Privacy Policy

Shopgate Privacy Policy

Last updated: August 12, 2019

This Privacy Policy is intended to help you understand how we collect, use, process, and disclose your personal data obtained via the Shopgate.com website including the country-specific web pages you may be directed to based on your location or IP address.

The Shopgate.com website is owned by Shopgate Inc. (hereinafter referred to as “we”, “us”, “Shopgate” or the “Company”), located in the United States. If you are located in the European Economic Area (EEA) or Switzerland, the terms of our GmbH Privacy Policy will also apply to you and is incorporated herein by reference.

This privacy policy does not cover the privacy practices of Shopgate merchants or other entities that use Shopgate services. If you are the customer of a merchant or other third party who uses a Shopgate mobile app on their phone, please refer to the privacy policy on that mobile app for information on how they may use and disclose your personal data.

Contacts

Responsible for this website:

Shopgate Inc.

2222 Rio Grande
Suite C300
Austin, TX 78705
E-Mail: office@shopgate.com
Phone: 800-490-2467

You can also contact our data protection officer via these contact details. If you have specific questions about your data, their deletion or your rights, you can contact them directly via the email address privacy@shopgate.com. If you want to submit a written request by post, the suffix “Privacy” is sufficient.

1. Rights

You can contact us at any time if you have any questions about your privacy rights or if you wish to exercise any of your rights below:

  • Right of withdrawal acc. Art. 7 para. 3 GDPR (for example, you can contact us if you wish to revoke a previously granted consent to a newsletter) . Please direct your revocation to privacy@shopgate.com .
  • Right to information acc. Art. 15 DSGVO (e.g. you can contact us if you want to know which data we have stored about you)
  • Correction acc. Art. 16 DSGVO (e.g. you can contact us if your email address has changed and we should replace the old email address.)
  • Deletion acc. Art. 17 GDPR (e.g. you can contact us if we should delete certain data that we have stored about you)
  • Restriction of processing acc. Art. 18 GDPR (e.g. you can contact us if you would like us not to delete your email address, but only to send essential emails.)
  • Data portability acc. Art. 20 DSGVO (e.g. you can contact us to receive your saved data in a compressed format, e.g. because you want to make the data available on another website.)
  • Contradiction gem. Art. 21 DSGVO (e.g. you can contact us if you do not agree with one of the advertising or analysis methods stated here.)
  • Complaint right with the responsible supervisory authority acc. Art. 77 para. 1 DSGVO (e.g. you can also contact the data protection supervisory authority directly if you have any complaints)

2. Data Collection and Use

You can visit our website without giving any personal information. We only store data that your browser transmits to enable you to visit the website, in so-called server log files, such as:

  • IP address (eg 95.91.215.example or 2a02: 8109: 9440: 1198: bdb1: 551f: example)
  • Approximate location based on IP range (e.g. Berlin & surrounding area)
  • Internet provider (e.g. AT&T or Spectrum)
  • Internet speed (eg 120 Mbit)
  • Date and time (e.g. 11:45 am 05.28.2018)
  • Last visited website (e.g. www.google.com)
  • Browser (e.g. Chrome or Safari)
  • Operating system (e.g Mac OS)
  • Hardware (e.g. Intel processor)

This data is stored solely to ensure trouble-free operation of the site and to improve our website and do not allow us to infer your identity.

Your IP address will not be saved by us. Thus, the other, technical data can not be traced back to you and are only anonymous, statistical purposes to optimize our website. The purpose of the temporary storage of the data at the beginning is to ensure the connection as well as accessibility and correct presentation of our website. The IP address and the technical data already mentioned are required to display the website, to avoid display problems for the visitors and to correct error messages. The legal basis is the so-called legitimate interest, which, within the framework of the abovementioned protective measures and in accordance with the European data protection requirements set out in Article 6 (1) lit. f DSGVO was examined.

We collect personal data if you voluntarily provide us with this within the scope of contacting us (e.g. by contact form or e-mail). The data collected is shown in the respective input forms.

To protect your privacy, the contact takes place – as well as the visit to the rest of the website – via an encrypted connection.

As a Shopgate customer you also have the option to sign up for a user account on our website.

