Skip to Content

Last Updated: December 12, 2024.

U.S. Privacy Notice for Consumers

Your trust and confidence in how we collect, use, disclose, and retain information about you is a priority. This U.S. Privacy Notice for Consumers (Notice) applies to our U.S. websites, our U.S. mobile applications (Citi apps), e-mail, our branded U.S. social media sites or pages, and other U.S. online, mobile or retail services that link to or from or expressly reference this Notice as well as any interactions you may have with our digital advertising campaigns (collectively, the Sites/Services).

This Notice explains how we collect, disclose, use, and protect information when you visit or use the Sites/Services. We advise you to read the Notice in its entirety, including the jurisdiction-specific provisions in the appendix to this Notice, which will apply to users in certain jurisdictions. Additionally, please note that Section I of this Notice, which describes our collection and use of information through our Sites/Services, also serves as our Notice At Collection for California residents for purposes of the California Consumer Privacy Act (CCPA), which you can view by clicking here.

You have the right to opt out of the sale of your Personal Information to, or the sharing of it with, Third Parties by clicking here to visit our Privacy Hub.  You can find more information about your right to opt out in Section I.A.5 of the Appendix below.

By using the Sites/Services, you agree to this Privacy Notice. Read our full notice with details about your rights here.

As you review this Notice, here are a few important things to keep in mind:

  • If you have a financial product or service with us for personal, family or household use with one of our U.S. businesses, that business would also have delivered to you a U.S. Customer Privacy Notice (Customer Privacy Notice) that explains how that business collects, uses and discloses information about you, and offers you certain choices with respect to the use and sharing of your personal information.
  • This Site is not intended for children under 13 years of age. We do not knowingly solicit information from, or market to, children under 13 years of age.
  • Wireless service providers, Internet service providers, device manufacturers and/or social media platforms may have their own privacy notices that are different from this one for the information they may access through your use of the Sites. We encourage you to read their privacy notices as the collection, uses and disclosure of information by those third parties may be different than Citi.
  • Our mobile, social media, or other services, sites, pages or materials may have additional terms about the privacy or use of your information. Please review the privacy notice for the specific Site/Service you are using.

Read our full notice with details about your rights here.

I. COLLECTION AND USE OF PERSONAL INFORMATION

II. SOURCES OF PERSONAL INFORMATION

III. DISCLOSURE OF PERSONAL INFORMATION

IV. AGGREGATION SERVICES

V. ONLINE ADVERTISING

VI. YOUR CHOICES REGARDING YOUR PERSONAL INFORMATION

VII. UPDATING YOUR PERSONAL INFORMATION

VIII. SECURITY OF PERSONAL INFORMATION

IX. OTHER IMPORTANT INFORMATION

X. CONTACT US

XI. APPENDIX — JURISDICTION SPECIFIC PROVISIONS

I. COLLECTION AND USE OF PERSONAL INFORMATION

We collect two types of information: Personal Information and Other Information.

Personal Information is any information:

  • that identifies or can be used to identify you or your household;
  • that relates to, describes, is capable of being associated with, or could reasonably be linked (directly or indirectly) with you or your household;
  • that can be used to authenticate you or provide access to an account;
  • that relates to you and that might be sensitive (such as personal medical or health information, account number, account value).

Personal Information includes Protected Health Information (as that is defined by the U.S. Health Insurance Portability and Accountability Act) and Sensitive Personal Information (as that is defined by applicable state laws) and Special Categories of Data (as that is defined by the E.U. General Data Protection Regulation).

Other Information is information that does not and cannot reveal an individual's specific identity, such as information that has been de-identified or aggregated. This Other Information is described in more detail in the Collection and Use of Information section below.

