Effective as of August 18, 2026
Thank you for visiting the official website (“Website”) of the California Residential Mitigation Program (“CRMP”).
CRMP is a California public agency and joint powers authority that administers seismic retrofit mitigation, education and grant programs, including the Earthquake Brace + Bolt (“EBB”) Program, Earthquake Soft-Story (“ESS”) Program, and Earthquake Multi-Unit Retrofit (“EMR”) Program (collectively, the “Mitigation Program(s)”).
Where applicable, CRMP collects, uses, discloses, safeguards, retains, and otherwise handles Personal Information consistent with the Information Practices Act of 1977 (Cal. Civ. Code § 1798 et seq.) (“IPA”), Government Code Section 11015.5, the California Public Records Act (Gov. Code § 7920.000 et seq.) (“CPRA”), and other applicable federal, state, grant, audit, tax, records-retention, and information-security requirements. This Privacy Notice (“Notice”) is intended to provide notice and transparency and does not create any contract, or limit any rights or obligations provided by applicable law.
1. SCOPE OF THIS NOTICE
This Notice applies to the Website, CRMP’s online services such as its social media pages, online portals, registration and application forms and dashboards for homeowners, contractors, and licensed design professionals (“LDPs”), as well as to regular mail, email, phone, and text-message communications, and other online or offline communications and information provided to or shared with CRMP in connection with the Mitigation Programs and related programs and services (collectively, the “Services”).
Even if linked from the Services, this Notice does not apply to third-party websites, applications, payment processors, social media platforms, identity providers, contractors, LDPs, local building departments, or other entities or services that are not controlled by CRMP, except to the extent they process information for CRMP under contract or applicable law.
This Notice supplements, and should be read together with, any applicable Mitigation Program rules, terms of use, social media guidelines, form-specific collection notices, grant documents, and other disclosures provided at or before the point of collection. If a form-specific notice describes a more specific purpose, authority, required field, consequence, or disclosure for that form, that form-specific notice controls for that collection.
2. KEY DEFINITIONS
The following definitions apply to this Notice:
- “Personal Information” means information that identifies or describes an individual, including information described in Civil Code Section 1798.3(a) and other information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual or household.
- “Electronically Collected Personal Information” has the meaning in Government Code Section 11015.5(d). In general, it includes information that identifies or describes an individual user, including a user’s name, social security number, physical description, home address, home telephone number, education, financial matters, medical or employment history, password, electronic mail address, and information revealing network location or identity such as an IP address. It excludes information manually submitted to CRMP, whether electronically or in written form, and information on or relating to users acting in a business capacity, such as business owners, officers, or principals of such business.
- “Technical Information” means information collected automatically from a device, browser, or network when you access the Services, as further described in Section 4.a. below.
- “Service Provider” means a vendor, contractor, consultant, or other person that processes information on CRMP’s behalf under CRMP instructions.
3. NOTICE AT COLLECTION AND COLLECTION AUTHORITY
CRMP requests information to operate and administer public mitigation programs, determine eligibility, manage accounts and dashboards, process grant payments, maintain public records, communicate with participants and the public, conduct audits and oversight, protect and improve the Services, and comply with applicable law and grant funding requirements. CRMP collection authority includes, as applicable, the Joint Exercise of Powers Act (Gov. Code § 6500 et seq.); CRMP’s joint powers agreement and Mitigation Program rules; applicable Federal Emergency Management Agency (“FEMA”) Hazard Mitigation Assistance and other federal and state grant requirements; funding and oversight requirements by CRMP’s JPA members (the California Governor's Office of Emergency Services (“Cal OES”) and the California Earthquake Authority (“CEA”)); California Insurance Code Sections 10089.395 and 10089.396; public agency accounting, audit, tax, records-retention, and fraud-prevention requirements; the IPA; Government Code Section 11015.5; the CPRA; and other federal, state, and local laws applicable to CRMP programs and operations.
Generally, unless a form states otherwise, providing information through the Services is voluntary. However, specific information may be required to use a Service, create an account, apply for a Program, verify eligibility, participate in a Program, receive Program updates, authorize a contractor or LDP to act on a Program participant’s behalf, obtain a payment, comply with any applicable Mitigation Program rules, or allow CRMP to respond to a request. If required information is not provided, CRMP may be unable to provide the requested Service, process an application, determine eligibility, make a grant payment, provide a directory listing, respond to a request, or maintain Program integrity. Technical Information that is necessary to operate, secure, and troubleshoot may be collected automatically when a person uses the Services. Non-essential analytics, advertising, or campaign-measurement technologies are addressed in Section 8 below.
