PRIVACY POLICY
1. INTRODUCTION AND SCOPE
1.1 Identity of the Operator. This Privacy Policy (this "Policy") is issued by Halos Development, LLC, a limited liability company organized under the laws of the State of Delaware, doing business as Solidans (the "Company," "we," "us," or "our"). Solidans is a trade name under which the Company offers fixed-price development, performance optimization, platform migration, application integration, and email marketing services to operators of online stores built on the Shopify platform and comparable e-commerce platforms. The Company is the operator of the websites located at solidans.com and getsolidans.com, together with their respective subdomains and any successor or replacement domains (collectively, the "Site").
1.2 Purpose of this Policy. This Policy describes the categories of personal information that the Company collects, the sources from which such information is obtained, the purposes for which such information is used, the categories of third parties to whom such information is disclosed, the period for which such information is retained, the means by which such information is protected, and the rights and choices available to the individuals to whom such information relates. This Policy is intended to satisfy the notice obligations imposed upon operators of commercial websites and online services by the California Online Privacy Protection Act, Cal. Bus. & Prof. Code § 22575 et seq., the Delaware Online Privacy and Protection Act, 6 Del. C. § 1201C et seq., Nevada Revised Statutes § 603A.300 through § 603A.360, and other applicable law.
1.3 Persons to Whom this Policy Applies. This Policy applies to the following categories of individuals (each, a "User," "you," or "your"):
- (a) "Visitors," meaning individuals who access or browse the Site without submitting a request for services;
- (b) "Prospective Clients," meaning individuals who request a complimentary store audit, request a quotation, or otherwise initiate contact with the Company concerning the Services;
- (c) "Clients," meaning merchants and other business entities that have engaged the Company to perform Services, and the owners, officers, employees, and other authorized representatives of such entities acting in that capacity ("Client Personnel"); and
- (d) "Business Contacts," meaning individuals whose business contact information the Company obtains from third-party data providers, publicly accessible sources, or referral partners for the purpose of business-to-business marketing communications, as further described in Sections 3.3 and 8.
1.4 Client Customer Data. In the course of performing the Services, the Company may be granted access to personal information relating to the customers, subscribers, and end users of a Client's online store ("Client Customer Data"). The Company processes Client Customer Data solely as a service provider acting on behalf of, and under the direction of, the applicable Client. The collection, use, and disclosure of Client Customer Data by the Client is governed by the Client's own privacy policy and not by this Policy. The Company's obligations with respect to Client Customer Data are set forth in Section 5 and in the written agreement between the Company and the Client (the "Client Agreement"). In the event of a conflict between Section 5 of this Policy and the Client Agreement with respect to Client Customer Data, the Client Agreement shall govern.
1.5 Acceptance. By accessing or using the Site, submitting information to the Company, or engaging the Company to perform Services, you acknowledge that you have read and understood this Policy. If you do not agree with the practices described in this Policy, you must not access or use the Site or submit personal information to the Company.
1.6 Relationship to Other Terms. This Policy is incorporated by reference into, and forms a part of, the Solidans Terms of Service and each Client Agreement. Capitalized terms used but not defined in this Policy have the meanings assigned to them in the Terms of Service.
2. DEFINITIONS
For purposes of this Policy, the following terms have the meanings set forth below. Terms defined elsewhere in this Policy have the meanings assigned to them where first defined.
2.1 "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. Personal Information does not include (a) information that has been deidentified or aggregated such that it cannot reasonably be used to infer information about, or otherwise be linked to, a particular individual or household, or (b) information that is lawfully made available from federal, state, or local government records or that is otherwise publicly available within the meaning of applicable law.
2.2 "Services" means the development, optimization, migration, integration, configuration, email marketing, maintenance, and related professional services offered by the Company under the Solidans name, whether provided on a fixed-price, recurring, or bespoke basis.
2.3 "Client Store" means the online store, e-commerce platform account, email marketing account, or other Third-Party Platform account of a Client to which the Company is granted access for the purpose of performing the Services.
2.4 "Third-Party Platform" means any software platform, application, or service that is owned or operated by a party other than the Company and that is used in connection with the Site or the Services, including without limitation Shopify Inc. and its affiliates ("Shopify"), Klaviyo, Inc. ("Klaviyo"), Stripe, Inc. and its affiliates ("Stripe"), and Google LLC and its affiliates ("Google").
2.5 "Independent Contractor" means any freelance developer, designer, marketing specialist, or other individual or entity that is engaged by the Company on an independent-contractor basis to perform all or any portion of the Services on the Company's behalf and that is bound by written confidentiality and data protection obligations in favor of the Company.
2.6 "Service Provider" means any vendor, contractor, or other party that processes Personal Information on behalf of the Company pursuant to a written contract that restricts such party from retaining, using, or disclosing the Personal Information for any purpose other than performing services for the Company.
2.7 "Sale" or "Sell" means the exchange of Personal Information by the Company to a third party for monetary or other valuable consideration, as such terms are defined under applicable state privacy law. "Share" or "Sharing" means the disclosure of Personal Information to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, as such terms are defined under the California Consumer Privacy Act, as amended.
2.8 "Sensitive Personal Information" means Personal Information that reveals an individual's Social Security number, driver's license or other government-issued identification number, financial account credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, citizenship or immigration status, genetic or biometric data, health condition or diagnosis, sex life or sexual orientation, or the Personal Information of a known child, in each case as such term or its equivalent is defined under applicable law.
3. CATEGORIES AND SOURCES OF PERSONAL INFORMATION COLLECTED
3.1 Information You Provide Directly. The Company collects the following categories of Personal Information that you provide directly to the Company, whether through the Site, by electronic mail, through a Third-Party Platform, or otherwise:
- (a) Identifiers and Contact Information, including your name, business name, business email address, business telephone number (if provided), business mailing address (if provided), and the URL or domain name of your online store;
- (b) Inquiry and Engagement Information, including the category of Services in which you have expressed interest, the description of your project or requirements, the platform or technologies your store employs, the contents of your communications with the Company, and any files or documents you transmit to the Company;
- (c) Client Store Access Information, including Shopify collaborator request codes, staff or user account invitations, application programming interface credentials, and login credentials for Third-Party Platforms that you elect to furnish to the Company for the purpose of performing the Services. The Company requests that you grant access through the platform-native mechanisms described in Section 5 wherever such mechanisms are available, and that you refrain from transmitting passwords or other credentials by unencrypted electronic mail;
- (d) Commercial and Transaction Information, including the Services you have purchased or considered purchasing, the dates and amounts of payments, invoice and receipt records, and your payment history with the Company; and
- (e) Payment Information. Payments for the Services are processed by Stripe. When you pay an invoice, your payment card number, expiration date, and card verification value are transmitted directly to Stripe and are not received or stored by the Company. The Company receives from Stripe only limited transaction data, consisting of the cardholder name, billing address, the last four digits and brand of the payment card, the transaction amount, and a transaction identifier. Stripe's processing of your Payment Information is governed by Stripe's privacy policy, available at stripe.com/privacy.
3.2 Information Collected Automatically. When you access the Site or open electronic mail sent by the Company, the Company and its Service Providers automatically collect certain information by means of server logs, cookies, pixel tags, and similar technologies, including:
- (a) Internet Protocol address, approximate geographic location derived therefrom, browser type and version, operating system, device type, screen resolution, and language preference;
- (b) the date and time of your visit, the pages viewed, the duration of your visit, the website or source from which you were referred to the Site, and the links or elements with which you interacted; and
- (c) with respect to electronic mail, whether and when a message was opened and whether any link contained in the message was selected.
The technologies through which such information is collected, and the choices available to you with respect to such technologies, are described in Section 7.
3.3 Information Obtained from Third-Party Sources. The Company obtains Personal Information from the following third-party sources:
- (a) Commercial Data Providers and Publicly Accessible Sources. The Company obtains business contact information relating to the operators of online stores from commercial business-data providers, including StoreRadar, and from publicly accessible sources such as store websites, business directories, corporate registries, professional networking platforms, and social media profiles. Such information consists of the business name, store domain name, e-commerce platform and installed technologies, publicly listed contact name, role or title, business email address, business telephone number, estimated store characteristics such as product count and traffic ranking, and the geographic region in which the business operates. The Company uses such information for the business-to-business marketing purposes described in Section 8 and does not obtain consumer marketing lists or information relating to individuals in their personal, non-commercial capacity.
- (b) Third-Party Platforms. When you grant the Company access to a Client Store, the Company receives from the applicable Third-Party Platform information relating to the store and to the account holder, including the store name, plan level, store owner name and email address, and the permissions granted to the Company. Shopify makes certain such information available to the Company through the Shopify Partner Dashboard in connection with collaborator access requests.
- (c) Payment Processors. The Company receives the limited transaction data described in Section 3.1(e) from Stripe.
- (d) Referral Partners and Agencies. Where you are introduced to the Company by a referral partner, a partner agency for which the Company performs white-label or overflow work, or a freelance marketplace, the Company may receive your name, business name, contact information, and a description of your requirements from such party.
3.4 Sensitive Personal Information. The Company does not request, and does not knowingly collect, Sensitive Personal Information from Users. You are requested not to furnish Sensitive Personal Information to the Company through the Site, by electronic mail, or otherwise. The Company does not Sell Sensitive Personal Information and does not process Sensitive Personal Information for the purpose of inferring characteristics about any individual.
3.5 Information Concerning Other Individuals. If you furnish the Company with Personal Information relating to another individual, including a colleague, employee, or business partner, you represent that you are authorized to do so and that you have provided such individual with notice of this Policy.
3.6 Deidentified and Aggregated Information. The Company may derive deidentified or aggregated information from Personal Information, including statistical information concerning the performance of stores audited by the Company. The Company maintains and uses such information only in deidentified or aggregated form, publicly commits not to attempt to reidentify such information except as permitted by law for the purpose of testing its deidentification processes, and contractually obligates any recipient of such information to comply with the same restrictions.
