A. Collection of Information
The type of Information submitted to or collected by The Refinery varies depending upon the nature of the activity and relationship with The Refinery.
- Browsing the Website: When You browse the company’s website, The Refinery may collect information regarding the domain and host from which You access the Internet, the Internet Protocol address of the computer or Internet Service Provider You are using, and anonymous site statistical data. This information is collected for the purpose of assessing the effectiveness of the company’s website and for security reasons.
- Inquiries: The website contains various forms, links to company e-mail addresses, and fax numbers that You may use to solicit information about the website, The Refinery services, and the company in general. When You complete and submit a form, send us an e-mail, send us a fax, or contact us by telephone, The Refinery may store the inquiries and their contents, including any personally identifiable information You may have provided. Any personally identifiable information You submit via an inquiry is collected only with Your knowledge and active participation.
- Use of Gateway Services: When You register to use The Refinery online processing services (“Gateway Services”), You will be required to provide personally identifiable information and to enter into a written agreement with The Refinery. If You ordered any products or services from businesses that use our Gateway Services (“The Refinery Customers”), You were required to submit personally identifiable information (“Order Information”). The Refinery Customers transmit Order Information to The Refinery for the purpose of processing Orders. Order Information is maintained in servers located within the U.S.A. and may also be maintained in servers located in Europe or Asia, depending on where the order originates or the geographic location of a The Refinery Customer. The Refinery may maintain Order Information for a certain period of time to comply with audits or for disaster recovery purposes.
- Applying for a Merchant Account: When You submit an application to obtain a merchant account through The Refinery, You will be required to provide personally identifiable information. Furthermore, The Refinery may also obtain information about You from third party sources, including, without limitation, consumer reporting agencies.
- Notice for European Users: The Data Protection Act puts obligations on users of personal information and sets forth principles for its use. One principle states that information must be processed fairly and lawfully. This means that You are entitled to know how we intend to use any information You provide. You can then decide whether You want to give personal information to us.
The Data Protection Act does not generally apply to data about limited companies or partnerships, but it does cover personal data relating to sole traders and partnerships. When we receive an application from a business, we may perform a search with a credit reference agency and fraud prevention agency on the individual company directors or partners.
Order Information provided by You to The Refinery Customers and any Information that You provide to The Refinery directly will be transferred outside of the European Union to the United States. By providing personal information to The Refinery Customers or us, You are consenting to the transfer of such information outside of the EU and to its storage and use as described herein.
B. Use and Disclosure of Information
Usage and disclosure of Your Information varies based on Your relationship with The Refinery. The Refinery never sells any personally identifiable information and, except as expressly set forth below, never discloses personally identifiable information to any third parties.
- Browsing the Website: Information collected while You’re browsing our website may be used to analyze trends, administer the website, improve site performance, gather broad demographic information, and for security purposes. Such Information may be disclosed to third parties to provide any of the aforementioned activities on behalf of The Refinery.
- Inquiries: Information collected during the course of You submitting an inquiry via online form, e-mail, fax, or telephone call may be used by The Refinery to respond to Your inquiries or to contact You to inform You of services of The Refinery that may be of use to You. Information collected during the course of an inquiry will not be disclosed to any third party unless such third party has been contracted by The Refinery, with obligations of confidentiality, to contact You on our behalf.
- Use of The Refinery Services: If You are a The Refinery Customer, The Refinery will use Your Information during the course of providing You with the Gateway Services. During the course of providing such services, The Refinery may disclose Your Information to third parties that have contracted with The Refinery to perform certain functions of the Gateway Services on our behalf (“Subcontractors”). The Refinery may also use Your Information to contact You about other The Refinery offerings and to inform You about general company news and industry trends, directly or through the use of third party vendors. The Refinery may also use Your Information for internal business analyses. If You are a customer of a The Refinery Customer, The Refinery will use Order Information during the course of providing processing services to such The Refinery Customer. The Refinery may also use Order Information at an aggregate level for internal business analyses and fraud prevention. During the course of providing Gateway Services to The Refinery Customers, The Refinery may disclose Order Information to banks, processors, card associations, and other financial institutions that are involved in the course of processing or screening the transaction applicable to the Order Information.
- Applying for a Merchant Account: If You apply for a merchant account from or through The Refinery, The Refinery may use and disclose the Information to evaluate Your eligibility for a merchant account, including disclosure to consumer reporting agencies, relevant financial institutions, and other entities involved in providing the merchant account services. The Refinery may also use and disclose Your Information during the course of providing or procuring on Your behalf the merchant account services. The Refinery may also use Your Information to contact You, directly or through a third party vendor, about other The Refinery offerings and to inform You about general company news and industry trends. The Refinery may also use Your Information for internal business analyses.
- Surveys and Questionnaires: If You submitted an inquiry to The Refinery or if You are a The Refinery Customer, periodically, The Refinery may use Your Information to contact You, directly or through a third party vendor, to complete a survey or questionnaire. Responses to any such survey or questionnaire may be used for internal business analyses and may be disclosed in aggregate form without disclosing any personally identifiable information.
- Confidentiality Obligations: All contracts entered into between The Refinery and The Refinery Customers, The Refinery and Subcontractors, and The Refinery and other third party service providers contain express provisions governing the confidential treatment of any and all personally identifiable information.
- Investigations and Proceedings: The Refinery may use Information to conduct internal investigations. The Refinery may disclose Information to cooperate with an investigation by law enforcement agencies or other governmental authorities and may also disclose Information in response to a subpoena, warrant, court order, or other comparable legal processes.
The Refinery is committed to privacy and security. The Refinery is compliant with the Payment Card Industry Data Security Standard (“PCI DSS”) as a Level 1 service provider. The Refinery has been compliant with PCI DSS since its inception in 2002. PCI DSS is the bankcard industry’s most stringent security standard. Examples of The Refinery’s security measures include: physical, electronic, and procedural safeguards; sophisticated security monitoring tools; documented security policies; use of strong encryption for transmissions of Order Information to and from The Refinery Customers; restricted access of personally identifiable information; and, periodic security audits by third party security experts.
Correction and Deletion of Information
If You want The Refinery to correct or delete Your Information that is stored on The Refinery systems, please submit Your request in writing to:
Subject to our ability to verify Your request and provided that The Refinery is not required to maintain the Information by applicable laws, regulations, or contractual obligations, The Refinery will correct or delete the Information within thirty (30) days of receipt of Your request.