St. Jude U.S. Privacy Policy Statement

This Privacy Policy explains how St. Jude Children's Research Hospital Inc. (“St. Jude”) collects, uses, and discloses information from or about you when you use our websites, and mobile applications (the “Site” or “Sites”) that link to this Policy. St. Jude respects the privacy of our visitors and donors.

For individuals in the European Economic Area (“EEA”), St. Jude Children's Research Hospital Inc., located at 262 Danny Thomas Place, Memphis, TN 38105, is considered the “data controller” of your personal data.

For information regarding our privacy policies for Canadian residents, please view our Canadian privacy policy.

Information You May Provide Us

We collect a variety of information that you provide directly to us.  For example, we collect information from you through:

  • The Site you visit or processing your donations or orders;
  • Requests or questions you submit to us via online forms, email, or otherwise
  • Your participation in surveys
  • Any reviews that you submit about the Services
  • Account registration and administration of your account
  • Uploads or posts to the Services
  • Requests for customer support and technical assistance
  • Any other information you provide us.

Information about you. While parts of the Site may not require you to provide any information that can directly identify you by name (such as if you choose to browse the website without logging in), the specific types of information we collect will depend upon the parts of the Site you use, how you use them, and the information you choose to provide. The types of data we collect directly from you includes:

  • Contact Information.  We may collect and store contact information including your name, address, phone number, email address, and situation specific information when you:
    • contact us directly via email.
    • provide contact information on a mail, electronic form or paper sign-up sheet.
    • opt out of future messaging after receiving a "Forward to a Friend" or "Share With Your Network" email message.

        We do not sell, share or rent our email lists to third-party organizations.

  • Survey Information. We occasionally conduct voluntary surveys on this Site. If you choose to participate in one of our surveys, we collect information related to you and your responses. We do not share personal information collected in these surveys with third parties (other than our service providers). We may share aggregate information with third parties to conduct analytics. The aggregate data cannot be used to identify individuals.
  • Donation or Purchase Information. When you donate online or offline, register or purchase items from stjude.org, we collect your contact information and credit card number, so that we can process your donation or order, notify you of order status or provide a receipt. If you dedicate your donation or send a gift to another person, we will also collect that person’s information, such as name, address, telephone number, and email address. We may also collect your contact information if you request a paper copy of the St. Jude Gift Shop Catalog. 

Please note that in some cases, we need certain types of information so that we can provide you with the services you request. If you do not provide us with such information, or ask us to delete it, you may not be able to obtain these services.

Information We Collect Through Automated Means

When you use the Sites, we and our service providers (which are third party companies that work on our behalf), may use a variety of technologies, including cookies and similar tools, to automatically collect information.  When you use our websites we may collect your IP address, browser types, browser language, operating system, the state or country from which you accessed the Sites, software and hardware attributes (including device IDs) referring and exit pages and URLs, platform type, the number of clicks, files you download, domain names, landing pages, pages viewed and the order of those pages, the amount of time spent on particular pages, the date and time you used the Sites, and upload or post content, error logs, and other similar information. When you use a one of our mobile applications, we automatically receive certain information about the mobile phone, tablet, or computer used to access the application or software, including device identifiers, IP address, operating system, version, Internet service provider, browser type, domain name and other similar information, whether and when you update the app, date and time of use, and how you use the app, including time spent in different portions of the application.

This information is used to improve the performance and content of our web pages and to personalize content and layout of our pages for individual visitors and donors.

How We Share and Use Information We Collect

We do not rent, share or sell your personal information to outside marketers.

We may share personal information with:

  • Our service providers, including shipping companies, and credit card processors, which may only use or disclose the information solely to perform services on our behalf or comply with the law.
  • our affiliates, or
  • if required to do so by law or in a good faith belief that disclosure is reasonably necessary to: (a) comply with legal process (e.g. a subpoena or court order); (b) enforce our Terms or this Privacy Policy, or other contracts with you, including investigation of potential violations thereof; (c) respond to claims that any content violates the rights of third parties; (d) respond to your requests for customer service; and/or (e) protect the rights, property or personal safety of St. Jude, its agents and affiliates, its users and/or the public; or
  • as part of a merger, acquisition, or sale of some or all of our assets (including for due diligence regarding a transaction) or in the unlikely event of an insolvency, bankruptcy, or receivership.

We, or our service providers, use your information for various purposes depending on the types of information we have collected from and about you, in order to:

  • for the purposes for which you provide it;
  • to communicate with you, including to respond to your request for information and provide you with more effective and efficient customer service;
  • to improve the site;
  • for internal recordkeeping purposes;
  • to secure the Sites and applications, and resolve app crashes and other issues being reported; or
  • to protect the rights of St. Jude or others.  

We may also use your information to share information about services or products you have requested or to inform you of promotional offers that might be of interest.

Legal Bases for Use of Your Information

The laws in some jurisdictions require companies to tell you about the legal ground they rely on to use or disclose your personal information.  To the extent those laws apply, our legal grounds are as follows:

  • To honor our contractual commitments to you: Much of our processing of personal information is to meet our contractual obligations to our users, or to take steps at users’ requests in anticipation of entering into a contract with them. For example, we handle personal information on this basis to process your donations or gift orders.
  • Consent: Where required by law, and in some other cases, we handle personal information on the basis of your implied or express consent. 
  • Legitimate interests: In many cases, we handle personal information on the ground that it furthers our legitimate interests in our activities in ways that are not overridden by the interests or fundamental rights and freedoms of the affected individuals. This includes: operating St. Jude and the Sites; providing security for the Sites, products, software, or applications; marketing; making and receiving payments; and preventing fraud.
  • Legal compliance: We need to use and disclose personal information in certain ways to comply with our legal obligations (such as our obligation to share data with tax authorities). 

Cookies and Other Technology

To collect the information in the “Information We Automatically Collect” section above, we and our service providers use Internet server logs, cookies, tracking pixels, and other similar tracking technologies. We use these technologies in order to offer you a more tailored experience in the future, by understanding and remembering your particular browsing preferences. 

Cookies are small text files that do not damage a visitor's system or files. We use cookies to (i) store visitors' preferences and recognize visitors’ computers, (ii) alert visitors to new areas of the site, (iii) customize Web page content based on visitor interests, (iv) record past activity in order to provide better service, and (vi) assist with security and administrative functions.

Most browsers will allow a user to accept or deny cookies. Please note that you can change your settings to notify you when a cookie is being set or updated, or to block cookies altogether. Please consult the “Help” section of your browser for more information (e.g., Internet ExplorerGoogle ChromeMozilla Firefox; or Apple Safari).  If a visitor rejects our cookies, they may still use our Site, but you may not have access to certain features or offerings of the Site.

St. Jude, or those acting on our behalf, uses web beacons to access St. Jude cookies inside and outside our network of websites. Web pages may contain an electronic file called a web beacon that allows a web site to count users who have visited specific content or sites or to access certain cookies.

We may use analytics services on this site, such as Google Analytics. These service providers use the technology described above to analyze how users use the site. The information collected by the technology (including your IP address) will be collected directly by these service providers[TLA1] .  To prevent Google Analytics from using information for analytics, a user may install the Google Analytics Opt-Out Browser Add-on by clicking here.

Do Not Track Signals and Similar Mechanisms

We do not respond to browser-initiated Do Not Track signals, as the Internet industry is currently still working on Do Not Track standards, implementations, and solutions

California Residents: Your California Privacy Rights

St. Jude does not disclose your personal information to third parties for the purpose of directly marketing their services to you unless you first agree to such disclosure. If you have any questions regarding this policy, or would like to change your preferences, you may contact us at the address listed above.

Your Choices and Rights

Residents of the European Union can exercise certain data subject rights available to them under applicable data protection laws. Where such rights apply, we will comply with requests to exercise these rights in accordance with applicable law. Please note, however, that certain information may be exempt from such requests in some circumstances, which may include if we need to keep processing your information for our legitimate interests or to comply with a legal obligation. If these rights apply to you, they may permit you to request that we:

  • Obtain access to or a copy of certain personal information we hold about you
  • Prevent the processing of your personal information for direct marketing purposes
  • Update personal information which is out of date or incorrect
  • Delete certain personal information which we are holding about you
  • Restrict the way that we process and disclose specific personal information about you
  • Transfer your personal information to a third-party provider of services
  • Revoke consent that you previously provided for the processing of your personal information

For more information on how to exercise these rights, contact us using the information in the “Contact Us” section below.  If applicable, you may make a complaint to the data protection supervisory authority in the country where you are based. Alternatively, you may seek a remedy through local courts if you believe your rights have been breached.

Security

We care about the security of your transactions and apply industry-standard practices and technologies to safeguard your credit card information. We also employ other appropriate security protocols to help protect your personally identifiable information from unauthorized access by users inside and outside the organization.  However, no method of transmission over the Internet or via mobile device, or method of electronic storage, is absolutely secure.  Therefore, while we strive to protect your information, we cannot guarantee its absolute security.

Retention of Your Information

We keep your information for no longer than necessary for the purposes for which it is processed and/or as required to comply with applicable laws.

Links to Third-Party Websites

This site contains links to other sites that are owned or operated by others (“third-party websites”). We are not responsible for the privacy and security practices of sites not owned by St. Jude Children's Research Hospital or ALSAC. We encourage our visitors to be aware of when they leave our site and to read the privacy statement of any site that collects personally identifiable data.

Children’s Privacy

This site is not intended for use by children under the age of 16 and we do not knowingly collect personal information from children under the age of 16.  If we become aware that we have collected personal information under applicable law from a child under such age without legally valid parental consent, we will take reasonable steps to remove that information.

International Users and Consent to Transfer

Our computer systems are based in the United States, so your information will be processed by us in the United States, where data protection and privacy regulations may not offer the same level of protection as in other parts of the world, such as the European Union.  By using the site, you understand that such information will be transferred to the United States, which may not offer a level of protection equivalent to that required in the European Union or certain other countries, and to the processing of that information as described in this Privacy Policy.

Where required, we will use appropriate safeguards when transferring your data outside of European Union.  For more information about these safeguards, please contact us as detailed in the “Contact Us” section below.

Changes to our Privacy Statement

Any changes to our Privacy Policy will be posted on this site. Any changes will become effective when posted unless indicated otherwise.  Your continued voluntary use of the site following any changes signifies your acceptance of our Privacy Policy as modified.

Email Choices

The quickest means of unsubscribing from electronic communications is through the Email Management Center or by using the unsubscribe function on the eNewsletter you are receiving.

Please note that you cannot opt out of transactional emails (e.g., emails for online transactions, orders, donations and registrations).

Contact Us

If you have any questions about St. Jude Children's Research Hospital, your account, or our privacy protections, please contact us at:

St. Jude Children’s Research Hospital
Office of Legal Services
262 Danny Thomas Place
Memphis, TN 38105-3678
(901) 595-6141
john.bailey@stjude.org

St. Jude Gift Shop
Phone: 1-800-746-1539
Email: onlinegiftshop@stjude.org

To protect your privacy and security, we will take certain steps to verify your identity before granting access to your information or making corrections. Callers will be asked specific questions, including full name, address, phone number and if applicable credit card numbers and/or expiration date, in order to verify their identity and protect the privacy of our visitors and donors.

Last updated June 6, 2018