WHAT INFORMATION DO WE COLLECT AND HOW IS IT USED?
- Information You Voluntarily Submit to the Website: We may collect personal information from you such as your name or email address. For example, you may voluntarily submit information to the Website by leaving a comment, subscribing to a newsletter, or submitting a contact form.
- Information We Collect from Others: We may receive information about you from other sources. For example, if you use a third-party software through the site, they may transfer information to us for fulfillment.
- Automatically-Collected Information: We automatically collect certain information about you and the device with which you access the Website. For example, when you use the Website, we will log your IP address, operating system type, browser type, referring website, pages you viewed, and the dates/times when you accessed the Website. We may also collect information about actions you take when using the Website, such as links clicked.
- Cookies: We may log information using cookies, which are small data files stored on your browser by the Website. We may use both session cookies, which expire when you close your browser, and persistent cookies, which stay on your browser until deleted, to provide you with a more personalized experience on the Website.
HOW YOUR INFORMATION MAY BE USED
We may use the information collected in the following ways:
- To operate and maintain the Website;
- To send you promotional information, such as newsletters. Each email promotion will provide information on how to opt-out of future mailings;
- To send you administrative communications, such as administrative emails, confirmation emails, technical notices, updates on policies, or security alerts;
- To respond to your comments or inquiries;
- To provide you with user support;
- To track and measure advertising on the Website;
- To protect, investigate, and deter against unauthorized or illegal activity.
THIRD-PARTY USE OF PERSONAL INFORMATION
We may share your information with third parties when you explicitly authorize us to share your information.
Additionally, the Website may use third-party service providers to service various aspects of the Website. Each third-party service provider’s use of your personal information is dictated by their respective privacy policies. The Website currently uses the following third-party service providers:
- Google Analytics – this service tracks Website usage and provides information such as referring websites and user actions on the Website. Google Analytics may capture your IP address, but no other personal information is captured by Google Analytics. For more information on Google’s Analytics privacy policies, please visit this site
- Easy Affiliate Links – When enabled, we track affiliate link clicks for analytic purposes. These include a (optionally hashed) IP address and user ID (when logged in). Click information is retained in the local database indefinitely for analytic purposes and optional export.
Image views are only recorded if the site owner, has explicitly enabled image view stats tracking for this feature via the jetpack_enable_carousel_stats filter.
Data Used: If image view tracking is enabled, the following information is used: IP address, WordPress.com user ID (if logged in), WordPress.com username (if logged in), user agent, visiting URL, referring URL, timestamp of event, browser language, country code.
Activity Tracked: Image views.
Data Used: If Akismet is enabled on the site, the contact form submission data — IP address, user agent, name, email address, website, and message — is submitted to the Akismet service (also owned by Automattic) for the sole purpose of spam checking. The actual submission data is stored in the database of the site on which it was submitted and is emailed directly to the owner of the form (i.e. the site author who published the page on which the contact form resides). This email will include the submitter’s IP address, timestamp, name, email address, website, and message.
Data Synced (?): Post and post meta data associated with a user’s contact form submission. If Akismet is enabled on the site, the IP address and user agent originally submitted with the comment are synced, as well, as they are stored in post meta.
Data Used: This feature will send a hash of the user’s email address (if logged in to the site or WordPress.com — or if they submitted a comment on the site using their email address that is attached to an active Gravatar profile) to the Gravatar service (also owned by Automattic) in order to retrieve their profile image.
Data Used: In order to record page views via WordPress.com Stats (which must be enabled for page view tracking here to work) with additional loads, the following information is used: IP address, WordPress.com user ID (if logged in), WordPress.com username (if logged in), user agent, visiting URL, referring URL, timestamp of event, browser language, country code.
Activity Tracked: Page views will be tracked with each additional load (i.e. when you scroll down to the bottom of the page and a new set of posts loads automatically). If the site owner has enabled Google Analytics to work with this feature, a page view event will also be sent to the appropriate Google Analytics account with each additional load.
Data Used: A visitor’s preference on viewing the mobile version of a site.
Activity Tracked: A cookie (akm_mobile) is stored for 3.5 days to remember whether or not a visitor of the site wishes to view its mobile version. Learn more about this cookie.
This feature is only accessible to registered users of the site who are logged in to WordPress.com.
