U.S. Online Privacy Notice

(Last updated April 3, 2025)

Your privacy matters to us. At Gulf of American Bank, we regularly review our policies and follow strict privacy standards to protect your personal information. This U.S. Online Privacy Notice ("Notice") explains how we collect, use, and share personal information when you interact with us through our websites, mobile apps, event registration pages, and official social media channels ("Sites and Mobile Apps"), whether you access them via computer, smartphone, tablet, or other connected devices.

This Notice covers:

  • How we collect personal information when you visit, use, or interact with our digital services or see our ads online.

  • How we use and share that information to deliver products, services, and personalized experiences, including for advertising and event purposes.

When we mention "Gulf of American Bank," "we," "us," or "our," we refer to Gulf of American Bank and its U.S. affiliates and subsidiaries that link to or reference this Notice.

By using our Sites and Mobile Apps, you agree to this Notice. Our online services are intended for a U.S. audience. If you access them from outside the U.S., your information may be transferred or processed in the United States.

Working with Third Parties

We may partner with third-party providers who are contractually obligated to follow our privacy and security policies. If you visit a third-party site or mobile app linked from our services, please review their privacy policies to understand how they collect and use your information.

Updates to This Notice

We may update this Notice periodically to reflect changes in technology, law, or business practices. The "Last updated" date at the top will reflect the most recent revision. Please review the Notice whenever you have questions about our practices.

OUR ONLINE PRIVACY PRACTICES

Transparency & Consent

We are committed to being transparent with how we use your information. When legally required, we ask for your consent. Otherwise, by using our Sites and Mobile Apps, you consent to our data practices as described here and in accordance with applicable law.

Links to Other Sites

We may provide links to third-party websites (e.g., credit bureaus, merchants, or service providers). These sites are not controlled by Gulf of American Bank and may have different privacy policies. We are not responsible for the security, content, or practices of those sites.

How We Protect Your Information

We use physical, digital, and procedural safeguards to protect personal data in accordance with federal and state laws. This includes secured facilities, encryption, access controls, and oversight of our service providers. In the event of a data breach, we provide timely notification as required by law.

We do not knowingly collect personal information from children under 13 without parental consent. Our services are not marketed to minors. For more details, see our Children's Privacy Policy.

Keeping Your Information Accurate

It's important your information is current and accurate. You can update your information through the "Contact Us" section of our Site or Mobile Apps, or by speaking with a customer service representative.

PERSONAL INFORMATION WE COLLECT ONLINE

How We Collect It

We collect personal information through:

  • Forms you complete to apply for or open accounts

  • Product or service registrations

  • Event sign-ups

  • Surveys, promotions, and contests

  • Use of financial aggregation tools (like consolidated views of accounts)

  • Cookies and other tracking technologies (see our Cookie Policy)

We may also receive personal information through business partners or third-party providers operating on our behalf.

Types of Personal Information We Collect

Depending on how you interact with us, we may collect:

  • Contact Information: name, address, email, phone number

  • Account Application Info: credit history, income

  • Identifiers: Social Security number, driver’s license, account numbers

  • Login Info: user IDs, PINs, passwords, security questions

  • Uploaded Documents: check images, ID documents, forms

  • Payment Info: debit/credit card number, CVV, billing address

  • Device Data: IP/MAC addresses, browser settings, screen resolution

  • Usage Behavior: clicks, gestures, page activity, keystrokes

  • Communications: chat or messaging content, notification preferences

  • Ads & Interaction Data: responses to campaigns or promotions

  • Location Data: for services like ATM finders or fraud alerts

  • Event-Related Data: accessibility needs, travel information

HOW WE USE AND SHARE PERSONAL INFORMATION

How We Use It

We use your personal information to:

  • Provide and support banking products and services

  • Process applications and transactions

  • Authenticate your identity and protect against fraud

  • Customize your digital experience

  • Deliver advertising (online, email, mobile, direct mail, phone)

  • Conduct analytics and improve our services

  • Fulfill legal, regulatory, or contractual obligations

  • Facilitate virtual or in-person events

We retain your information only as long as necessary for business and legal purposes, and we delete it securely when no longer needed.

Health or Sensitive Information

If you provide health or accessibility-related data (e.g., during event registration), it is used only as necessary to accommodate your needs and in accordance with applicable law.

With Whom We Share Information

We may share your information with:

  • Our affiliates and subsidiaries

  • Service providers under contract with us

  • Government agencies, as required by law

  • Aggregated or de-identified data, for business insights and service improvements

You may limit how your personal data is shared by managing your preferences at Control How We Can Share Your Data and Market to You.

ONLINE BEHAVIORAL ADVERTISING

We use your data to tailor ads and promotions across platforms:

  • On our Sites and Apps: based on your usage behavior

  • Via Direct Marketing: email, mail, or phone offers

  • On Third-Party Sites: with the help of ad partners

Ad Targeting

We personalize ads based on your site activity, account type, interests, and interactions with our services.

Opting Out

Gulf of American Bank adheres to the Digital Advertising Alliance (DAA) principles. You can opt out of interest-based advertising via:

YourAdChoices

Network Advertising Initiative Opt-Out Tool

Opt-out requires cookies. If you delete them or use a new device or browser, you must opt out again.

Important Reminder

Even if you opt out of behavioral ads:

  • You may still receive general advertising from us

  • Logged-in users may receive tailored content based on their account

  • Client managers may continue to offer product suggestions

ADDITIONAL INFORMATION

Third-Party Aggregation Tools

If you use a third-party service to aggregate financial data from your accounts (e.g., budgeting apps), they may request your login credentials. We recommend you:

  • Verify the third-party’s privacy and security practices

  • Understand how your data will be stored and shared

  • Revoke access and change your password if needed

You may also manage third-party access within your online banking Security Center.

Social Media

Gulf of American Bank maintains official profiles on platforms such as Facebook®, Instagram®, and LinkedIn®.

  • Anything you post on our pages is subject to those platforms’ terms and policies.

  • We may collect content or information you share with us through social media in accordance with this Notice.

  • We may include social sharing tools on our websites. These may collect data about your browsing behavior when used.