CSB understands how important privacy and security are to you not only in your banking, but also in your everyday life. We do our best to maintain the highest levels of security to protect your information. We also want to arm you with current information that you can use to keep up with cyber criminals.

You can also find a wealth of free resources by visiting www.onguardonline.gov 


Privacy

CSB and its associates and CSB Financial Advisors are committed to maintaining the confidentiality of our customer information, as stated here in our Privacy Policy.

You may add choose to add your name to CSB's Do Not Contact list. By adding your name to the Do Not Contact list, you will no longer receive marketing or promotional mailings from Community State Bank or its affiliated companies including, promotional offers, information on merchant programs and Bank newsletters. Please note that you will still receive communication form the Bank that is required by state and federal regulations.

Digital Privacy and Cookies Policy
Updated: May 10, 2019

Introduction and scope of policy

The Digital Privacy and Cookies Policy (“Policy”) applies to your interaction with Community State Bank or any of its subsidiaries (collectively “we,” “us,” “our”), at any online or mobile site or application that we own and control (“Site”), unless a different online and/or mobile policy is posted at a particular site, or is made available to you and by its terms supplants this Policy. Other privacy policies may also apply in addition to the terms of this Policy. As examples, certain additional Community State Bank privacy-related policies and notices are posted on the bankcsb.com. These include Community State Bank Consumer Privacy Notice, which also applies to U.S. customers and consumers as described in that notice and various international privacy policies, which apply to information collected by us outside of the U.S. as described in those policies. You may also receive an additional privacy notice in connection with your use of a particular product or relationship with a specific business. For example, Trust or fiduciary accounts for which Community State Bank is the trustee or service provider, including employer-sponsored retirement accounts, are protected under special rules of confidentiality. Information on these accounts is not shared for marketing purposes without specific consent. This Policy also explains certain data use and data protection functionalities and practices of our online ads, such as banner ads, on third party sites. Please note that where we have another type of presence on a site owned by a third party, such as a page or handle on a social media site, that third party’s privacy policy and terms of use, rather than this Policy, will govern, unless specifically stated otherwise.

Agreement to policy

By using a Site or interacting with a Community State Bank advertisement or page or account on a third party site, you consent to this Policy, including your consent to our use and disclosure of information about you in the manner described in this Policy.

Gathering, using, and sharing information

Types of information

You may interact with us in a variety of ways online, including through a mobile device. We may offer sites or applications that permit browsing and do not require registration. We may also offer the ability to enroll, register or access your accounts online. Information that we may collect about you through online interaction includes information that you input, such as your name, address, email address, other contact information; data resulting from your activity, such as transaction information; and location information. We may also gather additional information, such as the type of device and browser you are using, the IP address of your device, information about your device’s operating system, and additional information associated with your device. We may also gather information collected through cookies, tags, and other technologies, as described further below.

About “cookies” and Ad Choices on third party sites

Cookies are pieces of data stored on your device. Browser cookies are assigned by a web server to the browser on your device. When you return to a site you have visited before, your browser gives this data back to the server. Mobile applications may also use cookies.

We use cookies and information gathered through their use to make your experience with Community State Bank and certain other sites richer and more personalized based on the products, services, or other interaction you have with us and other sites. Information gathered through use of cookies may be used to make offers to you via online ads, email, U.S. mail, or telephone, subject to the privacy preferences you have on file with Community State Bank. (Privacy preferences for employer-sponsor retirement accounts default to no marketing, solicitation or sharing for marketing purposes without specific consent.) We also use cookies, sometimes in conjunction with service providers, in online advertising either on our own Site or on third party sites to help determine which of our advertisements are most likely to appeal to you. We respect consumers’ ability to exercise choice in receiving these types of ads on third party sites. We honor your choice as follows: For this type of advertising placed on third party sites, we participate in the program utilizing the “Unsubscribe” link. If you receive an ad delivered on a third party site in part based on information gathered through the use of cookies, you may opt out of receiving such ads by clicking the “Unsubscribe” link and following the instructions or by visiting http://www.aboutads.info/choices/. This “unsubscribe” link works via cookies, so if you delete cookies, use a different device, or change web browsers, you will need to opt out again. Please note that we respect your choice via participation in the Bank advertising campaigns. Information that we collect about you from one particular browser or device may be used to provide advertising or collect information on another browser or device. It may also be transferred to a third

party for advertising or information collection on behalf of Community State Bank. Please note that your choice to “Unsubscribe” on a particular browser or device will apply only to the collection and use of information from that particular browser or device. “Unsubscribing” on a particular device will not “unsubscribe” out of information collection on other devices, nor will it limit cross device sharing on those other devices. Industry standards are currently evolving and we may not separately respond to or take any action with respect to a “do not track” configuration set in your internet browser. The “unsubscribe” link does not apply to transactional communications from (Bank Name) in connection with providing services on an account.

