Effective as of November 22, 2024
1. General
National Retail Solutions, Inc. (“NRS”) is committed to protecting the privacy of your personal information.
This Privacy Policy (the “Policy”) sets forth our policies and procedures regarding the collection, use and sharing of your personal information. We also explain the steps we take to protect your information and how you can limit the collection, use and sharing of your information.
This Policy applies to the following unless otherwise noted:
When we use the term “Services” it collectively refers to the NRS Products, the NRS Websites, the NRS Reward Programs, the NRS Apps, and the NRS Web Stores. When we refer to NRS or “us,” or “we,” we’re talking about National Retail Solutions, Inc. and, as applicable, its affiliates, subsidiaries, parents, and other related entities.
You should also read the terms of service for each Service that you use, which can be found at the applicable NRS Website, NRS App or NRS Web Store.
We may update this Policy from time to time and you should review it periodically for changes. Any updated Policy will be posted at the NRS Websites, the NRS Apps and in the NRS Web Stores.
This Policy does not apply to any website, product, or service of any third-party companies, advertisers, partners, or service providers, even if the website links to (or is linked from) NRS Websites. NRS Websites may contain links to other third-party websites not owned, operated, maintained by or related to NRS (“Third-Party Sites”). Any such hyperlinks are to be accessed at the user’s own risk. We are not responsible for the content, privacy practices, data collection, policies, or any other aspect of a Third-Party Site, even if the NRS Websites contain a link to such site. This Policy does not apply to Third Party Sites, and we encourage you to independently read and understand each Third-Party Site’s own privacy policies. The presence of a link to a Third-Party Site does not necessarily indicate that such Third-Party Site is sponsored by or affiliated with NRS in any way.
2. Consent for use of NRS Websites
By accessing or using the NRS Websites, you agree to this Policy and our Terms of Use, which are incorporated by reference into this Policy. If you do not agree with our policies and practices, you may choose not to use our Sites. Your use of the Services, and any dispute over privacy, is subject to this Policy and our Terms of Use, including its applicable limitations on damages and the resolution of disputes.
We or third parties we work with may automatically collect certain information using technologies such as cookies, web beacons, clear GIF, pixels, internet tags, web server logs, and other data collection tools, further described below. By using the NRS Websites, you consent to NRS and third parties obtaining data about your visits to the NRS Websites, including, but not limited, to via technologies like Meta Pixel and Google Analytics.
Depending on where you reside, you may have additional rights, which are described in greater detail in the exhibits below – see infra Exhibits A-H (further describing the rights of California, Colorado, Connecticut, Montana, Oregon, Texas, Utah, and Virginia residents). Also, if you are a California resident, please review our California Rights Notice, which further supplements this Policy and explains additional rights you may have under California law regarding our use of your Personal Information.
3. Information We Collect
We may receive and collect both personal identifying and non-identifying information from you when we operate and provide you with the Services, when you install, access or use the Services and when you communicate with us. Personal information means information either on its own or in conjunction with other data that enables a specific person to be identified (“Personal Information”), but does not include “de-identified,” “anonymous,” or “aggregate” information, which is not otherwise associated with a specific person. Non-identifying information means information that by itself cannot be used to identify a specific person (e.g., zip code).
A. Information You Provide. Depending on the particular Service, you may provide the following Personal Information:
B. Information We Collect. Depending on the particular Service, we may automatically collect the following information:
C. Information Provided by Third Parties. When you install, access or use the Services we may obtain the following information from third party sources:
4. How We Use Information
We may use all the Personal Information we collect or you provide to help us operate, provide, improve, understand, customize, support, and market our Services (and some third party services). In addition, we may use your information for general, operational and administrative purposes, including maintaining your account, authenticating you and contacting you. As used in this Policy, the terms “use,” “using” and “processing” information include using cookies or other similar technologies on a computer/phone/device, subjecting the information to statistical or other analysis and using or handling information in any way, including but not limited to, scanning, collecting, storing, evaluating, aggregating, modifying, deleting, using, combining, disclosing and sharing information among our affiliates both in and outside the United States and to select service providers and vendors.
A. Our Services. We analyze how our customers use our Services and use that information to evaluate and improve our Services, to research, develop, and test new services and features, and to conduct troubleshooting activities. For example:
B. NRS Apps. We engage certain service providers and vendors who use mobile software development kits to passively collect information from users of the NRS Apps. We use this data primarily to help us deliver personalized notifications and to identify you in a unique manner across other devices or browsers for the purposes of customizing advertisements or content.
5. How We Share Information
We may share all the information we collect and receive with our affiliates, both in and outside the United States, and to select service providers and vendors, to help us operate, provide, improve, understand, customize, support, and market our Services (and some third party services), and for general, operational and administrative purposes, including maintaining your account, authenticating you and contacting you. We also share information with each NRS store with which you interact. When we share information with our service providers and vendors, we require them to use your information only in accordance with our instructions and terms or with express permission from you and not to sell your information. In addition, you share your information as you use and communicate through our Services.
A. Information Shared Within the NRS Family of Companies. We may share information within the NRS family of companies, including our affiliates both in and outside the United States (collectively, the “NRS Family of Companies”) primarily to operate, provide, support and market our Services. For example, we may share your information with various NRS affiliates in order to process your transaction.
B. Information Shared with our Service Providers and Vendors. We work with various service providers and vendors for a variety of business purposes such as to help us offer, operate, provide, improve, understand, customize, support and market our Services. We may share information with these service providers and vendors to the extent reasonably necessary for them to perform work on our and your behalf. For example, we may provide your credit card information and billing address to our payment processing company solely for the purpose of processing payment for a transaction you have requested. In addition, NRS shares certain information, including unique marketing identifiers, email addresses and mobile phone numbers (full or only partial), with some of our service providers and vendors, including tobacco companies, Google and Facebook, for marketing, advertising, rewards/loyalty programs and analysis purposes, including the delivery of advertising campaigns and preparing and sharing aggregate business and marketing reports, demographic profiling and to deliver targeted advertising about products and services. All the foregoing categories exclude text messaging originator opt in data and consent; this information will not be shared with any third parties. In addition, no mobile information will be shared with third parties/affiliates for marketing/promotional purposes. When we share information with our service providers and vendors, we request that these parties protect your information and limit their use of the data to the purposes for which it was provided, and not to sell your information. NRS does not sell, rent or lease its customer lists to third parties. NRS does on occasion sell certain pieces of personal information, such as personal identifiers, of some of our stores’ customers to data processors. Finally, if you purchase products or services offered jointly by NRS and one of our service providers or vendors, your customer information may be received by both NRS and the service provider or vendor that is providing the product or service. For these jointly offered products and services, you should also review the other company’s privacy policy, which may include practices that are different from the practices described here.
C. Special Circumstances. We may share information in certain special circumstances. For example:
D. Information Shared with Advertising Entities or Social Networks. You may see third party advertisements on our products and Services, the NRS Websites, the NRS Apps, and/or the NRS Web Stores. Some advertisements are chosen by companies that place advertisements on behalf of advertisers. These companies, often called ad servers, may place and access cookies on your device to collect information about your visit. The information they collect from our sites is in a form that does not identify you personally. This information may be combined with similar data obtained from other websites to help our advertisers better reach their targeted audiences. Targeting may be accomplished by tailoring advertising to interests that they infer from your browsing of our sites and your interaction with other websites where these ad servers also are present. If you choose to interact with specific advertisers who advertise on our products and Services, the NRS Websites, the NRS Apps, or the NRS Web Stores, the information you provide to them is subject to the conditions of their specific privacy policies. The NRS Websites, NRS Apps and NRS Web Stores also include plug-ins and widgets that may provide information to their associated social networks or entities about the NRS page you visit, even if you do not click on or otherwise interact with the plug-in or widget.
E. When You Share Information. You share your information as you use and communicate through our Services. Stores with whom you communicate may store or share your information (including your phone number or messages) with others on and off our Services.
6. Cookies & Other Tracking Technology
Our Services may use “cookies,” web beacons, and other tracking technologies (collectively, “Cookies”) to automatically collect users’ information (including Personal Information). Cookies are small data files that are transferred to users’ web browsers and/or stored on their devices as they are browsing. We may use Cookies to improve our Services and make your user experience online more customized and efficient. Among other uses, Cookies help us recognize repeat users, facilitate users’ access to and use of NRS Websites, and track users’ behavior on websites they visit. We may compile aggregate data for statistical purposes to improve the content of our Sites or to better administer the web pages available on the Sites.
Web beacons are used to tell us how and when pages in our sites are visited, by how many people, their point of origin and operating system and to monitor performance with our Services. Web beacons do not collect Personal Information.
The information collected with these technologies may include (i) your internet protocol (IP) address, unique device identifiers, location, browser type, and internet service provider information; (ii) information about when and how you access and use NRS Websites or Services, such as the domains you visit, what features you used and for how long, the website that referred you to us, and date/time stamps associated with your usage; (iii) information about the device you use to access NRS Websites or services, such as device type, device ID, and device/browser settings; and (iv) location of the device used to access the NRS Websites or services derived from GPS or WiFi use.
Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on your personal computer or mobile device when you go offline, while Session Cookies are deleted as soon as you close your web browser. We differentiate between Cookies that are essential for the technical features of our Sites and optional analytics and advertising Cookies, as follows:
Cookie Type | Description |
Essential Cookies | These are cookies that NRS Websites need to function, and that enable you to move around and use NRS Websites and features. You do not need to enable cookies to visit NRS Websites; however, some aspects of NRS Websites may be difficult or impossible to use if cookies are disabled. Examples of where these cookies are used include: to determine when you are signed in, to determine when your account has been inactive, and for other troubleshooting and security purposes. |
Analytics Cookies | Analytics cookies allow us to understand more about how many visitors we have to NRS Websites, how many times they visit us and how many times a user viewed specific pages within NRS Websites. Although analytics cookies allow us to gather specific information about the sites that you visit and whether you have visited NRS Websites multiple times, we cannot use them to find out details such as your name or address. We use certain Google Analytics Advertising Features, including Remarketing and Demographics and Interest Reporting. Google Analytics is a web analysis service provided by Google that allows us to collect data about the traffic on the NRS Websites through Google cookies and other identifiers, which enables us, among other things, to create user segments based on demographic or interest data and to deliver relevant advertising. Google utilizes the data collected to track and examine the use of our websites and to prepare reports on the activities and share them with other Google services. Google may use the data collected to contextualize and personalize the ads of its own advertising network. You may be able to opt out of the Google Analytics Advertising Features through your browser ads settings or by visiting Google’s Ads Settings page. For more information regarding how Google collects, uses and shares your information, please refer to “How Google Uses Information From Sites or Apps that Use Our Services,” which can be found at www.google.com/policies/privacy/partners/, or any other URL Google may provide from time to time. |
For information on how you can manage Cookies, please see the “Your Rights and How To Limit Sharing Of Information” section below.
7. Your Rights and How To Limit Sharing Of Information
You may have choices about how we use and share your information and there are additional protections that may apply with regard to certain information we collect.
A. Communications. If you do not wish to receive promotional communications from NRS, you can opt out at any time by following the unsubscribe instructions provided in those communications, or by contacting us as provided in the “Contact Us” section below. Please note that NRS may still continue to send you non-promotional emails, such as those regarding your orders, feedback submissions, and other service-related matters.
B. Promotional Emails. You may choose to provide us with your email address for the purpose of allowing us to send free newsletters, surveys, offers, and other promotional materials to you, as well as targeted offers from third parties. You can opt out of receiving promotional emails by following the unsubscribe instructions in emails that you receive. If you decide not to receive promotional emails, we may still send you service-related communications.
C. Promotional Mailings. If at any time you do not want to receive offers and/or circulars from us by mail, you can remove yourself from our mailing lists by emailing us (our contact information is below) with “NO SNAIL MAIL” in the subject line along with your name, address, and zip code. Please note that our mailings are prepared in advance of their being sent. Although we will remove your name from our mailing list after receiving your request, you may still receive mailings from us that had been initiated prior to your name being removed.
D. Promotional Text Messages. You can opt-out of receiving marketing text messages at any time by replying “STOP,” or following the unsubscribe instructions contained in the text messages that you receive.
E. Cookies. Web browser applications (such as Microsoft Internet Explorer, Google Chrome, Firefox and Apple Safari) typically have features that prevent cookies from being sent or notify you when they are sent. You will need to update your browser’s cookie settings in accordance with your preferences. Your ability to limit cookies is subject to your browser settings and limitations. If you use multiple browsers on your device, you will need to update each browser’s settings separately. Some web browsers incorporate a “Do Not Track” (“DNT”) or similar feature that signals to websites that a user does not want to have his/her online activity and behavior tracked. NRS does not respond to DNT signals or other similar mechanisms. If you are using a mobile device, you can reset your device settings to limit the use of information collected about you, including your location data. This is typically done by disabling your location settings/permissions. Please contact Apple Support or Google for Android (as applicable) for more information on how to do this on your device. You can stop all collection of information via our mobile application by uninstalling the application from your device.
F. Analytics. Google provides users choices on how their data is collected by Google Analytics by developing an Opt-out Browser Add-on which can be located at: http://tools.google.com/dlpage/gaoptout?hl=en. By installing this Add-on, no information is being sent to Google Analytics.
G. Push Notifications. You can opt out of receiving push notifications from us via the NRS Apps by going to your device “Settings” and clicking on “Notifications,” and then changing those settings for the applicable app. Please note that you cannot withdraw your consent to receive certain in app messages from us. Your ability to manage some of our Services could be limited if you withdraw your consent to receive text and SMS messages. In those cases NRS does not recommend using those Services without authorization to receive such messages.
H. Other Rights. In certain jurisdictions, such as California, you may also have the following rights regarding your Personal Information (see Section 8 and the Exhibits to this Policy for full details):
Many of the above rights are subject to exceptions and limitations. For example, you may be located in a jurisdiction that does not give you the right to make these requests. In such a case, your request may not be fulfilled. To the extent permitted by applicable law, we may reject requests that are unreasonably repetitive, unduly burdensome, risk the privacy of others, or would be very impractical to honor. If we are not able to provide the requested information or make the change you requested, you will be provided with the reasons for such decisions.
To exercise these rights, your request must: (i) provide sufficient information that allows us to reasonably verify that you are the person about whom we collected Personal Information or an authorized representative of that person; and (ii) describe the request with sufficient detail that allows us to properly understand, evaluate, and respond to it. We may need additional information to confirm your identity or your authorized agent’s identity (such as your name, email address and date of birth) or to obtain proof that you have given your authorized agent permission to act on your behalf. If our verification process is successful, we will respond to your request within the time and in the manner required by applicable law. If we cannot validate the identity of you and/or your authorized agent or obtain proof that you have given your authorized agent permission to act on your behalf, we will attempt to contact you to inform you.
If you designate an authorized agent to submit requests to exercise certain privacy rights on your behalf, we will require verification that you provided the authorized agent permission to make a request on your behalf. You must provide us with a copy of the signed permission you have given to the authorized agent to submit the request on your behalf and verify your own identity directly with us. If you are an authorized agent submitting a request on behalf of an individual, you must attach a copy of a completed Authorized Agent Designation Form (or equivalent form) indicating that you have authorization to act on the individual’s behalf.
You can submit your request by contacting us at the address described below or filling out the applicable state request form at www.idt.net.
8. Additional State Privacy Rights
If you are a resident of any of the following states, then the additional terms in the applicable Exhibit to this Policy also apply to you:
California – see Exhibit A to this Privacy Policy
Colorado – see Exhibit B to this Privacy Policy
Connecticut – see Exhibit C to this Privacy Policy
Montana – see Exhibit D to this Privacy Policy
Oregon – see Exhibit E to this Privacy Policy
Texas – see Exhibit F to this Privacy Policy
Utah – see Exhibit G to this Privacy Policy
Virginia – see Exhibit H to this Privacy Policy
9. Other Information
A. Keeping Children Safe. NRS does not knowingly market to or collect information from children under the age of 16 without obtaining verifiable parental consent. If you allow a child to use your device or our Services, you should be aware that their information could be collected as described in this Policy. We encourage parents to be involved in the online activities of their children to ensure that no information is collected from a child without parental permission.
B. Security. NRS has technical, organizational and physical safeguards in place to help protect against unauthorized access to, use or disclosure of the information we collect and store. Employees are trained on the importance of protecting privacy and on the proper access to, use and disclosure of customer information. NRS secures information on computer servers in a controlled, secure environment, protected from unauthorized access, use or disclosure. We use Secure Socket Layer (SSL) encrypted protection to protect the personal information transmitted to the NRS Websites and NRS Web Stores. The NRS Websites, NRS Apps and NRS Web Stores are PCI compliant in connection with your credit card information. Although we work hard to protect your information that we collect and store, no program is 100% secure and we cannot guarantee that our safeguards will prevent every unauthorized attempt to access, use or disclose Personal Information. By using the NRS Websites, you accept that risk. NRS maintains security and incident response plans to handle incidents involving unauthorized access to Personal Information we collect or store. In the event that we are required by law to inform you of a breach to your Personal Information we may notify you electronically, in writing, or by telephone, if permitted to do so by law. If you become aware of a security issue, please contact us.
C. Contact Information. If you have questions, concerns or suggestions related to our Policy or our privacy practices you may contact us at:
National Retail Solutions, Inc.
520 Broad Street, 3rd floor
Newark, NJ 07102
800-215-0931
Email: [email protected].
D. Social Networking. Some of our Services may allow you to participate in blog discussions, message boards, chat rooms, and other forms of social networking and to post reviews. Please be aware that these forums are accessible to others. We urge you to not submit any Personal Information to these forums because any information you post can be read, collected, shared, or otherwise used by anyone who accesses the forum. NRS is not responsible for the information you choose to submit in these forums. If you post content to information sharing forums, you are doing so by choice and you are providing consent to the disclosure of this information.
E. Changes to this Policy. We reserve the right to make changes to this Policy, so please check back periodically for changes. You will be able to see that changes have been made by checking to see the effective date posted at the beginning of the Policy.
©2024 National Retail Solutions, Inc. All rights reserved.
Exhibit A
California Consumers
If you are a resident of California, then the following section also applies to you.
A. Personal Information. Personal information (as defined in the California Consumer Privacy Act of 2018 and the California Privacy Rights Act of 2020 (collectively, the “CCPA”)) includes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information does not include publicly available information, including information lawfully made available to the general public by the consumer or from widely distributed media, and deidentified or aggregate consumer information. NRS may collect and use the following categories of personal information regarding California residents:
Categories of Personal Information Collected | Categories of Sources of Personal Information | Whether Sold, Shared(1) and/or Disclosed for a Business Purpose and Categories of to Whom | Business or Commercial Purposes for Collection and Use of Personal Information |
Personal Identifiers and Information, including items listed in subdivision (e) of Section 1798.80 of California Civil Code, which may include name, address, email address, phone number, birthdate, device and marketing identifiers, IP address, payment and financial information, credit/debit card number and details, bank account number and information, personal information necessary to verify you or your account, security code and login credentials, and other personal information you provide | Consumer, consumer’s device, automatic collection by NRS, credit reporting companies, financial companies, third party vendors that provide NRS with transactional services, and data resellers | Sold – yes Categories of Third Parties to whom NRS may sell personal information: data processors Shared – no Disclosed for a Business Purpose – yes Categories of third parties to whom NRS may disclose personal information for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our service providers and vendors to the extent reasonably necessary for them to perform work on our and your behalf (e.g., credit card processors); other NRS stores with which you interact; ad networks; data analytics providers; social networks; law enforcement; prospective purchasers of our business; outside auditors and lawyers; and government entities, agencies and regulators | To manage our products and services, including to help us operate, provide, evaluate, improve, monitor, customize, bill and support our products and services. To maintain the quality of our products and services, including to improve, upgrade, and enhance our products and services. To maintain and service your account, including to process orders and payments. To communicate with you about our terms and policies. To verify you, your account activity and your information. To detect, investigate and report fraud, abuse or illegal use of our products and services or customer accounts. To provide customer service. To perform due diligence, credit and fraud prevention checks. To maintain accurate record keeping. To ensure security and integrity of our customers’ personal information. To perform product, marketing and organizational analysis. To provide advertising and marketing to our customers. To measure our marketing campaigns and to audit consumer interactions. To comply with regulations and legal requirements. To comply with contractual requirements. For risk management and compliance. For legal advice and defense of claims. For general, operational and administrative purposes. |
Commercial information, which may include records of products or services purchased and used, diagnostic and service performance information, credit information from reporting agencies, transactional information, and other purchasing or consuming histories | Consumer, consumer’s device, automatic collection by NRS, credit reporting companies, financial companies, third party vendors that provide NRS with transactional services, and data resellers | Sold – no Shared – no Disclosed for a Business Purpose – yes Categories of third parties to whom NRS may disclose personal information for a business purpose: see list under Personal Identifiers and Information | |
Internet or other electronic network activity information, which may include browsing history, search history, messages, personal, phone or social network contact information, device information, device contacts, and information regarding a consumer’s interaction and usage with our websites, apps, web stores and advertisements | Consumer, consumer’s device, automatic collection by NRS, credit reporting companies, financial companies, third party vendors that provide NRS with transactional services, and data resellers | Sold – no Shared – no Disclosed for a Business Purpose – yes Categories of third parties to whom NRS may disclose personal information for a business purpose: see list under Personal Identifiers and Information | |
Geolocation data (if you enable location features in apps), which may include the location of y our device | Consumer, consumer’s device, and automatic collection by NRS | Sold – no Shared – no Disclosed for a Business Purpose – yes Categories of third parties to whom NRS may disclose personal information for a business purpose: see list under Personal Identifiers and Information | |
Inferences drawn from any of the information above, which may include profile reflecting the consumer’s purchasing and marketing preferences, aggregate information from third parties | Consumer, consumer’s device, automatic collection by NRS, credit reporting companies, financial companies, third party vendors that provide NRS with transactional services, and data resellers | Sold – no Shared – no Disclosed for a Business Purpose – yes Categories of third parties to whom NRS may disclose personal information for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our vendors and partners to the extent reasonably necessary for them to perform work on our and your behalf (e.g., credit card processors); ad networks; data analytics providers; social networks; and prospective purchasers of our business |
(1) Share and Shared (as defined in the CCPA) mean sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration.
B. Sensitive Personal Information. NRS may collect limited sensitive personal information and limits the use of that information to those uses which are necessary for us to perform the services and provide the goods consumers have requested and for other uses as authorized by applicable California privacy laws and regulations. NRS may collect the following sensitive personal information:
Categories of Sensitive Personal Information Collected | Whether Sold or Shared(1) | Business or Commercial Purposes for Collection and Use of Sensitive Personal Information |
Account information, which may include account log-in, financial account, debit card or credit card number in combination with any required security or access code, password, or credentials allowing access to an account | Sold – no Shared – no | To perform the services and provide the goods requested by the consumer, including to help us operate, provide, customize, bill and support our products and services. To verify consumer’s age. To ensure the security and integrity of our customers’ personal information, including to prevent, detect, and investigate security incidents that compromise the availability, authenticity, integrity, and confidentiality of stored or transmitted personal information. For short‐term, transient use, including but not limited to non‐personalized advertising shown as part of a consumer’s current interaction with NRS. To perform services on our behalf, including to maintain or service accounts, provide customer service, process or fulfill orders and transactions, verify customer information, process payments, provide financing, provide analytic services, provide storage, or provide similar services on behalf of our business. To maintain the quality and safety of our products and services, including to improve, upgrade, and enhance our products and services. To resist malicious, deceptive, fraudulent, or illegal actions directed at our business and to prosecute those responsible for those actions. To ensure the physical safety of natural persons. |
Personal Identifiers, which may include social security, driver’s license, state identification card, or passport number | Sold – no Shared – no | |
Precise geolocation (if you enable location features in our apps), which may include the location of your device | Sold – no Shared – no |
(1) Share and Shared (as defined in the CCPA) mean sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration.
C. Your Rights. As a California resident you have certain additional rights regarding your personal information under the CCPA.
(i) Right to Know Personal Information Collected, Sold, Shared, or Disclosed – you have the right to request that we provide certain information about how we have handled your personal information including:
(a) Categories of personal information collected;
(b) Categories of sources of personal information;
(c) Business or commercial purpose for collecting;
(d) Categories of personal information sold or shared with a third party;
(e) Categories of third parties to whom we have sold or shared personal information;
(f) Categories of personal information disclosed to third parties for a business purpose; and
(g) Categories of third parties with whom we have disclosed personal information for a business purpose.
(ii) Right to Access Personal Information Collected – you have the right to request the specific pieces of personal information that we have collected about you in a format that is easily understandable to the average consumer, and to the extent technically feasible, in a structured, commonly used, machine-readable format that may also be transmitted to another entity at the consumer’s request without hindrance.
(iii) Right of No Retaliation – NRS does not discriminate against any California consumer who exercises any of the consumer’s rights under the CCPA. Pursuant to the CCPA NRS is permitted to (a) charge a consumer a different price or rate and/or provide a different level of service to the consumer if that difference is reasonably related to the value provided to the consumer by the consumer’s data, (b) offer loyalty, rewards, premium features, discounts, or club card programs to its customers, and (c) offer financial incentives, including payments, as compensation for the collection, sale, sharing or retention of personal information.
(iv) Right to Delete – you have the right to request that NRS delete any personal information that it has collected about you. There are exceptions to this right and NRS does not have to delete your personal information if it is reasonably necessary to complete a transaction with you, to provide you with goods or services you requested, to comply with our legal obligations, and as otherwise provided in the CCPA. In addition, if your personal information is deleted you may not be able to purchase or use our products and services.
(v) Right to Correct Inaccurate Personal Information – you have the right to request that NRS correct any inaccurate personal information that it maintains about you.
(vi) Right to Opt Out of Sale or Sharing of Personal Information – NRS may sell (as defined in the CCPA) certain pieces of your personal information. NRS does not share (as defined in the CCPA) your personal information. You have the right to request that NRS not sell or share your personal information to third parties. To exercise this right please go to https://www.idt.net/ccpa-do-not-sell and complete the form. We will also process any opt-out of sale/sharing preference signal that meets the requirements set forth in the CCPA and its regulations. NRS does not intentionally collect the personal information of a consumer under the age of 16. NRS does not intentionally sell or share the personal information of a consumer under the age of 16 unless the consumer (if age 13-16) or the consumer’s parent (for consumers under 13) affirmatively authorizes the sale or sharing.
(vii) Right to Limit Use and Disclosure of Sensitive Personal Information – NRS does not use your sensitive personal information (as defined in the CCPA) for purposes other than as set forth in the CCPA. Nonetheless, you have the right to direct NRS to limit its use of your sensitive personal information to that use which is necessary for NRS to perform the services and provide the goods you requested from NRS, to ensure the security and integrity of your personal information, to perform services on our behalf, including to maintain or service accounts, provide customer service, process or fulfill orders and transactions, verify customer information, process payments, provide analytic services, to maintain the quality of our products and services, and as otherwise provided in the CCPA. Please note that sensitive personal information that is collected or processed by NRS without the purpose of inferring characteristics about a consumer, is not subject to this section, and shall be treated as personal information. To exercise this right please go to https://www.idt.net/ccpa-do-not-sell and complete the form.
(viii) California’s “Shine the Light” law (Civil Code Section § 1798.83) permits you to request certain information regarding our disclosure of your personal information to third parties for marketing purposes.
D. How to Exercise Your Rights. To exercise your rights to know and access your personal information collected, sold, shared or disclosed by NRS, or to exercise your right to delete your personal information or to correct inaccurate personal information, please go to https://www.idt.net/ccpa-request and complete the form. To exercise your right to opt out of the sale or sharing of your personal information, or to exercise your right to limit the use and disclosure of your sensitive personal information please go to https://www.idt.net/ccpa-do-not-sell and complete the form. We will also process any opt-out of sale/sharing preference signal that meets the requirements set forth in the CCPA and its regulations. In addition, you can exercise your rights by contacting us at 800-215-0931 or [email protected]. Your authorized agent can make these requests on your behalf using the same links and methods.
E. Verification of Consumer Requests. In order to comply with a consumer request, NRS must reasonably verify the requestor. A record of each request is made as soon as it is received by our data protection team. NRS will use all reasonable measures to verify the identity of the individual making the request. We will utilize the requested data to ensure that we can verify the requestor’s identity and where we are unable to do so, we may contact you for further information, or ask you to provide evidence of your identity prior to responding to your request. This is to protect your data and rights. If a third party, relative or representative is requesting the data on your behalf, we will verify their authority to act for you and may contact you and them to confirm you and their identity and gain your authorization prior to responding to the request.
F. Responding to Consumer Requests. NRS will attempt to confirm receipt of each request by contacting the requestor either at the email or telephone number submitted, through the consumer’s account or by other electronic means. NRS will attempt to verify each request and if it is able to verify a request will provide a response (if necessary and applicable) within 45 days of the receipt of the request, which time period may be extended by NRS for an additional 45 days. If a delay is necessary, NRS will contact the requestor within the original 45 day period and provide the reasons for the delay. NRS may charge a fee or refuse to act on any request that is manifestly unfounded or excessive. All NRS responses shall be in writing and cover the previous 12 month period unless the consumer requests information beyond the 12 month period (only applies to personal information collected on or after January 1, 2022). Where possible the response shall be sent through the consumer’s account. Otherwise, the response shall be sent by mail or electronically. NRS is not obligated to provide a response to a consumer more than two times in any 12 month period. The CCPA contains certain exemptions and exceptions to the exercise of some of these rights. If one or more of those exemptions or exceptions applies to your request, then we may not be able to act upon your request. Where possible we will inform you of the reasons for not acting upon your request.
G. How Long will NRS Retain Your Personal Information. NRS retains your personal information for only as long as is necessary to carry out the purposes described above in this privacy policy, and we have strict review and retention policies in place to meet these obligations. This time period may vary depending on the type of information and the services used, as detailed below, and applicable law, which may require us to maintain information for a set amount of time. After such time, we will either delete or anonymize your information or, if this is not possible (for example, because the information has been stored in backup archives), then we will securely store your information and isolate it from any further use until deletion is possible. We may also retain aggregate information beyond this time for research purposes and to help us develop and improve our services. You cannot be identified from anonymized information retained or used for these purposes.
(i) Customer account information – we store your account information for as long as your account is active and a reasonable period thereafter in case you decide to re-activate your service. We also retain some of your information as necessary to comply with our legal obligations, to resolve disputes, to enforce our agreements, to support business operations, and to continue to develop and improve our services. We are required under certain applicable tax laws to keep your basic personal information (name, address, contact details) for a minimum of six years after which time it will be destroyed unless required to be kept for other purposes.
(ii) Communications usage information – while you are an active customer, we retain the communications usage information generated by your use of our services until the information is no longer necessary to provide our services, and for a reasonable time thereafter as necessary to comply with our legal obligations, to resolve disputes, to enforce our agreements, to support business operations, and to continue to develop and improve our services.
(iii) Marketing information, cookies and web beacons – where you have consented to us using your details for direct marketing, we will keep such data until you notify us otherwise and/or withdraw your consent. We retain information derived from cookies and other tracking technologies for a reasonable period of time from the date such information was created.
(iv) Device information – we collect device-specific information from you. If you do not revoke our access to this information via the privacy settings on your device, we will retain this information for as long as your account is active.
H. For More Info. For more information on your rights and our obligations under the CCPA please send an email to [email protected]. For California residents with a disability please send an email to [email protected] for information on how to access this policy in another format.
Exhibit B
Colorado Consumers
If you are a resident of Colorado, then the following section also applies to you.
A. Personal Data. Personal data (as defined in the Colorado Privacy Act (the “COPA”)) includes any information that is linked or reasonably linkable to an identified or identifiable individual. Personal data does not include de-identified data or publicly available information. NRS may collect and process the following categories of personal data regarding Colorado residents:
Categories of Personal Data Collected or Processed | Whether Sold, Shared with Third Parties, Processed for Targeted Advertising or Processed for Profiling in furtherance of Decisions that Produce Legal or Significant Effects and Categories of to Whom | Purposes for Collection and Processing of Personal Data |
Personal Identifiers and Information, which may include name, address, email address, phone number, birthdate, device and marketing identifiers, IP address, payment and financial information, credit/debit card number and details, bank account number and information, personal information necessary to verify you or your account, security code and login credentials, and other personal information you provide | Sold – yes Categories of Third Parties to whom NRS may sell personal data: data processors Processed for Targeted Advertising – no Processed for Profiling in furtherance of Decisions that Produce Legal or Significant Effects – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our service providers and vendors to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; law enforcement; prospective purchasers of our business; outside auditors and lawyers; and government entities, agencies and regulators | To manage our products and services, including to help us operate, provide, evaluate, improve, monitor, customize, bill and support our products and services. To maintain the quality of our products and services, including to improve, upgrade, and enhance our products and services. To maintain and service your account, including to process orders and payments. To communicate with you about our terms and policies. To verify you, your account activity and your information. To detect, investigate and report fraud, abuse or illegal use of our products and services or customer accounts. To provide customer service. To perform due diligence, credit and fraud prevention checks. To maintain accurate record keeping. To ensure security and integrity of our customers’ personal information. To perform product, marketing and organizational analysis. To provide advertising and marketing to our customers. To measure our marketing campaigns and to audit consumer interactions. To comply with regulations and legal requirements. To comply with contractual requirements. For risk management and compliance. For legal advice and defense of claims. For general, operational and administrative purposes. |
Commercial Information, which may include records of products or services purchased and used, diagnostic and service performance information, credit information from reporting agencies, transactional information, and other purchasing or consuming histories | Sold – no Processed for Targeted Advertising – no Processed for Profiling in furtherance of Decisions that Produce Legal or Significant Effects – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Internet or other Electronic Network Activity Information, which may include browsing history, search history, messages, personal, phone or social network contact information, device information, device contacts, and information regarding a consumer’s interaction and usage with our websites, apps, web stores and advertisements | Sold – no Processed for Targeted Advertising – no Processed for Profiling in furtherance of Decisions that Produce Legal or Significant Effects – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Geolocation Data (if you enable location features in apps), which may include the location of your device | Sold – no Processed for Targeted Advertising – no Processed for Profiling in furtherance of Decisions that Produce Legal or Significant Effects – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Inferences drawn from any of the information above, which may include profile reflecting the consumer’s purchasing and marketing preferences, aggregate information from third parties | Sold – no Processed for Targeted Advertising – no Processed for Profiling in furtherance of Decisions that Produce Legal or Significant Effects – no Shared with Third Parties – yes Categories of third parties to whom NRS may disclose personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our vendors and partners to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; and prospective purchasers of our business |
B. Your Rights. As a Colorado resident you have certain additional rights regarding your personal data under the COPA:
(i) Right to Confirm if a Controller is Processing Your Personal Data and to Access Personal Data – you have the right to request that NRS confirm whether or not it has collected and processed personal data about you and to access the personal data that we have collected about you;
(ii) Right to Correct Inaccurate Personal Data – you have the right to request that NRS correct any inaccurate personal data that we maintain about you;
(iii) Right to Delete – you have the right to request that NRS delete any personal data that it has collected about you. There may be exceptions to this right and NRS does not have to delete your personal data if it is reasonably necessary to complete a transaction with you, to provide you with goods or services you requested, to comply with our legal obligations, and as otherwise provided by Colorado law. In addition, if your personal data is deleted you may not be able to purchase or use our products and services;
(iv) Right to Obtain Copy of Personal Data in Portable Format – you have the right to obtain from NRS a copy of the personal data that we maintain about you in a portable, and to the extent technically feasible a readily usable, format that allows you to transmit the data to another entity without hinderance;
(v) Right to Opt-Out of the Processing of Personal Data for purposes of Targeted Advertising, Sale, or Profiling with Legal Effects – NRS may sell (as defined in the COPA) certain pieces of your personal data. NRS does not process your personal data for Targeted Advertising (as defined in the COPA) or process your personal data for Profiling (as defined in the COPA) for decisions that produce legal or similarly significant effects. You have the right to request that NRS not process your personal data for those purposes. To exercise this right please go to https://www.idt.net/copa-request and complete the form.
C. How to Exercise Your Rights. To exercise any of your rights, please (i) go to https://www.idt.net/copa-request and complete the form, or (ii) send an email to [email protected] detailing your request(s). The COPA applies to individuals who are Colorado residents, but does not apply to individuals acting in a commercial context. An authorized agent may submit an opt-out request on your behalf using the same methods listed in this section.
D. Authentication of Consumer Requests. In order to comply with a consumer request, NRS must reasonably authenticate the request. A record of each request is made as soon as it is received by our data protection team. NRS will use all reasonable measures to authenticate the identity of the individual making the request. We will utilize the requested data to ensure that we can verify the requestor’s identity and where we are unable to do so, we may contact you for further information, or ask you to provide evidence of your identity prior to responding to your request. This is to protect your data and rights. If a third party, agent or representative is submitting an opt-out request on your behalf, we will verify their authority to act for you and may contact you and them to confirm your and their identity and to gain your authorization prior to taking action upon the request.
E. Responding to Consumer Requests. NRS will attempt to authenticate each request and if it is able to authenticate a request it will provide a response (if necessary and applicable) within 45 days of the receipt of the request, which time period may be extended by NRS for an additional 45 days. If a delay is necessary, NRS will contact the requestor within the original 45 day period and provide the reasons for the delay. All NRS responses shall be in writing. The response shall be sent by mail or electronically. If NRS is not able to process your request, we will inform you of that and (where possible) of the reasons for not acting upon your request.
F. Appeal of Refusal to Take Action. If NRS refuses to take action on your request you have the right to appeal that refusal within 30 days of your receipt of NRS’s response by sending an email to [email protected] and requesting an appeal. Within 45 days of NRS’s receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including the reasons for our decision. If your appeal is denied, then you may contact the Colorado Attorney General at https://coag.gov/ or 720-508-6000.
Exhibit C
Connecticut Consumers
If you are a resident of Connecticut, then the following section also applies to you.
A. Personal Data. Personal data (as defined in the Connecticut Privacy Act (the “CTPA”)) includes any information that is linked or reasonably linkable to an identified or identifiable individual. Personal data does not include de-identified data or publicly available information. NRS may collect and process the following categories of personal data regarding Connecticut residents:
Categories of Personal Data Collected or Processed | Whether Sold, Shared with Third Parties, or Processed for Targeted Advertising and Categories of to Whom | Purposes for Collection and Processing of Personal Data |
Personal Identifiers and Information, which may include name, address, email address, phone number, birthdate, device and marketing identifiers, IP address, payment and financial information, credit/debit card number and details, bank account number and information, personal information necessary to verify you or your account, security code and login credentials, and other personal information you provide | Sold – yes Categories of Third Parties to whom NRS may sell personal data: data processors Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our service providers and vendors to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; law enforcement; prospective purchasers of our business; outside auditors and lawyers; and government entities, agencies and regulators | To manage our products and services, including to help us operate, provide, evaluate, improve, monitor, customize, bill and support our products and services. To maintain the quality of our products and services, including to improve, upgrade, and enhance our products and services. To maintain and service your account, including to process orders and payments. To communicate with you about our terms and policies. To verify you, your account activity and your information. To detect, investigate and report fraud, abuse or illegal use of our products and services or customer accounts. To provide customer service. To perform due diligence, credit and fraud prevention checks. To maintain accurate record keeping. To ensure security and integrity of our customers’ personal information. To perform product, marketing and organizational analysis. To provide advertising and marketing to our customers. To measure our marketing campaigns and to audit consumer interactions. To comply with regulations and legal requirements. To comply with contractual requirements. For risk management and compliance. For legal advice and defense of claims. For general, operational and administrative purposes. |
Commercial Information, which may include records of products or services purchased and used, diagnostic and service performance information, credit information from reporting agencies, transactional information, and other purchasing or consuming histories | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Internet or other Electronic Network Activity Information, which may include browsing history, search history, messages, personal, phone or social network contact information, device information, device contacts, and information regarding a consumer’s interaction and usage with our websites, apps, web stores and advertisements | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Geolocation Data (if you enable location features in apps), which may include the location of your device | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Inferences drawn from any of the information above, which may include profile reflecting the consumer’s purchasing and marketing preferences, aggregate information from third parties | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may disclose personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our vendors and partners to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; and prospective purchasers of our business |
B. Sensitive Data. The only sensitive data (as defined in the CTPA) that NRS may collect and process is precise geolocation data (as defined in the CTPA) from our apps primarily for transaction compliance reasons if the user enables the app’s location feature. Users of our apps can enable or disable the app’s location feature in the app. By enabling the location feature, you thereby consent to NRS collecting and processing your precise geolocation data for the purposes identified herein and as outlined in the chart above.
C. Your Rights. As a Connecticut resident you have certain additional rights regarding your personal data under the CTPA:
(i) Right to Confirm if a Controller is Processing Your Personal Data and to Access Personal Data – you have the right to request that NRS confirm whether or not it has collected and processed personal data about you and to access the personal data that we have collected about you;
(ii) Right to Correct Inaccurate Personal Data – you have the right to request that NRS correct any inaccurate personal data that we maintain about you;
(iii) Right to Delete – you have the right to request that NRS delete any personal data that it has collected about you. There may be exceptions to this right and NRS does not have to delete your personal data if it is reasonably necessary to complete a transaction with you, to provide you with goods or services you requested, to comply with our legal obligations, and as otherwise provided by Connecticut law. In addition, if your personal data is deleted you may not be able to purchase or use our products and services;
(iv) Right to Obtain Copy of Personal Data in Portable Format – you have the right to obtain from NRS a copy of the personal data that we maintain about you in a portable, and to the extent technically feasible a readily usable, format that allows you to transmit the data to another entity without hinderance;
(v) Right to Opt-Out of the Processing of Personal Data for purposes of Targeted Advertising, Sale, or Profiling with Legal Effects – NRS may sell (as defined in the CTPA) certain pieces of your personal data. NRS does not process your personal data for Targeted Advertising (as defined in the CTPA) or process your personal data for Profiling (as defined in the CTPA) for decisions that produce legal or similarly significant effects. You have the right to request that NRS not process your personal data for those purposes. To exercise this right please go to https://www.idt.net/ctpa-request and complete the form.
D. How to Exercise Your Rights. To exercise any of your rights, please go to https://www.idt.net/ctpa-request and complete the form. The CTPA applies to individuals who are Connecticut residents, but does not apply to individuals acting in a commercial context. An authorized agent may submit an opt-out request on your behalf using the same method listed in this section.
E. Authentication of Consumer Requests. In order to comply with a consumer request, NRS must reasonably authenticate the request. A record of each request is made as soon as it is received by our data protection team. NRS will use all reasonable measures to authenticate the identity of the individual making the request. We will utilize the requested data to ensure that we can verify the requestor’s identity and where we are unable to do so, we may contact you for further information, or ask you to provide evidence of your identity prior to responding to your request. This is to protect your data and rights. If a third party, agent or representative is submitting an opt-out request on your behalf, we will verify their authority to act for you and may contact you and them to confirm your and their identity and to gain your authorization prior to taking action upon the request.
F. Responding to Consumer Requests. NRS will attempt to authenticate each request and if it is able to authenticate a request it will provide a response (if necessary and applicable) within 45 days of the receipt of the request, which time period may be extended by NRS for an additional 45 days. If a delay is necessary, NRS will contact the requestor within the original 45 day period and provide the reasons for the delay. All NRS responses shall be in writing. The response shall be sent by mail or electronically. If NRS is not able to process your request, we will inform you of that and (where possible) of the reasons for not acting upon your request.
G. Appeal of Refusal to Take Action. If NRS refuses to take action on your request you have the right to appeal that refusal within 30 days of your receipt of NRS’s response by sending an email to [email protected] and requesting an appeal. Within 60 days of NRS’s receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including the reasons for our decision. If your appeal is denied, then you may contact the Connecticut Attorney General by email at [email protected] or by phone at 860-808-5318.
Exhibit D
Montana Consumers
If you are a resident of Montana, then the following section also applies to you.
A. Personal Data. Personal data (as defined in the Montana Consumer Data Privacy Act (the “MCDPA”)) includes any information that is linked or reasonably linkable to an identified or identifiable individual. Personal data does not include de-identified data or publicly available information. NRS may collect and process the following categories of personal data regarding Montana residents:
Categories of Personal Data Collected or Processed | Whether Sold, Shared with Third Parties, or Processed for Targeted Advertising and Categories of to Whom | Purposes for Collection and Processing of Personal Data |
Personal Identifiers and Information, which may include name, address, email address, phone number, birthdate, device and marketing identifiers, IP address, payment and financial information, credit/debit card number and details, bank account number and information, personal information necessary to verify you or your account, security code and login credentials, and other personal information you provide | Sold – yes Categories of Third Parties to whom NRS may sell personal data: data processors Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our service providers and vendors to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; law enforcement; prospective purchasers of our business; outside auditors and lawyers; and government entities, agencies and regulators | To manage our products and services, including to help us operate, provide, evaluate, improve, monitor, customize, bill and support our products and services. To maintain the quality of our products and services, including to improve, upgrade, and enhance our products and services. To maintain and service your account, including to process orders and payments. To communicate with you about our terms and policies. To verify you, your account activity and your information. To detect, investigate and report fraud, abuse or illegal use of our products and services or customer accounts. To provide customer service. To perform due diligence, credit and fraud prevention checks. To maintain accurate record keeping. To ensure security and integrity of our customers’ personal information. To perform product, marketing and organizational analysis. To provide advertising and marketing to our customers. To measure our marketing campaigns and to audit consumer interactions. To comply with regulations and legal requirements. To comply with contractual requirements. For risk management and compliance. For legal advice and defense of claims. For general, operational and administrative purposes. |
Commercial Information, which may include records of products or services purchased and used, diagnostic and service performance information, credit information from reporting agencies, transactional information, and other purchasing or consuming histories | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Internet or other Electronic Network Activity Information, which may include browsing history, search history, messages, personal, phone or social network contact information, device information, device contacts, and information regarding a consumer’s interaction and usage with our websites, apps, web stores and advertisements | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Geolocation Data (if you enable location features in our apps), which may include the location of your device | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Inferences drawn from any of the information above, which may include profile reflecting the consumer’s purchasing and marketing preferences, aggregate information from third parties | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may disclose personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our vendors and partners to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; and prospective purchasers of our business |
B. Sensitive Data. The only sensitive data (as defined in the MCDPA) that NRS may collect and process is precise geolocation data (as defined in the MCDPA) from our apps primarily for transaction compliance reasons if the user enables the app’s location feature. Users of our apps can enable or disable the app’s location feature in the app. By enabling the location feature, you thereby consent to NRS collecting and processing your precise geolocation data for the purposes identified herein and as outlined in the chart above.
C. Your Rights. As a Montana resident you have certain additional rights regarding your personal data under the MCDPA:
(i) Right to Confirm if a Controller is Processing Your Personal Data and to Access Personal Data – you have the right to request that NRS confirm whether or not it has collected and processed personal data about you and to access the personal data that we have collected about you;
(ii) Right to Correct Inaccurate Personal Data – you have the right to request that NRS correct any inaccurate personal data that we maintain about you;
(iii) Right to Delete – you have the right to request that NRS delete any personal data that it has collected about you. There may be exceptions to this right and NRS does not have to delete your personal data if it is reasonably necessary to complete a transaction with you, to provide you with goods or services you requested, to comply with our legal obligations, and as otherwise provided by Montana law. In addition, if your personal data is deleted you may not be able to purchase or use our products and services;
(iv) Right to Obtain Copy of Personal Data in Portable Format – you have the right to obtain from NRS a copy of the personal data that we maintain about you in a portable, and to the extent technically feasible a readily usable, format that allows you to transmit the data to another entity without hinderance; and
(v) Right to Opt-Out of the Processing of Personal Data for purposes of Targeted Advertising, Sale, or Profiling with Legal Effects – NRS may sell (as defined in the MCDPA) certain pieces of your personal data. NRS does not process your personal data for Targeted Advertising (as defined in the MCDPA) or process your personal data for profiling for decisions that produce legal or similarly significant effects (as defined in the MCDPA). You have the right to request that NRS not process your personal data for those purposes. To exercise this right please go to https://www.idt.net/mtpa-request and complete the form.
D. How to Exercise Your Rights. To exercise any of your rights, please go to https://www.idt.net/mtpa-request and complete the form. The MCDPA applies to individuals who are Montana residents, but does not apply to individuals acting in a commercial context. An authorized agent may submit an opt-out request on your behalf using the same method listed in this section.
E. Authentication of Consumer Requests. In order to comply with a consumer request, NRS must reasonably authenticate the request. A record of each request is made as soon as it is received by our data protection team. NRS will use all reasonable measures to authenticate the identity of the individual making the request. We will utilize the requested data to ensure that we can verify the requestor’s identity and where we are unable to do so, we may contact you for further information, or ask you to provide evidence of your identity prior to responding to your request. This is to protect your data and rights. If a third party, agent or representative is submitting an opt-out request on your behalf, we will verify their authority to act for you and may contact you and them to confirm your and their identity and to gain your authorization prior to taking action upon the request.
F. Responding to Consumer Requests. NRS will attempt to authenticate each request and if it is able to authenticate a request it will provide a response (if necessary and applicable) within 45 days of the receipt of the request, which time period may be extended by NRS for an additional 45 days. If a delay is necessary, NRS will contact the requestor within the original 45 day period and provide the reasons for the delay. All NRS responses shall be in writing. The response shall be sent by mail or electronically. If NRS is not able to process your request, we will inform you of that and (where possible) of the reasons for not acting upon your request.
G. Appeal of Refusal to Take Action. If NRS refuses to take action on your request you have the right to appeal that refusal within 30 days of your receipt of NRS’s response by sending an email to [email protected] and requesting an appeal. Within 60 days of NRS’s receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including the reasons for our decision. If your appeal is denied, then you may contact the Montana Attorney General at https://dojmt.gov/consumer/consumer-complaints/.
Exhibit E
Oregon Consumers
If you are a resident of Oregon, then the following section also applies to you.
A. Personal Data. Personal data (as defined in the Oregon Privacy Act (the “ORPA”)) includes any information that is linked or reasonably linkable to an identified or identifiable individual. Personal data does not include de-identified data or publicly available information. NRS may collect and process the following categories of personal data regarding Oregon residents:
Categories of Personal Data Collected or Processed | Whether Sold, Shared with Third Parties, or Processed for Targeted Advertising or Profiling for Decisions that Produce Legal Effects, and Categories of to Whom | Purposes for Collection and Processing of Personal Data |
Personal Identifiers and Information, which may include name, address, email address, phone number, birthdate, device and marketing identifiers, IP address, payment and financial information, credit/debit card number and details, bank account number and information, personal information necessary to verify you or your account, security code and login credentials, and other personal information you provide | Sold – yes Categories of Third Parties to whom NRS may sell personal data: data processors Processed for Targeted Advertising or Profiling for Decisions that Produce Legal Effects – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our service providers and vendors to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; law enforcement; prospective purchasers of our business; outside auditors and lawyers; and government entities, agencies and regulators | To manage our products and services, including to help us operate, provide, evaluate, improve, monitor, customize, bill and support our products and services. To maintain the quality of our products and services, including to improve, upgrade, and enhance our products and services. To maintain and service your account, including to process orders and payments. To communicate with you about our terms and policies. To verify you, your account activity and your information. To detect, investigate and report fraud, abuse or illegal use of our products and services or customer accounts. To provide customer service. To perform due diligence, credit and fraud prevention checks. To maintain accurate record keeping. To ensure security and integrity of our customers’ personal information. To perform product, marketing and organizational analysis. To provide advertising and marketing to our customers. To measure our marketing campaigns and to audit consumer interactions. To comply with regulations and legal requirements. To comply with contractual requirements. For risk management and compliance. For legal advice and defense of claims. For general, operational and administrative purposes. |
Commercial Information, which may include records of products or services purchased and used, diagnostic and service performance information, credit information from reporting agencies, transactional information, and other purchasing or consuming histories | Sold – no Processed for Targeted Advertising or Profiling for Decisions that Produce Legal Effects – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Internet or other Electronic Network Activity Information, which may include browsing history, search history, messages, personal, phone or social network contact information, device information, device contacts, and information regarding a consumer’s interaction and usage with our websites, apps, web stores and advertisements | Sold – no Processed for Targeted Advertising or Profiling for Decisions that Produce Legal Effects – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Geolocation Data (if you enable location features in apps), which may include the location of your device | Sold – no Processed for Targeted Advertising or Profiling for Decisions that Produce Legal Effects – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Inferences drawn from any of the information above, which may include profile reflecting the consumer’s purchasing and marketing preferences, aggregate information from third parties | Sold – no Processed for Targeted Advertising or Profiling for Decisions that Produce Legal Effects – no Shared with Third Parties – yes Categories of third parties to whom NRS may disclose personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our vendors and partners to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; and prospective purchasers of our business |
B. Sensitive Data. The only sensitive data (as defined in the ORPA) that NRS may collect and process is precise geolocation data (as defined in the ORPA) from our apps primarily for transaction compliance reasons if the user enables the app’s location feature. Users of our apps can enable or disable the app’s location feature in the app. By enabling the location feature, you thereby consent to NRS collecting and processing your precise geolocation data for the purposes identified herein and as outlined in the chart above.
C. Your Rights. As an Oregon resident you have certain additional rights regarding your personal data under the ORPA:
(i) Right to Confirm if a Controller is Processing Your Personal Data and to Access Personal Data – you have the right to request that NRS confirm whether or not it has collected and processed personal data about you and to access the personal data that we have collected about you;
(ii) Right to Correct Inaccurate Personal Data – you have the right to request that NRS correct any inaccurate personal data that we maintain about you;
(iii) Right to Delete – you have the right to request that NRS delete any personal data that it has collected about you. There may be exceptions to this right and NRS does not have to delete your personal data if it is reasonably necessary to complete a transaction with you, to provide you with goods or services you requested, to comply with our legal obligations, and as otherwise provided by Oregon law. In addition, if your personal data is deleted you may not be able to purchase or use our products and services;
(iv) Right to Obtain Copy of Personal Data in Portable Format – you have the right to obtain from NRS a copy of the personal data that we maintain about you in a portable, and to the extent technically feasible a readily usable, format; and
(v) Right to Opt-Out of the Processing of Personal Data for purposes of Targeted Advertising, Sale, or Profiling with Legal Effects – NRS may sell (as defined in the ORPA) certain pieces of your personal data. NRS does not process your personal data for Targeted Advertising (as defined in the ORPA) or process your personal data for profiling for decisions that produce legal or similarly significant effects (as defined in the ORPA). You have the right to request that NRS not process your personal data for those purposes. To exercise this right please go to https://www.idt.net/orpa-request and complete the form.
D. How to Exercise Your Rights. To exercise any of your rights, please go to https://www.idt.net/orpa-request and complete the form. The ORPA applies to individuals who are Oregon residents, but does not apply to individuals acting in a commercial context. An authorized agent may submit an opt-out request on your behalf using the same method listed in this section.
E. Authentication of Consumer Requests. In order to comply with a consumer request, NRS must reasonably authenticate the request. A record of each request is made as soon as it is received by our data protection team. NRS will use all reasonable measures to authenticate the identity of the individual making the request. We will utilize the requested data to ensure that we can verify the requestor’s identity and where we are unable to do so, we may contact you for further information, or ask you to provide evidence of your identity prior to responding to your request. This is to protect your data and rights. If a third party, agent or representative is submitting an opt-out request on your behalf, we will verify their authority to act for you and may contact you and them to confirm your and their identity and to gain your authorization prior to taking action upon the request.
F. Responding to Consumer Requests. NRS will attempt to authenticate each request and if it is able to authenticate a request it will provide a response (if necessary and applicable) within 45 days of the receipt of the request, which time period may be extended by NRS for an additional 45 days. If a delay is necessary, NRS will contact the requestor within the original 45 day period and provide the reasons for the delay. All NRS responses shall be in writing. The response shall be sent by mail or electronically. If NTS is not able to process your request, we will inform you of that and (where possible) of the reasons for not acting upon your request.
G. Appeal of Refusal to Take Action. If NRS refuses to take action on your request you have the right to appeal that refusal within 30 days of your receipt of NRS’s response by sending an email to [email protected] and requesting an appeal. Within 45 days of NRS’s receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including the reasons for our decision. If your appeal is denied, then you may contact the Oregon Attorney General by email at [email protected] or by phone at 877-877-9392.
Exhibit F
Texas Consumers
If you are a resident of Texas, then the following section also applies to you.
A. Personal Data. Personal data (as defined in the Texas Data Privacy and Security Act (the “TDPSA”)) includes any information that is linked or reasonably linkable to an identified or identifiable individual. Personal data does not include de-identified data or publicly available information. NRS may collect and process the following categories of personal data regarding Texas residents:
Categories of Personal Data Collected or Processed | Whether Sold, Shared with Third Parties, or Processed for Targeted Advertising and Categories of to Whom | Purposes for Collection and Processing of Personal Data |
Personal Identifiers and Information, which may include name, address, email address, phone number, birthdate, device and marketing identifiers, IP address, payment and financial information, credit/debit card number and details, bank account number and information, personal information necessary to verify you or your account, security code and login credentials, and other personal information you provide | Sold – yes Categories of Third Parties to whom NRS may sell personal data: data processors Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our service providers and vendors to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; law enforcement; prospective purchasers of our business; outside auditors and lawyers; and government entities, agencies and regulators | To manage our products and services, including to help us operate, provide, evaluate, improve, monitor, customize, bill and support our products and services. To maintain the quality of our products and services, including to improve, upgrade, and enhance our products and services. To maintain and service your account, including to process orders and payments. To communicate with you about our terms and policies. To verify you, your account activity and your information. To detect, investigate and report fraud, abuse or illegal use of our products and services or customer accounts. To provide customer service. To perform due diligence, credit and fraud prevention checks. To maintain accurate record keeping. To ensure security and integrity of our customers’ personal information. To perform product, marketing and organizational analysis. To provide advertising and marketing to our customers. To measure our marketing campaigns and to audit consumer interactions. To comply with regulations and legal requirements. To comply with contractual requirements. For risk management and compliance. For legal advice and defense of claims. For general, operational and administrative purposes. |
Commercial Information, which may include records of products or services purchased and used, diagnostic and service performance information, credit information from reporting agencies, transactional information, and other purchasing or consuming histories | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Internet or other Electronic Network Activity Information, which may include browsing history, search history, messages, personal, phone or social network contact information, device information, device contacts, and information regarding a consumer’s interaction and usage with our websites, apps, web stores and advertisements | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Geolocation Data (if you enable location features in our apps), which may include the location of your device | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Inferences drawn from any of the information above, which may include profile reflecting the consumer’s purchasing and marketing preferences, aggregate information from third parties | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may disclose personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our vendors and partners to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; and prospective purchasers of our business |
B. Sensitive Data. The only sensitive data (as defined in the TDPSA) that NRS may collect and process is precise geolocation data (as defined in the TDPSA) from our apps primarily for transaction compliance reasons if the user enables the app’s location feature. Users of our apps can enable or disable the app’s location feature in the app. By enabling the location feature, you thereby consent to NRS collecting and processing your precise geolocation data for the purposes identified herein and as outlined in the chart above.
C. Your Rights. As a Texas resident you have certain additional rights regarding your personal data under the TDPSA:
(i) Right to Confirm if a Controller is Processing Your Personal Data and to Access Personal Data – you have the right to request that NRS confirm whether or not it has collected and processed personal data about you and to access the personal data that we have collected about you;
(ii) Right to Correct Inaccurate Personal Data – you have the right to request that NRS correct any inaccurate personal data that we maintain about you;
(iii) Right to Delete – you have the right to request that NRS delete any personal data that it has collected about you. There may be exceptions to this right and NRS does not have to delete your personal data if it is reasonably necessary to complete a transaction with you, to provide you with goods or services you requested, to comply with our legal obligations, and as otherwise provided by Texas law. In addition, if your personal data is deleted you may not be able to purchase or use our products and services;
(iv) Right to Obtain Copy of Personal Data in Portable Format – you have the right to obtain from NRS a copy of the personal data that we maintain about you (if available in a digital format) in a portable, and to the extent technically feasible a readily usable, format that allows you to transmit the data to another entity without hinderance; and
(v) Right to Opt-Out of the Processing of Personal Data for purposes of Targeted Advertising, Sale, or Profiling with Legal Effects – NRS may sell (as defined in the TDPSA) certain pieces of your personal data. NRS does not process your personal data for Targeted Advertising (as defined in the TDPSA) or process your personal data for profiling for decisions that produce legal or similarly significant effects (as defined in the TDPSA). You have the right to request that NRS not process your personal data for those purposes. To exercise this right please go to https://www.idt.net/txpa-request and complete the form.
D. How to Exercise Your Rights. To exercise any of your rights, please go to https://www.idt.net/txpa-request and complete the form. The TDPSA applies to individuals who are Texas residents, but does not apply to individuals acting in a commercial context. An authorized agent may submit an opt-out request on your behalf using the same method listed in this section.
E. Authentication of Consumer Requests. In order to comply with a consumer request, NRS must reasonably authenticate the request. A record of each request is made as soon as it is received by our data protection team. NRS will use all reasonable measures to authenticate the identity of the individual making the request. We will utilize the requested data to ensure that we can verify the requestor’s identity and where we are unable to do so, we may contact you for further information, or ask you to provide evidence of your identity prior to responding to your request. This is to protect your data and rights. If a third party, agent or representative is submitting an opt-out request on your behalf, we will verify their authority to act for you and may contact you and them to confirm your and their identity and to gain your authorization prior to taking action upon the request.
F. Responding to Consumer Requests. NRS will attempt to authenticate each request and if it is able to authenticate a request it will provide a response (if necessary and applicable) within 45 days of the receipt of the request, which time period may be extended by NRS for an additional 45 days. If a delay is necessary, NRS will contact the requestor within the original 45 day period and provide the reasons for the delay. All NRS responses shall be in writing. The response shall be sent by mail or electronically. If NRS is not able to process your request, we will inform you of that and (where possible) of the reasons for not acting upon your request.
G. Appeal of Refusal to Take Action. If NRS refuses to take action on your request you have the right to appeal that refusal within 30 days of your receipt of NRS’s response by sending an email to [email protected] and requesting an appeal. Within 60 days of NRS’s receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including the reasons for our decision. If your appeal is denied, then you may contact the Texas Attorney General at https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint.
Exhibit G
Utah Consumers
If you are a resident of Utah, then the following section also applies to you.
A. Personal Data. Personal data (as defined in the Utah Privacy Act (the “UTPA”)) includes any information that is linked or reasonably linkable to an identified or identifiable individual. Personal data does not include de-identified data, aggregated data or publicly available information. NRS may collect and process the following categories of personal data regarding Utah residents:
Categories of Personal Data Collected or Processed | Whether Sold to Third Parties, Shared with Third Parties, and/or Processed for Targeted Advertising and Categories of to Whom | Purposes for Collection and Processing of Personal Data |
Personal Identifiers and Information, which may include name, address, email address, phone number, birthdate, device and marketing identifiers, IP address, payment and financial information, credit/debit card number and details, bank account number and information, personal information necessary to verify you or your account, security code and login credentials, and other personal information you provide | Sold to Third Parties – yes Categories of Third Parties to whom NRS may sell personal data: data processors Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our service providers and vendors to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; law enforcement; prospective purchasers of our business; outside auditors and lawyers; and government entities, agencies and regulators | To manage our products and services, including to help us operate, provide, evaluate, improve, monitor, customize, bill and support our products and services. To maintain the quality of our products and services, including to improve, upgrade, and enhance our products and services. To maintain and service your account, including to process orders and payments. To communicate with you about our terms and policies. To verify you, your account activity and your information. To detect, investigate and report fraud, abuse or illegal use of our products and services or customer accounts. To provide customer service. To perform due diligence, credit and fraud prevention checks. To maintain accurate record keeping. To ensure security and integrity of our customers’ personal information. To perform product, marketing and organizational analysis. To provide advertising and marketing to our customers. To measure our marketing campaigns and to audit consumer interactions. To comply with regulations and legal requirements. To comply with contractual requirements. For risk management and compliance. For legal advice and defense of claims. For general, operational and administrative purposes. |
Commercial Information, which may include records of products or services purchased and used, diagnostic and service performance information, credit information from reporting agencies, transactional information, and other purchasing or consuming histories | Sold to Third Parties – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Internet or other Electronic Network Activity Information, which may include browsing history, search history, messages, personal, phone or social network contact information, device information, device contacts, and information regarding a consumer’s interaction and usage with our websites, apps, web stores and advertisements | Sold to Third Parties – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Geolocation Data (if you enable location features in apps), which may include the location of your device | Sold to Third Parties – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Inferences drawn from any of the information above, which may include profile reflecting the consumer’s purchasing and marketing preferences, aggregate information from third parties | Sold to Third Parties – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may disclose personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our vendors and partners to the extent reasonably necessary for them to perform work on our and your behalf (e.g., payment processors); ad networks; data analytics providers; social networks; and prospective purchasers of our business |
B. Sensitive Data. The only sensitive data (as defined in the UTPA) that NRS may collect and process is specific geolocation data (as defined in the CTPA) from our apps primarily for transaction compliance reasons if the user enables the app’s location feature. Users of our apps can enable or disable an app’s location feature in the app. By enabling the location feature, you thereby consent to NRS collecting and processing your precise geolocation data for the purposes identified herein and as outlined in the chart above.
C. Your Rights. As a Utah resident you have certain additional rights regarding your personal data under the UTPA:
(i) Right to Confirm if a Controller is Processing Your Personal Data and to Access Your Personal Data – you have the right to request that NRS confirm whether or not it has collected and processed personal data about you and to access the personal data that we have collected about you;
(ii) Right to Delete – you have the right to request that NRS delete any personal data that you provided to it. There may be exceptions to this right and NRS does not have to delete your personal data if it is reasonably necessary to complete a transaction with you, to provide you with goods or services you requested, to comply with our legal obligations, and as otherwise provided by Utah law. In addition, if your personal data is deleted you may not be able to purchase or use our products and services;
(iii) Right to Obtain Copy of Personal Data in Portable Format – you have the right to obtain from NRS a copy of the personal data that you previously provided to us in a portable and readily usable format to the extent technically feasible and practicable that allows you to transmit the data to another entity without impediment; and
(iv) Right to Opt-Out of the Processing of Personal Data for purposes of Targeted Advertising and/or Sale – NRS may sell (as defined in the UTPA) certain pieces of your personal data. NRS does not process your personal data for Targeted Advertising (as defined in the UTPA). You have the right to request that NRS not process your personal data for those purposes. To exercise this right please go to https://www.idt.net/utpa-request and complete the form.
D. How to Exercise Your Rights. To exercise any of your rights, please go to https://www.idt.net/utpa-request and complete the form. The UTPA applies to individuals who are Utah residents, but does not apply to individuals acting in a commercial context. An authorized agent may submit an opt-out request on your behalf using the same method listed in this section.
E. Authentication of Consumer Requests. In order to comply with a consumer request, NRS must reasonably authenticate the request. A record of each request is made as soon as it is received by our data protection team. NRS will use all reasonable measures to authenticate the identity of the individual making the request. We will utilize the requested data to ensure that we can verify the requestor’s identity and where we are unable to do so, we may contact you for further information, or ask you to provide evidence of your identity prior to responding to your request. This is to protect your data and rights. If a third party, agent or representative is submitting an opt-out request on your behalf, we will verify their authority to act for you and may contact you and them to confirm your and their identity and to gain your authorization prior to taking action upon the request.
F. Responding to Consumer Requests. NRS will attempt to authenticate each request and if it is able to authenticate a request it will provide a response (if necessary and applicable) within 45 days of the receipt of the request, which time period may be extended by NRS for an additional 45 days. If a delay is necessary, NRS will contact the requestor within the original 45 day period and provide the reasons for the delay. All NRS responses shall be in writing. The response shall be sent by mail or electronically. If NRS is not able to process your request, we will inform you of that and (where possible) of the reasons for not acting upon your request.
Exhibit H
Virginia Consumers
If you are a resident of Virginia, then the following section also applies to you.
A. Personal Data. Personal data (as defined in the Virginia Consumer Data Protection Act (the “VCDPA”)) includes any information that is linked or reasonably linkable to an identified or identifiable natural person. Personal data does not include de-identified data or publicly available information. NRS may collect and process the following categories of personal data regarding Virginia residents:
Categories of Personal Data Collected and Processed | Whether Sold, Shared with Third Parties and/or Processed for Targeted Advertising and Categories of to Whom | Purposes for Collection and Processing of Personal Data |
Personal Identifiers and Information, which may include name, address, email address, phone number, birthdate, device and marketing identifiers, IP address, payment and financial information, credit/debit card number and details, bank account number and information, personal information necessary to verify you or your account, security code and login credentials, and other personal information you provide | Sold – yes Categories of Third Parties to whom NRS may sell personal information: data processors Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our service providers and vendors to the extent reasonably necessary for them to perform work on our and your behalf (e.g., credit card processors); other NRS stores with which you interact; ad networks; data analytics providers; social networks; law enforcement; prospective purchasers of our business; outside auditors and lawyers; and government entities, agencies and regulators | To manage our products and services, including to help us operate, provide, evaluate, improve, monitor, customize, bill and support our products and services. To maintain the quality of our products and services, including to improve, upgrade, and enhance our products and services. To maintain and service your account, including to process orders and payments. To communicate with you about our terms and policies. To verify you, your account activity and your information. To detect, investigate and report fraud, abuse or illegal use of our products and services or customer accounts. To provide customer service. To perform due diligence, credit and fraud prevention checks. To maintain accurate record keeping. To ensure security and integrity of our customers’ personal information. To perform product, marketing and organizational analysis. To provide advertising and marketing to our customers. To measure our marketing campaigns and to audit consumer interactions. To comply with regulations and legal requirements. To comply with contractual requirements. For risk management and compliance. For legal advice and defense of claims. For general, operational and administrative purposes. |
Commercial Information, which may include records of products or services purchased and used, diagnostic and service performance information, credit information from reporting agencies, transactional information, and other purchasing or consuming histories | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Internet or other Electronic Network Activity Information, which may include browsing history, search history, messages, personal, phone or social network contact information, device information, device contacts, and information regarding a consumer’s interaction and usage with our websites, apps, web stores and advertisements | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Geolocation Data (if you enable location features in apps), which may include the location of your device | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may share personal data for a business purpose: see list under Personal Identifiers and Information | |
Inferences drawn from any of the information above, which may include profile reflecting the consumer’s purchasing and marketing preferences, aggregate information from third parties | Sold – no Processed for Targeted Advertising – no Shared with Third Parties – yes Categories of third parties to whom NRS may disclose personal data for a business purpose: NRS family of companies, including our affiliates both in and outside the United States; our vendors and partners to the extent reasonably necessary for them to perform work on our and your behalf (e.g., credit card processors); other NRS stores with which you interact; ad networks; data analytics providers; social networks; and prospective purchasers of our business |
B. Sensitive Data. The only sensitive data (as defined in the VCDPA) that NRS may collect and process is precise geolocation data (as defined in the VCDPA) from our apps primarily for transaction compliance and fulfillment reasons if the user enables the location feature in our apps. Users of our apps can enable or disable an app’s location feature in the app. By enabling the location feature, you thereby consent to NRS collecting and processing your precise geolocation data for the purposes identified herein and as outlined in the chart above.
C. Your Rights. As a Virginia resident you have certain additional rights regarding your personal data under the VCDPA:
(i) Right to Confirm if a Controller is Processing Your Personal Data and to Access Personal Data – you have the right to request that NRS confirm whether or not it has collected and processed personal data about you and to access the personal data that we have collected about you;
(ii) Right to Correct Inaccurate Personal Data – you have the right to request that NRS correct any inaccurate personal data that we maintain about you;
(iii) Right to Delete – you have the right to request that NRS delete any personal data that it has collected about you. There may be exceptions to this right and NRS does not have to delete your personal data if it is reasonably necessary to complete a transaction with you, to provide you with goods or services you requested, to comply with our legal obligations, and as otherwise provided by Virginia law. In addition, if your personal data is deleted you may not be able to purchase or use our products and services;
(iv) Right to Obtain Copy of Personal Data in Portable Format – you have the right to obtain from NRS a copy of the personal data that we maintain about you in a portable, and to the extent technically feasible a readily usable, format that allows you to transmit the data to another entity without hinderance;
(v) Right to Opt-Out of the Processing of Personal Data for purposes of Targeted Advertising, Sale, or Profiling with Legal Effects – NRS may sell (as defined in the VCDPA) certain items of your personal data, but NRS does not process your personal data for Targeted Advertising (as defined in the VCDPA) or process your personal data for Profiling (as defined in the VCDPA) for decisions that produce legal or similarly significant effects. You have the right to request that NRS not process your personal data for those purposes. To exercise this right please go to https://www.idt.net/vcdpa-request and complete the form.
D. How to Exercise Your Rights. To exercise any of your rights, please go to https://www.idt.net/vcdpa-request and complete the form. The VCDPA applies to individuals who are Virginia residents, but does not apply to individuals acting in a commercial context.
E. Authentication of Consumer Requests. In order to comply with a consumer request, NRS must reasonably authenticate the request. A record of each request is made as soon as it is received by our data protection team. NRS will use all reasonable measures to authenticate the identity of the individual making the request. We will utilize the requested data to ensure that we can verify the requestor’s identity and where we are unable to do so, we may contact you for further information, or ask you to provide evidence of your identity prior to responding to your request. This is to protect your data and rights.
F. Responding to Consumer Requests. NRS will attempt to authenticate each request and if it is able to authenticate a request it will provide a response (if necessary and applicable) within 45 days of the receipt of the request, which time period may be extended by NRS for an additional 45 days. If a delay is necessary, NRS will contact the requestor within the original 45 day period and provide the reasons for the delay. All NRS responses shall be in writing. The response shall be sent by mail or electronically. If NRS is not able to process your request, we will inform you of that and (where possible) of the reasons for not acting upon your request.
G. Appeal of Refusal to Take Action. If NRS refuses to take action on your request you have the right to appeal that refusal within 30 days of your receipt of NRS’s response by sending an email to [email protected] and requesting an appeal. Within 60 days of NRS’s receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including the reasons for our decision. If your appeal is denied, then you may contact the Virginia Attorney General at (804)786-2071 to submit a complaint.