Lightricks Ltd., including our subsidiaries and affiliates (collectively, “Lightricks”, “we”, “our” or “us”), puts great efforts in making sure that the personal data we process is stored securely and used properly, and that our data practices are accurately communicated to our users and prospective users (collectively “you” or “your”).
“Prospect Data” or “Prospect(s)” concerning individuals who visit, use or engage with our website, blogs or other similar forums, online ads and content, surveys, emails or other communications under our control.
“User Data” concerning individuals (“Users”) who download and register to the Lightricks’ Apps, Websites and Web Services (together the “Services”).
“Personal data” means any information that can be used, alone or together with other data, to uniquely identify any living human being.
1. Data Collection
2. Data Uses
3. Data Location
4. Data Retention
5. Data Security
6. Data Sharing
7. Cookies and Tracking Technologies
9. Data Subject Rights
10. Roles and Responsibilities
11. Additional Information and Contact Details
1. DATA COLLECTION
The data we process regarding our Prospects and Users is typically collected and generated through automatic means, directly from you, through your interaction with us or with our Services; from our Users; or through third-party services, social media, analytics tools, events we organize or take part in, and other business initiatives.
Such data may include:
- Account information: e-mail address, name, user name, nickname, date of birth, gender, social media accounts, shipping address (if needed), subscription status (including a token indicating payment of the subscription and payment method) and additional optional information such as profile photo and hashed password or other information used for authentication and access control, and any other information that may be required when signing up to any of our Services.
You may also choose to login to our Services using your Apple, Facebook or Gmail account or connect to your social media account, ads manager account, or other accounts via an Application Programming Interface (“API“) or otherwise. By doing so, you provide us with information connected to such an account which may also include your name, profile picture, friends list, your social media provider identifiers, followers, language preferences, demographic data, location, account ID number/token, and email address. Please note that Lightricks doesn’t have control over how any third party uses or discloses the personal data it collects about you.
In the Popular Pays platform you may also participate in campaigns for a Brand or its agency (the “Gig”). In addition to Account Information, we may collect information pertaining to a Gig, such as your clothing size when you voluntarily apply for an apparel campaign etc., and any other identifier you may provide. We may also collect information in order to facilitate a funds transfer from the Brand to you (e.g. your PayPal account details).
- Photographs/Videos: As a general rule, all photos and videos on your device will remain stored on your device. Our Services contain the functionality which allows you to upload images or videos to the Lightricks Feed which will be stored on Lightricks’ servers (“Lightricks Cloud”). In such cases, we will collect the images and videos you upload to the Lightricks Cloud, which may also include Face Data (defined below) and analytical information.
- Services usage information: connectivity, technical and aggregated usage data, user agent, IP addresses, device data (such as type, OS, device ID, browser version, locale and language settings used), access times and dates logs, communication and performance logs, session recordings, issues and bugs, and the cookies and pixels installed or utilized on your device.
- Image Data: The Apps allow users to use special functions that are designed for editing (e.g. manipulating facial and other body features) and processing images and videos, including identifying the characteristics of images of people and faces. When you first install an App, you will be asked whether you permit the App access to specific photos or to your entire camera roll. If you grant access to the camera roll, we scan all your images in your camera roll, and we may collect and process information on the characteristics of images and videos that you have in your camera roll, such as the image setting (e.g., sunset, indoor, party), the posture, location and characteristics of faces or other face parts (eyes, lips, etc.) that appear in an image or video, and the number, estimated age and gender of people in the image or video. Some Services (for example, the “cartoonification” feature) require the temporary storing and processing on Lightricks Cloud of images and videos for the duration of the editing process. In certain cases, if you have granted us access to your camera roll or to a specific image or video, we may also collect and temporarily store images and videos for analytics purposes. For more details on where and how we store your personal data, please see the “Data Location” and “Data Sharing” sections below. Our Services may also recognize the faces of people in your photos (“Face Data”) in order to match photos to other photos with the same people or characteristics, or to suggest the use of certain features or functionalities. This identification process is conducted on your device. We do not collect or retain any biometric information or biometric identifiers from your images.
- Direct interactions and communications: messages, comments, feedback (e.g., internal communications), as well as correspondence with us (e.g., for user enablement, support and training purposes), including chats, surveys, calls and video recordings, transcriptions, and analyses thereof, and any other data you choose to provide or upload via the Services or in the context of the interaction with one of our customer experience representatives;
- Lightricks Feed: On the Lightricks Feed, Lightricks will process personal data such as profile photos, names, emails, social media accounts, reactions to feed posts and comments to feed posts.
