Privacy policy

Last updated December 31, 2022

****Thank you for visiting Peach Finance Inc. (“Peach”). Please read the Privacy Policy and the Federal Privacy Notice under the Gramm-Leach-Bliley Act (“Federal Privacy Notice”) before using products and services on Peach’s website or through any other means (collectively the “Services”). Peach is the owner of this website, www.peachfinance.com (the “Website”), and the hosting, content, and other functionality of this Website and the Services are supported by Peach and other third parties that provide software and other services to Peach. Your use of the Website or Services indicates your acceptance of the terms of this Privacy Policy. Notices that supplement this Privacy Policy prevail in cases of conflict with this Privacy Policy.

This Privacy Policy, together with the Federal Privacy Notice, describes the type of personal information we collect from you, how we handle and protect your personal information, and how you may update and control the information you provide on our Website.

This Privacy Policy generally applies to users of our Website and Services, and this policy is incorporated into and a material term of the Peach Website Terms of Use which establishes your consent and/or use of the Services. 

This Privacy Policy applies to all prospective, current and former Peach customers and all users of Peach’s Website and Services. If you have questions or complaints regarding our Privacy Policy or practices, please contact us at privacy@peachfinance.com. Loans serviced using Peach’s platform are originated by various third-party lenders that are customers of Peach. Accordingly, please see your lender’s website for a copy of your lender’s privacy policy and federal privacy notice. You may also request a copy of your lender’s privacy policy and federal privacy notice by reaching out to your lender directly.

If you are a California resident, please see the section entitled “Notice to California Residents” below for more information.

By voluntarily providing us with personal information through the use of Services and the Website, you are consenting to its collection, use and disclosure in accordance with this Privacy Policy. You acknowledge and agree that such personal information may be transferred from your current location to the offices and servers of Peach and authorized third parties referred to herein located in Canada and the United States.

We may change this Privacy Policy from time to time in our sole discretion, so please be sure to check back periodically. You can tell if this Privacy Policy has changed by checking the last updated date that appears at the beginning of this Privacy Policy. We may, but are not obligated to (unless required by applicable laws), provide you with notice in case of any material changes made to this Privacy Policy. You should not continue using the Services if you do not agree with the version of this Privacy Policy in effect at that time. By continuing to use the Services, you agree and accept the version of this Privacy Policy in effect at that time. Any changes will be effective only after the effective date of the change and will not affect any dispute arising prior to the effective date of the change. 

Children’s Information

Our Website and Services are intended for adult use only. We do not direct any part of our Website to children less than 18 years old and children are not eligible to use our Services. Nor do we knowingly collect Personal Information from children. By using this Website or our Services, you represent and warrant that you are at least 18 years of age.

Information Peach Collects About You

Information Peach Collects From You Online

The information we collect from you varies, depending on the way you use our Website and/or Services and the information you provide to us. For example, when you contact us to inquire about or purchase certain products, or for technical support, customer service, or sales support, you will be required to provide certain information, including your name, email address, and company, as applicable.

Additionally, we may collect device and online usage information, such as information about your computer, browser, mobile, or other device that you use to access our Site. As described more below, we may use cookies, pixels, log files and other techniques to collect such information, including IP address, device identifiers and other unique identifiers, browser type, browser language, operating system name and version, device name and model, version, referring and exit pages, dates and times of Service access, links clicked, pages visited, forms submitted, features used, crash reports and session identification information.

If you use our Website to manage an account that you have with a bank or other lender, your bank or lender may provide some of your personal and banking information to us. You may also be asked to provide other pieces of your personal and banking information. The personal information we collect from your bank or lender, or directly from you may include but is not limited to your:

  • Name, address, and phone number

  • Social Security number or social insurance number, driver’s license number, or any government issued identification numbers

  • Date of Birth

  • Employment information

  • Salary and income

  • Email address

  • Bank account number, routing number, and name of your bank

  • Debit or credit card number, expiration date and CVV

  • Login credentials (username and password) you plan to use to access our Website

If you provide us with additional personal information during the time that you have an account or loan that is serviced using Peach, we may use this additional information in conjunction with any other information you have provided to:

  • Service your account (provide statements, apply payments, resolve errors, etc.)

