Privacy policy
Purpose of this notice
This Website Privacy Notice (this "Notice") explains which personal data are collected when you visit our website www.supportbravehood.org (our "Website") and how this data is processed by the non-profit organization Guiding Lights – Society to support people in need and charity initiatives, Postfach 0007, 1166 Vienna (Reg. No: 1500277594) as the data controller ("Guiding Lights" or "we").
This Notice is addressed to any visitor of our Website ("data subject "or "you").
We process your personal data in accordance with the EU General Data Protection Regulation ("GDPR") and applicable national data protection laws. Unless otherwise defined in this Notice, the terms used herein shall have the same meaning as defined in the GDPR.
What personal data we collect and how we use it
When you use our Website we may process those personal data which you voluntarily provide to us (e.g. by means of our contact form).
However, you can also visit our Website without actively providing us with information about you. In this case we collect certain data that your browser transmits to our website server (i.e. log files) as well as data that we collect via the use of cookies or similar technologies.
The following explanations shall serve to inform you about the different ways we may collect personal data about you on our Website and for what lawful purposes we may use them.
Personal data you actively disclose to us
When you actively communicate with us via our Website, we process those personal data that you voluntarily provide to us. In particular, this relates to our following services:
-
Contact forms: When you choose to contact us via the contact form provided on our Website the personal data you provide to us (e.g. name, email address, correspondence) will be processed for the purpose of answering your questions, fulfilling your requests or otherwise communicating with you.
Legal basis: Art 6(1) b GDPR – performance of (pre-)contractual duties. -
Orders of our products and donations: If you donate or order one of our #bravehood products, we need to process your personal data in order to fulfill our request and our contractual duties with you (e.g. your payment information, contact details, delivery address for shipping).
Legal basis: Art 6(1) b GDPR – performance of (pre-)contractual duties. -
User Account: If you have registered a user account on our Website, the personal data you voluntarily provide to us (e.g. name, email address, date of birth, password, product requests) will be processed for the purposes of providing you access to your user account and to send you personalized content offers.
Legal basis: Art 6(1) b GDPR – performance of contract.
Some of the data we request in connection with our above services may be marked as mandatory fields. You are not required to provide these data. However, without providing this information we may not be able to process your request or provide our services.
Log files
You may also visit our Website without actively providing us with information about you. In this case we collect certain data that your browser transmits to our website server (i.e. log files).
Our log files contain the following information: (i) date and time of retrieval of our Website, (ii) type, version and settings of your web-browser, (iii) your operating system and internet service provider, (iv) requested pages and files, (v) website used prior to visiting our Website as well as (vi) your IP-address. The IP address is a specific number assigned to your computer which enables your device to communicate in a network using the Internet Protocol (IP). IP addresses may qualify as personal data as they technically allow the identification of the user in certain circumstances.
The processing of these log files is necessary for us to maintain the functionality, stability and security of our Website. We may also process them for the purpose of forensic investigations in the case of a security incident or in order to generate user statistics. For statistical purposes your IP-address is used in anonymized form only.
Legal basis: Art 6(1) f GDPR – legitimate interest in maintaining functionality, stability and security of our Website.
Cookies
In addition, this Website uses cookies. These are small text files that may be placed on your device while browsing our Website which store certain information about you. Cookies cannot access, read or modify other data stored on your device. When we refer to “cookies” we include other technologies with similar purposes, such as pixel tags.
We use two types of cookies on our Website:
Essential cookies: Essential cookies help to make a website usable by enabling basic functions such as page navigation and access to secure areas of the website. Without these cookies, the website cannot function properly. For a detailed description of the used necessary cookies and respective purposes kindly see list below.
Legal basis: Section 165 Telecommunications Act 2021
Statistical cookies: Statistical cookies help shop owners understand how customers interact with websites by anonymously collecting and reporting information. Marketing cookies are used to track visitors across Web pages. The goal is to serve advertisements that are relevant and appealing to the individual user and are therefore more valuable to third-party advertisers. For a detailed description of the used optional cookies and respective purposes kindly see list below.
Legal basis: Art 6(1) a GDPR – consent
Essential cookies used on our Website
Name | Function | Duration |
---|---|---|
_ab | Used in connection with access to admin. | 2y |
_secure_session_id | Used in connection with navigation through a storefront. | 24h |
_shopify_country | Used in connection with checkout. | session |
_shopify_m | Used for managing customer privacy settings. | 1y |
_shopify_tm | Used for managing customer privacy settings. | 30min |
_shopify_tw | Used for managing customer privacy settings. | 2w |
_storefront_u | Used to facilitate updating customer account information. | 1min |
_tracking_consent | Tracking preferences. | 1y |
c | Used in connection with checkout. | 1y |
cart | Used in connection with shopping cart. | 2w |
cart_currency | Used in connection with shopping cart. | 2w |
cart_sig | Used in connection with checkout. | 2w |
cart_ts | Used in connection with checkout. | 2w |
cart_ver | Used in connection with shopping cart. | 2w |
checkout | Used in connection with checkout. | 4w |
checkout_token | Used in connection with checkout. | 1y |
dynamic_checkout_shown_on_cart | Used in connection with checkout. | 30min |
hide_shopify_pay_for_checkout | Used in connection with checkout. | session |
keep_alive | Used in connection with buyer localization. | 2w |
master_device_id | Used in connection with merchant login. | 2y |
previous_step | Used in connection with checkout. | 1y |
remember_me | Used in connection with checkout. | 1y |
secure_customer_sig | Used in connection with customer login. | 20y |
shopify_pay | Used in connection with checkout. | 1y |
shopify_pay_redirect | Used in connection with checkout. | 30 minutes, 3w or 1y depending on value |
storefront_digest | Used in connection with customer login. | 2y |
tracked_start_checkout | Used in connection with checkout. | 1y |
checkout_one_experiment | Used in connection with checkout. | session |
Statistical cookies used on our Website
Name | Function | Duration |
---|---|---|
_landing_page | Track landing pages. | 2w |
_orig_referrer | Track landing pages. | 2w |
_s | Shopify analytics. | 30min |
_shopify_d | Shopify analytics. | session |
_shopify_s | Shopify analytics. | 30min |
_shopify_sa_p | Shopify analytics relating to marketing & referrals. | 30min |
_shopify_sa_t | Shopify analytics relating to marketing & referrals. | 30min |
_shopify_y | Shopify analytics. | 1y |
_y | Shopify analytics. | 1y |
_shopify_evids | Shopify analytics. | session |
_shopify_ga | Shopify and Google Analytics. | session |
How to control and manage the use of cookies
By clicking on the "Accept"-button in the Website's cookie banner you agree to the use of the above listed optional cookies on our Website. Your consent can be withdrawn (for all or individual cookies) at any time with effect for the future.
