PRIVACY POLICY
INTRODUCTION
This Privacy Policy applies to the BOUNZ Program operated by City Points Loyalty Card Services LLC and explains how We collect, record, hold, store, use, disclose or otherwise process personal information.
The following additional Terms & Conditions, which also apply to Your use of the BOUNZ Program, the BOUNZ mobile app or the BOUNZ Platform. All definitions and terms used in this Privacy Policy shall have the same meaning as those previously referred to in the Terms and Conditions.
We may collect and use personal and transactional information that You directly or indirectly provide Us with. For example, We collect personal information when You fill out Our form, connect with Us on any social media sites, submit a request for customer support, or otherwise communicate with Us in any other way. Some examples of the type of personal information We may collect include Your name, mobile number, email, address, company information, pictures, payment information, descriptions of properties and other information You choose to provide. We also collect purchase information across all Our merchant partners to enhance Our services and provide a more personalized experience.
We respect Your privacy and are dedicated to protecting Your Data. This Privacy Policy will provide You information as to how We look after Your personal Data when You use the BOUNZ Application, the BOUNZ Platform or register for the BOUNZ Program and tell You about Your privacy rights and how the law protects You. This Privacy Policy has been created so that You understand the ways in which We collect, store, use and protect Your personal and private information safely and it is important for You to review this Privacy Policy prior to using Our services.
By accessing Our app or the BOUNZ Platform, You expressly consent to Us processing Your personal information in accordance with the Terms & Conditions and Privacy Policy. We may amend Our Terms & Conditions and Privacy Policy at any time by posting a revised version on the BOUNZ Platform. In the event of any amendments, We will notify members about the updates through the website, the platform, emails, SMS or any other mean where such revised version will be effective at the time We post it and, following such posting, Your continued use of the BOUNZ Platform will be considered as an express consent to Us for continuing to process Your personal information in accordance with the new revised Terms & Conditions and Privacy Policy.
Any modifications or updates to the Terms and Conditions or Privacy Policy shall be promptly communicated to the Members via the website, the platform, emails, SMS, or any other mean. The notification will include a clear and conspicuous link to the respective updated pages of the Terms and Conditions or Privacy Policy. The Members will be deemed to have received notice of such changes within a reasonable time after the notification has been sent to them by pop up notification when accessing the website or the Platform or to the email address or mobile phone number associated with their account.
Individuals under the age of 18 are strictly prohibited from accessing or using the Platform or the Services.
If any new technologies are going to be used to process data in a way that could significantly affect user privacy, a Data Protection Impact Assessment (DPIA) may need to be conducted and We shall communicate its results to You. You will be granted 24 hours as of the date of You receiving the assessment to decide whether We will pursue the data processing using such new technologies or to cancel Your account on the Platform, without any liability on BOUNZ.
If You have any questions about this Privacy Policy, including any requests to exercise Your legal rights, please contact Us on [email protected].
DATA COLLECTION (“DATA”)
Personal Information
When You sign up to become a Member, You will be required to provide Us with personal information including but not limited to, Your name, e-mail address, location, and phone number. All information We collect and/or receive under this section is collectively called “Personal Information”. We do not collect any personal information from visitors or Members unless they provide such information voluntarily.
Billing Information
You may be required to provide certain information to Our third-party payment vendors pursuant to the Terms & Conditions and conditions of their privacy policies and terms & conditions of use. Such information may include a debit card number, credit card number, expiration date, billing address, activation codes, and similar information. Such information is collectively called the “Billing Information”. You authorize Us and Our third-party payment vendors to collect, process and store, as per local laws, Your Billing Information. We affirm that storage of Your Billing Information is in compliance with Payment Card Industry Data Security Standard.
Other Information
Information that We automatically collect when You use the BOUNZ Platform or the Services, including, without limitation:
IP addresses, which may consist of a static or dynamic IP address and will sometimes point to a specific identifiable computer or device; browser type and language; referring and exit pages and URLs; date and time; amount of time spent on particular pages; what sections of Our BOUNZ Platform You visit; and similar Data;
MAC addresses, which are unique identifiers associated with network interfaces of devices;
Unique IDs such as advertising IDs, which may be assigned to Your device for marketing and advertising purposes;
Browser information, including details contained in URLs used in Our communications with You, such as offer links in emails;
Information about Your device, including the type of device, operating system, and version (e.g., iOS or Android); carrier and country location; hardware and processor information network type and similar Data;
Fitness Data: When You opt to use the BOUNZ Fitness feature, We collect and store Step data from Your connected devices, such as fitness trackers or smartphones. This Step data is collected to compute the data for points accrual within the BOUNZ Fitness program and to provide a more personalized experience. In addition to the Step data, auto-calculated values such as calories, distance, active minutes, exercise, and other variables are also passed on to Us through Our fitness portal.
Information related to Your communications on Our BOUNZ Platform, such as the content of messages sent by and between You and other Members in connection with a potential booking, for purposes of monitoring Your compliance with the Service Terms & Conditions including all non-circumvention requirements therein; and
Information that We collect using “Cookie” technology. Cookies are small packets of Data that a BOUNZ Platform stores on Your computer’s or mobile device’s hard drive so that Your computer will “remember” information about Your visit. We may use both session cookies (which expire once You close Your web browser) and persistent cookies (which stay on Your computer until You delete them) to help Us collect other information and to enhance Your experience using Our BOUNZ Platform or the Services. In addition to Cookies, We may also use other similar technologies such as pixels. If You do not want Us to place a cookie on Your hard drive, You may be able to turn that feature off on Your computer or mobile device. Please consult Your Internet browser’s documentation for information on how to do this and how to delete cookies. However, if You decide not to accept cookies from Us, Our BOUNZ Platform or the Services may not function properly.
YOUR USE OF YOUR AND OTHERS PERSONAL INFORMATION
You may need to share personal information and billing information with other members of the BOUNZ Platform to complete transactions on the BOUNZ Platform. You should respect, at all times, the privacy of any and all other Members.
In addition to this, when You choose to use the BOUNZ Fitness feature, We also collect and store Step data from Your connected devices, such as fitness trackers or smartphones. This step data is collected to track Your Step activity and compute the data for points accrual within the BOUNZ Fitness program. This information allows Us to monitor Your step progress and provide You with a more personalized experience.
This Privacy Policy does not cover, and We cannot guarantee the privacy of Your personal information when You share personal information and billing information with other Members, where applicable. We recommend always seeking information on the privacy and security policies of any other Members with whom You are transacting prior to sharing any of Your personal information and billing information.
You agree to use any personal information and billing information received from another user in relation to a transaction on the BOUNZ Platform solely in relation to such transaction and shall not use the information received from other Members for any other purposes (except with the express consent of the other Members).
You acknowledge and agree, and You shall use personal information received from other Members in accordance with all applicable laws.
It is important that the Data We hold about You is accurate and current. Please keep Us informed if Your Data changes during Your relationship with Us.
Data shall be provided only in the required sections and not anywhere else.
Restricting the Data, including Step data, to the required field shall protect You from the possibility of fraud or identity theft. The posting by You of any billing or personal information anywhere on the BOUNZ Platform other than in the required field shall release Our liability to any fraud or identity theft and shall lead to the suspension of Your use of the BOUNZ Platform or application.
HOW IS YOUR PERSONAL DATA COLLECTED?
Direct interactions.
You may give Us Your personal information by filling in forms or by corresponding with Us by phone, email or otherwise. This includes Data You provide when You:
- register as a member;
- use Our services;
- request marketing material to be sent to You;
- give us feedback, comments, or reviews.
- opt in to BOUNZ Fitness, allowing Step data collection from connected devices to track fitness activities for points accrual.
Purposes for processing Your personal data
Set out below is a description of the ways We intend to Use Your personal data and the legal grounds on which We will process such data. We have also explained what Our legitimate interests are where relevant.
We may process Your personal data for more than one lawful ground, depending on the specific purpose for which We are using Your data. Please email Us at [email protected] if You need details about the specific legal ground, We are relying on to process Your personal data where more than one ground has been set out in the table below.
Purpose/Activity | Type of Data | Lawful basis for processing |
To register You as a new Member | (a) Identity (b) Contact | Entrance into a contract with You |
To process and deliver Your order including: (a) Manage payments, fees and charges | (a) Identity (b) Contact (c) Financial (d) Transaction (e) Marketing and Communications | Entrance into a contract with You |
To manage Our relationship with You which will include: (a) Notifying You about changes to Our terms or Privacy Policy (b) Asking You to leave a review or take a survey | (a) Identity (b) Contact (c) Profile (d) Marketing and Communications | (a) Entrance into a contract with You (b) Necessary to comply with a legal obligation(c) Necessary for Our legitimate interests to keep Our records updated and to study how Members use Our Platform |
To enable You to partake in a competition or complete a survey | (a) Identity (b) Contact (c) Profile(d) Usage(e) Marketing and Communications | (a) Entrance into a contract with You (b) Necessary for Our legitimate interests to study how Members use Our Platform, to develop them and grow Our business
|
To administer and protect Our business and Our site (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) | (a) Identity (b) Contact (c) Technical | (a) Entrance into a contract with You (b) Necessary for Our legitimate interests for running Our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise (c) Necessary to comply with a legal obligation
|
To deliver relevant content and advertisements to You and measure and understand the effectiveness of Our advertising | (a) Identity (b) Contact (c) Profile(d) Usage(e) Marketing and Communications (f) Technical | (a) Entrance into a contract with You (b) Necessary for Our legitimate interests to study how customers use Our Platform, to develop them, to grow Our business and to inform Our marketing strategy
|
To use data analytics to improve Our website, products/services, marketing, customer relationships and experiences | (a) Technical (b) Usage | (a) Entrance into a contract with You (b) Necessary for Our legitimate interests to define types of members for Our Platform, to keep Our site updated and relevant, to develop Our business and to inform Our marketing strategy
|
To make suggestions and recommendations to You about goods or services that may be of interest to You | (a) Identity (b) Contact (c) Technical(d) Usage(e) Profile | (a) Entrance into a contract with You (b)Necessary for Our legitimate interests to develop Our Platform and grow Our business
|
To collect and process fitness data for tracking and points accrual within the BOUNZ Fitness program | (a) Steps Data | (a) Your explicit consent (b) Necessary for Our legitimate interests in tracking progress and accruing BOUNZ. |
Sensitive
Sensitive Data refers to any personal data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for uniquely identifying an individual, data concerning health, or data concerning a natural person’s sex life or sexual orientation, or data relating to criminal convictions and offences. For the protection of Your privacy, We strongly recommend refraining from disclosing or including any sensitive personal information in Your communication with us that could potentially compromise Your privacy or security. We assume no responsibility for any unauthorized access or misuse of such information shared through Our Platform. It is always advisable to exercise caution and avoid sharing sensitive personal information in any form of communication.
By registering on the Platform or by accessing and using the Platform and by using the Services, You hereby irrevocably certify and confirm that (i) You have read the above warning, (ii) you are granting Us a final approval and consent to gather and store Your Sensitive Data or any other sensitive information, (iii) you acknowledge that Your Sensitive Data on any other sensitive information may be shared by Us with Our partners, and (iv) you explicitly release, waive, and forever discharges BOUNZ and its successors, affiliates and companies and its past, present and future assigns, officers, directors, employees, agents, subsidiaries, affiliates, shareholders, stakeholders (the “Released Parties”) of any and from any and all past, present or future claims, demands, actions, liabilities, obligations, rights, benefits, entitlements, damages, interest, cost, attorney’s fees, expenses, compensation causes of actions, of every kind and character, whether asserted or un-asserted, whether known or unknown, suspected or unsuspected, in law or in equity, for or by reason of any matter, cause or thing whatsoever, arising out or relating to the disclosing and/or sharing of Your Sensitive Data on any other sensitive information.
