Privacy Policy

Effective September 19, 2019
Prism Intelligence dba iSecretShop (“Prism”) is an information technology service provider to mystery shopping and market research companies (“Providers”). Our platform is used by those Providers to collect data, store and process it, and reporting (“Services”) to their end-clients (“End Clients”). Prism also serves as a platform for independent contractors (“Panelists”) to advertise their services to Providers and to enter data requested by end-client users.

Prism respects the privacy of every individual who visits the Prism websites and uses our apps. This Privacy Policy is our commitment to transparency in communicating how Prism collects, uses, and discloses the information that is collected from you, the visitor of its Website and Apps, as well as the choices you have with respect to the information.

Roles

Depending on your role in this process you may be using our site, services, and/or products as one of the following types of users below:

  • A general visitor (General User)
  • An employee/agent of one of our providers (Provider User)
  • An independent contractor or respondent who submits data into our platform on behalf of one of our providers (Panelist)
  • An end-client of one of our providers (End-client User)
  • An Outside Person* (see below)

*Outside Person: If you are not a Provider User, Panelist, or End-client User, it is also possible that our platform still contains personal information about you loaded by one of those users. In this case you are an Outside Person.

Personal Data

Throughout this document we will use the term Personal Data to mean any information that can be used alone or in combination with other sources to uniquely identify, contact, or locate a single person or to identify an individual.

Our Providers or their End Clients may also collect your consent for some types of collection and processing of your Personal Data.

We will collect only as much Personal Data as needed to conduct specific, identified activities related to our business. As such, the “Do Not Track” browser setting is not relevant to our products and services.

Categories of Personal Data Collected

Personal Data is collected from you and used differently depending on your role as described above under “Roles”. As examples: If you are a General User of our products or services we may collect the following information about you:

  • Contact information (such as name, address, phone, email, fax)
  • Localization data (including geolocation/date/time)
  • Connection data (such as usage information, device or browser information, IP address, and page visits and navigation data)

If you are a Panelist then we may collect the above, and also the following additional categories of information from you using our products or services:

  • Employment and compensation details
  • ID data
  • Work/professional life data
  • Professional skills information
  • Personal life data
  • Personal master data
  • Contract master data (contractual relationships)
  • Performance metrics and history
  • Billing and payment data (PayPal addresses)
  • Media files and information from media files
  • Results from mystery shopping, mystery calling, mystery mailing and other marketing, service evaluation, business audit, opinion poll responses, and data collection and reporting projects

If necessary in connection with performing the services, we may also collect special categories of data such as the following:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Biometrics data for the purpose of uniquely identifying a natural person
  • Data concerning health
  • Data concerning a natural person’s sex life or sexual orientation

If you are a Provider User, or End-client User then our providers or their end-clients may collect the same data as a General User, and also the following additional categories of information from you using our products or services:

  • Employment and compensation details
  • ID data
  • Contract master data (contractual relationships)
  • Performance metrics and history
  • Customer history
  • Media files and information from media files
  • Results from mystery shopping, mystery calling, mystery mailing and other marketing, service evaluation, business audit, opinion poll responses, and data collection and reporting projects

If you are an Outside Person, it is possible that any of the above categories of information has been collected about you and entered into our system.

Who We Collect Information From or About (Data Subjects)

With the above roles in mind (see “Roles”), we collect the above information from or about the following individuals or entities (data subjects):

  • Staff, employees, agents, advisors, business partners, vendors, subcontractors
  • Independent Contractors such as field agents, mystery shoppers, callers, mailers, interviewers
  • Respondents
  • Friends & family
  • Data subjects from end-client (or prospective end-client) sources:
    • Staff, employees, agents, advisors, business partners, vendors, subcontractors
    • Customers, prospects, friends & family
  • Other third-party individuals
How We Use the Information We Collect

We do not sell your Personal Data and only use the information that we collect to provide and improve our products and services. If you provide to us contact information for the purpose of staying informed about our products and services, or for support/troubleshooting operations, we will use the information for those purposes. Your IP address may be used to infer your geographical location. We keep various logs relating to Personal Data for internal purposes.

If you are a Panelist, Provider User, End-client User, or Outside Person, your Personal Data may be used by us, our providers, and/or their end-clients for such things as contacting you, or for data verification, anti-abuse, and anti-fraud purposes. For details about how our providers or their end-clients use the information they collect using our products and services, please refer to their specific Privacy Policies, or contact that company directly. If you need any assistance in this regard, please contact us using the contact information below.

