Privacy Policy – veva

Privacy Policy


We ( Veva LLC collectively “Veva”, “we”, the “Company”, and “us”) believe you should know what data we collect from you and how we use it, share it, and protect it, and that you should have meaningful control over these actions to the fullest extent possible.

This Privacy Policy describes how we collect, use, share, and protect information in connection with the Services, which we make available to you through our Website.   This Privacy Policy is not applicable to any third party website or application, even if such website or application can be reached through an external link available on our Website.  

By accessing the Website and/or interacting with the Services, you are consenting to the information collection, use, sharing, and protection practices described in this Privacy Policy. 

Your use of the Website and the Services is also governed by the Terms of Use.  We strongly suggest that you examine and familiarize yourself with both of these documents prior to using the Services and that you check frequently for any updates to either document during your continued use of the Services. 

Capitalized terms not defined in this Privacy Policy shall have the meanings set forth in our Terms of Use.  Should you have any questions about our privacy practices that are not answered by this Privacy Policy, please feel free to contact us via the methods provided at the end of this Privacy Policy.

Information We Collect

When you visit the Website and/or engage with the Services, we may collect the following information:

Information you give us

  • Personal Information. When you register on the Website and/or sign up for the Services, we may collect information that can be used to identify you personally, such as your name, email address, mailing address, phone number, and profile picture (collectively, “Personal Information”).  Generally, you can visit our Website without entering any Personal Information. In certain cases, we may ask you for Personal Information to provide a service or carry out a transaction that you have requested, including your credit card or other payment card information.
  • Payment Information.  When you purchase one or more of the Services, including a Subscription, we, or a Third Party Payment Vendor, will collect information from you to complete your payment, such as the name, number, expiration date, certification code, and billing address associated with your credit card or payment card (collectively, “Payment Information”).  In the event that a Third Party Payment Vendor is collecting your Payment Information, such collect, use, and protection of your Payment Information is done according to the terms of such Third Party Payment Vendor’s privacy policy and/or terms of use, and we will not gain any access to your Payment Information.  Currently, we use the services of Stripe, Inc. (certified PCI level 1) as our Third Party Payment Vendor. For more information on Stripe's privacy practices, please refer to their Privacy Policy.
  • Other Information.  When you engage with any discussion with us, whether through email, phone, or live chat, we may collect other information about you and your situation or circumstances.  For instance, we may collect information from you about particular medical conditions you are experiencing or problems that you are having receiving a package. We may also collect information related to your orders and/or Subscription, including the products selected, the frequency of orders, etc.

Information automatically collected

  • We automatically log information about you and your computer.  For example, when you visit our Website, we may log such information as your computer operating system type, your browser type, your IP address, your browser language, the website you visited before browsing to our Website, pages you viewed, how long you spent on each page, access times, and information about your actions on the Website.  We collect this information, which does not include any Personal Information, for operational purposes such as evaluating, updating, and improving the Services.
  • Cookies.  We may log information using “cookies.”  Cookies are small data files stored on a user’s computer or device to allow a website to remember the user and give a more personalized experience.  We do not use cookies for tracking purposes, but we may use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your computer until you delete them) to provide you with a more personal and interactive experience on our Website.  This type of information is collected to make the Website more useful to you and to tailor the experience with us to meet your special interests and needs.  Should you wish, you can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. You do this through your browser settings. Since browser is a little different, look at your browser's Help Menu or visit websites providing step-by-step guides to learn the correct way to modify your cookies.  Please note that your decision to delete or stop accepting cookies may impair your use of some of the features or functionality of the Services or Website.
  • We may use third party analytics services. Currently, we use the analytics services of Google Analytics which is configured to learn how you use our Services by giving us the ability to collect information based on your interaction with our Services.  No Personal Information is collected or transmitted through this method.

We only communicate with Google servers and Microsoft servers through their API Services (OAuth). You can revoke access at any time. We store Google Calendar event ID's and Microsoft Calendar event ID's to retrieve or delete them, when and where required by the application.

How we use information

We do not entertain any advertising on our site. We may use the information we collect in the following ways:

  • To provide you with access to and use of the Services.
  • To personalize your experience, i.e, your information helps us to better respond to your individual needs.
  • To follow up with you after correspondence (live chat, email, or phone inquiries)
  • To improve customer service, i.e., your information helps us to more effectively respond to your support needs.
  • To communicate with you, including by sending you promotional email offers or emailing you in connection with your use of the Services. This helps us make our communications with you more interesting and improve our Services. 
  • To protect against, investigate, and deter fraudulent, unauthorized, or illegal activity.

By submitting your contact information, you are providing your express written consent to receive communications from us at the email address and telephone numbers you entered into our contact form, or that you later provide to us or enter into your contact page.  Any information that we do have will never be shared except under the circumstances described below in “How we share information.”

