Privacy

SUNBIT SERVICES PRIVACY POLICY

Last Updated: June 17, 2026

This privacy policy (“Policy”) governs the relationship between Sunbit, Inc. our corporate family, agents, assigns, and other third parties acting on our behalf (“Sunbit”“us”“we”, or “our”) and users (“you” and “your”) of Sunbit’s mobile applications and online products and services. Sunbit respects the privacy of our users, and Sunbit is committed to protecting personally identifiable information (“PII”). This Policy describes how we collect, use, and share your PII through Sunbit’s website www.sunbit.com (the “Site”), mobile applications and online products and services (collectively with the Site, “Services”), and applies wherever this Policy is linked. This Policy also applies to certain PII we collect in our business-to-business relationships.

Please note the following sections that include important disclosures related to our Websites and Services:

  • Cookies, Advertising, and Tracking Technology Disclosures: To learn more about how our Services use cookies and related technologies (including from third parties), see Cookies and Other Automatic Information Collection Technologies below.
  • Your Choices Disclosures: To learn more about your choices concerning your information, see Your Choices below. 
  • U.S. State Privacy Rights: If you are a resident of certain states, including California, Oregon, Minnesota, Nebraska, and Texas, you may be entitled to additional rights. Please see U.S. State Privacy Rights below. 

Eligibility

The Services are controlled, operated, and administered by Sunbit from its offices within the United States. If you are accessing the Services from a location outside the United States, you understand and consent to the collection, storage, processing, and transfer of your information to our facilities in the United States and to those third parties with whom we disclose it as described in this Policy. We reserve the right to restrict your ability to access the Services when you are in a jurisdiction outside of the United States.

This Policy does not apply to any non-public personal information we process in connection with our financial services under Gramm-Leach-Bliley.  Please see our “Sunbit Privacy Notice” below. 

This Policy does not apply to any protected health information (“PHI”) that we receive as a business associate of our covered entity customers. We will protect, use, and disclose such PHI in accordance with our agreement with the respective covered entity customer and our obligations under the Health Insurance Portability and Accountability Act (“HIPAA”).

PII that We Collect

Depending on your relationship with us, we may collect the following types of information about you:

  • Personal Identifiers: This includes real name, previous name, alias, unique personal identifier, online identifier, unique device identifier address, email address, IP address, telephone number, account name, driver’s license number, passport number, signature, or other similar identifiers.
  • Government Identifiers: This includes driver’s license or state identification number, tax-identification number, Social Security number, other government-issued identification number, and copies and information from government-issued IDs and death certificates.
  • Financial Information: This includes credit report information, credit scores, payment information, bank account numbers, debit card numbers, account details, ACH information, income, and similar data.
  • Demographic Information: This includes date of birth, familial status, education, employment, and housing information.
  • Protected Characteristics: This includes age, marital status, sex, and veteran or military status.
  • Commercial information: This includes products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
  • Geolocation Data: This includes any information used to identify your physical location or movements.
  • Internet, Application, and Network Activity: This includes browsing history, search history, and information regarding a consumer’s interaction with a website, application, or advertisement.
  • Biometric identifiers and biometric information, including a consumer’s selfie or picture of an identification card used to identify an individual.
  • Diversity or demographic information, including race or ethnicity, national origin, gender, or gender identity, religious or philosophical beliefs, political affiliation, opinion or association, veteran or disability status, status as nonbinary or transgender, or citizenship or immigration status.
  • Audio, Electronic, Visual, or Similar Information. This includes call recordings, photographic, or video images, or similar information.
  • Professional or employment-related information. This includes your employer, income, or other employment information.
  • Inferences About You: This includes a profile about you that may reflect preferences, characteristics, predispositions, behavior, attitudes, and creditworthiness.
  • Other PII: This includes any other PII you may include in any communications with us, including but not limited to questions, comments, suggestions, or survey responses.

Sensitive PII that We Collect

Depending on your relationship with us, we may collect the following types of sensitive PII about you:

  • Username and password.
  • Financial, account or billing information, including tax identification number, Social Security number, or credit/debit card information.
  • Proof of identification, including driver’s license number, or state/national government-issued identification.
  • Biometric identifiers and biometric information, including a consumer’s selfie or picture of an identification card used to identify an individual.
  • Diversity or demographic information, including race or ethnicity, national origin, gender, or gender identity, religious or philosophical beliefs, political affiliation, opinion or association, veteran or disability status, status as nonbinary or transgender, or citizenship or immigration status.
  • Geolocation Data: This includes any information used to identify your physical location or movements.
  • Information Sunbit has contractually agreed to manage under heightened confidentiality and security protocols, such as health and financial information or intellectual property.

Sources of Information

Information Provided by You 

Depending on your use of our Services you may provide us certain information directly, including in connection with the following: 

  • For use of Services: Sunbit collects PII from you when you directly provide when you use our Services. This includes your name; address; telephone number; email address; signature; driver’s license or state identification number; biometric identifiers or biometric information; age and Social Security number in some instances; financial and payment information including, without limitation, bank account numbers, debit card numbers, account details, ACH information, income, and similar data; purchase information; and any other application information necessary to provide you with the requested financing. This may include data collected through your use of your device’s camera in connection with the Services.
  • Account Access: If you open an account with Sunbit, we will also collect PII from you when you use our Services to access your account and engage in activities such as making payments. This may include your user name and password, bank account information, and transaction history.
  • Communications: We also collect any PII you provide us when communicating with Sunbit, including but not limited to your emails, phone calls (including recordings of such calls), text messages, and physical letters and the contents thereof. This may include but is not limited to questions, comments, suggestions, or survey responses.

Information Provided by Third Parties

We may collect PII from third parties, such as our partner bank, merchant partners, co-brand partners, consumer reporting agencies, wireless carriers, marketing or advertising providers, and service providers.

Information Collected Automatically

We collect certain information automatically when you use our Services, including in connection with the following: 

  • Service Use: The Services may automatically collect technical information through your use of the Services, such as which of the pages you access, the frequency of access, and what you click on while using the Services. 
  • Geolocation: Certain features and functionalities of the Services are based on your location. In order to provide these features and functionalities while you are using your mobile device, we may, with your consent, automatically collect geolocation information from your mobile device or wireless carrier and/or certain third-party service providers. You may decline to allow us to collect such geolocation information, in which case we will not be able to provide certain features or functionalities to you. We may collect information from service providers of geolocation information, such as Google.
  • Device Information: We may also automatically collect PII about your device as you use our Services, including but not limited to hardware model, external storage devices connected to your device, operating system, application version number, browser, and IP addresses. We may also collect mobile network information from mobile devices including the unique device identifier assigned to that device, mobile carrier, operating system, and other device attributes.

Information collected automatically may utilize cookies or other technologies we implement through our Services. For more information about such technologies, see Cookies and Other Automatic Information Collection Technologies below. For more information about your choices in connection with these technologies, please see Your Choices below. 

Cookies and Other Automatic Information Collection Technologies

Technologies Used

We use the following technologies with our Services: 

  • Cookies: A cookie is a small text file that is stored on a user’s device for recordkeeping purposes. We may use session cookies to make it easier for you to navigate the Services. We may also use persistent cookies that remain on your hard drive for an extended period of time and may store a password or track and target the interests of users navigating the Services. If you reject cookies, you may still use the Services, but your ability to use some areas of the Services may be limited.
  • Pixels: Pixels (also known as web beacons) are types of code embedded in a website, video, email, or advertisement that sends information about your use to a server. When you access a website, video, email, or advertisement that contains a pixel, the pixel may permit us or a separate entity to drop or read cookies on your browser.
  • Software Development Kits (SDKs): Software Development Kits (also known as “SDKs”) are sets of tools and code provided by third parties that are embedded in our mobile applications to enable specific functionalities and improve user experience. Some SDKs may collect data directly from your device, such as your IP address, device type, or usage patterns, to support these functions.
  • Analytic Tools: Analytic tools include technologies or software services that collect, measure, and analyze data about how users interact with our Websites and Services. These tools often use cookies, pixels, and similar technologies to gather information such as page views, clicks, and user behavior, which is then used to improve site functionality and user experience.

Purpose for Using Automatic Information Collection Technologies

Third-party technologies we have implemented on our Websites and through our Services include the following:

