EN

Privacy policy

Last modified:

Table of contents
Table of contents

LANGUAGE

Your privacy is important to us. This Privacy Policy (“Policy”) explains how we handle your personal data, including how it is collected, used, shared, and protected when you interact with our Services.

We encourage you to review this Policy carefully to understand how your personal data is processed and the rights available to you. By accessing or using the Services, you acknowledge and accept the terms outlined herein.

DEFINITIONS

Personal Information” means any data that identifies, relates to, describes, or could reasonably be linked—directly or indirectly—to an individual.

Data Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Information.

“Data Processor” means a natural or legal person, public authority, agency or other body which processes Personal Information on behalf of the Data Controller.

Other capitalized terms not defined herein have the meanings set forth in our Terms of Service.

PERSONAL INFORMATION WE PROCESS 

We collect the Personal Information you choose to share with us when you create an account, use the Services or interact with us. 

This may include the following categories:

Personal information you provide directly to us

(i) Account Registration Details: Information provided when setting up an account for the Services, including your username and encrypted password. 

(ii) Contact Information: Your name, email address, telephone number, mailing or billing address, title, and any optional profile information you choose to provide;

(iii) Communications & Other Information: Messages and interactions you send through the Services — such as emails, chat conversations, support tickets, feedback, survey responses, search queries, or prompts. 

(iv) Content You Upload or Create: Any materials you post, upload, or generate while using the Services, including text, images, design assets, comments, or participation in surveys, contests, or other interactive features. 

(v) Transaction & Billing Information: Details related to purchases or subscription activity, including payment confirmations and transaction history. 

(vi) Public or Optional Contributions: Information you voluntarily submit in public or community areas (such as blog comments or promotional activities).

Personal Information from third-parties

We may receive Personal Information about you from third-parties or external systems that you choose to interact with. These may include:

(i) Your Organization: Personal Information provided by your employer or another entity that manages your access to the Services.

(ii) Login and Authentication Providers: Personal Information shared by platforms you use to sign in (e.g., identity or social login services).

(iii) Social Media Platforms: Personal Information you share when interacting with us on social media, such as your username, profile image, comments, or posts.

(iv) Data Providers and Public Sources: Professional or business information available from data providers or public records.

(v) Advertising and Analytics Partners: Information about your interactions with our ads or referral links.

You may disconnect Third‑Party accounts or adjust your privacy settings at any time. Once disconnected, we will no longer receive information from that service.

Personal Information collected automatically

When you use the Services, we automatically collect certain Personal Information about your activity, device, and interactions. This may include:

(i) Service Activity and Account Events: Personal Information that reflects your interactions with the Services, including authentication actions, use of specific features, creation or modification of content, file uploads or downloads, preference adjustments, support‑related actions, and corresponding timestamps.

(ii) Device Details and Technical Diagnostics: Data supplied by your device or browser, such as IP address, operating system, browser type, device identifiers, language configuration, and approximate location when this setting is enabled.

(iii) Service Navigation and Interaction Logs: Records of how you move through and engage with the Services, including pages or screens accessed, time spent, elements selected, navigation paths, referring pages, and broader clickstream behavior.

(iv) Cookies, Pixels, and Related Tracking Tools: Information gathered through cookies, pixel tags, scripts, and similar tracking mechanisms, as further detailed in our Cookies and Tracking Technologies section.

For more details about cookies and similar technologies, please refer to the Cookies and Tracking Technologies section.

HOW WE USE YOUR PERSONAL INFORMATION

We process Personal Information for:

(i) Service Provision: to create and manage your account, provide features and functionalities, process payments, and deliver support.

(ii) Service Improvement: to analyze usage, troubleshoot issues, and enhance features, including through aggregated or de-identified data.

(iii) Personalization: to tailor content, recommendations, and features based on your activity and preferences.

(iv) Service Communications: to send essential notices (e.g., security, billing, technical updates), which cannot be opted out of.

(v) Marketing: to send promotional communications and personalize offers, where you have provided consent (you may opt out at any time).

(vi) Security and Fraud Prevention: to detect, prevent, and address misuse, unauthorized activity, or policy violations.

(vii) Legal and Regulatory Compliance: to comply with applicable laws, enforce our terms, and respond to lawful requests.

(viii) Corporate Transactions: to facilitate mergers, acquisitions, or similar business transfers, subject to appropriate safeguards.

(ix) Support: to resolve technical issues and respond to inquiries.

LEGAL BASES FOR PROCESSING

Depending on the context, we rely on one or more of the following legal bases to process Personal Information:

(i) Legitimate Interests: to operate, secure, and improve the Services, unless overridden by your rights (you have the right to object to such processing).

(ii) Consent: e.g., marketing, non-essential cookies, which you may withdraw at any time.

(iii) Performance of a Contract: to provide and manage the Services in accordance with our terms.

(iv) Legal Obligation: to comply with applicable laws and regulatory requirements.

(v) Vital Interests: to protect life or physical safety in exceptional situations.

(vi)Public Interest: where processing is required for reasons of public interest.

HOW WE SHARE YOUR PERSONAL INFORMATION

We may share Personal Information with trusted third-parties in the following situations:

(i) Service Providers: we rely on trusted third-parties that support the operation, maintenance, and delivery of the Services.

(ii) Affiliates: we may share Personal Information within our corporate group for internal administrative and operational purposes.

(iii) Legal & Protection Purposes: where required to comply with legal obligations, enforce our terms, or protect rights, users, or the public.

(iv) Corporate Transactions: in connection with mergers, acquisitions, financing, or similar business events, Personal Information may be shared for such specific purposes.

(v) Authorities & Safety: where necessary to respond to lawful requests or to address safety, fraud, or security concerns.

YOUR RIGHTS

(i) Right of Access: you have the right to obtain confirmation as to whether we process your Personal Information and receive a copy of such data.

(ii) Right to Rectification: you can request correction of inaccurate or incomplete Personal Information.

(iii) Right to Erasure: you can request deletion of your Personal Information where legally applicable.

(iv) Right to Restriction: you can request limitation of processing in certain circumstances.

(v) Right to Data Portability: you can receive your Personal Information in a structured, commonly used, machine-readable format and transmit it to another Data Controller where technically feasible.

(vi) Right to Object: you can object to processing based on legitimate interests, and to certain targeted advertising.

(vii) Right to Withdraw Consent: you have the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.

(viii) Right to Opt-Out of Marketing Communications: you may opt out of receiving promotional emails, newsletters, and other marketing communications at any time by using the unsubscribe link in our messages or by adjusting your account preferences. You will continue to receive essential service-related communications.

(ix) Right to Lodge a Complaint: you may lodge a complaint with a supervisory authority in your jurisdiction.

We will respond to all requests in accordance with applicable legal requirements and may require verification of your identity before fulfilling certain requests.

Appeals
If you are not satisfied with our response to a request, you may request a review of our decision (for US State Laws).

Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights. This means we will not deny you services, charge different prices, or provide a different level or quality of service because you have exercised your rights under applicable law.

Do Not Sell or Share My Personal Information: Where applicable under privacy laws, you may opt out of the “sale” or “sharing” of your personal information for targeted advertising purposes. You can exercise this right through your privacy settings or by using available opt-out mechanisms (including browser-based signals where supported).

No Automated Decision-Making: We do not use automated decision-making processes, including profiling.

HOW TO EXERCISE YOUR RIGHTS

You can contact us at privacy@bannersnack.com, including enough information to verify your identity and indicate the right you wish to exercise.

Depending on your location, you may also have the right to file a complaint with your local data protection authority:

(i) EU/EEA: You may contact the supervisory authority in your country of residence, workplace, or where the issue occurred. A list of authorities is available on the European Data Protection Board website.

(ii) United Kingdom: You may contact the Information Commissioner’s Office (ICO) at https://ico.org.uk/make-a-complaint/ .

(iii) Brazil: You may contact the Autoridade Nacional de Proteção de Dados (ANPD) at https://www.gov.br/anpd .

(iv) Other regions: You may contact the relevant data protection supervisory authority in your jurisdiction.

HOW WE KEEP YOUR PERSONAL INFORMATION SAFE

We take the security of your Personal Information seriously and implement a combination of technical, organizational, and administrative safeguards designed to protect it from unauthorized access, alteration, disclosure, destruction or unlawful processing. These measures include:

(i) Encryption: Data is protected in-transit and at-rest using TLS/HTTPS. Sensitive data at rest is encrypted. Passwords are stored using secure one-way hashing.

(ii) Access Controls: Access is strictly limited to authorized personnel on a need-to-know basis, using role-based access, least-privilege principles, unique credentials, and multi-factor authentication for administrative access.

(iii) Infrastructure Security: Systems are hosted in secure environments protected by firewalls, intrusion detection/prevention systems, network segmentation, and continuous monitoring.

(iv) Security Testing: We regularly conduct vulnerability assessments, penetration testing, code reviews, and security audits to maintain and improve security.

(v) Organizational Measures: Employees are subject to confidentiality obligations and receive regular data protection training. Where required, we appoint a Data Protection Officer or responsible security function.

(vi) Data Minimisation: We process only personal data necessary for defined purposes and retain it only for as long as necessary.

(vii) Incident Response: In the event of a personal data breach, we will notify the relevant supervisory authority and affected individuals where required by law, including details of the incident and mitigation measures.

Additionally, third‑party services or integrations you choose to connect may affect your privacy settings or security. We are not responsible for the security practices of third‑party platforms.

HOW LONG WE KEEP YOUR PERSONAL INFORMATION

We retain your Personal Information only for as long as it is necessary to achieve the purposes set out in this Policy and in line with applicable legal bases. 

(i) Account Data: We retain account-related information while your account is active. Upon closure or prolonged inactivity, data is deleted, anonymised, or de-identified within a reasonable period, unless retention is required by law.

(ii) Legal and Compliance Obligations: Certain data may be retained to comply with legal, tax, accounting, audit, or regulatory requirements, or to establish or defend legal claims (e.g., typically up to seven years for financial records, depending on jurisdiction).

(iv) Marketing Preferences: If you opt out of marketing, we retain minimal information (e.g., email address) solely to record and respect your preference.

(v) Support Data: Customer support records may be retained for a limited period (e.g., up to three years) to improve services and resolve disputes.

(vi) Technical and Usage Data: Logs and analytics data are generally retained for short periods (e.g., up to 90 days), unless longer retention is required for security, operational, or legal purposes.

(vii) Deletion: At the end of applicable retention periods, data is securely deleted or irreversibly anonymised. Where immediate deletion is not feasible (e.g., backups), data is securely isolated until removal is possible.

In determining appropriate retention periods, we take into account the type of data, the purposes for which it is processed, applicable legal and regulatory obligations, and the length of our relationship with you.

CHILDREN’S PRIVACY

Access to our Services is restricted to individuals who are at least 18 years old, or who meet the minimum age required under applicable law in their jurisdiction. We do not knowingly collect Personal Information from anyone under this age threshold. Therefore, please consider:

(i) Age Restriction: If you are under the required minimum age, you must not access or use the Services, or submit any personal information to us.

(ii) No Intentional Collection: We do not knowingly collect, sell, or share Personal Information of individuals who do not meet the applicable age requirement.

(iii) Unintentional Collection: If we become aware that Personal Information has been collected from a child in error, we will take reasonable steps to delete it promptly, unless retention is required by law.

(iv) Parental Contact: Parents or legal guardians who believe a child may have provided us with Personal Information may contact us at privacy@bannersnack.com to request its removal.

(v) Third-Party Services: If you choose to connect third-party services, their own terms and privacy practices will apply. We are not responsible for the data practices of such third parties.

INTERNATIONAL TRANSFER OF DATA

Your Personal Information may be processed, stored, or accessed in jurisdictions outside your country of residence, where data protection laws may differ. Wherever your Personal Information is processed, we implement appropriate technical and organizational safeguards to ensure it remains protected in accordance with applicable data protection laws.

Transfers from the EEA, UK, and Switzerland

When Personal Information is transferred from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have been formally recognized as providing an adequate level of protection, we rely on the relevant adequacy decisions or adequacy regulations issued by the European Commission, UK relevant authorities, or Swiss Federal Council.

Where no adequacy decision applies, we implement legally recognized safeguards to ensure that your personal information remains protected. These safeguards include:

(i) European Commission’s Standard Contractual Clauses (SCCs);

(ii) Supplementary Measures: where required, we apply additional technical, contractual, or organizational measures to address risks associated with cross‑border transfers.

Transfers from Other Jurisdictions

For transfers from countries with their own cross‑border transfer requirements (such as Brazil, India, Canada, or Australia), we comply with the mechanisms recognized under the applicable local laws, which may include contractual protections, or other approved transfer tools.

COOKIES AND SIMILAR TRACKING TECHNOLOGIES

To ensure the proper functioning of our Services and to enhance your experience, we use cookies and similar tracking technologies. These technologies enable us to store your preferences, understand how the Services are used, optimize performance, enhance security, and deliver tailored content and advertising.

Cookies are small text files stored on your device that enable the Services to operate effectively and understand how they are used. Similar technologies (such as pixels or tags) may collect information about your interactions, including pages visited, links clicked, and time spent.

We use different types of cookies, including essential, functional, analytics, advertising, and social media cookies. In some cases, limited information may be shared with trusted third-party providers in accordance with applicable laws.

You can control your cookie preferences through our cookie banner, your browser settings, or other available opt-out mechanisms. Please note that disabling certain cookies may impact the functionality of the Services.

Some cookies are placed by third-party providers that deliver analytics, advertising, or social media features. These providers process data in accordance with their own privacy policies.

For more detailed information about the cookies we use and how to manage them, please refer to our “Cookies” hyperlink available on the website.

THIRD-PARTY LINKS AND SERVICES

Some browsers include a Do Not Track (“DNT”) feature that signals to websites that you do not want your online activity tracked. Because there is no industry consensus on how to respond to DNT signals, we do not currently alter our data practices in response to DNT signals. However, where required by applicable law, we do honor Global Privacy Control (GPC) signals as a valid opt-out of the sale or sharing of Personal Information.

CONTACT US

If you wish to exercise your rights, if you have concerns about how we process your Personal Information or if you have any other privacy related questions, you can contact us at:

We will respond within the timeframes required by applicable law.

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority, as indicated above in Section 7 “How to exercise your rights”.

CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. When we make updates, we will revise the “Effective Date” at the top of this Policy.

To the extent permitted by law, your continued use of the Services after an updated version becomes effective will be considered an acknowledgment of the revised terms. 

We encourage you to periodically review this Policy to stay informed about how we protect your information

JURISDICTION-SPECIFIC DISCLOSURES

  1. California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), applies.

Your Rights (subject to verification and applicable exceptions):

  • Right to Know: request details about the Personal Information we collect, use, and disclose.

  • Right to Access: obtain a copy of your personal information.

  • Right to Correct: request correction of inaccurate information.

  • Right to Delete: request deletion of your personal information.

  • Right to Data Portability: receive your data in a portable format.

  • Right to Opt-Out: opt out of the “sale” or “sharing” of personal information and certain profiling (where applicable). 

  • Right to Limit Use of Sensitive Personal Information: as described in this Policy.

  • Non-Discrimination: you will not be treated differently for exercising your rights.

Additional Disclosures:
  • We do not sell Personal Information.

  • We do not share Personal Information for cross-context behavioral advertising.

  • We collect categories of Personal Information as described in this Policy for the purposes outlined therein.

  • Notice of Collection: This Policy serves as our notice at collection under CCPA. We have provided the categories, purposes, and whether we sell/share data.

  • Shine the Light (CA Civil Code §1798.83): We do not share personal information with third parties for their direct marketing purposes without consent.

  1. Other U.S. State Residents

If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or another U.S. state with applicable privacy laws, you may have similar rights to:

  • Access, correct, or delete your Personal Information.

  • Obtain a portable copy of your data.

  • Opt out of targeted advertising, profiling, or the “sale” of personal data (where applicable).

  • Appeal a denied request

  • Be free from discrimination for exercising your rights

  1. Nevada Residents

Under Nevada law, you may opt out of the sale of certain personal information. We do not sell personal information as defined under Nevada law.

How to Exercise Your Rights

To submit a request, please contact us at privacy@bannersnack.com. We will verify your identity and respond within the timeframe required by applicable law. You may also designate an authorized agent to act on your behalf, subject to verification.

  1. EEA, UK, and Switzerland (GDPR / UK GDPR)

If you are located in the EEA, UK, or Switzerland:

  • You have rights under applicable data protection laws, including access, correction, deletion, restriction, portability, and objection.

  • You may lodge a complaint with your local supervisory authority (e.g., ICO in the UK).

  • International transfers are safeguarded as described in this Policy.

  • Contact: privacy@bannersnack.com  | DPO: dpo@bannersnack.com 

  1. Other Jurisdictions

Australia: Rights to access and correct personal information; complaints may be made to the OAIC.
Canada: Rights to access, correct, and withdraw consent, subject to legal limitations.
Brazil: Rights under the LGPD, including access, correction, deletion, and portability; complaints may be directed to the ANPD.

For all regions, please contact privacy@bannersnack.com to exercise your rights.

Third-Party Services

Our Services may include links to third-party platforms. We are not responsible for their privacy practices, and we encourage you to review their policies.