Privacy – Castle Flexx

Privacy

CASTLE FIT CORPORATION (“Castle Flexx”, “Company”, “we”, “us” or “our”) is committed to protecting the privacy of visitors to our website located at castleflexx.com (the “Site”). This Privacy Policy (“Policy”) explains how we may collect, use, share and otherwise process information in connection with the Site, and the rights and choices that may be available to you with respect to your information. If you do not agree to the terms of this Policy, you must immediately cease your use of the Site. We may update this Policy from time to time, and your use of the Site constitutes your express acceptance to the terms of the then-posted version of this Policy.

INFORMATION COLLECTION

We collect personal information you provide to us, or that we receive from marketing partners, social media platforms, other users (via referrals or registries), and other publicly-available sources. The information we collect includes, without limitation:

  • Contact Data, such as your name; your email address; and your phone number.
  • Account Data, that you may set to establish an online account with us or register for a Castle Grade-sponsored event or other promotion. If you choose to login to the Site via a third-party platform or social media network, we may collect information from that platform or network.  You can read more about your privacy choices with respect to such platforms in the “Options” section below.
  • Feedback, such as information you provide, and content that you upload when you contact us with questions, feedback, upload attachments, or otherwise correspond with us online (including on our social media pages).
  • Payment Data, such as credit card number and expiration date, account number, and billing and shipping addresses.
  • Transaction Data, such as details about the products you browse and the purchases you make on our Site.
  • Engagement Data, such as your preferences for receiving communications about our activities and publications, and details about how you engage with our Site and communications.
  • Automatically Collected Data. We, our service providers and third-party advertising partners use cookies, beacons, pixel tags and other tracking technologies to automatically log information about you, your computer or mobile device, and your activity over time on the Site and other online services, including:
    • Device Data, such as your computer or mobile device operating system type and version number, manufacturer and model, browser type, screen resolution, IP address, device identifier (such as the Google Advertising ID or Apple ID for Advertising), the website you visited before browsing our Site, and general location information such as city, state or geographic area.
    • Online Activity Data, such as browsing history, search history, whether you clicked on or opened one of our emails, which of our pages or screens you viewed, how long you spent on a page or screen, navigation paths between pages or screens, information about your activity on a page or screen, access times, and duration of access.

Please visit the “Options” section of this Policy for information on how to disable or opt-out of cookies and similar technologies.

You may refuse to provide certain personal information, but some parts of the Site may not be fully available or functional without submitting such information.

USE OF INFORMATION

We use your personal information for the following purposes:

Operations.  We use personal information to operate the Site and provide related services, including to:

  • provide, operate and improve the Site and our services
  • manage and fulfill the orders you’ve placed on the Site
  • establish and maintain your account on the Site
  • facilitate your to login to the Site via third-party identity and access management providers
  • enable security features of the Site, such as by sending you security codes via email or SMS, and remembering devices from which you have previously logged in
  • communicate with you about the Site or your orders, including by sending you announcements, updates, security alerts, and support and administrative messages
  • communicate with you about events or contests in which you participate
  • understand your needs and interests, and personalize your experience with the Site and our communications
  • respond to your requests, questions and feedback
  • protect the security of the Site and our systems
  • provide you with customer support when needed

Research and development.  We analyze use of the Site to analyze and improve the Site and our services, and to develop new products and services, including by studying user demographics and use of the Site. We may use a third-party service provider for this purpose.

Marketing.  We may send you Castle Grade-related marketing communications as permitted by law. You will have the ability to opt-out of our marketing and promotional communications as described in the “Opt out of marketing” section below.

Advertising. We may also work with third-party advertising partners who use cookies and similar technologies to deliver targeted advertising that is displayed on unaffiliated websites, to measure the effectiveness of advertising on behalf of our advertising partners, and to identify the audience most likely to respond to an advertisement. These advertisements are delivered by our advertising partners and may be targeted based on your use of the Site or your activity elsewhere online.

Compliance, fraud prevention, and safety.  We may use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities, and as we believe necessary or appropriate to: (a) protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); (b) enforce the terms and conditions that govern the Site; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

We may create anonymous, aggregated or de-identified data from your personal information and other individuals whose personal information we collect, by removing the information that makes the data personally identifiable to you. We may use and share such anonymous, aggregated or de-identified data for any purpose we deem appropriate, including without limitation to maintain and improve the Site and our current and future products and services.

SHARING OF INFORMATION

We may share personal information with:

Service providers.  We may share your personal information with third-party companies and individuals that provide services on our behalf or help us operate the Site (such as payment, customer support, hosting, analytics, email delivery, marketing, and database management services). These third parties may use your personal information only as directed or authorized by us and in a manner consistent with this Policy and are prohibited from using or disclosing your information for any other purpose.

Advertising partners. We may enable advertising partners to automatically collect information directly from our Site for targeted marketing purposes.

