Data Privacy and Protection
Last updated: Jan 20, 2026
Bank Account Security Procedures
This Section describes the security requirements, procedures and protocols (“Security Procedures”) applicable to the Bank Services. We work hard to protect your Bank Account and keep your money safe, and we expect you to play your part too. The tools we give you to access your money can be used to steal your money in the wrong hands. For that reason, you agree to protect the Bank Account numbers and electronic access devices, like your payment cards, secret keys and credentials. Your Bank Account numbers can also be used to electronically remove money from your Bank Account, and payment can be made from your Bank Account even though you did not notify us directly and order the payment. If you give someone your card or other access device to use, and they abuse it, you are liable for their transactions until you have told us that the person is no longer authorized.
You agree to comply with and maintain the minimum security requirements on your computer systems as may be required and communicated to you from time to time by us. You release the Bank and its agents and service providers from liability and agree to indemnify and hold the Bank and its agents and service providers harmless from any and all claims or liability resulting from your failure to comply with the security requirements and for allowing any malicious software to be loaded onto your computer systems to the extent permitted by law.
You are strictly responsible for establishing and maintaining security measures and complying with the Security Procedures. You agree to take reasonable steps to maintain the confidentiality of any API key, token, passwords, unique identifiers, codes, security devices, and any related information provided by us or established by you in connection with the Security Procedures, the Bank Account, and the Increase Services. You will immediately notify us if you suspect or know that any API keys, tokens, passwords, unique identifiers, codes, security devices, or any related information have been accessed by or provided to an unauthorized person. You will be responsible for unauthorized activity until we have been notified of the unauthorized access and have had a reasonable opportunity to act upon such notice, to the extent permitted by law. You must also take precaution in keeping your blank checks safe. Notify us immediately if you believe your checks have been lost or stolen. You may be responsible for some or all of any loss from the misuse of your blank checks if you are negligent in safeguarding your checks.
Error Resolution and Provisional Credit – Business Accounts
For transactions involving business or commercial accounts not subject to Regulation E, the Bank may, at its sole discretion, provide provisional credit to the business account holder during the investigation of an alleged unauthorized or erroneous transaction. The Bank’s decision will be made on a case-by-case basis and may consider factors including the nature and amount of the dispute, account history, and available documentation. You must cooperate with the Bank’s error resolution procedures for business accounts, including providing requested authorization documentation within two (2) Business Days. You acknowledge that the Bank has no obligation to provide provisional credit for business account transactions. If the Bank elects to provide provisional credit and the investigation determines the transaction was unauthorized or erroneous, you will reimburse the Bank for the provisional credit provided, along with any associated costs or fees.
Data Security
You will, and will require any of your material subcontractors to, establish and maintain appropriate administrative, technical and physical safeguards designed to (i) protect the security, confidentiality and integrity of any data or information of any customer or applicant for a Bank Account, including, but not limited to, all lists of customers, former customers, account applicants, and all information relating to and identified with such customers or applicants, including, but not limited to, account transaction and balance data, and “non-public personal information” as defined by GLBA Gramm-Leach-Bliley Act and its implementing regulations, as amended, including, but not limited to, postal and e-mail addresses and associated data (including any personally identifiable information, personal account information, financial information, card numbers or expiration dates, account numbers, transaction data, personal identification numbers and other related information, social security numbers or personal or financial information) provided by a customer or account applicant (collectively, “Customer Data”). You shall (a) ensure against any anticipated threats or hazards to the security and integrity of Customer Data, (b) protect against unauthorized access to or use of such information or associated records which could result in substantial harm or inconvenience to any customer or applicant, and (c) ensure the proper disposal of Customer Data (collectively, the “Security Program”).
Each Party (Bank, Platofrm, and End User, as applicable) shall protect Customer Data and Confidential Information received or accessed in connection with the Program using at least the same degree of care it uses to protect its own similar information, and in no event less than a commercially reasonable standard of care. Each Party shall maintain and comply with a comprehensive written information security program (“Security Program”) containing appropriate administrative, technical, and physical safeguards designed to protect Customer Data against unauthorized access, acquisition, use, alteration, or disclosure. Such Security Program shall comply with all applicable federal and state laws and regulations, applicable payment network rules, and applicable regulatory guidance, as amended from time to time.
The Bank shall maintain a Security Program consistent with applicable banking laws and supervisory expectations. The Platofrm shall maintain a Security Program consistent with applicable laws and contractual obligations applicable to its role as program manager and service provider. To the extent an End User accesses or transmits Customer Data through a Platform, the End User shall use reasonable security measures to safeguard its credentials and systems and shall comply with all applicable Platform terms of use.
In the event of a Security Incident involving Customer Data (including unauthorized access, acquisition, use, or disclosure), the Party experiencing or discovering the incident (“Impacted Party”) shall notify the other applicable Party or Parties without undue delay and in no event later than forty-eight (48) hours after discovery, unless a shorter timeframe is required by applicable law. Such notice shall include, to the extent known at the time, a description of the nature of the incident, the categories of Customer Data affected, and the corrective actions taken or planned.
The Impacted Party shall, at its own expense, promptly take all commercially reasonable steps to contain, investigate, mitigate, and remediate the Security Incident. The Parties shall reasonably cooperate with one another in investigating the incident and fulfilling any required regulatory, payment network, or consumer notification obligations. Notwithstanding the foregoing, the Bank shall retain final authority over regulatory notifications where required by applicable banking law, and no Party shall issue public statements, regulatory notifications, or consumer communications relating to the Security Incident without prior coordination with the Bank, except where legally required.
Nothing herein relieves any Party of its independent legal obligations under applicable law.
Automated Clearing House Origination
Access to originate automated clearing house (“ACH”) entries is subject to the Bank’s review and approval. The Bank may, at its discretion, permit you to initiate ACH entries to debit or credit other bank accounts. Not all customers will be authorized for ACH origination. If the Bank approves your access, the provisions of this Section, along with any supplemental terms and conditions the Bank may establish, will apply.
Capitalized terms not defined in this Section have the meanings provided in the Operating Rules and Guidelines of the National Automated Clearinghouse Association (“the NACHA Rules”). The Bank may enable Bank Accounts to originate ACH debit or credit Entries by means of the Automated Clearing House Network (“ACH Services”) and according to the NACHA Rules. You agree you will comply with the NACHA Rules (including the obligation to obtain proper authorizations and retain records as required), any additional rules adopted by local or state ACH associations, the terms of this Bank Agreement, and the terms of any additional agreement the Bank may request in connection with the origination of ACH Entries. You shall be bound by and comply with the NACHA Rules for all Entries, whether an Entry is sent through the ACH network or not. The Bank may limit the type of Entries you are authorized to originate for any reason. You acknowledge receipt of the Security Procedures and agree that the Security Procedures apply to ACH Services and are commercially reasonable procedures for you. You authorize the Bank to act as the Originating Depository Financial Institution (“ODFI”) on your behalf.
The Bank may impose volume or dollar limits on ACH entries you initiate and may suspend or reject any entry that exceeds those limits or appears to violate applicable law or the NACHA Rules. You agree not to originate unauthorized or unlawful entries, including internet gambling or transactions involving sanctioned parties. You are responsible for all returned or reversed entries and any resulting obligations.
ACH Access, Approved Activities, and Risk Management
The Bank will establish risk standards and evaluations with each ACH Originator to identify the types, frequency, and volume of ACH activity, as well as the associated level of risk. If your activity is deemed higher risk, such as acting as a Third-Party Sender or Processor, or if the Bank later determines your activities present higher risk, additional measures will be required to ensure compliance with all applicable rules and regulations.
As an RDFI (Receiving Depository Financial Institution), the Bank receives ACH entries either directly or indirectly from an ACH Operator for posting to customer accounts. The Bank will ensure the timely receipt and processing of all ACH entries, returns, Notices of Change (NOCs), and related activities, in accordance with NACHA Operating Rules.
Cross-Border ACH Transactions
The Bank processes International ACH Transactions (IATs) for customers subject to all applicable rules and regulatory requirements. IATs are reviewed by the Bank’s BSA/Compliance team for suspicious activity in accordance with applicable laws.
Destroyed Checks
The Bank does not accept destroyed checks (XCK entries) for ACH processing, consistent with core system configurations.
Processing, Transmittal, Settlement, and Rejection
You will transmit Entries in compliance with the formatting and other requirements provided by us to you and in accordance with the Security Procedures. You authorize the Bank to: (a) process Entries received from you or your agent; (b) transmit such Entries as an Originating Depository Financial Institution to the ACH network; and (c) settle for such Entries. Subject to the terms and conditions of this Bank Agreement, you will transmit such Entries by the applicable deposit deadline of the ACH network, provided (i) such Entries are completely received by the cut-off time established by us and the NACHA Rules from time to time; (ii) the Entry Date on the file satisfies the criteria established by the Bank from time to time; and (iii) such Entry otherwise complies with the terms of this Bank Agreement. You have no right to cancel, reverse, or amend any Entry after its receipt by the Bank; however, the Bank will use commercially reasonable efforts to act on a request by you to cancel an Entry before transmitting it to the ACH. Any such request shall comply with the Security Procedures and the Bank shall have no liability if the Bank fails to effect the cancellation. You acknowledge that in the case of a Same-Day Entry, any request by you to cancel an Entry must be made immediately for the Bank to have an opportunity to effect cancellation. Despite the Bank’s commercially reasonable efforts to act on such a request, cancellation of a Same Day Entry may nevertheless be impossible, and you understand and accept the risk of this occurrence. The Bank will have the right to reject any Entry that does not comply with the requirements of this Bank Agreement or for any reason permitted under the NACHA Rules. The Bank will also have the right to reject any Entry if you have exceeded the Exposure Limits), have failed to maintain reserve balances have failed to comply with the Security Procedures, or have failed to meet any obligation to us or the Bank, including payment obligations pursuant to this Bank Agreement or any other obligation.
The Bank may, in the Bank’s discretion, reject any credit Entry that contains an effective Entry date more than two (2) Business Days after the Business Day such Entry is processed by the ACH Operator; or the effective Entry date for a debit Entry is more than one (1) Business Day after the processing date, or longer in the Bank’s discretion. The Bank will notify you of such rejection no later than the Business Day such Entry otherwise would have been processed, unless the effective date is the Business Day the file was received, in which case the Bank will notify you of rejection the following Business Day. Notices of rejection are effective when given. The Bank shall have no liability to you for a rejection of any Entry or the fact that notice is not given at an earlier time than provided in this Section. The Bank will have no liability to you for any rejection of an Entry or the fact that notice is not given at an earlier time than that provided for in the NACHA Rules.
If any Entry (or request with respect to an Entry) received by the Bank was transmitted or authorized by you or your agent, you shall pay us the amount of the Entry, regardless of whether the Bank complied with the Security Procedures with respect to that Entry and regardless of whether such Entry was erroneous or contained an error that would have been detected if the Bank had complied with the Security Procedures. If any Entry (or request with respect to an Entry) received by the Bank purports to have been transmitted or authorized by your or your agent, it will be deemed effective and you shall be obligated to pay the Bank for such Entry even if the Entry was not authorized by you, provided the Bank accepted the Entry in good faith and acted on it in compliance with the Security Procedures.
Payment Related to Entries and Returned Entries
The Bank will generally debit your Bank Account for credit Entries (including debit Reversals) immediately. The Bank will credit your Bank Account for debit Entries (including credit Reversals) after two Business Days. All such credits are provisional, and we may charge your Bank Account for a returned or rejected electronic debit Entry.
You will pay the Bank for any returned debit Entries (including rejected debit Entries) or any adjustment Entries, which the Bank has previously credited to the Account. You agree that we do not need to send a separate notice of debit Entries that are returned unpaid. Reports containing information regarding returned debit Entries are available. You authorize the Bank to debit your Bank Account on the day the returned or rejected electronic debit Entry is received or thereafter. You agree to maintain a sufficient balance in your Bank Account to cover returned or rejected electronic debit Entries. If a returned or rejected electronic debit Entry cannot be debited against your Bank Account, you will pay the Bank the amount of the returned or rejected debit Entry.
If the effective date is after the Business Day the file was received, the Bank will notify you of the receipt of a returned Entry from the ACH no later than one (1) Business Day after the Business Day of such receipt. The Bank shall have no obligation to re-transmit a returned Entry if the Bank complied with the terms of this Bank Agreement with respect to the original Entry; provided, however, the Bank may reinitiate the returned Entry no more than two times in accordance with the NACHA Rules.
The Bank will inform you of all notifications of change (NOC) received no later than two (2) Business Days after the receipt of the Entries. You agree to make the changes submitted within six (6) Business Days of the settlement date of the original Entry or before the next originated Entry, whichever is later; provided that, you may choose to make the changes specified in any NOC or corrected NOC received with respect to any Entry. If a NOC is incorrect, you will generate a refused notification of change and deliver it to the Bank.
You may initiate a reversing Entry for erroneous or duplicate transactions, as permitted by the NACHA Rules. In doing so, you warrant that you have initiated the Entry within five days of the original Entry and within 24 hours of the discovery of the error. The account holder for the reversing Entry must have been notified of the reversal and the reasons for the reversal no later than the settlement day of the reversal. For reversing Entries, you indemnify all parties to the transaction(s) from and against any claim, demand, loss, liability, or expense.