PRIVACY NOTICE
Effective Date: January 1, 2023
Version 4.0
This Privacy Notice describes our handling of Personal Information in connection with your activities in our locations or your use of our websites, mobile applications, or the services we provide. By visiting our locations, websites, or mobile applications or using our services, you hereby consent to these terms.
“Personal Information” refers to both online and offline information that identifies you or that can be reasonably linked to you as an individual. We encourage you to read this Privacy Notice which describes how we collect, use, disclose, share/sell, and protect your Personal Information, and the choices you have regarding your Personal Information.
Types of Personal Information that we, or our service providers on our behalf, may collect:
In certain situations, we, or our service providers on our behalf, may also collect data such as:
Personal Information is collected from the following:
If you use a mobile device, your device may disclose location information (when you enable location services) with our websites, mobile applications, services, or our service providers. For example, precise geo-location can be used to help you find our nearby locations.
Our sites and mobile applications may allow you to sign-in to our digital property using a social media network login and we may also include other social media features, such as a “share this” button. In these cases, we may receive information from the social media network, including your profile information, picture, user ID associated with your social media account, and other information you permit the social media network to disclose with partners. The data we receive from these social media networks is dependent upon their policies and your privacy settings on that partner site. You should always review and, if necessary, adjust your privacy settings on these websites and services before utilizing these features.
Minors
Our websites and online mobile applications are not directed toward children under 13 years of age. We do not knowingly collect online Personal Information of children under 13 years of age without parental/guardian consent.
Personal Information may be used for the following purposes:
We may disclose your Personal Information within our family of companies for purposes such as preference management, marketing, customer service functions, and improved user experiences.
We may also disclose your Personal Information outside our family of companies (for example, with partners such as service providers, data processors, contractors, etc.) for various purposes such as:
We participate in digital advertising to present you with online ads for our products and services that we believe may be of interest to you. We may partner with advertising companies to provide you with relevant content and offers that may be useful to you, we may partner with third-party companies to display content, offers or advertising that is tailored to your interests based on how you browse and shop both on and off our sites. In addition, others (advertisers and ad networks, ad serving companies, or other service providers) may infer user interests based on interactions with, or clicks on, personalized ads or content. As a result, you may see ads on our websites or other websites based on your purchases, search history, or web/mobile browsing activities (for instance, an ad from us may be displayed to you on another website if you recently browsed for office supplies). These interest-based ads (also sometimes called “personalized or targeted ads”) are displayed to you based on information collected from your online interactions across multiple websites that you visit, or across multiple devices you may use.
We may use your email address to deliver marketing information, product recommendations, and non-transactional communications about us via email.
We may use your mailing address to deliver notices of new services/partnerships, offers/coupons, printed catalogs, etc. about us or our products or services via direct mail.
We may send you promotional text messages (SMS) when you opt-in to receiving them.
Emails, Texts, Mail, and Notifications
Please note that if you opt out of receiving promotional communications from us, we may still send you transactional communications, including emails about your online account, Rewards account, membership program, or purchases. If you have any questions regarding transactional communications, please see Section 8 below to contact us.
If you are receiving any other communications, have any questions, or continue to receive communications after opting out, please e-mail us at Info@Staples.com. Please include any relevant information such as a forwarding of the email received, specification of the order number in question, screenshot of the online message, scan of the mailed marketing artifact, etc. Please note that you may continue to receive communications while we process your request.
If you have any questions regarding the above, please contact us at Privacy@Staples.com.
Interest Based Advertising
Industry groups such as the Digital Advertising Alliance and the Network Advertising Initiative have developed services to help you manage your Interest Based Advertising preferences. Please note that if you opt-out of Interest-Based Advertising, you may still see ads from us, but they will not be as relevant to you.
If your browsers are configured to reject cookies when you visit these pages, or if you subsequently erase your cookies, use a different device, or change web browsers, your opt-out may become ineffective and may need to be repeated.
You may visit the following sites to become more familiar with these entities and their unsubscribe options:
Website Analytics
We use Google Analytics on our web sites to collect usage data, to analyze how users use the web sites and to provide advertisements to you on other websites. For more information about how to opt out of having your information used by Google Analytics, visit https://tools.google.com/dlpage/gaoptout/.
Mobile Apps
If you have granted our mobile apps access to your device’s camera, microphone, location, etc., you may revoke such access by configuring the permissions located in your device’s “Settings”.
Cookie Preferences
You may adjust your cookie preferences using your internet browser setting or, on some of our sites, by using the link in the footer of our website. Please note that if you clear all cookies on your browser, or use a different browser or computer, you will need to complete the opt-out procedure again.
