Stilt

Stilt is a bank focusing on providing credit to immigrants and the underserved.

This page is not published. While you can access it via its direct link, it is not yet displayed on the website.

Transparency

Does the policy require users to be notified in case of a data breach? Yes, eventually

5/7

Decided May 17, 2020 (revision history). This question accounts for 8% of the final score.

Users will be notified in case of a data breach, but within an unspecified amount of time.

Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.

Possible Options

No0/7
Yes, eventually5/7
Yes, within 72 hours7/7
N/A (the service collects so little personal data that notification would not be possible)7/7

Citation

In the event of a data breach, we will comply with the notification guidelines required by federal law as well as the laws of each state in which we do business.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Will affected users be notified when the policy is meaningfully changed? Yes

5/5

Decided May 17, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

No0/5
Yes5/5
N/A (no personal data—or contact information—collected)5/5

Citation

We will post any changes to the Privacy Policy on this page and, if the changes are significant, we will provide a more prominent notice (including, for example, email notification). Your use of the Stilt site following any update to the Privacy Policy means that you accept the updated policy.

This Privacy Policy may change from time to time. We will post any changes to the Privacy Policy on this page and, if the changes are significant, we will provide a more prominent notice (including, for example, email notification). Any updates to this policy become effective when we post the updates on the Site. We will also keep prior versions of this Privacy Policy in an archive for your review. Your use of the Stilt site following the update to the Privacy Policy means that you accept the updated policy.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Is the policy's history made available? Only the date it was last modified

3/5

Decided May 17, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

No0/5
Only the date it was last modified3/5
Yes, with revisions or a change-log5/5

Citation

LAST UPDATED: JANUARY 6, 2016

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the policy outline the service's general security practices? Somewhat

1/3

Decided May 17, 2020 (revision history). This question accounts for 4% of the final score.

The policy provides only a very vague overview of its security practices.

Possible Options

No0/3
Somewhat1/3
Yes2/3
Yes, including audits2.5/3
N/A (no personal data collected)3/3
Yes, including independent audits3/3

Citation

Stilt takes your privacy and security seriously. We have enabled HTTPS access to our site, in addition to SSL technology, and your login information of your financial accounts is not accessible to anyone at Stilt. This data is stored offsite. Additionally, there are a number of precautions you can take to protect the security of your computer, including selecting a strong Stilt password and not sharing it with anyone. Stilt takes steps to safeguard your personal information through vigorous physical, electronic, and operational policies and practices: - Session Time-outs; - Protection of Account Numbers; - Secure, Off-Site Hosting; - Defined Service Access points; - [SSL] certificate technology; - Data encryption - Network firewalls

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Collection

Is it clear why the service collects the personal data that it does? Yes

10/10

Decided May 17, 2020 (revision history). This question accounts for 12% of the final score.

This question deals with transparency. Even if the service uses data for reasons that aren't ideal for privacy, provided they list all of those uses, the service can still receive full credit for this question. However, if they are not explicit about their uses (by employing language like "such as"), a lower score is assigned.

Possible Options

No0/10
Somewhat4/10
Mostly7/10
Yes10/10
No personal data is collected10/10

Citation

To establish that you are over the age of 18; To verify your identity and guard against potential fraud; To pull a credit report from a credit bureau, such as Experian, to help determine your creditworthiness; To determine your eligibility for a Stilt loan; To enable our financial services partners to implement automatic payments and fund transfers; To contact you if there is a problem completing a transaction you requested or to discuss a problem with your account; To implement collection activities as needed; and/or To maintain regular communications with you concerning transactions you initiate, including but not limited to requesting information or assistance, submitting a loan request, and making payments. More generally, we may use information that we collect from you or that you provide to us:

To provide, maintain, protect and improve our services, to develop new ones, and to protect Stilt and our users; To notify you about changes to the Stilt site or any products or services we offer or provide though it; To keep a record of your communication to help solve any issues you might be facing; For our marketing purposes to offer our products and services to you, such as advertisements, by us through third parties; To offer you tailored content giving you more relevant search results and ads; To enforce or apply our Terms of Use, loan agreement, and any other agreements between you and Stilt, including for billing and collection; To fulfill any other purpose for which you provide it or otherwise give your consent; and/or To comply with any court order, law, or legal process, including retaining personal data or responding to any government or regulatory request.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the policy list the personal data it collects? Yes, generally

7/10

Decided May 17, 2020 (revision history). This question accounts for 12% of the final score.

All general categories of collected personal data are listed, though not all types of personal data are explicitly mentioned (for example, the list might use a phrase like 'such as' when listing types of personal data).

Possible Options

No0/10
Only summarily3/10
Yes, generally7/10
Yes, exhaustively10/10
N/A (no personal information is collected)10/10

Citation

Information we collect while you use our site helps us improve our services. During the loan application process we also request and collect personal and financial information from you, such as your name and address. We collect information when you use Stilt website. We also collect personal and financial information during the registration and loan approval process. Additional information may be gathered during your future use of the site. Information that we collect may include personally identifying information, such as your name, address, email address, telephone number, or social security number. We may also collect financial information such as your income, account balance, payment history, credit history, or credit scores. We and/or our service providers may also collect information that is about you. We and/or our service providers may use this aggregated information in the administration of our Site to improve its usability, evaluate the success of particular marketing/advertising campaigns, and help optimize our Site based on your needs. This may include your internet protocol (IP) address, geographical location, browser type, referral source, length of visit, number of page views, or cookies and anonymous identifiers.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service collect personal data from third parties? Yes

0/10

Decided May 17, 2020 (revision history). This question accounts for 12% of the final score.

This includes the use of data brokers and independent verification authorities (such as background check providers).

Possible Options

Yes0/10
Only for critical data7/10
No10/10

Citation

We and/or our service providers may also collect information that is about you. We and/or our service providers may use this aggregated information in the administration of our Site to improve its usability, evaluate the success of particular marketing/advertising campaigns, and help optimize our Site based on your needs. This may include your internet protocol (IP) address, geographical location, browser type, referral source, length of visit, number of page views, or cookies and anonymous identifiers.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow the user to control whether personal data is used or collected for non-critical purposes? No

0/5

Decided May 17, 2020 (revision history). This question accounts for 6% of the final score.

Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.

Possible Options

No0/5
On an opt-out basis, but only for some non-critical data/uses1.5/5
On an opt-out basis, for all non-critical data/uses3/5
N/A (no data used for non-critical purposes)5/5
On an opt-in basis5/5

Note

No information proving such.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Handling

Does the policy allow personally-targeted or behavioral marketing? Yes

0/10

Decided May 17, 2020 (revision history). This question accounts for 12% of the final score.

Possible Options

Yes0/10
Yes, but you can opt-out3.5/10
Yes, but you must opt-in7/10
No10/10

Citation

Advertisers may use cookies on our site to collect information similar to the information we collect, and target ads to you based on information you included in your profile. We may also use remarketing to advertise to visitors who haven’t completed a task, such as completing their loan application.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow third-party access to private personal data? Yes, not all parties specified

0/10

Decided May 17, 2020 (revision history). This question accounts for 12% of the final score.

The policy allows sharing personal data with third-parties (not just critical service providers), and does not explicitly list the third-parties.

This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).

Note that whether the policy allows sharing aggregated user data does not affect this question.

If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).

If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).

Possible Options

Yes, not all parties specified0/10
Yes, all parties specified (including non-critical service providers such as advertisers)3/10
Yes, not all parties specified (but only to critical service providers)7/10
Yes, all parties specified (only to critical service providers)8/10
No10/10

Citation

Advertisers may use cookies on our site to collect information similar to the information we collect, and target ads to you based on information you included in your profile. We may also use remarketing to advertise to visitors who haven’t completed a task, such as completing their loan application. Stilt may share information with third parties as described below.

Advertisers:

Partners & Service Providers:

Third Party Accounts:

Aggregated Information:

Business Transfers:

Links:

Law Enforcement:

Note

These are vague categories with no information.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow you to permanently delete your personal data? No

0/5

Decided May 17, 2020 (revision history). This question accounts for 6% of the final score.

Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.

Possible Options

No0/5
Yes, by contacting someone3/5
Yes, using an automated mechanism5/5
N/A (no personal information collected)5/5

Note

According to their support site (https://help.stilt.com/hc/en-us/articles/360004386554), they will keep your data for as long as needed, up to 2 years, or to up to 5 years, depending on your situation.

It does not, however, explain if you can or cannot delete your account.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


When does the policy allow law enforcement access to personal data? When reasonably requested

3/5

Decided May 17, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

Always0/5
Not specified0/5
When reasonably requested3/5
Only when required by a court order or subpoena4/5
N/A (no personal data to share)5/5
Never (special legal jurisdiction)5/5

Citation

To comply with any court order, law, or legal process, including retaining personal data or responding to any government or regulatory request.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.



Warnings

Stilt has no warnings published on PrivacySpy. PrivacySpy publishes warnings when it learns a service has announced a data breach or is found misusing user data. If you believe a warning should be published for Stilt, submit one here.


Highlighted Policy Snapshot ALPHA

No highlighted policy snapshot has been created for this privacy policy. To view the policy at its original location, click here.

4/10

How we calculate ratings →


Version Added

May 17, 2020

Ratings Updated

May 17, 2020

Warnings

0

Maintained by

doamatto

Original Location
Open in New Tab
Other Versions