CarMax Information Privacy & Safeguards Notice

GENERAL PRIVACY POLICY
Thank you for visiting the CarMax website. We hope that you find our website to be a useful part of your car-buying experience. Please note that this General Privacy Policy describes our overall privacy practices for the website. Section II applies to California users. Section III is our privacy policy for nonpublic personal information used in the provision of financial services.

If any information we have about you is incorrect, we will gladly correct it. Simply Email us noting the incorrect information and the correction. We reserve the right to verify the correctness of this information. Please note that in the event we amend the Privacy Policy, posting the amended version will serve as notice to you of that change and the policy will note its effective date.

Some information collected is non-identifying. For example, although our site servers collect information about a user’s internet protocol address, our server is not able to automatically associate that information with a particular user. We may collect non-identifying information associated with that address, such as the time and date of a visit, the originating domain name, the browser type, and the particular pages or products viewed on the site.

CarMax may utilize a “cookie.” A “cookie” is a small text file that a website can place on your computer’s hard drive in order to collect information about your activities on the website. Most browsers automatically accept cookies, but you have the option to change your browser to decline them. We use cookies on certain pages of our websites, but these cookies are not used to identify anonymous site visitors. Our cookies enable you to proceed smoothly through our sites and enable us to know whether you’ve visited our sites before to eliminate some steps that are directed to new visitors. Similarly, a cookie may be placed by our third-party advertising companies. These companies may use aggregated statistics about your visits to this and other web sites in order to provide you with advertisements about goods and services that you may be interested in. The information they collect does not include your personal information.

Image tags work in conjunction with cookies. An image tag, also referred to as a clear GIF or web beacon, is a small image file that may be located on select pages on our websites.

The third-party advertising companies may also employ technology that is used to measure the effectiveness of ads. Any such information is anonymous. They may use this anonymous information about your visits to this and other sites in order to provide advertisements about goods and services of potential interest to you. No personal information about you is collected during this process. The information is anonymous and does not link online actions to an identifiable person. If you would like more information and want to explore the option of not having this information collected by third-party advertisers click here.

At this time, CarMax has contracted with Omniture, TruEffect and Google to collect information about how website users navigate our websites. This information will not be disclosed and will be used only to generate anonymous visitor profiles, which do not contain personally identifiable information. The anonymous profiles are used to provide website users content specifically tailored to them. To opt out of Omniture’s collection of information about how you navigate our websites, please go to http://www.omniture.com/en/company/acquisitions/visualsciences/privacy/policy. To opt out of TruEffect’s collection of information about how you navigate our websites, please go to http://www.trueffect.com/about-us/privacy. To opt out of Google’s collection of information about how you navigate our websites, please go to http://www.google.com/privacy_ads.html.

With respect to unrelated, third party web sites, such as third party online retailers, advertisers, or unrelated sites that we may happen to link to, or web sites that link to our website, those third parties may collect personal information directly from you. The information policies and practices of these unrelated parties are not covered by this privacy policy. We do not control the privacy policies of third parties even if we may provide hyperlinks or other access to their web sites. We are not responsible or liable for their independent policies and practices. Please review their privacy policies and practices. It is your responsibility to review them and decide if you are satisfied with their protections.

We collect certain personally identifying information that users voluntarily provide to use. For example, we collect the email addresses of those who contact us by email. We also collect information that you may voluntarily provide to us in surveys or by filling out a website registration form. As described above, we use that information to serve you, to improve the content of our site, and to contact you for marketing purposes. As a reminder, if you provide personal information to us for the purposes of a financial service, the please see Section III for the applicable privacy policy.

We take commercially reasonable steps to protect the information we collect online. However, as effective as these measures are, no security system is impenetrable. We do not provide an absolute guarantee of the security of our information databases, nor do we guarantee that the information you may choose to supply will not be intercepted while you transmit it from your computer, over the internet, or along other third party networks, and to our systems. However, with respect to security: when we intend to transfer and receive certain types of sensitive information, such as financial information, we redirect visitors to a secure server using, for example, Transport Layer Security or Secure Sockets Layer security.

CALIFORNIA USERS: YOUR CALIFORNIA PRIVACY RIGHTS
For residents of California Only. Section 1798.83 of the California Civil Code requires select businesses to disclose policies relating to the sharing of certain categories of customers' personal information with third-parties. These businesses are required to accept such requests from customers but are only required to honor one request per calendar year. Businesses have thirty (30) days to respond to each inquiry. Each inquiring customer will receive an explanation of the categories of customer information shared and the names and addresses of the third-party businesses. In limited circumstances, customers' failure to submit requests in the manner specified will not require a response from the business.

If you are a current CarMax customer in California, you may request such information from CarMax by sending an email correspondence noting your name, address, and email address. You must also include a request that CarMax provide such information to you using the following or similar verbiage. "I request that CarMax provide its third-party information sharing disclosures required by section 1798.83 of the California Civil Code." Press the link at the end of this sentence to create your message: WebOptOut@carmax.com. The same request may be made by regular mail by sending the above information to CarMax, 12800 Tuckahoe Creek Parkway, Richmond, VA 23238, ATTENTION: Legal Department.

FINANCIAL PRIVACY
FACTS WHAT DOES CARMAX DO WITH YOUR PERSONAL INFORMATION?
Why? Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do.
What? The types of personal information we collect and share depend on the product or service you have with us. This information can include:
  • Social Security Number and Income
  • Account Balances and Payment History
  • Credit Score and Credit History
When you are no longer our customer, we continue to share your information as described in this notice.
How? All financial companies need to share customers' personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers' personal information; the reasons CarMax chooses to share; and whether you can limit this sharing.
Reasons we can share your personal information Does CarMax share? Can you limit this sharing?
For our everyday business purposes — such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus Yes No
For our marketing purposes — To offer our products and services to you Yes No
For joint marketing with other financial companies No We don't share
For our affiliates' everyday business purposes — Information about your transactions and experiences Yes No
For our affiliates' everyday business purposes — Information about your creditworthiness No We don't share
For nonaffiliates to market to you No We don't share
Questions?
Call (800) 519-1511
Who we are
Who is providing this notice? CarMax and its related entities in the CarMax family of companies.
What we do
How does CarMax protect my personal information? To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings. We also maintain other physical, electronic and procedural safeguards to protect this information and we limit access to information for those employees for whom access is appropriate.
How does CarMax collect my personal information? We collect your personal information, for example, when you
  • apply for financing
  • give us your income information
  • give us your employment history
  • give us your contact information
  • show your driver's license
We also collect your personal information from others, such as credit bureaus, affiliates, or other companies.
Why can't I limit all sharing? Federal law gives you the right to limit only
  • sharing for affiliates' everyday business purposes – information about your creditworthiness
  • affiliates from using your information to market to you
  • sharing for nonaffiliates to market to you
State laws and individual companies may give you additional rights to limit sharing.
Definitions
Affiliates Companies related by common ownership or control. They can be financial and nonfinancial companies.
  • CarMax, Inc., CarMax Auto Superstores, Inc., CarMax of Laurel, LLC, CarMax Auto Mall, LLC, CarMax Auto Superstores West Coast, Inc., CarMax Business Services, LLC (includes CarMax Auto Finance, a division), CarMax Auto Superstores California, LLC, CarMax Funding Services, LLC, CarMax Funding Services II, LLC, CarMax Auto Superstores Services, Inc.
Nonaffiliates Companies not related by common ownership or control. They can be financial and nonfinancial companies.
  • CarMax does not share with nonaffiliates so they can market to you.
Joint marketing A formal agreement between nonaffiliated financial companies that together market financial products or services to you.
  • CarMax doesn't jointly market.
Other important information
CarMax includes, CarMax, Inc., CarMax Auto Superstores, Inc., CarMax of Laurel, LLC, CarMax Auto Mall, LLC, CarMax Auto Superstores West Coast, Inc., CarMax Business Services, LLC (includes CarMax Auto Finance, a division), CarMax Auto Superstores California, LLC, CarMax Funding Services, LLC, CarMax Funding Services II, LLC, CarMax Auto Superstores Services, Inc.