Privacy Policy

Last Modified: April 4, 2022

Principles

We protect the privacy of our users guided by the following principles:

  • Your pictures are YOUR property and yours alone.
  • Your pictures are private unless you share them. Your login and sharing functions allow you to control who sees your pictures and the content added to them.
  • You control how your pictures get distributed.
  • You will control who can add value to your pictures.
  • Our business is based on a paid subscription model. We will not “sell” your data or information about you to advertisers.
  • You are not the product. We will not sell your information to any third parties.
  • We will protect YOUR personal information as if it were our own.
  • We require our suppliers and partners to maintain the highest levels of security.
  • We do not store or maintain credit card data on our servers or website
  • All information is maintained in an encrypted form in a secure server environment protected by physical and electronic security precautions.

Privacy Notice

Ponga, Inc. (“Ponga”, “we” or “us”) values the privacy of the users of our services and applications (each a “User” or “you”), which include our website at ponga.com, and may include other websites, online services, mobile applications, content (e.g., widgets and feeds) and other services and applications offered by Ponga from time to time (collectively, the "Ponga Services"). Where additional information is needed to explain our privacy practices with respect to certain Ponga Services, we may post supplementary privacy notices to describe how we process personally identifiable information with respect to those Ponga Services.

Ponga provides this Privacy Notice to inform you of our policies and procedures regarding the collection, use and disclosure of information about you provided through the use of Ponga Services. Unless otherwise defined in this Privacy Notice, terms used in this Privacy Notice have the same meanings as in our Terms of Service (the "Terms of Service"), which may be accessed at ponga.com/tos.

What Information Do We Collect?

Information You Provide to Ponga

Registration and Account Data

When you sign up for a Ponga account, we ask you for a few pieces of personally identifiable registration information such as a name to use for display, a password, and email address. If you are a registered user of certain third party websites, services or applications, Ponga may provide you with the option of providing Ponga with your email, username, password and other credential information ("Credentials") to such third party website, service or application in order to register with Ponga through such third party website, service or application or in order for you to link your account with such third party website, service or application with your Ponga account.

Ponga will only use your Credentials to access your account with the applicable third-party website, service or application accounts to the extent necessary to access information to register your Ponga account or to provide you with the applicable Ponga Services and will otherwise keep your Credentials confidential. If you register for Ponga through a third party website, service or application, certain of your profile information from such third party website, service or application may be provided to Ponga. Any personal information transferred from your account with such third party website, service or application to your Ponga account will be collected used and disclosed by us only in accordance with this Privacy Notice. The amount and type of information we collect in the registration process will vary from time to time based on our business needs, but it is our goal to collect only the information that we need to provide and enhance the Ponga Services.

Transaction Data

We may also charge for certain Ponga Services or sell products or services through Ponga Services, and accordingly ask you to provide information, including information that may personally identify you, such as your credit card and shipping and/or billing information, in connection with your purchases of such products or services.

PCI-Certified. Our transaction processing partner has been audited by a PCI-certified auditor and is certified to PCI Service Provider Level 1. This is the most stringent level of certification available in the payments industry. To accomplish this, our payments systems make use of best-in-class security tools and practices to maintain a high level of security.

HTTPS. Our payments site forces HTTPS for all services using TLS (SSL), including our public website and is served only over TLS and connect to the servers over TLS and verify TLS certificates on each connection. Regular audits verify of the details of our implementation, the certificates we serve, the certificate authorities we use, and the ciphers we support. We use HSTS to ensure browsers interact only over HTTPS. Our payments system is also on the HSTS preloaded lists for both Google Chrome and Mozilla Firefox.

Encryption. All card numbers are encrypted at rest with AES-256. Decryption keys are stored on separate machines. None of the payment system’s internal servers and daemons are able to obtain plaintext card numbers; instead, they can just request that cards be sent to a service provider on a static whitelist. Stripe’s infrastructure for storing, decrypting, and transmitting card numbers runs in separate hosting infrastructure, and doesn’t share any credentials with the payment system’s primary services (API, website, etc.). The site utilizes two PGP keys to encrypt your communications, or verify signed messages you receive.

Information Collected by Ponga

Log Data

When you use Ponga Services, our servers automatically record certain information about your usage. These server logs may include information such as a device identifier, web requests, Internet Protocol ("IP") address, browser type, browser language, referring / exit pages and URLs, platform type, number of clicks, domain names, search terms, ratings, landing pages, pages viewed and the order of those pages, features used in the Ponga Services, the amount of time spent on particular screens, the dates and times of your requests, and one or more cookies that may uniquely identify your browser.

