Privacy Policy

Effective Date: June 6, 2026. Our Privacy Promise: we believe your personal information is yours. We do not sell your personal data for money. We only share it with trusted partners to run our business, improve our website, and show you relevant products. You always have the right to tell us to stop this sharing. OptiMA, Inc. (OptiMA, we, our, us) operates MyWhiteboards.com. This policy explains how we collect, use, and share your personal information, and your rights under the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other applicable state laws.

1. Information We Collect — Personal Information You Provide

We collect information you directly provide when you make a purchase, create an account, or contact us: first and last name; email address; phone number (used to contact you about your order and, with your consent, to send SMS text messages); and billing and shipping address (state, ZIP/postal code, city).

1. Information We Collect — Sensitive Personal Information

We do not collect Sensitive Personal Information (SPI) as defined under California and other state laws, other than limited payment information (e.g., last four digits of a card, tokenized payment data) processed exclusively by Authorize.net, our PCI-DSS Level 1 payment processor, to complete your transactions.

1. Information We Collect — Phone Call Recordings

When you call us at (866) 366-1500, your call is recorded. At the start of every inbound call, an automated message informs you that the call may be recorded; by remaining on the line, you consent to the recording. Outbound calls placed by our team are not recorded by default; if such a call is being recorded, the representative will identify themselves and state that the call is on a recorded line before the conversation begins. Recordings are used for quality assurance, training, dispute resolution, and regulatory compliance. We retain recordings only as long as needed for the purposes above and to meet our legal obligations.

1. Information We Collect — Files You Upload

If you submit a freight damage claim, order a custom-printed board, or apply for tax-exempt status, you may upload files to our website (e.g., photos of damaged shipments, custom artwork or design files, and government-issued tax-exemption certificates, which may include a federal EIN or state tax ID). Uploaded files are stored on Amazon Web Services (AWS S3) and accessed only by employees and contractors who need them to fulfill your request.

1. Information We Collect — Automatically

When you visit our website, we automatically collect certain information using technologies like cookies, Google Tag Manager, and Google Analytics:

  • IP address
  • Browser type and version
  • Pages visited and time spent
  • Referring website or source
  • Information about your browsing behavior and preferences

1. Information We Collect — Session Replay and Click Identifiers

We use Microsoft Clarity to record anonymized session replays (mouse movements, clicks, scrolls, page interactions) to understand how visitors use our website. Sensitive form fields (such as passwords and payment information) are automatically masked and never recorded. Session replays do not capture audio or video. We also capture click identifiers from advertising platforms (Google gclid, Meta fbclid, Microsoft Bing msclkid) and campaign parameters (UTM tags) when you arrive from an ad or marketing link. We store these identifiers in a cookie and your browser's local storage only as long as needed to attribute your purchase to the campaign that brought you to us. This capture only occurs if you have not opted out of advertising/marketing cookies.

2. How We Use Your Information

We use your information for specific, legitimate business purposes:

  • Order Fulfillment — to process orders, facilitate payments, and manage shipping to deliver your products.
  • Communications — to send transactional updates (order confirmations, shipping notifications, proof-ready alerts, account notifications) via email and, with your consent, via SMS; to respond to support inquiries; and, with your consent, to send marketing messages.
  • Quality Assurance and Training — to record phone calls for quality assurance, training, dispute resolution, and regulatory compliance.
  • Website Improvement and Security — to provide and improve our website and services, analyze traffic, and prevent fraud.

3. How We Share Your Information — Service Providers and Operational Vendors

We do not sell or rent your personal information for cash. We only share your data with specific third parties for the operational purposes below, and we require them to protect your information and use it only for the services they provide to us.

  • HubSpot — our marketing automation and CRM platform. Stores your contact information, tracks interactions with our website and emails, and handles delivery of our SMS messages (transactional and opted-in marketing). May set cookies to identify returning visitors.
  • Odoo — our enterprise resource planning (ERP) system. Stores order and customer records to process orders, manage inventory, and fulfill and support your purchases.
  • Yeastar — our cloud-based business phone system. Routes inbound and outbound calls and stores call recordings for the period described in Section 6.
  • Microsoft Clarity — anonymized session replay and behavioral analytics. Sensitive form fields are automatically masked.
  • Algolia — search service that processes your search queries and result interactions to power product search.
  • TaxCloud — sales-tax calculation service that receives your shipping address and cart contents to calculate applicable tax.
  • FreightPop and our shipping carriers (UPS, FedEx, USPS, and LTL freight providers) — to obtain shipping quotes and deliver your order.
  • Authorize.net (a Visa company) — payment processor for credit and debit card transactions.
  • Amazon Web Services (AWS) — hosts our website infrastructure, stores account data, processes file uploads, and manages account authentication via Amazon Cognito.
  • Customer support — vendors who help us respond to your inquiries.

3. How We Share Your Information — Advertising and Analytics Partners

We share limited data with advertising and analytics partners to measure performance and provide targeted advertising:

  • Meta (Facebook and Instagram) — Meta Pixel (browser) and Conversions API (server-side) to measure ad performance and create audiences. Conversion events include order details and hashed forms of your email and phone; Meta does not receive your name, address, or payment information from us.
  • Google — Google Ads, Google Analytics 4, and Google Tag Manager for measurement, attribution, and remarketing.
  • Microsoft (Bing) — Bing Ads / UET tag for advertising attribution.

3. How We Share Your Information — Legal and Safety

We may disclose your information if required by law or to protect our rights and safety. A full vendor and cookie list is available through the Didomi Preferences Center, accessible via the Cookie Settings link in the footer of any page.

4. Your Privacy Rights (For US Residents)

If you are a resident of a US state that provides comprehensive consumer privacy rights (such as California, Virginia, Colorado, or Connecticut), you have certain rights regarding your personal data. To exercise any of these rights, contact us at compliance@mywhiteboards.com or call (866) 366-1500.

  • Right to Know/Access — request what personal information we collect, use, and disclose about you.
  • Right to Deletion — request that we delete personal information we collected from you, with some legal exceptions.
  • Right to Correct — request that we correct inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing — opt out of the sale or sharing of your personal information.
  • Right to Limit Use of SPI — direct us to limit the use and disclosure of your sensitive personal information.
  • Right to Non-Discrimination — we will not discriminate against you for exercising your privacy rights.

4. Your Privacy Rights — Identity Verification, Response Time, Authorized Agents

Identity Verification: before we process your request, we will verify your identity. If you have an account, we may ask you to confirm your email and the last four digits of your phone number, OR your most recent order number. If you do not have an account, we may ask for two or more pieces of information that match what we have on file. For requests by authorized agents, we require a signed authorization, the agent's identification, and verification of the consumer's identity. Response Time: we will respond to verifiable consumer requests within 45 calendar days of receipt. If we need additional time, we will notify you in writing and the extension will not exceed an additional 45 days. Authorized Agents: you may use an authorized agent to submit a request on your behalf. We require a signed authorization document, the agent's verifiable identification, and proof of your own identity. Send authorized-agent requests to compliance@mywhiteboards.com.

5. Your Choices and Controls

Cookie and Tracking Preferences — we use Didomi as our consent management platform. Manage your preferences any time via the Cookie Settings link in the footer of any page. Do Not Sell or Share My Personal Information — California residents may opt out of the sale or sharing of personal information at any time via the Do Not Sell My Personal Information link in the footer. We also honor the Global Privacy Control (GPC) signal. Email Marketing Preferences — manage email subscriptions from your Communication Preferences page when logged in (/account/marketing) or via the unsubscribe link in every marketing email. Opting out of marketing cookies does not unsubscribe you from email marketing, and vice versa — they are managed separately. SMS and Text Message Communications — with your consent we send transactional messages (order-related) and marketing messages. You consent by checking the SMS opt-in box during checkout, in your account preferences, or by replying JOIN to (508) 501-4677. Message frequency varies; message and data rates may apply. Reply STOP to opt out, or HELP for help. Opting out of SMS does not unsubscribe you from email marketing. Phone Call Recording — calls to our customer service team are recorded, and outbound calls we place are recorded only when we tell you so at the start of the call. If you do not wish to be recorded, tell the representative at the start of the call and we will continue without recording, or contact us by email at support@mywhiteboards.com instead.

6. Data Security, Retention & Breach Notification

Data Security: we use appropriate technical and organizational measures to protect your personal data from unauthorized access, unlawful processing, or accidental loss. Data Retention: we retain personal information only as long as needed for the purpose it was collected, or as required by law:

  • Account and order data — retained while your account is active and for the period required by tax, accounting, and other legal obligations (typically 7 years for tax records).
  • Marketing engagement data — retained for up to 24 months after your last interaction with our communications, or until you opt out or request deletion.
  • Tax-exemption certificates — retained while your account is active and for 7 years after account deletion, to satisfy IRS and state record-keeping requirements.
  • Custom artwork files — retained to support reorders. We cannot guarantee retrieval of files, particularly older files, so we recommend you keep your own copy of any artwork you submit.
  • Freight-claim photos — retained for 3 years after claim closure for audit purposes.
  • Phone call recordings — retained only as long as needed for the purposes above and to meet our legal obligations.

6. Breach Notification

In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law, including Massachusetts law (201 CMR 17.00).

7. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for their privacy practices or content.

8. Children's Privacy

Our website is not intended for individuals under the age of 13. We do not knowingly collect personal data from children. If you believe we have collected information from a child, please contact us at compliance@mywhiteboards.com and we will delete it.

9. Geographic Scope

Our website and services are primarily intended for individuals located in the United States. We do not market to or offer services to individuals in the European Union, and the General Data Protection Regulation (GDPR) does not apply to our processing of personal data.

10. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted on this page and the Effective Date updated. We will review and update the policy at least every 12 months, as required by the CPRA.

11. Contact Us

If you have questions about this Privacy Policy, your privacy rights, or our data practices, please contact us. OptiMA, Inc., 220 Cherry St., Shrewsbury, MA 01545. Privacy/Compliance: compliance@mywhiteboards.com. General support: support@mywhiteboards.com. Phone: (866) 366-1500. Phone hours: Mon–Fri 8:00 AM – 4:30 PM ET.