For at least the past 12 months, we have collected and used the following categories of Personal Information for the following business or commercial purposes (depending on the nature of your interactions with us):

Category of Personal Information

Our Business or Commercial Purpose(s) for Collecting this Information

Personal Identifiers, such as your name, addresses, phone number, e-mail, alias, mother's maiden name, as well as Social Security number, and information that appears on your Driver's license, Green card, National ID, State ID, or Passport/Visa which are considered Sensitive Personal Information

  • Authenticate you so that you can access the Sites/Services and conduct account transactions on the Sites/Services;
  • Reviewing and processing applications for our Services and transactions;
  • Processing transactions;
  • Intake of new customers;
  • Account maintenance and servicing;
  • Ensure that the Sites/Services function properly and otherwise administer the Sites/Services;
  • Providing customer service;
  • Provide you with account information, as well as information regarding our branches and branch events;
  • Improving our products and Sites/Services;
  • Performing research and business analytics, and identifying usage trends;
  • Engaging in fraud monitoring and prevention;
  • Compliance with applicable laws and regulations;
  • Protecting our business and our customers against illegal activity;
  • Performing audits;
  • Verifying requests made pursuant to this Notice;
  • Tailoring marketing communications from our affiliates as well as from selected third parties;
  • Managing our business effectively;
  • Responding to your inquiries, fulfilling requests and requesting your feedback;
  • Developing new products and services;
  • Expanding our business activities.

Characteristics of Protected Classifications, including gender, race, age, and your citizenship and military status, all of which are considered Sensitive Personal Information.

  • Reviewing and processing applications for our Services and transactions;
  • Intake of new customers;
  • Account maintenance and servicing;
  • Ensure that the Sites/Services function properly and otherwise administer the Sites/Services;
  • Providing customer service;
  • Improving our products and Sites/Services;
  • Performing research and business analytics, and identifying usage trends;
  • Engaging in fraud monitoring and prevention;
  • Compliance with applicable laws and regulations;
  • Protecting our business and our customers against illegal activity;
  • Performing audits;
  • Verifying requests made pursuant to this Notice;
  • Tailoring marketing communications from our affiliates as well as from selected third parties;
  • Managing our business effectively;
  • Developing new products and services;
  • Expanding our business activities.

Demographic Information, including date of birth, information from a birth certificate or death certificate, and relationship status.

  • Reviewing and processing applications for our Services and transactions;
  • Intake of new customers;
  • Account maintenance and servicing;
  • Ensure that the Sites/Services function properly and otherwise administer the Sites/Services;
  • Providing customer service;
  • Improving our products and Sites/Services;
  • Performing research and business analytics, and identifying usage trends;
  • Engaging in fraud monitoring and prevention;
  • Compliance with applicable laws and regulations;
  • Protecting our business and our customers against illegal activity;
  • Performing audits;
  • Verifying requests made pursuant to this Notice;
  • Tailoring marketing communications from our affiliates as well as from selected third parties;
  • Managing our business effectively;
  • Developing new products and services;
  • Expanding our business activities.

Financial Information, including Tax ID, bank account and/or payment card information, credit history, credit score, credit report, account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account, all of which are considered Sensitive Personal Information.

  • Authenticate you so that you can access the Sites/Services and conduct account transactions on the Sites/Services;
  • Reviewing and processing applications for our Services and transactions;
  • Intake of new customers;
  • Account maintenance and servicing;
  • Ensure that the Sites/Services function properly and otherwise administer the Sites/Services;
  • Providing customer service;
  • Improving our products and Sites/Services;
  • Performing research and business analytics, and identifying usage trends;
  • Engaging in fraud monitoring and prevention;
  • Compliance with applicable laws and regulations;
  • Protecting our business and our customers against illegal activity;
  • Performing audits;
  • Verifying requests made pursuant to this Notice;
  • Tailoring marketing communications from our affiliates as well as from selected third parties;
  • Managing our business effectively;
  • Developing new products and services;
  • Expanding our business activities.

Commercial Account and Transaction Information, including your user ID, account holder name, account PIN and password, security question(s) and word(s), signature, assets in the account; bank SWIFT code, credit card PIN, loyalty program information (when applicable), merchant name and contact information, merchant category code, transaction data/history, and language preference. Your credit card PIN is considered Sensitive Personal Information.

