BISTROMD® Privacy policy

Effective Date: June 7, 2023

This Privacy Policy applies to information obtained through your use of www.bistromd.com and any other website, or digital service on or to which this Privacy Policy is linked (together, the “Website”). This Privacy Policy also applies to our data collection practices conducted offline. Please review this Policy carefully.

Changes to this Privacy Policy

The Effective Date of this Privacy Policy is set forth at the top of this webpage. As business needs change, we will review our data practices and we may amend this Privacy Policy as appropriate. The amended Privacy Policy supersedes all previous versions. We encourage you to visit this page periodically to learn of any updates.

Information Collected

The information we collect about you depends on your interactions and engagement with us and our advertisements across the Internet.

We may collect the following types of information when you register with the Website, order from us, or otherwise interact with the Website or provide the information to us:

  1. Your name, email address, telephone number, or postal address.
  2. Payment card or other billing information.
  3. Demographic information, such as your gender, height, weight, or birth date.
  4. Information about your order history and other purchase records.
  5. Information about how you use the Website.
  6. The content of various interactions you have with us, including recordings of telephone conversations, email communications, and chat logs.
  7. Other information about you that is provided by third parties and through interactions on social media.

When using our Website, you may voluntarily provide information about yourself or others you purchase items for. We may also collect information through your submissions. For instance, when you complete a survey, make a purchase, subscribe to our publication(s), or register for any portion of our services.

We (and other entities) also automatically collect some information relating to your interactions with us and our Website, including browser type, IP address, pages visited and other activities on the Website, device type, and time and date of visit, and other information we collect through the use of cookies and similar technology, including inferences based on information we collect. In particular, we use session replay and similar technology to record and better understand your interactions on the Website. See the “Digital Advertising & Analytics” section of this privacy policy to learn more about the use of this information and the choices available to you.

We may combine any of the information we collect about you together. Information about your use of bistroMD products and services may be aggregated or otherwise de-identified. BistroMD reserves the right to use and share de-identified or aggregated information without limitation.

Use of Information

We may use information about you for any lawful purpose including the purposes described in this Privacy Policy. For example, we may use information about you:

  1. To create and administer your Account;
  2. To create a shopping cart and/or process and fulfill your orders placed with bistroMD;
  3. To contact you, for example, if there is an issue with any orders placed through the Website;
  4. To send you email, mobile text communications, and/or newsletters or other information you have requested;
  5. To send updates to you about bistroMD, its services, listing, special offers, or information that may be of interest to you.
  6. To respond to questions or other requests;
  7. To contact you with respect to your use of the Website or changes to this Privacy Policy or other bistroMD policies;
  8. To provide, personalize, and improve the Website, including diagnosing problems and debugging the Website or conducting analytics;
  9. To manage your contact preferences and requests;
  10. To conduct market research and product development;
  11. To advertise and market our products and services, as well as products and services of third parties we think may interest you;
  12. To use for our internal business purposes;
  13. To comply with applicable laws and regulations;
  14. To evaluate or conduct a corporate transaction;
  15. To protect against fraudulent or illegal activity and to maintain the security of the Website; and
  16. With your consent, or as otherwise disclosed at the time information is collected.

Disclosure of Information

We may disclose information about you for the following reasons and to the following categories of third parties:

  1. With your consent or as otherwise disclosed at the time of data collection or sharing.
  2. With our affiliated entities and other parts of our corporate family.
  3. To our vendors. We may disclose information about you to third-party vendors that support our operations and process information on our behalf, such as internet service providers, data analytics providers, external consultants, advertising networks, operating systems and platforms, and vendors that facilitate payment.
  4. With third party advertising partners to advertise our own products and services, and to advertise other products and services that you may be interested in. We, and other third parties, may reach out to you through other channels, such as, but not limited to, email and/or direct mail.
  5. As we believe to be necessary and appropriate. We may also disclose information about you: (i) as permitted by law; (ii) if we determine that the disclosure of specific information is necessary to comply with the request of a law enforcement or regulatory agency or other legal process; (iii) to protect the legitimate rights, privacy, property, interests or safety of our company or our affiliated entities, customers, business partners, employees or the general public; (iv) to pursue available remedies or limit damages; (v) to enforce our Terms and Conditions of Use; and (vi) to respond to an emergency.
  6. In relation to a corporate transaction. We may disclose and transfer information about you if we are involved in a merger, sale, acquisition, divestiture, restructuring, reorganization, dissolution, bankruptcy, or other change of ownership or control (whether in whole or in part), including negotiation and diligence of such transaction.

The Website may offer interactive features, such as the ability to leave reviews or testimonials, that you can use to communicate with other Website visitors or to submit and post your own content. If you disclose information in one of these forums, this information can be viewed, collected, and used by others.

Digital Advertising & Analytics

We may partner with ad networks and other ad serving providers (“Advertising Providers”) that serve ads on behalf of us and others on non-affiliated platforms. Some of those ads may be personalized, meaning that they are intended to be relevant to you based on information Advertising Providers collect about your use of the Website and other sites or apps over time, including information about relationships among different browsers and devices. This type of advertising is also known as interest-based advertising.

You may visit the DAA Webchoices tool at www.aboutads.info/choices to learn more about this type of advertising and how to opt out of this advertising on this browser by companies participating in the DAA self-regulatory program. You can also exercise choices regarding interest-based advertising on your mobile device by downloading the appropriate version of the DAA’s AppChoices tool at https://youradchoices.com/appchoices.

If you delete your cookies, use a different browsers or mobile device, or reset your identifiers you may need to renew your opt-out choices. Note that electing to opt out will not stop advertising from appearing in your browser or applications. It may make the ads you see less relevant to your interests.

We may also work with third parties that collect data about your use of the Website and other sites or apps over time for non-advertising purposes. BistroMD uses Google Analytics and other third-party services to improve the performance of the Website and for analytics and marketing purposes. For more information about how Google Analytics collects and uses data when you use our Website, visit www.google.com/policies/privacy/partners, and to opt out of Google Analytics, visit tools.google.com/dlpage/gaoptout.

Additionally, your browser may offer tools to limit the use of cookies or to delete cookies; however, if you use these tools, our website may not function as intended.

Linked Web Sites

Our Website includes links or offers access to other websites, apps, or services operated and maintained by third-party companies. We have no responsibility for those websites and services, and provide this access solely for the convenience and information of our visitors.

The Website also includes integrated social media tools or “plug-ins,” such as social networking tools offered by third parties. If you use these tools to share personal information or you otherwise interact with these features on the Website, those companies may collect information about you and may use and share such information in accordance with your account settings, including by sharing such information with the general public.

Your interactions with third-party companies, websites, and services, and your use of their features are governed by the privacy policies of the companies that provide those features. We encourage you to carefully read the privacy policies of any accounts you create and use. bistroMD is not responsible for the privacy policies of other sites.

Children

This Website is not directed to or intended for use by minors.

Changes to Information

Please notify us of changes to your name, address, title, phone number or email address. You may correct information about you or select the option not to receive future contacts from bistroMD (for example, mailings, calls, etc.) by emailing us at CustomerService@BistroMD.com.

U.S. STATE PRIVACY RIGHTS

Rights and Choices for Select U.S. State Residents

This section contains disclosures required by the laws in California and Virginia (“Certain States”). If you are a resident of such states, this section of the Privacy Policy contains disclosures required by law and explains rights that may be available to you. Our use of the terms “sell” and “share” below generally refers to definitions under the California law. Consumers with disabilities may access this notice by utilizing standard screen readers.

Personal Information We Collect and Disclose

We collect the categories of personal information identified in the chart below. As further set forth in the chart below, in the past 12 months, we have disclosed and sold or shared personal information about Certain State residents to third parties for business or commercial purposes.

