1. What Data We Collect
1.1 Data You Provide to Us
When you create an account and use the Services, including through a third-party platform, we collect any data you provide directly, including:
|Account Data||In order to use certain features (like purchasing products), you need to create a user account. When you create or update your account, we collect and store the personal data you provide, like your name, address, mobile or land line telephone number, email address, password, gender, and date of birth (“Account Data”).|
|Shared Content||Parts of the Services let you interact with other users or share content publicly (for instance, when you post reviews on a product page). Such shared content may be publicly viewable by others depending on where it is posted.|
|Data About Your Accounts on other Platforms||We may obtain certain information through your online accounts if they are connected to your Farm Rio account. If you purchase Farm Rio products using Shopify; Global-e (for sales outside the U.S.); Facebook; Google; or another third-party platform or service, we ask for your permission to access certain information about that other account. For example, depending on the platform or service, we may collect your name, profile picture, account ID number, login email address, location, physical location of your access devices, gender, birthday, and list of friends or contacts.|
|Communications and Support||If you contact us for support or to report a problem or concern (regardless of whether you have created an account), we collect and store your contact information, the correspondence, and other data about you like your name, email address, location, operating system, IP address, and any other data you provide or that we collect through automated means (which we cover below).|
The data listed above is stored by us and associated with your account.
1.2 Data We Collect through Automated Means
When you access the Services (including browsing products by visiting our websites/apps), we collect certain data by automated means, including:
|System Data||Technical data about your computer or device, like your IP address, device type, operating system type and version, unique device identifiers, browser, browser language, domain and other systems data, and platform types (“System Data”).|
|Usage Data||Usage statistics about your interactions with the Services, including products viewed, time spent on pages or the Service, pages visited, features used, your search queries, click data, date and time, and other data regarding your use of the Services (“Usage Data”).|
|Approximate Geographic Data||An approximate geographic location, including information like country, city, and geographic coordinates, calculated based on your IP address.|
2. How We Get Data About You
2.1 Cookies and Data Collection Tools
We use web beacons (small objects that allow us to measure the actions of visitors and users using the Services) for things like identifying whether a page was visited, identifying whether an email was opened, and advertising more efficiently by excluding current users from certain promotional messages or identifying the source of a new order or account.
We use third-party browser and mobile analytics providers like Google Analytics, Facebook and Shopify. These providers use Data Collection Tools to help us analyze your use of the Services, including information like the third-party website you arrive from, how often you visit our site, usage and performance data, and your purchasing behavior. We use this data to improve the Services, better understand how the Services perform, and provide information that may be of interest to you.
2.3 Online Advertising
We use third-party advertising services like Facebook, Google, and other ad networks and ad servers to deliver advertising about our Services on other websites and applications you use.
The ads may be based on things we know about you, like your Usage Data and System Data (as detailed in Section 1), and things that these ad service providers know about you based on their tracking data. The ads can be based on your recent activity or activity over time and across other sites and services, and may be tailored to your interests.
Certain advertising services we use may also place cookies or other tracking technologies on your computer, phone, or other device to collect data about your use of our Services, and may access those tracking technologies in order to serve these tailored advertisements to you.
With your consent, we may send you marketing communications, for example by email to provide you with information on products, services that we, or third parties offer, competitions and other marketing information that we consider may be relevant to you or that you might be interested in, even after you cease acquiring products or services from us. You have the option to withdraw your consent to these communications at any time by following the unsubscribe link included in any marketing emails we send.
3. What We Use Your Data For
We use your data to do things like troubleshoot issues, secure against fraud and abuse, serve personalized advertising, and as required by law or necessary for safety and integrity.
