Privacy Policy
Last Updated: 05/08/2023
This Privacy Policy describes how Gregorysshepard.com ( “We” or “Us” or “Our”) uses and discloses the Personal Information you provide to us or that we collect when you use our websites, mobile applications, software, platforms and services (“Services”). Before providing Personal Information to us, please review this Privacy Policy carefully.
Certain Services may use a different privacy policy to provide notice to you about how we use and disclose the Personal Information we collect in the context of that Service. To the extent that we post or reference a different privacy policy, that different privacy policy, not this Privacy Policy, will apply to your Personal Information collected in the context of that Service.
1. GregoryShepard Users
Our treatment of Client Personal Information is governed by our agreements with you, Organizations, Entrepreneurs, Entrepreneur Affiliated Individual, Investors and Advisors with and through the Services (“Site Users”), including our Terms of Service, as applicable (our “Agreement”). If any provision in our Agreement with our Customers conflicts with any provision in this Privacy Policy, the provision in the Agreement will control to the extent of such conflict.
If you are an Entrepreneur, Entrepreneur Affiliated Individual, Investor and Advisor, we will also direct you to the Organization, who is the controller of your personal information. Please see the “California Privacy Statement” and “Additional State Privacy Laws” and "GDPR" sections of this privacy policy for more details. Any capitalized term not defined in this Privacy Policy, shall have the meaning ascribed in the Agreement.
Regardless, we may retain your Personal Information on behalf of that Organization. If you have questions about how we process your Personal Information, we encourage you to reach out to the appropriate Organization or visit our Support portal https://support.startupscience.io/knowledge or email support@startupscience.io
2. How We Collect and Use Your Personal Information
“Personal Information” is information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your household, such as your name, email address, IP address, telephone number, and broader categories of information such as your professional, educational or health information, commercial information and internet activity.
In the course of our business and in providing our Services to you, we may collect Personal Information directly from you and automatically through our use of cookies and other data collection technologies. We may also collect your Personal Information from third-party sources, such as social media platforms (if you interact with us through your social media account). We will treat Personal Information collected from third-party sources in accordance with this Privacy Policy but we are not responsible for the accuracy of information provided by third parties or for their policies or practices.
​
The categories of Personal Information we collect from you depend on your interactions with us. For example, we may collect:
-
Identifiers and contact information, such as your name, email address, mailing address, phone numbers, social security numbers, government-issued IDs (such as driver’s licenses), IP addresses, and unique identifiers such as your usernames and passwords. We collect this information directly from you and from third-party sources for the purpose of creating and managing your BSS account (“Account”), for communicating with you, verifying your identity, and providing our Services to you.
-
Professional and employment-related information, such as your business name, your license number, calendar and scheduling information, and other information related to your business. We collect this information directly from you for the purpose of administering your Account and providing you our Services.
-
Transactional information, to process billing information and transactions within the Client Portal;
-
Audio, electronic and visual information, such as your photograph or image, your voice and other similar information.
-
Internet and other electronic network activity information, such as your browsing history, search history, and your interactions with our Services and advertisements. We collect this information through our cookies and other tracking technologies to conduct business analytics in order to improve our business functionality and Services to you. Please review the “Tracking Technologies and Cookies” section below to learn more about our use of cookies and tracking technologies.
-
Commercial information, such as from BSS Materials. We collect this information to maintain user records, identify trends in our user relationships, and conduct business analytics.
-
Profile information and inferences, such as information about your preferences and characteristics. We collect profile information by drawing inferences from the above categories of Personal Information in order to understand your preferences and tailor our services and communications to you, after you agree to share this information with us.
-
Entity information on an Entrepreneur including any information that an Entrepreneur enters on their Entrepreneur Company profile. This may include, but is not limited to, entity information (year incorporated, incorporation location), industry vertical, company mission statements, product or service information, product or service demo video recordings or presentations, market information (such as market sizes, growth rates and average customer metrics), customer personas, exit strategy goals, funding received so far or planned for in the future, and any other information you choose to share on your Company profile or in a submission to an Organization.
-
Information we receive from authentication services you connect to our Sites. Some parts of our Sites may allow you to login through a third-party social network or authentication service such as Google. These services will authenticate your identity and provide you the option to share certain personal information with us, which may include your name, email address, or other information. The data we receive is dependent on that third party’s policies and your privacy settings on that third-party site. We will treat Personal Information collected from third party sources in accordance with this Privacy Policy, but we are not responsible for the accuracy of information provided by third parties or for their policies or practices. If you choose to connect a Google or Gmail account to our Services, we will ask you to grant us application permissions to access your Gmail account. These permissions are necessary to sustain the functionality of our Sites. We will store your authentication token and account email address. This data will be securely stored to be used by us to provide you with the Services (including, but not limited to, allowing you to access the Sites). This data will not be voluntarily shared with any third parties, but we may provide this information to legal authorities upon their lawful request. You may choose to disconnect your Gmail account at any time. We do not use data obtained from Clients (from their Google accounts) for advertising purposes. We may need access to the user data to resolve a support issue, provide advice on service usage or provide any other help requested by the Client, or as such access may be necessary for a security investigation or to comply with applicable laws. We use this information to operate, maintain, and provide to you the features and functionality of the Services. We may also send you service-related emails or messages (e.g. Client support, changes, or updates to features of the Services, or technical and security notices).
​
3. How We Use Personal Information
In addition to the purposes for collection described above, we also collect your Personal Information for the following general purposes:
-
To maintain and service your Account, including to confirm your orders, to send you requested product and Service information, and to send you product and Service updates;
-
To respond to your customer service requests and address your questions and concerns;
-
To process billing information and transactions within the Site;
-
To authenticate your identity and allow you to view, fill out, and sign documents in the Site;
-
To send you newsletters and marketing communications;
-
To administer and improve our Services and marketing efforts, including measuring the effectiveness of the websites, diagnosing problems with our servers, and analyzing traffic;
-
To detect security incidents, to protect against malicious, deceptive, fraudulent or illegal activity, and to comply with our policies and procedures;
-
To comply with our legal, regulatory and risk management obligations, including establishing, exercising and/or defending legal claims, to respond to law enforcement requests and as required by applicable law, court order, or governmental regulations, and to comply with applicable state and federal laws, including, but not limited to laws related to protecting Client and public health and safety;
-
Any other purpose with your consent.
4. How We Share and Disclose Your Personal Information
We may share your Personal Information in the following circumstances:
-
Publicly, meaning to those who are not Organizations, Entrepreneurs, Entrepreneur Affiliated Individuals, Investors and Advisors, but only with your permission: We may share your Personal Information publicly with your permission. For example, with your permission, we may publicly post your photograph, your name, professional titles, and comments on the “Reviews” section of our websites.
-
To Service Providers: We may share your Personal Information with companies that provide services to us, such as for hosting, marketing and communication services, and payment processing (“Service Providers”).Our policy is to authorize these Service Providers to use your Personal Information only as necessary to provide services for us, and require that they not use or disclose your Personal Information for any other purpose.
-
To third parties outside of GregoryShepard:
-
From time to time, we may be required to provide Personal Information to a third party in order to comply with a subpoena, court order, government investigation, or similar legal process.
-
Organizations, Entrepreneurs, Entrepreneur Affiliated Individuals, Investors and Advisors
-
We may also share your Personal Information to third parties, such as law enforcement agencies, when we, in good faith, believe that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
-
To any other third party with your prior consent to do so.
-
-
We may share your Personal Information with Organizations, Entrepreneurs, Entrepreneur Affiliated Individuals, Investors and Advisors who have Gregory Shepard Accounts. Specifically, Startup Science products are designed to share information you provide regarding your Company, Entity or Organization with other Organizations, Entrepreneurs, Entrepreneur Affiliated Individuals, Investors or Advisors. In addition, we may share analytic data regarding your use of the educational material, courses and tools on the site with the Organizations with which you are affiliated.
-
In a corporate transaction: If Gregory Shepard is involved in a bankruptcy, merger, acquisition, reorganization, or sale of all or a portion of its assets, we may share or transfer your Personal Information as part of any such transaction.
We do not sell your Personal Information.
5. Access and Choice
Account Settings
If your Personal Information changes, you may modify logging into your Account and making the changes in your Account settings. While we may delete your information from the Sites as provided in this Privacy Policy, information submitted or shared with those with BSS Accounts on the Sites may be retained by those users, on the Sites or outside the Sites and you agree that BSS has no control over and no responsibility for the use of such data.
Marketing Opt-out Preferences
You can opt out of receiving marketing emails by using the unsubscribe link contained in the email. We may still send you emails about your relationship with us and your transactions, including Account information and alerts, purchase confirmations, and updates to our products, services and policies.
6. Data Collection Technologies and Cookies
As is true of many digital properties, we and our third-party partners, or Organizations, Entrepreneurs, Entrepreneur Affiliated Individuals, Investors and Advisors may automatically collect certain information from or in connection with your device when visiting or interacting with our Services, such as:
-
Log Data, including internet protocol (IP) address, operating system, device type and version, browser type and version, browser id, the URL entered and the referring page/campaign, date/time of visit, other user agent string data, the time spent on our Services, and any errors that may occur during the visit to our Services). Log data may overlap with the other categories of data below.
-
Analytics Data, including the electronic path you take to our Services, through our Services and when exiting our Services, UTM source, as well as your usage and activity on our Services, such as the time zone, activity information (first and last active date and time), usage history (emails opened, total log-ins) as well as the pages and links you view, click or otherwise interact with.
-
Location Data, such as general geographic location which can be inferred based on your IP address.
We and our third party providers may use (i) cookies and other tracking technologies (including from Google, Facebook and LinkedIn) to keep, and sometimes track, information about you on our Services and (ii) other, related technologies, such as web beacons, pixels, SDKs, embedded scripts, and logging technologies (“cookies”) to automatically collect this information. We may use this information to monitor and analyze how you use and interact with our Services. Cookies are small data files that are sent to your browser from a web server and stored on your computer's hard drive. Cookies track where you travel on the Services and what you view. In doing so, a cookie may enable us to relate your use of the Services to your Personal Information.
We may use information gathered from these tracking technologies so that we can analyze trends, administer the Services, track users’ movements around the Services, and gather demographic information about our user base as a whole. We may combine information we obtain through tracking technologies with other Personal Information that we have collected about you in order to make our Services, communications and advertisements more targeted to your interests. If you would prefer not to accept cookies, most browsers will allow you to change the setting of cookies by adjusting the settings on your browser to: (i) notify you when you receive a cookie, which lets you choose whether or not to accept it; (ii) disable existing cookies; or (iii) set your browser to automatically reject cookies. Be aware that disabling cookies may negatively affect the functionality of this and many other websites that you visit. Disabling cookies may result in also disabling certain functionalities and features of the Sites.
You may also opt out of targeted advertisements by visiting the Network Advertising Initiative opt out page. Depending on your device and operating system, you may not be able to delete or block all cookies. In addition, if you want to reject cookies across all your browsers and devices, you will need to do so on each browser on each device you actively use. You may also set your email options to prevent the automatic downloading of images that may contain technologies that would allow us to know whether you have accessed our email and performed certain functions with it. Do Not Track
Please note that the Services are not presently configured to respond to DNT or “do not track” signals from web browsers or mobile devices. As such, we do not recognize or respond to Do Not Track requests.
7. Retention and Security
We will retain your Personal Information for as long as your Account is active, as needed to provide you Services, and as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
We follow generally accepted standards to protect the Personal Information submitted to us, both during transmission and once we receive it. For example, when you enter sensitive information (such as a credit card number and login credentials), we encrypt the transmission of that information using secure socket layer technology (SSL). However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee its absolute security.
8. California Privacy Statement
California residents have certain rights under the California Shine the Light law and the California Consumer Privacy Act (“CCPA”) and the California Privacy Rights Act (“CPRA”). The CPRA provided amendments and updates to the CCPA.
CCPA Disclosures
In general, within the preceding 12 months:
-
We have collected the categories of Personal Information listed in Section 2 above.
-
We have collected these categories of Personal Information directly from you, when you use our Services, and from third parties for the purposes described in Section 2 above.
-
We have disclosed the following categories of Personal Information for business purposes: Identifiers and contact information; billing information, professional and employment-related information; commercial information; transactional information; and internet and network activity information.
-
We have not sold your Personal Information.
CPRA and CCPA Privacy Rights
Certain California residents are entitled to privacy rights under the CPRA and CCPA. Customers who wish to exercise these rights should direct their requests to the registered member that controls their Personal Information.
-
The right to know. You have the right to request to know (i) the specific pieces of Personal Information we have about you; (ii) the categories of Personal Information we have collected about you in the last 12 months; (iii) the categories of sources from which that Personal Information was collected; (iv) the categories of your Personal Information that we sold or disclosed in the last 12 months; (v) the categories of third parties to whom your Personal Information was sold or disclosed in the last 12 months; and (vi) the purpose for collecting and selling your Personal Information.
-
The right to deletion. You have the right to request that we delete the Personal Information that we including our third-party Service Providers, Organizations, Entrepreneurs, Investors and Advisors, have collected or maintain about you. We may deny your request under certain circumstances, such as if we need to comply with our legal obligations, the retention of such information is within our archival process or to complete a transaction for which your Personal Information was collected. If we deny your request for deletion, we will let you know the reason why.
-
The right to correct. You have the right to request correction of any inaccurate Personal Information we have about you.
-
The right to opt-in and opt-out of sharing and selling of your Personal Information. We do not sell your Personal Information. We only share your Personal Information as outlined in this privacy policy to provide our Services to you.
-
The right to equal service. If you choose to exercise any of these rights, we will not discriminate against you in anyway. If you exercise certain rights, understand that you may be unable to use or access certain features of our Services.
You may exercise your right to know and your right to deletion twice a year free of charge. To exercise your right to know or your right to deletion, contact us at privacy@startupscience.io
We will take steps to verify your identity before processing your request to know or request to delete. We will not fulfill your request unless you have provided sufficient information for us to verify you are the individual about whom we collected Personal Information. If you have an Account with us, we will use our existing Account authentication practices to verify your identity. If you do not have an Account with us, we may request additional information about you to verify your identity. We will only use the Personal Information provided in the verification process to verify your identity or authority to make a request and to track and document request responses, unless you initially provided the information for another purpose.
You may use an authorized agent to submit a request to know or a request to delete. When we verify your agent’s request, we may verify both your and your agent’s identity and request a signed document from you that authorizes your agent to make the request on your behalf. To protect your Personal Information, we reserve the right to deny a request from an agent that does not submit proof that they have been authorized by you to act on their behalf.
Shine the Light
Our California customers are also entitled to request and obtain from BSS once per calendar year information about any of your Personal Information shared with third parties for their own direct marketing purposes, including the categories of information and the names and addresses of those businesses with which we have shared such information. To request this information please contact us at privacy@startupscience.io
9. Additional State Privacy Laws
Startup Science takes your privacy and data protection very seriously, and we work vigorously to ensure we remain compliant with applicable federal and state privacy laws.
Under the Virginia Consumer Data Protection Act (VCDPA), effective January 1, 2023, Virginia residents have additional privacy rights. If you who wish to exercise these rights should send an email to privacy@startupscience.io and also direct their requests to the Organization who controls their Personal Information.
-
The right to know, access and confirm personal data. You have the right to know whether or not we are processing your personal data and to access such personal data.
-
The right to deletion. You have the right to request that we delete the Personal Information that we, including our third-party service Providers, have collected or maintain about you. We may deny your request under certain circumstances, such as if we need to comply with our legal obligations or complete a transaction for which your Personal Information was collected. If we deny your request for deletion, we will let you know the reason why.
-
The right to correct. You have the right to request correction of any inaccurate Personal Information we have about you.
-
The right to data portability. You have the right to easy and portable access to all pieces of Personal Information that we have collected or maintain about you.
-
The right to opt-out of the processing of personal data for targeted advertising purposes. We do not use your Personal Information for targeted advertising. We may use your Personal Information, however, to provide updates to you about our product and Services and other necessary communications in the course of providing our services to you and your Organization.
