May 15, 2023
Who We Are
CannaSmack, is a privately owned woman-owned company that crafts high quality lip balms, bodycare, and skincare products made with premium hemp seed oil.
What information do we collect?
- Customer provided: Contact information (name, email, phone number, payment information, and other information provided by the user) to purchase our products, sign up for a special offer, or access our newsletter. Additional information is collected as customers engage with us through social media, uses our ticketing system to contact us, or provides us with feedback and reviews of our products and services.
- Automatically collected: IP Address, user agent, and the referring URL. When you visit our website we automatically receive your IP address and information such as the user-agent of your web browser. This information is provided to us and every other website that you visit on the Internet by your web browser.
What information do we know about you?
We don’t request or require you to provide personal information to access our website. As noted above, we may receive your IP address and user agent automatically. If you optionally elect to use our chat feature or fill out our contact form, we will receive your Name, Email, and Phone number, as well as your stated interest in our products and any other additional information that you elect to provide. If you sign up for a user account or subscription, we will collect your contact information (name, email, phone number, payment information, and other information provided by the user).
What about cookies?
The CannaSmack website and platform may place cookies on your browser in order to identify you when you return to our website, abandon your cart, or log in to our platform.
How do we use the information we collect?
- We use aggregate information to understand how many total users have visited our web site and the types of devices on which they are using it.
- We use information you choose to provide in our web forms to sell software and/or services
- We use information you provide to us when signing up for and using our services to provide services and to correspond with you about those services.
- We use information gathered through our platform solely to provide the services requested by customers.
Do we sell or share any of the personal information collected by the CannaSmack web site?
We don’t sell or rent personal information to any third parties in exchange for money.
Do we sell or share customers’ personal information?
We do not sell or rent customers’ personal information or data. We may share data with our vendors and service providers to perform tasks on our behalf to deliver our products.
What’s the difference between personal information and de-identified information?
Personal information is information that can be used to identify a particular individual, generally understood to be information such as your name, physical address, email address and phone number. De-identified information is not considered personal information and can’t be used to identify you.
Do we collect email addresses?
We do not require you to submit your email address, or any other personal information, to us in order to use the CannaSmack web site. If you use the information provided on the CannaSmack.com website to contact us directly, we will receive your contact information, but will only use it in order to respond to your inquiry. If you purchase our products through our website we will receive your contact and shipping information in order to deliver our products and it will remain in our system for 24 months. Our platform collects personal information, including email addresses, that is used solely to provide customer service and ship the products you purchase from us.
What Information We Collect and How We Collect It
To provide you with a pleasant shopping experience and customer service and ensure that our website is operating correctly, we collect various types of information, including information that identifies or may identify individuals (“personal information”). When you use our website or purchase our products we collect the following information:
Information you provide to us:
- If you use the contact information provided on the CannaSmack.com website to contact us directly, you agree to allow CannaSmack to store and process your contact information. We will receive your contact information which could include, depending on how you contact us, your email address, name, company name, job title, the reason for contacting, and postal address.
- We receive and store the information you provide directly to us when you purchase from us and use our services and platform. The types of information we may collect directly from our customers and users include name, email address, mailing address, phone number, payment and billing information, and any other information provided by the user (including a user-submitted photograph if a user chooses to provide one with respect to a review or in order to solve a customer service / product consern).
When you use our website or platform, we automatically collect the following information:
- Internet Protocol Address (“IP address”). IP addresses are assigned by your Internet service provider (e.g., Comcast/Xfinity, AT&T, Time Warner, Verizon, Charter, etc.) to the modem used to access the Internet for connected devices in your home and/or work-place. Any devices using the modem to access the Internet may broadcast the same IP address. At home, connected devices could include one or more laptop/desktop computers, tablets, mobile phones, smart/connected TVs and gaming consoles. At work, connected devices could include one (or all) floor(s) in an office building. Our website receives your IP address from your Internet browser each time you request a file or web page.
- User-Agent. Due to the nature of how the Internet works, we may receive information (known as “User-Agent”) automatically sent by your web browser, such as data associated with the source device’s Internet browser/content delivery software (e.g., Microsoft Explorer, Mozilla Firefox or Google Chrome). The User-Agent information we receive may also include information such as device type (e.g., computer, tablet, mobile device), and/or date/time of visit. Similar to the collection of IP addresses, our website also receives User-Agent information associated with your browser and type of device.
- Information collected by cookies and other similar technologies. We use various technologies to collect information which may include saving cookies to users’ computers. These tools help us understand and improve the performance of the CannaSmack website and platform.
We do not collect sensitive personal information other than as may be necessary to collect payment from our customers for our products and services. Unless we specifically request such sensitive information from you, we ask that you not send it to us or disclose any sensitive personal information to us.
How We Collect Information
This section details the information we collect automatically when you visit our website.
