Thank you for choosing to be part of our community at MJIC, Inc. (d/b/a ManifestSeven) and its subsidiaries, operating as “K2 DISPENSARY, LLC” or its applicable affiliates (“Company”, “we”, “us”, or “our”). We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about our policy, or our practices with regards to your personal information, please contact us at firstname.lastname@example.org.
(a) websites, portals, mobile applications, channels, and software, including https://k2spicestore.com, social media pages and channels (collectively, the “Sites”); and
(b) any services, features, media, functions, content, tools, and links contained or offered in the Sites (collectively, the “Services”); and
(c) if applicable, mobile applications (“Apps”).
- WHAT INFORMATION DO WE COLLECT?
We collect certain types of information in order to better provide our Sites and Services to all our users. The types of personal information we collect may include your name, address, contact information, passwords and security data, payment information, and social media login data. How this personal information is used depends on your use of the Sites and Services.
We collect only personal information that you voluntarily provide to us when registering on any of the Site or Services where you express an interest in obtaining information about us or our products and services, when participating in activities on the Sites or Services or otherwise contacting us. The personal information we collect can include the following:
- Account Information: If you create an account on any of the Sites or Services (a “User Account”), you may submit your first name, last name, maiden name, nickname, phone numbers, e-mail address, home address, phone number, zip code, gender, a profile bio, and birth date. Some users may also submit their means of age verification (e.g., driver’s license) or medical marijuana recommendation, including their recommending doctor’s name and license number, contact information, verification methodology, and verification number. We use this information to facilitate the creation and continued security of your User Account and to assist in facilitating transactions that you initiate through the sites and Services. We also use it to identify you as a user in our system based on a legitimate interest in providing, personalizing, and improving the Services for an optimal user experience. See Section 6 below for more information.
- Credentials. We may collect passwords, password hints, and similar security information used for authentication and account access.
- Public Content. The information that you contribute or post on the Sites or Services that is intended for public consumption, including your reviews, tips, photos, videos, check-ins, comments, likes, posts, events, bookmarks, friends, lists, compliments, and User Account name and profile photo.
- Communications. When you sign up for a User Account or use certain features, you can opt-in to receive social, transactional, marketing, or administrative messaging from other Company users, businesses, and the Company itself. You may also exchange messages with the Company administrators, or other users.
Messages that you exchange through the Sites or Services are saved. If you send or receive messages through the Sites or Services via SMS text message, we may log phone numbers, phone carriers, and the date and time that the messages were processed. We may also store the information that you provide when you communicate with us, including phone calls, letters, e-mails, and other electronic messages, or in person.
This information is largely used to process and deliver those messages, based on our legitimate interest in facilitating communications and responding to you for things like customer support. We also use it to send newsletters, surveys, offers, and other promotional materials. You may always opt-out of our direct marketing emails by following the instructions contained within our promotional emails, SMS text messages or, in some cases, by logging into your User Account and changing your communication preferences.
- Payment Data. If you initiate a transaction through any of our Sites or Services (the “Transactable Sites”), you may submit personal information such as your name, telephone number, billing address, shipping address, and e-mail address.
To most efficiently serve you when placing orders through our Transactable Sites, credit card transactions and order fulfillment are handled by established third-party banking managers, processing agents, and distribution institutions called SQUARE. They receive only the information required to verify and authorize your credit card or other payment information and to process and ship your order. We encrypt this information using industry-standard technology but use of your credit card information is governed by the Privacy Policies of SQUARE, who helps process those transactions. For more information, see: https://squareup.com/us/en/legal/general/privacy.
Some users may also submit data that may be considered personal medical information, such as medical marijuana recommendations for orders placed through the Transactable Sites. This can include order history. We use this information to facilitate your transaction, from receiving orders to sending communications about them to you. Things like order history can help populate forms for future transactions. Some of this information will be shared with third parties, to help facilitate the transaction you initiate.
- Social Media Login Data.We may provide you with the option to register using social media account details, like your Facebook, Twitter or other social media account. If you choose to register in this way, we will collect this information as described in Section 8 below.
- Applications.We may collect information regarding your push notifications, when you use our Apps. If you use our Apps, we may also request to send you push notifications regarding your account or mobile application. If you wish to opt-out of receiving these types of communications, you may turn these notifications off from within your device’s settings.
