The terms “we”, “us” and “our” and “The Ecotourist” and “The Mangrove Concept” refer to The Mangrove Concept. The terms “user,” “you” and “your” refer to site visitors, customers and any other users of the site.
The term “personal information” is defined as information that you voluntarily provide to us, which personally identifies you and/or your contact information, such as your name, phone number and email address.
The Mangrove Concept provides a blog where users can read articles on lifestyle, business, creativity, marketing, writing and motivation and a service where users may purchase digital products related to the topics aforementioned within (the “Service”).
Information We Collect
Your Payment Information. We collect payment information for each order, but we do not store payment information on TMC servers. Your payment information is securely communicated to and processed via our e-commerce software providers. All personal information collected for an order is used for the fulfilment of that order and to manage our customer relationship with you.
Product Orders. We collect a variety of personal information with each product order, but always only the bare minimum necessary to effect the sale. This includes your name, billing address, and email address. This information is shared with our e-commerce software providers to ensure the delivery of your order. We use your email to communicate with you about your order and to manage our customer relationship with you.
Your Payment Information. We collect payment information for each order, but we do not store payment information on TMC servers. Your payment information is securely communicated to and processed via our e-commerce software providers. All personal information collected for an order is used for the fulfillment of that order and to manage our customer relationship with you.
The Blog. We only collect the personal information you voluntarily provide to us which includes: Your first name and email address to subscribe to our mailing list; your first name, email address and/or social media profile to post a comment on our blog.
Comments. When you use the comment function on this website, information on the time the comment was generated and your e-mail-address and, if you are not posting anonymously, the user name you have selected will be archived in addition to your comments.c
Comments and any affiliated information (e.g. the IP address) shall be stored by us and remain on our website until the content the comment pertained to has been deleted in its entirety or if the comments had to be deleted for legal reasons (e.g. insulting comments).
Comments are stored on the basis of your consent (Art. 6 GDPR Sect.1 (a)). You have the right to revoke at any time any consent you have already given us. To do so, all you are required to do is sent us an informal notification via e-mail. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.
Contact form. If you submit inquiries to us via our contact form, the information provided in the contact form as well as any contact information provided therein will be stored by us in order to handle your inquiry and if we have further questions. We will not share this information without your consent.
Hence, the processing of the data entered into the contact form occurs exclusively based on your consent (Art. 6 GDPR Sect.1 (a)). You have the right to revoke at any time any consent you have already given us. To do so, all you are required to do is sent us an informal notification via e-mail. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.
The information you have entered into the contact form shall remain with us until you ask us to eradicate the data, revoke your consent to the archiving of data or if the purpose for which the information is being archived no longer exists (e.g. after we have concluded our response to your inquiry). This shall be without prejudice to any mandatory legal provisions – in particular, retention periods.
Activity. We may record information relating to your use of the Site, such as the searches you undertake, the pages you view, your browser type, IP address, requested URL, referring URL, and timestamp information. We use this type of information to administer the Site and provide the highest possible level of service to you. We also use this information in the aggregate to perform statistical analyses of user behaviour and characteristics in order to measure interest in and use of the various areas of the Site.
Cookies. We may send cookies to your computer in order to uniquely identify your browser and improve the quality of our service. The term “cookies” refers to small pieces of information that a website sends to your computer’s hard drive while you are viewing the Site.
We may use both session cookies (which expire once you close your browser) and persistent cookies (which stay on your computer until you delete them). You can accept or decline cookies using your web browser settings. If you choose to disable cookies, some areas of the Site may not work correctly or at all.
Cookies that are required for the performance of the electronic communications transaction or to provide certain functions you want to use (e.g. the shopping cart function) are stored on the basis of Art. 6 GDPR Sect.1 (f). The website operator has a legitimate interest in storing cookies to ensure the technically error-free and optimised provision of the operator’s services. If a corresponding agreement has been requested (e.g. an agreement to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 GDPR Sect.1 (a); the agreement can be revoked at any time.
