PRIVACY POLICY

This Privacy Policy describes how XTRACT BV, a company incorporated under Belgian law, having its registered office at Stoofstraat 9, 2000 Antwerpen, Belgium and registered with the Crossroads Bank for Enterprises (Kruispuntbank van Ondernemingen or KBO) under enterprise number 0792.479.310 (“XTRACT”, “We” or “Our”) collects, uses, and discloses Personal Data of the data subject (“You” or “Your”) when you visit or make a purchase from our website getxtract.co (the “Site”). We value your right to privacy and make every effort to protect your personal data in accordance with applicable data protection law, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and national implementing legislation.

 

All capitalized terms used but not otherwise defined herein shall have the meanings ascribed to them in the GDPR. 

 

CONTACT

 

After reviewing this policy, if you have additional questions, want more information about our privacy practices, or would like to make a complaint, please contact us by e-mail at hello@getxtract.co or by mail using the details provided below:

 

Stoofstraat 9, 2000 Antwerpen, Belgium

 

PROCESSING PERSONAL DATA

 

When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. See the list below for more information about what Personal Data we collect and why.

 

PROCESSING PURPOSES

PERSONAL DATA

LAWFUL BASIS

SHARED WITH THIRD PARTIES

1

To provide products or services to you to fulfill our contract, including but not limited to processing your payment information, shipping arrangements, sending invoices and/or order confirmations

name, billing address, shipping address, payment information (including credit card numbers, debit card numbers and PayPal information), email address, and phone number

Necessary for the performance of a contract (art. 6.1. (b) GDPR)

Shopify, Huboo and other fulfilment partners

2

Communicate with you, provide you information

Necessary for the purposes of our legitimate interests (art. 6.1. (f) GDPR), namely to provide you with updates and further information about our services.

/

3

To screen our orders for potential risk or fraud

Necessary for the purposes of our legitimate interests (art. 6.1. (f) GDPR), namely to prevent fraud and other unauthorized or illegal activities

/

4

To provide customer support

name, billing address, shipping address, payment information (including credit card numbers, debit card numbers and PayPal information), email address, and phone number

Necessary for the performance of a contract (art. 6.1. (b) GDPR)

Meta, Shopify, Huboo and Google (Gmail)

5

To perform analytics on Site usage to optimize our Site and to load the Site accurately for you

Version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site

the explicit, prior, free, specific and informed consent from the data subject

Shopify and other third-party vendors.

6

Promoting and informing existing customers and subscribers about similar products and services through electronic communications, such as sending information about new products and features, survey requests, newsletters and events via email

Email address

the necessity for the purposes of our legitimate interests (art. 6.1. (f) GDPR), namely to promote our products and services

/

7

Promoting and informing legal entities through electronic communications directed at a non-personal email address, e.g., info@ or sales@ (B2B communications).

Email address

the necessity for the purposes of our legitimate interests (art. 6.1., (f) GDPR), namely to promote our products and services

/

8

Promoting and marketing the Platform through electronic communication, which does not fall under the situation of (6) or (7), for example to prospects.

Email address

The explicit, prior, free, specific and informed consent from the data subject 

/

9

To comply with applicable laws, respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights

Data necessary to comply with the request

Necessary for compliance with a legal obligation (art. 6.1., (c) GDPR)

Judicial and law enforcement authorities 

10

Creating an account on one of our programs (such as loyalty program)

Name, surname, e-mail, password 

Necessary for the performance of a contract (art. 6.1. (b) GDPR)

/

11

Refer a friend program

Email address, full name, email address of friend

the necessity for the purposes of our legitimate interests (art. 6.1., (f) GDPR), namely to promote and offer our products and services

/

12

Maintaining your account

Account information, your use of the relevant portal and/or services pertaining to the portal

Necessary for the performance of a contract (art. 6.1. (b) GDPR)

/

13

Facilitating customer reviews

Name

the necessity for the purposes of our legitimate interests (art. 6.1., (f) GDPR), namely to improve our products and services

Trustpilot, Shopify reviews

 

SHARING PERSONAL DATA

 

We share your Personal Data with service providers to help us provide our services and fulfill our contracts with you, as described above. For example:

 

We use Shopify to power our online store. You can read more about how Shopify uses your Personal Data here: https://www.shopify.com/legal/privacy.

 

Other providers are: Webflow, Huboo, Google Analytics, Meta

 

Your Personal Data will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. We will ensure that the companies to which your Personal Data is transferred do provide an adequate level of protection. In particular, we have concluded Standard Contractual Clauses (SCC) with them. We guarantee to always verify, on a case-by-case basis, whether an adequate level of protection is in place for transfers to third countries.

