Matrix.org Shop Privacy Notice

1. Introduction

1.1 English, Not Legalese

Data privacy is important, and we want you to understand the issues involved. We have decided to use plain English as much as possible, to make our terms as clear as possible.

Where you read The Matrix.org Foundation C.I.C., The Matrix.org Foundation, or The Foundation, it refers to the Community Interest Company incorporated on 29 October 2018 to be the neutral custodian of the Matrix protocol: The Matrix Foundation C.I.C., and their agents.

Where you read New Vector, New Vector Ltd., we or us below, it refers to the company created in July 2017 to hire the Matrix core team and support Matrix's development: New Vector Ltd., its French subsidiary: New Vector SARL, and their agents.

Should you have other questions or concerns about this document, please send us an email at [email protected].

1.2 Who Provides this Service?

This service is provided by New Vector Ltd. for The Matrix.org Foundation C.I.C. New Vector Ltd. and The Matrix.org Foundation are Joint Data Controllers.

New Vector Ltd. provides stock management and order fulfillment. All proceeds go to The Matrix.org Foundation.

1.2.1 Contact Details

New Vector Ltd.

Email: [email protected]

Postal address:

10 Queen Street Place
London
United Kingdom
EC4R 1AG

The Matrix.org Foundation C.I.C.

Email: [email protected]

1.3 Using The Service Means Accepting These Terms

By accessing or using the Service in any way you agree to and are bound by the terms and conditions written in this document.

If you do not agree to all of the terms and conditions contained in this document, please do not use this service.

1.4 This Is a Living Document

With your help, we want to make our policy documents the best in the industry.

If you read something that rubs you the wrong way, or if you think of something that should be added, please get in touch! We're all ears! Email [email protected] and we'll chat.

We don't amend this document for any specific users or use case, but if your proposed changes apply to all of our users, we'll be happy to update it for everyone. Scroll to the bottom to see the history so far.

We will likely improve this document over time. By continuing to use the Service, you will implicitly accept the changes we make.

Your access and use of the Service is always subject to the most current version of this document.

2. What is the Matrix.org Shop?

It is an online store at which you can purchase Matrix.org-branded merchandise, such as stickers or tee-shirts. All proceeds go to The Matrix.org Foundation.

3. Access to Your Data / Privacy Policy

Your data is processed under Performance of Contract. This means that we process your data for the purposes of fulfilling orders you make from us, getting in touch with you, responding to your requests, working with our suppliers to deliver the Service and enabling its features, ensuring the security of our Service, developing, fixing and improving our Service, administering our business and complying with the law.

3.1.2 Your Rights as Data Subject

You have rights in relation to the personal data we hold about you. Some of these only apply in certain circumstances. Some of these rights are explored in more detail elsewhere in this document. For completeness, your rights under GDPR are:

  1. The right to be informed

  2. The right of access

  3. The right to rectification

  4. The right to erasure

  5. The right to restrict processing

  6. The right to data portability

  7. The right to object

  8. Rights in relation to automated decision making and profiling.

For more details about these rights, please see the guidance provided by the ICO. If you have any questions or to exercise your rights, please contact us at [email protected].

3.2 What Information Do You Collect About Me and Why?

The information we collect is purely for the purpose of taking payments for merchandise and shipping your purchases to you. We do not profile users or their data on the Service.

3.2.1 Information you provide to us:

We collect information about you when you input it into the Service or otherwise provide it directly to us.

  • Name and contact details

  • Delivery address

  • Purchase information

  • Payment details (handled by a third party provider, not visible to Matrix.org Foundation employees)

3.2.2 Information we collect automatically as you use the service:

Your IP address is logged when you access the Service. This data is used in order to mitigate abuse and debug operational issues. Our logs are kept for not longer than 180 days.

3.3 What Information is Shared With Third Parties and Why?

3.3.1 BigCartel

We have selected BigCartel to provide our shopfront. By purchasing from our shop, the following details will be shared with BigCartel:

  • Your purchase details

  • Your name and contact details

  • Your delivery address

Here is BigCartel's Privacy Policy

3.3.2 Stripe

We use Stripe to handle payment processing. By purchasing from our shop, the following details will be shared with Stripe:

  • Your payment details

  • Your purchase value

Stripe takes care of all payment processing, so The Matrix.org Foundation and its employees will never see your payment details.

Here is Stripe's Privacy Policy

3.3.3 Royal Mail

We use Royal Mail Click & Drop to generate shipping labels. By purchasing from our shop, the following details will be shared with Royal Mail Click & Drop:

  • Your name and address

Here is Royal Mail's Privacy Policy

3.4 Sharing Data in Compliance with Enforcement Requests and Applicable Laws; Enforcement of Our Rights

In exceptional circumstances, we may share information about you with a third party if we believe that sharing is reasonably necessary to

(a) comply with any applicable law, regulation, legal process or governmental request,

(b) protect the security or integrity of our products and services (e.g. for a security audit),

(c) protect New Vector Ltd., The Matrix.org Foundation, and our users from harm or illegal activities, or

(d) respond to an emergency which we believe in good faith requires us to disclose information to assist in preventing the serious bodily harm of any person.

3.5 Our Commitment to Children's Privacy

We never knowingly collect or maintain information in the Service from those we know are under 16, and no part of the Service is structured to attract anyone under 16. If you are under 16, please do not use the Service.

3.6 Who Can See My Data?

Employees or agents of New Vector Ltd. and The Matrix.org Foundation can access your data, subject to the data access guidelines below.

Employees or agents of the third parties identified in 3.3 (BigCartel, Stripe, and Royal Mail) can see data that is shared with those third parties, subject to their own data access guidelines.

3.7 What Are the Guidelines New Vector Ltd. and The Matrix.org Foundation Follow When Accessing My Data?

  • We restrict who at New Vector Ltd. and The Matrix.org Foundation (employees and contractors) can access user data to roles which require access in order to maintain the health of the Service.

  • We never share what we see with other users or the general public.

3.8 What happens if The Matrix.org Foundation is sold?

In the event that we sell or buy any business or assets, we may disclose your personal data to the prospective seller or buyer of such business or assets.

If we or substantially all of our assets are acquired by a third party, personal data held by us about our users will be one of the transferred assets.

3.9 What Should I Do If I Find a Security Vulnerability in the Service?

If you have discovered a security concern, please follow the Matrix.org Security Disclosure Policy.

3.10 How Long Is My Data Stored?

We may need your personal information to establish, bring or defend legal claims. For this purpose, we will retain your personal information for 7 years after the date it is no longer needed by us for any of the purposes listed under How we use your information above.

4. Cookies

BigCartel and Stripe set cookies to help deliver this service:

5. Making a Complaint

We try to meet the highest standards when collecting and using personal information. For this reason, we take any complaints we receive about this very seriously. We encourage people to bring it to our attention at [email protected] if they think that our collection or use of information is unfair, misleading or inappropriate. We would also welcome any suggestions for improving our procedures.

If you want to make a complaint about the way we have processed your personal information to the supervisory authority, you can contact the ICO (the statutory body which oversees data protection law) at https://www.ico.org.uk/concerns.

6. Document History

  • 2019, August 19: modified to represent New Vector Ltd. as Joint Data Controller
  • 2019, August 13: created

A note to other startups: this document was heavily inspired by Balsamiq's plain English ToS document. We were impressed by their championing of plain English, and wanted to reproduce that as much as possible in our own legal documentation. Feel free to draw similar inspiration from this document, though be sure to get any documents you produce checked over by a lawyer. Good luck!