The official responsible for CRMP records and privacy requests is:
CRMP Executive Director (Records Requests / Privacy)
California Residential Mitigation Program
400 Capitol Mall, Suite 1200
Sacramento, CA 95814
Phone: (877) 232-4300
Email: info@crmp.org.
4. WHAT INFORMATION CRMP COLLECTS
From time to time, depending on what Services are accessed and how, CRMP and its Service Providers may collect one or more of the following categories of information:
Information from your use of the Services
When you access the Services, CRMP and its Service Providers may automatically collect certain Technical Information, which may include:
- Network and device information (for example, IP address and approximate geographic location derived therefrom, internet domain and host, browser type and settings, device and operating system information, language settings).
- Usage information (for example, pages viewed, links clicked, time spent on pages, scrolling and interaction data, navigation path and referring/exit pages, and error logs).
- Identifiers associated with cookies or similar technologies (for example, cookie IDs, advertising identifiers, and analytics identifiers).
This Technical Information may be collected through server logs, cookies, tags, pixels, web beacons, content delivery networks, analytics or advertising tools, security tools, and similar technologies. These technologies may collect information about your browser and your interactions with the Services over time and across different websites or online services. Additional information about these technologies appears in Section 8.
Information you provide to CRMP manually
In some instances, in order to take full advantage of the Services, you may be required to provide certain information, including Personal Information. Depending on how you use the Services, CRMP may collect the following categories of Personal Information that you submit:
- Website Updates Sign-Up: If a member of the public opts to sign up for updates about the Mitigation Programs, they will be required to (i) provide their email address and property ZIP code, (ii) specify whether they are a homeowner, contractor, LDP, building department staff, legislative staff, city/state/federal staff, or other; and (iii) specify which Mitigation Program they are interested in receiving updates about (i.e., EBB, ESS and/or EMR). They will also have the option to specify the name of the organization they are with.
- Account, Authentication, and Portal Information: If you create or use a CRMP online account, CRMP may collect account login credentials (user name and password), authentication identifiers, contact information, account activity, login history, security events, and information needed to verify identity, manage access, maintain portal functionality, and protect the integrity of the Mitigation Programs. CRMP may use a third-party identity provider, currently Microsoft Azure AD B2C or any successor identity provider, to support authentication and access management.
- Homeowner and Property Registration Information: For homeowner registration and applications to any of the Mitigation Programs, CRMP may collect name, email address, primary and secondary telephone numbers, property address (including city, state, property ZIP code), mailing address if different from property address, property characteristics, home age, use and occupancy information, whether the property is a primary residence, ownership status and other homeowner/co-owner information, whether the property is owner occupied or used for another purpose, trust and trustee information where applicable, earthquake-insurance information, other descriptive characteristics of the property, property type and whether it has had any qualifying seismic retrofits or renovations, information about other seismic retrofit incentive payments from any entities, program eligibility responses, other homeowner (and optional co-owner) information and optional alert sign-up, information about how the registrant heard about CRMP, and for purposes of the EBB Program only, whether the registrant wishes to be considered for a supplemental grant, which is subject to a maximum household income. CRMP may use the property address and other property data to validate eligibility, geocode property location, determine latitude and longitude, verify assessor’s parcel numbers (APNs), evaluate program area, evaluate program-specific property criteria, support grant administration, and prevent duplicate or fraudulent applications.
- Mitigation Program Applications, Dashboard, Retrofit, and Payment-Support Information: For all Mitigation Program applicants and participants, CRMP may collect and maintain information (including Personal Information) uploaded or manually entered through the applicable program dashboard, including proof of residency (e.g., a California driver’s license, gas or electric utility bill, deed, property tax bill, or home retrofit permit), permits, plans, schematics, architectural drawings, engineering materials, pre- and post-retrofit photographs of the home, crawl space, water heater, foundation, cripple walls, soft-story conditions, or other program-relevant areas, retrofit project estimates, contractor or LDP selection information, optional contractor/LDP account read/write access rights, optional contractor/LDP reviews/comments, inspection materials, invoices, receipts, building department sign-off and other retrofit-completion documentation, payment authorization forms requiring applicant/program/payee identifiers, payee name, mailing address, approved grant amount, direct-deposit or other payment information, and other documents needed to verify eligibility/progress/completion of a retrofit project, administer grants, issue grant payments, conduct audits, or comply with any applicable Mitigation Program rules.
- For the EMR Program (and other programs where applicable), CRMP may collect building ownership and management information, mandatory city ordinance notices or documents received from city officials, unit-count information, other permit and retrofit documentation, soft-story or structural-condition documentation, contractor/LDP information, flood-insurance or Special Flood Hazard Area documentation, owner certifications, payment documentation, and audit or compliance materials required by grant conditions or Mitigation Program rules.
- Income, Tax, Grant, and Financial Verification Information:
- For certain CRMP programs that require income, tax, payment, or other grant-specific compliance requirements (e.g., the EBB Supplemental Grant applicants), CRMP may collect information such as name as it appears on tax return records, tax return filing status in applicable tax filing year, household-income eligibility responses, IRS Form W-9 or substitute tax form information (which includes social security number/individual taxpayer identification number), payee information, taxpayer identification information, identity-verification information, income-verification form responses, payment authorization materials, bank or direct-deposit information, and other information required by law, applicable Mitigation Program rules, grant conditions, audit requirements, or payment-processing requirements. CRMP may use third-party vendors or government systems to support verification and payment processing, subject to applicable law and contracts.
- For certain EBB Program and ESS Program participants who receive CRMP grant funds, CRMP may also collect and maintain IRS Form 1099 or other tax-reporting information only to the extent required by applicable tax-reporting rules, grant conditions or payment processing requirements.
- Contractor and LDP Registration: If a contractor, LDP, or related business user registers with CRMP to appear in a CRMP directory or program workflow, CRMP may collect and maintain information (including Personal Information) uploaded, manually entered or otherwise obtained, including name, contact information (business address, mailing address if different, email, phone, website address), business and professional information such as business name, license number, license classification/type, license status/expiration date, job title, insurance or bonding information, service area, training or qualification information, website, directory profile information, account credentials, program participation history, and other information otherwise obtained from the registrant, public records, and licensing boards and/or professional regulators (e.g., from California’s Contractors State License Board (“CSLB”) with respect to licensed contractors, and the Department of Consumer Affairs with respect to LDPs), information about how the professional heard about CRMP, text-alert option, and other information necessary to verify registration eligibility. CRMP may make certain contractor or LDP directory information available to the public or to Mitigation Program participants, but CRMP does not endorse, guarantee, supervise, or warrant any contractor, LDP, or third-party service provider unless expressly stated in applicable Mitigation Program rules.
- If a grant applicant has provided a specific contractor/LDP registrant read/write access to the grant applicant’s Property Owner Dashboard, CRMP may also collect additional information and uploaded documents from such professional about the grant applicant’s retrofit project, including photographs, invoices, receipts, schematics, drawings, and other project documentation when and as required for program participation or grant administration.
- ACH and Other Banking Information: If a grant applicant or licensed professional elects to receive fund disbursements electronically instead of by paper check, CRMP may collect name, email address and U.S. banking information (bank account name, country/region, account purpose, account type (checking or savings), account number, routing number, name on the account) and other payment credentials.
- Social Media and Related Content: If you interact with CRMP through official social media pages or public comment features, CRMP may receive your username, profile information, public comments, messages, reactions, shares, images, videos, tags, metadata, and other information made available to CRMP by you or the applicable platform. You should not post Social Security numbers, driver’s license numbers, tax information, financial account information, home access information, detailed security information, medical information, children’s information, or other sensitive Personal Information on CRMP’s social media pages.
- Ongoing Communications: If you otherwise contact CRMP in connection with one or more of the Services, CRMP may collect your name, email address, telephone number, mailing address, communication preferences, organization or role, other communications content (including any attachments), and other call or correspondence records.
Information from Other Sources
Consistent with law and this Notice, CRMP may receive information from third-party sources that support the Services. Sources may include Cal OES, CEA, FEMA, local building or permitting departments, tax or income-verification vendors, payment processors, property data providers, mapping or geocoding providers, the CSLB, the Department of Consumer Affairs, other licensing or regulatory entities, contractors, LDPs, and others authorized by a Program participant, and other federal, state, and local governmental entities, program partners, and Service Providers.
