ThatFoodNow! is the sole owner of the information collected on this site. We will not sell, share, or rent this information to others in ways different from what is disclosed in this statement. ThatFoodNow! may collect information from our customers at several different points on our website, as needed to service our customers, as outlined below.
There are a couple types of cookies related to the web browsing experience. Neither cookie type contains any personally identifiable information. A temporary cookie, technically known as a Session Cookie, is one that your browser sets by default to communicate your browsing experience between you and the server. These session cookiea are automatically destroyed when you close the web browsing session on the ThatFoodNow! site.
There is a second cookie type known as a persistent cookie. In general ThatFoodNow! does not utilize the persistent cookies for the site to function properly.
What information do we collect?
We request information from the user on our order form(s). In order for us to service Customer accounts, here a user must provide contact information (email, name, address, phone) and depending on payment method, financial information (credit card number, expiration date, bank information). Additionally the IP is recorded in the billing system. This information is used for billing purposes and to fill customer orders. If we have trouble processing an order, this contact information is used to get in touch with the user. We use a high encryption SSL certificate for securely gathering the requested information. We do not store credit card information or the CVV code for your security reasons.
When ordering or registering on our website, as appropriate, you may be asked to enter your name, email address, telephone number, and delivery address. In addition, when placing an order, you may be asked to enter credit card information. This information is not stored or used in any way other than to pass the data to a third party agency to process the transaction. We only conduct business with third party agencies who hold the same value as we do, and that is to protect your data and information.
Log files automatically collect certain types of information related to your browser, including your IP address. We use IP addresses to analyze trends and help provide an insight into how visitors transition from one page to another so we can optimize the visitor experience, and gather broad demographic information like the type of browser, for aggregate use. IP addresses are not linked to personally identifiable information.
What do we use your information for?
Any information we collect from you may be used in one of the following ways:
- To personalize your experience on our website (your information helps us to better respond to your individual needs)
- To improve our website (we continually strive to improve our website's offereings based on information and feedback we receive from you)
- To improve our customer service (your information helps us to more effectively respond to your customer service requests and support needs)
- To process transactions
Your information, whether public or private, will not be sold, exchanged, transferred, or given to any company for any reason whatsoever, without your consent, other than the express purpose of delivering the purchased product or service requested by the customer.
- To send periodic emails
The email address you provide for order processing, may be used to send you information and updates pertaining to your order, in addition to receiving ocassional company news, updates, related product or service information, etc.
Note: If at any time you would like to unsubscribe from receiving future emails, we include detailed unsubscribe instructions at the bottom of each email.
- To administer a contest, promotion, survey or other website features
If a visitor wishes to subscribe to our newsletter, we ask for contact information such as name and email address.
How do we protect your information?
We implement a variety of security measures to maintain the safety of your personal information when you access your personal information.
This website takes every precaution to protect our visitors' information. When visitors submit sensitive information via the website, the information is protected both online and off-line.
When our order form(s) asks visitors to enter sensitive information (such as credit card number), that information is encrypted and is protected with the best encryption software in the industry - SSL. While on a secure page, such as our order form(s), the lock icon in the Web browser becomes locked. ThatFoodNow! has taken additional steps to ensure SSL encryption is used at all times when browing our site.
While we use SSL encryption to protect sensitive information online, we also do everything in our power to protect user-information off-line. All of our users' information, not just the sensitive information mentioned above, is restricted in our offices. Only employees who need the information to perform a specific job (for example, our billing clerk or a customer service representative) are granted access to personally identifiable information. ALL employees are kept up-to-date on our security and privacy practices. Any time new policies are added, our employees are notified and/or reminded about the importance we place on privacy, and what they can do to ensure our customers' information is protected. Finally, the servers that we store personally identifiable information on are kept in a secure environment.
ThatFoodNow!'s website and services are not intended for, nor designed to attract, individuals under the age of 18. Hostek does not knowingly collect personally identifiable information from any person under the age of 18.
When paying by Credit Card, upon initial payment, you will be required to enter the CVV code for the card. We do NOT store this code or the credit card number. It is only asked for this once.
We send all new accounts an email providing new account information. Established customers will occasionally receive information on new services and/or special promotions. Out of respect for the privacy of our users we present the option to not receive these types of communications.
Do we disclose any information to outside parties?
We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information. This does not include trusted third parties who assist us in operating our website, conducting our business, or servicing you, so long as those parties agree to keep this information confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our website policies, or protect ours or others rights, property, or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.
Third party links
Occassionally, at our discretion, we may include or offer third party products or services on our website. These third party websites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our website and welcome any feedback about these websites.
Customer Information and Customer Privacy
Company shall act in accordance with industry practice in protecting Customer Information submitted by Customer to Company ("Customer Information"), and shall not sell or otherwise transfer Customer Information to third parties for marketing activitites in any circumstance. Company shall be entitled to use the Personal Information of Customer in the due performance of the Services, this Agreement and (unless opted out in writing) for communcation to Customer of Company's own marketing information.
As to Personal Information, also referred hereinto as Personal Data, supplied by or through Customer in the course of its business with Company, the following shall apply:
- Both parties will comply with their respective obligations under the applicable requirements of the Data Protection Laws.
- The parties acknowledge that for the purposes of the Data Protection Laws, Customer is the data controller and Company is the data processor (where Data Controller and Data Processor have the meanings as defined in the Data Protection Laws). The following sets out the scope, nature and purpose of processing by Company, the duration of the processing and the types of Personal Data (as defined in the Data Protection Laws) and categories of Data Subject:
- Processing by Company: The provision of data or application hosting services for Customer and indirectly its customers.
- Company does not control what personal or non personal data Customers collect from their customers. It is Customer's responsibility to have their own Data Protection guidelines in place for their own protection related to data Customer collects from its customers; additionally, it is Customer's responsibility to keep their applications up to date and secure from a code/software perspective.
- Customer declares and acknowledges that Company has no control, involvement, role or responsibility as to the type or use of data put by Customer itself or third parties generally nor, without limitation, Customer's employees, contractors, agents, customers or suppliers or end-users of Customer's services or those of Customer's customers and Company merely provides an IT repository for data with a specified conduit for its movement to and from Customer or third party infrastructure. Company's processing does not include the manipulation, selection, ordering, searching or monitoring of such Personal Data other than in a generic sense of storage in the scope of the Services. Customer is responsible for the cleansing, updating, timely deletion and maintenance of Personal Data.
- Customer will ensure that it has all necessary and appropriate consents and notices in place to enable lawful transmission of Personal Data to Company and its processing in accordance with this Agreement for the duration and purposes of this Agreement.
- Without prejudice to the generality of the above clause, Company shall, in relation to any Personal Data processed in connection with the performance by Company of its obligations under this Agreement:
- process that Personal Data only in accordance with the performance of Services and otherwise either required under this Agreement (this Agreement being agreed to constitute written instructions from Customer for processing of Personal Data) or by variation of Services agreed with Company; or
- process that Personal Data if required by the laws of any member of the European Union or by the laws of the European Union applicable to Company to process Personal Data (Applicable Laws). Where Company is relying on laws of a member of the European Union or European Union law as the basis for processing Personal Data outside of pre-agreed processing, Company shall promptly notify Customer of this before performing the processing required by the Applicable Laws unless those Applicable Laws prohibit Company from so notifying Customer;
- ensure that it has in place appropriate, industry-standard for England, technical and organisational measures to protect against unauthorised or unlawful processing of that Personal Data and against accidental loss or destruction of, or damage to, those Personal Data, having regard to the state of technological development and the cost of implementing any;
- ensure that all personnel who have access to and/or process those Personal Data are obliged not to permit disclosure of the Personal Data except as required by law or for the purposes of this Agreement; and
- not transfer any of those Personal Data, other than Customer Submitted information required for servicing Customer account (ie, US and UK based systems/support/billing teams), outside of the European Economic Area (other than Customerâ€™s transmission and receipt of data over the Internet and the use of similar networks that may involve part of the network being located outside the European Economic Area and/or the UK), unless the prior written consent of Customer has been obtained;
- assist Customer, at Customer's expense using Company's then current standard time rates, in responding to any request from a Data Subject and in ensuring compliance with its obligations under the Data Protection Laws with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;
- notify Customer without undue delay on becoming aware of a material Personal Data breach committed by Company, its employees or agents and take reasonable steps to prevent further disclosure or breach and mitigate the potential adverse effects on affected data subjects in cooperation with Customer;
- at the written direction of Customer, delete or return to Customer or allow Customer to retrieve Personal Data and copies thereof on termination of Agreement unless required by Applicable Law to store Personal Data;
- maintain appropriate records and information to demonstrate its compliance with this clause;
- in accordance with Data Protection Laws, make available to Customer such information as is reasonably necessary to demonstrate Company's compliance with its obligations under Article 28 of the GDPR (and under any Data Protection Laws equivalent to that Article 28), and allow for and contribute to audits, including inspections, by Customer's professional appointee for this purpose, subject to Customer:
- giving Company reasonable prior notice of such information request, audit and/or inspection being required by Customer;
- ensuring that all information obtained or generated by Customer or its auditor(s) in connection with such information requests, inspections and audits is kept strictly confidential (save for disclosure to the supervisory authority under Data Protection Laws or as otherwise required by Applicable Laws);
- ensuring that such audit or inspection is undertaken during normal business hours, with minimal disruption to Company's business, any sub-processorsâ€™ business and the business of other customers of Company; and
- paying Company's costs using the then current standard time rates of Company for assisting with the provision of information and allowing for and contributing to inspections and audits.
- Company shall nominate a point of contact for all issues related to data privacy and protection within the scope of the Agreement and pending notification; otherwise this will be the CEO/Managing Director.
- If Company informs Customer that it considers that an instruction violates Data Protection Laws then it shall be entitled to suspend the execution of the relevant instructions until Customer satisfactorily confirms compliance or changes them. Further, if Company follows the instructions of Customer, Customer indemifies Company for any and all such current and future items or incidences related to such instruction.
- Customer shall, without undue delay and in a comprehensive fashion, inform Company of any defect that Customer considers has occurred in their and/or Company's compliance with Data Protection Laws.
- Customer shall be obliged to maintain the public register of processing in accordance with Article 30 (1) GDPR.
The first step in resolving any concern is to contact Company (see Inquiries or Complaints below) with any details. Unresolved issues will be resolved via binding Arbitration as a sole remedy.
This policy was last modified on 5/25/2018