This Privacy Policy describes the privacy practices of Firstcard, Inc. and our affiliates (collectively,"Firstcard," "we", “us”, or "our") and how we handle personal information that we collect through our digital properties that link to this Privacy Policy, including our website and mobile application(collectively, the “Service”), as well as through social media, our marketing activities, and other activities described in this Privacy Policy.
You can download a printable copy of this Privacy Policy here.
Index
Personal information we collect
Information you provide to us
Personal information you may provide to us through the Service or otherwise includes:
- Contact data, such as your first and last name, salutation, email address, mailing address, and phone number.
- Profile data, such as the username and password that you may set to establish an online account with us, your contact data, residence address, date of birth, college, university or other institution name and student identification number, biographical details, and any other information that you add to your account profile.
- Communications data that we exchange with you, including when you contact us with questions or feedback, through the Service, social media, or otherwise.
- Marketing data, such as your preferences for receiving our marketing communications and details about your engagement with them.
- Financial data, such as the payment card number and routing number associated with yourFirstcard account, and your purchase and transaction history.
- Rewards and transaction data, such as your transaction and purchase history and rewards earned through your Firstcard account.
- Government-issued identification numbers, such as Social Security Number, tax identification number, passport number, state or local identification number (e.g., driver’s license or state ID number), and an image of the relevant identification card.
- Promotional information, including your contact data and other information you share when you enter any sweepstakes, contests, or promotions that we may offer through the Service.These sweepstakes, contests and promotions are voluntary. We recommend that you read the rules and other relevant information for each sweepstakes and contest that you enter.
- Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
Third-party sources
We may combine personal information we receive from you with personal information we obtain from other sources, such as:
- Public sources, such as government agencies, public records, social media platforms, and other publicly available sources.
- Data providers, such as information services and data licensors that provide demographic and other information.
- Our affiliate partners, such as our affiliate network provider and publishers, influencers, and promoters who participate in our paid affiliate programs.
- Marketing partners, such as joint marketing partners and event co-sponsors.
If you choose to login to the Service via a third-party platform or social media network, or otherwise connect your account on the third-party platform or network to your account through the Service, we may collect information from that platform or network. For example, this information may include yourFacebook username, user ID, profile picture, cover photo, and networks to which you belong (e.g.school, workplace). You may also have the opportunity to provide us with additional information via the third-party platform or network, such as a list of your friends or connections and your email address.
Automatic data collection
We, our service providers, and our business partners may automatically log information about you, your computer or mobile device, and your interaction over time with theService, our communications and other online services, such as:
- Device data, such as your computer’s or mobile device’s operating system type and version, manufacturer and model, browser type, screen resolution, RAM and disk size, CPU usage, device type (e.g., phone, tablet), IP address, unique identifiers (including identifiers used for advertising purposes), language settings, mobile device carrier, radio/network information (e.g., Wi-Fi, LTE,3G), and general location information such as city, state or geographic area.
- Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, the website you visited before browsing to the Service, navigation paths between pages or screens, information about your activity on a page or screen, access times and duration of access, and whether you have opened our marketing emails or clicked links within them.
- Precise geolocation data when you authorize the Service to access your device’s location.
Cookies and similar technologies
Like many online services, we use the following technologies:
- Cookies, which are text files that websites store on a visitor‘s device to uniquely identify the visitor’s browser or to store information or settings in the browser for the purpose of helping you navigate between pages efficiently, remembering your preferences, enabling functionality, helping us understand user activity and patterns, and facilitating analytics and online advertising. Our sites may use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your computer or mobile device until you delete them). Some of these cookies are served by third party service providers or business partners and can be used by these parties to recognize your computer or mobile device when it visits the Service and other online services.
- Local storage technologies, like HTML5 and Flash, that provide cookie-equivalent functionality but can store larger amounts of data, including on your device outside of your browser in connection with specific applications.
- Web beacons, also known as pixel tags or clear GIFs, which are used to demonstrate that a webpage or email address was accessed or opened, or that certain content was viewed or clicked.
