Effective on November 13, 2017
Digital River's Commitment to Privacy
When we make products available for sale through a website, we are doing so as an independent e-commerce reseller of, or service provider for, the Partner (as defined below) whose name and/or logo appears on the Website.
- Key Terms
- Data Controller, How to Contact Us, and Processing of Your Data
- Lawful Basis for Processing of Data
- How We Protect Your Information
- Use and Sharing of Information
- Your Choices
- Children's Privacy
- Privacy Commitment to California Residents
- Joint Use per Data Protection Legislation
- Information that can no longer be used to identify a particular person ("Anonymous Information").
- Independent data controller has the same meaning as "controller" under Directive 95/46/EC as of October 24, 1995 or any subsequent data protection legislation such as Regulation (EU) 2016/679 as of May 25, 2018, and is the natural person or legal entity, which alone or jointly with others, carries out processing of personal data (as defined below) as well as determines the purpose and means of the processing of personal data, composition and kinds of personal data to be processed, and determines actions (operations) with the personal data ("Data Controller" or "Controller").
- Data where certain identifiers are removed to prevent a person's identity from being directly connected with the information (such as masking certain personal identifiers) ("De-identified Data").
- Processing is permitted if it is necessary for the purposes of legitimate interests pursued by the Controller (or by a third party), except where the Controllers' interests are overridden by the interests, fundamental rights or freedoms of the affected end-users which require protection ("Legitimate Interests").
- Information that can be used to identify you, either alone or in combination with other information available to us, such as your name, shipping and billing address, e-mail address, phone number, identification number (where applicable), date of birth (where applicable), time and location data, bank account information, transaction and payment records, delivery records and other information associated with your account, which is collected by us during delivery of our commerce solution ("Personal Data").
- Digital River may resell products through transactions via its commerce solution, and will generally be the seller and merchant of record for such transactions ("Seller and Merchant of Record").
- Special categories of data require a heightened level of protection under data protection legislation in some jurisdictions, such as processing that reveals health, racial or ethnic origin ("Special Categories of Data")i.
- Any applicable data protection safeguards, as may be amended or replaced, for the transfers of data to Controllers established outside of the EU/EEA that do not ensure an adequate level of protection ("Standard Contractual Clauses").
- Supervisory Authority (or its equivalent under any data protection legislation) is the independent public authority to whom consumers may lodge a complaint ("Supervisory Authority").
Data Controller, How to Contact Us, and Processing of Your Data
- Controller(s) Responsible for Your Data. The Digital River entity that is the Data Controller will vary depending on the site you visit, your transaction with the Website and contractual language.
- Processing of Your Data. Your commerce request, and therefore your Personal Data, will be optimally processed in or near the region from which you initiated your session. This means that the processing of your Personal Data will take place in either the United States and/or Ireland.
- If you are located in Japan or a country with similar data protection requirements, for details of the transmission of your Personal Data to other Digital River entities, please see the "Joint Use" Section at the end of this policy.
REST OF WORLD
- Digital River Ireland, Ltd. as the Controller. Where Digital River Ireland Ltd. is the seller and merchant of record, then any Personal Data provided to or collected by visiting the Website is controlled by Digital River Ireland Ltd., Dromore House, East Park, Shannon, County Clare, V14 AN23, Ireland ("Data Controller").
- Digital River GmbH as the Controller. Digital River GmbH is part of the Digital River group of entities, a leader in e-commerce reselling services, and the authorized reseller of the products and services offered on the MyCommerce Share-it site. Here, any Personal Data provided to or collected by visiting the MyCommerce Share-it site is controlled by Digital River GmbH, Scheidtweilerstrasse 4 Cologne 50933 Germany ("Data Controller").
- Other Digital River entities as the Controller. For purposes of transactions that are made through another Digital River entity, that Digital River entity could be the Data Controller. Please refer to the section above, "Processing of Your Data", which explains where your Personal Data will be processed globally.
Lawful Basis for Processing of Data
In certain jurisdictions, the processing of your Personal Data is lawful only if it is permitted under data protection legislation. In this case, we have a lawful basis for each of our processing activities (unless an exemption applies) as outlined below:
- Legitimate Interest. We will process your data based on Legitimate Interest, and particularly where it is used for marketing purposes, such as to collect data from public sources and to contact prospects to start a conversation. We may also process your data based on Legitimate Interest in the employment contextiii.
- Other Lawful Basis. We may also process your data based on another lawful basis such as where the processing is necessary to enter into or perform a contract with you.
Background and Purpose
- collect Personal Data and other information when you use this Website;
- use, handle and disclose collected information; and
- choices you have about the ways we collect and use the information.
