Introduction
Gleam ("Gleam", "we" or "us") provides software that helps online businesses (our "Customers") run engaging marketing campaigns that are promoted to customers ("Campaign Users").
Security & Privacy is an important part of our platform that we take very seriously. Therefore, this Privacy Policy governs the manner in which Gleam collects, uses, maintains and discloses information collected from users (each, a "User") of the https://gleam.io website ("Site"). This privacy policy applies to the Site and all products or services offered by Gleam.
In order to ensure confidentiality and lawful processing of its, Visitors, Customers and Campaign Users personal data, Gleam in its capacity of a data controller and of a processor, conducts its activities in strict compliance with the requirements set in the Australia Privacy Act 1988, Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of this data (GDPR) and the California Consumer Privacy Act (CCPA).
This Privacy Policy applies to all Customers, Campaign Users and Visitors of our Site and Services.
What Information We Collect and How We Use It
We may collect the following types of information about you on our Website.
Customers and Visitors of our Site
Gleam Campaign Users


Cookies
Our Site uses both first and third party Cookies to enhance User experience. A User's web browser places a cookie on their hard drive for record-keeping purposes and sometimes to track information about them. Users may choose to set their web browser to refuse cookies, or to alert when cookies are being sent. If they do so, please note that some parts of the Site and Campaigns may cease to function.
Gleam Campaigns use Cookies to track information about users in order to serve them content. This includes but is not limited to:
Persist Customers sessions that are logged into Gleam
Persist Campaign Users sessions that are logged into campaigns (either on Gleam.io or embedded via iFrames)
Tracking and awarding credit for referring users via our Viral Share Action
Tracking browser behaviours to show Capture campaigns
Tracked users referred by our Referral Program
Device Fingerprinting
Device fingerprinting is a process by which a fingerprint of a device is captured when visiting a website.
Gleam uses 3rd party services to gather a number of data points from a Gleam Campaign Users computer, such as operating system version, browser version, screen resolution, plug-ins & language. This unique ID is then transmitted when Gleam Campaign Users consent by providing their details when entering a campaign.
The information collected via Device Fingerprinting is used to identify patterns of fraudulent behaviour by Gleam Campaign Users that violate our Terms of Service. This includes trying to cheat by creating multiple accounts, referring your own devices or accounts into a Campaign or attempting to redeem a Reward that is limited to one per person.
Gleam does not use this information to track or identify users on sites or apps not owned by Gleam or for any other purpose than to detect fraud & protect the integrity of Campaigns, nor do we use the gleam.io or js.gleam.io domains to fingerprint on 3rd party domains.
How We Use Collected Information
Gleam may collect and use User's personal information for the following purposes:
Gleam Website Users
Gleam Campaign Users
Sharing Information With Third Parties
We do not access, sell, trade, or rent Users personal identification information to others. Once you provide access to specific data it belongs to the Customer running that specific Campaign and only that Customer. We urge you to review the Terms & Conditions and Privacy Policy of the Campaign Owner to understand how they may use your data once it leaves Gleam.
To guarantee the legality of any transfer of personal data of EEA or Swiss citizens to sub-processors located outside the EEA or Switzerland, Gleam applies additional terms via our Data Processing Agreement.
Customers and Visitors of our Site
Gleam Campaign Owners
Third Party Websites
Legal Disclosures
Information Security
We use appropriate technical and organizational security measures to protect any personal information we process about visitors to our Website against unauthorized access, disclosure, alteration, and destruction. However, please note that no Internet transmission can ever be guaranteed 100% secure, and so we encourage you to take care when disclosing personal information online and to use readily available tools, such as Internet firewalls, secure e-mail and similar technologies to protect yourself online.
Sensitive and private data exchange between the Site and its Users happens over an SSL secured communication channel and is encrypted and protected with digital signatures. All user data is encrypted at rest using industry standard AES-256 encryption.
Gleam uses Stripe to process our credit card payments and no credit card details are stored on our servers. Stripe has been audited by a PCI-certified auditor, and is certified to PCI Service Provider Level 1. This is the most stringent level of certification available.
