Last updated: May 24, 2018.
Collection of Information
We collect personal information about our users in a variety of ways, including:
Information You Provide to Us: We may collect and store personal information when you register for the Platform or provide to us in some other manner. For example, when you create an account with the Platform, we may collect your name, username, password, email address, physical address, phone number, work history, schedule, availability, and any other information you provide, such as personal photographs. If you are a Company, we also collect information about your business, payment information and any information you provide about your Workers or business practices.
We may collect and store any communications between you and OpenSimSim, any communications between you and other users of the Platform, any information you provide if you take part in any interactive features of the Platform (such as comments, reviews, and other posts), and any other information you provide to us, including work history details on the Platform, such as clock-in details and any associated photos. We may use third party services such as payment processors, who will collect and store billing, credit card, and other payment information that you provide to them to enable payment for services purchased through or from OpenSimSim.
Information We Collect Automatically: We automatically collect and store certain information related to your use of the Platform, such as the site from which you came and the site to which you are going when you leave our website, the pages you visit, the links you click, how frequently you access the Platform, whether you open emails or click the links contained in emails, whether you access the Platform from multiple devices, and other actions you take on the Platform. We collect such usage information through a variety of tracking technologies, including cookies, Flash objects, web beacons, file information and similar technology (collectively, "tracking technologies").
When you access our Platform from a mobile device, we may collect information about your device and its software, such as your IP address, browser type, Internet Platform provider, platform type, device type, operating system, date and time stamp, a unique ID that allows us to uniquely identify your browser, mobile device or your account, and other such information.
Depending on your mobile device settings, we may also collect data regarding your geographical location, such as GPS coordinates (e.g., latitude and/or longitude) or similar information regarding the location of your mobile device, or we may be able to approximate your device’s location by analyzing other information, like an IP address.
If you have your mobile device’s "background location" turned on, the Platform will, tell us about your device’s location at the time of clocking in and out of work shifts. We use various technologies to determine location, such as location services of the applicable operating system or browser and sensor data from your device that may, for example, provide information on nearby Wi-Fi access points and cell towers. You may choose to disable location tracking in the Mobile App, but if you do so, certain functionality may not be available to you.
Information We Receive from Social Networking Sites: When you interact with our site through various social media, such as when you login through Facebook or Google, or share OpenSimSim content on Facebook, Twitter, or other sites, we may receive information from the social network including your profile information, profile picture, gender, user name, user ID associated with your social media account, age range, language, country, friends list, and any other information you permit the social network to share with third parties. The data we receive is dependent upon your privacy settings with the social network, and we will not post information about you on third party social media sites without your consent. You should always review, and if necessary, adjust your privacy settings on third-party websites and Platforms before linking or connecting them to our website or Platform.
Information We Receive from Third Parties. From time to time, we may receive information about you from third parties, including information about you that is provided by other users of the Platform, staffing or employment agencies, identity verification or payroll vendors, or other third parties. This may include, for example, your contact information, work history, work schedule, or any other information provided to us by a third party. We may also collect information about you that is otherwise publicly available.
Use of Information
In general, we use the information we collect to operate, maintain, optimize, and provide to you the features and functionality of the Platform, as well as to communicate directly with you, permit you to communicate with others on the Platform or on social media, or invite others to join the Platform.
We may use your personal information to contact you regarding work opportunities (or Workers, as the case may be) that may be a match for you. We may also use your personal information to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. If you decide at any time that you no longer wish to receive such communications from us, please follow the unsubscribe instructions provided in any of our communications to you, or update your account preferences.
We use your usage information to monitor and analyze use of the Platform and for technical administration of the same, to increase the functionality and user-friendliness of the Platform, and to better tailor it to our users’ needs. For example, we may use various tracking technologies to help us understand user activity, determine user interest in certain subject matter, and measure the effectiveness of the Platform and our communications. In addition, we may use technical information about your device, system and application software, and peripherals, to facilitate the provision of software updates, product support and other services to you related to the Platform.
We use or may use the data collected through tracking technologies to: (a) remember information so that you will not have to re-enter it during your visit or the next time you visit the site; (b) provide custom, personalized content and information; (c) identify you across multiple devices; (d) provide and monitor the effectiveness of our Platform; (e) monitor aggregate metrics such as total number of visitors, traffic, usage, and demographic patterns on our website; (f) diagnose or fix technology problems; and (g) otherwise to plan for and enhance our Platform.
We may collect analytics data, or use third-party analytics tools, to help us measure traffic and usage trends for the Platform and to understand more about the demographics of our users. We may also work with third party partners to employ technologies, including the application of statistical modeling tools, which attempt to recognize you across multiple devices.
