Privacy Policy for Columbia, MOre

Effective Date: July 1, 2026 | Last Updated: July 1, 2026

Introduction

At Columbia, MOre, accessible from https://comomore.com/, the privacy and security of our visitors is a top priority. This Privacy Policy describes what personal data we collect, why we collect it, how we use and protect it, and what rights and choices you have.

This policy applies to information collected through our website only. It does not cover data collected offline or via third-party services that link to or from our site.

By accessing or using Columbia, MOre, you acknowledge that you have read and agree to this Privacy Policy. Questions or requests may be sent to info@comochamber.com.

Definitions

  • Personal Data: Any information relating to an identified or identifiable person, including name, email, IP address, and online identifiers.
  • Processing: Any operation on personal data, including collection, storage, use, transfer, and deletion.
  • Data Controller: Columbia Chamber Foundation, determining the purposes and means of processing personal data on Columbia, MOre.
  • You / User: Any individual accessing or using Columbia, MOre.

Information We Collect

1. Information You Provide Directly

  • Contact form submissions: name, email address, address and message content
  • Email address and preferences for newsletter or mailing list subscriptions

2. Automatically Collected Data

  • IP address, browser type and version, operating system, and device type
  • Pages visited, time and date of visit, duration, and referring URL
  • HTTP request headers and server log data
  • Cookie identifiers, session tokens, and similar tracking data (see Cookies section)
  • Aggregated usage analytics via Google Analytics 4 or similar services

How We Use Your Information

We process personal data for the following purposes:

Purpose Examples Legal Basis (GDPR)
Service Delivery Operating the website; responding to support requests Contract / Legitimate Interests
Analytics & Improvement Understanding usage patterns; improving features Legitimate Interests
Email Marketing Newsletters, updates, and promotional content Consent
Security & Fraud Prevention Detecting malicious activity; protecting user accounts Legitimate Interests
Legal Compliance Meeting tax, regulatory, and court-ordered obligations Legal Obligation

Cookies and Tracking Technologies

Columbia, MOre uses cookies, web beacons, and similar technologies. Cookies are small text files placed on your browser to help us deliver and improve our services. We use the following categories:

Category Purpose Examples Duration
Strictly Necessary Core functionality, security, session management. Cannot be disabled. Session cookies, CSRF tokens, auth tokens Session
Analytics / Performance Anonymised visitor behaviour data; site performance improvement. Google Analytics 4 (_ga, _gid, _gat) Up to 2 years
Functional / Preference Remembering your settings: language, dark mode, layout. Theme preference, locale cookies Up to 1 year

Managing Cookies: You can control or delete cookies through your browser settings. Opt-out tools: DAA Opt-OutYour Online Choices (EU)Google Analytics Opt-Out. Disabling strictly necessary cookies may impair website functionality.

Cookie Consent: Where required by law (e.g. GDPR, ePrivacy Directive), you will be presented with a cookie consent banner on your first visit. Your preference is stored and honoured on subsequent visits.

Analytics

We use Google Analytics 4 (GA4) to measure traffic and usage patterns. GA4 uses first-party cookies and does not use third-party cookies for cross-site tracking. Our privacy configuration includes:

  • IP anonymisation enabled; your full IP address is never stored by Google
  • Data retention configured to a maximum of 14 months
  • We have signed a Data Processing Amendment with Google in accordance with GDPR
  • GA4 data is not shared with Google for its own advertising purposes

You may opt out of Google Analytics tracking at any time via the Google Analytics Opt-Out Browser Add-on.

Email Communications and Newsletter

With your explicit consent, we may send newsletters, product updates, or promotional emails. Every commercial email includes a working one-click unsubscribe link in compliance with the CAN-SPAM Act and, where applicable, CASL. You may also unsubscribe by emailing info@comochamber.com. Requests are processed within 10 business days. We may retain your address on a suppression list to honour your opt-out preference.

Third-Party Services and Integrations

We work with trusted third-party service providers who may access your personal data only to the extent necessary to perform services on our behalf. All processors are bound by Data Processing Agreements (DPAs). Categories include:

  • Hosting and infrastructure: Cloud providers who host our website and databases
  • Analytics: Tools for measuring usage and performance
  • Email delivery: Providers for transactional and marketing emails
  • Security and monitoring: Fraud detection and uptime monitoring services

How We Share Your Information

We do not sell your personal information. Data is shared only in these limited circumstances:

  • Service Providers: Trusted processors under contract who help operate our website; they may only process data as instructed by us.
  • Legal Requirements: Where required by law, regulation, subpoena, or court order. We notify you where legally permitted before disclosing.
  • Safety: To protect the rights, property, or safety of Columbia, MOre, our users, or the public.
  • Business Transfers: In a merger, acquisition, or asset sale, your data may transfer. You will be notified via a prominent website notice and, where feasible, by email.
  • With Your Consent: For any other purpose with your explicit prior consent.

Data Security

We implement appropriate technical and organisational measures to protect your personal data:

  • HTTPS/TLS 1.2+ encryption for all data in transit
  • Role-based access controls limiting data access to authorised personnel
  • Regular security assessments, penetration testing, and vulnerability scanning
  • Real-time monitoring systems for detecting suspicious activity
  • PCI-DSS compliant payment environment

In the event of a personal data breach likely to result in risk to your rights, we will notify affected individuals and relevant supervisory authorities within the legally mandated timeframe (e.g. 72 hours under GDPR).

Data Retention

We retain personal data only as long as necessary to fulfil stated purposes or as required by law:

Data Type Retention Period Reason
Server access logs 90 days Security monitoring and abuse prevention
Analytics data Up to 14 months Trend analysis (auto-deleted by GA4)
Newsletter subscriptions Until unsubscribed + 30 days Suppression list maintenance
Transaction records 7 years Tax and legal compliance
Contact form submissions 3 years Correspondence records and dispute resolution

Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or transfer your personal data. You may exercise these rights by contacting us at info@comochamber.com. We will respond within the timeframe required by applicable law. You will never be penalised or discriminated against for exercising your privacy rights.

CCPA / CPRA – California Consumer Privacy Rights

The California Consumer Privacy Act (CCPA), as amended by the CPRA (effective January 1, 2023), grants California residents:

  • Right to Know: Disclosure of categories and specific pieces of personal information collected, sources, purposes, and third parties with whom data is shared.
  • Right to Delete: Request deletion of personal information, subject to exceptions (completing transactions, security, legal obligations).
  • Right to Correct: Request correction of inaccurate personal information we hold.
  • Right to Opt Out of Sale or Sharing: Opt out of the sale or sharing of personal information for cross-context behavioural advertising. We do not sell personal information. Should this change, we will add a “Do Not Sell or Share My Personal Information” link to our homepage.
  • Right to Limit Sensitive Personal Information: Restrict use of sensitive personal information to necessary purposes only.
  • Right to Non-Discrimination: We will not deny service, charge different prices, or provide lower quality because you exercised a CCPA right.

Personal information collected in the past 12 months: Identifiers (name, email, IP address); Internet or network activity (browsing history, site interactions); Commercial information (if purchases made); Geolocation data (if location features used); Inferences drawn to build user profiles.

Submit CCPA requests to info@comochamber.com. We verify identity and respond within 45 days (extendable by 45 days). Authorised agents may submit requests on your behalf with proper documentation.

Other US State Privacy Rights: Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Oregon (OCPA), and other states with similar privacy laws may exercise equivalent rights by contacting info@comochamber.com.

COPPA – Children’s Online Privacy Protection

Columbia, MOre is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where a higher threshold applies, such as certain EU member states under GDPR Art. 8).

If we discover we have inadvertently collected data from a child under the applicable age threshold without verified parental consent, we will delete it immediately. Parents or guardians who believe their child has submitted data on Columbia, MOre should contact us at info@comochamber.com. We will investigate and take corrective action within 72 hours of notification.

Links to External Websites

Columbia, MOre may contain links to third-party websites. Once you leave our site, this Privacy Policy no longer applies. We have no control over and accept no responsibility for external sites’ content, privacy policies, or practices. We recommend reviewing the privacy policy of any third-party site you visit.

Do Not Track (DNT) Signals

Some browsers transmit “Do Not Track” signals to websites. There is currently no universally accepted standard for how websites must respond to DNT signals. At this time, Columbia, MOre does not alter its data collection practices in response to DNT browser signals. We will review this position as industry standards evolve.

Changes to This Privacy Policy

We may update this Privacy Policy periodically. When material changes are made, we will update the “Last Updated” date at the top and post a prominent notice on our website, and where feasible notify subscribers via email. Your continued use of Columbia, MOre after any modification constitutes acceptance of the revised policy. We encourage you to review this page periodically.

Contact Us

For questions, data subject requests, or privacy complaints, please contact us:

We aim to respond to all enquiries within 5 business days, and within applicable legal deadlines for formal data subject requests.