Server log files. The provider of this website and its pages automatically collects and stores information in so-called server log files, which your browser communicates to us automatically. The information comprises:
- The type and version of browser used
- The used operating system
- The hostname of the accessing computer
- The time of the server inquiry
The IP address
This data is not merged with other data sources.
This data is recorded on the basis of Art. 6 GDPR Sect.1 (f). The operator of the website has a legitimate interest in the technically error free depiction and the optimisation of the operator’s website. In order to achieve this, server log files must be recorded.
Request by e-mail. If you contact us by e-mail, your request, including all resulting personal data (name, request) will be stored and processed by us to process your request. We do not pass these data on without your consent.
The processing of these data is based on Art. 6 GDPR Sect.1 (b), if your request is related to the execution of a contract or if it is necessary to carry out pre-contractual measures. In all other cases, the processing is based on your consent (Art. 6 GDPR Sect.1 (a)) and/or on our legitimate interests (Art. 6 GDPR Sect.1 (f)), since we have a legitimate interest in the effective processing of requests addressed to us.
The data sent by you to us via contact requests remain with us until you request us to delete, revoke your consent to the storage or the purpose for the data storage lapses (e.g. after completion of your request). Mandatory statutory provisions – in particular, statutory retention periods – remain unaffected.
How Your Information is Used
The information you provide is used to process transactions, personalise your experience, improve customer service, send periodic emails, and improve the service we provide.
Your information, whether public or private, will not be sold, exchanged, transferred, or given to any other company for any reason whatsoever, without your consent, other than for the express purpose of delivering the purchased product or service requested.
In those cases, we will share your information with trusted third parties, such as our online course software, in order to provide the service. These trusted third parties agree to keep this information confidential. Your personal information will never be shared with unrelated third parties.
We do not store your credit card information. As a function of historical record-keeping, we keep contact form emails and records of purchase transactions indefinitely. If you leave a comment, the comment and its metadata are retained indefinitely.
If at any time you would like to unsubscribe from receiving future emails, we include detailed unsubscribe instructions at the bottom of each email.
Third-Party Links & Analytics
You have the option to object to such analyses, or you can prevent their performance by not using certain tools. For more information on Google Analytics, including how to opt-out from certain data collection, please visit https://support.google.com/analytics/topic/2919631?hl=en&ref_topic=1008008. If you opt-out of any service, you may not enjoy the full functionality of the Website.
In the context of our website, we use the functions of the web analysis service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics uses so-called “cookies” (see section above). These are text files that are stored on your computer and enable an analysis of your use of the website. The information generated by the cookie about your use of the website will generally be transmitted to and stored by Google on servers in the United States. The Google Analytics cookie (legal basis Art. 6 (1) (f) GDPR) is stored because of our legitimate interest in analysing user behaviour to optimise our website and advertising. We are supported in this by Google as a contract processor. Google will use this information to evaluate the user’s use of the website, compiling reports on website activity and providing other services to website operators relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google.
IP Anonymization. The IP anonymisation function is activated on our website. Your IP address will be shortened by Google within the European Union or in a contracting state of the Agreement on the European Economic Area before transmission to the USA. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. The legal basis for a transfer of personal data is the so-called EU-US Privacy Shield.
Data processing agreement. We have concluded an agreement with Google for data processing and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Demographic features of Google Analytics. This website uses the “demographic features” function of Google Analytics. This allows reports to be generated that contains information on the age, gender, and interests of website visitors. This data comes from interest-related advertising by Google and visitor data from third parties. This information cannot be associated with any specific individual. You can deactivate this function at any time via the ad settings in your Google Account or generally prohibit Google Analytics from collecting your data as described under “Objection to data collection”.
