Privacy Policy - BBB National Programs, Inc.

Revised June 1, 2019

Introduction

BBB National Programs, Inc. (“BBB NP,” “we,” “our,” “us”) is a U.S. nonprofit organization with a mission of fostering trust, innovation and competition in the marketplace through the development and delivery of cost-effective third-party self-regulation, dispute resolution, and other Programs. This Privacy Policy describes BBB NP’s policies and practices regarding its collection, use, and sharing of personal data.

In the course of providing its nonprofit services, BBB NP may collect and process the personal information of individuals, including consumers, website visitors, complainants, arbitrators, and the representatives of businesses that participate in or interact with its programs (collectively, unless otherwise specified, “you,” “your”). This privacy policy covers websites operated by BBB NP, including BBBNP.org, bbbprograms.org, asrcreviews.org, and caru.org as well as certain webpages hosted on BBB.org that link to this privacy policy. Other pages on BBB.org are governed by the privacy policy of the International Association of Better Business Bureaus, available at BBB.org/privacy-policy.

Programs operated by BBB NP include BBB Auto Line, BBB EU Privacy Shield, Children’s Advertising Review Unit (“CARU”), Children’s Confection Advertising Initiative (“CCAI”), Children’s Food and Beverage Advertising Initiative (“CFBAI”), Coalition for Better Advertising Dispute Resolution, Direct Selling Self-Regulatory Council (“DSSRC”), Electronic Retailing Self-Regulatory Program (“ERSP”), Digital Advertising Accountability Program, National Advertising Division (“NAD”), and National Advertising Review Board (“NARB”). BBB NP also operates the National Partner Program, an exclusive network of leading businesses, law firms, and associations dedicated to advancing marketplace trust. In general, policies and practices described in this Privacy Policy apply to all BBB NP programs. However, if a particular program is named in a section of this policy, that section applies only to the specified program.

Other organizations that make use of the BBB brand are governed by their own privacy policies. For example, BBB Wise Giving Alliance has a separate privacy policy published on give.org and the International Association of Better Business Bureaus has a separate privacy policy published on BBB.org.

With the limited exception of the BBB EU Privacy Shield Program, BBB NP provides its nonprofit services exclusively to businesses and consumers in the United States. Visitors to BBB NP websites from other countries should be aware that their information may be processed and stored in the United States. Individuals in the European Union, please see the BBB EU Privacy Shield section below for information about that program’s policies and practices with regard to your personal data.

We recognize our ongoing responsibility with regard to the privacy of individuals whose personal data we collect and process. If we embrace new data privacy practices or adopt new policies, we will update this Privacy Policy. In the event that we make material changes to this policy, we will notify affected individuals.

Our Collection, Use, and Sharing of Your Information

1. Information that you submit to us.

In general, BBB NP uses information you affirmatively submit to us for the purpose for which it is submitted, such as to reply to your email, respond to your inquiry, handle your complaint, process billing transactions, register your participation in an event, respond to requests related to program participation, review applications to be a BBB NP arbitrator, and communicate with you when appropriate.

BBB NP relies on information collected from our users to develop new services and conduct analyses to enhance current content and services. Information collected from you may be used in aggregate form to review usage and operations of our site and address issues with our site. We may also use personal information we collect for operational notices, in program record-keeping, and to conduct research on industry marketplace practices. We may publish aggregate data to report trends and statistics, but the aggregate data will not include personal information.

Specifically, we may collect and process personal data you submit to us under the following circumstances:

a. While you use our public website. You can affirmatively submit to BBB NP certain information as you make use of our online services, which we use for purposes of delivering our website and services to you and for analytics. Such information may include the contents of a search query or other text that you type in our web forms. We do not share this information with third parties except agents we may contract with to deliver our services and for analytics.

b. As part of a consumer complaint regarding a business, advertisement, or online service. If you submit a complaint to one of our programs through an online form or other method, we may collect your name and contact information as well as any text content you voluntarily provide. Please do not include sensitive information as part of your complaint. We may use information you provide to us in a complaint for purposes of contacting you about your complaint and resolving your complaint. We also use complaint information in aggregated form for purposes of analyzing and reporting complaint trends.

  • If you submit a complaint to BBB AUTO LINE, you may be asked to provide other information necessary to verify and process your complaint, including information about your vehicle. See the BBB AUTO LINE section of this privacy policy for full details.
  • If you submit a complaint to BBB EU Privacy Shield, you may be asked for additional information in order to verify your identity for purposes of resolving the complaint. Individuals in the European Union or European Economic Area, please see the BBB EU Privacy Shield section below for information on our special policies and practices for the data of EEA individuals.
  • If you submit a complaint to the Digital Advertising Accountability Program, you do so through the complaint portal hosted by our third-party vendor Freshworks, Inc. In order for us to process and respond to your complaint, the Freshworks complaint portal collects your contact information and may infer additional information about your device, such as operating system and web-browser version. Any use by Freshworks of collected or inferred data of visitors to its website beyond those purposes directly contracted by BBB NP is covered by the Freshworks privacy policy.

Under certain circumstances, we may share the contents of your complaint with any business mentioned in the complaint. At our discretion, we may also share complaint information with another appropriate organization for purposes of facilitating the resolution of your complaint. We may publish reports that include aggregate complaint statistics and, if required, anonymized complaint details. We will not otherwise share complaint information with non-agent third parties.

c. When registering for a user account with the Online Archive. Individuals who wish to access NAD, CARU, and ERSP case reports as well as NARB panel reports, should subscribe to the Online Archive. When you register as an Online Archive subscriber on the BBB NP website, we collect the name, business name, and job title for each licensed user of your account as well as contact information including email address, phone number, and billing address. We use this information to provide you with the Online Archive service and to contact you in relation to this service. We may also contact you with more information about our programs, events, and services. We do not share your contact information with third parties.

d. When registering for an event or conference. When you register for a BBB NP-hosted conference or other event, we collect your name, business name, title, email address, and phone number. We use this information to keep you informed about the event, to send you information about our programs, services, and future events as well as, if relevant, membership or sponsorship opportunities. You also have the option to provide us with your Twitter handle to facilitate ongoing discussion and, as applicable, the state in which you practice law for purposes of applying for CLE credits.

The registration process for our conferences is handled by a third-party agent, Cvent, which is authorized to use your personal information solely for purpose of providing the services that BBB NP has contracted it to provide and for any purposes described in Cvent’s privacy policy.

We may share your name, business name, and title with other conference attendees. With your permission, we may share your company name with conference speakers. We do not otherwise share conference registration information with non-agent third parties.

e. When applying to BBB NP in an individual capacity. When you apply to be a BBB NP employee or intern or to be an arbitrator for the BBB AUTO LINE or BBB EU Privacy Shield programs, you submit your name, address and other contact information, and information about your qualifications. We use this information for processing your application and for contacting you in relation to your application. We do not share this information with any non-agent third parties.

f. When applying to or requesting information from a BBB NP program on behalf of a business. BBB NP may collect contact and billing information from a business that enquires about National Partner sponsorship or participation with an individual BBB NP program (including BBB AUTO LINE, BBB EU Privacy Shield, CARU, or Children’s Food and Beverage Advertising Initiative). This may include personal contact information about representatives of the business. To request to change the personal information associated with your business account, please reach out to the individual program with which you do business.

g. When representing a business in the NAD competitor challenge process. BBB NP may collect contact information from individuals (including outside counsel, if applicable) that participate in a National Advertising Division challenge, either on behalf of a company challenging a competitor’s advertising or having their advertising challenged. We use this information to contact the individuals throughout the challenge process. We may also contact these individuals with more information about our programs, events, and services. We do not share this information with any non-agent third parties.

h. When settling an invoice. BBB NP will use any billing information you have provided in order to contact you for payment of an invoice. In the process, we may ask for payment information, which will be entered directly into the payment system controlled by our third-party payment processor. BBB NP does not directly process or store payment information.

i. When signing up for a newsletter. At certain points where your information is collected on our site, there may be a box where you may indicate you would like to be on a mailing list to receive information about BBB NP or an individual BBB NP program. This election box only appears in places where the service collecting your information maintains such lists. We do not sell mailing lists and this information is not shared with any non-agent third parties. You can remove your name from a BBB NP mailing list by utilizing the appropriate unsubscribe feature contained in the emails.

2. Information collected automatically through your use of BBB NP websites and services.

a. Device information. Like most websites, BBB NP may automatically collect certain information from the device you use to visit our website, which we store in log files. This may include your browser type, device type, IP address, region or general geographical location from which your device is accessing the internet, operating system, unique device identifier, software version, and the domain name from which you accessed the site. We may rely on third-party agents to collect or process this analytic information. This information is used solely for our internal business purposes, including to improve the functionality of our site, diagnose problems, and generate statistical reports.

b. Usage information. We also may collect information about your use of the site on a particular device, including the date and time you visit the site, the referring site URL, the areas or pages of the site that you visit, the amount of time you spend viewing or using the site, other click-stream or site usage data, emails that you open, forward or click-through to our site, and advertising that you click on. We may rely on third-party agents, such as Google Analytics, to collect or process this analytic information. This information is used solely for our internal business purposes, including to improve the functionality of our site, diagnose errors, generate statistical reports, analyze trends, understand and improve user experience, and identify aggregate user preferences.