3. Deletion of Data and Storage Duration

Unless otherwise stated, we will erase your information  when a period of retention required by law expires, unless there is a need to continue to store the data for a contract or fulfillment. Certain data may need to be kept longer for legal reasons. Of course, you can request information about the stored data at any time.

4. Newsletter

We use the so-called double opt-in procedure for providing our newsletter, so we will not email you a newsletter until you confirm that you have subscribed to our newsletter by clicking on a link in our notification email. If you confirm the request to receive the newsletter, we will save your email address until you unsubscribe from the newsletter. The sole purpose of the storage is to send you the newsletter.

Of course you can unsubscribe from our newsletter at any time, a link can be found in every newsletter. Alternatively, you can contact the above contact information.

Our newsletter is sent via Hubspot, based in Portsmouth, New Hampshire (U.S. office) and Dublin, Ireland (European HQ). We have concluded a contract processing contract with this service provider in accordance with the requirements of Art. 28 DSGVO. Other suitable guarantees for the transfer of data to other EU countries are available.

5. Cookies

In order to make a visit to our website attractive and to enable the use of certain functions, we use so-called cookies on various pages. Cookies are small text files that are usually stored in a folder on your browser. Cookies contain information about the current or last visit to the website:

  • Name of the website
  • Expiration date of the cookie
  • Any value

If cookies do not contain an exact expiration date, they are only cached and automatically deleted as soon as you close your browser or restart the device. Cookies with an expiration date are also saved when you close your browser or restart the device. Such cookies will not be removed until the specified date or if you delete them manually.

On our website we use the following three types of cookies:

  1. Required cookies (which we need, for example, in order to display the website correctly for you and to cache certain settings)
  2. Function and performance-related cookies (these help us, for example, to evaluate the technical data of your visit and thus avoid error messages)
  3. Advertising and analytics cookies (these ensure that, for example, advertising for shoes is displayed if you have previously searched for shoes)

You can configure, block and delete cookies in your browser settings. If you delete all cookies on our website, it may be that some functions of the website are not displayed correctly. The Federal Office for Information Security provides helpful information and instructions for common browsers:

https://www.bsi-fuer-buerger.de/BSIFB/DE/Empfehlungen/EinrichtungSoftware/EinrichtungBrowser/Sicherheitsmassnahmen/Cookies/cookies_node.html 

6. Google Analytics / Adsense

We use Google Analytics and Google Adsense, a web analytics service provided by Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA („Google“). Google Analytics uses the advertising and analytics cookies described above to analyze our website for your usage behavior. The information generated by cookies on the use of this website is transmitted to a Google server in the USA and stored there. However, your IP address will be truncated before the usage statistics are evaluated so that no conclusions can be drawn about you. For this purpose, Google Analytics has been enhanced on our website with the code „anonymizeIp“ to ensure an anonymous collection of IP addresses. Google will use the anonymised information obtained through the cookies, to evaluate your use of the website, to compile reports on website activity for website operators, and to provide other services related to website usage and internet usage. Google will also transfer this information to third parties if required by law or if third parties process this data on behalf of Google.

You can also configure your browser to refuse cookies, or you can prevent Google from collecting and analyzing the data by using a browser plug-in (https://tools.google.com/dlpage/gaoptout?hl=de Download and install from Google.

As protective measures we use Google’s anonymization process, which means that subsequent analysis of the data is not based on your personal data, but only on a statistical basis. In addition, the high security standards of the Google platform and the associated privacy policy of Google (http://www.google.com/intl/de-DE/privacy) apply. We have also entered into a special data protection agreement with Google, which stipulates the protection of your data through technical and organizational protection measures. Since Google is based in the US and thus in a so-called third country, further guarantees are required to ensure an adequate level of European data protection.

The purpose of using Google Analytics is the anonymous analysis of your usage behavior on our websites. The insights gained help to improve our offer. The legal basis is the so-called legitimate interest, which for the pursuit of the purpose and in the context of the aforementioned protective measures and in accordance with the European data protection requirements from Art. 6 para. 1 lit. f DSGVO was examined. In addition, a contract processing contract was concluded in accordance with the requirements of Art. 28 DSGVO.

