Your Privacy and Security - Details

We at TinToyArcade.com (Tin Toy Arcade LLC) are committed to respecting your privacy and the security of your personal information. We are committed to be transparent about the data we collect about you, how it is used and with whom it is shared. This privacy policy ("Privacy Policy") applies when you use our Services (described below). We offer our users choices about the data we collect, use and share as described in this Privacy Policy.

As you use our Services, we want you to be clear about how your personal information is used and shared, as well as the ways in which you can protect your privacy. Our Privacy Policy outlines:

Data we collect

How your data is used

How we share your data

Your choices

How we protect your data

How to contact us

Services and Scope. This Privacy Policy applies to www.TinToyArcade.com, interactions within our website that is owned or operated by our affiliates or any other linked pages, features, content, mobile applications, and any other communications or services we offer from time to time in connection with any of the foregoing ("Services") but excluding services that state that they are offered under a different privacy policy. As a user of our Services, the collection, use and sharing of your personal data is subject to this Privacy Policy (which includes information on the cookies we use and other documents referenced in this Privacy Policy) and updates. Please ensure that you read this Privacy Policy before transacting business with us. If you do not read it, or you disagree with any aspect of it, you should not use our Services.

Changes. Our Privacy Policy may change from time to time. We will post any changes on this website. If we make material changes to it, we will provide notice through our Services, or by other means, to allow your review of the changes before they become effective. If you object to any changes, you may close your account and discontinue use of the applicable Services. Each time a user uses any Service, the current version of the Privacy Policy applies. You acknowledge that your continued use of our Services after we publish or send a notice about our changes to this Privacy Policy means that the collection, use and sharing of your personal data is subject to the updated Privacy Policy.

  1. DATA WE COLLECT

    1. Data you provide to us

      When you create an account; place an order or make a return or exchange; inquire about our Services; request emails from us about our offerings; opt-in to marketing activities; receive a gift from someone else who purchases through our website; follow us or submit information, including photographs, via third-party social media platforms (e.g., Facebook, Twitter, Google+, etc.); enter a contest or participate in a marketing survey; or submit other information to us directly or through third-party services, you are asked to provide personal information that uniquely identifies you.

      We collect the following types of personal information: your contact information (such as name, postal or email address, or phone number), birthdate, name and email address of gift card recipients, username and password, payment information such as PayPal, credit or debit card details, shipping information (including the shipping address and phone number), purchase history, shopping preferences (such as an interest in a particular product category), information about your age, information you provide by interacting with us through social media, and photographs that you submit on our sites or through our social media channels. 

      You don't have to provide any information that directly identifies you to browse our website. However, we will ask you to provide certain personal information as necessary to provide you with requested products and services, complete the relevant transaction, or, if you wish, to avail of special features or functions of our website.

      Content posted by you. We may provide you with the ability to rate or review products or services we sell, or otherwise post content on our website our through our social media channels. Any comments or reviews that you provide are accessible to all users of the relevant platform and may be visible to others or collected by third-parties, so you should use discretion when posting information and you should not post personal information. If you do post personal information, you do so at your own risk. 

    2. Data we automatically get from you

      We and our affiliates, analytics or service providers, and select businesses with whom we have marketing relationships, use technologies such as cookies, beacons, tags, and scripts, to analyze trends, administer the website, tracking users' movements around the website, and to gather non-sensitive demographic information about our user base as a whole. We may receive reports based on the use of these technologies on an individual or aggregate basis. Further information is contained below.

      Analytics & Log Files. As is true of most websites, we gather certain information automatically and store it in log files. When you visit our websites, we automatically collect the following types of information: information about the device you use to access the Internet (such as the internet protocol (IP) address, internet service provider (ISP) or mobile carrier, proxy server, device type, browser and add-ons, and operating system), referring/exit pages, date/time stamps, information on your shopping behavior on our website (e.g., page views, paths you take through our websites, etc.), general geographic location information (e.g., country or city) that shows where you are when browsing our websites, and search terms that you enter to reach our websites or enter on our websites to find products. We utilize analytics services and log files to help us track the efficacy of our websites, help us learn more about our customers' and visitors' shopping behavior, and for troubleshooting and maintenance purposes. We may collect and summarize customer and visitor information in a non-personal, aggregate format for statistical and research purposes.

      Cookies, Web Beacons, and Other Similar Technologies. We use cookies and similar technologies (e.g., web beacons, pixels, ad tags and device identifiers) to recognize you and/or your device(s) on, off and across different Services and devices. For detailed information on the cookies we use, the purposes for which we use them, and how to disable them, see below.

