We may collect information submitted by users, information received on the basis of users’ visits to, interactions with, and activities on our Site, and other information provided by third-party vendors. We may use various technologies (e.g., cookies) on our Site to collect information about your device and about your activities on our Site, including which pages of our Site that you visit.
Data Collected through User SubmissionsWe collect and store information that you submit to us, including via registration or purchase activities. If you identify yourself by sending us an email, we collect and store your email address and any other information you provide in your email. As described in more detail in the “Use of Collected Data” section below, we use this information for our operational and commercial purposes, including to contact you and/or send you information, including marketing information, about our products.
While using our Site, we may ask you to provide us with certain information that can be used to contact, identify, or locate you. Such information includes, but is not limited to:
- Email address
- First name and last name
- Phone number
- Address, City, State, Province, ZIP/Postal code, Country
Data Collected through User Visits, Interactions, and Activities
A cookie is a small alphanumeric text file sent by a web server and placed on your computer by your web browser. Cookies can be divided into two different types: session and persistent. Session cookies are typically deleted when you close your browser. Persistent cookies, in contrast, remain stored on your computer after you close your browser until they are deleted either because they expire or you delete them.
The types of cookies we use are:
- Session Cookies. We use session cookies to operate our Site, for security purposes, and to customize our users’ experiences.
- Persistent Cookies. We use persistent cookies to remember your preferences and other information, including products you may be interested in, and various settings, and to customize our users’ experience
None of these cookies is strictly necessary to access our Site. You may set your browser to refuse all cookies or to indicate when a cookie is being set. However, if you do not accept cookies, parts of our Site may function differently and you may not be able to use some portions or features of our Site. For more information about how to manage your cookies and your cookie preferences, please use the “help” menu of your web browser or explore the customer support sections of your web browser. To “opt out” of Tailored Advertising, please see the “Your Choices: Opt-Out/Right to Withdraw Consent” section below.
We also collect certain additional passive tracking data concerning your device and how you access and use our Site ("Usage Data"). This Usage Data includes information such as your computer's Internet Protocol ("IP") address, browser type, and browser version, as well as the pages of our Site that you visit, the times and dates of your visits, the time spent on, and interactions with, those pages, location data, and diagnostic data. You can enable or disable location services when you use our Site at any time, through your device settings.
We may use third-party technology providers to monitor and analyze the use of our Site. This includes Google Analytics - for more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: http://www.google.com/intl/en/policies/privacy/.
Unsubscribe/Right to Withdraw Consent
If you do not want us to contact you or send you information by email, postal mail and/or telephone, or if you would like to change any of the information that you have previously provided to us, please let us know by emailing us at firstname.lastname@example.org. You may also unsubscribe from receiving our newsletters, marketing and promotional materials by following the unsubscribe link in our marketing and promotional emails or the instructions provided in any other communication we send.
Opt-Out/Right to Withdraw Consent
You may refuse or remove persistent targeting cookies by “opting out” of “interest-based advertising”/ “online behavioral advertising”/Tailored Advertising via third-party advertising cookies at the following sites:
- youronlinechoices.com(by clicking the “Your ad choices” link after selecting the appropriate country)
You may also “opt out” of “interest-based advertising”/“online behavioral advertising”/Tailored Advertising in mobile application environments via the privacy settings on your mobile device, including by selecting “Limit Ad Tracking” in such privacy settings. Selecting such setting will result in the elimination of Tailored Advertising via the applicable mobile advertising ID (e.g., Apple IDFA or Google Advertising ID) on that mobile device.
In addition, you may opt-out of Matched Ads via your email address by following the unsubscribe link in our marketing and promotional emails or by emailing us at email@example.com.
Please note that there may be a slight delay between your unsubscribe and/or Matched Ads email opt-out elections and the processing of such elections. Please also note that we are not responsible for third parties’ failure to comply with opt-out instructions.
