Privacy Policy

I.GENERAL

IP CARGO, CORP, doing business as Botica Express (“BOTICA EXPRESS”), owns and operates a website, application, and corresponding technology platform that allows users to buy medicines and medical supplies only to be delivered within Cuba. This Privacy Policy governs your relationship with our website “www.boticaexpress.com” (“Site”), its corresponding applications, content, products, services, and technology platform.

Anyone interacting with BOTICA EXPRESS’s Site, mobile application, and corresponding technology platform (“Digital Platform”), are collectively referred to herein as Users and the services provided by BOTICA EXPRESS’s Digital Platform to said Users shall be referred to herein as (“Services”).

This Privacy Policy, together with our Terms and Conditions and any additional data privacy notices on our websites or in targeted e-mails, explains how BOTICA EXPRESS collects and uses the personal data of our Site visitors and client and business contacts. Any changes we may make to our Privacy Policy in the future will be posted on this page. BOTICA EXPRESS is interested in maintaining your privacy while creating a valuable and Digital Platform, giving you the best user experience possible, and in some cases developing a personal relationship with you to provide you with customized services, products, and information. If you have any questions, please contact us using our Contact Us form.

By using BOTICA EXPRESS SERVICES, you are consenting to the practices described in this Privacy Policy.

II.DEFINITIONS

Affiliates”: include a parent company and any subsidiaries, joint venture partners or other companies that we control or that are under common control with us.

Identifier”: Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers.

Internet Activity”: Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer’s interaction with an Internet Web site, application, or advertisement.

Personal Information” or “Personal Data”: Any information that identifies, relates to, describes, or is capable of being associated with, a particular individual or data subject, including, but not limited to, his or her name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information medical information, or health insurance information.

Protected Classifications”: Characteristics of protected classifications under California or US federal law, such as age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).

Sensitive Personal Data”: Sensitive Person Data refers to the various categories of personal data identified by privacy laws as requiring special treatment, including in some circumstances the need to obtain explicit consent. This includes, but is not limited to, information consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health (“Health Data”), or data concerning a natural person’s sex life or sexual orientation.

Usage Data”: Usage Data means data collected automatically either generated by using the Service or from the Service infrastructure itself (for example, the duration of a page visit).

User”: The User is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data.

You” and “you”: means any natural or legal person who person is accessing the Site. The term ”Your” and “your” shall be construed accordingly.

III.PERSONAL DATA WE COLLECT

You provide information when you search, order a product, participate in a contest or questionnaire, or communicate with our customer service. For example, you provide information when you search for a product; place a request or purchase a product through the Site; provide information in your account; communicate with us by phone, e-mail, or otherwise; complete a questionnaire, and provide reviews. As a result of those actions, you might provide us with information such as your name, address, and phone numbers; credit card information; recipients of purchases, including their addresses and phone numbers; contacts (along with their addresses and phone numbers); email addresses of your friends and other individuals; content of reviews and emails to us; personal descriptions and photographs; and financial information.

User Information. If you register and open an account with us, we will collect the information you provide in your application, including your name, email address, phone number, birth date, profile photo, physical address, government identification number (such as social security number), or User’s license information. We collect the payment information you provide us, including your bank routing numbers, and tax information. We may need additional information from you at some point after you become a User, including information to confirm your identity.

Examples of the additional information we collect and analyze include the Internet protocol (IP) address used to connect your phone or computer to the Internet; login; email address; password; computer and connection information such as browser type, version, and time zone setting, browser plug-in types and versions, operating system, and platform; purchase history; the full Uniform Resource Locator (URL) clickstream to, through, and from our Site, including date and time; cookie number; products you viewed or searched for; and the phone number you used to call our number.

We may also use browser data such as cookies, Flash cookies (also known as Flash Local Shared Objects), or similar data on certain parts of our Site for fraud prevention and other purposes. During some visits we may use software tools such as JavaScript to measure and collect session information, including page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page. We may also collect technical information to help us identify your device for fraud prevention and diagnostic purposes.

Users: Information We May Automatically Collect When You Use Our Services

We, along with our service providers, may automatically collect the following information about you, your devices, and your activity when using our Services:

  • Device information: i.e., device identifiers and settings such as your computer or mobile device model, IP address, other unique device identifiers, operating system version, browser type, language, and settings, etc.
  • Usage information: i.e., the time, date, and duration of your use of our Services, your interaction with content offered through the Services, site engagement, search terms used, our referring website, browsing and search history, site and advertisement interactions, and software crash reports. We also collect information stored using cookies, mobile ad identifiers, and similar technologies set on your device. Our servers may automatically keep an activity log of your use of the Services. We may collect such usage information at the individual or aggregate level.
  • Location information: We collect and store your device’s source IP address, which may disclose the general location of your device at the time you access our Services and precise location derived from GPS-enabled services. Advertisements and certain content may be directed to you based on this data.

If you connect using our mobile application, we may also collect:

  • Geo-Location Information. We may request access or permission to and track location-based information from your mobile device, either continuously or while you are using our mobile application, to provide location-based services. If you wish to change our access or permissions, you may do so in your device’s settings.
  • Mobile Device Access. We may request access or permission to certain features from your mobile device, including your mobile device’s Bluetooth, calendar, camera, contacts, microphone, reminders, sensors, SMS messages, social media accounts, storage, and other features. If you wish to change our access or permissions, you may do so in your device’s settings.
  • Mobile Device Data. We may collect device information (such as your mobile device ID, model, and manufacturer), operating system, version information and IP address.
  • Push Notifications. We may request to send you push notifications regarding your account or the mobile application. If you wish to opt-out from receiving these types of communications, you may turn them off in your device’s settings.

IV.USE OF YOUR INFORMATION

  • Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use your information to:
  • Identify and Authenticate. We may use your information to verify you when you create, access, or manage your account.
  • Provide our Services. We may use your information to provide our Services, process and fulfill orders, provide customer support, manage your account, and to otherwise comply with our contractual obligations to you. We (and/or our service providers) may use your financial information to process purchases made by you.
  • Communicate with You. We may use your information when we communicate with you (e.g., when we respond to a customer support request or other inquiry; notify you of any updates regarding our Services; deliver targeted ads and content; newsletters; etc.);
  • Improve our Services. We may use your information to understand how our Services are being used and how we can improve them.
  • Customize your Experience. We may use your information to personalize our Services to you. This may include remembering your preferences for language or volume or displaying videos that you might enjoy, based upon your viewing choices.
  • Market and Advertise. We may use your information to show you ads on third-party sites and to send you offers. We may also use your information in delivering third-party advertisements to you. This may include ”targeted ads” based upon your activities.
  • Exercise our rights. Where reasonably necessary, we may use your data to exercise our legal rights and prevent abuse of our Services. For example, we may use your data to detect and prevent fraud, spam, or content that violates our Terms and Conditions.
  • Debugging. We may use your information to identify and repair errors that impair existing intended functionality.
  • To Aggregate Data or Create Anonymous Data. We may create aggregated, de-identified or other anonymous data records from your Personal Information and other individuals whose Personal Information we collect. We make Personal Information into anonymous data by excluding information, such as your name, that makes the data personally identifiable to you. We may use this anonymous data and share it with third parties for our lawful business purposes, including to analyze and improve the Services and promote our business.
  • Comply with the Law. We may use your data where we are legally required to do so. For example, we may need to gather your data to respond to a subpoena or court order.
  • Protect Your Information. We may use your information to provide technical support to you, where required, and to ensure the security of our Services is appropriate. We may anonymize, backup, and delete certain information. We may also use your information to prevent fraudulent transactions, monitor against theft, and protect against criminal activity.

We may use algorithms and other automated means to implement any of the above. Whenever we process your information for one of these purposes, we have determined that one or more of the following lawful bases apply:

  • Performance of a contract;
  • Legitimate commercial interest;
  • Compliance with a legal obligation; or
  • Your Consent.

V.DISCLOSURE OF YOUR INFORMATION

We will not sell Personal Data to third parties. We generally only share Personal Data with our contracted service providers and advisors. However, there will be other times when we need to share or disclose Personal Data you provide for a specific purpose, for example:

Sale or Bankruptcy. We may need to disclose your personal data to third parties in the event that we sell or liquidate any part of our business or assets. This may involve transferring some or all of your Personal Information if we or one of our business units undergoes a business transition, such as a merger, acquisition by another company, or sale of all or part of our assets, or if a substantial portion of our or a business unit’s assets is sold or merged in this way.

