Effective Date: July 31, 2019
Mastercard: SunTrust Masterpass™ Mobile Application/SunTrust Masterpass™ Wallet/Masterpass Online™ Privacy Notice
Mastercard International Incorporated and its affiliates (“Mastercard”) and SunTrust Bank (collectively, “We” or “we”) respect your privacy. This Privacy Notice applies to the SunTrust Masterpass Mobile Application, the SunTrust Masterpass Wallet and/or Masterpass Online (collectively, “Masterpass Wallet Services”).
This Privacy Notice describes the types of personal data Mastercard and SunTrust Bank collect in connection with the Masterpass Wallet Services, the purposes for which we collect that personal data, the other parties with whom we may share it and the measures we take to protect the security of the data. It also tells you about your rights and choices with respect to your personal data, and how you can reach us to update your contact information or get answers to questions you may have about our privacy practices.
We want you to understand that Mastercard and SunTrust Bank jointly offer the Masterpass Wallet Services to you and by signing up for the Masterpass Wallet Services, you are creating a relationship with both Mastercard and SunTrust Bank. Mastercard operates the technical infrastructure of the Masterpass Wallet Services, so Mastercard and its affiliates and service providers will typically collect and process your personal data and information about your use of Masterpass Wallet Services. However, because this is a joint product offering by Mastercard and SunTrust Bank, Mastercard and SunTrust Bank will both have access to and will jointly use the personal data and information collected through your use of the Masterpass Wallet Services.
For most instances, entities responsible for the collection and use of your personal data in the context of the Masterpass Wallet Services are both:
Global Privacy Office
Mastercard International Incorporated
2000 Purchase Street
Atlanta, GA 30308
Purchase NY 10577
To the extent a single entity will be responsible for the collection and use of your personal data or information in the context of a particular aspect of the Masterpass Wallet Services, we will identify that throughout this Privacy Notice.
This Privacy Notice does not cover the collection and use of your personal data by third parties on the Masterpass Wallet Services, such as merchants, on other Mastercard branded websites or products, on other SunTrust Bank branded websites or products, or any other information or communications that may reference Mastercard or SunTrust Bank outside the Masterpass Wallet Services. For more information about Mastercard’s privacy practices, visit Mastercard’s. For more information about SunTrust Bank’s privacy program, please visit .
Click on one of the links below to jump to the listed section:
We collect data in a number of ways when you use the Masterpass Wallet Services: personal data provided by you; personal data provided by participating merchants; personal data provided by the issuer of your payment cards or other financial institutions; personal data we collect automatically; and personal data provided by you in connection with other Masterpass mobile wallets on your device. By personal data we mean “any information relating to an identified or identifiable natural person.”
If you have more than one Masterpass mobile application with an active account on your mobile device, we may also present data from each Masterpass account to you when making a purchase at a participating merchant to help you choose how you would like to pay. To learn more, see Section 1(e), below.
· Personal Data Provided by You
In connection with your use of Masterpass Wallet Services, we may ask you for certain personal data upon registration, on applications forms or other forms, such as your name, home address, billing address, shipping address, telephone number, email address, national identity card number in some instances, user name, password, answers to our security questions, loyalty card information and payment card information. This personal data will be initially collected and processed by Mastercard and its affiliates and service providers, as the technical operator of the Masterpass infrastructure, but it will be shared and used jointly by SunTrust Bank and Mastercard in accordance with this Privacy Notice.
The provision of your personal data for the purposes listed below is voluntary. However, in some circumstances, withholding your personal data will mean that you cannot take advantage of certain products or services.
· Personal Data Provided by Participating Merchants in Connection with Your Use of the Masterpass Wallet
We receive certain data from merchants about your transactions using the Masterpass Wallet Services, including but not limited to, stock-keeping unit data, description of items, quantity, price and subtotal and payment cards registered with the Masterpass Wallet, merchant name, currency, amount, date and time of order and information about whether or not the order was completed. If you have an account on file with the merchant, they may also provide us with your shipping address.