  • Provide you with products or services that you have requested

  • Improve our Services and develop additional services or products

Information Peach Collects Based on Your Activity on the Peach Website

Peach collects information about your transactions and activity, in addition to other internet browsing data. We collect information about your computer and your visits to the Website, including your IP address, geographical location, browser type, referral source, length of visit, button clicks and page views. If you have a loan that is serviced using Peach, we will also collect information about your payment history.

Tracking Technologies

If you visit our Website without revealing any personal information, our servers still collect information about your Internet browsing activity on our Website, and other information such as your IP address, browser type and platform, and information about the link that brought you to our Website. This information is used by us and our service providers to better understand a user’s experience on our Website and to improve our Website and Services.

Cookies and Web Beacons. Cookies are data files stored by your Internet browser on your computer’s hard drive. Peach and some of our business partners and service providers may use technologies such as cookies, beacons, tags, and scripts, to analyze trends, administer the Website, track users’ movements around the Website, and gather demographic information about our user base as a whole. We may receive reports on this activity on an individual and aggregated basis. Cookies may also be used to gather statistical data, such as which pages are frequently visited, what is downloaded, and the address of sites visited immediately before or after coming to our Website.

If you have an account that can be managed on our Website, we may use cookies when you sign in to your account to keep track of your personal session, help authenticate your account, and detect fraud. You can control the use of cookies within your web browser. However, if you reject cookies, your ability to use some features or areas of our Websites may be limited or unavailable.

Usage Data & Site Activity. Peach also uses local storage to store your preferences and other information. Various browsers offer their own tools for managing content persisted in the browser’s local storage.

Third Party Technologies. We also partner with third parties to manage our advertising on other sites and evaluate our overall Website performance. Our third-party partners may use technologies such as cookies or other similar technologies to gather information about your activities on our Website and other sites in order to provide you advertising based upon your browsing activities and interests or help us track the success of our marketing efforts or overall Website performance. If you do not wish to have this information used to provide you with interest-based advertisements, you may opt out here. Please note that this opt-out only applies to interest-based advertisements provided through certain networks and third-parties. You may continue to receive other generic advertisements.

Third Party Practices

The Website or Services may contain links to other websites, including those of our partners. Please be aware that we are not responsible for the privacy practices or the online content of such third parties. The privacy policy of a partner listed on our Website may differ from ours. We encourage you to read the privacy policy of each third-party website you visit before sharing your information with that third party.

Do-Not-Track Signals

Our website is not currently able to respond to “do not track” signals from your browser at this time. To learn more about how “do not track” works, please visit All About Do Not Track.

How Peach Uses Your Information

We use the personal information that we collect for a variety of business purposes when it is reasonably necessary and proportionate to achieve the operational purpose for which the personal information was collected or processed or compatible with the context in which the personal information was collected, or when there is a legitimate interest, to the extent it does not infringe on any data subject’s fundamental rights and freedoms. For example, we use personal information: 

  • Pursuant to your consent;

  • To give you access to our Services and to provide and/or make our Website and/or Services available to you;

  • To administer your accounts or loans with us, including: generating your borrower profile; enabling automatic payments and fund transfers with other financial institutions; reviewing your payment history; implementing collection activities as needed; communicating with you concerning your account and transactions; and addressing any disputes you may raise concerning your account;

  • For entering into or performing a contract with you;

  • For complying with a legal obligation (e.g., provide our investors with required information about us); 

  • To administer and facilitate billing for your accounts;

  • To respond to your requests, assist with customer or sales support, or to process and/or resolve other issues regarding our Website or Services;

  • For marketing;

  • For business communications and updates;

  • To provide you with technical or sales support, including but not limited to identifying and decommissioning lost or stolen devices;

  • To notify you about changes to our Website or Services;

  • To improve the quality of the Website and Services;

  • To ensure compliance with applicable law, or manage our everyday business needs, such as auditing or administration of our Services;

  • For analytics, monitoring and security, and the enforcement of any corporate reporting obligations, Terms of Use, or other policies;

  • To analyze usage patterns in order to enhance the Website and Services, and in some instances tailor them to your preferences. Some of this information may be de-identified and aggregated, and thus not identifiable to you;

  • To help maintain the safety, security, and integrity of our Website, Services, databases and other technology assets, as well as our physical offices and business generally;

  • For testing, research, analysis, and product development, including to develop and improve our Website and Services; or

  • To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.

