Effective Date and Last Updated: August 24, 2020
1.0 INFORMATION COLLECTED BY US
a. Information You Provide. BNED provides a family of products, Internet sites, services and browser-based and/or mobile applications (collectively, "Services). While registration with us is optional, please keep in mind that you will not be able to use many features of our Services unless you register with us. Depending on how you interact with our Services, you may provide us, our agents, vendors, consultants, and other service providers (collectively, "Service Providers",) with, and the Services may include hyperlinks to websites, locations, platforms, applications or services operated by third parties (collectively, "Third-Party Services") which require, information that may include:
i. your name, email address, username, password, address, postal code, phone number, credit card number, gender, school attending, graduation year, and other registration information;
ii. information about your preferences;
iii. transaction-related information, such as your orders for any Services, downloads or other features, or purchases, if any, that you make from us;
iv. information you otherwise provide us, such as when you contact us (e.g., for help); and
v. other information related to your use of certain offerings on our Services.
b. Information Collected Automatically. We, our Service Providers, or Third-Party Services may automatically receive or collect certain information from you when you use the Services. This information may include:
i. your browser or operating system;
ii. your manner of connecting to the Internet (including the browser and/or type of device you are using) and the name of your Internet service provider or wireless carrier;
iii. your Internet protocol ("IP") address;
iv. data relating to malfunctions or problems that occur when you use the Services;
v. log file information, including your Web request, IP address, browser type, referring/exit pages and URLs, number of clicks and how you interact with links on our Services, domain names, landing pages, pages viewed, and other such information; and
vi. information collected by cookies, which are Cookies are small pieces of information or text files that a website sends to your computer for record-keeping purposes, which information is stored in a file on your computer's hard drive, and other tracking technologies, including but not limited to, web beacons (also known as "tracking pixels"), embedded scripts, location-identifying technologies, fingerprinting, device recognition technologies, in-app tracking methods and other tracking technologies now and hereafter developed ("Tracking Technologies") may be used to collect information about interactions with the Services or emails, including information about your browsing and purchasing behavior. Cookies make Web-surfing and browsing easier for you by saving your preferences so that we can use the saved information to facilitate and improve your use of the Services.
A. You can adjust your Internet browsers to reject cookies. However, if you disable the cookies on your computer you may not be able to use certain features of the Services and disabling cookies may invalidate opt outs that rely on cookies to function.
C. Note that your browser settings may allow you to automatically transmit a "Do Not Track" signal to websites and online services you visit; such signals may prevent third parties from collecting information about your online activities over time and across different websites. California law requires us to disclose how the Services respond to these kinds of "Do Not Track" signals. Like many websites, the Services currently are not designed to respond to "Do Not Track" signals from visitors' browsers. To learn more about "Do Not Track" you may wish to visit this site.
D. We will treat information that does not personally identify you as non-personal information, and we may de-identify, anonymize or otherwise convert your personal information to non-personal information. As permitted by applicable law, we reserve the right to use, process, share and otherwise exploit your non-personal information without limitation.
2.0 SWEEPSTAKES, CONTESTS AND PROMOTIONS
3.0 USE OF YOUR INFORMATION
Our Use of Your Information. We may use your information to:
i. process your registration, manage your account (including your payment information and preferences), and deliver our Services and features desired by you (including any customization features requested by you);
ii. improve our Services;
iii. fulfill other purposes disclosed to you at the time you provide us with your information or otherwise where we are legally permitted to do so;
iv. personalize content and offers and serve you advertising that may be of interest to you;
v. respond to your inquiries;
vi. fulfill your request for Services;
vii. provide you with updates and other information regarding the Services;
viii. understand your general location (i.e., not your specific geolocation) based on your IP address;
ix. keep our Services safe and secure and to prevent detect fraud and abuse;
x. comply with our legal obligations, policies, and procedures; and
xi. administer and manage our Services including content and layout, site usage, troubleshooting, data analysis, testing, research, statistical and survey purposes.
b. How We May Share Your Information. We may share your information:
i. with our Service Providers in connection with their work on our behalf;
ii. with our family of BNED affiliates who may have content and offers of interest to you. We do not share your personal information to non-affiliate third parties for marketing purposes unless expressly authorized by you;
iv. in the event of a change of ownership, as described below;
v. to comply with law, law enforcement or other legal process, and, where permitted, in response to governmental requests or legal process (for example, a court order, search warrant or subpoena); and
vi. to other circumstances in which we have a good faith belief that a crime has been or is being committed by a user.
