INFORMATION FOR CALIFORNIA RESIDENTS
CALIFORNIA CONSUMERS’ RIGHTS AND CHOICES
- Categories of Personal Information (as defined by applicable California law) collected, sold or disclosed by us;
- Purposes for which categories of Personal Information collected by us are used;
- Sources of information from which we collect Personal Information;
- Specific pieces of Personal Information we have collected about you.
- Opt-out of the sale or disclosure of your Personal Information, in some circumstances;
- Opt-out of receiving marketing communications from us; however, you may still receive administrative communications regarding our services;
- Opt-in to certain financial incentive programs we may offer related to the collection, sale, or deletion of your Personal Information; and
- Request deletion of your Personal Information by us and our service providers, in some circumstances.
You will not be discriminated against for exercising your rights under the California Consumer Privacy Act.
COLLECTION OF PERSONAL INFORMATION FROM CALIFORNIA RESIDENTS
We have listed below the personal information we may have collected from California residents in the past 12 months.
Category of personal information we may collect: Identifiers
Categories of sources from which we may obtain your “Identifiers” include:
Directly from consumers
The purposes for collecting your “Identifiers” include:
To communicate with our customers and improve our customer experience.
Category of personal information we may collect: Personal Characteristics
Categories of sources from which we may obtain your “Personal Characteristics” include:
Directly from consumers
The purposes for collecting your “Personal Characteristics” include:
To improve our customer experience.
Category of personal information we may collect: Internet/Electronic Activity
Categories of sources from which we may obtain your “Internet/Electronic Activity” include:
Directly from consumers
The purposes for collecting your “Internet/Electronic Activity” include:
To improve our customer experience.
Selling/sharing your personal information
Categories of third parties we may sell your personal information to
We do not sell personal information to third parties.
Categories of third parties we may otherwise share your personal information with
Data analytics providers, Operating systems and platforms
You can make requests be contacting us by e‑mail at email@example.com and include “Privacy Notice” in the subject line.
When you make a request, we may ask you to provide verifying information, such as your name, email, or phone number. We will review the information provided and may request additional information via email or other means to ensure we are interacting with the correct individual. Please also be aware that making any such request does not ensure complete or comprehensive removal or deletion of Personal Information or content you may have posted, and there may be circumstances in which the law does not require or allow us to fulfill your request.
Our Services are not directed to children, and we do not knowingly collect Personal Information from children under the age of 16. If you learn that a child has provided us with Personal Information, then you may contact us as indicated above.
DO NOT TRACK
FLAT WHITE does not currently take steps to respond to browsers’ “Do Not Track” signals as no uniform standard to respond to such signals has been developed at this time.
TEXT MARKETING AND NOTIFICATIONS
By entering your phone number in the checkout and initializing a purchase, subscribing via our subscription form or a keyword, you agree that we may send you text notifications (for your order, including abandoned cart reminders) and text marketing offers. Text marketing messages will not exceed 30 a month. You acknowledge that consent is not a condition for any purchase.
If you wish to unsubscribe from receiving text marketing messages and notifications reply with STOP to any mobile message sent from us or use the unsubscribe link we provided you with in any of our messages. You understand and agree that alternative methods of opting out, such as using alternative words or requests will not be accounted as a reasonable means of opting out. Message and data rates may apply.
For any questions please text HELP to the number you received the messages from. You can also contact us for more information. If you wish to opt out please follow the procedures above.
- Personal Data We Collect
In this Policy, “Personal Data” means any information relating to an identified or identifiable individual. We may collect Personal Data about you from various sources described below.
INFORMATION PROVIDED BY YOU
Account Information. If you create an account to use our Services, we collect Personal Data related to its creation and the usage of our Services via this account. When you sign up, you may provide us with your name, email address, password, mobile phone number, interest, and other account information.
Communications. When you contact us via a contact form, email, or other means, you provide us with Personal Data, such as your name and contact details, and the content, date, and time of our communications.
Support Information. When you request technical support services, we will process your Personal Data such as your name and the contact details you use to contact us, as well as information on the reasons for your support request, and any additional information you may provide in that context.
Careers. If you apply for a job with us, you may provide us with your resume, name and contact details, and any other information that you submit to us. If you become an employee, we collect additional information, such as your family information, beneficiary selections, and banking information, for employment, payroll, and benefit purposes.
Where applicable, we may indicate whether and why you must provide us with your Personal Data, as well as the consequences of failing to do so at the time the data is collected.
INFORMATION COLLECTED FROM OTHER SOURCES
Third Parties. We obtain Personal Data about you from third parties, such as Outbound marketing vendors and others. This information may include Outbound marketing lists and other similar information.
INFORMATION WE COLLECT BY AUTOMATED MEANS
Social media. We may collect Personal Data via social media tools, widgets, or plug-ins to connect you to your social media accounts. These features may allow you to sign in through your social media account, share a link, or post directly to your social media account. When you visit a website that contains such tools or plugins, the social media or other service provider may learn of your visit. Your interactions with these tools are governed by the privacy policies of the corresponding social media platforms.
Cookies. We collect Personal Data via cookies and similar technologies (see section 3 of this Policy for more information).
- How We Use Personal Data
We use the Personal Data we collect for the following purposes:
Providing the Services, including to operate, maintain, support, and provide our Services.
Communicating with You, including to contact you for administrative purposes (e.g., to provide services and information that you request or to respond to comments and questions) or to send you marketing communications, including updates on promotions and events, relating to products and services offered by us.
Personalization, including to customize our Services to you and provide you with the most relevant marketing and advertising materials.
Analytics and Product Development, including to analyze usage trends and preferences in order to improve our Services, and to develop new products, services, and features.
Customer and Vendor Relationship Management, including to track emails, phone calls, and other actions you have taken as our customer or vendor.
Aggregation. We may aggregate or otherwise de-identify Personal Data and use the resulting information for statistical analysis.
Administrative and Legal, such as to address administrative issues or to defend our legal rights and to comply with our legal obligations and internal policies.
- Legal Basis for the Processing of Personal Data
We rely on a legal basis to process your Personal Data, including:
Consent. You have consented to the use of your Personal Data, for example to send you electronic marketing communications or for the use of certain cookies.
Contract. We need your Personal Data to provide you with our Services and to respond to your inquiries.
Legal Obligation. We have a legal obligation to use your Personal Data, for example to comply with tax and accounting obligations.
Legitimate Interest. We or a third party have a legitimate interest in using your Personal Data, for example we have a legitimate interest in using your Personal Data for product development and analytics purposes. We only rely on this legal basis when our or a third party’s legitimate interests are not overridden by your rights and interests.
- How We Disclose Personal Data
We may disclose Personal Data about you in the following circumstances:
Group Entities. We may disclose Personal Data about you to our affiliates and subsidiaries.
Public Posts. Any information that you voluntarily choose to post to a publicly accessible area of our Services will be available to anyone who has access to that content.
Service Providers. We work with third-party service providers to provide services such as hosting, maintenance, and support. These third parties may have access to or process your Personal Data as part of providing those services to us.
Legal. We may disclose your Personal Data if we believe, in good faith, that this is appropriate (a) under applicable law, including laws outside your country of residence; (b) to comply with legal process; (c) to respond to requests from public and government authorities, including public and government authorities outside your country of residence; (d) to enforce our terms and conditions; (e) to protect our operations; (f) to protect our rights, privacy, safety, or property, and/or that of our affiliates, you or others; and (g) to allow us to pursue available remedies or limit the damages that we may sustain.
Merger. Information about our users, including Personal Data, may be disclosed and otherwise transferred to an acquirer, successor, or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets.
Aggregated Information. We may use and disclose aggregated or otherwise de-identified information for any purpose, unless we are prohibited from doing so under applicable law.
- Your Rights and Choices
Unless otherwise provided under applicable law, you have the following rights:
Access and Portability. You may ask us to provide you with a copy of the Personal Data we maintain about you, including a machine-readable copy of the Personal Data that you have directly provided to us, and request information about its processing.
Rectification and Deletion. You may ask us to update and correct inaccuracies in your Personal Data, or to have the information anonymized or deleted, as appropriate.
Restriction and Objection. You may ask us to restrict the processing of your Personal Data, or object to such processing.
Consent Withdrawal. You may withdraw any consent you previously provided to us regarding the processing of your Personal Data, at any time and free of charge. We will apply your preferences going forward and this will not affect the lawfulness of the processing before you withdrew your consent.
Complaint. You may lodge a complaint with a supervisory authority, including in your country of residence, place of work, or where an incident took place.
You may exercise these rights by contacting us using the contact details at the end of this Policy. Note that there are exceptions and limitations to each of these rights, and that we may nevertheless retain Personal Data about you where we reasonably believe that we have a legitimate reason to do so.
- International Data Transfers
We may transfer your Personal Data outside of Europe and, in particular, to USA and other non-European countries, where the level of protection of Personal Data may be different than in your country. If we do so, we will comply with applicable data protection laws, in particular by relying on an EU Commission adequacy decision, rely on contractual protections for the transfer of your Personal Data, on Binding Corporate Rules or on the EU-U.S. Privacy Shield framework. For more information about how we transfer Personal Data outside of Europe, or to obtain a copy of the contractual safeguards we
use for such transfers, please contact us as specified below.
- Data Security and Data Retention
We use physical, managerial, and technical safeguards that are designed to improve the integrity and security of Personal Data that we collect, maintain and otherwise process. We take measures to delete your Personal Data or keep it in a form that does not permit identifying you when this information is no longer necessary for the purposes for which we process it, unless we are required by law to keep it for a longer period. When determining the retention period, we take into account various criteria, such as the type of products or services provided to you, the nature and length of our relationship with you, mandatory retention periods and the statute of limitations.
- Third-Party Services
Our Services may contain features or links to websites and services provided by third parties. Any information you provide via these websites or services is provided directly to these third-party operators and is subject to their privacy policies, even if accessed through our Services. We encourage you to learn about these third parties’ policies before providing them with your Personal Data.
- Changes and Updates to this Policy
We may update this Policy from time to time to reflect changes in our privacy practices. If we modify this Policy, we will indicate the date of the latest revision above.