Supplement · California
California (CCPA / CPRA) Supplement
Last updated:
1. Applicability & threshold
The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (together, “CCPA”), formally applies to businesses that meet one or more statutory thresholds: (a) annual gross revenue above US $25 million; (b) buying, selling, or sharing the personal information of 100,000 or more consumers or households; or (c) deriving 50% or more of annual revenue from selling or sharing personal information.
We do not currently meet any of these thresholds. Nevertheless, we honour the rights and disclosures in this Supplement voluntarily for California residents because they reflect good privacy practice. The substantive rights below apply to you regardless of whether the statute technically obliges us. If we later cross a threshold, we will publish that fact here, register as required, and continue to honour all of the rights set out below without interruption.
2. Categories of personal information collected
In the past twelve (12) months we have collected the following CCPA-defined categories:
- Identifiers — email address, account ID, IP address, browser fingerprint hash.
- Customer records (Cal. Civ. Code §1798.80(e)) — billing name and address provided to our payment processor.
- Commercial information — subscription plan, analyses purchased.
- Internet or network activity — pages viewed, features used, log data, error reports.
- Geolocation — only the map coordinates you select for analysis; we do not collect device-level GPS.
- Inferences — none drawn from your personal information to create consumer profiles.
We do not collect: biometric information, precise device location, health information, government-issued ID numbers, financial account credentials (our Merchant of Record, Lemon Squeezy, holds these directly), education information, or employment information.
3. Sources, business purposes & retention
Sources: directly from you, from your device when you use the Service, and from our sub-processors (Supabase, Lemon Squeezy, Cloudflare, Upstash, Vercel, Google AI). Business purposes are limited to: providing and securing the Service, processing payments, preventing fraud and abuse, complying with law, and aggregate product analytics. We retain personal information no longer than described in the global Privacy Policy §11 and delete or anonymise it thereafter.
4. No sale or sharing — no GPC obligation
We have not, in the past twelve (12) months, “sold” or “shared” personal information within the meaning of the CCPA (including for purposes of cross-context behavioural advertising). We have no advertising network, no retargeting pixels, and no data-broker arrangements. We therefore do not display a “Do Not Sell or Share My Personal Information” link because there is no sale or sharing to opt out of. We do not honour Global Privacy Control signals for the same reason; if we ever begin to share or sell, we will honour GPC before doing so.
5. Your CCPA / CPRA rights
- Right to know — the categories and specific pieces of personal information we have about you, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to delete — request deletion of personal information we collected from you, subject to statutory exceptions (legal obligations, fraud-prevention, completing a transaction you requested).
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale or sharing — not applicable as we do neither.
- Right to limit use of sensitive PI — see §6.
- Right to non-discrimination — see §8.
- Right to data portability — receive a copy of your personal information in a structured, commonly used, machine-readable format.
6. Sensitive personal information
We do not collect or process “sensitive personal information” as that term is defined by CPRA §1798.140(ae) (e.g., social security number, account credentials, precise geolocation, racial/ethnic origin, religious beliefs, union membership, contents of mail/email/text not addressed to us, genetic data, biometric identifiers, health information, sex life or sexual orientation). The right-to-limit-use mechanism therefore has nothing to constrain. If our processing ever changes, this Supplement will be updated before any such collection begins.
7. How to exercise your rights
Email privacy@poigeo.app with the subject “CCPA request — [know / delete / correct / portability]”. We will:
- Acknowledge receipt within ten (10) business days and confirm how we will process your request.
- Substantively respond within forty-five (45) calendar days, extendable once by an additional forty-five (45) days where reasonably necessary with notice to you.
- Verify your identity using information already associated with your account before disclosing or deleting data.
Authorised agents: you may designate an authorised agent to act on your behalf by providing the agent with signed written permission. We may require you to verify your own identity directly with us before completing a request submitted through an agent.
Appeals: if we decline a request in whole or in part, you may appeal by replying to our decision; the appeal will be reviewed by a different person and you will receive a substantive response within sixty (60) days.
8. Non-discrimination
We will not deny you service, charge you a different price, provide a different level of service, or suggest that we will do any of these things because you exercise a right under the CCPA.
9. Notice of financial incentive
We do not offer any financial incentive, price difference, or service-level difference in exchange for the retention, sale, or sharing of personal information.
10. Updates
We will revise this Supplement to reflect changes in law or in our practices. The “Last updated” date above reflects the most recent revision. Where a change materially reduces your rights, we will provide thirty (30) days' advance notice by email to registered users.