PRIVACY POLICY

SCOPE OF PRIVACY POLICY
This Privacy Policy describes how Tapok (collectively, “Tapok”, “we”, “our”, or “us”) collects, uses, and shares information about you (“you”, “your”, or “user”) when you use our website with a homepage located at “tapok.info”, any applications we may provide (including mobile applications), together with all products and services we may offer from time to time via our website and/or related applications, our related social medial websites such as Instagram, Twitter, Facebook, or otherwise through your interactions with us (our website, applications, products, services, and social media pages, collectively, the “Services”). This Privacy Policy also describes your and our legal rights and responsibilities with respect to information which identifies you or which could be used to identify you such as your name and contact details, or your user account information, which we call “Personal Information” in the text below. “Personal Information” also may include information about how you use our website. Tapok takes very seriously its responsibility to protect the safety and security of your Personal Information that we process and is committed to respecting your privacy rights.

APPLICABILITY OF Tapok’S PRIVACY POLICY
This Privacy Policy is part of our Terms of Use that governs your access to and use of our Services. We will refer to access, use, transmission, and exchanges of information, availability or utilization of features, functions or activities, simply as “use” in the material below.
This Privacy Policy applies to Personal Information that we collect from or about you through the methods described below (see “Information We Collect” and “How We Use Your Information”) to provide the Services. This Privacy Policy applies regardless of the means used to access or provide the Services. This Privacy Policy also applies to our targeted content, including online offers and advertisements for products and services, which you may see on third party websites, platforms and applications (“Offer Sites”) based on your online activity. These Offer Sites may have their own privacy policies and terms and conditions. We encourage you to read them before using those Offer Sites.
This Privacy Policy does not apply to information from or about you collected by third parties such as Tapok’s service providers, including, but not limited to, Shopify, Inc. (that hosts our e-commerce website), PayPal, Inc. (that processes payments on our behalf), and social media pages. The collection and use of your information by such third parties is governed by the relevant third party’s privacy policies, statements, and practices and under no circumstances are we responsible or liable for any third party’s compliance therewith.
This Privacy Policy does not apply to websites that link to Tapok’s website or websites that may be accessed through the Services. We may provide links to other websites that contain information that we believe may be useful to you or that you will find valuable. However, we have not investigated the security of those linked websites and you should not assume those sites have a privacy policy equivalent to ours. If you access such a third party website through a link we provide, you will be subject to the privacy policy of the new site. Tapok is not responsible for the contents of any linked webpages referenced from our website. If you have any questions regarding the privacy, security, or content of those sites, you should contact the appropriate contact(s) at those websites directly.


ACCEPTANCE OF PRIVACY POLICY
By using Tapok’s Services, including our website, you signify your acceptance of this Privacy Policy. If you do not agree to the terms of this Privacy Policy, please do not use Tapok’s Services. Your continued use of Tapok’s Services following the posting of changes to this Privacy Policy will mean that you accept those changes.

AGE OF CONSENT
By accessing Tapok’s Services, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use the Services.

INFORMATION WE COLLECT
Information That You Provide: We collect information that you provide directly to us. For example, we collect information when you use our website, shop in our stores, call us on the phone, create an online account, sign up to receive our emails, participate in a giveaway sweepstakes, contest, promotion or survey, communicate with us via third-party social media sites such as Facebook or Instagram, reserve an Tapok yoga class, request customer support, apply for a job or otherwise communicate with us. Providing your Personal Information to us is voluntary, however, if you do not provide some or all of the information we request, we may not be able to provide you with certain products, services or information.

The types of information you may provide directly to us include, but are not limited to your name, shipping address, billing address, zip or postal code, telephone number, email address, birth date, credit card or payment information, product and communication preferences, family members, demographic information, or any other information that could be used to contact you or any other information that you may choose to disclose to Tapok.

