Privacy Policy

Last Updated: Feb 29, 2024

 

Summary

First Street Technology, Inc.™ (“First Street”) is a Delaware public benefit corporation with a mission to connect climate risk to financial risk. This Privacy Policy applies to the website www.RiskFactor.com, a digital product of First Street. This Privacy Policy explains what personal information is collected from you, how to access or correct this information, and how the information is used and kept safe.

Introduction

We want you to be familiar with how we collect, use, and disclose information. This Privacy Policy describes our practices in connection with information that we collect through:

  • www.riskfactor.com, from which you are accessing this Privacy Policy (the “Website”);
  • Software applications and APIs made available by us for use on or through computers and mobile devices, including the Risk Factor™ APIs (the “Apps”);
  • Our social media pages and apps (collectively, our “Social Media Pages”)
  • HTML-formatted email messages that we send to you that link to this Privacy Policy or other communications with you; and
  • Offline interactions you have with us.

Collectively, we refer to the Website, Apps, Social Media Pages, emails, communications, and offline interactions as the “Services.”

Personal Information” is information that identifies you as an individual or relates to an identifiable individual. The types of Personal Information we collect depends on your level of engagement with the Services. The more you interact with the Services, the more information we need to provide the Services.

To the extent permitted by applicable law, we may use, process, transfer and store user data in an anonymous and aggregated manner. We may combine such data with other information collected, including information from third-party sources. By using the Services, you agree that we are permitted to collect, use, share and store anonymized aggregated data collected through the Services for benchmarking, analytics, metrics, research, reporting, machine learning and other legitimate business purposes. Personal Information does not include information that has been de-identified or aggregated such that you can no longer be identified.

All Users of the Website

From registered and unregistered users of the Website, we automatically receive and record information whenever you interact with the Website, including:

  • IP address (we may also derive your approximate location from your IP address)
  • Cookie information
  • Browser information
  • Information about your activity while on the Website (such as the pages you request, properties that you view or save, and property that you claim)
  • The URL of the site you came to the Website from
  • Information submitted as a result of completing forms, entering a promotion or survey or subscribing or commenting on or downloading information from the Website

We may collect Personal Information from you when you request information about our Services, register for our newsletters, request customer or technical support, or otherwise communicate with us. We may send marketing materials to you using various communication channels, including without limitation, email, text messages/SMS, push notifications, telephone calls, and direct mail. We may contact you to participate in surveys. If you decide to participate, you may be asked to provide certain information, which may include Personal Information.

We may obtain information about you from other sources, including through third-party services and organizations to supplement information provided by you. We need to collect this information in order to provide the requested Services to you. If you do not provide the information requested, we may not be able to provide the Services. If you disclose any Personal Information relating to other people to us or to our service providers in connection with the Services, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Policy.

Registered Users of the Website

When you create your account on the Website, you provide us with:

  • Name
  • Email address
  • User name
  • Password, which is encrypted on our server
  • Company name and size, if applicable
  • Payment card information, which will be provided to a third party provider that we use
  • Other information such as address in order to allow us to resolve support issues that you may submit to us

By visiting your Account Settings on our Website, you can correct, amend, add or delete Personal Information associated with your account. However, even after you update information, we may maintain a copy of the original information in our records as required by applicable law or other legal obligation.

Use of Personal Information

We and our service providers use Personal Information for the following purposes:

  • Providing the functionality of the Services and fulfilling your requests.
    • To provide the Services’ functionality to you, such as arranging access to your registered account and providing you with related customer service.
    • To respond to your inquiries and fulfill your requests, when you contact us via one of our online contact forms or otherwise, for example, when you send us questions, suggestions, compliments, or complaints, or when you request a quote for or other information about our Services.
    • To complete your transactions, verify your information, and provide you with related customer service.
    • To send administrative information to you, such as changes to our terms, conditions, and policies.
  • Providing you with our newsletter and/or other marketing materials and facilitating social sharing.
  • Analyzing Personal Information for business reporting and providing personalized services.
    • To analyze or predict our users’ preferences in order to prepare aggregated trend reports on how our digital content is used, so we can improve our Services.
    • To better understand your interests and preferences, so that we can personalize our interactions with you and provide you with information and/or offers tailored to your interests.
    • To better understand your preferences so that we can deliver content via our Services that we believe will be relevant and interesting to you.
  • Allowing you to participate in focus groups, sweepstakes, contests, or other promotions.
    • We may offer you the opportunity to participate in a focus group, sweepstakes, contest, or other promotion.
    • Some of these focus groups, sweepstakes, contests, or promotions have additional rules containing information about how we will use and disclose your Personal Information. Please read those additional rules before choosing to participate.
  • Aggregating and/or anonymizing Personal Information.
    • We may aggregate and/or anonymize Personal Information so that it will no longer be considered Personal Information. We do so to generate other data for our use, which we may use and disclose for any purpose, as it no longer identifies you or any other individual.
  • Accomplishing our business purposes.
    • For data analysis, for example, to improve the efficiency of our Services;
    • For audits, to verify that our internal processes function as intended and to address legal, regulatory, or contractual requirements;
    • For fraud and security monitoring purposes, for example, to detect and prevent cyberattacks or attempts to commit identity theft;
    • For developing new products and services;
    • For enhancing, improving, repairing, maintaining, or modifying our current products and services, as well as undertaking quality and safety assurance measures;
    • For identifying usage trends, for example, understanding which parts of our Services are of most interest to users;
    • For determining the effectiveness of our promotional campaigns, so that we can adapt our campaigns to the needs and interests of our users; and
    • For operating and expanding our business activities, for example, understanding which parts of our Services are of most interest to our users so we can focus our energies on meeting our users’ interests.

