1. INFORMATION WE COLLECT
There are three general categories of information we collect.
1. Information You Give to Us.
1.1. Information that is necessary for the use of the Moltin Platform.
We ask for and collect the following personal information about you when you use the Moltin Platform. This information is necessary for the adequate performance of the contract between you and us and to allow us to comply with our legal obligations. Without it, we may not be able to provide you with all the requested services.
- Account Information. When you sign up for a Moltin Account, we require information including your first name, last name, and email address.
- Payment Information. To use certain features of the Moltin Platform (such as booking or creating a Listing), we may require you to provide financial information including your bank account or credit card information in order to facilitate the processing of payments.
- Log Data and Device Information. We automatically collect log data and device information when you access and use the Moltin Platform, even if you have not created a Moltin Account or logged in. That information includes details about how you’ve used the Moltin Platform (including if you clicked on links to third party applications), IP address, access dates and times, hardware and software information, device information, device event information, unique identifiers, crash data, cookie data, and the pages you’ve viewed or engaged with before or after using the Moltin Platform.
1.1.2. Information you choose to give us.
You may choose to provide us with additional personal information in order to obtain a better user experience when using Moltin Platform. This additional information will be processed based on your consent.
- Additional Profile Information. You may choose to provide additional information as part of your Moltin profile (such as company, project name, address, or phone number).
- Other Information. You may otherwise choose to provide us information when you fill in a form, conduct a search, update or add information to your Moltin Account, respond to surveys, post to community forums, participate in promotions, or use other features of the Moltin Platform.
1.2. Information We Collect from Third Parties.
Moltin may collect information, including personal information, that others provide about you when they use the Moltin Platform, or obtain information from other sources and combine that with information we collect through the Moltin Platform. We do not control, supervise or respond for how the third parties providing your information process your personal data, and any information request regarding the disclosure of your personal information to us should be directed to such third parties.
- Other Sources. To the extent permitted by applicable law, we may receive additional information about you, such as demographic data or fraud detection information, from third party service providers and/or partners, and combine it with information we have about you. For example, we may receive fraud warnings from service providers like identity verification services for our fraud prevention and risk assessment efforts. We may receive information about you and your activities on and off the Moltin Platform through partnerships, or about your experiences and interactions from our partner ad networks.
2. HOW WE USE INFORMATION WE COLLECT
We use, store, and process information, including personal information, about you to provide, understand, improve, and develop the Moltin Platform, create and maintain a trusted and safer environment and comply with our legal obligations.
2.1. Provide, Improve, and Develop the Moltin Platform.
- Enable you to access and use the Moltin Platform.
- Enable you to communicate with other Members.
- Operate, protect, improve, and optimize the Moltin Platform and experience, such as by performing analytics and conducting research.
- Provide customer service.
- Send you service or support messages, updates, security alerts, and account notifications.
- If you provide us with your contacts’ information, we may process this information: (i) to facilitate your referral invitations, (ii) send your requests for references, (iii) for fraud detection and prevention, and (iv) for any purpose you authorize at the time of collection.
- To operate, protect, improve, and optimize the Moltin Platform and experience, and personalize and customize your experience (such as making Listing suggestions or ranking search results), we conduct profiling based on your interactions with the Moltin Platform, your search and booking history, your profile information and preferences, and other content you submit to the Moltin Platform.
We process this information given our legitimate interest in improving the Moltin Platform and our Members’ experience with it, and where it is necessary for the adequate performance of the contract with you.
2.2. Create and Maintain a Trusted and Safer Environment.
- Detect and prevent fraud, spam, abuse, security incidents, and other harmful activity. Conduct security investigations and risk assessments.
- Comply with our legal obligations.
- Resolve any disputes with any of our Members and enforce our agreements with third parties.
- Enforce our Terms of Service and other policies.
- In connection with the activities above, we may conduct profiling based on your interactions with the Moltin Platform, your profile information and other content you submit to the Moltin Platform, and information obtained from third parties. In limited cases, automated processes may restrict or suspend access to the Moltin Platform if such processes detect a Member or activity that we think poses a safety or other risk to the Moltin Platform, other Members, or third parties.
We process this information given our legitimate interest in protecting the Moltin Platform, to measure the adequate performance of our contract with you, and to comply with applicable laws.
2.3. Provide, Personalize, Measure, and Improve our Advertising and Marketing.
- Send you promotional messages, marketing, advertising, and other information that may be of interest to you based on your preferences (including information about Moltin or partner campaigns and services) and social media advertising through social media platforms such as Facebook or Google).
- Personalize, measure, and improve our advertising.
- Administer referral programs, rewards, surveys, sweepstakes, contests, or other promotional activities or events sponsored or managed by Moltin or its third party partners.
