Privacy Policy
Roots Natural Kitchen Privacy Policy
This “Privacy Policy” will explain how Roots HoldCo, LLC, Roots OpCo, LLC, and their affiliates, collectively Roots Natural Kitchen (“Roots,” “our brand,” “we,” or “us”) processes the personal data we collect from you when you interact with our brand via ordering in our store or utilizing our website, mobile app, social media platforms, or other digital platforms, and the rights and choices available to you with respect to your information.
Table of Contents
- What data do we collect?
- How do we collect your data?
- How will we use your data?
- How long will we retain your data?
- How will we share your data?
- Your Choices
- What are Cookies?
- How do we use cookies?
- What types of cookies do we use?
- How to manage cookies
- International data transfer
- Security practices
- Children
- Other sites and services
- Changes to our privacy policy
- How to contact us
- State privacy rights notice
What data do we collect?
Our company collects personal information, cookie data, and/or device data you either directly or indirectly provide to us through interaction with our brand or from other sources, including third parties. Such data includes:
- Contact data, such as your first and last name, email address, mailing/delivery addresses and phone number.
- Profile data, such as username and password that you use to create an online account with us, as well as information you provide to complete your customer profile, such as your birthday.
- Order data, such as which products you purchased, which locations you purchased from, and on what dates and times you placed orders with us.
- Transactional data, such as an anonymized token that is passed through our credit card processing system to enable your bank or credit card company to charge your card upon placing an order.
- Communications records, such as when you reach out to our customer service representatives, request IT support, write a review, or engage with us on social media.
- Marketing data, such as your contact preferences for receiving marketing and brand communications from us or on our behalf, which designated marketing area you reside in, how you engage with our digital media and with our brand on social media platforms, and information you’ve provided to us to complete your marketing profile, complete a survey, or enter a contest, giveaway or sweepstakes.
- Demographic data about your age and gender preferences.
- Device data, such as what computer or mobile device and which operating systems you are using when you interact with our brand.
- Usage data, such as your IP address and cookie data from other websites you visited prior to visiting Roots’ website.
- Online activity data, such as the webpage(s) you visited with on our website, the date, time and length of your visit, and in which order you visited multiple pages on our website.
- Communication interaction data such as your interactions with our email, text or other communications (e.g., whether you open and/or forward emails) – we may do this through use of pixel tags, which may be embedded invisibly in our emails.
- Geolocation data, when you enable our mobile application to access your location.
- Other information that is not specifically detailed above which will be used in accordance with this Privacy Policy or as otherwise disclosed at time of collection.
How do we collect your data?
You directly provide Roots with most of the data we collect at such times as when you:
- Register or place an order online or through our mobile app
- Voluntarily complete a customer survey or provide feedback on any of our message boards or via email
- Use or view our website via your browser’s cookies
We also collect data from third parties, such as social media platforms, third-party delivery services, or our loyalty platform, Thanx.
How will we use your data?
Roots collects your data so that we can use it for the following purposes or as otherwise described to you at the time of collection:
- Service delivery and operations, including:
- Provide, operate, maintain and improve the website and mobile application
- Process and fulfill your order(s) and any related payments
- Create and administer your account
- Provide, operate, and improve our products, services, user experience, and brand aesthetic
- Address you with messages and special offers, including offers we think you might like, delivered via email, digital media, mobile app push notification marketing, and/or text messages
- Marketing and advertising, including:
- Research new and existing market opportunities
- Serve you with interest-based advertisements
- Research and development, including creating aggregated, de-identified and/or anonymized data from personal information we collect
- Compliance and protection, including:
- Protect our, your or other’s rights, privacy, safety or property (including by making and defending legal claims)
- Audit our internal processes for compliance with legal and contractual requirements and internal policies
- Enforce our Terms of Use
- Protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft
- Comply with applicable laws, lawful requests and legal process, such as to respond to subpoenas or requests from government authorities; and
- With your consent. For other purposes with your consent.
How long will we retain your data?
We generally retain personal information to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements, to establish or defend legal claims, or for fraud prevention purposes. To determine the appropriate retention period for personal information, we may consider factors such as the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.
