Privacy & Data Rights

Privacy Policy 

Revised December 2023
Effective December 2023

This privacy policy describes the personal information that we, Peaberry Software Inc. d/b/a Customer.io (“Customer.io,” “we,” “our” or “us”), collect (1) from individuals when they visit our website (the “Site”), interact with our marketing communications, register to attend events that we host, interact with our social media profiles and otherwise engage with us, and (2) the information we collect on behalf of our customers who employ our technology to use our digital marketing services (the “Services”). Individuals should refer to our customers’ privacy policies for information about how our customers collect, use and share information. In this privacy policy, we describe where we collect information on our own behalf, for our business purposes, and where we collect information on our customers’ behalf as a service provider or data processor.

[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop

This privacy policy does not apply to our employees or to job applicants. We do not knowingly collect information from children. If we discover that we have inadvertently collected information from anyone younger than the age of 16, we will delete that information.

This policy includes the following sections:

Personal Information We Collect, Purpose for Processing & Categories of Third Parties Personal Information is Shared with

Categories of Personal Information

Example

Purpose for Processing

Categories of Third Parties Shared With

Identifiers

Name, email address, unique identifier, online identifier, transaction identifiers, device ID, advertising ID, and IP address

Services

Customer.io

Select information in customer records

Name, email, address, and telephone number, products or services purchased, appointments made

Payment processor information is collected about the transactions you make (such as transaction date, payment information, credit card or debit card number and zip code)

Services

Customer.io

Geolocation

Course IP address (not precise geolocation)

Internet or network activity

Browsing history, search history, and information regarding a consumer’s interaction with website, application, or advertisement

Services

Customer.io

Audio, electronic, visual, thermal, olfactory, or similar information

Such as call recordings

Customer.io

Education information

Such as information that is not publicly available as defined in the California Family Educational Rights and Privacy Act

We only collect this information from employees and job applicants, in accordance with applicable law

.

Professional or employment related information

Such as place of employment, position, job history, salary, resume, and other related data

We only collect this information from employees and job applicants, in accordance with applicable law

.

Characteristics of protected classifications under California or Federal law

Characteristics of protected classifications under California or federal law refer to consumers’ race, ancestry, national origin, religion, age, mental and physical disability, sex, sexual orientation, gender identity, medical condition, genetic information, marital status, and military status

We only collect this information from employees and job applicants, in accordance with applicable law

.

Inferences from information that could be used to create a profile

Inferences drawn about you based on other personal information we collect, such as preferences, interests, user behavior data

Services

Customer.io

Sensitive Personal Information

Social security number, financial account information, your precise geolocation data, your genetic data, political beliefs, racial origin, religious beliefs, sex life, sexual orientation, trade union membership, etc.

Services

Customer.io

How We Collect Personal Information

We collect information in the following ways:

Information We Collect Automatically

When you interact with the Site or Services, certain information about your use of our Site and Services is collected automatically. This information is collected automatically when you visit our Site and when you open communications from our customers. This includes:

We use the following types of cookies on the Site for the following purposes:

How We Use Personal Information

We use the personal information that we collect to:

How We Share Personal Information

We share personal information with the following categories of third parties:

[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop

EEA, UK, & Swiss Data Privacy Rights

Data Subject Rights

If you are a resident of the European Economic Area (“EEA”), the United Kingdom (“UK”), or Switzerland, you are entitled to certain rights. These rights include:

[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop

We process personal information, or “Personal Data” as that term is defined in the EU General Data Protection Regulation, on the following legal bases: (1) with your consent; (2) as necessary to perform our agreement to provide Services; and (3) as necessary for our legitimate interests where those interests do not override your fundamental rights and freedom related to data privacy. We may also process personal information as necessary to comply with legal obligations. Information we collect may be transferred to, and stored, and processed in, the United States or any other country in which we or our affiliates or subcontractors maintain facilities, as described above.

[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop

Cross-border Transfer of Data

If you use our Services outside of the United States, you understand that we may collect, process, and store your information in the United States and other countries. The laws in the US regarding information may be different from the laws of your state or country. Any such transfers will comply with safeguards as required by relevant law.

[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop

Data Privacy Framework Notice

[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop

Customer.io is responsible for the processing of personal information it receives under the DPF and subsequently transfers to a third party acting as an agent on its behalf. Customer.io complies with the DPF Principles for all onward transfers of personal information from the EU, UK, and Switzerland, including the onward transfer liability provisions.

