NFL FLAG Privacy Policy 

Last Updated: September 19, 2023 
 

TABLE OF CONTENTS 

1. INTRODUCTION 

2. CHILDREN UNDER THE AGE OF 13

3. INFORMATION WE COLLECT ABOUT YOU AND HOW WE COLLECT IT

4. THIRD PARTY USE OF COOKIES AND OTHER TRACKING TECHNOLOGIES

5. HOW WE USE YOUR INFORMATION

6. DISCLOSURE OF YOUR INFORMATION

7. ADDITIONAL CALIFORNIA NOTICES

8. YOUR STATE DATA PRIVACY RIGHTS

9. YOUR INTERNATIONAL PRIVACY RIGHTS

10. DATA SECURITY

11. DATA RETENTION

12. TRANSFERRING YOUR PERSONAL INFORMATION

13. CHANGES TO OUR PRIVACY NOTICE

14. CONTACT INFORMATION

 

1.                  Introduction 

RCX Sports LLC (“RCX”, “we”, “our” or “us”) respects your privacy. We know that your privacy is important to you, and we want you to know that it is important to us too. As a result, we are providing this Privacy Notice (“Privacy Notice”) to you.

We operate the website available at www.nflflag.com (the “NFL FLAG Website”) as an extension of the youth flag football program known as “NFL FLAG” (“NFL FLAG”) that we manage under licenses from NFL Properties LLC (“NFLP”) in collaboration with NFLP, the National Football League (the “NFL”), The National Football League Foundation, NFL Enterprises LLC, NFL Productions LLC, NFL International LLC, the professional football teams that comprise The National Football League now or in the future, NFL Ventures, Inc. and NFL Ventures, L.P., and their respective affiliates (collectively, the “NFL Entities”). All information collected under this Privacy Notice shall be jointly owned by us and the NFL Entities, will be shared with the NFL Entities and may be used for the purposes set forth in this Privacy Notice.

We collect, use, and/or otherwise process certain Personal Information (defined in Section 3) about you. When we do so we are subject to various laws, including in the United States and Canada. This Privacy Notice describes the types of information we may collect from you or that you may provide in connection with NFL FLAG, including when you visit the NFL FLAG Website or the official NFL FLAG pages, posts or accounts on social media platforms (each, a “Social Media Presence”), and our practices for collecting, using, maintaining, protecting and disclosing that information. The NFL FLAG Website and each Social Media Presence may be referred to as a “Website” and collectively as the “Websites”. This Privacy Notice is intergrated into our Terms of Use (“Terms of Use”), located at https://nflflag.com/terms.

This Privacy Notice applies to information we collect from you, including information we collect:

  • On the NFL FLAG Website;
  • Through our Social Media Presences;
  • In email, text and other electronic messages between you and the NFL FLAG Website or Social Media Presences; and
  • When you interact with our advertising and applications on third-party websites and services, if those applications or advertising include links to this Privacy Notice.

This Privacy Notice does not apply to information collected by any third party, including through any application or content (including advertising) that may link to or be accessible from or on a Website.

Please read this Privacy Notice carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, you must not use the Websites. By accessing or using a Website, you agree to this Privacy Notice. This Privacy Notice may change from time to time. Your continued use of any Website after we make changes is deemed to be acceptance of those changes, so please check this Privacy Notice periodically for updates.

2.                    Children Under the Age of 13

The Websites and services are intended for general audiences. We do not knowingly collect, use, or disclose information, including Personal Information, from children under the age of thirteen (13) or as otherwise defined by local law without prior parental consent, except as permitted by the Children's Online Privacy Protection Act or other applicable law. 

Some of our services, such as online contests, sweepstakes, and promotions we may run from time to time, may seek information necessary for a child to participate, including the child's name, date of birth and parent's email address and contact information to communicate with the parent (as required by applicable law). For these services, children will be required to provide proof of consent from their parent or legal guardian in order to participate. Children are not permitted to provide information to us through any of the Websites or services or to share their information with us absent the consent of their parent or legal guardian. We will not use parent emails provided for parental consent purposes to market to the parent, unless the parent has expressly opted-in to email marketing or has separately participated in an activity that allows for such email contact.

If, at any time, a parent or legal guardian becomes aware that their child has provided us with information without their consent or wishes to withdraw their consent to our use or maintenance of information collected from their child, the parent or guardian should contact us at privacy@nflflag.com and we will promptly remove such information from our database(s). Please note that we may request proof of identity and relationship to the child before doing so.

If you have any comments or questions on policies related to children's data or about our commitment to protecting your and your children's privacy, please contact us at privacy@nflflag.com or by mail at the address below.

California residents under 16 years of age may have additional rights regarding the collection and sale of their Personal Information. Please see the Additional California Notices section below for more information.

 

3.                     Information We Collect About You and How We Collect It

We collect several types of information from and about users of our Websites, including information:

  • By which you or others may be personally identified, such as name, birth date, height/weight, postal address, city and state of residence, shipping and billing addresses, e-mail address, telephone number, credit card number, football league, club or school affiliations, and any other identifier by which you or others may be contacted online or offline (“Personal Information”).
  • That may be considered sensitive, such as Social security number, driver’s license number, state identification or passport number, account log-ins, financial accounts, debit or credit card number in combination with a security or access code, password, or other credentials, precise geo-location, racial or ethnic origin, biometric data, mental or physical health diaignosis, or personal data from a known child (“Sensitive Data”).
  • That is about you or relates to you but individually does not itself identify you, such as information about your internet connection, the equipment you use to access our Websites, and Website usage and activity details.

We collect this information:

  • Directly from you when you provide it to us.
  • Automatically as you navigate through the Website(s). Information collected automatically may include, for example, usage or activity details, IP addresses, and information collected through cookies, web beacons, and other tracking technologies. For more information on our use of cookies, web beacons, and other tracking technologies, please see below.

Information You Provide to Us

The information we collect on or through our Websites may include:

  • Information that you provide by filling in forms on, or submitting documents through, our Websites. This includes information provided at the time of registering to use a Website or making a transaction on a Website. We may also ask you for information when you enter a contest or promotion sponsored by us, and when you report a problem with a Website;
  • Payment and transaction information including credit or bank card information;
  • Preferences for communications, shopping, and products;
  • Account information and log in credentials, including unique identifiers such as username and password;
  • Records and copies of your correspondence (including email addresses), if you contact us;
  • Details of transactions you carry out through a Website and of the fulfillment of your orders. You may be required to provide financial information before placing an order through a Website;
  • Your search queries on a Website;
  • Information you provide to be published or displayed (hereinafter, “posted”) on public areas of the Websites, or transmitted to other users of the Websites or third parties (collectively, “User Contributions”). Your User Contributions are posted on and transmitted to others at your own risk. Please be aware that no security measures are perfect or impenetrable. Additionally, we cannot control the actions of other users of the Websites with whom you may choose to share your User Contributions. Therefore, we cannot and do not guarantee that your User Contributions will not be viewed by unauthorized persons;
  • Access to your geo-location or to other data held on social media platforms and other software (for example, access to your contacts, calendar or photos);
  • Photos and/or videos; and
  • Additional information as otherwise described to you at the point of collection or pursuant to your consent.

Information We Automatically Collect

As you navigate through and interact with our Websites, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:

  • Details of your visits to our Websites, including traffic data, location data, logs and other communication data and the resources that you access and use on a Website;
  • IP address, which is the number associated with the service through which you access the Internet, like your ISP (Internet service provider), or your company;
  • Date and time of your visit or use of our Websites;
  • Domain server from which you are using our Websites;
  • Type of computer, web browsers, search engine used, operating system, or platform you use;
  • Data identifying the web pages you visited prior to and after visiting our Websites or use of our Websites;
  • Your movement and activity within the Websites and services, which is aggregated with other information;
  • Geo-location information;
  • Mobile device information, if applicable, including the type of device you use, operating system version, and the device identifier (or “UDID”); and
  • Mobile application identification and behavior, use, and aggregated usage, performance data, and where the application was downloaded from, if applicable.

We also may use these technologies to collect information about your online activities over time and across third-party websites or other online services (behavioral tracking).

Some web browsers may transmit “do-not-track” signals to the websites with which the user communicates. We do not currently take action in response to those signals. If an industry standard on responding to such signals is established and accepted, we may reassess how to respond to those signals.

The information we collect automatically may include Personal Information or we may maintain it or associate it with Personal Information we collect in other ways or receive from third parties. It helps us to improve the Websites and NFL Flag, and to deliver a better and more personalized service, including by enabling us to:

  • Estimate our audience size and usage patterns.
  • Store information about your preferences, allowing us to customize our Websites according to your individual interests.
  • Speed up your searches.
  • Recognize you when you return to our Websites.

The technologies we use for this automatic data collection may include:

  • Cookies (or browser cookies). We, along with third-party partners, may use cookies. Cookies are small text files that websites and other online services use to store information about users on the users’ own computers. For example, cookies can be used to store your sign-in credentials so that you do not have to enter them each time you return to a website. Cookies also may be used to store a unique identification number tied to your computer so that a website can recognize you as the same user across different visits to the website. You can configure your internet browser to warn you each time a cookie is being sent or to refuse cookies completely. Cookies might be used for the following purposes: (1) to enable certain functions; (2) to provide analytics; (3) to store your preferences; and (4) to enable ad delivery and behavioral advertising.
    • You may learn more about cookies and how to opt out of them by visiting the following third party websites:
      • Allaboutcookies.org: http://www.allaboutcookies.org/
      • Direct Marketing Association: http://www.aboutads.info/choices/
      • Network Advertising Initiative: http://www.networkadvertising.org/choices/
  • Flash Cookies and Other Local Storage. We, along with third-party partners, may use other kinds of local storage, such as Local Shared Objects (also referred to as “Flash cookies”) and HTML5 local storage, in connection with the Websites. These technologies are similar to the cookies discussed above in that they are stored on your computer and can be used to store certain information about your activities and preferences. These objects are stored in different parts of your computer from ordinary browser cookies, however. Many internet browsers allow you to disable HTML5 local storage or delete information contained in HTML5 local storage using browser controls.
  • Web Beacons. We, along with our third-party partners, may also use technologies called web beacons that communicate information from your internet browser to a web server. Web beacons can be embedded in web pages, videos, or emails, and can allow a web server to read certain types of information from your browser, check whether you have viewed a particular web page or email message, and determine, among other things, the time and date on which you viewed the web beacon, the IP address of your computer, and the URL of the web page from which the web beacon was viewed. We and our partners use web beacons for a variety of purposes, including analyzing the use of the Websites and in conjunction with cookies to provide content that is more relevant to you.

Information We May Receive From Third Parties

We may collect additional information, including Personal Information, about you from third party websites, social media platforms, such as, but not limited, to Facebook, Twitter, Instagram, SnapChat (“Social Media Platforms”), and/or sources providing publicly-available information (e.g., from the U.S. postal service) to help us provide services to you, help prevent fraud, and for marketing and advertising purposes.

Information we may access about you, with your consent, may include, but is not limited to, your basic Social Media Platform information (e.g., name, username, email address, profile picture), your location data, your list of contacts, friends or followers and certain information about your activities on the Social Media Platform. Please keep in mind that when you provide information to us on a third party website or platform (for example, via our applications), the information you provide may be separately collected by the third party website or the Social Media Platform.

The information we collect is covered by this Privacy Notice, and the information the third-party website or Social Media Platform collects is subject to the third party website or platform's privacy practices. We encourage you to be aware when you leave our Websites and to read the privacy policies of other sites that may collect your information.

 

4.                    Third-Party Use of Cookies and Other Tracking Technologies

We may partner with third parties such as ad networks and other advertising companies to display advertising on our Website and manage our advertising on other websites. Some content or applications, including advertisements, on the Websites are served by third parties, including advertisers, ad networks and servers, content providers, and application providers. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our website. The information they collect may be associated with your Personal Information or they may collect information, including Personal Information, about your online activities over time and across different websites and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content. This information may also be used to evaluate the effectiveness of our online advertising campaigns.

We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly.

If you are a resident of California, Virginia, Colorado, Connecticut, or Utah, you have the right to opt out of our use of your Personal Information for the purpose of serving you interest-based ads. Residents of these states may opt-out by (1) clicking the following link: Do Not Sell or Share My Personal Information and following the instructions or (2) emailing us at privacy@nflflag.com.

To successfully opt out, you must have cookies enabled in your web browser (see your browser’s instructions for information on cookies and how to enable them). Your opt-out only applies to the web browser you use so you must opt-out of each web browser on each computer you use. Once you opt out, if you delete your browser’s saved cookies, you will need to opt-out again. Please note this does not opt you out of being served advertisements. You will continue to receive generic advertisements from us, but the ads will not be targeted based on behavioral information about you and may therefore be less relevant to you and your interests.

We may also partner with third-party service providers to engage in “profiling” which is defined in the VCPA, CPA, and CPDPA as “any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable natural person’s economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.” Residents of Virginia, Colorado, and Connecticut may opt out of processing of your Personal Information for purposes of profiling by following the process described in Your State Data Privacy Rights below.

 

5.                   How We Use Your Information

We and the NFL Entities may use information that we collect about you or that you provide to us, including any Personal Information:

  • To administer, operate, market, and maintain NFL FLAG.
  • To market NFL FLAG, RCX, or NFL Entity products or services;
  • To present our Websites and its contents to you;
  • To provide you with the Websites, and related products, promotions, newsletters, contests, sweepstakes, games, and information you request;
  • To respond to your inquiries and provide you with requested information and other communications, including by email or text messages, and including alerts, notification of promotions, contests, and events;
  • For general or targeted marketing and advertising purposes, including sending you promotional material or special offers on our behalf or on behalf of our marketing partners and/or their respective affiliates and subsidiaries and other third parties, provided that you have not already opted-out of receiving such communications;
  • To manage, improve and foster relationships with third-party service providers, including vendors, suppliers, and parents, affiliates, subsidiaries, and business partners;
  • To maintain, improve, customize, or administer the Websites, perform business analyses, or other internal purposes to improve the quality of our business, the Websites, resolve technical problems, or improve security or develop other products and services;
  • To comply with our Terms of Use;
  • To comply with any applicable laws and regulations and respond to lawful requests;
  • To fulfill any other purpose for which you provide it;
  • To provide you with notices about your account;
  • To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection;
  • To notify you about changes to our Websites or any products or services we offer or provide though it;
  • To allow you to participate in interactive features on our Websites;
  • In any other way we may describe when you provide the information; and
  • For any other purpose with your consent.

A legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests. The table below explains why we process your personal information:

How we process your personal information

Our reasons

To provide products and/or services to you

For the performance of our contract with you or to take steps at your request before entering into a contract

To prevent and detect fraud against you or our organization

For our legitimate interests or those of a third party, i.e. to minimize fraud that could be damaging for us and for you

To display advertisements to our advertisers’ target audiences

For our legitimate interests or those of a third party, i.e., to efficiently and accurately advertise to you so we can deliver the best service for you at the best price

Processing necessary to comply with professional, legal and regulatory obligations that apply to our business, e.g. under health and safety regulation or rules issued by our professional regulator

To comply with our legal and regulatory obligations

Gathering and providing information required by or relating to audits, enquiries or investigations by regulatory bodies

To comply with our legal and regulatory obligations

Ensuring business policies are adhered to, e.g. policies covering security and internet use

For our legitimate interests or those of a third party, i.e. to make sure we are following our own internal procedures so we can deliver the best service to you

Operational reasons, such as improving efficiency, training, and quality control

For our legitimate interests or those of a third party, i.e. to be as efficient as we can so we can deliver the best service for you at the best price

Ensuring the confidentiality of commercially sensitive information

For our legitimate interests or those of a third party, i.e. to protect trade secrets and other commercially valuable information

To comply with our legal and regulatory obligations

Statistical analysis to help us manage our business, e.g. in relation to our financial performance, customer base, product range or other efficiency measures

For our legitimate interests or those of a third party, i.e. to be as efficient as we can so we can deliver the best service for you at the best price

Preventing unauthorized access and modifications to systems

For our legitimate interests or those of a third party, i.e. to prevent and detect criminal activity that could be damaging for us and for you

To comply with our legal and regulatory obligations

Updating and enhancing customer records

For the performance of our contract with you or to take steps at your request before entering into a contract

To comply with our legal and regulatory obligations

For our legitimate interests or those of a third party, e.g. making sure that we can keep in touch with our customers about existing orders and new products

Statutory returns

To comply with our legal and regulatory obligations

Ensuring safe working practices, staff administration and assessments

To comply with our legal and regulatory obligations

For our legitimate interests or those of a third party, e.g. to make sure we are following our own internal procedures and working efficiently so we can deliver the best service to you

Marketing our services to existing and former customers, third parties who have previously expressed an interest in our services and/or third parties with whom we have had no previous dealings.

For our legitimate interests or those of a third party, i.e. to promote our business to existing and former customers

External audits and quality checks, e.g. for ISO or Investors in People accreditation and the audit of our accounts

For our legitimate interests or a those of a third party, i.e. to maintain our accreditations so we can demonstrate we operate at the highest standards

To comply with our legal and regulatory obligations

 

Promotional Communications

We may also use your information to contact you about our own and third-parties’ goods and services that may be of interest to you. We have a legitimate interest in processing your Personal Information for promotional purposes (see above How We Use Your Information). This means we do not usually need your consent to send you promotional communications. However, where consent is needed, such as for Canadian residents, we will ask for this consent separately and clearly. You have the right to opt out of receiving promotional communications at any time by contacting us at privacy@nflflag.com or using the “unsubscribe” link in emails.

From time to time, we may ask you to confirm or update your marketing preferences if you instruct us to provide further products and/or services in the future, or if there are changes in the law, regulation, or the structure of our business.We may use the information we have collected from you to enable us to display advertisements to our advertisers’ target audiences. Even though we do not disclose your Personal Information for these purposes without your consent, if you click on or otherwise interact with an advertisement, the advertiser may assume that you meet its target criteria.

6.                   Disclosure of Your Information

We may disclose aggregated information about our users, and information that does not identify any individual, without restriction. We may disclose Personal Information that we collect or you provide as described in this Privacy Notice:

  • NFL Entities. To the NFL Entities, who shall have the right to use all Personal Information collected under this Privacy Notice to the same extent as us.
  • Affiliates. To our subsidiaries and other affiliates – companies that control, are controlled by, or are under common control with, us. These entities may use your information to make predictions about your interests and may provide you with special offers, promotional materials, advertisements and other materials.
  • Partners. To partners who provide products or services that may be of interest to you, including: (i) educational products and services (e.g., colleges, student loans, financial aid, college admissions and tutorial services, and extra-curricular enrichment and recognition programs); (ii) career, employment, and military opportunities; (iii) athletic apparel and equipment companies; (iv) recruiting services; (v) sports related activities; and (vi) other relevant products and services. These partners may use your information to make predictions about your interests and may provide you with special offers, promotional materials, advertisements and other materials.
  • Service Providers. To contractors, service providers, and other third parties we use to support our business, including companies that provide payment processing, shipping, web analytics, data processing, web hosting, technical support, advertising, email distribution and other services.
  • Buyers and Successors. To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of RCX's assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Information held by RCX about our Websites’ users is among the assets transferred.
  • Advertisers. To third parties to market their products or services to you if you have not opted out of these disclosures. For more information, see Your State Data Privacy Rights section below.
  • Other. To fulfill the purpose for which you provide it or for any other purpose disclosed by us when you provide the information or with your consent.

We may also disclose your Personal Information:

  • To comply with any court order, law or legal process, including to respond to any government or regulatory request;
  • To enforce or apply our Terms of Use and other agreements, including for billing and collection purposes;
  • If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of RCX, the NFL Entities, or our customers and other users;
  • To provide, support, personalize, and develop our Websites, products, and services;
  • To create, maintain, customize, secure and provide you with notices about your account with us;
  • To provide you with information, products, or services that you request from us;
  • To process your requests, purchases, transactions, and payments and prevent transactional fraud;
  • To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses;
  • To personalize your Website experience and to deliver content and product and service offerings relevant to your interests, including targeted offers and ads through our Websites, third-party sites, and via email or text message (with your consent, where required by law);
  • To help maintain the safety, security, and integrity of our Websites, products and services, databases and other technology assets, and business;
  • For testing, research, analysis, and product development, including to develop and improve our Websites, products, and services;
  • To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Information held by us about our Websites’ users is among the assets transferred;
  • To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection;
  • To notify you about changes to our Websites or any products or services we offer or provide though it;
  • To allow you to participate in interactive features on our Websites; and
  • For any other purpose with your consent. 

 

In the preceding 12 months, we have not sold your Personal Information to third parties.

 

7.                    Additional California Notices

1. The personal information we collect

In accordance with the CCPA, we may collect, use, and share the following categories of personal information that identifies, relates to, describes, is reasonable capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household:

Category

Examples

Collected

A. Identifiers.

A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers

YES

B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).

A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.

YES

C. Protected classification characteristics under California or federal law.

Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).

YES

D. Commercial information.

Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

YES

E. Biometric information.

Genetic, physiological, behavioral, and biological characteristics or samples (such as breath, blood, or urine), or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.

NO

F. Internet or other similar network activity.

Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement.

YES

G. Geolocation data.

Physical location or movements.

