Last updated: May 31, 2019
Blackhawk Network (Canada) Ltd. and its Canadian affiliates (“Blackhawk”, “we”, “us” or “our”) are committed to protecting your personal information. This privacy policy (the “Policy”) describes how we use and disclose personal information (including “personal data” as defined in European and other applicable data protection laws) that we collect about you and the rights you have with respect to that information. This Policy applies to personal information that Blackhawk collects about users of our websites (including www.blackhawknetwork.com), our mobile applications and the services and features of those sites and applications (collectively, the “Sites”), as well as information we collect in the course of providing our services (the “Services”) and when individuals communicate with us about our Sites and Services, whether in person, by telephone, by mail or otherwise. Where we act as a data processor or service provider on behalf of another controller or entity, we collect, use and disclose certain personal information only on the instructions of that collector, and our processing of your personal information is subject to their instructions and privacy policies .
The Policy explains:
• How we collect, use and disclose your information or information about you;
• How our online advertisements (such as banner ads) on third-party sites process data;
• Your choices regarding our use of your personal information;
• How you can access and update your information; and
• How to exercise your rights.
Sometimes we feature on a third-party site (such as a Blackhawk page or indicator on a social media site) or link to a third-party site. When this is the case, the third party’s privacy policies and terms of use, not ours, will apply unless otherwise stated. In addition, some of Blackhawk’s services are offered through banks or other financial institutions. In these cases, the third party’s policies will govern their use of your personal information.
We collect personal information directly from you, through third parties, or automatically through our Sites and those linked to our Services, subject to applicable laws set forth below. We may collect personal information directly from you when you provide it to us. This may occur when you complete applications, create accounts, make a purchase, fund your account, submit forms, respond to surveys, or fill out various online fields on our Sites. We also collect personal information when you contact us for information, customer support, or employment inquiries. You are not required to provide us with your personal information. However, if you choose not to disclose certain information, we may not be able to provide you with certain services, such as saving your shopping cart choices.
We may also collect personal information from third parties when you provide it to us. For example, if you choose to use our Send a Gift to a Friend service or register a family member for an account, we will ask you for their name and street address or email address. In addition, we may collect personal information from a third party through our Refer a Friend program. Blackhawk retains this information for the sole purpose of completing the transaction. If you provide us with personal information about a third party, you must obtain that person’s consent to do so, if required by applicable law. If you provide personal information about a friend or family member and that person wishes to have that information deleted, they should contact us by email at privacy@bhnetwork.com . We are not always able to delete personal information. If we do, we will notify the person and explain why we are unable to comply with their request.
Personal information we collect directly from you:
Account Creation and Customer Service
• Your contact information, such as your name, email address, mailing address, fax or telephone number;
• Your payment and financial information, such as your credit or other payment card information, bank account information or billing address;
• Your shipping address and related details;
• Your resume, employment and education history, name and contact information, background and references, in cases where you respond to a job posting or contact us about employment opportunities;
• Information about your business and work experience;
• Your government-issued personal and tax identification numbers, including your social insurance number (for current and potential customers);
• Unique identifiers, such as username, account number or password;
• Preference information, such as product wish lists, order history or marketing preferences;
• Information about your business, such as your business name, size or type;
• Demographic information, such as age, gender, interests and zip code.
In cases where the personal information we collect is necessary to comply with the law or to enter into or perform an agreement with you, we will inform you at the time of collection. If we are unable to collect this information, we may not be able to welcome you as a customer or provide you with our products or services.
Comments, Posts, Submissions and Testimonials
When you submit an online form, participate in a survey, contest, promotion or sweepstakes, join an online chat or post on a blog, request customer support or post a testimonial, we collect personal information from you, such as your contact information and other information you choose to share. We post personal testimonials from satisfied customers on some of our sites and in print ads with your consent. Some of our sites offer publicly accessible blogs. Any information you provide in these areas may be read, collected and used by others who have access to them. You may delete your comments or posts on a blog or community forum. If you are unable to do so, contact us by email at privacy@bhnetwork.com . If we are unable to delete your personal information, we will explain why we cannot comply with your request.
Autres communications et soutien
Nous recueillons des renseignements personnels lorsque vous communiquez avec nous au sujet des Services, y compris durant les appels téléphoniques (et les enregistrements d’appels), les clavardages ou par courriel. Les renseignements personnels recueillis peuvent comprendre les coordonnées, les renseignements sur l’emploi, les préférences des utilisateurs et toute autre information que vous choisissez de partager. Veuillez inclure uniquement les renseignements personnels dont nous avons besoin pour répondre à votre demande.
Géolocalisation
Avec votre consentement, nous pouvons également recueillir des renseignements liés à votre emplacement pour vous aider, par exemple, à localiser un magasin offrant nos produits et services dans votre région ou à des fins de prévention de la fraude. Vous pouvez refuser de partager vos renseignements sur votre emplacement en modifiant les paramètres de votre appareil. Si vous choisissez cette option, il est possible que vous ne puissiez pas utiliser certaines fonctionnalités, surtout lorsque nous utilisons les renseignements liés à votre emplacement géographique pour éviter la fraude.
Renseignements personnels que nous recueillons auprès de tierces parties :
Il arrive parfois que nous recueillions des renseignements personnels auprès de sources tierces. Par exemple, sous réserve des lois applicables, nous pouvons confirmer votre adresse auprès des services postaux ou recevoir des renseignements personnels vous concernant de la part de nos clients qui utilisent nos Services. De même, si nos utilisateurs choisissent d’envoyer un cadeau à leur ami par l’intermédiaire de nos Sites, nous leur demanderons le nom et les coordonnées de cette personne.
Nous pouvons également offrir un service de recommandation où les utilisateurs peuvent recommander nos Services à d’autres personnes qu’ils connaissent, sous réserve des restrictions des lois locales applicables. Si vous choisissez d’utiliser notre service de recommandation pour parler de nos Services à vos amis, nous vous fournirons un code et des instructions d’inscription que vous pourrez partager avec vos amis. Lorsque la loi locale le permet, nous exploitons ces recommandations selon le principe de l’option de retrait. Si des renseignements personnels vous concernant nous ont été fournis et que vous souhaitez que nous les supprimions, vous pouvez nous envoyer un courriel à privacy@bhnetwork.com.
Renseignements personnels que nous recueillons automatiquement :
Nous et nos fournisseurs de services recueillons de manière automatique des renseignements au sujet de votre utilisation de nos Sites et Services par le truchement de témoins, de balises Web, de scripts java, de fichiers journaux, de pixels-espion et autres technologies. Ces renseignements comprennent : vos nom de domaine, type de navigateur, préférences linguistiques pour la navigation, type d’appareil et système d’exploitation, les pages que vous visualisez et les liens sur lesquels vous cliquez sur nos Sites, votre adresse IP, le numéro d’identification de votre appareil ou d’autres identifiants, des renseignements sur votre emplacement, la date, l’heure et la durée d’utilisation de nos Services, l’URL de référence, votre activité sur nos Sites et les renseignements de géolocalisation de l’appareil (lorsque les paramètres de celui-ci le permettent).
Nous recueillons également des renseignements provenant de services d’analyse, y compris Google Analytics, afin de compiler et d’analyser les renseignements issus de l’utilisation de nos Services, tels que les habitudes d’utilisation globales, les préférences des utilisateurs, les heures de pointe, le contenu préféré et d’autres renseignements.
Consultez la section « Témoins et suivi en ligne » ci-dessous pour plus de détails.
Nous pouvons utiliser les renseignements personnels que nous recueillons aux fins suivantes :
• Prestation de nos Services : Pour fournir nos services, exploiter nos sites, répondre à vos demandes de renseignements, remplir vos commandes, traiter vos paiements, signaler et corriger les bogues et les erreurs et effectuer des mises à niveau et des activités d’entretien;
• Service et soutien à la clientèle : Pour vous envoyer des renseignements importants, comme des modifications apportées aux conditions et aux politiques ou à d’autres renseignements administratifs.
• Personnalisation : Pour personnaliser votre expérience sur un Site ou votre utilisation d’un Service, par exemple en adaptant le contenu que nous vous envoyons ou affichons afin de personnaliser les fonctions d’aide et les instructions, et pour personnaliser autrement votre expérience d’utilisation de nos Services.
