PROJECT 9A LABS PRIVACY POLICY:
KAYA and Plastick
Last modified: August 2, 2020
This privacy policy (“Policy”) informs you of practices when handling your Information through the Services (both as defined below). In this Policy, “9a Labs,” “we,” “our,” or “us” refers to Project 9a Labs Inc., a company registered in California with its registered address located at 1100 Mandana Blvd, Oakland, CA 94610. We are the data controller under the applicable privacy laws.
For the purpose of this Policy, “Information” means any information relating to an identified or identifiable individual. This includes Information you provide or generated when you use: (1) our KAYA community climbing products (the “KAYA Services”) being, (a) our KAYA-Climbing mobile application (the “App”), and (b) the KAYA climbing website at kayaclimb.com and any other dedicated KAYA websites which link to this Policy (the “KAYA Website”); and (2) our Plastick climbing routesetter tracking and management website at plastick.rocks, and any other dedicated Plastick websites which link to this Policy (the “Plastick Website,” together with the KAYA Website, the “Websites,” and together with the KAYA Services, the “Services”). When you use the Services, you accept and understand we collect, process, use, and store your Information as described in this Policy. If you do not agree with this Policy, you must not use any of the Services. If you change your mind in the future, you must stop using the Services, and you may exercise your rights in relation to your Information as set out in this Policy.
1. INFORMATION WE COLLECT
We will collect and use the following Information about you:
· Information you provide to us
Registration information: for example, when you create an account on the App, you will be asked to provide your full name, email address, username and a password. You will also be asked to provide your height and sex. You may choose to update your profile to add additional information such as your wing span or “ape index”, a profile photo, biographical information and t-shirt size. For users of the Plastick Website who choose to create an account, we collect your full name, email address, nickname and password, profile picture, as well as details of your associated gym. You may also choose to link your KAYA account.
Location data: We collect your rough location based on IP address. With your consent we collect your GPS location.
Other information you provide as you use the Services: When you use the Services, you may choose to provide additional information, including as part of the social interaction with other users. This includes images, videos, information you provide as part of social feed posts, information on routes and climbs completed and any information you provide when sending messages to other users through the Services. You can choose to share information with other users about your training, and strength, including health information. If you use the Plastick Website, you may choose to share climbing routes. These will be visible to other gym members associated with the relevant gym.
Historic climb data: You may choose to upload historic climb and ascent data, including publicly available information from other sites.
Prize payout information: If you participate in a challenge and win a prize, we and our challenge partners will request additional information from you in order for you to receive your prize, including payment and tax information.
Communication and support: When you communicate with us via the Services or otherwise, you provide us with Information such as your name, email address and the contents and nature of your correspondence with us, including technical support requests, complaints and feedback on your use of the Services.
Surveys: if you choose to participate in a survey, we will ask you to provide your email address, account details, and, depending on the survey, information on your interests and habits, your opinion about different products and services, and your ratings, opinions, preferences, pictures, and other responses to survey questions.
Please make sure you have permission from your co-workers or friends before sharing Information referring to your co-workers or friends with us, or otherwise creating Information about them on the Services, for example associating users with a particular gym on the Plastick Website.
· Information we automatically collect or is generated about you when use the Services
Identifiers, such as your IP address, device ID, device information (such as model, brand and operating system), and browser type and version. We also create an individual account ID for you.
Information regarding your use of the Services, such as App and Website use information, interactions with our team, and transaction records.
Information you generate when using the Services: When you use the Services your interactions with other users and the Services themselves will generate Information about you. Some of the users of the App are coaches as well as standard users. These coaches may upload training plans which you as a user can subscribe to. You may also choose to follow gyms and other users via the App. If you are a user of the Plastick Website, you may be added to gyms to which you are affiliated. When you interact with challenges via the App, Information will be generated, including position and points won.
Cookies: we use cookies and other similar technologies to enhance your experience when using the Services and to provide us with analytics. For more information about our use of cookies, see Cookies here.
· Information received from third parties.
Information we receive from third party platforms: when you register for the App through a third party account (such as Facebook or Google), we receive Information which may include your username, full name, email address, language preference and profile picture.
Information from platforms our Services relies on: if you subscribe to certain of our paid subscription services via the Plastick Website you will provide Information to third party payment processors such as Stripe. We receive transaction information from such third parties, and information for payment verification, including your Stripe customer ID.
We also collect, use and share aggregated data such as statistical or demographic data for our purposes. Aggregated data may be derived from your Information but is not Information as this data will not directly or indirectly reveal your identity. For example, we may aggregate data about your use of our Services to calculate the percentage of users accessing a specific feature. However, if we combine or connect aggregated data with your Information so that it can directly or indirectly identify you, we will treat the combined data as Information which will be used in accordance with this Policy.
1. HOW WE USE YOUR PERSONAL INFORMATION
We use your Information to:
· Provide you with the Services. We will use your Information to perform our contractual obligation towards you to allow you to create an account and use the Services and to subscribe to paid services should you choose to. This includes logging your climbing and workout activity on the App. The Information we process when doing so includes your registration information, information you provide to us when using the Services, identifiers, information you generate when using the Services, and information regarding your use of the Services such as transaction information. If you are a subscribed user of the Plastick Website, we will use your payment information for payment processing purposes as well as sales tax collection and reporting as required by law. If you consent, we will use your GPS location to enable you to find your closest gyms and climbing destinations.
· Allow you to participate in social features of the Services. We will use your Information to perform our contractual obligation towards you to allow you to participate in social features offered as part of the Services, if you choose to do so. This includes, on the App, allowing you to partake in challenges, share your performance and activity, chat with other users including coaches, post information on your social feed, and interact with the social feeds of others. The information we process when we do so includes registration information, and information you provide and that is generated about you when you use the Services.
· Improve and monitor the Services. It is in our legitimate interests to improve our Services for our customers, including improving the security of our Services and fixing bugs, crashes and errors. When doing so, we may collect information we automatically collect or is generated about you when you use the Services, including identifiers, as well as non-personal information about your device such as device manufacturer, model and operating system, and the amount of free space on your device.
· Provide you with support and to respond to your requests or complaints. If you reach out to us for support, we will use your Information to respond to and resolve your queries and complaints and facilitate support (e.g. retrieval of a forgotten password). When doing so, we perform our contractual obligation towards you. The Information we process when doing so includes your registration information, your identifiers, and any other information about you collected via our customer support channels.
· Deliver challenge prizes. If you partake in a challenge and win a prize or reward, we use your Information to perform our contractual obligation to send you such prize. The Information we process when doing so includes prize payout information, registration information and information you generate while using the Services.
· Market and publicize the challenges. If you partake in a challenge and are successful, it is in our legitimate interests to process and share with the relevant challenge partners your name and email address to minimize cheating and foster a fair playing field for participants, and for our challenge partners to contact you should you win.
· Conduct analytics. It is in our legitimate interests to analyze the use of, and any other interaction or interest in our Services. When doing so we will process information we automatically collect or is generated about you when you use the Services to create anonymized and aggregated data regarding your App or Website usage.
· Send you newsletters about product news, updates and promotions that may be of interest to you. We will send you emails with daily reports, newsletters with product news, and tips and tricks to use our Services. When doing so, we process your registration information and information about your Services usage. Where it is required, we will only do so where we have your consent. Your consent can be withdrawn at any time by following the unsubscribe mechanism at the bottom of each communication.
· Provide you with advertising. We will present you with ads and suggestions in our Services and elsewhere. These may be ads relating to our own Services, or other services and brands you may be interested in. If you have consented, these ads and suggestions will be tailored specifically to you. Your consent can be withdrawn at any time. In situations where your Information is not used to tailor these ads to you, we provide ads on the basis of our legitimate interests. To tailor ads we process Information we automatically collect or is generated about you when you use the Services, as well as Information you provide to us.
· Prevent fraud, defend 9a Labs against legal claims or disputes, enforce our terms and to comply with our legal obligations. It is in our legitimate interest to protect our interests by (1) monitoring the use of the Services to detect fraud or any other user behavior which prejudices the integrity of our Services, (2) taking steps to remedy aforementioned fraud and behavior, (3) defending ourselves against legal claims or disputes, and (4) enforcing our terms and policies. When doing so, we will process the Information relevant in such a case, including information you provide us, information we automatically collect about you, and information which is provided to us by third parties.
