CCPA Privacy Notice / Notice At Collection

 

Last Updated December 2023

Maintaining the privacy and security of your personal information is LightStream’s highest priority. In doing so, we want to provide transparency regarding how and why your data is collected, how it is used, with whom it may be shared, and how long it is kept. This notice, as well as LightStream’s Privacy Policy and Statement of Online Privacy Practices informs consumers how we will interact with your personal information.

The purpose of this Notice at Collection and CCPA Privacy Notice (“Notice”) is to provide you with timely notice, at or before the point of collection, of the details about our practices concerning the privacy of your personal information. This Notice is directed to consumers who reside in the state of California (“consumers” or “you”) and relates to personal information covered by the California Consumer Privacy Act (CCPA). Specifically, this Notice provides comprehensive information about our online and offline practices, along with details concerning how you may exercise your California privacy rights and make requests to access, correct or delete the information that LightStream holds about you. We will not collect additional categories of personal information without providing you a new Notice at Collection disclosing these categories.

Please note that LightStream adheres to an exemption within the CCPA for data collected pursuant to the Gramm-Leach-Bliley Act (GLBA). This Notice and the rights described do not apply to information we collect when you apply for or obtain our financial products and services for personal, family, or household purposes, which is subject to our Privacy Policy.

The following charts provide specifics about LightStream’s practices related to the collection, use and selling or sharing of personal information:

General Personal Information

 
General Personal Information
 
Categories of Personal Information Collected & Disclosed Purpose for Collection Purpose for Disclosure
A. Identifiers: For example, real name or alias, address, online identifier, IP address, email address, account name, SSN, driver’s license number, passport number, or other similar identifiers.
  • Deliver, manage and support products and services, manage relationships and maintain accounts
  • Assess and manage risk
  • Manage fraud and financial crimes
  • Meet legal, regulatory, or compliance requirements
  • Market our products and services
  • Manage and optimize internal operations purposes
  • Support and optimize channels and interactions
  • Share for all purposes from “purpose for collection”
B. Personal Information Categories from Cal. Civ. Code § 1798.80I: For example, name, signature, SSN, physical characteristics or description, address, phone number, passport number, driver’s license or state ID card number, policy or account numbers, education, employment, employment history, credit or debit card numbers, or any other financial, medical or health insurance information.
  • Deliver, manage and support products and services, manage relationships and maintain accounts
  • Assess and manage risk
  • Manage fraud and financial crimes
  • Meet legal, regulatory, or compliance requirements
  • Market our products and services
  • Manage and optimize internal operations purposes
  • Support and optimize channels and interactions
  • Share for all purposes from "purpose for collections"
C. Characteristics of CA or Federal Protected Classifications: For example, race, religion, national origin), age (40 and over), gender, sexual orientation, medical condition, ancestry, pregnancy (includes childbirth, breastfeeding and/or related medical conditions), familial status, disability, veteran status, or genetic information.
  • Deliver, manage and support products and services, manage relationships and maintain accounts
  • Assess and manage risk
  • Manage fraud and financial crimes
  • Meet legal, regulatory, or compliance requirements
  • Market our products and services
  • Manage and optimize internal operations purposes
  • Support and optimize channels and interactions
  • Share for all purposes from “purpose for collection”
D. Commercial Information: For example, records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
  • Deliver, manage and support products and services, manage relationships and maintain accounts
  • Assess and manage risk
  • Manage fraud and financial crimes
  • Meet legal, regulatory, or compliance requirements
  • Market our products and services
  • Manage and optimize internal operations purposes
  • Support and optimize channels and interactions
  • Share for all purposes from “purpose for collection”
E. Biometric Information: For example, physiological, biological or behavioral characteristics, including DNA, that can be used to establish individual identity. Biometric information includes, but is not limited to, imagery of the iris, retina, fingerprint, face, hand, palm, vein patterns, and voice recordings, from which an identifier template, such as a faceprint, a minutiae template, or a voiceprint, can be extracted, and keystroke patterns or rhythms, gait patterns or rhythms, and sleep, health, or exercise data that contain identifying information.
  • Assess and manage risk (fraud and security detection through identity verification)
  • Share for all purposes from “purpose for collection”
F. Internet or Other Similar Network Activity: For example, browsing history, search history, and information regarding a consumer’s interaction with an Internet Web site, application, or advertisement
  • Deliver, manage and support products and services, manage relationships and maintain accounts
  • Assess and manage risk
  • Manage fraud and financial crimes
  • Meet legal, regulatory, or compliance requirements
  • Market our products and services
  • Manage and optimize internal operations purposes
  • Support and optimize channels and interactions
  • Share for all purposes from “purpose for collection”
G. Sensory Data or Recordings: For example, audio, electronic, visual, thermal, olfactory, or similar information that can be linked or associated with a particular consumer or household
  • To assess and manage risk
  • To meet regulatory or compliance requirements
  • Manage and Optimize Internal Business Operations
  • Support and Optimize Channels and Interaction
  • Share for all purposes from “purpose for collection”
H. Professional or Employment-Related Information: For example, compensation, evaluations, performance reviews, personnel files and current and past job history.
  • Assess and manage risk
  • Deliver, manage and support products and services, managing relationships and maintaining accounts
  • Meet legal, regulatory or compliance requirements
  • Share for all purposes from “purpose for collection”
I. Education Information (defined as information that is not publicly available personally identifiable information as defined in the Family Educational Rights and Privacy Act (20 U.S.C. section 1232g, 34 C.F.R. Part 99)): Education records directly related to a student maintained by an education institution or party acting on its behalf, for example, non-public information that can be used to distinguish or trace an individual’s identity in relation to an educational institution either directly or indirectly through linkages with other information.
  • N/A
  • N/A
J. Profile Data: For example, inferences drawn from personal information to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
  • Deliver, manage and support products and services, manage relationships and maintain accounts
  • Assess and manage risk
  • Manage fraud and financial crimes
  • Market our products and services
  • Manage and optimize internal operations purposes
  • Support and optimize channels and interactions
  • Share for all purposes from “purpose for collection”
 

We may also disclose personal information for other purposes at your direction or with your consent.

 

Sensitive Personal Information

 
Categories of Sensitive Personal Information Purpose for Collection Purpose for Disclosure
SSN, Driver’s License, State ID Card, Passport Number
  • Deliver, manage and support products and services manage relationships and maintain accounts
  • Assess and manage risk
  • Manage fraud and financial crimes
  • Meet legal, regulatory, or compliance requirements
  • Share for all purposes from “purpose for collection”
Account Login, financial account, debit or credit card number when provided with any security or access code, password or credentials allowing access to an account
  • Deliver, manage and support products and services manage relationships and maintain accounts
  • Assess and manage risk
  • Manage fraud and financial crimes
  • Meet legal, regulatory, or compliance requirements
  • Share for all purposes from “purpose for collection”
Contents of a consumer’s mail, email and text messages (unless LightStream is the intended recipient)
  • N/A
  • N/A
Genetic Data
  • N/A
  • N/A
Biometric information for the purpose of unique identification
  • Assess and manage risk (fraud and security detection through identity verification)
  • Share for all purposes from “purpose for collection”
 

What we Sell to Third Parties or Share with Third Parties for Cross-Context Behavioral Advertising and what we Share with Third Parties for Business Purposes

We have sold or shared with third parties for cross-context behavioral advertising personal information to third parties in the preceding 12 months as disclosed in the table below. We also share personal information for business purposes with the third parties described below.

General Personal Information
 
Categories sold to or shared with third parties over the last 12 months Categories of third parties to whom this category of personal information has been sold or shared Categories of Third Parties to whom the information was shared for business purposes
A. Identifiers:
  • Ad servers, networks, & exchanges
  • Social media platforms
  • Online publishers
  • Data analytics providers
  • Data providers and aggregators
  • Advertising services platforms
  • Market research companies
  • Consumer survey companies
  • Other entities in the Truist family
  • Service Providers that provide various services to us
  • Other parties when you authorize or direct us to share your information, such as when you use a third party service to help manage your financial information across financial institutions or when you transfer funds from LightStream
  • Credit reporting agencies to report on or learn about your financial circumstances
  • Government entities and other third parties as needed for legal or similar purposes
B. Personal Information Categories from Cal. Civ. Code § 1798.80(e)
  • N/A
  • Other entities in the Truist family
  • Service Providers that provide various services to us
  • Other parties when you authorize or direct us to share your information, such as when you use a third party service to help manage your financial information across financial institutions or when you transfer funds from LightStream
  • Credit reporting agencies to report on or learn about your financial circumstances
  • Government entities and other third parties as needed for legal or similar purposes
Characteristics of CA or Federal Protected Classifications
  • N/A
  • Other entities in the Truist family
  • Service Providers that provide various services to us
  • Other parties when you authorize or direct us to share your information, such as when you use a third party service to help manage your financial information across financial institutions or when you transfer funds from LightStream
  • Credit reporting agencies to report on or learn about your financial circumstances
  • Government entities and other third parties as needed for legal or similar purposes
D. Commercial Information
  • Ad servers, networks, & exchanges
  • Social media platforms
  • Online publishers
  • Data analytics providers
  • Data providers and aggregators
  • Advertising services platforms
  • Market research companies
  • Consumer survey companies
  • Other entities in the Truist family
  • Service Providers that provide various services to us
  • Other parties when you authorize or direct us to share your information, such as when you use a third party service to help manage your financial information across financial institutions or when you transfer funds from LightStream
  • Credit reporting agencies to report on or learn about your financial circumstances
  • Government entities and other third parties as needed for legal or similar purposes
E. Biometric Information
  • N/A
  • Other entities in the Truist family
  • Service Providers that provide various services to us
F. Internet or Other Similar Network Activity
  • Ad servers, networks, & exchanges
  • Social media platforms
  • Online publishers
  • Data analytics providers
  • Data providers and aggregators
  • Advertising services platforms
  • Market research companies
  • Consumer survey companies
  • Other entities in the Truist family
  • Service Providers that provide various services to us
  • Other parties when you authorize or direct us to share your information, such as when you use a third party service to help manage your financial information across financial institutions or when you transfer funds from LightStream
G. Professional or Employment-Related Information
  • Consumer survey companies
  • N/A
H. Profile Data
  • Ad servers, networks, & exchanges
  • Social media platforms
  • Online publishers
  • Data analytics providers
  • Data providers and aggregators
  • Advertising services platforms
  • Market research companies
  • Consumer survey companies
  • Service Providers that provide various services to us
 