• Marketing et promotions : Pour vous envoyer des communications de marketing pour lesquelles vous vous êtes inscrit;
• Publicité et référence : Pour aider à la publicité de nos Services sur des sites Web appartenant à des tiers et pour faire le suivi des références obtenues par l’entremise des sites Web de nos partenaires;
• Analyses et amélioration : Pour mieux comprendre comment les utilisateurs accèdent à nos Services et les utilisent, et pour d’autres fins de recherche et d’analyse, par exemple l’évaluation et l’amélioration de nos Services;
• Vérification de l’identité et détection de la fraude : Pour vérifier votre identité et/ou votre emplacement afin d’autoriser un accès à vos comptes, vous permettre de réaliser des transactions en ligne et sécuriser vos renseignements personnels, de même que pour le contrôle des risques, la détection et la prévention des fraudes et la conformité aux lois et réglementations;
• Protection de nos droits juridiques et prévention du mésusage : Pour protéger nos Services, empêcher l’accès non autorisé et autre mésusage et, dans la mesure où nous estimons que cela est nécessaire, pour mener des enquêtes, prévenir ou prendre les mesures appropriées à l’égard d’activités illégales, de fraudes soupçonnées, de situations présentant une menace potentielle pour la sécurité d’une personne ou de violations de nos Conditions d’utilisation ou de la présente Politique.
• Conformité à nos obligations juridiques : Pour nous conformer à la loi ou à une ordonnance juridique, par exemple dans les cas où nous sommes tenus de divulguer des renseignements en réponse à une demande légale des autorités publiques, y compris en ce qui a trait aux obligations de divulgation en vertu de la loi ou aux fins de la sécurité nationale; et
• Activités d’exploitation normales: As necessary for the administration of our normal operating, accounting, bookkeeping and legal functions.
Aggregated and Anonymized Information
We may also generate aggregated or anonymized information about users for marketing, advertising, research, or other similar purposes.
Purpose of Use
In the table below, we explain the purposes for which we use and process your personal information, as well as the legal bases for such use and processing under the European Union General Data Protection Regulation (“GDPR”) and other applicable laws .
Buts de l’utilisation (voir ci-dessus)
Fondement juridique du traitement (le cas échéant)
Prestation de nos services
Service et soutien à la clientèle
• Nécessaires pour conclure et réaliser un contrat avec vous (à votre demande ou selon les besoins pour vous fournir les Services)
• Nos intérêts commerciaux légitimes*
Personnalisation
Marketing et promotions
Publicités et références
• Nos intérêts commerciaux légitimes*
• Avec votre consentement
Analyses et améliorations
• Nos intérêts commerciaux légitimes*
Protection de nos droits juridiques et prévention du mésusage
Vérification de l’identité et détection de la fraude
Conformité à nos obligations juridiques
• Conformité à la loi
• Établir, défendre et protéger nos intérêts juridiques
• Nos intérêts commerciaux légitimes*
Activités d’exploitation normales
• Nos intérêts commerciaux légitimes*
• Établir, défendre et protéger nos intérêts juridiques
• Conformité à la loi
* For personal information from the EU, the processing is in our legitimate interests if they are not overridden by your legitimate interests and fundamental rights. Our legitimate interests include our interests in verifying identification, detecting and preventing fraud, protecting and improving our products and services, supporting our general business operations, and complying with our legal obligations. We only send marketing communications to EU consumers who provide consent or who are covered by exemptions from the passive opt-in principle.
We do not sell your personal information to third parties.
Affiliates
Blackhawk Network (Canada) Ltd. and its Canadian affiliates are part of a global group of companies. We disclose personal information between our affiliates and subsidiaries for the purposes set out in this Policy. In addition, their treatment of your personal information is subject to this Policy. Blackhawk’s affiliates have signed written agreements with each other that impose appropriate security measures for the protection of your personal information, in accordance with applicable privacy laws.
Service Providers
We disclose your personal information to certain companies that provide services to us and/or on our behalf and subject to our written instructions, such as payment of shipping costs, hosting and other support services. These companies may be located in the EU, US and other territories.
