This page brings together the policies that govern how The Collective SD collects, uses, protects, retains, and deletes personal information, and how you can exercise your rights over the information we hold about you.
Effective date: September 8, 2026 | Version: 1.1
1. Privacy Notice
1.1 Who We Are
The Collective SD is a marketing and branding firm based in San Diego, California (www.thecollectivesd.com). This Privacy Notice explains what personal information The Collective SD collects, how it is used and protected, and the choices available to the people it belongs to.
1.2 Information We Collect
The Collective SD collects only the personal information needed to run its business and deliver its services:
- Contact information you provide directly, such as your name, email address, phone number, and company, when you inquire about or engage our services.
- Business and billing information needed to deliver and invoice engagements.
- Website information collected automatically through cookies and Google Analytics when you visit www.thecollectivesd.com, such as browser type, approximate location, and pages visited, used in aggregate to operate and improve the site. You can block or delete these cookies in your browser settings.
- Client-provided information. When a client provides personal information (for example, a contact list for a marketing campaign), The Collective SD handles it solely as a service provider on that client’s behalf and under that client’s instructions.
1.3 How We Use Information
- To provide, manage, and invoice the services a client has engaged.
- To respond to inquiries and communicate about projects.
- To send marketing communications, which recipients can opt out of at any time (see the Opt-Out Request Policy).
- To meet legal, accounting, and contractual obligations.
1.4 What We Do Not Do
- The Collective SD does not sell personal information.
- The Collective SD does not share personal information for cross-context behavioral advertising.
- Client-provided information is never used for The Collective SD’s own marketing.
1.5 Sharing
Personal information is shared only with:
- Approved subcontractors who assist in delivering services, and only under a signed Confidentiality and Data-Handling Agreement that limits use, requires secure handling, and requires deletion after the task is complete.
- Service providers that host our systems (Google Workspace and Dropbox), which are certified to independent security standards.
- Platforms and providers used to deliver services and run the business, such as email and marketing delivery platforms, payment and invoicing processors, and our professional advisors (accountants and attorneys), each limited to the purpose for which it is used.
- Authorities where disclosure is required by law.
1.6 How Information Is Protected
The Collective SD maintains a written information security program, described in its Information Security Standards and Procedures. Key protections include full-disk encryption on all company computers, encryption in transit and at rest for cloud data, multi-factor authentication on all business accounts, least-privilege access, and security awareness training for all staff. If a security breach affecting unencrypted personal information occurs, affected individuals are notified as required by California Civil Code section 1798.82.
1.7 Retention
Personal information is kept only as long as needed for the purposes above, per the Record Retention Policy. Client-provided personal information is deleted within 30 days of the end of the project or engagement, or sooner at the client’s request.
1.8 Your Rights and Choices
You may request access to, correction of, or deletion of your personal information, and you may opt out of marketing communications at any time. California residents have additional rights described in our CCPA Notice. To exercise any right, email privacy@thecollectivesd.com or write to The Collective SD, [POSTAL ADDRESS], San Diego, California. An authorized agent may submit a request on your behalf with your written permission. Requests are handled under our Data Subject Access Request (DSAR) Policy.
If your information was provided to The Collective SD by one of our clients, we will refer your request to that client and support their response, as required of a service provider.
1.9 Children
The Collective SD’s services are directed at businesses. We do not knowingly collect personal information from children under 16.
1.10 Changes and Contact
This notice is reviewed at least annually and updated when practices change. Questions and requests: privacy@thecollectivesd.com, or The Collective SD, [POSTAL ADDRESS], San Diego, California.
2. CCPA Notice for California Residents
2.1 Scope
This notice supplements The Collective SD Privacy Notice and applies to California residents. It is provided in the spirit of the California Consumer Privacy Act as amended by the CPRA (together, the CCPA).
The Collective SD is a small firm that does not currently meet the CCPA’s statutory thresholds for a covered business (annual gross revenues over $26,625,000 (the statutory $25 million figure as adjusted for inflation, effective January 1, 2025), or buying, selling, or sharing the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of revenue from selling or sharing personal information). The Collective SD nonetheless voluntarily aligns its practices with the CCPA, and it acts as a service provider under the CCPA when it processes personal information on behalf of its clients.
2.2 Categories of Personal Information Collected
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Name, email address, phone number, company | Yes |
| Customer records | Billing contact and engagement details | Yes |
| Commercial information | Services engaged, project history | Yes |
| Internet activity | Website usage collected by our website provider | Yes (aggregate) |
| Sensitive personal information | Government identifiers, precise geolocation, biometrics, health or financial account data | No |
Personal information is collected directly from you, from your company in the course of an engagement, or from our clients when we act as their service provider.
Retention. Each category above is kept only as long as needed for the purposes below and is then destroyed under our Record Retention Policy: identifiers, customer records, and commercial information for the life of the business relationship, and up to seven years after it where they form part of a contract or financial record; internet activity in aggregate form only; and personal information provided by a client for the duration of that engagement plus 30 days.
2.3 Purposes
Personal information is used only for the business purposes described in the Privacy Notice: delivering and invoicing engaged services, communicating about projects, limited marketing with opt-out, and meeting legal obligations.
2.4 Selling, Sharing, and Disclosures for Business Purposes
The Collective SD does not sell personal information and does not share personal information for cross-context behavioral advertising, and it has not done so in the preceding 12 months. Because no sale or sharing occurs, no opt-out of sale or sharing is required; a request mechanism is nonetheless provided in the Opt-Out Request Policy.
In the preceding 12 months, The Collective SD disclosed identifiers, customer records, and commercial information for business purposes to the following categories of recipients: service providers that host our systems (cloud email and file storage), approved subcontractors working under a signed confidentiality and data-handling agreement, and payment and invoicing processors. No personal information was sold or shared.
2.5 Your CCPA Rights
- Right to know what personal information is collected, used, and disclosed.
- Right to access the specific pieces of personal information we hold about you.
- Right to correct inaccurate personal information.
- Right to delete personal information, subject to legal exceptions.
- Right to opt out of sale or sharing (not applicable, as described above).
- Right to limit the use of sensitive personal information (not applicable; The Collective SD does not collect sensitive personal information).
- Right to non-discrimination for exercising any of these rights.
2.6 How to Submit a Request
Submit requests by email to privacy@thecollectivesd.com or by mail to The Collective SD, [POSTAL ADDRESS], San Diego, California. An authorized agent may submit a request on your behalf; we will ask for your signed permission and may confirm the request with you directly. Requests are acknowledged within 10 business days and answered within 45 calendar days, extendable once by a further 45 days with notice, per our DSAR Policy. We verify requests by matching information you provide against information we hold. Requests are free of charge; a request that is manifestly unfounded or excessive may be declined with an explanation.
Where The Collective SD holds your information as a service provider to one of its clients, the CCPA directs your request to that client; we will forward the request and support the client’s response.
2.7 Contact
privacy@thecollectivesd.com — The Collective SD, [POSTAL ADDRESS], San Diego, California.
3. Opt-Out Request Policy
3.1 Purpose and Scope
This policy defines how The Collective SD receives, processes, and honors requests to opt out of communications and data processing. It covers marketing communications sent by The Collective SD for itself, campaigns The Collective SD runs on behalf of clients as a service provider, and CCPA opt-out requests.
3.2 How Opt-Out Requests Are Received
- The unsubscribe link included in every marketing email.
- Email to privacy@thecollectivesd.com.
- A reply or verbal request to any staff member, who must forward it to Management the same day.
3.3 Processing Standards
- Marketing email opt-outs are honored within 10 business days of receipt, per CAN-SPAM. No further marketing email is sent to the address after that point.
- CCPA opt-out of sale or sharing requests are honored within 15 business days. The Collective SD does not sell or share personal information, so such requests are recorded and confirmed to the requester.
- Opt-out requests are free of charge and do not require creation of an account.
- Every marketing email identifies The Collective SD as the sender, includes a valid postal address, and carries an unsubscribe mechanism that remains functional for at least 30 days after the send, per CAN-SPAM.
- Text message (SMS) marketing is not currently used. If it is introduced, every message will carry STOP instructions, and a STOP reply or any other reasonable opt-out request will be honored within 10 business days, per the Telephone Consumer Protection Act.
3.4 Suppression List
Opted-out addresses are added to a suppression list maintained by Management. The suppression list is checked before every send. Suppression entries are retained indefinitely so an opt-out is never forgotten, and they are stored with the minimum data needed (address and date).
3.5 Client Campaigns
When an opt-out arrives from a campaign run on behalf of a client, The Collective SD applies its own suppression immediately and forwards the request to the client within 10 business days so the client can update its own records, as required of a service provider.
3.6 Logging and Review
All opt-out requests and their completion dates are recorded in the Opt-Out Log (Security Registers and Logs workbook). This policy is reviewed at least annually by Management with the IT Department.
4. Data Subject Access Request (DSAR) Policy
4.1 Purpose and Scope
This policy defines how The Collective SD receives, verifies, and responds to requests from individuals to access, correct, or delete their personal information (DSARs). It applies to all staff and covers requests under the CCPA and any other applicable privacy law, as well as voluntary requests from any individual.
4.2 Intake
- DSARs may be submitted to privacy@thecollectivesd.com.
- A request received by any staff member through any channel (email, phone, social media) must be forwarded to Management the same business day.
- Each request is logged on receipt in the DSAR Log (Security Registers and Logs workbook) with the date received, requester, request type, how it was received, and due dates.
4.3 Verification
Before fulfilling a request, Management verifies the requester’s identity to a reasonable degree of certainty by matching at least two data points the requester provides (for example, the email address on file and a recent interaction) against information already held. Government ID is not requested unless legally required. If identity cannot be verified, the request is declined with an explanation and the declination is logged.
4.4 Business vs. Service Provider Requests
The Collective SD responds directly when it holds the information for its own purposes (its own contacts, prospects, and billing records).
When the information is held on behalf of a client (for example, a contact list provided for a campaign), The Collective SD acts as a service provider: the request is forwarded to the client within 10 business days, the requester is informed of the referral, and The Collective SD assists the client’s response, including deleting data at the client’s direction.
4.5 Timelines
- Acknowledge receipt within 10 business days.
- Substantive response within 45 calendar days, extendable once by up to 45 additional days with written notice to the requester.
- Requests are free of charge. Access responses cover the 12 months preceding the request, or longer where the information is readily available, and are fulfilled up to twice in any 12-month period; a request that is manifestly unfounded or excessive may be declined with an explanation.
- Deletion requests are completed across active systems (Google Workspace, Dropbox, endpoints); copies in encrypted backups age out through the normal backup cycle and are not restored except for disaster recovery.
4.6 Fulfillment
At Management’s direction, the IT Department searches all in-scope systems: Google Workspace (mail and Drive), Dropbox, and company endpoints. Access responses are delivered by Management in a readily usable format (PDF or spreadsheet) by secure means. Corrections are applied at the source. Deletions follow the Secure Disposal standard in the Information Security Standards and Procedures and are confirmed by the IT Department.
4.7 Exceptions
A request may be declined in whole or in part where an exception applies (for example, information that must be retained for legal, tax, or contractual reasons under the Record Retention Policy, or where deletion would impair completion of a contract). Any partial or full denial is explained to the requester and logged.
4.8 Logging and Review
Every DSAR, its verification outcome, actions taken, the basis for any denial, and completion date are recorded in the DSAR Log, which is retained for at least 24 months as CCPA regulations require. Management reviews the log at least annually alongside this policy.
5. Record Retention Policy
5.1 Purpose and Scope
This policy defines how long The Collective SD retains its business records and client data, and how records are destroyed when their retention period ends. It applies to all records in all formats, on all company systems (Google Workspace, Dropbox, company Macs, and backups). It extends section 6.5 (Data Retention and Destruction) of the Information Security Standards and Procedures, which remains the governing standard for client data.
5.2 Roles
The IT Department (SD Mac Tech) owns this policy, executes destruction, and confirms completion. Management (Ilo Neukam) approves the retention schedule and any exceptions.
5.3 Retention Schedule
| Record Type | Retention Period | Notes |
|---|---|---|
| Client project data, including Western Alliance Bank data | Duration of the engagement plus 30 days | Deleted sooner on client request. Governing rule per Standards section 6.5. |
| Subcontractor copies of client data | Deleted immediately after the task is complete | Confirmed by the IT Department. |
| Contracts, NDAs, purchase orders, and signed agreements | 7 years after expiration or termination | Includes client and subcontractor agreements. |
| Financial, tax, and invoicing records | 7 years | Aligned to federal and California tax guidance. Billing details only; never contain client project data. |
| General business correspondence (email) | 3 years, then reviewed | Correspondence that is part of a contract or financial record follows that record’s period. Messages or attachments containing Confidential/Restricted client data follow the client project data rule above and are deleted with it. |
| Personnel and contractor records | 7 years after the relationship ends | |
| Marketing portfolio and published work product | Retained while it has business value | Contains no Confidential or Restricted client data. |
| Security registers, logs, and training records | 3 years | Supports security reviews and client due diligence. Includes the DSAR Log, which CCPA regulations require to be kept at least 24 months. |
| Opt-out suppression list | Indefinite | Email address and opt-out date only, kept so an opt-out is never forgotten (Opt-Out Request Policy section 3.4). |
| Backups (encrypted Time Machine and cloud versions) | Rolling; superseded copies cycle out automatically | Deleted client data ages out of backups in the normal rotation and is not restored except for disaster recovery. |
5.4 Legal Hold
If litigation, an audit, or an investigation is pending or reasonably anticipated, Management or the IT Department places a legal hold: destruction of the affected records is suspended, regardless of the schedule above, until the hold is released in writing.
5.5 Destruction
When a retention period ends, records are destroyed using the Secure Disposal methods defined in section 6.6 of the Information Security Standards and Procedures: permanent deletion with trash and version history purged for cloud storage, secure or crypto erase for endpoints and media, and cross-cut shredding for any incidental paper. Destruction of client data is performed and confirmed by the IT Department.
5.6 Review
This policy and its schedule are reviewed at least annually, or when legal or client requirements change. Client-specific contractual requirements take precedence where they exceed this policy.
Questions or Requests
Email privacy@thecollectivesd.com, or write to The Collective SD, [POSTAL ADDRESS], San Diego, California.