, mobile applications, and/or contain advertisements from third parties that are not affiliates with us and which may link to other websites, services, or applications. While we endeavor to work with third parties that share our respect for user privacy, we are not responsible for the privacy policies or privacy practices of such third parties. Any information collected by third parties are not covered by this Privacy Policy. You are responsible for knowing when you are leaving the Services to visit a third-party website, service, or application and for reading and understanding the terms of use and privacy policy statements for each such third party. This Privacy Policy only governs information collected through the Services.
7. CHILDREN
The Services are not intended for children, and we encourage parents and guardians to be aware of and monitor the websites visited by their children. WeStock does not knowingly collect any Personal Data from children under 16 years of age. If WeStock learns that a child under the age of 16 has submitted Personal Data to the Services without guardian or parental consent, we will take all reasonable measures to remove or delete such information as soon as practicable and not use such information for any purpose, except where necessary to protect the safety of the child or others or as required or allowed by law. If you believe a child under age 16 has provided us with Personal Data, please contact us as specified in the Contact Information section below.
8. RETENTION PERIOD
WeStock may retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by applicable law. We are under no obligation to store such Personal Data indefinitely and, to the extent permitted by law, disclaim any liability arising out of, or related to, the destruction of such Personal Data.
9. CONFIDENTIALITY AND SECURITY
We take the security of your Personal Data seriously and have implemented appropriate technical and organizational measures to protect it from unauthorized access, disclosure, or destruction. While we implement these measures, please note that 100% security is not possible, and we cannot guarantee that the security measures we have in place to safeguard Personal Data will never be defeated or fail, or that those measures will always be sufficient or effective.
10. TESTIMONIALS
From time-to-time, we may display personal testimonials of yours received via email or as otherwise received from you by WeStock. By accepting the Terms of Use, which incorporate this Privacy Policy, you give us specific consent to use such personal testimonial. If you would like for us to remove your testimonial or customer review at any time, please contact us via the Contact Information section below, and we will promptly do so.
11. INTERNATIONAL TRANSFER OF INFORMATION
The Services are hosted in the United States. If you are visiting the Services from outside the United States, your Personal Data may be transferred to, stored, and processed in the United States in accordance with this Privacy Policy and applicable U.S. laws. Please note your Personal Data will be transferred, processed, collected, use, accessed, and/or stored in the United States, a country and jurisdiction that may not have the same data protection laws or rights as the country in which you reside, and subject to U.S. laws. Please do not provide your Personal Data to us if you do not want this information to be transferred or processed outside of your country, or if the laws in your country restrict such transfers. By using the Services, you consent to the transfer of your information to our facilities and the practices described in this Privacy Policy.
12. EEA AND UK PRIVACY RIGHTS
Individuals (“Data Subjects”) in the European Economic Area (EEA) and the United Kingdom (UK) have certain privacy rights under EU and UK law, including the General Data Protection Regulations (the “GDPR”) and UK Data Protection Act 2018. In the event, we collect Personal Data (as defined in the GDPR) that is subject to the GDPR, this section shall apply. Terms in this section are to be understood in a manner consistent with the GDPR including the definitions of such terms in the GDPR. Such terms may have a different definition or meaning in other portions of this Privacy Policy because the GDPR may not apply to those sections.
a. Data Controller
The Data Controller is WeStock.io.
b. Processing Purposes and Legal Bases
WeStock processes your Personal Data for the lawful purposes, and under the legal bases set forth in the Collection of Personal Data section above.
