Privacy Notice for California Residents

This Privacy Notice for California Residents ("Privacy Notice") supplements the information contained in the Goldfinch Privacy Policy (the "Privacy Policy") made available on the website located at [https://goldfinch.com](the "Site"). The Site is owned and operated by Goldfinch ("Company," "we," "us" or "our"). This Privacy Notice applies solely to residents of the State of California ("CA Consumer"). We adopt this Privacy Notice in compliance with the California Consumer Privacy Act ("CCPA"). Any terms defined in the CCPA have the same meaning when used in this Privacy Notice. CA Consumers with disabilities who wish to access this Privacy Notice in an alternative format can contact us by:


Categories of Information We Collect

We collect "personal information" that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked to a particular CA Consumer or device. In the past 12 months, we have collected the following categories:

  1. Identifiers
    Real name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account name, telephone number, or other similar identifiers.
  2. Personal Information
    Name, signature, Social Security number, physical characteristics or description, postal address, telephone number, passport or driver's license number, insurance policy number, education, employment history, bank or credit card number, medical or health insurance information, and other financial information.
  3. Protected Classification & Demographics
    Age (40+), race, color, ancestry, national origin, citizenship, religion/creed, marital status, medical or mental disability, sex (including gender identity/expression, pregnancy), sexual orientation, veteran/military status, genetic or familial genetic information.
  4. Commercial Information
    Records of personal property, products/services purchased, or other purchasing or consuming histories and tendencies.
  5. Internet or Similar Network Activity
    Browsing history, search history, interaction with a website/application/advertisement.
  6. Inferences from Personal Information
    Profile reflecting preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
  7. Sensitive Personal Information
    Social Security number, driver's license/state ID/passport number, account login credentials, financial account numbers with security codes, precise geolocation, racial/ethnic origin, religious/philosophical beliefs, union membership, contents of mail/emails/texts, genetic data.

Exclusions

Personal information does not include:

  • Publicly available government records
  • Lawfully public consumer or media disclosures without privacy limitations
  • De-identified or aggregated consumer data
  • Information excluded from CCPA/CPRA scope (e.g., HIPAA/CMIA-covered medical data, FCRA/GLBA/FIPA-covered financial data)

Sources of Personal Information


Retention of Personal & Sensitive Information

We retain personal information for the maximum period permitted by law. We may consider:


Use of Personal Information

We may use or disclose your personal information to:

We will not use your information for materially different purposes without notice.


Sharing Personal Information

Subject to your opt-out rights, we may share, rent, or sell your personal information:

We do not knowingly collect or sell the personal information of minors under 18.


Your CCPA Rights & How to Exercise Them

California residents may exercise the following rights. We respond within 15 business days and in no event later than 45 calendar days (or up to 90 days with notice):

  1. Opt-Out of Sale/Sharing
    • Click [here]
    • Call: [insert toll-free number]
    • Email: [insert email]
    • Mail: [insert mailing address]
  2. Limit Use of Sensitive Information
    Request that we only use your Sensitive Personal Information for:
    1. Services you've requested
    2. Security/integrity purposes
    3. Short-term, non-profiled advertising
    4. Performing services on our behalf
    5. Verifying/improving our products/services
  3. Access & Data Portability
    Request a disclosure of:
    • Categories/sources of collected information
    • Business/marketing purposes
    • Third-party recipients
    • Specific pieces of personal information
  4. Correction
    Request correction of inaccurate personal or sensitive information.
  5. Deletion
    Request deletion of personal and/or sensitive personal information, subject to legal exceptions.
  6. Non-Discrimination
    You will not be denied goods/services or charged different prices for exercising your rights.

Verifiable Requests

  • Max two requests per 12 months
  • Provide sufficient info to verify identity or authorized agent status
  • No fee unless request is excessive or repetitive

Authorized Agents

Only you or your registered agent may act on your behalf; we may verify authorization.


Response Timing & Format


Preference Signals

We honor Global Privacy Control (GPC) and other preference signals as valid opt-out requests.


Changes to This Notice

We may amend this Privacy Notice at any time. We'll notify you by email or via a Site notice when changes occur.


Contact Information

For questions or to exercise your rights, contact us by: