Privacy Policy

Table of Contents

Introduction

Stone Brewing Co., LLC. respects your privacy and our goal is to maintain your trust and confidence when handling personal information about you. We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. To support this, we promise:

  • To implement computer, physical and procedural safeguards to protect the security and confidentiality of the personal data we collect
  • To limit the personal data collected to the minimum required to provide a better service
  • To permit only properly trained, authorized employees to access personal data
  • Not to disclose your personal data to external parties unless you have agreed, we are required by law, or we have previously informed you.

This Privacy Notice describes how we may collect, use and share information you provide when you visit our websites, receive our emails, or interact with us on social media, and sets forth our support of your privacy rights. We recognize that information privacy is an ongoing responsibility, so we will periodically update this Privacy Notice as we undertake new personal data practices or adopt new privacy policies.

It is important that you read this privacy notice together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy notice supplements the other notices and is not intended to override them.

Controller

Stone Brewing GmbH, operating in Berlin, Germany, is a wholly-owned subsidiary of Stone Brewing Co. LLC, based in the United States. Our core business functions are the brewing, sales, and distribution of beer and ale, restaurant and retail store operations, and an ecommerce website.

Stone Brewing (collectively referred to as Company, we, us, our in this privacy notice) is the controller and responsible for your personal data. This means that we are responsible for deciding how we hold and use personal information about you. We are required under data protection regulation to notify you of the information contained in this privacy notice.

What personal information we collect about you and how it is collected

Stone Brewing collects personal information about our customers and business partners. Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). You may give us your personal information when you use our websites, when you purchase our products, and during the sales process.

With a few exceptions, the information we collect about our customers is limited to first name, last name, email, billing address, shipping address, and phone number. For our business partners, the information we collect is typically limited to the kinds of information that can be found on a business card: first name, last name, job title, employer name, work address, work email, and work phone number. We use this information to provide customers and business partners with goods and services, such as fulfilment of online purchases or delivery of opt-in email newsletters. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of these goods and services. We do not knowingly attempt to solicit or receive information from children.

We will collect, store, and use the following categories of personal information about you as follows:

Identity Data including personal contact details such as name and title.
Contact Data including addresses, telephone numbers, and email addresses.
Financial Data including bank account details, your debit or credit card information, and other banking information.
Transaction Data including your billing history and products and services you use and anything else relating your account.
Profile Data including information you provide to us in your communications with us, information you provide to us when entering prize draws or participate in surveys.
Marketing and Communications Data including your preferences in receiving marketing from us and your communication preferences.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offenses.

If you fail to provide personal data

Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with products or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.

Use of Stone Brewing's Websites

As is true of most other websites, Stone Brewing’s websites collect certain information automatically and store it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system and other usage information about the use of Stone Brewing’s websites, including a history of the pages you view. Stone uses Google Analytics to help analyze how users use our site. The tool uses "cookies," which are text files placed on your computer, to collect standard Internet log information and visitor behavior information in an anonymous form. The information generated by the cookie about your use of the website (including IP address) is transmitted to Google. This information is then used to evaluate visitors' use of the website and to compile statistical reports on website activity for Stone. We use this information to help us design our site to better suit our users’ needs. We may also use your IP address to help diagnose problems with our server and to administer our websites, analyze trends, track visitor movements on our websites, and gather broad demographic information that assists us in identifying visitor preferences. We do not track users when they cross to third party websites, do not provide targeted advertising to them, and therefore do not respond to Do Not Track (DNT) signals.

How we will use the information about you

We will only use your personal information when the law allows us to. Most commonly, we will use your personal information in the following circumstances:

  • Where we need to perform the contract we have entered into with you.
  • Where we need to comply with a legal obligation.
  • Where we have your consent.
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.

We may also use your personal information in the following situations, which are likely to be rare:

  • Where we need to protect your interests (or someone else's interests).
  • Where it is needed in the public interest.

Situations in which we will use your personal information

We need all the categories of information in the list above primarily to allow us to perform our contract with you. In some cases we may use your personal information to pursue legitimate interests of our own or those of third parties, provided your interests and fundamental rights do not override those interests. The situations in which we will process your personal information are listed below.

