Last Updated: May 22, 2018
We take your privacy extremely seriously. This policy explains the what, how, and why of the information we collect when you visit one of our websites, or when you use our Services. It also explains the specific ways we use and disclose that information.
Please note that for the purposes of EU data protection legislation, MageMail is the data processor of personal information.
Throughout this document, we may use certain words or phrases, and it is important that you understand the meaning of them. The following is a non-exhaustive list of definitions of words and phrases found in this document:
- “Customer” or “Customers” refers to your customers purchasing products or services from you. In this definition, this includes prospects who have not yet purchased your products or services but have shown interest;
- “MageMail” refers our Site, our Services, our company or a combination of all or some of the preceding definitions, depending on the context in which the word is used;
- “Personal Data” or “Personal Information” means any information relating to an identified or identifiable natural person.
- “Service” or “Services” refers to the applications, including related features and capabilities, that we provide through our Site, including our e-mail marketing services and our Site itself;
- “Site” or “Website” refers to our website, www.magemail.co, and underlying applications;
- “Store” refers to a single instance of an online store;
- “You” or “you” refers to you, the person who is entering into this Agreement with MageMail on behalf of yourself and your company;
- “User” or “Users” refers to anyone who uses our Service, including you and general visitors to our Site
- Information We Collect
- List and email information:When you add a subscriber list, create a campaign, or create an email with the Services, we have and may access the data on your list and the information in your email. If a Customer chooses to use forward a link in an email campaign you send, it will allow the Customer to share your email content with individuals not on your subscriber list or in your campaign. When a Customer forwards an email to another person, we do not store that other person’s email address.
- Information from your use of the Service:We may receive information about how and when you use the Services, store it in log files or other types of files associated with your account, and link it to other information we collect about you. This information may include, for example, your IP address, time, date, browser used, and actions you have taken within the application. This type of information helps us to improve our Services for both you and for all of our users.
- Web beacons and hooks:We use web beacons and hooks on our Websites and in our emails. When we send emails to Customers, we may track behavior such as who opened the emails and who clicked the links. This allows us to measure the performance of the email campaigns and to improve our features for specific segments. Reports are also available to us when we send email to you, so we may collect and review that information.
- Use and Disclosure of Personal Information
We may use and disclose Personal Information only for the following purposes:
- To promote use of our Services to you and others. For example, if we collect your Personal Information when you visit our Website and do not sign up for any of the Services, we may send you an email inviting you to sign up. If you use any of our Services and we think you might benefit from using another Service we offer, we may send you an email about that. You can stop receiving our promotional emails by following the unsubscribe instructions included in every email we send. In addition, we may use information we collect in order to advertise our Services to you or suggest additional features of our Services that you might consider using. In addition, we may use your Personal Information to advertise our Services to potential or other users like you.
- To send you informational and promotional content in accordance with your marketing preferences. You can stop receiving our promotional emails by following the unsubscribe instructions included in every email.
- To bill and collect money owed to us by You. This includes sending you emails, invoices, receipts, notices of delinquency, and alerting you if we need a different credit card number. We use third parties for secure credit card transaction processing, and we send billing information to those third parties to process your orders and credit card payments.
- To communicate with You about Your account and to provide customer support.
- To enforce compliance with our Terms of Services and applicable law. This may include developing tools and algorithms that help us prevent violations.
- To protect Your rights and safety as well as those of third parties and our own.
- To meet legal requirements, including complying with court orders, valid discovery requests, valid subpoenas, and other appropriate legal mechanisms.
- To provide information to representatives and advisors, including attorneys and accountants, to help us comply with legal, accounting, or security requirements.
- To prosecute and defend a court, arbitration, or similar legal proceeding.
- To respond to lawful requests by public authorities, including to meet national security or law enforcement requirements.
- To provide, support, and improve the Services we offer. This includes our use of the data that our Members provide us in order to enable our Members to use the Services to communicate with their Subscribers. This also includes, for example, aggregating information from your use of the Services or visit to our Websites and sharing this information with third parties to improve our Services. This might also include sharing your information or the information you provide us about your Subscribers with third parties in order to provide and support our Services or to make certain features of the Services available to you. When we do have to share Personal Information with third parties, we take steps to protect your information by requiring these third parties to enter into a contract with us that requires them to use the Personal Information we transfer to them in a manner that is consistent with this policy.
