Privacy Policy

Welcome to Ride in Tandem, Inc. (“Tandem”, “us” or “we”) and our services made available through the websites on which a link to this Privacy Policy is displayed, including www.usetandem.com (the “Site”), the downloadable application through which this Privacy Policy is made available (the “App,” together with the Site, the “Service”).

This Privacy Policy describes the information that we collect about you, how we use and share your information, and the steps we take to protect your information.

This Privacy Policy is incorporated into and is subject to the Tandem Terms of Service. By using the Service, you agree to the privacy practices described in this Privacy Policy, to our Terms of Service, and any other policies made available by us to you. Capitalized terms that are not defined in the Privacy Policy have the meaning given to them in the Tandem Terms of Service.

Tandem is intended only for users in the United States, and its use is governed by US law.

Information We Collect

A. User-Provided Information

When you use the Service, you may provide and we collect information, such as your name, email address, mailing address, phone number, and other information.

The categories of information we collect include:

● Contact Data, including your name, email address, mailing address, and phone number.

● Identifiers, including your social security number.

● Account Credentials, including your password, password hints, and information for authentication and account access.

● Financial Information, including your current income level, current expenses, investable assets, and other financial information.

● Profile Data, including your interests, inferences, and preferences.

● Content, including content within any messages you send to us (such as when contacting customer support or asking a question).

B. User-Provided Information Through Plaid and Other Third Party Integrations

Our Service may allow you to connect your third party accounts, including your financial accounts, to your Tandem account. We use Plaid and other third party integrations to provide this functionality to you. In order to connect your third party accounts to your Tandem account, you must expressly authorize such connection when registering your Tandem account or at a later time through your account settings. You may terminate this connection at any time through your account settings.

When you connect your third party accounts to your Tandem account, you give Tandem and the third party integration the authority to act on your behalf to access and transmit your information from the relevant bank or other entity that provides your accounts. The information we receive from the entities that maintain your accounts varies depending on the information made available by those entities. Information may include ACH authentication information (account and routing numbers), identity verification information and account balance details.

Please note that Tandem is not responsible for any third party’s privacy practices and we strongly encourage you to review their privacy policies before connecting your third party accounts with your Tandem account. Plaid’s privacy policy is available at https://plaid.com/legal. You are responsible for the accuracy and completeness of the data provided through any third parties you connect to the Service.

C. Transaction Data

We currently use Fidel and the Payment Card Networks (Visa, Mastercard and AMEX) to monitor card transactions for your participation in the Tandem program. Your agreement to the various Tandem Terms of Use (Terms) authorize Fidel and the Payment Card Networks to monitor the transactions made with your registered eligible payment cards via the Tandem Platform. The data collected from Fidel includes your registered card identifier, merchant, transaction date/time and amount.

Notwithstanding anything to the contrary in the Terms or Privacy Policy, Tandem and its Third Party Service Providers (including Fidel) will use transaction information solely as follows:

● To create a record of the transaction data and thereafter maintain and use data in connection with operating the Platform;

● To provide information in order to respond to a request from government authority or a payment organization involved in a transaction with you or a merchant. You authorize the sharing, exchange and use of transaction data described above and herein by and among Tandem and Tandem’s Third Party Service Providers and applicable Payment Card Networks

By registering a payment card in connection with transaction monitoring, you authorize Tandem to share your payment card information with the Payment Card Networks so it knows you enrolled and participating in Tandem’s Personal Finance Management Platform. You authorize the Payment Card Networks to monitor transactions on your registered card(s) in order to enable your usage of real time transaction data for all transactions made on an enrolled card linked through the Tandem Platform. You may opt-out of transaction monitoring on the payment card(s) you have registered by navigating to your settings menu to remove your linked card(s).

