California Privacy Rights Notice
CERTIFIED GOLD EXCHANGE, INC. Effective Date: 1/3/2023 Last Updated: August 21, 2026
WHO THIS NOTICE IS FOR
This notice is for California residents. It supplements our general Privacy Policy and describes the rights you have under the California Consumer Privacy Act, as amended by the California Privacy Rights Act — together, “the CCPA.” It applies to you if you are a California resident and any of the following is true:
- You are a CGE client
- You requested a quote, a quote comparison, or a consumer guide from us
- You visited our website
- You are named as a beneficiary on a client’s retirement account — even though you have never contacted us
- You are an individual at another dealer with whom we trade
You do not need to be a customer to have rights under this notice, and you do not need to be a customer to make a request.
PART ONE — WHAT WE DO AND DO NOT DO
Before the legal detail, the four things California residents most often want to know:
- We have never sold your personal information. Not for money, not for anything else. We have never rented, traded, or given away a client or prospect list, at any point in the company’s history. We do not buy leads.
- We do not call or text you unless you contacted us first. Our business runs on incoming calls. We do not make unsolicited sales calls and we do not send marketing text messages.
- We do not record telephone calls.
- We do not accept credit cards, debit cards, or cash. There is no payment card data in our systems, because we never take it.
PART TWO — WHAT WE COLLECT
2.1 Categories collected in the preceding twelve months
A. Identifiers
What we actually collect
Name, email, telephone number, IP address, device and browser type. Postal address only if you become a client.
Where it comes from
You; automatically from your device
B. Customer records
(Civ. Code § 1798.80(e))
What we actually collect
Name, signature, Social Security number, date of birth, address, phone, email, your account number with your existing IRA custodian, bank information on a check or wire you send. No card numbers — we do not accept cards.
Where it comes from
You; your current or prior IRA custodian
C. Protected classifications
What we actually collect
Age, date of birth
Where it comes from
You
D. Commercial information
What we actually collect
Metals purchased, sold, or considered; quantities, weights, dates, amounts; quote history
Where it comes from
You; generated during the transaction
E. Biometric information
What we actually collect
None collected
Where it comes from
—
F. Internet or network activity
What we actually collect
Pages viewed, time on page, referring URL, search terms, browser and computer type, IP address; session replay recordings of clicks, scrolling, and mouse movement
Where it comes from
Automatically, via cookies, tags, logs, and session replay
G. Geolocation
What we actually collect
Approximate location from IP address. No precise geolocation.
Where it comes from
Automatically
H. Audio, electronic, visual
What we actually collect
Email correspondence. No call recordings. No text messages.
Where it comes from
You
I. Professional or employment
What we actually collect
Employer, occupation, employment status, where relevant to an employer-plan rollover
Where it comes from
You
J. Non-public education information
What we actually collect
None collected
Where it comes from
—
Beneficiary information
What we actually collect
Name, Social Security number, date of birth, address of each named beneficiary
Where it comes from
The client who named you
K. Inferences
What we actually collect
Preferences such as likely interest in a particular metal or account type
Where it comes from
Generated by us
L. Sensitive personal information
What we actually collect
See Part Three
Where it comes from
See Part Three
2.2 Sources
We collect personal information directly from you, automatically from your device, from your IRA custodian or prior custodian in connection with a transfer or rollover, and — for beneficiary information — from the client who named the beneficiary. We do not obtain personal information from data brokers, lead vendors, or list sellers.
2.3 Purposes
- Responding to inquiries and delivering requested consumer guides
- Preparing quotes and quote comparisons
- Processing purchases, sales, and buy-backs of precious metals
- Opening, funding, transferring, and rolling over self-directed IRA accounts with third-party custodians
- Recording beneficiary designations required by the custodian’s account application
- Verifying that a shipping address is where the recipient actually resides
- Arranging insured shipment
- IRS reporting and required recordkeeping
- Detecting and preventing fraud and security incidents
- Operating, securing, and improving our website
- Sending market and product information by email, subject to unsubscribe
2.4 Retention
Inquiry and guide-request records (no account opened)
How long we keep it
Seven years from last contact
Client transaction and account records
How long we keep it
Five to seven years after the transaction
Beneficiary designations
How long we keep it
While the designation is in effect, then five to seven years
Website analytics and session replay
How long we keep it
24 months
Records supporting IRS reporting are retained for seven years. Where federal recordkeeping rules applicable to dealers in precious metals apply, associated transaction and identity records are retained for at least five years.
