Effective date: June 5, 2023
We are dedicated to ensuring that your health data is never shared with (or sold to) any third parties.
Categories of Personal Data We Collect
This chart details the categories of Personal Data that we collect and have collected over the past 12 months:
1. Profile or Contact Data
• 1a. Examples of personal data we collect: First and last name, Email, Phone number, Birthday, Unique identifiers such as passwords
• 1b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
• 2a. Examples of personal data we collect: Cultural or social identifiers (for example, being a skateboarder, a Green Bay Packers fan, an environmental activist, etc.)
• 2b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
3. Payment Data
• 3a. Examples of personal data we collect: Payment card type, Last 4 digits of payment card, Billing address, phone number, and email
• 3b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers (specifically our payment processing partner, currently Stripe, Inc.)
4. Commercial Data
• 4a. Examples of personal data we collect: Purchase history, Consumer profiles
• 4b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
5. Device / IP Data
• 5a. Examples of personal data we collect: IP address, Device ID, Domain server, Type of device/operating system/browser used to access the Services
• 5b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
6. Web Analytics
• 6a. Examples of personal data we collect: Web page interactions, Referring webpage/source through which you accessed the Services, Non-identifiable request IDs, Statistics associated with the interaction between device or browser and the Services
• 6b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
7. Social Network Data
• 7a. Examples of personal data we collect: Email, Phone number, User name, IP address, Device ID
• 7b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
8. Consumer Demographic Data
• 8a. Examples of personal data we collect: Age / date of birth, Zip code, Gender, Race, Ethnicity
• 8b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
9. Geolocation Data
• 9a. Examples of personal data we collect: IP-address-based location information, GPS data
• 9b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
10. Health Data
• 10a. Examples of personal data we collect: Medical conditions, Medications, Weight, Allergy triggers, Family medical history
• 10b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
11. Categories of Data Considered “Sensitive” Under the California Privacy Rights Act and the Virginia Consumer Data Protection Act
• 11a. Examples of personal data we collect: Personal information concerning a consumer’s health, Personal information concerning a consumer’s sex life or sexual orientation, Personal data revealing citizenship or immigration status, Precise geolocation data
• 11b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
12. Other Identifying Information that You Voluntarily Choose to Provide
• 12a. Examples of personal data we collect: Identifying information in emails or letters you send us
• 12b. Categories of Third Parties With Whom We Share this Personal Data: Service Providers, Advertising Partners, Analytics Partners, Business Partners, Parties You Authorize, Access or Authenticate
Categories of Sources of Personal Data
We collect Personal Data about you from the following categories of sources:
When you provide such information directly to us.
• When you create an account or use our interactive tools and Services.
• When you voluntarily provide information in free-form text boxes through the Services or through responses to surveys or questionnaires.
• When you send us an email or otherwise contact us.
When you use the Services and such information is collected automatically.
• Through Cookies (defined in the “Tracking Tools, Advertising and Opt-Out” section below).
• If you use a location-enabled browser, we may receive information about your location.
• If you download and install certain applications and software we make available, we may receive and collect information transmitted from your computing device for the purpose of providing you the relevant Services, such as information regarding when you are logged on and available to receive updates or alert notices.
• We may use analytics providers to analyze how you interact and engage with the Services, or third parties may help us provide you with customer support.
• We may use vendors to obtain information to generate leads and create user profiles.
• We receive information about you from some of our vendors who assist us with marketing or promotional services related to how you interact with our websites, applications, products, Services, advertisements or communications.
• If you provide your social network account credentials to us or otherwise sign in to the Services through a third-party site or service, some content and/or information in those accounts may be transmitted into your account with us.
Our Commercial or Business Purposes for Collecting or Disclosing Personal Data
Providing, Customizing and Improving the Services
• Creating and managing your account or other user profiles.
• Processing orders or other transactions; billing.
• Providing you with the products, services or information you request.
• Meeting or fulfilling the reason you provided the information to us.
• Providing support and assistance for the Services.
• Improving the Services, including testing, research, internal analytics and product development.
• Personalizing the Services, website content and communications based on your preferences.
• Doing fraud protection, security and debugging.
• Carrying out other business purposes stated when collecting your Personal Data or as otherwise set forth in applicable data privacy laws, such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (the “CPRA”).
Marketing the Services
• Marketing and selling the Services.
• Showing you advertisements, including interest-based or online behavioral advertising.
Corresponding with You
• Responding to correspondence that we receive from you, contacting you when necessary or requested, and sending you information about Nectar or the Services.
• Sending emails and other communications according to your preferences or that display content that we think will interest you.
Meeting Legal Requirements and Enforcing Legal Terms
• Fulfilling our legal obligations under applicable law, regulation, court order or other legal process, such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities.
• Protecting the rights, property or safety of you, Nectar or another party.
• Enforcing any agreements with you.
• Responding to claims that any posting or other content violates third-party rights.
• Resolving disputes.
We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated or incompatible purposes without providing you notice. If you are a California resident, please note that we only use or disclose your sensitive personal information for the purposes set forth in section 7027(m) of the CPRA regulations and we do not collect or process sensitive personal information with the purpose of inferring any characteristics about California residents.
How We Disclose Your Personal Data
We disclose your Personal Data to the categories of service providers and other parties listed in this section. Depending on state laws that may be applicable to you, some of these disclosures may constitute a “sale” of your Personal Data. For more information, please refer to the state-specific sections below.
Service Providers. These parties help us provide the Services or perform business functions on our behalf. They include:
• Hosting, technology and communication providers.
• Security and fraud prevention consultants.
• Support and customer service vendors.
• Product fulfillment and delivery providers.
• Payment processors.
Our payment processing partner Stripe, Inc. (“Stripe”) collects your voluntarily-provided payment card information necessary to process your payment.
Advertising Partners. These parties help us market our services and provide you with other offers that may be of interest to you. They include:
• Ad networks.
• Data brokers.
• Marketing providers.
Analytics Partners. These parties provide analytics on web traffic or usage of the Services. They include:
• Companies that track how users found or were referred to the Services.
• Companies that track how users interact with the Services.
Business Partners. These parties partner with us in offering various services. They include:
• Businesses that you have a relationship with.
• Companies that we partner with to provide the Services to you.
• Companies that we partner with to offer joint promotional offers or opportunities.
Parties You Authorize, Access or Authenticate
• Third parties you access through the services.
• Social media services.
• Other users.
We may share any Personal Data that we collect with third parties in conjunction with any of the activities set forth under “Meeting Legal Requirements and Enforcing Legal Terms” in the “Our Commercial or Business Purposes for Collecting Personal Data” section above.
All of your Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part). Should one of these events occur, we will make reasonable efforts to notify you before your information becomes subject to different privacy and security policies and practices.
Data that is Not Personal Data
We may create aggregated, de-identified or anonymized data from the Personal Data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and share it with third parties for our lawful business purposes, including to analyze, build and improve the Services and promote our business, provided that we will not share such data in a manner that could identify you.
Tracking Tools, Advertising and Opt-Out
We use the following types of Cookies:
• Essential Cookies. Essential Cookies are required for providing you with features or services that you have requested. For example, certain Cookies enable you to log into secure areas of our Services. Disabling these Cookies may make certain features and services unavailable.
• Retargeting/Advertising Cookies. Retargeting/Advertising Cookies collect data about your online activity and identify your interests so that we can provide advertising that we believe is relevant to you. For more information about this, please see the section below titled “Information about Interest-Based Advertisements.”
You can decide whether or not to accept Cookies through your internet browser’s settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your device. If you do this, however, you may have to manually adjust some preferences every time you visit our website and some of the Services and functionalities may not work.
To explore what Cookie settings are available to you or to modify your preferences with respect to Cookies, you can access your Cookie management setting by clicking your browser settings. To find out more information about Cookies generally, including information about how to manage and delete Cookies, please visit http://www.allaboutcookies.org/.
Information about Interest-Based Advertisements:
We may serve advertisements, and also allow third-party ad networks, including third-party ad servers, ad agencies, ad technology vendors and research firms, to serve advertisements through the Services. These advertisements may be targeted to users who fit certain general profile categories or display certain preferences or behaviors (“Interest-Based Ads”). Information for Interest-Based Ads (including Personal Data) may be provided to us by you, or derived from the usage patterns of particular users on the Services and/or services of third parties. Such information may be gathered through tracking users’ activities across time and unaffiliated properties, including when you leave the Services. To accomplish this, we or our service providers may deliver Cookies, including a file (known as a “web beacon”) from an ad network to you through the Services. Web beacons allow ad networks to provide anonymized, aggregated auditing, research and reporting for us and for advertisers. Web beacons also enable ad networks to serve targeted advertisements to you when you visit other websites. Web beacons allow ad networks to view, edit or set their own Cookies on your browser, just as if you had requested a web page from their site.
We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account. Although we work to protect the security of your account and other data that we hold in our records, please be aware that no method of transmitting data over the internet or storing data is completely secure.
We retain Personal Data about you for as long as necessary to provide you with our Services or to perform our business or commercial purposes for collecting your Personal Data. When establishing a retention period for specific categories of data, we consider who we collected the data from, our need for the Personal Data, why we collected the Personal Data, and the sensitivity of the Personal Data. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.
- We retain your profile information and credentials for as long as you have an account with us.
- We retain your payment data for as long as we need to process your purchase or subscription.
- We retain your device/IP data for as long as we need it to ensure that our systems are working appropriately, effectively and efficiently.
Personal Data of Children
Your Privacy Rights
Depending on where you reside, you may have certain privacy rights afforded to you. These rights may come with certain requirements, conditions, and exceptions. Please see the “Exercising Your Rights” section below for instructions regarding how to exercise these rights. Please note that we may process Personal Data of our customers’ end users or employees in connection with our provision of certain services to our customers. If we are processing your Personal Data as a service provider, you should contact the entity that collected your Personal Data in the first instance to address your rights with respect to such data.
You may have the following rights with respect to your Personal Data
You have the right to request certain information about our collection and use of your Personal Data over the past 12 months. In response, we will provide you with the following information:
• The categories of Personal Data that we have collected about you.
• The categories of sources from which that Personal Data was collected.
• The business or commercial purpose for collecting or selling your Personal Data.
• The categories of third parties with whom we have shared your Personal Data.
• The specific pieces of Personal Data that we have collected about you.
You have the right to request a copy of your Personal Data in a machine-readable format, to the extent technically feasible.
You may have the right to request that we delete the Personal Data that we have collected about you. We may decline your request for certain reasons as prescribed under applicable law.
You have the right to request that we correct any inaccurate Personal Data we have collected about you.
Opting out of certain processing activities:
- The use of your Personal Data for cross-contextual behavioral advertising or targeted advertising that you may opt-out from. This may constitute a “sale” depending on your place of residence.
- Our business or sale purposes for these activities may include:
- Marketing and selling the Services.
- Showing you advertisements, including interest-based or online behavioral advertising.
- We may share your Profile or Contact Data, Commercial Data, Device/IP Data, Web Analytics, Consumer Demographic Data, and Geolocation Data with respect to these purposes.
- We work with Advertising Partners, Analytics Partners, and Business Partners with respect to these purposes.
- Once you have submitted an opt-out request (“Sale or Share Opt Out”), we will not ask you to reauthorize the sale of your Personal Information for at least 12 months. To our knowledge, we do not sell the Personal Data of minors under 16 years of age.
- Our business or sale purposes for these activities may include:
- You have the right to opt out from direct marketing communications. You can do this by utilizing the “unsubscribe” link or method provided in such communication, or by contacting email@example.com.
- You have the right to opt-out from the processing of your Personal Data for the purposes of profiling in furtherance of decisions that produce legal or similarly significant effects for you, if applicable. We currently do not process your Personal Data for these purposes.
We will not discriminate against you for exercising your privacy rights. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise your privacy rights. However, we may offer different tiers of our Services as allowed by applicable data privacy laws (including the (CCPA) with varying prices, rates or levels of quality of the goods or services you receive related to the value of Personal Data that we receive from you.
Appealing a Decision
If you are a Virginia resident and we refuse to take action on a request within a reasonable period of time after receiving your request in accordance with this section, you may appeal our decision. In such appeal, you must (1) provide sufficient information to allow us to verify that you are the person about whom the original request pertains and to identify the original request and (2) provide a description of the basis of your appeal. Please note that your appeal will be subject to your rights and obligations afforded to you under the Virginia Consumer Data Protection Act. We will respond to your appeal within 60 days of receiving your request. If we deny your appeal, you have the right to contact the Virginia Attorney General using the methods described at https://www.oag.state.va.us/consumer-protection/index.php/file-a-complaint.
- Email us at firstname.lastname@example.org (the title of your email must include “VCDPA Appeal”).
- Call us at 1 (888) 851-3336.
Exercising Your Rights
We will work to respond to your Valid Request within the time period required by applicable law. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive, or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.
You may submit a Valid Request using the following methods:
• Email us at: email@example.com
• Call us at: 1 (888) 851-3336
If you are a California Resident, you may also authorize an agent (an “Authorized Agent”) to exercise your rights on your behalf. To do this, you must provide your Authorized Agent with written permission to exercise your rights on your behalf, and we may request a copy of this written permission from your Authorized Agent when they make a request on your behalf.
• Website: www.mynectar.com
• Phone: 1 (888) 851-3336
• Address: 30 Cooper Sq Fl 10, NY NY 10003