AT EQ LABS, WE BELIEVE THAT YOUR PRIVACY IS A FUNDAMENTAL RIGHT.

Privacy Policy

This Privacy Policy describes the kinds of information we collect and how we use and disclose it effective as of the date posted below.

Your Acceptance of this Privacy Policy

By accessing our website or using the services, you consent to our collection, storage, use, and disclosure of your information as described in this Privacy Policy. The provisions contained in this Privacy Policy supersede all previous notices and statements regarding our privacy practices with respect to the services. If you do not agree to every provision of this Privacy Policy, you may not access or use the services.

Information collected and how it is used.

“Personal Information” is any information that enables us to identify you, directly or indirectly, such as your email address, name, shipping and billing address, telephone number, company name, credit card information, any form of identification number or one or more factors specific to your physical, physiological, mental, economic, cultural or social identity. We collect information, including personal information, that you submit when using our website or services and automatically collect information when you interact with us. This includes the following:

Your email address.

When you sign up for an account, either through the web application or the mobile app, we collect and store your email address. We use email addresses to map managers to their team-members, so that we can survey team members on how their managers are doing at adopting more inclusive practices. If we received a complaint about a specific user (through the “Help” interface within the app, or through email or chat), we might be under a legal obligation to share the details of that complaint with your HR department. This is the only case when we would break the confidentiality of your use of EQ Labs tools. We also use your email address to notify you of any changes to our policies.

Your calendars and calendar events.

Every five minutes, the EQ Labs servers will connect to the Google APIs and check for any events that might be starting in the next ten minutes. If you have an event starting that has other participants, we’ll send you a “nudge” notification of a practice you could use. We store the plain IDs (usually the same as your email address) of your calendars so that we can save having to call the Google API to get your list of calendars over and over again. When we send you a nudge, we store the plain ID of the event (a meaningless string like: “cs1rvmhcjth7logas89f462955_20200511T210000Z”) so that we can make sure we don’t accidentally send you the same nudge twice. If any of the attendees of that event are also EQ Labs users (like your manager or your team members), we store their email address, so that we can survey them after the meeting. We also save the ending time of the meeting, so that we know when to send out that survey. We don’t store any other information about the event - we don’t store the title or location or notes.

Your cell phone number.

If you decide you’d like to receive notifications by SMS, we will store your cell phone number within your account record. This is used only to send you recommended practices or survey links, and not for any other purpose. You can disable it at any time from within the mobile app or the web interface. Your device token. By default, we will send practice nudges via push notification to your mobile device. We do this by storing an opaque token - it does not provide any information on your device ID or location, but it does indicate whether your device is an IOS or Android phone. You can disable this at any time within the mobile app, from the web interface, or through your mobile device settings.

Your activities within the mobile applications.

When you’re using the mobile app, we measure which screens you’re looking at and for how long. This is so we can tell which parts of the app are getting used, and also to troubleshoot any bugs. We record when you watch training videos, so that we know which practices should be enabled. And we record when you commit to trying out a practice, so we know whether to survey folks on how it went. We also record when you decline a practice, so we can try and suggest practices that are more relevant for you. Based on those activities, we also give “badges” and awards.

Your activities within the web applications.

Aside from ordinary web server logs (which contain IP addresses and not usually account IDs), we also record account IDs for when you’re using the browser plugins. This helps us see whether the browser plugins are also contributing to improvements in behavior, and which categories of users prefer which types of tools.

Additional personal information.

If you are involved in a corporate pilot, you might agree to an additional privacy policy that covers demographic information, including gender identity and ethnic origin. This information would be used for quantitative analysis of the effectiveness of different practices in different contexts and would be combined with the information covered here only after it had been tokenized and anonymized.

Additional uses.

We may use personal information for the purposes described elsewhere in this Privacy Policy and internally for our general legitimate commercial and research purposes, including, among other things, to provide the services and information you have requested from us and notices related thereto; verify that you qualify as a registered user of the website or services; analyze, improve, and customize the services; provide customer and technical support for the services; send you announcements, newsletters, promotional materials, and other information about the services and third-party products and services that we think may be of interest to you provided you have given consent if required by law; enforce or apply our agreements with you or others; contact you as necessary; detect, prevent, and investigate actual or suspected fraud, hacking, infringement, or other misconduct involving the website or the services; collect fees and other amounts owed in connection with the services; administer the website and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes; improve the website and to customize the content you see on the website; keep the website safe and secure; measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you; and do internal research on our website visitors’ interests and behaviors to better understand and serve our members.

Cookies and similar technologies.

We use cookies and similar technology to collect aggregate (non-personal) information about website and application usage by all of our visitors and to help us remember you and your preferences. These cookies may stay on your browser into the future until they expire or you delete them. We also use technology that helps our website and application function. These cookies usually are erased when you close your browser window. Further general information about cookies and how they work is available at www.allaboutcookies.org. We may allow selected third parties to place cookies through the website to provide us with better insights into the use of the site or user demographics or to provide relevant advertising to you. These third parties may collect information about a consumer’s online activities over time and across different websites when he or she uses our website. We may also permit third party service providers to place cookies through our Site to perform analytic or marketing functions where you are notified of them and you have consented to the usage. We do not control the use of such third party cookies or the resulting information and we are not responsible for any actions or policies of such third parties.

Do Not Track Signals.

