TOMO, PRIVACY POLICY

Effective: February, 2021

At TOMO, we greatly respect and value your privacy! 

We believe in transparency, we therefore, are dedicated to being honest and plain about our privacy practices – this includes how we handle your personal information.

This Privacy Policy informs you about what personal information we collect when you visit our website at tomobottle.com. It also lets you know why and how we collect, use and process such information. 

Note that “TOMO,” “we,” “us,” “our,” or “the store,” refers to the same entity which is the TOMO company and which will be referred to as the “The Services” in this policy.” Bear in mind, that this policy is not applicable to third party policies (this includes members who sell using the Services or API users) who may also collect or receive data in connection with your use of the Services. This site is owned and operated by TOMO BOTTLE LLC.

You agree that by using TOMO Services, you acknowledge that you permit TOMO to use your information in the United States, and every other country where TOMO operates. Bear in mind that the privacy laws and regulations in specific countries (including the rights of authorities to access your personal data), may be different from those of your country of residence. 

INFORMATION WE COLLECT OR RECEIVE 

In the process of providing you with our Services, we collect or receive your personal information in a variety of ways. The categories of personal information we collect from you include: 

- Those we collect directly from you: These include information you provide to us from forms you complete or during registration with TOMO. 

- Those we collect indirectly based on your activity on our website or from the device or browser you use to access the Services. 

- From our vendors, suppliers and business partners who help us provide our services to you, such as payments or customer support. 

Mostly, you get to decide what information to provide to us; however, sometimes we require specific information from you to provide our Services. The personal information you provide us with is used according to this Privacy Policy.
 

INFORMATION WE AUTOMATICALLY COLLECT

We automatically collect some specific information (device information) when you visit our website/store. Such information includes: info about your web browser, IP address, time zone, and some of the cookies installed on your device. Furthermore, as you surf through the Site, we collect information about the individual web pages or products viewed by you, we also save what websites or search terms/keywords that referred you to the Site, as well the information about how you interact with these pages and TOMO Site. 

When you visit the TOMO Store, we also automatically collect device-specific information when you install, access, or use our Services – this includes information such as the hardware model, operating system information, app version, app usage and debugging information, browser information, IP address, and device identifiers. 

All this information is used in preventing fraud and keeping the Services secure. We also use it to analyze and understand how the Services work for members and visitors, and to provide advertising across your devices, and to ensure a more personalized experience for you. 

To learn more about these online tools and how we use them, see our Cookies & Similar Technologies Policy and “Information Uses, Sharing, & Disclosure” Section below.

CURRENCY CONVERSION

By using our website, you (the visitor) agree to allow third parties to process your IP address, in order to determine your location for the purpose of currency conversion. You also agree to have that currency stored in a session cookie in your browser (a temporary cookie which gets automatically removed when you close your browser). We do this in order for the selected currency to remain selected and consistent when browsing our website so that the prices can convert to your (the visitor) local currency.

HOW WE USE, SHARE & DISCLOSURE YOUR INFORMATION

When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address and email address.

When you browse our store, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.

Email marketing (if applicable): With your permission, we may send you emails about our store, new products and other updates.

TOMO shares your Personal Information with third parties to help us use such Information, as described above. For instance, we use Shopify to power our online store—to learn more about how Shopify uses your Personal Information, checkout this link: https://www.shopify.com/legal/privacy. 

We also use Google Analytics in helping us to understand how our customers use and interact with the Site – learn more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. If you wish to opt-out of Google Analytics, you can do so here: https://tools.google.com/dlpage/gaoptout. 

Lastly, we may be required to disclose your Personal Information in compliance with applicable laws and regulations, to respond to a subpoena/court order, search warrant or other lawful request for information which we may receive. We may also do so to protect our legal rights. 

Legal Bases for Collecting and Processing your Personal Information 

At TOMO, we collect, use, share, and otherwise process your personal information for the purposes described in this policy whenever you use or access the TOMO website. We place reliance on a number of legal bases to use your information and they include: 

- To perform the contractual obligations in our Terms and Conditions and to provide the Services to you.

- You have consented to the processing of your information by TOMO – which you can choose to revoke at any time.

- In compliance with a legal obligation, a court order, or to exercise or defend any impending or asserted legal claims.

- For the purposes of our or a third party’s legitimate interests, such as those of visitors, members, or partners.

