Privacy Policy

Last updated: 23/2/21

This is the privacy policy (the “Policy”) of the mobile application BoxSize (the "Application") operated by MySize Inc. of 4 Yarden street, Airport City, Israel (the “Company”, “We,” Us”, “Our”).

The Company is committed to securing your Personal Data and your privacy. According to this commitment We will uphold the following principles:

Our Complete Privacy Policy

In order to view the entire document, please press here

To What Does This Privacy Policy Apply?

This Policy describes what kind of Personal Data the Company collects about natural persons, how it collects it, uses it, shares it with third parties, secures it, processes it etc.
In this Policy, any reference to “Personal Data” is to any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or in combination with additional information that We have or that We have access to.
In this policy, wherever We refer to the “processing” of Personal Data, We refer to any operation or set of operations which is performed on Personal Data, including the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
You must be at least 14 years old (or such other age permissible by applicable law, but no less than 13) to access or use the Application. We do not knowingly collect Personal Data from any person under the age of 14 (or such other age permissible by applicable law, but no less than 13).

Data Controller

The Company is the data controller in respect of the Personal Data about you.

Data Protection Officer

The data protection officer of the Company and the means to communicate with the data protection officer are:
Data Protection Officer, MySize Inc.
DPO@MYSIZEID.COM

When Do We Collect Personal Data About You?

We collect Personal Data about you whenever you use Our products and services (including the Application) and contact Us in any channel. In some instances, you will actively provide Us with the Personal Data, and in other instances We will collect the Personal Data about you from examining and analyzing your use of Our products and services (including the Application) and Our service channels.

No Obligation To Provide Personal Data To The Company And Its Implications

You are not obligated to provide Us with any Personal Data about you. However, in some instances, not providing such Personal Data will prevent Us from providing you with the products or services you request Us to provide you, prevent the use of the Application or cause the malfunctioning of Our products and services (including the Application). Please see below a detailed description of such instances:
A contractual obligation of the Company: in some instances, the Company is obligated by contract to provide Personal Data about you. In these instances, while you are not obligated to provide the Personal Data about you, if you will not provide the Company with such Personal Data, We will not be able to provide you with the products and services to which the contractual obligation applies.
By way of example, if you do not provide Us with Personal Data required by your employer who licensed the use of the Application by you, We will not be able to allow you to install or use the Application.
Providing Personal Data for the purpose of contracting with you or performing a contract with you in some instances, providing Personal Data about you is required in order to perform a contract between yourself and the Company. In these instances, while you are not obligated to provide the Personal Data about you, if you will not provide the Company with such Personal Data, We will not be able to provide you with Our products and services.
By way of example, in order for Us to be able to allow you access to Our Application, We will require to receive details regarding your device through which you request to access our Application, and its operating system.

What Personal Data About You Do We Collect?

Personal Data We collect upon your registration with the Application: when you register to the Application, you are required to provide Us with your email address. In addition, your email address is associated with your employer, who licensed the use of the Application by you. Therefore, due to the mere fact that your employers allowed you to use Our Application under its license, We learn about your workplace.
Personal Data We collect upon each time you visit the Application after installation: device model and type, operating system info, the name of your carrier / internet service provider, connection type, device language, device ID, unique device identifiers, iOS device name and the IP address from which you access the Application.
Personal Data We collect during your use of the Application:pictures taken using the Application, details regarding packages measured using the Application (measurements and barcodes of the packages), locations of transmission of packages through the Applications (geolocation), comments that you may have, dates and times of transmission of packages through the Applications.
Personal Data We receive from you: any Personal Data you provide to Us on your own free will when contacting Us, including via customer support, chat, social networks or in any other manner, including complaints, requests and comments. Our customer support representatives may record or document in writing your calls.

The Purposes Of The Processing Of Personal Data And Their Legal Basis

The Company processes your Personal Data for one or more of the purposes outlined in this section and according to the appropriate legal basis.
The Company shall not process Personal Data about you unless there is a legal basis for such processing. The legal bases according to which the Company may process Personal Data about you are as follows:

  1. Processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract. By way of example, in order to allow you to install and use the Application.

  2. Processing is necessary for the purposes of the legitimate interests pursued by the Company or by a third party By way of example, for the purpose of improving Our products and services (including the Application), or for the exercise or defense of legal claims. Whenever the processing of Personal Data about you is necessary for the purpose of the legitimate interests pursued by the Company or by a third party, the processing is conditional upon such interests not overridden by your interests or fundamental rights and freedoms which require protection of Personal Data about you. At any time, you may approach Us by sending a notice to the following email address: Privacy@mysizeid.com in order to receive information concerning the review performed by Us in order to reach the conclusion that We may process the Personal Data about you on account of such processing being necessary for the purposes of the legitimate interests pursued by the Company or by a third party.

