MyStories is an online service that allows members and subscribers to write their stories in response to prompts, and receive a book containing their stories (the "Service"). The Service is owned and operated by MyHeritage Ltd. ("MyHeritage", "we", "our" or "us"). 'You' means an adult, over the age of 18, user of the Service.
This Privacy Policy (“Policy”) explains how we collect, use, and share your personal information when you interact with the Service or this website (MyStories.com) (the "Website"). It addresses legal obligations and rights that apply to "personal information" or "personal data," which is information that identifies, relates to, describes, can reasonably be associated with, or could reasonably be linked directly or indirectly, with a particular individual.
Capitalized terms used but not defined in this Policy have the meaning ascribed to them in the Terms and Conditions. Please read them and this Policy carefully because by accessing the Website, you agree to the Terms and Conditions and our collection and use of personal information as described in this Policy. If you do not agree with this Policy, do not use the Website and the Service and delete your account.
1. Information We Collect and Receive and How We Use It
We collect the following categories of personal information when you create an account on the Service, interact with the Website, access or use the Service, when you seek customer support, or make a purchase.
This information may be collected directly from you (for example, when you create an account) or indirectly through your device or browser when you visit the Website. If you purchase a membership for your relative or anyone else, we will ask you for the individual's name and email address. You must first make certain that you have obtained their consent to pass on their details before providing them.
When you write your book, you decide which individuals to include in the book, deceased or living, and which information to include about them. Before writing information about living individuals or uploading their photos, you are required to obtain their consent. Before writing information about individuals below the age of 18, or uploading their photos, you must obtain the consent of their parent or guardian.
The chart below describes what categories of personal information we may collect, the categories of sources from which we collect the personal information, the purposes for collecting such information, and the categories of third parties with which we share personal information for business purposes. Additional details about certain personal data we may collect, and about other ways we may use it, can be found below the chart in this Policy.
Information Type
Source
Purpose
Categories of Entities to Which We Disclose Personal Information for a Business Purpose
Personal Identifiers: name, email address, shipping address, phone number.
Provided directly by you, or the person who invited you to use the Service.
To provide the Service including:
● creating and maintaining your account;
● providing customer support;
● printing and shipping the books you created;
● processing payments;
● improving the Service and the Website;
● internal data analysis;
● informing you of updates or additions to the Service;
● advertising and marketing our products to you;
preventing fraud, illegal activities, or other activities that violate the Terms and Conditions; and protecting our rights and the rights and safety of our users or others.
Service providers that provide:
● security services;
● cloud-based data storage, the Website hosting, backup and other IT-related functions;
● email services;
● book printing and fulfillment of orders;
● shipping services;
● payment and chargeback processors;
● marketing and advertising services;
● legal and accounting services.
Your Content including names of relatives and their relationship to you, birth dates, marriage dates, photos and similar information you choose to provide.
Protected class information, should you voluntarily share it with us when you write a book, including: gender, marital status, ancestry, religion, national origin information
Provided directly by you, or the people you invite to use the Service.
● Creating your book;
● Providing customer support.
● Hosting services;
● Book printers;
● Order fulfillment vendors.
Payment information: credit card information, billing addresses and other information required to facilitate payments.
Your full credit card number will be stored by our payment processors and only the last four digits will be stored by us.
Provided directly by you.
● Processing payments;
● Preventing fraud and illegal activities
● Payment and chargeback processors;
● Fraud prevention and site security vendors.
Commercial and financial information: records of products or services obtained, purchased or considered, and payment information.
Provided directly by you or collected through the use of the Website.
● Creating your book;
● Providing customer support;
● Processing payments;
● Operating, analyzing, and improving the Service;
● Advertising and marketing.
● Book printers;
● Order fulfillment vendors;
● Payment and chargeback processors.
Internet or other electronic network activity information: information relating to how you interact with the Website and advertisements, the type of computer and browser you use, the address of the website from which you arrived to the Website via link, IP address, page views.
Collected indirectly from your browser or device.
● Maintaining, operating, analyzing, and improving the Website and Service and your experience;
● Advertising and marketing our products to you;
● Preventing fraud and illegal activities;
Preventing activities that violate the Terms and Conditions; and protecting our rights and the rights and safety of our users or others.
● Marketing and advertising services;
● Website performance and analytics vendors;
● Fraud prevention and site security vendors.
Additionally, we may share your Personal Information with a third party in the following situations:
1) In an acquisition of MyHeritage: in the event that MyHeritage, or substantially all of its assets or stock are acquired, personal information will as a matter of course be one of the transferred assets. In such an event, your information would remain subject to the promises made in the pre-existing Policy prior to the event. Note that this situation is not unique to MyHeritage and applies to most companies.
2) In legal or privacy circumstances: as required or permitted by law to comply with a subpoena or similar legal process or government request, or when we believe in good faith that disclosure is legally required or necessary to protect our or other’s rights, property or safety, including to law enforcement agencies, and judicial and regulatory authorities, or to prevent fraud and cybercrime. We will not provide information to law enforcement unless required by a valid court order or subpoena
3) With the individual who purchased a membership and assigned you as the storyteller: such individual will be able to see and edit only the content of your book.
We also use non-personal information, i.e., personal information that has been aggregated in a manner such that the end-product does not personally identify you or any other user of the Website, for example, by using personal information to calculate the percentage of our users from a particular country. Because non-personal information does not personally identify you, we may use such non-personal information for any purpose. In addition, we reserve the right to share such non-personal information.
2. Legal Grounds for the Processing of Personal Information
We are required to specify the purposes for which we process your personal information and the legal grounds upon which we rely when doing so. Please review the table elaborating our processing activities and the legal grounds for each activity.
3. Use of Cookies and Tracking Technologies
We make use of browser cookies and similar automated means of data collection technologies to enhance your experience of using the Website. You can change your cookie settings with regards to analytics and advertising cookies at any time by clicking the 'Cookie settings'.
We also allow third parties to use tracking technologies on the Website for analytics and for advertising (in some states subject to your consent). They allow us to count visits and traffic sources to measure and improve the Website's performance, and to understand what interests our users. They are also used to better understand your interests, including which sites and ads you click on, and assist in delivering personalized ads that may be of interest to you. They also limit the number of times that you see an ad and help us measure the effectiveness of our advertising campaigns. Some of these third parties use the tracking technologies to collect information about how you interact with advertisements across the Internet in order to provide advertising that is tailored to your interests.
You may set your browser to notify you when you receive a cookie. Many web browsers also allow you to block cookies. You can disable cookies from your computer system by following the instructions on your browser or at www.youradchoices.com. For more information about cookies, see www.allaboutcookies.org.
4. Children’s Personal Information
The Service is not directed to children under the age of 18, and we do not knowingly collect personally identifiable information from children under this age.
If we learn that a child under the age of 18 has provided personal information to the Website, we will use reasonable efforts to remove such information. If you provide information about a child, you, as parent or legal guardian, consent to the processing and use of such information by us in accordance with this Policy.
5. Data Retention
You have control of the content you provide to us. If you delete your content from your account, it will be removed from the Service immediately and will be permanently deleted in the ordinary course of business.
We will retain your personal information only for as long as necessary to fulfill the purpose(s) for which it was collected and to comply with applicable laws. This means that we store your personal information for as long as it is required to deliver the Service, except where we have a lawful basis for saving it for an extended period of time (for instance, after your subscription or membership expires, we may still have a legitimate interest in using your contact details for marketing the Service to you). This may include keeping certain information after your subscription or membership has ended and/or after you have received your book in case you would like to download photos and stories and/or purchase additional books. If you don’t want us to keep it, you can delete your account.
We also retain the personal information we need for the execution of pending tasks and to realize our legal rights and our claims, as well as retain certain personal information that we must store for a legally mandatory period of time. In that latter case, the processing of such information by us is limited.
6. How We Keep Your Personal Information Secure
We implement and maintain reasonable security appropriate to the nature of the personal information that we collect. We are committed to providing a reasonable information security program, but no such program can be perfect; in other words, all risks cannot reasonably be eliminated. Data security incidents and breaches can occur due to factors that cannot reasonably be prevented. Accordingly, while our reasonable security program is designed to manage data security risks and thus help prevent data security incidents and breaches, it cannot be assumed that the occurrence of any given incident or breach results from our failure to implement and maintain reasonable security.
7. Where is Your Data Processed and Stored?
When you provide us with any personal information, that personal information may be transferred to and stored by us in the United States and locations around the world which may provide a different level of protection for personal information than in your country of residence.
We take appropriate steps to ensure that transfers of personal information are done in accordance with applicable law and are carefully managed to protect your privacy rights and interests. Accordingly, transfers are limited to countries which are recognized as providing an adequate level of legal protection or where we can be satisfied that alternative safeguards are in place to protect your privacy rights. In particular, we rely on the EU Commission standard contractual clauses. You have a right to contact us for more information about our safeguards.
8. Managing Your Privacy
You can control how you share personal information by changing your privacy settings in the following areas:
● Email Preferences: this allows you to control which marketing emails and other emails we may send you. All non-transactional emails that we send you have a footer link that leads directly to the email settings in which you can conveniently turn off any particular email type you do not wish to receive any longer or re-enable some emails that you have turned off in the past.
● Contact and Account Information such as email or shipping address can be managed through your account settings.
● Cookie Preferences: You can change your cookie settings with regards to analytics and advertising cookies at any time by clicking the 'Cookie settings' link in the footer.
