Privacy Policy
This Privacy Policy explains our privacy practices for customer information we collect in Canada at Decoraport Store and through our Web site, www.decoraport.ca. In this Privacy Policy, the terms "Decoraport", "we" and "our" refer to Decoraport International Ltd., unless otherwise indicated. Personal information and personal health information collected or provided when customers visit other non-Canadian Decoraport websites or Decoraport Store outside of Canada which are operated by our affiliates, are governed by the privacy policy that is posted on that website or that applies in those warehouses.
1. DECORAPORT'S COMMITMENT TO PRIVACY.
Decoraport is committed to protecting the privacy of our customers. We have and will take measures that protect the privacy of personal information and personal health information held by us.
This Privacy Policy provides you with details regarding: (1) why we collect personal information and personal health information; (2) what we do with that information; (3) the steps we take to ensure that access to that information is secure; (4) how you can access personal information and personal health information pertaining to you; and (5) who you should contact if you have questions or concerns about our policies or practices.
Children: We encourage parents to take an active interest in their children's use of the Internet. We do not intend to collect information from children who are under 18 years of age. If you are under 18, please do not provide information on our Web site.
2. WHAT IS PERSONAL INFORMATION?
In general terms, personal information means any information about an identifiable individual. For example, this includes your name, postal and e-mail address, telephone number, credit card number, the photograph included on your Decoraport membership card and if you request it and are approved, the Decoraport/American Express dual brand card, demographic information and purchasing history. A special category of personal information is "personal health information", which we describe in Section 3 below.
Personal information does not include aggregate information (data about a group or category of products, services or customers, from which individual customer identities have been removed). For example, information about how you use a service may be collected and combined with information about how others use the same service, but no personal information will be included in the resulting data. Likewise, information about the products you purchase may be collected and combined with information about the products purchased by others. Aggregate information about product purchases helps us understand trends and customer needs, and assists us in product selection, product ordering and sizing and the introduction of new products and services. It can also assist us in determining where it would be appropriate to build new warehouses by looking at the geographic location of members or to build new Web site functions by looking at member Web site browsing activities.
3. WHAT IS PERSONAL HEALTH INFORMATION?
Personal health information means any information relating to your physical or mental health collected or generated in the course of our providing you with the health services you request, such as optical, pharmacy and hearing aid services, and prescription profiles for fulfillment of pharmacy orders. Examples of personal health information may include your medical history, drug prescription information, eyeglass prescription information, or health insurance information, which we may require in order to provide you with pharmacy, hearing aid, optical and other health-related services. It may also include information you provide to Decoraport health services personnel when receiving counseling or advice, or when contacting Decoraport with a comment, question or complaint about our health services.
4. WHEN WE COLLECT PERSONAL INFORMATION.
We only collect such personal information as is strictly necessary for the purposes outlined in Section 5. We collect personal information: (1) when you apply for membership (including information about your credit history which may be collected, used and retained if you choose to pay by cheque.); (2) when you renew your membership; (3) when you contact us; (4) when you sign up for Member Services (see definition below) or use our Web site; (5) when you participate in any of our programs; (6) when you place orders or make purchases at our warehouses or on our Web site, by telephone, mail, e-mail, facsimile or any similar means; and (7) when you place orders or make purchases through our affiliated companies, including Decoraport International Ltd. (Decoraport and its affiliates are referred to collectively as the "Decoraport Affiliates"). Certain products and services offered to our customers (such as rebates, the Executive Membership Program and other business and consumer services, collectively the "Member Services") may be provided by third party suppliers. We collect from such third party suppliers a list of our customers who have signed up for Member Services and information about the use our customers make of such Member Services (for example, frequency of use and customer feedback). We may automatically collect some information when you visit our Web site, such as your computer's network address and operating system, the site from which you linked to us, and the time and date of your visit and purchases. This information is not linked by us to personal information, but rather is only used to compile aggregate information.
5. HOW WE USE PERSONAL INFORMATION.
As part of our business operations, we hold and use certain personal information pertaining to you in order to process your requests, provide you with Member Services, and to understand your needs so that we can serve you better. We may also tell you about opportunities we think will be of interest to you, such as our promotional programs and our "Decoraport Connection" magazine. Specifically, we may use personal information for the following purposes:
- Notifying you of recalls or safety issues;
- Approving you as a member when you apply for membership;
- Managing the provision of goods, services and privileges to you, including monitoring your membership, to conduct a credit check if you choose to pay by cheque, to determine your credit status and for fraud detection and identification purposes;
- Managing invoicing, accounting and information security services related to our transactions with you;
- Monitoring your satisfaction with our programs, including the Executive Membership Program, the services offered by our suppliers of Member Services and contacting you regarding the status of such programs and services (for example, to inform you of changes to or the termination of particular Member Services);
- We may promote, offer or market additional products, goods and services.
We may use personal information to create aggregate information as well.
6. WHEN WE SHARE PERSONAL INFORMATION.
Personal information we collect in accordance with this Privacy Policy may be shared with the Decoraport Affiliates, for the purposes listed above, provided that such shared information is required for and is used and disclosed for such purposes only. Personal information may also be disclosed to unaffiliated third parties in connection with the sale, assignment or other transfer of our business, in which case we will require such third parties to adhere to the terms of this Privacy Policy.
From time to time we engage unaffiliated third parties and their affiliates, agents and subcontractors ("Service Providers") to perform certain technological or administrative services. For example, a Service Provider may be asked to perform credit card processing services, administer a contest or be asked to run a computer program that identifies which of our members purchased a particular product so we can notify those members of special programs regarding the same or similar products. We also may use a Service Provider to host and administer one or more of our Web sites, process and store data, and fulfill similar technology-related functions on our behalf. In these circumstances, the personal information that the Service Provider receives is limited to only the personal information held by us that they need in order to render their service to us. The companies that are provided with the personal information are first required to sign an agreement that obligates them to keep the information confidential and secure and prohibits them from using it for unauthorized purposes.
We also may engage Service Providers to provide us with cloud computing services. Cloud computing is the provision of network-based services, located on remote computers, that allow individuals and businesses to use software and hardware operated by third parties. Examples of these services include online file storage, webmail and online business applications. Service Providers have policies and processes in place to ensure that the confidentiality of information in their care is properly safeguarded at all times.
You acknowledge that if Service Providers are located in the United States or the European Union, your personal information and personal health information may be processed and stored in the United States or the European Union and the governments, courts or law enforcement or regulatory agencies of the United States or the European Union may be able to obtain disclosure of your personal information and personal health information through a lawful order made where the information is located.
As outlined above, Member Services (such as rebates, the Executive Membership Program, and other business and consumer services) may be provided by Service Providers. When you sign up for Member Services, we will share your name, membership status, membership number and type and such other personal information as is necessary with the Service Provider so they can confirm your eligibility for the Member Service you requested. Service Providers who are suppliers of Member Services can only use the personal information that we share with them to provide the Member Services or, if you have consented, to notify you of their offerings and to evaluate new and existing products, offerings or services. We are not responsible for any additional information you provide directly to these Service Providers, and we encourage you to become familiar with their privacy and security practices and policies before disclosing information to them. There may be instances when we provide information relating to our business customers to various suppliers such as tobacco companies, so they can conduct market studies and other promotional activities. In the case of tobacco products, the information we provide is the business customer's name, address, the brand name of the tobacco products purchased and the amount of tobacco products purchased.
We will also disclose personal information in accordance with Section 12 below when the information is collected on-line at Decoraport.ca and/or may disclose personal information or personal health information without your knowledge or consent if a law, regulation, search warrant, subpoena or court order legally authorizes us or requires us to do so. We may also disclose personal information or personal health information to protect the rights, property or personal safety of Decoraport, its customers, employees or other members of the public.
Except as set out above, we do not sell, rent, share or disclose the personal information or personal health information we hold or make our membership list available to others for a fee without your consent.
7. WHEN WE COLLECT, HOW WE USE AND WHEN WE SHARE PERSONAL HEALTH INFORMATION.
In the course of providing you with pharmacy, hearing aid, optical and other health-related services and programs we introduce from time to time, we collect, generate and use personal health information to provide you with the health services you request, to obtain or process payment for health services and for internal management purposes, including planning, resource allocation, policy development, quality improvement, monitoring, audit, evaluation and reporting. Your personal health information may be shared between Decoraport Affiliates for these purposes only. Decoraport and its Service Providers will not use or disclose your personal health information without your consent except in connection with (1) processing or obtaining payment for government-funded health services (for example, obtaining authorization from your insurer or provincial authorities for direct payment of pharmacy services), (2) processing or obtaining payment from your health insurance provider, (3) providing Decoraport with technological or administrative services as described in Section 6 above or (4) in connection with the sale, assignment or other transfer of our business, in which case we will require such third parties to adhere to the terms of this Privacy Policy. We will also disclose personal health information if a law, regulation, search warrant, subpoena or court order legally authorizes us or requires us to do so or to protect the rights, property or personal safety of Decoraport, its customers, employees or other members of the public. We may also be required to disclose certain personal health information in order to maintain standing with the professional bodies for pharmacists, audiologists or opticians.
