Castbox

Castbox is a Hong Kong-based podcast company. The company both hosts and produces its own podcasts.

This page is not published. While you can access it via its direct link, it is not yet displayed on the website.

Handling

Does the policy allow personally-targeted or behavioral marketing? Yes, but you can opt-out

3.5/10

Decided May 19, 2020 (revision history). This question accounts for 12% of the final score.

Possible Options

Yes0/10
Yes, but you can opt-out3.5/10
Yes, but you must opt-in7/10
No10/10

Citation

We may engage in marketing activities with you to keep you updated about new products and services you may be interested in. We process your personal information, such as your contact information, to send you marketing communications, provide you with information about upcoming events, webinars or other relevant materials, and to deliver targeted marketing to you. We will always let you opt-out of our marketing activities at any time and free of charge.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow third-party access to private personal data? Yes, not all parties specified

0/10

Decided May 19, 2020 (revision history). This question accounts for 12% of the final score.

The policy allows sharing personal data with third-parties (not just critical service providers), and does not explicitly list the third-parties.

This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).

Note that whether the policy allows sharing aggregated user data does not affect this question.

If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).

If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).

Possible Options

Yes, not all parties specified0/10
Yes, all parties specified (including non-critical service providers such as advertisers)3/10
Yes, not all parties specified (but only to critical service providers)7/10
Yes, all parties specified (only to critical service providers)8/10
No10/10

Citation

We also share user information with third parties in some other circumstances as follows:

We disclose your information to our employees, contractors, affiliates, distributors, dealers, vendors and suppliers (collectively, the “Service Providers”) who provide certain services to us or on our behalf, such as operating and supporting the Service, analyzing data, or performing marketing or consulting services. These Service Providers will only have access to the information needed to perform these limited functions on our behalf. All our Service Providers are required by contract to handle your personal information in accordance with this Policy.

As a global company we may share your personal information within the Company’s corporate organization to provide you with the Service or respond to your requests. We have shared business processes, technical systems and management structures between legal entities in our corporate group.

We may share your personal information in the event we decide to sell, buy, merge or otherwise reorganize our business. We will handle and protect your personal information in accordance with this Policy in the event we share your information for such purposes.

As permitted by law or your consent, we may share your personal information with affiliated businesses. We will identify the affiliated business to you at the time of data collection.

Our Service allows you to connect with others, including third parties that may want to market to you. For example, you can leave comments on other users’ content or send messages. When you use our Service and share your information with other users, such users may reach out to you for marketing purposes. We cannot control such communications nor the processing of your personal information that you choose to make available to others.

Our Service allows you to interact with third-party apps and websites, friends and family, other users, and more. For example, you can connect your Facebook account with our Service or share any content you upload on our Service with users on other platforms. We will share your personal information upon your request. Please note, once you decide to share information with others, we no longer control how such information may be used by the third parties in receipt of your personal information. Furthermore, some parts of our Service are publicly available, which means that any information you provide in these parts of our Service may be analyzed, collected, and used by others with access.

We will share your personal information in the event we believe, in good faith, that such a disclosure would protect your interests or rights, or the interests or rights of others, including the Company and its personnel.

To the extent permitted by law, we will disclose your information to government authorities or third parties if: - required to do so by law, or in response to a subpoena or court order or similar request from judicial or public authority; or, - we believe that you have abused the Site or Service by using it to attack other systems or to gain unauthorized access to any other system, to engage in spamming or otherwise to violate applicable laws.

You should be aware that, following disclosure to any third party, your information may be accessible by others to the extent permitted or required by applicable law, unless specific restrictions have been implemented. As permitted by law, we will try to inform you of a law enforcement request, subpoena, or similar request from judicial or public authority disclosure prior to providing our response.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow you to permanently delete your personal data? Yes, by contacting someone

3/5

Decided May 19, 2020 (revision history). This question accounts for 6% of the final score.

Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.

Possible Options

No0/5
Yes, by contacting someone3/5
Yes, using an automated mechanism5/5
N/A (no personal information collected)5/5

Citation

While retention requirements can vary by country, we generally apply the retention periods noted below. Please contact us if you have any questions about our retention periods or if you would like to delete your account.

We store your marketing contact information for as long as you are still subscribed. When you unsubscribe from marketing communications, we will add your contact information to our suppression list to ensure we respect your unsubscribe request. We may store activity data, your user account information, and content for a period after the closure your account for the establishment or defense of legal claims, audit and crime prevention purposes. We may record our calls with you for call quality purposes. As required by applicable law, we will inform you that a call will be recorded before doing so. Any telephone calls with you may be kept for a period of up to six years. We retain any information collected via cookies, clear gifs, flash cookies, webpage counters and other technical or analytics tools up to one year from expiry of the cookie or the date of collection. Please refer to our Cookie Policy for more information.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


When does the policy allow law enforcement access to personal data? When reasonably requested

3/5

Decided May 19, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

Always0/5
Not specified0/5
When reasonably requested3/5
Only when required by a court order or subpoena4/5
N/A (no personal data to share)5/5
Never (special legal jurisdiction)5/5

Citation

To the extent permitted by law, we will disclose your information to government authorities or third parties if: - required to do so by law, or in response to a subpoena or court order or similar request from judicial or public authority; or, - we believe that you have abused the Site or Service by using it to attack other systems or to gain unauthorized access to any other system, to engage in spamming or otherwise to violate applicable laws.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Transparency

Does the policy require users to be notified in case of a data breach? No

0/7

Decided May 19, 2020 (revision history). This question accounts for 8% of the final score.

Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.

Possible Options

No0/7
Yes, eventually5/7
Yes, within 72 hours7/7
N/A (the service collects so little personal data that notification would not be possible)7/7

Note

This policy does not require users to be disclosed in the scenario of a data breach

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Will affected users be notified when the policy is meaningfully changed? Yes

5/5

Decided May 19, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

No0/5
Yes5/5
N/A (no personal data—or contact information—collected)5/5

Citation

We will notify you of changes to this Privacy Policy by posting the amended terms on the Service or via the email address we have on file. By continuing to use the Service after those changes are posted, you agree to be bound by the revised Policy. To find out when we last updated this Policy, please refer to the date listed after “Last Modified” at the top of this Policy. If you do not agree to the changes, you should discontinue your use of the Service immediately. In addition, we may provide you with “just-in-time” disclosures or additional information about the data collection, use and sharing practices of specific parts of our Service. These notices may provide additional information about our privacy practices, or additional choices about how we process your information.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Is the policy's history made available? Only the date it was last modified

3/5

Decided May 19, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

No0/5
Only the date it was last modified3/5
Yes, with revisions or a change-log5/5

Citation

Modified Date: June 29th 2018

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the policy outline the service's general security practices? Somewhat

1/3

Decided May 19, 2020 (revision history). This question accounts for 4% of the final score.

The policy provides only a very vague overview of its security practices.

Possible Options

No0/3
Somewhat1/3
Yes2/3
Yes, including audits2.5/3
N/A (no personal data collected)3/3
Yes, including independent audits3/3

Citation

We implement industry standard security measures intended to protect against the loss, misuse and alteration of the information under our control. Please be aware that no data transmission over the Internet can be guaranteed to be 100% secure. As a result, the Company cannot guarantee or warrant the security of any information you transmit on or through the Service and you do so at your own risk.

You should keep your account login information confidential, and make sure any wireless connections to our Service is secure. If you believe your account information has been compromised or that you have experienced unauthorized access to your account information, please contact us immediately at [email protected]

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Collection

Is it clear why the service collects the personal data that it does? Yes

10/10

Decided May 19, 2020 (revision history). This question accounts for 12% of the final score.

This question deals with transparency. Even if the service uses data for reasons that aren't ideal for privacy, provided they list all of those uses, the service can still receive full credit for this question. However, if they are not explicit about their uses (by employing language like "such as"), a lower score is assigned.

Possible Options

No0/10
Somewhat4/10
Mostly7/10
Yes10/10
No personal data is collected10/10

Citation

We use the information we gather through the Service to help us better understand how the Site or Service and our products, apps, and services are being used. We will only use your personal information as described in this Policy or as disclosed to you prior to such processing taking place.

If you believe that we are processing your information for purposes that are incompatible with the purposes for which we originally collected your information or subsequently obtained your consent, you may choose not to allow us to use your personal information for such processing. However, by limiting how we may process your information, some or all of the Service may not be available to you.

We describe how we use your personal information below:

In order to provide you with our Service, we need to process certain personal information about you. We also share information about you upon your request, and with third parties performing functions on our behalf. When we share your information with such third parties, we only share the information necessary for the third party to perform their functions and as permitted by applicable law. We cannot provide you with our Service without processing your personal information.

We want to make sure you stay informed about service- or account-related news, updates, or changes by sending you communications via email, in-app notifications and any other methods as permitted by law. For example, we may send you communications about changes to our security policies, your transaction information, or other important transaction information. Unlike marketing communications, service-related communications are not promotional in nature. You are not able to unsubscribe from service-related communications because such communications are part of our Service.

When you contact us with questions, feedback, or any other concerns, we use any information that you provide to us to respond to you. We cannot respond to you without processing your personal information.

When you access or use our Service you are bound to our Terms of Service and policies, including this Privacy Policy. We ensure your compliance with our terms, agreements and policies (the “Terms”) by: monitoring, investigating, preventing and mitigating any alleged or actual prohibited, illicit or illegal activities on our Service or violations of our Terms; enforcing our Terms with third parties and/or partners; and, as applicable, collecting fees based on your use of our Service. We cannot perform our Service in accordance with our Terms without processing your personal information.

Keeping your information secure requires us to process your personal information to improve and enforce our security measures. For example, we may process your personal information to combat spam, malware, security risks or malicious activities, or to monitor and verify your identity to prevent unauthorized access to your information. We cannot ensure the security of your information on our Service without processing your personal information for such purposes.

Our business is subject to certain laws and regulations which may require us to process your personal information. For example, we may process your personal information to pay our taxes, fulfill our business obligations, or as necessary for us to manage our risks as required under applicable law. We cannot perform our Service in accordance with our legal and regulatory obligations without processing your personal information for such purposes.

We want you to have the best possible experience on our Service, which is why we personalize our Service to your preferences (e.g., language selection, time zone, etc.), allow you to connect to your favorite third-party applications, and more. We cannot ensure your continued enjoyment of our Service without processing your personal information for such purposes.

We want to continue to provide you with new or expanded services and products that you enjoy. To do so, we analyze how you interact and use our Service and other personal information about you for research and development purposes. We apply technical, administrative, and physical security measures to your personal information when we use it for research and development purposes, such as pseudonymizing or de-identifying your information, where possible, and limiting access to personnel that conducts research and development. We cannot ensure your continued enjoyment of our Services without processing your personal information for such purposes.

We may engage in marketing activities with you to keep you updated about new products and services you may be interested in. We process your personal information, such as your contact information, to send you marketing communications, provide you with information about upcoming events, webinars or other relevant materials, and to deliver targeted marketing to you. We will always let you opt-out of our marketing activities at any time and free of charge.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the policy list the personal data it collects? Yes, generally

7/10

Decided May 19, 2020 (revision history). This question accounts for 12% of the final score.

All general categories of collected personal data are listed, though not all types of personal data are explicitly mentioned (for example, the list might use a phrase like 'such as' when listing types of personal data).

Possible Options

No0/10
Only summarily3/10
Yes, generally7/10
Yes, exhaustively10/10
N/A (no personal information is collected)10/10

Citation

You may use our Service as a guest or you can create an account. When you create an account with us, we will request you to provide certain personal information, which may include: name, e-mail address, and password. We may request additional information necessary to establish and maintain your account.

If you visit or access our Service, we may collect information that you provide to us when you communicate with any of our departments, such as customer service or technical services. You can also choose to provide us with additional information about yourself in your profile, leave comments on other user’s content, and more.

We may automatically collect information about you when you use the Service. For example, we collect information about your listening preferences so that we may suggest other audiobooks or podcasts that we think you might be interested in. We may also track your behavior within our App, including without limitation what you click on in the App, and what podcasts you subscribe to.

When you register an account with us, you may connect your iTunes or Android payment account with our Service or provide us with your digital currency information. If you connect your iTunes or Android payment account with our account, we do not collect your payment information. When you share your digital currency information with us, we collect your cryptocurrency address.

We use “cookies” and similar tracking technologies to collect information about your use of the Service and to provide you with interest-based advertising. For example, we collect information about the way you interact with features on our Site, how long you spend on certain pages, and whether you received an error message on our Service. Please read our Cookie Policy for more information about the cookie data we collect and how you can manage it.

We collect your geolocation data when you use our Service. For example, your device may configured such that it shares your real-time location-based information with us. In addition, the content you create or share with us while using our Service may contain recorded geolocation information. Also, some of the information we collect from your device (e.g., IP address) can sometimes be used to approximate your device’s location.

We collection information about the device you use to access or use our Service. For example, we may collect the following information from your device: the type of device you use (e.g., mobile, auto, a smart home device, etc.); your advertising Identifier (“IDFA” or “AdID”); network connection type (e.g., Bluetooth, WiFi, 3G, 4G, LTE, etc.); operating system and version (e.g., iOS, Android or Windows); language settings in your mobile device; and your mobile service carrier.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service collect personal data from third parties? Yes

0/10

Decided May 19, 2020 (revision history). This question accounts for 12% of the final score.

This includes the use of data brokers and independent verification authorities (such as background check providers).

Possible Options

Yes0/10
Only for critical data7/10
No10/10

Citation

In some cases, the information we collect about you comes from third party sources, as described below.

We may collect information about you or others from third party applications or services available on our Service. For example, when you register for an account with us, you may do so by choosing to connect your already existing social media account with our Service (e.g., Facebook, Google+, etc.). We receive certain information from your social media account depending on your permissions and which information you have made public. We use this information to make an account for you on our Service.

For users that upload content to our Service, we may populate your content submissions with publicly available information from other platforms, which may include personal information about you. The purpose of the information collection is to streamline your upload process and make it easier for you to upload content on our platform. For example, we may collect descriptions, social media accounts, or tags you have used for your podcast channel on other platforms so that you can use the same information on our Service.

We may receive your personal information from other users, such as your friends and family, when they want to share something with you through or about our Service. When you invite others to join our Service, we will contact them on your behalf.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow the user to control whether personal data is used or collected for non-critical purposes? On an opt-out basis, for all non-critical data/uses

3/5

Decided May 19, 2020 (revision history). This question accounts for 6% of the final score.

Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.

Possible Options

No0/5
On an opt-out basis, but only for some non-critical data/uses1.5/5
On an opt-out basis, for all non-critical data/uses3/5
N/A (no data used for non-critical purposes)5/5
On an opt-in basis5/5

Citation

We may engage in marketing activities with you to keep you updated about new products and services you may be interested in. We process your personal information, such as your contact information, to send you marketing communications, provide you with information about upcoming events, webinars or other relevant materials, and to deliver targeted marketing to you. We will always let you opt-out of our marketing activities at any time and free of charge.

If you sign up to receive marketing communications from us, we will always allow you to opt-out of such emails. Marketing communications include any communications to you that are only based on advertising or promoting products and services. Transactional communications about your account or our Services are not considered “marketing” communications.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.



Warnings

Castbox has no warnings published on PrivacySpy. PrivacySpy publishes warnings when it learns a service has announced a data breach or is found misusing user data. If you believe a warning should be published for Castbox, submit one here.


Highlighted Policy Snapshot ALPHA

No highlighted policy snapshot has been created for this privacy policy. To view the policy at its original location, click here.

4.5/10

How we calculate ratings →


Version Added

May 19, 2020

Ratings Updated

May 19, 2020

Warnings

0

Maintained by

doamatto

Original Location
Open in New Tab
Other Versions