Privacy Policy
How BI Finance VP collects, uses, discloses and protects your personal information. We operate a lead-generation service that shares — and in some cases sells — personal information to lender and marketing partners as described below. You have rights you can exercise at any time.
1) Introduction and scope
This Privacy Policy ("Policy") explains how BI Finance VP LLC ("BI Finance VP," "we," "us," or "our") collects, uses, discloses, and protects personal information when you access or use the BI Finance VP mobile application, our related website, and any associated features or services (collectively, the "App").
BI Finance VP operates a loan-matching / lead-generation service. We are not a lender, bank, or broker, and we do not make credit decisions, set interest rates, or guarantee any loan offer. The App allows you to submit a single request for a personal loan or cash-advance product; we then collect your information and transmit it to a network of third-party lenders, financial institutions, marketing partners, and other buyers that may consider your profile and present pre-qualified offers to you. As described in Section 5, this transmission constitutes a "sale" of personal information under the California Consumer Privacy Act and several other state privacy laws.
By accessing or using the App, you confirm that you have read, understood, and agreed to this Policy, including the collection, use, and sale of your information described below. If you do not agree, you must stop using the App.
The App is directed to U.S. residents who are at least 18 years old (or the age of majority in their state). This Policy does not apply to employees, contractors, or third parties not under our control, nor to any product or service offered to you directly by a lender (which is governed by that lender's own privacy notice).
2) Laws and regulatory framework
In handling your personal information, we work within the following federal and state legal frameworks where applicable:
- Gramm-Leach-Bliley Act (GLBA) — your Social Security number, bank account and routing numbers, income, employment data, and similar items qualify as "nonpublic personal financial information" subject to GLBA's privacy and safeguarding requirements.
- California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA) — including the broad "sale" and "sharing" definitions described in Section 5.
- Fair Credit Reporting Act (FCRA).
- Federal Trade Commission (FTC) rules and guidance on data brokers, lead generation, and unfair or deceptive practices.
- CAN-SPAM Act and Telephone Consumer Protection Act (TCPA).
- Other applicable U.S. federal and state privacy, financial, and consumer-protection laws.
Some rights described in this Policy may be limited or preempted with respect to GLBA-covered financial data. Where federal law preempts a state-law privacy right, the federal rule controls.
3) Information we collect
We collect personal information from three primary sources: information you provide directly to the App, information we collect automatically when you use the App, and information obtained from third parties.
3a. Information you provide directly
When you create an account and submit a loan-matching request, you provide us with the following specific data. We collect each item for the reason noted.
- Personal identifiers — full legal name (first, middle, last); date of birth; email address; mobile and/or home phone number; and full residential address including street, city, state, and ZIP code.
- Social Security Number (SSN) — used to verify your identity, perform "Know Your Customer" (KYC) checks that our lender partners are required to complete, and detect and prevent fraud. SSNs are encrypted in transit and at rest.
- Driver's license number and issuing state — used for identity verification, state-eligibility checks, and KYC.
- Bank account number (full), bank routing number, bank name, and account type (checking / savings) — used by lender partners to verify the account, confirm ownership, and set up potential ACH disbursement or repayment.
- Employer name and employer phone number — used by lender partners to verify employment and income.
- Employment status, job title, monthly or annual gross income, and source of income — used to evaluate eligibility for a loan match.
- Purpose of the loan or cash-advance request — to help lenders consider whether your request fits their product offerings.
- Account and security data — usernames, passwords, PINs, one-time passcodes (OTP), and security responses, stored using industry-standard encryption.
- Communications and uploads — messages, documents, or files you submit through the App or to our support team.
- Consents and acknowledgments — electronic signatures, checkbox confirmations, and records related to disclosures or agreements.
3b. Information collected automatically
- Device and technical data — IP address, device identifiers, device type, operating system, App version, language settings, time zone, and diagnostic or crash data.
- Usage data — screens viewed, features used, session duration, timestamps, click behavior, and referral sources.
- Approximate location — derived from your IP address or device signals for fraud prevention, compliance, and service optimization. We do not collect precise GPS coordinates.
