Personal Data We Collect
Personal Data you provide. We collect Personal Data that you provide directly to us. For example, you provide certain Personal Data when you create a Customer Account, enter into a contractual relationship with us (individually or on behalf of a company or other legal entity), fill out a “contact us” form, enroll in billing, or otherwise communicate with us. The types of Personal Data we collect include:- Customer Account Information. We collect Personal Data that you provide when you register for a Customer Account, including account credentials (such as your password), professional information (such as your company name, company URL, and job title), and identifiers (such as your name, email address, and phone number).
- Payment Information. We collect payment information that you provide when you sign up for our Services. We use third-party payment processors to process the payments you make to us. As such, you provide payment information directly to the third-party processor. You should review the processor’s privacy notice to learn how they treat your information. We receive only the last 4 digits of your credit card number and transaction-related information such as payment date, amount, card type, device type, and IP address.
- End User Information. We collect Personal Data that you provide to us or authorize us to access regarding your customers, including but not limited to customer identifiers, transaction history, order identifiers, and item-level purchase details. This Personal Data is collected and processed solely for the purpose of providing you with our Services. You must only provide end user Personal Data to us in accordance with applicable laws, and subject to any privacy or disclosure settings made by such end users.
- Product Information. We collect and process Personal Data regarding your products, including product identifiers (such as barcodes, SKUs, and UPCs), product names, and related metadata, in order to enable accurate matching of external retail purchases and for other purposes in connection with our Services.
- Communications. When you contact us through any mode of communication, such as email or a “contact us” form on our website, we may collect your name, email address, address, phone number, company name, account ID, and other Personal Data you provide to us. We may also collect information from you in connection with customer service calls. Please note that our written and verbal communications with you may be recorded and stored by us and vendors on our behalf for training and internal business purposes.
- Log Information. We collect information that your browser or device automatically sends when you use our Services. Log information includes your IP address, browser type and settings, the date and time of your request, and how you interact with our Services.
- Device Information. We collect information about the device you use to interact with our Services, such as the name of the device, the hardware model and operating system, IP address, domain server, the date and time of your interaction with the Services, timezone setting and location, and other technical information about the device. The information we collect may depend on the type of device you use and its settings.
- Location Information. We may determine the general area from which your device accesses our Services based on information such as its IP address.
- Cookies and Similar Technologies. As described more fully in our Cookie Policy, we use cookies and other related technologies in operating our Services.
How We Use Your Personal Data
We may use the Personal Data we collect for the following purposes:- To fulfill our contractual obligations and provide the Services you have requested;
- To operate, improve, and personalize our Services;
- To promote and sell our Services;
- To track opportunities and generate leads;
- To bill you for our Services;
- To respond to your communications with us, including support requests;
- To communicate with you about our products, services, offers, and events;
- To send you legal and technical notices, updates, security alerts, and messages about your account;
- To prevent and investigate fraud and other illegal activities;
- To monitor, test, and update our Services, and diagnose and fix technical problems;
- To maintain the security and integrity of our Services and property;
- To enforce our contractual rights, resolve disputes, and protect the rights, privacy, safety, and property of Subtotal and others; and
- To comply with our legal obligations.
Online Analytics and Advertising
Online Analytics. As discussed in greater detail in our Cookie Policy, we may use third-party analytics in connection with our Services (e.g., analytics platforms such as Google Analytics or PostHog). These vendors may set and access their own cookies, pixel tags, and similar technologies on our Services and on third-party services to collect information that can be used to track users over time and across services. These analytics tools help us understand how users arrive at and use our Services. If you do not want Google Analytics to collect and use information about your use of our Services, then you can install an opt-out in your web browser. You also may opt-out from Google Analytics for Display Advertising or the Google Display Network by using Google’s ads settings. Online Advertising. We strive to provide you with relevant, value-added content in our online advertisements. We work with online analytics and advertising partners to: (i) better understand the use of our Services so that we can improve them; and (ii) deliver advertisements that are more tailored to you both on our Services and on third-party apps and websites. Our partners may place cookies, pixel tags, and similar technologies on many online services, including ours. They use these technologies to collect information about your activities on these services in order to deliver you more relevant advertising. For example, they may use the information they collect from their cookies on our Services to identify products and services you might be interested in. For information about how to opt out of receiving personalized online advertisements from our advertising partners, follow the instructions in the “Your Rights and Choices” section below. Please visit our Cookie Policy for more details.How We Disclose Your Personal Data
We disclose your Personal Data as follows:- With service providers, agents, and contractors who provide services for us, such as payment processors, web hosting providers, data storage providers, email and messaging communications providers, analytics providers, and customer relationship and support providers;
- With advertisers and other third parties who use cookies and related technologies to collect information about your use of the Services (see our Cookie Policy and the “Online Advertising and Analytics” section above for more details);
- To comply with our legal obligations and with legal or regulatory processes (such as subpoenas);
- To prevent fraud, malicious activity, and other privacy and security-related concerns or otherwise protect the rights, property, and safety of Customers, end users, Retailers, Subtotal, and others;
- With third parties in relation to a change in ownership or control of all or a part of our business or assets, or in contemplation thereof, such as a merger, acquisition, bankruptcy, or reorganization; and/or
- Between and among Subtotal and our current and future parents, affiliates, and subsidiaries.
Data Security
We seek to protect your Personal Data from unauthorized access, use, and disclosure. We maintain a variety of physical, technical, and administrative security measures appropriate to the risk associated with the processing of your Personal Data. Unfortunately, no data transmission or storage system is completely secure. For additional information about our security practices, please visit our Security Page.Data Retention
We retain your Personal Data for as long as necessary to provide our Services and to fulfill the purposes for which we collected it, including for the purposes of complying with our legal obligations, resolving disputes, and collecting fees. When establishing a retention period for specific categories of information, we consider who we collected the information from, our need for the information, our reason for collecting the information, and the amount and sensitivity of the information. If we aggregate, de-identify, or anonymize information such that it can no longer be used to identify you personally, we may use that information indefinitely without further notice to you.Your Rights and Choices
Your Choices- Customer Account Information. You may update your Customer Account information by logging into your account on our website or by contacting us.
- Cookies. You can find more information about how we use cookies and your related choices in our Cookie Policy.
- Marketing Communications. In accordance with applicable law, we may send you marketing communications. You may opt out of receiving marketing emails from Subtotal by following the instructions in those emails. If you opt out, we may still send you other types of emails, such as legal notices and support, service, and other emails regarding your account.
- Information. To request information about the categories of Personal Data we have collected, the sources from which we collected the data, and how we have used and disclosed your Personal Data; this information is contained in this Privacy Policy.
- Access. To access a copy of the Personal Data we have collected from and about you.
- Deletion. To request that we delete the Personal Data we have collected from and about you.
-
Opt Out. To request to opt out of:
- The “sale” of your Personal Data;
- The “sharing” or “processing” of your Personal Data for online targeted advertising purposes;
- The use of automated decision-making regarding your Personal Data, where such processing results in legal or similarly significant impacts (note that we have not engaged in such processing over the prior 12 months); and
- The use of your “sensitive” Personal Data, in certain circumstances (note that we do not process “sensitive” Personal Data in a way that is subject to this opt out right).
- Nondiscrimination. To exercise these rights free from discrimination.
Additional Information for California Residents
If you are a California resident, the California Consumer Privacy Act (“CCPA”) requires us to provide you with information about:- The purpose for which we use each category of “personal information” (as defined in the CCPA) we collect; and
- The categories of third parties to which we (a) disclose such personal information for a business purpose, (b) “share” personal information for “cross-context behavioral advertising,” and/or (c) “sell” such personal information.
Personal Information Category | Business Purpose of Use | Third Parties to Whom Information is Disclosed | Third Parties to Whom Information is Sold/Shared |
---|---|---|---|
Identifiers (e.g., name, email address, address) |
|
|
|
Commercial information (e.g., records of your purchase of Services from us) |
|
|
|
Professional Information (e.g., company, title, and role) |
|
|
|
Payment Information (collected and stored by a third-party payment processor on our behalf) |
|
|
|
Internet or other similar network activity (including usage information) |
|
|
|
Geolocation data (e.g., physical location at the city/state level) |
|
|
|
Inferences drawn from other information |
|
|
|
Sensory data (e.g., photos or videos you provide in reviews, customer service call recordings for quality assurance) |
|
|
|
Account log-in credentials |
|
|
|
Contact Us
If you have any questions or comments about this Privacy Policy, our collection and use of your Personal Data, or your rights and choices regarding such collection and use, please contact us at: https://www.subtotal.com/legal@subtotal.com
100 Church Street, Suite 800
New York, NY 10007