  • Authenticate you so that you can access the Sites/Services and conduct account transactions on the Sites/Services;
  • Reviewing and processing applications for our Services and transactions;
  • Intake of new customers;
  • Account maintenance and servicing;
  • Ensure that the Sites/Services function properly and otherwise administer the Sites/Services;
  • Providing customer service;
  • Improving our products and Sites/Services;
  • Performing research and business analytics, and identifying usage trends;
  • Engaging in fraud monitoring and prevention;
  • Compliance with applicable laws and regulations;
  • Protecting our business and our customers against illegal activity;
  • Performing audits;
  • Verifying requests made pursuant to this Notice;
  • Tailoring marketing communications from our affiliates as well as from selected third parties;
  • Managing our business effectively;
  • Developing new products and services;
  • Expanding our business activities.

Internet or other Electronic Network Activity Information, such as usage data through Citi's mobile apps (e.g. the date and time the app on your device accesses our servers and what information and files have been downloaded to or presented through the app), information collected through cookies, web beacons and other technologies (e.g. operating system name and version, browser type and version), and aggregated information about your visits to, or use of, our Sites/Services, as well as across other sites, and various attributes associated with your device (e.g. device manufacturer and model, unique ID assigned to your device, IP address, installed fonts, language preference and browser settings, and time zone in order to create a device fingerprint or identifier so that we can recognize your device) and mobile carrier information (e.g. carrier name, line type, country code) and other mobile subscriber related metadata. While that information alone may not reveal your specific individual identity, we may associate this usage and Other Information we collect with Personal Information about you.

  • Authenticate you so that you can access the Sites/Services and conduct account transactions on the Sites/Services;
  • Reviewing and processing applications for our Services and transactions;
  • Intake of new customers;
  • Account maintenance and servicing;
  • Ensure that the Sites/Services function properly and otherwise administer the Sites/Services;
  • Providing customer service;
  • Improving our products and Sites/Services;
  • Reviewing statistical information about use of the Sites/Services in order to improve their design and functionality, to understand how they are used, and to assist us with resolving questions about the Sites/Services;
  • Facilitate social sharing functionality, where appropriate;
  • Performing research and business analytics, and identifying usage trends;
  • Engaging in fraud monitoring and prevention;
  • Compliance with applicable laws and regulations;
  • Protecting our business and our customers against illegal activity;
  • Performing audits;
  • Verifying requests made pursuant to this Notice;
  • Tailoring and sending marketing communications from our affiliates and for selected third parties;
  • Servicing your account and marketing to you, including advertisements and other communications tailored to you, on our Sites/Services and third-party sites, as well as offline (please see the Online Advertising section for more information on our online advertising practices);
  • Recognizing you, your device or your browser when you use the Sites/Services so that we can facilitate navigation, display information more effectively, store your preferences and otherwise personalize your experience and enhance the use of the Sites/Services;
  • Managing our business effectively;
  • Developing new products and services;
  • Operating, maintaining, and protecting our Sites/Services;
  • Tracking responses to our e-mails and advertisements and measuring the success of our marketing campaigns;
  • Understanding your interests and preferences;
  • Expanding our business activities.

Geolocation Information, including precise physical location of your device by using satellite, cell phone tower, or wireless local area network signals (for example), as well as through the use of beacons in our branches. Your precise geolocation is considered Sensitive Personal Information.

  • Reviewing and processing applications for our Services and transactions;
  • Intake of new customers;
  • Account maintenance and servicing;
  • Ensure that the Sites/Services function properly and otherwise administer the Sites/Services;
  • Providing customer service;
  • Improving our products and Sites/Services;
  • Performing research and business analytics, and identifying usage trends;
  • Engaging in fraud monitoring and prevention;
  • Compliance with applicable laws and regulations;
  • Protecting our business and our customers against illegal activity;
  • Performing audits;
  • Verifying requests made pursuant to this Notice;
  • Tailoring marketing communications from our affiliates as well as from selected third parties;
  • Managing our business effectively;
  • Developing new products and services;
  • Expanding our business activities.

We also may use your device's physical location to provide you with personalized location-based services and content, as well as to understand traffic patterns in and around our branches. In some instances, you may be permitted to allow or deny such uses and/or sharing of your device's location, but, if you choose to deny such uses and/or sharing, we may not be able to provide you with the applicable personalized services and content. We will collect your precise physical location only with your consent.