- Conduct profiling on your characteristics and preferences (based on the information you provide to us, your interactions with the Moltin Platform, information obtained from third parties, and your search and booking history) to send you promotional messages, marketing, advertising and other information that we think may be of interest to you.
- We will process your personal information for the purposes listed in this section given our legitimate interest in undertaking marketing activities to offer you products or services that may be of your interest. You can opt-out of receiving marketing communications from us.
3. SHARING & DISCLOSURE
3.1. With Your Consent.
Where you have provided consent, we share your information, including personal information, as described at the time of consent, such as when you participate in promotional activities conducted by Moltin partners or third parties.
3.2. Compliance with Law, Responding to Legal Requests, Preventing Harm and Protection of our Rights.
Moltin may disclose your information, including personal information, to courts, law enforcement or governmental authorities, or authorized third parties, if and to the extent we are required or permitted to do so by law or if such disclosure is reasonably necessary: (i) comply with our legal obligations, (ii) to comply with legal process and to respond to claims asserted against Moltin, (iii) to respond to verified requests relating to a criminal investigation or alleged or suspected illegal activity or any other activity that may expose us, you, or any other of our users to legal liability, (iv) to enforce and administer our Terms of Service, the Payment Terms or other agreements with Members, or (v) to protect the rights, property or personal safety of Moltin, its employees, its Members, or members of the public.
Where appropriate, we may notify Members about legal requests unless: (i) providing notice is prohibited by the legal process itself, by court order we receive, or by applicable law, or (ii) we believe that providing notice would be futile, ineffective, create a risk of injury or bodily harm to an individual or group, or create or increase a risk of fraud upon Moltin’s property, its Members and the Moltin Platform. In instances where we comply with legal requests without notice for these reasons, we will attempt to notify that Member about the request after the fact where appropriate and where we determine in good faith that we are no longer prevented from doing so.
3.3. Service Providers.
Moltin uses a variety of third party service providers to help us provide services related to the Moltin Platform. Service providers may be located inside or outside of the European Economic Area (“EEA”). In particular, our service providers are based in Europe, India, Asia Pacific and North and South America.
Moltin will need to share your information, including personal information, in order to ensure the adequate performance of our contract with you.
3.4. Corporate Affiliates.
To enable or support us in providing the Moltin Platform, we may share your information, including personal information, within our corporate family of companies (both financial and non-financial entities) that are related by common ownership or control.
Additionally, we share your information, including personal information, with our corporate affiliates in order to support and integrate, promote, and to improve the Moltin Platform and our affiliates’ services.
3.5. Social Media Platforms.
Where permissible according to applicable law we may use certain limited personal information about you, such as your email address, to hash it and to share it with social media platforms, such as Facebook or Google, to generate leads, drive traffic to our websites or otherwise promote our products and services or the Moltin Platform. These processing activities are based on our legitimate interest in undertaking marketing activities to offer you products or services that may be if your interest.
The social media platforms with which we may share your personal data are not controlled or supervised by Moltin. Therefore, any questions regarding how your social media platform service provider processes your personal data should be directed to such provider.
Please note that you may, at any time ask Moltin to cease processing your data for these direct marketing purposes by sending an e-mail to firstname.lastname@example.org.
3.6. Business Transfers.
3.7. Aggregated Data.
We may also share aggregated information (information about our users that we combine together so that it no longer identifies or references an individual user) and other anonymized information for regulatory compliance, industry and market analysis, demographic profiling, marketing and advertising, and other business purposes.
3.8. Transfer of Your Information Out of the EEA.
We may transfer your personal information to the following which are located outside the European Economic Area (EEA) as follows:
|Chartio||United States||Internal Analytics|
|Segment||United States||Marketing, Analytics, and Communication|
|Intercom||United States||Marketing, and Communication|
|Mautic||United States||Marketing, and Communication|
Such countries do not have the same data protection laws as the United Kingdom and EEA. Whilst the European Commission has not given a formal decision that such countries provide an adequate level of data protection similar to those which apply in the United Kingdom and EEA, any transfer of your personal information will be subject to appropriate and suitable relevant safeguards, including our Data Processing Addendum (available here https://moltin.com/terms/dpa (as permitted under Article 46(3)(a) of the General Data Protection Regulation that are designed to help safeguard your privacy rights and give you remedies in the unlikely event of a misuse of your personal information.
If you would like further information please contact our Data Protection Officer (see Section 8 below). We will not otherwise transfer your personal data outside of the United Kingdom or EEA or to any organization (or subordinate bodies) governed by public international law or which is set up under any agreement between two or more countries.
4. YOUR RIGHTS
You may exercise any of the rights described in this section before your applicable Moltin Data Controller by sending an email to email@example.com. Please note that we may ask you to verify your identity before taking further action on your request.
Under the General Data Protection Regulation you have a number of important rights free of charge. In summary, those include rights to:
- Access to your personal information and to certain other supplementary information that this Privacy Notice is already designed to address
- Require us to correct mistakes in your information which we hold
- Require the erasure of personal information concerning you in certain situations
- Receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
- Object at any time to processing of personal information concerning you for direct marketing
- Object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
- Object in certain other situations to our continued processing of your personal information
- Otherwise restrict our processing of your personal information in certain circumstances
For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals’ rights under the General Data Protection Regulation.
If you would like to exercise any of those rights, please:
- Email, call, or write to our Data Protection Officer at the contact details provided in Section 8 below.
- Let us have enough information to identify you (e.g., account number, user name, registration details)
- Let us have proof of your identity and address (a copy of your driving license or passport and a recent utility or credit card bill)
- Let us know the information to which your request relates including any account or reference numbers, if you have them
4.1. Managing Your Information.
You may access and update some of your information through your Account settings. You are responsible for keeping your personal information up-to-date.
4.2. Rectification of Inaccurate or Incomplete Information.
You have the right to ask us to correct inaccurate or incomplete personal information concerning you (and which you cannot update yourself within your Moltin Account).
4.3. Data Access and Portability.
In some jurisdictions, applicable law may entitle you to request copies of your personal information held by us. You may also be entitled to request copies of personal information that you have provided to us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible).
4.4. Data Retention and Erasure.
We generally retain your personal information for as long as is necessary for the performance of the contract between you and us and to comply with our legal obligations. If you no longer want us to use your information to provide the Moltin Platform to you, you can request that we erase your personal information and close your Moltin Account. Please note that if you request the erasure of your personal information:
- We may retain some of your personal information as necessary for our legitimate business interests, such as fraud detection and prevention and enhancing safety. For example, if we suspend a Moltin Account for fraud or safety reasons, we may retain certain information from that Moltin Account to prevent that Member from opening a new Moltin Account in the future.
- We may retain and use your personal information to the extent necessary to comply with our legal obligations. For example, Moltin may keep some of your information for tax, legal reporting and auditing obligations.
- Some copies of your information (e.g., log records) may remain in our database, but are disassociated from personal identifiers.
- Because we maintain the Moltin Platform to protect from accidental or malicious loss and destruction, residual copies of your personal information may not be removed from our backup systems for a limited period of time.
4.5. Withdrawing Consent and Restriction of Processing.
Where you have provided your consent to the processing of your personal information by Moltin you may withdraw your consent at any time by changing your Account settings or by sending a communication to Moltin specifying which consent you are withdrawing.
Please note that the withdrawal of your consent does not affect the lawfulness of any processing activities based on such consent before its withdrawal. Additionally, in some jurisdictions, applicable law may give you the right to limit the ways in which we use your personal information, in particular where (i) you contest the accuracy of your personal information; (ii) the processing is unlawful and you oppose the erasure of your personal information; (iii) we no longer need your personal information for the purposes of the processing, but you require the information for the establishment, exercise or defence of legal claims; or (iv) you have objected to the processing pursuant to Section 4.6 and pending the verification whether the legitimate grounds of Moltin override your own.
4.6. Objection to Processing.
In some jurisdictions, applicable law may entitle you to require Moltin not to process your personal information for certain specific purposes (including profiling) where such processing is based on legitimate interest. If you object to such processing Moltin will no longer process your personal information for these purposes unless we can demonstrate compelling legitimate grounds for such processing or such processing is required for the establishment, exercise or defence of legal claims.
Where your personal information is processed for direct marketing purposes, you may, at any time ask Moltin to cease processing your data for these direct marketing purposes by sending an e-mail to firstname.lastname@example.org.
4.7. Lodging Complaints.
You have the right to lodge complaints about the data processing activities carried out by Moltin before the competent data protection authorities. You have the right to file a complaint with in the UK with its lead supervisory authority, the Information Commissioner’s Office.
5. OPERATING GLOBALLY
To facilitate our global operations Moltin may transfer, store, and process your information within our family of companies or with service providers based in Europe.
We are continuously implementing and updating administrative, technical, and physical security measures to help protect your information against unauthorized access, loss, destruction, or alteration. Some of the safeguards we use to protect your information are firewalls and data encryption, and information access controls. If you know or have reason to believe that your Moltin Account credentials have been lost, stolen, misappropriated, or otherwise compromised or in case of any actual or suspected unauthorized use of your Moltin Account, please contact us following the instructions in the Contact Us section below.
8. CONTACT US
Europe: FAO Chris Roach, Moltin, 15 Carliol Square, Newcastle Upon Tyne, NE1 6UF, United Kingdom
USA: FAO Data Protection Officer, Moltin LLC, 133 Portland Street, Boston, MA, 02114