Customers and Partners
When we process personal information on behalf of our customers or partners, we process and share your personal information with that entity subject to their instructions. In such cases, the customer or partner is the controller of your personal information. This Policy does not apply to Blackhawk’s processing of your personal information in its capacity as the customer’s or partner’s data processor and our use of your personal information is subject to their instructions. Where our customers or partners process and use your personal information as agents, their own privacy policy applies.
Referral Partners
We offer referral-based commission schemes through third-party partners for the purpose of allowing publisher websites to refer users to our pages for purchases. These partners will be identified when you sign up, and we will obtain your consent where required by local law (and no other legal basis applies). Personal information collected about you is owned by Blackhawk and the third-party partner who are independent controllers of the information. This Policy governs Blackhawk’s use of the data only. The partner’s privacy policy governs its use of the data.
Brief Product Notices
Certain products offered in conjunction with banks are subject to exclusive data sharing agreements. Where applicable, Blackhawk will make available on its website brief privacy notices of data sharing policies relating to each product.
Other Disclosures
We may also disclose your personal information in any of the situations described below:
• As permitted or required by law, such as to comply with a subpoena or other legal process;
• When we believe, in good faith, that disclosure is necessary to respond to allegations against us, protect our rights, protect your safety or the safety of others, investigate fraud, respond to legal process (eg, a subpoena or warrant) or respond to a governmental request;
• If Blackhawk is involved in a merger, acquisition or sale of all or a portion of its assets, or in the event of a bankruptcy or dissolution of the company, your personal information may be transferred to an acquiring company or a third party, including in anticipation of such business transactions or for due diligence purposes, subject to applicable restrictions under applicable law; and
• To any other third party with your prior consent.
Aggregated and Anonymized Information
We may share aggregated or anonymized information about users with certain third parties for marketing, advertising, research or other purposes.
We and our third-party service providers may collect information automatically when you use our Sites or Services or read our emails, including through cookies, web beacons, pixels, tags, scripts, HTML5, and log files. We or our service providers may combine this information with other information, including personal information we collect about you, to record your preferences, gather information about the use of our Services, determine when our emails are viewed, personalize content and ads, and analyze the performance of our ads.
Log Files
Most browsers collect certain information, including your IP address, device type, screen resolution, operating system version, and Internet browser type and version. This information is automatically collected and stored in log files. We may link this information to personal information we have collected about you.
Cookies
Cookies are very small files with a unique identifier that are transferred to your browser by our websites. These technologies allow us to collect information such as your browser type, time spent on our Sites, pages viewed, language preferences, and your relationship with us. We can use this information to analyze trends, administer the website, track users’ movements around the website, measure the effectiveness of our communications, tailor our advertising to you, and gather demographic information about our user base as a whole. These technologies may provide us with information about the devices and networks you use to access our Services, as well as other information about your interactions with our Services. For detailed information about the cookies used on the Services and how you can manage your cookie preferences or opt out of their use, please see our Cookie Policy. You may opt out of the use of cookies. You will need to manage your cookie settings for each device and browser you use. However, if you choose not to accept cookies, your use of the features of our sites may be limited or compromised, and you may not be able to access some of them. For detailed information about these mechanisms and how we collect information about your activity, please read our Cookie Policy.
Pixels, Web Beacons and Clear GIFs
These are tiny graphic elements containing a unique identifier and similar in function to cookies that we use to track users’ online movements within our web pages and Advertising Services, to personalize content, and to identify when our emails are viewed or forwarded.
Our third-party partners use local shared objects, such as Flash cookies, to integrate functionality into our sites. To manage Flash cookies, please click here.
Do Not Track Option
Our Site does not recognize “Do Not Track” signals. However, we do not track your online activities across Sites and we only track your activities within a Site when you log in to your account. However, our practices remain the same whether or not you enable the “Do Not Track” feature. For more information about Do Not Track signals, please click here or review our Cookie Policy .
