Privacy Policy
PRIVACY POLICY
We understand the value of privacy. When you use the Caramel mobile application ("App") and our Websites, products, or services (collectively, the "Services"), you trust us with your information. We want to assure you that we respect your privacy and the confidential nature of the information that we gather during our relationship with you.
This Privacy Policy is meant to help you understand what data we collect, why we collect it, and what we do with it. Please take a few minutes to read this Privacy Policy carefully so you may understand our practices toward your personal information is used and the measures we take to protect your personal information. By using our Services, you agree to the practices described in this Privacy Policy.
Please carefully review this Privacy Policy prior to consenting to our collection and use of your information, including but not limited to your Biometric Information. Please note that once consent has been provided for the collection and processing of your private Information as part of your verification it may not be revoked where it is required to complete the transaction for which it was collected, or to complete the verification Services.
What Information We Collect.
Personal Information. "Personal information" is defined as any information that you may provide to us that can be used to identify you individually, including, but not limited to, contact information, home address, fax numbers, driver's license number, state identification card number, bank account number, credit card or debit card number, passport number, alien registration number, as well as any company account number that we assign to you.
Biometric Information. Biometric Information is a form of Personal Information related to biometric characteristics which may be used to identify you. As used by Caramel, Biometric information is gathered from a digital photo and/or video uploaded by you from a digital phone or computer camera. Examples include photos or digitally uploaded video of you performing various facial movements (e.g., Mouth closed/mouth open, looking right, looking left) facial geometry recognition, and iris or retina recognition. As used in this policy, Biometric Information includes any “biometric identifiers”, or “biometric information” as defined under applicable law. Caramel will not sell, rent, or trade your Biometric Information. Your Biometric Information will only be used by Caramel to verify your identity for the purposes of completing the purchase/sales/finance transaction being facilitated by us with your express permission, or as required for the prevention of fraud. Caramel will publish your likeness in the Caramel App and made available to the selling and buyer parties. Caramel will transfer your Biometric Information third-party partners including state DMV’s where required for electronic title and registration purposes or lenders to which you are applying for financing for the transaction, or when required by a subpoena, warrant, or other court ordered legal action. Additionally, by consenting to the collection and use of your Biometric Information you acknowledge that you have been provided with, and agree to be bound by, The Caramel Terms of Use <
What Biometric Information Do We Collect? The information we collect will vary depending on the specific type of Services you request. Many Caramel Services do not require Biometric Information, however certain Services, such as State Department of Motor Vehicles, or Third-Party lenders, may require a higher level of assurance for your identity verification. When you sign up for an applicable Caramel Service, we may collect the following Biometric Information:
Facial Biometrics: Our Service may require you to upload an image of your government issued or other identification document(s) as well as your photographic image or "selfie" photograph using your mobile or other device. We use these images to create a facial geometry or faceprint which we use for purposes of identity verification and to prevent the creation of multiple accounts in a fraudulent manner.
How Do We Use Your Biometric Information?
We use your Biometric Information only as follows:
To verify your identity when you are opening an account or using our Services; and
To authenticate use of your account and the Services for a transaction; and
To prevent fraudulent uses of Caramel Services or the creation of multiple accounts; and
To comply with legal obligations or comply with a request from law enforcement or government entities where not prohibited by law.
Do We Share or Disclose Your Biometric Information?
Caramel will only share your Biometric Information with our partners in the following circumstances:
As required with other third parties where permitted by law to enforce our Terms of Service, to comply with legal obligations, or to cooperate with law enforcement agencies concerning conduct or activity that we reasonably believe may violate federal, state, or local law when required by a subpoena, warrant, or other court ordered legal action, and to prevent harm, loss or injury to others.
To third party service providers that perform functions on our behalf. These service providers are limited to using the Biometric Information to assist in our provision of Services and must maintain any Biometric Information we share in a secure fashion.
Do We Sell Your Biometric Information?
