Privacy Policy - Evosus®, Inc.

Last updated November 10, 2022

 

Welcome to Evosus®, provided and maintained by Evosus, Inc. (“Evosus,” or “Company,” or “We,” or “Us,” or “Our”). This Privacy Policy (or “Policy”) describes how we collect and use your information when you access or use the Evosus Services and provides you with notice about your choices and controls over that information. Evosus offers on-premise and cloud based business management software and services to help businesses streamline and grow through evosus.com and other websites we own or operate (“Site”), including our legacy software product (“Legacy Software”), cloud-based applications (“SaaS Solution”), as well as related merchant products (“Products”), and other products and services we offer (collectively the “Evosus Services”). Read more about the Evosus Services in our respective Terms of ServiceService Level Agreement (“SLA”), End User License Agreements (“EULAs”), LOUcommerce Terms of Service

Your use of the Evosus Services is subject to this Privacy Policy and the respective terms and conditions between you and us governing the Evosus Services you use. By accessing or using the Evosus Services, you consent to this Privacy Policy in its entirety and the collection and use of information as described herein. If you do not agree with this Policy, do not access or use the Evosus Services. 

If you have any questions about this Privacy Policy or our privacy practices, please send a request via support.evosus.com or contact us by email at marketing@evosus.com or by phone at  360-735-9510.

  1. Personal Information

     

    As used in this Privacy Policy, “Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal Information falls within certain categories, for example:

    • Identifiers (e.g., name, email, telephone number, address, username); 
    • Sensitive Personal Information (e.g., government identification number; precise geolocation; racial or ethnic origin; religious beliefs; health information; contents of messages when we are not the recipient; in some cases, information about a known child);
    • Legally protected information (e.g., race, citizenship, marital status, sex);
    • Employment-related information (e.g., current or past employment);
    • Non-public educational information, including information protected under the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g, 34 C.F.R. Part 99);
    • Biometrics (e.g., DNA, face/voice prints, health data) and audio, electronic, visual, thermal, or olfactory information;
    • Inferences drawn from Personal Information to create a profile about preferences, characteristics, trends, predispositions, behavior, attitudes, intelligence, and aptitudes;
    • Commercial information (e.g., products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies); and
    • Internet or other similar activity (e.g., browsing history; content interactions). 

    Information that is not protected as Personal Information includes publicly available information; aggregated information (meaning data summaries or reports with Personal Information removed); and anonymized information that cannot be linked back to an individual.    

  2. Collection and Use of Personal Information

     

    Evosus will only collect your Personal Information with your consent, if we have a legitimate interest in doing so, or as authorized or required by law. We only collect, use, retain, and disclose Personal Information as adequate and relevant to the specific, express purposes described in this Policy or as reasonably necessary and proportionate to provide the Evosus Services or for other purposes that we disclose to you and are compatible with the context of how we collected your Personal Information. 

    1. Categories of Personal Information Collected

      The categories of Personal Information we collect about you depends on your interactions with the Evosus Services, whether as a customer using the Legacy Software, SaaS Solution, or other Evosus Services for your business (“Customer”), a user registered to access the Evosus Services on behalf of a Customer (“User”) or a visitor who interacts with us through the Site or other means. In the preceding 12 months, Evosus has collected identifiers, employment information, legally protected information, commercial history, and internal and similar information. 

    2. Sources for Collecting Personal Information

      In the preceding 12 months, we have collected Personal Information from the sources and for the purposes described below:

      1. Directly from you when you register for and use the Evosus Services.

        When you register to use Evosus Services, we will collect identifiers like your name, email and password, and your employment information like business name, location, industry, and number of employees. We use this information to register your account and provide access to the Evosus Services. When you use the Evosus Services, we will collect information related to your commercial history, such as service used, and transactions completed. Additionally, users may have the option to provide us with demographic information that includes sensitive Personal Information or protected Personal Information like gender, ethnicity, or age, which we only collect with your consent and never share with third parties. We collect this information with the user’s consent and use the information to provide the Evosus Services, communicate with you about our company, and for our internal business purposes.

