Privacy Policy

anchor

INTRODUCTION

American Financial Network Inc., DBA Orion Lending (“Company”) specifically designed this Privacy Policy (“Policy”) to protect nonpublic company and customer information and to abide by privacy protection laws. This Policy describes how the Company protects nonpublic personal information (“NPI”) and defines the roles and responsibilities of the Company’s employees in managing the potential risks associated with such information.

The Policy shall accomplish the following:

  1. Protect the security and confidentiality of company and customer nonpublic personal information;
  2. Protect against unauthorized access to or use of such information;
  3. Provide for the proper disposition of company and customer information when disposal is appropriate; and
  4. Require that the Company’s third party service providers with access to company and/or customer information take appropriate steps to adequately protect such information.

The standards set out in this Policy represent minimum requirements for compliance with federal consumer protection laws based on applicable legal and regulatory guidance.

anchor

BACKGROUND

The Gramm-Leach-Bliley Act, also known as the Financial Services Modernization Act of 1999, Pub.L. 106–102, 113 Stat. 1338, (the “Act”) and the Federal Trade Commission’s Privacy Rule, 16 CFR Part 313, govern the treatment of a customer’s NPI by “financial institutions”. A broad range of companies and institutions fall under the Act’s definition of “a financial institution”, as the term encompasses entities deemed to be significantly engaged in financial activities including, but not limited to, companies that originate residential and commercial loans, broker such loans, service such loans, and participate in debt collection.

A financial institution’s obligations under the Act, depends, in part, on whether its clients are “customers” or “consumers.” The Act defines a “consumer” as an individual (or that individual’s legal representative) who obtains or has obtained a financial product or service that is used primarily for personal, family, or household purposes from the institution. Examples of consumer relationships include making a wire transfer or applying for a loan (whether or not the individual actually obtains the loan). Meanwhile, “customers” are a subclass of consumers that maintain a continuing relationship with the institution whereby the institution provides them with one or more financial products or services, which are used primarily for personal, family, or household purposes. For example, a customer relationship may be established when a consumer maintains a deposit, investment or credit card account with the institution or obtains a loan from the institution. However, there is a special rule for with regard to loans; when a financial institution sells the servicing rights to a loan to another financial institution, the customer relationship transfers with the servicing rights. Any information on the borrower retained by the institution that sells the servicing rights must be accorded the protections due any consumer though.

In general, the Act prohibits “financial institutions” from disclosing NPI about their customers to nonaffiliated third parties, unless the institution satisfies various notice and opt-out requirements, and the customer has not elected to opt-out of the disclosure. Consumers who are not customers are only entitled to an initial privacy and opt-out notice if their financial institution wants to share their NPI with nonaffiliated third parties outside of some outlined exceptions.

NPI consists of:

  • any information an individual provides to us to obtain a financial product or service (i.e., name, address, income, Social Security number, or other information on an application);
  • any information about an individual resulting from a transaction involving our financial products or services (i.e., the fact that an individual is our consumer or customer, account numbers, payment history, loan or deposit balances, and credit or debit card purchases); or
  • any information obtained about an individual in connection with providing a financial product or service (i.e., information from court records or from a consumer report).

NPI does not include information that is “publically available”. Information is publicly available if an institution has a reasonable basis to believe that the information is lawfully made available to the general public from government records, widely distributed media, or legally required disclosures in the public domain (i.e., information in a telephone book or a publicly recorded document, such as a mortgage or securities filing). In addition to the Act, the Company's email and SMS communications with customers are governed by the CAN-SPAM Act (15 U.S.C. §7701 et seq.) and the Telephone Consumer Protection Act (47 U.S.C. § 227), respectively.

anchor

RECOGNITION OF A CUSTOMER’S EXPECTATION OF PRIVACY

Safeguarding our customer’s financial information and maintaining customer privacy is of utmost importance to American Financial Network Inc. Our policy is to recognize and respect our customers’ expectation that their personal and financial information will be kept confidential. Each customer has the right to expect that his or her information will be protected and only used in an appropriate business manner.

anchor

USE, COLLECTION, AND RETENTION OF CUSTOMER INFORMATION

We collect, retain, and use information about individual customers only when and to the extent we believe the information would be useful (and allowed by law) to administer our business and provide products, services, and other opportunities to our customers.