      • Cookies. We automatically collect aggregate anonymous information through cookies. Cookies are small text files stored by your Web browser on your computer, phone, tablet, or other device used to browse our Sites. Cookies allow us to identify and authenticate visitors, track aggregate behavior, and enable important site features. We use both session ID cookies and persistent cookies. A session ID cookie expires when you close your browser. A persistent cookie remains on your hard drive for an extended period of time. The persistent cookie maintains your login information so that your cart and login remain available when you return to the site. Session cookies are used to maintain your shopping state as you browse through the site. YouTube uses cookies to help maintain the integrity of video statistics, prevent fraud and to improve the site experience, among other things. We also contract with analytics services and third-party advertising companies to collect similar information for specific purposes. The use of cookies by our partners is not covered by this Policy.

      • Flash Cookies/LSO's. Third parties with whom we partner to provide certain features on our website or to display advertising based upon your web browsing activity also use Flash cookies or HTML5 Local Stored Objects (also known as LSO's), to collect and store information. Various browsers may offer their own management tools for removing HTML5. To manage Flash cookies, please click here.

      • Though you may disable cookies through your web browser, doing so may prevent you from taking advantage of some of the Sites' features. To opt out of these collection services, please see section "Your Choices" below. The use of cookies by our partners is not covered by this Policy. To opt out of the services related to these cookies, please see section "Your Choices" below.

      • Web Beacons/Tags. We automatically collect aggregate anonymous information through web beacons. We may also deliver a file to you through the Sites (known as a "web beacon") from an advertising network with which we have contracted. Web beacons allow advertising networks to provide anonymized, aggregated auditing, research and reporting for us and for advertisers.

      • Targeted Advertising. Third-party advertising companies serve ads on our behalf across the Internet. They may collect anonymous information about you through cookies and/or web beacons on our Sites and other sites, and then display targeted ads on various sites that you visit. If you wish to not have this information used for the purpose of serving you interest-based ads, you may opt-out by clicking here (or if located in the European Union click here). Please note this does not opt you out of being served ads. You will continue to receive generic ads, or, to opt out of third-party advertising or analytics, please see section "Your Choices"below.

      • Social Media Features. Our Sites include social media features, such as the Facebook "Like" button and widgets, the "share this" widget, or interactive mini-programs that run on our site. These features may collect your IP address, which page you are visiting on our Site, and may set a cookie to enable the feature to function properly. Social media features and widgets are either hosted by a third party or hosted directly on our Sites. Your interactions with these features are governed by the privacy statement of the company providing it.

    Returned Products. If you return products that may contain stored or recorded personal information, like computers, game consoles, etc., you are responsible for deleting or removing all personal information and media from your product before you return it. We are not responsible for any personal information or media that you do not delete or remove from such product.

    From time to time we may supplement information you give us with information from other sources, such as information validating your address or other available information you have provided to us. This is to help us maintain the accuracy of the information we collect and to help us provide better service. We often introduce new features to our Services, which may require the collection of new information. If we collect materially different personal data or materially change how we use your data, we will notify you and may also modify this Privacy Policy.

  2. HOW YOUR DATA IS USED

    1. How we use your data

      We use your data to provide, support, personalize and develop our Services. How we use your personal information will depend on which Services you use, how you use those Services and the choices you make in your settings. We use the information that we have about you to provide and personalize, including with the help of automated systems and inferences we make, our Services (including ads) so that they can be more relevant and useful to you and others. When providing direct services, advertising or marketing, or performing security, administrative, or customer service activities, we may use the information we collect in the following manner, including without limitation, to:

      • Providing Direct Services

        • complete a sales transaction, including to process and track website orders;

        • provide products and services that you request;

        • place pre-orders on your behalf;

        • enable subscription services or activations, like online games or downloadable content; and/or

        • administer rebates or extended service agreements.

      • Advertising and Marketing

        • send you email updates, newsletters, promotions, surveys, and direct mailings;

        • manage your participation in events and sweepstakes;

        • communicate with you about our products and services, and to customize our communications with you, including by identifying preferences you provide to us;

        • analyze your purchases and preferences to better understand your product and service needs and eligibility and to tailor our online content to you;

        • share your Wish List with those whose email addresses you provide for the sole purpose of completing your request;

        • publish customer testimonials or photos;

        • analyze our marketing strategies and trends regarding your use of our website or social media channels;

        • facilitate your acceptance of offers made by our third-party marketing partners;

        • improve the effectiveness of our marketing campaigns; and/or

        • to send follow-up communications thanking your for your business or inquiring as to your satisfaction.