- Cookies, mobile SDKs, and similar technologies — used for authentication, security, session management, analytics, and (where you consent) advertising attribution.
3c. Information from third parties
- Identity verification and fraud-prevention service providers.
- Credit bureaus and alternative data providers, in the FCRA context (see Section 14).
- Lender and financial partners that interact with your request.
- Referral, marketing, and advertising partners that direct users to the App or receive referrals from us.
- Public databases and government sources, when required for verification or compliance.
4) How we use your information
We use the personal information described in Section 3 for the following purposes:
- To create, authenticate, and manage your account.
- To verify your identity (KYC) and run anti-money-laundering and fraud checks.
- To package your data into a consumer lead and transmit it to third-party lender and marketing partners (see Section 5 — Sale and Sharing of Personal Information).
- To sell your personal information to third-party lenders, financial institutions, marketing partners, data aggregators, and other buyers, as described in Section 5.
- To facilitate transactions, including any account verification, disbursement, or repayment activity carried out by lender partners.
- To respond to your inquiries and provide customer support.
- To send transactional communications, and — where you have separately consented — marketing communications.
- To monitor App performance, analyze usage patterns, and improve our service.
- To comply with legal and regulatory obligations and to enforce our Terms of Use.
5) Sale and sharing of personal information
5.1 We sell your personal information
Please read this section carefully. BI Finance VP LLC sells personal information as that term is defined under the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and analogous state privacy laws. Selling, in this context, includes disclosing personal information to a third party in exchange for monetary or other valuable consideration — including referral fees, per-lead fees, cost-per-lead (CPL), cost-per-acquisition (CPA), revenue share, or similar arrangements.
We sell personal information to:
- Third-party lenders and financial institutions (personal-loan, installment-loan, cash-advance, and similar product providers).
- Marketing partners that promote financial and non-financial products to you.
- Data aggregators and lead buyers that may resell the data further down the chain.
- Other buyers that pay for or otherwise provide valuable consideration for consumer leads.
The data that may be sold includes the full set of information described in Section 3 — specifically: full legal name; date of birth; email address; phone number; full residential address including ZIP code; Social Security Number; driver's license number and issuing state; full bank account number, routing number, bank name, and account type; employer name and employer phone number; employment status, job title, and income; source of income; and the purpose of the loan or cash-advance request.
We may receive monetary compensation, per-lead fees, revenue share, or other valuable consideration in exchange for these data transfers. Compensation arrangements may influence which lender or partner receives your data first, how partners are ordered in the App, or how their offers are displayed. Compensation does not change the loan terms each lender ultimately offers you.
5.2 Categories of third parties that buy or receive your data
- Licensed lenders and financial institutions, including providers of personal loans, installment loans, cash advances, and lines of credit.
- Insurance companies and other financial-product providers.
- Debt-relief, credit-counseling, and similar service providers.
- Marketing partners that send offers for financial and non-financial products.
- Data brokers and aggregators that may resell your data to additional buyers.
- Identity verification, fraud prevention, and analytics service providers acting on our behalf.
Once we have sold or otherwise transferred your data to a buyer, that buyer's own privacy policy governs how it is used. We do not control how a buyer uses your data after the sale, and we cannot recall data already in a buyer's possession. We encourage you to review the privacy notice of any lender or partner you interact with.
5.3 Your right to opt out of sale
- California residents, and residents of other states whose laws provide an opt-out right, may request that we stop selling and/or sharing their personal information.
- To submit a request, email [email protected] with the subject line "Do Not Sell My Information", or use the in-app "Do Not Sell or Share My Personal Information" link in Settings.
- We will process opt-out requests within 15 business days of receipt.
- Opting out stops future sales only. Data that has already been sold cannot be recalled from third-party buyers' systems.
- Even after you opt out, we may still share data as required by law or for core App functionality (for example, to complete a request you have initiated).
6) Legal basis for processing
Depending on the activity and applicable law, we process personal information based on one or more of the following grounds:
- Consent — obtained before data collection and sale, including separate consent for certain marketing communications. You may withdraw consent at any time, recognizing that withdrawal may limit or end your ability to use the App.
- Contractual necessity — to deliver the matching service you have requested.
- Legal obligation — including KYC/AML and regulatory recordkeeping.
- Legitimate business interests — fraud prevention, App security, and service improvement.
7) Data retention
We retain personal information only for as long as necessary to support legitimate business purposes and to satisfy legal and regulatory requirements. After applicable retention periods expire, data is securely deleted or anonymized. Indicative retention ranges include:
- Full applicant profile (name, SSN, address, bank information, income, employer data): retained for the duration of the business relationship plus approximately 5 to 7 years after last activity, or longer where required by law or active legal hold. For example, if you last used the App in January 2026, your full profile data may be retained until approximately January 2031–2033.
- Lead and sale records (which buyer received which data, when, and at what price): retained for approximately 5 to 7 years to satisfy FTC recordkeeping requirements and to support potential dispute resolution.
- Marketing and communication records (consent logs, email and SMS opt-ins, campaign responses): retained for approximately 2 to 3 years after last interaction or until opt-out plus 90 days.
- Device and usage logs (IP address, session data, clickstream): retained for approximately 12 to 24 months.
- Opt-out records (Do-Not-Sell and similar requests): retained for a minimum of 5 years to demonstrate compliance. For example, an opt-out received in March 2026 is logged and kept until at least March 2031.
- Support communications: retained for approximately 3 years after ticket resolution.
Specific periods may differ based on data type, applicable law, or regulatory guidance. Where the law requires a longer retention period, the legal minimum applies.
8) Data security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, or destruction. These include:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 where applicable).
- Role-based access controls implementing the principle of least privilege.
- Ongoing system monitoring and periodic security assessments.
- Vendor security due diligence and contractual data-security obligations imposed on buyers and processors that receive personal information from us.
- Employee training and internal information-security policies.
You are responsible for safeguarding your account credentials and for notifying us immediately at [email protected] of any suspected unauthorized access to your account. No method of internet transmission or data storage is 100% secure. In the event of a data breach affecting sensitive information, we will notify affected users and applicable regulators as required by law.
9) Your privacy rights
Depending on your state of residence and the type of data involved, you may exercise one or more of the following rights:
- Right to know / access — request confirmation of whether we maintain personal information about you; the categories and specific pieces collected; the categories of buyers to whom we have sold it (where technically feasible); and the business purposes of collection.
- Right to deletion — request that we delete personal information we have collected. We may retain certain data for legal, contractual, fraud-prevention, or regulatory reasons, and data already sold cannot be "undeleted" from third-party buyers' systems.
- Right to correction — request that we correct inaccurate or incomplete information.
- Right to portability — receive certain information in a structured, machine-readable format where required by law.
- Right to opt out of sale and sharing — see Section 5.3.
- Right to non-discrimination — we will not discriminate against you for exercising a privacy right, although some App features inherently require data processing.
To submit a privacy request, email [email protected] with the subject line "Privacy Request" and include your full name, state of residence, and a brief description of your request. We will verify your identity before responding. Authorized agents are permitted to submit requests where state law allows. We aim to respond within 45 days for California residents and within 30 days for other states where applicable.
10) Marketing opt-outs
- Email — every marketing email contains an unsubscribe link. Opt-out requests are processed within 10 business days, consistent with the CAN-SPAM Act. Transactional and service emails will continue.
- SMS — if you have consented to marketing text messages, reply STOP at any time to opt out, or HELP for help (TCPA). One-time passcodes and other transactional messages are not affected.
- Push notifications — can be enabled or disabled through your device's operating-system settings.
- Phone marketing calls — to opt out of marketing phone calls, contact us at [email protected]. The TCPA requires prior express written consent for autodialed marketing calls.
Opting out of marketing communications does not stop the sale of your data. To stop sales, you must submit a separate "Do Not Sell My Information" request as described in Section 5.3.
11) California residents (CCPA / CPRA)
If you are a California resident, the following additional rights apply under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
- Right to know — the categories and specific pieces of personal information we collect; the categories of sources; the business or commercial purposes for collecting it; and the categories of third parties to whom we sell or disclose it. As described in Section 5, this includes the fact that we sell personal information and the categories of buyers that receive it.
- Right to delete — subject to the exceptions permitted by the CCPA.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale and sharing — we sell personal information under the CCPA/CPRA definition. You may opt out by emailing [email protected] with the subject line "California Privacy Request — Do Not Sell" or by using the in-app "Do Not Sell or Share My Personal Information" link. We will process your request within 15 business days.
- Right to limit use of sensitive personal information — your SSN, driver's license number, and bank account information are "sensitive personal information" under the CPRA. You may request that we limit the use of this information beyond the purposes permitted by the CPRA.
- Right to non-discrimination — we will not discriminate against you for exercising any CCPA/CPRA right.
To exercise a California right, email [email protected] with the subject "California Privacy Request." We will verify your identity, respond within 45 days as required by law, and honor one free request per 12-month period. You may designate an authorized agent to submit a request on your behalf where state law allows. Some rights may be limited or preempted with respect to GLBA-covered financial information.
12) Other state privacy rights
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other states with comprehensive consumer-privacy laws may also have rights to access, correct, delete, and opt out of certain processing of their personal information. To exercise these rights, please email [email protected] with the subject "State Privacy Request" and indicate your state of residence.
13) Do Not Track and Global Privacy Control
Many web browsers offer a "Do Not Track" (DNT) signal. Because there is no consistent industry standard for how to respond to DNT signals, we do not currently alter our data-collection practices in response to DNT.
For California residents, we honor the Global Privacy Control (GPC) signal as an opt-out of the sale and sharing of personal information for cross-context behavioral advertising under the CCPA/CPRA, to the extent applicable. This does not affect collection or use of data for other purposes described in this Policy.
14) GLBA and FCRA notices
GLBA. Your SSN, bank account number, routing number, income, and employment data are "nonpublic personal financial information" under the Gramm-Leach-Bliley Act. A separate GLBA Initial Privacy Notice may be provided in connection with specific financial relationships and may govern that information. Where GLBA applies, it may limit or supersede certain state-law privacy rights.
FCRA. If we share your data with a consumer reporting agency, or if "consumer reports" or "credit reports" are used in connection with your request, your rights under the Fair Credit Reporting Act apply. We do not initiate hard credit inquiries without your express prior authorization, and we will clearly disclose when and by whom any hard inquiry may be performed.
Preemption note. GLBA and FCRA may limit or preempt certain state privacy rights (including some CCPA rights) with respect to financial data.
15) Cookies and tracking technologies
We use cookies, mobile SDKs, pixels, and similar technologies for the following purposes:
- Authentication and session management.
- Fraud detection and security monitoring.
- Analytics, performance measurement, and bug diagnostics.
- Advertising attribution, where you have provided any required consent.
You can manage cookies through your browser settings on the website and through your device's operating-system settings on mobile. Disabling these technologies may limit App functionality, including login, security features, and personalized information.
16) Children's privacy
The App is intended for users 18 and older (or the age of majority in your state) and is not directed to minors. We do not knowingly collect personal information from anyone under 18. Consistent with the Children's Online Privacy Protection Act (COPPA), if we discover that we have collected information from a child under 13, we will delete it promptly. If you believe a minor has provided personal information through the App, please contact us at [email protected].
17) International users
The App is designed for and directed to users in the United States. If you access the App from outside the U.S., your information will be transferred to and processed in the United States, where privacy and data-protection laws may differ from those of your home jurisdiction. By using the App, you consent to that transfer and processing.
18) Policy updates
We may update this Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make material changes, we will update the Effective Date above and may provide additional notice through the App or by email. Your continued use of the App after an updated Policy becomes effective constitutes acceptance of the revised Policy. If you do not agree to a change, you must stop using the App and may request that we delete your account where permitted.
19) Contact us
For questions, concerns, or privacy-related requests, please contact:
BI Finance VP LLC
455 N Clay Ave
Kirkwood, MO 63122-3905
United States
Email: [email protected]
Support hours: Monday – Friday, 8:00 AM – 8:00 PM Central Time
We aim to respond to reasonable inquiries within a practical timeframe, and no later than 45 days for CCPA requests from California residents.