Privacy and Security
We want you to understand how and why Varty Inc, DBA GetRoasted, collects, uses, and shares information about you when you use our site. At Get Roasted, our top priority is to make sure that users’ personal data is protected and will not be tampered with. To this end, we store the videos created by our creators, unless either the creator of the video or th person to whom the video was sent request to have that video deleted.
When an account is created
. We do not store user passwords, phone numbers, addresses, Google payment information etc on the databases we manage. The only piece of information we store from users’ Google account is their name. (Using Google’s Firebase Authentication console, we are able to read the list of emails that have registered with us and their associated user IDs. However, in general, we do not store user emails in any of the databases we manage. This data is secured by Google, not Varty)
Personal information we store
Your name:Once an account has been authenticated through Firebase Authentication, an anonymized user ID is used as a reference to your personal data. Accounts store a record of the user’s name (the one they have registered on their Google account). A user’s name will be publicly available for purposes of allowing users to identify one another in public rooms. Our security rules leverage Google’s industry-standard software security to ensure that users have complete control over, and full responsibility for what name is associated with their own accounts. This prevents hackers from replacing name data with vulgar or inappropriate text. Images:Each time a user enters a new room, they are prompted to take a photo of themselves. This image will be publicly available for purposes of allowing users to identify one another in public rooms. User images can only be edited or overwritten by the user who owns them. Our security rules leverage Google’s industry-standard software security to ensure that users have complete control over what image is associated with their own accounts. This prevents hackers from replacing image data with vulgar or inappropriate images.
Personal information we transmit but do not store:
Video and audio data:We do not record, store, view, track, filter, or in any way monitor or mutate user-generated video and audio streams transmitted on Varty between users. All video and audio communications on the Varty platform are user-generated and the user has full control over and takes full responsibility for its content. The architecture for transmitting and receiving video and audio data on Varty is built using WebRTC. WebRTC is an open-source software developed by Google. It employs end-to-end encryption and is widely considered to be the most secure voice and video calling technology on the market. A full analysis of WebRTC security is available here: https://webrtc-security.github.io/
Other user data
Aside from the user’s personal information outlined above, as a user engages with the site, Varty will generate, store, and mutate data to be associated with a user’s anonymized user ID. This data consists of the necessary information required for the operation of Varty’s features and services. It is only relevant to that user’s behavior on Varty. This data is publicly accessible for purposes of allowing users to properly interact with one another in public virtual spaces. Examples of such data are the avatar’s positions in a room and the friends list.
Anonymized Metadata Collection
As you use the site, GetRoasted will extract completely anonymized metadata on overall user behavior on the site. We use this data only for our internal use for purposes of tracking performance and improving the experience for our users. Here is the list of metrics we track currently:Daily Active Users, Monthly Active UsersNumber of SignupsNumber of visits to the siteAverage session durationThe median number of rooms visitedNumber of users who add a friend per dayThe median number of friendsNumber of users that go to hub per dayNumber of users that go to a room >1x in a weekNumber of users that use call over per dayMedian call durationThe median number of people engaged withGDPR:
GetRoasted is committed to protecting your privacy and ensuring you have a positive experience when using the services we provide, which we generally refer to as GetRoasted or GetRoasted services, or when visiting our promotional or marketing websites.This policy explains how we handle data, including what we collect and how we obtain it, how we use it, when and if we disclose it, and some of your options for managing your data with GetRoasted. It applies worldwide to all of our subsidiaries and covers all data that you provide to us, as we describe below. Information that can be used to identify or be reasonably associated with a specific person is “personal data”. Where the data described in this policy is personal data, we only disclose it in the ways we have stated..GetRoasted does not knowingly allow children under the age of 16 to sign up for their own accounts. If you are a parent or legal guardian and believe your child has given us information, you can contact us at firstname.lastname@example.org, and we will take appropriate steps to investigate and address the issue. This policy may be updated periodically because our business, or regulations that apply to GetRoasted, may change. If we make any material changes to the way we handle personal data as described here, we will notify you by posting an updated notice on our website. We encourage you to review this page regularly for the latest information on our privacy practices. The effective date at the top of this policy indicates when the policy was last revised.
Collection And Use of Data
GetRoasted ServicesWe obtain data when you use GetRoasted in order to deliver our services and provide a better experience to you. The categories of data we obtain when you use GetRoasted include data you provide to us as well as data that our system collects from you. When we say “customer”, we mean the person or company that signs up for and has the account with GetRoasted. A “host” is someone who can host meetings under a customer account. “You” or “user” or “participant” is anyone who uses GetRoasted. (“You” and “user” may also include customers. Some of the information below applies only to customers, though, and we use “customer” to highlight those places.)Data you give us (or that we may receive from another GetRoasted user, for example: emails, numbers, your messages are all kept private. Only the actual video would we possibly use for advertisement (unless you request otherwise). Data that our system collects from you: Technical information about your devices, network, and internet connection, IP address, MAC address, other device ID (UDID), device type, operating system type and version, client version, type of camera, microphone or speakers, connection type, etc.
