Privacy Policy
- 1. Scope and How the Two Privacy Regimes Fit Together
- 2. What We Collect, Where It Comes From, and Why
- 3. Sensitive Personal Information
- 4. How We Use Personal Information
- 5. Who We Disclose Information To, and What Counts as a Sale
- 6. Do Not Sell or Share, and Global Privacy Control
- 7. How Long We Keep Information
- 8. How We Protect Information
- 9. Your Privacy Rights
- 10. Cookies, Pixels, Session Tools and Signals
- 11. Children
- 12. Our Status Under Data Broker Laws
- 13. Where Information Is Processed
- 14. Changes to This Policy
- 15. Contact the Privacy Team
1. Scope and How the Two Privacy Regimes Fit Together
This Privacy Policy explains how Banrox Inc. ("Banrox," "we," "us," "our") collects, uses, discloses, retains, and protects personal information through banrox.com, the Banrox member dashboard, our emails and text messages, and any page or feature that links to this policy.
Two different bodies of law apply to different data, and it matters which one you are looking at.
Financial information under GLBA
Information you give us to obtain or use a financial product or service, and information we obtain about you in connection with one, is governed by the Gramm-Leach-Bliley Act and Regulation P. The federal notice for that information is the GLBA Privacy Notice, and it controls for that data.
Everything else under state privacy law
Website analytics, marketing data, general enquiries, community posts, job applications, and other non-GLBA information are governed by this policy and by the state privacy laws described at State Privacy Rights.
Where a state law gives you a right that the GLBA exemption does not remove, you keep that right. Where the two overlap we apply the more protective standard rather than the narrower one.
This policy does not cover a third party's site or product. When you leave Banrox for a lender, bank, card issuer, or insurer, that company's own privacy policy governs from that moment.
2. What We Collect, Where It Comes From, and Why
The table below is the notice at collection required by California law and serves the equivalent requirement in other states. "Sold or shared" uses the statutory meaning in those laws, which is broader than an exchange of money.
| Category | Examples | Source | Why we collect it | Who receives it | Kept for | Sold or shared |
|---|---|---|---|---|---|---|
| Identifiers | Name, email, phone, postal address, IP address, device and account identifiers | You; your device | Create and run your account, support, security, fraud prevention, service messages | Hosting, email and SMS providers, fraud and identity vendors | Account life plus 7 years | No |
| Referral information | Name, email, phone, postal code, loan or product interest, requested amount | You, when you ask to be matched | Pass your request to the specific providers you asked about | The provider you selected | 24 months from the request | Only when you ask to be matched. See Section 5. |
| Government identifiers (sensitive) | Social Security number, taxpayer ID, driver licence or state ID number, date of birth | You | Verify that you are who you say you are, and obtain your credit file at your written request | Identity verification vendors, consumer reporting agencies | Account life plus 7 years, then destroyed | Never |
| Financial account information (sensitive) | Bank account tokens, card last four digits, balances, transactions, payment history | You; your bank through Plaid or an equivalent connection you authorise | Deliver the features you switched on, take payment for a paid plan | Payment processor, bank data aggregator | Account life plus 7 years | Never |
| Consumer report data (FCRA regulated) | Credit report contents, scores, alerts, tradelines, inquiries | Consumer reporting agencies, with your written authorisation | Show you your own credit position and alert you to changes | No one outside the vendors that deliver the feature to you | Displayed for the account life; source data retained per FCRA vendor terms | Never |
| Identity exposure data | Dark web findings, data broker listings that mention you | Monitoring vendors; public and non public sources | Alert you and send removal requests on your instruction | Monitoring vendors, the data brokers we write to on your behalf | Account life plus 2 years for the removal audit trail | Never |
| Online activity | Pages viewed, referring page, clicks, session duration, approximate city from IP | Your device, cookies and similar technologies | Run the site, measure what works, detect abuse | Analytics providers; advertising partners only if you consent | 25 months | Shared for advertising only with your consent. Off by default. |
| Communications | Emails, chat transcripts, support tickets, call recordings where lawful | You | Answer you, train our team, resolve disputes, meet record keeping duties | Support and telephony providers | 5 years | No |
| User content | Community posts, reviews, quiz answers, uploaded documents | You | Publish what you chose to publish, run the feature, enforce our rules | Hosting and moderation providers | Until you delete it, plus backups | No |
| Inferences | Product fit signals, risk and fraud scores | Derived by us from the above | Show relevant options, stop fraud | Fraud vendors | Account life plus 2 years | No |
We do not collect biometric identifiers, precise geolocation, health data, genetic data, union membership, religious or philosophical beliefs, racial or ethnic origin, sexual orientation, or immigration status, and we do not ask you for them. If you volunteer any of it in a free text field, we delete it when we find it.
