Privacy Policy

Privacy Policy

What we collect, why we collect it, who receives it, how long we keep it, and how you switch it off.
Document Information
Effective: September 8, 2026
Last updated: September 8, 2026
Next review: September 8, 2027
Applies to: banrox.com, the Banrox dashboard, and Banrox email and SMS
Your Controls
Global Privacy Control
We treat a GPC signal from your browser as a valid opt out of sale and sharing, automatically, with no account required.
One place to act
Access, correction, deletion, opt out and appeal all run through banrox.com/legal/state-privacy-rights or [email protected].

1. Scope and How the Two Privacy Regimes Fit Together

This Privacy Policy explains how Banrox Inc. ("Banrox," "we," "us," "our") collects, uses, discloses, retains, and protects personal information through banrox.com, the Banrox member dashboard, our emails and text messages, and any page or feature that links to this policy.

Two different bodies of law apply to different data, and it matters which one you are looking at.

Financial information under GLBA

Information you give us to obtain or use a financial product or service, and information we obtain about you in connection with one, is governed by the Gramm-Leach-Bliley Act and Regulation P. The federal notice for that information is the GLBA Privacy Notice, and it controls for that data.

Everything else under state privacy law

Website analytics, marketing data, general enquiries, community posts, job applications, and other non-GLBA information are governed by this policy and by the state privacy laws described at State Privacy Rights.

Where a state law gives you a right that the GLBA exemption does not remove, you keep that right. Where the two overlap we apply the more protective standard rather than the narrower one.

This policy does not cover a third party's site or product. When you leave Banrox for a lender, bank, card issuer, or insurer, that company's own privacy policy governs from that moment.

2. What We Collect, Where It Comes From, and Why

The table below is the notice at collection required by California law and serves the equivalent requirement in other states. "Sold or shared" uses the statutory meaning in those laws, which is broader than an exchange of money.

Category Examples Source Why we collect it Who receives it Kept for Sold or shared
Identifiers Name, email, phone, postal address, IP address, device and account identifiers You; your device Create and run your account, support, security, fraud prevention, service messages Hosting, email and SMS providers, fraud and identity vendors Account life plus 7 years No
Referral information Name, email, phone, postal code, loan or product interest, requested amount You, when you ask to be matched Pass your request to the specific providers you asked about The provider you selected 24 months from the request Only when you ask to be matched. See Section 5.
Government identifiers (sensitive) Social Security number, taxpayer ID, driver licence or state ID number, date of birth You Verify that you are who you say you are, and obtain your credit file at your written request Identity verification vendors, consumer reporting agencies Account life plus 7 years, then destroyed Never
Financial account information (sensitive) Bank account tokens, card last four digits, balances, transactions, payment history You; your bank through Plaid or an equivalent connection you authorise Deliver the features you switched on, take payment for a paid plan Payment processor, bank data aggregator Account life plus 7 years Never
Consumer report data (FCRA regulated) Credit report contents, scores, alerts, tradelines, inquiries Consumer reporting agencies, with your written authorisation Show you your own credit position and alert you to changes No one outside the vendors that deliver the feature to you Displayed for the account life; source data retained per FCRA vendor terms Never
Identity exposure data Dark web findings, data broker listings that mention you Monitoring vendors; public and non public sources Alert you and send removal requests on your instruction Monitoring vendors, the data brokers we write to on your behalf Account life plus 2 years for the removal audit trail Never
Online activity Pages viewed, referring page, clicks, session duration, approximate city from IP Your device, cookies and similar technologies Run the site, measure what works, detect abuse Analytics providers; advertising partners only if you consent 25 months Shared for advertising only with your consent. Off by default.
Communications Emails, chat transcripts, support tickets, call recordings where lawful You Answer you, train our team, resolve disputes, meet record keeping duties Support and telephony providers 5 years No
User content Community posts, reviews, quiz answers, uploaded documents You Publish what you chose to publish, run the feature, enforce our rules Hosting and moderation providers Until you delete it, plus backups No
Inferences Product fit signals, risk and fraud scores Derived by us from the above Show relevant options, stop fraud Fraud vendors Account life plus 2 years No

We do not collect biometric identifiers, precise geolocation, health data, genetic data, union membership, religious or philosophical beliefs, racial or ethnic origin, sexual orientation, or immigration status, and we do not ask you for them. If you volunteer any of it in a free text field, we delete it when we find it.

3. Sensitive Personal Information

Your Social Security number, government ID numbers, financial account information, and the contents of your consumer report are sensitive personal information under California law and are protected categories under other state laws.

We use them only to verify your identity, to prevent and detect fraud and security incidents, to deliver the specific service you asked for, and to meet a legal obligation. We do not use them to infer characteristics about you. We do not use them for advertising. We do not include them in a referral. We do not sell them and we do not share them for cross context behavioural advertising, in any circumstance, for any price.

Because we limit our use to the purposes that California law itself exempts, the right to limit the use of sensitive personal information does not change how we treat it. You may still send us the request, and we will confirm this in writing.

4. How We Use Personal Information

  • Provide, operate, secure, and improve the Services, and deliver the features you turned on
  • Verify identity, authenticate logins, and prevent fraud, account takeover, bot abuse, and money laundering
  • Obtain and display your own credit information at your written request
  • Monitor for exposure of your information and act on removal instructions you give us
  • Take payment, manage subscriptions, and issue refunds
  • Send service, security, billing, and legally required messages
  • Send marketing where you consented, and stop when you tell us to
  • Answer support requests and resolve complaints and disputes
  • Measure and improve the site, run aggregate analytics, and test changes
  • Comply with law, respond to lawful requests, enforce our terms, and establish or defend legal claims

We do not use your information to make an automated decision that produces a legal or similarly significant effect about you. Banrox does not approve, deny, or price credit, insurance, or any financial product. Those decisions belong to the providers.

5. Who We Disclose Information To, and What Counts as a Sale

Service providers

We use vendors to host, secure, verify, message, analyse, and support. Each is contractually restricted to using Banrox data only to perform its service for us, is barred from selling it, and is barred from combining it with data from other clients except where the law allows. The categories and named vendors are at Service Providers and Data Recipients.

Providers you asked to be matched with

When you ask to be matched or request a quote, we pass the referral information listed in Section 2 to the specific providers responsive to that request, so that they can respond to you. Under California law this transfer can be a "sale" because we may be paid for it, so we treat it as one and give you the opt out even though you asked us to make it.

The hard limits on referrals. A referral never contains your Social Security number, a government ID number, a financial account number, the contents of your credit report, or a precise location. We do not sell or share a referral for anyone we know to be under 16. We do not sell lists of members to companies you did not ask about, and we do not place your information into an open bidding exchange.

Advertising partners

We do not share personal information for cross context behavioural advertising unless you consent through the cookie banner. If you consent, you can withdraw at any time, and a Global Privacy Control signal withdraws it automatically. See the Cookie and Tracking Technologies Notice.

Legal, safety and corporate

We disclose information when compelled by law or valid legal process, to protect the rights, property, or safety of Banrox, our members, or the public, to enforce our terms, and to auditors, insurers, and professional advisers under confidentiality. In a merger, acquisition, financing, or sale of assets, information may transfer to the successor, which remains bound by this policy for information collected before the transfer, and we will give notice before any material change in how it is handled.

We do not give any government agency direct or unfettered access to member data, and we require valid legal process. Where we are permitted to tell you about a request, we will.

6. Do Not Sell or Share, and Global Privacy Control

You may opt out of the sale or sharing of your personal information at any time. It is free, it takes effect immediately for future transfers, and we do not treat you differently for using it.

  • Send a Global Privacy Control signal from your browser or extension. We detect and honour it automatically, with no account and no form. If you are signed in, we apply it to your account as well.
  • Use the Do Not Sell or Share control in your account privacy settings.
  • Email [email protected] with the subject line "Do Not Sell or Share."
  • Call (888) 888-6401.

An opt out stops future transfers. It cannot pull back information a provider already received, and you would need to contact that provider directly to ask it to delete what it holds. We will tell you which providers received a referral if you ask.

7. How Long We Keep Information

We keep each category for the period stated in the table in Section 2, and no longer, unless a law, a regulatory record keeping obligation, a tax rule, or an active legal claim or investigation requires us to keep it longer. When a retention period ends we delete the record or de-identify it so it can no longer be linked to you, and we do not attempt to re-identify de-identified data.

Backups follow their own rotation and are overwritten on a rolling basis, normally within 90 days. A deletion request removes the record from live systems immediately and from backups as they cycle.

8. How We Protect Information

We run a written information security programme with a named person accountable for it, a documented risk assessment, encryption of personal information in transit and at rest, multi factor authentication for administrative access, least privilege access control with periodic review, logging and monitoring, vulnerability management, secure development practices, vendor security review, staff training, and a written incident response plan that is tested.

No system is perfectly secure, and we do not claim otherwise. If a breach of unencrypted personal information about you occurs, we will notify you and the applicable regulators within the deadlines the law sets, and the notice will say what happened, what was involved, and what we are doing. Our full posture, including which certifications we do and do not hold, is at Security and Vulnerability Disclosure.

9. Your Privacy Rights

Depending on where you live, you have some or all of the rights below. Every one of them is exercised through the same place: State Privacy Rights, which also sets out how we verify a request, how an authorised agent may act for you, how long we take, and how to appeal a refusal.

  • Know and access. What we collected, where it came from, why, who received it, and a copy in a portable format.
  • Correct. Fix information about you that is inaccurate.
  • Delete. Have us delete information about you, subject to legal exceptions we will identify specifically if we rely on one.
  • Opt out of sale or sharing. As described in Section 6.
  • Limit sensitive information. As described in Section 3.
  • Opt out of profiling in furtherance of decisions with legal or similarly significant effects. We do not do this, so the right is satisfied by default.
  • Appeal a denied request, and then complain to your state attorney general.
  • Non-retaliation. We will not deny service, charge a different price, or give you a lower quality of service because you used a privacy right.

California residents may also request, once a year and free, information about disclosures of personal information to third parties for their direct marketing purposes under California Civil Code section 1798.83, the "Shine the Light" law. Write to [email protected] with the subject "Shine the Light." Nevada residents may submit a verified request not to sell covered information under NRS 603A.340 to the same address.

10. Cookies, Pixels, Session Tools and Signals

Strictly necessary cookies run so the site works and stays secure. Analytics, functional, and advertising technologies load only after you choose in the cookie banner, or where your jurisdiction does not require prior consent. Session replay and heat mapping, where used, are disclosed by name in the cookie notice and are subject to the same consent gate.

We honour Global Privacy Control. We do not respond to legacy Do Not Track headers, because no common standard for them was ever settled, and we say so here rather than leave it unanswered. Full detail, including every vendor and its purpose, is at Cookie and Tracking Technologies Notice.

11. Children

The Services are for adults. We do not knowingly collect personal information from a child under 13, and we do not knowingly sell or share the personal information of a consumer under 16. If you believe a child gave us information, write to [email protected] and we will delete it and confirm to you that we did.

12. Our Status Under Data Broker Laws

Banrox collects personal information directly from the people it serves and does not buy consumer lists to resell. Information we handle to deliver a financial product or service is regulated under the Gramm-Leach-Bliley Act, and consumer report information is regulated under the Fair Credit Reporting Act. Both are excluded from the definition of a data broker in the California Delete Act and in the equivalent state statutes.

We state our status here rather than leave you to guess it, and we will update this section in the same release as any change to how we obtain or transfer information. If our status ever changes, we will register where required and honour deletion requests through the state mechanism, and this page will say so.

13. Where Information Is Processed

Banrox serves the United States and processes personal information in the United States. Some vendors provide support from other countries under contractual protections. We are not offering the Services in the European Economic Area, the United Kingdom, or Switzerland, and we do not target residents there.

14. Changes to This Policy

We will post any change here with a new effective date. If a change materially affects how we use information already collected about you, we will give notice by email to the address on your account at least 30 days before it takes effect, and where the law requires consent for the new use we will ask for it rather than assume it. Prior versions are available on request at [email protected].

15. Contact the Privacy Team

Banrox Inc.

Attn: Privacy
40 N Altadena Dr, Ste 105
Pasadena, CA 91107

If you are not satisfied with our answer, you may complain to your state attorney general, to the California Privacy Protection Agency at cppa.ca.gov, or to the Federal Trade Commission at reportfraud.ftc.gov. Complaining to a regulator costs nothing and you do not have to come to us first.

Call Us
Customer Service: (888) 888-6401
Location
40 N Altadena Dr Ste 105
Pasadena, CA 91107

Get Your Full Report

We will save this calculation to your Banrox record so you can pick it up later.

Success!

Your calculation has been saved.