Privacy Policy

Effective Date: November 1, 2023

  1. About This Policy

    This Privacy Policy (the “Policy”) describes the information Yepzy, Inc. collects about you, how we use and share that information, and the privacy choices we offer. This Policy applies to information we collect when you register for Yepzy, access or use our website, mobile applications, products, and services (collectively, the "Services"), or when you otherwise interact with us. This includes information we collect when you access or use the mobile application operated by Yepzy to view, manage, or conduct transactions on the Yepzy deposit account (“Yepzy Financial Account”) or the Yepzy Debit Visa® (“Yepzy Card”), both of which are made available by Thread Bank (“Thread”) on behalf of Yepzy. However, it does not apply to the Yepzy Financial Account or Yepzy Card themselves. Please refer to the Yepzy Deposit Account Agreement for information concerning those products and your privacy rights with respect to those products. The terms Yepzy,” “we,” “us,” or our” mean Yepzy, Inc. You” or your” means an individual who visits or uses our Services. The term "Site" includes (1) all websites and all devices or mobile applications operated by Yepzy that collect PII from you and that link to this Privacy Policy; (2) pages within each such website, device, or mobile application, any equivalent, mirror, replacement, substitute, or backup website, device, or mobile application; and (3) all pages that within each such website, device, or mobile application.

  2. Things We Collect and Disclose

    Yepzy collects personally identifiable information (PII) about you for a variety of purposes. During the past 12 months, we have collected the following categories of PII from individuals:

    • PII, such as a full name, postal address, email address, online usernames and passwords for third-party sites and internet services, date birth social security number, drivers license number, or other similar identifiers.
    • Internet or other network activity information, such as information regarding how individuals interact with the Site, emails, or marketing materials.
    • Professional or employment-related information.
    • Commercial information, such as products or services purchased, obtained, used, or transactional data.
    • Inferences based on information about an individual to create a summary about, for example, an individuals preferences and characteristics.
    • Bank account and debit card information, such as account numbers, card numbers, and transaction histories.

    During the past 12 months, we have also disclosed the categories of PII listed above for our business purposes. We have not, however, sold PII to third parties. We may also collect information about you from mailing list providers, publicly available sources, identification verification services, and other third parties.

    2.1 Third-Party Credentials, Account Numbers, and Other Account Information

    When you use certain Services, we may collect from you: usernames, passwords, account numbers, and other account information for third-party websites and Internet banking services (Third-Party Sites”). We also collect account information from you when you open a Yepzy Financial Account and obtain a Yepzy Card through our mobile application. This information is used to obtain your account, transaction, and other banking information from the relevant financial institution on your behalf in order to display the information to you or to fulfill your requests for certain products, services, or transactions through a Service. We use third-party service providers, such as Plaid Inc. (Plaid”), Thread Bank (“Thread”), Unit.co Inc. (Unit”), and Twilio, Inc. (“Twilio”) to obtain this information. By using our Services, you grant Yepzy, Thread, Plaid, Unit, and Twilio the right, power, and authority to act on your behalf to access and transmit this information from the relevant financial institution, including from Thread for the Yepzy Financial Account and Yepzy Card. With respect to Plaid, you agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with Plaid's privacy policy. With respect to Unit, you agree to your personal and financial information being transferred, stored, and processed by Unit in accordance with Unit's privacy policy. With respect to Twilio, you agree to your personal and financial information being transferred, stored, and processed by Unit in accordance with Twilio's privacy policy. With respect to Thread, you agree to your personal and financial information being transferred, stored, and processed by Unit in accordance with Thread's privacy policy.

    2.2 Information Collected by Cookies and Web Beacons

    We use various technologies to collect information, and this may include sending cookies to your computer or mobile device. Cookies are small data files that are stored on your hard drive or in device memory by a website. Among other things, cookies support the integrity of our registration process, retain your preferences and account settings, and help evaluate and compile aggregated statistics about user activity. We may also collect information using web beacons. Web beacons are electronic images that may be used in our Services or emails. We may use web beacons to deliver cookies, count visits, understand usage, and determine whether an email has been opened and acted upon.

    2.3 Technical and Navigational Information

    We may collect your computer browser type, Internet protocol address, pages visited, and average time spent on our Site. This information may be used, for example, to alert you to software compatibility issues, or it may be analyzed to improve our web design and functionality.

    2.4 Device Data

    When you use our mobile applications or the mobile versions of our Site, we may collect the following device information:

    • Device-centered Data - Data tied to proper information about linguistic, cultural, and technological conventions for use in formatting data for presentation (calendar type, keyboard language, etc.)
    • Locale - Information pertaining to the user's locale (for example: calendar type used, language used in keyboard, etc.).
    • Accessibility - Active accessibility settings.
    • Device Motion - Device motion data, such as acceleration and gyroscope.
    • Accelerometer - Measures how fast your phone moves & in what direction it points.
    • Magnetometer - Measures magnetic fields, and is often used (for example) to detect which way "North" is in mapping applications.

