- Privacy Policy of www.sydneybamboo.com.au
- Sydney Bamboo Privacy Policy
- Owner and Data Controller
- Types of Data collected
- Place
- Retention time
- The rights of Users
- Details about the right to object to processing
- How to exercise these rights
- Applicability of broader protection standards
- Additional information about Data collection and processing
- Legal action
- Additional information about User's Personal Data
- System logs and maintenance
- Information not contained in this policy
- How “Do Not Track” requests are handled
- Changes to this privacy policy
- Notice at collection
- What are the purposes for which we use your personal information?
- How long do we keep your personal information?
- How we collect information: what are the sources of the personal information we collect?
- How we use the information we collect: disclosing of your personal information with third parties for a business purpose
- No sale of your personal information
- The right to request the deletion of your personal information
- The right to correct inaccurate personal information
- The right to opt out of sale or sharing of personal information and to limit the use of your sensitive personal information
- The right of no retaliation following opt-out or exercise of other rights (the right to non-discrimination)
- How to exercise your rights
- How and when we are expected to handle your request
- Categories of personal data processed
- Categories of personal data we collect
- Why we process your personal data
- How we use the data we collect: sharing of your personal data with third parties
- Sale of your personal data
- Processing of your personal data for targeted advertising
- How to exercise your rights
- How and when we are expected to handle your request
- The grounds on which we process your personal information
- Categories of personal information processed
- Why we process your personal information
- How to file your request
- How and when we will respond to your request
- Definitions and legal references
- Personal Data (or Data)
- Usage Data
- User
- Data Subject
- Data Processor (or Data Supervisor)
- Data Controller (or Owner)
- This Application
- Service
- European Union (or EU)
- Legal information
- Stripe Privacy Statement
- Definitions and legal references
- What Personally Identifiable Information is collected?
- Retention time
- How does the Website use Personally Identifiable Information?
- Stripe’s updated Privacy Policy will be effective as of January 24, 2023
- Welcome
- 1. Personal Data that we collect and how we use and share it
- 2. More ways we collect, use and share Personal Data
- 3. Legal bases for processing data
- 4. Your rights and choices
- 5. Security and retention
- 6. International data transfers
- 7. Updates and notifications
- 8. Jurisdiction-specific provisions
- 9. Contact us
- PayPal Privacy Statement
- Cookie Policy What Are Cookies
While you visit our site, we’ll track:
- Products you’ve viewed: we’ll use this to, for example, show you products you’ve recently viewed
- Location, IP address and browser type: we’ll use this for purposes like estimating taxes and shipping
- Shipping address: we’ll ask you to enter this so we can, for instance, estimate shipping before you place an order, and send you the order!
We’ll also use cookies to keep track of cart contents while you’re browsing our site.
When you purchase from us, we’ll ask you to provide information including your name, billing address, shipping address, email address, phone number, credit card/payment details and optional account information like username and password. We’ll use this information for purposes, such as, to:
Privacy Policy of www.sydneybamboo.com.au
Sydney Bamboo Privacy Policy
We collect information about you during the checkout process on our store.
Where is the data collected by your plugins stored?
We do not store any data fetched by our plugins on our servers, neither we share that data with any third party. Our plugins run absolutely on your website and store the data in the database of your website.
Do your plugins load any external scripts?
As mentioned before, our plugins run absolutely from your website and hence load the scripts too from your website with exception of third-party embedded widgets (like Facebook Like/Recommend official button, Twitter tweet official button, Facebook Comments) which require our plugin to load scripts from the servers of relevant service. You can include relevant snippets in the Privacy Policy of your website stating how these services handle privacy of your users.
GDPR Privacy Policy Snippets
We collect your public profile data only from your consent that you grant before initiating Social Login, from the social network used to login at our website. This data includes your first name, last name, email address, link to your social media profile, unique identifier, link to social profile avatar or the social profile avatar itself in the case of Facebook and Linkedin login. This data is used to create your user profile at our website. You can revoke this consent at any time from your profile page at our website or by sending us an email.
We collect your public profile data only from your consent that you grant before initiating Social Login, from the social network used to login at our website. This data includes your first name, last name, email address, link to your social media profile, unique identifier, link to social profile avatar. This data is used to create your user profile at our website. You can revoke this consent at any time from your profile page at our website or by sending us an email.
If you are using Heateor Login plugin, you can add following in the privacy policy of your website:
We collect your public profile data only from your consent that you grant before initiating Facebook Login, from the social network used to login at our website. This data includes your first name, last name, email address, unique identifier, link to social profile avatar. This data is used to create your user profile at our website. You can revoke this consent at any time from your profile page at our website or by sending us an email.
Facebook Comments
If you are using Facebook Comments feature of any of our plugin, you can add following in the privacy policy of your website:
We embed Facebook Comments plugin to allow you to leave comment at our website using your Facebook account. This plugin may collect your IP address, your web browser User Agent, store and retrieve cookies on your browser, embed additional tracking, and monitor your interaction with the commenting interface, including correlating your Facebook account with whatever action you take within the interface (such as “liking” someone’s comment, replying to other comments), if you are logged into Facebook. For more information about how this data may be used, please see Facebook’s data privacy policy: https://www.facebook.com/about/privacy/update
GooglePlus Comments
If you are using GooglePlus Comments feature of any of our plugin, you can add following in the privacy policy of your website:
We use GooglePlus Comments widget at our website for you to be able to comment at our webpages using your GooglePlus account. From this interaction Google automatically collects and store certain information in server logs like IP address, device event information such as crashes, system activity, hardware settings, browser type, browser language, the date and time of your request, in accordance with their data privacy policy: https://policies.google.com/privacy
Disqus Comments
If you are using Disqus Comments feature of any of our plugin, you can add following in the privacy policy of your website:
We use Disqus Comments widget at our website for you to be able to comment at our webpages using Disqus commenting system. Disqus may collect information about you when you register for and use the Service. Such information may include “Personally Identifiable Information” which means information that identifies you as an individual, such information may include, but is not limited to, your name, email address, telephone number, username or account ID, and “Non-Personally Identifiable Information” which means information that does not identify you as an individual. Non-Personally Identifiable Information may include, but is not limited to, information about your browser, your IP address, device ID, what pages you visit on our Partner Sites, which website you came from, what advertisements you clicked on, whether on our Partner Websites, the Service or other third party websites, and other information about your online activity that does not identify you as an individual, in accordance with their data privacy policy: https://help.disqus.com/terms-and-policies/disqus-privacy-policy
Fancy Facebook Comments Pro
If you are using Fancy Facebook Comments Pro plugin at your website and you have saved Facebook App ID and Facebook App Secret in the Moderation section, you can add following in the privacy policy of your website after enabling the GDPR opt-in from GDPR section:
We collect the data related to the Facebook Comment you post, only from your consent that you grant before posting Facebook Comment at our website. This data includes your Facebook account name, unique Facebook account identifier, unique identifier associated to the posted Facebook comment, unique open graph object identifier of the webpage at which you posted the comment, unique identifier associated to the parent comment if you reply to an existing comment. This data is used to show recent Facebook Comments made all over our website. You can revoke this consent at any time by unchecking the opt-in displayed above comment box
If you have enabled email notification from the Notification section, you can add following in the privacy policy of your website after enabling the GDPR opt-in from GDPR section:
We send the Facebook Comment you post, to page/post author and/or website administrator via automated email, only from your consent that you grant before posting Facebook Comment at our website. This data includes just the Facebook comment posted by you. You can revoke this consent at any time by unchecking the opt-in displayed above comment box
Facebook Comments Moderation
If you are using Facebook Comments Moderation add-on at your website and you have saved Facebook App ID and Facebook App Secret, you can add following in the privacy policy of your website after enabling the GDPR opt-in from GDPR section at add-on options page:
We collect the data related to the Facebook Comment you post, only from your consent that you grant before posting Facebook Comment at our website. This data includes your Facebook account name, unique Facebook account identifier, unique identifier associated to the posted Facebook comment, unique open graph object identifier of the webpage at which you posted the comment, unique identifier associated to the parent comment if you reply to an existing comment. This data is used to show recent Facebook Comments made all over our website. You can revoke this consent at any time by unchecking the opt-in displayed above comment box
Facebook Comments Notifier
If you are using our Facebook Comments Notifier add-on at your website, you can add following in the privacy policy of your website after enabling the GDPR opt-in from GDPR section at add-on options page:
We send the Facebook Comment you post, to page/post author and/or website administrator via automated email, only from your consent that you grant before posting Facebook Comment at our website. This data includes just the Facebook comment posted by you. You can revoke this consent at any time by unchecking the opt-in displayed above comment box
Social Analytics for Sharing
If you are using our Social Analytics for Sharing add-on at your website, you can add following in the privacy policy of your website:
We use Google Analytics to track social shares made at our website. Google automatically collect and store certain information in their server logs which includes device event information such as crashes, system activity, hardware settings, browser type, browser language, the date and time of your request and referral URL, cookies that may uniquely identify your browser or your Google Account, in accordance with their data privacy policy: https://policies.google.com/privacy
Facebook Like, Facebook Recommend, Facebook Share official buttons
If you are using social sharing feature of our plugins and you have enabled any of these official buttons, you can add following in the privacy policy of your website:
We embed a Facebook widget to allow you to see number of likes/shares/recommends and “like/share/recommend” our webpages. This widget may collect your IP address, your web browser User Agent, store and retrieve cookies on your browser, embed additional tracking, and monitor your interaction with the widget, including correlating your Facebook account with whatever action you take within the widget (such as “liking/sharing/recommending” our webpage), if you are logged in to Facebook. For more information about how this data may be used, please see Facebook’s data privacy policy: https://www.facebook.com/about/privacy/update
Twitter Tweet official button
If you are using social sharing feature of our plugins and you have enabled Twitter Tweet official button, you can add following in the privacy policy of your website:
We use a Twitter Tweet widget at our website. As a result, our website makes requests to Twitter’s servers for you to be able to tweet our webpages using your Twitter account. These requests make your IP address visible to Twitter, who may use it in accordance with their data privacy policy: https://twitter.com/en/privacy#update
GooglePlus, GooglePlus Share official buttons
If you are using social sharing feature of our plugins and you have enabled any of these official buttons, you can add following in the privacy policy of your website:
We use a GooglePlus widget at our website. As a result, our website makes requests to Google’s servers for you to be able to share our webpages using your GooglePlus account. These requests make your IP address visible to Google, who may use it in accordance with their data privacy policy: https://policies.google.com/privacy
Linkedin Share official button
If you are using social sharing feature of our plugins and you have enabled Linkedin Share official button, you can add following in the privacy policy of your website:
We use a Linkedin Share widget at our website to allow you to share our webpages on Linkedin. These requests may track your IP address in accordance with their data privacy policy: https://www.linkedin.com/legal/privacy-policy
Pinterest Save official button
If you are using social sharing feature of our plugins and you have enabled Pinterest Save official button, you can add following in the privacy policy of your website:
We use Pinterest Save widget at our website to allow you to pin images to Pinterest from our webpages. These requests may track your IP address in accordance with their data privacy policy: https://policy.pinterest.com/en/privacy-policy
Buffer official button
If you are using social sharing feature of our plugins and you have enabled Buffer official button, you can add following in the privacy policy of your website:
We use Buffer widget at our website to allow you to add our webpages to your Buffer account, which collects log data from your browser. This Log Data may include information such as your IP address, browser type or the domain at which you are interacting with the widget, in accordance with their privacy policy: https://buffer.com/privacy
Xing Share official button
If you are using social sharing feature of our plugins and you have enabled Xing Share official button, you can add following in the privacy policy of your website:
We use Xing Share widget at our website to allow you to share our webpages on Xing and this let Xing collate data about you automatically by means of tracking, in accordance with their privacy policy: https://privacy.xing.com/en/privacy-policy
Reddit Badge official button
If you are using social sharing feature of our plugins and you have enabled Reddit Badge official button, you can add following in the privacy policy of your website:
We use Reddit Badge widget at our website which may log information when you interact with the widget. This may include your IP address, user-agent string, browser type, operating system, referral URLs, device information (e.g., device IDs), pages visited, links clicked, user interactions (e.g., voting data), the requested URL and hardware settings, in accordance with their privacy policy: https://www.redditinc.com/policies/privacy-policy
StumbleUpon Badge official button
If you are using social sharing feature of our plugins and you have enabled StumbleUpon Badge official button, you can add following in the privacy policy of your website:
We use StumbleUpon Badge widget at our website which may log information when you interact with the widget. Log Data is a form of Non-Identifying Information, in accordance with their privacy policy: http://www.stumbleupon.com/privacy
Note: If you are using just the round, square social share icons that can be customized from the Theme Selection section at social share options page, you don’t need to include any privacy policy snippet regarding these in the privacy policy of your website
What we collect and store
- Send you information about your account and order
- Respond to your requests, including refunds and complaints
- Process payments and prevent fraud
- Set up your account for our store
- Comply with any legal obligations we have, such as calculating taxes
- Improve our store offerings
- Send you marketing messages, if you choose to receive them
If you create an account, we will store your name, address, email and phone number, which will be used to populate the checkout for future orders.