In some cases, we may also collect information you provide about others, such as when you schedule an Tapok yoga class, purchase a gift card for someone and request that we deliver it electronically, create and share a "wishlist" or decide to purchase and ship products to someone. We will use this information to fulfill your requests and will not send marketing communications to your contacts unless they separately opt in to receive communications from us.
Information We Collect Automatically: In order to improve the overall quality of your online experience, Tapok, its partners, and/or vendors automatically collect certain information about you when you access or use our website or Offer Sites, interact with our emails or online advertisements, or when you transact business with us. Information we automatically collect includes:
Log File Information: We collect information about your use of our website, such as the type of browser you use, access date/times, pages viewed, your Internet Protocol (“IP”) address and the referring link through which you accessed our websites. An IP address is a number that automatically identifies the computer or device you use to access the Internet. The IP address enables our server to send you the web pages that you want to visit, and it may disclose the server owned by your Internet Service Provider. We track and aggregate certain information about the visits to our website to analyze trends and statistics such as general traffic flow and feature usage related to Tapok’s website. We compile traffic-based statistics that show the numbers and frequency of visitors to our website and its individual pages. These are an aggregated statistical report that we use internally to better understand our website traffic, manage our website, and help diagnose any problems. Tapok may also aggregate such information and make it available to others as part of its business; however, we will not identify you when providing such information or make it possible to identify you by others in providing this information.
Cookies: Our website, online advertisements, and emails use first and third-party “cookies”, pixel tags, and other technologies to automatically collect information about you such as browser type, pages viewed, links clicked, and other actions you take in connection with our websites, online advertisements, and email. A cookie is data sent to your Internet browser from a Web server and stored directly on your computer hard drive. Cookies and similar technologies within a web browser allow us to collect and store data as you navigate our website. We use this information for various purposes, including to facilitate web page navigation, display information more effectively, personalize your online experience, to understand how our websites are used by users, market our products and services, measure the success of our marketing campaigns, and for security purposes.

Most web browsers are set up to accept cookies. You can adjust your browser settings to refuse all cookies or to inform you when a cookie is being placed on your hard drive. However, certain features of Tapok’s website may not work properly and you may be required to re-enter certain information each time you use our website. For example, to use our shopping cart feature, you must have cookies enabled. For more information about cookies and how to disable them, please see our Cookie Policy.

Where we use Google Analytics, we have set up the service to anonymize your IP address as soon as data is received by the Analytics Collection Network, before any storage or processing takes place. To opt out of being tracked by Google Analytics across all websites please visit http://tools.google.com/dlpage/gaoptout.
Transaction Information: When you purchase or return a product, we collect information about the transaction, such as product details and the date and location of the purchase/return.
Mobile Information: When you access our website from a mobile or smartphone device, we may receive information about your location and your mobile device, such as unique device identifiers.
Information From Third Party Sources: We also receive information about you from other sources, including service providers such as Shopify, PayPal, and Google, and through your interactions with us on social media websites, and we add it to the information we associate with your account.

INFORMATION WE DO NOT INTEND TO COLLECT
When you create an account on our website, you may provide us information such as your first and last name, e-mail address, password, birthdate and other info you provide. Tapok does not intend to collect and retain records of any sensitive personal information, data regarding minority status, or data received from third parties that is not expressly contemplated by this agreement or contractually authorized. We do not knowingly contact or collect information from persons under the age of majority in your state or province of residence. The Services are not intended to solicit information of any kind from persons under the age of majority in your state or province of residence.
TEXT MESSAGE/SMS CONSENT AND OPT-OUT
If you choose, you can provide your mobile phone number to receive text message alerts containing shipping information that may be sent via our third-party shipper, DHL Express (“DHL”) using automated dialing systems (“Text Messages”). You agree that by providing your mobile phone number you expressly consent to receive automated text messages from DHL to the mobile phone number provided. Message and data rates will apply and you should check the rates of your mobile carrier. You can opt out from further text marketing communications by following the opt-out instructions that will be sent to the SMS number used by DHL to contact you. Please refer to DHL’s privacy policy, found here, for how DHL manages its information.

