Privacy Policy2018-05-27T08:29:17-07:00
Privacy

Last Updated: May 24, 2018

INFORMATION COLLECTION AND USE

This Privacy Policy describes the ways in which SmartChic (“Company”, “we” or “our”) collects, uses, maintains and discloses information collected from our visitors and/or customers (collectively, “Customer”, “you” or “your”) through the use of the Company websites.

SmartChic is the sole owner of the information collected on this site. We will not sell, share, or rent this information to others in ways different from what is disclosed in this statement. SmartChic may collect information from our customers at several different points on our website, as needed to service our customers, as outlined below.

COOKIES

There are a couple types of cookies related to the web browsing experience. Neither cookie type contains any personally identifiable information. A temporary cookie, technically known as a Session Cookie, is one that your browser sets by default to communicate your browsing experience between you and the server. This session cookie is automatically destroyed in your browser when you close the web browsing session on the SmartChic site.

The second cookie type is known as a persistent cookie. A persistent cookie is a small bit of data stored locally on your machine that help with the overall browsing experience.

SmartChic in general does not utilize the use of persistent cookies for the site to function properly. However, these cookies can help us provide a more tailored experience for Customer based on the type of product Customer has expressed interest in and in the way a customer chooses to utilize the services. The types of persistent cookies SmartChic utilizes is for tracking how and when you initially found SmartChic including what page you first landed on.

For added control, customers have options for helping with login conveniences.

INFORMATION COLLECTED DURING ORDER PROCESS

We request information from the user on our order form(s). In order for us to service Customer account, here a user must provide contact information (email, name, address, phone) and depending on payment method, financial information (credit card number, expiration date, bank information). Additionally, the IP is recorded in the billing system. This information is used for billing purposes and to fill customer’s orders. If we have trouble processing an order, this contact information is used to get in touch with the user. We use a high encryption SSL certificate for securely gathering the requested information. We also use a third party credit card processing system which encrypts the credit card information for your security and all credit card information is NOT stored on our site.

LOG FILES

Log files automatically collect certain types of information related to your browser, including your IP address. We use IP addresses to analyze trends and help provide an insight into how visitors transition from one page to another, so we can optimize the visitor experience, and gather broad demographic information like the type of browser, for aggregate use. IP addresses are not linked to personally identifiable information.

SHARING OF INFORMATION

SmartChic does NOT share any personal information with any outside company except as outlined here:

Credit/Payment Card Processors – SmartChic uses a credit/payment card processing company (just like every business that accepts credit cards must do) to bill users for goods and services. SmartChic only passes the required information to the credit card company which includes the name, card number, expiration date and billing zip code. SmartChic does NOT forward any personally identifiable information to these card processing companies.

LINKS

Company web sites contain links to third party sites. These third-party websites have their own privacy policies and that we do not accept any responsibility or liability for their policies. We encourage our visitors to be aware when they leave our site and to read the privacy statements of each and every web site that collects personally identifiable information. This privacy statement applies solely to information collected by Company Web sites.

NEWSLETTER

If a visitor wishes to subscribe to our newsletter, we ask for contact information such as name and email address.

SURVEYS & CONTESTS

From time-to-time our site requests information from visitors or customers via surveys or contests. Participation in these surveys or contests is completely voluntary and the participant therefore has a choice whether or not to disclose this information. Information requested may include contact information (such as name and address), and demographic information (such as zip code and age). Contact information will be used to notify the winners and award prizes. Survey information will be used for purposes of improving SmartChic services or as a thank you for our customers’ continued support..

SECURITY

This website takes every precaution to protect our visitors’ information. When visitors submit sensitive information via the website, the information is protected both online and off-line.

When our order form(s) asks visitors to enter sensitive information (such as credit card number), that information is encrypted and is protected with the best encryption software in the industry – SSL. While on a secure page, such as our order form(s), the lock icon in the Web browser becomes locked. SmartChic has taken additional steps to ensure SSL encryption is used at all times when browsing our site.

