StockX Privacy Policy - Your Privacy Rights

StockX Privacy Policy

April 8th, 2022

StockX LLC and its affiliates (“StockX”, “we”, “our” and/or “us”) are committed to protecting your privacy.

In this Privacy Policy (“Privacy Policy”), “Personal Information” means any information relating to an identified or identifiable individual and “Services” mean our websites (“Sites”), including https://stockx.com/, our mobile apps (“Apps”), and other services that link to this Privacy Policy.

This Privacy Policy describes how we collect, process, and share Personal Information in the context of our Services. This Privacy Policy does not cover the practices of companies we don’t own or control, or people we don’t manage. By using the Services, you acknowledge you have read and understood this Privacy Policy.

Table of contents

  1. Personal Information we collect about you
  2. How we use your Personal Information
  3. With whom we share your Personal Information
  4. How we transfer your Personal Information
  5. How we protect your Personal Information
  6. How long we keep your Personal Information
  7. Your rights
  8. Personal Information of children
  9. Third parties
  10. Changes to this Privacy Policy
  11. Contact us
  12. Region-specific sections

  1. Personal Information we collect about you

We collect and process Personal Information about you or your devices from various sources described below.

  1. Personal Information you provide to us

This is Personal Information about you that you provide directly to StockX, including:

  • Region and language. When you visit our Sites or Apps, we may ask you to select your region and language to provide you with the relevant Services.
  • Registration and profile information. If you sign up for an account on our Services, we will ask you to provide your name and email address, to choose a password, and to select one or more areas of interest (e.g., sneakers, streetwear, watches etc.).
  • Buying / Selling information. In order to allow you to purchase or sell a product via our Services, we may additionally ask you to provide your postal and billing address, phone number, and VAT ID (in order to apply VAT discounts). In some jurisdictions, we may also collect your social security number or national ID where we are required by law to collect such information in order to provide you with the Services. We will not collect or store the credit or debit card or other payment information that you may provide in the context of the Services. Payments made on the Services using a credit or debit card are made through a third party payment gateway provider. You will be providing credit or debit card information directly to that payment gateway provider which operates a secure server to process payment details, encrypting your credit or debit card information and authorizing payment. Personal Information that you supply to third parties is not within our control and is subject to those third parties’ privacy policies and terms of service.
  • Newsletter. If you sign up to receive emails or information about our Services, then we will collect Personal Information from you, such as your first and last name, email address, and your areas of interest. When we send you emails, we may track whether you open them to learn how to deliver a better customer experience and improve our Services.
  • Communications. When you contact us via a contact form, email, phone, or other means (e.g., to submit a query, to enter a competition, promotion or survey, or to report a problem with our Services), you may provide us with Personal Information, such as your name and contact details, language, and the content, date, and time of our communications.
  • Careers. If you apply for a job with us directly, you may provide us with your resume, name and contact details, and any other information that you submit to us. If you apply for a job with us through a third-party platform (such as LinkedIn), we will collect the information you make available to us through such a third-party platform.

In some cases, provision of your Personal Information may be necessary to provide you with our Services. In these cases, if you fail to provide certain Personal Information when requested, we may not be able to give you access to our Services. In other cases, for example when we request your Personal Information so that we can send you marketing and promotional communications, if you do not provide Personal Information we will not send you the marketing and promotional communications. We will specify the consequences of refusal to provide Personal Information at the time of the collection.

  1. Information we collect about you from your use of our Services

When you use our Services or open our emails, we may collect certain information via automated means such as cookies, beacons, invisible tags, and similar technologies (collectively “Cookies”). These typically involve pieces of information or code that a website transfers to or accesses from your computer hard drive or mobile device to store and sometimes track information about you.

  • Types of information collected via Cookies. We may collect the following types of information via Cookies:
  • Technical information. Technical information may include the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform.
  • Usage information. Information about your visit may include the full Uniform Resource Locators (URL), clickstream to, through and from our Services (including date and time), products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, and any phone number used to call our customer service number or social media handle used to connect with our customer service team.

