This Privacy Policy for Evolve Bank & Trust (“Company”, “we”, “us” “our”) describes how we collect, use and disclose information about users of our website (www.getevolved.com), applications, financial products and services (through Company directly or via a third party partner), tools and features (collectively, the “Services”). For the purposes of this Privacy Policy, “you” and “your” means you as the user of the Services.
This Privacy Policy does not apply to information we collect about individuals who apply for or obtain financial products and services for personal, family or household purposes. For more information on how we collect, disclose and secure information relating to these customers, please refer to our separate Gramm-Leach-Bliley Act Privacy Policy located here.
Please read this Privacy Policy carefully. By using the Services, you agree to this Privacy Policy and its terms. If you do not agree to this Privacy Policy, please do not use or access any of the Services.
1. UPDATING THIS PRIVACY POLICY
We may modify this Privacy Policy, in which case we will update the “Last Revised” date. If we make material changes to the way we use information we collect, we will use commercially reasonable efforts to notify you and will take additional steps as required by applicable law. If you do not agree to any updates to this Privacy Policy, please do not use or access any of the Services.
2. OUR COLLECTION AND USE OF INFORMATION
When you use or access the Services, we may collect certain categories of information about you from a variety of sources. Some features of the Services may require you to enter information about yourself. You may decide not to provide this information, but doing so may prevent you from using or accessing these features.
Information that you submit through the Services may include:
- Basic contact information, such as your name, email address, company name and role, mailing address, and phone number. We collect this information to create and maintain your account, provide you with products or services you have requested, communicate with you (including to tell you about products that may be of interest to you), and respond to your queries.
- Account information, such as your username, password, and security questions. We collect this information to create, maintain, and secure your account with us. If you choose to register an account, you are responsible for keeping your account credentials safe. Do not share your access details with anyone else.
- Payment information, such as your bank account, credit or debit card information, and billing address. We collect this information to maintain and secure your account, process your payment, and to provide you with the products or services you have requested.
- Financial and commercial information, such as income, household size and income, expenses, assets, liabilities, credit score and report, business financial information, account information (e.g. account balances, payment history, account numbers and other billing information), tax related information, and records of property, products or services purchased, obtained or considered. We collect this information to verify your eligibility for, and provide you with, products and services you have requested.
- Information relating to your visit to our Site or use of our mobile application, including information that you submit when interacting with the Site’s and mobile application’s features and webforms and information collected via cookies and tracking technologies (“Tracking Technologies”), as described further below.
- Any other information you choose to provide, such as information provided to us to provide the Services, including your social security number, driver’s license, work experience, education, business information including TIN, gender, date of birth, and any other information that you choose to include in communications with us or to use the Services.
We collect certain information about your interaction with the Services (“Usage Data”) through Tracking Technologies, which we use to tailor features to you, provide you with offers or promotions, run analytics, and better understand user interactions with the Services:
- Device information, such as unique device identifier, IP address, device type, browser type, operating system, and precise location (if you choose to provide it).
- Online activity data, such as date and time stamps and log data.
- Other information, regarding your interaction with the Services, such as session recordings, clickstream data, and ad impressions.
We may also obtain information about you from outside sources, which we use to verify your identity and eligibility for the Services, provide you with products and services (including certain promotions, offers and rewards), personalize your experience and otherwise communicate with you, including from:
- Third parties, who help us supplement the information you have provided (e.g., credit bureaus, other financial institutions and banks and payment networks).
- Partners, with whom you may interact directly, and for whom Company provides products or services.
- Career websites, such as LinkedIn, Monster, or Indeed.
- Consumer marketing databases or other data companies who provide us with information.
- Other sources, such as from publicly available sources and government agencies
Any information we receive from outside sources will be treated in accordance with this Privacy Policy. We are not responsible or liable for the accuracy of the information provided to us by third parties and are not responsible for any third party’s policies or practices. See Section 5 below for more information. We may associate this information with your account (if you have a registered account), the device you use to access the Services, or email accounts that you use to engage us.