        If you wish to register employees or others as additional users, we will collect identifiers and other categories of Personal Information as needed to provide access to your additional users. You are responsible for ensuring that any Personal Information you provide on behalf of your additional users, or any other person is collected and submitted to Evosus in a lawful manner.

      2. Directly from you when you communicate with us.

        We may collect Personal Information directly from you online when you visit the Site or offline when you communicate with us through any means. If you submit an electronic form on our Site, place an online order for Evosus Services, apply for Evosus Financial Services, or contact our Support Center via the Site, we will collect your identifiers and other information necessary to fulfill your request, along with any other Personal Information you choose to provide as part of those communications. We collect this information with your consent and use it to provide you with the Evosus Services, information, or support that you request.

        If you submit feedback or testimonials to us, we may post your submission to the Site after giving you written notice. You may request that we remove your testimonial or other comments from the Site at any time by submitting a Consumer Privacy Requestvia email tosupport@evosus.com.

        Offline, if you interact with Evosus at a trade show and offer your business card, allow us to scan your badge, or sign-in at our booth, we will collect the Personal Information you offer to us and use that information to communicate with you about the Evosus Services and send you marketing materials. We also collect Personal Information from you when you call or write to us, and we add that information to contact you about your interest in the Evosus Services and to provide you with the information and support you request.

      3. Indirectly from your use of Evosus Services.

        In general, you can visit the Site without directly providing any Personal Information. However, we may automatically collect technical and Personal Information related to your internet activity on the Evosus Services, such as your: (i) search queries; (ii) device information (e.g., IP address, operating system, browser type, device ID, mobile network information); (iii) usage details (e.g., traffic data, communication data and the features or resources you access and use); and (iv) metadata. We may collect this information directly or through a service provider like Google Analytics. We collect this information to better understand visitor behavior, demographics, and other metrics, and to achieve our legitimate interest of providing and improving the Evosus Services. We do not link this information to your Personal Information.

      4. From referral sources and other third parties.

        We sometimes receive information about market trends and potential new business leads from referral sources like manufacturers, distributors, affiliates, and vendors offering complimentary products and services. Additionally, our Customers sometimes refer us to other businesses that might find the Evosus Services beneficial. The referrals we receive may include Personal Information for one or more individuals. In each case, we collect referral information as part of our legitimate interest to market the Evosus Services to new business leads. Evosus will only use the Personal Information collected from referral sources and other third parties to communicate with potential new business leads about the Evosus Services.

    3. Payment Information and Fees

      At registration, if you select an Evosus Service that requires payment of a fee, you will be prompted to provide payment information. All payments are processed through a secure PCI-DSS compliant third-party payment gateway. Payment information is collected via a secure connection and stored on the payment processor’s systems in a tokenized form and protected from unauthorized access by Evosus, our Customers, and third parties. We use your payment information solely to collect payments due or check your financial qualifications for the Evosus Financial Services, as applicable.

    4. Other ways we use the Personal Information we collect

      In general, we use the Personal Information we collect to provide you with the Evosus Services, process transactions, offer Customer support, or deliver service communications. We may also use this information for any purpose with your consent or to: (i) analyze trends, (ii) operate, improve, and maintain the Evosus Services; (iii) administer promotions; (iv) for our recordkeeping or other internal business purposes; (v) to enforce our rights or the rights of others; or (vi) if we believe it is necessary, to identify, contact, or bring legal action against persons or entities who may be causing injury to you, to us, or to others.

  3. Evosus Customers’ Privacy Practices

     

    Our Customers use our Legacy Software, SaaS Solution, LOUcommerce, and other Evosus Services to streamline and automate their businesses. Customers may use the Evosus Services to collect Personal Information about their own consumers. Evosus has no control over the type or scope of Personal Information collected, used or stored by our Customers (“Customer Collected Information”). Customer Collected Information belongs to the Customer and is collected, processed, stored, shared, and disclosed by each Customer according to its own terms of use and privacy policies. Evosus has no direct relationship with the consumers whose Personal Information is collected and processed by our Customers. Customer Collected Information is not subject to this Privacy Policy, and Evosus is in no way responsible for such Customer Collected Information.

  4. Children’s Privacy

     

    The Evosus Services are not intended for or targeted at children under the age of eighteen (18) (“Minors”). Evosus does not knowingly or intentionally collect any Personal Information from Minors. If we discover that a Minor has provided us with Personal Information, we will delete that information from our systems. If you believe we might have any information collected online from a Minor, or if you become aware of any unauthorized submission of information to us, please contact us at marketing@evosus.com.

  5. Retention of Personal Information

     

    Evosus retains the Personal Information we collect only for as long as is necessary to fulfill the purposes of collection or our internal business or other lawful purposes. When we have no ongoing legitimate business need to process your Personal Information, we will securely delete the information or anonymize it. If this proves infeasible for any reason, we will instead securely store your Personal Information and isolate it from any further processing until deletion is possible.

  6. Disclosure of Personal Information

     

    We will not disclose your Personal Information, whether directly or indirectly, to any third party except as described in this Privacy Policy or with your consent. Evosus will only disclose Personal Information to the third parties as described in this section, with your permission, or as required by law. In the preceding 12 months, we have disclosed all categories of Personal Information that we have collected to a third for a business purpose. The third parties that may receive Personal Information for a business purpose include:

    1. Referral Sources

      We work with select referral sources like manufacturers, distributors, affiliates, and vendors offering complimentary products and services to collaborate in joint marketing activity. We may share our Customers’ contact information, which may include Personal Information, with these referral sources to offer you co-branded services that may be of interest to you. You may request that Evosus refrain from disclosing your contact information to our referral sources by submitting a Consumer Privacy Request.

    2. Service Providers

      Service providers engaged by Evosus may have access to your Personal Information to perform their contractual obligations to us. Our service providers include but are not limited to marketing companies, IT service providers, payment processors, and email and data hosting providers. We prohibit our service providers from selling or disclosing the Personal Information we provide, and we require all service providers to maintain confidentiality standards and appropriate technical and organizational measures to ensure the security of your Personal Information.

    3. Affiliates

      We disclose the information we collect from you to our affiliates or subsidiaries. If we do disclose your Personal Information to our affiliates or subsidiaries, their use and disclosure of your Personal Information will be subject to this Privacy Policy.

    4. Law Enforcement and Third Parties

      Under certain circumstances we may disclose your Personal Information to other third parties, as required or permitted by applicable law. For example, we may be required to disclose Personal Information in response to a legal requirement, investigation, or court order. If Evosus goes through a business transition (e.g., merger, acquisition, or sale of a portion of our assets), or if we believe disclosure is appropriate to defend our legal claims, take action regarding illegal activities, or prevent fraud or harm to any person, we may disclose certain Personal Information to third parties. Additionally, Evosus may disclose your Personal Information to any third party if we have your consent.

    5. Aggregated and Deidentified Information

      Evosus reserves the right to share aggregated, anonymized, or deidentified information about any individuals with nonaffiliated entities for marketing, advertising, research, or other purposes, without restriction.

  7. Cookies and Similar Technologies

     

    Cookies are small text files downloaded and stored on your device when you visit a website or other platform. Cookies are generally used for functionality, security, analytics, or advertising. Some cookies are strictly necessary to the function of the website or other platform, while others enable certain features.

    From time to time, we may use cookies and other tracking technologies on the Site to track engagement, manage, and improve the Site. We use the information collected by cookies to analyze trends, track users’ movements around the Site, and administer the Site. We do not link automatically collected data by cookies and log files to Personal Information. This data typically does not include Personal Information but may be maintained or associated with your Personal Information. Third parties may also set cookies on our Site to collect information about you when you use the Site. We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly.

    On your device, you can set your browser or device to refuse all or some cookies or to alert you when cookies are being sent. You can also install third-party plugins to control cookie behavior. If you disable or refuse cookies or block the use of other tracking technologies, some parts of the Site may then be inaccessible or not function properly. If you get a new device, install a new browser, or erase or otherwise alter your device’s cookie file or privacy settings, your privacy preferences may not be saved. If you disable or refuse cookies or block the use of other tracking technologies, you will be able to use certain features, but some or all features may not function properly.

  8. Controlling Your Personal Information

     

    Evosus provides you mechanisms to exercise certain controls and choices regarding our collection, use, and sharing of your Personal Information.

    1. Your Account

      If you are a Customer or user, you can review, update, change, or delete your Personal Information by logging into your account. If you delete your Personal Information (or ask us to delete it for you), copies may remain viewable in cached and archived pages or might have been copied or stored by other Evosus users in compliance with applicable law. Note that if you delete information that you previously made public on the Site or other platforms, copies of that information may remain viewable to others who have seen or downloaded it, or in cached and archived pages of those websites. We have no control and are not liable for access to, or copies made of, Personal Information prior to the date you delete it.

    2. Emails

      We may send you promotional emails or alerts regarding service changes. You may unsubscribe from Our marketing, sales, and promotional communications by clicking on the "unsubscribe" link located on the bottom of the e-mail, updating your communication preferences in your account, or sending an email request to marketing@evosus.com. We may send you an email on behalf of one of our Customers who has invited you to register for Evosus Services. You may opt out of receiving these emails at any time by clicking on the “unsubscribe” button located at the bottom of the email. You cannot unsubscribe from emails regarding your Evosus account unless you delete your account.

    3. Text or SMS

      If you provide us with your wireless phone number, you consent to Evosus sending you informational text messages. The number of texts that we send to you will be based on your circumstances and the services you request from us. You can unsubscribe from text messages by replying STOP or UNSUBSCRIBE to any of these text messages. Messaging and data charges may apply to any text message you receive or send. Please contact your wireless carrier if you have questions about messaging or data charges.

    4. Communications from Referral Sources

      If you interact with one or more of our referral sources, those referral sources may send you marketing or other communications. Referral sources are solely responsible for their own privacy practices, including the marketing emails and other communications they send to you. Evosus is not able to unsubscribe you from these communications. Please contact the referral source directly if you wish to change your preferences for these communications.

    5. Do Not Track

      Do Not Track signals are signals sent through a browser informing us that you do not want to be tracked. Currently, our systems do not recognize browser “do-not-track” requests. If this changes in the future, we will update this Privacy Notice.

    6. Consumer Privacy Requests

      To exercise your privacy rights beyond the methods made available in the Evosus Services, express concerns, lodge a complaint, or obtain additional information about the use of your Personal Information, please submit a verifiable Privacy Request via support.evosus.com or by emailing support@evosus.com.

      Evosus can only assist with or fulfill a privacy request when we have sufficient information to verify that the requester is the person or an authorized representative of the person about whom we have collected Personal Information, and to properly understand, evaluate, and respond to the request. We do not charge a fee to process or respond to a verifiable request unless we have legal grounds to do so. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request. We endeavor to respond to privacy requests in accordance with the requirements of the law applicable to your jurisdiction. If we do not fulfill your request within the legally required timeline, you can appeal our response by contacting support@evosus.com.

      Note that if your Personal Information was entered into the Evosus Services by one of our Customers, then we process your Personal Information in our capacity as a service provider and cannot fulfill your request directly. In that case, we will relay your request to the respective Customer for further processing and fulfillment.

  9.  Notice of Privacy Rights

     

    In the United States, consumer privacy is governed by federal privacy laws covering specific industries or data uses and state privacy laws providing with general consumer privacy rights. This section provides informational notices for privacy laws governing states like California (the “CCPA”), Colorado, Connecticut, Nevada, Utah, Virginia, and other states require companies to inform consumers about their privacy rights and provide a method to exercise those rights. Residents of states offering privacy protections (each a “Consumer”) can exercise their privacy rights as applicable to our Services by submitting a Privacy Request. Evosus will respond to and fulfill your request to the extent required by applicable law.

    1. Right to Access

      You have the right to request confirmation that we have collected Personal Information about you and that we provide you with access to that Personal Information. If you submit an access request, we will provide you with copies of the requested pieces of Personal Information in a portable and readily usable format. Please note that Evosus may be prohibited by law from disclosing certain pieces of Personal Information, and we may be limited in the number or frequency of requests we must fulfill.