We do not currently use technology that recognizes a “do-not-track” signal from your web browser.

Data Processing and Storage

All of your authentication and application data is stored in the “Google Firestore” database. Access to this data is limited to yourself (as managed by the Firebase Authentication service) and the EQ Labs servers (as managed by a set of Google API Oauth credentials). Mobile app usage data is captured using Firebase Analytics. Web access data is captured using Mixpanel and Google Analytics. Web server logs may also be captured by Heroku, Netlify and Microsoft Azure CDN. We have made every effort to limit the amount of personal data that could be exposed in the web server logs, but they do contain IP addresses.

Cross-Border Data Transfers

Our website is maintained on servers located in the United States, and personal information submitted is stored on our servers in the United States. If you are visiting our website from outside the United States, please be advised that your information is transferred to our U.S. servers. Disclosing your personal information to us pursuant to this Privacy Policy is at your own risk. We strive to comply with laws of jurisdictions in which we maintain operations but we make no representations that the practices described in this Privacy Policy are compliant with laws outside those jurisdictions that apply to the collection, security, use and disclosure of personal information.

Security.

We use reasonable technical, administrative and physical measures to protect information contained in our system against misuse, loss or alteration. All of EQ Labs services use SSL certificates, so all data is encrypted in transit. Firestore uses a securely encrypted backend. Anonymous usage data might be stored in plain text in one of the analytic company datastores.

Your Choices and Accessing your Information.

Communications from us.

You can choose not to receive emails from us by “unsubscribing” using the instructions in any email you receive from us. This will not stop us from sending emails about your account or your transactions with us. You can unsubscribe from receiving text messages from us by replying STOP to any text and receive one final confirming message.

Cookies.

You can choose to delete or block cookies by setting your browser to either reject all cookies or to allow cookies only from selected sites. If you block cookies performance of the Site may be impaired and certain features may not function at all.

Deleting your account.

If you choose to delete your account, we delete all of your information. This does not include the answers to survey questions that were sent to your team members, since that is also their information.

Updating your Information.

You can update, amend or delete your information at any time by logging into your account to make the change.

Disclosing your Information.

We may reveal information about you to unaffiliated third parties: (1) if you request or authorize it; (2) if the information is provided to help complete a transaction for you; (3) if the information is provided to comply with the law, applicable regulations, governmental and quasi-governmental requests, court orders or subpoenas, to enforce our Terms of Use or other agreements, or to protect our rights, property or safety or the rights, property or safety of our users or others (e.g., to a consumer reporting agency for fraud protection etc.); (4) if the disclosure is done as part of a purchase, transfer or sale of services or assets (e.g., in the event that substantially all of our assets are acquired by another party, customer information may be one of the transferred assets); (5) if the information is provided to our agents, outside vendors or service providers to perform functions on our behalf (e.g., analyzing data, providing marketing assistance, providing customer service, processing orders, etc.); or (6) as otherwise described in this Privacy Policy.

We may disclose your non-private, aggregated or otherwise de-identified information to our affiliates and third parties.

We do not share your information with third parties for their marketing purposes.

Children’s Privacy.

Our website and application are not designed nor intended to be attractive to use by children under the age of 13. We do not knowingly collect information from children under the age of 13. If you are under 13 please do not submit any information to us.

Links to Other Websites.

We may permit others to link to this Site or to post a link to their site on ours. We do not endorse these sites and are not responsible for other sites or their privacy practices. Please read their privacy policies before submitting information.

California Consumer Privacy Act Notice.

Currently EQ Labs is not required to comply with the California Consumer Privacy Act (CCPA). When we are we will post a CCPA notice here.

Notice to visitors from Nevada.

We do not transfer personal information for monetary consideration. If you would like to tell us not to sell your information in the future please email us at discovery@eqlabs.io with your name, postal address, telephone number and email address with “Nevada do not sell” in the subject line.

Notice to European Union Residents.

For individuals within the European Economic Area only. Under the GDPR, in certain circumstances, you have the right to: (a) request access to any personal information we hold about you and related information, (b) obtain without undue delay the rectification of any inaccurate personal information, (c) request that your Personal Information is deleted provided the personal information is not required by EQ Labs for compliance with a legal obligation under European or Member State law or for the establishment, exercise or defense of a legal claim, (d) prevent or restrict processing of your personal information, except to the extent processing is required for the establishment, exercise or defense of legal claims; and (e) request transfer of your personal information directly to a third party where this is technically feasible. In addition, where you believe that EQ Labs has not complied with its obligation under this Privacy Policy or European law, you have the right to make a complaint to an EU Data Protection Authority.

For the purposes of the European Union General Data Protection Regulation 2016/679, (GDPR) the data controller is EQ Labs, Inc., 4326 3rd Ave NW, Seattle, WA 98107.

Changes to the Privacy Policy.

As we grow and change, we may amend this Privacy Policy. The Policy in effect at the time you use the website or the service governs how we may use your information. If we make material changes we will post the revised Policy and the revised effective date on this site. Please check back here from time to time to review any changes.

Contacting Us.

EQ Labs commits to resolve questions or complaints about your privacy and our collection or use of your personal information. European Union residents with inquiries or complaints regarding this privacy policy should first contact EQ Labs at:

Chief Privacy Officer
EQ Labs, Inc.
4326 3rd Ave NW
Seattle, WA 98107

EFFECTIVE DATE: May 13th, 2020.