How we share information

We do not sell or trade your Personal Information.  We may, however, share information we collect, including your Personal Information, as follows:

  • We may transfer or share your Personal Information with trusted and GDPR-compliant third party service providers who assist us in operating our Website, providing technical support, conducting our business, or servicing you.  All such service providers are subject to confidentiality obligations and may only access and utilize your data for purposes of fulfilling their obligations to us.
  • If a third party acquires our assets related to the Services and its products and services (whether by sale, merger, financing, reorganization, change of control, bankruptcy, or otherwise), information, including your Personal Information, may be transferred to such third party as permitted by law or contract.  In such case, we cannot control how such third party uses or shares any information, including your Personal Information.
  • We may share Personal Information with your consent.  For example, you may let us share your Personal Information with others for their own marketing uses.  Those uses will be subject to their privacy policies.
  • We may also your Personal Information for legal, protection, and safety purposes. 
    • We may share information to comply with laws.
    • We may share information to respond to lawful requests and legal processes, such as subpoenas or court orders.
    • We may share information to protect the rights and property of Veva, our agents, customers, and others.  This includes enforcing our agreements, policies, and Terms of Use.
    • We may share information in an emergency.  This includes protecting the safety of our employees and agents, customers, or any person.
  • We may share aggregated or anonymized data with third parties without your consent. 

Choices with Your Personal Information

Whether you submit any Personal Information to us is entirely up to you. You are under no obligation to provide Personal Information. However, in the event certain Personal Information is essential for us to provide certain of the Services to you, we will be unable to provide you with those Services if you choose to withhold requested information.

You may revoke your consent to receive marketing communications at any time by replying “stop” to any of our texts, or by any other reasonable means. We will make a commercially reasonable effort to comply with any communications from you opting out, but replying “stop” will automatically revoke your consent to further text communications, and we recommend that method. We may take up to 30 days to stop communications if you use a method other than the automatic reply “stop.” You consent to receive a final text message confirming your opt-out. You may revoke your consent to receive email communications by using the “unsubscribe” link in an email or on the website or by any other reasonable means. We will make a commercially reasonable effort to comply with any communications from you opting out of email, but selecting “unsubscribe” will automatically revoke your consent to further email communications, and we recommend that method. We may take up to 30 days to stop email communications if you use a method other than the “unsubscribe” link.  The “unsubscribe” link will also permit you to stop text communications.

You may choose to prevent us from disclosing or using your Personal Information under certain circumstances (“opt out”). You may opt out of any disclosure or use of your Personal Information for purposes that are incompatible with the purpose(s) for which it was originally collected or for which you subsequently gave authorization by notifying us by any reasonable method. We will undertake reasonable efforts to notify third parties with whom we have shared your Personal Information as permitted under this Privacy Policy of your election to opt out. There are some uses from which you cannot opt out, such as to provide products or services that you have requested from us.

How we protect information

We are committed to protecting your privacy. Our website is scanned on a regular basis for security holes and known vulnerabilities in order to make your visit to our site as safe as possible. We use regular Malware Scanning.

Your Personal Information, from account creation and integration through Google/Microsoft OAuth service is stored behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology. We implement a variety of security measures when a user submit or accesses their information to maintain the safety of your Personal Information.

The safety and security of your Personal Information also depends on you.  Never share your password with anyone else.  Notify Veva promptly if you believe your password has been breached.  Also, remember to log off our Website before you leave your computer.

However, please note that despite our best efforts, information security measures can never be guaranteed to be 100% effective, and we cannot ensure or warrant the absolute security of any of your information, including your Personal Information, that you provide to us or that we collect.  We disclaim any liability for any security breach or any other unintended disclosure of information.

Third Party Links

This Privacy Policy applies only to the Services. Occasionally, at our discretion, we may include or offer third-party products or services on our website. These third-party products or services are associated with separate and independent websites and therefore different privacy policies.  Once you follow a link to a third-party website, we cease to have control over your data collection, use, sharing, and protection, as the third-party’s privacy policy will apply.

California Online Privacy Protection Act

CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law's reach stretches beyond California to require any person or company in the United States (and conceivably the world) that operates websites collecting Personal Information from California consumers to post a clearly visible privacy policy on its website stating the information being collected and those individuals or companies with whom it is being shared. - See more at: http://consumercal.org/california-online-privacy-protection-act-caloppa/#sthash.0FdRbT51.dpuf

According to CalOPPA, we agree to the following:

Users can visit our site anonymously.

Our Privacy Policy link includes the word 'Privacy' and can easily be found on the page specified above.

You will be notified of any Privacy Policy changes:

  • On our Privacy Policy Page

You can change your Personal Information:

  • By logging in to your account

How does our site handle Do Not Track signals?

We honor Do Not Track signals and Do Not Track, plant cookies, or use advertising when a Do Not Track (DNT) browser mechanism is in place.

Does our site allow third-party behavioral tracking?

It's also important to note that we do not allow third-party behavioral tracking.

COPPA (Children Online Privacy Protection Act)

Veva does not market to or provide any services to children. The Services are not intended or designed for us by children younger than 13 years old, and Veva will not knowingly collect, use, or maintain information from, or allow account creation by, visitors to our Website younger than 13 years old.  In the event that your child has given us Personal Information, please alert us at care@veva.co.  If we discover that we have collected any Personal Information from children under 13 we will promptly take steps to delete any and all such information and terminate any account created by such children.  For more information on COPPA visit the The Federal Trade Commission, website - https://www.ftc.gov/tips-advice/business-center/privacy-and-security/children%27s-privacy.

Fair Information Practices

The Fair Information Practices Principles are the core of privacy law in the United States. They have also played a significant role in the development of data protection laws around the globe. Understanding the Fair Information Practice Principles and how they should be implemented is critical to comply with the various privacy laws that protect personal information.

In order to be in line with Fair Information Practices we will take the following responsive action, should a data breach occur:

We will notify you via email

  • Within 7 business days

We will notify our Visitors and Customers via in-site notification

  • Within 7 business days

The Individual Redress Principle requires that individuals have the right to legally pursue enforceable rights against data collectors and processors who fail to adhere to the law. This principle provides individuals with enforceable rights against data users, and also provides recourse to courts or government agencies to investigate and/or prosecute non-compliance by data processors.

CAN SPAM Act

The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.

We collect your email address in order to:

  • Send information, respond to inquiries, and/or other requests or questions
  • Process orders and to send information and updates pertaining to our Services
  • Send you additional information related to our Services
  • Market to our mailing list or continue to send emails to our clients after the original transaction has occurred.

To be in accordance with CANSPAM, we agree to:

  • Not use false or misleading subjects or email addresses
  • Identify marketing messages as an advertisement in some reasonable way
  • Include the physical address of our business
  • Honor opt-out/unsubscribe requests quickly
  • Allow users to unsubscribe by using the link at the bottom of each email

Data Retention

We will retain your information, including your Personal Information, for as long as your account is active or as needed to provide you with Services through Veva.  We will retain and use your information as necessary to comply with our legal obligations, prevent fraud or abuse, resolve disputes, enforce our agreements, or take other action permitted by law.  Aggregated or anonymized data may be retained indefinitely.

Your California Privacy Rights

CCPA Rights Disclosure. The CCPA allows California residents to make certain requests about their Personal Information. In particular, the CCPA allows California residents to ask us to:

  • Provide information about the categories of Personal Information we collect or share; the categories of sources of such information; the business or commercial purpose for collecting Personal Information; and the categories of third parties with whom we share/disclose Personal Information.
  • Give them access to and/or a copy of certain information we hold about them.
  • Erase certain information we hold about them.

The CCPA further provides you with the right to not be discriminated against (as explained further in applicable law) for exercising your rights.

Please note that certain information may be exempt from such requests under California law. For example, we need certain information in order to provide the Services to you. We also will take reasonable steps to verify your identity before responding to a request.

If you are a California resident and you would like to exercise any of your data rights under California law, please email us at: california@veva.co.  Please include your full name, email address, and residential address associated with your use of our Services, along with the rights you would like to exercise, so that we can process your request in an efficient manner.

Shine the Light Disclosure. California’s “Shine the Light” law gives California residents the right under certain circumstances to request information from us regarding the manner in which we share certain categories of Personal Information (as defined in the Shine the Light law) with third parties for their direct marketing purposes. Rest assured that we do not share your Personal information with third parties for their own marketing purposes.

Your Nevada Privacy Rights

If you are a Nevada resident, you may have the right to opt out of the sale of your “personally identifiable information” for monetary consideration (as such terms are defined under Nevada law) to a person when that person intends to license or sell your personally identifiable information to additional persons. We do not sell your Personal Information; however, if you are a Nevada resident, you may choose to opt out of any potential future sales (in the unlikely event that we begin to make such sales) under Nevada law by emailing us at nevada@veva.co. Please note that we will take reasonable steps to verify your identity and the authenticity of the request.

International Users

Veva is located in the United States.  By choosing to use the Services or access our Website or otherwise provide information to us, you agree that any dispute over privacy or the terms contained in this Privacy Policy will be governed by U.S. laws and any disputes arising in connection with Veva or the Services will be adjudicated in accordance with our Terms of Use.

If you are accessing or using the Services or Website from the European Union or other countries or blocs with laws governing data collection and use, please note that you are agreeing to the transfer of your information to the United States and to processing globally.  By providing your information, you consent to any transfer and processing in accordance with this Privacy Policy.

Contacting Us

If there are any questions regarding this privacy policy, you may contact us using the information below and we'll do our best to get back to you within 24 hours.

Veva LLC
1314 NW Irving St
Portland, Oregon 97209
USA
care@veva.co

Changes to this Privacy Policy

We may update this Privacy Policy from time to time.  The Last Updated date at the top of the page indicates the date the most recent update to this Privacy Policy was made.  If Veva updates this Privacy Policy, your continued use of the Services and our Website (following the posting of the revised Privacy Policy) means that you accept and agree to the terms of the revised Privacy Policy.  Remember, by using any part of the Services or visiting our Website, you accept and agree to our Privacy Policy and privacy practices.  We strongly suggest that you review this Privacy Policy from time to time to see whether any changes have been made.  If we make material changes to how we collect, use, share, or protect information, we will make reasonable efforts to inform you of such changes and obtain your consent to any such changes as required by law.