Privacy Policy
Veridiancu is committed to protecting member privacy and safeguarding personal information. This privacy policy describes how member data is collected, used, shared, and secured across all Veridiancu banking services, digital platforms, and branch operations.
Commitment to Member Privacy
Veridiancu collects and manages personal information under a privacy framework designed to meet the requirements of federal financial privacy regulations, NCUA guidance, and the reasonable expectations of member-owners who entrust the credit union with sensitive financial data.
Veridiancu operates as a federally insured credit union under the regulatory oversight of the National Credit Union Administration. As a financial institution, Veridiancu is subject to the privacy provisions of the Gramm-Leach-Bliley Act and implementing regulations that govern how financial institutions collect, use, and disclose nonpublic personal information. This privacy policy serves as the required notice to members describing the credit union's information practices and the choices available to members regarding the sharing of their personal data.
The privacy obligations Veridiancu upholds extend beyond statutory minimums. Because the credit union is member-owned, the institution has a structural incentive to handle member data with care — there are no external shareholders to whom data could be monetized, and there is no ad-supported business model that would encourage the collection of behavioral data beyond what is required to operate deposit accounts, process loan applications, and deliver the banking services members have explicitly requested. The privacy policy detailed on this page reflects that member-first orientation, and it applies across all service channels: the Waterloo, Iowa branch at 1405 East San Marnan Drive, the Veridiancu online banking platform and mobile app, the Veridian Credit Union login portal, the Veridian credit card login portal, and any telephone or written communications with the credit union. Additional resources on financial privacy regulations are available at ncua.gov.
Information Collection Practices
Veridiancu collects personal information through member applications, account transactions, online interactions, and credit reporting agencies — but only the categories of data that are reasonably necessary to provide requested financial services and comply with applicable legal obligations.
Veridiancu collects personal information from several sources, each corresponding to a specific business need. When a member applies for an account, the credit union collects identification information including full legal name, date of birth, Social Security number, physical and mailing addresses, telephone numbers, email addresses, employment information, and income data as relevant to the type of account or loan being requested. This information supports identity verification under the USA PATRIOT Act Customer Identification Program requirements, credit underwriting when applicable, and ongoing account administration including billing statement delivery, tax reporting, and regulatory compliance.
Transaction information is generated whenever a member uses a Veridiancu account — deposits, withdrawals, transfers, debit card purchases, bill payments, wire transactions, and loan payments all create records that the credit union retains for account management, statement generation, and regulatory compliance purposes. Web and mobile application usage data, including IP addresses, browser types, device identifiers, pages visited, and session duration, is collected during interactions with the Veridiancu website and mobile app. This information supports fraud detection, platform performance monitoring, and user experience improvement. Veridiancu does not sell personal information to third parties, does not share personal information with non-affiliated third parties for their own marketing purposes, and does not use member transaction data to target marketing for products unrelated to the member's existing banking relationship.
Information Sharing and Disclosure
Veridiancu shares member information only under circumstances defined by law, regulation, or explicit member authorization — never for unrelated third-party commercial purposes or non-affiliated marketing campaigns.
Veridiancu may share personal information with service providers and business partners that perform essential operational functions on behalf of the credit union. These include check printing and statement processing vendors, payment network operators that process debit and credit card transactions, credit reporting agencies for loan underwriting and account review purposes, regulatory examiners and auditors conducting statutory oversight, and law enforcement agencies when presented with valid legal process such as a subpoena, court order, or search warrant. In each case, the information shared is limited to what is necessary for the specific function being performed, and service providers are contractually bound to maintain confidentiality, use data only for the specified purpose, and return or destroy data when the service engagement concludes.
Veridiancu does not disclose account numbers or access codes to non-affiliated third parties for telemarketing, direct mail marketing, or electronic marketing purposes. The credit union may, with member consent or as permitted by law, share information with affiliated financial service providers for the purpose of offering additional products that may interest the member — for example, sharing deposit account standing with the mortgage lending division to pre-qualify a member for a home equity product. Members who prefer to limit this type of affiliate sharing may submit a written opt-out request to Veridiancu at the Waterloo branch address, which will be honored within thirty days and remain in effect until the member provides written revocation. The Consumer Financial Protection Bureau provides additional guidance on financial privacy rights at consumerfinance.gov.
Data Security Measures
Veridiancu employs administrative, technical, and physical safeguards designed to protect member personal information against unauthorized access, disclosure, alteration, and destruction throughout the data lifecycle.
The security infrastructure protecting member data at Veridiancu operates across multiple layers. At the network perimeter, firewalls, intrusion detection systems, and distributed denial-of-service mitigation protect against external threats targeting the credit union's online banking platform and website. Data in transit between a member's browser or mobile device and Veridiancu servers is encrypted using Transport Layer Security protocols with current cipher suites that resist known attacks. Data at rest within the credit union's systems — account databases, transaction records, member correspondence — is protected by file-level and database-level encryption with access controls that restrict data visibility to employees whose job functions require it.
Employee access to member information follows the principle of least privilege. A teller processing a deposit does not have access to credit report data. A marketing analyst reviewing aggregate product usage does not see individually identifiable transaction records. The information security team conducts periodic access reviews, comparing active user permissions against current job responsibilities and revoking access that is no longer justified. All employee access to member data is logged, and the logs are subject to audit review. Veridiancu also maintains a formal incident response plan that defines procedures for containing, investigating, and notifying affected parties in the event of a data breach, in accordance with applicable state breach notification laws and NCUA reporting requirements.
