1. OVERVIEW

The Privacy Stack empowers developers to bring the right set of privacy controls to their unique product architecture, enabling a quick and clear implementation of privacy-by-design.

This Privacy Policy explains how The Privacy Stack. (“The Privacy Stack”, “we” or “us”) processes personal information through our websites, applications, tools, services, and platform (collectively, the “Services”) and through other interactions you may have with The Privacy Stack. 

By accessing or using the Services, you are agreeing to this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Services.

You should read our full Privacy Policy to understand what data we collect, how we use it, and the circumstances where we may share it. Please note that if you reside outside the US, information collected through our Services will be transferred to and processed in the US or elsewhere. By using our Services, you consent to any transfer and processing in accordance with this Privacy Policy. If you have any questions, please contact us at contact@theprivacystack.org.

This Privacy Policy may change over time. If we make changes to it, we will post the modified Privacy Policy on our website, theprivacystack.org/privacy-policy. We encourage you to visit this page periodically to learn of any updates.

2. WHAT INFORMATION WE COLLECT

We collect personal information (or personal data) and non-personal information from you when you use our Services or otherwise interact with us. As further described in this section, we may receive personal information about you that you submit through the Services or that is provided to us by a third party; we also may receive personal information about you automatically as you use the Services.

Information You Submit.

We receive personal information that you choose to provide to us, including when you:

  • Create or register an account, or administer your account.
  • Input, post, or upload information, data, or other content through the Services.
  • Submit questions, requests, or other communications to us via various communication channels.
  • Contact us for customer support or technical support.
  • Visit any of our websites or download any of our applications.
  • Participate in any surveys or other marketing events.
  • Communicate through the Services.
  • Integrate third-party products and services with your The Privacy Stack account.

Information from Others with whom You Interact in your Use of the Services.

If you interact with others in your use of the Services, we may receive personal information about you from others.

Information from Third Party Services You Interact with in your Use of the Services

If you create an account on The Privacy Stack using a third-party service or a single-sign-on service, we may collect personal information about you from the third-party service (such as your username or user ID associated with that third-party service). If you create your account using such a third-party service, or if you give us permission by changing the settings on your The Privacy Stack account, we may also collect, and you authorize us to collect, information about your personal contacts as may be stored within that third-party service, which we may use to facilitate your invitation of collaborators to The Privacy Stack. By choosing to create an account using a third-party service, you also authorize us to collect personal information necessary to authenticate your account with the third-party service provider.

Certain aspects of the Services may allow you to link or integrate third-party products and services to enable certain features and functionalities with the Services. If you choose to use these features or functionalities, you may be asked to create an account with a third-party service provider or link your existing account with that service provider (and, by doing so, agree to the privacy policy and/or terms and conditions of that third-party). You may also be asked to authorize The Privacy Stack to collect information from the third-party service provider on your behalf. We will then collect information (such as your username or user ID associated with that third-party service) from you and/or that third-party service provider as necessary to enable the Services to access your data and content stored with that third-party service provider. Once the authentication is complete, we have the ability to access information you provided to us or was otherwise collected by the third-party service in accordance with the privacy practices of that third-party service. We will store the information and data we collect and associate it with your The Privacy Stack account, and we will use that information and data to enable the integration of the Services with the third-party service provider and to perform actions requested or initiated by you, or that are reasonably necessary to carry out instructions provided by you.

Information We Automatically Collect.

We and our third-party service providers (including any third-party content, advertising, and analytics providers) automatically collect certain information from your device or web browser when you interact with the Services. For example, when you interact with the Services, we may log and store your IP address and technical information about your usage like your device ID, browser type, and how you progressed through the Services, where you abandoned it, etc. We can use your IP address to determine your general location. Additionally, if you use a mobile application of ours, we may collect analytic information about your device, such as IP address, OS version, and clickstream.

In addition, we use tracking technologies, such as cookies, local storage, and pixel tags as described further below.

Cookies and Local Storage

Cookies and local storage may be set and accessed on your computer. Upon your first visit to the Services, a cookie or local storage will be sent to your computer that uniquely identifies your browser. “Cookies” and local storage are small files containing a string of characters that is sent to your computer’s browser and stored on your device when you visit a website. You can reset your browser to refuse all cookies or to indicate when a cookie is being sent; however, if you reject cookies, you may not be able to sign in to the Services or take full advantage of our Services. Additionally, if you clear all cookies on your browser at any point after setting your browser to refuse all cookies or indicate when a cookie is being sent, you will have to again reset your browser to refuse all cookies or indicate when a cookie is being sent.

Our Services use the following types of cookies for the purposes set out below: 

Type of cookie Purpose
Analytics and Performance Cookies These cookies are used to collect information about traffic to our Services and how users use our Services. The information gathered does not identify any individual visitor. The information is aggregated and therefore anonymous. It includes the number of visitors to our Services, the websites that referred them to our Services, the pages that they visited on our Services, what time of day they visited our Services, whether they have visited our Services before, and other similar information. We use this information to help operate our Services more efficiently, to gather broad demographic information and to monitor the level of activity on our Services. We use Google Analytics for this purpose. Google Analytics uses its own cookies. It is only used to improve how our Services works. You can find out more information about Google Analytics cookies here: https://developers.google.com/analytics/resources/concepts/gaConceptsCookies. You can find out more about how Google protects your data here: https://support.google.com/analytics/answer/6004245?hl=en. You can prevent the use of Google Analytics relating to your use of our Services by downloading and installing the browser plugin available via this link: http://tools.google.com/dlpage/gaoptout?hl=en-US
Essential Cookies These cookies are essential to provide you with services available through our Services and to enable you to use its features. For example, they allow you to log in to secure areas of our Services and help the content of the pages you request load quickly. Without these cookies, the services that you have asked for cannot be provided, and we only use these cookies to provide you with those services.
Functionality Cookies These cookies allow our Services to remember choices you make when you use our Services, such as remembering your language preferences, remembering your login details, remembering which polls you have voted in and in some cases, to show you poll results, and remembering the changes you make to other parts of our Services which you can customize. These cookies also enable us to identify you across various screens and devices as you login and use our Services, as well as enable us to work with partners to resolve your digital identities and personalize your experiences across our Services, our partners and customers, and across channels. The purpose of these cookies is to provide you with a more personal experience and to avoid you having to re-enter your preferences every time you visit our Services.

3. HOW WE USE YOUR PERSONAL INFORMATION

We will only share your personal information with third parties under the following circumstances:

  • When you ask us to or with your consent or if you choose to share. 
  • With affiliated businesses, agents, or vendors that are contractually engaged to provide us with services, such as email management. These companies are obligated by contract to safeguard any personal information they receive from us.
  • With advertising partners, to help us advertise our Services.
  • With any of our affiliated companies, including a parent company, subsidiaries, joint ventures, or other companies under common control with us (in which case we will require such entities to honor this Privacy Policy).
  • If we believe that disclosure is reasonably necessary to comply with a law, regulation, valid legal process (e.g., subpoenas or warrants served on us), or governmental or regulatory request; to protect the security or integrity of the Services; and/or to protect the rights, property, or safety of The Privacy Stack, its employees, customers, users, or others. If we are going to release your data, we will do our best to provide you with notice in advance by email, unless we are prohibited by law from doing so.
  • In the event we go through a business transition (such as a merger, acquisition by another company, bankruptcy, or sale of all or a portion of our assets, including, without limitation, during the course of any due diligence process), your personal information will likely be among the assets transferred. By providing your personal information, you agree that we can transfer such information in those circumstances without your further consent. Should such a business transition occur, we will make reasonable efforts to request that the new owner or combined entity (as applicable) follow this Privacy Policy with respect to your personal information. If your personal information would be used contrary to this privacy policy, we will request that you receive prior notice.

4. HOW WE MAY SHARE YOUR PERSONAL INFORMATION

We will only share your personal information with third parties under the following circumstances:

  • When you ask us to or with your consent or if you choose to share. 
  • With affiliated businesses, agents, or vendors that are contractually engaged to provide us with services, such as email management. These companies are obligated by contract to safeguard any personal information they receive from us.
  • With advertising partners, to help us advertise our Services.
  • With any of our affiliated companies, including a parent company, subsidiaries, joint ventures, or other companies under common control with us (in which case we will require such entities to honor this Privacy Policy).
  • If we believe that disclosure is reasonably necessary to comply with a law, regulation, valid legal process (e.g., subpoenas or warrants served on us), or governmental or regulatory request; to protect the security or integrity of the Services; and/or to protect the rights, property, or safety of The Privacy Stack, its employees, customers, users, or others. If we are going to release your data, we will do our best to provide you with notice in advance by email, unless we are prohibited by law from doing so.
  • In the event we go through a business transition (such as a merger, acquisition by another company, bankruptcy, or sale of all or a portion of our assets, including, without limitation, during the course of any due diligence process), your personal information will likely be among the assets transferred. By providing your personal information, you agree that we can transfer such information in those circumstances without your further consent. Should such a business transition occur, we will make reasonable efforts to request that the new owner or combined entity (as applicable) follow this Privacy Policy with respect to your personal information. If your personal information would be used contrary to this privacy policy, we will request that you receive prior notice.

5. WHEN WE USE & SHARE NON-PERSONAL INFORMATION

We use and share your non-personal, de-identified or aggregated data in a variety of ways, including to improve the Services.

6. HOW TO OPT-OUT OF EMAIL COMMUNICATIONS

To stop receiving notifications or promotions, please click the unsubscribe link found at the bottom of each email or update your account preferences.

7. STORAGE & SECURITY

We use industry standard technical, administrative and physical controls to protect your data. While we take reasonable precautions against possible security breaches, no website or internet transmission is completely secure and we cannot guarantee that unauthorized access, hacking, data loss or other breach will never occur.

We will process and store your personal information only for the period necessary to achieve the purpose of the storage, or as permitted by law.  The criteria used to determine the period of storage of information is the respective statutory retention period. After expiration of that period, the corresponding information is routinely deleted, as long as it is no longer necessary for the fulfillment of a contract or the initiation of a contract.

8. THIRD PARTY LINKS

The Services may contain links to and from third party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for their policies.

9. CALIFORNIA PRIVACY RIGHTS

This section, which supplements the rest of this Privacy Policy, applies to residents of California, containing disclosures required by the California Consumer Privacy Act (“CCPA”). This section applies only to “personal information” that is subject to the CCPA.

The Privacy Stack does not sell personal information and has not sold any personal information to third parties in the preceding 12 months.

Personal Information We Collect and Disclose for a Business Purpose. 

Without limiting the description of the information we collect, we collect the categories of personal information about California consumers identified in the chart below. More information regarding the personal information we collect can be found above in the section titled “What Information We Collect.”

Categories of Personal Information Examples Collected in Prior 12 Months
A. Personal and online identifiers. A real name, alias, postal address, unique personal identifier, online identifier Internet Protocol address, email address, or other similar identifiers. Yes
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). A name, address, telephone number, education, employment, employment history, or any other financial information. Some personal information included in this category may overlap with other categories. Yes
C. Protected classification characteristics under California or federal law. Age (40 years or older), race, color, ancestry, national origin, sex, veteran or military status. No
D. Commercial or transactions information. Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. No
E. Biometric information. Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. No
F. Internet or other similar network activity. Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement. Yes
G. Geolocation data. Physical location or movements. Yes
H. Sensory data. Audio, electronic, visual, thermal, olfactory, or similar information. No
I. Professional or employment-related information. Current or past job history. Yes
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)). Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. No
K. Inferences drawn from other personal information. Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. Yes

Categories of Sources. 

We collect personal information from, without limitation, consumers directly, our Services’ inferences, service providers, data resellers, and public sources. More information regarding the sources from which we collect personal information can be found above in the section titled “What Information We Collect.”  

Why We Collect, Use, and Share California Information. 

We use and disclose the personal information identified as collected in the chart above for our commercial and business purposes, as further described in this Privacy Policy and in the section titled “How We Use Your Personal Information.” These commercial and business purposes include, without limitation:

Our commercial purposes, which include:

  • To provide, develop, improve and personalize our Services.
  • To provide you with information, products, or services that you have requested.
  • To receive and process job applications for jobs with us.
  • To process data with machine learning algorithms, which helps us build, personalize, and improve the Services.
  • For internal business purposes, such as to detect, investigate and prevent harmful, fraudulent, and illegal activity and security issues and protect the rights and property of The Privacy Stack and others.
  • To enable communications through the Services.
  • To contact you about additional The Privacy Stack services you might be interested in, unless you opt-out (see “How to Opt-Out of Email Communications”).
  • As required by applicable law, legal process or regulation.

Our business purposes as identified in the CCPA, which include:

  • Auditing related to our interactions with you;
  • Legal compliance;
  • Detecting and protecting against security incidents, fraud, and illegal activity;
  • Debugging;
  • Performing services (for us or our service provider) such as account servicing, processing orders and payments, and analytics;
  • Internal research for technological improvement;
  • Internal operations;
  • Activities to maintain and improve our services; and
  • Other one-time uses.

Recipients of California Personal Information. 

We disclose, and have disclosed in the last 12 months, the categories of personal information identified as collected in the chart above for business purposes to the following categories of third parties: service providers, data analytics providers, advertising networks, internet service providers, and operating systems and platforms. More information regarding the categories of third parties with whom personal information is disclosed can be found in the section above titled “How We May Share Your Personal Information.”

Your Rights Regarding Personal Information. 

California residents have certain rights with respect to the personal information collected by businesses. If you are a California resident, you may exercise the following rights regarding your personal information, subject to certain exceptions and limitations:

  • The right to know the categories and specific pieces of personal information we collect, use, disclose, and sell about you, the categories of sources from which we collected your personal information, our purposes for collecting or selling your personal information, the categories of your personal information that we have either sold or disclosed for a business purpose, and the categories of third parties with which we have shared personal information;
  • The right to request that we delete the personal information we have collected from you or maintain about you.
  • The right not to receive discriminatory treatment for the exercise of the privacy rights conferred by the CCPA.

To exercise any of the above rights, please contact us using the following information and submit the required verifying information, as further described below:

  • by email at contact@theprivacystack.org.

Verification Process and Required Information. 

We may need to request additional information from you to verify your identity or understand the scope of your request, although you will not be required to create an account with us to submit a request or have it fulfilled. We will then typically attempt to match the identifying information provided by you to the personal information already maintained by us to verify the request. If you have a password protected account on the Services, we may verify your identity through the existing authentication practices for your account, in which case we will require you to re-authenticate yourself before we disclose or delete your personal information.

Authorized Agent. 

You may designate an authorized agent to make a CCPA request on your behalf by verifying your identity, as described above, and providing written permission for the authorized agent to act on your behalf.

Minors’ Right to Opt In. 

The Privacy Stack does not sell the personal information of minors under 16 years of age.

Non-Discrimination. 

The Privacy Stack will not discriminate against a user because the user exercised any of the user’s rights described above or afforded to it under applicable data privacy law.

10. NEVADA PRIVACY RIGHTS

This section, which supplements the rest of this Privacy Policy, applies to residents of Nevada. Under Nevada law, Nevada residents may submit a request directing us not to make certain disclosures of personal information we maintain about them.

To exercise this right, please contact us:

  • by email at contact@theprivacystack.org.

11. EXERCISING RIGHTS, CONTACT US AND ACCESSING YOUR INFORMATION

The Privacy Stack users may exercise their rights regarding their personal information as follows:

  • You can contact us at contact@theprivacystack.org.
  • You may withdraw your consent to receive cookies or tokens by adjusting your browser settings.
  • You may withdraw your consent to receive marketing or promotional communications at any time by clicking the “unsubscribe” link found within our email updates and changing your contact preferences. Please note, you will continue to receive essential account-related information, even if you unsubscribe from promotional emails.

If you have any questions about our privacy practices, or if you wish to make a request, contact us at either at contact@theprivacystack.org or:

The Privacy Stack
Attn: Privacy
23 Geary Street, Suite 600
San Francisco, CA 94108