This data will be initially collected and processed by Mastercard and its affiliates and service providers, as the technical operator of the Masterpass infrastructure, but it will be shared and used jointly by SunTrust Bank and Mastercard in accordance with this Privacy Notice.
· Personal Data Provided by the Issuer of Your Registered Payment Card or Other Financial Institutions
When you register a payment card with the Masterpass Wallet, Mastercard, as the operator of the Masterpass technical infrastructure, may send information to the issuer of that card to validate the card, authenticate your identity and tokenize your payment credentials to make your payments more secure. This information may include your name, payment card information, billing address, information about your mobile device and information about how you registered your payment cards in your Masterpass Wallet. To facilitate the validation/authentication/tokenization process, Mastercard may receive personal data about you back from the issuer of your payment card. In addition, when you make payments using tokenized credentials via the Masterpass Wallet, Mastercard receives data about the token and the transaction back from the issuer of your payment card.
In addition, in some instances, Mastercard may receive data about you from your financial institution in order to help ensure you create the correct Masterpass wallet. For example, your financial institution may provide Mastercard with your email address or phone number in an encrypted, protected form. When you click on the “Buy With Masterpass” button at a merchant or otherwise sign-up or sign-in for a wallet, you will be asked for your email or phone number. If the information you provide matches the information provided by your financial institution, you may be directed to a specific Masterpass wallet relating to that financial institution
· Personal Data We Collect Automatically
Overview: When you interact with the Masterpass Wallet Services, or visit the Masterpass websites, pages or other digital assets, certain information may be collected by using automated means, such as cookies and web beacons. Mastercard, together with its affiliates and service providers, as the technical operator of the Masterpass Wallet Services, is the entity collecting this information. However, this information may be shared with SunTrust Bank and used jointly by Mastercard and SunTrust Bank for any of the purposes identified in this Privacy Notice.
The information collected in this manner may include: IP address, mobile device IP address, mobile device unique identifier, browser type and setting data (such as screen resolution, color depth, time zone settings, browser extension and plugins, fonts, etc), operating system, referring URLs and information on actions taken or interaction with our digital assets. A “cookie” is a text file placed on a computer’s hard drive by a web server. A “web beacon,” also known as an Internet tag, pixel tag or clear GIF, is used to transmit information back to a web server.
Browser Data: In addition to the above, Mastercard and its service providers, may automatically collect browser data from your device. Browser data consists of information about settings on the configuration of the browser you use to access the Masterpass Wallet Services. This may include screen resolution and color depth, time zone settings, browser extensions and plugs installed in the browser and versions thereof, fonts installed on the browser, the user agent string and other similar data. This data is used to create a unique fingerprint of the browser used to access Masterpass Online to remember the choices made by that browser and to assist in preventing fraud and enhancing the security of the Masterpass Wallet Services. Mastercard may offer users of our Masterpass Wallet Services choices to opt-out of the collection and fingerprinting of browser data via our Cookie Consent Tool.
Third Party Analytics: Mastercard may use third-party web analytics services, such as those of Adobe Omniture. The analytics providers that administer these services use technologies such as cookies and web beacons to help analyze how visitors use the Masterpass Wallet Services. In the Masterpass Mobile Application, you can turn off Adobe Omniture web analytics. In the United States, you can also opt-out of analytics on the Masterpass Online websites via the AdChoices icon on both the Masterpass website and the SunTrust Masterpass Wallet website. Please see the “Your Rights and Choices” section of this Privacy Notice to learn about your ability to opt out or limit the use of your browsing behavior for online behavioral advertising purposes.
Pixels. When emails are sent to people with a Masterpass Wallet account, Mastercard may track behavior such as who opened the emails and who clicked the links. Mastercard does that to measure the performance of the emails and to improve the product features. To do this, Mastercard includes single pixel gifs, also called web beacons, in the emails it sends. Web beacons allow Mastercard to collect information about whether an email has been opened and the number of clicks inside that email. Mastercard uses the data from those web beacons to create the reports about how email campaigns performed and what actions individuals took within the email (e.g. links clicked). If you do not wish for us to track emails we send you, some email services allow you to adjust your display to turn off HTML or disable download of images which should effectively disable our email tracking.
Customized Checkout: Mastercard may use information about your use of the Masterpass wallet, or which Masterpass Wallet you use, in order to deliver you a customized merchant checkout experience. After making a Masterpass transaction, Mastercard may drop a cookie on your device that will provide a customized Masterpass checkout button on merchant websites based on which Masterpass Wallet you use, or, in some instances, which payment card you used for that transaction. This will deliver a more seamless consumer Masterpass experience. Merchants are not able to access this information. Please see the “Your Rights and Choices” section of this Privacy Notice to learn about your ability to opt out the customized checkout experience.
· Personal Data Presented from Your Other Masterpass Wallets on the Device
If you are using the Masterpass Wallet Services on an eligible device, when you click on the “Buy With Masterpass” button to make a payment using a participating merchant’s mobile application, technology through the Masterpass Wallet Services will scan your mobile device to see if any certified Masterpass mobile applications are loaded on the device. If so, during the checkout flow at the Participating Merchant, you may be presented with a list of each such Masterpass wallet and the registered payment cards for such wallets so you can choose which Masterpass wallet and payment card you would like to use for that transaction.
We may use the personal data we obtain about you to:
· Create, manage and personalize your online account (including providing you with a transaction history), provide our products and services, and respond to your inquiries;
· Route you to the appropriate Masterpass wallet based on whether you have an existing Masterpass wallet relationship or an existing banking relationship with a participating issuer;
· Validate your payment card information, authenticate your identity with your bank and tokenize your payment credentials to make your payments more secure;
· Provide a customized checkout experience;
· Create a view that shows you all of your eligible Masterpass wallet accounts, including this Masterpass Wallet, and each account’s registered payment cards, when you click on the “Buy with Masterpass” button via a participating merchant’s mobile application;
· Provide reporting back to the issuer of your enrolled payment cards and the merchants you transact with via the Masterpass Wallet Services;
· Anonymize personal information and prepare and furnish aggregated data reports showing anonymized information, (including, but not limited to, the following: compilations, analyses, analytical and predictive models and rules, and other aggregated reports);
· Perform data analyses (including anonymization of personal information) to determine, among other measurements, business performance, number of registrants, channels, transaction spend and site performance;
· Provide, administer and communicate with you about products, services and promotions (including contests, sweepstakes, programs and other offers), including the display of customized content and advertising via the Masterpass Wallet Services and elsewhere online;
· Protect against and prevent fraud, unauthorized transactions, claims and other liabilities, and manage risk exposure and franchise quality;
· Operate, audit, evaluate, monitor and improve our business and interactive assets (including by developing new products and services; managing our communications; determining the effectiveness of and optimizing our advertising; analyzing our products, services and websites; facilitating the functionality of our websites; and performing accounting, auditing, billing, reconciliation and collection activities);
· Assist third parties in the provision of products or services that you request;
· Enforce our Masterpass Wallet Consumer ;
· As may be required by applicable laws and regulations or requested by any judicial process or governmental agency having or claiming jurisdiction over Mastercard or Mastercard’s affiliate
· Comply with industry standards and our individual policies
We also may use the information in other ways for which we provide specific notice at the time of collection.
We do not sell or otherwise disclose personal data we collect about you, except as described in this Privacy Notice or otherwise disclose to you at the time the data is collected. In particular, your personal data may be shared:
· Between Mastercard and SunTrust Bank and with our respective affiliates and service providers in order to provide the Masterpass Wallet Services and for the purposes described above.
· With third parties that help facilitate the checkout experience or otherwise support your use of the Masterpass Wallet Services to complete the actions you initiate.
