menu
California Privacy Policy

Last Updated: December 5, 2023

Introduction

Books-A-Million, Inc., Booksamillion.com Inc., BAM Card Services, LLC, 2nd and Charles, American Wholesale Book Company, and Yogurt Mountain, LLC (collectively "The Company", "we", "us", and "our") supplements the information contained in its Privacy Policy with this California Privacy Policy (the "California Privacy Policy"), which applies solely to all natural persons who reside in the State of California ("consumers" or "you"). We adopt this California Privacy Policy to comply with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations (collectively referred to as the "CCPA"). Any terms defined in the CCPA have the same meaning when used in this California Privacy Policy.

This California Privacy Policy does not apply to information excluded from the scope of the CCPA. Furthermore, this California Privacy Policy does not apply to employment-related personal information collected from you when you act as an employee, job applicant, contractor or similar individual to The Company. A separate notice to California applicants and employees will be made available by us separately

CCPA Notice at Collection

For the purposes of the CCPA, we currently collect the categories of personal information listed in the chart below:

Category Description
Identifiers Examples: Real name, alias, postal address, online identifier, Internet Protocol (IP) address, email address, account name, driver's license number, passport number, or other similar identifiers
Sold or Shared? We do not sell or share this category of personal information.
Personal information described in Cal. Civ. Code § 1798.80(e) Examples: Name, address, telephone number, passport number, driver's license or state identification card number, bank account number, or credit card number.
Sold or Shared? We do not sell or share this category of personal information.
Characteristics of protected classifications Examples: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, sexual orientation, veteran or military status)
Sold or Shared? We do not sell or share this category of personal information.
Commercial information Examples: Records of personal property, products or services (work, labor, and services, including services furnished in connection with the sale or repair of goods) purchased, obtained, or considered, or other purchasing or consuming histories or tendencies
Sold or Shared? We do not sell or share this category of personal information.
Internet or other electronic network activity information Examples: browsing history; search history; internet service provider (ISP); type of computer; operating system; type of web browser; URLs of any referring or exited webpages; information about your interaction with the Site or advertisements on it; data about which pages you visit; and the date and time of your visit
Sold or Shared? We do not sell or share this category of personal information.
Geolocation data Examples: Location data automatically collected during use of the Site; location data provided when locating stores; shipping and billing information; zip code
Sold or Shared? We do not sell or share this category of personal information.
Audio, electronic, visual, thermal, olfactory, or similar information Examples: Call center recordings and electronic communications with us
Sold or Shared? We do not sell or share this category of personal information.
Professional or employment-related information Examples: Work history, experience, and references
Sold or Shared? We do not sell or share this category of personal information.
Inferences Examples: Derivation of information, data, assumptions, or conclusions from facts, evidence, or another source of information or data drawn from any of the information identified above to create a profile about a consumer reflecting the consumer's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes
Sold or Shared? We do not sell or share this category of personal information.
Sensitive Personal Information Examples: Social Security number, driver's license number, state identification number, passport number, account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account, precise geolocation information, racial or ethnic origin, contents of mail, email, and text messages unless the business is the intended recipient of the communication, or health information
Sold or Shared? We do not sell or share this category of personal information.

**We only collect Sensitive Personal Information for legitimate business purposes appropriate for the use and disclosure of Sensitive Personal Information as defined in the California Privacy Laws, and do not otherwise use it to infer characteristics about you

Exclusions from Personal Information: Personal information does not include:

  • Publicly available information or lawfully obtained, truthful information that is a matter of public concern.
  • Consumer information that is deidentified or aggregated
  • Information excluded from the scope of the CCPA including, but not limited to:
    • Personal information collected, processed, sold, or disclosed subject to the Gramm-Leach-Bliley Act (GLBA) or the California Financial Privacy Act
    • An activity involving the collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living by a consumer reporting agency, a furnisher of information who provides information for use in a consumer report, and by a user of a consumer report provided that the agency, furnisher, or user is subject to regulation under the Fair Credit Reporting Act (FCRA).
    • Medical information governed by the Confidentiality of Medical Information Act or protected health information as governed by the U.S. Department of Health and Human Services pursuant to the Health Insurance Portability and Accountability Act of 1996 (HIPAA)
    • Personal information collected, processed, sold, or disclosed pursuant to the Driver's Privacy Protection Act of 1994

Categories of Sources

We have collected the Personal Information in this California Privacy Policy form you directly when you provide it to us, automatically as you navigate through our Sites, and from our business partners, as applicable.