Professional, Employment, and Educational Information, including information about your education, employment and employment history, and property, criminal offenses, and dependent/beneficiary name(s).

  • Reviewing and processing applications for our Services and transactions;
  • Intake of new customers;
  • Account maintenance and servicing;
  • Ensure that the Sites/Services function properly and otherwise administer the Sites/Services;
  • Providing customer service;
  • Improving our products and Sites/Services;
  • Performing research and business analytics, and identifying usage trends;
  • Engaging in fraud monitoring and prevention;
  • Compliance with applicable laws and regulations;
  • Protecting our business and our customers against illegal activity;
  • Performing audits;
  • Verifying requests made pursuant to this Notice;
  • Tailoring marketing communications from our affiliates as well as from selected third parties;
  • Managing our business effectively;
  • Developing new products and services;
  • Expanding our business activities.

Biometric Informationwhich is considered Sensitive Personal Information.

  • Authenticate you so that you can access the Sites/Services and conduct account transactions on the Sites/Services;
  • Reviewing and processing applications for our Service and transactions;
  • Intake of new customers;
  • Account maintenance and servicing;
  • Ensure that the Sites/Services function properly and otherwise administer the Sites/Services;
  • Providing customer service;
  • Improving our products and Sites/Services;
  • Performing research and business analytics, and identifying usage trends;
  • Engaging in fraud monitoring and prevention;
  • Compliance with applicable laws and regulations;
  • Protecting our business and our customers against illegal activity;
  • Performing audits;
  • Verifying requests made pursuant to this Notice;
  • Managing our business effectively;
  • Developing new products and services;
  • Expanding our business activities.

Audio and Visual Information, including your photo (when provided), image documentation, and your voice recordings (when provided).

  • Reviewing and processing applications for our Service and transactions;
  • Intake of new customers;
  • Account maintenance and servicing;
  • Ensure that the Sites/Services function properly and otherwise administer the Sites/Services;
  • Providing customer service;
  • Improving our products and Sites/Services;
  • Performing research and business analytics, and identifying usage trends;
  • Engaging in fraud monitoring and prevention;
  • Compliance with applicable laws and regulations;
  • Protecting our business and our customers against illegal activity;
  • Performing audits;
  • Verifying requests made pursuant to this Notice;
  • Managing our business effectively;
  • Developing new products and services;
  • Expanding our business activities.

Inferences, drawn from any of the information above to create a profile about you that may reflect, for example, your preferences, characteristics, and behavior.

  • Providing customer service and support;
  • Improving our products and Sites/Services;
  • Performing research and business analytics;
  • Tailoring marketing communications from our affiliates as well as from selected third parties;
  • Expanding our business activities.

For more information, please see the Online Advertising below.

In addition to Personal Information you provide directly to us, we may collect Other Information about you, including acquiring and using services provided by other parties who collect and analyze customer data. In some instances, we may combine Other Information with Personal Information where permissible by law and applicable industry guidelines.

We will retain your information for as long as reasonably necessary for the purposes described above.

We may sell or share Personal Identifiers, Characteristics of Protected Classifications, Demographic Information, Financial Information, Commercial Account and Transaction Information, Internet or other Electronic Network Activity Information, Geolocation Information, Professional, Employment, and Educational Information, and Inferences to trusted third parties in limited circumstances.

We do not use any Sensitive Personal Information for any purpose outside of the purpose for which it was shared with us.

If you are a California resident, please see supplemental provisions in the Appendix of this Notice for information about your rights as a consumer under the CCPA.

II. SOURCES OF PERSONAL INFORMATION

We collect and obtain information from:

You. We collect information directly from you through the Sites/Services, through your use of our Citi apps, and through your use of Services offered at retail locations or other Citi locations. For example, we collect information if you contact us or sign up for our e-mails. We collect information to process your applications and transactions. We also collect information that you voluntarily submit to us, including by responding to our online polls and surveys, requesting information from us or asking to be contacted by one of our representatives. If you work for one of our institutional (business) clients, we may obtain your business contact information from your firm.

Service Providers. We work with service providers who collect information on our behalf in order to provide services to us. We only allow our service providers to collect and use your personal information in connection with the services they provide us.