Purpose/Activity Type of data Lawful basis for processing including basis of legitimate interest
To process and deliver your order including:
  1. Carrying out our obligations arising from any contracts entered into between you and us;
  2. To confirm that your orders have been received and to process them;
  3. To provide our products and services;
  4. To provide you with the information and services that you request from us;
  5. For billing purposes, to manage payments, fees and charges
  6. (f) To collect and recover money owed to us
  1. Identity
  2. Contact
  3. Financial
  4. Transaction
  5. Marketing and Communications
  1. Performance of a contract with you.
  2. Necessary for our legitimate interests (to recover debts due to us).
To validate you as a registered customer when using our services and calling our customer services.
  1. Identity
  2. Contact
  1. Performance of a contract with you.
To notify you about changes to our services and to make suggestions and recommendations to you about goods or services that may be of interest to you.
  1. Identity
  2. Contact
  3. Technical
  4. Profile
  1. Necessary for our legitimate interests (to develop our products/services and grow our business).
For the administration of files and records; business management and planning, including accounting and auditing.
  1. Identity
  2. Contact
  3. Technical
  1. Necessary for our legitimate interests (for running our business, provision of administration and IT services).
  2. Necessary to comply with a legal obligation.
To prevent fraud.
  1. Identity
  2. Contact
  3. Financial
  4. Transaction
  5. Technical
  1. Necessary for our legitimate interests (to prevent fraud).
  2. Necessary to comply with a legal obligation
To send certain communications (including by email and SMS) to you including service announcements and administrative messages and other communications relating to our services.
  1. Identity
  2. Contact
  3. Technical
  1. Performance of a contract with you.
  2. Necessary for our legitimate interests (for running our business, provision of administration services, network security and in the context of a business reorganization or group restructuring exercise)
To ensure security for you and our staff, and help maintain service quality (calls to our customer services may be monitored and/or recorded for authentication, security, quality and training purposes).
  1. Identity
  2. Contact
  1. Performance of a contract with you
To help the emergency services.
  1. Identity
  2. Contact
  1. Where we need to comply with a legal obligation.
To comply with applicable laws, regulations, court orders, government and law enforcement agencies’ requests, to operate our systems properly and to protect ourselves, our users and customers and to solve any customer disputes.
 
  1. Identity
  2. Contact
  3. Financial
  4. Transaction
  5. Technical
  1. Where we need to comply with a legal obligation.

Some of the above grounds for processing will overlap and there may be several grounds which justify our use of your personal information.

When and how we share information with others

Information about your Stone Brewing purchases are maintained in association with your profile account. The personal information Stone Brewing collects from you is stored in one or more databases hosted by Stone Brewing or for Stone Brewing by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval.

Transferring personal data from the EU to the US

Stone Brewing has its headquarters in the United States, therefore information we collect from you will be processed in the United States. The United States has not sought nor received a finding of “adequacy” from the European Union under Article 45 of the GDPR. Stone Brewing relies on derogations for specific situations as set forth in Article 49 of the GDPR. In particular, Stone Brewing collects and transfers to the U.S. personal data only: with your consent; to perform a contract with you; or to fulfill a compelling legitimate interest of Stone Brewing in a manner that does not outweigh your rights and freedoms. Stone Brewing endeavors to apply suitable safeguards to protect the privacy and security of your personal data and to use it only consistent with your relationship with Stone Brewing and the practices described in this Privacy Notice. Stone Brewing also minimizes the risk to your rights and freedoms by not collecting or storing sensitive information about you.

Data Subject Rights

Your rights in connection with personal information

Under certain circumstances, by law you have the right to:

  • Request access to your personal information (commonly known as a "data subject access request"). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
  • Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
  • Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
  • Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
  • Request the transfer of your personal information to another party. If you want to review, verify, correct or request erasure of your personal information, object to the processing of your personal data, or request that we transfer a copy of your personal information to another party, please contact our Data Protection Officer in writing (see contact details below).

No Fee Usually Required

You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

Right to withdraw consent

In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact our Data Protection Office in writing (see contact details below). Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.

Security of your Information

To help protect the privacy of data and personally identifiable information you transmit through use of our sites, we maintain physical, technical and administrative safeguards. We update and test our security technology on an ongoing basis. We restrict access to your personal data to those employees who need to know that information to provide benefits or services to you. In addition, we train our employees about the importance of confidentiality and maintaining the privacy and security of your information. We commit to taking appropriate disciplinary measures to enforce our employees' privacy responsibilities.

We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.

Data Storage and Retention

Your personal data is stored by Stone Brewing on its servers, and on the servers of the cloud-based database management services Stone Brewing engages, located in the United States. Stone Brewing retains data for the duration of the customer’s or business partner’s relationship with Stone Brewing. For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact Stone Brewing’s data protection officer at dpo@stonebrewing.com.

Changes and updates to the Privacy Notice

This version was last updated on 5th April 2018 and historic versions can be obtained by contacting us.

We reserve the right to update this privacy notice at any time, and we will provide you with a new privacy notice when we make any substantial updates. We may also notify you in other ways from time to time about the processing of your personal information

Questions, Concerns or Complaints

If you have any questions about this privacy notice, please contact Stone Brewing’s data protection officer or EU representative:

Data Protection Officer

Stone Brewing Co. LLC. is a for-profit business based in the United States. Stone Brewing has appointed an internal data protection officer for you to contact if you have any questions or concerns about Stone Brewing’s personal data policies or practices. Stone Brewing’s data protection officer’s name and contact information are as follows:

Brian Andrews
Stone Brewing Co., LLC
2120 Harmony Grove Road
Escondido, CA 92029
USA
dpo@stonebrewing.com
T: +1 760-294-7899

EU Representative

Stone Brewing GmbH is a for-profit business based in Berlin, Germany. Stone Brewing has appointed a representative in the EU for you to contact if you have any questions or concerns about Stone Brewing’s personal data policies or practices. Stone Brewing’s EU representative name and contact information are as follows:

Marcus Thieme
Stone Brewing GmbH
Im Marienpark 22
Berlin 12107
Germany
eu_rep@stonebrewing.eu
T: +49 030-212343-0