Privacy Policy
Privacy policy
This Privacy Policy describes Restitution Brands LLC dba TERRAPASS’ website and services (collectively, the “Service”). Restitution Brands LLC dba TERRAPASS (“TERRAPASS,” “we,” “us,” or “our”) and its wholly owned subsidiaries comply with the Personal Information Protection and Electronic Documents Act (“PIPEDA”) of Canada and the General Data Protection Regulation (GDPR) of the EU/UK for use and retention of personal information transferred from the Swiss and the European Union or Canada to the United States.
If you have questions, concerns, or believe there is an enforcement breach regarding this Privacy Policy, you should contact our Data Protection Officer at [email protected].
What Does This Notice Cover
This Website Privacy Notice applies only to your use of our website. Our site may contain links to other websites. Please note that we have no control over how your data is collected, stored, or used by other websites and we advise you to check the privacy policies of any such websites before providing any data to them.
What Is Personal Data?
Personal data is defined by the General Data Protection Regulation (EU Regulation 2016/679) (the “GDPR”) as ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’. Personal data is, in simpler terms, any information about you that enables you to be identified. Personal data covers obvious information such as your name and contact details, but it also covers less obvious information such as identification numbers, electronic location data, and other online identifiers. If you do not provide us with your personal data, we may not be able to provide you with our services or respond to any questions or requests you submit to us via our website. We will tell you when we ask for personal data which is a contractual requirement or is needed to perform our functions or to comply with our legal obligations.
Legal basis for collecting and processing your personal information
Our legal basis for obtaining and utilizing your personal information, as this policy outlines, depends on the context in which it is collected.
We may collect your personal data because:
- Consent
- Legitimate interests
- Compliance with laws
Why we process personal data
We process personal data for the following purposes:
- To operate and maintain our service
- To notify you about changes to our service
- To provide customer support
- To gather analytical data to improve our service
- To monitor the usage of our service
- To detect, prevent and address technical issues
- To communicate with you
Third-Party Payment Processors
When you subscribe to our services, third-party providers will be authorized to process your payment information. In these situations, we do not have access to your payment details. Instead, the third-party processors responsible for your payments, will have access to your data:
- Stripe
- PayPal
What Personal Data do we collect and how?
Our site collects certain information automatically, including your IP address, the type of browser you are using, and certain other non-personal data about your computer or device such as your operating system type or version, and display resolution. You can remove or reject cookies using your browser or device settings, but in some cases doing so may affect your ability to use our products and services.
We collect the following personally identifiable information about our users: name, e-mail address, corporate web address, telephone number, business address, preferred means of communication, and other voluntarily provided information. This personally identifiable information is typically provided when users register for online services, subscriptions, communications, surveys, or to request information. We also collect information about users regarding web pages accessed, traffic patterns and site usage. You can manage your permissions by clicking our Settings.
With whom we share the collected personal information
To facilitate and make our website accessible to visitors, we engage third-party companies and individuals (‘Data Processors’) who may require access to your personal information. These tools may use cookies and other tracking technologies:
- Metorik
Please note that these service providers only have access to your personal information to perform the tasks we have assigned to them, and they are obligated not to disclose or use it for any other purpose.
Some of these third-party service providers may track your online behavior over time and across different internet websites or online services. However, we do not have control over their data collection practices or the use of your personal information. Therefore, we encourage you to review their privacy policies before consenting to the use of their services on our website.
We share or disclose your personal information with the following third-party service providers:
Analytics
We use a 3rd party analytical software to gather statistical information about our website visitors. The services we use include:
- SourceBuster
- Google Analytics
- Metorik
Data Retention
The duration for which we retain each specific category of personal data depends on the processing purpose for which it was collected. We will store your personal data only for as long as it is necessary to fulfill the specific processing purpose for that category of data.
Following the deletion of your personal information from our database, the related backup data will be deleted, generally within 1 days.
General Data Protection Regulation (GDPR)
As a leading climate action and carbon offset services provider, TERRAPASS, has made the security and protection of your data a top priority by using state-of-the-art physical, technological, and procedural security safeguards.
The cornerstone to our platform is a rigorous security system that we—and by extension, you—can trust. We employ multiple safeguards and security protocols that are trusted in the industry with the singular goal of ensuring your data is protected.
We use multiple security measures, such as firewalls, encryption, IDS/IPS, physical/logical security, and regular security audits (to name a few), to safeguard the confidentiality of our users’ personally identifiable information. Information we collect about our users is stored on secured servers.
If you shoould have any questions about the security of the services or the TERRAPASS environment, please inquire by sending an email to [email protected].
Resolution of Complaints
In compliance with the General Data Protection Regulation (GDPR) principles, TERRAPASS commits to the resolution of complaints and our collection or use of your information. We have also committed to resolving any complaints pursuant to the General Data Protection Regulation (GDPR) by EU, UK, and Swiss individuals with inquiries or complaints regarding our GDPR policy should first contact TERRAPASS at: [email protected].