7. Google Adwords

We use the Google AdWords online advertising program and conversion tracking as part of Google AdWords. Google Conversion Tracking is an analytics service provided by Google Inc. (1600 Amphitheater Parkway, Mountain View, CA 94043, USA; “Google”). When you click on an ad served by Google, a conversion tracking cookie will be placed on your machine. These cookies lose their validity after 30 days, contain no personal data and are therefore not used for personal identification.

If you visit certain web pages on our website and the cookie has not expired, Google and we may recognize that you have clicked on the ad and have been redirected to this page. Each Google AdWords customer receives a different cookie. Thus, there is no way that cookies can be tracked through the websites of advertisers.

The information gathered using the conversion cookie is used to generate conversion statistics for AdWords advertisers who have opted for conversion tracking. It tells customers the total number of users who clicked on their ad and were redirected to a conversion tracking tag page. However, they do not receive any information that personally identifies users.

If you do not want to participate in the tracking, you can object to this use by preventing the installation of cookies by a corresponding setting of your browser software (deactivation option). You will not be included in the conversion tracking statistics. For more information and Google’s privacy policy, please visit: http://www.google.com/policies/technologies/ads/ , http://www.google.com/policies/privacy/

8. Privacy Policy – Facebook Business Page

For the information service offered here, this fan page uses the technical platform and services of Facebook Inc., 1601 S. California Ave., Palo Alto. CA 94304, USA (“Facebook”).

About this fan page personal data, as well as website / usage data of Facebook are collected. However, we, Shopgate Inc. and Shopgate GmbH, use this data exclusively on anonymized and statistical basis.

Joint processing of personal data:

The data processing on our Facebook pages is based on an agreement on joint processing of personal data. Further information on Facebook’s data processing can be found in the privacy policy https://www.facebook.com/about/privacy/ . Facebook, a US-based company, is certified under the EU-US Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active .

Purpose of processing:

The data of the users are processed for market research and advertising purposes. For example, user profiles can be created from the user behavior and resulting user interests. The usage profiles can be used, for example, to display advertisements inside and outside the platforms, which may correspond to the interests of the users. For these purposes, cookies are usually stored on the computers of the users, in which the user behavior and the interests of the users are stored.

Legal basis for processing:

The processing of personal data of users is based on our legitimate interests in an effective information of users and communication with users in accordance with. Art. 6 para. 1 lit. f. DSGVO. If you want to object to the data processing, the user has the option of objecting or the use can be terminated. OptOut: https://www.facebook.com/settings?tab=ads and http://www.youronlinechoices.com.

Your rights:

Request for information and the assertion of further data subject rights, we point out that these can be claimed most effectively on Facebook. For this purpose, Facebook provides an information portal that allows access to the data collected by Facebook and that can be downloaded: https://www.facebook.com/help/1701730696756992?helpref=hc_global_nav . Only Facebook has access to users‘ data and can directly take appropriate action and provide information. If you still need help, then you can contact us. You can find more information about your rights and our company in our privacy policy at: https://www.shopgate.com/de/datenschutz/ There you will also find the contact details of our data protection officer.

Facebook Remarketing

We use the remarketing capabilities of Facebook Inc., 1601 S. California Ave., Palo Alto. CA 94304, USA (“Facebook”). Using this feature, the provider can target advertisers to the website by displaying personalized, interest-based Facebook ads to visitors to the site when they visit the Facebook social network. To perform the feature, Facebook will implement our remarketing tag on our website.

These tags create a direct link to the Facebook servers when you visit the site. This will be transmitted to the Facebook server, which of our websites you have visited. Facebook assigns this information to your personal Facebook user account. For more information on the collection and use of data by Facebook, about your rights in this regard and ways to protect your privacy, please refer to the privacy policy of Facebook at  https://www.facebook.com/about/privacy/ . If you do not want Facebook to associate the collected information directly with your Facebook user account, you can disable the remarketing „Custom Audiences“ feature  here . You have to be logged in to Facebook.