We may share your mobile phone number with other service providers with whom we contract to assist us with the above activities, but we will not share your mobile phone number with third parties for their own purposes without your consent. You acknowledge that Text Messages are distributed via third party mobile network providers and, therefore, we cannot control certain factors relating to message delivery. You acknowledge that, depending on the recipient's mobile carrier, it may not be possible to transmit the Text Message to the recipient successfully; nor is content available on all carriers. We do not claim or guarantee availability or performance of this service, including liability for transmission delays or message failures. Tapok expressly disclaims any liability related to third party carriers or service providers.

SECURITY OF TRANSMISSION OF PERSONAL INFORMATION
Unfortunately, the transmission of information via the Internet or e-mail is not completely secure. Although we will do our best to protect Personal Information that you submit to us, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use commercially reasonable procedures and security features to try to prevent unauthorized access.

HOW WE USE YOUR INFORMATION
We may use your Personal Information to provide products and services and to support our business functions. For example, we may use this information for the following purposes:

Provide, Improve, and Develop the Tapok Website.
Provide the Services to you
Process and fulfill your order, including by shipping products to you, or others you designate, and sending emails to you, or others you designate, to confirm your order status and shipment and to process merchandise returns
Provide customer service
Operate, protect, improve, and optimize the Tapok Website and the user experience, such as by performing analytics and conducting research
Communicate with you and to send you information by email, postal mail, telephone, text message, or other means about our products, services, contests, support messages, updates, security alerts, and account notifications
Communicate with other persons using contact information you provide, such as when you designate another person as the recipient of a gift purchase
Make your shopping experience easier, more personalized, more enjoyable and more efficient
Address problems with and improve our products, brands, services and technologies, as well as to develop new products and services
Allow you to use our in-store and online technologies
Provide consistent, personalized services, including to personalize our advertising, marketing communications, shopping experiences and promotional offers
Organize local community events, promotions and in-store experiences
Facilitate your ability to share information to social media
Administer and fulfill our contests and other promotions
Help us learn more about your shopping preferences or product preferences
Fulfill a contract we have with you
Operate, protect, improve, and optimize the Tapok Website and experience, and personalize and customize your experience (such as making automatically entering your saved shipping information), we conduct profiling based on your interactions with the Tapok Website, your search and booking history, your profile information and preferences, and other content you submit to the Tapok Website.
We process this information given our legitimate interest in improving the Tapok Website and our users’ experience with it, and where it is necessary for the adequate performance of the contract with you.

Create and Maintain a Trusted and Safer Environment.
Prevent, detect, mitigate and investigate fraud, security breaches and activities that are or potentially may be prohibited or illegal
Conduct security investigations and risk assessments
Verify or authenticate information
As we believe to be required or appropriate to protect the rights, property, safety and security of Tapok and our employees, customers and others
As we believe to be required or appropriate under applicable law, to respond to requests from government authorities and to comply with legal process, investigations, regulatory or governmental enquiries or for other legal or regulatory purposes
Comply with our legal obligations
Resolve any disputes with any of our users or shoppers and enforce our agreements with third parties
Enforce our Terms of Use or other policies
We use your Personal Information in connection with automated decision making via our third party service provider Shopify to protect our business from fraud during the checkout process. Shopify uses customers’ Personal Information to block certain transactions that appear to be fraudulent through automated decision-making (you can review Shopify’s Privacy Policy here).

We process this information given our legitimate interest in protecting the Tapok Website, to measure the adequate performance of our contract with you, and to comply with applicable laws.

