Healthcare cost insights from 1,500 small and midsize employersRead more

California Privacy Policy

Effective Date: August 12, 2026

Last Reviewed on: August 12, 2026

Introduction

This California Privacy Policy (this “California Privacy Policy”) describes how Pareto Captive Services, LLC, Pareto Health, LLC, and Pareto Underwriting Partners, LLC, together with their respective subsidiaries (collectively, “Pareto,” “we,” or “us”) collect and process personal information about individuals who reside in California. The California Consumer Privacy Act (“CCPA”) requires us to provide such California-based individuals with a privacy policy that contains a comprehensive description of our online and offline practices regarding our collection, use, sale, and sharing of their personal information, along with a description of the rights they have regarding their personal information. This California Privacy Policy provides the information that the CCPA requires, together with other useful information regarding our collection, use, and disclosure of personal information. Any terms defined in the CCPA have the same meaning when used in this California Privacy Policy.

This California Privacy Policy does not apply to our collection and use of personal information in an employment capacity. Employees, job applicants, contractors, interns, or other workers seeking more information about our employment-related personal information policies and practices should see our employee privacy policy applicable to California-based individuals, available at Pareto’s CCPA Notice of Collection for California Employees and Applicants.

This California Privacy Policy does not apply to our collection and use of personal information from residents outside of California. Individuals residing in other locations should see our general privacy policy (the “General Privacy Policy”) at Privacy Policy 2026.

Personal Information Collected

Pareto collects certain information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device (“personal information”). Personal information does not include:

  • Publicly available information, including from government records, through widely distributed media, or that the consumer made publicly available without restricting it to a specific audience.
  • Lawfully obtained, truthful information that is a matter of public concern.
  • Deidentified or aggregated consumer information.
  • Information specifically excluded from the CCPA’s scope, such as
    • health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA), clinical trial data, or other qualifying research data; or
    • personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA), California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act.

Personal Information Categories Chart

The chart below identifies the categories of personal information we collected from our consumers within the last twelve (12) months:

Category Examples Collected?
A. Identifiers. A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers. Yes 
B.  Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.

Some personal information included in this category may overlap with other categories.

Yes  
C. Protected classification characteristics under California or federal law. Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). No
D. Commercial Information. Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. Yes  
E. Biometric information. Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. No
F. Internet and other similar network activity. Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement. Yes
G. Geolocation data. Physical location or movements, such as zip code, the time and physical location related to use of the website or mobile app, or other information about the individual’s location or locations he or she visited. Yes
H. Sensory data. Audio, electronic, visual, thermal, olfactory, or similar information. No
I.  Professional or employment-related information. Current or past job history or performance evaluations. Yes 
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)). Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. No
K. Inferences drawn from other personal information. Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. No
L. Sensitive personal information. Further identified in the chart below. No

Sensitive Personal Information Categories Chart

Sensitive personal information is a subtype of personal information consisting of the specific information categories listed in the chart below. Importantly, the CCPA only treats this information as sensitive personal information when we collect or use it to infer characteristics about a consumer.

The chart below identifies which sensitive personal information categories, if any, we have collected from consumers to infer characteristics about them in the last twelve (12) months.

Sensitive Personal Information Category Collected to Infer?
L.1.  Government identifiers, such as your Social Security number (SSN), driver’s license, state identification card, or passport number. No
L.2. Complete account access credentials, such as usernames, account logins, account numbers, or card numbers combined with required access/security code or password. No
L.3.  Precise geolocation, such as GPS data from a consumer’s mobile device that can provide its location in a geographic area, with an approximate radius of 1,850 feet. No
L.4.  Racial or ethnic origin. No
L.5.  Citizenship or immigration status. No
L.6.  Religious or philosophical beliefs. No
L.7.  Union membership. No
L.8.  Mail, email, or text messages not directed to Pareto. No
L.9.  Genetic data. No
L.10.  Neural Data, such as information generated by measuring a consumer’s central or peripheral nervous system’s activity that is not inferred from nonneural information. No
L.11.  Unique identifying biometric information. No
L.12.  Health information. No
L.13.  Sex life or sexual orientation information. No
L.14.  Children’s personal information (under age 16). No

Sources of Personal Information

Pareto obtains the categories of personal information listed above from the following categories of sources:

  • Directly from you, such as from the forms you complete on Pareto’s website, information you provide while attending an event hosted by Pareto, or other information you provide to Pareto or any of its agents or employees.
  • From our service providers, such as webinar providers, conference organizers, data analytics providers, and data enrichment providers.
  • Indirectly from you when you navigate Pareto’s websites or mobile applications. For example, Pareto obtains information about your IP address, type of computer equipment you use, your geographic location, and browsing history when you access and interact with Pareto’s website.
  • From Pareto’s clients.  For example, if your employer is a client of Pareto, your employer may provide Pareto with your personal information as part of its business relationship with Pareto.
  • From brokers and consultants with whom Pareto has a business relationship.

How Pareto Uses Personal Information

Personal Information Collection, Use, and Disclosure Purposes

Pareto may use and disclose the personal information it collects to advance Pareto’s business and commercial purposes, specifically to:

  • Develop, offer, and provide Pareto’s products and services to your organization and others.
  • Fulfill or meet the reason you provided the information. For example, if you share your name and contact information to request a quote or ask a question about Pareto’s products or services, Pareto will use that personal information to respond to your inquiry. 
  • Contact you/your organization in the future regarding Pareto’s other products or services.
  • Provide, support, personalize, and develop Pareto’s website.
  • Create, maintain, customize, and secure your/your organization’s account with Pareto.
  • Process your/your organization’s requests, purchases, transactions, and payments, and prevent transactional fraud.
  • Carry out Pareto’s obligations and enforce Pareto’s rights arising from any contracts entered into between you/your organization and Pareto, including for billing and collections.
  • Provide you/your organization with support and respond to your/your organization’s inquiries, investigate and address your/your organization’s concerns, and monitor and improve our responses.
  • Notify you/your organization about changes to Pareto’s products or services.
  • Personalize your website experience and deliver content and product and service offerings relevant to your interests.
  • Measure or understand the effectiveness of Pareto’s marketing to you, your organization, and others, and deliver relevant marketing to you.
  • Make suggestions and recommendations to you, your organization, and others about Pareto’s products or services that may interest you or them.
  • Allow you to participate in the interactive features on Pareto’s website, such as the chatbot feature.
  • Help maintain the safety, security, and integrity of Pareto’s website, products and services, databases and other technology assets, and business.
  • Administer Pareto’s systems and conduct internal operations, including troubleshooting, data analysis, testing, research, statistical, and survey purposes.
  • Test, research, analyze, develop, and improve products, services, website features and functionality, and customer relationship and experience.
  • Perform data analytics and benchmarking.
  • Protect Pareto, its employees, or operations.
  • Respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
  • Undertake any actions specifically described to you when collecting your personal information or as otherwise set forth in CCPA.
  • Evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by Pareto is among the assets transferred.

Sensitive Personal Information Use and Disclosure Purposes

Pareto may use or disclose sensitive personal information for the following statutorily approved reasons (“Permitted SPI Purposes”):

  • Performing actions that are necessary for our consumer relationship and that an average consumer in a relationship with us would reasonably expect.
  • Preventing, detecting, and investigating security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information.
  • Defending against and prosecuting those responsible for malicious, deceptive, fraudulent, or illegal actions directed at Pareto.
  • Ensuring physical safety.
  • Short-term, transient use, such as non-personalized advertising shown as part of your current interactions with us, where we do not:
    • disclose sensitive personal information to another third party; or
    • use it to build a profile about you or otherwise alter your experience outside your current interaction with the Company.
  • Services performed for Pareto, including maintaining or servicing accounts, processing or fulfilling transactions, verifying consumer information, processing payments, or providing financing, analytic services, storage, or similar services for the Company.
  • Activities required to:
    • verify or maintain the quality or safety of a product, service, or device that we own, manufacture, had manufactured, or control; or
    • improve, upgrade, or enhance the service or device that we own, manufacture, had manufactured, or controlled.
  • Collecting or processing sensitive personal information that we do not use for the purpose of inferring characteristics about a consumer.

Pareto does not use or disclose sensitive personal information for purposes other than the Permitted SPI Purposes.

Additional Categories or Other Purposes

Pareto will not collect additional categories of personal information or use the personal information it collected for materially different, unrelated, or incompatible purposes without providing you with an appropriate notice. If required by law, Pareto will also seek your consent before using your personal information for a new or unrelated purpose.

Pareto may collect, process, and disclose aggregated or deidentified consumer information for any purpose, without restriction. When we collect, process, or disclose aggregated or deidentified consumer information, we will maintain and use it in deidentified form and will not attempt to reidentify the information, except to determine whether our deidentification processes satisfy any applicable legal requirements.

Disclosing, Sharing, or Selling Personal Information

Pareto may disclose the personal information it collects to service providers and contractors for the business purposes described in the Personal Information Collection, Use, and Disclosure Purposes section and in the table below, such as to support Pareto’s business functions.  Pareto only makes these business purpose disclosures under written contracts that describe the purposes, require the recipient to keep the personal information confidential, prohibit using the disclosed information for any purpose except performing the contract, and meet the CCPA’s other contract requirements for engaging service providers or contractors.

The chart below identifies the personal information categories we disclosed to service providers or contractors for a business purpose over the preceding twelve (12) months and the specific business or commercial purpose for disclosing that information.

Business Purposes Disclosure Personal Information Category and Purposes Chart

Personal Information Category Business Purpose of the Disclosures
A. Identifiers.
  • Cloud storage
  • Marketing campaign management
  • Lead and customer relationship management
  • Website analytics and engagement tracking
  • Audience targeting and segmentation
  • Pareto event communication and registration
  • Business operations, platform support, service delivery
B.  Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
  • Cloud storage
  • Marketing campaign management
  • Lead and customer relationship management
  • Website performance analytics and engagement tracking
  • Audience targeting and segmentation
  • Pareto event communication and registration
  • Business operations, platform support, service delivery
C. Protected classification characteristics under California or federal law. None.  Pareto does not collect this category of personal information.
D. Commercial Information.
  • Cloud storage
  • Marketing and membership renewal communications
  • Customer relationship management
  • Analysis of Pareto’s products and services
  • Business operations and account support
  • Internal business operations
E. Biometric information. None. Pareto does not collect this category of personal information.
F. Internet and other similar network activity.
  • Marketing campaign management
  • Website performance analytics and engagement tracking
  • Lead and customer relationship management
  • Webinar administration and engagement analysis
  • Business operations, reporting, and platform support
G. Geolocation data.
  • Marketing campaign management
  • Website performance analytics and engagement tracking
  • Lead and customer relationship management
  • Webinar administration and engagement analysis
  • Business operations, reporting, and platform support
H. Sensory data. None. Pareto does not collect this category of personal information.
I.  Professional or employment-related information.
  • Lead generation and customer relationship management
  • Marketing communications and outreach
  • Pareto event registration and management
  • Marketing campaign optimization
  • Business operations, reporting, and platform support
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)). None. Pareto does not collect this category of personal information.
K. Inferences drawn from other personal information. None.  Pareto does not collect this category of personal information.
L. Sensitive personal information. None.  Pareto does not collect this category of personal information.

Selling or Sharing Personal Information

Pareto does not sell your personal information to third parties and has not sold it in the preceding twelve (12) months. Pareto may share your personal information with third parties for cross-context behavioral advertising purposes.  The chart below identifies the categories of third parties with whom Pareto has shared consumers’ personal information for cross-context behavioral advertising purposes over the preceding twelve (12) months, along with the personal information categories shared and the business or commercial purposes for sharing that information.

Categories of Third Parties Categories of Personal Information Shared Commercial or Business Purpose
Social media companies.
  • Identifiers
  • Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))
  • Geolocation data
  • Professional or employment-related information
To provide targeted advertising for Pareto’s products and services.

Pareto’s sharing of personal information does not include information about consumers that we know to be under the age of 16.

Your Rights and Choices

The CCPA provides California residents with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.

Right to Know and Data Portability

You have the right to request that Pareto disclose certain information to you about its collection and use of your personal information (the “right to know”), including the specific pieces of personal information we have collected about you (a “data portability request”).  Our response will cover the twelve (12) month period preceding the request, although we will honor requests to cover longer periods that do not extend past January 1, 2022, unless doing so would be impossible or involves disproportionate effort. Once Pareto receives your request and confirms your identity, Pareto will disclose to you:

  • The categories of personal information Pareto collected about you.
  • The categories of sources from whom Pareto collected your personal information.
  • Pareto’s business or commercial purpose for collecting your personal information and, if applicable, selling or sharing your personal information.
  • If applicable, the categories of persons, including third parties, to whom we disclosed your personal information, including separate disclosures identifying the categories of your personal information that we:
    • disclosed for a business purpose to each category of persons; and
    • sold or shared to each category of third parties
  • When your right to know submission includes a data portability request, a copy of your personal information, subject to any permitted redactions.

Right to Delete and Right to Correct

You have the right to request that Pareto delete any of your personal information that Pareto collected and retained, subject to certain exceptions (the “right to delete”). Once we receive your request and confirm your identity, we will delete your personal information from our systems unless an exception allows us to retain it. We will also notify our service providers, contractors, and other recipients to take appropriate action.

You also have the right to request correction of personal information that Pareto maintains about you that you believe is inaccurate (the “right to correct”). We may require you to provide documentation, if needed, to confirm your identity and support your claim that the information is inaccurate. Unless an exception applies, we will correct personal information that our review determines is inaccurate and notify our service providers, contractors, and other recipients to take appropriate action.

Right to Limit Sensitive Personal Information Use and Disclosure to Permitted SPI Purposes

You have a right to ask businesses that use or disclose your sensitive personal information to limit those actions to just the CCPA’s Permitted SPI Purposes. Because Pareto does not use or disclose sensitive personal information beyond the CCPA’s Permitted SPI Purposes, we do not currently provide this consumer right.

Personal Information Sales or Sharing Opt-Out and Opt-In Rights

You have the right to request that businesses stop selling or sharing your personal information at any time (the “right to opt-out”), including through a user-enabled opt-out preference signal. Similarly, the CCPA prohibits businesses from selling or sharing the personal information of consumers it actually knows are under 16 years old without first obtaining consent from consumers who are between 13 and 15 years old or the consumer’s parent or guardian for consumers under age 13 (the “right to opt-in”).

Pareto cannot sell or share your personal information after we receive your request to opt-out unless you later consent to the sale or sharing of your personal information.

Right to Non-Discrimination

You have the right not to be discriminated or retaliated against for exercising any of your privacy rights under the CCPA.

How to Exercise Your Rights

Exercising Your Rights to Know, Delete, or Correct

To exercise your rights to know (including data portability), delete, or correct described above, please submit a request by either:

  • Calling Pareto at 1-800-317-9876
  • Emailing Pareto at privacy@paretohealth.com

Please describe your request with sufficient detail so we can properly understand, evaluate, and respond to it.  You or your authorized agent may only submit a request to know twice within a twelve (12) month period.

Exercising Your Right to Opt-Out

You can submit your request to opt-out through:

  • An interactive form accessible via the hyperlink titled “Do Not Sell or Share my Personal Information”
  • Calling Pareto at 1-800-317-9876
  • Emailing Pareto at privacy@paretohealth.com

You can also submit your request to opt-out of personal information sales and sharing through an opt-out preference signal.

Verification Process and Authorized Agents

Only you, or someone legally authorized to act on your behalf, may make a request to know, delete, or correct related to your personal information. We may request specific information from you or your authorized representative to confirm your or their identity, or their authority to act on your behalf, before we can process your right to know, delete, or correct your personal information.

We cannot respond to your request to know, delete, or correct if we cannot verify your identity or authority to make the request and confirm the personal information relating to you. We will only use personal information provided in the request to verify the requestor’s identity or authority to make the request.

You do not need to create an account with us to submit a request to know, correct, or delete.

For requests to opt-out, we ask for the information necessary to complete the request, which may include, for example, the consumer’s name, email address, or account username.

Responding to Your Requests to Know, Delete, or Correct

We will confirm receipt of your request within ten (10) business days. If you do not receive confirmation within the ten-day timeframe, please contact Pareto at the contact information listed below.

We endeavor to substantively respond to a verifiable request within forty-five (45) days of its receipt. If we require more time (up to another forty-five (45) days), we will inform you of the reason and extension period in writing. We will deliver our written response to your verified email address or by mail, at your option. Our substantive response will tell you whether or not we have complied with your request. If we cannot comply with your request in whole or in part, we will explain the reason, subject to any legal or regulatory restrictions. Applicable law may allow or require us to refuse to provide you with access to some or all of the personal information that we hold about you, or we may have destroyed, deleted, or made your personal information anonymous in compliance with our record retention policies and obligations.

Any disclosures we provide will cover information for the twelve (12) month period preceding the date on which Pareto receives the request. We will consider requests to provide longer disclosure periods that do not extend past January 1, 2022, unless providing the longer timeframe would be impossible or involves disproportionate effort.

For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.

Pareto does not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

Response and Timing of Rights to Opt-Out

In response to your request to opt-out, Pareto will process your request as soon as feasibly possible, but no later than fifteen (15) business days from the date we receive the request. We will only use personal information provided from your request to comply with the request.

We will also notify our service providers, contractors, and certain other downstream recipients of your request to opt-out and instruct them to both:

  • Comply with your request.
  • Forward the request to their own downstream recipients, if applicable.

Once you make a request to opt-out, we will wait at least twelve (12) months before asking you to reauthorize personal information sales or sharing.

Changes to Pareto’s California Privacy Policy

Pareto reserves the right to amend this California Privacy Policy at its sole discretion and at any time. If we make any material changes to this California Privacy Policy, we will update the policy’s effective date and post the updated policy on our website. We encourage you to check our website to review the current California Privacy Policy in effect. 

Contact Information

If you have any questions or comments about this California Privacy Policy, the ways in which Pareto collects and uses your information described herein and in the General Privacy Policy, your choices and rights regarding such use, or wish to exercise your rights under California law, please do not hesitate to contact Pareto at:

Phone: 1-800-317-9876

Email: privacy@paretohealth.com

Mailing address:  Pareto Health, LLC

Attn: Privacy Officer

One Commerce Square

2005 Market Street

Suite 3900

Philadelphia, PA 19103

If you need to access this Policy in an alternative format due to having a disability, please contact Pareto by any method listed above.