4.0 THIRD-PARTY CONTENT, THIRD-PARTY SERVICES, SOCIAL FEATURES, ADVERTISING AND ANALYTICS
a. Third-Party Services. Third-Party Services may use their own Tracking Technologies to independently collect information about you and may solicit personal information from you. For example, BNED maintains its own branded pages on various social networks. When you visit these BNED-branded social media pages, the provider of the social network and other Third-Party Services may set Tracking Technologies on your browser or device.
b. Social Features. Certain functionalities on the Services may permit interactions that you initiate between the Services and certain Third-Party Services, such as third-party social networks ("Social Features"). Examples of Social Features include: enabling you to send content such as contacts and photos between the Services and a Third-Party Services; "liking" or "sharing" BNED content; logging in to the Services using your Third-Party Services account (e.g., using Facebook Connect to sign-in to the Services); and to otherwise connect the Services to a Third-Party Services (e.g., to pull or push information to or from the Services). If you use Social Features, and potentially other Third-Party Services, information you post or provide access to may be publicly displayed on the Services (see "Information You Disclose Publicly or to Others" section above) or by the Third-Party Services that you use. Similarly, if you post information on a third-party service that references the Services (e.g., by using a hashtag associated with BNED or its affiliates in a tweet or status update), your post may be used on or in connection with the Services or otherwise by BNED and its affiliates. Also, both BNED and the third party may have access to certain information about you and your use of the Services and any Third-Party Services.
c. Advertising. We may engage and work with Service Providers and other third parties to serve advertisements on the Services and/or on Third-Party Services. Some of these ads may be tailored to your interest based on your browsing, across time, of the Services and elsewhere on the Internet, which may include use of data from cross-device usage, sometimes referred to as "interest-based advertising" and "online behavioral advertising" ("Interest-based Advertising"), which may include sending you an ad on a third-party service after you have left the Services (i.e., "retargeting"). Our advertisers' and ad networks' use of Tracking Technologies are governed by their own privacy policies.
d. Your Tracking Technologies Choices.
i. Regular cookies may generally be disabled or removed by tools available as part of most commercial browsers, and in some instances blocked in the future by selecting certain settings. Browsers offer different functionalities and options so you may need to set them separately. Also, tools from commercial browsers may not be effective with regard to Flash cookies (also known as locally shared objects), HTML5 cookies, or other Tracking Technologies. For information on disabling Flash cookies, go to Adobe's website http://helpx.adobe.com/flash-player/kb/disable-third-party-local-shared.html. Please be aware that if you disable or remove these technologies, some parts of the Services may not work and that when you revisit the Services your ability to limit browser-based Tracking Technologies is subject to your browser settings and limitations.
ii. Some App-related Tracking Technologies in connection with non-browser usage (e.g., most functionality of a mobile app) can only be disabled by uninstalling the app. To uninstall an app, follow the instructions from your operating system or handset manufacturer. Apple and Google mobile device settings have settings to limit ad tracking, and other tracking, but these may not be completely effective.
iii. Your browser settings may allow you to automatically transmit a "Do Not Track" signal to online services you visit. Note, however, there is no consensus among industry participants as to what "Do Not Track" means in this context. Like many online services, we currently do not alter our practices when we receive a "Do Not Track" signal from a visitor's browser. To find out more about "Do Not Track," you can visit http://www.allaboutdnt.com , but we are not responsible for the completeness or accuracy of this third-party information. You have the right to request information from us about the Services that currently do not respond to "do not track" mechanisms featured in any Internet browser by contacting us according to the "How to Contact Us" section below.