c. Onward Transfer
WeStock will not disclose Personal Data to a third party except as stated below: We may disclose Personal Data to subcontractors and third-party agents. Before disclosing Personal Data to a subcontractor or third-party agent, we will obtain assurances by contractual agreement from the recipient that it will: (i) transfer such data only for limited and specified purposes; (ii) ascertain that the subcontractor or third-party agent is obligated to provide at least the same level of privacy protection as is required by the GDPR; (iii) take reasonable and appropriate steps to ensure that subcontractors and third-party agents effectively process the Personal Data transferred in a manner consistent with the organization’s obligations under the GDPR; (iv) require subcontractors and third-party agents to notify the organization if it makes a determination that it can no longer meet its obligation to provide the same level of protection as is required by the GDPR; (v) upon notice, including under (iv), take reasonable and appropriate steps to stop and remediate unauthorized processing; and (vi) provide a summary or a representative copy of the relevant privacy provisions of its contract with subcontractors and third-party agents to the Supervisory Authorities upon request. We also may be required to disclose, and may disclose, Personal Data in response to lawful requests by public authorities, including for the purpose of meeting national security or law enforcement requirements, or in the event of a merger or acquisition.
d. Rights under the GDPR
Data Subjects have the following privacy rights under the GDPR:
- Right of Access. You have the right to obtain confirmation from us as to whether or not we process Personal Data from you, and you also have the right to at any time obtain access to your Personal Data stored by us. •
Right to Rectification. If we process your Personal Data, we use reasonable measures to ensure that your Personal Data is accurate and up-to-date for the purposes for which your Personal Data was collected. If your Personal Data is inaccurate or incomplete, you have the right to require us to correct it. - Right to Erasure. You may have the right to require us to delete your Personal Data.
- Right to Restrict Processing. You may have the right to request the restriction or suppression of Personal Data.
- Right to Withdraw Consent. If you have given your consent to the processing of your Personal Data, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on the consent before the withdrawal.
- Right to Data Portability. You may have the right to receive the Personal Data concerning you and which you have provided to us, in a structured, commonly used and machine-readable format or to transmit this data to another controller.
- Right to Object. You may have the right to object to the processing of your Personal Data as further specified in this Privacy Policy and you may have the right to object to decisions being made with your Personal Data based solely on automated decision making or profiling.
- Right to Lodge a Complaint with Supervisory Authority. You have the right to lodge a complaint with a data protection supervisory authority located in the European Union or UK. Further information about how to contact your local data protection authority is available at the website of the European Commission.
If you would like to exercise your EEA and UK privacy rights, please contact us as specified in the Contact Information section with a reference to “EEA and UK.”
e. Choices under the GDPR
Data Subjects have the right to opt out of (i) disclosures of their Personal Data to third parties not identified at the time of collection or subsequently authorized, and (ii) uses of Personal Data for purposes materially different from those disclosed at the time of collection or subsequently authorized. Data Subjects who wish to limit the use or disclosure of their Personal Data should submit that request to our Data Protection Officer. We will cooperate with Data Subjects’ instructions regarding Data Subjects’ choices.
All of our general emails also contain an unsubscribe link at the bottom and you can unsubscribe to such emails at any time by clicking on that link.
f. Security
See Confidentiality and Security section above for more information about our security practices.
g. Retention of Personal Data
For more information, please refer to the Retention Period section above.
h. Transfers to the United States
In using the Services, your Personal Data will be transferred to the United States, which is not recognized as a country having adequate safeguards for the protection of Personal Data. WeStock relies on your consent or Article 49 of the GDPR for transfers of data collected from Data Subjects in the EU and EEA. Transfers are made to WeStock only if the Data Subject has explicitly consented to the proposed transfer after having been informed of the possible risks of such transfers. Additionally, we transfer data as necessary for the performance of a contract between you as the Data Subject and WeStock as the Controller, to Data Processors who have an agreement with us that includes protecting your privacy and the security of your data, and in cases where your Personal Data is necessary for the implementation of pre-contractual measures taken in accordance with your requests.
