banner bg graphic

Your Privacy Is Our Priority

In order to build a trusting relationship, we want to be transparent about why we need your personal information and what we do with it.

Website Privacy Policy

Last updated: February 2026

Our Respect for Privacy

Idaho First Bank (“Idaho First,” “Company,” “we,” “our,” or “us”) respects the importance of the privacy of your personal information. The Company provides this Website Privacy Policy so you know about our information handling and storage practices and understand how the Company treats the information it receives about you from your access or use of the Sites (https://www.idahofirstbank.com/ and https://www.peak.bank and its content, products, and services (collectively, the “Services”) made available in the United States, and its territories, by the Company.

Your Consent

BY SUBMITTING YOUR PERSONAL INFORMATION TO THE COMPANY, OR BY THE COMPANY RECEIVING YOUR PERSONAL INFORMATION FROM THIRD PARTIES, YOU ARE CONSENTING TO THE COLLECTION AND PROCESSING OF YOUR PERSONAL INFORMATION IN THE UNITED STATES AND TO THE COMPANY’S USE OF YOUR PERSONAL INFORMATION AND ANY RELATED INFORMATION IN THE MANNER DESCRIBED IN THIS PRIVACY POLICY, INCLUDING THE TRANSMISSION TO, AND STORAGE AND PROCESSING OF YOUR PERSONAL INFORMATION BY US OR THIRD PARTIES. IF YOU ARE SUBMITTING PERSONAL INFORMATION ABOUT THIRD PARTIES TO THE COMPANY, YOU WARRANT AND REPRESENT YOU HAVE THEIR CONSENT TO PROVIDE THEIR PERSONAL INFORMATION TO THE COMPANY AND YOU WILL INDEMNIFY THE COMPANY AND HOLD THE COMPANY HARMLESS FROM AND AGAINST CLAIMS BY SUCH INDIVIDUALS RELATING TO THE COMPANY’S PROCESSING AND USE OF SUCH PERSONAL INFORMATION WITHIN THE TERMS OF THIS PRIVACY POLICY.

The Information the Company Collects

Online Activities and Cookies. When you use our Services, we may collect information about your visit and store that information. Our servers automatically capture and save the information electronically. The information we collect helps us administer the Services, analyze usage, protect our websites and their content from inappropriate use, and improve the visitor’s experience. The information may also be used for marketing purposes and may uniquely distinguish your browser or computer from others’ devices.

In order to make full use of the Services, your browser must be set to accept “cookies.” Cookies are alphanumeric identifiers that the Company transfers to your computer or mobile device in order to enable the Services to “remember” any information you have saved, such as storage of progress in your application between visits to our online application portal.

In addition, third parties may use cookies, alone or in conjunction with web beacons, pixels, or other tracking technologies, to collect information about you when you use our website. The information they collect may be associated with your personal information or they may collect information about your online activities over time, across different websites and other online services. Information collected by or shared with third parties may be used to deliver advertising targeted to your preferences in addition to helping us administer the Services.

 The Company recognizes that you have a choice to refuse cookies. However, should you decide not to accept cookies from the Services, you may limit the functionality the Company can provide when you use the Services. View your browser’s help file for more information on cookies.

We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly.

Examples of information that we may collect or that third parties may collect while you navigate our website include, but are not limited to:

  • Your Internet protocol or “IP” address
  • The name of your Internet service provider
  • The city and state from which you access our website
  • The type and version of browser, operating system, computer, or mobile device you use
  • Screen resolution
  • A list of your browser’s plug-ins
  • Installed fonts
  • Other technical characteristics of your browser, computer, or device
  • The links you click within our websites and the pages you visit
  • The date and time of your visit, as well as the time you spend and your scrolling behavior on each page
  • The web page from which you arrived to our Services; and
  • Certain searches/queries that you conducted via our Services.

The third parties who operate such trackers include but are not limited to:

  • Google LLC
  • Meta Platforms, Inc.
  • Microsoft Corporation.
  • StackAdapt, Inc.

Your Transactions With Us.