We generally store information about you for as long as we need the information for the purposes for which we collect and use it, and we are not legally required to continue to keep it. For example, we will store order information for XXX years for tax and accounting purposes. This includes your name, email address and billing and shipping addresses.
We will also store comments or reviews, if you choose to leave them.
Who on our team has access
Members of our team have access to the information you provide us. For example, both Administrators and Shop Managers can access:
- Order information like what was purchased, when it was purchased and where it should be sent, and
- Customer information like your name, email address, and billing and shipping information.
Our team members have access to this information to help fulfil orders, process refunds and support you.
What we share with others
We share information with third parties who help us provide our orders and store services to you; for example —
Payments
We accept payments through PayPal. When processing payments, some of your data will be passed to PayPal, including information required to process or support the payment, such as the purchase total and billing information.
Please see the PayPal Privacy Policy for more details.
In order to receive information about your Personal Data, the purposes and the parties the Data is shared with, contact the Owner.
Owner and Data Controller
For more information about the owner, contact the following email address:
Owner contact email: sales@sydneybamboo.com.au
Types of Data collected
The owner does not provide a list of Personal Data types collected.
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application.
Unless specified otherwise, all Data requested by this Application is mandatory and failure to provide this Data may make it impossible for this Application to provide its services. In cases where this Application specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Any use of Cookies – or of other tracking tools – by this Application or by the owners of third-party services used by this Application serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy, if available.
Users are responsible for any third-party Personal Data obtained, published or shared through this Application and confirm that they have the third party’s consent to provide the Data to the Owner.
Mode and place of processing the Data
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
The Owner may process Personal Data relating to Users if one of the following applies:
Legal basis of processing
- provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
- processing is necessary for compliance with a legal obligation to which the Owner is subject;
- processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
- processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Place
The Data is processed at the Owner’s operating offices and in any other places where the parties involved in the processing are located.
Depending on the User’s location, data transfers may involve transferring the User’s Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Retention time
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
Therefore:
- Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
- Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
The rights of Users
Users may exercise certain rights regarding their Data processed by the Owner.
Users entitled to broader protection standards may exercise any of the rights described below. In all other cases, Users may inquire with the Owner to find out which rights apply to them.
In particular, Users have the right to do the following:
- Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
- Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent. Further details are provided in the dedicated section below.
- Access their Data. Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
- Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
- Restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
- Have their Personal Data deleted or otherwise removed. Users have the right, under certain circumstances, to obtain the erasure of their Data from the Owner.
- Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the Data is processed by automated means and that the processing is based on the User’s consent, on a contract which the User is part of or on pre-contractual obligations thereof.
- Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.
Details about the right to object to processing
Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Owner or for the purposes of the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time without providing any justification. To learn, whether the Owner is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to exercise these rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. These requests can be exercised free of charge and will be addressed by the Owner as early as possible and always within one month.
Applicability of broader protection standards
While most provisions of this document concern all Users, some provisions expressly only apply if the processing of Personal Data is subject to broader protection standards.
Such broader protection standards apply when the processing:
- is performed by an Owner based within the EU;
- concerns the Personal Data of Users who are in the EU and is related to the offering of paid or unpaid goods or services, to such Users;
- concerns the Personal Data of Users who are in the EU and allows the Owner to monitor such Users’ behavior taking place in the EU.
Additional information about Data collection and processing
Legal action
The User’s Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services.
The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
Additional information about User’s Personal Data
In addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.
System logs and maintenance
For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) use other Personal Data (such as the IP Address) for this purpose.
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
How “Do Not Track” requests are handled
This Application does not support “Do Not Track” requests.
To determine whether any of the third-party services it uses honor the “Do Not Track” requests, please read their privacy policies.
Changes to this privacy policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application and/or – as far as technically and legally feasible – sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User’s consent, the Owner shall collect new consent from the User, where required.
Notice at collection
Categories of personal information collected, used, sold, or shared
In this section we summarize the categories of personal information that we’ve collected, used, sold, or shared and the purposes thereof. You can read about these activities in detail in the section titled “Detailed information on the processing of Personal Data” within this document.
Information we collect: the categories of personal information we collect
We have collected the following categories of personal information about you: .
We do not collect sensitive personal information.
We will not collect additional categories of personal information without notifying you.
What are the purposes for which we use your personal information?
We may use your personal information to allow the operational functioning of this Application and features thereof (“business purposes”). In such cases, your personal information will be processed in a fashion necessary and proportionate to the business purpose for which it was collected, and strictly within the limits of compatible operational purposes.
We may also use your personal information for other reasons such as for commercial purposes (as indicated within the section “Detailed information on the processing of Personal Data” within this document), as well as for complying with the law and defending our rights before the competent authorities where our rights and interests are threatened or we suffer an actual damage.
We won’t process your information for unexpected purposes, or for purposes incompatible with the purposes originally disclosed, without your consent.
How long do we keep your personal information?
Unless stated otherwise inside the “Detailed information on the processing of Personal Data” section, we will not retain your personal information for longer than is reasonably necessary for the purpose(s) they have been collected for.
How we collect information: what are the sources of the personal information we collect?
We collect the above-mentioned categories of personal information, either directly or indirectly, from you when you use this Application.
For example, you directly provide your personal information when you submit requests via any forms on this Application. You also provide personal information indirectly when you navigate this Application, as personal information about you is automatically observed and collected.
How we use the information we collect: disclosing of your personal information with third parties for a business purpose
We do not disclose your personal information to third parties. For our purposes, the word “third party” means “a person who is not any of the following: a service provider or a contractor, as defined by the CCPA.
No sale of your personal information
We do not sell or share your personal information. In case we should decide to, we will inform you beforehand and will grant your right to opt out of such a sale.
The right to request the deletion of your personal information
You have the right to request that we delete any of your personal information, subject to exceptions set forth by the law (such as, including but not limited to, where the information is used to identify and repair errors on this Application, to detect security incidents and protect against fraudulent or illegal activities, to exercise certain rights etc.).
If no legal exception applies, as a result of exercising your right, we will delete your personal information and notify any of our service providers and all third parties to whom we have sold or shared the personal information to do so – provided that this is technically feasible and doesn’t involve disproportionate effort.
The right to correct inaccurate personal information
You have the right to request that we correct any inaccurate personal information we maintain about you, taking into account the nature of the personal information and the purposes of the processing of the personal information.
The right to opt out of sale or sharing of personal information and to limit the use of your sensitive personal information
You have the right to opt out of the sale or sharing of your personal information. You also have the right to request that we limit our use or disclosure of your sensitive personal information.
The right of no retaliation following opt-out or exercise of other rights (the right to non-discrimination)
We will not discriminate against you for exercising your rights under the CCPA. This means that we will not discriminate against you, including, but not limited to, by denying goods or services, charging you a different price, or providing a different level or quality of goods or services just because you exercised your consumer privacy rights.
However, if you refuse to provide your personal information to us or ask us to delete or stop selling your personal information, and that personal information or sale is necessary for us to provide you with goods or services, we may not be able to complete that transaction.
To the extent permitted by the law, we may offer you promotions, discounts, and other deals in exchange for collecting, keeping, or selling your personal information, provided that the financial incentive offered is reasonably related to the value of your personal information.
How to exercise your rights
To exercise the rights described above, you need to submit your verifiable request to us by contacting us via the details provided in this document.
For us to respond to your request, it’s necessary that we know who you are. Therefore, you can only exercise the above rights by making a verifiable request which must:
- provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative;
- describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We will not respond to any request if we are unable to verify your identity and therefore confirm the personal information in our possession actually relates to you.
Making a verifiable consumer request does not require you to create an account with us. We will use any personal information collected from you in connection with the verification of your request solely for the purposes of verification and shall not further disclose the personal information, retain it longer than necessary for purposes of verification, or use it for unrelated purposes.
If you cannot personally submit a verifiable request, you can authorize a person registered with the California Secretary of State to act on your behalf.
If you are an adult, you can make a verifiable request on behalf of a minor under your parental authority.
You can submit a maximum number of 2 requests over a period of 12 months.
How and when we are expected to handle your request
We will confirm receipt of your verifiable request within 10 days and provide information about how we will process your request.
We will respond to your request within 45 days of its receipt. Should we need more time, we will explain to you the reasons why, and how much more time we need. In this regard, please note that we may take up to 90 days to fulfill your request.
Our disclosure(s) will cover the preceding 12-month period. Only with regard to personal information collected on or after January 1, 2022, you have the right to request that we disclose information beyond the 12-month period, and we will provide them to you unless doing so proves impossible or would involve a disproportionate effort.
Should we deny your request, we will explain you the reasons behind our denial.
We do not charge a fee to process or respond to your verifiable request unless such request is manifestly unfounded or excessive. In such cases, we may charge a reasonable fee, or refuse to act on the request. In either case, we will communicate our choices and explain the reasons behind it.
Categories of personal data processed
In this section, we summarize the categories of personal data that we’ve processed and the purposes thereof. You can read about these activities in detail in the section titled “Detailed information on the processing of Persona Data” within this document.
Categories of personal data we collect
We have collected the following categories of personal data:
We do not collect sensitive data.
We will not collect additional categories of personal data without notifying you.
Why we process your personal data
To find out why we process your personal data, you can read the sections titled “Detailed information on the processing of Personal Data” and “The purposes of processing” within this document.
We won’t process your information for unexpected purposes, or for purposes incompatible with the purposes originally disclosed, without your consent.
You can freely give, deny, or withdraw such consent at any time using the contact details provided in this document.
How we use the data we collect: sharing of your personal data with third parties
We do not share nor disclose your personal data with third parties.
For our purposes, the word “third party” means “a natural or legal person, public authority, agency, or body other than the consumer, controller, processor, or an affiliate of the processor or the controller” as defined by the VCDPA.
Sale of your personal data
We do not sell your personal data. In case we should decide to, we will inform you beforehand and will grant your right to opt out of such a sale.
Processing of your personal data for targeted advertising
We do not process your personal data for targeted advertising. If we decide to do so, we will inform you beforehand and will grant your right to opt out of the processing of your personal data for targeted advertising.
How to exercise your rights
To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.
For us to respond to your request, we need to know who you are.
We will not respond to any request if we are unable to verify your identity using commercially reasonable efforts and therefore confirm that the personal data in our possession actually relates to you. In such cases, we may request that you provide additional information which is reasonably necessary to authenticate you and your request.
Making a consumer request does not require you to create an account with us. However, we may require you to use your existing account. We will use any personal data collected from you in connection with your request solely for the purposes of authentication, without further disclosing the personal data, retaining it longer than necessary for purposes of authentication, or using it for unrelated purposes.
If you are an adult, you can make a request on behalf of a minor under your parental authority.
How and when we are expected to handle your request
We will respond to your request without undue delay, but in all cases and at the latest within 45 days of its receipt. Should we need more time, we will explain to you the reasons why, and how much more time we need. In this regard, please note that we may take up to 90 days to fulfill your request.
Should we deny your request, we will explain to you the reasons behind our denial without undue delay, but in all cases and at the latest within 45 days of receipt of the request. It is your right to appeal such decision by submitting a request to us via the details provided in this document. Within 60 days of receipt of the appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied you may contact the Attorney General to submit a complaint.
We do not charge a fee to respond to your request, for up to two requests per year. If your request is manifestly unfounded, excessive or repetitive, we may charge a reasonable fee or refuse to act on the request. In either case, we will communicate our choices and explain the reasons behind them.
The grounds on which we process your personal information
We can process your personal information solely if we have a legal basis for such processing. Legal bases are as follows:
- your consent to the relevant processing activities;
- compliance with a legal or regulatory obligation that lies with us;
- the carrying out of public policies provided in laws or regulations or based on contracts, agreements and similar legal instruments;
- studies conducted by research entities, preferably carried out on anonymized personal information;
- the carrying out of a contract and its preliminary procedures, in cases where you are a party to said contract;
- the exercising of our rights in judicial, administrative or arbitration procedures;
- protection or physical safety of yourself or a third party;
- the protection of health – in procedures carried out by health entities or professionals;
- our legitimate interests, provided that your fundamental rights and liberties do not prevail over such interests; and
- credit protection.
To find out more about the legal bases, you can contact us at any time using the contact details provided in this document.
Categories of personal information processed
To find out what categories of your personal information are processed, you can read the section titled “Detailed information on the processing of Personal Data” within this document.
Why we process your personal information
To find out why we process your personal information, you can read the sections titled “Detailed information on the processing of Personal Data” and “The purposes of processing” within this document.
How to file your request
You can file your express request to exercise your rights free from any charge, at any time, by using the contact details provided in this document, or via your legal representative.
How and when we will respond to your request
We will strive to promptly respond to your requests.
In any case, should it be impossible for us to do so, we’ll make sure to communicate to you the factual or legal reasons that prevent us from immediately, or otherwise ever, complying with your requests. In cases where we are not processing your personal information, we will indicate to you the physical or legal person to whom you should address your requests, if we are in the position to do so.
In the event that you file an access or personal information processing confirmation request, please make sure that you specify whether you’d like your personal information to be delivered in electronic or printed form.
You will also need to let us know whether you want us to answer your request immediately, in which case we will answer in a simplified fashion, or if you need a complete disclosure instead.
In the latter case, we’ll respond within 15 days from the time of your request, providing you with all the information on the origin of your personal information, confirmation on whether or not records exist, any criteria used for the processing and the purposes of the processing, while safeguarding our commercial and industrial secrets.
In the event that you file a rectification, deletion, anonymization or personal information blocking request, we will make sure to immediately communicate your request to other parties with whom we have shared your personal information in order to enable such third parties to also comply with your request – except in cases where such communication is proven impossible or involves disproportionate effort on our side.
Definitions and legal references
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Usage Data
Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
User
The individual using this Application who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Data Supervisor)
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.
This Application
The means by which the Personal Data of the User is collected and processed.
Service
The service provided by this Application as described in the relative terms (if available) and on this site/application.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Legal information
This privacy statement has been prepared based on provisions of multiple legislations, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation).
This privacy policy relates solely to this Application, if not stated otherwise within this document.
Stripe Privacy Statement
Definitions and legal references
This Website (or this Application)The property that enables the provision of the Service.Owner (or We)Sydney Bamboo – The natural person(s) or legal entity that provides this Website and/or the Service to Users.User (or You)The natural person or legal entity that uses this Website.ServiceThe service provided by this Website as described in these Terms and on this Website.Personally Identifiable InformationRefers to any information that identifies or can be used to identify, contact, or locate the person to whom such information pertains, including, but not limited to, name, address, phone number, fax number, email address, financial profiles, social security number, and credit card information. Personally Identifiable Information does not include information that is collected anonymously (that is, without identification of the individual user) or demographic information not connected to an identified individual.CookiesA cookie is a string of information that a website stores on a visitor’s computer, and that the visitor’s browser provides to the website each time the visitor returns.Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.Privacy Policy of Sydney BambooThis Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.This Application collects some Personal Data from its Users.Owner and Data ControllerSydney BambooOwner contact email:sales@sydneybamboo.com.au
What Personally Identifiable Information is collected?
We may collect basic user profile information from all of our Users. We collect the following additional information from our Users: that the User intends to purchase or sell.
Retention time
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
Therefore:
Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
How does the Website use Personally Identifiable Information?
We use Personally Identifiable Information to customize the Website, to make appropriate service offerings, and to fulfill buying and selling requests on the Website. We may email Users about research or purchase and selling opportunities on the Website or information related to the subject matter of the Website. We may also use Personally Identifiable Information to contact Users in response to specific inquiries, or to provide requested information.
We may also use your personal information for other reasons such as for commercial purposes (as indicated within the section “Detailed information on the processing of Personal Data” within this document), as well as for complying with the law and defending our rights before the competent authorities where our rights and interests are threatened or we suffer an actual damage.We will not use your personal information for different, unrelated, or incompatible purposes without notifying you.
How is Personally Identifiable Information stored?
Personally Identifiable Information collected by Sydney Bamboo is securely stored and is not accessible to third parties or employees of Sydney Bamboo except for use as indicated above.
What options are available to Users regarding collection, use and distribution of the information?
Users may opt out of receiving unsolicited information from or being contacted by us and/or our vendors and affiliated agencies by responding to emails as instructed, or by either :
How does Sydney Bamboo use login information?
Sydney Bamboo uses login information, including, but not limited to, IP addresses, ISPs, and browser types, to analyze trends, administer the Website, track a Users movement and use, and gather broad demographic information.
What partners or service providers have access to Personally Identifiable Information from Users on the Website?
Sydney Bamboo has entered into and will continue to enter into partnerships and other affiliations with a number of vendors. Such vendors may have access to certain Personally Identifiable Information on a need to know the basis for evaluating Users for service eligibility. Our privacy policy does not cover their collection or use of this information. Disclosure of Personally Identifiable Information to comply with the law. We will disclose Personally Identifiable Information in order to comply with a court order or subpoena or a request from a law enforcement agency to release information. We will also disclose Personally Identifiable Information when reasonably necessary to protect the safety of our Users.
How does the Website keep Personally Identifiable Information secure?
All of our employees are familiar with our security policy and practices. The Personally Identifiable Information of our Users is only accessible to a limited number of qualified employees who are given a password in order to gain access to the information. We audit our security systems and processes on a regular basis. Sensitive information, such as credit card numbers or social security numbers, is protected by encryption protocols, in place to protect information sent over the Internet. While we take commercially reasonable measures to maintain a secure site, electronic communications and databases are subject to errors, tampering, and break-ins, and we cannot guarantee or warrant that such events will not take place and we will not be liable to Users for any such occurrences.
How can Users correct any inaccuracies in Personally Identifiable Information?
Users may contact us to update Personally Identifiable Information about them or to correct any inaccuracies by either:
Can a User delete or deactivate Personally Identifiable Information collected by the Website?
We provide Users with a mechanism to delete/deactivate Personally Identifiable Information from the Website’s database by contacting. However, because of backups and records of deletions, it may be impossible to delete a Users entry without retaining some residual information. An individual who requests to have Personally Identifiable Information deactivated will have this information functionally deleted, and we will not sell, transfer, or use Personally Identifiable Information relating to that individual in any way moving forward.
User rights
These are summarized rights that you have under data protection law:
What happens if the Privacy Policy changes?
We will let our Users know about changes to our privacy policy by posting such changes on the Website. However, if we are changing our privacy policy in a manner that might cause disclosure of Personally Identifiable Information that a User has previously requested not be disclosed, we will contact such User to allow such User to prevent such disclosure.
Last Updated: December 22, 2022
Stripe’s updated Privacy Policy will be effective as of January 24, 2023
We’re updating our Privacy Policy to clearly explain how we collect and use data as we work to improve the Stripe experience.
Here’s a summary of key changes:
- We added more clarity about how our services use Personal Data.
- We clarified how we will use Personal Data for Stripe’s own marketing purposes to Visitors, End Users and Representatives.
- We updated the information on our legal bases for cross-border data transfers, including those between the EEA and US.
- We added more information about privacy rights that exist in some countries where Stripe offers services.
These are just a few highlights of the changes we made, so please read the updated Privacy Policy below carefully. If you have questions, please check out the rest of our Privacy Center and/or contact us.
Welcome
We provide financial infrastructure for the internet. People use our services to enable their purchases and businesses of all sizes use our technology and services to accept payments, send payouts, and manage their businesses online. Stripe wants to be clear about our use of the Personal Data that is entrusted to us.
This Privacy Policy (“Policy”) describes the “Personal Data” that we collect about you, how we use it, how we share it, your rights and choices, and how you can contact us about our privacy practices. This Policy also outlines your data subject rights, including the right to object to some uses of your Personal Data by us. Please visit the Stripe Privacy Center for more information about our privacy practices.
“Stripe”, “we”, “our” or “us” means the Stripe entity responsible for the collection and use of Personal Data under this Privacy Policy. It differs depending on your jurisdiction. Learn More.
“Personal Data” means any information that relates to an identified or identifiable individual, and can include information that you provide to us and that we collect about you, such as when you engage with our Services (e.g. device information, IP address).
“Services” means the products and services that Stripe indicates are covered by this Policy, which may include Stripe-provided devices and apps. Our “Business Services” are Services provided by Stripe to entities (“Business Users”) who directly and indirectly provide us with “End Customer” Personal Data in connection with those Business Users’ own business and activities. Our “End User Services” are those Services which Stripe provides directly to people (rather than entities) for their own use.
“Sites” means Stripe.com and the other websites, apps and online services that Stripe indicates are covered by this Policy. Collectively, we refer to Sites, Business Services and End User Services as “Services”.
Depending on the context, “you” means End Customer, End User, Representative or Visitor:
- When you directly use an End User Service for your personal use (such as when you sign up for Link, or make a payment to Stripe Climate in your personal capacity), we refer to you as an “End User.”
- When you do business with, or otherwise transact with, a Business User (e.g. when you buy a pair of shoes from a merchant that uses Stripe Checkout for payment processing) but are not directly doing business with Stripe, we refer to you as an “End Customer.”
- When you are acting on behalf of an existing or potential Business User (e.g. you are a founder of a company, administer an account for a merchant who is a Business User, or receive an employee credit card from a Business User using Stripe Issuing), we refer to you as a “Representative.”
- When you visit a Site without being logged into a Stripe account or otherwise communicate with Stripe, we refer to you as a “Visitor.” (e.g. you send Stripe a message asking for more information because you are considering being a user of our products).
Depending on the activity, Stripe acts as a “data controller” and/or “data processor (or service provider)”
1. Personal Data that we collect and how we use and share it
2. More ways we collect, use and share Personal Data
3. Legal bases for processing data
6. International data transfers
8. Jurisdiction-specific provisions
1. Personal Data that we collect and how we use and share it
Our collection and use of Personal Data changes depending on whether you are acting as End User, End Customer, Representative or Visitor and our different Services. For example, if you are the sole owner of a business (i.e., sole proprietorship), we may collect Personal Data to onboard your business, but you may also be an End Customer that purchased goods from another Business User that uses Stripe’s Services for payment processing and you may also be an End User who uses Link to make those purchases.
“Transaction Data” as used in this Privacy Policy includes Personal Data, and may include the following: your name, email address, billing address, shipping address, payment method information (such as credit or debit card number, bank account information or payment card image selected by you), merchant and location, purchase amount, date of purchase, and in some cases, some information about what you have purchased and your phone number and past purchases.
1.1 End Users
We provide End User Services where we do not act as a service provider or processor to Businesses but instead provide the Services directly to you for your personal use (e.g. Link). We provide more information about our collection, use and sharing of Personal Data in our Privacy Center, including the legal bases which we rely on for using (processing) your Personal Data.
a. Personal Data that we collect about End Users
- Using Link or Connecting your Bank Account. Stripe offers you the opportunity to store your payment methods with Stripe so that you can conveniently use it across merchants who are our Business Users (“Link” was formerly known as “Remember Me”). When you opt in to Link, you agree to let us store your Personal Data such as your payment method so that you can more readily make purchases through Link with Business Users of our payment processing Business Services (e.g. name, contact information, payment method details (e.g. card number, cvc, and expiration date)). When you choose to pay with Link, we will also collect Transaction Data related to your transactions. Learn More.
- If you choose to share bank account information (including for use in Link) with us, Stripe will periodically collect and process your account information (e.g. bank account owner information, account balances, account number and details, account transactions and, in some cases, credentials). With your separate permission, we will share this Personal Data with Business Users that you choose. You can ask us to stop collecting and sharing this information. Learn More.
- With your separate permission, we will share contact information (e.g. shipping address, billing address and phone number) with Business Users that you do business with.
- Paying Stripe. If you are buying goods or services directly from Stripe, we receive Transaction Data. For example, when you make a payment to Stripe Climate, we will collect contact information, payment method information, and information about that transaction.
- Identity/Verification Services. We provide an identity verification service that automates comparing an identity document with your image (e.g., selfie). You may choose to opt-in to allow us to store that verification for future use across other merchants and/or separately consent to letting us use your biometric data to improve our verification technology. You can also ask us to stop providing you these services. Learn More.
- More. Please see below for information about additional types of Personal Data that we may collect about End Users, including about your online activity and how you engage with our End User Services.
b. How we use and share Personal Data of End Users
- Services. We use your Personal Data to provide the End User Service to you, including security, sanctions screening, delivery, support, personalization (e.g. language preferences and settings choices) and messages related to the End User Service (e.g. communicating Policy updates and information about our Services). For example, we will use Personal Data to assess whether your use of Link to make a payment with a merchant is authorized by you (and not a bad actor) and likely to be successfully authorized by the payment method you choose to use when you choose to make purchases with Link.
- Our Business Users. When you choose to connect your financial account with Stripe you may also choose to share account information with Business Users that you do business with. These Business Users will have their own privacy policies which describe how they use that information.
- Transactions. For payment transactions with Link, End User Personal Data is shared with others to enable or “process” the transaction. For example, when you choose to use a payment method for the transaction with Stripe or with Link (e.g. credit card, debit card, buy now pay later, or direct debit), the third party provider of your payment method will receive Transaction Data that includes your Personal Data. When you use Link, the merchant you choose to do business with will also receive Transaction Data that includes your Personal Data and, with your separate consent, your bank account information. Please review the privacy policies of your payment method and the merchants who you choose to learn more about their processing of your Personal Data.
- Fraud Detection and Loss Prevention. We use your Personal Data collected across our Services (e.g. Stripe Radar) to detect fraud and prevent financial losses for you, us, and our Business Users and financial partners, including to detect unauthorized purchases. Learn More. We may provide Business Users and financial partners (including card issuers, payment methods and others involved in payment processing activities) that use our fraud Business Services with Personal Data about you (including your attempted transactions) so that they can assess the associated fraud or loss risk with a transaction. You can learn more about how we may use technology to assess the fraud risk associated with an attempted transaction and what information we share with Business Users here.
- Advertising. We may use your Personal Data to assess your eligibility for, and offer you, other End User Services or promote existing End User Services. Where allowed by law (including with your opt-in consent where required), we use and share End User Personal Data with others so that we may market our End User Services to you, including through interest-based advertising. See our Cookie Policy.
- We do not sell or share End User Personal Data with third parties for marketing or advertising their products without your separate consent.
- More. Please see below for information about additional ways in which we may use and share your Personal Data.
1.2 End Customers
Stripe offers Business Services to our Business Users (e.g. payment processing through in-person or online checkout, or processing pay-outs for those Business Users). When we are acting as a Business User’s service provider (also known as a data processor), we will process Personal Data in accordance with the terms of our agreement with the Business User and the Business User’s lawful instructions (e.g. when we process a payment for a Business User because you bought a product from them) or they instruct us to send funds to you.
Business Users are responsible for making sure that their End Customers’ privacy rights are respected, including ensuring appropriate disclosures about data collection and use that happens in connection with their products and services. If you are an End Customer, please refer to the privacy policy or notice of the Business User you choose to do business with for information regarding their privacy practices, choices and controls. We provide more information about our collection, use and sharing of Personal Data in our Privacy Center, including the legal bases which we rely on for using (processing) your Personal Data.
a. Personal Data that we collect about End Customers
- Transaction Data. If you are an End Customer, when you make payments to, get refunds from, begin a purchase, make a donation or otherwise transact with a Business User that uses us to provide payment processing Business Services, we will receive Transaction Data. We may also receive your transaction history with the Business User. Learn More. Moreover, we may obtain information typed into a checkout form, even if you choose not to complete the form or purchase with the Business User. Learn More.
- Identity/Verification Information. Stripe provides a verification and fraud prevention Service that allows a Business User to verify Personal Data about you, such as your age (when purchasing age restricted goods) or your authorization to use a payment method. As part of these Services, you will be asked to share Personal Data with us for this purpose (e.g., your government ID, your image (selfie), and Personal Data you input or that is apparent from the physical payment method (e.g. credit card image)). To protect against fraud, we may compare this information with information about you we collect from Business Users, financial partners, business partners, identity verification services, publicly available sources, and other third party service providers and sources so that we can assess whether the person is likely to be you or a person purporting to be you. Learn More.
- More. Please see below for information about additional types of Personal Data that we may collect, including your online activity.
b. How we use and share Personal Data of End Customers
To provide our Business Services to our Business Users, we use Personal Data, and share Personal Data of a Business User’s End Customers with the Business User. Where allowed, we also use End Customers’ Personal Data for Stripe’s own purposes to secure, improve and provide our Business Services and prevent fraud, loss and other harms as described below.
- Payments and Accounting. We use your Transaction Data to provide our Payments related Business Services to Business Users, including to process online payment transactions, to calculate applicable sales tax, to invoice and bill, and to help them calculate their revenue, pay their bills and perform accounting tasks. Learn More. We may also use Personal Data to provide and improve our Business Services.
- For payment transactions, your Personal Data is shared with a number of parties in connection with your transaction. Because we act as a service provider or processor, we share Personal Data to enable the transaction. For example, when you choose to use a payment method for the transaction (e.g. credit card, debit card, buy now pay later, or direct debit), your payment method will receive the Transaction Data that includes your Personal Data. Please review your payment method’s privacy policy to learn more about how they use and share this information.
- The merchant you choose to do business with will also receive Transaction Data that includes your Personal Data and the merchant may share that Personal Data with others. Please review your merchant’s privacy policy to learn more.
- Financial Services. Some of our Business Users use our Services in order to offer financial services to you, through Stripe or its financial partners. For example, they may provide a card product that enables you to purchase goods and services. These cards may carry the Stripe brand, bank partner brand and/or the brands of Business Users. In addition to any Transaction Data we may produce or receive when these cards are used for purchases, we will also receive and use your Personal Data in order to provide and manage these products. Please also see the privacy policies of the Business User and our bank partners, if applicable, associated with the financial service (whose brands may be shown on the card).
- Identity/Verification Services. We use Personal Data about your identity, including information provided by you and our service providers, to perform verification Services for Stripe or for the Business Users that you are doing business with, to reduce fraud and enhance security. If you provide a “selfie” along with an image of your identity document, we will use technology to compare and calculate whether they match and you can be verified. Learn More.
- Fraud Detection and Loss Prevention. We use your Personal Data collected across our Services (e.g. Stripe Radar) to detect and prevent losses for you, us, our Business Users and financial partners. We may provide Business Users (including card issuers, payment methods and others involved in payment processing activities) that use our fraud Business Services with Personal Data about you (including your attempted transactions) so that they can assess the fraud or loss risk associated with a transaction. You can learn more about how we may use technology to assess the fraud and loss risk associated with an attempted transaction and what information we may share with Business Users about such risks here and here.
- Our Business Users (their Authorized Third Parties). We share Personal Data of End Customers with their respective Business Users and with parties directly authorized by those Business Users to receive Personal Data. This includes sharing Personal Data of End Customers with Business Users when a Business User authorizes a third party application provider to access its Stripe account using Stripe Connect. For example, when the Business User uses Identity Services to verify an End Customer’s identity, Stripe shares with the Business User the information, documents or photos provided by the End Customer to verify their identity. The Business Users you choose to do business with may further share your Personal Data to third parties they authorize (e.g. other third party service providers). Please review their privacy policy to learn more.
- Advertising by Business Users. If you have begun a purchase, we share Personal Data with that Business User in connection with our provision of Services and that Business User may use your Personal Data to market and advertise their products or services, subject to the terms of their privacy policy. Please review your merchant’s privacy policy to learn more, including your rights to stop their use of your Personal Data for marketing purposes.
- We do not use, sell or share End Customer Personal Data for our marketing or advertising, or for marketing and advertising by third parties who are not the Business User with which you have transacted or attempted to transact.
- More. Please see below for information about additional ways in which we may use and share your Personal Data.
1.3 Representatives
To provide Business Services, we collect, use and share Personal Information from Representatives of Business Users (e.g. a business owner). We provide more information about our collection, use and sharing of Personal Data in our Privacy Center, including the legal bases which we rely on for using (processing) your Personal Data.
a. Personal Data that we collect about Representatives
- Registration and Contact Information. If you register for a Stripe account for a Business User (including incorporation of a Business), we collect your name and account log-in credentials. If you register for an event that Stripe organizes or attends or if you sign up for Stripe communications, we collect your registration and profile information. If you are a Representative or Representative of a potential Business User, we receive your Personal Data from third parties (including data providers) in order to advertise to, market and communicate with you as described further below and in Section 2. We may also associate a location with you in order to assess which Services or information may be useful to you. Learn More.
