Effective as of January 29, 2020

IDT Privacy Policy

We know your privacy is important to you, and we want you to know it’s important to us too.  This Privacy Policy is meant to explain our practices when it comes to your use of our products, services, apps and websites.  We encourage you to take the time to review it carefully, to understand what information we collect, why we collect it, and what we do with it.

Who We Are

IDT Corporation, including its corporate affiliates (collectively “IDT”), is a global provider of various telecommunication, payment and other services and products for our business and residential customers.

If you are a customer located in the European Economic Area (“EEA”), the following corporate affiliate of IDT Corporation processes your personal data as a controller under the General Data Protection Regulation, including for the provision of its products and services, marketing and support:

IDT Retail Europe Limited (registration number 135555314), c/o Sable Accounting Ltd, 13th Floor, One Croydon, 12-16 Addiscombe Road, Croydon, CR0 0XT

This Privacy Policy sets forth our policies and procedures regarding the collection, use and sharing of your personal information.  We also explain the steps we take to protect your information and how you can limit the collection, use and sharing of your information.

Who This Privacy Policy Applies To

IDT Corporation has many corporate affiliates, both in the United States and internationally, and this Privacy Policy applies generally to our customers, prospective customers, users of our products and services, users of and visitors to the IDT family of websites and applications, and members of any IDT loyalty or rewards program.  In addition to this general Privacy Policy, the specific privacy policies listed below in the section Specific Product or Brand Privacy Policies also apply if you use any of the applicable products and services or interact with any of the referenced IDT affiliates

This Privacy Policy and the policies listed below under Specific Product or Brand Privacy Policies apply only to IDT products, services, websites and applications that carry an IDT brand, and not to third party services, websites and apps to which we link.

If you do not agree with this Privacy Policy, do not access or use our products, services, websites or apps, or interact with any other aspect of our business.

Specific Product or Brand Privacy Policies

The following specific privacy policies apply to the customers and prospective customers of the referenced IDT Corporation affiliates (service providers) and to and users of the following products, services, websites and applications:

Boss Revolution Telecommunication Products, Services, Websites and Applications (by country or residence and the country of the phone number you use to register with us)

United States or any North American Numbering Plan Country (except Canada)

Privacy Policy Link:  https://www.bossrevolution.com/en-us/privacy-policy

Websites:  www.bossrevolution.comhttps://bosswireless.com/https://www.brclub.com/

Apps:  BR Calling App

Service Provider:  IDT Domestic Telecom, Inc.

Australia

Privacy Policy Link:  https://www.bossrevolution.com/en-us/privacy-policy-rorow

Websites:  https://www.bossrevolution.com/en-au

Apps:  BR Calling App

Service Provider:  IDT Telecom Asia Pacific Limited

Canada

Privacy Policy Link:  https://www.bossrevolution.ca/en-ca/privacy-policy

Websites:  https://www.bossrevolution.ca/en-ca

Apps:  BR Calling App

Service Provider:  IDT Canada Corp.

Germany

Privacy Policy Link:  https://www.bossrevolution.com/en-us/privacy-policy-rorow

Websites:  https://www.bossrevolution.com/en-de

Apps:  BR Calling App

Service Provider:  IDT Retail Europe Limited

Spain

Privacy Policy Link:  https://www.bossrevolution.com/es-us/privacy-policy-rorow

Websites:  https://www.bossrevolution.com/en-es

Apps:  BR Calling App

Service Provider:  IDT Retail Europe Limited

United Kingdom

Privacy Policy Link:  https://www.bossrevolution.co.uk/en-gb/privacy-policy

Websites:  https://www.bossrevolution.co.uk/en-gb/

Apps:  BR Calling App

Service Provider:  IDT Retail Europe Limited

Rest of World – Excluding EU Countries and Countries Listed Above

Privacy Policy Link:  www.bossrevolution.com/privacy-policy

Websites:  www.bossrevolution.com

Apps:  BR Calling App

Service Provider:  IDT Domestic Telecom, Inc.

Rest of World – EU Countries Not Listed Above

Privacy Policy Link:  https://www.bossrevolution.com/en-us/privacy-policy-rorow

Apps:  BR Calling App

Service Provider:  IDT Retail Europe Limited

Boss Revolution Money Transfer Products, Services, Websites and Applications

United States

Privacy Policy Link:  https://www.bossrevolution.com/en-us/privacy-policy

Websites:  https://www.bossrevolution.com

Apps:  Boss Revolution Money App

Service Provider:  IDT Payment Services, Inc. and IDT Payment Services of New York LLC

Net2Phone Products and Services

United States

Privacy Policy Link:  https://www.net2phone.com/privacy-policy/

Websites:  www.net2phone.com

Apps:  Net2Phone Mobile App

Service Provider:  Net2Phone, Inc.

National Retail Solutions Products and Services

United States

Privacy Policy Link:  https://nrsplus.com/privacy-policy/

Websites:  https://nrsplus.com/

Apps:  BR Club Shopping App

Service Provider:  National Retails Solutions, Inc.

IDT Express Products and Services

United States

Privacy Policy Link:  https://www.idtexpress.com/privacy-statement/

Websites:  https://www.idtexpress.com/

Service Provider:  IDT Domestic Telecom, Inc.

What Information We Collect

IDT receives and collects both personal and non-identifying information from you when we provide you with our services, when you install, access or use our websites, apps and services and when you interact or communicate with us.  Personal information means information either on its own or in conjunction with other data that enables a specific person to be identified, but does not include “de-identified,” “anonymous,” or “aggregate” information, which is not otherwise associated with a specific person.  Non-identifying information means information that by itself cannot be used to identify a specific person.

We collect your information in the following ways:

  • Information you provide directly to us. When you purchase, use or sign up for one of our products or services, when you request us to contact you, or through other interactions with us, we may ask you for certain personal information, such as your name, birthdate, address, e-mail address, telephone number, and payment information.  When you request support from us, we may also collect information from you such as login credentials, security code, contact information, documentation, screenshots, or other information you or we may believe is helpful to solving the issue.  When you speak with our customer service or sales representative on the phone, your calls may be recorded and/or monitored for quality assurance and training purposes.
  •  
  • Information we collect automatically. We and our service providers and vendors, such as our advertising and analytics partners, collect information about your visits to our websites and your interactions with our services, apps, advertisements and content.  Depending on the service and your device, we may automatically collect information such as your IP address, service related diagnostic and performance information (how you use the service), call records or messages sent with our services, browsing history, certain data on your device, device and marketing identifiers, and geolocation data (if you use our location services).
  •  
  • Information we get from third parties. Third party sources of information include:
  •  
  • Third party services and social media. If you create an account or access our services through your account with a third-party service, such as Facebook or Google, or use a social media feature through our services, certain personal data from those third-party social media services may be shared with us, such as your interests, “likes,” and friends list.  We may use this information, for example, to personalize your experiences and marketing communications, to enhance our services, and to better serve you.  You can control this data sharing via options in your social media accounts.  We may also collect information from third party services that are integrated with our services or other applications that you authorize our services to connect with.
  •  
  • Credit agencies. We may obtain your credit information from third party reporting agencies in order to control our own credit risk in onboarding new customers.
  •  
  • Demographic, lead, and interest data. We may obtain information from outside companies such as those that collect customer information including demographic and interest data.  We use this data and combine it with other information we have about you to help us predict your preferences and to direct marketing offers that might be more relevant to you.  We also obtain where permitted by law contact information and other marketing lead information from third parties, website “refer-a-friend” options or social media platforms and may combine it with information we have to contact you or direct IDT marketing offers to you.
  •  
  • Information from other customers. We may obtain information about you from other customers of our services through their use of our services or programs such a refer-a-friend.
  •  
  • Information about our customers’ users. Our customers and other third parties may also provide us with personal information about our customers’ users and others.  For example, we may receive personal information and other information from our customers, message senders, mobile network operators, databases with information relevant to mobile telephone numbers submitted to our services, and other third parties.  This information may include, without limitation, telephone numbers, telephone numbers’ validity, type (g., mobile, landline, etc.), corresponding device status (e.g., whether or not it is currently available for messaging), roaming status, carrier, country of location, and whether or not the number has been ported and is used to help us provide our services.
  •  
  • Information collected in connection with your use of services delivered via our platform. We and our service providers may collect information in connection with your use of our services delivered via our platform.
  •  
  • Communications usage information. This includes information about your communications delivered via our platform such as the time and duration of usage, source and destination identifiers, completion status, location, IP address, and amount of usage.
  •  
  • Communications content. To enable you to send and receive communications via our platform, we need to be able to handle the content of the messages, calls, and other communications channels used by you.
  •  
  • Device information. We collect device-specific information from you, including your hardware model, operating system version, firmware, browser information, device and network configuration, device identifier, and IP address.  We use the device information we collect in order to deliver and improve our services.
  •  
  • Your contact lists and address book. If you use one of our apps, we may request your permission to access and store the contact list or address book maintained on your mobile phone, tablet, or other broadband-connected device.  Your contact list is considered your personal data.  We may use your contact list information to facilitate certain services where selected by you such as to enable you to make calls easily and to facilitate calls, texts, and other services.  We may also facilitate the delivery of messages to individuals in your contact list that you wish to invite to download our mobile apps so that you can utilize our services with these selected individuals, although it is always your choice to send invites to such individuals.  We will not use your contact list information for other purposes without first notifying you of the proposed use.  You do not have to allow us to access your contact list information, but if you do not, certain features of our apps may not be available to you.  You may at any time opt out from allowing this access via the privacy settings on your device.
  •  
  • Your location information. If your mobile device is equipped with GPS or can connect with wireless access points or hot spots, or if your mobile device is also a phone that communicates with cell towers or satellites, then your mobile device is able to use these features to determine its precise geographic location.  Your precise geographic location is considered your personal data.  To the extent our apps collect precise geographic location, you may at any time opt out from further allowing us to have access to your mobile device’s precise location information via the app’s location settings on your mobile device.

Why We collect Your Information and How We Use It

We use all the information we collect and receive to help us operate, provide, improve, understand, customize, support, and market our services.  In addition, we use your information for general, operational and administrative purposes, including maintaining your account, authenticating you and contacting you.  As used in this Privacy Policy, the terms “use,” “using” and “processing” information include using cookies or other similar technologies on a computer/phone/device, subjecting the information to statistical or other analysis and using or handling information in any way, including but not limited to, scanning, collecting, storing, evaluating, aggregating, modifying, deleting, using, combining, disclosing and sharing information among our affiliates both in and outside the United States and to select service providers and vendors.

In addition, how we use the information we collect depends on which of our services you use, how you use them, and specific preferences you may have communicated to us.  We list below the specific purposes for which we collect your information.

  • To deliver our services. We use your information because it is necessary to perform our obligations in delivering our services to our customers.  This includes delivering your communications to the intended end user, processing transactions with you (such as billing), authenticating you when you log into our platform, providing customer support, and operating and maintaining our services.  We also need your information to communicate with you about the services, including registration confirmations, purchase confirmations, expiration or renewal reminders, responding to your requests, and sending you notices, updates, security alerts, administrative messages, and other communications necessary to usage of the services.
  •  
  • To carry out core activities relating to our services. To effectively deliver our services to you, we use your information to engage in important supporting activities such as:  billing and collections, including maintenance of records in the event of a subsequent billing dispute; preventing fraud, violations of our acceptable use policies, and unlawful activities; troubleshooting, quality control, and analytics; and monitoring the performance of our systems and platform.
  •  
  • For research and development. We are constantly looking for ways to improve our services, to make them more reliable, secure, and useful to you and our users generally.  We use data regarding our users’ communications on our platform to understand how our services are performing and how they are being used in order to identify areas where we can do better.  We and our service providers may use your information to assess the level of interest in, and use of, our services, our communications to our customers, and our other messaging campaigns, both on an individual basis and in the aggregate.  We also use information about your use of our websites and apps to understand how our website visitors and app users are using our websites and apps.  Among other things, this usage information, along with tracking technologies, enables analytics companies, such as Google Analytics, to generate analytics reports on the usage of our services.  To opt out of your usage information being included in our Google Analytics reports, you may follow these instructions.
  •  
  • To market, promote, and drive engagement of our products and services. We use data about you to send promotional communications that may be of specific interest to you.  Based on information we collect about you, we may decide whether and how to promote certain of our products or services to you over others.  These communications are to drive your engagement and maximize the value of our services to you.  To perform the above functions and others described in this Privacy Policy, we may match information collected from you through different means or at different times, including personal data and usage information, and use such information along with information obtained from other sources (including third parties) such as contact information, demographic information, and personal interest information.
  •  
  • To comply with legal requirements. Applicable laws or regulations may require our processing of your data, such as laws mandating retention of communications data.
  •  
  • To protect our legitimate business interests and legal rights. Where we believe it is necessary to protect our legal rights, interests and the interests of others, we use information about you in connection with legal claims, compliance, regulatory, and audit functions, and disclosures in connection with the acquisition, merger or sale of a business.
  •  
  • According to your explicit consent. If we wish to use your information for certain purposes which require consent under applicable law, we will first seek out and obtain your consent. This may include, for example, testimonials or case studies that identify you in your individual capacity.
  •  
  • Apps. We engage certain service providers and vendors who use mobile software development kits to passively collect information from users of our applications.  We use this data primarily to help us deliver personalized notifications and to identify you in a unique manner across other devices or browsers for the purposes of customizing advertisements or content. 
  •  
  • Other. IDT does not associate sensitive data, such as your race, religion, or political affiliations, with personally identifiable information. IDT takes precautions to segregate any sensitive data you may provide on IDT sites and services that reference your race, religion, sexual orientation, ethnicity or political affiliations.
  •  
  • EEA users and our lawful bases for using their data. European data protection law requires organizations like us to provide a lawful basis to collect and use your information.  Our lawful basis to collect and use information from our EEA users include when:
    • We need it in order to provide you with the services and to carry out the core activities related to our provision of the services;
    •  
    • We need to comply with a contract or legal obligation;
    •  
    • We have a legitimate interest (which is not overridden by your data protection interests), such as for research and development, to market and promote the services and to protect our legal rights and interests; and/or
    •  
    • You give us your consent to do so for a specific purpose.

Who We Share Your Information With and Why

We share all the information we collect and receive with our affiliates, both in and outside the United States, and to select service providers and vendors, to help us operate, provide, improve, understand, customize, support, and market our services, and for general, operational and administrative purposes, including maintaining your account, authenticating you and contacting you.  When we share information with our service providers and vendors, we require them to use your information in accordance with our instructions and terms or with express permission from you and not to sell your information.  In addition, you share your information as you use and communicate through our services.

More specifically, we may share your information as detailed below:

  • Within the IDT family of companies. We share information within the IDT family of companies, including our affiliates both in and outside the United States primarily to operate, provide, support and market our services.  For example, if you purchase a service, then we share your purchase information with various IDT affiliates in order to process your transaction.  We may share your information in connection with a sale, merger, liquidation, or reorganization of our business or assets. 
  •  
  • Service Providers and Vendors. We work with various service providers and vendors for a variety of business purposes such as to help us deliver, support and market our services.  We share information with these service providers and vendors to the extent reasonably necessary for them to perform work on our behalf.  For example, we may provide your credit card information and billing address to our payment processing company solely for the purpose of processing payment for a transaction you have requested.  More specifically we share information with the following service providers and vendors:
    • Communications providers. As the provider of a communications platform, we share the data we collect from you with communications providers (including traditional PSTN telecommunications companies and over-the-top communications service providers) as necessary in order to provide you with the services.  These are the telecommunications companies, for instance, who we need to ensure your calls, messages and other communications reach the people you want to contact.
    •  
    • Business operations vendors. We work with service providers and vendors to provide website and application development, hosting, maintenance, backup, storage, virtual infrastructure, payment processing, analysis and other services for us, which may require them to access or use information about you.  We only work with carefully selected vendors, and we require any vendors with whom we share personal data to protect the confidentiality of such information and use it solely for the purposes for which it was shared.
    •  
    • Social Networks; Marketing Partners. Depending on the service your use, IDT may share certain information, including unique marketing identifiers, email addresses and mobile phone numbers, with social networks and marketing partners, including Google and Facebook, for marketing, advertising and analysis purposes, including the delivery of advertising campaigns and preparing and sharing aggregate business and marketing reports, demographic profiling and to deliver targeted advertising about products and services. You may see third-party advertisements on our websites.  Some advertisements are chosen by companies that place advertisements on behalf of other advertisers.  These companies, often called ad servers, may place and access cookies on your device to collect information about your visit.  The information they collect from our sites is in a form that does not identify you personally.  This information may be combined with similar data obtained from other websites to help advertisers better reach their targeted audiences.  Targeting may be accomplished by tailoring advertising to interests that they infer from your browsing of our sites and your interaction with other websites where these ad servers also are present.
    •  
    • Other Partners. In the event that you purchase services offered by IDT or a partner through a special marketing arrangement (for example, through a co-branded advertisement or offer, or an arrangement where we and a partner market or offer the other’s products or services), we may share your information with these partners in connection with their services, such as to assist with billing and collections, to provide localized support, and to provide customizations.  We may also share information with these partners where you have agreed to that sharing.
    •  
    • Other websites. Our services, websites and apps may include links that direct you to other websites or services whose privacy practices may differ from ours.  If you submit information to any of those other sites, your information is governed by their privacy policies, not this one.  We encourage you to carefully read the privacy policy of any website you visit.
    •  
  • Compliance with applicable law and enforcement of our rights. We may disclose personal data as required by applicable law, regulation, legal process or government request; to protect IDT, our services, our customers or the public from harm or illegal activities, and to enforce our agreements, policies and service terms.  We may share personal data with our outside auditors, lawyers and regulators.
  •  
  • With your explicit consent. We share information about you with third parties when you give us consent to do so.  For example, we often display use cases or testimonials of satisfied customers on our public websites and require your consent to identify you in your individual capacity.
  •  
  • Sharing with senders and recipients of your communications. You share your information as you use and communicate through our services.  The name on your account, your phone number, profile name, photo, and/or online status may be displayed to people that you make calls to and to other users of the services so that they may contact you.  Depending on the service you’re using, you may be able to control what’s displayed by adjusting your settings within the mobile app or your customer account, or by contacting customer care at the address provided when you signed up for the services.
  •  
  • Credit control. We conduct credit checks on new customers in order to control the risk of non-payment.  In the event of non- or late payment, we may disclose your name, address and other details to credit bureaus and agencies.  They may use that information to assess your credit rating and provide that rating to other companies.
  •  
  • Other. IDT does not sell, rent or lease its customer lists to third parties.

How we Protect Your Information

IDT has technical, organizational and physical safeguards in place to help protect against unauthorized access to, use or disclosure of the information we collect and store.  Employees are trained on the importance of protecting privacy and on the proper access to, use and disclosure of customer information.  IDT secures information on computer servers in a controlled, secure environment, protected from unauthorized access, use or disclosure.  We use Secure Socket Layer (SSL) encrypted protection to protect the personal information transmitted to our websites.  Our websites and apps are PCI compliant in connection with your credit card information.  Although we work hard to protect your information that we collect and store, no program is 100% secure and we cannot guarantee that our safeguards will prevent every unauthorized attempt to access, use or disclose that information.  Therefore, you acknowledge the risk that third parties may gain unauthorized access to your information.  Keep your account password secret and please let us know immediately if you think your password was compromised.  Remember, you are responsible for any activity under your account using your account password or other credentials.  IDT maintains security and incident response plans to handle incidents involving unauthorized access to information we collect or store.  If you become aware of a security issue, please contact us.

Where we Store Your Information

Personal information held by IDT is stored on and processed on computers situated in the United States and in the EEA.  We and/or our service providers also process data in some other countries for customer care, account management and service provisioning.

If you are an EEA resident, your personal data held by IDT may be transferred to, and stored at, destinations outside the EEA that may not be subject to equivalent data protection laws, including the United States.  When you sign up for service with IDT or inquire about our services, we transfer your information to the United States and other countries as necessary to perform our agreement with you or to respond to an inquiry you make.  It may also be processed by staff situated outside the EEA who work for us or for one of our suppliers.

Accordingly, by using our services, you authorize the transfer of your information to the United States, where we are based, and to other locations where we and/or our service providers operate, and to its (and their) storage and use as specified in this Privacy Policy and any applicable terms of service or other agreement between you and IDT.  In some cases, IDT may seek specific consent for the use or transfer of your information overseas at the time of collection.  If you do not consent, we may be unable to provide you with the services you requested.  The United States and other countries where we operate may not have protections for personal information equivalent to those in your home country.

Where your information is transferred outside the EEA, we will take all steps reasonably necessary to ensure that your data is subject to appropriate safeguards, such as relying on a recognized legal adequacy mechanism, and that it is treated securely and in accordance with this Privacy Policy.

To facilitate our global operations, we transfer information among our corporate affiliates in countries whose privacy and data protection laws may not be as robust as the laws of the countries where our customers and users are based.  For data transfers from the EEA to the United States and other countries we make use of legally recognized data transfer mechanisms, which may include standard contractual clauses approved by the European Commission, reliance on the European Commission’s adequacy decisions about certain countries, privacy shield frameworks, binding corporate rules for transfers to data processors, or other appropriate legal mechanisms to safeguard the transfer.

Some of the service providers and vendors described in this Privacy Policy, which provide services to us under contract, are based in other countries that may not have equivalent privacy and data protection laws to the country in which you reside.  When we share information of users in the EEA with such service providers and vendors, we shall make use of legally-recognized data transfer mechanisms, which may include privacy shield frameworks, the European Commission’s standard contractual clauses, binding corporate rules for transfers to data processors, or other appropriate legal mechanisms to safeguard the transfer.

How Long We Store Your Information

We store your information until it is no longer necessary to provide the services or otherwise relevant for the purposes for which it was collected.  This time period may vary depending on the type of information and the services used, as detailed below, and applicable law, which may require us to maintain information for a set amount of time.  After such time, we will either delete or anonymize your information or, if this is not possible (for example, because the information has been stored in backup archives), then we will securely store your information and isolate it from any further use until deletion is possible.  We may also retain aggregate information beyond this time for research purposes and to help us develop and improve our services.  You cannot be identified from anonymized information retained or used for these purposes.

  • Customer account information. We store your account information for as long as your account is active and a reasonable period thereafter in case you decide to re-activate the services. We also retain some of your information as necessary to comply with our legal obligations, to resolve disputes, to enforce our agreements, to support business operations, and to continue to develop and improve our services.
  •  
  • Communications usage information. While you’re an active customer, we retain the communications usage information generated by your use of the services until the information is no longer necessary to provide our services, and for a reasonable time thereafter as necessary to comply with our legal obligations, to resolve disputes, to enforce our agreements, to support business operations, and to continue to develop and improve our services.
  •  
  • Marketing information, cookies and web beacons. If you have elected to receive marketing from us, we retain information about your marketing preferences for a reasonable period of time from the date you last expressed interest in our services, such as when you last opened an e-mail from us or visited our websites.  We retain information derived from cookies and other tracking technologies for a reasonable period of time from the date such information was created.
  •  
  • Device information. We collect device-specific information from you.  If you do not revoke our access to this information via the privacy settings on your device, we will retain this information for as long as your account is active.

How To Access and Control Your Information

Your choices.  You have choices about how we use and share your information and there may be additional protections that apply with regard to certain information we collect depending on where you reside.

Access to your account information.  Consistent with applicable laws and data security requirements, we will reasonably honor written requests from you to access or amend your account information, such as name, address, and billing information.  You are responsible for ensuring that the information on file with IDT is current and accurate.  You may access and update your account information by logging into your account or contacting us as described in this Privacy Policy.  Where permitted by law, we may charge a reasonable fee to process requests for access to data and may limit the number of requests per year.  Your right to amend your information is subject to our records retention policies.  To request deletion of your IDT account, please contact us as described in this Privacy Policy.  You should know that deletion of your IDT account will result in you permanently losing access to your account and all customer data to which you previously had access through your account.  Please note that certain data associated with that account may nonetheless remain on IDT’s servers in an aggregated or anonymized form that does not specifically identify you.  Similarly, data associated with your account that we are required by law to maintain will also not be deleted.

Opt out of communications.  You may opt out of receiving promotional communications from us by using some or all of the following methods: the unsubscribe link within each e-mail, replying STOP to a text message, updating your e-mail preferences within your service account settings menu, or by contacting us as provided below to have your contact information removed from our promotional list or registration database.  Even after you opt out from receiving promotional messages from us, you will continue to receive transactional and informational messages from us regarding our services. Depending on your type of account with IDT, you may be able to opt out of some notification messages in your account settings.

Customer Proprietary Network Information (CPNI).  For residents of the United States, CPNI is information made available to us solely by virtue of our relationship with you that relates to the type, quantity, destination, technical configuration, location, and amount of use of the telecommunications and interconnected VoIP services you purchase from us, as well as related billing information.  You have a right, and we have a duty, under U.S. federal law to protect the confidentiality of your CPNI.  We use and share your CPNI within the IDT family of Companies and with/to their agents, contractors and partners for marketing purposes, including to offer you services that are different from the services you currently purchase from us.  If you don’t want your CPNI used for the marketing purposes described above, please contact us as described in this Privacy Policy.  Unless you notify us, we may use your CPNI as described above and your choice will remain valid until you notify us that you wish to change your selection.  Your decision about use of your CPNI will not affect the provision of any services you currently have with us.  Note:  this CPNI notice may not apply to residents of certain states, including Arizona.

Telemarketing.  U.S. federal “Do Not Call” laws allow U.S. residents you to place your phone numbers on the National Do Not Call Registry to prevent telemarketing calls to those numbers.  To add your numbers to this list, please call 1-888-382-1222, or visit https://www.donotcall.gov/.  Most telemarketing laws allow companies to contact their own customers without consulting the Federal or State Do Not Call lists.  If you would like to be removed from IDT’s telemarketing list, please contact us as described in this Privacy Policy.  Please allow 30 days for your telephone number to be removed from any sales programs that are currently underway.  Please note that we may still call you regarding your services and account even if you remove your number from our telemarketing list.

Email, Text Messages and Push Notifications.  Marketing emails you receive from us will include an unsubscribe feature usually found at the bottom of the email that you may use to opt out of receiving future marketing emails.  Marketing text and SMS messages from us also contain an opt-out feature that you can use to prevent future marketing text and SMS messages from us.  You may refuse to consent to receive calls and texts from IDT and its affiliates that require your consent, including autodialed, pre-recorded or artificial voice telemarketing calls.  You may also withdraw your previously given consent to receive such calls and texts.  You can opt out of receiving push notifications from us via our apps by going to your device “Settings” and clicking on “Notifications,” and then changing those settings for the applicable app.  Please note that you cannot withdraw your consent to receive certain in-app messages from IDT.  Your ability to manage some of our services could be limited if you withdraw your consent to receive text and SMS messages.  IDT does not recommend using those services without authorization to receive such messages.

Online Information.  You have choices about whether certain information collected on our websites and apps is used to customize advertising based on predictions generated from your visits over time and across different websites and apps.  Similarly, many mobile devices offer controls you can set to limit the advertising use of information collected across mobile apps on your device.  Please note that many opt outs use browser cookies or device controls and are specific to the device and browser you are using. 

California, USA Consumers.  If you are a resident of the State of California, please review Appendix A to this Privacy Policy which sets forth additional provisions that apply to you.

Your rights as an EEA resident. If you are from the EEA, you may have broader or additional rights, including:

  • the right to obtain from us a copy of any personal data that IDT processes about you and to know the purposes of the processing;
  • the right to request the rectification of any inaccurate personal data held by us;
  • the right to request the erasure of your personal data held by us;
  • the right to request that we restrict processing of your personal data;
  • the right to request that your provided personal data be moved to a third party;
  • the right to object to any processing of your personal data which is based on our legitimate interests, including the right to object to marketing and profiling; and
  • the right not to be subject to a decision based solely on automated processing.

Where the processing of your personal data by us is based on consent, you have the right to withdraw that consent without detriment at any time by contacting us.  If you do not want your personal data used by IDT for any direct marketing purposes, or shared with third parties for their own marketing use, then you may opt out of such use or sharing by contacting us, even if you have previously consented to such use.

If you have any concerns or complaints regarding the treatment of your personal information by us, or you believe we have breached any privacy law in relation to your personal information, please contact us.  We will treat any concerns or complaints confidentially.  We will promptly investigate any concern or complaint that you raise with us.

You can exercise the rights listed above at any time by contacting us and if you feel that your request or concern has not been satisfactorily resolved, or if our response was not provided within a reasonable time, you may approach your local data protection authority (links here for residents of the EEA or Australia).  The Information Commissioner is the supervisory authority in the United Kingdom and can provide further information about your rights and our obligations in relation to your personal data, as well as deal with any complaints that you have about our processing of your personal data.

Other Important Information

Information from children.  IDT does not sell products or services for purchase by children and we do not knowingly solicit or collect personal data from children under the age of sixteen without obtaining verifiable parental consent.  If you believe that a minor has disclosed personal data to IDT, please contact us.  If you allow a child to use your device or our services, you should be aware that their information could be collected as described in this Privacy Policy.  We encourage parents to be involved in the online activities of their children to ensure that no information is collected from a child without parental permission.

Cookies and Tracking.  See Appendix B to this Privacy Policy.

Use of Third Party Advertising.  The majority of the advertisements you see on IDT websites are displayed by IDT.  In addition, IDT also allows third-party advertisers to display advertisements while you are viewing content on IDT websites.  These advertisements are selected based on what we believe will be of most interest to you.

Electronic Communications.  Unless otherwise required by applicable law, you authorize IDT to send or provide the following categories of information (“Communications”) by electronic means and not in paper format:  (a) any customer agreement you have with IDT and any amendments, modifications or supplements to it; (b) your purchase and use records regarding service transactions; (c) any initial, periodic or other disclosures or notices provided in connection with the services, including without limitation those required by U.S. federal, state, international or other applicable law; (d) any customer service communications, including without limitation, communications with respect to claims of error or unauthorized use of the services; and (e) any other communication related to the services, a transaction or IDT.  Electronic means may include email, SMS/MMS, App to App, text, push notification through our apps, website chat with customer service, or posting in our applicable apps or on our applicable website.  Message and data rates may apply when you receive SMS/MMS, text or push notification messages on your mobile phone.  You may withdraw your consent to receive all Communications electronically (except for app to app messages from IDT) at any time.  In order to withdraw your consent, you must contact us.  In order to access and retain Communications, you must have:  (i) an Internet browser that supports 128-bit encryption, (ii) a mobile number and the capability to receive messages from or on behalf of IDT, and (iii) a device and data or Internet connection capable of supporting the foregoing.

Consent to Receive Messages.  Subject to your ability to opt-out, by using any of our services, you consent to receive text messages, phone calls, faxes, postal mail, push notifications through our apps, and app to app messages from IDT and its affiliates regarding account management activities and special offers.  This consent is specific to the phone number(s) you provide to us to use the services and open accounts.  Where local law permits, you consent to receive phone calls from IDT even if your phone number is listed on “do not call” registries.  Where local law permits, an auto-dialer and/or artificial or prerecorded message may be used to make calls or send text messages to you.  Message and data rates may apply when you receive SMS/MMS, text or push notification messages on your mobile phone.  You may refuse to consent to receive calls and texts from IDT and its affiliates that require your consent, including autodialed, pre-recorded or artificial voice telemarketing calls.  You may also withdraw your previously given consent to receive such calls and texts.  Your ability to manage and use certain features of the services could be limited if you refuse or withdraw your consent to receive these messages.  You are not required to agree to promotional communications in order to purchase goods or services from us.

Changes to this policy.  In the event we make changes to this Privacy Policy, we’ll let you know by posting an updated policy on our website at www.idt.net.

How to contact us

If you are a resident of the EEA, the data controller responsible for your information is:

IDT Retail Europe Limited

c/o Sable Accounting Ltd

13th Floor, One Croydon

12-16 Addiscombe Road, Croydon, CR0 0XT

Email:  legal-uk@idt.net

IDT’s Representative:  Amy Reynolds

IDT’s Representative’s Email:  data_info@idt.net

If you live anywhere else, please direct questions about this Privacy Policy to:

IDT Corporation

520 Broad Street

Newark, NJ 07102 USA

E-mail:   ccpa@idt.net 

Appendix A

Additional Information for California Consumers

If you are a resident of California, then the following sections also apply to you.

  1. Personal Information. Personal information includes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.  IDT collects, discloses and/or shares the following categories of personal information regarding California residents:
Categories of Personal Information CollectedSpecific Personal Information Collected within CategoryCategories of Sources of Personal InformationIs this info Shared and/or Sold and Categories of to WhomBusiness or Commercial Purposes for Collection and Sharing of Personal Information
Personal Identifiers and Information, including items listed in subdivision (e) of Section 1798.80 of California Civil Codename, address, email address, phone number, birthdate, device and marketing identifiers, IP address, payment and financial information, credit/debit card number and details, bank account number and information, personal information necessary to verify you or your account, security code and login credentials, and other personal information you provideconsumer, consumer’s device, automatic collection by IDT, credit reporting companies, financial companies, 3rd party vendors that provide IDT with transactional services, data resellersShared – yesCategories of third parties with whom IDT shares personal information:  IDT family of companies, including our affiliates both in and outside the United States; our service providers and vendors to the extent reasonably necessary for them to perform work on our and your behalf (e.g., credit card processors); ad networks; data analytics providers; social networks; law enforcement; prospective purchasers of our business; outside auditors and lawyers; and government entities, agencies and regulatorsSold – no To manage our products and services, including to help us operate, provide, evaluate, improve, monitor, customize, bill and support our products and servicesTo maintain and service your account, including to process orders and paymentsTo communicate with you about our terms and policiesTo verify you, your account activity and your informationTo detect, investigate and report fraud, abuse or illegal use of our products and services or customer accountsTo provide customer serviceTo perform due diligence, credit and fraud prevention checksTo maintain accurate record keepingTo perform product, marketing and organizational analysisTo provide advertising and marketing to our customersTo measure our marketing campaigns and to audit consumer interactionsTo comply with regulations and legal requirementsTo comply with contractual requirementsFor risk management and complianceFor legal advice and defense of claimsFor general, operational and administrative purposes
Commercial informationrecords of products or services purchased and used, diagnostic and service performance information, call records and other traffic data, credit information from reporting agencies, transactional information, and other purchasing or consuming histories or tendenciesconsumer, consumer’s device, automatic collection by IDT, credit reporting companies, financial companies, 3rd party vendors that provide IDT with transactional services, data resellersShared – yesCategories of third parties with whom IDT shares personal information:  see list under Personal Identifiers and InformationSold – no
Internet or other electronic network activity informationbrowsing history, search history, messages, personal, phone or social network contact information, device information, device contacts, and information regarding a consumer’s interaction and usage with our websites, apps and advertisementsconsumer, consumer’s device, automatic collection by IDT, credit reporting companies, financial companies, 3rd party vendors that provide IDT with transactional services, data resellersShared – yesCategories of third parties with whom IDT shares personal information:  see list under Personal Identifiers and InformationSold – no
Geolocation data (if use location features)location of deviceconsumer, consumer’s device, automatic collection by IDTShared – yesCategories of third parties with whom IDT shares personal information:  see list under Personal Identifiers and InformationSold – no
Inferences drawn from any of the information aboveprofile reflecting the consumer’s marketing preferences; aggregate information from third partiesconsumer, consumer’s device, automatic collection by IDT, credit reporting companies, financial companies, 3rd party vendors that provide IDT with transactional services, data resellersShared – yesCategories of third parties with whom IDT shares personal information:  IDT family of companies, including our affiliates both in and outside the United States; our vendors and partners to the extent reasonably necessary for them to perform work on our and your behalf (e.g., credit card processors); ad networks; data analytics providers; social networks; and prospective purchasers of our businessSold – no
  1. Your Rights. As a California resident you have certain additional rights regarding your personal information under the California Consumer Privacy Act of 2018 (“CCPA”). 

(i)         Right to Know Personal Information Collected – you have the right to request the following from IDT:  categories of personal information collected; categories of sources of personal information; business or commercial purpose for collecting or selling your personal information; categories of third parties with whom we share your personal information; and the specific pieces of personal information that we have collected about you.

(ii)        Right to Know Personal Information Sold or Disclosed – you have the right to request the following from IDT:  categories of personal information collected; categories of personal information sold by IDT; categories of third parties to whom IDT has sold your personal information; and categories of personal information IDT has disclosed for a business purpose.

(iii)       Right of No Discrimination – IDT does not discriminate against any California consumer who exercises any of the consumer’s rights under the CCPA.  Pursuant to the CCPA, IDT is permitted to charge a consumer a different price or rate and/or provide a different level of service to the consumer if that difference is reasonably related to the value provided to the consumer by the consumer’s data.

(iv)       Right of Deletion/Erasure – you have the right to request that IDT delete any personal information that it has collected about you.  There are exceptions to this right and IDT does not have to delete your personal information including if necessary to complete a transaction, to provide you with services, to detect fraud, to comply with our legal obligations, and to use internally in a lawful manner compatible with the context in which the personal information was given.  In addition, if your personal information is deleted you may not be able to purchase or use our products and services.

(v)        Right to Not Sell Personal Information – IDT does not sell your personal information to third parties. Nonetheless, you have the right to request that IDT not sell your personal information should IDT decide in the future to sell personal information to third parties. To exercise this right please go to https://www.idt.net/ccpa-do-not-sell and complete the form.  IDT does not intentionally collect the personal information of a consumer under the age of 16.  IDT does not intentionally sell the personal information of a consumer under the age of 16 unless the consumer (if age 13-16) or the consumer’s parent (for consumers under 13) affirmatively authorizes the sale. 

