Last updated on August 12, 2020

INTRODUCTION

KIRUNIVERSE is committed to respecting your privacy rights and personal data. This privacy policy (“Policy”) explains how we collect, store and use information about you when you use or interact with KIRUNIVERSE.COM (our website) and where we otherwise obtain or collect information about you. This policy applies to all users of KIRUNIVERSE.COM and its associated websites, features, content, materials, apps, products, and/or services which is owned by KIRUNIVERSE LLC (“KIRUNIVERSE,” “us” or “we”). This policy does not apply to websites, services or products that have their own privacy policies, or are not clearly identified as applicable entities below. You are strongly encouraged to read this policy in its entirety. 

 

If you find that you are opposed to this policy, please refrain from using the website or similar services. When you use the website, you understand that we may collect and use information about you as described within this policy.

 

This Privacy Policy went into effect on the date it was last updated on August 12, 2020.

 

SUMMARY

Information we collect: name, contact details, payment information (e.g. your credit or debit card details), IP address, information from cookies, information about your computer or device (e.g. device and browser type), information about how you use our website (e.g. which pages you have viewed, the time when you view them and what you clicked on, the geographical location from which you accessed our website (based on your IP address), your answers to quizzes or surveys, and information about your internet connection.

INFORMATION WE COLLECT AND HOW WE USE IT

Types of Information we may collect:

 

  • Real name, alias, unique personal identifier, online identifier, Internet Protocol address, account name, driver’s license number, or other similar identifiers;

  • Physical characteristics;

  • Commercial information, or other purchasing or consuming histories or tendencies;

  • Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer’s interaction with an Internet website, application, or advertisement;

  • Audio, electronic, visual, or similar information;

  • Inferences drawn from any of the information identified in this section to create a profile about you reflecting your preferences, characteristics, predispositions, behaviour and attitudes.

Web server log information

 

We use third-party servers to host our website called Wix.com Ltd. and Squarespace, Inc., the privacy policies of which are available here: https://www.wix.com/about/privacy and here: https://www.squarespace.com/privacy. Our website servers automatically log the IP address you use to access our website as well as other information about your visit such as the pages accessed, information requested, the date and time of the request, the source of your access to our website (e.g. the website or URL (link) which referred you to our website), and your browser version and operating system.

 

This website and our services may be operated, in whole or in part, from a country other than the United States. Because the internet is used in a global environment, using it to collect and process personal information involves the transmission of data on an international basis. The information we collect about you may be transferred to, accessed in and stored at, a destination outside the European Economic Area (“EEA”). For more information on the safeguards used, please see the section of this privacy policy entitled Transfers of your Information outside the European Economic Area.

 

Use of website server log information for IT security purposes

 

Our third party hosting providers collect and store server logs to ensure network and IT security and so that the server and website remain uncompromised. This includes analysing log files to help identify and prevent unauthorised access to our network, the distribution of malicious code, denial of services attacks and other cyber attacks, by detecting unusual or suspicious activity.

 

Unless we are investigating suspicious or potential criminal activity, we do not make, nor do we allow our hosting provider to make, any attempt to identify you from the information collected via server logs.

 

Legal basis for processing: compliance with a legal obligation to which we are subject (Article 6(1)(c) of the General Data Protection Regulation).

Legal obligation: we have a legal obligation to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of our processing of information about individuals. Recording access to our website using server log files is such a measure.

 

Legal basis for processing: our and a third party’s legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interests: we and our third party hosting provider have a legitimate interest in using your information for the purposes of ensuring network and information security.

 

Cookies and similar technologies

 

Cookies are small pieces of data sent from a website to a browser to record information about users for various purposes.

 

We use cookies and similar technologies on our website, as they allow us to collect information about your online browsing, such as information regarding your browser type, the country code where your device is located, the pages of our website that were viewed during your visit, the advertisements you clicked on, and any search terms that you entered on our website.

 

You can reject some or all of the cookies we use on or via our website by changing your browser settings, but doing so can impair your ability to use our website or some or all of its features. For even more information about cookies, please visit www.allaboutcookies.org

 

Information we collect when you contact us

 

We collect and use information from individuals who contact us in accordance with this section and the section entitled Disclosure and additional uses of your information.

 

Email and Contact Form

 

When you send an email to the email address displayed on our website, we collect your email address and any other information you provide in that email (such as your name, telephone number and the information contained in any signature block in your email).

 

Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

 

Legitimate interest(s): responding to enquiries and messages we receive and keeping records of correspondence.

 

Legal basis for processing: necessary to perform a contract or to take steps at your request to enter into a contract (Article 6(1)(b) of the General Data Protection Regulation).

 

Reason why necessary to perform a contract: where your message relates to us providing you with goods or services or taking steps at your request prior to providing you with our goods and services (for example, providing you with information about such goods and services), we will process your information in order to do so).

