Privacy Policy
Last Updated: June 25, 2025
This Privacy Policy governs how Rise Digital Financial Corp. ("Blink", "we", "our", or "us") collects, uses, discloses, and safeguards your information when you use our mobile application and services. By accessing or using the Blink App, you acknowledge that you have read and understood this Privacy Policy.
Table of Contents
Scope & Purpose
This Privacy Policy explains how Rise Digital Financial Corp. ('Blink,' 'we,' 'our,' or 'us') collects, uses, discloses, and safeguards your information when you download, access, or use the Blink mobile application (the 'Blink App') and related services (collectively, the 'Services').
It covers information that you provide directly to us, that we collect automatically through your device, and that we obtain from third-party sources such as open-banking data aggregators.
The Policy also outlines the legal bases on which we process personal information, the limited circumstances under which we share it, and the rights and choices available to you. This document applies only to Blink-branded products and services and does not govern any third-party websites, applications, or services that may be linked from the Blink App.
By using the Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
Key Definitions
For clarity, the following terms have the meanings set out below when used in this Privacy Policy:
Core Terms
Personal Information - Data that identifies, relates to, describes, or could reasonably be linked directly or indirectly to a particular individual or household. Examples include name, postal address, email address, telephone number, Social Security number, device identifiers, and certain financial information.
Financial Data - Account and transaction details retrieved from your linked bank or payroll accounts via authorized data aggregators (e.g., balances, deposits, withdrawals, recurring payments, and payroll history).
Processing - Any operation performed on Personal Information, whether by automated means or not, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
Service & Legal Terms
Service Providers - Third-party companies that process Personal Information on Blink's behalf under written contracts that require them to safeguard the data and use it only for the contracted purpose.
Applicable Law - All privacy, data-protection, and financial-services laws and regulations that apply to Blink's operations, such as the Gramm-Leach-Bliley Act (GLBA), the California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA), and relevant state earned-wage-access statutes.
You or User - The natural person who downloads or uses the Blink App or otherwise accesses Blink's Services.
Information We Collect
We collect three broad categories of information to operate, maintain, and enhance the Services. Specific data elements within each category may vary depending on how you interact with the Blink App, the features you use, and the permissions you grant.
Information You Provide Directly
Account Registration Data - Full legal name, email address, mobile phone number, mailing address, date of birth, and a password or comparable authentication credential.
Identity & Compliance Data - Social Security number (or other government identifier), driver's license or state ID images, and live selfie or liveness-check images collected during Know-Your-Customer (KYC) verification.
Employment & Income Details - Employer name, pay frequency, pay dates, and salary or wage amounts you input manually or confirm during onboarding.
Customer Support & Communications - The content of messages, emails, or phone calls you send to Blink, including attachments and metadata.
Voluntary Survey & Marketing Preferences - Feedback, product reviews, and opt-in choices for promotional emails or beta features.
Information We Obtain Automatically
Device Information - Hardware model, operating system version, unique device identifiers (e.g., IDFA, Android Ad ID), screen resolution, and language settings.
Usage & Diagnostic Logs - Feature interaction events (e.g., buttons tapped, pages viewed), session timestamps, crash reports, and performance metrics that help us improve stability.
Network & Connection Data - IP address, mobile network provider, and approximate geolocation (derived from IP address or device settings) to detect fraud and support compliance with state eligibility limits.
Cookies & Similar Technologies - Pixel tags, SDKs, and local storage objects used to remember your preferences, conduct analytics, and personalize your experience.
Information We Receive from Third Parties
Open Banking & Payroll Aggregators (e.g., Plaid) - Tokenized account identifiers, current and historical balances, transaction descriptions and amounts, deposit and withdrawal history, recurring debits, and income deposits.
Identity Verification Vendors - Results of watch-list screening, document authenticity scores, and device-risk signals.
Fraud Prevention Networks - Information about suspected fraudulent or abusive behavior linked to your device or account identifiers.
Marketing & Attribution Partners - Non-personally identifiable analytics data (e.g., campaign ID, attribution tag) that tells us how you discovered Blink.
How We Use Your Information
We process Personal Information only for purposes that are necessary, proportionate, and compatible with the reasons it was collected. Depending on your interactions with Blink, we may use your information to:
• Deliver Core Functionality - Authenticate your identity, create and maintain your Blink account, evaluate eligibility for BlinkAdvance®, calculate approved advance amounts, initiate ACH or RTP transactions, and populate your dashboard with BlinkInsights®.
• Operate, Maintain & Improve the Services - Diagnose technical issues, monitor performance, analyze usage patterns, develop new features, and refine our risk-scoring models.
• Detect, Prevent & Mitigate Fraud or Abuse - Correlate device signals, network data, and open-banking activity to identify suspicious behavior, enforce our Terms & Conditions, and protect Users, Blink, and our financial partners.
• Provide Customer Support - Respond to inquiries, resolve disputes, and troubleshoot problems via in-app chat, email, or phone.
• Comply with Legal & Regulatory Obligations - Satisfy KYC/AML requirements, maintain audit logs, generate mandated reports, and cooperate with lawful requests from regulators or law-enforcement agencies.
• Personalize Your Experience - Tailor in-app messages, educational content, and Early Repay Reward reminders based on your usage and financial behavior.
• Conduct Research & Analytics - Aggregate and de-identify data to understand trends, measure campaign effectiveness, and publish statistics that do not identify individual Users.
• Send Marketing & Promotional Communications - Where permitted by Applicable Law and your preferences, inform you about product updates, new features, surveys, or promotions.
• Facilitate Corporate Transactions - In connection with any merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality safeguards.
Legal Bases for Processing
While Blink is headquartered in the United States and primarily serves U.S. residents, we adopt a hybrid compliance framework that aligns with the principles of the EU General Data Protection Regulation (GDPR) and comparable international standards. Accordingly, Blink relies on one or more of the following legal bases when Processing Personal Information:
• Consent - When you voluntarily provide information (e.g., connecting your bank via Plaid, opting into marketing emails), you grant Blink permission to process that data for the stated purpose.
• Contractual Necessity - We process data that is essential to perform our contract with you, such as authenticating your login, disbursing BlinkAdvance® funds, or debiting your linked account for repayment.
• Legal or Regulatory Obligations - Certain data must be processed and retained to meet obligations under KYC/AML rules, state earned-wage-access regulations, tax laws, court orders, or other legal mandates.
• Legitimate Interests - We process information to further Blink's legitimate business interests in ways that do not override your privacy rights—for example, detecting fraud, safeguarding the App's security, improving user experience, and communicating product updates.
• Vital Interests - In the unlikely event we need to process data to protect you or another individual from serious harm (e.g., detecting signs of financial exploitation), we may do so without prior consent.
Your Privacy Choices & Rights
Blink recognizes that privacy is not one-size-fits-all. Depending on where you live and how you use the Services, you may have specific statutory rights—along with universal controls we extend to every User.
Access, Correction & Deletion (All Users)
Access: You may request a copy of the Personal Information we hold about you, including a list of data sources and processing purposes.
Correction: If any information is inaccurate or incomplete, you can update most fields directly in the Blink App or by contacting support@blinkfinances.com.
Deletion: You may ask us to delete your Personal Information. We will honor the request unless retention is required for an ongoing relationship, legal obligations, or defense of legal claims.
California & Comparable State Rights
Right to Know / Access: Request the categories and specific pieces of Personal Information we collected, the sources, purposes, and categories of third parties to whom the data was disclosed.
Right to Delete: Ask us to delete Personal Information, subject to statutory exceptions.
Right to Correct: Require us to rectify inaccurate Personal Information.
Right to Opt-Out of Sale or Sharing: Blink does not sell or share Personal Information for cross-context behavioral advertising.
Right to Non-Discrimination: Blink will not deny goods or services, charge different prices, or provide different levels of quality solely because you exercised a privacy right.
GLBA Opt-Out (Financial Information)
Under the Gramm-Leach-Bliley Act, you have the right to opt out of our affiliate using your information to market new, non-Blink products or services to you. To opt out, visit Settings > Privacy Controls > GLBA Opt-Out or email support@blinkfinances.com.
Marketing Communications Preferences
Email & SMS: Click the 'unsubscribe' link in any marketing email or respond 'STOP' to marketing SMS messages.
Push Notifications: Disable via your device's notification settings or in-app under Settings > Notifications.
Analytics & Personalization: Use the toggles under Settings > Privacy Controls to disable optional analytics or personalized content.
Data Retention & Destruction
Blink retains Personal Information only for as long as reasonably necessary to: (a) fulfill the purposes outlined in this Policy; (b) satisfy legal, regulatory, or accounting requirements; and (c) protect our legitimate interests (e.g., dispute resolution, fraud prevention). Retention periods vary by data category and context, but our general guidelines are:
• User Account & Profile Data: For the duration of the active account, plus 5 years after closure (aligns with AML/KYC record-keeping rules)
• Financial Data (Bank & Payroll): 7 years from the date of each transaction record (supports audits, tax inquiries, and dispute resolution)
• Transaction & Ledger Records: At least 7 years post-transaction (required by NACHA rules)
• Customer Support Communications: 3 years after ticket closure (enables pattern analysis)
• Crash Logs & Diagnostic Data: ≤ 24 months (evaluated in aggregate)
• Aggregated or De-identified Data: Indefinite (no longer reasonably linkable to an individual)
Once retention obligations lapse, we securely dispose of data through cryptographic deletion, logical deletion with periodic purge cycles, or secure wipe of storage media in accordance with NIST SP 800-88 guidelines.
Data Security Measures
Blink employs multiple layers of technical, administrative, and physical safeguards to protect Personal Information against unauthorized access, loss, misuse, alteration, or destruction. Key elements of our security program include:
Technical Safeguards
Encryption in Transit & at Rest - All network traffic is protected by TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256.
Tokenization & Segmentation - We never store full bank credentials. Production databases are logically segregated from development environments.
Continuous Monitoring & Logging - SIEM tools aggregate logs to detect anomalies in real time with 24×7 incident-response team alerts.
Administrative Controls
Role-Based Access Control (RBAC) - Employees receive minimum permissions needed. Administrative access requires unique credentials and MFA.
Security Awareness & Confidentiality - All personnel undergo background checks, receive annual security training, and sign confidentiality agreements.
Vulnerability Management - Regular internal code reviews, automated dependency scanning, and quarterly external penetration tests.
Compliance & Auditing
Independent Audits & Certifications - Core infrastructure hosted on ISO 27001- and SOC 2 Type II-certified providers.
Incident Response & Breach Notification - Documented incident-response plan aligned with NIST SP 800-61. Breach notifications within 72 hours of confirmation.
If you believe your account or data has been compromised, contact us immediately at security@blinkfinances.com.
International Data Transfers
Blink is based in the United States, and all primary servers are located in U.S. data centers. However, certain Service Providers that support the operation of the Services may process Personal Information in other jurisdictions. When we transfer Personal Information across borders, we implement safeguards designed to ensure the data remains protected at a level comparable to U.S. and EU standards.
• Contractual Protections - We require non-U.S. Service Providers to sign Data Processing Agreements (DPAs) that incorporate Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the European Commission.
• Technical Measures - End-to-end encryption, tokenization, and pseudonymization are employed to minimize exposure during transfer and processing.
• Risk Assessments - Prior to onboarding a vendor located outside the U.S., we perform a Transfer Impact Assessment (TIA) that evaluates local surveillance laws and security controls.
• Onward Transfers - Service Providers must obtain Blink's written authorization before disclosing Personal Information to any sub-processor in a different jurisdiction.
By using the Services, you understand that your Personal Information may be transferred to—and stored on—servers located outside your jurisdiction where privacy laws may differ. In all such cases, Blink ensures that the transfer is lawful and that your information remains subject to appropriate protections.
Children's Privacy
The Blink App and its Services are not directed to, and may not be used by, children under the age of 13 (or under 16 in jurisdictions that impose a higher age of digital consent). We do not knowingly collect Personal Information from anyone in this age group, nor do we knowingly allow such individuals to register for an account.
• No Intentional Collection: Blink's onboarding flow requires age confirmation and other data elements that make it highly unlikely for a child to complete registration undetected. If we become aware that we have inadvertently collected Personal Information from a child, we will delete that information from our records as quickly as practicable.
• Parental Notification & Deletion Requests: If you believe that a child under the applicable age threshold has provided Personal Information to Blink, please contact us immediately at privacy@blinkfinances.com.
• Educational Resources: Parents and guardians may wish to consult the Federal Trade Commission's (FTC) Consumer Information pages for tips on protecting children's privacy online.
Blink complies with the Children's Online Privacy Protection Act (COPPA) and equivalent international laws. We do not knowingly engage any third-party ad networks or analytics services that target or profile children.
Third-Party Links & Services
The Blink App may contain links to external websites, mobile applications, or services that are not operated or controlled by Blink (collectively, 'Third-Party Services'). Examples include educational articles, partner-merchant promotions, or app-store pages. Any interaction with Third-Party Services is governed by their own privacy policies and terms, not this Privacy Policy.
• No Endorsement or Control: The presence of a link or integration does not imply that Blink endorses or has reviewed the Third-Party Service. We have no control over—and are not responsible for—the content, privacy practices, or security of such external resources.
• Data Exchange: When you click a third-party link or enable an integration, any information you provide directly to that third party will be subject to its privacy practices. Likewise, if a Third-Party Service shares information with Blink, such data will be handled in accordance with this Privacy Policy.
• Use Caution: We encourage you to read the privacy policies and terms of any Third-Party Service you visit or use. Exercise caution before sharing personal or financial information with any external platform.
Blink is not liable for any damages or losses arising from your use of—or reliance on—Third-Party Services. Your interactions with such services are solely between you and the third party.
Your Privacy Rights
By using Blink, you acknowledge that you have read and understood this Privacy Policy. You have certain rights regarding your personal data, and we are committed to protecting those rights and maintaining the confidentiality and security of your information.
Document ID: PP-BLK-MD-001
Last Updated: June 25, 2025
© 2025 Rise Digital Financial Corp.All Rights Reserved.