5. HOW CRMP USES INFORMATION
CRMP uses information for purposes that are lawful, relevant, and reasonably necessary for its functions as a public agency. These purposes include:
- Providing information and support about the Services and specific programs.
- Processing program registrations and applications, and communicating about Services and program status.
- Creating and managing portal access and accounts, including authentication and security controls.
- Verifying documentation for eligibility and conducting program integrity checks.
- Administering grant programs and payments, tracking projects, and coordinating with funding and oversight entities and local jurisdictions; and conducting program audits and compliance activities.
- Communicating with you about your application, participation status, deadlines, and program updates (and responding to inquiries).
- Operating, administering, and improving the Website and Services, including Website operations, performance monitoring, debugging, and usability improvements.
- Conducting analytics and measurement to understand Website performance and use and improve the usability, accessibility, and content effectiveness of the Services.
- Conducting outreach and public education, including advertising and campaign measurement, where implemented.
- Delivering and improving the Services, and overall user experience.
- Identifying Services that may be of interest to you and conducting public-outreach campaign measurement, where implemented and permitted by applicable law.
- Contacting you directly with information that may be useful about CRMP, the Mitigation Programs or public-safety and mitigation resources.
- Combining information in an aggregate or de-identified manner to derive program, operational, website or public-outreach statistics.
- Using photographs submitted by you for educational, research, or public relations purposes where permitted by applicable law, applicable Mitigation Program rules, and any required consent or release. Personal Information will be removed or minimized where feasible.
- Using aggregate or de-identified information where feasible to analyze how houses that are seismically retrofitted perform in earthquakes.
- Protecting the security and integrity of CRMP systems and users, protecting against fraud, abuse, unauthorized or illegal activity, and enforcing applicable terms and policies.
- Complying with applicable laws, regulations, recordkeeping obligations, lawful requests, and governmental oversight.
- Protecting the rights and safety of CRMP and the public.
- For any other purpose, with your consent, or as otherwise permitted or required by laws, regulations or legal process.
6. HOW CRMP DISCLOSES PERSONAL INFORMATION
CRMP discloses Personal Information only as permitted or required by applicable law, grant conditions, Mitigation Program rules, contracts, or an individual’s direction or permission. CRMP may share or disclose information in the following circumstances, to the extent permitted by applicable law:
- To CRMP personnel, officials, board members where appropriate, agents, consultants, contractors, and service providers who need the information to perform services for CRMP, operate the Services, administer programs, support technology, process payments, send communications, conduct audits, perform analytics, advertising and campaign measurement, provide customer service, or carry out CRMP’s public-agency functions.
- To Cal OES, CEA, FEMA, local building departments, permitting authorities, planning or engineering departments, funding partners, program administrators, auditors, oversight entities, and other federal, state, or local governmental entities, for program coordination and administration, grant compliance, eligibility review, audits, oversight, reporting, legal compliance, or public safety.
- To contractors, LDPs, inspectors, or other program participants when a homeowner or property owner directs CRMP to share information, authorizes access through a portal feature, selects the professional for program participation, or when sharing is otherwise necessary to administer the applicable program.
- To payment processors, financial institutions, tax or income-verification vendors, property-data vendors, mailing vendors, communications providers, identity providers, cloud-service providers, cybersecurity vendors, analytics providers, advertising and campaign-measurement providers, and other service providers under contracts, platform terms, configurations, or other arrangements that impose appropriate use and disclosure restrictions and safeguards appropriate to the information.
- As required or permitted by applicable law or regulation or in the good-faith belief that such action is necessary to: (a) comply with a legal obligation or respond to a request from law enforcement, courts, regulators, auditors, oversight bodies, or other public authorities (including response to subpoenas, court orders, search warrants, investigations, audits, legal process, legal claims, or governmental inquiries); (b) protect and defend the rights, safety, security, property, or integrity of CRMP, program participants, systems, contractors, public officials, or the public; (c) protect against or investigate fraud, abuse, misuse, cybersecurity incidents, or violations of Mitigation Program rules or law; (d) respond to emergencies; (e) enforce the Terms of Use or otherwise protect against legal liability; (f) support audit, compliance, and public-agency governance functions; or (g) respond to CPRA requests or other transparency-law obligations.
- For research, reporting, statistics, public education, and program evaluation and improvement, using aggregate, de-identified or anonymized information where feasible and lawful.
- Pursuant to your direction or consent, when consent is an appropriate legal basis, CRMP may share information for any other purposes not listed above.
CRMP does not sell Personal Information for money. CRMP does not disclose Personal Information collected through program applications or portal use to third parties for those third parties’ direct marketing purposes.
CRMP does not distribute or sell Electronically Collected Personal Information about Website users to any third party without prior written permission, except as required to investigate possible violations of Penal Code Section 502, as authorized under the IPA, or as otherwise permitted by Government Code Section 11015.5.
7. THIRD PARTY WEBSITES, PLATFORMS, AND SOCIAL MEDIA
The Services may link to or use a number of third-party websites, platforms, portals, applications, analytics tools, content delivery services, and other external products or services that CRMP does not own or control (“Third Party Sites”). This Notice does not apply to such Third-Party Sites. Please review such Third-Party Sites’ privacy, security, terms, conditions, and disclosures directly. CRMP does not control and is not responsible for the content, use or misuse of any information provided to or collected by any such Third-Party Sites.
CRMP also maintains social media pages. Your interactions on CRMP’s official social media pages are governed by the applicable social media platform’s terms and privacy practices as well as CRMP’s social media-related policies. Social media content may be visible to the public and may be subject to public records retention and disclosure. Please review CRMP’s applicable social media-related policies available on the Website or on the applicable social media page.
8. COOKIES, PIXELS, TAGS, WEB BEACONS, ANALYTICS, ADVERTISING AND OTHER TRACKING TECHNOLOGIES
CRMP uses (and permits certain Service Providers to use) internet methods, devices, identifiers, database applications, and other technologies to collect Technical Information and, in some cases, Electronically Collected Personal Information. These technologies may include cookies, pixels, tags, web beacons, software development kits, and similar tools.
a. Types of Technologies and How CRMP Uses Them
Essential / Functional Technologies
CRMP uses these technologies to operate the Website and portals, maintain sessions, authenticate users, remember settings or temporary registration responses, secure systems, prevent fraud, troubleshoot errors, enable core functionality, and comply with records, audit and security requirements.
Non-Essential Tools
CRMP may also use non-essential analytics, advertising, campaign-measurement, and similar public-outreach tools to understand how people use the Website and other Services, improve performance and usability, measure outreach campaigns, and inform the public about the Services, where permitted by applicable law.
These non-essential tools are intended for site performance, usability, outreach, and campaign measurement, not to collect or record sensitive program-application, tax, banking, payment, account-credential, or uploaded-document content. Where such tools are enabled, CRMP uses available configurations to limit or avoid capture of sensitive fields, files, dashboard content, and uploaded materials.
Analytics tools
CRMP uses analytics tools to understand Website usage and improve performance and usability. Current, planned, or periodically enabled tools include:
- Google Analytics, used to collect and analyze pages visited, user interactions and events, referring sources, device/browser information, approximate geographic location, session activity, traffic-source attribution, and aggregated Website analytics data.
- Crazy Egg, used to analyze how visitors interact with the Website by visually representing user behavior, such as clicks, scrolls, and navigation patterns. This helps CRMP understand how users engage with content and identify opportunities to improve site usability and performance. For more information, please see Crazy Egg’s privacy policy.
- GoSquared, used to help collect and analyze certain information for analytics purposes. For more information, please see GoSquared privacy policy.
- Hotjar, used to help understand users’ experience (for example, how much time is spent on which pages, which links are clicked, what users do and do not like, etc.), including through heatmaps, session recordings, scroll/click behavior, surveys, or feedback tools where enabled. For further details, please see Hotjar’s privacy policy.
Analytics providers may use cookies and similar technologies to collect and store Technical Information about use of the Services for the purposes described in this Notice. Where available, you may opt out of certain analytics collection through the provider’s opt-out mechanisms and browser settings.
Advertising and campaign-measurement tools
CRMP may use advertising and measurement tools to promote CRMP programs and measure the effectiveness of outreach campaigns, where permitted by applicable law. Current or planned tools include:
- Google Ads, including conversion measurement, used to collect or make available to CRMP campaign attribution data, advertising click identifiers, conversion events, pages visited, device/browser information, aggregated advertising performance metrics, daily performance, keywords, campaigns, and audience-breakdown data.
