This Notice at Collection describes how we collect, use, and disclose personal information we collect from or about you.
We collect personal information you provide directly to us. For example, we collect personal information directly from Merchants who register to use our application on their ecommerce websites, Consumers who subscribe for our services, B2B Contacts when we conduct business dealings with them, and generally from individuals who respond to our inquiries, surveys, communications, offers, or marketing. The types of personal information that we may collect directly from you include:
Redo does not see your sensitive financial information, such as financial account, debit card, or credit card information. However, when subscribing to our services, you may transmit such information to third parties, such as banks, processing gateways, and merchant processors, in order to process transactions and payments.
We automatically collect certain personal information about your interactions with us or our services, including the Redo application and website.
We collect information about how you access our services, including data about the device and network you use, such as your hardware model, operating system version, mobile network, Internet Protocol (“IP”) address, unique device identifiers, device type, browser type, and app version. We also collect information about your activity on our services, such as access times, pages viewed, links clicked, and the page you visited before navigating to our services.
We and others that control collection of personal information use tracking technologies, such as cookies and web beacons, to collect information about you. Cookies are small data files stored on your hard drive or in device memory that help us improve our services and your experience, see which areas and features of our services are popular, and count visits. Web beacons (also known as “pixel tags” or “clear GIFs”) are electronic images that we use on our services and in our emails to help deliver cookies, count visits, and understand usage and campaign effectiveness. For more information about cookies and how to disable them, see Your Choices About Cookies below.
We do not envisage that any decisions will be taken about you using automated means (without any human involvement), including profiling, which produces legal or similarly significant effects. In the event that this position changes, we will notify you.
We obtain personal information from other sources. For example, we may collect information from advertising networks, data analytics providers, operating systems and platforms, mailing list providers, social networks, and other advertising partners. This information includes your contact information and usage data collected through cookies and other trackers described in the Advertising and Analytics section below.
We will also receive personal information from Merchants regarding the consumers whom they offer their products and/or services to (“Merchant Consumers”).
Merchants are solely responsible for ensuring that any personal information they provide to us is in compliance with applicable privacy laws, including, but not limited to, ensuring that notice is provided to Merchant Consumers about the sharing of their personal information with us and, where applicable, obtaining appropriate consent.
For certain personal information we receive from Merchants, we will process that personal information in our capacity as a data processor. As such, we will only process such personal information on the documented instructions of the Merchant as a data controller. Please refer to the Purpose and Use of Personal Information section below, where we have identified the purposes for which we may undertake processing activities in our capacity as a data processor on behalf of a Merchant.
We may derive personal information or draw inferences about you based on the information we collect. For example, we may make inferences about your approximate location based on your IP address or infer that you are looking to purchase certain products based on your browsing behavior and past purchases.
We may use the categories of personal information identified in the Collection of Personal Information section above for the following purposes in our capacity as a data processor on behalf of a Merchant:
In addition, we may use the categories of personal information identified in the Collection of Personal Information section above for the following purposes in our capacity as a data controller:
In the EEA and UK, the GDPR requires us to identify a “lawful” or “legal” basis for the processing (our use) of your personal information. The lawful bases we have identified is set out in more detail in the Summary of Prior 12 Month Personal Information Processing Activities section below.
We may disclose your personal information in the following circumstances or as otherwise described in this Privacy Policy. To learn more about the categories of personal information we may disclose and the categories of recipients, please see the Summary of Prior 12 Month Personal Information Processing Activities section below, which describes our prior 12 month and going-forward personal information disclosure practices.
We store personal information for as long as necessary to carry out the purposes for which we originally collected it and for other legitimate business purposes, including legal and compliance obligations. Specifically, we will keep the personal information of Merchants, Consumers, and B2B Contacts as long as we have a continuing relationship with them to provide or receive services and for up to 6 years thereafter, unless we need to retain the personal information for an additional length of time under the law.
If you’d like, I can convert the entire privacy policy into Webflow-ready rich text format in one combined document.