In addition to the specific uses of information described above, we may use all of the above information to provide, improve and develop the Services and our product offerings, to comply with any applicable legal or regulatory obligations, to enforce any applicable agreement, to protect or defend the Services, our rights, the rights of our users, or others, for the purpose of combatting fraud, or to otherwise operate our business.
3. HOW THE COMPANY DISCLOSES YOUR INFORMATION
We may disclose your information with third parties, including with:
- Vendors or other service providers who help us provide the Services, including for cloud storage, security, customer relationship management, fraud detection and prevention, marketing communications, web analytics, payment networks and payment processors.
- Partners, with whom you may interact directly and for whom Company may provide products or services.
- Other third parties, for marketing purposes, including joint marketing with other financial companies.
- Credit reporting agencies, to report account information as permitted by law.
We may also share your information to comply with applicable law or any obligations thereunder, in connection with an asset sale, merger, bankruptcy, or other business transaction, to comply with applicable terms of service, to ensure the safety of the Company and/or its users, within our corporate group, with professional advisors such as auditors, law firms, and accounting firms, or when you consent, request or direct us to share information.
4. COOKIES AND OTHER TRACKING TECHNOLOGIES
As described above, we collect Usage Data through Tracking Technologies, including Google Analytics, Hotjar, and DoubleClick.
For example, we use Hotjar to better understand our users’ experience, (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain the Services with user feedback. Hotjar uses cookies and other technologies to collect this information and stores this information on our behalf in a pseudonymized user profile. For further details, please see the ‘about Hotjar’ section of Hotjar’s support site.
Most browsers accept cookies automatically, but you may be able to control the way in which your devices permit the use of Tracking Technologies. If you choose, you may block or delete our cookies from your browser; however, blocking or deleting cookies may cause some of the Services to work incorrectly. To opt out of tracking by Google Analytics, click here.
Your browser settings may allow you to transmit a “Do Not Track” signal when you visit websites. Like many websites, our website is not designed to respond to “Do Not Track” signals received from browsers. To learn more about “Do Not Track” signals, you can visit http://www.allaboutdnt.com/.
In addition, we collect phone contacts and images in the mobile app when you share the app.
5. THIRD PARTY WEBSITES AND LINKS
We may provide links to third party websites or platforms. If you follow links to sites not affiliated with us, you should review their policies and other terms. We are not responsible for the privacy, security, or information found on these sites. Information you provide on public or semi-public venues such as third-party social networking platforms may also be viewable by other users of the Services and/or users of those third-party online platforms without limitation as to its use. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators.
6. CHILDREN’S PRIVACY
Children under the age of 13 are not permitted to use the Services, and we do not seek or knowingly collect any personal information about children under 13 years of age. If we become aware that we have unknowingly collected information about a child under 13 years of age, we will make commercially reasonable efforts to delete such information from our database.
If you are the parent or guardian of a child under 13 years of age who has provided us with their personal information, you may contact us using the below information to request that it be deleted.
7. TRANSFERS OF PERSONAL DATA
The Services are hosted and operated in the United States through Company and our service providers. By using the Services, you acknowledge that any information about you, regardless of whether provided by you or obtained from a third party, is provided to us and hosted on servers in the United States, and you authorize us to transfer, store, and process your information to and in the United States.
8. DATA SECURITY
Despite our reasonable efforts to protect your information, no security measures are impenetrable, and we cannot guarantee “perfect security.” Any information you send to us electronically, while using the Services or otherwise interacting with us, may not be secure while in transit. We recommend that you do not use unsecure channels to send us sensitive or confidential information.
9. CALIFORNIA RESIDENTS
This section applies to you only if you are a California resident (“resident” or “residents”). For purposes of this section, references to “personal information” shall include “sensitive personal information,” as these terms are defined under the California Consumer Privacy Act (“CCPA”). Please note that certain of the data we describe below is exempt from the requirements of the CCPA and the rights that you have under the CCPA, such as data regulated by the Fair Credit Reporting Act and the Gramm Leach Bliley Act. To view additional disclosures regarding our collection and processing of your nonpublic personal information and your rights regarding such data, please see our Gramm-Leach-Bliley Act Privacy Policy located here.
Processing of Personal Information
In the preceding 12 months, we collected and (where indicated below) disclosed for a business purpose the following categories of personal information and sensitive personal information (denoted by *) about residents:
Category | Categories of Recipients |
Identifiers such as name, e-mail address, IP address | Vendors or other service providers Third parties for marketing purposes Credit reporting agencies Partners for whom Company may provide products or services |
Personal information categories listed in the California Customer Records statute such as name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number | Vendors or other service providers Third Parties for marketing purposes Credit reporting agencies Partners for whom Company may provide products or services |
Characteristics of protected classifications under California or federal law such as race, color, national origin or ancestry, sex, age, physical or mental disability, veteran status and citizenship | Vendors or other service providers |
Commercial information such as records of products or services purchased | Vendors or other service providers Third Parties for marketing purposes Partners for whom Company may provide products or services |
Internet or other similar network activity such as information regarding your interaction with the website | Vendors or other service providers |
Geolocation data such as IP address | Vendors or other service providers |
Audio, electronic, visual, thermal, olfactory, or similar information such as photographs, video recordings and voice recordings | Vendors or other service providers |
Professional or employment-related information such as title of profession, employer, professional background | Vendors or other service providers Third Parties for marketing purposes Partners for whom Company may provide products or services |
Inferences drawn from other personal information such as profile reflecting your preferences | Vendors or other service providers Third parties for marketing purposes |
Government Identifiers* such as Social Security, driver’s license, state identification card, or passport number | Credit reporting agencies Vendors or other service providers Partners for whom Company may provide products or services |
Account access credentials* such as account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to your account | Vendors or other service providers |
Precise geolocation data* | Vendors or other service providers |
The specific business or commercial purposes for which we collect your personal information and the categories of sources from which we collect your personal information are described in the Section 1, Our Collection and Use of Information. For further information on the purposes for which we disclosed personal information over the preceding 12 months, see Section 3, How the Company Discloses Your Information. We only use and disclose sensitive personal information for the purposes specified in the CCPA.
We retain your information for as long as is reasonably necessary for the purposes specified in this Privacy Policy. When determining the length of time to retain your information, we consider various criteria, including whether we need the information to continue to provide you the Services, resolve a dispute, enforce our contractual agreements, prevent harm, promote safety, security and integrity, or protect ourselves, including our rights, property or products.
Selling and/or Sharing of Personal Information
We do not “sell” or “share” (as those terms are defined under the CCPA) personal information, nor have we done so in the preceding 12 months. Further, we do not have actual knowledge that we “sell” or “share” personal information of residents under 16 years of age.
Your California Privacy Rights
As a California resident, you may have the rights listed below in relation to personal information that we have collected about you. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
- Right to Know. You have a right to request the following information about our collection, use and disclosure of your personal information:
- categories of personal information we have collected, disclosed for a business purpose;
- categories of sources from which we collected personal information;
- the business or commercial purposes for collecting personal information;
- categories of third parties to whom the personal information was disclosed for a business purpose; and
- specific pieces of personal information we have collected.
- Right to Delete. You have a right to request that we delete personal information we maintain about you.
- Right to Correct. You have a right to request that we correct inaccurate personal information we maintain about you.
We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address, government issued ID or date of birth, before providing a substantive response to the request. You may designate, in writing or through a power of attorney document, an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorized them to act on your behalf, and we may need you to verify your identity directly with us.
In addition, California law permits residents to request certain details about how their “personal information” (as defined in California Civil Code Section 1798.83) is shared with third parties for their direct marketing purposes. We may from time to time elect to share certain personal information about you with third parties for those third parties’ direct marketing purposes. Residents may, under certain circumstances, obtain the categories of personal information shared and the names and addresses of all third parties that received personal information for their direct marketing purposes during the immediately prior calendar year. To make such a request, please contact us using the information listed below. Please note that we are only required to respond to one request per resident each year.
10. HOW TO CONTACT US
To exercise your CCPA rights or should you have any questions about our privacy practices or this Privacy Policy, please use the following contact form or contact us at 866.395.2754.