PART THREE — SENSITIVE PERSONAL INFORMATION
We collect two kinds, both narrowly: Social Security number. Required by the custodian to open a self-directed IRA and for IRS reporting. Collected for the account holder and, where a client names beneficiaries, for each beneficiary — because the custodian’s application requires it. Driver’s license or state identification number. Only where a depository or custodian requires it. Clients usually submit identification to those institutions directly; occasionally they ask us to prepare the paperwork for them. This is rare — across the company’s history it has involved a small number of clients. We collect it solely to forward it to the institution requesting it. We do not collect account log-in credentials, passwords, security codes, payment card numbers, precise geolocation, biometric or genetic data, health information, or information about racial or ethnic origin, religious beliefs, union membership, or sexual orientation. Nothing in this Part is collected from someone who simply requests a guide or asks a question.
Your right to limit — and why it does not apply here
California gives you a right to limit a business’s use of sensitive personal information. That right applies when a business uses it beyond a defined set of permitted purposes. We use sensitive personal information only to perform the service you requested, verify identity, prevent fraud, ensure physical safety, transmit it to the custodian or depository that requires it, and meet legal obligations. We never use it to infer characteristics about you. Because our use stays within California Civil Code § 1798.121(a), the limitation right does not apply to our practices and we do not offer a “Limit the Use of My Sensitive Personal Information” link. If our practices change we will update this notice and provide that link.
PART FOUR — DISCLOSURE, SALE, AND SHARING
4.1 Who receives your information
IRA custodians and trust companies
Categories
A, B, C, D, I, L, beneficiary information
Precious metals depositories
Categories
A, B, D, L
Banks, for check deposit and wire settlement
Categories
A, B, D
Shipping and insurance carriers
Categories
A, D
Less Annoying CRM (our client database)
Categories
A, B, C, D, H, I, beneficiary information
Google Analytics, Lucky Orange (site analytics and session replay)
Categories
A, F, G
Website hosting and email providers
Categories
A, F, H
Attorneys, accountants, auditors
Categories
As necessary
IRS, law enforcement, regulators
Categories
As legally required
Each service provider is bound by written contract to use your information only on our instructions and not for its own purposes.
4.2 Sale
We have not sold personal information in the preceding twelve months, and we have never sold personal information.
4.3 Sharing for cross-context behavioral advertising
California treats disclosure of personal information for cross-context behavioral advertising as “sharing,” whether or not money changes hands. We have not shared personal information in the preceding twelve months. Our analytics and session replay providers act as service providers under written contract. They do not use your information to build advertising profiles or to target you elsewhere. We do not sell or share the personal information of consumers we know to be under 16.
PART FIVE — YOUR RIGHTS
5.1 Right to know
You may ask us to disclose:
- Categories of personal information we collected about you
- Categories of sources
- Business or commercial purposes for collecting, selling, or sharing it
- Categories of third parties to whom we disclosed it
- The specific pieces of personal information we hold about you
Not limited to twelve months. Where we have kept your information longer than twelve months, you may ask for information collected before that period, and we will provide it — except for information collected before January 1, 2022. You may give us a date range or ask for everything.
5.2 Right to correct
You may ask us to correct inaccurate information. We will use commercially reasonable efforts to do so. Where the information is material to a transaction or a legal obligation, we may ask for documentation supporting the correction.
5.3 Right to delete
You may ask us to delete personal information we collected from you. If you only requested a consumer guide and never opened an account, we will delete everything. There is no exception that applies to you. If you are or were a client, we cannot delete everything. California law permits us to keep information needed to:
- Complete a transaction or perform a contract with you
- Comply with a legal obligation — tax law requires retention of records supporting IRS reporting, and federal recordkeeping rules may require retention of transaction and identity records
- Detect security incidents or protect against fraudulent or illegal activity
- Exercise or defend legal claims
- Enable internal uses reasonably aligned with your expectations given your relationship with us
We will tell you specifically which exception applies to which records, and we will delete everything not covered.
5.4 Right to opt out of sale or sharing
See Part Four.
5.5 Right to limit use of sensitive personal information
See Part Three.
5.6 Right to non-discrimination
We will not deny you goods or services, charge you a different price, give you a lower level of quality, or suggest we will do any of these things because you exercised a right under this notice. Your metals pricing does not change because you submitted a privacy request. Our specialists do not see whether you have made one.
5.7 Financial incentives
We offer none. We do not offer discounts, promotions, gifts, or bonus metal in exchange for your information. Our consumer guides are available at no cost to anyone who asks, and requesting one does not change the price of anything we sell.
PART SIX — IF YOU ARE A BENEFICIARY
When a client opens a self-directed IRA, the custodian’s application requires them to name beneficiaries and supply each beneficiary’s name, Social Security number, date of birth, and address. We collect that from our client — not from you — and pass it to the custodian so the designation can be recorded. You may never have heard of us. You still have the full set of rights in Part Five. You may ask what we hold about you, ask us to correct it, and ask us to delete it. You do not need to be a client. Three things to expect:
- We will verify your identity first. We will not confirm or deny that we hold information about you, or tell you whose account you are named on, until we have verified who you are. That protects you.
- We can delete our copy, but not the custodian’s. The custodian holds the designation independently, and only the account holder can change a beneficiary designation on the account itself. We will tell you which custodian holds the account so you can contact them.
- Deleting our copy does not affect your rights as a beneficiary. Your standing comes from the designation on the account, not from our records.
Contact us using any method in Part Seven.
PART SEVEN — HOW TO MAKE A REQUEST
7.1 Ways to reach us
Toll-free telephone
Detail
800-300-0715
Detail
Support at certifiedgoldexchange.com subject line “Privacy Request” Or use our form at https://certifiedgoldexchange.com/contact-us/ and start your message “California Privacy Request”.
7.2 What we will ask you for
We must verify who you are before we act. We will ask for information that matches what we already hold — typically your name, email or phone number on file, and details of your relationship with us. For a request for specific pieces of personal information or anything involving sensitive personal information, we require a higher degree of certainty and may ask for a signed declaration under penalty of perjury that you are the person whose information you are requesting. We will not ask you to create an account. Information you give us for verification is used only to verify you and deleted as soon as practicable afterward.
7.3 Authorized agents
You may use an authorized agent. We require written permission signed by you, and we will verify your identity directly with you. If your agent holds a valid power of attorney under California Probate Code sections 4000 to 4465, no additional written permission is needed.
7.4 How long we take
Acknowledge receipt
Our deadline
10 business days
Substantive response
Our deadline
45 calendar days (extendable once by 45 more, with notice to you inside the first 45)
Act on an opt-out
Our deadline
15 business days
For opt-outs, we also notify third parties to whom we sold or shared your information in the 90 days before your request, and we confirm to you that we processed it.
7.5 Cost
Free. If a request is manifestly unfounded or excessive we may charge a reasonable fee or decline, and we will explain why.
7.6 If we say no
We will tell you why. You may appeal by emailing Support at certifiedgoldexchange.com with “Privacy Appeal” in the subject line. We respond to appeals within 60 days. If we deny the appeal we will give you information for contacting the California Attorney General or the California Privacy Protection Agency.
PART EIGHT — CONTACT
CERTIFIED GOLD EXCHANGE, INC. Fort Worth, Texas 800-300-0715 Support at certifiedgoldexchange.com Or visit our contact form: https://certifiedgoldexchange.com/contact-us/ Please start your message with “California Privacy Request”.
CERTIFIED GOLD EXCHANGE
AMERICA'S TRUSTED SOURCE FOR GOLD
2026 GOLD IRA SMART MOVES GUIDE
VERIFIED FAIR
PRICING
EXPERT
INSIGHTS
AVOID COSTLY
MISTAKES