Summary
Overall, SHIELD's Privacy Policy is well-structured and provides a clear understanding of data collection, usage, sharing, user rights, and security measures. The policy effectively addresses key privacy concerns, particularly for users in the EEA under GDPR. Areas for improvement include enhancing transparency around data sharing circumstances, providing more details on marketing opt-out processes, and specifying retention periods for different data types.Data Collection (8.5)SHIELD provides a comprehensive overview of the types of data collected, including passive biometric data, device information, shopping cart information, user information, payment information, geolocation information, and aggregated data. The methods of collection are clearly stated, particularly in relation to user consent and interaction with Merchant platforms. However, the policy could benefit from more clarity on how data is anonymized or aggregated to further protect user privacy.
Data Usage (8)The policy outlines the purposes for which data is used, primarily focusing on fraud prevention and enhancing user experience on Merchant platforms. It mentions the use of data for marketing communications when users interact with SHIELD's website. However, more transparency regarding analytics and personalization practices could enhance user understanding of how their data is utilized.
Data Sharing (7.5)SHIELD clearly states that it does not share, rent, or sell user information to third parties, except as required by law. The policy mentions subprocessors like Amazon Web Services for data storage, which is a positive aspect. However, it could provide more detail on the specific circumstances under which data might be shared with law enforcement or other third parties.
User Rights (8)The policy effectively outlines user rights under GDPR, including access, modification, and deletion of data. It provides actionable steps for users to exercise these rights, such as contacting SHIELD via email. However, it could improve by including more information on how users can opt-out of marketing communications and the process for doing so.
Security Measures (8.5)SHIELD describes robust security measures, including audit assessments, access controls, and network security protocols. The retention policy is clear, stating that data is kept only as long as necessary for fraud prevention purposes. However, it could benefit from specifying the exact retention periods for different types of data.