PRIVACY POLICY

Last Updated: February 9, 2023

Welcome to Super!

Super is a platform that makes it easy to support the philanthropic causes you care about. The Super website, mobile application, and any related content and services (the “Services”) are provided by Super Give Co. (“Super”). We respect your privacy and have designed the Services with your privacy in mind. This Privacy Policy describes how we collect, use, and disclose personal information and what choices you have with respect to the information.

Wherever used in this Privacy Policy, “you,” “your,” or similar terms means the person or legal entity using the Services. If you are using the Services on behalf of a company (such as your employer) or other legal entity, you represent and warrant that you have the authority to bind that company or other legal entity to this Privacy Policy.

Wherever used in this Privacy Policy, “Super,” “we,” “us,” or “our” means Super Give Co.

We may update or amend this Privacy Policy in our sole discretion. If we do so, we will notify you of any changes that, in our sole discretion, materially impact this Privacy Policy. Continued use of the Services after any such changes to the Privacy Policy have been made shall constitute your consent to such changes. You are responsible for regularly reviewing the most current version of the Privacy Policy, which is available at https://heysuper.com/privacy. When we change this Privacy Policy, we will modify the “Last Updated” date above.

INFORMATION WE COLLECT

We may collect both personal information and anonymous information when you access and use the Services. Personal information means information that directly or indirectly identifies you, such as your name, email address, telephone number, or social media profile. Anonymous information means information that does not directly or indirectly identify you, such as your browser type, type of mobile device (if applicable), IP address, operating system, and internet service provider.

To access many of the Services, we require that you register for an account on our website and provide us with certain personal information, such as your full name, a valid email address, and a password.

In order to donate to charity funds via the Super platform, you will need to provide certain financial information, such as credit card or bank account information. We store this information securely to enable recurring donations.

We may collect information about how you use the Services, such as the features you use, the actions you take, and the time and duration of your activities.

We may also collect information about you through your use of our Services. When you access and use the Services, our web server automatically collects anonymous information about your computer and/or browser, including the following: your browser type, IP address, operating system, internet service provider’s name, and the referring URL.

HOW WE USE INFORMATION

We use information that we collect to help us operate, improve, support, and market the Services. Specifically, we may use such information:

Information that is aggregated or de-identified so that it is no longer reasonably associated with an identifiable natural person may be used for any legitimate business purpose.

HOW LONG WE KEEP YOUR PERSONAL INFORMATION

We keep your information for no longer than is necessary. We will retain your information for any period required by law. When we are not under a legal obligation to retain your information, we will determine how long is necessary based on our legitimate business interests. If you have any questions about how long we keep your information, please contact us.

SHARING INFORMATION WITH THIRD PARTIES

We contract with certain third-party service providers in order to operate and provide features through the Services. Those service providers may need access to your information, including personal information, to perform fulfillment and other services. We undertake to provide only that portion of your information needed to perform the pertinent service, and we require that all of our service providers hold your information in confidence and use it only to provide the service for which they have been engaged.

We do not provide contact information to third-party marketers without your permission. We may share your information when legally required to do so, at the request of governmental authorities conducting an investigation or by applicable law, rule or regulation, to verify or enforce compliance with our Terms of Service and any other policies governing the Services, or to protect against misuse or unauthorized use of the Services. We also may disclose information whenever we believe disclosure is necessary to limit our legal liability, to protect or defend our rights or property, or protect the safety, rights, or property of our users or other third parties.

In the event of a merger, consolidation, or other corporate reorganization in which we participate or a sale of all or substantially all of our stock and/or assets to which the Services relate, we may transfer your personal information to the successor entity or purchaser.

LINKS TO THIRD-PARTY CONTENT

We may provide links to websites, software, or services owned or operated by third parties (“Third-Party Content”). We are providing these links to you as a convenience, and Super does not verify, make any representations, or take any responsibility for such Third-Party Content, including, without limitation, the truthfulness, accuracy, quality, or completeness of the content, products, services, or information provided therein. The Third-Party Content may be subject to different privacy policies and business practices than the Services. Your dealings and communications through the Services with any party other than Super are solely between you and such third party.

We encourage you to be aware when you leave the Super website or mobile application to read the privacy policy of each and every third-party website that collects personally identifiable information. This Privacy Policy applies solely to information collected by us.

INTERNATIONAL TRANSMISSION OF INFORMATION

The internet is a global environment. Your information may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where the privacy laws may not be as protective as those in your jurisdiction. By using the Services and/or communicating electronically with us, you acknowledge and agree to our processing of your information in this manner, and agree to be bound by all privacy laws that apply to you and us.

