Theraleaf Dispensary in San Jose Logo
Theraleaf Dispensary in San Jose Logo

1. Introduction

Welcome to the THERALEAF family of sites and software! This THERALEAF Privacy Policy (“Privacy Policy”) describes how we collect, use, and share information about you when you access or use:

a) (i) THERALEAF’ websites, portals, applications (including mobile applications), channels, software, and widgets (including as embedded on sites owned by third parties), and (ii) THERALEAF’ social media pages and channels (collectively, the “Websites”); and

b) any services, features, media, functions, content, tools, and links contained in or offered via the Websites (collectively, the “Services”).

We may also post other privacy policies or statements on our Websites or Services where applicable. To the extent those other privacy policies or statements conflict with this Privacy Policy, this Privacy Policy shall control to the extent of the conflict with regard to the Websites or Services.

From time to time, we may make changes to this Privacy Policy. When we make such changes, we will do our best to notify you by email, push notification or in-app notification, or a prominent notice on our Websites.

Capitalized terms not defined herein shall have the meanings defined in the THERALEAF Terms of Use.

2. Information We Collect

We may collect certain types of information in order to better provide our Websites and Services:

Information You Provide: We collect information you provide us, such as:

Information Created When You Use Our Websites and Services:

Information Collected from Other Sources:

3. How We Use Your Information

We may use your information to:

4. How We Share Your Information

We generally do not share your personal information, except in the following limited circumstances:

  1. We may share your personal information at your direction, including with third parties such as Retailers to fulfill orders or requests you place on our Websites or through our Services. Similarly, by participating in one of our campaigns, such as a referral campaign, you direct us to share your information as contemplated in that campaign.
  2. If you use our Websites or Services to place an order for cannabis products from a Retailer that has designated a point-of-sale service provider we integrate with as its service provider, we will share information from or about you with these third-party service providers so that they may facilitate your requested transaction, including by providing information such as tax calculations and product availability as well as real-time status updates. The applicable point-of-sale service provider may also use your order-related information as required to process and report cannabis transactions under applicable law. Most of your order information will only be shared with a point-of-sale service provider after you submit your order, but we will share your delivery zip or postal code, THERALEAF internal user identification number, certain Medical Marijuana Information, and requested products, and any other information required to provide accurate tax calculations in the jurisdiction in which your order is placed, in advance of order submission in order to obtain tax calculations, product availability, and other information relevant to your potential order. Retailers may also directly share your order-related information with their point-of-sale service provider for the fulfillment, processing and reporting of your order.
  3. If you use our Websites or Services to place an order for cannabis products from a Retailer that has designated a loyalty program service provider we integrate with as its service provider, we will share information from or about you with these third-party service providers so that they may facilitate your requested transaction, including by enabling you to sign up for rewards programs or use rewards you have previously earned with the same Retailer. The applicable loyalty program service provider will also use information about your order to enable you to earn rewards for orders placed via our Websites or Services.
  4. We may share your information with service providers who perform services on our behalf. For example, we may share your information to provide some of the features and services that are available through our Websites or Services, such as communications and hosting services, network security, technical and customer support, tracking and reporting functions, quality assurance testing, payment processing, marketing and promotional features, identification verification, product listings, and brand management. To the extent that you have the legal right to limit our sharing of your information, for example, if you choose not to receive personalized marketing, you may exercise your rights.
  5. In the event that THERALEAF is or may be acquired by or merged with another company or involved in any other business deal (or negotiation of a business deal) involving sale or transfer of all or part of our business or assets, we may transfer or assign your information as part of or in connection with the transaction and such acquirer or merged entity may thereafter utilize your personal information in accordance with this Privacy Policy. Finally, in the event of insolvency, bankruptcy, or receivership, information may be transferred as a business asset.
  6. Some of our Websites utilize framing techniques and technology (for example, iFrames) to serve content to you from our third-party service providers and other third parties. In such cases, you are sharing your information directly with the applicable third party. For example, this can occur when you place an order on shop.theraleafsjc.com. When placing an order on shop.theraleafsjc.com, you are sharing your payment information with Shopify, which processes your payment on our behalf. Use of your payment card information in relation to orders placed on shop.theraleafsjc.com is governed by the Privacy Policies of Shopify, which helps process those transactions. For more information, see: https://www.shopify.com/legal/privacy. Similarly, some portions of our Websites and Services use Google Services and APIs and this Privacy Policy therefore incorporates Google’s Privacy Policy by reference.
  7. If you’re a Canadian user, our Websites may also utilize framing techniques and technology when you use a third-party payment processor in order to directly pay a retailer listed on the Website. In those instances, your information is provided directly to the applicable payment processor and/or retailer, and the applicable payment processor and/or retailer’s Privacy Policy governs the information which you provide to them.
  8. If you log into our Websites or Services through a third-party service (e.g., Facebook, Google and Apple), we and the third party may receive and share information about you and your use of our Websites and Services. You should review the privacy policies of these third-party services for more information.
  9. We may share user information in the aggregate with third parties, including with the general public in our marketing materials and in our non-public discussions with third parties such as advertisers, brand managers, and content distributors. For example, we may disclose the number of users that have been exposed to or clicked on advertisements or certain products available in the Websites or Services, or the general characteristics of such users.
  10. We may disclose information from or about you to government officials, law enforcement or private parties if we believe that such disclosure: (i) is reasonably necessary to comply with federal, state, or local legal process and legally binding law enforcement instructions and orders, such as a search warrant, subpoena, statute, judicial proceeding, or other legal process served on us; (ii) is helpful to prevent, investigate, or identify possible wrongdoing in connection with our Websites or Services; or (iii) protects our rights, reputation, property, or that of our users, affiliates, clients, partners, or the public. We may disclose your information if we believe doing so is appropriate or necessary to prevent any liability, or fraudulent, abusive, or unlawful uses, or to protect THERALEAF, our Websites and Services, or any rights, property, or personal safety of THERALEAF or others.
  11. We may share information from or about you (such as your age and gender, your devices, and your use of the Websites and Services) with Retailers, for example, when you place orders via any of our Websites or Services, including for the avoidance of doubt via any embedded order functionality on third party websites. Keep in mind that Retailers may see your Public Content and receive information about orders you place with them as described in our Information We Collect section above, regardless of your settings.
  12. If you are an employee or agent of a Retailer, we may collect and share information from or about you (such as geolocation data or other personal information) with Retailers, in which case THERALEAF is acting as service provider of the Retailer.

