Data Privacy Policy

Last Updated: July 26, 2018

AnyPerk, Inc. d/b/a Fond respects your privacy and is committed to transparent privacy practices, in compliance with the European Union’s General Data Protection Regulation (“GDPR”) as applicable.

This “Privacy Policy” explains how AnyPerk, Inc. d/b/a Fond (collectively “Fond,” “we,” “us,” or “our”) collects, uses, processes, and shares your personal information in connection with your use of www.fond.co (the “Site”), our mobile applications, and our web-based services, and explains your choices for how we handle your personal information. For convenience, the Site and our services are collectively referred to as the “Service” or the “Services.” This Privacy Policy applies only to personal information of users of the Service. Please read this policy carefully. This policy is incorporated into and is subject to our Terms of Service.

As used in this Privacy Policy, “personal information” or “personal data” means information that relates to an identified individual or to an identifiable individual. For example, this could include, among other things, your name, address, email address, business contact details, or information gathered through your interactions with us via our websites or at events. Personal information is also referred to as “information about you”. For more detail about the types of information about you that we may process, please review the following sections. Personal information may be collected, used, processed, and/or shared both offline and online. Information may, in some cases directly identify you, while in other cases it may only indirectly identify you.

European Union residents should be sure to read the important information provided here.


Fond’s Service and Client User Data

Customers of our Service (each, a “Client” and collectively, “Clients”) use the Service to: (a) engage Client employees through a series of capabilities, including perks (employee discounts), recognition (company, manager and/or peer-to-peer recognition), to purchase experiences, gift cards, physical goods; and (b) periodically survey Client employees to gauge their job satisfaction.

Client user data (“Client User Data”) means and includes, without limitation, information about the identity of Client users (Client employees, such employees’ family members, and other users of the Site on Client’s behalf or under Client’s subscription) such as name, e-mail address and shipping address, as well as information about the pages that users visit, the features they use, and the actions they take while using the Services.

Our Clients have their own policies regarding the collection, use and disclosure of your personal information. To learn about how a particular Client handles your personal information, we encourage you to read the Client’s privacy statement. Our use of Client User Data provided by our Clients in connection with our Services is subject to the written agreement between Fond and Client. This Privacy Policy also does not apply to websites, applications or services operated by other parties or that display or link to different privacy statements.

Personal Information We Collect

Information You Provide Us

We collect the following information from our Clients, their employees and employee family members who sign up for our Services:

Registration and Profile Information: We collect information about you when you create an account for our Services, which may include your name, title, company name, address, phone number, email address, birthdate, hire date, user identification, and password. If you are an employee of one of our Clients, we may also receive your name and email address from your employer. Other employees may also provide us your information when they invite you to try our Services.

Payment Information: We may ask you to provide payment card and/or financial account information when you pay for our Services, including the benefits commonly referred to as “Rewards” or “Perks,” or when you add payment card information to your Services account. Payment information is collected and processed by our Payment Card Industry (PCI) service provider Stripe (www.stripe.com), and not by Fond. Please review their Privacy Policy.

Feedback and Information: We collect information you provide in response to surveys, and any ‘likes’ and comments you make in the Services. Providing this information is optional. All survey feedback is anonymized.

Request a Perk: If you choose to request a Perk that is not then currently available via the Services, we collect your email address, company name and city to improve our ability to access a relevant Perk and to notify you when the Perk is available. Requesting a Perk is optional.

Communications: We receive information from you when you contact us or we communicate with you, including via email or social networks. All such communication is optional.

Information We Collect from Your Use of Our Services

Perks and Rewards Information: We collect information regarding which Perks you claim and which Rewards you give or receive. We also collect any additional information provided when you give or receive a Reward, including a description as to why you are receiving the Reward and how you use the Rewards you receive. We also collect any feedback and ratings you provide about Perks or our Services. We may also collect analytics information regarding Perks redeemed from our third-party vendors (“Vendors”).