iv. Many advertisers and service providers that perform advertising-related services for us and third parties participate in voluntary programs that provide tools to opt-out of such interest-based advertising such as the Digital Advertising Alliance's ("DAA") Self-Regulatory Program for Online Behavioral Advertising. To learn more about how you can exercise certain choices regarding interest-based advertising for DAA members, visit http://www.aboutads.info/choices/, and http://www.aboutads.info/appchoices for information on the DAA's opt-out program for mobile apps. Some of these companies also are members of the Network Advertising Initiative ("NAI"). To learn more about the NAI and your opt-out options for their members, see http://www.networkadvertising.org/choices/. You can also go to http://www.adroll.com/about/privacy to adjust your advertising preferences with our provider AdRoll.
v. Please be aware that, even if you are able to opt out of certain kinds of Interest-based Advertising, you may continue to receive other types of ads. Opting out only means that those selected, participating members should no longer deliver certain interest-based advertising to you but does not mean you will no longer receive any targeted content and/or ads (e.g., from other ad networks). Also, if your browsers are configured to reject cookies when you visit these opt-out webpages, or you subsequently erase your cookies, use a different device or web browser or use a non-browser-based method of access (e.g., mobile app), your browser-based opt-out may not, or may no longer, be effective.
vi. We support the ad industry's 2009 Self-regulatory Principles for Online Behavioral Advertising (https://www.iab.com/wp-content/uploads/2015/05/ven-principles-07-01-09.pdf) and expect that ad networks that we directly engage to serve you interest-based advertising will do so as well, though we cannot guaranty their compliance. We are not responsible for the effectiveness of, or compliance with, any third-parties' opt-out options or programs or the accuracy of their statements regarding their programs.
vii. In addition, we may serve ads on third-party services that are targeted to reach people on those services that are also identified on one of more of our databases ("Matched List Ads"). This is done by using Tracking Technologies, or by matching common factors between our databases and the databases of the third-party services. We are not responsible for these third-party services, including without limitation their security of the data. We are not responsible for such third parties' failure to comply with your or our opt-out instructions as they may not give us notice of opt-outs to our ads that you give to them, and they may change their options without notice to us or you.
e. Analytics. We may use Third-Party Services such as Google Analytics and Sailthru to help us analyze our performance and our delivery of services and advertising to you. For example, we may use Remarketing with Google Analytics, Google Display Network Impression Reporting, the DoubleClick Campaign Manager and Google Analytics Demographics and Interest Reporting.
iii. We and third-party vendors, including Google, may use first-party cookies (such as the Google Analytics cookies) and third-party cookies (such as the DoubleClick cookie) together to report how your ad impressions, other uses of ad services, and interactions with these ad impressions and ad services are related to visits to our site.
5.0 INFORMATION YOU DISCLOSE PUBLICLY OR TO OTHERS
8.0 CHANGE OF OWNERSHIP
In the event that our ownership was to change as a result of a merger, acquisition, or any transaction involving the transfer of some or all of our assets by another company, your Services information may be transferred. We will provide you notice prior to any such transfer of your Personal Information.
9.0 HOW TO CONTACT US
Barnes & Noble College Booksellers, LLC
120 Mountain View Blvd.
Basking Ridge, NJ 07920
Attention: Chief Privacy Officer
10.0 OPTING OUT OF PROMOTIONAL COMMUNICATIONS
You can make choices about how your information may be used by us to provide information and offers to you. You may opt out of commercial messages by clicking on the "opt out" or "unsubscribe" link provided with each message. These preferences do not apply to transactional communications, such as those that are related to your registration with us, required or important notices related to your use of our Services, or the fulfillment of a specific transaction.
11.0 LINKS AND OTHER SITES
12.0 ACCESSING AND CHANGING INFORMATION
We may provide web page(s), other mechanisms or processes allowing you to delete, correct, or update some of the personal information that we collect from you, and potentially certain other information about you (e.g., profile and account information). We will make good faith efforts to make requested changes in our then-active databases as soon as practicable, but it is not always possible to completely change, remove or delete all of your information or public postings from our databases and residual and/or cached data may remain archived thereafter. Further, we reserve the right to retain data: (a) as required by applicable law; and (b) for so long as reasonably necessary to fulfill the purposes for which the data is retained except to the extent prohibited by applicable law.
California minors should see the "Minors" section below regarding potential removal of certain UGC they have posted on the Services.
