CropReach Privacy Policy

Last Revised: Aug 29th, 2024

Introduction

This privacy policy (“Privacy Policy”) describes the collection of personal information by Crop Reach LLC., (“Crop Reach”, “CropReach”, “Company,” “we,” “us”, or “our”) from users (“you”, “your”) of our website at www.cropreach.com (our “Site”) along with our related websites, networks, applications, platforms, and other services provided by us and on which a link to this Privacy Policy is displayed (collectively, our “Service” or “Services”). This Privacy Policy also describes our use and disclosure of such information. This Privacy Policy is incorporated by reference into our Terms and Conditions at https://www.cropreach.com/terms-of-service.

This Privacy Policy also describes your rights as a data subject to inquire about your personal information that we process and describes certain rights that you, as the data subject, have regarding this information.

For the purposes of EU, United Kingdom, and Swiss data protection laws ("Data Protection Legislation"), Crop Reach is a data controller (i.e., the company that is responsible for and controls the processing of your personal information).

Please read this Privacy Policy carefully to understand our practices regarding your personal information and how we will use it. By accepting this Privacy Policy and Terms and Conditions, you agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy.

Contacting us

If you have any questions or comments about this Privacy Policy, please contact us using the following contact information:

Crop Reach, LLC
Phone: unavailable currently
privacy@cropreach.com

If you are located in the European Union, and pursuant to Article 27 of the General Data Protection Regulation (GDPR), we have appointed the European Data Protection Office (EDPO) as our GDPR Representative in the EU. You can contact the EDPO regarding matters pertaining to the GDPR by using the EDPO’s online request form: https://edpo.com/gdpr-data-request/, or in writing to the EDPO Avenue Huart Hamoir 71, 1030 Brussels, Belgium.

If you are located in the UK, and pursuant to Article 27 of the UK GDPR, we have appointed EDPO UK Ltd as its UK GDPR representative. You can contact EDPO UK regarding matters pertaining to the UK GDPR by using EDPO’s online request form: https://edpo.com/uk-gdpr-data-request/, or in writing to the EDPO UK at 8 Northumberland Avenue, London WC2N 5BY, United Kingdom.

What information do we collect?

We use your personal information to carry out the obligations arising from providing and improving the Service. This section describes the types and categories of personal information we may collect, and how we may use that information.

Information you provide us directly

We collect personal information that you provide when you sign up, enter your information into online forms, or otherwise use the Site and the Services. We use this personal information in a variety of ways, and this personal information includes the following:

  • When you create an account on the Service we collect your first name, last name, and email address;
  • When you order or use the Services, we will collect the information necessary to complete billing transactions, including your first name, last name, credit card information, and a billing address, which may be your personal address or the address of the company you are associated with;
  • There may be times where certain features and functionality of the Service are invite-only, and as a result, we may collect your first name, last name, email address, the URL of your company or entity you are associated with, links to social media accounts so we may contact you that way, and a mobile phone number we may send scheduling reminders to. We may also collect the email addresses of contacts associated with you that you would like to include in these
  • If you sign up for our mailing lists, provide feedback, or otherwise communicate with us, we may collect contact and business information from you, such as your first and last name, e-mail address, mailing address, one or more phone numbers and the company name with which you are associated with;
  • If you apply for a job posting on our careers page, we collect information necessary to process your application, including your name, address, contact information, and details regarding your education and prior
  • We also collect other types of personal information that you provide to us voluntarily, such as if you contact us via the Site or Service regarding customer support or if you ask other questions regarding the

Automatically collected information

When you use our Services, some information is collected automatically and is not provided directly by you. For example, when you access our Service, we automatically collect your browser’s Internet Protocol (IP) address, your browser type, the nature of the device from which you are visiting the Service (e.g., a personal computer or a mobile device), the identifier for any handheld or mobile device that you may be using, the web site that you visited immediately prior to accessing our Service, the actions you take on our Service, and the content, features, and activities that you access and participate in on our Service. We also may collect information regarding your interaction with email messages, such as whether you opened, clicked on, or forwarded a message.

Our Services may collect information about your use of third-party websites that have enabled integrations with our Services, for example, whether you have clicked on an advertisement, the website address of the site that published this advertisement, and other associated information. This personal information may be combined with other information obtained from advertising networks and other sources to create more accurate data about your viewing and click-through activity with these advertisements. If you believe your personal information has been used in this manner, you should consult the privacy notices posted on the third-party sites for more information about the use of your personal information and your associated rights.

Information Collected from You About Others

If you decide to invite a third-party to create an account, receive an invitation for a demo, or otherwise interact with the Service, we will collect the third-party’s email addresses in order to send an invitational email to, and follow up with, the third-party. You should ensure that you know the third-party and they are expecting this invitation. In any case, you and/or the third party may contact us at privacy@cropreach.com to request the removal of this information from our databases.

Customer End-User Data

Through your use of the Services, you may provide Company with data, including personally identifiable information, you collect from your end-users, customers, prospects, or other users who interact directly with the websites, webpages, applications, landing pages, or any other media provided to or integrated with the Services. This data is processed on your behalf and under your instruction in accordance with our Data Processing Addendum.

Information from other sources

We may receive information about you, including personal information, from third parties, and may combine this information with other personal information we maintain about you. If we do so, this Privacy Policy governs any combined information that we maintain in a personally identifiable format.

Collection and processing of sensitive information

The Service does not collect or process ‘sensitive information’, which includes data describing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, data concerning a natural person’s sex life or sexual orientation, precise geolocation, and government-issued identifiers.

If you provide account information related to financial institutions and services when interacting or otherwise using one of our contracted payments processors, we do not process this category of data directly.

How do we use personal information?

We collect personal information when you create an account with the Services, when you update your account information, or otherwise correspond with us. We use your personal information for the following purposes:

  • To facilitate the creation of your account with the Service, to secure and personalize your interaction with the Service, and to provide the Services you have requested;
  • To send you a welcome email to verify ownership of the email address provided when your account was created with the Service;
  • To send you administrative email notifications, such as security or support and maintenance advisories;
  • We may also use the personal information you provide to contact you regarding your use of the Service or to solicit feedback;
  • When you communicate with us using one of the methods described in this Privacy Policy, we may also keep a record of the time and date of any correspondence, and also organize this correspondence in one or more of an electronic filing system, an email system, or a customer relationship management system;
  • We link this personal information to data about the way you use our Service and the pages you visit to help enhance, improve, operate, and maintain our Service, our platforms, websites, and other systems;
  • To prevent fraudulent use of our Service and other systems;
  • To prevent or take action against activities that are, or may be, in violation of our Terms and Conditions or applicable law;
  • We may also use the personal information you provide for direct marketing of our Services to you. We allow you to opt-out from receiving marketing communications from us as described in the “Communication choices” section below, and also at the time you sign up and create an account with the Service. Even if you opt-out, we may continue to send you administrative emails, including, for example, periodic updates to this Privacy Policy;
  • To display personalized or targeted content to you, and to display targeted advertising on third-party websites;
  • For internal product development purposes to develop new products and services, and to improve existing ones;
  • To respond to your inquiries related to employment opportunities with us, or other general

Legal basis for processing in Europe

If you are a resident of the EU, the United Kingdom, or Switzerland, we need to inform you about the legal basis on which we collect and use your personal information. In the EU, the United Kingdom, and Switzerland, the purposes for which we process your personal information are:

  • Where we need to perform the contract we are about to enter into or have entered into with you for the Service;
  • For the purposes of legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;
  • Where we need to comply with a legal or regulatory

The legal basis depends on the category of personal information being processed, and the purpose for that processing. The following table indicates each category of personal information we process, and the legal bases we rely on to do so. Where legitimate interest has been used as the legal basis for processing, the specific legitimate interest we use has been described.

Please contact us if you need details about the specific legal basis we are relying on to process your personal information where one or more legal bases have been indicated.