Other parties that may collect information about your web browsing behavior when you use our Site are generally limited to service providers who may only use any information collected to provide services and marketing for us and not to provide services or advertising for any other party. Note, however, that we also provide certain widgets or tools on our sites, such as tools that allow web surfers to easily share information on another platform, such as a social media platform. At other times, information from a third party may be embedded on our site, such as a map or information streaming from another site, including communications streaming from a third party social media platform. These widgets, tools, and informational items often function through the use of third party cookies utilized by the third party site, such as the social media platform. As a result, these third parties may have access to information about your web browsing on the pages of our Site where these widgets, tools, or information are placed. You may wish to review information at third party sites, such as social media platforms where you have an account, to determine how these third parties treat data that they obtain through the use of cookies.

We also use cookies for purposes such as maintaining continuity during an online session; gathering data about the use of our site; monitoring online promotions; and anti-fraud and information security purposes.

Do you have to accept cookies?

You may be able to set your browser to reject browser cookies. However, if you choose to reject cookies, you cannot access your accounts online with Community State Bank. Therefore, if you set your browser options to disallow cookies, you will limit the functionality we can provide when you visit our Site. The latest versions of internet browsers provide cookie management tools, such as the ability to delete or reject cookies. We recommend that you refer to information supplied by browser providers for more specific information, including how to use these tools.

Additional cookies

Cookies is a term also used to describe other locally stored objects, such as cookies stored in an Adobe folder on your device. These cookies will not be deleted when you clear cookies from your browser. We may use this technology for purposes such as information security and fraud prevention. We may use this technology for online behavioral advertising purposes. Please refer to information provided by Adobe for information on how to disable and control Flash objects. If you choose those options, you may limit the functionality we can provide when you visit our Site.

Additional technologies. We may also use additional technologies such as pixel tags, web beacons, and clear GIFs, and may permit our third party service providers to use these technologies. We use these technologies for purposes such as measuring the effectiveness of our advertisements or other communications, determining viewing and response rates, and determining which offers to present to you on our own or on third party sites.

Using information. In addition to the uses described above, we use information for purposes as allowed by law such as: servicing; communicating with you; improving our Site, products, or services; legal compliance; risk control; information security; anti-fraud purposes; marketing or personalizing the presentation of our products and services to you; tracking website usage, such as number of hits, pages visited, and the length of user sessions in order to evaluate the usefulness of our sites; and using read-receipt notifications in our email communications.

Sharing

We may share information with service providers with whom we work, such as data processors and companies that help us market products and services to you. When permitted or required by law, we may share information with additional third parties for purposes including response to legal process. As applicable, please see the additional privacy policies referenced above, such as the Community State Bank Consumer Privacy Notice, for more information on how we may share information with affiliates and third parties.

Children’s privacy

From our web pages, we do not knowingly collect personal information from individuals under the age of 13 without obtaining verifiable consent from their parents or legal guardians. We request that such individuals do not provide personal information through the services.

For more information about the Children’s Online Privacy Protection Act (COPPA), visit the FTC website: www.ftc.gov Dialog.

Policy updates and effective date

If we make updates to this Policy, we will update the Policy with the changes and revise the “date of most recent update” posted at the top of this Policy. Any updates to the Policy become effective when we post the updates on the Site. Your use of the Site following the update to the Policy means that you accept the updated Policy.

Mobile Privacy Policy
Last Updated: August 28, 2023

Personal Online Banking App (the “App”) – helps you control your debit cards through your mobile device, making it easy to manage your finances on the go.

The App allows you to:

• get real-time balances for your accounts

• manage your money

• view your transactions and statements

• make transfers

• pay your bills and manage billers

• deposit a check

• receive alerts

• manage cards

This Privacy Policy, in combination with other relevant privacy notices that we provide to you (e.g., pursuant to financial privacy laws), inform you of the policies and practices regarding the collection, use and disclosure of any personal information that we and our service providers collect from or about users in connection with the App’s website and mobile application (the “Services”).

THE TYPES OF INFORMATION WE COLLECT IN THE APP

Through your use of the Services, we may collect personal information from you in the following ways:

(a) Personal Information You Provide to Us.

• We may collect personal information from you, such as your first and last name, address, e-mail, telephone number, and social security number when you create an account.

• We will collect the financial and transaction information necessary to provide you with the Services, including account numbers, payment card expiration date, payment card identification, verification numbers, and transaction and payment history.

• If you provide feedback or contact us via email, we will collect your name and email address, as well as any other content included in the email, in order to send you a reply.

• We also collect other types of personal information that you provide voluntarily, such as any information requested by us if you contact us via email regarding support for the Services.

(b) Personal Information Collected from Third Parties. We may collect certain information from identity verification services and consumer reporting agencies, including credit bureaus, in order to provide some of our Services.

(c) Personal Information Collected Via Technology. We and our service providers may automatically log information about you, your computer or mobile device, and your interaction over time with our Services, our communications and other online services, such as:

• Device data, such as your computer’s or mobile device’s operating system type and version, manufacturer and model, browser type, screen resolution, RAM and disk size, CPU usage, device type (e.g., phone, tablet), IP address, unique identifiers, language settings, mobile device carrier, radio/network information (e.g., WiFi, LTE, 3G), and general location information such as city, state or geographic area.

• Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, the website you visited before browsing to the Service, navigation paths between pages or screens, information about your activity on a page or screen, access times, and duration of access.

• Cookies, which are text files that websites store on a visitor’s device to uniquely identify the visitor’s browser or to store information or settings in the browser for the purpose of helping you navigate between pages efficiently, remembering your preferences, enabling functionality, and helping us understand user activity and patterns.

• Local storage technologies, like HTML5 and Flash, that provide cookie-equivalent functionality but can store larger amounts of data, including on your device outside of your browser in connection with specific applications.

• Web beacons, also known as pixel tags or clear GIFs, which are used to demonstrate that a webpage or email was accessed or opened, or that certain content was viewed or clicked.

• Location Information. If you have enabled location services on your phone and agree to the collection of your location when prompted by the Services, we will collect location data when you use the Services even when the app is closed or not in use; for example, to provide our fraud detection services. If you do not want us to collect this information, you may decline the collection of your location when prompted or adjust the location services settings on your device.

HOW WE USE YOUR INFORMATION COLLECTED IN THE APP

(a) General Use. In general, we use your personal information collected through your use of the Services to respond to your requests as submitted through the Services, to provide you the Services you request, and to help serve you better. We use your personal information, in connection with the App, in the following ways:

• facilitate the creation of, and secure and maintain your account;

• identify you as a legitimate user in our system;

• provide improved administration of the Services;

• provide the Services you request;

• improve the quality of experience when you interact with the Services;

• send you administrative e-mail notifications, such as security or support and maintenance advisories; and

• send surveys, offers, and other promotional materials related to the Services.

(b) Compliance and protection. We may use your personal information to:

• comply with applicable laws, lawful requests and legal process, such as to respond to subpoenas or requests from government authorities;

• protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims);

• audit our internal processes for compliance with legal and contractual requirements and internal policies;

• enforce the terms and conditions that govern the Service; and

• prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft.

(c) Creation of Non-Identifiable Data. The App may create de-identified information records from personal information by excluding certain information (such as your name) that makes the information personally identifiable to you. We may use this information in a form that does not personally identify you to analyze request patterns and usage patterns to enhance our products and services. We reserve the right to use and disclose non-identifiable information to third parties in our discretion.

DISCLOSURE OF YOUR PERSONAL INFORMATION

We disclose your personal information collected through your use of the Services as described below.

(a) In Accordance with Our Other Privacy Notices. Other than as described in this Privacy Policy in connection with the App, this Privacy Policy does not apply to the processing of your information by us or third parties with whom we share information.

(b) Third Party Service Providers. We may share your personal information with third party or affiliated service providers that perform services for or on behalf of us in providing the App, for the purposes described in this Privacy Policy, including: to provide you with the Services; to conduct quality assurance testing; to facilitate the creation of accounts; to optimize the performance of the Services; to provide technical support; and/or to provide other services to the App.

(c) Authorities and Others. Regardless of any choices you make regarding your personal information, The App may disclose your personal information to law enforcement, government authorities, and private parties, for the compliance and protection services described above.

LINKS TO OTHER SITES

The App may contain links to third party websites. When you click on a link to any other website or location, you will leave the App and go to another site and another entity may collect personal and/or anonymous information from you. The App’s provision of a link to any other website or location is for your convenience and does not signify our endorsement of such other website or location or its contents. We have no control over, do not review, and cannot be responsible for, these outside websites or their content. Please be aware that the terms of this Privacy Policy do not apply to these outside websites. We encourage you to read the privacy policy of every website you visit.

YOUR CHOICES REGARDING YOUR INFORMATION

You have several choices regarding use of information on the Services.

(a) How We Respond to Do Not Track Signals. Some web browsers transmit “do not track” signals to the websites and other online services with which your web browser communicates. There is currently no standard that governs what, if anything, websites should do when they receive these signals. We currently do not take action in response to these signals. If and when a standard is established, we may revise its policy on responding to these signals.