Third-Party Advertisers. We work with companies that help us deliver, measure, and analyze the effectiveness of our ads. These companies collect information about you when you interact with ads on our platforms and on the websites where our ads are displayed.

Third-Party Partners. We may collect information about you through your use of the Services and share it with other third-party sources, such as travel agents, travel partners (such as airlines and travel and hospitality providers) so they can provide services to you.

Third-Party Sources. We may collect information about you from certain third-party sources, including, for example, financial institutions and government sources. This helps us with engaging in fraud monitoring and prevention, compliance with applicable laws and regulations; reviewing and processing applications for our Services, intake of new customers, managing our business effectively, and account maintenance and servicing.

Cookies and Similar Technologies. We may use cookies, web beacons/pixel tags, log files, and other technologies to collect certain information about visitors to our website, use of our online features, and interactions with our e-mails and online advertisements. For example, through these means, we may collect your browser type and operating system, viewed web pages, links that are clicked, IP address, sites visited before coming to our website, e-mails we send that you open or forward or click through to our website. Collecting the foregoing information, and linking it with other information that you may provide, helps us to best tailor our website to you and enhance your online experience by saving your preferences while you are visiting a particular page, and to help identify website features and offers that may be of particular interest to you.

Can You Opt Out? Visit the Your Choices Regarding Your Personal Information section below for more information on how to opt out from tracking technologies.

III. DISCLOSURE OF PERSONAL INFORMATION

During at least the past 12 months, we have disclosed your Personal Information for the following business or commercial purposes:

  • All categories of Personal Information listed above to our affiliates to the extent permissible under applicable law;
  • Personal Identifiers, Characteristics of Protected Classifications, Demographic Information, Financial Information, Commercial Account and Transaction Information, Internet or other Electronic Network Activity Information, Biometric Information, Audio and Visual Information, and Inferences to third parties, for a business purpose, as detailed in the Notice at Collection section above;
  • All categories of Personal Information listed above to our service providers, who provide services such as sending you marketing communications on our behalf, website hosting, data analysis, information technology and related infrastructure provision, customer service, processing your transactions, e-mail delivery, auditing, and other services; and
  • All categories of Personal Information listed above may be disclosed to a third party in the event of any proposed reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).

During at least the past 12 months, we have sold or shared the following for business or commercial purposes:

  • Personal Identifiers, Characteristics of Protected Classifications, Demographic Information, Financial Information, Commercial Account and Transaction Information, Internet or other Electronic Network Activity Information, Geolocation Information, Professional, Employment, and Educational Information, and Inferences with select third party advertising partners to allow them to provide custom advertising, programs and other services to you.

We also may use and disclose your Personal Information as we believe to be necessary or appropriate: (a) under applicable law, which may include laws outside your country of residence; (b) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include such authorities outside your country of residence; (c) to enforce our terms and conditions; and (d) to protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or others.

Where appropriate, we will limit disclosure of your Personal Information in accordance with the choices you have provided us in response to our Customer Privacy Notice(s) or other privacy choices that we may make available.

We may provide de-identified and aggregated information to our affiliates and third parties to help deliver products, services, and content that are tailored to the users of our Sites/Services and for other business purposes.

We may transfer information to Citi affiliated companies or other parties throughout the world to process transactions and provide you with products and services. Regardless of where we process your information, we still treat it in accordance with this Notice and applicable law.

IV. AGGREGATION SERVICES

Citi, like many similar companies, offers account aggregation services that allow you to consolidate your electronically enabled financial account information from different sources (such as your accounts with us or with other financial institutions) so that you can view all your account information in one online location.

When acting as an account aggregator, Citi or its aggregation service provider may request your account user credentials for third-party (non-Citi) financial accounts, including usernames and passwords, in order to access your account information as your agent.

If you provide us access, as your agent, to your third-party account information we may use such information as well as your Citi account information where applicable, to provide you offers, suggestions and insights on your spending, savings and other financial behaviors. These insights are not investment, tax or legal advice and neither Citibank not any of its affiliates are acting as a tax, legal or investment advisor in providing same. With your consent, subject to written agreement, Citigroup Personal Wealth Management or other Citigroup businesses may currently or in the future provide investment advisory or other investment services based on online access to your investment account and other financial information.

