PLEASE READ IT AS IT INCLUDES IMPORTANT INFORMATION REGARDING YOUR PERSONAL DATA AND INFORMATION.
1. Who we are
Zollo Social Shopping Ltd. (hereinafter: “OurCart”, “The Company”, “We”) is an Israeli based Company that provides receipt capture, analyzing and processing services under the OurCart brand name (hereinafter: “the Services”). We develop and operate the OurCart website: https://www.ourcart.com (hereinafter: “the Website”), and the Ourcart mobile application (hereinafter: “the App”).
2. Privacy statement
3.1. To use our Services, we may need to collect, store or process data provided by you. Therefore, we might receive, collect, store and process personal data that:
3.1.1. you voluntarily provide; and/or
3.1.2. give your consent to collect and process it; and/or
3.1.3. the processing is necessary to meet contractual obligations entered by you and us or our customers; and/or
3.1.4. Processing is necessary to comply with legal obligations of us or our customers; and/or
3.1.5. Processing is for the purposes of legitimate interests pursued by us or our customers.
IF YOU HAVE A REASONABLE BASIS TO ASSUME OR YOU KNOW THAT ANY OF THE ABOVE MENTIONED IS NOT MEET, YOU REQUIRED TO INFORM US, WITHOUT DUE DELAY, BY SEND US EMAIL TO: firstname.lastname@example.org.
4. Personal data that we use
4.1 Some information may be mandatory provided by you to us, as part of the services, and some information may have collected by us during the services. The types of data that we may receive, collect, store and process may include your:
4.1.1 Personal Data – such as: Name, Address, Email address, Phone number, ID number, IP address, age, gender, country, preferred language; Financial Data; Location data; cookies; your shopping list etc.
4.1.2 Media Data: your receipt snapshot.
4.1.3 Device and Usage Data: We may also collect information on how the Service and Website are accessed and used ("Usage Data"). This Usage Data may include information such as your computer's or device IP address, device ID number, browser type or version, which Service pages you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.
5. How we use the personal data
5.1 Performing our Services: your receipt snapshots and any usage data of any mobile application provided by you, are used to perform our Services (i.e. receipt analysis, processing etc.). Furthermore, we may provide our customers whose receipts were uploaded by you with your Personal Data.
5.2 Access and Use: Any Personal Data provided to us by you in order to obtain access to any functionality of our services may be used by us in order to provide you with access to the needed functionality and to monitor your use of such functionality.
5.4 Specific Purpose: If you provide Personal Data for a specific purpose, OurCart may use said Personal Data in connection with the purpose for which it was provided. For instance, if you contact OurCart by email, we will use the Personal Data you provide to answer your question or resolve your problem and will respond to the email address used to contact us. ; or if you upload a receipt for which you may be entitled to certain benefits or credits from one or more of our customers, we will share your Personal Data with such customers.
5.5 Marketing: We may use any Personal Data you provide us with to contact you in the future for our marketing and advertising purposes, including, without limitation, to inform you about new services we believe might be of interest to you, and to develop promotional or marketing materials and provide those materials to you.
IF YOU RECEIVE DIRECT MARKETING BY MISTAKE OR WITHOUT YOUR SPECIFIC CONSENT AND/OR YOU WISH TO OPT-OUT, YOU ARE REQUIRED TO CONTACT US AT: email@example.com.
5.6 Statistics: We may use any Personal Data you provide us with to generate statistical reports containing aggregated information, , which may also sell to third party. We may also share or market aggregated data, including data derived from your usage and your Personal data, for market research purposes.
5.7 Security and Dispute Resolution: We may use Personal Data to protect the security of our Website and Services, to detect and prevent cyber attacks, fraud, phishing, identity theft, and data leaks, to verify genuine software licenses, to resolve disputes, and to enforce our agreements.
5.10 Cloud Services: We may need to share Personal Data with our cloud service. For example, assist in protecting and securing our Website or Services the cloud service admin may need access to Personal Data to provide those functions. In such cases, the cloud service provider must abide by our data privacy and security requirements and is not allowed to use Personal Data they receive from us for any other purpose.
5.11 Development and Customer Service: For example, to provide customer service and support or assist in protecting and securing our systems and services our development and customer service team may require access to Personal Data. In such cases, our personnel must abide by our data privacy and security requirements and policy and are not allowed to use Personal Data for any other purpose.
5.13 Law Enforcement: In order to, for example, respond to a subpoena or request from law enforcement, a court or a government agency (including in response to public authorities to meet national security or enforcement requirements), or in the good faith belief that such action is necessary to (a) comply with a legal obligation, (b) protect or defend our rights, interests or property or that of third parties, (c) prevent or investigate possible wrongdoing in connection with the Services, (d) act in urgent circumstances to protect the personal safety of Users of the Website and Services or the public, or (e) protect against legal liability.
IF YOU HAVE A REASONABLE BASIS TO ASSUME OR YOU KNOW THAT ANY OF THE ABOVE MENTIONED IS NOT MET, YOU ARE REQUIRED TO PROMPTLY INFORM US, WITHOUT DELAY, BY SENDING US AN EMAIL TO: firstname.lastname@example.org.
5.15 Non-Personal Data: Since Non-Personal Data cannot be used to identify you in person, we may use such data in any way permitted by law.
6. How We Store and Transfer Information
6.1 We have no intention to transfer data to third-party countries. Therefore, we try to store Personal data at the same region where it was collected:
6.1.1 Where Personal Data is collected within the EU jurisdiction, we store the data including its backups at AWS-UK region.
