Privacy Policy

Privacy Policy

\HOCKEY WESTERN NEW YORK, LLC PRIVACY POLICY \

TABLE OF CONTENTS:

Privacy Policy. 1

  1. INFORMATION WE COLLECT ABOUT YOU.. I.
  2. Information You Provide to Us. I,A.
  3. Sensitive Information. I,B.
  4. Information We May Automatically Collect About You. I,C.
  5. Cookies & Technologies Used to Collect Information About You. I,C,1.
  6. Information We May Receive from Third Parties. I,D.
  7. HOW WE USE YOUR INFORMATION.. II.
  8. Use and Purpose of Processing Your Information. II,A.
  9. Sharing Your Information. II,B.
  10. Categories of Information Sold. II,C.
  11. LINKS TO OTHER WEBSITES.. III.
  12. INFORMATION SECURITY.. IV.
  13. DATA RETENTION.. V.
  14. HOW WE WILL CONTACT YOU.. VI.
  15. YOUR INFORMATION CHOICES.. VII.
  16. DATA SUBJECT REQUESTS.. VIII.
  17. NOTICE TO CERTAIN RESIDENTS OF DATA SUBJECT RIGHTS.. IX.
  18. NOTICE TO CALIFORNIA RESIDENTS.. IX,A.
  19. Your Rights under CCPA.. IX,A,1.
  20. Authorized Agent IX,A,2.
  21. Notice of Financial Incentive. IX,A,3.
  22. Additional Information. IX,A,4.
  23. NOTICE TO INDIVIDUALS IN THE EUROPEAN ECONOMIC AREA
    AND THE UK.. IX,B.
  24. Identity and Contact Details of Controller IX,B,1.
  25. Your Data Protection Rights. IX,B,2.
  26. Lawful Basis for Processing Your Information. IX,B,3.
  27. Consent to Transfer IX,B,4.
  28. Retention. IX,B,5.
  29. EXERCISING YOUR DATA SUBJECT RIGHTS.. X.
  30. GEOGRAPHIC LOCATION OF DATA STORAGE AND PROCESSING.. XI.
  31. CHILDREN'S INFORMATION.. XII.
  32. DIFFICULTY ACCESSING OUR PRIVACY POLICY.. XIII.
  33. “DO NOT TRACK” SIGNALS.. XIV.
  34. CHANGES TO THIS PRIVACY POLICY.. XV.
  35. HOW TO CONTACT US.. XVI.

Hockey Western New York, LLC, together with its affiliates including, but not limited to, Buffalo Sabres Foundation (hereinafter referred to as “HWNY,” “us,” “we,” “our,” or “Company”) has created the following Privacy Policy for when you visit our website at www.nhl.com/sabres, mobile and other applications, and any other online services where this Privacy Policy is posted (collectively, our “Services”). This Privacy Policy describes, among other things, the types of information we collect from users when you use our Services, how we use it, and how you can access your information.

This Privacy Policy is integrated into our Terms & Conditions of Use(“Terms & Conditions”).

By using the Services and providing us with your personal Information (defined below), you agree to the practices described in this Privacy Policy and Terms & Conditions referenced below and to the updates to these policies posted here from time to time.

Please note that our privacy practices are subject to the applicable laws depending on where you are visiting our Services from. Please see the Data Subject Requests Section and Notice to Certain Residents of Data Subject Rights Section of our Privacy Policy for your rights and how to exercise them for users located in specific geographic regions.

I. INFORMATION WE COLLECT ABOUT YOU

We may collect the following types of information about you which are described in more detail below: (A) information you provide to us, (B) sensitive information, (C) information we may automatically collect, and (D) information we may receive from third parties. All of the information listed in (A)-(D) above, are detailed below, and hereinafter referred to as “Information.”

This Information is collected from you when you use our Services and when you engage with us in some of the following circumstances:

  • Attending an event at one of our venues;
  • Completing a survey, raffle, or participating in a focus group or the Sabres Member Fan council;
  • Purchasing ticket to an event;
  • Entering a contest, raffle, giveaway, focus group, or sweepstakes administered by us;
  • Filling out an application for employment with us;
  • Joining a Sabres Kids Club program; or
  • Signing up for our newsletter.

A. Information You Provide to Us

In using our Services, you may provide us with Information, including, without limitation:

  • Contact information such as name, email address, postal address, and telephone number(s);
  • Demographic information such as birth date or gender;
  • Account information and log in credentials, including unique identifiers such as username and password;
  • Payment and transaction information including credit or bank card information;
  • Communications and opinions in chat rooms, message boards, forums, surveys, polls, and online forms;
  • Photos and/or videos;
  • Information about your guests or family for events; and
  • Additional information as otherwise described to you at the point of collection or pursuant to your consent.

