Last updated: September 26, 2016
1. Core Principles
When you use the Services, we collect the following information, and use it only as described below:
2.1. Account Information. This may include your name, address, email address and phone number. We use this information in the ways you would expect, such as to set up your Account or contact you.
2.2. Third Party Account Information. If you use Third Party Services, such as social media or photo-sharing services, you may provide us with your Third Party Services account information, such as your username (note that we don’t store any passwords you use to access Third Party Services). We transmit, and may store, such account information, only as needed to provide the Services, and only in accordance with the terms and policies of the Third Party Services.
2.4. Communications With Us. When you send us emails or other communications, such as customer support inquiries, we maintain those communications and their contents so that we can resolve your inquiries or otherwise assist you.
2.5. Public Comments On The Services. We maintain any comments, contributions to discussions or messages submitted to users of the Services, in order to provide the Services.
2.6. Files You Provide Us. When you use the Services, we store, process and transmit your User Content (such as your photos) and information related to your User Content (such as location tags in photos). We process and store such files and information in order to provide the Services, as described in our Terms of Service.
2.7. Usage Information. This includes information about your activity on and interaction with the Services, such as your IP address, your device or browser type, the webpage you visited before coming to our sites and identifiers associated with your devices. This information enables us to analyze how the Services are being accessed and used, and to track performance of the Services.
2.8. Location Information. Your devices (depending on your settings) may transmit location information to the Services. We use this information to customize, improve and protect the Services. For example, we may use your location information to determine local language preferences, or to geotag a post.
When you use the Services, we may share your information only as described below:
3.1. Third Parties You Authorize. You can give third parties access to your and your End Users’ information on the Services. For example, you may wish to integrate Your Sites with a third party newsletter service that requires access to the email addresses you collect from your End Users, in order for that newsletter service to send emails on your behalf and at your direction. Just remember that such third party’s use of this information will be governed by the terms and privacy policies of the third party.
3.2. Following The Law. We may disclose your information to third parties if we determine that such disclosure is reasonably necessary to comply with the law, protect our rights or prevent fraud or abuse of Squarespace or our users. When we receive law enforcement or national security requests for information, we strongly believe in privacy and transparency. We scrutinize such requests carefully and challenge vague, overbroad or otherwise unlawful requests. And when legally permitted, we provide our users with notice that their information is being requested. This notice is provided so that you have the opportunity to challenge such requests.
3.4. Business Transfers. If we're involved in a reorganization, merger, acquisition or sale of our assets, your information may be transferred as part of that deal.
While no service is completely secure, we have a security team dedicated to keeping your information safe. We employ security measures such as using firewalls to protect against intruders, building redundancies throughout our network (so that if one server goes down, another can cover for it) and testing for and protecting against network vulnerabilities. Payment information is transmitted using HTTPS encryption, and we maintain a PCI DSS certification.
We'll retain your personal information for as long as we need it to provide you with the Services. You can ask for your personal information to be deleted at any time by deleting your Account or contacting us at firstname.lastname@example.org. Please note that there may be latency in deleting your personal information from our servers and backup storage, and we may retain your personal information in order to comply with the law, protect our rights, resolve disputes or enforce our agreements.
To modify or delete the personal information you have provided to us, simply log into the Services and update your profile. We may retain certain information as required by law or for necessary business purposes. On request, we'll provide you with a copy of your personal information that we maintain. This request may be subject to a fee not exceeding the prescribed fee permitted by law.
We may periodically email you service-related announcements. We'll also send you emails related to your transactions. We may also send you marketing or promotional communications, but you can opt out of receiving subsequent marketing or promotional communications by clicking the link marked unsubscribe (or a similar phrasing) that’s included in those communications.
9. End User Information
9.3. End User Payment Information. Your End Users’ payment information may be processed via third party eCommerce Payment Processors with which you integrate your Account, in accordance with such eCommerce Payment Processors’ terms and policies. We transmit your End Users’ complete payment information when they initially provide or update it, only so that we can pass it along to the eCommerce Payment Processors you agree to use. We don’t collect or store your End Users’ payment information.
10. Privacy Shield
10.1. Compliance. Squarespace complies with the EU-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use and retention of personal information transferred from the European Union to the United States (“EU Personal Data”). We’ve certified to the Department of Commerce that we adhere to the Privacy Shield Principles and, assuming our certification is approved, you’ll be able to find it here. You can learn more about Privacy Shield by visiting https://www.privacyshield.gov/.
10.3. Inquiries And Disputes. If you have questions you believe to be within the scope of our Privacy Shield certification, please contact us first at email@example.com and we'll respond within 45 days. For any complaints that we can’t resolve directly, JAMS is the independent organization responsible for reviewing and resolving complaints about our Privacy Shield compliance, and you can contact JAMS at https://www.jamsadr.com/eu-us-privacy-shield. In the event your concern still isn't addressed by JAMS, you may be entitled to a binding arbitration under the Privacy Shield Principles. For purposes of enforcing compliance with the Privacy Shield, Squarespace is subject to the investigatory and enforcement authority of the U.S. Federal Trade Commission.