YES

H. Sensory data.

Audio, electronic, visual, thermal, olfactory, or similar information.

 

NO

I. Professional or employment-related information.

Current or past job history or performance evaluations.

NO

J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).

Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.

NO

K. Inferences drawn from other personal information.

Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

YES

L. Sensitive data.

Social security number, driver’s license number, state identification card, or passport number; account log-ins, financial accounts, debit or credit card numbers in combination with a security or access code, password, or other credentials; precise geo-location; racial or ethnic origin, religious or philosophical beliefs, or union membership; contents of mail, email or text messages; genetic or biometric data; mental or physical health diagnosis, sexual orientation; or personal data from a known child.

YES

 

2. How we disclose, share, and sell personal information

We disclose personal information as shown below.

The first chart shows the categories of personal information we disclose to our service providers and contrators for business or commerical purposes. Although we do not sell personal information in exchange for money, some of the ways in which we disclose personal information for advertising or to our affiliated brands and companies may be considered “sales” or “sharing” under some state consumer data privacy laws.

The second chart shows the categories of personal information we share for purposes of cross-contextual behavioral advertising. We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.

Disclosures for a Business or Commercial Purpose

Category of Personal Information

Categories of Recipients

Purposes for Disclosure

Personal Information

Identifiers

Service providers and affiliates to provide services on our behalf

To fulfill orders and provide you with information or other services you request from us

To provide you with functionality of the website

To provide customer service and/or marketing products or services

To conduct research and perform analysis to measure, maintain, protect, develop, and improve our products or services

To make communications necessary to notify you regarding order confirmation, products, services, market research, requests, marketing, security, privacy and administrative issues

To comply with our legal and regulatory obligations

To ensure our business policies are adhered to

Preventing unauthorized access and modifications to systems

Personal records

Service providers and affiliates to provide services on our behalf

To fulfill orders and provide you with information or other services you request from us

To provide you with functionality of the website

To provide customer service and/or marketing products or services

To conduct research and perform analysis to measure, maintain, protect, develop, and improve our products or services

To make communications necessary to notify you regarding order confirmation, products, services, market research, requests, marketing, security, privacy and administrative issues

To comply with our legal and regulatory obligations

To ensure our business policies are adhered to

Preventing unauthorized access and modifications to systems

Characteristics of protected classifications

Service providers and affiliates to provide services on our behalf

To fulfill orders and provide you with information or other services you request from us

To provide customer service and/or marketing products or services

To conduct research and perform analysis to measure, maintain, protect, develop, and improve our products or services

To ensure our business policies are adhered to

Commercial information

Service providers and affiliates to provide services on our behalf

To provide customer service and/or marketing products or services

To conduct research and perform analysis to measure, maintain, protect, develop, and improve our products or services

Internet or similar network activity

Service providers and affiliates to provide services on our behalf

To provide you with functionality of the website

To provide customer service and/or marketing products or services

To conduct research and perform analysis to measure, maintain, protect, develop, and improve our products or services

To comply with our legal and regulatory obligations

Preventing unauthorized access and modifications to systems

 

 

 

Inferences

Service providers and affiliates to provide services on our behalf

To provide customer service and/or marketing products or services

To conduct research and perform analysis to measure, maintain, protect, develop, and improve our products or services

To make communications necessary to notify you regarding order confirmation, products, services, market research, requests, marketing, security, privacy and administrative issues

To comply with our legal and regulatory obligations

Sensitive Information

Geolocation

Service providers and affiliates to provide services on our behalf

To fulfill orders and provide you with information or other services you request from us

To provide customer service and/or marketing products or services

To conduct research and perform analysis to measure, maintain, protect, develop, and improve our products or services

To comply with our legal and regulatory obligations

Payment Information

Service providers and affiliates to provide services on our behalf

To fulfill orders and provide you with information or other services you request from us

 

 

Sale or Sharing of Personal Information

Category of Personal Information

Categories of Recipients

Purposes for Selling / Sharing

Identifiers

Service providers and affiliates to provide services on our behalf

To show you relevant advertising and other promotional content

Analytics, data strategy, consultation, development or improvement of products and services, marketing, advertising, and related services

Personal records

Service providers and affiliates to provide services on our behalf

To show you relevant advertising and other promotional content

Analytics, data strategy, consultation, development or improvement of products and services, marketing, advertising, and related services

Commercial information

Service providers and affiliates to provide services on our behalf

To show you relevant advertising and other promotional content

Analytics, data strategy, consultation, development or improvement of products and services, marketing, advertising, and related services

Inferences

Service providers and affiliates to provide services on our behalf

To show you relevant advertising and other promotional content

Analytics, data strategy, consultation, development or improvement of products and services, marketing, advertising, and related services

 

3. Shine the Light Notice

Certain Californians are also entitled to certain other notices, as follows: This Shine the Light Notice provides information on our online practices and your California rights specific to our online services. Without limitation, Californians that visit our online Services and seek to acquire goods, services, money or credit for personal, family or household purposes are entitled to the following notices of their rights:

California’s “Shine the Light” law (Civil Code Section § 1798.83) permits users of our Websites who are California residents to request certain information regarding our disclosure of personal data to third parties for their direct marketing purposes. To make such a request, please send an email to privacy@nflflag.com or send a physical request to:

RCX Sports LLC

250 Hembree Park Drive, Suite 100
Roswell, GA 30076

You must put the statement “Shine the Light Request” in the body of your correspondence. In your request, please attest to the fact that you are a California resident and provide a current California address for your response. This right is different than, and in addition to, CCPA rights (as described in Your State Data Privacy Rights), and must be requested separately. However, a Do Not Sell or Share My Personal Information opt-out is broader and will limit our sharing with third parties for their own direct marketing purposes without the need for making a separate Shine the Light request. We will not accept Shine the Light requests by telephone or by fax, and are not responsible for requests not labeled or sent properly, or that are incomplete. 

 

8.                     Your State Data Privacy Rights

If you are a resident of the states of California, Virginia, Colorado, Connecticut, Nevada, Utah, Texas, Montana, Tennessee, Oregon, Iowa, or Indiana you may have certain rights under applicable data privacy laws. If you are a resident of the state of California, you have the right under the CCPA to exercise your rights free of charge twice per year. These rights are described below:

Right to Know and Request Disclosure (California residents only)

You have the right to know and request disclose of:

  • The categories of personal information we have collected about you, including sensitive personal information
  • The categories of sources from which the personal information is collected
  • Our business or commercial purpose for collecting, selling, or sharing personal information
  • The categories of third parties to whom we disclose personal information, if any; and
  • The specific pieces of personal information we have collected about you.

 

In connection with any personal information we may sell, share, or disclose to a third party for a business purpose, you have the right to know:

  • The categories of personal information about you that we sold or shared and the categories of third parties to whom the personal information was sold or shared; and
  • The categories of personal information that we disclosed about you for a business purpose and the categories of persons to whom the personal information was disclosed for a business purpose.

Please note that we are not required to:

  • Retain any personal information about you that was collected for a single one-time transaction if, in the ordinary course of business, that information about you is not retained;
  • Reidentify or otherwise link any data that, in the ordinary course of business, is not maintained in a manner that would be considered personal information; or
  • Provide the personal information to you more than twice in a 12-month period.

Right to Confirm

You have the right to confirm whether or not we are processing your personal information. 

Your request to confirm may be denied for any reason allowable under applicable state privacy law. For example, we may deny your request to delete if the personal information is necessary for us or a service provider to complete the transaction for which we collected the personal information, comply with a legal obligation, or make other internal or lawful uses of that information that are compatible with the context in which you provided. 

Right to Access

You have the right to access your personal information, subject to exceptions set out in applicable privacy legislation. Examples of such exceptions include:

  • Information that is aggregated or de-identified.
  • Information that is part of a formal dispute resolution process.
  • Information that is about another individual that would reveal their personal information or confidential commercial information.
  • Information that is prohibitively expensive to provide.

Right to Delete

Subject to certain exceptions set out below, on receipt of a verifiable request from you, we will:

  • Delete your personal information from our records;
  • Direct any service providers or contractors to delete your personal information from their records; and
  • Direct third parties to whom the business has sold or shared your personal information to delete your personal information unless this proves impossible or involves disproportionate effort.

Your request to delete may be denied for any reason allowable under applicable state privacy law. For example, we may deny your request to delete if the personal information is necessary for us or a service provider to:

  • Complete the transaction for which the personal information was collected, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, provide a good or service requested by you, or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between you and us;
  • Help to ensure security and integrity to the extent the use of the consumer’s personal information is reasonably necessary and proportionate for those purposes;
  • Debug to identify and repair errors that impair existing intended functionality;
  • Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law;
  • Comply with the California Electronic Communications Privacy Act;
  • Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when our deletion of the information is likely to render impossible or seriously impair the achievement of such research, provided we have obtained your informed consent;
  • Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us
  • Comply with an existing legal obligation; or
  • Otherwise use your personal information, internally, in a lawful manner that is compatible with the context in which you provided the information.

Right of Correction

If we maintain inaccurate personal information about you, you have the right to request us to correct that inaccurate personal information. Upon receipt of a verifiable request from you, we will use commercially reasonable efforts to correct the inaccurate personal information.

Right to Obtain a Copy

You also have the right to obtain a copy of the personal information you have provided to us in a portable, readily usable format that can be easily transferred to a third party.

Right to Opt-Out

You have the right to opt out of the following uses of your personal information:

  • Sharing or your personal information for targeted behavioral advertising;
  • Marketing communications; and
  • Profiling.

We will act upon your request to opt-out no later than 15 days from the date we received the request. Note that we may deny a request to opt-out if we have a good-faith, reasonable, and documented belief that the request is fraudulent or for any other reason allowable under applicable state privacy law. 

To opt out of the sharing of your personal information, email privacy@nflflag.com.

Right to Limit Use of Sensitive Personal Information

We may collect sensitive data about you, including your account-login ins, debit or credit card numbers, or other credentials. We do not collect or process your sensitive personal information to infer characteristics about you. We take specific business practices to limit the use and disclosure of sensitive personal information, such as:

  • Just-in-time notices at the collection of sensitive information
  • Requiring your express consent for the collection of sensitive information
  • Aggregating and/or de-identifying the sensitive information

You may direct us to limit the use of this sensitive information only for purposes necessary to:

  • Perform the services or provide the goods requested by you
  • Help ensure the security and integrity of the use of your information
  • Perform services on behalf of our business, such as maintainging or servicing accounts, providing customer service, processing or fulfilling orders, payments, ore rturns, or verifying customer information
  • Undertaking activities to verify the quality of, maintain, or improve our services or systems

You have a right to know if your sensitive personal information is used or disclosed to a service provider or contractor, for additional, specified purposes.  

We will not use your sensitive information for any purpose other than those allowed under applicable law. You may limit the use of sensitive information for purposes other than necessary to perform the service that you request from us by emailing privacy@nflflag.com.

Right to Non-Discrimination

You have the right to not be retaliated or discriminated against by us because you exercised any of your rights under the CCPA. This means we cannot, among other things:

  • Deny goods or services to you;
  • Charge different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties;
  • Provide a different level or quality of goods or services to you; or
  • Suggest that you will receive a different price or rate for goods or services or a different level or quality of goods or services.

 

If you or an authorized representative want to review, access, correct, or withdraw consent to the use of your personal information you may send us an email at privacy@nflflag.com to request access to, correct, or delete any personal information that you have provided to us. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect. We may request specific information from you to help us confirm your identity and your right to access, and to provide you with the personal information that we hold about you or make your requested changes. Any personal information we collect from you to verify your identity in connection with you request will be used solely for the purposes of verification. To verify a request, you will need to provide:

  • Enough information to identify you;
  • Proof of your identity and address; and
  • A description of what right you want to exercise and the information to which your request relates.
  • If your request is submitted on your behalf by an authorized representative, you will need to provide proof of the representative’s authority to act on your behalf by writing signed by you.

If we are unable to verify your request, we may deny the request or ask you for additional information that is reasonably necessary to authenticate your identity in connection with the consumer request.

Once submitted, you will receive an email within 10 days that we will use to verify your identity and provide confirmation of your request. We will respond to your request to know or delete or correct within 30 days from the day we receive the request. If necessary, we may extend the time period to a maximum of 30 additional days from the day we receive the request. In such case, you will receive an email notifying you of the extension and explaining the reason for the extension.

Applicable law may allow or require us to refuse to provide you with access to some or all of the personal information that we hold about you, or we may have destroyed, erased, or made your personal information anonymous in accordance with our record retention obligations and practices. If we cannot provide you with access to your personal information, we will inform you of the reasons why, subject to any legal or regulatory restrictions. For California residents, we will provide access to your personal information, subject to exceptions set out in the CCPA, such as information that is aggregated or de-identified.

You also have the right to appeal our decision if we deny your consumer request. If we deny your consumer request, you can send an email to privacy@nflflag.com requesting an appeal of the denial. Within 30 days of receipt of your appeal, we will inform you of the action we took or did not take in response to your appeal. If allowed under applicable law, we may extend the 30-day period by an additional 15 days where reasonably necessary and inform you of the delay and the reasons for the delay. If your appeal is denied, we will provide you with an online mechanism to contact the Attorney General to submit a complaint in your respective state.

If you are concerned about our response or would like to correct the information provided, you may contact our Privacy Officer at privacy@nflflag.com.

The CCPA may allow or require us to refuse to provide you with access to some or all of the personal information that we hold about you, or we may have destroyed, erased, or made your personal information anonymous in accordance with our record retention obligations and practices. If we cannot provide you with access to your personal information, we will inform you of the reasons why, subject to any legal or regulatory restrictions.

 

9.                       Your International Privacy Rights Canada

If you are a citizen of Canada, in addition to the rights described within this Privacy Notice, you are entitled to the following rights under the Personal Information Protection and Electronic Documents Act:

Withdrawing Your Consent. Where you have provided your consent to the collection, use, and transfer of your personal information, you may have the legal right to withdraw your consent under certain circumstances, including the following:

 

To withdraw your consent, if applicable, contact us as described below in the section entitled Contact Information or follow the process described in Your State Data Privacy Rights above. Please note that if you withdraw your consent we may not be able to provide you with a particular product or service. We will explain the impact to you at the time to help you with your decision.

Accessing and Correcting Your Personal Information. By law, you have the right to request access to and to correct the personal information that we hold about you. If you want to review, verify, correct, or withdraw consent to the use of your personal information pursuant to the process described in Your State Data Privacy Rights, you may also send us an email at privacy@nflflag.com to request access to, correct, or delete any personal information that you have provided to us.

Europe

Legal Basis for Data Processing: We process personal information for the specific purposes set out in this Privacy Notice, as described above. Where such concept is recognized, our legal basis to process personal information includes:

  • Necessary for the entry into or performance of a contract: When you enter into a transaction with us, we will need to collect, process, and share your personal information. Failure to provide the requisite personal information when entering into such an agreement, objecting to this type of processing, and/or exercising your deletion rights may mean that products and/or services cannot be provided to you.
  • Legitimate interest: In certain circumstances we may use your personal information to pursue legitimate interests of our own, but this is provided your interests and fundamental rights do not override those interests. This is on the basis of our legitimate interest to:
    • provide you with information and services as requested by you on a non-contractual basis;
    • develop and improve our services to you and to our other customers;
    • communicate with you and manage our relationship with you;
    • administer our websites and applications;
    • carry out management analysis, audit, forecasts, business planning, and transactions;
    • ensure our compliance with applicable laws, regulatory requirements, and our policies; and
    • deal with legal claims and related administrative activities.
  • Consent: We may, on occasion and where permitted by law, process your personal information based on your consent. For example, we may process sensitive categories of information or send you marketing messages by email with your consent. You may opt out of receiving certain marketing messages by exercising the choices described in Your State Privacy Rights above. To the extent our processing is based on consent, you can withdraw your consent at any time. However, please note that the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
  • Compliance with legal obligations: To meet our regulatory and legal obligations, we may need to process some of your personal information.

