Privacy Policy
Effective Date: January 3, 2026
This Privacy Policy explains how Datarate LLC (“Datarate,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you visit our website or use our services, and describes the rights and choices available to you. Please read it before using our website or services. Continued use of the website or services after reviewing this Policy indicates that you accept it; if you do not, please stop using the website and services.
At a glance:
We collect information you give us, information gathered automatically when you use our site, and information obtained from third-party partners.
We use, sell, and share personal information as part of our business, subject to the opt-out and other rights described below.
U.S. state residents can access, correct, or delete their data and opt out of sales, sharing, targeted advertising, and profiling through our Your Privacy Choices page.
Individuals in the European Economic Area (EEA), the United Kingdom, and Switzerland have additional rights under the GDPR and UK GDPR, described in the International Privacy Rights section.
We honor Global Privacy Control (GPC) browser signals as opt-out requests.
Who We Are
Datarate LLC is the controller of personal information collected through this website and our services. Our contact details, including how to reach our Privacy Administrator, appear in the Contact Us section at the end of this Policy.
Information We Collect
Information you provide to us
Depending on how you interact with us, this may include:
Contact details — name, postal address, phone number, email address, gender, and date of birth;
Account credentials — username and password;
Payment and financial details — bank account information, statements, transaction records, and payment card numbers;
Professional information — job title, employer, industry, and similar occupational details, for example when you engage with us in a business capacity; and
Audio and visual information — for example, recordings of customer support calls, where permitted by law and with any required notice.
Information collected automatically
When you visit our website, our servers automatically log technical data, which may include your browser type and version, operating system, the site that referred you to us, the pages you view, the date and time of your visit, your IP address, and your Internet service provider, together with related diagnostic details that help us investigate attacks on our systems.
We do not use raw server logs to draw conclusions about individual visitors. This data helps us deliver content correctly, keep the website stable and secure, improve the site and how we promote it, and support law enforcement if our systems are attacked. Log data is analyzed on an aggregate, statistical basis and kept separate from personal information you actively provide.
We also collect device and advertising identifiers — including Mobile Advertising IDs (MAIDs), Connected TV (CTV) identifiers, IP addresses, cookie IDs, and other pseudonymous identifiers used for measurement and advertising delivery.
Information from other sources
We obtain personal information from third-party business partners such as social media platforms, advertising networks, data aggregators, and analytics providers, and by observing how you interact with our website.
How We Use Personal Information
We use the information described above to:
fulfill the purpose for which you provided it — for example, answering an inquiry, providing a quote, processing a payment, or completing a transaction;
create, maintain, secure, and personalize your account and your experience with us;
provide, support, improve, and develop our website, products, and services, including testing, research, and analytics;
deliver content, offers, and advertising relevant to your interests on our website, on third-party sites, and by email or text message (with your consent where the law requires it);
prevent fraud and protect the safety, security, and integrity of our website, systems, and business;
comply with law, respond to law enforcement requests, and enforce our legal rights;
evaluate or complete a corporate transaction such as a merger, sale of assets, restructuring, or bankruptcy, in which personal information may be among the transferred assets; and
for any other purpose described to you at the point of collection.
We will not collect materially new categories of personal information, or use what we have collected for materially different or incompatible purposes, without notifying you.
Legal Bases for Processing (EEA, UK, and Switzerland)
Where the EU General Data Protection Regulation (“GDPR”), the UK GDPR, or the Swiss Federal Act on Data Protection applies, we process personal information only where we have a valid legal basis to do so:
Consent (Art. 6(1)(a) GDPR) — for example, for marketing emails, non-essential cookies, and any processing where the law requires opt-in consent. You may withdraw consent at any time, and withdrawing it is as easy as giving it; withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Performance of a contract (Art. 6(1)(b) GDPR) — where processing is necessary to provide services you have requested or to take steps at your request before entering a contract, such as creating and administering your account.
Legal obligation (Art. 6(1)(c) GDPR) — where we must process information to comply with laws that apply to us, such as record-keeping, tax, and law-enforcement obligations.
Legitimate interests (Art. 6(1)(f) GDPR) — where processing is necessary for our legitimate business interests and those interests are not overridden by your rights and freedoms. Our legitimate interests include securing our systems, preventing fraud, performing analytics, improving our services, and conducting business-to-business marketing. Where we rely on legitimate interests, you have the right to object as described in International Privacy Rights below.