We also use the data we collect through your use of the Services to:
- Provide and administer the Services, including to display customized content and facilitate communication with you;
- Process your requests and orders for products, information, or features;
- Communicate with you about your account by:
- Responding to your questions and concerns and verifying your identity in order to do so;
- Sending you administrative messages and information, including messages regarding your orders, notifications about changes to our Service, and updates to our agreements;
- Sending you information and messages about our rewards programs, new services, new features, new products, promotions, recipes, and newsletters (which you can opt out of at any time);
- Manage your account preferences;
- Facilitate the Services’ technical functioning, including troubleshooting and resolving issues, securing the Services, and preventing fraud and abuse;
- Solicit feedback from users;
- Market and administer surveys and promotions operated or sponsored by Farm Rio;
- Learn more about you by linking your data with additional data through third-party data providers or analyzing the data with the help of analytics service providers;
- Identify unique users across devices and browsers;
- Tailor advertisements across devices and browsers;
- Improve our Services and develop new products, services, and features;
- Track purchases and usage data to analyze trends and traffic;
- Advertise the Services on third-party websites and applications;
- Conduct activities required or permitted by law; or
- To take other actions that, in our sole discretion, we determine to be necessary to ensure the safety or integrity of our users, employees, third parties, the public, or our Services.
- We have a legitimate interest. This is the most flexible legal basis for Processing and may only be relied upon if our legitimate interests are not overridden by your interests or fundamental rights and freedoms. When relying on this purpose, we will conduct a balancing test or legitimate interest assessment to determine if your rights and freedoms override our interests in Processing Personal Data.
- We have a contractual obligation. We rely on this legal basis where we have entered into a contract with you (such as a purchase order) and it is necessary for us to process your personal data to comply with the our obligations under such contract. For instance, we will require your delivery address to send you the items you have purchased as part of your purchase order.
- We have your consent. We rely on this legal basis to process your personal data when you have consented to such processing. Your consent must be freely given, informed, undisputable/unambiguous and capable of being withdrawn at any time.
- Performance of legal or regulatory obligation. We can rely on this legal basis to process your personal data when it is necessary for us to comply with a legal obligation to which we are subject. For instance, we may be asked by a government authority, court, or law enforcement agency to share your personal information.
4. Who We Share Your Data With
- With Service Providers, Contractors, and Agents. We share your data with third-party companies who perform services on our behalf, like payment processing, product delivery, data analysis, marketing and advertising services (including retargeted advertising), email and hosting services, and customer services and support. These service providers may access your personal data and are required to use it solely as we direct to provide our requested service.
- With Analytics and Data Enrichment Services. As part of our use of third-party analytics tools like Google Analytics and data enrichment services, we share certain contact information, Account Data, System Data, Usage Data (as detailed in Section 1), or de-identified data as needed. De-identified data means data where we’ve removed things like your name and email address and replaced it with a token ID. This allows these providers to provide analytics services or match your data with publicly-available database information (including contact and social information from other sources).
- To Administer Promotions and Surveys. We may share your data as necessary to administer, market, or sponsor promotions and surveys you choose to participate in, as required by applicable law (like to provide a winners list or make required filings), or in accordance with the rules of the promotion or survey.
- For Security and Legal Compliance. We may disclose your data to third parties if we (in our sole discretion) have a good faith belief that the disclosure is:
- Permitted or required by law;
- Requested as part of a judicial, governmental, or legal inquiry, order, or proceeding;
- Reasonably necessary as part of a valid subpoena, warrant, or other legally-valid request;
- Required to detect, prevent, or address fraud, abuse, misuse, potential violations of law (or rule or regulation), or security or technical issues; or
- Reasonably necessary in our discretion to protect against imminent harm to the rights, property, or safety of Farm Rio, our users, employees, members of the public, or our Services.
- During a Change in Control. If Farm Rio undergoes a business transaction like a merger, acquisition, corporate divestiture, or dissolution (including bankruptcy), or a sale of all or some of its assets, we may share, disclose, or transfer all of your data to the successor organization during such transition or in contemplation of a transition (including during due diligence).
- Soma Group. We may share your data as necessary to provide the Services with other companies in the Soma Group, some of which are located outside of the EEA and UK. The countries to which your data may be transferred include Brazil, the United States, France, the United Kingdom and Switzerland.
Farm Rio takes appropriate security measures to protect against unauthorized access, alteration, disclosure, or destruction of your personal data that we collect and store. These measures vary based on the type and sensitivity of the data. Unfortunately, no system is 100% secure, so we cannot guarantee that communications between you and Farm Rio, the Services, or any information provided to us in connection with the data we collect through the Services will be free from unauthorized access by third parties. Your password is an important part of our security system so you must protect your password and contact us if you suspect any unauthorized access to your account.