While we use SSL encryption to protect sensitive information online, we also do everything in our power to protect user-information off-line. All of our users’ information, not just the sensitive information mentioned above, is restricted in our office. Only employees who need the information to perform a specific job are granted access to personally identifiable information. Finally, the servers that we store personally identifiable information on are kept in a secure environment.

SmartChic’s website and services are not intended for, nor designed to attract, individuals under the age of 18. SmartChic does not knowingly collect personally identifiable information from any person under the age of 18.

SPECIAL OFFERS

We send all new accounts an email providing new account information. Established customers will occasionally receive information on new services and/or special promotions. Out of respect for the privacy of our users we present the option to not receive these types of communications.

CORRECTING/UPDATING/DELETING PERSONAL INFORMATION

If a user’s personally identifiable information changes (such as your phone number or email address), or if a user no longer desires our service, we will endeavor to provide a way to correct, update or remove that user’s personal data provided to us. This can usually be done at the user’s Control Panel page or by emailing us.

CUSTOMER INFORMATION AND CUSTOMER PRIVACY

New European Union (EU) Data Protection laws (GDPR) are effective May 25, 2018. While GDPR only holds us accountable for how we process EU customers’ personal data, we have taken this opportunity to review our practices and ensure that our high standards for data privacy encompass every one of our customers. Therefore, you may see references to GDPR within the Privacy Policy.

Company shall act in accordance with industry practice in protecting Customer Information submitted by Customer to Company (“Customer Information”) and shall not sell or otherwise transfer Customer Information to third parties for marketing activities in any circumstance. Company shall be entitled to use the Personal Information of Customer in the due performance of the Services, this Agreement and (unless opted out in writing) for communication to Customer of Company’s own marketing information.

As to Personal Information, also referred hereinto as Personal Data, supplied by or through Customer during its business with Company, the following shall apply:

(1) Both parties will comply with their respective obligations under the applicable requirements of the Data Protection Laws.

(2) The parties acknowledge that for the purposes of the Data Protection Laws, Customer is the data controller and Company is the data processor (where Data Controller and Data Processor have the meanings as defined in the Data Protection Laws). The following sets out the scope, nature and purpose of processing by Company, the duration of the processing and the types of Personal Data (as defined in the Data Protection Laws) and categories of Data Subject:

(a) Processing by Company: The provision of data or application hosting services for Customer and indirectly its customers.

(b) Company does not control what personal or non-personal data Customers collect from their customers. It is Customer’s responsibility to have their own Data Protection guidelines in place for their own protection related to data Customer collects from its customers; additionally, it is Customer’s responsibility to keep their applications up to date and secure from a code/software perspective.

(3) Customer declares and acknowledges that Company has no control, involvement, role or responsibility as to the type or use of data put by Customer itself or third parties generally nor, without limitation, Customer’s employees, contractors, agents, customers or suppliers or end-users of Customer’s services or those of Customer’s customers and Company merely provides an IT repository for data with a specified conduit for its movement to and from Customer or third-party infrastructure. Company’s processing does not include the manipulation, selection, ordering, searching or monitoring of such Personal Data other than in a generic sense of storage in the scope of the Services. Customer is responsible for the cleansing, updating, timely deletion and maintenance of Personal Data.

(4) Customer will ensure that it has all necessary and appropriate consents and notices in place to enable lawful transmission of Personal Data to Company and its processing in accordance with this Agreement for the duration and purposes of this Agreement.

(5) Without prejudice to the generality of the above clause, Company shall, in relation to any Personal Data processed in connection with the performance by Company of its obligations under this Agreement:

(a) process that Personal Data only in accordance with the performance of Services and otherwise either required under this Agreement (this Agreement being agreed to constitute written instructions from Customer for processing of Personal Data) or by variation of Services agreed with Company; or

(b) process that Personal Data if required by the laws of any member of the European Union or by the laws of the European Union applicable to Company to process Personal Data (Applicable Laws). Where Company is relying on laws of a member of the European Union or European Union law as the basis for processing Personal Data outside of pre-agreed processing, Company shall promptly notify Customer of this before performing the processing required by the Applicable Laws unless those Applicable Laws prohibit Company from so notifying Customer;

