MOUNTAIN AMERICA FEDERAL CREDIT UNION

ONLINE PRIVACY NOTICE

Effective: May 20, 2024

  1. OVERVIEW
  2. PERSONAL DATA WE COLLECT
    • How We Use Your Personal Data
    • How We Obtain Your Personal Data
    • Who We Share Your Personal Data With
  3. YOUR RIGHTS REGARDING PERSONAL DATA
    • Accessing, Modifying, Rectifying, and Correcting Collected Personal Data
    • Your California Privacy Rights
    • Your Nevada Rights
  4. YOUR CHOICES
    • Communications Opt-Out
    • Location Information
    • Cookies, Web Tracking, and Advertising
  5. PROTECTING PERSONAL DATA
  6. RETENTION OF PERSONAL DATA
  7. OTHER IMPORTANT INFORMATION ABOUT PERSONAL DATA AND THE SERVICES
    • Collection of Personal Data from Children
    • Third-Party Websites and Services
    • Business Transfer
    • Payment Information
    • Do Not Track
    • International Use
  8. MODIFICATIONS AND UPDATES TO THIS ONLINE PRIVACY NOTICE
  9. APPLICABILITY OF THIS ONLINE PRIVACY NOTICE
  10. ADDITIONAL INFORMATION AND ASSISTANCE

1. OVERVIEW

Mountain America Credit Union (collectively, “Mountain America,” “we,” “us,” “our”) respects your privacy and is committed to protecting the personal data we hold about you. If you have questions, comments, or concerns about this Online Privacy Notice or our processing of personal data, please see the bottom of this Online Privacy Notice for information about how to contact us.

This Online Privacy Notice explains our practices with respect to personal data we collect and process about you. This includes information we collect through, or in association with, our websites with home pages located at https://www.macu.com/ (and all subdomains), our online branch, our mobile apps that we may provide, our products and services that we may offer from time to time via our website and/or related apps, and our related social media sites (such as Facebook, YouTube, Instagram, X and LinkedIn), or otherwise through your interactions with Mountain America (the Site, apps, products, services, and social media pages, collectively, the “Services”).

Please review the following to understand how we process and safeguard personal data about you. By using any of our Services, whether by visiting our website or otherwise, and/or by voluntarily providing personal data to us, you acknowledge that you have read and understand the practices contained in this Online Privacy Notice. This Online Privacy Notice may be revised from time to time, so please ensure that you check this Online Privacy Notice periodically to remain fully informed.

2. PERSONAL DATA WE COLLECT

We collect information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household (“personal data”). In addition, we may collect data that is not identifiable to you or otherwise associated with you, such as aggregated data, and is not personal data. To the extent this data is stored or associated with personal data, it will be treated as personal data; otherwise, the data is not subject to this notice.

a. How We Use Your Personal Data

We collect and process your personal data as part of our business operations, which include:

  1. Providing, predicting, or performing, including maintaining or servicing accounts and loans, providing customer service, processing or fulfilling orders and transactions, verifying customer information, making credit-worthiness decisions, processing payments, and all other aspects of a financial institution.
  2. Marketing our products and services to you, including sending you messages about the products and services we offer, and which are offered by third parties, which may include rewards, events, and special offers for products and services. Communicating with you by text (with prior consent), email, mail, telephone, and other methods of communication, about products, services, and information tailored to your requests or inquiries.
  3. Facilitating your engagement with the Services, including to enable you to participate in our customer feedback surveys, and post your experiences.
  4. Auditing related to a current interaction with the consumer and concurrent transactions, including, but not limited to, counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards.
  5. Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
  6. Debugging to identify and repair errors that impair existing intended functionality.
  7. Short-term, transient use, including, but not limited to, the contextual customization of ads shown as part of the same interaction.
  8. Undertaking internal research for technological development and improving the platform experience.
  9. Undertaking activities to verify or maintain the quality or safety of the services or devices owned, manufactured, manufactured for, or controlled by us, and to improve, upgrade, or enhance the services or devices owned, manufactured, manufactured for, or controlled by us.
  10. Complying with applicable laws, regulations, rules and requests of relevant law enforcement and/or other governmental agencies, court orders, or for other purposes, as permitted or required by law.
  11. Enforcing our Website Terms of Service, Membership Agreement and other usage policies.
  12. As necessary or appropriate to protect the rights, property, and safety of our users, us, and other third parties.

b. How We Obtain Your Personal Data

We collect your personal data from the following categories of sources:

  • Directly from you. When you provide it to us directly whether online, by email, phone, text, or in-person; applying for membership or creating an account; the following may be collected: name, mailing and/or billing address, email, telephone number, date of birth, age, social security number, individual taxpayer identification number, passport number, driver’s license number, payment card information, security phrases, codeword, financial information, and behavioral biometrics. In addition, we may record our conversations with you for security, quality control, and verification reasons.
    • Information collected while using the Services, including Mountain America’s mobile application:
      While using Zelle®, to use the QR Code feature, with your prior permission, Mountain America may collect or access pictures and other information from your device's Contacts, Camera, and Photos.
      Any information collected by Mountain America is used to provide features of the Zelle® service and/or to improve and customize the Mountain America user experience. You can enable or disable access to this information at any time, through your device settings.
  • Automatically or indirectly from you. For example, through logging and analytics tools (such as but not limited to, Google Analytics, Google Tag Manager, Adobe Experience Cloud, Meta and LinkedIn Analytics), cookies, pixel tags, and as a result of your use of and access to the Services, or through your interactions with us on social media websites (such as such as Facebook, YouTube, Instagram, X, and LinkedIn).
  • From our Service Providers. For example, credit bureaus, and other Service Providers we engage.
  • From Third Parties. For example, ad networks, such as Google, Bing, Meta, X, LinkedIn, StackAdapt, to serve advertisements across the Internet. These advertisers use cookies, pixel tags, and other tracking technologies to collect information about your online activity and provide online behavioral advertising.

c. Who We Share Your Personal Data With

We share your personal data as described more fully in Mountain America’s Consumer Privacy Notice.

3. YOUR RIGHTS REGARDING PERSONAL DATA

You have certain rights regarding the collection and processing of personal data.

a. Accessing, Modifying, Rectifying, and Correcting Collected Personal Data

We strive to maintain the accuracy of any personal data collected from you, and will try to respond promptly to update our records when you tell us the information in our records is not correct. However, we must rely upon you to ensure that the information you provide to us is complete, accurate, and up-to-date, and to inform us of any changes. Please review all of your information carefully before submitting it to us, and notify us as soon as possible of any updates or corrections.

b. Your California Privacy Rights

We do not share information with joint marketing partners for members with mailing addresses in California.

c. Text Messaging Marketing

We will not market products or services to you through text messaging, including SMS, without your prior consent.

4. YOUR CHOICES

You have choices about certain information we collect about you, how we communicate with you, and how we process certain personal data. When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services. In addition, it is possible to change your browser settings to block the automatic collection of certain information.

a. Location Information. If you want to limit or prevent our ability to receive location information from you, you can deny or remove the permission for certain Services to access location information or deactivate location services on your device. Please refer to your device manufacturer or operating system instructions for instructions on how to do this.

b. Cookies, Web Tracking, and Advertising.Consult our Cookie Notice for more information about how to control and/or opt out of certain web tracking technologies and/or advertising providers from collecting information about you. You may opt out of certain tracking technologies through your device’s or browser’s cookie and/or advertising settings (including by blocking, deleting, or restricting cookies, or resetting your device’s applicable advertising ID). Consult your device and/or browser documentation for more information about how to do this. To opt out of many online behavioral advertising mechanisms, including Facebook, Google, and others, you can use the Network Advertising Initiative’s Consumer Opt-Out service and/or the Digital Advertising Alliance’s Consumer Choice Tool. If you would like to opt out of Google Analytics, and certain Google advertising functionality, you may do so using Google’s opt-out tool.

5. PROTECTING PERSONAL DATA

We use commercially reasonable and appropriate physical, technical, and organizational safeguards designed to promote the security of our systems and protect the confidentiality, integrity, availability, and resilience of personal data. Those safeguards include: (i) encryption of personal data at rest and in transit; (ii) use of a layered defense; (iii) role based access; (iv) monitoring the Services for anomalous activity; (v) taking steps to ensure personal data is backed up and remains available in the event of a security incident; and (vi) periodic testing, assessment, and evaluation of the effectiveness of our safeguards.

However, no method of safeguarding information is completely secure. While we use measures designed to protect personal data, we cannot guarantee that our safeguards will be effective or sufficient. In addition, you should be aware that Internet data transmission is not always secure, and we cannot warrant that information you transmit utilizing the Services is or will be secure.

6. RETENTION OF PERSONAL DATA

We retain your personal data pursuant to our records retention policy, as well as to the extent we deem necessary to carry out the processing activities described above, including but not limited to compliance with applicable laws, regulations, rules and requests of relevant law enforcement and/or other governmental agencies, and to the extent we reasonably deem necessary to protect our and our partners’ rights, property, or safety, and the rights, property, and safety of our users and other third parties.

7. OTHER IMPORTANT INFORMATION ABOUT PERSONAL DATA AND THE SERVICES.

a. Collection of Personal Data from Children. Children under 18 years of age are not permitted to use the Services without parental or legal guardian consent, and we do not knowingly collect information from children under the age of 18 without parental or legal guardian consent. By using the Services, you represent that you are 18 years of age or older. If you are a parent or legal guardian and you are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from children without verification of parental consent or legal guardian, we will take steps to remove that information from our servers.

b. Third-Party Websites and Services. As a convenience, we may reference or provide links to third-party websites and services, including those of unaffiliated third parties, our affiliates, service providers, and third parties with which we do business. When you access these third-party services, you leave our Services, and we are not responsible for, and do not control, the content, security, or privacy practices employed by any third-party websites and services. You access these third-party services at your own risk. This Online Privacy Notice does not apply to any third-party services; please refer to the Online Privacy Notices or policies for such third-party services for information about how they collect, use, and process personal data.

c. Business Transfer. We may, in the future, sell or otherwise transfer some or all of our business, operations or assets to a third party, whether by merger, acquisition or otherwise. Personal data we obtain from or about you via the Services may be disclosed to any potential or actual third-party acquirers and may be among those assets transferred.

d. Do Not Track. We use analytics systems and providers and participate in ad networks that process personal data about your online activities over time and across third-party websites or online services, and these systems and providers may provide some of this information to us. We do not currently process or comply with any web browser’s “do not track” signal or similar mechanisms.

You may exercise your choice regarding the use of cookies and other tracking technologies by visiting the analytics systems websites for customization tools or by modifying the settings of your web browsers across the devices you use.

e. International Use. Your personal data will be stored and processed in the United States. If you are using the Services from outside the United States, by your use of the Services you acknowledge that we will transfer your data to, and store your personal data in, the United States, which may have different data protection rules than in the foreign country, and personal data may become accessible as permitted by law in the United States, including to law enforcement and/or national security authorities in the United States.

8. MODIFICATIONS AND UPDATES TO THIS ONLINE PRIVACY NOTICE

Except for notices provided pursuant to the Consumer Privacy Notice, this Online Privacy Notice replaces all previous disclosures we may have provided to you about our information practices with respect to the Services. This Online Privacy Notice is not intended to replace the Consumer Privacy Notice, but is provided in addition to such. We reserve the right, at any time, to modify, alter, and/or update this Online Privacy Notice, and any such modifications, alterations, or updates will be effective upon our posting of the revised Online Privacy Notice. We will use reasonable efforts to notify you in the event material changes are made to our processing activities and/or this Online Privacy Notice, such as by posting a notice on the Services or sending you an email. Your continued use of the Services following our posting of any revised Online Privacy Notice will constitute your acknowledgement of the amended Online Privacy Notice.

9. APPLICABILITY OF THIS ONLINE PRIVACY NOTICE

This Online Privacy Notice is subject to the Website Terms of Service, Online Services Agreement, and Membership Agreement, which govern your use of the Services. This Online Privacy Notice applies regardless of the means used to access or provide information through the Services.

This Online Privacy Notice does not apply to information from or about you collected by any third-party services, applications, or advertisements associated with, or websites linked from, the Services. The collection or receipt of your information by such third parties is subject to their own privacy policies, statements, and practices, and under no circumstances are we responsible or liable for any third party’s compliance therewith.

10. ADDITIONAL INFORMATION AND ASSISTANCE

If you have any questions or concerns about this Online Privacy Notice and/or how we process personal data, please contact us at:

Address:
Mountain America Credit Union
Attn: Privacy
P.O. Box 2331
Sandy, UT 84091

Website:
macu.com

Toll Free Phone:
1-800-748-4302

E-mail:
help@macu.com