OverDrive, Inc. and its affiliates ("OverDrive", "we", "us" or "our") provides digital content, applications, technology, services, and hosted websites to third parties. This Privacy Policy discloses the privacy practices for all OverDrive-hosted websites, software, technologies, services, support services, applications including Libby, Sora, and the OverDrive app, and OverDrive accounts (collectively referred to as "Services").
OverDrive respects your privacy. The purpose of this Privacy Policy is to make you aware of how OverDrive collects, manages, protects, uses, and/or shares information and what choices are available to you regarding the collection, use and distribution of your personally identifiable information (“PII”) and non-personally identifiable information ("non-PII").
Many users under the age of 13 enjoy using the Services. To see OverDrive's policy regarding the collection of information from children who are under 13 years old, please click here for OverDrive's Privacy Policy for Children.
Generally, PII is information that can be used on its own to identify a specific person. For example, PII can be a full name, home address, email address, phone number, or login details. In most cases, non-personally identifiable information or "non-PII" is data that cannot be used on its own to identify a specific person. For example, in the context of the Services, non-PII can be language preference, bookmarks, or highlights.
Non-PII is treated by OverDrive as PII when it's collected on an individual level and linked to any PII that you have chosen to submit to OverDrive or that OverDrive may have collected from your interactions with the Services.
You can use most Services without submitting much information to OverDrive. A valid library card or school ID is all you need to use most Services.
An OverDrive account is not required to use most Services, including Sora. In using the library Services, if you choose to create an OverDrive account, you will be required to submit PII to OverDrive. Please click here to visit the section of this Privacy Policy that applies specifically to your OverDrive account.
As part of your interaction with the library Services, you may willingly submit your PII in order to access certain features, such as submitting your email address in order to place a hold on a digital content title.
In addition to information that you may willingly submit to OverDrive, such as your library card number, school ID number, and/or email address, OverDrive may collect and store certain PII and non-PII related to your interactions and use of our Services, including but not limited to, IP address, device type, device ID, operating system, library card number, Adobe ID, library name, lending history, holds, reading progress, bookmarks, highlights, notes, and online activity.
Some Services provide the ability for you to see your lending history. If you are using your institution’s OverDrive-hosted website, Libby, or the OverDrive app, you will have the option to show your lending history. You can hide your lending history by following the instructions within the app or help articles. Your lending history is protected by OverDrive as confidential. It is not shared with any third parties, except to staff with appropriate authority acting within the scope of their duties for the administration of your institution (library, school, etc.). If we are compelled to disclose your lending history pursuant to a court order or subpoena, or to a person or agency with the relevant administrative or legislative investigative power, we will seek to challenge and limit the scope and comply with the authorized agency or person only as required by law.
OverDrive takes information security very seriously. We have implemented measures to protect against the loss, misuse, and alteration of your information. Your information is protected by physical, electronic, and procedural safeguards to prevent unauthorized disclosure. We encrypt the transmission of information using secure sockets layer (SSL) technology. We use computer safeguards such as firewalls and data encryption and physical access controls to our buildings and files. We authorize access to PII only for those employees who require it to fulfill their job responsibilities.
We collect information from you in order to:
OverDrive never sells your PII or non-PII. OverDrive will not use your information for any purposes other than the specified use. OverDrive does not share data that could result in third-party targeted advertising.
Email addresses submitted to OverDrive for holds notifications are stored by OverDrive so you can place future holds in a quicker, more convenient manner. OverDrive will not use your email address to send you any marketing or promotional communications without your opt-in consent.
We may anonymize certain PII and share it in an aggregated form with third parties in order to analyze Service usage, improve the Service, or for other similar purposes. Such information is anonymous and cannot be used to identify you. The use and disclosure of such anonymous information is not subject to any restrictions under this Privacy Policy.
We may also use third parties to process information you willingly submit to OverDrive, such as Alchemer (fka SurveyGizmo, https://www.alchemer.com/) for product and experience surveys, OnceHub (https://www.oncehub.com/) for meeting scheduling, and Salesforce (https://www.salesforce.com/) for customer administration and support.
Third parties may utilize OverDrive’s APIs to integrate their application(s) with OverDrive-hosted digital content collections to promote the discovery and circulation of digital content. OverDrive APIs may use Google Analytics (https://analytics.google.com) to track anonymous usage data for research and analytics purposes.
We retain information for as long as OverDrive deems necessary to provide the Services or as otherwise permitted by applicable law. Information about users of school Services is only retained by OverDrive for the time period necessary to support the authorized school or educational purposes.
Yes, we use cookies and similar technologies to collect and store certain information when you use, access, or interact with the Services. Cookies are small data file identifiers that are transferred to your device or web browser that allow us to recognize your device or web browser when you visit or use the Service. We use cookies for many purposes, such as to support the internal operations of the Services and make improvements to the Services. To read more about cookies and similar technologies, please visit our Cookie Policy.
While using our library Services, you may enjoy opportunities to post reviews, rate digital content, and share digital content information with others in public forums and on social networking websites such as Facebook, Twitter, and Goodreads. When you share such information, it is made public and is not subject to this Privacy Policy. We are not responsible for any third party's use of information you publicly display or disclose through our Services.
The ability to post reviews, ratings, and connect to social media to share digital content information is not a supported function of school Services, such as Sora.
In using the library Services, you may choose to access to other online digital content services, such as learning platforms and video catalogs, that are provided by a third party and are outside the control of OverDrive. You will leave the OverDrive library service when you access such third party digital content services. OverDrive sends minimal, anonymized information to the third party service so they can authorize you as a valid library patron. You may be required by the third party service to create an account. Any information you submit to the third party is not shared with OverDrive. You may also have the opportunity to opt-in to receive marketing or promotional emails from the third party. Any such marketing or promotional emails are not controlled by OverDrive. These third party digital content services have separate and independent privacy statements, notices, and terms of use, which we recommend you read carefully.
Given that the Internet is a global environment, using the Internet to collect and process information necessarily involves the transmission of data on an international basis. Therefore, by using the Services, you acknowledge and consent to the transfer of your information outside your country of residence to any country where we have facilities or engage third parties (including but not limited to, payment processors, cloud service or other Information Technology providers, and other companies that provide services to us). If you are visiting the Services from the EU, please click here to visit the section of this Privacy Policy that applies to transfers from the EU to the US. You understand that the countries to which we may transfer information may not have as comprehensive a level of data protection as in your country. OverDrive requires that third parties (if any), such as cloud service providers, with whom information about users of school Services is shared are obligated to safeguard such information using policies and procedures that are consistent with this Privacy Policy and must only use the information in order to perform the authorized school or educational purpose for which it was provided.
If you contact OverDrive directly for assistance resolving an issue with the Services, it may be necessary for OverDrive to use support tools to resolve your issue. For a limited number of issues, these tools may provide OverDrive support personnel with visibility of your borrowing information while your support case is being resolved.
Your name, email address, and password are required to create an OverDrive account. By creating and using an OverDrive account and/or otherwise consenting to the sharing of information with us, you authorize OverDrive to collect and retain the PII submitted by you. You also affirm that you are at least 13 years of age and acknowledge that an OverDrive account is not intended for use by individuals under 13 years of age. You may not share your information regarding your OverDrive account, including but not limited to your login credentials such as your password.
OverDrive accounts are intended for patrons using their public library. An OverDrive account is not required to use school Services, such as Sora. OverDrive accounts are separate and distinct from any sign-up or authentication required for Sora.
You can change your preferences for receiving newsletters, promotional offers, product updates and other OverDrive-initiated communications by emailing privacy@overdrive.com.
OverDrive's Instant Digital Card online service ("IDC") helps users obtain access to the library's OverDrive digital collection. Only authorized patrons of the library are permitted to access and checkout digital content from the library's digital collection.
You must be at least 13 years old to use IDC.
For users of libraries located in the U.S.:
If your library is located in the U.S. and you use IDC, you will be asked to submit your name, mobile phone number, and email address to OverDrive. Only U.S. mobile phone numbers are eligible for use with IDC. Your name and mobile phone number will be used to confirm your mobile phone number is associated with you and to verify that you have an address in your library's service area. U.S. libraries that participate in IDC provide OverDrive with the zip codes that comprise their service area. Submitting your name, mobile phone number, and email address to IDC confirms your consent to this Privacy Policy and OverDrive's Terms and Conditions.
To verify that your address is in your library's service area, OverDrive will share your name and mobile phone number with a third-party verification service, Cognito. Cognito will use your name and mobile phone number to return an address, if any, to OverDrive.
Cognito does not use your name or mobile phone number for marketing or sales purposes, nor do they share your name or mobile phone number with third parties for marketing or sales purposes.
OverDrive will send a text message to the mobile phone number you provide (standard text message rates apply) to verify the mobile phone number's association with you.
If you are validated as having a residential address within your library’s service area, your mobile phone number will serve as your digital library card and you will be able to access and checkout digital content from your library’s OverDrive digital collection. Your name, mobile phone number, and address are stored by OverDrive for the purpose of authenticating your checkouts from the library’s OverDrive digital collection. Unless otherwise permitted through your opt-in consent to receive marketing communications, OverDrive does not use your name or mobile phone number for marketing or sales purposes, nor do we share your name or mobile phone number with third parties for marketing or sales purposes.
In addition to obtaining checkout privileges to your library's digital collection, you may also be eligible for a library card for access to your library's additional resources (e.g., physical book and media borrowing). Through the validation process, OverDrive will store your address for the purpose of providing your name, address, mobile phone number, and email address (if provided by you) to your library, where you may be eligible for a library card for access to additional library resources. Your use of IDC confirms your consent to OverDrive providing your name, address, mobile phone number, and email address (if provided by you) with your library, and confirms your consent to be contacted by your library, if necessary.
If you have questions or concerns regarding IDC, please contact OverDrive at privacy@overdrive.com.
For users of libraries located outside of the U.S.:
If your library is located outside of the U.S. and you use IDC, you will be asked to submit your name, mobile phone number, and a country code or campaign code (“Code”). The Code you submit will be used to verify that you have a valid Code to be granted access to your library’s OverDrive digital collection. Submitting a Code to IDC confirms your consent to this Privacy Policy and OverDrive’s Terms and Conditions.
If your Code is validated by IDC, your mobile phone number will serve as your digital library card and you will be able to access and checkout digital content from your library’s OverDrive digital collection. Your name and mobile phone number are stored by OverDrive for the purpose of authenticating your checkouts from the library’s OverDrive digital collection. Unless otherwise permitted through your opt-in consent to receive marketing communications, OverDrive does not use your name or mobile phone number for marketing or sales purposes, nor do we share your name or mobile phone number with third parties for marketing or sales purposes.
In addition to obtaining checkout privileges to your library’s digital collection, you may also be eligible for a library card for access to your library’s additional resources (e.g., physical book and media borrowing). OverDrive may provide your name, mobile phone number, and email address (if provided by you) to your library, where you may be eligible for a library card for access to additional library resources. Your use of IDC confirms your consent to OverDrive providing your name, mobile phone number, and email address (if provided by you) with your library, and confirms your consent to be contacted by your library, if necessary.
If you have questions or concerns regarding IDC, please contact OverDrive at privacy@overdrive.com.
Data Transfer. OverDrive has adopted Standard Contractual Clauses (SCCs) to safeguard international data transfers, including transfers of PII from the EU, Switzerland, and other countries that use SCCs, to the US. OverDrive has adopted the International Data Transfer Agreement (IDTA) to safeguard international data transfers of PII from the UK to the US.
