Privacy Policy
Privacy Policy 1. Our Privacy Statement. 1.1 Application. This Privacy Policy sets forth our policy with respect to information that can be associated with, or which relates to, a person and/or could be used to identify a person ("Personal Data") that is collected from Users on or through the Services provided by HigH Sport (as defined in paragraph 2 of the HigH Sport Terms and Conditions, incorporated herein by reference). We take the privacy of your Personal Data seriously. Because of that, we have created this Privacy Policy. Please read this Privacy Policy as it includes important information regarding your Personal Data and other information. "Non-Personal Data", as used in this Privacy Policy, is therefore any information that does not relate to a person and/or cannot be used to identify a person. When you interact with the Services, we may collect Non-Personal Data. The limitations and requirements in this Privacy Policy on our collection, use, disclosure, transfer, and storage/retention of Personal Data do not apply to Non-Personal Data.
2. Personal Data That We Collect. When you use or interact with us through the Services, we may collect Personal Data. Sometimes this will be on our own behalf and other times this will be on behalf of an Organiser using our Services to run an event. This is an important distinction for EU data protection law purposes and is explained in more detail in Section 16 below. 2.1 All Users. Information you provide to us: For all Users we collect Personal Data when you voluntarily provide such information to the Services, such as when you register for access to the Services, contact us with inquiries, respond to one of our surveys or browse or use certain parts of the Services. The Personal Data we may collect includes without limitation your name, address, email address and other information that enables Users to be personally identified. Information we automatically collect: We also automatically collect certain technical data that is sent to us from the computer, mobile device, and/or browser through which you access the Services ("Automatic Data"). Automatic Data, includes without limitation, a unique identifier associated with your access device and/or browser (including, for example, your Internet Protocol (IP) address) characteristics about your access device and/or browser, statistics on your activities on the Services, information about how you came to the Services and data collected through Cookies, Pixel Tags, Local Shared Objects, Web Storage, and other similar technologies. You can find out more information about how we use Cookies and other similar tracking technologies in our Cookie Statement. When you register for the Services or otherwise submit Personal Data to us, we may associate other Non-Personal Data (including Non-Personal Data we collect from third parties) with your Personal Data. At such instance, we will treat any such combined data as your Personal Data until such time as it can no longer be associated with you or used to identify you. 2.2 Organisers. As an Organiser, we will collect additional Personal Data from you. Information you provide to us: In some cases, we may collect your credit card information (e.g., your credit card number and expiration date, billing address, etc.), some of which may constitute Personal Data, to secure certain payments. In addition, if you use our payment processing services, we will collect financial information from you (e.g., your bank account information or an address to send checks) as necessary to facilitate payments and information required for tax purposes (e.g., your taxpayer identification number). In accordance with Requirement 3.1 of the Payment Card Industry Data Security Standard (PCI DSS), we have established compliant data retention and disposal procedures to ensure that records no longer needed are deleted promptly and adequately. All data is secured in accordance with PCI DSS in all sections, and the following requirements for retention and disposal are complied with: all sensitive and credit card data provided for our Services will be destroyed when no longer required for legal, contractual, or legitimate business purposes. We also implement a quarterly process to identify and securely delete stored cardholder data that exceeds the defined retention and disposal requirements. We will take all necessary technical and administrative measures to ensure deleted cardholder data are inaccessible and unavailable for appropriate users. To further comply with regulations, system and audit logs showing access to private stored data will be retained for at least one year. Information we obtain from other sources: We may also collect or receive Personal Data from third party sources, such as third-party websites, your bank, our payment processing partners and credit reporting agencies. 