Privacy Policy
Last updated: July 2026
Whitestone Trust Credit Union ("we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our banking services, visit our website, or interact with us in any way.
1. Information We Collect
We collect information that you provide directly to us, information we collect automatically when you interact with our services, and information we obtain from third-party sources.
Information You Provide
- Identity Information: Full name, date of birth, nationality, government-issued identification numbers, and other details required for Know Your Customer (KYC) verification.
- Contact Information: Email address, phone number, residential address, and mailing address.
- Financial Information: Account balances, transaction history, income details, source of funds, tax identification numbers, and payment instructions.
- Account Credentials: Username, password, transaction PIN, and security questions used to access your account.
- Communications: Records of correspondence when you contact our support team, including emails, chat transcripts, and phone call recordings.
Information Collected Automatically
- Device and Usage Data: IP address, browser type and version, operating system, device identifiers, pages visited, time spent on pages, and referring website addresses.
- Login and Activity Data: Login timestamps, account actions performed, transaction patterns, and session duration information.
- Cookies and Similar Technologies: Information collected through cookies, web beacons, and similar tracking technologies. Please see our Cookie Policy for more details.
Information from Third Parties
- Credit Reference Agencies: Credit history and scoring information to assess creditworthiness where applicable.
- Identity Verification Services: Confirmation of identity document authenticity and address verification.
- Fraud Prevention Databases: Information to help detect and prevent fraudulent activity.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing Banking Services: To open and maintain your account, process transactions, manage transfers, issue cards, and deliver the banking services you request.
- Security and Fraud Prevention: To verify your identity, detect and prevent fraud, protect against unauthorized access, and maintain the security of our systems.
- Regulatory Compliance: To comply with applicable laws, regulations, and legal obligations, including anti-money laundering (AML) and counter-terrorism financing (CTF) requirements.
- Customer Support: To respond to your inquiries, resolve disputes, and provide technical assistance.
- Service Improvement: To analyse usage patterns, improve our website and services, and develop new features and products.
- Communications: To send you important account notifications, service updates, security alerts, and, with your consent, marketing communications about products and services that may interest you.
3. How We Protect Your Information
We implement and maintain administrative, technical, and physical safeguards designed to protect your personal information against accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use. These measures include:
- Encryption: All data transmitted between your device and our servers is protected using industry-standard Transport Layer Security (TLS) encryption. Data at rest is encrypted using AES-256 encryption.
- Multi-Factor Authentication: Access to your account requires multiple verification factors, adding an additional layer of security beyond a password.
- Access Controls: Strict internal access controls ensure that only authorised personnel with a legitimate business need can access your personal information.
- Security Monitoring: Continuous monitoring of our systems for suspicious activity, with automated alerts and incident response procedures.
- Regular Audits: Independent security assessments and compliance audits to verify the effectiveness of our safeguards.
4. Sharing of Your Information
We do not sell your personal information. We may share your information in the following circumstances:
- With Service Providers: Trusted third-party vendors who perform services on our behalf, such as payment processing, identity verification, IT infrastructure, and customer support. These providers are contractually bound to protect your information and use it only for the services we request.
- For Legal and Regulatory Purposes: When required by law, regulation, court order, or governmental authority, we may disclose your information to law enforcement, regulatory bodies, or other authorised entities.
- To Protect Rights and Safety: When necessary to enforce our terms and conditions, protect our rights and property, or safeguard the safety of our customers or the public.
- With Your Consent: We may share your information with other parties when you provide explicit consent for us to do so.
5. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your browsing experience, analyse website traffic, and personalise content. Cookies are small text files placed on your device when you visit our website. For detailed information about the cookies we use, how we use them, and your choices regarding cookies, please see our Cookie Policy.
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Right to Access: You can request a copy of the personal information we hold about you.
- Right to Rectification: You can request that we correct inaccurate or incomplete personal information.
- Right to Erasure: In certain circumstances, you can request that we delete your personal information, subject to our legal and regulatory retention obligations.
- Right to Restrict Processing: You can request that we limit how we use your personal information in specific situations.
- Right to Data Portability: You can request a copy of your personal information in a structured, machine-readable format.
- Right to Object: You can object to certain types of processing, including direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent, you can withdraw that consent at any time.
To exercise any of these rights, please contact us using the details provided in Section 7 below. We will respond to your request within the timeframe required by applicable law.
7. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, accounting, or reporting requirements. When your information is no longer needed, we securely delete or anonymise it in accordance with our data retention policies and applicable law.
8. International Data Transfers
Your information may be transferred to, stored, and processed in countries other than your country of residence, including countries that may have different data protection laws. When we transfer your information internationally, we ensure that appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable data protection laws.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes, we will notify you by email (sent to the address associated with your account) or through a prominent notice on our website prior to the change becoming effective. We encourage you to review this policy periodically.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please contact our Data Protection Officer:
- Email: [email protected]
- Phone: +1 (800) 555-0199
- Mail: Data Protection Officer, Whitestone Trust Credit Union, 1201 North Market Street, Wilmington, DE 19801, United States
You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your data protection rights have been violated.