- You have expressly made the information public.

- To protect public interest, for example to prevent the commission of a crime.

- Occasionally necessary to protect your vital interests or those of others (in rare cases where we may need to share information to prevent loss of life or personal injury). 
 

CONSENT

How do you get my consent?

When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.

If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no.

How do I withdraw my consent?

If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at any time, by contacting us at support@tomobottle.com.

DISCLOSURE

We may disclose your personal information if we are required by law to do so or if you violate our Terms and Conditions.

SHOPIFY

Our store is hosted on Shopify Inc. They provide us with the online e-commerce website that allows us to sell our products and services to you. 

Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.

PAYMENT 

If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase

transaction information is deleted.

All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover.

PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.

For more insight, you may also want to read Shopify’s Terms and Conditions

(https://www.shopify.com/legal/terms) or Privacy Statement

(https://www.shopify.com/legal/privacy).

THIRD-PARTY SERVICES

In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.

However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.

For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.

In particular, remember that certain providers may be located in or have facilities that are located in a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.

As an example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.

Once you leave our store’s website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s Terms and Conditions.
 

LINKS

When you click on the links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.

SECURITY

We value the security of your personal information; and in the light of this, we take active steps in following generally accepted industry standards to protect your personal information which you have with us. To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.

One of the ways by which we keep you covered is through encryption – this is commonly used in protecting your credit card details. Please note that, no method of transmission of data via the internet or method of electronic storage is flawlessly secure.

If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.

Therefore, while we do all we can to keep your personal information safe, we cannot guarantee its total security. 

Your account is protected by a password. We therefore urge you to protect your account from unauthorized access by choosing a strong password which you can easily remember and signing out after using TOMO Services. 
 

COOKIES

Here is a list of cookies that we use. We’ve listed them here so you that you can choose if you want to opt-out of cookies or not.

_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).

_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits _shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, 

Counts the number of visits to a store by a single customer.

cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.

_secure_session_id, unique token, sessional

storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.

In providing the Services to you, we use cookies and similar technologies. Please read our TOMO Cookies & Similar Technologies Policy for a more detailed explanation of the technologies we use, and how to opt out when applicable. 

AGE OF CONSENT

By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.

YOUR RIGHTS 

If you are a European resident, you have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us through suppot@tomobottle.com

Additionally, if you are resident in Europe, note that we are processing your information in order to fulfill contracts we might have with you (for instance, if you purchase an order via TOMO Site), or otherwise to guarantee our legitimate business interests which we have listed above. Furthermore, take note that your information will be transferred outside of Europe – this includes to Canada and the United States. 

Specific privacy laws in different countries around the world, including the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), provide users with rights related to the processing and use of their personal information. In accordance with those laws, you have the choice to access, edit, or even remove certain information, and also choices about us contacting you. If you wish to change or correct or remove any part of your TOMO account information, contact us through suppot@tomobottle.com You are also at liberty to request the permanent closure of your account and to delete your personal data. You may also, depending on your location, enjoy a variety of rights in connection with your information. Please note that although some of these rights apply generally, some specific rights apply in limited cases.  

- Right to Access & Portability: You have the right to access specific personal information connected to your account by going to your account privacy settings. You are at liberty to request for a copy of your personal information in an easily accessible format and information explaining how your personal information is being used. For more information, contact us through 

suppot@tomobottle.com

- Right to Correction: if you think there is any incorrect information about you in our systems, you have the right to request that we rectify such information. You can correct or change certain personal information associated with your TOMO account through your account settings.  

- Right to Restrict Processing: In some instances, where we process your information, you may also have the right to restrict or limit the methods we employ in using your personal information. 

- Right to Deletion: in specific cases, you have the right to request that we erase your personal information – except information we are required to retain by law, regulation, or in order to guarantee the safety, security, and integrity of TOMO. 

- Right to Object: If we use or process your information based on our legitimate interests as explained above, or in public interest, you have the right to object to this processing in certain circumstances. Should this happen, we will stop processing your information unless we have compelling legitimate reasons to continue processing or where it is needed as a legal obligation. Where we use your personal data for sending you direct marketing messages or correspondences, you can decide to object to that by using the unsubscribe link in such messages or by changing your account email settings. 

- Right to Withdraw Consent: Where we rely on your consent before performing an action, you have the right to choose to withdraw such consent to our processing of your information using specific features provided to enable you to withdraw consent, like an email unsubscribe link or your account privacy preferences. If you have agreed to share your device location details but you wish to discontinue sharing that information with us, you can revoke your consent to the sharing of such information through your mobile device settings. 

Additional Rights provided by the CCPA to residents in California: 

- Right to Know: If you are resident in California, you are at liberty to request the disclosure of the specific pieces and/or categories of personal information that the we have collected about you, the categories of sources for that personal information, the business or commercial purposes for collecting the information, the categories of personal information that we have disclosed, and the categories of third parties with which the information was shared. 

- Right to Opt-Out: To the extent that TOMO “sells” personal information and that term is defined under the CCPA), California residents have the right to opt-out of the “sale” of data at any time (see below for more information). 

If you wish to manage, change or alter, limit, or delete your personal information, you can do so through your TOMO account settings. You are free to exercise any of the rights above by contacting us through 

suppot@tomobottle.com Note that we may need to verify your identity using government issued or other forms of identification. If you wish to designate someone else to exercise this right on your behalf, you must provide a valid power of attorney, the requester’s valid government issued identification, and the authorized agent’s valid government issued identification, and we may verify the authenticity of your request to exercise this right directly with you. 

EMAIL & MESSAGES 

You are at liberty to control the types of communications which we can have with you through your account settings. We may send you messages about the Services or your activity while interacting with the Services. Some messages are required or service related (e.g. legal notices), while others are optional such as newsletters. If you wish to discontinue the use of the Services or want to stop receiving service-related messages (except for legally required notices), you can close your account by contacting us through suppot@tomobottle.com

ADDITIONAL DISCLOSURES FOR CALIFORNIA RESIDENTS

Notice of Collection: 

Adding to the Rights & Choices described above, the CCPA requires disclosure of the categories of personal information collected over the past 12 months. The categories of personal information that we have collected (as described by the CCPA) are:  

- Identifiers, which include name, email address, shop name, IP address, and an ID or number assigned to your account. 

- Additional individual records like phone number, billing address, or credit or debit card information. This category includes personal information protected under pre-existing California law (Cal. Civ. Code 1798.80€), and overlaps with other categories listed here. 

- Demographics, such as your age or gender –this category includes data that may qualify as protected classifications under other California or federal laws. 

- Commercial information – this includes purchases and engagement with the Services. 

- Internet activity, including your interactions with our Services and what led you to our Services. 

- Sensory visual data, such as pictures posted on our Service. 

- Geolocation data provided through location enabled services such as WiFi and GPS. 

- Inferences, including information about your interests, preferences and favorites.  

THE PURPOSES OF OUR COLLECTION 

We collect these types of personal information for business and commercial purchases – Including providing and improving the Services, maintaining the safety and security of the Services, processing purchase and sale transactions, and for advertising and marketing services. 

If you wish to learn more on this, please see our “Information Uses, Sharing and Disclosure” Section above. 

Third Party Marketing and Advertising and Your Rights (Opt-Out of “Sale”) 

We do not sell personal information to anyone for money or monetary value. However, the term “sale” is defined broadly under the California Consumer Privacy Act. To the extent that the CCPA interprets “sale” to include interest based advertising or other data uses, we will comply with the applicable law as to those activities. You can opt-out by doing so through your account privacy settings or the general privacy settings link at the foot of our homepage and most pages on our Site (the right to opt-out of interest based advertising is available to every TOMO member). 


CURRENCY CONVERSIONS

By using our website, you (the visitor) agree to allow third parties to process your IP address, in order to determine your location for the purpose of currency conversion. You also agree to have that currency stored in a session cookie in your browser (a temporary cookie which gets automatically removed when you close your browser). We do this in order for the selected currency to remain selected and consistent when

browsing our website so that the prices can convert to your (the visitor) local currency.

CHANGES TO THIS PRIVACY POLICY

We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.

If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.

We encourage you to check back regularly and review any updates that we have made. 

QUESTIONS AND CONTACT INFORMATION

If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information Contact TOMO Support team through support@tomobottle.com.

If you have an unresolved privacy or data use concern that we have not taken care of satisfactorily, you can contact us any time and we will do our best to help you resolve it.