Data Privacy Policy

Data Privacy Policy

Last updated: March 2, 2021

Kibo Software, Inc. and its subsidiaries (collectively, “Kibo”, “us”, “our”, “we”) respect the privacy of our website visitors, customers, partners, and employees. We believe it is important that you understand the kinds of data we collect about you, how we protect that data, and how it is used. We recognize the need for appropriate safeguards and management of Personal Data you provide to us. This Privacy Statement sets forth the privacy principles Kibo follows with respect to your Personal Data. This privacy statement covers all Personal Data received by Kibo through: (i) its website published at www.kibocommerce.com (and any other websites with “Kibo” branding that link to or reference this Privacy Statement including, without limitation, www.monetate.com and www.certona.com (collectively, the “Site” or “Sites”)) and (ii) Kibo’s software-as-a-service platforms (the “Kibo Services”). Personal Data is any information relating to an identified or identifiable natural person and may include data that makes it possible to identify you by reference to an identifier such as your name, identification number, location data, or other similar information.

By using the Site or the Kibo Services, you signify your acceptance of this Privacy Statement. Kibo may modify this Privacy Statement from time to time consistent with applicable law.  When material changes are made, the date of the latest revision will be reflected above.

Our Privacy Statement is organized as follows:

  1. The Sites
    • a. Collection of Personal Data on the Sites
    • b. Use of Personal Data Collected on the Sites
    • c. Non-Personal Data
    • d. Third Parties
    • e. Forums
  2. The Kibo Services
    • a. eCommerce and Order Management
    • b. Mobile Point of Contact
    • c. Personalization
    • d. Third Parties
  3. Retention of Personal Data
  4. International Transfers
  5. Your Legal Rights
  6. Security
  7. Additional Disclosures and Limitations
  8. Contact Information
  1. THE SITES

We collect information about your use of the Site.  This information falls into two categories: Personal Data and Non-Personal Data. We want you to be informed about what data is collected, when it is collected, and what we do with the data. Unless otherwise stated, we do not share any of this data with third parties.

a. Collection of Personal Data on the Site

We collect Personal Data when you:

Register for an account or support account on the Site:  With your consent, Kibo collects the information you provide us such as you name, email address, physical address, employer information, username, location information, IP address and the like.

Request information about products or services:  With your consent, Kibo collects the information you provide us such as your name, email address, employer information, country of residence, and phone number.

Register for an event, answer a survey, or correspond with us:  With your consent, Kibo collects the information you provide to us such as your name, email address, employer information, country of residence, and phone number.

Download technical resources such as whitepapers:  With your consent, Kibo collects the information you provide us such as your name, email address, employer information, country of residence, and phone number.

Apply for a Job on the Site:  Kibo collects information provided by you to evaluate your suitability for positions to which you apply and evaluate Kibo’s performance with equal opportunity laws.  Collected information may include: your email address, name, address, location information, telephone numbers, work authorization information,  gender, race, veteran status, work history, education history and the like.

b. Use of Personal Data Collected on the Site

Kibo uses Personal Data it collects through the Site to send you information about products or services, to respond to requests for technical or customer support; to track compliance with the Site’s rules and policies; to contact you in regards to Kibo products or services, to deliver technical resources and documents to you in email form, to provide you with Kibo’s newsletters and other documents, to coordinate communication with you regarding events you have registered to attend, and to evaluate applicants for jobs listed on the Site.

We may disclose Personal Data collected on the Site to effect a merger, acquisition or similar transaction, to support the sale or transfer of business assets, and to assist our private equity sponsor, Vista Equity Partners, and its affiliates, including Vista Consulting Group (collectively, “Vista”), for administration, research, database development, workforce analytics and business operation purposes, in line with the terms of this Privacy Statement. Vista processes and shares your Personal Data with its affiliates, including other Vista portfolio companies, on the basis of its legitimate interests in managing, administering and improving its business and overseeing the recruitment process and, if applicable, your employment relationship with Kibo. If you have consented to us doing so, we also share your Personal Data with other Vista portfolio companies for the purpose of being considered for other job opportunities in the pooling system, both inside and outside the European Economic Area (“EEA”). Please find a full list of all Vista portfolio companies at: https://www.vistaequitypartners.com/companies/ and Vista’s privacy policy at https://www.vistaequitypartners.com/privacy/. Where this requires us to transfer your Personal Data outside of the EEA, please refer to Section 4 of this Privacy Statement for further details on cross-border transfers. In connection with the recruitment process, we transfer your Personal Data outside of the EEA to Hirebridge, LLC and Criteria Corp., which provide applicant tracking services. Hirebridge, LLC and Criteria Corp. both comply with the EU-U.S. Privacy Shield Framework and ensure that your Personal Data is adequately protected whilst outside of the EEA.

