Privacy Policy

Cap Hill Brands, Inc. Privacy Policy

Effective Date: February 1, 2023

The website on which this Privacy Policy is posted (the “Site”) is provided by a member of the brands portfolio held by Cap Hill Brands, Inc. and its affiliates. Throughout this Privacy Policy (“Privacy Policy”), the terms “Cap HiIl Brands”, “CHB”, “our”, “us”, and/or “we” refer to Cap Hill Brands, Inc. along with the affiliate(s) and brand(s) identified on the “About Company” page. The terms “you” and/or “your” refer to any visitor of the Site.. 

We understand that you care about how your personal information is used and shared, and we take your privacy seriously. Please read the following to learn more about how we collect, use, and disclose information that we obtain from users of our Services (as defined below), and how we use and disclose that information. 

This Privacy Policy describes the personal information that we collect from you, how we use it, how we protect it, and the choices you can make about your personal information on our website. By using or accessing our Services (as defined below) in any manner, you acknowledge that you accept the practices and policies outlined in this Privacy Policy, and that we will collect, use, and share your information in the following ways. 

We’re constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time. Any changes to this Privacy Policy will be reflected in the "Effective Date” provided at the top of this Privacy Policy. We will alert you to material changes by placing a notice on this page, by sending you an email, and/or obtaining consent regarding such changes as may be required by law. By using the Services after any changes to the Privacy Policy have been posted, you agree to the new Privacy Policy.

Your use of this website is also subject to the Terms of Service, which incorporate this Privacy Policy by reference. Any terms we use in this Policy without defining them have the definitions given to them in the Terms of Service.

  • What Does This Privacy Policy Cover?

  • This Privacy Policy applies to the website on which it is posted, and all subdomains, other websites, applications, widgets, products, services, and other offerings (collectively, the “Services”) owned and operated by CHB (including its affiliates) that link to this Privacy Policy. This Privacy Policy covers our treatment of the personal information we gather through use of our Services.

    For purposes of data privacy law, Cap Hill Brands, Inc. (113 Cherry St, PMB 89249, Seattle, WA 98104) is the data controller of personal information collected in connection with use of the Services. CHB is also the “business” which determines the purposes for which your personal information is used for purposes of the California Consumer Privacy Act. This means that we are responsible for deciding how and why we hold and use your personal information. 

    Residents of California may have different rights and obligations available to them. For more information, please see the “Consumer Privacy Rights Under State Law” section below.

  • What Information do the Services Collect?

  • We collect personal information through your use of our Services, as explained in more detail below. The specific information that we collect from or about you depends on the context of your interactions with us and our Services, the choices you make, and the products and features you use. 

    We may combine the information we collect and use it in the manner described in this Privacy Policy. 

    Additionally, note that we use personal information to create de-identified, aggregated information such as: information about demographics, de-identified location information, information about devices used to access our Services, and de-identified, aggregate information on transactions on our Services that help our users understand and optimize sales. Statistical, anonymised, and aggregated information which we may derive from personal information (“Anonymous Data”) is excluded from the definition of personal information because it does not personally identify you. 

  • Information You Provide to Us:

  • We receive and store any information you provide to us. If you create an account or place an order with us, we may collect personal information depending on how you interact with our Services.

    1. Users

    When you register for an account to use our Services, we will collect identifying information including your first and last name, email address, phone number, and mailing address. If you are registering as a user of our Services for retail stores, we may also collect information such as the name and address of your store, years you have been in business, and related employment information.

    If you place an order to purchase goods through us, we will also collect information to facilitate that order, such as your shipping address, and payment information.

    In some cases, we may request additional information to validate your account, such as photos of your store or your social media profile. We may also request information such as your tax identifier or other government issued numbers or financial or lease records to establish your account limits.

    1. Using the Services

    When you browse and use our Services, we collect information about the items you browse, show interest in, and buy. 

    1. Communicating with Us

    We collect personal information from you when you communicate with us, for example, when you request information about our services, or contact our Support team or Sales team. 

    1. Forums and Social Media

    Our Services may provide forums, blogs, social media pages, or other channels where individuals may review purchases, talk about their experience using our Services, or “like” or “share” content to social media. Note that content provided for and posted in these channels, including by you, is public and the information you provide is subject to the policies and notices of the third parties that make such channels available.