B. Sensitive Information

We may process the following categories of sensitive personal Information when you use our Services:

  • Precise Geolocation data (including through our mobile app)
  • Driver’s license number

C. Information We May Automatically Collect About You

Our Services may automatically collect the following categories of usage and technical Information about you. This Information is used by us for the operation of the Services, to maintain quality of the Services, and to provide general statistics regarding use of the Services. This Information may include:

  • IP address, which is the number associated with the service through which you access the Internet, like your ISP (Internet service provider), or your company;
  • Date and time of your visit or use of our Services;
  • Domain server from which you are using our Services;
  • Type of computer, web browsers, search engine used, operating system, or platform you use;
  • Data identifying the web pages you visited prior to and after visiting our website or use of our Services;
  • Your movement and activity within the website and Services, which is aggregated with other information;
  • Mobile device information, including the type of device you use, operating system version, and the device identifier (or “UDID”); and
  • Mobile application identification and behavior, use, and aggregated usage, performance data, and where the application was downloaded from.

1. Cookies & Technologies Used to Collect Information About You

We and our third-party partners and service providers operating on our behalf may collect information about your activity, or activity on devices associated with you over time, on our sites and applications, and across non-affiliated websites or online applications. We may collect this Information by using certain technologies, such as cookies, session replay, pixels, web beacons, software developer kits, third-party libraries, and other similar technologies (“collectively referred to as “online tracking technologies”). Third-party service providers, advertisers, and/or partners may also view, edit, or set their own cookies, place web beacons, or use pixels and tags on social media posts, ads and chatbots to track click through rates on our website. The use of these technologies by such third parties is subject to their own privacy policies and is not covered by this Privacy Policy, except as required by law.

  1. Cookies (or browser cookies). A cookie is a small file placed on the hard drive of your computer. Most web browsers automatically accept cookies. You may refuse to accept browser cookies by activating the appropriate setting on your browser. However, if you select this setting, you may be unable to access certain parts of our Services. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our website.
  2. Pixels. We may use pixels, such as the Facebook Pixel to customize our advertising and to serve you ads on your social media based on your browsing behavior. This allows your behavior to be tracked after you have been redirected to our websites and mobile applications by clicking on the Facebook ad. Facebook Pixel stores a cookie on your device to enable us to measure the effectiveness of Facebook ads for statistical and market research purposes. We do not have access to the information collected through Facebook Pixel. However, the information collected via the Facebook Pixel is also stored and processed by Facebook. Facebook may link this information to your Facebook account and also use it for its own promotional purposes in accordance with Facebook’s Data Usage Policy. Facebook Pixel also allows Facebook and its partners to show you advertisements on and outside of Facebook.
  3. Web Beacons. Website pages may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit us, for example, to count users who have visited those pages and for other related statistics (for example, recording the popularity of certain content and verifying system and server integrity). We also use these technical methods to analyze the traffic patterns, such as the frequency with which our users visit various parts of the Services. These technical methods may involve the transmission of Information either directly to us or to a third party authorized by us to collect Information on our behalf. Our Services use retargeting pixels from Google, Facebook, and other ad networks. We also use web beacons in HTML emails that we send to determine whether the recipients have opened those emails and/or clicked on links in those emails.
  4. Analytics. Analytics are tools we use, such as Google Analytics, to help provide us with information about traffic to our website and use of our Services, which Google may share with other services and websites who use the collected data to contextualize and personalize the ads of its own advertising network. You can view Google’s Privacy Practices here: Privacy Policy – Privacy & Terms – Google.
  5. Mobile Application Technologies. If you access our website and Services through a mobile device, we may automatically collect Information about your device, your phone number, and your physical location.
  6. Third-Party Advertising Technologies. We may also allow third parties to place advertisements on our Services. By interacting with such third-party advertisements or clicking on them, these third parties may collect Information about your visits to this and other websites, your IP address, your internet service provider, the browser you use to visit our Services, and in some instances it may collect Information available from your social media accounts and profiles, such as your name, address, email address, telephone number, contacts and activities. These third parties do this using their own cookies and other technologies. Information collected may be used, among other things, to deliver advertising targeted to your interests and to better understand the usage and visitation of our website and the other sites tracked by these third parties. The Information we collect is covered by this Privacy Policy, and the information the third parties or social media platforms collect is subject to the third-party website or platform’s privacy practices. We encourage you to be aware when you leave our Services to read the privacy policies of other sites that may collect your Information to learn about their use of cookies and other technology. As stated in Section II-B of this Privacy Policy, this Privacy Policy does not apply to, and we are not responsible for, cookies or other technologies in third-party advertisements or websites.
  7. Behavioral Targeting/Re-Targeting/Intelligent Advertising. We may partner with a third-party ad network to either display advertising on our Services or to manage our advertising on other sites. Our ad network partner may use cookies and web beacons to collect information about your activities on this and other websites and social media platforms to provide you targeted advertising based upon your interests, available information, and online activities.

Our use of these various online tracking technologies may be considered a “sale” or “sharing” under certain laws. To the extent that these online tracking technologies are deemed to be a “sale” or “sharing” under certain laws, you can opt out of these online tracking technologies by contacting us at [email protected] or (866) 918-0235, or by broadcasting an opt-out preference signal, such as the Global Privacy Control (GPC), on the browsers and/or browser extensions that support such a signal. To download and use a browser supporting the GPC browser signal, click here: https://globalprivacycontrol.org/orgs. If you choose to use the GPC signal, you will need to turn it on for each supported browser or browser extension you use. Please note that some features of our website may not be available to you as a result of these choices.

D. Information We May Receive from Third Parties

We may collect additional Information about you from third party websites, social media platforms, such as, but not limited, to Facebook, Twitter, Instagram, SnapChat (“Social Media Platforms”), and/or sources providing publicly-available information (e.g., from the U.S. postal service) to help us provide services to you, help prevent fraud, and for marketing and advertising purposes.

Information we may access about you, with your consent, may include, but is not limited to, your basic Social Media Platform information, your location data, your list of contacts, friends or followers and certain information about your activities on the Social Media Platform. Please keep in mind that when you provide Information to us on a third-party website or platform (for example, via our applications), the Information you provide may be separately collected by the third-party website or the Social Media Platform.

This Privacy Policy only applies to Information collected by our Services. We are not responsible for the privacy and security practices of those other websites or Social Media Platforms or the Information they may collect (which may include IP address). You should contact such third parties directly to determine their respective privacy policies. Links to any other websites or content do not constitute or imply an endorsement or recommendation by us of the linked website, Social Media Platform, and/or content.

II. HOW WE USE YOUR INFORMATION

A. Use and Purpose of Processing Your Information

We use and process your Information for things that may include, but are not limited to, the following:

  • Provide you with the Services, and related products, promotions, newsletters, contests, sweepstakes, games, and information you request;
  • To process, support, fulfill, or administer transactions and orders for products, events, and services ordered by you;
  • To respond to your inquiries and provide you with requested information and other communications, including by email or text messages, and including alerts, notification of promotions, contests, and events;
  • For general or targeted marketing and advertising purposes, including sending you promotional material or special offers on our behalf or on behalf of our marketing partners and/or their respective affiliates and subsidiaries and other third parties, provided that you have not already opted out of receiving such communications;
  • To fulfill contracts we have with you;
  • To manage, improve, and foster relationships with third-party service providers, including vendors, suppliers, and parents, affiliates, subsidiaries, and business partners;
  • Maintain, improve, customize, or administer the Services, perform business analyses, or other internal purposes to improve the quality of our business, the Services, resolve technical problems, or improve security or develop other products and services;
  • Comply with our Terms & Conditions;
  • Analytics for business purposes and business intelligence;
  • Comply with any applicable laws and regulations and respond to lawful requests; and/or
  • For any other purposes disclosed to you at the time we collect your Information and/or pursuant to your consent.

We may also use Information that has been de-identified and/or aggregated for purposes not otherwise listed above.

B. Sharing Your Information

We may share and/or disclose your Information as set forth in the Privacy Policy and in the following circumstances:

  • Third-Party Service Providers.We may share your Information with third-party service providers that perform certain functions or services on our behalf (such as to host the Services, fulfill orders, provide products and services, manage databases, perform analyses, process credit card payments, provide customer service, or send communications for us). These third-party service providers are authorized to use your Information only as necessary to provide these services to us. In some instances, we may aggregate Information we collect so third parties do not have access to your particular Information to identify you individually.
  • Disclosure of Information for Legal and Administrative Reasons.We may disclose your Information without notice: (i) when required by law or to comply with a court order, subpoena, search warrant, or other legal process; (ii) to cooperate or undertake an internal or external investigation or audit; (iii) to comply with legal, regulatory or administrative requirements of governmental authorities (including, without limitation, requests from the governmental agency authorities to view your Information); (iv) to protect and defend the rights, property or safety of us, our subsidiaries and affiliates and any of their officers, directors, employees, attorneys, agents, contractors and partners, and the Service users; (v) to enforce or apply our Terms & Conditions; and (vi) to verify the identity of the user of our Services.
  • Business Transfers.Your Information may be transferred, sold, or otherwise conveyed (“Conveyed”) to a third party where we: (i) merge with or are acquired by another business entity; (ii) sell all or substantially all of our assets; (iii) are adjudicated bankrupt; or (iv) are liquidated or otherwise reorganize. You agree to any and all such Conveyances of your Information.
  • Information Shared with our Subsidiaries and Affiliates.We may share your Information with our subsidiaries and affiliates. If you do not want us to share your Information with our subsidiaries and affiliates, please email us at [email protected].
  • Information Shared with Third Party Advertisers.In using, clicking on, or responding to third-party advertisements on the Services, third-party advertisers may compile information about you, your browser’s or device’s visits and usage patterns on the Services, and to measure the effectiveness of their ads and to personalize the advertising content or to determine targeted demographics for advertisements. Please note that an advertiser may ask us to show an ad to a certain audience of users (e.g., based on demographics or other interests). In that situation, we will determine the target audience and will serve the advertising to that audience and only provide anonymous aggregated data to the advertiser. If you respond to such an ad, the advertiser or ad server may conclude that you fit the description of the audience they are trying to reach. This Privacy Policy does not apply to, and we cannot control the activities of, third-party advertisers. Please consult the respective privacy policies of such advertisers or contact them for more information about how they use your Information.
  • Products or Services Offered in Partnership with Third Party(s). Certain products and/or services available on the Services are provided to you in partnership with third party(s) and may require you to disclose Information in order to register for and access such products and/or services. Such products and/or services shall identify the third-party partners at the point of registration. If you elect to register for such products and/or services, your Information will be transferred to such third party(s) and will be subject to the privacy policy and practices of such third party(s). We are not responsible for the privacy practices and policies of such third party(s) and, therefore, you should review the privacy practices and policies of such third party(s) prior to providing your Information in connection with such products and/or services.
  • Focus Groups, Surveys, Fan Council Program. If you choose to participate in our Sabres Fan Council program or a similar focus group or provide us with a testimonial or survey, we will retain such correspondence and the Information contained in it for our internal purposes and to improve our Services.
  • Online Communications (Chatrooms, Forums, Message Boards).If you correspond with us by email, social media, or other digital online platform, we may retain such correspondence and the Information contained in it and use it to respond to your inquiry. You are not required to provide any Information when using these areas, but you may choose to do so. If you post personal Information online, you agree you have no expectation of privacy concerning that Information, that it will be publicly available and that you may receive unsolicited messages from other parties. We cannot ensure the security of any Information you choose to make public in a chat room, forum, or message board. Also, we cannot ensure that parties who have access to such publicly available Information will respect your privacy. Please exercise caution when deciding to disclose Information in these areas. To request removal of your personal Information from our blog or community forum, contact us at [email protected]. In some cases, we may not be able to remove your Information, in which case we will let you know if we are unable to do so and why.
  • We may share ticketing and other information about you with other members of the National Hockey League family (“NHL”). For example, we may share ticketing and other information about you with the National Hockey League and NHL Interactive CyberEnterprises, LLC, so that they can conduct analysis to better understand NHL fans and fan engagement across the NHL, including its member clubs. NHL may also use and share insights with member clubs to enable the NHL, including its member clubs, to customize and improve their services, advertising, and communications. Please see the NHL Privacy Policyfor more information and the NHL Do Not Sell page for information on how to manage your cookie choices.
  • De-Identified or Aggregated Data. We may share your Information on an aggregated basis for any purpose in which your specific personal Information is blinded, masked, or otherwise not identifiable.
  • With Your Consent.We may share Information consistent with this Privacy Policy with your consent.

C. Categories of Information Sold

We may sell or share the below categories of personal Information. For purposes of this Privacy Policy, “sell,” “sold,” or “sale” means the disclosure of personal Information for monetary or other valuable consideration but does not include, for example, the transfer of personal Information as an asset that is part of a merger, bankruptcy, or other disposition of all or any portion of our business.

Category of Information

Examples of Information Disclosed

Identifying Information

Name, mailing address, email address, phone number, and other identifiers.

Payment Information

Your name and billing totals for payment and processing your transaction.

Usage and Technical Information

Information about your interaction with our website and content on third-party sites or platforms, such as social networking sites (e.g., IP address; browsing history; search history; device information; information about user’s interaction with website, such as scrolling, clicks, and mouse-overs via cookies, pixel tags, web beacons, transparent GIFs; browser information; operating system and platform; geolocation information; user content (e.g., photos, videos, audio, images, social media /online posts, first-party works)).

III. LINKS TO OTHER WEBSITES

Our Services may contain links to other websites or services that are not owned or controlled by us, including links to Social Media Platforms such as Facebook, Instagram, Twitter, TicketMaster and SnapChat, or may redirect you off our website away from our Services to other websites for information, other services, or to receive special offers, contests, games, sweepstakes, or for transactions or purchases.

For example, if you “click” on a banner advertisement, the “click” may take you off our Services and onto a different website. This includes links from advertisers, sponsors and marketing partners that may use our logo as part of a co-branding agreement or other similar agreements. These other websites may send their own cookies to you, independently collect data, or solicit personal Information and may or may not have their own published privacy policies. If you visit a website that is linked to our Services, you should consult that website’s privacy policy before providing any Information.

This Privacy Policy only applies to Information collected by our Services. We are not responsible for the privacy and security practices of those other websites or Social Media Platforms or the Information they may collect (which may include IP address). You should contact such third parties directly to determine their respective privacy policies. Links to any other websites or content do not constitute or imply an endorsement or recommendation by us of the linked website, Social Media Platform, and/or content.

IV. INFORMATION SECURITY

We use commercially reasonable measures to provide our Services. However, you should assume that no data transmitted over the Internet or stored or maintained by us or our third-party service providers can be 100% secure. Therefore, although we believe the measures implemented by us reduce the likelihood of security problems to a level appropriate to the type of data involved, we do not promise or guarantee, and you should not expect, that your Information or private communications will always remain private or secure. We do not guarantee that your Information will not be misused by third parties. We are not responsible for the circumvention of any privacy settings or security features. You agree that we will not have any liability for misuse, access, acquisition, deletion, or disclosure of your Information.

If you believe that your Information has been accessed or acquired by an unauthorized person, you shall promptly Contact Us so that necessary measures can quickly be taken.

V. DATA RETENTION

We will retain your Information for as long as needed to provide you the Services, or as permitted or required by law. If you wish to cancel your account or request that we no longer use your Information to provide you the Services, please contact us at [email protected]. We will retain and use your Information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. In accordance with our routine record keeping, we may delete certain records that contain Information you have submitted to us. We are under no obligation to store such Information indefinitely and disclaim any liability arising out of, or related to, the destruction of such Information.

VI. HOW WE WILL CONTACT YOU

You agree that we, our affiliates, and/or third-party service providers with whom we collaborate and contract, may communicate with you regarding our Services via electronic messages, including email, text message, or mobile push notification to, for example, send you information relating to our products and Services that we think may be of interest to you, communicate with you about contests, sweepstakes, offers, promotions, rewards, upcoming events, and other news about products and services provided by or through us through permissible targeted advertisements offered by us, our parent companies, our subsidiaries, our affiliates, and other business partners. See Your Information Choices, below, for how you can update the way we contact you.

VII. YOUR INFORMATION CHOICES

  1. Email If you do not want to receive marketing and promotional emails from us, you may click on the “unsubscribe” link in the email to unsubscribe and opt out of marketing email communications or see Contact Us below for more information.
  2. Mobile Push Notifications. By using our Services, you agree that we may contact you by calling or sending messages to your You can use the settings on your mobile device to enable or turn off mobile push notifications from us or Contact Us.
  3. Correct or View Your Information. You may access your Buffalo Sabres account to correct or view certain Information you have provided to us and which is associated with your account.
  4. Cookie Choices. To exercise choices regarding cookies set through our Services, as well as other types of online tracking and internet advertising, see our Cookies Policy for more details or Contact Us.
  5. Location Choices. You can change the privacy settings of your device at any time to turn off the sharing of location information with our Services. If you choose to turn off location services, this could affect certain features or services of our Services. If you have specific questions about the privacy settings of your device, we suggest you contact the manufacturer of your device or your mobile service provider for help.
  6. Opting Out of Direct Marketing by Third Parties.To exercise choices regarding the marketing information you receive, you may also review the following links:

  7. You may opt out of tracking and receiving tailored advertisements on your mobile device by some mobile advertising companies and other similar entities by downloading the App Choices app at aboutads.info/appchoices.

  8. You may opt out of receiving permissible targeted advertisements by using the NAI Opt-out tool available at http://optout.networkadvertising.org/?c=1 or visiting About Ads at http://optout.aboutads.info.

  9. You can opt out of having your activity on our Services made available to Google Analytics by installing the Google Analytics opt-out add-on for your web browser by visiting: https://tools.google.com/dlpage/gaoptoutfor your web browser.

  10. Notice to Certain Residents. In addition to the above methods of exercising choice, to the extent required by applicable law or as otherwise noted in the Notice to Certain Residents of Data Subject Rights, Section IX below, we may provide you with additional choices regarding the processing of your Information, which you may exercise by contacting us as detailed in the “How to Contact Us” section below. We will try to comply with your request as soon as reasonably practicable as required by applicable law.

VIII. DATA SUBJECT REQUESTS

Subject to applicable laws based on your residency, you may have certain rights with respect to your Information. For instance, you may have the right to request that we provide you access to, correct, or delete your Information. If you would like to exercise any of these rights and/or if you believe you are entitled to additional rights that you would like to exercise regarding your Information, contact us at:

Email: [email protected]

Call us: (866) 918-0235

Write us: One Seymour H. Knox III Plaza, Buffalo, New York 14203, Attn: Privacy Officer

If you have a Buffalo Sabres account, you may be able to exercise some of these rights, such as correcting or accessing your information, by logging into your account on our website.

For residents of California or persons in the European Union or European Economic Area or United Kingdom, please refer to the following sections for the specific data rights available to you.