When we no longer require the personal information we have collected about you, we may either delete it, anonymize it, or isolate it from further processing.
How will we share your data?
We do not share your information with third parties without your consent, except in the following circumstances or as described in this Privacy Policy:
- Affiliates. We may disclose your personal information to our subsidiaries and corporate affiliates for use consistent with this Privacy Policy.
- Business transferees. We may sell, transfer or otherwise share some or all of our business or assets, including your personal information, in connection with a business transaction (or potential business transaction) such as a corporate divestiture, merger, consolidation, acquisition, reorganization or sale of assets, or in the event of bankruptcy or dissolution.
- Service providers. We may share your personal information with third party companies and individuals that provide services on our behalf or help us operate our website and mobile application (such as customer support, hosting, analytics, email delivery, marketing, and database management services).
- Merchant Payment Processors. We may share your personal information with third party companies that process credit card transactions on our behalf, currently Toast Inc. and Stripe Inc.
- Business and marketing partners. We may share your personal information with our business partners, such as our delivery partners (including, but not limited to, Uber Eats, DoorDash, GrubHub and Postmates) and our loyalty partner (currently, Thanx).
- Advertising partners. We work with third-party advertising partners to deliver advertising and personalized content to you on the website and mobile application, on other sites and services you may use, and across other devices you may use.
- Professional advisors. We may disclose your personal information to professional advisors, such as lawyers, bankers, auditors and insurers, where necessary in the course of the professional services they render to us.
- Authorities and others. We may disclose your personal information as we believe appropriate to government or law enforcement officials or private parties (a) for the compliance and protection purposes described above; (b) as required by law, lawful requests or legal process, such as to respond to subpoenas or requests from government authorities; (c) where permitted by law in connection with any legal investigation; and (d) to prosecute or defend legal claims.
Your Choices
In this section, we describe the rights and choices available to all users. Users who are located in certain states, including Virginia, can find additional information about their rights below.
Access or update your information. If you have registered for an account with us, you may review and update certain personal information in your account profile by logging into the account, or by contacting us at feedback@rootsnk.com or via our Reach Us form, linked here.
Marketing. Roots would like to send you information about products and services of ours that we think you might like, as well as those of our partner companies:
- Third-party delivery services (including but not limited to Uber Eats, DoorDash, GrubHub, and Postmates)
- Our third-party loyalty provider, Thanx
If you have agreed to receive marketing, you may always opt out at a later date.
You have the right at any time to stop Roots from contacting you for marketing purposes; provided, however, that you may continue to receive service-related and other non-marketing emails.
If you no longer wish to be contacted for marketing purposes, please contact us at feedback@rootsnk.com or via our Reach Us form, linked here.
Opt-out of communications. You may opt-out of marketing-related emails by following the opt-out or unsubscribe instructions at the bottom of the email, or by contacting us. Please note that if you choose to opt-out of marketing-related emails, you may continue to receive service-related and other non-marketing emails.
Advertising choices. You can limit use of your information for interest-based advertising by:
- Mobile device settings. Using your mobile device settings to limit use of the advertising ID associated with your mobile device for interest-based advertising purposes.
- Platform settings. Using Google’s and Facebook’s interest-based advertising opt-out features:
- Google: https://adssettings.google.com/
- Facebook: https://www.facebook.com/about/ads
- Ad industry tools. Opting out of interest-based ads from companies participating in the following industry opt-out programs:
- Network Advertising Initiative: https://thenai.org/opt-out/
- Digital Advertising Alliance: optout.aboutads.info, which lets you opt-out of interest-based ads on websites.
The opt-out preferences described above must be set on each device for which you want them to apply. Not all companies that serve interest-based ads participate in the ad industry opt-out programs described above, so even after opting-out, you may still receive some cookies and interest-based ads from other companies. If you opt-out of interest-based advertisements, you will still see advertisements online but they may be less relevant to you.
Mobile location data. You can disable our access to your device’s precise geolocation in your mobile device settings.
Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” or similar signals. To find out more about “Do Not Track,” please visit https://allaboutdnt.com/.
Declining to provide your personal information. If you do not provide information indicated as required or mandatory, or that is otherwise necessary to provide a requested service or feature, that portion or all of our services may be unavailable to you and we may deactivate your account.
