california consumer privacy act supplemental notice

Effective: January 18, 2023

This supplemental privacy notice ("Notice") explains your rights as a California consumer regarding personal information that is subject to the California Consumer Privacy Act ("CCPA"). This Notice, which supplements the information contained in our Privacy Policy about Esurance's general privacy practices, applies only to California residents.

This Notice only describes Esurance's privacy practices with regard to personal information that is subject to the CCPA ("CCPA Information"). The Privacy Policy, and not this Notice, describes Esurance's privacy practices relating to personal information collected, processed, sold, or disclosed in connection with a financial transaction, which is not subject to the CCPA. This includes personal information collected, used, and shared in connection with getting an insurance quote, submitting an application for insurance, issuing or managing a policy, and servicing a claim. The Privacy Policy also includes other information about Esurance's privacy practices generally.

How we collect, use and share CCPA information

We collect CCPA Information about you in several ways and from several sources. For example, we collect information directly from you when you sign up as a guest user of our DriveSense® mobile application. We and service providers working on our behalf collect information from you when you use one of our websites, mobile apps, view our emails or otherwise engage with us through a computer or mobile device. We also collect personal information about you from third parties such as service providers, marketing companies and data providers.

We use your CCPA Information for business purposes including to market our products and services, to provide services such as our DriveSense® mobile application, and to perform analytics and research to improve, develop, and protect our websites, mobile apps, services and products.

We do not sell your CCPA Information, or any other personal information that we collect about you. We also do not share personal information for cross-context behavioral advertising as defined under California law. We may share your CCPA Information with third parties for business purposes or as permitted or required by law, including with service providers that provide marketing and advertising or other communications services, or that perform analytics and research to improve, develop, and protect our websites, mobile apps, services and products.

We collect, use and share the following categories of CCPA Information:

CCPA INFORMATION CATEGORIES EXAMPLES
PERSONAL IDENTIFIERS Name, alias, postal address, email address, unique personal identifier, online identifier, internet protocol (IP) address, phone number, date of birth, or other similar identifiers.
PERSONAL CHARACTERISTICS Age, race, ancestry, national origin, citizenship, religion or creed, marital status, gender, veteran or military status.
COMMERCIAL INFORMATION Service or product related information including policy coverage information, premiums, account name, policy number, payment history, claims history, records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies, account log-in, bank account number, credit or debit card number, other payment or financial information, health insurance information, driving record, credit information, medical history, or family member information.
INTERNET OR OTHER ELECTRONIC NETWORK ACTIVITY INFORMATION Information regarding your interaction with our website, application or advertisements, links you use or web pages you visit while visiting our site or applications, browser type, internet service provider (ISP), cookies, and mobile device information including device identifier or other device information, and location information.
GEOLOCATION DATA Physical location, movements, or trip tracking information.
PROFESSIONAL OR EMPLOYMENT INFORMATION Employment history or union membership.
EDUCATION INFORMATION Education records, grades or transcripts.
INFERENCES Inferences drawn from personal information to create a profile reflecting preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities or aptitudes.

Sensitive Personal Information: Some CCPA information we collect is defined under the law as sensitive personal information. Sensitive personal information we collect includes Social Security number, driver's license number, state identification card number, or passport number, customer account log-in, financial account number, debit card number, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account, precise geolocation information, personal health information, racial or ethnic origin, and religious beliefs or union membership.

We use sensitive personal information only as reasonably necessary to perform or maintain the services or provide goods you requested, to perform services on behalf of the business such as maintaining or servicing accounts, processing payments, to provide analytics services or similar services, to detect security incidents, resist malicious, deceptive, fraudulent, or illegal actions and to prosecute those responsible for those actions, to ensure customers and other peoples' physical safety, for short-term use such as non-personalized advertising as part of our current interactions, to verify or maintain the quality or safety of service, improve, upgrade or enhance service, or other reasons that do not require an opt-out of this use.

We do not market any products or services to children under the age of thirteen or knowingly collect any information from children under the age of thirteen. We do not knowingly sell or share for cross-context behavioral advertising the personal information of consumers under the age of sixteen. Our website is not intended for children.

How Long We Keep Your Information: We retain CCPA information in accordance with applicable laws or regulatory requirements and also for as long as necessary to fulfill the purposes for which it was collected and to fulfill the business or commercial purposes that are explained in this Privacy Statement.

California Consumer Privacy Act rights and choices

Under the CCPA, California residents have certain rights to request access to, correction of and deletion of CCPA Information about them, as well as other rights described below. California residents that have engaged in a financial transaction with us also have rights with regard to other personal information. For information about these rights, see "Reviewing or Modifying Your Information" in our Privacy Policy.

Right to Know and Access CCPA Information: You have the right to request the specific pieces of CCPA information we have collected about you and the right to know:

  • the categories of CCPA Information we have collected about you,
  • the categories of sources from which CCPA Information about you was collected,
  • the business purpose for collecting CCPA Information about you, and
  • the categories of third parties with whom we have shared CCPA Information about you.

Right to Deletion of CCPA Information: You have the right to request deletion of CCPA Information collected from you, subject to certain exceptions including that we need the personal information to:

  • Complete a transaction for which we collected the CCPA Information, provide a good or service you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you,
  • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities,
  • Comply with a legal obligation, or
  • Otherwise use your personal information, internally, in a lawful manner that is compatible with the context in which you provided the information.

Right to Correct CCPA Information: You have the right to request we correct any inaccurate information we have about you. We may request that you provide documentation to support your request and we will correct your information unless we determine that the personal information is more than likely accurate.

Non-Discrimination Rights: We will not discriminate against you for exercising any of your rights under the CCPA.

Verified Requests: To protect you and your CCPA information, we will only respond to requests to know, access, delete or correct that we have been able to properly verify through our authentication processes. To verify your identity, you will be asked to provide several pieces of personal information, such as name and demographic information, which we only use to verify your identity or authority to make the request.

Submitting a Request: To submit an access or deletion request, please click here to submit an online request or call us at 1-844-472-1759. To submit a correction request, please click here to submit an online request or call us at 1-844-864-8536. Responses to a verified request may take up to 45 calendar days, or longer depending on the nature of the request. If additional time is needed, we will notify you of the additional time. We may only respond to two access requests within a 12-month period. Requests from authorized agents must be submitted via the same online portal or toll-free number but to protect your privacy, consumers will be required to verify their identity directly with us via our online portal or toll-free number.

Consumer Request Metrics: The chart below lists the number of access and deletion requests Esurance received, complied with and denied from residents of California in 2021 along with the average amount of days it took to complete a request.

Metrics: 2021 Access My Data Requests for California Residents Quantity
Number of requests received 17
Number of Requests Complied with in whole or in part 7
Number of Requests Denied* 9
Average Days to Complete a Request 22
*We were unable to authenticate the requestor.
Metrics: 2021 Delete My Data Requests for California Residents Quantity
Number of requests received 66
Number of Requests Denied* 66
Average Days to Complete a Request 6
*Allstate's practice is to delete personal information after it is no longer needed for business purposes. These business purposes are explained in our Privacy Statement.