Privacy Notice Pursuant to the California Consumer Privacy Act (CCPA)
Effective Date: January 1, 2020. Oak Street Funding® is committed to protecting the personal data and privacy of individuals for whom we provide financial services. This Privacy Notice pursuant to the California Consumer Privacy Act (CCPA) supplements the information contained in Oak Street Funding’s Privacy Notice and applies solely to all visitors, users, and others who reside in the State of California (“customer” or “you”). We adopt this notice to comply with the California Consumer Privacy Act of 2018 (CCPA). Any terms defined in the CCPA have the same meaning when used in this notice. We will process your personal information as described below on the basis of our legitimate interest in fulfilling our service commitment to you.
Information We Collect
The following categories of personal information are collected from you at the time you request commercial loan services from Oak Street Funding and/or at the time you use Oak Street Funding’s Website. This information identifies, relates to, describes, references or is capable of being associated with or could reasonably be linked, directly or indirectly, with a particular customer (“personal information”). In particular, in the last twelve (12) months, the following categories of personal information have been collected:
A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.
- Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.
Some personal information included in this category may overlap with other categories.
- Protected classification characteristics under California or federal law.
Age (40 years or older) , race, color, ancestry, national origin, citizenship, religion or creed, marital status , medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
Collected: YES (only as reflected in footnotes 1 & 2)
- Commercial information.
Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
- Biometric information.
Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.
- Internet or other similar network activity.
Browsing history, search history, information on a customer’s interaction with a website, application, or advertisement.
- Geolocation data.
Physical location or movements.
- Sensory data.
Audio, electronic, visual, thermal, olfactory, or similar information.
- Professional or employment-related information.
Current or past job history or performance evaluations.
- Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).
Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.
- Inferences drawn from other personal information.
Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
How We Collect Personal Data
Oak Street Funding obtains the categories of personal information listed above from the following categories of sources: (1) Directly from you at the time you request commercial loan services from Oak Street Funding; (2) Directly from you at the time you use Oak Street Funding’s website; or (3) Indirectly from you when observing your actions on our website.
How We Use Personal Data
We will use or disclose your personal data for one or more of the following business purposes: (i) to determine whether you are a “specifically designated national” (SDN) pursuant to the Office of Foreign Assets Control (OFAC), (ii) to comply with 31 CRF Part 1010, et seq. (Customer Due Diligence Requirements), (iii) to determine whether you meet the required underwriting criteria for the requested loan, and/or (iv) as otherwise necessary to process, service and collect your loan (collectively, the “Loan Requirements”). We may also use or disclose the personal information we collect to respond to law enforcement requests and as required by applicable law, court order or governmental regulations; or, as described to you when collecting your personal information; or, as otherwise set forth in the CCPA (collectively, the “Legal Requirements”). In compliance with 12 CFR Part 1002 (Regulation B), the Records Management Policy of First Financial Bank (FFB), and applicable legal, regulatory and business requirements, Oak Street Funding Capital maintains the foregoing categories of your personal information (collectively, the “Banking Requirements,” and collectively, with the Loan Requirements and Legal Requirements, the “Permissible Purposes”).
We may also need to gather personal information from you for the following business purposes: for the operation and offering of our financial services, to maintain quality of the service, to inform you of other commercial loan products or commercial loan services available from Oak Street Funding and its affiliates, and to provide general statistics regarding use of the Oak Street Funding Website. Moreover, your e-mail, name, address and/or telephone number may also be used by Oak Street Funding to contact you via surveys to conduct research about your opinion of current services or of potential new services that may be offered. We collect this information as needed to provide these financial services or to conduct these surveys.
Oak Street Funding will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated or incompatible purposes without providing you notice.
Sharing Personal Information
Oak Street Funding may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract. The categories of third parties with whom we share your personal information are as follows: credit bureau(s), federal and state regulatory agencies, investigation services, and third party valuation companies (collectively, the “Loan Related Third Parties”).
In addition, Oak Street Funding may share data with trusted partners to help us perform statistical analysis, send you email or postal mail, provide customer support, or arrange for deliveries or permit third parties to use, sell, license, reproduce, distribute and disclose de-identified or aggregated, non-personally identifiable data that is derived through your use of certain services (collectively, the “Business Third Parties”, and collectively with the Loan Related Third Parties, the “Third Parties”). All Business Third Parties are prohibited from using your personal information except to provide these services to Oak Street Funding and you, and they are required to maintain the confidentiality of your information.