Legal basis for processing your PII. If you are visiting a Service from the EU, we must have a legal basis to process your PII. There are different legal bases on which we rely to process your PII, namely:
Performance of a contract. The use of your PII may be necessary to perform the specified function for which you submit your PII, and/or perform other contractual obligations and policies under which we provide our Services to you;
Consent. We will rely on your consent to use your information for direct marketing purposes. You may withdraw your consent at any time by contacting us using the information at the end of this Privacy Policy or by following an unsubscribe link in any marketing communication you receive from us; and
Legitimate interests. We use your PII for our legitimate interests to improve our Services, for internal administration, and security purposes. In such circumstances, it is important for us to ensure that your data protection interests or fundamental rights and freedoms are not overridden by our legitimate interests.
Your choices under EU law. If you are visiting from the EU, you may email privacy@overdrive.com or visit the Data Request center to ask us to:
If contacting us does not resolve your issue, you have the right to make a complaint to your data protection authority (if one exists in your country).
If you are not subject to EU law, these rights do not apply to you.
In addition to, and consistent with our other statements on privacy, OverDrive adopts the required principles for the EU-U.S. Data Privacy Framework (DPF), UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, as set forth by the U.S. Department of Commerce. To learn more about the standards incorporated into this policy via the DPF program, see: Data Privacy Framework (DPF) Principles. To view our certification under the DPF program, see: U.S. Department of Commerce Data Privacy Framework List.
This policy adheres to the EU-U.S. DPF Principles with regard to personal data transferred from the European Union and the United Kingdom and the Swiss-U.S. DPF Principles with regard to personal data transferred from Switzerland. If you are not subject to EU, UK, or Swiss law, this section does not apply to you. Under the DPF program OverDrive may be required to disclose PII in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. OverDrive is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). OverDrive is obligated to arbitrate claims and follow the terms as set forth in Annex I of the DPF Principles, provided that an individual has invoked binding arbitration by delivering notice to OverDrive and following the procedures and subject to conditions set forth in Annex I of the DPF Principles. Consistent with the DPF Principle II. 3., OverDrive maintains accountability for onward transfers. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at TRUSTe.
As explained in this Privacy Policy, OverDrive may collect certain information related to your interactions and use of our Services.
Information we collect directly from you. Depending on your use of the Services, the categories of information we may collect directly from you include the following:
We may also collect information you provide in your communications to us, such as when you respond to polls or surveys, or contact us with a question, comment, or request.
Information we automatically collect from you. As you interact with the Services, we may also collect information about you automatically though the use of cookies and similar technologies. Depending on your use of the Services, the categories of information we automatically collect from you may include the following:
If you do not want OverDrive-hosted websites to collect information through the use of cookies, you can set your web browser to block cookies. Additionally, you can manage your cookie preferences through the "Cookie Settings" link located within the Service. Please see our Cookie Policy for more information.
Information selling, sharing, and disclosing. OverDrive does not sell your information. OverDrive does not share your information with third parties for money or other valuable consideration. OverDrive may disclose your information to service providers solely for business purposes. These service providers support the internal operations of the Services, assist OverDrive in providing you access to the Services, and assist OverDrive in monitoring, analyzing, and optimizing the Services. The following categories of information may be disclosed to service providers for business purposes: identifiers and internet or other electronic network activity information.
Your rights under applicable law. If you are a California resident, you or your authorized agent may email privacy@overdrive.com, call toll-free 866-269-5794, or visit the Data Request center to ask us to:
Users may freely exercise these rights without fear of being denied the Services.
OverDrive will provide notice to users of the Sora service in the event of a security breach or material change in terms as required by contract with OverDrive's customers and in compliance with applicable regulations.
This Privacy Policy was last updated in February 2024. We will continue to evaluate this Privacy Policy against new technologies, business practices, and our users’ needs, and may make changes to the Privacy Policy accordingly. Please check the Privacy Policy periodically for updates. Your continued use of the Services after the posting of any changes to this Privacy Policy means that you agree to be bound by such changes.
In the event of a change of control (i.e. sale of sale or merger of OverDrive, Inc.) the successor entity will be subject to these same privacy commitments.
If we make material changes this Privacy Policy that increase our rights to use your PII, we will notify you via a prominent notice on the Services or via email prior to the change becoming effective. If you do not agree to the changes, you should discontinue use of the Services.
Please contact OverDrive at privacy@overdrive.com if: