This California Consumer Privacy Act Policy (“CCPA Disclosure”) explains how Oak Valley Community Bank, its subsidiary Eastern Sierra Community Bank, and Oak Valley Bancorp (“Company,” “Bank,” “we,” “us,” or “our”) collect, use, and disclose personal information relating to California residents covered by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the “CCPA”). This “Notice” constitutes our notice at collection and outlines our privacy policy pursuant to the CCPA.
Under the CCPA, "Personal Information" refers to information that identifies, relates to, or could reasonably be linked directly or indirectly to a particular California resident and includes certain categories of Personal Information discussed below that constitute "Sensitive Personal Information." The CCPA, however, does not apply to certain information, such as information subject to the Gramm-Leach-Bliley Act ("GLBA").
The specific Personal Information that we collect, use, and disclose relating to a California resident covered by the CCPA will vary based on our relationship or interaction with that individual. For example, this Notice does not apply with respect to information that we collect about California residents who apply for or obtain our financial products and services for personal, family, or household purposes. For more information about how we collect, disclose, and secure information relating to these customers, please refer to our Privacy Statement: https://www.ovcb.com/privacy.html.
Keeping Personal Information secure is one of our most important priorities. Consistent with our obligations under applicable laws and regulations, we maintain physical, technical, electronic, procedural, and organizational safeguards and security measures that are designed to protect personal data against accidental, unlawful, or unauthorized destruction, loss, alteration, disclosure, or access, whether it is processed by us or elsewhere.
In the past 12 months, we have collected and disclosed for our business purposes each of the following categories of Personal Information relating to California residents covered by this Notice:
Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers.
Any information that identifies, relates to, describes, or is capable of being associated with a particular individual, including name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, financial information, medical information, or health insurance information.
Characteristics of protected classifications under California or federal law, such as race, ethnicity, sex, and marital status.
Commercial information such as records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Biometric information.
Internet or other electronic network activity information, such as browsing history, search history, and information regarding interaction with an internet website, application, or advertisement.
Geolocation data such as device location and Internet Protocol (IP) location.
Audio, electronic, visual, thermal, or similar information such as call and video recordings.
Professional or employment-related information such as work history and prior employer.
Education information directly related to a student and maintained by an educational agency or institution or by a party acting for the agency or institution.
Inferences drawn from any of the Personal Information listed above to create a profile about a California resident reflecting preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
In addition to collecting Personal Information ourselves, we also coordinate with third parties to collect Personal Information on our behalf. These third parties are engaged in one or more of the following business practices:
The categories of sources from which we collected Personal Information are:
With respect to each category of Personal Information disclosed in the past 12 months, the categories of persons or entities to whom we disclosed that information are:
We collect, use, and disclose Personal Information, including Sensitive Personal Information, for the following business or commercial purposes:
The length of time that we intend to retain each category of Personal Information will depend on a number of criteria, including (i) the length of time we are required to retain Personal Information in order to comply with applicable legal and regulatory requirements, (ii) the length of time we may need to retain Personal Information in order to accomplish the business or commercial purpose(s) for which such Personal Information is collected, used or disclosed (as indicated in this Notice), and (iii) whether you choose to exercise your right, subject to certain exceptions, to request deletion of your Personal Information.
In the 12 months preceding the date of this notice, we have not "sold" or "shared" Personal Information or Sensitive Personal Information of a California resident subject to the CCPA nor have we "sold" or "shared" Personal Information or Sensitive Personal Information for minors under 16 years of age. For the purposes of this Notice:
We only use or disclose Sensitive Personal Information for the following purposes consistent with CCPA Regulations:
To perform the services or provide the goods reasonably expected by an average person who requests those goods or services. For example, the precise geolocation may be used by a mobile application that is providing a person with directions on how to get to a specific location.
To detect security incidents that compromise the availability, authenticity, integrity, and confidentiality of stored or transmitted Personal Information, provided that the use of Personal Information is reasonably necessary and proportionate for this purpose. For example, we may disclose account information to a data security company that is hired to investigate and remediate a data incident that involved that individual's account.
To resist malicious, deceptive, fraudulent, or illegal actions directed at the business and to prosecute those responsible for those actions, provided that the use of Personal Information is reasonably necessary and proportionate for this purpose. For example, we may use information about ethnicity and/or the contents of email messages to investigate claims of racial discrimination.
To ensure the physical safety of natural persons, provided that the use of Personal Information is reasonably necessary and proportionate for this purpose. For example, we may disclose account information to law enforcement, when required by law, to investigate financial elder abuse.
For short-term, transient use, including non-personalized advertising shown as part of a current interaction with us.
To perform services such as maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying information, processing payments, providing financing, analytic services, or storage.
To verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by us, and to improve, upgrade, or enhance the service or device that is owned, manufactured by, manufactured for, or controlled by us.
If you are a California resident covered by the CCPA, you have the right to:
Receive this Notice at or before the point of collection of your Personal Information.
Request we disclose to you free of charge the following information covering the 12 months preceding your request:
The categories of Personal Information about you that we collected.
The categories of sources from which the Personal Information was collected.
The purpose for collecting Personal Information about you.
The categories of third parties to whom we disclosed Personal Information about you and the categories of Personal Information that were disclosed (if applicable) and the purpose for disclosing the Personal Information about you.
The specific pieces of Personal Information we collected about you.
Request we correct inaccurate Personal Information that we maintain about you.
Request we delete Personal Information collected from you, unless the CCPA recognizes an exception.
Be free from unlawful discrimination for exercising your rights under the CCPA.
Please see the section below entitled "How to Exercise Your Rights" for instructions explaining how you can exercise these rights described above.
We will acknowledge receipt of your request and advise you how long we expect it will take to respond if we are able to verify your identity. Requests for specific pieces of Personal Information will require additional information to verify your identity.
For individuals submitting a request on behalf of another person, we may require proof of authorization and verification of identity directly from the person for whom the request is made.
For a company or organization submitting a request on behalf of another person, we may require proof of authorization from the individual such as a Power of Attorney and verification of identity directly from the person for whom the request is made.
In some instances, we may not be able to honor your request. For example, we will not honor your request if we cannot verify your identity or if we cannot verify that you have the authority to make a request on behalf of another individual. Additionally, we will not honor your request where an exception applies, such as where the disclosure of Personal Information would adversely affect the rights and freedoms of another consumer or where the Personal Information that we maintain about you is not subject to the CCPA's access or deletion rights.
We will advise you in our response if we are not able to honor your request. We will not provide Social Security numbers, driver's license numbers or government-issued identification numbers, financial account numbers, unique biometric data, health care or medical identification numbers, account passwords or security questions and answers, or any specific pieces of information if the disclosure presents the possibility of unauthorized access that could result in identity theft or fraud or an unreasonable risk to data or systems and network security.
We will work to process all verified requests within 45 days pursuant to the CCPA. If we need an extension for up to an additional 45 days in order to process your request, we will provide you with an explanation for the delay.
If you are a California resident, you may submit a request by:
Completing an online request at: CCPA Request Form – California Consumer Privacy Act Request Form
Calling us at 1-866-844-7500, Monday through Friday from 8:00 AM to 5:00 PM Pacific Time.
We may change or update this Notice from time to time. When we do, we will post the revised Notice on this page with a new "Last Updated" date.
If you have any questions or concerns about our privacy policies and practices, please call 1-866-844-7500, Monday through Friday from 8:00 AM to 5:00 PM Pacific Time or email us.
Last updated: November 1, 2025.