The following list outlines the purposes for which We may process Personal Data about you and the legal basis for any such processing:

Purpose

Legal Basis

1

In order to install the Application We will process your Personal Data in order to allow you to install the Application.

Processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract.

2

In order for Us to be able to provide you with Our products and services (including the Application) Whenever you request to use Our products and services (including the Application), We will process the Personal Data required for Us to perform such request.

Processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract.

3

In order to contact you for the purpose of operational requirements In some circumstances, in order to provide you with the services that you require from Us, We will need to contact you. For instance, where a certain aspect of the Application) is changing, We will need to use Personal Data about you to notify you of this change.

Processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract.

4

In order to respond to your queries, requests or complaints, and to provide you with customer support services Processing of Personal Data about you is required in order to respond to queries you have concerning Our products and services (including the Application), and in general to provide you with customer support services.

Processing is necessary for the purpose of the legitimate interests pursued by the Company or by a third party.

5

In order to improve Our products and • services, as well as to offer new ones We may use Personal Data about you in order to improve Our products and services (including the Application), as well as for the purpose of offering new ones; such processing will include, for example, an analysis of previous uses by you of Our products and services (including the Application), any comments and complaints received in respect of them, as well as any errors and malfunctions.

Processing is necessary for the purpose of the legitimate interests pursued by the Company or by a third party.

6

In order to perform and maintain various activities supporting the offering and provision of Our products and services Such activities include back office functions, business development activities, technical functionality and security, strategic decision making, oversight mechanisms etc.

Processing is necessary for the purpose of the legitimate interests pursued by the Company or by a third party.

7

In order to perform analysis, including statistical analysis We use various analytical measures (including statistical ones) in order to make decisions in various issues, including improving existing products and services and introducing and developing new ones.

Processing is necessary for the purpose of the legitimate interests pursued by the Company or by a third party.

8

In order to perform surveys and analyze the responses to such surveys

Processing is necessary for the purpose of the legitimate interests pursued by the Company or by a third party.

9

In order to protect Our and third parties’ interests, rights and assets, including initiation or exercise or defense of legal claims We may process Personal Data about you in order to protect the interests, rights and assets of Ours and of third parties, according to any law, regulation and agreement, including any of Our terms and conditions and policies.

Processing is necessary for the purpose of the legitimate interests pursued by the Company or by a third party.

Your Right To Object To The Processing of Personal Data About You Where Such Processing Is Necessary For The Purpose Of The Legitimate Interests Pursued By The Company Or By A Third Party

Where the processing of Personal Data about you is necessary for the purpose of the legitimate interests pursued by the Company or by a third party, you have the right to object to such processing for this purpose by sending a notice to the following email address: Privacy@mysizeid.com , unless We demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.

Transfer Of Personal Data To Other Parties

The Company shares Personal Data with companies within the group of companies of which the Company is a part, for the purpose of supporting the activities of the Company and the offering of the Company’s products and services.
The Company may also share Personal Data about you with third parties that provide Us with the following services:

  1. Storage and hosting providers, including cloud computing services
  2. IP address information
  3. Analysis of user experience
  4. Support
  5. Marketing
  6. Dispatch of materials, including marketing materials, via various means of communications, such as emails, push notifications and other electronic messages
  7. CRM data management
  8. Accounting and legal services
  9. Research, analytical, technical and diagnostic services

The Company may also share the Personal Data about you with Vendors’ (brands’) websites and stores, which use such Personal Data in order to offer you their products and services and in order to enhance and improve your user experience.
The Company may share Personal Data about you with governmental, local, official and regulatory authorities, as well as where such disclosure is required to protect Our and third parties’ interests, rights and assets, including initiation or exercise or defense of legal claims.
In addition, We may disclose Personal Data about you to potential purchasers or investors, or lenders to, the Company or any company within the group of companies of which the Company is a part, or in the event of any similar transaction, or in connection with any merger, reorganization, consolidation or bankruptcy of the Company or any company within the group of companies of which the Company is a part.

In the preceding twelve (12) months, We have not sold any Personal Data.

Your Rights in respect of The Personal Data About you

You are entitled to the following rights in respect of the Personal Data about you. The exercise of such rights will be via sending an email requesting to exercise your right to the following email address: Privacy@mysizeid.com

Right of access

You have the right to receive from the Company confirmation as to whether or not Personal Data about you is being processed by Us, and, where that is the case, access to the Personal Data and the following information: (1) the purposes of the processing; (2) the categories of Personal Data concerned; (3) the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in countries outside the European Economic Area (EEA) or international organizations; (4) where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period; (5) the existence of the right to request from the Company rectification or erasure of Personal Data or restriction of processing of Personal Data about you or to object to such processing; (6) the right to lodge a complaint with a supervisory authority; (7) where the Personal Data is not collected from you, any available information as to its source; (8) the existence of profiling; and (9) where Personal Data is transferred to a third country outside the EEA or to an international organization, the appropriate safeguards relating to the transfer.
The Company shall provide a copy of the Personal Data undergoing processing and may charge a reasonable fee for any further copies requested by you. Where you make the request by electronic means, and unless otherwise requested by you, the information shall be provided in a commonly used electronic form.
The right to obtain a copy of the Personal Data shall not adversely affect the rights and freedoms of others, and therefore if the request will harm the rights and freedoms of others, the Company may not fulfill your request or do so in a limited manner.

