Galls' Privacy Policy
Last Updated: June 30, 2023.
This Privacy Policy explains what information may be collected when you access this website, our agency or business specific websites, or any other website where we place this Privacy Policy ("Website") when you use any of our mobile, text, or other applications ("Applications"), or when you provide us with information in our stores, over the telephone, via mail or email, though promotions, by requesting our email newsletters, or via other communication channels ("Communications"). Depending on your activities when using or accessing our Website, Applications, or Communications (collectively, "Services"), you may from time-to-time be required to agree to additional terms and conditions. Please note that this Privacy Policy applies regardless of whether you use our Services via a computer, mobile device, or any other platform (collectively, your "Equipment").
A. INFORMATION WE COLLECT
(1) Personally Identifiable Information: We collect only personally identifiable information that you provide us, such as your name, mail address, telephone number, email address, shipping and billing information (e.g. credit card number and expiration date), demographic history, past purchase history, and any other information that you may voluntarily provide.
(2) Non-Personally Identifiable Information: We also collect and record non-personally identifiable information, which is information that does not personally identify you. This information can include, among other things, the types of products ordered on the site, information on how many visits each page receives, user-specific information on what pages on the site were visited and for how long, the third party website from which your visit originated, and the page you visited after visiting our site. This also includes certain types of technical information such as your Internet protocol (IP) address, your mobile device, your wireless carrier, the type and version of browser you are using, the operating system you are using, the domain name of your Internet service provider, the search terms you use, how much you use our Services, download errors, page response times, and technical interaction information regarding scrolling, clicks, and other methods used to browse the site's pages.
B. HOW WE USE AND SHARE THE INFORMATION COLLECTED
(1) Personally Identifiable Information: The personally identifiable information you submit to us is generally used to carry out your requests, respond to your inquiries, better serve you, modify areas that need to be improved upon, and customize your shopping experience. We may also use this information to later contact you for a variety of reasons, such as customer service, providing you promotional information for special offers or our products or for those of our parent company, subsidiaries, or other affiliated companies ("Affiliated Companies"), or to communicate with you about content or other information you have posted or shared with us via use of our Services. We may also use the information provided for billing and shipping purposes, for internal business and marketing purposes, and to monitor security. You may opt-out from receiving future promotional information from us or our Affiliated Companies, or direct that we not share your information with any Affiliated Companies, as set forth below.
In certain instances we may also share your personally identifiable information with third parties performing functions on our behalf (or on behalf of our Affiliated Companies). These functions may include but are not limited to directly or indirectly collecting your personally identifiable information, operating our website store/shop, processing credit card orders, delivering packages, administering our promotions, providing us marketing or promotional assistance, analyzing our data, generating and revising customer lists, and assisting us with customer service. In addition, we may share your personally identifiable information with participating sponsors or co-promotional partners to a program or promotion (e.g., a sweepstakes or contest) you enter via our Services and others with whom we have marketing or other relationships, including marketing cooperatives. Finally, we may share and/or use your personally identifiable information as disclosed by you at the time you provide us your personally identifiable information. Except as provided in this Privacy Policy or in our Terms of Use, your personally identifiable information will not be shared or sold to any third parties without your prior approval.
(2) Non-Personally Identifiable Information: We may use your non-personally identifiable information to evaluate use of and improve our Services, for internal business or marketing purposes, or for any other business purpose. We may use your non-personally identifiable information by itself or aggregate it with information we have obtained from other customers or sources. We may, among other things, share your non-personally identifiable information with our Affiliated Companies or allow third parties to collect such information from you.
C. COOKIES AND PREFERENCE BASED ADVERTISING
(1) Cookies and Web Beacons: We automatically receive and store certain types of non-personally identifiable information whenever you interact with us. For example, like many websites, we use "cookies" and "web beacons" to obtain certain types of information when your web browser or Equipment accesses our Website. "Cookies" are small files that we transfer to your Equipment's hard drive, memory, or web browser to enable our systems to recognize you and to provide convenience, customization, and other features to you. If you are concerned about the storage and use of cookies, you may be able to block or limit the storage of cookies via browser controls or other software. Please note, we do not promise that our Services will recognize or be able to work with any such browser controls or software. "Web beacons" are tiny graphics with a unique identifier, similar in function to cookies, and may be used to track the online movements of users, when an email has been opened, and to provide other information.