In case of an unauthorized security intrusion that materially affects you or the people on your mailing list Gleam will notify you as soon as possible and will within reasonable time report the action we took in response.
Reporting Security Issues
EU and EEA residents
The servers where Gleam stores all personal data are located in the US. If you are located in a country member of either the EU or the EEA, please be aware that any information provided to us, including personal information, will be transferred from your country of origin to the US. Except in the case of data transfers under the EU-US Privacy Shield and the Swiss-US Privacy Shield, we may ask for your express consent to provide such data to us or allow us to collect such data.
International Transfer of Personal Data
All personal data we process is stored directly, without any subsequent transfers, on US-based servers, which we loan from a third-party datacenter that is certified and adheres to the EU – U.S Privacy Shield Framework.
To additionally guarantee to our Customers and their European Campaign users (data subjects) the legality of our processing services and the international transfers of the personal data, Gleam has undertaken GDPR compliant contractual commitments, binding us, as a data processor, to protect the data privacy and to ensure the most adequate level of data security.
Please note that the country where we operate may have privacy and data protection laws that differ from, and are potentially less protective than, the laws of your country. You agree to this risk when you create an account with Us and click "I accept Gleam's Terms of Service & Privacy Policy" to data transfers, irrespective of which country you live in. If you later wish to withdraw your consent, you can delete your Gleam account as described in the "Your Rights" section.
Data Processing Agreement
Data Retention Periods
Privacy Controls & Choices
Gleam's Data Protection Officer
California Consumer Privacy Act
For our users or customers living or doing business in California, Gleam is subject to the California Consumer Privacy Act ("CCPA").
Gleam Does Not Sell Your Personal Information. You can read more about this in our Sharing Information With Third Parties section.
Cookie Policy. You can learn about this in our Cookies section.
Accuracy and Access To Your Personal Information. If you believe that Personal Information Gleam holds about you is inaccurate, you may modify or correct your Personal Information the Edit tab for Gleam Campaign Users, the User Settings tab for Gleam Customers or by contacting us at: privacy@gleam.io. We may request specific information from you to confirm your identity.
Deleting Your Personal Information. You can learn about this in our Privacy Controls & Choices section.
Compliance With Children's Online Privacy Protection Act
Because the nature of our Site and Services does not appeal to children under the age of 13, Gleam does not knowingly acquire or receive personal data from children under 13. We do not intentionally process any information, including Personal Data, from children or other individuals who are not legally able to use our Site and Services. If we later learn that any user of our Service is under the age of 13 and that we have obtained his/her Personal Data, we will promptly delete it from our database and will take further steps to restrict that individual from future access to our Services, unless we are legally obligated to retain such data.
If you are a parent or legal guardian of a child under 13 and believe that we might have any information from or about such child, please contact us at the email or mailing address provided at the end of this Privacy Policy
Business Transfers
In some cases, we may choose to buy or sell assets. In these types of transactions, customer information is typically one of the business assets that are transferred. Moreover, if Gleam, or substantially all of its assets were to be acquired, or in the unlikely event that Gleam goes out of business or enters bankruptcy, customer information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, and that any acquire of Gleam or its assets may continue to use your Personal Information as set forth in this policy.
Changes To This Privacy Policy
Gleam has the discretion to update this privacy policy at any time. When we do, we will revise the updated date at the bottom of this page. We encourage Users to frequently check this page for any changes to stay informed about how we are helping to protect the personal information we collect. You acknowledge and agree that it is your responsibility to review this privacy policy periodically and become aware of modifications.
Your Acceptance Of These Terms
By using this Site, you signify your acceptance of this policy and terms of service. If you do not agree to this policy, please do not use our Site. Your continued use of the Site following the posting of changes to this policy will be deemed your acceptance of those changes.
Contacting Us
If you have any questions about this Privacy Policy, the practices of this site, or your dealings with this site, please contact us at privacy@gleam.io