Right to rectification

You have the right to request that the Company rectifies of inaccurate Personal Data about you. Taking into account the purposes of the processing, you have the right to have incomplete Personal Data about you completed, including by means of providing a supplementary statement.

Right to erasure

You have the right to request that the Company will erase Personal Data about you where one of the following grounds applies: (a) the Personal Data is no longer necessary in relation to the purpose for which it was collected or otherwise processed; (b) you object at any time, on grounds relating to your particular situation, to processing of the Personal Data which is based on the legitimate interests pursued by Us or by a third party, and there are no overriding legitimate grounds for the processing; (c) the Personal Data has been unlawfully processed; (d) the Personal Data has to be erased for compliance with a legal obligation in European Union or Member State law to which the Company is subject.
This right does not apply to the extent that the processing is necessary: (a) for compliance with a legal obligation which requires processing by European Union or Member State law to which the Company is subject; or (b) for the establishment, exercise or defense of legal claims.

Right of restriction of processing

You have the right to request that the Company will limit the processing of Personal Data about you where one of the following applies: (a) the accuracy of the Personal Data is contested by you, for a period enabling the Company to verify the accuracy of the Personal Data; (b) the processing is unlawful and you oppose the erasure of the Personal Data and request the limitation of its use instead; (c) the Company no longer needs the Personal Data for the purposes of the processing, but it is required by you for the establishment, exercise or defense of legal claims; (d) where the processing of the Personal Data is necessary for the purpose of the legitimate interests pursued by the Company or by a third party, unless We demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims; (e) where the Personal Data is processed for direct marketing purposes, including profiling the extent that it is related to such direct marketing.
Where processing of Personal Data about you has been limited following your request, such Personal Data shall, with the exception of storage, only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.

Right to data portability

You have the right to receive the Personal Data about you, which you have provided to the Company, in a structured, commonly used and machine-readable format and have the right to transmit such Personal Data to another controller, where: (a) the processing is based on your consent or on a contract to which you are a party; and (b) the processing is carried out by automated means.
In exercising your right to data portability, you have the right to have the Personal Data about you transmitted directly from the Company to another controller, where technically feasible. The exercise of your right to data portability shall not derogate from your and the Company’s rights under your right to erasure. In addition, the right to data portability shall not adversely affect the rights and freedoms of others.

Right to object

You have the right to object at any time, on grounds relating to your particular situation, to processing of Personal Data about you which is based on the legitimate interests pursued by the Company or by a third party, including profiling based on such legitimate interests; in which case, We shall no longer process the Personal Data about you unless We demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or that the processing is required for the establishment, exercise or defense of legal claims.
You have the right to object at any time to the processing of Personal Data about you for direct marketing purposes, which includes profiling to the extent that it is related to such direct marketing.

Right to withdraw consent

You may withdraw your consent provided to Us for the purpose of processing Personal Data about you at any time, without affecting the lawfulness of processing based on your consent before its withdrawal.

Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a supervisory authority which is established by a European Member State in order to protect the fundamental rights and freedoms of natural persons in relation to processing of Personal Data within the European Union.

Your rights in respect of Personal Data about you as outlined in this section 10 may be limited by European Union or Member State law to which the Company is subject.
We shall provide you with the information requested according to your rights outlined in this section 11 10 without undue delay and within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. We shall inform you of any such extension within one month of receipt of your request, together with the reasons for the delay.
The information requested according to your rights outlined in this section 10 shall be provided free of charge, unless stated otherwise in this section 10. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, We may either: (a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or (b) refuse to act on the request.
The Company may require you to provide additional information necessary to confirm that you are who you claim to be before it will act on your request according to your rights outlined in this section 10, where the Company has reasonable doubts concerning your identity.

if you reside in California, please read below with respect to the California Consumer Privacy Act (CCPA) rights you have:

Right

Scope

1

Right to know

you have the right to receive the following information:
  • What types of Personal Data collected.
  • What are the types of sources of the Personal Data collected
  • To what end We collect the Personal Data;
  • Types of third parties whom We share Personal Data, if any; and
  • the specific pieces of Personal Data We have collected aboust you.

2

Right to Erasure

You make ask Us to delete your Personal Data and direct Our service providers to do so.