Business or Commercial Purposes: We use the categories of personal information listed above to provide our products and services to you, to operate, manage, and maintain our business, and to accomplish other business and commercial purposes, including the following:

  • To process your purchases and returns;
  • To process your payments and refunds;
  • To detect fraud and prevent loss;
  • To provide you with information about our products and services;
  • To enable you to track the status of your purchase or return;
  • To establish and maintain your user account with us;
  • To allow you to contact us and facilitate your communication with us;
  • To manage our relationship with you;
  • To personalize your experience;
  • To enhance your experience in stores and online;
  • To authenticate you;
  • To present and improve content and functionality on our websites;
  • To provide and improve customer service;
  • To deliver products and services to you;
  • To comply with your instructions;
  • To conduct research and analysis;
  • To provide notice of changes to our websites or the produces and services we offer;
  • To administer a context, promotion, survey or other feature;
  • To respond to visitor, subscriber, and customer inquiries;
  • To market our products and services to you or to send you information about The Company; including our affiliates, or products or services that may be of interest to you;
  • To contact you when necessary;
  • For any purpose related to and/or ancillary to any one of the purposes and uses described in this Policy or The Company's general Privacy Policy;
  • To engage with you on social media;
  • To register you for your email or text message distribution lists;
  • To send you periodic emails or text messages;
  • To operate our business;
  • To ensure safety of person or property;
  • To ask you if you would like for us to share your information with third parties; and
  • In any other way we may describe when you provide the information.

Other Processing Activities: As permitted by applicable law, we may use all of the personal information that we collect in order to:

  • Comply with federal, state, or local laws;
  • Comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities;
  • Cooperate with law enforcement agencies concerning conduct or activity that we, a service provider, or a third party reasonably and in good faith believe may violate federal, state, or local law;
  • Exercise or defend legal claims; and
  • Collect, use, retain, sell, or disclose consumer information that is deidentified or in the aggregate consumer information.

Additional Data Collection and Uses: We will not collect categories of personal information other than those disclosed above without providing a new notice at collection. In addition, we will not use your personal information for any purpose other than those disclosed above. If we intend to use your personal information for a purpose that was not previously disclosed in the notice at collection, we will directly notify you of the new use and obtain consent from you to use it for the new purpose

DATA PRACTICES DURING THE LAST 12 MONTHS

Personal Information Collected: As described in this policy, we have collected the categories of personal information listed below during the preceding 12 months:

  • Identifiers
  • Categories of personal information described in the California Customer Records statute
  • Characteristics of protected classifications
  • Commercial information
  • Internet or other electronic network activity information
  • Geolocation data
  • Audio, electronic, visual, thermal, olfactory, or similar information
  • Professional or employment-related information
  • Inferences
  • Sensitive Personal Information

Categories of Sources: We have collected the personal information identified in this Policy from you when you provide it to us, automatically as you navigate through our Sites, and from our business partners and service providers, as applicable.

Business and Commercial Purpose for Collecting: We have collected the categories of personal information listed above for the purposes listed in the "Business or Commercial Purposes" section above.

Categories of Personal Information Disclosed for a Business Purpose. We have disclosed for a business purpose the categories of personal information listed below during the preceding 12 months:

  • Identifiers
  • Categories of personal information described in the California Customer Records statute
  • Characteristics of protected classifications
  • Commercial information
  • Internet or other electronic network activity information
  • Geolocation data
  • Audio, electronic, visual, thermal, olfactory, or similar information
  • Professional or employment-related information
  • Inferences
  • Sensitive Personal Information

We have disclosed each category of personal information to the following categories of third parties: (1) corporate parents, subsidiaries, and affiliates; (2) advisors (accountants, attorneys); (3) service providers (data analytics, data storage, mailing, marketing, payment processing, website and platform administration, technical support); (4) operating systems and platforms; (5) advertising networks; (6) internet service providers; and (7) social networks.

Prior to disclosing any personal information to a service provider or contractor for a business purpose, we enter into a written contract which describes, among other things: (1) the specific purpose which the personal information can be used by the service provider or contractor to perform the services specified in the contract; (2) requires the service provider or contractor to keep any personal information confidential; (3) prohibits the service provider or contractor receiving the personal information from retaining, disclosing, or using the personal information for any purpose other than performing and providing services under the contract; (4) provides us the right to take reasonable and appropriate steps to ensure that the service provider or contractor uses personal information in accordance with contractual terms

No Personal Information Sold or Shared: We do not sell or share your personal information and have not sold or shared categories of personal information to third parties during the preceding 12 months. We will not sell your personal information unless we modify this California Privacy Policy and take additional steps as may be required under the CCPA

NOTICE OF FINANCIAL INCENTIVE

In some instances, we may offer discounts, coupons, and other benefits on products and services by joining our email subscription lists, our 2nd & Charles Rewards Program, or other promotions. The availability of these promotions or offerings to you at any given time will vary. If and when we offer such programs, we may ask for your personal data (such as your name, email address, or phone number) as a prerequisite to your participation and opt-in to our programs. There is no obligation to opt-in and you may opt-out at any time.

The value of any financial incentive we offer is reasonably related to the value of any personal information you provide to us. We estimate the value of your personal information by considering various factors including, without limitation, the expenses we incur from collecting your personal information and/or providing the financial incentive to you, the revenue generated by your use of the financial incentive, and any improvements we can make to our products and services based on aggregating information obtained through the financial incentive program. Please note that we may provide additional terms that apply to a particular financial incentive. If applicable, those terms will be presented to you at sign up.

How to opt-in. You may choose to receive these financial incentives by opting-in on our Sites and providing personal information when the option is presented to you.

How to withdraw: You have the right to withdraw from the financial incentive at any time. You may exercise that right by contacting us via the "Contact Us" details at the end of this Policy. If you opt-out, we will not reduce the value of any financial incentives you previously received from us.

CALIFORNIA CONSUMER RIGHTS AND CHOICES

The CCPA gives consumers specific rights regarding their personal information. This section describes your rights and how to exercise those rights. You may submit these requests to us as described below, and we honor these rights where they apply

Right to Know: You have the right to request: (1) the specific pieces of personal information we have collected about you; (2) the categories of personal information we have collected about you; (3) the categories of sources from which the personal information is collected; (4) the categories of personal information about you that we have sold and the categories of third parties to whom the personal information was sold; (5) the categories of personal information about you that we disclosed for a business purpose and the categories of third parties to whom the personal information was disclosed for a business purpose; (6) the business or commercial purpose for collecting, disclosing, or selling personal information; and (7) the categories of third parties with whom we share personal information.

Submission Instructions. You may submit a request to know via a toll-free telephone call to 1-800-201-3550 or [email protected].

Verification Process. We are required by law to verify the identities of those who submit requests to know, and our verification process is described in detail below. We will inform you if we cannot verify your identity

  • If we cannot verify the identity of the person making a request for categories of personal information, we may deny the request. If the request is denied in whole or in part for this reason, we will provide a copy of, or direct you to, our privacy policy
  • If we cannot verify the identity of the person making the request for specific pieces of personal information, we are prohibited from disclosing any specific pieces of personal information to the requestor. However, if denied in whole or in part for this reason, we will evaluate the request as if it is seeking the disclosure of categories of personal information about the consumer
  • If there is no reasonable method by which we can verify the identity of the requestor to the degree of certainty required, we will state this in our response and explain why we have no reasonable method by which we can verify the identity of the requestor

Response Process. Upon receiving a request to know, we will confirm receipt of the request within 10 business days and provide information about how we will process your request. The information provided will describe our verification process and when you should expect a response from us (unless we have already granted or denied the request). In general, we will respond to the request within 45 calendar days from the day we receive it; but, if necessary, we may take up to an additional 45 days to respond to your request. If an extension is needed, we will notify you of the extension and explain the reasons that responding to your request will take more than 45 calendar days

Once verification is complete, we will associate the information provided by you in the verifiable consumer request to any personal information previously collected by us about you. We will promptly take steps to disclose and deliver, free of charge to you, the information requested. We will provide an individualized response to requests regarding categories of personal information as required by applicable law; but, we may refer you to our general practices outlined in this Policy when our response would be the same for all consumers and all the information that is otherwise required to be in a response is presented here

If you do not have a password-protected account with us, we may respond to a request to know related to household personal information by providing aggregate household information. If all consumers of a household jointly request access to specific pieces of personal information for the household, we will comply with the request if we can verify the identity of each consumer

Delivery. Except as otherwise provided by applicable law, the information will be provided in writing and may be delivered through your account with us. If you do not maintain an account with us, we will respond by mail or electronically (at your option) in a portable and, to the extent technically feasible, readily-useable format that allows you to transmit the information to another entity. Alternatively, we may offer a secure self-service portal for consumers to access, view, and receive a portable copy of their personal information. If we do not take action on your request, we will, without delay and, at the latest, within the time period permitted for our response, inform you of the reasons that we did not take action and any rights you may have to appeal the decision

Limitations. We are committed to responding to requests to know in accordance with applicable law. However, your rights are subject to the following limitations:

  • We are only required to respond to requests to know twice in a 12-month period
  • We are prohibited from disclosing Social Security numbers, driver's license numbers, other government-issued identification numbers, financial account numbers, health insurance numbers, medical identification numbers, account passwords, security questions and answers, or unique biometric data generated from measurements or technical analysis of human characteristics

Denials. If we deny a verified request to know specific pieces of personal information, in whole or in part, because of a conflict with federal or state law, or an exception under applicable law, we will inform the requestor and explain the basis for the denial. If the request is denied only in part, we will disclose the other information sought by the consumer

Right to Delete:You have the right to request the erasure/deletion of certain personal information collected, sold, shared or maintained by us.

Right to Limit:In certain circumstances, you have the right to limit the use and disclosure of sensitive personal information. Our use of your sensitive personal information is solely for business purposes and not for those purposes for which a consumer may exercise a right to limit the use or disclosure under the CCPA. Therefore, we include this disclosure of information for information purposes only.

Right to Opt-Out of Sale/Sharing: You have the right to direct a business that sells or shares personal information about you to third parties to stop doing so. We do not sell or share any personal information as defined by the CPRA. Therefore, we include this disclosure of information for informational purposes only

Right to Correct: You have the right to request that we correct inaccurate personal information that we maintain about you. Our goal is to keep your personal information accurate, current, and complete.

Other California Privacy Rights: California's "Shine the Light" law (Civil Code Section § 1798.83) permits California residents who are users of our Sites to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. We do not disclose your personal information for direct marketing purposes

How to Submit Requests to Know, Requests to Delete, and Requests to Correct

You may submit a Request to Know, Request to Delete, or Request to Collect by either: (1) via a toll-free telephone call to 1-800-201-3550 or (2) by email to [email protected].

Verification Process

We are required by law to verify the identities of those who submit Requests to Know, Requests to Delete, or Requests to Correct. We will take steps to verify your identity before granting you access to such personal information or acting on your request to exercise your rights as outlined below.

A verifiable consumer request must provide sufficient information that allows us to reasonably verify that you are the person about whom we collected information. Whenever feasible, we will verify your identity by matching the identifying information provided by you in the request to the personal information we may already maintain about you. As part of this process, we ask that you provide the following information when submitting your request: name, telephone number, and email address. We may also request the dollar amount of your most recent purchase in order to verify your request

You may designate an authorized agent to make a Request to Know, Request to Delete, or Request to Correct on your behalf. If you use an authorized agent to submit a request, we require the authorized agent to provide proof that the consumer gave the authorized agent signed, written permission to submit the request. We may also require you to verify your identity directly with us and you to directly confirm with us that you provided the authorized agent permission to submit the request. We will inform you if we cannot verify your identity

  • If we cannot verify the identity of the person making a Request to Know specific pieces of personal information, we are prohibited from disclosing any specific pieces of personal information to the requestor. However, if denied in whole or in part for this reason, we will evaluate the request as if it is seeking the disclosure of categories of personal information about the consumer. If we still cannot verify the request, and the request is denied in whole or in part, we will provide a copy of, or direct you to, our Privacy Policy.
  • If we cannot verify the identity of the person making a Request to Delete or Request to Correct, we may deny the request and inform the person making the request that their identity cannot be verified.

Response Timing

Upon receiving a Request to Know, Request to Delete, or Request to Correct, we will confirm receipt of the request within 10 business days and provide information about how we will process your request. The information provided will describe our verification process and when you should expect a response from us (unless we have already granted or denied the request). We will use a two-step process for online requests to delete in which you must first, clearly submit the request to delete and then second, separately confirm that you want your personal information deleted. In general, we will respond to the request within 45 calendar days from the day we receive it; but, if necessary, we may take up to an additional 45 days to respond to your request. If an extension is needed, we will notify you of the extension and explain the reasons that responding to your request will take more than 45 calendar days

Response Process

If you have an online account with us, we may deliver our written response to that account along with any requested personal information that may be responsive to your request in a portable and, to the extent technically feasible, readily usable format. If you do not have a password-protected account with us, we will deliver our written response and any requested personal information that may be responsive to you by mail or electronically, at your option. The response we provide will also explain the reasons we cannot comply with a request, if applicable.

Limitations

We are committed to responding to requests in accordance with applicable law. However, your rights are subject to certain limitations including, but not limited to, the following: we are not required to delete your personal information if it is necessary for us (or our service providers) to maintain your personal information in order to:

  • We are only required to respond to Request to Know twice in a 12-month period
  • A response to a Request to Know may be limited to the 12-month period preceding receipt of the request if it would be impossible, involve disproportionate effort, or the request is for data for a specific time period
  • We are prohibited from disclosing certain pieces of personal information in response to a Request to Know including, but not limited to, Social Security numbers, driver's license numbers, and financial account numbers.

Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights including, but not limited to, by:

  • Denying you goods or services
  • Charging you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties
  • Providing you a different level or quality of goods or services
  • Suggesting that you may receive a different price or rate for goods or services or a different level or quality of goods or services

Updates and Changes to this Policy

We reserve the right, at any time and without notice, to add to, change, update, or modify this California Privacy Policy to reflect any changes to the way in which we treat your personal information or in response to changes in law. Should this California Privacy Policy change, we will post all changes we make on this page. Any such changes, updates, or modifications shall be effective immediately upon posting on the Sites. The date on which this policy was last modified is identified at the beginning of this California Privacy Policy

You are expected to, and you acknowledge and agree that it is your responsibility to, carefully review this California Privacy Policy prior to using the Sites, engaging with us on social media, or communicating with us, from time to time, so that you are aware of any changes. Your continued use of the Sites, engaging with us on social media, or communicating with us in any format after the "Last Updated" date will constitute your acceptance of and agreement to such changes and to our collection and sharing of your personal information according to the terms of the then-current California Privacy Policy.

Contact Us

For more information, or if you have any questions regarding this California Privacy Policy or wish to exercise your rights, you may contact us using the information below, and we will do our best to assist you. Please note, if your communication is sensitive, you may wish to contact us by postal mail or telephone.

In Writing: Books-A-Million Customer Service
402 Industrial Lane
Birmingham, AL 35211
By Telephone: (800) 201-3550
By Email: [email protected]