Privacy Policy

Effective Date: September 1, 2023

WHO WE ARE AND WHAT WE DO

ChatThreads Corp. DBA Purchased (“Purchased,” “us,” “we,” or “our”) is committed to protecting the privacy of users (“user,” “you” or “your”) of (a) its websites, including Purchased.com, Shopalongapp.com and affiliated sub-domains (collectively, the “Site”); (b) mobile applications, including the Shopalong and affiliated mobile applications (collectively, “Mobile Apps”); (c) surveys or other research opportunities offered on the Site or Mobile Apps, or hosted on a third-party website for one of our clients (“Surveys”); (d) sweepstakes or other incentive programs administered by Purchased (“Incentives”); (e) SMS (short messaging service) alert programs (collectively, "SMS Alerts"), and (f) any other products or services offered under the Purchased, Shopalong and/or Why Not Buy brands (collectively, and inclusive of all capitalized terms in this list, the “Services”).

This Privacy Policy governs data collection and usage associated with the Services. By accessing, browsing and/or using the Services, whether you (a) are a “visitor” (which means that you simply browse the Services), (b) are a “registered user” (which means that you have registered with Purchased), or (c) complete a Survey hosted on a third-party website, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

This Privacy Policy is incorporated into and is subject to our Terms of Use. If you do not agree with this Privacy Policy, do not use the Services.

WHAT PERSONAL INFORMATION DOES PURCHASED COLLECT?

Information You Actively Submit

In order to engage with us beyond simply surfing the Site or a Mobile App (for example, by registering, filling out a Survey, inquiring about our Services, registering for SMS Alerts or contacting us), you may be required to provide information which may personally identify you, such as your name, email address, mailing address, and/or mobile phone number (“Personal Information”). In each case, you know what Personal Information we collect, because you will actively submit the information.

Information We May Passively Collect

If you choose to participate in certain Surveys, we will collect additional information about your activities on your device, including but not limited to all webpages that you visit on the device and apps that you use on the device. Participation in Surveys that require this additional information is optional.  

Location Information, IP Addresses, Invitation URLs

If you visit the Site or interact with our Services on your mobile device, and your device is configured to allow it, we may also collect geolocation data. Otherwise, we only collect location data from individuals who explicitly agree to share it with us. Your location data will not be sent to us beyond the Survey participation period. We will not share your location data on an individually identifiable basis. You have the ability to stop location sharing by opting out of the Survey. When you fill out a Survey on the Site, or on a third-party website, we may also collect internet protocol (“IP”) addresses and/or the Uniform Resource Locator ("URL") on which you were invited to complete a Survey in order to help assess fraudulent Surveys, and to administer and operate the Surveys. 

We restrict access to and disclose Personal Information to Purchased employees and third parties acting as either our agents or service providers who need to know that Personal Information in order to perform their functions for Purchased. These third parties are prohibited from using your Personal Information for any other purpose, and have committed to meeting data protection obligations which are at least as restrictive as those contained in this Privacy Policy.

Awarding of prizes from Incentives may result in your contact details being passed onto a third party (e.g., Amazon or PayPal) in order for the prize to be sent out to you electronically.

If you indicate consent to sharing your feedback and contact information with third-party companies (such as retailers or manufacturers) as part of your participation in SMS Alerts or Surveys and use of our Mobile Apps then we will provide your feedback and contact information with the third-party companies you designate. 

Except as otherwise stated herein, we will not rent, sell, or otherwise release your Personal Information to third parties without your explicit permission.

Notwithstanding the foregoing, we may transfer, sell or assign information concerning your use of the Services, including without limitation Personal Information, to third parties, as a result of the sale, merger, consolidation, change in control, transfer of substantial assets, reorganization or liquidation of Purchased, provided that said third parties agree to abide by our Privacy Policy as it applies to Personal Information.

Registration Information

Only users who are direct participants in marketing programs with Purchased or our business partners are required to complete a registration form in order to complete our Surveys. During this registration process we will ask for Personal Information, as well as demographic information, such as age, sex, income level, and educational and racial/ethnic background (“Demographic Information”).

No Requirement to Submit Personal Information

You may choose not to provide us with any Personal Information; however, if you do so you may not be able to access and use all of the Services. The results that we send to our clients and/or provide to research participants do not include Personal Information.

Legally Required Uses

Purchased may be required to disclose personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements. We reserve the right to disclose your Personal Information as required by law and when we believe that disclosure is necessary to: (a) comply with a judicial proceeding, court order, or legal process; (b) protect our rights or property; (c) enforce our Terms of Use; (d) detect, prevent, or otherwise address fraud, security or technical issues; (e) operate or conduct maintenance and repair of our services or equipment, as authorized by law; or (f) protect against imminent harm to the rights, property or safety of the Services, users or the public, as required or permitted by law. 

 SUMMARY - WHAT WE DO WITH INFORMATION WE COLLECT FROM YOU OR ABOUT YOU


WHAT STEPS DOES PURCHASED TAKE TO PROTECT PRIVACY?