To protect your privacy , you can choose to have the collected information associated directly with your Facebook user account by disabling the remarketing “Custom Audiences“ feature here . You have to be logged in to Facebook. Because some of the Facebook services are located in the United States, and therefore in a country outside the EU and the EEA (in a third country), further safeguards are required to ensure that your data is protected in accordance with a European level of data protection. Facebook is certified according to the EU-US Privacy Shield for advertising-related services and has thus demonstrated a sufficient level of data protection (https://www.facebook.com/about/privacyshield). The purpose The use of this offer is the viewing of anonymous usage statistics about our users and the presentation of personalized advertisements tailored to the interests of the users. The legal basis is the so-called legitimate interest, which for the pursuit of the purpose and in the context of the aforementioned protective measures and in accordance with the European data protection requirements from Art. 6 para. 1 lit. f DSGVO was examined.

9. Social plugins

On our blog you will find so-called social plugins of external social networks, which you can recognize by the well-known logos:

Facebook (Facebook Inc., 1601 S. California Avenue, Palo Alto, CA 94304, USA ), Privacy Policy

Twitter (Twitter, Inc., 795 Folsom St. , Suite 600, San Francisco, CA 94107, USA), Privacy Policy

LinkedIn (1000 W Maude, Sunnyvale, CA 94085, USA), Privacy Policy

Xing (XING AG, Dammtorstrasse 30, 20354 Hamburg, Germany ), privacy policy

When you visit an article or page on our blog that contains such social plug-ins, you will be connected to the servers of the respective social networks and will be shown the respective function for sharing or publishing to the social network. If you are already logged in to the respective social network, the information is transferred to you that you visit our site and respective providers can assign this information to your user account. If you interact with the social plugins, eg using the Facebook “Like” or Twitter “Tweet This” function, the contents of our pages will be linked to your Facebook or Twitter profile.

If you are not a member of the respective social networks or have logged off before visiting our website with the providers, there is still the possibility that at least your IP address is transmitted and stored there at least in anonymized. For reasons of transparency, we would like to point out that these data are processed directly by the social networks and, for example, the storage duration of up to 250 days is determined exclusively by the respective providers. For more information, see the privacy policies of the social network above.

The legal basis for integrating these social plugins is the legitimate interest of Art. 6 para. 1 lit. f DSGVO to integrate the popular features of our users on our blog to provide the advanced features of their social networks. A large part of the visitors of our website have an interest in these functions, which enjoy lively use and facilitate an easy connection with their own profile and a sharing of information with friends or acquaintances.

10. Applications

If you respond to one of the open job applications or to one of our job advertisements, we collect and process the personal applicant data for the purpose of processing the application process. There is an electronic processing of the data, if an applicant submits corresponding application documents by electronic means, for example by e-mail or via the form on the website. We use HR software called JazzHR (operated by Hireku, Inc., 610, Lincoln St # 205, Waltham, MA 02451 ) to handle the entire application process . As the location of the service provider is located in the USA, we attach great importance to secure data transmission and storage. The company is EU-US Privacy Shield certified and we have a contract processing contract that ensures that the data is processed only to our specifications. If we conclude a contract of employment with an applicant, the transmitted data will be stored for the purpose of the employment relationship in compliance with the legal requirements. If no employment contract is concluded with the applicant, the application documents shall be kept for a maximum of six months after the announcement of the rejection decision and thereafter deleted. This storage period is primarily due to mutual interests in the context of any claims under § 15 (4) of the General Equal Treatment Act (AGG). The application documents will only be kept longer if the applicant has given his express consent to do so.

If you apply via the LinkedIn or Indeed external platforms, we will gain access to your profile with personally identifiable information you have provided yourself on each platform. What data exactly, you learn in a very transparent way before you connect to the respective platform. You always have the possibility to disconnect from these platforms and to prevent access by us. More information on this and the data protection of the respective platform can be found at https://privacy.linkedin.com/en-us (when applying via LinkedIn) or https://de.indeed.com/legal#privacy (when applying for a job via Indeed).

The legal basis for the above-mentioned storage and processing of the application documents is § 26 Abs. 1 BDSG-new, since the purpose of the application process is the recruitment or rejection of the applicant. The application process in this form is therefore absolutely necessary in the course of recruitment. Legal basis in the context of the application via the external platforms described above, your consent in accordance with the European data protection provisions in accordance with Art. 6 para. 1 lit. a DSGVO. You can cancel it at any time by disconnecting from the platform or by sending us a message.