- Pixels/tags and related services from advertising channels and publishers, which may vary by campaign, but which may include, for example, Meta/Facebook, Taboola, Floodlight, Yahoo, and Nextdoor. CRMP’s advertising channels may change over time.
- LinkedIn Ads and the LinkedIn Insight Tag, if enabled for CRMP campaigns, used to measure the effectiveness of LinkedIn advertising campaigns and understand how users interact with the Website after viewing or engaging with LinkedIn advertisements. The LinkedIn Insight Tag may collect information about visits to the Website and interactions with Website content for advertising, analytics, and conversion-measurement purposes. For further details, please see LinkedIn’s Privacy Policy (https://www.linkedin.com/legal/privacy-policy). You may manage your advertising preferences through LinkedIn’s advertising settings (https://www.linkedin.com/help/linkedin/answer/a1342443).
- Web beacons or similar tags used by third-party advertising Service Providers, including Google and LinkedIn where enabled, may recognize a browser or device and collect information about interaction with ads or campaign landing pages.
These advertising and campaign-measurement technologies may involve Service Providers or advertising platforms collecting information or receiving identifier and usage information (for example, cookie IDs, device identifiers, IP address, pages visited, conversion events, and campaign-source information) when you use the Services. CRMP uses these tools only as permitted by applicable law and applicable permissions, and uses available contractual terms, platform settings, and other controls to limit use and disclosure where required or appropriate.
Third-party content delivery
CRMP loads content (such as icons, fonts, scripts, or libraries) from third-party providers or content delivery networks such as Font Awesome and Google Fonts. Font Awesome does not currently set cookies or browser storage for CRMP’s use. Google Fonts does not use cookies for CRMP’s use, but when your browser requests fonts or other content, the provider may receive Technical Information such as your IP address, browser/device details, and the requested resource.
SEMrush (SEO) and crawler tools
CRMP uses SEMrush as a search engine optimization and content analysis tool to review publicly available information about the Website (similar to a search engine crawler). SEMrush is not installed on the Website for user tracking, and CRMP has disabled SEMrush AI features.
b. Duration of Cookie and Similar Identifiers
Cookies and similar identifiers may be “session” based or “persistent,” and some analytics or advertising providers also maintain related event, analytics, or campaign data for periods set in CRMP’s administrative configuration or the provider’s systems:
- Session cookies typically expire when you close your browser.
- Persistent cookies remain on your device until they expire (based on the cookie’s settings) or until you delete them.
Based on CRMP’s current implementation information and available provider documentation, current cookie/storage durations and related CRMP-accessible data-retention periods include the following. You can see cookie storage and expiration information in your browser settings and can block or delete cookies at any time; however, some Services may not function properly if essential cookies are blocked.
- Essential login/session technologies. Azure AD B2C login cookies generally last until the end of the browser session or up to 1 hour and may be refreshed during the session. CRMP access-token cookies currently persist for up to 3 days, and CRMP access-token-refresh cookies currently persist for up to 1 year, unless deleted earlier by the user or superseded by a refreshed session.
- Registration prefill cookies. On registration pages, CRMP may use short-lived cookies to store individual dwelling qualification answers so that the registration form can be prefilled if a user returns. These cookies currently expire after 24 hours and do not renew automatically; if a user returns after expiration and answers the questions again, new cookies are created.
- Google Analytics. Google Analytics cookies used to distinguish users or maintain session state may persist for up to 2 years unless deleted earlier or configured differently. CRMP’s Google Analytics configuration currently retains CRMP-accessible analytics data for up to 14 months on a rolling basis.
- Google Ads. Google Ads conversion-measurement cookies and identifiers, including cookies that begin with “_gcl_,” generally last up to 90 days unless deleted earlier or configured differently. CRMP’s Google Ads configuration currently retains CRMP-accessible campaign attribution, advertising click identifiers, conversion events, pages visited, device/browser information, aggregated advertising performance metrics, daily performance, keywords, campaigns, and audience-breakdown data for up to 37 months on a rolling basis.
- Crazy Egg. When enabled, Crazy Egg implementation tags may collect page visits, click activity, scrolling behavior, mouse-movement patterns, navigation paths, device and browser information, traffic sources, and aggregated user-experience insights. Crazy Egg tracking-script cookies and storage items may include short-lived test/session items (for example, 1 second, 30 minutes, 24 hours, or session-only), visitor/recording/variant cookies that may persist up to 1 year, and attribution cookies that may persist up to 180 days. CRMP’s current implementation information identifies Crazy Egg snapshot-based data retention as up to 12 months.
