Privacy & Data Protection

Privacy Policy

At PinnaclePB, your privacy is our priority. This policy explains how we collect, use, protect, and share your personal information.

Last updated: September 27, 2026
~12 min read
English
1

Introduction

PinnaclePB ("we," "us," or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our banking services, website, mobile applications, and related platforms (collectively, the "Services").

Our Commitment: We believe that privacy is a fundamental right. We will never sell your personal information to third parties, and we will only use your data in ways that are transparent, secure, and in compliance with applicable privacy laws including GDPR, CCPA, and other relevant regulations.

1.1 Scope of This Policy

This Privacy Policy applies to all personal information we collect through:

  • Our website (www.weatherbys.com)
  • Our mobile applications (iOS and Android)
  • In-person interactions at our branches
  • Phone conversations with our customer service team
  • Email communications and marketing materials
  • Social media interactions

1.2 Data Controller

PinnaclePB is the data controller for the personal information collected through our Services. This means we determine the purposes and means of processing your personal data.

2

Information We Collect

We collect various types of personal information to provide our banking services effectively. The specific data we collect depends on your relationship with us and the services you use.

2.1 Personal Identification Information

  • Full name, date of birth, and gender
  • Residential address and mailing address
  • Email address and phone number(s)
  • Government-issued identification numbers (SSN, passport number, driver's license)
  • Tax identification numbers
  • Photographs and signatures (for identity verification)

2.2 Financial Information

  • Account numbers and balances
  • Transaction history and payment records
  • Income and employment information
  • Credit history and credit scores
  • Investment holdings and portfolio information
  • Loan applications and repayment history

2.3 Technical & Device Information

  • IP address and device identifiers
  • Browser type and version
  • Operating system and device type
  • Mobile network information
  • Location data (with your consent)
  • Usage patterns and interaction data
Data Category Examples Purpose
Identity Data Name, DOB, ID numbers Account opening, KYC verification
Contact Data Email, phone, address Communication, service delivery
Financial Data Account info, transactions Banking services, compliance
Technical Data IP address, device info Security, fraud prevention
Usage Data App interactions, features used Service improvement

2.4 Information from Third Parties

We may receive personal information about you from third parties, including:

  • Credit bureaus — Credit reports and scores
  • Employers — Income verification
  • Government agencies — Regulatory compliance information
  • Service providers — Information collected on our behalf
  • Public sources — Publicly available information
3

How We Use Your Data

We use your personal information for the following purposes:

3.1 Service Delivery

  • Opening and managing your accounts
  • Processing transactions and payments
  • Providing customer support
  • Issuing cards, checks, and other banking products
  • Calculating and applying interest

3.2 Security & Fraud Prevention

  • Verifying your identity
  • Monitoring for suspicious activity
  • Preventing fraud and money laundering
  • Protecting against unauthorized access
  • Investigating security incidents

3.3 Legal & Regulatory Compliance

  • Complying with Anti-Money Laundering (AML) laws
  • Meeting Know Your Customer (KYC) requirements
  • Responding to legal requests and court orders
  • Reporting to tax authorities as required
  • Maintaining required records

3.4 Product Improvement & Innovation

  • Analyzing usage patterns to improve our Services
  • Developing new features and products
  • Conducting research and analytics
  • Personalizing your experience

3.5 Marketing & Communications

  • Sending account-related notifications
  • Providing promotional offers (with your consent)
  • Conducting customer satisfaction surveys
  • Sharing relevant product information
Marketing Opt-Out: You can opt out of marketing communications at any time by clicking the "unsubscribe" link in any email, adjusting your preferences in your account settings, or contacting our customer service team. Note that you will continue to receive essential service-related communications even after opting out of marketing.
4

Legal Basis for Processing

Under the General Data Protection Regulation (GDPR) and similar privacy laws, we must have a legal basis for processing your personal data. We rely on the following legal bases:

4.1 Contractual Necessity

We process your data when necessary to perform our contract with you, such as providing banking services, processing transactions, and maintaining your accounts.

4.2 Legal Obligation

We process your data when required to comply with legal obligations, including Anti-Money Laundering (AML) laws, tax reporting requirements, and regulatory mandates.

4.3 Legitimate Interests

We process your data for our legitimate business interests, such as fraud prevention, service improvement, and marketing, provided these interests are not overridden by your rights and freedoms.

4.4 Consent

In some cases, we rely on your explicit consent to process your data, such as for certain marketing activities or processing special categories of data. You can withdraw your consent at any time.