Please note that We may not delete your Personal Data if it is necessary to complete Our legal obligation to you to provide to Services or otherwise protect Our legal rights, comply with an existing legal obligation; or use your Personal Data, internally, in a lawful manner that is compatible with the context in which you provided the information

3

Right to Non-Discrimination for the exercise of your privacy right

You have the right to not be discriminated against by Us because you exercised any of your rights under the CCPA

4

Right to designate an authorized agent to submit CCPA requests on your behalf

You may designate an authorized agent to make a request under the CCPA on your behalf. To do so, you need to provide the authorized agent written permission to do soand the agent will need to submit to Us proof that such agent has been authorized by you. We will also require that you verify your own identity, as explained below.

In order to exercise your CCPA right, please contact us using the following details:


Privacy@mysizeid.com

Toll free number: 18008474412

Please note that We may need to receive Personal Data form you in order to verify your identity prior to allowing you to exercise your rights.

Tracking And Cookies

When you visit or access the Application , a cookie file (which is a small text file) is installed on the device via which you visit or access the Application. The cookies enable Us to collect Personal Data about you and your behavior, in order to improve your user experience, to remember your preferences and settings, to customize and offer you with products and services that may interest you. Cookies are also used to collect statistics about your usage of the Application and perform analytics.
Some of the cookies We use are session cookies, which are downloaded temporarily to your device, while others are persistent cookies which last on your device after you close the Application.
You may adjust the tracking settings on your mobile device’s settings page in order to block tracking and the use of cookies. Please note that such an adjustment solely impacts Our use of the tracking technologies but does not prevent the collection and processing of Personal Data about you as otherwise provided in this Policy.
Please note, however, that if you do so, some or all of the features and functionalities of the Application might not perform as intended.

Retention Of Personal Data About You

The Company shall retain Personal Data about you for as long as is required to fulfill the purposes of the processing of the Personal Data as outlined in this Policy, or for a longer period as required according to the legislation or other requirements that apply to Us.
In general, We will hold Personal Data about you for a minimum period of seven years after you install the Application
In order to ensure that Personal Data about you is not retained for longer than is required, We periodically review Personal Data retained by Us in order to examine whether any Personal Data can be erased.

Transfers Of Personal Data To A Third Country Or An International Organization

Personal Data about you may be transferred to a third country (i.e., if you are a resident of the EEA, jurisdictions outside the EEA; and otherwise, any country outside you country of residency) or to international organizations. In such circumstances, the Company shall take appropriate safeguards aimed to ensure the protection of Personal Data about you and provide that enforceable rights and effective legal remedies for you are available.

These safeguards and protection will be available if any of the following are met:

  1. The transfer is to a third country or an international organization which the European Commission decided that they provide an adequate level of protection to the Personal Data that is transferred to them pursuant to Article 45(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 ("GDPR");
  2. The transfer is according to legally binding and enforceable instrument between public authorities or bodies pursuant to Article 46(2)(a) of the GDPR; or
  3. The transfer is in accordance with standard data protection clauses adopted by the EU Commission pursuant to Article 46(2)(c) of the GDPR; the clauses adopted by the EU Commission can be viewed at https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en

You may request the Company to be provided with details concerning the safeguards employed by it to protect the Personal Data about you which is transferred to a third country or an international organization, by sending an email to the following address: Privacy@mysizeid.com

Protection Of Personal Data About You

We implement appropriate technical and organizational measures to ensure an appropriate level of security to Personal Data taking into account the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored or otherwise processed.
We may be required, due to legal or other obligations outside Our control, to transfer Personal Data about you to third parties, such as public authorities. In such circumstances, We have limited control over the level of protection provided to the Personal Data about you by such third parties.
Any transfer of Personal Data via the internet cannot be fully secured. Therefore, the Company cannot ensure the protection of Personal Data about you when transferred via the internet to Us (including via the Application).

Links To Websites And Applications of Third Parties

The Application may provide links to websites and applications of third parties. The Company does not control such websites and applications, nor the collection and processing of Personal Data about you by such websites and applications, and We are not responsible for such websites and applications, nor to their privacy and data protection policies and activities. This Policy does not apply to any actions taken via such websites and applications.
Wherever you access such third parties' websites or applications, We recommend that you carefully review their privacy policies prior to using such websites or applications and prior to disclosing any Personal Data by you.

Changes To This Policy

We may amend, from time to time, the terms of this Policy. Whenever We amend this Policy, We will notify such amendments by publishing the updated Policy in the Application. In addition, when We make significant amendments of this Policy, We will strive to inform you about such amendments via means of communication which We believe are reasonably appropriate to inform you of such amendments and by publishing a notice about such amendments in the Application. Unless stated otherwise, all amendments will enter into force upon publishing the updated Policy in the Application.