California Privacy Policy

REV 11/2019
CALIFORNIA PRIVACY POLICY AND NOTICE AT COLLECTION

This CALIFORNIA PRIVACY POLICY AND NOTICE AT COLLECTION ("Policy" and/or "Notice") of Credit First National Association ("we," "us," or "our") applies solely to residents of the State of California ("consumers" or "you"). We adopt this Policy and Notice to comply with the California Consumer Privacy Act of 2018 ("CCPA") and other California privacy laws. Any terms defined in the CCPA have the same meaning when used in this Policy and Notice. The general Privacy Policy on our website is also applicable to you, but to the extent any information in the general Privacy Policy conflicts with this Policy, the information in this Policy shall apply to you.

Information We Collect

We collect information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household ("personal information"). In particular, we may collect the following categories of personal information from you and have collected these categories of personal information from consumers in the past 12 months:

Category Examples
Identifiers. Real name, alias, postal address, unique personal or online identifier, Internet Protocol address, email address, government issued ID, or other similar identifiers.
Purpose of Collection/Usage of Identifiers
We may use the personal information in this category to: make the credit card application decision; service the CFNA loan; provide you with information about products and services requested; provide you with information about CFNA products and services; enforce CFNA obligations and rights arising from agreement between CFNA and you; improve CFNA website and/or mobile application; testing, research, analysis and product development; respond to law enforcement, regulatory or judicial requests; evaluate or conduct a merger, divestiture, or restructuring; and protect the rights, property or safety of CFNA or other parties.
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Name, address, telephone number, Social Security number, government issued ID, signature, bank account number, credit/debit card number, or any other financial information. Some personal information included in this category may overlap with other categories.
Purpose of Collection/Usage of Personal Information
We may use the personal information in this category to: make the credit card application decision; service the CFNA loan; provide information about products and services requested; enforce CFNA obligations and rights arising from agreement between CFNA and you; improve CFNA website and/or mobile application; testing, research, analysis and product development; respond to law enforcement, regulatory or judicial requests; evaluate or conduct a merger, divestiture, restructuring, and protect the rights, property or safety of CFNA or other parties.
Protected classification characteristics under California or federal law. Age (40 years or older), race, physical or mental disability.
Usage of Protected Classifications
We may use the personal information in this category to: improve CFNA website and/or mobile application; testing, research, analysis and product development; respond to law enforcement, regulatory or judicial requests; and protect the rights, property or safety of CFNA or other parties.
Commercial information. Records of personal property, products or services purchased, obtained, or considered.
Usage of Commercial Information
We may use the personal information in this category to: service the CFNA loan; provide information about products and services requested; provide information about CFNA products and services; enforce CFNA obligations and rights arising from agreement between CFNA and you; testing, research, analysis and product development; respond to law enforcement, regulatory or judicial requests; and protect the rights, property or safety of CFNA or others parties.
Internet or other similar network activity. Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.
Usage of Internet or Network Activity
We may use the personal information in this category to: provide information about products and services requested; improve CFNA website and/or mobile application; testing, research, analysis and product development; respond to law enforcement, regulatory or judicial requests; and protect the rights, property or safety of CFNA or other parties.
Geolocation data. Physical location or movements.
Usage of Geolocation Information
We may use the personal information in this category to: provide information about products and services requested; improve CFNA website and/or mobile application; testing, research, analysis and product development; respond to law enforcement, regulatory or judicial requests; and protect the rights, property or safety of CFNA or other parties.
Sensory data. Audio, electronic, visual, thermal, olfactory, or similar information.
Usage of Sensory Data
We may use the personal information in this category to: service the CFNA loan, respond to law enforcement, regulatory or judicial requests; and protect the rights, property or safety of CFNA or other parties.
Inferences drawn from other personal information. Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Usage of Inferences
We may use the personal information in this category to: enforce CFNA obligations and rights arising from agreement between CFNA and you; respond to law enforcement, regulatory or judicial requests; and protect the rights, property or safety of CFNA or other parties.

Personal information does not include:

  • Publicly available information from government records.
  • De-identified or aggregated consumer information.
  • Information excluded from the CCPA's scope, like:
    • Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data;
    • Personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994.
Sources of Information Collected:
  • Identifiers, California Customer Records Statute personal information, and Commercial Information
    • Obtained indirectly from our cardholders or applicants through information we collect in the course of providing services to them
    • Obtained directly from our cardholders, applicants, or their authorized agents including the credit application completed at retail locations or on our website
    • Obtained from affiliates or dealers who provide information to us collected from their customers
  • Protected Classification Characteristics under California or Federal law
    • Obtained directly from our cardholders, applicants, or their authorized agents including the credit application completed at retail locations or on our website
    • Obtained directly and indirectly from activity on our website (www.cfna.com). For example, from submissions through our website portal or website usage details collected automatically
      • American with Disabilities Act requires websites to be accessible to those with disabilities — the tool enables consumers to set up preferences such as large font, voice recognition, etc.
  • Internet or similar activity
    • Obtained directly and indirectly from activity on our website (www.cfna.com). For example, from submissions through our website portal or website usage details collected automatically
  • Geolocation Information
    • Obtained directly from our cardholders, applicants, or their authorized agents including the credit application completed at retail locations or on our website
  • Sensory Data
    • Obtained directly from our cardholders, applicants, or their authorized agents including the credit application completed at retail locations or on our website
    • Obtained indirectly from our cardholders or applicants through information we collect in the course of providing services to them
  • Inferences
    • Obtained directly from our cardholders, applicants, or their authorized agents including the credit application completed at retail locations or on our website
    • Obtained indirectly from our cardholders or applicants through information we collect in the course of providing services to them
Sharing or Disclosure of Personal Information with Third Parties

We may disclose or share personal information to or with a third party for a business or commercial purpose and have done so in the preceding twelve (12) months.

In the preceding twelve (12) months, we have disclosed the following categories of personal information for a business purpose:

  • Identifiers
  • California Customer Records Statute personal information categories
  • Protected classification characteristics under California or federal law
  • Internet or other similar activity
  • Sensory data
  • Inferences
  • Commercial information

We disclose your personal information for a business purpose to the following categories of third parties:

  • Service providers
  • Our affiliates
  • Third parties to whom you or your agents authorize us to disclose your personal information in connection with products or services we provide to you
  • Government agencies as required by state or federal law
Sale of Personal Information

In the preceding twelve (12) months, we have not sold any personal information to a third party.

Additionally, we do not knowingly disclose or sell the personal information of minors under 16 years of age.

Your Rights and Choices

The CCPA provides consumers who are California residents with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.

Access and Deletion Rights

Right to Access Specific Information:

You have the right to request that we disclose certain information to you about our collection, use, and disclosure of your personal information over the past twelve (12) months, using the web form at the following link:

www.cfna.com (Option Titled "Privacy and Legal", select "Rights Request") or call 855-218-6524

We will use your name, address, email, and last four (4) digits of your social security number to verify your identity. Information provided will be compared to company records and validated against a third party verification database.

Once we receive and confirm your verifiable consumer request, we will disclose to you:

  • The categories of personal information we collected about you
  • The categories of sources from which we received the personal information we collected about you
  • Our business or commercial purpose for collecting or selling that personal information
  • The categories of third parties with whom we share that personal information
  • The specific pieces of personal information we collected about you (also called a data portability request)
  • The categories of personal information that we disclosed for a business or commercial purpose and the categories of recipients

We are not obligated to provide you with this information more than twice within a 12-month period.

Right to Request Deletion of Personal Information:

You have the right to request that we delete any of your personal information that we collected from you and maintained, subject to certain exceptions. You can submit a deletion request using the web form at the following link:

www.cfna.com (Option Titled "Privacy and Legal", select "Rights Request") or call 855-218-6524

The company will use your name, address, email, and last four (4) digits of your social security number to verify the consumer's identity. Information provided will be compared to company records and validated against a third party verification database. The consumer will be required to respond to an email generated from the company to confirm the deletion request.

Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.

We may deny your deletion request for certain reasons as set forth in CCPA, which will be described to you if all or a portion of your deletion request is denied.

General Rights Request Information:

Only you or a person that you authorize to act on your behalf, may make a verifiable consumer request related to your or your household's personal information. You may also make a verifiable consumer request on behalf of your minor child. We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use personal information provided in a verifiable consumer request to verify the requestor's identity or authority to make the request. If an authorized agent submits a request on behalf of a consumer, the authorized agent must provide proof of his/her/its registration as an authorized agent with the Secretary of State.

Response Timing and Format:

We will try to fully respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our response to you electronically via the email address provided on the request form. Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request's receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For access requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.

We do not charge a fee to process or respond to your verifiable consumer request.

Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:

  • Deny you goods or services
  • Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties
  • Provide you a different level or quality of goods or services
  • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services
Changes to Our Privacy Notice

We reserve the right to change this California Privacy Policy and Notice at Collection in our discretion and at any time. When we make changes to the California Privacy Policy and Notice at Collection, we may notify you by e-mail or through a notice on our website homepage.

Contact Information

If you have any questions or comments about the California Privacy Policy and Notice at Collection, the ways in which we collect and use your personal information, your choices and rights regarding such use, or wish to exercise your rights under California law, please do not hesitate to contact us at 855-218-6524 or Privacy@cfna.com.