Your Consumer Rights
Firefighters First Credit Union is committed to protecting consumers’ privacy. The California Consumer Privacy Act (CCPA) creates new consumer rights relating to the access to, deletion of, and sharing of personal information that is collected by businesses. Firefighters First Credit Union is not responsible for data entry errors.
Last Updated and Effective: 12/13/2022
I. CATEGORIES OF PERSONAL OF INFORMATION WE COLLECT
In the preceding 12-months, we have collected the following categories of personal information (please note that some categories overlap):
|A. Identifiers||A real name or alias; postal address; signature; home phone number or mobile phone number; member number, credit card number, debit card number, or other financial information; physical characteristics or description; email address; account name; Social Security number; date of birth, driver's license number or state identification card number; passport number; or other similar identifiers.|
|B. Protected classification characteristics under state or federal law||Age, race, ancestry, national origin, citizenship, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status.|
|C. Commercial information||Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.|
|D. Biometric information||Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information.|
|E. Internet or other similar network activity||Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.|
|F. Geolocation data||Physical location or movements. For example, city, state, country, and ZIP code associated with your IP address or derived through Wi-Fi triangulation; and, with your permission in accordance with your mobile device settings, and precise geolocation information from GPS-based functionality on your mobile devices.|
|G. Sensory data||Audio, electronic, visual, or similar information.|
|H. Professional or employment-related information.||Current or past job history, and salary.|
|I. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g, 34 C.F.R. Part 99)).||Educational records directly related to a class roster or student identification card, college or university, major (course of study), and graduation date.|
|J. Inferences drawn from other personal information.||Profile reflecting a person’s preference, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.|
II. CATEGORIES OF SOURCES OF INFORMATION WE COLLECT
We obtain the categories of personal information listed above from one or more of the following categories of sources:
a. From You or Your Authorized Agent
We may collect information directly from you or your authorized agent. For example, when you provide us your name and Social Security number to open an account and become a member. We also collect information indirectly from you or your authorized agent. For example, through information we collect from our members in the course of providing services to them.
b. From Our Website and Applications That You Access on Your Mobile Device
We collect certain information from your activity on our website, www.firefightersfirstcu.org, and your use of Firefighters First CU applications, such as the Firefighters First CU Mobile Banking app on your mobile device. We may collect your IP address, device and advertising identifiers, browser type, operating system, the date and time of your visit, information about the links you click and pages you view on our website, and other standard server log information. Geolocation information can be monitored on a continuous basis in the background only while the feature(s) are being used or not at all, depending on the end user's selection. The end user can change their location permissions at any time in their device settings. This information may be collected when you use certain services that are dependent on your mobile device's location ( such as the location of an ATM or in store transactions).
i. The Role of Cookies and Other Online Tracking Technologies
“Cookies” are small amounts of data a website can send to a visitor’s web browser. They are often stored on the device you are using to help track your areas of interest. Cookies may also enable us or our service providers and other companies we work with to relate your use of our online services over time to customize your experience. Most web browsers allow you to adjust your browser settings to decline or delete cookies, but doing so may degrade your experience with our online services.
Clear GIFs, pixel tags or web beacons—which are typically one-pixel, transparent images located on a webpage or in an email or other message—or similar technologies may be used on our sites and in some of our digital communications (such as email or other marketing messages). They may also be used when you are served advertisements, or you otherwise interact with advertisements outside of our online services. These are principally used to help recognize users, assess traffic patterns and measure site or campaign engagement.
Local Shared Objects, sometimes referred to as “flash cookies” may be stored on your hard drive using a media player or other software installed on your device. Local Shared Objects are similar to cookies in terms of their operation but may not be managed in your browser in the same way. For more information on managing Local Shared Objects, click here.
“First party” cookies are stored by the domain (website) you are vising directly. They allow the website’s owner to collect analytics data, remember language settings, and perform useful functions that help provide a good experience. “Third-party” cookies are created by domains other than the one you are visiting directly, hence the name third-party. They may be used for cross-site tracking, retargeting and ad-serving. We also believe that cookies fall into the following general categories:
- Essential Cookies: These cookies are technically necessary to provide website functionality. They are a website’s basic form of memory, used to store the preferences selected by a user on a given site. As the name implies, they are essential to a website’s functionality and cannot be disabled by users. For example, an essential cookie may be used to prevent users from having to log in each time they visit a new page in the same session.
