Bricks Financial, Inc. (“Bricks,” “we,” “us”) provides banking, collections, accounting and compliance tools to nonprofit and member organizations in the United States. This policy explains how we handle personal information when you visit our website, apply for or use our services, or communicate with us.
We collect what we need to open and run your accounts, move your money, verify who you are, prepare your filings, and keep the platform secure. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Much of what we hold we are legally required to keep — anti–money laundering and tax rules set the floor, not us.
Who this policy covers
Bricks handles personal information in two different roles, and which one applies changes what you should do.
- Information we control
- Information about visitors to our website, people who contact us or book a call, and the administrators, signatories, beneficial owners and authorized users of an organization that applies for or holds a Bricks account. This policy governs that information, and you can bring requests about it straight to us.
- Information we process for a customer organization
- Information about an organization’s donors, members, families, residents, ticket buyers and other constituents, which the organization uploads to Bricks or collects through features like donation pages, dues collection and event ticketing. We process that information as a service provider on the organization’s instructions and under our agreement with it. The organization’s own privacy notice governs it — if you are a donor or member and want to access, correct or delete your record, contact the organization directly. If you come to us instead, we will refer you to them and help them respond.
This policy does not cover our partner banks, card issuers or payment processors, each of which handles information under its own privacy notice and, where applicable, its own Gramm-Leach-Bliley Act notice.
Information we collect
Information you give us
- Contact and relationship details — name, email address, phone number, mailing address, job title or role, organization name, and anything you write to us in a support request, form or booked call.
- Organization application details — legal name, EIN, IRS determination letter, formation and governing documents, board resolutions, addresses, and information about the organization’s activities and expected account use.
- Individual verification details — for the people we are required to identify (typically each control person and beneficial owner), full legal name, date of birth, residential address, Social Security number or ITIN, an image of a government-issued identification document, and ownership or control percentages. We collect this to meet our obligations, and our partner banks’, under the USA PATRIOT Act and FinCEN’s customer due diligence rule.
- Financial and transaction details — account and routing numbers for accounts you link, card details, payment instructions, transaction descriptions and amounts, and the ledger, chart of accounts, fund and expense data you keep in Bricks.
- Content you submit — documents, receipts, images, notes and files you upload.
Information we collect automatically
- Device and connection data — IP address, browser and operating system, device identifiers, language and time zone.
- Usage data — pages and screens viewed, links and features used, referring URL, session times, and error and diagnostic logs.
- Approximate location — a general region derived from IP address. We do not collect precise GPS location from our website.
- Cookies and similar technologies — see Cookies and similar technologies.
Information we receive from others
- Partner banks, card issuers, payment processors and networks — account status, transaction, settlement, return, dispute and chargeback data.
- Identity verification, sanctions screening and fraud prevention providers — results of identity checks, document authentication, watchlist and politically-exposed-person screening, device and risk signals.
- Consumer reporting agencies, where permitted by law and where relevant to an application or account.
- Services you connect — for example your accounting system, where you authorize an integration.
- Public and commercial sources — the IRS Business Master File, state charity registries, corporate registries, and business contact data providers.
- Your organization — an administrator may add you as an authorized user and provide your details.
How we use information
- To evaluate applications and open, maintain and service accounts.
- To process payments, transfers, donations, dues and ticket sales, and to issue receipts and confirmations.
- To verify identity and to meet legal obligations under the Bank Secrecy Act, the USA PATRIOT Act, sanctions programs administered by the U.S. Treasury’s Office of Foreign Assets Control, and related rules — including customer identification, beneficial ownership, screening, monitoring, recordkeeping and reporting.
- To detect, investigate and prevent fraud, unauthorized transactions and other prohibited or unsafe activity.
- To prepare Form 990 and 990-EZ returns and state charitable registrations from the data in your account, and to arrange review and sign-off by a licensed CPA.
- To categorize transactions, produce reports, and sync with the accounting systems you connect.
- To provide customer support and respond to what you ask us.
- To operate, secure, troubleshoot and improve the platform, including analytics and product research.
- To send service messages — and, where you have opted in or where permitted for existing business contacts, marketing messages you can stop at any time.
- To enforce our Terms of Service, protect our rights and the rights of others, and comply with law, subpoenas and other lawful requests.
- To evaluate or carry out a merger, financing, acquisition or sale of assets.
We may create de-identified or aggregated information — figures that do not identify any person or organization — and use it for any purpose, including benchmarking and product development. We maintain de-identified information in that condition and do not attempt to re-identify it.
How we share information
We do not sell personal information for money, and we do not share it for cross-context behavioral advertising, as those terms are used in California and other state privacy laws. We disclose personal information in these circumstances:
- Partner banks and issuers — the FDIC-member banks that hold deposits and issue cards, and their service providers, so that accounts and cards can be opened and operated.
- Payment processors and card networks — to authorize, clear, settle, return and dispute transactions.
- Service providers we engage to run the business under contract, including cloud hosting and storage, identity verification and fraud prevention, communications and email delivery, customer support tooling, electronic signature, call scheduling, and product analytics. They may use the information only to perform services for us.
- Accountants and tax preparers — the licensed CPAs who review and sign filings prepared through Bricks.
- Your organization — administrators can see the account activity, transactions and approvals of the organization’s authorized users. If you use Bricks through an organization, expect that organization to have visibility into what you do in it.
- Integrations you authorize — services you choose to connect, which then handle that data under their own terms.
- Professional advisers — lawyers, auditors, insurers and bankers, under duties of confidentiality.
- Legal and regulatory recipients — regulators, law enforcement, courts and other parties where we believe disclosure is required by law or reasonably necessary to comply with legal process, enforce our agreements, or protect the rights, safety or property of Bricks, our customers or the public. Some reports we are required to make, including suspicious activity reports, may not be disclosed to you.
- In a corporate transaction — a buyer, investor or successor in a merger, financing, acquisition, reorganization or sale of assets, including in bankruptcy, subject to this policy or a successor notice.
- With your direction or consent — anywhere else you ask us to send it.
Cookies and similar technologies
We use cookies, local storage and similar technologies for three things:
- Strictly necessary — signing you in, keeping your session alive, load balancing, and security and fraud prevention. These cannot be switched off in our systems.
- Preferences — remembering choices such as language and display settings.
- Analytics — understanding which pages and features get used, in aggregate, so we can improve them.
Most browsers let you block or delete cookies through their settings. Blocking strictly necessary cookies will break parts of the platform. We honor the Global Privacy Control signal where your browser sends one, and treat it as a valid opt-out request for the browser and device it comes from. Because there is no common standard for “Do Not Track” browser signals, we do not respond to them separately.
Your choices
- Marketing email — use the unsubscribe link in any marketing message, or email us. We will still send you service and legal messages about your account.
- Cookies — control them in your browser, as above.
- Account information — administrators can update most organization and user details inside Bricks. Some details, such as verification information we are required to retain, cannot be deleted while the account is open.
Your U.S. state privacy rights
Depending on where you live, state law may give you rights over the personal information we control. These rights currently exist in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky and Rhode Island, among others, and they vary by state.
Personal information we collect and use in connection with financial products and services is largely exempt from these state laws, because it is already regulated by the federal Gramm-Leach-Bliley Act. In practice that means most of the information tied to your accounts, transactions and identity verification falls outside the rights below, and is covered instead by Financial privacy under the Gramm-Leach-Bliley Act. We will tell you if that is why we cannot fulfill a request.
Rights that may be available to you
- Know and access — what we have collected about you, where it came from, why we collected it, and who we gave it to, and to receive a copy in a portable format.
- Correct — inaccurate personal information.
- Delete — personal information we hold about you, subject to legal retention requirements.
- Opt out — of sale, of sharing for targeted or cross-context behavioral advertising, and of profiling that produces legal or similarly significant effects. We do none of these, so there is nothing to opt out of.
- Limit the use of sensitive personal information — we use sensitive personal information only for purposes state law permits without an opt-out, such as providing the services you asked for, verifying identity, preventing fraud and complying with law, so we do not offer a limitation option.
- Non-discrimination — we will not deny service, charge a different price or give you a lesser experience for exercising a right.
- Appeal — if we decline a request and you are in a state that provides an appeal right, you can ask us to reconsider by replying to our decision. We will respond in writing within the time your state allows, and will tell you how to contact your state attorney general if you are still unsatisfied.
Making a request
Email info@bricksbanking.com with the request you want to make and the state you live in. We will verify you before acting — usually by asking you to respond from the email address on file and to confirm details we already hold. We do not create new accounts or ask for new sensitive information in order to verify a request. An authorized agent may act for you with written permission and proof of identity; in California, an agent may instead provide a valid power of attorney.
We respond within 45 days, and may extend once by a further 45 days where a request is complex, in which case we will tell you before the first period ends.
Categories of personal information
Over the 12 months before the date of this policy, we collected the categories of personal information below and disclosed each of them for a business purpose to the recipients described in How we share information. We sold none of them, and shared none of them for cross-context behavioral advertising.
| Category (CCPA) | Examples | Where it comes from |
|---|---|---|
| Identifiers | Name, postal and email address, phone number, IP address, account identifier, EIN | You, your organization, automatic collection, public sources |
| Customer records (Cal. Civ. Code §1798.80(e)) | Signature, physical address, financial account numbers, identification numbers | You, partner banks and processors |
| Commercial information | Products and services obtained, transaction and fee history, support history | You, automatic collection, partner banks and processors |
| Internet or network activity | Pages and features used, referring URL, session and error logs, email engagement | Automatic collection |
| Geolocation data | Approximate region derived from IP address | Automatic collection |
| Professional or employment information | Job title, role and permissions at the organization | You, your organization |
| Audio and electronic information | Support call recordings where we tell you in advance, uploaded documents and images | You |
| Sensitive personal information | Social Security number or ITIN, driver’s license or passport number, account log-in credentials, financial account number together with an access code | You, verification providers |
| Inferences | Limited — for example product interest and risk indicators | Derived from the above |
We keep each category for the periods described in How long we keep information. We do not knowingly sell or share the personal information of consumers under 16 years of age.
Financial privacy under the Gramm-Leach-Bliley Act
Financial products offered through Bricks and our partner banks are regulated by the Gramm-Leach-Bliley Act. If you obtain a financial product or service from us primarily for personal, family or household purposes, you will receive a separate Consumer Privacy Notice — the standard “Facts” form required by Regulation P — when the relationship begins, and annually where required. That notice sets out the categories of information we collect and share, the reasons we share it, and any right you have to limit sharing.
Where that notice and this policy differ on information covered by the Gramm-Leach-Bliley Act, the Consumer Privacy Notice controls.
Children’s information
Bricks is a business platform. It is not directed to children, and we do not knowingly collect personal information from anyone under 13 through our website or app. If you believe a child has given us information directly, email info@bricksbanking.com and we will delete it.
Schools, scouting groups, youth sports clubs and similar organizations do use Bricks to collect dues, fees and registrations that relate to minors. Where they do, the organization — not Bricks — decides what to collect and is responsible for any notice and parental consent required by the Children’s Online Privacy Protection Act, the Family Educational Rights and Privacy Act, or state student-privacy law. We process that information only on the organization’s instructions, do not use it to build profiles or for advertising, and delete or return it as our agreement with the organization requires.
Security
We encrypt personal information in transit and at rest, restrict access to staff who need it for their role, log and monitor access, require multi-factor authentication for administrative systems, and test our controls. Our partner banks and processors maintain their own programs under federal banking and payment card standards.
No system is perfectly secure, and we cannot guarantee absolute security. Protect your side of it: use a strong, unique password, turn on multi-factor authentication, review who has access to your account, and tell us immediately at info@bricksbanking.com if you think an account has been compromised. If a breach affects your personal information, we will notify you and any regulator as state and federal law require.
How long we keep information
We keep personal information for as long as we need it for the purposes in this policy, and then for as long as the law requires. Some of these periods are not ours to shorten.
| What | How long |
|---|---|
| Identity verification records | At least 5 years after the account closes, as required by the Bank Secrecy Act |
| Transaction and payment records | At least 5 years from the transaction |
| Tax filings, ledger and supporting records | At least 7 years after the relevant filing |
| Support correspondence | Up to 3 years after the matter closes |
| Website and analytics logs | Up to 24 months |
| Marketing contacts | Until you opt out, after which we keep the minimum needed to honor the opt-out |
Where we no longer need information, we delete it or de-identify it. Information held in backups is deleted on our normal backup cycle.
Where information is processed
Bricks is a United States company and we store and process personal information in the United States. Some of our service providers operate elsewhere, in which case information may be transferred to and processed in those countries under contractual protections. If you access Bricks from outside the United States, you are sending your information to the United States, where privacy laws differ from those where you live.
Other sites and services
Our site links to services we do not operate — our scheduling provider, our partner banks, accounting systems you connect, and others. We are not responsible for their privacy practices, and their notices govern what they do with your information. Read them before you hand anything over.
Changes to this policy
We update this policy as the business and the law change. When we do, we revise the “Last updated” date at the top. If a change materially affects how we use information you have already given us, we will give you notice — by email or in the product — before it takes effect, where the law requires it or where we judge it the right thing to do. Continuing to use Bricks after a change takes effect means you accept the updated policy.
Contact us
Bricks Financial, Inc.info@bricksbanking.com
Privacy questions, requests under this policy, and security reports all go to that address. We monitor it and respond within the time frames described above.
If you are a donor, member or resident and your question is about a record held by a nonprofit or club that uses Bricks, contact that organization first — it controls the record, and we can only act on its instructions.