  • Functionality, Support and Security: We may also use other mobile tracking technologies to identify you and keep track of your preferences, prevent fraudulent activity, and improve the security of the Services, assess the performance of the Services. 
  • Advertising, Marketing Measurements: Cookies and pixel tags may be used to deliver content to you based on your interests, measure the success of our marketing campaigns, and compile statistics about usage and response rates. In addition our third-party service providers acting on our behalf, may collect information about you, your online activities, or activity on devices associated with you using tracking technologies such as Flash cookies, HTML5 cookies, pixels, tags, device fingerprints, and/or web beacons in order to display the most relevant content and advertising that has been targeted for you based on your preferences, usage patterns, and location when you use our Services or visit other websites. Some of these tracking technologies may track your activities across time and services for purposes of associating the different devices you use, and delivering relevant ads and/or other content to you (“Interest-based Advertising”). Third-party technologies we have implemented on our Websites and through our Services include the following:
    • Microsoft Bing Universal Event Tracking (UET): We use Universal Event Tracking (“UET”), an advertising measurement and audience targeting technology provided by Microsoft Corporation (“Microsoft”), on our Website. The UET tag records certain user interactions on our Website — including page visits, purchases, form submissions, and other conversion events — and transmits that information to Microsoft Advertising to enable us to measure the effectiveness of our advertising campaigns, create remarketing audiences, and optimize ad performance. UET collects information through first-party and third-party cookies, including pseudonymous identifiers (such as cookie IDs and IP address), browser and device information, URLs visited, and behavioral data reflecting interactions with our Website. This data is used by Microsoft to support targeted advertising, conversion tracking, and remarketing across the Microsoft Advertising network (including Bing and partner properties). For more information, including how to opt out, please visit Microsoft’s Privacy Statement at https://privacy.microsoft.com/en-us/privacystatement.
    • Meta Pixel: We use the Meta Pixel (also referred to as the “Facebook Pixel”), a web analytics and advertising tool provided by Meta Platforms, Inc. (“Meta”), on our Website. The Meta Pixel is a snippet of JavaScript code that, when loaded, may set one or more cookies and collect information about your interactions with our Website — including pages you visit, products you view, items added to a cart, purchases, and other events you complete. This information is transmitted to Meta and may be associated with your Facebook or Instagram account (if you are a Meta user and logged in). We use the Meta Pixel for the following purposes: (i) conversion tracking, to measure the effectiveness of our advertising campaigns; (ii) custom audience creation, to serve personalized advertisements to Website visitors on Facebook, Instagram, and Meta’s Audience Network; (iii) lookalike audience targeting, to reach new users with similar characteristics to our existing customers; and (iv) aggregate analytics and campaign optimization. Meta may use data collected through the Meta Pixel in accordance with its own Privacy Policy, including for its own internal product improvement purposes. Meta may combine this information with data it has collected from other sources. We do not control Meta’s independent data practices. You may opt out of personalized advertising on Facebook and Instagram by adjusting your ad preferences at https://www.facebook.com/settings?tab=ads or by visiting the Digital Advertising Alliance’s opt-out tool at https://optout.aboutads.info/. For more information, please visit Meta’s Privacy Policy at https://www.facebook.com/privacy/policy/.
    • Google Ads Tag: We use the Google Ads Tag, an advertising technology provided by Google LLC (“Google”), to measure the effectiveness of our advertising campaigns and to enable conversion tracking and audience-based advertising. The Google Ads Tag collects information about your interactions with our Website — including pages visited, actions taken (such as completing a purchase or filling out a form), and other behavioral signals — and may set advertising cookies on your device to associate your activity with a Google advertising profile. This information is used to: (i) measure when users who have seen or clicked on our advertisements subsequently take actions on our Website (conversion tracking); (ii) enable us to show you personalized advertisements on Google’s network, including Google Search, YouTube, and partner websites (remarketing); and (iii) provide aggregate campaign performance reports. Google may use this data in accordance with its own privacy policy. 
    • The Trade Desk: We use the advertising technology platform operated by The Trade Desk, Inc. (“Trade Desk”) to serve targeted advertising and measure campaign effectiveness across digital channels. The Trade Desk’s technology collects pseudonymous information — including cookie identifiers, device identifiers, IP address, and behavioral data reflecting your interactions with our Website and other websites — and uses this information to build interest-based profiles for targeted ad delivery across the Trade Desk’s programmatic advertising network. This constitutes cross-contextual behavioral advertising as defined under applicable privacy laws.
    • LinkedIn Insight Tag: We use the LinkedIn Insight Tag, a JavaScript tag provided by LinkedIn Corporation, a subsidiary of Microsoft Corporation (“LinkedIn”), on our Website. The LinkedIn Insight Tag creates a unique browser cookie and enables LinkedIn to collect certain information about visitors to our Website, including IP address, timestamps, page view data (URLs visited), device and browser information, and referral URLs. For visitors who are LinkedIn members and are logged into LinkedIn, this information may be associated with their LinkedIn member profile, which may include professional information (such as job title, company, industry, and seniority level). We use the LinkedIn Insight Tag for the following purposes: (i) conversion tracking, to measure when visitors who interacted with our LinkedIn advertisements subsequently take actions on our Website; (ii) website retargeting, to serve personalized advertisements to Website visitors through LinkedIn’s platform and LinkedIn Audience Network; and (iii) aggregate analytics and website audience insights regarding the professional characteristics of our Website visitors. LinkedIn does not share individual member data with us; we receive only aggregate, non-identifying reports. You may opt out of the LinkedIn Insight Tag by visiting LinkedIn’s opt-out page at https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out, or by adjusting your LinkedIn advertising settings. For more information, please visit LinkedIn’s Privacy Policy at https://www.linkedin.com/legal/privacy-policy.
  • Analytics: We use service providers for Website analytic services, to best understand how our Website is being used and to make improvements to our Website, including the following Services: 
    • Google Analytics: We use Google Analytics to help us understand how users access and use the Websites through the use and sharing of cookies. You can learn about Google’s practices by going towww.google.com/policies/privacy/partners/.

 

How We Use PII

The following explains how we use your PII:

