Privacy Policy

Last Updated August 24, 2018

Welcome to People for Bikes! This Privacy Policy is here to help you understand how we collect, use, disclose, and process your Personal Data (as defined below). We also describe your choices and rights with respect to how we process that Personal Data. Please read this policy carefully.

Who We Are
This is the Privacy Policy of the People for Bikes Coalition and the People for Bikes Foundation (“PeopleForBikes”, “us”, “our”, or “we”), a Colorado non-profit with offices at 1966 13th St., Suite 250, Boulder, CO 80302. You can contact us here.

Applicability
This Privacy Policy applies to our website, including any subdomains, mobile versions, and any other sites that link to or post this Privacy Policy (collectively, the “Site(s)”).

Agreement
This Policy is incorporated into the Terms of Use governing your use of our Sites. Any capitalized terms not defined in this Privacy Policy will have the definitions provided in our Terms of Use.
Your continued use of our Sites indicates your acknowledgement of the practices described in this Policy.

Third Parties
This Policy does not apply to information processed by other third parties, for example, when you visit a third-party website or interact with third-party services (including third-party services listed as “PeopleForBikes Resources” on our Site), unless and until we receive your information from those parties. Please review any third-party privacy policies before disclosing your Personal Data to them.

Collection and Use of Personal Data

Personal Data We Collect
We may collect and process information that relates to identified or identifiable individuals (“Personal Data”). We collect and process the following categories of Personal Data (note, specific Personal Data elements listed in each category are only examples and may change):

  • Identity Data: Personal Data about you and your identity, such as your first name, last name, favorite activities, and other Personal Data you may provide on engagement forms or donation forms on our site (e.g. biographical information).
  • Transaction Data: Personal Data we collect in connection with a transaction or purchase, such as the item purchased, the price, the delivery location, zip code, and other similar information.
  • Contact Data: Personal Data used to contact you, e.g. email address(es), physical address(es), phone number(s), or social media or communications platform usernames/handles, as well as a name or other salutation.
  • Financial Data: Personal Data relation to financial accounts or services, e.g. a credit card or other financial account number, and other relevant information you provide in connection with a financial transaction.
  • Device Data: Personal Data relating to your device, browser, or application e.g. IP addresses, MAC addresses, application or device IDs, identifiers from cookies, session history, site-referral, and other data generated through applications and browsers, including cookies and similar technologies.
  • Use Data: Personal Data relating to your use of our Site, such as when you visited or used our forms, information about electronic communications you receive from us, such as whether that communication has been opened or if you have clicked on any links within that communication, site-referral, and other data generated through applications and browsers, including cookies and similar technologies.
  • Preferences Data: Personal Data relating to your preferences, interests, personal demographics (e.g. location of residence, age group, gender, etc.), your “likes,” and other information provided to us via social media services, including any other categories of information (such as Transaction Data or Identity Data linked to such information).
  • User Content: Information that a user provides in a story, testimonial, free text field, or other unstructured format, including any Personal Data to the extent provided by the user.

Processing of Personal Data

Purchases and Donations

  • Data: We process Transaction Data, Identity Data, Financial Data, Preferences Data, and certain Contact Data when you complete a purchase or make a donation on our Sites. Note, some purchases and donations are made directly through us, and others are processed by third parties on our behalf. For example, as of the effective date of this policy, our store is powered by a third party vendor, Shopify. We may obtain any Personal Data processed by a third party on our behalf.
  • Uses: We use the Transaction Data, Identity Data, and Contact Data as necessary to complete and provide you with important information regarding your transaction or donation. Financial Data is used primarily to process your transaction. Subject to Your Rights and Choices, we may process Transaction Data and Identity Data, to improve our services and create a personalized user experience, or in connection with marketing communications, and any information we collect in connection your transaction may be processed in order to detect fraud, risk., and customer authentication or for information security purposes (which may be performed via automated means).
  • Note: Any personal data processed by Shopify will be processed as set forth in the Shopify Privacy Policy available at: shopify.com/legal/privacy. Shopify (and other payment processors) may process personal data provided during your purchase/payment transaction using automated means, and such automated processing may result in your inability to complete a transaction, e.g. as a result of security or fraud detection.

User Content and Form Submission

  • Data: We process Identity Data, Contact Data, and Use Data when you submit User Content to us or fill out one of our forms – for example, the Local Engagement Portal, our Letter to Congress form, or a Why Do You Ride story. If you use social media services to post content that references our official accounts, your comment or content may appear on our Site or be linked to our official accounts through the social media platform. We may receive this data from a third party if provided to us by a third party.
  • Uses: We use Identity Data and Contact Data as necessary to feature User Content and for integration with social media on our Sites. Subject to Your Rights and Choices, we may also use Identity Data and User Content to improve our services and we may process Identity Data and Contact Data in connection with marketing communications.
  • Note: Certain User Content you provide may be made public as when as you post it on our Sites. We do not screen comments or other postings for personal or inappropriate content.

Marketing Communications

  • Data: If you choose to enroll to receive marketing communications or when you open or interact with our marketing communication, we may process Identity Data and Contact Data you provide us in order to personalize and send email marketing communications.
  • Uses: We use Identity Data and Contact Data as necessary to provide marketing communications, and consistent with our legitimate business interests, we may send you marketing and promotional communications if you sign up for those communications or register for our Service. See Your Rights and Choices for information about how you can limit or opt out of this processing.

Cookies and Similar Tracking Technologies

  • Data: We, and certain third parties, may process Contact Data, Preferences Data and Device Data when you interact with cookies and similar technologies on our Site. We may receive this data from third parties to the extent allowed by the applicable partner. Please note that the privacy policies of third parties may apply to these technologies and information collected.
  • Uses: Subject to Your Rights and Choices, we use this information as follows:
    • (i) for “essential” or “functional” purposes, such as to enable various features of the Platform such as remembering passwords, or staying logged in during your session;
    • (ii) for “analytics” purposes, consistent with our legitimate interests in how the Platform is used or performs, how users engage with and navigate through the Platform, what sites users visit before visiting our Platform, how often they visit our Platform, and other similar information; and
    • (iii) for “retargeting” or similar advertising purposes, so that you can see advertisements from us on other websites. These technologies and the data they collect may be use advertisers deliver ads that are more relevant to you based on content you have viewed, including content on our Site. These tracking technologies may also help prevent you from seeing the same advertisements too many times, and help us understand whether you have interacted with or viewed ads we’ve delivered to you. This collection and ad targeting takes place both on our Site and on third-party websites or Sites that participate in the ad network, e.g. any advertisements delivered by that ad network on a third party website.
  • Note: Some of these technologies can be used by us and/or our third-party partners to identify you across platforms, devices, sites, and services.

Internal Processes
Subject to Your Rights & Choices, we may process any information we collect in connection to analyze how users interact with our Site, in connection with market research, for product and Site improvements, and as necessary to monitor and maintain the integrity and security of our Site and the data we process.

Aggregated Data
We will collect and aggregate on an anonymous basis information about you, including with information about other users of the Sites in order to identify trends, security anomalies, process maps, or other proprietary data (“Aggregated Data”). We may share Aggregated Data with the third parties referred to in the section below to improve the functionality and effectiveness of the Site. Aggregated Data will not contain information from which you may be personally identified.

Additional Processing
If we process Personal Data in connection with our Site in a way not described in this Policy, this Policy will still apply generally (e.g. with respect to Your Rights and Choices) unless otherwise stated when you provide it.
Note that we may, without your consent, also process your Personal Data on certain public interest grounds. For example, we may process information as necessary to fulfil our legal obligations, to protect the vital interests of any individuals, or otherwise in the public interest. Please see the Data Sharing section for more information about how we disclose Personal Data in extraordinary circumstances.

Data Sharing

Generally
Information we collect may be shared with a variety of parties, depending upon the purpose for and context in which that information was provided. We generally transfer data to the following categories of recipients:

  • Service Providers: In connection with our general business operations, product/service improvements, to enable certain features, and in connection with our other legitimate business interests, we may share your Personal Data with service providers or subprocessors who provide certain services or process data on our behalf. For example, we may use hosting services such as Amazon Web Services to host our Site.
  • Affiliates: In order to streamline certain business operations and develop products and services that better meet the interests and needs of our customers, and inform our customers about relevant products and services, we may share your Personal Data with any of our current or future affiliated entities, subsidiaries, and parent companies.
  • Corporate Events: Your Personal Data may be processed in the event that we go through a business transition, such as a merger, acquisition, liquidation, or sale of all or a portion of our assets. For example, Personal Data may be part of the assets transferred, or may be disclosed (subject to confidentiality restrictions) during the due diligence process for a potential transaction.
  • Legal Disclosures: In limited circumstances, we may, without notice or your consent, access and disclose your Personal Data, any communications sent or received by you, and any other information that we may have about you to the extent we believe such disclosure is legally required, to prevent or respond to a crime, to investigate violations of our Terms of Use, or in the vital interests of us or any person. Note, these disclosures may be made to governments that do not ensure the same degree of protection of your Personal Data as your home jurisdiction. We may, in our sole discretion (but without any obligation), object to the disclosure of your Personal Data to such parties.

