Privacy Policy Last updated: 10 Dec, 2024
Richie Loyalty Program & Website Privacy Policy
Introduction
Welcome to Richie. Please carefully read this Privacy Policy (“Policy”) as it outlines how Mega Fortuna Teknoloji ve Yazilim Anonim Şirketi, a joint stock company incorporated as per the laws of the Republic of Turkiye (“Richie,” “we,” “us” or “our”, the “Owner”) gathers, uses, discloses, and manages your personal data collected in connection with our website, mobile app, products and services (collectively referred to as the “Services”, “Application”, or “Platform”). By using our website, mobile app, products, and services (collectively referred to as the “Services”), you agree to this Policy. This policy is incorporated into and forms a part of our Terms of Use. Before accessing or using the application, please ensure that you have read and understood our Privacy Policy. If there are any terms in this Privacy Policy that you do not agree with, please discontinue use of our Services immediately.
Please note that the data controller responsible for the collection, use, and protection of personal data as per this Privacy Policy is Richie. The official title and contact information of Richie is given below.
Title: Mega Fortuna Teknoloji ve Yazilim Anonim Şirketi
Address: Odunluk Mah. Akpınar(180) Cad. İşyeri (Ofisler) Green Whıte Plaza 5/25 Bursa/Turkey
Email: [email protected] with “Privacy” in the subject line
Consent and Age Restrictions
By clicking the “ACCEPT & CONTINUE” button during the account creation, you affirm that you have read, understood, and agree to these terms (and we will hereby refer to you as “User”). If you are under 18 or do not agree with these terms, you are prohibited from registering with Richie.
Terms Of Use
Our Privacy Policy is part of our Terms of Use. By using our Services, you agree to these terms, available at the bottom of most pages on the Richie website.
Updates to This Policy
We may update this Policy at our discretion. Any changes will be noted by the “Last Updated” date, and an alert will be provided within our mobile app. Please revisit this page to stay informed. If the modified Policy is not acceptable to you, please refrain from using our Services.
It’s important to highlight that Richie only collects and processes your data for reasons explicitly listed in this Policy and by applicable laws. This legal framework safeguards your privacy and ensures that your information is handled responsibly.
By providing this comprehensive overview of data collection practices, Richie aims to instill transparency and empower you to navigate the platform with confidence. Should you have any further questions or require clarification, do not hesitate to reach out to the designated contact points within the Policy.
A. PERSONAL DATA WE COLLECT
1. Types of Data Collected Directly by Richie
“Personal Data” used throughout this Privacy Policy means in short personally identifiable information of Users of the Platform that is collected through the Platform from User and maintained by us in an accessible form, and by definition may include personal identifiers such as a first and last name, a physical address, an e-mail address, a telephone number, a Social Security number, or any other identifier that permits the physical or online contacting of the User and any other information concerning the User collected by us from User and maintained in personally identifiable form in combination with any identifier described in this paragraph.
a. Account Data Collection:
When you actively engage with Richie, certain information is directly provided by you. During the account creation process, details like your name and email address, phone number, account preferences, and other communications details are collected. We can also collect data indirectly from your use of our Services such as your IP address, your device location, mobile device identification, and advertising identifier. Please check section 4 titled “Service Providers Processing Personal Data on Our Behalf” of this Privacy Policy for the information we gather from third-party service providers. This section of the Richie User Privacy Policy clarifies the specific data points we collect when you interact with us directly or participate in our promotional activities. Understanding this information empowers you to make informed decisions regarding your privacy within the platform.
- Name: Both your first and last name are collected when you create a Richie account.
- Age: Providing your age allows us to ensure compliance with age restrictions and tailor platform features accordingly.
- Gender: While optional, sharing your gender information helps us personalize user experience and recommendations. You may choose to share this personal information at your discretion. If you change your mind about sharing this information, you can always opt-out of sharing via your account preferences settings.
- Your Google Mail or Facebook Account: Your Google or Facebook account acts as your primary login credential and serves as a communication channel for important updates, promotions, and support. When you sign up to the platform with your Google or Facebook account we collect your data in these platforms such as e-mail address.
- Profile Picture: If you choose to use your profile picture of your Google Mail or Facebook account or choose to upload a new profile picture, it may include your personal photo or other personal information and it will be shown in some parts of the Services. You can always opt-out by removing your profile picture, or changing to a picture that does not contain your personal information, such as an avatar.
- Phone Number: Your phone number allows us to security verification through SMS. Also, if you give additional and explicit consent, it can be used to offer relevant promotions through SMS.
- FaceID: Richie prioritizes the security and integrity of its platform, particularly when users redeem rewards earned through their interactions. To ensure these rewards are issued legitimately and prevent fraudulent activity, we utilize a “video selfie” verification process during redemption.
- Account Preferences: Your individual preferences within your account settings, such as language choice or notification preferences, are collected to personalize your user experience.
- Direct Communication: Information shared during direct communication with Richie, including email exchanges, support inquiries, or feedback via surveys, is collected to understand your needs and improve our customer services.
- Participation in Promotions: When you choose to participate in promotions or contests organized by Richie, additional information may be collected as required by the specific promotion’s terms and conditions. This could potentially include the username, email address, and other details relevant to the promotion.
b. Device Data Collection:
This section of the Richie User Privacy Policy delves into the specific details of the personal data we collect, providing transparency and enabling you to understand the scope of information utilized within the platform.
-
- IP Address: We collect your IP address, which can provide an approximate location (city/country level) and other network-related information.
- Geolocation Data: In certain instances, with your explicit consent, we may collect precise geolocation data, including longitude and latitude coordinates, to offer location-based services or features. The geographic location of the User is determined in a matter that isn’t continuous. This means that it is impossible for our Services to derive the approximate position of you on a continuous basis.
- Mobile Device Identifier: Unique identifiers associated with your mobile device, such as the International Mobile Equipment Identity (IMEI) or Android advertising ID, are collected for device identification and security purposes.
- Advertising Identifier: We leverage advertising identifiers like the Google Advertising ID to personalize advertising and measure its effectiveness. You can opt-out by changing your device settings.
- Device Information: Details about your operating system, device model, and language preferences are collected to optimize the platform for your specific device.
B. WHERE WE STORE PERSONAL DATA
Based in Germany: Your personal information is stored on secure servers provided by Amazon AWS & Azure Cloud Services in Germany. However, your information may be transferred, stored, or used in other jurisdictions like the United States, where our service providers might be located.
Protections and Risks: Although we take precautions by selecting reputable service providers and contractual safeguards, privacy laws in these jurisdictions may differ and be less protective than those in Germany, United States or the EEA & UK. There may also be potential access to your information by foreign governments.
GDPR Compliance: For information collected in the EEA & UK, we transfer and store it securely in the Germany in line with GDPR adequacy standards. Other transfers to third countries follow specific mechanisms like the “model clauses.”
C. Use of Personel Data:
Data protection laws require that we meet certain conditions before we are allowed to use your personal data in the manner described in this Privacy Policy. To use your personal data, we will rely on one of the following conditions, depending on the activities we are carrying out:
- You have given us consent.
- Processing is necessary for our legitimate business interests or those of a third party: provided this does not override any interests or rights that you have as an individual.
- Processing is necessary for compliance with our legal obligations.
- Processing is necessary for legal claims.
- Processing is necessary for substantial public interest.
Below you will find detailed information on the basis that we collect and use your personal data. If we look to use your personal data for any other purpose not covered in this Privacy Policy, we will let you know about any proposed new purposes before using your personal data in this way.
1.Consent
We ask that you provide affirmative and informed consent to the use of your personal data as described in this Privacy Policy when you access the Platform and participate in the Services. Please discontinue using the Services if you do not have such consent.
We do not collect personal data for the purpose of sale of such information in a way that specifically identifies the individual (i.e., we don’t sell Member information).
We may provide you with marketing information about our services or products where you have indicated your consent for us to do so (to the extent that we are required to collect consent under data protection laws). We may contact you by mail or email, phone and electronic notifications (where you have agreed to those methods of communication) to provide you with the information on your requested service or product. We may also provide you with information, special offers, research, promotions, and similar products and services. Where you have indicated your consent to us doing so, we may also pass your details to our group companies for marketing purposes. You may change your marketing preferences at any time from your account settings.
If we are relying solely on your consent to process your personal data, you may withdraw your consent to our processing of your personal data at any time; however, withdrawing consent may result in your inability to continue using some or all of the services in the Platform. Please note that the withdrawal of your previous consent will not affect the lawfulness of the processing before its withdrawal, nor will it affect the processing of your personal data conducted in reliance on lawful processing grounds other than consent. Please check the “Withdrawal of Consent to Collect Personal Information” section of this Privacy Policy for further information about withdrawing the consent.
2. Legitimate Interest
Sometimes our collection and use of your personal data may not depend on your informed consent but our legitimate interests. It is in our legitimate interests to collect your personal data as it provides us with information that we need to provide our Services to you and to make our Platform available.
This requires us to carry out a balancing test of our interests in using your personal data (for example, in order to provide you with access to the Platform, against the interests you have as a person and the rights you have under Delaware Online Privacy and Protection Act and other applicable Data protection law (for example, to not have your personal data sold to third party marketing companies without your knowledge).
The outcome of this balancing test will determine whether we may use your personal data in the ways described in this Privacy Policy. We will always act reasonably and give full and proper consideration to your interests in carrying out this balancing test.
Our main legitimate interests are listed below:
- Tailored Experiences: Leveraging collected data, Richie aims to personalize your journey by suggesting surveys aligned with your interests.
- Rewarding Engagement: Completion of surveys within the platform translates to rewards offered through the Richie program.
- Service Enhancement: Data plays a vital role in monitoring survey completions, managing in-app gift card redemption, and ultimately improving the overall user experience.
- Strategic Marketing: Richie employs collected data to effectively promote its services across diverse platforms.
- Operational Efficiency: Reward program management relies on accurate data collection.
- Security and Fraud Prevention: Safeguarding the platform and preventing fraudulent activity requires utilizing relevant data points.
- Face Verification for Security and Fraud Prevention: This process involves capturing a short video of your face using a feature powered by our trusted third-party face verification technology. The captured video generates a mathematical representation of your facial features, creating a unique identifier that becomes part of your account information. Importantly, this video selfie is encrypted directly on your device before secure transmission to our servers for processing. By implementing this verification step, Richie aims to achieve several key objectives:
-
- The uniqueness of User Registration: We safeguard against duplicate accounts and ensure legitimate participation by verifying the uniqueness of each user within the platform.
-
- Prevention of Fraudulent Activity: The system helps deter the use of bots, automated processes, or any unauthorized software that could fraudulently exploit the reward system.
-
- Reward Security: Video selfies enhance the security of your rewards, guaranteeing they are rightfully issued to verified users and cannot be obtained through illegitimate means.
This verification process aligns with Richie’s commitment to creating a secure and fair environment for all users. By understanding its purpose and implementation, you can confidently engage with the platform and enjoy the rewards earned through your participation.
-
- Product Development and Innovation: Insights gleaned from data drive the creation of new products and the enhancement of existing services.
-
- Data-Driven Reporting: Aggregated and anonymized data empowers the generation of valuable reports and insights, fostering optimization across various aspects of the platform.
-
- Effective Communication: Understanding user preferences allows Richie to tailor its communication channels and improve their relevance.
-
- Machine Learning for Personalization: Data fuels the development of machine learning models, ensuring a customized content experience for each user.
3. Contractual Performance
Please note that when you become a User of the Platform you enter into a contractual relationship with us via the Terms of Use which you accept by use of our Platform. This contractual relationship necessitates the processing, use and storage of your personal data for the purpose of fulfilling our contractual obligations and/or facilitating our contractual rights. Therefore, at this stage, the contractual relationship itself becomes the legal basis of our processing of your personal data.
4. Legal Obligations and Legal Claims
We are permitted to process your personal data where it is necessary for compliance with our legal obligations. We are also permitted to process your personal data where it is necessary to establish, pursue or defend a legal claim.
We may disclose your personal data to third parties without your consent if we have reason to believe that disclosing this information is necessary to identify, contact, or bring legal action against someone who may be causing injury to or interference with (either intentionally or unintentionally) our rights or property, other users of the Services, or anyone else (including the rights or property of anyone else) that could be harmed by such activities. We may disclose personal data when we believe in good faith that such disclosure is required by and in accordance with the law.
5. Substantial Public Interest
We are permitted to process your personal data where it is necessary for reasons of substantial public interest, on the basis of data protection laws.
D. DATA PROCESSING ACTIVITIES REQUIRING YOUR SPECIAL ATTENTION
a. Automatic Collection:
Please note that certain information listed above in section 1 titled “Personal Data We Collect” is automatically collected when accessing and using our Services, such as:
- Aggregated usage information
- Session ID
- Access time and date
- Device data
b. Push notifications:
Our Services may send push notifications to the User to achieve the purposes outlined in this Privacy Policy. Users may in most cases opt-out of receiving push notifications by visiting their device settings, such as the notification settings for mobile phones, and then change those settings for this Application, some or all of the apps on the particular device. Users must be aware that disabling push notifications may negatively affect the utility of this Application.
c. Children’s Data Privacy Protection
Richie prioritizes the protection of children’s privacy. In terms of the collection of personal data, we would like to stress that we do not knowingly solicit data from children under 18 years of age. By using the Platform, you represent that you are at least 18. If we learn that personal data from users who are under 18 years of age has been collected due to their misrepresentation during membership, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at [email protected]
Also, it is important to remember that:
- Children under 18 are not permitted to use the platform.
- Richie retains data for legal requirements, as long as you actively use the service, or for its originally intended purposes.
- Information on cookie usage and other tracking technologies is available in the separate Cookie Notice.
d. External Links
Our Services might direct you to other websites or surveys, controlled by third parties. These third-party sites have separate privacy practices that we don’t oversee. Please read their privacy policies to understand how they may use your information.
e. Withdrawal of Consent to Collect Personal Information
If you wish to withdraw consent to collect personal information, you can send a written request to help@richiegames. Upon receipt, we will:
- Stop Processing: Cease processing your personal information within a reasonable time.
- Effects of Withdrawal: Please be aware that withdrawing consent may impact your ability to use the Services, including loss of benefits and loyalty points. Please note that the withdrawal of your previous consent will not affect the lawfulness of the processing before its withdrawal, nor will it affect the processing of your personal data conducted in reliance on lawful processing grounds other than consent.
- Account Deletion: You may also request account deletion. If you choose to delete your account, any unredeemed loyalty points will be deleted, and we will send an email to confirm the deletion (please refer to the Data Retention section above).
f. Promotional Communications
If you have given explicit and separate consent, we may send you promotional messages. You can choose to opt out of these communications at any time by following the unsubscribe instructions in the messages. Note that even if you opt out, you may still receive non-promotional communications regarding your account, requested Services, or our ongoing business relationship.
E. SERVICE PROVIDERS PROCESSING PERSONAL DATA ON OUR BEHALF
We may use contractors and service providers to process the information collected about you on our behalf for the purposes described in this Privacy Policy. We contractually require service providers to keep information secure and confidential and we do not allow our data processors to disclose your information to others without our authorization, or to use it for their own purposes. However, if you have an independent relationship with these service providers their privacy statements will apply for that independent relationship.
a. Advertising: This type of service allows User Data to be utilized for advertising communication purposes. These communications are displayed in the form of banners and other advertisements on the Service platform, possibly based on User interests. This does not mean that all Personal Data are used for this purpose. Information and conditions of use are shown below. Some of the services listed below may use Trackers to identify Users or they may use the behavioral retargeting technique, i.e. displaying ads tailored to the User’s interests and behavior, including those detected outside this Application. For more information, please check the privacy policies of the relevant services. In addition to any opt-out feature offered by any of the services below, Users may opt-out by visiting the Network Advertising Initiative opt-out page. Users may also opt out of certain advertising features through applicable device settings, such as the device advertising settings for mobile phones or ads settings in general.
-
- AdMob (Google Ireland Limited): AdMob is an advertising service provided by Google Ireland Limited. To understand Google’s use of Data, consult Google’s partner policy.
Place of processing: Ireland – Privacy Policy – Opt Out.
- AdMob (Google Ireland Limited): AdMob is an advertising service provided by Google Ireland Limited. To understand Google’s use of Data, consult Google’s partner policy.
-
- Facebook Audience Network (Facebook Ireland Ltd): Facebook Audience Network is an advertising service provided by Facebook Ireland Ltd To understand Facebook’s use of Data, consult Facebook’s data policy. This Application may use identifiers for mobile devices (including Android Advertising ID or Advertising Identifier for iOS, respectively) and technologies similar to cookies to run the Facebook Audience Network service. One of the ways Audience Network shows ads is by using the User’s ad preferences. The User can control this in the Facebook ad settings.
-
- Users may opt out of certain Audience Network targeting through applicable device settings, such as the device advertising settings for mobile phones, or by following the instructions in other Audience Network-related sections of this privacy policy, if available.
-
- Personal Data processed: Tracker; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); Usage Data.
Place of processing: Ireland – Privacy Policy – Opt Out.
- Personal Data processed: Tracker; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); Usage Data.
-
- Adjust (Adjust GmbH): Adjust is an advertising service provided by Adjust GmbH.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: Germany – Privacy Policy – Opt out.
- Personal Data processed: Tracker; Usage Data.
-
- AdColony (AdColony, Inc.): AdColony is an advertising service provided by AdColony, Inc.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt out.
- Personal Data processed: Tracker; Usage Data.
-
- Tapjoy (Tapjoy, Inc.): Tapjoy is an advertising service provided by Tapjoy, Inc.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt out.
- Personal Data processed: Tracker; Usage Data.
-
- Liftoff (Liftoff Mobile, Inc.): Liftoff is an advertising service provided by Liftoff Mobile, Inc.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt out.
- Personal Data processed: Tracker; Usage Data.
-
- PubMatic (PubMatic, Inc.): PubMatic is an advertising service provided by PubMatic, Inc.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt Out.
- Personal Data processed: Tracker; Usage Data.
-
- Smaato (Smaato, Inc.): Smaato is an advertising service provided by Smaato, Inc.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt out.
- Personal Data processed: Tracker; Usage Data.
-
- TripleLift (TripleLift, Inc.): TripleLift is an advertising service provided by TripleLift, Inc.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt out.
- Personal Data processed: Tracker; Usage Data.
-
- Unruly (Unruly Group Ltd): Unruly is an advertising service provided by Unruly Group Ltd.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: United Kingdom – Privacy Policy – Opt out. - InMobi: InMobi is an advertising service.
- Personal Data processed: Tracker; Usage Data.
Place of processing: India – Privacy Policy – Opt out. - Mintegral (Mintegral International Ltd.): Mintegral is an advertising service provided by Mintegral International Ltd.
- Personal Data processed: Tracker; Usage Data.
Place of processing: China – Privacy Policy – Opt out. - AppLovin (AppLovin Corporation): AppLovin is an advertising service provided by AppLovin Corporation.
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt out. - myTarget (MGL MY.COM (CYPRUS) LIMITED): myTarget is an advertising service provided by MGL MY.COM (CYPRUS) LIMITED.
- Personal Data processed: Tracker; Usage Data.
Place of processing: Russia – Privacy Policy – Opt out. - DT Exchange (Digital Turbine Inc.): DT Exchange is an advertising service provided by Digital Turbine Inc.
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt out. - Pangle (Bytedance Pte. Ltd.): Pangle is an advertising service provided by Bytedance Pte. Ltd.
- Personal Data processed: Tracker; Usage Data.
Place of processing: Singapore – Privacy Policy – Opt out.
- Personal Data processed: Tracker; Usage Data.
-
- Google Ad Manager (Google Ireland Limited): Google Ad Manager is an advertising service provided by Google Ireland Limited that allows the Owner to run advertising campaigns in conjunction with external advertising networks that the Owner unless otherwise specified in this document, has no direct relationship with. To opt out of being tracked by various advertising networks, Users may make use of Youronlinechoices. To understand Google’s use of data, consult Google’s partner policy. This service uses the “DoubleClick” Cookie, which tracks the use of this Application and User behavior concerning ads, products, and services offered.
-
- Users may decide to disable all the DoubleClick Cookies by going to: Google Ad Settings.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: Ireland – Privacy Policy.
- Personal Data processed: Tracker; Usage Data.
