Effective Date: June 1st, 2020
Thank you for using Pyrl!
Pyrl is a consumer purchase data privacy platform. We believe that how you spend your money is among the most valuable data about you. Pyrl was created to give consumers the control and privacy of their purchase data, and that is our core business. Our policies, and our technology, are built to set the highest standard to put you in the driver’s seat of your own data. Your privacy, and your ability to decide if and how your purchase data can be utilized to benefit you, is our highest business priority.
This Privacy Statement explains the ways that we collect, use, and share information in order to operate, improve, develop, and protect our services.
Our Data Practices
- Information We Collect and Categories of Sources
- How We Use and Share Your Information
The fine print …
- Our Retention Practices
- International Data Transfers
- Your Data Protection Rights
- Changes To This Policy
- Contacting Pyrl
A quick note about Pyrl, and some definitions
Our mission at Pyrl is to empower consumers to exercise their data privacy and access rights over their purchase data (our “Services”). Our technology allows you, our “Users” to appoint Pyrl as an agent to act on your behalf, in order to exercise your right that your data not be sold, shared, or brokered by the companies you choose to buy from, and to exercise your right to be able to utilize your own purchase data. We aim to provide this service to you across anywhere you purchase merchandise, including brick-and-mortar retailers, e-commerce, direct-to-consumer brands, or purchases made over social platforms or apps. Collectively we refer to all such businesses as your “Retailers”.
About this Policy
Our goal with this Policy is to provide a clear explanation of what information Pyrl collects about users (“User Information”), in order to provide users with our Services, and how we use and share that information.
Information We Collect and Categories of Sources
Information you provide:
- When you subscribe to email updates about our company, or fill out our Contact-Us form, we collect your email address, and IP address. This is to respond to you, and to prevent spam and abuse.
- When you sign up for our Services by creating an account profile:
- We collect your email address, name, physical address, and mobile number. This is so that you can personalize your account, so that we can contact you about the services you’ve requested, confirm which privacy laws apply within the State in which you reside, and so that we can fulfil our commitment to convey your privacy rights to your chosen retailers, in a manner that allows them to find you in their systems, and to validate your request actually came from you. We collect your IP address to prevent spam, fraud and abuse, diagnose errors on our platform, and to provide you with support.
- When you ask us to act on your behalf to express your purchase data privacy rights, we collect your typed initials, together with your IP address and timestamp, as a legally accepted form and proof of your electronic signature. This is so that we can meet Retailers’ requirements to prove that you indeed formally directed us to act on your behalf with regard to expressing your data privacy rights.
- When you select or edit your list of Retailers manually:
- We collect the list of Retailers that you have chosen, so that we can work on your behalf to express your data privacy rights and preferences to your Retailers.
- When you set your privacy preferences, we collect your chosen settings, so that we can appropriately act on your behalf.
- When you contact us for help or support, we’ll keep the correspondence and the email address, for future reference.
- When you refer friends or family to Pyrl, we collect the recipient’s email address.
Information we receive from your linked account(s):
- When you choose to link a credit / debit card account to retrieve or maintain your list of Retailers and transactions automatically:
- We utilize a secure and industry-standard platform (‘Bank Connection Provider’) to enable you to link your chosen account(s) to Pyrl. When you use this feature, you will choose your issuing bank and link your account by providing your login credentials. Pyrl will never see, store, or have access to your credentials.
- We collect a secure access token provided to us by the Provider, so that we can retrieve your transactions and securely display them to you for your review.
- To enable you to see your retail-related transactions, and to confirm which Retailers you want us to engage with on your behalf to express your data privacy rights, we collect information about your retail-related transactions to display to you. This is so that we can show this information to you and enable you to make decisions about your data privacy with the retailers from whom you have made purchases. This includes the transaction date, amount, payee, type, location, and description information.
- We utilize the transaction’s category type to determine which transactions are retail-related, and we ignore and do not store or otherwise retain or process any other information about your linked account transactions.
- Pyrl also uses your password to encrypt the linkage between your identity, and your retail-related transaction data including dates and amounts. This linkage can only be decrypted by you, using your password, when you log into our Service. This is so that your information remains private, and so that only you have access to see and use it.
When you upgrade to our Premium service:
- Our premium service allows you to keep your card(s) linked to Pyrl until you cancel, so that your growing list of retailers is always protected by our privacy Services, even as you shop at new places online and off. Our premium service will also keep your Retailer transaction information up-to-date, so that you can see your latest retail spend on your dashboard.
