Skip to main content

Privacy policy

What this site collects, who receives a matching request, and how California residents use their CCPA and CPRA rights.

Privacy and California law

Privacy policy

This page puts California law first, then explains how Golden State Planner handles your information. A request you send can reach up to three licensed advisors, and advisors may pay to receive it. Run the checklist first.

  • California rights: know, correct, delete, opt out
  • Shine the Light requests get an answer
  • Up to three advisors see a request
  • Ads and extra analytics wait for your consent

The checklist

Eight checks, in the order that matters

California rights first, then the path your information takes.

  1. California residents: your rights

    Under the CCPA and CPRA you may ask what we hold about you, ask us to correct it, ask us to delete it, and opt out of its sale or sharing. Using a right will not change how we treat you. Ask through the contact page and name the right you mean. People elsewhere may have comparable rights and can use the same route.

  2. California residents: Shine the Light

    California's Shine the Light law lets residents ask which categories of personal information a business shared with other companies for their direct marketing, and with whom. Advisors who receive a matching request fit that description. Ask through the contact page and we will answer.

  3. Check what you are sending

    The request form takes your full name, email and phone, state or region, what you need help with, ranges for net worth, income and investable assets, goal and timeline, whether an advisor already works with you, and your contact preference. Cloudflare, which carries all traffic, sees requests and IP addresses. The site is not for children, and nothing is knowingly collected from anyone under 16.

  4. Check who receives it

    With your consent, a person on our team reads what you sent and contacts you to confirm what you need, and you are matched with a licensed advisor. Up to three advisors receive the request and may pay for it, which California law can treat as a sale or sharing. Before buying, they see only an anonymous summary; names and contact details follow the purchase.

  5. Check what runs in your browser

    Before you allow cookies, only Google Analytics is active, in a denied mode without cookies. Once you allow them, Google Analytics, Google AdSense and the Meta Pixel can load and may hand visit information to those companies. Yandex Metrica logs page visits to help Yandex Search find our pages, waiting for analytics consent, with session recording off.

  6. Check your opt-out signals

    Turn on Global Privacy Control and we read it as an opt-out of sale or sharing, and Yandex Metrica does not load. A request sent while the signal is on is recorded as do-not-sell. The Do not sell or share my personal information page holds the manual controls, and your picks there are saved in your browser only.

  7. Check how long it is kept

    Requests are held for as long as making the match and legal record-keeping require. If you ask for one to be deleted, it is, except where the law says the record must stay. The form data sits on our cloud infrastructure, and an email-delivery provider sends it on to us by email. Cloudflare Turnstile, a hidden honeypot field and rate limiting guard the form.

  8. Advisors: check what we store

    Sign-up takes a name, work email and CRD number, and we look the CRD up in the SEC's public record of investment advisers. Two things send a sign-up to manual review: a personal email address and reported disclosure events. We keep the details and the check result. A payment provider takes card payments, and we store no card numbers. Only advisors at SEC-registered firms can receive introductions; that is checked against the public record at sign-up and before each purchase.