-
- Google AdSense (Google Ireland Limited): Google AdSense is an advertising service provided by Google Ireland Limited. This service uses the “DoubleClick” Cookie, which tracks the use of this Application and User behavior concerning ads, products, and services offered. Users may decide to disable all the DoubleClick Cookies by going to: Google Ad Settings – Opt Out.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: Ireland – Privacy Policy – Opt Out.
- Personal Data processed: Tracker; Usage Data.
-
- Unity Ads (Unity Technologies ApS): Unity Ads is an advertising service provided by Unity Technologies ApS.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: Denmark – Privacy Policy – Opt out.
- Personal Data processed: Tracker; Usage Data.
-
- Aarki (Aarki Inc.) Aarki is an advertising service provided by Aarki Inc.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt out.
- Personal Data processed: Tracker; Usage Data.
-
- Fluct (Fluct Inc.) : Fluct is an advertising service provided by Fluct Inc.
- Personal Data processed: Tracker; Usage Data.
Place of processing: Japan – Privacy Policy – Opt out.
- Vungle: Vungle is an advertising service.
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt out. - Chartboost (Chartboost Inc.): Chartboost is an advertising service provided by Chartboost Inc.
- Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt out. - Ironsource (Ironsource Mobile Ltd.): Ironsource is an advertising service provided by Ironsource Mobile Ltd.
- Personal Data processed: Tracker; Usage Data.
Place of processing: Israel – Privacy Policy – Opt out.
- Personal Data processed: Tracker; Usage Data.
- b. Analytics :The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
-
- Google Analytics for Firebase (Google Ireland Limited): Google Analytics for Firebase or Firebase Analytics is an analytics service provided by Google Ireland Limited. To understand Google’s use of Data, consult Google’s partner policy. Firebase Analytics may share Data with other tools provided by Firebase, such as Crash Reporting, Authentication, Remote Config or Notifications. The User may check this privacy policy to find a detailed explanation about the other tools used by the Owner.
-
- This Application uses identifiers for mobile devices and technologies similar to cookies to run the Firebase Analytics service.
-
- Users may opt-out of certain Firebase features through applicable device settings, such as the device advertising settings for mobile phones or by following the instructions in other Firebase related sections of this privacy policy, if available.
-
- Personal Data processed: Application opens; Application updates; device information; geography/region; In-app purchases; launches; number of sessions; number of Users ; operating systems; session duration; Tracker; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); Usage Data.
-
- Place of processing: Ireland – Privacy Policy.
-
- Flurry Analytics (Flurry, Inc.) :Flurry Analytics is an analytics service provided by Yahoo! Inc. This service is designed for mobile apps analytics and can collect various information about your phone, highlighted in the Flurry Analytics privacy policy. If the User chooses to opt-out, Flurry will stop tracking data for the device identified by the provided MAC address and/or device identifier going forward. The analytics service tracking will stop across all applications within the Flurry network.
-
- Personal Data processed: Tracker; Usage Data; various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy – Opt Out.
- Personal Data processed: Tracker; Usage Data; various types of Data as specified in the privacy policy of the service.
-
- Facebook Analytics for Apps (Facebook Ireland Ltd): Facebook Analytics for Apps is an analytics service provided by Facebook Ireland Ltd
-
- Personal Data processed: Usage Data; various types of Data as specified in the privacy policy of the service.
Place of processing: Ireland – Privacy Policy.
- Personal Data processed: Usage Data; various types of Data as specified in the privacy policy of the service.
-
- Unity Analytics (Unity Technologies ApS): Unity Analytics is an analytics service provided by Unity Technologies ApS.
-
- Personal Data processed: Usage Data; various types of Data as specified in the privacy policy of the service.
Place of processing: Denmark – Privacy Policy.
- Personal Data processed: Usage Data; various types of Data as specified in the privacy policy of the service.
-
- Yandex Metrica (YANDEX, LLC) :Yandex Metrica is an analytics and heat mapping service provided by YANDEX, LLC. Yandex Metrica is used to display the areas of this Application that Users interact with most frequently. This shows where the points of interest are.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: Russian Federation – Privacy Policy.
- Personal Data processed: Tracker; Usage Data.
-
- Facebook Ads conversion tracking (Facebook pixel) (Facebook Ireland Ltd): Facebook Ads conversion tracking (Facebook pixel) is an analytics service provided by Facebook Ireland Ltd that connects data from the Facebook advertising network with actions performed on this Application. The Facebook pixel tracks conversions that can be attributed to ads on Facebook, Instagram and Audience Network.
-
- Personal Data processed: Tracker; Usage Data.
Place of processing: Ireland – Privacy Policy.
- Personal Data processed: Tracker; Usage Data.
-
- Beta Testing: This type of service makes it possible to manage User access to this Application, or parts of it, for the purpose of testing a certain feature or the entire Application. The service provider may automatically collect data related to crashes and statistics related to the User’s use of this Application in a personally identifiable form.
-
- TestFlight (Apple Inc.): TestFlight is a beta testing service provided by Apple Inc.
-
- Personal Data processed: app information; country; device logs; Tracker; Usage Data; various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
- Personal Data processed: app information; country; device logs; Tracker; Usage Data; various types of Data as specified in the privacy policy of the service.
- c. Content performance and features testing (A/B testing): The services contained in this section allow the Owner to track and analyze the User response concerning web traffic or behavior regarding changes to the structure, text, or any other component of this Application.
-
- Firebase Remote Config (Google Ireland Limited) : Firebase Remote Config is an A/B testing and configuration service provided by Google Ireland Limited.
-
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: Ireland – Privacy Policy.
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
-
- Applovin (Applovin Corporation): Applovin is an analytics and marketing service provided by Applovin Corporation.
- Personal Data Processed: country; device information; device logs; Tracker; Usage Data; various types of Data as specified in the privacy policy of the service.
- Place of processing: United States –Privacy Policy.
- Appsflyer (AppsFlyer Limited): Appsflyer is an analytics and marketing service provided by AppsFlyer Limited.
- Personal Data Processed: country; device information; device logs; Tracker; Usage Data; various types of Data as specified in the privacy policy of the service.
- Place of processing: United States – Privacy Policy.
d. Handling payments: Unless otherwise specified, this Application processes any payments by credit card, bank transfer or other means via external payment service providers. In general and unless where otherwise stated, Users are requested to provide their payment details and personal information directly to such payment service providers. This Application isn’t involved in the collection and processing of such information: instead, it will only receive a notification by the relevant payment service provider as to whether payment has been successfully completed.
-
- RevenueCat (RevenueCat, Inc.): RevenueCat is a payment service provided by RevenueCat, Inc. The service allows the Owner to monitor and analyze the User and their purchase history and can be used to keep track of User behavior.
-
- Personal Data processed: Application opens; device information; Tracker; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); Usage Data.
Place of processing: United States – Privacy Policy – Opt Out.
- Personal Data processed: Application opens; device information; Tracker; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); Usage Data.