Third-Party Analytics
We also use automated devices and applications like Google Analytics (learn more here ) to evaluate the use of our Services. These tools help us collect non-personal information about users, helping us improve our Services and user experiences. These analytics providers may use cookies and other technologies to provide their services on our behalf. See our Cookie Policy for more information about our use of analytics tools.
We partner with ad networks, Facebook, Google and other third party ad companies to manage our advertising on other sites. Our third party partner uses technologies such as cookies to collect information about your activities on this and other websites in order to provide you with personalized advertising based on your browsing activities and interests. Please see the “Cookies and Online Tracking” section above or our Cookie Policy for more information.
Marketing and Newsletters
If you subscribe to our newsletters, we will use your name and email address to send them to you. You may choose to stop receiving our newsletter or marketing emails at any time. To do so, simply follow the unsubscribe instructions in these emails or access the email preferences in your account.
Custom Audiences
Subject to local legal restrictions, we may disclose certain information (such as your email address) to third parties like Facebook (learn more about Facebook Custom Audiences here) to better target ads and content to our users and others with similar interests on those third parties’ platforms or networks (“Custom Audiences”). We can also work with third-party ad networks and marketing platforms that enable us and other participants to target the ads we and others serve to Custom Audiences. If you wish to opt out of our Custom Audiences, please email us at privacy@bhnetwork.com and we will remove you from our Custom Audiences.
Opting out of ad network mailing lists
If you would like to opt out of using cross-site information to serve you these targeted ads, you can opt out by clicking here (or, if you are a resident of the European Union, by clicking here ). You will continue to see ads on the sites you visit, but the ad networks you opted out of will no longer serve you targeted ads based on your activities on other sites. Please note, however, that these opt-out mechanisms use cookies, so if you delete or block cookies, or use a different device, your opt-out will no longer be in effect. For more information, visit www.aboutads.info .
To learn more about this and to opt out of interest-based ads from many ad networks, please visit our Cookie Policy . Please note: if you delete cookies or use a different device, your opt-out will no longer be in effect.
Our Sites include social media features, such as the Facebook “Like” button, hosted by a third party or directly on our website (“Widgets”). Please review the privacy policies of the relevant third party websites or services to learn more about the collection, use and disclosure of your personal information through these features. We will comply with any legal obligations imposed on the use of these technologies in certain jurisdictions, which may affect how these Widgets operate.
The security of your personal information is important to us. We have implemented safeguards to protect the personal information submitted to us. Please note that no data transmission over the Internet can be 100% secure. Therefore, we cannot guarantee the security of the personal information we process.
We retain your information for as long as your account is active or as needed to provide you with our services. To the extent permitted by applicable law, we may retain and use your information only as necessary to comply with our legal obligations, resolve disputes, maintain adequate records, and enforce our agreements.
Some of our websites offer you the opportunity to upload your portrait to create a personalized product. You have the option to make these images available in public repositories. You should be aware that any information you provide in these areas may be read, collected, and used by others who have access to them. You may request deletion of your personal information at any time. To request removal of your personal information from these public forums, please email us at privacy@bhnetwork.com or contact us by mail at the address listed below. Depending on the circumstances, we may not be able to delete your personal information, in which case we will notify you and explain why we cannot comply with your request.
Some countries and regions, including the European Union, have adopted laws that provide privacy rights to individuals residing in the EU. Regardless of your location and jurisdiction, Blackhawk may, in its sole discretion, choose to extend these rights to all individuals and comply with the requests detailed below. We do not charge for these services, but in some cases we may require additional proof of identity or ask you to clarify the scope and nature of your request if it is not sufficiently clear. If you are entitled to a right, we will respond to your request within the time limits required by law, or within a reasonable time if we respond voluntarily.
Please note that we will only respond directly to your request in cases where we are the data controller of your personal information. In cases where we are acting as a data processor on behalf of a client or partner, we will direct your request to that client or partner who is the controller of your personal information.
Access, Rectification, Portability and Deletion
You may have the right to access, rectify (correct) or delete the personal information we hold about you or you may request a restriction of processing. You may also have the right to request a summary or copy of your personal information or to request that some of your personal information be exported to another service provider, where such export is technically feasible (data portability). On some of our Sites, you can access, rectify or delete your personal information by changing the settings directly on your account page. There are, however, certain exceptions to these rights. For example, we cannot delete your personal information if we are required by law to retain it or if we hold it in connection with a contract we have with you. Similarly, you may be denied access to your personal information if doing so would reveal personal information about others or if we are prohibited by law from disclosing that information.