    2. Right to Correct

      You have the right to request that we correct inaccurate Personal Information about you on our systems. If you become aware that the Personal Information that we hold about you is incorrect, or if your information changes, please inform us and we will update our records.

    3. Right to Deletion

      You have the right to request that we delete your Personal Information that we collected and retained, with certain exceptions. Evosus may permanently delete, deidentify, or aggregate the Personal Information in response to a request for deletion.

    4. Right to Disclosure

      You may request that we disclose information to you about our collection and use of your Personal Information, such as: (i) the categories of Personal Information we have collected about you; (ii) the categories of sources for the Personal Information we have collected about you; (iii) our business purpose for collecting, using, processing, sharing or selling that Personal Information, as applicable; (iv) the categories of third parties with whom we share that Personal Information; and (v) if we sold or shared your Personal Information under the CCPA, two separate lists stating: (A) sales or sharing, identifying the Personal Information categories that each category of recipient purchased; and (B) disclosures for a business purpose, identifying the Personal Information categories that each category of recipient obtained. Certain laws may limit the number or frequency of requests we must fulfill.

    5. Limited Use and Disclosure of Sensitive Personal Information

      You have the right to opt-out or limit our use of your sensitive Personal Information. Evosus does not seek to collect sensitive Personal Information about any individual, and in no case do we disclose any sensitive Personal Information for the purpose of inferring characteristics about you or otherwise use your sensitive Personal Information without your consent. If this ever changes in the future, we will update this Privacy Notice and provide you with methods to opt-out or limit our use and disclosure of sensitive Personal Information.

      However, we have no control over whether our Customers may use or disclose sensitive Personal information for any particular purpose. Please direct any questions about your sensitive Personal Information to the respective Customer.

    6. No Selling or Sharing

      Some states entitle consumers to opt-out of the sale or sharing of Personal Information or targeted advertising practices. Evosus does not sell your Personal Information or share your Personal Information with third parties for cross-contextual advertising purposes. If this ever changes in the future, we will update this Policy and provide you with methods to opt-out of such sale and sharing.

      Note, however, that we have no control or responsibility over whether an Evosus Customer may sell or share Personal Information the Customer collects via the Evosus Services. Please direct any questions about sale or sharing of Personal Information to the respective Customer.

    7. No Profiling

      You have the right to opt-out of automated profiling. Evosus does not process your Personal Information to evaluate, analyze, or predict your interests and preferences or otherwise use automated profiling to produce significant effects that concern you. If this changes in the future, we will update this Privacy Notice and provide you with a method to opt-out.

    8. Right to Nondiscrimination

      We will not discriminate against you for exercising your privacy rights. For example, unless permitted by law we will not: (i) deny you goods or services; (ii) charge you different prices or rates for goods or services; (iii) provide you a different level or quality of goods or services; (iv) retaliate against you as an employee, applicant for employment, or independent contractor for exercising your privacy rights; or (v) suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services, because you exercised a right under applicable privacy laws.

    9. Right to Disclosure of Marketing Information

      California’s Shine the Light Act (Civil Code sections 1798.83-1798.84) entitles California residents to request certain disclosures regarding Personal Information sharing with affiliates and/or third parties for marketing purposes.

      If you are a Consumer, you may exercise these rights by submitting a Privacy Request. Only you or someone legally authorized to act on your behalf may make a verifiable Privacy Request related to your Personal Information. You may also make a verifiable privacy request on behalf of your minor child. You may designate a third party to exercise your rights – an authorized agent – however we will require written proof of the authorization and potentially proof of your identity.

  10. Security of Your Personal Information

     

    We work to protect your Personal Information by using reasonable and appropriate technical, administrative, and physical security practices and procedures to help protect Personal Information from unauthorized or illegal access, destruction, use, modification, or disclosure. We maintain internal policies to govern the collection, processing, access, and handling of data. Our security measures are appropriate to the volume, scope, and nature of the Personal Information processed and designed to meet our duty of care with respect to your Personal Information.

    Evosus computer systems are hosted in a secure data center environment that uses a firewall, intrusion detection systems, and other advanced technology to prevent interference or access from outside intruders. The data center is a highly protected environment with several levels of physical access security and twenty-four (24) hour surveillance. Access to Personal Information is restricted in Our office(s) and only employees, Evosus affiliated service providers, engineers, developers, and/or independent contractors who need the information to perform a specific job, are granted access to your Personal Information. Employees and independent contractors who violate our privacy safeguards are subject to disciplinary action, including termination. Evosus employees responsible for handling user inquiries are informed of applicable privacy law requirements.

    All information you provide to us is secured using industry standard measures, including encryption where appropriate. Secure areas of the Site are protected using server authentication and data encryption including Secure Sockets Layer (SSL) technology to ensure that data is safe, secure, and available only to authorized persons. Personal Information input to the SaaS Solution is stored and managed on secure servers and third-party hosting services. Personal Information input to our Legacy Software is stored and managed on the servers of the Customer using the Legacy Software according to the Customer’s privacy practices. 

    Please note, however, that no transmission of data over the Internet or mobile platforms is 100% secure, and we cannot guarantee absolute security or that unauthorized third parties will not defeat our security measures or use your Personal Information for improper purposes. To use certain Evosus Services, you will have a login and password. We encourage you to take steps to protect against unauthorized access to your password, phone, and computer by, among other things, signing off after using a shared computer, choosing a robust password that nobody else knows or can easily guess, and keeping your login and password private. We are not responsible for any lost, stolen, or compromised passwords, or for any activity on your profile via unauthorized activity.

  11. Data Transfers

     

    Evosus is owned and operated in the United States and is intended for use by users living in the United States or Canada. We do not warrant that Evosus is appropriate or authorized for use in any other jurisdictions. If you use Evosus from outside of the United States, Personal Information we collect about you will be transferred to our servers in the United States and maintained there indefinitely. This may require the transfer of your Personal Information out of your country of origin with laws governing data collection and use that may differ from or be more restrictive than U.S. law, or may result in governments, courts, law enforcement, or regulatory agencies having access to or obtaining disclosure of your Personal Information pursuant to the laws of the applicable foreign jurisdiction. You are responsible for determining whether this Policy and Evosus comply with the laws that apply to you. By allowing us to collect Personal Information about you, you consent to the transfer and processing of your Personal Information as described in this paragraph.

  12. Social Media Features

     

    If you access the Site via a social networking platform (e.g., Facebook, LinkedIn), we may receive your Personal Information from that platform according to the platform’s terms and privacy practices. Additionally, our Site may include social media features either hosted by a third party or hosted directly on the Site, such as a “like” button, sharing buttons, or interactive mini-programs that run on our Site. These features may collect technical data or Personal Information related to your use of the features. Your interactions with these features are governed by the privacy policy and other policies of the companies providing them. Evosus does not control these features and they are not governed by this Privacy Policy.

  13. External Websites

     

    This Policy applies only to information collected by us when you use Evosus Services. We may provide links to third-party websites for your convenience, but we have no ability to control, and we are not responsible for, the privacy and data collection, use, and disclosure practices of third parties. Any access to and use of linked websites is not governed by this Privacy Policy, but instead is governed by the privacy notices of those websites. Evosus is not responsible for the privacy practices of any third party. We encourage you to review and understand the privacy policies of such websites before providing them with any information.

  14.  General

    Additional, separate terms and conditions may apply to certain Evosus Services. Our affiliates, service providers, referral sources, manufacturers, distributors, licensors, or third-party websites may also have privacy policy terms, restrictions, limitations and data collection, and protection practices that apply to your use of their products and services, with which you are solely responsible for review and compliance. Nothing in this Policy shall be deemed to confer any third-party rights or benefits. Evosus is not liable for the data collection, storage, and usage practices of any third party.

    If we make material changes to our privacy practices, we will post a revised Privacy Policy on this page. Your continued use of the Evosus Services after we post the revised Policy is deemed to be your acceptance of those changes. The date that this Privacy Policy was last revised is identified at the top of the page. You are responsible for periodically visiting this page to check for any changes to our privacy practices.