 

We consider that it is reasonable for us to process your personal information for achieving our legitimate interests, as outlined above, as:

    • We process your personal information only so far as is necessary to achieve the purpose outlined in this Privacy Notice; and
    • The processing of your personal information does not unreasonably intrude on your privacy and ultimately benefits you in optimizing our provision of services to you.

 

In some instances, you may be required to provide us with personal information for processing, as described above, in order for us to be able to provide you all of our Services and for you to use all the features of our website.

 

If you are aware of changes or inaccuracies in your information, you should inform us of such changes so that our records may be updated or corrected. You may lodge a complaint with your local supervisory authority if you consider that our processing of your personal information infringes applicable law.

 

Additional Rights. If you are a citizen of the European Economic Area (“EEA”), in addition to the rights described within, you are also entitled to the following rights under the General Data Protection Regulation (“GDPR”):

Right to Access

The right to be provided with a copy of your personal information (the right of access)

Right to Rectification

The right to require us to correct any mistakes in your personal information

Right to be Forgotten

The right to require us to delete your personal information—in certain situations

Right to Restriction of Processing

The right to require us to restrict processing of your personal information—in certain circumstances, e.g. if you contest the accuracy of the data

Right to Data Portability

The right to receive the personal information you provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party—in certain situations

Right to Object

The right to object:

  • At any time to your personal information being processed for direct marketing (including profiling);
  • In certain other situations to our continued processing of your personal information, e.g. processing carried out for the purpose of our legitimate interests.

Right Not to be Subject to Automated Individual Decision-Making

The right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you

 

We hope that we can resolve any query or concern you raise about our use of your information.

How to File a GDPR Complaint. The GDPR also gives you right to lodge a complaint with a supervisory authority, in the European Union (or EEA) state where you work, normally live, or where any alleged infringement of data protection laws occurred. For contact details of your local Data Protection Authority, please see:   https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.

 

10.                        Data Security

We have implemented measures designed to secure your Personal Information from accidental loss and from unauthorized access, use, alteration, and disclosure, which we may change from time to time.

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Websites, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although we have implemented reasonable safeguards and endeavor to protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted to our Websites. Any transmission of Personal Information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Websites. You should assume that no data transmitted over the Internet or stored or maintained by us or our third party service providers can be 100% secure. Therefore, although we believe the measures implemented by us reduce the likelihood of security problems to a level appropriate to the type of data involved, we do not promise or guarantee, and you should not expect, that your Personal Information other information, or private communications will always remain private or secure. We do not guarantee that your information including Personal Information will not be misused by third parties. We are not responsible for the circumvention of any privacy settings or security features. You agree that we will not have any liability for misuse, access, acquisition, deletion, or disclosure of your information, including Personal Information.

If you believe that your information has been accessed or acquired by an unauthorized person, you shall promptly contact us so that necessary measures can quickly be taken.

11.                           Data Retention

Except as otherwise permitted or required by applicable law or regulation, we will only retain your Personal Information for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Under some circumstances, we may anonymize your Personal Information so that it can no longer be associated with you. We reserve the right to use such anonymous and de-identified data for any legitimate business purpose without further notice to you or your consent.

In accordance with our routine record keeping, we may delete certain records that contain your information, including Personal Information, you have submitted to us. We are under no obligation to store such information indefinitely and disclaim any liability arising out of, or related to, the destruction of such information.

 

12.                             Transferring Your Personal Information

We may transfer Personal Information that we collect or that you provide as described in this Privacy Notice to contractors, service providers, and other third parties we use to support our business (such as analytics and search engine providers that assist us with Website improvement and optimization) and who are contractually obligated to keep Personal Information confidential, use it only for the purposes for which we disclose it to them, and to process the Personal Information with the same standards set out in this Privacy Notice.

We may process, store, and transfer your Personal Information in and to a foreign country, with different privacy laws. In these circumstances, the governments, courts, law enforcement, or regulatory agencies of that country may be able to obtain access to your Personal Information through the laws of the foreign country. Whenever we engage a service provider, we require that its privacy and security standards adhere to this Privacy Notice and applicable state privacy legislation.

This Website is hosted in the United States. This Website may function in countries other than the United States. If you use the Website from outside the United States and submit your Personal Information or engage with the Website, you explicitly consent to the transfer, storage, or processing of your Personal Information in a country other than the United States where laws regarding processing of Personal Information may differ from the laws of other countries. You are responsible for compliance with the laws of the jurisdiction in which you choose to use the Website.

You are welcome to contact us to obtain further information about RCX policies regarding service providers outside of the United States. See Contact Information below.

By submitting your Personal Information or engaging with the Website, you consent to this transfer, storage, or processing. 

 

13.                            Changes to Our Privacy Notice

It is our policy to post any changes we make to our Privacy Notice on this page. If we make material changes to how we treat our users’ information, including Personal Information, we will notify you by email to the primary email address specified in your account (if applicable) and/or through a notice on the Websites’ home page. The date the Privacy Notice was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Websites and this Privacy Notice to check for any changes.

  

14.                              Contact Information 

 We welcome your questions, comments, and requests regarding this Privacy Notice and our privacy practices. Please contact us at: 

          RCX Sports LLC 

          250 Hembree Park Drive, Suite 100 
          Roswell, GA 30076 

We have procedures in place to receive and respond to complaints or inquiries about our handling of information, including Personal Information, our compliance with this Privacy Notice, and with applicable privacy laws. To discuss our compliance with this Privacy Notice please contact us using the contact information listed above.