(c) ensure that it has in place appropriate, industry-standard for England, technical and organizational measures to protect against unauthorized or unlawful processing of that Personal Data and against accidental loss or destruction of, or damage to, those Personal Data, having regard to the state of technological development and the cost of implementing any;

(d) ensure that all personnel who have access to and/or process those Personal Data are obliged not to permit disclosure of the Personal Data except as required by law or for the purposes of this Agreement; and

(e) not transfer any of those Personal Data, other than Customer Submitted information required for servicing Customer account (ie, US and UK based systems/support/billing teams), outside of the European Economic Area (other than Customer’s transmission and receipt of data over the Internet and the use of similar networks that may involve part of the network being located outside the European Economic Area and/or the UK), unless the prior written consent of Customer has been obtained;

(f) assist Customer, at Customer’s expense using Company’s then current standard time rates, in responding to any request from a Data Subject and in ensuring compliance with its obligations under the Data Protection Laws with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;

(g) notify Customer without undue delay on becoming aware of a material Personal Data breach committed by Company, its employees or agents and take reasonable steps to prevent further disclosure or breach and mitigate the potential adverse effects on affected data subjects in cooperation with Customer;

(h) at the written direction of Customer, delete or return to Customer or allow Customer to retrieve Personal Data and copies thereof on termination of Agreement unless required by Applicable Law to store Personal Data;

(i) maintain appropriate records and information to demonstrate its compliance with this clause;

(j) in accordance with Data Protection Laws, make available to Customer such information as is reasonably necessary to demonstrate Company’s compliance with its obligations under Article 28 of the GDPR (and under any Data Protection Laws equivalent to that Article 28), and allow for and contribute to audits, including inspections, by Customer’s professional appointee for this purpose, subject to Customer:

(j.1) giving Company reasonable prior notice of such information request, audit and/or inspection being required by Customer;

(j.2) ensuring that all information obtained or generated by Customer or its auditor(s) in connection with such information requests, inspections and audits is kept strictly confidential (save for disclosure to the supervisory authority under Data Protection Laws or as otherwise required by Applicable Laws);

(j.3) ensuring that such audit or inspection is undertaken during normal business hours, with minimal disruption to Company’s business, any sub-processors’ business and the business of other customers of Company; and

(k) paying Company’s costs using the then current standard time rates of Company for assisting with the provision of information and allowing for and contributing to inspections and audits.

(6) Company shall nominate a point of contact for all issues related to data privacy and protection within the scope of the Agreement and pending notification; otherwise this will be the CEO/Managing Director.

(7) If Company informs Customer that it considers that an instruction violates Data Protection Laws then it shall be entitled to suspend the execution of the relevant instructions until Customer satisfactorily confirms compliance or changes them. Further, if Company follows the instructions of Customer, Customer indemnifies Company for any and all such current and future items or incidences related to such instruction.

(8) Customer shall, without undue delay and in a comprehensive fashion, inform Company of any defect that Customer considers has occurred in their and/or Company’s compliance with Data Protection Laws.

(9) Customer shall be obliged to maintain the public register of processing in accordance with Article 30 (1) GDPR.

DISPUTE RESOLUTION

The first step in resolving any concern is to contact Company (see Inquiries or Complaints below) with any details. Unresolved issues will be resolved via binding Arbitration as a sole remedy.

INQUIRIES OR COMPLAINTS

To make an inquiry or complaint related to this Privacy Policy, send an email to info[ at ]smartchic.me.

NOTIFICATION OF CHANGES

From time to time, we may need to update this Privacy Policy. When that occurs, we will post those changes on this page as well as update the Modified date, so Customer can stay aware of what information we collect, how we use it, and under circumstances, if any, we disclose it. If at any point we decide to use personally identifiable information in a manner different from that stated at the time it was collected, we will notify users by way of an email. Users will have a choice as to whether or not we use their information in this different manner. We will use information in accordance with the privacy policy under which the information was collected.