As we continue to develop our business, we might sell or buy assets, subsidiaries, or business units. Information that we collect from our Users, including Personal Information, is a business asset. In such transactions, customer information generally is one of the transferred business assets and accordingly, User information, including Personal Data collected from you through your use of our Services, could be included in the transferred assets. If BOTICA EXPRESS or any subsidiary thereof is acquired by, or merged with, any other entity, we reserve the right to assign or transfer any information that we have collected. Therefore, if we are acquired by a third party as a result of a transaction such as a merger, acquisition, or asset sale, or if our assets are acquired by a third party in the event we go out of business or enter bankruptcy, some or all of our assets, including your Personal Information, may be disclosed or transferred to a third-party acquirer in connection with the transaction. Additionally, on the event of any bankruptcy, insolvency, reorganization, receivership, or assignment for the benefit of creditors, or for any application of laws or equitable principles affecting creditor’s rights, your information might be transferred or disclosed to third parties.

In the event of such a transaction, we will provide you notice of the transaction and the opportunity for a period of thirty (30) days to refuse disclosure or transfer of your Personal Information to the third-party acquirer in connection with the transaction. If you do not refuse the disclosure or transfer of your Personal Information to the third-party acquirer, then the third-party acquirer will receive your Personal Information and assume the rights and obligations regarding your Personal Information as provided in this Privacy Policy. You acknowledge that such transfers may occur, and that the transferee may decline to honor commitments we made in this Privacy Policy.

  • By Law or to Protect Rights. If we believe the release of information about you is necessary to respond to the legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others, we may share your information as permitted or required by any applicable law, rule, or regulation. This includes exchanging information with other entities for fraud protection and credit risk reduction.
  • Third-Party Service Providers. We may share your information with third parties that perform services for us or on our behalf, including payment processing, data analysis, email delivery, hosting services, customer service, and marketing assistance.
  • Marketing Communications. With your consent, or with an opportunity for you to withdraw consent, we may share your information with third parties for marketing purposes, as permitted by law.
  • Third-Party Advertisers. We may use third-party advertising companies to serve ads when you visit our Site. These companies may use information about your visits to the Site and other websites that are contained in web cookies to provide advertisements about goods and services of interest to you.
  • Affiliates. We may share your information with our Affiliates, in which case we will require those Affiliates to honor our Privacy Policy.
  • Business Partners. We may share your information with our business partners to offer you certain products, services, or promotions.

We are not responsible for the actions of third parties with whom you share personal or sensitive data, and we have no authority to manage or control third-party solicitations. If you no longer wish to receive correspondence, emails, or other communications from third parties, you are responsible for contacting the third party directly.

VI.PERSONAL DATA

We do not generally seek to collect Sensitive Personal Data through this site. In the limited cases where we do seek to collect such data, we will do this in accordance with local data privacy law requirements. If you choose to provide us with unsolicited Sensitive Personal Data, you consent to our using the data, subject to applicable law as described in this Privacy Policy.

These Services are governed by and operated in accordance with US law. If you are located outside of the US, you use thes Services at your own risk. BOTICA EXPRESS is a company that operates on the World Wide Web so it may be necessary to transfer your information internationally. In particular, your information will be transferred to and processed in the United States where our databases operate. By using our Services, you (a) acknowledge that the data protection and other laws of other countries, such as the United States, may provide a less comprehensive or protective standard of protection than those in your country, and consent to your information being collected, processed and transferred as set forth in this Privacy Policy and US law.

VII.DERIVATIVE DATA

Our servers automatically collect derivative data when you access the Site, such as your IP address, your browser type, your operating system, your access times, and the pages you have viewed directly before and after accessing the Site. If you are using our mobile application, this information may also include your device name and type, your operating system, your phone number, your country, your likes and replies to a post, and other interactions with the application and other users via server log files, as well as any other information you choose to provide.

VIII.FACEBOOK AND INSTAGRAM PERMISSIONS

The Site and mobile application may by default access your Facebook/Instagram basic account information, including your name, email, gender, birthday, current city, and profile picture URL, as well as other information that you choose to make public. We may also request access to other permissions related to your account, such as friends, check-ins, and likes, and you may choose to grant or deny us access to each individual permission. For more information regarding Facebook permissions, refer to the Facebook Permissions Reference page.