  • Information Collected Automatically

  • Whenever you interact with our Services, we automatically receive and record information on our server logs from your browser or device, including your IP address, geolocation data, device identification, the type of browser and/or device you’re using to access our Services, and the page or feature you requested.

    Additionally, we, as well as third parties that provide content through the Services, advertising, or other functionality on our Services, may use cookies, pixel tags, local storage, and other technologies to collect information automatically through our Services.

    These technologies are small data files that we transfer to your browser or device that allows us to provide and enhance our Services. Most browsers and many devices allow you to change your preferences to prevent or limit acceptance of these technologies, but this may impact the functionality of our Services and/or prevent you from taking advantage of some of our features.

    Our use of information collected automatically falls into the following general categories:

    • Strictly Necessary: Technologies that allow you to access our Services and use our features, and tools that help us identify irregular site behavior and prevent fraudulent activity or improve security.
    • Functionality: Technologies that collect information about your use of our Services, including measuring, understanding, and reporting on your usage of the Services. We may use these cookies to measure the effectiveness of that content, including information about what content was shown, how often or how long it was shown, when and where it was shown, and what actions, if any, you took on the content.
    • Performance: Technologies that store information or provide access to information that is already stored on your device, such as your shopping cart and whether you have logged into our site previously.
  • Information Collected by Third Parties

  • We may use analytics service providers, including Google Analytics, to collect information regarding visitors to our Services, such as their behavior on our Services or information about their demographic. For more information about Google Analytics, see https://www.google.com/policies/privacy/partners/. To opt out of Google Analytics, visit https://tools.google.com/dlpage/gaoptout. We may also receive information about you from business partners such as Target. For more information about the types of information that may be shared with us, please see “Will the Services Share Any of the Personal Information Received?”

    Whenever we use information about visitors collected by third parties, we rely on our partners to ensure and document the appropriate legal basis for sharing your information with us, and any information that we collect about you for purposes of our Services will be subject to this Privacy Policy.  

  • Children’s Information

  • As noted in our Terms of Service, we do not knowingly collect nor solicit personal information from anyone under the age of 18. If you are under 18, please do not attempt to register for the Services or send any personal information about yourself to us. If we learn that we have collected personal information from a child under the age of 18, we will delete that information as quickly as possible. If you believe that a child under 18 may have provided us with personal information, please contact us as described below.

  • How Do the Services Use the Personal Information It Collects?

  • We use the information that we collect about you for various business purposes as described below, in each case as permitted by applicable laws. We store personal information for as long as you use our Services or as may be necessary to fulfill the purposes for which the information was collected, provide our Services, resolve disputes or establish legal defenses, enforce our Terms of Service or other agreements, engage in audits, protect our Services, prevent fraud, comply with the law, or for legitimate business purposes.

    Our business purposes include:

  • To provide you with our Services by:
    • Entering into a contract with you
    • Allowing you to set up a user account and profile
    • Fulfilling your requests for products and services (such as by shipping your orders to you, and e-mailing you regarding shipment confirmations or order cancellations)
    • Communicating with you about your account and updates to our Services
    • Determining your order or account limits and eligibility for certain service terms
    • Processing applications, transactions, and payments
  • For our legitimate interests, which include:
    • Analyzing how you use the Services
    • Understanding user interest and engagement on the Services
    • Engaging in marketing or sales outreach
    • Providing customized content, offers, or Services, including marketing content via email, postal mail, social media, SMS, or other channels, subject to applicable laws
    • Researching and developing our Services
    • Verifying your identity and preventing fraud
    • Detecting security incidents, or protecting against malicious, deceptive, fraudulent, or illegal activity
    • Ensuring quality control
    • Debugging to identify and repair errors
    • Enforcing our Terms of Service and policies
    • Audit or other compliance activities
  • To comply with our legal obligations
  • We retain and use your information in connection with potential legal claims, and for compliance, regulatory and auditing purposes. For example, we retain information where we are required by law, or if we are compelled to do so by a court order or regulatory body. Also, when you exercise any applicable legal rights you have to access, amend or delete your personal information, we may request identification and verification documents from you for the purpose of confirming your identity. In exceptional cases, we may further process your personal information to protect your vital interests or as further required for the public good.

  • Will the Services Share Any of the Personal Information Received?