For more information on how data transfers of Shopify comply with the GDPR, see Shopify’s GDPR Whitepaper: https://help.shopify.com/en/manual/your-account/privacy/GDPR.



BEHAVIOURAL ADVERTISING

 

As described above, we use your Personal Data to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For example:

 

We use Google Analytics to help us understand how our customers use the Site. You can read more about how Google uses your Personal Data here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.

 

We share information about your use of the Site, your purchases, and your interaction with our ads on other websites with our advertising partners. We collect and share some of this information directly with our advertising partners, and in some cases through the use of cookies or other similar technologies.

 

We use Shopify Audiences to help us show ads on other websites with our advertising partners to buyers who made purchases with other Shopify merchants and who may also be interested in what we have to offer. We also share information about your use of the Site, your purchases, and the email address associated with your purchases with Shopify Audiences, through which other Shopify merchants may make offers you may be interested in.

 

We use Meta, TikTok and Linkedin audiences to help us show ads to people who purchased before, added to cart, have been on our website before.

For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at https://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

 

You can opt out of targeted advertising by:

 

FACEBOOK - https://www.facebook.com/settings/?tab=ads

 

GOOGLE - https://www.google.com/settings/ads/anonymous

 

BING - https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads]

 

 

 

Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: https://optout.aboutads.info/.



RETENTION

 

We do not keep Personal Data longer than necessary for the purposes for which it is collected and processed. For the purposes for providing services to you, we will retain it for as long as necessary to fulfill the purposes set out in this Privacy Policy, unless a longer retention period is (i) necessary to cover our liability or (ii) required or permitted by law.



YOUR RIGHTS AS A DATA SUBJECT UNDER GDPR

 

  • to access the Personal Data we hold about you;
  • to port it to a new service (data portability);
  • to ask that your Personal Data be corrected or updated;
  • to erase your Personal Data in certain specific cases;
  • to withdraw your consent at any time where you have previously given your consent to the processing of personal data;
  • to restrict the processing of Personal Data in certain specific cases;
  • to object to processing of your Personal Data if the processing is carried out on the legal basis of a legitimate interest or for direct marketing purposes;

to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you. We do engage in fully automated decision-making that has a legal or otherwise significant effect using customer data. Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you. Services that include elements of automated decision-making include: (i) Temporary blacklist of IP addresses associated with repeated failed transactions. This blacklist persists for a small number of hours and (ii) temporary blacklist of credit cards associated with blacklisted IP addresses. This blacklist persists for a small number of days.

 

Cookies

A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.

We use the following cookies to optimize your experience on our Site and to provide our services.

[Be sure to check this list against Shopify’s current list of cookies on the merchant storefront: https://www.shopify.com/legal/cookies ]

Reporting and Analytics

The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.


You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.


Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as: www.allaboutcookies.org.


Additionally, please note that blocking cookies may not completely prevent how we share information with third parties such as our advertising partners. To exercise your rights or opt-out for targeting by these parties, you should go to such third party’s website. Please follow the instructions in the “Behavioural Advertising” section above.

This website uses the web analysis service intelliAd operated by emarketing AG, Landsberger Strasse 110, 80339 Munich, Germany. Anonymised data is processed and saved on an aggregated basis, in order to ensure effective design and for optimising the website. The collected data does not allow any conclusions to be drawn about individual users neither for the operator of the website nor for emarketing AG. Using intelliAd Tracking involves cookies being saved locally. You have the right to deactivate the saving and further use of your browsing data. Please use the intelliAd Opt-Out function for this purpose. You can also set your browser so that it generally prevents the setting of cookies. To improve tracking accuracy, the "first-party tracking" method is used. In this process, a first-party cookie (ia-8333138373136323131303) is set on the customer domain. Complete IP addresses are also not stored in the procedure and are only processed in anonymized form.

 


CHANGES


We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.


LINKS TO OTHER WEBSITES


Our Site may contain links to other sites that are not operated by us. When you click on a third-party link, you will be transferred to that third-party site. We strongly recommend that you review the Privacy Policy of any site you visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party web sites or services.


COMPLAINTS


As noted above, if you would like to make a complaint, please contact us by e-mail or by mail using the details provided under “Contact” above.


For further information and advice on the above rights, please visit the website of the Belgian Data Protection Authority: www.gegevensbeschermingsautoriteit.be


If you are not satisfied with our response to your complaint, you have the right to lodge your complaint with the relevant data protection authority. You can contact your local data protection authority, or the Belgian supervisory authority here at contact@apd-gba.be or by mail at the following address:


Gegevensbeschermingsautoriteit

Drukpersstraat 35

1000 Brussel

Last updated: [15/6/2023]