Signed in as:
filler@godaddy.com
Signed in as:
filler@godaddy.com
# Privacy Policy for PoppaJoes.org
**Effective Date:** January 2, 2026
**Last Updated:** January 2, 2026
PoppaJoes LLC (“PoppaJoes,” “we,” “us,” or “our”) operates **PoppaJoes.org** and related online properties, including links to Facebook, Instagram, Messenger, Threads, WhatsApp, X, Telegram, Zangi, Twitch, Discord, Reddit, our blog, YouTube channel, and weekly podcast with video content. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our websites, order catering or products, interact with our content, or contact us.
We designed this Policy to meet transparency and disclosure obligations under U.S. state privacy laws (e.g., **CCPA/CPRA**, **VCDPA**, **CPA**) and the **GDPR** for international users. [2](https://www.oag.ca.gov/privacy/ccpa)[3](https://law.lis.virginia.gov/vacode/title59.1/chapter53/)[4](https://coag.gov/resources/colorado-privacy-act/)[5](https://www.edpb.europa.eu/our-work-tools/our-documents/publication-type/guidelines_en)
---
## 1) Information We Collect
We collect the following categories of information:
- **Identifiers & Contact Information:** name, username/handle, email, phone, postal address, billing address, and order details.
- **Commercial Information:** order history (catering bookings, product purchases), preferences, special requests (e.g., dietary needs).
- **Internet/Device Activity:** IP address, device type, browser, pages viewed, referring/exit pages, timestamps, and cookie or similar identifiers (see **Cookies & Tracking**). Under GDPR, online identifiers like cookies and IP addresses may be personal data. [6](https://termly.io/resources/articles/gdpr-cookies/)
- **Geolocation Data:** approximate location derived from IP or delivery address (when you request local services).
- **Audio/Visual Content:** user‑submitted recipes, reviews, or comments; interactions on our social channels; podcast Q&A, live streams, and recorded events.
- **Payment Information:** processed securely by our payment processors; we do not store full card numbers.
- **Sensitive Data (limited):** if you voluntarily provide dietary restrictions that may imply health‑related information; we use it only to fulfill catering safely and do not use it for advertising. Some states treat certain categories (e.g., biometric, precise geolocation) as **sensitive** and require heightened protections. [7](https://www.bakerdonelson.com/webfiles/Privacy_Guide/Colorado-Privacy-Law-Guide.pdf)
We collect data directly from you (forms, orders, messages), automatically (cookies, analytics), and from integrated platforms (e.g., social media, messaging apps) as permitted by their terms and your settings.
---
## 2) How We Use Your Information
We use information to:
- **Provide Services:** process orders; schedule catering; deliver purchases; manage bookings; customer support.
- **Operate & Improve Sites:** analytics, troubleshooting, performance, and security; fraud prevention; quality control.
- **Communications:** confirmations, service updates, and responses to inquiries; marketing (where permitted) including newsletters and promotions; podcast and video updates.
- **Legal & Compliance:** meet regulatory requirements, handle disputes, protect rights, and maintain records.
Under California law, we must disclose collection purposes and categories at or before the point of collection via a **Notice at Collection**; we provide that notice wherever we collect data (e.g., checkout, contact forms). [1](https://california-ccpa.org/cpra/section-7012-notice-at-collection-of-personal-information/)[2](https://www.oag.ca.gov/privacy/ccpa)
---
## 3) Cookies & Tracking Technologies
We use cookies and similar technologies (e.g., local storage, pixels) for:
- **Essential Operations:** login, cart, checkout, security.
- **Preferences & Performance:** remember settings, measure engagement.
- **Analytics & Marketing:** understand traffic and reach (e.g., YouTube, social referrals), and—where permitted—deliver or measure promotions.