You can request that inaccuracies pertaining to your Personal Information be corrected.
You can update some information by logging into your account or you may contact us as described in section 8 below with changes. To prevent unauthorized changes, we may ask for certain information to verify your identity before we process such requests.
We may not fulfill your request in some cases, for example, if it requires a disproportionate technical or practical cost or effort or if it conflicts with our legal obligations or business requirements.
We employ technical, physical, administrative, and organizational safeguards to help protect your Personal Information.
Our websites may contain links to other websites, services, social media platforms, etc. operated and maintained by partners. We may also provide social media features that enable you to disclose information with social networks and to interact with us on various social media sites. Your use of these features may result in the collection or sharing of information about you, depending on the feature. These properties, which we do not control, operate independently, and have their own privacy and security practices and statements, which we encourage you to review to make sure you understand the information that may be collected, used, and disclosed by those sites and how it is protected.
Unfortunately, no e-commerce solution, website, mobile application, database, or system can be guaranteed to be 100% secure. As a result, while we strive to protect your Personal Information, we cannot guarantee or warrant the security of the information you transmit to or from us. You should also take steps to protect your personal information against unauthorized disclosure or misuse:
If you think the Personal Information you provided to us has been improperly accessed or used, or if you suspect that unauthorized purchases have been made on our websites using your Personal Information, please see Section 8 below to contact us immediately.
If you are a contract customer and would like to opt-out of receiving promotional postal mail and/or email from us, please notify your Account Managers.
If you are a business entity receiving unsolicited communications from us and do not have an Account Manager, please see Section 8 below to contact us.
Under Nevada SB 220, Nevada residents may submit an opt-out request regarding the sale of their Personally Identifiable Information (PII) collected through a website or online service. You may submit your request to Opt-Out of the sale of Personal Information to third parties by submitting an online request at: Do Not Sell My Personal Information
This section applies specifically to residents of Virginia, in addition to all other non-state specific information contained in this Notice and sections 7.e. and 7.f. below.
Virginia residents have the following rights under the Virginia Consumer Data Protection Act (VCDPA):
To exercise the rights applicable to you, see instructions below in section 7.f. How to Exercise Your State-Specific Privacy Rights.
Targeted Advertising:
We may participate in targeted advertising. You have the Right to Opt-Out of this advertising, as described above.
Appeal Process:
Virginia residents may submit an appeal for refusals to take action on your request by emailing Privacy@Staples.com with your name, email address, phone number and request id of the original request.
De-identified Data:
In any instances where we maintain data in a de-identified format, we will not attempt to re-identify the data.
As an additional resource, you may also contact us at ConsumerRightsRequest@Staples.com for any additional questions related to the rights granted under the VCDPA.
Under California Civil Code sections 1798.83–1798.84, California residents may request a notice disclosing the categories of personal information we have disclosed with third parties, for the third parties’ direct marketing purposes, during the preceding calendar year. If you are a California resident and would like to make such a request, please see Section 8 below to contact us. Please allow 30 days for a response.
This section applies to residents of California, in addition to all other non-state specific information contained in this Notice and sections 7.e. and 7.f. below.
California residents have the following rights under the CCPA/CPRA:
To exercise the rights applicable to you, see instructions below in section 7.f. How to Exercise Your State-Specific Privacy Rights.
Authorized Agent:
You may designate an authorized agent to exercise your rights under the CCPA/CPRA on your behalf. You must provide the authorized agent written permission to exercise your rights under the CCPA/CPRA on your behalf and we may deny a request from an agent on your behalf if we cannot verify that they have been authorized by you to act on your behalf. Even if you use an authorized agent to exercise your rights under the CCPA/CPRA on your behalf, pursuant to the CCPA/CPRA we may still require that you verify your own identity directly to us. This provision does not apply if you have provided a power of attorney under the California Probate Code.
Opt-Out Signal:
An opt-out preference signal may be sent by certain platforms, technologies, or mechanisms on your behalf to communicate your choice to opt out of the sale/sharing of your personal information. Opt-out preference signals will opt you out of the selling/sharing of personal information at the browser level.
Metrics:
The following section describes consumer rights submission metrics for requests we received from January 1, 2022 through December 31, 2022 for Company business units (not limited to California residents):
Disclosure Requests |
Number of Requests Received |
13 |
Number of Requests Denied |
0 |
|
Number of Days to Resolve Requests (Mean) |
43 |
|
Deletion Requests |
Number of Requests Received |
116 |
Number of Requests Denied |
0 |
|
Number of Days to Resolve Requests (Mean) |
32 |
|
Do Not Sell My Personal Information Requests |
Number of Requests Received |
3533 |
Number of Requests Denied |
0 |
|
Number of Days to Resolve Requests (Mean) |
8 |
Minors:
We do not knowingly share or sell the Personal Information of children under 16 years of age.
Notice of Financial Incentive:
We may provide price discounts, coupons, services, and other perks to our customers and for members of our loyalty programs. Through these offerings, you may provide us with Personal Information depending on how you choose to interact with us when and after you opt-in to our programs. There is no obligation to opt-in, and you may opt-out at any time. The details of the programs are contained in the program offerings. We offer these programs, among other things, to enhance our relationship with you so you can enjoy more of our products/services at a lower price. While we invest in our marketing and brands, consumer data is more valuable to our business when it is combined with a sufficient amount of other consumer data and after it is enhanced by our efforts described in this Privacy Notice. The value to our business of any individual consumer’s data is dependent on several factors, including, for example, whether and to what extent you take advantage or opt out of any offerings and whether we are able to enhance the data through our efforts described in this Privacy Notice. While we do not calculate the value of consumer data in our accounting statements, we provide this good faith summary for California residents. To the extent we create overall business value from our programs that could be directly or reasonably related to the value of consumer data, the method for calculating the value would include: a) costs related to maintaining the program including but not limited to IT infrastructure, delivery of offers, and marketing activities to enhance consumer data; b) whether the sales generated by the program exceeds the cost to us of offering the program including value of discounts to consumer; and c) value of the insights we are able to create based upon aggregate data.
Data Retention:
We retain all categories of your personal information for as long as is necessary, even if you are no longer an active customer, to provide the goods and services and to fulfill the transactions you have requested of us, and to support other necessary purposes such as:
In determining how long to retain information, we may consider various criteria such as the amount, nature and sensitivity of the information, and the potential risk of harm from unauthorized use or disclosure of the information.
The purposes and criteria for which we process the data may dictate different retention periods for the same types of information. For example, we retain your email address as an authentication credential (where applicable) as long as you have an account with us and an additional period of time after that for our legitimate interests and for our fraud and legal compliance purposes. We may also retain cached or archived copies of your information.
Non-Discrimination:
We will not discriminate against you for exercising any of your CCPA/CPRA Rights and we will not deny you goods or services, charge you a different price, or provide you with a lesser quality of goods or services if you exercise any of your CCPA/CPRA Rights.
As an additional resource, you may also contact us at ConsumerRightsRequest@Staples.com for any additional questions related to the rights granted under the CCPA/CPRA.
If you are a data controller with a consumer rights request for us, please contact us at ConsumerRightsRequest@Staples.com.
For California and Virginia residents, the following section describes:
*Share/Shared/Sharing as defined by California and Virginia law.
Not all categories or examples of specific Personal Information may be collected about you depending on how you interact with us.
Categories of Personal Information We Collect |
Examples of Specific Personal Information that may be Collected |
Categories of Sources from which Personal Information is Collected
|
Purpose of Collecting Personal Information
|
Categories of Other Parties to whom Personal Information may be Disclosed
|
Categories of Third Parties to whom Personal Information is Sold/Shared and the Purpose of Sale/Sharing |
Identifiers |
Names, Account/Loyalty Program IDs, Emails, Addresses, Phone Numbers, IP Addresses, Other Device Identifiers, Tax Exempt Numbers, Driver’s License |
From You, Your Devices (when you visit our sites or use our apps), Service Providers (e.g., data brokers, fraud prevention companies), Business Partners, Social Networks |
To identify you in support of business activities such as fulfilling a transaction, communicating with you (order notification, etc.), personalizing your experience, fraud prevention, administering programs |
Advertising Networks and Service Providers/Business Partners such as cloud service providers, payment processing companies, fraud prevention companies, delivery companies, CA recycling partners, and product manufacturers |
Advertising Networks for the purpose of Marketing and improving their products and services |
Commercial Information |
Products or Services Purchased, Price or Service Quotations, Credit Card or other Financial Information, Chat Sessions, Feedback/Survey Responses, Copy/Print Materials, Website Account Credentials, Communications Entrusted to Us |
From You (when you transact with us or participate in any of our programs) |
To support a business transaction, communicating with you (surveys about your purchase, customer service, order notification, etc.), improve our products and services, to provide services you request of us |
Advertising Networks and Service Providers/Business Partners such as cloud service providers, fraud prevention companies, payment processing companies, delivery companies, and product manufacturers |
Advertising Networks for the purpose of Marketing and improving their products and services (We do not sell credit card or other financial information.) |
Biometrics
|
N/A |
N/A |
N/A |
None |
None |
Characteristics of Protected Classifications
|
Demographic information such as age ranges, marital status, etc. |
From You and Service Providers (e.g., data brokers, survey vendors, fraud prevention companies) |
To protect against fraud, enable you to apply for a company credit card, demographically understand our customers to improve our products and services |
Advertising Networks and Service Providers/Business Partners such as cloud service providers and marketing/sales analytics companies |
None |
Internet or Other Electronic Network Activity |
Browsing activity, searches, and other interactions on our websites or mobile apps (such as text entered, pages visited, links clicked, keystrokes/ cadence, and mouse movements), your interactions with our ads |
From You, Your Devices (when you access our websites or mobile apps) and fraud prevention companies |
To send marketing to you, improve our products and services, fraud prevention, etc. |
Advertising Networks and Service Providers/Business Partners such as cloud service providers, fraud prevention companies, and eCommerce analytics companies |
Advertising Networks for the purpose of Marketing and improving their products and services |
Geolocation Data |
Location based on IP address or mobile device location information |
From You, Your Devices (when you access our websites or mobile apps), Service Providers (e.g., data analytics providers, fraud prevention companies) |
To personalize your experience, display store locations near you, fulfill your orders, analyze web/app traffic, fraud prevention |
Advertising Networks and Service Providers/Business Partners such as cloud service providers and eCommerce functionality vendors |
None |
Recordings/ Electronic Communications (e.g., audio, visual, chat, etc.) |
Voice, Video, Chat, and CCTV Recordings |
From You (calls with customer service or sales, or when you visit some of our locations), Service Providers (e.g., chat service providers, call recording software providers) |
For quality assurance, training and analysis purposes, to improve our products and services, fraud prevention |
Service Providers/Business Partners such as cloud service providers and customer service call recording companies |
None |
Professional or Employment-Related Information |
Employer Name and Job Title
|
From You (e.g., when you inquire about our programs), Service Providers (e.g., data brokers), Business Partners |
To send you marketing, personalize your experience, enroll you in certain programs at your request |
Advertising Networks and Service Providers/Business Partners such as cloud service providers and program administrators |
None |
Education Information |
School Affiliations |
From You (when you participate in certain programs such as Classroom Rewards) |
To administer certain programs |
Advertising Networks and Service Providers/Business Partners such as cloud service providers and program administrators |
None |
Inferences |
Product and Service Preferences |
From You (when you tell us what products and service are of interest), by analyzing other data we have about you, Service Providers (e.g., advertising networks, fraud prevention companies), Social Networks |
To provide you personalized experiences and marketing, group you into segments with other similar customers, improve our products and services |
Advertising Networks and Service Providers/Business Partners such as cloud service providers and marketing/ eCommerce analytics companies |
None |
Sensitive Personal Information* |
Driver’s License Number, Passport Number, Contents of Mail, Precise Geolocation |
From you, postal mail that you requested we receive/process, your mobile device |
To fulfill the services you requested of us |
Returns Processing Vendor, Passport Processing Vendor, Mail Service Vendor, Store Locator Service |
None |
The above categories are intended to encompass the Personal Information described in subdivision (e) of Section 1798.80 of the California Civil Code.
*We do not collect or process Sensitive Personal Information for the purpose of inferring characteristics about you.
California and Virginia residents may submit a Right to Know/Access request by either:
California and Virginia residents may submit a Data Correction or Data Deletion request by either:
California and Virginia residents may submit a request to Opt-Out of Targeted Advertising, Selling/Sharing with Third Parties, or Profiling by either:
We will take reasonable steps to verify your above request prior to fulfilling it by requiring a response to a confirmation email sent to the email address on the request. For purposes of verifying your identity, we will request that you provide personal information we already have on file including your first and last name, email address, and phone number. We may also request mailing address and, if applicable, your account number, login ID for our websites, and rewards/loyalty number to ensure that we have a verified match. We will respond to your request and let you know if we need additional information.
We consider "personal information" to be information about an identifiable individual. We do not consider public information found in directories and listings, or business names, addresses and/or contact numbers to be personal information.
As applicable to Canadian residents, we recognize the 10 personal information privacy principles stated in the Canadian Standards Association (CSA Group) Model Code for the Protection of Personal Information. The 10 principles are: