PRIVACY POLICY FOR UNBOXIE.AI
Unboxie.ai ("we," "our," or "us") respects your privacy and is committed to protecting the personal data of our users, including customers, vendors, and visitors to our platform. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information.
By using our platform, you agree to the terms of this Privacy Policy. If you do not agree, please do not use our services.
1. INFORMATION WE COLLECT
We collect the following categories of information:
1.1. Personal Data Provided by You
- Name, email address, phone number, and shipping/billing addresses.
- Payment details (e.g., credit card numbers) processed through third-party payment providers.
- Business information for vendors, including business registration numbers and tax identification.
1.2. Data Collected Automatically
- IP address, browser type, device information, and operating system.
- Usage data, such as the pages you visit, time spent on our platform, and interactions with our services.
- Location data (if enabled on your device).
1.3. Third-Party Sources
- Social media platforms when you interact with our profiles.
- Third-party integrations, such as payment gateways or analytics providers.
2. HOW WE USE YOUR INFORMATION/ DATA
We use your information to:
- Facilitate the use of our services, including order processing, delivery, and returns.
- Personalize your experience, such as recommending products or services.
- Improve our platform, diagnose technical issues, and enhance security.
- Comply with legal obligations and enforce our terms and conditions.
- Communicate with you regarding promotions, updates, or customer service inquiries.
- Personalize the experience.
- To train personalized recommendation models to enhance the user’s experience on the platform.
- Detect, investigate, and prevent fraudulent transactions or security breaches.
- Monitor accounts for suspicious activities and unauthorized access attempts.
- Fulfill tax, legal, and regulatory obligations, including KYC (Know Your Customer) checks.
- Assist law enforcement or respond to valid legal requests (e.g., subpoenas, court orders).
- Administer customer loyalty programs, discounts, and incentives.
- Track user participation in referral or promotional campaigns.
- Conduct surveys, feedback collection, and consumer behavior analysis.
- Improve business decisions based on aggregated usage patterns.
- Show relevant ads on UNBOXIE and partner platforms based on user interests.
- Share limited data with third-party ad partners (with user consent).
- Optimize AI-powered gift recommendations based on user preferences.
- Enhance chatbot interactions and automated support services.
- In case of mergers, acquisitions, or partnerships, share user data with potential investors or business partners under confidentiality agreements.
- Review and moderate user-generated content (e.g., product reviews) to maintain quality.
- Prevent abuse, offensive content, or policy violations.
- Send reminders about abandoned carts, order status, and product restocks.
- Notify users about policy updates, platform changes, or security alerts.
- Identify technical issues, bugs, and optimize system performance.
- Analyze how users interact with the platform to enhance usability.
3. Legal Basis for Data Processing
For users in the EU/EEA, we process your personal data under the following legal bases:
- Consent: When you opt-in for marketing communications.
- Contractual Necessity: To fulfill orders and provide requested services.
- Legal Obligation: To comply with applicable laws, such as tax or anti-fraud regulations.
- Legitimate Interests: For analytics, platform improvement, and customer support.
4. HOW WE SHARE YOUR INFORMATION
We do not sell your personal data. However, we may share information with:
- Service Providers: Third-party vendors who assist with payment processing, data analysis, marketing, and logistics.
- Legal and Regulatory Authorities: To comply with applicable laws or respond to lawful requests.
- Business Transfers: In case of mergers, acquisitions, or asset sales, your data may be transferred to the new entity.
- Other Users: Vendors may receive shipping details to fulfill orders placed by customers.
5. YOUR PRIVACY RIGHTS
5.1. For Nigerian Residents (NDPR Rights):
Under the Nigeria Data Protection Regulation (NDPR), you have the following rights:
- Access: To request a copy of the personal data we hold about you.
- Correction: To request corrections to inaccurate or incomplete data.
- Deletion: To request the deletion of your personal data, subject to legal and contractual obligations.
- Consent Withdrawal: To withdraw consent where processing is based on your prior consent.
- Objection: To object to processing for purposes such as marketing or profiling.
- Data Portability: To request that we transfer your data to you or another controller in a structured, commonly used, and machine-readable format.
5.2. For EU/EEA Residents (GDPR Rights):
You have the right to:
- Access: Access, correct, or delete your personal data.
- Restriction: Restrict or object to data processing.
- Data Portability: Data portability (transfer your data to another service).
- Withdraw Consent: Withdraw consent at any time for specific processing activities.
- Complaint: File a complaint with a data protection authority in your region.
5.3. For California Residents (CCPA Rights):
You have the right to:
- Know what personal data we collect and how we use it.
- Request deletion of your data (with certain exceptions).
- Opt out of the sale of personal information (if applicable).
6. DATA SECURITY
We implement appropriate technical and organizational measures to safeguard your data against unauthorized access, alteration, or destruction. These include:
- Encryption of sensitive data.
- Regular security audits and vulnerability testing.
- Access controls for staff and third-party partners.
7. DATA RETENTION
We retain personal data only as long as necessary for the purposes outlined in this policy or as required by law. For example:
- Customer order information is retained for tax and legal compliance.
- Vendor data is retained during the active partnership and for a reasonable period after.
8. COOKIES AND TRACKING TECHNOLOGIES
We use cookies to:
- Enhance your browsing experience.
- Analyze site performance and usage.
- Deliver personalized content and advertisements.
You can manage cookie preferences through your browser settings or opt-out of tracking.
9. INTERNATIONAL DATA TRANSFERS
If you access our services outside of Nigeria or the EU, your data may be transferred to and processed in other countries. We ensure adequate safeguards, such as Standard Contractual Clauses, for data transfers to regions without equivalent privacy protections.
10. CHILDREN'S PRIVACY
Our platform is not intended for use by children or minors as defined under the applicable laws of their country, state, or region. We do not knowingly collect personal data from individuals under the minimum age of consent for data processing in their jurisdiction.
Examples of age definitions:
In Nigeria, the Child Rights Act defines a child as a person under the age of 18.
In the United States, laws like the Children's Online Privacy Protection Act (COPPA) apply to individuals under the age of 13.
In the European Union, the GDPR sets the age of consent for data processing at 16, though member states may set it lower (no less than 13).
If we discover that personal data has been collected from a minor without appropriate consent, we will promptly delete it. Parents or guardians may contact us to request the removal of such data.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Significant changes will be communicated to you via email or a notice on our platform.
12. DATA BREACH NOTIFICATION AND RESOLUTION
While we implement strict security measures to safeguard your personal data, no system is completely immune to breaches. In the unlikely event of a data breach, we are committed to addressing it swiftly and responsibly.
Definition of a Breach:
A data breach refers to any unauthorized access, disclosure, alteration, or destruction of personal data. This includes, but is not limited to:
- Cyber-attacks, such as hacking or malware.
- Unauthorized access by employees or third parties.
- Accidental loss or exposure of personal data.
In the event of a breach, we will:
- Investigate
- Contain
- Notify Authorities
- Notify Affected Individuals
Legal Implications of Breaches:
Vendor Responsibility: Vendors are required to report any data breach to us immediately upon discovery. Failure to do so may result in penalties or termination of their agreement with us.
Liability: UNBOXIE shall not be liable for damages resulting from breaches caused by third-party service providers or vendors, provided that we have exercised due diligence in their selection.
After resolving the breach, we will conduct a post-incident review to identify vulnerabilities and enhance security measures to prevent future incidents.
13. CONTACT US
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at support@unboxie.ai.