Zen Cart Logo
Forums / General Questions / General Data Protection Rules GDPR

General Data Protection Rules GDPR

Views: 266,303

Results 101 to 120 of 177
26 May 2018, 12:31 AM
#102
gilby avatar

gilby

Totally Zenned

Join Date:
Aug 2005
Location:
Vic, Oz
Posts:
1,816
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

Ahhh.. That link is also broken:blink:

26 May 2018, 12:35 AM
#103
delia avatar

delia

Totally Zenned

Join Date:
May 2006
Location:
Gardiner, Maine
Posts:
2,383
Plugin Contributions:
7

Re: General Data Protection Rules GDPR

obviously I have had a very long hard day....
copied and pasted
http://deliatest.com/readytogo/index.php?main_page=privacy

typo, sorry guys!

26 May 2018, 11:45 AM
#104
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,694
Plugin Contributions:
56

Re: General Data Protection Rules GDPR

Not a bad little privacy policy generator: https://www.shopify.com/tools/policy-generator

26 May 2018, 11:55 AM
#105
delia avatar

delia

Totally Zenned

Join Date:
May 2006
Location:
Gardiner, Maine
Posts:
2,383
Plugin Contributions:
7

Re: General Data Protection Rules GDPR

There's definitely some good verbiage there - but it is an effort to sign you up for shopify. It's a template that plugs in your business/website information and they do collect (with absolutely no transparency!) your email address.

I particularly like the google analytics information I had never seen before.

In that light I'm posting it:

Business name Privacy Policy

This Privacy Policy describes how your personal information is collected, used, and shared when you visit or make a purchase from https://wiztech4zc.com (the “Site”).

PERSONAL INFORMATION WE COLLECT

When you visit the Site, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Site, and information about how you interact with the Site. We refer to this automatically-collected information as “Device Information.”

We collect Device Information using the following technologies:

- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable cookies, visit <http://www.allaboutcookies.org>.

- “Log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- “Web beacons,” “tags,” and “pixels” are electronic files used to record information about how you browse the Site.
[[INSERT DESCRIPTIONS OF OTHER TYPES OF TRACKING TECHNOLOGIES USED]]

Additionally when you make a purchase or attempt to make a purchase through the Site, we collect certain information from you, including your name, billing address, shipping address, payment information (including credit card numbers [[INSERT ANY OTHER PAYMENT TYPES ACCEPTED]]), email address, and phone number. We refer to this information as “Order Information.”

[[INSERT ANY OTHER INFORMATION YOU COLLECT: OFFLINE DATA, PURCHASED MARKETING DATA/LISTS]]

When we talk about “Personal Information” in this Privacy Policy, we are talking both about Device Information and Order Information.

HOW DO WE USE YOUR PERSONAL INFORMATION?

We use the Order Information that we collect generally to fulfill any orders placed through the Site (including processing your payment information, arranging for shipping, and providing you with invoices and/or order confirmations). Additionally, we use this Order Information to:
Communicate with you;
Screen our orders for potential risk or fraud; and
When in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
[[INSERT OTHER USES OF ORDER INFORMATION]]
We use the Device Information that we collect to help us screen for potential risk and fraud (in particular, your IP address), and more generally to improve and optimize our Site (for example, by generating analytics about how our customers browse and interact with the Site, and to assess the success of our marketing and advertising campaigns).
[[INSERT OTHER USES OF DEVICE INFORMATION, INCLUDING: ADVERTISING/RETARGETING]]

SHARING YOUR PERSONAL INFORMATION

We share your Personal Information with third parties to help us use your Personal Information, as described above. For example, we use Shopify to power our online store--you can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy. We also use Google Analytics to help us understand how our customers use the Site--you can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.

Finally, we may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.

[[INCLUDE IF USING REMARKETING OR TARGETED ADVERTISING]]
BEHAVIOURAL ADVERTISING
As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

You can opt out of targeted advertising by:
[[
INCLUDE OPT-OUT LINKS FROM WHICHEVER SERVICES BEING USED.
COMMON LINKS INCLUDE:
FACEBOOK - https://www.facebook.com/settings/?tab=ads
GOOGLE - https://www.google.com/settings/ads/anonymous
BING - https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads
]]

Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.abouta############fo/.

DO NOT TRACK
Please note that we do not alter our Site’s data collection and use practices when we see a Do Not Track signal from your browser.