      • Administration

        • register and manage your account;

        • administer our loyalty program;

        • track the efficacy of our website and help us learn more about our visitors' and customers' shopping behavior; and/or

        • improve our website experience.

      • Security

        • protect against error, fraud, unauthorized transactions, claims and other liabilities;

        • manage exposure to risk from unauthorized users;

        • enforce the terms of use on our websites; and/or

        • comply with applicable legal mandates, our policies, or industry standards.

      • Customer Service Activities

        • provide customer service when you need help and/or to improve customer experiences;

        • provide status updates on your order;

        • provide information concerning product recalls or products you have purchased; and/or

        • enable you to communicate with us through social networks or other interactive media.

  3. HOW WE SHARE YOUR DATA

    We do not rent or sell personal information to others. We may share information we collect with our business partners, advertising companies, and other third parties for the purposes described in this Privacy Policy.

    Marketing Partners. If you accept an offer from any of our third-party marketing partners, we will share your contact and billing information with that specific third party, in accordance with the terms of the offer. If you have previously requested that your personal information not be shared with third parties, but then later consent by accepting a third-party marketing offer available through one of our websites, we will share your contact and billing information with that specific third-party, in accordance with the terms of the offer.

    Service Providers. We use third parties to manage one of more aspects of our business operations, including the processing or handling of personal information. We may share personal information with such third parties to perform services on our behalf such as fulfilling online orders, email distribution, processing non-cash payments, sending marketing communications, servicing products, maintenance of your account, conducting research surveys, verifying and validating information that you have provided to us, delivering products, third-party advertising, and providing customer support services. When we do use an outside company, we use contractual and other appropriate means to ensure that your personal information is used in a manner that is consistent with this Privacy Policy. We do not share email addresses with third parties for the purpose of sending their own emails to you. Third parties will only have access to your information as reasonably necessary to perform these tasks on our behalf and are obligated not to disclose or use it for other purposes.
     

    Third Parties. This Privacy Policy does not apply to the practices of companies that we do not own or control, or to individuals that we do not employ or manage, even if you have accessed the websites or services of those companies through our website. Our Services may offer services or features that are not owned or controlled by us. When you access or use third party services, you agree to comply with any applicable terms or conditions thereof. Links to third-party websites are provided solely as a convenience to you. Once you leave our website, we neither control nor have responsibility for third-party sites, their content, or their privacy practices. We encourage you to read the terms and conditions and privacy policy of each third-party service that you access or utilize. Some of our pages utilize framing techniques to serve content from our partners while preserving the look and feel of our website. Please be aware that you are providing your personal information to these third parties and not to one of our websites.

    Direct Marketing and Do Not Track Signals. We do not share personal data with third parties for their direct marketing purposes without your permission.

    Security. In the event we become aware that the security of the sites has been compromised or users' personal information has been disclosed to unrelated third parties as a result of external activity, including, but not limited to, security attacks or fraud, we reserve the right to take reasonably appropriate measures, including, but not limited to, investigation and reporting, as well as notification to and cooperation with data protection and law enforcement authorities.

    Sale or Transfer of Business or Assets. Any information we have about you may be transferred or disclosed to a purchaser or prospective purchaser in the event of a sale, assignment, or other transfer of all or a portion of our business or assets. Should such a transfer occur, we will use reasonable efforts to ensure that the transferee uses your information in a manner that is consistent with this Privacy Policy.

    Legal Disclosure. We may need to share your data when we believe it's required by law or to help protect the rights and safety of you, us or others. It is possible that we will need to disclose information about you when required by law, subpoena, or other legal process or if we have a good faith belief that disclosure is reasonably necessary to (1) investigate, prevent, or take action regarding suspected or actual illegal activities or to assist government enforcement agencies; (2) enforce our agreements with you, (3) investigate and defend ourselves against any third-party claims or allegations; or (4) protect the security or integrity of our Service. We attempt to notify customers about legal demands for their personal data when appropriate in our judgment, unless prohibited by law or court order, or when the request is an emergency. We may dispute such demands when we believe, in our discretion, that the requests are overbroad, vague or lack proper authority, but we do not promise to challenge every demand.

