Privacy Policy
Privacy Policy
Last updated: [March 31, 2024]
This Privacy Policy tells you about your privacy rights and sets out how Imprint Engine, Inc., including its affiliates and subsidiaries (collectively, “Imprint Engine” and also referred to as “our”, “us” and “we”) collects, uses and discloses personal data, as well as any choices you have with respect to this personal data. We collect, use, and disclose your personal information (or "personal data") when you visit, use, or make a purchase from miromerchshop.myshopify.com (the "Site") or otherwise communicate with us. For the purposes of this Privacy Policy, "you" and "your" means you as the visitor to the Site, whether you are a customer, solely a visitor, or another individual whose information we have collected pursuant to this Privacy Policy.
Our Site is intended to be used by adults. Imprint Engine does not knowingly collect personally identifiable information from children under 16 without permission from a parent or guardian. If you are a parent or legal guardian and think your child under 16 has given information to Imprint Engine, please contact the address set out in the Who we are and how to contact us? section below.
This privacy policy is designed to describe:
- What rights do you have?
Please read this privacy policy carefully. By continuing to use our site and by submitting personal data to us, you are agreeing to the terms of this privacy policy.
This Privacy Policy should be read in conjunction with our Cookie Policy.
We are Imprint Engine, Inc., and we are the merchant of record for this Site. This means that we sell you the goods that you purchase via the Site. We do this as part of an arrangement with RealtimeBoard, Inc. dba Miro, including its affiliates and subsidiaries (collectively, Miro) to manage their online shop. The Site is designed and managed by us, as are our products, using Miro's branding and in collaboration with Miro. We work closely with Miro to bring you the Site. We share your personal information with Miro to report on and enable Miro to review our administration of the Site, as well as to inform Miro's marketing and promotional activities.
For the purpose of applicable data protection laws (including the General Data Protection Regulation 2016/679/EU (the "EU GDPR") and the EU GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018 (the "UK GDPR")), Imprint Engine, Inc. is the data controller and is responsible for your personal data which may be processed via the Site (and if you are located in the European Economic Area ("EEA"), it does so jointly with Imprint Engine Limited established in Ireland).
Our corporate details are:
Imprint Engine Inc.
4001 Lake Breeze Avenue N
Suite 400
Brooklyn Center MN 55429
United States
Imprint Engine Limited
Unit 5 Keypoint Business Park
Rosemount Industrial Estate
Ballycoolin
Dublin 11
Ireland
Where personal data has been provided to us by Miro, we remain a processor on behalf of Miro, our customer, and we will not be the data controller in respect of such processing. Questions, comments, requests and complaints regarding this Privacy Policy and the personal data we hold are welcome. Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please call 1-800-696-1419 or email us at privacy@imprintengine.com. Alternatively, you may contact us in writing at Imprint Engine, Inc. 4001 Lake Breeze Avenue N, Suite 400, Brooklyn Center MN 55429, United States.
Miro’s Privacy Policy is available here.
All requests will be dealt with promptly and efficiently and in accordance with applicable data protection laws.
When we refer to personal data we are referring to any information that relates to an identified or identifiable living individual such as a name, ID number, location data or any online identifier. It does not include data where any potential identifiers have been removed (anonymous data) or data held in an unstructured file.
When you visit our Site, communicate with us, purchase goods from us, or enter into contests, we may collect and process the following information about you:
- Identity Data includes first name, last name, username or similar identifier and title.
- Contact Data includes billing address, delivery address, email address and telephone numbers.
- Financial Data includes bank account and payment card details.
- Transaction Data includes details about payments to and from you and other details of goods you have purchased from us, as well as your credit history.
- Technical Data includes mobile device ID, internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our website.
- Profile Data includes your username and password, purchases or orders made by you.
- Usage Data includes information about how you use our website (including the date, time and duration for which you visit our Site).
In operating our Site, we may receive personal data directly and indirectly, including from publicly accessible sources and from third parties, such as from vendors and service providers who may collect information on our behalf. For example:
- We may receive information about you directly from Miro if you are an employee of Miro.
- Companies who support our Site and business operations, such as Shopify, Stripe, Google Workspace & Slack, Fedex, DHL, USPS, UPS, ShipStation and QuickBooks.
- Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders so that we can provide you with products or services you have requested, in order to perform our contract with you.
- When you visit our Site, open or click on emails we send you, or interact with us or advertisements, we, or third parties we work with, may automatically collect certain information about your interaction with the Site ("Usage Data"). To do this we may use online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies. Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Site. Please refer to our Cookie Policy available here for further details.
Any information we obtain from third parties will be treated in accordance with this Privacy Policy. We are not responsible or liable for the accuracy of the information provided to us by third parties and are not responsible for any third party's policies or practices.
We will only use your personal data for the purposes and legal bases set out in the table below:
Purpose/Activity |
Type of Personal Data |
Lawful basis of processing (as applicable in the EEA and/or UK) |
To provide our services, and manage our relationship with you as our customer, including:
|
|
|
To operate our Site through the deployment of strictly necessary cookies |
|
To support our legitimate Interests in operating our Site. |
To process payments in relation to an order placed |
|
To fulfill our obligations to you under our contract with you |
Security and Fraud Prevention To detect, investigate or take action regarding possible fraudulent, illegal or malicious activity, money laundering and other crimes or for the purpose of responding to a binding request from a public authority or court . To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data). To establish, exercise or defend legal claims. |
|
To comply with our legal obligations under the law. |
What happens if you fail to provide us with the necessary personal data?
Some features of the Site may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.
If you do not provide us with personal data we request, we may not be able to provide you with our services or respond to any questions or requests you submit to us via our Site, by telephone, email or in writing.
We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
In some circumstances, you can ask us to delete your data. Please see your legal rights below for further information.
In some circumstances, we will anonymize your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
Imprint Engine will share information with its employees who need to know such information for purposes of performing their jobs, including to respond to requests or questions that you may have.
When we disclose your personal data to third parties, we only disclose to them any personal data that is necessary for them to provide their service and where we are sure that they have adequate policies/procedures in place in relation to data security. We have contracts in place with these third parties in receipt of your personal data requiring them to keep your personal data secure and not to use it other than in accordance with our specific instructions.
We may disclose your personal data:
- To Miro, as part of our day-to-day reporting on the functioning of the Site and Miro's online shop. We will share with Miro personal information about you and the products you purchase and return to us, as well as comments and queries you submit to us about the Site or the products available on the Site. Miro will also collect some personal information about how you access and use the Site through cookies, analytics tools and similar technologies. This information may include information about your device and the pages you view on the Site, as described further in the section above titled How is your personal data collected?
- To vendors or other third parties who perform services on our behalf (e.g., internet service provision, IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping). The following third parties provide services to us: Shopify, Stripe, Google Workspace & Slack, Fedex, DHL, USPS, UPS, ShipStation and QuickBooks.
- To our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders so that we can provide you with products or services you have requested, in order to perform our contract with you.
- To a third party if we are under a duty to disclose or share your personal data in order to comply with any legal obligation or court order.
- To third parties when you direct, request us or otherwise consent to our disclosure of certain information to such third parties, such as through your use of login integrations where you have provided your consent.
- In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend our business, our rights, and the rights of our users or others.
User-Generated Content
Our Site may enable you to post product reviews and other user-generated content. If you choose to submit user generated content to any public area of the Site, this content will be public and accessible by anyone.
We do not control who will have access to the information that you choose to make available to others, and cannot ensure that parties who have access to such information will respect your privacy or keep it secure. We are not responsible for the privacy or security of any information that you make publicly available, or for the accuracy, use or misuse of any information that you disclose or receive from third parties.
Links to Other Websites
Our Site may, from time to time, contain links to and from other websites or online platforms operated by third parties. If you follow a link to any of those websites not affiliated or controlled by us, please note that those websites have their own privacy and security policies, and we do not accept any responsibility or liability for those policies. Please check those policies and other terms and conditions before you submit any personal data to those websites. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Site and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Site.
We are committed to protecting the security of your personal data. We use a variety of technologies and procedures to help protect your personal data from unauthorized access and use. As effective as modern security practices are, no physical or electronic security system is entirely secure. We cannot guarantee the complete security of our database, nor can we guarantee that information you supply will not be intercepted while being transmitted to us over the internet. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us. Any transmission of personal data is at your own risk. We have implemented strict internal guidelines to ensure that your privacy is safeguarded at every level of our organization. We will continue to revise policies and implement additional security features as new technologies become available.
Upon request, we will provide you with details regarding your personal data that has been collected by us or which is under our control. If you would like to change information that we maintain about you, you may log into your account and change it or submit a support request for any information to which you don’t have access or the ability to change yourself. Information covered by this Privacy Policy may be deleted upon your request, provided that such deletion may impact our ability to provide you with the Services. You may also request that we update or correct your personal data by submitting a Data Privacy Request form through our website. We will respond to your request within a reasonable timeframe. You may opt-out of receiving most e-mails from us by following the “unsubscribe” instructions provided in the e-mails. Alternatively, you may contact us using the details in the Who we are and how to contact us section above. If you are our customer, you may not be able to opt out of all emails, including certain administrative or billing communications which are important to the ongoing maintenance of your account.
Where applicable law allows for such a right, if you want to request access, correct, object to the use, or delete the personal data that you have previously provided us, you may submit a request through our website by filling out the Data Request Form. We will respond to your request in compliance with applicable law.
For your protection, we may only implement requests with respect to the personal data associated with the email address that you use to send us your request, and we will need to verify your identity before implementing your request. We will verify the requestor’s identity via email using a unique identifier code.
We will encrypt any personal data sent to the data subject requestor to protect their personal identifiable information. We will send all user data in Excel format.
- Additional Information for California Residents
If you are a resident of the State of California, this Section addresses your rights and our obligations under the California Consumer Privacy Act of 2018 as modified by the California Privacy Rights Act (“CPRA”) of 2020 (“CCPA”). Terms used in this Section have the same meaning as provided in the CCPA, including the “Business Purpose(s)”, “Personal Information”, “Share”, “Sell” (or “Sale”), “Service Provider(s)” These term references and disclosures are limited to this section of the Privacy Policy and designated exclusively for California Consumers.
Information We Collect
Our Site collects information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device (“Personal Information”). In particular, our Site has collected the following categories of personal information from visitors within the last 12 months:
Category: Identifiers. Examples: A real name, IP address, email address, account name, or other similar identifiers.
Category: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Examples: A name, address, telephone number, and (if you are applying for a job) your current employment and employment history.
Category: Internet or other similar network activity. Examples: Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement.
Category: Geolocation data. Examples: Physical location or movements.
Personal Information does not include:
- Publicly available information from government records.
- De-identified or aggregated consumer information.
- Information excluded from the CCPA’s scope.
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from you. For example, from forms you complete on our Website.
Use of Personal Information
We may use, or disclose the personal information we collect for one or more of the following Business Purposes:
-
To fulfill or meet the reason you provided the information. For example, if you share your name and contact information to request a price quote or ask a question about our products or services, we will use that personal information to respond to your inquiry. If you provide your personal information to purchase a product or service, we will use that information to process your payment and facilitate delivery. We may also save your
information to facilitate new product orders or process returns. - To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to you when collecting your personal information or as otherwise set forth in the CCPA.
- We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Sharing Personal Information
We disclose all the above categories of personal information to our third-party service providers subject, in each case, to a written contract that describes the business purpose of the disclosure and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the specific agreed-upon contractual obligations as directed to them as our service providers by us as the business. .
Sales of Personal Information
Neither we nor our third-party service providers will sell your personal information.
Access to Specific Information and Data Portability Rights
You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we verify your consumer request, we will provide:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting or selling that personal information.
- The categories of third parties with whom we share that personal information.
- The specific pieces of personal information we collected about you (also called a data portability request).
- The categories of personal information we sold to the purchaser, and the categories of recipients.
- The categories of personal information we disclosed for a business purpose, and the categories of recipients.
Deletion Request Rights
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies. We may deny your deletion request if retaining the information
is necessary for us or our service provider(s) to:
- Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
Exercising Access, Data Portability, and Deletion Rights
To exercise the access, data portability, and deletion rights described above, you may submit a Data Privacy Request form through our website. Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf,
may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child. You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
-
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. We will
only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
Response Timing and Format
We endeavor to respond to a verifiable consumer request within 45 days of its receipt. If we require more time, we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding our receipt of your request. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily usable and should allow you to transmit the information from one entity to another entity without hindrance, specifically by electronic mail communication. We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny you goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of goods or services.
