August 2026
Privacy Policy
Naven Federal Credit Union
Naven Federal Credit Union is dedicated to ensuring a secure environment for your financial needs while prioritizing your privacy. This statement details our privacy practices for all Naven digital channels, including our websites, mobile apps, social media platforms, digital banking apps, and digital ad campaigns, collectively referred to as “digital property”. References to "Naven," "we," “CU,” or "us" pertain to Naven Federal Credit Union and its U.S. affiliates.
Information collected by Naven during the application for or servicing of one of our products or services is also governed by Naven’s Privacy and Opt-Out Notice. If you are a California resident, you may have rights under the California Consumer Privacy Act as described in Naven’s California Privacy Statement at the end of this document.
Our digital properties do not intentionally target children under the age 13 and we do not knowingly collect personal information from children under the age of 13. Social media sites may have their own privacy policies that you should understand prior to using their services to interact with Naven.
Information We Collect
Naven gathers personal data to provide a seamless digital experience whenever you interact with our online platforms, such as when initiating a new account application, enrolling in products, or using our mobile applications. Specific categories of data collected include:
- Registering and using our web or mobile applications
- Conducting payment transactions using the CU web or mobile applications
- Identity and Contact details (name, address, email, phone).
- Financial data, government identifiers (SSN, driver’s license), and secure access credentials.
- Technical device data (IP addresses, browser settings) and interaction analytics.
- Geolocation data for fraud prevention and ATM locators.
- Property and Asset Information (e.g. address for real estate owner by you, license plate/VIN number for your vehicle)
- Inference Information (e.g. personal Information inferred about personal characteristics and preferences, such as, but not limited to, predicted creditworthiness, demographics, interests, behavioral patterns, psychological trends, predispositions, or behavior)
- Third-Party Data Sources. For e.g. we may combine Personal Information we receive from you with Personal Information we obtain from other sources, such as:
- Public sources, such as government agencies, public records, social media platforms, and other publicly available sources.
- Data providers, such as information services and data licensors that provide demographic and other information.
- Marketing partners, such as joint marketing partners and event co-sponsors.
- Digital communications while you are on our website or using the mobile app will be recorded and monitored to manage any digital chats or other communications you may have with our employees or agents acting on our behalf.
Definitions
For the purposes of this policy, the following definitions apply in accordance with the Gramm-Leach-Bliley Act (GLBA) and related regulatory frameworks:
- Affiliate: Any company that controls, is controlled by, or is under common control with the Credit Union.
- Consumer: An individual who obtains or has obtained a financial product or service from the Credit Union that is to be used primarily for personal, family, or household purposes.
- Member: A consumer who has a continuing relationship with the Credit Union.
- Nonpublic Personal Information: Personally identifiable financial information and any list, description, or other grouping of consumers derived using any personally identifiable financial information that is not publicly available.
- Personally Identifiable Financial Information: Any information a consumer provides to the Credit Union to obtain a financial product or service, or information resulting from any transaction involving a financial product or service between the Credit Union and a consumer.
How We Use and Share Your Information
We utilize information to manage accounts, process transactions, prevent fraud, and promote financial services. We may disclose collected information to trusted third-party service providers and marketing partners who are contractually bound to our privacy standards, or as required by law.
Third-Party Disclosure
Naven Federal Credit Union and its affiliates abide by all applicable laws governing the privacy of nonpublic personal information, including the NCUA Privacy of Consumer Financial Information rule (Part 716), the FTC Privacy rule (Part 313), the Gramm-Leach-Bliley Act (GLBA), Reg P, and the Fair Credit Reporting Act (FCRA).
We disclose nonpublic personal information to third parties only under the following required exceptions:
- To effect, administer, or enforce a transaction requested or authorized by the member.
- To protect the confidentiality or security of Credit Union records.
- To prevent actual or potential fraud, unauthorized transactions, claims, or other liability.
- To comply with federal, state, or local laws, rules, and other applicable legal requirements, such as responding to a subpoena or regulatory examination.