UNSUBSCRIBING FROM COMMUNICATIONS AND YOUR RIGHT TO BE FORGOTTEN

When you supply us with personal information in the course of registering an account, the information you provide may be added to our user database and email list.

We may send you an email with information on new products, services, and offers. If you do not wish to receive such email in the future, please contact us at legal@heysuper.com with the subject header “unsubscribe” to remove yourself from our email list.

We may send you periodic notices or announcements relating to the Services and/or your account. We reserve the right to send you such notices even if you unsubscribe from all voluntary email communications. If you do not wish to receive any communications from us at all, then you will need to delete your account entirely. To do so, go to the “My Account” page on the website and click the “Delete Account” button at the bottom of the page. Alternatively, you can email legal@heysuper.com with the subject header “delete account”. Upon your request we will delete your account as soon as reasonably possible.

SECURITY

We use a variety of physical, electronic, and procedural safeguards to protect your personal information. However, no method of electronic storage or method of transmission over the internet or phone lines is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee the protection of any information against unauthorized access, disclosure, alteration, or destruction, or that any information may not be disclosed or accessed by accidental circumstances or by the unauthorized acts of others. Consequently, when you transmit your personal information to us, you do so at your own risk.

If you create an account with Super, your account information may be password-protected. It is important for you to protect against unauthorized access to your username and password, as well as to your smartphone or other mobile device. We request that you not communicate any confidential or sensitive information to us through email, social media, or any other means.

If we learn of a security systems breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to your personal information, we shall notify you electronically so that you can take appropriate protective steps. We will endeavor to provide notice to you of any such security systems breach and efforts to restore the integrity of the Services in accordance with applicable law. By using the Services or providing personal information to us, you agree that we can communicate with you electronically regarding security and privacy issues related to the Services.

The security of personal information also depends in part on the security of the smartphone or device you use to communicate with us, the security you use to protect usernames and passwords, and the security provided by your internet service provider or mobile carrier. We are not responsible for the security of your internet service provider or mobile carrier.

CHILDREN’S PRIVACY

The Services are not intended or designed to attract children under the age of 13. We do not collect personally identifiable information from any person we actually know is a child under the age of 13. If we learn that a child under the age of 13 has provided personal information, we will comply with the Children’s Online Privacy and Protection Act (“COPPA”) to delete the information or obtain verifiable parental consent in accordance with COPPA.

YOUR RIGHTS UNDER THE GENERAL DATA PROTECTION REGULATION

If you are a user living in the European Economic Area, your privacy rights are covered by our General Data Protection Regulation (GDPR) Privacy Policy. Please see our GDPR Privacy Policy for your rights as a user in the European Economic Area. Our GDPR Privacy Policy supplements this Privacy Policy.

GOVERNING LAW

This Privacy Policy is governed by the laws of the State of New York, without giving effect to any choice of law provision or rule. Any dispute arising in connection with this Privacy Policy must be filed in the state or federal courts located in New York.

QUESTIONS OR CONCERNS

For questions or concerns about this Privacy Policy, please email us at legal@heysuper.com.

GDPR PRIVACY POLICY FOR USERS IN THE EUROPEAN ECONOMIC AREA

Last Updated: February 9, 2023

This GDPR Privacy Policy for Users from the European Economic Area supplements Super’s existing Privacy Policy.

All capitalized terms shall be understood as defined in our Terms of Service.

Since Super is an American company, all data collected from users is processed within the United States. 

Super respects personal data of users within the European Economic Area and commits to adhering to all regulations of the generally applicable law of the European Union, in particular, with regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or GDPR).

Super ensures that its employees are trained in how to protect the personal data of its users.

WHO HAS ACCESS TO USERS’ PERSONAL DATA?

The controller of users’ personal data is:

Super
568 Union Ave. Apt 6N
Brooklyn, NY 11211
legal@heysuper.com

WHY DOES SUPER PROCESS PERSONAL DATA?

Super collects personal data from our users to provide the services outlined in the Terms of Service.

WHAT RIGHTS DO USERS HAVE OVER THE COLLECTION, STORAGE AND USE OF THEIR PERSONAL DATA?

A user has the right to request from Super access to their personal data and to obtain information about the purposes of its processing, categories of data processed, recipients of data, and storage period of said data.

A user also has the right to update incorrect personal data and to provide missing personal data if they deem their personal data is incomplete.

A user has the right to request that their personal data be deleted if:

  1. Their personal data is no longer required by Super to fulfill the Terms of Service
  2. They have withdrawn their consent for Super to collect and use their personal data
  3. They object to their personal data being used for marketing purposes
  4. They object to the processing of their personal data by Super, or any third party, on any grounds unless there are valid, legally justified grounds for processing of the user's personal data that override the interests, rights and freedoms of the user, or there are grounds for establishing, investigating or defending such claims.