IX. NOTICE TO CERTAIN RESIDENTS OF DATA SUBJECT RIGHTS

A. NOTICE TO CALIFORNIA RESIDENTS

To the extent any California data privacy law applies to the collection of your Information, this supplemental section of our Privacy Policy outlines the rights that California residents may have, and how they can exercise those rights. This notice applies solely to California residents. We provide the supplemental section below to comply with the California Consumer Privacy Act [as amended by the California Privacy Rights Act (referred to collectively hereinafter as CCPA)] and any terms defined in the CCPA have the same meaning when used below.

1. Your Rights under CCPA

  • Right to Know and Access Specific Information. You have the right to request that we disclose certain information to you about our collection and use of your Information over the past twelve (12) months. Once we receive and confirm a verifiable consumer request from you, we will disclose to you, to the extent permitted by law:
  • The categories of Information we collected about you, and whether we sell or share your Information to third parties.
  • The specific pieces of Information we hold about you.
  • The categories of personal Information sold within the last 12 (twelve) months.
  • The categories of sources from which Information about you is collected.
  • Our business or commercial purpose for collecting, selling, or sharing your Information.
  • The categories of third parties with whom your Information is sold, shared, or disclosed for a business purpose.

You have the right to request that the Information described above be provided to you in a portable and readily useable format, to the extent technically feasible (“data portability”).

  • Deletion Request Rights. You have the right to request that we delete the Information that we collected from you, subject to certain exceptions. To the extent that we can delete your Information, once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your Information, unless an exception applies.
  • Right to Correct Inaccurate Information. To the extent that we may maintain inaccurate personal Information, you have the right to request that we correct such inaccurate personal information taking into account the nature of the personal Information and the purposes of the processing of the personal Information. Once we receive and verify your verifiable consumer request, we will use commercially reasonable efforts to correct your personal Information.
  • Sale and Sharing of Personal Information and the Right to Opt Out. You have the right to opt out of the processing of your Information for the following purposes:
  • Sale of your Information.
  • Sharing of your Information for cross-context behavioral advertising.

The use of online tracking technologies may be considered a “sale” or “sharing” under California law. To the extent that these online tracking technologies are deemed to be a “sale” or “sharing” under California law, you may opt out of these online tracking technologies by submitting a request to us via one of the contact methods in the Exercising Your Rights section or by broadcasting an opt-out preference signal, such as the Global Privacy Control (GPC).

  • Right to Limit Use and Disclosure of Sensitive Personal Information. You have the right to request that we limit the ways we use and disclose your sensitive personal Information (as defined by CCPA) to uses which are necessary for us to perform the Services, or deliver the goods reasonably expected by you, or and as authorized by law.
  • Right to Non-Discrimination. You have a right to not be discriminated against in the Services or quality of Services you receive from us for exercising your rights. We may not, and will not, treat you differently because of your data subject request activity. As a result of your data subject request activity, we may not and will not deny goods or Services to you, charge different rates for goods or Services, provide a different level quality of goods or Services, or suggest that we would treat you differently because of your data subject request activity.
  • Right to Disclosure of Direct Marketers. You have a right to the categories and names/addresses of third parties that have received personal Information for their direct marketing purposes upon simple request, and free of charge.

You may make an authenticated consumer request exercising your Right to Know and Access Specific Information including Right to Know what Personal Information is being Sold or Shared or under the CCPA twice within a twelve (12) month period. To exercise the rights described above, see the Exercising Your Rights section below.

2. Authorized Agent

You may use an authorized agent to submit verifiable consumer requests on your behalf provided that the authorized agent is a natural person or a business entity that you have authorized to act on your behalf. If you use an authorized agent, we will require: (1) proof of written permission for the authorized agent to make requests on your behalf, and identity verification from you; or (2) proof of power of attorney pursuant to California Probate Code sections 4000 to 4665. We may deny a request from an authorized agent that does not submit proper verification proof.

3. Notice of Financial Incentive

As an incentive for providing us with your Information, you may receive a financial benefit in the form of an email coupon, discount code, promotion, or other similar reward that will be sent to you. This discount may constitute a financial incentive under the California Consumer Privacy Act (“Financial Incentive”). The categories of personal Information required for us to provide the Financial Incentives include personal identifiers such as full name and contact information including email address as well as personal and demographic Information you choose to provide.

To offer these discounts, we may track your personal Information, such as purchase history and other demographic data. You have the right to withdraw from the Financial Incentive at any time by submitting a request to [email protected] or calling us at (866) 918-0235. Please note that if you request deletion of part or all your personal Information, that could affect your ability to qualify for the discount.

4. Additional Information

To the extent permitted by applicable law, we may charge a reasonable fee to comply with your request.

B. NOTICE TO INDIVIDUALS IN THE EUROPEAN ECONOMIC AREA AND THE UK

This section applies only to individuals coming to our Services from within the European Union (EU), the European Economic Area (EEA), and the UK, and only if we collect through the Services any Information from you that is considered “Personal Data,” as defined in the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.

