What is Personal Information and non-PII?
"Personal Information" is information that can be used on its own to identify a specific person. For example, Personal Information can be a full name, home address, email address, phone number, or login details. OverDrive does not collect your Personal Information unless you choose to submit it to OverDrive.
In most cases, non-personally identifiable information or "non-PII" is data that cannot be used on its own to identify a specific person. For example, non-PII can be an IP address, device ID, or geolocation information. OverDrive collects and stores certain non-PII related to your interactions and use of our Services.
Non-PII is treated by OverDrive as Personal Information when it's collected on an individual level and linked to the Personal Information that you have chosen to submit to OverDrive.
Do I need to provide Personal Information to OverDrive in order to use the Services?
No, you can use most Services without providing any Personal Information to OverDrive. A valid library card or school ID is all you need to use most Services. As part of your interaction with the Services, you may willingly submit your Personal Information in order to access certain features, such as placing a hold on a digital content title.
If you have created an OverDrive account, you may use Facebook login as an option to sign into your OverDrive account. OverDrive does not send any Personal Information or non-PII to Facebook.
How Does OverDrive Protect my Personal Information?
OverDrive takes information security very seriously. We have implemented measures to protect against the loss, misuse, and alteration of your Personal Information. Any Personal Information is protected by physical, electronic, and procedural safeguards to prevent unauthorized disclosure. We encrypt the transmission of Personal Information using secure sockets layer (SSL) technology. We use computer safeguards such as firewalls and data encryption and physical access controls to our buildings and files. We authorize access to Personal Information only for those employees who require it to fulfill their job responsibilities.
What non-PII does OverDrive collect?
We collect and store certain information related to your interactions and use of our Services, including but not limited to, IP address, device type, device ID, operating system, library card number, Adobe ID, library name, digital content selections (e.g. lending history), and online activity. If you have chosen to submit your Personal Information to OverDrive, any such non-PII may be linked to your Personal Information and will be treated by OverDrive as Personal Information.
Some Services provide the ability for you to see your digital content selections/lending history. If you are using your institution's OverDrive-hosted website, Libby, or the OverDrive app, you will have the option to show your lending history. You can hide your lending history by following the instructions within the app or help articles. Your lending history is protected by OverDrive as confidential. It is not shared with any third parties, except to staff with appropriate authority acting within the scope of their duties for the administration of your institution (library, school, etc.) If we are compelled to disclose your lending history pursuant to a court order or subpoena, or to a person or agency with the relevant administrative or legislative investigative power, we will seek to challenge and limit the scope and comply with the authorized agency or person only as required by law.
How does OverDrive use information?
We collect Personal Information and non-PII from you in order to:
- Determine your current geographic location and/or language so that we may provide localized content and Services;
- Comply with the requirements of our publisher, library, and retail partners;
- Alert you if digital content becomes available for check-out from a library partner;
- Provide recommendations for digital content we think you may enjoy;
- Notify you of opportunities to provide feedback for OverDrive's Services;
- Sync bookmarks and most recent point viewed/played across devices;
- Support the internal operations of the Services, including but not limited to support for: activities necessary to maintain or analyze the Services, network communications, user authentication or personalization of content, activities necessary to perform authorized school or educational purposes, and security of users;
- Integrate with additional service providers for use of the Services;
- Personalize our Services to better reflect particular interests and preferences and for remarketing; and
- Generally improve your experience.
OverDrive never sells your Personal Information or non-PII. If you provide Personal Information to us, such as your email address for notification of library hold availability, OverDrive will not use your Personal Information for any other purposes than the specified use. OverDrive will not use your email address to send you any communications without your consent. Information about users of school Services is only retained by OverDrive for the time period necessary to support the authorized school or educational purposes.
How long is information retained by OverDrive?
We retain information for as long as OverDrive deems necessary to provide the Services or as otherwise permitted by applicable law.
What if I share Information with others while using the Services?
How can I change my preferences?
You can change your preferences for receiving newsletters, promotional offers, product updates and other OverDrive-initiated communications by emailing email@example.com.
What happens when I visit an external website not related to OverDrive's Services?
Is my information transmitted to other countries?
What if I contact OverDrive for a support issue?
If you contact OverDrive directly for assistance resolving an issue with the Services, it may be necessary for
OverDrive to use support tools to resolve your issue. For a limited number of issues, these tools may provide
OverDrive support personnel with visibility of your borrowing information while your support case is being
Your name, email address, and password is required to create an OverDrive account. By creating and using an OverDrive account and/or otherwise consenting to the sharing of information with us, you authorize OverDrive to collect and retain the Personal Information submitted by you. You also affirm that you are at least 13 years of age and acknowledge that an OverDrive account is not intended for use by individuals under 13 years of age. You may not share your information regarding your OverDrive account, including but not limited to your login credentials such as your password.
OverDrive's Instant Digital Card online service ("IDC") helps users obtain access to the library's OverDrive digital collection. Only authorized patrons of the library are permitted to access and checkout digital content from the library's digital collection
To verify that your address is in your library's service area, OverDrive will share your name and mobile phone number with a third-party verification service, Cognito. Cognito will use your name and mobile phone number to return an address, if any, to OverDrive. To aid the verification process and increase the likelihood that an address is found, you may be asked to submit your date of birth. Your date of birth will be shared with Cognito.
Cognito does not use your name, mobile phone number, or date of birth for marketing or sales purposes, nor do they share your name, mobile phone number, or date of birth with third parties for marketing or sales purposes.
OverDrive will send a text message to the mobile phone number you provide (standard text message rates apply) to verify the mobile phone number's association with you.
If you are validated as having a residential address within your library's service area, you will be able to access and checkout digital content from your library's OverDrive digital collection for twelve (12) months from the date you are validated. Your name, mobile phone number, address, and email address are stored by OverDrive for the purpose of authenticating your checkouts from the library's OverDrive digital collection. Your date of birth, if submitted to OverDrive, is not stored by OverDrive. Unless otherwise permitted through your opt-in consent to receive marketing communications, OverDrive does not use your name, mobile phone number, address, email address, or date of birth for marketing or sales purposes, nor do we share your name, mobile phone number, address, email address, or date of birth with third parties for marketing or sales purposes.
In addition to obtaining checkout privileges to your library's digital collection, you may also be eligible for a library card for access to your library's additional resources (e.g. physical book and media borrowing). Through the validation process, OverDrive will store your address for the purpose of providing your name, address, email address, and mobile phone number to your library, where you may be eligible for a library card for access to additional library resources. Your use of IDC confirms your consent to OverDrive providing your name, address, email address, and mobile phone number with your library, and confirms your consent to be contacted by your library, if necessary.
If you have questions or concerns regarding IDC, please contact OverDrive via email at firstname.lastname@example.org.
Rights applicable to users located in the EU
Data Transfer. OverDrive is part of the Rakuten Group, which includes the affiliates and subsidiaries of Rakuten, Inc. More information about Rakuten is available at https://global.rakuten.com/corp/about/company. As part of the Rakuten Group, OverDrive has adopted Rakuten's Binding Corporate Rules (BCRs) to safeguard international data transfers, including transfers from the EU to the US. The Rakuten BCRs have been approved by the Data Protection Authority of Luxembourg and can be found at https://corp.rakuten.co.jp/privacy/en/bcr.html.
Legal basis for processing your Personal Information. If you are visiting a Service from the EU, we must have a legal basis to process your Personal Information. There are different legal bases on which we rely to process your Personal Information, namely:
Performance of a contract. The use of your Personal Information may be necessary to perform the specified function for which you submit your Personal Information, and/or perform other contractual obligations and policies under which we provide our Services to you;
Legitimate interests. We use your Personal Information for our legitimate interests to improve our Services, for internal administration, and security purposes. In such circumstances, it is important for us to ensure that these interests are not overridden by your data protection interests or fundamental rights and freedoms.
Your choices under EU law. If you are visiting from the EU, you may email GDPRrequest@overdrive.com to ask us to:
- See what Personal Information we hold about you
- Object to our use of your Personal Information
- Erase your Personal Information
- Receive/Port your Personal Information in a usable electronic format
If contacting us does not resolve your issue, you have the right to make a complaint to your data protection authority (if one exists in your country).
If you are not subject to EU law, these rights do not apply to you.
Parents may email SDLremove@overdrive.com to inquire if their child has submitted Personal Information to OverDrive and to request the review, correction, and/or removal of any such Personal Information from our system.
Users of school Services may email SDLremove@overdrive.com to request the review, correction, and/or removal of your Personal Information, if any, from our system.
If you are a teacher or administrator at an educational institution using the school Services, please email SDLremove@overdrive.com to request the review, correction, and/or removal of a student's Personal Information, and we will facilitate your access to and correction of such Personal Information promptly upon your request.