Caramel will not sell, rent, or trade your Biometric Information. Your Biometric Information will only be used by Caramel to verify your identity for the purposes of completing the purchase/sales/finance transaction being facilitated by us with your express permission, or as required for the prevention of fraud. In fulfilling our Services to you, Caramel will transfer your Biometric Information third-party partners including state DMV’s where required for electronic title and registration purposes or lenders to which you are applying for financing for the transaction, or when required by a subpoena, warrant, or other court ordered legal action.
How Long Does Caramel Retain My Biometric Information?
Caramel may retain your Biometric Information as required by state and federal document retention laws. Biometric Information is retained in line with Caramel’s obligations to state or federal regulatory agencies, our partners with the specific retention periods determined by such government or third-party partner with whom identity verification is requested (e.g., a state motor vehicle title and registration agency, etc.) Certain partners may require this information to be purged within twenty-four (24) hours following a successful verification, other partners may require a longer retention period, but under no circumstances will Caramel retain this information for longer than seven (7) years absent a subpoena, warrant, or other legally compelling justification.
For Caramel users who are residents of Illinois, in accordance with Illinois state law Caramel will retain Biometric Information only until the occurrence of the first of the following:(a) The initial purpose for collecting or obtaining such Biometric Information has been satisfied; or (b) Three (3) years following your last interaction with Caramel.
Can I Request that Caramel Delete My Biometric Information?
Yes, you may direct Caramel to delete your Biometric Information if you cancel a purchase/sale transaction prior to completion. After completion of a purchase/sale transaction, Caramel will only delete your Biometric Information if permitted by state or federal law, if retention is not required by a third-party partner document retention policy, or absent a subpoena, warrant, or other legally compelling justification to retain your information. Deletion of the selfie image and associated Biometric Information may take up to ten (10) business days. Caramel reserves the right to retain this information as needed to comply with our legal obligations, including warrants, subpoenas, or other court orders, or to help prevent fraud.
Pursuant to the California Consumer Privacy Act of 2018 (CPRA), residents of California are entitled to additional rights and disclosures regarding their Personal information, including Biometric Information. Please refer to the additional California disclosure set forth in this Privacy Policy for additional information.
Can I refuse to provide My Biometric Information?
Yes, you may refuse to consent for the collection of your Biometric Information. Please note that if you refuse to consent to the collection and processing of your Biometric Information then we may not be able to verify you at the required level of assurance for use of all of our Services.
Alternate pathways to verification may be available. Caramel provides an alternate pathway for individuals to verify their identity. Instead of providing consent for the collection and use of your Biometric Information, you may be presented with the option to manually enter your state-issued Driver’s License information and to provide other indemnifying documentation that verifies your identity.
What Kind of Storage and Security Do You Use With My Biometric Information?
We are committed to protecting your information. We have adopted technical, administrative, and physical security procedures to help protect your information from loss, misuse, unauthorized access, and alteration. Please note that no data transmission or storage can be guaranteed to be 100% secure.
We employ appropriate security safeguards. To safeguard certain sensitive information (such as Biometric Information and government-issued identification information), we implement security measures such as encryption, firewalls, and intrusion detection and prevention systems.
Nonpersonal Information. You can use certain Services to obtain certain information without revealing any personally identifiable information. During these types of visits, we may collect, analyze, or share such information on an anonymized basis. We use this information to generate statistics and measure the activity of our Services in order to improve the usefulness of the Services and the customer experience.
How We Collect Information.
Information You Provide: When you use our services, we may collect personal information that you provide via the mobile app, website, forms, applications, surveys, and other online fields during your usage of the Services. We also collect information from third parties. This information may include, but is not limited to, your name, postal or email address, Social Security number, mobile telephone number(s), username, and password.
Information We Collect Passively: We may passively collect information such browser type, ISP, referring/exit pages, operating system, access date/time stamp, and clickstream data. We use this information to improve the usability of our Services.
