|
I. IntroductionBeach Cities Commercial Bank (“BCCB” or “we” or “us”) respects your privacy. This Privacy Policy (this “Policy”) describes our policies and practices with respect to our collection, protection, use and sharing of personally identifiable information (“PII”). For purposes of this Policy, PII about you means information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your communications device (computer, tablet, mobile phone, etc.). We commit to using PII responsibly and safeguarding it according to our detailed security standards. In no event do we sell your or others’ PII. We may add to, delete or change the terms of the Policy from time to time. When we make changes, we will post the amended policy on this website, beachcitiescb.com (the “Site”). Any changes to the Policy will become effective immediately upon our posting of the Policy, and your use of the Site and our services is deemed to constitute your agreement with the Policy terms. Please be sure to check the Policy before providing us with PII. We encourage you to review the Policy carefully as it relates to your experience with BCCB, from the outset when exploring a potential partnership, to opening and maintaining an account with us, and including the introduction of additional services that support your evolving financial needs. If you are, or apply to become, a customer of BCCB with respect to products or services to be used primarily for personal, family or household purposes, you have additional privacy rights, as reflected in our customer privacy notice, available at: www.beachcitiescb.com II. How Does Beach Cities Commercial Bank Collect Your PII and What Types of PII Does It Collect?BCCB collects PII about you when you actively provide it to us, such as by completing an Online form, providing PII at your discretion or responding to a request for information, and when you interact with us Online, such as browsing our website. For example, if you decide to opt in to any of our communications options, such as receiving text messages at a number you provide or emails at an email address you provide, we will collect the number or email address, and we will collect any additional PII you may send to us by text, email or otherwise. We also may collect PII about you from the following sources: the Internet, including social media websites and other websites; conferences; the press or other print media; credit reporting agencies; and other persons (including persons who might refer you to us for a possible customer relationship) and organizations as permitted under applicable law. Not all information that we collect from you is PII. We may collect information about you that we cannot use to identify you specifically. Listed below are the types of information about you that we may have collected within the past 12 months. These types of information are PII only if the information identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your device.
III. Our Business Purposes for Collecting PII; How We Use the InformationWe may use the PII we collect from you for a variety of purposes permitted by law, including:
IV. When and With Whom We Share Personally Identifiable InformationWe may share the PII we collect with our service providers. We engage service providers to deliver services to you on our behalf, such as bill payment, money transfers, check processing, wiring services and payment solutions; and to assist us with technology support, operational support and other forms of assistance. We bind our service providers to protect the confidentiality and security of the PII we share with them. We also share PII with others as we believe to be necessary or appropriate, consistent with applicable law, for the following purposes: (a) to comply with applicable legal requirements (for example, responding to subpoenas) and regulatory requirements (for example, monitoring of fair lending law compliance); (b) to respond to requests from public and government authorities; (c) to enforce and investigate violations of applicable Terms and Conditions; (d) to protect our rights, privacy, safety or property, you or others; (e) to allow us to pursue available remedies or limit the damages that we may sustain; and (f) to evaluate or conduct a merger, divestiture, restructuring, reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets or stock. Other than for these purposes, we do not share PII with third parties and in no event do we sell PII. We do not share PII with non-affiliated entities for those entities to use for their own marketing purposes. V. Other Information Collection, Use and SharingWe also may collect, use, and share information that is not PII as follows:
VI. SecurityTo help prevent unauthorized access to any of your PII, we seek to use reasonable organizational, technical, and administrative measures to protect the PII we maintain within our organization. In addition to the safeguards, we apply to protect your PII, there are steps you can take to protect it as well, such as never sharing your passwords and maintaining them in a secure location. The steps you take to complement the many safeguards we apply are particularly important. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us of the problem by contacting us at 949.704.1010. VII. Control Over Your Personally Identifiable InformationIf you would like to update PII that you have provided to us, you may contact us through one of the means listed in the “How to Contact Us” section below. Note that certain information is required to provide the services; requests to delete required information may result in our inability to provide the services. VIII. California Residents’ Privacy RightsIf you are a resident of California, you have certain privacy rights under the California Consumer Privacy Act (“CCPA”). We honor those rights, as described below, and we are prohibited by law from discriminating against you for exercising any of those rights. A. Right to KnowSubject to the exemption and exceptions mentioned below, if you are a California resident, you have the right to know what PII we have collected about you, why we collected it, and the categories of third parties (excluding service providers) with whom we have shared the PII during the past 12 months. (See below on “How to Submit a Request.”) You may request that we provide a description of the categories of PII we have collected (a “Categories Request”) or a request for access to the specific pieces of PII we have collected (a “Specific Pieces Request”). If you make a Categories Request, and you do not have any type of account with us, we will need you to provide us with at least two data elements specific to you, such as your cell phone number or mother’s maiden name (depending on the data elements we already maintain about you), so that we can verify your identity. After we confirm that your request is a verifiable consumer request, we will disclose to you:
If you make a Specific Pieces Request, we need to be sure we have verified your identity with great certainty to safeguard your privacy. In order for to verify your identity, if you do not have any type of account with us, you will need to provide to us at least three data elements specific to you, together with a signed declaration under penalty of perjury that you are the consumer whose personal information is the subject of the request. After we confirm that your request is a verifiable consumer request, we will disclose to you:
B. Right to Request DeletionYou have the right to request that we delete any of your PII that we collected from you and retained, other than Personal Customer Information (as defined above). We are not obligated to comply with your request if we have a legal basis to retain the PII. If you make a request for us to delete PII, and you do not have any type of account with us, we may need you to provide us with at least two data elements specific to you so that we can verify your identity. Once we receive and confirm that your request is a verifiable consumer request (see below on “How to Submit a Request”), we will inform you whether we have deleted (and have directed our service providers to delete) your PII from our records, or whether we are declining to grant your request to delete due to an exception to the CCPA deletion requirements. C. ExceptionsCertain PII is protected by federal and state privacy law other than the CCPA and thus the specific rights described above do not apply in the case of that PII. Specifically:
D. How to Submit a RequestTo request access to or deletion of your PII as described above, please submit a verifiable consumer request to us by either:
Beach Cities Commercial Bank You may make a request on your own behalf, and if you are the parent or guardian of a minor child, you also may make a request related to your child’s PII. If you wish to designate an authorized agent to make a request on your behalf, please provide us with a signed declaration stating that your intent is to permit that individual to act on your behalf and include such individual’s full name, address, email address and phone number. That way we will be sure you have fully authorized us to act in accordance with the requests of that individual. To protect your PII from unauthorized disclosure or deletion at the request of someone other than you or your legal representative, BCCB requires identification verification before granting any request to provide copies of, know more about or delete your PII. We take special precautions to help ensure this. Specifically, we require that any request submitted to us:
We cannot respond to your request or provide you with PII if we cannot verify your identity or authority to make the request and confirm that the PII relates to you. We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to 45 additional days), we will inform you of the reason and extension period in writing. We will only use PII provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request. IX. Information RetentionWe retain information, including PII, for as long as necessary to achieve the purpose for which it was collected, to fulfill legal or contractual obligations, or for as long as permitted by applicable law. We may retain aggregated or de-identified information indefinitely. X. Scope of UsersOur online products and services, including our website and mobile applications, are not directed to users under the age of 13. We do not knowingly collect PII online from any person we know to be under the age of 13. XI. Do Not Track SignalsYour browser may allow you to send us a “do-not-track signal” to communicate your privacy preferences to us. Our website currently does not respond to browser do-not-track signals. XII. Links to Other WebsitesOur website and mobile applications may feature links to third-party websites that offer goods, services, or information. When you click on one of these links, you will be accessing content and services that are not subject to this Policy. We are not responsible for the information-collection practices of the other websites that you visit and urge you to review their privacy policies before you provide them with any PII. Third-party sites or services may collect, use, and secure information about you in a way that is different from those described in this Policy. XIII. How to Contact UsIf you have any questions regarding this Policy, you can call us at 949.704.1010 or write to us at: Beach Cities Commercial Bank |