3. Sensitive Personal Information
Your Social Security number, government ID numbers, financial account information, and the contents of your consumer report are sensitive personal information under California law and are protected categories under other state laws.
We use them only to verify your identity, to prevent and detect fraud and security incidents, to deliver the specific service you asked for, and to meet a legal obligation. We do not use them to infer characteristics about you. We do not use them for advertising. We do not include them in a referral. We do not sell them and we do not share them for cross context behavioural advertising, in any circumstance, for any price.
Because we limit our use to the purposes that California law itself exempts, the right to limit the use of sensitive personal information does not change how we treat it. You may still send us the request, and we will confirm this in writing.
4. How We Use Personal Information
- Provide, operate, secure, and improve the Services, and deliver the features you turned on
- Verify identity, authenticate logins, and prevent fraud, account takeover, bot abuse, and money laundering
- Obtain and display your own credit information at your written request
- Monitor for exposure of your information and act on removal instructions you give us
- Take payment, manage subscriptions, and issue refunds
- Send service, security, billing, and legally required messages
- Send marketing where you consented, and stop when you tell us to
- Answer support requests and resolve complaints and disputes
- Measure and improve the site, run aggregate analytics, and test changes
- Comply with law, respond to lawful requests, enforce our terms, and establish or defend legal claims
We do not use your information to make an automated decision that produces a legal or similarly significant effect about you. Banrox does not approve, deny, or price credit, insurance, or any financial product. Those decisions belong to the providers.
5. Who We Disclose Information To, and What Counts as a Sale
Service providers
We use vendors to host, secure, verify, message, analyse, and support. Each is contractually restricted to using Banrox data only to perform its service for us, is barred from selling it, and is barred from combining it with data from other clients except where the law allows. The categories and named vendors are at Service Providers and Data Recipients.
Providers you asked to be matched with
When you ask to be matched or request a quote, we pass the referral information listed in Section 2 to the specific providers responsive to that request, so that they can respond to you. Under California law this transfer can be a "sale" because we may be paid for it, so we treat it as one and give you the opt out even though you asked us to make it.
The hard limits on referrals. A referral never contains your Social Security number, a government ID number, a financial account number, the contents of your credit report, or a precise location. We do not sell or share a referral for anyone we know to be under 16. We do not sell lists of members to companies you did not ask about, and we do not place your information into an open bidding exchange.
Advertising partners
We do not share personal information for cross context behavioural advertising unless you consent through the cookie banner. If you consent, you can withdraw at any time, and a Global Privacy Control signal withdraws it automatically. See the Cookie and Tracking Technologies Notice.
Legal, safety and corporate
We disclose information when compelled by law or valid legal process, to protect the rights, property, or safety of Banrox, our members, or the public, to enforce our terms, and to auditors, insurers, and professional advisers under confidentiality. In a merger, acquisition, financing, or sale of assets, information may transfer to the successor, which remains bound by this policy for information collected before the transfer, and we will give notice before any material change in how it is handled.
We do not give any government agency direct or unfettered access to member data, and we require valid legal process. Where we are permitted to tell you about a request, we will.
6. Do Not Sell or Share, and Global Privacy Control
You may opt out of the sale or sharing of your personal information at any time. It is free, it takes effect immediately for future transfers, and we do not treat you differently for using it.
- Send a Global Privacy Control signal from your browser or extension. We detect and honour it automatically, with no account and no form. If you are signed in, we apply it to your account as well.
- Use the Do Not Sell or Share control in your account privacy settings.
- Email [email protected] with the subject line "Do Not Sell or Share."
- Call (888) 888-6401.
An opt out stops future transfers. It cannot pull back information a provider already received, and you would need to contact that provider directly to ask it to delete what it holds. We will tell you which providers received a referral if you ask.
7. How Long We Keep Information
We keep each category for the period stated in the table in Section 2, and no longer, unless a law, a regulatory record keeping obligation, a tax rule, or an active legal claim or investigation requires us to keep it longer. When a retention period ends we delete the record or de-identify it so it can no longer be linked to you, and we do not attempt to re-identify de-identified data.
Backups follow their own rotation and are overwritten on a rolling basis, normally within 90 days. A deletion request removes the record from live systems immediately and from backups as they cycle.
8. How We Protect Information
We run a written information security programme with a named person accountable for it, a documented risk assessment, encryption of personal information in transit and at rest, multi factor authentication for administrative access, least privilege access control with periodic review, logging and monitoring, vulnerability management, secure development practices, vendor security review, staff training, and a written incident response plan that is tested.
No system is perfectly secure, and we do not claim otherwise. If a breach of unencrypted personal information about you occurs, we will notify you and the applicable regulators within the deadlines the law sets, and the notice will say what happened, what was involved, and what we are doing. Our full posture, including which certifications we do and do not hold, is at Security and Vulnerability Disclosure.
9. Your Privacy Rights
Depending on where you live, you have some or all of the rights below. Every one of them is exercised through the same place: State Privacy Rights, which also sets out how we verify a request, how an authorised agent may act for you, how long we take, and how to appeal a refusal.
- Know and access. What we collected, where it came from, why, who received it, and a copy in a portable format.
- Correct. Fix information about you that is inaccurate.
- Delete. Have us delete information about you, subject to legal exceptions we will identify specifically if we rely on one.
- Opt out of sale or sharing. As described in Section 6.
- Limit sensitive information. As described in Section 3.
- Opt out of profiling in furtherance of decisions with legal or similarly significant effects. We do not do this, so the right is satisfied by default.
- Appeal a denied request, and then complain to your state attorney general.
- Non-retaliation. We will not deny service, charge a different price, or give you a lower quality of service because you used a privacy right.
California residents may also request, once a year and free, information about disclosures of personal information to third parties for their direct marketing purposes under California Civil Code section 1798.83, the "Shine the Light" law. Write to [email protected] with the subject "Shine the Light." Nevada residents may submit a verified request not to sell covered information under NRS 603A.340 to the same address.
10. Cookies, Pixels, Session Tools and Signals
Strictly necessary cookies run so the site works and stays secure. Analytics, functional, and advertising technologies load only after you choose in the cookie banner, or where your jurisdiction does not require prior consent. Session replay and heat mapping, where used, are disclosed by name in the cookie notice and are subject to the same consent gate.
We honour Global Privacy Control. We do not respond to legacy Do Not Track headers, because no common standard for them was ever settled, and we say so here rather than leave it unanswered. Full detail, including every vendor and its purpose, is at Cookie and Tracking Technologies Notice.
11. Children
The Services are for adults. We do not knowingly collect personal information from a child under 13, and we do not knowingly sell or share the personal information of a consumer under 16. If you believe a child gave us information, write to [email protected] and we will delete it and confirm to you that we did.
12. Our Status Under Data Broker Laws
Banrox collects personal information directly from the people it serves and does not buy consumer lists to resell. Information we handle to deliver a financial product or service is regulated under the Gramm-Leach-Bliley Act, and consumer report information is regulated under the Fair Credit Reporting Act. Both are excluded from the definition of a data broker in the California Delete Act and in the equivalent state statutes.
We state our status here rather than leave you to guess it, and we will update this section in the same release as any change to how we obtain or transfer information. If our status ever changes, we will register where required and honour deletion requests through the state mechanism, and this page will say so.
13. Where Information Is Processed
Banrox serves the United States and processes personal information in the United States. Some vendors provide support from other countries under contractual protections. We are not offering the Services in the European Economic Area, the United Kingdom, or Switzerland, and we do not target residents there.
14. Changes to This Policy
We will post any change here with a new effective date. If a change materially affects how we use information already collected about you, we will give notice by email to the address on your account at least 30 days before it takes effect, and where the law requires consent for the new use we will ask for it rather than assume it. Prior versions are available on request at [email protected].
15. Contact the Privacy Team
Privacy Team
Banrox Inc.
Attn: Privacy
40 N Altadena Dr, Ste 105
Pasadena, CA 91107
If you are not satisfied with our answer, you may complain to your state attorney general, to the California Privacy Protection Agency at cppa.ca.gov, or to the Federal Trade Commission at reportfraud.ftc.gov. Complaining to a regulator costs nothing and you do not have to come to us first.