We and third parties may use cookies, clear gifs, and other technologies to help us gather statistical information that does not include personally identifiable information to improve your experience with our Services, save your preferences, and to serve you better ads. Cookies are pieces of information that a website or mobile device application transfers to an individual's devices or drives to track application and user activity. Most web browsers automatically accept cookies and session IDs, but you may be able to disable cookies by making the appropriate selection from your browser options. Note that by doing so, the functionality we can provide may be limited.
Additionally, we use data analytics tools like Google Analytics and other third-party technologies to understand how users interact with our advertisements and Services. For more information, you can visit www.google.com/policies/privacy/partners/ ("How Google Uses Information From Sites Or Apps That Use Our Services"). You may opt out of receiving certain advertising tailored to you from third parties. If you would like to opt out of behavioral advertising or to learn more, please visit: http://www.aboutads.info/choices/ or https://policies.google.com/technologies/ads or http://optout.networkadvertising.org/?c=1#!%2F . Options you select are browser and device specific.
We adhere to the Digital Advertising Alliance’s ("DAA") Self-Regulatory Principles. We may partner with third-party companies that collect web viewing data from our Services as well as from other non-affiliated websites and mobile apps over time in order to infer your interests and to deliver more relevant advertising to your browser or device, as well as browsers and devices associated with you. This type of advertising is known as interest-based advertising. To learn more about this type of advertising for your browser, and your choices about it for companies that participate in the Digital Advertising Alliance’s ("DAA") Web Choices tool, you can visit www.aboutads.info/choices . To learn about your choices about this activity on your mobile device for companies that participate in the DAA’s App Choices you can download the appropriate version of the app from www.youradchoices.com/appchoices . When you exercise choice through these tools, data will no longer be collected from that browser or device for interest-based advertising, and data collected from associated browsers or devices will not be used on the browser or device for interest-based advertising on the browser or device where choice was exercised.
How We Use Your Information.
We use this information to:
Process your request for Services, products or information and verify your identity;
Improve the quality of our Services and develop new ones;
Improve security by protecting against fraud and abuse;
Allow you to access Services and accounts, and to service your account;
Communicate with you about the Services and your accounts;
Provide you with personalized offers;
Provide technical support to the Services;
Comply with applicable legal requirements and protect our legal rights and the legal rights of our users and other third parties;
Conduct analytics and measurement to understand how our Services are used;
Engage in other legitimate business activities as permitted by law; and
Comply with your requests and to carry out any specific purposes for which we have obtained your consent.
How We Share Your Information.
We may share your information with our service providers, affiliates, and other third parties for the reasons specified above and in accordance with the Privacy Policy.
We may share your information with third parties to provide the Services you have requested. This may include companies that assist us in processing transactions, preparing, and mailing statements, performing title and registration services, performing marketing services for us, or financial service providers. For example, we use third-party service provider Plaid Technologies, Inc. ("Plaid") to authenticate and gather your data from your banks or financial institutions. Plaid enables our App to connect with your bank accounts. By using our Services, you authorize us and Plaid to act on your behalf to access and transmit your personal and financial information from your banks or financial institutions. You agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with Plaid's privacy policy found at: https://plaid.com/legal.
We may also share your personal information in the event of a potential or actual merger, asset sale, financing, corporate divestiture, reorganization or acquisition involving our business, including any transfer made as part of insolvency or bankruptcy proceedings. We may share information about you with our affiliates (i.e., other companies in the Caramel family) and with nonaffiliates for analysis, market research and marketing purposes as allowed by law. We may also disclose information about you as required or permitted by law, such as to comply with a subpoena, respond to inquiries from government authorities, or defend legal actions. Finally, we may disclose your personal information as otherwise permitted or required by law.
Security.
To protect the confidentiality and security of your personal information transmitted to us, we maintain appropriate administrative, technical, and physical safeguards that comply with applicable federal standards. We restrict access to the personal information obtained from our website to only those employees, agents, and contractors who need it to do their jobs. If you choose to complete and submit a credit application to us, or to access your account through our App, your personally identifiable information will be transmitted via an encryption process. We also require our service providers with whom we contract to protect customer information, and to use the information they collect or receive for the sole purpose of providing the services they provide for us. Please note, however, that no data transmission over the Internet or other network can be guaranteed to be 100% secure. It is your responsibility to keep your username and password confidential and safe. We will retain your information as needed for the purposes of servicing your relationships with us, if any, and for internal analysis in compliance with applicable laws and regulations.
Third-Party Links.
The App and our Services may include links to third-party sites or social media applications like Twitter, Snapchat, Instagram, or Facebook. Because these features are hosted by third parties, when you leave our environment, your interactions with these third-party apps, sites, or features are governed by the privacy policy and practices of the respective company and not this Privacy Policy.
Your Rights and Choices.
If you obtain Services through us, we will use and share financial information we collect from or about you in accordance with our Privacy Notice, found here. California residents can view the California-specific opt-out notice here. These notices supplement this Privacy Policy by offering you certain choices with respect to the use and sharing of your financial personal information.
In addition, you may call us at (800) 976-8305 or email us at privacy@drivecaramel.com to learn how to access or delete your personal information and exercise certain other data rights you may have with regard to your personal information. At this time, our Services do not respond to do-not-track signals.
Changes to this Policy.
As permitted by law, we may change, modify, or adjust our Privacy Policy as needed. Any revisions will be posted in a timely manner. Your continued use of the Services following the effective date of any posted revisions constitutes your consent to any changes to this Privacy Policy.
Notice to California Residents – Your California Privacy Rights.
This notice is intended for all individuals residing in the state of California who access Caramel’s website(s), apps, or any other products or services, or otherwise interact with Caramel in a manner involving the collection of Personal Information. This notice is part of Caramel’s Privacy Policy, but is limited in application to only those individuals residing in California. It explains some additional rights and details that were introduced by the California Privacy Rights Act of 2020 (the “CPRA”).
PRIVACY NOTICE FOR CALIFORNIA RESIDENTS Effective July 7, 2022
This PRIVACY NOTICE FOR CALIFORNIA RESIDENTS (“CA Privacy Notice”) supplements the information contained in the Privacy Policy of Caramel Inc, Doing business in California as Caramel Holdings. (“we,” “us,” or “our”) and applies solely to visitors, users, and others who reside in the State of California (“California Consumers” or “you”).
I. Information We Collect About Our California Consumers
Types of Information We Collect
To maintain best-in-class standards and technologies, and to provide you with the best possible service, in the past twelve months we may have collected through the course of our business the following types of information:
How We Collect Information
We collect information in a variety of ways, each of which gives us a different opportunity to tailor our services (the “Services”) and provide you with the best experience possible. Our methods include gathering information from you through forms, applications, surveys, and other online fields offered throughout our Services; in email, text, and other electronic messages between you and us; and when you interact with our advertising and applications on third-party websites and services.
Why We Collect Information
We may use the information that we collect from you to:
Provide you with the services or products that we offer; or
Respond to your inquiries, requests, or other service-related purposes; or
Communicate with you to administer the Services, including notifying you about any updates, changes, or additions to the Privacy Policy; or
Enhance your experience with us, such as tailoring content to your preferences or developing new products or services based on your interactions with the Services; or
Send you information about products or services that we think may be of interest to you; or
Carry out any specific purposes for which we have obtained your prior consent; or
Conduct any other legitimate business activities not otherwise prohibited by law.
We may also use your information for business purposes such as:
Auditing related to counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards.
Helping to ensure security and integrity to the extent the use of the consumer’s personal information is reasonably necessary and proportionate for these purposes.
Debugging to identify and repair errors that impair existing intended functionality.
Short-term, transient use, including, but not limited to, non-personalized advertising shown as part of a consumer’s current interaction with the business, provided that the consumer’s personal information is not disclosed to another third party and is not used to build a profile about the consumer or otherwise alter the consumer’s experience outside the current interaction with the business.
Performing services on behalf of the business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of the business.
