Effective Date: [2025-5-1]
At Vivue.com, we take your privacy seriously and are dedicated to safeguarding your personal information while providing you with a seamless online experience. This Privacy Policy outlines in detail how we collect, use, store, share, and protect your data when you interact with our website or services. By using our platform, you agree to the practices described herein. Please read this policy carefully to understand our commitment to transparency and your rights.
Personal data is any information that relates to an identified or identifiable individual. This includes direct identifiers like your name, email address, or phone number, as well as indirect identifiers such as IP addresses or behavioral data that, when combined, could identify you. We also handle non-personal data, such as anonymized statistics, which cannot be linked back to an individual and is thus outside the scope of this policy.
We gather various types of data to operate our services effectively, enhance your experience, and comply with legal requirements. Below is a detailed breakdown:
· Account Creation: When you sign up, we collect your full name, email address, username, password, and optionally your phone number for account verification or two-factor authentication.
· Transaction Data: For purchases, we collect payment details (e.g., credit card number, expiration date, CVV code), billing address, shipping address, and order preferences.
· Preferences and Subscriptions: You may opt into newsletters, promotional offers, or loyalty programs, providing us with your communication preferences.
· User-Generated Content: If you post reviews, comments, or upload images (e.g., for product feedback), we collect that content along with associated metadata (e.g., timestamps).
· Support Interactions: When you reach out via email, chat, or phone, we record your contact details, inquiry content, and any attachments you provide.
· Technical Data: We log your device type (e.g., iPhone, PC), operating system (e.g., iOS 17, Windows 11), browser type (e.g., Chrome, Safari), screen resolution, and language settings.
· Behavioral Data: We track your interactions, such as pages visited, time spent per page, links clicked, search queries entered, and items added to your cart.
· Geo-location: Your IP address provides an approximate location (e.g., city or region), and with your permission, we may access precise GPS coordinates for location-based features.
· Cookies and Similar Technologies: These tools track session activity, store login states, and analyze trends (see Section 4 for an in-depth explanation).
· Social Media Integration: Logging in via platforms like Facebook, Twitter, or Google allows us to access your public profile data (e.g., username, profile picture) and email address, depending on your settings.
· Partners and Vendors: We may receive supplemental data from advertising networks, marketing partners, or data brokers, such as demographic insights or inferred interests.
· Public Sources: In rare cases, we might use publicly available information (e.g., business directories) to verify account details or enhance our records.
We process your data for a variety of purposes, always striving to balance our operational needs with your privacy rights. Here’s how:
· Core Functionality: To fulfill orders, manage accounts, process payments, and deliver services like personalized recommendations or customer support.
· Communication: To send order confirmations, account updates, security alerts, and, if you’ve opted in, marketing emails or SMS messages about new products or discounts.
· Experience Optimization: To customize content (e.g., suggesting items based on past purchases) and serve targeted ads on our site or third-party platforms like Google Ads.
· Research and Development: To study user trends, test new features (e.g., A/B testing a checkout process), and improve site performance using aggregated data.
· Security: To authenticate users, detect bots, prevent fraud (e.g., flagging unusual login attempts), and investigate policy violations.
· Compliance and Reporting: To adhere to tax laws, anti-money laundering regulations, and other legal mandates, such as maintaining records for audits.
We rely on legal bases like your consent, our legitimate business interests, or contractual necessity to process your data, ensuring compliance with applicable laws.
Cookies, web beacons, and other tools are integral to our site’s functionality and analytic. Here’s a deeper look:
· Types of Cookies:
o Essential Cookies: Enable core features like logging in or completing purchases.
o Performance Cookies: Measure page load times, error rates, and traffic sources.
o Functional Cookies: Save your settings (e.g., language choice) across visits.
o Targeting Cookies: Track browsing habits to deliver relevant ads.
· Other Tools: Web beacons in emails track open rates, while pixel tags on pages report ad impressions.
· Control Options: You can accept, reject, or customize cookie use via our consent banner or browser settings, though blocking essential cookies may disrupt site access.
We share data only when necessary and with strict safeguards in place:
· Service Providers: We partner with companies for hosting (e.g., AWS), payment processing (e.g., Stripe, PayPal), email delivery (e.g., Mailchimp), and logistics (e.g., FedEx). These entities are bound by confidentiality agreements.
· Business Affiliates: Data may be shared within our corporate family for internal analytics or support, always under unified privacy standards.
· Regulatory Bodies: We disclose data if compelled by subpoenas, court orders, or to cooperate with investigations (e.g., fraud probes).
· Corporate Transactions: During mergers, acquisitions, or asset sales, your data may transfer to new owners, with assurances of continued protection.
· With Your Consent: We may share data for specific purposes (e.g., joint promotions with a partner brand) if you agree.
We never sell your data to third parties for their independent use.
As a global service, your data may cross borders. For instance:
· Transfer Scenarios: Data from an EU user might be stored on U.S. servers or processed by a support team in Asia.
· Legal Safeguards: We comply with frameworks like GDPR and CCPA, using mechanisms such as:
o Standard Contractual Clauses (SCCs): Contracts ensuring recipients meet EU privacy standards.
o Adequacy Decisions: Transfers to countries (e.g., Canada, Japan) recognized as privacy-safe by the EU.
o Binding Corporate Rules: Internal policies for intra-company transfers.
· User Notification: We’ll inform you if your data moves to a jurisdiction with weaker protections, offering opt-out options where feasible.
You have robust control over your data, including:
· Access: View all data we’ve collected about you, such as account details or purchase history.
· Rectification: Fix errors, like an outdated address or misspelled name.
· Erasure: Request deletion of your data, barring legal exceptions (e.g., tax records).
· Restriction: Pause processing for specific uses while we address your concerns.
· Objection: Opt out of marketing or profiling activities.
· Data Portability: Export your data (e.g., order list in CSV format) or send it to another provider.
· Withdraw Consent: Revoke permissions (e.g., for cookies) at any time, effective moving forward.
To exercise these rights, email [Your Contact Email] with your request. We’ll verify your identity (e.g., via account login) and respond within 30 days, extending to 90 days for complex cases.
Our site may link to external platforms (e.g., Instagram, YouTube) or embed tools like payment gateways. These third parties operate under their own privacy policies, which we don’t control. For example, clicking a PayPal link subjects you to PayPal’s terms. Always review their policies before engaging.
We deploy extensive protections, including:
· Encryption: AES-256 for stored data, TLS 1.3 for data in transit.
· Access Management: Role-based access, multi-factor authentication for staff, and audit logs.
· Monitoring: Real-time threat detection, quarterly penetration testing, and annual SOC 2 compliance reviews.
· Employee Training: Regular sessions on phishing prevention, data handling, and privacy laws.
· Physical Security: Data centers with biometric locks, 24/7 surveillance, and disaster recovery plans.
Despite these efforts, no system is infallible. Report suspected breaches to [Your Contact Email] immediately.
Our services are not intended for users under 16 (or 13 in the U.S. per COPPA). We don’t knowingly collect data from minors. If a parent or guardian believes we’ve inadvertently collected such data, contact us at [Your Contact Email] for swift removal.
We obtain your consent where required:
· Explicit Consent: Via check boxes for marketing emails or precise Geo-location.
· Implied Consent: Assumed for essential functions (e.g., saving cart items) when you use our site.
· Management: Update preferences in your account dashboard or withdraw consent by contacting us.
We keep data only as long as needed:
· Active Use: Account data persists while you’re a user, plus 6 months post-closure for reactivation.
· Legal Needs: Transaction records stay for 7 years per tax laws.
· Analytic: Behavioral data is anonymized after 24 months.
· Deletion: Expired data is securely shredded using NIST 800-88 standards.
If a data breach occurs, we’ll:
· Investigate promptly, containing the issue within 72 hours if possible.
· Notify affected users via email and site banners if there’s a significant risk.
· Report to regulators (e.g., ICO under GDPR) as required.
We’ll revise this policy as needed, notifying you of material changes via email or a homepage alert at least 14 days before they take effect. Check back regularly for the latest version.
Reach us at service@vivue.com or via our online form for any privacy-related matters. Our Data Protection Officer is available for escalated concerns.