You may cancel enrollment in Citi's aggregation service or delete accounts at any time. Upon cancellation or deletion of an account, we will delete and direct our service provider to delete this data from our and their respective records as permitted under applicable law, rules and regulations.

With regard to aggregation services provided by a third-party, if you provide your user credentials or other Personal Information about your Citi accounts to a third-party aggregation services provider, we will consider that you have authorized all transactions or actions initiated by such access information you provide, whether or not you were aware of a specific transaction or action. If you decide to revoke the authority you have given to an aggregation website, we strongly recommend that you change your password for Citi Online to ensure that the aggregation website cannot continue to access your account information.

V. ONLINE ADVERTISING

We may, directly or through third parties, serve ads regarding products and services intended to be of interest to you on the Site and on third party sites or apps. We and others may use the online technologies described in the Collection and Use of Information section above to make inferences and predictions about your characteristics, interests and preferences based on your online interests and activities across other sites. We may also use technologies to associate and recognize your various mobile and desktop devices in order to deliver ads and other content in a consistent manner across the devices you use. Information we collect using the technologies described above may also be associated or linked with Personal Information, such as email or postal address, you provided directly to us or others. Alternatively, Personal Information may also be linked with characteristics or attributes about you, such as lifestyle interests, in support of our marketing efforts. If you opt out of interest based advertising, as described in the Your Choices Regarding Your Personal Information section below, you will not receive such customized ads on the Site or in other places.

VI. YOUR CHOICES REGARDING YOUR PERSONAL INFORMATION

You have certain rights with regard to your Personal Information.

A. Your California Privacy Rights

If you are a California resident, you have the right to request and receive certain information about disclosure of your Personal Information to third parties for their direct marketing purposes. Because it is our policy not to share your Personal Information with third parties for third-party direct marketing purposes without your consent, we are exempt from the requirement to respond to such requests. If you have any questions related to our policy, please contact us using the information provided in the Contact Us section below.

For information regarding how to exercise your rights as a consumer under the California Consumer Privacy Act, please see supplemental provisions for California residents in the Appendix to this Statement.

B. Marketing E-mails

To stop receiving our promotional e-mails, you can follow the instructions in any promotional message you get from us. Even if you opt out of getting marketing messages, we will still send you transactional messages.

C. Cookies and Interest-Based Advertising

Both the Network Advertising Initiative and the Digital Advertising Alliance (to whose principles we adhere) provide information about and technologies to opt-out of receiving some or all interest based advertising. You can also opt-out of interest based advertising by clicking on the appropriate icon within an interest based ad which will take you to tools to help you manage these choices. These technologies are browser and device specific, they must be adopted on each device you use. If you block or clear cookies, these technologies may not work. You will continue to see ads on the Site which reflect how you use the Site and our Services.

If you would prefer not to receive interest-based advertising, you can opt-out of this activity at the DAA website by visiting http://www.aboutads.info/choices/(for U.S. residents) and/or the NAI website by visiting http://optout.networkadvertising.org/?c=1.

You can choose whether to accept cookies through your browser settings (check the Help file). For example, most browsers allow you to automatically decline cookies or decline or accept a particular cookie (or cookies) from a particular site when browsing. If you decide not to accept cookies, some features of the Site may not work properly because we may not be able to recognize your device and associate you with your Citi account(s). In addition, the offers or content we provide when you visit our site or on third-party sites may not be as relevant to you or tailored to your interests.

D. Do Not Track

Some browsers have a Do Not Track feature that lets you tell websites that you do not want to have your online activities tracked. At this time, we do respond to browser do not track signals.

VII. UPDATING YOUR PERSONAL INFORMATION

Keeping your account information accurate and up to date is very important. If your account information is incomplete, inaccurate or not current, please use the Contact Us option on our Site, or call or write to us at the telephone numbers or appropriate address for changes listed on your account statements, records, online or other account materials. You can also speak to a branch representative, your financial advisor or your designated account representative.