IX.DATA FROM SOCIAL NETWORKS

User information from social networking sites (such as Apple’s Game Center, Facebook, Google+, Instagram, Pinterest, and Twitter) including your name, your social network username, location, gender, birth date, email address, profile picture, and public data for contacts, will be accessible to us if you connect your account to such social networks. If you are using our mobile application, this information may also include the contact information of anyone you invite to use and/or join our mobile application.

X.MOBILE DEVICE DATA

The Site and our mobile application may by default access device information, such as your mobile device ID, model, and manufacturer, and information about the location of your device, if you access the Site from a mobile device.

If you connect using our mobile application:

Geo-Location Information. We may request access or permission to track location-based information from your mobile device, either continuously or while you are using our mobile application, to provide location-based services. If you wish to change our access or permissions, you may do so in your device’s settings.

Mobile Device Access. We may request access or permission to certain features from your mobile device, including its Bluetooth, calendar, camera, contacts, microphone, reminders, sensors, SMS messages, social media accounts, storage, and other features. If you wish to change our access or permissions, you may do so in your device’s settings.

Mobile Device Data. We may collect device information (such as your mobile device ID, model, and manufacturer), operating system, version information and IP address.

Push Notifications. We may request to send you push notifications regarding your account or the mobile application. If you wish to opt-out from receiving these types of communications, you may turn them off in your device’s settings.

XI.SECURITY MEASURES

We take appropriate steps to maintain the security of Personal Data collected via BOTICA EXPRESS’ Site. You should understand that the open nature of the Internet is such that information and Personal Data may flow over networks connecting you to our systems without security measures and may be accessed and used by people other than those for whom the data is intended.

When you sign into your account on our Site or mobile application, we may give you the option to stay signed into your account for a certain period of time. If you are using a public or shared computer, we encourage you not to choose to stay signed in. You or any other user of the computer/browser you signed in on will be able to view and access most parts of your account and take certain specific actions during this signed in period without any further authorization.

The security of your data is important to us. We follow generally accepted standards to protect the Personal Data submitted to us, both during transmission and once it is received but remember that no method of transmission over the Internet, or method of electronic storage is a hundred percent secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

XII.YOUR RIGHTS

You are entitled to know whether we hold Personal Data about you and, if we do, to have access to that personal data and require it to be corrected if it is inaccurate. You can do this by using our Contact Us form. You can exercise your right to prevent marketing communications to you by checking certain boxes on the forms we use to collect your Personal Data, or by utilizing opt-out mechanisms in e-mails we send to you. You can also exercise the right to discontinue marketing communications to you, or to have your Personal Data removed from our customer relationship management (CRM) databases at any time by using our Contact Us form. If you withdraw your consent for the use or disclosure of your Personal Information for purposes set out in this Privacy Policy, you may not have access to our Services, and we might not be able to provide you with all of the Services and customer support offered to our Users as authorized under this Privacy Policy and our Terms and Conditions.

XIII.COOKIES AND OTHER TRACKING TECHNOLOGIES

Cookies are text files containing small amounts of information which are downloaded to your computer or mobile device when you visit a website. Cookies are then sent back to the originating website on each subsequent visit, or to another website that recognizes that cookie. Cookies are useful because they allow a website to recognize a user’s device. Cookies do many different jobs, like letting you navigate between pages efficiently, remembering your preferences, and generally improving the user experience. They can also help to ensure that the advertisements and other content you see online are more relevant to you and your interests. They can be set by the website that you are visiting (known as first party cookies) or by another entity such as an advertising network (known as third party cookies). Session cookies are temporary and once you close the browser window they are deleted from your device. Persistent cookies remain on your device for a longer period and are used by the website to recognize your device when you return.

The help feature on most browsers will tell you how to prevent your browser from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether. Additionally, you can disable or delete similar data used by browser add-ons, such as Flash cookies, by changing the add-on’s settings or visiting the website of its manufacturer. Because cookies allow you to take advantage of some of the Site’s essential features, we recommend that you leave them turned on. For instance, if you block or otherwise reject our cookies, you will not be able to add items to your Shopping Cart, proceed to Checkout, or use any Site products and services that require you to Sign In to your account.

XIV.INTERNET-BASED ADVERTISING

BOTICA EXPRESS may use third-party software to serve ads on our platforms, implement email marketing campaigns, and manage other interactive marketing initiatives. This third-party software may use cookies or similar tracking technology to help manage and optimize your online experience with us. For more information about opting-out of interest-based ads, visit the Network Advertising Initiative Opt-Out Tool or Digital Advertising Alliance Opt-Out Tool.

XV.WEBSITE ANALYTICS

BOTICA EXPRESS may also partner with selected third-party vendors, such as Adobe Analytics, Clicktale, Clicky, Cloudfare, Crazy Egg, Flurry Analytics, Google Analytics, Heap Analytics, Inspectlet, Kissmetrics, Mixpanel, Piwik, and others, to allow tracking technologies and remarketing services on our Site and mobile application through the use of first-party cookies and third-party cookies. This is done to, among other things, analyze and track User’s use of our Site and mobile application, determine the popularity of certain content, and better understand online activity. By accessing the Site or mobile application, you consent to the collection and use of your information by these third-party vendors. You are encouraged to review their privacy policy and contact them directly for responses to your questions. We do not transfer personal information to these third-party vendors. However, if you do not want any information to be collected and used by tracking technologies, you can visit the Network Advertising Initiative Opt-Out Tool or Digital Advertising Alliance Opt-Out Tool.

You should be aware that getting a new computer, installing a new browser, upgrading an existing browser, or erasing or otherwise altering your browser’s cookie files may also clear certain opt-out cookies, plug-ins, or settings.

XVI.SPECIAL OFFERS AND UPDATES

We will occasionally send information regarding our products, including without limitation educational offers and our newsletter, to our customers and/or prospective customers. We typically use your name and email address to send these communications to you. Out of respect for your privacy, if you’d prefer not to hear from us, you can choose not to receive these types of communications. We often send our customers announcements for new or augmented Services. Many of these emails or other communications are necessary for the continued optimal functionality of our Services. Please see the section entitled ”Choice and Opt-out” within your account.

We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the “Last Updated” date of this Privacy Policy. Any changes or modifications will be effective immediately upon posting the updated Privacy Policy on the Site, and you waive the right to receive specific notice of each such change or modification.

You are encouraged to periodically review this Privacy Policy to stay informed of updates. You will be deemed to have been made aware of, will be subject to, and will be deemed to have accepted the changes in any revised Privacy Policy by your continued use of the Site after the date such revised Privacy Policy is posted.

XVII.CONTESTS AND SWEEPSTAKES

When you enter a contest, challenge, or sweepstakes with BOTICA EXPRESS, we will use the information you submit to determine a winner, to provide the winner(s) with their prizes (including via mail by sharing Personal Data with the postal or delivery service), and for auditing and legal purposes. We need such consent because your purpose in and reason for submitting your information is for and in connection with your contest entry.

XVIII.ACCOUNT TERMINATION AND DELETION

If for any reason you terminate your user account with us, we will destroy active records containing your Personal Data as soon as reasonably possible. ”Reasonably” here means no more than thirty (30) business days from the termination of the account. However, we may need to retain some information for a longer period as legal records or for auditing purposes. We retain data where we have a valid justification to hold onto it, such as to resolve disputes, keep track of product sales, comply with our legal obligations, or ensure we do not use it again pursuant to a User’s request.

If you are a resident or citizen of a country where the GDPR applies, and ask us to delete your account, we will remove your Personal Data from our Services, and then from our records in accordance with our data deletion cycle, except that we may retain Personal Data where we have a valid justification to hold onto it, such as to resolve disputes, keep track of product sales, comply with our legal obligations, or to ensure we do not use it again pursuant to a User’s request. If we terminate your access to the Services, we may retain enough information to prevent you from using the Services in the future.

XIX.POLICY FOR CHILDREN

We do not knowingly solicit information from or market to children under the age of 13. If you become aware of any data we have collected from children under age 13, please contact us using the contact information provided below.

XX.CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems and our platforms include a Do-Not-Track (DNT) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. No uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of the Privacy Policy. If you set the DNT signal on your browser, we will respond to such DNT browser signals.

XXI.EUROPEAN UNION GENERAL DATA PROTECTION REGULATION

We exclusively market and sell our Services to United States-based organizations and individuals. Even though we do not intentionally collect information about residents of the European Union (EU), some EU resident’s data may be inadvertently collected through marketing channels or by virtue of our customer’s legitimate use of our Services. Collection and storage of any EU resident’s data by us is minimal and incidental. No such data is used for marketing or any other purpose.

