Letter from the founders
First and foremost, we do not sell your personal information. Ever.
EcoCart makes your online orders carbon neutral so we can all join in the fight against climate change. We do this for free by using the commission from our brand partners to buy certified carbon offsets on your behalf. We also pass along a portion of the commission to you in the form of EcoPoints, which you can use to redeem rewards such as planting trees or clean water to families in need.
The rest of the commission we keep for salaries for our team, server costs, and just to keep the lights on. That’s how we make money. Not by selling your data – ever.
Our stance on privacy is simple: We don’t collect any personal information other than what is absolutely necessary for the calculation of your order’s carbon footprint. We’re in the business of saving the planet, not violating your privacy.
If you have any questions or comments, feel free to reach out to us at firstname.lastname@example.org
Dane Baker, Co-Founder & CEO
If we ever need additional personal information for a specific reason, we will tell you and ask for your permission. Also, to the extent that EcoCart has links to other websites (like retailers), please note that we do not own, operate, or control them, and they have their own controlling privacy policies that you should review.
What data we collect and why
In order to provide our products, EcoCart collects information that you share directly with us when you use our website or extension. Though you don’t have to, you can choose to provide your email to set up an account with us, which lets you earn EcoPoints, see a personalized recommendation feed, and more. You can also set up your profile with your name and other info for a more personalized experience.
EcoCart also collects technical information about your device and use of EcoCart to make sure that our products are working correctly. The information we collect is geared to providing EcoCart members with a better way to shop online and to help us develop, improve, and market our services.
Account and Profile Information
When you become a member of EcoCart, you share a limited amount of information during the registration process, optionally including your name, email address, member password and other registration information to personalize your profile. You can also sign up using your existing Google or Facebook account, which lets EcoCart see basic profile information you provided to Google or Facebook, like your name and email address.
If you choose to sign in with Google, you’ll have the option of importing your contacts so that you can refer your friends to EcoCart. Referral addresses are masked, so we never see or store them, nor can we contact anyone without your permission.
As you continue to use EcoCart’s products, you might also provide information when you:
- refer friends from your contacts to EcoCart
- click “follow” on stores you like
- communicate with EcoCart through email or other means
EcoCart cannot see and does not store your payment card data, except in tokenized format (a random algorithmically-generated string) that can only be interpreted by the payment processor.
EcoCart automatically collects information to ensure that our products work correctly on different devices and browsers. This includes data like:
- the type of device you’re using
- the device’s unique ID (where available)
- operating system
- browser type
- IP address
- event stamp
- error logs
This data allows us to make sure EcoCart products are working correctly, to make your experience better, and to detect and prevent fraud. Also, to help us coordinate our communications and marketing campaigns, and to understand how our users engage with our products, we use common digital tools that allow us to see if you opened an email we sent, visited a link in those emails, or generally interacted with EcoCart as a result of our marketing efforts.
Shopping and Usage Data
On retail sites, EcoCart collects the name of the retailer, page views, and in some cases, product information that allows us to track price changes and update our product catalog. The information you share, and we collect, enables us to improve our products and gives us insights about deals, pricing, and availability of retail items, which we can share with the rest of the EcoCart community. We may also use this information to provide you with a more tailored, relevant experience or show sponsored product offers that may interest you.
Aggregate and Anonymized Data
We may also use the information we collect in aggregate or otherwise anonymized form. This lets us look at interactions with our site and products generally and does not identify you or any specific person. We use this general data for research, development, marketing, analytics, and to enhance the shopping experience for the EcoCart community.
What data we do not collect
We collect information that we believe can help us save our users time and money. This does not include, and we do not collect, any information from your search engine history, emails, or from websites that are not retail sites.
We also do not collect bank or credit card information.
How we share your data
We know how important your personal data is to you, so we will never sell it. We’ll only share it with your consent or in ways you’d expect (as we explain here). That means we will share your data if needed to complete your purchase, with businesses who help us operate EcoCart, or if we are legally required to do so.