c. Non-Personal Data

Non-Personal Data (“NPD”): NPD is information that cannot reasonably be used to identify or contact you. Such information may include browser information, domain names, and other anonymous or anonymized statistical data related to use of the Site.

The Site collects NPD to monitor user traffic patterns and Site usage. We may link some of this NPD to Personal Data for purposes such as personalizing and improving your experience on the Site and for general Site evaluation. More specifically, browser information is collected when you are using the Site through log files and third-party scripts that automatically collect information that may include, browser type, internet service provider, referring/exit pages, number of clicks, date/time stamp, and other similar information. Log files and third-party scripts may also collect general demographic and visit information. We use these log files and third-party scripts to help us analyze trends and to improve the value of the Site and services. Finally, we may also use third party scripts to collect NPD that is necessary to optimize effectiveness of advertisements appearing on other parties’ sites.

We also collect NPD which involves cookies, action tags, and web beacons. Cookies are stored on your computer’s hard drive and identify your web browser and the activities of your computer on the Site and other websites. Most browsers accept cookies automatically, but you may disable them. Cookies help us facilitate efficient site navigation, improve your experience on the Site and to allow us to take note of visits to the Site and show relevant ads on our website and across the Internet. Action tags, also known as web beacons or single pixel GIFs, are a web technology used to help track website usage information, such as how many times a specific page has been viewed. Action tags are invisible to you. Any portion of the Site, including advertisements or emails sent on our behalf, may contain action tags. Action tags can be used to count Site users, to deliver co-branded services, or to determine whether email messages have been opened or acted upon. Action tags may be used to conduct research on behalf of certain clients, to compile statistics for advertising purposes, for auditing purposes, or to report certain aggregate information. By using cookies and action tags together, we are able to gather information to improve the Site and measure the effectiveness of our advertising and marketing campaigns. Embedded URLs allow use of the Site without cookies and we utilize them as a tracking tool to collect NPD. Embedded URLs are exhibited as plain text or encoded extensions to the URL that appear in the browser address or location toolbar. They provide limited NPD about navigation on the Site during the current session.

d. Third Parties

As part of Kibo’s operation of its Site, we may contract with third-party providers to perform certain functions. These third parties may have access to Personal Data and NPD to the extent necessary to permit them to assist Kibo in performing the functions set forth above. Before Kibo does this, it contracts with potential third parties to ensure that such data may only be processed for limited and specific purposes consistent with law and the consent provided by individuals, and that the recipient will provide the same level of protection as are required by applicable law. Kibo also requires that if a determination is made that the third party can no longer meet these obligations, it must notify Kibo.  If Kibo receives such notice from any third party, or if such a determination is made by Kibo, Kibo will require that the third party cease processing Personal Data or take other reasonable and appropriate steps to remediate its situation.

The Site contains links to other sites. Kibo is not responsible for the privacy practices of such other sites. We encourage you to be aware when you leave the Site and to read the privacy statements of each and every site you visit.

e. Forums

We may provide online forums as a means for our clients and other users of the Kibo Services to communicate. If you use a forum, you should be aware that any Personal Data you submit through a forum can be read, collected, or used by other users of these forums. Kibo is not responsible for Personal Data you choose to submit in forums.

2. THE KIBO SERVICES

The Kibo Services comprise software-as-a-service platforms that support the eCommerce businesses of retailers (“Data Controllers”) and process both Personal Data and Non-Personal Data on their behalf. With respect to the Kibo Services, Kibo is a Data Processor or Service Provider.

a. eCommerce and Order Management

Kibo’s eCommerce service powers the consumer-facing web presence of retailers on both computer and mobile browsers.  Kibo’s Order Management service provides logistical support for order routing, fulfillment, shipment, inventory tracking and sales enablement. The Kibo eCommerce and Order Management services are not a part of the Sites. Kibo serves as a Data Processor for its clients who use these services. Kibo does not own the information that is submitted to its clients’ websites. The information that is submitted to its clients’ websites will be subject to its clients’ privacy policies.

In providing its eCommerce and Order Management services, Kibo processes Personal Data in furtherance of online sales contracts for the purchase of goods entered into by our clients.  This Personal Data includes your name, email address, physical address, country of residence, location data, phone number, payment card numbers, third party payment account identifiers, IP address, order history, account information, account identifiers and the like. Kibo processes this information to ensure that online orders are processed by shippers & fulfillers, to process payments related to online orders, to screen for fraudulent orders, to provide consumer and client support, and to send messages related to the placement, fulfillment, shipment and delivery of orders.  Kibo’s eCommerce service may also process information about client personnel to provide control functions for the eCommerce service. This information may include personnel names, email addresses, account identifiers, IP addresses, physical addresses, location data, phone numbers, employer information, job function information and the like.

Our clients’ website pages may contain “cookies.” A cookie is a small amount of data which a website stores on a visitor’s computer, and which we or our clients can later retrieve. The cookie cannot be read by a site other than our client’s. We and our clients use cookies for a number of administrative purposes; for example, to store visitors’ preferences for certain kinds of information. We will not write to any cookie information that will allow anyone to contact visitor’s via telephone, e-mail, or any other means. Any additional use of cookies by our clients will be governed by our clients’ privacy policies. Website visitors can monitor use of cookies on their computers by setting their web browser to inform them when cookies are set, or visitors can prevent the cookies from being set entirely. The “help” portion of the toolbar on most browsers explains how to prevent the browser from accepting new cookies, how to have the browser provide notice when a new cookie is received, or how to disable cookies altogether. Please understand that if a visitor disables the use of cookies, the visitor may be unable to access certain portions or services in our applications or those of our clients.

Kibo also processes NPD on its eCommerce and Order Management services and may link certain NPD to Personal Data for purposes such as personalizing and improving your experience on the client sites and for general client site evaluation. More specifically, browser information may be processed when you are using client sites through log files and third-party scripts that automatically collect information that may include, browser type, internet service provider, referring/exit pages, number of clicks, date/time stamp, and other similar information. Log files and third-party scripts may also process general demographic information. Kibo may also process NPD collected by client sites using cookies, action tags, web beacons and embedded URLs.

Kibo cannot be fully aware of and is not responsible for data collected by its clients and/or data that is not processed by Kibo.

b. Mobile Point of Commerce

Kibo’s Mobile Point of Commerce (“MPOC”) solution powers mobile checkout, registration, purchases, and the placement of orders, for delivery or in-store pickup on a mobile tablet used by client associates. In providing this service, Kibo processes Personal Data in furtherance of point of sale sales contracts, orders, or registration contracts entered into by its clients.  This Personal Data may include your name, email address, physical address, country of residence, location data, phone number, payment card numbers, third party payment account identifiers, IP address, order history, account information, account identifiers and the like. Kibo processes this information on behalf of clients to ensure that orders placed are processed by shippers & fulfillers, to process payments, to screen for fraudulent orders, to provide consumer and client support, and to send messages related to the placement, fulfillment, shipment and delivery of orders.  Kibo’s MPOC solution may also process information about client personnel to provide control functions for the MPOC platform. This information may include personnel names, email addresses, account identifiers, IP addresses, physical addresses, location data, phone numbers, employer information, job function information and the like.

c. Personalization Services

Kibo Personalization Services (also formerly known as: Monetate, Certona, and Real-Time Individualization (“RTI”)) provide individualized web experiences tailored to website visitors by processing data collected by Kibo’s client that relates to visits to the client’s websites.  The processed data may include non-specific location information, user actions, click activity, search activity, purchase history, dwell time, and the like.  In some circumstances, Kibo may, on behalf of a client, process Non-Personal Data and associate it with Personal Data, both provided by the client to facilitate further personalized online experiences on behalf of that client.

d. Third Parties

As part of Kibo’s services we may contract with third-party providers to perform certain functions on behalf of our clients to enhance our existing product and service offerings. Examples include providing product and service support. In cases of onward transfer to third parties of Personal Data, Kibo is potentially liable. These third parties may have access to Personal Data and NPD to the extent necessary to permit them to do their jobs, however, they are bound by confidentiality agreements or similar contractual restrictions before any information is provided to them, and they are restricted from using the information for other purposes. Kibo contracts with third parties to ensure that such data may only be processed for limited and specific purposes consistent with law and the consent provided by individuals, and that the recipient will provide the same level of protection as is required by applicable law. Kibo also requires that if a determination is made that a third party can no longer meet these obligations, it must notify Kibo. If Kibo receives such notice from any third party, or if such a determination is made by Kibo, Kibo will require that the third party cease processing Personal Data or take other reasonable and appropriate steps to remediate its situation.