Provide, Personalize, Measure, and Improve our Advertising and Marketing.
Send you promotional messages we believe may be of interest to you, marketing, advertising, and other information that may be of interest to you based on your preferences (including information about Tapok or partner campaigns and services) and social media advertising through social media platforms such as Facebook or Google).
Personalize, measure, and improve our advertising.
Administer referral programs, rewards, surveys, sweepstakes, contests, or other promotional activities or events sponsored or managed by Tapok or its third party partners.
Conduct profiling on your characteristics and preferences (based on the information you provide to us, your interactions with the Tapok Website, information obtained from third parties, and your search and booking history) to send you promotional messages, marketing, advertising and other information that we think may be of interest to you.
We will process your Personal Information for the purposes listed in this section given our legitimate interest in undertaking marketing activities to offer you products or services that may be of your interest. You can opt-out of receiving marketing communications from us by following the unsubscribe instructions included in our marketing communications or changing your notification settings within your Tapok Account.

Other Purposes.
When you consent to it
When it is necessary to protect your vital interests or that of another person
When it is necessary for the performance of a task carried out in the public interest
When it is in our legitimate interests. Legitimate interests are our business or commercial reasons for using your data, such as (i) keeping our records up to date (ii) providing the Services to you; (iii) maintaining or administering the Services (iv) performing business analyses or for other internal purposes to improve the quality of our business and the Services we offer; (v) prevention of fraud and financial crime to protect the public; (vi) communicating with you concerning programs or services consistent with our obligations to provide those services or otherwise; and (vii) participating in litigation, investigations, regulatory or governmental enquiries or for other legal or regulatory purposes involving our customers who use or have used our Services or other third parties. We will not unfairly place our legitimate interests above what is best for you.
HOW WE SHARE YOUR INFORMATION
We share your Personal Information under confidentiality agreements with, or obtain data from, third parties in the following ways:
Brands. When you provide Personal Information to one of our Color Image Apparel, Inc. brands (Tapok, Bella+Canvas, Cody, or Ingrid & Isabel), we may share that information with our other Color Image Apparel, Inc. brands.
By You. You may disclose Personal Information when you post digital content to our website, third party websites, or other public forums, such as Tapok’s social media pages, blogs, and online product reviews. Any information that you disclose through these services will become public.
Third Party Service Providers. We share your information with third party service providers who we work with or who manage our customer information and perform services on our behalf, such as hosting our e-commerce platform, fulfilling promotions, processing online payments, providing and maintaining website features, sending communications and products to our customers, and conducting surveys. Our third party service providers are only authorized to collect, use, and disclose your information to the extent necessary to allow the third party service providers to perform the services they provide to us. Certain third-party service providers, such as Shopify and Paypal, have their own terms of use and privacy policies with respect to the information we are required to share with them in order to provide us with their services. For these third party service providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
Third Parties. We may share your information when we team up with another company to offer or provide products, services, contests, or promotions to our customers.
Social Sharing. Your Personal Information may be disclosed in connection with your social sharing activity, such as if you log into your customer account from your social media account. By connecting your customer account and your social media account, you authorize us to share information with your social media account provider, and you understand that the use of the information we share will be governed by the social media site’s privacy policy.
Legal Requirements. We may share information about you if necessary or appropriate to comply with laws or regulations or in response to a valid subpoena, court order, legal processes, or government request, or to protect the operations, privacy, safety, property or rights of Color Image Apparel, Inc or others, or when we believe it is necessary to share such information in order to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, or as otherwise required by law or to protect the public.
Business Transfer. In the event of a sale or merger of Color Image Apparel, Inc. or any of our businesses, our customers' Personal Information and other information we have collected as described in this policy may be among the transferred business assets.
Other Disclosures. We may share your Personal Information with our legal, regulatory, audit, and other professional advisors. Those companies may use your Personal Information to assist us in our operations consistent with our legitimate business interests. We also may share information about you as described at the point of collection or otherwise pursuant to your consent or where Tapok has a legitimate interest in doing so.
These third parties do not have any independent right to share your Personal Information. We will exercise reasonable measures to have the third parties to whom we disclose your Personal Information respect your Personal Information and comply with applicable data protection laws.
HOW WE KEEP YOUR INFORMATION
We will store your Personal Information for as long as is necessary to achieve the purposes for which it was collected, whether that is to provide services to you, for our own legitimate interests (described above), or so that we can comply with the law. We reserve the right to retain it to the full extent not prohibited by law. We may delete Personal Information in our discretion, so you should retain your own records, and not rely upon our storage of any Personal Information, content, or other data.

We will review the information we hold and when there no longer is a user, legal, or business need for us to hold it, we will either delete it securely or in some cases irreversibly anonymize it. When we delete any information, it will be deleted from our active databases but may remain in our archives.

HOW WE PROTECT YOUR PERSONAL INFORMATION
To prevent unauthorized access, maintain data accuracy, and facilitate the correct use of Personal Information obtained through our website, we have put in place appropriate physical, technical, and operational measures to safeguard and secure the Personal Information we collect online against unauthorized access, unlawful use, accidental loss, corruption, or destruction.

We also use operational measures to protect your Personal Information, for example by limiting the number of people who have access to your membership information. Access to Personal Information is restricted to Tapok staff members and third party service providers who require the access for specific purposes, such as helping us provide the Services to you.

We use technical measures such as password protection to protect your data and the systems where they are stored. However, messages you send to us through the Internet or otherwise electronically may not be secure. We recommend that you do not send any confidential information to us by email. If you choose to send confidential information to us, you accept the risk that a third party may intercept this information. We make reasonable efforts to keep your information safe and secure while shopping. We protect your online order and Personal Information by using Secure Sockets Layer (SSL) technology. All the data that travels between your computer and our servers is SSL encrypted, and then stored on a computer that is not connected to the Web. To make sure you are accessing a secure server, look at the lower left or right hand corner of your browser window after accessing the server. An un-broken key or closed lock (depending on your browser) indicates that SSL is active in your window. Some versions of browsers and firewalls don't permit communication through secure servers. In that case, you'll be unable to connect to the server so you won't have to worry about mistakenly placing an order through an unsecured connection.

LOCATION OF YOUR PERSONAL INFORMATION / YOUR PARTICULAR CONSENT
You are giving us the following particular express, voluntary, and informed consent to a few activities relating to your Personal Information that is disclosed in providing goods and services to you, or for a purpose directly related to such purpose:

Consent to International Transfer and Disclosure of Personal Information: Tapok is located in the United States (“U.S.”) and is subject to the applicable laws of the United States (where data privacy laws are less stringent than in the European Union and certain other jurisdictions). We will store and process information we receive about you, as described in this Privacy Policy, in the U.S.

We are involved in business activities in a variety of countries. For example, our e-commerce store is hosted on Shopify Inc., a Canadian company. Shopify provides us with the online e-commerce platform that allows us to sell our products to you. Your data is stored through Shopify’s data storage, databases and the general Shopify application. Accordingly, Shopify may transmit your personal information outside of the country, state, or province in which you are located.

You agree that Tapok and those with whom we share your Personal Information (“Recipients”) may disclose, transfer, process, and store your Personal Information outside of your country of origin to our affiliates, sponsors and partners, and any other third party service providers for the purposes described in this Privacy Policy.

