LAST UPDATED: January 1, 2020
- Through offline business interactions you may have with us.
Collectively, we refer to the Websites, Social Media Pages, emails and offline business interactions as the “Services”.
Within this Policy you will find:
- Who We Are
- Personal Information
- Collection of Personal Information
- Use of Personal Information
- Disclosure of Personal Information
- Cookies and Other Information
- Choices and Access
- Retention Period
- Third Party Services
- Age Verification
- Use of Services by Minors
- Jurisdiction and Cross-Border Transfers
- Sensitive Information
- Third Party Payment Services
- Contacting Us
- Additional Information Regarding the EEA
- Additional Information Regarding California
WHO WE ARE
“Personal Information” is information that identifies you as an individual or relates to an identifiable individual
- Postal address (including billing and shipping addresses);
- Telephone number;
- Email address;
- Payment information;
- Account information (including your name and contact details, as well as any account preferences you have created within your account);
- Date of birth, and other information included in a government-issued identification;
- Transaction history (which shows us products and services you have requested, payments and credits and any returns processed);
- Location data (for example, a location is derived from your Internet Protocol (“IP”) address or data such as a zip code or name of a town or city);
- Information you provide on any Website page or other online sharing platforms, such as photos, comments, ratings and other information you choose to submit with us;
- Profile picture;
- Social media account ID, photos, posts and other account content; and
- Any other information you voluntarily provide so that we can communicate with you (for example, when you contact us to provide customer feedback).
COLLECTION OF PERSONAL INFORMATION
We and our service providers collect Personal Information in a variety of ways, including:
- Through the Services
We collect Personal Information through the Services, for example, when you sign up for a newsletter, register an account to access the Services, or make a purchase.
We collect Personal Information from you offline, e.g. place an order over the phone, or contact customer service.
- From Other Sources
We receive your Personal Information from other sources, for example:
Publicly available databases;
If you connect your social media account to your Services account, you will share certain Personal Information from your social media account with us, for example, your name, email address, photo, list of social media contacts, and any other information that may be or you make accessible to us when you connect your social media account to your Services account.
USE OF PERSONAL INFORMATION
We and our service providers use Personal Information for legitimate business purposes including:
- Providing the functionality of the Services and fulfilling your requests.
To provide the Services’ functionality to you, such as arranging access to your registered account, and providing you with related customer service.
To respond to your inquiries and fulfill your requests, when you contact us via one of our online contact forms or otherwise, for example, when you send us questions, suggestions, compliments or complaints, or when you request a quote for or other information about our Services.
To complete your transactions, and provide you with related customer service.
To send administrative information to you, such as changes to our terms, conditions and policies.
We will engage in these activities to manage our contractual relationship with you and/or to comply with a legal obligation.
- Providing you with our newsletter and/or other marketing materials and facilitating social sharing
To send you marketing related emails, with information about our services, new products and other news about our company.
We will engage in this activity with your consent or where we have a legitimate interest.
- Analysis of Personal Information for business reporting and providing personalized services.
To analyze or predict our users’ preferences in order to prepare aggregated trend reports on how our digital content is used, so we can improve our Services.
To better understand you, so that we can personalize our interactions with you and provide you with information and/or offers tailored to your interests.
To better understand your preferences so that we can deliver content via our Services that we believe will be relevant and interesting to you.
We will provide personalized services either with your consent or because we have a legitimate interest.
- Allowing you to participate in sweepstakes, contests or other promotions.
We may offer you the opportunity to participate in a sweepstakes, contest or other promotion.
Some of these promotions have additional rules containing information about how we will use and disclose your Personal Information.
We use this information to manage our contractual relationship with you.
- Aggregating and/or anonymizing Personal Information.
We may aggregate and/or anonymize Personal Information so that it will no longer be considered Personal Information. We do so to generate other data for our use, which we may use and disclose for any purpose.
- Accomplishing our business purposes.
For data analysis, for example, to improve the efficiency of our Services;
For audits, to verify that our internal processes function as intended and are compliant with legal, regulatory or contractual requirements;
For fraud and security monitoring purposes, for example, to detect and prevent cyberattacks or attempts to commit identity theft;
For developing new products and services;
For enhancing, improving, or modifying our current products and services;
For identifying usage trends, for example, understanding which parts of our Services are of most interest to users;
For determining the effectiveness of our promotional campaigns, so that we can adapt our campaigns to the needs and interests of our users; and
For operating and expanding our business activities, for example, understanding which parts of our Services are of most interest to our users so we can focus our energies on meeting our users’ interests;
We engage in these activities to manage our contractual relationship with you, to comply with a legal obligation, and/or because we have a legitimate interest.
