Privacy Policy
Tangerine Bay takes data privacy seriously. This privacy policy explains who we are, how we collect, share and use Personal Information, and how you can exercise your privacy rights.
We recommend that you read this privacy policy in full to ensure you are fully informed.
If you have any questions or concerns about our use of your Personal Information, then please contact us.
1. OVERVIEW
Collection of your personal information
Generally, Tangerine Bay will collect personal information directly from you and only to the extent necessary to provide a product or service or to carry out our internal administrative operations. For example, we may collect personal information from you when you fill in our online email form, deal with us over the telephone, ask us to contact you after visiting our web site or have contact with us in person. We will collect personal information from you by lawful and fair means and not in an unreasonably intrusive way.
Email Subscription Lists. If you elect to register an account with Tangerine Bay, and use this account to make purchases from the Tangerine Bay website, some of your personal information (being your email address and/ or contact phone number) will be provided to Tangerine Bay’s delivery carrier. This information is used by the carrier to send you updates on the status of your deliveries from Tangerine Bay. For more information on our Email Distribution Carrier, please visit MailChimp.
Opt In/Out/Unsubscribe. You have the ability to opt out of these communications directly from the messages you receive. We currently have an electronic Direct Marketing (eDM) email list which provides marketing offers to subscribers. If you elect to subscribe to our eDM, these services will be provided to you to communicate product information, special events and offers.
Social Media. We also use search engine and social media sites to make marketing offers which may be of interest to you. Our marketing subscription list is an ‘opt in’ system. eNEWS You may unsubscribe easily by clicking on the unsubscribe link that appears in all of our marketing communications to you.
Spam
We will never knowingly send you electronic messages without your consent. For more information on the Spam Act 2003, please visit The Australian Government Website.
Information we collect from other sources: From time to time, we may obtain information about you from third-party sources, such as social media platforms and Google. We take steps to ensure that such third parties are legally or contractually permitted to disclose such information to us.
Examples of the information we receive from other sources include demographic information (such as age and gender), device information (such as IP addresses), location (such as city and state), and online behavioural data (such as information about your purchase activity on our website, page view information and search results and links). We use this information, alone or in combination with other information (including Personal Information) we collect, to enhance our ability to provide relevant marketing and content to you and to develop and provide you with more relevant products, features, and services.
Device information: We may collect information about the type of device and operating system you use. We do not ask for, access, or track any location-based information from your mobile device at any time while downloading or using our mobile apps or Services.
Product usage data: We may use mobile analytics software (such as Google Analytics) to better understand how people use our application. We may collect information about how often you use the application and other performance data.
We may use the Personal Information we collect through the Services or other sources for a range of reasons, including:
To bill and collect money owed to us by you. This includes sending you emails, orders, order receipts, notices of product information and updates, and alerting you if we need a different credit card number. We use third parties for secure credit card transaction processing, and those third parties collect billing information to process your orders and credit card payments. To learn more about the steps we take to safeguard the data that you provide, visit PayPal.
To send you system alert messages. For example, we may inform you about temporary or permanent changes to our products, such as new releases, special offers or send you account, security or compliance notifications, such as new features, version updates, releases, abuse warnings, and changes to this privacy policy.
To communicate with you about your account and provide customer support. For example, if you use our mobile apps, we may ask you if you want to receive push notifications about activity in your account. If you have opted in to these push notifications and no longer want to receive them, you may turn them off through your operating system.
To enforce compliance with our Terms of Use and applicable law, and to protect the rights and safety of our Members and third parties, as well as our own. This may include developing tools and algorithms that help us prevent violations. For example, sometimes we review the content of our Members’ email campaigns to make sure they comply with our Terms of Use. To improve that process, we have software that helps us find email campaigns that may violate our Terms of Use. Our employees or independent contractors may review those particular email campaigns. This benefits all Members who comply with our Terms of Use because it reduces the amount of spam being sent through our servers and helps us maintain high deliverability. Email was not built for confidential information. Please do not use Tangerine Bay to send confidential information.
To meet legal requirements, including complying with court orders, valid discovery requests, valid subpoenas, and other appropriate legal mechanisms.
To provide information to representatives and advisors, including attorneys and accountants, to help us comply with legal, accounting, or security requirements.
To prosecute and defend a court, arbitration, or similar legal proceeding.
To respond to lawful requests by public authorities, including to meet national security or law enforcement requirements.