The Company collects NPI about its customers from the following sources:

  • Information we receive on applications or other forms;
  • Information about transactions with us or others; and
  • Information we receive from a consumer reporting agency or other outside sources regarding verification of information provided by the consumer or from which the consumer has expressly given the Company permission to obtain information.

We only use the NPI collected to handle the customer’s request for specific services. We do not collect information about customers from third parties without a valid reason. In some cases, we gather information to comply with laws and regulations governing our industry. For example, federal regulations require us to obtain a tax identification number (generally a social security number) for some loans, so that we can report interest paid.

We also use some of the data we collect to maintain the security of customer account(s) and to protect the privacy of the financial information. We must be able to positively identify our customers and prevent access by unauthorized individuals.

California Online Privacy Protection Act Compliance

Because we value your privacy we have taken the necessary precautions to be in compliance with the California Online Privacy Protection Act. We therefore will not distribute your personal information to outside parties without your consent. Children's Online Privacy Protection Act Compliance. We are in compliance with the requirements of COPPA (Children's Online Privacy Protection Act), we do not collect any information from anyone under 13 years of age. Our website, products and services are all directed to people who are at least 13 years old or older.

anchor

MAINTENANCE OF ACCURATE INFORMATION

The Company will attempt to keep customer files complete, up-to-date, and accurate in accordance with reasonable commercial standards. We will tell our customers how and where to conveniently access their account information (except when prohibited by law) and how to notify us about errors. We will quickly respond to any request that we correct inaccurate information. We will take prompt action to make the appropriate corrections and to notify anyone with whom we may have shared inaccurate information.

anchor

LIMITING EMPLOYEE ACCESS TO INFORMATION

When conducting business, employees may obtain access to confidential information about the Company and its customers. We limit employee access to personally identifiable information to those employees with a business reason for knowing the information. Employees who possess such confidential and/or proprietary information must understand that it has been given to them for an expressed, permissible business purpose, and may only be disclosed on a need-to-know basis and for that business purpose. Discretion must be used when disclosing confidential information – it must never be disseminated to unauthorized persons including employees that do not have a need-to-know basis for the information.

We regularly conduct training sessions and otherwise educate our employees so they understand the importance of confidentiality and customer privacy. We maintain physical, electronic and procedural safeguards that comply with federal regulations to guard your nonpublic personal information, including but not limited to, requiring all documents containing NPI to be secured in locked cabinets or file drawers when not in use, utilizing shredders and/or confidentiality bins for disposal of NPI when no longer needed, and conducting periodic sweeps of work areas to ensure compliance with the Policy.

Misuse of confidential information may result in civil or criminal liability, or in sanctions or penalties against both the Company and the individual responsible for the misuse of such information. The Company will take disciplinary measures to enforce our employees’ privacy responsibilities.

anchor

SHARING CUSTOMER INFORMATION

The Company does not disclose any NPI about customers or former customers to anyone, except as permitted by law. For example, we are required to share financial information with parties named in a lawsuit or administrative action when we are served with a subpoena or court order and with federal or state regulatory authorities, such as banking examiners or the Internal Revenue Service, as authorized by federal or state law. Consistent with the practice of other institutions, we also share information with reputable credit reporting agencies as authorized under federal law and with others who may receive certain information from us under particular circumstances, but only as lawfully permitted or required.

We require our third party service providers to disclose and detail their electronic security measures for review and as part of our vendor compliance procedures. The service providers acting on our behalf and with exposure to customers’ NPI are contractually obligated to keep the information we provide to them confidential, and only use such information to provide the services we request from them.

anchor

COMMUNICATIONS PREFERENCES

The Company communicates withcustomers by email and SMS/text message in connection with their accounts andloans. These communications fall into two categories:

  • Marketing Communications. These include promotional or advertising messages sent through the Company's customer relationship management (CRM) system. Customers may opt out of marketing emails, SMS, and/or phone communications at any time using the Company's opt-out form. Once a customer opts out of marketing SMS through the CRM, the Company will not send further marketing text messages to that customer.
  • Transactional Communications.These include loan status updates, condition and documentation requests,underwriting or compliance notices, closing coordination, required disclosures,and other communications reasonably necessary to service, process, or close acustomer's loan. The Company may continue to send transactional emailsregardless of a customer's marketing opt-out election, consistent with theCAN-SPAM Act.

