California Businesses Detail CCPA Rights
Coverage from Rōti Modern Mediterranean, Northgate, and others

ASP-RCM Solutions, Northgate, and Rōti Modern Mediterranean publish California-specific notices describing the personal information they collect, how it is used and shared, and how residents can exercise CCPA/CPRA rights.
All three describe identity verification and response timelines for consumer requests, while their disclosures differ on tracking and advertising: ASP-RCM and Northgate deny sale or cross-context behavioral advertising, whereas Rōti notes that cookies and tracking may qualify as sale or sharing under California law. The notices provide a practical view of how organizations are operationalizing California privacy transparency requirements across websites, customer services, and loyalty programs.
The main update is a sharper, more specific framing of how each company handles California opt-outs and third-party processing. Northgate’s recognition of Global Privacy Control and Rōti’s identification of Thanx as its loyalty-program provider add concrete implementation details to the privacy-notice story.
The update mainly reframes the notices as a broader privacy-disclosure system and adds an explicit third-party service provider actor, including a loyalty-program vendor tied to Roti. It also sharpens the procedural detail around authorized agents and privacy-choice mechanisms, but the core CCPA/CPRA story remains the same.
The update sharpens the comparison between the notices by adding Roti’s explicit treatment of cookies and tracking as potential sale/sharing under California law, alongside clearer identification of service-provider categories. It also broadens the factual detail on what data categories are disclosed, including more sensitive and inferred information.
The story is largely unchanged, but the framing is slightly sharpened around how companies operationalize California privacy compliance. The current version more explicitly emphasizes request-handling, verification, and limits on tracking/sharing, rather than just describing standardized notices.
The update is mostly a reframing: the notices are described more clearly as standardized California privacy disclosures for website and customer-facing services, with stronger emphasis on compliance operations and common disclosure patterns. No new incident, enforcement action, or materially new company behavior appears.
The story has been reframed from a simple set of standard California privacy notices into a more operational picture of how companies implement CCPA/CPRA through specific collection tools, verification steps, and opt-out mechanics. The current version also makes the tracking-based sharing and service-provider distinctions more explicit.
These notices outline how different companies collect, use, and disclose California residents’ personal information under the CCPA and CPRA. Across the set, the main pattern is a standard privacy-rights framework: notices of data collection, disclosures to service providers, and procedures for access, deletion, correction, and opt-out requests. One company includes broader sale/sharing language tied to tracking technologies, while others explicitly state they do not sell or share personal information for cross-context behavioral advertising.
