Privacy Policy
This privacy policy explains how we collect, use, protect, or otherwise handle your Personally Identifiable Information (PII) when you use our website. PII is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please read this policy carefully.
What personal information do we collect?
When ordering or registering on our site, you may be asked to enter your name, email address, phone number, or other details to help with your experience.
When do we collect information?
We collect information when you fill out a form or enter information on our site, such as when you register, make a purchase, sign up for our newsletter, respond to a survey or marketing communication, browse the website, or use certain other site features.
How do we use your information?
We may use the information we collect from you to send periodic emails regarding your order, inform you of new products (including products of our affiliates), services and offers, and provide you with information about us and our products.
We may contract with third-party service providers to provide certain services for our business, such as credit card processing, computer system services, shipping, data management, advertisements, or promotional services. We provide the information needed for these providers to perform these services, which may include some personal and Personally Identifiable Information. These providers are not authorized to use the information for purposes other than providing services to us.
We may share information with governmental agencies and other organizations assisting us in fraud prevention or for investigative purposes when permitted or mandated by law; when trying to protect against or prevent fraud; when attempting to prevent unauthorized or improper transactions; or when investigating fraud or improper conduct. Information is not provided to these agencies or organizations for marketing or unrelated purposes.
How do we protect visitor information?
Our website is regularly scanned for security holes and known vulnerabilities. Your personal information is contained behind secured networks and is only accessible by a limited number of persons with special access rights who are required to keep the information confidential. All sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology. For your convenience, we may store your credit card information for more than 60 days to expedite future orders and automate billing.
Use of Payment Sources
To make a purchase, you will need to provide a payment source (e.g., credit card). We use third-party billing services and have no control over these services. We use our best efforts to ensure your payment source is kept strictly confidential by using third-party billing services that use industry-standard technologies. However, we are not responsible for any misuse of your payment source.
Cookies
Our website may send a “cookie” to your computer. A cookie is a small piece of data stored on your device to identify which areas of our site you have visited and to personalize content on return visits. Cookies may also be used to serve relevant advertisements and emails after you leave our site. Most browsers can be set to reject cookies via their settings. If you disable cookies, some features may be disabled and some services may not function properly.
Our Email Policy
We comply with international laws regarding SPAM. You can opt out of further email correspondence at any time. We will not sell, rent, or trade your email address to any unaffiliated third party without your permission. We use your email address to provide customer service, facilitate transactions with third-party marketing partners, and inform you of offers and promotions from us or our affiliates.
Google Remarketing & AdRoll Retargeting
We use cookies to serve you relevant ads based on your interactions with our site. These ads, served by third-party vendors including Google and AdRoll, may appear across various sites on the Internet.
If you wish to opt out of Google Remarketing, visit: http://www.google.com/settings/ads/
If you wish to opt out of AdRoll Retargeting, visit: http://www.aboutads.info/choices/
California Online Privacy Protection Act (CalOPPA)
CalOPPA requires commercial websites and online services to post a privacy policy stating the information being collected and with whom it is shared, and to comply with that policy.
According to CalOPPA we agree to the following:
- Users can visit our site anonymously.
- Once this privacy policy is created, we will add a link to it on our home page or on the first significant page after entering our website.
- Our Privacy Policy link includes the word “Privacy” and can be easily found.
Users will be notified of any privacy policy changes:
- On our Privacy Policy page by noting the date of the most recent update.
Does our site allow third-party behavioral tracking?
Yes. We allow third-party behavioral tracking.
COPPA (Children’s Online Privacy Protection Act)
When it comes to collecting personal information from children under 13, COPPA puts parents in control. The Federal Trade Commission enforces the COPPA Rule.
We do not specifically market to children under 13. We do not verify the age of our users and have no liability for verifying a user’s age.
Fair Information Practices
The Fair Information Practice Principles form the backbone of privacy law in the United States. To align with these principles, if a data breach occurs, we will notify users via email within 7 business days.
We also agree to the individual redress principle, which requires that individuals have enforceable rights against data collectors and processors who fail to adhere to the law, and recourse to courts or a government agency.
CAN-SPAM Act
The CAN-SPAM Act sets rules for commercial email, establishes requirements for commercial messages, gives recipients the right to stop emails, and provides penalties for violations.
We collect your email address in order to:
- Send information, respond to inquiries, and/or other requests or questions.
- Process orders and send information and updates pertaining to orders.
- Send additional information related to your product and/or service.
- Market to our mailing list or continue to send emails to our clients after the original transaction has occurred.
To be in accordance with CAN-SPAM we agree to:
- Not use false or misleading subjects or email addresses.
- Identify the message as an advertisement in a reasonable way.
- Include the physical address of our business or site headquarters.
- Monitor third-party email marketing services for compliance, if used.
- Honor opt-out/unsubscribe requests promptly.
- Allow users to unsubscribe by using the link at the bottom of each email.
If at any time you would like to unsubscribe from receiving future emails, click the Unsubscribe link in the email. Alternatively, you can email us at info@makeitjamaica.com or contact us through our website, www.makeitjamaica.com, and we will promptly remove you from all correspondence.
Changes to Our Privacy Policy
Our privacy and security practices may change from time to time. If we modify our Privacy Policy, we will update the “Last Updated” date below. Changes are effective as of that date and apply to all current and past users. We encourage visitors to review this policy periodically.
Questions About Our Privacy Policy
To help us improve our privacy and security policies and practices, please send questions and feedback using the Contact Us and Feedback forms on our website, www.makeitjamaica.com.
GDPR - Data Processing Agreement Addendum
This GDPR Data Processing Agreement Addendum forms part of this Privacy Policy. Its purpose is to reflect the parties’ agreement with regard to processing personal data in accordance with applicable Data Protection Laws. To the extent we store, transmit, collect, or otherwise use EU Personal Data, we will comply with the following additional provisions.
- Definitions. Terms used in this section have the meanings set forth below.
- Data Breach. Any security breach or similar incident leading to the unintended, accidental, unauthorized, or unlawful loss, disclosure of, or access to EU Personal Data by any Processor.
- Data Controller. Has the meaning given under the GDPR.
- Data Processor. Has the meaning given under the GDPR.
- Data Protection Laws. Any data protection, privacy, or similar laws or regulations relating to the processing or use of personal data, including the GDPR, that apply to Personal Data processed in connection with this Agreement.
- EU Data Subject. Has the meaning given to “Data Subject” under the GDPR.
- EU Personal Data. Has the meaning given to “Personal Data” under the GDPR.
- GDPR. Regulation (EU) 2016/679 and, to the extent the GDPR no longer applies in the UK, any equivalent UK legislation.
- Our Prior Guest Personal Data. EU Personal Data processed by us or our employees, agents, or personnel in performing our obligations under this Agreement, or made available to us by Our Prior Guest or our merchant processor(s).
- Processing. Has the meaning given under the GDPR.
- Processor Security Obligations. Article 32 of the GDPR.
- Supervisory Authority. Has the meaning given under the GDPR.
- Compliance. We will comply with applicable Data Protection Laws and ensure that all employees, subcontractors, and personnel comply with equivalent obligations. We will not intentionally perform any act that puts Our Prior Guest in breach and will notify Our Prior Guest if performance of any action would result in such a breach.
- General. We determine the purposes and means of processing Our Prior Guest Personal Data and will be the Data Controller. We and our merchant provider(s) will be the Data Processor(s) and will process Personal Data only to perform our obligations under this Agreement and during its term.
- Requests. We will, within required timescales, comply with written requests by Our Prior Guest to: correct or delete inaccurate Personal Data; provide copies of Personal Data; provide information about Processing and security measures; assist with requests or notices from EU Data Subjects or Supervisory Authorities; and provide reasonable assistance to Authorities.
- Use. Without Our Prior Guest’s prior written consent (e.g., opt-in to our mailing list), we will not: use Personal Data for our own purposes; transfer or allow access to Personal Data by third parties; or process Personal Data by automatic means for decisions that significantly affect a Data Subject as the sole basis.
- Transfer. We may disclose Personal Data worldwide to fulfill the purposes described, including transfers outside the EEA. We maintain a strict no-sharing policy: our database is neither sold nor leased and is accessed only through passworded, encrypted access. We will protect EU Personal Data in accordance with GDPR requirements.
- Complaints. We will promptly notify Our Prior Guests of any third-party complaints regarding processing, will not make admissions or settlements that prejudice defenses, and will provide reasonable assistance in connection with such complaints. If we independently acquire EU Personal Data from EU Data Subjects, we will provide appropriate data protection notices. We will promptly notify Our Prior Guest of any unauthorized, unlawful, or dishonest conduct, or any Data Breach, and provide relevant information.
- Security Obligations. We will: take appropriate technical and organizational measures to safeguard against unauthorized or unlawful processing and against accidental loss, destruction, or damage; process Personal Data only in accordance with Our Prior Guest’s written instructions; take reasonable steps to ensure reliability of personnel with access; and ensure such personnel have adequate training in handling EU Personal Data.
- Audit. We will cooperate with any audit by a relevant Supervisory Authority required by law or regulation to ascertain or monitor compliance with Data Protection requirements.
Last Updated 05/15/2018