We do not use consent obtained by default, inactivity, or mere use of the website as a legal basis where the GDPR or UK GDPR applies; where those laws require consent, we obtain it through a clear affirmative action.
Cookies and Similar Technologies
Cookies are small text files placed on your browser by a web server. “Session” cookies expire when you close your browser; “persistent” cookies remain until their set expiration or until you delete them. We use the following categories:
Strictly necessary — enables core functions such as page navigation, load balancing, and secure sign-in to restricted areas. Duration: session.
Preferences — remembers choices you make, such as language settings or personalized content in areas where you hold an account. Duration: session or persistent (up to 12 months).
Analytics — third-party measurement tools that show us, in aggregate, how visitors find and use the site — such as total visits, page views, and referring sites — so we can improve it. Duration: persistent (up to 24 months).
Advertising and social media — third-party cookies, pixels, and social-sharing widgets that support interest-based advertising, measure campaign performance, and let you share our content on social platforms. These providers may log your activity across the web; review their privacy policies before use. Duration: persistent (up to 24 months).
You can block or delete cookies at any time through your browser settings, and you can manage non-essential cookies through the consent tools we provide where required by law. To opt out of interest-based advertising from participating companies, visit the Digital Advertising Alliance at optout.aboutads.info or the Network Advertising Initiative at optout.networkadvertising.org; opting out limits targeting but does not eliminate advertising. General information about cookies is available at www.allaboutcookies.org.
Our website may link to sites we do not operate. Their privacy and cookie practices are their own; review their policies before providing personal information.
Accounts, Marketing Emails, and Contact Forms
Accounts. When you register, the registration form determines what information you submit. We collect and store that information for our internal purposes, and our service providers may process it on our behalf for the same purposes. We also record the IP address, date, and time of registration — solely to prevent misuse of our services and to support the investigation of unlawful activity — and we do not disclose those records to third parties except where the law requires it or a criminal investigation makes it necessary. You may update your account information at any time or ask us to delete it entirely.
Marketing emails. You can sign up for our marketing communications by providing a valid email address through our sign-up form. Every marketing email we send includes an unsubscribe option, and you can also manage your preferences through our Your Privacy Choices page.
Contacting us. If you reach us by email or a contact form, we store what you send solely to handle your inquiry and respond to you. We do not pass it to third parties.
How We Share and Sell Personal Information
As part of our business, we disclose personal information — about both current and former customers — to Datarate affiliates and to unaffiliated third parties, including email service providers, fraud-verification services, and other users with whom you transact. These disclosures occur:
to service providers performing services (including marketing services) on our behalf under contracts that limit their use of the information to performing those services and require them to keep it confidential;
to data aggregators;
for routine operations such as processing transactions, maintaining accounts, responding to court orders and legal process, and reporting to credit bureaus; and
where we are legally required to disclose the information.
We may share personal information with partners for marketing purposes as the law allows, and we may sell personal information as defined under applicable state privacy laws. You can opt out of the sale or sharing of your personal information at any time — see Your U.S. State Privacy Rights below. Under some state laws, including California’s, certain targeted-advertising practices count as a “sale” or “share.”
Third parties that support our identity-verification and anti-fraud controls may retain and use information about you to perform those services and to improve them.
We may also disclose aggregated or de-identified information. Where we treat information as de-identified, we maintain it in de-identified form, commit not to attempt reidentification except as permitted by law, and require the same of recipients.
International Data Transfers
We are based in the United States, and personal information we collect is processed there and in other countries where we or our service providers operate. Where we transfer personal information from the EEA, the UK, or Switzerland to a country that has not received an adequacy decision from the European Commission or the UK Government, we rely on appropriate safeguards recognized under Articles 46 and 49 of the GDPR and their UK equivalents — principally the European Commission’s Standard Contractual Clauses, supplemented for UK transfers by the UK International Data Transfer Addendum, together with any additional technical and organizational measures the transfer requires. You may request more information about the safeguards applicable to a specific transfer through our Your Privacy Choices page.
How Long We Keep Information
We keep personal information only as long as needed for the purposes for which it was collected or for other disclosed, legitimate business purposes — including internal analytics, service improvement, and, where the law permits, the sale or sharing of data. Where permitted, we may retain certain categories of personal information for future sale or targeted advertising even after our relationship with you ends; in those cases we honor every applicable opt-out, and records flagged “Do Not Sell” or “Do Not Share” are segregated and excluded from future transactions.
