Privacy overview
UMB Direct publishes this Privacy policy for people reviewing its information practices.
| Document | Privacy policy |
|---|---|
| Institution | UMB Direct |
Privacy Policy
UMB Direct details how to reach the privacy team with questions for customers in Kansas City, Missouri at umbdirects.us.com.
Updated
Effective January 15, 2025. This privacy policy establishes how UMB Direct collects, handles, safeguards, and discloses customer personal and transactional records across our online banking platforms, business cash management systems, and direct depository services.
1. Scope and Gramm-Leach-Bliley Act (GLBA) Annual Notice
UMB Direct, operating as a service of UMB Bank, n.a., provides this annual notice in compliance with the Gramm-Leach-Bliley Act (GLBA) and Regulation P. Financial institutions are mandated to explain how they handle nonpublic personal data. This document outlines the categories of nonpublic personal information collected from customers, the internal and external recipients of such records, and the practical methods individuals can use to limit specific distributions.
Under federal financial privacy rules, UMB Direct maintains distinct sharing categories. We distribute necessary account data to process routine settlements, execute consumer transfers, support ACH clearing runs, and counter unauthorized network intrusions. Customers possess the direct ability to opt out of non-essential marketing sharing with our corporate affiliates and external joint marketing partners. These non-essential disclosures focus primarily on non-depository investment offerings or secondary lending proposals.
Every active customer receives a privacy disclosure update annually through either secure electronic document notification or direct mail notice. If our institutional sharing practices change substantially, an advance notice describing those adjustments arrives before any new data distribution takes place.
2. Customer Information Captured Across Central & Western U.S. Channels
UMB Direct gathers data across Kansas, Missouri, and surrounding regional markets to service checking, savings, commercial treasury, and digital payment accounts reliably. We acquire personal identifiers when an individual registers an account or submits an inquiry. These records include government tax identification numbers, physical street addresses, telephone contacts, legal names, and official state credential numbers.
Financial data points and ongoing transaction histories accumulate through routine usage of our platforms. Our ledgers register internal account figures, deposit amounts, merchant debit settlement logs, wire instructions, and ACH return codes within our corporate cash-management systems. When commercial administrators review processing reports or manage bulk payroll, these granular identifiers confirm operational legitimacy.
Online interactions via desktop portals or the UMB Mobile Deposit Business application generate technical device records. Network servers capture your client IP address, operating system architecture, browser fingerprint, session timestamps, and device identifiers. In addition, UMB Direct receives credit bureau evaluations and secondary fraud scores from consumer reporting agencies to verify applicant backgrounds during initial underwriting.
3. Operational and Transactional Uses of Customer Data
UMB Direct uses customer information to maintain deposit balances, clear checks, and execute day-to-day fund movements across domestic settlement lines. Account servicing requires ongoing balance calculations, generation of periodic account disclosures, and routing of funds through automated clearing houses. Deposit holdings with UMB Direct remain insured by the Federal Deposit Insurance Corporation (FDIC) up to established regulatory caps per ownership category.
Fraud mitigation and defensive identity validation represent primary operational purposes for processing collected data. Analytical security routines evaluate device telemetry and geographic parameters during sign-in attempts to prevent account takeover. When anomalous funds transfers arise, automated systems cross-check login behavior and device signatures against historical baselines before authorizing release.
We also process client metrics to satisfy regulatory compliance requirements, underwrite lending requests, and evaluate commercial credit profiles under NMLS 417539. Transaction data helps evaluate operational performance, eliminate user interface bottlenecks, and occasionally deliver promotional notices regarding specialized treasury management features suited to regional enterprises.
4. Institutional Sharing Boundaries and Safeguards
UMB Direct shares nonpublic personal information strictly within defined statutory boundaries to process customer transactions and service ongoing deposit relationships. We partner with operational service providers who deliver secure core banking technology, statement rendering, check imaging, and specialized transaction routing. Every third-party contractor operates under binding confidentiality terms that ban any secondary use of financial records beyond the exact services we contract them to handle.
Affiliate sharing within our corporate banking family remains restricted to standard administrative, internal auditing, and operational support tasks. When mandated by federal banking regulators, the Financial Crimes Enforcement Network (FinCEN), or lawful judicial orders, UMB Direct produces relevant customer logs to satisfy legal subpoenas, statutory court directives, and formal examination requirements.
We maintain clear red lines regarding customer data distribution. UMB Direct does not sell customer personal information to third parties or unaffiliated buyers under any circumstance. We never trade customer contact lists to external telemarketing firms or disclose transaction profiles to unauthorized aggregators.
5. Direct Privacy Controls and Opt-Out Protocols
Customers retain explicit controls over how their profile details are used for discretionary marketing and secondary data exchange. You may limit our sharing of creditworthiness profiles among corporate affiliates for promotional pitches regarding secondary financial products. Customers can decline promotional announcements delivered through physical mail, telephone calls, or digital notifications by updating profile preferences.
Within digital banking, alerts for Privacy Policy activity and transaction thresholds can be configured directly in online settings. Modifying security alerts ensures you receive real-time updates whenever profile data changes or unknown devices connect. If you observe errors within your personal file or account records, you may request prompt factual revisions by contacting client service teams directly.
Electing to limit voluntary marketing distributions will never alter your fundamental banking services or account fees. Routine service notifications, regulatory disclosures, monthly account statements, and critical security warnings will continue to arrive regardless of your marketing opt-out elections.
