Last Revised: May 24, 2018
Lovepop (“Lovepop”, “we”, “us” or “our”) spends a lot of time thinking about what is important to you. We know that includes making the most of birthdays and holidays, spectacular paper sculptures, bloom-filled trees, and sharing unexpected Magical Moments with the people you love.
We also know your privacy is very important to you. It is to us, too.
LovePop Inc. of 125 Lincoln St. Boston, MA 02111, USA, is the data controller responsible for the Websites and any handling of Personal Information by Lovepop.
We have appointed as our representative pursuant to article 27 of the GDPR the French law firm Foley Hoag AARPI, Avocats au Barreau de Paris, 153 rue du Faubourg Saint Honoré, 75008 Paris, France. You can contact the personnel at LovePop Inc. responsible for the protection of Personal Information at the following email address: email@example.com.
Our Websites are directed to and structured to attract Users over age 18. If you are under age 18, you are not permitted to use our Websites. If you are a parent with concerns about children’s privacy issues in conjunction with the use of the Sites, please contact us at firstname.lastname@example.org.
INFORMATION WE COLLECT
We collect a variety of information about our Users, in different ways.
Information You Provide To Us
We collect Personal Information that you provide to us by, for example, filling out a form, registering for an account, making a purchase, or contacting us. We collect Personal Information you provide to us in several ways, including:
Information Collected Automatically
When you visit our Websites, we may automatically collect certain information, namely:
Information from Other Sources
From time to time, we may acquire additional information about our Users from third parties, such as the Postal Service and third parties that assist us in the provision of products and services requested by you. This may include third-party analytics providers and advertising networks.
OUR USE OF INFORMATION
We use the Personal Information that we collect for various purposes.
We use it to generate your orders and fulfill the orders you place.
We use Personal Information to carry out our legitimate interests. These include:
We use Personal Information to fulfill our legal obligations, like keeping records for compliance purposes.
And, we use Personal Information to provide you, or permit selected third parties to provide you, information about products and services we feel may interest you, but only if you have consented to receiving these communications.
We may also combine the information which you provide to us (such as your registration details) with information which we collect about you (such as information about your orders) and/or receive from other sources, and use this combined information for the purposes set out above.
Lovepop uses third party payment processors Shopify, Stripe, Amazon Pay and PayPal to process payments made for products and services via the Websites. All online payments will be conducted in accordance with Payment Card Industry (PCI) data security standards. Your billing information (which is only used by these payment processors for fraud protection) is encrypted before being communicated to them. Subject to the below exceptions, your credit card details are communicated directly from your browser to these payment processors - Lovepop never sees your full Permanent Account Number (PAN).
Shopify, Inc. provides us with the online e-commerce platform that allows us to sell our products and services to you. Some of your Personal Information is stored through Shopify’s data storage, databases and the general Shopify application. Shopify stores your data on a secure server behind a firewall.
If you use a credit card to make a purchase (with the exception of wedding and membership purchases, which are discussed below), then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
We use Stripe, Inc. to process payments for wedding or membership purchases. For Stripe payments, if on the payment page you have requested that your card details be remembered and the payment was successful, Lovepop stores the card type, a Masked PAN (only the first 6 and last 4 digits) and the card’s expiration date as well as an associated token. This information is stored by us so that you and we can identify your stored card and use it for further payments at Lovepop. This stored information can be deleted via the payment form on the Website should you wish to do so. We also store separately the last 4 digits and card type so that we can identify transactions made by a particular card.
Pay Pal, Amazon Pay and Apple Pay
If you choose to pay with PayPal, Amazon Pay or Apple Pay, we only store the tokens required to identify the transaction, issue refunds and identify transactions.
Cookies are text files containing small amounts of information which are downloaded to your personal computer, mobile or other device when you visit a website. Cookies are then sent back to the originating website on each subsequent visit, or to another website that recognizes that cookie. You can find more information about cookies generally at www.allaboutcookies.org and www.youronlinechoices.eu.
Types of Cookies We Use
We use the following categories of cookies on our Websites.
Strictly Necessary Cookies
These cookies are essential to enable you to move around the Websites and use its features, such as accessing secure areas of the Websites. Without these cookies, services you have asked for, like check out, cannot be provided.
These cookies collect information about how visitors use the Websites, for instance which pages visitors go to most often, and if they get error messages from web pages. These cookies don't collect information that identifies a visitor. All information these cookies collect is aggregated and therefore anonymous. It is only used to improve how the Websites work.
These cookies allow the Websites to remember choices you make (such as your user name) and provide enhanced, more personal features. They may also be used to provide services you have asked for such as watching a video or commenting on a blog.
Target Or Advertising Cookies
These cookies collect information about your browsing habits to make advertising delivered to you more relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising. They are usually placed by advertising networks with our permission. They remember what you have looked at on our site, and we may share this information with other organizations such as advertisers.
Not all advertising you may see from us is a result of target or advertising cookies. We purchase ad space in different places that you may come across, even if you have disabled target or advertising cookies.
More information on target and advertising cookies, including how you can disable these technologies, is available at www.aboutads.info/consumers.
Third Party Cookies
When you use our Websites, your device or browser may be sent cookies from third parties, for example when using embedded content and social network links. We have no access to or control over cookies used by these companies or third party websites. We suggest you check the third party websites for more information about their cookies and how to manage them.