Use of Collected Data
We use the information we collect for our operational and commercial purposes, including:
- Product, Service, and Contract Fulfillment (including to manage, perform, and administer our contracts)
- Customer Support (including to manage and administer our relationships with our customers and potential customers, and to maintain and improve the experiences of our customers and potential customers)
- Quality Assurance and Supply Chain Management (including to assist in buying decisions)
- Site Performance and Administration (including to measure the number of visitors to different sections and pages of our Site, to determine how best to enhance the usability and performance of our Site, and to detect and prevent fraud)
- Marketing and Advertising (to send marketing information about our products and services to consumers, and to engage in advertising, including Tailored Advertising)
- Other Communications with Customers
- Internal Financial, Employment, and Administrative Purposes
- Compliance with Legal/Regulatory Obligations
Bombas will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Site, or we are legally obligated to retain this data for longer time periods.
Transfer of Data
Your information, including personal data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction, in jurisdictions where the data protection laws may differ than those from your jurisdiction.
If you are located outside of the United States and provide information to us, please note that such information, including personal data, may be sent to, and processed in, the United States and/or other countries. By providing us with your personal data, you consent to such transfers to and subsequent processing in such countries (including the United States), which your country may not consider to provide for adequate privacy protections. You may withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
Sharing and Disclosure of Data
We may share your information with our authorized service providers that perform certain services on our behalf. These services may include fulfilling orders, processing payments, providing customer service and marketing assistance, performing business and sales analysis, supporting our Site functionality and supporting other features offered through our Site, and providing advertising and marketing services (including delivering Tailored Advertising and email marketing campaigns, and analyzing and improving the effectiveness of our advertising and marketing). These service providers may have access to personal information needed to perform their functions and are generally not permitted to share or use non-aggregated personal information for any other purposes. We may also share your personal information with Bombas affiliates. In addition, unless you are a California or EEA consumer, we may share your personal information with third-party data resellers in connection with our use of their data cooperative and data enrichment, verification, and analytics services.
Disclosure for Law Enforcement or Legal Requirements
Under certain circumstances, Bombas may be required to disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).
Bombas will disclose your information in the good faith belief that such action is necessary to:
- To comply with a legal obligation
- To protect and defend the rights or property of Bombas
- To prevent or investigate possible wrongdoing in connection with our Site
- To protect the personal safety of users of our Site or the public
- To protect against legal liability
"Do Not Track" Signals
We do not support browser “Do Not Track” (DNT) signals, and do not change any of our data collection or use practices when we receive such signals. Do Not Track is a preference you can set in your web browser. We will continue to evaluate potential responses to “Do Not Track” signals in light of industry developments or legal changes.
We are committed to honoring your privacy choices. For more information, please see the “Your Choices” section above.
Your California Privacy Rights under the California Consumer Privacy Act (CCPA)
If you are an individual who is a resident of California (a California “consumer”), you have the following rights under the California Consumer Privacy Act, which went into effect on January 1, 2020, with respect to your “personal information” (as defined by CCPA):
- Right to Know. You have the right to request that we disclose to you, following your “verifiable consumer request”:
- The categories of personal information we have collected about you
- The categories of sources from which the personal information is collected
- The business or commercial purpose for collecting personal information
- The categories of third parties with which we share personal information
- The specific pieces of personal information we have collected about you
- The categories of personal information about you that we disclosed for a business purpose
- If we sell your personal information (to our knowledge, we do not sell personal information of California consumers – see below in this section under the heading “Disclosure of Personal Information”):
- The categories of personal information that we sold about you
- The categories of third parties to which your personal information was sold, by category or categories of personal information for each category of third parties to which the personal information was sold
- The business or commercial purpose for selling personal information
- Right to Delete. You have the right to request that we delete, following your “verifiable consumer request”, the specific pieces of personal information we have collected about you.
- Categories of personal information we collect
- Specific pieces of personal information we have collected about you
- Categories of sources from which we collect personal information
- Right to Non-Discrimination. We may not discriminate against you because you exercise any of your rights under CCPA, including by:
- Denying goods or services to you
- Charging you different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties
- Providing a different level or quality of goods or services to you
- Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services
Methods of Submitting Requests
If you are a California consumer, you may submit requests to exercise your “right to know” or your “right to delete” via either of the following methods:
- By email, to: CAprivacy@bombas.com
- By toll-free telephone, to: 1-844-944-0093
If you are a California consumer, you may use an “authorized agent” (as defined by CCPA) to submit requests to exercise your “right to know” and/or your “right to delete” on your behalf. Your authorized agent will need to provide us with a copy of a written permission that is signed by you and indicates that you have provided such authorization.
