At Highland Park Brewery, we value your privacy and are committed to protecting your personal data. This Privacy Policy outlines how we collect, use, and safeguard your information, and explains your rights under privacy laws, including the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and General Data Protection Regulation (GDPR).
1. Information We Collect
We may collect the following categories of personal data:
- Identifiers: Name, email address, phone number, and mailing address.
- Commercial Information: Purchase history or preferences.
- Internet Activity: IP address, browsing behavior, and interactions with our website.
- Geolocation Data: Approximate location information from your device.
- Inferences: Preferences or characteristics derived from your interactions.
2. How We Use Your Information
We may use your personal data to:
- Provide and improve our services.
- Communicate with you about orders, products, and services.
- Personalize your experience on our website.
- Comply with legal obligations.
3. Legal Basis for Processing (GDPR)
We process your data based on the following legal grounds:
- Consent: When you provide consent to the processing of your data.
- Contractual Obligation: To fulfill our obligations in providing services or products to you.
- Legal Compliance: To comply with applicable laws and regulations.
- Legitimate Interest: For purposes such as improving our services, detecting fraud, or protecting our rights.
4. Your Rights
Under the CCPA and CPRA (California Residents):
- Right to Know: You can request details on the personal data we collect and how it’s used.
- Right to Delete: You may request the deletion of your personal data, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell your personal information. However, if this changes, you will have the right to opt out.
- Right to Correct: You can request corrections to inaccurate personal information.
- Right to Limit Use of Sensitive Data: You can restrict the use of certain sensitive personal information.
Under the GDPR (EU/EEA Residents):
- Right of Access: You can request a copy of your personal data.
- Right to Rectification: You can ask us to correct inaccurate or incomplete data.
- Right to Erasure: You can request that we delete your data under specific conditions.
- Right to Object: You may object to the processing of your data for marketing purposes.
- Right to Data Portability: You can request to receive your data in a commonly used format.
5. Data Subject Access Requests (DSAR)
To exercise your rights, you may submit a Data Subject Access Request (DSAR). We will verify your identity before processing your request. To make a DSAR, please contact us at main@hpb.la.
6. Do Not Sell (DNS) Requests
We respect your right to opt out of the sale of your personal data. As stated, we do not currently sell personal information. If that changes, a Do Not Sell (DNS) mechanism will be available on our website. California residents can use our DNS link or contact us directly to opt out.
7. Cookies, Tracking Technologies, and Third-Party Sharing
Our website uses cookies and similar tracking technologies to improve user experience and analyze traffic. We use third-party services such as Google Analytics to understand how visitors interact with our site. Google Analytics helps us analyze website traffic and usage patterns. You can opt out of Google Analytics tracking by visiting https://tools.google.com/dlpage/gaoptout/.
Tracking technologies may also be used for:
- Monitoring and analyzing website traffic;
- Evaluating your interaction with our advertisements;
- Verifying whether you’re logged into the website;
- Testing and optimizing content;
- Saving your preferences and settings;
- Recognizing and personalizing your experience when you revisit the website.
Most web browsers are set to accept cookies by default. However, you can adjust your browser settings to block or limit cookies. Keep in mind that this may limit certain features and functionalities of the website, affecting your overall experience.
8. Data Retention
We retain personal data only as long as necessary for the purposes outlined in this Privacy Policy or to comply with legal obligations.
9. Data Security
We implement appropriate security measures to protect your personal data from unauthorized access, disclosure, alteration, and destruction.
10. International Transfers
If you are located outside the United States, your personal data may be transferred to and processed in the U.S. By using our services, you consent to such transfers, which will be safeguarded by appropriate measures to protect your data.
11. Children’s Privacy
Our services are not directed to children under the age of 16, and we do not knowingly collect personal information from children.
12. Changes to this Privacy Policy
We may update this Privacy Policy periodically. We will notify you of any significant changes by posting the updated policy on our website with the effective date.
13. California “Shine the Light” Law
Under California’s “Shine the Light” law (California Civil Code Section 1798.83), California residents who have provided personal data to us may request information regarding the disclosure of that data to third parties for direct marketing purposes. We do not currently share personal information with third parties for direct marketing. If this practice changes, California residents can request this information once per calendar year, free of charge, by contacting us at main@hpb.la.
14. Links to Other Sites
Our website may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every website you visit, as we have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services.
15. Contact Us
If you have any questions about this Privacy Policy, or to submit a DSAR or DNS request, please contact us at:
Email: main@hpb.la