Location: We collect location information if you provide it to us or based on, for example, your device’s GPS coordinates, unless you configure your operating system settings to prevent this collection.

Device and Usage Information: We record certain information and store it in log files when you interact with our Services. This information may include device and browser information, internet protocol (IP) address, the web pages or sites that you visit just before or just after you use our Services, the pages or other content you view or interact with on our Services, the information you search for, and the dates and times that you visit our Services.

Cookies and Other Technologies: We may use various technologies to collect information, including cookies, that we save to your device. Cookies are small data files stored on your hard drive or in device memory. We use cookies for purposes such as improving our Services and your experience and allowing you to access and use our Services without re-entering your username or password. You can instruct your browser by changing its options to stop accepting cookies or to prompt you before accepting a cookie from websites you visit. If you do not accept cookies, you may not be able to use all aspects of our Services.

Information We Get from Others

We may obtain additional information about you from third-party sources, such as your company’s Human Resources Information System (HRIS) to enrich your experience on the Service and provide you with more relevant information related to our service offerings.

Sensitive Personal Information

Subject to the following paragraph, we ask that you not send or disclose to us any sensitive personal information (e.g., social security numbers or other government-issued IDs, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal backgroundor union membership) on or through the Service or otherwise.

If you send or disclose any sensitive personal information to us (such as when you submit user generated content to the Site), you must consent to our processing and use of such sensitive personal information in accordance with this Privacy Policy. If you do not consent to our processing and use of such sensitive personal information, you must not provide it.

How We Use Personal Information We Collect

In order to provide the Services, we use your personal information to:

  • Provide, operate, maintain, improve, and promote our Services
  • Develop new products, services, features, and functionality
  • Notify you when you visit a website or location that has a Perk available for redemption
  • Process and complete transactions you make through the Service and send you related information, including confirmations and invoices
  • Monitor and analyze trends, usage, and activities to enhance our Services and to provide insights to you and your employer
  • Manage and communicate with you regarding your Service account, if you have one, including by sending you Service announcements, technical notices, updates, security alerts, and support and administrative messages.
  • Better understand your needs and interests, and personalize your experience with the Service
  • As required by law, such as to comply with a subpoena or other legal process, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to government requests, including public and government authorities outside your country of residence, for national security and/or law enforcement purposes.

Changes to Your Personal Information

It is important that the personal information we hold about you is accurate and current. Please let us know if your personal information changes during your relationship with us by updating your profile or emailing us at privacy@fond.co.

Correspondence

If you correspond with us via email, we may gather the information you submit in a file specific to you. This includes information submitted for support purposes.

Communications

Fond uses your data to communicate with you, including responding to your Service-related requests, questions, and feedback; providing customer service and support; providing you with information about our Services, including technical notices, updates, security alerts, administrative messages, or advertising or marketing messages; and providing other news or information about us. You can manage your email Preferences via the Account page here https://fond.co/users/edit

If you request information from us, register for the Service, or express interest in learning more about our Service, we may send you Fond-related marketing communications, if permitted by law. Such emails provide you the ability to opt out of receiving such communications.

Information Sharing and Disclosures

Fond does not share or sell the personal information that you provide us with other organizations, except as described in this Privacy Policy. We disclose personal information to third parties under the following circumstances:

Consent

Fond may use or share your personal information with companies, organizations, or individuals outside of our company when we have your consent, such as when you consent to let us post your feed comments and likes on our Site or you instruct us to take a specific action with respect to your personal information.

Your Company

Fond provides aggregate information regarding the number of Perks redeemed to your employer. We do not share the specific Perks you redeem with your employer.

Vendors

When you redeem a Perk or Reward, Fond may provide your information to our Vendors or service providers as necessary to facilitate the redemption. Our Services contain features or links to websites and services provided by our Vendors. Any information you provide on these sites or services is provided directly to the operators of such services and is subject to those operator’s policies, if any, governing privacy and security, even if accessed through our Services. We are not responsible for the content or privacy and security practices and policies of the sites or services to which links or access are provided through our Services. We encourage you to learn about third parties’ privacy and security policies before providing them with information.

Service Providers and Others

Fond may share your information with our service providers and other third parties who perform services on our behalf, such as email delivery, fulfillment, technology, analytics, and marketing services. We also provide your payment information to our service providers for payment processing and verification. Service providers such as analytics providers may collect information about your online activities over time and across different online services when you use our Services. These third parties are permitted to use your personal information only to perform these tasks in a manner consistent with this Privacy Policy and are obligated not to disclose or use it for any other purpose.

Legal Compliance, Fraud Prevention, and Safety

Fond may disclose your information (including your personal information) to government or law enforcement officials or third parties and disclose and use such information as we believe necessary or appropriate to (a) comply with applicable laws and lawful requests and legal process, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern the Service; (c) protect our rights, privacy, safety or property, and/or that of you or others; (d) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity; (e) to respond to an emergency which we believe in the good faith requires us to disclose information to assist in preventing the death or serious bodily injury of any person, or (f) to investigate and defend ourselves against any third-party claims or allegations.

Business Transfers

We may share or transfer your information (including your personal information) in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. We will notify you of such a change in ownership or transfer of assets by posting a notice on our Services. In such events, we will make reasonable efforts to require the recipient to honor this Privacy Policy.

Aggregate and Anonymous Data

We may share aggregate information that does not directly identify you with our Vendors and other third parties in order to improve the overall experience of our Services and for any other purposes as permitted by this Privacy Policy or applicable law.

We may create anonymous data from your personal information and other individuals whose personal information we collect. We make personal information into anonymous data by excluding information that makes the data personally identifiable to you and we may use that anonymous data for our lawful business purposes.

Professional Advisors

We may disclose your personal information to professional advisors, such as lawyers, bankers, auditors, and insurers where necessary in the course of the professional services that they render to us.

Your Choices

You may decline to share certain personal information with us, in which case we may not be able to provide you with some of the features and functionality of our Services.

Access, Update, Correct, or Delete Your Information

All Fond account holders may review, update, correct or delete the personal information in their registration profiles by logging into their accounts. Fond account holders may also contact us at privacy@fond.co to accomplish the foregoing, or if they have additional requests or questions.

Access to Data Controlled by Our Clients

Fond has no direct relationship with the individuals whose personal information is contained within the Client User Data processed by our Service. An individual who seeks access or who seeks to correct, amend, or delete personal information provided by our Clients should direct their request to the Client. You may also contact us at privacy@fond.co if you have additional questions or concerns.

Marketing Communications

You may opt out of marketing-related emails by clicking on a link at the bottom of each such email. You may continue to receive Service-related and other non-marketing emails.

Tracking and Targeted Advertising

We may allow service providers and other third parties to use cookies and other tracking technologies to track your browsing activity over time and across our Site and third-party websites. We may also partner with a third-party ad network to either display advertising on our Site, to manage our advertising on other sites, or to provide you targeted advertisements based upon your interests on our Site or on third-party sites. You may opt out of having your personal information used for targeted ads by clicking here (or if you are in the European Union, here), but you may still receive generic ads. Other companies’ use of their tracking technologies is subject to their own privacy policies. Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to do not track or similar signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.

In some of our communications, we use tracking means, such as a “click-through URL” linked to content on the Site. We track this data to help us measure the effectiveness of our customer communications.

Choosing Not to Share Your Personal Information

Where we need to collect your personal information by law or to be able to provide the Service to you and you do not provide that information when requested (or you later ask to delete it), we may not be able to provide you with the Service and may need to close your account. We will tell you what information you must provide to receive the Service by designating it as required in the Service or through other appropriate means.

International Transfer

Fond’s Services are hosted in the United States. If you choose to use the Services from other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that we may transfer your information outside of those regions to the United States for storage and processing. By providing your information, you consent to the collection, transfer, use, storage, and disclosure of your information in accordance with this Privacy Policy.

European Union resident users should read the important information provided here about transfer of personal information outside of the European Economic Area.

Data Security

Data security is very important to us. To help protect the privacy of data we collect through the Service, we employ measures intended to be consistent with industry standard practices for security and encryption in data transmission and storage. We process payments securely using an industry-accepted Payment Gateway (currently, Stripe), and we do not store any billing information on our own servers.

Please be aware, however, that despite our efforts, no security measures are perfect or impenetrable and no method of data transmission can be guaranteed against any interception or other type of misuse.

Other Sites and Services

The Service may contain links to other websites and services. These links are not an endorsement, authorization or representation that we are affiliated with that third-party. We do not exercise control over third-party websites or services and are not responsible for their actions. Other websites and services follow different rules regarding the use or disclosure of the personal information you submit to them. We encourage you to read the privacy policies of the other websites you visit and services you use.

Social Widgets

Our Site may include social features, such as the ‘like’ button, the ability to share comments in the feed, and widgets such as the ‘share’ button. These features may collect your personal information and track your use of the Site. These social features are either hosted directly on our Site or by a third-party. Your interactions with these features are governed by the privacy policy of the company providing such functionality.

User Generated Content

We may make available on our Site, or link to, features that allow you to share information online (e.g., on the Engagement Feed, in recognition activities, etc.). Please be aware that whenever you voluntarily disclose personal information online, that information becomes public and can be collected and used by others. We have no control over, and take no responsibility for, the use, storage or dissemination of such publicly-disclosed personal information. By posting personal information online, you may receive unsolicited messages from other parties.

Children

Fond’s Services are focused on businesses and, therefore, are not designed to be used by individuals under 13 years of age, nor are the Services directed to minors. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information. If you become aware that a child has provided us with personal information, please contact us at privacy@fond.co.

What additional rights do California residents have?

California Civil Code Section § 1798.83 permits users of our Site or Service who are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please contact us at privacy@fond.co.

Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time. If we make any changes, we will notify you by revising the "last updated" date at the top of this Privacy Policy and, in some cases, where appropriate we may provide you with additional notice (such as adding a statement to the home page or sending you an email notification). Your continued use of our Services after the revised Policy has become effective indicates that you have read, understood, and agreed to the current version of this Policy.

Any modifications to this Privacy Policy will be effective upon our posting of the new terms and/or upon implementation of the new changes on the Service (or as otherwise indicated at the time of posting). If we make any material changes in this Privacy Policy in ways that affect how we use your personal information, we will notify you by email (sent to the email address specified in your Fond account) or by means of a notice provided via the Services prior to the change becoming effective. We will also advise you of the choices you may have as a result of those changes. In all cases, your continued use of the Service after the posting of any modified Privacy Policy indicates your acceptance of the terms of the modified Privacy Policy.

Questions?

If you have any questions or concerns at all about our Privacy Policy, please feel free to email us at privacy@fond.co. Or if you are feeling old fashioned, you can mail us at:

Fond
33 New Montgomery, Suite 700
San Francisco, CA 94105 USA
Attention: Data Protection Officer

Additional Information for European Union Resident Users

Personal information

References to “personal information” in this Privacy Policy are equivalent to “personal data” governed by European data protection legislation.

Controller and Data Protection Officer

AnyPerk, Inc. d/b/a Fond is the controller of your personal information for purposes of European data protection legislation. Our Data Protection Officer can be reached at privacy@fond.co. See the Questions? section above for additional contact details.

Legal Basis for Processing

We only use your personal information as permitted by law. We are required to inform you of the legal bases of our processing of your personal information, which are described in the table below. If you have questions about the legal basis of how we process your personal information, contact us at privacy@fond.co.

Processing purpose Legal basis
To provide the Service

To ensure Service availability (backups, etc.)
Processing is necessary to perform the contract governing our provision of the Service or to take steps that you request prior to signing up for the Service.
To communicate with you after you request more information, request a demo or fill out a contact form on the Fond.co website

To communicate with you about changes in the service or scheduled maintenance

To create anonymous data for analytics

For compliance, fraud prevention and safety
These processing activities constitute our legitimate interests. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal information for our legitimate interests. We do not use your personal information for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
To comply with law Processing is necessary to comply with our legal obligations
With your consent, we will send the Perks Newsletter, Recognition Roundup and Rewards Reminder emails Processing is based on your consent. Where we rely on your consent, you have the right to withdraw it anytime in the manner indicated in the Service or by contacting us at privacy@fond.co.

Use for New Purposes

We may use your personal information for reasons not described in this Privacy Policy where permitted by law and the reason is compatible with the purpose for which we collected it. If we need to use your personal information for an unrelated purpose, we will notify you and explain the applicable legal basis.

Retention

We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.

Fond retains your profile data while you are an active user of the system. If you leave your company, your account will be deactivated, however Fond will retain your (inactive) account profile until you request that we remove it. You will not be able to access your account or its contents after your account is deactivated. You can make a request to remove your data by sending an email to privacy@fond.co.

If you request your account information to be removed, your request will generally be processed within 14 business days. Fond de-identifies logs within 30 days of account closure and deletes all backups after 12 months, except as noted here.

Data Subject rights requests, and Fond’s responses, will be retained for 12 months from the initial user request.

By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Information) for six years after they cease being customers for tax purposes.

In some circumstances we may anonymize your personal information (so that it can no longer be associated with you) in which case we may use this information indefinitely without further notice to you.

Your rights

European data protection laws give you certain rights regarding your personal information. You may ask us to take the following actions in relation to your personal information that we hold:

  • Opt-out. Stop sending you direct marketing communications. You may continue to receive Service-related and other non-marketing emails.
  • Access. Provide you with information about our processing of your personal information and give you access to your personal information.
  • Correct. Update or correct inaccuracies in your personal information.
  • Delete. Delete your personal information.
  • Transfer. Transfer a machine-readable copy of your personal information to you or a third-party of your choice.
  • Restrict. Restrict the processing of your personal information.
  • Object. Object to our reliance on our legitimate interests as the basis of our processing of your personal information that impacts your rights.

You can submit these requests by email to privacy@fond.co or our postal address provided above. We may request specific information from you to help us confirm your identity and process your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to legal restrictions. If you would like to submit a complaint about our use of your personal information or response to your requests regarding your personal information, you may contact us at privacy@fond.co or submit a complaint to the data protection regulator in your jurisdiction. You can find your data protection regulator here.

Cross-Border Data Transfer

Whenever we transfer your personal information out of the European Economic Area (EEA) to countries not deemed by the European Commission to provide an adequate level of personal information protection, the transfer will be based on one of the following safeguards recognized by the European Commission as providing adequate protection for personal information, where required by EU data protection legislation:

  • Contracts approved by the European Commission which impose data protection obligations on the parties to the transfer. For further details, see European Commission Model contracts for the transfer of personal information to third countries.
  • For transfers to third parties in the United States, ensuring they participate in the EU–US Privacy Shield Framework

Please contact us at privacy@fond.co if you want further information on the specific mechanism used by us when transferring your personal information out of the EEA.

What law governs my use of the Service?

By choosing to use the Site or the Service or otherwise provide information to Fond, you agree that any dispute over privacy or the terms contained in this Privacy Policy will be governed by the law of the State of California. You also agree to abide by any limitation on damages contained in our Terms of Service or other agreement that we have with you. This does not prevent consumers in the European Union from bringing a claim to enforce their consumer rights in relation to this Policy in their local courts.