    The data above allow app developers, and others to uniquely identify your device for purposes of storing application preferences and for your security.

  3. How We Use Your Information

    We may use the information you provide about yourself and about your Yepzy Financial Account, Yepzy Card, or Third-Party Sites to fulfill your requests for our products, programs, and Services, to respond to your inquiries about our Services, and to offer you other products, programs, or services that we believe may be of interest to you. We may use your information to complete transactions you request, to verify the existence and condition of your accounts, or to assist with a transaction. For example, we may use the account information you provide or that we collect from Third-Party Sites to confirm your accounts are valid and to access funds from your accounts in connection with fulfillment of the Services. We may use your information to improve and personalize the Services. For example, we may use your information to pre-fill form fields on the Sites for your convenience.

  4. How We Share Your Information


    We may share PII about you as follows:

    • With third parties to provide, maintain, service and improve our Services.
    • To process transactions that you authorize or to fulfill your requests.
    • With participating merchants to determine if you are eligible to receive rewards or promotions.
    • In connection with, or during the negotiation of, any merger, sale of company stock or assets, financing, acquisition, divestiture, or dissolution of all or a portion of our business.
    • To respond to subpoenas, court orders, or legal process.
    • In order to investigate, prevent, defend against, or take other action regarding violations of our Terms of Use, illegal activities, suspected fraud, or situations involving potential threats to the legal rights or physical safety of any person or the security of our network, Sites or Services.
    • the legal rights or physical safety of any person or the security of our network, Sites or Services.
    • To respond to claims that any posting or other content violates the rights of third parties.
    • In an emergency, to protect the health and safety of our Sites' users or the general public.
    • As otherwise required by law.
  5. How We Secure Your Information


    We take your privacy and the security of your information very seriously, and have an information security program that includes administrative, technical, and physical measures to protect your information. We hold ourselves responsible for the security of cardholder data we possess or otherwise store, process, or transmit on your behalf, or to the extent that we could impact the security of your cardholder data environment. Yepzy will maintain all applicable PCI DSS requirements to the extent we handle, have access to, or otherwise store, process, or transmit the customer's cardholder data or sensitive authentication data, or manage the customer's cardholder data environment on behalf of a customer. Examples of measures we have taken to protect your information include, but are not limited to:

    • The use of industry standard encryption while transmitting and storing PII.
    • Mobile application session timeouts to ensure your PII is protected when you put down your device without logging out.
    • We implement appropriate security controls to protect PII from unauthorized access, use, disclosure, modification, or destruction. These controls may include encryption, access control, and intrusion detection and prevention systems.
    • We restrict access to PII to authorized personnel on a need-to-know basis. This may involve using role-based access control and least privilege principles.
    • We monitor systems and environments for unauthorized access to PII.
    • Passwords and personal identification numbers (PINs”) are only known by you. No employee, contractor or Third-Party Site has access to your Yepzy password or PIN. We will never ask for your password or PIN through our customer service teams.
    • Two-factor authentication is provided to ensure your account can only be accessed by the device you register with.
    • Our systems are periodically audited for security flaws.
    • Our retention policy for PII will comply with Bank Secrecy Act (BSA)/ Anti-Money Laundering (AML) regulations after the customer account is closed or dormant.

  6. Note On Communication

    We may provide you with information and summaries of your accounts and Services through email, SMS and mobile notifications. We may also allow you to subscribe to email newsletters and from time to time may transmit emails to you promoting Yepzy or third-party goods or services. Subscribers have the ability to opt out of receiving our promotional emails and to terminate their newsletter subscriptions by following the instructions in the emails. Opting out in this manner will not end transmission of service-related emails, such as information and summaries of your accounts and Services.
  1. How To Update Your Information

    If you wish to access PII that you have submitted to us or to request the correction of any inaccurate information you have submitted to us, you may correct certain information through our Site. Alternatively, you can send an email that includes your contact information to WeCare@yepzy.com to request any corrections to your PII. You may also email us if you wish to deactivate your Services, but even after you deactivate your Services, we may retain archived copies of information about you for a period of time that is consistent with applicable law.
  1. California Privacy Rights

    The California Consumer Privacy Act (CCPA”) allows California residents, upon a verifiable consumer request and subject to applicable exemptions, to request that we give you access, in a portable and (if technically feasible) readily usable form, to the specific pieces and categories of PII that we have collected about you, the categories of sources for that information, the business or commercial purposes for collecting the information, and the categories of third parties with which the information was shared. California residents also have the right to submit a request for deletion of information under certain circumstances. Yepzy will not discriminate against you for exercising your rights, such as by denying you services, charging you different prices for services, or providing you a different level or quality of services. Please note that you must verify your identity and request before further action will be taken. As part of this process, we may require you to provide government identification. Consistent with California law, you may designate an authorized agent to make a request on your behalf. In order to designate an authorized agent to make a request on your behalf, you must provide a valid power of attorney, the requesters valid government issued identification, and the authorized agents valid government issued identification.We do not sell your PII to third parties. We do, however, share PII with third parties for the business purposes described in this Policy.California law also permits our customers who are California residents to request and obtain from us once a year, free of charge, information about the PII (if any) we disclosed to third parties for direct marketing purposes in the preceding calendar year.If you are a California resident and would like to exercise your data protection rights, where applicable, you can submit a request using our online form (available here) or contact us through Yepzys Mobile App or WeCare@yepzy.com.We will consider all requests and provide our response within a reasonable period of time (and within any time period required by applicable law). Please note, however, that certain information may be exempt from such requests, for example, if we need to keep the information to comply with our own legal obligations or to establish, exercise, or defend legal claims. Here is a summary of the CCPA-related categories of PII we may have collected about you over the past 12 months as well as how we use it and with whom we may have shared it.

    Categories of PII we collect:

    How we use PII:

    Parties with whom your information may be shared:

Personal identifiers

Financial information

Contact information

Transaction information

Geolocation information

Device information

Internet or other electronic network activity information

Professional or employment related information

Bank account and debit card information

Commercial information, such as products or services purchased, obtained, or used

Identity verification

Compliance, risk, and fraud detection

Providing, personalizing, and improving our products

To fulfill your requests for certain products, services, or transactions

Contacting you to resolve disputes and help with our Services

Conducting investigations, complying with and enforcing any applicable laws, regulations, legal requirements, and industry standards

Responding to lawful requests for information

To perform other business purposes

Affiliate partners

Issuing financial institutions

Payment networks

Payment card associations

Service providers to facilitate:

Bank account aggregation

Fraud detection

Identity verification

Payment processing

Card issuing services

Law enforcement or other third parties in response to a legal request

  1. How We Update Our Privacy Policy

    We reserve the right, at our discretion, to make changes to this Policy from time to time, so please review it frequently. You may review updates to our Terms of Use and Privacy Policy at any time via links on www.Yepzy.com. You agree to accept electronic communications and/or postings of revised versions of this Policy on www.Yepzy.com and agree that such electronic communications or postings constitute notice to you of the revised version of this Policy. Changes take effect immediately upon posting.

  2. Everything make sense?

    If you have questions or concerns regarding this Policy, or if you have any questions or suggestions, please contact WeCare@yepzy.com.

    Federal Privacy Notice

FACTS

WHAT DOES Yepzy, Inc. (Yepzy”) DO WITH YOUR PII?

Why?

Financial companies choose how they share your PII. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your PII. Please read this notice carefully to understand what we do.

What?

The types of PII we collect and share depend on the product or service you have with us. This information can include:

Social Security number (when applicable)

Employment information and income

Account balances

Account transactions and transaction history

Checking account information

How?

All financial companies need to share customers PII to run their everyday business. In the section below, we list the reasons financial companies can share their customersPII; the reason Yepzy chooses to share; and whether you can limit this sharing.

 

Reasons we can share your PII

Does Yepzy share?

Can you limit this sharing?

For our everyday business purposes – such as to process your transactions, maintain your account(s), respond to court orders and legal investigations

Yes

No

For our marketing purposes– to offer our products and services to you

Yes

No

For joint marketing with other financial companies

Yes

No

For our affiliates' everyday business purposes –information about your transactions and experiences

Yes

No

For our affiliates to market to you

Yes

Yes

For nonaffiliates to market to you

No

Yes

 

 

To limit our sharing

Email us at WeCare@yepzy.com

Please note:

If you are a new customer, we can begin sharing your information 30 days from the date you sent this notice. When you are no longer our customer, we continue to share your information as described in this notice.

However, you can contact us at any time to limit our sharing.

Questions?

Email us at WeCare@yepzy.com

Who we are

 

Who is providing this notice?

Yepzy is providing this privacy policy and it applies to all products and services made and offered by the company.

 

What we do

 

How does Yepzy protect my PII?

To protect your PII from unauthorized access and use, we use security measures that comply with industry standards. These measures include computer safeguards and secured files and buildings.

How does Yepzy collect my PII?

We collect your PII, for example, when you

Apply for services and accounts

Give us your income information

Tell us where to send money

Provide account information

Provide employment information

 

Why can't I limit all sharing?

Federal law gives you the right to limit sharing only for:

affiliates from using your information to market to you

sharing for nonaffiliates to market to you

for joint marketing with other financial companies

State laws and individual companies may give you additional rights to limit sharing. See below for more on your rights under state law.

What happens when I limit sharing for an account I hold jointly with someone else?

Your choices will apply to everyone on your account.

Definitions

 

Affiliates

Companies related by common ownership or control. They can be financial and nonfinancial companies.

Yepzy, Inc

Nonaffiliates

Companies not related by common ownership or control. They can be financial and nonfinancial companies.

Nonaffiliates we share with can include consumer loan brokers, lenders and direct marketing companies.

Joint marketing

A formal agreement between nonaffiliated financial companies that together market financial products or services to you.

Our joint marketing partners can include institutions such as consumer lenders or marketers