- Activity:We may collect information about you through your use of our Sites and Services, including geographic location, IP address, browser type, domain name, the website that led you to the Sites, the website to which you go after leaving the Sites, the dates and times you access the Sites and Services, device ID, and activities within our Sites or Services (e.g., links you click, searches you run, the date and time of your visit or order, the businesses you call or email using our mobile applications, and the purchases you make through the Transactable Sites).
We do this to customize the advertising you view and to recommend content based on our legitimate interest in advertising our Sites and Services. We also do this to provide user base demographics to our listing providers in order to help connect you to those businesses and facilitate your transactions with them.
Further, we may collect certain information with the help of cookies and other tracking mechanisms–please see Section 5 below for more information.
All personal information that you provide to us must be true, complete and accurate, and you must notify us of any changes to such personal information.
- HOW DO WE USE YOUR INFORMATION?
We use personal information collected via our Sites and Services for a variety of business purposes described below. We process your personal information for these purposes in reliance on our legitimate business interests, in order to enter into or perform a contract with you, with your consent, and/or for compliance with our legal obligations. We indicate the specific processing grounds we rely on next to each purpose listed below.
We use the information we collect or receive:
- To facilitate account creation and logon process. If you choose to link your account with us to a third party account (such as your Google or Facebook account), we use the information you allowed us to collect from those third parties to facilitate account creation and logon process for the performance of the contract. See Section 8 below for more information.
- To send you marketing and promotional communications. We and/or our third-party marketing partners may use the personal information you send to us for our marketing purposes if this is in accordance with your marketing preferences. You can opt-out of our marketing emails at any time. See Sections 12 and 13 below for more information.
- To track usage of the Sites and Services. We track usage, analyze system administration, debug and identify repairs, and back up our systems to allow for disaster recovery, based on our legitimate interest in operating and administering the continued availability of our Sites and Services.
- To send administrative information to you. We may use your personal information to send you product, service and new feature information and/or information about changes to our terms, conditions, and policies.
- To prevent illegal activities. We detect security incidents to protect, investigate, prevent, and potentially take action against possible deceptive, fraudulent, unauthorized, malicious or illegal activities, and to respond to claims that Site or Services content is inauthentic, counterfeit, or otherwise violates the rights of third parties, based on our legitimate interest in promoting the safety and security of the systems and applications used for our Sites and Services and in protecting our rights, your rights, and the rights of others.
- Fulfill and manage your orders. We may use your information to fulfill and manage your orders, payments, returns, and exchanges made through the Sites and Services.
- Deliver targeted advertising to you. We may use your information to develop and display content and advertising (and work with third parties who do so) tailored to your interests and/or location and to measure its effectiveness.
- To post testimonials. We may post testimonials on our Sites, Services or Apps that may contain personal information. Prior to posting a testimonial, we will obtain your consent to use your name and testimonial. If you wish to update, or delete your testimonial, please contact us at email@example.com and be sure to include your name, testimonial location, and contact information.
- Administer prize draws and competitions. We may use your information to administer prize draws and competitions when you elect to participate in competitions.
- Request Feedback. We may use your information to request feedback and to contact you about your use of our Sites, Services or Apps.
- To respond to legal requests and prevent harm. If we receive a subpoena or other legal request, we may need to inspect the data we hold to determine how to respond.
- To manage user accounts. We may use your information for the purposes of managing our account and keeping it in working order.
CONTROLS FOR DO-NOT-TRACK FEATURES
- THIRD PARTIES
We only share information with your express consent, to comply with laws, to provide you with services, to protect your rights, or to fulfill business obligations.
We may process or share data based on the following legal bases:
- Consent: We may process your data if you have given us specific consent to use your personal information for a specific purpose.
- Legitimate Interests: We may process your data when it is reasonably necessary to achieve our legitimate business interests.
- Performance of a Contract: Where we have entered into a contract with you, we may process your personal information to fulfill the terms of our contract.
- Vital Interests: We may disclose your information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person and illegal activities, or as evidence in litigation in which we are involved.
We may need to process your data or share your personal information with Third Parties in the following situations:
- Third Party Advertisers. The Company does not disclose your personal information to third parties for the purpose of directly marketing their services to you unless you first agree to such disclosure. However, we may allow third-party Cookies to collect the same type of information for the same purposes that the Company does for itself, including to serve ads when you visit the Sites or Services. In doing so, the Company adheres to the Digital Advertising Alliance’s Self-Regulatory Principles for Online Behavioral Advertising. These companies may also use information about your visits to our Website(s) and other websites that are contained in web cookies and other tracking technologies in order to provide advertisements about goods and services of interest to you.
