Privacy Policy

Last Updated: January 1, 2025

Background

Welcome, and thank you for your interest in Digital Ledger (“Digital Ledger,” “we,” or “us”) and our web application at app.digitalledger.io (the “App”), on which a link to this Privacy Policy (this “Policy”) is displayed.

Privacy and security are important to us at Digital Ledger. This Policy describes how Digital Ledger may collect, use, process, disclose, and safeguard information we obtain through the App and is meant to help you (the “User”). It also tells you about your rights and choices with respect to your information, and how you can contact us if you have any questions or concerns. We promise we never sell your data: never have, and never will.

This Policy is incorporated into and is subject to the Digital Ledger Terms of Use, which can be found at digitalledger.io/legal. Capitalized terms used but not defined in this Policy have the meaning given to them in the Digital Ledger Terms of Use.

Our Data Practices

1.  Data We Collect

For the purpose of this Policy, “Data” means any information relating to an identified or identifiable individual. We obtain Data relating to you from various sources described below.

Where applicable, we indicate whether and why you must provide us with your Data, as well as the consequences of failing to do so. If you do not provide Data when requested, you may not be able to benefit from all of the features of our App if that information is necessary to provide you with full access to the App features or if we are legally required to collect it.

a.    Data Provided by You

Account Registration. If you register to use the App, then you must provide us with your name, email address, and a password in order to create an account and user profile. Some types of user registrations also require a physical address or location. You may also optionally add other information, such as a phone number.

Making Payments. When you make payments to or through the Service, you may need to provide Data to our third-party service provider, Stripe, such as your credit card number and billing address. We never have access to or store your payment information in any way. Stripe’s privacy policy can be found at stripe.com/privacy.

User Content. We will collect any information you upload or enter in the App.

Communications. We will collect any information which you provide to us through your communications, such as when you communicate with our support staff.

b.    Data Collected from Financial Institutions About and From Your Accounts

When you willfully connect Financial Institutions via the App, we may collect, use, and store information regarding connected accounts, account owners, and account transaction data. We utilized Plaid to connect your bank accounts to our App. We never have access to or store your bank account credentials in any way. Plaid’s privacy policy can be found at plaid.com/legal/#end-user-privacy-policy.

Account Data. Including financial institution name, account name, account type, account ownership, branch number, IBAN, BIC, account number, routing number, and sort code.

Account Owner Identifiers. Including data about the account owner(s), including name, email address, phone number, and address information.

Transaction Data. Including amount, date, payee, type, quantity, price, location, involved securities, and a description of the transaction.

 c.    Data Collected via Automated Means

In addition to information that you provide to us, we may collect information about you and your use of the App via automated means, such as cookies, web beacons and similar technologies:

Cookies and Similar Technologies. When you use the App, we may send one or more cookies – small text files containing a string of alphanumeric characters – to your device. We may use both session cookies and persistent cookies to automatically collect certain information. A session cookie disappears after you close your browser. A persistent cookie remains after you close your browser and may be used by your browser on subsequent visits to the App. When you use the App, we may also automatically collect certain information from your device by using similar technologies, including “clear gifs” or “web beacons.” Please review your web browser “Help” file to learn the proper way to modify your settings with regard to such automated data collection. Please note that if you delete, or choose not to accept, such technologies from the App, you may not be able to utilize the features of the App to their fullest potential.

The automatically collected information may include your IP address or other device address or ID, web browser and/or device type, the web pages or sites that you visit just before or just after you use the App, the pages or other content you view or otherwise interact with on the App, and the dates and times that you visit, access, or use the App. We also may use these technologies to collect information regarding your interaction with email messages, such as whether you opened, clicked on, or forwarded a message. This information is gathered from all users.

We use this information to assess how many users access or use our App, how they interact with our App, which content, products, and features of our App most interest or are of most value to our users, what types of offers and incentives our customers and their end-customers respond to, and how our App performs from a technical point of view.

Google Analytics. We utilize Google Analytics, which uses cookies and similar technologies to collect and analyze information about use of the App and report on activities and trends. You can learn about Google’s practices by going to: https://policies.google.com/technologies/partner-sites, and opt out of them by downloading the Google Analytics opt-out browser add-on, available at: https://tools.google.com/dlpage/gaoptout.