- Software Development Kits (SDKs), which are used to incorporate third party computer code into the Service that allows our third party service providers or advertising partners to collect data directly from the Service for a variety of purposes, including to provide us with analytics regarding the use of the Service, to integrate with social media, add features or functionality to the Service, or to facilitate online advertising.
- Session Replay Technologies, may use third party services that employ software code to record users’ interactions with the Services in a manner that allows us to watch DVR-like replays of those user sessions. These replays may include users’ clicks, mobile app touches, mouse movements, scrolls and keystrokes during those sessions. These replays help us diagnose usability problems and identify areas for improvement.
These technologies may be employed for the following purposes:
- Advertising. Used by advertising companies to collect information about how you use our websites and other websites over time. These companies use this information to show you ads they believe will be relevant to you within our services and elsewhere, and to measure how the ads perform.
- Analytics. Help us understand how our services are performing and being used. These cookies may work with web beacons included in emails we send to track which emails are opened and which links are clicked by recipients. For example, we use Google Analytics to help us understand user activity on the Service. You can learn more about Google Analytics cookies at https://developers.google.com/analytics/resources/concepts/
gaConceptsCookies and about how Google protects your data at http://www.google.com/analytics/learn/privacy.html. You can prevent the use of Google Analytics relating to your use of our sites by downloading and installing a browser plugin available at https://tools.google.com/dlpage/gaoptout?hl=en. - Essential. Necessary to allow the technical operation of our services (e.g., remember preferences you set or information you entered on a previous page).
Data about others
Users of the Service may have the opportunity to refer friends or other contacts to us and share their contact information with us. Please do not refer someone to us or share their contact information with us unless you have their permission to do so.
How we use your personal information
We may use your personal information for the following purposes or as otherwise described at the time of collection:
Service delivery
We may use your personal information to:
- provide, operate and improve the Service and our business;
- facilitate your invitations to friends who you want to invite to join the Service;
- communicate with you about the Service, including by sending announcements, updates,
security alerts, and support and administrative messages; - understand your needs and interests, and personalize your experience with the Service and our communications; and
- provide support for the Service, and respond to your requests, questions and feedback.
Research and development
We may use your personal information for research and development purposes, including to analyze and improve the Service and our business. As part of these activities, we may create aggregated, de-identified, or other anonymous data from personal information we collect. We make personal information into anonymous data by removing information that makes the data personally identifiable to you. We may use this anonymous data and share it with third parties for our lawful business purposes, including to analyze and improve the Service and promote our business.
Marketing and advertising
We, our service providers and our third-party advertising partners may collect and use your personal information for marketing and advertising purposes:
- Direct marketing. We may send you Firstcard -related or other direct marketing communications as permitted by law. You may opt-out of our marketing communications as described in the Opt-out of marketing section below.
- Interest-based advertising. We may engage third-party advertising companies and social media companies to display ads on our Service and other online services. These companies may use cookies and similar technologies to collect information about your interaction (including the data described in the automatic data collection section above) over time across the Service, our communications and other online services, and use that information to serve online ads that they think will interest you. This is called interest-based advertising. We may also share information about our users with these companies to facilitate interest-based advertising to those or similar users on other online platforms. You can learn more about your choices for limiting interest-based advertising in the Your choices section.
Compliance and protection
We may use your personal information to:
- comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities;
- protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims);
- audit our internal processes for compliance with legal and contractual requirements and internal policies;
- enforce the terms and conditions that govern the Service; and
- prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal
activity, including cyberattacks and identity theft.
To create anonymous, aggregated
or de-identified data
We may create anonymous, aggregated or de-identified data from your personal information and other individuals whose personal information we collect. We make personal information into anonymous, aggregated, or de-identified data by removing information that makes the data identifiable to you. We may use this anonymous, aggregated, or de- identified data and share it with third parties for our lawful business purposes, including to analyze and improve the Service and promote our business.
Retention
We retain personal information as necessary to perform services, to satisfy legal, accounting, or reporting requirements, to establish or defend legal claims, for fraud prevention purposes and as otherwise permitted by law.
Your choices
You have the following choices with respect to your personal information.
Access or update your information
If you have registered for an account with us through the Service, you may review and update certain account information by logging into the account.
Opt-out of marketing communications
You may opt-out of marketing-related emails by following the opt-out or unsubscribe instructions at the bottom of the email, or by contacting us at support@firstcard.com. Please note that if you choose to opt-out of marketing-related emails, you may continue to receive service-related and other non-marketing emails.
Cookies
Most browsers let you remove or reject cookies. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. Please note that if you set your browser to disable cookies, the Service may not work properly. For more information about cookies, including how to see what cookies have been set on your browser and how to manage and delete them, visit www.allaboutcookies.org.
Mobile location data
You can disable our access to your device’s precise geolocation in your mobile device settings.
Advertising choices
You can limit use of your information for interest-based advertising by:
- Browser settings. Blocking third-party cookies in your browser settings.
- Platform settings. Google and Facebook offer opt-out features that let you opt-out of use of your information for interest-based advertising:
- Google: https://adssettings.google.com/
- Facebook: https://www.facebook.com/about/ads
- Ad industry tools. Opting out of interest-based ads from companies participating in the following industry opt-out programs:
- Network Advertising Initiative: http://www.networkadvertising.org/
managing/opt_out.asp
- Digital Advertising Alliance: optout.aboutads.info.
- AppChoices mobile app, available at https://www.youradchoices.com/appchoices, which will allow you to opt-out of interest-based ads in mobile apps served by participating members of the Digital Advertising Alliance.
- Mobile settings. Using your mobile device settings to limit use of the advertising ID associated with your mobile device for interest-based advertising purposes.
You will need to apply these opt-out settings on each device from which you wish to opt-out.
Do Not Track
Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” or similar signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
Declining to provide information
We need to collect personal information to provide certain services. If you do not provide the information we identify as required or mandatory, we may not be able to provide those services.
Third-party platforms
If you choose to connect to the Service through your social media account or other third-party platform, you may be able to use your settings in your account with that platform to limit the information we receive from it. If you revoke our ability to access information from a third- party platform, that choice will not apply to information that we have already received from that third party.
Delete data or close your account
You can choose to delete certain profile data in your account or you can request to close your account by contacting us at support@firstcard.app.
Other sites and services
The Service may contain links to websites, mobile applications, and other online services operated by third parties. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control websites, mobile applications or online services operated by third parties, and we are not responsible for their actions. We encourage you to read the privacy policies of the other websites and mobile applications and online services you use.
Security
We employ a number of technical, organizational and physical safeguards designed to protect the personal information we collect. However, security risk is inherent in all internet and information technologies and we cannot guarantee the security of your personal information.
International data transfer
We are headquartered in the United States and may use service providers that operate in other countries. Your personal information may be transferred to the United States or other locations where privacy laws may not be as protective as those in your state, province, or country.
Children
The Service is not intended for use by children under 13 years of age. If we learn that we have collected personal information through the Service from a child under 13 without the consent of the child’s parent or guardian as required by law, we will delete it.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on the Service. If required by law we will also provide notification of changes in another way that we believe is reasonably likely to reach you, such as via email or another manner through the Service. Any modifications to this Privacy Policy will be effective upon our posting the modified version (or as otherwise indicated at the time of posting). In all cases, your use of the Service after the effective date of any modified Privacy Policy indicates your acceptance of the modified Privacy Policy.
How to contact us
Email: support@firstcard.app
California privacy rights notice
Scope
This section applies only to California residents. It describes how we collect, use, and share Personal Information of California residents in our capacity as a “business” under the California Consumer Privacy Act (“CCPA”) and their rights with respect to that Personal Information. For purposes of this section, the term “Personal Information” has the meaning given in the CCPA but does not include information exempted from the scope of the CCPA. For example, this section does not apply to personal information governed by the Gramm-Leach-Bliley Act (GLBA), a federal law that applies to certain financial institutions. For information relating to your choices under the GLBA, please see our Consumer Privacy Disclosure.
Your California privacy rights
As a California resident, you have the rights listed below. However, these rights are not absolute, and in certain cases we may decline your request as permitted by law.
- Information. You can request the following information about how we have collected and used your Personal Information during the past 12 months:
- The categories of Personal Information that we have collected.
- The categories of sources from which we collected Personal Information.
- The business or commercial purpose for collecting and/or selling Personal Information.
- The categories of third parties with whom we share Personal Information.
- The categories of Personal Information that we sold or disclosed for a business purpose.
- The categories of third parties to whom the Personal Information was sold or disclosed for a business purpose.
- Access. You can request a copy of the Personal Information that we have collected about you during the past 12 months.
- Deletion. You can ask us to delete the Personal Information that we have collected from you.
- Opt-out of sales. You can opt-out any sale of your Personal Information.
- Opt-in. If we know that you are 13-15 years of age, we will ask for your affirmative authorization to sell your Personal Information before we do so.
- Nondiscrimination. You are entitled to exercise the rights described above free from discrimination as prohibited by the CCPA.
Right to information, access and deletion
You may submit requests to exercise your right to information, access or deletion at www.firstcard.app/about-us, calling us toll free at +1 (833) 401-0040, or via email to support@firstcard.app.
Notice of right to opt-out of the “sale”
of your Personal Information
Like many companies, we use services that help deliver interest-based ads to you. Our use of some of these services may be classified under California law as a “sale” of your Personal Information to the advertising partners that provide the services because they collect information from our users (e.g., device data and online activity data) to help them serve ads more likely to interest you. You can request to opt-out out of this “sale” of your personal information here: Do Not Sell My Personal Information, where you will find instructions on opting-out of the use of your information for interest-based advertising.
We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it.
We will need to verify your identity to process your information, access and deletion requests and reserve the right to confirm your California residency. To verify your identity, we may require government identification, a declaration under penalty of perjury or other information. Your authorized agent may make a request on your behalf upon our verification of the agent’s identity and our receipt of a copy of a valid power of attorney given to your authorized agent pursuant to California Probate Code Sections 4000-4465. If you have not provided your agent with such a power of attorney, you must provide your agent with written and signed permission to exercise your CCPA rights on your behalf, provide the information we request to verify your identity, and provide us with confirmation that you have given the authorized agent permission to submit the request.
We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it.
We will need to verify your identity to process your information, access and deletion requests and reserve the right to confirm your California residency. To verify your identity, we may require government identification, a declaration under penalty of perjury or other information. Your authorized agent may make a request on your behalf upon our verification of the agent’s identity and our receipt of a copy of a valid power of attorney given to your authorized agent pursuant to California Probate Code Sections 4000-4465. If you have not provided your agent with such a power of attorney, you must provide your agent with written and signed permission to exercise your CCPA rights on your behalf, provide the information we request to verify your identity, and provide us with confirmation that you have given the authorized agent permission to submit the request.
Personal information that we collect,
use and disclose
The chart below summarizes the Personal Information we collect by reference to the categories of Personal Information specified in the CCPA and describes our practices currently and during the 12 months preceding the effective date of this Privacy Policy. Information you voluntarily provide to us, such as in free-form webforms, may contain other categories of personal information not described below.
Statutory category of personal information (PI)
(Cal. Civ. Code § 1798.140)
PI we collect in this category
(See Personal information we collect above for description)
Source of PI
Business/
commercial purpose for collection
commercial purpose for collection
Categories of third parties to whom we “disclose” PI for a business purpose
Categories of third parties to whom we “sell” PI
Identifiers
(other than online identifiers)
- Contact data
- Profile data
- Data about others
- Government-issued identification numbers
- You
- Third-party sources
- Service delivery
- Research & development
- Marketing & advertising
- Compliance & protection
- Affiliates
- Service providers
- Advertising partners
- Third parties designated by you
- Professional advisors
- Authorities and others
- Business transferees
- Third-party platforms and social media networks
- Advertising partners(to facilitate online advertising)
California Customer Records
(as defined in California Civil Code section 1798.80)
- Contact data
- Financial data
- Data about others
- Government-issued identification numbers
- You
- Third-party sources
- Service delivery
- Research & development
- Marketing & advertising
- Compliance & protection
- Affiliates
- Service providers
- Advertising partners
- Third parties designated by you
- Professional advisors
- Authorities and others
- Business transferees
- Third-party platforms and social media networks
- Advertising partners(to facilitate online advertising)
Commercial Information
- Rewards and transaction data
- Financial data
- Marketing data
- Online activity data
- Promotional information
- You
- Third-party sources
- Automatic collection
- Service delivery
- Research & development
- Marketing & advertising
- Compliance & protection
- Affiliates
- Service providers
- Advertising partners
- Third parties designated by you
- Professional advisors
- Authorities and others
- Business transferees
- Third-party platforms and social media networks
- Advertising partners(to facilitate online advertising)
Financial Information
- Rewards and transaction data
- Financial data
- You
- Third-party sources
- Service delivery
- Research & development
- Marketing & advertising
- Compliance & protection
- Affiliates
- Third parties designated by you
- Professional advisors
- Authorities and others
- Business transferees
None
Online Identifiers
- Profile data
- Device data
- Online activity data
- You
- Third-party sources
- Automatic collection
- Service delivery
- Research & development
- Marketing & advertising
- Compliance & protection
- Affiliates
- Service providers
- Advertising partners
- Third parties designated by you
- Professional advisors
- Authorities and others
- Business transferees
- Third-party platforms and social media networks
- Advertising partners(to facilitate online advertising)
Internet or Network Information
- Marketing data
- Device data
- Online activity data
- Automatic collection
- Service delivery
- Research & development
- Marketing & advertising
- Compliance & protection
- Affiliates
- Service providers
- Advertising partners
- Third parties designated by you
- Professional advisors
- Authorities and others
- Business transferees
- Third-party platforms and social media networks
- Advertising partners(to facilitate online advertising)
Geolocation Data
- Device data
- Precise geolocation data
- Automatic collection
- Service delivery
- Research & development
- Marketing & advertising
- Compliance & protection
- Affiliates
- Service providers
- Advertising partners
- Third parties designated by you
- Professional advisors
- Authorities and others
- Business transferees
- Third-party platforms and social media networks
- Advertising partners(to facilitate online advertising)
Inferences
May be derived from your:
- Contact data
- Profile data
- Rewards and transaction data
- Financial data
- Marketing data
- Device data
- Online activity data
N/A
- Service delivery
- Research & development
- Marketing & advertising
- Compliance & protection
- Affiliates
- Service providers
- Advertising partners
- Authorities and others
- Business transferees
- Third-party platforms and social media networks
- Advertising partners(to facilitate online advertising)
Protected Classification Characteristics
We do not intentionally collect this information but it may be revealed in identity data or other information we collect
N/A
N/A
N/A
N/A
We may also share your information for other purposes as described in the Compliance and protection and Business transferees sections above.
Your California privacy rights
Under California’s Shine the Light law (California Civil Code Section 1798.83), California residents may ask companies with whom they have formed a business relationship primarily for personal, family or household purposes to provide the names of third parties to which they have disclosed certain personal information (as defined under the Shine the Light law) during the preceding calendar year for their own direct marketing purposes and the categories of personal information disclosed. You may send us requests for this information to support@firstcard.app In your request, you must include the statement “Shine the Light Request,“ and provide your first and last name and mailing address and certify that you are a California resident. We reserve the right to require additional information to confirm your identity and California residency. Please note that we will not accept requests via telephone, mail, or facsimile, and we are not responsible for notices that are not labeled or sent properly, or that do not have complete information.