Privacy Policy
At PointsTrail.com, we are committed to protecting your personal data and ensuring compliance with privacy laws across the U.S. This Privacy Policy outlines how we collect, use, and safeguard your personal data in accordance with state-specific laws (e.g., California CCPA/CPRA, Virginia Consumer Data Protection Act), sector-specific federal laws (e.g., HIPAA, Gramm-Leach-Bliley Act), and Federal Trade Commission (FTC) guidelines. By using our services, you agree to the practices described in this Privacy Policy.
INTRODUCTION
This Privacy Policy applies to all users of PointsTrail.com. It explains how we collect, process, and protect your personal data and details your rights under various state and federal laws.
For questions, complaints, or to exercise your privacy rights, please contact our Data Protection Officer (DPO) at info@pointstrail.com.
What personal data is collected by PointsTrail
By using PointsTrail services, you provide us with, and we collect, certain personal data relating to you. From the moment you interact with PointsTrail, we collect your personal data. In some cases, you directly provide your personal data to PointsTrail, but we may also collect your data automatically.
In addition, we also receive some personal data sent by partners that we hire for specific purposes, so that we can comply with legal obligations or applicable regulations and others that will be detailed later.
By accepting the terms of this Privacy Policy, you expressly agree to provide only true, current and accurate personal data and not to change your identity or your personal data in any way when accessing and using our products or services. You will be solely responsible for false, outdated or inaccurate information that you provide directly to PointsTrail.
These are your personal data processed by PointsTrail, divided by categories:
Personal data that may be requested and informed by the holder:
-
Personal identification information: name, email and SSN/ITIN
-
Personal details: age, marital status and gender of the user
-
Family situation: who you live with
-
Education
-
Work situation: whether you are self-employed, self-employed, unemployed, employed or retired
-
Habits of consumption
-
Financial situation: if you are negative or with some financial restriction
Personal data we collect from third parties:
-
Registration data, such as: name, date of birth, SSN/ITIN, telephone number and address
-
Data on financial restrictions, such as: negatives, amounts due and due dates
-
Credit history information
-
Score generated by credit bureaus
-
Information on debts falling due or overdue, co-obligations and guarantees
Browsing and device data:
-
IP address of the mobile device used to access
-
Interactions made and website usage profile
-
Technical data, such as URL, network connection, provider, and device information
-
Cookies
-
Device attributes such as ID, operating system, browser, and model
-
Device geolocation data if you authorize collection from your device
-
Application access logs
-
Date and time of use of the application
-
Navigation data, reflecting the areas visited
Personal data arising from the use of our services:
-
Contracting data for our services
-
Data for contracting credit operations with partners, such as personal loans, negotiation of amounts due and debt installments
-
Credit history
-
Customer service history
How PointsTrail uses your personal data
PointsTrail uses your personal data to be able to promote and offer the best products for you.
PointsTrail undertakes to continuously implement physical, technical and administrative information security measures in the processing of your personal data, in accordance with the best market practices. Therefore, we seek to protect your data against unauthorized access, accidental or unlawful situations of destruction, loss, alteration of communication or any form of inappropriate or unlawful treatment.
We detail below the purposes for which we use your personal data:
Personal data informed by the owner
Purposes:
-
The correct and precise identification of the user
-
Access to the services and products provided by PointsTrail
-
The analysis of the profile of users with the aim of disclosing and indicating the best products and information
-
Identification, authentication and verification of requirements
-
Answering requests and doubts
-
Contact by phone, email, SMS, WhatsApp, or other means
-
Improvement of the services provided by PointsTrail
-
Marketing and promotion of products and services from our partners
-
Credit protection
-
Prevention and resolution of technical or security problems
-
Fraud prevention
-
Compliance with legal or regulatory obligations
Personal Data We Collect From Third Parties
Purposes:
-
Improvement of products and services
-
Marketing and research
-
Credit protection
-
Compliance with legal or regulatory obligations
Browsing and device data
Purposes:
-
Service provision
-
Personalized product recommendations
-
Display of advertising
-
Behavior and usage analytics
-
Credit protection
-
Security monitoring
-
Fraud prevention
-
Compliance with legal or regulatory obligations
Personal data arising from the use of our partners’ products and services
Purposes:
-
Contract execution
-
Improvement and development of services
-
Marketing and promotional activities
-
Credit protection
-
Security and technical support
-
Compliance with legal obligations
Public data
Purposes:
-
Disclosure and promotion of PointsTrail products
-
Credit protection
-
Fraud prevention
-
Regulatory compliance
COMPLIANCE WITH STATE-SPECIFIC PRIVACY LAWS
We comply with privacy laws enacted in various states, including:
California (CCPA/CPRA)
-
Right to Know
-
Right to Delete
-
Right to Opt-Out
-
Limit use of Sensitive Data
Virginia (VCDPA) & Colorado (CPA)
-
Right to Access, Correct, and Delete
-
Right to Opt-Out of Targeted Ads or Profiling
-
Data Protection Assessments
Utah (UCPA) & Connecticut (CDPA)
-
Right to Opt-Out
-
Parental Consent for users under 16
FEDERAL LAW COMPLIANCE
HIPAA
If personal data relates to healthcare, we comply with HIPAA’s confidentiality and security requirements.
Gramm-Leach-Bliley Act (GLBA)
We protect financial data according to GLBA regulations.
COPPA
We do not knowingly collect data from children under 13.
FTC GUIDELINES
We follow FTC guidelines regarding:
-
Transparency
-
Fairness
-
Security
TCPA COMPLIANCE
We only contact you via phone/SMS if:
-
You opted in
-
You may opt out at any time
-
We respect the Do Not Call Registry
DATA USAGE
We share data with:
-
Trusted third-party service providers
-
Business partners (with consent)
-
Legal authorities (when required)
OPT-OUT AND DO-NOT-SELL REQUESTS
You may opt out of:
-
The sale of personal data
-
Targeted advertising
Use the “Do Not Sell My Personal Information” link on our website or email us at info@pointstrail.com.
SENSITIVE DATA PROCESSING
We only process sensitive personal data with your explicit consent, as required by law.
DATA SECURITY
We implement:
-
Encryption
-
Access controls
-
Continuous monitoring
No system is 100% secure, but we follow industry best practices.
DATA RETENTION
We retain data only as long as necessary, or as required by law. Data is securely deleted or anonymized thereafter.
COOKIES AND TRACKING TECHNOLOGIES
You may manage cookies in your browser. Disabling them may affect site functionality.
GOOGLE ADSENSE AND ANALYTICS
We use:
-
Google AdSense for personalized ads
-
Google Analytics for usage tracking
You may opt out via Google Ad Preferences.
DATA PROTECTION ASSESSMENTS
For high-risk processing, we conduct data protection assessments in line with state laws like VCDPA and CPA.
CHILDREN’S PRIVACY
We do not collect data from individuals under 18 years old. Contact us if you believe we have inadvertently done so.
INTERNATIONAL DATA TRANSFERS
If data is transferred outside the U.S., we ensure appropriate safeguards are in place.
CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy periodically. Material updates will be announced via email or a notice on the site.
CONTACT US
If you have any questions about this Privacy Policy or wish to exercise your privacy rights, please contact our Data Protection Officer (DPO):
Email: info@pointstrail.com
Last Updated: 08/30/2025