Legal & PCI
Last Updated: December 2022
Splitit is committed to your right to privacy. Reference to “Splitit” “we,” “us” or the “Company” is a reference to Splitit Ltd. and the relevant affiliates or subsidiaries involved in the data processing activity, including the collection, holding, use and disclosure of Personal Data.
We also process Personal Data on behalf of Merchants with respect to transactions made by Merchant’s individual customers via the Splitit Solution (“Consumer”). If you are a Consumer, we are a data processor of your Personal Data on behalf of the Merchant, who is the data controller.
Each of the Visitors, Merchant and Consumer shall also be referred to herein as “you” or “User”.
- You are not required by law to provide us with any Personal Data (defined below). Sharing Personal Data with us is entirely voluntary. However, certain Personal Data is required for us to provide the Srevices to you. If you do not provide such Personal Data, we will not be able to provide the Services to you.
- Our Website and Services are intended for Users over the age of 16, or equivalent minimum age for either providing consent to processing of Personal Data or using the Services in the relevant jurisdiction. Users under such age are not permitted to use the Services. If you are under such age you should cease to use the Services immediately. In certain jurisdictions using the Services may be restricted for Users under the age of 21.
- In certain jurisdictions you may be entitled under applicable law to request, review of access to, or amendment, correction erasure or restriction of the Personal Data held by us or the processing of your Personal Data. Please note that in case you request to erase, or restrict the processing, or withdraw consent to the processing of your Personal Data, your use of the Services may be restricted or disabled. You may be entitled to exercise additional rights under the CCPA, please refer to our User Rights Policy.
- We do not sell, trade, or rent Users’ Personal Data to third parties. We only share Personal Data with third parties in connection with the provision of the Services to our Users, or other limited circumstances as specified herein.
- What is Personal Data, and what data is collected about me by Splitit?
“Personal Data” or “Personal Information” (will be referred together as “Personal Data”), means any information about an identifiable individual or that identifies or can be used to identify a natural person, including, but not limited to, first and last name, phone number, email address, online identifiers, IP address, billing information, information concerning households, devices etc.
“Non-Personal Data”, means non-identifiable aggregated data, such as technical data transmitted by the user’s device and aggregated use of the website. This data is not used to identify individuals.
Personal Data is only used for limited purposes, as specified below:
|Type of user and type of Data
|Purposes for which we may collect, use or disclose this Personal Data
|For EU persons – Legal Basis under the GDPR
If you register as a Merchant to our Services, we will collect, use and disclose your information during the registration process. Such information includes, but is not limited to, your name, position, region, company, email address, contact details of your contact person, financial information (e.g., bank account details), etc. This information is collected from you directly when you engage with us (for instance when executing an agreement with us or signing a purchase order).
We collect this information directly from you when you ask for a demo or when you engage with Splitit in a merchant agreement.
We collect technical information transmitted by your device when using the Website and/or Services, this information includes: type of the operating system and device used to access the Website and/or Services, date and time stamp, language preferences, approximate geolocation (i.e., country/state), and your actions such as page views, search queries, etc.
In addition, when you access the Services, we collect your IP address (“Online Identifiers”). Note that, while the Online Identifiers are considered Personal Data in many jurisdictions (such as the EEA, Canada and in California), there are some jurisdictions in which such data sets is not considered as Personal Data. We treat the Online Identifiers as Personal Data, in accordance with applicable laws.
This information is collected automatically from you when you are using the Website and Services.
In case you are using the Services as a Consumer, we may receive this information directly from the Merchant from whom you purchased a product using the Splitit Solution.
|Consumers Using the Splitit Solution
When you use the Services, namely the Splitit Solution to pay for purchases you made through the Merchant’s platform (e.g., monthly installments), we collect use and disclose certain information about you. Such information includes, your full name, address, email, phone number, billing information (such as billing address, credit card number, expiration date, etc.). In your first use of the Services we will create for you a user account in Splitit. For this purpose you will receive an email with your account details. ~by using your account details you can view your purchases made through the Splitit Solution, change your credit card details, pay the balance of your account, etc.
We will collect use and disclose additional information about you when you pay via the Splitit Solution, such information includes, your shopping history, products and services purchased from the Merchant, purchase details (e.g., payment schedule and name of the Merchant), in each case limited to purchases made via the Splitit Solution.
The above mentioned information may be collected directly from you when you pay with the Splitit Solution, or transferred to us by the Merchant you are making the purchase from, depending on the process of implementation of the Splitit Solution in the merchant’s payment process.
|To provide you with the Services, and enable you to pay for goods and services offered by the Merchants in installments (via the Splitit Solution). To provide Merchants (our clients) with the Services, therefore we will share with our Merchants information we collected from you.
To resolve any disputes, communicate with you regarding customer service and support issues and to respond to questions or comments and help resolve any problems.
|Necessity of processing for the purposes of the legitimate interests of Splitit.
To perform the contract which the Consumers is a party.
In order to take steps at the request of the Customer prior to entering into a contract.
To fulfill our legal obligations.
|Surveys and Service Review
We may collect, use and disclose information when you participate and respond to surveys, provide your feedback to service review forms, rate or review the Services (“Survey”). For this purpose we will collect and use your email address.
We also collect, use and disclose the information provided during the Surveys, such as your experience while using the Services, including your feedback on the process and customer support. Information regarding your age, range, gender, payment preferences, income, etc.
We may link the information collected in the survey to information we already have about you, such as which type of payment card you used with the Splitit Solution, the Merchant you were purchasing from, Merchant location, your location, etc. We will link the above-mentioned information to the information we have on you (only to the extent we have) in order to analyze and get insights regarding transactions made with our Services and in order to improve our Services.
This information may be requested by us directly or by our service providers who provide us with third party Survey services.
|We will use your email to send you Surveys, and if applicable to send your any vouchers or coupons.
We will use this information in order to improve our Services and products, understand if there are any difficulties or failures in the process, analyzing the Services, enhancing your experience, improving our customer service and your user experience.
We also collect this information for our statistics and analytics purposes and make the Services customized for our Consumers.
|Contact Us Information
If you contact us via the “Contact Us” feature available through the Website our otherwise, we may collect certain information regarding you, such as your full name, your email, your phone number, your position (e.g., Consumer or Merchant) your company (if applicable to you), country, the content of your massage, etc.
We collect this information directly from you when you contact us.
|To answer your queries and provide you with the services you requested from us.
If you voluntarily subscribe to our newsletter through the Website, you will be requested to provide us with your email address. You can unsubscribe at any time using the unsubscribe option within the body of the applicable email or by contacting us directly. Please note that we may send you newsletters in case we are allowed based on other legal bases.
|We use this information solely to provide you with the content you have requested.
In addition, we may use certain of the above-mentioned Personal Data in order to prevent potentially prohibited or illegal activities, fraud, misappropriation, infringements, identity theft and any other misuse of the Services and to enforce our rights against you, as well as to protect the security or integrity of our databases and Services. Such use and disclosure is based on our legitimate interests or based on legal obligation.
We do not knowingly collect or use or disclose any Personal Data included in Special Categories of Personal Data (as defined in the GDPR). In the event you become aware that such data has been posted to the Website or collected by us, please inform us immediately.
Non-Personal Data is used mainly for click stream analysis in order to constantly improve and maintain our Website and Services, including among others, in order to measure and understand the level of engagement to our Services, for general business analytics and in order to provide a more personalized experience and tailored content, for ensuring the technical functioning of our network, to help prevent fraudulent use of our Services and for developing new services and features.
- Will Splitit Share My Personal Data With Others?
WE DO NOT SELL OR RENT ANY OF YOUR PERSONAL DATA TO NON-AFFILIATED THIRD PARTIES FOR THEIR MARKETING PURPOSES.
- Non-Personal Data, aggregate and statistical or otherwise anonymized data may be shared without limitation with third parties at our discretion. This information does not contain Personal Data and is used to develop content and Services for our Users and Merchants.
- We share Personal Data only under the following limited circumstances:
- With partners who are an integral part of our Services, such as the Merchant you placed a purchase with, credit card processors, acquirers, banking institutions, payment gateway, lenders etc.
- With trusted third parties who assist us in operating the Services and conducting our business. Such as service providers who provide us with fraud prevention services, customer support call center services, debt collection agencies, account maintenance, marketing services, survey services and platforms, and technology services.
- With our affiliates and connected companies, such as subsidiaries to provide you with information about products and services that we or they believe may be of interest to you.
- For personalizing your experience of the Services, including by way of targeted advertising on the Website.
