Nirvana General Privacy Policy

This General Privacy Policy describes the ways Nirvana may collect, use, and disclose your personal information in connection with products and services offered through Nirvana (collectively, the “Nirvana Services”). You accept this policy by using Nirvana Services on our website or by any other means.

If you have any financial product or service with us, including a Nirvana Membership , we will use and share any Non-Public Information (“NPI”) as defined by the Gramm-Leach-Bliley Act (“GLBA”) that we collect from or about you related to your use of that product or service in accordance with our Privacy Notice.

Furthermore, you acknowledge that the use of any credit card or deposit account offered by Coastal Community Bank, Member FDIC (“Coastal”), through Nirvana (a “Nirvana Membership”) is governed by the Account and Cardholder Agreement that is provided to you. View the Coastal Community Bank Privacy Notice.

What Does This General Privacy Policy Cover?

This General Privacy Policy covers the treatment of personally identifiable information (“Personal Information”) we gather when you use or access the Nirvana Services, and any Personal Information shared between us and any third party, including Coastal or service providers (collectively, “Third Parties”) for use in connection with Nirvana Services. By using Nirvana Services, you authorize us to review and share your information (including Personal Information) with Third Parties.

When Nirvana shares your personal information with vendors and other third party service providers (“Third Party Service Providers”) who perform functions on our behalf, we require the security and confidentiality of your information, as well as limiting their use of the information to what is reasonable and necessary to carry out their work with us and comply with applicable laws and regulations.This General Privacy Policy does not apply to Third Party Service Providers that you elect to access through the Nirvana Services or that you share information with directly. While we attempt to facilitate access only to those Third Party Service Providers that share our respect for your privacy, we cannot take responsibility for the content or privacy policies of those Third Party Service Providers. We encourage you to carefully review the privacy policies of any Third Party Service Providers you access

What Information Do We Collect and How Do We Use the Information?

The information we gather enables us to personalize, improve, and continue to operate the Nirvana Services. Below we describe in more detail the type of information we collect and how we use it.

Bank Account Information:

Registered users of Nirvana Services may provide us with access credentials (e.g., username, email, phone number, and password) that allow us to gain online access to one or more accounts that you maintain with a third party financial institution and that you choose to designate for use in connection with Nirvana Services (each, an “Authorized Bank Account”).  We work with one or more Third Party Service Providers that will securely store pursuant to industry standards any Authorized Bank Account access credentials that you provide on Nirvana Services and will access your Authorized Bank Accounts for the purposes of providing and improving Nirvana Services. You may only provide account access credentials for and authorize us to access valid accounts that you hold in your own name. You may not provide access credentials for an account that is held by a third person. You must update your Nirvana account information to reflect any change to the username or password that is associated with any Authorized Bank Account.If you choose to link your Authorized Bank Account, you authorize the use of this information to provide you with Nirvana Services. This authorization will remain in effect until you notify us that you wish to revoke this authorization, which may affect your ability to receive the Nirvana Services. The Third Party Service Providers that we work with includes Plaid Inc. (“Plaid”).  By using our Services, you grant us, Coastal, and Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from the relevant financial institution. You agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with the Plaid Privacy Policy ( ) .

Sources of Personal Information:

If you sign-up for a Nirvana Membership or otherwise provide your contact information to us, including during the application process whether that application is approved or declined, you will provide us with Personal Information that may include your name, username, password, email address, home address, and phone number. By providing us with your phone number, you authorize us to contact you via text message (SMS) at that phone number, and you thereby consent to the receipt of such messages.  You may opt-out of receiving most of these messages at any time by sending us a request at You acknowledge that opting out of receiving text messages may impact your use of the Nirvana Services. More generally, we may use your contact information to send you messages about the Nirvana Services. You may unsubscribe from some of these messages through your Account settings, although we reserve the right to contact you when we believe it is necessary, such as for account recovery purposes or suspected fraud.  In addition, as part of the Nirvana Membership application process, you may be asked to provide additional information such as your social security number, date of birth, address and annual income.  Information obtained through the application process is transmitted to Third Parties to verify your identity and to access your credit report.  