Disclosing Your Information

We may disclose personal information:

  • To contractors, subcontractors, vendors, and third parties who help us make the Website or Services available or who support our business;

  • To third parties to whom you ask us to send Personal Information;

  • To our marketing and analytics partners to improve and tailor your experience on our Site and customize our advertising to your interests;

  • To a company that merges with, acquires, or purchases the assets of Peach, in which case such company may continue to process your Personal Information as set forth in this Privacy Policy;

  • In situations in which you have provided explicit permission to disclose certain Personal Information, for example, in connection with marketing materials shared with the general public; or

  • If we believe in good faith that such disclosure is necessary to: (a) resolve disputes, investigate problems, or enforce our Terms of Use; (b) comply with applicable laws or respond to requests from law enforcement or other government officials, including governmental safety agencies; or (c) protect or defend the rights or property of Peach, you, or third parties.

Peach may use and disclose your personal information that is collected through our Website and Services to run our everyday business and in accordance with applicable law. We do not share, sell, rent or trade your personal information with any third party other than as described in this Privacy Policy including to our service providers to provide the Services to you or those which you request and with your bank or lender in connection with any loan or account. We may share your information with law enforcement, government officials, or other third parties as required by law and when we believe that such disclosure is necessary to protect our rights and/or comply with a judicial proceeding, court order, regulatory request or other legal process. We may also aggregate information and statistics and use them in our business and provide them to third parties so long as they do not contain any personally identifiable information.

Protecting your Information

Our goal is to protect the personal information you submit to us through this Website or the Services, both in transmission and once received. We and our service providers have implemented technical and organizational measures designed to protect against loss or unauthorized access, disclosure, alteration or destruction of the information you provide on our Website. Despite these efforts, no security measures, however thorough, are perfect. Accordingly, we do not guarantee the security of the information you provide to us.

Data security is achieved through technical safeguards that include a combination of firewalls, intrusion detection system, malware detection system, and data loss prevention systems. Peach also conducts vulnerability scans of applications and systems regularly.

Access to the system is limited to only those who have a need to access information. Administrative safeguards such as a security awareness program, background checks, and our information security policy ensure that only trained and trusted staff are permitted to access personal information. Some additional features of our security program include:

Secure Data Center

Peach uses an industry leading infrastructure service provider for its computing infrastructure needs. Peach’s cloud infrastructure facility (provided through the service provider) is enabled with encryption and data protection capabilities for the systems and services we develop and/or deploy within. Peach’s infrastructure provider is SOC 1, SOC 2, and SOC 3 compliant.

Physical access to the data center is strictly controlled and we use the latest threat prevention technologies such as network and web application firewalls, VPN, antivirus, intrusion detection systems, web filtering and antispam technologies.

Website Security Certificates

Peach equips all customer-facing services with an Extended Validation (EV) Secure Socket Layer (SSL) certificate to ensure that when you connect to our Website you can tell that you are actually on our Website and that all data entered into the websites are transmitted to us in a secure encrypted channel. Once on our system, personal information can only be read or written through defined service access points, the use of which is password-protected.

Session Time-Outs

We employ session time-outs to protect your account. You will be logged out of the Website automatically after a specified period of inactivity. This time-out feature reduces the risk of others being able to access your account if you leave your computer unattended.

Passwords

Where applicable, you should always choose a password that is difficult for others to guess and change your password frequently. At a minimum and where applicable, we require the use of both numbers and letters in your password. We have also instituted secure steps by which you can regain access to your account should you forget your password, including the use of a security question.

You should never share your password with anyone. Your password is not known to any Peach employee or third party, and we will never ask for your password by phone or email. If you ever receive a communication claiming to be from Peach that asks for your password, you should immediately report it by contacting us at support@peachfinance.com.

Security Awareness Training

We conduct security awareness training for all staff at least annually, and provide additional training on Peach privacy and security-related policies and procedures for personnel that have access to sensitive information. We instruct staff that access must be used only in adherence with the principles set forth in this Policy and applicable laws, and for no other purpose. Personnel who misuse customer information are subject to disciplinary action.

Additional Steps You Should Take to Ensure the Security of Your Information

Secure your Email Account and Username. Peach sends important communications regarding your account via email. You should therefore take steps to secure and restrict access to your email account and change your email account password frequently. If your email address changes, you should promptly update your contact information on our Website, or contact Peach Finance Customer Service at (888) 517-3224.

You should not include any personally identifying information in your Peach Username. We are not responsible for any personal information that you may choose to reveal in your Username.

**Beware of suspicious emails. **You should be aware of fraudulent emails known as “phishing,” from companies claiming to be Peach and requesting your login information or other account information. PEACH WILL NEVER ASK FOR YOUR LOGIN INFORMATION IN AN EMAIL.

Regularly Remove Cache Files. When you are finished using our Website, you should log out completely, then close the browser window and clear the browser’s cache files. This step is particularly important if you use a computer that is accessed by other people, such as in a public library or Internet café.

Create Strong Passwords. Where applicable, you should use passwords that are at least 10 characters long and contain letters, numbers, and symbols.

Retention of Personal Information

Unless otherwise required by law, it is our policy to not retain personal information or sensitive personal information for longer than is reasonably necessary to achieve the purpose for which it was collected. The criteria we use to determine the specific retention period include: the type of data; whether you have provided your consent and have not withdrawn it; whether there are other legal grounds for the continued processing; whether you have objected to the processing and there are no overriding legitimate grounds for the processing; and whether retention or deletion is necessary to comply with legal obligations.

Additional Policy Disclosures

This Privacy Policy is subject to revision from time to time. We will post any revised version of the Privacy Policy on this Website. Continued use of our Website or Services following notice of such changes will indicate your acknowledgement of such changes and agreement to be bound by the revised terms and conditions. We recommend that you review this Website regularly for updates to our Privacy Policy.

Contact Us

If you have any questions regarding our Privacy Policy, please contact us at privacy@peachfinance.com.

Notice at Collection (California Residents)

This section only applies to California residents. The rights discussed in this section do not extend to individuals who are not California residents. 

Pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively the “CCPA”), California residents may have certain data privacy rights, such as the right to be notified about what personal information categories we collect about you, and our intended use and purpose for collecting such personal information. This section describes the personal information we may have collected directly from you or indirectly about you if you use our Website or Services or otherwise interact with Peach, and how we have used and/or disclosed your personal information. It also describes the personal information that we will collect and the purposes for that collection, as well as your rights under the CCPA. The information that Peach collects about its users as described in the “Information Peach Collects about You” section of this Privacy Policy. Because Peach is a “service provider” as defined under the CCPA, the rights that are available to California residents under this Privacy Policy will depend on the status of your lender or loan servicer.

Categories of Personal Information Collected: We may collect the following categories of Personal Information from or about you, with the type of information collected varying depending on your use of the Site and/or our Services:

  • Identifiers such as a real name, postal address, IP address, email address, account name, telephone number, and device identifier; 

  • Other categories of personal information, such as signature and financial information, including for example your credit or debit card related information;

  • Characteristics of protected classifications under California or federal law; 

  • Commercial information, including for example records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies; 

  • Internet or other electronic network activity information, such as your browsing and search history, information regarding your interaction with an internet website or application, and information regarding a consumer’s interaction with an internet website, application, or advertisement; 

  • Audio, electronic, visual, or similar information;

  • Professional or employment-related information; and

  • Certain sensitive personal information. For example, we may collect SSNs and other sensitive information that may appear on documents related to a loan. We do not sell or share this sensitive Personal Information, as those terms are defined by the CCPA.     

***Categories of Sources from which Personal Information Is Collected: ***We collect these categories of personal information from various sources, including (a) you, (b) your interactions with the Website or Services, (c) our business partners, or (d) our marketing or other partners. 

***Categories of Personal Information Disclosed for a Business Purpose: ***We may disclose the following categories of Personal Information for a business purpose:

  • Identifiers such as a real name, postal address, IP address, email address, account name, telephone number, and device identifier; 

  • Other categories of personal information, such as signature and financial information, including for example your credit or debit card related information;

  • Characteristics of protected classifications under California or federal law; 

  • Commercial information, including for example records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies; 

  • Internet or other electronic network activity information, such as your browsing and search history, information regarding your interaction with an internet website or application, and information regarding a consumer’s interaction with an internet website, application, or advertisement; 

  • Audio, electronic, visual, or similar information;

  • Professional or employment-related information; and

  • Certain sensitive personal information. For example, we may collect SSNs and other sensitive information that may appear on documents related to a loan. We do not sell or share this sensitive Personal Information, as those terms are defined by the CCPA.     

Categories of Third Parties with whom Peach Discloses Personal Information: See “Disclosing Your Information” above, which describes the third parties with whom we may disclose your personal information for a business purpose. This may apply to each category of personal information we disclose for a business purpose.

“Selling” and “Sharing” under the CCPA: As defined by the CCPA, we “sell” and/or “share” certain online identifiers for the purposes of online advertising and analytics. Specifically, we disclose certain online identifiers to advertising partners and analytics providers. We do not knowingly collect Personal Information from anyone under 18, so we do not have actual knowledge of “selling” or “sharing” Personal Information of minors under 16. 

Right to Know General Collection and Use of Personal Information. Under the CCPA, California residents have the right to request that Peach disclose what information we have collected, used, disclosed, or sold over the past 12 months. Once we receive and confirm your verifiable consumer request for such information, (see Exercising Your California Rights), we will disclose to you, based on your specific request:

  1. The categories of personal information we collected about you over the past 12 months.

  2. The categories of sources from which the personal information is collected over the past 12 months.

  3. The business or commercial purpose for collecting or selling that personal information over the past 12 months.

  4. The categories of third parties with whom we shared your personal information over the past 12 months.

  5. If we disclosed your personal information for a business purpose, the personal information categories that each category of recipients obtained.

  6. If we sold your personal information for a business purpose, the personal information categories that each category of recipients purchased.

Right to Know Specific Pieces of Personal Information. Upon your verified request for such information, (see Exercising Your California Rights), we will also disclose to you certain specific pieces of personal information we have collected about you over the past 12 months. 

Right to Request Deletion. Under the CCPA, California residents have the right to request that we delete any of your personal information that we have collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request (see Exercising Your California Rights), we will delete your personal information from our records, and direct our service providers to do the same, unless an exception applies.

We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:

  1. Complete the transaction for which we collected the personal information, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.

  2. Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.

  3. Debug products to identify and repair errors that impair existing intended functionality.

  4. Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.

  5. Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).

  6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may likely render impossible or seriously impair the research's achievement, if you previously provided informed consent.

  7. Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.

  8. Comply with a legal obligation.

  9. Make other internal and lawful uses of that information that are compatible with the context in which you provided it.

Right to Opt-Out of Sale of Personal Information. Under the CCPA, California residents have the right to direct businesses that sell personal information to not sell your personal information (the "right to opt-out"). Peach does not and will not sell personal information of consumers.

Right to Non-Discrimination. Under the CCPA, California residents have the right not to be discriminated against for having exercised the rights established by the CCPA. We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:

  1. Deny you goods or services.

  2. Charge you different prices or rates for goods or services, including through granting discounts or other benefits or imposing penalties.

  3. Provide you a different level or quality of goods or services.

  4. Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

Exercising Your California Rights

This section only applies to California residents. The rights discussed in this section do not extend to individuals who are not California residents. 

For you to exercise the right to know and the right to request deletion, you or your authorized agent may submit a verifiable consumer request in one of the following ways:

We will process your verifiable request free of charge, but we are only obligated to provide information to you pursuant to such requests two times in a 12-month period. Note, we may deny your request in whole or in part if we cannot verify your identity. The verifiable consumer request must do the following:

  1. Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.

  2. Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

Upon receiving a request to know, we will confirm receipt within 10 days. If we are able to verify your request, we will make our best effort to respond within 45 days of our receipt of your request. If we require more time (up to 45 additional days), we will inform you of the reason and extension period in writing.  To verify your identity, when feasible, we will use information about you that we already have; however, we may need to request additional information, which we will use only for the purposes of verification. We may also use a third-party identity verification service.

The information we need to verify your request will depend on the nature and scope of your request. Upon receipt of your request, we will notify you if we need additional information from you to verify your request.

How California Residents Can Designate an Authorized Agent

This section only applies to California residents. The rights discussed in this section do not extend to individuals who are not California residents. 

Only you as a California resident, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable request to know/request for access, request for deletion, or request to opt-out. 

To appoint an authorized representative to submit requests on your behalf, please provide us with written instructions stating the identity of the authorized representative and your authorization to have the representative act on your behalf by emailing privacy@peachfinance.com. We may also request additional information from you as needed to authenticate your request. If an authorized representative is acting on your behalf, your representative may contact us at privacy@peachfinance.com with a brief description of the request, but please note that we may request additional information from your representative as needed to authenticate your request.

Amendments to Privacy Policy

This section only applies to California residents. The rights discussed in this section do not extend to individuals who are not California residents. If a material change is made to this privacy policy, we will provide notice on our website and email a copy of our updated policy to registered users.