Privacy Policy
This Privacy Policy applies to your use of the Privable website at https://privable.io, the Privable mobile app, the Privable Safari extension, and related services (together, the "Service"). It explains what data we collect, how we store it, how that data may be used, with whom it may be shared, and the choices you have about those uses and disclosures. Please read this Privacy Policy carefully and in full when using our Service.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation). "UK GDPR" means the GDPR as retained in the law of the United Kingdom.
"EEA" covers all current Member States of the European Union and the European Economic Area.
"CCPA" means the California Consumer Privacy Act of 2018.
"Process," in relation to personal data, includes collecting, storing, using, and disclosing it to others.
For the meaning of defined terms (words starting with a capital letter) that are not explicitly defined in this Privacy Policy, see the Privable Terms of Use and Service (the "Terms").
1. Personal Data Controller
1.1. Notch Limited, a company registered in England and Wales under company number 15849302, with its registered office at Unit 4, 27 Calder Yard, London EC2A 3LH, United Kingdom, is the controller of your personal data.
2. What Categories of Personal Data Do We Collect?
2.1. We collect data that you choose to make available to us (for example, your email address, phone number, name, and date of birth). We also collect data automatically when you use the Service (for example, your IP address and device type).
Data You Give Us
2.2. You provide data about yourself when you register for and/or use the Service — for example, when you create a user profile ("Profile"), reply to our emails, or report a problem. The data you give us includes:
- Account Data. If you create an account with us, we collect identifiers such as your name, mailing address, email address, phone number, and user credentials (login name and password). Depending on the Service purchased, we may also collect emergency contact information, location-identifying labels, your driver's license, and your date of birth, as well as audio, electronic, visual, or similar information, such as your picture (or avatar, if you choose one).
- Payment Data. If you complete a purchase of any part of our Service, we collect your billing address and payment data, including credit card, debit card, and/or PayPal details, a National ID (region-specific, if outside the United States), and a VAT/Tax ID (region-specific, if outside the United States), as well as commercial information, such as details of the items you have purchased.
- Identity Data. We collect your date of birth, age, and gender, as well as identifiers such as your address, email, bank account information, credit/debit card information, mother's maiden name, insurance information, gamer tag, and other personal details, such as your Social Security Number and/or state or government identifier, driver's license number, or other national personal identifier. We use this data to verify your identity and to provide identity monitoring, leaked-data alerts, and identity theft protection services, including the removal of your information from data-broker sites.
- Communications. If you contact us directly, we collect personal data about you, including identifiers such as your name, email address, and phone number, the contents of any message or attachments you send us, and any other information you choose to provide. We may retain and review audio, electronic, visual, or similar information, such as recordings of audio calls and chats and/or the contents of messages, as required or permitted by law and by our recording and information management policies. We also collect identifiers such as your email address and phone number when you sign up to receive Service updates, offers, and other promotional information or messages from us. When we send you emails, we may track whether you open them, so that we can learn how to deliver a better customer experience and improve our Service.
Data We Collect Automatically
2.3. We collect the following data automatically:
- Data about how you found us. We collect data about your referring URL (that is, where you were on the web when you tapped on our ad).
- Cookies and other similar technologies. Our Service uses cookies that record data about how the Service is used, so that we can distinguish you from other users. You can manage cookies through your browser settings.
- Browser and device data. Depending on the permissions you have granted, we collect data from or about the devices you use to access the Service. Examples include language settings, IP address, location, time zone, device type and model, device settings, operating system, Internet Service Provider, mobile carrier, hardware ID, and Facebook ID.
- Advertising identifiers. We also collect your Apple Identifier for Advertising ("IDFA"), where your device settings allow it.
- Transaction data. When you make payments through the Service, you need to provide financial account data, such as your credit card number, to our third-party service providers. We do not collect or store full credit card numbers.
- Usage data. We record how you interact with our Service (for example, logs of the features and content you interact with, and how often and for how long).
3. For What Purposes Do We Process Your Personal Data?
3.1. We process your personal data for the following purposes:
- To provide the Service to you. This means enabling smooth use of the Service and dealing with errors or technical issues. For example, we use your data to authenticate you and to authorize your access to our Service.
- To research and analyze your use of the Service. This helps us maintain, improve, innovate, and develop our Service. We run surveys and research and test features in development. We analyze the data we hold to evaluate our Service and carry out audits and troubleshooting to improve the Service's content and layouts. As a result, we often decide how to improve the Service based on the outcome of this processing. For example, if we find that users rarely use a certain section of the Service, we may focus on improving that section.
- To customize the Service for you. For example, selecting the available payment processors or determining whether you are eligible for promotions.
- To process your payments. We provide paid Service features within the Service. For this purpose, we use third-party services for payment processing (for example, payment processors). As a result of this processing, you are able to pay for paid features of the Service.
- To enforce our terms and prevent fraud. We use personal data to enforce our agreements and contractual commitments and to detect, prevent, and combat fraud. As a result of this processing, we may share your information with others, including law enforcement agencies (in particular, if a dispute arises in connection with the Terms).
- To communicate with you. We may communicate with you, for example, by email or directly within the Service, including through push notifications.
- To send marketing communications. We process your personal data for our marketing campaigns and may add your email address to our marketing list. As a result, you will receive information about our Service features, offers, promotions, contests, and events, or other news or information about third-party services that may interest you. You can opt out of marketing communications at any time by clicking the "Unsubscribe" button in any of the emails you receive.
- To provide customer service and support. As a result of this processing, we will send you messages about the availability and security of our Service, payment transactions, the status of your orders, legal notices, or other Service-related information.
- To personalize our ads. We and our partners use your personal data to tailor ads and, where possible, to show them to you at a relevant time.
- To comply with legal obligations. We may process, use, or share your data where the law requires it, in particular if a law enforcement agency requests your data through available legal means.
4. Legal Basis for Data Processing (UK and EEA Only)
4.1. This section applies only to users based in the United Kingdom or the EEA. We process data on the following legal grounds:
- Your consent. Where you give explicit or implied consent.
- Performance of a contract. Providing the Service, customizing your experience, communicating account updates, processing payments, and providing customer support.
- Legitimate interests. To promote, operate, and maintain our business, we process your personal data on the basis of our legitimate interests, provided those interests are not overridden by your fundamental rights and freedoms. This includes processing data to better administer, test, and understand the usability, performance, and effectiveness of our Service (including troubleshooting, debugging, data analytics, and statistical analysis); to strengthen the security of our information networks, prevent cyber threats, and detect fraudulent or malicious activity (such as fake accounts); and to personalize our communications or recommend relevant features.
- Legal obligations. Carrying out identity verification and meeting other statutory requirements.
5. California Privacy Rights
5.1. This section gives additional details about how we process the personal data of California consumers and the rights available to them under the California Consumer Privacy Act of 2018 ("CCPA") and California's Shine the Light law. Accordingly, this section applies only to residents of California, United States.
5.2. If you are a California resident, you may ask us to provide you with the information we have shared with third parties for electronic or online direct marketing purposes, if any such sharing has taken place. We can provide this information once a year free of charge, and it will cover information shared during the previous twelve (12) months. We will provide the information within forty-five (45) days of your request, or tell you that we need more time to fulfill it.
5.3. If you are a California resident and wish to make such a request, please give us enough information to determine whether this applies to you, confirm that you are a California resident, and provide a current California address for our response. You can make a request by contacting us at [email protected]. The first line of the description in any such request must read "California privacy rights request," and the request must include your name, street address, city, state, and ZIP code. Please note that we are only required to respond to one request per customer each year, and we are not required to respond to requests made by any means other than this address.
5.4. Information shared for purposes other than direct marketing will not necessarily be included in our response to such a request. We reserve the right to request and confirm proof of identity as we consider necessary at our sole discretion, and to keep your request for at least two years for auditing and user management purposes.
6. Data Retention
6.1. We keep personal data for as long as necessary to fulfill the purposes described in this Privacy Policy, unless the law requires or permits a longer retention period.
6.2. Please note that we have various obligations to retain the data you provide to us — for example, to make sure transactions can be properly processed, settled, refunded, or charged back, to help identify fraud, and to comply with anti-money laundering and other laws and rules that apply to us and to our financial service providers. As a result, even if you disable or delete your Profile, we will keep certain data to meet these obligations.
7. Security of Your Personal Data
7.1. We take reasonable and appropriate physical, technical, and organizational security measures, in line with applicable laws, to protect your personal data against the risk of accidental loss, compromise, or any unauthorized access, disclosure, or processing.
- Physical safeguards. We control physical access to our facilities, enforce clean-desk policies, and securely destroy any physical media that contains personal data.
- Technical safeguards. We use industry-standard information security protocols and technologies, including data encryption (both in transit and at rest), intrusion detection systems, firewalls, and regular vulnerability scanning.
- Organizational safeguards. We provide regular, role-specific privacy and security awareness training to our employees, contractors, and service providers who have authorized access to your personal data.
8. With Whom Do We Share Your Personal Data?
8.1. We share information with third parties that help us operate, provide, improve, integrate, customize, support, and market our Service. We may share certain sets of personal data, in particular for the purposes listed in Section 3 of this Privacy Policy. The types of third parties we share information with include, in particular:
- Cloud storage providers: Google Cloud Platform
- Data analytics providers: Facebook, Google Analytics, Amplitude
- Marketing partners: Microsoft Ads, Google Ads, Google Tag Manager
- Engineering partners: Sentry, Cloudconvert, Cloudflare
- Customer communication partners: Customer.io, Zendesk
- Payment processors: third-party contractors
- Law enforcement: public authorities, where legally required
- Corporate transfers: affiliates, or parties to a merger or acquisition
9. International Data Transfers
9.1. We may transfer personal data to countries other than the one in which it was originally collected, in order to provide the Service described in the Terms and for the purposes set out in this Privacy Policy. If those countries do not have the same data protection laws as the country where you first provided the information, we put special safeguards in place.
9.2. In particular, if we transfer personal data originating from the UK or the EEA to countries that do not provide an adequate level of data protection, we rely on one of the following legal bases: (i) Standard Contractual Clauses approved by the European Commission (together with the UK International Data Transfer Addendum, where applicable); (ii) the EU-U.S. Data Privacy Framework (and its UK Extension, where applicable); or (iii) adequacy decisions or regulations issued for certain countries by the European Commission or the UK government.
10. Changes to This Privacy Policy
10.1. We may change this Privacy Policy at any time. If we decide to make material changes to it, we will notify you through our Service or by other available means, and you will have the opportunity to review the revised Privacy Policy. By continuing to access or use the Service after the changes take effect, you agree to be bound by the revised Privacy Policy.
11. Age Limitation
11.1. We do not knowingly process data from people under 18 years of age (or a higher age where local law requires it). If you find out that a minor has shared data with us, contact us at [email protected] and we will erase it promptly.
12. Privacy Rights
12.1. You keep full control over your data rights, including the rights of access, updating or correction, erasure, restriction of processing, and data portability, as well as the right to lodge a complaint with a data protection supervisory authority.
12.2. Verification of privacy requests. When we receive a request to exercise any of your privacy rights (such as access, portability, or erasure of data), we must verify your identity and authorization before we act on it. We require you to authenticate your identity securely, at a level appropriate to the action requested (for example, through an email confirmation link, multi-factor authentication, or by signing in directly to your secure account). This verification is strictly necessary to prevent identity theft, phishing, or unauthorized disclosure of personal data to third parties.
13. How Do We Handle "Do Not Track" Requests?
13.1. Unless stated otherwise, this Service does not natively support browser-based "Do Not Track" requests.
14. Translations
14.1. Translations are provided for convenience only. If there is any ambiguity, the English version of this Policy will prevail.
15. Contact Us
15.1. If you have any questions or concerns, contact us at:
Notch Limited
Unit 4, 27 Calder Yard, London EC2A 3LH, United Kingdom
Email: [email protected]