End User Privacy Policy

FYSICAL END USER PRIVACY STATEMENT

Last Modified: March 3rd,2020

GIS Operations, Inc (doing business as"Fysical", and referred to as "we" "us","our") is committed to protecting your privacy. In this Section, we describe the type of data that is collected through our Customers' apps and shared with Fysical. Apps that use Fysical may use only some of the features and information that Fysical can collect.

Capitalized terms that are not defined in this Privacy Policy have the meanings given them in the Fysical Terms of Service.

Fysical is a member of the Network Advertising Initiative (NAI) and adheres to its code(s), as applicable. The NAI is an industry leader in privacy and consumer protection practices for online advertising. The NAI has created a compliance program that incorporates attestation reviews, a consumer complaint process, and annual reporting to help ensure that member companies keep their promises to you and abide by the NAI's Self-Regulatory Code of Conduct. Click here to learn more about the NAI:http://www.networkadvertising.org/

1. End User Data

Our Service provides a technology that is installed in third-party mobile applications ("apps") belonging to our commercial customers ("Customers"), and which provides ourCustomers with real-time analytics as well as tools that can provide or enable the provision of, content, ads, offers or other marketing solutions tailored to user interests, based upon visits to participating retailers or other venues.When a Customer uses our Service, the Customer's app collects information from end users including IP addresses, location data and the data described atSection 2 ("What we collect from end users or their devices") ("End User Data") that is shared with Fysical.

2. What we collect from end users or their devices

If an end user's smartphone has downloaded an application of one of our Customers, then data may be collected about that user. Specifically, our Customers' apps can collect information from an enduser's device periodically throughout the day (using GPS), or any time the device programmed with the app comes within range of a "beacon". A"beacon" is a small Bluetooth-enabled device that may be placed in retail stores or other locations which emits a unique signal that ourCustomers' applications can detect. Fysical collects an app-specific identifier or device specific identifier that is used to identify a unique app user or device user. This identifier is associated only with the specific Customer app and can be tied to a specific mobile device. If an end user deletes theCustomer app from its device, the service will stop receiving information on that user from that app, alone. Relying on this app-specific, or device-specific advertising ID (IDFA, ADID), we collect:

  • An     app-specific identifier or device specific identifier that is used to     identify a unique app user or device user which can be tied to a specific     mobile device or Customer app;
  • All     location meta data when a user is within range of a beacon, or when a     periodic location coordinate (ie GPS) is taken, including location data     (latitude/longitude coordinates including, street address, establishment     name, touch point);
  • Times     of end user location detection;
  • Device     information, such as the device type, model and operating system version,     device language, mobile carrier, device name, device processes, device     battery state, device speed, and current IP address.

We collect location data from third party partners such as Cuebiq.

3. How data is shared

End users should consult the privacy policies of the apps which have enabled our technology to learn how ourCustomers share data collected through our app, if at all. If Fysical itself shares or publicly discloses information (e.g., in marketing materials or in application development) that is derived from End User Data, such data will be aggregated or anonymized to reasonably avoid identification of a specificCustomer, end user or individual. Any End User Data that we maintain or process we consider to be strictly confidential. We do not use or disclose End UserData except as authorized and required by our Customers and provided for in our agreements with our Customers. Each Customer will remain responsible for the privacy and security of the End User Data that it collects and processes and for compliance with applicable data protection laws that may apply to the collection, processing and disclosure of End User Data.

We may also share or transfer your personal information in the instances described below.

We may share your personal information with any future corporate subsidiaries we own or control.

We reserve the right to transfer any information we collect in the event we sell or transfer all or a portion of our business or assets (including any shares in the company) or any portion or combination of our products, services, businesses and/or assets. Should such a transaction occur (whether a divestiture, merger, acquisition, bankruptcy, dissolution, reorganization, liquidation, or similar transaction or proceeding), we will use reasonable efforts to ensure that any transferred information is treated in a manner consistent with this End User PrivacyStatement.