- Legal Obligations: We may investigate and disclose information from or about you to third parties like law enforcement if we have a good faith belief that such investigation or disclosure: (i) is reasonably necessary to comply with federal, state, or local legal process and legally binding law enforcement instructions and orders, such as a search warrant, subpoena, statute, judicial proceeding, or other legal process served on us (including in response to public authorities to meet national security or law enforcement requirements); (ii) is helpful to prevent, investigate, or identify possible wrongdoing in connection with the Websites or Services; or (iii) protects our rights, reputation, property, or that of our users, affiliates, clients, partners, or the public.
Cookies collect and transmit information about you, such as your use of the Sites or Services; your browser type, search preferences, IP address; and the date and time of your use. Cookies may have unique identifiers, and reside, among other places, on your computer or mobile device, in emails we send to you, and on our web pages.
We use both session-based and persistent Cookies. Session-based Cookies exist only during one session and disappear from your device when you close your browser or turn off your device. Persistent Cookies remain on your computer or device after you close your browser or turn off your computer.
We use the following different categories of Cookies:
- Operationally Necessary. We use these Cookies for the proper operation of our Sites, Services, and relevant essential applications, features, and tools, including, if applicable, our Apps. This includes technologies (i) that allow you to access our Sites and Services, applications, and tools, (ii) that are required to identify irregular site behavior, prevent fraudulent activity, and improve security, or (iii) that allow you to use our other ancillary functions such as shopping carts, saved searches, or similar features. If you prevent these cookies, we cannot guarantee that the Sites or Services will function.
- Performance Related. Performance-related Cookies collect information related to your use of the Site or Services, such as web page analytics or error reports. We use these Cookies to assess the performance of our Sites, Services, and relevant applications, features, and tools, and to help us understand how people use them. For example, we use Google Analytics and other enterprise-grade platforms to help in this effort.
- Functionality Related. Functionality-related cookies offer you enhanced functionality and personalization when accessing or using our Sites, Services, and relevant applications, features, and tools. This may include technologies (i) that identify you when you sign into our Sites or Services, (ii) that keep track of your specific preferences, interests, or past items viewed so that we may enhance the presentation of content on our Sites or Services, (iii) that determine if you have interacted with our messaging and notifications, or (iv) that improve upon or create new site content, applications, products, services, features, or tools.
- Advertising or Targeting Related. Marketing cookies help us to deliver content, including ads relevant to your interests, on our sites or on third-party sites. This involves using technologies to understand data relating to advertisements that have been displayed to you or that you have clicked on. This helps us determine the usefulness of the advertisements and content that has been delivered to you.
We also work with third parties to help better serve you, and these companies use their own cookies when they serve you content on our site.
Managing Cookies: It may be possible to delete, block, or disable Cookies through your device or browser settings, but doing so can affect the functionality of the Sites and Services and may prevent you from accessing certain features. The method for disabling Cookies may vary by device and browser but can usually be found in preferences or security settings. Please note that disabling a cookie or category of cookies does not delete the cookies from your browser unless manually completed through your browser function.
- MANAGING AND DELETING YOUR INFORMATION
Your Right to Access and Manage Your Information
You have the right to access, review, correct, or update the information you provide to us as part of your registration for a User Account with our Sites or Services. You can exercise this right and manage your own information by updating your User Account directly or by submitting a Data Request to us pursuant to the section below. You are responsible for the information you provide to us, and you should maintain the accuracy of the personal information in your User Account so that we can best provide products and services to you.
You may also be able to disallow our use of certain location data through your device or browser settings. Please note, however, that disabling location services may adversely impact your experience with the functionality of our Site or Services and enabling such services may be necessary in some cases to allow certain transactions.
Your Right to Delete Your Information
You have the right to delete certain personal information you provide to us as part of your registration for a User Account with our Sites or Services, or that you submit through the Transactable Sites. Keep in mind, we need this information to provide account management and access, and if you choose to delete information, you may not be able to take advantage of certain features of the Sites and Services. Should you choose to delete information, you can exercise this right by submitting a Data Request to us pursuant to the section below. We will never discriminate against you should you choose to exercise these rights.
You also cannot delete information associated with past purchases because we, and third-party businesses listed on the Sites or Services, may be required to maintain records of purchases for a limited period pursuant to federal, state, or local law. Also, any public postings or other communications you have made on the Sites or Services, such as in forums or blogs, generally cannot be removed, so please be mindful of the information you include there.