Further, we do not intentionally collect information on individuals under 18 years of age, regardless of their residency. Incidental exposure to this information may be possible if, for example, our customers upload this information to our Digital Platform or it is inadvertently captured by our marketing organization.

Notwithstanding the foregoing, if you are an EU resident and would like to request that your data be securely removed from our systems, however collected, please send an email with proof of EU residency to:

IP CARGO, CORP

13117 N.W. 107TH AVE STE 8

HIALEAH GARDENS, FL 33018

Via email to: Customerservice@boticaexpress.com

We will remove all relevant data, so long as that removal is technically feasible, does not impact the legitimate accounting or business practices of our customers, and does not violate other regulatory or legal standards with which we must comply. We will also cooperate with our customers in good faith to address any requests they receive or that may impact them directly.

XXII.NOTIFICATION OF CLAIMS OF COPYRIGHT INFRINGEMENT

If you believe that your work has been copied in a way that constitutes copyright infringement, or your intellectual property rights have been otherwise violated, please notify BOTICA EXPRESS’s agent for notice of claims of copyright or other intellectual property infringement (”

Copyright Agent”), at:

IP CARGO, CORP

13117 N.W. 107TH AVE STE 8

HIALEAH GARDENS, FL 33018

Via email to: Customerservice@boticaexpress.com

or:

Copyright Agent

Augusto Perera, Esq.

Telf. 305-489-1901

ap@tmmiami.com

www.tmmiami.com

121 Alhambra Plaza,

Suite 1500,

Coral Gables, FL 33134

Please provide our Copyright Agent with the following Notice:

a) Identify the material on the Site or mobile application that you claim is infringing, with enough detail so that we may locate it on the Site;

b) A statement by you that you have a good faith belief that the disputed use is not authorized by the copyright owner, its agent, or the law;

c) A statement by you declaring under penalty of perjury that (1) the above information in your Notice is accurate, and (2) that you are the owner of the copyright interest involved or that you are authorized to act on behalf of that owner;

d) Your address, telephone number, and email address; and

e) Your physical or electronic signature.

The Site will remove the infringing posting(s), subject to the procedures outlined in the Digital Millennium Copyright Act (DMCA).

XXIII.CALIFORNIA CONSUMER PRIVACY ACT

How We Collect, Use, and Share Your Personal Information. We collect the following statutory categories (as defined by CCPA) of Personal Information:

Personal Identifiable Information Category

Sources

Personal information described in Cal. Civ.Code§1798.80(e)(such as name, address, telephone number, education, employment history,

credit card or debit card number)

Information you provide directly or through your interactions with our Services.

Identifiers (e.g., real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address,

account name,or other similar identifiers)

Information you provide to us directly or through your interactions with our Services.

Characteristics of protected classifications under California or Federal law(e.g.,your gender or age)

Information you provide to us directly.

Commercial information (e.g., information regarding products or services purchased, obtained, or considered)

Information you provide to us directly when you use our Services.

Internet or Other Electronic Network Activity Information (e.g., browsing history, search history, and information regarding your interactions with our Services)

Your interactions with our Services.

Geolocation Data

Information you provide to us directly or through your interactions with our Services.

Professional or Employment Related Information (e.g., information you provide when you apply for a job with us).

Information you provide to us directly.

Inferences (e.g., information about your interests, preferences, and favourites).

Information you provide to us directly or through your interactions with our Services.

Audio, electronic, visual, or similar Information

Information you provide directly or through your interactions with our Services.

Financial information (e.g., your financial account numbers or payment card information)

We store only very limited, if any, financial information we collect. Credit card data is tokenized and held by a certified Service Provider. Otherwise, all financial information is stored by our own internal payment processors.

XXIV.CALIFORNIA PRIVACY RIGHTS

California Civil Code Section 1798.83, also known as the “Shine The Light” law, permits our Users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.

If you are under 18 years of age, reside in California, and have a registered account with our platforms you have the right to request removal of unwanted data that you publicly post on our platforms. To request removal of such data, please contact us using the contact information provided below, and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on our platforms, but please be aware that the data may not be completely or comprehensively removed from our systems.

