Privacy Policy

Thanks for visiting FullStory. This privacy policy explains the what, how, and why of the personally identifying Information we collect when you visit the website located at www.fullstory.com (the “Site”) and when you use the FullStory SaaS analytics software and services (“Services”) and includes Personal Information collected via email, SMS, telephone, WAP or other means. It also explains the specific ways we use and disclose that information. By using or accessing the Site or Services, you are accepting the practices described in this Privacy Policy, and you are consenting to our processing of your information as described below.

The Full Story on FullStory

The FullStory Services utilize a powerful script that creates a new level of ease for website owners to understand the usability of their websites. Website owners who use FullStory Services can watch a DVR-like video playback of user sessions on their website, enabling meaningful insight into their users' experience, as an effective way to identify usability problems and other areas for improvement. FullStory exists to make the web better for end-users, and it is only available to websites that share that goal.

Definitions

Getting a few definitions out of the way should help you better understand this policy.

When we say we, us, our or FullStory, we're referring to FullStory, Inc., a Delaware corporation.
FullStory Customer refers to any customer that has entered into an agreement with FullStory to use the FullStory Services on its Site.
Personal Information refers to any information which may identify an individual personally, such as first and last name, home address, billing address, or other physical address, email address, telephone number, etc.
User refers to a visitor to a website that uses the FullStory Services or a client of a FullStory Customer.
Visitor refers to anyone accessing the FullStory Site.

Information Collected

Information Collected from FullStory Visitors

If you are a Visitor, FullStory collects information on your use of our Site, such as pages visited, links clicked, non-sensitive text entered, and mouse movements, as well as information more commonly collected such as the referring URL, browser, operating system, cookie information, and Internet Service Provider (“Usage Data”). FullStory’s purpose in collecting Usage Information is to better understand how FullStory’s Visitors use the Site. FullStory does not use the Usage Information to identify its Visitors and does not disclose the Usage Information other than under the circumstances described in this Privacy Policy.

As a Visitor, FullStory collects potentially personally identifying information like Internet Protocol (or “IP”) addresses (“Potential PII”). Also, you may choose to interact with the Site that results in your providing Personal Information to FullStory, such as giving us your name, email address, user name and password when signing up for a free trial of the Services or creating an account to post comments to the FullStory blog or social media sites, etc. You should be aware that any information you provide in the FullStory blog or social media areas may be read, collected, and used by others who access them.

We only collect Personal Information that is reasonable or necessary to accomplish the purpose of your interaction with FullStory as a Visitor. You may choose not to provide this information but you need to understand that as a result, you may not be able to engage in certain activities on the Site. Any Personal Information provided by you as a Visitor to the Site will be used only as described in this Privacy Policy and FullStory’s Acceptable Use Policy located at https://www.fullstory.com/legal/acceptable-use/.

Information Collected from FullStory Customers

If you are a Customer of FullStory, when you signed up for the Services, you entered into an agreement with FullStory to accept FullStory’s terms of use of the Services, which includes the obligations in this Privacy Policy and our Acceptable Use Policy (“Agreement”). As part of your use of the Services, we collect the same information as that of a Visitor above and may ask you for additional information such as payment information, usage data in relation to the Services and other information we deem relevant for the purpose of providing the Services.

FullStory may use your information and data as agreed to in the Agreement and to:

  • Process transactions between you and FullStory.
  • Send e-mails about our Site or respond to inquiries.
  • Send e-mails and updates about the FullStory Services, including newsletters.
  • Provide support for the FullStory Services.
  • Enhance or improve user experience, our Site, or FullStory Services.
  • Monitor data to ensure that it complies with your contractual obligations to us.
  • Perform any other function that we believe in good faith is necessary to protect the security or proper functioning of our Site or the FullStory Services.
  • With your prior consent, we may post your personal testimonials along with those of other satisfied customers on our Site in addition to other endorsements.

The information we collect from a Customer is disclosed only in accordance with the Agreement and this Privacy Policy and the Acceptable Use Policy.

Information Collected from Visits to Websites that use FullStory Services

For Users of a FullStory Customer, FullStory is acting as a service provider to the Customer for the FullStory Services. FullStory collects information on a User under the direction of its Customer, and has no direct relationship with the User whose information it processes. It is important to understand that when a User visits other websites that use the FullStory Services, the FullStory Customer’s privacy policy apply to that information collected instead of this Privacy Policy. FullStory may use your information as permitted by the FullStory Customer in accordance with its privacy policies.

Use of Your Personal Information

We will never sell your data to third parties. However, in the course of business, we may hire third party individuals and organizations to help us make the FullStory Services better. These third parties include our web host provider, other SaaS providers, such as an email hosting service, payment processors or outside contractors we hire to perform maintenance or assist us in securing our website. We may also hire third parties to operate, maintain, repair, or otherwise improve or preserve our website or its underlying files or systems.

FullStory will may disclose Personal Information and Potential PII only to those of its employees and third party organizations that (1) need to know such information in order to process it on FullStory’s behalf or to provide services as described above and (2) have agreed not to disclose it to any other parties without FullStory’s consent. Some of those employees, contractors and affiliated organizations may be located outside of your home country; by using the Site and/or the Service, you consent to the transfer of information to such individuals and organizations in order to accomplish these purposes.

Before using or sharing your information with non-agent third parties in ways not discussed here or previously authorized by you, we will provide you Notice and an opportunity to control the further use or disclosure of your personal information.

FullStory has potential liability in cases of onward transfer to third parties of data of EU individuals received pursuant to the EU-US Privacy Shield. (See below).

If you are a registered user of the Service and have supplied your email address, FullStory may occasionally send you an email to tell you about new features, solicit your feedback, or just keep you up to date with what’s going on with FullStory and our products. If you send us a request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish it in order to help us clarify or respond to your request or to help us support other users. FullStory takes all measures reasonably necessary to protect against the unauthorized access, use, alteration, or destruction of Personal Information and Potential PII.

In some cases, we may choose to buy or sell assets. In these types of transactions, user information is typically one of the transferred business assets. If we, or substantially all of our assets, were acquired, or if we go out of business or enter bankruptcy, user information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, and that any acquirer of us or our assets may continue to use your Personal Information and Potential PII as set forth in this policy. You will be notified via email and/or a prominent notice on our Site of any change in ownership or uses of your Personal Information and Potential IP, as well as any choices you may have regarding your Personal Information and Potential IP.

Release of Your Information for Legal Purposes

We may access or release Personal Information about you when required to do so in order to comply with any applicable, laws, regulations, subpoena or enforceable governmental or public authority request, including, to meet national security or law enforcement requirements. We may also access or release Personal Information when we have a good faith believe that such access or release is reasonably necessary to (i) enforce applicable terms of service, including investigation of potential violations, (ii) detect, prevent, or otherwise address fraud, security or technical issues, (iii) respond to user support requests, or (iv) protect our rights, property or safety, our users and the public. This includes exchanging information with other companies and organizations for fraud protection and spam/malware prevention.

Right to Access, Edit, and Remove Your Information

You have a right to access personal information we hold about you. Whenever you use our Site or FullStory Services, we strive to make sure that the Personal Information is correct. If that information is wrong, we give you ways to update it quickly or to delete it – unless we have to keep that information for legitimate business or legal purposes. When updating your Personal Information, we may ask you to verify your identity before making any changes. We may reject requests that are unreasonably repetitive, require disproportionate technical effort (for example, developing a new system or fundamentally changing an existing practice), risk the privacy of others, or would be extremely impractical (for instance, requests concerning information residing on backup systems). Where we can provide information access and correction, we will do so for free, except where it would require a disproportionate effort. Because we protect information from accidental or malicious destruction, even after information is deleted from the FullStory Services, it may not be immediately deleted from FullStory’s servers.

To request removal of your Personal Information from our Site, Services, blog or social media, contact us at privacy@fullstory.com. In some cases, we may not be able to remove your Personal Information, in which case we will let you know if we are unable to do so and why.

If a User interacts with one of our Customers and the User seeks to access, or correct, amend, or delete inaccurate data or no longer wants to be contacted by one of our Customers, the User should direct its inquiry to the Customer because the Customer is the data controller. If the Customer requests FullStory to remove the Personal Information, we will respond to their request within 30 days.

Security Measures

We take measures to enhance the security of our Site and the FullStory Service. These measures include using SSL Certificates and two-factor authentication. It is important for you to protect against unauthorized access to your password and to your computer. No security measures are perfect and we cannot promise that the information about you will remain secure in all circumstances.

International Transfer

We store and process information about you on computers in the United States. Privacy laws local to our servers and computers will apply to information we store about you.

Do Not Track Signal

We treat the data of everyone who comes to our site in accordance with this Privacy Policy, whatever their Do Not Track setting.

Children

Our site is intended for a general audience and we do not knowingly collect personal information from anyone under the age of 13.

How FullStory Collects Information

Cookies are small data files placed on your computer by the websites you visit and the emails you read and can be used to help recognize you when you return to a website, or when you visit other sites. We, or third party service providers, may use cookies to, among other things, measure activity, personalize your experience, remember your viewing preferences, or track your status or progress when accessing our site. For some of these purposes, our cookies may be tied to Personal Information and/or Potential PII. In particular, the FullStory Services use first-party cookies to maintain a coherent scope for a user session across multiple pages on a single website. These cookies do not track the same user across unrelated domains and, as described above, attempts to infer identity across domains is strictly prohibited.

Local Storage is a standard facility provided by HTML5-compliant browsers used to retain data on your computer across visits to the same website. We use local storage as a temporary holding area for user events that were observed locally but, due to the timing of a page unload, were unable to be transmitted as part of the user session. Return visits to the same website read and transmit events previously stored in local storage to complete previously recorded sessions.

This information may in the aggregate identify a User, however we will not identify a User as they browse the web if the User turns off cookies, as explained below.

FullStory does not and will not ever attempt to identify the same person across disparate, unrelated domains. It is a violation of our Acceptable Use Policy for our customers to attempt to build multi-site user profiles for the intent of selling or exchanging lists of users or demographic information.

Opting Out

If you wish to prevent all websites using the FullStory Services to be able to record an its activity, you can opt-out of the FullStory Services. Opting out will create a cookie that tells FullStory to turn off recording on any site which uses the FullStory Services. The presence of this cookie is required to continue opting out, so if you clear your browser cookies, you will have to opt-out again. (We regret that there isn't a better way to make your opt-out more permanent, but due to technical reasons, this really is the best we can do at present.)

One more thing.

If you are considering opting-out, it's probably a good time to make sure you really understand that the purpose of the FullStory Services is to help well-intentioned companies make their website better for you. It is emphatically not one of those we-track-you-around-the-web kind of deals. We think that's creepy, too.

Most people who make websites are just like you: nice people who want to do a good job and make something awesome. And you wouldn't believe how much time and energy product teams spend trying to make their websites great for you. Without the FullStory Services, though, they simply do not have enough information to understand when they get it wrong. If they can see how you actually experience their website, like an ongoing usability study, they'll actually know what to improve! They don't need to record anything sensitive in order to do that, and we have a strict Acceptable Use Policy where you can see for yourself the high standards we expect of FullStory customers with respect to your privacy.

Blocking Cookies

If you choose, you can set your browser to reject cookies or you can manually delete individual or all of the cookies on your computer by following your browser’s help file directions. Note that turning off cookies may also disable functions of many websites you visit. If your browser is set to reject cookies or you manually delete cookies, FullStory will not be able to coalesce your anonymous user identity automatically into sessions across pages on the same website.

FullStory could in principle coalesce your user identity across pages of a single website even if you are blocking cookies if (1) you are logged into the website of a FullStory customer and (2) that customer uses the JavaScript API to identify you using an application-unique identifier.

EU-US Privacy Shield Framework.

FullStory complies with the EU-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries. FullStory has certified that it adheres to the Privacy Shield Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement and Liability. If there is any conflict between the policies in this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles will govern. To learn more about the Privacy Shield program, and to view our certification page, please visit www.privacyshield.gov.

In compliance with the EU-US Privacy Shield Principles, FullStory commits to resolve complaints about your privacy and our collection or use of your Personal Information. European Union individuals with inquiries or complaints regarding this privacy policy should first contact FullStory at privacy@fullstory.com, or via postal mail at:

FullStory
Attn: Privacy
818 Marietta Street
Atlanta, GA 30318

FullStory has further committed to refer unresolved privacy complaints under the EU-US Privacy Shield Principles, to the BBB EU PRIVACY SHIELD, a non-profit alternative dispute resolution provider located in the United States and operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-customers/ for more information and to file a complaint.

Under certain limited conditions, if your complaint is not resolved thorough these channels, it may be possible for individuals to invoke binding arbitration before the Privacy Shield Panel to be created by the U.S. Department of Commerce and the European Commission.

US- Swiss Safe Harbor Framework.

FullStory complies with the US-Swiss Safe Harbor Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from Switzerland. FullStory has certified that it adheres to the Safe Harbor Privacy Principles of notice, choice, and accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse, enforcement and liability. If there is any conflict between the policies in this privacy policy and the Safe Harbor Privacy Principles, the Safe Harbor Privacy Principles shall govern. To learn more about the US-Swiss Safe Harbor and to view our certification page, please visit http://www.export.gov/safeharbor/.

In compliance with the US-Swiss Safe Harbor Principles, FullStory commits to resolve complaints about your privacy and our collection or use of your personal information. Swiss citizens with inquiries or complaints regarding this privacy policy should first contact FullStory at privacy@fullstory.com, or via postal mail at:

FullStory
Attn: Privacy
818 Marietta Street
Atlanta, GA 30318

FullStory has further committed to refer unresolved privacy complaints under the US-Swiss Safe Harbor to an independent dispute resolution mechanism operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/us/safe-harbor-complaints for more information and to file a complaint.

FullStory is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).

Changes

We may amend this Privacy Policy from time to time. When there are changes to this Privacy Policy, we will update this page. The date on the bottom will always indicate when we last made changes. If you are a visitor to this Site and disagree with the Privacy Policy, you should leave the Site and/or cancel your agreement with FullStory.

What If I Have Questions or Concerns?

If you have any questions or concerns regarding privacy when using FullStory, please send us a detailed message to privacy@fullstory.com or via postal mail at:

FullStory
Attn: Privacy
818 Marietta Street
Atlanta, GA 30318

We will make every effort to address your concerns.

Effective Date

This Privacy Policy became effective on: August 1, 2016.