We may allow others to provide analytics services and serve advertisements on our behalf across the web and in mobile apps. These entities may use cookies, web beacons, device identifiers, and other technologies to collect information about your use of our services and other websites and applications, including your IP address, web browser, mobile network information, pages viewed, time spent on pages or in mobile apps, links clicked, and conversion information.
This information may be used by us and others to, among other things, analyze and track data, determine the popularity of certain content, deliver advertising and content targeted to your interests on our services and other websites, and better understand your online activity.
For more information about interest-based ads, or to opt out of having your web browsing information used for behavioral advertising purposes, please visit
www.aboutads.info/choices.
Your device may also include a feature that allows you to opt out of having certain information collected through mobile apps used for behavioral advertising purposes.
We may also work with third parties to serve ads to you as part of customized campaigns on third-party platforms. As part of these ad campaigns, we or the third-party platforms may convert information about you into a unique value that can be matched with a user account on these platforms to allow us to learn about your interests and serve you advertising that is customized to your interests. Note that the third-party platforms may offer you choices about whether you see these types of customized ads.
Redo is headquartered in the United States, and we have operations and/or service providers in the United States and other countries. Therefore, we and our service providers may transfer your personal information to, or store or access it in, jurisdictions that may not provide levels of data protection that are equivalent to those of other countries (such as in the EEA or UK). We will take steps to ensure that your personal information receives an adequate level of protection in the jurisdictions in which we process it. For more information on the safeguards used, see the Data Privacy Framework Notice below.
Most web browsers are set to accept cookies by default. If you prefer, you can usually adjust your browser settings to remove or reject browser cookies. Please note that removing or rejecting cookies could affect the availability and functionality of our services.
If you wish to reject the use of certain cookies, you can also use the “Preferences” banner at the bottom of our website to reject the use of cookies.
This website is not intended for or directed at children under the age of 18. In addition, we do not knowingly collect personal information from children under the age of 18. We also do not knowingly sell, share, use for targeted advertising, or disclose the personal information of children under the age of 18.
In the preceding 12 months, we have collected the categories of personal information set forth below. For details about the precise data points we collect and the categories of sources of such collection, please see the Collection of Personal Information section above. We collect personal information for the business and commercial purposes described in the Purpose and Use of Personal Information section above.
In the preceding 12 months, we have disclosed the following categories of personal information for business purposes to the following categories of recipients, which we also describe in greater detail in the Disclosure of Personal Information section above.
Below, we describe the categories of personal information we may sell or share for targeted advertising currently and in the preceding 12 months. We also describe the third parties who received or may receive the personal information and the business or commercial purpose for the sale or sharing. We do not knowingly sell or share the personal information of children under the age of 18, and have not done so in the prior 12 months.
We honor opt-out preference signals. An opt-out preference signal is a signal that is sent by a platform, technology, or mechanism on your behalf that communicates your choice to opt out of the sharing for targeted advertisements or sale of your personal information. You can learn more about implementing opt-out preference signals by exploring technologies and services that offer this tool. We treat opt-out preference signals as valid requests to opt out of the sale or sharing of your personal information under privacy laws.
Please note that you can also opt out of the sale or sharing of your personal information for targeted advertising through our other methods described in the Instructions on How to Exercise Your Privacy Rights section below.
Some browsers have incorporated “Do Not Track” features. Most of these features, when turned on, send a signal or preference to the websites you visit indicating that you do not wish to be tracked. Because there is not yet a common understanding of how to interpret the do not track signal, we currently do not respond to browser do not track signals. However, as noted above, we do honor opt-out preference signals.
Under some privacy laws, certain types of personal information are considered “sensitive” or “special” personal information or data and require additional data privacy rights and obligations. Redo does not process “special” personal information under the GDPR. However, the financial information described in this Privacy Policy may be considered “sensitive” under US privacy laws.
Specifically, Redo does not see any information that constitutes “sensitive” personal information or data, but you may provide to banks, processing gateways, and merchant processors your sensitive financial account, debit card, or credit card information when using our services. Redo facilitates your provision of this information to these parties in order to provide our services.
