Privacy Policy

This Vista Privacy and Cookie Policy (“Privacy Policy”) describes what information Vista and its signature services, including VistaPrint, VistaCreate and 99designs by Vista (collectively, “Vista”, “we”, “our”, or “us”) collects from you through your use of and access to all of our websites, mobile sites (“Sites”), applications (“Apps”), services or other tools we offer and where reference is made to this Privacy Policy (collectively “Services”) and how we use, share and protect it. It also summarizes your rights and tells you how you can exercise those rights.

Content
1. Applicability
2. Who we are
3. What Personal Information do we collect and how do we collect it?
4. How do we use your Personal Information?
5. On what legal bases do we collect your Personal Information?
6. Children
7. Who do we disclose and share your Personal Information with?
8. Data transfers
__9. What rights do you have to access and control the use of your information?10. How can you exercise these rights?
11. What happens when you request your account to be deleted?
12. How long do we keep your Personal Information and how do we protect it?
13. What are Cookies?
14. How can you manage which Cookies are placed on your device?
15. Contact Us
16. Changes to this Privacy Policy

Supplemental Privacy Pages
i. Special Notice for California Residents
ii. Special Notice for Nevada Residents

1. Applicability.
This Privacy Policy applies to all users of our Sites and Applications, including unregistered and registered users, designer contributors as well as to our customers or potential customers (collectively, “User”, “you”, or “your”), and to all Vista Services that link to this Privacy Policy. To provide you the Services, we must collect personal information relating to an identified or identifiable natural person (“Personal Information”). Any such information that we collect from and about you while using our Services will be handled in accordance with this Privacy Policy. Depending on where you live and what you are doing on the Vista Sites and Apps, the supplemental privacy pages listed below may apply to you.

Please keep in mind that this Privacy Policy does not apply to Personal Information collected about you by third-party websites and Apps that may post links or advertisements on or otherwise be accessible from our Vista Sites and Apps. The Personal Information collected by these third-party websites is subject to their own privacy policies and we are not responsible for the privacy practices of those websites and Apps.

We encourage you to read this Privacy Policy and the supplemental privacy pages in its entirety before using our Vista Services to make sure you fully understand our practices in relation to your Personal Information. By accessing or using our Vista Sites, Apps and Services, you acknowledge that you have read and agree to this Privacy Policy.
If you have general questions about this Privacy Policy, you can reach our privacy team at dataprotection@vista.com.

2. Who we are.
Vista is a global e-commerce business with a primary objective of being the expert design and marketing partner for small businesses. Vista strives to meet this objective through a wide variety of products and services offered and delivered by a growing collection of Vista signature services, which include VistaPrint, VistaCreate and 99designs by Vista. The Vista global e-commerce business is operated by Cimpress Schweiz GmbH and certain other Cimpress plc subsidiaries. Where we refer below to “Vista”, “we” or “us”, we mean the relevant Cimpress plc subsidiary that is responsible for the processing of your Personal Information.

When you create an account and/or use our Vista Services, your Personal Information is controlled by Cimpress Schweiz GmbH and/or another Cimpress plc subsidiary. The list of the relevant data controller that is responsible for the Personal Information collected, processed, and used as described in this Privacy Policy can be found below. Cimpress Schweiz GmbH and the other Cimpress plc subsidiaries listed below work collaboratively to bring together your print, digital and design needs all over the world, and they may sometimes be acting as joint data controllers (for example in relation to your Vista account). Despite their joint responsibility for data processing, the companies cannot act as legal representatives for one another.

In relation to your Vista account:
Cimpress Schweiz GmbH
Talacker 41
8001 Zürich
Switzerland

In relation to VistaPrint Services:

• If you reside in the European Economic Area (“EEA”), UK, or Switzerland:

Vistaprint B.V.
Hudsonweg 8
5928 LW Venlo
The Netherlands

• If you reside in the United States:

Vistaprint Netherlands B.V.
Hudsonweg 8
5928 LW Venlo
The Netherlands

• If you reside in Australia, New Zealand and Singapore:

Vistaprint Australia Pty Limited
66 Paramount Boulevard
Derrimut, Victoria 3030
Australia

• If you reside in Canada:

Vistaprint Canada Corporation
333 Bay Street
Suite 2400
Toronto, Ontario
M5H 2T6
Canada

• If you reside in India:

Cimpress India Private Limited
‘C’ Block, Voltas Premises
T. B. Kadam Marg, Chinchpokli
Mumbai -400 033
Maharashtra
India

In relation to VistaCreate Services:
Crello Limited
1 Anastasi Sioukri
Themis Court
4th floor, Office 402
3105 Limassol
Cyprus

In relation to 99designs by Vista Services:
99designs Pty Limited
Level 2, 41-43 Stewart Street
Richmond, VIC 3121
Australia

In all other cases, you can reach out to the Privacy team by emailing at dataprotection@vista.com or writing to:

Attn: Data Protection Officer
Cimpress Schweiz GmbH
Talacker 41
8001 Zürich
Switzerland

3. What Personal Information do we collect and how do we collect it?
Vista offers you a wide range of services to bring together your print, digital and design needs. Depending on which services you use, we collect various types of Personal Information from different sources. As described below, some information is collected automatically when you visit our Sites and Apps or purchase something, and some you provide to us when registering or filling out a form, uploading content, buying a product or service, or communicating with us. We may also acquire information indirectly from third parties and other sources, including social media websites. If you choose not to share certain Personal Information, we might not be able to provide some of our Services. Similarly, if you decline to let us place certain cookies on your device, our Sites and Apps will only have limited functionality (see more information about cookies below).

