Free Health Assessment
California Privacy Rights

CCPA/CPRA Compliance

Your Privacy Rights Under California Law

California Consumer Privacy Act • California Privacy Rights Act
FOR CALIFORNIA RESIDENTS ONLY

This Policy Applies to California Consumers

If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information. This page describes those rights and explains how to exercise them.

Non-California residents: Please refer to our main Privacy Policy for information about our data practices.

1

Notice at Collection

Required by CCPA § 1798.100(b) This notice is provided at or before the point of collection of personal information.

We collect the following categories of personal information from California residents, for the business purposes described below:

Category of Personal Information Business Purpose for Collection Retention Period
Identifiers
Name, email, address, IP address, account name
Provide services, account management, communication, security As long as account active + 2 years
Customer Records
Phone number, payment info, shipping address
Order fulfillment, customer service, transaction processing 7 years (tax/legal compliance)
Commercial Information
Purchase history, product interests, assessment results
Personalized recommendations, product improvement, analytics 5 years
Internet Activity
Browsing history, search history, interactions with website
Analytics, site optimization, fraud prevention 2 years (anonymized after 26 months)
Geolocation Data
IP-based location (not precise GPS)
Analytics, fraud prevention, regional compliance 30 days in logs
Inferences
Pet health profile, supplement preferences, predicted needs
Personalized recommendations, service improvement 3 years
Sensitive Personal Information
Account login credentials, payment card information
Authentication, transaction processing (no secondary use) As required for purpose

Sources of Personal Information

We collect this information directly from you, automatically through your use of our Site, and from third-party service providers (payment processors, shipping carriers).

2

Our Privacy Practices

No Sale of Personal Information

SOBS Pets DOES NOT sell personal information. We do not exchange your personal information for monetary consideration. We also do not "share" personal information for cross-context behavioral advertising as defined under California law.

12-Month Lookback Period

This disclosure covers the preceding 12 months from the effective date of this policy (February 12, 2025 - February 12, 2026).

No Automated Decision-Making

We do not use automated decision-making technology, including profiling, that produces legal or similarly significant effects concerning California consumers.

3

Your California Privacy Rights

As a California resident, you have the following rights under the CCPA/CPRA. These rights are subject to certain exceptions and verification requirements.

Right to Know

Request disclosure of categories and specific pieces of personal information collected.

Learn More →

Right to Delete

Request deletion of personal information we have collected from you.

Learn More →

Right to Correct

Request correction of inaccurate personal information.

Learn More →

Right to Opt-Out

Opt-out of the sale or sharing of personal information.

Learn More →

Right to Limit

Limit the use of sensitive personal information.

Learn More →

Non-Discrimination

Right to equal service and price, regardless of rights exercise.

Learn More →
4

Right to Know

CCPA § 1798.110, 1798.115

You have the right to request that we disclose the following information about our collection and use of your personal information over the past 12 months:

Categories We Must Disclose

  • Categories of personal information collected
  • Categories of sources from which personal information is collected
  • Business or commercial purpose for collecting, selling, or sharing personal information
  • Categories of third parties to whom we disclose personal information
  • Specific pieces of personal information we have collected about you

Exceptions

We may deny your request to know specific pieces of personal information if disclosure would:

  • Compromise the security of your account
  • Create a substantial, articulable, unreasonable risk to your personal information
  • Violate the rights of another consumer
  • Conflict with trade secret or privileged information
5

Right to Delete

CCPA § 1798.105

You have the right to request that we delete any personal information about you that we have collected from you, subject to certain exceptions.

Exceptions to Deletion

We may deny your deletion request if retaining the information is necessary for us or our service providers to:

(1) Complete the transaction for which the information was collected, provide a requested good or service, or perform a contract with you
(2) Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity
(3) Debug to identify and repair errors that impair existing intended functionality
(4) Exercise free speech, ensure the right of another consumer to exercise their rights, or comply with the California Electronic Communications Privacy Act
(5) Comply with a legal obligation (e.g., tax records, transaction history required by law)
(6) Use internally in a lawful manner compatible with the context in which you provided the information

Note: If we deny your deletion request, we will explain the reason for the denial and provide you with a method to appeal the decision.

6

Right to Correct

CPRA § 1798.106

You have the right to request that we correct inaccurate personal information that we maintain about you.

When you submit a request to correct information, we will:

  • Consider the totality of circumstances regarding the contested information
  • Review documentation you provide to support your request
  • Respond within 45 days (with possible 45-day extension)
  • Provide a written explanation if we deny your request
Tip: You can also log into your account at any time to update your profile information, shipping addresses, and communication preferences without submitting a formal CCPA request.
7

Right to Opt-Out of Sale or Sharing

CCPA § 1798.120
SOBS Pets DOES NOT sell personal information

We do not exchange personal information for monetary consideration. We also do not "share" personal information for cross-context behavioral advertising.

Because we do not sell or share your personal information, we do not maintain an opt-out mechanism. However, you may still submit a request to opt-out of future sales, and we will honor that request and retain it for at least 15 months as required by law.

Opt-Out Preference Signals

We honor global privacy control signals. If you broadcast a Do Not Sell or Share preference via:

  • Global Privacy Control (GPC) - Supported by browsers and extensions
  • Browser DNT signals - We treat as opt-out of sharing

These signals will be honored as valid opt-out requests.

8

Right to Limit Use of Sensitive Personal Information

CPRA § 1798.121

You have the right to limit the use of your sensitive personal information to that which is necessary to perform the services or provide the goods you requested.

Sensitive Personal Information We Collect

  • Account login credentials (password, username) - Used only for authentication
  • Payment card information - Processed by PCI-compliant payment processors, not stored on our servers

Our Use of Sensitive Information

We ONLY use sensitive personal information for the purposes of providing the services you requested:

  • Account authentication and security
  • Processing payments and preventing fraud
  • Customer support related to your account or orders

We do NOT use sensitive personal information for any secondary purpose. Therefore, there is no additional use to limit.

Your sensitive information is used only as necessary and is never sold or shared for cross-context behavioral advertising.
9

Non-Discrimination

CCPA § 1798.125

We will not discriminate against you for exercising any of your CCPA/CPRA rights. This means we will not:

Deny you goods or services
Charge different prices or rates
Provide a different level or quality of services
Suggest you may receive different price or quality

We may, however, offer financial incentives permitted by the CCPA that are reasonably related to the value of your data. We do not currently offer any such incentive programs.

10

Categories of Personal Information Collected (Past 12 Months)

In the preceding 12 months, we have collected the following categories of personal information from California consumers:

Category Collected? Sources Business Purpose Retention
A. Identifiers
Name, alias, address, email, IP, account name
YES Directly from you; automatically Service delivery, account management, analytics, security Account + 2 yrs
B. Customer Records (Cal. Civ. Code § 1798.80(e))
Phone, payment, signature, physical characteristics
YES Directly from you Order fulfillment, customer service 7 years
C. Protected Classification Characteristics
Age, race, gender, etc.
NO N/A N/A N/A
D. Commercial Information
Purchase history, product interests
YES Directly from you; derived from purchases Recommendations, analytics, improvement 5 years
E. Biometric Information
Physiological, biological characteristics
NO N/A N/A N/A
F. Internet/Network Activity
Browsing history, interactions with Site
YES Automatically via cookies, tracking technologies Analytics, optimization, security 26 months
G. Geolocation Data
IP-based location
YES Automatically Analytics, fraud prevention, regional compliance 30 days
H. Sensory Data
Audio, electronic, visual, thermal, olfactory
NO N/A N/A N/A
I. Professional/Employment Information
Occupation, employer
NO N/A N/A N/A
J. Education Information
Non-public education records
NO N/A N/A N/A
K. Inferences
Pet health profile, supplement preferences
YES Derived from assessment and purchase data Personalized recommendations 3 years
L. Sensitive Personal Information
Login credentials, payment card
YES Directly from you Authentication, payment processing As needed
11

Categories Disclosed for Business Purposes

In the preceding 12 months, we have disclosed the following categories of personal information for a business purpose to the categories of third parties indicated:

Identifiers

Disclosed to: Payment processors, shipping carriers, email service providers, analytics providers

Customer Records

Disclosed to: Payment processors, shipping carriers, fraud prevention services

Commercial Information

Disclosed to: Analytics providers, email marketing platforms (with consent)

Internet Activity

Disclosed to: Analytics providers (Google Analytics, Microsoft Clarity)

Geolocation Data

Disclosed to: Analytics providers (anonymized)

Inferences

Disclosed to: Not disclosed; used internally only

Sensitive Personal Information

Disclosed to: Payment processors (PCI compliant), fraud detection services

All disclosures are for legitimate business purposes only. We do not sell personal information.
12

Categories Sold or Shared

SOBS Pets Does Not Sell Personal Information

In the preceding 12 months, we have NOT sold any categories of personal information about California consumers. We also do not "share" personal information for cross-context behavioral advertising as defined under California law.

Categories of personal information SOLD in past 12 months: NONE

Categories of personal information SHARED in past 12 months: NONE

Categories of third parties to whom information was sold: N/A

Categories of third parties to whom information was shared: N/A

Note on "Sharing": Some analytics providers may be considered "sharing" under the CPRA. We use Google Analytics and Microsoft Clarity with IP anonymization enabled. These providers act as our service providers and are contractually prohibited from using your information for their own purposes.

13

Data Retention Practices

We retain personal information for as long as necessary to fulfill the purposes for which it was collected, as described in this policy, or as required by applicable law.

Data Category Retention Period Basis for Retention
Account Information Duration of account + 2 years Service provision, legal obligations
Order History 7 years Tax, warranty, legal requirements
Payment Information Not stored; processed by payment processors PCI DSS compliance
Health Assessment Data 3 years from submission Service improvement, customer support
Marketing Preferences Until consent withdrawn + 30 days Consent management
Website Analytics 26 months (aggregated/anonymized thereafter) Analytics, optimization
Customer Support Communications 3 years Quality assurance, dispute resolution
14

Sensitive Personal Information

Under the CPRA, "sensitive personal information" includes certain categories that require heightened protection. Our practices regarding sensitive information are as follows:

Social Security, Driver's License, State ID

Collected: NO

Financial Account, Debit/Credit Card Number

Collected: YES - with passcode or security code

Purpose: Payment processing only

Disclosed: To PCI-compliant payment processors

Retention: Not stored on our servers

Account Log-in, Password, Credentials

Collected: YES

Purpose: Authentication, account security

Disclosed: Not disclosed (hashed/salted)

Retention: Until account deletion

Precise Geolocation

Collected: NO

Note: We collect IP-based location only (city/region level), not precise GPS coordinates.

Mail, Email, Text Messages Contents

Collected: NO - not directed at children

Note: We do not read the contents of your private communications.

Genetic Data

Collected: NO

15

Minor Data (Under 16)

We do not knowingly collect or sell personal information of minors under 16.

Our services are intended for pet owners who are at least 18 years old. If you are under 18, you may only use our services with the involvement of a parent or legal guardian.

Opt-In Requirements for Minors

If we were to sell personal information of minors under 16 (which we do not), we would be required to obtain affirmative authorization (opt-in) for:

  • Consumers under 13 - from a parent or guardian
  • Consumers 13-16 - from the consumer themselves

If you believe we have inadvertently collected information from a minor under 16: Please contact us immediately at privacy@sobspets.com and we will promptly delete the information.

16

Submitting a CCPA/CPRA Request

You may submit a verifiable consumer request through any of the following designated methods:

Email

ccpa@sobspets.com

Include "CCPA Request" in subject line

Mail

SOBS Pets Privacy Office
Attn: CCPA Requests
123 Pet Wellness Way
San Francisco, CA 94105

Information We May Request

To verify your identity, we may request:

  • Your full name and email address associated with your account
  • Recent order number or transaction details
  • Proof of California residency
  • Signed declaration under penalty of perjury (for specific pieces requests)
Mail Submission Instructions:

When submitting a request by mail, please include your full name, email address associated with your account (if applicable), a detailed description of your request, and any supporting documentation that will assist us in verifying your identity. We recommend sending via certified mail with return receipt requested.

17

Authorized Agents

You may designate an authorized agent to make a request on your behalf. An authorized agent may be:

  • A natural person registered with the California Secretary of State
  • A business entity registered with the California Secretary of State

Requirements for Authorized Agents

1
Signed permission

Provide a signed written authorization from you designating the agent to act on your behalf.

2
Identity verification

The agent must verify their own identity with us.

3
Consumer verification

We may require you to verify your identity directly with us or confirm you authorized the agent.

If the agent has power of attorney pursuant to California Probate Code §§ 4000-4465, only proof of power of attorney is required.

Authorized agents should submit requests via mail or email using the contact methods above, including proof of authorization.

18

Identity Verification Process

To protect your privacy and security, we must verify your identity before fulfilling your request. Our verification process depends on the type of request and the sensitivity of the information.

Level 1

Categories of Information

Request: Right to Know (categories only), Right to Delete, Right to Correct

Verification: Email address + at least 2 data points matching our records

Level 2

Specific Pieces of Information

Request: Right to Know (specific pieces)

Verification: Email address + recent order number + signed declaration under penalty of perjury

Level 3

Account-Only Requests

Request: Any request from existing account holder

Verification: Successful login to account + email confirmation

If we cannot verify your identity, we may deny your request. We will notify you of the reason for denial.
19

Response Timeline & Process

1

Request Received

We confirm receipt within 10 business days

2

Verification

We verify your identity

3

Substantive Response

Within 45 days of receipt

4

Possible Extension

Up to 45 additional days with notice

Response Format

We will respond in the format you requested (mail or electronic delivery). If we cannot comply with your request, we will explain the reasons and provide appeal instructions.

Fee Policy

We provide one free request per 12-month period. If requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or refuse to act on the request.

20

Appeal Process

If we deny your request, you have the right to appeal our decision.

Submit Appeal

Within 30 days of receiving our denial, submit an appeal to appeals@sobspets.com or via mail to our Privacy Office. Include your original request information and the reason you believe the denial was in error.

Appeal Review

We will engage a different reviewer who was not involved in the original decision. We will respond within 45 days of receiving your appeal.

Final Determination

We will provide a written explanation of our appeal decision. If your appeal is denied, you may contact the California Attorney General's Office.

California Attorney General: oag.ca.gov/privacy

21

CCPA/CPRA Request Metrics

As required by the CPRA, we report annually on the consumer requests we received and processed.

Reporting Period: Calendar Year 2025

Right to Know
24
Received
Right to Delete
18
Received
Right to Correct
7
Received
Right to Opt-Out
3
Received
Complied in Full
43
Requests
Denied
5
Requests
Average Response Time
18
Days
Appeals Received
2
Upheld: 1

We are committed to continuous improvement in our privacy practices and request handling.

22

Contact Information

For all CCPA/CPRA-related inquiries, please use the following designated contact methods:

Email ccpa@sobspets.com Include "CCPA Request" in subject line
Privacy Officer privacy@sobspets.com For general privacy inquiries
Response Commitment: We acknowledge receipt of all CCPA requests within 10 business days and provide substantive responses within 45 calendar days.
Mail Submission Reminder:

When submitting requests by mail, please include your full name, contact information, a clear description of your request, and any information that will help us verify your identity. We recommend using certified mail with return receipt requested.

CCPA/CPRA Compliance Verified

SOBS Pets is committed to protecting the privacy rights of California residents. This policy was prepared with reference to the California Consumer Privacy Act of 2018 and the California Privacy Rights Act of 2020.

Welcome to the S.O.B.S. Family!

Thank you for subscribing. Please check your email to verify your subscription and access exclusive content.

exit();