You may also request this by emailing us at privacy@bhnetwork.com or by contacting us by mail at the address below.
There are, however, certain limitations to these rights. For example, we cannot delete your personal information if we are required by law to keep it or if we hold it as part of a contract we have with you. Similarly, you may be denied access to your personal information if doing so would reveal personal information about others or if we are prohibited by law from disclosing that information. If we are unable to comply with your request, we will inform you of the reasons why we cannot do so.
Withdrawal of consent
Where we process your personal information based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of the processing undertaken before we withdrew your consent.
Objection to processing
You have the right to object to processing (including profiling) on the grounds of your legitimate interest where we process your personal information for the purposes of our legitimate interests. If you object, we must cease processing unless we are able to demonstrate compelling legitimate grounds which override your interests, rights and freedoms or where we need to process your personal information to establish, exercise or defend a legal claim. Where we process your personal information for the purposes of our legitimate interests, we consider that we are able to rely on such compelling legitimate grounds, but we will assess each situation on a case-by-case basis.
Objection to marketing
You also have the right to object to our use of your personal information (including profiling) for direct marketing purposes, for example where we use your personal information to invite you to promotional events.
Right to lodge a complaint
You have the right to lodge a complaint with your supervisory authority, if you consider that the processing of your personal information is in breach of applicable law.
To exercise your rights, please send an email to privacy@bhnetwork.com (or contact us as indicated in the “Contact Us” section below). It is important to note that revoking your consent may impact certain services, as may deleting certain personal information or objecting to its processing. We will respond to your request in accordance with applicable law and will inform you in case we are unable to comply with your request.
Our Sites are not directed to children and we do not knowingly collect personal information online from children under the age of 16. We therefore request that children not provide us with their personal information through our Sites.
The personal information we collect from you may be transferred to, accessed and stored in countries outside your country of residence, which may not provide the same level of data protection as your jurisdiction of residence. Your personal information may also be processed in a country outside your country of residence by one of our service providers. As a result, this information may be subject to access requests by governments, courts or law enforcement in those jurisdictions under their laws.
In cases where Blackhawk stores personal information outside the territory where it is collected, we take steps to ensure that such information receives an adequate degree of protection in the territories where we process and store such information. This includes implementing appropriate written agreements covering the conditions of processing and/or transfer of data, which incorporate standard contractual clauses approved by the European Commission (you can find a list of standard contractual clauses here: European Commission Standard Contractual Clauses), or in cases where a decision on the adequacy of protection has been issued by the European Commission for a particular country.
By submitting your personal information, you agree to the transfer, storage and processing of your information. We will ensure that your personal information is treated securely and in accordance with this Policy.
This Policy may be subject to change. We encourage you to review it from time to time. If we make material changes to this Policy in relation to how we treat your personal data, we will post those changes on this page and change the “Last Revised” date at the top of the page and notify you by email or by a prominent notice on this Site prior to the change becoming effective. Where required by law, we will obtain your consent or provide you with an opportunity to decline such changes. Any changes will be effective when the revised Policy is posted.
If you have a question or concern about how we handle your personal information, please contact us:
Chief Privacy Officer
Blackhawk Network, Inc.
6220 Stoneridge Mall Road
Pleasanton CA 94588 United States
privacy@bhnetwork.com
EU Information Requests
You may contact Blackhawk Network, Inc. at the address or email address above or by contacting Blackhawk’s EU Data Protection Officer listed below, and we will endeavor to respond appropriately to your request.
Blackhawk Network DPO (European Union except Germany, Austria and Switzerland):
ourprivacycommitments@bhnetwork.com
DPO of Blackhawk Network (Germany, Austria and Switzerland):
privacy@bhnetwork.de
If you have additional questions or complaints that we are unable to address, we invite you to contact the data security supervisory authority in your country of residence. A list of national data protection authorities in the European Economic Area can be found here .