3.1 Personal Information we collect automatically.
Device and location data. Whenever you visit or navigate our Sites and Apps, we automatically collect certain information through your device or browser. This information includes your IP address and information about your computer's hardware and software (for example, the type of operating system, the browser you use, the versions of the application or software and language settings). We may also collect location information from your IP address or if you have instructed your device to send such information via the privacy settings on that device. We collect some of this information by using cookies or other similar technologies directly from your device. For more information about how we use these technologies, see our Cookies section below.

Site navigation and usage data. We also automatically collect and store certain information about your activities on our Sites and Apps such as the date, time and pages you visit, and how you use our Services and access its contents (such as search history, clickstream data, access logs and other usage data regarding your interactions with our Sites and Apps and our marketing emails and online ads).

Session replay recordings. We also collect session replay recordings (such as mouse movements, clicks, typing, and scrolling).

Purchase and transaction history. If you place an order or request a service, we will collect your purchase and transaction history.

Bot usage data. If you contact us via chatbot, in addition to processing your contact information, we will be able to collect your device information and IP address.

If you are a registered user, we link this automatically collected data to the other Personal Information we collect about you as described below. We use this data for various purposes as further detailed below.

3.2 Personal Information you give us.
Contact details and log-in credentials. When you register for an account on our Sites and Apps, we collect your first and last name, e-mail address and password.

Payment information. If you place an order or request a service, we collect information that you provide to us such as your shipping, billing, and payment information (such as credit card or bank account details) as well as tax information and information to verify your identity (i.e., passport, ID card or driver's license information). You may also have the option to store credit card or other payment information to make it easier to purchase products or services from our Sites and Apps in the future.

Content data. Some of our Services allow you to upload and share images, photos, logos, videos, music tracks or other content (“Content”) with us or other users, in order to communicate with us or other users or to personalize products and services. The Content you choose to upload to our Sites and Apps may include Personal Information about you. For example, if you design and personalize a product, such as a business card, we collect the Personal Information you use to customize the product, such as the name of your business, your professional title, your photo or other Content you upload. If you choose to enter into a design contest, we collect the Personal Information you choose to provide to us in the logo and brand guide brief, such as the name of your business, your slogan or other Content you upload. When you upload your Content to our Sites and Apps or give us permission to access the Content stored on your device, your Content may also include related image information such as the time and the place your photo was taken, tags and similar information stored by your image capture device.

Profile information. We may collect demographic information about you such as your gender, country, and preferred language, as well as other information about your interests and preferences, including favorite templates and work on designs or products. For example, if you are a designer using our Services, we will store the information on the profile you create and the content you choose to make available to other users, such as your professional background, time zone, location, avatar, design concepts and templates, service offerings, and messages and testimonials. Some of this information is part of your public profile and will be publicly visible.

Communications and marketing. If you contact our customer service teams or communicate with us by other means (for example, social networks), we will also collect information from you from these communications, either in relation to feedback you give us or help you ask for in relation to the use of our products and services. We will also collect your preferences in receiving direct marketing from us and our third parties and your communication preferences.

Forms. From time-to-time, we may give you the opportunity to participate in sweepstakes, contests or surveys. If you participate, we will collect certain Personal Information from you and we may publicly disclose that information.

Reviews. We may also ask you to write a review to share your experiences with others. When you write a review on our Sites and Apps, we collect the information you include, along with the name you display. Please note that reviews posted on our Sites and Apps are public, so only include information you are comfortable with sharing publicly.

3.3 Personal Information you give us about others.
The Content you choose to upload to our Sites and Apps may include Personal Information of others. If you choose to share your Content or other information with someone else through a feature we offer or participate in our referral program, we will use the Personal Information you provide (for example, the e-mail address of the recipient) to fulfill your request and for other purposes described in this Privacy Policy. Before you upload and/or share Personal Information of others through our Sites and Apps, please ensure that you have the consent of such persons to do so and that the persons about whom you have provided Personal Information have understood and accepted how Vista uses their Personal Information (as explained in this Privacy Policy).

3.4 Personal Information we receive from other sources.
Vista may also obtain information about you that is publicly available or from other sources, such as independent third parties, business partners, Cimpress plc subsidiaries. Any information we get from these sources is combined with Personal Information you provide to us for the purposes described in this Privacy Policy.

For example, we may receive Personal Information about you from third-party sources, such as i) postal service providers to validate postal address information; ii) security providers, fraud detection and prevention providers to help us screen out users associated with fraud, ii) social media platforms, when you log-in or sign-up using your social media account (e.g., your username, basic profile account information, profile photo), (iii) in some cases, we may collect Personal Information from lead enhancement companies which help us to improve our service offering; and vi) advertising and marketing partners in order to monitor, manage and measure our ad campaigns and serve you more relevant advertising.

3.5 End Users Information
We may also collect Personal Information pertaining to visitors and users of our User’s websites or services (“End Users Information”), solely for and on your behalf. For example, you are able to add a Contact Form on your website. Information submitted by visitors of your website are then stored with Vista, on your behalf. For such purposes, Vista serves and shall be considered as a “Processor” and not as the “Controller” (as both such capitalized terms are defined in the European Union General Data Protection Regulation (“GDPR”)) of such End Users Information. You are responsible for complying with all laws and regulations that may apply to the collection and control of such End Users Information, including all privacy and data protection laws of all relevant jurisdictions. The processing and transfer of the End Users Information shall be in accordance to the Data Processing Agreement (“DPA").