California Privacy Disclosure

Your privacy is important to us. This California Consumer Privacy Act of 2018 (“CCPA”) Disclosure (“Disclosure”) is provided by Pumpkin Insurance Services Inc. (together with its affiliates, “we,” “our” or “us”). Our insurance programs are underwritten by United States Fire Insurance Company and administered by Pumpkin Insurance Services Inc. This Disclosure explains how we collect, use, and disclose personal information relating to California residents that are subject to the CCPA (“CA Users”).

What is Personal Information

Under the CCPA, “Personal Information” is information that identifies, relates to, or could reasonably be linked with a particular CA User. The CCPA, however, does not apply to certain information, such as information subject to certain federal and state privacy laws, such as the Gramm-Leach-Bliley Act (“GLBA”).As a result, this Disclosure does not apply with respect to certain information that we collect about CA Users who request or obtain our financial products and services for personal, family or household purposes. For more information about how we collect, disclose, and secure information in these and other contexts, please refer to https://www.pumpkin.care/privacy-center/consumer-privacy-notice.

Our Collection, Use, Sale and Sharing and Disclosure of Personal Information

We collect Personal Information relating to CA Users in a variety of contexts. The specific personal information that we collect, use, disclose, sell or share depends upon our relationship or interaction with that individual.

The following chart details which categories of personal information we collect and process as well as which categories of personal information we disclose to third parties for our operational business purposes within the 12 months preceding the date this Disclosure was last updated. The chart also details the categories of personal information that we “sell” or “share” for purposes of cross context behavioral advertising within the 12 months preceding the date this Disclosure was last updated.

Category of Personal Information Disclosed to Which Categories of Third Parties for Operational Business Purposes Shared with Which Categories of Third Parties for Cross- Context Behavioral Advertising Sold to Which Categories of Third Parties

Personal Identifiers:

Name, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, telephone number, or other similar identifiers

• Third-party service
Providers
• Your veterinary care
providers
• Insurance plan underwriter / carrier
• Our affiliates

• Ad
networks/third-
party advertisers

• Ad
networks/third-
party advertisers
• Analytics
platforms

Customer and Other Records:

Name, signature, postal
address, telephone number, insurance policy number, bank account number, credit card number and
debit card number

• Third-party service
providers
•  Your veterinary care
providers
•  Insurance plan
underwriter / carrier
• Our affiliates

None

None

Protected Classifications:

Gender/gender identity and age

• Third-party service
providers

None

None

Commercial Information:
Purchasing activity, records of products or services considered, purchased or owned

• Third-party service
providers
• Your veterinary care
providers
• Insurance plan
underwriter / carrier

None

None

Usage Data:
Browsing history, browser type, time spent browsing, interactions with websites

• Third-party service providers

• Ad networks/third-party advertisers

• Ad networks/third-party advertisers
• Analytics platforms

Geolocation data:
Approximate location based on IP address

• Third-party service
providers

• Ad networks/third-party advertisers

• Ad networks/third-party advertisers
• Analytics platforms

Audio/Visual Information:
Electronic photographs or videos

• Third-party service
providers

None

None

Professional or Employment-related information:
Employment status and role

• Third-party service providers

None

None

Education Information:
Education history and level

• Third-party service providers

None

None

Sources of Personal Information

We collect this Personal Information directly from you and from the following types of sources:
publicly available databases, internet service providers, social media platforms, third-party data brokers and aggregators, data analytics providers, service providers and affiliates.

Purposes for the Collection, Use, Disclosure, Sale and Sharing of Personal Information

The purposes for which we use, disclose, sell or share personal information t depends on our relationship with a specific CA User. We use, disclose, sell and share personal information to:

    • Operate, grow, manage and maintain our business;
    • Manage relationships with service providers;
    • Provide products and services; and
    • Accomplish other business purposes.

More specifically, we use and disclose personal information to develop, and market our products and services or other pet-health related products or services; operate our services; conduct research and data analysis; maintain our facilities and infrastructure, protect health and safety; operate and manage IT and communications systems; facilitate communications; conduct risk and security control and monitoring; detect and prevent fraud; perform identity verification; perform accounting, audit, and other internal functions, such as internal investigations; comply with law, legal process, and internal policies; evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of our assets; maintain records; and exercise and defend legal claims. We also sell and share personal information for purposes of advertising and marketing pet-health related products and services.

Purposes for the Collection, Use and Disclosure of Sensitive Personal Information

We collect, use, and disclose Sensitive Personal Information only for purposes permitted under the CCPA, including, without limitation, performing services for our business, providing goods or services as requested by you, ensuring the security and integrity of our business, short term transient use such as displaying first party, non personalized advertising, order processing and fulfillment, servicing accounts, providing customer service, verifying customer information, processing transactions, and activities relating to quality and safety control or product improvement.

Retention Period

We retain personal information including, without limitation, sensitive personal information for as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with this disclosure and applicable law. The criteria used to determine our retention periods include:

    • The length of time we have an ongoing relationship with you and provide services to you (for example, for as long as you have an account with us or keep using our services), and the length of time thereafter during which we may have a legitimate need to reference your personal information to address issues that may arise;
    • Whether there is a legal obligation to which we are subject (for example, certain laws may require us to keep records of certain transactions for a certain period of time); and
    • Whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation or regulatory investigations).

Individual Rights

You may, subject to applicable law, make the following requests.

1. You may request that we disclose to you the following information:

a. The categories of personal information we collected about you and the categories of sources from which we collected such personal information;
b. The categories of personal information about you that we “shared” for purposes of cross-context behavioral advertising as defined under the CCPA and the categories of third parties with whom we “shared” such personal information;
c. The business or commercial purpose for collecting, sharing personal information about you;
d. The categories of personal information about you that we otherwise disclosed, and the categories of third parties to whom we disclosed such personal information; and
e. The specific pieces of your personal information, including a copy of the personal
information you provided to us in a portable format.

2. You may request to correct inaccuracies in your personal information.
3. You may request to have your personal information deleted.
4. You may request to opt out of any future “sharing” of your personal information for purposes of cross-context behavioral advertising.
5. You may request to opt-out of the future “sale” of your personal information.

To make a request for disclosures, correction or deletion, please contact us by:

    • Emailing us at: [email protected];
    • Sending us mail to: 432 Park Ave South, 12th floor, New York NY 10016;
    • Calling the Pumpkin U.S. Privacy Toll-free Number: 866-273-6369

We will verify and respond to your request consistent with applicable law, taking into account the type and sensitivity of the personal information subject to the request. We may need to request additional personal information from you, such as your email address or account number in order to verify your identity and protect against fraudulent requests. If you make a request to delete, we may ask you to confirm your request before we delete your personal information. We may decline to honor your request, in full or part, for certain reasons, such as a legal exemption. For example, if the information you are requesting is subject to certain
federal privacy laws, like the GLBA that are outside the scope of the CCPA, we may decline to honor your request.

You may request to opt-out of any future sale and/or sharing of your personal information by clicking on the “Do Not Sell or Share My Personal Information” link. We do not knowingly sell or share the personal information, including the Sensitive Personal Information, of minors under 16 years of age.

Information would adversely affect the rights and freedoms of another consumer.

We process opt-out preference signals, such as the Global Privacy Control, as required by the CCPA. These signals set the opt-out of sale and sharing preferences for the particular browser or device you are using. For information about how to use the Global Privacy Control, please visit https://globalprivacycontrol.org/.

You have the right to be free from unlawful discrimination for exercising your rights under the CCPA.

Requests by Authorized Agents

If an agent would like to make a request on your behalf as permitted by applicable law, the agent may use the submission methods noted in the section entitled “Individual Requests.” As part of our verification process, we may request that the agent provide, as applicable, proof concerning their status as an authorized agent. In addition, we may require that you verify your identity as described in the section entitled “Individual Requests” or confirm that you provided the agent permission to submit the request.

De-identified Information

Where we maintain or use de-identified information, we will continue to maintain and use the de-identified information only in a de-identified fashion and will not attempt to re-identify the information.

Updates to this Disclosure

We may change or update this Disclosure from time to time. When we do, we will post the revised Disclosure on this page with a new “Last Updated” date.

Contact Us

If you have any questions regarding this Disclosure or our privacy policies and practices, please do not hesitate to contact us by either:

    • Emailing us at: [email protected];
    • Sending us mail to: 432 Park Ave South, 12th floor, New York NY;
    • Calling the Pumpkin U.S. Privacy Toll-free Number: 866-273-6369

You may also refer to our Privacy Center: https://www.pumpkin.care/privacy-center

Last Updated: January 2023