We engage in these activities to manage our contractual relationship with you, to comply with a legal obligation, and/or based on our legitimate interest. We will provide personalized services based on our legitimate interests and with your consent, to the extent that your consent is required by applicable law.

Disclosure of Personal Information

We disclose Personal Information:

  • To our affiliates for the purposes described in this Privacy Policy.
  • To our third party service providers, to facilitate services they provide to us.
    • These can include providers of services such as website hosting, data analysis, payment processing, order fulfillment, information technology and related infrastructure provision, protections against fraud or criminal activity, customer service, email delivery, auditing, and other services.
    • To the extent applicable, we require these parties to comply with this Privacy Policy and appropriate confidentiality and security measures.
  • To third party companies that support our marketing efforts including advertising service providers and companies delivering customer surveys and feedback and helping us understand the effectiveness of those efforts.
  • To third party providers of focus groups, sweepstakes, contests, and similar promotions.

Other Uses and Disclosures

We also use and disclose your Personal Information as necessary or appropriate, in particular when we have a legal obligation or legitimate interest to do so:

  • To comply with applicable law and regulations.
    • This may include laws outside your country of residence.
  • To cooperate with public and government authorities.
    • To respond to a request or to provide information we believe is necessary or appropriate.
    • These can include authorities outside your country of residence.
  • To cooperate with law enforcement.
    • For example, when we respond to law enforcement requests and orders or provide information we believe is important.
  • For other legal reasons.
    • To enforce our terms and conditions; and
    • To protect our rights, privacy, safety or property, and/or that of our affiliates, you, or others.
  • In connection with a sale or business transaction.
    • We have a legitimate interest in disclosing or transferring your Personal Information to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).

Other Information

Other Information” is any information that does not reveal your specific identity or does not directly relate to an identifiable individual. We collect Other Information such as:

  • Browser and device information
  • Website and App usage data
  • Information collected through cookies, pixel tags, and other technologies
  • Demographic information and other information provided by you that does not reveal your specific identity
  • Information that has been aggregated in a manner such that it no longer reveals your specific identity

Collection of Other Information

We and our service providers may collect Other Information in a variety of ways, including:

  • Through your browser or device.
    • Certain information is collected by most browsers or automatically through your device, such as your Media Access Control (MAC) address, computer type (Windows or Mac), screen resolution, operating system name and version, device manufacturer and model, language, Internet browser type and version, and the name and version of the Services (such as the App) you are using. We use this information to ensure that the Services function properly.
  • Through your use of the App.
    • When you download and use the App, we and our service providers may track and collect App usage data, such as the date and time the App on your device accesses our servers and what information and files have been downloaded to the App based on your device number.
  • Through cookies.
    • Cookies are pieces of information stored directly on the computer that you are using. Cookies allow us to collect information such as browser type, time spent on the Services, pages visited, language preferences, and other traffic data. We and our service providers use the information for security purposes, to facilitate navigation, to display information more effectively, and to personalize your experience. We also gather statistical information about use of the Services in order to continually improve their design and functionality, understand how they are used, and assist us with resolving questions regarding them. We do not currently respond to browser do-not-track signals. If you do not want information collected through the use of cookies, most browsers allow you to automatically decline cookies or be given the choice of declining or accepting a particular cookie (or cookies) from a particular website. You may also wish to refer to http://www.allaboutcookies.org/manage-cookies/index.html. If, however, you do not accept cookies, you may experience some inconvenience in your use of the Services.
  • Through pixel tags and other similar technologies.
    • Pixel tags. Pixel tags (also known as web beacons and clear GIFs) may be used to, among other things, track the actions of users of the Services (including email recipients), measure the success of our marketing campaigns, and compile statistics about usage of the Services and response rates.
    • Analytics. We use Google Analytics, Tableau and Segment, which use cookies and similar technologies to collect and analyze information about use of the Services and report on activities and trends. These services may also collect information regarding the use of other websites, apps, and online resources. You can learn about Google’s practices by going to www.google.com/policies/privacy/partners/ and exercise the opt-out provided by Google by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout. You can learn more about Tableau’s practices by going to https://www.salesforce.com/company/privacy. You can learn about Segment’s practices by going to https://segment.com/docs/privacy/.

