Zurich NA Privacy Policy
Updated October 2021
For more information about Zurich Privacy Policies, visit:
Zurich NA Privacy Policy: https://www.zurichna.com/services/privacy-policy
Zurich NA “Do Not Sell My Personal Information request: https://www.zurichna.com/services/donotsell
Zurich Data Subject Request: https://zurich.my.salesforce-sites.com/data_subject_requests?company=zna
All ZURICH NA’s Privacy Policies listed above are incorporated herein by reference.
Caramel Privacy Policy
Updated December 06,2023
We understand the value of privacy. When you use the Caramel mobile application ("App") and our websites,products, or services (collectively, the "Services"), you trust us with your information. We want to assure you that we respect your privacy and the confidential nature of the information that we gather during our relationship with you.
This Privacy Policy is meant tohelp you understand what data we collect, why we collect it, and what we do with it. Please take a fewminutes to read this Privacy Policy carefully so you may understand our practices toward your personal information andthe measures we take to protect your personalinformation. By using ourServices, you agree to the practicesdescribed in this PrivacyPolicy.
Please carefully review this Privacy Policyprior to consenting to our collection and use of your information, includingbut not limited to your Biometric Information. Please note that once consenthas been provided for collecting and processing your private Information aspart of your verification, it may not be revoked where it is required tocomplete the transaction for which it was collected or to complete theverification Services.
What Information We Collect.
Personal Information. "Personal information" is defined as any information that you may provide to us that can be used to identify you individually, including, but not limited to, contact information, home address, fax numbers, driver's license number, state identification card number, bank account number, credit card or debit card number, passport number, alien registration number, as well as any company account number that we assign to you.
Biometric Information. Biometric Information is a form of Personal Information related to biometric characteristics which may be used to identify you. As used by Caramel, Biometric information is gathered from a digital photo and/or video uploaded by you from a digital phone or computer camera. Examples include photos or digitally uploaded video of you performing various facial movements (e.g., Mouth closed/mouth open, looking right, looking left) facial geometry recognition, and iris or retina recognition. As used in this policy, Biometric Information includes any “biometric identifiers”, or “biometric information” as defined under applicable law. Caramel will not sell, rent, or trade your Biometric Information. Your Biometric Information will only be used by Caramel to verify your identity for the purposes of completing the purchase/sales/finance transaction being facilitated by us with your express permission, or as required for the prevention of fraud. Caramel will publish your likeness in the Caramel App and made available to the selling and buyer parties. Caramel will transfer your Biometric Information third-party partners including state DMV’s where required for electronic title and registration purposes or lenders to which you are applying for financing for the transaction, or when required by a subpoena, warrant, or other court ordered legal action. Additionally, by consenting to the collection and use of your Biometric Information you acknowledge that you have been provided with, and agree to be bound by, The Caramel Terms of Use <<active link>>.
What Biometric Information Do We Collect?The information we collect will vary depending on the specific type of Services you request. Many Caramel Services do not require Biometric Information, however certain Services, such as State Department of Motor Vehicles, or Third-Party lenders, may require a higher level of assurance for your identity verification. When you sign up for an applicable Caramel Service, we may collect the following Biometric Information:
- Facial Biometrics: Our Service may require you to upload an image of your government issued or other identification document(s) as well as your photographic image or "selfie" photograph using your mobile or other device. We use these images to create a facial geometry or faceprint which we use for purposes of identity verification and to prevent the creation of multiple accounts in a fraudulent manner.
We use your Biometric Information only as follows:
- To verify your identity when you are opening an account or using our Services; and
- To authenticate use of your account and the Services for a transaction; and
- To prevent fraudulent uses of Caramel Services or the creation of multiple accounts; and
- To comply with legal obligations or comply with a request from law enforcement or government entities where not prohibited by law.
Do We Share or Disclose Your Biometric Information?
Caramel will only share your Biometric Information with our partners in the following circumstances:
- As required with other third parties where permitted by law to enforce our Terms of Service, to comply with legal obligations, or to cooperate with law enforcement agencies concerning conduct or activity that we reasonably believe may violate federal, state, or local law when required by a subpoena, warrant, or other court ordered legal action, and to prevent harm, loss or injury to others.
- To third party service providers that perform functions on our behalf. These service providers are limited to using the Biometric Information to assist in our provision of Services and must maintain any Biometric Information we share in a secure fashion.
Do We Sell Your Biometric Information?
Caramel will not sell, rent, or trade your Biometric Information. Your Biometric Information will only be used by Caramel to verify your identity for the purposes of completing the purchase/sales/finance transaction being facilitated by us with your express permission, or as required for the prevention of fraud. In fulfilling our Services to you, Caramel will transfer your Biometric Information third-party partners including state DMV’s where required for electronic title and registration purposes or lenders to which you are applying for financing for the transaction, or when required by a subpoena, warrant, or other court ordered legal action.