6. Your Rights
You have certain rights relating to our use of your data, including the ability to opt out of promotional emails, cookies, and collection of your data by certain analytics providers. You can update or terminate your account from within our Services, and can also contact us to exercise your rights with respect to your personal data. A parent who believes we have unintentionally collected personal data about their underage child should contact email@example.com with any concerns.
6.1 Your Choices About the Use of Your Data
You can choose not to provide us with certain data but you may not be able to use certain features of the Services.
- To stop receiving promotional communications from us, you can opt out by using the unsubscribe mechanism in the promotional communication you receive or by changing the email preferences in your account. Regardless of your email preference settings, we will send you transactional and relationship messages regarding the Services, including administrative confirmations, order confirmations, important updates about the Services and notices about our policies.
- To opt out of Google’s display advertising or to customize Google Display Network ads, visit the Google Ads Settings page.
- To opt out of allowing Google Analytics to use your data for analytics or enrichment, see the Google Analytics Opt-out Browser Add-on.
- To update data you provide directly, you can log into your account and update such information.
6.2 Your rights relating to your personal data
Under the data protection laws we comply with, you may have the right to:
- Request access to your personal data. This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
- Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us to continue to process it. You also have the right to ask us to delete or remove your personal data where you have exercised your right to object to processing.
- Object to processing of your personal data. This right exists where we are relying on a Legitimate Interest as the legal basis for our processing and there is something about your particular situation, which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal data for direct marketing purposes.
- Request the restriction of processing of your personal data. This enables us to suspend the processing of personal data about you, for example if you want us to establish its accuracy or the reason for processing it.
- Request the transfer of your personal data. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw consent. This right only exists where we are relying on consent to process your personal data. If you withdraw your consent, we may not be able to provide you with access to certain functionalities of our Services.
6.3 How to exercise your rights
- If you want to exercise any of the rights described above, please email us at firstname.lastname@example.org. Please allow up to 30 days for a response. For your protection, we may require that the request be sent through the email address associated with your account, and we may need to verify your identity before implementing your request. Please note that we retain certain data where we have a lawful basis to do so, including for mandatory record-keeping and to complete transactions.
6.4 Our Policy Concerning Children
The Services are not intended for the use of children under the age of 16 and we do not knowingly collect data relating to such children. If we learn that we’ve collected personal data from a child under 16 years of age, we will take reasonable steps to delete it.
Parents who believe that Farm Rio may have collected personal data from a child under those ages can submit a request that it be removed to email@example.com.
7. Jurisdiction-Specific Rules
7.1 Users in California
If you are a California resident, you have the right to request certain details about what personal information we share with third parties for those third parties’ direct marketing purposes. To submit your request, send an email to firstname.lastname@example.org with the phrase “California Shine the Light” and include your mailing address, state of residence, and email address.
Since the internet industry is still working on Do Not Track standards, solutions, and implementations, we do not currently recognize or respond to browser-initiated Do Not Track signals.
7.2 Users Residing in the EU or UK
Farm Rio is registered in the United States, and some of our external third parties, including service providers, may be based outside of the European Economic Area (EEA) and UK so the processing of your personal data will involve a transfer of data to countries outside of the EEA and UK. By visiting or using our Services, you acknowledge and accept that we may transfer, store, or process your data on servers located outside of the EEA and UK, where the transfer relates to us sharing your data as set out in section 4 above.
We have entered into data processing agreements with our service providers that restrict and regulate their processing of your data on our behalf. Where your personal data is transferred to a country which is not recognized as having adequate protection for personal data, we will enter into standard terms approved by the European Commission or UK Government (as appropriate) as a way of putting adequate safeguards in place to protect your personal data and comply with data protection laws. You can obtain further information about this by contacting us at email@example.com.
8. Updates & Contact Info
You can also lodge a complaint with your national Data Protection Authority if you are unhappy with how we have used your data.