Maintaining the privacy and security of your personal information is LightStream’s highest priority. In doing so, we want to provide transparency regarding how and why your data is collected, how it is used, with whom it may be shared, and how long it is kept. This notice, as well as LightStream’s Privacy Policy and Statement of Online Privacy Practices informs consumers how we will interact with your personal information.
The purpose of this Notice at Collection and CCPA Privacy Notice (“Notice”) is to provide you with timely notice, at or before the point of collection, of the details about our practices concerning the privacy of your personal information. This Notice is directed to consumers who reside in the state of California (“consumers” or “you”) and relates to personal information covered by the California Consumer Privacy Act (CCPA). Specifically, this Notice provides comprehensive information about our online and offline practices, along with details concerning how you may exercise your California privacy rights and make requests to access, correct or delete the information that LightStream holds about you. We will not collect additional categories of personal information without providing you a new Notice at Collection disclosing these categories.
Please note that LightStream adheres to an exemption within the CCPA for data collected pursuant to the Gramm-Leach-Bliley Act (GLBA). This Notice and the rights described do not apply to information we collect when you apply for or obtain our financial products and services for personal, family, or household purposes, which is subject to our Privacy Policy.
The following charts provide specifics about LightStream’s practices related to the collection, use and selling or sharing of personal information:
Categories of Personal Information Collected & Disclosed | Purpose for Collection | Purpose for Disclosure |
A. Identifiers: For example, real name or alias, address, online identifier, IP address, email address, account name, SSN, driver’s license number, passport number, or other similar identifiers. |
|
|
B. Personal Information Categories from Cal. Civ. Code § 1798.80I: For example, name, signature, SSN, physical characteristics or description, address, phone number, passport number, driver’s license or state ID card number, policy or account numbers, education, employment, employment history, credit or debit card numbers, or any other financial, medical or health insurance information. |
|
|
C. Characteristics of CA or Federal Protected Classifications: For example, race, religion, national origin), age (40 and over), gender, sexual orientation, medical condition, ancestry, pregnancy (includes childbirth, breastfeeding and/or related medical conditions), familial status, disability, veteran status, or genetic information. |
|
|
D. Commercial Information: For example, records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. |
|
|
E. Biometric Information: For example, physiological, biological or behavioral characteristics, including DNA, that can be used to establish individual identity. Biometric information includes, but is not limited to, imagery of the iris, retina, fingerprint, face, hand, palm, vein patterns, and voice recordings, from which an identifier template, such as a faceprint, a minutiae template, or a voiceprint, can be extracted, and keystroke patterns or rhythms, gait patterns or rhythms, and sleep, health, or exercise data that contain identifying information. |
|
|
F. Internet or Other Similar Network Activity: For example, browsing history, search history, and information regarding a consumer’s interaction with an Internet Web site, application, or advertisement |
|
|
G. Sensory Data or Recordings: For example, audio, electronic, visual, thermal, olfactory, or similar information that can be linked or associated with a particular consumer or household |
|
|
H. Professional or Employment-Related Information: For example, compensation, evaluations, performance reviews, personnel files and current and past job history. |
|
|
I. Education Information (defined as information that is not publicly available personally identifiable information as defined in the Family Educational Rights and Privacy Act (20 U.S.C. section 1232g, 34 C.F.R. Part 99)): Education records directly related to a student maintained by an education institution or party acting on its behalf, for example, non-public information that can be used to distinguish or trace an individual’s identity in relation to an educational institution either directly or indirectly through linkages with other information. |
|
|
J. Profile Data: For example, inferences drawn from personal information to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. |
|
|
We may also disclose personal information for other purposes at your direction or with your consent.
