Skip to main content

FIGFCU Online Privacy Notice

Internet/Website/ Mobile

Effective Date: July 14, 2026

This Online Privacy Notice is designed to inform you of our website and online information privacy practices, the types of information we collect, how the information is used, and to assure you that we maintain strict security procedures to protect your information. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand how we handle user privacy.

This Notice applies to members, prospective members, former members, the authorized representatives and agents of business or organizational members, and visitors to our website and digital services. It describes how Farmers Insurance Federal Credit Union ("FIGFCU," "we," "us," or "our") collects, uses, shares, and protects your personal information.

Regulatory Scope of This Notice

The legal framework that applies to your personal information depends on the type of information involved:

  • Member financial data (GLBA). Personal information we collect, use, and disclose to provide you with financial products or services is "nonpublic personal information" ("NPI") governed primarily by the federal Gramm-Leach-Bliley Act ("GLBA") and its implementing regulations, including the National Credit Union Administration's Part 716 and the Consumer Financial Protection Bureau's Regulation P. How we handle NPI is described in our separate GLBA Privacy Notice, which we provide to members at account opening and annually thereafter (or upon material change). NPI is exempt from most provisions of the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), under California Civil Code §1798.145(e).
  • Employee and job applicant data (CCPA/CPRA). Personal information we collect from current, former, and prospective employees is not exempt from CCPA/CPRA. The rights and disclosures described in the Your Privacy Rights sections of this Notice apply in full to this information.
  • Website visitor and other non-financial data (CCPA/CPRA and other state laws). Personal information collected from website visitors, marketing prospects, and through online tracking technologies that is not collected to provide a financial product or service is subject to CCPA/CPRA and other applicable state privacy laws.

The GLBA exemption under CCPA/CPRA applies at the data level, not the entity level. Where the same data is regulated under both frameworks, we apply the protections required by each.

In conjunction with our Online Privacy Notice you should also refer to our:

1. Information We Collect About You

To help us serve your financial needs, provide services, and offer new products and services to you, we collect personally identifiable information about you. The following table describes the categories of personal information we have collected in the preceding twelve (12) months:

Category Examples Business Purpose
Identifiers Real name, alias, postal address, phone number, unique personal identifier, online identifier, IP address, email address, account name, SSN, driver's license number Account opening and servicing; identity verification; fraud prevention; regulatory compliance; communications
Personal information Name, signature, SSN, address, phone, bank account number, credit/debit card number, financial information Account administration; loan processing; payment facilitation; regulatory reporting; credit evaluation
Business contact information Business contact information relating to the authorized representatives and agents of business or organizational members — such as company or organization name, job title or role, work email address, and work phone number Opening, administering, and servicing business and organizational accounts; verifying authority of account signers; communications with business representatives; regulatory compliance
Protected classification characteristics Age, date of birth, race, ethnicity, national origin, citizenship, marital status, sex, veteran or military status Regulatory compliance (e.g., fair lending reporting); membership eligibility verification
Commercial information Transaction information, purchase history, account balances, payment history, financial details Account servicing; statement generation; fraud monitoring; product recommendations; regulatory reporting
Internet or similar network activity Browsing history, search history, interaction with website, IP address, device information Website analytics and improvement; security monitoring; personalization of online experience; advertising effectiveness
Geolocation data Device location, IP-based approximate location Location-based offers and messages; fraud detection; branch/ATM locator functionality; security verification
Audio, electronic, visual, or similar information Call recordings when you contact our member services line; chat transcripts from online or mobile support; voicemail recordings Quality assurance; training; dispute resolution; fraud detection; regulatory compliance; service improvement
Professional or employment-related information Current or past employer, job title Membership eligibility verification; loan underwriting; account servicing
Employee and job applicant information Name, contact information, SSN, employment history, education, background check results, financial information for payroll; collected from applicants and current/former employees Application processing; employment management; payroll and benefits administration; legal and regulatory compliance. This data is subject to CCPA/CPRA and is not covered by the GLBA exemption.
Education information Student records or directory information, if collected in connection with loan applications (e.g., student loan refinancing) or scholarship programs Loan underwriting and eligibility evaluation; scholarship program administration
Inferences drawn from collected PI Profiles reflecting preferences, characteristics, behavior, attitudes, or aptitudes derived from any of the above categories Product prequalification and marketing; personalization of offers; fraud risk scoring; creditworthiness assessment
Email interconnectivity Data captured when you open emails from us or click on links or banners within our email communications Measuring effectiveness of member communications; improving relevance and engagement of marketing and service messages
Sensitive personal information Social Security number, driver's license, financial account number with access credentials, precise geolocation Identity verification; account authentication; regulatory compliance (BSA/AML, IRS reporting); fraud prevention; loan processing