You acknowledge that Visa, Mastercard and AMEX may be unable to monitor every transaction made with your enrolled Visa, Mastercard and AMEX including PIN-based purchases on debit cards, purchases you initiate through identification technology that substitutes for a PIN, payments made through other payment methods (such as a digital wallet or a third party payment app, where you may choose your Visa, Mastercard and AMEX card as a funding source but you do not present your card directly to the merchant), payments of existing balances, balance transfers, or transactions that are not processed or submitted through the Visa U.S.A. or MasterCard, AMEX payment systems, and that these transactions are not eligible. You may opt-out of this monitoring at any time by selecting ‘Account’ from the home screen of your Tandem App and deleting your registered card(s). If you register a debit card, your transaction must be processed as a ‘credit’ (i.e., signature) transaction to make sure the transaction can be monitored. Do not use a Personal Identification Number (PIN) when paying for your purchases with your enrolled card if you want the transaction to be available for view or action on the Tandem App.

Not all Visa, MasterCard, and American Express cards are eligible for registration - including PIN based purchases on debit cards. Visa, MasterCard, and American Express Corporate cards, Visa, MasterCard, and American Express Purchasing cards, non-reloadable prepaid cards, government-administered prepaid cards (including EBT cards), healthcare (including Health Savings Account (HSA) or Flexible Spending Account (FSA) or insurance prepaid cards, Visa Buxx, and Visa-, MasterCard-, and American Express-branded cards whose transactions are not processed through the Visa payment system, MasterCard payment system, and/or American Express payment system are not eligible to participate.

D. Automatically Collected Information

When you use the Service or open one of our HTML emails, we (or our service providers or vendors) automatically collect certain information from your web browser and through your device by using different types of technology, including “cookies,” “log files,” "pixels," and other tracking technologies. This automatically collected information includes:

● Device Data, including data about device identifiers such as IP address or other device address or ID, web browser and/or device type, your device’s operating software, your internet service provider, and your device’s regional and language settings.

● Service Use Data, including data about the web pages or sites that you visit just before or just after the Service, the pages you view on the Service, your actions on the Service, features you use, emails and advertisements you view, products and services you view and purchase, and the dates and times that you visit, access, or use the Service.

● Location Data, including imprecise location data (such as location derived from an IP address or data that indicates a city or postal code level).

The types of tracking technologies used include:

● Cookies. When you use the Service, we may send one or more cookies – small text files containing a string of alphanumeric characters – to your device. We may use both session cookies and persistent cookies. A session cookie disappears after you close your browser. A persistent cookie remains after you close your browser and may be used by your browser on subsequent visits to the Service to personalize your experience, remember your preferences, and support security features. Additionally, persistent cookies allow us to bring you advertising both on and off the Service. Persistent cookies can be removed. Please review your web browser "Help" file to learn the proper way to modify your cookie settings. Please note that if you delete, or choose not to accept, cookies from the Service, you may not be able to utilize the features of the Service to their fullest potential.

● Pixels and JavaScript. Pixels (also known as web beacons) are code embedded in a website, video, email, or advertisement that send information about your use to a server. There are various types of pixels, including image pixels (which are small graphic images) and JavaScript pixels (which contain JavaScript code). When you access a website, video, email, or advertisement that contains a pixel, the pixel may permit us or a separate entity to write or read cookies on your browser. Pixels are used in combination with cookies to track activity by a particular browser on a particular device. We may incorporate pixels from separate entities that allow us to track our conversions, bring you advertising both on and off the Service, and provide you with additional functionality.  

● App Technologies. These technologies are included in our Apps that are not browser-based like cookies and cannot be controlled by browser settings. For example, our Apps may include SDKs, which is code that sends information about your use to a server. These SDKs allow us to track our conversions, bring your advertising both on and off the Service, and provide you additional functionality, such as the ability to connect our Service with your Google account.

For further information on how we use tracking technologies for analytics and advertising, and your rights and choices regarding them, see the “Analytics and Advertising” and “Your Rights and Choices” sections below.

How We Use Information

Your information is an integral part of our operations, and we use it in a variety of ways in providing the Service and operating our other business and commercial purposes.

We use the information we collect about you for the following purposes:

● For purposes about which we notify you and with your consent.