Other users of the Site and social media.  We may provide functionality that enables you to disclose personal information to other users of the Site or certain social media platforms. We do not control how other users or third parties use any personal information that you make available to other users or third-party platforms.

Compliance; corporate transaction. We may also share personal information with third parties: (i) for our compliance, fraud prevention and safety purposes, including in connection with a court order, subpoena, government investigation, or when otherwise required by law; and (ii) in connection with, or during negotiation of, a corporate sale, merger, acquisition, or similar event.

OPTIONS

Opt out of marketing communications. If at any time you wish to opt-out of future newsletters or other promotional emails, you may click the “unsubscribe” link in the email or otherwise contact us at [info@castleflexx.com]. It may take up to 10 business days before you stop receiving promotional emails. This opt-out does not apply to operational communications, for example, order confirmation emails.

Access, update or delete information. If you have registered for an account with us, you may review and update certain personal information in your account profile by logging into the account. You may delete your account by contacting us at [info@castleflexx.com].

Cookies & browser web storage.  Most browsers let you remove or reject cookies.  To do this, follow the instructions in your browser settings.  Many browsers accept cookies by default until you change your settings.  Please note that if you set your browser to disable cookies, the Site may not work properly.  Similarly, your browser settings may allow you to clear your browser web storage. 

Targeted online advertising. Some of our business partners that collect information about users’ activities on or through the Site may be members of organizations or programs that provide choices to individuals regarding the use of their browsing behavior for purposes of targeted advertising. Users may opt out of receiving targeted advertising by:

Note that because these opt-out mechanisms are specific to the device or browser on which they are exercised, you will need to opt-out on every browser and device that you use.

Do Not Track.  Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit.  We currently do not respond to “Do Not Track” or similar signals.  To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.

Third-party platforms or social media networks. If you choose to connect to the Site via a third-party platform or social media network, you may have the ability to limit the information that we may obtain from the third party at the time you login to the Site using the third party’s authentication service or otherwise connect your account. Subsequently, you may be able to control your settings through the third party’s platform or service. If you withdraw our ability to access certain information from a third-party platform or social media network, that choice will not apply to information that we have already received from that third party.

INFORMATION ABOUT CHILDREN

This Site is not directed to persons under 18. By using the Site, you represent that you are at least 18 years of age (or twenty-one (21) years of age in places where eighteen (18) years is not the age of majority). We do not knowingly solicit or collect Personal Data online from children under the age of 13 without parental or guardian consent. If we discover that we have collected personal information from a person under 13, we will take commercially reasonable measures to promptly delete such information from our systems. If a parent or guardian becomes aware of his or her child has provided us with personal information, please contact us at [info@castleflexx.com].

USER GENERATED CONTENT

We may make available on our Site, or link to, features that allow you to generate your own content or share information online (e.g., on our blog or product pages). Please do not embed personal information in the content you generate or share personal information online in public forums, because any such information can be collected and used by others. We have no control over, and take no responsibility for, the use, storage, dissemination or erasure of personal information embedded in user-generated content or shared on the Site. By posting personal information online in public forums, you may receive unsolicited messages from other parties.

SITE LIMITED TO UNITED STATES

The Site is intended for use only by United States residents at this time. If you reside outside the United States, you access the Site at your own risk. Users may not access or register for or use the Site if prohibited by law in their country of residence.

CastleFlexx is headquartered in the United States. Presently, information we collect from you will be processed in the United States, but your personal information may be stored and processed in any country where we have facilities or in which we engage service providers, and by using the Site you understand that your information may be transferred to countries outside of your country of residence, including the United States, which may have data protection laws that are different from those of the country in which you reside.

SECURITY

We maintain technical, administrative, physical, electronic and procedural safeguards to protect the confidentiality and security of personal information provided to us. We take reasonable steps to protect personal information, including: using Secure Socket Layer to encrypt your credit card number, name and address; requiring you to establish a password or other method of authentication to access your account on the Site; and regularly monitoring our servers and IT systems for possible vulnerabilities and attacks. Unfortunately, despite these efforts, the transmission of information via the Internet is not completely secure. We cannot guarantee the security of personal information transmitted to or through our Site, and any such transmission is at your own risk.

THIRD-PARTY SITES

The Site contains links to third-party websites. We cannot control, and take no responsibility for, the content or privacy practices of such third-party websites. Please carefully review the privacy policy and any other applicable terms for such third-party websites.

CONTACT

If you have any further questions concerning this Policy, or would like to request to correct, update, or delete personal information, please contact us at [info@castleflexx.com].

POLICY UPDATES

This Policy was last updated on [insert date Policy is posted]. Any changes we may make to this Policy in the future will be posted on this page and, where appropriate, notified to you by email. Please check back regularly to keep informed of updates or changes to this Policy.

