Privacy Policy
eco2win.com (“we,” “us,” or “our”) is committed to safeguarding the privacy and personal data of our users. This Privacy Policy outlines how we process and protect personal information in compliance with applicable data protection laws, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). We adhere to the principles of transparency, fairness, and accountability in the handling of personal data entrusted to us.
1. Introduction
We value your privacy and take our responsibility to protect your personal data seriously. This Privacy Policy explains how we collect, use, disclose, and store your personal information when you access or interact with our website (eco2win.com), services, and communications. Our commitment is grounded in strong privacy ethics and industry best practices.
2. Scope of This Policy and Data Controller Role
This Privacy Policy applies to all personal data collected via eco2win.com and our associated services. eco2win.com acts as the Data Controller as defined under the GDPR, meaning we determine the purposes and means of processing your personal data. If you are a California resident, we also serve as a Business, as defined by the CCPA.
3. Categories of Data We Process
We collect and process the following categories of personal data depending on your interactions with eco2win.com:
– Usage Data: Information such as IP address, browser type, browser version, pages visited, time spent on pages, referral URLs, session timestamps, and interaction data.
– Account Data: Personal information you provide to register or create an account, including your name, billing/shipping address, phone number, and email address.
– Profile Data: Details you choose to add to your user profile, such as preferences, browsing habits, previous orders, saved items, and behavioral data.
– Communication Data: Records of communications with us, including customer support queries, contact form entries, live chat logs, call transcripts, and email correspondence.
– Technical Data: Information about the device you use to access our services, including operating system, mobile identifiers, browser configurations, and system preferences.
– Transaction Data: Payment details (excluding full card information), purchase history, order numbers, product selections, delivery data, and transaction timestamps.
– Preference Data: Marketing communication preferences, opt-in consents, product interest data, and survey responses.
4. Legal Bases for Processing
Our processing of personal data is grounded in one or more of the following lawful bases as required under the GDPR:
– Consent: We process personal data when you have given clear, informed consent, such as signing up for newsletters or promotional offers.
– Contractual Necessity: Data necessary for the performance of a contract with you, including fulfilling online purchases and providing services.
– Legitimate Interests: Processing that is necessary for our legitimate business interests—such as improving our services, securing our platform, or preventing fraud—unless your rights override those interests.
– Legal Obligation: Where processing is necessary to comply with a legal or regulatory obligation.
Under the CCPA, personal information is used in ways that are consistent with its collection context and in accordance with your rights under California law.
5. Your Data Protection Rights
In accordance with GDPR and CCPA, you have the following rights over your personal data:
– Access: Request access to your personal data and obtain a copy of the data we hold.
– Rectification: Request correction of incomplete or inaccurate data.
– Erasure: Request the deletion of your personal data, subject to legal retention obligations (also known as the “right to be forgotten”).
– Restriction: Request a halt to processing under certain conditions.
– Portability: Receive your personal data in a structured, commonly used, and machine-readable format for portability purposes.
– Objection and Opt-Out: Object to certain processing (e.g., direct marketing) or withdraw previously granted consents.
To exercise any of your rights, please contact us at [email protected].
California residents have additional rights under the CCPA, including the right to opt out of the “sale” of personal information, even though eco2win.com does not sell your personal data in the traditional sense.
6. Security Measures
We employ industry-standard administrative, technical, and physical measures to protect your personal data:
– Data encryption at rest and in transit.
– Access control and authentication mechanisms.
– Secure coding and software development practices.
– Routine data backups and disaster recovery protocols.
– Ongoing employee training and security awareness programs.
While we take all reasonable steps to secure your data, no security system is impenetrable. If we experience a data breach that materially affects your data, we will notify you as required by law.
7. International Data Transfers
Your personal data may be stored or processed outside your country of residence, including in jurisdictions that may not provide the same level of data protection as your home country. Where we transfer personal data outside the European Economic Area, we implement appropriate safeguards, including:
– European Commission-approved Standard Contractual Clauses.
– Binding Corporate Rules (where applicable).
– Other lawful transfer mechanisms in compliance with Article 46 of the GDPR.
By using eco2win.com, you understand and agree to such transfers.
8. Data Retention
We retain personal data only as long as necessary to fulfill the purposes for which it was collected or to comply with legal, accounting, or regulatory obligations. Typical retention periods are as follows:
– Account Data: Retained for the duration of the user’s account, plus 2 years.
– Transaction Data: Retained for 7 years for tax and legal compliance.
– Usage and Technical Data: Retained for up to 2 years for system analysis and security.
– Communication Data: Retained for 3 years.
– Marketing/Preference Data: Retained until consent is withdrawn or data is no longer actionable.
Once personal data reaches its applicable retention limit, it is securely deleted or anonymized.
9. Cookie Policy
eco2win.com uses cookies and similar technologies to provide, protect, personalize, and improve the user experience. The following types of cookies are used:
– Essential Cookies: Necessary for site functionality and secure login.
– Functional Cookies: Enable features like remembering preferences or location.
– Analytics Cookies: Collect aggregated usage data to improve site performance and functionality.
– Performance Cookies: Help monitor site speed, error messages, and responsiveness.
We do not use cookies that track you across other websites for advertising purposes without your explicit consent.
10. Cookie Management and Compliance
Upon first visit to eco2win.com, users are presented with a cookie banner. Users may consent to or reject non-essential cookies in accordance with GDPR-compliant cookie consent models. Settings may be changed at any time via the cookie preferences center.
California residents can manage cookie-based data sharing as provided in the CCPA’s “Do Not Sell or Share My Personal Information” framework. Our site includes appropriate mechanisms to exercise such rights.
11. Children’s Privacy
eco2win.com is not designed for or directed at children under the age of 13. We do not knowingly collect personal data from children under 13 without verified parental consent. If we become aware that personal data has been inadvertently collected from a child without appropriate consent, we will take prompt steps to delete such information.
12. Policy Updates
eco2win.com may revise this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When changes are significant, we will provide a prominent notice on our site or contact you directly, where required by law. Continued use of our services after changes indicates your acceptance of those changes.
13. Contact Us
If you have any questions, requests regarding your personal data, or concerns about our privacy practices, please contact us:
Email: [email protected]
We are committed to full compliance with applicable data protection laws and welcome your feedback to improve our privacy practices.
We are dedicated to ensuring that your personal data is treated with the utmost care and responsibility. Please do not hesitate to reach out to [email protected] if you have any questions or concerns about how your information is handled.