- When enabled, Hotjar implementation tags may collect pages visited, clicks, taps, scrolling behavior, navigation paths, session recordings, user feedback or survey responses, device and browser information, and aggregated user-experience insights. Hotjar tracking-code cookies and storage items may include short-lived test items, session cookies of approximately 30 minutes that may be extended by user activity, site-specific user cookies or survey/feedback cookies that may persist up to 365 days, and related local or session storage. CRMP’s current configuration retains Hotjar data for approximately 1 month, although Hotjar configurations may permit retention for up to 12 months.
- LinkedIn Ads / LinkedIn Insight Tag. If enabled for CRMP campaigns, LinkedIn advertising and analytics technologies may use cookies and identifiers for advertising, analytics, and conversion measurement. LinkedIn’s third-party-site cookie table identifies, among others, session cookies, a 24-hour cookie (such as lidc), 30-day cookies (such as li_fat_id, UserMatchHistory, AnalyticsSyncHistory, lms_ads, and lms_analytics), 90-day cookies (such as li_sugr and _guid), 6-month cookies (such as li_gc and li_mc), and 1-year cookies (such as bcookie, bscookie, and oribili_user_guid). Actual cookies set may depend on LinkedIn configuration, campaign activity, and browser/user status.
- Content delivery and SEO tools. Font Awesome does not currently set cookies or browser storage for CRMP’s use. Google Fonts may receive Technical Information associated with browser requests for fonts or other resources. SEMrush is not installed on the Website for user tracking, and CRMP has disabled SEMrush AI features.
c. Your choices / Opting Out
You can control cookies and tracking in several ways:
- Browser controls: most browsers let you block or delete cookies, and control certain tracking behaviors. If you block cookies, some Website features may not function properly.
- DNT: Your browser settings may automatically transmit a “Do Not Track” (“DNT”) signal. Because there is no single, universally accepted technical standard for interpreting these browser DNT signals, CRMP does not currently alter its practices when it receives a DNT signal. Some third-party providers may offer their own Do Not Track mechanisms (see above). For more about DNT signals, please see the linked DNT resource.
- Provider-Specific Opt-Out Tools. You may also use provider-specific opt-out tools or privacy settings where available. These include:
- Google Analytics: you may be able to opt out using the Google Analytics opt-out browser add-on.
- Google Ads: you can control ad personalization through Google’s ad settings.
- LinkedIn: you may manage your advertising preferences through LinkedIn’s advertising settings and other LinkedIn privacy controls.
- Crazy Egg: Crazy Egg’s opt-out page may be accessed here: https://www.crazyegg.com/opt-out.
- Hotjar: where Hotjar is enabled, Hotjar states that it checks for the Do Not Track header in your browser before collecting data; Hotjar’s
Do Not Track instructions are available at
https://www.hotjar.com/policies/do-not-track/. - Industry opt-out tools: If you would like more information about interest-based advertising and to understand your options for not having this information used by these companies, please visit the Digital Advertising Alliance (DAA), or the Network Advertising Initiative (NAI). If you opt out of interest-based ads, you will still see ads on websites you visit, but those ads may no longer be based on your browsing behavior.
d. Discard Requests for Electronically Collected Personal Information
To the extent Government Code Section 11015.5 applies, you may request that CRMP discard Electronically Collected Personal Information without reuse or distribution. See Sections 10 and 13 for information on how to submit a request. CRMP will process such requests consistent with applicable records-retention, audit, grant, security, and legal requirements.
9. PUBLIC RECORDS AND RECORDS RETENTION
All records that CRMP creates, receives, or maintains in connection with the Mitigation Programs and other Services become CRMP records. As a public agency, CRMP records may be subject to public disclosure under the CPRA, unless an exemption or other legal requirement permits or requires withholding or redaction. Electronically Collected Personal Information is exempt from CPRA requests to the extent provided by Government Code Section 11015.5(a)(7). Other privacy, confidentiality, security, privilege, and public-interest exemptions may also apply depending on the nature of the record and circumstances. This Notice does not determine whether a record is subject to disclosure. CRMP will evaluate CPRA requests consistent with applicable law and will apply available exemptions and redactions as appropriate.
CRMP retains records in accordance with applicable laws, grant conditions, audit and security requirements, litigation holds, operational needs, and records-retention schedules and other policies.
- Program application and participation records, payment records, audit records, security logs, and other public records are retained as needed to administer programs, support audits and oversight, resolve disputes, and comply with legal, audit and recordkeeping obligations.
- Technical Information is retained for operational, security, analytics, advertising, and campaign-measurement purposes for periods appropriate to those purposes; current CRMP-accessible analytics and advertising/campaign-measurement data-retention periods are described in Section 8.b above.
CRMP may retain information longer where reasonably necessary for public agency functions, or where required or otherwise permitted by law.
10. YOUR RIGHTS AND PRIVACY REQUESTS
- IPA Access and Correction Rights. To the extent the IPA applies, you may inquire whether CRMP maintains records about you, request access to Personal Information in records maintained by reference to an identifying particular assigned to you, request an accounting of certain disclosures, and request amendment of records you believe may be incorrect or inaccurate, irrelevant, untimely, or incomplete. CRMP will process IPA requests subject to applicable exemptions, identity verification, IPA, CPRA and other legal limitations, including protection of other individuals’ Personal Information, and applicable deadlines. See Civ. Code §§ 1798.30, 1798.32, 1798.34, 1798.35, and 1798.36.
- Government Code Section 11015.5 (Electronically Collected Personal Information) Discard Requests. To the extent Government Code Section 11015.5 applies, you may request that CRMP discard Electronically Collected Personal Information without reuse or distribution. CRMP will process such requests consistent with Government Code Section 11015.5, and other applicable operational, security, legal, audit, and records-retention requirements.
- Email and Text Communications. If you receive optional email updates, you may unsubscribe using the unsubscribe instructions in the email or by contacting CRMP. If CRMP offers optional text alerts or messages, you may opt out of receiving any further optional text messages by following the instructions in the message or by contacting CRMP. CRMP may still send non-marketing communications necessary to administer your account, program participation, grant, payment, legal, administrative, or security obligations, as permitted or required by law.
- No General Consumer Deletion Rights. The California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act generally applies to certain for-profit businesses and does not create a general consumer “delete my data” deletion right against public agencies such as CRMP. CRMP will process deletion, discard, correction, access, and opt-out requests according to the IPA, Government Code Section 11015.5, records-retention laws, grant requirements, and other applicable laws.
To submit an IPA access/correction request, a Government Code Section 11015.5 discard request, or any other privacy requests or questions, please contact CRMP using the contact information in Section 13 below. To verify your identity and the scope of your request, locate responsive records, and protect the privacy of other individuals, CRMP may need you to provide additional information before proceeding.
11. INFORMATION SECURITY AND INCIDENT NOTIFICATION
CRMP maintains administrative, technical, and physical safeguards designed to protect information from unauthorized access, use, disclosure, alteration, or destruction, consistent with applicable state security standards. Safeguards may include secure transmission, encryption where appropriate, role-based access controls, authentication controls, logging and monitoring, vendor due diligence and security requirements, personnel training, incident-response procedures, and other measures appropriate to the sensitivity of the information and the risk to individuals and CRMP. No method of transmission or storage is completely secure. You are responsible for using secure devices and networks, protecting your credentials, and promptly notifying CRMP of suspected unauthorized account access.
If CRMP discovers a breach of the security of the system involving Personal Information, CRMP will provide notice as required by California law, including Civil Code Section 1798.29 where applicable, and any other applicable legal requirements.
12. CHILDREN’S PRIVACY
The Services are intended for adults, including homeowners who own real property in California, contractors, LDPs, and public agency personnel. The Services are not directed to children under 13 or to minors under 16. CRMP does not knowingly solicit or collect Personal Information from children. If you believe a child has provided Personal Information to CRMP, please contact CRMP using the contact information in Section 13 below.
13. HOW TO CONTACT CRMP
Address: California Residential Mitigation Program
Attn: CRMP Executive Director (Records Requests / Privacy)
400 Capitol Mall, Suite 1200
Sacramento, CA 95814
Phone: (877) 232-4300
Email: info@crmp.org
14. CHANGES TO THIS NOTICE
CRMP may update this Notice from time to time. When CRMP makes material changes, CRMP will post the updated Notice on the Website and update the Notice’s effective date. Where required by law, CRMP will provide additional notice, obtain permission, or apply prospectively any material changes to how information is collected, used or disclosed.