Actual retention periods depend on the type and sensitivity of the information, whether you have exercised an opt-out or other right, legal and contractual obligations, and the need to keep records for audit, security, fraud-prevention, or enforcement purposes. When the applicable period ends, or when we receive a valid deletion request, we delete or de-identify the information unless the law requires or permits us to keep it.
How We Protect Information
We maintain technical, administrative, and physical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, and destruction, including encryption of data in transit and at rest, role-based access controls with multi-factor authentication, recurring vulnerability assessments and penetration testing, secure development and code-review practices, access monitoring and logging, regular staff privacy and security training, and contractual data-protection requirements for vendors.
No Internet transmission or storage method is completely secure. We use commercially reasonable measures but cannot guarantee absolute security, and transmission of information to us is at your own risk. We are not responsible for the security of data transmitted over public networks or on third-party platforms outside our control.
Your U.S. State Privacy Rights
Residents of states with consumer privacy laws — currently including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Montana, Nevada, Oregon, Tennessee, Texas, Utah, Vermont, and Virginia — may have some or all of the rights below. The State-Specific Supplement at the end of this Policy details each state’s rights and our related disclosures.
Right to know / access — obtain the categories and specific pieces of personal information we have collected about you, the sources, our purposes, and the categories of third parties to whom it was disclosed or sold.
Right to correct — have inaccurate personal information corrected.
Right to delete — have your personal information deleted, subject to statutory exceptions.
Right to opt out — opt out of the sale or sharing of your personal information, its use for targeted advertising, and certain profiling.
Right to portability — receive your information in a usable format you can transmit elsewhere.
Right to non-discrimination — exercise these rights without being denied services or charged different rates, except through lawful financial-incentive programs you opt into.
Submit requests through our Your Privacy Choices page, by email at privacy@datarate.com, or by mail to Datarate LLC, Attn: Privacy Administrator, 2810 N Church St #97104, Wilmington, DE 19802. Verification, timing, appeal, and opt-out mechanics are described in the Supplement.
A note on how opt-outs work. Opting out does not delete your information. Instead, we place a “Do Not Sell / Do Not Share” suppression flag on it in our systems. We keep the flagged record precisely so that your choice survives: if your information later reaches us again from another source, the flag tells us not to sell or share it. If we deleted the record instead, we would have no way of recognizing that you had opted out. If you want your information deleted rather than suppressed, submit a deletion request.
International Privacy Rights (EEA, UK, and Switzerland)
If you are located in the EEA, the UK, or Switzerland, you have the following rights regarding your personal information, in addition to any that overlap with the rights described above:
Access (Art. 15 GDPR) — confirmation of whether we process your personal information and, if so, a copy of it along with information about the purposes of processing, the categories of data, the recipients or categories of recipients (including recipients in third countries and the safeguards applied), the envisaged retention period or the criteria used to set it, the source of the data if we did not collect it from you, and the existence of any automated decision-making, including profiling, with meaningful information about the logic involved and its significance and consequences for you.
Rectification (Art. 16) — correction of inaccurate personal information and completion of incomplete information.
Erasure (Art. 17) — deletion of your personal information where it is no longer necessary for the purposes for which it was collected, you withdraw consent and no other legal basis applies, you object and no overriding legitimate grounds exist, the data was unlawfully processed, or erasure is required by law.
Restriction (Art. 18) — restriction of processing while we verify accuracy you have contested, where processing is unlawful but you prefer restriction over erasure, where we no longer need the data but you need it for legal claims, or while an objection is pending.
Portability (Art. 20) — receipt of the information you provided to us in a structured, commonly used, machine-readable format, and transmission of it to another controller where technically feasible.
Objection (Art. 21) — objection to processing based on our legitimate interests, on grounds relating to your particular situation. Where you object to processing for direct marketing, including related profiling, we will stop that processing without exception.
Withdrawal of consent (Art. 7(3)) — withdrawal, at any time, of any consent you have given us.
Complaint (Art. 77) — the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. In the UK, the supervisory authority is the Information Commissioner’s Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concerns first, but you may contact a supervisory authority at any time.
To exercise these rights, use our Your Privacy Choices page or email privacy@datarate.com. We respond to requests within one month of receipt; where a request is complex or we receive many, we may extend by up to two further months and will tell you why within the first month. Exercising these rights is free of charge unless a request is manifestly unfounded or excessive.
Global Privacy Control
When we detect a Global Privacy Control (GPC) signal from your browser or device, we treat it as a request to opt out of the sale and sharing of the associated personal information and its use for targeted advertising, as applicable privacy laws require. We will limit or disable non-essential cookies and tracking for that browser or device, apply the “Do Not Sell / Do Not Share” suppression flag described above, and, where the law requires, pass the opt-out along to our service providers and contractors. We may continue to retain the underlying information for permitted purposes such as compliance, security, fraud prevention, and internal analytics, but not in ways inconsistent with your opt-out.
GPC recognition applies to the specific browser or device sending the signal and may not carry over to your other devices or to offline records. Learn more at globalprivacycontrol.org.
Children’s Privacy
Our website and services are for adults only. They are not directed at children, we do not permit anyone under 18 to use them, and our sign-up forms reject registrations where the date of birth indicates the person is under 18. We do not knowingly collect personal information from anyone under 18, and we do not knowingly sell or share the personal information of consumers under 16.
If we learn that we have collected personal information from a minor — including any information from a child under 13 that is subject to the Children’s Online Privacy Protection Act (COPPA) — we will delete it promptly. If you believe a minor has provided us with personal information, please contact us at privacy@datarate.com so we can take appropriate action.
Profiling and Automated Decisions
We do not use automated decision-making to produce legal or similarly significant effects on individuals — decisions affecting eligibility for credit, employment, housing, insurance, or access to services — and we do not make determinations affecting your legal rights solely by algorithm without human review.
We do engage in lawful profiling: automated processing that evaluates or categorizes individuals or devices based on attributes such as behavior, interests, device type, browsing activity, location, or demographic indicators. We use this profiling to build aggregated insights and audience segments, improve data quality and performance, support analytics, and enable lawful marketing and advertising by our clients. All profiling is conducted in line with applicable law — including the CCPA/CPRA, the Colorado Privacy Act, the Virginia CDPA, and, where applicable, the GDPR and UK GDPR — with human oversight of data outputs and transparency about how audience segments are built. We do not profile using sensitive personal data. You can opt out of profiling connected to targeted advertising or the sale or sharing of personal data at any time through our Your Privacy Choices page.
Restrictions on Foreign Access to Data
We do not knowingly sell, transfer, or otherwise make personal information or sensitive data categories available to foreign adversaries as defined under applicable United States law, including the Protecting Americans’ Data from Foreign Adversaries Act (PADFAA) and its implementing regulations. We maintain contractual, technical, and organizational safeguards designed to prevent unauthorized foreign access to data under our control, and all cross-border transfers are made in accordance with applicable U.S. and international data protection law.
Questions and Complaints
If you believe we have handled your personal information in a way that does not comply with this Policy, or you have any privacy question or concern, please raise it through our Your Privacy Choices page or by emailing privacy@datarate.com with as much detail as possible. We investigate promptly and take appropriate action. If you submit conflicting preferences — for example, an opt-out followed by an opt-in — we will apply the most recent verifiable instruction we can confirm, but we cannot guarantee that conflicting instructions will resolve as you intend in every system simultaneously. EEA, UK, and Swiss residents also have the right to complain to a supervisory authority, as described in International Privacy Rights.
Changes to This Policy
We may update this Policy from time to time at our discretion. When we do, we will post the revised version here and update the effective date at the top. For material changes affecting EEA or UK residents, we will provide notice consistent with applicable law. Your continued use of the website or services after changes are posted means you accept the revised Policy; we encourage you to check back periodically.
Contact Us
Online: Your Privacy Choices page
Email: privacy@datarate.com
Mail: Datarate LLC, Attn: Privacy Administrator, 2810 N Church St #97104, Wilmington, DE 19802
EEA, UK, and Swiss inquiries: If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may direct any privacy inquiry or request to privacy@datarate.com, and we will handle it in accordance with the laws that apply to you.
State-Specific Supplement
This Supplement forms part of the Datarate LLC Privacy Policy and applies to residents of U.S. states with consumer privacy laws (“consumers” or “you”). Not every provision applies to every reader. Terms defined in a state’s statute carry the same meaning here.
Categories of Personal Information Collected
In the preceding twelve (12) months, we have collected the following categories of personal information, as those categories are defined under the California Consumer Privacy Act and organized per Cal. Civ. Code § 1798.140:
A. Identifiers — Real name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account name. Collected: Yes.
B. Customer records (Cal. Civ. Code § 1798.80(e)) — Name, address, telephone number, financial and payment information. Collected: Yes.
C. Protected classification characteristics — Age, gender, and similar characteristics protected under California or federal law. Collected: Yes.
D. Commercial information — Records of products or services purchased or considered; purchasing histories and tendencies. Collected: Yes.
E. Biometric information — Fingerprints, faceprints, voiceprints. Collected: No.
F. Internet or other electronic network activity — Browsing history, search history, interactions with our website and advertisements. Collected: Yes.
G. Geolocation data — Physical location or movements. Collected: Yes.
H. Sensory data — Audio, electronic, visual, or similar information, such as recorded support calls. Collected: Yes.
I. Professional or employment-related information — Job title, employer, occupational history. Collected: Yes.
J. Non-public education information (FERPA) — Education records maintained by an educational institution. Collected: No.
K. Inferences drawn from other personal information — Profiles reflecting preferences, characteristics, behavior, and attitudes. Collected: Yes.
L. Sensitive personal information — Government ID numbers, precise geolocation, racial or ethnic origin, health data, biometric identifiers. Collected: No.
Personal information does not include publicly available information from government records; de-identified or aggregated consumer information; or information excluded from the CCPA’s scope, such as health information covered by HIPAA or California’s Confidentiality of Medical Information Act, clinical-trial data, and information governed by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, the California Financial Information Privacy Act, or the Driver’s Privacy Protection Act of 1994.
Sources: We collect these categories directly from you (forms you complete, purchases you make), indirectly from you (your activity on our website), and from third-party business partners (social media platforms, advertising networks, data aggregators, analytics providers).
Purposes: We collect and use these categories for the business purposes listed under How We Use Personal Information in the main Policy.
Disclosures and Sales of Personal Information
We disclose personal information to third parties for business purposes under contracts that state the purpose, require confidentiality, and prohibit use beyond the contract. The categories of third parties are service providers and data aggregators.
In the preceding twelve (12) months, we disclosed the following categories for a business purpose, to service providers: Categories A, B, C, D, F, G, H, I, and K.
In the preceding twelve (12) months, we sold or shared (as those terms are defined under applicable state law) the following categories: Categories A, B, C, D, F, G, I, and K, to advertising networks, data aggregators, and marketing partners.
Submitting Verifiable Consumer Requests
Our secure online portal is the primary channel for privacy requests; it helps us process requests accurately and screen out fraudulent or automated submissions. You may also submit requests by email or mail:
Online: Your Privacy Choices page
Email: privacy@datarate.com
Mail: Datarate LLC, Attn: Privacy Administrator, 2810 N Church St #97104, Wilmington, DE 19802
Only you — or an agent you have authorized who is registered with your state’s Secretary of State where the law requires — may submit a request concerning your personal information. You may also submit a request on behalf of your minor child. Access and portability requests are limited to twice in any 12-month period.
Your request must give us enough information to reasonably verify that you are the person the request concerns (or their authorized agent) and enough detail for us to understand and respond to it. We cannot fulfill a request if we cannot verify identity or authority or confirm the information relates to the requestor. You do not need an account with us to submit a request, and information submitted for verification is used only for verification.
Timing. We aim to respond within forty-five (45) days of receiving a verifiable request. If we need more time (up to 90 days total), we will explain why in writing. Responses are delivered to your account if you have one, or otherwise by mail or electronically at your option, and cover the 12 months preceding the request. If we deny a request, we will explain why. Portability responses use a readily usable format you can transmit to another entity. We do not charge for requests unless one is excessive, repetitive, or manifestly unfounded, in which case we will explain the fee and estimate the cost before proceeding.
Deletion exceptions. We may decline to delete information where retention is necessary to: complete the transaction or provide a service you requested, or otherwise perform our contract with you; detect security incidents or protect against and prosecute malicious, deceptive, fraudulent, or illegal activity; debug and repair errors; exercise or safeguard free-speech rights or another legal right; comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et seq.); support public or peer-reviewed research in the public interest, where you gave informed consent and deletion would seriously impair the research; enable solely internal uses reasonably aligned with your expectations; comply with a legal obligation; or make other lawful internal uses compatible with the context of collection.