Additionally, if you make a phone call or otherwise contact a Retailer through or in connection with your use of our Websites or Services, we may share basic information about your call or chat with the Retailer that you contacted, such as the date and time of your call or other contact method and your phone number or other applicable contact information. Your phone number and basic information about your call or other contact method would have been available to the Retailer had you contacted them directly, and not through our Websites or Services. You may be able to limit our ability to collect and share your phone number through your phone’s settings or phone service provider.

Your Medical Marijuana Information is not used for marketing purposes, other than in the aggregate, or at your request, or with your consent.

5. Cookies and Other Web Technologies

We may use cookies, web beacons, tags, scripts, local shared objects such as HTML5, advertising identifiers (including mobile identifiers such as Apple’s IDFA or Google’s Advertising ID) and similar technology in connection with your use of our Websites or Services. In addition, we may allow third parties to incorporate their third-party SDKs, cookies or other technologies into our Websites and Services to perform services on our behalf, such as analytics or advertising services.

For more information about how we use cookies and other web technologies, please see our Cookie Notice.

6. Managing And Deleting Your Information

* If you are a resident of California, please see our Your California Rights; Privacy Notice For California Residents section below.

Your Right To Access and Manage Your Information

You have the right to access, review, correct, or update the information you provide to us as part of your registration for a User Account with our Websites or Services.

You can exercise this right and manage your own information by updating your User Account directly, visiting the Privacy Settings page or by submitting a data request to us pursuant to our Data Requests section below. You are responsible for the information you provide to us, and you should maintain the accuracy of the personal information in your User Account so that we can best provide products and services to you.

You may also be able to disallow our use of certain location data through your device or browser settings, for example, by disabling “Location Services” for the THERALEAF application in iOS privacy settings. Please note, however, that disabling Location Services may adversely impact your experience with the functionality of our Websites or Services, and enabling such services may be necessary in some cases to allow certain transactions.