  • We do not rent nor sell your personal information. We may share or disclose your personal information in an identifiable form as provided below.

    Target Plus Partner: This brand participates in the Target Plus program, which offers a select assortment of products from third-party sellers via the Target website. This means that Target will process your payment for items sold by us (in our capacity as a Target Plus Partner), and Target will handle any payment-related disputes, refunds, credits, and adjustments. When you choose to use the Services that we provide as a Target Plus partner, we may share your personal information with Target as part of our participation in the Target Plus Program. Personal information about you that is shared with Target will be subject to Target’s Privacy Policy. We will not use personal information received in connection with the Target platform to send marketing communications or to conduct surveys, contests or sweepstakes.

    Service Providers: We employ service providers to perform tasks on our behalf, and we need to share your information with them in order to provide products or services to you. For example, we may use a payment processing company to receive and process any credit card transactions for us. We may also use a software vendor to assist us in measuring the effectiveness of our advertising.

    Business Transfers: We may share your personal information with our affiliates and subsidiaries for the purposes described in this Privacy Policy. We may also choose to buy or sell our company assets, and may share and/or transfer customer information in connection with the evaluation of and entry into such transactions. Also, if we (or our assets) are acquired, or if we go out of business, enter bankruptcy, or go through some other change of control, personal information could be one of the assets transferred to or acquired by a third party.

    Protection of Company and Others: We reserve the right to access, read, preserve, and disclose any information that we reasonably believe is necessary to comply with law or court order; enforce or apply our Terms of Service and other agreements; or protect the rights, property, or safety of our company, our employees, our users, or others.

    When You Request That We Share Your Information: We may offer Services, features, or promotions that involve sharing your information with a third party or with other users of our Services. If you request or agree to have your information shared with a third party as part of a feature or Services, we will share that information at your request.

  • What Are My Privacy Rights and Choices?

  • Opt-Outs
  • You can always opt not to disclose information to us, but keep in mind some information may be needed to register with us, use our Services or to take advantage of some of our features.

    Opting Out of Communications: If  you no longer wish to receive electronic communications from us, please contact  us using the information provided in our "Contact Information” for guest inquiries link. Note you may still receive transactional emails from us. We process requests to be placed on do-not-mail and do-not-call lists as required by applicable law.

    Opting Out of Cookies: You may stop or restrict the placement of cookies on your device or remove them as your browser or device permits. 

    Updating Your Account Information: Through your account settings, you may access, and, in some cases, edit or delete the following information you have provided to us:

    • name
    • email address
    • location
    • payment information

    The information you can view, update, and delete may change as the Services change. If you have any questions about viewing or updating information we have on file about you, please contact us as described below.

    Subject to the requirements of applicable law, you may also have privacy rights under state privacy laws. Please see “Consumer Privacy Rights Under State Law” below.

  • Do-Not-Track
  • Our Services are set to honor and process certain commonly used “opt-out preference signals”, which are settings through which consumers can indicate that they have opted out of the sale and sharing of their personal information without sending an individual or manual request. 

    We recognize and honor the following opt-out preference signals: “Do Not Track” and Global Privacy Control. All such opt-out preference signals are processed in a frictionless manner (as that term is defined by the CCPA). To learn more about how to implement opt-out preference signals and/or Global Privacy Control, you should consult your browser’s privacy settings or visit the Global Privacy Control website.

    To implement an opt-out preference signal on your device or browser, you may download the appropriate browser that uses a recognized opt-out preference signal or a browser extension that can be enabled to support your single opt-out preference signal. 

    Note that our acknowledgment of opt-out preference signals are based on browser settings, not your device. If you use multiple devices, or if your browser settings do not carry over between devices, you may need to implement such opt-out preference signals across each of your devices and browsers to ensure that your preferences are properly recognized.

  • Security
  • We take commercially reasonable and appropriate measures to help us in protecting the personal information that we collect from unauthorized access, use, disclosure, alteration, or destruction. Unfortunately, no data transmission or storage system is guaranteed to be 100% secure. As such, we are unable to guarantee the security of your personal information. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time.

    You are advised to prevent unauthorized access to your personal information and other account details by selecting and protecting your password appropriately and limiting access to your computer or device and browser by signing off after you have finished accessing your account. You should use caution whenever submitting information online and take special care in deciding which information you provide.

