Effective Date: October 19, 2020
This Privacy Policy describes the policies of Ditto Technologies, Inc. (“we”, “our” or “us”) on the collection, use and disclosure of your (“you” or “your”) information in connection with your use of our products and services including https://ditto.com/ and our in-store mobile applications (collectively the “Site”).
This Privacy Policy does not apply to the practices of third parties that we do not own or control, including any third party websites, services and applications that you elect to access through or in connection with the Site, or to individuals that we do not manage or employ. We cannot take responsibility for the content or privacy policies of those third parties and encourage you to carefully review their privacy policies before you access such services.
This Privacy Policy applies only to information you provide to us through the Site. If you choose to use our services pursuant to a separate agreement with us, the collection, use, and disclosure of any information provided to us under such agreement will be governed by such agreement.
We do not knowingly collect or solicit personal information from anyone under the age of 13. If you are under 13, please do not attempt to send any personal information about yourself to us. If we learn that we have collected personal information from a child under age 13, we will delete that information as quickly as possible. If you believe that a child under 13 may have provided us personal information, please contact us at privacy@ditto.com.
The Site may be hosted and operated in the United States (“U.S.”) through us and our service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Site, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to us in the U.S. and may be hosted on U.S. servers, and you authorize us to transfer, store and process your information to and in the U.S., and possibly other countries. You hereby consent to the transfer of your data to the U.S. solely for the purposes set forth below.
Our privacy policy is not to collect, store, or share any personally identifiable information, except as described below.
We may communicate with you if you’ve provided us the means to do so. For example, if you’ve given us your email address, we may send you promotional email offers on behalf of Ditto or our business partners, or email you about your use of the Site. Also, we may receive a confirmation when you open an email from us. This confirmation helps us make our communications with you more interesting and improve our services. If you do not want to receive communications from us, please indicate your preference by emailing privacy@ditto.com.
Through cookies we place on your browser or device, we may collect information about your online activity after you leave our Site. Just like any other usage information we collect, this information allows us to improve the Site and customize your online experience, and otherwise as described in this Privacy Policy. Your browser may offer you a “Do Not Track” option, which allows you to signal to operators of websites and web applications and services (including behavioral advertising services) that you do not wish such operators to track certain of your online activities over time and across different websites. Our Site does not support Do Not Track requests at this time, which means that we collect information about your online activity both while you are using the Site and after you leave our Site.
We never share or sell your information to third parties for their own purposes. We may now or in the future contract with other companies to provide certain services to us, such as suppliers, payment processors and technology service providers, and we may need to give them access to information, such as your email address, in order for them to perform services for us. Unless we tell you differently, these companies do not have any rights to use the information we share with them beyond what is necessary to assist us.
In addition, we may at times share aggregated and anonymized Site statistics with our partners and service providers so that we and they can understand how and how often people use our Site. We will never disclose Site statistics in a manner that would allow a third party to identify you individually without your express consent.
If we or our assets were acquired, or if we go out of business or enter bankruptcy, user information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, and that any acquirer of us or our assets may continue to use your information as set forth in this policy. We do not currently have a parent company or any affiliates, but in the future we may and may share your information with them, but they will be subject to the same obligations set out in this policy.
We also reserve the right to access, read, preserve, and disclose any information as we reasonably believe is necessary to (i) satisfy any applicable law, regulation, legal process or governmental request, (ii) detect, prevent, or otherwise address fraud, security or technical issues, or (iii) protect our rights, property or safety, our users and the public.
We retain your biometric information submitted to Ditto from the U.S. to the Site for a maximum of three years following collection.
We retain your other personal data: (A) for as long as reasonably necessary to provide you with access to the Site; (B) as necessary to comply with our legal obligations, resolve disputes or collect fees owed; and (C) as otherwise required by applicable law, rule or regulation, We retain some of your information in a depersonalized or aggregated form but not in a way that it could be used to identify you.
We store all of our information, including your personal information, using industry-standard techniques. Unfortunately, due to the nature of the Internet, unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time. We do not guarantee or warrant that the techniques we employ will prevent unauthorized access to information about you that we store.
If we make changes to this Privacy Policy, we will notify you by sending you an email or by way of a conspicuous posting on the Site. Any material changes will take effect for existing users thirty (30) days after we give such notice and will be immediately effective for new users. If you do not agree to any such changes, please do not continue to use the Site following the effective date of such change.
You may request deletion of your personal information submitted to the Site by sending an email to privacy@ditto.com. If you use our services through a third-party service provider, you may request a deletion of your personal information by contacting that service provider.
Non-U.S. Users: Please be advised that your information may be processed in the country in which it was collected and in other countries, including the United States, where laws regarding processing of personal data may be less stringent than the laws in your country. If you have concerns about our processing of your personal data, please do not use the Site.
California Privacy Rights: Under California Civil Code sections 1798.83-1798.84, California residents are entitled to ask us for a notice identifying the categories of personal customer information which we share with our affiliates and/or third parties for marketing purposes, and providing contact information for such affiliates and/or third parties. If you are a California resident and would like a copy of this notice, please submit a written request to privacy@ditto.com.
If you are a resident of the European Union (“EU”), United Kingdom, Lichtenstein, Norway, or Iceland, you may have additional rights under the EU General Data Protection Regulation (the “GDPR”) with respect to your Personal Data, as outlined below.
For this section, we use the terms “Personal Data” and “processing” as they are defined in the GDPR, but “Personal Data” generally means information that can be used to individually identify a person, and “processing” generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure. We will be the controller of your Personal Data processed in connection with the Site.
Where applicable, this section is intended to supplement, and not replace, our Privacy Policy. If there are any conflicts between this section and any other provision of this Privacy Policy, the policy or portion that is more protective of Personal Data shall control to the extent of such conflict. If you have any questions about this section or whether any of the following applies to you, please contact us at privacy@ditto.com. Note that we may also process Personal Data of our customers’ end users or employees in connection with our provision of services to customers, in which case we are the processor of Personal Data. If we are the processor of your Personal Data (i.e., not the controller), please contact the controller party in the first instance to address your rights with respect to such data.
We collect Personal Data about you when you provide such information directly to us, when third parties such as our business partners or service providers provide us with Personal Data about you, or when Personal Data about you is automatically collected in connection with your use of our Site.
Information we collect directly from you: We receive Personal Data directly from you when you provide us with such Personal Data, including without limitation the following:
Website | Store iPad App | Analytics | |
ditto_ID | Yes | Yes | Yes |
PD | Yes | Yes | No |
Image | Yes | Yes | No |
IP Address | Yes | Yes | Yes |
Gender | Yes | Yes | Yes |
Birthdate | Yes | Yes | No |
Ear Junction | Yes | Yes | No |
Eye Corner Width | Yes | Yes | No |
Face Image | Yes | Yes | No |
Face Shape | Yes | Yes | No |
Nose bridge height | Yes | Yes | No |
Nose bridge width | Yes | Yes | No |
Progressive/multifocal prescription | Yes | Yes | No |
Temple Length Y/N | Yes | Yes | No |
Language | Yes | Yes | No |
Address | Yes | Yes | No |
Education Level | Yes | Yes | No |
Income Band | Yes | Yes | No |
Income Amount | Yes | Yes | No |
Preferences (open field) | Yes | Yes | No |
Wear Glasses or Contacts | Yes | Yes | No |
Prescription | Yes | Yes | No |
Frame “favorites” | Yes | Yes | No |
Customer_ID | Yes | Yes | No |
Name | No | Yes | Yes |
No | Yes | Yes | |
Company detail | No | No | Yes |
Browser | No | No | Yes |
Location Information | No | No | Yes |
Information we automatically collect when you use our Site: Some Personal Data is automatically collected when you use our Site, such as the following:
How Do We Use Your Personal Data? We process Personal Data to operate, improve, understand and personalize our Site. For example, we use Personal Data to:
We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.
How and With Whom Do We Share Your Data? We may share Personal Data with vendors, third party service providers and agents who work on our behalf and provide us with services related to the purposes described in this Privacy Policy or our Terms of Service. These parties include:
We also share Personal Data when we believe it is necessary to:
We also share information with third parties when you give us consent to do so.
Last, we share Personal Data with our affiliates or other members of our corporate family. Furthermore, if we choose to buy or sell assets, user information is typically one of the transferred business assets. Moreover, if we, or substantially all of our assets, were acquired, or if we go out of business or enter bankruptcy, user information would be one of the assets that is transferred or acquired by a third party, and we would share Personal Data with the party that is acquiring our assets. You acknowledge that such transfers may occur, and that any acquirer of us or our assets may continue to use your Personal Information as set forth in this policy.
What Security Measures Do We Use? We seek to protect Personal Data using appropriate technical and organizational measures based on the type of Personal Data and applicable processing activity.
Personal Data of Children: We do not knowingly collect or solicit Personal Data from anyone under the age of 16. If you are under 16, please do not attempt to use the Site or send any Personal Data about yourself to us. If we learn that we have collected Personal Data from a child under age 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us Personal Data, please contact us at privacy@ditto.com.
What Rights Do You Have Regarding Your Personal Data? You have certain rights with respect to your Personal Data, including those set forth below. For more information about these rights, or to submit a request, please email privacy@ditto.com. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need to you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request.
What If You Have Questions Regarding Your Personal Data? If you have any questions about this section or our data practices generally, please contact us using the following information:
If you have any questions or concerns regarding your privacy when using the Site, please send us a message to privacy@ditto.com. We will make every effort to resolve your concerns.