3. RETENTION OF PERSONAL DATA

Kibo retains the Personal Data it processes for no more than seven (7) years.  Personal Data is processed on servers based in the EU and the United States.

4. INTERNATIONAL TRANSFERS

Due to the international nature of our business, we may need to transfer Personal Data within the Kibo group of companies and to third parties as noted above, in connection with the purposes set out in this Privacy Statement. For this reason, we may transfer Personal Data to other countries that may have different laws and data protection compliance requirements to those that apply in the country in which the Personal Data was collected. For example, some third parties are outside of the EEA.

Whenever we transfer Personal Data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

The transferee is located in a country that has been deemed to provide an adequate level of protection for Personal Data by the European Commission.

Kibo and the transferee have agreed to terms that are approved by the European Commission which give Personal Data the same protection it has in the EEA.

The transferee is located in the United States and is a part of the Privacy Shield which requires the transferee to provide similar protection to personal data shared between the EEA and the United States.

5. YOUR LEGAL RIGHTS

In accordance with applicable privacy laws such as GDPR and CCPA, we provide you with a right to (i) receive a copy of the Personal Data we hold about you and (ii) erasure and/or correction of Personal Data.  To exercise any of these rights, please complete the form located at https://kibocommerce.com/GDPR. Kibo generally responds to requests within 30 days of receiving a completed request form with proof of identity. If your request relates to Personal Data that we hold on behalf of a Data Controller, we will forward your request to the Data Controller for processing.

To protect your privacy and security, we take reasonable steps to verify identity before granting access requests for Personal Data. In addition, we may limit or deny access to Personal Data where providing such access would be unreasonably burdensome or expensive. Due to the distributed nature of our business systems, we cannot guarantee that a change request will update Personal Data immediately in all of our systems. In addition, it may not reasonably possible to remove each and every instance of the Personal Data you have provided to us. For example, copies of Personal Data may temporarily continue to exist in certain backup systems that are difficult for us to modify.

6. SECURITY

To prevent unauthorized access or disclosure, to maintain data accuracy, and to allow only the appropriate use of your Personal Data, we utilize industry standard physical, technical, and administrative controls and procedures to safeguard the information we collect. To help ensure the integrity and privacy of the Personal Data that you provide to us, we encrypt that information using secure socket layer technology (SSL). We follow generally accepted industry standards to protect Personal Data, both during transmission and once we receive it. However, you should recognize there is always some risk involved in transmission of information over the internet or in a method of electronic storage.

7. ADDITIONAL DISCLOSURES AND LIMITATIONS

Other than as stated in this Privacy Statement, we will endeavor not to release your Personal Data to unknown or unaffiliated third parties. We do not share, sell, rent or trade your Personal Data to third parties for promotional purposes. However, we may disclose your Personal Data if we are required to do so by law or we in good faith believe that such action is necessary to (1) comply with the law or with legal process including court orders or subpoenas; (2) protect and defend our rights and property; (3) protect against misuse or unauthorized use of our websites or the Kibo Services; or (4) protect the personal safety or property of our users or the public (among other things, this means that if you provide false information or attempt to pose as someone else, information about you may be disclosed as part of any investigation into your actions). Please note that we may be required to release an individual’s personal information in response to lawful requests by public authorities including to meet national security and/or law enforcement requirements.

8. CONTACT INFORMATION

At any time, you may contact Kibo with questions or concerns about this Privacy Statement at privacy@kibocommerce.com. Written responses may also be submitted to:

Kibo Software, Inc.
Attention: Privacy Officer
717 N. Harwood Street, Suite 1900
Dallas, TX 75201

Unified commerce

Discover the Modular Approach to Subscription Commerce

See how Kibo can change the way you deliver products using a trusted subscription management platform that unifies customer experiences. With modern, microservices-based, and API-first technology you’re empowered to make impactful decisions.

Request a Demo