SIONIC MOBILE
Privacy Policy
Effective Date: January 2, 2026 | Last Updated: June 25, 2026
Sionic Mobile Corporation (“Sionic,” “we,” “us,” or “our”) provides financial technology products and services, including Sionic Instant Bank Pay, our bank-to-bank payment technology that operates through The RTP® Network and the FedNow℠ Network (the “IBP Gateway”), the Fraud Detection Service (“FDS”), and the Bank Perks Pass. This Privacy Policy explains how we collect, use, share, and protect personal information in connection with our websites, mobile applications, and other products and services (collectively, our “Services”).
If you use the Bank Perks Pass, please also review our Bank Perks Pass Privacy Policy, which describes that feature in more detail and supplements this Policy.
This Policy describes Sionic’s own collection, use, and sharing of personal information through the Services. It does not apply to:
- The mobile banking app, website, or other products and services of any financial institution, credit union, or reseller partner that offers Sionic’s technology to its own customers (each, a “Financial Institution” or “Partner”), which are covered by that Financial Institution’s or Partner’s own privacy notices (see Section 10);
- Apple Wallet, Google Wallet, or other device or operating-system features generally, which are covered by Apple’s and Google’s own privacy policies; or
- Other websites or applications that link to or integrate with our Services but are not operated by Sionic.
This Policy is intended for individuals located in the United States. Sionic does not direct the Services to, and does not knowingly collect personal information from, individuals located outside the United States.
“Financial Institution” means a bank, credit union, or similar institution that works with Sionic to offer the Services to its customers, including by participating in The RTP Network and/or the FedNow Network. “Partner” means a reseller or other business partner that integrates Sionic’s technology into its own product or service offering. “Personal Information” means information that identifies, relates to, or could reasonably be linked, directly or indirectly, with you. “Services” means Sionic’s websites, mobile applications, Sionic Instant Bank Pay, the IBP Gateway, the FDS, the Bank Perks Pass, and Sionic’s other current products and services. “Third-Party Provider” means a vendor that Sionic engages in supporting the Services.
We may collect your name, contact information, account registration details, information needed to link a bank account, and any information you provide when you contact us for support or respond to a survey.
When you access the Services through a Financial Institution or Partner, that Financial Institution or Partner may provide us with information needed to set up and operate your access to the Services, such as confirmation of your eligibility and limited account-identifying information.
We collect information about transactions processed through Sionic Instant Bank Pay and the IBP Gateway, such as the date, amount, status, and the merchant or payee involved.
If you use the Bank Perks Pass, we collect information about perks, rewards, or similar benefits associated with your linked account, including balances, status, and redemption history.
We automatically collect certain technical information when you use our Services, such as device identifiers, operating system and browser type, IP address, app version and diagnostics, and general information about how you use our websites and applications. On our websites, we and our service providers may use cookies and similar technologies to collect this information, as described in Section 6.
With your permission, we may collect approximate or precise location information from your device, for example to support transaction verification or location-based features. You can decline or withdraw this permission at any time through your device settings.
We analyze transaction-related information through the Fraud Detection Service (FDS), an artificial intelligence-based fraud-screening tool, certain aspects of which were co-designed with Google, that interoperates with fraud typologies available through Tazama, an open-source fraud mitigation platform, to help identify potentially fraudulent activity in connection with the Services.
If you use the Bank Perks Pass, Apple and Google may provide us with limited information needed to deliver, update, or troubleshoot your pass. See our Bank Perks Pass Privacy Policy for more detail.
We may also obtain information about you from other sources, such as through a corporate transaction (for example, a merger or acquisition) or from commercial sources, including credit reporting or fraud-prevention agencies, and combine it with other information we have collected about you.
We use the information described above to:
- Create, maintain, and support your access to the Services;
- Process transactions made through Sionic Instant Bank Pay and the IBP Gateway;
- Calculate and display perks, rewards, and transaction history, where applicable;
- Detect, investigate, and help prevent fraud and other potentially harmful or illegal activity, including through the FDS;
- Provide customer support and respond to your requests;
- Maintain the security and integrity of the Services;
- Develop, test, and improve our products and services;
- Communicate with you about your account or the Services, including service-related and, where you have not opted out, promotional communications; and
- Comply with applicable law, regulation, and legal process.
We may also use information in aggregated or de-identified form, such that it does not identify you, for analytics and to improve our products and services.
Sionic does not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising. We share information only as described below:
- Financial Institutions and Partners. We share account-linking and transaction information with the Financial Institution or Partner through which you access the Services, as needed to operate the Services.
- Apple and Google. If you use the Bank Perks Pass, we share information needed to provision and operate the pass within Apple Wallet or Google Wallet. See our Bank Perks Pass Privacy Policy for more detail.