Third Party Web Beacons and Third Party Buttons. We may also implement third-party content or advertising on the App that may use clear gifs or other forms of web beacons, which allow the third-party content provider to read and write cookies to your browser in connection with your viewing of the third party content on the App. Additionally, we may implement third party buttons (such as “like” or “share” buttons) that may allow third parties to collect information about you through such third parties’ browser cookies, even when you do not interact with the button. Information collected through web beacons and buttons is collected directly by these third parties, and Digital Ledger does not participate in that data transmission. Information collected by a third party in this manner is subject to that third party’s own data collection, use, and disclosure policies.

 d.    Information We Derive From Data Collected

We may derive additional information about you from the data we collect. For example, we may infer your geolocation, spending habits or patterns, or potential 3rd party offers that may interest you―such as recommending a high interest savings account. Information we derive is not shared with 3rd parties to process or use for their marketing purposes, derived information is for internal use only.

2.  How We Use Data We Collect

We may use Data we collect for the following purposes:

Internal and Service-Related Usage. We use your Data to operate, maintain, enhance and provide all features of the App, to provide services and information that you request, to respond to comments and questions and otherwise to provide support to users.

Analytics and Improving the Service. We use your Data to understand and analyze the usage trends and preferences of our users, to improve the App, and to develop new services, feature, and functionality.

Verify Your Identity or Protect Privacy. To verify your identity to help protect your data and privacy against malicious activity.

Communications. We may use your email address or other Data (i) to contact you for administrative purposes such as customer service, to address intellectual property infringement, privacy violations or defamation issues related to your User Content posted on the App or (ii) to send communications, including updates on promotions, relating to products and services offered by us and by third parties we work with. Generally, you have the ability to opt-out of receiving any promotional communications as described below under “Your Rights and Choices.”

Develops Improvements and Insights. We may use your Data to: (i) improve or personalize our services, such as remembering your name so that you will not have to re-enter it during your visit or the next time you visit the App; (ii) develop new products and services; (iii) provide customized 3rd party offers, content, and information.

Aggregate Data. We may de-identify and aggregate information to monitor and analyze the effectiveness of App and third-party marketing activities and to monitor aggregate site usage metrics such as total number of visitors and pages viewed.

Legal Purpose. We may use your Data to enforce our Terms of Use, to defend our legal rights, and to comply with our legal obligations and internal policies.

Other Purposes. We also may use your Data as may be described in a notice to you at the time the information is collected, or in any other manner to which you consent.

Our App is marketed exclusively to users and located in the United States. We do not intentionally target users who are citizens of the European Union or any other geographic region. If you are reside in the European Economic Area or another geographic area that is not the United States, we only process your Data based on a valid legal ground, including when:

  • You have consented to the use of your Data;
  • We need your Data to provide you with service, including for account registration and to respond to your inquiries;
  • We have a legal obligation to use your Data;
  • We retain the right to refuse service to any user located in the European Economic Area or another geographic area that is not the United States as is outlined in our Terms of Use.

 3.  How We Share Your Data

Except as described in this Policy or otherwise disclosed to you at the time of the collection, we will not disclose your Data to third parties without your consent. We may disclose information to third parties in the following circumstances: 

(For US users) We do not share your data with non-affiliated third parties except as permitted by law (as authorized by 12 C.F.R. § 1016.14 and 1016.15). 

  • Digital Ledger affiliates and subsidiaries. We may disclose Data about you to our affiliates and subsidiaries.
  • Vendors and Service Providers. We work with third party service providers to provide App or application development, hosting, maintenance, and other services for us. These third parties may have access to or process your Data as part of providing those services for us. We limit the information provided to these service providers to that which is necessary for them to perform their functions, and we require them to agree to maintain the confidentiality of such information.
    • Other Third Parties. We may also share Data about you with other third parties in the following circumstances:
    • In Aggregated Form. We may make certain automatically-collected, aggregated, or otherwise de-identified information available to third parties for various purposes, including (i) compliance with various reporting obligations; (ii) for business or marketing purposes; or (iii) to assist such parties in understanding our users’ and our Business Customers’ end-customers’ interests, habits, and usage patterns for certain programs, content, services, advertisements, promotions, and/or functionality available through the App.
    • To Comply with Legal Obligations. We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to comply with state and federal laws (such as U.S. copyright law), in response to a court order, judicial or other government subpoena or warrant, or to otherwise cooperate with law enforcement or other governmental agencies.
    • To Protect and Enforce Our Rights. We also reserve the right to disclose your information that we believe, in good faith, is appropriate or necessary to (i) take precautions against liability, (ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity, (iii) investigate and defend ourselves against any third-party claims or allegations, (iv) protect the security or integrity of the App and any facilities or equipment used to make the App available, or (v) protect our property or other legal rights (including, but not limited to, enforcement of our agreements), or the rights, property, or safety of others.
    • In case of Merger, Sale, or Other Asset Transfer. Information about our users, our Business Customers and their end-users and end-customers, including Data, may be disclosed and otherwise transferred to an acquirer, or successor or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets.
    • With Your Consent. We also may disclose your Data as may be described in a notice to you at the time the information is collected, or in any other manner to which you consent.

 

4.  Your Rights and Choices

Account Information. You may, of course, decline to share certain Data with us, in which case we may not be able to provide to you some of the features and functionality of the App. You may update, correct, or delete your account information and preferences at any time by accessing your admin settings page on the App, or by contacting us at privacy@digitalledger.io. Please note that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain all information you submit for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so, to the extent permitted under applicable law.

Opt-Out. If you receive commercial email from us, you may unsubscribe at any time by following the instructions contained within the email. You may also opt-out from receiving commercial email from us, and any other promotional communications that we may send to you from time to time, by sending your request to us by email to privacy@digitalledger.io or by writing to us at the address given at the end of this policy. We may allow you to view and modify settings relating to the nature and frequency of promotional communications that you receive from us in user account functionality on the App.

Please be aware that if you opt-out of receiving commercial email from us or otherwise modify the nature or frequency of promotional communications you receive from us, it may take up to ten business days for us to process your request, and you may receive promotional communications from us that you have opted-out from during that period, unless we are required by applicable law to process your request within a shorter period of time. Additionally, even after you opt-out from receiving commercial messages from us, if you are a registered user you may continue to receive administrative messages from us regarding your use of the App.

Privacy Settings. Although we may allow you to adjust your privacy settings to limit access to certain Data, please be aware that no security measures are perfect or impenetrable. To the fullest extent permitted under applicable law, we are not responsible for circumvention of any privacy settings or security measures on the App. Additionally, we cannot control the actions of others with whom you may choose to share your information. Furthermore, even after information posted on the App is removed, caching and archiving services may have saved that information, and others, including third parties, may have copied or stored the information available on the App. To the fullest extent permitted under applicable law, we cannot and do not guarantee that information add or transmit in the App will not be viewed by unauthorized persons.

Do Not Track. Some web browsers incorporate a “Do Not Track” feature. Because there is not yet an accepted standard for how to respond to Do Not Track signals, our App does not currently respond to such signals.

Other Rights. If you are located in or are a citizen of the European Economic Area, you may have the following additional rights:

  • Request access to and receive information about the Data we maintain about you, to update and correct inaccuracies in your Data, to restrict or to object to the processing of your Data, to have the information anonymized or deleted, as appropriate, or to exercise your right to data portability to easily transfer your Data to another company. In addition, you may also have the right to lodge a complaint with a supervisory authority, including in your country of residence, place of work or where an incident took place.
  • Withdraw any consent you previously provided to us regarding the processing of your Data, at any time and free of charge. We will apply your preferences going forward and this will not affect the lawfulness of the processing before your consent withdrawal.

Those rights may be limited in some circumstances by local law requirements. You may exercise these rights in accordance with the "How to Contact Us" section below.

 

5.   Third-Party Services

This Privacy Policy applies only to the processing of your Data by Digital Ledger. The App may contain features or links to Web sites and services provided by third parties. The policies and procedures described in this Privacy Policy do not apply to Third Party Sites. Any information you provide on third-party sites or services is provided directly to the operators of such services and is subject to those operators’ policies, if any, governing privacy and security, even if accessed through the App. We are not responsible for the content or privacy and security practices and policies of third-party sites or services to which links or access are provided through the App. We encourage you to learn about third parties’ privacy and security policies directly from those sites before providing them with any information.

 

6.   Children’s Privacy

We recognize the importance of protecting the privacy of young children. Our App is not directed to children under the age of 13, and we do not knowingly collect Data from children under the age of 13 without obtaining parental consent. If you are under 13 years of age, please do not use or access the App at any time or in any manner. If we learn that Data has been collected on the Service from persons under 13 years of age and without verifiable parental consent, then we will take the appropriate steps to delete this information. If you are a parent or guardian and discover that your child under 13 years of age has obtained an account on the App, then you may alert us at privacy@digitalledger.io and request that we delete that child’s Data from our system.

 

7.   Data Security

We use certain physical, managerial, and technical safeguards that are designed to appropriately protect Data against accidental or unlawful destruction, accidental loss, unauthorized alteration, unauthorized disclosure or access, misuse, and any other unlawful form of processing of the Data in our possession. The below are a sample of the security standards employed by the 3rd party vendor responsible for hosting and maintenance of our Data:

  • Vulnerability Testing. Automated code testing, vulnerability testing (including OWASP Top 10), and continuous monitoring technologies.
  •  Penetration Tested. Conducts pen tests annually (at minimum) following the comprehensive OWASP WSTG.
  •  State-of-the-art Encryption. Your data is safeguarded in transit with TLS and at rest through RDS AES-256.
  • Secured with AWS. Our app is built on AWS, which supports 143 security standards and compliance certifications, including PCI-DSS, HIPAA/HITECH, FedRAMP, GDPR, FIPS 140-2, and NIST 800-171.

 Stripe and Plaid are other 3rd party vendors referenced in this document. Below is an overview and links to their relevant security information for your convenience.

  • Stripe. Utilized to process your payment for App subscriptions. They are PCI-certified as a PCI Service Provide Level 1, which is the most stringent level of certification available in the payments industry. More information can be found atdocs.stripe.com/security.
  •  Plaid. Utilized to link your bank accounts as defined in the Data We Collect section of this document. Plaid is certified in internationally-recognized security standards, like ISO 27001, ISO 27701, and is SSAE18 SOC 2 compliant. More information can be found at plaid.com/legal/#end-user-privacy-policy.

WE CANNOT, HOWEVER, GUARANTEE THE SECURITY OF ANY INFORMATION YOU TRANSMIT TO US OR STORE ON THE SERVICE, AND YOU DO SO AT YOUR OWN RISK. WE ALSO CANNOT GUARANTEE THAT SUCH INFORMATION MAY NOT BE ACCESSED, DISCLOSED, ALTERED, OR DESTROYED BY BREACH OF ANY OF OUR PHYSICAL, TECHNICAL, OR MANAGERIAL SAFEGUARDS. The foregoing is subject to requirements under applicable law to ensure or warrant information security.

If we learn of a security systems breach, then we may attempt to notify you electronically so that you can take appropriate protective steps. We may post a notice through the App if a security breach occurs. Depending on where you live, you may have a legal right to receive notice of a security breach in writing. To receive a free written notice of a security breach you should notify us at privacy@digitalledger.io

8.   Data Retention

We take measures to delete your Data or keep it in a form that does not permit identifying you when this information is no longer necessary for the purposes for which we process it, unless we are required by law to keep this information for a longer period. When determining the retention period, we take into account various criteria, such as the type of products and services requested by or provided to you, the nature and length of our relationship with you, possible re-enrollment with our products or services, the impact on the services we provide to you if we delete some information from or about you, mandatory retention periods provided by law and the statute of limitations.

 

9.   Data Transfers

The App is hosted in the United States and is intended only for visitors located within the United States. Users outside the United States are not eligible to use our App. If you are located outside of the United States or a citizen of a country other than the United States, please do not upload or enter any Data to our App

If you choose to use the App from the European Union or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your Data outside of those regions to the United States for storage and processing. Also, we may transfer your data from the U.S. to other countries or regions in connection with storage and processing of data, fulfilling your requests, and operating the App. By providing any information, including Data, on or to the App, you consent to such transfer, storage, and processing. 

When we transfer Data outside of the European Economic Area, we will comply with applicable EU data protection laws when legally required to do so. We may transfer your Data to countries which provide an adequate level of protection under EU law, we may use contractual protections for the transfer of Data, or rely on other legal transfer mechanisms or derogations. You may contact us as specified below to obtain a copy of the safeguards we use to transfer Data outside of the European Economic Area.

10. Changes and Updates to this Policy

Please revisit this page periodically to stay aware of any changes to this Policy, which we reserve the right to update from time to time. If we modify the Policy, we will make it available through the App, and indicate the date of the latest revision. In the event that the modifications materially alter your rights or obligations hereunder, we will make reasonable efforts to notify you of the change. For example, we may send a message to your email address, if we have one on file, or generate a pop-up or similar notification when you access the App for the first time after such material changes are made. Your continued use of the App after the revised Policy has become effective indicates that you have read, understood and agreed to the current version of the Policy.

 11. How to Contact Us

Digital Ledger is the entity responsible for the processing of your Data as described in this Policy. If you have any questions or comments about this Policy, your Data, our use and disclosure practices, or your consent choices, please contact us by email at privacy@digitalledger.io  or write to us at:

 

Digital Ledger
ATTN: Legal Department (Copyright)

30 N Gould St

STE N

Sheridan, WY 82801

United States of America