- Identification Information. If you are an owner of a Business User or you are expected to be a shareholder, officer or director of a Business User, we require that you provide your contact details, such as name, postal address, telephone number, and email address to fulfill our financial partner and regulatory requirements. We will directly (and through others) collect Personal Data about you, such as your ownership interest in the Business User, your date of birth and government identifiers associated with you and your Business User (such as your social security number, tax number, or Employer Identification Number). You may also choose to provide bank account information.
- More. Please see below for information about additional types of Personal Data that we may collect, including about online activity.
b. How we use and share Personal Data of Representatives
We generally use Personal Data of Representatives to provide the Business Services to the associated Business Users, as well as for the purposes described below.
- Business Services. We use and share Personal Data of Representatives with Business Users to provide the Services you (or the Business User you are associated with) have requested.
- In some cases our Business Service will require us to submit your Personal Data to a government entity (e.g. incorporating a business, or paying applicable sales tax). For our tax Business Services, we may use your Personal Data to file taxes on behalf of your associated Business User. For our Atlas business incorporation services, we may use your Personal Data to submit forms to the IRS on your behalf and to file documents with other governmental authorities (e.g. articles of incorporation in your state of incorporation).
- We share data with parties directly authorized by a Business User to receive Personal Data (e.g. financial partners servicing the financial product, or third party apps or services the Business User uses in conjunction with our Business Services). For example, providers of payment methods (e.g., Visa, WeChat Pay) will require merchant onboarding information for the Business Users that accept their payment methods, and Stripe will provide required onboarding information (including Personal Data of Representatives) to those financial partners. In some cases, these payment method providers will be located outside your home country for example WCP, AliPay, Block, Klarna Bank AB. Learn More.
- The use of Personal Data by a Business User’s authorized third party is subject to the third party’s privacy policy.
- If you are a Business User and have chosen a name that includes Personal Data (e.g. a sole proprietorship or family name in a company name), we will share and use that information as any company name in connection with the provision of our Services (e.g. including it on receipts and other descriptions identifying financial transactions).
- Advertising. Where allowed by applicable law, we use and share Representative Personal Data with others so that we may advertise and market our Services to you. Subject to applicable law (including any consent requirements), we may advertise to you through interest-based advertising and emails and seek to measure the effectiveness of our ads. See our Cookie Policy. We do not sell or share Representative Personal Data to others for their advertising purposes.
- More. Please see below for information about additional ways in which we may collect, use and share your Personal Data.
1.4 Visitors
We collect, use and share Personal Data of Visitors (who are not End Users, End Customers or Representatives). We provide more information about our collection, use and sharing of Personal Data in our Privacy Center, including the legal bases which we rely on for using (processing) your Personal Data.
a. Visitor Personal Data that we collect
When you visit our Sites, we will receive your Personal Data either from you providing it to us or through our use of cookies and similar technologies. See our Cookie Policy.
- Forms. When you choose to fill in a form on the Site or on third party websites featuring our advertising (e.g. LinkedIn or Facebook), we will collect the information included in the form (e.g. your contact information and other information about your question related to our Services). We may also associate a location with your visit. Learn More.
- More. Please see below for information about additional types of Personal Data that we may collect, including about online activity.
b. How we use and share visitor Personal Data
- Personalization. We use information about you that we gather from cookies and similar technologies to measure engagement with the content on the Sites, to improve relevancy and navigation, to personalize your experience (e.g. language and relevant geography) and to tailor content about Stripe and our Services to you. For example, because not all of our Services are available in all regions, so we may tailor our answers for your region.
- Advertising. As allowed by law, we use and share Visitor Personal Data with others so that we may advertise and market our Services to you. Subject to applicable law (including any consent requirements), we may advertise our Services to you through interest-based advertising and emails, and seek to measure the effectiveness of our ads. See also our Cookie Policy. We do not sell or share Visitor Personal Data to others for their advertising purposes.
- Engagement. When visitors engage with our stripe.com site, we will use information we collect about and through your devices in order to provide the opportunity to engage in conversations or with chatbots to address your questions.
- More. Please see below for information about additional ways in which we may collect, use and share your Personal Data.
2. More ways we collect, use and share Personal Data
In addition to the ways we collect, use and share Personal Data that are described above, we also process your Personal Data as follows:
a. Personal Data Collection
- Online Activity. Depending on the Service you use and the Business Users’ implementation of our Business Services, we will collect information about:
- Devices and browsers across our Sites and third-party websites, apps and other online services (“Third-Party Sites”),
- Usage data associated with those devices and browsers and how you’ve engaged with our Services, including IP address, plug-ins, language used, time spent on Sites and Third-Party Sites, pages visited, links clicked, payment methods used, and the pages that led or referred you to Sites and Third-Party Sites. For example, activity indicators, like mouse activity indicators, to help us detect fraud. Learn More. Please also see our Cookie Policy.
- Communication and Engagement Information. We will collect any information you choose to provide to us, for example, through support tickets, emails or social media. When you respond to Stripe emails or surveys, we collect your email address, name and any other information you choose to include in the body of your email or responses. If you contact us by phone, we will collect the phone number you use to call Stripe, as well as other information you may provide during the call. We will also collect your engagement data such as your registration for, attendance of, or viewing of Stripe events and other interaction with Stripe personnel.
- Forums and Discussion Groups. Where our Sites allow you to post content, we will collect Personal Data that you provide in connection with the post.
b. Personal Data Usage. In addition to the Personal Data usage described above, we use Personal Data in the following ways:
- Improving and Developing our Services. We use analytics on our Sites to help us analyze your use of our Sites and Services and diagnose technical issues. To learn more about the cookies that may be served through our Sites and how you can control our use of cookies and third-party analytics, please see our Cookie Policy. We also collect and process Personal Data through our different Services, whether you are an End User, End Customer, Representative or Visitor, to improve our Services, develop new Services and support our efforts to make our Services more relevant and more useful to you. Learn More.
- Communications. We will use the contact information we have about you to perform the Services, which may include sending codes via SMS to authenticate you. Learn More. If you are an End User, Representative or Visitor, we may communicate with you using the contact information we have about you (e.g. using email, phone, text message or videoconference) to provide information about our Services and our affiliates’ services, invite you to participate in our events or surveys, or otherwise communicate with you for our marketing purposes, provided that we do so in accordance with applicable law, including any consent or opt-out requirements. For example, when you submit your contact information to us or when we collect your business contact details through our participation at trade shows or other events, we may use the information to follow-up with you regarding an event, send you information that you have requested on our products and services and include you on our marketing information campaigns.
- Social Media and Promotions. If you choose to submit Personal Data to us to participate in an offer, program or promotion, we will use the Personal Data you submit to administer the offer, program or promotion. We will also use that Personal Data and Personal Data you make available on social media to market to you unless we are not permitted to do so.
- Fraud Prevention and Security. We collect and use Personal Data to help us to detect and manage the activity of fraudulent and other bad actors across our Services, to enable our fraud detection Business Services, and to otherwise seek to secure our Services and transactions against unauthorized access, use, modification or misappropriation of Personal Data, information and funds. In connection with fraud and security monitoring, prevention, detection, and compliance activities for Stripe and its Business Users, we receive information from service providers (including credit bureaus), third parties, and the Services we provide. We may collect information from you, and about you, from Business Users, financial parties and in some cases third parties. For example, to protect our Services, we may receive information from third parties about IP addresses that malicious actors have compromised. Learn More. This Personal Data (e.g. name, address, phone number, country) helps us to confirm identities, run credit checks subject to applicable law and prevent fraud. We may also use technology to assess the fraud risk associated with an attempted transaction by an End Customer or End User with a Business User or financial partner.
- Compliance with Legal Obligations. We use Personal Data to meet our contractual and legal obligations related to anti-money laundering, Know-Your-Customer (“KYC”) laws, anti-terrorism, export control and prohibitions on doing business with restricted persons or in certain business areas and other legal obligations. Learn More. We strive to make our Services safe, secure and compliant, and the collection and use of Personal Data is critical to this effort. For example, we may monitor patterns of payment transactions and other online signals and use those insights to reduce the risk of fraud, money laundering and other activity that is harmful to Stripe, our End Users and their End Customers.
- Minors. The Services are not directed to minors, including children under the age of 13, and we request that they not provide Personal Data through the Services. In some countries, we may impose higher age limits as required by applicable law.
c. Personal Data Sharing. In addition to the ways described above, we share Personal Data in the following ways:
- Stripe Affiliates. We share Personal Data with other Stripe affiliated entities. When we share with these entities, it is for purposes identified in this Policy.
- Service Providers or Processors. In order to provide Services to our Business Users and End Users and to communicate, market and advertise to Visitors, Representatives and End Users regarding our Services, we will rely on others to provide us services. Service providers provide a variety of critical services, such as hosting (storing and delivering), analytics to assess the speed, accuracy and/or security of our Services, identity verification, customer service, email and auditing. We authorize such service providers to use or disclose the Personal Data that we make available to perform services on our behalf and to comply with applicable legal requirements. We require such service providers to contractually commit to protect the security and confidentiality of Personal Data they process on our behalf. Our service providers are predominantly located in the European Union, the United States of America and India. Learn More.
- Financial Partners. “Financial Partners” are financial institutions that we partner with to offer the Services (including payment method acquirers, banks and payout providers). We share Personal Data with certain Financial Partners to provide the Services to the associated Business Users and to offer certain Services in partnership with our Financial Partners. For example, we share certain Personal Data of Representatives (e.g. loan repayment data and contact information) with institutional investors who purchase or provide credit secured by the Capital loans that we have made to the associated Business Users.
- Others with Consent. In some cases we may not provide a service, but instead refer you to, or enable you to engage with, others to get services (e.g. professional services firms that we partner with to deliver Atlas). In these cases, we will disclose the identity of the third party and the information that will be shared with them and seek your consent to share the information.
- Corporate Transactions. In the event that we enter into, or intend to enter into, a transaction that alters the structure of our business, such as a reorganization, merger, sale, joint venture, assignment, transfer, change of control, or other disposition of all or any portion of our business, assets or stock, we may share Personal Data with third parties in connection with such transaction. Any other entity which buys us or part of our business will have the right to continue to use your Personal Data, but subject to the terms of this Policy.
- Compliance and Harm Prevention. We share Personal Data as we believe necessary: (i) to comply with applicable law, (ii) to comply with rules imposed by a payment method in connection with use of that payment method (e.g. network rules for Visa); (iii) to enforce our contractual rights; (iv) to secure or protect the Services, rights, privacy, safety and property of Stripe, you or others, including against other malicious or fraudulent activity and security incidents; and (v) to respond to valid legal process requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence.
3. Legal bases for processing data
For the purposes of the General Data Protection Regulation, we rely upon a number of legal bases to enable our processing of your Personal Data. For more information, see here.
a. Contractual and Pre-Contractual Business Relationships. We process Personal Data for the purpose of entering into business relationships with prospective Business Users and End Users and to perform the respective contractual obligations with them. Activities include:
- Creation and management of Stripe accounts and Stripe account credentials, including the evaluation of applications to commence or expand the use of our Services;
- Creation and management of Stripe Checkout accounts;
- Accounting, auditing, and billing activities; and
- Processing of payments, including fraud detection, loss prevention, optimizing valid transactions, communications regarding such payments, and related customer service.
b. Legal Compliance. We process Personal Data to verify the identity of individuals and entities in order to comply with fraud monitoring, prevention and detection obligations, laws associated with the identification and reporting of illegal and illicit activity, such as “Anti-Money Laundering (“AML”) and Know-Your-Customer (“KYC”)” obligations, and financial reporting obligations. For example, we may be required to record and verify a User’s identity for the purpose of compliance with legislation intended to prevent money laundering and financial crimes. These obligations are imposed on us by the operation of law and may require us to report our compliance to third parties, and to submit to third party verification audits.
c. Legitimate Interests. Where allowed under applicable law, we rely on our legitimate business interests to process Personal Data about you. The following list sets out the business purposes for which we have a legitimate interest in processing your data:
- Detect, monitor and prevent fraud and unauthorized payment transactions;
- Mitigate financial loss, claims, liabilities or other harm to End Customers, End Users, Business Users and Stripe;
- Determine eligibility for and offer new Stripe products and services Learn More;
- Respond to inquiries, send Service notices and provide customer support;
- Promote, analyze, modify and improve our Services, systems, and tools, and develop new products and services, including reliability of the Services;
- Manage, operate and improve the performance of our Sites and Services by understanding their effectiveness and optimizing our digital assets;
- Analyze and advertise our Services, and related improvements;
- Conduct aggregate analysis and develop business intelligence that enable us to operate, protect, make informed decisions, and report on the performance of, our business;
- Share Personal Data with third party service providers that provide services on our behalf and business partners which help us operate and improve our business Learn More;
- Enable network and information security throughout Stripe and our Services; and
- Share Personal Data among our affiliates.
d. Consent. We may rely on consent to collect and process Personal Data as it relates to how we communicate with you and for the provision of our Services such as Link, Financial Connections, Atlas and Identity. When we process data based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on such consent before the consent is withdrawn.
4. Your rights and choices
You may have choices regarding our collection, use and disclosure of your Personal Data:
a. Opting out of receiving electronic communications from us
If you no longer want to receive marketing-related emails from us, you may opt-out via the unsubscribe link included in such emails or as described here. We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt-out of receiving marketing-related emails from us, (i) we retain the right to communicate to you regarding the services you receive (e.g. support and important legal notices) and (ii) our Business Users may still send you messages and/or direct us to send you messages on their behalf.
b. Your data protection rights
Depending on your location and subject to applicable law, you may have the following rights described here with regard to the Personal Data we control about you:
- The right to request confirmation of whether Stripe processes Personal Data relating to you, and if so, to request a copy of that Personal Data;
- The right to request that Stripe rectify or update your Personal Data that is inaccurate, incomplete or outdated;
- The right to request that Stripe erase your Personal Data in certain circumstances provided by law. Learn More;
- The right to request that Stripe restrict the use of your Personal Data in certain circumstances, such as while Stripe considers another request that you have submitted (including a request that Stripe make an update to your Personal Data);
- The right to request that we export your Personal Data that we hold to another company, where technically feasible;
- Where the processing of your Personal Data is based on your previously given consent, you have the right to withdraw your consent at any time;
- Where we process your information based on our legitimate interests, you may also have the right to object to the processing of your Personal Data. Unless we have compelling legitimate grounds or where it is needed for legal reasons, we will cease processing your information when you object. Learn More.
- The right not to be discriminated against for exercising these rights; and/or
- The right to appeal any decision by Stripe relating to these rights.
You may have additional rights regarding your Personal Data under applicable law. For example, see Jurisdiction-specific provisions section under California below.
c. Process for exercising your data protection rights
To exercise your data protection rights please also see the Stripe Privacy Center or contact us as described below.
5. Security and retention
We make reasonable efforts to provide a level of security appropriate to the risk associated with the processing of your Personal Data. We maintain organizational, technical and administrative measures designed to protect Personal Data covered by this Policy against unauthorized access, destruction, loss, alteration or misuse. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
To help us protect Personal Data, where you have an account with Stripe, we encourage you to use a strong password, protect that password from unauthorized use and not use the same log-in credentials (e.g. password) for your Stripe accounts as you do with other services or accounts. If you have reason to believe that your interaction with us is no longer secure (e.g. you feel that the security of your Stripe account has been compromised), please contact us immediately. Learn More.
We retain your Personal Data as long as we are providing the Services to you or our Business Users (as applicable) or for a period during which we reasonably anticipate providing the Services. Even after we stop providing Services directly to you or a Business User with which you are doing business, and even if you close your Stripe account or complete a transaction with a Business User, we may retain your Personal Data:
- to comply with our legal and regulatory obligations.
- to enable fraud monitoring, detection and loss prevention activities.
- to comply with our tax, accounting, and financial reporting obligations
- where required by our contractual commitments to our financial partners (and where data retention is mandated by the payment methods you used).
In cases where we keep Personal Data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law. Learn More.
6. International data transfers
We are a global business. We may transfer your Personal Data to countries other than your own country, including to the United States. These countries may have data protection rules that are different from your country. When transferring data across borders, we take measures to comply with applicable data protection laws related to such transfer. In certain situations, we may be required to disclose Personal Data in response to lawful requests from officials (such as law enforcement or security authorities). Learn More.
If you are located in the European Economic Area (“EEA”), the United Kingdom (“UK”) or Switzerland, please see Stripe Privacy Center for more information. Where applicable law requires a data transfer mechanism, we use one or more of the following:
- Transfers to certain countries or recipients that are recognised as having an adequate level of protection for Personal Data under applicable law.
- EU Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum issued by the Information Commissioner’s Office. You can obtain a copy of the relevant Standard Contractual Clauses. Learn More.
- or other legal methods available to us under applicable law.
While Stripe, Inc. remains self-certified under the E.U.-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield, it is not currently relying on these frameworks for the transfer of Personal Data to the United States.
7. Updates and notifications
We may change this Policy from time to time to reflect new services, changes in our privacy practices or relevant laws. The “Last updated” legend at the top of this Policy indicates when this Policy was last revised. Any changes are effective the latter of when we post the revised Policy on the Services or otherwise provide notice of the update as required by law.
We may provide you with disclosures and alerts regarding the Policy or Personal Data collected by posting them on our website and, if you are an End User or Representative, by contacting you through your Stripe Dashboard, email address and/or the physical address listed in your Stripe account.
8. Jurisdiction-specific provisions
- Australia. If you are an Australian resident, and you are dissatisfied with our handling of any complaint you raise under this Policy, you may wish to contact the Office of the Australian Information Commissioner.
9. Contact us
If you have any questions or complaints about this Policy, please contact us. If you are an End Customer (i.e. an individual doing business or transacting with a Business User), please refer to the privacy policy or notice of the Business User for information regarding the Business User’s privacy practices, choices and controls, or contact the Business User directly.
PayPal Privacy Statement
Effective Date: 21 March 2022
This version: 22-1
Previous version: 21-1
Jump to section:
- Overview
- What Personal Data Do We Collect?
- Why Do We Retain Personal Data?
- How Do We Process Personal Data?
- Do We Share Personal Data?
- How Do We Work with Other Services and Platforms?
- How Do We Use Cookies and Tracking Technologies?
- What Privacy Choices Are Available To You?
- What Are Your Rights?
- How Do We Protect Your Personal Data?
- Can Children Use Our Services?
- What Else Should You Know?
- Contact Us
- Definitions
- Additional Information
Overview
PayPal has developed this Privacy Statement to explain how we may collect, retain, process, share and transfer your Personal Data when you visit our Sites or use our Services. This Privacy Statement applies to your Personal Data when you visit Sites or use Services, and does not apply to online websites or services that we do not own or control, including websites or services of other PayPal Users.
This Privacy Statement is designed to help you obtain information about our privacy practices and to help you understand your privacy choices when you use our Sites and Services. Please note that our Service offerings may vary by region.
We have defined some terms that we use throughout the Privacy Statement. You can find the meaning of a capitalized term in the Definitions section.
Please contact us if you have questions about our privacy practices that are not addressed in this Privacy Statement.
What Personal Data Do We Collect?
The primary purpose for collecting your Personal Data is to provide you with a secure, smooth, efficient, and customised experience. We may collect information about you when you visit our Sites or use our Services, including the following:
- Registration and use information – When you register to use our Services by establishing an Account, we will collect Personal Data as necessary to offer and fulfill the Services you request. Depending on the Services you choose, we may require you to provide us with your name, postal address, telephone number, email address and identification information to establish an Account. We may require you to provide us with additional Personal Data as you use our Services.
- Transaction and experience information – When you use our Services or access our Sites, for example, to make purchases from merchants, to receive money, to process payments, to send payouts or to send money to friends and family, we collect information about the transaction, as well as other information associated with the transaction such as amount sent or requested, amount paid for products or services, merchant information, including information about any funding instruments used to complete the transaction, Device Information, Technical Usage Data, and Geolocation Information.
- Participant information – When you use our Services or access our Sites, we collect Personal Data you provide us about the other participants associated with the transaction.
- Send or request money: When you send or request money through the Services, we collect Personal Data such as name, postal address, telephone number, and financial account information about the participant who is receiving money from you or sending money to you. The extent of Personal Data required about a participant may vary depending on the Services you are using to send or request money.
- Pay or request someone else to pay a bill: If you use our Services to pay a bill for the benefit of someone else, or if you request a User to pay a bill for you, we collect Personal Data from you about the account holder such as name, postal address, telephone number, email address, and account number of the bill that you intend to pay or request to be paid.
- Add value to your accounts: If you use our Services to add value to your Account or any other account you may have, or if you ask a User to add value to any of these accounts, we may collect Personal Data from you about the other party, or from the other party about you to facilitate the request. For example, if you use our Services to reload a mobile phone, or to request value be added to your mobile account, we may collect Personal Data and other information including mobile account number from the other participant.
- Information about your public profile and your friends and contacts – It may be easier for us to help you transact with your friends and contacts if you choose to connect your contact list information with your Account or if your Account profile is publicly available. If you establish an account connection between your device or a social media platform and your Account, we will use your contact list information (such as name, address, email address) to improve your experience when you use the Services. When your Account profile is public, other users can find your profile to send you money by searching for you by name, username, email, or mobile number on PayPal and confirm it’s you by viewing your photo. You can make your Account profile private anytime in your PayPal.me settings.
- Information that you choose to provide us to obtain additional Services or specific online Services – If you request or participate in an optional Site feature, or request enhanced Services or other elective functionality, we may collect additional information from you. We will provide you with a separate notice at the time of collection, if the use of that information differs from the uses disclosed in this Privacy Statement.
- Personal Data about you if you use unbranded Services – certain Services are available without being required to log in to or establish an Account. We will collect Personal Data when you are interacting with and making payments to merchants using our card payment services that do not carry the PayPal brand and when you checkout with PayPal without logging into an account. For our unbranded payment services, your interaction is with the merchant, on their platform. If you are an Account holder, or create an Account at a later date, we may collect information about unbranded transactions and associate them with your Account to improve your customer experience as an Account holder and for compliance and analytics purposes. If you are not an Account holder, we will collect and store all information you provide and use such information in accordance with this Privacy Statement.
- Information about you from third-party sources – We obtain information from third-party sources such as merchants, data providers, and credit bureaus, where permitted by law.
- Other information we collect related to your use of our Sites or Services – We may collect additional information from or about you when you communicate with us, contact our customer support teams or respond to a survey.
Notice to Non-Account holders
If you use our Services without creating or logging into an account, we’ll still collect personal data, which may include your payment information, device information, and location. When you use our Services without creating or logging into an account, we will use this information to process transactions, prevent fraud and comply with the law. We may connect this information with your account, if you have one or if you create an account at a later date.
Why Do We Retain Personal Data?
We retain Personal Data to fulfill our legal or regulatory obligations and for our business purposes. We may retain Personal Data for longer periods than required by law if it is in our legitimate business interests and not prohibited by law. If your Account is closed, we may take steps to mask Personal Data and other information, but we reserve our ability to retain and access the data for so long as required to comply with applicable laws. We will continue to use and disclose such Personal Data in accordance with this Privacy Statement.
How Do We Process Personal Data?
We may Process your information for the following reasons:
- To operate the Sites and provide the Services, including to:
- execute a payment, send or request money, send payouts, add value to an account, or pay a bill;
- confirm your identity;
- authenticate your access to an Account;
- communicate with you about your Account, the Sites, the Services, or PayPal;
- create an account connection between your Account and a third-party account or platform;
- perform creditworthiness and other financial standing checks, evaluate applications, and compare information for accuracy and verification purposes; and
- keep your Account and financial information up to date.
- To manage our business needs, such as monitoring, analyzing, and improving the Services and the Sites’ performance and functionality. For example, we analyze User behavior and perform research about the way you use our Services.
- To manage risk and protect the Sites, the Services and you from fraud by verifying your identity. PayPal’s risk and fraud tools use Personal Data, Device Information, Technical Usage Data and Geolocation Information from our sites and websites that offer PayPal Services to help detect and prevent fraud and abuse of the Services.
- To market to you about PayPal products and Services and the products and services of unaffiliated businesses. We may also Process your Personal Data to tailor the marketing content and certain Services or Site experiences to better match your interests on PayPal and other third-party websites.
- To provide personalized Services offered by PayPal on third-party websites and online services. We may use your Personal Data and other information collected in accordance with this Privacy Statement to provide a targeted display, feature, Services or offer to you on third-party websites. We may use cookies and other tracking technologies to provide these online services and/or work with other third-parties such as merchants, advertising or analytics companies to provide these online services.
- To provide you with location-specific options, functionality or offers if you elect to share your Geolocation Information through the Services. We will use this information to enhance the security of the Sites and Services and provide you with location-based Services, such as advertising, search results, and other personalized content.
- To comply with our obligations and to enforce the terms of our Sites and Services, including to comply with all applicable laws and regulations.
- To make it easier for you to find and connect with others. For instance, if you let us access your contacts or when your Account profile is public, we can suggest connections with people you may know and help others connect with you to send you money by letting them find your profile when they search for you by name, username, email, or mobile number on PayPal. We may also associate information that we learn about you through your and your contacts’ use of the Services, and information you and others provide, to suggest people you may know or may want to transact with through our Services. Social functionality and features designed to simplify your use of the Services with others vary by Service.
- To respond to your requests, for example to contact you about a question you submitted to our customer service team.
Do We Share Personal Data?
We may share your Personal Data or other information about you with others in a variety of ways as described in this section of the Privacy Statement.
We may share your Personal Data or other information for the following reasons:
With other members of the PayPal corporate family: We may share your Personal Data with members of the PayPal family of entities to, among other things, provide the Services you have requested or authorized; to manage risk; to help detect and prevent potentially illegal and fraudulent acts and other violations of our policies and agreements; and to help us manage the availability and connectivity of PayPal products, Services, and communications.
With other companies that provide services to us: We may share Personal Data with third-party service providers that perform services and functions at our direction and on our behalf. These third-party service providers may, for example, provide you with Services, verify your identity, assist in processing transactions, send you advertisements for our products and Services, or provide customer support.
With other financial institutions that we have partnered with to jointly create and offer a product or service: We may share Personal Data with other financial institutions that we have partnered with to jointly create and offer a product. These financial institutions may only use this information to market and offer PayPal-related products, unless you have given consent for other uses. We may also share Personal Data to process transactions, provide you with benefits associated with your eligible cards, and keep your financial information up to date.
With the other parties to transactions when you use the Services, such as other Users, merchants, and their service providers: We may share information about you and your Account with the other parties involved in processing your transactions. This includes other Users you are sending or receiving funds from, and merchants and their service providers. The information might include:
- Personal Data and Account information necessary to facilitate the transaction;
- information to help other participant(s) resolve disputes and detect and prevent fraud; and
- aggregated data and performance analytics to help merchants better understand Users and to help merchants enhance Users’ experiences.
With other third parties for our business purposes or as permitted or required by law: We may share information about you with other parties for PayPal’s business purposes or as permitted or required by law, including:
- if we need to do so to comply with a law, legal process or regulations;
- to law enforcement authorities or other government officials, or other third parties pursuant to a subpoena, a court order or other legal process or requirement applicable to PayPal or PayPal’s corporate family;
- if we believe, in our sole discretion, that the disclosure of Personal Data is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation of suspected or actual illegal activity;
- to protect the vital interests of a person;
- to investigate violations of or enforce a user agreement or other legal terms applicable to any Service;
- to protect our property, Services and legal rights;
- to facilitate a purchase or sale of all or part of PayPal’s business;
- in connection with shipping and related services for purchases made using a Service;
- to help assess and manage risk and prevent fraud against us, our Users and fraud involving our Sites or use of our Services, including fraud that occurs at or involves our business partners, strategic ventures, or other individuals and merchants;
- to banking partners as required by card association rules for inclusion on their list of terminated merchants;
- to credit reporting and collection agencies;
- to companies that we plan to merge with or be acquired by; and
- to support our audit, compliance, and corporate governance functions.
With your consent: We also will share your Personal Data and other information with your consent or direction, including if you authorize an account connection with a third-party account or platform.
In addition, PayPal may provide aggregated statistical data to third-parties, including other businesses and members of the public, about how, when, and why Users visit our Sites and use our Services. This data will not personally identify you or provide information about your use of the Sites or Services. We do not share your Personal Data with third parties for their marketing purposes without your consent.
How Do We Work with Other Services and Platforms?
A significant benefit and innovation of PayPal’s Services is that you can connect your Account with a third-party account or platform. For the purposes of this Privacy Statement, an “account connection” with such a third-party is a connection you authorize or enable between your Account and a non-PayPal account, payment instrument, or platform that you lawfully control or own. When you authorize such a connection, PayPal and the third-party will exchange your Personal Data and other information directly. Examples of account connections include:
- linking your Account to a social media account or social messaging service;
- connecting your Account to a third-party data aggregation or financial services company, if you provide such company with your Account log-in credentials; or
- using your Account to make payments to a merchant or allowing a merchant to charge your Account.
If you choose to create an account connection, we may receive information from the third-party about you and your use of the third-party’s service. For example, if you connect your Account to a social media account, we will receive Personal Data from the social media provider via the account connection. If you connect your Account to other financial accounts, directly or through a third-party service provider, we may have access to your account balance and transactional information, such as purchases and funds transfers. We will use all such information that we receive from a third-party via an account connection in a manner consistent with this Privacy Statement.
Information that we share with a third-party based on an account connection will be used and disclosed in accordance with the third-party’s privacy practices. Before authorizing an account connection, you should review the privacy notice of any third-party that will gain access to your Personal Data as part of the account connection. For example, Personal Data that PayPal shares with a third-party account or platform such as a social media account may in turn be shared with certain other parties, including the general public, depending on the account’s or platform’s privacy practices.
How Do We Use Cookies and Tracking Technologies?
When you visit our Sites, use our Services, or visit a third-party website for which we provide online Services, we and our business partners and vendors may use cookies and other tracking technologies (collectively, “Cookies”) to recognize you as a User and to customize your online experiences, the Services you use, and other online content and advertising; measure the effectiveness of promotions and perform analytics; and to mitigate risk, prevent potential fraud, and promote trust and safety across our Sites and Services. Certain aspects and features of our Services and Sites are only available through the use of Cookies, so if you choose to disable or decline Cookies, your use of the Sites and Services may be limited or not possible.
Do Not Track (DNT) is an optional browser setting that allows you to express your preferences regarding tracking by advertisers and other third-parties. We do not respond to DNT signals.
Please review our Statement on Cookies and Tracking Technologies to learn more about how we use Cookies.
What Privacy Choices Are Available To You?
You have choices when it comes to the privacy practices and communications described in this Privacy Statement. Many of your choices may be explained at the time you sign up for or use a Service or in the context of your use of a Site. You may be provided with instructions and prompts within the experiences as you navigate the Services.
- Choices Relating to the Personal Data We Collect
- Personal Data. You may decline to provide Personal Data when it is requested by PayPal, but certain Services or all of the Services may be unavailable to you.
- Location and other device-level information. The device you use to access the Sites or Services may collect information about you, including Geolocation Information and User usage data that PayPal may then collect and use. For information about your ability to restrict the collection and use of such information, please use the settings available in the device.
- Choices Relating to Our Use of Your Personal Data
- Online Tracking and Interest-Based Advertising. We work with partners and third-party service providers to serve you advertising using ad-related cookies and web beacons. You can opt-out of third-party advertising-related cookies and web beacons, in which case our advertising should not be targeted to you. You will continue to see our advertising on third party websites.
- For more information on third-party advertising-related cookies and interest-based advertising, and to learn how to opt-out of these practices with companies participating in industry self-regulation, please visit Your Ad Choices.
- Personalized Services offered by PayPal on third-party websites and services. You may manage your preferences for other PayPal Services that are personalized and offered to you on third-party websites from your Account. We may also provide you with instructions and prompts on how to manage your preferences within the Service experience.
- Finding and connecting with others. If available, you may manage your preferences for finding and connecting with others from your account of the Service you use.
- Online Tracking and Interest-Based Advertising. We work with partners and third-party service providers to serve you advertising using ad-related cookies and web beacons. You can opt-out of third-party advertising-related cookies and web beacons, in which case our advertising should not be targeted to you. You will continue to see our advertising on third party websites.
- Choices Relating to Account Connections
- If you authorize an account connection to a third-party account or platform, such as a social media account, you may be able to manage your connection preferences from your Account or the third-party account or platform. Please refer to the privacy notice that governs the third-party platform for more information on the choices you may have.
- Choices Relating to Cookies
- You may have options available to manage your cookies preferences. For example, your browser or internet device may allow you delete, disable, or block certain cookies and other tracking technologies. You can learn more by visiting AboutCookies.org. You may choose to enable these options, but doing so may prevent you from using many of the core features and functions available on a Service or Site.
- You may have an option regarding the use of cookies and other tracking technologies when you use a Service or visit parts of a Site. For example, you may be asked if you want the Service or Site to “remember” certain things about you, and we will use cookies and other tracking technologies to the extent that you permit them.
- You can learn more about our cookies and tracking technologies by visiting the Statement on Cookies and Tracking Technologies page.
- Choices Relating to Your Registration and Account Information
- If you have an Account, you generally may review and edit Personal Data by logging in and updating the information directly or by contacting us. Contact us if you do not have an Account or if you have questions about your Account information or other Personal Data.
- Choices Relating to Communication
- Notices, Alerts and Updates from Us:
- Marketing: We may send you marketing content about our Sites, Services, products, products we jointly offer with financial institutions, as well as the products and services of unaffiliated third parties and members of the PayPal corporate family through various communication channels, for example, email, text, pop-ups, push notifications, and messaging applications. You may opt out of these marketing communications by following the instructions in the communications you receive. If you have an Account with us, you may also adjust your communication preferences in your Account settings. For messages sent via push notifications, you may manage your preferences in your device.