- External Profile (“Link in bio”): As part of certain of its Services, Lightricks allows users to host an external linkable profile on its servers, which is called Link in bio.
- A Link in bio profile might include links to other social media accounts of the user, users’ full name, email, pictures websites, blogs or other communication methods. In addition, you can add features and integrations to the Link in bio, such as Topjar, Zoom call links, subscription and purchasing off content or merchandise, which may contain your personal data or links to external sources which contain your personal data.
- If you sell anything via Link in bio (e.g. merchandise), Lightricks may hold details of completed transactions such as date, amount, transaction ID. Lightricks will not store credit card information.
- If you decide to add subscription or other features which collect personal data from other users via the Link in bio, it is up to you to make sure that the collected personal data is being collected according to relevant privacy and data protection legislation.
2. DATA USES
Lightricks processes the personal data described in Section 1 as necessary for the performance of our Services; to comply with our legal and contractual obligations; and to support our legitimate interests in maintaining, improving and advertising our Services. These include understanding how our Services are used, and how our Services, campaigns and other activities are performing; gaining insights which help us dedicate our resources and efforts more efficiently; marketing, advertising and selling our Services; providing customer service and technical support to our users and customers; and protecting and securing our Services, ourselves and the entities and individuals we engage with.
We do not sell your personal information, as set forth in the California Consumer Privacy Act (CCPA).
Specifically, we use your data for the following purposes:
3. DATA LOCATION
We and our authorized Service Providers maintain, store and process personal data in the various locations we operate around the globe, including in Israel, the EU and the US, as reasonably necessary for the proper performance and delivery of our Services, or as may be required by law.
4. DATA RETENTION
We retain your personal data for as long as it is reasonably necessary to provide you with our Services and to maintain and expand our relationship; to comply with our legal and contractual obligations; or to protect ourselves from any potential disputes (e.g. as required by laws applicable to log-keeping, records and bookkeeping, and in order to have proof and evidence concerning our relationship, should any legal issues arise following your discontinuance of use), all in accordance with applicable laws and regulations. Please note that for many of our Services, Users may not use an App for a certain amount of time and still expect us to retain their personal data, such as their account information and photos. Therefore, we will generally retain your personal data for you until you instruct us to delete it. You may ask us to do so by emailing [email protected] or by initiating the process in-App, if such option is available.
When images/videos are uploaded to the Lightricks Feed and are incorporated by other Users into their own creations (“Incorporated Assets”) we won’t be able to amend, delete or fulfil any rights in relation to such Incorporated Assets.
Please note that except as required by applicable law or our specific agreements with you, we will not be obligated to retain your personal data for any particular period, and we are free to securely delete it or restrict access to it for any reason and at any time, with or without notice to you. If you have any questions about our data retention policy, please contact us by e-mail at [email protected].
Please also note that we do not retain your payment information, as it is transferred directly to the relevant Service Provider (as per Section 6 below). We only retain a token of such payment information (which cannot be used to re-identify you) and the chosen payment method.
5. DATA SECURITY
We implement appropriate technical, organizational, and security measures to reduce the risks of damage to (or loss of) information, or any unauthorized access or use of information. However, these measures do not provide absolute information security. Therefore, although efforts are made to secure your personal data, it is not guaranteed, and you cannot expect that the Services will be immune to information security risks or attacks. Also, as the security of information depends in part on the security of the computer, device or network you use to communicate with us, and the security you use to protect your user IDs and passwords. Please make sure to take appropriate measures to protect this information.
6. DATA SHARING
Legal Compliance: in exceptional circumstances, we may disclose or allow government and law enforcement officials access to your personal data, in response to a subpoena, search warrant or court order (or similar requirement), or in compliance with applicable laws and regulations, with or without notice to you. Such disclosure or access may occur if we believe in good faith that: (a) we are legally compelled to do so; (b) disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing; or (c) such disclosure is required to protect our legitimate business interests, including the security or integrity of our Services.
Service Providers: we engage selected third-party entities to perform services complementary to our own. Such Service Providers include hosting and server co-location services, communications and content delivery networks (CDNs), internet service providers, operating systems and platform, data analytics services, marketing and advertising services, data and cyber security services, fraud detection services, billing and payment processing services, shipping and handling services, web analytics, e-mail and SMS distribution and monitoring services, session or activity recording services, remote access services, performance measurement, data optimization services, social and advertising networks, content providers, support and customer relation management systems; and our business, legal, financial and compliance advisors (collectively, “Service Providers“). These Service Providers may have access to your personal data, depending on each of their specific roles and purposes in facilitating, supporting and enhancing our Services, and may only use it for such purposes.
Protecting Rights and Safety: we may share personal data with others if we believe in good faith that this will help protect the rights, property or personal safety of Lightricks, our Prospects, Users, or any members of the general public.
In-App sharing: due to the nature of the Apps and the Lightricks Feed feature, certain personal data available in the Apps is visible to other Lightricks Users in that App, for example your username, likes and comments on other Users’ content. We will never share your photos or videos with other Users unless you actively choose to do so.
SDKs: We use third party software development kits (SDKs) and other similar technologies on our Services to ensure their stable operation and to provide the Services as described above. Please see below a list of SDK providers we use (which may be updated from time to time), and more information about our use and sharing of your personal data with our SDK providers. Some of these third-party SDK providers may collect personal data from you for their use and processing and may obtain your consent prior to doing so.
Additional Sharing: we may share your personal data in additional ways, pursuant to your request or explicit approval, or if we are legally obligated to do so, or if we have successfully rendered such data non-personal, non-identifiable and/or anonymous. We may transfer, share or otherwise use non-personal and non-identifiable data at our sole discretion and without the need for further approval.
7. COOKIES AND TRACKING TECHNOLOGIES
Cookies: cookies are small text files that are stored through the browser on your computer or mobile device (for example, Google Chrome or Safari) when you visit a website. Some cookies are removed when you close your browser session – these are the “session cookies”. Some last for longer periods and are called “persistent cookies”. We use both types of cookies to facilitate the use of the Services’ features and tools. Whilst we do not change our practices in response to a “Do Not Track” signal in the HTTP header from a browser or mobile application, you can manage your cookies preferences, including whether or not to accept them and how to remove them, through your browser settings. Please bear in mind that disabling cookies may complicate or even prevent you from using the Services. For more information regarding cookies, you may find the following websites useful: www.allaboutcookies.org, www.youronlinechoices.co.uk.
Facebook Pixel Tags: We use pixel tags from Facebook. These tags provide information about, e.g., a user’s patterns of activity on our Services, IP address, time of visit, and so on. This information can be used by Lightricks and/or Facebook to help target Lightricks’ advertising. You can read more about Facebook’s Pixel Tag policies here.
We engage in service and promotional communications, through e-mail, phone, SMS and notifications.
Service Communications: we may contact you with important information regarding our Services. For example, we may send you notifications (through any of the means available to us) of changes or updates to our Services (such as billing issues, login attempts or password reset instructions, alerts and notifications concerning anomalies detected by our Services, abandoned cart emails, surveys, etc.). You can control your communications and notifications in accordance with the instructions included in the communications sent to you. Please note that you will not be able to opt-out of receiving certain service communications which are integral to your use.
Notifications and Promotional Communications: we may also notify you about new features, additional offerings, events, webinars, special opportunities or any other information we think you will find valuable. We may provide such notices through any of the contact means available to us (e.g., SMS, phone, mobile or e-mail), through the Services, or through our marketing campaigns on any other sites or platforms. Furthermore, if you contact us with an inquiry, we may respond with promotional emails relating to your inquiry. For example, if you contact us with an inquiry about a feature you would like to see on one of our Services, we will use your Contact Information to later inform you once our Services have been updated to include features similar to those you inquired about or other features you may be interested in. In order to control your notifications settings- please follow the instructions included in the promotional communications sent to you. If you do not wish to receive such communication, you may also notify us by sending an e-mail to: [email protected] or opt-out of these email updates by following the unsubscribe link located at the bottom of the email.
9. DATA SUBJECT RIGHTS
Should you ever decide to delete your Account, you may do so by emailing [email protected] or by clicking on the delete account option in the App settings. If you terminate your Account, any association between your Account and personal data we store will no longer be accessible through your Account. However, given the nature of sharing on certain Services, any public activity on your Account prior to deletion will remain stored on our servers and will remain accessible to the public.