As a California resident, you have the rights listed below. However, these rights are not absolute, and in certain cases we may decline your request as permitted by law. In certain circumstances, you have rights in relation to the Personal Information we hold about you. We set out below an outline of those rights and how to exercise those rights. Please note that we will require you to verify your identity before responding to any requests to exercise your rights. To exercise any of your rights, please email us at Customerservice@boticaexpress.com. In your request, please make clear what Personal Information you would like to have changed, or whether you would like to have your Personal Information that you have provided to us deleted from our database. Please note that for each of the rights below we may have valid legal reasons to refuse your request. In such instances we will let you know if that is the case.

Right to Know

You have the right to request that we disclose to you the following:

  • The categories of Personal Information we have collected about you;
  • The categories of sources from which the Personal Information is collected;
  • The business or commercial purpose for collecting or selling your Personal Information;
  • The categories of third parties with whom we share Personal Information; and
  • The specific pieces of Personal Information we have collected about you.

We will comply upon receipt of a verifiable request from you.

Right to Deletion.

You may request that we delete Personal Information we hold about you by sending us a verifiable request. We have no obligation to comply with your request to delete your Personal Information if it is necessary for us to maintain your Personal Information in order to:

  • Complete the transaction for which your Personal Information was collected, provide the service requested by you (or reasonably anticipated within the context of a business’s ongoing business relationship with you), or otherwise perform a contract between the business and you;
  • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity;
  • Debug to identify and repair errors that impair existing intended functionality;
  • Exercise free speech, ensure the right of another User to exercise his or her right of free speech, or exercise another right provided for bylaw;
  • Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code;
  • Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the businesses’ deletion of the information is likely to render impossible or seriously impair the achievement of such research, if you have provided informed consent;
  • To enable solely internal uses that are reasonably aligned with the expectations of the User based on the User’s relationship with BOTICAEXPRESS;
  • Comply with a legal obligation; and
  • Otherwise use the User’s Personal Information, internally, in a lawful manner that is compatible with the context in which the User provided the information.

Right to opt-out

At any time, you have the right to instruct a business that sells your Personal Information to third parties not to do so.

Non-Discrimination

We will not discriminate against you for exercising any of your rights stated herein, including, but not limited to, by:

  • Denying our Services to you;
  • Charging different prices for services, including through the use of discounts or other benefits or imposingpenalties;
  • Providing a different level or quality of our Services to you; and
  • Suggesting that you will receive a different price for our Services or a different level or quality of services.

Nothing prohibits us from charging you a different price or rate, or from providing a different level or quality of our Services to you, if that difference is reasonably related to the value provided to you by your information. We do not offer any financial incentives, including payments to you as compensation, for the collection of your Personal Information, the sale of Personal Information, or the deletion of your Personal Information.

Exercise California Rights to information, access, and deletion

California Residents may exercise their California rights to access information or assert deletion rights by contacting us by email at Customerservice@boticaexpress.com

Right to opt-out of the “sale” of your Personal Information

BOTICA EXPRESS does not sell your Personal Information in the conventional sense (i.e., for money). Like many companies, however, we use services that help deliver interest-based ads to you and may transfer Personal Information to business partners for their use. Making Personal available to these companies may be considered a “sale” under the CCPA. You may request to opt out of such “sale” of your Personal Information clicking here: Do Not Sell My Personal Information. Please note that you will still see some advertising, regardless of your selection.

XXV.IMPORTANT INFORMATION FOR USERS IN NEVADA

Nevada residents have the right to opt out of the sale of certain “covered information” collected by operators of websites or online services. We currently do not sell covered information, based on the definition of “sale” under the Nevada Privacy Law, and we do not have plans to sell such information at this time. However, if you would like to be notified if we decide in the future to sell your covered information under the Nevada Privacy Law, you can provide us with your name and email address at Customerservice@boticaexpress.com. You are responsible for updating any change in your email address by the same method and we are not obligated to cross-reference other emails you may have otherwise provided us for other purposes. We will maintain this information and contact you if our plans change. At that time, we will create a process for verifying your identity and providing an opportunity to verified consumers to complete their opt-out. Please become familiar with our data practices as set forth in this Privacy Policy. We may share your data as explained in this Privacy Policy, such as to enhance your experiences and our Services, and those activities will be unaffected by a Nevada do not sell request.