Your Right To Delete Your Information

You have the right to delete certain personal information you provide to us as part of your registration for a User Account with our Websites or Services, or that you otherwise submit to us, for example, through our Websites or Services. Keep in mind, we may need this information to provide account management and access, and if you choose to delete information, you may not be able to take advantage of certain features of our Websites and Services. Should you choose to delete information, you can exercise this right by submitting a data request to us pursuant to our Data Requests section below. We will never discriminate against you should you choose to exercise these rights.

In some circumstances, we may retain information about you for legitimate business or legal purposes, or for any purposes authorized under this Privacy Policy unless prohibited by law. For example, we may retain information to prevent, investigate, or identify possible wrongdoing in connection with our Websites or Services, or to comply with legal obligations. Some information may persist in a limited internal capacity for internal administration, such as in backup files maintained for data integrity and disaster recovery. We strive to store your information no longer than necessary, and will take steps to delete your information where reasonably possible.

You also cannot delete information associated with past orders and purchases because we, and third-party businesses listed on our Websites or Services, may be required to maintain records of orders and purchases for a specified period pursuant to applicable federal, provincial, state, or local law. Also, any public postings or other communications you have made on our Websites or Services, such as in forums or blogs, generally cannot be removed, so please be mindful of the information you include there.

Customer Data

Third-party businesses like Retailers who use our Websites or Services may submit electronic data or information they possess about their own customers to us (“Customer Data”) for various purposes, including hosting and processing. Customer Data may include personal information, including, but not limited to, the name, location, and e-mail address of such customer. Any uses of the Customer Data by THERALEAF are conducted pursuant and subject to the terms of THERALEAF’ Terms of Use and this Privacy Policy, or as required by law.

If your personal information has been submitted to us by a third-party business using our Websites or Services as Customer Data and you wish to exercise your rights to access, revise, or delete such data, please inquire with the relevant third-party business and submit a data request to us pursuant to our Data Requests section below.

Please note that we take your privacy seriously and therefore take steps to safeguard your personal information, including ensuring an adequate level of data protection in accordance with international standards.

If you are not satisfied with how we have stored or processed your personal information, please contact us pursuant to our Contact Information section below.

Data Requests

If you would like to access, revise, or delete any personal information, please submit a written data request by contacting us pursuant to our Contact Information section below.

We will take such steps as we deem necessary to verify your identity before proceeding with your data request. For example, we may ask you for a piece of information held in your records that you might reasonably be expected to know. We cannot disclose personal information pursuant to a data request to anyone other than the individual in question.

Once any queries around the information requested have been resolved, copies of the information will be sent to you electronically wherever possible or, if this is not technically possibly, by mail.

If you submit multiple data requests and these data requests are excessive or manifestly unfounded, we will charge $20.00 to cover the administrative costs involved in dealing with each data request. In extreme circumstances, we reserve the right to refuse your data requests if they are excessive or manifestly unfounded.

We will attempt to respond to proper and confirmed data requests within the timeframe required by applicable law. If you are not satisfied with the way your data request was handled, you may refer your data request to your state (if in the US) or country’s data protection authority. In the European Economic Area (EEA), any such request should be directed to the appropriate Data Protection Authority in the EU Member States and in Iceland, Liechtenstein, and Norway.

Your Right To Cancel Or Modify Marketing Communications

You have the right to cancel or modify the e-mail marketing communications you receive from us. You can exercise this right by following the instructions contained within our promotional e-mails or, in some cases, by logging into your User Account and changing your communication preferences. Please note that this will not affect subsequent or different subscriptions--if your opt-out preferences are limited to certain types of e-mails, the opt-out will be so limited.

While you can manage some of your e-mail preferences, please note that you cannot opt out of receiving certain administrative, transactional, or legal messages from THERALEAF which we may send in the course of legitimate business if you are signed up for a User Account and/or use certain features. However, such announcements can be terminated by asking us to close your User Account.

You also have the ability to modify certain personalized THERALEAF marketing you receive on third-party websites by visiting the Privacy Settings page. When we display THERALEAF advertising on other websites, we may use personal information for the purpose of showing you more relevant advertising that is selected based on information we have obtained or inferred over time based on your activities on our platform (“targeted advertising” or “cross-context behavioral advertising”). When you opt out of this personalized advertising, you may still see THERALEAF advertising on other websites, but it may be less relevant to you.

7. Your California Rights; Privacy Notice For California Residents

This California Privacy Notice (“CA Privacy Notice”) supplements the information contained in the Privacy Policy and applies solely to visitors, purchasers, users, and others who reside in the State of California (“California Consumers” or “you”), and who use our Services, as referenced above in the Privacy Policy. In the event of a conflict between this CA Privacy Notice and the Privacy Policy, this CA Privacy Notice will prevail only to the extent of resolving such conflict.

Information We Collect About Our California Consumers

Personal information covered under this CA Privacy Notice does not include aggregated information or other information that cannot reasonably be linked to you. In the past twelve months, regardless of whether you have a User Account or were logged in to any such account, we may have collected the following California Consumer Privacy Act (“CCPA”) categories of personal information about you, which we use and share as described in the following chart:

Categories of Personal Information We May Have Collected:

Examples of How We Use this Personal Information Include:

The Persons We May Share this Personal Information with Include:

Identifiers, such as your name, signature, phone number, and email address, and identifiers tied to the specific technology you’re using to access the THERALEAF products

Demographic information, such as your gender

Biometric information, such as selfies in connection with WM Orders

Medical information, such as medical cannabis recommendation data, if you choose to share it

Commercial Information, such as records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies

Internet or other network activity information, such as information regarding your interactions with content (what you click, how much time you spend viewing it, the way you interact with ads and more)

Geolocation data and other location-related information, such as the location of your device

Audio, visual, or similar information, such as selfies you upload in connection with placing an order or audio or visual recordings of user testing sessions

Professional-, employment-, and education-related information, such as job title and degree information you provide in response to a survey

Financial information, such as your income level, if you choose to provide it

Inferences based on the foregoing categories, which may include your preferences and interests, such as inferring that you like flower when you frequently search for flower products

Providing, personalizing (including through our business partners and other clients), and improving the THERALEAF products

Communicating with you

Performing data analysis, market research, and research and development

Complying with legal obligations, protecting the THERALEAF Products; and defending our legal rights

Our affiliates

Our service providers

Our business partners, such as Retailers, brands, partners who use our analytics or data services, researchers and academics

Service providers of our business partners, such as point-of-sale systems serving Retailer clients

New owners if ownership or control of all or part of the THERALEAF products or their assets changes

Law enforcement or other third parties in connection with legal requests

Other third parties to whom you consent sharing your info, such as services that integrate with our services

Your Rights As A California Consumer

As a California Consumer, you have certain rights regarding your personal information. You have the right to request from us the following information: (1) the specific pieces of personal information we have collected about you; (2) the categories of personal information we have collected about you; (3) the categories of sources from which your personal information is collected; (4) the categories of personal information we sold or disclosed for a business purpose; (5) the categories of third parties to whom your personal information was sold or disclosed for a business purpose; and (6) the business or commercial purpose for collecting or selling your personal information.

You also have the right to correct your personal information or request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies. To the extent that we use information defined as sensitive personal information, THERALEAF limits our use of such information only to that which is necessary for providing our Websites and Services.

How To Exercise Your Rights Under California Law

To exercise any of the rights described above, please submit a verifiable request by contacting us pursuant to our Contact Information section below. Please note that THERALEAF must verify the identity of the requestor. You may designate an authorized agent to make a request on your behalf by providing proof of a valid power of attorney, your valid government issued identification, and the authorized agent’s valid government issued identification. Upon receiving your request, we will send you a follow-up email asking you to provide and certify information necessary to verify your identity. We cannot respond to requests where the identity and authority of the requestor cannot be confirmed.

You are not required to have a User Account with us in order to submit a request and we will only use personal information provided in a request to verify the requestor’s identity or authority to make such a request. Please note you may only make a verifiable request for access or data portability twice within a 12-month period.