2.3 Consumers. As a Consumer, we will collect additional Personal Data from you, sometimes for our own purposes and other times on behalf of an Organiser (see Section 16 below for more information). Information you provide via HigH Sport Properties or Applications: If you register for a paid event, you will provide financial information (e.g., your credit card number and expiration date, billing address, etc.) some of which may constitute Personal Data. In accordance with Requirement 3.1 of the Payment Card Industry Data Security Standard (PCI DSS), we have established compliant data retention and disposal procedures to ensure that records no longer needed are deleted promptly and adequately. All data is secured in accordance with PCI DSS in all sections, and the following requirements for retention and disposal are complied with: all sensitive and credit card data provided for our Services will be destroyed when no longer required for legal, contractual, or legitimate business purposes. We also implement a quarterly process to identify and securely delete stored cardholder data that exceeds the defined retention and disposal requirements. We will take all necessary technical and administrative measures to ensure deleted cardholder data are inaccessible and unavailable for appropriate users. To further comply with regulations, system and audit logs showing access to private stored data will be retained for at least one year. Organisers can also set up event registration pages to collect virtually any information from Consumers in connection with registration for an Organiser's event listed on the Services. HigH Sport does not control an Organiser's registration process nor the Personal Data that they collect. Personal Data collected on behalf of Organisers is provided to the Organiser of the applicable event in accordance with "How We Disclose and Transfer Your Personal Data: Organisers" below. Information we obtain from other sources: We may also collect or receive Personal Data from third party sources, such as Organisers, other Consumers, social media or other third-party integrations, your credit card issuing bank, our payment processing partners or other third parties. 3. How We Use Your Personal Data. We collect and use the Personal Data we collect in a manner that is consistent with this Privacy Policy. We may use the Personal Data as follows: 3.1 Specific Reason. If you provide Personal Data for a certain purpose, we may use the Personal Data in connection with the purpose for which it was provided. For instance, if you contact us by e-mail, we will use the Personal Data you provide to answer your question or resolve your problem and will respond to the email address from which the contact came. 3.2 Access and Use. If you provide Personal Data in order to obtain access to or use of the Services or any functionality thereof, we will use your Personal Data to provide you with access to or use of the Services or functionality and to analyse your use of such Services or functionality. For instance, if you supply Personal Data relating to your identity or qualifications to use certain portions of the Services, we will use that information to decide whether to grant you access to use such Services and to assess your ongoing qualification to use such Services. 3.3 Internal Business Purposes. We may use your Personal Data for internal business purposes, including without limitation, to help us improve the content and functionality of the Services, to better understand our Users, to improve the Services, to protect against, identify or address wrongdoing, to enforce our Terms of Service, to manage your account and provide you with customer service, and to generally manage the Services and our business. 3.4 HigH Sport Marketing Communications. Where it is in accordance with your marketing preferences, we may use your Personal Data to contact you in the future for our marketing and advertising purposes, including without limitation, to inform you about services or events we believe might be of interest to you, to develop promotional or marketing materials and provide those materials to you, and to display content and advertising on or off the Services that we believe might be of interest to you. See "Opt Out from Electronic Communications" below on how to opt out of HigH Sport Marketing Communications. 3.5 Organiser Emails. We allow Organisers to use our email tools to contact Consumers for their current and past events, so you may receive emails from our system that originate with such Organisers and that we send on their behalf. If you registered for an event on the Services, your email address is available to that Organiser. However, Organisers may also import the email addresses they have from external sources and send communications through the Services to those email addresses, and we will deliver those communications to those email addresses on the Organiser's behalf. The Organiser and not HigH Sport is responsible for sending these emails. See "Opt Out from Electronic Communications" below on how to opt out of Organiser initiated communications. 3.6 Other Purposes. If we intend to use any Personal Data in any manner that is not consistent with this Privacy Policy, you will be informed of such anticipated use prior to or at the time the Personal Data is collected, or we will obtain your consent after such collection but prior to such use. 3.7 Aggregated Personal Data. In an ongoing effort to understand and serve our Users better, we often conduct research on our customer demographics, interests and behavior based on Personal Data and other information that we have collected. This research is typically conducted on an aggregate basis only that does not identify you. Once Personal Data is in an aggregated form, for purposes of this Privacy Policy, it becomes Non-Personal Data. 4. How We Disclose and Transfer Your Personal Data. 4.1 Business Transfers. As we develop our business, we might sell or buy businesses or assets. In the event of a corporate sale, merger, reorganisation, dissolution or similar event, Personal Data may be part of the transferred assets. You acknowledge and agree that any successor to or acquirer of HigH Sport (or its assets) will continue to have the right to use your Personal Data and other information in accordance with the terms of this Privacy Policy. 