    • Communications: We may use your PII to communicate with you, or allow a partner bank to communicate with you, such as sending account updates, or other communications regarding your account, other products, and services that we think may be of interest to you, or to inform you of any changes to our Services. 
    • Customer Support: We, or a partner bank, may also use your PII to provide you with customer support or other services that you request. For example, we, or a partner bank, may need your information in order to evaluate your application for a Service, process your transactions or payments, provide technical support, or answer questions about our Services, or to send you information about our products, services, or new offerings. 
    • Collection Activities: We, or a partner bank, may also use it to conduct collections activities if necessary. 
    • Location Based Services: We may also use your PII to provide you with location-based services that rely on geolocation information. 
    • Verification Activities: We may also use your PII for purposes including but not limited to information verification and providing Geolocation Information services. We may also disclose your PII with non-affiliates for advertising and marketing purposes.
    • Marketing Activities: We may engage in marketing communications containing information about products and services that may be of interest to you. For Sunbit application users, personal data collected through the short code/SMS program will not be shared, sold, or rented to unaffiliated or affiliated third parties for their own marketing purposes.
    • Analytics and Service Experience Improvement. To provide our customers with the best possible service, we may analyze how our users interact with our Services in order to maintain and improve our Services. Third-party vendors may collect PII about your online activities over time and across different websites when you use the website. 
    • Protect Services, Users, Fraud Prevention and other Security Purposes. We also use PII that we collect to diagnose any problems with our Services and to investigate, prevent, or detect fraud or other illegal activities.
    • Automated Data Entry. We may use your PII to automatically enter PII into certain fields or forms provided as part of the order to increase the ease of use of any product or service we offer including the Services.
    • Transaction Processing and Payments. We may also use your PII to allow for payment or other similar transactions including to enable the Services to use your device(s)’ near field communication (NFC) services including but not limited to Apple Pay and Android Pay and other similar mobile device payment methods.
  • Surveys, Sweepstakes, Promotions, and Contests. We use your PII to administer surveys, sweepstakes, promotions, and other contests that we offer from time to time and that you voluntarily participate in. 
  • Necessary to Conduct our Business (i.e., Legitimate Business Purposes). We also may use PII for any other legitimate business purpose, including but not limited, for:
  • Auditing related to counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards.
  • Helping to ensure security and integrity to the extent the use of your PII is reasonably necessary and proportionate for these purposes.
  • Debugging to identify and repair errors that impair existing intended functionality.
  • Short-term transient use, including, but not limited to, non-personalized advertising shown as part of your current interaction with Sunbit, provided the PII is not disclosed to another third party and is not used to build a profile about you or otherwise alter your experience outside the current interaction with Sunbit.
  • Performing services on behalf of Sunbit, including maintaining or servicing accounts, providing customer service, processing, or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, or providing similar services on behalf of Sunbit.
  • Providing advertising and marketing services, except for cross-context behavioral advertising, to you, for the purpose of advertising and marketing, a service provider or contractor shall not combine the PII of opted-out consumers that the service provider or contractor receives from, or on behalf of, Sunbit with PII that the service provider or contractor receives from, or on behalf of, another person or persons or collects from its own interaction with consumers.
  • Undertaking internal research for technological development and demonstration.
  • Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Sunbit, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Sunbit.
  • Any commercial purposes, including any purpose to advance our commercial or economic interests, such as by inducing another person to buy, rent, lease, join, subscribe to, provide, or exchange products, goods, property, information, or services, or enabling or effecting, directly or indirectly, a commercial transaction.
  • We use your PII for other legitimate business purposes that we believe are appropriate or necessary for us to offer you any of our Services, to enhance our Services, or to develop new Services.
  • We may also use your PII for any purpose for which you provide us with consent. We may provide you with a mechanism to revoke any such consent at a later time.
  • We may also use your information for other legitimate business purposes as permitted by law.

Retention of PII

The length of time that we retain each category of your PII may vary based on our relationship with you. For example, we will retain certain PII throughout our customer relationship with you in order to provide you with our Services and as needed or permitted in accordance with the purposes for which it was collected. We also retain certain PII to comply with applicable laws and regulations as well as for other legal purposes, such as for our litigation purposes. We may also retain certain PII for our internal business purposes, such as auditing or security purposes. We will not retain your information for longer than is reasonably necessary for these purposes or as required to be destroyed under applicable law.

To the extent that we retain any PII in deidentified form, we publicly commit to maintaining and using the deidentified data without attempting to reidentify the deidentified data.

When We Disclose PII

We may have to disclose PII to third parties in a variety of circumstances, as further described below. 

  • Partner Banks. We may disclose your PII to our partner banks as necessary to facilitate, service, or support the financial products and services offered through our Services, including for purposes of underwriting, transaction processing, regulatory compliance, and account management.
  • Service Providers. We may disclose your PII to service providers, merchant partners, co-brand partners, and other third parties who assist us in providing our Services, verifying your identity, determining your physical location, processing your transactions, or conducting consumer reporting activities.
  • Business Transactions. We may disclose your PII in connection with a merger, acquisition, consolidation, change of control, or sale of all or a portion of our assets, or in the event we undergo bankruptcy or liquidation.
  • Protecting Our Services, Users, and Legal Rights. We may disclose your PII as necessary to detect, investigate, prevent, or take action against illegal activities, fraud, or situations involving potential threats to the rights, property, or personal safety of any person, or as otherwise required by law, such as in response to court orders or legal process, to exercise our legal rights, to defend against legal claims or demands, or to comply with the requirements of any applicable mandatory law.
  • Business Functions. We may also disclose PII to conduct any other legitimate business activities, including to maintain records related to business management, loss prevention, collecting amounts owed, and identifying and repairing errors or problems in the Websites.
  • Affiliate Disclosures. We may also disclose PII to members of our corporate family, such as affiliates, subsidiaries, joint partnerships, etc.
  • Consent. We may also disclose PII to third parties subject to your consent. We may request your permission to disclose your PII for a specific purpose. In these instances, we will notify you and request your permission before you provide the PII or before we disclose the PII that you have already provided to us for such purpose.
  • Credit Bureau Disclosures. We may disclose information about you and your account to credit bureaus. This may include information about on-time and late payments, missed payments, or other defaults on your account, and such information may be reflected on your credit report.

Third-Party Websites

The Services may contain links to third-party websites. Sunbit has no control over, and assumes no responsibility for any of the content, privacy policies, or practices of any third-party websites. By including a link to a third-party website, Sunbit does not endorse or recommend any products or services offered or information contained at the third-party website, nor is Sunbit liable for any failure of products or services offered or advertised at those websites. Such third party may have a privacy policy different from that of Sunbit, and the third-party website may provide less security protection than our Services. If you decide to visit a third-party website via a link contained on the Services, you do so at your risk.

Children’s Online Privacy Protection

The Services are not available to persons who have not reached the age of majority in their states of residence. We do not knowingly collect PII from children under the age of 13 years. If we become aware that a child under 13 has provided us with PII, we will take immediate steps to delete such PII.