Categories of Sensitive Personal Information | Purpose for Collection | Purpose for Disclosure |
---|---|---|
SSN, Driver’s License, State ID Card, Passport Number |
|
|
Account Login, financial account, debit or credit card number when provided with any security or access code, password or credentials allowing access to an account |
|
|
Contents of a consumer’s mail, email and text messages (unless LightStream is the intended recipient) |
|
|
Genetic Data |
|
|
Biometric information for the purpose of unique identification |
|
|
We have sold or shared with third parties for cross-context behavioral advertising personal information to third parties in the preceding 12 months as disclosed in the table below. We also share personal information for business purposes with the third parties described below.
Categories sold to or shared with third parties over the last 12 months | Categories of third parties to whom this category of personal information has been sold or shared | Categories of Third Parties to whom the information was shared for business purposes |
A. Identifiers: |
|
|
B. Personal Information Categories from Cal. Civ. Code § 1798.80(e) |
|
|
Characteristics of CA or Federal Protected Classifications |
|
|
D. Commercial Information |
|
|
E. Biometric Information |
|
|
F. Internet or Other Similar Network Activity |
|
|
G. Professional or Employment-Related Information |
|
|
H. Profile Data |
|
|
Categories sold to or shared with third parties over the last 12 months | Categories of third parties to whom this category of personal information has been sold or shared | Categories of third parties to whom the information was shared for business purposes |
---|---|---|
Social Security Number, Driver’s License, State Identification Card, or Passport Number |
|
|
Account log-in, financial account, debit card, or credit card number when provided with any security or access code, password, or credentials allowing access to an account |
|
|
Contents of a consumer’s mail, email, and text messages (unless we are the intended recipient of the communication) |
|
|
Genetic Data |
|
|
Biometric information for the purpose of unique identification |
|
|
You may at any time direct LightStream to stop selling or sharing your personal information, which is called the “Right to Opt Out.” Once you make an opt out request, LightStream will comply within 15 business days, and will wait at least 12 months before asking you to reauthorize sales or sharing.
You may exercise your Right to Opt Out of Sale/Sharing in the following ways:
To opt out of tags, cookies, pixels that collect information when you visit LightStream.com |
|
To opt out of other personal information sold to or shared with third parties |
|
You have the right to limit our use and disclosure of your sensitive personal information collected by LightStream for the purpose of inferring characteristics about you. This is called the “Right to Limit”. LightStream only collects/processes sensitive personal information without the purpose of inferring characteristics about a consumer, therefore there is not an opt-out for the use of sensitive personal information.
You do not have the right to limit certain uses and disclosures of your sensitive personal information for the following business purposes:
LightStream has established product and business-level criteria for retention and disposal according to business requirements, laws, regulations, and applicable industry standards.
Sources of Personal Information
LightStream collects information from various sources, including:
You have the right to request that LightStream disclose categories or specific pieces of personal information we have collected about you over the last 12 months, the categories of sources from which that information was collected, the business or commercial purpose(s) for which the information was collected, sold, or shared with third parties for cross context behavioral advertising, and the categories of third parties with whom we share personal information.
You have the right to request correction of inaccurate personal information maintained by LightStream. Such updates are best made by logging into your online account or in the mobile app to make the corrections.
You have the right to request deletion of personal information that LightStream has collected, subject to certain exceptions. For example, we may deny your request if retaining the information is necessary for us to complete a transaction you requested or comply with our legal obligations
Consumers are welcome to submit right to know, correction, or deletion requests by visiting the Truist Privacy Center. LightStream is a division of Truist Bank and your requests made through the Truist Privacy Center will extend to other personal information Truist maintains about you. For example, if you ask to correct your phone number, we will modify the phone number across all Truist records where a correction can be made. Privacy preferences, such as email opt-outs or information sharing and use preferences, are managed separately. Information about LightStream’s privacy practices and how to manage your LightStream privacy preferences is available on this page (Lightstream.com/privacy).
If you need assistance completing the form or have any other questions or comments, you may email us at customerservice@lightstream.com. All requests must be verified prior to receiving a response, using Truist authentication protocols. Requesters will be asked to supply certain basic personal information to enable us to verify the request against our records, such as name, Social Security number, and address. Information submitted for verification purposes will only be used to verify the requestor’s identity and/or authority to make a request on another’s behalf.