4. PURPOSES FOR WHICH PERSONAL INFORMATION IS USED
4.1 Business and Commercial Purposes. The Company uses the Personal Information described in Section 3 for the following purposes:
- (a) to perform the Services, including to access and modify Client Stores as authorized by the Client, to prepare and deliver complimentary store audits and performance reports, to communicate regarding project scope, milestones, and deliverables, and to provide ongoing care, maintenance, and email marketing management services;
- (b) to respond to inquiries, prepare quotations and proposals, and otherwise communicate with Prospective Clients and Clients;
- (c) to issue invoices, process payments, administer refunds, maintain accounting records, and pursue collection of amounts owed;
- (d) to send commercial electronic mail and other marketing communications concerning the Services to Prospective Clients and Business Contacts, subject to the requirements and the opt-out rights described in Section 8;
- (e) to operate, maintain, secure, and improve the Site and the Services, including to measure Site traffic and usage patterns, to diagnose technical problems, and to evaluate the effectiveness of the Company's marketing;
- (f) to detect, investigate, and prevent fraud, unauthorized access, security incidents, and other unlawful or prohibited activity, and to protect the rights, property, and safety of the Company, its Clients, its Independent Contractors, and the public;
- (g) to comply with applicable law, regulation, legal process, and governmental request, to enforce the Terms of Service and Client Agreements, and to establish, exercise, or defend legal claims;
- (h) to evaluate or effect a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, as further described in Section 16; and
- (i) for any other purpose disclosed to you at the time of collection or to which you have otherwise consented.
4.2 Limitation on Use of Client Store Information. The Company uses Client Store Access Information and any information obtained from a Client Store solely for the purpose of performing the Services for the applicable Client, and for no other purpose. Without limiting the foregoing, the Company does not use Client Customer Data for the Company's own marketing purposes, does not use information obtained from one Client Store for the benefit of any other Client, and does not use Client Store information or Client Customer Data to create, develop, train, fine-tune, or improve any artificial intelligence or machine learning system.
4.3 Automated Decision-Making. The Company does not use Personal Information to make decisions that produce legal or similarly significant effects concerning any individual by means of solely automated processing, and does not engage in profiling of individuals in furtherance of such decisions.
5. PERSONAL INFORMATION PROCESSED ON BEHALF OF CLIENTS
5.1 Nature of Access. Performance of the Services ordinarily requires that the Company, acting through its personnel and Independent Contractors, be granted access to one or more Client Stores. The Company is a member of the Shopify Partner Program, and access to Client Stores on the Shopify platform is ordinarily granted by the Client through the collaborator access mechanism made available by Shopify, under which the Client furnishes a collaborator request code and approves the specific permissions requested by the Company. Access to Klaviyo and other Third-Party Platforms is granted through staff or user accounts or comparable platform-native mechanisms. Depending upon the Services engaged and the permissions granted, such access may enable the Company to view, export, import, or modify Client Customer Data, including customer names, email addresses, postal addresses, telephone numbers, order histories, purchase amounts, marketing consent and subscription status, email engagement data, and segment membership. Store migration services in particular involve the export of customer, order, and product records from the originating platform and the import of such records into the destination platform.
5.2 Role of the Parties. As between the Company and each Client, the Client is the business or controller that determines the purposes and means of the processing of Client Customer Data, and the Company is a service provider, processor, or contractor that processes Client Customer Data solely on behalf of the Client and in accordance with the Client's documented instructions, as set forth in the Client Agreement and in the scope of the Services engaged.
5.3 Company Obligations. With respect to Client Customer Data, the Company shall:
- (a) process Client Customer Data solely for the purpose of performing the Services for the applicable Client and in accordance with the Client's instructions, and for no other purpose;
- (b) not Sell, Share, rent, lease, or otherwise disclose Client Customer Data to any third party, except to Independent Contractors and Service Providers engaged to perform the Services and bound by written obligations no less protective than those set forth in this Section 5;
- (c) not use Client Customer Data for the Company's own marketing or commercial purposes, and not communicate, directly or indirectly, with the customers or subscribers of any Client except as expressly instructed by the Client in connection with the Services;
- (d) not combine Client Customer Data with Personal Information received from any other Client or from any other source, except as necessary to perform the Services for the applicable Client;
- (e) not use Client Customer Data to create, develop, train, fine-tune, or improve any artificial intelligence or machine learning system;
- (f) implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of the Client Customer Data, as described in Section 10;
- (g) request only those permissions within a Client Store that are reasonably necessary to perform the Services engaged, and refrain from accessing areas of a Client Store that are unrelated to the Services;
- (h) ensure that each Independent Contractor and Service Provider that accesses Client Customer Data is bound by a written agreement imposing confidentiality and data protection obligations no less protective than those set forth in this Section 5, and remain responsible to the Client for the acts and omissions of such Independent Contractors and Service Providers;
- (i) notify the Client without undue delay, and in any event within seventy-two (72) hours, after the Company confirms any unauthorized access to, or acquisition, disclosure, or loss of, Client Customer Data in the Company's possession or control, and cooperate reasonably with the Client in its investigation and in the discharge of any notification obligations imposed upon the Client by applicable law;
- (j) upon completion or termination of the Services, and in any event within thirty (30) days thereafter, delete all Client Customer Data in the Company's possession or control, including any exported files, backups, and working copies held by Independent Contractors, except to the extent retention is required by applicable law, and, upon written request, certify such deletion to the Client; and
- (k) refer to the Client, without undue delay, any request received by the Company from an individual seeking to exercise privacy rights with respect to Client Customer Data, and provide reasonable assistance to the Client in responding to such request.
5.4 Client Responsibilities. Each Client represents and warrants that (a) it has all rights, consents, and authority necessary to grant the Company access to the Client Store and to Client Customer Data for the purpose of performing the Services; (b) its collection and processing of Client Customer Data, and its engagement of the Company as a service provider, comply with applicable law and with the Client's own published privacy policy; and (c) it has provided all notices to, and obtained all consents from, its customers that are required under applicable law for the Company's processing of Client Customer Data as contemplated by the Client Agreement. Each Client is encouraged to grant the Company the minimum permissions necessary to perform the Services, to grant such permissions for a limited duration, and to revoke the Company's access promptly upon completion of the Services. Shopify permits a store owner to remove a staff user or collaborator at any time and automatically expires collaborator access following ninety (90) days of inactivity.
5.5 Requests by Client Customers. If you are a customer or subscriber of a Client and wish to exercise privacy rights with respect to Personal Information held in a Client Store, you should direct your request to the Client. The Company is not in a position to respond to such requests independently of the Client and will refer any such request it receives to the applicable Client in accordance with Section 5.3(k).
5.6 Shopify Partner Program. As a member of the Shopify Partner Program, the Company's access to Client Stores on the Shopify platform is additionally subject to the Shopify Partner Program Agreement and the Shopify API License and Terms of Use, which impose upon the Company independent obligations of confidentiality, data protection, breach reporting, and restriction on the use of merchant and customer data, including a prohibition on the use of merchant and customer data to train artificial intelligence or machine learning systems. Where a Client instead elects to grant the Company access as a staff user, such access is subject to the Shopify Terms of Service applicable to the Client's account. Nothing in this Policy limits any obligation of the Company under such agreements. Shopify's own processing of merchant and customer data is governed by Shopify's privacy policy, available at shopify.com/legal/privacy.
6. DISCLOSURE OF PERSONAL INFORMATION
6.1 Categories of Recipients. The Company discloses Personal Information to the following categories of recipients for the purposes described in Section 4:
- (a) Independent Contractors. The Company engages Independent Contractors to perform all or portions of the Services. Independent Contractors receive Personal Information, Client Store Access Information, and Client Customer Data only to the extent necessary to perform the work assigned to them, are bound by written confidentiality and data protection obligations, and are required to delete such information upon completion of their assignment. Independent Contractors engaged by the Company may be located in the United States or in other countries.
- (b) Service Providers. The Company discloses Personal Information to Service Providers that perform functions on the Company's behalf, including website hosting and content delivery, electronic mail delivery and marketing automation, customer relationship management, business data provision, document storage and collaboration, electronic signature, project management, accounting and invoicing, payment processing, website analytics, and customer support. Service Providers are contractually restricted from using Personal Information for any purpose other than performing services for the Company.
- (c) Third-Party Platforms. In connection with the Services, the Company interacts with Third-Party Platforms, including Shopify, Klaviyo, Stripe, Google, and the originating platforms from which stores are migrated. Such platforms receive Personal Information as an incident of the Company's use of their services, and their processing of Personal Information is governed by their respective privacy policies rather than by this Policy.
- (d) Affiliates and Other Business Lines. The Company operates additional brands and business lines. Personal Information may be disclosed among the Company's brands and business lines for the purposes described in Section 4, subject to this Policy.
- (e) Professional Advisers. The Company discloses Personal Information to its attorneys, accountants, insurers, and other professional advisers to the extent necessary for the provision of professional services to the Company.
- (f) Legal and Regulatory Recipients. The Company discloses Personal Information to courts, law enforcement agencies, regulatory authorities, and other governmental bodies, and to other parties, where the Company believes in good faith that such disclosure is required by applicable law, regulation, subpoena, court order, or other legal process, or is reasonably necessary to protect the rights, property, or safety of the Company, its Clients, its Independent Contractors, or the public, to enforce the Terms of Service or a Client Agreement, or to detect, prevent, or address fraud or security issues.
- (g) Successors and Transferees. The Company discloses Personal Information to actual or prospective acquirers, successors, assignees, financing sources, and their respective advisers in connection with the transactions described in Section 16.
- (h) Recipients Designated by You. The Company discloses Personal Information to third parties at your direction or with your consent.
6.2 No Sale of Personal Information. The Company does not Sell Personal Information and has not Sold Personal Information within the twelve (12) months preceding the Effective Date of this Policy. The Company does not Sell or Share the Personal Information of individuals under sixteen (16) years of age.
6.3 Sharing for Cross-Context Behavioral Advertising. The Company does not Share Personal Information for cross-context behavioral advertising and does not deploy third-party advertising cookies or pixels on the Site, as further described in Section 7.
6.4 Disclosures in the Preceding Twelve Months. In the twelve (12) months preceding the Effective Date, the Company disclosed the categories of Personal Information described in Sections 3.1 through 3.3 to the categories of recipients described in Section 6.1(a) through (f) for the business purposes described in Section 4.