For users in the EU/EEA, we obtain **explicit consent** before activating non‑essential cookies and provide granular controls (accept, reject, or manage categories). Consent must be freely given, specific, informed, and unambiguous, and you can withdraw it anytime via our **Cookie Preferences** link. [6](https://termly.io/resources/articles/gdpr-cookies/)[8](https://gdprlocal.com/gdpr-cookies/)
For U.S. users, we honor applicable state requirements and **Universal Opt‑Out Mechanisms (UOOM)** where mandated (e.g., Global Privacy Control) to opt out of targeted advertising/sale/sharing. [4](https://coag.gov/resources/colorado-privacy-act/)[9](https://www.gunster.com/newsroom/publications/2026-data-privacy-laws-state-changes-universal-opt-out-compliance)
---
## 4) How We Share Information
We share information with:
- **Service Providers/Processors:** payment processing, hosting, analytics, customer support, delivery/courier, marketing (acting on our instructions and subject to contractual safeguards).
- **Business Partners & Platforms:** integrated social/messaging platforms you use to interact with us; we limit data to what’s needed for functionality and respect your platform settings.
- **Legal/Compliance:** to comply with law, enforce terms, protect rights, or in due diligence/transfer events (e.g., merger).
We **do not sell** personal information for money. Some state laws define “sale” or “sharing” to include disclosure for **other valuable consideration** or **cross‑context behavioral advertising**; to the extent our analytics/ads are deemed “sale” or “sharing,” you may **opt out** (see **Your Rights**). [7](https://www.bakerdonelson.com/webfiles/Privacy_Guide/Colorado-Privacy-Law-Guide.pdf)[10](https://gdprlocal.com/cpra-2024-the-new-compliance-requirements/)
---
## 5) Your Privacy Rights
Depending on where you live, you may have the following rights:
- **Access / Know:** request the categories and specific pieces of personal information we have collected and how we use/disclose it. (CA, VA, CO, others) [2](https://www.oag.ca.gov/privacy/ccpa)[3](https://law.lis.virginia.gov/vacode/title59.1/chapter53/)[4](https://coag.gov/resources/colorado-privacy-act/)
- **Correct:** request correction of inaccurate data. (CA CPRA; various states) [2](https://www.oag.ca.gov/privacy/ccpa)
- **Delete:** request deletion of personal information, subject to lawful exceptions. (CA, VA, CO, others) [2](https://www.oag.ca.gov/privacy/ccpa)[3](https://law.lis.virginia.gov/vacode/title59.1/chapter53/)[4](https://coag.gov/resources/colorado-privacy-act/)
- **Opt Out:** opt out of the **sale** or **sharing** of personal information and **targeted advertising**; we also recognize required **UOOM** signals (e.g., GPC) where applicable. (CA, CO; more states in 2026) [2](https://www.oag.ca.gov/privacy/ccpa)[4](https://coag.gov/resources/colorado-privacy-act/)[9](https://www.gunster.com/newsroom/publications/2026-data-privacy-laws-state-changes-universal-opt-out-compliance)
- **Limit Use of Sensitive Personal Information:** for California residents where applicable. [2](https://www.oag.ca.gov/privacy/ccpa)
- **Appeal:** appeal a decision if we cannot honor your request (where state law requires). (e.g., VA, CO) [3](https://law.lis.virginia.gov/vacode/title59.1/chapter53/)[4](https://coag.gov/resources/colorado-privacy-act/)
**How to exercise:**
- Use our **Privacy Request Form** (link in footer) or email **privacy@poppajoes.org**.
