US Regional Privacy Rights Statement
Effective: October 4, 2024
(Defined terms used but not otherwise defined herein shall have the same meaning as used in the eXp World Holdings, Inc. Privacy Policy and Data Processing Policy, or Attendee Terms (as defined below)).
If you are a resident of the United States, you may have additional rights with regards to your Personal Information. Please note this Statement only applies to United States’ residents. This Statement explains how we collect, use, and disclose your Personal Information. It also describes how to exercise your rights under various U.S. privacy laws, collectively the “U.S. Privacy Laws.”
A. Shine the Light Disclosures: Under California Civil Code Section 1798.83 (the “Shine the Light” law), California residents who provide certain personal information in connection with obtaining products or services for personal, family, or household use are entitled to request and obtain the following from us: (i) a list of the categories of personal information (such as name, address, email address, and the type of services provided to the user) that we have disclosed to third parties during the immediately preceding calendar year for the third parties’ direct marketing purposes, and (b) the names and addresses of all such third parties. To request the above information, please contact us using the contact information in Section III (Where to Send Requests), below. We will respond to such written requests within thirty (30) days following receipt at the email or mailing address stated below. Please note that we are only required to respond to each user once per calendar year. Please be aware that not all information sharing is covered by the “Shine the Light” requirements, and only information on covered sharing will be included in our response.
B.California Consumer Privacy Act (CCPA) Disclosures: The California Consumer Privacy Act (“CCPA”) (Cal. Civ. Code §1798.100 et seq.), as amended by the California Privacy Rights Act, requires that we inform you of your rights and that we disclose, among other things, the categories of Personal Information we have collected, sold, and/or disclosed for a business purpose from California residents in the previous twelve (12) month period and the source of such collection.
C. U.S. Privacy Law Disclosures: Other U.S. Privacy Laws, require that we inform you of your rights as well as how we collect, use, and disclose of Personal Information. To provide the Services offered by eXp, we process information about you, including Personal Information, whether or not you have an account or are logged in to the Services. You should review our Privacy Policy along with this Statement to learn more.
I. Personal Information Collection
In the previous twelve (12) month period, we have collected the Personal Information set forth in the table below:
Categories | Source | Business/Commercial Purpose for Collecting | Categories of third parties to whom Personal Information is disclosed | Length of Data Retention (or criteria for determining period of retention) |
Identifiers (Examples: name, address, email address, IP address, account username) | Consumer; Agent; Employee, Service providers; computer-monitoring software; public records |
|
| The retention period for identifiers is based on our contractual obligations to you, legal retention periods for the information, your continued interest in a business relationship with us, whether such information is valuable for us to detect and prevent fraud and information security attacks, and whether you are a prospective, current, or former employee of ours. |
Customer Records Information (Examples: education, employment history, bank account number, or other financial information) | Consumer; Employee; Agent |
|
| The retention period for Customer Records Information is based on our contractual obligations to you, legal retention periods for the information, your continued interest in a business relationship with us, whether such information is valuable for us to detect and prevent fraud and information security attacks, and whether you are a prospective, current, or former employee of ours. |
Protected Information (Examples: race, color, religion, gender, national origin, disability, familial status, sexual orientation) | Employee; Agent |
| We do not disclose or sell this information. | The retention period for Protected Information is based on our contractual obligations to you, legal retention periods for the information, and whether you are a prospective, current, or former employee of ours. |
Commercial Information (Examples: records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies) | Consumer; Agent; Service providers |
|
| The retention period for Commercial Information is based on our contractual obligations to you, legal retention periods for the information, your continued interest in a business relationship with us, whether such information is valuable for us to detect and prevent fraud and information security attacks, and whether you are a prospective, current, or former employee of ours. |
Sensitive Personal information
(examples: social security number, driver’s license, state identification card, passport number, account login, debit/credit card number in combination with any required security or access code) | Agent, Employee, Consultants |
| We only disclose Sensitive Personal Information to our third party providers to the extent necessary to assist us in fulfilling our obligations to Agents, Consultants, and employees, such as providing employee benefits, processing payment, and tax reporting. | The retention period for Sensitive Personal Information is based on our contractual obligations to you, legal retention periods for the information, your continued interest in a business relationship with us, whether such information is valuable for us to detect and prevent fraud and information security attacks, and whether you are a prospective, current, or former employee of ours. |
Biometric Data (Examples: fingerprints, DNA, etc.) | We do not collect this information. | N/A | N/A | We do not collect biometric data. |
Internet Information (Examples: browsing history, search history, or other information about a consumer’s interaction with eXp Site or Services) | Consumer; Agent; Analytics and website service providers; computer monitoring software |