Children under the age of sixteen (16) are not eligible to use the Services and must not submit any personal information to us.
a. Minor CA Residents. Any California residents under the age of eighteen (18) who have registered to use the Services, and who posted content or information on the Services, can request removal by contacting us in the manner described under the "How to Contact Us" section below, detailing where the content or information is posted and attesting that you posted it. We will then make reasonable, good faith efforts to remove the post from prospective public view or anonymize it so the minor cannot be individually identified to the extent required by applicable law. This removal process cannot ensure complete or comprehensive removal. For instance, third parties may have republished or archived content by search engines and others that we do not control.
14.0 JURISDICTION-SPECIFIC TERMS
a. Your California Privacy Rights. The California Consumer Privacy Act (“CCPA”), which provides California Consumers certain rights regarding their Personal Information (“PI”) as those terms are defined in the CCPA, became effective on January 1, 2020. We are providing you with notice of the PI we collect and our purposes for that collection for data that may be subject to the CCPA (“CCPA Notice”). This CCPA Notice does not cover information that is outside of the scope of the CCPA. This notice also does not apply to data collected from employees, applicants or contractors or to data collected from individuals acting as representatives of another business in connection with business communications or transactions.
We collect PI directly from you, your device or browser, your education institution, our service providers and suppliers, and our corporate affiliates. We use and share PI for the following business purposes:
- to provide requested products and services;
- to advertise and offer new products and services;
- to improve our products and services;
- for quality assurance;
- for research and development;
- for prevention of fraud and illegal activity; and
- for marketing purposes.
We collect the following categories of PI from Consumers which we share with our service providers, agents and licensees who perform services on our behalf, with our affiliates, and with your education institution:
- identifiers (e.g., name, phone number, email address, I.P. address);
- personal records (e.g., name, phone number, email address);
- customer account details / commercial information (e.g., your order history);
- internet usage information (e.g., information regarding your interaction with our online services); and
- inferences from PI collected (e.g., your preferences, your performance).
If you are a California Consumer and would like to register a request under your “right to know about personal information collected, disclosed or sold” (including right to obtain copies of specific pieces and/or information about categories of PI practices), “right to request deletion of personal information,” or “right to opt-out of the sale of personal information,” you can contact us at CaliforniaPrivacy@BNED.com or toll-free at 833-720-0427. You have the right to not receive discriminatory treatment in a manner prohibited by the CCPA because of exercising your rights under the CCPA.
To fulfill your CCPA request, we may require you to provide sufficient information to reasonably verify you are the Consumer about whom we collected PI. This verification process includes providing us at least two (2) unique data points, depending on the type of request.
Consumers have the right to exercise CCPA privacy rights via an authorized agent who meets the agency requirements of the CCPA. Authorized agent requests must include a copy of the agency agreement between the authorized agent and the consumer. We will ask the consumer to independently confirm the agency relationship.
The Right to Know
- Categories: You have the right, subject to statutory exceptions, to send us a request, no more than twice in a twelve-month period, for any of the following for the period that is twelve months prior to the request date:
- The categories of PI we have collected about you.
- The categories of sources from which we collected your PI.
- The business or commercial purposes for our collecting or selling your PI.
- The categories of third parties to whom we have shared your PI.
- A list of the categories of PI disclosed for a business purpose in the prior 12 months, or that no disclosure occurred.
- Specific Pieces: You have the right, subject to statutory exceptions, to make or obtain a transportable copy, no more than twice in a twelve-month period, of your PI that we have collected in the period that is 12 months prior to the request date and are maintaining.
The Right to Deletion
You have the right, subject to statutory exceptions, to request that we delete your PI that we have collected directly from you and are maintaining. Note also that we are not required to delete your PI that we did not collect directly from you.
You may alternatively exercise more limited control of your PI by instead by canceling or modifying our email marketing communications you receive from us. You can do so by following the instructions contained within our promotional emails.
The Right to Opt Out of Sale of Personal Information
We do not “sell” PI that we collect from you, including PI of minors under the age of 16, in accordance with the definition of “sell” in the CCPA. We treat all PI that we collect from you as subject to a “do not sell” request.
Effective Date and Last Updated: August 24, 2020