Please note that such rights are not absolute. There are instances where applicable law or regulatory requirements allow or require us to refuse to provide some or all of the personal data that we hold about you. In the event that we cannot accommodate your request, we will inform you of the reasons why, subject to any legal or regulatory restrictions.
Individuals have rights concerning their personal data. If you wish to exercise your privacy rights under any applicable law, including the EU General Data Protection Regulation (GDPR), or the CCPA, such as the right to request access, rectification, or erasure of your personal data held with Lightricks, your right to restrict or object to such personal data’s processing, or to port such personal data – please contact us by e-mail at: [email protected]. Please be advised that deleting your personal data stored with Lightricks will adversely affect your use of our Services.
When images/videos are uploaded to the Lightricks Feed and are incorporated by other Users into their own creations (“Incorporated Assets”) we won’t be able to amend, delete or fulfil any rights in relation to such Incorporated Assets. If you wish to exercise your rights in relation to such Incorporated Assets, please reach out directly to the relevant creator.
Please also note that we may require additional information, including certain personal data, in order to authenticate and process your request. Such additional information may be then retained by us for legal purposes (e.g., as proof of the identity of the person submitting the request), in accordance with Section 4 above. We may redact from the data which we will make available to you, any personal data related to others.
10. ROLES AND RESPONSIBILITIES
Certain data protection laws and regulations, such as the GDPR or the CCPA typically distinguish between two main roles for parties processing personal data: the “data controller” (or under the CCPA, “business”), who determines the purposes and means of processing; and the “data processor” (or under the CCPA, “service provider”), who processes the data on behalf of the data controller (or business). Below we explain how these roles apply to our Services, to the extent that such laws and regulations apply.
Lightricks is a “co-controller” of certain portions of its Users Data, alongside such Service Providers that process Personal Data for both Lightricks’ analytics and marketing purposes – and the Service Providers’ own purposes. In such cases, such Service Providers (e.g. Facebook and Google) will in such circumstances be deemed as “co-controllers” of such data, which would typically relate to Users who also use the Service Provider’s own platforms. If you wish to limit such independent activities by these Service Providers, consider disabling third-party cookies as detailed in Section 7 above.
Lightricks is the “Data Processor” of Creator Data (as defined below) uploaded to Popular Pays’ platform. “Creator Data” means content created by Users and includes, but not limited to, personal data contained within creative materials, audio, written text in captions and blogs, photographs, video, or other deliverables provided on the Popular Pays platform by the User to a Brand. The Brand is the Data Controller of Creator Data.
11. ADDITIONAL INFORMATION AND CONTACT DETAILS
Children: The Services (both Web Services and Apps) are not intended for minors under the age of thirteen (13). IF YOU ARE UNDER THE AGE OF THIRTEEN (13) YOU MAY NOT USE THE SERVICES. If you are between thirteen (13) and eighteen (18) years old, you must review this Policy with your parent or guardian. If you have concerns about your child’s privacy, or if you believe that your child may have provided us with their personal data, please contact us at [email protected]. We will take steps to delete the information as soon as possible should we learn that we have collected the personal data of a child under 13 without first receiving verifiable parental consent.
California Privacy Rights: California Civil Code Section 1798.83 permits our Users and Customers who are California residents to request certain information regarding our disclosure of personal data to third parties for their direct marketing purposes. To make such a request, please send an email to [email protected]. Please note that we are only required to respond to one request per customer each year.
Deletion of Content from California Residents: If you are a California resident under the age of 18 and a registered User, California Business and Professions Code Section 22581 permits you to remove content or personal data you have publicly posted. If you wish to remove such content or personal data and you specify which content or personal data you wish to be removed, we will do so in accordance with applicable law. Please be aware that after removal you will not be able to restore removed content. In addition, such removal does not ensure complete or comprehensive removal of the content or personal data you have posted and that there may be circumstances in which the law does not require us to enable removal of content.
EU Representative: Lightricks has designated representatives in Germany for data protection matters. Inquiries regarding our EU privacy practices may be sent to [email protected] or Lightricks GmbH, c/o Mazars Tax GmbH, Theodor Stern Kai 1, 60596 Frankfurt am Main, Germany.
UK Representative: Lightricks has designated representatives in the United Kingdom for data protection matters. Inquiries regarding our UK privacy practices may be sent to [email protected] or Lightricks (UK), 37 Broadhurst Gardens, London, England, NW6 3QT United Kingdom.
Effective Date: July 10, 2022