CCPA Personal Information
We collect (and during the last 12 months have collected) the following categories of personal information, from the following categories of sources, and for the following business or commercial purposes:
|Categories of Personal Information||Categories of Sources||Business/Commercial Purposes|
|Characteristics of protected classifications under California or federal law (such as gender and age)||We receive such information from third-party vendors, including vendors that perform analytics and Tailored Advertising services for us and third-party data providers||For our operational and commercial purposes, including to engage in Tailored Advertising|
|Commercial information (such as records of the products a consumer purchased)||We receive such information directly from consumers (based on the purchase activities of those consumers on our Site) and/or from third-party vendors (such as third-party data providers)||For our operational and commercial purposes, including to manage, perform, and administer our contracts and relationships with consumers, to engage in Tailored Advertising, and to manage our supply chain (including with respect to buying decisions)|
|Geolocation data||We receive such information directly from consumers (such as when they complete a purchase on our Site) or from third-party vendors (such as third-party data providers)||For our operational and commercial purposes, including to manage, perform, and administer our contracts and relationships with consumers, to contact consumers and/or to send information (including marketing information about our products) to consumers|
|Inferences (drawn from any of the other categories of personal information of the information to create a profile about a consumer reflecting, for example, a consumer’s product preferences)||We receive such information from third-party vendors, including vendors that perform analytics and remarketing services for us||For our operational and commercial purposes, including to engage in Tailored Advertising|
Disclosure of Personal Information
We disclose (and during the last 12 months have disclosed) each of the above categories of personal information for a business purpose with our authorized service providers that perform certain services on our behalf, including fulfillment, shipping, and handling providers, payment service providers, data analytics providers, technology service providers, and advertising and marketing service providers and platforms. These services may include fulfilling orders, processing credit card payments, providing customer service and marketing assistance, performing business and sales analysis, supporting our Site functionality and supporting other features offered through our Site, and providing advertising and marketing services (including delivering Tailored Advertising and email marketing campaigns, and analyzing and improving the effectiveness of our advertising and marketing).
To our knowledge, we do not sell personal information of California consumers. Prior to January 1, 2020 (including during the 12 months prior to January 1, 2020), we shared the personal information (in particular, identifiers, characteristics of protected classifications under California or federal law, commercial information, Internet or other electronic network activity information, and geolocation data) of California consumers with third-party data resellers in connection with our use of their data cooperative and data provision, enrichment, verification, and analytics services, but we ceased that sharing practice with respect to California consumers prior to January 1, 2020.
Your California Privacy Rights under “Shine the Light”
For more information, please email us at CAprivacy@bombas.com, with “California Shine the Light Privacy Request” in the subject line, and your full name, email address, postal address and specific services you have used in the body of your email.