- To provide information to agencies, as permitted under law.
Online Technologies and Security
We use cookies and pixel tags to optimize performance such as monitoring advertising and marketing campaigns, and bolster security like engaging in fraud prevention. Some of these tracking tools may detect the features or settings of the specific device you use to access our website. While you can disable cookies in your browser, doing so may limit access to secure banking features. We maintain physical, electronic, and procedural safeguards that comply with federal regulations to protect your non-public personal information and network.
The Credit Union uses “cookies” which are small amounts of data websites can send to visitors’ web browsers. Cookies are typically stored on your device to help track your interests. Cookies may also enable the Credit Union or its service providers and other partners to relate your use of the Credit Union’s online services over time to customize your experience. Most web browsers allow you to adjust your settings to decline or delete cookies, but doing so may degrade your experience with the Credit Union’s website.
The Credit Union may also use clear GIFs, pixel tags or web beacons. These are usually single pixel, transparent images located on a webpage or in an email or other message. Other similar technologies may also be used on the Credit Union’s websites and in some of our digital communications (such as email or other marketing messages). Clear gifs, pixel tags, or web beacons also be used when you receive advertisements or you otherwise interact with advertisements outside of the Credit Union’s online services. These are primarily used to help the Credit Union recognize users, assess website traffic patterns and measure site or marketing campaign engagement.
Compliance and Administration
The Credit Union provides ongoing training to employees on recognizing and controlling risks to nonpublic personal information, including handling procedures and reporting unauthorized access attempts. Internal controls are maintained to ensure that every new product, service, or delivery method is reviewed for conformity with existing privacy policies. When sharing information with vendors for business purposes, all contracts must include guarantees that the vendor will safeguard such information. The Credit Union reserves the authority to amend this policy as required by law or business judgment.
Protecting your data is a shared responsibility. We recommend using robust passwords, monitoring your account activity frequently, and never recording your PIN on your card or in unencrypted notes. If you suspect fraud or have questions, contact us at 1-408-560-1780 or Email: member-support@navencreditunion.com.
Naven Federal Credit Union California Privacy Statement
This statement applies to California residents and supplements Naven Federal Credit Union’s Online Privacy Statement and GLBA Notice. It outlines the Personal Information we collect, how it is used and shared, and your rights under the California Consumer Privacy Act (CCPA). Employment-related data is covered separately under Naven’s Employment Privacy Statement. Note that most information we collect is exempt from the CCPA as it is governed by federal laws like the Gramm-Leach-Bliley Act and Fair Credit Reporting Act.
What is Personal Information?
Personal Information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your household ("Personal Information"). Under the CCPA, Sensitive Personal Information includes a consumer’s social security number, driver’s license, financial account or card number, precise geolocation, racial and ethnic characteristics, religious and philosophical beliefs, union membership, contents of mail, email and text messages, and genetic and biometric data ("Sensitive Personal Information").
Personal Information does not include:
- Publicly available information from federal, state, or local records.
- De-identified or aggregate consumer information.
- Information covered by industry-specific privacy laws such as HIPAA, the Fair Credit Reporting Act, or the Gramm-Leach-Bliley Act.
As described below, the CCPA provides you with certain rights regarding the collection, use, retention, and disclosure of your personal information.
Notice at Collection: Personal Information We Collect, Use, or Disclose
The following table outlines the categories of Personal Information Naven has collected about consumers in the last 12 months, the sources of that information, the business purposes for collection, and the categories of third parties to whom we disclose such information.
Categories of Personal Information
Identifiers: Name, alias, address, online identifier, IP address, email, SSN, driver's license, or passport number.
Customer Records: Name, signature, SSN, physical characteristics, address, phone, insurance policy, bank/credit/debit numbers.
Protected Classifications: Age, race, color, ancestry, religion, marital status, medical condition, sex, veteran status.
Commercial Information: Property records, products/services purchased or considered, consuming histories.
