GiddyUp Privacy Policy
The GiddyUp Group, Inc.
(“GiddyUp”) is a US company, based in California. Our mission is to bring you remarkable
products from the world’s most innovative companies.
When you use our
services, you’re trusting us with your personal data. We understand this is a big
responsibility, so we work hard to protect your personal data and put you in control.
This Privacy Policy will help you understand what information we collect, why we collect
it, and how you can manage your information.
If you are a resident of
the European Union (“EU”), the European Economic Area (“EEA”), or Switzerland,
processing of your personal data will always be in line with the General Data Protection
Regulation (GDPR).
GiddyUp is the
Controller of this website, as defined in the GDPR. All personal data collected by
GiddyUp is stored exclusively in secure hosting facilities in the US. GiddyUp has data
processing agreements in place with our hosting facilities, ensuring compliance with
GDPR. Please see our Terms of Service for details. All hosting is performed in
accordance with the highest security regulations.
In the case of a
personal data breach, we shall notify the effected parties not later than 72 hours after
having become aware of it, where feasible and without undue delay, unless the personal
data breach is unlikely to result in a risk to the rights and freedoms of natural
persons. If the notification to the effected parties is not made within 72 hours, it
shall be accompanied by the reasons for the delay when the notification is made.
If you are located in
the US, GiddyUp processes your data solely in data centers located in the US. GiddyUp
has adopted reasonable physical, technical and organizational safeguards which
substantially mirror the EU safeguards against accidental, unauthorized or unlawful
destruction, loss, alteration, disclosure, access, use or processing of your data in
GiddyUp’s possession. GiddyUp will promptly notify you in the event of any known
unauthorized access to, or use of, your data.
What
Information do we collect, and how do we use that Information?
Browser
and Device Information. When you visit a GiddyUp website, we automatically
collect some information about your device and your web browser based on a legitimate
interest to this information, since it is needed to make our website function properly.
We collect your browser’s language and country settings so we can display our website in
your preferred language and your country’s currency. We collect information about your
device in order to adapt our website to be displayed best on your type of device -
smartphone, tablet, laptop or desktop.
Marketing
Partner Attribution.GiddyUp works with a number of Marketing Partners who
advertise GiddyUp products in a variety of places – Facebook, Google, Pinterest,
YouTube, MSN, etc. The mix keeps changing, since our Marketing Partners are always
trying new ideas. We will update this policy notification as new partners are added.
We have a legitimate
interest in these Marketing Partners being properly credited for their efforts. So, we
developed a system that passes a unique id for the Marketing Partner and a unique id for
this sale across the Web pages you view along the way to making a product purchase. This
system makes use of cookies (a small piece of text sent to your browser by a website you
visit) and similar technologies. We also pass this identification information as
additional parameters added to the end of the Web address of a page. If you leave a
GiddyUp website and then come back, we try our best to re-establish this identification
information. We also use a third-party processor for managing Marketing Partner
attribution – CAKE, which also uses cookies and IP addresses.
Marketing Partner
Attribution data is kept for 90 days.
Advertiser
Sales Attribution. Another aspect of Marketing Partner attribution that we
have a legitimate interest in are the systems provided by the advertisers for keeping
track of successful and unsuccessful sales. The advertisers substantially raise the
price of advertisements if they do not receive this information, which would make it
economically infeasible for our Marketing Partners to operate.
Advertiser Sales
Attribution data is kept for 30 days.
Advertising
Audience Generation. Advertising platforms such as Facebook and Google have
the concept of an audience, which is a group of people that come to a website over a
period of time. GiddyUp and our Marketing Partners can utilize audiences in various ways
– to have the advertising platforms find people that are similar to the members of an
audience, to show the members of an audience additional advertisements, to exclude
members of an audience from additional advertisements, etc. GiddyUp has a legitimate
interest in these systems, since advertising would not be financially feasible without
utilizing audience mechanisms. But we understand if you do not wish to participate. You
can opt-out of being part of an audience by unchecking the box below:
Include me in Advertising Audiences
Advertising Audience
Generation data is kept for 90 days.
Behavioral
Tracking. GiddyUp makes use of third-party behavioral tracking systems such
as HotJar, Google Analytics, Amplitude and Optimizely. These systems allow us to observe
how people use our websites and enable us to improve how they operate. We also use these
systems to perform A/B testing of new features and site improvements. This processing is
a legitimate interest, but we understand that you might not wish to participate. You can
opt-out of behavioral tracking by unchecking the box below:
Include me in Behavioral Tracking
Behavioral Tracking data
is kept for up to 14 months.
Personal
Information Collected When Purchasing Products.
When you make a purchase
or attempt to make a purchase on our website, we collect the following personal
information:
- IP Address
- Email Address
- Name
- Shipping Address
- Billing Address, if
it is not the same as the Shipping Address
- Phone Number
- Credit Card, PayPal
or Amazon Pay payment information. No credit card data is stored on our site.