Supplemental Privacy Notices
Partner or Other Third Party Privacy Policies
Terms of Sale
Using or submitting Personal Data through the Website, shall also be governed by our Terms of Sale.
How We Protect Your Information
Digital River takes reasonable steps to provide a level of security appropriate to the sensitivity of the information we collect. We have implemented physical, technical and administrative security practices and safeguards reasonably designed to protect your Personal Data from unauthorized access and disclosureiv. When we collect or transmit sensitive information such as a financial account number, we use industry standard methods to protect that information as required by applicable laws. Although we use reasonable measures to protect your information, we cannot guarantee the security of information provided over the Internet or stored in our databases. You are also responsible for taking reasonable steps to protect your information against unauthorized disclosure or misuse, for example, by protecting your password and signing off when finished using a shared computer or mobile device. We leverage industry best practices to mitigate potential compromises. If the Personal Data under the custody of Digital River is (or is likely to be) divulged, damaged or lost, we will immediately take remedial measures, inform the users in a timely manner and report to the competent government agencies as required by applicable laws.
Information You Manually Provide
We collect Personal Data from you when you use this Website such as:
- when you provide information during a purchase of a product or service,
- when you request information about or otherwise use the Website,
- when you enter into a contest or promotion, sign-up for a newsletter or related services,
- when you submit an order or purchase, download or register products, or request additional services,
- when you call our customer service, you may voluntarily provide information to our representatives, and
- when you apply for a job opening or otherwise submit employment data to us.
Special Categories of Data
Generally, Special Categories of Data will not be collected or processedv. However, there could be a situation (such as for employment purposes) where such data may be processed. In this case, we will be sure to comply with applicable data protection legislation, including relying on the necessary legal grounds to process the data (e.g., processing health data for an insurance contract). We shall use reasonable security practices and procedures to safeguard your Special Categories of Data.
Information from Your Browser or Device
We may also receive information from your web browser. This may include information that does not identify you personally (such as the date and time of your visit). The information we receive depends on the settings on your web browser. If you created a user identity during a visit to this Website, this shall be regarded as giving your consent for processing your Personal Data, if any, and we may link the information provided by your browser to information that identifies you personally, as described below. Please review the settings on your web browser to learn how to change your browser settings. We may also collect limited Personal Data (e-mail address) through web technologies in connection with your use of a Website, as described below.
Cookies and Other Similar Technologies
If you do not wish to receive cookies, you may set your browser to reject cookies or to alert you when a cookie is placed on your computer. Although you are not required to accept cookies, you may be unable to use all of the Website functionality if your browser rejects our cookies.
Information about Third-Party Cookies and Other Technologies
Web technologies may also be placed on this Website by third party providers. Also, we or third party providers may place web technologies on behalf of the Partner whose branding appears on this Website or its service providers. In this way, our Partner would be allowed to use the data collected. This information is used to enhance your experience with the Website, for marketing analysis, for targeted and display advertising, and for quality improvement. We may collect your IP address through web technologies.
We and our Partners use third party service providers in connection with this Website, which may include Alexa Metrics, SeeWhy, Google Analytics and Omniture, and ClickTale. These and other service providers may collect information about your visits to websites, your interaction with that website, and the products and services offered by us, our Partners and our suppliers. Their collection and use of information is subject to their own privacy policies. Please visit the applicable third party service provider if you would like to opt-out per below:
- You may view a list of third party service providers who collect information and opt-out of this collection by visiting www.networkadvertising.org/choices , www.aboutads.info/choices , or www.youronlinechoices.com,
- If you would like to opt-out of Google Ads categories associated with your cookies for display advertising purposes, please visit www.google.com/settings/ads , and
- If you would like to opt-out of Alexa Metrics, please refer to https://support.alexa.com/hc/en-us/articles/200685410-Opting-Out-of-Alexa-Measurement-Pixel
- If you would like to opt-out of tracking of your information through ClickTale, visit www.clicktale.net/disable.html .
Do Not Track Requests
If you opt-out of having your information collected through cookies and other web technologies, your existing display advertising cookie(s) will be deleted and a new cookie will attempt to be placed that instructs service providers not to track your future activities when that cookie is detected (a "no-track" cookie). If your browsers are configured to reject cookies when you visit our opt-out page, a "no-track" cookie cannot be set on your computer. Also, if you subsequently erase "no-track" cookies, use a different computer or change web browsers, you will need to opt-out again. We currently do not respond to browser "no-track" signals.
Information from Third Parties
We may also receive certain information about you from third parties such as through your use of a social network authentication to sign-in to this Website, or through other online data sources, according to the rules of the use and processing of such information established by the respective online data sources. If any Special Categories of Data are freely available or accessible in the public domain, we will not have any obligations to you regarding the same.