For further information on your choices regarding your information, see "This is an opt-in only services" below.

4. How data is used

We may collect, analyze and use End UserData and data that is derived from the End User Data, for the purposes of:

(i) providing or improving our Services;

(ii) enabling us to assist retailers and other venues in better serving and understanding the end users at a summary level; and

(iii) facilitating or enabling the delivery of content, ads, offers or other marketing solutions that may be of interest to end users.

(iv) analytics purposes and facilitating the analysis of this data

Information we collect will be deleted or made de-identified after 7 years from the date of collection.

5. This is an opt-in only service

As part of our Terms of Service, Fysical requires that its Customers: (i)inform end users about our purposes for the collection of their data; (ii)receive consent from end users prior to the commencement of the processing of the End User Data; and (iii) notify end users about how their consent can be revoked.

If end users do not want Fysical to identify their mobile device, they can: (a) delete the Customer app or adjust the in-app settings of the Customer app if the app makes that option available(this will limit data collection from this app alone); or (b) opt-out of sharing your mobile advertiser ID by limiting ad tracking on the device. For iOS, navigate to your Settings > Select Privacy > Select Advertising >Enable the "Limit Ad Tracking" setting. For Android, open your GoogleSettings app > Ads > Enable "Opt out of interest-based advertising".

For more information on specific opt-out choices, please visit: http://www.networkadvertising.org/mobile-choices

6. Storage and transfer:

Your information may be stored and processed in the United States or any other country in which Fysical or its subsidiaries, affiliates or service providers maintain facilities. If you are located in the European Union or other regions with laws governing data collection and use that may differ from U.S. law, please note that we may transfer information, including personal information, to a country and jurisdiction that does not have the same data protection laws as your jurisdiction, and you consent to the transfer of information to the U.S. or any other country in which we or our parent, subsidiaries, affiliates or service providers maintain facilities and the use and disclosure of information about you as described in this End User Privacy Statement and the Privacy Policy.

7. Children's Privacy & Age Restriction

Fysical's website and services are intended for use strictly by adults. We do not knowingly solicit or collect personal information from children under the age of 13. If we learn that any personal information has been collected from a child under 13, we will delete the information as soon as possible. If you believe that we might have collected information from a child under 13, please contact us at contact@fysical.com. You also maintain that you have the ability to suppress data on individuals under the age of 18 upon the request of Fysical.

8. Changes to End User Privacy Statement

We reserve the right to change this EndUser Privacy Statement from time to time in our sole discretion. We will post changes on this page and indicate the "last modified" date at the top of this page. Please check back often for any updates. Your continued use of our website or services after any change in this End User Privacy Statement will constitute your acceptance of such change.

9. EU-US Privacy Shield

Fysical participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework. Fysical is committed to subjecting all personal data received from the EU in reliance on the PrivacyShield Framework, to the Framework's applicable Principles, including thePrinciples of Notice, Choice, Accountability for Onward Transfer, Security,Data Integrity and Purpose Limitation, Access, Recourse, Enforcement andLiability. To learn more about the Privacy Shield Framework, visit the U.S.Department of Commerce's Privacy website at www.privacyshield.gov and to view our certification please visit the Privacy Shield List at:https://www.privacyshield.gov/list. If there is any conflict between the policies in this Privacy Policy and the Privacy Shield Principles, the PrivacyShield Principles shall govern.

Fysical's Privacy Policy, the Terms ofService, API and Data License and End User Privacy Statement describe the types of personal information Fysical collects, the uses of this information, the types of third parties to which it discloses the data and the purposes for which it does so. Residents of the EU have the right to access the personal data that Fysical maintains, and in some cases, may have the right to corrector amend any personal data that is inaccurate or has been processed in violation of the Privacy Shield Principles, to the extent allowed by law. To exercise this right, contact us at privacy@fysical.com.For information on opting out of the collection of data through beacons, please see "This is an opt-in only service" of this End User Privacy Statement.