Delete your content or close your account. You can choose to delete certain content through your account. If you wish to request to close your account, you can request to do so through the app by navigating to the “Account” page and selecting “Delete Account” or by contacting us at feedback@rootsnk.com or via our Reach Us form, linked here.
What are Cookies?
Cookies are text files placed on your computer to collect standard internet log information and visitor behavior information. When you visit our websites, we may collect information from you automatically through cookies or similar technology, such as SDKs (software development kits), which enable third-party partners to collect data directly from our mobile application used to facilitate online advertising. For further information, visit www.allaboutcookies.org.
How do we use cookies?
In addition to the other uses outlined in the “How will we use your data?” section, Roots may use cookies and other similar technologies for:
- Gauging your interest in our product and services
- Determining which users might be interested in receiving advertising and marketing communications in the form of digital media
- Keeping you signed in
- Understanding how you engage with our website
- Utilizing user behavior statistics to improve our website functionality
What types of cookies do we use?
There are a number of different types of cookies, however, the Roots website uses:
- Functionality – Roots uses these cookies so that we recognize you on our website and remember your previously selected preferences. These could include what language you prefer and location you are in. A mix of first-party and third-party cookies are used.
- Advertising – Roots uses these cookies to collect information about your visit to our website, the content you viewed, the links you followed and information about your browser, device, and your IP address. Roots may share some limited aspects of this data with third party partners for advertising purposes. We may also share online data collected through cookies with our advertising partners. This means that when you visit another website, you may be shown an advertisement based on your browsing patterns on our website.
- Analytics – To help us understand user activity on the Service, including which pages are most and least visited and how visitors move around the Service, as well as user interactions with our emails. For example, we use Google Analytics for this purpose. You can learn more about Google Analytics and how to prevent the use of Google Analytics relating to your use of our sites here: https://tools.google.com/dlpage/gaoptout?hl=en.
How to manage cookies
You can set your browser not to accept cookies, and the above website tells you how to remove cookies from your browser. Please note, however, in a few cases, some of our website features may not function as a result of disabling cookies. Additionally, you may be able to use privacy browsers and/or ad-blocking browser plug-ins that let you block tracking technologies. For more information, please see “Your Choices.”
International data transfer
We are headquartered in the United States and have service providers in other countries, and your personal information may be transferred to the United States or other locations outside of your state, province, or country where privacy laws may not be as protective as those in your state, province, or country.
Security practices
The security of your personal information important to us. We take a number of organizational, technical and physical measures designed to protect the personal information we collect, both during transmission and once we receive it. However, no security safeguards are 100% secure and we cannot guarantee the security of your information.
Children
We do not knowingly collect any information from children under the age of 16. If a parent or legal guardian becomes aware that his or her child has provided us with any personally identifiable information without such parent’s or legal guardian’s consent, he or she should contact us at feedback@rootsnk.com. If we become aware that a child under 16 has provided us with any personally identifiable information, we will promptly delete such information and the child’s account.
Other sites and services
The Roots website and mobile application may contain links to other websites and services operated by third parties, such as social media platforms, advertising services and other websites and applications. These links are not an endorsement of, or representation that we are affiliated with, any third party. We do not control third party websites, applications or services, and are not responsible for their actions. Other websites and services follow different rules regarding their collection, use and disclosure of your personal information. We encourage you to read their privacy policies to learn more.
Changes to our privacy policy
We reserve the right to modify this Privacy Policy at any time. We encourage you to periodically review this page for the latest information on our privacy practices. If we make material changes to this Privacy Policy we will notify you by email (if you have an account linked to a valid email address) or another manner that we believe is reasonably likely to reach you.
Any modifications to this Privacy Policy will be effective upon our posting of the new terms and/or upon implementation of the new changes (or as otherwise indicated at the time of posting). In all cases, your continued use of the website and/or the mobile application after the posting of any updated Privacy Policy indicates your acceptance of the update.
How to contact us
If you have any questions about Roots’ privacy policy, or the data we collect, please do not hesitate to contact us via email at feedback@rootsnk.com, our Reach Us form linked here, phone at (434) 465-2811, or mail Roots at 935 2nd St SE, Charlottesville, VA 22902, USA.
