California Businesses Detail CCPA Rights
Coverage from ASP-RCM Solutions, Northgate, and others
Articles
3
Active Days
44
The Topic

ASP-RCM Solutions, Northgate, and Rōti Modern Mediterranean publish California-specific notices describing the personal information they collect, how it is used and shared, and how residents can exercise CCPA/CPRA rights. All three describe identity verification and response timelines for consumer requests, while their disclosures differ on tracking and advertising: ASP-RCM and Northgate deny sale or cross-context behavioral advertising, whereas Rōti notes that cookies and tracking may qualify as sale or sharing under California law. The notices provide a practical view of how organizations are operationalizing California privacy transparency requirements across websites, customer services, and loyalty programs.
First Article: 05/01/26
Latest Article: 06/13/26
Summary
- ASP-RCM Solutions and Northgate state that they do not sell personal information or share it for cross-context behavioral advertising.
- Rōti says it does not sell data for monetary consideration but acknowledges that cookies and tracking may constitute sale or sharing under California law.
- All three notices describe consumer rights such as access, deletion, and request verification, with responses generally due within 45 days and possible extensions.
- Data collection ranges from website forms and professional information to restaurant-platform activity, geolocation, inferences, and sensitive personal information.
- Northgate says it honors Global Privacy Control signals, while the other notices emphasize different opt-out or privacy-request mechanisms.
- Third-party processing is generally described as contract-based, with Thanx identified as the service provider for Rōti’s loyalty program.
History
The main update is a sharper, more specific framing of how each company handles California opt-outs and third-party processing. Northgate’s recognition of Global Privacy Control and Rōti’s identification of Thanx as its loyalty-program provider add concrete implementation details to the privacy-notice story.
The update mainly reframes the notices as a broader privacy-disclosure system and adds an explicit third-party service provider actor, including a loyalty-program vendor tied to Roti. It also sharpens the procedural detail around authorized agents and privacy-choice mechanisms, but the core CCPA/CPRA story remains the same.