Category of Personal Information Legal Basis for Processing

Contact And Account Information

The performance of a contract and to take steps prior to entering into a contract;

Our legitimate interests, namely, administering the Service, for marketing purposes and communicating with users;

Where we need to comply with a legal or regulatory obligation.

Payment card information in order to process payment for the Services

The performance of a contract and to take steps prior to entering into a contract;

Where we need to comply with a legal or regulatory obligation.

Online Inquiries and Correspondence

Legitimate interest, namely for marketing purposes and to respond to inquiries.

Automatically collected information such as user actions and IP addresses

Legitimate interest, namely better understanding your use of the Service, making improvements to the Service

Employee candidate information

Legitimate interest, namely for considering your application for employment with us.

When do we share personal information?

Except as described in this Privacy Policy, we will not disclose your personal information that we collect on the Service to third parties without your consent. We may disclose information to third parties if you consent to us doing so, as well as in the following circumstances:

  • Service Providers. We may disclose personal information to third-party service providers (e.g., web hosting providers and other SaaS providers) that assist us in our work. We limit the personal information provided to these service providers to that which is reasonably necessary for them to perform their functions, and we require them to agree to maintain the confidentiality of such personal information;
  • Business Transfers. Information about our users, including personal information, may be disclosed and otherwise transferred to an acquirer, successor, or assignee as part of any merger, acquisition, debt financing, sale of company assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which personal information is transferred to one or more third parties as one of our business assets;
  • To Protect our Interests. We also disclose personal information if we believe that doing so is legally required, or is in our interest to protect our property or other legal rights (including, but not limited to, enforcement of our agreements), or the rights or property of others, or otherwise to help protect the safety or security of our Service and other users of the Service;
  • To Comply with the Law. We may also disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement

For personal information subject to an onward transfer by us under the EU-US Data Privacy Framework, the UK Extension to the EU-US Data Privacy Framework, and the Swiss-US Data Privacy Framework, we will remain liable under the Data Privacy Framework Principles (the “Principles”) if a recipient of your personal information processes such personal information in a manner inconsistent with the Principles, unless we are able to prove that we are not responsible for the event giving rise to the inconsistent processing.

Communication choices

If you receive marketing emails from us, you may unsubscribe at any time by following the instructions contained within the email. You may also opt-out from receiving marketing emails from us, and any other promotional communications that we may send to you from time to time (e.g., by postal mail) by sending your request to us by email at privacy@cropreach.com or by writing to us at the address given in the ‘Contacting Us’ section of this Privacy Policy.

Please be aware that if you opt-out of receiving marketing emails from us, it may take up to ten business days for us to process your opt-out request, and you may receive marketing emails from us during that period. Additionally, even after you opt out from receiving marketing messages from us, you will continue to receive administrative and transactional messages from us regarding your use of the Service.

Through your use of the Services, you may have provided us with a mobile telephone number. We may use this telephone number to send automated text/SMS messages, for example, to send you reminders for various events, webinars, and strategy sessions you have signed up for. You may opt-out of receiving these messages by replying with a request to opt-out. You may also opt-out of receiving these messages by sending your request to us by email at privacy@cropreach.com or by writing to us at the address given in the ‘Contacting Us’ section of this Privacy Policy.

Rights to access

If you have a user account and profile on our Service, you have the ability to access and update many categories of personal information that you provide to us by logging in to your account and accessing your account settings. If you wish to access or amend any other personal information we hold about you, you may contact us at privacy@cropreach.com. If you request that we delete your account with our Service, we will do so within a reasonable period of time, but we may need to retain some of your personal information in order to satisfy our legal obligations, or where we reasonably believe that we have a legitimate reason to do so.

