Postcrossing Privacy Policy
We are Postcrossing Lda, a company in Portugal with tax number 513308016, registered at Rua Dom João IV 399, 2, sala 12, 4000-302 Porto. We provide the services at www.postcrossing.com, forum.postcrossing.com and community.postcrossing.com (jointly, the “Website”) which allow members from around the world to exchange postcards.
Anyone can navigate through parts of our Website without having to register, however, it is necessary to register to be able to make use of certain features, in particular those that enable the sending and receiving of postcards.
By registering and using our services, you share some of your personal information with us. We are committed to protecting your privacy, and have therefore developed this Privacy Policy to explain:
- Which information is collected
- How we use the collected information
- How we share the collected information
- How we store and secure information
- How you can access and control your information
- How we transfer information we collect internationally
- Other important privacy information
We advise everyone to read it carefully, in order to become familiar with our privacy practices.
Which information is collected
To bring you our services, we collect or receive your personal information in a few different ways:
- Registration, account setup
- To create an account in Postcrossing, we require some information from you: a username and password, email address, name and postal address, and your (approximate) location in order to place you on a world map.
- Profile
- You can choose to personalize your profile with optional information, such as birthday, gender, an avatar or a short text about yourself. Together with account activity, this information is part of your public profile.
- Use of the service
- We gather information provided by you and arising from your interactions with the Website, namely, the postcards you exchange and the content you post such as comments, images, and favorite postcards.
- Automated information
- When accessing our Website, our servers automatically receive and store information from your browser, such as your browser details, your IP address, requested page and referral page. This information is stored in log files for up to 30 days. We use this information only for the purpose of defending our servers against abuse, troubleshooting technical problems and understanding how our platform is used.
- Analytics information
- To improve the Website’s functionality and understand its usage, we rely on statistical information gathering services, which collect anonymized information about the Website’s visits (for example, pages viewed, length of visits, browser and operating system).
- Cookies
- Like many other websites, our Website makes use of browser cookies. Postcrossing has a dedicated Cookie Policy page, which explains in detail what cookies are, how Postcrossing uses them and how you can control and/or remove them. The Cookie Policy page is an integral part of this Privacy Policy.
- Customer support
- When you contact us with questions or ask for help, we save your message and contact details, in order to be able to help you.
- Payment information
- If you make any payment to us, we are legally required to keep a record of these transactions.
How we use the collected information
When you access or use our services, we collect, use, share, and process information about you as described in this Privacy Policy and only when we have a legal basis to do so. The legal basis depend on the services you use and how you use them. These legal basis are:
- We need the information to provide you the services and perform the contractual obligations in our Terms Of Service;
- There is a legitimate interest, such as providing, improving and personalizing the services, and/or protect the safety and security of the Website;
- You’ve given us your consent to do so for a specific purpose;
- You have made the information public, or;
- We need to comply with a legal obligation.
In more detail, we use the information we collect to:
- Provide the services and personalize experience
- We use the information we receive to provide our services to you, and to maintain and operate the Website. For example, it wouldn’t be possible to allow members to exchange postcards if we didn’t have their postal address. Other types of provided information allow us to authenticate you into your account, create your profile, show you maps and statistics about your activities and personalize certain aspects of the Website such as the types of advertisement you see or your preferred units of measurement.
- Improve our service
- Some of the information you provide is used to analyze, develop and improve the Website. For example, we use third party analytics providers, like Google Analytics, to gain insights into how our Website is used and to help us improve it.
- To communicate with you about the Website
- Your contact information is used to send you communications via email, such as when you request to send a postcard, when one of your sent postcards is registered, or when one of your postcards is marked as a favorite. We also use it to send you reminders, notices or updates about your account or the Website. While most of these communications can be disabled in your account settings, some cannot as they are part of the service we provide.
- Customer support
- We use your information to help you when you contact us about your account or about our Website. We may also contact you about your account use, to resolve disputes or to enforce our Community Guidelines and Terms of Service.
- Keeping our service safe and secure
- Postcrossing may use your information to ensure the safety and security of our Website and of our members, for example, by monitoring misuse or suspicious activity, identifying violations of our Terms of Service, protect the community against spam, harassment, and other security risks.
How we store and secure information
Security
We take the security of personal information very seriously, and do our best to safeguard it. Keeping in mind the industry best practices and the technical knowledge available, we use technical and organizational measures to protect your personal information, both during transmission and after it is received, against destruction, accidental or unlawful loss, accidental alteration, disclosure or unauthorized access, within a level of security appropriate to the nature of the information being protected. However, Postcrossing cannot guarantee the total security of the information of its users' accounts against all possible situations of unauthorized access, hardware or software failures and other factors that may compromise the security of the information.
Accounts
Your account access is protected by a password chosen by you. You should make careful use of the Website in order to prevent unauthorized access of your account and your personal information, namely, by carefully choosing and protecting your password and limiting access to the devices through which you access the Website.
Hosting
To provide you access to our Website, we use the hosting provider Amazon AWS, and their data centers in the E.U. Amazon AWS follows the industry best practices, adheres to globally known compliance programs in both security and data privacy, and implements several recognized certifications assessed by independent auditors.
Additionally, we use several technical measures to secure the information stored and ensure strict controlled access to it. Some of the safeguards we use are firewalls, intrusion detection systems, data encryption and access controls.
Backups
In order to ensure continued availability of the Website in case of any technical or physical incidents, we make regular backups of the information so we can restore your access to it in a timely manner. These backups are encrypted and kept for a limited period of time.
Storage period
When your account is terminated (either by you or by us), if you don't have any postcards traveling from your account, all your personal information is immediately deleted.
If you still have postcards traveling to other members, we may keep some of your account information (name, username, email, address, profile text and IP address) until either these postcards arrive or are deleted by our system. We do this so that we can help the recipients of your postcards register them, if they need our help. This means, some information can be kept for up to one year, but you can always contact us at any time to request that it is deleted sooner.
We may also keep some information to comply with legal obligations (for example, applicable tax/revenue laws), to resolve disputes or to enforce our Terms of Service.
How you can access and control your information
Most of the information Postcrossing collects about you is easily accessible to you simply by logging in to the Website.
Through your account settings, you can update your information, withdraw any consent that you had previously given (for instance, about which emails you’d like to receive from us or which types of ads you’re shown) or terminate your account to erase your personal information. Please ensure you’ve read the details about how long we store your information on the “storage period” section above.
If you require additional access to other information about your account, or would like to exercise your right to data portability, you’ll need to contact us so that we can first verify your identity.
Under certain circumstances, you may have the right to restrict the processing of your information. Please contact us, so that we can analyze your request.
Lastly, if you’ve lost access to your account or are having trouble exercising any of your rights, please contact us.
How we transfer information we collect internationally
When we transfer any personal information to a third party service provider in a country which is not a member state of the E.U., we will comply with the applicable legislation, in particular, we will make sure there is an adequate level of protection offered to personal information and we will not transfer personal information to services in jurisdictions that do not provide adequate safety and security guarantees.
Other important privacy information
Links to other websites or services
The Website may contain links to third party websites, including in advertisement banners. These third party websites and the way they process collected information are the sole responsibility of their owners, and therefore, Postcrossing is not responsible for their privacy policies and/or practices.
Updates to our Privacy Policy
We may update this Privacy Policy from time to time, and we will post the changes on this page. If the changes are significant, we will adequately announce those changes.
Contact
If you have any questions or concerns about how your information is handled, or if you believe we are not following this Privacy Policy, please contact us through our contact form or use our address:
Postcrossing Lda
Rua Dom João IV 399, 2, sala 12
4000-302 Porto
PORTUGAL
If we do not satisfactorily deal with a complaint you have, you may also contact the Portuguese Data Protection Authority.
Effective from: May 25, 2018