Sensitive Personal Information

 
Categories sold to or shared with third parties over the last 12 months Categories of third parties to whom this category of personal information has been sold or shared Categories of third parties to whom the information was shared for business purposes
Social Security Number, Driver’s License, State Identification Card, or Passport Number
  • N/A
  • Other entities in the Truist family
  • Service Providers that provide various services to us
  • Other parties when you authorize or direct us to share your information
  • Credit reporting agencies to report on or learn about your financial circumstances
  • Government entities and other third parties as needed for legal or similar purposes
Account log-in, financial account, debit card, or credit card number when provided with any security or access code, password, or credentials allowing access to an account
  • N/A
  • Service Providers that provide various services to us
Contents of a consumer’s mail, email, and text messages (unless we are the intended recipient of the communication)
  • N/A
  • N/A
Genetic Data
  • N/A
  • N/A
Biometric information for the purpose of unique identification
  • N/A
  • Other entities in the Truist family
  • Service Providers that provide various services to us
 

Notice of Right to Opt Out of Sale/Sharing

You may at any time direct LightStream to stop selling or sharing your personal information, which is called the “Right to Opt Out.” Once you make an opt out request, LightStream will comply within 15 business days, and will wait at least 12 months before asking you to reauthorize sales or sharing.

You may exercise your Right to Opt Out of Sale/Sharing in the following ways:

To opt out of tags, cookies, pixels that collect information when you visit LightStream.com
  • Click Do Not Sell or Share My Personal Information to use the interactive form
To opt out of other personal information sold to or shared with third parties
  • Sign on to LightStream Online Portal/Account Services platform and go to Profile then Privacy & Preferences to opt out of sharing personal information
 

Notice of Right to Limit Use of Sensitive Personal Information

 

You have the right to limit our use and disclosure of your sensitive personal information collected by LightStream for the purpose of inferring characteristics about you. This is called the “Right to Limit”. LightStream only collects/processes sensitive personal information without the purpose of inferring characteristics about a consumer, therefore there is not an opt-out for the use of sensitive personal information.

You do not have the right to limit certain uses and disclosures of your sensitive personal information for the following business purposes:

 

Retention of Personal Information

LightStream has established product and business-level criteria for retention and disposal according to business requirements, laws, regulations, and applicable industry standards.

Sources of Personal Information

LightStream collects information from various sources, including:

 

Consumer Rights Under the CCPA

 
Right to Know / See Data Request

You have the right to request that LightStream disclose categories or specific pieces of personal information we have collected about you over the last 12 months, the categories of sources from which that information was collected, the business or commercial purpose(s) for which the information was collected, sold, or shared with third parties for cross context behavioral advertising, and the categories of third parties with whom we share personal information.

Right to Correct

You have the right to request correction of inaccurate personal information maintained by LightStream. Such updates are best made by logging into your online account or in the mobile app to make the corrections.

Right to Delete

You have the right to request deletion of personal information that LightStream has collected, subject to certain exceptions. For example, we may deny your request if retaining the information is necessary for us to complete a transaction you requested or comply with our legal obligations

Submitting a Verified Consumer Request

Consumers are welcome to submit right to know, correction, or deletion requests by visiting the Truist Privacy Center. LightStream is a division of Truist Bank and your requests made through the Truist Privacy Center will extend to other personal information Truist maintains about you. For example, if you ask to correct your phone number, we will modify the phone number across all Truist records where a correction can be made. Privacy preferences, such as email opt-outs or information sharing and use preferences, are managed separately. Information about LightStream’s privacy practices and how to manage your LightStream privacy preferences is available on this page (Lightstream.com/privacy).

If you need assistance completing the form or have any other questions or comments, you may email us at customerservice@lightstream.com. All requests must be verified prior to receiving a response, using Truist authentication protocols. Requesters will be asked to supply certain basic personal information to enable us to verify the request against our records, such as name, Social Security number, and address. Information submitted for verification purposes will only be used to verify the requestor’s identity and/or authority to make a request on another’s behalf.