- IP address. Our website receives an IP address from your Internet browser (e.g., Microsoft Explorer, Mozilla Firefox, Google Chrome) each time you request a file or web page.
- User-Agent. Similar to the collection of IP addresses, our website also receives User-Agent information associated with your browser (e.g., Microsoft Explorer, Mozilla Firefox, Google Chrome, etc.) and type of device (e.g., whether the device is running a Windows or Apple operating system.)
- If you choose to contact us directly with an inquiry (by email, chat, or postal mail) using the contact information available to you on the CannaSmack.com website, we will receive your contact information and use it to provide you with a response.
- We may collect information from third parties, such as social networks, that help us identify prospective businesses or customers that might be interested in our products and services.
How We Use the Information We Collect
- Products and Services. We may use the information we collect in connection with the services we provide. We may use the information we collect to set up user accounts; provide, operate, and maintain services; process and complete transactions and purchases; provide customer service and support and respond to inquiries; send communications; prevent fraudulent activity; for any other purpose based on our legitimate interest.
- Website. We may use the information we collect to administer and improve the CannaSmack website and platform.
- Promotional Communications. We may use your personal information to contact you with newsletters, marketing or promotional materials, and other information that may interest you. You may opt out of receiving any, or all, of these communications from us by following the instructions provided in any email we send or by following the unsubscribe link in those emails.
- Marketing. We may use the information we obtain from you, your interactions with us and our website, as well as from third parties who help us with our marketing efforts, to provide you with marketing and promotional content, to deliver targeted and relevant advertising and marketing to you, to determine the effectiveness of our marketing campaigns and to better understand our website visitors’ preferences. You can view and change your preferences concerning this use of information through your cookie settings or by submitting a data subject request to us.
- Analytics. We may use de-identified information collected to understand general information and trends related to our website, such as how many users have visited our website during a given period of time and the types of devices the visitors use. The information can’t be used to identify an individual and is used by us to help improve consumers’ solutions.
- IP addresses – Fraud Prevention. Our use of IP addresses is limited to helping identify and combat potentially fraudulent activity. IP addresses are stored in our log files and are deleted after 30 days.
- Respond to Inquiries. If you choose to contact us directly (by email, form, or postal mail) using the contact information we provide on the CannaSmack website, we will use your contact information to respond to your inquiry.
The CannaSmack website and platform may place cookies on your browser in order to identify you when you return to our website or log in to your account.
With Whom We Share Information
We may share and disclose information (including personal information) in the following instances:
- Vendors and Service Providers. We may share your information with vendors and service providers we engage to perform tasks on our behalf, for example, to help us deliver our services, bill our customers, and respond to support tickets. More details about these vendors and service providers can be found in our GDPR statement.
- We may share your information with service providers and advertising networks as reasonably necessary for marketing our products and services.
- If CannaSmack is acquired or merged with another company, we will transfer the collected information to the acquiring company.
- Under certain circumstances, we may be required to disclose personal information if necessary to comply with a subpoena or court order, to establish or exercise our legal rights or defend against legal claims, or to cooperate with government and/or law enforcement officials.
We may share de-identified information (i.e., information that cannot be used to identify an individual) for a variety of reasons, including under the following circumstances:
- To make our products better and foster transparency.
- If CannaSmack is acquired or merged with another company, we will transfer aggregate information to the acquiring company.
- We may share de-identified information if necessary to comply with a subpoena or court order, to establish or exercise our legal rights or defend against legal claims, or to cooperate with government and/or law enforcement officials.
- For any lawful basis.
We take security very seriously. Ensuring that the information collected by our website and platform is secure and protected is very important to us. Consistent with industry standards and applicable law, CannaSmack has established appropriate technical and organizational measures to help prevent unauthorized access to, disclosure, alteration or misuse of information collected by the CannaSmack website and platform (“Collected Data”).
All data transmitted between visitors to the CannaSmack website and users of the CannaSmack platform is encrypted in transit.
All data received and stored by CannaSmack servers is encrypted at rest.
Enterprise-level firewall and DDoS protection
Two powerful firewalls protect your sites at all times. GCP’s IP-based protection firewall and Cloudflare’s enterprise-level firewall prevent many attacks from ever reaching your server. Cloudflare’s strict rules filter helps monitor your site’s incoming traffic and block IPs associated with hacking and DDOS attacks. Google Cloud Platform’s premium tier assures secure transport of your data by delivering traffic over Google’s well-provisioned, low-latency, global network. Our platform runs in an isolated software container. And each contains all the software resources required to run the site — Linux, NGINX, PHP, MySQL — making each site 100% private.
All services related to operations and infrastructure are accessible only through secure connectivity (e.g., SSL, SSH). All systems require multi-factor authentication. Our back-office, service, and infrastructure password policies require minimum lengths, complexity, lockout, and disallow reuse. CannaSmack grants access to staff and contractors based on least privilege rules, reviews permissions monthly, and revokes access immediately after employee termination.
All systems and applications undergo security review for vulnerabilities prior to production deployment. All application dependencies are monitored for vulnerabilities using third party dependency scanning tools.
CannaSmack maintains industry standard security incident response policies and procedures.
If you provide information to us to request a demo, we will keep that information for up to twenty-four months after your last communication with us. Other information collected during your use of our website will be kept until you withdraw consent or your information is no longer needed for marketing or analytical purposes.
We will keep personal information collected by our platform or provided by customers for up to three months after the end of our business relationship and subject to our agreement with our customers.
If you contact us directly using the contact information provided on the CannaSmack website, we will retain your contact information for up to three months after we respond to your inquiry. After that, the communications will be deleted from our system unless we are required by law to retain them longer.
Data Storage & Data Transfer
IP addresses are an essential component of the Internet. Every request made to a server includes the IP address of the visitor.
For visitor-facing components of CannaSmack, such as the CannaSmack Consent Management platform, all personal data are stored exclusively in Dublin, Ireland, in compliance with GDPR.
The CannaSmack website and platform were not developed or intended for individuals under the age of 18 and we do not knowingly collect information from children under the age of 18 years old. If you provide your information to us through a request form or any part of our platform you represent to us that you are at least 18 years old. If you learn that your child has provided us with personal information without your consent, you may alert us at firstname.lastname@example.org, and we will promptly take steps to delete such information.
“Do Not Track” and Global Privacy Control
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. DNT is a way for users to inform websites and services that they do not want certain information about their webpage visits collected over time and across websites or online services. Please note that we do not respond to or honor DNT signals.
Global Privacy Control is a browser setting that allows you to notify websites you visit about your privacy preferences. We honor website visitors’ Global Privacy Control signals.
- You can opt out of receiving certain marketing or promotional communications from CannaSmack at any time by using the unsubscribe link in the email communications we send.
- You can also manage your privacy preferences with us anytime by clicking the cookie icon on our website.
- If you would like to request access, review, update, rectify, or delete any personal information we have about you, you can contact us here. Our privacy team will respond as soon as possible. Rights available under the GDPR are described in our GDPR statement.
- California residents have the rights described below. California residents can exercise this right by submitting a written request here.
California Privacy Rights under the CCPA
The California Consumer Privacy Act of 2018 (“CCPA”) took effect on January 1, 2020, and provides California consumers with certain rights regarding their personal information.
The section “What Information We Collect and How We Collect It” explains the specific details of the personal information CannaSmack collects. The CCPA also requires listing categories of personal information collected. As defined by the CCPA, we collect, or have collected in the past 12 months, the following categories of personal information:
- Identifiers (such as name, email address, postal address, phone number, and IP address)
- Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) (such as name, contact information)
- Commercial information (such as transaction information, purchase history, payment information)
- Internet or other electronic network activity information (such as browsing history, search history, online behavior)
- Professional or employment-related information (such as job title and your business contact information)
- Inference data about you (such as additional features we think would be of interest to you)
Personal information, as defined by the CCPA, does not include publicly available information from government records and de-identified or aggregated consumer information.
We use and disclose the categories of personal information we collect from, and about you consistent with the business purposes discussed in the section “How We Use the Information We Collect”.
The CCPA also sets forth obligations for businesses that “sell” personal information to third parties, as that term is construed under the CCPA. We do not exchange personal information with any third parties for money, and we have not “sold” (as construed by the CCPA) any personal information in the past 12 months. Going forward, we may “sell” or exchange personal information in a manner that constitutes a “sale” under CCPA to support our marketing efforts.
California residents have the ability to opt out of such sales as described below. If you are a California resident, you may have the following consumer rights under the CCPA:
- Right to request deletion of personal information. You have the right to request the deletion of your personal information we have collected from you, subject to certain conditions and limitations under the law.
- Right to Opt-Out of the sale of personal information. The CCPA provides consumers with the right to opt out of the sale of their personal information. We may share personal Information with third parties in a manner that constitutes a “sale” as defined by the CCPA. You have the right to opt out of such a “sale”.
- Right to non-discrimination for exercising consumer privacy right. We will not discriminate against you for exercising your rights under the CCPA.
To exercise any of your rights as set out above, please contact us by submitting a request at https://cannasmack.com/contact-us/ or by contacting us at CannaSmack PO Box 571381, Murray, UT 84157. You will need to verify your identity before we can fulfill your request. You can designate an authorized agent to request on your behalf. To do so, you will need to provide a written authorization or power of attorney signed by you for the agent to act on your behalf. You will still need to verify your identity with us. Note that consumers may only make a personal information request twice in a 12-month period under the CCPA. We will work to respond to your verifiable request within 45 days of receipt. Certain information may be exempt from requests under applicable law.
How to Contact Us
PO Box 571381,
Murray, UT 84157