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
- However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your personal information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time. California’s “Shine the Light” law (Civil Code Section § 1798.83) permits users of our Website that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send us an electronic message through our website or write to us at our address listed on our webpage.
- Additional Information for EEA and/or UK Residents
GDPR/UK GDPR Rights
If you are located in the EEA and/or the UK, you have certain rights under data protection legislation as summarized below:
- Right of access: You have the right to obtain from us confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, to request access to the personal data, as well as certain information on how we are processing such data.
- Right to rectification: You have the right to obtain from us the rectification of inaccurate personal data concerning you. Considering the purpose of the processing, you may also, in some cases, be entitled to supplemental information regarding incomplete personal data.
- Right to erasure (right to be forgotten): You may, in certain circumstances, have your personal data deleted, for example if your personal data is no longer necessary in relation to the purpose for which it was collected, if you have objected to the processing of personal data and we do not have a legitimate interest which outweighs your interest, if the personal data has been processed unlawfully, or if the personal data must be deleted to comply with a legal obligation.
- Right to restriction of processing: You may require that we restrict the processing of your personal data in certain cases, for example where we no longer need your personal data but you need it to determine, enforce or defend legal claims or you have objected to processing based on our legitimate interest in order to enable us to check if our interest overrides your interest.
- Right to data portability: In some circumstances, you may be entitled to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format and you have the right to transmit those personal data to another controller, or to request us to transmit those personal data to that other controller without hindrance.
- Right to object: You have the right to object to the processing of your personal data in certain circumstances, for example where the processing is based on our legitimate interest (or that of a third party). If so, in order to continue processing, we must be able to show compelling legitimate grounds that override your interests, rights and freedoms.
- Right to withdraw consent at any time where we are relying on consent to process your personal data by contacting us using the information contained in the Who we are and how to contact us section above. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
We would welcome addressing any concerns you may have about our handling of your personal data; however, you have the right to lodge a complaint with the supervisory authority in the Member State of your residence, place of work or place of an alleged infringement, if you consider that the processing of your personal data infringes the GDPR. For example, in Ireland, this is the Data Protection Commission and in the UK, this is the Information Commissioner’s Office.
Your rights will in each case be subject to the restrictions set out in applicable data protection laws. Further information on these rights, and the circumstances in which they may arise in connection with our processing of your personal data, can be obtained by contacting us using the details contained in the Who we are and how to contact us section above. If you want to review, verify, correct or request erasure of your personal data, object to the processing of your personal data, request that we transfer a copy of your personal data to another party, or withdraw your consent, please contact us using the details in the Who we are and how to contact us section above. We will respond to your request within one month. That period may be extended by two further months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of your request. We may require proof of identification to verify your request. We have the right to refuse your request where there is a basis to do so in law, or if it is manifestly unfounded or excessive.
In accordance with applicable laws, you may designate an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorised them to act on your behalf, and we may need you to verify your identity directly with us.
International Transfers
We may transfer the personal information we collect about you for the purposes described in this Privacy Policy to countries that have not been found to provide an adequate level of data protection by the European Commission or the UK government.
To the extent that it is necessary to transfer personal data outside of the EEA and/or UK, we will ensure appropriate safeguards are in place to protect the privacy and integrity of such personal data, including by entering into standard contractual clauses under Article 46(2) of the GDPR/UK GDPR with the recipient or by relying on an adequacy decision under Article 45 of the GDPR/UK GDPR. Please contact us if you wish to obtain information concerning such safeguards or obtain a copy of the standard contractual clauses we use (see Who we are and how to contact us section above).
- Changes to this privacy policy and your duty to inform us of changes
We reserve the right to change this Privacy Policy from time to time at our sole discretion. Laws, regulations, and industry standards evolve, which may make those changes necessary, or we may make changes to our services or business. If we make any changes, we will post those changes here and update the “Last Updated” date at the top of this Privacy Policy so we encourage you to review our Privacy Policy to stay informed. However, if we make material changes to this Privacy Policy, we will notify you by means of a prominent notice on the Site prior to the change becoming effective. If you disagree with the changes to this Privacy Policy, you should deactivate your account. By continuing to use our website you are agreeing to any updates that we may make.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.