- To provide suggestions to you. This includes adding features to compare email campaigns or using data to suggest products or services that you may be interested in or that may be relevant to you or your Customers.
- Data Collected for and by our Users
As you use our Services, you may import into our system Personal Information you have collected from your Customers or other individuals. We have no direct relationship with your Customers or any person other than you, and for that reason, you are responsible for making sure you have the appropriate permission for us to collect and process information about those individuals.
- Commercial and Non-Commercial Communications to You
We will retain Personal Information we process for as long as needed to provide our Services or to comply with our legal obligations, resolve disputes, prevent abuse, and enforce our agreements.
- Public Information and Third Party Websites
Blog. We have public blogs on our Websites. Any information you include in a comment on our blog may be read, collected, and used by anyone. If your Personal Information appears on our blogs and you want it removed, contact us. If we are unable to remove your information, we will tell you why.
Social media platforms and widgets. Our Site includes social media features. These features may collect information about your IP address and which page you are visiting on our Site, and they may set a cookie to make sure the feature functions properly. Social media features and widgets are either hosted by a third party or hosted directly on our Site. We also maintain presences on social media platforms including Facebook, Twitter, and Instagram. Any information, communications, or materials you submit to us via a social media platform is done at your own risk without any expectation of privacy. We cannot control the actions of other users of these platforms or the actions of the platforms themselves. Your interactions with those features and platforms are governed by the privacy policies of the companies that provide them.
- Third Parties
Service Providers. Sometimes, we share your information with our third party Service Providers, who help us provide and support our Services. For example, if it is necessary to provide you something you have requested then we may share your and/or your Customer’s Personal Information with a Service Provider for that purpose. Just like with the other third parties we work with, these third party Service Providers enter into a contract that requires them to use your Personal Information only for the provision of services to us and in a manner that is consistent with this policy. Examples of Service Providers include payment processors, hosting services, and content delivery services.Without limiting the generality of the foregoing, you authorize us to collect, share, store, and otherwise use your information in conjunction with the entities listed in our Third-Party Sub-Processors page.
- Content of Email Campaigns
When you send an email marketing campaign, it bounces from server to server as it crosses the Internet. Along the way, server administrators can read what you send. Email was not built for confidential information. Please do not use MageMail to send confidential information.
- Your Subscriber Lists and Campaigns
A Subscriber List and related Campaigns can be created in a number of ways, including by importing contacts, such as through csv or directly from Magento. Magento is the system of record for your Subscriber Lists, and we sync subscribes and unsubscribes. Data is stored on a secure MageMail server. We do not, under any circumstances, sell your Subscriber Lists. Only authorized employees have access to view Subscriber Lists. You may export (download) your Subscriber Lists from MageMail at any time.
We do not, under any circumstances, sell your Subscriber Lists. We will use and disclose the information in your Subscriber Lists only for the legal and regulatory reasons. We will not use and disclose the information in your Subscriber Lists to:
- bill or collect money owed to us;
- send you informational and promotional content.
If we detect abusive or illegal behavior related to your Subscriber List, we may share your Subscriber List or portions of it with affected ISPs or anti-spam organizations.
- Notice of Breach of Security
If a security breach causes an unauthorized intrusion into our system that materially affects you or people on your Subscriber Lists, then MageMail will notify you as soon as possible and later report the action we took in response.
- Safeguarding Your Information
We take reasonable and appropriate measures to protect Personal Information from loss, misuse and unauthorized access, disclosure, alteration and destruction, taking into account the risks involved in the processing and the nature of the Personal Information.
Our credit card processing vendor uses security measures to protect your information both during the transaction and after it is complete. Our vendor is certified as compliant with card association security initiatives, including the Visa Cardholder Information Security and Compliance (CISP), MasterCard® (SDP), and Discovery Information Security and Compliance (DISC). If you have any questions about the security of your Personal Information, you may contact us at email@example.com.
MageMail accounts require a username and password to log in. You must keep your username and password secure, and never disclose it to a third party. Because the information in your Subscriber Lists is sensitive, account passwords are encrypted, which means we cannot see your passwords.
- Operations in the United States
Our servers and headquarter offices are located in the United States, so your information may be transferred to, stored, or processed in the United States. While the data protection, privacy, and other laws of the United States might not be as comprehensive as those in your country, we take many steps to protect your privacy, including offering a data processing addendum. By using our Site, you understand and consent to the collection, storage, processing, and transfer of your information to our facilities in the United States and those third parties with whom we share it as described in this policy.
- Data Transfers from Switzerland or the EU to the United States
MageMail adheres to and is being certified for its compliance with the EU-U.S. Privacy Shield Framework and the Swiss-U.S Privacy Shield Framework. We are committed to subjecting all Personal Information received from European Union (EU) member countries and Switzerland, respectively, in reliance on each Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Frameworks, visit the U.S. Department of Commerce’s Privacy Shield website: https://www.privacyshield.gov/welcome. A list of Privacy Shield participants is maintained by the Department of Commerce and is available at: https://www.privacyshield.gov/list.
MageMail is responsible for the processing of Personal Information it receives under each Privacy Shield Framework and subsequently transfers to a third party acting as an agent on its behalf. We comply with the Privacy Shield Principles for all onward transfers of personal data from the EU and Switzerland, including the onward transfer liability provisions.
With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, we are subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider JAMS (free of charge to you) at JAMS File a Claim. Under certain conditions, more fully described on the Privacy Shield website, https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
Users located in Switzerland and the EU are also free to request our updated data processing agreement which incorporates the Standard Contractual Clauses here in addition or instead of relying on MageMail’s Privacy Shield certification, as applicable.
- Users Located in Australia
If you are a Member who lives in Australia, this Section applies to you. We are subject to the operation of the Privacy Act 1988 (“Australian Privacy Act”). Here are the specific points you should be aware of:
Where we say we assume an obligation about Personal Information, we are also requiring our subcontractors to undertake a similar obligation, where relevant.
We will not use or disclose Personal Information for the purpose of our direct marketing to you unless: you have consented to receive direct marketing; you would reasonably expect us to use your personal details for the marketing; or we believe you may be interested in the material but it is impractical for us to obtain your consent. You may opt out of any marketing materials we send to you through an unsubscribe mechanism or by contacting us directly. If you have requested not to receive further direct marketing messages, we may continue to provide you with messages that are not regarded as “direct marketing” under the Australian Privacy Act, including changes to our terms, system alerts, and other information related to your account.
Our servers are primarily located in the United States. In addition, we or our subcontractors, may use cloud technology to store or process Personal Information, which may result in storage of data outside Australia. It is not practicable for us to specify in advance which country will have jurisdiction over this type of off-shore activity. All of our subcontractors, however, are required to comply with the Australian Privacy Act in relation to the transfer or storage of Personal Information overseas.
If you think the information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, we will take reasonable steps, consistent with our obligations under the Australian Privacy Act, to correct that information upon your request.
If you are unsatisfied with our response to a privacy matter then you may consult either an independent advisor or contact the Office of the Australian Information Commissioner for additional help. We will provide our full cooperation if you pursue this course of action.
- Accuracy and Retention of Data
We do our best to keep your data accurate and up to date, to the extent that you provide us with the information we need to do so. If your data changes (for example, if you have a new email address), then you are responsible for notifying us of those changes. Upon request, we will provide you with information about whether we hold, or process on behalf of a third party, any of your Personal Information. We will retain your information for as long as your account is active or as long as needed to provide you with our Services. We may also retain and use your information in order to comply with our legal obligations, resolve disputes, prevent abuse, and enforce our Agreements.
We will give an individual, either you or a Subscriber, access to any Personal Information we hold about them within 30 days of any request for that information. Individuals may request to access, correct, amend or delete information we hold about them by contacting us. Unless it is prohibited by law, we will remove any Personal Information about an individual, either you or a Subscriber, from our servers at your or their request. There is no charge for an individual to access or update their Personal Information.
- California Privacy
Under California Law, California residents have the right to request in writing from businesses with whom they have an established business relationship, (a) a list of the categories of Personal Information, such as name, email and mailing address and the type of services provided to the customer, that a business has disclosed to third parties (including affiliates that are separate legal entities) during the immediately preceding calendar year for the third parties’ direct marketing purposes and (b) the names and addresses of all such third parties. To request the above information, please contact us at firstname.lastname@example.org.
If you have any questions or comments, or if you want to update, delete, or change any Personal Information we hold, or you have a concern about the way in which we have handled any privacy matter, please contact us by postal mail or email at: email@example.com or 112 Water Street, Suite 500, Boston, MA 02109, United States.