Archiving period: Data on the user or incident level stored by Google linked to cookies, user IDs or advertising IDs (e.g. DoubleClick cookies, Android advertising ID) will be anonymised or deleted after 14 months. For details, please click the following link: https://support.google.com/analytics/answer/7667196?hl=en
We may collect or receive information from third parties, such as Facebook, Instagram and/or other third-party social media and similar sites.There are, however, no social plugins on our website, especially not the “Like” button of the social network facebook.com.
We only link to our own social media profiles and enable you sharing specific site content (i.e. blogposts) on your social media. If you are logged into your social media account and follow the respective link, the social network will be able to assign your visit to our website to your user account there. If you do not want your social networks to be able to assign your visit to our website to your user accounts there, you must log out of your social media accounts before clicking any of these links.
If you would like to subscribe to the newsletter offered on this website, we will need your e-mail address as well as information that allows us to verify that you are the owner of the e-mail address provided and consent to the receipt of the newsletter. No further data shall be collected or shall be collected only on a voluntary basis.
This website uses the services of ActiveCampaign to send out its newsletters. The provider is ActiveCampaign LLC, 1 N Dearborn Street, Chicago, IL 60602, USA.
Among other things, ActiveCampaign is a service that can be deployed to organise and analyse the sending of newsletters. Whenever you enter data to subscribe to a newsletter (e.g. your e-mail address), the information is stored on ActiveCampaign servers in the United States.
ActiveCampaign has a certification that complies with the “EU-US-Privacy-Shield.” The “Privacy-Shield” is a compact between the European Union (EU) and the United States of America (USA) that aims to warrant compliance with European data protection standards in the United States.
With the assistance of the ActiveCampaign tool, we can analyse the performance of our newsletter campaigns. If you open an e-mail that has been sent through the ActiveCampaign tool, a file that has been integrated into the email (a so-called web-beacon) connects to ActiveCampaign’s servers in the United States. As a result, it can be determined whether a newsletter message has been opened and which links the recipient possibly clicked on.
Technical information is also recorded at that time (e.g. the time of access, the IP address, type of browser and operating system). This information cannot be allocated to the respective newsletter recipient. Their sole purpose is the performance of statistical analyses of newsletter campaigns. The results of such analyses can be used to tailor future newsletters to the interests of their recipients more effectively.
If you do not want to permit an analysis by ActiveCampaign, you must unsubscribe from the newsletter. We provide a link for you to do this in every newsletter message. Moreover, you can also unsubscribe from the newsletter right on the website.
The data is processed based on your consent (Art. 6 GDPR Sect.1 (a)). You may revoke any consent you have given at any time by unsubscribing from the newsletter. This shall be without prejudice to the lawfulness of any data processing transactions that have taken place prior to your revocation.
We shall archive the data you archive with us for the purpose of the newsletter subscription until you unsubscribe from the newsletter. Once you cancel your subscription to the newsletter, the data shall be deleted from our servers, as well as those of ActiveCampaign. This shall not affect data we have been archiving for other purposes.
For more details, please consult the Data Privacy Policies of ActiveCampaign at https://www.activecampaign.com/privacy-policy.
Execution of a contract data processing agreement. We have executed a so-called “Data Processing Agreement” with ActiveCampaign, in which we mandate that ActiveCampaign undertakes to protect the data of our customers and to refrain from sharing it with third parties.
YouTube with expanded data protection integration
We sometimes embed videos of the website YouTube. The website operator is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in the expanded data protection mode. According to YouTube, this mode ensures that YouTube does not store any information about visitors to this website before they watch the video. Nevertheless, this does not necessarily mean that the sharing of data with YouTube partners can be ruled out as a result of the expanded data protection mode. For instance, regardless of whether you are watching a video, YouTube will always establish a connection with the Google DoubleClick network.
As soon as you start to play a YouTube video on this website, a connection to YouTube’s servers will be established. As a result, the YouTube server will be notified, which of our pages you have visited. If you are logged into your YouTube account while you visit our site, you enable YouTube to directly allocate your browsing patterns to your personal profile. You have the option to prevent this by logging out of your YouTube account.
