CATO Gas & Oil
Mobile App Privacy Policy

1. PURPOSE

The purpose of this policy is to establish requirements governing the use of SMS text messaging communications associated with the Cato Rewards Program, Cato Rewards Mobile Application, customer engagement activities, marketing campaigns, promotional offers, account notifications, and loyalty program administration.

This policy helps ensure that SMS messaging activities are conducted in a controlled, transparent, privacy-conscious, and compliant manner.

This policy supports alignment with

  • Applicable consumer protection regulations
  • Carrier messaging requirements
  • SMS industry best practices
  • Customer privacy requirements
  • Cato Inc. Information Security Policies
  • Customer consent requirements for text messaging communications

2. SCOPE

This policy applies to all SMS text messaging activities associated with the Cato Rewards Program and related customer engagement services.

This policy applies to

  • Cato Rewards Program members
  • Mobile application users
  • SMS subscribers
  • Marketing campaigns utilizing SMS
  • Loyalty and rewards notifications
  • Third-party providers administering SMS communications
  • Employees responsible for SMS campaigns

3. AUTHORIZED SMS COMMUNICATIONS

Transactional Messages

  • Loyalty account notifications
  • Points balance updates
  • Reward redemption confirmations
  • Account verification messages
  • Password reset notifications
  • Security alerts

Marketing Messages

  • Promotional offers
  • Fuel discount notifications
  • Digital coupon alerts
  • Event announcements
  • Limited-time offers
  • Loyalty bonus opportunities

4. CUSTOMER CONSENT REQUIREMENTS

Customers must provide affirmative consent before receiving marketing-related SMS messages. Customer consent records must be retained in accordance with applicable record retention requirements.

Accepted consent methods may include

  • Mobile application registration
  • Loyalty enrollment forms
  • Website enrollment forms
  • Electronic consent forms
  • Written consent forms
  • Other approved consent mechanisms

5. SMS OPT-IN DISCLOSURE

Customers enrolling in SMS communications shall be informed of the program purpose, expected message types, expected message frequency, customer support contact information, opt-out instructions, and message/data rate disclosures.

Example disclosure: By providing your mobile number and enrolling in Cato Rewards SMS Alerts, you consent to receive recurring automated marketing and informational text messages from Cato Inc. Message frequency may vary. Message and data rates may apply. Consent is not a condition of purchase.

6. SMS OPT-OUT REQUIREMENTS

Customers must be able to opt out at any time. Upon opt-out, marketing messages shall cease promptly, opt-out requests shall be honored without charge, and customer preferences shall be updated within the messaging platform.

Approved opt-out methods include

  • Reply STOP
  • Mobile application settings
  • Customer Support requests
  • Website preference center

7. SMS HELP REQUESTS

Customers may request assistance by replying HELP, contacting Customer Support, or using available support channels within the mobile application.

Example response: For support regarding Cato Rewards SMS Alerts, contact Customer Support at [Phone Number] or visit [Website].

8. MESSAGE FREQUENCY

Message frequency shall be limited to legitimate business needs. Cato shall implement reasonable controls to prevent excessive messaging and customer fatigue.

Examples include

  • Reward notifications
  • Fuel discount alerts
  • Promotional campaigns
  • Account activity notifications

9. PROHIBITED MESSAGING CONTENT

The following content is prohibited

  • False or misleading statements
  • Illegal activity
  • Unauthorized financial solicitations
  • Harassing or abusive content
  • Content prohibited by wireless carriers
  • Unapproved third-party advertisements
  • Messages that violate customer privacy obligations

10. THIRD-PARTY SERVICE PROVIDERS

Cato may utilize third-party providers to deliver SMS communications. Provider administration must align with the requirements governing loyalty and customer engagement services used by the Cato Rewards Program.

PROVIDERS MUST

  • Protect customer information
  • Maintain confidentiality
  • Limit use of information to authorized purposes
  • Comply with applicable privacy requirements
  • Comply with contractual security requirements

11. CUSTOMER INFORMATION PROTECTION

Information collected for SMS communications may include mobile phone number, loyalty account identifier, communication preferences, enrollment records, and opt-in/opt-out history.

Such information shall be protected in accordance with Cato privacy, data use, retention, incident response, and vendor management requirements.

12. SECURITY REQUIREMENTS

Administrative, technical, and physical safeguards shall be implemented to protect SMS subscriber information.

Controls may include

  • Access controls
  • Multi-factor authentication
  • Vendor security reviews
  • Encryption where applicable
  • Monitoring and logging
  • Incident response procedures

13. INCIDENT RESPONSE

Any suspected compromise involving SMS subscriber data shall be reported immediately to Information Technology and Information Security personnel. Incidents shall be managed according to Cato approved Incident Response procedures.

14. COMPLIANCE AND ENFORCEMENT

Failure to comply with this policy may result in suspension of messaging activities, revocation of system access, disciplinary action, contract termination, or legal/regulatory reporting where required.

15. RELATED POLICIES

Related Cato policies include

  • IT-DATA-401 Data Use Policy
  • IT-DATA-402 Customer Privacy Policy – Cato Rewards Mobile Application
  • IT-DATA-405 Data Retention and Disposal Policy
  • IT-GEN-004 Email Communication Policy
  • Incident Response Policy
  • Vendor Management Policy

16. COMPLIANCE MAPPING

FrameworkAreaPolicy Alignment
CTIA Messaging Best PracticesCustomer Consent, Opt-Out Processing, Message Transparency, Consumer ProtectionDefines consent, STOP/HELP handling, and permitted text message content.
TCPAPrior Express Consent and Revocation RightsRequires consent before marketing SMS and supports customer opt-out rights.
PCI DSS 4.0Requirements 7, 8, 10, and 12Documents access control, authentication, logging, monitoring, and policy governance for systems handling customer data.
NIST CSFGovern, Protect, Detect, Respond, RecoverAligns SMS data protection with the Cato security governance lifecycle.
Privacy PrinciplesNotice, Choice, Consent, Security, AccountabilitySupports customer transparency and responsible handling of mobile messaging data.

17. CUSTOMER SMS CONTACT INFORMATION

Questions regarding SMS messaging practices, opt-in records, opt-out requests, or program support may be directed to:

Cato Inc.
SMS Program Administrator
Email: [email protected]
Phone: [Insert Number]
Address: [Insert Corporate Address]