- Payment Networks. We share transaction information with The Clearing House (operator of the RTP Network) and the Federal Reserve Banks (operator of the FedNow Network) as needed to process payments.
- Service Providers. We share information with Third-Party Providers that perform services on our behalf, such as hosting, customer support, analytics, and fraud-detection support, under confidentiality and data protection obligations.
- Legal and Safety Reasons. We may disclose information to comply with law, respond to legal process, protect against fraud, or protect the rights, property, or safety of Sionic, our users, or others.
- Business Transfers. We may disclose information in connection with a merger, acquisition, financing, or sale of business assets.
- Aggregated or De-Identified Data. We may share information that has been aggregated or de-identified such that it no longer identifies you.
When you use our website, we and our service providers may use cookies and similar technologies to recognize your browser, keep you signed in, understand how our website is used, and improve our Services. We use these technologies for purposes such as authentication, security, and analytics — not to sell your personal information or share it for cross-context behavioral advertising.
You can control cookies through your browser settings; declining certain cookies may affect how parts of our website function. Where required by law, we honor the Global Privacy Control and other recognized opt-out preference signals as a valid request to opt out of any sale or sharing of personal information, to the extent such activities apply to you.
- You can update your account information by signing in to the applicable Service or by contacting us.
- You can opt out of promotional communications by following the unsubscribe instructions included with those communications.
- You can control location and other device permissions at any time through your device settings.
Depending on where you live, you may have additional rights regarding your personal information under state privacy laws, including the right to:
- Know or access the categories and specific pieces of personal information we have collected about you;
- Correct inaccurate personal information;
- Delete personal information, subject to certain exceptions (for example, where retention is required by law or necessary to complete a transaction);
- Obtain a portable copy of your personal information; and
- Opt out of the sale of personal information, sharing for cross-context behavioral advertising, or certain profiling — although, as noted above, Sionic does not currently engage in these practices.
To exercise these rights, contact us using the information in Section 14. We may need to verify your identity, or the identity of an authorized agent acting on your behalf, before responding to your request, and we will not discriminate against you for exercising these rights. If we deny your request, you may have the right to appeal that decision using the contact information in Section 14.
The table below summarizes the categories of personal information described in Section 3, consistent with applicable state privacy law category definitions.
| Category | Examples | Source |
|---|---|---|
| Identifiers | Name, email, mailing address, phone number | You; Financial Institutions/Partners |
| Financial Information | Linked account identifiers, transaction history | You; Financial Institutions/Partners; payment networks |
| Commercial Information | Perks, rewards, and redemption history | Generated through your use of the Services |
| Device and Internet Activity | Device identifiers, IP address, app/website usage data | Automatically collected |
| Geolocation Data | Approximate or precise location (with permission) | You (opt-in) |
| Inferences | Fraud-risk indicators generated by the FDS | Generated by Sionic |
California residents may request information about our disclosure of personal information to third parties for those third parties’ own direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes without your consent.
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption, access controls, and ongoing fraud monitoring through the FDS. No security measure is perfect, and we cannot guarantee the absolute security of your information.
We retain personal information for as long as needed to provide the Services, and for a reasonable period afterward as needed to resolve disputes, support fraud investigations, comply with legal or regulatory obligations, and enforce our agreements. For payment dispute resolutions and fraud investigations, the minimal retention period is two years. For legal or regulatory compliance, the minimal retention period is five years.
Sionic provides its technology to Financial Institutions and Partners, who maintain their own customer relationships with you. Your Financial Institution’s own privacy notice — including, where applicable, the annual privacy notice required under the Gramm-Leach-Bliley Act — governs your broader account relationship, including its own collection, use, and sharing of your nonpublic personal financial information, and any opt-out rights available to you with respect to that sharing. This Policy describes only Sionic’s own data practices and does not replace or modify your Financial Institution’s or Partner’s privacy notice. Where Sionic provides a feature-specific privacy policy, such as the Bank Perks Pass Privacy Policy, that policy provides additional detail about that feature and works together with this Policy.
The Services are not directed to children under 13, and we do not knowingly collect personal information (including biometric identifiers) from children under 13. If we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete that information. If you believe we might have information from or about a child under 13, please contact us using the information in Section 14.
Our Services may link to or integrate with websites, applications, or services that we do not operate. This Policy does not apply to those third-party sites and services, and we encourage you to review their privacy policies before providing any information to them.
We may update this Policy from time to time. When we do, we will revise the “Last Updated” date above and, where required by law or where changes are significant, provide additional notice to you.
If you have questions about this Policy or wish to exercise your privacy rights, please contact us at:
Sionic Mobile Corporation 1800 Peachtree Street NW, Suite 809 Atlanta, GA 30309 USA Attn: Privacy Office Email: privacy@sionic.io