· Conduct surveys. From time to time, we may ask you to participate in surveys we conduct which are in our legitimate interest because they help us understand our userbase and improve the Services. If you participate, we process your registration information and any other information collected through the survey questions.
2. WHO WE SHARE YOUR PERSONAL INFORMATION WITH
We share your Information with selected third parties, including:
Other users who will see your profile information and social feed and any other information you choose to share with them through the Services such as photos, videos, chat content and challenge participation. Note that you can control which users see some information in the App settings.
Between Plastick Website users. Other Plastick users will have access to your name and email address, and any information on the routes chosen and set, in order to manage your account, confirm affiliation, track usage and evaluate the efficiency and safety of users.
Vendors and service providers we rely on for the provision of the Services, for example:
ü Cloud service providers who rely on for data storage, web servers and content delivery including Amazon Web Services, Salesforce and Cloudflare Inc. who are based in the U.S.;
ü Customer support solution providers, who help us manage and respond to our customer questions and complaints. This includes Freshworks Inc. who are located in the US;
ü Analytics providers. We work with a number of analytics, segmentation and mobile measurement] service providers who help us understand our userbase. This includes Google LLC and Amplitude Inc. who are based in the U.S. You can learn about Google’s practices by going to https://www.google.com/policies/privacy/partners/, and opt-out of them by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout.
ü Service improvement providers, who we work with to improve the services including by providing error and crash reporting, such as Sentry.io who are located in the US.
ü Communication tool providers, who help us communicate with you. This includes Expo and The Rocket Science Group LLC, both located in the US.
Challenge partners. If you choose to partake in a challenge and win, we will provide certain information, including your email address and name to our challenge partners.
Payment processors, such as Stripe. These payment processors are responsible for the processing of your Information and may use your Information for their own purposes in accordance with their privacy policies. More information on how Stripe uses your Information is available here.
Companies who belong to the same group as 9a Labs. We share your Information with entities in the group we belong to, to operate the Services.
Law enforcement agencies, public authorities or other judicial bodies and organizations. We disclose Information if we are legally required to do so, or if we have a good faith belief that such use is reasonably necessary to comply with a legal obligation, process or request; enforce our terms of service and other agreements, policies, and standards, including investigation of any potential violation thereof; detect, prevent or otherwise address security, fraud or technical issues; or protect the rights, property or safety of us, our users, a third party or the public as required or permitted by law (including exchanging information with other companies and organizations for the purposes of fraud protection).
Change of corporate ownership. If we are involved in a merger, acquisition, bankruptcy, reorganization, partnership, asset sale or other transaction, we may disclose your Information as part of that transaction.
Consent. We may also disclose your information with your permission.
1. COOKIES
Cookies are small text files of letters and numbers that are stored on your browser or the hard drive of your device. Our Websites use cookies, beacons, invisible tags and similar technologies (collectively, “cookies”) to collect information about your browsing activities and to distinguish you from other users of our Websites. This aids your experience when you browse our Websites, allows us to improve the functionality of our Websites, increase security, and measure use and effectiveness of our Websites.
We use the following cookies:
Strictly necessary cookies: Some cookies are strictly necessary to make our Website available to you; for example, to perform your login functionality and for user authentication and security. We cannot provide you with the Website without this type of cookies.
Functional cookies: These are used to recognize you when you return to our Website. This enables us to personalize our content for you, greet you by name and remember your account preferences.
Analytical or performance cookies: We use cookies for analytics purposes in order to operate, maintain, and improve our Website and Services. We use third party analytics providers, including Google Analytics, to help us understand how users engage with the Services. Google Analytics uses first-party cookies to track User interactions which helps show how users use our Services. This information is used to compile reports and to help us improve our Services. The reports disclose Website trends without identifying individual visitors. You can learn about Google’s practices by going to https://www.google.com/policies/privacy/partners/ and opt-out of them by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout.
You can block cookies by setting your internet browser to block some or all or cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our Website.
All cookies will expire within 2 years.
2. SECURITY
Although we have in place security measures to maintain the privacy and integrity of your Information, unfortunately, the transmission of Information via the internet is not completely secure. We may also take extra steps to protect your Information and minimize the Information we process.