DISCLOSURE OF PERSONAL INFORMATION
We disclose Personal Information:
You can consult the list and location of our affiliates in our most recent 10Q or 10K filing here.
- To our third party service providers, to facilitate services they provide to us.
These can include providers of services such as website hosting, data analysis, payment processing, order fulfillment, information technology, marketing management, financial services, age-verification services and related infrastructure provision, customer service, email delivery, auditing, and other services.
- By using the Services, you may elect to disclose Personal Information.
On message boards, chat, profile pages, blogs, and other services to which you are able to post information and content (including, without limitation, our Social Media Pages and any Website page). Please note that any information you post or disclose through these services will become public and may be available to other users and the general public.
Other Uses and Disclosures
We also use and disclose your Personal Information as necessary or appropriate, especially when we have a legal obligation or legitimate interest to do so:
- To comply with applicable law and regulations.
This can include laws outside your country of residence.
- To cooperate with public and government authorities.
To respond to a request or to provide information we believe is important
These can include authorities outside your country of residence.
- To cooperate with law enforcement.
For example, when we respond to law enforcement requests and orders or provide information we believe is important.
- For other legal reasons.
To enforce our terms and conditions; and
To protect our rights, privacy, safety or property, and/or that of our affiliates, you or others.
- In connection with a sale or business transaction.
We have a legitimate interest in disclosing or transferring your Personal Information to third parties in connection with any actual or potential reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings). Such third parties may include, for example, an acquiring entity and its advisors. .
COOKIES AND OTHER INFORMATION
In addition to Personal Information, we and our third-party partners, also collect certain Other Information when you visit our Websites, use our Services, read our emails, or otherwise engage with us. “Other Information” is any information that does not reveal your specific identity or does not directly relate to an identifiable individual. This includes:
- Browser and device information
- App usage data
- Information collected through cookies, pixel tags and other technologies
- Demographic information and other information provided by you that does not reveal your specific identity
- Information that has been aggregated in a manner such that it no longer reveals your specific identity
Collection of Other Information
We and our service providers may collect Other Information in a variety of ways, including:
- Using cookies
- Through your browser or device:
- Certain information is collected by most browsers or automatically through your device, such as your Media Access Control (MAC) address, computer type (Windows or Mac), screen resolution, operating system name and version, device manufacturer and model, language, Internet browser type and version and the name and version of the Services you are using. We use this information to ensure that the Services function properly.
- IP Address
- Your IP address is automatically assigned to your computer by your Internet Service Provider. An IP address may be identified and logged automatically in our server log files whenever a user accesses the Services, along with the time of the visit and the page(s) that were visited. Collecting IP addresses is standard practice and is done automatically by many websites, applications and other services. We use IP addresses for purposes such as calculating usage levels, diagnosing server problems and administering the Services. We may also derive your approximate location from your IP address.
- We may collect the physical location of your device by, for example, using satellite, cell phone tower or WiFi signals. We may use your device’s physical location to provide you with personalized location-based services and content. We may also share your device’s physical location, combined with information about what advertisements you viewed and other information we collect, with our marketing partners to enable them to provide you with more personalized content and to study the effectiveness of advertising campaigns. In some instances, you may be permitted to allow or deny such uses and/or sharing of your device’s location, but if you do, we and/or our marketing partners may not be able to provide you with the applicable personalized services and content.
Uses and Disclosures of Other Information
We may use and disclose Other Information for any purpose, except where we are required to do otherwise under applicable law. In some instances, we may combine Other Information with Personal Information. If we do, we will treat the combined information as Personal Information as long as it is combined.
We seek to use reasonable organizational, technical and administrative measures to protect Personal Information within our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the Contacting Us section below.
CHOICES AND ACCESS
Your choices regarding our use and disclosure of your Personal Information
We give you choices regarding our use and disclosure of your Personal Information for marketing purposes. You may opt-out from:
- Receiving electronic communications from us: We will only send you marketing-related email communications consistent with your preferences. The ability to opt-in/out of such communications is available at check-out and within your account. You can also stop receiving marketing email communications from us by sending an email to email@example.com with subject “Unsubscribe”.
We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages, from which you cannot opt-out.
How you can access, change or delete your Personal Information
If you would like to request to review, correct, update, suppress, restrict or delete Personal Information, object to the processing of Personal Information, or if you would like to request to receive an electronic copy of your Personal Information for purposes of transmitting it to another company (to the extent these rights are provided to you by applicable law), please send an email to firstname.lastname@example.org. We will respond to your request consistent with applicable law. If you are a California resident, please refer to the “Additional Information Regarding California” section at the end of this Policy for more information about the requests you may make under the CCPA.