Categories of Personal Information: Categories of Sources From Which Information Is Collected: Business or commercial purposes for collection, use, and sharing: Disclosed for business purposes to the following categories of third parties: Sold to the following categories of third parties:
Personal identifiers (such as first and last name, email address) Consumers; Our service providers Marketing; Auditing; Legal compliance; targeted advertising; Detecting and protecting against security incidents, fraud, and illegal activity; Performing services (for us or our service provider) such as account servicing or processing orders and payments; and Other one-time uses. Our affiliates; Our business partners; Our service providers. Advertising companies and networks
Online identifiers (such as unique online identifiers) Consumers; Our affiliates and joint venture partners; Our business partners; Our service providers; Advertising companies and networks Advertising; Targeted advertising; Marketing; Auditing; Data analytics and insights; Measurement; Attribution; Reporting and fraud prevention; Legal compliance; Detecting and protecting against security incidents, fraud, and illegal activity; Debugging; Performing services (for us or our service provider) such as account servicing or processing orders and payments; Internal research for technological improvement; Internal operations; Activities to develop, maintain and improve our products and services; and Other one-time uses. Our affiliates; Our business partners; Our service providers. Advertising companies and networks
Recordkeeping information (such as billing or shipping addresses) Consumers; Our affiliates and joint venture partners; Our business partners; Our service providers; Advertising companies and networks Auditing; Legal compliance; Detecting and protecting against security incidents, fraud, and illegal activity; Performing services (for us or our service provider) such as account servicing or processing orders and payments; and Other one-time uses. Our affiliates; Our business partners; Our service providers.
Characteristics of protected classifications under relevant law (such as gender) Consumers; Our service providers Advertising; Targeted advertising; Data analytics and insights; Reporting and fraud prevention; Legal compliance; Detecting and protecting against security incidents, fraud, and illegal activity; Debugging; Performing services (for us or our service provider) such as account servicing, processing orders and payments; Internal research for technological improvement; Internal operations; Activities to develop, maintain and improve our products and services; and Other one-time uses. Our affiliates; Our business partners; Our service providers.
Commercial information (such as records of products or services purchased) Consumers; Our service providers Advertising; Targeted advertising; Data analytics and insights; Measurement; Attribution; Reporting and fraud prevention; Legal compliance; Detecting and protecting against security incidents, fraud, and illegal activity; Debugging; Performing services (for us or our service provider) such as account servicing, processing orders and payments; Internal research for technological improvement; Internal operations; Activities to develop, maintain and improve our products and services; and Other one-time uses. Our affiliates; Our business partners; Our service providers. Advertising companies and networks
Internet or other electronic network activity information (such as browsing history, search history, interactions with a website, email, application, or advertisement) Consumers; Service providers; Advertising; Targeted advertising; Data analytics and insights; Measurement; Attribution; Reporting and fraud prevention; Legal compliance; Detecting and protecting against security incidents, fraud, and illegal activity; Debugging; Performing services (for us or our service provider) such as account servicing, processing orders and payments; Internal research for technological improvement; Internal operations; Activities to develop, maintain and improve our products and services; and Other one-time uses. Our affiliates; Our business partners; Our service providers. Advertising companies and networks
Sensory data (such as audio recordings of our telephone calls with you) Consumers; Our service providers Data analytics and insights; Reporting and fraud prevention; Legal compliance; Detecting and protecting against security incidents, fraud, and illegal activity; Performing services (for us or our service provider) such as account servicing, processing orders and payments; Internal research for technological improvement; Internal operations; Activities to develop, maintain and improve our products and services; and Other one-time uses. Our affiliates; Our business partners; Our service providers. N/A
Inferences drawn from the above information about your predicted characteristics and preferences Consumers; Our affiliates and joint venture partners; Our business partners; Our service providers; Advertising companies and networks Advertising services and advertising products; Targeted advertising; Data analytics and insights; Measurement; Attribution; Reporting and fraud prevention; Legal compliance; Detecting and protecting against security incidents, fraud, and illegal activity; Debugging; Performing services (for us or our service provider) such as account servicing, processing orders and payments; Internal research for technological improvement; Internal operations; Activities to develop, maintain and improve our products and services; and Other one-time uses. Our affiliates; Our business partners; Our service providers. Advertising companies and networks
Potentially sensitive information (such as dietary information) Consumers; Our service providers Data analytics and insights; targeted advertising; Legal compliance; Detecting and protecting against security incidents, fraud, and illegal activity; Performing services (for us or our service provider) such as account servicing, processing orders and payments; Internal research for technological improvement; Internal operations; Activities to develop, maintain and improve our products and services; and Other one-time uses. Our affiliates; Our business partners; Our service providers. Advertising companies and networks
Other information about you that is linked to the personal information above Consumers; Our affiliates and joint venture partners; Our business partners; Our service providers; Advertising companies and networks Advertising services and advertising products; Targeted advertising; Data analytics and insights; Measurement; Attribution; Reporting and fraud prevention; Legal compliance; Detecting and protecting against security incidents, fraud, and illegal activity; Debugging; Performing services (for us or our service provider) such as account servicing, processing orders and payments; Internal research for technological improvement; Internal operations; Activities to develop, maintain and improve our products and services; and Other one-time uses. Our affiliates; Our business partners; Our service providers. Advertising companies and networks
Employee and job applicant data, which may include the categories of personal information listed above that are collected during the job application process and while individuals are bistroMD employees Consumers; Our affiliates and joint venture partners; Our business partners; Our service providers Processing your application.

Using your information in connection with your employment roles and responsibilities. This includes, for example:

·Providing you with services and tools to use in connection with your employment, such as email service and information technologies;

·Responding to your requests;

·Maintaining compliance with our policies and procedures;

·Paying you and administering your employment benefits, including those provided to other individuals like family members; and

·Responding to emergencies or safety concerns, such as by maintaining and using your emergency contact information.

Other business purposes as identified in the CCPA, which include:

·Auditing related to our interactions with you;

·Legal compliance;

·Detecting and protecting against security incidents, fraud, and illegal activity;

·Debugging;

·Performing services (for us or our service provider) such as account servicing, processing orders and payments, and analytics;

·Internal research for technological improvement;

·Internal operations;

·Activities to maintain and improve our business; and

·Other one-time uses.
N/A N/A

We may use and share aggregated and de-identified information to the extent permitted by applicable law. When we use de-identified information, we maintain and use the information in de-identified form and do not attempt to re-identify it, except to check whether our de-identification processes satisfy the requirements of applicable law.

Data Retention

We will retain each category of personal information we collect in accordance with applicable laws and as reasonably necessary for our processing purposes set out under this Privacy Policy. When it is no longer necessary to process personal information for these purposes, we will deidentify, aggregate, or delete this data to the extent possible.

Rights Regarding Personal Information

Residents of Certain States have rights with respect to the personal information collected by bistroMD. You may be able exercise the following rights regarding personal information, subject to certain exceptions and limitations:

  • The right to confirm whether we are processing personal information about you.
  • The right to know the categories and specific pieces of personal information we collect, use, disclose, and sell about you; the categories of sources from which we collected personal information about you; our purposes for collecting or selling personal information about you; the categories of personal information about you that we have sold or disclosed for a business purpose; and the categories of third parties with which we have shared personal information.
  • Depending on your state, the right to receive a portable and readily usable copy of the personal information we have collected about you, to the extent feasible.
  • The right to correct inaccuracies in the personal information we have collected about you.
  • The right to request that we delete the personal information we have collected about you.
  • The right to opt out of (i) the sharing of personal information for targeted advertising; (ii) the sale of personal information; or (iii) profiling for decisions that have significant effects. Please note that if you opt out of certain practices, we may be unable to provide you with some services. Additionally, we do not knowingly sell or share personal data of individuals under 16.
  • Choice regarding sensitive information. Depending on your state, you can
    • Limit our processing of certain “sensitive” personal information; We do not use or disclose sensitive personal information for purposes other than as permitted under the California privacy law.
    • Opt out of our processing of certain “sensitive” information; or
    • Withdraw consent for such processing if you previously gave it.
  • The right not to receive discriminatory treatment for the exercise of the above privacy rights.

Exercising Privacy Rights

To exercise the privacy rights described above, please submit a verifiable consumer request:

If allowed by your state law, you or a person that you authorize to act on your behalf, may make a verifiable consumer request related to personal information about you.

The verifiable consumer request must provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information about or an authorized representative. Our processes for verifying requests include matching identifying information that we already have on record to provide services to the customers. Otherwise, we may need to request additional information from you to verify your identity or understand the scope of your request. We will require you to provide, at a minimum, basic contact information, such as your name, email address and phone number.

Additionally, if your state law allows, if you have submitted a request that we have not reasonably fulfilled, you may contact us to appeal our decision by sending an email with the subject line “Appeal” to CustomerService@BistroMD.com.

Contact

If you have other concerns or questions about any aspect of this Privacy Policy, you may email us at CustomerService@BistroMD.com.