2. Sources of Personal Information

We collect personal information from the following categories of sources:

  • Directly from you — when you apply for membership, open accounts, apply for loans, complete forms, or contact us
  • From your transactions — information about your account activity, payment history, and usage of our products and services
  • From third parties — consumer reporting agencies, identity verification services, government agencies, and joint marketing partners
  • Automatically — through cookies, log files, and similar technologies when you visit our website or use our digital services
  • From business representatives — contact and account information provided by the authorized representatives or agents of business or organizational members

3. How We Use Your Information

We may use your information:

  • To evaluate your eligibility for accounts, loans, and other products and services for which you apply
  • To respond to your inquiries and fulfill your requests
  • To administer, manage and service your accounts, products, and services
  • To send you marketing communications on products and services that may be of interest to you, and/or to prequalify you for such products and services
  • To personalize your experience on our website by presenting products and offers tailored to you
  • To verify your identity in order to allow you online access to your accounts, conduct online transactions, and to maintain measures aimed at preventing fraud and protecting the security of your account and personal information
  • To facilitate your transactions
  • To send you important information about your account(s), products and services
  • To comply with applicable law and regulation, other legal process, and law enforcement requirements
  • For our business purposes, such as data analysis, audits, developing new products and improving our existing products and services, enhancing our website, identifying usage trends, and determining the effectiveness of promotional campaigns
  • Location data is collected to provide location-based messages, offers, and interactions
  • To detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, and prosecute those responsible for such activities
  • To maintain and improve the quality and safety of our services

4. Categories of Third Parties with whom FIGFCU May Share Information

We may disclose your personal information, including nonpublic personal information, in the following circumstances:

Legal and Regulatory Requirements

We may disclose your information when required by law, regulation, court order, subpoena, or other legal process, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others, or to detect, prevent, or address fraud, security, or technical issues.

Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

We may share your personal information, including nonpublic personal information, with the following categories of third parties for the purposes described elsewhere in this Notice and as permitted by applicable law:

  • Service providers and processors. Vendors that perform services on our behalf, including cloud hosting and infrastructure providers, statement printing and mail fulfillment, document management and storage, member communications platforms, IT and cybersecurity support, software-as-a-service applications, and member service support providers. These vendors are bound by contractual confidentiality and use-limitation requirements.
  • Core data processor and banking technology providers. The provider of our core account processing platform and the providers of our online banking, mobile banking, bill pay, remote deposit, and digital banking technology. These providers process account, transaction, and authentication data necessary to operate our financial services.
  • Card networks and payment processors. Card networks (such as Visa and Mastercard), debit and credit card processors, ATM and shared-branching networks, and wire transfer networks used to facilitate transactions you initiate.
  • Fraud prevention, identity verification, and authentication vendors. Vendors that provide identity verification, knowledge-based authentication, document and biometric verification, device intelligence, fraud scoring, and transaction monitoring services to detect, prevent, and investigate fraudulent or unauthorized activity.
  • Consumer reporting agencies and specialty reporting agencies. Nationwide consumer reporting agencies and specialty consumer reporting agencies, to which we furnish account information and from which we obtain reports for underwriting, account management, and risk decisioning, consistent with the Fair Credit Reporting Act.
  • Joint marketing partners. Other financial institutions with whom we have entered into joint marketing agreements under GLBA to jointly offer financial products and services. Such partners are contractually restricted from using your information for purposes beyond the joint marketing arrangement.
  • Insurance and ancillary product partners. Providers of insurance products, debt protection administrators, and other ancillary product partners we make available to members.
  • Loan servicing, participation, assignment, and collection partners. Loan servicers, loan participants and assignees (including secondary-market purchasers of mortgages and other loans), and collection agencies engaged to recover on delinquent accounts.
  • Affiliates. Companies under common ownership or control with FIGFCU.
  • Analytics and advertising vendors. Third-party analytics, measurement, and advertising technology vendors that may receive information about your interactions with our website and digital services.
  • Professional advisors and auditors. External auditors, attorneys, consultants, and other professional advisors, in each case under obligations of confidentiality.
  • Regulatory and supervisory authorities. Federal and state regulatory and supervisory bodies.
  • Law enforcement and parties to legal process. Law enforcement agencies, courts, and parties to legal process, in response to subpoenas, court orders, search warrants, civil discovery requests, and similar legal demands, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
  • Parties to corporate transactions. In the event of a merger, acquisition, reorganization, financing, or sale of all or part of our assets, your personal information may be transferred as part of that transaction. We will notify you of any change in control of your personal information as required by applicable law.