(2) Do Not Track Features: Certain browsers may offer you the option of providing notice to websites that you do not wish for your online activities to be tracked for preference based advertising purposes ("DNT Notice"). For a variety of other reasons, we do not take any action based on browser based DNT Notices.
D. OTHER USES AND INFORMATION
(1) Email Communications: If you send us an email with questions or comments, we may use your personally identifiable information to respond to your questions or comments, and we may save your questions or comments for future reference. For security reasons, we do not recommend that you send non-public personal information, such as passwords, social security numbers, or bank account information, to us by email. You may "opt out" of receiving future commercial email communications from us by clicking the "unsubscribe" link included at the bottom of most emails we send, or as provided below; provided, however, we reserve the right to send you transactional emails such as customer service communications.
(2) Transfer of Assets: As we continue to develop our business, we may sell or purchase assets. If another entity acquires us or all (or substantially all) of our assets, the personally identifiable information and non-personally identifiable information we have about you will be transferred to and used by this acquiring entity, though we will take reasonable steps to ensure that your preferences are followed. Also, if any bankruptcy or reorganization proceeding is brought by or against us, all such information may be considered an asset of ours and as such may be sold or transferred to third parties.
(3) Other: Regardless of any other provision in this Privacy Policy, we reserve the right to disclose any personally identifiable or non-personally identifiable information about you to: (a) fulfill a government request; (b) conform with the requirements of the law or legal process; (c) protect or defend our legal rights or property, our Services, or other users; or (d) protect, in an emergency, the health and safety of our customers or the general public. This includes exchanging information with third parties and organizations in connection with credit risk reduction and fraud protection.
E. PUBLIC FORUMS AND LINKS
We may offer chat rooms, blogs, message boards, bulletin boards, or similar public forums where you and other users of our Services can communicate. The protections described in this Privacy Policy do not apply when you provide information (including personally identifiable information) in connection with your use of these public forums. We may use personally identifiable and non-personally identifiable information about you to identify you with a posting in a public forum. Any information you share in a public forum is public information and may be seen or collected by anyone, including third parties that do not adhere to our Privacy Policy. We are not responsible for events arising from the distribution of any information you choose to publicly post or share through public forums.
F. CHILDREN
The features, programs, promotions, and other aspects of our Services requiring the submission of personally identifiable information are not intended for children. We do not knowingly collect personally identifiable information from children under the age of 13. If you are a parent or guardian of a child under the age of 13 and believe he or she has disclosed personally identifiable information to us, please contact us as described below.
G. KEEPING YOUR INFORMATION SECURE
We have implemented security measures we consider reasonable and appropriate to protect against the loss, misuse, and alteration of the information under our control. Such measures include authentication of our web servers by VeriSign, Secure Socket Layer (SSL) security software that encrypts your credit card and other sensitive information, industry standard firewall and anti-virus protection, maintenance of vendor security patches, and third party security scanning to assure we are up to widely accepted industry standards.
Please be advised, however, that while we strive to protect your personally identifiable information and privacy, we cannot guarantee or warrant the security of any information you disclose or transmit to us online or through our Services, and are not responsible for the theft, destruction, or inadvertent disclosure of your personally identifiable information. In the unfortunate event that your personally identifiable information is compromised, we may notify you by email (at our sole and absolute discretion) to the last email address you have provided us in the most expedient time reasonable under the circumstances; provided, however, delays in notification may occur while we take necessary measures to determine the scope of the breach and restore reasonable integrity to the system as well as for the legitimate needs of law enforcement if notification would impede a criminal investigation. If you have any questions or concerns about the security of our Services, please email us at help-desk@galls.com.
H. OTHER SITES/LINKS
Our Services may link to or contain links to other third party websites that we do not control or maintain, such as in connection with purchasing products we may recommend or reference via our Services and/or advertisements you may see while using our Services. We are not responsible for the privacy practices employed by any third party website, and we encourage you to read the privacy statements of all third party websites before submitting any personally identifiable information through these websites.
I. CONTACT AND OPT-OUT INFORMATION
You may contact us as at help-desk@galls.com if you: (a) have questions or comments about our Privacy Policy; (b) wish to make corrections to any personally identifiable information you have provided or that a child under the age of 13 for whom you are the parent or guardian may have provided; (c) want to opt-out from receiving future commercial correspondence, including emails, from us or our Affiliated Companies; or (d) wish to withdraw your consent to sharing your personally identifiable information with third parties. You may also call us at 866.673.7643 or write to us at 1340 Russell Cave Road, Lexington, KY 40505. You can also click on "My Account" on our homepage to view or update your personal information.
When contacting us, please include your name, address, city, state, zip code, and phone number to ensure we can process the request. We will process your request promptly, but please note that you may receive additional contacts before your name removal or change takes effect. We also may not be able to fulfill some requests while allowing you access to certain benefits and features of our Services. We apologize for any inconvenience this may cause.
J. CALIFORNIA PRIVACY RIGHTS.
The following explains your rights pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (collectively, “the Act”).
CONSUMERS
Scope
This Privacy Policy explains how Company collects, uses and discloses Personal Information that we collect from individuals who are residents of California, including but not limited to users who visit our websites or consumers who receive services directly from Company. This Privacy Policy does not apply to Job Applicants or HR Individuals, as that term is defined in the Act. Information for those groups can be found at the end of this policy.
For purposes of this Privacy Policy, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer.
Collection, Disclosure, and Sharing of Personal Information
The following details which categories of Personal Information we collect and process, which categories of third parties may have access to your Personal Information for operational business purposes, as well as which categories of Personal Information we “share” for purposes of cross-context behavioral advertising, including within the 12 months preceding the date this Privacy Policy was last updated.
Sources of Personal Information
We collect this Personal Information actively (e.g., direct input from individual) or passively (e.g., website cookies) from you. Additionally, we may also collect Personal Information from third-party sources, such as our affiliates, business partners, and service providers, listed below where applicable.
No Sales of Personal Information
Company does not sell your Personal Information for cross-context behavioral advertising or any other purposes.
Purposes for the Collection, Use and Sharing of Personal Information
Company uses your Personal Information for the following Business Purposes and objectives:
Categories of Personal Information | Disclosed to Which Categories of Third Parties for Operational Business Purposes (see below for a more detailed description of these categories) | Shared with Which Categories of Third Parties for Cross-Context Behavioral Advertising |
---|---|---|
Identifiers, such as name, contact information, unique personal identifiers, email address, IP address, online identifiers, government-issued identifiers. | Service Providers/Subcontractors, Related Entities, Law enforcement/Legal authorities, Third Parties in the event of a Corporate Transaction, with your consent. | Ad networks. |
Personal information as defined in the California customer records law, such as name, contact information, financial, education, employment information. | Service Providers/Subcontractors, Related Entities, Law enforcement/Legal authorities, Third Parties in the event of a Corporate Transaction, With Your Consent. | None. |
Characteristics of protected classifications under California or federal law, such as race, religious creed, color, national origin, ancestry, physical disability, mental disability, medical condition, marital status, sex, gender expression, gender identify, age, sexual orientation, military or veteran status. | Service Providers/Subcontractors, Related Entities, Law enforcement/Legal authorities, Third Parties in the event of a Corporate Transaction, With Your Consent. | None. |