The phone number of a person making a call using GetRoasted services (e.g. GetRoasted Phone)Connect you to and optimize your experience using our services
Provide customers dashboards and reports
Respond to requests for support
Monitor performance of our data centers and networks
Conduct anonymized, aggregated analytics to improve GetRoasted's service performance Approximate LocationTo the nearest city (we do not “track” your specific location)Connect you to the nearest data center
Comply with privacy and other laws – for example, so we can provide you with the right notices for your area
Suggest choices such as language preferences
Monitor performance of our data centers and networks
Respond to requests for supportInformation about how you use GetRoasted (this is NOT information or content you share in your meetings or in chats)Did you use VoIP or a phone call?
Did you shift from the mobile client to the desktop?Optimize your GetRoasted experience
Respond to requests for support
Conduct anonymized, aggregated analytics to improve GetRoasted's performance.Setting and preferences chosen by the userJoin with video off
Require meeting password
Enable waiting room
Do not allow screen sharing other than hostTo provide you choices for how you use GetRoastedMetadataDuration of the meeting / GetRoasted Phone call
Email address, name, or other information that a participant enters to identify themselves in the meetingJoin and leave time of participants
Name of the meeting
Date / time that meeting was scheduled
Chat status (unless a setting is actively chosen by user)
Call data records for GetRoasted PhoneProvide GetRoasted services
Provide customers dashboards and reports
Respond to requests for support
GetRoasted Marketing Sites
GetRoasted may also gather data from you when you visit our marketing websites, such as GetRoasted.us and GetRoasted.com. These are our webpages that tell you about our product, plans and pricing, features, and other information about GetRoasted. The categories of data we collect from our websites include: data you choose to give us; data we may obtain from cookies or similar analytics tools; data we receive from referrals by other customers; and data we collect if you choose to answer any marketing communications. As used in this section, “you” means visitors to our marketing pages or people who do the things we describe here. (“You” here does not mean a user of GetRoasted services.)Data you can choose to give us: Type of DataExamplesGetRoasted Uses it toInformation that identifies youYour name, username, physical address, email address, phone numberCreate an account when you sign up
Respond to requests from you
Send you marketing communications, unless you tell us not to (or if you say it’s OK, i.e., opt-in)Information about your jobCompany, title, departmentProvide tailored information
Respond to requests from youPayment informationCredit/debit card (goes directly to our payment processor; credit card information is not accessed or stored by GetRoasted)Charge you when you sign up for a paid plan
Data we may obtain about you:
and the Cookie section below)Analyze how our website is used so we can improve your experience
Allow you to do things like completing orders, sharing pages, and remembering settings.
Evaluate the success of our Marketing campaigns
Send you tailored GetRoasted advertising when you are on other sites.
)Third PartiesData Enrichment servicesMailing ListsPublic SourcesSend you marketing communications, unless you tell us not to (or if you say it’s OK, i.e., opt-in)
Provide tailored information based on your interests
Cookies and Automated Collection of Data
. Our Referral ProgramYou can use our referral program to tell others about GetRoasted. When you do, you will be asked to provide that person’s name and email so that we can contact them. We rely on you to make sure the person you are referring to us has agreed to be contacted. We will send a one-time email inviting them to visit the marketing site. Unless that person says they want to hear more, we will only use their name and email address to send this one-time email and to maintain an activity log of our referral program.
You can sign up to receive email or newsletter communications from us. If you would like to stop receiving these communications, you can update your preferences by using the “Unsubscribe” link found in these emails, or by emailing email@example.comWe may send you push notifications to update you about any events or promotions that we may be running. If you don’t want to receive these types of communications, you can turn off the setting on your device that allows these notifications to be delivered.