● To operate, maintain, enhance and provide the features of the Service.

● To perform services requested by you, such as responding to your comments and questions.

● To contact you for administrative purposes such as customer service, sending technical notices regarding updates, security alerts, information regarding our policies.

● To address fraud, breach of policies or terms, and threats or harm.

● To personalize our services, such as remembering your information so that you will not have to re-enter it during your visit or the next time you visit the Service.

● To monitor aggregate site usage metrics such as total number of visitors and pages/screens viewed.

When We Disclose Information

We disclose information we collect in accordance with the practices described in this Privacy Policy. The categories of parties with whom we share information include:

● Service Providers. We share information with service providers that process information on our behalf. Service providers assist us with services such as payment processing, fraud prevention, data analytics, marketing and advertising, website hosting, and technical support. To the extent required by law, we contractually prohibit our service providers from retaining, using, or disclosing information about you for any purpose other than performing the services for us, although we may permit them to use information that does not identify you (including information that has been aggregated or de-identified) for any purpose except as prohibited by applicable law.

● Third Party Integrations. We share information with third parties (such as Plaid) and any relevant banks or other entities in connection with you connecting your third party accounts to your Tandem account. You may terminate this connection at any time through your account settings.

● Merger or Acquisition. In the event that all or a portion of Tandem or its assets are acquired by or merged with another entity, we reserve the right, in any of these circumstances, to transfer or assign the information that we have collected from users in connection with such merger, acquisition, sale, or other change of control.

● Security and Compelled Disclosure. We share information to comply with the law or other legal process, and where required, in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We also share information to protect the rights, property, life, health, security and safety of us, the Service or anyone else.

● Facilitating Requests. We share information at your request or direction.

● Consent. We share information with notice to you and your consent. For example, where we have received your consent, we will share your Service account with your partner. Where we have received such consent, we are not responsible for the acts or omissions of your partner on the Service. You can opt-out of such sharing at any time by disconnecting to your partner in the "Profile” section of the app.

Analytics

We may use third party data collection tools to provide us with analytics data regarding Users’ interactions with our Services, including:

● Google Analytics. For more information, please visit Google Analytics’ Privacy Policy. To learn more about how to opt-out of Google Analytics’ use of your information, please click here.

● Mixpanel. You may opt-out of Mixpanel’s automatic retention of data collected while using the Services by visiting https://mixpanel.com/optout/. To track opt-outs, Mixpanel uses a persistent opt-out cookie placed on your device.

● Fullstory. For more information, please visit Fullstory’s Privacy Policy. FullStory is an analytics and heat mapping service.

Your Rights and Choices

You may, of course, decline to share certain information with us, in which case we may not be able to provide to you some of the features and functionality of the Service. Below is further information regarding your rights and choices for the Service:

● Account Information. If you have an account with us, you may update, correct, or delete your profile information and preferences you set within the account at any time by accessing your account preferences page through the Service. Please note that we will retain and use information about you as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

● Emails. If you do not wish to receive email offers or newsletters from us, you can opt-out of receiving email information from us (except for emails related to the completion of your registration, correction of user data, change of password and other similar communications essential to your transactions on the Service) by using the unsubscribe process at the bottom of the email. You can also unsubscribe or change your email preferences by updating your account preferences through the Service. Please note that while your changes are reflected promptly in active user databases, we may retain all information you submit for a variety of purposes, including backups and archiving, prevention of fraud and abuse, and analytics.

● Push Notifications. If you have opted-in to receive push notifications on your device, you can opt-out at any time by updating your account preferences through the Service, through your device settings, or by uninstalling the app.

● Cookies and Pixels. Most browsers accept cookies by default. You can instruct your browser, by changing its settings, to decline or delete cookies. If you use multiple browsers on your device, you will need to instruct each browser separately. Your ability to limit cookies is subject to your browser settings and limitations.

● Do Not Track. Your browser settings may allow you to automatically transmit a “Do Not Track” signal to online services you visit. Note, however, there is no industry consensus as to what site and app operators should do with regard to these signals. Accordingly, unless and until the law is interpreted to require us to do so, we do not monitor or take action with respect to “Do Not Track” signals.  For more information on “Do Not Track,” visit https://www.allaboutdnt.com.

● App and Imprecise Location Technologies. You can stop all collection of information via an app by uninstalling the app. You can also reset your device Ad Id at any time through your device settings, which is designed to allow you to limit the use of information collected about you.

● Google Analytics and Advertising. Google provides tools to allow you to opt out of the use of certain information collected by Google Analytics at https://tools.google.com/dlpage/gaoptout and by Google Analytics for Display Advertising or the Google Display Network at https://www.google.com/settings/ads/onweb.  

● Interest-based Advertising. The companies we work with to provide you with targeted ads are required by us to give you the choice to opt out of receiving targeted ads. Most of these companies are participants of the Digital Advertising Alliance (“DAA”) and/or the Network Advertising Initiative (“NAI”). To learn more about the targeted ads provided by these companies, and how to opt out of receiving certain targeted ads from them, please visit: (i) for website targeted ads from DAA participants, https://www.aboutads.info/choices; (ii) for app targeted ads from DAA participants, https://www.aboutads.info/appchoices; and (iii) for targeted ads from NAI participants, https://www.networkadvertising.org/choices. Opting out only means that the selected participants should no longer deliver certain targeted ads to you, but does not mean you will no longer receive any targeted content and/or ads (e.g., in connection with the participants’ other customers or from other technology services).

● Mobile Device. You may also limit our use of information collected from or about your mobile device for purposes of serving targeted ads to you by going to your device settings and selecting “Limit Ad Tracking” (for iOS devices)

Please note that if you opt out using any of these methods, the opt out will only apply to the specific browser, device, account, email address, and/or phone number from which you opt out. It will not affect subsequent subscriptions (where applicable). We are not responsible for any other entities’ effectiveness of, or compliance with, any opt out options or programs, or the accuracy of their statements regarding their opt out options or programs.

Third Parties

The Service may contain features or links to websites and services provided by other parties. In addition, we integrate technologies operated or controlled by other parties into parts of our Service. Some examples include:

● Third Party Integrations as detailed in the Section above.

● Logging-In. We may embed a pixel or SDK on our Service that allows you to log-in to your Tandem account through your social media account. If you choose to log-in, we may receive information from the social network that you have authorized to share with us. Please note that the social network may independently collect information about you through your use.

● Brand Pages and Chatbots. We may offer our content through social media. Any information you provide to us when you engage with our content (such as through our brand page or via Facebook Messenger) is treated in accordance with this Privacy Policy. Also, if you publicly reference our Service on social media (e.g., by using a hashtag associated with Tandem in a tweet or post), we may use your reference on or in connection with our Service.

Any information you provide on another party’s sites or services is provided directly to that party and is subject to that party’s policies and practices regarding privacy and security, even if accessed through the Service. We encourage you to learn about third parties’ privacy and security policies before providing them with information.

Children's Privacy

The Service is intended for general audiences and is not directed at anyone under the age of 18. For that reason, we do not allow anyone under the age of 18 to use the Service or knowingly collect personal information (as defined by the U.S. Children’s Privacy Protection Act, or “COPPA”) from anyone under the age of 18. If you are under 18 years of age, please do not use or access the Service at any time or in any manner. If we learn that personal information has been collected on the Service from children, we will take the appropriate steps to delete this information in accordance with COPPA. If you are a parent or guardian and discover that your child has obtained an account on the Service or provided us with personal information, you may alert us at team@usetandem.com and request that we delete the personal information from our systems. We will remove the personal information in accordance with COPPA.

Data Security

We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of your information. Nevertheless, transmission via the internet is not completely secure and we cannot ensure or warrant the security of any information you transmit to us or store on the Service and you do so at your own risk. We also cannot guarantee that such information will not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards.