Internet Activity: Browsing history, search history, interactions with websites, apps, or advertisements.
Geolocation Data: Physical location or movements.
Sensitive Personal Information: Information creating a heightened risk of harm if disclosed.
Categories of Sources
Consumers, Members, Employer Sponsors, Credit Agencies, Collections, Service Providers, Gov Agencies.
Consumers, Members, Employer Sponsors, Contractors, Service Providers, Data Resellers.
Consumers, Members, Employer Sponsors, Contractors, Service Providers, Gov Agencies.
Consumers, Members, Credit Reporting, Collections, Service Providers, Gov Agencies, Data Resellers.
Consumers, Members, Credit Reporting, Service Providers, Data Resellers, ISPs.
Consumers, Members, ISPs, Mobile Providers, Collections, Service Providers, Gov Agencies.
Consumers, Members.
Business or Commercial Purpose(s)
Marketing, Underwriting, Servicing, Fraud Prevention, Security, Regulatory Requirements, Research.
Underwriting, Loan Servicing, Collection, Responding to Requests, Authentication, Employment, Debugging.
Marketing, Underwriting, Loan/Account Servicing, Research, Fraud Prevention, Membership.
Marketing, Underwriting, Loan Servicing, Recovery, Responding to Requests, Data Analytics.
Marketing, Underwriting, Servicing, Member Experience, Fraud Prevention, Debugging.
Marketing, Underwriting, Servicing, Fraud Prevention, Systems Monitoring, Authentication.
Underwriting, Servicing, Fraud Prevention, Security, Regulatory Requirements, Membership.
Categories of Third Parties / Service Providers
Servicing Partners, Credit Reporting, Gov Entities, Marketing Firms, Data Analytics, Financial Aggregators.
Servicing Partners, Credit Reporting, Marketing Firms, Gov Entities, Operating System Providers.
Servicing Partners, Credit Reporting, Gov Entities, Data Analytics, Joint Marketing Partners.
Servicing Partners, Operating System Providers, Data Analytics, Marketing Firms, Gov Entities.
Servicing Partners, Marketing Firms, Data Analytics, Social Networks, Gov Entities.
Servicing Partners, Gov Entities, Data Analytics, Marketing Firms, Joint Marketing Partners.
Servicing Partners, Credit Reporting, Marketing Firms, Gov Entities, Financial Aggregators.
Disclosure and Sale of Personal Information
Naven does not sell Personal Information or share Personal Information with a third party for cross-contextual behavioral marketing. We do not target offers to or sell/share the information of consumers under 16 years of age. Additionally, Naven does not use or disclose Sensitive Personal Information for purposes other than those permitted by the CCPA, such as to perform services reasonably expected by a consumer.
Your Rights under the CCPA
- The CCPA provides you with specific rights regarding your non-exempt Personal Information:
- The Right to Know: You may request information about the categories and specific pieces of Personal Information we have collected, the sources used, and the business purpose for collecting or sharing that information in the preceding 12 months.
- The Right to Request Deletion: You have the right to request that we delete non-exempt Personal Information that we have collected and maintained.
- The Right to Request Correction: You have the right to request that we correct inaccurate non-exempt Personal Information.
- Non-Discrimination: We will not discriminate or retaliate against you for exercising any of your CCPA rights, including denying services or charging different rates.
Instructions for Submitting a Request
- To exercise your Right to Know, Delete, or Correct, please submit a verifiable consumer request by:
- Email: member-support@navencreditunion.com
- Phone: 1-408-560-1780
Verification Process
- Members: We may verify your identity through existing authentication practices. We require re-authentication before disclosing, deleting, or correcting information.
- Non-Members: You must provide your name, address, date of birth, and SSN for processing through a third-party identity verification service. Requests for specific pieces of information or deletion also require a signed declaration under penalty of perjury.
Contacting Us
If you have any questions regarding our privacy policies or how to exercise your rights, please contact us via email: member-support@navencreditunion.com or Phone: 1-408-560-1780.