7. COOKIES, ANALYTICS, AND TRACKING TECHNOLOGIES
7.1 Technologies Employed. As of the Effective Date, the Site does not employ third-party analytics services, advertising pixels, or other third-party tracking technologies. The Site and the Company's electronic mail communications employ only the following:
- (a) Strictly Necessary Technologies, consisting of server logs maintained by the Company's hosting provider and such cookies or local storage objects as are required for the operation and security of the Site, including the delivery of content and protection against automated abuse. These technologies do not track your activity across other websites and cannot be disabled through the Site.
- (b) Electronic Mail Technologies, consisting of pixel tags and tracked hyperlinks that may be contained in commercial and transactional electronic mail sent by the Company, which enable the Company to determine whether a message has been opened and whether links within it have been selected.
7.2 Third-Party Collection Across Websites. Because the Site does not employ third-party analytics or advertising technologies, no third party collects Personal Information concerning your online activities over time and across different websites or online services through your use of the Site. Should the Company introduce any such technology, the Company will amend this Section 7 in accordance with Section 17 before doing so, will identify the provider and the categories of information collected, and will describe the means by which you may opt out.
7.3 Your Choices. Most web browsers permit you to refuse or delete cookies through the browser's settings; refusing cookies may impair certain functions of the Site. You may prevent electronic mail pixel tags from functioning by configuring your email client not to load remote images, and you may opt out of commercial electronic mail altogether as described in Section 8.3.
7.4 Do Not Track and Global Privacy Control Signals. No industry standard currently exists for the recognition of browser "Do Not Track" signals, and the Company does not respond to such signals. The Company does not Sell or Share Personal Information collected through the Site; accordingly, a Global Privacy Control signal transmitted by your browser does not alter the Company's processing. Should the Company introduce technologies that constitute Sharing under applicable law, the Company will treat such a signal as a valid request to opt out.
8. COMMERCIAL ELECTRONIC MAIL AND MARKETING COMMUNICATIONS
8.1 Business-to-Business Marketing. The Company sends commercial electronic mail messages concerning the Services to Business Contacts and Prospective Clients whose information was obtained from the sources described in Section 3.3 or who have inquired about the Services. Such messages are directed to individuals in their capacity as owners, operators, or personnel of commercial online stores and are sent from domains owned by the Company, including getsolidans.com. Such messages may include an offer of a complimentary store performance audit.
8.2 Compliance with the CAN-SPAM Act. The Company conducts its commercial electronic mail activities in compliance with the Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003, 15 U.S.C. § 7701 et seq., and the regulations of the Federal Trade Commission promulgated thereunder. Without limiting the foregoing, each commercial electronic mail message sent by the Company (a) contains accurate header and routing information identifying the Company as the sender; (b) contains a subject line that accurately reflects the content of the message; (c) contains the Company's valid physical postal address; (d) contains a clear and conspicuous explanation of how the recipient may opt out of receiving future commercial electronic mail from the Company; and (e) identifies the message as an advertisement or solicitation where required by law. The Company remains responsible for compliance with the foregoing requirements where it engages a Service Provider to transmit messages on its behalf.
8.3 Opting Out. You may opt out of receiving commercial electronic mail from the Company at any time by (a) selecting the unsubscribe link contained in any such message; (b) replying to any such message with the word "unsubscribe" or a comparable instruction; or (c) sending a request to the Company at the electronic mail address set forth in Section 18. The Company will honor your opt-out request within ten (10) business days after receipt and will not thereafter send you commercial electronic mail unless you subsequently request or consent to receive it. The Company maintains a suppression list of opted-out addresses for the purpose of honoring such requests, and retains such list for so long as is necessary for that purpose. The Company does not Sell or transfer opted-out addresses to any third party except to a Service Provider for the purpose of honoring the opt-out.
8.4 Transactional and Relationship Messages. Your opt-out from commercial electronic mail does not affect the Company's ability to send you transactional or relationship messages, including invoices, receipts, project status updates, deliverables, requests for information necessary to perform the Services, security notices, and notices concerning changes to this Policy or the Terms of Service, so long as you remain a Client or have a pending inquiry or transaction with the Company.
8.5 Telephone and Text Message Communications. The Company conducts its business primarily by electronic mail and does not place unsolicited telemarketing calls or send unsolicited text messages. Where you furnish a telephone number to the Company, the Company will use it only to communicate with you concerning your inquiry or engagement.
9. RETENTION OF PERSONAL INFORMATION
9.1 Retention Criteria. The Company retains Personal Information for no longer than is reasonably necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying legal, accounting, tax, and reporting requirements, resolving disputes, and enforcing the Company's agreements. In determining the appropriate retention period, the Company considers the nature and sensitivity of the Personal Information, the purposes for which it is processed, the potential risk of harm from unauthorized use or disclosure, and applicable legal requirements.