|
| The retention period for Internet Information is based on our contractual obligations to you, legal retention periods for the information, your continued interest in a business relationship with us, whether such information is valuable for us to detect and prevent fraud and information security attacks, and whether you are a prospective, current, or former employee of ours. |
Geolocation Data (Geolocation Data collected when using the Services is not considered precise geolocation data as defined under U.S. Privacy Law) | Derived from IP address or cookies; Agent |
| We do not disclose or sell this information. | The retention period for Geolocation Data is based on our contractual obligations to you, legal retention periods for the information, your continued interest in a business relationship with us, whether such information is valuable for us to detect and prevent fraud and information security attacks, and whether you are a prospective, current, or former employee of ours. |
Audio, Electrical, or Visual Information | Consumer; Employee; Agent |
| We do not disclose or sell this information. | The retention period for Audio, Electrical, or Visual Information is based on our contractual obligations to you, legal retention periods for the information, your continued interest in a business relationship with us, whether such information is valuable for us to detect and prevent fraud and information security attacks, and whether you are a prospective, current, or former employee of ours. |
Professional Information (Examples: employment-related information and history) | Consumer; Employee; Agent; cookies |
| We do not disclose or sell this information. | The retention period for Professional Information is based on our contractual obligations to you, legal retention periods for the information, your continued interest in a business relationship with us, whether such information is valuable for us to detect and prevent fraud and information security attacks, and whether you are a prospective, current, or former employee of ours. |
Education Information | Consumer; Employee; Agent; cookies |
| We do not disclose or sell this information. | The retention period for Education Information is based on our contractual obligations to you, legal retention periods for the information, your continued interest in a business relationship with us, whether such information is valuable for us to detect and prevent fraud and information security attacks, and whether you are a prospective, current, or former employee of ours. |
Inferences (Examples: inferences that can be drawn from any of the foregoing information, such as preferences, psychological trends, behavior, attitude, intelligence, or abilities) | We do not collect this information. | N/A | N/A | We do not compile composite profiles of individuals in order to make inferences from such profiles. |
II. Personal Information Disclosure
III. Sale of Personal Information
In the preceding twelve (12) months, we have sold the following categories of Personal Information, as defined in the table above, to our Affiliates, Independent Third Parties, and event sponsors and vendors:
- Identifiers;
- Internet Information; and
- Commercial Information.
Personal Information was sold for the following purposes:
- Marketing of our Services to you based on your interaction with our Sites;
- Displaying advertisements; and
- Marketing the services of Independent Third Parties.
eXp does not knowingly collect, process, disclose or sell the Personal Information of minors.
IV. Your Rights
Depending on where you live and subject to certain exceptions, you may have some or all of the following rights:
- Right to Know: The right to request that we disclose to you the Personal Information we collect, use, or disclose, and information about our data practices.
- Right to Request Correction: The right to request that we correct inaccurate Personal Information that we maintain about you.
- Right to Request Deletion: The right to request that we delete your Personal Information that we have collected from or about you.
- Right to Opt out of Targeted Advertising: The right to opt-out of the processing of your Personal Information for the purposes that may be considered “targeted advertising” under the U.S. Privacy Laws, including information obtained from your activities on nonaffiliated websites or online applications.
- Right to Non-Discrimination: The right not to receive discriminatory treatment for exercising your privacy rights.
- Right to Limit Sensitive Data Processing: The right to limit processing of certain categories of Personal Information based on the applicable state definition of Sensitive Personal Information. eXp does not process Sensitive Personal Information beyond what is expressly allowed under U.S. Privacy Laws.
- Right to Data Portability: You can request a transfer of Personal Information to you or a third party where we process the data based on your consent or a contract with you, and in a commonly used and machine-readable format
V. How to Make a Request
- Where to Send Your Request
Webform: Request Form
Email: send request to [email protected] with “U.S. Privacy Information Request” in the subject line
- Verifying Your Request
- Opting out of Targeted Advertising
- Responding to Your Request
We will confirm receipt of right to know and deletion requests within the timeframe specified under applicable U.S. Privacy Laws and will provide information as to how we will process such requests. We will respond to verified requests within the timeframes allowed by applicable U.S. Privacy Laws. Please note that we may only be required to respond to a verifiable request for access or portability twice per twelve (12) month period.
We are not required to: (1) retain any Personal Information about you that was collected for a single, one-time transaction if, in the ordinary course of business, that information about you is not retained; or (2) reidentify or otherwise link any data that, in the ordinary course of business, is not maintained in a manner that would be considered Personal Information.
We will comply with your requests free of charge. Please note, however, that we are permitted to charge a reasonable fee if requests are manifestly unfounded or excessive.
Copyright © 2024 eXp World Holdings, Inc. | All Rights Reserved.