- When you subscribe to a Premium service, we collect your credit card number so that we can charge you for your subscription. Your credit card is passed directly to our payment processor and doesn’t ever go through our servers. We store a record of the transaction, including the last four digits of the credit card number, for account history, invoicing, and billing support. We store your billing address to calculate any sales tax due, to detect fraud, and to include on your invoices.
Information we receive from your Retailers:
- When retailers respond to your data privacy or access requests via Pyrl,
- We collect the status of the Retailer honoring your data privacy request, and any actions required to completion.
- If requested by you, and honored by the Retailer, we collect the details of your purchases from the Retailer so that they are securely accessible to you via Pyrl.
Cookies, analytics services provided by others, and information provided by your devices:
- We utilize a ‘privacy-first’ third party web site analytics platform to enable us to understand how our Services are visited and used. This service captures masked (partial) IP addresses, the type of browser and device used to access our Services, pages viewed and links clicked, and related usage statistics, to determine the usage patterns of our users so that we can identify errors and improve, test, and develop our Services.
- We do not allow third parties to provide free analytics services to us. In order to make interested Beta users aware of Pyrl we have temporarily enabled google Ads on our site which will serve Pyrl ads to users who have searched for relevant terms or visited our site.
- In our app
- We securely track logged-in sessions, which includes your IP address, in order for us to provide our Services and to prevent misuse of your account.
How We Share Your Information
The only times we’ll ever share your End User Information:
- To provide the Services you’ve requested, with your permission.
- To investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our terms of service, to protect the rights, privacy, safety, or property of you, our company, our partners or others, or as otherwise required by law.
- For other notified purposes with your consent.
How We Use Your Information
We use your End User Information to operate, improve, and protect the services we provide, and to develop new services. More specifically, we use your End User Information:
- To operate, provide, and maintain our services;
- To improve, enhance, modify, add to, and further develop our services;
- To protect you, our partners, our company, and others from fraud, malicious activity, and other privacy and security-related concerns;
- To develop new services;
- To provide customer support to you;
- To investigate any misuse of our service;
- For other notified purposes with your consent.
We may collect, use, and share End User Information in an aggregated, de-identified, or anonymized manner (that does not identify you personally) for any purpose permitted under applicable law, and to advocate on behalf of our user base. This includes creating or using aggregated, de-identified, or anonymized data based on the collected information to develop new services and to facilitate research.
For example, to advocate on behalf of our user-base with any given Retailer to secure your privacy rights and benefits, we may convey to that Retailer the total aggregate monthly spend of our total user base at that Retailer.
We do not sell or rent personal information that we collect.
Our Retention Practices
We retain End User Information for no longer than necessary to fulfill the purposes for which it was collected and used, as described in this Policy, unless a longer retention period is required or permitted under applicable law. You have the ability to fully delete your account, in which case we will entirely delete all information in our records that we can associate with you, and as permitted by law.
Please refer to the “Your Data Protection Rights” section for options that may be available to you, including the right to request deletion of End User Information. You can also contact us about our data retention practices using the contact information below.
Some Final Details…
International Data Transfers
Pyrl is currently available to Users within the United States only. We do not yet operate in the EU or UK. Our systems and servers are located and hosted within the United States. We do not transfer the information we collect across international borders, for processing or storage.
Your Data Protection Rights
As a data privacy platform, Pyrl recognizes and complies with data privacy laws and regulations, including the California Consumer Privacy Act (“CCPA”). Specifically, your rights and capabilities include:
- Right to opt-out of any “sales” of your personal information: We do not sell or share your End User Information.
- Right to Erasure: To request deletion of your account and any information we have that we can link to your account. “Delete my account” is available under Account Settings.
- Right to Access and Portability: You may request a download of the categories and specific pieces of User information on our platform.
For inquiries or to exercise any data protection requests not covered here, you can submit a request using our online form or contact us as described in the “Contacting Pyrl” section below. You may be required to provide additional information necessary to confirm your identity before we can respond to your request.
We will consider all such requests and provide our response within a reasonable period of time (and within any time period required by applicable law).
Changes To This Policy
We may update or change this Policy from time to time. If we make any updates or changes, we will post the new policy on Pyrl’s website at https://pyrl.io/privacy and update the effective date at the top of this Policy. We will also notify our Users of any material changes via email or messaging within Pyrl, as appropriate.
If you have any questions or concerns about this Policy, or about our privacy practices generally, you can contact us at firstname.lastname@example.org or by mail at:
DataFi Platform LLC, dba Pyrl
6700 Alexander Bell Drive
Columbia, MD 21046