For SMS specifically,transactional text messages related to an individual loan file are sent onlywhere the customer has elected to receive SMS communications for that loan. Acustomer's general marketing SMS opt-out (or opt-in) status in the Company's CRMdoes not automatically apply to, or override, the customer's separate electionfor a specific loan, and vice versa. Customers may revoke consent totransactional SMS for a given loan at any time by replying "STOP" toany message or by contacting their Company representative, consistent with theTelephone Consumer Protection Act and applicable FCC guidance. Customers whorevoke SMS consent remain responsible for monitoring loan status through otheravailable channels, such as email or direct contact with their Company representative.

CONSENT TO RECEIVE ELECTRONIC LOAN DOCUMENTS

Federal and state law requirethat customers be provided certain disclosures, records, notifications, anddocuments ("Loan Documents") over the course of a loan transaction.Customers have the option of receiving Loan Documents either physically orelectronically. Electronic delivery of Loan Documents is offered through athird-party service provider and is subject to the customer's consent,consistent with the Electronic Signatures in Global and National Commerce Act(E-SIGN Act, 15 U.S.C. § 7001 et seq.).

A customer's consent toelectronic delivery applies only to the specific loan transaction for which itis given and does not carry over to any other or subsequent loan transaction.

Customers may withdraw consent toreceive Loan Documents electronically at any time, without charge. To withdrawconsent or to update contact information (including email address), customersmust send a written request to:

American Financial Network, Inc. DBA: Orion Lending
3070 Bristol St. Suite 200
Costa Mesa, CA 92626

Customers have the right torequest and obtain a paper version of any electronically-delivered LoanDocument at no charge, even if they previously consented to electronic deliveryand later withdrew that consent.

This electronic delivery andconsent process is administered separately from the Company's CRM-based emailand SMS communications described under Communications Preferences above.

anchor

PRIVACY NOTICE

The Company utilizes the model privacy form located in the Appendix to Regulation P, 12 CFR, Part 1016, Privacy of Consumer Financial Information. In regard to completing this form the Company will ensure the following:

  • It provides “Yes” or “No” responses for the disclosure table that accurately reflect its information sharing policies and practices;
  • It provides one of the following three responses in the right column of the disclosure table that reflects whether a consumer can limit such sharing: “Yes” if it is required to or voluntarily provides an opt-out; “No” if it does not provide an opt-out; or “We don't share” if it answers “No” in the middle column;
  • If the Company provides an opt-out, it will include a "To Limit Sharing" section with a direct link to the Company's opt-out form. This form allows consumers to opt out of marketing email, SMS, and/or phone communications. Click here to view Opt-Out Form.
    • This opt-out does not apply to transactional or relationship communications — such as loan status updates, condition and documentation requests, underwriting or compliance notices, closing coordination, and other communications reasonably necessary to service, process, or close an active loan. The Company may continue to send these communications regardless of a consumer's marketing opt-out election, consistent with the CAN-SPAM Act and the Telephone Consumer Protection Act.
  • If the Company uses a website link it will ensure the link goes to an opt-out privacy policy page or that the website listed includes a clear and conspicuous link that directs the consumer to an opt-out page;
  • The Company does not indicate that it shares information with affiliates if it has no affiliates;
  • Orion Lending will reflect this as follows: “American Financial Network, Inc., DBA Orion Lending has no affiliates.”
  • That the Company’s nonaffiliates definition section is properly completed based on the fact that the Company does not share information with non-affiliates.
  • Orion Lending will reflect this as follows: “American Financial Network, Inc., DBA Orion Lending does not share with nonaffiliates so they can market to you.”
anchor

PROTECTION OF INFORMATION

The Company is committed to the security of its customers’ financial and personal information. All of our operational and data processing systems are in a secure environment that protects account information from being accessed by third parties. We maintain and grant access to customer information only in accordance with our internal security standards.

LET'S STAY CONNECTED!

Please complete the form found below so we can stay in touch.

Fields Market with * are REQUIRED. All other fields are optional.

Opt-Out Request

Communication should always be on your terms, and we’re here to support that. Please use the form below to make your selections.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.