Effective Date: July 15, 2022
WHO WE ARE
This is the Policy of TraceGains, Inc. (“TraceGains,” “us,” “our,” or “we”), a Delaware corporation with offices at 10385 Westmoor Dr., Bldg. 5, Suite 200, Westminster, CO 80021. You can contact us using the information below.
TraceGains is revolutionizing information exchange across the supply chain by connecting TraceGains customers with their suppliers (collectively, the “Clients”). TraceGains delivers full-service supplier, compliance, and regulatory document management services. Our solutions address the unique needs of the food and beverage industry by connecting partners, collecting critical documents, and capturing data to predict and reduce risk. In each case, we provide a platform for use by Clients, and this Policy reflects the data processed and activities undertaken through our Services. However, the Policy does not apply to the Client’s own uses of your data, including processing they may choose to undertake that is not described in, or different from, this Policy.
This Policy also does not apply to information processed by other third parties, for example, when you visit a third- party website or interact with third-party services, unless and until we receive your information from those parties. Please review any third parties’ privacy policies before disclosing information to them. See our list of third parties for more information regarding our sources and recipients of personal data.
COLLECTION AND USE OF PERSONAL DATA
Data We Collect
We collect and process the following types of information, including data that relates to identified or identifiable individuals (“Personal Data”) (note, specific Personal Data elements listed in each category are only examples and may change):
|Identity Data||Personal Data about you and your identity, such as your name, username, company affiliation and title, and other Personal Data you may provide on applications, registration forms, or as part of an account profile.|
|Contact Data||Personal Data used to contact an individual, e.g. email address(es), physical address(es), phone number(s), or communications platform usernames/handles, as well as a name or other salutation.|
|Transaction Data||Personal Data we collect in connection with a transaction or purchase, such as subscription information, price, and other similar information.|
|Payment Data||Information such as bank account details, payment card information, and information from credit reference agencies, including similar data defined in Cal Civil Code § 1798.80(e).|
|Professional Data||Personal Data relating to your employment or profession.|
|Device Data||Personal Data relating to your device, browser, or application e.g. IP addresses, MAC addresses, application ID/AdID/IDFA, identifiers from cookies, session navigation history and similar browsing metadata, and other data generated through applications and browsers, including cookies and similar technologies.|
|Inference Data||Inferred data created from the analysis of or related to Personal Data, e.g. individual predispositions, characteristics, behaviors, and attitudes.|
|Custom Content||Information that a user provides in a free text or other unstructured format, or in custom fields created by a Client; this may include Personal Data to the extent provided by the user.|
Processing of Personal Data
Account Registration; Subscriptions
Clients and users may register and create an account (or Client administrators may create accounts on behalf of users) in order to use our Services. If you choose to register, we will process Identity Data, Professional Data, Device Data, and Contact Data. We may also collect certain Custom Content from you, for example, in free-form fields, questionnaire responses, file uploads, user bios, or similar account features/functions.
We use this Personal Data as necessary to create, administer, maintain, and provide you with important information about your account, and to otherwise provide the Services, the features Clients, Supplier, or their users’ request, as well as for our Business Purposes (described below). Where allowed by law, we may also process such Personal Data as described in the Marketing Communications section below.
Additionally, if you subscribe to our Platform or pay an invoice through the Services, we (or our service provider) may process Identity Data, Contact Data, Device Data, Payment Data, and Transaction Data in connection with generation and payment of an invoice or subscription payment, to detect fraud and secure the transaction, and for other appropriate Business Purposes.
If you use Gather, we may collect the information specified above in the Account Registration and Service Use sections, as well as the Cookies and Similar Technologies section below. Additionally, we may process supplemental Identity Data, Usage Data, Device Data, and Professional Data associated with your use of Gather. For example, we may collect information relating to the Clients, Suppliers, products, industries, or other content you view when you use of Gather, or interact with other Clients, Suppliers, or users. If you provide shared documents, we may also collect certain Custom Content. Additionally, we may create certain Inference Data, for example, to understand the types of products or industries you and other users in your organization are interested in, or information about your organization that may be of interest to others.
We use this Personal Data primarily to operate, administer, maintain, and otherwise provide and operate Gather. Additionally, we use this data to assess trends, suggest products, Suppliers, or Clients that may be of interest to you or others in your organization, to count product/profile/content views, and to develop other similar metrics. In some cases, we may advertise Supplier and buyer products or services to users, in which case, we will collect information and create reports relating to the advertiser and the product/service advertised, as well as Identity Data, Professional Data, and other Personal Data relating to the user or Client viewing the advertisement. We may prepare and disclose aggregated reports relating to advertisement or company page views (e.g. viewer industry, view count, etc.) In some cases (subject to user account permissions and controls), we may also disclose to advertisers certain Personal Data of users who view Client/Supplier advertisements, posts, or pages. Personal Data we collect in connection with Gather may also be used in connection with marketing communications (where allowed by law) and for our general Business Purposes.
Users may access, view, and engage with certain areas of our Services, including but not limited to support communities and message boards. When you participate in these Services, we process certain Personal Data, which typically includes Identity Data, Contact Data, and Custom Content that may be provided. Any materials you choose to share on such public areas of the Services are public and non-confidential.
Depending on the service in use, we may use Identity Data and Contact Data as necessary to enable posts and communications on the Platform or our public Services. Subject to Your Rights and Choices, we may also use Identity Data in connection with marketing communications, as part of our efforts to improve our Services, and for our other Business Purposes.
Clients may submit inquiries, company and product information, requirements, and offerings through our Services. When you submit an data relating to either a Supplier or Customer, or related product, we process certain Personal Data, which typically includes Identity Data, Professional Data, and Contact Data, and if requested by the Client, Custom Content (“Application Data”).
We use all Application Data as necessary to provide our Services to the Clients, including in connection with the assessment of applications and prospective applicants, to operate the Platform, and as necessary to create, maintain, and provide you with important information about your account and the products and services you may be offering as a Supplier or soliciting as a Customer. Subject to Your Rights and Choices, we may also use Identity Data, Contact Data, and Custom Content: (i) in connection with the maintenance of Client records; (ii) to provide marketing or other communications between customers and suppliers; and (iii) for our Business Purposes.
Workspaces, Client Comments, Messaging & Custom Content
We process Identity Data, Contact Data, and if provided, Custom Content when you use our Services to fill out forms relating to products offered or sought, message a Client, or if you otherwise submit any Custom Content (e.g. on a comment board or other free form content submission form).
We use Identity Data and Contact Data as necessary to carry out the processes you request. Subject to Your Rights and Choices, we may also use Identity Data to improve our Services and, on behalf of the Client, we may make certain Custom Content and Identity Data contained in Client profiles available on our site for viewing by other Clients, and we may process Identity Data and Contact Data in connection with marketing communications, as well as for our Business Purposes.
Note: We do not screen messages, comments, or other postings for personal or inappropriate content.
If you use our Mobile Apps in connection with our annual conference (“TGCon”), we may process certain Personal Data, which typically includes Identity Data, Contact Data, and Device Data. Note, you may also be able to view other attendees, connect on social media, and receive additional speaker information through our Mobile App.
On behalf of the Clients, we process the Identity Data, Contact Data, and Device Data as necessary to deliver the Service and fulfill your requests. Subject to Your Rights and Choices, we may use the Identity Data, Contact Data, and Device Data to improve our services and for our Business Purposes.
Cookies and Similar Technologies
We, and certain third parties, may process Device Data when you interact with cookies and similar technologies. We may receive this data from third parties to the extent allowed by the applicable partner. Please note that the privacy policies of third parties may apply to these technologies and information collected.
In connection with our legitimate interests in providing and improving the user experience and efficiency of our Services, and understanding information about the devices and demographics of visitors to our Services, we use this information (i) for “essential” or “functional” purposes, such as to enable various features of the Services such as your browser remembering your username or password, maintaining a session, or staying logged in after a session has ended; and (ii) for analytics and site performance purposes, such as tracking how the Services are used or perform, how users engage with and navigate through the Services, what sites users visit before visiting our Services, how often they visit our Services, and other similar information.
Additionally, in some cases (and subject to your consent where required by law), we may collect and process certain information about use of the Platform (e.g. feature use, navigation, or Platform performance) by you or the Client/Supplier/Customer’s on whose behalf you use the Platform (“Personal and Company Analytics Data”). We may associate the Personal and Company Analytics Data with your Registration Data and data relating to the relevant Client/Supplier/Customer. We use Personal and Company Analytics to understand how users and Clients/Suppliers/Customers use the Platform, provide you with customer service and support, and to otherwise improve the Platform. Note, if we do associate Personal and Company Analytics with your Registration Data, we may still derive aggregate statistics from it to assess the use by Clients/Suppliers/Customers. We use a third party to collect and process Personal and Company Analytics Data, and we may make such data available to our personnel with a need to know such information in connection with support requests.
Note: Some of these technologies can be used by third parties to identify you across platforms, devices, sites, and services; however, we do not permit Personal and Company Analytics Data nor the associated Registration Data to be used except in connection with our Platform. Clients may also have access to information, such as reports and analytics, generated through these Services.
We may process Identity Data and Contact Data in connection with email marketing communications, including (i) on behalf of Clients, when you register for an account, and choose to enroll, or are enrolled by the Client, to receive marketing communications; (ii) on behalf of Clients, when you open or interact with, a Client’s electronic marketing communications; (iii) on our own behalf when you contact us directly, or express an interest in our products and services; and (iv) on our own behalf when you open or interact with our marketing communications.
We use Identity Data and Contact Data as necessary to provide marketing communications, and consistent with our legitimate business interests, we may send you marketing and promotional communications if you sign up for such communications or purchase services from us. See Your Rights and Choices, below, for information about how you can limit or opt out of this processing.
If we process Personal Data in connection with our Services in a way not described in this Policy, this Policy will still apply generally (e.g. with respect to your rights and choices) unless otherwise stated when you provide it.
GENERAL PURPOSES & BASES FOR PROCESSING PERSONAL DATA
In addition to the specific processing purposes described above, we typically process Personal Data for several general “Business Purposes” related to the day-to-day operation of our business. For example, we process your Personal Data as necessary:
- to fulfill our contractual or pre-contractual obligations to you and to provide our Services;
- in connection with our legitimate interests in providing, improving, and securing the Services;
- to create aggregated data about our Services; and
- to comply with the law, and in the public interest.
Please see below for more information regarding the purposes for which we process your Personal Data for “Business Purposes.”
Contractual Necessity; Service Provision
We process any Personal Data as is necessary to provide the Services, and as otherwise necessary to fulfill our contractual obligations to you, e.g. to provide you with the information, features, and services you request. Similarly, we may process payment in relation to billing, invoicing, payment, and other account management functions.
Our Legitimate Interests and Internal Business Purposes
We may process Personal Data (and we may create related Inference Data or other Personal Data), as appropriate in connection with our legitimate interests in carrying out common business functions, e.g.:
- improving or optimizing the design and functionality of our Services;
- to develop new features or services;
- to personalize the Platform or Services, display, UI/UX elements, or other features of the Services for specific Clients, Suppliers, and their users;
- for customer service purposes;
- for internal reporting and modeling, e.g. to understand what parts of our Services are most relevant to users, how users interact with various aspects of our Services, how our Services perform or fail to perform, etc.;
- to detect, prevent, and respond to information security risks to the Services or users, e.g. through the creation and analysis of access logs and other relevant metadata, analysis of network traffic, device patterns and characteristics, and similar processing; and
- to detect and mitigate fraud, and otherwise monitor and ensure the security, availability, and stability of the Services.
We process Personal Data as necessary in connection with our legitimate interests in the creation of aggregate analytics relating to how our Services are used, the products and services our users purchase, to create service delivery metrics, and to create other reports regarding the use of our Services, demographics of our Users, and other similar information and metrics. The resulting aggregate data will not contain information from which an individual may be readily identified.
To respond to communications, reach out to you about your use or our provision of our Service, your account, to provide other relevant notifications or information, or request information or feedback. From time to time, we may use your Personal Data to send important notices, such as communications about purchases and changes to our terms, conditions, and policies, or other information that relating to the Service to which you are subscribed or that you use.
Security, Safety, and Fraud Prevention
We may process Personal Data as necessary to carry out actual or prospective corporate transactions, e.g. as part of corporate restructuring, mergers, acquisitions, and other similar administrative purposes, including related due diligence.
Compliance and Public Interest
We may also process any Personal Data as necessary to comply with our legal obligations, such as: where you exercise your rights under applicable law; for the establishment and defense of legal claims; where we must comply with our legal obligations; lawful requests from government or law enforcement officials; or as may be required to meet national security or law enforcement requirements, or to prevent illegal activity. We may also process data to protect the vital interests of individuals, or on certain public interest grounds, each to the extent allowed under applicable law.
Other Processing of Personal Data
Information we collect may be shared with a variety of parties, depending upon the purpose for and context in which that information was provided. We generally transfer Personal Data to the following categories of recipients:
Clients: We process data on behalf of Clients and may share your Personal Data with Clients to the extent such information was provided to us for processing on the Client’s behalf. For example, any forms, applications, messages, or other material may be processed by us for Clients, and all Personal Data processed on behalf of the Client may be available to the Client and its users. These parties may engage in direct marketing, or other activities that are outside our control.
Users: In some cases, information may be shared with other users, for example, in connection with our collaboration or messaging tools, or as part of Gather Applications (e.g. when users view pages, advertisements, or other pages/content on Gather, subject to applicable privacy options/controls).
Service Providers: In connection with our general business operations, product/service improvements, to enable certain features, and in connection with our other legitimate business interests, we may share your Personal Data with service providers or sub-processors who provide certain services or process data on our behalf.
Affiliates: In order to streamline certain business operations, develop products and services that better meet the interests and needs of our customers, and inform our customers about relevant products and services, we may share your Personal Data with any of our current or future affiliated entities, subsidiaries, and parent companies.
Corporate Events: Your Personal Data may be processed in the event that we go through a business transition, such as a merger, acquisition, liquidation, or sale of all or a portion of our assets. For example, Personal Data may be part of the assets transferred, or may be disclosed (subject to confidentiality restrictions) during the due diligence process for a potential transaction.
Legal Disclosures: In limited circumstances, we may, without notice or your consent, access and disclose your Personal Data, any communications sent or received by you, and any other information that we
YOUR RIGHTS & CHOICES
To the extent required under applicable law, and subject to our rights to limit or deny access/disclosure under applicable law, you have the following rights in your Personal Data. You may exercise your rights by contacting us at the address below.
Access: You may receive a list of your Personal Data that we process to the extent required and permitted by law.
Rectification: You may correct any Personal Data that we hold about you to the extent required and permitted by law. You may be able to make changes to much of the information you provided directly via the Service via your account settings menu.
Erasure: To the extent required by applicable law, you may request that we delete your Personal Data from our systems.
Data Export: To the extent required by applicable law, we will send you a copy of your Personal Data in a common portable format of our choice.
Direct Marketing: Residents of California (and others to the extent required by applicable law) may request a list of Personal Data we have disclosed about you to third parties for direct marketing purposes during the preceding calendar year. This request must be written, signed, and mailed to us.
Regulator Contact: You have the right to contact or file a complaint with regulators or supervisory authorities about our processing of Personal Data. To do so, please contact your local data protection or consumer protection authority.
We may require that you provide additional Personal Data to exercise these rights, e.g. information necessary to prove your identity.
It is possible for you to use some of our Services without providing any Personal Data, but you may not be able to access certain features or view certain content. You have the following choices regarding the Personal Data we process:
Consent: If you consent to processing, you may withdraw your consent at any time, to the extent required by law.
Direct Marketing: You have the choice to opt-out of or withdraw your consent to processing related to direct marketing communications. You may have a legal right not to receive such messages in certain circumstances, in which case, you will only receive direct marketing communications if you consent. You may exercise your choice via the links in our communications or by contacting us re: direct marketing.
Other Processing: You may have the right under applicable law to object to our processing of your Personal Data for certain purposes. You may do so by contacting us re: data rights requests. Note that we may not be required to cease processing based solely on an objection.
Note Regarding Clients’ Data
TraceGains is a processor of Personal Data in our Clients’ possession. We may notify Clients of your data rights requests; however, we may be unable to directly fulfill rights requests regarding Personal Data unless we control or have the necessary rights of access. TraceGains may not have access to or control over all or some Personal Data controlled by Clients. Please contact the Client directly for data rights requests regarding Client-controlled information, and we will assist the Client as appropriate in the fulfillment of your request. Please note that, to the extent we make interfaces available for you to directly control your data, these will take effect only with respect to the data on our Service, and Clients may have additional copies of this information that is outside of our control.
We follow and implement reasonable security measures to safeguard the Personal Data we process, however we do not warrant perfect security and we do not provide any guarantee that your Personal Data or any other information you provide us will remain secure. We sometimes share Personal Data with, or process data on behalf of third parties, as noted above. While we may require our service providers to follow certain security practices, we do not have control over and will not be liable for third parties’ security processes.
We retain Personal Data for so long as it remains relevant to its purpose, and in any event, for so long as is required by law. As we process Personal Data on behalf of Clients, we may retain information for the periods requested by the Client or delete information at the Client’s request. We will review retention periods periodically, and if appropriate, we may pseudonymize or anonymize data held for longer periods.
Our Services are intended for use by Clients and are neither directed at nor intended for direct use by individuals under the age of 16. Further, we do not knowingly collect Personal Data directly from such individuals. If we learn that we have inadvertently done so, we will promptly delete it. Do not access or use the Services if you are not of the age of majority in your jurisdiction unless you have the consent of your parent or guardian.
We operate and use service providers located in the United States. If you are located outside the U.S., your Personal Data may be transferred to the U.S. The U.S. does not provide the same legal protections guaranteed to Personal Data in the European Union. If you are in the EEA/Switzerland/UK, your Personal Data may be transferred to the U.S. on one of the following basews:
- Standard Contractual Clauses (e.g. Personal Data relating to our Client).
- Binding corporate rules (e.g. data processed by a subprocessor or other vendor under a BCR agreement).
- Pursuant to the derogations provided under applicable law (e.g. consent or necessity to provide the services, e.g. where users that access the system to provide information to Clients).
- Pursuant to other adequacy mechanisms (e.g. where transfers are within the EEA or to other justification subject to an adequacy decision).
If you would like additional information regarding the specific transfer mechanism applicable in the context of transfers of your personal data, please contact us.
Feel free to contact us with questions or concerns using the appropriate address below.
General Inquires: firstname.lastname@example.org
Physical Address: TraceGains, Inc.
10385 Westmoor Dr., Bldg. 5, Suite 200,
Westminster, CO 80021
LIST OF THIRD PARTIES
Unaffiliated Parties and Partners
The following is a list of unaffiliated third parties with whom we may share data, or which may engage in processing: Asana – receives data for internal project management
Avalara – receives data for tax compliance purposes Calendly – receives data for appointment scheduling
Conga – receives data for document drafting and management
Demandbase – receives data for customer insight, records management, and marketing DocuSign – receives data for document management
Dropbox – receives data for document storage
FileZilla – receives data for document transfer and storage Google Analytics – shares data with us for usage analytics GTR – shares and receives data regarding TGCon Live
Hive Digital Strategy – receives data to optimize our service and customer experience Hotjar – receives data to optimize our service and customer experience
Hubspot – receives data for customer records management and marketing InsideView – receives data for customer records management
MeetingOne Adobe Connect – receives data for hosted webinars and training sessions Microsoft – receives data for hosted services and through Office 365
NetSuite – receives data for customer invoicing
ON24 – receives data for hosted webinars and training sessions Owler – receives data for customer records management
Pendo – shares and receives data for usage analytics
Rocket Reach – receives data for customer records management Salesforce – receives data for customer records management
SalesLoft – received data for customer records management and marketing
Sales Navigator – receives data for customer records management, marketing, and sales Seamless.AI – receives data for customer records management
SEMrush – shares data with us for usage analytics
Sendoso – receives data for customer records management and marketing Sharekits – receives data for customer records management and marketing Sprout Social – shares data with us for engagement analytics
Survey Monkey – receives data for surveys
Thought Industries – receives data for online knowledgebase and support request management VisionE – receives data for location mapping
Wistia – receives data for video hosting, storage and viewing ZenDesk – receives data for support request management
Note that this list may not always reflect the most recent third-party sharing agreements and may be subject to change.