Updated/Effective date: July 28, 2020
Before you use or submit any information on or through the Platform, please carefully review this Policy. By using any part of the Platform, you consent to the collection, use, and disclosure of the information you provide as further outlined in this Policy. We will continue to evaluate this Policy as we update and expand the Platform and our offerings, and we may make changes to the Policy accordingly. Any changes will be incorporated into this Policy and posted on the Platform. Your continued use of the Platform will signify acceptance of the terms of the updated Policy.
- Privacy of Joint Applicants
If you are using the Platform with another person to apply jointly for a loan or other financial services product, you and your co-applicant may choose to provide information for your application using a single joint Platform account or multiple individual Platform account(s). If joint applicants choose to utilize a single Platform account, they will have access to all information supplied by Platform account users to complete that application. Such joint applicants will have the ability to view, print, transmit, save, and/or edit the information. Access may continue for as long as the joint applicants utilize the single Platform account in connection with the application process.
- What Information Does CANDID Collect?
- Categories of Information
We collect the following categories of information. The exact information we collect about you depends on the data collection practices of your Financial Services Provider, what products/services you use and how you use our Platform and interact with us. We base the information in this disclosure on our data collection practices over the previous 12 months until present time.
Identifiers (such as a real name, postal address, IP address, email address, social security number, or other similar identifiers);
Commercial information (such as transactional data or records of personal property, or other purchasing or consuming histories or tendencies);
Financial information (such as financial history);
Internet or other network or device activity (such as browsing history and log data);
Geolocation information (such as general location information inferred from an IP address);
Professional or employment related data (such as information you provide about your work history);
Education data (such as information about your educational institutions and history);
Characteristics of protected classifications under state or federal law (such as gender and marital status);
Physical characteristics or description;
Inference data about you (such as profiles we develop based on how you use our Platform); and
Other information that identifies or can be reasonably associated with you.
- Categories of Sources of Information
We collect information in multiple ways, including when you provide information directly to us and when we passively collect information from you, such as from your browser or device.
Information You Provide Directly to Us
We may collect information from you during your use of or access to the Platform, such as when you:
Register for a CANDID Platform account;
Enter information in the CANDID Platform;
Communicate with us; or
Connect with your third-party accounts to retrieve your information.
For example, through the registration process and/or through your Platform account settings, we may collect information such as your email address, account password, and recovery phone number for creating and authenticating a CANDID Platform account (CANDID Account Credentials”). We may also collect third-party account credentials (e.g., your log-in credentials for accessing your bank account or tax return information) (Third-Party Account Credentials”), as well as contact, financial, and other information that may be used for the purpose of retrieving information from third-parties. We will also collect information from the accounts you authorize us and others to access on our or the Financial Services Provider’s behalf that is used in connection with applications for financial services products. All such information we collect from you through or in connection with the Platform is covered by this Policy.
Information Collected Passively
Device/usage information: We may automatically collect certain information about the computer or devices (including mobile devices or tablets) you use to access the Platform. We may collect and analyze information such as (a) IP addresses (including city and state information), unique device identifiers, IMEI and TCP/IP addresses, and other information about your computer or device(s), browser types, browser language, operating system, mobile device carrier information, and the state or country from which you accessed the Platform; and (b) information related to the ways in which you interact with the Platform, such as referring and exit web pages and URLs, platform type, number of clicks, domain names, landing pages, pages and content viewed and the order of those pages, statistical information about the use of the Platform, amount of time spent on particular pages, date and time you used the Platform, frequency of your use of the Platform, error logs, and other similar information. As described further below, we may use third-party analytics providers and technologies, including cookies and similar tools, to assist in collecting this information.
Cookies and Other Electronic Technologies: We may also collect data about your use of the Platform through the use of internet server logs, cookies, and/or tracking pixels. An internet server log is a file where website activity is stored. A cookie is a small text file that is placed on your computer when you visit a website that enables us to: (i) recognize your computer; (ii) store your preferences and settings; (iii) understand the web pages of the Platform you have visited; (iv), enhance your user experience by delivering content specific to your interests; (v) perform searches and analytics; and (vi) assist with security administrative functions. Some cookies are placed in your browser cache. Tracking pixels (sometimes referred to as web beacons or clear GIFs) are tiny electronic tags with a unique identifier that are embedded in websites, online ads, and/or email and are designed to provide usage information like page clicks, measure popularity of the Platform and associated content, and access user cookies. We may update this Policy from time to time as we adopt new technologies to gather additional information through other methods.
Blocking cookies through your browser settings : Please note that you can change your settings to notify you when a cookie is being set or updated, or to block cookies altogether. Please consult the “Help” section of your browser (e.g., Internet Explorer ; Google Chrome ; Mozilla Firefox ; or Apple Safari ) for more information. Please note that by blocking any or all cookies, you may not have access to certain features or offerings of the Platform.
Information from Third Parties
We may also obtain information about you from third parties such as other financial institutions with which you have a relationship, third-party data access providers (see below) and credit reporting agencies, among others. These third parties provide data, products, and services that enable us to provide the Services through the Platform.
- How Will CANDID Use My Information?
CANDID may use the information we collect from and about you for business purposes (as defined by applicable law) and commercial purposes, such as:
Performing services on behalf of the business or other service providers, including maintaining or servicing accounts, processing or fulfilling transactions, verifying customer information, processing payments, providing financing, providing analytic services, or providing similar services on behalf of the business or service provider. Specifically, this may include:
Processing and fulfilling a transaction or to providing products or services through or in connection with the Platform (e.g., to pull relevant information from your financial accounts to assist in compiling documentation for your Financial Services Provider and others);
Facilitating your registration for a CANDID Platform account;
Sending you information about your Platform-related activities;
Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
Debugging to identify and repair errors that impair existing intended functionality (i.e. to administer and troubleshoot the Platform).
Short-term, transient use, provided that the personal information is not disclosed to another third party and is not used to build a profile about a consumer or otherwise alter an individual consumer’s experience outside the current interaction.
Undertaking internal research and reporting;
For technological development and demonstration, including to improve the content and features of the Platform or develop or deliver new products or services;
Contacting you with information or surveys regarding our Platform;
Processing and responding to your inquiries or to request your feedback;
Personalizing the content that you see on the Platform (see How Does CANDID Personalize Content to My Interests?” section below); and
Enforcing the legal terms that govern your use of the Platform.
In addition to the use of your information to process your loan or other financial services transaction, we may also aggregate and/or de-identify the information we collect. We may use aggregated and/or de-identified information for improving the Platform and developing business analytics, and may also share such information and analytics with third parties.
How Does CANDID Personalize Content to My Interests?
Online and Email Analytics: We may use third-party web analytics services on the Platform, such as those of Google Analytics. These service providers use the sort of technology previously described in the Cookies and Other Electronic Technologies” section to collect information (including your IP address) to help us analyze how users use the Platform, including by noting the third-party website from which you arrive, providing certain features to you, improving and developing the Platform, monitoring and analyzing use of the Platform, aiding our technical administration, assisting in our troubleshooting and customer support efforts, and verifying that users have the authorization needed for us to process their requests. To prevent Google Analytics from using your information for analytics, you may install the Google Analytics Opt-out Browser Add-on by clicking here . If you get a new computer, install a new browser, erase or otherwise alter your browser’s cookie file (including upgrading certain browsers), you may clear the Google Analytics opt-out cookies, and you will need to re-visit the relevant opt-out page. If you receive email communication from us, we may use certain tools, such as clear GIFs, to capture data such as when you open our message or click on any links or banners our email contains.
Notice Concerning Do Not Track Signals: Do Not Track (DNT”) is a privacy preference that users can set in certain web browsers. We are committed to providing you with meaningful choices about the information collected on the Platform for third-party purposes, and that is why we provide choices provided by Google Analytics. However, we do not recognize or respond to browser-initiated DNT signals, as the internet industry is currently still working toward defining exactly what DNT” means, what it means to comply with DNT, and a common approach to responding to DNT. You can learn more about DNT by clicking here.
- How Will CANDID Share My Information?
We may share all of the categories of information identified above in Section 2 with the following categories of third parties as described in this section. We base the information in this disclosure on our data sharing practices over the previous 12 months until present time.
Affiliates and Subsidiaries of CANDID . We may share information we collect with other members of the CANDID family of companies (e.g., CANDID Insurance) on behalf of your Financial Services Provider to deliver products and services to you, ensure a consistent level of service across our products and services, and enhance our products, services, and your customer experience.
Service Providers . We may provide access to or share your information with select third parties who perform services on our behalf to facilitate the operation and functionality of the Platform. For example, we may use companies that assist with billing, customer support, fulfillment, data storage, analysis and processing, and legal services. We may also provide access to or share information with third parties as necessary to effect, administer, or enforce a transaction that you request or authorize.
Consent . On behalf of your Financial Services Provider we may also share your information with other third parties after obtaining your consent.
Protection of CANDID and Others . By using the Platform, you acknowledge, consent, and agree that we may access, preserve, and disclose your information, including but not limited to any user content, if required to do so by law or in a good faith belief that such access, preservation, or disclosure is reasonably necessary to: (a) comply with legal process; (b) enforce our Terms of Service, this Policy, or other contracts with you, including investigation of potential violations thereof; (c) respond to claims that any content violates the rights of third parties; (d) respond to your requests for customer service; and/or (e) protect the rights, property, or personal safety of CANDID, its agents and affiliates, and/or its users and/or the public. This includes exchanging information with other companies and organizations for fraud protection, spam/malware prevention, and similar purposes.
Business Transfers . As we continue to develop our business, we may buy or merge with other companies. In such transactions (including in contemplation of such transactions, e.g., due diligence), user information may be among the transferred assets. If a portion or all of CANDID’s assets are sold or transferred to a third party pursuant to a corporate purchase, sale, or merger, customer information may be one of the transferred business assets.
- How Does CANDID Secure My Data?
We have implemented administrative, technical, and physical security measures via third party vendors to protect against the loss, misuse, and/or alteration of your information. These safeguards vary based on the sensitivity of the information that we collect and store. However, we cannot and do not guarantee that these measures will prevent every unauthorized attempt to access, use, or disclose your information because despite our efforts, no internet and/or other electronic transmissions can be completely secure.
We recommend that you change your password periodically. You are responsible for maintaining the security of your Platform account username and password. If you believe that your Platform account username and/or password have been stolen or been made known to others, it is your responsibility to immediately contact us at email@example.com and change your password. We are not responsible if someone else accesses your Platform account through information they have obtained from you.
- What Choices Do I Have?
Updating and Deleting Your Information . You may be able to add, update, or delete certain information through the Platform. When you update information, however, we may maintain a copy of the unrevised information in our records for legal compliance purposes. Any information that cannot be updated or deleted through the Platform will require you to contact the Financial Services Provider for further assistance. Additionally, to the extent applicable law affords you rights to your personal information, such as access and deletion rights, please reach out to your Financial Services Provider to inquire about your data rights. We retain the information we process for as long as needed to provide services to the Financial Services Provider, including providing information to successors-in-interest throughout the term of the transaction. We may retain some of the information for reasons including, but not limited to, compliance with applicable banking and lending regulations, resolving disputes, and enforcing our agreements. We may also continue to use any aggregated or de-identified information but not in a manner that would identify you personally.
Account Access for Providing Financial Services . If you no longer want us or our data access providers to obtain information from your financial accounts on behalf of your Financial Services Provider, please email us at firstname.lastname@example.org
- California Residents.
This section of the Policy applies solely to those individuals who reside in the State of California (“consumers” or “you”). We are providing this policy in compliance with the California Consumer Privacy Act of 2018 (“CCPA”) and other applicable California privacy laws. Any terms used in this Notice that are not defined in the Notice itself have the same definition as used in the CCPA and its implementing regulations.
Right to Know
Right to Delete
California law provides California consumers with the right to request that certain covered businesses delete personal information that they have collected from you. This Right to Delete” is subject to certain exceptions. CANDID will not respond to requests pursuant to this right if made directly by a consumer because we are a Service Provider to your Financial Services Provider. To request deletion of specific pieces of personal information CANDID collects about you on the Platform, please reach out to your Financial Services Provider. Please note, we need certain types of information so that we can provide the services to you. If you request deletion of your information through your Financial Services Provider and we are required to delete your information, you may no longer be able to access or use the services we provide.
When a consumer uses an authorized agent to submit a request to know or a request to delete, a business may require that the consumer do the following (this does not apply when a consumer has provided the authorized agent with power of attorney pursuant to Probate Code sections 4000 to 4465):
Provide the authorized agent signed permission to do so.
Verify their own identity directly with the business.
Directly confirm with the business that they provided the authorized agent permission to submit the request.
A business may deny a request from an authorized agent that does not submit proof that they have been authorized by the consumer to act on their behalf.
To make an authorized request on behalf of another pursuant to consumer rights provided by California Law, please reach out to your Financial Services Provider for instructions.
We do not offer financial incentives for the collection of your data. If this changes, we will notify you prior to doing so, and we will obtain your consent to opt-in to this program before enrolling you.
You also have the right to not be discriminated against for exercising certain of your rights under the CCPA. If you exercise your rights under the CCPA, we will not:
Deny you goods or services.
Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
Provide you a different level or quality of goods or services.
Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
How other data privacy laws may affect your ability to request access to, or delete, your data
Please note that your rights and choices regarding your personal information are often subject to other laws. Personal information collected pursuant to other laws, such as information governed by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, and the California Financial Information Privacy Act, may be exempt from requests to access or delete data.
We are a technology Service Provider
We are a Service Provider as defined by the CCPA and we process your information on behalf of banks, mortgage companies, and other lenders (Financial Services Providers”). To the extent California law allows you to make certain requests including access to personal information or requests to delete Personal Information, you must make these requests directly to your Financial Services Provider.
If you have any questions regarding your rights under California law, you may reach out to us at email@example.com
- Nevada Residents.
Under Nevada law, certain Nevada consumers may opt out of the sale of personally identifiable information” for monetary consideration to a person for that person to license or sell such information to additional persons. Personally identifiable information” includes first and last name, address, email address, phone number, Social Security Number, or an identifier that allows a specific person to be contacted either physically or online. We do not engage in such activity; however, if you are a Nevada resident who has purchased or leased goods or services from us, you may submit a request to opt out of any potential future sales under Nevada law by emailing firstname.lastname@example.org. Please note we will take reasonable steps to verify your identity and the authenticity of the request. Once verified, we will maintain your request in the event our practices change.
- What Is CANDID’s Responsibility for Third-Party Links on the Platform?
The Platform may contain links to or frame” third-party websites, applications, and other services available to support Platform operations and functionality. Please be aware that we are not responsible for the privacy practices of such other sites and services. We encourage our users to be aware when they access third-party websites and/or leave the Platform and to read the privacy statements of each and every site they visit that collects their information.
- What Is CANDID’s Policy on Children?
We do not knowingly collect or solicit personal information (as defined by the Children’s Online Privacy Protection Act”) from anyone under the age of 13. If you are under 13, please do not attempt to register for the Platform or send any personal information about yourself to us. If we learn that we have collected personal information from a child under age 13, we will delete that information as quickly as possible. If you believe that a child under 13 may have provided us personal information, please contact email@example.com.
- Retention of Your Information
We keep your information in identifiable form for no longer than necessary for the purposes for which it is processed. The length of time for which we retain information depends on the purposes for which we collected and use it and/or as required to comply with applicable laws.
- Will CANDID Change This Policy?
We reserve the right to change this Policy at any time to reflect changes in the law, our data collection and use practices, the features of the Platform, or advances in technology. Please check this page periodically for changes. Your continued use of the Platform following the posting of changes to this Policy will mean you accept those changes.