You may also refuse the use of cookies by selecting the appropriate settings on your browser or by deleting the cookies from the device and browser. Most browsers accept cookies automatically, but you can alter the settings of your browser to erase cookies or prevent automatic acceptance if you prefer. Generally you have the option to see what cookies have been placed and delete them individually, block third party cookies or cookies from particular sites, accept all cookies, to be notified when a cookie is issued or reject all cookies. Visit the ‘options’ or ‘preferences’ menu on your browser to change settings, and check the following links for more browser-specific information:
Cookie settings in Internet Explorer
Cookie settings in Firefox
Cookie settings in Chrome
Cookie settings in Safari
You should be aware that any preferences will be lost, if you delete all cookies and many websites will not work properly or you will lose some functionality. We do not recommend turning cookies off when using our website for these reasons.
To whom we may disclose your personal data
For the above mentioned purposes we may share your personal data with the following recipients:
-
Guiding Light - Organisation for Ethics and Sustainability in Technologies
-
Shopify
-
Printful
-
Advertising und web-analysis partners who provide certain services to us in connection to our Website
-
Where disclosure is required (i) by law or regulation or (ii) to establish, exercise or defend legal claims, we may also disclose personal data to a competent authority, such as supervisory, regulatory or criminal authorities, courts of law or other third parties who advise us in this context (e.g. lawyers or forensics experts).
Some of these recipients may be located in countries outside the EU/EEA for which an adequate level of data protection has not yet been established by the EU Commission. In particular, this includes our group companies. It should be noted that the level of data protection in such countries may not be the same as within the EU/EEA. Also, subject to local laws and regulations data may be accessible to local authorities or courts.
However, where personal data is transferred to such third countries we implement appropriate safeguards to ensure that your rights are protected in accordance with the GDPR. Further details on the implemented safeguards as well as copies of the respective agreements are available on request at contact@supportbravehood.org.
How long we keep your personal data
Log files (see Section 2.5 above) are generally kept for a period of three months. Beyond this time period log files will only be stored for the purpose of investigating irregularities or security incidents in our system. For the storage duration of cookies see Section 2.6 above.
We generally retain your personal data for as long as this is necessary for the fulfilment of the purpose for which they were obtained. Thus, in any case we process your personal data for the duration of our contractual or service relationship with you (see Section 2.4 above). Beyond this time period we keep your personal data to comply with statutory retention obligations (e.g. to fulfill the 7-year retention obligation under applicable tax and company law). Where necessary we may also keep your data for as long as potential legal claims against us are not yet time-barred; for certain claims the statutory limitation period may be up to 30 years.
As soon as there are no legitimate grounds for the further storage of personal data available, they will either be deleted or anonymized.
Your rights as a data subject
As a data subject you have inter alia the following rights under the statutory conditions:
-
to check whether and what kind of personal data we hold about you and to request copies of such data (right of access)
-
to request correction, supplementation or deletion of your personal data that is inaccurate or processed in non-compliance with applicable requirements (right to rectification and erasure)
-
to request us to restrict the processing of your personal data (right to restriction)
-
in certain circumstances, to object for legitimate reasons to the processing of your personal data or to revoke consent previously granted for the processing (right to object or withdraw consent)
-
to receive the personal data you provided to us in a structured, commonly used and machine-readable format and to transmit those data to another controller (right to data portability)
We do not process your personal data for the purpose of taking decisions based solely on automated processing, including profiling, which produce legal effects concerning you (Art 22 GDPR).
To exercise any of the above rights kindly send an email to contact@supportbravehood.org. In addition, you have the right to lodge a complaint with a supervisory authority, if you believe your data protection rights have been violated. For Austria the competent authority is the Data Protection Authority (Datenschutzbehörde).
Updates to this notice
We may update this Notice to reflect legal, technical or business changes. When we update this Notice, we will take reasonable steps to inform you about the changes made. You will find the date of the "last update" at the end of this Notice.
Disclaimer
The Website contains links to third-party websites. We have no control over the content or privacy practices of these other websites. Please read the respective data protection provisions of other websites that you visit.
Our contact details
Should you have any requests or questions in relation to the processing of your personal data by us, kindly address them at contact@supportbravehood.org.
Our office address:
Guiding Lights – Society to support people in need and charity initiatives
Postfach 0007
1166 Vienna
Austria
Last updated: 14.12.2022