Replay.io Privacy Policy

Effective Date: October 9, 2014

Introduction

Welcome! You have arrived at www.replay.io and/or are otherwise interacting with our Service (defined below), which is owned and operated by Replay.io, Inc., a Delaware company, (“Replay.io” or “we,” “our” or “us”). This “Privacy Policy” governs your use of any online service location (e.g., web site or mobile app) that posts a link to this Privacy Policy (each a “Site”), and also applies to your use of interactive features, widgets, plug-ins, applications, content, downloads and/or other services that we own and control and make available through a Site (collectively, the “Service”), regardless of how you access or use them, whether via personal computers, mobile devices or otherwise, unless we combine such data with Personal Information (defined below) that we have ourselves collected under this Privacy Policy. This Privacy Policy does not apply to our data collection activities offline or otherwise outside of our Service (unless otherwise stated below), and does not govern the data practices of third parties that may interact with our Service.

To the extent we provide you notice on our Service of different or additional privacy policies or practices (e.g., at the point of our collection), those additional terms shall govern such data collection and use.

In addition, please review the Service’s Terms of Service [http://replay.io/terms_of_service], which governs your use of the Service. By using our Service, you consent to our Privacy Policy and Terms of Service and our collection, use and sharing of your information and data, and other activities, as described below.

1. What Information Does the Service Collect?

(a) Information You Provide to Us

Personal Information and Demographic Information. On the Service, we may ask you to provide us with certain categories of information such as: (1) personally identifiable information, which is information that identifies you personally, such as your first and last name, e-mail address, phone number, and postal address ("Personal Information"); and (2) demographic information, such as information about your job title, your type of business, business income or revenues, number of employees ("Demographic Information"). We may collect this information through various forms and in various places on the Service, including account registration forms, contact us forms, or when you otherwise interact with the Service. To the extent we combine Demographic Information with your Personal Information we collect directly from you on the Service, we will treat the combined data as Personal Information under this Privacy Policy.

(b) Information Collected or Stored As You Access and Use the Service

In addition to any Personal Information or other information that you choose to submit to us via our Service, we and our thrid-party service providers may use a variety of technologies that automatically (or passively) store or collect certain information whenever you visit or interact with the Service ("Usage Information"). This Usage Information may be stored or accessed using a variety of technologies that may be downloaded to your personal computer, browser, laptop, tablet, mobile phone or other device (a "Device") whenever you visit or interact with our Service. To the extent we associate Usage Information with your Personal Information we collect directly from you on the Service, we will treat it as Personal Information.

This Usage Information may include:

We may use various methods and technologies to store or collect Usage Information (“Tracking Technologies”). Tracking Technologies may set, change, alter or modify settings or configurations on your Device. A few of the Tracking Technologies include, without limitation, the following (and subsequent technology and methods later developed):

Cookies. A cookie is a data file placed on a Device when it is used to visit the Service. A Flash cookie (or locally shared object) is a data file placed on a Device via the Adobe Flash plug-in that may be built-in to or downloaded by you to your Device. HTML5 cookies can be programmed through HTML5 local storage. Unlike Flash cookies, HTML5 cookies do not require a plug-in. Regular cookies may generally be disabled or removed by tools that are available as part of most commercial browsers, and in some but not all instances can be blocked in the future by selecting certain settings. Each browser you use will need to be set separately and different browsers offer different functionality and options in this regard. Also, these tools may not be effective with regard to Flash cookies or HTML5 cookies. For information on disabling Flash cookies, go to Adobe’s web site www.adobe.com. Please be aware that if you disable or remove cookies, Flash cookies, or HTML5 cookies on your Device, some parts of our Service may not function properly, and that when you revisit our Service your ability to limit cookies is subject to your browser settings and limitations.

Web Beacons.Small graphic images or other web programming code called web beacons (also known as “1x1 GIFs” or “clear GIFs”) may be included in our Service’s pages and messages. Web beacons may be invisible to you, but any electronic image or other web programming code inserted into a page or e-mail can act as a web beacon. Web beacons or similar technologies may be used for a number of purposes, including, without limitation, to count visitors to the Service, to monitor how users navigate the Service, to count how many e-mails that were sent were actually opened or to count how many particular articles or links were actually viewed.

Embedded Scripts. An embedded script is programming code that is designed to collect information about your interactions with the Service, such as the links you click on. The code is temporarily downloaded onto your Device from our web server or a third party service provider, is active only while you are connected to the Service, and is deactivated or deleted thereafter.

Browser Fingerprinting. Collection and analysis of information from your Device, such as, without limitation, your operating system, plug-ins, styem fonts and other data, for purposes of identification.

ETag, or Entity Tag. A feature of the cache in browsers. It is an opaque identifier assigned by a web server to a specific version of a resource found at a URL. If the resource content at that URL ever changes, a new and different ETag is assigned. Used in this manner ETags are a form of Device Identifier. ETag tracking may generate unique tracking values even where the consumer blocks HTTP, Flash, and/or HTML5 cookies.

Recognition Technologies. Technologies, including application of statistical probability to data sets, which attempt to recognize or make assumptions about users and devices (e.g., that a user of multiple devices is the same user).

We may use Tracking Technologies for a variety of purposes, including:

Strictly Necessary. We may use cookies or other Tracking Technologies that we consider are strictly necessary to allow you to use and access our Service, including cookies required to prevent fraudulent activity, improve security or allow you to make use of shopping-cart functionality.

Performance-Related. We may use cookies or other Tracking Technologies that are useful in order to assess the performance of the Service, including as part of our analytic practices or otherwise to improve the content, products or services offered through the Service.

Functionality-Related. We may use cookies or other Tracking Technologies that are required to offer you enhanced functionality when accessing the Service, including identifying you when you sign-in to our Service or keeping track of our specified preferences, including in terms of the presentation of content on our Service.

Targeting-Related. We may use Tracking Technologies to deliver content relevant to your interests on our Service and third-party sites based on how you interact with our content. This includes using Tracking Technologies to understand the usefulness to you of the content that has been delivered to you. Most Web browsers are set to accept cookies by default. If you prefer, you can choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of our Service and could remove cookies used for opt-out of tracking, including our Replay.io opt-out cookie.

Replay.io does not respond to "Do Not Track" browser signals or other mechanisms. Third parties may collect personal information about your online activities over time and across sites when you use the Service.There may be other Tracking Technologies now and later devised and used by us in connection with the Service. Further, third parties may use Tracking Technologies in connection with our Service, which may include the collection of information about your online activities over time and across third-party web sites or online services. We may not control those Tracking Technologies and we are not responsible for them. However, you consent to potentially encountering third party Tracking Technologies in connection with use of our Service and accept that our statements under this Privacy Policy do not apply to the Tracking Technologies or practices of such third parties.

(c) Information Third Parties Provide About You

We may receive information about you from your friends and others that use the Service, such as when they submit content to us or post on the Service. Additionally, we may, from time to time, supplement the information we collect directly from you on our Service with outside records from third parties for various purposes, including to enhance our ability to serve you, to tailor our content to you and to offer you opportunities that may be of interest to you. To the extent we combine information we receive from those sources with your Personal Information we collect on the Service, it will be treated as Personal Information and we will apply this Privacy Policy to such combined information, unless we have disclosed otherwise. In no other circumstances do our statements under this Privacy Policy apply to information we receive about you from third parties, even if they have used our technology to collect it and share it with us.

(d) Interactions with Third-Party Services

The Service may include functionality that allows certain kinds of interactions between the Service and a third-party web site or application. The use of this functionality may involve the third-party operator providing certain information, including Personal Information, to us. For example, when you register with the Service, you may have an option to use your Facebook, Google or other account provided by a third-party site or application to facilitate the registration and log-in or transaction process on the Service, or otherwise link accounts. If we offer and you choose to use this functionality to access or use our Service, the third-party site or application may send Personal Information about you to us. If so, we will then treat it as Personal Information under this Privacy Policy, since we are collecting it as a result of your accessing of and interaction on our Service. In addition, we may provide third-party sites’ interfaces or links on the Service to facilitate your sending a communication from the Service. For example, we may use third parties to facilitate emails, tweets or Facebook postings. These third parties may retain any information used or provided in any such communications or other activities and these third parties’ practices are not subject to our Privacy Policy. Replay.io may not control or have access to your communications through these third parties. Further, when you use third-party sites or services, you are using their services and not our services and they, not we, are responsible for their practices. You should review the applicable third-party privacy policies before using such third-party tools on our Service.