You have the right to withdraw Your consent for the processing of sensitive information at any time. You shall be responsible for the withdrawn data and the data that You didn’t explicitly ask to be withdrawn. Withdrawing Your consent will not affect the lawfulness of any processing carried out before the withdrawal. To withdraw Your consent or make any changes to Your sensitive information preferences, please refer to the instructions provided in the ‘Your Legal Rights’ section of this Privacy Policy.
Automatic interactions.
As You interact with BOUNZ Platform, We may automatically collect technical data about Your equipment, browsing actions and patterns. We collect this Data by using cookies and other similar technologies.
Third parties or publicly available sources.
We may receive personal Data about You from various third parties and public sources. This may include technical data from parties such as Google and Data from publicly available sources.
You acknowledge that such Personal Data was gathered lawfully by those third parties and that You granted them Your explicit consent for that. You agree to indemnify BOUNZ, its employees, agents and representatives, and to hold all defended and harmless from any claims, and liabilities including legal costs that may arise from any breach of Data performed by any of the above mentioned third parties.
Data from BOUNZ Partners and Brands
We may obtain additional personal data about You from BOUNZ Partners and Brands, who may share information gathered during their interactions with you, such as website and application usage, transaction history, participation in competitions and surveys, responses to marketing activities, engagement with other loyalty programs, and characteristics attributed to You based on Your interactions with those companies.
Data from Third-Party Data Companies
We may also receive personal data from third-party data companies that provide customer information or publicly available data, including assistance with verifying or updating Your address or companies, information about Your household profile based on modeling. Such data, received on an individual or anonymous level, may include information based on Your address or location.
Social Media and Digital Advertising
If We promote Our products or services to You through social media or digital advertising platforms like Google or Facebook, We may utilize available segmentations on those platforms to enhance the relevance of Our marketing communications to You.
HOW WE USE YOUR DATA?
We use any Data You provide Us, either through Our BOUNZ Platform, by email, feedback, comments, SMS/push messages, social media messaging, or other digital communication channels in any of the following manners:
- To provide You with personalized service;
- To operate the BOUNZ Platform;
- To manage and process bookings, inquiries, registrations and any other interactions with you;
- To provide You with information about Our services;
- For other marketing purposes where You have consented;
- To share Your personal information with Our affiliates and third-party organizations which We feel could be of interest to you, provided You agree to such sharing;
- To conduct Data analytics, including combining data from the data You provide, other users provide, third parties and across partners to build data models and identify patterns.
By registering, You consent that We will collect, process, and use information about You and any additional members within Your account. This information includes Your registration details, information about the use of Your BOUNZ Card, shopping purchases, and other information that You give us (together “Your Information”).
We undertake to refrain from (i) keeping member’s information stored longer than necessary, and (ii) using member’s Information for purposes other than to implement, administer and manage the member’s participation in the Program, or as required to comply with legal or regulatory obligations, therefore We undertake to destroy, delete, and cancel Your Information whenever those purposes are not served anymore.
Additionally, when You choose to use the BOUNZ Fitness feature and provide fitness-related data, such as Step counts and workout information, We will process this data to track the steps taken and enable points accrual within the BOUNZ Fitness program. This data is used to personalize Your fitness experience and rewards.
This information will allow us to administer the BOUNZ Program – including the management of member accounts, to accurately record and update BOUNZ balances including spending of BOUNZ. Periodically You may be asked to provide additional personal information via market research or surveys (“Member Information”). Your ‘member information’ is processed and stored in secure and confidential databases in the xx. If You choose not to provide this information, it will not affect Your ability to collect or spend BOUNZ.
Your information may be analyzed to see how You use BOUNZ, to understand Your interests and to send You (and/or additional members on Your account) information and offers for the products or services which are most likely to add value to you. When You join the program, You automatically agree to receive these communications to make the most of what BOUNZ has to offer. We protect Your information; Our business depends on it. We will only share Your information within the Company and Our Authorized Partners, including their group companies and companies contracted to process and manage transactions such as BOUNZ spend requests and other communication. The list of companies participating in the BOUNZ program is available on the BOUNZ Platform.
Should You be a resident of the European Union, You acknowledge and agree that the Services may include processing, storing, and/or managing data which is governed by legislation relating to data protection and privacy including without limitation the EU Data Protection Directive 95/46/EE and the General Data Protection Regulation. To the extent that is permitted, We undertake to comply with obligations stipulated in the legislation referenced above.
To the extent that Your data contains personal information as defined under the California Consumer Privacy Act 2018 (as amended) (“CCPA”), The Company shall (when applicable) act as a service provider with respect to such personal information and in accordance with the CCPA.
USE OF YOUR DATA FOR MARKETING AND PROMOTION
By registering on Our BOUNZ Platform, You agree to grant us Your express consent to receive promotional communications about Our services and emails announcing changes to, and new features on, Our BOUNZ Platform. If, at any time, You prefer not to receive further communications from us in any or all forms You will have the ability to unsubscribe from such communications by clicking on the link provided in every email that is sent to You by us or by emailing us at [email protected].
We may collect and use anonymized and pseudonymized data for data matching and analysis purposes.
When personal data is stripped of identifying information, it becomes anonymous. This occurs when details like names and addresses are removed, or when personal data is aggregated into groups where only information about the groups is retained (e.g., data at a postal code level or shopping behaviour analysis by age groups). Additionally, models created from personal data that identify certain traits or characteristics (e.g., customers’ likelihood to purchase a specific product or category) can also contribute to anonymized data.
Since anonymous data does not allow for the identification of individuals, it is treated differently from personal data and is not governed by this policy. We may use anonymized data for various purposes, including but not limited to improving our services, conducting research, and enhancing overall user experience.
Pseudonymized data refers to personal data that has undergone processing to ensure the removal or separation of identifying details, such as names and addresses. However, it is important to note that the data can still be linked to individuals using a separate “key” or additional information.
The purpose of pseudonymization is to enhance security and privacy by enabling individual-level data processing without relying on identifying information. Despite the removal of explicit identifiers, pseudonymized data remains classified as personal data under the scope of this policy and is subject to the applicable regulations and laws governing the processing of personal data.
By accepting this policy and utilizing our BOUNZ Platform, You acknowledge and understand the distinction between anonymized and pseudonymized data, and You consent to the collection, storage, and processing of pseudonymized data in accordance with the relevant privacy laws and regulations.
If You have any questions or concerns regarding the use of anonymous or pseudonymized data, please contact us at [email protected].
COOKIES AND SPAM
Our Cookies
- We use ‘cookie’ technology where the cookie identifies Your browser with a unique and random number.
- Cookies are small data files stored in the memory of the device You are using that help us improve our members’ experience of our BOUNZ Platform and services, identify popular features and count visits to our BOUNZ Platform.
- The cookies used by us do not reveal any personal information about you.
- Cookies use is to help us improve members experience of the BOUNZ Platform.
Spam
- We do not tolerate spam.
- To report BOUNZ Platform related spam or spoof emails, please forward the email to [email protected].
- You undertake not to use our communication tools to send spams or otherwise send content that would violate our Service or this Privacy Policy.
THIRD PARTY DISCLOSURES
You acknowledge, consent, and explicitly agree that We shall share Your personal Data with third parties for the purposes as described below.
- To operate the Platform;
- To analyse and understand how BOUNZ members use the Platform;
- To provide personalised marketing to members based on their profile;
- To manage and administer any kind of competitions or promotional events;
- To conduct surveys and market research;
- To prevent security breaches, detect and investigate fraud, or to comply with legal obligations;
- To create data models to understand user behaviour, trends and preferences.
In addition to the above, We may also share aggregated fitness data, which is anonymized and does not personally identify any individual, with third parties for potential partnerships with health and fitness-related partners. This aggregated data may be used to explore collaborations, research, and initiatives that benefit the health and fitness community.
The types of data that We may share with these third parties include:
- Account information;
- Transaction data;
- Program analytics;
- Surveys;
- Market research;
- Anonymous IDs;
- Pseudonymous datal;
- Device information, digital IDs, cookies and other tracking information.
We require all third parties to respect the security of Your personal Data and to treat it in accordance with local laws. We do not allow our third-party service providers to use Your personal Data for their own purposes and only permit them to process Your personal Data for specified purposes and in accordance with our instructions.
We do not sell or rent any of Your personal information to third parties in the normal course of doing business.
We partner with and are supported by service providers. Data will be made available to these parties only when necessary to fulfil the services they provide to us. Our third-party service providers are not permitted to share or use personal information We make available to them for any other purpose than to provide services to us. We will share personal information when We believe it is required, such as to comply with legal obligations and respond to requests from government agencies, including law enforcement and other public authorities.
INTEGRITY AND DATA RETENTION
We undertake to refrain from (i) keeping member’s information stored longer than necessary, and (ii) using member’s Information for purposes other than to implement, administer and manage the member’s participation in the Program, or as required to comply with legal or regulatory obligations, therefore We undertake to destroy, delete and cancel Your Information whenever those purposes are not served anymore including for the purposes of satisfying any accounting, or reporting requirements.
We retain Your personal information during and following the end of Your use of our BOUNZ Platform as required to comply with local laws, for technical troubleshooting requirements, to prevent fraud, to assist in any investigations and to take any other actions otherwise permitted by law.
In the event of a personal data breach as defined under the General Data Protection Regulation (“GDPR”), the data controller shall promptly notify the affected members without undue delay, and where feasible, not later than 72 hours after becoming aware of the breach, provided that the breach is likely to result in a high risk to their rights and freedoms. The communication shall be clear, concise, and written in plain language, providing a description of the nature of the breach, the categories and approximate number of affected individuals, the likely consequences of the breach, and any measures taken or proposed to address the breach and mitigate its potential adverse effects.
We have appointed Data Protection Officer (DPO) to oversee the company’s data protection practices and ensure compliance with the GDPR. If You have any questions, concerns, or requests regarding the processing of Your personal data or if You would like to exercise Your rights under the GDPR, You may contact our DPO at the following address:
Mr Abdul Rahman
04-4928869
YOUR LEGAL RIGHTS
In accordance with applicable data protection laws, including but not limited to the GDPR and CCPA, You have
Right to Access:
You have right to access Your Data We hold about You.
Right to Rectification:
You have a right to request us to correct Your Data where it is inaccurate or out of date.
Right to be Forgotten (Right to Erasure):
You have the right, under certain circumstances, to have Your personal information erased. Your information can only be erased if Your Data is no longer necessary for the purpose for which it was collected, and We have no other legal ground for processing the Data.
Right to Object to Processing:
You have the right to object to the processing of Your Data at any time, on legitimate grounds, except if otherwise permitted by applicable law, or to lodge a complaint with a supervisory authority. If You raise an objection, We have an opportunity to demonstrate that We have compelling legitimate interests which override Your rights and freedoms.
Right to Restrict Processing:
You have the right to restrict the processing of Your Data, but only where:
- its accuracy is contested, to allow us to verify its accuracy; or
- the processing is unlawful, but You do not want it erased; or
- it is no longer needed for the purposes for which it was collected, but We still need it to establish, exercise or
defend legal claims; or - You have objected to processing of Your Data, and verification of overriding grounds is pending.
Right to Decline Automated Decision Making:
Automated Decision Making refers to a decision which is taken solely on the basis of automated processing of Your personal data. This means processing using, for example, software code or an algorithm, which does not require human intervention.
You have the right to not be subject to decisions based solely on automated decision making, which produce legal or significant effects for you, except where these are:
- necessary for a contract to which You are a party;
- authorized by law;
- based on Your explicit consent.
In cases where automated decision making is based on Your explicit consent, We will seek Your prior consent before engaging in such processing. You have the right to withdraw Your consent at any time. If You withdraw Your consent, We will no longer process Your personal data for automated decision-making purposes, unless there are other legal grounds for processing.
To exercise these rights, please email us at [email protected] with a description of Your request.