The Federal Trade Commission has jurisdiction over Customer.io’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. In certain situations, Customer.io may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Customer.io commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to JAMS, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit jamsadr.com/dpf-dispute-resolution for more information or to file a complaint. The services of JAMS are provided at no cost to you.

For complaints regarding DPF compliance not resolved by any of the other DPF mechanisms, you have the possibility, under certain conditions, to invoke binding arbitration. Further information can be found on the official DPF website.

U.S. State Privacy Rights

If you are a resident of California, Virginia, Colorado, Connecticut, or Utah, or any other state that grants you specific data privacy rights, you may have additional rights regarding our use of your personal information. The rights outlined in this section do not apply to information exempted under applicable state privacy law. Further, the rights described in this Section are not absolute, are subject to exceptions and limitations, and may not be afforded to residents of all states. In certain cases, we may decline requests to exercise these rights where permitted by law.

Persons with disabilities may obtain this notice in alternative format upon request by contacting us at legal@customer.io.

U.S. Privacy Rights

To the extent you are provided additional privacy rights in the state you reside, you have the following rights with respect to the information that we collect (in each case, subject to applicable law):

Right to Opt Out of the Sale or Sharing of Personal Information to Third Parties

[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop

Exercising Your State Privacy Rights

If you reside in a state that provides specific data privacy rights, you may contact us:

[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop
[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop

Your rights may only be exercised by you or by your designated agent. You may submit a request to know twice within a 12-month period unless applicable data privacy law grants you additional rights.

Your request must include enough information to allow us to reasonably verify that you are the person about whom we collected personal information or an authorized representative, which may include: (1) verifying your account information if you have an account with us; or (2) requesting two forms of identification that are reliable for verification purposes, unless the request includes sensitive information and, in which case, we may require three forms of verification and a signed declaration. The information included in your request must allow us to properly understand, evaluate, and respond to it.

We cannot respond to your request if we cannot verify your identity or authority to make the request and confirm that the personal information relates to you. If we cannot verify your identity or authority, we will not fulfill your request. We will only use personal information provided in the request to verify the requestor’s identity or authority to make it.

You may submit a request through a designated agent. You must instruct that agent that they will need to state that they are acting on your behalf when making the request, have reasonably necessary documentation, and be prepared to provide the necessary personal information to properly verify your request.

We will acknowledge receipt of your request. We will provide a substantive response within 45 calendar days or inform you of the reason and extension period (up to a total of 90 days) in writing.

Special Information for Nevada Residents

Residents of the State of Nevada have the right to opt-out of the sale of certain pieces of their information to other companies who will sell or license their information to others. At this time, Customer.io does not engage in such sales. If you are a Nevada resident and would like more information about our data-sharing practices, please email legal@customer.io.

California Shine the Light

Residents of the State of California have the right to request information from Customer.io regarding other companies to whom the company has disclosed certain categories of information during the preceding year for those companies’ direct marketing purposes. If you are a California resident and would like to make such a request, please email legal@customer.io or write to us at 921 SW Washington St., Suite #820, Portland, OR 97205.

How We Protect Personal Information

We use a combination of physical, technical, and administrative safeguards to protect the information we collect through the Services. While we use these precautions to safeguard your information, we cannot guarantee the security of the networks, systems, servers, devices, and databases we operate or that are operated on our behalf.

How Long We Retain Personal Information

We retain your personal information for as long as we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax, or accounting requirements).

The criteria used to determine appropriate retention period for personal information include:

Changes to This Policy

We may make changes to this privacy policy from time to time. We will post any changes here, and such changes will become effective when they are posted. Your continued use of the Site or our Services, or your interaction with us following the posting of any changes will mean you consent to those changes.

Your Choices Regarding Your Information

We offer the following options for updating your information or opting out of our processing of your personal information:

[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop
[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop

Contact Us

For questions about our privacy practices, contact us at:

Peaberry Software Inc. d/b/a Customer.io

9450 SW Gemini Dr., Suite 43920, Beaverton, Oregon 97008-7105.

[@portabletext/react] Unknown block type "block", specify a component for it in the `components.types` prop

Phone Number: 646-820-9503