Blink Logo
Back to Home

Privacy Policy

Last Updated: June 25, 2025

This Privacy Policy governs how Rise Digital Financial Corp. ("Blink", "we", "our", or "us") collects, uses, discloses, and safeguards your information when you use our mobile application and services. By accessing or using the Blink App, you acknowledge that you have read and understood this Privacy Policy.

Table of Contents

This Privacy Policy explains how Rise Digital Financial Corp. ('Blink,' 'we,' 'our,' or 'us') collects, uses, discloses, and safeguards your information when you download, access, or use the Blink mobile application (the 'Blink App') and related services (collectively, the 'Services').

It covers information that you provide directly to us, that we collect automatically through your device, and that we obtain from third-party sources such as open-banking data aggregators.

The Policy also outlines the legal bases on which we process personal information, the limited circumstances under which we share it, and the rights and choices available to you. This document applies only to Blink-branded products and services and does not govern any third-party websites, applications, or services that may be linked from the Blink App.

By using the Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

For clarity, the following terms have the meanings set out below when used in this Privacy Policy:

Personal Information - Data that identifies, relates to, describes, or could reasonably be linked directly or indirectly to a particular individual or household. Examples include name, postal address, email address, telephone number, Social Security number, device identifiers, and certain financial information.

Financial Data - Account and transaction details retrieved from your linked bank or payroll accounts via authorized data aggregators (e.g., balances, deposits, withdrawals, recurring payments, and payroll history).

Processing - Any operation performed on Personal Information, whether by automated means or not, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.

Service Providers - Third-party companies that process Personal Information on Blink's behalf under written contracts that require them to safeguard the data and use it only for the contracted purpose.

Applicable Law - All privacy, data-protection, and financial-services laws and regulations that apply to Blink's operations, such as the Gramm-Leach-Bliley Act (GLBA), the California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA), and relevant state earned-wage-access statutes.

You or User - The natural person who downloads or uses the Blink App or otherwise accesses Blink's Services.

We collect three broad categories of information to operate, maintain, and enhance the Services. Specific data elements within each category may vary depending on how you interact with the Blink App, the features you use, and the permissions you grant.

Account Registration Data - Full legal name, email address, mobile phone number, mailing address, date of birth, and a password or comparable authentication credential.

Identity & Compliance Data - Social Security number (or other government identifier), driver's license or state ID images, and live selfie or liveness-check images collected during Know-Your-Customer (KYC) verification.

Employment & Income Details - Employer name, pay frequency, pay dates, and salary or wage amounts you input manually or confirm during onboarding.

Customer Support & Communications - The content of messages, emails, or phone calls you send to Blink, including attachments and metadata.

Voluntary Survey & Marketing Preferences - Feedback, product reviews, and opt-in choices for promotional emails or beta features.

Device Information - Hardware model, operating system version, unique device identifiers (e.g., IDFA, Android Ad ID), screen resolution, and language settings.

Usage & Diagnostic Logs - Feature interaction events (e.g., buttons tapped, pages viewed), session timestamps, crash reports, and performance metrics that help us improve stability.

Network & Connection Data - IP address, mobile network provider, and approximate geolocation (derived from IP address or device settings) to detect fraud and support compliance with state eligibility limits.

Cookies & Similar Technologies - Pixel tags, SDKs, and local storage objects used to remember your preferences, conduct analytics, and personalize your experience.

Open Banking & Payroll Aggregators (e.g., Plaid) - Tokenized account identifiers, current and historical balances, transaction descriptions and amounts, deposit and withdrawal history, recurring debits, and income deposits.

Identity Verification Vendors - Results of watch-list screening, document authenticity scores, and device-risk signals.

Fraud Prevention Networks - Information about suspected fraudulent or abusive behavior linked to your device or account identifiers.

Marketing & Attribution Partners - Non-personally identifiable analytics data (e.g., campaign ID, attribution tag) that tells us how you discovered Blink.

We process Personal Information only for purposes that are necessary, proportionate, and compatible with the reasons it was collected. Depending on your interactions with Blink, we may use your information to:

• Deliver Core Functionality - Authenticate your identity, create and maintain your Blink account, evaluate eligibility for BlinkAdvance®, calculate approved advance amounts, initiate ACH or RTP transactions, and populate your dashboard with BlinkInsights®.

• Operate, Maintain & Improve the Services - Diagnose technical issues, monitor performance, analyze usage patterns, develop new features, and refine our risk-scoring models.

• Detect, Prevent & Mitigate Fraud or Abuse - Correlate device signals, network data, and open-banking activity to identify suspicious behavior, enforce our Terms & Conditions, and protect Users, Blink, and our financial partners.

• Provide Customer Support - Respond to inquiries, resolve disputes, and troubleshoot problems via in-app chat, email, or phone.

• Comply with Legal & Regulatory Obligations - Satisfy KYC/AML requirements, maintain audit logs, generate mandated reports, and cooperate with lawful requests from regulators or law-enforcement agencies.