Any disclosures we provide will only cover the 12-month period preceding the verifiable request’s receipt. If we are unable to comply with a request, we will inform you of the reason why.

Personal Information Sold Or Shared

We do not “sell” the personal information we collect in the traditional sense, and we will not do so without providing you the opportunity to opt out.

However, California law defines “sale” broadly in such a way that the term sale may include sharing personal information for the purpose of displaying advertising that is selected based on information we have obtained or inferred over time based on an individual’s activities across businesses or distinctly-branded websites, applications, or other services (“targeted advertising” or “cross-context behavioral advertising”). Like most online publishers, we use these information and inferences to enable us to provide the Websites and Services, to offer personalized features, for tracking and analytics, and to show relevant offers to you directly on our own Websites and across the web, including at your request.

To opt out of targeted advertising, you can visit the Privacy Settings page and deselect “Personalized advertising”.

Non-Discrimination Policy

California Consumers who choose to exercise the rights described in this section will not be denied any goods or services, charged different prices or rates, or be provided a different level or quality of goods or services unless those differences are related to your personal information.

Shine the Light Disclosure

California law allows you to request and obtain from us once a year, free of charge, a list of the third parties to whom we have disclosed your personal information (if any) for their direct marketing purposes in the prior calendar year, as well as the types of personal information disclosed to those third parties. THERALEAF does not share personal information with third parties for their own direct marketing purposes without your prior consent. You can also prevent disclosure of your personal information to third parties for their direct marketing purposes by withholding consent.

8. Children Using The Websites Or Services

Our Websites and Services are intended for adults only and require that users be no less than eighteen (18) years of age. Please note that certain of our Websites and Services require you to be at least twenty-one (21) years of age to access and use such Websites and Services. Please check the applicable terms and conditions for such Websites and Services for further information. Individuals under the age of eighteen (18) (or twenty-one (21) for applicable Websites and Services) are prohibited from creating a User Account and profile, accessing our Websites or Services, and/or ordering products on our Websites or Services. If you become aware that an underage user has created a User Account using false, stolen, or otherwise misleading information, please contact us immediately pursuant to our Contact Information section below.

9. Security

We have implemented a number of measures to help protect your personal information. These measures include, but are not limited to, minimizing access to personal information to employees with a need to access it, and encrypting personal information provided through our Websites using SSL/TLS. Please note, however, that while we endeavor to keep our security measures up-to-date, no data security measures can guarantee complete security.

In addition, there are steps you can take to help protect your information, including choosing a robust password for your device and/or User Account that nobody else knows or can easily guess, and keeping your log-in and password private.

THERALEAF is not responsible for the actions or activities of unauthorized third parties who compromise our security measures, and so we cannot be responsible for such unauthorized party’s access, acquisition, or distribution of your personal information. If you believe your personal information has been compromised, we encourage you to notify us immediately pursuant to our Contact Information section below.

Please note that we retain some personal information about you in accordance with our record retention policies, as required by law, or as required for the achievement of the purposes of the processing as mentioned above (e.g., to enforce any agreements or provide a product/service).

It is important for you to protect against unauthorized access to your User Account, password, and computer. Be sure to sign off of your User Account when finished, especially if you are using a shared computer. You can learn more about steps you can take to protect your personal information at: https://www.consumer.ftc.gov/articles/0272-how-keep-your-personal-information-secure.

10. International Data Transfer

We share information globally, both internally within THERALEAF and externally with our partners around the world. If you are located outside of the United States, please be aware that information we collect, including your personal information, may be transferred to, and processed, stored, and used within the United States. This transfer is necessary to provide our Websites and Services.

The United States may have data protection laws that are different from those of your country. However, we take measures to ensure that any such transfers comply with applicable data protection laws and that your personal information remains protected to the standards described in this Privacy Policy.

11. Contact Information

For any questions related to this Privacy Policy or to submit a data request, you may contact us via e-mail at contact@THERALEAFsjc.com, by phone at 1-833-660-0420, or write to us at the following address: Theraleaf, Attn: Legal Department, 1014 Timothy Drive, San Jose CA 95133, United States of America.

For other customer service inquiries, please contact us via email at contact@THERALEAFsjc.com or by phone at the phone number above.