Data Security Policy

Data Security Policy

We are committed to safeguarding the confidentiality, integrity, and availability of the personal and financial

information entrusted to Cash Cowboy. This policy explains the controls and practices we use across our products,
websites, and internal systems.

1) Scope & Compliance

This policy applies to all employees, contractors, service providers, and partners who access Cash Cowboy systems,
data, or infrastructure.

We align our security program with applicable laws and standards, including:

  • Canada: PIPEDA; provincial privacy laws (e.g., BC PIPA, Alberta PIPA, Manitoba FIPPA); consumer financial protections.
  • U.S. (where applicable): relevant federal and state data protection requirements for financial services.
  • Industry: encryption in transit/at rest, strong authentication, secure development, and (where applicable) PCI DSS.

2) Definitions

TermMeaning
Personal Information (PI)Information that can identify an individual (name, contact info, banking details, employment information).
Sensitive Financial DataBank statements, account numbers, IBV data, income records, loan history, and underwriting documents.
PIIPersonally Identifiable Information that directly links to an individual.
Data CustodianIT & Security team responsible for secure storage, infrastructure, and technical controls.
Data UserEmployees who handle customer data (e.g., underwriting, compliance, customer service).

3) Roles & Responsibilities

All Personnel

  • Use data only for approved business purposes.
  • Keep credentials private and secure; enable multi-factor authentication (MFA) where available.
  • Report suspicious activity or data concerns immediately.

Management & IT Security

  • Implement access controls and encryption.
  • Monitor activity and maintain security logs.
  • Conduct audits and risk assessments.
  • Provide regular training on secure handling procedures.

4) Access Control

  • Access to customer data is permission-based and role-specific (least privilege).
  • Internal systems require strong passwords, MFA, and secure session timeouts.
  • Access requests are documented; changes are logged and reviewed.

5) Data Protection

Encryption

  • All sensitive data is encrypted in transit and at rest.
  • Database fields containing banking or identity information may be masked or tokenized.
  • Encryption keys are stored securely and never shared in plain text.

Secure Transmission

  • Online forms, application data, IBV connections, and file uploads use TLS encryption.
  • External data exchanges occur only via secure, encrypted channels.

6) Network & System Security

  • Firewalls, intrusion detection, and endpoint protection safeguard our environment.
  • Systems are patched and updated regularly to mitigate vulnerabilities.
  • Servers are hosted in secure, compliant data centers with strict controls.

7) Data Storage, Backup & Retention

  • Customer data is retained only as long as required for regulatory and operational purposes.
  • Secure backups are maintained and tested for recovery.
  • Data scheduled for disposal is permanently destroyed using certified erasure procedures.

8) Third-Party Data Sharing

We share certain personal information with carefully vetted third parties to operate our services, process applications, and meet legal obligations. We require every third party to protect data using appropriate technical and organizational safeguards and to use it only for the contracted purposes.

Purposes of Sharing

  • Identity & fraud checks: identity verification, watchlist screening, fraud prevention.
  • Bank & income verification (IBV): secure retrieval of banking data you authorize for underwriting.
  • Payment processing: disbursements, debits, refunds, and chargeback handling.
  • Underwriting & servicing: credit risk assessment, decisioning support, collections logistics.
  • Customer support & communication: email, SMS, in-app messaging, and helpdesk tools.
  • Compliance & legal: regulators, auditors, law enforcement, and required disclosures.
  • Analytics & security: product analytics, system monitoring, threat detection.
  • Referral & counseling partners (if applicable): When you ask us to connect you with third-party partners, including but not limited to debt counseling, financial advisors, or any other service providers.
  • Sale or transfer of data: We may sell or transfer your data to third parties for marketing, business operations, or other purposes. This includes sharing anonymized or aggregated data for analysis, product development, or advertising.

Categories of Data Shared

  • Identifiers and contact details (e.g., name, email, phone, address).
  • Government/ID and eligibility details (as provided and permitted by law).
  • Financial information (e.g., bank account identifiers, authorized IBV data, repayment history).
  • Application data (employment, income, stated expenses), device and usage data for security.

Safeguards & Contracts

  • Third parties are bound by written agreements, confidentiality obligations, and security requirements.
  • Data is encrypted in transit and at rest where applicable; access is limited to a need-to-know basis.
  • We conduct due diligence and periodic reviews of vendors’ controls.
  • Cross-border transfers (if any) follow applicable laws and include appropriate transfer safeguards.

Your Choices

  • You may withdraw specific consents (e.g., marketing) at any time using the links in our messages or by contacting us.
  • If required by law in your region, you may opt out of certain “sales” or “sharing” for targeted advertising: Privacy Choices.
  • Note: Essential sharing for identity checks, IBV, underwriting, payments, security, and legal compliance is necessary to provide our services.

Where local law defines “sale” or “share” to include some advertising or analytics, we honor applicable opt-out rights.

9) Incident Response

  1. Immediately restrict access to affected systems.
  2. Investigate, assess impact, and document findings.
  3. Notify relevant regulators and affected customers as required by law.
  4. Implement remediation and preventive measures.

10) Employee Training

  • All staff complete mandatory privacy and security training.
  • Additional training is provided for underwriting, compliance, and leadership roles.

11) Policy Review

This policy is reviewed annually or in response to system changes, legal updates or identified risks

12) Contact

Questions about how we protect your information? Contact our Data Security & Privacy Team:

Email: [email protected]
Website: cashcowboy.net

Last Modified: March, 2025