BAYAN PRIVACY POLICY

Chicago - Spring 2021

Effective Date: 7/01/2020

As part of the services offered on the Bayan digital platform, we need to collect detailed information from you. In doing so, Bayan is committed to respecting the privacy of all its users. This Privacy Policy describes how Bayan, Inc. (“BAYAN”, “we”, “our”, “us”) collects, uses, and shares your personal information and applies to your use of any part of the BAYAN website (including bayanclaremont.org and bayanonline.org) as well as any mobile application, subscription or digital property that links to this Privacy Policy and all features, content, and other services that we own, control and make available through such online service location (collectively, the “Service”), regardless of how you access or use it. The collection and processing of this information is necessary for the administration of our business and the provision of our services, which is necessary for the legitimate interests of our business. This Privacy Policy also explains your rights as well as the choices you can make to limit how your personal information is shared by BAYAN. Within this Privacy Policy, we describe the following as it relates to your personal information:

  1. TYPES OF PERSONAL INFORMATION WE COLLECT ABOUT YOU AND HOW IT IS COLLECTED
  2. HOW WE USE YOUR PERSONAL INFORMATION
  3. YOUR PRIVACY RIGHTS AND CHOICES
  4. USE OUTSIDE THE UNITED STATES
  5. CALIFORNIA PRIVACY RIGHTS
  6. CHILDREN’S PRIVACY
  7. OUR DATA SECURITY PROCEDURES
  8. CHANGES TO OUR PRIVACY POLICY
  9. HOW TO CONTACT US

TYPES OF PERSONAL INFORMATION WE COLLECT ABOUT YOU AND HOW IT IS COLLECTED

We may collect information you provide directly to us. For example, we collect information when you use the BAYAN website (including bayanclaremont.org and bayanonline.org), set-up or change your account information on, subscribe to notifications, make requests, or communicate with us while using our website. Our website and mobile application provide convenient ways for you to access the Service and learn about important BAYAN opportunities and events. We collect information about our online visitors both directly and indirectly from other companies that provide data to us. We use this information to communicate with our supporters and clients and process their transactions. We do not sell it to other organizations. When you use our website or mobile application to make a donation we may ask you for your name, address, phone number(s), and other information relevant to the transaction. We will ask for standard credit card information when you make a financial donation or purchase. We and our authorized subcontractors may automatically collect certain information about you when you access or use our Service (“Usage Information”). Usage Information may include your IP address, device identifier, Ad ID, browser type, operating system characteristics, data regarding network connected hardware (e.g., computer or mobile device), and information about your use of our Service, such as the time and duration of your visit and how you arrived at our Service. Except to the extent required by applicable law, BAYAN does not consider Usage Information to be Personal Information. However, Usage Information may be combined with your Personal Information. To the extent that we combine Usage Information with your Personal Information, we will treat the combined information as Personal Information under this Privacy Policy. The methods that may be used on the Service to collect Usage Information include:

  1. Log Information: Log information is data about your use of the Service, such as IP address, browser type, Internet service provider, referring/exiting pages, operating system, date/time stamps, and related data, which may be stored in log files or otherwise.
  2. Information Collected by Cookies and Other Tracking Technologies: Cookies, web beacons (also known as “tracking pixels”), embedded scripts, location-identifying technologies, fingerprinting, device recognition technologies, in-app tracking methods and other tracking technologies now and hereafter developed (“Tracking Technologies”) may be used to collect information about interactions with the Service or emails, including information about your browsing and activity behavior.
  3. Cookies: A cookie is a small text file that is stored on a user’s device which may be session ID cookies or tracking cookies. Session cookies make it easier for you to navigate the Service and expire when you close your browser. Tracking cookies remain longer and help in understanding how you use the Service, and enhance your user experience. Cookies may remain on your hard drive for an extended period of time. If you use your browser’s method of blocking or removing cookies, some, but not all types of cookies may be deleted and/or blocked and as a result, some features and functionalities of the Service may not work. A Flash cookie (or locally shared object) is a data file that may be placed on a device via the Adobe Flash plug-in that may be built-in to or downloaded by you to your device. HTML5 cookies can be programmed through HTML5 local storage. Flash cookies and HTML5 cookies are locally stored on your device other than in the browser, and browser settings won’t control them. To identify certain types of locally shared objects on your computer, visit your settings and make adjustments. The Service may associate some or all of these types of cookies with your devices.
  4. Web Beacons (“Tracking Pixels”): Web beacons are small graphic images, also known as “Internet tags” or “clear gifs,” embedded in web pages and email messages. Web beacons may be used, without limitation, to count the number of visitors to our Service, to monitor how users navigate the Service, and to count how many particular articles or links were actually viewed.
  5. Embedded Scripts: An embedded script is programming code designed to collect information about your interactions with the Service. It is temporarily downloaded onto your computer from our web server, or from a third party with which we work, and is active only while you are connected to the Service, and deleted or deactivated thereafter.
  6. Location-identifying Technologies: GPS (global positioning systems) software, geo-filtering and other location-aware technologies locate (sometimes precisely) you for purposes such as verifying your location and delivering or restricting content based on your location. If you use our Services from your mobile device, that device will send us data about your location based on your phone settings. We will ask you to opt-in before we use GPS or other tools to identify your precise location.
  7. Fingerprinting: Collection and analysis of information from your device, such as, without limitation, your operating system, plug-ins, system fonts and other data, are for purposes of identification and/or tracking (note that we do NOT collect any fingerprints or other biometric data from you).
  8. Device Recognition Technologies: Technologies, including application of statistical probability to data sets, as well as linking a common unique identifier to different device use (e.g., Facebook ID), attempt to recognize or make assumptions about users and devices (e.g., that a user of multiple devices is the same user or household).
  9. In-app Tracking Methods: There are a variety of Tracking Technologies that may be included in mobile applications, and these are not browser-based like cookies and cannot be controlled by browser settings. Some use device identifiers, or other identifiers such as “Ad IDs” to associate app user activity to a particular app.
We are giving you notice of the Tracking Technologies and your choices regarding them explained in the “Analytics Services, Advertising, and Online Tracking” and “Your Choices” sections below, so that your consent to encountering them is meaningfully informed and to track user activity across apps. We may also obtain information about you from other sources and combine that with information we collect about you. To the extent we combine such third-party-sourced information with Personal Information we collect directly from you on the Service, we will treat the combined information as Personal Information under this Privacy Policy. We are not responsible for the accuracy of the information provided by third parties or third-party practices.

HOW WE USE YOUR PERSONAL INFORMATION

We may use information about you for any purposes not inconsistent with our statements under this Privacy Policy or prohibited by applicable law, including to:

  1. Create and service your account;
  2. Fulfill, confirm, and communicate with you regarding your transactions;
  3. Respond to your comments, questions, and requests, and provide support;
  4. Send you technical notices, updates, security alerts, information regarding changes to our policies, and support and administrative messages;
  5. Prevent and address fraud, breach of policies or terms, and threats or harm;
  6. Monitor and analyze trends, usage, and activities;
  7. Improve our Service or other BAYAN digital properties, mobile applications, marketing efforts, products and services; and
  8. Send you recommendations and communicate with you regarding our and third-party offerings, programs, services, offers, promotions, rewards and events we think you may be interested in (for information about how to manage these communications, see “Your Choices” below).

YOUR PRIVACY RIGHTS AND CHOICES

Accessing and Changing InformationYou may access, review, correct, and update certain account information you have submitted to us by contacting us here. We will make a good faith effort to make the changes in BAYAN then-active databases as soon as practicable, but it may not be possible to completely change your information. We reserve the right to retain data as required by applicable law; and for so long as reasonably necessary to fulfill the purposes for which the data is retained as permitted by applicable law (e.g., business records).

Tracking Technologies Generally Regular cookies may generally be disabled or removed by tools available as part of most commercial browsers, and in some instances blocked in the future by selecting certain settings. Browsers offer different functionalities and options so you may need to set them separately. Also, tools from commercial browsers may not be effective with regard to Flash cookies (also known as locally shared objects), HTML5 cookies or other Tracking Technologies. For information on disabling Flash cookies, go to Adobe’s website here. Please be aware that if you disable or remove these technologies, some parts of the Service may not work and that when you revisit the Service, your ability to limit browser-based Tracking Technologies is subject to your browser settings and limitations.

Tracking Technologies Generally Regular cookies may generally be disabled or removed by tools available as part of most commercial browsers, and in some instances blocked in the future by selecting certain settings. Browsers offer different functionalities and options so you may need to set them separately. Also, tools from commercial browsers may not be effective with regard to Flash cookies (also known as locally shared objects), HTML5 cookies or other Tracking Technologies. For information on disabling Flash cookies, go to Adobe’s website here. Please be aware that if you disable or remove these technologies, some parts of the Service may not work and that when you revisit the Service, your ability to limit browser-based Tracking Technologies is subject to your browser settings and limitations. App-related Tracking Technologies in connection with non-browser usage (e.g., most functionality of a mobile app) can only be disabled by uninstalling the app. To uninstall an app, follow the instructions from your operating system or handset manufacturer. Your browser settings may allow you to automatically transmit a “Do Not Track” signal to online services you visit. Note, however, there is no consensus among industry participants as to what “Do Not Track” means in this context. Like many online services, we currently do not alter our practices when we receive a “Do Not Track” signal from a visitor’s browser. To find out more about “Do Not Track,” you can visit here, but we are not responsible for the completeness or accuracy of this third party information. Some third parties, however, may offer you choices regarding their Tracking Technologies. One way to potentially identify cookies on our Site is to add the free Ghostery plug-in to your browser, which according to Ghostery will display for you traditional, browser-based cookies associated with the websites (but not mobile apps) you visit and privacy and opt-out policies and options of the parties operating those cookies. BAYAN is not responsible for the completeness or accuracy of this tool or third-party choice notices or mechanisms. For specific information on some of the choice options offered by third party analytics and advertising providers, see the next section.

Analytics Services and Advertising Tracking Technologies You may exercise choices regarding the use of cookies from Google Analytics by going here or downloading the Google Analytics Opt-out Browser Add-on. You may choose whether to receive Interest-based Advertising by submitting opt-outs. Some of the advertisers and subcontractors that perform advertising-related services for us and our partners may participate in the Digital Advertising Alliance’s (“DAA”) Self-Regulatory Program for Online Behavioral Advertising. To learn more about how you can exercise certain choices regarding Interest-based Advertising, visit here, and here for information on the DAA’s opt-out program for mobile apps. Some of these companies may also be members of the Network Advertising Initiative (“NAI”). To learn more about the NAI and your opt-out options for their members, see here. Please be aware that, even if you are able to opt out of certain kinds of Interest-based Advertising, you may continue to receive other types of ads. Opting out only means that those selected members should no longer deliver certain Interest-based Advertising to you, but does not mean you will no longer receive any targeted content and/or ads (e.g., from other ad networks). BAYAN is not responsible for effectiveness of, or compliance with, any third-parties’ opt-out options or programs or the accuracy of their statements regarding their programs. However, we support the ad industry’s Self-regulatory Principles for Online Behavioral Advertising and expect that ad networks we directly engage to serve you Interest-based Ads will do so as well, though we cannot guarantee their compliance.

Additional Limits on Use of Your Google User DataNotwithstanding anything else in this Privacy Policy, if you provide the Service access to the following types of your Google data, the Service's use of that data will be subject to these additional restrictions:

  1. We will only use access to read, write, modify, or control Gmail message bodies (including attachments), metadata, headers, and settings to provide a web email client that allows users to compose, send, read, and process emails and will not transfer this Gmail data to others unless doing so is necessary to provide and improve these features, comply with applicable law, or as part of a merger, acquisition, or sale of assets.
  2. We will not use this Gmail data for serving advertisements.
  3. We will not allow humans to read this data unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes such as investigating abuse, to comply with applicable law, or for the Service’s internal operations and even then only when the data have been aggregated and anonymized.

Retention of Data

We will keep hold of your data for no longer than necessary. The length of time we retain it will depend on any legal obligations we have (such as tax recording purposes), the nature of any contracts we have in place with you, the existence of your consent or our legitimate interests as a business.

Communications

You can opt out of receiving certain promotional email communications from us at any time by following the instructions provided in emails to click on the unsubscribe link, or if available by changing your communication preferences by logging into your account. Please note that your opt-out is limited to the email address and will not affect subsequent requests or accounts you set-up. If you opt-out of only certain communications, other communications may continue. Even if you opt out of receiving promotional communications, we may, subject to applicable law, continue to send you non-promotional communications, such as those about your account, transactions, servicing, or our ongoing business relations.

Our Mobile Applications

With respect to our mobile apps (“App(s)”), you can stop all collection of data generated by use of the App by uninstalling the App. Also, you may be able to exercise specific privacy choices, such as enabling or disabling certain location-based or other services, by adjusting the permissions in your mobile device or in App settings. However, other means of establishing or estimating location in connection with Service use (e.g., IP address, connecting to or proximity to wi-fi, Bluetooth, beacons, or networks, etc.) may persist. See also the prior section regarding the DAA’s mobile Interest-based Advertising choices.

USE OUTSIDE OF THE UNITED STATES

The Service was created by and is controlled, operated and administered by BAYAN or its agents from offices within the United States of America utilizing servers located in the United States of America. We make no representation that materials on this Service are appropriate or available for transmission to or from, or use in, locations outside of the jurisdiction(s) stated above and accessing any Service from any jurisdiction where such Service’s contents are illegal is prohibited. You may not use this Service or export the materials in violation of import or export laws and regulations. If you access the Service from a location outside of the United States, you are responsible for compliance with all local laws. If you are accessing the Service from outside of the United States, please be aware that information collected through the Service may be transferred to, processed, stored and used in the United States Data protection laws in the United States. may be different from those of your country of residence. Your use of the Service or provision of any information therefore constitutes your consent to the transfer to and from, processing, usage, sharing and storage of your information, including Personal Information, in the United States as set forth in this Privacy Policy.

Your Rights as a European Union Resident Under GDPR

The General Data Protection Regulation (“GDPR”) sets forth certain rights for residents of the European Union countries. These rights are:

  1. The right to be informed – this means we must inform you how we are going to use your personal data. We do this through this Privacy Policy and by informing you how your data will be used each time we collect it.
  2. The right of access – you have the right to access your personal data (e.g. data that is about you) that we hold. This is called a subject access request. We must respond to your request within one month. To request access to your data, please email support@bayanonline.org. It is very helpful if you tell us what of your personal data you are seeking when you inquire.
  3. The right to rectification – if you think the data we hold on you is incorrect, tell us so we can put it right. You can do this by logging into your BAYAN account or emailing us at support@bayanonline.org.
  4. The right to erasure – you have the right to request that we delete your data. We will do so, provided that we do not have a compelling reason for keeping it. To request this, please email support@bayanonline.org.
  5. The right to restrict processing – you can change your communication preferences (therefore restricting how we communicate with you) by logging into BAYAN. There are also certain other circumstances in which you can suppress the processing of your personal data. To request this, please email support@bayanonline.org.
  6. The right to data portability – As applicable, you can obtain and reuse your personal data for your own purposes across different services. To request this, please email support@bayanonline.org.
  7. The right to object – you have the right to object to a) Direct marketing from BAYAN or from third parties we have shared your data with for direct marketing purposes. You can opt out of direct marketing any time by logging into BAYAN or visiting our Opt-Out Form here. There will also be instructions on how to unsubscribe included in any direct marketing message that we send to you; b) Any processing where our lawful basis is legitimate interest. If you would like to formally object to any of our legitimate interest processing, please email support@bayanonline.org.
  8. Rights in relation to automated decision making and profiling – this is not something we do at BAYAN at this time. If that ever changes, this policy will be updated accordingly.

At BAYAN, we are committed to upholding your rights as an EU resident. If you think we have not done so, please contact support@bayanonline.org.

CALIFORNIA PRIVACY RIGHTS

“Shine the Light” LawCalifornia’s “Shine the Light” law permits customers in California to request certain details about how certain types of their information are shared with third parties and, in some cases, affiliates, for those third parties’ and affiliates’ own direct marketing purposes. Under the law, a business should either provide California customers certain information upon request or permit California customers to opt in to, or opt out of, this type of sharing. BAYAN provides California residents with the option to opt-out of sharing “personal information” as defined by California’s “Shine the Light” law with third parties for such third parties own direct marketing purposes. California residents may exercise that opt-out, and/or request information about BAYAN compliance with the “Shine the Light” law, by contacting BAYAN here, or by sending a written request to:

Bayan 2854 North Santiago Blvd Suite 201 Orange, CA 92867 support@bayanonline.org

Requests must include “California Privacy Rights Request” in the subject line of your request and include your name, street address, city, state, and ZIP code. Please note that BAYAN is not required to respond to requests made by means other than through the provided email address or mailing address. Any California residents under the age of eighteen (18) who have registered to use the Service, and who have posted content or information on the Service, can request removal by contacting us here, or by sending a written request to:

Bayan 2854 North Santiago Blvd Suite 201 Orange, CA 92867 support@bayanonline.org

Your written request should detail where the content or information is posted and attesting that you posted it. We will then make reasonable good faith efforts to remove the post from prospective public view or anonymize it so the minor cannot be individually identified to the extent required by applicable law. Please note that the removal process cannot ensure complete or comprehensive removal. For instance, third-parties may have republished or archived content by search engines and others that we do not control. The Service discloses its tracking practices (including across time and third-party services) here and its practices regarding “Do not track” signals here.

California Consumer Protection Act (“CCPA”)

Information we CollectBAYAN. obtains personal information from categories of sources as set forth in the TYPES OF PERSONAL INFORMATION WE COLLECT ABOUT YOU AND HOW IT IS COLLECTED above. BAYAN. will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you with additional notice.

Sharing Personal InformationBAYAN. may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we require that the recipient both keep that personal information confidential and not use it for any purpose except performing the contract. We share your personal information with categories of third parties set forth in HOW WE SHARE YOUR PERSONAL INFORMATION above.

Sale of Personal InformationYou have rights regarding the personal information BAYAN collects and shares about you. The California Consumer Privacy Act (“CCPA”) gives California residents the right to opt-out of the sale of their personal information – as CCPA defines “sale” – and you can do that by clicking here and completing the opt-out form. If you have any questions or concerns regarding your rights or our Privacy Policy, you may email support@bayanonline.org or call 909-447-6347.

Your Rights and ChoicesThe CCPA provides California residents with specific rights regarding their personal information. This subsection describes your CCPA rights and explains how to exercise those rights.

  1. Access to Specific Information and Data Portability Rights

    You have the right to request that BAYAN. disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:

    • The categories of personal information we collected about you
    • The categories of sources for the personal information we collected about you
    • Our business or commercial purpose for collecting that personal information
    • The categories of third parties with whom we share that personal information
    • The specific pieces of personal information we collected about you (also called a “data portability” request)
    • If we disclosed your personal information for a business purpose, the personal information categories that each category of recipient obtained
  2. Deletion Request Rights

    You have the right to request that BAYAN delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies. We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:

    • Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
    • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities
    • Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided by law
    • Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. Seq.)
    • Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us
    • Comply with a legal obligation
    • Make other internal and lawful uses of that information that are compatible with the context in which you provided it
  3. Exercising Access, Data Portability, and Deletion Rights

    To exercise the access, data portability, and deletion rights describe above, please submit a verifiable request to use by either emailing support@bayanonline.org or call (909) 447-6347, and provide the following information:

    • First and last name
    • Email address
    • Mailing address, city, state and zipcode
    • Request type (Information/Access Request and/or Data Deletion)
    • Request details

    Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child. You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:

    • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative
    • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

    We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.

  4. Response Timing and Format

    We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily usable and should allow you to transmit the information from one entity to another entity without hindrance. We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

  5. Non-Discrimination

    We will not discriminate against you for exercising any of your CCPA rights.

CHILDREN’S PRIVACY

Our Service is not intended for nor targeted toward children under the age of thirteen (13). We do not knowingly collect personal information as defined by the United States Children’s Online Privacy Protection Act (“COPPA”) from children under the age of thirteen (13), and if we learn that we have collected such information, we will delete the information in accordance with COPPA. If you are a child under the age of thirteen (13), you are not permitted to use the Service and should not send any information about yourself to us through the Service. If you are a parent or guardian and believe we have collected information in a manner not permitted by COPPA, please contact us here. Any California residents under the age of eighteen (18) who have registered to use the Service, and who posted content or information on the Service, can request removal by contacting BAYAN here or by sending a written request to:

Bayan 2854 North Santiago Blvd Suite 201 Orange, CA 92867 support@bayanonline.org
When you contact us detailing where the content or information is posted and attesting that you posted it. BAYAN will then make reasonable good faith efforts to remove the post from prospective public view or anonymize it so the minor cannot be individually identified to the extent required by applicable law. This removal process cannot ensure complete or comprehensive removal. For instance, third-parties may have republished or archived content by search engines and others that BAYAN does not control.

OUR DATA SECURITY PROCEDURES

We take reasonable measures to protect Personal Information from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. Nevertheless, transmission via the internet and online digital storage are not completely secure and we cannot guarantee the security of your information collected through the Service. To help protect you and others, we and our subcontractors may (but make no commitment to) monitor use of the Service, and may collect and use related information including account and other Personal Information for all purposes not prohibited by applicable law or inconsistent with this Privacy Policy, including without limitation, to identify fraudulent activities and transactions; prevent abuse of and investigate and/or seek prosecution for any potential threats to or misuse of the Service; ensure compliance with our Terms of Use and this Privacy Policy; investigate violations of or enforce these agreements; and otherwise to protect the rights and property of BAYAN, its partners, and users. Monitoring may result in the collection, recording, and analysis of online activity or communications through our Service. If you do not consent to these conditions, please discontinue your use of the Service.

CHANGES TO THIS PRIVACY POLICY

We reserve the right to revise and reissue this Privacy Policy at any time. Any changes will be effective immediately upon posting of the revised Privacy Policy. Subject to applicable law, your continued use of our Service indicates your consent to the Privacy Policy posted. Your continued use of the Service indicates your consent to the Privacy Policy then posted. If you do not agree, please discontinue use of the Service, and uninstall Service downloads and applications.

HOW YOU CAN CONTACT US

For any requests relating to your Personal Information, or if you have any questions about this Privacy Policy, please contact us here or via mail at:

Bayan 2854 North Santiago Blvd Suite 201 Orange, CA 92867 support@bayanonline.org 909-447-6347