Uses and Disclosures of Other Information

We may use and disclose Other Information for any purpose, except where we are required to do otherwise under applicable law. If we are required to treat Other Information as Personal Information under applicable law, we may use and disclose it for the purposes for which we use and disclose Personal Information as detailed in this Privacy Policy. In some instances, we may combine Other Information with Personal Information. If we do, we will treat the combined information as Personal Information as long as it is combined.

Choices and Access

We give you choices regarding our use and disclosure of your Personal Information for marketing purposes. You may opt out from:

  1. Receiving marketing-related emails from us. If you no longer want to receive marketing related emails from us on a going-forward basis, you may opt out by following the instructions contained in each such email message.
  2. Our sharing of your Personal Information with affiliates for their direct marketing purposes. If you prefer that we discontinue sharing your Personal Information on a going-forward basis with our affiliates for their direct marketing purposes, you may opt out of this sharing by contacting us at support@riskfactor.com. Please refer to this section 2 in your email.
  3. Our sharing of your Personal Information with unaffiliated third parties for their direct marketing purposes. If you prefer that we discontinue sharing your Personal Information on a going-forward basis with unaffiliated third parties for their direct marketing purposes, you may opt out of this sharing by emailing us at support@riskfactor.com. Please refer to this section 3 in your email.

We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt out of receiving marketing related emails from us, we may still send you important administrative messages, from which you cannot opt out.

Third-Party Services

This Privacy Policy does not address, and we are not responsible for, the privacy, information, or other practices of any third parties, including any third party operating any website or service to which the Services link. The inclusion of a link on the Services does not imply endorsement of the linked site or service by us or by our affiliates.

In addition, we are not responsible for the information collection, use, disclosure, or security policies or practices of other organizations, such as Facebook, Apple, Google, Microsoft, RIM, or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider, or device manufacturer, including with respect to any Personal Information you disclose to other organizations through or in connection with the Apps or our Social Media Pages.

Our Advertising

We may use third-party advertising companies to serve advertisements regarding goods and services that may be of interest to you when you access and use the Services and other websites or online services.

You may receive advertisements based on information relating to your access to and use of the Services and other websites or online services on any of your devices, as well as on information received from third parties. These companies place or recognize a unique cookie on your browser (including through the use of pixel tags). They also use these technologies, along with information they collect about your online use, to recognize you across the devices you use, such as a mobile phone and a laptop. If you would like more information about this practice, and to learn how to opt out of it in desktop and mobile browsers on the particular device on which you are accessing this Privacy Policy, please visit http://optout.aboutads.info/#/ and http://optout.networkadvertising.org/#/. You may download the AppChoices app at www.aboutads.info/appchoices to opt out in mobile apps.

Use of the Services by Minors

The Services are not directed to individuals under the age of thirteen (13), and we do not knowingly collect Personal Information from individuals under 13.

Jurisdiction

Your Personal Information may be stored and processed in any country where we have facilities or in which we engage service providers, and, by using the Services, you understand that your information will be transferred to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country.

Sensitive Information

Unless we request it, we ask that you not send us, and you not disclose, any sensitive Personal Information (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, or criminal background) on or through the Services or otherwise to us.

Third-Party Payment Service

We may use a third-party payment service to process payments made through the Services. If you wish to make a payment through the Services, your Personal Information will be collected by such third party and not by us and will be subject to the third party’s privacy policy, rather than this Privacy Policy. We have no control over, and are not responsible for, this third party’s collection, use, and disclosure of your Personal Information.

Individual Rights in Personal Information

In accordance with applicable law, you may have the right to: (i) request confirmation of whether we are processing your Personal Information; (ii) obtain access to or a copy of your Personal Information; (iii) receive an electronic copy of Personal Information that you have provided to us, or ask us to send that information to another company (the “right of data portability”); (iv) restrict our uses of your Personal Information; (v) seek correction or amendment of inaccurate, untrue, incomplete or improperly processed Personal Information; and (vi) request erasure of Personal Information held about you by us, subject to certain exceptions prescribed by law. If you would like to exercise any of these rights, please contact us as set forth below. We will process such requests in accordance with applicable laws. To protect your privacy, we may take steps to verify your identity before fulfilling your request.

Personal Information Storage and Security

We are headquartered in the United States. You agree that we may store and process the information we collect anywhere in the world, including but not limited to, the United States, the European Union or other countries. We take steps to ensure that your information is treated securely and in accordance with this Privacy Policy. Unfortunately, the Internet cannot be guaranteed to be 100% secure, and we cannot ensure or warrant the security of any information you provide to us. To the fullest extent permitted by law, we do not accept liability for unintentional disclosure. By using the Services or providing Personal Information to us, you agree that we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use of the Services. If we learn of a security system’s breach, we may attempt to notify you electronically by posting a notice on the Services, by mail or by sending an email to you. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the “Contacting Us” section below.

Delete your Account

You may delete your Risk Factor account on the Settings page under “Close Account”. We retain Personal Information for as long as we have a valid business purpose to or to meet our legal obligations. We may be required to keep a copy of your Personal Information as necessary to fulfill the purposes(s) for which it was collected, provide our Services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws.

Updates to this Privacy Policy

The “LAST UPDATED” legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes will become effective when we post the revised Privacy Policy on the Services.

Contacting Us

Risk Factor32 Bridge Street, Floor 3Brooklyn, NY 11201support@riskfactor.com

Because email communications are not always secure, please do not include credit card or other sensitive information in your emails to us.

California Privacy Notice Provisions

The California Consumer Protection Act (“CCPA”) provides California residents (“consumers”) with certain rights as described herein and in this Privacy Policy. The terms in this section use the definitions set forth in the CCPA.

Pursuant to the CCPA, effective January 1, 2020, consumers whose personal information have been collected by us, have certain rights, including:

  • The right to know the categories of personal information we’ve collected and the categories of courses from which we got the information;
  • The right to know the business purpose for sharing personal information;
  • The right to know the categories of third parties with whom we’ve shared personal information;
  • The right to access the specific pieces of personal information we’ve collected; and
  • The right to delete your information.

We may have collected the following categories of personal information of California residents in the past 12 months:

  • Identifiers such as a name, email address, mailing address, Internet Protocol address, telephone number or account number;
  • Personal information described in subdivision (e) of CALIFORNIA CIVIL CODE SECTION 1798.80;
  • Commercial information, including records of products or services purchased;
  • Internet or other electronic network activity information, including browsing history, search history, and information regarding a consumer’s interaction with an Internet website, application, or advertisement; and
  • Professional or employment-related information, including job title or business affiliation.

We may have disclosed your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract. During the past 12 months, we have disclosed the following categories of personal information for a business purpose: Identifiers, California Customer Records personal information categories, professional or employment-related information.

Right to Opt-Out of Sale of Your Personal Information: Consumers have the right to request that a business that sells the consumer’s personal information, or that discloses it for a business purpose, inform the consumer of what has been collected about them and who it has been sold or disclosed to. Consumers also have the right, at any time, to direct a business that sells personal information about them not to sell their personal information. The CCPA sets forth certain obligations for businesses that “sell” personal information. The CCPA defines “sale” broadly to include not only providing data to third parties for payment but also transferring personal information to third parties in exchange for “other valuable consideration.” During the past 12 months, we have not provided and we do not currently provide personal information to third parties for monetary payment.

Consumer request process: Consumers may submit a Verifiable Consumer Request by sending us a message through the Website or emailing us at support@riskfactor.com on up to two occasions every 12 months. Upon receiving a Verifiable Consumer Request (that’s reasonable in light of the nature of the personal information requested) we will provide this information in writing, free of charge, within 45 days of the request, or if reasonably necessary (upon notice to you), within 90 days. We will also disclose, if applicable: the categories of sources from which the personal information was collected; the business or commercial purpose for collection of the information; and the categories of service providers with whom we shared the information.

We may not be able to fulfill the request if we (or our service providers) are required to retain the personal information for the following reasons:

  • Transactional: to complete a transaction for which the personal information was collected, provide a good or service requested by the consumer, or perform a contract we have with the consumer;
  • Security: to detect data security incidents;
  • Error Correction: to debug or repair any errors;
  • Legal: to protect against fraud or illegal activity or to comply with applicable law or a legal obligation, or exercise rights under the law, such as the right to free speech; or
  • Internal use: to use the personal information, internally, in a lawful manner that is compatible with the context in which the consumer provided the information (i.e., to improve our services).

California residents also have the right to not be discriminated against if they choose to exercise their privacy rights. We will not discriminate against the consumer for exercising their CCPA rights. Unless permitted by the CCPA, we will not:

  • Deny the consumer goods or services;
  • Charge different prices or rates for goods and services, including through granting discounts or other benefits, or imposing penalties;
  • Provide a different level or quality of goods or services; or
  • Suggest that a consumer may receive a different price or rate for goods or services or a different level or quality of goods or services.

Prior versions