navigation menu
HomeAbout usProductNonprofitsCareersBlog

Spiral Privacy Policy

The Privacy Policy (the “Privacy Policy,” or the “Policy”) outlines how Spiral Financial, Inc. (“we,” “us”, and “our”) source, use, disclose, and protect the personal information you (“you” or “your”) provide when you access or use (1) our websites located at https://www.spiral.us (the “Website”); (2) our mobile application(s) (collectively, the “Application”); and (3) any services, content, communications, and product features relating to the Website and Application (together with the Website and the Application, the “Services”). This Policy does not apply to the practices of third-party websites, services or applications.

  1. Personal Information Defined.
    “Personal Information” refers to any information we can use to identify you or can reasonably be linked or associated with you. Personal Information includes:
    1. Your name, social security number, physical address, telephone number, and Digital Identifiers (digital identifies include your device ID, IP address, cookies, and voice recordings when you contact Spiral).
    2. Any information about how you use a Spiral website, where you are physically located when you login, the operating system you use, the kind of Spiral products and services you use, and your transaction history on any accounts you have with Spiral or nbkc bank.
  2. Information lawfully available from government records and used for a purpose consistent with its availability is not Personal Information. Likewise, information that is disassociated from anything that identifies you is not Personal Information. For example, if Personal Information from you is combined with Personal Information of other persons who use the Services, and the individual consumer identities of everyone has been removed and are not associated to a particular person, it is not Personal Information.
  3. Personal Information Collected and Corrections.
    Spiral collects the following from you:
    1. Your name, social security number, date of birth, home address, email address, and phone number.
    2. If any information that you provide in 2.1 above is incorrect or otherwise unverifiable, Spiral may collect your correct Personal Information from an identity service and ask you to verify it.
    3. If you correct or update your information collected in 2.1 above, Spiral may require you to provide a government-issued photo ID (such as a driver’s license or passport), photographs of you, and proof of address documentation (such as a utility bill).
    4. If you contact Spiral using a social media platform, Spiral may collect your social media handle from the social network or from a social media analytics tool.
  4. Financial Information Collected.
    Financial information includes your Spiral and other bank account numbers, debit card and credit card numbers, and transaction history. When Spiral collects this information, it does so on behalf of nbkc bank, pursuant to the Privacy Notice you received from us and nbkc bank when you opened an account. You may review the Privacy Notice(s) applicable to your account(s) at any time at https://www.spiral.us/privacy-policy.
    1. Spiral nbkc bank Account Numbers. Spiral collects your checking, savings and Giving Account numbers from nbkc bank, which is the bank that issued your bank accounts.
    2. External Bank Account Information. When you use certain features of the Services, Spiral collects account numbers, balances, and other information about your bank accounts unrelated to your relationship with Spiral. Spiral may collect this information through a payment processor that facilitates a transfer to a Spiral partner bank account or through a third-party secure access tool, such as Plaid.
    3. Debit Card Numbers. Spiral collects the first six and the last four digits of your debit card number from its processor and/or nbkc bank for the Services in which you enroll. Spiral does not routinely collect, but may access, your full debit card number. We access and use (but do not store) this information only through a payment network or transaction dispute processing service to process and resolve disputes you initiate.
    4. History of Spiral nbkc bank Account Transactions. Spiral collects your Spiral account transaction history from its third -party processor and nbkc bank. If you enroll in Spiral direct deposit, Spiral will collect identifying information about your employer from you or a third-party service provider, including your employer’s name and address. Whenever you interact with Spiral via the in-app chat, email, phone, or website, Spiral collects your communications for customer service training and quality assurance, but may also use the information to investigate fraud or unusual activity relating to your account.
  5. Collection of IP Addresses, Web Beacons and Customized Links, Cookies and Other Session Trackers (collectively, “Digital Identifiers”) and Geolocation Data.
    1. When you use the Services, Spiral automatically collects device identifiers (including internet protocol (“IP”) addresses, web beacons, device manufacturers, model numbers, and mobile phone plan carriers, and other session-tracking information as applicable) from the computer, mobile device, technology or other device (collectively “Device”) you use to access the Services.
    2. IP Addresses. Spiral collects your IP address from your internet service provider (“ISP”), who assigns it. Your IP address is subject to change, so Spiral may maintain a record of many ISPs associated with you or your devices over time. IP addresses are typically associated with a particular geographic area and are used to estimate your location.
    3. Web Beacons & Customized Links. When you use the Website, Spiral collects web beacons and customized link information (also known as “clear GIFs” or “pixel tags”). Web beacons are transparent graphic images placed on a web page or in an email to identify you. They can indicate that you have viewed a page or email, tell your browser to get content from another server, and measure traffic to or from, or use of, our online forms, tools or content items and related browsing behavior. Customized links and related technologies track hyperlinks that you click and associate that information with you to provide you with more focused communication.
    4. Cookies & Other Session Trackers. Spiral may also collect cookies, local shared objects and similar session-tracking technologies (“Session Trackers”) to identify you over the course of many sessions. Session Trackers help provide additional functionality to the Services, customize users’ experiences with the Services and help us analyze Services usage more accurately for research and product development purposes. If you would prefer not to accept Session Trackers when using the Site, follow the instructions provided by your website or mobile browser (usually located within the “Help”, “Tools” or “Edit” facility) to modify your Session Tracker settings. Please note that if you disable Session Trackers, you may not be able to access certain parts of our Services or the Services may not work properly. We recommend that you leave Session Trackers turned on when accessing the Services because they allow you to take advantage of all of the Service’s features.
    5. Geolocation Data. Spiral may collect information from your mobile Device about your location while you are accessing or using the Application and while you are not accessing or using the Application. You may opt out of the collection of location data at any time by changing your settings on your mobile Device. However, if you do so, certain features of the Services may not be available to you or the performance of certain features of the Services may be limited or not work at all.
  6. How we use Your Personal Information, Financial Information, Digital Identifiers, and Geolocation Data.
    Spiral uses your Personal Information, Financial Information, Digital Identifiers and Geolocation Information to:
    1. Deliver the Services and send you related communications;
    2. Deliver promotions and rewards and collect fees and other amounts owed for the Services.
    3. Provide certain features of the Services, including determining your external bank account balance and facilitating transfers between your external and Spiral nbkc bank accounts.
    4. Provide you with the Services, prepare your statement, resolve errors and unauthorized transfers, and verify your identity. Spiral may use certain transaction information (e.g., whether you electronically deposit your paycheck above a minimum threshold (“Direct Deposit Status”), to determine your eligibility for certain features of the Services.
    5. Activate your debit card by verifying your physical address;
    6. Place Session Trackers on your Device for security purposes, to facilitate navigation of the Services, and to personalize your experience while using our Services.
    7. Provide targeted offers to you and notify you of nearby third-party locations where you may use the Services.
    8. Analyze individual and aggregated behavior to improve and customize the Services;
    9. Verify your identity; comply and support our bank partner’s compliance with applicable law, including anti-money laundering (“AML”) and government sanctions screening rules;
    10. Prevent, detect, and investigate fraud, hacking, infringement, or other suspected or actual misconduct, crime, or violation of an agreement involving the Services;
    11. Send you announcements, newsletters, promotional materials, and other information about the Services and third-party products and services that we think may be of interest to you;
    12. Process and deliver promotions and rewards;
    13. Collect fees and other amounts owed for the Services;
    14. Comply with obligations to tax authorities;
    15. Diagnose and debug our technical systems; and
    16. Log and store this information.
  7. With Whom We Share Your Personal Information, Financial Information, and Digital Identifiers.
    To accomplish the business purposes outlined in section 5 above, Spiral may disclose your Personal Information, Financial Information, Digital Identifiers, and Geolocation Data to the following third-party service providers who are contractually obligated to secure and refrain from disclosing any Personal Information that we disclose or otherwise entrust to them:
    1. our bank partners, including nbkc bank,
    2. eligible charities to whom you donate,
    3. payment processors, payment networks, card fulfillment vendors,
    4. mobile check deposit processing services,
    5. identity services,
    6. customer service vendors,
    7. communications platforms,
    8. risk investigation and mitigation tools,
    9. transaction dispute processing services,
    10. website and app usage trackers, data processors, modeling and analytics tools, and
    11. network infrastructure and data storage services.
  8. How to Opt-Out of Email Communications.
    We may use your Personal Information to provide you with marketing or other promotional communications via email. If you would like to stop receiving these promotional emails, you may follow the opt-out instructions contained in any such e-mail or by contacting us as set out at the bottom of this policy. Please note that by opting out, you may prohibit Spiral from informing you of offerings that may be of interest to you. It may take up to ten (10) business days for us to process opt-out requests. You will continue to receive non-promotional emails about your relationship with us.
  9. Spiral Never Sells Your Information.
    Spiral does not sell your Personal Information, Financial Information, Digital Identifiers, and Geolocation Data to third parties.
  10. Referrals.
    If you refer a customer to Spiral, we may share the fact that you have a Spiral nbkc bank account with the customer referred, but we will not share your account information.
  11. Legal Disclosures.
    Spiral may transfer and disclose information, including your Personal Information and information about how the Services are accessed and used, to:
    (a) third parties to comply with a legal obligation,
    (b) when we believe in good faith that the law requires it,
    (c) at the request of governmental authorities conducting an investigation,
    (d) to verify or enforce our Terms of Use and other agreements with us and nbkc bank or other applicable policies,
    (e) to respond to an emergency, or
    (f) otherwise to protect the rights, property, safety or security of third parties, users of the Services, or the public.
  12. Business Transfers.
    If another entity acquires us or our assets, Personal Information, Financial Information, Digital Identifiers and Geolocation Data that are collected through the Services may be disclosed to such entity as one of the transferred assets.
  13. Sharing with Your Permission.
    At your direction or request, we may share your Personal Information, Financial Information, Digital Trackers, and Geolocation Data with specified third parties.
  14. Updating Your Personal Information and Information Retention.
    If you wish to modify, verify, correct, or update any of your Personal Information collected through the Services, you may do so by logging into your Spiral nbkc bank account and updating your account profile or by emailing us at support@spiral.us. Please note that Spiral may continue to use your de-identified data after you delete any of your Personal Information or Financial Information. There may be certain instances in which we will retain your Personal Information and Financial Information. Those instances may include but are not limited to providing you Services, complying with our legal obligations, resolving disputes, preventing fraud or as otherwise permitted under law. Spiral will not use the information it retains for record-keeping purposes for any other business purpose.
  15. Security of Your Personal Information.
    Spiral has, and requires our Third-Party Service Providers to have, administrative, technical, and physical safeguards in place in our respective physical facilities and in our respective computer systems, databases, and communications networks that are commercially reasonably designed to protect the information contained within such systems from loss, misuse, and alteration. We employ commercially reasonable website security and customer verification procedures to protect your data. The measures we use may include storing Personal Information, Financial Information, Digital Identifiers and Geolocation Data on secured servers, transmitting this information using encryption technologies, and auditing and reviewing our data collection and storage practices.

    User passwords and other sensitive information are saved and encrypted to prevent unauthorized access or disclosure and accidental loss, alteration, or destruction. We regularly review our operational and business practices for compliance with corporate policies and procedures governing the security, confidentiality, and quality of our information. We require all of our employees, contractors, and other third parties to protect confidential information as a condition of doing business with, and our business practices limit the use and disclosure of such information, including Personal Information and Financial Information, to authorized persons, processes, and transactions.

    Because no method of electronic transmission or storage is completely secure, we do not guarantee absolute security of your Personal Information or Financial Information. You also play a role in protecting your Personal Information and Financial Information. Please safeguard your username and password for your Spiral nbkc bank account and do not share them with others. If we receive instructions using your account log-in information, we will consider that you have authorized the instructions. You agree to notify us immediately of any unauthorized use of your Account or any other breach of security related to the Services. We reserve the right, in our sole discretion, to refuse to provide the Services, terminate your account, and to remove or edit content.
  16. Links to Third-Party Websites and Applications.
    When you access or use the Services, you may be directed to other websites or applications that are beyond our control. We may also allow third-party websites or applications to link to the Services or use Session Trackers with the Services. We are not responsible for the privacy practices of any third parties or the content of linked websites and applications. We encourage you to read the applicable privacy policies and terms and conditions of such parties, websites, and applications. This Privacy Policy only applies to the Services and not to the services of third parties.
  17. Do-Not-Track Settings.
    Do Not Track (“DNT”) is an optional browser setting that allows you to express your preferences regarding tracking by advertisers and other third parties. We do not use technology that recognizes DNT signals from your web browser and do not respond to such signals.
  18. Children Under 13.
    The Website and Application are not directed to children under 13 years of age and we do not knowingly collect, use, or disclose Personal Information from children under 13. If we become aware that a child under 13 has provided us with Personal Information, we will make reasonable efforts to delete such information from our files.
  19. Consent to Processing and Transfer Of Information.
    The Services are governed by and operated in, and in accordance with the laws of, the United States, and are intended for the enjoyment of residents of the United States. If you use the Services, or otherwise provide us with data, from outside the United States, you agree that your Personal Information and Financial Information may be transmitted outside your resident jurisdiction. The laws pertaining to the collection, use, disclosure and protection of Personal Information and Financial Information in the United States may be more or less stringent than the laws of other countries. By using the Services, you
    (a) acknowledge that the Services is subject to the laws of the United States;
    (b) consent to your Personal Information and Financial Information being stored and processed in the United States and handled as described in this Policy; and
    (c) waive any claims that may arise under the laws of the country where you reside, are a citizen, and/or from where you access the Services.
  20. Changes to this Policy.
    Spiral may revise this Policy from time to time without prior notice to you, and any changes will be effective immediately upon the posting of the revised Privacy Policy on the Website or Application. You can determine when this Policy was last revised by checking the “Last Updated” legend at the bottom of this Privacy Policy.
  21. Questions About This Privacy Policy.
    If you have any questions or concerns about this Policy, please contact us at:

Spiral Financial, Inc.

31 Hudson Yards, Fl 11

New York, NY 10001

Email: support@spiral.us

Telephone: 888-888-8075

This Privacy Policy was last updated on December 21, 2020.