California Consumer Privacy Act (CCPA) Notice
This notice supplements the JointCommerce Privacy Policy and applies specifically to California residents as required by the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act (CPRA). This notice describes your rights regarding the personal information we collect, use, and disclose.
1. Your Rights Under CCPA
As a California resident, you have the following rights regarding your personal information:
Right to Know
You have the right to request that JointCommerce disclose the categories and specific pieces of personal information we have collected about you in the past 12 months, the categories of sources from which the information was collected, the business or commercial purpose for collecting the information, and the categories of third parties with whom we share the information.
Right to Delete
You have the right to request that JointCommerce delete the personal information we have collected about you, subject to certain exceptions. We may retain data where required by law, such as order records retained for tax compliance (7 years), audit logs (3 years), or ongoing legal obligations. Upon receiving a verified deletion request, we schedule a 14-day grace period before permanent removal to allow you to cancel the request if needed.
Right to Correct
You have the right to request that we correct inaccurate personal information that we maintain about you. You can update most account information directly through your account settings, or contact us to request corrections to information you cannot modify yourself.
Right to Opt-Out of Sale or Sharing
JointCommerce does not sell your personal information to third parties. We also do not share your personal information for cross-context behavioral advertising. However, you may exercise this right for the record at any time by using the opt-out controls described in the "Do Not Sell My Personal Information" section below.
Right to Limit Use of Sensitive Personal Information
You have the right to limit the use and disclosure of your sensitive personal information to purposes that are necessary for providing our services. Medical cannabis card information is used solely for verification purposes and is encrypted at rest.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Specifically, we will not:
- Deny you access to our services.
- Charge you different prices or rates for services.
- Provide you a different level or quality of service.
- Suggest that you may receive a different level or quality of service for exercising your rights.
2. Categories of Personal Information We Collect
In the preceding 12 months, we have collected the following categories of personal information from California residents:
| Category | Examples | Source | Business Purpose |
|---|---|---|---|
| Identifiers | Name, email address, username, IP address, account ID, date of birth | Directly from you; automatically collected | Account creation, authentication, age verification, compliance |
| Commercial Information | Order history, dispensary preferences, saved strains | Directly from you; dispensary partners | Order routing, personalized recommendations, platform features |
| Internet / Network Activity | Browsing history on our platform, search queries, page views, click data | Automatically collected via first-party analytics | Platform improvement, advertising measurement, analytics |
| Geolocation Data | Approximate location derived from IP address (city/state level) | Automatically collected | State compliance, dispensary recommendations, geo-targeted advertising |
| Sensitive Personal Information | Medical cannabis card status (encrypted at rest) | Directly from you | Medical user verification, age compliance |
| Profile Information | Bio, experience level, preferred strains, consumption methods | Directly from you | Personalized recommendations, community features |
3. How We Use Personal Information
We use personal information collected from California residents for the following business and commercial purposes:
- Service delivery: Providing, maintaining, and improving the JointCommerce platform and services.
- Compliance: Verifying age eligibility and ensuring compliance with state cannabis regulations.
- Personalization: Recommending strains, dispensaries, and deals based on your preferences and location.
- Order facilitation: Routing orders to dispensaries for fulfillment (JointCommerce is non-plant-touching and does not handle cannabis products).
- Advertising measurement: Measuring the effectiveness of advertising campaigns using first-party analytics only.
- Security: Detecting, preventing, and addressing fraud, abuse, and security issues.
- Communications: Sending order confirmations, account notifications, and promotional messages (with opt-out).
4. Sharing & Disclosure
We may disclose your personal information to the following categories of third parties for business purposes:
- Dispensary partners: Order details and delivery information necessary for order fulfillment.
- Service providers: Payment processors (Aeropay for payment processing), hosting providers, and analytics services.
- Legal authorities: When required by law, regulation, or legal process.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. JointCommerce uses first-party tracking only and does not share data with third-party advertising networks.
5. Do Not Sell My Personal Information
JointCommerce does not sell your personal information and has not sold personal information in the preceding 12 months. While we do not engage in the sale of personal information as defined by the CCPA, we provide the following mechanisms for you to formally record your preference:
- Use the "Do Not Sell My Info" toggle in your account privacy settings.
- Email privacy@jointcommerce.com with the subject line "Do Not Sell - CCPA Opt-Out."
- Call our privacy hotline at 1-800-JOINT-CA (toll-free).
Do Not Sell My Personal Information
Although JointCommerce does not sell personal information, you can formally record your opt-out preference.
Record Opt-Out Preference6. How to Exercise Your Rights
California residents can exercise their CCPA rights through any of the following methods:
- Online: Log in to your account and visit Account Settings > Privacy to use the data export, deletion, or opt-out controls.
- Email: Send a request to privacy@jointcommerce.com specifying which right you wish to exercise.
- Phone: Call our privacy hotline at 1-800-JOINT-CA (toll-free).
- Mail: Submit a written request to: JointCommerce Privacy Team, 123 Main St, Los Angeles, CA 90001.
- Contact form: Use our online contact form.
CCPA Data Requests
California residents: exercise your CCPA rights using the links below.
7. Verification Process
To protect your privacy and security, we must verify your identity before processing CCPA requests. Our verification process includes:
- Account holders: We will verify your identity by confirming ownership of the email address associated with your JointCommerce account. You may be required to log in to your account or respond to a verification email.
- Non-account holders: We will request at least two pieces of identifying information to match against our records (e.g., email address, name, and order history details).
- Sensitive requests: For requests involving sensitive personal information or account deletion, we may require additional verification steps, such as answering security questions or providing a signed declaration under penalty of perjury.
We will respond to verified requests within 45 calendar days. If we need additional time (up to 90 days total), we will notify you of the extension and the reason for the delay.
If we cannot verify your identity, we will explain why and provide instructions for alternative verification methods.
8. Authorized Agents
You may designate an authorized agent to submit a CCPA request on your behalf. To do so:
- Provide a signed, written authorization to the agent.
- We may still require you to verify your identity directly with us.
- The agent must provide proof of authorization upon request.
We may deny requests from agents who cannot provide adequate proof of authorization.
9. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this notice and our Privacy Policy. Specific retention periods include:
- Account data: Retained until you request deletion or close your account.
- Order history: 7 years (tax and legal compliance).
- Analytics data: Raw event data aggregated after 90 days; aggregated data retained indefinitely.
- Session data: Expires after 24 hours of inactivity.
- Audit logs: 3 years (security and compliance).
10. Changes to This Notice
We may update this CCPA notice from time to time. When we make material changes:
- We will update the "Last updated" date at the top of this page.
- We will notify California residents via email at least 30 days before material changes take effect.
- We will display a prominent notice on the platform.
11. Contact Information
For questions about this CCPA notice or to exercise your rights, contact us:
- Email: privacy@jointcommerce.com
- Phone: 1-800-JOINT-CA (California residents, toll-free)
- Mail: JointCommerce Privacy Team, 123 Main St, Los Angeles, CA 90001
- Online: Contact Form
Related Legal Documents
Review additional legal documents that govern your use of JointCommerce.