NOTICE TO CALIFORNIA RESIDENTS

Scope.  This section describes how we collect, use, and share the Personal Information of California residents as a “business” under the California Consumer Privacy Act (“CCPA”) and their rights with respect to their Personal Information.  For purposes of this section, “Personal Information” has the meaning given in the CCPA but does not include information exempted from the scope of the CCPA.  Additionally, this section does not apply to information we collect from you in the course of communicating with you in your capacity as an employee, controlling owner, director, officer or contractor of an organization (i.e., company, partnership, sole proprietorship, non-profit or government agency) in the context of performing due diligence on, or providing or receiving products or services to or from, that organization.  In some cases we may provide a different privacy notice to certain categories of California residents, such as job applicants, in which case that notice will apply instead of this section.

PERSONAL INFORMATION THAT WE COLLECT AND USE

The list below summarizes the Personal Information we collect and use by reference to the categories specified in the CCPA in California Civil Code § 1798.140(o), and describes our practices during the 12 months preceding the effective date of this Policy. The “categories we collect” refer to the categories described above in the section entitled Information Collection. Information you voluntarily provide to us, such as in free-form webforms, may contain other categories of Personal Information not described below.

  • Identifiers 
    • Categories we collect: Contact data
  • Commercial Information
    • Categories we collect: Transaction data, Engagement data, Feedback
  • Financial Information 
    • Categories we collect: Payment data, Transaction data
  • Online Identifiers
    • Categories we collect: Account data, Device data
  • Internet or Network Information
    • Categories we collect: Transaction data, Engagement data, Device data, Online activity data
  • Geolocation Data
    • Categories we collect: Device data
  • Inferences
    • Categories we collect: Transaction data, Engagement data, Device data, Online activity data

For information about:

  • The categories of sources of this information, see the section above entitled Information Collection;
  • The business/commercial purposes for which we collect this information, see the section above entitled Use of Information; and
  • The categories of third parties to which we disclose this information for business purposes, see the section above entitled Sharing of Information.

CALIFORNIA RESIDENTS’ PRIVACY RIGHTS

As a California resident, you have the rights listed below. However, these rights are not absolute, and in certain cases we may decline your request as permitted by law.

  • Information.  You can request the following information about how we have collected, used and shared your personal information during the past 12 months, which we have made available to you without your having to request it by describing it above: 
    • The categories of Personal Information we have collected.
    • The categories of sources from which we collected the Personal Information.
    • The business or commercial purpose for collecting and/or selling Personal Information.
    • The categories of third parties with whom we share the Personal Information.
    • The categories of Personal Information that we sold or disclosed for a business purpose.
    • The categories of third parties to whom the Personal Information was sold or disclosed for a business purpose.
  • Access.  You can request a copy of the Personal Information that we maintain about you.
  • Deletion.  You can ask us to delete the Personal Information that we collected from you.
  • Nondiscrimination. You are entitled to exercise the rights described above free from discrimination as prohibited by the CCPA.

WE DO NOT SELL YOUR PERSONAL INFORMATION

Based on our understanding of the term “sell” under the CCPA, we do not “sell” your Personal Information and have not sold it to third parties for a business or commercial purpose in the 12 months preceding the effective date of this Policy.  However, like many companies online, we use services provided by Facebook and others that help deliver interest-based ads to you as described in the section above entitled Targeted Online Advertising. You can opt-out of this advertising as described below under the section entitled California Residents – Online Tracking Opt-out.

HOW TO SUBMIT A REQUEST

  • To request access to or deletion of personal information:
    • Visit [Insert link to web form.  The web form is not required but can be useful for triaging CCPA requests.]
    • Call: [telephone number (not required where relationship with customer is strictly online – but even if relationship is strictly online there must be at least two methods of making request in this list (e.g. web form and email))]
    • Email: [info@castleflexx.com]

We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it.

We will need to verify your identity to process your information, access and deletion requests and reserve the right to confirm your California residency.  To verify your identity, we may require you to log into your Castle Grade account (if applicable), provide government identification, give a declaration as to your identity under penalty of perjury and/or provide additional information.  Your authorized agent may make a request on your behalf upon our verification of the agent’s identity and our receipt of a copy of a valid power of attorney given to your authorized agent pursuant to California Probate Code Sections 4000-4465.  If you have not provided your agent with such a power of attorney, you must provide your agent with signed permission to exercise your CCPA rights on your behalf, provide the information we request to verify your identity, and provide us with written confirmation that you have given the authorized agent permission to submit the request. Authorized agents are required by California law to implement and maintain reasonable security procedures and practices to protect their clients’ information.

CALIFORNIA RESIDENTS – ONLINE TRACKING OPT-OUT

Like many companies online, we use services provided by Google, Facebook and other companies that use tracking technology. These services rely on tracking technologies – such as cookies and web beacons – to collect directly from your device information about your browsing activities, your interactions with websites, and the device you are using to connect to the Internet. There are a number of ways to opt out of having your online activity and device data collected through these services, which we have summarized below:

Note that because these opt-out mechanisms are specific to the device or browser on which they are exercised, you will need to opt-out on every browser and device that you use.