Our Services may contain links to other sites that are not operated by us. If you click a third party link, you will be directed to that third party’s site. We advise you to review the privacy policy of these sites. We are not responsible for the content, privacy policies or practices of such third parties. Additionally, we are not responsible for how third party integration services may collect, use or share the Information you send from the App. Please review the privacy policy of such third party integration partners before connecting those services to the App.
3. WHERE WE STORE YOUR INFORMATION
Your Information will be processed by our employees and service providers in the U.S. We take steps to ensure all transfers are protected by adequate safeguards, including the standard contractual clauses approved by the European Commission.
4. HOW LONG WE STORE YOUR INFORMATION
Your Information is kept for as long as necessary to achieve the purpose set in this Policy, or for as long as we are required by law or in order to comply with a regulatory obligation.
When deleting Information, we will take measures to make the Information irrecoverable or irreproducible, and electronic files which contain Information will be deleted permanently.
5. YOUR RIGHTS
If you are based in Europe, in some circumstances you have certain rights in relation to your Information. You will find more information below on when which rights can apply. To exercise your rights, please contact us at [email protected]. Please note that we may ask you to verify your identity before responding to such requests.
Access. You have the right to access Information, and to receive an explanation of how we use it and who we share it with. This right is not absolute. For example, we cannot reveal trade secrets, or give you Information about other individuals.
Erasure. You have the right to delete your account and erase your Information although we reserve the right to retain some of your Information where there are valid grounds for us to do so under data protection laws. For example, for the defense of legal claims, respect freedom of expression, or where we have an overriding legitimate interest to do so.
Note that where the Information is held by a third party data controller, such as a payment processor, we will use reasonable steps to inform them of your request, but we recommend you contact them directly in accordance with their own privacy policies to ensure your personal data is erased.
Objection. You may have the right to object to our processing of you Information. This is the case where we process such Information on the basis of our legitimate interests (see above under How we use your personal information here), or where the Information is used for direct marketing purposes. You may exercise this right as follows:
To stop receiving marketing newsletters: You may withdraw your consent through the unsubscribe mechanism at the bottom of each communication.
To stop our cookies being placed for either advertising or analytics purposes: please [change your cookie setting as set out in our Cookie Policy].
To object to all other processing based on our legitimate interests, please contact us at [email protected]. Please note that we may have an overriding legitimate interest to keep processing your Information, but we will let you know where this is the case.
Other rights
You also have the following rights if you are based in Europe in some circumstances:
Portability. You have the right to receive a copy of Information we process on the basis of consent or contract in a structured, commonly used and machine-readable format, or to request that such Information is transferred to a third party.
Correction. You have the right to correct any Information held about you that is inaccurate.
Restriction. You have a right in certain circumstances to stop us processing Information other than for storage purposes.
Children
The Plastick Website is not intended for use by anyone under the age of 18 and we do not knowingly collect Information from children under the age of 18 via this Service. The other Services are not intended for anyone under the age of 13, or 16 if you are based in the European Economic Area or the United Kingdom (together, “Europe”). If you learn that a child has provided us with Information in violation of this Policy, please contact us as indicated below.
6. CONTACT & COMPLAINTS
We welcome questions, comments and requests regarding this Policy.
If you wish to make a complaint about how we process your Information, please contact us at [email protected] and we will endeavor to deal with your complaint as soon as possible. This is without prejudice to your right to launch a claim with a data protection authority. In some circumstances you may lodge a claim with the Information Commissioner’s Office in the UK (at +44 0303 123 1113) or the data protection supervisory authority in the EU country in which you live or work (for example the Irish Data Protection Commissioner at +353 578 684 800), where you believe we have infringed data protection laws.
You can also send a letter to us at 1100 Mandana Blvd, Oakland, CA 94610. Alternatively, if you are based in Europe, you can send a letter to our EU representative by:
· Sending an email to DataRep at [email protected] quoting <Project 9a Labs, Inc.> in the subject line.
· Contacting us on our online webform at www.datarep.com/data-request or
7. CHANGES
If we make any material changes to this Policy, we will post the updated Policy here and notify our users through the Services and/or newsletters. Please check this page frequently to see any updates or changes to this Policy.