6.1.2 Where Personal Data is collected outside the EU jurisdiction and/or the data process by suppliers outside the EU jurisdiction, we store the collected or received data including its backups at AWS-US cloud services in us- east region.
6.1.3 The Amazon Cloud Services is comply with the GDPR and is ISO 27001, 27017,27018 certified (for AWS full statement see https://aws.amazon.com/blogs/security/all-aws-services-gdpr-ready/).
6.1.4 Furthermore, AWS is certified under the EU-US Privacy Shield (For more information see: https://aws.amazon.com/compliance/eu-us-privacy-shield-faq/).
6.2 To deliver our services and/or operate our business, Information, which may include Personal Data, may be processed by our third-party service providers (“Suppliers”) (e.g. business analytic tools, Customer Service Software & Support Ticket System, Goods providers, Survey conducting services, Image analysis providers etc.). We transfer only the minimum data that is necessary for conducting our services. The data is transferred only to Suppliers approved by us that allow compliance with GDPR or other local privacy laws.
6.3 Personal Data may be transferred, stored, and processed in countries outside the EU or European Economic Area (EEA). Such transfer to third-party countries may include countries that do not guarantee an adequate level of data protection laws as required under EU privacy laws. We implement a high level of information security techniques and technical measures and/or third-party contractual obligations to ensure that their information security level matches that implemented by us.
6.4 We may transfer Personal Data to Israel – where we maintain our headquarters. The EU considers Israel to have an adequate data protection law.
7. Personal Data Security
7.1 We are strongly committed to protecting your Personal Data and information, and we will take reasonable technical steps, accepted in our industry, to keep your Information secure and protect it against loss, misuse or modification. However, no network, server, database or Internet or email transmission is ever fully secure or error-free. Therefore, you should take special care in deciding what information you disclose.
7.2 If you notice any security risks or violations, we advise you to report them to us at: email@example.com so that we may resolve them as soon as possible.
7.3 We recommend that you use, disclose and share your Personal Data and information with caution and do not give out Personal Data and information unless it is necessary, as we cannot guarantee the security of data over the internet and cannot control the actions of other users of the Services with whom you choose to share Personal Data and information.
8. California Privacy Rights
The California Consumer Privacy Act of 2018 (“CCPA”) permits users who are California residents to request to exercise certain rights. The CCPA distinguishes between two main roles for companies involved in the processing of Personal Data:
a. Business (similar to ‘controller’ under the GDPR).
b. Service Provider (similar to ‘processor’ under the GDPR).
The CCPA imposes various obligations on ‘Businesses’ as well as sets forth limitations on the ‘sale’ of Personal Data. In particular, you can request from a customer who is a ‘Business’ under the CCPA to receive information on the following:
The categories and specific pieces of your Personal Data that was collected.
The categories of sources from which your Personal Data was collected.
The business or commercial purposes for which your Personal Data is collected.
The categories of third parties with which your Personal Data is shared.
Our Service provides, enables customers to facilitate incentives for their brands. Where Ourcart’s customers are considered ‘Businesses’ and are subject to the CCPA, Ourcart may be considered a Service Provider. Ourcart will therefore comply with the obligations imposed on Service Providers and will follow customers’ instructions to facilitate their compliance with the CCPA.
We can assure you that will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
Deny you goods or services.
Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
Provide you with a different level or quality of goods or services.
Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
9. Accessing, Updating, Correcting, and Deleting Information, Restricting Information Processing, and Lodging a Complaint with a Supervisory Authority
9.1 You may have the right to request access to some of your Personal Data being stored by us. You can also ask to correct, update or delete any inaccurate Personal Data that we process about you. The foregoing is subject to our policies and the applicable laws and regulations. To exercise these rights, you can contact us at: firstname.lastname@example.org.
9.2 We may retain your Personal Data for any period permitted or required under applicable laws. Even if we delete your Personal Data it may remain stored on backup or archival media for an additional period due to technical issues or for legal, tax or regulatory reasons, or for legitimate and lawful business purposes.
9.3 You may have the right to restrict processing if one of the following applies:
8.3.1 The accuracy of the Personal Data is contested by the data owner;
8.3.2 The processing is unlawful and the data owner objects to having their Personal Data erased, instead requesting that its use be restricted;
8.3.3 Your service provider no longer needs the Personal Data for the purposes of the original processing, but the data is required by the data owner for establishing, exercising or defending legal claims;
8.3.4 The data owner has objected to processing pending verification of whether the legitimate grounds of your service provider override those of the data owner.
IF YOU WISH TO OBJECT TO PROCESSING, YOU ARE REQUIRED TO CONTACT US AT: email@example.com.
9.4 You may have the right to lodge a complaint with a supervisory authority. However, prior to doing so, you are welcome to contact us by email at: firstname.lastname@example.org_ in order to resolve the issue for the benefit of all parties. Our supervisory authority is the Israeli Data Protection Authority.
11. Change in Terms and Conditions
12. Dispute Resolution
12.1 If you have a complaint about OurCart’s privacy practices, you should write to us at: email@example.com. We will take reasonable steps to work with you to attempt to resolve your complaint.
Representation for data subjects in the EU or in the UK:
We value your privacy and your rights as a data subject and have therefore appointed Prighter as our privacy representative and your point of contact.
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative Prighter or make use of your data subject rights, please visit: https://prighter.com/q/12054331