Requests made on another person’s behalf can only be accepted upon receipt of documentation that the requestor is an authorized agent, parent, or legal guardian of the consumer whose information is being requested. This will require the submission of a valid Power of Attorney, Birth Certificate, approved LightStream authorization form, Guardianship Order, or other court order granting authority to receive information, as appropriate.
Upon submission of a request, consumers will receive an initial confirmation of receipt within 10 days. We will respond to your request within 45 days (unless an extension of up to 45 additional days is requested, upon which the consumer will receive notice and an explanation for the extension).
Your internet browser may give you more control over your privacy preferences via a Global Privacy Control (GPC) signal. This is a setting in your browser that notifies the websites you visit of your preferences to opt out of selling or sharing your personal information under California law. If you have opted out via the GPC signal, LightStream sites will recognize this signal and process your preference automatically as it pertains to tags, cookies and pixels that collect personal information when you visit LightStream.com. Please note the signal is processed at the browser-level and is not applied if you visit LightStream.com from a different browser or device that does not have the GPC signal enabled.
The submission of any CCPA request will have no impact on the service and/or pricing you receive from LightStream. It will not result in any denial of goods or services, or different prices, rates or quality of goods or services, nor will it result in retaliation against an employee, applicant, or independent contractor.
LightStream products and services are not intended for consumers under the age of 16, and we do not knowingly collect information from children under the age of 16 without consent. LightStream does not knowingly sell the personal information of minors under the age of 16 or share such information for cross-contextual advertising.
You can submit requests to update your sharing and marketing preferences by logging into your online account.
This Notice may be revised from time to time, so please review this page periodically. Any changes will become effective when we post the revised notice on the site (please note the effective date listed at the top of this page).
If you have any questions or comments on this notice or our privacy practices generally, please contact us at privacy@lightstream.com. You can also visit www.LightStream.com/privacy-security for additional information.
In today's environment, where people are subjected to marketing calls, junk mail, and spam and are very concerned about fraud and identity theft, we recognize the seriousness of our responsibility to help maintain the privacy and security of your personal information. As a result, we have adopted privacy and security practices that go beyond minimum legal requirements in order to give you greater comfort. We invite you to compare what we do with any other lender that you are presently using or considering.
Recognize and prevent scams
We take your security seriously. Protect yourself from fraudsters who reach out to you pretending to be LightStream.
Always confirm the caller is from LightStream before sharing personal information.
We are a Norton Secure Site:
For Nevada residents only, Nevada law requires that we also provide you with the
following contact information:
Bureau of Consumer Protection, Office of the Nevada Attorney General
555 E. Washington St., Suite 3900
Las Vegas, NV 89101
Phone: 702.486.3132
Email: BCPINFO@ag.state.nv.us
We may modify this privacy and security policy from time to time. We will post such changes to this page and update the last revised date. If the changes to the policy are significant, we will provide a more prominent notice including, possibly, an email notification to you.
FACTS | WHAT DOES LIGHTSTREAM DO WITH YOUR PERSONAL INFORMATION? |
---|---|
Why? | Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do. |
What? | The types of personal information we collect and share depend on the product or service you have with us. This information can include:
|
How? | All financial companies need to share customers' information to run their everyday business—to process transactions, maintain customer accounts, and report to credit bureaus. In the section below, we list the reasons financial companies can share their customers' personal information; the reasons LightStream chooses to share; and whether you can limit this sharing. |
Reason we can share your personal information | Does LightStream share? | Can you limit this sharing? |
---|---|---|
For our everyday business purposes—
such as process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus |
Yes | No |
For our marketing purposes—
to offer our products and services to you |
Yes | Yes (See below) |
For joint marketing with other financial companies | No | We don't share |
For our affiliates' everyday business purposes—
information about your transactions and experiences |
Yes | No |
For our affiliates' everyday business purposes—
information about your creditworthiness |
Yes | Yes (See below) |
For our affiliates to market to you | Yes | Yes (See below) |
For nonaffiliates to market to you | No | We don't share |
To limit our sharing |
|
---|---|
Questions? |
|
Who we are | |
---|---|
Who is providing this notice? | LightStream, and its affiliates. |
What we do | |
---|---|
How does LightStream protect my personal information? | To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings. Our employees are bound by our Code of Ethics and policies to access consumer information only for legitimate business purposes and to keep information about you confidential. |
How does LightStream collect my personal information? | We collect your personal information, for example, when you
|
Why can't I limit all sharing? | Federal law gives you the right to limit sharing only for
|
What happens when I limit sharing for an account I hold jointly with someone else? | Your choices will apply to everyone on your account—unless you tell us otherwise |
Definitions | |
---|---|
Affiliates | Companies related by common ownership or control. They can be financial and nonfinancial companies. LightStream is a division of Truist Bank.
|
Nonaffiliates | Companies not related by common ownership or control. They can be financial and nonfinancial companies.
|
Joint marketing | A formal agreement between nonaffiliated financial companies that together market financial products or services to you.
|
Other important information |
---|
State and Local Regulations: If, in addition to federal law, you are protected by specific state or local rules concerning information sharing and marketing, Truist will fully comply with these regulations as well. Under Vermont and California law, we will not share information we collect about you with companies outside of Truist Bank, unless the law allows. Nevada State law requires that we provide residents with the following contact information: Bureau of Consumer Protection, Office of the Nevada Attorney General, 555 E. Washington Street, Suite 3900, Las Vegas, NV 89101; Phone: 702.486.3132; Email: BCPINFO@ag.state.nv.us.
Use of Third Parties: We have arrangements with companies whose experience is essential for our own services to operate properly. These companies, some of which may be located outside the United States, work at LightStream's direction, only receive the information necessary to perform these functions, and adhere to LightStream’s data security guidelines.
Important Notice about Credit Reporting: We may report information about your account(s) to credit bureaus. Late payments, missed payments, or other defaults on your account(s) may be reflected in your credit report.
Do Not Call Policy. This notice is LightStream’s Do Not Call Policy under the Telephone Consumer Protection Act. LightStream abides by all federal and state regulations on telephone usage, maintains an internal Do Not Call list and makes no telemarketing calls to numbers on this list. All Do Not Call requests are implemented within 30 days and the selection is permanent - unless you elect to remove your number from the list.
|
Updated March 2023
LightStream has a longstanding commitment to protecting the confidentiality and security of our clients' personal information. We believe it is helpful to have an overview of how this commitment is applied as LightStream collects, uses, and protects your personal information when you visit us online.
For California residents, the California law requires that we provide consumers with advance notice of the types of personal information we collect from consumers, our intended use of such information, and a description of your privacy rights under California law. This includes rights to request disclosure of the types of personal information we have collected on you and your right to request that we delete certain information we have collected from you. Please see the CCPA Notice at Collection section of this Privacy page for further information on your specific consumer privacy rights.
This LightStream Statement of Online Privacy Practices (“Privacy Practices”) describes how we collect information when you visit or use our websites, mobile application, and other online services (“Online Services”) that link to this Privacy Policy. It also describes how we use and share such information and explains your privacy rights and choices.
LightStream’s business address is LightStream, PO Box 117320, Atlanta, GA, 30368-7320, USA. Our Customer Service Team may also be contacted via email at customerservice@lightstream.com.
This Privacy Practices do not apply to the websites, mobile applications, or services of LightStream that do not directly link to this policy. It also does not apply to non-LightStream companies, such as third-party websites to which we link online. Please review the privacy policies of other websites and services you visit to understand their privacy practices.
Our Consumer Privacy Policy applies to information that we collect about individuals who seek, apply for, or obtain our financial products and services for personal, family, or household purposes. In addition, our CCPA Notice at Collection related to the California Consumer Privacy Act applies to certain information we collect about California residents.
When you visit the LightStream website, application, or otherwise interact with us online, we may collect the following information:
1About biometric-enabled sign-ons: Your device stores the information it needs to recognize your facial features or fingerprints. The LightStream Mobile App uses your device’s functionality to obtain a signal that your device recognizes your facial features or fingerprints when you sign on. LightStream does not have access to the information your device uses to enable facial or fingerprint recognition, nor do we have access to or store your facial image or fingerprint data. You can always turn off facial or fingerprint recognition and go back to inputting user ID and password at any time. Your device’s user information will have additional information regarding its user controls and settings, including its privacy and security controls.
The information we collect online helps us to:
We only use personal information that we have about you when we have a legal basis to use such personal information under applicable data protection laws.
LightStream shares your information in different ways as permitted and required by law. For example, we may share your information with:
Please see the Privacy Policy section of this Privacy page for more information on how we may share your personal information and how you may be able to limit certain types of sharing.
Please note, we may also share aggregated and de-identified data, such as aggregated statistics regarding product usage, with third parties.
We reserve the right to transfer personal information we have about you in the event we sell or transfer all or a portion of our business or assets (including, without limitation, in the event of a reorganization, dissolution, or liquidation).
Our Online Services are intended for a U.S. audience. If you are visiting the LightStream website, please be aware that your personal information may be transferred to, or stored and processed in, the United States. We will rely on legally provided mechanisms (for example, derogations such as performance of a contract) to lawfully transfer personal data across borders.
We store your personal information as long as it is required to meet our contractual and legal obligations, or if we have a legitimate business need to do so.
LightStream and its online advertising and marketing partners may employ various technologies to collect information, including:
LightStream advertises its products and services on pages within our sites and on mobile applications. To make the content and advertising as informative and useful as possible, LightStream may target and personalize content and advertisements for products and services on our site.
LightStream advertises its products and services on websites and applications not affiliated with LightStream. The third-party companies we hire to display these ads use their own tracking technologies to measure the effectiveness of these ads and to understand your interests. Many of our third-party partners have their own privacy policies. We encourage you to review these policies carefully.
Some of our third-party advertising is interest-based and may use information about your online interests to customize the online ads you see. Many ad platforms have adopted the use of the AdChoices Icon for our interest-based advertising (excluding ads appearing on platforms that do not accept the icon). Anyone receiving an interest-based ad can click on the displayed icon to receive more information. The AdChoices Icon does not prevent you from receiving advertisements; instead, it allows you to control whether you receive interest-based advertisements and from which companies. Visit the Digital Advertising Alliance website for more information about the AdChoices Icon and interest-based advertising. If you would like to know more about how to opt out with your specific browser and device, you may visit the DAA Webchoices Browser Check and NAI Opt Out of Interest-Based Advertising tools for additional options. You can also download the AppChoices app to opt out in mobile apps.
Aggregation allows you to gather information from many websites and view that information in a consolidated format. An example of why you might use a third-party aggregation tool is if you wanted a comprehensive view of assets and liabilities held within your financial accounts. If you provide information about your LightStream accounts (including your access information) to an aggregation service provider, we will consider that as your having authorized all transactions initiated by that aggregation site. LightStream reserves the right to disable aggregation for any account without notice. If you wish to cancel your third-party aggregation services, you should also change your password at LightStream.com.
LightStream provides experiences on social media platforms such as Facebook, Instagram, LinkedIn, or Twitter that enable online sharing and collaboration. We use social media to facilitate social engagement and sharing, when such sharing is appropriate and safe. Please note, any content you post, such as pictures, information, opinions, or any personal information that you make available to other participants on these social platforms, is subject to the terms of use and privacy policies of those platforms. Please refer to them to better understand your rights and obligations with regard to such content.
Given the very public nature of social media, it is critical that we all safeguard confidential financial information. If you post information on a LightStream site that we feel should be shielded from public view, we will remove it. This includes not only specific details about your LightStream accounts and other private, confidential information (such as your Social Security number), but details of information relayed in private conversations between you and LightStream representatives. Please know that in taking down or editing your posts, we are focusing our experience and best judgment to keep your personal information safe.
Email transmitted across the internet is normally not protected and may be intercepted and viewed by others. Therefore, you should refrain from sending any confidential or private information via unsecured email to LightStream. We'll never ask you to send confidential information to us via email, such as your logon ID, password, full account numbers, or Social Security number.
Occasionally, we will retain the content of your email—and our replies—to confirm proper responses to your questions and requests, to comply with legal and regulatory requirements, and to ensure that we consistently deliver an enjoyable client experience to you.
LightStream may provide links to non-LightStream companies, such as credit bureaus or merchants, and will notify you when leaving the LightStream site. If you choose to link to websites not controlled by LightStream, we are not responsible for the privacy or security of these sites, including the accuracy, completeness, reliability or suitability of their information. If you are asked to provide information on one of these sites, we urge you to carefully study their privacy policies before sharing.
In summary, the following links can help you to customize and control your privacy preferences when interacting with LightStream online:
LightStream strictly follows the federal guidelines of the Children’s Online Privacy Protection Act (COPPA), which gives parents control over what type of information is collected online about their children. We do not knowingly collect, maintain, or use personally identifiable information from children under age 13 on our websites. We are not responsible for the data collection and use practices of nonaffiliated third parties that are linked from our websites. Visit the Federal Trade Commission’s COPPA Website for more information.
To protect personal information from unauthorized access and use, we use security measures that comply with applicable federal and state laws. These measures may include device safeguards and secured files and buildings as well as oversight of our third-party service providers to ensure information remains confidential and secure.
Keeping your account information accurate and up to date is very important. If your account information is incomplete, inaccurate or not current, please login to your online account and make appropriate updates. If you need help logging into your online account, please contact us at customerservice@lightstream.com.
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws. We will ask you to verify your identity to help us respond efficiently to your request.
Under non-U.S. data protection laws, you may have the right to complain to a data protection authority about our collection and use of your personal information.
You authorize your wireless carrier to use or disclose information about your account and your wireless device, if available, to us or our service provider for the duration of your business relationship, solely to help them identify you or your wireless device and to prevent fraud. LightStream’s Statement of Online Privacy Practices and Privacy Policy detail how we treat your data.
LightStream’s Online Privacy Practices may be revised from time to time, so please review them periodically. Any changes will become effective when we post the revised Practices on the site (Please note the effective date listed at the top of this page). If we revise our Online Privacy Practices in a material way, we will provide a conspicuous notice on our website when any changes take effect.
With regard to the security of your personal information, we employ a variety of electronic, physical, and procedural safeguards to protect your personal information including:
Encryption - We employ 128-bit Secure Sockets Layer (SSL) technology to encrypt your personal information when it is in transit between your web browser and our web server or vice versa. In addition, we also use advanced encryption when storing or backing up your personal information on our computers, substantially reducing the risk even in the event of loss or misuse of your personal information.
Software and Hardware Security - We employ stringent, up-to-date software and hardware solutions to minimize the risk that your encrypted, personal information could be hacked, lost, or stolen from our computer systems.
Physical Security - Your encrypted, personal information is located and stored in secure areas within our building and any offsite data processing facilities.
Access - Access to your personal information (either physically or online) is limited to you and our employees who have a "need to know" in order to perform their jobs and who have the appropriate authentications such as key cards, user IDs, and passwords. A user ID and password is required on the Sign In page on our web site for you to access and/or update your account information. Please remember to keep your user id and password secure. Also, if you prefer additional security, we offer our AccountLock feature which will prevent access to your account even with a valid user id and password. Access will only be granted after you request a pass code from us. We will then email you a randomly-generated, temporarily available pass code, allowing you one-time access to your account.
Training - We provide training to our employees regarding our security procedures.