  • Third-Party Websites
  • We may offer links to third-party websites or Services, which are not controlled by us and not subject to the protections laid out in this Privacy Policy. We do not endorse nor approve any third-party website and we encourage our users to read the privacy policy of each service with which they interact.

  • What State Privacy Laws Apply to the Services?

  • If you are located in the United States, you may have additional privacy rights under the law of the state in which you reside. 

  • Privacy Rights in Virginia and California
  • For further information relating to the Virginia Consumer Data Privacy Act or the California Consumer Privacy Act please contact us using the information provided in our "Contact Information” for guest inquiries link. 

  • What Are My Privacy Rights and Choices as a European Data Subject?

  • If you use the Services, are located in the European Union, and are subject to any one of (i) the General Data Protection Regulation, (ii) data protection laws implemented by member states of the EU in harmony with the General Data Protection Regulation,  or (iii) the U.K. Data Protection Act of 2018, as amended and incorporated into U.K. law (collectively, the “GDPR”), the following applies with respect to your rights to exercise control over your personal data. Under the GDPR, you are defined as a “Data Subject” and we are a “Data Controller” for any personal data that constitutes “Personal Data” under the GDPR that is processed under this Privacy Policy. 

    If you are not a Data Subject, the provisions in this Section 8 do not apply to you.

    Lawful Grounds for Processing Personal Data of Data Subjects

    We rely upon the following legal grounds to process Personal Data under the GDPR: 

    • If you have consented to the processing of Personal Data for one or more specific purposes.
    • If the processing is necessary for the performance of an agreement with you (including for any pre-contractual obligations thereof), for our compliance with a legal obligation to which we are subject, to protect your vital interests or of another natural person, or otherwise for our legitimate interests.
    • If the processing relates to a task that is carried out in the public interest or in the exercise of official authority, as permitted by law.

    Data Transfer Notice

    We use servers located in the United States to process your Personal Data. By using our Services, you acknowledge and agree that we are authorized to transfer your Personal Data for processing in the United States. Under the GDPR, the transfer of Personal Data to a country outside the EU may take place where the European Commission has determined that the country ensures an adequate level of protection. The transfer of your Personal Data to the United States in the absence of an adequacy decision by the European Commission is made because it is necessary for the performance of a contract with you, or with your explicit consent.

    Retention of Personal Data

    Pursuant to the GDPR, we will permanently erase your Personal Data at such time there is no lawful basis or legal obligation for us to store or process the Personal Data.

    Individual Rights and Data Subject Requests

    If you are a Data Subject and we process your Personal Data, you may exercise certain rights under the GDPR, which are described below. We will endeavor to respond to any requests within 30 days from receipt, but in some instances it may take longer. We will inform you within 30 days from receipt of your request if an extension is necessary and the reason for the delay. 

    To exercise your lawful rights as a Data Subject (enumerated below), please contact us as specified in Section 9, and provide specific and detailed information about your request necessary for us to respond to and carry out your request.

    • You may object to processing: You may object to certain types of processing, including processing for direct marketing (i.e. if you no longer want to be contacted with potential opportunities).
    • You may request to be informed about our processing: You may request information about how we process your Personal Data and request additional information about how to exercise your rights under the GDPR.
    • You may obtain access to your Personal Data: You may obtain access to your Personal Data that we process.
    • You may request rectification: If you believe any Personal Data that we process is incorrect or incomplete, you may request that we correct it.
    • You may request deletion of your Personal Data: Under certain conditions, you may request that we remove or delete your Personal Data. For example, if there is no legitimate reason for us to continue processing it. In accordance with applicable law, we may retain certain Personal Data to keep a record of our compliance with your request.
    • You may restrict our processing of your Personal Data: You may request that we cease further processing of your Personal Data. If you make such a request, we may continue to store your Personal Data but will not make further use of it.
    • You may withdraw consent: If we are relying on consent as the lawful grounds on which we process your Personal Data, you may withdraw your consent for such processing at any time without affecting the lawfulness of processing based upon your consent before it is withdrawn.

    In addition to the rights granted by applicable laws, you may submit a complaint about our processing of your Personal Data to your national data protection regulator.

  • How Can We Contact CHB?

  • If you have any questions or concerns regarding our privacy policies, you may contact us using the information provided in our “Contact Information for guest inquiries link.