How Long Does Caramel Retain My Biometric Information?
Caramel may retain your Biometric Information as required by state and federal document retention laws. Biometric Information is retained in line with Caramel’s obligations to state or federal regulatory agencies, our partners with the specific retention periods determined by such government or third-party partner with whom identity verification is requested (e.g., a state motor vehicle title and registration agency, etc.) Certain partners may require this information to be purged within twenty-four (24) hours following a successful verification, other partners may require a longer retention period, but under no circumstances will Caramel retain this information for longer than seven (7) years absent a subpoena, warrant, or other legally compelling justification.
For Caramel users who are residents of Illinois, in accordance with Illinois state law Caramel will retain Biometric Information only until the occurrence of the first of the following:(a) The initial purpose for collecting or obtaining such Biometric Information has been satisfied; or (b) Three (3) years following your last interaction with Caramel.
Can I Request that Caramel Delete My Biometric Information?
Yes, you may direct Caramel to delete your Biometric Information if you cancel a purchase/sale transaction prior to completion. After completion of a purchase/sale transaction, Caramel will only delete your Biometric Information if permitted by state or federal law, if retention is not required by a third-party partner document retention policy, or absent a subpoena, warrant, or other legally compelling justification to retain your information. Deletion of the selfie image and associated Biometric Information may take up to ten (10) business days. Caramel reserves the right to retain this information as needed to comply with our legal obligations, including warrants, subpoenas, or other court orders, or to help prevent fraud.
Pursuant to the California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act of 2020, residents of California are entitled to additional rights and disclosures regarding their Personal information, including Biometric Information. Please refer to the additional California disclosure set forth in this Privacy Policy for additional information.
Can I refuse to provide My Biometric Information?
- Yes, you may refuse to consent for the collection of your Biometric Information. Please note that if you refuse to consent to the collection and processing of your Biometric Information then we may not be able to verify you at the required level of assurance for use of all our Services.
- Alternate pathways to verification may be available. Caramel provides an alternate pathway for individuals to verify their identity. Instead of providing consent for the collection and use of your Biometric Information, you may be presented with the option to manually enter your state-issued Driver’s License information and to provide other indemnifying documentation that verifies your identity.
What Kind of Storage and Security Do You Use With My Biometric Information?
- We are committed to protecting your information. We have adopted technical, administrative, and physical security procedures to help protect your information from loss, misuse, unauthorized access, and alteration. Please note that no data transmission or storage can be guaranteed to be 100% secure.
- We employ appropriate security safeguards. To safeguard certain sensitive information (such as Biometric Information and government-issued identification information), we implement security measures such as encryption, firewalls, and intrusion detection and prevention systems.
Nonpersonal Information. You can use certain Services to obtain certain information without revealing any personally identifiable information. During these types of visits, we may collect, analyze, or share such information on an anonymized basis. We use this information to generate statistics and measure the activity of our Services to improve the usefulness of the Services and the customer experience.
How We Collect Information.
Information You Provide: When you use our services, we may collect personal information that you provide via the mobile app, website, forms, applications, surveys, and other online fields during your usage of the Services. We also collect information from third parties. This information may include, but is not limited to, your name, postal or email address, Social Security number, mobile telephone number(s), username, and password.
Information We Collect Passively: We may passively collect information such browser type, ISP, referring/exit pages, operating system, access date/time stamp, and clickstream data. We use this information to improve the usability of our Services.
We and third parties may use cookies, clear gifs, and other technologies to help us gather statistical information that does not include personally identifiable information to improve your experience with our Services, save your preferences, and to serve you better ads. Cookies are pieces of information that a website or mobile device application transfers to an individual's devices or drives to track application and user activity. Most web browsers automatically accept cookies and session IDs, but you may be able to disable cookies by making the appropriate selection from your browser options. Note that by doing so, the functionality we can provide may be limited.
Additionally, we use data analytics tools like Google Analytics and other third-party technologies to understand how users interact with our advertisements and Services. For more information, you can visit www.google.com/policies/privacy/partners/ ("How Google Uses Information from Sites Or Apps That Use Our Services"). You may opt out of receiving certain advertising tailored to you from third parties. If you would like to opt out of behavioral advertising or to learn more, please visit: http://www.aboutads.info/choices/ or https://policies.google.com/technologies/ads or http://optout.networkadvertising.org/?c=1#!%2F . Options you select are browser and device specific.
We adhere to the Digital Advertising Alliance’s ("DAA") Self-Regulatory Principles. We may partner with third-party companies that collect web viewing data from our Services as well as from other non-affiliated websites and mobile apps over time in order to infer your interests and to deliver more relevant advertising to your browser or device, as well as browsers and devices associated with you. This type of advertising is known as interest-based advertising. To learn more about this type of advertising for your browser, and your choices about it for companies that participate in the Digital Advertising Alliance’s ("DAA") Web Choices tool, you can visit www.aboutads.info/choices . To learn about your choices about this activity on your mobile device for companies that participate in the DAA’s App Choices you can download the appropriate version of the app from www.youradchoices.com/appchoices . When you exercise choice through these tools, data will no longer be collected from that browser or device for interest-based advertising, and data collected from associated browsers or devices will not be used on the browser or device for interest-based advertising on the browser or device where choice was exercised.
How We Use Your Information.
We use this information to:
- Process your request for Services, products or information and verify your identity;
- Improve the quality of our Services and develop new ones;
- Improve security by protecting against fraud and abuse;
- Allow you to access Services and accounts, and to service your account;
- Communicate with you about the Services and your accounts;
- Provide you with personalized offers;
- Provide technical support to the Services;
- Comply with applicable legal requirements and protect our legal rights and the legal rights of our users and other third parties;
- Conduct analytics and measurement to understand how our Services are used;
- Engage in other legitimate business activities as permitted by law; and
- Comply with your requests and to carry out any specific purposes for which we have obtained your consent.
How We Share Your Information.
We may share your information with our service providers, affiliates, and other third parties for the reasons specified above and in accordance with the Privacy Policy.
We may share your information with third parties to provide the Services you have requested. This may include companies that assist us in processing transactions, preparing, and mailing statements, performing title and registration services, performing marketing services for us, or financial service providers. For example, we use third-party service provider Plaid Technologies, Inc. ("Plaid") to authenticate and gather your data from your banks or financial institutions. Plaid enables our App to connect with your bank accounts. By using our Services, you authorize us and Plaid to act on your behalf to access and transmit your personal and financial information from your banks or financial institutions. You agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with Plaid's privacy policy found at: https://plaid.com/legal.
We may also share your personal information in the event of a potential or actual merger, asset sale, financing, corporate divestiture, reorganization, or acquisition involving our business, including any transfer made as part of insolvency or bankruptcy proceedings. We may share information about you with our affiliates (i.e., other companies in the Caramel family) and with nonaffiliates for analysis, market research and marketing purposes as allowed by law. We may also disclose information about you as required or permitted by law, such as to comply with a subpoena, respond to inquiries from government authorities, or defend legal actions. Finally, we may disclose your personal information as otherwise permitted or required by law.
Security.
To protect the confidentiality and security of your personal information transmitted to us, we maintain appropriate administrative, technical, and physical safeguards that comply with applicable federal standards. We restrict access to the personal information obtained from our website to only those employees, agents, and contractors who need it to do their jobs. If you choose to complete and submit a credit application to us, or to access your account through our App, your personally identifiable information will be transmitted via an encryption process. We also require our service providers with whom we contract to protect customer information, and to use the information they collect or receive for the sole purpose of providing the services they provide for us. Please note, however, that no data transmission over the Internet or other network can be guaranteed to be 100% secure. It is your responsibility to keep your username and password confidential and safe. We will retain your information as needed for the purposes of servicing your relationships with us, if any, and for internal analysis in compliance with applicable laws and regulations.
Third-Party Links.
The App and our Services may include links to third-party sites or social media applications like Twitter, Snapchat, Instagram, or Facebook. Because these features are hosted by third parties, when you leave our environment, your interactions with these third-party apps, sites, or features are governed by the privacy policy and practices of the respective company and not this Privacy Policy.
Your Rights and Choices.
If you obtain Services through us, we will use and share financial information we collect from or about you in accordance with our Privacy Notice, found here. California residents can view the California-specific opt-out notice here. These notices supplement this Privacy Policy by offering you certain choices with respect to the use and sharing of your financial personal information.
In addition, you may call us at (800) 976-8305 or email us at privacy@drivecaramel.com to learn how to access or delete your personal information and exercise certain other data rights you may have with regard to your personal information. At this time, our Services do not respond to do-not-track signals.
Changes to this Policy.
As permitted by law, we may change, modify, or adjust our Privacy Policy as needed. Any revisions will be posted in a timely manner. Your continued use of the Services following the effective date of any posted revisions constitutes your consent to any changes to this Privacy Policy.
Notice to California Residents – Your California Privacy Rights.
This notice is intended for all individuals residing in the state of California who access Caramel’s website(s), apps, or any other products or services, or otherwise interact with Caramel in a manner involving the collection of Personal Information. This notice is part of Caramel’s Privacy Policy, but is limited in application to only those individuals residing in California. It explains some additional rights and details that were introduced by the California Consumer Privacy Act of 2018 (the “CCPA”) and the California Privacy Rights Act of 2020 (the “CPRA”). California law may provide you with additional rights regarding our use of your identifying information and other types of personal information. To learn more about your California privacy rights, see the following portions of this privacy policy.
California’s “Shine the Light” law (Civil Code Section § 1798.83) permits users of our Website that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email to support@drivecaramel.com.