Effective date May 18th, 2018
Who we are
At Woodturning Tool Store (https://woodturningtoolstore.com) we care about your privacy and believe in transparency. That’s why we are committed to being upfront about our privacy practices. We only collect personal information necessary to deliver our services and we handle it carefully and sensibly.
This Policy explains our privacy practices for Woodturningtoolstore.com (we’ll refer to it as the “Site”) and our other services. This Privacy Policy describes why and how we collect and use the personal information of our customers and website visitors. It also describes your options to choose how we use your personal data and how to contact us with any concerns and requests to in relation to that. Toshra Holdings, LLC (dba Woodturning Tool Store) is a company registered and existing under the laws of Texas, USA, with registered address: 728 Pulitzer Lane, Allen, TX, USA, and is the data controller of the personal data that we collect from you.
What personal data we collect and why we collect it
Contact Form
We receive and store any information you enter on our Site. Our Site uses forms to collect your personal information including your name, address, telephone number, email address so you can request information, get support and ask questions.
We use this information to contact you regarding the progress of your orders, status of the delivery, responding to information requests and answering customer questions about the site or products and services we sell.
Where you have opted in to receive our email newsletter, we add your name and email address to our email list so that you receive the relevant and informative newsletter we publish periodically.
Payments and billing information
When purchasing products and services, we request additional personal and payment information such as your name, credit card information, PayPal or relevant service, billing address, customized order notes and your opt-in request for our email newsletter.
Obviously we need this payment and billing information and your contact details to process your orders and/or to invoice you and to fulfill our legal obligations for tax calculations.
Where you have opted in to receive our email newsletter, we add your name and email address to our email list so that you receive the relevant and informative newsletter we publish periodically.
My Account
If you use the My Account page on our Site to register then we collect your email address. Your password is not collected but we have the ability to generate a new password which is seen only by you via your email address. The My Account page allows you to manage some of your personal information such as your name, email address and password, your shipping and billing addresses. You can also review your orders and order status and review the value of any gift cards you may have received.
This information is stored on the Site so that the user can enhance and manage the customer experience.
Surveys and contests
We may, from time to time, offer surveys and opinion polls and ask you to provide information about your experience and feedback for our services. Occasionally we may organize contests, sweepstakes, competitions, prize draws, or other promotions (collectively “Contests”) on our Site or through our Social Media channels and may offer a prize as a sign of appreciation to the people who have participated, qualified and/or completed our Contest. Information requested for entry may include personal contact information such as your name, email, address, phone number, etc. Participation is entirely voluntary and it’s up to you whether you choose to disclose any information or not.
If you enter a Contest, we use the data you provide for the successful administration of the Contest, to contact you or work with third parties to contact you in case you’ve won anything and fulfill prizes in accordance to the announcement and terms of the participation for the respective Contest. We may also, where you have opted in to receive such communication, and unless prohibited by law, use your information provided via our surveys and Contests to send you details about our products, services or offers.
Comments
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
If you download our archived newsletters that we offer free as a service, we collect IP address and user agent information and if you are a registered user and logged in we collect your user name and email address.
We collect this information as part of the software we use to maintain the free download service and it is used to diagnose problems with our servers, to administer our Site and services. This is not linked to any personally identifiable information, except if necessary to prevent fraud or abuse on our Site and systems.
Information we receive from your use of our site or third-parties
Automated information – when you visit our website we receive and collect information, which may – in certain circumstances constitute personal information – and which includes your IP address, referral URL, exit URL, browser software, operating system, date/time and/or clickstream data.
Website Analytics tools – We use analytics services by third parties to collect information about the use of this Site, such as number of visits, pages visited, popularity of certain content. Analytics tools use tracking technologies (like cookies) to recognize your device and compile information about you. They collect information such as what pages you visit and how much time you spend on these pages, the IP address assigned to you, what operating system and web browser you use, and what site you visited prior to visiting our website.
Information Logs – when you visit the Site, view content provided by us, ask us a question, request technical assistance in regards to our products and services, send us an email or participate in a contest or survey on our website, we automatically collect and store certain information in log files. This includes your IP address, URL, referral URL, exit URL, browser software, operating system, date/time, requests type to our Site and error responses returned by our Site or Services.
Cookies
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you have an account and you log in to this site, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracing your interaction with the embedded content if you have an account and are logged in to that website.
Purposes of data processing
When you access or use our Site, we need to collect, use, and otherwise process your information, as set out in this Policy. We are committed to your privacy and follow a few fundamental principles when we process personal data:
- We strive to collect only the minimum personal data that we need to deliver any products or services to you.
- We aim for full transparency on how we use your information to comply with legal or other lawful purposes and respect your privacy.
- We make sure we only use your information for the purposes you have given us permission for.
We rely on a number of legal bases to use your information, as set out in this Policy:
- Contract – the use of your information is necessary to perform any contractual obligations in order to provide any products and services to you or to administer any Contests you enter into.
- Legal obligations – our use of your personal information is necessary to comply with a legal obligation, a court order, or to exercise or defend legal claims. For example, if we are requested to disclose your personal information to regulatory bodies or law enforcement authorities; or to use your personal information for tax calculations.
- Our legitimate interests – necessary for the purposes of our legitimate interests, such as to:
- run, grow, develop and deliver our products and services;
- detect and prevent fraudulent activities;
- enhance the security of our Site;
- better understand how people interact with our website;
- determine the effectiveness of our promotional campaigns and advertising; and
- enhance, modify, personalize or otherwise improve our services and communications for the benefit of our customers.
Consent – we rely on your consent for us to use your personal information to send you marketing information (such as our newsletters and promotional offers) by email or telephone. You may withdraw your consent at any time by updating your personal Info/Settings in your user profile in our My Account, using our Unsubscribe option in relation to email subscriptions, or contacting us using the details set out in the “Further questions and contacts” section of this Policy.
How and Who we share your data with
All personal information collected by Woodturning Tool Store is treated as confidential. We disclose entire or part of your data in the limited circumstances described below and with appropriate safeguards on your privacy:
- If we are required by law – we will disclose information about you in response to a subpoena, court order, or other legitimate governmental request.
- We will disclose information about you to our business partners, external consultants, auditors, collaborators or other third parties, some of our employees, and individuals who are our independent contractors that need to know the information in order to help us provide our services or to process the information on our behalf and also for administrative purposes, billing and tax and all other purposes related to the management of your account. We require all of them to comply strictly with this Privacy Policy.
- Third Party Vendors – we will share information with third party vendors based within the United States and European Union who need to know information about you in order to provide various services on our behalf. This group includes vendors that help us provide our services such as payment providers that process your credit card information or information about alternative payment methods and invoicing, and shipping and logistics companies, our accounting provider as well as vendors that help us prevent fraud. This group also includes trusted vendors we partner with that perform analysis of our products or customer demographics and do market research that help us understand and enhance our services and help us serve better advertisements. This group also includes third party providers that perform analytic services and analyse the data of our surveys and/or contests. We will only share information about you that is necessary for the third party vendor to provide the requested service. These companies will process the provided data under instructions of Woodturning Tool Store and in compliance with this Privacy Policy. We do not authorize vendors to retain, share, store or use your personally identifiable information for any secondary purposes. The third party vendors include companies that operate in different industries such as Fraud Detection, Technology Service, Internet Information Providers, Payments and Data Processors, Logistics, Media, Internet Content & Information Industries, Advertising & Marketing and Technologies, that are located in the territory of the European Union and United States.
- To Protect Rights and Property – We will share account and personal information with companies, organizations or individuals when we believe in good-faith that access, use, preservation or disclosure of the information is necessary to meet any applicable law, comply with regulation, legal process or enforceable request; to enforce or apply our Terms of Service and other agreements; to investigate potential violations; to protect against harm to the rights, property or safety of Woodturning Tool Store, our users or the public as required or permitted by law. To the extent we are legally permitted to do so, we will take all reasonable steps to notify you in the event that we are required to provide your personal information to third parties as part of legal process.
- Business Transfers – in connection with any merger, sale of company assets, or acquisition of all or a portion of our business by another company, or in the unlikely event that Woodturning Tool Store goes out of business or enters bankruptcy, user information would likely be one of the assets that is transferred or acquired by a third party. If any of these events happens, we will take any reasonable steps to notify you and this Privacy Policy would continue to apply to your information and the party receiving your information shall continue to use your information, but only consistent with this Privacy Policy.
- With Your Consent – with your explicit consent or at your direction we may share and disclose information you have authorized us to with other third parties. We will not, however, sell, rent, share or otherwise disclose personally identifiable information for commercial purposes in any way that is contrary to the commitments made in this Privacy Policy. We will take all reasonable steps to notify you when and what information might go to third parties and you will be able to choose whether to share it or not.
Security measures
We use Secure Sockets Layer (SSL) software to encrypt the information you enter on our Site in order to protect its security during transmission to and from our Site. When storing information, we protect its security by encryption and pseudonymization of critical data. When we process credit card information and payments, the credit card is subject to tokenization and strong security measures.
We maintain physical, electronic and procedural safeguards in connection with the collection, storage and disclosure of personally identifiable customer information. Our security procedures require us in some cases to request proof of identity before disclosing personal information to you.
Although we take all these measures to maintain the safety and security of your personal information, please note that no transmission over the Internet can ever be guaranteed to be secure. Consequently, please note that we cannot fully guarantee the security of any personal information that you transfer over the Internet to us.
How long we retain your data
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
By visiting the My Account page on our website, you can access, correct, change, and delete certain personal information associated with your account. If you need further assistance, you can contact us using the details at the end of this policy statement or using the Contact Us form on the website. Please contact us to request any of the following:
- confirm whether or not personal data about you is being processed;
- provide you with further details about how we process your personal data;
- provide you with a copy of any data which we hold about you;
- withdraw your consent to using your personal information, where we rely on your consent as a legal basis to justify using your personal data;
- consider any valid objection to the processing of your personal information (including the right to object to processing on grounds related to your particular situation where we are relying on our legitimate interests as a legal basis for processing);
- request to update or delete personal data which we hold about you;
- restrict the way that we process your personal data;
- consider any valid request to transfer your personal data to a third party provider of services (data portability); and
- we will consider all those requests. However, certain personal information may be exempt from those requests in certain circumstances, which include a need to keep processing information for our legitimate interests or to comply with a legal obligation. If such an exception applies, we will notify you when responding to your request. Please note that we may ask you to provide us with information necessary to confirm your identity before responding.
Additional information
California Online Privacy Protection Act
CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law’s reach stretches well beyond California to require any person or company in the United States (and conceivably the world) that operates websites collecting Personally Identifiable Information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals or companies with whom it is being shared. – See more at: http://consumercal.org/california-online-privacy-protection-act-caloppa/#sthash.0FdRbT51.dpuf
According to CalOPPA, we agree to the following:
Users can visit our site anonymously. Once this privacy policy is created, we will add a link to it on our home page or as a minimum, on the first significant page after entering our website. Our Privacy Policy link includes the word ‘Privacy’ and can easily be found on the page specified above.
You will be notified of any Privacy Policy changes on our Privacy Policy Page
Users can change your personal information:
- By emailing us
- By calling us
- By logging in to your account
We honor Do Not Track signals and Do Not Track, plant cookies, or use advertising when a Do Not Track (DNT) browser mechanism is in place.
It’s also important to note that we allow third-party behavioral tracking via Google Analytics
COPPA (Children Online Privacy Protection Act)
When it comes to the collection of personal information from children under the age of 13 years old, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, United States’ consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online. We do not specifically market to children under the age of 13 years old.
Fair Information Practices – In order to be in line with Fair Information Practices we will take the following responsive action, should a data breach occur, we will notify you via email within 7 business days.
We also agree to the Individual Redress Principle which requires that individuals have the right to legally pursue enforceable rights against data collectors and processors who fail to adhere to the law. This principle requires not only that individuals have enforceable rights against data users, but also that individuals have recourse to courts or government agencies to investigate and/or prosecute non-compliance by data processors.
CAN SPAM Act
The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.
We collect your email address in order to:
- Send information, respond to inquiries, and/or other requests or questions
- Process orders and to send information and updates pertaining to orders.
- Send you additional information related to your product and/or service
- Market to our mailing list or continue to send emails to our clients after the original transaction has occurred.
To be in accordance with CANSPAM, we agree to the following:
- Not use false or misleading subjects or email addresses.
- Identify the message as an advertisement in some reasonable way.
- Include the physical address of our business or site headquarters.
- Monitor third-party email marketing services for compliance, if one is used.
- Honor opt-out/unsubscribe requests quickly.
- Allow users to unsubscribe by using the link at the bottom of each email.
If at any time you would like to unsubscribe from receiving future emails, follow the instructions at the bottom of each email.
Changes to the Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we decide to change our Privacy Policy, we will post the updates to this Privacy Policy here and on any other place we deem appropriate, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it.
If we make material changes to this Policy, we will notify you here, by email, or by means of a notice on our Site.
Contact information
If you have any questions regarding this Privacy Policy, if you wish to exercise any of your rights in relation to your personal information, or if you want to object to the collection or processing of your data by Woodturning Tool Store, whether entirely or partially, please contact us at tod@woodturningtoolstore.com