-
- Payments are processed via the Apple App Store (Apple Inc.): This Application uses a payment service provided by Apple Inc. that allows the Owner to offer the purchase of the app itself or in-app purchases.
-
- Personal Data processed to complete the purchases are processed by Apple, as described in the privacy policy for the App Store.
-
- Personal Data processed: payment info.
Place of processing: United States – Privacy Policy.
- Personal Data processed: payment info.
-
- Payments processed via Paypal (Paypal Holdings, Inc.): Our Services use a payment service provided by Paypal Holdings, Inc. that allows us to offer in-app purchases.
-
- Personal Data processed to complete the purchases are processed by Paypal, as described in their Privacy Policy.
-
- Personal Data processed: payment info.
-
- Place of processing: United States – Privacy Policy.
- e. Hosting and backend infrastructure: This type of service has the purpose of hosting Data and files that enable this Application to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of this Application.Some services among those listed below, if any, may work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
-
- Amazon Web Services (AWS) (Amazon Web Services, Inc.): Amazon Web Services (AWS) is a hosting and backend service provided by Amazon Web Services, Inc.
-
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
-
- Azure Cloud Services (Microsoft): Azure Cloud Services is a hosting and backend service provided by Microsoft.
-
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
- f. Infrastructure monitoring: This type of service allows this Application to monitor the use and behavior of its components so its performance, operation, maintenance, and troubleshooting can be improved. Which Personal Data are processed depends on the characteristics and mode of implementation of these services, whose function is to filter the activities of this Application.
-
- Firebase Performance Monitoring (Google Ireland Limited): Firebase Performance Monitoring is a monitoring service provided by Google Ireland Limited.
-
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: Ireland – Privacy Policy.
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
-
- Crashlytics (Google Ireland Limited): Crashlytics is a monitoring service provided by Google Ireland Limited.
-
- Personal Data processed: crash data; device information; Universally unique identifier (UUID).
Place of processing: Ireland – Privacy Policy.
- Personal Data processed: crash data; device information; Universally unique identifier (UUID).
- g. Managing contacts and sending messages: This type of service makes it possible to manage a database of email contacts, phone contacts, or any other contact information to communicate with the User. These services may also collect data concerning the date and time when the message was viewed by the User, as well as when the User interacted with it, such as by clicking on links included in the message.
-
- Firebase Notifications (Google Ireland Limited): Firebase Notifications is a message-sending service provided by Google Ireland Limited. Firebase Notifications can be integrated with Firebase Analytics to target analytics-based audiences and track opening and conversion events.
-
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: Ireland – Privacy Policy.
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
- h. Platform services and hosting: These services have the purpose of hosting and running key components of this Application, therefore allowing the provision of this Application from within a unified platform. Such platforms provide a wide range of tools to the Owner – e.g. analytics, user registration, commenting, database management, e-commerce, and payment processing – that imply the collection and handling of Personal Data. Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
-
- Apple App Store (Apple Inc.): This Application is distributed on Apple’s App Store, a platform for the distribution of mobile apps, provided by Apple Inc.
-
- By virtue of being distributed via this app store, Apple collects basic analytics and provides reporting features that enable the Owner to view usage analytics data and measure the performance of this Application. Much of this information is processed on an opt-in basis.
-
- Users may opt out of this analytics feature directly through their device settings. More information on how to manage analysis settings can be found on this page.
-
- Personal Data processed: Usage Data.
Place of processing: United States – Privacy Policy.
- Personal Data processed: Usage Data.
- i. Social features
-
- Firebase Dynamic Links (Google Ireland Limited) :Firebase Dynamic Links is a social feature provided by Google Ireland Limited. Dynamic Links are tracked within Firebase or Google Analytics for Firebase, which informs the Owner about the details of the User journey to and within this Application.
-
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: Ireland – Privacy Policy.
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
-
- Firebase Invites (Google Ireland Limited) Firebase Invites is a social feature provided by Google Ireland Limited that enables Users to share this Application. The sharing may contain referral codes, or content from within this Application and may be done via email or SMS. Sharing is tracked with Google Analytics for Firebase, which informs the Owner that the User has opened or installed this Application via invite.
-
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: Ireland – Privacy Policy.
- Personal Data processed: various types of Data as specified in the privacy policy of the service.
-
- Further information about Personal Data
-
- Push notifications This Application may send push notifications to the User to achieve the purposes outlined in this privacy policy. Users may in most cases opt-out of receiving push notifications by visiting their device settings, such as the notification settings for mobile phones, and then change those settings for this Application, some or all of the apps on the particular device. Users must be aware that disabling push notifications may negatively affect the utility of this Application.
F. DELETION AND RETENTION
-
-
- We will retain your personal data for as long as needed to fulfill the purpose for which we collected it and for a reasonable period thereafter in order to comply with audit, contractual, or legal requirements, or where we have a legitimate interest in doing so. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
- Deletion: We delete your data by shredding physical information and irrecoverably deleting electronic files. Inactive accounts may be terminated after one year, with the associated data destroyed.
- Retention: Richie will only retain personal data for as long as is required by law, as long as you use the Services, or as long as is necessary to meet the purposes for which it was collected. After account deletion, we may retain data for an additional twelve (12) months for administrative purposes. We may also anonymize data, reserving the right to use it for legitimate business purposes such as to comply with applicable tax laws.
- Request to Delete: You may also directly ask us to delete your account by using our communication information provided in this Privacy Policy. By deleting your account, however, any loyalty points or similar advantages and benefits that you have earned and not redeemed will be deleted. If we choose to maintain or use de-identified information, we continue to do so in a de-identified manner and will not attempt to re-identify you.
- We will retain your personal data for as long as needed to fulfill the purpose for which we collected it and for a reasonable period thereafter in order to comply with audit, contractual, or legal requirements, or where we have a legitimate interest in doing so. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
G. DISCLOSURE OF YOUR PERSONAL DATA
While your data remains at the core of Richie operations, there are instances where controlled sharing occurs. For more information about how we share and process your data and about who we share your data with, please carefully read “Use of Personal Data” title above. These scenarios encompass:
-
-
- Corporate Affiliates and Transaction Parties: When necessary, data might be shared with subsidiaries, affiliates, or counterparties involved in corporate transactions, always adhering to legal agreements and data protection regulations.
- Legal and Security Considerations: If protecting legal rights of Richie, Richie’s users or third parties; preventing fraud, managing risks, or complying with legal obligations necessitates data disclosure, Richie does so responsibly and within the confines of the law.
- Service Providers: A network of trusted service providers assists with various tasks like customer support, technical infrastructure, reward management, system security, and marketing efforts. All such providers are contractually bound to uphold the same data protection standards as Richie. These providers enable us to better align our Services with your interests and may combine the data we share with them with other data they collect about you such as your independent use of their services.
- Advertising and Marketing: Collaborative efforts with advertising platforms and networks enable targeted advertising displays, advertising analytics, and effective management of Richie advertising presence on other platforms. In order to limit the number of times you see an advertisement and to align with your user preferences, we may share with these agents personal data such as device ID’s and IP addresses.
- Marketing Vendors: Lawful partnerships with marketing vendors allow for engaging campaigns, testing activities, user events, and surveys, respecting your right to opt out as stipulated by applicable laws. If you choose to participate, your personal data may be disclosed to these marketing vendors within the confines of the law.
- Analytics Insights: Partnering with analytics providers grants valuable insights into user trends and patterns, aiding in sales optimization, service improvement, and product development.
H. DATA SECURITY
The security of your personal data is important to us. We use commercially reasonable efforts to store and maintain your personal data in a secure environment. We also take technical, contractual, administrative, and physical security steps designed to protect any and all personal data you provide. We have implemented procedures designed to limit the dissemination of your personal data to only such designated staff as are reasonably necessary to carry out the stated purposes we have communicated to you in this Privacy Policy.
Please note that you are also responsible for helping to protect the security of your personal data. For instance, never give out the credentials you use in connection with accessing the Platform, so that other people will not have access to your personal data. Furthermore, you are responsible for maintaining the security of any personal computing device on which you utilize the Services.
We are not liable for disclosure of data due to errors in transmission, unauthorized access or acts by third parties, or omissions or acts beyond our reasonable control. Although we employ commercially reasonable measures of security, we also cannot guarantee that your personal data may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards by persons or systems with malicious intent.
In the event we become aware of a security breach that could result in your personal data being disclosed in a manner that is not authorized under this Privacy Policy, we will notify you via email (or other communication channel you have provided to us) if we can and use other means (such as posting a notice on our Platform) to try to alert you as appropriate.
We have implemented the following security measures to protect its product or service:
- The (database) servers can be accessed only via our trusted network locations.
- Procedures are in place to ensure only authorized personnel have access to the personal data. A non-disclosure and confidentiality agreement ensures this still applies when a member of staff leaves the company.
- All our mobile carriers (such as laptops, USB sticks and portable HDs) are password protected.
- Our web servers and database servers are firewall-protected.
- All data within the Platform will be stored as securely as possible.
- Encryption will be used when possible.
- All data will be transmitted with the highest possible form of encryption that is supported.
- We prevent two different users from logging using the same browser.
- We keep our content on AWS S3 subject to private access.
- Only authorized people can see any details started by a Member.
- We use PostgreSQL database and here we control all access with row level security policies so that only the invitees of us can see the details of it.
- We have a rate limit definition for requests from the same IP.
- We work together with external security service providers regularly to perform penetration tests to ensure our protection against unauthorized access.
I. YOUR RIGHTS REGARDING YOUR PERSONAL DATA
As a User, you are empowered to make informed decisions regarding your data through several rights:
- Opting Out of Marketing Communications: You have the right to choose not to receive marketing messages from Richie.
- Withdrawing Consent: You can revoke your consent to data collection and processing at any time. Please note that this is only possible for data processed based solely on your consent as per this Policy. For example, Gender information. Please note that the withdrawal of your previous consent will not affect the lawfulness of the processing before its withdrawal, nor will it affect the processing of your personal data conducted in reliance on lawful processing grounds other than consent.
- Request Information on the Processing of Your Data: You may request information on whether or not any specific data is being processed. You may also request further information on any processing detailed in this Privacy Policy.
- Deletion of Your Data: Richie grants you the right to request the deletion of your personal data or the closure of your account. However, please note that we may be legally required to retain some of your personal data and may be unable to fully comply with this request.
- Correction of Your Data: You may request that we correct any data collected from you if you believe that the data is incorrect, incomplete or inaccurate.
- Objecting to Data Processing: You hold the right to object to how your personal data is processed for specific purposes or object to the results of automatic processing.
If you have any inquiries or requests regarding your personal information under this policy, you can contact Us using the contact information given above. This contact is provided for addressing concerns related to data privacy and handling within the parameters set by applicable data protection laws.
J. SUPPLEMENTAL PROVISIONS FOR RESIDENTS OF THE EUROPEAN ECONOMIC AREA AND THE UNITED KINGDOM (EEA & UK)
1. Data transfer outside the EU
Richie uses servers located in Germany to keep Personal Data within the EU, please check the Where Do We Store Personal Data section of this Privacy Policy. Richie is allowed to transfer Personal Data collected within the EU to third countries (i.e. any country not part of the EU) only pursuant to a specific legal basis. Any such Data transfer is based on one of the legal bases described below. Users can inquire with the Owner to learn which legal basis applies to which specific service.
- Data transfer outside the EU based on the transferred country being declared as offering an adequate level of protection through a European Commission decision (‘Adequacy Decision’), meaning that data can be transferred with another company in that third country without the data exporter being required to provide further safeguards or being subject to additional conditions. In other words, the transfers to an ‘adequate’ third country will be comparable to a transmission of data within the EU.
- Data transfer outside the EU is based on standard contractual clauses (this Privacy Policy). If this is the legal basis, the transfer of Personal Data from the EU to third countries is carried out by Richie according to “standard contractual clauses” provided by the European Commission. This means that Data recipients have committed to process Personal Data in compliance with the data protection standards set forth by EU data protection legislation. For further information, Users are requested to contact us through the contact details provided in this Privacy Policy.
- Data transfer outside the EU is based on adherence to a code of conduct or certification mechanism together with obtaining binding and enforceable commitments from the recipient to apply the appropriate safeguards to protect the transferred data as set forth by the European Commission.
- Data transfer outside the EU based on your explicit consent to that transfer after being provided with all necessary information about the risks associated with the transfer. By reading and accepting this Privacy Policy you are considered being informed about all necessary information about risks and give your explicit consent.
2. Your Rights under the GDPR
Richie undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights. We process your data for fulfilling contracts (e.g., creating your account), based on our legitimate interests (e.g., fraud prevention), or to comply with legal obligations (e.g., tax requirements). In alignment with EU, Swiss, and UK data protection laws including the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection, we recognize that you have the right under this Privacy Policy, and by law if You are within the EEA or the UK to:
- Right to access: You have the right to access, update or delete the information We have on You. Whenever made possible, you can access, update or request deletion of Your Personal Data directly within Your account settings section. If you are unable to perform these actions yourself, please contact Us to assist You. This also enables You to receive a copy of the Personal Data We hold about You.
- Right to request correction of the Personal Data: You have the right to have any incomplete or inaccurate information We hold about You corrected.
- Right to object: This right exists where We are relying on a legitimate interest as the legal basis for Our processing and there is something about Your particular situation, which makes You want to object to our processing of Your Personal Data on this ground. You also have the right to object to where We are processing Your Personal Data for direct marketing purposes.
- Right to erasure: You have the right to ask Us to delete or remove Personal Data when there is no good reason for Us to continue processing it.