- As necessary to help detect and prevent potentially illegal acts and fraud, and to guide decisions about the products, services and communications.
- Credit bureaus and collection agencies to report account information, as permitted by law.
- To comply with a legal requirement, for the administration of justice, to protect your vital interests or the vital interests of others, to protect the security or integrity of our databases or the Services, to take precautions against legal liability, or in the event of a corporate sale, merger, reorganization, dissolution or similar event.
- Other third parties with your consent or direction to do so.
- Will Splitit transfer my Personal Data internationally?
Personal Data may be disclosed to an entity in the Splitit corporate group that is incorporated in Israel (“Splitit Israel”). Personal Data will be held on servers located in the U.S.
Therefore, your Personal Data may be stored or processed in countries in which the privacy laws provide for a different level of protection for your Personal Data than that which exists in your country of residence.
The European Commission has decided that the State of Israel ensures an adequate level of privacy and data protection, therefore, in accordance with the GDPR, the transfer of Personal Data from the EU to Israel is lawful and does not require any specific authorization.
Any other transfer of Personal Data originating from the EU to a third country (other than Israel) shall be made in accordance with applicable law, including by providing adequate protections, or otherwise implementing appropriate safeguards to ensure the protection of our Users’ rights.
If you would like to receive more information about our practices and policies with respect to our use of service providers and the jurisdictions in which they are located, please get in touch with us using the contact information provided below.
- Will I receive promotional materials from Splitit?
We may send Users of the Services or Users who provided us with their consent with information on new products, features, activities, services and periodic announcements or newsletters. You may opt-out any time from such communications by either: (i) using an “unsubscribe” feature available within the message; or (ii) sending us an email to: [email protected] asking to opt-out.
- Persons under 16
Our Website is a general audience Website, which is not directed to persons under 16 years old. If a parent or guardian becomes aware that his/her child has provided us with Personal Data without their consent, he/she should contact us immediately. We do not knowingly collect or solicit Personal Data from people under 16 years old. If we become aware that a person under 16 years old has provided us with Personal Data, we will delete such data from our databases. Please note, in certain jurisdictions you may be banned from using the Splitit Solution unless you are 21 years old.
- Users rights with respect to Personal Data
Subject to applicable law requirements, we will provide individuals with the opportunity to exercise their rights regarding their Personal Data. Individuals’ principal rights under data protection and privacy laws may include (you may have some or all of these rights depending on your jurisdiction):
- the right to confirm whether or not we hold your Personal Data.
- the right to access your Personal Data and being provided with a copy of the Personal Data that we hold, and the right to rectification of your Personal Data.
- The right to request access to the Personal Data that we hold about you and correct it if it is inaccurate, incomplete or out of date. If we do not give you access to your Personal Data or we do not agree to your request for correction, we will provide you with reasons why. If you are not satisfied with our decision or reasons, please see Section 11 below. If we agree to grant you access or to correct your Personal Data, usually we will do this as soon as reasonably practicable following receipt of your request.
- the right to erasure of your Personal Data.
- the right to restrict the use and disclosure of your Personal Data.
- the right to object to collection, use or disclosure of your Personal Data.
- the right to data portability.
- the right to complain to a supervisory authority (in the event that you are a European Economic Area (“EEA”) resident); and
- the right to withdraw consent.
For California and EU residents, please Please review our User Rights Policy regarding your rights under applicable law.
You may exercise any or all of your above rights in relation to your Personal Data (including to request access to and/or correct your Personal Data held by us) by filling out the Data Subject Request Form (“DSR”) and send it to our privacy team at: [email protected].
We may request additional information from you when you contact us with a DSR in order to: (i) verify your identity; (ii) determine the applicable laws apply to you; (iii) and locate your data.
It may take time to process requests in a way that is consistent with applicable privacy law.
- How does Splitit protect my data?
Splitit implements measures to reduce the risks of loss of information and unauthorized access or use of information. We adopt appropriate and generally accepted data collection, storage and processing practices and security measures to protect against unauthorized access, alteration, disclosure or destruction of your Personal Data. In particular, your payment information is secured in accordance with the PCI-DSS standard. However, these measures are unable to provide absolute information security. Therefore, although efforts are made to secure your personal information, it is not guaranteed and you cannot reasonably expect that the Service and its related databases will be immune from any wrongdoings, malfunctions, unauthorized interceptions or access, or other kinds of abuse and misuse.
- Data Retention
Unless you instruct us otherwise and subject to applicable laws, we retain the information we collect for as long as needed to provide our services and to comply with our legal obligations, resolve disputes and enforce our agreements if applicable.
- Applicable Laws
- Questions or concerns regarding privacy
If you have any questions or concerns regarding privacy issues, please send us a detailed message to [email protected] and we will make every effort to resolve your concerns without delay.
For Australian residents, if you feel that your complaint has not been adequately resolved, you are able to contact the Office of the Australian Information Commissioner on the details below:
- PRIVACY NOTICE FOR CALIFORNIA RESIDENTS UNDER THE CALIFORNIA CONSUMER PRIVACY ACT
TYPES OF PERSONAL INFORMATION WE COLLECT
Under the CCPA, “Personal Information” is defined as any information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household or device. The categories of Personal Information that we collect (and has collected within the last 12 months), are detailed in the table below.
Please note that, under the CCPA Personal Information does not include: publicly available information from government records and de-identified or aggregated consumer information, information excluded from the CCPA’s scope (e.g., health or medical information covered by applicable laws such as the Health Insurance Portability and Accountability Act of 1996 (HIPAA)); and information covered by certain sector-specific privacy laws (e.g., the California Financial Information Privacy Act (FIPA)).
|A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers.
|B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
|A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.
Some personal information included in this category may overlap with other categories.
|C. Protected classification characteristics under California or federal law.
|Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
|D. Commercial information.
|Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
|E. Biometric information.
|Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.
|F. Internet or other similar network activity.
|Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement.
|G. Geolocation data.
|Physical location or movements.
|H. Sensory data.
|Audio, electronic, visual, thermal, olfactory, or similar information.
|I. Professional or employment-related information.
|Current or past job history or performance evaluations.
|J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).
|Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.
|K. Inferences drawn from other personal information.
|Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
HOW WE COLLECT INFORMATION
Depending on the nature of your interaction with us, we may collect the above detailed information from you, as follows: (i) directly from you, for example, when you place an order via Splitit Solution on Merchant’s platform; (ii) automatically when you visit our Website; (iii) from third-party business partners such as analytics providers.
USE OF PERSONAL INFORMATION
We may use, or disclose the Personal Information we collect for one or more of the following business purposes:
- To fulfill or meet the reason you provided the information. For example, if you contact us with an inquiry and share your name and contact information, we will use that Personal Information to respond to your inquiry.
- To provide, support, personalize, and develop our Website and Services, as well as improve our Website and Services.
- For security and fraud detection purposes, and to maintain the safety, security, and integrity of our Site Services.
- For testing, research, analysis, and product development, including to develop and improve our Website and Services.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to you when collecting your Personal Information or as otherwise set forth in the CCPA.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding.
We will not collect additional categories of Personal Information or use the Personal Information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
SHARING AND SELLING DATA
We may disclose your Personal Information to a third party for a business purpose. When we disclose Personal Information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that Personal Information confidential and not use it for any purpose except performing the contract.
We share your Personal Information with the following categories of third parties:
- We share your Personal Information with our service providers (such as AWS our cloud storage services and our customer support call center service provider)
- We share your Personal Information data aggregators (such as Google Analytics)
- We share your Personal Information to our business partners (such as when you purchase through Merchant’s platform via Splitit Solution we share information with the Merchant).
DISCLOSURES OF PERSONAL INFORMATION FOR A BUSINESS PURPOSE OR FOR SELLING PURPOSES
In the preceding twelve (12) months, the Company has disclosed the following categories of Personal Information for a business purpose:
Category A: Identifiers.
Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
Category D: Commercial information: Commercial Information
Category F: Internet or other similar network activity.
Category G: Geolocation data.
SALES OF PERSONAL INFORMATION
In the preceding twelve (12) months, Company has not sold Personal Information.
YOUR RIGHTS REGARDING YOUR PERSONAL INFORMATION
The CCPA provides consumers with specific rights regarding their Personal Information. Please review our User Rights Policy regarding your rights under applicable law.
By sending us email at: [email protected].
By regular mail at: Splitit USA Inc. 5901 Peachtree Dunwoody Road, Suite C-480, Atlanta, GA 30328.