8. HOW LONG DO WE HOLD PERSONAL INFORMATION AND PERSONAL HEALTH INFORMATION?
Personal information and personal health information is retained only for so long as is necessary for the purposes set out above. When no longer required, we will destroy, erase or de-personalize the personal information. Legal requirements may necessitate our retaining some or all of the personal information and personal health information we hold for a period of time that is longer than we might otherwise hold it. However, Decoraport will restrict access to such information to prevent it from being used except for the fulfillment of these legal requirements.
9. ACCURACY.
To ensure that the personal information and personal health information you provided is accurate, complete and up-to-date, we urge you to provide us with updates regarding such information and to inform us of any errors affecting the personal information and personal health information we hold. You may update, review or correct your Decoraport.ca on-line account information at any time by accessing your password-protected registration page via the "My Account" area of the Web site. To update any other information, please visit the Membership Counter in any of our warehouses with your membership card to confirm your identity.
10. SECURITY MEASURES.
We will continue to keep in place security measures in an effort to protect personal information and personal health information held by us from unauthorized use, access, disclosure, distribution, loss or alteration. We employ physical, administrative, contractual and technological safeguards to protect personal information, and insist that our Service Providers do the same. Access to personal information and personal health information will be restricted to authorized personnel who require the information in order to perform their duties properly. In addition, access will be limited to only that information that is strictly necessary for the performance of those duties.
We periodically update our policies regarding information security measures in an effort to protect the personal information and personal health information held by us in the most effective manner possible.
11. ACCESSING PERSONAL INFORMATION AND PERSONAL HEALTH INFORMATION.
Our customers are entitled to access the personal information and personal health information held by us concerning them. In recognition of the importance we attach to each customer's information, you can only access personal information and personal health information we hold about you, but not personal information and personal health information about your spouse or others who may have been issued a membership card on your account. Under limited circumstances, we may give you access to personal information or personal health information that we hold about others, but only if required or permitted by law (for example, a parent or guardian may, in certain instances, be given access to the personal information or personal health information of a child or a person who requires a substitute decision maker). You can access the personal information and personal health information you provided to us by showing your membership card at the Membership Counter in each warehouse to confirm your identity and completing a written request for such information on a form we provide. We will generally respond to your request for information within thirty (30) days, unless, for reasons beyond our control, a longer response time is necessary, in which case you will be advised accordingly. While our response will generally be provided at no cost, you will be informed in advance of any charges that apply in connection with the information request. Charges may relate to the transcription, reproduction or transmission of personal information or personal health information held by us. Personal information and personal health information may be stored by Decoraport or Decoraport Affiliates in Canada, in the United States or in the European Union. You acknowledge that if Service Providers are located in the United States, or the European Union, your personal information and personal health information may be processed and stored in the United States or the European Union, and the governments, courts or law enforcement or regulatory agencies in the United States or the European Union may be able to obtain disclosure of your personal information and personal health information through a lawful order made where the information is located.
In very limited circumstances, we may not be able to supply personal information and personal health information for reasons of a legal nature, including privileged communications between professional and client or a pending judicial proceeding. In each case, we will provide written reasons outlining why your request for access has not been granted by us.
12. ON-LINE PRIVACY PRACTICES.
Collection: We may collect personal information and personal health information on-line when you visit our Web site as described in Sections 4 and 7 above. In addition, we may collect cookie and web beacon information when you browse the Web site. Cookies are small files that are stored on your computer, and web beacons are electronic images that allow us to count visitors visiting certain Web pages, to access cookies, and to analyze whether advertising banners on our site or other sites were effective. At Decoraport.ca, we may use cookies and beacons to help optimize your shopping experience, to evaluate use of our Web site, and to support Web site analytics and marketing campaigns. In doing so, we may collect technical information such as your IP address, your browser type, the addresses of referring Web sites, and your path through our Web site. Cookies help us to customize our home page for you and to better display pages according to your browser type. While cookies are optional for browsing Decoraport.ca, they are required for registering, logging on, purchasing or adding items to your cart. If you wish to purchase items or set up an account on Decoraport.ca, you will need to accept a Decoraport.ca cookie. (In order to control the ability of Web site providers to place cookies on your computer, you should consult your browser's "Options" and "Help" pages to learn how to adjust your settings to suit your privacy preferences.)