International Transfers
We operate and use service providers located in the United States. If you are located outside the U.S., your Personal Data may be transferred to the U.S. The U.S. does not provide the same legal protections guaranteed to Personal Data in the European Union. Accordingly, your Personal Data may be transferred to the U.S. pursuant to Standard Contractual Clauses or other adequacy mechanisms, with your consent, or pursuant to exemptions under EU law. Please contact us if you have questions regarding the method of transfer for information from the EU.

Your Rights & Choices

Your Rights
Subject to the rights granted to other individuals, and our rights to limit or deny access or disclosure under applicable law, certain individuals have the following rights in Personal Data under the GDPR or other laws. Note, we may require that you provide additional Personal Data to exercise these rights, e.g. information necessary to prove your identity. You may exercise these rights by contacting us at the address below.

Note: While we may notify third parties of your request, we are able to fulfill rights requests regarding Personal Data we control or process, and we may not have access to or control over Personal Data controlled by third parties. Please contact the third party directly to exercise your rights in third party-controlled information.

  • Access: You may receive a list of your Personal Data we process to the extent required and permitted by law.
  • Rectification: You may correct any Personal Data that we hold about you to the extent required and permitted by law.
  • Erasure: To the extent required by law, you may request that we delete your Personal Data from our systems.
  • Data Export: To the extent required by applicable law, we will send you a copy of your Personal Data in a common portable format of our choice.
  • Regulator Contact: You have the right to contact or file a complaint with regulators or supervisory authorities about our processing of Personal Data. To do so, please contact the Federal Trade Commission or your local data protection or consumer protection authority.
  • Direct Marketing: Residents of California (and others as required by applicable law) may request a list of Personal Data we have disclosed about you to third parties for direct marketing purposes during the preceding calendar year. This request must be written, signed, and mailed to us.

Your Choices
You have the following choices regarding the Personal Data we process, which you may exercise by contacting us:

  • Consent: If you consent to processing, you may withdraw consent any time, to the extent required by law.
  • Direct Marketing: You have the choice to opt-out of or withdraw consent to processing related to marketing communications. You may exercise your choice via the links in our communications or by contacting us re: direct marketing.
  • Personalization: You may object to processing for personalization purposes, to the extent applicable law gives you the right to do so. Note that we may not be required to cease certain types of processing based solely on an objection (for example, where we are required to comply with applicable legal requirements).
  • Cookies & Similar Tech: If you do not want information collected through the use of cookies, you can manage/deny cookies (and certain technologies) using your browser’s settings menu. You must opt out of third party services directly via the third party. For example, to opt-out of Google’s analytic and marketing services, visit Google Analytics Terms of Use, the Google Privacy Policy, or Google Analytics Opt-out. To learn more about how to opt out of Google’s use of cookies for advertising or retargeting, visit Google’s Ads Settings, here. Our Site does not respond to your browser’s do-not-track request.
  • Other Processing: You may have the right under applicable law to object to our processing of your Personal Data for certain purposes. You may do so by contacting us re: data rights requests. Note that we may not be required to cease processing based solely on an objection.

Security
We follow and implement reasonable security measures to safeguard the Personal Data you provide us. However, we sometimes share Personal Data with third parties as noted above, and we do not have control over third parties’ security processes. Please note, we do not warrant perfect security and we do not provide any guarantee that your Personal Data or any other information you provide us will remain secure.

Data Retention
We retain information for so long as it, in our discretion, remains relevant to its purpose, and in any event, for so long as is required by law. We will review retention periods periodically, and may sometimes pseudonymize or anonymize data held for longer periods, if appropriate.

Minors
Our Sites are neither directed at nor intended for use by minors under the age of majority in the relevant jurisdiction. Further, we do not knowingly collect Personal Data from such individuals. If we learn that we have inadvertently done so, we will promptly delete it.

Changes to Our Privacy Policy
We may change this Privacy Policy from time to time. Please visit this page regularly so that you are aware of our latest updates. Your use of the Site following notice of any changes indicates acceptance of any changes.

Contact Us
Feel free to contact us with questions or concerns using the appropriate address below.
General inquires: [email protected]
Physical address: 1966 13th St.
Suite 250
Boulder, CO 80302
Phone: 303-449-4893