Effective Date: January 1, 2020
Information We Collect
We collect and use information that we believe is necessary to administer and promote our business and provide you with the products and services you request from us. This information identifies, relates to, describes, or is capable of being associated with particular individuals (hereinafter "Personal Information"). Within the last twelve (12) months, we have collected the following types of Personal Information from Consumers:
|Personal Information We Collect||Information You Directly Provide to Us or Is Obtained from Third Parties|
|Categories of Personal Information||Personal identifiers - name, postal address, telephone number, and email address|
|Categories of Sources from which Personal Information is Collected||Apparel and Accessory Companies, Data Compiling Companies, Health and Wellness Product and Service Companies, and Publishing Product Companies|
|Categories of Third Parties to Whom Personal Information was Disclosed for Business Purposes||Third Party Service Providers, Consumer Data Resellers, Consumer Data Aggregators, Consumer Data Analytics Providers, Direct Marketers, and Internet Service Providers|
|Categories of Third Parties to Whom Personal Information was Sold||Apparel and Accessory Companies, Automotive Companies, Health and Wellness Product and Service Companies, Data Analytics Providers, Consumer Data Resellers, Not-for-Profit Organizations, Publishing Product Companies, and Insurance Companies|
|Purposes for Collecting Personal Information||Provide the services Consumers request; improve our products, services, and website; create and update Consumer profiles; internal market research and analytics; notify Consumers about promotions and special offers; generate statistical studies; security and safety; protect our rights or property; respond to Consumer inquiries; retain customers and obtain new customers, and rent the Personal Information to third parties for a one-time use only|
Personal Information does not include the following:
- Publicly available information from government records.
- Deidentified or aggregated Consumer information.
- Information excluded from the CCPA's scope, including:
- Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data;
- Personal Information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994.
Use of Personal Information
We may use, disclose, share and/or rent (for one-time use only) Personal Information we collect for one or more of the following business and/or commercial purposes:
- To support and complete the process Consumers start by visiting our Website or responding to our online and offline marketing efforts including, but not limited to, taking and fulfilling product orders, providing customer service, processing payments and returns, and improving our responses in all areas.
- To support, personalize, and develop our Website and online and offline products, and services along with testing, research, and analysis to improve the same.
- To personalize Consumers' Website, online, and offline experiences and to deliver content, products, and services which they may be interested in.
- To retain current Consumers and obtain new Consumers who are interested in our Website, products, and services.
- To help maintain the safety, security, and integrity of Consumers' Personal Information, our Website, products, services, data, databases, software, hardware, and business operations, and to secure Consumers' Personal Information and accounts to prevent transactional fraud.
- To respond to governmental and law enforcement requests as required by applicable law, court order, statutes, rules and/or regulations.
- As described to Consumers when collecting their Personal Information or as otherwise set forth in the CCPA.
Per the California Laws, we will not collect additional categories of Personal Information or use the Personal Information collected for materially different, unrelated, or incompatible purposes from the above without first providing Consumers with notice of said collection.
Sharing Personal Information
We may share Consumers' Personal Information with third party service providers to assist us with a business purpose. When disclosing Personal Information for a business purpose, we intend to obtain an executed acknowledgement and/or certification from them that: (i) describes the business purpose, (ii) requires them to both keep the Personal Information confidential and not use it for any purpose except for performing the terms and conditions of the contract, and (iii) states they are aware of the terms and conditions contained therein. These third party service providers are also obligated to protect the Personal Information per the terms and conditions of the CCPA 2018 and California Laws.
Renting Personal Information
We sometimes rent (for one-time use only) Personal Information to select third party direct marketers whose products or services might be of value to Consumers. Prior to making any of our Consumers' Personal Information available to these third party direct marketers, we intend to obtain an executed acknowledgement and/or certification from them stating that: (i) they are aware of the CCPA and California Laws, (ii) they have read and understand the terms and conditions thereof, and (iii) they are fully compliant with the terms and conditions contained therein.
Consumers' Rights and Choices
Under California Laws and specifically the CCPA, Consumers can exercise three privacy rights regarding their Personal Information:
- Right to Know/Access
- Right to Delete
- Right to "Do Not Sell"/Opt Out
Please note that these Rights are not absolute and are subject to certain exceptions. The following describes Consumers' CCPA rights and explains how they can exercise those rights.
Know/Access Specific Personal Information (Data Portability Rights)
Consumers have the right to request that we disclose certain information about how and why we collect, and then use their Personal Information during the 12-month period immediately preceding the date of the Request. The Information will include:
- The categories of Personal Information we collected about them.
- The categories of sources for the Personal Information we collected about them.
- The specific pieces of Personal Information we collected about them (also called a Data Portability Request).
- Our business or commercial purpose for collecting or selling that Personal Information.
- The categories of third parties with whom we shared or rented (for one-time use only) that Personal Information to.
Only a Consumer, or a person registered with the California Secretary of State that a Consumer authorizes to act on their behalf, may make a Verifiable Consumer Request related to a Consumer's Personal Information. When a Consumer uses an authorized agent to submit a Request to Know/Access or a Request to Delete Form to us, we may require the Consumer to provide the authorized agent with written permission to do so and verify their own identity directly with us. We reserve the right to deny a Request from an agent that does not submit proof they have been authorized by the Consumer to act on their behalf. Consumers may also make a Verifiable Consumer Request on behalf of a minor child.
Also note that we are only required to fulfill Requests to Know/Access from a Consumer two times (2x) per every 12-month period.
Deletion Request Rights
Consumers have the right to request that we delete any of their Personal Information that has been collected and retained, subject to certain exceptions listed below. Once we receive and confirm a Verifiable Consumer Request, we will delete your Personal Information from our records/databases.
We may deny a Consumer's Request to Delete if retaining the Personal Information is necessary for us or our service provider(s) to:
- Complete the transaction for which we collected the Personal Information, provide a product or service that was requested, take actions reasonably anticipated within the context of our ongoing business relationship with the Consumer, or otherwise perform our contract with the Consumer.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for any such activities.
- Debug products and services to identify and repair errors that impair existing intended functionality. Exercise free speech, ensure the right of another Consumer to exercise their free speech rights, or exercise another right provided by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 seq.).
- Enable solely internal uses that are reasonably aligned with our Consumers' expectations based on their relationship with us.
- Comply with all laws or government rules, regulations, or obligations.
- Explore other internal and lawful uses of Personal Information that are compatible with the context in which the Consumer provided it.
Exercising Know/Access, Data Portability, and Deletion Rights
Consumers can make a Request to Know/Access or Request to Delete, subject to the exceptions listed above, by submitting a Verifiable Consumer Request to us by either:
- Filling out and submitting one of the following "Verifiable Consumer Request Forms":
- Calling our Customer Service Department at: 1-800-355-0558
- Sending a written Request to Baker's Best Health Customer Service, P.O. Box 930724, Wixom, MI 48393
However, we cannot respond to a Consumer's Request or provide a Consumer with Personal Information if we cannot verify his/her identity, or the Consumer's authority to make the Request and confirm the Personal Information related to that Consumer.
The only Personal Information we try to collect is Consumers' names, addresses, telephone numbers, and email addresses. For the vast majority of Consumers, we only have and maintain their names and addresses in our records/databases; there are no telephone numbers, postal addresses, email addresses, or any other data points or corroborating identification information available to us to verify a Consumer's identity.
As such, the Personal Information we collect: (i) is not very sensitive and/or valuable in and of itself; (ii) does not represent a great risk of harm if it is improperly accessed or deleted from our records/databases; (iii) can be very easily obtained from a multitude of other sources by fraudulent or malicious actors; and (iv) is not sufficiently robust to protect against fraudulent requests or being spoofed or fabricated.
The widespread access and general availability of the Personal Information we collect and maintain means there is no reasonable method by which we can verify the identity of a Consumer to either degree of certainty required by Section 999.323 of the CCPA Regulations.
Making a Verifiable Consumer Request does not require a Consumer to have a Customer Number with us. If the Consumer does not have a Customer Number and wants to verify his/her name, address, telephone number, and/or email address that we currently have in our records/databases, they can click here to access and fill out a Request to Know/Access Form.
As a part of the identity verification process for Consumers who do not have a Customer Number, we require a signed Declaration Under Penalty of Perjury (which will be provided) that certifies the requester is the Consumer whose Personal Information is the subject of the Request to Know/Access. Once we receive the signed Declaration, we can verify the Consumer's identity and provide confirmation of the name, postal address, telephone number, and/or email address per the Request to Know/Access.
If the Consumer has a Customer Number with us, they can click here to access and fill out the same Request to Know/Access Form referenced above. The inclusion of your Customer Number on the form is necessary because it is the data point that verifies you in our system and enables us to respond to your Request to Know/Access as soon as possible.
In either case, we will deliver our written response to a Request to Know/Access by email or regular mail, at the Consumer's option. Also, we will only use Personal Information provided in a Verifiable Consumer Request Form to verify the requestor's identity or authority to make the Request
Exercising "Do Not Sell My Personal Information" (Opt-Out) Rights
California Laws require that any business that "sells" Consumers' Personal Information must provide a webpage where Consumers can opt out of having their Personal Information "sold". Click here to access our "Do Not Sell My Personal Information"/Opt Out Form.
Response Timing and Format
Per the CCPA, we will confirm receipt of a Consumer's Verifiable Request to Know/Access or Request to Delete within ten (10) business days of our receipt of that Request. We will then respond to the Request within forty-five (45) calendar days of its receipt. If we require more time to respond (up to 90 days), then we will inform the Consumer as soon as possible via email or in writing of the reason for the necessary extension period.
Any disclosures we provide to a Verifiable Consumer Request will only cover the 12-month period preceding that Request's receipt. The response we provide will also explain the reasons we cannot comply with a Request, if applicable. For data portability requests, we will select a format to provide a Consumer's Personal Information that is readily usable and should allow the Consumer to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to a Verifiable Consumer Request unless it is excessive, repetitive, or entirely unfounded. If we determine that the request warrants a fee, then we will inform the Consumer why we made that decision and provide him/her with a cost estimate before completing the Request.
Per the CCPA, we will: (i) act upon "Do Not Sell My Personal Information Requests" (Opt Out) within fifteen (15) business days of our receipt of the Request, (ii) notify all third parties to whom we have rented (one-time use only) the Personal Information to within ninety (90) days prior to our receipt of the Consumer's Request, (iii) indicate that the Consumer has exercised his/her right to opt-out, and (iv) instruct the third parties not to further sell the Personal Information. We will also notify the Consumer by email or regular mail, at the Consumer's option, when the notification process was made/completed on our end.
We will not discriminate against Consumers for exercising any of their CCPA rights. Unless otherwise permitted by California Laws, we will not:
- Deny Consumers access to any of our products or services
- Charge Consumers different prices or rates for our products or services, including granting discounts or other benefits, or imposing any fines or penalties
- Provide Consumers with a different level or quantity of goods or services
- Suggest Consumers may receive a different price or rate for our products or services, or a different level or quality of our products or services
This Website is not intended to be used by children under the age of 16. We do not collect any Personal Information from anyone under the age of 16 knowingly, and we do not use any Personal Information that has been inadvertently collected. If we learn that we have collected Personal Information from someone under the age of 16, we immediately delete it from our records/database. Please note that children should always receive parental permission before sharing any Personal Information online with any website.
Other California Privacy Rights
California's "Shine the Light" law, Civil Code section 1798.83, requires certain businesses to respond to requests from California customers asking about the businesses' practices related to disclosing Personal Information to third parties for the third parties' direct marketing purposes. Alternately, such businesses may have in place a policy not to disclose Personal Information of customers to third parties for the third parties' direct marketing purposes if the customer has exercised an option to opt-out of such information-sharing. As discussed above, if a Consumer wishes to opt-out of our sharing of their Personal Information with third parties for the third parties' direct marketing purposes offline, please click here. While this notice is designed to comply with California's "Shine the Light" law, the opt-out option is also available to all our users. To find out more about your opt-out rights, please contact us via e-mail or postal address described below.
Changes to Our Privacy Notice
Baker's Best Health Customer Service
P.O. Box 930724
Wixom, MI 48393
Last updated: February 28, 2020