In your request, please make clear what Personal Information you would like to have changed, or whether you would like to have your Personal Information suppressed from our database. For your protection, we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable.
Please note that we may need to retain certain information for recordkeeping purposes and/or to complete any transactions that you began prior to requesting a change or deletion (e.g., when you make a purchase or enter a promotion, you may not be able to change or delete the Personal Information provided until after the completion of such purchase or promotion).
We retain Personal Information for as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with applicable law. The criteria used to determine our retention periods include:
- The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services);
- Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them); or
- Whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation, or regulatory investigations).
THIRD PARTY SERVICES
In addition, we are not responsible for the information collection, use, disclosure or security policies or practices of other organizations, such as Facebook, Apple, Google, Microsoft, RIM, or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider or device manufacturer, including with respect to any Personal Information you disclose to other organizations through or in connection with our Social Media Pages.
Some of the products that we sell on our Services are highly regulated and age-restricted. We are required and committed to preventing sales to anyone under the legal purchasing age. We will only send you marketing materials and information that encourage or facilitate a purchase of our products after you have certified that 1) you are of legal purchasing age for the product you wish to purchase, and 2) that you understand that providing false information may constitute a violation of the law.
Before you can make a purchase from a product-specific newsletter mailing list, we will verify your age through a non-affiliated third-party service provider to perform an age and identify verification check for adherence to this requirement. We utilize these trusted verification services to verify the information that you provide and ensure that you qualify to access and purchase products from the Services. This process has been developed with your privacy in mind with detailed information neither shared nor accessible.
In some cases, in compliance with applicable law, we may require that you provide a government-issued identification (“ID”) or other forms of a valid ID. If through the third-party verification service we are not able to verify your age and/or identity, you will be requested to upload a copy of your government ID so that our team can manually verify your date of birth. Photo ID’s are uploaded to our third-party partner’s secure database and we simply process the result that they provide – we do not receive a file with your ID to be stored on our servers or database.
USE OF SERVICES BY MINORS
The Services are not directed to individuals under the age of twenty-one (21), and we do not knowingly collect Personal Information from individuals under 21.
JURISDICTION AND CROSS-BORDER TRANSFERS
Your Personal Information may be stored and processed in any country where we have facilities or in which we engage service providers, and by using the Services you understand that your information will be transferred to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country. In certain circumstances, courts, law enforcement agencies, regulatory agencies, or security authorities in those other countries may be entitled to access your Personal Information.
ADDITIONAL INFORMATION REGARDING THE EEA: Some of the non-EEA countries are recognized by the European Commission as providing an adequate level of data protection according to EEA standards (the full list of these countries is available here. For transfers from the EEA to countries not considered adequate by the European Commission, we have put in place adequate measures, such as standard contractual clauses adopted by the European Commission to protect your Personal Information. You may obtain a copy of these measures by contacting us as noted in the Contacting Us section below.
Unless we request it, we ask that you not send us, and you do not disclose, any sensitive Personal Information (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the Services or otherwise to us.
THIRD PARTY PAYMENT SERVICES
Greenlane 1095 Broken Sound Parkway NW, Suite 300 Boca Raton, FL 33487
Because email communications are not always secure, please do not include credit card or other sensitive information in your emails to us.
ADDITIONAL INFORMATION REGARDING THE EEA
You may also lodge a complaint with a data protection authority for your country or region or where an alleged infringement of applicable data protection law occurs. A list of data protection authorities is available here.