[[INCLUDE IF LOCATED IN OR IF STORE HAS CUSTOMERS IN EUROPE]]
YOUR RIGHTS
If you are a European resident, you have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us through the contact information below.

Additionally, if you are a European resident we note that we are processing your information in order to fulfill contracts we might have with you (for example if you make an order through the Site), or otherwise to pursue our legitimate business interests listed above. Additionally, please note that your information will be transferred outside of Europe, including to Canada and the United States.

DATA RETENTION
When you place an order through the Site, we will maintain your Order Information for our records unless and until you ask us to delete this information.

[[INSERT IF AGE RESTRICTION IS REQUIRED]]
MINORS
The Site is not intended for individuals under the age of [[INSERT AGE]].

CHANGES
We may update this privacy policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons.

CONTACT US
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at email address or by mail using the details provided below:

mail address

26 May 2018, 12:00 PM
#106
lat9 avatar

lat9

Administrator

Join Date:
Sep 2009
Location:
Stuart, FL
Posts:
14,085
Plugin Contributions:
56

Re: General Data Protection Rules GDPR

Very nice, Delia; thanks for sharing.

26 May 2018, 1:46 PM
#107
delia avatar

delia

Totally Zenned

Join Date:
May 2006
Location:
Gardiner, Maine
Posts:
2,383
Plugin Contributions:
7

Re: General Data Protection Rules GDPR

I personally hate extensive policy statements 'cause none of us read them but...

I combined the two and rewrote the one I have posted. It is written for non-European companies and for ease of use in Zen Cart. I will be editing it as needed on an ongoing basis, but I am going to start including it in my templates and clean installs. Sometimes clients just don't get around to creating one. I'm tempted to automate some parts of it with real site integration which might work for many small sites but I can see that being an issue with larger companies who may actually have a lawyer.

I also added some wording for COWOA which anyone is welcome to suggest changes to if I have failed there.

http://deliatest.com/readytogo/index.php?main_page=privacy

One reason for me doing this is that I am a writer, first and foremost. (and am available for hire:smile:) Ah, yes, a writer but not a lawyer (disclaimer again)

I am astonished at that the GDPR is having unintended repercussions such as major companies blocking European IP addresses completely, i.e., the Chicago Tribune. Interesting times.

26 May 2018, 5:22 PM
#108
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,694
Plugin Contributions:
56

Re: General Data Protection Rules GDPR

delia:

I am astonished at that the GDPR is having unintended repercussions such as major companies blocking European IP addresses completely, i.e., the Chicago Tribune. Interesting times.

I am astonished that you are astonished. This is a huge pain in the neck. I'm tempted to do likewise.

26 May 2018, 5:25 PM
#109
delia avatar

delia

Totally Zenned

Join Date:
May 2006
Location:
Gardiner, Maine
Posts:
2,383
Plugin Contributions:
7

Re: General Data Protection Rules GDPR

swguy, I got European clients on my hosting. Not giving up money. Part of the reason for me digging into this was to see what I needed on my website. Global business -which I know you have as well.

26 May 2018, 7:17 PM
#110
mesnitu avatar

mesnitu

Totally Zenned

Join Date:
Aug 2014
Location:
Lisbon
Posts:
597
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

Well, it was a pain, but personally I do like this law. And I'm European.
I'm tired of getting phone messages, emails, from companies that I've never contacted.
Those days are over (I hope).
Until now we've had one customer that made a purchase and after asked to remove the account. So it was remove. Simple.
I guess the guest_account module from lat9 will prevent this situations, but didn't had the time to look into it.
From all the notifications to review the account, nothing really happen, and some "old" customers already agree with the new privacy policy. etc.
I already receive a lots of emails to review my own account on other sites, and I'm not going to. At least today. But it's nice to have the tools and laws to do it.

26 May 2018, 7:29 PM
#111
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,694
Plugin Contributions:
56

Re: General Data Protection Rules GDPR

"We share your Personal Information with third parties to help us use your Personal Information, as described above."

To me, this would be better worded as,

"We share your Personal Information with third parties to help us process orders, as described above."

26 May 2018, 7:30 PM
#112
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,694
Plugin Contributions:
56

Re: General Data Protection Rules GDPR

mesnitu:

Well, it was a pain, but personally I do like this law. And I'm European.
I'm tired of getting phone messages, emails, from companies that I've never contacted.
Those days are over (I hope).

I would bet my bottom dollar they're not. Laws like this inconvenience honest vendors and don't slow down the bad guys one bit.
Bad guys are criminals. They are not concerned with obeying the law. That's why we call them bad guys!

26 May 2018, 8:23 PM
#113
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

swguy:

I am astonished that you are astonished. This is a huge pain in the neck. I'm tempted to do likewise.

DITTO. For now, We're using GDPR recital 23 and removing EU from advertisement targets

27 May 2018, 7:21 PM
#114
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,694
Plugin Contributions:
56

Re: General Data Protection Rules GDPR

GDPR Checklist: https://gdprchecklist.io/

27 May 2018, 10:28 PM
#115
torvista avatar

torvista

Totally Zenned

Join Date:
Aug 2007
Location:
Gijón, Asturias, Spain
Posts:
2,872
Plugin Contributions:
7

Re: General Data Protection Rules GDPR

@jsweb
Thanks for making your efforts public. You should put it on Github for the moment, this is not really the place to discuss code.

But:

  1. includes\modules\pages\privacy_review\header_php.php
    has a block of code in it for sending an email.

As far as I can see, there is nothing in includes\templates\MYTEMPLATE\templates\tpl_privacy_review_default.php
to send that: the "send" action is missing.

I am guessing this header code is copied from delete_account and has not been cleaned.

  1. There are many instances of incorrect break tags: <br/>.

regards
Steve

28 May 2018, 1:35 PM
#116
mshultise avatar

mshultise

Zen Follower

Join Date:
Feb 2005
Location:
Captain Cook, Hawaii
Posts:
172
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

HeathenMagic:

A lot of websites are sending email to ask to resubscribe to newsletter. Are there any implications for not doing this? I asked the newsletter people I use, even they are not sure how to proceed.

Probably not the best solution, but a while back I created a Mailchimp account. I added all customers to the list. I disabled the default newsletter checkbox in my Zen Cart (and I think I set newsletters to NO in all user records).

I added a link in the new customer email telling them to click if they wanted the newsletter.

In the first newsletter I sent out, I told people I had switched to Mailchimp, and that if they wished at any time to remove themselves, click the link at the bottom. (I realize this forced an OPT-OUT rather than OPT-IN but decided to do it this way). If one wanted to make this an OPT-IN you would not import anyone into Mailchimp and might use the email all customers function with the Mailchimp signup link.

28 May 2018, 7:27 PM
#117
mshultise avatar

mshultise

Zen Follower

Join Date:
Feb 2005
Location:
Captain Cook, Hawaii
Posts:
172
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

While I applaud the work done so far by others, I have decided to temporarily ban European visitors until I can become compliant. I will continue to work towards that goal myself, but in the meantime..

I think I have only had a couple of customers in other countries so far.

I found a service that blocks EU visitors for free, up to 25,000 pageloads per month. It took all of 20 minutes from start to finish (most time spent adding 1 line in my header for both Zen-Cart and Wordpress). I tested it with a VPN and it seems to work fine. ezigdpr.com

As I say, I will continue to implement changes to my customers Zen-carts but this has allowed me more time to do it right.

29 May 2018, 6:49 PM
#118
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,694
Plugin Contributions:
56

Re: General Data Protection Rules GDPR

mshultise:

In the first newsletter I sent out, I told people I had switched to Mailchimp, and that if they wished at any time to remove themselves, click the link at the bottom. (I realize this forced an OPT-OUT rather than OPT-IN but decided to do it this way).

This is actually a violation of MailChimp's TOS. I encourage others not to do this.

29 May 2018, 6:57 PM
#119
design75 avatar

design75

Totally Zenned

Join Date:
Dec 2009
Location:
Amersfoort, The Netherlands
Posts:
2,862
Plugin Contributions:
5

Re: General Data Protection Rules GDPR

And in a lot of countries that is called spamming, and has been for years.

29 May 2018, 7:02 PM
#120
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,694
Plugin Contributions:
56

Re: General Data Protection Rules GDPR

For those who are not aware: the definition Mailchimp uses of Spam is a pretty common one; it's on the Spamhaus website: https://www.spamhaus.org/consumer/definition/

Spam is bulk, unsolicited email.

Easy peasy. Govern yourselves accordingly!