  • Use of information collected via Cookies. Cookies enable you to be remembered when using that computer or device to interact with websites and online services and can be used to manage a range of features and content as well as storing searches and presenting personalized content. We and our third-party partners use Cookies to distinguish you from other users of our Services. This helps us to provide you with a good experience when you use our Services and allows us to improve them. You can find more information about the individual Cookies we use and the purposes for which we use them here. The types of Cookies we use can be classified as follows:
  • Strictly necessary cookies. These Cookies are required for the operation of our Services and under our terms with you. They include, for example, Cookies that enable you to log into secure areas of our Services, use a shopping cart, or make use of e-billing services.
  • Analytical/performance cookies. These Cookies allow us to recognize and count the number of users and to see how users move around our Services. This helps us to improve the way our Services work, for example, by ensuring that users are finding what they are looking for easily.
  • Functionality cookies. These Cookies are used to recognize you when you return to our Services. This enables us to personalize our content, and remember your preferences (for example, your choice of language or region).
  • Targeting cookies. These Cookies record your visit to our Services, the pages you have visited and the links you have followed. We will use this information to make our Services and the advertising displayed on them more relevant to your interests (as further set forth below). We may also share this information with third parties for this purpose.

We may also work with advertising networks that gather information about the content you visit on our Services and other websites and services you visit. This may result in you seeing advertisements through our Services or our advertisements when you visit other websites and services of third parties. For more information about how to turn this feature off see below or visit http://www.youronlinechoices.co.uk.

We may serve advertisements, and also allow third-party ad networks, including third-party ad servers, ad agencies, ad technology vendors and research firms, to serve advertisements through the Services. These advertisements may be targeted to users who fit certain general profile categories or display certain preferences or behaviors (“Interest-Based Ads”). Information for Interest-Based Ads (including Personal Information) may be provided to us by you, or derived from the usage patterns of particular users on the Services and/or services of third parties. Such information may be gathered through tracking users’ activities across time and unaffiliated properties, including when you leave the Services. To accomplish this, we or our service providers may deliver Cookies, including a file known as a “web beacon” from an ad network to you through the Services. Web beacons allow ad networks to provide anonymized, aggregated auditing, research and reporting for us and for advertisers. Web beacons also enable ad networks to serve targeted advertisements to you when you visit other websites. Web beacons allow ad networks to view, edit or set their own Cookies on your browser, just as if you had requested a web page from their website.

We may also use analytics services such as Google Analytics to collect and process certain analytics data. These services may also collect information about your use of other websites, apps, and online resources. You can learn about Google’s practices by going to https://www.google.com/policies/privacy/partners/ and opt-out of them by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout.

Where required by applicable law, we will obtain your consent to use Cookies. You can find more information about your rights and choices, and how to block the use of certain Cookies below.

  • Cookies Preferences. You may change your Cookies preferences as described below. Where you have not set your permissions, we may separately prompt you regarding our use of Cookies on the Services. However, you may not be able to take full advantage of our Services if you disable certain Cookies. The effect of disabling Cookies depends on which Cookies you disable but, in general, the Services may not operate properly if all Cookies are switched off. If you only disable third party Cookies, you will not be prevented from making purchases on our Services. If you disable Cookies, you will be unable to complete a purchase on our Services.
  • Browser settings. Most web browsers automatically accept Cookies, but if you prefer, you can change your browser settings to prevent cookies. How you can do this will depend on the browser you use (see your browser help screen for details).
  • DAA and NAI. We comply with the Digital Advertising Alliance (“DAA”) Self-Regulatory Principles for Online Behavioral Advertising. Through the DAA and Network Advertising Initiative (“NAI”), several media and marketing associations have developed an industry self-regulatory program to give consumers a better understanding of, and greater control over, ads that are customized based on a consumer’s online behavior across different websites and properties. To make choices about Interest-Based Ads from participating third parties, including to opt-out of receiving behaviorally targeted advertisements from participating organizations, please visit the DAA’s or NAI’s consumer opt-out pages, which are located at http://www.networkadvertising or www.aboutads.info/choices. Users in the European Union should visit the European Interactive Digital Advertising Alliance’s user information website http://www.youronlinechoices.eu/. Users in Canada should visit the Canadian Digital Advertising Alliance’s user information website https://youradchoices.ca/
  • DNT. Please note that because of our use of Cookies, the Services do not support “Do Not Track” requests sent from a browser at this time.

  • Duration of Cookies. A number of Cookies we use last only for the duration of your session and expire when you close your browser or exit the App. Others are used to remember you when you return to the Services and will last longer..

