CATO Gas & Oil
SMS Terms

1. PURPOSE

The purpose of this Privacy Policy is to establish Cato Inc.’s commitment to protecting customer privacy and safeguarding personal information collected through the Cato Rewards Mobile Application, Loyalty and Rewards Program, associated websites, and related services.

This policy defines how customer information is collected, used, disclosed, retained, protected, and managed in accordance with applicable privacy laws, contractual obligations, industry best practices, payment card security requirements, and Cato Inc. information security standards.

This policy supports compliance with PCI DSS 4.0, applicable state privacy laws, federal consumer protection regulations, payment industry requirements, and Cato Inc. information security policies.

2. SCOPE

This policy applies to the Cato Rewards Mobile Application, customer loyalty accounts, rewards activity, digital coupons, promotions, customer communications, mobile app permissions, and related customer-facing loyalty services.

This policy applies to all customers participating in the Cato Rewards Program, users of the Cato Rewards Mobile Application, customer information collected through loyalty services, website users interacting with rewards services, and third-party service providers that process customer information on behalf of Cato Inc.

This policy applies to customer data collected electronically, digitally, verbally, or through business operations related to the Loyalty and Rewards Program.

3. INFORMATION COLLECTED

3.1 Account Information

  • First name
  • Last name
  • Email address
  • Mobile telephone number
  • Mailing address
  • Date of birth, where provided or required for eligibility
  • Loyalty Program Account ID
  • Username and password credentials

3.2 Loyalty Program Information

  • Loyalty account activity
  • Reward point balances
  • Fuel discount activity
  • Promotion participation
  • Digital coupon usage
  • Sweepstakes participation
  • Purchase history associated with loyalty accounts
  • Reward redemption activity

3.3 Mobile Application Information

  • Mobile device type
  • Operating system
  • Device identifiers
  • IP address
  • Application version
  • Network information
  • Mobile carrier information
  • Diagnostic data and crash logs

3.4 Location Information

  • With customer consent, the application may collect location information to locate nearby Cato locations, provide store locator functionality, enable location-based offers, and improve customer experience.
  • Customers may disable location services at any time through device settings.

4. USE OF CUSTOMER INFORMATION

Customer information may be used only for legitimate business purposes related to operation of the loyalty program and customer services.

Uses include

  • Create and manage loyalty accounts
  • Track reward eligibility
  • Award and redeem rewards points
  • Deliver personalized offers
  • Process promotions
  • Deliver digital coupons
  • Improve products and services
  • Analyze customer purchasing trends
  • Prevent fraud and abuse
  • Respond to customer inquiries
  • Comply with legal obligations
  • Maintain system security

5. MARKETING COMMUNICATIONS

Customers may elect to receive promotional emails, text messages, push notifications, loyalty program updates, fuel discount notifications, special event announcements, and product or service promotions.

Transactional communications relating to account access, rewards activity, security notifications, and legal communications may continue regardless of marketing preferences.

Opt-out methods include

  • Application settings
  • Email unsubscribe links
  • SMS STOP commands
  • Customer Support requests

6. SHARING OF INFORMATION

Cato Inc. does not sell customer personal information.

Customer information may be shared with authorized service providers that support operation, security, and administration of the loyalty program.

Authorized service provider functions may include

  • Loyalty program administration
  • Rewards processing
  • Mobile application services
  • Customer support services
  • Marketing communications
  • Data analytics services
  • Cloud hosting services
  • Fraud detection services

Service provider requirements

  • Maintain appropriate administrative, physical, and technical safeguards
  • Use customer information only as authorized by Cato Inc.
  • Protect customer information from unauthorized access, disclosure, alteration, or misuse

7. PAYTRONIX SERVICE PROVIDER PROCESSING

The Cato Rewards Program may utilize third-party loyalty program providers, including Paytronix and associated service providers, to administer rewards programs, offers, customer engagement services, and loyalty communications.

Third-party providers may process customer information solely for legitimate business purposes necessary to operate the Loyalty Program.

Provider obligations include

  • Maintain confidentiality of customer information
  • Protect customer information using reasonable safeguards
  • Comply with contractual security obligations
  • Comply with applicable privacy requirements

8. MOBILE APPLICATION PERMISSIONS

The mobile application may request access to specific device functions. Customers can manage app permissions through their device settings.

8.1 Location Services

  • Locate nearby stores
  • Deliver location-based promotions
  • Improve customer experience

8.2 Camera Access

  • Scan loyalty barcodes
  • Scan promotional QR codes
  • Redeem offers

8.3 Push Notifications

  • Reward alerts
  • Promotional notifications
  • Security messages
  • Program updates

9. INFORMATION SECURITY

Cato Inc. maintains administrative, technical, and physical safeguards designed to protect customer information from unauthorized access, accidental disclosure, alteration, loss, theft, or misuse.

Cato continuously evaluates and enhances security measures appropriate to the sensitivity of information processed.

Security controls may include

  • Access controls
  • Multi-factor authentication
  • Encryption technologies
  • Network security controls
  • Logging and monitoring
  • Vendor security reviews
  • Security awareness training
  • Vulnerability management processes

10. DATA RETENTION

Customer information will be retained only as long as necessary to operate the Loyalty Program, process rewards, maintain transaction histories, meet legal requirements, resolve disputes, prevent fraud, and support security investigations.

Information will be securely deleted, destroyed, anonymized, or archived when no longer required.

11. CONSUMER PRIVACY RIGHTS

Subject to applicable law, customers may request access to personal information, correction of inaccurate information, deletion of eligible information, information regarding information-sharing practices, and withdrawal of consent where applicable.

Cato will evaluate and respond to requests in accordance with applicable legal requirements.

12. CHILDREN’S PRIVACY

The Loyalty and Rewards Program is not intended for children under the age of thirteen (13).

Cato does not knowingly collect personal information from children under 13 without legally required parental consent. If such information is identified, reasonable efforts will be taken to remove the information.

13. INCIDENT RESPONSE AND BREACH NOTIFICATION

Any suspected unauthorized access, disclosure, loss, or breach involving customer information shall be handled in accordance with the Cato Incident Response Plan.

Cato will investigate suspected incidents and provide notifications where required by law, contractual obligations, or regulatory requirements.

14. POLICY VIOLATIONS

Violations of this policy by employees, contractors, vendors, or service providers may result in removal of system access, contract termination, disciplinary action, legal action, or reporting to regulatory authorities where applicable.

15. EXCEPTIONS

Any exceptions to this policy must be documented, include a business justification, be reviewed by Information Technology Management, and be approved by Executive Management.

16. RELATED POLICIES

Related Cato policies include

  • IT-DATA-401 Data Use Policy
  • IT-DATA-405 Data Retention and Disposal Policy
  • IT-IAM-101 Access Control Policy
  • IT-AI-902 AI Data Protection Policy
  • IT-GEN-004 Email Communication Policy
  • Incident Response Policy
  • Vendor Management Policy

17. COMPLIANCE MAPPING

FrameworkAreaPolicy Alignment
PCI DSS 4.0Requirement 3 – Protection of Stored Account DataProtects sensitive customer and payment-related information.
PCI DSS 4.0Requirement 7 – Access ControlLimits access to customer information based on business need.
PCI DSS 4.0Requirement 8 – Identification and AuthenticationSupports authenticated access to systems processing customer data.
PCI DSS 4.0Requirement 10 – Logging and MonitoringSupports monitoring and auditability for customer data systems.
PCI DSS 4.0Requirement 12 – Information Security PoliciesDocuments privacy and security responsibilities.
NIST CSFGovern, Protect, Detect, Respond, RecoverAligns privacy governance with security lifecycle controls.
Privacy PrinciplesNotice, Purpose Limitation, Data Minimization, Safeguards, Individual RightsDefines customer notice, permitted use, protection, and request handling.

18. CUSTOMER PRIVACY CONTACT

Questions regarding privacy practices, personal information requests, or concerns regarding this policy may be directed to:

Cato Inc.
Privacy Officer
Email: [email protected]
Phone: [Insert Number]
Address: [Insert Corporate Address]