Non-discrimination. We will not deny you goods or services, charge different prices or rates, provide a different level or quality of service, or suggest we might do any of these, because you exercised a privacy right — except through financial-incentive programs the law permits. Any such program will reasonably relate to the value of your data, will be described in written terms, and requires your prior opt-in consent, which you may revoke at any time.
California “Shine the Light.” California Civil Code § 1798.83 lets California residents request information about our disclosure of personal information to third parties for those parties’ direct marketing purposes. Submit these requests through our Your Privacy Choices page.
Rights by State
Submit requests under any of the laws below through our Your Privacy Choices page unless otherwise noted.
California — CCPA, as amended by the CPRA (effective Jan. 1, 2020 / Jan. 1, 2023). Rights to know, access, correct, and delete personal information; opt out of its sale or sharing; limit use and disclosure of sensitive personal information; data portability; and non-discrimination. We honor GPC signals as a valid opt-out for the transmitting browser or device.
Colorado — Colorado Privacy Act (effective July 1, 2023). Rights of access, correction, deletion, and portability, and opt-outs from the sale of personal data, targeted advertising, and certain profiling. Denied requests may be appealed through our portal.
Connecticut — Connecticut Data Privacy Act (effective July 1, 2023). Rights of access, correction, deletion, and portability, and opt-outs from data sales and targeted advertising. Denied requests may be appealed through our portal.
Delaware — Delaware Personal Data Privacy Act (effective Jan. 1, 2025). Rights of access, correction, deletion, and portability, and opt-outs from data sales and targeted advertising.
Florida — Florida Digital Bill of Rights (effective July 1, 2024). Rights to access and delete personal data (subject to exceptions) and to opt out of sales and certain profiling.
Indiana — Indiana Consumer Data Protection Act (effective Jan. 1, 2026). Rights of access, correction, and deletion, and opt-outs from targeted advertising, data sales, and profiling.
Iowa — Iowa Consumer Data Protection Act (effective Jan. 1, 2025). Rights of access and deletion, and opt-outs from data sales and profiling.
Montana — Montana Consumer Data Privacy Act (effective Oct. 1, 2024). Rights of access, correction, deletion, and portability, and opt-outs comparable to those under the Virginia and Colorado laws.
Nevada — NRS 603A (effective Oct. 1, 2019). Nevada residents may opt out of the sale of covered personal information.
Oregon — Oregon Consumer Privacy Act (effective July 1, 2024). Rights of access, correction, deletion, and portability, and opt-outs from targeted advertising and profiling. Oregon residents may also request a list of the specific third parties to which we have disclosed personal data.
Tennessee — Tennessee Information Protection Act (effective July 1, 2025). Rights of access, correction, and deletion, and opt-outs from targeted advertising, data sales, and profiling.
Texas — Texas Data Privacy and Security Act (effective July 1, 2024). Datarate operates as a data broker under Texas law and is registered with the Texas Secretary of State as Texas law requires; registrant information is available on the Texas SOS website. Texas residents have rights of access, correction, and deletion, and may opt out of processing for targeted advertising, the sale of personal data, or profiling.
Utah — Utah Consumer Privacy Act (effective Dec. 31, 2023). Rights of access and deletion, and opt-outs from sale and targeted advertising.
Vermont — 9 V.S.A. § 2430 et seq. (effective Jan. 1, 2019). Vermont regulates data brokers through registration and transparency requirements rather than direct consumer opt-out rights; we maintain compliance with those requirements, including annual data broker registration with the Vermont Secretary of State.
Virginia — Virginia Consumer Data Protection Act (effective Jan. 1, 2023). Rights of access, correction, deletion, and portability, and opt-outs from targeted advertising, profiling, and data sales. Denied requests may be appealed through our portal within 30 days.
If you live in a U.S. state not listed here that has enacted a consumer privacy law, you may still contact us to exercise applicable rights. Use our Your Privacy Choices page, or if the portal is unavailable to you, email privacy@datarate.com with the subject line “[Your State] Privacy Request,” your state of residence, and the nature of your request. We will respond as applicable law requires.