Additional Data Uses
Specific Requests. In addition to the uses described above, GetRoasted may also receive data from you for specific purposes. When you give it to us, we use the data for that specific purpose:To keep you up to date on the latest Service announcements, software updates, upgrades, system enhancements, special offers, and other informationTo run opt-in contests, sweepstakes or other promotional activities To provide you with information and offers from us or third partiesIf you choose to participate, to conduct questionnaires and surveys to provide better services to our customers and end usersTo personalize marketing communications and website content based on your preferences, such as in response to your request for specific information on products and services that may be of interest.Comply with legal obligations. We use data to detect, investigate and stop fraudulent, harmful, unauthorized or illegal activity. We also use data to comply with our contractual and legal obligations, resolve disputes with users, and enforce our agreements, if needed.Disclosures
During use of GetRoasted. When you use GetRoasted, some data will be disclosed to other participants and to meeting or webinar hosts. For instance, when you attend a meeting, your name might appear in the attendee list. If you turn on your video camera, your image will be shown. If you send a chat or share content, that can be viewed by others in the chat or the meeting.Customer Content, Dashboards and Reports. Customer content, including information shared during meetings, information about participants in meetings and any recordings of meetings, belongs to our customers. Customers may use this content, which may include personal data about participants, for their own purposes. Customers may also receive data we collect (for example, participants’ names) when they generate GetRoasted dashboards and usage reports for themselves.At the direction of our Customers. As described more below, under the EU’s GDPR, GetRoasted is a “Processor” of customer content and personal data that our Customers may put into our systems when they use GetRoasted. Our customers are the “Controllers”. We follow their directions regarding this data, and may store it, delete it, or disclose it at their direction.For Legal Reasons. We may also disclose data when we respond to valid legal process including jurisdiction. GetRoasted's policies regarding compliance with valid legal process preclude cooperation where a government does not have jurisdiction. GetRoasted may also disclose data when reasonably necessary to preserve GetRoasted's legal rights.To Third Party Service Providers. We use third-party service providers to help us provide portions of the GetRoasted services and give support. Examples of these third parties include public cloud storage vendors, carriers, our payment processor, and our service provider for managing customer support tickets. They only receive data needed to provide their services to us. We have agreements with our service providers that say they cannot use any of this data for their own purposes or for the purposes of another third party. We prohibit our service providers from selling data they receive from us or receive on our behalf. We require service providers to use data only in order to perform the services we have hired them to do (unless otherwise required by law). For example, we may use a company to help us provide customer support. The information they may receive as part of providing that support cannot be used by them for anything else. For more information about our service providers, please see our Sub-processors page
.Does GetRoasted sell Personal Data?We do not sell your data.We do not allow marketing companies, advertisers or similar companies to access personal data in exchange for payment. We do not allow third parties to use any personal data obtained from us for their own purposes, unless you consent (e.g., when you download an app from the Marketplace). Our customers may use the webinar service to generate their own marketing leads and they may provide marketing information to you. When you register for a webinar, you provide your data to the host of the webinar, and if required, any consent that you give about your data would be to them, as well. GetRoasted may keep the data about the registration in our system in order to facilitate the webinar, but GetRoasted does not use or share that data other than to provide the services. A customer may also charge for their webinars. Again, that transaction is between the host and participant of the webinar. GetRoasted is not selling any data.As described in the GetRoasted marketing sites section, GetRoasted does use certain standard advertising tools on our marketing sites which, provided you have allowed it in your cookie preferences, sends personal data to the tool providers, such as Google. This is not a “sale” of your data in the sense that most of us use the word sale. However, California’s CCPA law has a very broad definition of “sale”. Under that definition, when GetRoasted uses the tools to send the personal data to the third-party tool providers, it may be considered a “sale”. It is important to know that advertising programs have always worked this way and we have not changed the way we use these tools. It is only with the recent developments in data privacy laws that such activities may fall within the definition of a “sale”.Because of CCPA’s broad definition, as is the case with many providers since the CCPA became law, we provide a “Do Not Sell My Personal Information” link at the bottom of our marketing sites. You can use this link to change your Cookie Preferences and opt out of the use of these advertising tools. If you opt out, Personal Data that was used by these tools will no longer be shared with third parties in a way that constitutes a “sale” under CCPA.Data Retention
We will retain personal data collected for as long as required to do what we say we will in this policy, unless a longer retention period is required by law. Customers can delete their own content.Transfer and Storage of Personal Data
GetRoasted services generally store data in the United States, though through our global data centers, data may come in from wherever users are located. We may transfer your data to the U.S., or to third parties acting on our behalf, for the purposes of processing or storage. Our customers may choose to have their data stored outside of the U.S; for example, they may choose to have their data stored in their geographic vicinity. We may store local data locally in order to comply with specific local laws and regulations. By using GetRoasted, or providing personal data for any of the purposes stated above, you consent to the transfer to and storage of your personal data in the U.S., or other location as directed by our customer. In certain limited circumstances, courts, law enforcement agencies, regulatory agencies, or security authorities in those other countries may be entitled to access your personal data.Security of your Personal Data
GetRoasted is committed to protecting your personal data. We use a combination of industry-standard security technologies, procedures, and organizational controls and measures to protect your data from unauthorized access, use, or disclosure. We recommend you take every precaution in protecting your data when you are on the Internet. For example, change your passwords often, use a combination of upper and lower-case letters, numbers, and symbols when creating passwords, and make sure you use a secure browser. If you have any questions about the security of your data, please contact our security team at firstname.lastname@example.orgLinked Websites and Third-Party Services
Our marketing websites may provide links to other third-party websites and services which are outside our control and not covered by this policy. We encourage you to review the privacy policies posted on these (and all) sites you visit or services you use.Data Subject Rights
Generally, when we obtain personal data, we do so on behalf of our customers. For purposes of GDPR and CCPA, our customer is the “Controller”, or decision maker, for the personal data, and we are the “Processor”, acting as a “service provider” for, and at the direction of, our customer. “Processing” just means doing something with the data. We are typically required to follow a customer’s instructions about personal data we hold for that customer. These are certain requests you can make related to personal data about you, which we will respond to as much as we can under applicable laws. (See below for other legal rights you may have with respect to your personal data depending on where you reside.) Access: You can request more information about the personal data we hold about you. You can request a copy of the personal data. Rectification: If you believe that any personal data we are holding about you is incorrect or incomplete, you can request that we correct or supplement the data. You can also correct some of this information directly by logging into your service account, if you are a customer. Please contact us as soon as possible if you notice any inaccuracy or incompleteness.Objection: You can let us know that you object to the collection or use of your personal data for certain purposes.Opt Out of “Sales”: You can ask us to take you out of certain advertising related to your personal data by clicking on the “Do Not ‘Sell’ My Personal Information” link. Erasure: You can request that we erase some or all of your personal data from our systems. For instructions on how to delete your account please email email@example.comRestriction of Processing: You can ask us to restrict further processing of your personal data. (This just means you can ask us to stop using it for what we have been using it for.) This may mean that we have to delete your account.Portability: You can ask for a copy of your personal data in a machine-readable format. You can also request that we transmit the data to someone else where it’s technically possible.Withdrawal of Consent: If we are processing your personal data based on consent that you gave us when we got the data, you may have the right to withdraw your consent at any time. For example, if you have signed up for marketing communications you can request to be removed from these communications.Right to File Complaint: You have the right to lodge a complaint about GetRoasted's practices with respect to your personal data with the supervisory authority of your country or EU Member State.Sometimes we will not be able to fulfill your request. If it prevents us from complying with our regulatory obligations or impacts other legal matters, if we cannot verify your identity, or if it requires extraordinary cost or effort, we will tell you in a reasonable time and give you an explanation. To make a request, please contact our Privacy Team at firstname.lastname@example.org or by writing to the following address:Varty, Inc.email@example.comIf you have a password protected GetRoasted account, we will use your account information to verify your identity. If not, we will ask you to provide additional verification information. What we request will depend on the nature of your request, how sensitive the information is, and how harmful unauthorized disclosure or deletion would be.Additional Information About Specific Regulations Residents of the European Union (EU), United Kingdom, Lichtenstein, Norway, Iceland or Switzerland
If you reside in the European Union (EU), United Kingdom, Lichtenstein, Norway, Iceland or Switzerland, you may have legal rights with respect to your personal data, including those set forth under the EU’s General Data Protection Regulation (GDPR). GDPR requires that we have a “basis” for processing your data. We process your personal data (i) with your consent (where applicable), (ii) to perform a contract with a customer, and (iii) for other legitimate interests and business purposes. Residents of the State of California
If you reside in California, you may have legal rights with respect to your personal data, including those set forth under the California Consumer Privacy Act (CCPA). If you are a California resident, you can request information about both the categories and specific pieces of data we have collected about you in the previous twelve months, the reason we collected it, the category of entities with whom we have shared it and the reason for any disclosure. GetRoasted is prohibited from discriminating against California consumers that choose to exercise their privacy-related rights under the CCPA. EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield
GetRoasted Video Communication, Inc. participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield. GetRoasted is committed to subjecting all personal data received from EU member countries, Switzerland, and the United Kingdom, in reliance on the Privacy Shield Frameworks, to the Framework's applicable Principles. To learn more about the Privacy Shield Frameworks, and to view our certification, visit the U.S. Department of Commerce's Privacy Shield List, https://www.privacyshield.gov/list
.GetRoasted is responsible for the processing of personal data it receives under the Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. GetRoasted complies with the Privacy Shield Principles for all onward transfers of personal data from the EU, Switzerland, and the United Kingdom including the onward transfer liability provisions.With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, GetRoasted is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, GetRoasted may be required to disclose personal data in response to valid and lawful requests by public authorities or pursuant to requests from law enforcement.If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request
.Under certain conditions, more fully described on the Privacy Shield website https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint, you can invoke binding arbitration when other dispute resolution procedures have been exhausted.Standard Contractual Clauses
In certain cases, GetRoasted will transfer personal data from the EU in accordance with the European Commission-approved Standard Contractual Clauses, a copy of which can be obtained at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32010D0087
.Contact Us: firstname.lastname@example.org