  1. Information we receive from third parties

  • Social Sign-In. We may collect Personal Information about you when you sign up or log in to our Services via third party services (such as Google, Facebook, Apple, Twitter). This information may include your social media user ID and email address.
  • Third-Party Services. You may also post photos, comments, or reviews on our pages available through third-party platforms. If you do so, we and other users on those third-party platforms may be able to view the Personal Information you make available through these third-party platforms.
  • Partners. We receive additional Personal Information about you (such as demographic, census, mail order responses for categories of interest) from third parties (such as partners and third party data providers that provide information about you or location information based on your IP address) or marketing partners and combine it with other Personal Information we have about you.

  1. How we use your Personal Information

If you are located in the European Economic Area (“EEA”) or the United Kingdom (“UK”), you can see the categories of Personal Information we process, the purpose for which we process it and the lawful basis on which it is processed below, under the “EEA and UK residents” section at the bottom of this Privacy Policy.

We use your Personal Information to:

  • Provide you with our Services, including to administer your account with us, notify you about changes to our Services, and allow you to participate in interactive features of our Services, when you choose to do so.

  • For internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes.

  • Ensure that content from our Services is presented in the most effective manner for you and for your computer.

  • Perform marketing analysis and provide you with promotional updates and information about our products we feel may interest you, including via email and SMS messaging. You can object to further marketing at any time by managing your account settings or selecting the “unsubscribe” link at the end of our marketing and promotional update communications to you. Personal Information obtained through SMS short codes and email will not be shared with third parties for those third parties’ marketing purposes.
  • Deliver relevant content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you.
  • Keep our Services safe and secure (including fraud prevention via third-party identity verification services).

  • Analyze and improve our Services, and develop new products and services.

  • For compliance purposes, including enforcing our legal rights, or as may be required by applicable laws and regulations including anti-money laundering and sanctions compliance, as well as for other purposes for which we obtain your prior consent or provide specific notice at the time Personal Information is collected.

  1. With whom we share your Personal Information

We may disclose Personal Information we collect from or about you as described below or otherwise disclosed to you at the time of collection.

  • StockX group. Any member of our group, which includes our subsidiaries, our ultimate holding company, and its subsidiaries, who support our processing of Personal Information.
  • Service providers. We may also share your Personal Information with service providers (“processors”) that perform services on our behalf (e.g., customer support). For an updated list, please click here. This includes payment processing providers who provide secure payment processing services. Note your payment card details are not shared with us by the provider.
  • Other selected third parties. Our selected third parties may include:
  • Analytics and search engine providers that assist us in the improvement and optimization of our Services.
  • Advertising Partners that we work with that show you ads that we think may interest you and provide ad measurement services to us. In “Cookies Preferences” above, we describe options for opting out of the sharing of your data for these purposes.
  • Business partners who jointly with us provide Services to you.
  • Other parties at your direction, including:
  • Other users (where you post information publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services).
  • Social media services (if you intentionally interact with them through your use of the Services).
  • Third-party business partners that you access through the Services.
  • Other parties authorized by you.
  •  Merger, sale, or other asset transfers. In connection with the consideration, negotiation, or completion of a corporate transaction in which we sell or transfer all or a portion of our business or assets.
  • As required by law and similar disclosures. If we are under a duty to disclose or share your Personal Information in order to comply with any legal obligation, regulation, process or governmental request, or in order to enforce or apply our terms and other agreements with you; or to protect the rights, property, or safety of StockX, our customers, or others. This includes exchanging information with other companies and organizations, including law enforcement agencies, for the purposes of fraud protection and to prevent cyber or other suspected or alleged crime.
  • With your consent. We may also disclose Personal Information from or about you or your devices with your permission obtained in accordance with applicable law.

  1. How we transfer your Personal Information

We may transfer your Personal Information to the United States and other countries that may not have the same data protection laws as the country in which you initially provided the information for purposes such as storage and processing of data, fulfilling your requests, and operating our Services.

We comply with applicable legal requirements when transferring Personal Information to countries other than the country where you are located. If you are located in the EEA or the UK , we will transfer Personal Information to countries for which adequacy decisions have been issued (see list of countries for which the European Commission has issued an adequacy decision here), use contractual protections for the transfer of Personal Information to third parties, such as the European Commission’s Standard Contractual Clauses or their equivalent under applicable law, or rely on other data transfer mechanisms where applicable. Depending on your country, you may contact us as specified below to obtain a copy of the safeguards we use to transfer Personal Information outside of your jurisdiction.

  1. How we protect your Personal Information

All information you provide to us is stored on our secure servers. Where we have given you (or where you have chosen) a password that enables you to access certain parts of our Services, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your Personal Information, we cannot guarantee the security of your data transmitted to our Services; any transmission is at your own risk. Once we have received your Personal Information, we will implement appropriate technical and organizational measures to protect it from unauthorized access, loss, destruction or alteration.

  1. How long we keep your Personal Information

We delete your Personal Information or keep it in a form that does not identify you when this information is no longer necessary for the purposes for which we process it, unless we are required by law to keep this information for a longer period. When determining the retention period, we take into account various criteria, such as the nature and length of our relationship with you, possible re-enrolment with our Services, the impact on our ability to provide you with certain features of our Services if we delete some information from or about you, mandatory retention periods provided by law and the statute of limitations. We may also retain aggregate information beyond this time for research purposes and to help us develop and improve our Services. You cannot be identified from aggregate information retained or used for these purposes.

  1. Your rights

Depending on your jurisdiction and under certain circumstances, you may have the following rights:

  • to be provided with a copy of your Personal Information held by us;
  • to request the rectification or erasure of your Personal Information held by us;
  • to request that we restrict the processing of your Personal Information (while we verify or investigate your concerns with this information, for example);
  • to object to the further processing of your Personal Information, including the right to object to marketing communications, if applicable. If you object to the processing of your Personal Information for marketing purposes, this will also apply to any processing of your Personal Information for profiling purposes to the extent that it is related to such marketing purposes. You can also object to the data processing for profiling purposes only;
  • to request that your Personal Information be provided to you in a structured, commonly used and machine-readable format to transmit them to a third party;
  • to provide instructions about your Personal Information after death; and
  • to withdraw consent where the processing of your Personal Information by us is based on consent, without detriment at any time by managing your account settings or contacting us as indicated in the “Contact us” section below. We will apply your preferences going forward and this will not affect the lawfulness of the processing before your consent withdrawal.

You may exercise some of the rights listed above by contacting us at SRR Request. For a third party on your behalf, the third party can contact us at 3rd Party Request.

If you wish to raise a complaint, please contact us as indicated in the “Contact us” section below.

If your request or concern is not satisfactorily resolved by us, or you have another complaint regarding the Personal Information processing, where applicable, you may approach your local data protection authority, including in your country of residence, place of work, or where an incident took place (to access a list of the EEA data protection authorities, see https://edpb.europa.eu/about-edpb/about-edpb/members_en).

  1. Personal Information of children

We do not knowingly collect or solicit Personal Information from children under 16; if you are a child under 16, please do not attempt to register on or otherwise use the Services or send us any Personal Information. If we learn we have collected Personal Information from a child under 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us with their Personal Information, please contact us as indicated in the “Contact us” section below.

  1. Third parties

Our Services may contain links to other websites, products, or services that we do not own or operate. We are not responsible for the privacy practices of these third parties. Please be aware that this Privacy Policy does not apply to your activities on these third party services or any information you disclose to these third parties. We encourage you to read their privacy policies before providing any information to them.

  1. Changes to this Privacy Policy

Any changes we make to our Privacy Policy in the future will be posted on this page. If we make material changes to this Privacy Policy or the ways in which we use or share personal information previously collected from you, we will notify you by email or other communication.

  1. Contact us

You may find additional information and tips in our Help Center available at https://stockx.com/help. If you cannot find the information you are looking for in the Help Center, you may contact us at [email protected] or, if you are located in the EEA or the UK, at [email protected].

The entity responsible for the processing of your Personal Information (“data controller”) is:

StockX LLC

1046 Woodward Avenue,
Detroit, MI 48226 USA
Email: [email protected]
Fax: 1-800-332-9360

  1. Region-specific sections

  1. Nevada Resident Rights

If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Information to third parties who intend to license or sell that Personal Information. You can exercise this right by contacting us as indicated in the “Contact us” section above and providing us with your name, account and the email address associated with your account. Please note that we do not currently sell your Personal Information as sales are defined in Nevada Revised Statutes Chapter 603A.

  1. California Resident Rights

If you are a California resident, you have the rights outlined in this section. Please see the “Exercising Your Rights” section below for instructions regarding how to exercise these rights. If there are any conflicts between this section and any other provision of this Privacy Policy and you are a California resident, the portion that is more protective of Personal Information shall control to the extent of such conflict. If you have any questions about this section or whether any of the following applies to you, please contact us as indicated in the “Contact us” section above.

Additional information about the Personal Information we collect about you

The following chart details the categories of Personal Information that we collect and have collected over the past twelve (12) months. Throughout this Privacy Policy, we will refer back to the categories of Personal Information listed in this chart (for example, “Category A. Personal identifiers”).

Category of Personal Information

Personal Information Collected

A.

Personal identifiers

 

Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name.

B.

Customer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e)))

Name, address, and telephone number.

C.

Commercial information

Products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

D.

Internet or other similar network activity information

Browsing history, search history, or information on a consumer's interaction with a website, application or advertisement.

E.

Professional or employment-related information

Job application, resume.

In the preceding twelve months since this notice was last updated, we disclosed your Personal Information to the following categories of third parties:

  1. Vendors: Vendors and service providers.
  • Personal Information we share: Personal identifiers, Customer records identified by state law, Commercial information, Internet or other similar network activity information, Professional or employment-related information.
  1. Advertising Providers: Advertising technology companies, such as advertising networks.
  • Personal Information we share: Personal identifiers, Internet or other similar network activity information.
  1. Analytics Providers.
  • Personal Information we share: Personal identifiers, Internet or other similar network activity information.
  1. Payment Service Providers:
  • Personal Information we share: Personal identifiers, Customer records identified by state law, Commercial information.
  1. Business Partners: Business partners who jointly with us provide Services to you.
  • Personal Information we share: Personal identifiers, Customer records identified by state law, Commercial information.
  1. Government: Government entities, such as customs and duties officials.
  • Personal Information we share: Personal identifiers, Customer records identified by state law, Commercial information, Internet or other similar network activity information.
  1. Social Networks.
  • Personal Information we share: Personal identifiers, Customer records identified by state law.
  1. Affiliates.
  • Personal Information we share: Personal identifiers, Customer records identified by state law, Commercial information, Internet or other similar network activity information, Professional or employment-related information.
  1. Integrated Third Parties: Third parties integrated into our services.
  • Personal Information we share: Personal identifiers, Customer records identified by state law, Internet or other similar network activity information.
  1. Third Parties as Legally Required: Third parties as required by law and similar disclosures.
  • Personal Information we share: Personal identifiers, Customer records identified by state law, Commercial information, Internet or other similar network activity information, Professional or employment-related information.
  1. Third Parties in Merger/Acquisition: Third parties in connection with a merger, sale, or asset transfer.
  • Personal Information we share: Personal identifiers, Customer records identified by state law, Commercial information, Internet or other similar network activity information, Professional or employment-related information.
  1. Third Parties with Consent: Other third parties for whom we have obtained your permission to disclose your Personal Information.
  • Personal Information we share: Personal identifiers, Customer records identified by state law, Commercial information, Internet or other similar network activity information, Professional or employment-related information.

In the preceding twelve months since this notice was last updated, we have collected Personal Information from the following categories of sources:

  1. You
  2. Our third party service providers
  3. Social Networks
  4. Third party data providers

Access

You have the right to request certain information about our collection and use of your Personal Information over the past 12 months. We will provide you with the following information:

  • The categories of Personal Information that we have collected about you.
  • The categories of sources from which that Personal Information was collected.
  • The business or commercial purpose for collecting or selling your Personal Information.
  • The categories of third parties with whom we have shared your Personal Information.
  • The specific pieces of Personal Information that we have collected about you.

If we have disclosed your Personal Information for a business purpose over the past 12 months, we will identify the categories of Personal Information shared with each category of third party recipient.

Deletion

You have the right to request that we delete the Personal Information that we have collected from you. Under the California Consumer Privacy Act (“CCPA”), this right is subject to certain exceptions: for example, we may need to retain your Personal Information to provide you with the Services or complete a transaction or other action you have requested. If your deletion request is subject to one of these exceptions, we may deny your deletion request.

