Bookshop Santa Cruz (BSC) and bookshopsantacruz.com are committed to maintaining and protecting the privacy of your personal information. Collectively BSC and bookshopsantacruz.com will be referred to as either “we,” “our” or “us.” The following discloses our policy for gathering and disseminating personal information collected by us. If you have any questions about your rights as a user of our services, you may contact Lindsay, Manager of Ecommerce and Website, via email.
- The information we collect and how we use it;
- Your right to access or update your personally identifiable information;
- Your right to opt-out of receiving communications from us; and
- Our pledge to have reasonable security measures in place to protect against loss, misuse, or alteration of information under our control.
A. Information We Collect
We may collect two types of information about you when you visit the Site, contact us, place an order, or in any other communication we may have with you: personal information (such as, your name, address, telephone number, e-mail address, and credit card number), and, via the Site only, non-personal, aggregate information (such as information regarding the pages on our site you have visited and your IP address).
1. Personally Identifiable Information
The only personally identifying information that we collect and store about you is the information that you have chosen to provide to us. For example, if you place an order or register on the Site, we may collect your name, phone number, mailing address, email address, and payment information. In addition, if you contact us via phone or send us e-mail requesting information about us or otherwise ask us a question, we may collect your name, phone number, address, e-mail address and other personal information so that we can respond to your request or question. We may also from time to time send you e-mail and postal correspondence regarding products and services that we believe may be of interest to you. You may, however, visit our site anonymously.
2. Non-Personally Identifiable Information
From the Site, we may collect and use non-personally identifiable information about you in the following ways:
- Your Internet Protocol (IP) address or the proxy address of your Internet Service Provider (e.g. AOL, CompuServe, Comcast, etc.);
- The resource on our server accessed as a result of the request, such as the web page, image, etc.;
- The query in the request;
- The name and version of your web browser;
- The content of any sent or received cookie, as defined below;
- The Uniform Resource Locator (“URL”) that was accessed before making the request for our web server.
Some parts of this Site web site may use a “cookie” – a file placed on your computer hard drive allowing our server to log the pages accessed in the Site to determine if you have visited before. This cookie captures no personally identifying information. You may set your browser to warn you when placement of a cookie is requested, and decide whether or not to accept it. Please not that by rejecting a cookie some of the features available on the site may not function properly.
b. Referrers, IP Addresses and Environmental Variables
We may also collect information through “referrers,” IP addresses and various environmental variables. A "referrer" is information the web browser passes along to the BSC web server that references the URL from which you came. An “IP Address” is a number used by computers on a network to identify your computer so that data can be transmitted to you. An “environmental variable” may include, among other things, the domain from which you access the Internet, the time you accessed the web site, the type of web browser and operating system or platform used, the Internet address or the web site you left to visit the web site, the pages you visit while at the web site and the Internet address of the web site you then visit. We may collect IP address information in order to administer the web site and to gather broad demographic information.
B. Sharing Your Information with Third Parties
1. Disclosure of Information by Us
We may share your personally identifiable information with any affiliates, partners, agents or other parties whose products and services may be of interest to you. If you do not want us to share your information in this manner, please see the "CHOICE" section below. We also reserve the right to disclose your personal and non-personal information if we reasonably believe we are required to do so by law; to protect our self or to protect the rights of another user; to reduce the risk of credit or other kind of fraud; or to comply with a court order.
We may also share your personally and non-personally identifiable information with third parties that help manage our web site, databases, credit card processing companies, and affiliate relationships.
We may share your information with third parties in order to fulfill your request or otherwise complete a service provided to you.
In the unlikely event that all or substantially all of our assets are sold or transferred to another party, your personally identifiable information may be transferred to this acquiring entity.
Though we may also from time to time share your personal information with third parties for research and development purposes, we will not sell your personal information to any third parties, other than as specifically disclosed in this policy.
2. Online Blogs and Forums
Our Site also may offer blogs, chatrooms and forums that allow you to post information for other users to read. You may publish information on electronic bulletin boards generally accessible to other Site subscribers. We do not assume any responsibility for the privacy or security of any such communications, and you assume all risks of publishing such information on the system for examination by others, including our employees and persons who gain unauthorized access to the site (“hackers”). Furthermore, any such information published by you will pass through and be stored upon one or more of our servers. We will access the information stored on our server(s) for three purposes: first, to verify that the Site program and system is operating properly; second, to police the content of publications in response to any customer complaints about inappropriate content, and, third, to gather information for statistical purposes. No information published by a user is to be considered an expression of opinion or fact by us. We do not adopt, ratify, guarantee or endorse the contents or accuracy of any such publications. If you believe a communication published through such a forum or blog violates your privacy, you may report the same to us by e-mailing us for investigation or by sending mail to Bookshop Santa Cruz Att: Lindsay, 1520 Pacific Ave, Santa Cruz, CA 95060.
C. Third Party Links
We provide you with the following choices regarding the use of your personal information:
- You may choose not to provide us with any personal information;
- If you are a user of the Site, you may set your browser not to accept cookies, or to warn you when a cookie is being placed on your computer. If you choose not to accept cookies, however, your ability to navigate this web site may be hindered;
- If you would like to unsubscribe to any of our services or would like us to remove you from any of our on-line mailing lists, please email us with the subject heading "unsubscribe from BSC information" or call us at 831-423-0900 and ask to speak to Lindsay.
We make every effort to have reasonable security measures in place to protect the loss, misuse, or alteration of information under our control, including using Secure Sockets Layer (SSL) technology to collect and transmit your information. All supplied sensitive/credit information is transmitted via Secure Socket Layer (SSL) technology and then encrypted into our Payment gateway providers database only to be accessible by those authorized with special access rights to such systems, and are required to keep the information confidential. After a transaction, your private information (name, address, e-mail, etc.) may be kept on file for more than 60 days in order to process future transactions.
F. Notification of Changes
We do not knowingly collect personally identifiable information from any child under the age of 13 without parental consent. When we receive such information, we delete it as soon as we discover it and do not use it or share it with third parties. When we do collect personally identifiable information from any child under the age of 13 it is done with parental consent (as in the online submission of entries to our Young Writers Contest) and that information is not shared with any third parties. We retain personal information collected online from a child for only as long as is necessary to fulfill the purpose for which it was collected and delete the information using reasonable measures to protect against its unauthorized access or use.
The identity and the contact details of the data controller
For services and websites used by residents of the European Economic Area, BSC is the data controller responsible for your personal data. For more information please contact us here.
The contact details of the data protection officer or EU representative
Phone: (831) 423-0900
The legal basis for the processing
We will have a lawful basis for processing your data when:
- We need to process your information in order to provide you with the products or service you have requested or to enter into a contract;
- We have a legitimate interest for processing your data – e.g., for fraud prevention; network and information systems security; data analytics; enhancing, modifying, or improving our services; identifying usage trends; determining the effectiveness of promotional campaigns; and advertising personalization of the service using data to make it easier and faster for you to place orders;
- You have consented to such processing; and/or
- We are required to do this by law (for example, where it is necessary to retain it in connection with potential litigation).
Information on the transfer of personal data to a third country or international organization
BSC is a global business and it, or its service providers, may process, transfer, and store information about our users on servers located in a number of countries outside the European Economic Area (EEA), including in the United States (where data protection laws may be less stringent than in the country where you live). Since we are committed to protecting your information, we take steps to ensure that there are appropriate safeguards in place when we transfer that data.
To ensure that your data is adequately protected, we only transfer your data subject to suitable safeguards being in place. Where applicable, we only transfer your personal data subject to suitable safeguards being in place, such as through Privacy Shield certified organizations. To find out more about how we safeguard your information (including obtaining a copy of such safeguards) in relation to transfers outside the EEA, please contact us here.
The period for which the personal data will be stored or the criteria used to determine that period
BSC will keep your personal data for as long as we need it for the purpose it is being processed for. For example, we will retain your information for as long as your account is active or as needed to provide you services; and after that, we will keep the personal information for a period which enables us to handle or respond to any complaints, queries or concerns relating to your account. Your information may also be retained so that we can continue to improve your experience with us and to ensure that you receive any loyalty rewards which are due to you. We will periodically review the personal information we hold and delete it securely, or in some cases anonymize it, when there is no longer a legal, business, or consumer need for it to be retained.
The existence of data subject rights
If you live in the European Economic Area (EEA), you have a number of rights when it comes to your personal data. If you wish to exercise these rights with regards to your personal data that we hold, please contact us here. Further information and advice about your rights can be obtained from the data protection regulator in your country. These include:
- The right to be provided with clear, transparent and easily understandable information about how we use your information and your rights (which is why we are providing you with the information in this Policy).
- The right to obtain access to your information (if we are processing it).
- The right to have your information corrected if it is inaccurate or incomplete. You can do this through your account page or by contacting us.
- The right to “block” or suppress further use of your information. When processing is restricted, we can still store your information, but may not use it further. We keep lists of people who have asked for further use of their information to be 'blocked' to make sure the restriction is respected in future.
- The right to request that we delete or remove your data where there is no compelling reason for us to keep using it. This is not a general right to erasure; there are exceptions
- The right to request that we transfer or port elements of your data either to you or another service provider.
- The right to object to certain types of processing, including processing for direct marketing (i.e., if you no longer want to be contacted with potential opportunities).
- If you have given your consent to anything we do with your personal data, you have the right to withdraw your consent at any time.
- You also have the right to lodge a complaint about the way we handle or process your personal data with your national data protection regulator.
Pursuant to applicable data protection law, we may be entitled to refuse to act on the request. To make these requests with BSC, please submit your name, address, and email address, in addition to the specifics of your request, in an email to Lindsay here.
Updated: July 18, 2022