 

Transfer and storage of your information

 

We use a third party email provider/customer management tool to store emails and messages you send us. Our third party email provider is G Suite by Google, located in the United States. Their privacy policy is available here: https://policies.google.com/privacy?hl=en

 

Emails you send us will be stored outside the European Economic Area on our third party email provider’s servers in the United States and other locations based on their sub-processors. For further information, please see the section of this privacy policy entitled Transfers of your information outside the European Economic Area.

 

Information we collect when you use our website

 

We collect and use information from individuals who interact with particular features of our website in accordance with this section and the section entitled Disclosure and additional uses of your information.

 

E-Newsletter

 

When you sign up for our e-newsletter on our website or opt to receive news, offers, updates on out-of-stock items from us by entering your name and email address and clicking subscribe or ticking a box at checkout indicating that they would like to receive your e-newsletter, we collect your email address, information about your browser, information about the page you signed up on, and any other additional information you may provide to us.

 

Legal basis for processing: your consent (Article 6(1)(a) of the General Data Protection Regulation). 

 

Consent: you give your consent to us sending you our e-newsletter by signing up to receive it using the steps described above.

 

Transfer and storage of your information

 

We use a third party service to send out our e-newsletter and administer our mailing list, The Rocket Science Group LLC, and Ascend by Wix. Their privacy policies are available here at https://mailchimp.com/legal/privacy/, and https://www.wix.com/about/privacy.

 

Information you submit to subscribe for our e-newsletter will be stored outside the European Economic Area on our third party mailing list provider’s servers in the United States. For further information about the safeguards used when your information is transferred outside the European Economic Area, see the section of this privacy policy below entitled Transfers of your information outside the European Economic Area.

 

Registering on our website

 

When you register and create an account on our website, we collect the following information: Email address, IP address, and any other information you provide to us when you complete the registration form.

 

If you do not provide the mandatory information required by the registration form, you will not be able to register or create an account on our website.

 

Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation). 

 

Legitimate interest: registering and administering accounts on our website to provide access to content, secure access to order history and status for customers and to facilitate the running and operation of our business.

 

Transfer and storage of your information

 

Information you submit to us via the registration form on our website will be stored outside the European Economic Area on our third party hosting provider’s servers in The United States and Canada. Our third party hosting provider is Wix with servers located throughout North America and where its sub-processors may be located. Their privacy policy is available here: https://www.wix.com/about/privacy.

 

For further information about the safeguards used when your information is transferred outside the European Economic Area, see the section of this privacy policy below entitled Transfers of your information outside the European Economic Area.

 

Information we collect when you place an order on our site

 

We collect and use information from individuals who place an order on our website in accordance with this section and the section entitled Disclosure and additional uses of your information.

 

Information collected when you place an order

 

Mandatory information

 

When you place an order for goods or services on our website, we collect your name, email address, billing address, shipping address, company name (if applicable), billing name, and information about your browser.

 

If you do not provide this information, you will not be able to purchase goods or services from us on our website or enter into a contract with us.

 

Legal basis for processing: necessary to perform a contract (Article 6(1)(b) of the General Data Protection Regulation). 

 

Reason why necessary to perform a contract: we need the mandatory information collected by our checkout form to establish who the contract is with and to contact you to fulfil our obligations under the contract, including sending you receipts and order confirmations.

 

Legal basis for processing: compliance with a legal obligation (Article 6(1)(c) of the General Data Protection Regulation). 

 

Legal obligation: we have a legal obligation to issue you with an invoice for the goods and services you purchase from us and we require the mandatory information collected by our checkout form for this purpose. We also have a legal obligation to keep accounting records, including records of transactions.

 

Optional information

 

We also collect optional information from you, such as your phone number or information about how your experience was in the form of a survey. We also ask you if you would like to receive marketing communications from us. For further information, see ‘Marketing communications’ in this section below.

 

If you do not supply the optional information requested at checkout, such as phone number. we will not be able to contact you by phone or SMS.

 

Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation. 

 

Legitimate interests: finding out how a customer’s experience was to improve your business’ website or to be able to contact the customer by phone where (if necessary) in relation to their order.

 

AND

 

Legal basis for processing: your consent (Article 6(1)(a) of the General Data Protection Regulation). 

 

Legitimate interests: you consent to us processing any optional information you provide by submitting that information to us.

 

Processing your payment

 

After you place an order on our website you will need to make payment for the goods or services you have ordered. In order to process your payment we use a third party payment processor (Wix Payments). Your payment will be processed by Wix Payments.

 

Wix Payments collects, uses and processes your information, including payment information, in accordance with their privacy policies. You can access their privacy policy via the following link:  https://support.wix.com/en/article/wix-payments-and-pci-compliance

 

For further information about the safeguards used when your information is transferred outside the European Economic Area, see the section of this privacy policy below entitled Transfers of your information outside the European Economic Area.

 

Legal basis for processing: necessary to perform a contract (Article 6(1)(b) of the General Data Protection Regulation).

 

Reason why necessary to perform a contract: to fulfil your contractual obligation to pay for the goods or services you have ordered from us.