International Transfers

The Service is hosted in the United States and is intended solely for users located within and are residents of the United States. Your use of the Service, or provision of any information on the Service, is your consent to the transfer, storage, usage, sharing, and processing of information about you in the U.S. and other jurisdictions as set out in this Privacy Policy.

Changes and Updates to this Privacy Policy

Please revisit this page periodically to stay aware of any changes to this Privacy Policy, which may be revised periodically at our sole discretion. In the event that a change to the Privacy Policy materially modifies your rights or obligations, we may provide additional notice to your email address or through Service. Any changes are effective upon publication of the revised Privacy Policy. Your continued use of our Service indicates your consent to the Privacy Policy then posted. For the avoidance of doubt, disputes arising hereunder will be resolved in accordance with the Privacy Policy in effect at the time the dispute arose.

Our Contact Information

Please contact us with any questions or comments about this Privacy Policy, your information, our use and disclosure practices, or your consent choices by email at team@usetandem.com or by mail:

Ride in Tandem, Inc.

Attn. Privacy Officer

330 E Liberty St

Ann Arbor, MI 48104

This Privacy Policy has been designed to be accessible to people with disabilities. If you experience any difficulties accessing the information here, please contact us by emailing us at team@usetandem.com

Additional Disclosures for California Residents

These additional disclosures apply only to California residents. The California Consumer Privacy Act of 2018 (“CCPA”) provides additional rights to know, delete and opt-out, and requires businesses collecting or disclosing personal information to provide notices and means to exercise rights.

A. Notice of Collection

In the past 12 months, we have collected the following categories of personal information enumerated in the CCPA:

● Identifiers, including name, email address, mailing address, social security number, and online identifiers (such as IP address).

● Customer records, including phone number, billing address, and financial information.

● Commercial or transactions information, including records of products, services, and subscriptions purchased, obtained, or considered.

● Internet activity, including browsing history, search history, and interactions with a website, email, application, or advertisement.

● Geolocation data.

● Employment and education information.

● Inferences drawn from the above information about your predicted characteristics and preferences.

For further details on information we collect, including the sources from which we receive information, review the “Information We Collect” section above. We collect and use these categories of personal information for the business purposes described in the “How We Use Information” section above, including to manage our Service.

We do not generally sell information as the term “sell” is traditionally understood. To the extent “sale” under the CCPA is interpreted to include the activities set out in this Privacy Policy, such as those disclosed in the “Analytics” section above, we will comply with applicable law as to such activity. We disclose the following categories of personal information for commercial purposes: identifiers, characteristics, commercial or transactions information, internet activity, geolocation data, and inferences drawn. Please review the “When We Disclose Information” section above for further details about the categories of parties with whom we share information.

B. Right to Know and Delete

You have the right to know certain details about our data practices in the past 12 months. In particular, you may request the following from us:

● The categories of personal information we have collected about you;  

● The categories of sources from which the personal information was collected;

● The categories of personal information about you we disclosed for a business purpose or sold;

● The categories of third parties to whom the personal information was disclosed for a business purpose or sold;

● The business or commercial purpose for collecting or selling the personal information; and

● The specific pieces of personal information we have collected about you.

In addition, you have the right to delete the personal information we have collected from you.

To exercise any of these rights, please submit a request by emailing team@usetandem.com. In the request, please specify which right you are seeking to exercise and the scope of the request. We will confirm receipt of your request within 10 days. We may require specific information from you to help us verify your identity and process your request. If we are unable to verify your identity, we may deny your requests to know or delete.

C. Right to Opt-Out.

To the extent Tandem sells your personal information as the term “sell” is defined under the CCPA, you have the right to opt-out of the sale of your personal information by us to third parties at any time. You may submit a request by emailing team@usetandem.com.

D. Authorized Agent.

You can designate an authorized agent to submit requests on your behalf. However, we will require written proof of the agent’s permission to do so and verify your identity directly.

E. Right to Non-Discrimination.

You have the right not to receive discriminatory treatment by us for the exercise of any your rights.

Contact Information

If you have any questions about this Privacy Policy, please contact us by emailing team@usetandem.com