Statement of Commitment
Wellthi and its affiliates are committed to compliance with the privacy requirements of the Gramm-Leach-Bliley Act, 15 U.S.C. §§ 6801, et seq. (GLBA), as well as other applicable federal and state laws that govern the use and protection of nonpublic personal information. GLBA Title V governs the treatment of nonpublic personal information about consumers. It requires notice to consumers about a financial institution’s privacy policies and practices, describes when nonpublic personal information may be disclosed to nonaffiliated third parties, and provides mechanisms for consumers to “opt out” from information sharing in certain circumstances. It also imposes requirements to ensure that customer information is properly protected and secured.
This Policy is owned by the Compliance Officer and is reviewed, updated, and submitted to Executive Management at least annually.
Wellthi utilizes an electronic version of the Consumer Privacy Notice in alignment with the Issuing Bank’s requirements and consistent with the government’s model form. An updated version of the notice will be maintained on Wellthi’s website.
Collection of Information
We generally collect Personal Information in three ways: 1) information you provide to us, 2) information from third parties, and 3) information we collect automatically.
When you use, visit, or otherwise interact with the Services, for example, by contacting customer service, we collect Personal Information that you share with us or our third-party service providers. In order to establish a card account, Wellthi requests the customer to provider certain personal nonpublic information, including physical address, Social Security number, date of birth, email address, and other personal information that assist in verifying the identity of the individual. The full name, birth date and mobile phone number of a designee to help manage the account (often a spouse or partner) may also be requested to establish supplemental user rights to the applicant’s account, when available and if requested by the applicant.
If a minor requests that an account be created, we ask for the minor’s date of birth in order to determine whether the minor is eligible to set up their own account. Wellthi does not provide its Services to children younger than 18. We do not knowingly process any information from, or direct any of our products or services to children under the age of 18. Please do not provide us with any personal information related to children under the age of 18.
An account holder will often provide financial information to transfer funds from a bank account to fund the Wellthi account. This financial information is not provided to Wellthi. We use a third-party to affect this transfer of funds, and users provide the required information to transfer funds to our third-party vendor.
We may also obtain information about you from third parties, including, but not limited to, identity verification services, credit bureaus, financial institutions, and other users to verify your identity or account, detect fraud, engage in collections, or as may otherwise be required by applicable law.
Whenever you interact with the Services, we, as well as our service providers, may collect information about which of the Services you have used and how you have used them. This can include usage information, time and date of activities, location, IP address, operating system version, internet service provider identity, or other usage information. This information helps us manage, improve, and customize the Services’ features and functionality and can be used to identify you like Personal Information.
Use of Information
Wellthi will not share customers’ nonpublic personal information with non-affiliates. We may share customer information with affiliates to enable them to work on our platform system. Wellthi will only share customers’ personal information with contracted entities for everyday business purposes such as processing transactions, maintaining accounts, delivering benefits to your account, or responding to court orders and legal investigations. Some examples of how we may use your Personal Information include:
- create, maintain, customize, and secure your account with us;
- process and analyze account transactions and payments, notify you about them, and audit them, if needed;
- provide the Services and customer support to you; deliver service update notices and promotional offers, answer questions and respond to your requests, and otherwise to communicate with you;
- determine your location and the location of merchants, and correlate your location with transaction activity for the purpose of providing you services;
- maintain the security and integrity of the Services, our technology, assets and business; engage in detection and prevention of fraud or other illegal activities and debugging;
- enforce our Terms of Service and the Cardholder Agreement, including to prevent potential breaches;
- respond to law enforcement requests and as required by applicable law, court order, or governmental regulations;
- test, personalize, develop and improve the Services, including to create new analytics, algorithms, or other tools;
- lock and unlock your Wellthi card;
- use the information as reasonably necessary to achieve our operational or notified purpose for collecting personal information and as compatible with the context in which it was collected; and
- retain the information for as long as necessary for the above purposes, or for so long as required or permitted under applicable law.
- delivering account enhancements or benefits
- We will never share your personal information with third parties for marketing purposes
How We Share Personal Information
The Wellthi accounts are maintained at a network of local financial institutions and the Wellthi Card is issued by Central Bank of Kansas City. Wellthi shares Personal Information collected by us with the banks and financial institutions in order to establish accounts and have a prepaid account issued to the account holder.
Wellthi may also share Personal Information with third parties, as follows:
- Service Providers. We engage with select service providers who provide services to support our operations such as: partner banks and financial institutions, identity verification services, and collection agencies, web hosting, and other service providers. Such service providers will be limited to using your Personal Information to provide their services to Wellthi, or as otherwise permitted by law.
- Other Parties. As further described above, we may share your information when we have reason to believe that disclosing the information is necessary to prevent fraud, damage to person or property, protect and secure our business, assets, user accounts or enforce legal rights or comply with subpoena, court order, legal process or obligations. We reserve the right to disclose any Personal Information as needed if that information is requested by law enforcement agencies or if we are required to do so by law or court order.
- Successor Entities. We reserve the right to sell, disclose or transfer your Personal Information to a successor entity in the event of a corporate merger, consolidation, sale of assets or other corporate changes respecting Wellthi.
Please be aware that users of the Services may also themselves disclose Personal Information to others:
- Account holders may communicate with other account holders in the social networking aspect of the Wellthi App.
Wellthi may share aggregated customer information with third parties to offer partner or reward program benefits, so that Wellthi may offer you merchant promotions. However, this aggregated information does not identify a specific individual and does not contain Personal Identifiable Information (PII).
Your Rights and Choices
Wellthi maintains the preferences you have provided to us regarding the use, collection, and sharing of information, including how we may contact you.
- Communication & Marketing Preferences. You can update your preferences regarding information sharing and marketing communications by sending an email request to email@example.com. Please note that you may continue to receive emails with account-related information, even if you opt-out of marketing emails.
- Account Information. The primary account holder and any designee they manage to oversee the account and any sub-accounts linked to the primary account will have access to information about sub-accounts unless and until a sub-account is closed. If a sub-account is closed, the sub-account’s Personal Information may still be accessible to the linked primary accountholder or their designee if the primary account remains open after the sub-account is closed.
- Update Your Information. Your Personal Information can be reviewed and edited at any time by logging in to the primary account and reviewing your account settings and profile. It is your responsibility to make sure that your Personal Information is accurate, and you should promptly update your Personal Information on the Website or Application if your Personal Information changes or becomes inaccurate.
Protection of Information
We use reasonable administrative, technical, and physical security measures to protect such Personal Information against loss, misuse, and unauthorized access, disclosure, or alteration.
Children’s Privacy under age 18
We comply with the U.S. Children’s Online Privacy Protection Act and the regulations implementing it (“COPPA”), to the extent applicable to us and to the Services.
Wellthi does not offer Services requested by children under the age of 18 and we do not knowingly collect “personal information,” as defined under COPPA, directly from individuals under the age of 18.
Notice to California Residents
Collection, Use, and Disclosure of Personal Information
- See “Collection of Information” above for categories of Personal Information we collect, the sources from which, and how, we collected Personal Information
- See “Use of information” above for our business or commercial purposes for collecting personal information
- See “How We Share Personal Information” above for third parties with whom we share personal information
We will not collect additional categories of Personal Information or use the Personal Information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Your CCPA Rights and How to Exercise Them
If you are a California resident, you have certain rights, pursuant to the California Consumer Privacy Protection Act (“CCPA”). These CCPA rights may only apply in certain circumstances and are subject to certain exemptions. Please see the information below for a summary of your rights, how to exercise your rights and the information we require in order to respond to your requests. Please note that we may ask for certain information to verify the request in accordance with applicable law.
- Right to Know. You have the right to request that we disclose what Personal Information we collect, use, and/or disclose about you. To exercise your right to know, please Contact Us to submit your request. You will be required to provide certain information which we will use to verify you and your request.
- Right to Delete. You have the right to delete Personal Information that we collect or maintain about you. To request deletion of your information, please Contact Us to submit your request. You will be required to provide certain information which we will use to verify you and your request. Please note that certain exceptions apply to this right, such as when we retain your information to comply with law, or to complete the transaction for which the Personal Information was collected, or to detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity. We will notify you of any such exceptions as applicable to your request.
- Right to Opt-Out of Sale. We do not sell Personal Information within the meaning of the CCPA, and so do not offer a mechanism to opt-out or ask us not to sell your Personal Information.
- Right to Non-Discrimination. You have the right not to receive discriminatory treatment by us for the exercise of any of your CCPA rights. However, we may offer certain financial incentives, charge reasonable fees related to your requests, or deny your right to know, right to request deletion, or right to opt-out of sale in accordance with applicable law.
- Right to an Authorized Agent. You can exercise your CCPA rights yourself or you can designate an authorized agent to make a request on your behalf. Your authorized agent must be able to demonstrate authority to act on your behalf as further instructed when submitting a verifiable request.
Third-Party Marketing Disclosure
Under California Civil Code Section 1798.83 (the “Shine the Light” law), California residents with whom we have a business relationship can request certain information regarding what types of personal information, if any, we shared with third parties for the direct marketing purposes of the third parties and the identities of the third parties with whom the business has shared such information in the immediately preceding 12 months. Please Contact Us if you would like to receive this information.
Notice to Nevada Residents
We do not exchange your Personal Information for money with anyone so that they can license or sell the Personal Information to additional parties