Supplemental U.S. State Privacy Notice for Residents of Covered States

Supplemental U.S. State Privacy Notice for Residents of Covered States

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana or another state with a similar comprehensive consumer privacy law (collectively, “Covered States”), you may have specific rights regarding your personal information under the California Consumer Privacy Act (“CCPA”), Virginia Consumer Data Protection Act, Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, Texas Data Privacy and Security Act, Oregon Consumer Privacy Act, Montana Consumer Data Privacy Act and other applicable laws (collectively, “State Privacy Laws”). This section describes the rights that consumers of Covered States have and explains how to exercise those rights. These rights are granted only to the extent that you are considered a consumer of a Covered State and we are acting as a “controller” or “business” (as applicable) under State Privacy Laws with respect to your personal information.

This Supplemental Policy applies to the Company’s online and offline information gathering and dissemination practices in connection with the Company’s website (the “Site”) and Personal Information we may collect or receive through other means.

The chart below shows the Personal Information we may collect, retain, or share including: (i) the categories of Personal Information collected in the preceding 12 months; (ii) examples of Personal Information collected; (iii) the sources from which we may have collected it; (iv) the business purposes for which we may have collected it; and (v) categories of third parties with whom we share or disclose the Personal Information we collect. Please know that “Personal Information” does not include:

  • Publicly available information from government records;
  • De-identified or aggregated consumer information;
  • Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) or the California Confidentiality of Medical Information Act (“CMIA”) or clinical trial data (CA Consumers Only);
  • Personal Information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (“FCRA”), the Gramm-Leach-Bliley Act (“GLBA”), or California Financial Information Privacy Act (“CFIPA”) (CA Consumers Only), Family Education Rights and Privacy Act (“FERPA”) (except for CO consumers), and the Driver’s Privacy Protection Act of 1994 (“DPPA”);
  • Employee and commercial business-to-business data; and
  • Information from registered national securities associations.
Category of Personal InformationExamplesSources of Personal InformationBusiness Purpose for CollectionTypes of Third Parties with Whom Personal Information is Shared, Sold, or Disclosed
Contact Information and IdentifiersName, IP address, email address, Phone number, or other similar identifiersDirectly from you via our Site;

Communication with you; cookies (IP address);

Connection with social media accounts
Provide you with content and services;

Manage your preferences;

Customize your experience
Disclosed:
Website provider

Shared:
Marketing providers
Analytics providers
Social media platforms
Business partners
Date of birthDate of birthShared by you with usProvide you with content and services;

Manage your preferences;

Customize your experience
Disclosed:
Website provider

Shared:
Marketing providers
Geolocation DataDevice location or country of residenceFrom your device or shared by you with usProvide you with
content and
services;

Customer service
communications;

Improve
promotions and
offerings
Disclosed:
Website provider

Shared or Sold:
Marketing providers

Analytics providers

Social media platforms

Business partners
GenderMale, female, etc.Shared by you with usProvide you with content and services;

Customize your experience;

Improve promotions and offerings
Disclosed:
Website provider

Shared or Sold:
Marketing providers

Analytic providers

We do not store or retain any credit card or other billing and payment information. Any online payments made through a link from our Site is to a third-party internet payment site (Stripe.com, Shopify.com, or Patreon.com) that is outside of this Privacy Policy and is instead governed by its own separate privacy policy. We do not collect, receive, or keep any Personal Information you may provide through such third-party internet payment sites.

If you are a resident of a Covered State, you may make the following requests, subject to certain conditions or exceptions as set forth under State Privacy Laws:

You have the right to know the categories of Personal Information the Company has collected about you, including:

  • The categories of Personal Information we have collected about you;
  • The categories of sources from which that Personal Information is collected;
  • Our business or commercial purpose for collecting or selling Personal Information we collected from you;
  • The categories of third parties with which we share Personal Information; and/or
  • The specific pieces of Personal Information we collect about you.

You also have the right to know and access, in a verifiable consumer request, the categories of Personal Information that we sell or share about you, including:

  • The categories of Personal Information we collected about you;
  • The categories of Personal Information we sold or shared about you and categories of third parties to which the Personal Information was sold by category or categories of Personal Information for each third party to which the Personal Information was sold; and/or
  • The categories of Personal Information we have disclosed for business purposes.

Click here to exercise this right.

You have the right to request that we correct any inaccurate Personal Information that we maintain about you, considering the nature of the Personal Information and the purposes of the processing of the Personal Information. Click here to exercise this right.

You have the right to request that we delete certain Personal Information that we collect from you and retain, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your Personal Information from our records, unless an exception applies. Click here to exercise this right.

Residents of several Covered States also have the right to obtain a copy of their Personal Information previously provided to us in a portable and, to the extent technically feasible, readily usable format that allows them to transmit the data to another business without hinderance. Click here to exercise this right.

You have the right to exercise the foregoing consumer rights under applicable privacy laws. We cannot deny you goods or services, charge you a different price, or provide a different level or quality of goods or services just because you exercised your rights. However, if you decline to provide your Personal Information or ask us to delete or stop selling your Personal Information, and that Personal Information or sale is necessary for us to provide you with goods or services, we may not be able to complete that transaction. We can also offer you promotions, discounts, and other deals in exchange for collecting, keeping, or selling your Personal Information. But we will only do this if the financial incentive offered is reasonably related to the value of your Personal Information.

You may be able to opt out of some collection or uses of your Personal Information.

  • You have the right to opt out of the sharing of your Personal Information, as those terms are defined under respective Covered State privacy laws.
  • You have the right to opt out of cross-behavioral advertising.
  • You have the right to opt out of profiling.

We do not sell, trade, or otherwise transfer to Third-Parties for their own use any of your Personal Information, unless we provide you with advance notice and you consent. Except as described in this Privacy Policy, we also do not disclose to Third Parties any personally identifiable information about your visits to our Site.

Further, we do not share Personal Information of consumers less than 16 years of age, unless the consumer, in the case of consumers between 13 and 16 years of age, or the consumer’s parent or guardian, in the case of consumers who are less than 13 years of age, has affirmatively authorized the sharing of the consumer’s Personal Information.

If you elect to opt out, we honor Opt-Out Preference Signals, also known as Global Privacy Controls (“GPC”), that communicate a consumer’s choice to opt out of sale or sharing. GPC is a browser extension that sets privacy preferences for Personal Information as you browse the internet.

California residents may request to limit the use or disclosure of your Sensitive Personal Information in certain circumstances.

You have the right to consent to the use of your Sensitive Personal Information and to limit the use and disclosure of your Sensitive Personal Information to that which is necessary for providing products or services to you.

Residents of California may request information about our disclosure of Personal Information to other parties for their direction marketing purposes under California Civil Code Section § 1798.83. California residents may email us at privacy@candaceowens.com to make a “Shine the Light Request.” Please include “Shine the Light” in the subject line of the email.

You have the right to appeal our decision about your data subject request. If you would like to appeal a decision regarding your data request, please email privacy@candaceowens.com. Please include “Appeal” in the subject line of the email and describe the date and nature of your original request.

If you still disagree with our decision following the appeal, you can submit a complaint to your state’s Attorney General’s Office.

If you wish to exercise any of the consumer rights summarized above, such as a Request to Know, Correct, or Delete Personal Information, you can do so in one of the following ways:

Click on this link to complete and submit the referenced web form; or

Reach us by email or U.S. mail at:

Chief Legal Officer
GeorgeTom Inc.
PO Box 158067
1906 Glen Echo Road
Nashville TN 37215

Email: privacy@candaceowens.com

Upon receiving a verifiable consumer request, we will confirm receipt of the request within 10 days, provide information about how we will verify and handle the request, and advise when you should expect to receive a response.

Of course, we need to be reasonably sure that the person making the request is you. So, we may need some information from you to verify that you are the person whose Personal Information you are asking to know about or to delete. Accordingly, the verifiable consumer request must:

  • Provide sufficient information that allows us to reasonably verify whether you are the person about whom we collected Personal Information or an authorized representative.
  • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use Personal Information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.

Only you or a person registered with the Secretary of State where you reside that you designate and authorize to act on your behalf, may make a verifiable consumer request related to your Personal Information. For your protection, we will need some proof that someone seeking to act on your behalf is authorized by you to do so. You may also make a verifiable consumer request on behalf of your minor child.

We will try to respond to a verifiable consumer request within 45 days of its receipt. If we need more time (up to 90 days), we will inform you of the reason and extension period in writing. If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding our receipt of the verifiable consumer request.

If you are making a Request to Delete your Personal Information, we will re-confirm with you that you want your information deleted after verifying your request.

If we cannot respond to or comply with your consumer request because we cannot verify your identity or because an exception applies, we will explain the reasons we cannot comply with your request. For data portability requests, we will select a format to provide your Personal Information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.


American Dreamer Text Overlay Image