5. Other Online Information We Collect and Use

In addition to the personal information described above, we automatically collect certain information when you visit or use our website and digital services:

Cookies and Similar Tracking Technologies

We and our service providers use cookies, web beacons, pixels, software development kits (SDKs), and similar tracking technologies on our website and digital services to operate the site, recognize your device, remember your preferences, analyze site performance, and — where you have not opted out — deliver advertising tailored to your interests. Cookies are small text files placed on your device; web beacons and pixels are tiny graphics or scripts that work alongside cookies to recognize visits and measure engagement.

Your Choices. You have several ways to control cookies and tracking on our site:

  • Cookie Consent Manager. You can accept, reject, or change your preferences for non-essential cookies (Functional, Performance, Social Media, and Targeting) at any time using the Cookie Consent Manager available on our website.
  • Global Privacy Control (GPC). When your browser transmits a GPC signal, we treat it as a valid opt-out of the "sale" and "sharing" of personal information for cross-context behavioral advertising, and we will configure cookies accordingly for that browser.
  • Browser Controls. Most browsers allow you to block, delete, or restrict cookies through their settings. Note that blocking Strictly Necessary Cookies will impair core site functionality, including the ability to log in to online and mobile banking.

For a complete description of the specific cookies and tracking technologies we use, the parties that set them, their duration, and the purposes they serve, please refer to our Cookie Policy.

IP Address

Your IP Address is a number that is automatically assigned to the device that you are using by your Internet Service Provider (ISP). An IP Address is identified and logged automatically in our server log files whenever a user visits the website, along with the time of the visit and the page(s) that were visited. Collecting IP Addresses is standard practice on the internet and is done automatically by many websites. We use IP Addresses for purposes such as calculating website usage levels, helping diagnose server problems, and administering the Credit Union's website.

Video Viewing Information

Our website may include embedded video content hosted by third-party platforms such as YouTube, Vimeo, and Facebook. When you view a video on our website, these third-party video hosting providers may collect information about your viewing activity through cookies, pixels, or similar technologies. This information may be shared with those providers to enable video playback, measure video performance, and deliver relevant content or advertising. You may manage your preferences for these technologies through our Cookie Consent Manager or by adjusting your browser settings. For more information about how these third-party providers handle your data, you may review their respective privacy policies.

6. Mobile / Online Applications — Tulee

FIGFCU mobile / online banking applications allow you access to your account balances, transfer funds, pay bills, make deposits, and conduct other financial transactions on your mobile devices. This Online Privacy Notice applies to any personal or other information that we may collect through the mobile applications. These applications can run in the background of a device even when they aren't being used.

The Tulee mobile application may collect additional information including device identifiers, operating system information, mobile network information, and biometric authentication data (such as fingerprint or facial recognition data used for login). If you enable location services, the app may collect precise geolocation data. You can manage these permissions through your device settings.

7. Advertising and Marketing

To opt out of advertisements and other marketing information (including loan preapprovals), you can call 800.877.2345.

You may also opt out of marketing communications by logging into your Online banking account and updating your communication preferences, by emailing us at msc@figfcu.org, or by writing to us at the address provided in the Contact Us section below.

8. Protecting Your Information, Confidentiality, and Security

We maintain an information security program designed to protect the confidentiality, integrity, and availability of personal information. Our program includes administrative, technical, and physical safeguards calibrated to the sensitivity of the information and the risks we identify.

Key elements of the program include:

  • Governance and accountability. Designated qualified individuals oversee the program and report periodically to senior management and the Board (or a Board committee). The program is reviewed and updated based on the results of risk assessments, testing, material changes to our operations, and the evolving threat landscape.
  • Risk assessment. We perform written risk assessments to identify reasonably foreseeable internal and external threats to the security of personal information, evaluate the likelihood and potential impact of those threats, and assess the sufficiency of our existing safeguards.
  • Access controls. We restrict access to personal information to authorized personnel and service providers with a documented business need, applying least-privilege and need-to-know principles, role-based access, periodic access reviews, and prompt termination of access when no longer required.
  • Authentication. We require multi-factor authentication for personnel and service providers accessing systems containing personal information, and we offer multi-factor authentication options for member access to our digital services.
  • Encryption. We encrypt personal information in transit over external networks and at rest in our production environments, using industry-standard cryptographic protocols, with documented exceptions managed through compensating controls.
  • Network and endpoint security. We deploy firewalls, intrusion detection and prevention systems, endpoint protection, network segmentation, and similar technical controls to protect our environment from unauthorized access and malicious activity.
  • Continuous monitoring and logging. We log and monitor user activity on systems containing personal information, and we operate detection and response capabilities designed to identify and respond to anomalous or unauthorized activity.
  • Vulnerability management and testing. We conduct vulnerability assessments and penetration testing on a regular basis, manage software patching, and remediate identified vulnerabilities according to documented timelines based on severity.
  • Secure development and change management. We follow secure software development practices for systems we develop in-house and apply documented change management procedures for systems that handle personal information.
  • Personnel security and training. Personnel with access to personal information receive privacy and information-security training at hire and periodically thereafter, are subject to background screening to the extent permitted by law, and are bound by confidentiality obligations.
  • Service provider oversight. Before engaging service providers that will handle personal information, we conduct due diligence to evaluate their security practices, impose contractual security and confidentiality requirements, and periodically reassess them as required by the GLBA Safeguards Rule.
  • Secure disposal. We securely dispose of personal information when it is no longer required to be retained, using methods described in the Data Retention section.
  • Incident response. We maintain a written incident response plan that establishes roles and responsibilities, internal and external escalation procedures, evidence preservation, regulatory notification, and member notification as described in the Breach Notification section.
  • Physical security. We protect physical premises, hardware, and records storage areas containing personal information through controlled access, surveillance, environmental controls, and secure handling and disposal of physical media.

We periodically test, evaluate, and adjust these safeguards in light of relevant technology developments, the sensitivity of the information we hold, internal and external threat assessments, and changes to our operations and business arrangements.

No method of transmission or storage is fully secure. Although we use reasonable measures to protect your personal information, no system can guarantee absolute security.

Member responsibilities. The security of your information also depends on actions you take, including safeguarding your account credentials, enabling multi-factor authentication where offered, keeping your contact information current, using updated devices and software, and being alert to phishing and social-engineering attempts. Please contact us promptly if you suspect your account or personal information has been compromised.

9. Breach Notification

FIGFCU maintains an incident response program designed to detect and respond to unauthorized access to or use of member information. In the event of a security breach involving your personal information, we will notify you in accordance with applicable federal and state law. Our notification will describe, to the extent possible, the nature of the breach, the types of information that may have been compromised, the steps we have taken in response, and what you can do to protect yourself.

10. Sale and Sharing of Personal Information

We do not "sell" your personal information for monetary consideration. However, our use of certain third-party cookies and tracking technologies on our website may constitute "sharing" of personal information for cross-context behavioral advertising purposes under the CCPA. You may opt out of this sharing by clicking the "Do Not Sell or Share My Personal Information" link available on our website, or by enabling the Global Privacy Control (GPC) signal in your browser.

11. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, to service your account, to comply with our legal and regulatory obligations (including record retention requirements under federal and state law), to resolve disputes, and to enforce our agreements. The specific retention period depends on the nature of the information and the reason for which it was collected. Key factors we consider include:

  • The duration of our relationship with you (e.g., while your account is active and for a reasonable period thereafter)
  • Applicable regulatory retention requirements
  • Whether the information is needed to resolve disputes, enforce agreements, or establish legal defense
  • The sensitivity of the information and the potential risk of harm from unauthorized disclosure

When we no longer have a legitimate business need to retain your personal information, we will securely delete or anonymize it in accordance with our data retention and disposal policies. We ensure proper disposal of member information in compliance with applicable guidelines.

12. Making Sure Your Information is Accurate

Keeping your FIGFCU account information up to date is very important. If your account information is inaccurate, incomplete, or not current, you can update it through our Online Banking Service (you must be registered) by selecting "Profile Info" and updating the appropriate information. You can also update your information by sending an email to msc@figfcu.org, calling us at 800.877.2345, by writing to us at FIGFCU, P.O. Box 2723, Torrance, CA 90509, or by visiting your local FIGFCU branch.

13. Social Media Sites

We provide experiences on social media platforms such as Facebook®, X® (formerly Twitter), LinkedIn®, and others that enable online sharing and collaboration among users who have registered with them. All social media websites referenced on the FIGFCU website, or on social media websites in which FIGFCU has a presence, are controlled and administered by a third party, are not owned or controlled by FIGFCU, have different privacy policies from FIGFCU, and this FIGFCU Online Privacy Notice does not apply to those sites. Any content you post on social media websites is subject to the privacy policies of those platforms. You should refer to their privacy policies to better understand your rights and obligations with regard to such content and their privacy and information sharing practices.

14. Links to Other Websites

We may provide links to other websites. If you follow links to websites not controlled by FIGFCU, you should review their privacy policies and other terms, as they may be different from our website.

15. Terminated Relationships

If your FIGFCU account relationship is terminated, we will not share information we have collected about you, except as permitted or required by law.

16. Protecting Children's Online Privacy

The primary goal of the Children's Online Privacy Protection Act is to give parents control over what information is collected from their children online and how such information may be used. We do not knowingly collect, solicit data from, or market to children under 13 years of age, nor do we knowingly sell such personal information. This website and our Services are not directed to persons under the age of 13. We do not knowingly collect information from, solicit, market, or provide online services or web pages directed to children under the age of 13. For more information about the Children's Online Privacy Protection Act (COPPA), visit the Federal Trade Commission's website at www.ftc.gov.

17. Your Privacy Rights

Depending on your location, you may have the following general rights regarding your personal information:

  • Right to Know and Access: You have the right to request that we disclose the personal information we collect, use, and disclose about you. If required by law, upon request, we will grant you reasonable access to the personal information that we have about you.
  • Right to Correct: You have the right to request that we correct inaccurate personal information that we maintain about you.
  • Right to Delete: You have the right to request the deletion of your personal information, subject to certain exceptions permitted by law.
  • Right to Limit Use and Disclosure of Sensitive Personal Information: Where provided by law, you have the right to limit the use and disclosure of your sensitive personal information to certain purposes permitted by law.
  • Right to Data Portability: You have the right to receive your personal information in a structured, commonly used, machine-readable format that may be transmitted to another entity.
  • Right to Opt Out: You have the right to opt out of the sale or sharing of your personal information and, where provided by state law, out of the processing of your personal information for targeted advertising. Verification of identity may be required to process requests.
  • Right to Opt Out of Certain Automated Decision-Making: Where provided by law, you have the right to opt out of the use of automated decision-making technology, including profiling, in furtherance of decisions that produce legal or similarly significant effects concerning you.
  • Right to Non-Discrimination: You have the right not to receive discriminatory or retaliatory treatment for exercising any of these rights.

Your Privacy Rights under California Law (CCPA/CPRA)

If you are a California resident, you have the following rights under the CCPA/CPRA:

Right What It Means How to Exercise
Right to Know Request the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it. Submit a request through any channel listed under How to Submit a Request below.
Right to Delete Request that we delete personal information we have collected from you, subject to legal exceptions (including records we are required to retain under applicable law). Submit a request through any channel listed under How to Submit a Request below.
Right to Correct Request that we correct inaccurate personal information we maintain about you. Submit a request through any channel listed under How to Submit a Request below, or update certain information directly through Online Banking ("Profile Info").
Right to Opt Out of Sale or Sharing Direct us to stop "selling" or "sharing" your personal information for cross-context behavioral advertising. We do not sell personal information for monetary consideration; certain advertising and analytics technologies on our website may constitute "sharing." Click the "Do Not Sell or Share My Personal Information" link on our website footer; adjust your preferences in our Cookie Consent Manager; or transmit a Global Privacy Control (GPC) signal from your browser. We honor each of these as a valid opt-out.
Right to Limit Use of Sensitive Personal Information Direct us to limit our use and disclosure of sensitive personal information (such as Social Security number, financial account credentials, precise geolocation, and biometric information) to purposes necessary to provide the services you have requested, and other purposes permitted by CCPA/CPRA. Click the "Limit the Use of My Sensitive Personal Information" link on our website footer or submit a request through any channel listed under How to Submit a Request below. As described in the Biometric Information section, we already limit our use of sensitive personal information to authentication, security, fraud prevention, and other permitted purposes.
Right to Non-Discrimination Receive equal service and pricing whether you exercise your privacy rights or not. Automatic — no action required.

How to Exercise Your Rights. To exercise any of the rights described above, you may submit a request by calling us toll-free at 800.877.2345, or by emailing msc@figfcu.org. We will verify your identity before processing your request. We may ask you to provide information that matches information we have on file about you. You may also designate an authorized agent to make a request on your behalf. We may require the authorized agent to provide written and signed permission from you, or proof of power of attorney.

Response Timing. We will respond to verifiable consumer requests within forty-five (45) calendar days of receiving the request. If we require more time, we will inform you of the reason and extension period in writing, which may be extended by an additional forty-five (45) days.

Appeals. If we decline to take action regarding your request, you may appeal our decision by contacting us at msc@figfcu.org. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decision.

California "Shine the Light" Law. California Civil Code Section 1798.83 permits our members who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes. If you are a California resident and would like to make such a request, please contact us using the information provided in the Contact Us section below.

18. Do-Not-Track and Global Privacy Control Signals

Do-Not-Track ("DNT"). Most web browsers include a Do-Not-Track feature or setting. At this time, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals.

Global Privacy Control ("GPC"). We recognize and honor the Global Privacy Control signal as a valid opt-out preference signal under the CCPA. When our systems detect that your browser is transmitting a GPC signal, we will automatically treat this as a valid request to opt out of the "sale" or "sharing" of your personal information, as those terms are defined under CCPA/CPRA.

19. Updates to this Online Privacy Notice

This Online Privacy Notice is subject to change.

If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes on our website or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.

We will review and update this Privacy Notice at least once every twelve (12) months. The "Last Updated" date at the top of this Notice indicates when the most recent revisions were made.

20. Contact Us

If you have any questions regarding this Online Privacy Notice or have privacy-specific inquiries, CCPA requests, or to exercise your opt-out rights, call us at 800.877.2345 or write to us at:

Farmers Insurance Federal Credit Union

Attn: Social Media / Website Administrator

P.O. Box 2723, Torrance, CA 90509

Email: msc@figfcu.org

This Credit Union is federally insured by the National Credit Union Administration.

This Credit Union is an Equal Housing Lender; we make loans without regard to race, color, religion, national origin, sex, handicap, or familial status.

If you are using a screen reader or other auxiliary aid and are having problems using this website, please call 800.877.2345 for assistance.

This Online Privacy Notice is subject to change; we review and update it at least once every twelve (12) months.