Privacy Policy

Updated January 6,2022

Overview

This Privacy Policy outlines how we collect, store and use data collected from our website (www.checkbox.com) and from our Checkbox hosted account services (customer account websites which may follow the format of yourcompany.checkboxonline.com, yourcompany.checkbox.ca, yourcompany.ckbx.eu, or a custom sub-domain of the customer’s choosing).

This Privacy Policy demonstrates our firm commitment to your privacy and the protection of your personal information. Information obtained from website visitors and customers of our products and services will only be used for the purposes outlined in this policy. Except as specified in this Privacy Policy, at no time will we sell, rent, or otherwise provide your personal information or survey data to a non-agent third party.

Use of our website or services constitutes your agreement with this Privacy Policy, so please read it carefully. If you do not agree to this Privacy Policy, please discontinue use of our website and services immediately. This Privacy Policy may also be updated from time to time, as noted in our company news and customer announcements. Continued use of our website and services following the announcement of these updates constitutes your agreement with the changes.

How Data is Collected & UsedData from Order & Contact Forms

When you purchase our products or services online, we collect your contact and payment information (such as name, postal address, email address, and credit card number). We use the information collected from our order forms to create and update your account, verify your identity, authorize payments, and to send you a confirmation of your payment. We will share your credit card information via a secure Internet connection with our third party credit card processing vendor for the sole purpose of processing your order or refund.

When you fill out a form on our website, we store the information you provide to us, such as your name, email address, phone number, and contact message. Following the collection of your data using a website form, we may also use marketing or analytics tools to subsequently track certain purchasing and browsing activities, such as website pages visited, time spent on pages, and marketing emails opened or clicked.

Data collected from our website forms and our marketing tools may be used to periodically send marketing notices, product updates, or company news notices to that email address. You may opt-out of receiving these emails at any time by following the Unsubscribe link located in the footer of these emails or by contacting us as specified in the Contact Information clause of this Privacy Policy. We will process your request as soon as possible. We may also use this data in aggregate to improve our overall website performance and product/service offerings.

At no time will we sell or otherwise transfer any of your data to any non-agent third party.

Data from Surveys and Other Checkbox Hosted Account Use

Data that is collected in your Checkbox Hosted account through the use of surveys or when you import data into your account is used by us for the sole purpose of maintaining and supporting your account. We will not contact individuals using the data in your Checkbox Hosted account, except as required by law, or use or transfer any of the data stored about those individuals except as outlined in this Privacy Policy. Individuals whose data has been collected using a Checkbox Survey or imported into Checkbox should contact the administrator of that Checkbox account regarding requests to access, change or delete that data.

At no time will we sell or otherwise transfer any data from your Checkbox account to any non-agent third party.

Data from Log Files

As is true of most websites, we gather certain information from our website and Checkbox hosted account sites automatically and store it in log files. This information includes internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time stamp and clickstream data.

We use this information, which does not identify individual users, to analyze trends, to monitor system performance, to administer the site, to track users’ movements around the site and to gather demographic information about our user base as a whole.

We do not link this automatically-collected data to personally identifiable information.

Cookies

A cookie is a small text file that is stored on a user’s computer for record-keeping purposes. We use cookies on our website and on our Checkbox hosted account sites. We do not link the information we store in cookies to any personally identifiable information you submit while on our site.

We use persistent cookies. A persistent cookie remains on your hard drive for an extended period of time. You can remove persistent cookies by following directions provided in your Internet browser’s “help” file.

We set cookies when you visit the Checkbox website, use our Checkbox hosted application, and take a Checkbox survey. Cookies are used to:

- Identify whether a user is logged in, for security purposes, and to allow the use of software features
- Allow us to see how visitors use our site (these may be third party cookies like Google Analytics or Google Ads, as more fully described below)
- Identify a unique survey response when you are a respondent taking a survey

If you reject cookies, you may still use our site, but your ability to use some areas of our site, such as online surveys, will be limited.

Third-Party Analytics and Advertising Services

We may use website analytics tools and services, such as Google Analytics, to help us analyze our site and how it is used. Information about how Google Analytics handles personal information is available here, and you can learn how to opt out of Google Analytics here.

We may also use third-party tools to help us deliver advertising. As noted above, these third parties may use cookies or similar technologies to track a user’s online activities. Targeted advertising may take place on our site or on websites not affiliated with us, if those websites participate in the same advertising networks. We currently use Google Ads (also known as Google AdWords) and Microsoft Advertising (also known as Bing Ads).

You can take steps to limit or block targeted advertising. You can learn how to control or block advertisements enabled by Google Ads here. If you have a Google account, you can also learn how to control targeted advertising enabled by Google here. If you have a Microsoft account, you can learn how to control targeted advertising enabled by Microsoft here. In addition, both Google and Microsoft participate in the “AdChoices” program of the Digital Advertising Alliance and have committed to comply with the NAI Code of Conduct of the Network Advertising Initiative. You can learn more about advertising networks and how to opt out of targeted advertising through the Digital Advertising Alliance here and through the Network Advertising Initiative here.

Please note that opt-out mechanisms described above typically rely on cookies to retain your opt-out preferences. So if you reject or erase all cookies, your opt-out choices may not function properly, or you may have to opt out again.

Other Uses of Data

Our privacy practices as described in this Privacy Policy are subject to our ongoing obligation to comply with applicable law or lawful requests by government authorities and with our right to protect ourselves and others when necessary. We may disclose any information necessary to investigate or take action with respect to suspected fraud or other illegal activities, to enforce the terms of agreements to which we are a party, or as otherwise required by law.

In connection with a potential acquisition or merger of our company with another company, we may share our data, which may include information about you, with that other company, but we will only do so under an appropriate confidentiality agreement.

Data Retention & DeletionData Retention

We retain data collected through our website or other marketing or analytics tools for as long as is required to provide services to our customers and users, as well as to fulfill our applicable legal obligations.

We retain data that is collected through our Checkbox hosted service as long as the account remains active and in good standing, unless that data is deleted by the account administrator or unless the account administrator requests that we delete the data, in accordance with applicable law. We permanently delete data from terminated accounts ninety (90) days following termination, unless earlier deletion is requested by the account administrator in writing.

Requesting/Updating/Deleting Your Information

We do not sell, share, distribute, or otherwise transfer any information that we collect from you, except as outlined in this Privacy Policy. If you have questions or concerns about how data is collected is stored, would like to request a copy of your information on file as a registered user, or would like to update or delete your information, please contact us as specified in the Contact Information clause of this Privacy Policy.

Individuals whose data has been collected using a Checkbox Survey or imported into Checkbox should contact the administrator of that Checkbox account regarding requests to access, change or delete that data.

Data Security

We follow generally accepted industry standards to protect the personal information submitted to us, both during transmission and once we receive it. When data collected from our website or Checkbox hosted account sites is transmitted, we encrypt that transmission using TLS. Additional security and encryption features may also be enabled on your Checkbox hosted account. No method of transmission over the internet, or method of electronic storage, is 100% secure, however. Therefore, while we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

If you have questions about the security of your data, you can contact us  as specified in the Contact Information clause of this Privacy Policy.

Sub-Processors

We use third-party vendors to host data from our website and Checkbox hosted accounts, send emails from our hosted service, send marketing and newsletter emails, store customer relationship data, process customer support tickets, and process credit card payments. Data is only transferred to these sub-processors as needed to perform the activities detailed in this Privacy Policy, to perform contracted services to our customers, or to comply with applicable laws.

If you have questions about how your data is transferred or used by sub-processors, you can contact us  as specified in the Contact Information clause of this Privacy Policy.

EU-US and Swiss-US Privacy Shield

We comply with the EU-US and Swiss-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries and Switzerland. We have certified that we adhere to the Privacy Shield principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement, and Liability. If there is any conflict between this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit https://www.privacyshield.gov/

In addition to self-assessment, as a participant in the EU-US and Swiss-US Privacy Shield program, we are subject to the investigatory and enforcement powers and authority of the U.S. Federal Trade Commission with respect to maintenance of, and adherence to, this Privacy Policy.

In compliance with the EU-US and Swiss-US Privacy Shield Principles, we commit to resolve complaints about your privacy and our collection or use of your personal information. European Union and Swiss individuals with inquiries or complaints regarding this Privacy Policy should first contact us as directed in the Contact Information clause of this Privacy Policy.

We have further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism, the BBB EU PRIVACY SHIELD, operated by BBB National Programs. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit https://bbbprograms.org/privacy-shield-complaints/ for more information and to file a complaint. This service is provided free of charge to you.

As a last resort and under certain limited and prescribed circumstances and conditions, you have the right to invoke a “last resort” binding arbitration process between you and us to resolve a dispute related to our collection, use or disclosure of your personal information.

In particular, we will maintain compliance with the Privacy Shield principles by adhering to the following practices:

Notice

When we collect your personal information, we’ll give you timely and appropriate notice describing what personal information we’re collecting, how we’ll use it, and the types of third parties with whom we may share it. This Privacy Policy serves as such notice, and any changes to our collection, use or disclosure of your personal information will be reflected in revisions to the Privacy Policy posted on our website.

Choice

As established and described in this Privacy Policy, we’ll give you choices about the ways we use and share your personal information, and we’ll respect the choices you make.  You may request the restriction of the processing of personal data in certain circumstances by emailing us at info@checkbox.com, namely where:

a. you contest the accuracy of the personal data which we process and we are verifying the query;

b. the data has been unlawfully processed;

c. we no longer need that personal data but you require us to keep it; or

d. you have objected to our processing the personal data but we are considering whether our legitimate grounds override those of the individual.If you request that we restrict processing of your personal data, we would make that data temporarily unavailable, not process it apart from to store it and would inform any additional sub-processors about the restriction/limitation.

Accountability for Onward Transfer

If we transfer your personal information to another country, we may remain liable and will take appropriate measures to protect your privacy and the personal information we transfer.

Security

We’ll take appropriate physical, technical, and organizational measures to protect your personal information from loss, misuse, unauthorized access or disclosure, alteration, and destruction, as further-specified in the Checkbox Online Survey & Data Security section of this Privacy Policy.

Data Integrity and Purpose Limitation

We’ll collect only as much personal information as we need for specific and identified purposes, and we won’t use it for other purposes without obtaining your consent. We’ll take appropriate steps to make sure the personal information in our records is accurate.

Access

You have the right to confirm the accuracy of your personal information or have it removed from our systems and records, you may contact us at the email address, telephone number or postal address provided in the Contact Information clause of this Privacy Policy.

Recourse, Enforcement, and Liability

We’ll regularly review our continued adherence to our privacy obligations, and we’ll provide and maintain the independent mechanism specified in this Privacy Policy as a way of resolving complaints or concerns about our privacy practices. Further, we acknowledge our potential liability for misuse of your personal information by us or our third-party service providers, as further set forth in this Privacy Policy.

GDPR

We are aware of and committed to meeting our obligations under the General Data Protection Regulation (GDPR), which is in effect as of May 25, 2018. Please review our statement on GDPR for specific information regarding our features and data policies as they related to GDPR.

HIPAA Compliance

We strive to maintain data security and confidentiality policies in compliance with HIPAA regulations for all of our Checkbox Online customers. However, certain HIPAA-required security measures are only available with our dedicated Team and Enterprise plans. If you are transmitting or storing personal health information (PHI), you must notify us and follow certain HIPAA compliance procedures, including signing a business associate agreement (BAA) with us and ensuring that certain features such as password lockout restrictions and data encryption are available on your account and enabled.

For more information on HIPAA compliance, please contact our sales team at sales@checkbox.com.

Other Data Protection LawsYour rights and our obligations relating to your personal information may be further defined under other applicable data protection laws. For example, if you are a resident of California, you may have specific rights relating to your personal information under the California Consumer Privacy Act (CCPA). These include the right to be informed about the categories of personal information we collect, the sources of that information, and how we use and share that information, all of which we have addressed in the applicable section of this Privacy Policy. You may also have the right to know the specific personal information we may have about you or to ask us to delete that information, and you may do so by contacting us as specified in the Contact Information clause of this Privacy Policy. We will respond and, where applicable, comply with your requests free of charge and within the timeframe required under applicable law.

As noted throughout this Privacy Policy, we do not sell personal information to third parties for their direct marketing or any other purposes. The elements of CCPA concerning the “sale” or “commercial use” of personal information, therefore, do not apply to us. Similarly, we do not track users over time across third-party, non-customer websites. Accordingly, we do not recognize or respond to browser-initiated “do not track” signals.Your rights under data protection laws depend on the nature of your relationship with us. If we have received information about you through a Checkbox Survey or otherwise from an organization that is our customer, for example, then we are in the role of a service provider or “sub-processor” to that customer, and we may only access and use our customer’s data (which may include personal information about you) in accordance with our customer’s instructions. If you are a Survey participant or other customer user and wish to make an inquiry or exercise your rights under applicable data protection laws, please contact the applicable Survey administrator or your organization.

Children’s Privacy
Only persons who are age 18 or older have permission to access our services or use our products. We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you learn that your minor children have provided us with such information, please contact us. If we become aware that we have collected personally identifiable information from a child under age 13 without verification of parental consent, we will take steps to remove that information from our service and records.

Contact Information
You may contact Checkbox concerning this Privacy Policy, our privacy practices, and any questions or concerns you may have at the following:

Mailing Address: Checkbox Technology, Inc. PO Box 470697, San Francisco, CA 94147 USA
Phone Number: 1-617-231-8890
Email Address: info@checkbox.com

You do not need to establish an account with us or be a registered user in order to send us a request, but if you already have an account with us or are a registered user, we may respond to your request through your account. We do not discriminate against our users based on their data-privacy choices