Privacy Policy


Rev. Date 9/14

FACTS
WHAT DOES FIVE STAR BANK DO WITH
YOUR PERSONAL INFORMATION?
Why? Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do.
What? The types of personal information we collect and share depend on the product or service you have with us. This information can include:
  • Social Security number and account balances
  • Transaction history and overdraft history
  • Account transactions and checking account information
When you are no longer our customer, we continue to share your information as described in this notice.
How? All financial companies need to share customers’ personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers’ personal information, the reasons Five Star Bank chooses to share, and whether you can limit this sharing.
Reasons We Can Share Your Personal Information Does Five Star Bank Share? Can You Limit This Sharing?
For our everyday business purposes
such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus
Yes No
For our marketing purposes
to offer our products and services to you
No We Do Not Share
For joint marketing with other financial companies No We Do Not Share
For our affiliates’ everyday business purposes
information about your transactions and experiences
No We Do Not Share
For our affiliates’ everyday business purposes
information about your creditworthiness
No We Do Not Share
For non-affiliates to market to you No We Do Not Share
Questions? Call toll-free (800) 416-6117

What We Do
How does Five Star Bank protect my personal information?
To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings.
We also maintain other physical, electronic, and procedural safeguards to protect this information and we limit access to information to those employees for whom access is appropriate.
How does Five Star Bank collect my personal information? We collect your personal information, for example, when you
  • Open an account or apply for a loan
  • Use your credit or debit card to make deposits or withdrawals from your account
  • Give us your contact information
We also collect your personal information from others,such as credit bureaus, affiliates, or other companies.
Why can’t I limit all sharing? Federal law gives you the right to limit only
  • Sharing for affiliates’ everyday business purposes –information about your creditworthiness
  • Affiliates from using your information to market to you
  • Sharing for non-affiliates to market to you
State laws and individual companies may give you additional rights to limit sharing.
Definitions
Affiliates
Companies related by common ownership or control. They can be financial and non-financial companies.
- Five Star Bank has no affiliates.
Non‑Affiliates
Companies not related by common ownership or control. They can be financial and non-financial companies.
- Five Star Bank does not share with non-affiliates so they can market to you.
Joint Marketing
A formal agreement between non-affiliated financial companies that together market financial products or services to you.
- Five Star Bank does not jointly market.
Other Important Information
Special Notice for California Residents
We will not share personal information with non-affiliates either for them to market to you or for joint marketing without your authorization. We will also limit our sharing of personal information about you with our affiliates to comply with all California privacy laws that apply to us.

California Consumer Privacy Act Notice

 
Effective January 1, 2020
Rev. December 2022

Notice and Policy for the California Consumer Privacy Act (CCPA)

Five Star Bank is committed to maintaining the security of the personal information collected from its consumer customers. The following describes the information we may collect about you, how it may be shared, and your rights connected with that information.
 
CATEGORIES OF INFORMATION WE MAY COLLECT

In the past 12 months, we have collected the following categories of personal information identifiers such as, your:

  • Name;
  • Alias;
  • Addresses;
  • Online identifiers;
  • Email address;
  • Social Security number*;
  • Driver's license and/or passport number or similar identification*;
  • Internet Protocol (IP) address*;
  • Geolocation data;
  • Records of personal property;
  • Products or services purchased, obtained, or considered;
  • Account numbers*;
  • Information regarding your interaction with our web site;
  • Professional or employment-related information;
  • Financial information*; and/or
  • Publicly available information.
                                     * personal information identifiers that are considered sensitive information

SOURCES FROM WHICH WE OBTAIN INFORMATION

In the past 12 months, we have collected information for our business purposes from the following sources:

  • Information you provide to us when applying for a deposit account or loan, or any related services;
  • Information received from credit reporting agencies (third party);
  • Information from third-party identity verification services;
  • Internet search engines, including social media;
  • Job application with us;
  • Background check services (third party); and/or
  • Government entities.
Five Star Bank will retain the information we may collect as required by State and federal laws.

USE OF THE INFORMATION WE COLLECT

  • To approve or decline loan and/or deposit account applications;
  • To maintain or service those products and services you have with us;
  • To fulfill requirements according to legal process and law enforcement;
  • To detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activities;
  • To consider your job application for hiring; and/or
  • To commission consultants and auditing firms for institution risk analysis and mitigation.
Five Star Bank does not disclose sensitive personal information for purposes other than prescribed by the CCPA.

SHARING AND DISCLOSING OF INFORMATION

We do not share your information except as allowed by law. In the past 12 months, we have collected, and disclosed to third parties' private information for our consumer customers only with the third parties providing servicing of your products and services. Five Star Bank requires all third parties to contractually agree to not sell, share, or use your information for any other purpose, except as agreed upon for our business purposes. We share information with consultants and auditors for institutional risk analysis and mitigation.

We do not offer products and services to consumers under 16 years of age. If the Bank were to begin offering products and services to consumers under 16, we would only share with the third parties providing servicing of their products and services that are required to not sell, share, or use personal information.

SELLING OF INFORMATION

Five Star Bank does not sell the information it collects.

OPTING OUT OF OUR SELLING

Because Five Star Bank does not sell the information it collects, you do not have, nor do you need, the right to opt out of our selling your information. If at a future date, the Bank decides to sell the information it collects, you will be notified in advance, and given the opportunity to opt out.

YOUR RIGHTS

If your Personal Information is covered by the CCPA, you have the right to request that we disclose to you, free of charge, any of the following information:

The right to know what personal information is collected about you

Your request to us must be a verifiable request, meaning we must be able to verify your identity and that the personal information that we collected relates to you. We will acknowledge your request within 10 business days and provide the requested information within 45 days. If we need more time, we will inform you of the reason for delay during this time period and may extend the time to respond up to an additional 45 days. You may request this information up to two times per 12 month period. We reserve the right to verify the legitimacy of all requests, using any information you have given us, or any transactional information we have.

We are prevented from providing the following:

  • Your social security number;
  • Driver's license or other government-issued identification number;
  • Financial account number;
  • Any health insurance or medical identification number (if we have it);
  • Account passwords or security questions and answers.
 
The right to correct inaccurate personal information maintained about you

You have the right to request that Five Star Bank correct any inaccurate personal information that we maintain about you.

The right to have your information deleted

Federal and State laws may govern our retention of your information; however, anything we are not required to maintain under those guidelines may be deleted. You may request deletion of specific information by contacting us in one of the ways described in this Notice. Exceptions to our deletion responsibilities include information necessary to:

  • Complete the transaction for which the information is collected;
  • Provide a good or service requested by you or reasonably anticipated within the context of our ongoing business relationship with you;
  • Perform a contract between us and you;
  • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or to prosecute those responsible for that activity;
  • Debug to identify and repair errors;
  • To enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us;
  • Comply with a legal obligation;
  • Otherwise use your information internally in a lawful manner that is compatible with the context in which you provided the information.
The right to non-discrimination for the exercise of your Consumer Privacy Rights under this Act

You have the right not to receive discriminatory treatment by us for the exercise of your privacy rights conferred by the California Consumer Privacy Act (CCPA).

The right to allow an authorized agent to make a request

You may designate an authorized agent to make a request under the CCPA on your behalf. We retain the right to verify the legitimacy of that designation, and to identify both you and the agent. We will identify you with information you have previously provided to us and with information about your account(s) or transactions. We may deny a request from an authorized agent that does not submit proof that they were authorized by you.

The right to opt-out of the sale of personal information where we might otherwise sell it

Because Five Star Bank does not sell the information it collects, you do not have, nor do you need, the right to opt out of our selling your information. If at a future date, the Bank decides to sell the information it collects, you will be notified in advance, and given the opportunity to opt out.

TO EXERCISE YOUR CCPA RIGHTS AND MAKE A REQUEST:

We ask that you utilize the Contact Us Form or call us directly.

  1. Complete a Contact Us Form located at https://fivestarbank.com/contact-us

     2. To make a request or for questions related to this policy:
          Call us toll free at (800) 416-6117

Authorized agents making requests on your behalf will be asked by Bank staff to provide proof of authorization by you and the Bank will require proof of identity that validates both you and your authorized agent.

We may not honor your request if we cannot verify you or your authorized agent's identity. We will generally verify your identity from the information you provide us from information maintained by us in providing services to you. However, if we cannot verify your identity, we may request additional information from you or your authorized agent.

We will work to process all verified requests within 45 days pursuant to the CCPA and if we need the additional 45 days permitted by the CCPA, we will provide you with an explanation.


Notice to Applicants/Employees Regarding Collection of Personal Information

 
Five Star Bank (FSB) collects certain types of personal information from you, the job applicant/employee, as part of the employment relationship and/or hiring process. Under the California Consumer Privacy Act (“CCPA”), the California Privacy Rights Act of 2020 (“CPRA”), and other California privacy laws, any terms defined in the CCPA/CPRA (collectively, the “Act”) have the same meaning when used in this notice. FSB hereby provides you notice of the categories of personal information it has collected or will collect about its job applicants/employees as part of the employment relationship and/or hiring process, and the purposes for which it collects such information. This information is used for internal purposes only. FSB does not sell your personal information.

The Act provides applicants and employees with certain rights, which may include:

• Knowledge of information collected;
• Deletion of information collected;
• Opt-out of information collected;
• Opt-in of information collected;
• Correction of information collected and
• Not to be discriminated or retaliated against for exercising rights under the law.

Where We Obtain Information About You. FSB may collect information about you from the following sources: (1) you; (2) prior employers, references, recruiters, job-related social media platforms; (3) third-party companies, such as background check companies, drug testing facilities; and (4) claim administrators and investigators. Depending on FSB’s interactions with you, we may or may not collect all of the information identified about you.

The Personal Information That We Collect. The following are the categories of personal information that FSB may collect about its employees/job applicants. FSB collects this information to facilitate the hiring and employment process, including verifying your identity, supporting human resources procedures, and ensuring internal security. Not every category will apply to every job applicant/employee. Some information may be considered “sensitive personal information” under the Act.

• Identifiers, including real name, social security number, driver’s license number, and contact information;
• Educational and employment background and professional credentials;
• Medical records;
• Demographic data;
• Data regarding responses to employment application screening questions and/or assessments;
• Military or Veteran status (this is collected on a voluntary basis) and
• Geolocation data.

How Your Personal Information is Used. FSB may use Personal Information for various business purposes and as permitted by California and federal law:

• For hiring, retention, and employment purposes;
• To operate, manage, and maintain FSB’s business;
• To otherwise accomplish FSB’s business purposes and objectives, which may include for:
• Conducting research, analytics, and data analysis;
• Maintaining our facilities and infrastructure;
• Quality and safety assurance measures;
• Conducting risk and security controls and monitoring;
• Protecting confidential and trade secret information;
• Detecting and preventing fraud;
• Performing identity verification;
• Performing accounting, audit, and other internal functions, such as internal investigations;
• Complying with the law, legal process, and internal policies;
• Maintaining records and claims processing;
• Responding to legal requests for information and subpoenas and
• Exercising and defending legal claims.

And any other purposes authorized by the Acts, California or Federal law.

The above are examples of potential uses—FSB may or may not have used Personal and Sensitive Personal Information about you for each of the above purposes.

Selling of Personal Information. FSB does not sell your Personal Information.

Data Retention Periods. FSB retains Personal Information about you for 6 years, unless a shorter or longer period is required by California or federal law.

Changes to Notice of Collection: FSB reserves the right to amend this Notice of Collection at any time. When FSB makes any changes to this Notice of Collection, it will be made through a visible notice on its Careers page.

Contact Information: If you have any questions about FSB Job applicant/employee Notice of Collection
or any related topic, please feel free to contact Amanda Rusk at arusk@fivestarbank.com
or by phone at 916-660-5389.