Privacy Policy

This “Privacy Notice” describes the practices of the Plugg & Co. and its subsidiaries and affiliates (collectively, “Plugg & Co.”, “we”, “us”, or “our”) and the rights and choices available to individuals, regarding personal data. Personal data means any information that relates to an identifiable individual.
Plugg & Co. may provide separate privacy notices that apply to specific products or services that we offer, in which case this Privacy Notice does not apply. Where this Privacy Notice applies, Plugg & Co. may provide additional or supplemental privacy notices to individuals at the time we collect their data, which will govern how we may process the information provided at that time. We may alter this Privacy Statement as needed for certain products and services and to abide by local laws or regulations around the world, such as by providing supplemental information in certain countries. This Privacy Notice does not apply to Plugg & Co.’s processing of the personal data of its personnel, such as employees and contractors.

1. The personal data we collect

We collect personal data about individuals from various sources described below. Where applicable, we indicate whether and why individuals must provide us with personal data, as well as the consequences of failing to do so. Information that we collect directly from individuals and the parties with which we do business We may collect personal data directly from individuals and the parties with which we do business, including prospects. These may include parties that interact with us directly (such as individuals who download our mobile applications or job applicants), parties to which we provide goods or services (such as clients, merchants, and individuals) (collectively, “clients”), parties that provide services to us (such as vendors, banks or financial institutions) (collectively, “service providers”), and other parties with whom we offer or provide products and services (such as independent sales organizations) (collectively, “partners”). We may collect information from these parties in a variety of contexts, such as when completing one of our online forms, making an application for one of our products or services, interacting with us on social media, or corresponding with us. The types of information we obtain in these contexts include:

Information that we collect about individuals who do not interact with us directly

We may receive personal data about individuals who do not interact with us directly. For example, our clients, service providers, and partners may provide us with information about individuals other than themselves when using our products or services. In addition, due to the unique nature of Plugg & Co.'s business, in many cases, Plugg & Co. obtains personal data from other participants in a transaction processing chain, such as card associations and debit network operators and their members. The types of information we receive about third parties includes:

Information we collect from private and publicly accessible sources

We and our service providers may collect information about individuals that is publicly available, including by searching publicly accessible government lists of restricted or sanctioned persons (such as the Specially Designated Nationals And Blocked Persons List), public records databases (such as company registries and regulatory filings), and by searching media and the internet. We and or our third party verification providers may also collect information from private or commercially available sources, such as by requesting reports or information from credit reference and fraud prevention agencies, to the extent permitted under applicable law.
We may also maintain pages for our company and our products and services on a variety of third-party platforms, such as LinkedIn, Facebook, Twitter, YouTube, Instagram, and other social networking services. When you interact with our pages on those third-party platforms, the third-party’s privacy policy will govern your interactions on the relevant platform. If the third-party platform provides us with information about our pages on those platforms or your interactions with them, we will treat that information in accordance with this Privacy Notice.

Information collected via automated means

When you access our websites or use our mobile applications, we, our service providers, and our partners may automatically collect information about you, your computer or mobile device, and activity on our websites or mobile applications. Typically, this information includes your computer or mobile device operating system type and version number, manufacturer and model, device identifier, browser type, screen resolution, IP address, the website you visited before browsing to our website, general location information such as city, state or geographic area; and information about your use of and actions on or in our websites or mobile applications, such as pages or screens you accessed, how long you spent on a page or screen, navigation paths between pages or screens, information about your activity on a page or screen, access times, and length of access. Certain products or services that we provide or which merchants may incorporate into their websites or mobile applications may automatically collect additional information, as may be further described in a separate privacy notice.
Our service providers and business partners may collect this type of information over time and across third-party websites. This information is collected via various mechanisms, such as via cookies, web beacons, embedded scripts, through our mobile applications, and similar technologies. This type of information may also be collected when you read our HTML-enabled emails. You can choose to disable cookies or to opt out of the use of your browsing behaviour for purposes of targeted advertising.

Sensitive personal data

In limited circumstances and when permitted by law, we may collect information that may reveal health or medical information, such as when we process transactions at health or medical facilities or pharmacies. In the context of processing employment applications, we may also request sensitive information, such as racial or ethnic origin or information about disability, where required or permitted by law of the country in which you are applying for employment.
Outside of these contexts or otherwise as we specifically request, we ask that you not provide us with any sensitive personal data (meaning information revealing racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, genetic, health, or biometric information, information about sex life or sexual orientation, or criminal convictions or offenses) through our websites or mobile applications, or otherwise to us.