Use: We use personal information and personal health information collected on-line as described in Sections 5 and 7 above. In addition, we use personal information and personal health information: (a) to facilitate and monitor certain features of our Web site that you choose to interact with, such as on-line forums, feeds and chatrooms; (b) to respond to your questions and concerns and to understand your needs and preferences; (c) to conduct surveys and other research; (d) to provide you with customized Web site content and advertising; (e) to fulfill your on-line orders for products and services and to facilitate product deliveries, pickups and returns; (f) to detect, prevent, or otherwise address fraud, security or technical issues, or (g) protect against harm to the rights, property or safety of Decoraport, its users or the public as required or permitted by law.
Sharing: We share personal information and personal health information collected on-line as described in Sections 6 and 7 above. In addition, we may provide Service Providers with certain information that is necessary to fulfill an order you have placed with us. For example, if you request shipment for a purchase, we may provide your address to the shipping carrier and customs service provider, and if you pay by credit or debit card, your card number and sales transaction information are passed to the card processor and/or issuer (including their service providers such as fraud verification services). We also may use Service Providers to host and administer the Web site, process and store data, and fulfill other technology-related functions on our behalf. However, we only give or permit access to vendors, suppliers and other Service Providers involved in Web site administration and the commerce distribution chain the limited information needed to perform their duties and provide you with the products and services you order. We are not responsible for any additional information you provide directly to these parties.
Protection: Personal information and personal health information we collect on our Web site is stored electronically, and may be combined with other off-line information. Personal information and personal health information entered on our Web site is encrypted using a security protocol called SSL (Secure Sockets Layer). SSL encrypts information entered on our site before it is sent over the Internet. SSL also allows you to view securely your on-line account and registration information. Account information is accessible on-line only through the use of a password. To protect the confidentiality of personal information and personal health information, you must keep your password confidential and not disclose it to any other person. You are responsible for all uses of our Web site by any person using your password. You are advised that, unlike communication within our Web site, we have no control over the privacy of your e-mail communications with us while in transit. We recommend that you do not include confidential, proprietary, personal or personal health information in e-mails, including credit card numbers, passwords, prescriptions and other similar information. Also, if other people have access to your e-mail account, they may be able to access your password and obtain personal information about you (such as your credit card information), or change information about your user profile. You should not use an e-mail account operated by your employer because many employers have the legal right to access such e-mail accounts. Please advise us immediately by e-mail at customer.ca@decoraport.com if you believe your password has been misused.
Children: We encourage parents to take an active interest in their children's use of the Internet. We do not intend to collect information from children who are under 18 years of age. If you are under 18, please do not provide information on our Web site.
On-line links to other Web sites: Through links provided on our Web site, you can link to other Web sites of third parties who have agreed to offer goods and services to our members. Any personal information you provide on the linked pages is provided directly to that third party and is subject to that third party's privacy policy. Except as described above, we are not responsible for the content or privacy and security practices and policies of Web sites to which we provide links. Links from our site to third parties or to other sites are provided for your convenience. We encourage you to learn about their privacy and security practices and policies before providing them with personal information.
13. COMPLAINT PROCESS.
If you are not completely satisfied with or wish to submit comments concerning this Privacy Policy or its application by us, we invite you to convey your concerns or suggestions to Decoraport International Ltd., Attention: Privacy Officer. We will reply as quickly as possible and inform you of the steps, if any, that have been or will be taken in order to address the concern or implement the suggestion. You can also file a complaint with the Privacy Commissioner in the province in which you reside or with the Office of the Privacy Commissioner.
14. CHOICE.
If you (1) previously consented to the sharing of the personal information you provided, or (2) are a Business Member and you do not want us to disclose information about your purchases, you can change your mind by: E-mail: customer.ca@decoraport.com(for individual members); business.ca@decoraport.com(for business members).