Effective Date: May 14, 2018
Thanks for visiting Squarespace! Squarespace (“Squarespace”, “we”, “us” or “our”) respects your privacy. When it comes to your personal information, we believe in transparency, not surprises. That’s why we’ve set out here what personal information we collect, what we do with it and your choices and rights.
1. Some key terms
If you are a User, see our Data Processing Addendum to learn more about how we process User Content on your instructions or with your permission.
3. Personal information we collect
We collect various personal information regarding you or your device. This includes the following:
4. How we collect personal information
We obtain personal information from various sources. We do this in three main ways:
We’ve described this in more detail below.
a. Personal information you provide
When you use our Services, we collect information from you in a number of ways. For instance, we ask you to provide your name and email address to register and manage your Account. We also maintain your marketing preferences and the emails and other communications that you send us or otherwise contribute, such as customer support inquiries or posts to our customer message boards or forums. You might also provide us with information in other ways, including by responding to surveys, submitting a form or participating in contests or similar promotions.
Sometimes we require you to provide us with information for contractual or legal reasons. For example, we may ask you to select your jurisdiction when you sign up for Paid Services to determine if, and how much, tax we need to collect from you. We’ll normally let you know when information is required, and the consequences of failing to provide it. If you do not provide personal information when requested, you may not be able to use our Services if that information is necessary to provide you with the service or if we are legally required to collect it.
b. Personal information obtained from your use of our Services
When you use our Services, we collect information about your activity on and interaction with the Services, such as your IP address(es), your device and browser type, the web page you visited before coming to our sites, what pages on our sites you visit and for how long and identifiers associated with your devices. If you’ve given us permission through your device settings, we may collect your location information in our mobile apps.
If you are an End User of our Users’ sites, we also get information about your interactions with their sites, though we use this in anonymous, aggregated or pseudonymized form which does not focus on you individually. We use this data to evaluate, provide, protect or improve our Services (including by developing new products and services).
c. Personal information obtained from other sources
If you use a Third Party Service (such as Google) to register for an Account, the Third Party Service may provide us with your Third Party Service account information on your behalf, such as your name and email address (we don’t store passwords you use to access Third Party Services). Your privacy settings on the Third Party Service normally control what they share with us. Make sure you are comfortable with what they share by reviewing their privacy policies and, if necessary, modifying your privacy settings directly on the Third Party Service.
5. How we use your personal information
We use the personal information we obtain about you to:
We process your personal information for the above purposes when:
6. How we share your personal information
We share personal information in the following ways:
7. Your rights and choices
Where applicable law requires (and subject to any relevant exceptions under law), you may have the right to access, update, change or delete personal information.
You can access, update, change or delete personal information (or that of your End Users) either directly in your Account or by contacting us at firstname.lastname@example.org to request the required changes. You can exercise your other rights (including deleting your Account) by contacting us at the same email address.
You can also elect not to receive marketing communications by changing your preferences in your Account or by following the unsubscribe instruction in such communications.
Please note that, for technical reasons, there is likely to be a delay in deleting your personal Information from our systems when you ask us to delete it. We also will retain personal Information in order to comply with the law, protect our and others’ rights, resolve disputes or enforce our legal terms or policies, to the extent permitted under applicable law.
You may have the right to restrict or object to the processing of your personal information or to exercise a right to data portability under applicable law. You also may have the right to lodge a complaint with a competent supervisory authority, subject to applicable law. If you are subject to EU data protection laws, we suggest you lodge any such complaints with our lead supervisory authority:
Irish Data Protection Commissioner
Office of the Data Protection Commissioner
Canal House, Station Road, Portarlington, Co. Laois, R32 AP23, Ireland
Phone +353 57 868 4757
Fax: +353 57 868 4757
Additionally, if we rely on consent for the processing of your personal information, you have the right to withdraw it at any time and free of charge. When you do so, this will not affect the lawfulness of the processing before your consent withdrawal.
If you are an End User of one of our User’s sites, you should contact them to exercise your rights with respect to any information they hold about you.
8. How we protect your personal information
While no service is completely secure, we have a security team dedicated to keeping personal information safe. We maintain administrative, technical and physical safeguards that are intended to appropriately protect against accidental or unlawful destruction, accidental loss, unauthorized alteration, unauthorized disclosure or access, misuse and any other unlawful form of processing of, the personal information in our possession. We employ security measures such as using firewalls to protect against intruders, building redundancies throughout our network (so that if one server goes down, another can cover for it) and testing for and protecting against network vulnerabilities.