To view an overview of the privacy practices of Google Analytics, please go here: https://support.google.com/analytics/answer/6004245. Google Analytics supports an optional browser add-on that—once installed and enabled—disables measurement by Google Analytics for any site a user visits. You can find the browser add-on here: https://tools.google.com/dlpage/gaoptout.

c. Cookies or other persistent identifiers. BBB NP and our third-party agents may use persistent identifiers such as cookies, embedded scripts, web beacons, pixel tags, or similar technologies to collect information about our visitors’ interactions with our site. We use these identifiers to generate the data described in “usage information” above. This information is used to understand how visitors use our sites and provide better services to you, provide easier site navigation, access to forms, or to track analytics and certain statistical information that enables us to improve our site and provide you with more relevant content and information on our site and other sites.

You can still use BBB NP's websites if you have set your browser to reject cookies or tracking identifiers, but there is a possibility that this will prevent you from viewing or accessing some of the features of our sites. At this time we do not respond to “Do Not Track” signals issued by web browsers.

3. Information collected by third parties and shared with BBB NP.

a. In the course of complaint resolution, conciliation, or arbitration. BBB NP may receive information about you from businesses or organizations with which you have interacted for the purposes of facilitating the resolution of a pending complaint, conciliation, or arbitration proceeding. This may include your name, date of birth, account number, or other information used to verify your identity. This may also include account history information, your previous communications with the business or organization related to the matter in your complaint, or any other relevant information.

b. Participating business contact information. A business participating in BBB NP programs may share with BBB NP contact information for its employees or designated representatives. BBB NP will use this information only for the purposes of fulfilling the contract with the business.

Other Ways Information May Be Shared

We may use third-party agents to collect or process data on our behalf. Such contractors are obligated to not disclose or use your information for purposes other than for which it was originally collected or subsequently authorized.

BBB NP may also share information under the following circumstances:

  • We respond to requests from governmental agencies or where required by law (such as by subpoena, investigative demand, court order, or regulation).
  • We may share information with appropriate governmental or regulatory authorities, where warranted by a company’s failure to (i) participate in certain BBB NP self-regulatory programs including the Children’s Advertising Review Unit and the Digital Advertising Accountability Program; (ii) follow procedures or implement a decision of BBB EU Privacy Shield; (iii) substantially comply with its CFBAI pledge or CCAI Core Commitments; or (iv) participate in or honor the recommendations of the National Advertising Division, Children's Advertising Review Unit, National Advertising Review Board, Electronic Retailing Self-Regulatory Program, or Digital Advertising Accountability Program.
  • We may share information with appropriate persons or governmental authorities should your communication suggest possible harm to others.

Choices about your information.

Mailing Lists

You may unsubscribe from our mailing lists or other routine email communications using the link included at the end of each message or by sending an email to privacy@BBBNP.org.

Your Ad Choices
BBB NP adheres to the Digital Advertising Alliance’s Self-Regulatory Principles for Online Behavioral Advertising, and commits to provide consumers with notice and choice about interest-based advertising. On pages where we allow third parties to collect data for interest-based ads, you will see the notice “Your Ad Choices” near the link to our Privacy Policy. You may also see the AdChoices Icon Your Ad Choices icon in or near the ad. This Icon may mean that this ad was tailored to your possible interests as inferred from your browsing activity. Clicking on the Icon should provide you with access to more information about interest-based ads, including how to opt out of this practice.To learn more about interest-based advertising, click here. To opt out of future interest-based advertising, click here. You will still see ads, but they will not be tailored to your interests.

Children

BBB NP’s websites are not designed with the purpose of attracting any person under age 16. BBB NP does not knowingly collect or maintain any personal information from children under the age of 16. If we learn that we have collected personal information from a child under age 16, we will delete that information. Parents, if you believe your child has provided personal information to us, you can request that the information be deleted by contacting us at privacy@BBBNP.org.

Security

Personal data that you provide to BBB NP is stored by BBB NP on servers located in third-party data centers in the United States with restricted access, that have implemented reasonable procedures to prevent unauthorized access to, and the misuse of, personal data. BBB NP restricts access to your personal data to authorized BBB NP employees, independent contractors and service providers who need to access the data in order to provide services in support of BBB NP operations and program services.

BBB NP has taken steps to ensure the ongoing confidentiality, integrity, availability, and resilience of systems and services processing personal information and will restore the availability and access to information in a timely manner in the event of a physical or technical incident.