We may also share information in the following cases:
- with your express consent;
- in an aggregate or anonymized format that does not identify any specific person;
- as required by law, or to comply or respond to a valid government request;
- when we believe in good faith that it’s necessary to protect our rights, protect your safety or the safety of others, or investigate fraud; and
- with a buyer or successor if EcoCart is involved in a merger, acquisition, or similar corporate transaction. If that happens, you will be notified via email and/or a prominent notice on the Website of any change in ownership, as well as any choices you will have as a result.
How we protect your data
The security of your information is important to us. Our team is dedicated to protecting your information and have put in place physical, electronic, and procedural safeguards.
These measures include limiting access, using encryption, testing for vulnerabilities, advanced malware detection, employing pseudonymization and anonymization techniques, and more.
Though we hate to say it, despite our efforts, we can’t guarantee that user information will not be accessed, viewed, disclosed, altered, or destroyed as a result of a breach of any of our safeguards. You provide us with information at your own risk.
EcoCart only retains information about you as long as you keep using EcoCart. We’ll also keep information if we need it to meet our legal obligations and to defend against legal claims.
Some cookies can be temporary (“session cookies” like those used for navigating your browser) and disappear once you close it. Others last longer (“persistent cookies,” like when you ask a site to remember your login) and are saved to your computer until you delete them.
Our cookies serve several important functions:
- Analytics: These types of cookies help EcoCart monitor the traffic and activity on our site, and to coordinate our own marketing campaigns. While they do not identify you specifically, they may be indirectly linked to your unique user ID. We aggregate and anonymize this data to help us detect fraud, understand trends, broad demographic data, and the general operation of our site.
If you want to disable cookies entirely, your browser or mobile device might have an option to do that. For more information, including instructions on disabling cookies, please visit: http://www.allaboutcookies.org/
Your choices for managing your data
If you would like to delete your profile or personal information, you can always ask us by emailing email@example.com. We will delete any personal information we have, though we may still store some data in an aggregated and anonymized format that doesn’t identify you and can’t be attributed to you (or if we’re legally required).
Additional rights regarding your data
Depending on where you live, you may have additional rights as to the personal information that you share and EcoCart collects. Residents of the EU, UK, Canada, Australia, New Zealand, and California can click below to learn more.
EU, UK, Canada, Australia, and New Zealand residents
Controller: EcoCart is a private company, established in the United States of America. Our address is 340 Fremont St. Suite 301. Our contact email address is firstname.lastname@example.org. For the purposes of the General Data Protection Regulation, we are the data controller.
- When you consent to our use of your data for a specific purpose.
- When we need that data to enact a transaction or to provide you with services and products that you request. This includes personalizing features and protecting the security of EcoCart and its users.
- When EcoCart has a legitimate interest in using that data in the normal ways you’d expect, like ensuring EcoCart’s products run properly, improving and creating new products, historical analytics research, promoting EcoCart, and protecting our legal rights.
- When we need to process your data to comply with a legal or regulatory obligation.
Your rights: You have the following rights with regard to your personal data. To exercise any of these rights, please contact us at email@example.com. Please note that these rights are limited, like for example, where fulfilling your request would adversely affect other individuals or our legal obligations.
- Right to Access: You have the right to request information about your personal data that we hold, how we use it, and who we share it with.
- Right to Portability: Where you have provided your personal data to us on the basis of your consent, you have the right to ask us for a copy of this data in a structured, machine-readable format and to ask us to send this data to another data controller.
- Right to Rectification: You have the right to ask us to correct your personal data where it is inaccurate or incomplete.
- Right to Erasure: In certain circumstances, you have the right to ask us to delete the personal data we hold about you.
- Right to Withdraw Consent: In situations where we are processing your personal data based on your consent, you may withdraw this consent at any time.
