Effective Date: January 14, 2020
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell Products and provide Services to you.
SECTION 1 – PERSONAL INFORMATION WE COLLECTInformation You Give Us. When you contact us, register to receive alerts or other information via email, or purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, postal address, phone number, email address; payment information, such as your credit or debit card number and other card information, billing and other account authentication information; Products purchased, as well as any other information that you directly give us.
SECTION 2 - COOKIES
Here is a list of cookies that we use. We’ve listed them here so you that you can choose if you want to opt-out of cookies or not.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
PREF, persistent for a very short period, Set by Google and tracks who visits the store and from where.
SECTION 3 – HOW WE USE PERSONAL INFORMATIONWe use the information we collect primarily to provide, maintain, protect and improve our current Site, Products, and Services, and to develop new products. We use personal information collected through our Site as described in this Policy to:
- Create and secure your account and identify you as a user in our system;
- Improve our Products, Site, Services and business;
- Understand and enhance your experience with us;
- Facilitate your order and deliver the Products you request;
- Respond to your comments or questions and provide service;
- Send you information, including confirmations, invoices, updates, support and other messages;
- Communicate with you about promotions, upcoming events and news about Products and Services, and for other marketing purposes;
- Link or combine your information with other information we get from third parties to help understand your needs and provide you with better service;
- Protect, investigate and deter against fraudulent, unauthorized or illegal activity; and
- For any additional purposes for which we have obtained your consent to the use or disclosure of your personal information.
SECTION 4 – DISCLOSURE OF PERSONAL INFORMATION
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our Products and Services to you.
Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
As an example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.
Links:When you click on links on our store, they may direct you away from our Site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements. Information collected by other sites is subject to their own terms and policies, not this one.
Google Analytics:Our store uses Google Analytics to help us learn about store visits and the pages being viewed.
We may also share your personal information as follows:
- We may share personal information if you opt-in to receiving our marketing materials. For example, you may let us share personal information with our partners and others for their own marketing uses. Those uses will be subject to their privacy policies.
- We may share your information with vendors, service providers, contractors and agents in connection with the performance of services on our behalf. These service providers are prohibited from using your information except as needed to perform our work or as required by law.
- We may share personal information when we do a business deal, or negotiate a business deal, involving the sale or transfer of all or a part of our business or assets. These deals can include any merger, financing, acquisition, or bankruptcy transaction or proceeding.
- We may share personal information for legal, protection, and safety purposes.
- We may share information to comply with laws or as permitted by laws.
- We may share information to respond to lawful requests and legal processes.
- We may share information with other companies and brands owned or controlled by [Company], Inc., including our subsidiaries.
- We may share information in an emergency. This includes protecting the safety of our employees and agents, our customers, or any person.
SECTION 5 – HOW WE SECURE YOUR INFORMATION
We take the security of your personal information seriously and use reasonable electronic, personnel and physical measures to protect it from loss, theft, alteration or misuse. However, please be advised that even the best security measures cannot fully eliminate all risks. We cannot guarantee that only authorized persons will view your information. We are not responsible for third-party circumvention of any privacy settings or security measures.
Wherever we or a trusted third-party service collects sensitive information (such as credit card data), that information is encrypted and transmitted in a secure way. You can verify this by looking for a closed lock icon at the bottom of your web browser or looking for “https” at the beginning of the address of the web page. When you make a purchase at our store with a credit card, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
We are dedicated to protecting all personal information as is necessary. However, you are responsible for maintaining the confidentiality of your personal information by keeping your password confidential. You should change your password immediately if you believe someone has gained unauthorized access to it or your account. If you learn of any incident involving the loss of or unauthorized access to or disclosure of personal information that is in our custody, you should notify us immediately.
SECTION 6 – YOUR CALIFORNIA PRIVACY RIGHTS
This section describes the rights of California residents pursuant to the California Consumer Privacy Act of 2018 (“CCPA”) and its implementing regulations issued thereunder.
RIGHT TO OPT-OUT OF SALE OF PERSONAL INFORMATION
We do not sell, trade, otherwise transfer your personal information outside of the situations detailed above, so we do not have an opt-out.
RIGHT TO ACCESS YOUR PERSONAL INFORMATION
Subject to applicable laws, you can review, verify or correct your personal information. To submit a request to review, verify, or correct your personal information email us at firstname.lastname@example.org or mail your request to Curaleaf Hemp, 1890 Star Shoot Parkway, Suite 170, Lexington, KY 40509. Only you, or a person legally authorized to act on your behalf (an “Authorized Agent”), may make a verifiable consumer request related to your personal information. You have the right to request this information up to two times in a 12-month period.
RIGHT TO DELETE YOUR PERSONAL INFORMATION
You have the right to request deletion of your personal information. To request the deletion of your personal information, email us at email@example.com or mail your request to Curaleaf Hemp, 301 Edgewater Place #405, Wakefield, MA 01880. Only you, or a person legally authorized to act on your behalf (an “Authorized Agent”), may make a verifiable consumer request related to your personal information.
AUTHORIZED AGENTSIf you use an Authorized Agent to submit a request to know or a request to delete, we may require the Authorized Agent to submit proof that they have been authorized to act on your behalf. We may accept as proof either:
- Written permission from you; or
- A power of attorney pursuant to the California Probate Code §§ 4000 to 4465.
ACCESSIBILITYWe recognize the need to develop electronic and information technology (E&IT) products and services that are accessible and usable by all people, including those with disabilities and special needs. We provide technical and customer support to accommodate the needs of users with disabilities and address issues related to the accessibility of our Products.
Our services include:
- General Customer Support: (781) 451-0150. Available Monday-Friday from 8:30 a.m. to 5pm EST, excluding holidays
NON-DISCRIMINATIONWe will not discriminate against you for exercising any of your rights under the CCPA. Unless permitted by the CCPA, we will not:
- Deny you Products or Services.
- Charge you different prices or rates for Products or Services, including through the use of discounts or other benefits or imposing penalties.
- Provide you with a different level or quality of Products or Services.
- Suggest that you will receive a different price or rate for Products or Services or a different level or quality of Products or Services.
SECTION 7 - CONSENT
You may change or withdraw your consent at any time utilizing the instructions set forth above, subject to legal or contractual restrictions, reasonable notice. Please note that in some circumstances, withdrawing or changing your consent to certain uses of your personal information may affect: (i) our ability to provide you with the products or services you request and (ii) your ability to access to this Site. Kindly note that if you opt-out of receiving our marketing materials, we may still send you non-marketing emails (e.g. order confirmations).
SECTION 8 – REQUEST TO UNSUBSCRIBE FROM FURTHER MESSAGESBy providing us your email address, you are giving us permission to send you emails about our store, new products and other updates. You may unsubscribe at any time by clicking the “Unsubscribe” link at the bottom of each email.
How do I withdraw my consent?If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at firstname.lastname@example.org, clicking the “Unsubscribe” button at the bottom of each email, or mailing us at: Curaleaf Hemp, 301 Edgewater Place #405, Wakefield, MA 01880
SECTION 9 - AGE OF CONSENTBy using this Site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this Site. If we learn or have reason to suspect that a user is under age 18, we will promptly delete any personal information in that user’s account.
Curaleaf Hemp, 301 Edgewater Place #405, Wakefield, MA 01880