We may use your location data to tailor the Platform to your current location (e.g., to show you a list of nearby Workers or Company opportunities, and/or to calculate your proximity or estimated time of arrival to a nearby Company opportunity). We also use location data for our sales operations and business reporting.
We may use user communications (e.g. messages to other users, comments, reviews, etc.) for our business purposes, including in the course of customer service investigations regarding any user complaints, disputes among users, and for research and development related to how users use the Platform.
We may also use the information we collect, on a de-identified or aggregate basis, to compile analytics and share performance data.
Sharing of Information
OpenSimSim’s policy is not to share user information it collects with third parties, other than as specified below, or where a user expressly consents to our sharing of certain information with a third party:
Other Users of the Platform: Your information will be shared other users of the Platform, as needed to provide the Platform and its functionality to you and other users. For example, some of your information may be shared with your Company and with other Workers of the same Company in order to facilitate scheduling and communication. You may be able to control the visibility of some of your information and actions through your Settings (see "Your Choices Regarding Your Information" below). We also share information about your use of the Platform with your Company for analytic purposes. For example, we provide reporting tools to allow a Company to evaluate the efficiency of its workforce, and its employees’ responsiveness and availability.
Business Partners and Vendors: We work closely with certain business partners and vendors and we may provide your information to them so that they can provide services related to the Platform, or offer their products or services to you. For example, we may provide your information to our business partners or other trusted entities for the purpose of providing you with information on products or services we believe will be of interest to you, we will notify you and obtain your prior consent prior to doing so. We may also use third party companies and individuals to facilitate the Platform; to provide the Platform or portions of the Platform on our behalf; to perform related services, including without limitation, maintenance services, database management, fulfillment, web analytics, and improvement of the features or functionality; or to assist us in analyzing how the Platform is being used.
Under certain circumstances, you may avoid having OpenSimSim share your information with its business partners and vendors by not granting OpenSimSim permission to share your information. Not granting OpenSimSim permission to share your information with its business partners or vendors may limit your access to their services through the Platform.
Social Media Platforms: If you access the Platform from a third party social media platform, we may share your personal information with that platform to the extent permitted by your agreement with that platform and its privacy settings.
Other Companies owned by or under Common Ownership with OpenSimSim: These companies will use your personal information in the same way as we can under this Policy. This includes our subsidiaries (i.e., any organization we own or control) or our ultimate holding company (i.e., any organization that owns or controls us) and any subsidiaries it owns.
Other Parties in Connection with any Company Transaction, such as a merger, sale of all or a portion of company assets or shares, reorganization, financing, change of control or acquisition of all or a portion of our business by another company or third party or in the event of bankruptcy or related or similar proceedings.
Aggregate Site Use Information: We may also share information with others in an aggregated and anonymous form that does not reasonably identify you directly as an individual.
Your Choices Regarding Your Information
Changing or Deleting Information You Provided: Users who have created an account on the Platform may review, update, correct or delete the personal information in their registration profile by revising their account profiles. If you completely delete all such information, then your account may become deactivated. We may retain an archived copy of your records as required by law or for legitimate business purposes.
Device Information, Including Location Information: You may control the app’s access to your device information through your "Settings" feature on your device. For instance, you can withdraw permission for the app to access your location data.
Tracking Technologies: If you would prefer not to accept cookies, most browsers will allow you to: (i) change your browser settings to notify you when you receive a cookie, which lets you choose whether or not to accept it; (ii) disable existing cookies; or (iii) set your browser to automatically reject cookies. Please note that doing so may negatively impact your experience using the Platform, as some features on our Platform may not work properly. Depending on your mobile device and operating system, you may not be able to delete or block all cookies.
You may set your e-mail options to prevent the automatic downloading of images that may contain technologies that would allow us to know whether you have accessed our e-mail and performed certain functions with it.
Some web browsers may be configured to send Do Not Track signals to websites, or users may use similar mechanisms, to indicate a user’s preference that certain web technologies not be used to track the user’s online activity. The Platform, including the Website, does not accept or process such Do Not Track signals or similar mechanisms.
Information Sharing Settings: You may change some of your data sharing preferences on your Settings page. For example, you may mark certain aspects of your profile as private so that it may not be viewable by other users of the Platform. If you use the Platform as a Worker, certain elements of your information will be automatically shared with your Company, depending on how your Company has configured the company account and user permissions on the Platform.
Communications: From time to time, the Platform will send communications about news and updates, advice and analytics relating to your use of the Platform. The Platform also facilitates communication among users by email, text message and in-app notifications. Users can adjust communications preferences through Settings.
Marketing Communications: From time to time, we may send you promotional messages. If you do not wish to receive promotional emails, you can change your email preferences on your Settings page on our websites, or you can click the "unsubscribe" button on promotional email communications. Note that you are not permitted to unsubscribe or opt-out of non-promotional messages regarding your account, such as account verification, change or updates to features of the Platform, or technical and security notices.