- Right to Object to Processing: In situations where we are processing your personal data based on our legitimate interest, you can object that the interest is no longer legitimate. EcoCart will stop processing that data, unless we can demonstrate an overriding legitimate ground. You can also request to opt out of direct marketing.
- Right to Restrict Processing: You have the right to ask us to stop any active processing of your personal data while we seek to verify data you claim is inaccurate, while we verify our legitimate interests, or while we cannot erase that data due to legal obligations.
EcoCart will try to respond to these requests within 30 days, but some might take longer. You will typically not be charged any fee for effecting these rights, but EcoCart reserves the right to charge a reasonable fee (or refuse to comply) if the request is unfounded, repetitive, or excessive.
Complaints: In the event that you wish to make a complaint about how we process your personal data, please contact us at firstname.lastname@example.org and we will do our best to resolve it. You can also choose to file a complaint with the relevant data protection authority.
If you live in California and use EcoCart, you have some additional rights when it comes to your data.
- Right to Delete: You can ask us to delete the personal information we have about you.
California law gives you the right to opt out of the sale of your personal information. But EcoCart does not and will not sell (or rent, or disclose for value) any of your personal information in the first place. So you’re good.
To exercise any of these rights, you (or your authorized agent) can contact us through the “Contact us” webform on our Help page (help.ecocart.io) or by email at email@example.com. We will confirm receipt of your request within 10 days, and will provide a response to you within 45 days of your request, though in some exceptional cases it might take longer (if that happens, we’ll let you know). We will need your name and email address to verify your request, and may also ask for additional information if necessary to verify the identity of the person making the request. We reserve the right to deny your request if we cannot verify your identity, or if an exemption applies (for example, where fulfilling your request would adversely affect other individuals, or where we have a conflicting legal obligation). That said, we will not discriminate against you for exercising any of your privacy rights.
To learn about the categories of personal information that EcoCart uses, please see the section of this policy called “What data we collect and why.” The personal information that we have collected in the past 12 months falls into the following categories as set out under California law:
- The contact information you provide – California law refers to these as identifiers.
- We don’t track your location, but your IP address gives us a general idea of the city, state, and country – what California law calls geolocation.
- Shopping and EcoCart usage data – California law calls this internet activity.
- Purchases on retail sites when using EcoCart – this is commercial information under California law.
To learn about the limited ways in which we disclose data for our business purposes — that is, to a service provider — and the categories of those service providers, please see the section of this policy called “How we share your data.”
Please note that, while EcoCart provides tools to manage your privacy as described in this policy, we do not support “Do Not Track” browser settings at this time.
Data Transfers and the EU-US Privacy Shield
If we transfer your data outside of the European Economic Area, we will do so within the safeguards of Model Contract Clauses and the EU-US Privacy Shield framework.
As we are located in the United States and EcoCart’s products are operated in the United States, if you are located outside of the United States, please be aware that information you share and we collect will be transferred to, and processed, stored, and used in the United States in order to provide EcoCart’s products to you. The United States does not have an adequacy decision regarding data protection from the European Commission.
EcoCart is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission. With regard to personal data that EcoCart may transfer from the European Union to the United States, in some circumstances, including liability for cases of onward transfers to third parties, you may invoke binding arbitration
We will respond to complaints in a timely fashion, and further commit to refer unresolved Privacy Shield complaints to the American Arbitration Association (AAA), an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit http://go.adr.org/privacyshield for more information or to file a complaint. The services of the AAA are provided at no cost to you.
We created EcoCart for the exclusive use of adults (18 and older). We don’t knowingly collect or solicit personal information from children. If you are a child under 18, please do not attempt to register for EcoCart’s products or send any personal information to us.
If we learn we have collected personal information from someone under 18, we will delete that information as quickly as possible. If you are a parent or guardian of a child who you think may have given us some personal information or posted information on any public portion of EcoCart’s products, please let us know at firstname.lastname@example.org. We’ll help you remove it.
Changes to this policy