Privacy Policy

October 21, 2020

Thank you for visiting Peach Finance Inc. (“Peach”). Please read the Privacy Policy and the Federal Privacy Notice before using products and services on Peach’s website or through any other means (collectively the “Services”). Peach Finance Inc. is the owner of this website, www.peachfinance.com (the “Website”), and the hosting, content, and other functionality of this Website and the Services are supported by Peach and other third parties that provide software and other services to Peach.

This Privacy Policy, together with the Federal Privacy Notice, describes the type of information we collect from you, what we do with the information we collect, how we protect your personal information we have collected, and how you may update and control the information you provide on our Website.

This Privacy Policy applies to Peach, and this policy is incorporated into and a material term of the Peach Website Terms of Use which establishes your consent and/or use of the Services. Among other things, these terms note that you must be 18 years of age or older to use the Services.

This Privacy Policy applies to all prospective, current and former Peach customers and all users of Peach’s Website and Services. By accessing or using Peach’s Website or Services, you consent to this Privacy Policy. If you have questions or complaints regarding our Privacy Policy or practices, please contact us at privacy@peachfinance.com. All loans serviced using Peach, whether or not through use of the Website and other online tools, are made by various lenders. Please see your lender’s website for a copy of your lender’s privacy policy and federal privacy notice. You may also request a copy of your lender’s privacy policy and federal privacy notice by reaching out to your lender directly.

Effective January 1, 2020, the California Consumer Privacy Act (“CCPA”) provides specific rights and protections to California residents. If you are a California resident, please see the section entitled “Notice to California Residents” below for more information.

Information Peach Collects About You

Information Peach Collects From You Online

You can visit our Website without revealing any personal information, in which case our servers collect information about your internet browsing activity on our Website (as described under “Tracking Technologies”).

If you use our Website to manage an account that you have with a bank or other lender, your bank or lender may provide some of your personal and banking information to us. You may also be asked to provide other pieces of your personal and banking information. The personal information we collect from your bank or lender, or directly from you may include but is not limited to your:

  • Name, address, and phone number
  • Social Security number
  • Date of Birth
  • Employment information
  • Salary and income
  • Email address
  • Bank account number, routing number, and name of your bank
  • Debit or credit card number, expiration date and CVV
  • Login credentials (username and password) you plan to use to access our Website

If you provide us with additional personal information during the time that you have an account or loan that is serviced using Peach, we may use this additional information in conjunction with any other information you have provided to:

  • Service your account (provide statements, apply payments, resolve errors, etc.)
  • Provide you with products or services that you have requested
  • Notify you of other products or services that Peach offers
  • Improve our Services and develop additional services or products

Information Peach Collects From Third Parties About You

Credit Reports. During the process of servicing your loan, we may collect information from credit bureaus and other partners to assist your lender with determining your current financial situation and evaluating risks associated with your loan and to offer you additional products or services. The credit bureau information we collect includes information about your:

  • Credit score
  • Open and closed accounts
  • Credit inquiries
  • Late payments and collections activity
  • Public records, including bankruptcy, judgments, tax liens, payment statuses

Information Peach Collects Based on Your Activity on the Peach Website

Peach collects information about your transactions and activity, in addition to other internet browsing data. We collect information about your computer and your visits to the Website, including your IP address, geographical location, browser type, referral source, length of visit, button clicks and page views. If you have a loan that is serviced using Peach, we will also collect information about your payment history.

Tracking Technologies

If you visit our Website without revealing any personal information, our servers still collect information about your internet browsing activity on our Website, and other information such as your IP address, browser type and platform, and information about the link that brought you to our Website. This information is collected anonymously and is used by us and our service providers to better understand a user’s experience on our Website and to improve our Website.

Cookies and Web Beacons. Cookies are data files stored by your internet browser on your computer’s hard drive. Peach and some of our business partners and service providers may use technologies such as cookies, beacons, tags, and scripts, to analyze trends, administer the website, track users’ movements around the website, and gather demographic information about our user base as a whole. We may receive reports on this activity on an individual and aggregated basis. Cookies may also be used to gather statistical data, such as which pages are frequently visited, what is downloaded, and the address of sites visited immediately before or after coming to our Website.

If you have an account that can be managed on our Website, we may use cookies when you sign in to your account to keep track of your personal session, help authenticate your account, and detect fraud. You can control the use of cookies within your web browser. However, if you reject cookies, your ability to use some features or areas of our websites may be limited or unavailable.

Usage Data & Site Activity. Peach also uses local storage to store your preferences and other information. Various browsers offer their own tools for managing content persisted in the browser’s local storage.

Third Party Technologies. We also partner with third parties to manage our advertising on other sites and evaluate our overall Website performance. Our third-party partners may use technologies such as cookies or other similar technologies to gather information about your activities on our Website and other sites in order to provide you advertising based upon your browsing activities and interests or help us track the success of our marketing efforts or overall Website performance. If you do not wish to have this information used to provide you with interest-based advertisements, you may opt-out by clicking here. Please note that this opt-out only applies to interest-based advertisements provided through certain networks and third-parties. You may continue to receive other generic advertisements.

Do-Not-Track Signals

We do not respond to “do not track” signals from your browser at this time. To learn more about how “do not track” works, please visit http://allaboutdnt.com.

How Peach Uses Your Information

Servicing Your Account

If you manage your loan or account using the Peach Website, we will use your information to help facilitate the servicing of your account. The information collected in connection with your loan or account may include:

  • Generating your borrower profile
  • Enabling automatic payments and fund transfers with other financial institutions
  • Reviewing your payment history
  • Implementing collection activities as needed
  • Communicating with you concerning your account and transactions
  • Addressing any disputes you may raise concerning your account

Data Analysis & Business Optimization

Peach also uses your information to conduct analyses related to our Services and our Website. We use this information to improve our Services in order to provide you with a simple and streamlined experience. We also use this information to improve our Websites’ usability and to evaluate the success of the Services.

Sharing Your Information

Peach may use and disclose your personal information that is collected through our Website and Services to run our everyday business and in accordance with applicable law. We do not share, sell, rent or trade your personal information with any third party other than as described in this Privacy Policy including to our service providers to provide the Services to you or those which you request and with your bank or lender in connection with any loan or account. We may share your information with law enforcement, government officials, or other third parties as required by law and when we believe that such disclosure is necessary to protect our rights and/or comply with a judicial proceeding, court order, regulatory request or other legal process. We may also aggregate information and statistics and use them in our business and provide them to third parties so long as they do not contain any personally identifiable information.

Protecting your Information

Our goal is to protect the personal information you submit to us through this Website or the Services, both in transmission and once received. We and our service providers have implemented technical and organizational measures designed to protect against loss or unauthorized access, disclosure, alteration or destruction of the information you provide on our Website. Despite these efforts, no security measures, however thorough, are perfect. Accordingly, we do not guarantee the security of the information you provide to us.

Data security is achieved through technical safeguards that include a combination of firewalls, intrusion detection system, malware detection system, and data loss prevention systems. Peach also conducts vulnerability scans of applications and systems regularly.

Access to the system is limited to only those who have a need to access information. Administrative safeguards such as a security awareness program, background checks, and our information security policy ensure that only trained and trusted staff are permitted to access personal information. Some additional features of our security program include:

Secure Data Center

Peach uses an industry leading infrastructure service provider for its computing infrastructure needs. Peach’s cloud infrastructure facility (provided through the service provider) is enabled with encryption and data protection capabilities for the systems and services we develop and/or deploy within. Peach’s infrastructure provider is SOC 1, SOC 2, and SOC 3 compliant.

Physical access to the data center is strictly controlled and we use the latest threat prevention technologies such as network and web application firewalls, VPN, antivirus, intrusion detection systems, web filtering and antispam technologies.

Website Security Certificates

Peach equips all customer-facing services with an Extended Validation (EV) Secure Socket Layer (SSL) certificate to ensure that when you connect to our Website you can tell that you are actually on our Website and that all data entered into the websites are transmitted to us in a secure encrypted channel. Once on our system, personal information can only be read or written through defined service access points, the use of which is password-protected.

Session Time-Outs

We employ session time-outs to protect your account. You will be logged out of the Website automatically after a specified period of inactivity. This time-out feature reduces the risk of others being able to access your account if you leave your computer unattended.

Passwords

Where applicable, you should always choose a password that is difficult for others to guess and change your password frequently. At a minimum and where applicable, we require the use of both numbers and letters in your password. We have also instituted secure steps by which you can regain access to your account should you forget your password, including the use of a security question.

You should never share your password with anyone. Your password is not known to any Peach employee or third party, and we will never ask for your password by phone or email. If you ever receive a communication claiming to be from Peach that asks for your password, you should immediately report it by contacting us support@peachfinance.com.

Security Awareness Training

We conduct security awareness training for all staff at least annually, and provide additional training on Peach privacy and security-related policies and procedures for personnel that have access to sensitive information. We instruct staff that access must be used only in adherence with the principles set forth in this Policy and applicable laws, and for no other purpose. Personnel who misuse customer information are subject to disciplinary action.

Additional Steps You Should Take to Ensure the Security of Your Information

Secure your Email Account and Username. Peach sends important communications regarding your account via email. You should therefore take steps to secure and restrict access to your email account and change your email account password frequently. If your email address changes, you should promptly update your contact information on our Website, or contact Peach Finance Customer Service at (888) 517-3224.

You should not include any personally identifying information in your Peach Username. We are not responsible for any personal information that you may choose to reveal in your Username.

Beware of suspicious emails. You should be aware of fraudulent emails known as “phishing,” from companies claiming to be Peach and requesting your login information or other account information. PEACH WILL NEVER ASK FOR YOUR LOGIN INFORMATION IN AN EMAIL.

Regularly Remove Cache Files. When you are finished using our Website, you should log out completely, then close the browser window and clear the browser’s cache files. This step is particularly important if you use a computer that is accessed by other people, such as in a public library or Internet café.

Create Strong Passwords. Where applicable, you should use passwords that are at least 10 characters long and contain letters, numbers, and symbols.

Additional Policy Disclosures

We reserve the right to modify this Privacy Policy at any time, without advance notice. If we make any material change to this Policy, we will update our Website to include such changes. We recommend that you review this Website regularly for updates to our Privacy Policy.

Notice at Collection (California Residents)

This section only applies to California residents. The rights discussed in this section do not extend to individuals who are not California residents. 

Effective January 1, 2020, the California Consumer Privacy Act (“CCPA”) provides specific rights to California residents related to their “personal information,” as defined under the CCPA. The information that Peach collects about its users as described in the “Information Peach Collects about You” section of this Privacy Policy. Because Peach is a “service provider” as defined under the CCPA, the rights that are available to California residents under this Privacy Policy will depend on the status of your lender or loan servicer.

Right to Know General Collection and Use of Personal Information. Under the CCPA, California residents have the right to request that Peach disclose what information we have collected, used, disclosed, or sold over the past 12 months. Once we receive and confirm your verifiable consumer request for such information, (see Exercising Your California Rights), we will disclose to you, based on your specific request:

  1. The categories of personal information we collected about you over the past 12 months.
  2. The categories of sources from which the personal information is collected over the past 12 months.
  3. The business or commercial purpose for collecting or selling that personal information over the past 12 months.
  4. The categories of third parties with whom we shared your personal information over the past 12 months.
  5. If we disclosed your personal information for a business purpose, the personal information categories that each category of recipients obtained.
  6. If we sold your personal information for a business purpose, the personal information categories that each category of recipients purchased.

Right to Know Specific Pieces of Personal Information. Upon your verified request for such information, (see Exercising Your California Rights), we will also disclose to you certain specific pieces of personal information we have collected about you over the past 12 months. 

Right to Request Deletion. Under the CCPA, California residents have the right to request that we delete any of your personal information that we have collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request (see Exercising Your California Rights), we will delete your personal information from our records, and direct our service providers to do the same, unless an exception applies.

We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:

  1. Complete the transaction for which we collected the personal information, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
  2. Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
  3. Debug products to identify and repair errors that impair existing intended functionality.
  4. Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
  5. Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
  6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may likely render impossible or seriously impair the research's achievement, if you previously provided informed consent.
  7. Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
  8. Comply with a legal obligation.
  9. Make other internal and lawful uses of that information that are compatible with the context in which you provided it.

Right to Opt-Out of Sale of Personal Information. Under the CCPA, California residents have the right to direct businesses that sell personal information to not sell your personal information (the "right to opt-out"). Peach does not and will not sell personal information of consumers.

Right to Non-Discrimination. Under the CCPA, California residents have the right not to be discriminated against for having exercised the rights established by the CCPA. We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:

  1. Deny you goods or services.
  2. Charge you different prices or rates for goods or services, including through granting discounts or other benefits or imposing penalties.
  3. Provide you a different level or quality of goods or services.
  4. Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

Exercising Your California Rights

This section only applies to California residents. The rights discussed in this section do not extend to individuals who are not California residents. 

For you to exercise the right to know and the right to request deletion, you or your authorized agent may submit a verifiable consumer request in one of the following ways:

You may only make a verifiable consumer request to know twice within a 12-month period. The verifiable consumer request must do the following:

  1. Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
  2. Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

Upon receiving a request to know, we will confirm receipt within 10 days. If we are able to verify your request, we will make our best effort to respond within 45 days of our receipt of your request. If we require more time (up to 45 additional days), we will inform you of the reason and extension period in writing. We will not disclose information to you if we cannot verify your identity.

How California Residents Can Designate an Authorized Agent

This section only applies to California residents. The rights discussed in this section do not extend to individuals who are not California residents. 

Only you as a California resident, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable request to know/request for access, request for deletion, or request to opt-out. 

To appoint an authorized representative to submit requests on your behalf, please provide us with written instructions stating the identity of the authorized representative and your authorization to have the representative act on your behalf by emailing privacy@peachfinance.com. We may also request additional information from you as needed to authenticate your request. If an authorized representative is acting on your behalf, your representative may contact us at privacy@peachfinance.com with a brief description of the request, but please note that we may request additional information from your representative as needed to authenticate your request.

How We Verify California Residents’ Requests to Know/Requests for Access and Requests for Deletion

This section only applies to California residents. The rights discussed in this section do not extend to individuals who are not California residents. 

We will not respond to requests to know/requests for access or requests for deletion unless we can verify your identity to a reasonable degree of certainty. To verify your identity, when feasible, we will use information about you that we already have; however, we may need to request additional information, which we will use only for the purposes of verification. We may also use a third-party identity verification service.

The information we need to verify your request will depend on the nature and scope of your request. Upon receipt of your request, we will notify you if we need additional information from you to verify your request.

Amendments to Privacy Policy

This section only applies to California residents. The rights discussed in this section do not extend to individuals who are not California residents. 

If a material change is made to this privacy policy, we will provide notice on our website and email a copy of our updated policy to registered users.