How To Manage Cookies
The Help menu on the menu bar of most browsers will tell you how to enable or prevent your browser from accepting new cookies, how to have the browser notify you when you receive a new cookie and how to disable cookies altogether. Information on changing cookie setting for commonly used browsers can be found at www.allaboutcookies.org/manage-cookies/index.html.
DISCLOSURE OF INFORMATION
We may disclose information about our Users to third parties consistent with this Policy.
In order to carry out certain business functions, such as order fulfillment, payment processing, e-mail delivery, or marketing, we may hire other companies to perform services on our behalf (“Service Providers”). We may disclose Personal Information that we collect to these companies to enable them to perform these services. By way of example, information relating to your order which we have combined with other Personal Information (as explained above) may be shared with our third party service providers that assist us with our marketing efforts. We do not disclose to Service Providers more Personal Information than is necessary to carry out the service that they provide, and require Service Providers to keep Personal Information confidential.
Third Party Partners
We may partner with third parties to provide you with information about products or services that we feel may be of interest to you. We will only disclose your Personal Information to such third parties if you have consented to receiving such information.
Law Enforcement, Protection of Lovepop, Users, and Others
We may also disclose Personal Information in other circumstances as required by law. We also reserve the right to disclose your Personal Information when we believe such disclosure is appropriate to cooperate with an investigation of activities claimed to be unlawful, to enforce our Terms of Service, or to protect the rights or property of Lovepop or others.
In addition, it is possible that in the future another company may acquire Lovepop or its assets or that Lovepop may partner with or purchase another company to continue to do business as a combined entity. In the event that any such transaction occurs, it is possible that Personal Information, may be transferred to the new business entity as one of Lovepop’s assets. In such an event, we will update this policy to reflect any change in ownership or control of your Personal Information.
WHERE WE STORE DATA
Lovepop transfers, processes and stores data about you on servers located in the United States. We use data processors, however, that may store or process your data in a different country. Your Personal Information may therefore be transferred to, processed and stored in a country different from your country of residence, and be subject to privacy laws that are different from those in your country of residence. Information collected within the European Economic Area (“EEA”) and Switzerland may, for example, be transferred to and processed by third parties located in a country outside of the EEA and Switzerland, where you may have fewer rights in relation to your Personal Information. By using the Website and providing us with your Personal Information, you are consenting to the transfer, processing and storage of your Personal Information in countries outside of your country of residence.
THIRD PARTY PRODUCTS AND SERVICES
While you are visiting or using the Websites, you may be presented with an opportunity to purchase third party products or services. These products and services are offered and supplied by independent companies. If you click on one of the presented offers, you will be redirected to the site of the third party, and any information you provide in response to the offer will be will be governed by the privacy and other policies of that third party. We do not guarantee the security of your Personal Information when using such third party sites or that the operator of such third party sites will comply with applicable data protection laws and regulations.
Communications from Lovepop
If you do not want to receive email communications from Lovepop about our own or third-party products and services that may be of interest to you, you can update your preferences in the My Account section of our Websites. You can also click on the unsubscribe link at the bottom of one of our emails. We may still contact you via mail or phone, unless you request to be added to our Do-Not-Call list, and/or our Do-Not-Mail list by contacting us using the below details and indicating your preferences. Please be sure to provide your exact name, e-mail address, mailing address and telephone number(s) and the list or lists you would like to be included on (Do-Not-Call, and/or Do-Not-Mail).
Even if you opt-out of email marketing or choose to be placed on one of these lists, we may still communicate with you using any of these methods for those non-marketing purposes set out above in the ‘Our Use of Information’ section.
Deactivation Of Your Account
You may request deactivation of your Lovepop account by contacting us using the contact information below and requesting deactivation. Please note that you Personal Information may remain in our archived records after your account has been deactivated, but we will not keep it for longer than necessary to fulfill the purposes described above.
Retention and Deletion
We retain Personal Information for as long as useful or permitted to further the purposes of collection. You can request deletion of your Personal Information. We provide information on how to do that below. Remember, though, that even if you request deletion of your information, we may keep certain information for a time after your deletion request to comply with legal or recordkeeping requirements. Also, we may not always be able to delete all of your information because of technical or other constraints.
Updating And Access To Your Personal Information
If you wish to change your name, e-mail address, password, and/or communication preferences after you have registered, you can access your account in the My Account section of the Websites. You may also request these changes by contacting us using the below details.
For European Union Residents
If you are a resident of the European Union, you have several additional rights regarding personal information:
When you establish an account at Lovepop, you choose a password to help protect your account information. A password is only as strong as you make it: you should select a unique password and keep it safe. You may change your password as often as you wish by going to My Account section of the Website. You are responsible for keeping this password confidential. We ask you not to share a password with anyone. Our sign-in process is designed to help protect your privacy. If you have trouble signing in to our Websites, please ensure that you are using your registered e-mail address and correct password. If you are using your registered e-mail address and correct password, and you continue to have trouble signing in to our Website, please contact us using the details below.
Notwithstanding the above, unfortunately, the transmission of information via the internet is not completely secure. Although we employ commercially reasonable safeguards to protect your Personal Information, we cannot guarantee the security of your data transmitted to our Websites; any transmission is at your own risk.
LOVEPOP CONTACT DETAILS
If you need to contact Lovepop about privacy or this policy:
125 Lincoln Street
Boston, MA 02111
When writing to us, please be sure to include your exact name, mailing address, telephone number and specific preferences or request.