Providing advertising and marketing services, except for cross-context behavioral advertising, to the consumer provided that, for the purpose of advertising and marketing, a service provider or contractor shall not combine the personal information of opted-out consumers that the service provider or contractor receives from, or on behalf of, the business with personal information that the service provider or contractor receives from, or on behalf of, another person or persons or collects from its own interaction with consumers.
Undertaking internal research for technological development and demonstration.
Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business.
II. Information We Share or Collect About Our California Consumers
We will not sell your personal information such as name, email address, physical address, or phone number unless you give us permission. However, California law defines “sale” broadly in such a way that the term sale may include using targeted advertising on the Services or other affiliated sites. Like most online publishers and social networks, we use these services, which enable us to provide the Services and relevant offers to you, including at your request.
As such, our use of these services may constitute a California-covered “sale” for the following categories of information to advertising partners in the last twelve months: identifiers such as Internet Protocol address, device IDs, cookie IDs, and advertising IDs; demographic information such as age bracket, commercial information such as the types of products or services you are interested in purchasing.
We may share information about you with relevant and appropriate third parties in the following situations:
To our service providers that perform functions on our behalf; or
To protect or enforce our rights or property, to protect your safety or the safety of others, or to investigate, prevent, or take action against fraud or other illegal activities; or
In response to legal process or as otherwise required by law; or
If we go through a business transition or corporate transaction, such as a merger, capital investment, acquisition by another company, or sale of all or a portion of its assets; or
To conduct any other legitimate business activities not otherwise prohibited by law.
Notwithstanding anything else in the Privacy Policy, we may share aggregate or non-personally identifying information about California Consumers with third parties for marketing, advertising, research, or other business purposes.
III. Your Rights as a California Consumer
As a California resident, you have certain rights regarding your personal information.
Opting Out of “Sales”
As discussed above, we will not sell your personal information such as name, email address, physical address, or phone number unless you give us permission. However, like most online publishers and social networks, we use targeted advertising services on the Services or other affiliated sites, which enable us to provide the Services and relevant offers to you, including at your request. We may share (meaning communicating personal information to a third party for cross-context behavioral advertising) the following categories of information to advertising partners: identifiers such as Internet Protocol address, device IDs, cookie IDs, and advertising IDs; demographic information such as age bracket, commercial information such as the types of products or services you are interested in purchasing.
We do not knowingly sell the personal information of consumers under 18 years of age.
You have the right to direct us not to “sell” or “share” your personal information by emailing us at privacy@drivecaramel.com.
Your Access Rights
You have the right to request from us the following information: (1) the categories of personal information we have collected about you; (2) the categories of sources from which your personal information is collected; (3) the business or commercial purpose for collecting, selling, or sharing your personal information; (4) the categories of third parties to whom we disclose personal information; (5) the specific pieces of personal information we have collected about you; (6) the categories of personal information sold or shared about you and the categories of third parties to whom the personal information was sold or shared; and (7) the categories of personal information that the business disclosed about the consumer for a business purpose and the categories of persons to whom it was disclosed for a business purpose.
To the extent that we sold any of your personal information or used any of your personal information for a business person, you have the right to request that we disclose to you: (1) the categories of personal information that we collected about you; (2) the categories of personal information that we sold about you and the categories of third parties to whom the personal information was sold, by category or categories of personal information for each third party to whom the personal information was sold; and (3) the categories of personal information that we disclosed about you for a business purpose.
Please note that the CPRA prohibits us from disclosing to anyone the following information in response to a request to know a consumer’s Social Security number, driver's license number or other government-issued identification number, financial account number, any health insurance or medical identification number, an account password, security questions and answers, or unique biometric data generated from measurements or technical analysis of human characteristics.
You can exercise your right via the Right to Know webform or by emailing privacy@drivecaramel.com.
Your Deletion Request Rights
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
You can exercise your right via the Right to Delete webform or by emailing privacy@drivecaramel.com.
Your Correction Request Rights
You have the right to request that we correct your personal information that we maintain that is inaccurate, taking into account the nature of the personal information and the purposes of the processing of the personal information. Once we receive and confirm your verifiable consumer request, we will use commercially reasonable efforts to correct the inaccurate personal information.
You can exercise your right via the Right to Correct webform or by emailing privacy@drivecaramel.com.
Your Right to Limit the Use and Disclosure of Sensitive Personal Information
You have the right to direct us to limit our use of your sensitive personal information that we have collected to the following, subject to any exceptions provided under the law:
Use which is necessary to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services;
To perform the following services:
Helping to ensure security and integrity to the extent the use of the consumer’s personal information is reasonably necessary and proportionate for these purposes; or
Short-term, transient use, including, but not limited to, non-personalized advertising shown as part of a consumer’s current interaction with us, provided that the consumer’s personal information is not disclosed to another third party and is not used to build a profile about the consumer or otherwise alter the consumer’s experience outside the current interaction with us; or
Performing services on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on our behalf; or
Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by us, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by us; or
As authorized by regulations adopted pursuant to the CPRA.
Sensitive personal information that we collect or processed without the purpose of inferring characteristics about you is not subject to this right to limit.
How to Exercise Your Rights
To exercise any of the rights listed above, please submit a verifiable consumer request to us by submitting the appropriate request form found here. We will only use personal information provided in a consumer request to verify the requestor's identity or authority to make such a request. Please note you may only make a verifiable consumer request for access or data portability twice within a 12-month period.
Please note that Caramel must verify the identity of the requestor by requesting your full name, email address and phone number associated with your account, and account number. You may designate an authorized agent to make a request on your behalf by providing proof of a valid power of attorney, your valid government issued identification, and the authorized agent’s valid government issued identification. We cannot respond to requests where the identity and authority of the requestor cannot be confirmed.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request's receipt. If we are unable to comply with a request, we will inform you of the reason why.
Non-Discrimination Policy
California residents that choose to exercise such rights will not be denied any goods or services, charged different prices or rates, or be provided a different level or quality of goods or services unless those differences are related to your personal information.
Shine the Light Disclosure
You may request and obtain from us once a year, free of charge, information about the personal information (if any) we disclosed to third parties for direct marketing purposes in the preceding calendar year.
Changes to Our Privacy Notice for California Residents
We reserve the right to modify this CA Privacy Notice at any time. If we make changes to this CA Privacy Notice, we will make the modified version available on our Privacy Hub. Your continued use of the Services after any modification to this CA Privacy Notice will constitute your acceptance of such modification.
Contact
If you have any questions about this policy, please contact us in any of the following ways: (1) call us at the following toll-free number: (800) 976-8305, or (2) send us an email at privacy@drivecaramel.com.
PRIVACY NOTICE FOR CONNECTICUT RESIDENTS Effective July 7, 2022
Pursuant to Connecticut General Statutes Sec. Section 42-471, it is the policy of Caramel to protect the privacy of your personal information by doing the following:
Safeguarding any data, computer files and documents containing your personal information from any misuse by third parties; or
Destroying, erasing, or making unreadable any data, computer files and documents containing your personal information prior to their disposal; or
Protecting the confidentiality of your Social Security number and other personal information; or
Prohibiting the unlawful disclosure of your Social Security number and other personal information; or
Limiting and/or restricting the access to your Social Security number and other personal information to other third parties; and
Limiting the access of your Social Security number and other personal information only to our employees who need access to your personal information to allow us to provide legal services to you, limiting the access of these employees to extent that it is needed, and otherwise imposing restrictions and reasonable safeguards on our employees to prevent them from accessing your personal information.
Children's Privacy
Our Services are not directed to individuals under the age of 18 and we do not knowingly collect personal information from individuals under the age of 18. If you believe that we have personal information about a child, please notify us immediately, and we will delete the information quickly as possible
Contact.
If you have any questions, please contact us at privacy@drivecaramel.com.
Last Updated July 7, 2022