9. No Selling and Sharing of Personal Information
We do not sell or share with third parties for cross-context behavioral advertising, or process for targeted advertising (as those terms are defined in the CCPA and other state data privacy laws) your personal information.
10. No Use or Disclosure of Sensitive Personal Information
We do not use or disclose sensitive personal information to create inferences or profiles about individuals or for any purpose other than providing the Service.
11. No Profiling to Facilitate Decisions with Legal or Other Significant Effects
We do not engage in the automated processing of personal information to create profiles about individuals that are used in furtherance of decisions with legal or other similarly significant effects, such as the provision or denial of financial or lending services, housing, insurance, or access to essential goods or services.
12. Your Rights
Many countries and states provide their residents with certain rights in relation to their personal information. These rights vary, but they may include the following rights, which may be subject to certain exemptions:
● The right to access information held about you. This right can normally be exercised free of charge.
● The right to object to processing which has our legitimate interests as its lawful basis.
● The right to obtain a portable copy of personal information you previously provided to us.
● The right to request rectification or restriction of the information we process about you.
● The right to withdraw your consent when we rely on this legal basis to process your personal information.
● The right to request deletion of your personal information.
Any request should be in writing and addressed to us by email at support@mystories.com. We shall endeavor to respond as soon as possible. We will make every effort to resolve all requests that we receive. However, if you are dissatisfied with our response to a request, you may have the right to lodge a complaint.
Without limitation, in jurisdictions where the GDPR applies (i.e., the European Economic Area and the United Kingdom), you have the right to lodge a complaint with the data protection supervisory authorities.
13. State Data Privacy Rights and Other State-Specific Disclosures
Laws in certain US states give residents of those states specific rights with respect to the personal information collected about them. See below for more information about those rights and other state-specific disclosures.
13.1. CALIFORNIA
If you are a California resident, the California Consumer Privacy Act (“CCPA”) and other California laws grant the rights described below with respect to personal information we collect about you.
Your Right to Request Disclosure of Information We Collect and Share About You
California residents have the right to request certain information about our practices with respect to their personal information. In particular, you have the right to request that we disclose any or all of the following information to you about our processing of your personal information:
● Specific pieces of your personal information that we've collected
● The categories of personal information we have collected
● The sources from which we collected personal information
● The business or commercial purposes for which we collected personal information
● The categories of third parties with which we disclosed personal information
● The categories of personal information that we've disclosed to third parties for business purposes
Your Right to Request the Deletion Of Personal Information We Have Collected From You: Upon your request, we will delete your personal information we have collected from you, subject to exceptions under the law.
Your Right to Request to Correct Personal Information We Hold About You: You have the right to request that we correct personal information we hold that you believe is not accurate. We will take steps to determine the accuracy of the personal information that is the subject of your request to correct, and in doing so will consider the totality of the circumstances relating to the personal information you have identified as being incorrect. We may ask that you provide documentation regarding your request to correct in order to assist us in evaluating the request.
Shine the Light
California residents with whom we have an established business relationship are entitled to ask us for a notice describing certain categories of personal customer information we shared in the immediately preceding calendar year with third parties for those third parties’ direct marketing purposes. We do not share your personal information with third parties or corporate affiliates for their direct marketing purposes.
How We Respond to Do Not Track Signals
We currently do not respond to Do Not Track (“DNT”) signals from your browser because a uniform technological standard has not yet been developed for DNT.
Exercising Your Rights
To exercise any of the rights described in this Policy, email support@mystories.com. All requesters will be required to authenticate themselves before we respond to their request.
Authorized Agents
You may designate an agent to submit requests on your behalf. If you do so, we will require your written authorization to release your personal information to your agent. The agent will need to provide us with your signed permission indicating the agent has been authorized to submit the request on your behalf. We will also require that you verify your identity directly with us or confirm with us that you provided the agent with permission to submit the request.
Verification Process
If you have an account with us, you may be asked to log in to your account. If you do not have an account with us, you may be asked to provide us with personal information to be matched with information we already have. The number and scope of such personal information will depend on the sensitivity of the personal information involved and the risk of harm due to any unlawful disclosure or deletion of such personal information. If we do not have a reasonable method by which we can verify your identity to the degree of certainty required, then your request may be denied.
Response Timeline and Additional Information
For requests for access, correction, or deletion, we will first acknowledge receipt of your request within 10 business days of receipt of your request. We provide a substantive response to your request as soon as we can, generally within 45 days from when we receive your request, although we may be allowed to take longer to process your request under certain circumstances. If we expect your request is going to take us longer than normal to fulfill, we will let you know.
When we act on requests we usually provide information free of charge. In some cases, the law may allow us to refuse certain requests. When this is the case, we will endeavor to provide you with an explanation.
If you wish to receive further information or have any questions or concerns, email us at support@mystories.com.
Right to Non-Discrimination
If you exercise any of the rights explained in this Policy, we will continue to treat you fairly. Consumers who exercise their rights under this Policy will not be denied or charged different prices or provided a different quality of service than other Consumers.
13.2. COLORADO, CONNECTICUT, DELAWARE, IOWA, MONTANA, NEVADA, NEW JERSEY, NEW HAMPSHIRE, NEBRASKA, OREGON, TEXAS, UTAH, VIRGINIA
If you are a resident of the above states, you are entitled to all or some of the following with respect to personal information we collect about you:
● Right to Know: You have the right to confirm whether or not we are processing your personal information and to access such data.
● Right to Access: You have the right to a portable copy of the personal information we have collected from you.
● Right to Delete: You have the right to request deletion of the personal information that we have collected about you and to have such information deleted, subject to certain exceptions.
● Right to Correct: You have the right to ask that we correct inaccuracies in your personal information, taking into account the nature of personal data and purposes of processing such information.
Exercising Your Rights and How We Will Respond
To exercise your rights email support@mystories.com. We will respond to such requests within 45 days from when we receive your request, although we may be allowed to take longer to process your request under certain circumstances. If we expect your request is going to take us longer than normal to fulfill, we will let you know.
When we act on requests we usually provide information free of charge. In some cases, the law may allow us to refuse certain requests. When this is the case, we will endeavor to provide you with an explanation.
Our Commitment to Honoring Your Rights
If you exercise any of the rights explained in this Policy, we will continue to treat you fairly. If you exercise your rights under this Policy, you will not be denied or charged different prices or provided a different quality of service than others.
Verification of Identity
If you have an account with us, you may be asked to log in to your account. If you do not have an account with us, you may be asked to provide us with personal data to be matched with data we already have. The number and scope of such personal data will depend on the sensitivity of personal data involved and the risk of harm due to any unlawful disclosure or deletion of such personal data. If we cannot reasonably verify your identity to the degree of certainty required, then your request may be denied.
When We Do Not Act on a Request – Appeal Process
In some cases, we may not act on your requests (e.g., if we cannot do so under other laws that apply). When this is the case, we will explain our reasons for not providing you with the information or taking the action (e.g., correcting data) you requested.
Additionally, you have the right to appeal our decision by contacting us at support@mystories.com within 30 days after your receipt of our decision. Please provide us with an email address to identify your original request. We will respond to your appeal within 45 days of our receipt of the request.
14. Changes to This Policy
We may update this Policy from time to time, and when we do so, we will update the Last Updated date. If the changes are material, we will notify you by email or on the Website.
Use of the Website or the Service following any changes in the Policy constitutes your acceptance of the revised Policy then in effect.
15. CONTACTING US ABOUT PRIVACY
If you have any questions about this Policy, the practices of this Website, or your dealings with it, you can contact our Data Protection Officer (DPO) via email at dpo@myheritage.com, our dedicated privacy email address at support@mystories.com, or our legal EU representative, Evgeny Inberg, via email at: eurepresentative@myheritage.com.
Privacy Policy
Last updated: January 25, 2025
Legal Grounds for The Processing of Personal Information
The table below details the legal grounds upon which we rely for the processing of personal information.
Note that we may process your personal information relying upon more than one legal ground if such information is used for several purposes. Whenever we rely upon consent, you can withdraw your consent at any time.
When sharing personal information with third parties and affiliates of MyHeritage for the below purposes, we rely upon the legal grounds mentioned in the table below.
Purpose
Legal Grounds for processing
1. To provide the Service to you.
-
Creating and maintaining your account;
-
Printing and shipping the books you created;
-
Processing your payments;
-
Providing you with customer support;
-
Informing you of updates or additions to the Service;
-
Preventing fraud, illegal activities, or other activities that violate the Terms and Conditions; and protecting our rights and the rights and safety of our users or others.
-
Performance of a contract with you.
-
Our legitimate interests (for example, to improve the Service and grow our customer base and the attractiveness of our platform).
2. To market our Service: Conduct promotional campaigns and marketing activities.
-
Our legitimate interests (for example, to better sell our products).
-
Where required by applicable laws -Consent.
3. For internal business purposes:
-
Improving the Service and the Website;
-
Developing new products and services;
-
Internal data analysis;
-
Preventing fraud, illegal activities, or other activities that violate the Terms and Conditions; and protecting our rights and the rights and safety of our users or others.
-
Our legitimate interests (for example, to improve the Service and the Website).
-
Legal obligations to which we are subject.
4. For legal necessities:
-
Legal obligations to which we are subject.
-
Our legitimate interests (for example, to defend our legal interest).