Data Used: IP address, WordPress.com user ID, WordPress.com username, WordPress.com-connected site ID and URL, Jetpack version, user agent, visiting URL, referring URL, timestamp of event, browser language, country code. Some visitor-related information or activity may be sent to the site owner via this feature. This may include: email address, WordPress.com username, site URL, email address, comment content, follow actions, etc.
Activity Tracked: Sending notifications (i.e. when we send a notification to a particular user), opening notifications (i.e. when a user opens a notification that they receive), performing an action from within the notification panel (e.g. liking a comment or marking a comment as spam), and clicking on any link from within the notification panel/interface.
Data Used: In order to check login activity and potentially block fraudulent attempts, the following information is used: attempting user’s IP address, attempting user’s email address/username (i.e. according to the value they were attempting to use during the login process), and all IP-related HTTP headers attached to the attempting user.
Activity Tracked: Failed login attempts (these include IP address and user agent). We also set a cookie (jpp_math_pass) for 1 day to remember if/when a user has successfully completed a math captcha to prove that they’re a real human. Learn more about this cookie.
Data Synced (?): Failed login attempts, which contain the user’s IP address, attempted username or email address, and user agent information.
Data Used: Any of the visitor-chosen search filters and query data in order to process a search request on the WordPress.com servers.
WordPress.com Secure Sign On
This feature is only accessible to registered users of the site with WordPress.com accounts.
Data Used: User ID (local site and WordPress.com), role (e.g. administrator), email address, username and display name. Additionally, for activity tracking (see below): IP address, WordPress.com user ID, WordPress.com username, WordPress.com-connected site ID and URL, Jetpack version, user agent, visiting URL, referring URL, timestamp of event, browser language, country code.
Activity Tracked: The following usage events are recorded: starting the login process, completing the login process, failing the login process, successfully being redirected after login, and failing to be redirected after login. Several functionality cookies are also set, and these are detailed explicitly in our Cookie documentation.
Data Synced (?): The user ID and role of any user who successfully signed in via this feature.
Data Used: IP address, WordPress.com user ID (if logged in), WordPress.com username (if logged in), user agent, visiting URL, referring URL, timestamp of event, browser language, country code. Important: The site owner does not have access to any of this information via this feature. For example, a site owner can see that a specific post has 285 views, but he/she cannot see which specific users/accounts viewed that post. Stats logs — containing visitor IP addresses and WordPress.com usernames (if available) — are retained by Automattic for 28 days and are used for the sole purpose of powering this feature.
This feature is only accessible to registered users of the site who are also logged in to WordPress.com.
Data Used: Gravatar image URL of the logged-in user in order to display it in the toolbar and the WordPress.com user ID of the logged-in user. Additionally, for activity tracking (detailed below): IP address, WordPress.com user ID, WordPress.com username, WordPress.com-connected site ID and URL, Jetpack version, user agent, visiting URL, referring URL, timestamp of event, browser language, country code.
Activity Tracked: Click actions within the toolbar
We’ve always valued privacy at our core here at Gleam and have built the platform always in alignment with the Australian Privacy Act (which shares many common requirements with GDPR) to:
- Implement a privacy by design approach to compliance
- Be able to demonstrate compliance with privacy principles and obligations
- Adopt transparent information handling practices
Gleam by nature is a consent based platform, users specifically give consent to enter campaigns and the data they provide is only ever shared with the owner of the campaign. So Gleam acts as a Data Processor on behalf of the customer (Data Controller).
For example, when a user enters a campaign that validates an entry via an API, this data is often only used at the point of validation and never stored on Gleam or shared with Customers.
We understand that as a popular platform in the space we must always maintain a high level of privacy and trust across both customers and their users.
So, as a global business it’s important that we align ourselves with GDPR and also assist our customers to ensure that they are compliant with GDPR when running campaigns.
Upcoming changes that we will be rolling out:
- We’ve appointed a Data Protection Officer
- You can now contact us directly via firstname.lastname@example.org to discuss any specific concerns
- New Data Processing Agreement: Since we store data in the USA (in an EU Privacy Shield-Compliant facility) we will be updating our agreement with EU customers detailing how we process their data
- Right to be forgotten: We have always honored this since our inception, we allow anyone to request for their account or data to be deleted. For campaign owners, you already have the power to delete contestants if they exercise this request to you directly
- Any reactionary changes based on GDPR rollouts from any service that we integrate with (to comply with their policies)
- Continent targeting for all campaign types to include or exclude EU (or other continents from campaigns)
- Improving the ability to obtain additional consent on Subscribe actions
- Improving the ability to obtain additional consent via checkboxes in Capture
- EU users will no longer be able to have Custom Fields checkboxes auto select
- Rolling out new Guides to help customers understand how to ensure their campaigns are GDPR compliant
- Helping customers understand which users have or have not given prior consent in previous campaigns
- Helping customers understand the 3rd parties that we have data processing agreements with (i.e. Mailchimp)
You can expect these changes to roll out before 25th May 2018, we’re looking forward to continuing providing a platform that lets you run campaigns in a way that helps you achieve business outcomes whilst protecting the privacy of users.
At this time, your personal information is not shared with any other third-party applications. This list may be amended from time to time in the Website’s sole discretion.
Except when required by law, we will not sell, distribute, or reveal your email addresses or other personal information without your consent; however, we may disclose or transfer personal information collected through the Website to third parties who acquire all or a portion of our business, which may be the result of a merger, consolidation, or purchase of all or a portion of our assets, or in connection with any bankruptcy or reorganization proceeding brought by or against us.
From time to time, we may use anonymous data, which does not identify you alone, or when combined with data from other parties. This type of anonymous data may be provided to other parties for marketing, advertising, or other uses. Examples of this anonymous data may include analytics or information collected from cookies.
PUBLICLY VISIBLE INFORMATION
If you leave a comment, certain information may be publicly visible.
Users may, at any time, prevent the setting of cookies, by the Website, by using a corresponding setting of your internet browser and may thus permanently deny the setting of cookies. Furthermore, already set cookies may be deleted at any time via an Internet browser or other software programs. This is possible in all popular Internet browsers. However, if users deactivate the setting of cookies in your Internet browser, not all functions of our Website may be entirely usable.
Sponsored Content Tracking PixelsThis Website may engage in sponsored campaigns with various influencer networks, brands, and agencies. All sponsored content is duly disclosed in accordance with the FTC’s requirements. From time to time, these sponsored campaigns utilize tracking pixels (aka web beacons), which may contain cookies to collect data regarding usage and audience. This information is collected by the sponsoring company to track the results of the campaign. No personally identifiable information collected by the Website is used in conjunction with these tracking pixels.
Affiliate Program ParticipationThe Website may engage in affiliate marketing, which is done by embedding tracking links into the Website. If you click on a link for an affiliate partnership, a cookie will be placed on your browser to track any sales for purposes of commissions.
Danny’s Nature Blog is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and links to Amazon.com. As part of this Amazon Associates program, the Website will post customized links, provided by Amazon, to track the referrals to their website. This program utilizes cookies to track visits for the purposes of assigning commission on these sales.
On the Website, you may subscribe to our newsletter, which may be used for advertising purposes. All newsletters sent may contain tracking pixels. The pixel is embedded in emails and allows an analysis of the success of online marketing campaigns. Because of these tracking pixels, we may see if and when you open an email and which links within the email you click. Also, this allows the Website to adapt the content of future newsletters to the interests of the user. This behavior will not be passed on to third parties.
RIGHTS RELATED TO YOUR PERSONAL INFORMATION
Opt-out – You may opt-out of future email communications by following the unsubscribe links in our emails. You may also notify us at email@example.com to be removed from our mailing list.
Access – You may access the personal information we have about you by submitting a request to firstname.lastname@example.org
Amend – You may contact us at email@example.com to amend or update your personal information.
Forget – In certain situations, you may request that we erase or forget your personal data. To do so, please submit a request to firstname.lastname@example.org
Please note that we may need to retain certain information for record keeping purposes or to complete transactions, or when required by law.
SENSITIVE PERSONAL INFORMATION
The Website does not knowingly collect any personally identifiable information from children under the age of 16. If a parent or guardian believes that the Website has personally identifiable information of a child under the age of 16 in its database, please contact us immediately at email@example.com and we will use our best efforts to promptly remove such information from our records.