Fysical is responsible for the processing of personal information it receives, under the Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf.Fysical complies with the Privacy Shield Principles for all onward transfers of personal data from the EU. Fysical may be liable under the Privacy ShieldPrinciples if a third party processes personal information in a way in consistent with those Principles, unless Fysical proves it is not responsible for the event giving rise to damage.

With respect to personal information received or transferred pursuant to the Privacy Shield Framework, Fysical is subject to the investigatory and enforcement powers of the Federal TradeCommission in respect of Fysical's self-certification of compliance with thePrivacy Shield framework. In certain situations, Fysical may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Fysical commits to cooperate with the panel established by the EU data protection authorities (DPAs) and to comply with the advice given by the panel with regard to personal data transferred from the EU.Residents of the EU with inquiries or complaints regarding this Privacy Policy should first contact Fysical via the contact information listed below. If your privacy concern is not resolved satisfactorily, you may wish to contact your local data protection authority who will refer your complaint to the panel to investigate your query free of charge. Please note that if your complaint is not resolved, you may have the right, under certain limited conditions, to invoke binding arbitration before the Privacy Shield Panel of the U.S.Department of Commerce.

 

Residents of the EU with inquiries or complaints regarding this Privacy Policy should first contact Fysical at:

privacy@fysical.com
GIS Operations, Inc
1836 Broadway Street
San Francisco, CA, 94109

10. Modifying Account Information

Please note that Fysical cannot modify or delete End User Data except at the request of our Customer, or as permitted by our Terms of Service.

11. California Residents

If you are a California resident, you have the following rights below. We will not discriminate against any California resident who exercises these rights. If you are not a California resident, we may, at our discretion, respond to requests relating to the below.

Right to Access

You may request from us a list of: (i) the personal information that we have collected about you; (ii) the categories of third parties to whom we have disclosed your personal information; and (iii) the categories of third parties to whom we have sold your personal information. You have the right to up to two (2) access requests each twelve (12) months.

Right to Delete YourPersonal Information

You may request, at any time, to delete your Fysical account and/or your personal information.

Right to Opt-Out From theSale of Your Personal Information

You may request, at any time, to direct us to stop selling your personal information. You may make this request by clicking the “Do Not Sell My Personal Information” button located at www.fysical.com.Please note that we do not generally collect personal information directly from consumers.

You may contact us in relation to these rights by completing this form or by contacting us at 800 320-7760 as otherwise indicated below. We will not use the information you provide as part of your request for any other purpose other than to fulfill your opt out request.

Verification

To ensure the privacy and protection of individuals, we will verify or otherwise authenticate your request(s).

In relation to the opt-out request above, we may require that you provide us with your device identifier, which we will use to opt you out.

If you do not know your device identifier, please read the instructions below on how to obtain your device identifier. We will not use the information you provide as part of your request for any other purpose other than to fulfill your opt out request.

If you use an iOS operating system, a third-party tool is required to locate your Apple IDFA. Please note that we do not control such third-party tools and are not responsible for their content, their privacy policies, or their use of your Personal Information. When you provide Data to a third-party, the Data you provide may be separately collected by that third-party. The Data the third-party collects is subject to that third-party’s privacy practices. Privacy choices you make on the third-party website or app will not apply to our use of the Data we collect.

If you use an Android operating system, open the Google Settings app on your Android device and select “Ads.” YourAdvertising Identifier should be listed at the bottom of the screen.

Additionally, you may also submit such requests through an authorized agent. To designate an authorized agent, please send us a notarized power of attorney. Requests from agents that do not submit such proof that they have been authorized by you to act on their behalf will be denied as we are unable to verify their authentication.

As a California or other U.S. resident, you may contact us with any questions or to request a list of third parties to whom we may disclose your data for such third parties’ marketing purposes and the categories of Information we may disclose.

 

12. Contact Us

For additional inquiries about this EndUser Privacy Statement, please send us an email at privacy@fysical.com or contact us at:

GIS Operations, Inc
1836 Broadway Street
San Francisco, CA, 94109