Requests made on another person’s behalf can only be accepted upon receipt of documentation that the requestor is an authorized agent, parent, or legal guardian of the consumer whose information is being requested. This will require the submission of a valid Power of Attorney, Birth Certificate, approved LightStream authorization form, Guardianship Order, or other court order granting authority to receive information, as appropriate.

Upon submission of a request, consumers will receive an initial confirmation of receipt within 10 days. We will respond to your request within 45 days (unless an extension of up to 45 additional days is requested, upon which the consumer will receive notice and an explanation for the extension).

Opt Out Preference Signals

Your internet browser may give you more control over your privacy preferences via a Global Privacy Control (GPC) signal. This is a setting in your browser that notifies the websites you visit of your preferences to opt out of selling or sharing your personal information under California law. If you have opted out via the GPC signal, LightStream sites will recognize this signal and process your preference automatically as it pertains to tags, cookies and pixels that collect personal information when you visit LightStream.com. Please note the signal is processed at the browser-level and is not applied if you visit LightStream.com from a different browser or device that does not have the GPC signal enabled.

Non-Discrimination

The submission of any CCPA request will have no impact on the service and/or pricing you receive from LightStream. It will not result in any denial of goods or services, or different prices, rates or quality of goods or services, nor will it result in retaliation against an employee, applicant, or independent contractor.

Consumers Under 16 Years of Age

LightStream products and services are not intended for consumers under the age of 16, and we do not knowingly collect information from children under the age of 16 without consent. LightStream does not knowingly sell the personal information of minors under the age of 16 or share such information for cross-contextual advertising.

Updating Preferences

You can submit requests to update your sharing and marketing preferences by logging into your online account.

Updates

This Notice may be revised from time to time, so please review this page periodically. Any changes will become effective when we post the revised notice on the site (please note the effective date listed at the top of this page).

Contact Us

If you have any questions or comments on this notice or our privacy practices generally, please contact us at privacy@lightstream.com. You can also visit www.LightStream.com/privacy-security for additional information.

Overview

In today's environment, where people are subjected to marketing calls, junk mail, and spam and are very concerned about fraud and identity theft, we recognize the seriousness of our responsibility to help maintain the privacy and security of your personal information. As a result, we have adopted privacy and security practices that go beyond minimum legal requirements in order to give you greater comfort. We invite you to compare what we do with any other lender that you are presently using or considering.

Recognize and prevent scams
We take your security seriously. Protect yourself from fraudsters who reach out to you pretending to be LightStream. Always confirm the caller is from LightStream before sharing personal information.

We are a Norton Secure Site:

Norton Security Badge

For Nevada residents only, Nevada law requires that we also provide you with the following contact information:

Bureau of Consumer Protection, Office of the Nevada Attorney General
555 E. Washington St., Suite 3900
Las Vegas, NV 89101
Phone: 702.486.3132
Email: BCPINFO@ag.state.nv.us

We may modify this privacy and security policy from time to time. We will post such changes to this page and update the last revised date. If the changes to the policy are significant, we will provide a more prominent notice including, possibly, an email notification to you.

Privacy Policy

Rev. 03/2023

Printable PDF

FACTS WHAT DOES LIGHTSTREAM DO WITH YOUR PERSONAL INFORMATION?
Why? Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do.
What? The types of personal information we collect and share depend on the product or service you have with us. This information can include:
  • Social Security number and income
  • account balances and payment history
  • credit history and credit scores
How? All financial companies need to share customers' information to run their everyday business—to process transactions, maintain customer accounts, and report to credit bureaus. In the section below, we list the reasons financial companies can share their customers' personal information; the reasons LightStream chooses to share; and whether you can limit this sharing.
 
Reason we can share your personal information Does LightStream share? Can you limit this sharing?
For our everyday business purposes—
such as process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus
Yes No
For our marketing purposes—
to offer our products and services to you
Yes Yes (See below)
For joint marketing with other financial companies No We don't share
For our affiliates' everyday business purposes—
information about your transactions and experiences
Yes No
For our affiliates' everyday business purposes—
information about your creditworthiness
Yes Yes (See below)
For our affiliates to market to you Yes Yes (See below)
For nonaffiliates to market to you No We don't share
 
To limit our
sharing
  • LightStream customers, please go to Preferences in the customer service section of the LightStream web site to change your preferences to limit our sharing.
  • You may also email LightStream at privacy@lightstream.com
If you are a new customer, we can begin sharing information 30 days from the date you receive this notice. When you are no longer our customer, we may continue to share your information as described in this notice. However, you can contact us at any time to limit our sharing and to restrict telemarketing, direct marketing postal mail and email solicitations.
Questions?
 
Who we are
Who is providing this notice? LightStream, and its affiliates.
What we do
How does LightStream protect my personal information? To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings.

Our employees are bound by our Code of Ethics and policies to access consumer information only for legitimate business purposes and to keep information about you confidential.
How does LightStream collect my personal information? We collect your personal information, for example, when you
  • open an account or deposit money
  • pay your bills or apply for a loan
  • use your credit or debit card
We also collect your personal information from others, such as credit bureaus, affiliates, or other companies.
Why can't I limit all sharing? Federal law gives you the right to limit sharing only for
  • affiliates' everyday business purposes—information about your creditworthiness
  • affiliates to market to you
  • nonaffiliates to market to you
State laws and individual companies may give you additional rights to limit sharing.
What happens when I limit sharing for an account I hold jointly with someone else? Your choices will apply to everyone on your account—unless you tell us otherwise
 
Definitions
Affiliates Companies related by common ownership or control. They can be financial and nonfinancial companies. LightStream is a division of Truist Bank.
  • Our affiliates include companies with a Truist name; financial companies such as Sterling Capital Management LLC, GenSpring Holdings, Inc., Regional Acceptance Corporation, McGriff Insurance Services, Inc., MBT, Ltd., and GFO Advisory Services, LLC.
Nonaffiliates Companies not related by common ownership or control. They can be financial and nonfinancial companies.
  • LightStream does not share information with nonaffiliates so they can market to you.
Joint marketing A formal agreement between nonaffiliated financial companies that together market financial products or services to you.
  • LightStream does not have any joint marketing partners.
 
Other important information
State and Local Regulations: If, in addition to federal law, you are protected by specific state or local rules concerning information sharing and marketing, Truist will fully comply with these regulations as well. Under Vermont and California law, we will not share information we collect about you with companies outside of Truist Bank, unless the law allows. Nevada State law requires that we provide residents with the following contact information: Bureau of Consumer Protection, Office of the Nevada Attorney General, 555 E. Washington Street, Suite 3900, Las Vegas, NV 89101; Phone: 702.486.3132; Email: BCPINFO@ag.state.nv.us.
Use of Third Parties: We have arrangements with companies whose experience is essential for our own services to operate properly. These companies, some of which may be located outside the United States, work at LightStream's direction, only receive the information necessary to perform these functions, and adhere to LightStream’s data security guidelines.
Important Notice about Credit Reporting: We may report information about your account(s) to credit bureaus. Late payments, missed payments, or other defaults on your account(s) may be reflected in your credit report.
Do Not Call Policy. This notice is LightStream’s Do Not Call Policy under the Telephone Consumer Protection Act. LightStream abides by all federal and state regulations on telephone usage, maintains an internal Do Not Call list and makes no telemarketing calls to numbers on this list. All Do Not Call requests are implemented within 30 days and the selection is permanent - unless you elect to remove your number from the list.

Updated March 2023

LightStream has a longstanding commitment to protecting the confidentiality and security of our clients' personal information. We believe it is helpful to have an overview of how this commitment is applied as LightStream collects, uses, and protects your personal information when you visit us online.

For California residents, the California law requires that we provide consumers with advance notice of the types of personal information we collect from consumers, our intended use of such information, and a description of your privacy rights under California law. This includes rights to request disclosure of the types of personal information we have collected on you and your right to request that we delete certain information we have collected from you. Please see the CCPA Notice at Collection section of this Privacy page for further information on your specific consumer privacy rights.

This LightStream Statement of Online Privacy Practices (“Privacy Practices”) describes how we collect information when you visit or use our websites, mobile application, and other online services (“Online Services”) that link to this Privacy Policy. It also describes how we use and share such information and explains your privacy rights and choices.

LightStream’s business address is LightStream, PO Box 117320, Atlanta, GA, 30368-7320, USA. Our Customer Service Team may also be contacted via email at customerservice@lightstream.com.

What isn’t covered by this policy?


This Privacy Practices do not apply to the websites, mobile applications, or services of LightStream that do not directly link to this policy. It also does not apply to non-LightStream companies, such as third-party websites to which we link online. Please review the privacy policies of other websites and services you visit to understand their privacy practices.

Other important notices


Our Consumer Privacy Policy applies to information that we collect about individuals who seek, apply for, or obtain our financial products and services for personal, family, or household purposes. In addition, our CCPA Notice at Collection related to the California Consumer Privacy Act applies to certain information we collect about California residents.

What information do we collect?


