SMAC's Privacy Policy
DAC Privacy Policy as of 09/01/2024
Released on September 2024
Thank you for using the SM Advantage (“SMAC”) Loyalty & SHOP Online e-Commerce Platform (“SMAC&SHOP”)! SMAC&SHOP is the newest innovation from Digital Advantage Corporation team which affords its SMAC members exclusive and rewarding online shopping experience.
Who we are:
Digital Advantage Corporation (“DAC”, “we”, “us” or, “our) operates and manages the SMAC Loyalty Program which is the biggest loyalty program in the country with the widest network of stores like SM Store, SM Markets, specialty stores, and other partner merchants where SMAC members can earn and redeem points every time they shop. SMAC members also get exclusive access to sale events, discounts, special offers, and freebies from SM group and our partner merchants. SMAC members who meet the criteria and spending level in a year may be upgraded to SMAC Prestige, an elite version of SMAC.
DAC is also the owner and operator of the SMAC&SHOP e-commerce platform and mobile application through which SMAC members can manage their SMAC accounts (such as link/unlink cards, check/transfer points, view transaction history and other functionalities), conveniently purchase from SMAC merchant partners and earn/redeem SMAC points/rewards.
What does this Privacy Policy cover:
This Privacy Notice describes how we handle your personal information when you interact with us or avail of any of the following services, namely:
· Membership in the SMAC or SMAC Prestige Loyalty Program, including such activities which are related thereto such as, program administration, earning, awarding and availment of points or membership privileges;
· Account or membership administration;
· Usage of the SMAC&SHOP platform and mobile application, including its related ecommerce transactions, fulfillment and delivery/pick-up services;
· Customer service and marketing activities;
· Promotional activities or events;
This policy also outlines the purposes for which we use your personal information and the measures we implement to protect the privacy and security of your information.
Our Commitment
We value and respect the SMAC members’ privacy rights under the Data Privacy Act of 2012 (DPA) and other applicable privacy laws. The objective of this Privacy Policy (or “policy”) is to inform SMAC members how we collect, use, share, retain, and dispose their personal data in relation to their membership with the SMAC Loyalty Program and its related services. This
policy also outlines our practices and the security measures we have in place to ensure that our members’ personal data are protected and processed in accordance with the purposes disclosed in this policy and the law.
What We Collect
DAC may request the SMAC member to provide his or her personal data, depending on the services which the member is using. The personal data we may collect from you are as follows:
· If you access any SMAC website or online applications
o IP address
o Device information
o Browsing behavior
· If you create a SMAC account through our website or mobile app
o Full name
o Mobile number
o Email address
o Birthday
o Password
o Purchase history
o Gender
o Civil status
o Shopping preferences
· If you register your SMAC or link a retail affiliate loyalty card through our website or mobile app
o Full name
o Mobile number
o Email address
o Birthday
o Password
o SMAC card number
o Loyalty account number of retail affiliates such as Ace Rewards, Mom Card, Love Your Body, Toy Kingdom
o Purchase history
o Gender
o Civil status
o Shopping preferences
· If you visit any SMAC Prestige lounge or SMAC customer service counter
o Video footage
o SMAC card number
· If you contact the SMAC contact center
o Full name
o Contact number
o Email
o SMAC card number
o Nature and details of inquiries, concerns, or complaints
o Birthday
· If you purchase through SMAC&SHOP: o Name
o Contact number
o Email address
o Delivery address
o Billing Address
o Quantity
o Items ordered (SKU)
o Total Order Value When you pay via credit card, debit card, or e-wallet, you will be redirected to a secure payment method form owned and operated by an independent payment gateway service provider, which shall collect and process your financial information pursuant to its own terms and policies.
The SMAC member is responsible in ensuring that the personal data he provides is accurate and updated. Any member may update his or her personal data at any time by accessing the member’s SMAC account on the SMAC&SHOP website or mobile application. DAC and its affiliates, specialty stores, service group, or partner merchant shall not be held liable for any loss, damage, injury or claim arising from the member’s failure to keep his account information or personal data updated.
How We Use Your Personal Data
We will use your information only for the following legitimate purposes (“Purposes”):
· Customer Interaction and Service:
For administration of the SMAC Loyalty Program, including registration, maintenance of the SMAC account, points earning or redemption, and such services related to the SMAC Loyalty Program;
Providing you with products, services, promos, or activities that you have availed;
Processing your orders, payments and completing your transactions with us;
Contacting you in relation to your inquiries, requests or complaints;
Maintaining your accounts when you register in or use our digital platforms, including our mobile applications;
Verifying your identity when you access your account;
· Analytics, Marketing and Promotion:
Performing data analytics and profiling for statistical, marketing, analytical, and research purposes;
Conducting business analyses to improve our goods and/or services;
Sending out market surveys, campaigns, promotions, and other marketing activities;
Communicating relevant products and services and advisories to you;
· Legal and Regulatory Purposes:
Complying with the requirements of the law and legal proceedings;
Preventing, detecting, and investigating a crime;
Pursuing or defending our legal claim, if any;
· Security and General Business Operations:
Ensuring the security of our premises and the safety of our personnel and visitors; and
Carrying out other legitimate business purposes.
Member’s Consent
By signing up for SMAC membership or purchasing a SMAC membership kit or by accessing our website/ app or creating a SMAC account or by registering your SMAC card through our websites and/or mobile applications or by linking your retail affiliate loyalty card to your SMAC account or by member’s continued use of his/her SMAC (or SMAC&SHOP) account and availment of SMAC privileges, the member confirms that he or she has read, understood, and agreed to be bound by this policy and consents to the collection, use, sharing or otherwise processing of the member’s personal data by DAC and its service group, affiliates, specialty stores, and partner merchants obtained at the time of submission of application of membership, whether manually or electronically, and/or upon purchase of the SMAC membership kit. DAC shall continue processing the member’s personal data as long as the member maintains his membership or continues to use SMAC.
By using SMAC and/or participating in the SMAC Loyalty Program or using SMAC&SHOP, the member reaffirms his consent to the processing of his personal data. Below is a copy of the member’s consent:
“By signing up for SMAC Membership or by purchasing a SMAC membership kit or by accessing the SM Advantage (SMAC) or SMAC&SHOP website or app or creating a SMAC account or registering your SMAC card through the SMAC SMAC&SHOP website or app or by linking your retail affiliate loyalty card to your SMAC account or by member’s continued use of the SMAC or SMAC&SHOP website or app or availment of SMAC privileges, you signify that you have read, understood, and agreed to be bound by the Terms and Conditions and Privacy Policy of Digital Advantage Corporation (DAC) for SMAC.
Subject to applicable privacy laws and regulations, you hereby give your full and informed consent to DAC, its parent company, affiliates, specialty stores, partner merchants, and service group to collect, use, store, share or otherwise process your personal data in accordance with the purposes disclosed in the SMAC&SHOP Privacy Policy, such as but not limited to, account management, direct marketing, data analytics, announcements on system enhancements, updates, discounts, sales and marketing promotions, and/or for the performance of such other services which you may request from DAC. In case you are chosen as a winner in any SMAC contests, promotional campaigns or automated electronic draws, you hereby give your consent to DAC to publish your full name in social media or in such media which may be necessary to comply with requirements of regulatory agencies.”
The member can withdraw or modify the scope of consent anytime by contacting our data protection officer in the contact details below or through the opt-out procedures in our emails or your SMAC account. Please note that should you opt to withdraw or limit the scope of consent provided, we may not be able to provide certain services and the member is unlikely to receive our optimal overall member experience. If you opt out of receiving promotional communications from us, we may still send you non-promotional communications such as emails about your accounts or our ongoing business relations.
Do We Share Your Personal Information to Other Entities?
We ensure that your personal information shall be shared only in a manner that respects your privacy and in compliance with the requirements of the DPA. We may share your personal information to the following in certain circumstances:
· Our Parent Company, Affiliates, and Authorized Personnel:
We may share your personal information to our parent company, affiliates, and our authorized personnel in relation to the Purposes declared in this Privacy Policy. We may also share your personal information to any business or legal entity that acquires the SMAC business, whether in whole or in part.
· Service Group:
Our service group may access and/or use your personal information. These may include our IT providers, data encoders, website and database hosts, couriers and delivery, advertising and marketing service providers, card printers, and partner merchants in line with the SMAC points earning/redemption program, and those that help us with our business activities.
Our service providers have confirmed that they apply appropriate data protection policies and security controls to keep your personal data safe and secured. We have also imposed contractual obligations on these service providers to ensure that they will only use your personal data to render the services agreed upon in relation to your SMAC membership. We only share such information that is needed to provide services
to you and if we stop using a third party, we require them to return, destroy or remove your information from their systems. We do not, and will not, sell your personal data. For members who will purchase from merchants on the SMAC&SHOP app or website, we may share your name and contact details to the merchant concerned for purposes of fulfilling the orders and for marketing purposes so you can be informed of special discounts and privileges that you may avail of from the said merchants. Through the execution of data privacy agreements or similar contracts, we require our partner merchants to keep your personal information secure and we prohibit them from using or sharing your personal information for any purpose other than the purposes declared in this Privacy Policy and the agreement.
· Government Agencies:
We may also share your personal data in compliance with applicable laws or when required by a competent court, relevant government office or agency pursuant to DPA legislation and other applicable rules and regulations pertaining to data privacy.
1. What are our Legal Bases for the Processing of Your Personal Information?
We may process your personal information based on one or more of the following legal grounds:
Consent: We may process your personal information or sensitive personal information based on your explicit consent. This means that you have provided clear and voluntary permission for us to use your data for specific purposes, which you can withdraw at any time. Please note, however, that should you opt to withdraw, modify or limit the scope of consent provided, we may not be able to provide you with the services which you require.
By continuously availing of our services or by your continued use of our website and mobile application, you reaffirm the consent you have provided and authorize us to process your personal data pursuant to this Policy.
Contractual Obligation: If you have entered into an agreement with us, we may process your personal information to fulfill our obligations under that contract. This includes providing the services or products you've requested and managing the associated transactions.
Legal or Regulatory Obligation: In certain situations, we may need to process your personal information or sensitive personal information to comply with legal or regulatory requirements, such as tax regulations, or to respond to lawful requests from government authorities.
Legitimate Interests: We may process your personal information when it's necessary for our legitimate interests, provided those interests are not overridden by your rights and interests. This could include improving our services, conducting marketing activities, or ensuring the security of our systems.
What are the Risks Involved?
Risk is the chance that a harmful incident may happen. In the context of personal data, risk refers to the chance that someone might collect, use, disclose, or access your personal data in an unauthorized manner or in a way that may cause you harm. In order to ensure that the risks to your personal information are minimized, we employ various measures to safeguard your personal information. However, this does not guarantee protection against all threats such as when systems are exposed to targeted cyberattacks, malware, ransomware, and computer viruses or when manual records are accessed without authority. In case a security incident occurs, we’re prepared to respond and manage such incidents in line with our policies and in accordance with regulations.
Where We Process and Store Data
DAC stores, processes, and transmits personal data within the Philippines. DAC shall comply with the applicable laws and regulations should it become necessary to process or store your data in another jurisdiction.
Information Security
DAC ensures the security and protection of your personal data against risk of data loss, unauthorized access and disclosure, alteration and unlawful processing. Aside from establishing policies, rules and procedures, the company also ensures that all information are secured and protected within the scope of the organization. DAC conducts periodic Privacy Impact Assessments to evaluate and manage the privacy implications of projects, programs and processes. DAC also ensures that a Personal Data Breach Management is in place.
DAC uses various appropriate measures to safeguard your personal information. This includes but not limited to:
Organizational measures: appointment of Data Protection Officer, access control policy, security awareness training, among others.
Physical measures: security on data centers, card storage, biometric devices, among others.
Technical security measures: encryption, anti-virus software, among others.
How Long We Will Store Your Information
DAC will store your information for as long as the member retains his or her membership to the SMAC Loyalty Program or, for as long as needed for us to be able to provide the relevant services to the member. DAC’s general retention policy is to retain information for 3 years from expiration or termination of SMAC membership.
In some circumstances, such as to meet our legal or regulatory obligations, resolve disputes, prevent fraud and abuse, or enforce the SMAC Terms and Conditions, we may retain your personal data beyond the 3-year period.
Disposal of Your Personal Data
Electronic files shall be erased, while physical records shall be shredded for disposal. When appropriate, anonymization techniques may be performed to permanently remove identifiable information from our records. In all cases, we will make sure that the personal information is destroyed in a way that prevents unauthorized people from accessing, processing or retrieving it.
Collection of Computer Data
We or our authorized service providers may use cookies, web beacons, and other similar technologies for storing information to provide you with a better, faster, safer, and personalized experience when you use the SMAC or SMAC&SHOP services and/or access our digital platforms and technologies.
Cookies contain information about the web activities of the user. This allows DAC to understand more about your visit and help us to enhance your experience and may be used for authentication and storing website information or preferences. You are free to accept or decline cookies by modifying your browser setting to decline cookies. However, should you choose to decline cookies, you may not be able to fully experience the features of our website and app.
Web beacons are small graphic images that may be included in the services available on our website and app digital. These will allow DAC to count users who have viewed these pages, the time spent on the pages, items searched for, among others, to better understand your preference and interests so we can improve our services.
If you do not want to accept cookies from the SMAC or SMAC&SHOP website and app, you can remove or reject cookies in your browser settings. If you choose to do this, please be aware that SMAC or SMAC&SHOP website and app may no longer function as intended.
The Rights of the Data Subject
As provided under the DPA, you have the following data privacy rights:
Right to be informed. You have the right to be informed of the collection and processing of your personal data, the purpose for which they will be processed, among others. Thus, you are required to read this privacy notice before giving your consent to the collection and processing of your personal data.
Right to object. You have the right to object to the processing of your personal data. You will be given an option or opportunity to withhold your consent to the processing of your personal data whenever DAC communicates with you.
Right to access your information. It is your right to obtain confirmation on whether or not data relating to you are being processed as well as other relevant information about the processing involved.
Right to updating or rectification. You have the right to rectify or correct any inaccuracy or error in your personal data through the SMAC website and app or by submitting your request for rectification or correction.
Right to erasure or blocking. You have the right to the erasure or blocking of your personal data in accordance with the requirements of the DPA, subject to restrictions imposed by other regulations.
Right to damages. You have the right to be indemnified if you incur damages due to inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorized use of your personal data.
Right to data portability. You have the right to obtain a copy of your data in an electronic or structured format if the same is processed by electronic means and in a structured and commonly used format by submitting a proper request.
Right to file a complaint. If you have reason to believe that your personal information has been misused, maliciously disclosed, or improperly disposed of or that your data privacy rights have been violated, you have the right to file a complaint.
If you intend to exercise any of your abovementioned data privacy rights you, may contact our Data Protection Officer (DPO). We may ask some information in order to verify your identity to avoid unwanted disclosure of personal information.
Minors
Our website and mobile application are intended only for persons who are at least eighteen (18) years old. We neither offer products nor services nor knowingly collect personal data of persons below eighteen (18) years old (“Minors”) without any legal basis or consent of the minor’s parent or guardian. Should we learn that we were provided with personal data of minors, we will delete the same from our database.
Inquiry
For inquiries relating to your personal data or about this Privacy Policy or if you would like to exercise any of your rights as data subject or if you would like to raise concerns regarding data privacy, please contact our data protection officer at:
DAC Data Protection Officer
4th Floor One E-com Building Harbor Drive Mall of Asia Complex Pasay City, Philippines 1300 Email: dpo@smadvantage.com
Any data privacy complaint, request or inquiry should be made in writing, clearly state the material facts, specify your contact information and include supporting evidence, if
applicable. DAC reserves the right to require further documentation from you, depending on the nature of your request/inquiry.
Helpdesk Contact Number
+63 288 338 888 / +63 27 944 388 (for Metro Manila)
0917-833-2090 (Globe)
0998-533-8888 (Smart)
We urge you to submit your inquiries, requests or concerns in writing for proper documentation and monitoring. Kindly provide our DPO with the factual background and documentary evidence. Please provide information on how we can contact you regarding your concern/inquiry or complaint.
Changes to Our Privacy Policy
This policy is subject to periodic review. We may update this policy as we may deem fit or as may be necessary to comply with government regulation. We may also revise this policy to comply with the industry’s best practices or if there is a need to revamp the website to adapt to new requirements of technologies or security protocols. All changes on this policy will be posted on our official privacy policy page https://digiweb.smac.ph/privacy-policy and on the SMAC mobile application.
Version 07/18/2024