Commercial Information, such as transaction information and purchase history, including purchases considered, consuming histories or tendencies. | Service Providers/Subcontractors, Related Entities, Law enforcement/Legal authorities, Third Parties in the event of a Corporate Transaction, With Your Consent. | Ad Networks. |
Biometric Information, such as fingerprints, voiceprints and faceprints. | Not Applicable. | Not Applicable. |
Internet or network activity information, such as IP address, mobile device ids, MAC address, browsing history, search history. | Service Providers/Subcontractors, Related Entities, Law enforcement/Legal authorities, Third Parties in the event of a Corporate Transaction, With Your Consent. | Ad networks. |
Geolocation Data, such as precise location/tracking data and coarse location/tracking data. | Service Providers/Subcontractors, Related Entities, Law enforcement/Legal authorities, Third Parties in the event of a Corporate Transaction, With Your Consent. | None. |
Audio/Video Data, such as photographs. | Service Providers/Subcontractors, Related Entities, Law enforcement/Legal authorities, Third Parties in the event of a Corporate Transaction, With Your Consent. | None. |
Education Information subject to the federal Family Educational Rights and Privacy Act such as education and training history, education degrees, qualifications/certifications. | Service Providers/Subcontractors, Related Entities, Law enforcement/Legal authorities, Third Parties in the event of a Corporate Transaction, With Your Consent. | None. |
Employment Information. Professional or employment-related information, such as professional or employment related information such as work history and prior employer, background checks, performance rating or feedback, employer, occupation title/job role. | Service Providers/Subcontractors, Related Entities, Law enforcement/Legal authorities, Third Parties in the event of a Corporate Transaction, With Your Consent. | None. |
Sensitive Personal Information, such as social security, driver’s license, state identification card, or passport number; account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; citizenship, immigration status, union membership. (Note: Generally, this information is only collected and retained in order to verify that you are legally authorized to purchase certain products). | Service Providers/Subcontractors, Related Entities, Law enforcement/Legal authorities, Third Parties in the event of a Corporate Transaction, With Your Consent. | None. |
Detailed Description of Categories of Third Parties
Third Parties that Company may disclose your Personal Information to are as follows:
-
Service Providers/Subcontractors
Company may share your Personal Information with our subcontractors for certain business purposes. This information is provided in order for them to provide Company with services such as payment processing, advertising services, marketing partners, web analytics, data processing, IT services, customer support and other services such as for the purpose of auditing and fraud investigations.
-
Related Entities
Company may share Personal Information between and among Company, its subsidiaries, and affiliated companies for purposes of management and analysis, and other business purposes. For instances, Company may share your Personal Information with our subsidiaries and affiliated companies to expand and promote our product and service offerings.
-
Law Enforcement/Legal Authorities
Company may be required to disclose your Personal Information to third parties including law enforcement agencies when required to protect and defend our legal rights, protect the safety and security of users of our Services, prevent fraud, respond to legal process, or a request for cooperation by a government entity, as required by law.
-
Corporate Transactions
In the event of sale, transfer, merger, reorganization, or similar event, Company may transfer your Personal Information to one or more third parties as part of that transaction with the business entities or people involved in the deal negotiation or transfer.
-
With Your Consent
Company may share Personal Information about you with other third-party companies if you give us permission or direct us to share the information. Company will share Personal Information with authorized agents with whom you authorize Company to communicate.
We do not sell and have not sold Personal Information, including your Sensitive Personal Information. Without limiting the foregoing, we do not sell the Personal Information, including the Sensitive Personal Information, of minors under 16 years of age. We do not knowingly “share” the Personal Information, including the Sensitive Personal Information, of minors under 16 years of age.
Sources of Personal Information
We collect this Personal Information actively (e.g., direct input from individual) or passively (e.g., website cookies) from you. Additionally, we may also collect Personal Information from third-party sources, such as our affiliates, business partners, and service providers.