What are your rights as the owner of personal information
You have the following data protection rights:
- The right to access your data
- The right to update or correct your data
- The right to object to the use of your data
- The right to restrict the use of your data
- The right to transfer your data to another data controller
- The right to the erasure of your data
- The right to withdraw consent
- The right to opt-out
- The right to lodge a complaint to the relevant data protection authority
Correction/Updating Personally Identifiable Information
You can ask to see the personal information that we hold about you. If you want to review, verify, or correct your personally identifiable information, or if you no longer desire TERRAPASS’s services, we will endeavor to provide a way to correct, update, or remove the data you provided to us. Please note that any such communication must be in writing by sending an e-mail to [email protected]. In the event that we cannot provide you with access to your personal information, we will endeavor to inform you of the reasons why, subject to any legal or regulatory restrictions.
Our response to universal opt-out mechanisms
Where the applicable regulations require us, we honor the opt-out signals you send to us by universal opt-out mechanisms.
Universal opt-out mechanisms are tools designed to give you more control over your online privacy by simplifying the process of opting out of data collection and sharing practices. You can set your preferences through your browser, and once it sends your opt-out preferences to us, we will honor your request.
How can you exercise your rights as the owner of personal information
If you would like to exercise your rights under the state law, you may submit your requests to us through the following channels:
- Email: [email protected]
- Website: https://terrapass.com
Please note that we may ask you to verify your identity before responding to your request to protect the security of your personal information.
You also have the right to file a complaint with a Data Protection Authority regarding our collection and use of your personal information. For more information on this, please contact your local data protection authority.
Personal Information Protection and Electronic Documents Act (PIPEDA)
TERRAPASS complies with Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”). PIPEDA sets out rules for the collection, use, and disclosure of personal information in the course of commercial activity as defined in the Act.
TERRAPASS fully complies with the 10 principles of PIPEDA, which are accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and providing recourse.
Complaints/Questions
Any questions or concerns about TERRAPASS’s personal information handling practices may be directed to the Privacy Officer. Requests for access to information or to make a complaint are to be made in writing (via letter or email) and sent to the Privacy Officer at the address;
Privacy Officer
5444 Westheimer Rd,
Ste 1000, Houston, TX 77056 Toll Free: +1 800 252 0522 or Email address: [email protected]
If the client is dissatisfied with the findings and corresponding action taken by TERRAPASS’s Privacy Officer, the client may bring a complaint to the Federal Privacy Commissioner at the address below:
The Privacy Commissioner of Canada 112 Kent Street Place de Ville Tower B, 3rd Floor Ottawa, Ontario K1A 1H3 Toll Free +1 800 282 1376 Email: [email protected] Website: www.priv.gc.ca
TERRAPASS’s full Standard Operating Procedure (SOP) for PIPEDA can be provided upon request by emailing [email protected].
California Privacy Rights Act (CPRA)
At Terrapass, we prioritize your data privacy. We are fully compliant with the California Privacy Rights Act (CPRA), ensuring that your personal information is handled with care and transparency.
We are committed to protecting your personal information and ensuring full compliance with the California Privacy Rights Act of 2020 (CPRA), which enhances the privacy rights of California consumers.
For any questions or inquiries concerning how Terrapass addresses its obligations and your rights under the CPRA, including your rights to know, delete, correct, opt-out of your personal information, and limit the use and disclosure of your sensitive personal information, please email [email protected] or click here to contact us via our request form.
Location and transfer of your personal information
We utilize several third-party service providers, including:
- Metorik
These providers are considered our data processors and are contractually bound to keep your personal information secure and confidential. They may only use your data for the purposes outlined in our agreement with them.
We store your data in the following locations:
- United States of America
However, some of these third-party service providers may be located in countries outside these locations. In such cases, we ensure that your data is transferred based on appropriate safeguards, such as adequacy decisions, standard contract clauses, or another transfer tool.
We take all reasonable steps to ensure that your data is treated securely and that no transfer of your personal data will take place to an organization or a country unless adequate controls are in place to safeguard your data and other personal information. We are committed to maintaining the security of your personal information and protecting your privacy rights.
Security of your personal information
We understand how important it is to keep your personal information secure. To protect your data, we implement the following technical measures:
- Encryption
- Two-factor authentication
- Backups
- Firewalls & malware protection
We also ensure that our sub-contractors are aware of our privacy policy and receive regular updates on our security practices.
We recommend that you use a strong and unique password, keep it confidential, and log out of your account on shared computers to safeguard the security of your personal information. At our company, we take the security and privacy of your data seriously and work hard to keep it safe.
Protecting your child’s privacy
We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your children have provided us with personal data, please contact us. If we become aware that we have collected personal data from children without verification of parental consent, we take steps to remove that information from our servers.
Changes to this privacy policy
From time to time we may update this Privacy Policy. If we do, we will update the “last updated” sections at the top of the Privacy Policy. If we make material changes to this policy, we may notify you on our website, by a blog post, by email, or by any method we determine. Your continued use of this website or our service and/or continued provision of information to us will be subject to the terms of the then-current Privacy Policy.
Contact us
If you have any questions about our Privacy Practices or this Policy, our Data Protection Officer contact details are:
- Email: [email protected]
- Website: https://terrapass.com/
- Address: 5444 Westheimer Rd, Suite 1000, Houston, TX 77056, USA