To provide, support and improve the Services. For example, this may include sharing your information with third parties in order to provide and support our products or to make certain features of the website available to you. When we share Personal Information with third parties, we take steps to protect your information by requiring these third parties to enter into a contract with us that requires them to use the Personal Information we transfer to them in a manner that is consistent with this privacy policy and applicable privacy laws.
Other purposes. To carry out other legitimate business purposes, as well as other lawful purposes about which we will notify you.
The right to complain to a data protection authority about the collection and use of Personal Information. For more information, please contact your local data protection authority. Contact details for data protection authorities in the EEA are available here.
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection law. We may ask you to verify your identity in order to help us respond efficiently to your request. If we receive a request from one of your Contacts, we will either direct the Contact to reach out to you, or, if appropriate, we may respond directly to their request.
We may use the information we collect through our Websites for a range of reasons, including:
- To provide, operate, optimise, and maintain our Websites.
- To send you information for marketing purposes, in accordance with your marketing preferences.
- To respond to your online enquiries and requests, and to provide you with information and access to resources or services that you have requested from us.
- To manage our Websites and system administration and security.
- To improve the navigation and content of our Websites.
- To identify any server problems or other IT or network issues.
- To process transactions and to set up online accounts.
- To compile aggregated statistics about site usage and to better understand the preferences of our Visitors.
- To carry out research and development to improve our products and services.
- To customise content and layout of the Websites.
- To carry out other legitimate business purposes, as well as other lawful purposes.
In addition, we may combine Personal Information with other information we collect or obtain about you (such as information we source from our third-party partners) to serve you specifically, such as to deliver a product or service according to your preferences or restrictions, or for advertising or targeting purposes in accordance with this privacy policy. When we combine Personal Information with other information in this way, we treat it as, and apply all of the safeguards in this privacy policy applicable to, Personal Information.
Testimonials. We have public testimonials on our Website. Any information you include in a comment on our blog may be read, collected, and used by anyone. If your Personal Information appears on our testimonials and you want it removed, contact us here.
Social media platforms and widgets. Our Websites include social media features, such as the Facebook Like button. These features may collect information about your IP address and which page you are visiting on our Website, and they may set a cookie to make sure the feature functions properly. Social media features and widgets are either hosted by a third party or hosted directly on our Website. We also maintain presences on social media platforms, including Facebook, Twitter, and Instagram. Any information, communications, or materials you submit to us via a social media platform is done at your own risk without any expectation of privacy. We cannot control the actions of other users of these platforms or the actions of the platforms themselves. Your interactions with those features and platforms are governed by the privacy policies of the companies that provide them.
Links to third-party websites. Our Website include links to other websites, whose privacy practices may be different from ours. If you submit Personal Information to any of those sites, your information is governed by their privacy policies. We encourage you to carefully read the privacy policy of any website you visit.
You have the following data protection rights: To access, correct, update, or request deletion of your Personal Information. Tangerine Bay takes reasonable steps to ensure that the data we collect is reliable for its intended use, accurate, complete, and up to date. You may contact us directly at any time about accessing, correcting, updating, or deleting your Personal Information, or altering your data or marketing preferences by contacting us through our contact form. We will consider your request in accordance with applicable laws.
In addition, if you are a resident of the EEA, you can object to processing of your Personal Information, ask us to restrict processing of your Personal Information or request portability of your Personal Information. Again, you can exercise these rights by contacting us through our contact form.
In addition, individuals who are residents of the EEA can object to processing of their Personal Information, ask to restrict processing of their Personal Information or request portability of their Personal Information. You can exercise these rights by contacting us through our contact form.
Similarly, if Personal Information is collected or processed on the basis of consent, the data subject can withdraw their consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Information conducted in reliance on lawful processing grounds other than consent.
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws. We may ask you to verify your identity in order to help us respond efficiently to your request.
2. GENERAL INFORMATION
We may share and disclose your Personal Information to the following types of third parties for the purposes described in this privacy policy (for purposes of this section, "you" and "your" refer to Members, Contacts, and Visitors unless otherwise indicated):
Our service providers: Sometimes, we share your information with our third-party service providers, who help us provide and support our products and other business-related functions.
- MailChimp https://mailchimp.com/legal/privacy/
- PayPal https://www.paypal.com/au/webapps/mpp/ua/privacy-full
For example, if it is necessary to provide Members something they have requested (like enable a feature such as Social Profiles), then we may share Members’ or Contacts’ Personal Information with a service provider for that purpose. Other examples include analysing data, hosting data, engaging technical support for our Services, processing payments, and delivering content.