Purposes for the Collection, Use and Sharing of Personal Information
Company uses your Personal Information for the following Business Purposes and objectives:
-
Business Purposes for processing Personal Information pertaining to consumers. Personal Information pertaining to consumers with whom Company has a business relationship may be processed as needed:
- To provide the information, product, or service requested by the individual, and as would be reasonably expected by the individual given the context in which the Personal Information was collected, and the information provided in the applicable Privacy Policy given to the individual (such as for personalization, remembering preferences, or respecting individual rights);
- For due diligence, including verifying the identity of the individual, as well as the eligibility of the individual to receive information, products, or services (such as verifying age, employment, or account status);
- To send transactional communications (such as requests for information, responses to requests for information, orders, confirmations, training materials, and service updates);
- To manage the individual's account, such as for customer service, finance, and dispute resolution purposes;
- For risk management and mitigation, including for audit and insurance functions, and as needed to license and protect intellectual property and other assets;
- For security management, including monitoring individuals with access to the website; applications, systems, or facilities, investigation of threats, and as needed for any data security breach notification; and
- To anonymize or de-identify the Personal Information. Where we maintain or use de-identified information, we will continue to maintain and use such information only in a de-identified fashion and will not attempt to re-identify such information.
- Business-necessary processing activities. Company may process Personal Information as needed (i) to protect the privacy and security of the Personal Information it maintains, such as in connection with advanced security initiatives and threat detection; (ii) for treasury operations and money movement activities; (iii) for compliance functions, including screening individuals against sanction lists in connection with anti-money laundering programs; (iv) for business structuring activities, including mergers, acquisitions, and divestitures; and (v) for business activities, management reporting, and analysis.
- Development and improvement of products and/or services. Company may process Personal Information to develop and improve its products and/or services, and for research, development, analytics, and business intelligence.
- Relationship management and marketing. Company may process Personal Information for relationship management and marketing. This purpose includes sending marketing and promotional communications to individuals who have not objected to receiving such messages, such as product and service marketing communications, investor communications, customer communications (e.g., sale notifications, product updates, and invitations to Company events), customer satisfaction surveys, supplier communications, corporate communications, and Company news.
- Operational purposes. Additionally, Company uses your Personal Information for purposes such as: (i) disaster recovery and business continuity; (ii) internal audits or investigations; (iii) implementation or verification of business controls; (iv) statistical, historical, or scientific research; (v) dispute resolution; (vi) legal or business counseling; (vii) compliance with laws and company policies; and/or (viii) insurance purposes.
Purposes for the Collection and Use of Sensitive Personal Information
Subject to your consent where required by applicable law, we may use Sensitive Personal Information for purposes of performing services for our business, providing goods or services as requested by you, ensuring security and integrity, short term transient use such as displaying first party, non-personalized advertising, servicing accounts, providing customer service, verifying customer information, processing payments, and activities relating to quality or product improvement.
Retention Period
We retain Personal Information for as long as needed or permitted in light of the purpose(s) for which it was collected. The criteria used to determine our retention periods include:
-
The length of time we have an ongoing relationship with you and provide products or services to you (for example, for as long as you have an account with us or keep purchasing our product or services) and the length of time thereafter during which we may have a legitimate need to reference your Personal Information to address issues that may arise;
-
Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them); or
-
Whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation or regulatory investigations).
California Privacy Rights
If you are a California resident you may make the following requests, subject to applicable law:
-
Right to Access and Know -- You may request that we disclose to you the following information covering the 12 months preceding your request:
- The categories of Personal Information we collected about you and the categories of sources from which we collected such Personal Information;
- The specific pieces of Personal Information we collected about you;
- The business or commercial purpose for collecting or sharing Personal Information about you;
- The categories of Personal Information about you that we shared (as defined under the applicable privacy law) and the categories of third parties with whom we shared such Personal Information; and
- The categories of Personal Information about you that we otherwise disclosed, and the categories of third parties to whom we disclosed such Personal Information (if applicable).
- Please note that the Act’s right to obtain “specific pieces” does not grant a right to the whole of any document that contains personal information but only to items of personal information. Moreover, you have a right to know categories of sources of personal information and categories of third parties to which personal information is disclosed but not the individual sources or third parties. Company does not always track individualized sources or recipients.