Multiple Legal Bases: We may rely on more than one legal basis for processing your data, depending on the specific purpose and context. We will clearly indicate which legal basis applies in our communications with you.
5

Data Sharing & Disclosure

We do not sell your personal information to third parties. However, we may share your data in the following circumstances:

5.1 Service Providers

We share data with third-party service providers who assist us in operating our business, such as:

  • Cloud hosting and data storage providers
  • Payment processors and card networks
  • Customer support and call center services
  • Marketing and analytics platforms
  • Legal, accounting, and consulting firms

All service providers are contractually obligated to protect your data and use it only for the purposes we specify.

5.2 Regulatory & Legal Requirements

We may disclose your information when required by law, regulation, or legal process, including:

  • Government authorities and regulatory bodies
  • Law enforcement agencies
  • Court orders and subpoenas
  • Tax authorities

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred to the acquiring entity. We will notify you of any such change and any choices you may have regarding your data.

5.4 With Your Consent

We may share your data with third parties when you have given us explicit consent to do so. You can withdraw your consent at any time.

Our Promise: We will never sell your personal information to third parties for their own marketing purposes. Any sharing of your data is strictly for the purposes outlined in this policy and in compliance with applicable laws.
6

Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience, analyze usage patterns, and deliver personalized content.

6.1 What Are Cookies?

Cookies are small text files stored on your device when you visit our website. They help us remember your preferences, understand how you use our site, and improve our services.

6.2 Types of Cookies We Use

  • Essential Cookies: Required for the website to function properly. Cannot be disabled.
  • Performance Cookies: Help us understand how visitors interact with our website by collecting anonymous data.
  • Functional Cookies: Enable personalized features and remember your preferences.
  • Marketing Cookies: Track your activity across websites to deliver relevant advertisements (only with your consent).

6.3 Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to:

  • View what cookies are stored and delete them individually
  • Block third-party cookies
  • Block all cookies
  • Delete all cookies when you close your browser
Important: If you disable essential cookies, some features of our website may not function properly. This may affect your ability to log in, make transactions, or access certain services.

6.4 Do Not Track

Some browsers have a "Do Not Track" feature that signals to websites that you do not want to be tracked. We currently honor Do Not Track signals and do not track your activity across third-party websites.

7

Data Security

We take the security of your personal information seriously and implement comprehensive measures to protect your data from unauthorized access, disclosure, alteration, or destruction.

7.1 Technical Safeguards

  • Encryption: All data is encrypted in transit (256-bit SSL/TLS) and at rest using industry-standard encryption protocols.
  • Access Controls: Strict access controls ensure only authorized personnel can access your data, with multi-factor authentication required.
  • Network Security: Firewalls, intrusion detection systems, and regular security audits protect our infrastructure.
  • Monitoring: 24/7 security monitoring detects and responds to potential threats in real-time.

7.2 Organizational Safeguards

  • Regular security training for all employees
  • Strict confidentiality agreements
  • Background checks for personnel with data access
  • Clear data handling policies and procedures
  • Regular security audits and penetration testing

7.3 Incident Response

In the event of a data breach that affects your personal information, we will:

  • Investigate the incident immediately
  • Take steps to secure your data and prevent further unauthorized access
  • Notify you and relevant authorities as required by law
  • Provide guidance on protecting your account
Bank-Grade Security: Our security measures meet or exceed industry standards and regulatory requirements. We undergo regular third-party security audits and maintain SOC 2 Type II certification.
8

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.

8.1 Retention Periods

Data Type Retention Period Reason
Account records Life of account + 7 years Regulatory compliance
Transaction records 7 years after closure Tax and legal requirements
KYC documentation 5 years after relationship ends AML regulations
Marketing preferences Until consent withdrawn Respecting your choices
Website analytics 24 months Service improvement

8.2 Data Deletion

When data is no longer needed, we securely delete or anonymize it in accordance with our data retention policies. You can request deletion of your data as outlined in Section 9 (Your Privacy Rights).

9

Your Privacy Rights

Depending on your location and applicable laws, you have certain rights regarding your personal information. We make it easy to exercise these rights through your account settings or by contacting us.

9.1 Right to Access

You have the right to request a copy of the personal information we hold about you. We will provide this information in a commonly used, machine-readable format within 30 days of your request.

9.2 Right to Rectification

You have the right to request correction of inaccurate or incomplete personal information. You can update most information directly through your account settings.

9.3 Right to Erasure (Right to be Forgotten)

You have the right to request deletion of your personal information in certain circumstances, such as when:

  • The data is no longer necessary for the purpose it was collected
  • You withdraw your consent (where consent was the legal basis)
  • You object to the processing and there are no overriding legitimate grounds
  • The data was processed unlawfully
Limitations: We may be unable to delete certain information if we are required to retain it by law (such as transaction records for tax purposes) or if deletion would prevent us from providing our services to you.

9.4 Right to Restrict Processing

You have the right to request that we restrict the processing of your personal information in certain circumstances, such as when you contest the accuracy of the data.

9.5 Right to Data Portability

You have the right to receive your personal information in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance.

9.6 Right to Object

You have the right to object to the processing of your personal information based on legitimate interests or for direct marketing purposes. We will stop processing your data for these purposes unless we demonstrate compelling legitimate grounds.

9.7 Right to Withdraw Consent

Where we rely on your consent to process your data, you can withdraw that consent at any time. This does not affect the lawfulness of processing before your withdrawal.

9.8 How to Exercise Your Rights

To exercise any of these rights, you can:

  • Update your preferences directly in your account settings
  • Email our Data Protection Officer at info@pinnaclepbonline.com
  • Call our dedicated privacy line at +1 (800) 123-4568
  • Write to us at: PinnaclePB, Data Protection Officer, Sanders Road, Wellingborrow NN8 4BX, United Kingdom

We will respond to your request within 30 days. In complex cases, we may need up to 90 days, in which case we will inform you of the extension and the reasons for it.

10

International Data Transfers

As a global bank, we may transfer your personal information to countries outside your home country, including to our affiliates, service providers, and partners located in various jurisdictions.

10.1 Adequacy Decisions

When transferring data to countries that the European Commission has determined provide an adequate level of data protection, we rely on that adequacy decision.

10.2 Appropriate Safeguards

For transfers to countries without an adequacy decision, we implement appropriate safeguards, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules (BCRs) for intra-group transfers
  • Certification mechanisms or codes of conduct
  • Explicit consent from you (where appropriate)

10.3 Your Rights Regarding Transfers

You have the right to be informed about the safeguards in place for international transfers of your data. You can request a copy of these safeguards by contacting us.

11

Children's Privacy

Our Services are not directed to individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children.

11.1 Custodial Accounts

We offer custodial accounts for minors, which are opened and managed by a parent or legal guardian. In these cases, we collect information from the guardian and limited information about the minor as required by law.

11.2 If We Learn of a Child's Data

If we learn that we have collected personal information from a child without proper parental consent, we will delete that information as quickly as possible.

Parental Responsibility: If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately so we can take appropriate action.
12

Third-Party Links & Services

Our website and mobile applications may contain links to third-party websites, services, or applications that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

12.1 Your Responsibility

We strongly encourage you to review the privacy policies of any third-party sites you visit. Your use of third-party services is subject to their terms and privacy policies, not ours.

12.2 Integrated Services

Our platform may integrate with third-party services (such as payment processors, financial aggregators, or investment platforms). When you use these integrated services, your data may be shared with those third parties in accordance with their privacy policies.

13

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

13.1 Notification of Changes

For material changes that affect how we use your personal information, we will:

  • Post the updated policy on our website with a revised "Last Updated" date
  • Notify you via email or in-app notification at least 30 days before the changes take effect
  • Request your explicit consent where required by law

13.2 Your Continued Use

Your continued use of our Services after the effective date of any changes constitutes your acceptance of the revised Privacy Policy. If you do not agree to the changes, you should close your account and cease using our Services.

13.3 Historical Versions

We maintain historical versions of our Privacy Policy. You can request a copy of the policy that was in effect at any given time by contacting us.

14

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

PinnaclePB — Data Protection Officer

info@pinnaclepbonline.com

+1 (800) 123-4568 (Privacy Hotline)

123 Financial District, New York, NY 10005, USA

Response within 30 days

14.1 Supervisory Authorities

If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with your local data protection authority. In the European Union, you can find your supervisory authority here.

We're Here to Help: We encourage you to contact us first with any privacy concerns. Our dedicated privacy team is committed to resolving issues quickly and transparently.

14.2 Regulatory Information

PinnaclePB is regulated by multiple financial authorities and complies with all applicable data protection laws, including:

  • General Data Protection Regulation (GDPR) — European Union
  • California Consumer Privacy Act (CCPA) — California, USA
  • Gramm-Leach-Bliley Act (GLBA) — United States
  • Personal Information Protection and Electronic Documents Act (PIPEDA) — Canada
  • Other applicable local and international privacy laws

Your privacy matters to us. Thank you for trusting PinnaclePB.

© 2026 PinnaclePB. All rights reserved.