Skip to main content

Zable California Consumer Privacy Notice

Last Updated: February 1, 2026

Zendable, Inc. and its affiliates ("Zable," "we," or "us") provide this notice to California residents ("you") pursuant to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

Scope: Financial vs. Consumer Data

Important: Most of the data Zable collects is "nonpublic personal information" (e.g., loan balances, credit scores, repayment history) governed by the federal Gramm-Leach-Bliley Act (GLBA). This financial data is exempt from most CCPA requirements because such data is governed by specific financial information privacy laws.

This Notice Applies To: Data collected outside of that financial relationship, such as marketing data, website visitor activity (cookies), and job applicant data. For job applicants, please see our Candidate Privacy Policy.

This Privacy Notice does not apply to personal information that is protected under the Gramm-Leach-Bliley Act, a federal financial privacy law, and the California Financial Information Privacy Act, a California-equivalent financial privacy law, as set out in our Consumer Privacy Notice and Privacy Policy.

Notice at Collection

In the past 12 months, we have collected the following categories of Personal Information (PI). We have updated this list to include specific tracking technologies and inference data used by our industry peers.

Category Examples of Data Collected and Purpose Retention Period
Characteristics of protected class Age is used to verify identity and being of legal age to enter into a contract. Receipt of public assistance can be self disclosed as income. Other data and factual information are used for self-tests as allowed under 12 CFR 1002.15 Duration of account + 7 years.
Commercial Information Our history together, services provided or discussed, payment information such as bank account or wiring instructions, and your credit history, credit scores and other information provided by consumer reporting agencies are used to review credit worthiness and process payments. Duration of account + 7 years.
Identifiers Name, physical address, email, phone number, unique device identifiers, social security number, documents that verify your identity such as your driver's license or passport, and social media handles are used to verify identity. Duration of account + 7 years.
Sensitive PI Social Security number, driver's license, passport number, text and email communications, and biometric data (facial geometry for ID verification), geolocation (see below) are used to verify identity. Biometrics: Deleted within 3 years of account closure.
Internet Activity Browsing history, search history, and Session Replay data (mouse movements, clicks, scrolls, and keystrokes, which are used to debug errors). Until the session data is no longer needed for analytics or debugging.
Geolocation Location data derived from device signals. Retained only as long as necessary for fraud prevention.
Inferences Profiles reflecting your creditworthiness and predispositions to tailor marketing offers. Duration of active marketing relationship.
Professional Info Job title, employer, income, and consumer provided tax returns, W-2, and pay stub (in some instances) to verify credit worthiness. Duration of account + 7 years.

Sources of Information

We collect this information from:

  • You Directly: Applications, forms, and customer support chats.
  • Automated Technologies: Cookies, pixels, and session replay tools on our website.
  • Third Parties: Other financial institutions or information aggregators, credit bureaus, lead generators, marketing partners, Data Analytics Providers, Third-party websites, such as social media websites.
  • Our website and mobile applications.

We do not collect, sell, or share the personal information of consumers under 16 years of age.

How We Use and Disclose Your Information

We use your information in the following ways:

  • Complete the transaction for which the personal information was collected, provide a good or service requested by you, or reasonably anticipated by you within the context of our ongoing business relationship with you, or otherwise perform a contract between us and you.
  • Auditing related to counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards.
  • Helping to ensure security and integrity to the extent the use of the consumer's personal information is reasonably necessary and proportionate for these purposes.
  • Debugging to identify and repair errors that impair existing intended functionality.
  • For short-term, transient use, including, but not limited to, non-personalized advertising shown as part of your current interaction with us.
  • Performing services on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of the business.
  • Providing advertising and marketing services, except for cross-context behavioral advertising, to you.
  • Undertaking internal research for technological development and demonstration.
  • Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business.
  • To enable solely internal uses that are reasonably aligned with your expectations based on our relationship and compatible with the context in which you provided the information.
  • To comply with a legal obligation.
  • To advance our commercial or economic interest not otherwise identified above.

We do not sell your personal information for monetary value. However, we "share" information with advertising networks for cross-context behavioral advertising, which is considered a "sale" under California law.

We disclose the following categories for business purposes:

  • Service Providers: We share Identifiers, Sensitive PI, and Professional Info with vendors for payment processing and fraud detection.
  • Advertising Partners: We share Internet Activity and Inferences with partners (e.g., Google, Meta) for cross-context behavioral advertising so that you are shown relevant Zable ads.
  • AI & Automated Processing: We use Artificial Intelligence to analyze fraud risks, for servicing and provide chatbot support, including sensitive personal information such as social security numbers and geolocation. We contractually prohibit our AI vendors from using your data to train their own non-Zable models.

Your California Privacy Rights

You have the following rights regarding your non-GLBA personal information:

  • Right to Know and Access: Right to know and request the categories and specific pieces of PI we have collected, used, and shared about you.
  • Right to Delete: Request deletion of your PI (subject to legal exceptions, such as maintaining records for bank audits).
  • Right to Correct: Request correction of inaccurate PI we hold about you.
  • Right to Opt-Out of "Sharing/Selling": You may opt out of having your data shared for targeted advertising.
    • How: Click "Your Privacy Choices" in our footer or enable the Global Privacy Control (GPC) signal in your browser. We treat GPC signals as a valid opt-out request.
  • Right to Limit Use of Sensitive PI: We only use Sensitive PI (like SSN or Biometrics) for necessary business purposes (e.g., fraud prevention, identity verification) and not for inferring characteristics for marketing; therefore, we do not offer a "Limit Use" opt-out as permitted by the CPRA.
  • Right to Nondiscrimination/Retaliation: We cannot discriminate or retaliate against you if you exercise your rights under the CCPA.

Submitting a Request & Appeals

  • Online: Visit our Privacy Center
  • Email: privacy@zable.com
  • Phone: 1-844-779-2253
  • Business Hours: Monday through Friday 8am to 9pm EST

To protect your privacy, we will verify your identity (e.g., matching your email or requesting a declaration) before processing requests.

Right to Appeal: If we deny your request, you may appeal by replying to our denial email. We will provide a written explanation of our decision within 45 days.

Authorized Agents

You may designate an authorized agent to make a request on your behalf. Agents must provide proof of signed authorization. To verify agent requests, we may contact you directly to confirm permission.

Contact Us

For questions specific to this California Notice:

Zendable Privacy Team
Email: privacy@zable.com
Address: Zendable, Inc., 3100 Clarendon Blvd, Suite 200, Arlington, VA 22201