Who We Are
engineARC, provides professional Web development and web hosting services. This privacy policy applies to all visitors and customers using or accessing our website and services. It also covers the WordPress services we provide as part of engineARC memberships that utilize APIs to interact with our servers or the engineARC site, as well as the human resources data of our employees and contractors.
This policy does not cover websites that we host for our customers as part of engineARC. For these sites, the site owner/customer is responsible for publishing their own privacy policy.
For any privacy-related questions, you can reach us at info@enginearc.com.
Sharing Your Data
We use third-party services (data processors) on our site. The extent to which your data is shared with these providers depends on your use of our services. We list specific third parties in use (with links to their privacy policies) in the sections below.
Each third-party provider has been vetted by our security team to ensure that their privacy policies and practices meet or exceed our compliance standards. Where appropriate and available, we hold additional signed Data Privacy Agreements with these companies to help ensure your data is safe and secure.
We disclose potentially personally identifying information only to our employees, contractors, and affiliated organizations that (i) need to know that information in order to process it on our behalf or to provide services, and (ii) have agreed, in writing, not to disclose it to others. Some of these employees, contractors, and affiliated organizations may be located outside of your home country; by using our websites and services, you consent to the transfer of such information to them. We will not rent or sell potentially personally identifying and personally identifying information to anyone.
We may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.
If we ever engage in any onward transfers of your data with third parties for purposes other than what it was originally collected for or subsequently authorized, we will provide you with an opt-out choice to limit the use and disclosure of your personal data.
Cookies
A cookie is a string of information that a website stores on a visitor’s computer, and that the visitor’s browser provides to the website each time the visitor returns. We use cookies across our site to help identify and track visitors, their usage of our services, and their website access preferences. We describe the specific cookies used in the sections below. Visitors who do not wish to have cookies placed on their computers should set their browsers to refuse cookies before using our websites, with the drawback that certain features may not function properly without the aid of cookies. Learn more about how engineARC uses cookies in our Cookie Declaration documentation.
Personal Data We Collect
Registered Users
- Profile Information: Your profile picture (Gravatar), display name, website (URL) (if any), and biographical info (if any) may be visible to visitors to the website (e.g., if you leave a comment, forum post, or contribute an article/post).
- Published Content: If you author an article/post, your username, user ID, profile picture (Gravatar), display name, website (URL) (if any), and biographical info (if any) are provided to any visitor using the website’s REST API interface.
- Media Uploads: If you upload media (e.g., images) to the website (in forums, posts, or comments), avoid uploading images with EXIF GPS location data included. Visitors to the website can download and extract any location data included in images on the website. Visitors using the website’s REST API interface can correlate uploaded media to a particular user, which may allow mapping a user to a particular time and location if EXIF GPS location data was included in the uploaded media.
- Comments: When visitors leave comments on our site, we collect the data shown in the comments form, as well as the visitor’s IP address and browser user agent string to help spam detection. If you leave a comment, you may opt-in to saving your name, email address, and website in cookies so we can recognize you as a commenter. These cookies will persist for one year. Additional spam detection is provided by Automattic/Akismet (Automattic privacy policy is available here).
- Cookies for Authors/Editors: If you edit or publish an article/post, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after one day.
- Data Retention: Published content and comments are stored indefinitely unless deletion/removal is requested by the original author.
Email/Chat/Contact Forms
- We use Google/G Suite to process all internal email and communication with our customers. Google’s privacy policy is available here.
- Customers that email us or use any of the contact forms on our website will have their email address, IP address, and any data provided in the contact form or body of the email stored in G Suite archives and in our help desk third-party service provider, HelpScout (HelpScout privacy policy is found here).
- We use LiveChatInc to provide live chat and live support services. Any data provided during a live chat session with one of our team members will be recorded and logged in an email sent to our HelpScout help desk. This includes your name, email address, and IP address. The LiveChatInc privacy policy is found here. LiveChatInc uses cookies to tailor chat sessions to the individual. No personal information is stored in these cookies (only visit history). Cookies expire in three years.
- We keep all email and chat communication indefinitely to help us provide support and improve our services. Individuals can request copies of any previous correspondence with us at any time.
Embedded Content From Other Websites
Embedded content from other websites may appear on our site occasionally. This content behaves as if the visitor has visited the other website and may use cookies or capture information. Typically, embedded content is from websites that share videos, images, or other content. These services may collect your IP address, user agent, store and retrieve cookies on your browser, embed additional third-party tracking, and monitor your interaction with that embedded content, including correlating your interaction with the content with your account with that service if you are logged in to that service.
Links to the privacy policies of the most common services are included below:
Analytics
- Google Analytics: We use Google Analytics for tracking visitors and aggregating information about the traffic to our website. The Google Analytics privacy policy can be found here. Learn more about how to opt-out of tracking in Google Analytics here.
- Mixpanel: We use Mixpanel to track the logged-in activity of users of engineARC. This includes profile information provided during signup. Mixpanel’s privacy policy is found here. Mixpanel uses cookies to track activity on the engineARC site. Cookies include a unique identifier tied to your engineARC account but do not include personally identifying information. Cookies expire within one year. Mixpanel, like Google Analytics, respects ‘Do Not Track’ settings that are available in modern web browsers.
- Hotjar: We use Hotjar to help us analyze and improve user experiences. You may opt-out from having Hotjar collect your information when visiting a Hotjar Enabled Site at any time by enabling Do Not Track (DNT) in your browser. Hotjar’s privacy policy is found here.
- Sentry: We use Sentry for application monitoring. Sentry’s privacy policy can be found here.
Marketing Campaigns
- Email Marketing: We use email marketing to communicate with customers and potential customers from time to time. We may also send you “system” emails, such as password reset requests or payment notifications/receipts even if you have not opted-in to email marketing lists. All marketing emails sent by us will include an unsubscribe link in the footer of the email. Emails sent to you may also include standard tracking, including open and click activities. We use a number of different services for email marketing. You can read the privacy policy of each service here: Mailjet, Airship, G2.
- Social Media and Web Advertising: We may utilize social media and web advertising campaigns. These service providers use cookies on our sites and/or pixel tracking to serve ads across the different platforms.
- Google AdSense & DoubleClick (privacy policy | opt out)
- Twitter (privacy policy | opt out)
- Facebook (privacy policy | opt out)
Paying Customers
- Business Analytics and Payment Subscription Records: For business analytics and payment subscription records for engineARC, we use Chartmogul. Chartmogul’s privacy policy can be found here. For business analytics, CRM, and subscription records of Enterprise customers, we use Hubspot. Hubspot’s privacy policy can be found here.
- Payment Transactions: For payment transactions for engineARC, we support a number of different providers. You can read the privacy policy of each here: PayPal, Stripe, Google Pay, Apple Pay, Microsoft Pay. To comply with accounting and legal requirements, we keep data on financial transactions in the systems above for up to 10 years.
Hosting and API Services
- Web Servers and Hosting: All web servers and hosting are managed by our team on the Amazon Web Services, Digital Ocean, Vultr, and Linode platforms located in different regions around the world. This includes website hosting, backups, web database, file storage, APIs, and log files. Hosting and Enterprise customers may choose which region/country their website is hosted in, and in that case, all WordPress and database files for that site will be stored in that region only. Privacy policies of our providers can be found here: Amazon, Digital Ocean, Linode, Vultr.
- Content Delivery Network (CDN): Our ‘Hummingbird’ and ‘Smush’ products and our hosting services use the Bunny Content Delivery Network (CDN). Bunny may collect anonymous web log information of site visitors, including browser name, pages visited, and points of interest on the website. Bunny may also share information with key third parties, including IP, browser user agent, browser language, and email address. Bunny’s privacy policy can be found here.
Agency Directory
Agencies interested in having a profile on our Agency Directory should provide the following information:
- Company name
- Company description
- Website link
- Logo
- Location
- Social media links (FB, LinkedIn, Instagram, and Twitter)
- The services that the agency offers
- Contact us page link
- Screenshots and links to websites completed by the agency
- The number of employees
- The project sizes the agency accepts
- The minimum project budget the agency accepts
We won’t share the agency information with third parties, although the directory is a publicly accessible page. Your agency profile may be promoted through engineARC social media channels, including Facebook, LinkedIn, Twitter, and Instagram. Agencies may request updating or removing their agency profile via our contact us page. We may, in our discretion and without liability to you, with or without prior notice and at any time, modify or discontinue, temporarily or permanently, our agency directory.
Your Rights
If you are a registered user or have left comments on our site you can request to see or download the data we have about you.
Typically for visitors that have left comments, the data will be their email address, any IP addresses assigned to them at the time of leaving the comments, and the user agent strings of the browsers they used. The rest of the data is public as published by the visitors.
For registered users or paying customers, this will also include profile information and download, payment, and support ticket histories.
You can also request “to be forgotten” and we will erase any personally identifiable data we have about you. Of course, this excludes data we need for administrative or security purposes or if we are required by law to retain some of the data.
An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data, should direct his/her query to info@enginearc.com. We will respond within a reasonable timeframe, not to exceed one week.
Protecting Your Data
The security and reliability of our service is our number one priority. We invest heavily in the training of our staff and our infrastructure to ensure that best practices are followed in everything that we do. See wordpress.org/about/security for details on the security of the WordPress core itself.
- Prevention: As a first step, we follow all WordPress Code Standards in the plugins that we build and use. In addition, we have an extensive internal review and Quality Assurance process in place specifically to prevent potential security vulnerabilities in our plugins and services.
- Staff Training and Access: Every engineARC employee and contractor goes through background checks and an onboarding process that includes a trial period where access to customer data is provided only when working directly under the supervision of another staff member. All staff only have access to systems that are directly required to complete the functions of their job. We use dual factor authentication for all critical systems and communications services, and automatically log all staff activity using an internal logging tool, Google ‘G’ Suite features, and Amazon Cloud Trail.
- Ongoing Training: All staff (including any contractors) undergo initial training to ensure proper understanding of all security-related processes. Staff regularly attend industry conferences and otherwise stay informed of best practices and relevant trends. Staff review and agree, in writing, to all policies and procedures annually.
- Third-party Services: We only use third-party services, such as Amazon Web Services, that are fully vetted and adhere to the highest levels of privacy and security practices.
Data Breach Procedures
Should any event occur where customer data has been lost, stolen, or potentially compromised, our policy is to alert our customers via email no later than 48 hours of our team becoming aware of the event. We will also report such incident to any required data protection authority. We will work closely with any customers affected to determine next steps such as any end-user notifications, needed patches, and how to avoid any similar event in the future.
Privacy Shield Frameworks
engineARC complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States. engineARC has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit privacyshield.gov.
In compliance with the Privacy Shield Principles, engineARC commits to resolve complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact engineARC at admin@incsub.com or by mail at the address at the top of this policy.
If we do not resolve your complaint, you may contact JAMS, our designated independent dispute resolution provider for Privacy Shield inquiries. You can contact JAMS, which is based in the United States, through its website at the following link: https://www.jamsadr.com/eu-us-privacy-shield
If neither engineARC nor JAMS resolves your complaint, you may, in certain circumstances, be able to seek binding arbitration through the Privacy Shield Panel. You can read more about binding arbitration in Annex I to the Privacy Shield Principles.
engineARC commits to cooperate with EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) and comply with the advice given by such authorities with regard to human resources data transferred from the EU and Switzerland in the context of the employment relationship.
Our commitments under the Privacy Shield are subject to the investigatory and enforcement powers of the United States Federal Trade Commission.
Privacy Policy Changes
Although most changes are likely to be minor, engineARC may change its Privacy Policy from time to time, and in engineARC’s sole discretion. engineARC will notify clients by email when making changes.