4.2 Parent Companies, Subsidiaries and Affiliates. We may also share your Personal Data with our parent companies, subsidiaries and/or affiliates for purposes consistent with this Privacy Policy. Our parent companies, subsidiaries and affiliates will be bound to maintain that Personal Data in accordance with this Privacy Policy. 4.3 Agents, Consultants and Service Providers. We may share your Personal Data with our contractors and service providers who process Personal Data on behalf of HigH Sport to perform certain business-related functions. These companies include our marketing agencies, database service providers, backup and disaster recovery service providers, email service providers and others. When we engage another company to perform such functions, we may provide them with information, including Personal Data, in connection with their performance of such functions. 4.4 Organisers. When you purchase tickets to, register for or donate to an event through the event page, or through a related fundraising page on the Services, we provide the Personal Data entered on the applicable event or related fundraising page to the Organisers of such event or related fundraising page. For fundraising pages, we may provide your Personal Data both to the Organiser charity of the fundraising page and the Organiser of the event to which the fundraising page is linked. In some instances, an Organiser may appoint a third party, which may or may not be affiliated with the Organiser, to create an event or fundraising page on its behalf (we call these third parties ("Third Party Organisers"). For example, and without limitation, a concert venue (the Organiser, in this case) may allow third party promoters or production companies (the Third Party Organisers) to create events that will be hosted at the Organiser's venue using its HigH Sport account. In that case, we may provide your Personal Data to the Third Party Organisers on behalf of the Organisers. We are not responsible for the actions of these Organisers, or their Third Party Organisers, with respect to your Personal Data. It is important that you review the applicable policies of the Organisers, and if applicable and available, their appointed Third Party Organisers, of an event (and the related fundraising page, if applicable) before providing Personal Data or other information in connection with that event or related fundraising page. Similarly, if you are a member of an Organiser's organisation within HigH Sport, your Personal Data will be available to the Organiser and shared with those Third Party Organisers granted permission by the Organiser to view all members of the Organiser's organisation. 4.5 Facebook and Other Third Party Connections. You can connect your HigH Sport account to your accounts on third party services like Facebook, in which case we may collect, use, disclose, transfer and store/retain information relating to your account with such third party services in accordance with this Privacy Policy. For example, if you connect with Facebook, we store your Facebook ID, first name, last name, email, location, friends list and profile picture and use them to connect with your Facebook account to provide certain functionality on the Services, like recommending events that your Facebook friends are interested in and sharing the events you are interested in, or attending, with certain groups of people like your Facebook friends. 4.6 Legal Requirements. We may disclose your Personal Data if required to do so by law in order to (for example) respond to a subpoena or request from law enforcement, a court or a government agency (including in response to public authorities to meet national security or law enforcement requirements), or in the good faith belief that such action is necessary to (a) comply with a legal obligation, (b) protect or defend our rights, interests or property or that of third parties, (c) prevent or investigate possible wrongdoing in connection with the Services, (d) act in urgent circumstances to protect the personal safety of Users of the Services or the public, or (e) protect against legal liability. 5. How We Store Your Personal Data. We may store Personal Data itself or such information may be stored by third parties to whom we have transferred it in accordance with this Privacy Policy. We take what we believe to be reasonable steps to protect the Personal Data collected via the Services from loss, misuse, unauthorised use, access, inadvertent disclosure, alteration, and destruction. However, no network, server, database or Internet or e-mail transmission is ever fully secure or error free. Therefore, you should take special care in deciding what information you send to us electronically. Please keep this in mind when disclosing any Personal Data.
6. How You Can Access, Update, Correct or Delete Your Personal Data. You can request access to some of your Personal Data being stored by us. You can also ask us to correct, update or delete any inaccurate Personal Data that we process about them. If you are a registered User, you can exercise these rights by logging in and visiting the My Account page. Both registered and unregistered Users may also exercise these rights by contacting us directly by email or at the address specified below. If a Consumer initiates a data deletion request, HigH Sport is authorised to delete or anonymize Personal Data of the requesting Consumer from the Services even if that means removing its availability to the Organiser through the Services. However, if you are a Consumer, you understand that even if HigH Sport deletes or anonymizes your Personal Data upon your request or pursuant to this Policy, your Personal Data may still be available in the Organiser's own databases if transmitted to the Organiser prior to HigH Sport receiving or taking action on any deletion or anonymization activity. We will consider and respond to all requests in accordance with applicable law. 7. How Long We Retain Your Personal Data. We may retain your Personal Data so long as you are registered to use the Services, unless such retention conflicts with the requirements of PCI DSS and/or GDPR standards. You may close your account by contacting us. However, we may retain Personal Data for an additional period as is permitted or required under applicable laws. Even if we delete your Personal Data it may persist on backup or archival media for an additional period of time for legal, tax or regulatory reasons or for legitimate and lawful business purposes.
8. Cookies, Pixels Tags, Local Shared Objects, Web Storage And Similar Technologies. Please refer to our Cookie Statement for more information about our use of cookies and other similar tracking technologies.
9. Your Choices. You have several choices available when it comes to your Personal Data: 9.1 Limit the Personal Data You Provide. You can browse the Services without providing any Personal Data (other than Automatic Data to the extent it is considered Personal Data under applicable laws) or with limiting the Personal Data you provide. If you choose not to provide any Personal Data or limit the Personal Data you provide, you may not be able to use certain functionality of the Services. For instance, to buy tickets as a Consumer, your name and email address will be required by the Organiser. 9.2 Opt Out from Electronic Communications. (a) HigH Sport Marketing Communications. Where it is in accordance with your marketing preferences, HigH Sport may send you electronic communications marketing or advertising the Services themselves or events on the Services, to the extent you have registered for the Services or purchased a ticket and/or registration to an event listed on the Services. You can also "opt out" of receiving these electronic communications by clicking on the "Unsubscribe" link at the bottom of any such electronic communication. In addition, you may also manage your email preferences at any time by logging in (or signing up and then logging in), clicking on "Account" and then "Email Preferences." (b) Organiser Initiated Communications. Organisers may use our email tools to send electronic communications to those on their email subscription lists, including Consumers who have registered for their events on the Services in the past. Although these electronic communications are sent through our system, HigH Sport does not determine the content or the recipients of these electronic communications. Organisers are required to use our email tools only in accordance with all applicable laws. HigH Sport provides an "Unsubscribe" link on each of these emails, which allows recipients to "opt out" of electronic communications from the particular Organiser. (c) Social Notifications. If you connect your Facebook account or sign up for other social media integrations whose product features include social notifications (i.e., updates on what your friends are doing on the Services), you will receive these social notifications. You can manage these social notifications by toggling your social settings to private or disconnecting such integration. (d) Transactional or Responsive Communications. Certain electronic communications from HigH Sport are responsive to your requests. For instance, if you are a Consumer, we must email you your ticket or registration on behalf of the Organiser when you purchase such ticket or registration. As a further example, if you email our customer support department, we will return your email. Notwithstanding any unsubscribe election that you have made, you will still receive these transactional or responsive emails. You can stop receiving these types of emails only by contacting us. By electing to stop receiving all electronic communications from us or through our system you will no longer receive any updates on events you have created (including pay-out issues) or on events you are registered to attend (including emails with your tickets). We do not recommend that you do this unless you plan to stop using the Services, are not currently registered for an event, are not currently organising an event, and will have no need to receive further communications from us or through our system. (e) Retention. It may take up to forty-eight (48) hours for us to process an unsubscribe request. Even after you opt out of all electronic communications, we will retain your Personal Data in accordance with this Privacy Policy, however, we will no longer use it to contact you. However, Organisers who have received your Personal Data in accordance with this Privacy Policy may still use that Personal Data to contact you in accordance with their own privacy policies, but they may not use our system to do so. 9.3 Do Not Track. We currently do not participate in any "Do Not Track" frameworks that would allow us to respond to signals or other mechanisms from you regarding the collection of your Personal Data.
10. Exclusions. 10.1 Personal Data Provided to Others. This Privacy Policy does not apply to any Personal Data that you provide to another User or visitor through the Services or through any other means, including to Organisers on event pages or information posted by you to any public areas of the Services. 10.2 Third Party Links. This Privacy Policy applies only to the Services. The Services may contain links to other websites not operated or controlled by us (the "Third Party Sites"). The policies and procedures we described here do not apply to the Third Party Sites. The links from the Services do not imply that we endorse or have reviewed the Third Party Sites. We suggest contacting those sites directly for information on their privacy policies.
11. Children - Children's Online Privacy Protection Act We do not knowingly collect Personal Data from children under the age of thirteen (13). If you are under the age of thirteen (13), please do not submit any Personal Data through the Services. We encourage parents and legal guardians to monitor their children's Internet usage and to help enforce our Privacy Policy by instructing their children never to provide Personal Data through the Services without their permission. If you have reason to believe that a child under the age of 13 has provided Personal Data to us through the Services, please contact us and we will endeavor to delete that information from our databases. 12. International Privacy Laws. In order to offer and provide HigH Sport Services, we are a business that processes and stores personal information provided by and about EU citizens. Accordingly, we comply with the General Data Protection Regulation (GDPR). Article 5(e) of the GDPR provides that data must be “kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.” We comply with this requirement by storing your Personal Data only so long as is necessary for legitimate business purposes. All Personal Data acquired from EU citizen users who access our Services is limited in scope to what is necessary to complete the agreed upon functions for the Services desired by the user. Our general retention schedule is __________________, our rules for safeguarding data during retention are ____________________, and our guidelines for destruction of data are __________________. In the event of a breach, our policy is ___________________. If you are visiting the Services from outside the United States, please be aware that you are sending information (including Personal Data) to the United States where our servers are located. That information may then be transferred within the United States or back out of the United States to other countries outside of your country of residence, depending on the type of information and how it is stored by us. These countries (including the United States) may not necessarily have data protection laws as comprehensive or protective as those in your country of residence; however, our collection, storage and use of your Personal Data will at all times continue to be governed by this Privacy Policy.
EU - US Privacy Shield For Personal Data we receive from the EEA, HigH Sport has certified its compliance to the EU-US Privacy Shield as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal data from the European Union countries. We have certified that we adhere to the Privacy Shield principles of Notice, Choice, Accountability for Onward Transfers, Security, Data Integrity & Purpose Limitation, Access and Recourse, Enforcement & Liability when processing Personal Data from the EEA in the United States. Though the EU US Privacy Shield Framework has virtually been invalidated by the Court of Justice of the European Union, we continue to participate in the Privacy Shield framework to demonstrate our commitment to protect personal information in accordance with a set of privacy principles with meaningful protections and recourse for EU citizens. We continue to hold ourselves accountable to the promises made under the Privacy Shield, at a minimum.
13. Changes To This Privacy Policy. The Services and our business may change from time to time. As a result, at times it may be necessary for us to make changes to this Privacy Policy. We reserve the right, in our sole discretion, to update or modify this Privacy Policy at any time (collectively, "Modifications"). Modifications to this Privacy Policy will be posted to the Site with a change to the "Updated" date at the top of this Privacy Policy. In certain circumstances HigH Sport may, but need not, provide you with additional notice of such Modifications, such as via email or with in-Service notifications. Modifications will be effective thirty (30) days following the "Updated" date or such other date as communicated in any other notice to you. Please review this policy periodically, and especially before you provide any Personal Data. This Privacy Policy was updated on the date indicated above. Your continued use of the Services following the effectiveness of any Modifications to this Privacy Policy constitutes acceptance of those Modifications. If any Modification to this Privacy Policy is not acceptable to you, you should cease accessing, browsing and otherwise using the Services.