Your trust and confidence in how we collect, use, and share information about you is a priority. This U. Online Privacy Notice for Consumers ( S
Notice) applies to our U. websites, SU. mobile applications, e-mail, our branded SU. social media sites or pages, and other SU. online or mobile services that link to or from this Notice as well as any interactions you may have with our digital advertising campaigns (collectively, the S
This Notice explains how we collect, share, use, and protect information when you visit or use the Sites. By using the Sites, you agree to this Online Privacy Notice.
As you review this Notice, here are a few important things to keep in mind:
- If you have a financial product or service with us for personal, family or household use with one of our U. businesses, that business would also have delivered to you a SU. Customer Privacy Notice ( S
Customer Privacy Notice) that explains how that business collects, uses and shares information about you and offers you certain choices with respect to the use and sharing of your personal information.
- This Site is not intended for children under 13 years of age. We do not knowingly solicit information online from, or market online to, children under 13 years of age.
- Wireless service providers, Internet service providers, device manufacturers and/or social media platforms may have their own privacy notices that are different from this one for the information they may access through your use of the Sites. We encourage you to read their privacy notices as the collection, uses and sharing of information by those third parties may be different than Citi.
- Our mobile, social media, or other online services, sites or pages may have additional terms about the privacy or use of your information. Please review the privacy notice for the specific Site you are using.
- Information We Collect Through the Sites
- Use of Information
- Sharing of Personal Information
- Managing Your Personal Information
- Other Information We Collect
- Aggregation Services
- Online Advertising
- Do Not Track
- Security of Personal Information
- Other Important Information
For Customers Enrolled in Citi Pay
We and our service providers may use information about your use of Citi Pay/Masterpass in order to create a customized checkout experience. After using Masterpass or visiting our website, a cookie may be placed on your device that will provide a customized Citi Pay/Masterpass checkout button on merchant websites. You can opt-out of seeing a customized checkout button on merchant websites and Mastercard's collection of analytical information by configuring the settings on Masterpass' AdChoices page.
For Customers Enrolled in Citi / Masterpass
We and our service providers may use information about your use of Citi / Masterpass in order to create a customized checkout experience. After using Masterpass or visiting our website, a cookie may be placed on your device that will provide a customized Citi / Masterpass checkout button on merchant websites. You can opt-out of seeing a customized checkout button on merchant websites and Mastercard's collection of analytical information by configuring the settings on Masterpass' AdChoices page.
We collect personal information that identifies you as an individual or relates to identifying information about you such as your name, address, phone number, and e-mail. Depending upon the services you request, we may collect additional personal information such as date of birth, relationship status, Social Security number, Driver's license number, bank account and/or payment card information and employment information, biometric information and personal identification numbers.
We, or companies we work with, collect other information such as browser and device information, app usage data, information collected through cookies, web beacons and other technologies, demographic and other information, and aggregated information about your visits to, or use of our sites, and other online services. While that information alone may not reveal your specific individual identity, we may associate this usage and other information we collect online with personal information about you. This other information is described in more detail below in Section 5.
We may use the personal and other information we collect from and about you to:
- Authenticate you so that you can access the Sites and conduct account transactions on the Sites;
- Recognize you, your device or your browser when you use the Sites so that we can facilitate navigation, display information more effectively, store your preferences and otherwise personalize your experience and enhance the use of the Sites;
- Process your applications and transactions;
- Respond to your inquiries, fulfill requests and request your feedback;
- Service your account and market to you, including advertisements and other communications tailored to you, on our Sites and third party sites, as well as offline (please see the section below entitled Online Advertising for more information on our online advertising practices);
- To track responses to our e-mails and advertisements and to measure the success of our marketing campaigns;
- Provide you with account information, as well as information regarding our branches and branch events;
- Facilitate social sharing functionality, where appropriate;
- Manage our business, such as for data analysis, audits, fraud monitoring and prevention, information security, improving the Sites, developing new products and services, identifying usage trends, and expanding our business activities;
- Review statistical information about use of the Sites in order to improve their design and functionality, to understand how they are used, and to assist us with resolving questions about the Sites; and
- Ensure that the Sites function properly and otherwise administer the Sites.
Your personal information may be shared:
- with our affiliates to the extent permissible under applicable law;
- with third parties, to permit them to send you marketing communications on our behalf;
- with our third party service providers, who provide services such as website hosting, data analysis, information technology and related infrastructure provision, customer service, processing your transactions, e-mail delivery, auditing, and other services;
- with individuals you associate with your social media account and to your social media account provider, in connection with your social sharing activity; and
- with a third party in the event of any proposed reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).
We also may use and disclose your personal information as we believe to be necessary or appropriate: (a) under applicable law, which may include laws outside your country of residence; (b) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include such authorities outside your country of residence; (c) to enforce our terms and conditions; and (d) to protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or others.
Where appropriate, we will limit sharing of your personal information in accordance with the choices you have provided us in response to our Customer Privacy Notice(s) or other privacy choices that we may make available.
We may share anonymized or de-identified aggregated information with third parties to help deliver products, services, and content that are tailored to the users of our Sites and for other purposes.
We may transfer information to Citi affiliated companies or third parties throughout the world, for example to process transactions and provide you with products and services. Regardless of where we process your information, we still treat it in accordance with this Notice and applicable law.
Keeping your account information accurate and up to date is very important. If your account information is incomplete, inaccurate or not current, please use the Contact Us option on our Site, or call or write to us at the telephone numbers or appropriate address for changes listed on your account statements, records, online or other account materials. You can also speak to a branch representative, your financial advisor or your designated account representative.
In addition to personal information you provide directly to us, we may collect other information about you, including acquiring and using services provided by third parties who collect and analyze customer data.
We collect information in a variety of ways, including:
- Through your browser or device: Certain information is collected by internet browsers or automatically through your device, such as your Media Access Control (MAC) address, computer type (Windows or Macintosh), screen resolution, operating system name and version, device manufacturer and model, device identifier, language, and Internet browser type and version. We may also collect your IP address, along with the time of your visit and the page(s) visited.
- Through your use of our mobile apps: When you download and use one of our mobile apps, we may collect and/or track app usage data, such as the date and time the app on your device accesses our servers and what information and files have been downloaded to or presented through the app.
fingerprint or identifier so that we can recognize your device. Other similar tracking technologies may be introduced and used by us in the future in connection with the Site.
- Physical location when using your mobile device: We may collect the physical location of your device by, for example, using satellite, cell phone tower, or wireless local area network signals, as well as through the use of beacons in our branches. We may also use your device's physical location to provide you with personalized location-based services and content, as well as to understand traffic patterns in and around our branches. In some instances, you may be permitted to allow or deny such uses and/or sharing of your device's location, but, if you choose to deny such uses and/or sharing, we may not be able to provide you with the applicable personalized services and content. We will collect your precise physical location only with your consent. Please note that if you enroll in certain branch related services, such as cardless entry and in- branch navigation services, the Citi Mobile App may collect your precise location through the use of beacons, whether or not you are using the app. We may also collect your precise physical location in order to provide you insights and facilitate goals regarding your spending activities. You can de-enroll in these services at any time.
- You can choose whether to accept cookies through your browser settings. For example, most browsers allow you to automatically decline cookies or decline or accept a particular cookie (or cookies) from a particular site when browsing. If you decide not to accept cookies, some features of the Site may not work properly because we may not be able to recognize your device and associate you with your Citi account(s). In addition, the offers or content we provide when you visit our site or on third party sites may not be as relevant to you or tailored to your interests.
- Local Shared Objects, sometimes referred to as
flash cookies may be stored on your hard drive using a media player or other software installed on your device. Local Shared Objects are similar to cookies in terms of their operation, but may not be managed in your browser in the same way. Restricting acceptance of Local Shared objects may impede the functionality of some Flash applications, including those used in connection with the Site including animation and video presentations. For more information on managing Local Shared Objects, click here. Similarly, certain authentication features of our mobile apps may set a persistent token, similar to a cookie, on your mobile device. This token allows that device to be uniquely associated or
bound with your account. This token will remain on your device until you un-enroll from those features or delete the app from your device.
In some instances, we may combine other information with personal information where permissible by law and applicable industry guidelines.
Citi, as well as others, offers account aggregation services that allow you to consolidate your electronically enabled financial account information from different sources (such as your accounts with us or with other financial institutions) so that you can view all your account information in one online location.
When acting as an account aggregator, Citi or its aggregation service provider may request your account user credentials for third-party (non-Citi) financial accounts, including usernames and passwords, in order to access your account information as your agent.
If you provide us access, as your agent, to your third-party account information we may use such information as well as your Citi account information where applicable, to provide you offers, suggestions and insights on your spending, savings and other financial behaviors. These insights are not investment, tax or legal advice and neither Citibank not any of its affiliates are acting as a tax, legal or investment advisor in providing same. With your consent, subject to written agreement, Citigroup Personal Wealth Management or other Citigroup businesses may currently or in the future provide investment advisory or other investment services based on online access to your investment account and other financial information.
You may cancel enrollment in Citi's aggregation service or delete accounts at any time. Upon cancellation or deletion of an account, we will delete and direct our third party service provider to delete this data from our and their respective records as permitted under applicable law, rules and regulations.
With regard to aggregation services provided by a third-party, if you provide your user credentials or other information about your Citi accounts to a third-party aggregation services provider, we will consider that you have authorized all transactions or actions initiated by such access information you provide, whether or not you were aware of a specific transaction or action. If you decide to revoke the authority you have given to an aggregation website, we strongly recommend that you change your password for Citi Online to ensure that the aggregation website cannot continue to access your account information.
We may, directly or through third parties, serve ads regarding products and services intended to be of interest to you on the Site and on third party sites or apps. We and others may use the online technologies described in Section 5 above to make inferences and predictions about your characteristics, interests and preferences based on your online interests and activities across other sites. We may also use technologies to associate and recognize your various mobile and desktop devices in order to deliver ads and other content in a consistent manner across the devices you use. Information we collect using the technologies described above may also be associated or linked with personal information, such as email or postal address, you provided directly to us or others.
Alternatively, personal information may also be linked with characteristics or attributes about you, such as lifestyle interests, in support of our marketing efforts. We may use, or share with others (in anonymous or non-readable form where appropriate) your information in order to better recognize you when visiting the Site and to provide relevant advertising (for Citi or third party's products/services), based on your interests, on the Site, on other sites and apps and other channels including television, email and direct mail. If you opt out of interest based advertising, as described below, you will not receive such customized ads on the Site or in other places.
Both the Network Advertising Initiative and the Digital Advertising Alliance (whose principles we adhere to) provide information about and technologies to opt-out of receiving some or all interest based advertising. You can also opt-out of interest based advertising by clicking on the appropriate icon within an interest based ad which will take you to tools to help you manage these choices. These technologies are browser and device specific, they must be adopted on each device you use. If you block or clear cookies, these technologies may not work. You will continue to see ads on the Site which reflect how you use the Site and our services.
Some browsers have a
do not track feature that lets you tell websites that you do not want to have your online activities tracked. At this time, we do not respond to browser
do not track signals.
The security of personal information about you is a priority. We seek to protect this information by maintaining physical, electronic, and procedural safeguards designed to protect personal information within our organization. We provide employee training in the proper handling of personal information. When we use other companies to provide services for us, we require them to protect the confidentiality of personal information they receive from us. Although we take extensive measures to protect your personal information, and to anticipate and mitigate new threats to personal information, unfortunately, no data transmission over the Internet or wireless network or data storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please immediately contact us.
Notice of Changes
We may change this Notice from time to time. When we do, we will let you know by appropriate means, such as posting the revised Notice on this page with a new effective date. Any changes will become effective when we post the revised Notice on the Site. Your use of the Sites following these changes means that you accept the revised Notice.
Third-Party Sites and Services
This Notice does not address, and we are not responsible for, the privacy, security, or other practices of any third parties, including any third party operating any site or service to which the Site links. The inclusion of a link on the Site does not imply endorsement of the linked site or service by us or by our affiliates.
In addition, we are not responsible for the information collection, usage, disclosure, or security policies or practices of other organizations, such as Facebook, Apple, Google, Microsoft, or any other third-party app provider, social media platform provider, operating system provider, device manufacturer, or wireless service provider, including with respect to any personal information you disclose to other organizations through or in connection with the Site.
The Site is controlled and operated by us from the United States and are not intended to subject us to the laws or jurisdiction of any state, country, or territory other than those of the United States. Information about you may be stored and processed in any country where we have facilities or in which we engage service providers, and, by using the Site, you consent to the transfer of information to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country. In certain circumstances, courts, law enforcement agencies, regulatory agencies, or security authorities in those other countries may be entitled to access your personal information.
If you have any questions about this Notice, please contact us. If you are contacting us from outside the United States, please refer to the Citi website in your country or use the contact details in the local privacy notice for your product.
Last Updated: March 2019