VIII. SECURITY OF PERSONAL INFORMATION

The security of your Personal Information is a priority. We seek to protect this information by implementing and maintaining reasonable physical, electronic, and procedural security measures and safeguards designed to protect Personal Information within our organization. We provide employee training in the proper handling of Personal Information. Unfortunately, no data transmission over the Internet or wireless network or data storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please immediately contact us in accordance with the Contact Us section below.

IX. OTHER IMPORTANT INFORMATION

A. Notice of Changes

We may change this Notice from time to time. Please take a look at the Last Updated legend at the beginning of this Notice to see when this Privacy Notice was last revised. When we do, we will post the revised Notice on this page with a new effective date. Any changes will become effective when we post the revised Notice on the Site. Your use of the Sites/Services following these changes means that you accept the revised Notice.

B. Third-Party Sites and Services

This Notice does not address, and we are not responsible for, the privacy, security, or other practices of any third parties, including any third party operating any site or service to which the Site links. The inclusion of a link on the Site does not imply endorsement of the linked site or service by us or by our affiliates.

In addition, we are not responsible for the information collection, usage, disclosure, or security policies or practices of other organizations, such as Facebook, Apple, Google, Microsoft, or any other third-party app provider, social media platform provider, operating system provider, device manufacturer, or wireless service provider, including with respect to any Personal Information you disclose to other organizations through or in connection with the Site/Services.

C. Jurisdictional Issues

The Sites/Services are controlled and operated by us from the United States and are not intended to subject us to the laws or jurisdiction of any state, country, or territory other than those of the United States. Information about you may be stored and processed in any country where we have facilities or in which we engage service providers, and, by using the Sites/Services you consent to the transfer of information to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country. In certain circumstances, courts, law enforcement agencies, regulatory agencies, or security authorities in those other countries may be entitled to access your Personal Information.

X. CONTACT US

If you have any questions about this Notice, please contact your account representative, call the number on the back of your card, or contact us

If you are contacting us from outside the United States, please refer to the Citi website in your country or use the contact details in the local privacy notice for your product. If you would like to submit a request pursuant to the California Consumer Privacy Act (CCPA), please visit Citi's Privacy Hub at online.citi.com/US/ag/dataprivacyhub or call us at (833) 971-1191 (TTY: 711). If you wish to submit a request to have your Personal Information deleted or corrected (see sections I.A.3 and I.A.4 in the Appendix below), call us at (833) 971-1191 (TTY: 711).

APPENDIX — JURISDICTION SPECIFIC PROVISIONS

I. Supplemental provisions for California residents.
 

A. Requests. California residents have certain rights with respect to Personal Information under the California Consumer Privacy Act (CCPA). For purposes of this subsection, the terms consumer, categories of personal information, business purpose, third party, sell, and share have the meanings ascribed to them respectively in the CCPA. Terms defined under the CCPA may differ in meaning from the common usage of the same terms used elsewhere in this Notice.

  1. You have the right to request, up to two times every 12 months, that Citi disclose to you the following: (i) the categories of Personal Information that Citi has collected about you; (ii) the categories of sources from which Citi has collected Personal Information about you; (iii) the business or commercial purpose for collecting , selling, or sharing your Personal Information; (iv) the categories of Third Parties to whom the Personal Information was disclosed and (v) the specific pieces of Personal Information that Citi has collected about you. Please note that Personal Information we have collected in connection with your personal account with us is not subject to the requirements of CCPA because it is already protected under existing federal and California state privacy laws, including the Graham Leach Bliley Act.

  2. You have the right to request a portable copy of your Personal Information.

    In response to verified requests pursuant to #1 or #2 above, we will confirm receipt of the request within 10 business days of receipt of the request, and disclose and deliver the required information to you free of charge within 45 days of receiving a verifiable consumer request. We may extend this time period to deliver information once by an additional 45 days when reasonably necessary. We will provide notice of the extension within the first 45-day period.

  3. You have the right to request that Citi delete Personal Information collected from you, subject to certain exceptions allowed under applicable law.

    In response to verified requests pursuant to #3 above, we will confirm receipt of the request within 10 business days of receipt of the request. Following verification of your request, we may require you to separately confirm that you want your Personal Information to be deleted. We will delete the information within 45 days of receiving a verifiable consumer request (subject to certain exceptions). We may extend this time period once by an additional 45 days when reasonably necessary. We will provide notice of the extension within the first 45-day period.

  4. You have the right to request that Citi correct inaccurate Personal Information collected from you, subject to certain exceptions allowed under applicable law. We will accept, review, and consider any documentation that you provide in connection with your right to correct, provided you make a good-faith effort to provide Citi with all relevant information available at the time of the request.

    In response to verified requests pursuant to #4 above, we will confirm receipt of the request within 10 business days of receipt of the request. Following verification of your request, we may require you to provide documentation if necessary to rebut our own documentation that the Personal Information is accurate. If, we determine, based on the totality of the circumstances, that the information is not accurate, we will respond to the request by correcting the information or deleting the information (if deletion of the information does not negatively impact you).We will correct within 45 days of receiving a verifiable consumer request. We may extend this time period once by an additional 45 days when reasonably necessary. We will provide notice of the extension within the first 45-day period.

  5. NOTICE OF RIGHT TO OPT OUT:  You have the right to opt out of the sale of your Personal Information to, or the sharing of it with, Third Parties by clicking here to visit our Privacy Hub. CCPA defines sale very broadly, covering both monetary and other consideration. The same is true of the CCPA's definition of share, except that sharing under the CCPA relates only to the targeting of advertising based on Personal Information from an individual's interaction with other websites and services. Citi does not sell or share Personal Information for money. However, we share some types of Personal Information as further described in Section III of this Notice above.

  6. Citi will not discriminate against you because you elect to exercise these rights, including by:

    • Denying goods or services to you.
    • Charging you different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties.
    • Providing a different level or quality of goods or services to you.
    • Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services.

    None of the foregoing, however, prohibits Citi from charging you a different price or rate, or from providing a different level or quality of goods or services to you, if that difference is reasonably related to the value provided to Citi by your data.

B. Submission of Requests. You may exercise these rights by managing this information through Citi's Privacy Hub at online.citi.com/dataprivacyhub or by calling us at (833) 971-1191 (TTY: 711). If you wish to submit a request to have your Personal Information deleted or corrected (see sections I.A.3 and I.A.4 in this Appendix), or to opt-out of the selling or sharing of your Personal Information , call us at (833) 971-1191 (TTY: 711). If you wish to submit any type of CCPA request through an authorized agent, please follow the process in Section I.C. below.

C. CCPA Authorized Agent. CCPA permits consumers to designate authorized agents to submit requests on their behalf. Under CCPA, an authorized agent is a natural person or a business entity in California that a consumer has authorized to act on their behalf subject to the requirements. If you would like to designate an authorized agent to submit a request to know, a request to delete, or a request to correct Personal Information on your behalf, please call us at (833) 971-1191 (TTY: 711).

You or your authorized agent may provide us with a written power of attorney, executed by you, confirming the authority of the authorized agent with respect to your CCPA request(s).

If we have not received a power of attorney, we may require your authorized agent to provide proof that you gave the agent signed permission to submit your CCPA request(s).

In addition, we may also require you to do the following directly with us:

  1. Verify your own identity with us;

  2. Confirm you have provided the authorized agent permission to submit the CCPA request(s).

Once verified (see Section I.D. below), your authorized agent may create a unique account for you through Citi's Privacy Hub at online.citi.com/dataprivacyhub and manage your requests through that account.

D. Verification. Whether you submit a request directly on your own behalf, or through an authorized agent, we will take reasonable steps to verify your identity prior to responding to your requests under CCPA. Upon receiving a request pursuant to I.A.2, I.A.3 or I.A.4 above, we will confirm receipt within 10 days and provide you with information about how we will verify and process the request. In order to verify your request, we will require you to provide your social security number, tax ID number or passport number and issuing country, in addition to your first and last name, e-mail address and mailing address. We do not require you to verify your identity to make a request pursuant to I.A.5, but we may ask you for information necessary to compete the request. For example, we may ask you for your name, but we will not require you to take a picture of yourself with your driver's license.

Annual CCPA Request Metrics

Our annual CCPA request metrics can be found at this link.