Gibson Foundation | Gibson Gives - Privacy Policy

Effective Date: June 1, 2019

Gibson Foundation, dba Gibson Gives and Epiphone Gives takes your privacy very seriously. For that reason, we have developed this policy to let you know about our collection, use, and disclosure of your Personal Data and the choices you have associated with that data. This Privacy Policy applies to all of the Gibson Brands, Inc. divisions and subsidiaries and related websites. Personal Data may be shared without further notice between all Gibson Brands, Inc. divisions and subsidiaries.

It’s important to know that this privacy policy does not apply to your activities on the websites of social networks or other providers that you can reach via links on our websites. Don’t forget to check the websites of these providers for their data protection regulations.

We use your data to provide and improve our services. But we also use your data to market directly to you. We collect several different types of data

Types of Collected Data

Personal Data can be processed only for the purpose that was defined before the data was collected. The type of data we may collect includes:

Personal Data, which is data that can be used to identify you. Personal Data may include your:

  • Email address

  • Name

  • Address/Phone

  • Gender

  • Age

  • Purchase Information

  • Hobbies

  • Cookies and Usage Data

You are generally not legally or contractually obliged to make available your Personal Data. However, it is possible that certain functions of our websites depend on the availability of Personal Data. If you do not make available Personal Data in these cases, this may result in functions not being available or only being available to a limited extent. For example, if you’d like to allow us to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you, you will need to provide your Personal Data and provide us with your consent to process it

Usage Data, which is data that tells us how our websites are accessed and used. Usage Data may include your:

  • Computer's Internet Protocol address (e.g. IP address)

  • Browser type,

  • Browser version

  • Our website pages that you visit

  • Time and date of your visit

  • Time spent on those pages, unique device identifiers

  • Other diagnostic data

Sometimes Usage Data is also personal data because it may let us know who you are.

Location Data, which is data about where you are located. Like the other types of data, we will only use and store this information if we have your permission.

Tracking & Cookies Data, which is data that allows us to operate our websites (session cookies), store your preferences and settings (preference cookies), and perform security (security cookies). Cookies are files with small amount of data which sometimes include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies include things such as beacons, tags, and scripts that collect and track information. Sometimes cookies and tracking data is also Personal Data. Because we need to use different types of cookies with our websites, if you do not accept cookies, you may not be able to use some areas of our websites that rely on them. We use cookies and similar software tools such as HTML5 Storage or Local Shared Objects to identify your interests and particularly popular areas of our websites and use this information to improve the design of our websites and make them even more user-friendly. For the same purposes we use the analysis tools Adobe Analytics and Google Analytics; cookies may also be used here.

Processing of Data

Now that you know what types of data we may be getting from you, you’re probably curious as to what we do with it. We use your data to:

  • Provide and maintain our services

  • Provide email marketing and social targeting

  • Notify you about changes to our services

  • Allow you to participate in interactive features of our websites

  • Provide customer support and order fulfillment

  • Perform market research

  • Monitor the usage of our websites

  • Detect, prevent and address technical issues

  • Provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about

Gibson Foundation only collects and uses your Personal Data with a lawful basis: with your consent, when it is necessary in order to provide our services, when we need to fulfill a legal obligation, or when there is a legitimate business reason behind the collection which is not overridden by your data protection interests.

Disclosure of Data

Sometimes we may need to disclose your data without your consent, for example when we have the good faith belief that such action is necessary to:

  • Comply with a legal obligation

  • Protect and defend the rights or property of Gibson Brands, Inc.

  • Prevent or investigate possible wrongdoing in connection with our services

  • Protect the personal safety of users of our services or the public

  • Protect against legal liability

Data Retention

We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

Gibson Foundation, Gibson Gives, and Gibson Brands, Inc. also retains Usage Data for internal analysis purposes.

Personal Data that is no longer needed after the expiration of legal or business process-related periods will be deleted. There may be an indication of interests that merit protection or historical significance of this data in individual cases. If so, the data must remain on file until the interests that merit protection have been clarified legally, or the corporate archive has evaluated the data to determine whether it must be retained for historical purposes.

Transfer of Data

We may transfer your information, including Personal Data, outside of your state, province, country or other governmental jurisdiction. In some of these areas, the

data protection laws may differ than those from your jurisdiction and you may not have the same protections. Your data may be maintained in these jurisdictions.

If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to the United States and process it there. Your consent under this Privacy Policy followed by your submission of Personal Data represents your agreement to that transfer.

If you click on a link to a third party website, please remember that from the point of the European Union “EU”, the third party may not have an adequate level of protection for processing of Personal Data according to EU standards.

Gibson Brands, Inc. will take steps to ensure that transferred Personal Data is treated securely and in accordance with this Privacy Policy. No transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

If Gibson Brands, Inc. is involved in a merger, acquisition or asset sale, your Personal Data may be transferred if you give your continuing consent or another lawful basis exists. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

Security of Data

Remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we continue to strive to use commercially acceptable means to protect your Personal Data, no one can guarantee its absolute security. However, we are constantly improving our security measures in line with technological developments.

"Do Not Track" Signals

Some browsers have a “do not track” feature that lets you tell websites that you do not want to have your online activities tracked. At this time, we do not respond to browser “do not track” signals, but we do provide you the option to opt out of interest-based advertising.

Managing Your Data

Gibson Foundation allows you to correct, amend, delete, or limit the use of your Personal Data. If you have consented to the processing of your Personal Data by us, you have the right to revoke your consent at any time. If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us.

You always have the following rights regarding your Personal Data:

The right to access, update or to delete the information we have on you. Whenever made possible, you can access, update or request deletion of your Personal Data directly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you.

The right to correct. You have the right to have your information corrected if that information is inaccurate or incomplete.

The right to object. You have the right to object to our processing of your Personal Data.

The right of restriction. You have the right to request that we restrict the processing of your Personal Data or specific aspects of your Personal Data.

The right to data portability. You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format.

The right to withdraw consent. You have the right to withdraw your consent at any time regarding the collection and processing of your Personal Data.

Please note that we may ask you to verify your identity before responding to such requests.

If you are a resident/citizen of the EU, you additionally have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).

Service Providers

We may employ third party companies and individuals to facilitate our services, such as our websites ("Service Providers"), to provide the services on our behalf, to perform service-related services or to assist us in analyzing how the services are used. We contractually make sure that these third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

The specific third-party services we use include:

  • Google Analytics

Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the

use of our websites. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.

You can opt-out of having made your activity on the websites available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sharing information with Google Analytics about visits activity.

For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: http://www.google.com/intl/en/policies/privacy/

  • Submittible

Submittible is an online processor of donation requests. We utilize them as a third party to ensure all data is captured and compliance with all federal and international laws are followed. Your data is stored with Submittble who are compliant with GDPR and HIPPA.

Payment Processors

We may provide for paid donations within our websites. In that case, we use third-party services for payment processing (e.g. payment processors). Gibson Foundation will not store or collect your payment card details. That information is provided directly to our third-party payment processors. Their use of your personal information is governed by their privacy policies. However, all payment processors that are used adhere to the standards set by PCI-DSS , requirements which help ensure the secure handling of payment information.

The payment processors we work with are:

  • PayPal

  • Stripe

  • Infintech

Big Commerce

Big Commerce is an online provider of ecommerce software and platforms.

MailChimp

MailChimp is a marketing automation platform and an email marketing service.

Links to Other Sites

Our websites may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit.

Children's Privacy

Our services do not address anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we will take steps to remove that information.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and allow you to opt in. We will let you know via email and/or a prominent notice on our websites, prior to the change becoming effective and update the "effective date" at the top of this Privacy Policy. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

Controller within the meaning of the General Data Protection Regulation (“GDPR”) is:

Gibson Brands, Inc.

309 Plus Park Blvd

Nashville, TN 37217

If you have any questions about this Privacy Policy, please contact us:

By email: gibsonfoundation@gibson.com

By visiting this page on our website: https://www.gibson.com/Support/Customer-Service

By phone number: 1-800-444-276