Furthermore, after you have started to play a video, YouTube will be able to place various cookies on your device. With the assistance of these cookies, YouTube will be able to obtain information about our website’s visitors. Among other things, this information will be used to generate video statistics with the aim of improving the user friendliness of the site and to prevent attempts to commit fraud. These cookies will stay on your device until you delete them.
Under certain circumstances, additional data processing transactions may be triggered after you have started to play a YouTube video, which are beyond our control.
The use of YouTube is based on our interest in presenting our online content in an appealing manner. Pursuant to Art. 6 GDPR Sect.1 (f), this is a legitimate interest. If a corresponding agreement has been requested (e.g. an agreement to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 GDPR Sect.1 (a); the agreement can be revoked at any time.
TMC shares your information with third parties in some circumstances as follows:
Response to Subpoenas or Court Orders or to Protect Rights and to Comply with Our Policies. To the extent permitted by law, we will disclose your information to government authorities or third parties if: (i) required to do so by law, or in response to a subpoena or court order; (ii) we believe in our sole discretion that disclosure is reasonably necessary to protect against fraud, to protect the property, safety or other rights of us or other users, third parties or the public at large; or (iii) we believe that you have abused the Service by using it to attack other systems or to gain unauthorized access to any other system, to engage in spamming or otherwise to violate applicable laws. You should be aware that, following disclosure to any third party, your information may be accessible by others to the extent permitted or required by applicable law.
The data processing controller on this website is:
3033 XP Rotterdam
The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data (e.g. names, e-mail addresses, etc.).
Security Measures. We maintain security measures to protect your personal information from unauthorised access, misuse or disclosure. We offer the use of a secure server.
All supplied sensitive/credit information is transmitted via Secure Socket Layer (SSL) technology and then encrypted into our Payment gateway providers database only to be accessible by those authorised with special access rights to such systems, and are required to keep the information confidential.
However, no exchange of data over the Internet can be guaranteed as 100% secure. While we make every effort to protect your personal information shared with us through our Site, you acknowledge that the personal information you voluntarily share with us through this Site could be accessed or tampered with by a third party.
You agree that we are not responsible for any intercepted information shared through our Site without our knowledge or permission. Additionally, you release us from any and all claims arising out of or related to the use of such intercepted information in any unauthorised manner.
Sharing. Please be aware that when you use our Site to post comments and share other information, any information that you provide may not be secure and can be collected and used by others. As a result, you should exercise caution before you make such disclosures.
If you are a customer or mailinglist subscriber, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us (“right to transparent information”).
Under certain circumstances, you have the right to demand the restriction of the processing of your personal data (“right to restriction of processing”).
You can request to have your data transferred or ported elsewhere (“right to data portability“).
You have the right to object on grounds relating to your particular situation to the collection or processing of certain kinds of information (“right to object”), as well as to withdraw consent even after it has been given, without affecting the lawfulness of the processing of your data prior to your withdrawal (“right to withdraw consent”)
Further, if you feel that we have not complied with the relevant data protection regulations, please contact us by sending us an email at susanna(at)mangroveconcept.com with your first and last name, your country of origin, and a summary of your concern or complaint. We will endeavour to respond at our earliest possible convenience to address your concern. If contacting us does not resolve your complaint, you may have additional options.
Residents in Designated Countries may also have the right to lodge a complaint with the relevant EU data protection authority. You may access a list of the Data Protection Authorities in the EU here.
How to Update Your Information
If you opt-in to our mailing list, the option to unsubscribe will be included in every email. You may also access and correct your personal information and privacy preferences by contacting us with your request at susanna(at)mangroveconcept.com.
Notification of Changes to this Policy
You acknowledge and agree that it is your responsibility to review this Site and this Policy periodically and to be aware of any modifications.
Updated: March 2020