Your Choices 

Account

You may access, update, or remove certain information that you have provided to us through your account by visiting your account settings or by contacting us at the email address set out in the Contact Us section below. We may require additional information from you in order to confirm your identity before processing your request. Please note that we will retain and use information about you as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Communications

The following describes how you may opt out of receiving certain communications from us, depending on the means of delivery:

  • Emails. You can opt out of receiving promotional emails from us at any time by following the unsubscribe instructions included in any such email, or by emailing us at [email protected] with the word UNSUBSCRIBE in the subject line. Please note that you cannot opt out of non-promotional emails, such as those relating to your account, transactions, servicing, or our ongoing business relationship with you.
  • Phone & SMS Text Messaging. You can opt out of receiving text messages or calls to your phone number at any time by: (i) for text messages, texting “STOP” in response to any text message you receive from us, or contacting us at [email protected] and specifying that you want to opt out of text messages; and (ii) for calls, requesting opt-out during any call you receive from us, or contacting us at [email protected] and specifying that you want to opt out of calls.
  • Push Notifications. If you have opted in to receive push notifications on your device, you can opt out at any time by adjusting the notification permissions in your device settings or by uninstalling our mobile application.

 

Cookies and Do Not Track Signals

The following disclosures relate to your choices in connection with cookies and other tracking technologies: 

  • “Do Not Track” Signals: Your browser settings may allow you to automatically transmit a “Do Not Track” signal to online services you visit. The Services do respond to “Do Not Track” signals sent by Internet browsers including other opt-out preference signals, such as the Global Privacy Control.
  • Cookies: Most browsers accept cookies by default. You may stop or restrict the placement of certain cookies and other tracking technologies on your device or remove them by adjusting your preferences through your browser settings or as your device permits. Below are links to instructions for managing cookies on commonly used browsers:
  • Google Chrome: https://support.google.com/chrome/answer/95647   
  • Microsoft Edge: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09   
  • Mozilla Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox   
  • Safari (macOS): https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac

Please be aware that if you adjust your preferences, our Services may not work properly. Please note that cookie-based opt-outs may not be effective for mobile applications. However, you may opt-out of personalized advertisements on some mobile applications by following the instructions for AndroidiOS, and other operating systems.

Analytics and Interest Based Advertising 

  • Analytics. Analytic providers offer certain methods to opt out based on their use of information used for analytics. 
  • Advertising. The online advertising industry also provides websites from which you may opt out of receiving targeted ads from data partners and other advertising partners that participate in these self-regulatory programs. Most of these companies are participants of the Digital Advertising Alliance (“DAA”) and/or the Network Advertising Initiative (“NAI”).  To learn more about the targeted ads provided by these companies, and how to opt out of receiving certain targeted ads from them, please visit: (i) for website targeted ads from DAA participants, https://www.aboutads.info/choices; (ii) for app targeted ads from DAA participants, https://www.aboutads.info/appchoices; and (iii) for targeted ads from NAI participants, https://www.networkadvertising.org/choices/. Opting out only means that the selected participants should no longer deliver certain targeted ads to you, but does not mean you will no longer receive any targeted content and/or ads (e.g., in connection with the participants’ other customers or from other technology services). 

In addition, You may opt out of personalized advertising of certain third-party advertising using settings or tools provided by such third party. 

    • Google – You may opt out of personalized advertising by visiting Google’s Ad Settings at https://www.google.com/settings/ads or by installing the Google Analytics Opt-out Browser Add-on. 
  • LinkedIn – You may opt out of the LinkedIn Insight Tag by visiting LinkedIn’s opt-out page at https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out, or by adjusting your LinkedIn advertising settings.

Please note that if you opt out using any of these methods, the opt out will only apply to the specific browser or device from which you opt out. We are not responsible for the effectiveness of, or compliance with, any opt out options or programs, or the accuracy of any other entities’ statements regarding their opt out options or programs.

U.S. State Privacy Rights

Your Rights

Certain states, such as California, Oregon, and Minnesota (collectively, “Applicable State Laws”), provide consumers with additional information and rights as related to their PII. These rights do not apply, however, to any information we collect that is exempt from these Applicable State Laws, such as non-public PII that Sunbit collects, uses, or discloses in providing a financial product or service for personal, family, or household use. Under Applicable State Laws, residents may have the right to:

  • Request that a business delete any PII about the consumer which the business has collected from the consumer.
  • Request correction of inaccurate PII.
  • Request that a business that collects PII about the consumer disclose to the consumer, free of charge, the following:
  • The categories of PII that it has collected about that consumer.
  • The categories of sources from which the PII is collected.
  • The business or commercial purpose for collecting, selling, or sharing PII.
  • The categories of third parties with whom the business shares PII.
  • The specific pieces of PII it has collected about that consumer.
  • A list of specific third parties that the business has disclosed the consumer’s PII.
  • Request that a business that sells or shares the consumer’s PII, or that discloses it for a business purpose disclose, free of charge, to the consumer:
  • The categories of PII that the business collected about the consumer.
  • The categories of PII that the business sold or shared about the consumer and the categories of third parties to whom the PII was sold or shared, by category or categories of PII for each third party to whom the PII was sold or shared.
  • The categories of PII that the business disclosed about the consumer for a business purpose and the categories of persons to whom it was disclosed for a business purpose.
  • Direct a business that sells or shares PII about the consumer to third parties not to sell or share the consumer’s PII, including not to share PII for targeted advertising. Such opt-out right may be available through an opt-out preference signal.
  • Direct a business that collects sensitive PII about the consumer to limit its use and disclosure of the consumer’s sensitive PII to that use which is necessary to perform the services or provide the goods and is reasonably expected by an average consumer who requests such goods or services.
  • Opt-out of the processing of PII concerning the consumer for purposes of targeted advertising, the sale of PII, or profiling in furtherance of automated decisions that produce legal effects or similarly significant effects. Such opt-out right may be available through an opt-out preference signal. If your PII is profiled in furtherance of decisions that produce legal effects or similarly significant effects, you also have the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision, and, if feasible, to be informed of what actions you might have taken to secure a different decision and the actions that you might take to secure a different decision in the future. You may also have the right to review the PII used in the profiling, and if inaccurate, request to have the data corrected and the profiling decision reevaluated based upon the corrected data.
  • Withdraw your consent to our processing of your PII. Please note that your withdrawal will only take effect for future processing and will not affect the lawfulness of processing before the withdrawal.

To exercise rights as described in this section, please see the Section “Exercising Your Rights” below.

Notice At Collection

  • To learn more about the categories of personal information we collect, please see PII that We Collect above.
  • For more information about how we use those categories of personal information, please see How We Use PII above.
  • For more information about how we collect categories of personal information, please see Sources of Information and Cookies and Other Automatic Information Collection Technologies above.
  • To learn more about how we disclose categories of personal information, and the categories of third parties with whom we disclose such information, please see When We Disclose PII above.
  • To learn more about how long we keep your information, please see Retention of PII above.

Notice Regarding Disclosure for a Business Purpose

To learn more about the categories of personal information we have disclosed for a business purpose, and the categories of third parties with whom we have disclosed personal information, please see When We Disclose PII above. 

Notice Regarding Sale or Sharing of Personal Information 

We may sell or share your PII with third parties for advertising or marketing purposes. The categories of PII that may be sold or shared about you include personal identifiers; demographic information; geolocation data; Internet, application, and network activity; and inferences. The categories of third parties to whom your PII may be sold or shared may include advertising networks, internet service providers, data analytics providers, operating systems and platforms, social networks, and data brokers.

Notice Regarding Use of Sensitive Personal Information

Please see the section “Sensitive PII that We Collect” above to learn about how we process sensitive PII.

California “Shine the Light” Law

If you are a California resident, you have the right to request information from us once per calendar year regarding the customer information we share with third parties for the third parties’ direct marketing purposes. To request this information, please send an email to [INSERT EMAIL] with ‘Request for California Privacy Information’ in the subject line and in the body of your message. We will provide the requested information to you via an email response.

California Eraser Button Law

If you are a California resident under 18 years old and a registered user of the Website (as defined above), you can request that we remove content or information that you have posted to our website or other online services. Fulfillment of the request may not ensure complete or comprehensive removal (e.g., if the content or information has been reposted by another user). To request removal of content or information, please send an email to [INSERT EMAIL] or contact us as otherwise provided in the Contact Us section above.

Exercising Your Rights

Verification Requirements 

In order for us to be able to respond to certain requests or provide you with PII, we must be able to verify your identity or your authority to make the request and confirm that the PII relates to you or to the person who has designated you as an authorized agent. 

Where verification is required, please submit with your request the following PII, which we will match against our business records to verify your identity: full name, date of birth, and email address. We reserve the right to request additional information that may be necessary to verify your identity. If we are unable to verify your identity, we may deny your requests to know or delete.

Right to Know, Access and Deletion Requests

You may exercise your right to know, access or delete information through any of the following means: 

  • Calling our toll free number: 855.678.6248 

In the request, please specify which right you are seeking to exercise and the scope of the request. 

Under certain circumstances, applicable law allows or requires us to retain certain personal information, in which case we will notify you that the relevant information will not be deleted.

Correction Requests

You can correct information we process about you by:

  • Calling our toll free number: 855.678.6248 

Right to Opt-out of Sale, Profiling, and Context-Based Advertising

    You have the right, at any time, to direct us not to sell or share your PII to third parties. This right to opt-out of sale or sharing may be exercised by clicking on the “Do Not Sell/ Share My Information” toggle on our homepage or calling us at 855.678.. You may also opt out by using an opt-out preference signal, such as the Global Privacy Control (GPC) on your browser. To download and use a browser supporting the GPC, you may click here. If you choose the GPC signal, you will need to turn it on for each supported browser or browser extension you use.  

    We will not ask you to verify your identity for such request. 

    Right to Limit the Processing of Sensitive PII

    Where we process sensitive PII on your behalf, you have the right to limit our processing of such sensitive PII, provided however we may not be able to provide you certain Services that are dependent on such Sensitive PII.

    We will not ask you to verify your identity for such limitation request. 

    Authorized Agents

    Residents of California, Colorado, and Connecticut may designate an authorized agent to submit a request on your behalf to access or delete your personal information. To do so, you must: (1) provide that authorized agent written and signed permission to submit such request; and (2) verify your own identity directly with us. Please note, we may deny a request from an authorized agent that does not submit proof that they have been authorized by you to act on your behalf.

    Responding to Requests

    Requests properly submitted will be responded to within the required period under applicable law. If a request is deficient, we may deny the request but will use reasonable efforts to explain the deficiency in the request so that you may correct the request. Please note that we may charge a reasonable fee for multiple requests in the same 12-month period, as permitted by applicable law.

    Non-Discrimination 

    Sunbit will not discriminate or retaliate against a consumer because the consumer exercises any of the consumer’s rights as described in this section. You are also not required to open an account with us to make a request.

    External Storage

    We may store and exchange information with external storage devices connected to your device (including mobile devices). We may install some of the Services, and/or any information used by the Services, on an external storage device (including but not limited to an SD card on supported devices). We will not collect or use any information on any external storage device that was not directly installed on the external storage device by Sunbit.

    Security

    We maintain reasonable physical, technical, and administrative security measures to protect and limit access to your PII. However, no method of transmission over the Internet or electronic storage technology is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your PII, we cannot guarantee its absolute security.

    To protect the security of your information, we may require you to authenticate your identity to conduct certain transactions using the Services. 

    Contact Us

    Any questions, complaints, or claims regarding the Services or our privacy policies and practices should be directed to:

    Sunbit, Inc.
    PO Box 24010
    Los Angeles CA, 90024

    855.678.6248

    Thank you for using the Services!

    California Important Privacy Choices Notice

    Download»

    SUNBIT, INC.

    Important Privacy Choices for Consumers

    You have the right to control whether we share some of your personal information. Please read the following information carefully before you make your choices below.

    Your Rights

    You have the following rights to restrict the sharing of personal and financial information with our affiliates (companies we own or control) and outside companies that we do business with. Nothing in this form prohibits the sharing of information necessary for us to follow the law, as permitted by law, or to give you the best service on your accounts with us. This includes sending you information about some other products or services.

    Your Choices

    Restrict Information Sharing With Companies We Own or Control (Affiliates): Unless you say “No”, we may share personal and financial information about you with our affiliated companies.

    (_) NO, please do not share personal and financial information with your affiliated companies.

    Restrict Information Sharing With Other Companies We Do Business With To Provide Financial Products And Services: Unless you say “No”, we may share personal and financial information about you with outside companies we contract with to provide financial products and services to you.

    (_) NO, please do not share personal and financial information with outside companies you contract with to provide financial products and services.

    Time Sensitive Reply

    You may make your privacy choice(s) at any time. Your choice(s) marked here will remain unless you state otherwise. However, if we do not hear from you we may share some of your information with affiliated companies and other companies with whom we have contracts to provide products and services.

    Name:                                                                                                                            

    Account or Policy Number(s):                                                                               

    Signature:                                                                                                                     

     

    To exercise your choices, do one of the following:

    1. Fill out, sign, and send back this form to us by chatting with us on the Sunbit mobile app or at sunbit.com; or
    2. Call this toll-free number: 1-855-678-6248
    Sunbit Privacy Notice

    Download »
    Rev. 08/23

    FACTS

    WHAT DOES SUNBIT DO WITH YOUR PERSONAL INFORMATION?
    Why?

    Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do.

    What?

    The types of personal information we collect and share depend on the product or service you have with us. This information can include:
    • Social Security number and purchase history
    • Payment history and transaction history
    • Credit history and credit scores

    How?

    All financial companies need to share customers’ personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers’ personal information; the reasons Sunbit chooses to share; and whether you can limit this sharing.

    Reasons we can share your Personal Information
    Does Sunbit Share?
    Can you limit this sharing?
    For our everyday business purposes such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus Yes No
    For our marketing purposes to offer our products and services to you Yes No
    For joint marketing with other financial companies Yes No
    For our affiliates’ everyday business purposes information about your transactions and experiences Yes No
    For our affiliates’ everyday business purposes information about your creditworthiness Yes Yes
    For affiliates to market to you Yes Yes
    For nonaffiliates to market to you Yes Yes
    To limit our sharing

    Call 1-855-678-6248
    Please note:
    If you are a new customer, we can begin sharing your information 30 days from the date we sent this notice. When you are no longer our customer, we continue to share your information as described in this notice.
    However, you can contact us at any time to limit our sharing.

    Questions?

    Call 1-855-678-6248 or chat with us on the Sunbit mobile app or at sunbit.com

    Who we are

    Who is providing this notice?

    Sunbit, Inc. and Sunbit Now, LLC (“Sunbit”)

    What we do

    How does Sunbit protect my personal information?

    To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings.

    How does Sunbit collect my personal information?

    We collect your personal information, for example, when you

    • apply for financing or give us your contact information

    • show your driver’s license or show your government ­issued ID provide account information.

    We also collect your personal information from others, such as credit bureaus, affiliates, or other companies.

    Why can’t I limit all sharing?

    Federal law gives you the right to limit only

    • sharing for affiliates’ everyday business purposes ­ information about your creditworthiness

    • affiliates from using your information to market to you

    • sharing for nonaffiliates to market to you

    State laws and individual companies may give you additional rights to limit sharing. See below for more on your rights under state law.

    Definitions

    Affiliates

    Companies related by common ownership or control. They can be financial and nonfinancial companies.Our affiliates may include companies with the Sunbit name.

    Nonaffiliates

    Companies not related by common ownership or control. They can be financial and nonfinancial companies.Nonaffiliates we share with can include financial service providers, non­ financial companies, merchant partners, and other businesses.

    Joint marketing

    A formal agreement between nonaffiliated financial companies that together market financial products or services to you.Our joint marketing partners may include banks.

    Other important information

    California Customers: Please refer to the notice provided separately, entitled “Important Privacy Choices for Consumers.
    Nevada Customers: We are providing you this notice pursuant to state law. You may be placed on our internal do-not-call list by calling us at 855.678.6248 or chatting with us on the Sunbit mobile app or at sunbit.com. For more information about this Nevada law, you may contact Sunbit by chatting with us on the Sunbit mobile app or at sunbit.com or the Bureau of Consumer Protection, Office of the Nevada Attorney General by mail at 555 E. Washington Ave., Suite 3900, Las Vegas, NV 89101; telephone at 888-434-9989; or email at [email protected].
    North Dakota Customers: We will not share personal information with nonaffiliates either for them to market to you or for joint marketing without your authorization.
    Texas Customers: For questions or complaints about this loan, contact Sunbit Now, LLC at 855.678.6248, PO Box 24010, Los Angeles, CA 90024, or chat with us on the Sunbit mobile app or at sunbit.com. The lender is licensed and examined under Texas law by the Office of the Consumer Credit Commissioner (OCCC), a state agency. If a complaint or question cannot be resolved by contacting the lender, consumers can contact the OCCC to file a complaint or ask general credit-related questions. OCCC address: 2601 N. Lamar Blvd., Austin, Texas 78705. Phone: (800) 538-1579. Fax: (512) 936-7610. Website: occc.texas.gov. E-mail: [email protected].
    Vermont Customers: We will not disclose information about your creditworthiness to our affiliates and will not disclose your personal information, financial information, credit report, or health information to nonaffiliated third parties to market to you, other than as permitted by Vermont law, unless you authorize us to make those disclosures. Additional information concerning our privacy policies can be found at www.sunbit.com or by calling 855.678.6248.
    TAB Bank Privacy Notice

    Download »

    Rev. PRIV-MODEL 11/2023

    FACTS

    WHAT DOES TAB BANK DO WITH YOUR PERSONAL INFORMATION?
    Why?

    Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do.

    What?

    The types of personal information we collect and share depend on the product or service you have with us. This information can include:
    • Social Security number
    • Income
    • Payment history
    • Credit history
    • Employment information
    • Wire transfer instructions

    When you are no longer our customer, we continue to share your information as described in this notice.

    How?

    All financial companies need to share customers’ personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers’ personal information; the reasons TAB Bank chooses to share; and whether you can limit this sharing.

    Reasons we can share your personal information
    Does TAB Bank Share?
    Can you limit this sharing?
    For our everyday business purposes such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus Yes No
    For our marketing purposes to offer our products and services to you Yes No
    For joint marketing with other financial companies Yes No
    For our affiliates’ everyday business purposes information about your transactions and experiences No We don’t share
    For our affiliates’ everyday business purposes information about your creditworthiness No We don’t share
    For our affiliates to market to you No We don’t share
    For our nonaffiliates to market to you Yes Yes
    Questions?

    Call 1-855-678-6248

    To Limit our Sharing

    Call (toll free) 1-855-678-6248

    • Mail the form below

    If you are a new customer, with respect to those circumstances in which you can limit our sharing, we can begin sharing your information thirty (30) days from the date we sent this notice. When you are no longer our customer, we continue to share your information as described in this notice. However, you can contact us at any time to limit our sharing.

    —————————————————————————————————————————–

    Mail-in Form

    Mark any/all you want to limit:

    [  ] Do not share my personal information with nonaffiliates to market their products and services to me.

    Name

    Mail to:
    Transportation Alliance Bank
    c/o Sunbit
    Attention: Customer Support
    PO Box 24010
    Los Angeles, CA 90024

    Who we are

    Who is providing this notice?

    TAB Bank means Transportation Alliance Bank Inc. dba TAB Bank.

    What we do

    How does TAB protect my personal information?

    To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings.

    We also maintain other physical, electronic and procedural safeguards to protect this information and we limit access to information to those employees for whom access is appropriate.

    How does TAB collect my personal information?

    We collect your personal information, for example, when you

    • Open an account

    • Apply for a loan

    • Make deposits or withdrawals from your account

    • Provide employment information

    • Make a wire transfer

    We also collect your personal information from others, such as credit bureaus or other companies.

    Why can’t I limit all sharing?

    Federal law gives you the right to limit only

    • sharing for affiliates’ everyday business purposes – information about your creditworthiness

    • affiliates from using your information to market to you

    • sharing for nonaffiliates to market to you

    State laws and individual companies may give you additional rights to limit sharing. See below for more on your rights under state law.

    Definitions

    Affiliates

    Companies related by common ownership or control. They can be financial and non-financial companies.

    • TAB Bank does not share with our affiliates.

    Nonaffiliates

    Companies not related by common ownership or control. They can be financial and non-financial companies.

    • Nonaffiliates we share with can include bank partners, card issuers, or direct marketing companies.

    Joint marketing

    A formal agreement between nonaffiliated financial companies that together market financial products or services to you.

    • Our joint marketing partners include other financial service companies, insurance companies and direct marketing companies or providers of products or services that may be of interest to our customers.

    Other important information

    For Alaska, Illinois, Maryland and North Dakota Customers. We will not share personal information with nonaffiliates either for them to market to you or for joint marketing – without your authorization.
    For California Customers. We will not share personal information with nonaffiliates either for them to market to you or for joint marketing – without your authorization. We will also limit our sharing of personal information about you with our affiliates to comply with all California privacy laws that apply to us.
    For Massachusetts, Mississippi and New Jersey Customers. We will not share personal information from deposit or share relationships with nonaffiliates either for them to market to you or for joint marketing – without your authorization.

    By agreeing to this Policy, you expressly consent to receive marketing communications form us containing information about products and services that may be of interest to you.We collect your personal information, for example, when you

    • Open an account

    • Apply for a loan

    • Make deposits or withdrawals from your account

    • Provide employment information

    • Make a wire transfer

    We also collect your personal information from others, such as credit bureaus or other companies.