· With merchants and their service providers to perform and/or facilitate payment card transactions (including via Near Field Communication (NFC) and other contactless payment technology), to ensure the safety and security of those transactions (including card fraud detection and prevention), to resolve disputes, provide customer service, usage analysis and reporting and to provide the Masterpass Wallet Services that you request. Please note that merchants and their service providers may have their own privacy policies governing how they use and disclose personal data. We recommend that you review privacy policies of the companies you interact with to learn about their practices.
· In addition, if you elect to connect your wallet to a merchant, we will provide personal data to that merchant in order to personalize your shopping experience and/or facilitate faster check-outs. In such instances, merchants are not permitted to use your data for any other purpose.
· With financial institutions and their service providers to perform and/or facilitate payment card transactions (including via NFC and other contactless payment technology), to ensure the safety and security of those transactions (including card fraud detection and prevention), to authenticate and identity you and the payment cards you register with the Masterpass Wallet, to tokenize your payment credentials, to resolve disputes, provide customer service, usage analysis and reporting and to provide the Masterpass Wallet Services that you request. Please note that financial institutions and their service providers may have their own privacy policies governing how they use and disclose personal data. We recommend that you review privacy policies of the companies you interact with to learn about their practices.
· With our respective service providers who perform services on our behalf. We do not authorize these service providers to use or disclose the data except as necessary to perform certain services on our behalf or comply with legal requirements. We require these service providers by contract to appropriately safeguard the privacy and security of personal data they process on our behalf.
· In the event Mastercard or SunTrust Bank sells or transfers all or a portion of our respective business or assets. Should such a sale or transfer occur, we will inform you in due course about the identity of the new data controller, as well as of the details about how you may exercise your rights of access, correction and suppression after the sale or transfer has taken place, and we will use reasonable efforts to direct the transferee to use personal information you have provided to us in a manner that is consistent with this Privacy Notice.
· If we are required to do so by law or legal process, (ii) to law enforcement authorities or other government officials, or (iii) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss, or in connection with an investigation of suspected or actual fraudulent or illegal activity.
· Otherwise with your consent.
In addition, we also may share aggregated or anonymized data with third parties for any lawful purpose.
You may have certain rights under applicable law regarding the personal data we maintain about you. We offer you certain choices about what personal data we collect from you, how we use that information, and how we communicate with you.
· Account Information and Email Marketing Preferences: At any time, you can access your account by logging into your account. You can view or change your personal details and manage your marketing preferences here. You can at any time tell us not to send you marketing communications by e-mail by clicking on the unsubscribe links within the marketing e-mails you receive from us or by changing your settings on your preferences page on your account. You also may opt-out of receiving marketing e-mails from Mastercard by clicking here. You also may opt-out of receiving marketing e-mails from SunTrust Bank by clicking here. We will apply your preferences going forward. If you opt out via either method, you will no longer receive marketing communications relating to the Masterpass Wallet Services. In some circumstances, withdrawing your consent to our use or disclosure of your personal data will mean that you cannot take advantage of certain products or services.
· Third Party Analytics: As indicated above, Mastercard may use third-party web analytics services, such as those of Adobe Omniture, to analyze how you use the Masterpass Mobile Application, your usage of the Masterpass Online websites and other Mastercard websites. You can turn off the use of the analytics service inside the Masterpass Mobile Application by visiting “Settings” and turning off “Send Data.” In the United States, you can also opt-out of analytics on the Masterpass Online websites via the AdChoices icon on the Masterpass website and the SunTrust Masterpass Wallet website.
· Customized Checkout: If you have a customized checkout experience, you can opt-out of seeing a customized checkout button on merchant websites through the AdChoices icon on the Masterpass website and the SunTrust Masterpass Wallet website.