These third-party service providers enter into a contract that requires them to use your Personal Information only for the provision of services to us and in a manner that is consistent with this privacy policy.
In connection with our Services, we use a third-party service provider, MailChimp, Inc. We use MailChimp’s API, which allows us to connect a module into our Tangerine Bay website to enable us to communicate with our Members through emails and email notifications, which we use for two-factor authentication for our application. If you are a Member, MailChimp may need to collect and process certain Personal Information about you as a controller to provide such services. To learn more about MailChimp’s privacy practices, please visit here.
Any competent law enforcement body, regulatory body, government agency, court or other third party where we believe disclosure is necessary (a) as a matter of applicable law or regulation, (b) to exercise, establish, or defend our legal rights, or (c) to protect your vital interests or those of any other person.
Any other person with your consent. If you are from the European Economic Area, our legal basis for collecting and using the Personal Information described above will depend on the Personal Information concerned and the specific context in which we collect it.
However, we will normally collect and use Personal Information from you where the processing is in our legitimate interests and not overridden by your data-protection interests or fundamental rights and freedoms. Typically, our legitimate interests include improving, maintaining, providing, and enhancing our technology, products and our Website; and for our marketing activities.
If you are a Member, we may need the Personal Information to perform a contract with you. In some limited cases, we may also have a legal obligation to collect Personal Information from you.
If we ask you to provide Personal Information to comply with a legal requirement or to perform a contact with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Information is mandatory or not, as well as of the possible consequences if you do not provide your Personal Information.
Where required by law, we will collect Personal Information only where we have your consent to do so.
If you have questions about or need further information concerning the legal basis on which we collect and use your Personal Information, please contact us using the contact details provided in the "Questions and Concerns" section below.
Unsubscribe/Opt Out. Members and Visitors who have opted in to our marketing emails can opt out of receiving marketing emails from us at any time by clicking the "unsubscribe" link at the bottom of our marketing messages.
Also, all opt-out requests can be made by emailing us using the contact details provided in the "Questions and Concerns" section below. Please note that some communications (such as service messages, account notifications, billing information) are considered transactional and necessary for account management, and Members cannot opt out of these messages unless you cancel your Tangerine Bay account.
We take appropriate and reasonable technical and organizational measures to protect Personal Information from loss, misuse, unauthorised access, disclosure, alteration, and destruction, taking into account the risks involved in the processing and the nature of the Personal Information. If you have any questions about the security of your Personal Information, you may contact us through our contact form.
Login Details. Tangerine Bay accounts require a username and password to log in. Members must keep their username and password secure, and never disclose it to a third party. Because the information in a Member’s Tangerine Bay account is so sensitive, account passwords are hashed, which means we cannot see a Member’s password. We cannot resend forgotten passwords either. We will only provide Members with instructions on how to reset them.
Cookies
A "cookie" is a packet of information that allows the Tangerine Bay server (the computer that houses our web site) to identify and interact more effectively with your computer. A Cooke does not store personal details.
When you access our web site, we send you a "temporary cookie" that gives you a unique identification number. A different identification number is sent each time you use our web site. Cookies do not identify individual users, although they do identify a user's internet browser type and your Internet Service Provider.
Our cookie allows us to keep track of the pages you have accessed on our web site. It also allows you to page back and forwards through our web site and return to pages you have already visited without having to bother about logging on to our home page again. You can configure your internet browser to accept all cookies, reject all cookies or notify you when a cookie is sent. Please refer to your internet browser's instructions or help screens to learn more about these functions.
3. PRIVACY IN YOUR COUNTRY
We operate in Australia. Our servers and offices are located in Australia, so your information may be transferred to, stored, or processed in Australia. While the data protection, privacy, and other laws of Australia might not be as comprehensive as those in your country, we take many steps to protect your privacy, including offering our Members a Data Processing Agreement.
Members located in Australia. If you are a Member who lives in Australia, this section applies to you. We are subject to the operation of the Privacy Act 1988 ("Australian Privacy Act"). Here are the specific points you should be aware of:
Where we say we assume an obligation about Personal Information, we are also requiring our subcontractors to undertake a similar obligation, where relevant.
We will not use or disclose Personal Information for the purpose of our direct marketing to you unless you have consented to receive direct marketing; you would reasonably expect us to use your personal details for the marketing; or we believe you may be interested in the material but it is impractical for us to obtain your consent. You may opt out of any marketing materials we send to you through an unsubscribe mechanism or by contacting us directly. If you have requested not to receive further direct marketing messages, we may continue to provide you with messages that are not regarded as "direct marketing" under the Australian Privacy Act, including changes to our terms, system alerts, and other information related to your account.
Our servers are located in the Australia. In addition, we or our partners may use cloud technology to store or process Personal Information, which may result in storage of data outside Australia. All of our subcontractors, however, are required to comply with the Australian Privacy Act in relation to the transfer or storage of Personal Information overseas.
Data transfers from Switzerland or the EU to Australia. Tangerine Bay participates in and has certified its compliance with the EU-OAIC’s Privacy Framework and the Swiss-OAIC’s Privacy Framework. We are committed to subjecting all Personal Information received from European Union (EU) member countries and Switzerland, respectively, in reliance on each OAIC Framework, to each Framework’s applicable Principles.
Tangerine Bay is responsible for the processing of Personal Information we receive under each OAIC Framework and subsequently transfer to a third party acting as an agent on our behalf. We comply with the OAIC Principles for all onward transfers of Personal Information from the EU and Switzerland, including the onward transfer liability provisions.
With respect to Personal Information received or transferred pursuant to the OAIC Frameworks, we are subject to the regulatory enforcement powers of the Australian Government Office of the Australian Information Commissioner. In certain situations, we may be required to disclose Personal Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact the Office of the Australian Information Commissioner. Under certain conditions, more fully described on the OAIC website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
Members located in California. Under California Law, California residents have the right to request in writing from businesses with whom they have an established business relationship, (a) a list of the categories of Personal Information, such as name, email, and mailing address, and the type of services provided to the customer that a business has disclosed to third parties (including affiliates that are separate legal entities) during the immediately preceding calendar year for the third-parties’ direct marketing purposes, and (b) the names and addresses of all such third parties. To request the above information, please contact us through our contact form.
4. CONCERNS
If you think the information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, we will take reasonable steps, consistent with our obligations under the Australian Privacy Act, to correct that information upon your request.
If you are unsatisfied with our response to a privacy matter then you may consult either an independent advisor or contact the Office of the Australian Information Commissioner for additional help. We will provide our full cooperation if you pursue this course of action.
We retain Personal Information where we have an ongoing legitimate business or legal need to do so. Our retention periods will vary depending on the type of data involved, but, generally, we'll refer to these criteria in order to determine retention period:
- Whether we have a legal or contractual need to retain the data.
- Whether the data is necessary to provide our Services.
- Whether our Members have the ability to access and delete the data within their Tangerine Bay accounts.
- Whether our Members would reasonably expect that we would retain the data until they remove it or until their Tangerine Bay accounts are closed or terminated.
- When we have no ongoing legitimate business need to process your Personal Information, we will either delete or anonymise it or, if this is not possible (for example, because your Personal Information has been stored in backup archives), then we will securely store your Personal Information and isolate it from any further processing until deletion is possible.
Changes to our Policy. We may change this privacy policy at any time and from time to time. The most recent version of the privacy policy is reflected by the version date located at the top of this privacy policy. All updates and amendments are effective immediately upon notice, which we may give by any means, including, but not limited to, by posting a revised version of this privacy policy or other notice on the Websites. We encourage you to review this privacy policy often to stay informed of changes that may affect you. Our electronically or otherwise properly stored copies of this privacy policy are each deemed to be the true, complete, valid, authentic, and enforceable copy of the version of this privacy policy that was in effect on each respective date you visited the Website.
5. OUR OBLIGATION AND COMMITMENT
Tangerine Bay’s Privacy Policy respects the privacy of all members and visitors to our website and social media accounts. Tangerine Bay fosters transparent information handling practices and business accountability, to give individuals confidence that their privacy is being protected. Both laws require businesses to implement measures that ensure compliance with a set of privacy principles, and both take a privacy by design approach to compliance. Tangerine Bay is complaint with The European Union General Data Protection Regulation (the GDPR) and the Australian Privacy Act 1988.
Questions or Comments. If you have any questions or comments, or if you have a concern about the way in which we have handled any privacy matter, please use our contact form to email us or send a letter to:
Tangerine Bay
PO Box 803
Jimboomba, Queensland 4280
Australia
Further information on privacy
Should you require more specific details concerning our privacy practices please contact us via email on our contact page. Or you can obtain further general information about privacy protection from the Office of the Federal Privacy Commissioner by:
Calling their Privacy Hotline on 1300 363 992, or visiting their web site at www.privacy.gov.au, or
by writing to:
The Federal Privacy Commissioner
GPO Box 5218
Sydney NSW 1042
© 2018 Tangerine Bay. All Rights Reserved.