We use Shopify / Shopify-Plus (collectively, “Shopify”) as the e-commerce shopping cart solution on our Website.
Shopify is certified as a PCI DSS Level 1 compliant service provider, and follows industry standards on information security management to safeguard sensitive information, such as financial information, intellectual property, employee details and any other personal information entrusted to Shopify.
How Long Do We Store Your Personal Information?
We will retain your personal information for as long as needed to fulfill the purposes for which it was collected. We also will retain and use your personal information as long as necessary to comply with our business requirements, legal obligations, resolve disputes, protect our assets, provide our services, and enforce our agreements.
When we no longer have a purpose to retain your personal information, we will security destroy your personal information in accordance with applicable law and our policies. We take reasonable steps to delete the personal information we collect if you ask us to delete your information, unless we determine that doing so would violate our existing, legitimate legal, regulatory, dispute resolution, contractual, or similar obligations. To the extent permitted by law, we may retain and use anonymous and aggregated information for performance reporting, benchmarking, and analytic purposes and for product and service improvement.
Security Of Your Personal Information
We maintain appropriate technical and organizational measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorized manner, altered or disclosed during collection, storage, and processing. While our security measures seek to protect your personal information in our possession, no security system is perfect and we cannot guarantee that your personal information will remain absolutely secure in all circumstances or that any privacy settings or security measures contained on the Website cannot be circumvented.
The majority of communications on our Site, including any submissions through available forms, are sent through the standard HTTP protocol and may be delivered using regular e-mail. Information sent over HTTP is not encrypted. E-mail, while convenient, does pose some risks (e.g., e-mail is not a secure form of communication, is unreliable, can be forwarded, etc.). The safety and security of your personal information also depends on you. Where you use a password for access to restricted parts of the Website, you are responsible for keeping the password confidential. Do not share your password with anyone.
If a security breach causes an unauthorized intrusion into our Site or systems that compromises your data, we will notify you and any applicable regulator when we are required to do so by applicable law.
Updating Your Personal Information
If you of the personal information you have provided to us changes, please let us know. For instance, if your email changes, you wish to cancel any request you have made of us, or if you become aware of inaccurate personal information about you, use our Contact Us details to update your information. You may also edit your account details if you have a user account through our site.
We are not responsible for any losses arising from any inaccurate, inauthentic, deficient or incomplete personal data that you provide to us.
Your Rights To Access And Control Your Personal Information
Please use the Contact Us details at the end of this Policy to exercise your rights and choices under this Policy.
Right of Access. If required by law (e.g., under the GDPR), upon request, we will grant reasonable access to the personal information that we hold about you.
Accuracy. Our goal is to keep your personal information accurate, current and complete. Please contact us if you believe your information is not accurate or changes.
Right to Object. In certain circumstances, as permitted under applicable law, you have the right to object to processing of your personal information and to ask us to erase or restrict our use of your personal information. If you would like us to stop using your personal information, please contact us and we will let you know if are able to agree to your request.
Right to Erasure and Deletion of Your Personal Information. You may have a legal right (for instance, if you are located in the EU or EEA under the GDPR) to request that we delete your personal information when it is no longer necessary for the purposes for which it was collected, or when, among other things, your personal information has been unlawfully processed. All deletion requests should be sent to the address noted in the Contact Us section of this Policy.
We may decide to delete your personal information if we believe it is incomplete, inaccurate or that our continued storage of your personal information is contrary to our legal obligations or business objectives. When we delete personal information, it will be removed from our active servers and databases and our Site, but it may remain in our archives when it is not practical or possible to delete it. We may also retain your personal information as needed to comply with our legal obligations, resolve disputes, or enforce any agreements.
Right to Withdraw Consent. If you have provided your consent to the collection, processing and transfer of your personal information, you have the right to fully or partially withdraw your consent. To withdraw your consent, please notify us using the information in the Contact Us section of this Policy and you may follow opt-out links on any marketing communications sent to you.
Once we have received notice that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there are compelling legitimate grounds for further processing that override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims. Withdrawal of consent to receive marketing communications will not affect the processing of personal information for the provision of our services.
Right to Complain. If you believe that your rights relating to your personal information have been violated, you have a right to lodge a complaint with the applicable enforcement or supervisory authority, or seek a remedy through the courts. You may also lodge a complaint with us by contacting us using the information provided in the Contact Us section of this Policy.
We do not currently recognize browser settings or signals of tracking preferences, which may include “Do Not Track” instructions.
California Residents. California residents may be entitled to ask us for a notice describing what categories of personal information (if any) we share with third parties or affiliates for those parties to use for direct marketing. If you are a California resident and would like a copy of such notice, please submit a written request to us using the information in the “Contact Us” section of this Policy.
European Union or European Economic Area Residents. If you are located in the EU or EEA and believe we have not processed your personal information in accordance with applicable provisions of the EU GDPR, you may lodge a complaint with your local data protection or supervisory authority.
Your California Privacy Rights
Under California Civil Code Section 1798.83, California residents who provide personal information in obtaining products or services for personal, family, or household use may be entitled to request and obtain from us once a calendar year information about the information we shared, if any, with other businesses for direct marketing uses. At present, we do not share your personal information with third parties for those third parties’ direct marketing purposes. Please be aware that not all information sharing is covered by the “Shine the Light” requirements and only information on covered sharing, if any, will be included in our response. As part of the California Online Privacy Protection Act, all users of the Site may make any changes to their information at any time by contacting us at email@example.com.
Cross-Border Transfers of Personal Information
We are located and established in the United States and therefore, your personal information may be transferred to, stored or processed in the United States. While the data protection, privacy and other laws of the United States might not be as comprehensive as those in your country, we take necessary and appropriate steps to protect the security and privacy of your personal information.
Children’s Online Privacy Protection Act
The Children’s Online Privacy Protection Act (“COPPA”), as well as other data privacy regulations, restrict the collection, use, or disclosure of personal information from and about children on the Internet. Our Site and services are not directed to children aged 13 or younger, nor is information knowingly collected from children under the age of 13. No one under the age of 13 may access, browse, or use the Site or provide any information to or on the Site. If you are under 13 years of age, please do not use or provide any information on the Site (including, for example, your name, telephone number, email address, and username). If we learn that we have collected or received personal information from a child under the age of 13 without a parent’s or legal guardian’s consent, we will take steps to stop collecting that information and delete it. If you believe we might have any information from or about a child under the age of 13 without his/her parent’s consent, please contact us using the contact information provided below.
For more information about COPPA, please visit the Federal Trade Commission’s website at: https://www.ftc.gov/enforcement/rules/rulemaking-regulatory-reform-proceedings/childrens-online-privacy-protection-rule.
Links To Other Sites
This Policy is applicable only to True Citrus and the specific processing activities defined in this Policy. It does not apply to any third-party websites.
This Site may contain links to, and media and other content from, third party websites. These links are to external websites and third parties with which we have no relationship. If you click on an embedded third-party link, you will be redirected away from this Website to the external third-party website. You can check the URL to confirm that you have left this Website.
We cannot and do not (i) guarantee the adequacy of privacy, security, practice content or media provided by third parties or their websites, (ii) control third parties’ independent collection or use or your personal information, or (iii) endorse any third party information, products, services or websites that may be reached through embedded links on this Site.
The Site is controlled and operated from the United States. If any materials on the Site are contrary to the laws of the place where you are when you access them, then we ask you not to use the Site. You are responsible for informing yourself of the laws of your jurisdiction and complying with them. By using the Site, you consent to the transfer of information to the United States, which may have different data protection rules than those of your country.
Updates And Changes To This Policy
We reserve the right, at any time and without notice, to add to, change, update, or modify this Policy to reflect any changes to the way in which we treat your personal information or in response to changes in law. Should this Policy change, we will post all changes we make to this Policy on this page. If we make material changes to how we treat your personal information, we will also notify you through a notice on the home page of the Site for a reasonable period of time. Any such changes, updates, or modifications shall be effective immediately upon posting on the Site. The date on which this policy was last modified is identified at the beginning of this Policy.
You are expected to, and you acknowledge and agree that it is your responsibility to, carefully review this Policy prior to using the Site, engaging with us on social media, or communicating with us, from time to time, so that you are aware of any changes. Your continued use of the Site, engaging with us on social media, or communicating with us in any format after the “Last Updated” date will constitute your acceptance of and agreement to such changes and to our collection and sharing of your personal information according to the terms of the then-current Policy.
How To Contact Us
U.S. postal address:
Attn: True Citrus Consumer Affairs
True Citrus Company
11501 Pocomoke Court
Baltimore, Maryland 21220