U.S. State Privacy Notice

Effective date: September 7, 2026

1. Scope

This U.S. State Privacy Notice (“Notice”) supplements the Knocking Inc. Privacy Policy and applies to residents of U.S. states whose comprehensive privacy laws grant the rights described below — including, without limitation, California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and Maryland, and any other state whose law of similar scope takes effect after the date of this Notice (collectively, “State Privacy Laws”). Where a specific state law grants a right listed here, we honor it for residents of that state; where it does not, we may nonetheless honor requests as a courtesy at our discretion.

Terms such as “personal information,” “personal data,” “sale,” “sharing,” “targeted advertising,” and “sensitive personal information” have the meanings given in the applicable State Privacy Law.

2. Categories of Personal Information Collected & Disclosed

The categories below describe the personal information we have collected in the preceding 12 months and expect to collect, the purposes, the categories of recipients, and whether the category is sold or shared as defined by State Privacy Laws. Sources for all categories are described in Section 2 of the Privacy Policy.

Identifiers

  • Examples: Name, postal and email address, phone number, IP address, device and online identifiers
  • Purposes: Services, communications, marketing, advertising, security, legal
  • Disclosed to (categories): Service providers; featured brands and suppliers; media partners; advertising and analytics partners
  • Sold / shared? Yes

Customer records (Cal. Civ. Code §1798.80)

  • Examples: Contact details; payment information (processed by payment processors)
  • Purposes: Services, fraud prevention, legal
  • Disclosed to (categories): Service providers (platform, payment, fulfillment)
  • Sold / shared? No

Commercial information

  • Examples: Purchase and order history, cart contents, returns
  • Purposes: Services, marketing, advertising, analytics
  • Disclosed to (categories): Service providers; featured brands and suppliers; media partners; advertising partners
  • Sold / shared? Yes

Internet or other electronic network activity

  • Examples: Browsing and interaction data, pages viewed, clicks and cursor movements, media viewing, approximate location inferred from IP
  • Purposes: Services, analytics, advertising, personalization, security
  • Disclosed to (categories): Service providers; advertising, analytics, and measurement partners
  • Sold / shared? Yes

Inferences

  • Examples: Preferences and characteristics derived from the above
  • Purposes: Personalization, marketing, advertising
  • Disclosed to (categories): Service providers; advertising partners
  • Sold / shared? Yes

We do not collect biometric information, precise geolocation (as defined by State Privacy Laws), health or medical information, or education or employment records through the Services. We collect government-issued identifiers only if required for a specific transaction and disclosed to you at that time.

3. Sale, Sharing & Targeted Advertising

We disclose the categories marked “Yes” above to advertising, analytics, and measurement partners, featured brands and product suppliers, and media partners in ways that may constitute a “sale” or “sharing” of personal information, or processing for “targeted advertising,” under State Privacy Laws — for example, using advertising and analytics technologies that build cross-context audiences, and, where you have opted in, providing your contact information to featured brands for their own direct marketing.

You may opt out at any time by any of the methods in Section 7. Once you opt out, we will not sell or share your personal information or process it for targeted advertising, unless you later opt back in.

4. Sensitive Personal Information

We do not intentionally collect sensitive personal information except account log-in credentials and payment credentials handled by our platform and payment processors for the purpose of providing the Services. We use and disclose sensitive personal information only for the purposes permitted by State Privacy Laws without a right to limit (such as performing the Services, security, and fraud prevention), and we do not use it to infer characteristics about you. Accordingly, we do not offer a separate “limit the use of my sensitive personal information” control; if our practices change, we will update this Notice and provide the required control before doing so.

5. Retention

We retain each category of personal information for as long as reasonably necessary for the purposes disclosed in this Notice and the Privacy Policy, applying the criteria described in Section 8 of the Privacy Policy (relationship and Services used; sensitivity of the data; legal, tax, and audit obligations; claims; fraud and security; business records). Transaction records are generally retained for the limitations and tax periods required by law; marketing data is retained while your opt-in remains active plus a reasonable suppression period.

6. Your Rights

Subject to the law of your state and applicable exceptions, you have the right to:

  • Know / access — confirm whether we process your personal information and obtain a copy of the specific pieces and the category-level disclosures described in this Notice.
  • Portability — receive your personal information in a portable and, to the extent technically feasible, readily usable format.
  • Delete — request deletion of personal information we collected from or about you.
  • Correct — request correction of inaccurate personal information.
  • Opt out — of sales, sharing, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects (we do not currently engage in such profiling).
  • Limit sensitive personal information — as described in Section 4.
  • Non-discrimination — we will not discriminate or retaliate against you for exercising your rights.

7. How to Exercise Your Rights

You may submit a request by any of the following methods:

We will confirm receipt and respond within the time required by the applicable State Privacy Law (generally 45 days, extendable once where permitted with notice to you). If we cannot honor a request in whole or in part, we will explain why in our response. We do not charge a fee for a first request in any 12-month period unless permitted by law for excessive or repetitive requests.

8. Opt-Out Preference Signals (Global Privacy Control)

We are implementing automated support for browser-based opt-out preference signals, including the Global Privacy Control (GPC). Until that support is live, please submit opt-out requests through any of the methods in Section 7, and we will honor them for the sale and sharing of personal information and for targeted advertising.

9. Verification, Authorized Agents & Appeals

Verification. For access, deletion, correction, and portability requests we must verify your identity to a degree of certainty appropriate to the sensitivity of the request, typically by matching identifiers you provide against information we maintain; we may request additional information solely for verification. Opt-out requests do not require verification but may be denied where we reasonably believe the request is fraudulent.

Authorized agents. You may designate an authorized agent to act on your behalf. We may require proof of the agent’s authority (such as a signed permission or power of attorney) and direct verification of your identity, as permitted by law.

Appeals. If we decline to act on your request, residents of states providing an appeal right may appeal within a reasonable period by replying to our decision or emailing privacy@knocking.com with the subject “Privacy Request Appeal.” We will respond within the statutory appeal window (generally 45–60 days). If your appeal is denied, you may contact your state Attorney General; we will include instructions in our appeal response.

10. Minors

We do not knowingly collect, sell, or share the personal information of consumers under 16 years of age. We have no actual knowledge of selling or sharing personal information of consumers under 16.

11. De-Identified Data

Where we receive or create de-identified data, we maintain and use it without attempting to re-identify it (except as permitted by law to test de-identification processes) and contractually require recipients to do the same.

12. Changes & Contact

We may update this Notice from time to time; the effective date above reflects the latest revision, and material changes will be notified as described in the Privacy Policy. Questions about this Notice may be directed to privacy@knocking.com or Knocking Inc., Attn: Privacy, 357 Commerce Drive, PB 320599, Fairfield, CT 06825, United States.