ADDITIONAL INFORMATION REGARDING CALIFORNIA
Pursuant to the California Consumer Privacy Act of 2018 (“CCPA”), we are providing the following additional details:
We collected and disclosed the following categories of Personal Information of our customers, prospective customers, visitors to our websites, social media pages, and stores and other premises, and other individuals who engage with our Services, in the preceding 12 months:
|Category||We Collect||We Disclose|
|A. Identifiers such as real name, alias, postal address, online identifier, IP address, email address, account name (including for social media) and driver’s license or other government- issued ID number (solely for the purposes of required age verification – see Age Verification above).||YES||YES|
|B. Personal information as defined in the California customer records law, such as name, contact information, account information, profile picture and social media account ID, and driver’s license or other government-issued ID information (solely for the purposes of required age verification – see Age Verification above).||YES||YES|
|C. Characteristics of protected classifications under California or federal law, such as age.||YES||YES|
|D. Commercial information, such as transaction information, purchase history, financial details and payment information.||YES||YES|
|E. Biometric information, such as fingerprints and voiceprints.||NO||NO|
|F. Internet or other electronic network activity information, such as browsing history, search history, online behavior, interest data, and interactions with our Websites, applications, systems, emails and advertisements.||YES||YES|
|G. Geolocation data, such as device location and IP location.||YES||YES|
|H. Audio, electronic, visual and similar information, such as call recordings and CCTV footage created for quality assurance, safety and security purposes.||YES||YES|
|I. Professional or employment-related information.||NO||NO|
|J. Education information subject to the federal Family Educational Rights and Privacy Act, such as student records.||NO||NO|
|K. Inferences drawn from any of the personal information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics.||NO||NO|
As described above in Collection of Personal Information, we collected this Personal Information from you, our affiliates, publicly available databases and social media providers (when you make this public and/or elect to share this information with us). Also as described above in Use of Personal Information and Disclosure of Personal Information, we use this Personal Information to operate, manage, and maintain our business, to provide our products and services, and to accomplish our business purposes and objectives, including, for example, using Personal Information to: develop, improve, repair, and maintain our products and services; personalize, advertise, and market our products and services; conduct research, analytics, and data analysis; maintain our facilities and infrastructure; undertake quality and safety assurance measures; conduct risk and security control and monitoring; detect and prevent fraud; perform age verification; perform accounting, audit, and other internal functions, such as internal investigations; comply with law, legal process, and internal policies; maintain records; facilitate corporate transactions; and exercise and defend legal claims. Finally, as described above in Disclosure of Personal Information, we share this Personal Information with our affiliates, service providers and other vendors (including data analytics providers), social networks (when you elect to share or post this information), public or government entities and third parties to facilitate corporate transactions (mergers, acquisitions etc.).
We collect the following categories of Personal Information of employees, independent contractors, owners, directors, officers and job applicants, as well as their emergency contacts, dependents and beneficiaries:
|A. Identifiers, such as name, contact information, online identifiers and Social Security numbers and other government-issued ID numbers.||YES|
|B. Personal information, as defined in the California customer records law, such as name, contact information, education information, employment history, financial information and medical and medical insurance information.||YES|
|C. Characteristics of protected classifications under California or federal law, such as sex, age, race, religion, national origin, disability, medical conditions and information, citizenship, immigration status, request for leave and marital status.||YES|
|D. Commercial information, such as transaction information and payment information, in each case for employee-only deals and discounts on our goods and products.||YES|
|E. Biometric information, such as fingerprints and voiceprints.||YES|
|F. Internet or other electronic network activity information, such as browsing history and interactions with our Websites, applications, systems, and emails.||YES|
|G. Geolocation data, such as device location and IP location.||YES|
|H. Audio, electronic, visual and similar information, such as call recordings and CCTV footage created for quality assurance, safety and security purposes.||YES|
|I. Professional or employment-related information, such as work history, prior employer, information relating to references, details of qualifications, skills and experience, human resources data, and data necessary for benefits and related administration services.||YES|
|J. Education information subject to the federal Family Educational Rights and Privacy Act, such as student records.||YES|
|K. Inferences drawn from any of the personal information listed above to create a profile or summary.||YES|
We use this Personal Information for the purposes of operating, managing, and maintaining our business, managing our workforce, and accomplishing our business purposes and objectives, including, for example, using Personal Information to: manage workforce activities and personnel generally, including for recruitment, employee training, leaves, promotions and discipline; manage payroll, wages, tax forms and filing, stock grants and bonuses; administer benefits; maintain and secure our facilities and systems; protect the health and safety of our workforce and others; conduct research, analytics, and data analysis to assist in planning succession and to ensure business continuity; perform accounting, audit, and other internal and business functions; obtain legal and other professional advice; facilitate corporate transactions; comply with law, legal process, investigations, internal policies and other requirements; and establish, exercise or defend legal rights.
We have not “sold” Personal Information for purposes of the CCPA.
If you are a California resident, you may have the right to request that we:
(1) Disclose to you the following information covering the 12 months preceding your request:
The categories of Personal Information we collected about you and the categories of sources from which we collected such Personal Information;
The specific pieces of Personal Information we collected about you;
The business or commercial purpose for collecting (if applicable) Personal Information about you; and
The categories of Personal Information about you that we otherwise shared or disclosed, and the categories of third parties with whom we shared or to whom we disclosed such Personal Information (if applicable).
(2) Delete Personal Information we collected from you.
To make a request for the disclosures or deletion described above, please either:
We will respond to your request consistent with applicable law. For your protection, we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable. Please note that we may need to retain certain information for recordkeeping purposes and/or to complete any transactions that you began prior to requesting a change or deletion (e.g., when you make a purchase or enter a promotion, you may not be able to change or delete the Personal Information provided until after the completion of such purchase or promotion).
You have the right to be free from unlawful discrimination for exercising your rights under the CCPA.