A user has the right to request that the use of their personal data be restricted if:

  1. They contest the accuracy of the personal data; in this case, the use of personal data will be restricted for a period of time suitable for Super to verify the accuracy of the personal data
  2. They feel that the use of their personal data is unlawful and would prefer that the use of it be restricted rather than requesting that their data deleted
  3. Super no longer needs the user’s personal data, but the user still needs pieces of personal data to be retained by Super for the purpose of legal claims
  4. They are in disagreement with Super as to the legitimate grounds for the use of their personal data; in this case, the user can request that the use of their data be restricted until this is resolved.

If a user requests that the use of their personal data be restricted, Super will refrain from using their personal data without their consent except to:

  1. store or process personal data in order to establish, exercise, or defend claims
  2. protect the rights of another natural or legal person
  3. honor important reasons of public interest of the European Union or one of its member states.

The user will be informed about this before the restriction of processing is lifted.

A user has the right to object in case of processing of the personal data for the purposes of direct marketing, including profiling, to the extent that it is related to such direct marketing. After submitting the objection, Super will refrain from processing the personal data of the user for direct marketing purposes (including profiling). The user has the right to submit objections by automated means using technical specifications. 

A user has the right to request a copy of their personal data collected by Super. The data must be given to the user in a structured, commonly-used and machine-readable format. A user also has the right to transfer their personal data to another service without interference from Super if:

  1. processing takes place on the basis of the user’s consent or a contract, which performance needs processing of data; and
  2. the processing is carried out by automated means.

A user has the right to withdraw their consent to the processing of personal data at any time, but the withdrawal does not retroactively apply to the consented-to use of their personal data before the withdrawal.

A user has the right to lodge a complaint with a supervisory authority about Super’s use of their personal data. 

What personal data does Super collect?

In order for a user to create and maintain an account with Super, the following data are collected:

When contacting a user, Super will only collect the personal data that the user provides to us for such purpose.

Super may collect a user’s email address, with the user’s consent, for the following purposes:

In order for a user to make donations and pledges to charitable funds, Super may collect the user’s credit card information (including billing address) and/or bank account information, in each case with the user’s consent. Alternatively, users may make donations and pledges via Super by linking their Apple Pay or Google Pay accounts.

HOW LONG IS PERSONAL DATA STORED?

Super stores a user’s personal data from the moment when the user registers their account or when the user starts using the Services. After a user sends an email requesting to delete their account, Super will permanently remove all of the user’s data from its servers within 30 days.

Generally, Super stores personal data for as long as is necessary to provide the Services, and for a reasonable retention period in accordance with applicable law and industry standards. Our usual storage period is seven (7) years, unless dictated otherwise by legal requirements and/or our internal policies.

WHO DOES SUPER TRANSFER PERSONAL DATA TO?

Super transfers personal data of its users to the following companies, for the purposes outlined below:

Third Party

Purpose

Category of Personal Data

Stripe https://stripe.com/

We use Stripe to process payments on behalf of individuals using our platform to collect donations, processing fees, and tips.

First and last name, email address, mailing address, credit card information.

Plaid https://plaid.com/

We use Plaid to provide a simple experience for connecting an individual’s bank account to a payment method.

First and last name, email address, bank account information.

As far as Super is aware, all of the servers that belong to the companies outlined above, to which a user’s personal data are transferred by Super, are located in the United States of America.

COOKIES

The Super website uses cookies. We use cookies to personalize content and to provide features.

Cookies are small text files that can be used by websites to make a user’s experience more efficient. The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we will obtain your permission. This site uses different types of cookies. Some cookies are placed by third-party services that appear on our pages.

Your consent applies to the following:

FUNCTIONALITY

The cookies outlined here are required for the Super website to function normally.

Domain

Type

Duration

_super_key

.heysuper.com

First party

session

user_remember_me

.heysuper.com

First party

60 days

AWSALBCORS

.heysuper.com

First party

7 days

AWSALB

.heysuper.com

First party

7 days

__stripe_mid

.heysuper.com

First party

1 year

THIRD-PARTY PROVIDERS

We work with third-party providers to provide additional functionality like collecting payment information and authentication. These providers may set their own cookies. While this list may not be exhaustive, it will be updated periodically to reflect new information from these providers. Please use the below resources to review these providers’ respective cookie policies.

Google Pay: https://policies.google.com/technologies/cookies

Stripe: https://stripe.com/legal/cookies-policy

Plaid: https://plaid.com/legal/#cookie-policy