- Right to Request Correction of Your Personal Information -- You may request to correct inaccuracies in your Personal Information;
- Right to Request Deletion of Your Personal Information -- You may request to have your Personal Information deleted; and
- Right to Opt-out of Sharing for Cross-Context Behavioral Advertising -- You may request to opt out of the “sharing” of your Personal Information for purposes of cross-context behavioral advertising.
We will not unlawfully discriminate against you for exercising your rights under the Act.
How to Submit a California Rights Request
Company will respond to requests to know, delete, and correct in accordance with applicable law if it can verify the identity of the individual submitting the request. You can exercise these rights in the following ways:
-
Call Company's Toll-Free Hotline: 833-896-0007
-
Smartsheet Process: https://app.smartsheet.com/b/form/c7ead225398d46d7866b6fa21b1c73f2
To request to opt out of any future sharing of your Personal Information for purposes of cross-context behavioral advertising, you may contact us as at help-desk@galls.com if you: (a) want to opt-out from receiving future commercial correspondence, including emails, from us or our Affiliated Companies; or (b) wish to withdraw your consent to sharing your personally identifiable information with third parties. You may also call us at 866.673.7643 or write to us at 1340 Russell Cave Road, Lexington, KY 40505. You can also click on "My Account" on our homepage to view or update your personal information.
When contacting us, please include your name, address, city, state, zip code, and phone number to ensure we can process the request. We will process your request promptly, but please note that you may receive additional contacts before your name removal or change takes effect. We also may not be able to fulfill some requests while allowing you access to certain benefits and features of our Services. We apologize for any inconvenience this may cause.
How Company Will Verify a California Rights Request
Company will verify and respond to your request consistent with applicable law, taking into account the type and sensitivity of the Personal Information subject to the request. Company may need to request additional Personal Information from you, such as your name and email address, in order to verify your identity and protect against fraudulent requests. If you maintain a password-protected account with us, we may verify your identity through our existing authentication practices for your account and require you to re-authenticate yourself before disclosing or deleting your Personal Information. If you make a request to delete, we may ask you to confirm your request before we delete your Personal Information.
Authorized Agents Submitting a Request on Behalf of a Consumer
You may choose to designate an authorized agent to make a request under the Act on your behalf. No information will be disclosed until the authorized agent’s authority has been reviewed and verified. Agents may be asked to provide proof of their status as an authorized agent. Once a request has been submitted by an authorized agent, we may require additional information from you to verify your identity as described in the section entitled “How to Submit a California Rights Request” or confirm that you provided the agent permission to submit the request.
Changes to This Consumer Privacy Policy
If we change this Privacy Policy, we will post those changes on this page and update the Privacy Policy modification date above.
For More Information
For questions or concerns about Company’s Consumer Privacy Policy and practices, please contact us at help-desk@galls.com.
JOB APPLICANTS
Our Applicant Notice and Privacy Policy can be found on our Career Site under Galls Privacy Policy.
HR INDIVIDUALS
To view or obtain a copy of our Notice at Collection and Privacy Policy for HR Individuals (defined in the Act as employees; non-employee individuals who perform work for the company, including but not limited to independent contractors; and the dependents, emergency contacts and beneficiaries of both employees and non-employee individuals who perform work for the company), please visit the HR Department page of the Company’s intranet site or contact humanresource@galls.com for assistance.
K. MODIFICATIONS TO THIS PRIVACY POLICY
We generally keep this Privacy Policy posted on our Website. You should review this Privacy Policy frequently, as it may change from time to time without notice. Any changes will be effective immediately upon the posting of the revised Privacy Policy. WHEN YOU USE OUR SERVICES, YOU AGREE TO THIS PRIVACY POLICY. IF YOU DO NOT AGREE TO THIS PRIVACY POLICY, OR TO ANY CHANGES WE MAY SUBSEQUENTLY MAKE, IMMEDIATELY STOP USING OUR SERVICES.