If your personal information has been submitted to us by a third-party business using the Sites or Services as Customer Data and you wish to exercise your rights to access, revise, or delete such data, please inquire with the relevant third-party business and submit a Data Request to us pursuant to the section below.
Please note that we take your privacy seriously and therefore take steps to safeguard your personal information, including ensuring an adequate level of data protection in accordance with international standards. If you are not satisfied with how we have stored or processed your personal information, please contact us pursuant to the section below. If you would like to access, revise, or delete any personal information, please submit a written Data Request by contacting us pursuant to Section 7 below.
We will take such steps as we deem necessary to verify your identity before proceeding with your Data Request. For example, we may ask you for a piece of information held in your records that you might reasonably be expected to know. We cannot disclose personal information pursuant to a Data Request to anyone other than the individual in question. Once any queries around the information requested have been resolved, copies of the information will be sent to you electronically wherever possible or, if this is not technically possible, by mail.
If you submit multiple Data Requests and these Data Requests are excessive or manifestly unfounded, we will charge $20.00 to cover the administrative costs involved in dealing with each Data Request. In extreme circumstances, we reserve the right to refuse your Data Requests if they are excessive or manifestly unfounded.
We will attempt to respond to proper and confirmed Data Requests within thirty (30) days, or as otherwise required by applicable law. If you are not satisfied with the way your Data Request was handled, you may refer your Data Request to your country’s data protection authority. In the European Economic Area (EEA), any such request should be directed to the appropriate Data Protection Authority in the EU Member States and in Iceland, Liechtenstein, and Norway.
Your Right to Cancel, Opt-Out or Modify Marketing Communications
Under 12 CFR Part 40, you have the right to cancel or modify the e-mail marketing communications you receive from us. You can exercise this right by following the instructions contained within our promotional e-mails or, in some cases, by logging into your User Account and changing your communication preferences. Please note that this will not affect subsequent or different subscriptions–if your opt-out preferences are limited to certain types of emails, the opt-out will be so limited.
While you can manage some of your email preferences, please note that you cannot opt- out of receiving certain administrative, transactional, or legal messages from the Company which we may send in the course of legitimate business if you are signed up for a User Account and/or use certain features. However, such announcements can be terminated by asking us to close your User Account.
- CONTACT INFORMATION FOR SUBMITTING A DATA REQUEST
Attn: Legal Department, 111 Pacifica Suite 100, Irvine, CA 92618 United States of America
Additional information regarding how to contact the Company may be found at: https://k2dispensary.com/pages/terms-of-service/
- SOCIAL MEDIA LOGINS
If you choose to register or log in to our services using a social media account, we may have access to certain information about you.
Our Site and Services may offer you the ability to register and login using your third-party social media account details (like your Facebook or Twitter logins). Where you choose to do this, we will receive certain profile information about you from your social media provider. The profile Information we receive may vary depending on the social media provider concerned, but will often include your name, e-mail address, friends list, profile picture as well as other information you choose to make public.
- DATA RETENTION POLICY
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
We aim to protect your personal information through a system of organizational and technical security measures. We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. These measures include, but are not limited to, minimizing access to personal information to employees with a need to access it, and encrypting personal information provided through our Site using SSL/TLS. However, please also remember that we cannot guarantee that the internet itself is 100% secure. Although we will do our best to protect your personal information, transmission of personal information to and from our Sites and Services is at your own risk. You should only access the services within a secure environment.
In addition, there are steps you can take to help protect your information, including choosing a robust password for your device and/or account that nobody else knows or can easily guess, and keeping your log-in and password private.
The Company is not responsible for the actions or activities of unauthorized third parties who compromise our security measures, and so we cannot be responsible for such unauthorized party’s access, acquisition, or distribution of your personal information. If you believe your personal information has been compromised, we encourage you to notify us immediately using the contact information above.
Please note that we retain some personal information about you in accordance with our record retention policies, as required by law, or as required for the achievement of the purposes of the processing as mentioned above (e.g., to enforce any agreements or provide a product/service).
It is important for you to protect against unauthorized access to your account, password, and computer. Be sure to sign off your account when finished, especially if you are using a shared computer. You can learn more about steps you can take to protect your personal information at: https://www.consumer.ftc.gov/articles/0272-how-keep-your-personal-information-secure.
- COLLECTION OF INFORMATION FROM MINORS
The Sites, Services and Apps are intended for adults only and require that users be no less than nineteen (19) years of age. Please note that certain affiliated Sites and Services may require you to be at least twenty-one (21) years of age to access and use such Sites and Services. Please check the applicable terms and conditions for such sites and services for further information. Individuals under the age of nineteen (19) (or twenty-one (21) for applicable Sites and Services) are prohibited from creating a User Account and profile, accessing the Sites or Services, and/or ordering products on the Transactable Sites. If you become aware that an underage user has created a User Account using false, stolen, or otherwise misleading information, please contact us immediately at firstname.lastname@example.org.
- YOUR PRIVACY RIGHTS GENERALLY
Your Rights as a Resident of the European Economic Area
You may review, change, or terminate your account at any time. If you are resident in the European Economic Area and you believe we are unlawfully processing your personal information, you also have the right to complain to your local data protection supervisory authority. You can find their contact details here: https://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612080
If you have questions or comments about your privacy rights, you may email us at email@example.com.
International Data Transfer
Though we currently do not share information globally, we may in the future, both internally within the Company and externally with our partners around the world. If you are located outside of the United States, please be aware that information we collect, including your personal information, may be transferred to, and processed, stored, and used within the United States. This transfer is necessary to provide our Sites and Services.
If you would at any time like to review or change the information in your account or terminate your account, you can:
Log into your account settings and update your user account.
Opting out of email marketing:
You can unsubscribe from our marketing email list at any time by clicking on the unsubscribe link in the emails that we send or by contacting us using the details provided below. You will then be removed from the marketing email list – however, we will still need to send you service-related emails that are necessary for the administration and use of your account. To otherwise opt-out, you may:
- Note your preferences when you register an account with the site.
- Access your account settings and update preferences.
- PRIVACY RIGHTS AND NOTICE FOR CALIFORNIA RESIDENTS
Relevant California Law
If you are a resident of California, you are granted specific rights regarding access to your personal information. California Civil Code Section 1798.83, also known as the “Shine The Light” law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided above.
As a California consumer, you have certain rights regarding your personal information. You have the right to request from us the following information: (1) the categories of personal information we have collected about you; (2) the categories of sources from which your personal information is collected; (3) the business or commercial purpose for collecting or selling your personal information; (4) the categories of third parties with whom we share personal information; and (5) the specific pieces of personal information we have collected about you. You also have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
How to Exercise Your Rights
To exercise any of the rights listed in the section above, please submit a verifiable Data Request by contacting us pursuant to Section 7 above.
You are not required to have an account with us in order to submit a request and we will only use personal information provided in a request to verify the requestor’s identity or authority to make such a request. Please note you may only make a verifiable Data Request for access or data portability twice within a 12-month period.
Please note that the Company must verify the identity of the requestor. You may designate an authorized agent to make a request on your behalf by providing proof of a valid power of attorney, your valid government issued identification, and the authorized agent’s valid government issued identification. We cannot respond to requests where the identity and authority of the requestor cannot be confirmed.
Any disclosures we provide will only cover the 12-month period preceding the verifiable Data Request’s receipt. If we are unable to comply with a request, we will inform you of the reason why.
Information We Collect About Our California Customers
In the past twelve (12) months we may have collected from you the types of personal information described in Sections 2 and 3 above. We collect and use this information for the business and commercial purposes described in Sections 2 and 3 above. We share this information with third parties for the limited purposes described in Sections 2, 3 and 4 above.
We Do Not Sell Your Personal Information
We do not “sell” (as such term is defined in the California Consumer Privacy Act) the personal information we collect, and we will not sell it without providing you the opportunity to opt-out.
California residents who choose to exercise the rights described in this section will not be denied any goods or services, charged different prices or rates, or be provided a different level or quality of goods or services unless those differences are related to your personal information.
- UPDATES TO THIS POLICY
We will update this policy as necessary to stay compliant with relevant laws, from time-to-time. We may also post privacy policies or statements on the Sites or Services where those additional policies apply. The updated version will be indicated by an updated “Revised” date and the updated version will be effective as soon as it is accessible.
(a) sending an e-mail to the e-mail address you most recently provided; or
(b) sending an SMS message to the phone number you most recently provided to us, if you have given us express consent to notify you by SMS text message; or
(b) sending a push notification or in-app notification; or
(c) prominently posting a notice of the changes on those Sites.