Some of the recipients of Personal Information as specified above may be located in countries that do not provide a level of data protection equivalent to that set forth by the European Union and some other jurisdictions. If you submit any Personal Information or choose to access or use the Services offered by Tapok such as our website, you consent to such disclosure, transfer, process, and storage of information in accordance with this Privacy Notice and subject to such applicable laws which may include access by law enforcement and other government entities including courts and tribunals. If we do transfer Personal Information outside the U.S., we will make sure that it is protected in the same way as if it were being used in the U.S. We will use one of the following legally recognized safeguards protect your information:
Transfer the data to a non-EEA country that has privacy laws at least as protective as those within the EEA, or
Put in place a contract with the recipient of the data, which means the recipient must protect the data to the same standards as required within the EEA, or
Transfer it to organizations that are part of the Privacy Shield. The Privacy Shield is a framework that sets out the standards for data to be sent between the United States and European countries. The Privacy Shield ensures that data are protected to the same standards as used within the EEA.
Consent to Electronic Notice If There is a Security Breach: We will take reasonable measures to safeguard your Personal Information and prevent such information from unauthorized access, disclosure, or use. However, there can never be a guarantee of data security. If we or a Recipient is required to provide notice of unauthorized access to or other invasion of certain security systems, you agree that we (or they) may do so when required (or voluntarily) by posting notice on our website or sending notice to any email address we have for you, in our (or their) good faith discretion. You agree that notice to you will count as notice to others for whom you are acting, and agree to pass the notice on to them.

YOUR OPT-OUT CHOICES
We also work with third parties such as Google and Facebook to manage our advertising on other websites. Our third party advertising partners may use cookies or similar technologies on our website and other websites to provide you advertising based upon your browsing activities and interests, or to display ads that link back to our site. For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s educational page. You can opt-out of some, but not all, online behavioral based advertising by clicking here or by using your browser settings to block cookies or notify you when a cookie is set. If you are in the European Union, click here to opt out of online behavioral based advertising.

If you do not want Tapok to send you email or postal mail regarding Tapok or its Services, you can choose not to provide your Personal Information to Tapok, even though it might be necessary to make a purchase or to take advantage of certain features on our Services. You may also manage, update and correct the information you provide as part of your online account by logging into your user account and clicking on the “Settings” hyperlink. If you choose not to give us certain Personal Information, you can still use many aspects of our website. However, you will not be able to access website areas that require account registration.

If you have previously opted-in to receiving marketing emails from us, you can update your preferences to tell us specifically what you are interested in hearing about by clicking on the preferences link included in the marketing e-mails. You can update your preferences at any time.

If you would prefer not to receive marketing emails sent by Tapok, simply click on the “unsubscribe” link included at the bottom of any of those emails. If you opt out of receiving marketing emails, we may still send you other types of messages, such as purchase receipts, information about shipments, or emails about your user account.

YOUR RIGHTS OVER YOUR PERSONAL INFORMATION
EU Privacy Rights

If you are a European Union resident, in accordance with Tapok’s policies and procedures you have the right to review, verify, correct, and request erasure of the Personal Information that we hold about you under certain circumstances. You also have the right to limit, restrict, or object to the processing of your Personal Information under certain circumstances. You may also have the right to request that we transfer your Personal Information to another party to the extent provided for under applicable data privacy laws. For more information on your rights, please see https://ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens_en.

If you want to review, verify, correct, or request erasure of your Personal Information; limit, restrict, or object to the processing of your Personal Information; or request a transfer of your Personal Information to another party, please contact us at support@tapok.info.

When you contact us, we will respond as soon as possible and where possible within one month. If your request is more complicated, it may take longer to respond to you, but we will respond within three months of your request. There is no charge for most requests, but if you ask us to provide a significant amount of data, for example, we may ask you to pay a reasonable administrative fee. We also may ask you to verify your identity before we provide any information to you.



California Do Not Track Disclosure: Do Not Track is a privacy preference that users can set in their web browsers. When a user turns on the Do Not Track signal, the browser sends a message to websites requesting them not to track the user. For information about Do Not Track, please visit www.allaboutdnt.org. At this time, we do not respond to Do Not Track browser settings or signals. For information about Do Not Track, please visit: www.allaboutdnt.org.
COMPLAINTS
If you have any complaints concerning Tapok’s processing of your Personal Information, please email us at support@tapok.info

Please note that if you are an EU Resident, you may have the right to lodge a complaint with a European Union supervisory authority that is responsible for the protection of Personal Information in the country where you live or work, or in which you think a breach of data protection laws might have taken place. You can learn more about these rights at https://ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens_en.