Last Updated August 14th, 2020
Who we are
Our website address is: https://gueycbd.com. Our organization name is EightTwenty LLC with a mailing address of 1041 N Grand Ave #168, Covina, CA. 91724. Guey (“us”, “we”, or “our”) operates the https://gueycbd.com website (the “site”.) This statement of Privacy applies to https://gueycbd.com and Guey and governs data collection and usage.
The Guey website is an e-commerce website with an online catalog wherein customers can browse products and complete purchases.
- Personal Data: Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
- Usage Data: Usage Data is data collected automatically either generated by the use of the Site or from the Site infrastructure itself (for example, while you are visiting a page on https://gueycbd.com, we may collect data on which pages you visited and which links you clicked on).
- Cookies: Cookies are small pieces of data stored on your device (computer or mobile device).
- Data Processors (or Service Providers): Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively and to more accurately and more easily provide our product or service to you. In an effort to give you control over your personal information, Guey provides a list of those Service Providers and how your information is being used under the Storage and Transfer of Your Data section.
- Data Subject (or User): Data Subject is any living individual who is using our Site and is the subject of Personal Data. The Data Subject is you and is often called the “user” or “consumer”.
Collecting Your Personal Information
We collect several different types of information from you for the purposes of providing and improving our product or service to you, analyzing website functionality, or to diagnose and track errors or glitches. Below are the types of data we collect:
Storing and Transferring Your Data
Guey will not retain your credit or debit card information on https://gueycbd.com or any other online service. Only the approved service providers under the General Information section will retain access to your credit or debit card details. Guey will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Site, or we are legally obligated to retain this data for longer time periods.
Your information, including Personal Data, may be transferred to (and maintained on) computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those from your jurisdiction. If you are located outside of the United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to the United States and process it there.
Guey does not sell, rent or lease its customer lists or its users’ Personal Data to third parties.
Guey may share data with trusted partners to help perform statistical analysis, send you email or postal mail, provide customer support, or arrange for deliveries. All such third parties are prohibited from using your personal information except to provide these services to Deluca’s Italian Deli, and they are required to maintain the confidentiality of your information.
The next few tabs contain a list of places where Guey keeps your personal information and the way your data is transferred between them.
Google Analytics: Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Site. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.
We may use third-party Service Providers to show advertisements to you to help support and maintain our Site.
You may opt out of the use of the DoubleClick Cookie for interest-based advertising by visiting the Google Ads Settings web page: https://policies.google.com/privacy?hl=en
Facebook: Facebook re-marketing service is provided by Facebook Inc. You can learn more about interest-based advertising from Facebook by visiting this page: https://www.facebook.com/help/164968693837950
To opt-out from Facebook’s interest-based ads follow these instructions from Facebook: https://www.facebook.com/help/568137493302217.
Facebook adheres to the Self-Regulatory Principles for Online Behavioral Advertising established by the Digital Advertising Alliance.
You can also opt-out from Facebook and other participating companies through the Digital Advertising Alliance in the USA: https://www.aboutads.info/choices/, the Digital Advertising Alliance of Canada in Canada: https://youradchoices.ca/ or the European Interactive Digital Advertising Alliance in Europe: https://www.youronlinechoices.eu/, or opt-out using your mobile device settings. For more information on the privacy practices of Facebook, please visit Facebook’s Data Policy: https://www.facebook.com/privacy/explanation.
Google Web Fonts: For uniform representation of fonts, this website uses web fonts provided by Google. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly.
For this purpose your browser has to establish a direct connection to Google servers. Google thus becomes aware that our web page was accessed via your IP address. The use of Google Web fonts is done in the interest of a uniform and attractive presentation of our Site. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.
Under certain circumstances, Guey may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency). Guey may disclose your personal information, without notice, if required to do so by law or in the good faith belief that such action is necessary:
- To conform to the edicts of the law or comply with legal process served on Guey or the site.
- To protect and defend the rights or property of Guey.
- To act under exigent circumstances to protect the personal safety of users of Guey, or the public.
- To protect against legal liability.
The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security. As a result, you acknowledge that:
- There are security and privacy limitations inherent to the Internet which are beyond our control.
- Security, integrity, and privacy of any and all information and data exchanged between you and us through this Site cannot be guaranteed.
Enhanced Validation (EV) SSL Protocol: When personal information (such as a credit card number) is transmitted to other websites, it is protected through the use of encryption, such as the Secure Sockets Layer (SSL) protocol. We have gone above the standard SSL Certificate and use an Enhanced Validation (EV) SSL Certificate, which has a Strong SHA-2 & 2048-bit encryption and a Security trust seal so you will always be able to tell if your information is secure. If you ever do not see the Security Trust Seal or the green padlock in the url browser bar, please refrain from sending any personal information and make sure you are on the correct website: https://gueycbd.com.
We may provide paid products and/or services within the Site. In that case, we use third-party services for payment processing (e.g. payment processors).
The payment processor we work with is:
This procedure outlines the processes to be followed in the event that Guey experiences a data breach or suspects that a data breach has occurred. A data breach involves the loss of, unauthorized access to, or unauthorized disclosure of, personal information.
Alert: When a privacy data breach is known to have occurred, or is suspected, a site admin of https://gueycbd.com who becomes aware of this must alert the DPO (Data Protection Officer) or Privacy Officer within 24 hours. The information included in this alert consists of:
- Time and date of breach.
- Description of breach and type of Personal Data involved.
- Cause of the breach, if known, as well as how it was discovered.
- Which systems are affected.
- Whether actions have been taken to correct or remedy the breach, or suspected breach.
- Is Personal Data involved?
- Is the Personal Data of a sensitive nature?
- Has there been unauthorized access to personal information, unauthorized disclosure of personal information, or loss of personal information?
- Determining the severity of the breach through type and extent of Personal Data involved.
- Determining whether multiple individuals have been affected, whether the information is protected by any security measures (password protection, SSL encryption, etc.).
- Determining the person or groups who now have access and whether they pose a real risk of serious harm (physical, emotional, economic, or financial harm to reputation) to the affected individuals.
- Determining if there are Federal or State laws that may have been implicated by the breach, or suspected breach.
The DPO or Privacy Officer must issue internal notifications to the site admins and Guey officers to make aware of the breach, or potential breach, and the plan for managing and correcting the issue. The Data Breach Response Team will consist of:
- DPO or Privacy Officer
- Human Resources Manager (or CEO if no Human Resources Manager is appointed)
- Marketing Director
- Information Technology Manager or Webmaster
- Contain the breach (if it has not already been contained) through retrieving the lost Personal Data, completely blocking unauthorized access, securing physical areas (server locations), and/or shutting down the affected systems.
- Collecting and documenting all available evidence of the breach.
- Reporting the breach to the governing agency: the FTC in the United States.
- Remove any improperly posted information from the web: If the data breach involved Personal Data which became posted on https://gueycbd.com the Response Team must remove it and search other websites to make sure they do not have a saved copy of the Personal Data.
- In the case the Personal Data is posted on other websites, the DPO or Privacy Officer will contact those sites and ask them to remove it.
- All service providers of https://gueycbd.com will be investigated and/or contacted to determine if they were the source of the breach. The Response Team will verify that the service providers have taken every step to remedy the vulnerability and ensure another breach does not occur.
The Marketing Director must issue the following public and private notifications:
- Through the use of a site-wide banner on https://gueycbd.com, notify any resident of California whose unencrypted Personal Data was, or is reasonably believed to have been, acquired by an unauthorized person, according to the California S.B. 1386 bill.
- Notify local law enforcement of the potential risk for identity theft.
- Communicate the details of the breach, what Personal Data may have been affected, what steps Guey is taking or has taken to correct the breach, and recommendations to the user regarding changing their password on https://gueycbd.com (if they have one) and any other suggestions to help prevent further Personal Data Breaches.
General Data Protection Regulation (GDPR) Policies
- We need to process a sale or transaction with you.
- You have given us permission to do so.
- The processing is in our legitimate interests and it’s not overridden by your rights.
- For payment processing purposes.
- To comply with the law.
If you are a resident of the European Economic Area (EEA), you have certain data protection rights. Guey aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us. In certain circumstances, you have the following data protection rights:
- The right to access, update or to delete the information we have on you. Whenever made possible, you can access, update or request deletion of your Personal Data directly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you.
- The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
- The right to object. You have the right to object to our processing of your Personal Data.
- The right of restriction. You have the right to request that we restrict the processing of your personal information.
- The right to data portability. You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format.
- The right to withdraw consent. You also have the right to withdraw your consent at any time where Guey relied on your consent to process your personal information.