Item 1A. Risk Factors
ITEM
1A. RISK FACTORS
Except
as described below, there have been no material changes from the risk factors previously disclosed in our Annual Report on Form 10-K filed
with the SEC on March 22, 2023.The disclosure of risks identified below does not imply that the risk has not already materialized.
Anti-takeover provisions in our Second Amended
and Restated Certificate of Incorporation, our Third Amended and Restated Bylaws as well as provisions of Delaware law, contain anti-takeover
provisions, any of which could delay or discourage a merger, tender offer, or assumption of control of the Company not approved by our
Board of Directors that some stockholders may consider favorable.
Provisions of Delaware law, our Second Amended and Restated Certificate
of Incorporation, and our Third Amended and Restated Bylaws could hamper a third party’s acquisition of us, or discourage a third
party from attempting to acquire control of us. You may not have the opportunity to participate in these transactions. These provisions
could also limit the price that investors might be willing to pay in the future for equity interests in the Company. These provisions
include:
● the
right of our Board to elect a director to fill a vacancy created by the expansion of our Board or the resignation, death or removal of
a director in certain circumstances, which prevents stockholders from being able to fill vacancies on our Board;
● a
prohibition on stockholder action by written consent, which forces stockholder action to be taken at an annual or special meeting of
our stockholders;
● a
prohibition on stockholders calling a special meeting and the requirement that a meeting of stockholders may only be called by members
of our Board, which may delay the ability of our stockholders to force consideration of a proposal or to take action, including the removal
of directors;
● the
requirement that changes or amendments to certain provisions of our certificate of incorporation or bylaws must be approved by holders
of at least two-thirds of our common stock; and
● advance
notice procedures that stockholders must comply with in order to nominate candidates to our Board or to propose matters to be acted upon
at a meeting of stockholders, which may discourage or deter a potential acquirer from conducting a solicitation of proxies to elect the
acquirer’s own slate of directors or otherwise attempting to obtain control of us.
In December 2022, we amended
our bylaws to add requirements relating to stockholder nominations of directors, including a requirement that stockholder nominees complete
a written questionnaire and that stockholder nominees make themselves available for interviews by our Board upon request.
In addition, we are subject
to the provisions of Section 203 of the Delaware General Corporation Law, which may prohibit certain transactions with stockholders owning
15% or more of our outstanding voting stock or require us to obtain stockholder approval prior to engaging in such transactions. Coliseum
collectively holds approximately 44.7% of our outstanding voting stock. Any delay or prevention of a change in control transaction or
changes in our Board could adversely affect our ability to execute transactions that are needed to carry out our operations and growth
strategies and cause the market price of our common stock to decline.
40
Our business and our reputation could be
adversely affected by the failure to protect sensitive employee, customer and consumer data, or to comply with evolving regulations relating
to our obligation to protect such data.
In the ordinary course of
our business, we collect and store certain personal information from individuals, such as our customers and suppliers, and we process
customer payment card and check information for purchases via our website. In addition, we may share with third-parties personal information
we have collected. Cyber-attacks designed to gain access to sensitive information by breaching security systems of large organizations
leading to unauthorized release of confidential information have occurred at a number of major U.S. companies despite widespread recognition
of the cyber-attack threat and improved data protection methods. Computer hackers may attempt to penetrate our computer system or the
systems of third-parties with which we have shared personal information and, if successful, misappropriate personal information, payment
card or check information or confidential Company business information. In addition, a Company employee, contractor or other third party
with whom we do business may attempt to circumvent our security measures in order to obtain such information and may purposefully or inadvertently
cause a breach involving such information. For example, though it did not involve access to or release of personal information, we recently
experienced an unauthorized intrusion into one of our vendor’s system using a former contractor’s credentials that resulted
in access to email addresses and an unauthorized email being sent under a valid Purple email address. Breaches involving any personal
information could be more likely to the extent we have any material weakness in internal control over financial reporting related to information
technology general controls in the areas of user access and segregation of duties related to certain IT systems that support the Company’s
financial reporting processes.
We and third-parties with
which we have shared personal information have been subject to attempts to breach the security of networks, IT infrastructure, and controls
through cyber-attack, malware, computer viruses, social engineering attacks, ransomware attacks, and other means of unauthorized access.
For example, in 2022, we experienced a spear-phishing attack that resulted in the unauthorized change to a significant vendor’s
bank account to which we made payments that were lost in part until the scheme was discovered. We expect that this attack will result
in costs to us of up to $250,000. We anticipate that we may, in the future, continue to be subject to these and similar cyber threats.
A breach of systems resulting in the unauthorized release of sensitive data could also adversely affect our reputation and lead to financial
losses from remedial actions or potential liability, possibly including punitive damages, and could also materially increase the costs
we already incur to protect against these risks. In addition, cyber-attacks, such as ransomware attacks, if successful, could interfere
with our ability to access and use systems and records that are necessary to operate our business. Such attacks could materially adversely
affect our reputation, relationships with customers, and operations and could require us to expend significant resources to resolve such
issues. We continue to balance the additional risk with the cost to protect us against a breach. Additionally, while losses arising from
a breach may be covered in part by insurance that we carry, such coverage may not be adequate for liabilities or losses actually incurred.
We may be subject to data
privacy and data breach laws in the states in which we do business, and as we expand into other countries, we may be subject to additional
data privacy laws and regulations. In many states, state data privacy laws (such as the California Consumer Privacy Act), including application
and interpretation, are rapidly evolving. The rapidly evolving nature of state and federal privacy laws, including potential inconsistencies
between such laws and uncertainty as to their application, adds additional compliance costs and increases our risk of non-compliance.
While we attempt to comply with such laws, we may not be in compliance at all times in all respects. Failure to comply with such laws
may subject us to fines, administrative actions, and reputational harm.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.