International Transfers

If you are visiting our site from outside the United States, be aware that your information will be transferred to, and maintained on, computers located within the United States. The collection, use, retention and any other processing of your information will be governed by U.S. law and further by the specific jurisdictions within the United States where that information is stored, unless otherwise specified.

 

 

Problems or Complaints with BBB Privacy Policy

If you have comments or concerns about this privacy policy, you may contact us at privacy@BBBNP.org.

Special Notice from BBB AUTO LINE

BBB NP operates BBB AUTO LINE, a dispute resolution program that assists consumers in certain U.S. states with resolving car warranty complaints against participating automobile manufacturers. BBB AUTO LINE only uses collected personal information for purposes of resolving warranty complaints and as required by law. For example, BBB AUTO LINE may be required to provide access to consumer case files to an independent compliance auditor for purposes of confirming BBB AUTO LINE compliance with applicable laws and regulations.

For BBB AUTO LINE consumers:

  • What information do we collect? BBB AUTO LINE collects personal data when you submit a claim via our online claim form, phone, mail or fax, and during subsequent interactions with our staff while processing your claim for resolution. Specifically, BBB AUTO LINE may collect your name, phone number, fax number, email address, mailing address, and applicable vehicle information such as your sales/lease agreement, vehicle registration, and repair orders. 
  • Please do not send any additional personal information unless specifically requested. BBB AUTO LINE will never request your Social Security Number or other sensitive financial information unrelated to your vehicle’s purchase or lease (e.g., bank account numbers). For your security, please redact or black out any such information from the documents you are submitting.
  • What do we do with your information? This information will be entered into your claim file and available on associated BBB AUTO LINE online platforms. Any other information you submit to BBB AUTO LINE through your online consumer account, over the phone, or via fax or mail will also be saved in your claim file.  The information you provide will only be used for the purpose of resolving your claim. Information about your complaint, in aggregate form, may also be used for federal and state regulatory reporting and statistics regarding BBB AUTO LINE.
  • Who else will see your information? The information you provide for your claim file may be shared with the automobile manufacturer mentioned in your warranty dispute. If your claim requires arbitration, the information may also be shared with a local BBB and arbitrator. If your claim requires consultation with a Technical Expert (TE), we may share your contact information and vehicle information including repair history to enable the TE to conduct an inspection and prepare a report of findings. TEs are contractually obligated to use your contact information only for purposes of performing their services as a TE.

 

 

For BBB AUTO LINE attorneys: If relevant, BBB AUTO LINE will collect information about individual attorneys representing consumers. This information includes name, firm name, attorney ID, and contact information. This information is associated with the attorney’s username on the BBB AUTO LINE online portal and is used only for the purpose of resolving disputes with which the attorney is involved.

For BBB AUTO LINE arbitrators: As described in section 1(e) above, BBB AUTO LINE will collect information about arbitrators who are contracted to resolve disputes within the BBB AUTO LINE program. In addition to name and contact information, BBB AUTO LINE collects information on the arbitrator’s biography and qualifications, including employment history, training history, and language proficiency. This information will be used solely for contacting the arbitrator with regard to pending or possible arbitrations.

Special Notice from BBB EU Privacy Shield Program to Individuals in the European Union and Switzerland

BBB NP operates the BBB EU Privacy Shield dispute resolution program ("BBB EUPS"), an independent recourse mechanism ("IRM") supporting the Privacy Shield Frameworks. BBB EUPS handles privacy complaints from individuals in the European Union ("EU"), the European Economic Area ("EEA"), and Switzerland regarding their personal data transferred to the United States pursuant to Privacy Shield and processed by U.S. organizations that have designated BBB EUPS as their IRM ("Participating Businesses").

Information BBB EUPS collects about EU/EEA Complainants
BBB EUPS collects personal data when you submit a privacy complaint using the BBB EUPS online complaint form, and during any subsequent contacts you have with BBB EUPS staff by electronic mail or telephone in relation to your Privacy Shield complaint. Except as otherwise indicated below, BBB EUPS does not collect personally identifiable information or personal data unless you voluntarily provide it to us, and limits the personal data it collects to information relevant for the purposes of processing. Types of personal data we collect include your name, full address, phone number, and email address, as well as documents and other information you may provide to us to authenticate your identity or substantiate your complaint. In the course of handling your complaint, we may also collect information about you from the Participating Business against which you filed your complaint.

How BBB EUPS Uses Your Personal Data
BBB EUPS may process your Personal Data for the following purposes:

  • Effective complaint handling, including verifying your identity and location; making eligibility determinations; and facilitating communications between you and BBB EUPS, and between BBB EUPS and the participating business that is a party to your case, as well as any independent Panelist conducting a Data Privacy Review of your complaint, in the conduct of the case.
  • Preparing and publishing reports as required under Privacy Shield or by the BBB EUPS Procedure Rules.
  • Providing information you may request about the services of BBB EUPS, and answering your questions.
  • Investigating and processing suspected violations of BBB EUPS's Procedure Rules.
  • Complying with BBB EUPS obligations as an IRM under Privacy Shield, including (i) provision of complaint data to the appropriate governmental authorities and (ii) complying with applicable data retention obligations.

When BBB EUPS transmits complaint-related information over the internet, we protect it through the use of data encryption methods.

Bases for Processing
To process the personal data of BBB EUPS complainants as described above, BBB relies on the following independent legal bases under GDPR: BBB EUPS carries out tasks in the public interest; processing is necessary for BBB EUPS's legitimate interests; and BBB EUPS receives complainants' express consent to process their personal data.

Public Interest. BBB NP is a not-for-profit organization that operates numerous widely recognized self-regulatory and alternative dispute resolution (ADR) programs in North America, including BBB EU Privacy Shield. The alternative dispute resolution programs of organizations such as BBB NP are sanctioned by the laws of many countries, most of which acknowledge the importance of ADR's role as an important channel in the administration of justice. The personal data collected by BBB EUPS in processing privacy complaints from EU and EEA individuals is essential to BBB EUPS's performance of its dispute resolution function under Privacy Shield, which constitutes "a task in the public interest" as a basis for collecting and maintaining such information under the GDPR.

Legitimate interests. Personal data related to complainants is collected only to the extent necessary given BBB EUPS's legitimate interests as a data controller, in its role as an independent recourse mechanism (IRM) providing dispute resolution services to individuals in the EU/EEA with privacy complaints against U.S. businesses participating in the Privacy Shield Frameworks that have identified BBB EUPS as their IRM.

Consent. Before completing the BBB EUPS online complaint form, BBB EUPS requests your express consent to our processing of your personal data in the United States. If you withdraw your consent to processing before we make an eligibility determination regarding your complaint and open a case, we will discontinue your complaint and delete your information. After a case has been opened, BBB EUPS may proceed with processing on the alternative legal bases set forth above, or where legally obligated to do so.

Sharing Your Personal Data with Third Parties
BBB EUPS may share your Personal Data with (i) a BBB EUPS Participating Business against which you have submitted a complaint, in order to process the complaint; (ii) independent Data Privacy Panelists we may assign to arbitrate your complaint, should you request a Data Privacy Review; and (iii) BBB NP's service providers, including data processors, in order to deliver the services provided by BBB EUPS.

Data Retention
BBB EUPS will store your Personal Data for as long as necessary to perform the purposes of processing, which include handling your complaint to its final resolution; producing required reports pursuant to Privacy Shield and to the BBB EUPS Procedure Rules; and otherwise complying with our legal and regulatory obligations.

Data Subject Rights for EU/EEA Individuals
Subject to some limits, individuals in the EU and EEA countries have a number of rights regarding personal data collected by BBB NP in the course of BBB EUPS complaint handling:

  • Right of access and portability. The right to obtain access to your personal information, along with certain related information, and to receive that information in a commonly used format and to have it transferred to another data controller;
  • Right to rectification. The right to obtain rectification of your personal information without undue delay where that personal information is inaccurate or incomplete;
  • Right to erasure. The right to obtain the erasure of your personal information without undue delay in certain circumstances, such as where the personal information is no longer necessary in relation to the purposes for which it was collected or processed;
  • Right to restriction. The right to obtain the restriction of the processing undertaken by us on your personal information in certain circumstances, such as where the accuracy of the personal information is contested by you, for a period enabling us to verify the accuracy of that personal information; or where BBB NP no longer needs to retain the personal data, but you would like us to keep it in order to establish, exercise or defend a legal claim.
  • Right to object. The right to object, on grounds relating to your particular situation, to the processing of your personal information.

If you need further assistance regarding the above rights, please contact us at privacy@BBBNP.org and we will consider your request in accordance with applicable law.

In some cases our ability to uphold one or more of these rights for you may be limited, in light of BBB NP's role as a private organization providing ADR services through BBB EUPS in the public interest, or for security, safety, fraud prevention reasons, compliance with regulatory or legal requirements, or because processing is necessary to deliver the services you have requested. Where this is the case, we will inform you of specific details in response to your request.

EU and EEA individuals also have the right to lodge a privacy complaint with the appropriate supervisory authority. Contact information for the EU data protection authorities can be found here: https://edpb.europa.eu/about-edpb/board/members_en.