Payment and Transaction Information:

When you make payments or conduct transactions through the Nirvana Services (e.g., Nirvana Money Card), we or i2c, our third party payment and transaction processor, may collect information related to your payments and transaction, such as your payment method, account number, type, or expiration date. The use and storage of such information is governed by this General Privacy Policy and i2c’s privacy policy, available at .

Web Browser Information:

We automatically receive and record information from your web browser when you go on our website, including your IP address and cookie information. We use this information to fight fraud (including spam or malware) and also to analyze your interaction with the Nirvana Services (e.g., what links you click on).Generally, the Nirvana Services automatically collect usage information, such as the number and frequency of visits to the Nirvana Services. We may use this data in aggregate form, but not in a manner that would identify you personally. This type of aggregate data enables us and third parties authorized by us to determine how often individuals use parts of the Nirvana Services so that we can analyze and improve those services.

Email, SMS, and Push Notification Communications:

We may communicate with you about our products and services using email, SMS or other text messages (collectively, “Text Messages”) or push notifications. When we communicate with you via email, Text Message, or push notifications, we may collect information regarding such communications, such as confirmation when you open an email, read a text message, or receive a push notification. We use this information to operate and improve our customer service and other Nirvana Services. Some services such as near real-time alerts require notifications to be enabled. If at any time you do not wish to receive the benefit of such services, you can turn off notifications using the functionality made available in the browser, application, or device settings. 

Information We Receive from Third Parties:

We may collect information about you from third parties that perform services and analytics for us. Such companies may include credit bureaus, data providers, fraud detection services, and data analytics providers., as well as certain of our Third Party Service Providers and their partners. 

Information We Receive from Browsers:

Cookies are pieces of text that are stored on your computer or device when you access a website. Your browser stores cookies in a manner associated with each website you visit. We use cookies to enable our servers to recognize your web browser and tell us how and when you visit and use the Nirvana Services.Most browsers have an option for turning off the cookie feature, which, depending on your browser, may prevent your browser from accepting new cookies or allow you to choose whether to accept each new cookie.  We recommend that you leave cookies active, because they enable you to take full advantage of the Nirvana Services’ features.

Information Related to Advertising and the Use of Web Beacons; Interest-Based Advertisements:

We may serve advertisements, and also allow third party digital marketing partners, including third party advertising servers, advertising agencies, advertising networks, advertising exchanges, advertising vendors and research firms, to serve advertisements through the Nirvana Services. These advertisements, which may be both for our own products and services and for third party products and services that we think might be of interest to you, may be targeted to users who fit certain general profile categories or display certain preferences or behaviors (“Interest-Based Ads”). Information for Internet-Based Ads (including Personal Information) may be provided to us by a user, or derived from the usage patterns of particular users on the Nirvana Services and/or services of Third Party Service Providers. Such information may be gathered through tracking users’ activities across time and unaffiliated properties. To accomplish this, we or our service providers may deliver a pixel (known as a “web beacon”) from a digital marketing partner to you through the Nirvana Services. Web beacons allow our digital marketing partners to provide anonymized, aggregated auditing, research and reporting for us and for advertisers. Web beacons also enable our digital marketing partners to serve targeted advertisements to you when you visit other websites, and to view, edit or set their own cookies on your browser, just as if you had requested a web page from their site. We do not provide Personal Information to any digital marketing partners for use outside of Nirvana Services. We may use analytics service providers to analyze how you interact and engage with the Nirvana Services and our advertisements, so we can learn and make enhancements to offer you a better experience. Some of these entities may use cookies, web beacons, and other technologies to collect information about your use of the Nirvana Services and other websites, which may include tracking activity across time and unaffiliated properties, non-sensitive including your IP address, web browser, pages viewed, non-sensitive text entered, mouse movements, time spent on pages, links clicked and conversion information. Information from analytics service providers may be used by us and others to, among other things, analyze and track data, determine the popularity of certain content, deliver advertising and content targeted to your interests in the Nirvana Services and other websites and better understand your online activity. For example, Google, Inc. (“Google”) uses cookies in connection with its Google Analytics services. Google’s ability to use and share information collected by Google Analytics about your visits to the Nirvana Services is subject to the Google Analytics Terms of Use and the Google Privacy Policy. You have the option to opt out of Google's use of cookies by visiting the Google advertising opt-out page at or the Google Analytics Opt-out Browser Add-on at Through the Digital Advertising Alliance (“DAA”) and Network Advertising Initiative (“NAI”), several media and marketing associations have developed an industry self-regulatory program to give consumers a better understanding of and greater control over ads that are customized based on their online behavior across different websites. To make choices about Interest-Based Ads from participating third parties, including to opt out of receiving behaviorally targeted advertisements from participating organizations, please visit the DAA’s or NAI’s consumer opt out pages, which are located at and, respectively.

Aggregate and De-identified Information:

We collect statistical information about both unregistered and registered users that is not Personal Information and cannot be tied back to you, your Account or your web browser (“Aggregate and De-identified Information”). Some of this information is derived from Personal Information. We may use Aggregate and De-identified Information for various business purposes where permissible under applicable laws and regulations, including for analytics or to develop or improve our services and marketing. We may share this Aggregate and De-identified Information with Third Party Service Providers for their business purposes. Third Party Service Providers may also share with us non-private, aggregated, or otherwise non-Personal Information about you that they have independently developed or acquired. We may also use and share Aggregate and De-identified Information for research, including research conducted by government entities, non-profit entities, and academic institutions. This may involve publishing findings or combining Aggregate and De-identified Information with other data sets, but such information will not be shared in a way that allows you or any other person to be personally identified.

How, and With Whom, Is My Information Shared?

Information Disclosed for Our Everyday Business Purposes:

We share information about you for our everyday business purposes, such as to process your application, assist in underwriting, process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus.

Information Disclosed for Our Marketing Purposes:

We share information about you for our marketing purposes to offer products and services to you.

Information Disclosed Pursuant to Business Transfers:

If we decide to buy or sell assets, user information is typically one of the transferred business assets. Moreover, if we (or substantially all of our assets) were acquired, or if we go out of business or enter bankruptcy, user information would be one of the assets that may be transferred or acquired by a third party. Any acquirer of us or our assets may continue to use your Personal Information as set forth in and in accordance with this policy.

Information Disclosed for Our Protection and the Protection of Others:

We reserve the right to access, read, preserve and disclose any information as we reasonably believe is necessary to (i) satisfy any applicable law, regulation, legal process or governmental request, (ii) enforce this General Privacy Policy and our Terms of Use, including investigation of potential violations hereof, (iii) detect, prevent or otherwise address fraud, security or technical issues, (iv) respond to user support requests, or (v) protect our rights, property or safety, our users and the public. This includes exchanging information with other companies and organizations for fraud protection and spam/malware prevention.

Information We Share With Your Consent:

In addition to the disclosures described in this General Privacy Policy, we may also share your information, which may include your Personal Information, in additional ways, if you consent.We do not sell or share your Personal Information with third parties for their own commercial uses without your consent, except as set forth in the “Information Disclosed Pursuant to Business Transfers” section above.

Is Information About Me Secure?

We protect your personal information from unauthorized access and use by maintaining physical, electronic, and procedural safeguards in compliance with applicable law. These measures include computer safeguards and secured files and buildings. We authorize our employees to access your information only when they need it to do their work, and we require companies that work for us to protect your information. However, we cannot guarantee the security of any information. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time.

What Information of Mine Can I Access?

If you are a registered user, you can view information associated with your Account by logging into your Account.  In addition, you can access and delete cookies through your web browser settings, as detailed above.