- Informational and Other: We will send communications to you that are required or necessary to send to Users of our Services, notifications that contain important information and other communications that you request from us. You may not opt out of receiving these communications. However, you may be able to adjust the media and format through which you receive these notices.
- Notices, Alerts and Updates from Us:
What Are Your Rights?
Subject to limitations set out in Data Protection Laws, you have certain rights in relation to your personal data. You have the right to request access to your data and rectification. Please contact us if you want to exercise these rights.
You may also revoke consent. Revocation of your consent may affect our ability to provide services to you. If you want to exercise any of your rights, contact us. If you wish to complete a request for access to all personal data PayPal holds about you, remember that you may be required to prove your identity.
If you have an Account with any of our Services, you will generally be able to review and edit Personal Data in the Account by accessing the account and updating information directly.
You can also contact us if you do not have an Account or if you have questions about Account information or other Personal Data.
How Do We Protect Your Personal Data?
We maintain technical, physical, and administrative security measures designed to provide reasonable protection for your Personal Data against loss, misuse, unauthorized access, disclosure, and alteration. The security measures include firewalls, data encryption, physical access controls to our data centers, and information access authorization controls. While we are dedicated to securing our systems and Services, you are responsible for securing and maintaining the privacy of your password(s) and Account/profile registration information and verifying that the Personal Data we maintain about you is accurate and current. We are not responsible for protecting any Personal Data that we share with a third-party based on an account connection that you have authorized.
Can Children Use Our Services?
The Sites and Services are not directed to children under the age of 13. We do not knowingly collect information, including Personal Data, from children or other individuals who are not legally able to use our Sites and Services. If we obtain actual knowledge that we have collected Personal Data from a child under the age of 13, we will promptly delete it, unless we are legally obligated to retain such data. Contact us if you believe that we have mistakenly or unintentionally collected information from a child under the age of 13.
What Else Should You Know?
Changes to This Privacy Statement.
We may revise this Privacy Statement from time to time to reflect changes to our business, the Sites or Services, or applicable laws. The revised Privacy Statement will be effective as of the published effective date.
If the revised version includes a substantial change, we will provide you with 30 days prior notice by posting notice of the change on the “Policy Update” page of our website. We also may notify Users of the change using email or other means.
Transfers of Your Personal Data to Other Countries
Our operations are supported by a network of computers, cloud-based servers, and other infrastructure and information technology, including, but not limited to, third-party service providers. We and our third-party service providers store and Process your Personal Data in the United States of America and elsewhere in the world. We will protect your information as described in this Privacy Statement if your Personal Data is transferred to other countries. By using our Sites and Services, you consent to your Personal Data being transferred to other countries, including countries that have different data protection rules than your country. We do not represent that our Sites and Services are appropriate or available in any particular jurisdiction.
Our Management of Credit-Related Personal Information
When you apply for Services involving consumer credit, PayPal Credit may collect, use and disclose your credit-related personal information. PayPal Credit collects the following kinds of credit information to assess your creditworthiness: Personal Data, PayPal account transaction and experience data, and information about any existing PayPal Credit loans you may have.
PayPal Credit may also collect credit information about you from an external credit bureau including identification information (e.g., name, address, date of birth), previous credit checks done by credit providers to whom you have applied, insolvencies, bankruptcies, defaults (at least 60 days overdue on consumer debts over $150) and consumer credit fraud. If PayPal Credit collects information from a credit bureau it may also receive your credit score.
PayPal Credit collects, uses, and discloses your credit-related personal information for the purposes of engaging in the Australian credit reporting system including to determine your creditworthiness and report defaults and fraud to an external credit bureau. It does not hold, use, or disclose this information for any other purpose and if the information is no longer needed for this purpose and is not otherwise required by law to be retained, then it will be destroyed or de-identified. PayPal Credit is not likely to disclose your credit information to entities that do not have an Australian link.
If you have questions about your Account information or Personal Data that was used for an application for credit Services made by you, the correction of that information, or to make a complaint about our management of credit-related personal information, please refer to the Contact us section below.
Contact Us
You may contact us if you have general questions about our Privacy Statement and practices or questions about your Account information or Personal Data.
We want to make sure your questions go to the right place:
- Click here to contact us about your PayPal account or transaction, or a card payment made to a merchant.
Alternatively, you can contact us at:
Email: | auexecutiveescalations@paypal.com |
---|---|
Mail: | Privacy Officer PayPal Australia GPO Box 351 Sydney NSW 2001 |
Handling your complaints
We aim to:
- Acknowledge receipt of all complaints within 24 hours (or 1 business day) of receiving it, or as soon as practicable.
- Resolve all complaints within 30 days after receiving the complaint. This may not be possible in all circumstances. Where we cannot resolve a complaint within 30 days, we will notify you of the reason for the delay as well as an indication of when we expect to resolve the complaint.
We are a member of the Australian Financial Complaints Authority (“AFCA”), an independent external dispute resolution scheme covering applicable Australian customers. For more information on AFCA, please visit www.afca.org.au. If you are not satisfied with the outcome of your complaint, you may wish to contact the AFCA on:
Phone: | 1800 931 678 |
---|---|
Mail: | Australian Financial Complaints Authority GPO Box 3 Melbourne VIC 3001 |
You may also contact the Office of the Australian Information Commissioner (“OAIC”) in relation to the handling of your personal information. You may contact OAIC on:
Phone: | 1300 363 992 |
---|---|
Mail: | Office of the Australian Information CommissionerGPO Box 5218Sydney NSW 2001 |
Definitions
Account means a PayPal member account.
Device Information means data that can be automatically collected from any device used to access the Sites or Services. Such information may include, but is not limited to, your device type; your device’s network connections; your device’s name; your device’s IP address; information about your device’s web browser and the internet connection being used to access the Site or Services; Geolocation Information; information about apps downloaded to your device; and biometric data (e.g., Touch ID/Fingerprint to verify your identity).
Geolocation Information means information that identifies with reasonable specificity your location by using, for instance, longitude and latitude coordinates obtained through GPS, Wi-Fi, or cell site triangulation. Some of our Services may ask you for permission to share your current location. Some of the Sites and Services require this information to provide a specific product or online Service. If you do not agree to our collection of the geolocation information, our Sites or Services may not function properly when you try to use them.
PayPal means PayPal Australia Pty Ltd ABN 93 111 195 389, AFSL 304962 and subsidiaries or affiliates. In this Privacy Statement, PayPal is sometimes referred to as “we,” “us,” or “our,” depending on the context.
PayPal Credit means PayPal Credit Pty Limited (ABN 66 600 629 258).
Personal Data means information that can be associated with an identified or identifiable person. “Personal Data” can include name, postal address (including billing and shipping addresses), telephone number, email address, payment card number, other financial account information, account number, date of birth, and government-issued credentials (e.g., driver’s licence number, national ID, or passport).
Process means any method or way that we handle Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, and consultation, disclosure by transmission, disseminating or otherwise making available, alignment or combination, restriction, erasure or destruction of Personal Data.
Services means any products, services, content, features, technologies, or functions, and all related websites, applications and services offered to you by PayPal and PayPal Credit.
Sites means the websites, mobile apps, official social media platforms, or other online properties through which PayPal offers the Services and which has posted or linked to this Privacy Statement.
Technical Usage Data means information we collect from your phone, computer or other device that you use to access the Sites or Services. Technical Usage Data tells us how you use the Sites and Services, such as what you have searched for and viewed on the Sites and the way you use our Services, including your IP address, statistics regarding how pages are loaded or viewed, the websites you visited before coming to the Sites and other usage and browsing information collected through Cookies.
User means an individual who uses the Services or accesses the Sites.
Additional Information
The information provided in this section may be specific to customers depending on your region or how you use the Services. This information is provided to PayPal from third parties you may interact with when using the Services.
Google ReCaptcha
PayPal uses ReCaptcha on the Sites and Services. Your use of ReCaptcha is subject to the Google Privacy Policy and Terms of Use.
ReCaptcha is only used to fight spam and abuse.
The PayPal service is provided by PayPal Australia Pty Limited (ABN 93 111 195 389) which holds Australian Financial Services Licence number 304962. Any information provided is general only and does not take into account your objectives, financial situation or needs. Please read and consider the Combined Financial Services Guide and Product Disclosure Statement before acquiring or using the service. PayPal credit services are provided by PayPal Credit Pty Limited (ACN 600 629 258).
When you visit or interact with our sites, services, applications, tools or messaging, we or our authorised service providers may use cookies, web beacons, and other similar technologies for storing information to help provide you with a better, faster and safer experience and for advertising purposes. Learn more here.
accessible from https://www.sydneybamboo.com.au
Cookie Policy What Are Cookies
As is common practice with almost all professional websites this site uses cookies, which are tiny files that are downloaded to your computer, to improve your experience. This page describes what information they gather, how we use it and why we sometimes need to store these cookies. We will also share how you can prevent these cookies from being stored however this may downgrade or ‘break’ certain elements of the sites functionality.
How We Use Cookies
We use cookies for a variety of reasons detailed below. Unfortunately in most cases there are no industry standard options for disabling cookies without completely disabling the functionality and features they add to this site. It is recommended that you leave on all cookies if you are not sure whether you need them or not in case they are used to provide a service that you use.
Disabling Cookies
You can prevent the setting of cookies by adjusting the settings on your browser (see your browser Help for how to do this). Be aware that disabling cookies will affect the functionality of this and many other websites that you visit. Disabling cookies will usually result in also disabling certain functionality and features of the this site. Therefore it is recommended that you do not disable cookies. This Cookies Policy was created with the help of the Cookies Policy Generator.
The Cookies We Set
Third Party Cookies
- Account related cookies
- If you create an account with us then we will use cookies for the management of the signup process and general administration. These cookies will usually be deleted when you log out however in some cases they may remain afterwards to remember your site preferences when logged out.
- Login related cookies
- We use cookies when you are logged in so that we can remember this fact. This prevents you from having to log in every single time you visit a new page. These cookies are typically removed or cleared when you log out to ensure that you can only access restricted features and areas when logged in.
- Orders processing related cookies
- This site offers e-commerce or payment facilities and some cookies are essential to ensure that your order is remembered between pages so that we can process it properly.
- Forms related cookies
- When you submit data to through a form such as those found on contact pages or comment forms cookies may be set to remember your user details for future correspondence.
- This site uses Google Analytics which is one of the most widespread and trusted analytics solution on the web for helping us to understand how you use the site and ways that we can improve your experience. These cookies may track things such as how long you spend on the site and the pages that you visit so we can continue to produce engaging content.For more information on Google Analytics cookies, see the official Google Analytics page.
- From time to time we test new features and make subtle changes to the way that the site is delivered. When we are still testing new features these cookies may be used to ensure that you receive a consistent experience whilst on the site whilst ensuring we understand which optimisations our users appreciate the most.
- The Google AdSense service we use to serve advertising uses a DoubleClick cookie to serve more relevant ads across the web and limit the number of times that a given ad is shown to you.For more information on Google AdSense see the official Google AdSense privacy FAQ.
In some special cases we also use cookies provided by trusted third parties. The following section details which third party cookies you might encounter through this site.
More Information
Hopefully that has clarified things for you and as was previously mentioned if there is something that you aren’t sure whether you need or not it’s usually safer to leave cookies enabled in case it does interact with one of the features you use on our site.
For more general information on cookies, please read the Cookies Policy article.
However if you are still looking for more information then you can contact us through one of our preferred contact methods: