PRIVACY POLICY

Effective date: 08/26/2026  |  Last updated: 08/27/2026

Turicum LLC, doing business as Napa Valley Wine Academy (“NVWA,” “we,” “us,” or “our”), respects your privacy. This Privacy Policy explains how we collect, use, retain, disclose, and protect personal information when you visit napavalleywineacademy.com, use our online course platforms, create an account, enroll in a course or event, make a purchase, communicate with us, or otherwise interact with our services (collectively, the “Services”).

This Policy applies to information we collect online and offline in connection with the Services. It does not apply to information handled under a separate privacy notice, such as an employee or job-applicant notice, or to third-party websites and services that we do not control.

1. Personal information we collect

“Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular person or household. It does not include deidentified, aggregated, or publicly available information where excluded by law.

Identifiers and contact information. Name, billing and shipping address, email address, telephone number, account username, customer number, IP address, device, cookie, cross-device, and identity-resolution identifiers, and similar identifiers. An identity-resolution partner may provide an email address or basic identifier for a visitor who did not submit a form directly to us.

Customer records and transaction information. Products, courses, events, memberships, gift cards, promotions, and services considered or purchased; order and payment status; invoices; refunds; shipping details; and customer-service history.

Payment information. Payment method, billing address, limited payment metadata, and transaction confirmations. Payment processors generally collect and process full payment-card or wallet credentials directly; we do not intentionally store full card numbers or security codes.

Account and education information. Login details, course registrations, attendance, progress, assessments, results, certifications, instructor interactions, learning preferences, and records needed to administer programs or verify credentials.

Commercial, CRM, and preference information. Shopping and enrollment history, lead source and status, customer and prospect history, CRM tags, notes, tasks, campaign and automation history, wish lists, interests, wine-education preferences, survey responses, promotion use, and communications preferences.

Internet and electronic activity. Pages viewed, links clicked, search and navigation activity, referring URLs, session activity, browser and device information, digital fingerprints or similar signals used for identity resolution, interactions with emails and advertisements, and diagnostic logs.

Approximate location. General location inferred from IP address and information you provide, such as city, state, or country. We do not intend to collect precise geolocation through the Services unless we provide a separate notice and choice.

Communications and user content. Emails, chat messages, calls, support requests, reviews, testimonials, photos, event or class submissions, and other content you provide.

Marketing and lead information. Email address, mobile number, date of birth or age-related information, campaign source, CRM tags and segmentation, identity-match and audience-source information, consent records, and engagement with newsletters, SMS messages, promotions, retargeting, and connected-TV advertising.

Inferences. Likely interests, preferences, customer segments, and marketing audiences derived from your interactions with us.

Sensitive personal information. Account login credentials and payment information needed to access an account or complete a transaction. We use this information only for permitted operational purposes and do not use it to infer characteristics about you.

2. Sources of personal information

We obtain personal information from the following sources:

  • Directly from you, including when you shop, enroll, create an account, contact us, complete a form, attend a class or event, post a review, or exercise a privacy choice.
  • Automatically from your browser or device through cookies, pixels, tags, software development kits, local storage, logs, and similar technologies.
  • From service providers and business partners, including Shopify, Keap/Thryv, Klaviyo, Opensend, payment and fraud-prevention providers, course and learning platforms, shipping and fulfillment providers, scheduling and event tools, customer support systems, affiliate and referral partners, and marketing platforms.
  • From identity-resolution and data-enrichment partners that match website activity or device and network signals with contact or audience information obtained from participating publishers, opted-in profiles, or other permitted sources.
  • From advertising and analytics partners, which may provide campaign, audience, attribution, measurement, and inferred-interest information.
  • From publicly available sources and social networks when you interact with our pages, content, or advertisements, subject to your settings and the platform’s policies.

3. How we use personal information

  • Provide the Services; process orders and enrollments; deliver physical and digital products; administer accounts, courses, assessments, credentials, events, appointments, gift cards, and refunds.
  • Authenticate users, maintain records, provide customer support, respond to inquiries, and communicate service or transaction information.
  • Personalize content and recommendations and remember your settings and preferences.
  • Maintain customer and prospect records in our CRM; identify or enrich certain U.S. website visitors; score, tag, segment, and route leads; automate follow-up; send newsletters, promotions, abandoned-cart messages, event information, and SMS messages where permitted; manage consent, opt-outs, and suppression lists.
  • Measure traffic, engagement, advertising performance, and conversions; perform analytics, attribution, testing, and research; improve our Services.
  • Advertise and market our Services, including identity resolution, cross-device recognition, retargeting, and creating, matching, suppressing, and measuring audiences and delivering interest-based or connected-TV advertising, subject to your choices.
  • Detect, investigate, and prevent fraud, misuse, security incidents, and other harmful or illegal activity; maintain the integrity and availability of our systems.
  • Comply with law, tax and accounting obligations, awarding-body requirements, legal process, and contractual obligations; establish, exercise, or defend legal claims.
  • Support a merger, financing, acquisition, reorganization, bankruptcy, or sale of some or all of our business or assets.
  • Carry out other purposes disclosed to you at collection or with your consent.

4. Cookies, analytics, and interest-based advertising

We and other parties use cookies, pixels, tags, local storage, and similar technologies to operate the Services, remember preferences, understand usage, prevent fraud, measure campaigns, and deliver or assess advertising. These parties may collect information about your online activities over time and across different websites or services when you use our Services.

Our technology providers may include Shopify, Keap/Thryv, Klaviyo, Opensend, Google Analytics, Google Ads, Google Tag Manager, Meta, Microsoft Clarity, Microsoft Advertising, TikTok, Vibe.co, AdNabu, Parse.ly, affiliate or referral platforms, chat and support providers, scheduling tools, course platforms, website testing and personalization tools, site performance and error monitoring providers, automated-traffic and bot protection providers, and other vendors described in our Cookie Policy. Opensend may use a Shopify app, pixel, scripts, APIs, device/network signals, or cookie-less matching technology to recognize or identify certain U.S. visitors and provide email addresses or basic identifiers, sync matched profiles to our marketing systems, and support email, advertising, SMS, onsite, or other retargeting. Vibe.co may use pixels, cookies or other browser storage, APIs, device or connected-TV identifiers, hashed contact identifiers, IP-derived location, audience segments, content-viewing or ad-interaction data, and measurement data to target connected-TV/OTT advertising and evaluate campaign effectiveness. The specific technologies and retention periods may change as our tools change.

Cookie controls. You can use our cookie banner or visit Cookie Policy to review categories and change nonessential-cookie preferences. Browser settings may also delete or block cookies, but doing so can affect site functionality.

Global Privacy Control and opt-out preference signals. We treat a recognized Global Privacy Control (“GPC”) or other legally valid opt-out preference signal as a request to opt out of sale or sharing for the browser or device that sends the signal and, where required and technically feasible, for a known consumer profile associated with that browser or device. You may also use Your Privacy Choices.

Do Not Track. Some browsers offer a “Do Not Track” setting. Because there is no single accepted standard for interpreting this setting, we do not respond to it separately. We do respond to GPC and other opt-out preference signals as described above.

5. How we disclose personal information

We may disclose personal information to the following categories of recipients for the purposes described in this Policy:

Service providers and contractors. Hosting, ecommerce, CRM and marketing automation (including Keap/Thryv), identity resolution and data enrichment (including Opensend where it acts on our behalf), payment processing, order fulfillment, shipping, course delivery, credential administration, cloud storage, cybersecurity, fraud prevention, customer support, chat, scheduling, email/SMS delivery, document signing, analytics, site performance and error monitoring, website testing and personalization, automated-traffic and bot protection, and professional services. Keap stores and processes customer, prospect, communication, campaign, transaction, and related CRM records on our behalf and may exchange data with connected systems as we direct.

Identity-resolution, enrichment, and publisher-network partners. Companies such as Opensend that may receive website activity, IP address, device/network, page-view, cart, transaction, and similar event information; compare those signals with identity graphs or participating publisher data; provide matched email addresses or basic identifiers; and sync audiences or profiles with our CRM, email, SMS, advertising, or onsite marketing tools. Depending on the relationship and applicable law, these activities may be considered a sale, sharing, targeted advertising, or processing by a service provider.

Advertising and analytics partners. Companies that help measure, personalize, deliver, and assess advertising and marketing, including Google, Meta, Microsoft (including Microsoft Clarity and Microsoft Advertising), TikTok, Vibe.co, Klaviyo, Parse.ly, affiliate platforms, and related technology providers. Vibe.co helps target, deliver, retarget, and measure OTT/connected-TV advertising. Certain disclosures may be considered “sale” or “sharing” under California law even when no money changes hands.

Course, event, and certification partners. Instructors, venues, awarding bodies, examination providers, learning platforms, and operational partners as reasonably necessary to provide the program you request.

Payment, financial, and transaction partners. Payment processors, wallet providers, banks, fraud-prevention providers, and related entities involved in completing or securing a transaction.

Business and professional advisers. Auditors, accountants, insurers, attorneys, consultants, and other advisers subject to appropriate duties or agreements.

Authorities and other parties for legal or safety reasons. Courts, regulators, law enforcement, government agencies, and other parties when we believe disclosure is required or appropriate to comply with law, protect rights or safety, prevent harm, or enforce agreements.

Transaction parties. Prospective or actual buyers, investors, lenders, advisers, and other participants in a corporate transaction, subject to appropriate confidentiality protections where applicable.

At your direction. Other persons or organizations when you direct us or consent to the disclosure, such as when you ask us to coordinate with an employer, educator, or event partner.

6. Sale and sharing of personal information

We do not sell personal information for money. However, California law defines “sale” broadly and defines “sharing” to include disclosure of personal information for cross-context behavioral advertising. Our use of advertising cookies, pixels, audience tools, and related technologies may constitute sale or sharing under those definitions.

During the preceding 12 months, we may have sold or shared the following categories of personal information with advertising, analytics, and identity-resolution partners, including Vibe.co and Opensend: identifiers, email addresses or basic contact identifiers obtained through identity matching, and pseudonymous or hashed contact identifiers; commercial information; internet or other electronic network activity; device, cross-device, and connected-TV identifiers; approximate geolocation; audience or interest segments; page, cart, ad, and content interaction data; and inferences. We do not knowingly sell or share personal information of consumers under 16 years of age. We do not sell or share sensitive personal information for cross-context behavioral advertising.

To opt out, visit Your Privacy Choices or enable GPC in a supported browser. You do not need to create an account, and we will not ask you to verify your identity solely to process an opt-out request. Your choice may be specific to the browser or device unless you are logged in and we can associate the choice with your account.

7. Data retention

We retain each category of personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain records, meet legal and awarding-body requirements, resolve disputes, enforce agreements, and protect security. Our criteria include the nature and sensitivity of the information, the duration of our relationship, applicable limitation periods, and legal, tax, accounting, accreditation, and operational requirements.

8. Security

We use administrative, technical, and physical safeguards designed to protect personal information. No system, transmission, or storage method is completely secure, and we cannot guarantee absolute security. You are responsible for keeping account credentials confidential and notifying us if you suspect unauthorized access.

9. California privacy rights and disclosures

This section applies to California residents. Where the California Consumer Privacy Act, as amended (“CCPA”), applies to NVWA, California residents have the rights described below, subject to exceptions and verification requirements. We may choose to honor some requests even when we are not legally required to do so.

Right to know/access. Request the categories and specific pieces of personal information we collected about you; categories of sources; purposes; categories of third parties; and categories sold, shared, or disclosed.

Right to delete. Request deletion of personal information we collected from you, subject to exceptions.

Right to correct. Request correction of inaccurate personal information we maintain about you.

Right to opt out of sale or sharing. Direct us not to sell or share personal information, including through Your Privacy Choices or GPC.

Right to limit sensitive personal information. Direct a covered business to limit certain uses or disclosures of sensitive personal information. We use sensitive personal information only for permitted purposes, such as providing requested services, processing payments, account authentication, and security, so we do not offer a separate limit mechanism unless our practices change.

Right to non-discrimination. Receive equal service and pricing for exercising privacy rights, subject to legally permitted programs and differences reasonably related to the value of personal information.

How to exercise your rights

You or your authorized agent may submit a request using any applicable method below:

We will confirm receipt and respond within the time required by law. We may need to verify your identity by matching information you provide with information in our records. We will use verification information only for that purpose. If we cannot verify a request, we may deny or limit it as permitted by law. Authorized agents may be required to provide written permission, and we may ask you to verify your identity directly unless an applicable power of attorney is provided.

California disclosure summary for the preceding 12 months

We collected the categories listed in Section 1 from the sources in Section 2, used them for the purposes in Section 3, and disclosed them to the recipient categories in Section 5. For business purposes, we may have disclosed identifiers; customer and CRM records; commercial information; internet activity; approximate location; education/account information; communications; inferences; and limited sensitive personal information to service providers, contractors, identity-resolution and enrichment partners, course and certification partners, payment partners, professional advisers, and legal authorities as applicable. We may have sold or shared identifiers, email addresses or basic identifiers obtained through identity matching, pseudonymous or hashed contact identifiers, commercial information, internet activity, device, cross-device, and connected-TV identifiers, approximate location, audience segments, page/cart/ad/content interaction data, and inferences with advertising, analytics, and identity-resolution partners, including Vibe.co and Opensend, as described in Section 6.

Direct marketing disclosures (“Shine the Light”)

California Civil Code § 1798.83 may allow California customers to request information about certain disclosures of personal information to third parties for their own direct-marketing purposes. To make a request, email info@napavalleywineacademy.com with the subject “California Shine the Light Request” or write to the address in Section 16.

10. Marketing communications and promotions

You can unsubscribe from promotional email by using the unsubscribe link in a message. You can opt out of promotional text messages by replying STOP or following the instructions in the message. We may still send non-promotional messages about purchases, accounts, courses, safety, or other service matters. Consent to receive marketing texts is not a condition of purchase.

We may offer discounts, promotions, or other benefits in connection with providing contact or preference information. If a program is a financial incentive or price/service difference under California law, we will provide the material terms and obtain any required opt-in before enrollment. You may withdraw as described in the applicable offer. See any linked Notice of Financial Incentive for details.

11. Children and minors

The Services are not directed to children under 13, and we do not knowingly collect personal information online from children under 13 without legally required consent. We do not knowingly sell or share the personal information of consumers under 16. If you believe a child provided personal information to us improperly, contact us so we can investigate and take appropriate action. Some educational programs may be available to minors with a parent, guardian, school, or organizational sponsor; additional notices or permissions may apply.

12. International visitors and data transfers

NVWA is based in the United States. If you access the Services from another country, your information may be transferred to, stored in, and processed in the United States and other countries where we or our providers operate. Those countries may have different data-protection laws. Where required, we use appropriate safeguards and provide rights under applicable law. Residents of jurisdictions with additional rights may contact us using Section 16.

13. Third-party sites and services

The Services may link to or integrate with third-party websites, social networks, payment services, maps, video platforms, course platforms, or other services. Their privacy practices are governed by their own policies. We encourage you to review those policies before providing information. We are not responsible for third-party privacy practices except where required by law.

14. Your account and information choices

You may review or update certain account information by signing in to the relevant storefront or course account. You may also contact us to request review or correction. Cookie and advertising choices are described in Section 4, communication choices in Section 10, and California rights in Section 9.

15. Changes to this Policy

We may update this Policy to reflect changes in our practices, technology, Services, or legal obligations. We will post the revised Policy and update the “Last updated” date. If a change is material, we will provide additional notice as appropriate, such as a prominent website notice or direct communication. The Policy in effect when information was collected will govern our use of that information unless we provide notice and obtain consent where required.

16. Contact us

Questions, concerns, or privacy requests may be directed to:

Turicum LLC dba Napa Valley Wine Academy
Attn: Privacy
2501 Oak Street
Napa, CA 94559
United States
Email: info@napavalleywineacademy.com
Telephone: 1-855-513-9738