    Cross-Border Data Transfers. The vast majority of your data that we process or store is kept within the United States. However, to provide you with certain Services, we may share your information with processors outside of the US, or with our corporate affiliates. For EU Citizens: When we process data outside of the US, we rely on legally-provided mechanisms to transfer data across borders because countries where we process data may have laws which are different, and potentially not as protective, as the laws of your own country. In this regard, we will continue to use European Commission-approved Standard Contractual Clauses as a legal mechanism for data transfers from the EU, which remain an approved method of transferring data outside of the EU under the General Data Protection Regulation. You may request a copy of the Standard Contractual Clauses by contacting us at support@tintoyarcade.com

    Data Controller. Unless explicitly stated otherwise, TinToyArcade.com is the controller of your personal data provided to, or collected by or for, or processed in connection with our Services.

  4. YOUR CHOICES

    1. Rights to access and control your personal information

      We provide many choices about the collection, use and sharing of your data, from deleting or correcting data you include in your profile to advertising opt-outs and communication controls.

      • If you have registered for an account, you can access, review and manage many changes yourself via the customer Dashboard. Within the Dashboard, you can do things like update your profile information and change your communication preferences.

      • If you have not registered for an account, or the information you are seeking is not available within the customer Dashboard, you can contact us at support@tintoyarcade.com or via mail at: 3120 S Martin Street, Suite 300 Bldg 2, East Point, GA USA 30344.

      • For further details, see section 3.2 below.

      For personal information that we have about you, you can request the following:

      Delete Data: You can ask us to erase or delete all or some of your personal data (provided it is no longer necessary for legal purposes or to provide Services to you).

      Change or Correct Data: If you have created an account on our website, you can edit some of your personal data through the customer Dashboard. You can also ask us to change, update or fix your data in certain cases, particularly if it's inaccurate.

      Object to, or Limit or Restrict, Use of Data: You can ask us to stop using all or some of your personal data (e.g., if we have no legal right to keep using it) or to limit our use of it (e.g., your personal data is inaccurate or unlawfully held).

      EU Citizens: Right to Access and/or Take Your Data: you may contact our Data Protection Officer at support@tintoyarcade.com to request a copy of your personal data and can ask for a copy of personal data be provided in machine readable form. You can also ask to review any of the information that we have retained, how we have used it, and to whom we have disclosed it at any time by contacting us.

      EU Citizens: Right to Lodge a Complaint; the Irish Data Protection Commissioner. You have the right to lodge a complaint with your local supervisory authority or TinToyArcade's lead supervisory authority, the Data Protection Commission (DPC). For more information on how to contact the DPC or lodge a complaint, please visit https://www.dataprotection.ie/docs/Contact-us/b/11.htm.

    2. Opting out of communications

      We offer you choices about how to manage how we communicate with you.

      • Email/Direct Mail. You may opt out of receiving marketing emails from us at any time by sending an email to support@tintoyarcade.com or by clicking on the unsubscribe link in our emails. You will continue to receive service-related emails (e.g. order status). To opt out of direct mail, please send your request to support@tintoyarcade.com and include your postal address in the body of the email.

      • Targeted Advertising. If you do not want information about your activity on our sites to be used for tailored advertising, please visit the opt-out page hosted by the Network Advertising Initiative and follow the instructions there.

      • Cookies. You may disable cookies in your Web browser, but doing so will impact the usability of the website. 

      • Analytics. You may opt-out of Google Analytics by following this link. You may opt-out of Adobe analytics by following this link.

      • Updating Your Profile. You may update or correct your personal information related to your account through your Dashboard or by contacting Customer Support at support@tintoyarcade.com. If you wish to request deletion of your personal information, then please contact us at support@tintoyarcade.com. We will respond to requests within a reasonable timeframe. We retain and use your information as necessary to comply with our legal obligations, contractual statute of limitations, resolution of disputes, and enforcement of our agreements. Please note that we may not be able to delete all of your data upon request depending on the reasons above and the nature of your interactions.

      • Contests. From time to time, we may provide you the opportunity to participate in contests, sweepstakes, surveys and/or other promotions on our website. If you participate, we will request certain personal information from you. Participation in these contests, sweepstakes, surveys and/or promotions is completely voluntary, and you therefore have a choice about whether or not to disclose this information. We may use a third-party service provider to conduct these surveys or contests; in those cases, that company will be prohibited from using our users' personally identifiable information for any other purpose. We will not share the personal data you provide through a contest, sweepstakes, survey and/or promotion with other third parties.

