Privacy Policy
Last updated: January 2025
1. Introduction
BondBricks ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information in accordance with applicable U.S. federal and state privacy laws including CCPA, CPRA, and other state regulations.
2. Information We Collect
We collect the following types of information:
Personal Information
- Full name, date of birth, and contact details
- Email address and phone number
- Residential address and proof of address documents
- Government-issued ID (driver's license, passport)
- Social Security Number (SSN) or Tax ID for tax reporting purposes
Financial Information
- Bank account details for payments and withdrawals
- Investment history and portfolio holdings
- Transaction records and payment information
- Source of funds declarations
Technical Information
- IP address, browser type, and device information
- Usage data, pages visited, and time spent on platform
- Cookies and similar tracking technologies
3. How We Use Your Information
We use your personal information for the following purposes:
- To verify your identity and comply with KYC/AML regulations
- To facilitate your investments and transactions through our licensed financial partners who process all regulated activities
- To coordinate interest payment information with Prime Trust, who distributes all payments
- To provide customer support and respond to inquiries
- To send important account notifications and updates
- To comply with legal and regulatory obligations
- To prevent fraud and ensure platform security
- To improve our services and user experience
- To send marketing communications (with your consent)
4. Information Sharing and Disclosure
We may share your information with:
- SEC and other regulatory authorities as required by law
- Licensed financial partners (US Bond Partners, Prime Trust) who conduct regulated activities including bond issuance, custody, and payment distribution
- Payment processors and financial institutions
- Identity verification service providers (Onfido)
- Tax authorities (IRS (Internal Revenue Service)) for tax reporting
- Legal and professional advisors
- Service providers who assist with platform operations
We will never sell your personal information to third parties for marketing purposes.
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption of data in transit and at rest
- Secure authentication and access controls
- Regular security audits and penetration testing
- Staff training on data protection
- Incident response and breach notification procedures
6. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services to you
- Comply with legal and regulatory requirements (minimum 7 years for financial records)
- Resolve disputes and enforce our agreements
7. Your Privacy Rights
Under applicable privacy laws, you have the right to:
- Know what personal information is collected about you
- Know whether your personal information is sold or disclosed
- Opt-out of the sale of your personal information
- Access your personal information
- Request deletion of your personal information (subject to legal exceptions)
- Receive equal service and pricing even if you exercise your privacy rights
To exercise these rights, contact us at privacy@bondbricks.com
8. State-Specific Privacy Rights (US Residents)
California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: You can request information about the personal information we have collected about you in the past 12 months
- Right to Delete: You can request deletion of your personal information (subject to certain legal exceptions)
- Right to Correct: You can request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: You have the right to opt-out of the "sale" or "sharing" of your personal information for targeted advertising
- Right to Limit Use of Sensitive Personal Information: You can request that we limit use of your sensitive personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
Do Not Sell or Share My Personal Information: We do not sell your personal information in the traditional sense. However, like many platforms, we use third-party analytics and advertising tools that may constitute "sharing" under California law.
To exercise your "Do Not Sell" or "Do Not Share" rights, visit: Do Not Sell My Personal Information
Virginia Residents (VCDPA)
Virginia residents have rights under the Virginia Consumer Data Protection Act (VCDPA) including:
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to data portability
- Right to opt-out of targeted advertising, sale of personal data, and profiling
Colorado Residents (CPA)
Colorado residents have rights under the Colorado Privacy Act (CPA) including:
- Right to access, correct, and delete personal data
- Right to data portability
- Right to opt-out of targeted advertising and sale of personal data
Connecticut Residents (CTDPA)
Connecticut residents have rights under the Connecticut Data Privacy Act (CTDPA) including:
- Right to confirm whether we process personal data
- Right to access, correct, and delete personal data
- Right to data portability
- Right to opt-out of targeted advertising, sale, and profiling
Utah Residents (UCPA)
Utah residents have rights under the Utah Consumer Privacy Act (UCPA) including:
- Right to access and delete personal data
- Right to data portability
- Right to opt-out of targeted advertising and sale of personal data
How to Exercise Your Rights:
To exercise any of these state-specific rights, please contact us at:
Email: privacy@bondbricks.com
Subject Line: "[Your State] Privacy Rights Request"
Response Time: Within 45 days of verified request
Data Breach Notification: In the event of a data breach affecting your personal information, we will notify you within 72 hours of discovering the breach, as required by applicable state and federal law.
9. Cookies and Tracking
We use cookies and similar technologies to:
- Remember your login session
- Analyze platform usage and performance
- Personalize your experience
- Detect and prevent fraud
You can control cookies through your browser settings, but disabling cookies may limit platform functionality. For detailed information about the cookies we use, their purpose, and how to manage them, please see our Cookies Policy.
10. International Data Transfers
Your personal information is stored on secure servers located in the United States. We may transfer data to service providers in other countries, but only with appropriate safeguards in place to ensure your data remains protected in accordance with applicable privacy laws.
11. Children's Privacy
BondBricks is not intended for use by individuals under 18 years of age. We do not knowingly collect information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the platform. The updated policy will be effective upon posting.
13. Contact Us
For privacy-related questions or complaints, contact:
Privacy Officer
BondBricks
Email: privacy@bondbricks.com
Phone: +1 (855) BONDS-US
If you are not satisfied with our response, you may lodge a complaint with the Federal Trade Commission (FTC) or your state attorney general at https://www.ftc.gov