Stash · Stash Privacy Policy · View original document ↗

Bank Account Credential Collection

High severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Stash Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Stash collects your bank account login credentials, meaning the username and password you use to log into your external bank account, in addition to your Social Security number and other highly sensitive financial identifiers.

This analysis describes what Stash's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Collection of bank login credentials is associated with account aggregation services that access your external financial accounts on your behalf; this practice involves significant security considerations and may be subject to regulatory scrutiny regarding data access standards and consumer protection.

Consumer impact (what this means for users)

Stash collects your actual bank account login credentials as part of account linking, which means providing a third party with the ability to access your external financial accounts; consumers should understand what access is granted and whether it persists after initial linking.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact Stash at privacy@stash.com to request deletion of your stored bank account credentials and clarify the scope and duration of account access granted through credential linking. You may also review linked account settings within the Stash app.

Cross-platform context

See how other platforms handle Bank Account Credential Collection and similar clauses.

Compare across platforms →

Monitoring

Stash has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Your name, alias, date of birth, citizenship and passport number, visa information, home address, telephone number, email address, Social Security number, bank account number, bank routing number, bank account login credentials, bank name, employer name, employment status, and job position.

— Excerpt from Stash's Stash Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: The collection and use of consumer bank login credentials for account aggregation engages the CFPB's regulatory posture on financial data access, including the CFPB's Personal Financial Data Rights rule (Section 1033 of the Dodd-Frank Act), which addresses standards for consumer-authorized data access. The FTC Act applies to material omissions about the scope and security of credential-based account access. The GLBA applies to the security and handling of nonpublic personal financial information. The CFPB is the primary enforcement authority for Section 1033 compliance. GOVERNANCE EXPOSURE: High. Collection of bank login credentials is a practice subject to increasing regulatory scrutiny. The CFPB's Section 1033 rulemaking addresses the conditions under which third parties may access consumer financial accounts and places requirements on data minimization, security, and revocation of access. Compliance with these emerging standards is a material governance consideration for Stash's account aggregation practices. JURISDICTION FLAGS: US federal exposure through CFPB is primary. State-level exposure may arise under state unfair and deceptive practices statutes if the scope of credential-based access is not clearly disclosed. New York's NYDFS cybersecurity regulation imposes specific requirements on entities handling sensitive financial data including access credentials. CONTRACT AND VENDOR IMPLICATIONS: If a third-party account aggregation vendor (such as Plaid or similar) processes bank credentials on Stash's behalf, the vendor agreement should address data minimization, retention limits, access revocation procedures, and alignment with CFPB Section 1033 requirements. Liability allocation for credential-based security incidents should be addressed in vendor contracts. COMPLIANCE CONSIDERATIONS: Legal and compliance teams should review whether Stash's credential collection and account aggregation practices align with CFPB Section 1033 rulemaking requirements, including consumer disclosure, data minimization, and revocation of access. Security practices for credential storage and transmission should be audited. The policy should clearly explain how long credential-based access persists and how consumers can revoke it.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • CFPB
    The CFPB has authority over financial data access practices including credential-based account aggregation under Dodd-Frank Section 1033 and general consumer financial protection standards.
    File a complaint →
  • FTC
    The FTC has authority over unfair or deceptive practices related to the collection and security of sensitive financial credentials from consumers.
    File a complaint →

Provision details

Document information
Document
Stash Privacy Policy
Entity
Stash
Document last updated
March 14, 2026
Tracking information
First tracked
March 15, 2026
Last verified
May 9, 2026
Record ID
CA-P-007860
Document ID
CA-D-00061
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c314a917a32611f62e28ff71b79a50309bf3c87dea6cc7bd197833b0719565f8
Analysis generated
March 15, 2026 10:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Stash
Document: Stash Privacy Policy
Record ID: CA-P-007860
Captured: 2026-03-15 10:51:58 UTC
SHA-256: c314a917a32611f6…
URL: https://conductatlas.com/platform/stash/stash-privacy-policy/bank-account-credential-collection/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Stash's Bank Account Credential Collection clause do?

Collection of bank login credentials is associated with account aggregation services that access your external financial accounts on your behalf; this practice involves significant security considerations and may be subject to regulatory scrutiny regarding data access standards and consumer protection.

How does this clause affect you?

Stash collects your actual bank account login credentials as part of account linking, which means providing a third party with the ability to access your external financial accounts; consumers should understand what access is granted and whether it persists after initial linking.

Is ConductAtlas affiliated with Stash?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stash.