9. How we retain your personal information
The precise periods for which we keep your personal information vary depending on the nature of the information and why we need it. Factors we consider in determining these periods include the minimum required retention period prescribed by law or recommended as best practice, the period during which a claim can be made with respect to an agreement or other matter, whether the personal information has been aggregated or pseudonymized, and other relevant criteria. For example, the period we keep your email address is connected to how long your Account is active, while the period for which we keep a support message is based on how long has passed since the last submission in the thread.
As Users may have a seasonal site or come back to us after an Account becomes inactive, we don’t immediately delete your personal information when your trial expires or you cancel all Paid Services. Instead, we keep your personal information for a reasonable period of time, so it will be there for you if you come back.
Please note that in the course of providing the Services, we collect and maintain aggregated, anonymized or de-personalized information which we may retain indefinitely.
10. Data transfers
Personal information that you submit through the Services may be transferred to countries other than where you live, such as, for example, to our servers in the U.S. We also store personal information locally on the devices you use to access the Services.
Your personal information may be transferred to countries that do not have the same data protection laws as the country in which you initially provided the information.
We rely upon a number of means to transfer personal information which is subject to the European General Data Protection Regulation (“GDPR”) in accordance with Chapter V of the GDPR. These include:
You can find out more information about these transfer mechanisms here.
11. Privacy Shield
Squarespace, Inc has certified its compliance to the Privacy Shield.
Squarespace is committed to treating personal information received from the European Economic Area and Switzerland pursuant to the Privacy Shield Frameworks in accordance with the applicable Principles. You can find our certification hereand you can learn more about the Frameworks and Principles by visiting https://www.privacyshield.gov/.
If you have a question or complaint you believe to be within the scope of our Privacy Shield certification, please contact us first at email@example.com, or using the contact details in the “How to contact us” section below. We'll respond within 45 days.
For any complaints that we can’t resolve directly, JAMS is the independent organization responsible for reviewing and resolving complaints about our Privacy Shield compliance. You can contact JAMS free of charge at https://www.jamsadr.com/eu-us-privacy-shield. JAMS is an alternative dispute resolution provider based in the U.S.
If your concern still isn't addressed by JAMS, you may be entitled to a binding arbitration under the Privacy Shield Principles. For purposes of enforcing compliance with the Privacy Shield, Squarespace, Inc. is subject to the investigatory and enforcement authority of the U.S. Federal Trade Commission.
12. End Users’ personal information
Our customers who have created a site using Squarespace are responsible for what they do with the personal information they collect, directly or through Squarespace, about their End Users. This section is directed to such customers.
a. Your relationship with End Users
You're solely responsible for complying with any laws and regulations that apply to your collection and use of your End Users’ information, including personal information you collect about them from us or using Squarespace functionality or cookies or similar technologies.
We’re not liable for your relationship with your End Users or how you collect and use personal information about them (even if you collect it from us or using Squarespace functionality or cookies or similar technologies) and we won’t provide you with any legal advice regarding such matters.
b. End User payment information
Your End Users’ payment information may be processed via third party eCommerce Payment Processors with which you integrate your Account, in accordance with such eCommerce Payment Processors’ terms and policies. We transmit your End Users’ complete payment information when they initially provide or update it only so that we can pass it along to the eCommerce Payment Processors you agree to use. We don’t collect or store your End Users’ payment information.
14. Who is Squarespace?
When we say “Squarespace” (or “we”, “us” or “our”), we mean: (a) Squarespace, Inc. if you are a resident of or have your principal place of business in the United States of America or any of its territories or possessions (the “US”); or (b) Squarespace Ireland Limited, in any other case.
If your place of residence or principal place of business changes, the Squarespace entity that controls your personal information will be determined by your new residence or principal place of business from the date it changes.
15. How to contact us
If you are a resident of or have your principal place of business in the US:
Attention: Legal - Privacy
225 Varick Street, 12th Floor
New York, NY 10014 United States
If you are a resident of or have your principal place of business anywhere other than the US:
Squarespace Ireland Ltd.
Attention: Legal - Privacy
Le Pole House, 1st Floor
Ship Street Great
Dublin 8 Ireland