What Information Do We Collect?
Personally-Identifiable Information: We may collect personally identifiable information when you specifically and knowingly provide it to us, for example when you request support, or register and provide personal information such as your e-mail address, name, phone number, year of birth, or other information. Where applicable, personally identifiable information includes “personal data”, “personal information” and/or “sensitive personal information” each as defined in applicable law. We ask that you not send us, and you do not disclose, any sensitive personal data (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through Services or otherwise. If you do send or disclose any sensitive personal data to us, you consent to our processing and use of such sensitive personal data in accordance with this Policy.
You may have the option to register using a TPS or connect your account to a TPS such as Instagram, Facebook, Twitter or YouTube. By authorizing us to access your TPS account, you understand that we may obtain certain information from your TPS account, you authorize us to obtain certain information from your TPS account, which may including your name, email address, birthday, work history, education history, current city, shared media, and the names, profile pictures, relationship status, and current cities of your TPS contacts. We only obtain information from your TPS account that you specifically authorize and grant us permission to obtain.
MD GLAM does not consider personally identifiable information to include information that has been anonymized so that it does not allow a third party to easily identify a specific individual. We collect and use your personally-identifiable information to: provide the Services; operate and improve our Service; provide customer service; perform research and analysis aimed at improving our products, Service and technology; and display content that is customized to your interests and preferences.
Sensitive Personal Data: Subject to the following paragraph, we ask that you not send us, and you not disclose, any sensitive personal data (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the Services or otherwise to us.
Non-Personally-Identifiable Information: We may collect and aggregate non-personally identifiable information which is information which does not permit you to be identified or identifiable either by itself or in combination with other information available to a third party. This information may include information, such as a website that referred you to us, your IP address, browser type and language, log data, hardware types, geographic location, and access times and durations. We also may collect navigational information, including information about the Service content or pages you view, the links you click, and other actions taken in connection with the Service.
Cookies, Pixels and Local Storage: We may collect information using “cookies”, which are small data files stored on the hard drive of your computer or mobile device by a website. We may use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your computer or mobile device until you delete them) to provide you with a more personal and interactive experience when using the Services.
We use two broad categories of cookies: (1) first party cookies, served directly by us to your computer or mobile device, which are used only by us to recognize your computer or mobile device when it revisits any site or application that is party of the Services; and (2) third party cookies, which are served by service providers on sites or applications and can be used by such service providers to recognize your computer or mobile device when it visits other websites.
Cookies we use
The Services use the following types of cookies for the purposes set out below:
Disabling cookies: You can typically remove or reject cookies via your browser settings. In order to do this, follow the instructions provided by your browser (usually located within the “settings,” “help” “tools” or “edit” facility). Many browsers are set to accept cookies until you change your settings. If you do not accept our cookies, you may experience some inconvenience in your use of the Services. For example, we may not be able to recognize your computer or mobile device and you may need to log in every time you use the Services.
Pixel Tags: We may also use pixel tags (which are also known as web beacons and clear GIFs) on the Services to track the actions of users on our sites and applications. Unlike cookies, which are stored on the hard drive of your computer or mobile device by a website, pixel tags are embedded invisibly on webpages. Pixel tags measure the success of our marketing campaigns and compile statistics about usage of the Services, so that we can manage our content more effectively. The information we collect using pixel tags is not linked to our users’ personal data.
Do Not Track Signals: Some Internet browsers may be configured to send "Do Not Track" signals to the online services that you visit. We currently do respond to do not track signals. To find out more about "Do Not Track," please visit https://allaboutdnt.com/.
What Do We Do With The Information That We Collect?
- to operate, maintain, and improve the Services;
- to manage your account, including to communicate with you regarding your account;
- to operate and administer any proposals, events, or promotions you participate in on any site or application;
- to respond to your comments and questions and to provide customer service;
- to send information including technical notices, updates, security alerts, and support and administrative messages;
- with your consent, to send you marketing e-mails about new proposals, opportunities, upcoming events, and other news, including information about products and services offered by us and our affiliates. You may opt-out of receiving such information at any time: such marketing emails tell you how to “opt-out.” Please note, even if you opt out of receiving marketing emails, we may still send you non-marketing emails. Non-marketing emails include emails about your account with us (if you have one) and our business dealings with you;
- to process payments you make via the Services; and
- We will only use access to read, write, modify or control Gmail message bodies (including attachments), metadata, headers, and settings to provide a web email client that allows users to compose, send, read, and process emails and will not transfer this Gmail data to others unless doing so is necessary to provide and improve these features, comply with applicable law, or as part of a merger, acquisition, or sale of assets.
