This page uses JavaScript. Your browser either does not support JavaScript or you have it turned off. To see this page properly please use a JavaScript enabled browser.
Foothill Credit Union
Foothill Credit Union Go to main content
Routing/Transit #322273489 facebooktwitterInstagramyelpYouTube
Ask a Question 866-995-3328

Online Banking

Share Print Email

California Consumer Privacy Act

Effective 3/1/2020

These CALIFORNIA DISCLOSURES AND PRIVACY POLICY govern the information collected, used, and shared relating to the Foothill Credit Union (“we,” “us,” or “our”) and the associated site www.foothillcu.org and applies solely to visitors, users, and others who reside in the State of California (“consumers” or “you”).  We adopt this policy to comply with the California Consumer Privacy Act of 2018 (“CCPA”) and other California privacy laws.  Any terms defined in the CCPA have the same meaning when used in this policy.  These CALIFORNIA DISCLOSURES AND PRIVACY POLICY supplement our Federal Privacy Disclosure and California (SB1) Privacy Disclosure, Website Policy, and Security disclosure––all of which are posted here.

You can jump to the section by clicking the link:

  1. Personal Information We Collect
  2. Your Rights Under the California Consumer Privacy Act of 2018
  3. Submitting a Verified Consumer Request
  4. Submitting a Request to Opt-out
  5. Changes to our California Disclosures and Privacy Policy
  6. How to Contact Us
     

1.  Personal Information We Collect

We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with an individual consumer or device (“personal information”).

1.1.  Personal information does not include:

  • Publicly available information from government records
  • De-identified or aggregated consumer information
  • Information excluded from the CCPA, like:
    • health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data;
    • personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994.

1.2.  How we Obtain Your Personal Information:

  • Directly from you - You enter or provide us with information, whether online or by email, phone or document upload. For example, your contact information that you provide, your application for a loan, or documents you provide to verify your identity.
  • Directly and indirectly from you based on activity on our website - For example, from submissions through our website or website usage details collected automatically.
  • From vendors or third-parties that interact with us in connection with the services we perform - For example, companies that work with us to market our products to you, credit reporting agencies from which we check your credit in connection with a submitted application, or other vendors that provide data we use in underwriting or in protecting you and our products from fraud and identity theft.

1.3.  How We Use Your Personal Information:

We may use or disclose the personal information we collect for one or more of the following business
or commercial purposes:

  1. To fulfill or meet the reason for which the information is provided.
  2. To provide you with information, products or services that you request from us.
  3. To provide you with email alerts and other notices concerning our products or services, or events or news, that may be of interest to you.
  4. To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collections.
  5. To improve our website and present its contents to you.
  6. For testing, research, analysis and product development.
  7. As necessary or appropriate to protect the rights, property or safety of you, us or others.
  8. To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
  9. As described to you when collecting your personal information or as otherwise set forth in the CCPA.
  10. For marketing purposes, including with third parties.

We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.

1.4.  Who We Share Your Personal Information with for a Business or Commercial Purpose:

We may disclose your personal information to a service provider or third party for a business or commercial purpose. We may also disclose your personal information to third parties that in turn offer you insurance products or services in exchange for monetary or other valuable consideration. When we disclose personal information for a business or commercial purpose with service providers, we enter a contract that describes the purpose and requires the service provider to both keep that personal information confidential and not use it for any purpose except performing the contract.

Examples of who we share with include:

  • Our affiliates and lending partners
  • Service providers
  • Third parties, some of whom you or your agents authorize us to disclose your personal information in connection with products or services we provide to you.

1.5.  Within the last 12 months we collected the categories of personal information listed below and shared it as follows:

CCPA chart

1.6.  Sale of Personal Information:

We do not and will not sell the Personal Information of minors under 18 years of age.

2.  Your Rights Under the California Consumer Privacy Act of 2018

The CCPA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.

2.1.  Right to Know and Data Portability Rights:

You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months.  Once we receive and confirm your verifiable consumer request for access, we will disclose to you:

  • The categories of personal information we collected about you.
  • The categories of sources for the personal information we collected about you.
  • Our business or commercial purpose for collecting or sharing that personal information.
  • The categories of third parties with whom we share that personal information.
  • The specific pieces of personal information we collected about you (also called a data portability request).
  • If we disclosed your personal information for a business or commercial purpose, the categories of personal information shared with each category of recipients.

We may deny your request for access if we are unable to verify your identity or have reason to believe that the request is fraudulent.

2.2.  Right to Delete:

You have the right to request that we delete any of your personal information that we collected and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers and third parties to delete) your personal information from our records, unless an exception applies.

We may deny your deletion request if retaining the personal information is necessary for us or our service providers to:

  • Complete the transaction for which the personal information was collected, provide a good or service requested by the consumer, or reasonably anticipated within the context of a business's ongoing business relationship with the consumer, or otherwise perform a contract between the business and the consumer.
  • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity.
  • Debug to identify and repair errors that impair existing intended functionality.
  • Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law.
  • Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code.
  • Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the businesses' deletion of the information is likely to render impossible or seriously impair the achievement of such research, if the consumer has provided informed consent.
  • To enable solely internal uses that are reasonably aligned with the expectations of the consumer based on the consumer's relationship with the business.
  • Comply with a legal obligation.
  • Otherwise use the consumer's personal information, internally, in a lawful manner that is compatible with the context in which the consumer provided the information.

Additionally, we may deny your request to delete if we are unable to verify your identity or have reason to believe that the request is fraudulent.

2.3.  Right to Opt-Out:

We may also disclose your personal information to third parties that in turn offer you insurance products or services in exchange for monetary or other valuable consideration. You have the right to opt-out of the sale of your personal information.  See Section 4 below on how to submit a Request to Opt-Out.

We do not and will not sell the Personal Information of minors under 18 years of age.  

2.4.  Right to Non-Discrimination:

We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:

  • Deny you goods or services.
  • Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
  • Provide you a different level or quality of goods or services.
  • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

3.  Submitting a Verified Consumer Request

3.1.  Exercising Right to Know, Data Portability, and Right to Delete:

To exercise the access, data portability, and deletion rights described above, please submit a verifiable consumer request to us by either:

  • Calling us at (866) 995-FFCU or (626) 445-0950
  • or by using this form

Making a verifiable consumer request does not require you to create an account with us.

Only 1) you, 2) a person authorized by you to act on your behalf, or 3) an entity registered with the California Secretary of State and authorized by you to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.

You may only make a verifiable consumer request for access (aka Right to Know) or data portability twice within a 12-month period. The verifiable consumer request must:

  • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.  Given the sensitivity of your personal information that we collect and retain, we will need to verify your identity with at least 3 separate pieces of information such as name, address, account number, date of birth, last 4 of your Social Security Number, phone number, etc.  If you are making a data portability request and are not verifying your identity through an existing account, you will be required to submit a declaration under the penalty of perjury.
  • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

3.2.  Authorized Agents:

Before we can respond to a verifiable consumer request submitted by an authorized agent, we need to confirm not only that person or entity’s authority to act on behalf of a consumer and verify the identity of the authorized agent.  If you are authorized to submit a request on behalf of a California resident, please email us at CPPA@foothillcu.org and provide the following information:

  1. To verify your authorization to request on behalf of a California resident, please attach a copy of one or more of the following to your request email:
    • California Secretary of State authorization,
    • written permission from the California resident, or
    • power of attorney
  2. To verify your identity, please attach copies of the following to your request email:
    • Valid Government Issued ID (not expired) AND
    • a Utility Bill, Bank Statement, or similar documentation to verify your name and address
  3. You will also be required to verify the identity of the consumer for whom you are submitting the request.

We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. We will only use personal information provided in a verifiable consumer request to verify the requestor's identity or authority to make the request.

3.3.  Response Timing and Delivery Method:

We will acknowledge receipt of the request within 10 business days of its receipt.  We will respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request's receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will provide the responsive information in a portable and, to the extent technically feasible, in a readily useable format that allows you to transmit the information to another entity without hindrance.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

4.  Submitting a Request to Opt-out

4.1.  How consumers can opt-out:

To submit a Request to Opt-Out yourself, you may either:

  • Complete this form, or
  • Email us at CPPA@foothillcu.org.  Your email needs to include the following information:  3 separate pieces of information such as name, address, account number, phone number.

4.2.  How a consumer can opt-out via an authorized agent:

A consumer may also submit a Request to Opt-Out using an authorized agent.  To do so, the authorized agent needs to email us at cu@foothillcu.org.  The email must to include the following information: 

  • 3 separate pieces of information such as name, address, account number, phone number of the consumer, and
  • proof that the authorized agent is authorized to act on behalf of the consumer with one or more of the following:
  • California Secretary of State authorization,
  • written permission from the California resident, or
  • power of attorney.

4.3.  Response to Requests to Opt-Out:

Once we receive your Request to Opt-Out, we will process the opt-out within 15 business days and we will communicate your opt-out to any company we sold your Personal Information to.  We will continue to honor your request for 12 months from the day we received your Request to Opt-Out.  

5.  Changes to our California Disclosures and Privacy Policy

We reserve the right to amend these CALIFORNIA DISCLOSURES AND PRIVACY POLICY at our discretion and at any time. When we make changes to these CALIFORNIA DISCLOSURES AND PRIVACY POLICY, we will notify you by email or through a notice on our website homepage.

6.  How to Contact Us

If you have any questions or comments about this policy, the ways in which we collect and use your personal information, your rights regarding such use, or wish to exercise your rights under California law, please do not hesitate to contact us at:

  • Privacy Support Phone: (866) 995-FFCU or (626) 445-0950
  • Privacy Support email: CPPA@foothillcu.org
  • Website: www.foothillcu.org
  • Postal Address: Foothill Credit Union, Attn: Foothill Privacy, P.O. Box 660130, Arcadia, California 91066-0130

 

Go to main navigation