Personal Data includes any information relating to an identified or identifiable natural person, who could be identified either directly or indirectly by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person (which may include some or all your Information as defined in this Privacy Policy).

[INCLUDE TOC WITH LINKS TO EACH SECTION OF THIS PROVISION]

1. Identity and Contact Details of Controller

Unless otherwise stated, we are the Data Controller for the Information we process.

Contact Details:

Email: [email protected]

Call us: (866) 918-0235

Write us: One Seymour H. Knox III Plaza, Buffalo, New York 14203, Attn: Privacy Officer

2. Your Data Protection Rights

To the extent the GDPR and Data Protection Act 2018 apply, and we hold your Information in our capacity as a Data Controller as defined under those laws, you may request that we:

  • Restrict the way that we process and share your Information;
  • Transfer your Information to a third party;
  • Provide you with access to your Information;
  • Remove your Information if no longer necessary for the purposes collected;
  • Update your Information so it is correct and not out of date; and/or
  • Object to our processing of your Information.

You may also revoke your consent for processing of your Information. If you wish to object to the use and processing of your Information or withdraw consent to this Privacy Policy, you can contact us in the following ways:

Email: [email protected]

Call us: (866) 918-0235

Write us: One Seymour H. Knox III Plaza, Buffalo, New York 14203, Attn: Privacy Officer

The requests above will be considered and responded to in the time-period stated by applicable law. Note, certain Information may be exempt from such requests. We may require additional Information from you to confirm your identity in responding to such requests.

You have the right to lodge a complaint with the supervisory authorities applicable to you and your situation, although we invite you to contact us with any concern as we would be happy to try and resolve it directly. Please contact us at:

Email: [email protected]

Call us: (866) 918-0235

Write us: One Seymour H. Knox III Plaza, Buffalo, New York 14203, Attn: Privacy Officer

3. Lawful Basis for Processing Your Information

The lawful basis for our processing of your Personal Data will depend on the purposes of the processing. For most Personal Data processing activities covered by this Privacy Policy, the lawful basis is that the processing is necessary for our legitimate business interests. Where we process Personal Data in relation to a contract, or a potential contract, with you, the lawful basis is that the processing is necessary for the performance of our contract with you or to take steps at your request prior to entering into a contract. If we are required to share Personal Data with law enforcement agencies or other governmental bodies, we do so on the basis that we are under a legal obligation to do so. We will also use consent as the legal basis where we deem appropriate or to the extent required by applicable law, for example, before we collect precise location data from your mobile device.

Depending on what Personal Data we collect from you and how we collect it, we may also rely on various grounds for processing your Personal Data, including the following reasons:

  • Processing on the basis of legitimate business interests.When we process Personal Data on the basis that the processing is necessary for our legitimate business interests, such interests include: (i) providing, improving, and promoting our Services; (ii) communicating with current and potential customers, other business partners, and their individual points of contact; (iii) managing our relationships with our customers and other business partners, and their individual points of contact; (iv) other business development purposes; (v) sharing information within the Company, as well as with service providers and other third parties; and (vi) maintaining the safety and security of our products, Services, and employees, including fraud protection.
  • Processing on the basis of performance of a contract. Examples of situations in which we process Personal Data as necessary for performance of a contract include e-commerce transactions in which you purchase a service from us.
  • Processing on the basis of consent.Examples of processing activities for which we may use consent as its legal basis include: (i) collecting and processing precise location Information from your mobile device; (ii) sending promotional emails when consent is required under applicable law; and (iii) processing Personal Data on Company Services through cookies and similar technologies when consent is required by applicable law.
  • Processing because we are under a legal obligation to do so. Examples of situations in which we must processes Personal Data to comply with our legal obligations include: (i) providing your Personal Data to law enforcement agencies and other governmental bodies when required by applicable laws; (ii) retaining business records required to be retained by applicable laws; and (iii) complying with court orders or other legal process.

If the processing of your Personal Data is based on your consent, the GDPR and Data Protection Act 2018 also allow users the right to access, revoke, or modify your consent at any time. Please see the How to Contact Us section, below, to review or modify your consents.

4. Consent to Transfer

We are operated in the United States, and we may use service providers based in the United States to operate our business and our relationship with you. Please be aware that Information, including your Personal Data, that we collect will be transferred to, stored, and processed in the United States, a jurisdiction in which the privacy laws may not be as comprehensive as those in the country where you reside and/or are a citizen. We maintain measures to address the transfer of your Personal Data between our group companies and between us and our third-party providers in accordance with applicable data protection laws and regulations.

5. Retention

We will retain your Information for as long as needed for the purposes described in this Privacy Policy. More specifically, the time we maintain your Information depends on the following factors:

  • Whether we need the Information to provide the Services. We will maintain any data needed to provide you with the Services, such as contact information and payment or transaction information, for as long as needed for us to provide you with the Services, respond to your questions and requests, and/or administer your account (if applicable).
  • Whether we need the Information to comply with our legal obligations. We may have legal obligations to maintain your Information where a legal or regulatory body may ask for it in the future, for example in response to a data subject request or complaint. This information may include contact information and location information.
  • Whether we need the Information for a legitimate business interest. We may store Information like contact information, cookies, and location information in order to perform analytics, troubleshoot errors, or improve our Services. In any event, we delete the Information when it is no longer needed for our legitimate interest.

Regardless of our reason for retaining your Information, we delete all Information in accordance with our routine record keeping policies.

X. EXERCISING YOUR DATA SUBJECT RIGHTS

To exercise any of the rights described above, please submit a verifiable consumer request to us via the methods described below. The verifiable consumer request must:

  • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Information, or an authorized representative; and
  • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

To help protect your privacy and maintain security, if you request access to or deletion of your Information, we will take steps and may require you to provide certain information to verify your identity before granting you access to your Information or complying with your request. In addition, if you ask us to provide you with specific pieces of Information, we may require you to sign a declaration under penalty of perjury that you are the consumer whose Information is the subject of the request. Only you or your authorized agent may make a verifiable consumer request related to your Information. If you designate an authorized agent to make a request on your behalf, we may require you to provide the authorized agent written permission to do so and to verify your own identity directly with us (as described above). You may also make a verifiable consumer request on behalf of your minor child.

Email: [email protected]

Call us: (866) 918-0235

Write us: One Seymour H. Knox III Plaza, Buffalo, New York 14203, Attn: Privacy Officer

XI. GEOGRAPHIC LOCATION OF DATA STORAGE AND PROCESSING

Our Services are located in the United States. As such, the Services collect Information and process and store that Information in databases located in the United States. If you are visiting the Services from a country outside the United States, you should be aware that you may transfer personally identifiable Information about yourself to the United States, and that the data protection laws of the United States may not be as comprehensive as those in your own country. By visiting the Services and submitting any personally identifiable Information you consent to the transfer of such personally identifiable Information to the United States.

XII. CHILDREN'S INFORMATION

Our Services are intended for general audiences. We do not knowingly collect, use, or disclose Information from children under the age of thirteen (13) or as otherwise defined by local law without prior parental consent, except as permitted by the Children’s Online Privacy Protection Act (hereinafter “COPPA”) or other applicable law. If we become aware that a user is under thirteen (13) (or a higher age threshold where applicable) and has provided us with Information, we will take steps to comply with any applicable legal requirement to remove such Information. Contact us if you believe that we have mistakenly or unintentionally collected Information from a child under the age of thirteen (13).

Some of our Services, such as online contests, sweepstakes, and promotions we may run from time to time, may seek information necessary for a child to participate, including the child’s name, date of birth and parent’s email address and contact information to communicate with the parent (as required by applicable law). For these services, children will be required to provide proof of consent from their parent or legal guardian in order to participate. Children are not permitted to provide Information to us through any of our Services or to share their Information with us absent the consent of their parent or legal guardian. We will not use parent emails provided for parental consent purposes to market to the parent, unless the parent has expressly opted in to email marketing or has separately participated in an activity that allows for such email contact.

If, at any time, a parent or legal guardian becomes aware that their child has provided us with Information without their consent or wishes to withdraw their consent to our use or maintenance of Information collected from their child, the parent or guardian should contact us at [email protected] and we will promptly remove such Information from our database(s). Please note that we may request proof of identity and relationship to the child before doing so.

If you have any comments or questions on policies related to children’s data or about our commitment to protecting your and your children’s privacy, please contact us at [email protected] or by mail at the address below.

XIII. DIFFICULTY ACCESSING OUR PRIVACY POLICY

Individuals with disabilities who are unable to usefully access our Privacy Policy online may contact us to inquire how they can obtain a copy of our policy in another, more easily readable format.

XIV. “DO NOT TRACK” SIGNALS

We do not support “Do Not Track.” Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable “Do Not Track” by visiting the “Preferences” or “Settings” page of your web browser. Do Not Track is different from Global Privacy Controls (“GPC”), which may notify websites of consumers’ privacy preferences regarding the sale or sharing of personal Information, or the use of sensitive personal Information.

XV. CHANGES TO THIS PRIVACY POLICY

We reserve the right to change, modify or amend this Privacy Policy at any time to reflect changes in our products and service offerings, accommodate new technologies, regulatory requirements, or other purposes. If we modify our Privacy Policy, we will update the “Effective Date” and such changes will be effective upon posting. It is your obligation to check our current Privacy Policy for any changes.

XVI. HOW TO CONTACT US

If you have any questions about this Privacy Policy or the Information we have collected about you, please contact us at the following:

Email: [email protected]

Call us: (866) 918-0235

Write us: One Seymour H. Knox III Plaza, Buffalo, New York 14203, Attn: Privacy Officer

Last Updated October 20, 2023