Provision record
Chime · Chime Privacy Policy · View original document ↗

Annual Privacy Notice Delivery

Medium severity Common · 289 of 352 platforms
Stay ahead of the changes
Track Chime and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

Federal law limits your opt-out rights to specific categories of data sharing, but state laws — particularly in California — may give you additional rights to control how your financial information is used.

This analysis describes what Chime's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the operative scope of opt-out rights available under federal privacy law, defining which sharing practices fall within permissible categories that consumers may limit. The acknowledgment of state law variations creates a framework where Chime's actual restriction obligations may exceed the federal baseline described here, depending on applicable state regimes.

Recent Activity

This document changed recently

Medium Jun 21, 2026

The updated privacy notice now explicitly discloses that Chime shares customer information with other financial companies for joint marketing purposes, whereas the prior 2017 version stated Chime did not engage in this sharing. This represents a material change in the stated data handling practice. Under the updated terms, customers can limit this sharing by logging into their Chime account at chime.com or through the Chime Mobile application and updating their Privacy Settings.

View change record →
Medium May 11, 2026

The updated policy no longer explicitly discloses whether Chime or its banking partner The Bancorp shares personal information for specific purposes such as marketing, joint marketing, or affiliate use. Previously, each sharing scenario included a 'Yes' or 'No' answer and stated whether customers could limit sharing. The revised policy directs users to login to chime.com or the Chime Mobile application and update their Privacy Settings to control sharing. You can adjust sharing preferences through your account settings, but the policy no longer itemizes which sharing practices are subject to customer limits.

View change record →
Medium Apr 20, 2026

The updated notice states Chime no longer shares your personal information (such as transaction history and creditworthiness) with other financial companies for joint marketing purposes. This is a narrowing of third-party data sharing compared to the prior language. The notice also clarifies that Chime does not share certain affiliate information, which may further limit how your data is used by related companies. These changes reduce the scope of data sharing disclosed in the privacy notice.

View change record →

Clause Stability Stable

0
Changes
4
Months Monitored
May 8, 2026
First Seen
May 8, 2026
Last Seen
This clause type exists across 5149 other provisions on other platforms.

Consumer impact (what this means for users)

California residents and consumers in states with stricter financial privacy laws may have additional opt-out or opt-in rights not fully described in this federal GLBA notice, meaning you should separately inquire about your state-specific rights to ensure you are exercising full control over your financial data.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    If you are a California resident, contact Chime or The Bancorp Bank to request information about your additional rights under California FIPA, including potential opt-in rights for certain data sharing that exceeds the federal GLBA baseline. Request written confirmation of the rights available to you.

How other platforms handle this

Google Cloud Medium

When you use them, we'll validate your request by verifying your identity (for example, by confirming that you're signed in to your Google Account).

Plaid Medium

Client will not... (ii) interfere with any independent efforts by Plaid to provide End User notice or obtain End User consent

Notion Medium

Not be Discriminated Against by us for exercising your privacy rights.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
Federal law gives you the right to limit only: sharing for affiliates' everyday business purposes — information about your creditworthiness; affiliates from using your information to market to you; sharing for nonaffiliates to market to you. State laws and individual companies may give you additional rights to limit sharing.

Excerpt from Chime's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY FRAMEWORK: This provision references the GLBA limitation on federal preemption, acknowledging that state laws may provide additional consumer rights (15 U.S.C.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Consumer Financial Protection Bureau (cfpb)
    Regulates consumer financial products and services. Can investigate companies for unfair, deceptive, or abusive financial practices including improper fees, billing errors, and data misuse.
    Who can file: Anyone who has used a consumer financial product or service in the US
    What you need: Account number or details, dates of transactions or events, description of the issue, and any supporting documents
    What to expect: The company must respond within 15 days. The CFPB forwards your complaint and may use it in enforcement actions. Individual compensation is possible in some cases.
    File a complaint →
  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FCRA
United States Federal
FTC Act Section 5
United States Federal
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
TCPA
United States Federal
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Chime Privacy Policy
Entity
Chime
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 8, 2026
Record ID
CA-P-006625
Document ID
CA-D-00078
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2abe49718004a1f397ca825b6b38f54ec9b89102654fa3ae82ef2e8ffea944af
Analysis generated
May 8, 2026 12:08 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Chime
Document: Chime Privacy Policy
Record ID: CA-P-006625
Captured: 2026-05-08 12:08:44 UTC
SHA-256: 2abe49718004a1f3…
URL: https://conductatlas.com/platform/chime/chime-privacy-policy/provision/CA-P-006625/annual-privacy-notice-delivery/
Accessed: Aug. 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Chime's Annual Privacy Notice Delivery clause do?

This provision establishes the operative scope of opt-out rights available under federal privacy law, defining which sharing practices fall within permissible categories that consumers may limit. The acknowledgment of state law variations creates a framework where Chime's actual restriction obligations may exceed the federal baseline described here, depending on applicable state regimes.

How does this clause affect you?

California residents and consumers in states with stricter financial privacy laws may have additional opt-out or opt-in rights not fully described in this federal GLBA notice, meaning you should separately inquire about your state-specific rights to ensure you are exercising full control over your financial data.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.

Is ConductAtlas affiliated with Chime?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Chime.