Exercising Your Access and Deletion Rights

To exercise the rights described above, you must send us a request that (1) provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Information, and (2) describes your request in sufficient detail to allow us to understand, evaluate, and respond to it. Each request that meets both of these criteria will be considered a “Valid Request.” We may not respond to requests that do not meet these criteria. We will only use Personal Information provided in a valid request to verify you and complete your request. You do not need an account to submit a Valid Request.

We will work to respond to your Valid Request within 45 days of receipt. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive, or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.

You may submit a Valid Request to exercise the rights listed above at any time by contacting us at SRR Request or sending an email to the email address indicated in the “Contact us” section above. For a third party on your behalf, the third party can contact us at 3rd Party Request.

Opting Out of Sales

In some cases, we share identifiers, usage data, and Commercial information with business partners in order to deliver ads that are more relevant to you and to measure and report on the effectiveness of our advertising campaigns. Under the CCPA, some of this data sharing may be broadly considered a “sale” of information, even though these activities do not fit what most people would understand “sale” to mean. Except for this type of sharing, we do not sell your information. Please send an email to [email protected] to opt out of the sale of your Personal Information.

We Will Not Discriminate Against You for Exercising Your Rights Under the CCPA

We will not discriminate against you for exercising your rights under the CCPA. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise your rights under the CCPA. However, we may have different tiers of services as allowed by applicable data protection laws (including the CCPA) with varying prices, rates, or levels of quality of the goods or services you receive related to the value of Personal Information that we receive from you.

  1. EEA and UK residents

If you are located in the EEA or the UK, this section applies to you. This table sets out:

  • What Personal Information we process
  • For what purpose we process Personal Information
  • The legal basis for the processing

Purpose/Activity

Type of data

Legal basis for processing

Provide you with our Services, including to administer your account with us, notify you about changes to our Services, and allow you to participate in interactive features of our Services, when you choose to do so.

Any Personal Information we collect about you, in particular:

(a) Account information

(b) Information about your activity related to purchases and sales on StockX

(c) Information collected via Cookies

(a) Performance of a contract with you (Art 6 (1) (b) GDPR)

For internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes.

Any Personal Information we collect about you, in particular:

(a) Account information

(b) Information about your activity related to purchases and sales on StockX

(c) Information collected via Cookies

(a) Performance of a contract with you (Art 6 (1) (b) GDPR)

(b) Necessary for our legitimate interests (Art 6 (1) (f) GDPR: to operate and improve our Services)

(c) Consent (Art 6 (1) (a) GDPR)

Ensure that content from our Services is presented in the most effective manner for you and for your computer.

Any Personal Information we collect about you, in particular:

(a) Account information

(b) Information collected via Cookies

(a) Necessary for our legitimate interests (Art 6 (1) (f) GDPR: customize our Services to you)

Perform marketing analysis and provide you with promotional updates and information about our products we feel may interest you.

Any Personal Information we collect about you, in particular:

(a) Account information

(b) Information about your activity related to purchases and sales on StockX

(c) Information collected via Cookies

(a) Consent (Art 6 (1) (a) GDPR)

(b) Necessary for our legitimate interests (Art 6 (1) (f) GDPR: market our Services to you)

Deliver relevant  content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you.

Any Personal Information we collect about you, in particular:

(a) Account information

(b) Information collected via Cookies

(a) Consent (Art 6 (1) (a) GDPR)

(b) Necessary for our legitimate interests (Art 6 (1) (f) GDPR: advertise our Services to you)

Keep our Services safe and secure.

Any Personal Information we collect about you, in particular:

(a) Account information

(b) Information about your activity related to purchases and sales on StockX

(c) Information collected via Cookies

(a) Performance of a contract with you (Art 6 (1) (b) GDPR)

(b) Necessary for our legitimate interests (Art 6 (1) (f) GDPR: keep our Services safe)

For compliance purposes, including enforcing our legal rights, or as may be required by applicable laws and regulations.

Any Personal Information we collect about you, in particular:

(a) Account information

(a) Necessary to comply with a legal obligation (Art 6 (1) (c) GDPR)

(b) Necessary for our legitimate interests (Art 6 (1) (f) GDPR: enforce our legal rights)

  1. Mexican residents

If you are located in Mexico, this section applies to you.

Primary and Secondary Purposes

The purposes indicated in the  “How we use your Personal Information” section are primary purposes, with the exception of the following purposes which qualify as secondary purposes: (i) perform marketing analysis and provide you with promotional updates and information about our products we feel may interest you; (ii) deliver relevant content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you.

Exercising Your Rights

Your request must contain or be accompanied by: a) your full name and address, or other means to communicate the response to your request; b) compliance with any identity requests from our DSAR provider; c) a clear description of the right that you wish to exercise, and the Personal Information related to your request; and d) where appropriate, any other information or document that helps us locate your Personal Information. You may exercise some of the rights listed above by contacting us at SRR Request. For a third party on your behalf, the third party can contact us at 3rd Party Request.

We will answer your request within 20 (twenty) business days following the date it is received. If the request is complete and can be fulfilled, we will make it effective within 15 (fifteen) business days following the date on which we send our response. If the information and/or documentation provided in your request is incomplete, wrong and/or insufficient, or the documents necessary to prove your identity or the corresponding legal representation are not included, we will request additional information to be able to process your request. You will have 10 (ten) business days to provide us with the requested additional information; if you fail to provide the requested additional information, your request will be considered as withdrawn.

  1. South Korean residents

If you are located in South Korea, this section applies to you.

We destroy your personal information pursuant to the following procedure and method.

Destruction procedure. We select the personal information which is required to be destroyed and destroy it under the approval of the personal information protection officer.

Method of destruction. We destroy personal information recorded and stored in the form of electronic files in a way that it cannot be recovered, and personal information recorded and stored in the form of paper by shredding or incineration.

Department in charge of handling complaints related to personal information

Name: Compliance Department

Contact Information: Please see section 11 “Contact us” above.

  1. Japanese residents

Joint user of Personal Information. We may jointly use Personal Information with any member of our group, which includes our subsidiaries, our ultimate holding company, and its subsidiaries, and that supports our processing of Personal Information. The types of Personal Information that we would use jointly for the purposes described in Section 2 of this Privacy Policy are: name, contact information, and other Personal Information as described in Section 1 of this Privacy Policy. The name, address, and representative of the business operator responsible for the management of Personal Information are as follows: StockX LLC, 1046 Woodward Avenue, Detroit MI 48226, USA, Representative: see https://stockx.com/about/company/.

Information security management. We will take all necessary and appropriate measures to prevent leakage, loss, or damage of Personal Information and to safely manage Personal Information. The safety management measures we will take include the following:

  1. Development of rules on the handling of Personal Information. We have established rules on the handling of Personal Information that stipulate the handling methods with respect to Personal Information, the persons responsible for and in charge of the protection of Personal Information, and the duties of such persons.

  1. Organizational measures. We have appointed a person responsible for the handling of Personal Information, clarified the scope of Personal Information handled by employees handling Personal Information, and established a system for reporting information to the person in charge in the event of any violation of the laws or rules on the handling of Personal Information or any evidence of such violation. We regularly conduct self-inspections of the status of the handling of Personal Information and our auditing department regularly conducts audits.

  1. Security control measures involving Our Employees. We regularly train our employees on matters of concern regarding the handling of Personal Information. All of our employees owe confidentiality obligations regarding Personal Information.

  1. Physical security control measures. In areas under our control, such as our business sites, where Personal Information is handled, we control the entry and exit of employees and restrict devices, etc. brought in, and take measures to prevent unauthorized persons from viewing Personal Information. We take measures to prevent the theft or loss of equipment, electronic media, and documents that handle or contain Personal Information, and take measures to prevent Personal Information from being easily detected when transporting such equipment, electronic media, etc., including transportation within our business sites.

  1. Technical security control measures. Access control is implemented to limit the number of personnel in charge and Personal Information databases handled. We have introduced a mechanism to protect information systems that handle Personal Information from unauthorized access from outside sources or from unauthorized software.

  1. External environments. When Personal Information is handled or transferred outside Japan, safety management measures are implemented in compliance with legislation on the protection of Personal Information in the relevant countries where Personal Information is stored. Please contact us using our contact details above if you require further details on this point.