- Right to data portability: You have the right to transfer your information to a third party in a structured, commonly used and machine-readable format, in circumstances where the information is processed with your consent or by automated means. You have the right to receive your Personal Data from us in a structured format and you have the right to (let) transmit such Personal Data to another controller. In that case we will provide to You, or to a third-party You have chosen, Your Personal Data in a structured, commonly used, machine-readable format.
- Right to withdraw Your consent. You have the right to withdraw Your consent on using your Personal Data. If You withdraw Your consent, we may not be able to provide You with access to certain specific functionalities of the Service.
3. Exercising of Your GDPR Data Protection Rights
You may exercise your rights of access, rectification, cancellation, and opposition by contacting us. Please note that we may ask you to verify your identity before responding to such requests. If You make a request, we will try our best to respond to you as soon as possible. You have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. For more information, if You are in the European Economic Area (EEA), please contact Your local data protection authority in the EEA.
K. SUPPLEMENTAL PROVISIONS FOR RESIDENTS OF THE STATE OF CALIFORNIA, USA
Under the California Consumer Privacy Act (CCPA), California residents are granted extensive rights and control over their personal information. Here’s what this means for you:
1. Right to Know and Delete:
- Our policy ensures transparency regarding sharing users’ personal data with third parties. We are committed to informing our users if their personal data is being shared, who it is being shared with, and the purpose of such sharing. California residents have the right to know the specifics of personal data shared with third parties as per the CCPA requirements.
- You can request, twice a year at no cost, details about your personal information that we have disclosed or sold, and a description of the categories of personal information shared.
- We also provide, twice a year and free of charge, any information related to your personal data and how we process it, in a clear and easily understandable manner.
- You can ask us to delete your personal data on our platform. Depending on your choice, we will either remove your information entirely or add you to a “do not contact” list for a specified period.
2. Requests Timeline:
- We’ll respond to your requests to know or delete within 45 days. If more time is needed, we’ll inform you.
3. Authorized Agents:
- You may appoint an authorized agent registered with the California Secretary of State to act on your behalf for disclosure or deletion requests under the CCPA.
- We will honor such requests if you provide written authorization to the agent, and we can verify both your identity and the agent’s proof of authorization.
4. Collection, Usage, and Disclosure Chart:
- The following chart details the categories, sources, and purposes of the personal information we may handle (as described in CCPA Sec. 1798.140(o)):
CATEGORY | DESCRIPTION | SOURCES | BUSINESS USE | COMMERCIAL USE |
A | Identifiers – name, email, postal and IP address, unique personal identifier, online identifier, Internet Protocol address, account name | User provided on registration and upon redeeming points using the online shop, customer service inquiries and claim forms; related and 3rd party sources to verify user-supplied information, selfie in video format | Operational purposes including customer service; fraud & security incidence detection; website improvement; award prize winners | None |
B | Protected classification characteristics under California or federal law | Age and Gender | Recommend suitable surveys | None |
C | Internet or similar network activity -browsing and search history, information on a consumer’s interaction with a website, application, or advertisement | To determine the performance of media content and analytics purposes | User provided on registration and upon redeeming points using online shop, customer service inquiries and claim forms; related and 3rd party sources to verify user-supplied information, selfie in video format | None |
D | Geolocation data | Country Identified using IP Address | Recommend surveys for Country | None |
E | Inferences are drawn from other personal information | Profile reflecting a person’s preferences | Recommend surveys based on preference | None |
- Note that although we have collected and disclosed personal information within the last year for business purposes, we do not sell your personal information.
5. Data Use and Disclosure
We may share your information with third parties for the outlined business purposes. We do not sell personal information (excluding anonymized data) but some sharing might be considered a “sale” under California law. We never intend to collect or share data of users under 16.
6. Data Retention
We retain data only for service usage, legal requirements, or its intended purpose. Inactive accounts with no use for one year may be automatically terminated, and data destroyed, as per the Terms.
7. California Incentive and Your Rights
The Rewards Program, considered a financial incentive under California law, provides benefits balanced against the value we receive from data insights and user analytics. Participation is voluntary, and you can opt-out anytime (refer to Terms of Use).
8. Your Data Privacy Rights at Richie
The California Consumer Privacy Act (CCPA) grants you rights regarding your data:
Right to Know: Understand what data we collect, why, and to whom it’s shared.
Right to Delete: Request deletion of your collected data, subject to exceptions.
Right to Correct: Request correction of any inaccuracies in your data.
Right to Opt Out: Opt out of data sales/sharing and cross-context behavioral advertising.
Right to Limit Use/Disclosure: Limit the use and disclosure of your sensitive information for specific purposes.
Right to Non-discrimination: Not be discriminated against for exercising your CCPA rights.
To opt out of sales/sharing or limit sensitive data use, email [email protected] We also honor opt-out requests via privacy signals like the Global Privacy Control (GPC).
Submit requests to know, delete, or correct data following the instructions in the Policy. Include “Personal Information Privacy Request” in the subject line, specify the service, and provide your name, address, and email. If requesting deletion, specify removal or a “do not contact” listing. We cannot guarantee you won’t be contacted again if we acquire your data in the future. Responses to know/delete requests will be made within 45 days, with potential extensions.
California users can appoint authorized agents to submit CCPA requests. We’ll verify your identity and the agent’s authorization before processing requests.
9. Non-Discrimination Assurance
- Richie will not discriminate against you for exercising your rights under the CCPA.
10. Do Not Track Signals
Most web browsers have a “Do Not Track” (DNT) setting, which, when activated, tells websites that the user does not wish to have their online behavior and personal information tracked (e.g., for interest-based advertising). Under California Online Privacy Protection Act (CalOPPA), we’re obliged to let you know that, like most websites, we do not recognize or respond to DNT signals set by your browser.
L. SUPPLEMENTAL PROVISIONS FOR RESIDENTS OF THE STATES OF COLORADO, CONNECTICUT, AND VIRGINIA IN USA
Residents of Colorado, Connecticut, and Virginia, please note this section supplements the main Policy. For details on data collection, use, sharing, and third-party disclosures, refer to the sections titled “Use of Personal Data”, “Disclosure of Your Personal Data” and “Types of Data Collected”. Sharing for marketing/advertising may fall under “sales” or “targeted advertising.”
Depending on your location, you may have certain rights regarding your data:
Access: Request confirmation and access to your data.
Data Portability: Request a copy of your data in a readily usable format.
Correction: Request correction of inaccuracies in your data.
Deletion: Request deletion of your data.
Opt Out of Sales/Targeted Advertising: Opt out of data processing for these purposes.
Opt Out of Profiling: Opt out of data processing for profiling that impacts your legal rights.
Use the methods described in the Policy to exercise these rights. Include “Personal Information Privacy Request” in the subject line, specify the service you’re inquiring about, and provide your name, address, and email. If requesting deletion, specify whether you want your data completely removed or just kept on a “do not contact” list. You may also appeal a refusal to comply with your request as outlined in the Policy. Residents within these states may also use an authorized agent to submit requests on their behalf, following the outlined verification process.
M. SUPPLEMENTAL PROVISIONS FOR RESIDENTS OF KOREA
If you are accessing our Services from Korea, please note that we may need to transfer your personal information overseas. If this occurs, we’ll ensure that the transfer is done according to the privacy requirements of the Korean Personal Information Protection Act (PIPA) and the Network Act. This includes using a secure information communication network. Your information will be retained and used only until the purpose for which it was collected is fulfilled.
COMPANY NAME | COUNTRY | CONTACT OF EMPLOYEE OR DEPARTMENT RESPONSIBLE FOR MANAGING PERSONAL INFORMATION AND LINK TO PRIVACY POLICY | DATE AND TIME OF TRANSFER | PURPOSE OF TRANSFER | PERSONAL INFORMATION ITEMS TO BE TRANSFERRED |
Amazon Web Services, Inc. | U.S.A | Amazon.Com | Upon accessing and using Richie services | Hosting and data security and management services for the personal data that we store. Also used for analytics to monitor and track the reliability of the Services | CONTACT OF EMPLOYEE OR DEPARTMENT RESPONSIBLE FOR MANAGING PERSONAL INFORMATION AND LINK TO THE PRIVACY POLICY |
Azure Cloud Services | U.S.A | Microsoft.com | Upon accessing and using Richie services | Hosting and data security and management services for the personal data that we store. Also used for analytics to monitor and track the reliability of the Services | CONTACT OF EMPLOYEE OR DEPARTMENT RESPONSIBLE FOR MANAGING PERSONAL INFORMATION AND LINK TO THE PRIVACY POLICY |
Adjust | U.S.A | Email Adjust.Com | Upon accessing and using Richie services | Advertising, rewards, and fraud detection | Mobile application Google Ad ID, IP address, age, device model, OS version |
U.S.A | Facebook.Com | Upon accessing and using Richie services | Used for business analytics to better understand how users interact with Richie Services | Google Advertising ID | |
U.S.A | Google.Com | Upon accessing and using Richie services | Used for business analytics to better understand how users interact with Richie Services | Google Advertising ID | |
AdGate | Canada | Adgatemedia.com | Upon accessing and using Richie services | Advertising, and rewards | IP address, user agent |
Richie Analytics | U.S.A | Richie – Privacy Policy | Upon accessing and using Richie services | Richie Analytics is a feature that is integrated with our app. Richie Analytics allows users to earn in-app points by completing surveys. The processing of the data is necessary for fraud prevention, users’ security & privacy. It is also required to recommend, via system messages, and calculates rewards. | Approximate Location, Device ID, Device Model, Operating System, Mail, Phone Number |
N. SUPPLEMENTAL PROVISIONS FOR RESIDENTS OF BRAZIL
This section applies to all Users in Brazil under the “Lei Geral de Proteção de Dados” (the “LGPD”) and supersedes any conflicting information in the privacy policy. We use the term “personal information” as defined in the LGPD.
1. Grounds for Processing Personal Information
We process your personal information only if we have a legal basis under LGPD, such as your consent. For more details, contact us using the information provided in this Privacy Policy.
2. Categories of Personal Information Processed
Refer to the “Types of Data Collected” section in this Privacy Policy to see what categories of your personal information are processed.
3. Disclosure of Your Personal Information
Refer to the “Disclosure of Your Personal Data” and “Use of Personal Data” sections in this Privacy Policy to see details about with whom your personal information is shared and for what purpose.
4. Purpose of Processing Personal Information
Refer to the “Use of Personal Data” section in this Privacy Policy to understand why we process your personal information.
5. Your Data Privacy Rights
You have the right to:
- Obtain confirmation of processing activities on your personal information.
- Access your personal information.
- Have incomplete, inaccurate, or outdated personal information rectified.
- Request the anonymization, blocking, or deletion of unnecessary or excessive personal information or information not processed in compliance with the LGPD.
- Obtain information on the possibility of providing or denying your consent and the consequences.
- Learn about the third parties with whom we share your personal information.
- Request the portability of your personal information to another service or product provider, safeguarding our commercial and industrial secrets.
- Request the deletion of personal information processed based on your consent, unless exceptions in art. 16 of the LGPD apply.
- Revoke your consent at any time.
- Lodge a complaint with the ANPD (National Data Protection Authority) or consumer protection bodies.
- Oppose processing activities not compliant with the law.
- Request clear information on the criteria and procedures for automated decisions.
- Request a review of decisions made solely on automated processing affecting your interests, including decisions defining your personal, professional, consumer, and credit profile or personality aspects.
You will not be discriminated against or suffer any detriment for exercising your rights.
6. How to file a request
You or your legal representative can file a request to exercise your rights free of charge using the contact details in this Privacy Policy. We strive to respond promptly. If unable to do so, we will communicate the reasons. If we are not processing your personal information, we will direct you to the appropriate person if possible.
For access or processing confirmation requests, specify if you want your personal information delivered electronically or in print and if you need an immediate simplified response or a complete disclosure. For complete disclosures, we’ll respond within 15 days, providing information on the origin of your personal information, confirmation of records, processing criteria, and purposes, while protecting our commercial and industrial secrets.
For rectification, deletion, anonymization, or blocking requests, we will notify third parties with whom we shared your information, except where impossible or involving disproportionate effort.
7. Transfer of personal information outside of Brazil
We may transfer your personal information outside Brazil under LGPD. For more details, contact us using the information in this Privacy Policy.
O. SUPPLEMENTAL PROVISIONS FOR RESIDENTS OF TURKIYE; LEGAL BASIS FOR PROCESSING PERSONAL DATA UNDER KVKK
If you are a resident of Turkiye, the following provisions will also apply to you.
1. What Kind of Personal Information Do We Collect?
The personal data we collect includes:
- contact information such as your email address, first name, last name (in case your user name contains your name)
- user picture or “avatar” (in case it contains your personally identifiable information);
- details of your correspondence with us;
- technical information, such as your Internet Protocol (IP) address used to connect your computer to the internet, your login information, browser type and version, screen resolution, flash version, time zone setting, browser plug-in types and versions, operating system, platform and traffic data, cookies data, web logs and other communication data, and details of the resources that you access, as well as your sessions records, which we collect from you when you access the Platform; and
- any other information you provide to us.
Please check the sections of this Privacy Policy named “Types of Data Collected Directly By Richie”, “Types of Data Collected from Third-Party Social Networks” and “Service Providers Processing Personal Data on Our Behalf” for more information about the Personal Data we collect.
2. What Lawful Reasons Do We Have to Process Personal Data?
We collect and process your Personal Data one or more of the below-listed reasons:
- Contract – We may process personal data to fulfill our contractual obligations with you and/or your employer.
- Consent – We may rely on your freely given consent at the time you provide your personal data to us.
- Legitimate interests – We may rely on legitimate interests based on our assessment that the processing is fair, reasonable and balanced.
- Legal obligations and public interest – We may process personal data to fulfill legal obligations.