Privacy Principles Summary
The core privacy principles Veridiancu follows can be summarized across five dimensions that govern how member information is handled from collection through eventual disposal.
| Privacy Principle | How Veridiancu Implements It | Member Impact |
|---|---|---|
| Collection Limitation | Only data necessary for account operation, identity verification, and legal compliance is collected | Members are not asked for information unrelated to banking services |
| Use Limitation | Member data is used exclusively for the purposes disclosed in this privacy policy | No repurposing of data for unanticipated secondary uses |
| Disclosure Control | Data is shared only with service providers, regulators, and as required by law | No sale of data to third parties or sharing for external marketing |
| Security Safeguards | Encryption, access controls, monitoring, and incident response protect data at all stages | Reasonable protection against unauthorized access and data breaches |
| Retention and Disposal | Records retained per regulatory schedules and securely destroyed when retention expires | Data is not kept indefinitely beyond its useful lifespan |
| Member Access and Correction | Members may review and request correction of personal information through written request | Members maintain visibility into and control over their own data |
These privacy principles are embedded in Veridiancu's operational procedures, employee training programs, and vendor management practices. New employees complete privacy and data security training during onboarding, and existing employees complete annual refresher training that covers updates to privacy regulations, emerging threat vectors, and changes to internal data handling procedures. The privacy policy itself is reviewed on an annual cycle and updated as necessary to reflect changes in applicable law, regulatory guidance, or the credit union's operational practices.
Online Privacy and Digital Services
When members use the Veridiancu website, online banking platform, or mobile app, additional data is generated through the normal operation of these digital services, and this section describes how that digital interaction data is handled under the privacy policy.
The Veridiancu website and associated digital properties use standard internet technologies including cookies, session identifiers, and analytics tools that record technical data about each visit. Session cookies maintain the authenticated state during a Veridian Credit Union login and expire when the browser is closed. Persistent cookies store user preferences such as display language and accessibility settings between visits, with a maximum lifespan of twelve months unless the member clears them earlier. Analytics scripts collect aggregated, de-identified data about page traffic patterns and platform performance — this data does not include account numbers, passwords, or individually identifiable financial transaction details. Members who prefer not to participate in analytics data collection may enable the Do Not Track setting in their browser, which the Veridiancu website respects for analytics purposes while continuing to use session cookies essential to secure online banking functionality.
The Veridiancu mobile app for iOS and Android generates device-level data that includes operating system version, device model, app version, and crash report data for debugging purposes. Location data is accessed only when the member actively uses the ATM locator feature; location is never tracked in the background or stored beyond the duration of the locator session. Push notification tokens are stored to deliver the account alerts that members have explicitly configured. Members can disable push notifications at any time through the app settings or the device operating system notification controls. No information collected through the mobile app is shared with third-party advertising networks, data brokers, or analytics providers — all mobile data processing occurs within systems controlled by Veridiancu or its contracted service providers under the same data protection terms that apply to core banking data.
Children's Privacy
Veridiancu complies with the Children's Online Privacy Protection Act and does not knowingly collect personal information from individuals under the age of thirteen through its website or digital platforms absent verifiable parental consent on a youth account application.
Veridiancu offers youth savings accounts that parents or legal guardians can open on behalf of minor children. The information collected for a youth account is limited to the child's name, date of birth, and Social Security number, and it is collected through a parent or guardian who acts as the joint account holder and provides the consent required under applicable law. Veridiancu does not use youth account data for marketing purposes directed at children, does not sell youth account data to third parties, and does not collect behavioral or browsing data on child users beyond what is necessary to operate the deposit account and comply with regulatory reporting obligations. Parents or guardians who wish to review, correct, or request deletion of their child's information may contact Veridiancu customer service at (319) 555-0147 or submit a written request to the Waterloo branch. The Federal Trade Commission provides guidance on children's privacy protections that supplements this policy at fdic.gov.
Member Rights and Contact Information
Members hold specific rights regarding their personal information under this privacy policy, including the right to review, request correction of, and in certain circumstances request deletion of personal data maintained by Veridiancu.
Veridiancu members may exercise the following rights by submitting a written request to the credit union's Waterloo headquarters at 1405 East San Marnan Drive, Waterloo, IA 50701, or by contacting Veridian customer service at (319) 555-0147. Members have the right to request a copy of the personal information Veridiancu maintains about them, subject to reasonable processing fees and identity verification requirements. Members have the right to request correction of inaccurate personal information, which Veridiancu will investigate and, where substantiated, correct within thirty business days of receiving a documented correction request. Members have the right to request deletion of personal information in certain circumstances, though Veridiancu may decline deletion requests where the information is necessary to maintain the member's active accounts, comply with legal record-retention requirements, prevent fraud, or protect the security of the credit union's systems.
Members who have questions about this privacy policy, who believe their privacy rights have been violated, or who wish to file a formal privacy complaint may do so through the channels listed above. Veridiancu is committed to resolving privacy concerns directly with affected members. Members who are not satisfied with the resolution of a privacy complaint may also contact the National Credit Union Administration through its consumer assistance center or the Iowa Division of Banking for matters involving state-chartered credit union operations. This privacy policy was last updated and posted on April 28, 2026, and supersedes all prior versions of the Veridiancu privacy policy.
The privacy notice I received when opening my accounts at Veridiancu was written in plain language that I could actually understand. That level of transparency about how my financial data is handled builds trust that keeps me here year after year.