- we will not use this Gmail data for serving advertisements.
- we will not allow humans to read this data unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes such as investigating abuse, to comply with applicable law, or for the App's internal operations when the data have been aggregated and anonymized.
We may share this information with service providers who perform services on our behalf, such as processing information requests, displaying stored data you access, to assist us in marketing, to conduct audits, etc. Those companies will be permitted to obtain only the personal information they need to provide the service they provide, will be required to maintain the confidentiality of the information, and will be prohibited from using it for any other purpose.
We may also use information you provide to better serve you, and, if you have given your consent for us to do so, to send you email or text messages concerning offers from our partners and other third parties that we think may be of interest to you. If you do not wish to receive marketing emails, you may adjust your “Personal Information Preferences” as described below or follow the “unsubscribe” or “stop” instructions included within each communication.
We will only retain your personally identifiable information as long as reasonably required to provide you with the Services unless a longer retention period is required or permitted by law (for example, for regulatory purposes). Data collected via the YouTube API will be retained for a maximum of 30 days unless required to provide you with the Services or a longer retention period is required by law.
You may contact us anytime to opt-out of: (i) direct marketing communications; (ii) our collection of sensitive personal data; (iii) any new processing of your personal data that we may carry out beyond the original purpose; or (iv) the transfer of your personal data outside the EEA. Please note that your use of some of the Services may be ineffective upon opt-out. You may also: (A) access the data we hold about you at any time via your account or by contacting us directly; (B) update or correct any inaccuracies in your personal data by contacting us; (C) move your data to other service provider; (D) in certain situations, for example when the data we hold about you is no longer relevant or is incorrect, you can request that we erase your data. You may contact us at privacy.support@MDGLAM.com anytime for any other questions you may have about your personally identifiable information and our use of it.
Disclosure: As a general rule, MD GLAM will not disclose any of your personally identifiable information except under one of the following circumstances: we have your permission; we determine in good faith that it is legally required to be revealed by any relevant statute, regulation, ordinance, rule, administrative or court order, decree, or subpoena; it is information that we determine must be disclosed to correct what we believe to be false or misleading information or to address activities that we believe to be manipulative, deceptive or otherwise a violation of law; where you are otherwise notified at the time we collect the data; where we need to share your information to provide the product or service you have requested; when such disclosure is made subject to confidentiality restrictions in connection with a sale, merger, transfer, exchange, or other disposition (whether of assets, stock, or otherwise) of all or a portion of the business conducted by MD GLAM. MD GLAM may share the non-personally identifiable information that MD GLAM gathers, in aggregate form only, with advertisers and other partners.
Consistent with applicable law, you may exercise any of the rights described in this section. See here for information on personal data rights requests and how to submit a request. Please note that we may ask you to verify your identity and request before taking action on your request.
Managing Your Information: If you have an Account, you may access and update some of your information through your Account settings. If you have connected your Account to a TPS you can change your settings and remove permission for the TPS app by changing your Account settings. You are responsible for keeping your personal information up-to-date.
Rectification of Inaccurate or Incomplete Information: You have the right to ask us to correct inaccurate or incomplete personal information about you (and which you cannot update yourself within your Account, if any).
Data Access and Portability: In some jurisdictions, applicable law may entitle you to request certain copies of your personal information held by us. You may also be entitled to request copies of personal information that you have provided to us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible).
Data Retention and Erasure: We generally retain your personal information for as long as is necessary for the performance of the contract between you and us and to comply with our legal obligations. In certain jurisdictions, you can request to have all your personal information deleted entirely. Please note that if you request the erasure of your personal information:
- We may retain some of your personal information as necessary for our legitimate business interests, such as fraud detection and prevention and enhancing safety. For example, if we suspend an Account for fraud or safety reasons, we may retain certain information from that Account to prevent that user from opening a new Account in the future.
- We may retain and use your personal information to the extent necessary to comply with our legal obligations. For example, for tax, legal reporting and auditing obligations.
- Information you have shared with others (e.g., Reviews, forum postings) may continue to be publicly visible on or through the Service, even after your Account is cancelled. Additionally, some copies of your information (e.g., log records) may remain in our database, but are disassociated from personal identifiers.
- Because we maintain the Service to protect from accidental or malicious loss and destruction, residual copies of your personal information may not be removed from our backup systems for a limited period of time.
- Withdrawing Consent and Restriction of Processing.