(b) Access, Update, or Correct Your Information. You can access, update or correct your information by changing preferences in your account. For additional requests, please contact us.

(c) Opting Out of Email or SMS Communications. If you have signed-up to receive our email marketing communications, you can unsubscribe any time by clicking the "unsubscribe" link included at the bottom of the email or other electronic communication. Alternatively, you can opt out of receiving marketing communications by contacting us at the contact information under "Contact Us" below. If you provide your phone number through the Services, we may send you notifications by SMS, such as provide a fraud alert. You may opt out of SMS communications by unlinking your mobile phone number through the Services.

(d) Opting Out of Location Tracking. If you initially consented to the collection of geo-location information through the Services, you can subsequently stop the collection of this information at any time by changing the preferences on your mobile device. Please note, however, that if you withdraw consent to our collection of location information, you may no longer be able to use some features of the App.

SAFEGUARDS AND RETENTION

We implement reasonable administrative, technical and physical measures in an effort to safeguard the information in our custody and control against theft, loss and unauthorized access, use, modification and disclosure. Nevertheless, transmission via the internet is not completely secure and we cannot guarantee the security of your information.

A NOTE ABOUT CHILDREN

The Services are not directed towards individuals under the age of 18, and we do not, through the App, intentionally gather personal information about visitors who are under the age of 18. If a child under 18 submits personal information to us through the App and we learn that the personal information is the information of a child under 18, we will attempt to delete the information as soon as possible.

PRIVACY POLICY UPDATES

This Privacy Policy is subject to occasional revision. We will notify you of any material changes in its collection, use, or disclosure of your personal information by posting a notice on the Services. Any material changes to this Privacy Policy will be effective thirty (30) calendar days following notice of the changes on the Services. These changes will be effective immediately for new users of the Services. If you object to any such changes, you must notify us prior to the effective date of such changes that you wish to deactivate your account. Continued use of the Services following notice of any such changes shall indicate your acknowledgement of such changes.

CONTACT US

If you have any questions or complaints about this Privacy Policy or The App’s data collection or processing practices, or if you want to report any security violations to The App, please contact us.


Credit Reporting Agency Information

Know your Credit Score Help protect yourself from Identity Theft

Equifax PO Box 740241 Atlanta, GA 30374-0241 www.equifax.com 800-685-1111

Experian PO Box 2002 Allen, TX 75013 www.experian.com 888-397-3742

TransUnion PO Box 390 Springfield, PA 19064-0390 www.transunion.com 800-916-8800

Fraud Management Information/Resources

Fraud Management for Debit Cards

Protecting you from unauthorized use of your debit card is a top priority at Community State Bank. To that end, we are partnering with Fiserv, our debit card administrator, to implement a fraud monitoring system, called Debit Card Fraud Management. This service will help monitor your bank account for fraudulent debit card activity. If suspicious activity is detected on the account associated with your debit card (i.e. out-of-state purchases or uncharacteristically high charges), you will be contacted by Community State Bank or by a Fiserv fraud specialist, calling on our behalf, to verify those transactions.

We would like to ensure that we can reach you promptly if fraudulent activity is suspected. If at any time your contact information changes, please notify your personal banker, teller or Customer Care at 515-331-3100. As always, we keep your personal information strictly confidential. Please remember that we will NOT ask for your debit card number or personal identification number (PIN) to verify your identity. Remember to use caution when providing your debit card information, and contact us immediately if you suspect your debit card has been stolen or compromised.

Fraudulent Check Scam

If you think you may have become victimized by a fraudulent check scam, contact the following agencies:

  • Contact the bank who issued the check directly to report receipt of the check and to verify authenticity. Do not use the telephone number provided on the check – this number is probably not associated with the bank, but rather with the scam artist. To locate a bank’s mailing address, you can check the FDIC’s Web site at: http://www.fdic.gov/
  • Federal Trade Commission (FTC): by telephone at 1-877-FTC-HELP or file an electronic complaint via their Internet site at http://www.ftc.gov
  • The Iowa Attorney General at: https://www.iowaattorneygeneral.gov
  • For Internet Scams - Federal Bureau of Investigation (FBI) Internet Fraud Complaint Center: http://www.ic3.gov
  • Mail-based scams-U.S. Postal Inspector Service at http://www.usps.com

Important Information - Preventing a Business Email Compromise

Other Useful Resources

At CSB, we know you need to feel your financial information is secure from theft. We use the maximum level of security offered through our systems to make sure your accounts are safe. At CSB, we know the importance of staying abreast of the latest scam warnings. Protect yourself from this activity by checking this page of our website for recent warnings.