· Online Behavioral Advertising and Other Cookie Preferences: We may offer users of the Masterpass Wallet Services choices to manage their cookie preferences through the Cookie Consent tool displayed in the bottom right corner of the Masterpass websites or accessible via the AdChoices icon on the Masterpass website and the SunTrust Masterpass Wallet website. Your browser may tell you how to be notified and opt out of receiving certain types of cookies, including analytics and advertising cookies. Otherwise, you can opt out at http://www.aboutads.info/choices/. You can also opt out of some of Mastercard’s use of web analytics at this link usinghttps://www.Mastercard.com/us/personal/en/general/web-analytics-opt-out.html. To learn more about Cookies, please visit http://www.aboutads.info/choices/ or http://www.adobe.com/privacy/opt-out.html or our Cookies Notice available on Masterpass Online in the European Economic Region, Turkey, Switzerland and Canada.
Where required by law, Mastercard and SunTrust Bank obtain your prior opt-in consent at the time of collection for the processing of (i) personal data for marketing purposes, (ii) personal data deemed sensitive pursuant to applicable law, or (iii) personal data to be used for other data processing activities for which your consent may be required.
Subject to applicable law, you may have the right to request access to and receive information about the personal data we maintain about you, update and correct inaccuracies in your personal data, to object to the processing of your personal data and have the information blocked or deleted, as appropriate. The right to access personal information may be limited in some circumstances by local law requirements. To update your preferences, ask us to remove your information from our mailing lists or submit an access request, please contact us as specified in the “How to Contact Us” section below.
We maintain appropriate administrative, technical and physical safeguards to protect personal data against accidental or unlawful destruction, accidental loss, unauthorized alteration, unauthorized disclosure or access, misuse, and any other unlawful form of processing of the personal data in our possession. The types of measures we take vary with the type of data, and how it is collected and stored.
When you provide personal data online, we use the industry standard for encryption on the Internet – Secure Socket Layer (SSL) technology – to help protect the data that you provide. This Internet encryption standard scrambles data as it travels from your device to our server. You will know that you are in a secure area of the Site when a lock icon appears on your screen that the “http” prefix of our URL address changes to “https.” The “s” represents “secure”. We also use digital certificates to ensure that you are connected to the authentic Site.
We will never ask you for your password in any unsolicited communication (including unsolicited correspondence, such as letters, phone calls or e-mail messages). If you believe your user name and password have been compromised, please contact us by following the instructions provided in the section "How to Contact Us" below.
We also take measures to destroy or permanently de-identify personal data in the Masterpass Wallet Services when there is no longer a business need to keep the information.
We may transfer personal information to countries other than the country in which the data was originally collected. These countries may not have the same data protection laws as the country in which you initially provided the information. When we transfer your personal information to other countries, we will protect that information as described in this Privacy Notice.
Mastercard is a global business. To offer the Masterpass Wallet Services services, Mastercard may need to transfer your personal information among several countries, including the United States, where Mastercard is headquartered. Mastercard complies with applicable legal requirements providing adequate safeguards for the transfer of personal information to countries outside of the European Economic Area or Switzerland.
On our Site you may choose to use certain features for which we partner with other entities or click on links to other websites for your convenience and information. These features, which may include social networking and geographic location tools, and other websites may operate independently from Mastercard and SunTrust Bank. They may have their own privacy notices or policies, which we strongly suggest you review. To the extent any features or linked websites you visit are not owned or operated by Mastercard and SunTrust Bank, we are not responsible for the sites’ content, any use of the sites, or the privacy practices of the sites.
Although the Masterpass Wallet Services currently do not have a mechanism to recognize the various web browser Do Not Track signals, we may offer users of our Masterpass Wallet Services choices to manage their preferences via our Cookie Consent Tool, we will honor your preferences. To learn more about browser tracking signals and Do Not Track, please visit http://www.allaboutdnt.com.
If you have any questions, comments or complaints about this Privacy Notice and our privacy practices, or would like to update your privacy preferences, please email us at: email@example.com or write to us at:
You may also contact Mastercard or SunTrust Bank by writing to:
Global Privacy Office
303 Peachtree St NE
Atlanta, GA 30308