When you visit the LightStream website, application, or otherwise interact with us online, we may collect the following information:

  • Your browser type (such as Google Chrome, Microsoft Edge, Apple Safari, Mozilla Firefox)
  • Your Internet Protocol or “IP” address (Your IP address is a number that is automatically assigned to your device by your Internet Service Provider. An IP address is identified and logged automatically whenever you visit a site, along with the time of the visit and the page(s) that were visited.)
  • The presence of any software on your device that may be necessary to view our site
  • Configuration information about the device you are using, including, but not limited to, your device type, web browser type and version, operating system type and version, display/screen settings, and language preferences
  • Information from your mobile device, such as contacts, photos (for example, to deposit checks or capture receipts), mobile network information, and cross-device IDs
  • Personal information submitted on applications, forms, and onsite electronic messaging. Types of personal information typically include:
    • Name
    • Social Security number
    • Driver’s license number or other government-issued ID
    • Address
    • Email
    • Telephone number
    • Account numbers and account information
    • Usernames
    • Passwords and other authentication information like PINs, security questions, and other secure sign-on methods1
    • Other non-public information, including credit and income information
  • Website analytics information such as pages visited and average time spent on a particular page
    • If you would prefer that your movements and actions online at lightstream.com not be monitored, you can opt-out of tracking.
      • NOTE: It is necessary to install a cookie on your browser to identify that you have opted-out. If you delete the opt-out cookie, or change devices or web browsers, you will need to opt-out again.
  • Search engine traffic referral information
  • Responses to advertisements and promotions
  • Transactional information from behind the secure login about your relationship with us (such as types of accounts or the state in which you bank)


1About biometric-enabled sign-ons: Your device stores the information it needs to recognize your facial features or fingerprints. The LightStream Mobile App uses your device’s functionality to obtain a signal that your device recognizes your facial features or fingerprints when you sign on. LightStream does not have access to the information your device uses to enable facial or fingerprint recognition, nor do we have access to or store your facial image or fingerprint data. You can always turn off facial or fingerprint recognition and go back to inputting user ID and password at any time. Your device’s user information will have additional information regarding its user controls and settings, including its privacy and security controls.


How does LightStream use collected information?


The information we collect online helps us to:

  • Effectively manage your account:
    • Ensure your identity and protect the security of your personal and account information from unauthorized access
    • Process transactions on your account
    • Respond to product applications and questions
    • Fulfill regulatory requirements
  • Fulfill regulatory requirements
  • Analyze our site usage and enhance the user's experience:
    • Diagnose server problems
    • Alert users of any possible software compatibility issues
    • Help us make decisions about how various technologies are used and identify usage trends
  • Send marketing communications:
    • Present personalized or targeted offers, ads, or content we believe may be of interest to you
    • Determine the effectiveness of promotional campaigns
  • Make business decisions:
    • Analyze data and credit risk
    • Perform market research
    • Conduct audits
    • Develop and improve products and services
  • Carry out other day-to-day business operations, such as to comply with applicable laws; share with our affiliates and subsidiaries; disclose to contractors, business partners, and other third parties under specific contracts and agreements; perform compliance activities; conduct credit reporting activities; and engage in human resources activities
  • Prevent and detect fraud
  • Protect against risks to security:
    • Monitor network activity logs
    • Detect security incidents and conduct data security investigations
    • Protect against malicious, deceptive, fraudulent, or illegal activity

We only use personal information that we have about you when we have a legal basis to use such personal information under applicable data protection laws.

How does LightStream share collected information?


LightStream shares your information in different ways as permitted and required by law. For example, we may share your information with:

  • Affiliates and other entities in the LightStream family
  • Businesses with which we partner to offer products and services for our clients or prospective customers, such as joint marketing partners or bill pay partners
  • Service providers that provide various services to us, such as those we use to help detect and prevent fraud, improve our online services, and to better market and advertise our services to you
  • Credit reporting agencies to report on or learn about your financial circumstances and as permitted by law
  • Government entities and other third parties as needed for legal or similar purposes, such as:
    • To respond to requests from our regulators
    • To respond to a warrant, subpoena, governmental audit or investigation, law enforcement request, legal order, or other legal process
    • To facilitate a merger, acquisition, sale, bankruptcy, or other disposition of some or all of our assets
    • To exercise or defend legal claims

Please see the Privacy Policy section of this Privacy page for more information on how we may share your personal information and how you may be able to limit certain types of sharing.

Please note, we may also share aggregated and de-identified data, such as aggregated statistics regarding product usage, with third parties.

We reserve the right to transfer personal information we have about you in the event we sell or transfer all or a portion of our business or assets (including, without limitation, in the event of a reorganization, dissolution, or liquidation).

What if I’m visiting the LightStream website from outside the United States?


Our Online Services are intended for a U.S. audience. If you are visiting the LightStream website, please be aware that your personal information may be transferred to, or stored and processed in, the United States. We will rely on legally provided mechanisms (for example, derogations such as performance of a contract) to lawfully transfer personal data across borders.

How long does LightStream retain records?


We store your personal information as long as it is required to meet our contractual and legal obligations, or if we have a legitimate business need to do so.

What technologies does LightStream use?


LightStream and its online advertising and marketing partners may employ various technologies to collect information, including:

  • Cookies – Cookies are pieces of information stored directly on your device. Cookies provide information that is used for security purposes, to facilitate navigation, to display information more effectively, and to personalize/customize your online experience. The cookies LightStream uses do not collect or store any personally identifiable information about you. LightStream uses persistent cookies to learn how visitors use our site, such as which pages are viewed the most, to identify the most common navigation paths, or to customize the presentation of information on the site. LightStream also uses session cookies to assist in delivering some online transactions, like online banking. Session cookies are no longer active after you log off the service that initiated them, and all session cookies are automatically deleted when you close all browser windows. LightStream may also contract with third parties, including, but not limited to, Adobe (see Cross-Device Tracking, below), to track user activity on our website. You can choose to block or disable these cookies as most devices and browsers offer their own privacy settings. Doing so, however, may result in diminished performance on our site.
  • Marketing pixels, web beacons, clear GIFs, or other technologies – This technology may be placed on certain pages of our website, applications, emails, and other marketing initiatives. These tags usually work in conjunction with cookies and allow us to measure the effectiveness of our site and compile statistics about usage and response rates.
  • Software Development Kits (SDKs) – Our mobile applications may include third-party SDKs that allow us and our service providers to collect information about your mobile app activity. In addition, some mobile devices come with a resettable advertising ID (such as Apple’s IDFA and Google’s Advertising ID) that, like cookies and pixel tags, may allow us and our service providers to identify your mobile device over time for advertising purposes in compliance with applicable app store consent rules.
  • Advertising and Cross-Device Tracking – LightStream uses certain Adobe Analytics services and products, which help companies build websites, applications, and advertisements that seamlessly flow between all your devices (such as a desktop, laptop, tablet, phone, or smart watch). The Adobe services recognize which of your devices are linked through use of technology that includes cookies and your IP address (without collecting your sensitive personal information). Visit the Adobe website for more information on opting out of certain services, cross-device tracking, and/or to unlink your devices. NOTE: Adobe needs to install a cookie on your browser to identify that you have opted out. If you delete the opt-out cookie, or change devices or web browsers, you will need to opt out again.
  • Firewalls, passcodes, data encryption, and other safety features – LightStream uses these technologies to ensure that the information you provide us remains secure. To learn more about how we safeguard your information online please go to the Security Policy section of this Privacy page.
  • Third-party plugins – Other companies may have plugins that appear on certain pages of our website or applications. Some of these, for example, may be from social media companies (for example, the Facebook “Like” button). These plugins may collect information, such as information about the pages you visit, and share it with the company that created the plugin even if you do not click on the plugin. These third-party plugins and the way they operate are governed by the privacy policies and terms of the companies that created them.

How does LightStream interact with me online?


Online advertising on LightStream website and application


LightStream advertises its products and services on pages within our sites and on mobile applications. To make the content and advertising as informative and useful as possible, LightStream may target and personalize content and advertisements for products and services on our site.

Online advertising on third-party websites and applications


LightStream advertises its products and services on websites and applications not affiliated with LightStream. The third-party companies we hire to display these ads use their own tracking technologies to measure the effectiveness of these ads and to understand your interests. Many of our third-party partners have their own privacy policies. We encourage you to review these policies carefully.

Some of our third-party advertising is interest-based and may use information about your online interests to customize the online ads you see. Many ad platforms have adopted the use of the AdChoices Icon for our interest-based advertising (excluding ads appearing on platforms that do not accept the icon). Anyone receiving an interest-based ad can click on the displayed icon to receive more information. The AdChoices Icon does not prevent you from receiving advertisements; instead, it allows you to control whether you receive interest-based advertisements and from which companies. Visit the Digital Advertising Alliance website for more information about the AdChoices Icon and interest-based advertising. If you would like to know more about how to opt out with your specific browser and device, you may visit the DAA Webchoices Browser Check and NAI Opt Out of Interest-Based Advertising tools for additional options. You can also download the AppChoices app to opt out in mobile apps.

Third-party aggregation services and tools


Aggregation allows you to gather information from many websites and view that information in a consolidated format. An example of why you might use a third-party aggregation tool is if you wanted a comprehensive view of assets and liabilities held within your financial accounts. If you provide information about your LightStream accounts (including your access information) to an aggregation service provider, we will consider that as your having authorized all transactions initiated by that aggregation site. LightStream reserves the right to disable aggregation for any account without notice. If you wish to cancel your third-party aggregation services, you should also change your password at LightStream.com.

Social Media


LightStream provides experiences on social media platforms such as Facebook, Instagram, LinkedIn, or Twitter that enable online sharing and collaboration. We use social media to facilitate social engagement and sharing, when such sharing is appropriate and safe. Please note, any content you post, such as pictures, information, opinions, or any personal information that you make available to other participants on these social platforms, is subject to the terms of use and privacy policies of those platforms. Please refer to them to better understand your rights and obligations with regard to such content.

Given the very public nature of social media, it is critical that we all safeguard confidential financial information. If you post information on a LightStream site that we feel should be shielded from public view, we will remove it. This includes not only specific details about your LightStream accounts and other private, confidential information (such as your Social Security number), but details of information relayed in private conversations between you and LightStream representatives. Please know that in taking down or editing your posts, we are focusing our experience and best judgment to keep your personal information safe.

Email


Email transmitted across the internet is normally not protected and may be intercepted and viewed by others. Therefore, you should refrain from sending any confidential or private information via unsecured email to LightStream. We'll never ask you to send confidential information to us via email, such as your logon ID, password, full account numbers, or Social Security number.

Occasionally, we will retain the content of your email—and our replies—to confirm proper responses to your questions and requests, to comply with legal and regulatory requirements, and to ensure that we consistently deliver an enjoyable client experience to you.

Linking to other sites


LightStream may provide links to non-LightStream companies, such as credit bureaus or merchants, and will notify you when leaving the LightStream site. If you choose to link to websites not controlled by LightStream, we are not responsible for the privacy or security of these sites, including the accuracy, completeness, reliability or suitability of their information. If you are asked to provide information on one of these sites, we urge you to carefully study their privacy policies before sharing.

Control your online and other privacy preferences


In summary, the following links can help you to customize and control your privacy preferences when interacting with LightStream online:

  • If you are a current LightStream customer, you can control your marketing preferences for direct mail, email, and telemarketing preferences, along with the sharing of your personal information via our Preferences page. You may also email LightStream at privacy@lightstream.com.
  • Do Not Track and Global Privacy Control
    • We will respond to the Global Privacy Control signal as explained further in our CCPA Notice at Collection. At this time, we do not currently respond to other browser “do not track” signals or other mechanisms that allow you to tell websites you do not want to have online activities tracked.

Protecting your children


LightStream strictly follows the federal guidelines of the Children’s Online Privacy Protection Act (COPPA), which gives parents control over what type of information is collected online about their children. We do not knowingly collect, maintain, or use personally identifiable information from children under age 13 on our websites. We are not responsible for the data collection and use practices of nonaffiliated third parties that are linked from our websites. Visit the Federal Trade Commission’s COPPA Website for more information.

How does LightStream protect me from fraud and secure my information?


To protect personal information from unauthorized access and use, we use security measures that comply with applicable federal and state laws. These measures may include device safeguards and secured files and buildings as well as oversight of our third-party service providers to ensure information remains confidential and secure.

How can I make sure my information is accurate and use my individual rights?


Keeping your account information accurate and up to date is very important. If your account information is incomplete, inaccurate or not current, please login to your online account and make appropriate updates. If you need help logging into your online account, please contact us at customerservice@lightstream.com.

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws. We will ask you to verify your identity to help us respond efficiently to your request.

Under non-U.S. data protection laws, you may have the right to complain to a data protection authority about our collection and use of your personal information.

What is LightStream’s cellular phone identity verification statement?


You authorize your wireless carrier to use or disclose information about your account and your wireless device, if available, to us or our service provider for the duration of your business relationship, solely to help them identify you or your wireless device and to prevent fraud. LightStream’s Statement of Online Privacy Practices and Privacy Policy detail how we treat your data.

How will LightStream notify me about online privacy practices updates?


LightStream’s Online Privacy Practices may be revised from time to time, so please review them periodically. Any changes will become effective when we post the revised Practices on the site (Please note the effective date listed at the top of this page). If we revise our Online Privacy Practices in a material way, we will provide a conspicuous notice on our website when any changes take effect.

Our Security Practices

With regard to the security of your personal information, we employ a variety of electronic, physical, and procedural safeguards to protect your personal information including:

Encryption - We employ 128-bit Secure Sockets Layer (SSL) technology to encrypt your personal information when it is in transit between your web browser and our web server or vice versa. In addition, we also use advanced encryption when storing or backing up your personal information on our computers, substantially reducing the risk even in the event of loss or misuse of your personal information.

Software and Hardware Security - We employ stringent, up-to-date software and hardware solutions to minimize the risk that your encrypted, personal information could be hacked, lost, or stolen from our computer systems.

Physical Security - Your encrypted, personal information is located and stored in secure areas within our building and any offsite data processing facilities.

Access - Access to your personal information (either physically or online) is limited to you and our employees who have a "need to know" in order to perform their jobs and who have the appropriate authentications such as key cards, user IDs, and passwords. A user ID and password is required on the Sign In page on our web site for you to access and/or update your account information. Please remember to keep your user id and password secure. Also, if you prefer additional security, we offer our AccountLock feature which will prevent access to your account even with a valid user id and password. Access will only be granted after you request a pass code from us. We will then email you a randomly-generated, temporarily available pass code, allowing you one-time access to your account.

Training - We provide training to our employees regarding our security procedures.