Privacy Policy & Notices (“Privacy Policies”)

Last Updated: March 22, 2021

This privacy policy (the “Bread Privacy Policy”) and privacy notice (the “Bread Privacy Notice”) describes how Lon Operations LLC (d/b/a Bread and Bread Operations) and its affiliates, agents and assigns (collectively, “Bread”, “we”, or “us”) collect and use the personal or other information provided by any user of our Site or the Bread Services (as defined below) (such user, “you”). The Bread Privacy Policy and Bread Privacy Notice applies to the use of any Bread online product or services, including (1) use of Bread’s technology and interface to determine potential eligibility for a loan or to request a loan from a partner financial institution, which may be a Bread affiliate (the “Partner Bank”), (2) submitting a request to make a purchase with a retail Merchant (as defined below) under a retail installment transaction, (3) submitting an application for any other financial product or repayment method Bread may make available, (4) to manage your account (the “Bread Services”), and (5) to access or use the Bread website at www.breadpayments.com, including derivatives of the Bread website such as the member’s portal where you can access information on your account (collectively, the “Site”). As used in this Privacy Policy, “Personal Data” means any information that identifies or relates to a particular individual and also includes information referred to as “personally identifiable information” or “personal information” as these terms are defined under applicable data privacy laws, rules, or regulations.

To see how we use and share your information, see “Information Shared With Other Parties” below.

The “In a nutshell...” summaries next to each section are for reference purposes only, may not summarize all of the rights and obligations contained in that section, and are not contract terms. As such, please read the entirety of the Bread Privacy Policy and Bread Privacy Notice carefully. The privacy and the protection of your Personal Data are important to us and this policy and privacy notice describe how we collect and store your information, how we share that information, and your choices regarding how the information is used or shared.

Bread loans are made by Comenity Capital Bank, a Utah state-chartered bank, Member FDIC (the “Bank”). For information about how the Bank collects, uses, and discloses your Personal Data obtained in connection with your loan, see the Privacy Notice below.

Changes to Bread Privacy Policy

We may update the Bread Privacy Policy and Bread Privacy Notice from time to time. If we do this, we will post the revised Bread Privacy Policy or the Bread Privacy Notice on the Site and will indicate at the top of the page when this policy or notice was last revised. If any such changes impose additional obligations on you and if we deem any such change to be material, we may send you a notification regarding such changes (e.g., by sending you an email). In some cases, we may notify you in advance of the changes taking effect. Your continued use of the Bread Services or the Site after we have made any such changes will constitute your acceptance of the new Bread Privacy Policy or Bread Privacy Notice, as applicable.

In any event, at least annually, we will provide our “Customers” (defined as users of Bread Services with an outstanding loan or retail installment transaction) a copy of the Bread Privacy Policy and Bread Privacy Notice, which will be sent electronically to the email address provided to us at the time of application or of which the Customer has subsequently notified us.

In a nutshell...

We may change this Privacy Policy or the Privacy Notice. If you continue to use the Bread Services or the Site after we make any changes, you are agreeing to the new Bread Privacy Policy and Privacy Notice. The dates on the top shows when the Bread Privacy Policy was last updated. Customers of Bread Services will receive a copy of the Bread Privacy Policy and Bread Privacy Notice annually by email.

Sources of Personal Data

We collect Personal Data about you from:

Categories of Personal Data Collected

The following chart details the categories of Personal Data that we collect and have collected over the past twelve (12) months. Throughout this Privacy Policy, we will refer back to the categories of Personal Data listed in this chart (for example, “Category A. Personal identifiers”).

