California Grand Casino Data Collection Notice and Privacy Policy for Employees

  1. California Grand Casino Privacy Policy

Respecting the privacy of our employees is an essential part of our privacy program. We are committed to the proper handling of the Personal Information collected or processed in connection with your employment relationship with us. Please read this Privacy Policy carefully.

This disclosure describes categories of Personal Information we collect and the purposes for which we process that information in accordance with section 1798.100 (b) of the California Consumer Privacy Act of 2018, as amended from time to time, (“CCPA”).  The CCPA defines Personal Information as categories of information that identifies, relates to, describes or is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly to a particular individual or household.  We will not collect additional categories of Personal Information or use Personal Information that we have collected for additional purposes without providing you with prior notice.

This policy is for our current and former employees and their family members, dependents, and beneficiaries.  If you are a California resident who is a current or former employee of the Company or a family member, dependent, or beneficiary of any of our current or former employees, you may request access to our Employee Privacy Policy or additional information by sending an email to [email protected]

If you reside in California, USA, you have additional rights with respect to your personal information as granted by the California Consumer Privacy Act of 2018, as amended from time to time (“CCPA”). We do not sell information to third parties within the meaning of the CCPA, that is information used for cross-context behavioral advertising, and have not done so within the prior 12 months.  We do not share information with third parties for commercial purposes.  Our information sharing with specific third parties and the purposes for sharing are disclosed in section 3 of this policy.  We do not target customers outside the United States. This privacy policy is not intended to comply with the law of any jurisdiction outside the U.S.

  1. Notice of Collection of Personal Information

“Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information includes, but is not limited to, the following if it identifies, relates to, describes, is reasonably capable of being associated with, or could be reasonably linked, directly or indirectly, with a particular consumer or household.

We have collected each of the following categories of Personal Information from one or more employees in the last 12 months.

(A) Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers.

(B) Any personal information described in subdivision (e) of Section 1798.80, which means any information that identifies, relates to, describes, or is capable of being associated with, a particular individual, including, but not limited to, his or her name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information,

(C) Characteristics of protected classifications under California or federal law. This includes sex, age, race, color, disability, medical conditions, marital status, gender (including pregnancy) and gender identity, military or veteran status, citizenship, primary language, and immigration status.

(D) Medical and health information including doctors’ notes and/or correspondence/documents from health care providers regarding absences, work restrictions, accommodation requests, medical leave of absence records, verification of the absence of TB, immunization records, various illnesses impacting public health, such as COVID-19 related information including diagnosis, testing results, having or displaying symptoms, and whether you have been in close contact in the last 14 days of anyone who has exhibited any of these symptoms or has tested positive for COVID-19.

(E) Information of family, friends, co-workers, and other individuals including phone and email of emergency contacts, dates of birth and gender of spouse/partner and/or children, medical and health information for family members, friends, co-workers and other individuals with whom you’ve had contact related to certain illness impacting public health, such as COVID-19 symptoms, exposure, testing, and family travel information.

(F) Internet or other electronic network activity information, including, but not limited to, information regarding interaction with an internet website application, or advertisement, internet or network activity information, such as use of our wifi and interactions with our website or systems.

(G) Geolocation data.

(H) Audio, electronic, visual, or similar information, such as images and audio, video or call recordings created in connection with our business activities.

(I) Professional or employment-related information, such as highest educational level, business or work history, Live Scan background check, professional licenses and certifications, schools attended, graduation dates and degrees or diplomas obtained, school transcripts, references, internship and volunteer activities, and awards received.

(J) Travel information including whether you’ve recently traveled to a restricted area under a Travel Advisory, locations traveled to within 14 days prior to coming to the workplace and dates spent in those locations.

(K) Inferences drawn from any of the information identified in this subdivision to create a profile about a consumer reflecting the consumer’s preferences, characteristics, predispositions, behavior, attitudes, and abilities.

We have also collected information from public websites and public records.

Sensitive personal information” we collect includes Personal information that reveals:

(A) A consumer’s social security, driver’s license, state identification card, or passport number.

(B) A consumer’s financial account, debit card, or credit card number in combination with credentials allowing access to an account in the case of counter checks or credit transactions.

We use this information to process transactions, comply with Title 31 laws and other laws and regulations, and to assist law enforcement or claims handling.  We also use the subpart (A) information for hiring and contracting decisions.