9.2 Retention Periods. Subject to Section 9.1, the Company applies the following retention periods:
- (a) Inquiry and Prospective Client Information is retained for twenty-four (24) months following the Company's last communication with the Prospective Client, after which it is deleted or deidentified unless the Prospective Client has become a Client;
- (b) Client Account, Commercial, and Transaction Information is retained for the duration of the Client relationship and thereafter for the period required by applicable tax, accounting, and commercial law, which generally does not exceed seven (7) years following the last transaction;
- (c) Client Store Access Information, including credentials and access codes, is retained only for the duration of the Services for which it was furnished and is deleted or revoked within thirty (30) days after completion or termination of the applicable Services;
- (d) Client Customer Data is retained in accordance with Section 5.3(j);
- (e) Business Contact Information obtained from third-party sources is retained until the Business Contact opts out of communications or until twenty-four (24) months have elapsed without engagement, whichever is earlier, after which it is deleted except for the opted-out address retained on the suppression list;
- (f) Server Logs are retained for a period not exceeding twelve (12) months in identifiable form, subject to the retention settings of the Company's hosting provider; and
- (g) Correspondence and records relating to a legal claim, dispute, investigation, or regulatory inquiry are retained until the matter is finally resolved and all applicable limitation periods have expired.
10. SECURITY OF PERSONAL INFORMATION
10.1 Safeguards. The Company maintains reasonable administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, acquisition, disclosure, alteration, and destruction, having regard to the nature of the Personal Information and the risks to which it is exposed. Such safeguards include (a) restriction of access to Personal Information to those personnel and Independent Contractors who require such access to perform their assigned functions; (b) use of platform-native access grants, including Shopify collaborator access and Klaviyo user accounts, in preference to shared credentials wherever available; (c) storage of any credentials furnished by Clients in an encrypted password management system rather than in electronic mail or unencrypted documents; (d) multi-factor authentication on Company accounts with access to Personal Information; (e) encryption of Personal Information in transit by means of Transport Layer Security; (f) written confidentiality and data protection obligations binding upon all Independent Contractors and Service Providers; and (g) revocation of access and deletion of working copies upon completion of each engagement.
10.2 Limitations. No method of transmission over the Internet and no method of electronic storage is fully secure. The Company therefore cannot guarantee the absolute security of Personal Information, and you acknowledge that you furnish Personal Information to the Company at your own risk. You are responsible for maintaining the confidentiality of any credentials you furnish to the Company and for promptly revoking the Company's access to any Client Store upon completion of the Services.
10.3 Security Incident Notification. In the event of a breach of security resulting in the unauthorized acquisition of Personal Information in the Company's possession or control, the Company will notify affected individuals, Clients, and, where required, regulatory authorities and consumer reporting agencies, in the manner and within the time required by applicable state data breach notification law, including Massachusetts General Laws chapter 93H and 201 Code of Massachusetts Regulations 17.00 to the extent applicable, and by the Company's contractual obligations, including those owed to Clients under Section 5.3(i) and to Shopify under the Shopify Partner Program Agreement.
11. YOUR PRIVACY RIGHTS AND CHOICES
11.1 Rights Extended to All Users. The Company does not, as of the Effective Date, meet the applicability thresholds of any comprehensive state consumer privacy statute, as further described in Section 12. Nonetheless, as a matter of Company policy, the Company extends the following rights to all Users residing in the United States, subject to the verification requirements and exceptions set forth in this Section 11:
- (a) Right to Know and Access. You may request that the Company confirm whether it processes your Personal Information and provide you with the categories of Personal Information the Company has collected about you, the categories of sources from which it was collected, the purposes for which it was collected, the categories of third parties to whom it was disclosed, and the specific pieces of Personal Information the Company holds about you.
- (b) Right to Correct. You may request that the Company correct inaccurate Personal Information that it maintains about you.
- (c) Right to Delete. You may request that the Company delete Personal Information that it has collected from or about you.
- (d) Right to Portability. You may request that the Company provide you with a copy of the Personal Information you have furnished to the Company in a portable and, to the extent technically feasible, readily usable format.
- (e) Right to Opt Out of Marketing. You may opt out of commercial electronic mail at any time as described in Section 8.3.
- (f) Right to Opt Out of Sale, Sharing, and Targeted Advertising. The Company does not Sell Personal Information, does not Share Personal Information for cross-context behavioral advertising, and does not process Personal Information for targeted advertising. Should the Company commence any such activity, it will amend this Policy in accordance with Section 17 and provide a means of opting out.
11.2 Submitting a Request. You may submit a request to exercise any of the foregoing rights by sending an electronic mail message to the address set forth in Section 18 with the subject line "Privacy Request," or by written correspondence to the mailing address set forth in Section 18. Your request should identify the right you wish to exercise and provide sufficient information to permit the Company to locate your Personal Information.
11.3 Verification. The Company will take reasonable steps to verify your identity before acting upon a request, which ordinarily will consist of confirming that the request originates from the electronic mail address associated with your Personal Information in the Company's records. The Company may request additional information reasonably necessary to verify your identity and will use such information solely for that purpose. The Company may decline a request that it cannot verify.
11.4 Authorized Agents. You may designate an authorized agent to submit a request on your behalf. The Company may require the agent to provide written authorization signed by you and may require you to verify your identity directly with the Company.
11.5 Response Timing. The Company will respond to a verified request within forty-five (45) days after receipt. Where reasonably necessary in light of the complexity or number of requests, the Company may extend the response period by an additional forty-five (45) days upon written notice to you within the initial period. The Company will not charge a fee for responding to a request unless the request is manifestly unfounded, excessive, or repetitive, in which case the Company may charge a reasonable fee or decline to act and will inform you of the reason.
11.6 Exceptions. The Company may decline to act upon a request, in whole or in part, where permitted by applicable law, including where the Personal Information is necessary to complete a transaction or perform a contract with you, to detect security incidents or protect against fraudulent or illegal activity, to comply with a legal obligation, to establish, exercise, or defend legal claims, or to perform internal uses reasonably aligned with your expectations. Where the Company declines a request, it will inform you of the reason.
11.7 Appeals. If the Company declines to act upon your request, you may appeal the decision within sixty (60) days by replying to the Company's response with the subject line "Privacy Appeal." The Company will respond in writing to your appeal within forty-five (45) days, stating the action taken or the reason for declining to take action. You may also submit a complaint to the Attorney General of your state of residence.
11.8 Non-Discrimination. The Company will not deny goods or services to you, charge you a different price, or provide a different level or quality of goods or services to you because you have exercised any of the rights described in this Section 11.
11.9 Client Customer Data. This Section 11 does not apply to Client Customer Data, with respect to which requests must be directed to the applicable Client in accordance with Section 5.5.
12. STATE-SPECIFIC DISCLOSURES
12.1 California. This Policy is posted in compliance with the California Online Privacy Protection Act, Cal. Bus. & Prof. Code § 22575 et seq., and the Company's response to "Do Not Track" signals is set forth in Section 7.4. The Company does not, as of the Effective Date, qualify as a "business" subject to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, Cal. Civ. Code § 1798.100 et seq. (the "CCPA"), because the Company has not had annual gross revenues in excess of the threshold established under Cal. Civ. Code § 1798.140 as adjusted by the California Privacy Protection Agency (currently twenty-six million six hundred twenty-five thousand dollars ($26,625,000)), does not annually buy, sell, or share the Personal Information of one hundred thousand (100,000) or more California consumers or households, and does not derive fifty percent (50%) or more of its annual revenue from selling or sharing Personal Information. Should the Company become subject to the CCPA, this Policy will be revised accordingly. In the interim, the Company voluntarily extends to California residents the rights described in Section 11. Pursuant to Cal. Civ. Code § 1798.83 (the "Shine the Light" law), California residents may request information concerning the disclosure of Personal Information to third parties for their direct marketing purposes; the Company does not disclose Personal Information to third parties for such purposes.
12.2 Nevada. This Policy constitutes the notice required by Nev. Rev. Stat. § 603A.340. The Company does not Sell "covered information," as defined in Nev. Rev. Stat. § 603A.320, and does not intend to do so. Nevada consumers may nonetheless submit a verified request directing the Company not to Sell their covered information by contacting the Company as set forth in Section 18. The Company will respond to such request within sixty (60) days after receipt, subject to a single extension of not more than thirty (30) days where reasonably necessary.
12.3 Delaware. This Policy is posted in compliance with the Delaware Online Privacy and Protection Act, 6 Del. C. § 1201C et seq. The Company does not, as of the Effective Date, meet the applicability thresholds of the Delaware Personal Data Privacy Act, 6 Del. C. § 12D-101 et seq., which applies to persons that control or process the personal data of not fewer than thirty-five thousand (35,000) Delaware consumers, or not fewer than ten thousand (10,000) Delaware consumers while deriving more than twenty percent (20%) of gross revenue from the sale of personal data. The Company voluntarily extends to Delaware residents the rights described in Section 11.
12.4 Massachusetts. The Company maintains its principal place of business in the Commonwealth of Massachusetts. To the extent the Company owns or licenses "personal information" as defined in Mass. Gen. Laws ch. 93H, § 1, the Company maintains a written information security program in accordance with 201 Code of Massachusetts Regulations 17.00 and will provide notice of any breach of security in accordance with Mass. Gen. Laws ch. 93H, § 3.
12.5 Texas and Nebraska. The Company qualifies as a small business as defined by the United States Small Business Administration and is accordingly exempt from the Texas Data Privacy and Security Act, Tex. Bus. & Com. Code ch. 541, and the Nebraska Data Privacy Act, Neb. Rev. Stat. § 87-1101 et seq., except that the Company shall not Sell Sensitive Personal Information without the prior consent of the individual to whom it relates. The Company does not Sell Sensitive Personal Information.
12.6 Other States. The Company does not, as of the Effective Date, meet the applicability thresholds of the comprehensive consumer privacy statutes of Colorado, Connecticut, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Utah, or Virginia, each of which applies only to persons that control or process the personal data of a specified minimum number of consumers of that state during a calendar year or that derive a specified portion of revenue from the sale of personal data. The Company voluntarily extends to residents of such states the rights described in Section 11 and will revise this Policy should it become subject to any such statute.
13. CHILDREN'S PRIVACY
The Site and the Services are directed to business operators and are not directed to children. The Company does not knowingly collect Personal Information from any individual under the age of eighteen (18), and does not knowingly collect Personal Information from children under the age of thirteen (13) within the meaning of the Children's Online Privacy Protection Act, 15 U.S.C. § 6501 et seq. If you are under eighteen (18) years of age, you must not use the Site or submit Personal Information to the Company. If the Company learns that it has collected Personal Information from a child under the age of thirteen (13), it will delete such information promptly. A parent or guardian who believes that the Company may have collected Personal Information from a child may contact the Company as set forth in Section 18.
14. THIRD-PARTY WEBSITES AND PLATFORMS
The Site may contain links to, and the Services may be performed upon, websites, platforms, and services operated by third parties, including Shopify, Klaviyo, Stripe, Google, and the platforms from which stores are migrated. This Policy does not apply to the collection, use, or disclosure of Personal Information by such third parties, and the Company is not responsible for their privacy practices. You are encouraged to review the privacy policy of each third-party website or platform that you visit or use. The inclusion of a link on the Site does not constitute an endorsement of the linked website or its operator.
15. USERS OUTSIDE THE UNITED STATES
The Site is operated from, and the Services are offered to businesses located in, the United States of America. Personal Information collected by the Company is stored and processed in the United States and may be accessed by Independent Contractors located in other countries for the purpose of performing the Services. The Company does not direct the Site or the Services to individuals located in the European Economic Area, the United Kingdom, Switzerland, or other jurisdictions outside the United States, and this Policy is not intended to satisfy the requirements of the data protection laws of such jurisdictions. If you access the Site from outside the United States, you do so on your own initiative and acknowledge that your Personal Information will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction. Should the Company engage Clients located outside the United States, the Company will enter into such supplemental terms as applicable law requires.
16. BUSINESS TRANSFERS
The Company may sell, transfer, or otherwise dispose of all or any portion of its business or assets, including the Solidans brand, the Site, its Client relationships, and its Client and Business Contact records, whether by merger, consolidation, acquisition, reorganization, sale of assets or equity, financing, or in connection with bankruptcy, insolvency, or receivership proceedings. In connection with any such actual or proposed transaction, Personal Information may be disclosed to the counterparty and its advisers, subject to customary confidentiality obligations, and may be transferred to the acquirer or successor as one of the transferred assets. Any acquirer or successor will be bound by this Policy with respect to Personal Information transferred to it until this Policy is amended in accordance with Section 17. The Company will provide notice of any such transfer in accordance with Section 17 where required by applicable law.
17. CHANGES TO THIS POLICY
17.1 Right to Amend. The Company reserves the right to amend this Policy at any time. Each amended version of this Policy will be posted on the Site at solidans.com/privacy and will bear a revised Effective Date. Amendments become effective on the Effective Date stated in the amended Policy.
17.2 Notice of Material Changes. Where the Company makes a material change to this Policy, including any change that would permit the Company to use or disclose Personal Information in a manner materially different from that disclosed at the time of collection, the Company will, not less than fifteen (15) days before the change becomes effective, (a) post a conspicuous notice of the change on the Site and (b) send notice of the change by electronic mail to each Client and each other User for whom the Company holds a current electronic mail address. The Company will not apply a material change retroactively to Personal Information collected before the Effective Date of the change without obtaining your consent where required by applicable law.
17.3 Continued Use. Your continued use of the Site or the Services after the Effective Date of an amended Policy constitutes your acknowledgment of the amended Policy. You are encouraged to review this Policy periodically.
18. CONTACT INFORMATION
Questions, comments, requests, and complaints concerning this Policy or the Company's privacy practices should be directed to the Company as follows:
- Halos Development, LLC, d/b/a Solidans
- Attention: Legal and Privacy
- PO Box 260
- Waterville Valley, New Hampshire 03215
- Electronic mail: legal@halosdev.com
- Website: solidans.com
The Company will acknowledge receipt of a privacy request within ten (10) business days and will respond substantively within the periods set forth in Section 11.5.
19. GENERAL PROVISIONS
19.1 Governing Law. This Policy and any dispute arising out of or relating to it shall be governed by the laws of the State of Delaware, without regard to its conflict-of-laws principles, except to the extent that the privacy law of the state in which you reside mandatorily applies to the Company's processing of your Personal Information.
19.2 Severability. If any provision of this Policy is held to be invalid, illegal, or unenforceable, such provision shall be enforced to the maximum extent permissible and the remaining provisions shall continue in full force and effect.
19.3 Headings and Interpretation. Section headings are for convenience of reference only and shall not affect the interpretation of this Policy. The words "include," "includes," and "including" are deemed to be followed by the words "without limitation." References to a statute include the regulations promulgated thereunder and any successor statute or regulation.
19.4 Language. This Policy is drafted in the English language. Any translation is provided for convenience only, and the English-language version shall control in the event of any inconsistency.
19.5 Entire Statement of Privacy Practices. This Policy, together with the Terms of Service and any Client Agreement, constitutes the complete statement of the Company's privacy practices with respect to the Site and the Services and supersedes all prior privacy statements of the Company relating to Solidans.
END OF PRIVACY POLICY