If we are processing your personal information based on your consent you may withdraw your consent at any time by changing your Account settings or by sending a communication to us specifying which consent you are withdrawing. Please note that the withdrawal of your consent does not affect the lawfulness of any processing activities based on such consent before its withdrawal. Additionally, in some jurisdictions, applicable law may give you the right to limit the ways in which we use your personal information, in particular where (i) you contest the accuracy of your personal information; (ii) the processing is unlawful and you oppose the erasure of your personal information; (iii) we no longer need your personal information for the purposes of the processing, but you require the information for the establishment, exercise or defense of legal claims; or (iv) you have objected to the processing pursuant to the next section and pending the verification whether our legitimate grounds override your own.
Objection to Processing: In some jurisdictions, applicable law may entitle you to require us not to process your personal information for certain specific purposes (including profiling) where such processing is based on legitimate interest. If you object to such processing we will no longer process your personal information for these purposes unless we can demonstrate compelling legitimate grounds for such processing or such processing is required for the establishment, exercise or defense of legal claims.
Where your personal information is processed for direct marketing purposes, you may, at any time ask us to cease processing your data for these direct marketing purposes by sending an e-mail to firstname.lastname@example.org.
Lodging Complaints: You have the right to lodge complaints about our data processing activities by filing a complaint with us via the “Contact Us” section below or with a supervisory authority.
The Terms of Service clearly provide that Users must be (i) 18 or older, or (ii) 13 and older if either (a) an emancipated minor, or (b) he/she possess legal parental or guardian consent. MD GLAM does not knowingly collect personally identifiable information from users under 13. In the event that we learn that we have collected any personal information from a user under the age of 13, we will attempt to identify and delete that information from our database.
California Privacy Rights
California law permits users who are California residents to request and obtain from us once a year, free of charge, a list of the third parties to whom we have disclosed their personal information (if any) for their direct marketing purposes in the prior calendar year, as well as the type of personal information disclosed to those third parties. See the “Contact Us” section below for where to send such requests.
Security and Encryption
We follow generally accepted industry standards to help protect your personal information. No method of transmission over the internet, mobile technology, or method of electronic storage, is completely secure. Therefore, while we endeavor to maintain physical, electronic, and procedural safeguards to protect the confidentiality of the information that we collect online, we cannot guarantee its absolute security. Our Service has security measures in place designed to protect against the loss, misuse and alteration of the information under our control. We use standard Secure Socket Layer (SSL) encryption that encodes information for such transmissions. All Service information is maintained on secure servers. Access to stored data is protected by multi-layered security controls including firewalls, role-based access controls and passwords. You are responsible to keep your password secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please immediately notify us of the problem by contacting us at email@example.com.
Changes to This Policy
For general inquires or to lodge a complaint, email us at firstname.lastname@example.org, or by mail to MD GLAM Data Inquiries, 400 Capitol Mall 9th Floor, Sacramento, CA 95814. To opt-out of use of your data for direct marketing, email us at email@example.com.
To deactivate your account, go to your Account, click Settings, and then click Deactivate my account.
Deactivating an Account and an Account deletion request are two different things. When you choose to deactivate your account, you can reactivate it at a later date if you wish; when you delete your Account, no deleted information can thereafter be recovered. You can request permanent deletion of your personal data and closure of your Account at any point by submitting a deletion request to firstname.lastname@example.org. We may ask you to verify your identity before taking action on your request. Please include the subject line “Personal Data Right Request - Deletion Request”, and your country of residence.
To access your data, you can visit the Dashboard of your Account. If you would like to get a copy of some or all of the personal data we hold about you pursuant to applicable law, you can send us an email to email@example.com. Please note that we may ask you to verify your identity before taking further action on your request. Please include the subject line “Personal Data Right Request - Access Request”, provide us your country of residence, and provide as much information as you have regarding the data you would like a copy of.
To exercise a right to portability under applicable law, please email us at firstname.lastname@example.org and include the subject line “Personal Data Right Request - Portability Request” and your country of residence.
To object to our processing of some of your personal data where allowed under the laws of the jurisdiction where you reside, you may request that we not process your personal information for certain specific purposes (including profiling) where such processing is based on legitimate interest. If you object to such processing, we will no longer process your personal information for these purposes unless we can demonstrate compelling legitimate grounds for such processing, or such processing is required for the establishment, exercise, or defense of legal claims. You may exercise your rights to object to processing by sending us an email to email@example.com. Please include the subject line “Personal Data Right Request – Processing Objection” and your country of residence.