- Performance and Function Cookies: These cookies are used to enhance the performance and functionality of a website, but are not essential to its use. However, without these cookies, certain functions (like videos) may become unavailable.
- Analytics and Customization Cookies: Analytics and customization cookies track user activity, so that website owners can better understand how their site is being accessed and used.
- Advertising Cookies: Advertising cookies are used to customize a user’s ad experience on a website. Using the data collected from these cookies, websites can prevent the same ad from appearing again and again, remember user ad preferences, and tailor which ads appear based on a user’s online activities.
ii. Online Advertising & Online Behavioral Advertising
You will see advertisements when you use many of our online services. These advertisements may be for our own products or services (including pre-screened offers of credit) or for products and services offered by third parties. Which advertisements you see is often determined using the information we or our affiliates, service providers and other companies that we work with have about you, including information about your relationships with us (e.g., types of accounts held, transactional information, location of banking activity). To that end, where permitted by applicable law, we may share with others the information we collect from and about you.
Online behavioral advertising (also known as “OBA” or “interest-based advertising”) refers to the practice of collecting information from a computer or device regarding a visitor’s web-browsing activities across non-affiliated websites over time in order to deliver advertisements that may be of interest to that visitor based on their browsing history.
We do not engage in OBA.
c. Third-party service providers in connection with our services or our business purposes
We collect information from third-party service providers that interact with us in connection with the services we perform or for our operational purposes. For example, a credit report we obtain from a credit bureau to evaluate a loan application. Another example is a third-party service provider that provides us information to help us detect security incidents and fraudulent activity.
d. Information we collect from third-parties for a commercial purpose
e. Google Analytics
We use Google Analytics to understand how visitors engage with our website. For information on how Google uses the data it collects and how to control the information sent to Google please visit: Google's Privacy Terms
III. HOW WE USE YOUR PERSONAL INFORMATION
We may use or disclose personal information we collect for one or more of the following operational or other notified purpose (“business purpose”):
- To fulfill or meet the reason for which the information is provided. For example, you apply for a loan, and we use the information in your loan application to give you the loan.
- To provide you with information, products or services that you request from us.
- To provide you with email alerts, event registrations or other notices concerning our products or services, or events or news, that may be of interest to you.
- To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collections.
- To improve our website and present its contents to you.
- For testing, research, analysis to improve our products and services and for developing new ones.
- To protect the rights, property or safety of us, our employees, our members or others.
- To detect security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to you when collecting your personal information.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of our assets, in which personal information held by us is among the assets transferred.
We also use your personal information to advance our commercial or economic interests (“commercial purpose”), such as advertising our membership, products and services, or enabling or effecting, directly or indirectly, a commercial transaction.
IV. SHARING PERSONAL INFORMATION
We disclose your personal information to a third party for a business purpose or commercial purpose. When we disclose personal information for a business or commercial purpose, we enter a contract that describes the purpose and requires the recipient to keep that personal information confidential and not to use it for any purpose except performing the contract.
In the preceding 12-months, we have disclosed the following categories of personal information for a business purpose and, for each category, the following categories of third-parties with whom such personal information was shared:
- Category A
- Category B
- Category C
- Category D
- Category E
- Category F
- Category G
- Category H
- Category I
- Category J
We disclose your personal information for a business or commercial purpose to the following categories of third-parties:
- Our third-party service providers;
- Our affiliated websites and businesses in an effort to bring you improved service across our family of products and services, when permissible under relevant laws and regulations
- Other companies to bring you co-branded services, products or programs;
- Third parties that help us advertise products, services or membership with us to you;
- Third parties to whom you or your agents authorize us to disclose your personal information in connection with products or services we provide to you;
- Third parties or affiliates in connection with a corporate transaction, such as a sale, consolidation or merger of our financial institution or affiliated business; and
V. SELLING PERSONAL INFORMATION
In the preceding 12-months, we have not sold any personal information and, going forward, we will not sell your information. If this changes, we will notify you in accordance with applicable law.
VI. YOUR RIGHTS AND CHOICES
If you are a California resident, this section describes your rights and choices regarding how we collect, share, use, and protect your personal information, how to exercise those rights, and limits and exceptions to your rights and choices under the CCPA.
In the following instances, the rights and choices in this Section VI do not apply to you:
- If you are not a California resident.
- “Aggregated information” that relates to a group or category of consumers, from which consumer identities have been removed, that is not linked or reasonably linkable to any consumer or household, including via a device.
- “Deidentified information” that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to you, provided that we have: (i) implemented technical safeguards that prohibit reidentification of your information; (ii) implemented business processes that specifically prohibit reidentification of the information; (iii) have business processes to prevent inadvertent release of deidentified information; and (iv) make no attempt to reidentify the information.
- The information we have is publicly available from government records.
b. Access to Specific Information and Data Portability Rights
If the above exceptions do not apply, and you have not made this request more than twice in a 12-month period, you have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months from the date we receive your request. Once we receive and confirm your request and verify that the request is coming from you or someone authorized to make the request on your behalf, we will disclose to you or your representative:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting or selling that personal information.
- The categories of third parties to whom we sold or disclosed the category of personal information for a business or commercial purpose.
- The business or commercial purpose for which we sold or disclosed the category of personal information.
- The specific pieces of personal information we collected about you in a form that you can take with you (also called a “data portability request”).
c. Deletion Request Rights
You have the right to request that we delete any of your personal information that we collect from you and retained, subject to certain exceptions. Once we receive and verify your request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies. We may deny your deletion request if retaining the information is necessary for us or our service providers to:
- Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity.
- Debug to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law.
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the businesses’ deletion of the information is likely to render impossible or seriously impair the achievement of such research, if you previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
d. Exercising Access, Data Portability, and Deletion Rights
To exercise the access, data portability, and deletion rights described above, please submit a verifiable consumer request to us by either:
- Calling us toll-free at 800-231-1626.
- Visiting our website and completing our web form.
- Visiting one of our branch locations.
After we receive your request, we will send you instructions on how to verify your identity. If you are submitting a request that applies to an entire household, we will need to verify the identity of each consumer in the household to whom the request applies. Depending on the type of information you are requesting, you may also be required to provide a signed declaration under penalty of perjury confirming that you are the consumer whose information you are requesting. If the request is submitted on your behalf by an agent, we will verify the identity of the agent and the authority of the agent to make the request on your behalf.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
An authorized agent is any person or legal entity registered with the California Secretary of State that you have authorized to act on your behalf. If we receive a request through your authorized agent, we may require:
- Submission of a written document signed by you with your permission for the authorized agent to submit a verifiable request on your behalf and require the authorized agent to verify its own identity to us; or
- You to directly verify with us that you have provided the authorized agent to submit the request.
- We will not require either of the above if your authorized agent provides a copy of a power of attorney pursuant to California Probate Code sections 4000 to 4465 and we are able to verify authorized agent’s identity.
We will deny a request from an agent that does not submit proof that they have been authorized by you to act on your behalf and cannot verify their own identity to us.
f. Response Timing and Format
We endeavor to respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. All responses will be mailed via U.S. Mail or be emailed to the verified addresses, depending upon your communication preferences.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request.
g. Right of Non-Discrimination
- Deny you goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of goods or services.
- Suggest that you may receive a different price for goods or services or a different level or quality of goods or services.
VII. DO NOT TRACK (“DNT”) SIGNALS
IX. CHILDREN’S ONLINE INFORMATION PRIVACY
Our website is not intended for children under the age of 13. We do not knowingly collect, maintain, or use personally identifiable information from our website about children under the age of 13 without parental consent. For more information about the Children’s Online Privacy Protection Act (COPPA), visit the Federal Trade Commission website: www.ftc.gov.
X. LINKING TO THIRD-PARTY WEBSITES
We use reasonable physical, electronic, and procedural safeguards that comply with federal standards to protect and limit access to personal information. This includes device safeguards and secured files and buildings.
Please note that information you send to us electronically may not be secure when it is transmitted to us. We recommend that you do not use unsecure channels to communicate sensitive or confidential information (such as your Social Security number) to us.
XII. CONTACT INFORMATION
Mail: Firefighters First Credit Union, Attn: Operations,
1520 West Colorado Blvd
Pasadena, California 91105