Cookies

When you use Ponga, we may send one or more cookies (small text files containing a string of alphanumeric characters) to your computer, mobile phone or another device through which you access the Ponga Services. Ponga may use both session cookies and persistent cookies. A session cookie disappears after you close your browser. A persistent cookie remains after you close your web browser and may be used by us during your subsequent visits to the Ponga Services. Persistent cookies set by Ponga can be removed. Third-party websites, services, and applications that are accessible through the Ponga Services or through which the Ponga Services may be accessed may also place or read cookies on your browser. Please review your web browser "Help" file to learn the proper way to modify your cookie settings. If you configure your browser to reject cookies, you may not be able to use Ponga Services that require you to sign in or take advantage of all the features of the Ponga Services.

Other Internet Tracking Technology

We do not currently, but may in the future use internet tracking technologies from time to time, to gather information on how our Users interface with the Ponga Services and to otherwise help us better manage content on the Ponga Services and efficiently operate and monitor the Ponga Services.

These technologies show us, for example, popular pages, conversion rates, click-through and other information that can be used to operate, monitor and improve the Ponga Services. In contrast to cookies, these technologies are typically embedded invisibly on web pages and not stored on a user’s computer hard drive.

Third-Party Embeds

Our technology allows us to display content in Ponga pictures not hosted on our servers. You as our subscribers, you have the ability to post content that is actually hosted by a third party, but is embedded in our pages (an “Embed”). When you interact with an Embed, it can send information about your interaction to the hosting third party just as if you were visiting the third party’s site directly. For example, when you paste a link for a YouTube video into a Ponga picture and share the picture, the video is embedded in the picture and can be watched without leaving the Ponga site. When you or other subscribers watch the video, YouTube receives information about your activity, such as your IP address and how much of the video you watch. Ponga does not control what information third parties collect through Embeds or what they do with the information. This Privacy Policy does not apply to information collected through Embeds. The privacy policy belonging to the third party hosting the Embed applies to any information the Embed collects, and we recommend you review that policy before interacting with embedded content.

Information Contributed by You and Other Users

Ponga Pictures and Other Data Contributed to Ponga

In creating your Ponga Pictures, you will contribute information in the form of photos, scanned text, drawings or other images, location information, notes, comments, links, contact details, specifications, dates, and other information; you may also contribute information in items created as part of third party services or applications which services or applications interface or interoperate with the Ponga Services or which items are otherwise usable within the Ponga Services. The Ponga Services may scan uploaded images to detect and match faces so you can associate names to faces. Matched faces are grouped for your convenience in using the service. Images of faces used in the detection function are retained by Ponga as protected personally identifiable information and used exclusively to deliver the service.

The Ponga Services may allow you to specify the privacy of your Ponga Pictures. Your pictures will be available only to you and any Users whom you have authorized to view them. You are not required to authorize any other Users to view your private Ponga Pictures, but if you do, certain levels of authorization will permit Users to comment on and otherwise contribute data or information to your Ponga Pictures, and these comments and other contributions can be seen by anyone who is authorized to view those Ponga Pictures.

You may further contribute information to Ponga by commenting on or otherwise contributing information or data to the Ponga Pictures of other Users or participating in other community activities that Ponga may offer from time to time, such as user forums, chat rooms, message boards or blogs. Your comments, and those others make on your pictures, trigger notifications that are shared via email and other notifications which may include the original image and added comments.

You are not required to disclose any personally identifiable information when creating your Ponga Pictures, contributing information to Ponga Pictures of other Users, or submitting or posting comments or other information through other community activities, but you will be able to do so in connection with the submitted or posted information that you generate. All information you post or submit through your Public Ponga Pictures or that you post or submit in other community activities is public information. All information you post or submit as a contribution to the Ponga Pictures of another User may be made public or available to other Users at the discretion of such other User. Accordingly, we urge you to use caution when including personally identifiable information in any such submissions or posts. We will not associate your registration information with your posts or submissions on Ponga Services, but they will be associated with your Ponga display name. Accordingly, we urge you not to use any sensitive information when selecting your display name.

Feedback

When you send email or other communications to us, we may retain those communications in order to process your inquiries, respond to your requests and improve the Ponga Services. For example, if you provide feedback to us, we may use and disclose such feedback for any purpose, provided we do not associate such feedback with your personally identifiable information unless we are authorized by you to do so. We will collect information contained in such feedback and will treat any personally identifiable information contained in it in accordance with this Privacy Notice.

Referrals

Ponga implements a referral service to allow you to share individual pictures, albums of pictures or to the Ponga Service itself. In such event, we will ask you to provide certain information about the individual you wish to invite. Ponga will automatically send that contact a one-time email inviting them to register for Ponga Services. Your contact may request Ponga to remove this information from our systems by sending an email to privacy@ponga.com.

How Do We Use Your Information and When May It Be Shared With Others?

General

We use the information we collect in the delivery and support of the Ponga Services and will not sell your personal information. Ponga does not disclose your personally identifiable information to other companies for their commercial use without your express consent or unless you have opted-in to be part of a specific program or feature in accordance with the applicable Ponga Services consent procedures.

Information Use

Ponga uses the information that we collect to provide our services and products and to operate our business. We may use and store such information for legitimate and lawful business purposes, for example, in order to:

  • create and manage your membership account;
  • fulfill and manage your membership benefits and purchases, orders, payments and other transactions;
  • analyze, evaluate, and improve member and prospective member needs, interests and trends, and improve the member and prospective member experience;
  • notify you (via email, telephone, mail and other means) of official Ponga business, news, activities, programs, events, meetings, conferences, services, products, benefits and offer new products, services and recommendations to you;
  • contact you (via email, telephone, mail and other means) regarding your member account, registrations or orders of our products and services;
  • send you newsletters and other communications;
  • deliver targeted promotions, coupons, newsletters, and other information related to the Website and our application to you;
  • track event, meeting, and conference attendance;
  • prepare invoices and process payments;
  • respond to communications and inquiries that you send to us;
  • promote the function, safety and security of our services;
  • for other legitimate and lawful business purposes, you will have the opportunity to opt out of any participation or use of your personal information.

Compliance and Enforcement

In addition to uses described elsewhere in this Privacy Notice, Ponga may release your information, if required to do so by law, or in the good-faith belief that such action is necessary to comply with state and federal laws or respond to a court order, subpoena, or search warrant. Ponga also reserves the right to disclose your information that Ponga believes, in good faith, is appropriate or necessary to: enforce our Terms of Service; take precautions against liability; protect Users from fraudulent, abusive, or unlawful uses; investigate and defend ourselves against any third-party claims or allegations; assist government enforcement agencies; protect the security or integrity of the Ponga Services; or protect the rights, property, or personal safety of Ponga, Users, or others.

Notices and Communications

We may use your personal information to send you notices relating to your Ponga account and your agreement for the use of Ponga Services, including any notices required by law. We may also use your personal information to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. We may also use this information for billing purposes and to fill orders for products and services. If you decide at any time that you no longer wish to receive such communications from us, please follow the unsubscribe instructions provided in any of the communications. Please note that you cannot unsubscribe from certain correspondence from us, including messages relating to your account transactions.

Aggregate Information and Non-Identifying Information

Information which does not contain personally identifiable information or from which we have removed personally identifiable information, for example by summarizing, aggregating or removing certain data elements, may be used by or shared with third parties. For example, Ponga may disclose aggregate, anonymous log file, and usage information in reports to interested third parties to assist those parties in understanding the usage patterns and performance results of certain content, services, promotions, or features.

Service Providers

We may employ third party companies and individuals to process your payments, facilitate the Ponga Services, to provide Ponga Services on our behalf, to perform services related to the Ponga Services (e.g., without limitation, maintenance services, face detection software, database management, web analytics and improvement of the Ponga Services' features) or to assist us in analyzing how the Ponga Services are used.

These third parties have access to Personal Information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. Images and files related to face detection and organizing functions to map names to faces are not stored or shared with third parties.  

Ponga makes use of Service Providers to provide state-of-the-art face detection and private recognition functions. While the functions can provide tremendous value to organizing photo collections, we cannot guarantee 100% accuracy in face detection or the association of recognized faces into collections.

Third-Party Sites, Services and Applications

We may make it possible for you to link to or otherwise access certain third party websites, services or applications from the Ponga Services. In some cases selected information may be provided to these third-party websites, services or applications if you are also a user of those third-party websites or applications, such as if you post one of your Ponga Pictures to Facebook or distribute a Ponga Picture through Twitter.

Third-party websites, services or applications may further link to or otherwise make it possible for you to access the Ponga Services from such websites, services or applications. This Privacy Notice applies to the Ponga Services only. Ponga is not responsible for the privacy practices of any third party websites, services or applications, whether or not they are accessible from the Ponga Services or the Ponga Services accessible from them.

Each such website, service or application may have data collection, storage and use practices that differ materially from this Privacy Notice. We encourage you to be aware when you leave the Ponga Services and to read the privacy statements of each and every such third party website, service, or application.

Business Transfers

In the event that Ponga is acquired by or merged with a third-party entity, we reserve the right, in any of these circumstances, to transfer or assign the information we have collected from our Users as part of such merger, acquisition, sale, or other change of control so that Ponga can continue operations. In the unlikely event of our bankruptcy, insolvency, reorganization, receivership, or assignment for the benefit of creditors, or the application of laws or equitable principles affecting creditors' rights generally, we may not be able to control how your personal information is treated, transferred, or used.

How Do We Protect the Integrity and Security of Personal Information?

Ponga is committed to protecting the security of all of the information you provide to Ponga. We take reasonable measures to protect the security and integrity of personally identifiable information that we collect, such as the following:

Your Ponga registered account information is protected by a password that you select for your privacy and security. While your password is protected by encryption, we encourage you to use “strong” passwords (that use a combination of upper and lower case letters, numbers and letters.) Please also make sure to protect your account information and log off when you are done using the Ponga Services, particularly if other users have access to the device you are using to access the Ponga Services.

Your images, comments, voice recordings and other data and information stored in our systems are protected in our data center with the following Global security certifications that provide physical, electronic and procedural safeguards:

As a rule, Ponga employees do not monitor or view your personal information or content stored in the Ponga Services, but it may be viewed if we learn that our Terms of Service may have been violated and confirmation is required, or we otherwise determine that we have an obligation to review it.

If Ponga learns of a security system breach we may attempt to notify you and provide information on protective steps, if available, through the e-mail address that you supplied during registration or posting a notice on our website.

However, Internet data transmissions, whether wired or wireless, cannot be guaranteed to be 100% secure, and no protection measures are perfect or impenetrable. As a result we cannot ensure the security of information you transmit to us; accordingly, you acknowledge that you do so at your own risk.

How Can You Update, Correct or Delete Your Information?

You may update, correct, or delete your settings and profile information in your Ponga Account at any time. To protect your privacy and security, we take reasonable steps to verify your identity before granting you profile access or making corrections. You are responsible for maintaining the secrecy of your unique password and account information at all times.

You may organize, modify or delete your Ponga Pictures, and associated information such as comments, notes and other information contained in Ponga Pictures. Such deletions or terminations will take immediate effect in your account view. Residual copies of deleted photos, associated data, or accounts may take up to 60 days to be deleted from our active servers and may remain in our backup systems.

Your Rights Under the GDPR

Under the European Union’s General Data Protection Regulation (GDPR) you have the following rights:

  • The right to be informed. We use this Privacy Notice to capture our policies related to data privacy. See “Changes and Updates to this Privacy Notice” below for notification policies.
  • The right of access. We will provide you access to the information you’ve provided to us. This includes the images and account information.
  • The right to rectification. Your personal data that we retain can be rectified if found inaccurate or incomplete.
  • The right to erasure. As described in the section “How Can You Update, Correct or Delete Your Information?” your account can be deleted either directly from the Account Settings panel or by contacting us at privacy@ponga.com. See our Terms of Service for details on paid accounts.
  • The right to restrict processing. You may request that we restrict processing on your account but otherwise maintain access to the account.
  • The right to data portability. You may request access to the images you’ve provided us by contacting us at support@ponga.com with valid login credentials.
  • The right to object. You may object to our use of your contact information for notifications, product updates, and newsletters. You will find opt-out selections in your Account settings panel.
  • Rights related to automated decision making and profiling. Ponga Services do not include automated decision-making functions except for the matching of detected faces as part of face recognition features. All recognition features can be manually over-ridden.  

How Can This Privacy Notice Be Changed?

Changes and Updates to this Privacy Notice

This Privacy Notice may be revised periodically without further notice to you and this will be reflected by the "last modified" notice below. Please revisit this page to stay aware of any changes. In general, we only use your personal information in the manner described in the Privacy Notice in effect when we received that personal information. Your continued use of the Ponga Service constitutes your agreement to this Privacy Notice and any future revisions. If we decide to change our privacy policies, then we will post those changes to this Privacy Notice, and other places we deem appropriate so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it.

For revisions to this Privacy Notice that may be materially less restrictive on our use or disclosure of personal information you have provided to us, we will make reasonable efforts to notify you and obtain your consent before implementing such revisions with respect to such information. If we make such material changes to this policy, then we will notify you here in this Privacy Notice, by email, or by means of a notice on the Ponga Services home page.