We refer to this
information as “Order Information”. We use the Order Information to fulfill your order
(including processing your payment information, arranging for shipping, and providing
you with order acknowledgement and shipping confirmation emails). We will also send you
reminder emails if you fill out some of the Order Information but don’t complete the
purchase.
We store your Order
Information for at least year, since we are contractually obligated to be able to
communicate with you about warranty coverage or other customer service issues. If a
product has a warranty period longer than a year, your Order Information will be
retained for that period.
Communications
from us after Product Purchase. GiddyUp makes use of third-party behavioral
tracking systems such as HotJar, Google Analytics, Amplitude and Optimizely. These
systems allow us to observe how people use our websites and enable us to improve how
they operate. We also use these systems to perform A/B testing of new features and site
improvements. This processing is a legitimate interest, but we understand that you might
not wish to participate. You can opt-out of behavioral tracking by unchecking the box
below:
Do
Not Track. Most modern web browsers give you the option to send a Do Not
Track signal to the websites you visit. However, there is no accepted standard for how a
website should respond to this signal. We currently do not respond to do not track or
similar signals.
Your
Rights under the GDPR
Here is a list of the
rights that all residents of the European Economic Area have under the GDPR. They don’t
apply in all circumstances - if you wish to use any of them, we’ll explain at that time
if they are engaged or not.
- The right to be
informed about the processing of your personal information;
- The right to have
your personal information corrected if it is inaccurate and to have incomplete
personal information completed;
- The right to object
to processing of your personal information;
- The right to
restrict processing of your personal information;
- The right to have
your personal information erased (the “right to be forgotten”);
- The right to
request access to your personal information and to obtain information about how we
process it;
- The right to move,
copy or transfer your personal information (“data portability”);
- Rights in relation
to automated decision making which has a legal effect or otherwise significantly
affects you.
- You have the right
to complain to the Data Protection Supervisory Authority which enforces data
protection laws in your country.
- You have the right
to object to certain purposes for processing, in particular to data processed for
direct marketing purposes and to data processed for certain reasons based on our
legitimate interests.
For the purpose of more
effective compliance with European data protection laws, including the GDPR (2016), the
UK Data Protection Act (2018), and the PECR (2003), GiddyUp confirms that it has
appointed a U.K. company as outsourced DPO, and therefore recognizes the U.K.
Information Commissioner Office (ICO) as its lead supervisory authority.
With respect to GiddyUp
and matters relating to privacy and data protection, we can be reached via email at [email protected], or at the following
address:
Attn: Privacy
Matter
The GiddyUp Group, Inc.
20 N. Oak St.
Ventura, CA 93001
USA
Please email us if you
would like your personal data deleted.
You can also contact our
Data Protection Officer by sending us an email with a subject line of “DPO Contact
Request”.
Additional information for California residents and their rights under the California
Consumer Privacy Act (CCPA)
GiddyUp does not collect
personal information from California residents who we know are under 16 years of age. We
do not sell, as defined in the CCPA, the personal information that we collect.
Subject to certain
exceptions and restrictions, the CCPA provides California consumers the right to request
to:
1) Know more details
about the categories or specific pieces of personal information that we collect
(including how We use and disclose this information);
2) Delete personal
information;
3) Opt out of any sales
that may be occurring.
Please note that for any
of these requests, we will need to verify your identity prior to fulfilling your request
in order to protect your privacy and security. Also, please be advised that we need
certain types of information in order to provide our services. We will not discriminate
against you should you choose to exercise your options under the CCPA.
California residents may
make a request pursuant to their rights under the CCPA by contacting us at [email protected]. We will verify your request
using the information associated with Your account, including email address. Government
identification may be required. Residents can also designate an authorized agent to
exercise these rights on their behalf by providing us documentation sufficiently
demonstrating that You have granted that authorized agent those rights.
Changes
to this Policy
We may change this
Privacy Policy from time to time in order to reflect changes in the law or changes to
our privacy practices. We encourage you to check this privacy notice for changes
whenever you visit a GiddyUp website.
Conditions of Use
We assume that all users
of this website and the GiddyUp platform have carefully read this document and agree to
its contents. If you do not agree with this Privacy Policy, you should refrain from
using our website and platform. We reserve the right to change our Privacy Policy as
necessity dictates. Continued use of GiddyUp’s website and platform after having been
informed of any such changes to these conditions implies acceptance of the revised
privacy policy. This privacy policy is an integral part of GiddyUp’s Terms and
Conditions.
Contact
Us
If you have any
questions, please send us an email at [email protected].
Effective Date of this Privacy Policy
IThis Privacy Policy is
effective as of May 27, 2018 and last updated December 31, 2019.