2. How Do We Use the Information Collected?

Use of Information by Us. We may use your Personal Information, Demographic Information or Usage Information that is subject to this Privacy Policy: [(1) to provide you with information or services or process transactions that you have requested or agreed to receive including to send you electronic newsletters, or to provide you with special offers or promotional materials on behalf of us or third parties; (2) to enable you to participate in a variety of the Service’s features such as online entry sweepstakes, contests or other promotions; (3) to process your registration with the Service, including verifying your information is active and valid; (4) to improve the Service or our services, to customize your experience on the Service, or to serve you specific content that is relevant to you; (5) to contact you with regard to your use of the Service and, in our discretion, changes to the Service and/or Service’s policies; (6) for internal business purposes; and (7) for purposes disclosed at the time you provide your information or as otherwise set forth in this Privacy Policy].

3. How and When Do We Share Information with Third Parties?

We may share non-Personal Information, such as aggregated user statistics, with third parties. We may share your Device Identifiers with third parties along with data related to you and your activities. In addition, we may share the information we have collected about you, including Personal Information, as disclosed at the time you provide your information and as described below or otherwise in this Privacy Policy. Replay.io may disclose your information as follows:

(a) When You Request Information From or Provide Information to Third Parties. You may be presented with an option on our Service to receive certain information and/or marketing offers directly from third parties or to have us send certain information to third parties or give them access to it. If you choose to do so, your Personal Information and other information may be disclosed to such third parties and all information you disclose will be subject to the third-party privacy policies and practices of such third parties. In addition, third parties may store, collect or otherwise have access to your information when you interact with their Tracking Technologies, content, tools apps or ads on our Service or link to them from our Service. This may include using third-party tools such as Facebook, Twitter, Pinterest or other third-party posting or content sharing tools and by so interacting you consent to such third party practices. It may also include ordering or purchasing products from third parties through us where we indicate that the third party rather than us is the seller. We are not responsible for the privacy policies and practices of such third parties and, therefore, you should review such third-party privacy policies and practices of such third parties prior to requesting information from or otherwise interacting with them.

(b) Third Parties Providing Services on Our Behalf. We may use third-party vendors to perform certain services on behalf of us or the Service, such as hosting the Service, designing and/or operating the Service’s features, tracking the Service’s activities and analytics, and enabling us to send you special offers or perform other administrative services. We may provide these vendors with access to user information, including Device Identifiers and Personal Information, to carry out the services they are performing for you or for us. Third-party analytics and other service providers may set and access their own Tracking Technologies on your Device and they may otherwise collect or have access to information about you, potentially including Personal Information, about you. We are not responsible for those third party technologies or activities arising out of them. We are not responsible for the effectiveness of or compliance with any third parties’ opt-out options.

(c) To Protect the Rights of Replay.io and Others. To the fullest extent permitted by applicable law, we may also disclose your information if we believe in good faith that doing so is necessary or appropriate to: (i) protect or defend the rights, safety or property of Replay.io or third parties (including through the enforcement of this Policy, our Terms of Service [http://replay.io/terms_of_service], and other applicable agreements and policies); or (ii) comply with legal and regulatory obligations (e.g., pursuant to law enforcement inquiries, subpoenas or court orders). To the fullest extent permitted by applicable law, we have complete discretion in electing to make or not make such disclosures, and to contest or not contest requests for such disclosures, all without notice to you.

(d) Affiliates and Business Transfer. We may share your information, including your Device Identifiers and Personal Information, Demographic Information and Usage Information with our parent, subsidiaries and affiliates (“Affiliates”). We also reserve the right to disclose and transfer all such information: (i) to a subsequent owner, co-owner or operator of the Service or applicable database; or (ii) in connection with a merger, consolidation, restructuring, the sale of substantially all of our interests and/or assets or other corporate change, including, during the course of any due diligence process.

(i) Your California Privacy Rights. We may from time to time elect to share certain information about you collected by us on the Service with third parties for those third parties’ direct marketing purposes. California Civil Code Section 1798.83 permits California residents who have supplied personal information, as defined in the statute, to us to, under certain circumstances, to request and obtain certain information regarding our disclosure, if any, of personal information to third parties for their direct marketing purposes. If this applies, you may obtain the categories of personal information shared and the names and addresses of all third parties that received personal information for their direct marketing purposes during the immediately prior calendar year (e.g. requests made in 2012 will receive information about 2011 sharing activities)] OR [to request to opt-out of such future sharing. To make such a request, please provide sufficient information for us to determine if this applies to you, attest to the fact that you are a California resident and provide a current California address for our response. You may make this request in writing at:

(a) Email: support@replay.io

(b) Postal Mail: 580 Market Street, 3rd Floor, San Francisco CA 94104

4. Third-Party Content, Links To Third-Party Sites, and/or Third-Party Apps Appearing on the Service

The Service may contain content that is supplied by a third party, and those third parties may collect Usage Information and your Device Identifier when pages from the Service are served to you. In addition, when you are on the Service you may be directed to other services that are operated and controlled by third parties that we do not control. We are not responsible for the data collection and privacy practices employed by any of these third parties or their services and they may be tracking you across multiple sites and may be sharing the results of that tracking with us and/or others. For example, if you “click” on a link, the “click” may take you off the Service onto a different site. These other sites may associate their Tracking Technologies with you, independently collect data about you, including Personal Information, and may or may not have their own published privacy policies.

Third-party applications may also be available via the Service. The owners of these applications (“Third-Party Owners”) may collect Personal Information and other data from you and may have their own policies and practices. We are not responsible for how Third-Party Owners or their applications collect or use your information and they may be tracking you across multiple sites and may be sharing the results of that tracking with us and/or others. These Third-Party Owners may have their own terms of service, privacy policies or other policies and ask you to agree to the same. We are not responsible for these third-party privacy policies or the practices of Third-Party Owners. Be sure to review any available policies before submitting any personally identifiable information to a third-party application or otherwise interacting with it and exercise caution in connection with these applications. We also encourage you to note when you leave our Service and to review the third-party privacy policies of all third-party locations and exercise caution in connection with them.

5. Are Ads Served on the Service?

The Service may use third parties such as network advertisers and ad exchanges to serve advertisements on the Service and may use third-party analytics and other service providers to evaluate and provide us and/or third parties with information about the use of the Service and viewing of ads and of our content. Network advertisers are third parties that display advertisements, which may be based on your visits to the Service and other apps and sites you have visited. Third-party ad serving enables us to target advertisements to you for products and services in which you might be interested.

The Service’s third-party ad network and exchange providers, the advertisers, the sponsors and/or traffic measurement services may themselves set and access their own cookies (including Flash cookies), web beacons and other Tracking Technologies on your Device and track certain behavioral Usage Information regarding users of your Device via a Device Identifier. These third-party Tracking Technologies may be set to, among other things: (a) help deliver advertisements to you that you might be interested in; (b) prevent you from seeing the same advertisements too many times; and (c) understand the usefulness to you of the advertisements that have been delivered to you. You acknowledge and agree that associated technology may access and use your Device and may set or change settings on your Device in connection with the associated operations. Note that any images (or any other parts of content) served by third parties in association with third-party ads or other content may serve as web beacons, which enable third parties to carry out the previously described activities.

Third-party Tracking Technologies are not controlled by us, even if they use our technology to help store or collect data. Statements regarding our practices do not apply to the methods for collecting information used by these third-party advertisers and others or the use of the information that such third parties collect. We do however work with third parties to make efforts to have you provided with information on their practices and any available opportunity to exercise choice. The relevant third party’s terms of service, privacy policy, permissions, notices and choices should be reviewed regarding their collection, storage and sharing practices. We make no representations regarding the policies or practices of third-party advertisers or advertising networks or exchanges or related third parties.

Further, while we may use a variety of companies to serve advertisements on the Service, you may wish to visit http://www.networkadvertising.org/optoutnonppii.asp, which provides information regarding this practice by Network Advertising Initiative (“NAI”) members, and your choices regarding having this information used by these companies, including the “opt-out” procedures of NAI members. Opting out of one or more NAI members only means that those NAI members no longer will be allowed under their own rules to deliver targeted content and/or ads to you, which will affect this and other sites, but does not mean you will no longer receive any targeted content and/or ads. Also, if your browsers are configured to reject cookies when you visit this opt-out page, or you subsequently erase your cookies, use a different Device or change web browsers, your NAI opt-out may not, or may no longer, be effective. Additional information is available on the NAI’s web site accessible by the above link. You may also opt-out of receiving third-party behavioral ads on this site by visiting the Digital Advertising Alliance (“DAA”_) web site at http://www.aboutads.info/choices/#completed. Similar limitations may apply to the DAA opt-out. We are not responsible for effectiveness of, or compliance with, any third-parties’ opt-out options or programs.

6. How Do I Change My Information and Communications Preferences?

You are responsible for maintaining the accuracy of the information you submit to us, such as your contact information provided as part of registration. The Service may allow you to review, correct or update Personal Information you have provided through the Service’s account management forms or otherwise, and you may provide registration updates and changes by contacting us here [support@replay.io]. If so, we will make good faith efforts to make requested changes in our then active databases as soon as reasonably practicable (but we may retain prior information as business records). With respect to our mobile and other applications (i.e., when we are the application publisher), you can prospectively stop all collection of information by the application by uninstalling the application. You may use the standard uninstall process as may be available as part of your applicable Device or potentially via the appropriate application or app marketplace. Please note that it is not always possible to completely remove or delete all of your information from our databases and that residual data may remain on backup media or for other reasons. When you edit your Personal Information or change your preferences on the Service, information that you remove may persist internally for Replay.io’s administrative purposes. You may cancel or modify our e-mail marketing communications you receive from us by following the instructions contained within our promotional e-mails . This will not affect subsequent subscriptions and if your opt-out is limited to certain types of e-mails the opt-out will be so limited. If you subscribe to text messages from us, you can terminate a particular text message subscription by reply texting “STOP.” Subsequent or different subscriptions will be unaffected. Please note that we reserve the right to send you certain communications relating to your account or use of our Service, such as administrative and service announcements and these transactional account messages may be unaffected if you choose to opt-out from receiving our marketing communications. If you have any questions about the Privacy Policy or practices described in it, you should contact us in the following ways: Postal Mail: 580 Market Street, 3rd Floor, San Francisco CA 94104; By e-mail here: support@replay.io.

7. What About Transfer of Information to the United States?

Our Service is operated in the United States and intended for users located in the United States. If you are located outside of the United States, please be aware that information we collect, including Personal Information, will be transferred to, and processed, stored and used in the United States. The data protection laws in the United States may differ from those of the country in which you are located, and your Personal Information may be subject to access requests from governments, courts, or law enforcement in the United States according to laws of the United States. By using the Service or providing us with any information, you consent to the transfer to, and processing, usage, sharing and storage of your information, including Personal Information, in the United States as set forth in this Privacy Policy.

8. What Should Parents Know About Children?

We understand the importance of protecting children’s privacy in the interactive world. We are a general audience service and do not use the Service to knowingly collect personal information from children under the age of thirteen (13) that requires parental notice and consent under the Children’s Online Privacy Protection Act (“COPPA”) without such parental consent. If you are a child under 13 years of age, you are not permitted to use the Service and should not send any information about yourself to us through the Service.

In the event that we become aware that we have collected personal information from any child, we will dispose of that information in accordance with COPPA and other applicable laws and regulations. If you are a parent or guardian and you believe that your child under the age of 13 has provided us with personal information without COPPA-required consent, please contact us here: support@replay.io.

9. What About Security?

We endeavor to incorporate commercially reasonable safeguards to help protect and secure your Personal Information. However, no data transmission over the Internet, mobile networks, wireless transmission or electronic storage of information can be guaranteed to be 100% secure. Please note that we cannot ensure the security of any information you transmit to us, and you use our Service and provide us with your information at your own risk.

10. What About Changes to the Privacy Policy?

We reserve the right to change this Privacy Policy at any time. Any changes will be effective immediately upon the posting of the revised Privacy Policy and your use of our Service indicates your consent to the privacy policy posted at the time of use. To the extent any provision of this Privacy Policy is found by a competent tribunal to be invalid or unenforceable, such provision shall be severed to the extent necessary for the remainder to be valid and enforceable.


313092830.3