State privacy rights notice
This section provides additional information to residents about their rights pursuant to state privacy laws, including under the Virginia Consumer Data Protection Act (“CDPA”) and other applicable laws (collectively the “State Privacy Laws”).
This section describes how we collect, use, and share Personal Information of residents of these states and the rights these users may have with respect to their Personal Information. Please note that not all rights listed below may be afforded to all users, and, therefore, you may not be able to exercise these rights. In addition, we may not be able to process your request if you do not provide us with sufficient detail to allow us to confirm your identity or understand and respond to it.
For purposes of this section, the term “Personal Information” has the meaning given in the State Privacy Laws and does not include information exempted from the scope of the State Privacy Laws.
Your privacy rights. The State Privacy Laws may provide residents with some or all of the rights listed below. However, these rights are not absolute and some State Privacy Laws do not provide these rights to their residents. Therefore, we may decline your request in certain cases as permitted by law.
- Information. You can request the following information about how we have collected and used your Personal Information during the past 12 months:
- The categories of Personal Information that we have collected.
- The categories of sources from which we collected Personal Information.
- The business or commercial purpose for collecting and/or selling Personal Information.
- The categories of third parties with which we share Personal Information.
- The categories of Personal Information that we sold or disclosed for a business purpose.
- The categories of third parties to whom the Personal Information was sold or disclosed for a business purpose.
- Access. You can request a copy of the Personal Information that we have collected about you during the past 12 months.
- Appeal. You can appeal our denial of any request validly submitted.
- Correction. You can ask us to correct inaccurate Personal Information that we have collected about you.
- Deletion. You can ask us to delete the Personal Information that we have collected from you.
- Opt-out.
- Opt-out of tracking for targeted advertising purposes. You can opt-out of certain tracking activities for targeted advertising purposes.
- Opt-out of other sales of personal data. You can opt-out of other sales of your Personal Information.
- Nondiscrimination. You are entitled to exercise the rights described above free from discrimination as prohibited by the State Privacy Laws.
Exercising your right to information/know, access, appeal, correction, and deletion. You may submit requests to exercise your right to information/know, access, appeal, correction, or deletion by calling us at (434) 465-2811, via email to feedback@rootsnk.com, or via our Reach Us form, linked here.
Exercising your right to opt-out of tracking for targeted advertising purposes. Like many companies, we use services that help deliver interest-based ads to you as described above. The State Privacy Laws may classify our use of some of these services as “selling” or “sharing” your Personal Information with the advertising partners that provide the services. You can by submit requests to opt-out of tracking for targeted advertising purposes or other sales of Personal Information via email to feedback@rootsnk.com, via our Reach Us form, linked here, or via phone by calling (434) 465-2811.
Verification of Identity; Authorized agents. We may need to verify your identity in order to process your information/know, access, appeal, correction, or deletion requests and reserve the right to confirm your residency. To verify your identity, we may require government identification, a declaration under penalty of perjury, or other information, where permitted by law.
Under some State Privacy Laws, you many enable an authorized agent to make a request on your behalf upon. However, we may need to verify your authorized agent’s identity and authority to act on your behalf. We may require a copy of a valid power of attorney given to your authorized agent pursuant to applicable law. If you have not provided your agent with such a power of attorney, we may ask you to take additional steps permitted by law to verify that your request is authorized, such as by providing your agent with written and signed permission to exercise your rights under State Privacy Laws on your behalf, the information we request to verify your identity, and confirmation that you have given the authorized agent permission to submit the request.
Personal information that we collect, use and disclose. We have summarized the Personal Information we collect by reference below to the categories defined in the “What data do we collect?” section of this Policy above and describes our practices currently and during the 12 months preceding the effective date of this Privacy Policy. Information you voluntarily provide to us, such as in free-form webforms, may contain other categories of personal information not described below.
Personal Information (“PI”) we collect | Source of PI | Business/ commercial purpose for PI collection |
Categories of third parties to whom we disclose PI for a business purpose | Categories of third parties to whom we disclose for targeted advertising purposes |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
We do not intentionally collect this information, but it may be revealed in identity data or other information we collect |
|
|
|
|