Information We Share: Partners and integrations

Prism shares the information it collects about you in the following ways:

  • Providers - Prism shares your information with participating Providers to facilitate matching Panelists with specific data collection opportunities and to facilitate payment for work performed from the Providers to you.
  • Third Party Providers – Prism may use third-party vendors to provide storage, hosting, infrastructure, support, and processing in the delivery of our products and services. We may also use third-party vendors for data verification and anti-fraud purposes. We enter into confidentiality and data processing agreements with each of our vendors to ensure that they comply with high levels of confidentiality and best practices in privacy and security standards. We regularly review these standards and practices. A list of these companies is available upon request.
  • Aggregated or De-identified Data - We may disclose or use aggregated or de-identified information with third party providers for research purposes relating to our Services.
  • As Required by Law or Similar Investigations - To comply with legal obligations (e.g. subpoena) or investigate potential legal violations. Prism may be required to share personal data in response to lawful requests from public authorities including to meet national security and/or law enforcement requirements.
  • Safety - We may disclose your information to protect and defend the safety of Prism in connection with investigating and preventing fraud or security issues.
  • Consent - Prism may share your information with your consent.
Cookies

Our products use cookies and similar technologies to provide certain features and functionality. These are used only for our legitimate interests of delivering and optimizing services to you. We gather information such as internet protocol (IP) addresses, internet service provider (ISP), operating system, browser type, date/time stamp, and store it in log files for identification purposes. To collect this information, a cookie, a standard feature of a website that allows us to store a small amount of data on your computer to allow our web servers to recognize you, may be set on your computer or device when you visit our Website. We may track your use across different websites and services. In some countries, including those in the European Economic Area ("EEA"), the information in this paragraph may be considered personal information under applicable data protection laws.

Specifically, we use cookies for:

  • Security/Authentication: When you log in and we authenticate your identity we use a cookie to confirm that you are logged in.
  • Functionality: Certain functionality you use in the system may use a cookie to deliver the data or information you request.
  • Preferences: When you set certain configuration settings in our products we may use a cookie to store that setting.

You can control how websites use cookies by changing your cookie settings (www.aboutcookies.org), but your modification may limit your use and functionality of some of the features on our Website.

Security

We take the security of your Personal Data very seriously and take reasonable and appropriate measures to protect it from loss, misuse and unauthorized access, disclosure, alteration, and destruction. We have put in place appropriate physical, electronic, and managerial procedures to ensure the protection of your Personal Data.

External Links

We are not responsible for any content in external links. Content on third-party websites, and the related Privacy Policies covering those, are the responsibility of their respective owners.

Data Retention

We keep your Personal Data only as long as needed for the purposes for which it was originally collected, or as permitted by law.

For the data retention policies of our providers or their end-clients, please contact the appropriate company.

Safety of Minors

Our products and services are not intended to be used by anyone under 18 years of age. We do not allow anyone under 18 to register and do not knowingly collect Personal Data from any minor. If it comes to our attention that we have collected Personal Data from a minor, we may delete this information without notice. If you have reason to believe that this has occurred, please contact customer support.

Changes to Our Privacy Policy

From time to time we may update our privacy policy. Please check back periodically to see any changes. If we make a change to this privacy policy that materially affects your protections under the policy, we will notify you.

EU / EEA / Swiss Residents

For users who reside in the European Union, the European Economic Area (Norway, Liechtenstein, or Iceland), or Switzerland, we have additional privacy-related information for you.

EU / EEA residents are covered under the General Data Protection Regulation (GDPR). Swiss residents are covered under the Swiss Federal Data Protection Act (Swiss DPA). These provide certain protections and rights regarding how Personal Data is collected, processed, and how and when it may be transferred outside of those countries.

GDPR Rights and Your Data Controller
If you are an EU/EEA resident you have certain legal rights, listed below. You exercise these rights by contacting your data controller:
Your Data Controller

  • As a Panelist, Prism is your data controller.
  • In most cases your Personal Data is controlled by one of our providers. This is especially true if you are a Provider User, or an Outside Person. Please contact the provider that collected the information, as they are the data controller.
  • If you are an End-Client User, it is also possible that your employer is the data controller that collected and supplied your Personal Data to one of our providers. In that case, please contact the appropriate person at your employer.
  • If you are a General User visiting our website or using our products, we collect only the limited Personal Data mentioned above, and are the data controller for that limited data. If you have questions about this data, please contact us using the contact information below. We will respond to your request to exercise any of these rights within 30 days of receiving it.

If you need any assistance in determining who your data controller is, or how to contact them, please contact us using the contact information below.

As an EU/EEA resident, your specific rights under the GDPR include:


In addition, you have the right to not be subject to decisions based solely on automated processing, including profiling, which produce legal or other significant effects for you.

If a Personal Data breach occurs and is likely to result in a high risk to your rights and freedoms, we will notify you, the Data Controller and the appropriate supervisory authority in a timely fashion.

Legal Basis for Processing Personal Information
For individuals in the EEA, Prism’s legal basis for collecting and using your personal information will depend on the personal information collected and the specific context in which we collect it. Prism will process personal information from you where, a) we have your consent to do so, b) where processing is necessary for Prism to perform Services pursuant to an agreement, or c) where processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect personal information, or may otherwise need the personal information to protect your vital interests or those of another person. At any time, you have the right to withdraw or decline consent. If you do not provide the requested information, Prism may not be able to perform Services for you. Also, you have the right to object where we rely on our legitimate interests to process your personal information.

The following information describes additional principles that we follow while managing your Personal Data under the Privacy Shield Frameworks:

  • Notice – If we collect any Personal Data from you directly, we will inform you of the purpose for which it is collected and used. We must have your agreement for any disclosure or use of Personal Data for a purpose other than for which it was originally collected. Prior to disclosing Personal Data to non-agent third parties, you will be notified and presented with a choice and means (an “opt out” option) for limiting the disclosure of the Personal Data. An exception is government and law enforcing agencies in cases where we are required by law to provide such information, including without notice.
  • Choice – We will provide the opportunity to choose (i.e.: to opt out) whether your Personal Data may be disclosed to third parties or be used for a purpose other than for which it was originally collected. This is accomplished using the means provided in the notice, or by contacting us directly using the contact information provided below.
  • Accountability for Onward Transfer – We do not routinely disclose Personal Data to non-agent third parties. If the need should arise, prior to disclosing Personal Data to a non-agent third party, we will notify you of such disclosure and allow you the choice to opt out of such disclosure. We will ensure that any third party to which Personal Data may be disclosed subscribes to the same principles for managing Personal Data and agrees in writing to provide an adequate level of privacy protection. We may be liable for the inappropriate transfer of Personal Data to third parties. Also note that we may be required to disclose your Personal Data in response to a lawful request by governmental authorities.
  • Security – We secure Personal Data as described above in this Privacy Policy.
  • Data Integrity and Purpose Limitation – We will only process Personal Data in a way that is compatible with, and relevant to, the purpose for which it was collected or authorized by you. To the extent necessary for those purposes, we will take reasonable steps to ensure that Personal Data is accurate, complete, current, and reliable for its intended use.
  • Access – We acknowledge your right to access your Personal Data and will allow you access to your Personal Data. We will allow you to correct, amend, or delete inaccurate information, except where the burden or expense of providing such access would be disproportionate to the risks to your privacy in the case in question, or where the rights of other persons would be violated. You may access your Personal Data by logging on to the website or product where you registered or by contacting us directly using the contact information below.
  • Recourse, Enforcement and Liability – We use a self-assessment approach to assure compliance with this Privacy Policy and periodically verify that the Policy is accurate, comprehensive for the information intended to be covered, prominently displayed, completely implemented, accessible, and in conformity with its principles. We encourage interested persons to raise any concerns using the contact information provided, and we will investigate and attempt to resolve any complaints or disputes regarding use and disclosure of Personal Data in accordance with our principles outlined above. To ask questions about our privacy policy, or to make a complaint, contact us using the information below.
  • If you have any questions or complaints concerning our processing of Personal Data on behalf of our providers or their end-clients, or to make choices about how those companies use your Personal Data, please contact those companies directly, or contact us using the contact information below.
  • In compliance with the EU-US and Swiss-US Privacy Shield Principles, we commit to promptly resolve complaints about your privacy and our collection or use of your personal information. EU/EEA or Swiss individuals with inquiries or complaints regarding this Privacy Policy should first contact us using the contact information below.
  • We have further committed to refer unresolved privacy complaints under the EU-US and Swiss-US Privacy Shield Principles to an independent dispute resolution mechanism, the JAMS EU-US Privacy Shield, operated by JAMS. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed by us, please visit the JAMS EU-US Privacy Shield website https://www.jamsadr.com/eu-us-privacy-shield for more information and to file a complaint.
  • We are also committed to using "last-resort" binding arbitration at your request to address any complaint that has not been resolved by other recourse and enforcement mechanisms.
Contacting Us

For privacy-related inquiries, please contact us at:

Prism Intelligence LLC ATTN: Privacy Policy Inquiry
PO Box 1212
Kula, HI 96790, USA
Phone: +1(888) 206-2349 x111
Phone: +1 (206) 866-9060 x111
Fax: +1 866 674 7244
E-mail: privacy@prismintelligence.com

FAQ

Do I have to have a smartphone?

Absolutely Not. Using a smartphone gives you tremendous advantages like completing assignments from the field – without having any homework to do later, but it is by no means necessary. On the iSecretShop system you can use a smartphone app, the mobile web, a computer at home – or ANY combination of the three! It’s all about making it easier (and more convenient) for you!

What is iSecretShop’s Payment Policy?

iSecretShop is a software platform and a job board. We do not pay shoppers. Our clients (the ones offering the opportunities) do. Every company has its own Payment Policy. Some jobs pay within days, others on a monthly schedule. All Payment Policies are published for you to review prior to agreeing to do any work.

How do I qualify as a Mystery Shopper? Do I have to apply?

As an adult consumer, your opinions and observations are extremely important. Registering is fast and free – and you’ll be able to start taking assignments right away! There is no application process, and you ‘qualify’ because your opinion matters.