This policy is incorporated by reference into the Railflow Terms of Service (the “Agreement”). Terms used in this policy shall have the same definitions as in the Agreement except where otherwise noted. This policy governs the manner in which Railflow (“Railflow”, “We” and “Us”), collects, uses, maintains and discloses information collected from users (each, a “User”) of our Websites.
Personal identification information
We may collect personal identification information from Users, when Users visit our site, register on the site, place an order, subscribe to the newsletter, respond to a survey, fill out a form, and in connection with other activities, services, features or resources we make available on our Site. Users may be asked for, as appropriate, name, email address, mailing address, phone number. Users may, however, visit our Site anonymously. We will collect personal identification information from Users only if they voluntarily submit such information to us. Users can always refuse to supply personally identification information, except that it may prevent them from engaging in certain Site related activities.
Non-personal identification information
We may collect non-personal identification information about Users whenever they interact with our Site. Non-personal identification information may include the browser name, the type of computer and technical information about Users means of connection to our Site, see “Information we automatically collect when you use our Services”.
Web browser cookies
How we use collected information
Railflow may collect and use Users personal information for the following purposes:
- To improve customer service and community support. Information you provide helps us respond to your customer service requests and community support needs more efficiently.
- To personalize user experience. We may use information in the aggregate to understand how our Users as a group use the services and resources provided on our Site.
- To improve our Site. We may use feedback you provide to improve our products and services.
- To run a promotion, contest, survey or other Site feature.
- To understand how the downloaded software is used and if it encounters any issues during use.
- To send Users information they agreed to receive about topics we think will be of interest to them.
- To send periodic emails. We may use the email address to send User information and updates pertaining to their order. It may also be used to respond to their inquiries, questions, and/or other requests. If User decides to opt-in to our mailing list, they will receive emails that may include company news, updates, related product or service information, etc. If at any time the User would like to unsubscribe from receiving future emails, we include detailed unsubscribe instructions at the bottom of each email or User may contact us via our Site.
How we protect your information
We adopt appropriate data collection, storage and processing practices and security measures to protect against unauthorized access, alteration, disclosure or destruction of your personal information, transaction information and data stored on our Site. Sensitive and private data exchange between the Site and its Users happens over a SSL secured communication channel and is encrypted and protected with digital signatures.
Sharing your personal information
We do not sell, trade, or rent Users personal identification information to others. We may use third-party service providers to help us operate our business and the Site or administer activities on our behalf, such as sending out newsletters or surveys. We may share your information with these third parties for those limited purposes provided that you have given us your permission.
EU Residents Rights Under GDPR
What Personal Data Do We Collect From You?
We collect Personal Data about you when you provide such information directly to us, when third parties such as our business partners or service providers provide us with Personal Data about you, or when Personal Data about you is automatically collected in connection with your use of our Services.
Information we collect directly from you:
We receive Personal Data directly from you when you provide us with such Personal Data, including without limitation the following:
First and last name Email address Mailing address Telephone number Credit/debit card information
Information we automatically collect when you use our Services:
Some Personal Data is automatically collected when you use our software or visit our website such as the following:
- IP address
- Device identifiers
- Web browser information
- Page view statistics
- Browsing history
- Usage information
- Transaction information (e.g. transaction amount, date and time such transaction occurred)
- Cookies and other tracking technologies (e.g. web beacons, pixel tags, SDKs, etc.)
- Location information (e.g. IP address, zip code)
- Log data (e.g. access times, hardware and software information)
Third Party Analytic Tools:
How Do We Use Your Personal Data?
We process Personal Data to operate, improve, understand and personalize our Services. We use Personal Data to:
- Create and manage user profiles
- Communicate with you about the Services
- Contact you about Service announcements, updates or offers
- Provide support and assistance for the Services
- Personalize website content and communications based on your preferences
- Meet contract or legal obligations
- Respond to user inquiries
- Fulfill user requests
- Comply with our legal or contractual obligations
- Resolve disputes
- Protect against or deter fraudulent, illegal or harmful actions
- Enforce our Terms of Service
We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.
Contractual Necessity: We process the following categories of Personal Data as a matter of “contractual necessity”, meaning that we need to process the data to perform under our Terms of Service with you, which enables us to provide you with the Services. When we process data due to contractual necessity, failure to provide such Personal Data will result in your inability to use some or all portions of the Services that require such data.
Legitimate Interest: We process the following categories of Personal Data when we believe it furthers the legitimate interest of us or third parties. Operation and improvement of our business, products and services Marketing of our products and services Provision of customer support Protection from fraud or security threats Compliance with legal obligations Completion of corporate transactions
Consent: In some cases, we process Personal Data based on the consent you expressly grant to us at the time we collect such data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection.
Other Processing Grounds: From time to time we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.
How and With Whom Do We Share Your Data?
- Payment processors
- Analytics service providers
- Hosting service providers
We also share Personal Data when necessary to complete a transaction initiated or authorized by you or provide you with a product or service you have requested. In addition to those set forth above, these parties also include:
- Other users (where you post information publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services)
- Social media services (if you interact with them through your use of the Services)
- Third party business partners who you access through the Services
- Other parties authorized by you
We also share Personal Data when we believe it is necessary to:
- Comply with applicable law or respond to valid legal process, including from law enforcement or other government agencies
- Protect us, our business or our users, for example to enforce our terms of service, prevent spam or other unwanted communications and investigate or protect against fraud
- Maintain the security of our products and services
We also share information with third parties when you give us consent to do so. Furthermore, if we choose to buy or sell assets, user information is typically one of the transferred business assets. Moreover, if we, or substantially all of our assets, were acquired, or if we go out of business or enter bankruptcy, user information would be one of the assets that is transferred or acquired by a third party, and we would share Personal Data with the party that is acquiring our assets. You acknowledge that such transfers may occur, and that any acquirer of us or our assets may continue to use your Personal Information as set forth in this policy.
How Long Do We Retain Your Personal Data?
We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide you Services. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. Afterwards, we retain some information in a depersonalized or aggregated form but not in a way that would identify you personally.
What Security Measures Do We Use?
We seek to protect Personal Data using appropriate technical and organizational measures based on the type of Personal Data and applicable processing activity. For example, we protect the security of your information during transmission by using Secure Sockets Layer (SSL) software, which encrypts information you input.
For EU Individuals
Your Rights under the General Data Protection Regulation You have certain rights with respect to your Personal Data, including those set forth below. For more information about these rights, or to submit a request, please email firstname.lastname@example.org. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need to you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request.
- Access: You can request more information about the Personal Data we hold about you and request a copy of such Personal Data. You can also access certain of your Personal Data by sending an email request to email@example.com.
- Rectification: If you believe that any Personal Data we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data. You can correct some of this information directly by sending an email request to firstname.lastname@example.org.
- Erasure: You can request that we erase some or all of your Personal Data from our systems.
- Withdrawal of Consent: If we are processing your Personal Data based on your consent (as indicated at the time of collection of such data), you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Data, if such use or disclosure is necessary to enable you to utilize some or all of our Services.
- Portability: You can ask for a copy of your Personal Data in a machine-readable format. You can also request that we transmit the data to another controller where technically feasible.
- Objection: You can contact us to let us know that you object to the further use or disclosure of your Personal Data for certain purposes, such as for direct marketing purposes.
- Restriction of Processing: You can ask us to restrict further processing of your Personal Data.
- Right to File Complaint: You have the right to lodge a complaint about Company’s practices with respect to your Personal Data with the supervisory authority of your country or EU Member State.
You may also have the right to make a GDPR complaint to the relevant Supervisory Authority. A list of Supervisory Authorities is available here: https://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612080. If you need further assistance regarding your rights, please contact us using the contact information provided below and we will consider your request in accordance with applicable law. In some cases our ability to uphold these rights for you may depend upon our obligations to process personal information for security, safety, fraud prevention reasons, compliance with regulatory or legal requirements, or because processing is necessary to deliver the services you have requested. Where this is the case, we will inform you of specific details in response to your request.
What If You Have Questions Regarding Your Personal Data?
If you have any questions about this section or our data practices generally, please contact us via email at email@example.com
Your acceptance of these terms
By using this Site and/or our Product, you signify your acceptance of this policy. If you do not agree to this policy, please do not use our Site and/or our Product. Your continued use of the Site and/or our Product following the posting of changes to this policy will be deemed your acceptance of those changes.