  1. How to Exercise Your Rights. To exercise your rights to know personal information collected, sold or disclosed, or to exercise your right to delete your personal information, please go to https://www.idt.net/ccpa-request and complete the form.  To exercise your right to opt out of the sale of your personal information please go to https://www.idt.net/ccpa-do-not-sell and complete the form.  In addition, you can exercise your rights by calling the following toll-free number:  888-412-0477. 
  2. Verification of Consumer Requests. In order to comply with a consumer request, IDT must reasonably verify the requestor.  A record of each request is made as soon as it is received by our data protection team.  IDT will use all reasonable measures to verify the identity of the individual making the request.  We will utilize the requested data to ensure that we can verify the requestor’s identity and where we are unable to do so, we may contact you for further information, or ask you to provide evidence of your identity prior to responding to your request.  This is to protect your data and rights.  If a third party, relative or representative is requesting the data on your behalf, we will verify their authority to act for you and may contact you and them to confirm you and their identity and gain your authorization prior to responding to the request.
  3. Responding to Consumer Requests. IDT will attempt to confirm receipt of each request by contacting the requestor either at the email or telephone number submitted, through the consumer’s account or by other electronic means.  IDT will attempt to verify each request and if it is able to verify a request will provide a response (if necessary and applicable) within 45 days of the receipt of the request, which time period may be extended by IDT for an additional 45 days.  If a delay is necessary, IDT will contact the requestor within the original 45 day period and provide the reasons for the delay.  If a request is particularly complex, IDT may take an additional 90 days to respond.  IDT may charge a fee or refuse to act on any request that is manifestly unfounded or excessive.  All IDT responses shall be in writing and cover the previous 12 month period.  Where possible the response shall be sent through the consumer’s account.  Otherwise, the response shall be sent by mail or electronically.  IDT is not obligated to provide a response to a consumer more than two times in any 12 month period.  The CCPA contains certain exemptions and exceptions from the right of deletion and/or the provision of personal information.  If one or more of those exemptions or exceptions applies to your request, then we may not be able to act upon your request.  Where possible we will inform you of the reasons for not acting upon your request.
  4. For More Info. For more information on your rights and our obligations under the CCPA please send an email to ccpa@idt.net.  For California residents with a disability please send an email to ccpa@idt.net for information on how to access this Privacy Policy in another format.

Appendix B

Cookies and Tracking Notice

A cookie is a small text file that a website saves on your computer or mobile device in order to facilitate and enhance your interaction with that service.  We or our service providers may use cookies and equivalent technologies such as clear gifs, web beacons, pixel tags, Javascript, device fingerprinting, and third-party cookies on our websites and, where relevant, in our promotional e-mails.

They also help us track users, conduct research, allow you to back click to earlier registration pages viewed by you and improve our content and services.  For instance, we may use web beacons on our websites to access and set cookies and otherwise help us to better understand how users are moving through our websites.  Information provided by the web beacon includes the computer’s IP address, the type of browser being used and the time that the web beacon was viewed.  We may also use web beacons in e-mails so that we know when such communications have been opened and to otherwise help us tailor our communications to individual users.  Cookies cannot be used to run programs or deliver viruses to your computer. Cookies are uniquely assigned to you, and can only be read by a web server in the domain that issued the cookie to you.

You can control and/or delete cookies as you wish.  You can delete all cookies that are already on your computer and you can set most browsers to prevent them from being placed.  If you do this, however, you may have to manually adjust some preferences every time you visit a site and some services and functionalities may not work.  You will not be able to opt-out of any cookies or other technologies that are “strictly necessary” for the services.  Where you have not set your permissions, we may also separately prompt you regarding our use of cookies on the site.  We do not honor any web browser “do not track” signals or other mechanisms that provide you the ability to exercise choice regarding the collection of information about your online activities over time and across other websites or online services. 

Learn more about when and how we use cookies and tracking technologies:

  • When it’s strictly necessary

These cookies and other technologies enable us to recognize you when you return to our service and to maintain your web session so you can more easily navigate the subscription process.  They are also essential for you to access secure areas of our sites, for example, to use shopping baskets or make payments.

  • For performance and analytics

These cookies and similar technologies collect statistical information about how you use our websites so that we can improve your user experience.  We use cookies to identify the number of unique visitors we receive to different parts of the website and identify where leads originate.  This helps us for our legitimate interests of improving the way our website works, for example, by ensuring that users are finding what they are looking for easily.

Google Analytics is one of the analytics providers that we use to help us improve our website.  Google Analytics uses cookies to help the website analyze how visitors use the site.  The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by a Google server in the United States.  Google uses this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing website operators with other services relating to website activity and internet usage.  You can prevent the storage of data relating to your use of the website and created via the cookie (including your IP address) by Google as well as the processing of this data by Google by downloading and installing the browser plug-in available here.

  • To enable functionality

These cookies and similar technologies can tell us which language you prefer and what your communications preferences are.  They can help you fill out forms on our sites more easily.  They also enable customization of the layout and/or content of the pages on our sites.

  • For targeted advertising

These cookies and other technologies record your visits to our website, the pages you have visited and the links you have followed.  We will use this information subject to your choices and preferences to make our website more relevant to your interests.  We may also share this information with our service providers and vendors for this purpose.  These companies may use information about your online activities over time and across our services and other online properties, the region of the country or world where your IP address indicates you are located, as well as other information about you, in order to provide advertisements about goods and services of interest to you.  The information practices of these ads networks are governed by their own privacy policies and are not covered by this Privacy Policy.  You have to opt out using each of your web browsing applications, computers and mobile devices separately.

  • Social media cookies and widgets

We use social media platforms to advertise to you online and to monitor the success of our advertising (for instance by receiving reports when you click on our ads on social media sites).  We may use Google Customer Match and Facebook Custom Audience or other similar services to enable us to display personalized ads to people on our e-mail lists when they visit Google or Facebook.  We provide personal information such as your e-mail address and phone number in encrypted form to these social networks (so they cannot be seen by anyone at the social network) to enable the social network to determine if you are a registered account holder with them.