Sensitive Information and Personal Information as used in this policy does not include publicly available information, or information that is “aggregate consumer information” or information that is “deidentified” as defined in Cal. Civ. Code sec. 1798.140(b) and (m).

Personal Information That You Provide To Us. You provide us information when you:

  1. provide us with your personal information for any reason;
  2. join our email list;
  3. register for or participate in one of our events, surveys, contests or promotions;
  4. use casino services, including cash advance, ATM, players’ bank, check cashing, credit, counter checks, chip advance, ACH or wire payment, or food and beverage services where you provide personal information, including a credit or debit card, bank information or tax identification number;
  5. provide identification which we may scan, copy or record;
  6. provide us information or we record information in order to comply with legal requirements respecting financial transactions;
  7. enter the premises, parking area, or nearby areas and are recorded on video;
  8. Stand near the cage where there are audio recordings;
  9. visit our website at https://www.californiagrandcasino.com/;
  10. view digital ads;
  11. enable location services when using your phone;
  12. use our Wi-Fi services;
  13. engage with us on social media;
  14. register under a problem gambling program;
  15. provide services to us as an independent contractor; or
  16. apply for employment, work for us or ask to work as an independent contractor or vendor. For example, an employee may supply information about education, employment, employment history, financial information, medical information and health information, and the identification of relatives that work here.

We collect data on family members, dependents, and beneficiaries to the extent needed to contact you or provide you benefits.

We also may use information you provide us to prevent harmful exposures in the workplace.

We also collect data from:

  1. Your job application
  2. Surveillance cameras.
  3. Audio recording at and nearby the cage.
  4. State, County and federal agencies
  5. Security and risk management vendors
  6. Other persons when you interact with them and they submit information about you to us
  7. Job references, recruiters, and staffing agencies
  8. Job performance documentation and incident reporting.
  9. Customer Reports.
  10. Social media platforms;.

Commencing in 2023, we may collect information from consumer and credit reporting agencies for applicants for certain job positions, such as cage and shift manager.

Information That We Collect From You Automatically.

We may collect information from you automatically when you visit our website, use the Internet or your phone, your web browser, or operating system, which may transmit certain information to servers. The information may include the unique number assigned to your server or Internet connection, your geographic location, or your movement within a website including what pages you look at and what information you download.

We use cookie technology on our website. A “cookie” is a small data file that can be placed on your hard drive. Cookies store information that a website may need to personalize your experience and to gather statistical data, such as the pages you visit, what material you download, your internet provider’s domain name and country, and other information.  The California Grand Casino uses cookies to collect and store your preferences for viewing our website and for providing a unique identifier to your computer so that we can generate statistics regarding the use of our website.

  1. Use of Information

The California Grand Casino may use the information collected by us: (1) to respond to your inquiries or requests for service, wage and hour determinations, payroll and benefits, including financial services and third party financial services; (2) for marketing purposes, including, but not limited to, providing you with e-mail or notification of future California Grand Casino events, food specials and services that may be of interest to you; (3) to process and fulfill registrations, awards or participation in games, gaming activities or promotions; (4) to organize and facilitate events, communications or offers; (5) to process and fulfill transactions; (6) to respond to complaints and other communications; (7) to comply with laws and regulations, legal requirements and internal control policies, including to respond to subpoenas, court orders, legal process, or to exercise our legal rights or defend against legal claims; (8) for hiring and for management of employees; (9) for demographic purposes; (10) to investigate incidents, insurance claims or other claims; (11) to assist law enforcement; (12) to generate information from our website use to generate aggregate statistics about visitors to our website; (13) to investigate, prevent or take action regarding, or to keep records regarding prior, possible illegal activities, suspected fraud, situations involving potential threats to any person’s personal safety, or other incidents involving reasonably suspected criminal activity or violations of law, or policies; (14) to cooperate with law enforcement, insurance companies or regulators in an on-going investigation, (15 for use in hiring or contracting.    Hiring uses include promotions, re-assignment, compliance with laws and regulations, the evaluation of job candidates or applicants, background checks, insurance coverage and rules, and to aggregate data to perform workforce analytics, hiring data and benchmarking; (16) because of or to supply insurance, benefits or a retirement savings plan; and (17) to comply with labor laws and agency regulations relating to employees and employment.  In the prior 12 months, personal information has been put to each of these uses.

In the future, personal information could be shared in connection with a business transaction involving a sale, purchase, reorganization, or transfer to a third party of any of the assets of the California Grand Casino or California Grand Casino website. For example, we may transfer customer lists to a buyer of the Casino.

The casino uses personal information for the purposes listed above which may be determined to be other than those specified in Reg section 7027, subsection (m) and Regs. Sec. 7011(e)(1)(K). You may limit your use of such information through our website form https://www.californiagrandcasino.com/ccpa-request-form/ or by contacting us at [email protected] We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.

We also have video and audio surveillance in and outside our facility in order to comply with laws and regulations, to provide patron security, to assist law enforcement and to improve our operations. We do not use images for commercial use unless we have obtained consent, we have posted notice that at certain times we are filming commercials or recording images for advertising and persons present may be imaged, or unless the use is inadvertent.

Information Sharing and Disclosure with Third Parties and Purposes.  We allow specific third parties to access Personal Information and/ or Sensitive Information for business purposes only. When you provide us with a credit card, we use third party payment processors Shift4 Payments and MICROS to process your credit card for food and beverage sales. We use the Fabitrack system to track floor transactions in order to comply with federal laws and regulations known as Title 31. If you use the ATM or cash advance system you will be providing information to Everi, the operator of those systems, in order to complete your transaction.  Website usage information is seen by Social SEO, our digital marketing agency; and Google for paid advertising. We use this information to improve our marketing.  We share information with companies and persons that assist us in fulfilling our “customer due diligence” and Title 31 obligations, including Fabitrack and independent auditors.  We share demographic information with Social SEO for marketing but without customer names, phone numbers, email addresses or residential house numbers or street names.  We may run credit checks using a third party credit agency as part of a transaction, hiring or employment decision. You should know that where it is possible to do so, third parties may link available information to your Personal Information. When we provide personal information to our business partners and other third parties for such purposes, we require them to the extent feasible to exercise reasonable care to protect your Personal Information and restrict the use of your Personal Information to the purposes for which it was provided to them.

We also share information with ADP for payroll purposes, Kaiser for health care purposes, and a plan administrator for retirement accounts.

We encourage our customers to “Play Responsibly.” While most individuals gamble for entertainment purposes, some individuals may develop a gambling problem. California Grand Casino offers a voluntary Self-Restriction program with materials available in our Casino. Individuals who sign up for this program and identify means of contact (such as an email address) may not receive any direct marketing materials or information about products or services during their self-restriction period.

We also participate in the state-wide Self-Exclusion program.  More information can be found in our Casino, by calling 1-800-Gambler, or at the Office of Problem Gambling website: http://problemgambling.ca.gov/ccpgwebsite/default.aspx

In order to comply with regulations and laws, information disclosed to us under our Self-Restriction program may be shared with law enforcement and regulators if we need assistance from law enforcement to remove you from the premises, and may also be shared or upon the request of a government agency. Information disclosed to us under the statewide Self-Exclusion program is shared with other cardrooms and the Bureau of Gambling Control, and may be shared with law enforcement if we need assistance from law enforcement to remove you from the premises, or shared upon request of a government agency.

  1. Retention Periods.

We are subject to the regulations of government agencies, including the California Gambling Control Commission. We retain personal information for financial transactions as required in those regulations for up to seven years. We retain certain financial and employment records for employees for seven years after employment ends. These records include but are not limited to personnel files, complaint, incident and investigation records, payroll and timekeeping, and medical records.  Other electronic records, such as video recordings, computer activity, cookies, geo location data is retained for weeks and up to a year. Other records are retained for the period in which a claim may be brought under the applicable statute of limitations, or the periods or periods determined by management for the Company’s legitimate business or commercial purposes that is reasonably necessary and compatible with the context in which the information was collected.  These periods are subject to change by management and subject to government regulation and changes in regulation.  You may request a copy of the then current record retention policy as provided under Contact Us in this policy.

  1. Data Security

California Grand Casino has security measures in place to protect against the loss, misuse, and alteration of the information under our control. While we make every effort to ensure the integrity and security of our network and systems, we cannot guarantee that our security measures will be fool proof or prevent third-parties including “hackers” from illegally obtaining this information.

  1. Exercising Your Rights – California Residents

The CCPA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.

Rights.

You have the right to: (1) know what personal information we have about you; (2) request a copy of the information we have in a manner that allows you to obtain your personal information in a readily-usable format that can be transferred to another service; (3) the right to know whether your personal information is being sold or shared with third parties, and to opt out of data collection including the sale or sharing of your personal information; (4) have personal information deleted, subject to the authorized exceptions in this privacy policy and law; (5) correct inaccurate personal information; (6) limit the information we have if we use sensitive personal information outside of the permitted reasons in Regulation 7027(m), which is summarized below in the subsection for Deletion Request Rights; or (7) withdraw from any promotions or incentives. A person may also submit their request through an authorized agent.  No person may be discriminated against or retaliated against for exercising any of the above rights.

The right to know includes the right to know what personal information the business has collected about the consumer or person, including the categories of personal information, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting, selling, or sharing personal information, the categories of third parties to whom the business discloses personal information, and the specific pieces of personal information the business has collected about the consumer.

You also can request:

  • Our business or commercial purpose for collecting or selling your personal information.
  • The categories of third parties with whom we shared your personal information.
  • If we sold or disclosed your personal information for a business purpose, two separate lists disclosing:
    • sales, identifying the personal information categories that each category of recipient purchased; and
    • disclosures for a business purpose, identifying the personal information categories that each category of recipient obtained.

            Deletion Request Rights

You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request (see Exercising Access and Deletion Rights, below), we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies under Regulation 7027(m), which provides in subparts (1)-(8):

We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:

(1) To perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services. For example, a consumer’s precise geolocation may be used by a mobile application that is providing the consumer with directions on how to get to specific location. A consumer’s precise geolocation may not, however, be used by a gaming application where the average consumer would not expect the application to need this piece of sensitive personal information.

(2) To prevent, detect, and investigate security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information. For example, a business may disclose a consumer’s log-in information to a data security company that it has hired to investigate and remediate a data breach that involved that consumer’s account.

(3) To resist malicious, deceptive, fraudulent, or illegal actions directed at the business and to prosecute those responsible for those actions. For example, a business may use information about a consumer’s ethnicity and/or the contents of email and text messages to investigate claims of racial discrimination or hate speech.

(4) To ensure the physical safety of natural persons.  For example, a business may disclose a consumer’s geolocation information to law enforcement to investigate an alleged kidnapping.

(5) For short-term, transient use, including, but not limited to, nonpersonalized advertising shown as part of a consumer’s current interaction with the business, provided that the personal information is not disclosed to another third party and is not used to build a profile about the consumer or otherwise alter the consumer’s experience outside the current interaction with the business. For example, a business that sells religious books can use information about its customers’ interest in its religious content to serve contextual advertising for other kinds of religious merchandise within its store or on its website, so long as the business does not use sensitive personal information to create a profile about an individual consumer or disclose personal information that reveals consumers’ religious beliefs to third parties.

(6) To perform services on behalf of the business. For example, a business may use information for maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of the business.

(7) To verify or maintain the quality or safety of a product, service, or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured by, manufactured for, or controlled by the business. For example, a car rental business may use a consumer’s driver’s license for the purpose of testing that its internal text recognition software accurately captures license information used in car rental transactions.

(8) To collect or process sensitive personal information where such collection or processing is not for the purpose of inferring characteristics about a consumer. For example, a business that includes a search box on their website by which consumers can search for articles related to their health condition may use the information provided by the consumer for the purpose of providing the search feature without inferring characteristics about the consumer.

Common reasons why we may keep your personal information include:

  • Because you are still employed here.
  • To complete your transaction, provide a reasonably anticipated product or service, or for certain liability purposes.
  • For certain business security practices.
  • For certain internal uses that are compatible with reasonable employee expectations or the context in which the information was provided
  • To comply with legal obligations, exercise legal claims or rights, or defend legal claims.
  • If the personal information is certain medical information, consumer credit reporting information, or other types of information exempt from the CCPA.
  • Where deletion proves impossible or involves disproportionate effort, as provided in Civil Code sections 1798.105(c). See Civil Code sections 1798.105(d) and 1798.145 for additional exceptions.

The additional statutory exceptions under 1798.105(d) include:

  1. Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform our contract with you.
  2. Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity.
  3. Debug to identify and repair errors that impair existing intended functionality.
  4. Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law.
  5. Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code.
  6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the businesses’ deletion of the information is likely to render impossible or seriously impair the achievement of such research, if the consumer has provided informed consent.
  7. To enable solely internal uses that are reasonably aligned with the expectations of the consumer based on the consumer’s relationship with the business.
  8. Comply with a legal obligation.

      Opt-out

You may request that California Grand Casino not collect your personal information by opting out.  Opting-out will not prevent your Personal Information from being used for purposes specified in Section 4, including where legally required.  Opting-out also may not protect you from future data collection if you continue to visit our website, casino or continue to use our services.

Our website through the use of a plug-in will process cookie limits and opt-out preference signals by device as requests to opt-out of the sale and sharing of the consumer’s information.  You simply need to state your preference using the banner notice on the website.  You also can use the Limit the Use of My Sensitive Personal Information Form Link at the bottom of our website pages https://www.californiagrandcasino.com/, or email us at [email protected] if you wish to opt out based on other criteria.

      Exercising Access, and Deletion Rights

We have pre-printed forms for you to complete for CCPA requests.  You can start the process by:

  1. Using the form and submitting it in person at the cage.
  2. Filling out the same form on our website.
  3. Calling this toll-free number: 855-556-8813,
  4. Emailing the form or a request to [email protected], or
  5. Mailing the form or a Written Request sent First Class Mail to: Attn:  Privacy Policy Administrator,  5988 Pacheco Blvd., Pacheco CA 94553

All requests must contain the following information:

  • Your full and complete legal name, and any alias or other names or nicknames you use:
  • Your contact information, including mailing address, email and phone. We need your email to speed up communications between us in processing your request, and because some records we maintain may be searchable by or contain only an email address.

A description of the services you used and personal information you provided us with the circumstances, approximate dates and times.  For example, did you use cash advances or check cashing?

            Verifying Consumer Request and Agency.

We also will need to verify your identity before releasing any personal information about you, except a request to opt-out need not be a verifiable consumer request and a request to limit also need not be a verifiable request. For other requests, including requests to know, delete or correct, we will ask for visual verification of your identity using government issued identification.  This may be done in person, or over communications facilities, or a means that is practical for the consumer or requestor. We will attempt to match the verification to the personal information we have.  We shall delete any new personal information collected for the purposes of verification as soon as practical after processing the consumer’s request, except as required to comply with regulation section 7101. We do not require the consumer or the consumer’s authorized agent to pay a fee for the verification of their request to delete, correct or know. For requests to correct, we will make an effort to verify the consumer based on personal information that is not the subject of the request to correct.

An authorized agent may make a request on a consumer’s behalf with written evidence of authority.

Response Timing and Format.

For a request to opt out, we must stop selling and sharing personal information as soon as feasibly possible, but no later than 15 business days from the date we receive the request. We must also notify all third parties to whom we have sold or shared personal information within that same 15 business day period that the consumer has made a request to opt-out of the selling and sharing of personal information.

For requests to limit, we must stop using and disclosing consumer’s sensitive personal information except for permissible purposes as soon as feasibly possible, but no later than 15 business days from the date we receive the request. Further, we must notify all our service providers, contractors, and third parties that use or disclose the consumer’s sensitive personal information for other than the permissible purposes as soon as feasibly possible, but no later than 15 business days from the date you receive the request.

For other requests, we endeavor to confirm receipt of your request within 10 days of receiving the request and we may take 45 days from the initial request to respond. We can add 45 days to our response time only if there is good cause to do so, such as the customer not supplying us with adequate information to use to verify identity and locate personal information, and we provide notice to the customer of the extension within the original 45 day response period. The information we will provide is through the date the request is received.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded.

Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. There are no limits on the number of requests to delete.  For other requests, a maximum of two requests may be made in a 12 month period.

For persons who are not California residents, please submit your requests using the form and means described herein.

  1. Other California Privacy Rights

California’s “Shine the Light” law (Civil Code Section § 1798.83) permits users of our Website that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email to mailto:[email protected] or write us at:   Attn:  Privacy Policy Administrator, 5988 Pacheco Blvd., Pacheco CA 94553.

  1. Questions About California Grand Casino’s Privacy Policy

If you have questions about this Privacy Policy or the practices described herein, you may contact the Privacy Policy Administrator by mail:

Attn: Privacy Policy Administrator

California Grand Casino
5988 Pacheco Blvd.,

Pacheco, CA 95443

Or by email at [email protected] with “Privacy” in the subject field.

  1. Revisions to This Policy

California Grand Casino reserves the right to revise, amend, or modify this policy at any time and in any manner. Any revision, amendment, or modification will be posted on our website and found at our cage. We will also email a link to the updated privacy policy to those persons for whom we have an email address.  You can provide us your email address at the bottom of the home page of our website.

Rev. / Review  Sept. 25, 2024

(Click here for a printable Information Request Form pdf)