This information may also be used to prevent, detect, and investigate security incidents, resist malicious, deceptive, fraudulent, or illegal actions and prosecute those responsible, and ensure physical safety of natural persons. Because this “sensitive” personal information is used for limited and permitted purposes, we do not offer a limit use and disclosure of sensitive personal information right. However, where required by law, we will obtain your consent before such sensitive personal information is collected. You may withdraw your consent by contacting us at privacy@getredo.com.
Data privacy laws afford consumers residing in the United States certain rights with respect to their personal information, subject to certain exceptions. If you reside in the United States, this section applies to you. Subject to certain limitations, you have the following rights in the United States:
In certain circumstances, under the GDPR you will have the right to:
If you want to access, rectify, or request deletion of your personal information, object to the processing of your personal information, request that we transfer a copy of your personal information to another party, or withdraw your consent to processing (if applicable), please contact us using the information below.
If you are dissatisfied with the handling of your personal information, you have a right to lodge a complaint with the data protection supervisory authority where you live. In the UK, this would be the Information Commissioner’s Office. In the EU, this would be the Irish Data Protection Commission.
You may exercise your privacy rights by emailing us at privacy@getredo.com. You may also opt out of the sale of your personal information or the sharing of your personal information for targeted advertising by clicking the Do Not Sell or Share My Personal Information link located in the footer of this website.
In some instances, we will need to verify your identity before honoring your privacy rights request. We will verify your identity by asking you to provide personal information related to your recent interactions with us. We will honor privacy rights requests within 45 calendar days of receipt unless an extension is permitted by law. Opt-out requests for sale or sharing will be honored within 15 business days. Identity verification is not required for opt-out requests, but we may need additional information to locate your records.
You may appeal a denial of your privacy rights request by emailing us at privacy@getredo.com. Within 45 days of receiving an appeal, we will notify you in writing of any action taken, including an explanation of our decision. If we deny your appeal, you may submit a complaint to your state’s Attorney General.
If permitted or required by applicable law, you may exercise your privacy rights through an authorized agent (including a guardian or conservator). If we receive a request from an authorized agent, we may ask for proof that you granted the agent authority to act on your behalf. Authorized agents may contact us at privacy@getredo.com.
California law permits residents to request details about how their information is shared with third parties for direct marketing purposes. If you are a California resident and would like to make such a request, please contact us at privacy@getredo.com.
As a supplement to the information provided throughout this Privacy Policy, we provide the following information in accordance with our obligations as a participating organization under the EU–U.S. Data Privacy Framework and the UK Extension to the EU–U.S. DPF.
Redo complies with the EU–U.S. Data Privacy Framework (“EU–U.S. DPF”) and the UK Extension to the EU–U.S. DPF as set forth by the U.S. Department of Commerce. Redo has certified to the U.S. Department of Commerce that it adheres to the EU–U.S. DPF Principles regarding the processing of personal data received from the European Union and the United Kingdom (and Gibraltar). If there is any conflict between this Privacy Policy and the EU–U.S. DPF Principles, the Principles shall govern. To learn more about the DPF program or to view our certification, visit the Data Privacy Framework website
.
For purposes of the Google Workplace API, our application does not retain user data obtained through the Workplace API to develop, improve, or train generalized artificial intelligence or machine-learning models. Redo does not sell Google user data to third parties.
If you have any questions about this Privacy Policy, you may contact us at:
Email:
privacy@getredo.com
Our representative in the UK:
GDPRLocal Ltd.
1st Floor Front Suite
27–29 North Street
Brighton, England BN1 1EB
Email: contact@gdprlocal.com
Telephone: 441 772 217 800
Our representative in the EU:
Instant EU GDPR Representative Limited
Office 2, 12A Lower Main Street
Lucan, Co. Dublin K78 X5P8, Ireland
Email: contact@gdprlocal.com
Telephone: 353 15 549 700