We take reasonable steps to safeguard Personal Information we collect from unauthorized access or disclosure, or accidental loss, alteration or destruction. Personal Information is encrypted during transmission using secure socket layer technology (“SSL”), and is also encrypted while at rest. Unfortunately, no data transmission or electronic storage is guaranteed to be 100% secure. While we strive to use commercially acceptable means to protect your Personal Information, we cannot ensure or warrant the security of any information you transmit to us, and you do so at your own risk.

Purchased will offer EU, UK and Swiss individuals whose personal information has been transferred to us the opportunity to choose whether the personal information it has received is to be used for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual. An individual may opt-out of such uses of their personal information by contacting us at privacy (at) purchased (dot) com.

SHARING OF PERSONAL INFORMATION WITH THIRD PARTIES

We restrict access to and disclose Personal Information to Purchased employees and third parties acting as either our agents or service providers who need to know that Personal Information in order to perform their functions for Purchased. These third parties are prohibited from using your Personal Information for any other purpose, and have committed to meeting data protection obligations which are at least as restrictive as those contained in this Privacy Policy.

Awarding of prizes from Incentives may result in your contact details being passed onto a third party (e.g., Amazon, Tango Rewards, PayPal, etc.) in order for the prize to be sent out to you electronically.

If you indicate consent to sharing your feedback and contact information with third-party companies (such as retailers or manufacturers) as part of your participation in SMS Alerts, emails or Surveys and use of our Mobile Apps then we will provide your feedback and contact information with the third-party companies you designate. 

Except as otherwise stated herein, we will not rent, sell, or otherwise release your Personal Information to third parties without your explicit permission.

Notwithstanding the foregoing, we may transfer, sell or assign information concerning your use of the Services, including without limitation Personal Information, to third parties, as a result of the sale, merger, consolidation, change in control, transfer of substantial assets, reorganization or liquidation of Purchased, provided that said third parties agree to abide by our Privacy Policy as it applies to Personal Information.

HOW LONG DOES PURCHASED RETAIN INFORMATION?

We retain information in anonymized form indefinitely for benchmarking purposes (i.e., so that we can compare Survey results against aggregate data), and in pseudonymized form for the purpose of associating an initial survey with a follow-up survey. If you register as a Shopalong user, we keep your registration information, including Personal Information, for as long as your account is active. We do this to administer Incentives, to facilitate your repeated participation in Surveys, and for fraud detection services. If you wish to cancel your account or request that we no longer use your information, contact us using the “Contact Information” below. Notwithstanding the foregoing, we reserve the right to retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

HOW DO USERS UPDATE THEIR INFORMATION?

If you wish to delete, correct, or update information previously provided to us, you may do so by logging into your account and changing the information, or by contacting us at the information in the “Contact Information” section below. We commit to responding to your request for access to modify or delete your information without undue delay, and in any event within thirty (30) days.

HOW DO USERS LIMIT THE USE AND DISCLOSURE OF THEIR PERSONAL DATA?

To limit the use and disclosure of your personal data, please use the “Contact Information” below to request that we no longer use your information and to cancel your account. Notwithstanding the foregoing, we reserve the right to retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

CHILDREN & MINORS

We operate in compliance with the Children’s Online Privacy Protection Act (“COPPA”), under the enforcement authority of the US Federal Trade Commission (“FTC”). We do not knowingly collect, use or disclose information from children under the age of 13 online without permission from a parent or guardian in the manner required by law. We also do not “sell” (as defined in CCPA) the personal information of persons under 16 without affirmative authorization). For more information on COPPA, please visit  http://www.ftc.gov/ogc/coppa1.htm.  

If you are a California resident who is 16 years of age or older, you have the right to direct us to not sell your personal information. We do not knowingly sell such information unless we receive an opt-in from the Consumer who is at least 13 but under 16, or from the parent or guardian of a Consumer younger than 13. Consumers who opt-in to the sale of their personal information may opt out at any time. If you think we may have unknowingly collected personal information for sale relating to yourself or of your child under the age of 13, or if you are at least 13 but under 16, please exercise your (or your child’s) right to opt out of such sale (per the instructions in the “HOW DO USERS LIMIT THE USE AND DISCLOSURE OF THEIR PERSONAL DATA?”  section above).

THIRD-PARTY LINKS

Services may contain links to third-party web sites. The linked sites are not under our control, and we are not responsible for the contents or use of any linked site. We provide these links as a convenience only, and a link does not imply endorsement or sponsorship of, or association or affiliation with, the linked site. If you decide to access linked third-party web sites, you do so at your own risk.

YOUR RIGHTS UNDER THE DATA PRIVACY FRAMEWORK

Purchased complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Purchased has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF.  Purchased has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.  If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern.  To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/


Purchased is registered under the EU-U.S. Data Privacy Framework ("DPF"), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, and accordingly is committed to the DPF Principles and is under the enforcement authority of the Federal Trade Commission. For a list of all companies participating in DPF, see here: https://www.dataprivacyframework.gov/s/participant-search.

Purchased shall remain liable under the EU-U.S. Data Privacy Framework ("DPF"), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF for Onward Transfer if its sub-processors process your Personal Information in a manner inconsistent with the DPF, unless we prove we are not responsible for the event giving rise to the damage.

If you are visiting this website from a country other than the country in which our servers are located, your communications with us will result in the transfer of information across international boundaries. By visiting this website and communicating electronically with us, you consent to such cross-border transfers. In the case of data transfers from the European Economic Area the EU-U.S. DPF applies.

If we share your Personal Information with third-party service providers and/or processors, we will: (a) transfer such Personal Information only for limited and specified purposes; (b) require the processor to provide at least the same level of privacy protection as is required by this Privacy Policy; (c) take reasonable and appropriate steps to ensure that the processor effectively processes the Personal Information transferred in a manner consistent with the obligations under this Privacy Policy; (d) require the processor to notify us if it determines it can no longer meet its obligation to provide the same level of protection as is required by this Privacy Policy; (e) upon notice, take reasonable and appropriate steps to stop and remediate unauthorized processing; and (f) provide a summary or a copy of the relevant privacy provisions of its contract with that processor to the Department of Commerce upon request.

The privacy laws of some jurisdictions (e.g. California, Virginia, and the European Union) define personally identifying information broadly to include the de-identified feedback you provide to us in Research Studies; even when it is impractical for us to reveal your identity with such information. Some jurisdictions (namely, the European Union and some states in the United States e.g. California, Utah, Virginia, Colorado, and Connecticut) also recognize a subset of personal information that is referred to as “sensitive personal information” or “special categories of personal data”. Examples of “sensitive personal information” include your ethnicity, religious beliefs, and sexual preferences. At any time, you may contact us (see Contact Information section below) to send us requests related to your privacy.  When you make a privacy request, please be aware that it is often impossible to match your name, email, and other identifying information to records in our system because you may have entered into our system in a de-identified manner and we use best efforts to preserve your anonymity or pseudonymity in such instances.  Nevertheless, we will use good faith efforts to find a record that matches you and, if found, we will process your request in accordance with applicable laws, industry customs, and our privacy policies. 

CONTACT INFORMATION 

Purchased is subject to the investigatory and enforcement authority of the FTC.   

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Purchased commits to resolve DPF Principles-related complaints about our collection and use of your personal information.  EU and UK individuals and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Purchased at:

Attn: Privacy Department
Purchased Corporation
31 St. James Ave
6th Floor
Boston, MA 02116
USA

URL: https://www.purchased.com
E-mail: privacy (at) purchased (dot) com
Phone: 617-209-4319
Fax: 617-249-0238

DISPUTE RESOLUTION

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Purchased commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to ICDR®/AAA®, an alternative dispute resolution provider based in the United States. Under certain conditions, you may have the right to invoke binding arbitration.  If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://www.icdr.org/dpf for more information or to file a complaint.  The services of ICDR®/AAA® are provided at no cost to you.

All disputes arising under this Privacy Policy shall be governed by and interpreted in accordance with the laws of Massachusetts, without regard to principles of conflict of laws. The parties to this Privacy Policy will submit all disputes arising under this agreement to arbitration in Boston, Massachusetts, before a single arbitrator of the ICDR®/AAA®. The arbitrator shall be selected by application of the rules of the ICDR®/AAA®., or by mutual agreement of the parties, except that such arbitrator shall be an attorney admitted to practice law Massachusetts. No party to this Privacy Policy will challenge the jurisdiction or venue provisions as provided in this section. Nothing contained herein shall prevent the party from obtaining an injunction.

CLASS ACTION WAIVER

Any arbitration or court trial, whether before a judge or jury or pursuant to judicial reference, related to any claim under this Privacy Policy will take place on an individual basis, without resort to any form of class or representative action (“Class Action Waiver”). THIS CLASS ACTION WAIVER PRECLUDES ANY PARTY FROM PARTICIPATING IN OR BEING REPRESENTED IN ANY CLASS OR REPRESENTATIVE ACTION REGARDING A CLAIM UNDER THIS POLICY. Regardless of anything else herein, the validity and effect of the Class Action Waiver may be determined only by a court and not by an arbitrator.

NOTICE TO RESIDENTS OF CALIFORNIA AND CANADA

If you are a California resident, you have the right to request and receive information about the Personal Information (if any) we disclosed to third parties for direct marketing purposes in the preceding calendar year. If applicable, this information would include a list of the categories of Personal Information that was shared and the names and addresses of all third parties with which we shared the Personal Information.

If you are a Canadian resident, please note that any Personal Information you provide to us may be transferred to our offices in the U.S. You agree that by providing us with your Personal Information, your Personal Information may be subject to U.S. laws, regulations and/or court orders and may be disclosed to third parties or U.S. authorities in complying with U.S. laws, regulations and/or court orders.

CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time by posting an amended version of the statement. Please refer to this policy regularly.