6. California Consumer Privacy Act (CCPA) Disclosures
Consumers residing in California maintain specific data oversight privileges under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). It is important to emphasize that personal information collected, processed, or disclosed pursuant to the federal Gramm-Leach-Bliley Act falls outside the scope of CCPA consumer rights. However, for non-GLBA records collected through our public website or direct commercial marketing, California residents hold defined statutory options.
Eligible individuals may ask us to disclose the exact categories of personal data collected, and the operational reasons for maintaining that information over the preceding twelve months. You can request that we delete qualifying personal records held outside statutory banking retention mandates.us.com. Verification protocols require matching two to three institutional data points, such as legal name, past transaction parameters, and verified contact addresses, to safeguard against unauthorized disclosures.
7. Digital Tracking, Telemetry, and Browser Cookies
UMB Direct deploys small digital text markers known as cookies alongside server-level tracking tools to secure web sessions and optimize navigation. When you sign in to online banking, temporary session markers authenticate your credentials and prevent unauthorized cross-site data manipulation. These session files disappear completely once you log out of your dashboard or close your browser program.
We also use persistent cookies to help web servers remember your geographic preferences, regional site configurations, and returning device authentications across multiple visits. Persistent cookies remain stored on your physical drive until their set lifespan expires or you clear your browser cache. Analytical measurement tools monitor visitor flows across our informational pages, recording aggregated dwell times, search paths, and bounce rates without attaching individual identity profiles to public visitors.
Browser software permits users to block cookies, clear cache archives, or issue automated Do Not Track signals. Because our digital banking security architecture relies upon authenticated session tokens for user verification, blocking technical cookies will impair online banking functionality. Informational marketing pages remain accessible even if tracking tools are manually disabled in your browser settings.
8. Technical Safeguards and Network Defense Systems
Protecting customer financial assets and personal databases requires strong, layered defense controls. UMB Direct implements Transport Layer Security (TLS) encryption to protect all electronic transmissions passing between your client browser and our host servers. Sensitive internal data repositories remain guarded behind redundant perimeter firewalls, network intrusion detection systems, and dedicated hardware security modules.
Access controls enforce the principle of least privilege across our workforce. Bank employees receive permission to view customer files only when essential for resolving specific customer inquiries, underwriting accounts, or balancing system records. Personnel complete recurring data privacy and operational information security training, reinforcing strict procedures for safeguarding confidential data.
Our institutional incident response protocols outline clear actions if unauthorized network events arise. Dedicated security teams monitor system logs continuously, investigate unusual behavioral indicators, and execute pre-approved mitigation procedures. If an incident compromises unencrypted customer records, we issue timely notices to affected account holders and relevant regulatory authorities in full alignment with state and federal legal obligations.
9. Protection of Children's Digital Privacy
Protecting youth privacy on the internet is a fundamental compliance responsibility. UMB Direct does not target marketing materials to, nor knowingly gather personal identifying records from, children under 13 years of age. Our online banking portals, mobile utilities, and public informational web pages are designed exclusively for legal adult consumers and authorized corporate representatives.
In adherence to the Children's Online Privacy Protection Act (COPPA), our systems do not intentionally process names, email addresses, or location markers belonging to minors under 13. If an individual under 13 provides personal records without verified parental authorization, our technical team purges the stored records immediately upon identification. Parents or legal guardians who suspect a minor has submitted personal identifiers to our platform should notify our privacy personnel right away.
10. Record Retention Policies and Secure Disposal Methods
UMB Direct preserves customer files and transaction logs in compliance with federal banking regulations, state financial statutes, and internal audit requirements. The Bank Secrecy Act (BSA) and anti-money laundering frameworks mandate that depository institutions retain customer identification profiles, check images, electronic fund transfer logs, and deposit records for at least five to seven years following account closure. Certain legal agreements and tax accounting documentation require extended retention periods.
Once statutory retention windows expire and records no longer serve operational or legal purposes, we dispose of them systematically. Physical paper documents pass through cross-cut industrial shredding systems to render the raw fibers completely illegible. Electronic files, database archives, and magnetic media undergo multi-pass digital sanitization or physical degaussing in accordance with National Institute of Standards and Technology (NIST) destruction recommendations.
11. Revisions and Amendments to This Policy
UMB Direct reviews this privacy policy continuously to match evolving data processing practices, emerging digital banking tools, and changing state or federal regulations. When structural alterations occur, we revise the effective date placed at the beginning of this disclosure document. Minor editorial adjustments take effect immediately upon digital publication across our public web address.
For material revisions that affect sharing categories or expand the scope of collected nonpublic records, UMB Direct provides prominent notice to customers in Missouri, Kansas, and our neighboring markets prior to activating the changes. We deliver these notifications through direct electronic messages inside your secure banking portal, account statement enclosures, or physical postal mailings. Continued utilization of our deposit accounts, digital interfaces — or commercial cash management utilities after the effective date of an update confirms your acknowledgment of the revised policy terms.
12. Privacy Office and Customer Communication Details
If you have specific inquiries concerning this privacy policy, require details regarding our GLBA disclosures, or wish to submit an opt-out request, reach out directly to our compliance department. Our customer service and privacy representatives are equipped to handle questions regarding personal data administration, account records verification, and regional privacy rights.
- Entity Name: UMB Direct (UMB Bank, n.a.)
- Primary Phone: +1-800-860-4862
- Support Email: [email protected]
- Nationwide Multistate Licensing System Identifier: NMLS 417539
- Headquarters & Mailing Address: Privacy Officer, UMB Direct, 1010 Grand Boulevard, Kansas City, Missouri 64106
Our client service lines remain open Monday through Friday during standard regional business hours. If you communicate via email, please refrain from including unencrypted tax identification numbers or sensitive account credentials within standard message text.