-
The right to opt-out of the sale of personal data. We do not sell your Personal Information. We only share your Personal Information as outlined in this privacy policy to provide our Services to you.
-
The right to opt-out of profiling based upon personal data. You have the right to opt-out of any processing of personal data for the purposes of profiling for decisions that produce legal effects or similarly significant effects on you. We do not use your Personal Information for this purpose.
-
The right to equal service. If you choose to exercise any of these rights, we will not discriminate or retaliate against you in any way. If you exercise certain rights, understand that you may be unable to use or access certain features of our Services.
Per the VCDPA, information provided in response to your requests shall be provided by us, free of charge, up to twice annually per user. We will update this privacy policy periodically and as necessary to maintain compliance with the evolving privacy landscape.
​
10. GDPR and European users
The rules of the EU General Data Protection Regulation cover European users of the platform. GDPR grants the following rights to data subjects:
The right of access (art 15) : You have the right to access that data and to be provided with a copy and get any relevant additional information (such as reason for processing your personal data, the categories of personal data used, etc.).This right of access should be easy and be made possible at reasonable intervals. You should get a copy of your personal data free of charge. Any further copies may be subject to a reasonable fee.
The right to rectification (art 12) : You have the right to request correction of any inaccurate Personal Information we have about you
The right to erasure (art 2, 17 and 23) : also known as the right to be forgotten. You have the right to request that we delete the Personal Information that we, including our third-party service Providers, have collected or maintain about you. We may deny your request under certain circumstances, such as if we need to comply with our legal obligations or complete a transaction for which your Personal Information was collected. If we deny your request for deletion, we will let you know the reason.
The right to restrict processing (art 18): That right can be exercised when the accuracy of the data in question is contested; when you don’t want the data to be erased; when the data is no longer needed for the original purpose but may not be deleted yet because of legal grounds or when the decision on your objection to processing is pending.
The right to data portability ( art 20) : You have the right to easy and portable access to all pieces of Personal Information that we have collected or maintain about you.
The right to object (art 7,12 and 21): You have the right to object to the processing of your personal data and the company to stop processing your personal data if is being processed for the purpose of direct marketing; scientific/historical research and statistics or their own legitimate interest or in carrying out a task in the public interest/for an official authority.
The right not to be subject to a decision based solely on automated processing (art 22) : GDPR grants the data subject the right not be subject to a decision based solely on automated processing means, if the decision produces legal effects concerning you or significantly affects you in a similar way.
You can refer to the European Commission web site here for more information on GDPR.
11. Additional Information
Information for Visitors from Outside of the United States
We are committed to complying with this Privacy Policy and the data protection laws that apply to our collection and use of your Personal Information. We are located in the United States, where the laws may be different and, in some cases, less protective than the laws of other countries. By providing us with your Personal Information and using the Services, you acknowledge that your Personal Information will be transferred to and processed in the United States and other countries where we and our vendors operate.
Social Media Widgets
Our Services may include social media features, such as the Facebook Like button, and widgets, such as the “Share this” button, or interactive mini-programs that run on our websites (collectively referred to as “Features”). These Features may collect your IP address, which page you are visiting, and may set a cookie to enable the Feature to function properly. The Features are either hosted by a third party or hosted directly on our Services. Your interactions with these Features on a third-party site are governed by the privacy policy of the company providing it.
Links to Other Sites
The Services may contain links to other sites that are not owned or controlled by GregoryShepard. Please be aware that we are not responsible for the privacy practices of such other sites. We encourage you to be aware when you leave our site and to read the privacy statements of each and every website that collects Personal Information. This Privacy Policy applies only to information collected by our Services.
Children’s Privacy
Our Services are not directed to, and we do not knowingly collect any Personal Information from children under 13.
Changes to This Policy
We may update this Privacy Policy to reflect changes to our information practices. If we make any material changes, we will notify you by email (sent to the email address specified in your Account) or by means of a notice on our websites prior to or upon the change becoming effective. We encourage you to review this page periodically for the latest information on our privacy practices.
12. Contact Us
For help with matters not related to exercising your rights under the aforementioned privacy laws, please contact us at support@startupscience.io