• Personalize Your Experience - Tailor in-app messages, educational content, and Early Repay Reward reminders based on your usage and financial behavior.

• Conduct Research & Analytics - Aggregate and de-identify data to understand trends, measure campaign effectiveness, and publish statistics that do not identify individual Users.

• Send Marketing & Promotional Communications - Where permitted by Applicable Law and your preferences, inform you about product updates, new features, surveys, or promotions.

• Facilitate Corporate Transactions - In connection with any merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality safeguards.

Blink does not sell or rent Personal Information and does not share it with third parties for cross-context behavioral advertising. We disclose data only in the limited situations described below, each grounded in an Applicable Law basis and protected by contractual safeguards.

We engage carefully vetted third-party Service Providers to perform functions on our behalf—such as cloud-hosting, payment initiation, identity verification, customer-support tooling, analytics, and document storage. These partners are bound by confidentiality obligations and permitted to use Personal Information only as instructed by Blink.

To maintain a secure ecosystem and comply with KYC/AML requirements, we may share relevant data with identity-verification vendors, transaction-monitoring and sanctions-screening services, and network partners that flag devices or accounts linked to known fraud. Such sharing helps us detect suspicious activity, meet regulatory mandates, and protect Users from financial harm.

If Blink enters into a merger, acquisition, reorganization, or sale of assets, Personal Information may be transferred as part of the transaction. Any successor entity will be bound by this Privacy Policy or a policy with materially similar protections, unless you consent otherwise.

We may disclose Personal Information when we believe in good faith that such action is necessary to comply with a subpoena, court order, or other legal process; cooperate with regulators, law-enforcement, or supervisory authorities; or enforce our Terms & Conditions or protect the rights, property, or safety of Blink, our Users, or others.

We may share aggregated statistics or de-identified datasets that cannot reasonably be used to identify you, for purposes such as market research, academic studies, or industry benchmarking.

Like most modern apps and websites, Blink uses a combination of cookies, software development kits (SDKs), pixel tags, and local storage objects (collectively, 'Tracking Technologies') to deliver, secure, and enhance the Services.

Strictly Necessary Cookies / SDK Flags - Enable core functionality such as session management, load balancing, fraud detection, and user authentication.

Performance & Analytics Tools - Collect aggregated usage metrics to help us understand feature adoption and improve stability. We currently employ platforms such as Firebase Analytics and Sentry.

Preference Cookies - Remember your language selection, marketing opt-in state, and in-app tutorial progress.

Advertising & Attribution Tags - Limited to first-party campaign measurement. Blink does not use third-party advertising networks for interest-based ads.

Security & Fraud Mitigation - Detect automated bots, unauthorized access attempts, and unusual device fingerprints.

Performance Monitoring - Identify slowdown points, error rates, and UX bottlenecks across different OS versions and device models.

Product Analytics - Evaluate which features are most valuable to Users to guide roadmap prioritization.

User Experience Personalization - Remember your onboarding progress, dismissed alerts, and preferred dashboard layout.

Marketing Attribution - Measure the effectiveness of Blink's own advertising campaigns in a privacy-respecting manner.

In-App Settings - Toggle analytics sharing and marketing-communication preferences at any time via Settings > Privacy Controls.

Device-Level Controls - Most mobile operating systems allow you to reset or limit ad identifiers.

Browser Controls - If you access Blink's web properties, you can set your browser to refuse or delete certain cookies.

Global Privacy Control (GPC) - Where technically feasible on our web properties, we honor valid GPC signals as a request to opt out of any 'sale' or 'sharing' of Personal Information under the CCPA/CPRA.

Blink recognizes that privacy is not one-size-fits-all. Depending on where you live and how you use the Services, you may have specific statutory rights—along with universal controls we extend to every User.

Access: You may request a copy of the Personal Information we hold about you, including a list of data sources and processing purposes.

Correction: If any information is inaccurate or incomplete, you can update most fields directly in the Blink App or by contacting support@blinkfinances.com.

Deletion: You may ask us to delete your Personal Information. We will honor the request unless retention is required for an ongoing relationship, legal obligations, or defense of legal claims.

Right to Know / Access: Request the categories and specific pieces of Personal Information we collected, the sources, purposes, and categories of third parties to whom the data was disclosed.

Right to Delete: Ask us to delete Personal Information, subject to statutory exceptions.

Right to Correct: Require us to rectify inaccurate Personal Information.

Right to Opt-Out of Sale or Sharing: Blink does not sell or share Personal Information for cross-context behavioral advertising.

Right to Non-Discrimination: Blink will not deny goods or services, charge different prices, or provide different levels of quality solely because you exercised a privacy right.

Under the Gramm-Leach-Bliley Act, you have the right to opt out of our affiliate using your information to market new, non-Blink products or services to you. To opt out, visit Settings > Privacy Controls > GLBA Opt-Out or email support@blinkfinances.com.

Email & SMS: Click the 'unsubscribe' link in any marketing email or respond 'STOP' to marketing SMS messages.

Push Notifications: Disable via your device's notification settings or in-app under Settings > Notifications.

Analytics & Personalization: Use the toggles under Settings > Privacy Controls to disable optional analytics or personalized content.

Blink retains Personal Information only for as long as reasonably necessary to: (a) fulfill the purposes outlined in this Policy; (b) satisfy legal, regulatory, or accounting requirements; and (c) protect our legitimate interests (e.g., dispute resolution, fraud prevention). Retention periods vary by data category and context, but our general guidelines are:

• User Account & Profile Data: For the duration of the active account, plus 5 years after closure (aligns with AML/KYC record-keeping rules)

• Financial Data (Bank & Payroll): 7 years from the date of each transaction record (supports audits, tax inquiries, and dispute resolution)

• Transaction & Ledger Records: At least 7 years post-transaction (required by NACHA rules)

• Customer Support Communications: 3 years after ticket closure (enables pattern analysis)

• Crash Logs & Diagnostic Data: ≤ 24 months (evaluated in aggregate)

• Aggregated or De-identified Data: Indefinite (no longer reasonably linkable to an individual)

Once retention obligations lapse, we securely dispose of data through cryptographic deletion, logical deletion with periodic purge cycles, or secure wipe of storage media in accordance with NIST SP 800-88 guidelines.

Blink employs multiple layers of technical, administrative, and physical safeguards to protect Personal Information against unauthorized access, loss, misuse, alteration, or destruction. Key elements of our security program include:

Encryption in Transit & at Rest - All network traffic is protected by TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256.

Tokenization & Segmentation - We never store full bank credentials. Production databases are logically segregated from development environments.

Continuous Monitoring & Logging - SIEM tools aggregate logs to detect anomalies in real time with 24×7 incident-response team alerts.

Role-Based Access Control (RBAC) - Employees receive minimum permissions needed. Administrative access requires unique credentials and MFA.

Security Awareness & Confidentiality - All personnel undergo background checks, receive annual security training, and sign confidentiality agreements.

Vulnerability Management - Regular internal code reviews, automated dependency scanning, and quarterly external penetration tests.

Independent Audits & Certifications - Core infrastructure hosted on ISO 27001- and SOC 2 Type II-certified providers.

Incident Response & Breach Notification - Documented incident-response plan aligned with NIST SP 800-61. Breach notifications within 72 hours of confirmation.

If you believe your account or data has been compromised, contact us immediately at security@blinkfinances.com.

Blink is based in the United States, and all primary servers are located in U.S. data centers. However, certain Service Providers that support the operation of the Services may process Personal Information in other jurisdictions. When we transfer Personal Information across borders, we implement safeguards designed to ensure the data remains protected at a level comparable to U.S. and EU standards.

• Contractual Protections - We require non-U.S. Service Providers to sign Data Processing Agreements (DPAs) that incorporate Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the European Commission.

• Technical Measures - End-to-end encryption, tokenization, and pseudonymization are employed to minimize exposure during transfer and processing.

• Risk Assessments - Prior to onboarding a vendor located outside the U.S., we perform a Transfer Impact Assessment (TIA) that evaluates local surveillance laws and security controls.

• Onward Transfers - Service Providers must obtain Blink's written authorization before disclosing Personal Information to any sub-processor in a different jurisdiction.

By using the Services, you understand that your Personal Information may be transferred to—and stored on—servers located outside your jurisdiction where privacy laws may differ. In all such cases, Blink ensures that the transfer is lawful and that your information remains subject to appropriate protections.

The Blink App and its Services are not directed to, and may not be used by, children under the age of 13 (or under 16 in jurisdictions that impose a higher age of digital consent). We do not knowingly collect Personal Information from anyone in this age group, nor do we knowingly allow such individuals to register for an account.

• No Intentional Collection: Blink's onboarding flow requires age confirmation and other data elements that make it highly unlikely for a child to complete registration undetected. If we become aware that we have inadvertently collected Personal Information from a child, we will delete that information from our records as quickly as practicable.

• Parental Notification & Deletion Requests: If you believe that a child under the applicable age threshold has provided Personal Information to Blink, please contact us immediately at privacy@blinkfinances.com.

• Educational Resources: Parents and guardians may wish to consult the Federal Trade Commission's (FTC) Consumer Information pages for tips on protecting children's privacy online.

Blink complies with the Children's Online Privacy Protection Act (COPPA) and equivalent international laws. We do not knowingly engage any third-party ad networks or analytics services that target or profile children.

Your Privacy Rights

By using Blink, you acknowledge that you have read and understood this Privacy Policy. You have certain rights regarding your personal data, and we are committed to protecting those rights and maintaining the confidentiality and security of your information.

Document ID: PP-BLK-MD-001

Last Updated: June 25, 2025

© 2025 Rise Digital Financial Corp.All Rights Reserved.