Third Party Processors, Tracking, and Online Advertising
We may share, or we may permit third party online advertising networks, social media companies and other third party Platforms, to collect information about your use of our website over time so that they may play or display ads that may be relevant to your interests on our Platform as well as on other websites or apps, or on other devices you may use. Typically, though not always, the information we share is provided through cookies or similar tracking technologies, which recognize the device you are using and collect information, including hashed data, click stream information, browser type, time and date you visited the site, and other information. This information is used to display targeted ads on or through our Platform or on other websites or apps, including on Facebook. We or the online advertising networks use this information to make the advertisements you see online more relevant to your interests.
As noted above, depending on your browser or mobile device, you may be able set your browser to delete or notify you of cookies and other tracking technology by actively managing the settings on your browser or mobile device.
Links to Third Party Websites
If you follow a link to any of these third party websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for their policies. Please check the individual policies before you submit any information to those websites.
We may retain your information for as long as your account is active or as needed to for our internal purposes. You may obtain a copy of the personal information we have about you by emailing us at firstname.lastname@example.org. When you deactivate your account, we will remove your information from view by others on the Platform, but we may retain your account information internally so that you can access your account history and so that you may re-register an account more quickly in the future. You may request to fully delete your account information by contacting us at email@example.com. However, please be aware that we may not be able to delete any content you have shared with others on the Platform that is required to be retained by law or regulation or legitimate business purposes. For example, your Company will have a record of your schedule when you were working, and we may retain any data a Company provided to us about you that is required to be retained by the Company under law or regulation or in pursuance of Company’s legitimate business interests in maintaining records of Workers and schedules.
Privacy of Minors
We are committed to protecting the privacy of children. The Platform and its content are not directed to children under the age of 13 and Users must be at least 13 years old in order to access and use the Platform. In the event that we learn that we have collected personal information from a child under age 16 without parental consent, we will delete that information as quickly as possible. If you believe that we might have any information collected from a child without parental consent, please contact us at firstname.lastname@example.org.
If you are under 18 years of age, you may request to delete user content that you posted to the Platform such that your personal information will not be identifiable publicly on our Platform by contacting us at email@example.com. While we will use all commercially reasonable efforts to delete your user content upon request, please be aware that due to the nature of our Platform, you may not be able to completely remove all of your personally identifiable user content if, for example, that content has been stored, republished, or reposted by another user or a third party. We may also maintain your information in identifiable form for our internal use, even if your personal data is no longer visible to the public on our Platform.
California law entitles residents to ask us for a notice describing what categories of personal information we share with third parties for those entities direct marketing purposes. If you are a California resident with an established business relationship with OpenSimSim, California Civil Code Section 1798.83 may permit you to request information regarding the disclosure of your Personal Information by OpenSimSim to third parties for their direct marketing purposes. To make such a request, please contact us directly at firstname.lastname@example.org.
OpenSimSim processes personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
OpenSimSim ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
OpenSimSim will use commercially reasonable efforts, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GPDR ;
OpenSimSim assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36  of the GDPR taking into account the nature of processing and the information available to the processor;
OpenSimSim will, at the choice of the controller, which should be exercised via the Platform or by emailing the choice to email@example.com, delete or return all the personal data to the controller after the end of the provision of services relating to processing, and will delete existing copies unless Union or Member State law requires storage of the personal data;
OpenSimSim will make available to the controller all information necessary to demonstrate compliance with the obligations laid down in Article 28.3 of the GDPR and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
You may view a full list of third party data processors who may be involved in processing your personal data at https://oss.ws/3party.
Security and Storage of Information
OpenSimSim cares about the security of your information and employs physical, administrative, and technological safeguards designed to preserve the integrity and security of all information we collect and store.
However, no security system is impenetrable and we cannot guarantee the security of our systems 100%. Accordingly, we do not guarantee the security of our databases, nor that information you supply won't be intercepted while being transmitted to us over the Internet or other network. Any information you transmit to OpenSimSim, you transmit at your own risk. In the event that any information under our control is compromised as a result of a breach of security, we will take reasonable steps to investigate the situation and where appropriate, notify those individuals whose information may have been compromised and take other steps, in accordance with any applicable laws and regulations.
Updates to this Policy
6965 El Camino Real, Suite 105-550
Carlsbad, CA, 92009
This will require a discussion with the company re: their architecture and the principles of security by design. At a minimum they need to get their documentation in order to show compliance as the required response time is 72 hours, so docs need to be ready before an issue arises.
Compliance here will likely require a discussion with the company around what third parties they use (AWS? Others?)
Need to walk through this with the client.
Need to walk through this with the client.
Confirm OSS can do this.