      • Gift Card Recipients. Your gift card recipient may contact us at support@tintoyarcade.com to request an update, correction or deletion of their personal information. Again, for various reasons stated above, we may not be able to delete information upon request. 

    3. Data retention and account closure

      If you wish to close your account, we will keep some of your data even after you close your account. We retain your personal data even after you have closed your account if reasonably necessary to comply with our legal obligations (including law enforcement requests), meet regulatory requirements, resolve disputes, maintain security, prevent fraud and abuse, enforce our Terms and Conditions, or fulfill your request to "unsubscribe" from further messages from us. We will retain de-personalized information after your account has been closed, but will destroy your personal data when it is no longer needed for the foregoing purposes, or we remove your personal information to render it anonymous.

  5. HOW WE PROTECT YOUR DATA

    Security. We monitor for and try to prevent security breaches. We implement appropriate security safeguards designed to protect your data. For example, electronic records are stored in secure, limited-access servers; electronic data is stored behind secured encryption access; we use technological tools like firewalls and passwords; and we ensure our employees are trained on the importance of maintaining the security and confidentiality of personal information. We regularly monitor our systems for possible vulnerabilities and attacks, however, we cannot warrant the security of any information that you send us. There is no guarantee that data may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, organizational, or managerial safeguards.

    • SSL Technology. Our website uses encryption technology, such as Secure Sockets Layer ("SSL"), to protect your personal information during data transport. SSL encrypts ordering information such as your name, address, and credit card number.

    • Choosing a Password. When you register as a user and create an online account on our website, you will be prompted to select a personal password. To maximize your level of protection, you should choose a strong personal password, which means that you should use at least 6 characters including a combination of both letters and numbers. You are solely responsible for maintaining the secrecy of your password and any account information. We will never send an unsolicited communication asking you for your password.

    Lawful Bases for Processing. We will only collect and process personal data about you where we have a lawful basis to do so. Lawful bases include consent (where you have given it), contractual necessity (where processing is necessary for the performance of a contract with you (e.g., to deliver Services you have requested)), and legitimate interests. Where we process data based on consent, we will ask for your explicit affirmative consent. We will rely on legitimate interests as a basis for data processing only where the processing of your data is not overridden by your interests or fundamental rights and freedoms.

    At any time, you can withdraw consent you have provided by managing your Dashboard or by contacting us as set forth below, but that will not affect the lawfulness of the processing of your personal data prior to such withdrawal. Where we rely on legitimate interests, you have the right to object.

    Minors. Our website is not intended for use by anyone under the age of 13. If you are under 13, please do not attempt to create an account or send any information about yourself to us, including your name, address, telephone number or email address. No one under the age of 13 may provide any personal information to us, and we do not knowingly collect personal information from anyone under the age of 13. If we learn that we have collected personal information from a child under age 13 without verification of parental consent, we will delete that information as quickly as possible. If you believe that we might have any information from or about a child under the age of 13, please contact us immediately at support@tintoyarcade.com.

  6. HOW TO CONTACT US

    If you have questions about how we collect, store and use personal data, please contact us at the following:

    Email: support@tintoyarcade.com

    Phone: 1-888-896-1814

    Mail: 
    Tin Toy Arcade
    3120 S Martin Street, Suite 300 Bldg 2 
    Atlanta, GA USA 30344 

    EU Citizens - You can contact our Data Protection Officer at the following:

    Email: support@tintoyarcade.com

    Please remember that email sent over the Internet is not secure. If you send an email directly to us from your own email account, the contents will not be encrypted. Do not send sensitive information (like a credit card number) to us via unencrypted email. We are not responsible for any transmission by you of any personal information over the Internet.

Last Modified: May 24, 2018

SECURITY

Credit card information for web orders is protected in the following ways:

  • 128-bit encryption to and from the servers and web browser.

  • Credit card numbers are not stored in our database. We keep on file only the last 4 digits to verify the card that was used. If you've chosen to store your payment method with us in your virtual wallet, what we actually have is not your credit card number but an encrypted token we use to communicate with the credit card processor about your orders.

  • Once the information is transmitted to our servers for processing, we use encryption in the back end to transmit the request to our payment processor to verify the credit card and place an authorization for the order total.

  • If the authorization, address verification and risk assessment all clear, the order is accepted and a unique ID is associated with the order for purposes of billing the previous authorization. This ID contains no identifiable link to the credit card number.