EU General Data Protection Regulation (GDPR)
|Purpose||Legal Basis(es), if and to the extent applicable in the EEA (with respect to “personal data” of EEA data subjects)|
|To respond to requests and questions, including about our products||Such responses may be necessary to manage and perform our contracts (including our Terms and Conditions) with the applicable data subject or to take steps at the request of the data subject prior to entering into a contract In addition, we have a legitimate interest in managing our relationships with our customers and potential customers and to ensure that we are effective and efficient as we can be and that we optimize the experience and satisfaction of our customers|
|To provide customer support||Such support may be necessary to manage and perform our contracts (including our Terms and Conditions) with the applicable data subject or to take steps at the request of the data subject prior to entering into a contract In addition, we have a legitimate interest in providing customer support and in optimizing the experience and satisfaction of our customers|
|To provide goods and services to our customers, and otherwise to perform our contracts with our customers||To manage and perform our contracts (including our Terms and Conditions) with the applicable data subject|
|To provide, maintain, administer, improve and customize our Site||We have a legitimate interest in maintaining and improving the quality and efficiency of the products and services offered to our customers and potential customers, and in optimizing the experience and satisfaction of our customers|
|The day-to-day running and management of our business and the products and services offered to customers||We have a legitimate interest in managing our business, including for operational purposes, such as supply chain management (including with respect to buying decisions) and financial, employment, and administrative decision-making|
|For fraud prevention and detection and other security purposes||We have a legitimate interest in preventing and detecting fraud, especially in connection with our Site and our products and services|
|In response to diligence investigation inquiries by third parties that are evaluating the prospect of acquiring all or part of our business, assets, or shares, or that succeed us in carrying on our business.||We have a legitimate interest in managing our business, including for operational, financial, employment, and administrative purposes|
|To enforce or defend our rights||To manage and perform our contracts (including our Terms and Conditions) with the applicable data subject and, if applicable, to comply with our legal or regulatory obligations|
|To investigate, manage, and resolve complaints and claims||To manage and perform our contracts (including our Terms and Conditions) with the applicable data subject and, if applicable, to comply with our legal or regulatory obligations|
|To investigate, manage, and resolve regulatory matters, investigations, and claims||To comply with our legal or regulatory obligations|
|To share data with police, law enforcement, tax authorities or other government agencies where we have a legal obligation and to comply with applicable laws, regulations or codes of practice||To comply with our legal or regulatory obligations|
|To allow you to participate in interactive features of our Site when you choose to do so||With your consent, if required by applicable law|
|For marketing and advertising, including Tailored Advertising||With your consent, if required by applicable law. If you no longer wish to consent to Tailored Advertising, you can withdraw your consent at any time (please see the “Your Choices: Opt-Out/Right to Withdraw Consent” section above). If you wish to stop receiving marketing communications from us, you can unsubscribe by following the unsubscribe link in our marketing and promotional emails or the instructions provided in any other communication we send|
Your Rights under GDPR
If you are an EEA data subject and certain requirements are fulfilled, you have the following data protection rights under GDPR:
- Right of Rectification. You have the right to have your personal data rectified if that information is inaccurate or incomplete.
- Right to Object. You have the right to object to our processing of your personal data carried out for our legitimate reasons and/or for direct marketing, including profiling that is related to such direct marketing.
- Right of Restriction. You have the right to request that we restrict the processing of your personal data (i.e., we would need to secure and retain the personal data for your benefit but not otherwise use it).
- Right to Data Portability. You have the right to be provided with a copy of your personal data in a structured, machine-readable and commonly used format (or have this transferred to a third party).
- Right to Withdraw Consent. You also have the right to withdraw your consent at any time where Bombas relied on your consent to process your personal data.
You also have the right to complain to a data protection authority about our collection and use of your personal data. We would, however, appreciate the opportunity to address your concerns before you approach a data protection authority, and would welcome you directing an inquiry first to us at: firstname.lastname@example.org.
Links to Third-Party Websites and Third-Party Features
- Liking, Sharing, and Logging-In. We may embed a pixel or other technology on our Site that allows you to “like” or “share” content on, or log in to your Bombas account through, third-party services, including social networks such as Facebook. If you choose to engage with such a third-party service through our Site, we may collect any information you have authorized the third-party service to share with us (such as your user ID, billing information, public profile information, email address, birthday, friends list, and other account and profile data). Likewise, if you choose to engage with such a third-party service through our Site or visit our Site while logged in to that third-party service on your device or through our Site, the third party may receive information about your activities on our Site and be able to associate that information with information the third party already has about you.
Our Site is not intended for children, and we do not sell products for purchase by children. We sell children's products for purchase by adults. If you are under 18, you may use our Services only with the involvement and permission of a parent or guardian. We do not knowingly collect personal information from children under the age of 13 without the consent of the child’s parent or guardian. If you are a parent or guardian and you believe that your child has provided us with personal information, please contact us. (Please see the “Contact Us” section below.) If we become aware that we have collected personal information from children without verification of parental consent, we will take steps to remove that personal information from our servers.