Oak Street Funding may, from time to time, contact you on behalf of external business partners about a particular offering that may be of interest to you. In those cases, your unique personally identifiable information (e-mail, name, address, telephone number) is not transferred to such third parties.
In the preceding twelve (12) months, Oak Street Funding has not sold personal information. Other than the Third Parties, Oak Street Funding does not sell or share this personal information with third-party business partners.
YOUR RIGHTS AND CHOICES
Access to Specific Information and Data Portability Rights
You have the right to request that Oak Street Funding disclose to you certain information about our collection and use of your personal information over the past 12 months. Once we receive and confirm your verifiable customer request (see Exercising Access, Data Portability, and Deletion Rights, below), we will make an individualized disclosure to you about:
- Categories of personal information we collected about you;
- Categories of sources for the personal information we collected about you;
- Our business or commercial purpose for collecting the personal information;
- Categories of third parties with whom we share that personal information;
- Specific pieces of personal information we collected about you (also called a data portability request);
- If we sold or disclosed your personal information for a business purpose, two separate lists disclosing:
- sales, identifying the personal information categories that each category of recipient purchased; and,
- disclosures for a business purpose, identifying the personal information categories that each category of recipient obtained.
Your Right to Request Deletion of Personal Data
Under the CCPA, you have the right to request that Oak Street Funding delete the personal information that we have collected and retained. Upon Oak Street Funding’s receipt of a verifiable request to delete personal information, we shall delete the personal information from its records and will direct any service providers to delete your personal information from their records. However, please note that Oak Street Funding may deny your deletion request and need not comply with this request (and need not ask service providers to comply with a deletion request) if retaining the information is necessary to perform certain functions or commitments, including: completing the transaction for which the personal information was collected; providing a service requested; otherwise performing our contract with you or taking reasonably anticipated actions within the context of our ongoing business relationship with you; detecting security incidents and protecting against malicious, deceptive or otherwise illegal activity or to prosecute those responsible for those activities; complying with a legal obligation or otherwise using the personal information, internally, in a lawful manner; complying with the California Electronic Communications Privacy Act; or for a purpose otherwise contemplated by Cal. Civ. Code Section 1798.105(c)-(d) or as otherwise amended.
Exercising Access, Data Portability and Deletion Rights
To exercise the access, data portability and deletion rights described above, please submit a verifiable customer request to us by either:
Only you or a person registered with the California Secretary of State that you authorize to act on your behalf may make a verifiable customer request related to your personal information. You may also make a verifiable customer request on behalf of your minor child.
You may only make a verifiable customer request for access or data portability twice within a 12-month period. The verifiable customer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative;
- Describe your request with sufficient detail that allows us to properly understand, evaluate and respond to it.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. We will only use personal information provided in a verifiable customer request to verify the requestor’s identity or authority to make the request.
Response Timing and Format
We endeavor to respond to a verifiable customer request within forty-five (45) days of its receipt. If we require more time, we will inform you of the reason and extension period in writing. If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the 12-month period preceding the verifiable customer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance. We do not charge a fee to process or respond to your verifiable customer request unless it is excessive, repetitive or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
As mentioned above, we may collect or process sensitive data as needed or required to deliver services you have requested, to inform you of other products or services, and to contact you via surveys to conduct research about your opinions. You may request that we delete this information, subject to certain exceptions as provided by the CCPA.
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not: deny you goods or services; charge you different prices or rates; provide you a different level or quality of goods or services; or suggest that you may receive a different price or rate or a different level or quality of goods or services. We may offer certain financial incentives permitted by the CCPA that can result in different prices, rates or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your personal information’s value and contain written terms that describe the program’s material aspects.
Changes to our Privacy Notice
Oak Street Funding reserves the right to amend this privacy notice at our discretion and at any time. When we make changes to this notice, we will post the updated notice as appropriate. Your continued use of our Website following the posting of changes constitutes your acceptance of such changes.
If you have any questions or comments about this CCPA notice, the ways in which Oak Street Funding collects and uses your information, your choices and rights regarding such use, or wish to exercise your rights, you can contact us at:
 Solely in connection with the Loan Requirements.
 Solely in connection with the Loan Requirements.