When you use a smart phone, mobile device or computer to access our Website or use our mobile application, we may collect information about your physical location. We may combine this information with other location-based information (e.g., your IP address and billing/postal code), to provide you with other services on your mobile device. We share your location information only with third parties that help us provide you with services. You can opt-out of sharing this information by changing the permissions in your mobile device.
Use and Sharing of Information
Your Personal Data provided will be processed on our computer servers. In some cases (such as where it is necessary to fulfill our contractual obligations to you) the information may also be made available to third parties providing services to Digital River.
How We Use Your Data
We may use your Personal Data for the following purposes:
- to contact you if you have requested communication from us,
- to determine the country where you are located such as for trade compliance, security and fraud prevention,
- to otherwise verify compliance with applicable laws,
- to help verify that data we have about you is accurate,
- to provide you with product updates, special offers and other promotional information, either on our own behalf or on the behalf of a Partner, where you have consented to receive it and in accordance with applicable law,
- in connection with keys, access codes or other information so you can access the websites or services of our Partners to receive products or services,
- as identified in a supplemental privacy notice posted on the Website, and
- for human resources such as to collect your email address if you are applying for a position online.
We may also use your Personal Data for the following purposes where you visit the Website to complete a transaction:
- to process your order, process payment, verify your tax status, contest chargebacks, determine your eligibility for a line of credit, or notify you of the status of your order,
- for fraud monitoring and prevention purposes,
- to provide you with a personalized shopping experience,
- to register your purchase with the manufacturer or service provider for warranty, technical support or similar purposes,
- to provide notice of your purchase to the provider of an online service for which you purchase a service use right from us,
- to establish an account for future purchases that you have consented to,
- to facilitate the renewal of subscriptions for products or services, and
- to provide you with an effective experience and support (which may, as allowable by law, include contacting visitors who start a checkout process to follow-up on the incomplete session or to see if there was a problem with their use of the Website).
We will take reasonable steps to ensure any person or entity receiving Personal Data for the purposes described above, are obligated to keep the Personal Data secure. If any Special Categories of Data are being collected, received or retained by an external entity, details of such entity will be shared with you if required by applicable law. Our obligations will not, apply to information shared with any Government entity mandated under law to obtain such information or by an order under law for the time being in force.
In limited situations, we may use your Personal Data to help us make automated decisions to further improve our business. For example, in the context of marketing, we could use data to segment and target users with personalized messages. For example, we may use a job title to determine the users' persona and alter the content accordingly. We may also use that users' geographic location and company data. In some circumstances, for account-based marketing, this could include "likes" that we find in the public domain.
Also, we rely on fraud monitoring to help us reduce the need to manually review orders for fraud. We could also rely on automated processing in the context of employment and to ensure our employees are adhering to our internal security policies. You have the right to avoid any decisions based on automated data processing where they can be characterized as profiling. However, in this case, we reserve the right not to complete your transaction.
Our Use of Anonymous Information
We may use Anonymous Information collected by us. In this case, the following data elements will be anonymized such as first and last name, street address, phone number, email address and other data elements in accordance with applicable law. The Anonymous Information may be used as described here:
- to personalize and support your use of this Website and/or the services of our Partners,
- to improve this Website, the customer experience, our advertising systems, and our products and services,
- for fraud prevention purposes, such as device fingerprinting,
- to identify transactions as originating through an affiliate marketing or referral program,
- to deliver targeted advertisements on this Website and other commerce solutions,
- to provide reporting to our current and prospective Partners and service providers, and
- for other historical, statistical, research and analysis purposes.
We may also use De-identified Data for the purposes mentioned above, and related purposes as allowed by applicable law.
We will provide certain Personal Data, Anonymous Information or De-identified Data to our Partners to fulfill our obligations to you, and otherwise assist Digital River's use of Personal Data as described in the "How We Use Your Data" section:
- for reporting purposes,
- to allow our Partner or its service provider to register your purchase,
- to enable your access to products or services provided by our Partner or its suppliers,
- to facilitate warranty, technical support or after-sales service,
- to allow our Partner or subcontractor to send email or direct mail communications if you have consented to receive them,
- to allow our Partner or its service provider to provide services in connection with this Website (such as customer support or single sign-on functionality), or
- for similar purposes in order to fulfill obligations to you.
Our Service Providers
We utilize other companies, including our corporate affiliates, to provide certain services to us or on our behalf to help us operate our business such as:
- to host or maintain this Website,
- to process credit card payments,
- to provide fraud monitoring or detection services,
- to perform data integrity checks,
- to offer you a line of credit,
- to provide optimization services,
- to fulfill your order,
- for payment collection,
- to deliver advertisements on this Website and third party websites,
- to send mail or e-mail,
- for purposes related to employment and human resources, and/or
- to provide customer service.
We will not share your Personal Data with our service providers in connection with their offering of services to us, unless it is required for the purposes of our Legitimate Interests and purposes of fulfilling our obligations as to delivery of our commerce solution to you. These service providers may be contractually required to use any information we share with them only to perform services to us or on our behalf and to protect the confidentiality of your Personal Data. We may also allow these companies to use Anonymous Information for their business purposes. We will not share your Personal Data with our affiliates or unrelated third parties to use for their own marketing purposes without your consent.
To Comply With Legal Requirements, Prevent Fraud and Crimes
As permitted by applicable law, we may disclose Personal Data or Special Categories of Data about you when we believe disclosure is appropriate to:
- to comply with the law or a regulatory requirement,
- to comply with governmental, administrative or judicial process, requirement or order (such as a court order),
- to cooperate with law enforcement or other governmental investigations or report any activities that may be in violation of legal or regulatory requirements,
- to enforce a contract,
- to protect the legal rights, Website or safety of Digital River and our employees, Partners, third parties, the public in general or youvi.
In Connection with a Sale, Merger or related Event
We respect your right to make choices about the ways we collect, use and share your Personal Data.
Access to Your Information
If you contact us we may ask you for additional information to verify your identity. We reserve the right to limit or deny your request if you have failed to provide sufficient information to verify your identity or to satisfy our legal and business requirements as noted in our data retention policy. When we delete your Personal Data or Special Categories of Data, it will be disposed of in a manner that prevents loss, theft, misuse, or unauthorized access in-line with our data retention policy.
You have the right to report to your local Supervisory Authority where you feel as though your rights under data protection legislation have not been appropriately considered. However, before doing so, please contact us directly as we are committed to working with you to help resolve any concerns about your privacy.
Data Retention Policy
Digital River may retain your Personal Data for as long as you continue to use our Website, and thereafter as permitted or required by applicable law or to satisfy our business requirements.
Marketing and Related-Communications
When you provide Personal Data, we may offer you a choice as to whether you would like to receive further marketing and related communications from us or our Partners. These communications could be in the form of direct mail, email or telephone and will contain information to inform you of our products and services. You may opt-out of receiving these communications by e-mailing us at firstname.lastname@example.org, or by following any unsubscribe instructions in e-mail communications.
If you give us consent to add your contact information to our Partner's mailing list and later withdraw this permission, you must contact our Partner (or follow the unsubscribe instructions in the e-mails from our Partner) to have your name removed from our Partner's mailing lists.
This Website is not directed at nor targeted to children. If you have not reached the age of majority or are not able to enter into legally binding agreements in your country, you may not use this Website unless necessary parental consent has been obtained. If you believe that we have received information from a person protected under child protection laws where necessary parental consent was not obtained, please notify us immediately, and we will take reasonable steps to securely remove that information.
Privacy Commitment to California Residents
Joint Use per Data Protection Legislation
In certain jurisdictions (such as under Japanese data protection legislation), the details of the transmission of your Personal Data to other Digital River entities must be included. Therefore, the following categories of Personal Data could be jointly used with certain Digital River entities, which entities are listed by region here ("Joint Users"):
- Consumer data (such as name, shipping and billing address, e-mail address, phone number, transaction and payment records, delivery records and other information associated with a consumer's account), which is collected by us during delivery of our commerce solution;
- Human Resource data (such as employee data or prospective employee data); and
- Other data which is collected by us when an individual visits our Website or otherwise utilizes our services.
The Joint Users will use the Personal Data for the purposes set forth in "How We Use Your Data" section above. Digital River, Inc. and/or Digital River Ireland Ltd. are currently responsible for management of Personal Data subject to the joint use.
i Please note that for India, data protection legislation applies only to sensitive personal data and not to general personal information. Also, specifically for Russia, requirements for protection of special categories of Personal Data is regulated under Art. 10 of the Russian Federal Law "On personal data" N152-FZ as of July 27, 2006 ("FL 152").
ii In case we need your written (or other form of) consent for processing your Personal Data, the Data Controller will process such Personal Data only with your respective consent and under the terms of this consent.
iii Only if such processing is not prohibited under the applicable law.
iv Notwithstanding anything contained herein, "reasonable security practices and procedures" under section 43A Explanation (ii) of the Indian Information Technology Act 2000 means and includes such aforementioned practices and safeguards and you agree to the same.
v As noted above, Indian data protection legislation apply only to sensitive personal data (Special Categories of Data) and not to general personal information.
vi Please also refer to the grounds provided for by the applicable local law (such as Art. 6 of FL 152 for Russia).