Links to external sites

The Service may contain links to other websites, products, or services that we do not own or operate. The Service also may contain links to Third-Party Sites such as social networking services. If you choose to visit or use any Third-Party Sites or products or services available on or through such Third-Party Sites, please be aware that this Policy will not apply to your activities or any information you disclose while using those Third-Party Sites or any products or services available on or through such Third-Party Sites. We are not responsible for the privacy practices of these Third-Party Sites or any products or services on or through them. Additionally, please be aware that the Service may contain links to websites and services that we operate but that are governed by different privacy policies. We encourage you to carefully review the privacy policies applicable to any website or service you visit other than the Service before providing any personal information on them.

How long do we keep your personal information for?

Unless otherwise specifically stated elsewhere in this Privacy Policy, we will retain your personal information for the period necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Aggregated and anonymized data that no longer identifies the user of the Service is maintained for the purposes necessary to provide the Service.

EU privacy rights

If you are located in the EU, the United Kingdom, or Switzerland, you have the following Data Subject Access Rights with respect to your personal information that we hold:

  • Right of You have the right to access the personal information that we hold about you;
  • Right to You may have the right to require us to correct any inaccurate or incomplete personal information we hold about you;
  • Right to erasure. In certain circumstances, you may have the right to the erasure of your personal information we hold about you (for example where it is no longer necessary in relation to the purposes for which it was collected or processed);
  • Right to restriction. You may have the right to request that we restrict processing of your personal information in certain circumstances (for example where the accuracy of the personal information is contested by you, for a period enabling us to verify the accuracy of that personal information);
  • Right to portability. In some limited circumstances, you may have the right to portability which allows you to move, copy, or transfer personal information from one organization to another;
  • Right to object. You have a right to object to us processing your personal information when the processing is based on legitimate interests and also to stop us from sending you direct marketing;
  • Rights in relation to automated decision making and profiling. You have the right not to be subject to a decision that affects you based solely on automated processing. We do not perform any automated decision making and

If you wish to exercise one of these rights, please contact us using the information in the ‘Contacting us’ section of this Privacy Policy.

What is our policy on children?

Children’s safety is important to us, and we encourage parents and guardians to take an active interest in the online activities of their children. Our Services are not directed to users under the age of 16, and we do not knowingly collect personal information from children under the age of 16 without obtaining parental consent. If we learn that we have collected personal information from a child under the age of 16 on our Services, we will delete that information as quickly as possible. If you believe that we may have collected any such personal information on our Services, please notify us at privacy@cropreach.com.

Where do we store and process your personal information?

  • International Transfers: Our servers and data centers are located in the United States (US). If you choose to use the Service from outside the US, then you should know that you are transferring your personal information outside of your region and into the US for storage and processing. We may also transfer your data from the US to other countries or regions in connection with the storage and processing of data, fulfilling your requests, and operating the Service. You should know that each region can have its own privacy and data security laws, some of which may be less stringent as compared to those of your own If you are located in the European Union (EU), the United Kingdom (UK), or Switzerland, then the countries we may transfer your data to, including the US, may not have data protection laws as comprehensive as those in your own country. To ensure your data is protected, and that we comply with the applicable data protection laws, we have implemented the following measures:
    • Standard Contractual Clauses. We use the Standard Contractual Clauses (SCCs) for transfers of personal information to us, and also for transfer of personal information to third-party service providers. These clauses require the recipients to protect the personal information they receive in accordance with European data protection laws and regulations. Details of our use of SCCs can be provided upon request.
    • Derogations. In certain circumstances we may transfer personal information based on the derogations contained in Article 49 of the General Data Protection Regulation (GDPR).
    • Supplementary Measures. In addition to the SCCs, we may use contractual, technical and organizational measures to further protect your personal information.
    • Adequacy Decisions. Where applicable, we may rely on adequacy decisions provided by the European Commission under Article 45 of the GDPR to transfer your personal information outside of the EU, the UK, or Switzerland.
  • US Data Privacy Framework Notice: We comply with the EU-US Data Privacy Framework (“EU-US DPF”), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework (“Swiss-US DPF”) as set forth by the US Department of CropReach has certified to the US Department of Commerce that it adheres to the EU-US Data Privacy Framework Principles (“EU-US DPF Principles”) with regard to the processing of personal data received from the European Union in reliance on the EU-US DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-US Crop Reach has certified to the US Department of Commerce that it adheres to the Swiss-US Data Privacy Framework Principles (“Swiss-US DPF Principles”) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-US DPF. If there is any conflict between the terms in this privacy policy and the EU-US DPF Principles and/or the Swiss-US DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

Jurisdiction and Enforcement

  • As part of our participation in the EU-US DPF, UK Extension to the EU-US DPF, and the Swiss-US DPF, we are subject to the investigatory and enforcement powers of the US Federal Trade Commission (FTC).
  • For European Union residents, you also have the right to lodge a complaint to your local data protection authority. Further information about how to contact your local data protection authority is available at: https://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612080
  • For UK residents, you also have the right to lodge a complaint to the UK Information Commissioner's Office at: https://ico.org.uk/.
  • For Swiss residents, you also have the right to lodge a complaint to the Swiss Federal Data Protection and Information Commissioner (FDPIC) at: https://www.edoeb.admin.ch/edoeb/en/home.html.
  • In compliance with the EU-US DPF Principles and the Swiss-US DPF Principles, we commit to resolve complaints about your privacy and our collection or use of your personal European Union, and Swiss individuals with inquiries or complaints regarding this Privacy Policy should first contact us at privacy@cropreach.com.
  • We have further committed to refer unresolved privacy complaints under the EU-US DPF Principles and the Swiss-US DPF Principles to an independent dispute resolution If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit JAMS at:https://www.jamsadr.com/eu-us-data-privacy-framework for more information and to file a complaint.
  • Under certain conditions specified by the EU-US DPF Principles and the Swiss-US DPF Principles, you may also be able to invoke binding arbitration to resolve your complaint.

Do Not Track

California law requires us to let you know how we respond to web browser Do Not Track (DNT) signals. Because there currently isn’t an industry or legal standard for recognizing or honoring DNT signals, we don’t respond to them at this time. We await the result of work by the privacy community and industry to determine when such a response is appropriate and what form it should take.

California Shine the Light

A California resident who has provided personal information to a business with whom he/she has established a business relationship for personal, family, or household purposes (“California Customer”) is entitled to request information about whether the business has disclosed personal information to any third parties for the third parties’ direct marketing purposes, subject to certain exceptions, as defined in California Civil Code Sec. 1798.83. We do not share Personal Information with third parties for the third parties’ direct marketing purposes.

How do we secure your personal information?

To help protect your data, we use commercially reasonable steps to protect the data that we collect, including your personal information. The reasonable steps include protecting this data against accidental loss, unauthorized use, disclosure, and restricting access to personal information by our staff. The Service is hosted by a third-party hosting company that we have determined maintains adequate security controls and utilizes TLS encryption for all internet communication with the Service. We also require all staff that administer and develop the Service to follow industry-standard controls, including strong passwords, the use of anti-virus and anti-malware software, disk encryption, and other best practices.

We use various 3rd party processors to enable us to provide the Service, and as part of our vendor due-diligence, we review the security controls these processors have in place and ensure they meet industry standards appropriate for the type of data we collect.

You should keep in mind, however, that the Service utilizes software, hardware, and networks, which from time to time require maintenance and experience problems beyond our control. Note that no data transmission over the public internet or encryption method can be guaranteed to be 100% secure. Consequently, we cannot ensure or warrant the security of any information that you provide to us. You transmit information to us at your own risk.

Updates to this Policy

We may occasionally update this Policy. When we do, we will also revise the ‘last updated’ date at the beginning of the Policy. Your continued use of our Service after such changes will be subject to the then-current policy. If we change this Policy in a manner that is material, we will use reasonable efforts to notify you via the contact methods you have provided of the change prior to applying the change to any personal information that we collected from you prior to the date the change becomes effective. We encourage you to periodically review this Privacy Policy to stay informed about how we collect, use, and disclose personal information.