Category of Personal Data Personal Data Collected What is the source of this Personal Data?
A. Personal identifiers
  • Your name
  • Your email address
  • Your phone number
  • Your date of birth
  • Your identification number (Social Security Number or other taxpayer identification number)
  • Your home street address
  • Photographs, government identification, and other official identifying information; and
  • Your device’s IP address.
You /Third Parties
B. Customer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e)))
  • Your name
  • Your email address
  • Your phone number
  • Your date of birth
  • Your identification number (Social Security Number or other taxpayer identification number)
  • Your home street address
  • Photographs, government identification, and other similar information;
  • A debit card, credit card and/or account number and its associated account information (your debit card and credit card information is processed by a third party; we do not have access to your payment card information or other information you provide to us to facilitate a payment by debit or credit card); and
  • Your personal financial information, including voluntarily reported income information and predicted annual income.
You /Third Parties
C. Protected classification characteristics under state or federal law
  • Your date of birth
You /Third Parties
D. Commercial information considered, or other purchasing or consuming histories or tendencies.
  • Other information about your interaction with the Bread Services on any Merchant website or the Site
  • The type of device you are using to access the Bread Services or the Site
You /Third Parties
E. Biometric information We do not collect this category of Personal Data.
F. Internet or other similar network activity information
  • Other information about your interaction with the Bread Services on any Merchant website or the Site
  • Your device’s IP address
  • The type of device you are using to access the Bread Services or the Site
You /Third Parties
G. Geolocation data
  • Your device’s IP address
  • Your device’s location information and any other information sent to us by the device
You /Third Parties
H. Sensory data We do not collect this category of Personal Data.
I. Professional or employment-related information We do not collect this category of Personal Data.
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)) We do not collect this category of Personal Data.
K. Inferences drawn from other personal information We do not collect this category of Personal Data.
L. Age or date of birth
  • Your date of birth
You

Information That You Provide

In addition to the information in the table above, in the course of communicating with us, you may also provide information in writing; through our website, including through our “Contact Us” feature or any other customer service tools; or over the phone which will be recorded and maintained in order to provide the Bread Services to you, to improve Bread Services for other Customers, or as required by law.

You agree to promptly notify us if there are any changes to the Personal Data you have provided to us by calling us at (844) 992-7323 or writing to us at Bread at P.O. Box 1264, New York, NY 10276.

Information We Collect Automatically

In order to help us further identify you to protect against fraud and identity theft, and for other purposes (including, for example, to improve our product or services or for us or Third Parties to market to you), our technology may gather further information about you, which information may include the following:

Like many online services, we use cookies or other anonymous identifiers to collect information about you. We may also gather and store “clickstream information,” including information regarding your use of our Site directly or through service providers, including cookies, web beacons, page tags, pixels or similar tools (collectively, “Cookies”) and information about your computer, the type of browser you are using, your internet service provider, your page views, pathways to and from the Site, referral URL, data from third party analytics or marketing companies regarding the interaction with any web-based advertising, and your operating system. Cookies are small pieces of data – usually text files – placed on your computer, tablet, phone, or similar device when you use that device to visit our Services. We may also supplement the information we collect from you with information received from Third Parties, including Third Parties that have placed their own Cookies on your device(s). Please note that because of our use of Cookies, the Bread Services do not support “Do Not Track” requests sent from a browser at this time. You can control the use of Cookies at the individual browser level. If you reject Cookies, you may not be able to use the Bread Services or access the Site.

We use the following types of Cookies:

You can decide whether or not to accept Cookies through your internet browser’s settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allowing you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your computer. If you do this, however, you may have to manually adjust some preferences every time you visit a site and some of the Bread Services and functionalities may not work.

To explore what Cookie settings are available to you, look in the “preferences” or “options” section of your browser’s menu. To find out more information about Cookies, including information about how to manage and delete Cookies, please visit https://www.allaboutcookies.org/.

In a nutshell...

We ask for and collect personal and other information about you directly from you and from third party vendors. This information is used for many purposes, including improving the Bread Services and verifying your identity.

Retaining Your Information

For legal and other reasons, we need to retain the information we collect about you. We retain your information in accordance with our data retention policies, which are designed to satisfy our legal and other obligations. We will only use this information for limited purposes. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.

In a nutshell...

We will retain your information in accordance with our data retention policies even after you have ceased to be a Bread Customer.

How We May Use Your Information

We may use your information for everyday business purposes and marketing purposes, including to:

We may use or combine information that we collect through other sources or from service providers to enhance, expand or verify the accuracy of our records, or for other reasons. Data collected from a particular browser, device or application may be used with another linked browser, device or application.

We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated, or incompatible purposes without providing you notice.

As noted in the list above, we may communicate with you if you’ve provided us the means to do so. For example, if you’ve given us your email address, we may send you promotional email offers or email you about your use of the Bread Services. Also, we may receive a confirmation when you open an email from us, which helps us improve the Bread Services. If you do not want to receive promotional communications from us, please indicate your preference by emailing us at support@breadpayments.com.

In a nutshell...

We may use your information for our everyday business purposes, to facilitate the use of the Bread Service, to market to you, and for various other business purposes.

Information Shared With Other Parties

By using Bread Services, you authorize us to share with the Merchant, for their marketing purposes, and with other non-affiliated third parties (for example, marketing companies) for the purposes of marketing the Bread Services or the Merchant’s products and services to you, certain information that is a part of or related to your application for Bread Services, including, but not limited to, your name, email address and whether or not you were pre-qualified to use the Bread Services, as permitted by law. You may opt out of this sharing at any time by calling us at (844) 992-7323 or emailing us at support@breadpayments.com.

We may share your information with other third parties for business purposes, including the following:

In the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of any or all of our assets, some of the Personal Data that we hold may be among the assets transferred to a buyer or other successor. We may transfer to another business or non-affiliated entity or its affiliates, advisors or service providers some or all information about you in connection with, or during negotiations of, any joint marketing relationship, merger, acquisition, sale of assets or any line of business, change in ownership control or financing transaction. If we do, we may not be able to limit how such other party may use or further transfer your information.

We may also share with third parties – such as advertisers – aggregated or de-identified information and we do not limit our third-party providers from using, selling, licensing, distributing, or disclosing such aggregated or de-identified data.

We may share information in other ways if you give us consent or direct us to do so.

Sales of Personal Data

We have not sold your Personal Data over the last twelve (12) months.

In a nutshell...

By using Bread Services, you authorize us to share with the Merchant for their marketing purposes and with other non-affiliated third parties (for example, marketing companies) for purposes of marketing the Bread Service or the Merchant’s products and services to you, certain information that is a part of or related to your application for Bread Services, including, but not limited to, your name, email address and whether or not you were pre-qualified to use the Bread Service, as permitted by law. You may opt out of this sharing at any time by calling us at (844) 992-7323 or emailing us at support@breadpayments.com. We may also share your information with non-affiliated third parties for everyday business purposes and for marketing purposes, our affiliates for everyday business purposes, or other third parties in response to a legal or regulatory inquiry or as required by law. We do not sell your Personal Data.

Safeguarding Your Information

We have adopted a security policy and certain safeguards intended to protect your information against unauthorized access, which may include firewalls, data encryption and restricting access to your Personal Data only to those employees, contractors or other representatives who have a need to know such information to carry on our operations. These safeguards are reviewed and adjusted periodically based on ongoing risk assessments.

Some of our employees, contractors and representatives may have access to your information. Wherever possible, our policies and procedures may limit access to your information to those employees, contractors, and representatives who have a need for such information to perform their job functions.

Please keep in mind that the Internet is not a 100% secure medium for communication, and we cannot guarantee that the information collected about you will always remain private when using the Bread Services. We recommend that users implement their own security controls, including the use of strong passwords, antivirus software, and maintaining up-to-date web browsers.

In a nutshell...

We have adopted a security policy and certain safeguards intended to protect your information against unauthorized access.

Other sites

The Bread Privacy Policy and Bread Privacy Notice only cover your use of the Bread Services or access to the Site. Merchants through which you purchase products or services using Bread Services may have different privacy policies with respect to the handling of your information. In addition, Merchants which sell products that are health related may have other requirements with respect to the collection and use of your information. The Bread Services are not, and are not intended to be, a part of Merchants’ privacy policies. Before providing Merchants with your Personal Data, you should consult their privacy policies to understand how any information you may have provided to Merchants, or that the Merchants may have accessed, will be handled.

In a nutshell...

This policy only covers the Bread Services and this Site. The Merchant with whom you use the Bread Services will likely have their own privacy policies which you should consult.

Rights with Respect to Your Personal Data

You can access certain Personal Data that you have provided to us by logging into your account at https://members.getbread.com. You can update your bank account information through the account portal and if you need to change any other information you can contact us at support@breadpayments.com or (844) 992-7323. You agree to notify us promptly of any changes to your Personal Data.

Access

The following rights to access and deletion of your Personal Data are available to all users of the Bread Services, and if you are a California resident, you are entitled to these rights under the California Consumer Privacy Act (CCPA). However, there may be other laws and regulations that supersede your rights under this section of the Bread Privacy Policy and the CCPA, including the Gramm-Leach-Bliley Act and the Fair Credit Reporting Act. For example, this section does not apply with respect to information that we collect on users who apply for or obtain our products and services for personal, family, or household purposes, as those uses would be governed under the Gramm-Leach-Bliley Act.

You have the right to request certain information about our collection and use of your Personal Data over the past twelve (12) months. We will provide you with the following information:

If we have disclosed your Personal Data for a business purpose over the past twelve (12) months, we will identify the categories of Personal Data shared with each category of third-party recipient.

Deletion

You have the right to request that we delete the Personal Data that we have collected from you. Under the CCPA and other privacy laws, this right is subject to certain exceptions: for example, we may need to retain your Personal Data to provide you with the Bread Services or complete a transaction or other action you have requested, including in connection with a financial transaction. If your deletion request is subject to one of these exceptions, we may deny your deletion request.

Marketing (California)

Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to contact us to prevent disclosure of Personal Data to third parties for such third parties’ direct marketing purposes; in order to submit such a request, please contact us at support@breadpayments.com.

Exercising Your Rights

To exercise the rights described above, you must send us a request that (1) provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Data (e.g., the IP address you used to access a Merchant website or the email address you provided), and (2) describes your request in sufficient detail to allow us to understand, evaluate, and respond to it. Each request that meets both of these criteria will be considered a “Valid Request”. We may not respond to requests that do not meet these criteria. We will only use Personal Data provided in a Valid Request to verify you and complete your request. You do not need an account to submit a Valid Request.

We will work to respond to your Valid Request within forty-five (45) days of receipt. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive, or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.

You may submit a Valid Request using the following methods:

We Will Not Discriminate Against You for Exercising Your Rights Under the CCPA

We will not discriminate against you for exercising your rights under the CCPA. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise your rights under the CCPA.

In a nutshell...

You can, and should, update your information by contacting us at support@breadpayments.com or (844) 992-7323. You have the right to request certain information about our collections and use of Personal Data and the right to request that we delete your Personal Data. Certain of the rights set forth in this Section, however, may not apply to our collection and use of your Personal Data governed by the Gramm-Leach-Bliley Act or the Fair Credit Reporting Act.

Other Limitations

Age Restrictions

Your use of the Site and/or Bread Services is intended for use only in the United States and states where Bread Services are available. The Bread Services are intended only for persons aged eighteen (18) years or older (nineteen (19) years of age in Alabama or Nebraska). While certain Merchant’s products may be sold outside the United States, including in the European Union, the Bread Services and the Site are not marketed to or intended to be used by any non-United States resident.

We do not knowingly collect or solicit Personal Data from anyone under the age of thirteen (13). If you are under thirteen (13), please do not attempt to use Bread Services or send any Personal Data about yourself to us. If we learn that we have collected Personal Data from a child under age thirteen (13), we will delete that information as quickly as possible. If you believe that a child under thirteen (13) may have provided us Personal Data, please contact us immediately at support@breadpayments.com.

Nevada Resident Rights

If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. You can exercise this right by contacting us at support@breadpayments.com with the subject line “Nevada Do Not Sell Request” and providing us with your name and the email address associated with your account. Please note that we do not currently sell your Personal Data as sales are defined in Nevada Revised Statutes Chapter 603A.

Do Not Track Signals

Our Site does not support Do Not Track (“DNT”) at this time. DNT is a privacy preference you can set in your web browser to indicate that you do not want certain information about your web page visits tracked and collected across websites. For more details, including how to turn on Do Not Track, visit https://www.donottrack.us/

In a nutshell...

Your use of the Site and/or Bread Services is intended for use only in the United States and the states where Bread Services are available. The Bread Services are intended only for persons aged eighteen (18) years or older (nineteen (19) years of age in Alabama or Nebraska). We do not knowingly collect or solicit Personal Data from anyone under the age of thirteen (13). If you believe that a child under thirteen (13) may have provided us Personal Data, please contact us immediately at support@breadpayments.com.

Bread Privacy Notice

Rev. January 2021

What does Lon Operations LLC (“Lon”) do with your Personal Data?

Why?
Financial companies choose how they share your Personal Data. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your Personal Data. Please read this notice carefully to understand what we do.

What?
The types of Personal Data we collect and share depend on the product or service you have with us. This information can include:

When you are no longer our customer, we continue to share your information as described in this notice.

How?
All financial companies need to share Personal Data to run their everyday business. In the section below, we list the reasons financial companies can share their customers’ Personal Data; the reasons Lon chooses to share; and whether you can limit this sharing.

Reasons We Can Share Your Personal Data Does Lon share? Can you limit this sharing?
For our everyday business purposes—such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus Yes No
For our marketing purposes—to offer our products and services to you Yes No
For joint marketing with other financial companies No We don’t share.
For our affiliates’ everyday business purposes—information about your transactions and experiences Yes Yes
For our affiliates’ everyday business purposes—information about your creditworthiness Yes Yes
For our affiliates to market to you Yes Yes
For non-affiliates to market to you Yes Yes
To Limit Our Sharing

Please note:
If you are a new customer, we can begin sharing your information forty-five (45) days from the date we send this notice; however we may immediately share your information with Merchants and non-affiliated marketing companies pursuant to the authorization and consent you provide in the “How We May Use Your Information” and “Information Shared With Third Parties” section of our Privacy Policy. When you are no longer our customer, we continue to share your information as described in this notice.

However, you can contact us at any time to limit our sharing.

Questions?

Call (844) 992-7323 or contact us at support@breadpayments.com.

Who we are

Who is providing this notice?
Lon Operations LLC

What we do

How does Lon protect my Personal Data?
To protect your Personal Data from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings.

How does Lon collect my Personal Data?
We collect your Personal Data, for example, when you

We also collect your personal information from others, such as credit bureaus, affiliates, or other companies.

Why can't I limit all sharing?
Federal law gives you the right to limit only

State laws and individual companies may give you additional rights to limit sharing. See below for additional information on your rights under state law.

Definitions

Affiliates
Companies related by common ownership or control. They can be financial and nonfinancial companies.

Non-affiliates
Companies not related by common ownership or control. They can be financial and nonfinancial companies.

Joint marketing
A formal agreement between non-affiliated financial companies that together market financial products or services to you.

Other Important Information

California Customers

In accordance with California law, we will not share information we collect about California residents with non-affiliates, unless the law allows. For example, we may share information with your consent or to service your accounts. We will limit sharing among our companies to the extent required by California law.

Vermont Customers

We will not disclose information about your creditworthiness to our affiliates and will not disclose your Personal Data, financial information, credit report, or health information to non-affiliated third parties to market to you, other than as permitted by Vermont law, unless you authorize us to make those disclosures. Additional information concerning our privacy policies can be obtained by calling (844) 992-7323.