13. CALIFORNIA PRIVACY RIGHTS
This section explains how we collect, use, and disclose Personal Information about users, customers, and visitors who reside in California (“consumers” or “you”). It also explains certain rights afforded to consumers under California’s Shine the Light law and the California Consumer Privacy Act of 2018 (“CCPA”), as revised and updated by the California Privacy Rights Act (“CPRA”). This section uses certain terms that have the meaning given to them in the CCPA including Personal Information.
a. Shine the Light
Under California Civil Code Section 1798.83 (“Shine the Light”), California residents have the right to request in writing from businesses with whom they have an established business relationship, (a) a list of the categories of Personal Information, such as name, e-mail and mailing address and the type of services provided to the customer, that a business has disclosed to third parties (including affiliates that are separate legal entities) during the immediately preceding calendar year for the third parties’ direct marketing purposes; and (b) the names and addresses of all such third parties. To request the above information, please contact us as directed in the Contact Information section below with a reference to California Disclosure Information.
b. Categories of Personal Information Collected
We may collect (and have collected during the 12-month period prior to the “Last Modified” date of this Privacy Policy) the above categories of Personal Information about you in the Collection of Personal Data section above.
c. Purpose of Collection
We may use (and may have used during the 12-month period prior to the “Last Modified” date of this Privacy Policy) your Personal Information for the business or commercial purposes described in the Purpose of Collection section above.
d. Sources of Personal Information
During the 12-month period prior to the “Last Modified” date of this Privacy Policy, we may obtain (and may have obtained) Personal Information about you from the sources identified in the Collection of Personal Data section above.
e. Selling and Sharing Personal Information
We do not sell or share your Personal Information in exchange for monetary consideration; however, we may use tools described above such as Google Analytics, which may be interpreted as sharing your Personal Information. As such, please see the above Personal Data Automatically Collected and Choices sections for more information regarding opting out of use of these tools.
During the 12-month period prior to the “Last Modified” date of this Privacy Policy, we may have shared or disclosed the following categories of Personal Information about you for a business or commercial purpose with certain categories of third parties, as described below:
f. California Consumer Privacy Rights
Under CCPA, consumers have certain rights regarding their Personal Information, as described below.
- Right of Access: You have the right to request, twice in a 12-month period, that we disclose to you the following information about you, limited to the preceding twelve (12) months:
- The categories of Personal Information that we collected about you; o
- The categories of sources from which the Personal Information is collected; o
- The business or commercial purpose for collecting or selling Personal Information; o
- The categories of third parties with whom we share Personal Information; o
- The specific pieces of Personal Information that we have collected about you; o
- The categories of Personal Information that we disclosed about you for a business purpose or sold to third-parties; and o
- For each category of Personal Information identified, the categories of third parties to whom the information was disclosed or sold.
- Right of Deletion: You have the right to request that we delete any Personal Information about you which we have collected from you, subject to exceptions within the law.
- Right to Opt-Out: You have the right to opt-out of the disclosure of Personal Information about you for monetary or other valuable consideration. However, we do not sell any Personal Information.
- Right to Opt-In: We do not have actual knowledge that we collect, share, or sell the Personal Information of minors under the age of 16.
- Right to Limit Use and Disclosure of Sensitive Personal Information: You may request specific limitations on further sharing, use, or disclosure of your Sensitive Personal Information that is collected or processed for “the purpose of inferring characteristics about a consumer.” However, we do not collect or process Sensitive Personal Information for this purpose.
- Right to Correction: You have the right to request that we maintain accurate Personal Information about you and correct any Personal Information about you which we have collected from you, subject to exceptions within the law.
If you would like to exercise your California privacy rights, please refer to the Consumer Requests and Verification section below.
14. VIRGINIA, COLORADO, CONNECTICUT, UTAH PRIVACY RIGHTS
This section is applicable to residents of Virginia, Colorado, Connecticut, or Utah. If you are a resident of Virginia, Colorado, Connecticut, or Utah, you have certain rights described below. The following do not apply to individuals who do not live in Virginia, Colorado, Connecticut, or Utah on a permanent basis, individuals we do not collect personal information about, or individuals for whom all of the information we collect is exempt from the statutes. “Personal Data,” for purposes of this section regarding the rights of residents, means any information that is linked or reasonably linkable to an identified or identifiable natural person and does not include de-identified information or publicly available information.
This section applies only to Virginia, Colorado, Connecticut residents to the extent their Personal Data is subject to the Virginia Consumer Data Protection Act (VCDPA), or the Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA) or any amendments or acts thereto upon their effective dates. The categories of Personal Data processed, the purposes of processing, the categories of Personal Data shared, and the categories of third parties to which Personal Data is shared are provided in the above sections of this Policy, including the chart depicted in the above section California Privacy Rights.
a. Rights under VCDPA, CPA, CTDPA, and UCPA
Virginia, Colorado, Connecticut, and Utah privacy law provides residents with specific rights regarding Personal Data, including:
- Right to Access. You have the right to confirm whether or not we are processing your Personal Data and to access such information.
- Right to Correction. You have the right to correct inaccuracies in your Personal Data which we have collected, taking into account the nature of the Personal Data and the purposes of processing the Personal Data.
- Right to Deletion. You have the right to request deletion of Personal Data provided by or obtained about you, subject to legal exemptions.
- Right to Data Portability. You have the right to obtain a copy of your Personal Data. •
- Right to Opt-Out. You have the right to opt out of the processing of Personal Data for purposes of (1) targeted advertising; (2) the sale of Personal Data; or, if you are in Virginia or Colorado (3) profiling in furtherance of decisions that produce legal or similarly significant effects.
If you would like to exercise any of the rights provided, please refer to the Consumer Requests and Verification section below.
15. CONSUMER REQUESTS AND VERIFICATION
a. Right to Non-Discrimination
We may not discriminate against you because you exercise any of your privacy rights contained in this Privacy Policy including, but not limited to:
- Denying goods or services to you;
- Charging different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties;
- Providing a different level or quality of goods or services to you; or
- Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services.
b. Verifying Requests
You may request to exercise your rights of access, deletion, or correction by contacting us as described in the Contact Information section below. To help protect your privacy and maintain security, we will take steps to verify your identity before processing your request. If you request access to or deletion of your Personal Data, we may require you to provide any of the following information: name, date of birth, email address, telephone number, or postal address. When you make such a request, you can expect the following:
- As required under applicable law, we will verify your identity. You will need to provide us with your email address and full name. We may ask for additional information if needed.
- We will confirm that you want your information accessed, corrected, and/or deleted.
- We will confirm our receipt of your request within 10 days. If you have not received a response within a few days after that, please let us know by contacting us at the webpage or phone number listed below.
- We will respond to your request within 45 days upon receipt of your request. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why.
- In certain cases, a request for access, correction, or deletion may be denied. For example, if we cannot verify your identity, the law requires that we maintain the information, or if we need the information for internal purposes such as providing Services or completing an order. If we deny your request, we will explain why we denied it and delete any other information that is not protected and subject to denial.
c. Authorized Agents
You may designate an authorized agent to request any of the above rights on your behalf. You may make such a designation by providing the agent with written permission, signed by you, to act on your behalf. Your agent may contact us as described in the Contact Information section below to make a request on your behalf. Even if you choose to use an agent, we may, as permitted by law, require:
- The authorized agent to provide proof that you provided signed permission to the authorized agent to submit the request;
- You to verify your identity directly with us; or
- You to directly confirm with us that you provided the authorized agent permission to submit the request.
d. Virginia and Connecticut Appeal Process
If you have made a request to access, correct, or delete your Personal Data under VCDPA and CTDPA, and we have declined to take action, you may appeal our decision within 45 days of the denial. When you make such an appeal, you can expect the following:
- We will verify your identity. You will need to provide us with your email address and full name. We may ask for additional information if needed.
- We will review your appeal and respond in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decision, within 45 days upon receipt of your appeal. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why.
- In certain cases, an appeal may be denied. For example, if we cannot verify your identity, the law requires that we maintain the information, or if we need the information for internal purposes such as providing Services or completing an order. If we deny your appeal, we will explain why we denied it and provide you with a method to contact your state’s Attorney General to submit a complaint.
16. CONTACT INFORMATION
If you have any questions or concerns about this Privacy Policy or our privacy practices, you can contact us via:
Email: Cameron@westock.io
Phone: 973-934-3637