Pardon our dust while we update this corner of the website.


Effective April 7, 2020

Overview
The Philadelphia Museum of Art (“PMA,” “we,” “our,” and/or “us”) is committed to safeguarding the privacy and security of our members, donors, visitors, attendees of any PMA programming, and users of this website or any other PMA-generated content (collectively or individually, “Users,” “you” and/or “your”). Thank you for visiting PMA’s website and reviewing our privacy policy. PMA collects information for several different purposes and this privacy policy explains what data we collect both online and offline and how we use it.

PMA’s privacy policy ensures compliance with the European Union’s General Data Protection Regulation (“GDPR”). For more information, please see the “Data Protection Privacy under the General Data Protection Regulation (“GDPR”)” section of this policy.

Disclaimers
PMA is a 501(c)3, nonprofit organization. Information on this website is presented purely for educational and informational purposes. Your use of this website is subject to the provisions of this privacy policy, as well as the terms and conditions set forth in the Copyright Notice.

We cannot guarantee the website will be error-free. However, we will make every reasonable effort to make content accurate, reliable and complete. This includes correcting any errors that are brought to our attention. You may contact us at .

Viewing the Website
Information Collected and Stored Automatically
When you visit our website, we automatically gather and store the following information about your visit using cookies. This information is used in the aggregate to develop statistics that guide us in making improvements and enhancements to the website.

The following information is stored and used in the aggregate only, and is not used to contact you personally:

• The IP address from which you access our website
• The date and time you access our website
• The pages, files, documents and links that you visit
• The Internet address of the website from which you linked to our website
• The name of the domain from which you access the Internet
• The type of browser and operating system used to access our website
• The type of Plug-in and Plug-in version on the system

Also, when you perform a search within the website, PMA may record certain information regarding your search and use that information to, among other things, solve technical problems with the website and to calculate overall usage statistics.

PMA does not sell, rent, or offer the foregoing information to third parties.

Cookies
PMA uses technology known as “cookies” to track usage patterns, traffic trends and user behavior, as well as to record other information from the website. For certain services provided on this website, cookies allow us to save information locally so that you will not have to re-enter it the next time you visit. Many content adjustments and customer service improvements are made based on the data derived from cookies. The information we collect from cookies will not be used to create profiles of users and will only be used in aggregate form. Users should be aware that PMA contracts with third party vendors for services that require the sharing of non-personally identifiable information collected via cookies.

You may set your browser to refuse cookies. If you so choose, you may still gain access to most of our website, but you may not be able to conduct certain types of transactions (such as shopping) or take advantage of some of the interactive elements offered.

If you would like more information about cookies and the option not to have them used by third-party companies during your visit to the PMA website, you may visit: http://www.usa.gov/optout-instructions.

In addition to using cookies and related technologies as described above, we also may permit certain third-party companies to help us tailor advertising that we think may be of interest to users and to collect and use other data about user activities on our Sites and/or Services (e.g., to allow them to tailor ads on third-party services). These companies may deliver ads that might also place cookies and otherwise track user behavior.

Providing Us Personal Information
If you provide us personal information—by submitting an e-mail, completing an online form or survey, providing us information over the phone, requesting materials or information, ordering merchandise or PMA tickets, making a donation, signing up for membership or providing us with your personal information in person for any reason—we will use this information to respond to your inquiry or request. We may also use it to contact you to provide information about other PMA activities, programs, membership and fundraising opportunities, products and special events that may interest you, unless PMA knows you are a European citizen or resident in which case no personal information will be used for these purposes. You may opt-out of having your information used by PMA for these purposes, or you may update your contact information anytime, by contacting us via the following e-mail or postal mail addresses:


Philadelphia Museum of Art
Website
Box 7646
Philadelphia, PA 19101-7646
USA

Moreover, when we send you communications regarding PMA programs and activities, you will always have an immediate opportunity to decline further communications by unsubscribing. If you are a citizen of a jurisdiction subject to GDPR, please see the section entitled “Data Protection Privacy under the General Data Protection Regulation (“GDPR”)” below for information in exercising your rights with regard to your personal information.

The names and postal addresses of Users who have provided such information to the Philadelphia Museum of Art may be shared with other organizations that may be of interest to you for informational, fundraising, or related purposes. In these cases, we may share your name and address with other reputable organizations, but we will not share your e-mail or phone number with these institutions. In addition, all information we do share with other institutions is provided subject to confidentiality obligations limiting the nature of the use of your information and restricting the further dissemination of your information. If you do not wish to have your name and address shared with other institutions for these purposes, you may opt out at any time by contacting us via the above email or postal mail address.

Transactions
Purchasing Tickets/Web Ticketing
PMA provides Users with the opportunity to purchase tickets, programs, and membership online. When you choose to make a purchase online, we may collect your name, billing and shipping addresses, telephone number, and e-mail address, along with information about what you purchase. This information is subject to the “Providing Us Personal Information” section above. PMA uses Accesso Passport (“Accesso”), a secure third party, to process your payment card information, allowing us to efficiently automate the selling and allocating of tickets in real-time. Your payment card information is collected and stored in accordance with Accesso’s privacy policy, which can be found here: Accesso Privacy Policy. PMA does not collect or store your payment card information.

Museum Store and Online Membership
PMA provides Users with an opportunity to make online purchases from our retail store as well as purchase a PMA membership. When you choose to make an online purchase or to become a member of PMA through the PMA’s online store (the “Online Store”), you are linked to a website powered by BigCommerce, a secure third party. You may browse the Online Store without registering or submitting personally identifiable information.

When you choose to make a purchase through the Online Store or make an in-person purchase, PMA may collect your name, billing and shipping addresses, telephone number, and e-mail address, along with information about what you purchase. This information is subject to the “Providing Us Personal Information” section above. When you make a purchase through the Online Store, PMA uses BigCommerce to process your payment card information. Your payment card information is collected and stored in accordance with BigCommerce’s privacy policy, which can be found here: BigCommerce Privacy Policy. PMA does not collect or store your payment card information when you make a purchase online. Your personal information may also be collected and stored by BigCommerce, in accordance with their privacy policy. PMA will retain minimal personally identifiable information for our records to facilitate better customer service, keep you up-to-date on your order status, and to inform you of future products and promotions. When you make an in-person purchase, PMA collects your credit card information to process your order, in accordance with the “Security” section below. If you are a citizen of a jurisdiction subject to GDPR, please see the section entitled “Data Protection Privacy under the General Data Protection Regulation (“GDPR”)” below for information in exercising your rights with regard to your personal information.

If you choose to register at our Online Store, PMA will request some of the same personally identifiable information used to process an order (which includes your name, mailing address, phone number, and email address). This information is used to create a more personalized experience for you each time you visit. With registration, you will be able to keep items in a shopping cart for review or purchase at a later date, view a history of your past orders, and experience a faster checkout. If you need to change any of the information that you provided, you can safely update it any time you log in or it can be permanently removed if you contact us via the above email or postal mail address.

Support the Museum
The Philadelphia Museum of Art also provides Users with an opportunity to make a contribution to our organization in person, over the telephone or through an online donation page. The information that you supply during any of the above transaction processes is used to fulfill your order and will also be used to track and analyze transaction trends. This information is also subject to the “Providing Us Personal Information” section above. When you choose to make a contribution to our organization through the online donation page, you are linked to a website powered by Accesso Passport, allowing us to efficiently process donations. Your payment card information is collected and stored in accordance with Accesso’s privacy policy. PMA does not collect or store your payment card information. Accesso’s privacy policy can be found here: Accesso Privacy Policy.

The Planned Giving Calculator is hosted by PG Calc and linked to our website to allow you to explore the benefits of charitable giving. Users of the Planned Giving Calculator are subject to PG Calc’s privacy policy, which can be found here: PG Calc Privacy Policy.

Security
The online transactions conducted on PMA’s website and on site are protected by security features, including encryption, designed to prevent the unauthorized release of your personal financial data. All credit card information will be encrypted using SSL and complies with current PCI standards. We also monitor network traffic in an effort to make the website available to all users and to identify unauthorized attempts to access, upload or change information or otherwise cause damage to our systems.

While PMA has endeavored to create a secure and reliable website, please be advised that the confidentiality of any communication or material transmitted to/from this website over the Internet cannot be guaranteed. Accordingly, PMA and its employees, agents, officers, directors, legal representatives, predecessors, successors and assigns are only responsible for information after receipt and while in our custody and control.

You assume the sole and complete risk for using this website and must make your own determination as to these matters.

Unauthorized access is prohibited and punishable under the Computer Fraud and Abuse Act and the National Information Infrastructure Protection Act.

Children’s Privacy on the Web
PMA is concerned about protecting children’s privacy. We do not knowingly collect personally identifiable information from children under the age of 13. There are some areas within the Philadelphia Museum of Art website where children could post messages or provide feedback, but children are discouraged from providing personal information. If a visitor known to be a child under the age of 13 sends an e-mail to PMA, we will only use it to respond to the writer and not to create profiles or otherwise retain the information.

Linking
PMA’s website may provide links to third-party websites that may offer various products, services, and/or information. You should be aware that your use of these third-party websites may be subject to separate terms and conditions, information collection practices, and other provisions. PMA does not endorse, nor is it responsible for, any of the products, services, or content offered in any third-party sites. Before using any third-party service, it shall be your sole responsibility to conduct whatever investigation you deem necessary and appropriate. PMA has used reasonable efforts to confirm such third parties comply with GDPR.

Data Protection Privacy under the General Data Protection Regulation (“GDPR”)
The GDPR protects personal data collected from citizens of European Union Member States. PMA collects and stores certain personal data through our website, in person or over the phone for the reasons set forth in the “Providing Us Personal Information” section above.

In order for the PMA to collect this information, you must consent to the collection of your personal data. PMA will only use your personal data for the purposes established in this policy, unless we discover another purpose that is in line with the PMA’s original purpose for collection. In the event that you do not consent to the collection of your personal data, then the PMA may not be able to completely and fully provide you with all of our services.

The PMA will store your personal data for as long as necessary to fulfill the purpose for which the personal data was collected and processed, including for the purposes of satisfying any legal, regulatory, accounting or reporting requirements. To determine the appropriate retention period for your personal data, we will consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use of disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve these purposes through other means, and the applicable legal requirements. Upon expiration of this time frame, PMA will securely erase and destroy all of your collected personal data, in accordance with applicable laws and regulations.

Personal Data
The term “personal data” includes information such as your name, address, email address, telephone number, IP address, credit card information, identification number, website cookies, occupation and location. Personal information does not include data from which you can no longer be identified due to encryption or anonymity. In some circumstances, the PMA may completely anonymize your personal data so that it is no longer attributable to you. In this case, the information will no longer be considered personal data for GDPR purposes.

Rights to your Personal Data under the GDPR
If the GDPR applies to you, then you have particular rights as an individual under this regulation, including the right to:
  • (i) request access to your personal data stored by PMA and request certain information in relation to its processing;
  • (ii) request a change and/or update be made to your personal data stored by PMA; and
  • (iii) request restriction of processing of your personal data;
  • (iv) request erasure of your personal data stored by PMA; and
  • (v) object to the processing of your persona data.
To exercise one of these rights, please contact us at .

In most cases, requests in accordance with exercising your rights under the GDPR will not accumulate any fees. However, to the extent that your requests are manifestly unfounded or excessive, PMA may request that you pay a reasonable fee.

Withdrawal of Consent
The PMA acknowledges that even though you may initially consent to the processing of your personal data, you may want to withdraw your consent from time to time. You may withdraw your consent from the processing of personal data either entirely or in part. To withdraw your consent, please contact .

Questions or Concerns
If you have any questions or concerns regarding the rights established under the GDPR, please feel free to contact us at .

Data Breach Notification Procedures
In the event that a data breach occurs, the PMA’s Information and Interpretive Technology (IIT) Department will (i) review the breach and implement reasonable steps to prevent future incidents; (ii) review the scope and detail of compromised data; (iii) communicate the details of the breach to PMA’s Executive Officers and any other relevant departments or services providers; and (iv) if it is determined that the breach materially compromises the security, confidentiality, or integrity of Users’ personal information, notify affected individuals of the security breach in accordance with the Pennsylvania Breach of Personal Information Notification Act. Notifications will be sent out via email whenever possible, but phone and mail notifications will be used if an individual has not supplied a working email address.

Revisions to Our Policies
Please note that PMA may revise its privacy policy at any time. Occasionally, changes in technology, functionality, content we provide, laws and/or Museum policy may require us to revise policies and practices on this page. We encourage you to periodically visit this page to review our most current policy. Your continued use of the site shall constitute your acceptance of any such changes to this policy.

Questions about this privacy policy can be directed to:


Philadelphia Museum of Art
Website
Box 7646
Philadelphia, PA 19101-7646
USA