- We will verify your identity, respond within the legal timeframe, and explain any denials and appeal options. (e.g., VA transparency & modalities requirements) [3](https://law.lis.virginia.gov/vacode/title59.1/chapter53/)
**International (GDPR):** If you are in the EU/EEA/UK, you may have additional rights (e.g., data portability, restriction, objection). We rely on consent, contract performance, legitimate interests, or legal obligations as our lawful bases. [11](https://gdpr.datasumi.com/privacy-policies-and-transparency-under-gdpr)[5](https://www.edpb.europa.eu/our-work-tools/our-documents/publication-type/guidelines_en)
---
## 6) Notice to California Residents (CCPA/CPRA)
We provide a **Notice at Collection** at or before collection and maintain this Privacy Policy describing: categories collected, purposes, retention, disclosure, your rights, and how to exercise them. We recognize **Global Privacy Control (GPC)** signals for opt‑out of sale/sharing where applicable. [1](https://california-ccpa.org/cpra/section-7012-notice-at-collection-of-personal-information/)[2](https://www.oag.ca.gov/privacy/ccpa)
---
## 7) Notice to Virginia Residents (VCDPA)
Virginia residents may access, correct, delete, and opt out of targeted advertising, sale, or certain profiling. We provide a clear and meaningful privacy notice and an internal appeal process for denied requests. [3](https://law.lis.virginia.gov/vacode/title59.1/chapter53/)[12](https://www.oag.state.va.us/consumer-protection/files/tips-and-info/Virginia-Consumer-Data-Protection-Act-Summary-2-2-23.pdf)
---
## 8) Notice to Colorado Residents (CPA)
Colorado residents have rights to access, correct, delete, data portability, and opt out of sale or targeted advertising. We conduct assessments for processing that presents heightened risk and provide disclosures aligned with CPA rules, including updated provisions for sensitive data (e.g., biometric/biological). We recognize approved **universal opt‑out mechanisms**. [4](https://coag.gov/resources/colorado-privacy-act/)[13](https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20241219-colorado-ag-finalizes-new-rules-for-cpa)[14](https://content.leg.colorado.gov/sites/default/files/documents/2024A/bills/2024a_1058_rer.pdf)
---
## 9) Other U.S. States
Many states have enacted or amended comprehensive privacy laws (e.g., **Indiana, Kentucky, Rhode Island** effective Jan 1, 2026; additional changes in CA, CO, CT, OR, UT throughout 2026). We strive to offer a consistent rights experience and will update this Policy as laws evolve. [9](https://www.gunster.com/newsroom/publications/2026-data-privacy-laws-state-changes-universal-opt-out-compliance)[15](https://www.mondaq.com/unitedstates/privacy-protection/1719602/preparing-for-new-and-amended-comprehensive-state-data-privacy-laws-in-2026)
**Kansas:** Kansas does not currently have a comprehensive state privacy law; we nevertheless apply the protections described herein to Kansas customers. [16](https://securiti.ai/privacy-laws/us/kansas/)
---
## 10) Data Retention
We retain personal information only as long as needed for the purposes described, to comply with legal obligations, resolve disputes, and enforce agreements. California requires disclosure of retention periods or criteria in the Notice at Collection and Privacy Policy. [1](https://california-ccpa.org/cpra/section-7012-notice-at-collection-of-personal-information/)
---
## 11) Security
We implement administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and monitoring. No method of transmission or storage is 100% secure.
---
## 12) Children’s Privacy
Our services are intended for general audiences. We do not knowingly collect personal information from children under 13. Where state laws impose heightened requirements for minors’ data, we comply and limit processing accordingly. (e.g., Colorado minors’ privacy amendments) [13](https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20241219-colorado-ag-finalizes-new-rules-for-cpa)
---
## 13) International Transfers
If you access our services from outside the United States, your data may be processed in the U.S. We take steps consistent with GDPR transparency and lawful bases when processing personal data of EU/EEA residents. [11](https://gdpr.datasumi.com/privacy-policies-and-transparency-under-gdpr)
---
## 14) Do Not Track & Universal Opt‑Out
While many browsers offer “Do Not Track,” there is no consensus standard. We honor legally required **Universal Opt‑Out** signals (e.g., GPC) where mandated by state law. [4](https://coag.gov/resources/colorado-privacy-act/)[9](https://www.gunster.com/newsroom/publications/2026-data-privacy-laws-state-changes-universal-opt-out-compliance)
---
## 15) Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a revised “Last Updated” date and, where required, provide additional notice (e.g., email or site banner).
---
## 16) Contact Us
**PoppaJoes LLC**
Leavenworth, Kansas
Email: **privacy@poppajoes.org**
Mailing Address: (Add your preferred address here)
If you are in the EU/EEA, you may contact us via the above details to exercise GDPR rights; if required, we will provide additional contact information for our EU representative.
PoppaJoes.Org
211 Lakeside Drive, Leavenworth, KS 66048, USA
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.