California Consumer Privacy Notice
Last updated: March 22, 2026
This California Privacy Notice supplements our Privacy Policy and applies solely to California consumers.
The sections below describe how we process California consumers’ personal information based on definitions laid out in the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).
Categories of Personal Information We Collect
The table below describes the categories of personal information we collect under the CCPA, along with the sources, third parties with whom we share it, and our business purposes. Not all items are relevant to every user.
| Category | Sources | Third Parties* | Purposes |
|---|---|---|---|
| Identifiers: Display name, email address, phone number (optional), IP address, device identifiers, cookies | You (including via account creation, profile, preferences, content) Third parties (including security affiliates, law enforcement) | Service providers Analytics partners | Service delivery Marketing Legal compliance |
| Personal Records: Financial information related to purchases (order history, transaction amounts) | You (including via your account, payments, profile, content) Third parties (including Apple/Google receipts, security affiliates, and law enforcement) | N/A | Service delivery Marketing Legal compliance |
| Protected Classifications: User-generated content may incidentally contain information about protected characteristics. We do not ask for or use this information to infer characteristics about you. | You (account, profile, direct contact) | Service providers | Service delivery Legal compliance |
| Commercial Information: Purchase history, products/services purchased or considered | You (via your purchases) Third parties (including Apple/Google receipts) | Service providers | Service delivery Marketing Legal compliance |
| Biometric Information: Photos voluntarily uploaded by users may include faces and other features that may be considered biometric identifiers under applicable laws | You (via voluntary photo uploads) | Service providers | Service delivery Marketing Legal compliance |
| Internet/Network Activity: In-app activity (pages viewed, features used, clicks), interactions with our ads on third-party platforms | You (including site interactions, pages visited, clicks, searches) Third parties (including analytics partners) | Service providers Advertising partners Analytics partners | Service delivery Marketing Legal compliance |
| Geolocation Data: Precise location information | Your device (with consent) IP address (approximate) | Service providers | Service delivery Legal compliance |
| Sensory Information: Audio, visual, and similar information | You (via voluntary photo uploads) | Service providers | Service delivery Marketing Legal compliance |
| Other Information: Emails, messages, survey responses, support communications | You (via direct communications) | Service providers | Service delivery Marketing Legal compliance |
| Inferences: Preferences and characteristics derived from your data | Created from your profile and usage | Service providers | Service delivery Marketing |
* All categories may also be disclosed to government or law enforcement officials in response to valid legal process.
Business Purposes for Collection
We use the personal information described above for the following purposes:
- Service Delivery and Enhancement: Managing your account and processing transactions; customizing the Services based on your preferences; providing support; improving the Services through research, testing, and analytics; ensuring security, fraud prevention, and debugging
- Communicating and Marketing: Marketing our Services; responding to your inquiries; sending communications according to your preferences
- Legal and Safety Compliance: Complying with laws, regulations, and legal processes; protecting rights, property, and safety; enforcing agreements and resolving disputes
Sensitive Personal Information
Some of the information we collect is categorized as “sensitive personal information” under the CCPA, which includes any information which may include precise geolocation (collected with your permission), the contents of your messages, and photos you upload. We do not use sensitive personal information we collect for purposes other than providing and improving our services to you and protecting our services and our community, and we do not use sensitive personal information to infer characteristics about you.
Information Retention
We keep your personal information only as long as we need it for legitimate business purposes and as permitted by applicable law.
If you decide to stop using our services, you can close your account. We may close your account automatically if you are inactive for an extended period. Following account closure, we delete your data except as described below.
| Data Type | Retention Period | Reason |
|---|---|---|
| Transaction data | 7 years after transaction | Tax and accounting requirements |
| Payment card information | Duration you may challenge the transaction | Dispute resolution |
| Traffic data and logs | 1 year | Legal data retention obligations |
| Customer support records | 3 years after resolution | Customer care, enforce rights, defend claims |
| Security and fraud data | As long as necessary | Protect users, investigate violations |
| Legal hold data | Duration of issue, claim, or dispute | Legal process and proceedings |
| De-identified data | Indefinitely | Service improvement and security |
California Consumer Privacy Rights
| Your Right | Description |
|---|---|
| Right to Know/Access | Know what personal information we have collected and request a copy of specific pieces |
| Right to Opt-Out of Sales/Sharing | Opt out of our sale or sharing of your personal information |
| Right to Correct | Request that we correct inaccurate information we hold about you |
| Right to Delete | Request deletion of personal information we have collected from you |
| Right to Non-Discrimination | Not receive discriminatory treatment for exercising your privacy rights |
| Right to Limit Sensitive Data Use | Limit our use or disclosure of sensitive personal information |
How to Submit a Request
If you are a California resident who has provided personal information to Candle, you may submit a request that Candle honor your right to access, correct, or delete by sending an email to Candle at support@trycandle.app.
Notice of Opt-Out of Sale/Sharing
While we do not sell your information for money, under California law, certain advertising-related activities may constitute “sharing” or “sales” of personal information. If we engage in such activities, they involve the following categories of personal information and third parties:
| Categories of Personal Information | Categories of Third Parties |
|---|---|
| Identifiers (IP address, cookie ID, email address) | Advertising networks |
| Internet or electronic network activity (links clicked, browsing activity) | Data analytics providers |
| Basic demographic data (age or age range, gender) | Social networks |
You can opt out of these activities by adjusting your privacy settings in your account, emailing support@trycandle.app with “Do Not Sell or Share My Personal Information” in the subject line, using the opt-out link in the footer of our website at www.trycandle.app, or by enabling Global Privacy Control (GPC) in your browser.
We do not knowingly “share” or “sell” personal information about individuals under 18.
You have the right to limit our use and disclosure of your sensitive personal information.
You may also email support@trycandle.app. We will promptly respond to a request to opt-out of sale/sharing, but no later than fifteen business days from the date we received the request and verify your identity.
Verification of Requests
For your security and to comply with the CCPA, we will need to verify your identity to respond to any requests you submit to exercise your rights.
The type and amount of personal information we request depends on your relationship with us and the type of request you’re making. For example:
- If you have an account with us that is password-protected, we may try to verify your identity through our existing account authentication practices.
- If you do not have an account with us, and your request concerns “categories” of personal information collected, we may request from you two data points of personal information to verify your identity.
- If you do not have an account with us, and your request concerns specific pieces of personal information, we may request from you at least three data points of personal information as well as a signed declaration with penalty of perjury to verify your identity.
The procedures above are for illustrative purposes only. We may ask you for additional or different information as we determine reasonably necessary to complete your request in compliance with the CCPA.
Authorized Agents
You may use an authorized agent to submit a request on your behalf. If you do, we may ask for evidence that you have provided the agent valid power of attorney or other written permission to submit requests on your behalf, and we may also take steps to verify your identity directly. If you are an authorized agent seeking to make a request, please contact us and include proof of your authorization.
Contact Us
If you have any questions about our privacy policies or practices or this notice, please contact us at support@trycandle.app.
See also our Privacy Policy for our full privacy practices.