2. How we use your personal data

We use your personal data for the purposes of:

Providing our products and services, which includes:

For research and development

We use the information we collect for our own research and development purposes, which include:

Marketing

We may use your personal data to form a view on what products or services we think you may want or need, or what may be of interest to you.
We may contact you with marketing communications using the personal data you have provided to us if you have actively expressed your interest in making a purchase or have made a purchase from us and, in any case, you have not opted out of receiving that marketing, to the extent permitted by applicable law.
Where required by law, we will get your express opt-in consent before we share your personal data with any company outside Plugg & Co. for marketing purposes.
You can ask us to stop sending you marketing messages at any time by contacting us using the details at Contact Us section or clicking on the opt-out link included in each marketing message.
Should you choose to opt out of receiving our marketing messages, we will continue to carry out our other relevant activities using your personal data, including sending non-marketing messages.

Managing our recruiting and processing employment applications

We process personal data, such as information submitted to us in a job application, to facilitate our recruitment activities and process employment applications, such as by evaluating a job candidate for an employment activity, and monitoring recruitment statistics.

Complying with law

We use your personal data as we believe necessary or appropriate to comply with applicable laws, lawful requests and legal process, such as to respond to subpoenas or requests from government authorities.

Compliance, fraud prevention and safety

We use your personal data as we believe necessary or appropriate to (a) enforce the terms and conditions that govern our products and services; (b) protect our rights, privacy, safety or property, and/or that of you or others; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

With your consent

In some jurisdictions, applicable law may require us to request your consent to use your personal data in certain contexts, such as when we use certain cookies or similar technologies or would like to send you certain marketing messages. If we request your consent to use your personal data, you have the right to withdraw your consent any time in the manner indicated when we requested the consent or by contacting us. If you have consented to receive marketing communications from our third party partners, you may withdraw your consent by contacting those partners directly.

To create anonymous data

We may create anonymous data from your personal data and other individuals whose personal data we collect. We make personal data into anonymous data by excluding information that makes the data personally identifiable to you, and use that anonymous data for our lawful business purposes.

3. How we share your personal data

Subsidiaries

We may disclose your personal data to our subsidiaries and corporate affiliates for purposes consistent with this Privacy Notice.

Service providers

We may employ third party companies and individuals to administer and provide services on our behalf (such as companies that provide customer support, companies that we engage to host, manage, maintain, and develop our website, mobile applications, and IT systems, and companies that help us process payments). These third parties may use your information only as directed by Plugg & Co. and in a manner consistent with this Privacy Notice, and are prohibited from using or disclosing your information for any other purpose. When Plugg & Co. performs services with service providers for its clients, it may share personal data with those entities. For example, Plugg & Co. may collect information about a client’s customers from or on behalf of the service provider, such as when Plugg & Co. processes payment transactions, and Plugg & Co. may provide personal data about those customers back to the service provider. We are not responsible for the privacy practices of our service providers.

Our clients

When Plugg & Co. performs services for its clients, it may share personal data with those entities. For example, Plugg & Co. may collect information about a client’s customers from or on behalf of the client, such as when Plugg & Co. processes payment transactions, and Plugg & Co. may provide personal data about those customers back to the client. We are not responsible for the privacy practices of our clients.

Participants in the transaction processing chain

Plugg & Co. shares personal data with companies in the transaction processing chain in connection with processing a payment transaction, such as merchants, banks or other card issuers, card associations, debit network operators and their members.

Credit reference, fraud protection, risk management, and identity and verification agencies

Plugg & Co. shares personal data with credit reference, fraud protection, risk management, and identity verification agencies to help guard against, detect, and respond to fraud or money laundering, and/or manage our or our service providers’ risk, and ensure we comply with contractual, legal, or regulatory requirements.

Automated Decisions, Credit Reference Agencies and Fraud Prevention Agencies

We sometimes make automated decisions based on your personal data (whether provided by you or collected by us from third parties such as credit reference and fraud prevention agencies). We will only do this where it is required in connection with a contract, authorized by law, or based on your explicit consent. You can contact us for more information on automated decision making.

Professional advisors

We may disclose your personal data to professional advisors, such as lawyers, bankers, auditors and insurers, where necessary in the course of the professional services that they render to us.

Compliance with Laws and Law Enforcement; Protection and Safety

Plugg & Co. may disclose information about you to government or law enforcement officials (including tax authorities) or private parties as required by law, and disclose and use such information as we believe necessary or appropriate to (a) comply with applicable laws and lawful requests and legal process, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern our products and services; (c) protect our rights, privacy, safety or property, and/or that of you or others; and (d) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

Business Transfers

Plugg & Co. may sell or transfer some or all of its business or assets, including your personal data, in connection with a business transaction (or potential business transaction) such as a merger, consolidation, acquisition, reorganization or sale of assets or in the event of bankruptcy, in which case we will make reasonable efforts to require the recipient to honor this Privacy Notice.

To Other Parties with Your Permission or to Fulfill a Contract They Have With You

Plugg & Co. may transfer your personal data to any third party who is not otherwise covered by the other listed categories above where you have given us permission to do so, or with whom you have entered into a contract when we need to transfer your personal data to that party in order to fulfil that contract.

How long will you use my personal data?

We will use your personal data for as long as necessary based on why we collected it and what we use it for. This may include our need to satisfy a legal, regulatory, accounting, or reporting requirement.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In general terms, we will retain your personal data for the duration of your involvement/engagement with us and for as long as reasonably necessary afterwards; however, we may maintain different retention periods for different products and services. There are also certain types of information which are required to be retained for a certain period by law.

4. Your Rights and Choices

Marketing communications

You can ask us to stop sending you marketing messages at any time by contacting us or clicking on the opt-out link included in each marketing message. You may continue to receive service-related and other non-marketing messages.

Targeted online advertising

Some of the business partners that collect information about users’ activities on our websites or in our mobile applications, may be members of organizations or programs that provide choices to individuals regarding the use of their browsing behavior or mobile application usage for purposes of targeted advertising.
Please note that we also may work with companies that offer their own opt-out.

Choosing not to provide your personal data

Where we request personal data directly from you, you do not have to provide it to us. If you decide not to provide the requested information, in some circumstances we, or our service providers, may be unable to provide products or services to you. For example, we may be unable to process your transaction.

Accessing, modifying or deleting your information

In some jurisdictions, applicable law may provide a right for individuals to access, modify, or delete their personal data in some. You may contact us directly to request access to, or modify or delete your information. We may not be able to provide access to, modify, or delete your information in all circumstances.

Complaints

If you have a complaint about our handling of your personal data, you may contact our privacy officer using our contact information. We request that a complaint be made in writing. Please provide details about your concern or complaint so that our privacy officer can investigate it. We will take appropriate action in response to your complaint, which may include conducting internal discussions with relevant business representatives. We may contact you for additional details or clarification about your concern or complaint. We will contact you to inform you of our response to your complaint. You also may have a right to file a complaint with a national or local regulatory agency.

5. International Transfers

Plugg & Co. is headquartered in Canada, and it maintains offices and has service providers in other countries. Your personal data may be transferred to Canada or other locations outside of your province, country or other governmental jurisdiction where we or our service providers maintain offices and where privacy laws may not be as protective as those in your jurisdiction. If we make such a transfer, we will require that the recipients of your personal data provide data security and protection in accordance with applicable law.

6. How we keep your data safe

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We maintain annual compliance with global Payment Card Industry Data Security Standard (PCI DSS) adopted by the payment card brands for all companies that process, store or transmit cardholder data.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

7. This Website May Link to Other Websites

We may also link to third-party websites, mobile applications, and other content. Plugg & Co. is not responsible for the privacy practices of any third party, and this privacy notice does not apply to such third party’s websites, mobile applications, or other content. Plugg & Co. does not guarantee, approve, or endorse any information, material, services, or products contained on or available through any linked third-party website, mobile application or other content. Plugg & Co. is not responsible for any content on third-party properties to which we link. Plugg & Co. provides links to third-party properties or content as a convenience, and visiting or using linked third-party properties or content is at your own risk.

8. Changes to this Privacy Notice

We reserve the right to modify this Privacy Notice at any time. We encourage you to periodically review this page for the latest information on our privacy practices. If we make material changes to this Privacy Notice, we will notify you by updating the date of this Privacy Notice and posting it on our website and in app stores where our mobile applications covered by this Privacy Notice are available for download. We may (and, where required by law, will) also provide notification of changes in another way that we believe is reasonably likely to reach you, such as via e-mail (if you have an account where we have your contact information) or another manner through our website or mobile applications.

Any modifications to this Privacy Notice will be effective upon our posting of the new terms and/or upon implementation of the new changes (or as otherwise indicated at the time of posting). In all cases, your continued use of our products or services after the posting of any modified Privacy Notice indicates your acceptance of the terms of the modified Privacy Notice.

9. Contact Us

If you have any questions, concerns, or complaints about this Privacy Notice or our privacy practices, or to request access to your personal data, you may contact our Privacy Officer at privacy@pluggco.com.