We also collect information directly, including:

  • Information you give us on applications or other forms, such as transaction documents, online forms, e-mails, registration forms, surveys, or other documents or submissions related to the products and services we provide, including your name, address, telephone number, social security number, driver’s license number, email address, employment information, demographic information, bank account information, and information about your assets, debts, and income (Social Security Numbers are secured and kept confidential, and unlawful disclosure of Social Security Numbers is prohibited).
  • Information about your transactions with us, our affiliates, or others, such as your account history, transaction balances, payment history, overdraft history, parties to transactions, and your reasons for doing business with us.
  • Information we may receive from third parties, such as consumer reporting agencies and other lenders, regarding your creditworthiness and credit history, and to verify your identity.
  • Information we may obtain to verify representations made by you, such as your employment history or income.
  • Contact information, including SMS and email, for purposes of our marketing to you. You have the right to opt out of marketing communications by following the opt-out instructions in those communications.

To create and/or submit an application or request to the Services you will need to provide your email address, and other personal and non-personal information. By creating and/or submitting an application or request, you are authorizing us to collect, store and use your email address in accordance with this Website Privacy Policy.

Other Activities. When you engage in certain activities through the Services, such as registering as a user of the Services, sending the Company a message using the Services, ordering a product or service, the Company may ask you to provide personal information. If you choose to share any personal information with the Company, you will see that the amount and type of personal information the Company requests depends on how you use the Services. It is completely optional for you to engage in these activities.

Advertising Service Providers. In addition, the Company may use third-party service providers to serve ads on behalf of the Company across the Internet. They may collect anonymous information about your access and use of the Services, and your interaction with the products and services of the Company. They may use cookies and other online tools such as pixel tags and action tags to serve ads and personalize your web experience based on your prior visits to the the Company websites. They may also use information about your visits to the the Company websites and other websites to target advertisements for products and services. This anonymous information is collected through the use of a cookie. No personally identifiable information is collected or used in this process. These third-party service providers do not know your name, phone number, address, e-mail address, or any other personally identifying information about you. Many third-party service providers are members of the “National Advertising Initiative” (“NAI”). If you would like more information about this practice or to opt out of having this anonymous information used by third-party service providers who are NAI members, visit the NAI consumer opt-out page by clicking here: www.networkadvertising.org/choices/.

How We Use Your Personal Information

The Company uses personal information to provide and improve its products and services, including the Services, for purposes in its legitimate interests, and for compliance with applicable laws. The Company processes personal information on the basis that it is: (a) necessary for the performance of a contract the Company has with you; (b) in the Company’s or a third party’s legitimate interests; (c) where you give the Company your consent; or (d) for compliance with a legal obligation.

The Company may use your IP address and other device information to, among other things: (a) help diagnose problems with the the Company server, administer the Services, measure the use of the Services, and improve the content of the Services; (b) identify visitors’ domain names, the type of web browsers used, the pages viewed, the websites from which a visitor found the Services, the search terms and search engines used to find the Services; and (c) gather other web analytics information relating to visitors’ use and navigation of the Services. This information does not identify you personally. On occasion the Company may aggregate this data with data on the pages visited by other users to track overall visitor traffic patterns and provide this aggregate information to vendors, potential advertisers, business partners, news agencies, or other parties to demonstrate the amount of interest in the Services and to help the Company plan for technical infrastructure requirements.

The Company may use your personal information for particular activities, including, without limitation, processing your application; payment processing;  storing personal information on your behalf for your own use; customer service; marketing and research; studies, making referrals; providing product, promotional and other information to you; and to contact you.

The Company may share your personal information and any other information you provide to the Company with its affiliates, referral partners, financial service providers, lenders, or other business partners in connection with any of the activities described in this Privacy Policy or otherwise engaged in by you through your use of the Services. In addition, the Company may share this information with consumer reporting agencies.

The Company may also share your information with service providers, such as payment processors, cloud storage providers, and customer support platforms, who assist us in delivering our services and maintaining app functionality.

Note that the Company does not have any responsibility for the actions or policies of any business partners, many of which may themselves have relationships with other businesses. You should satisfy yourself about how your information may be used by any business partner.

The Company may use the information it collects and that you provide (other than payment processing information), in an anonymous or aggregated format that does not identify you personally, which uses might include, without limitation, to evaluate existing products, services, and systems; to assist in the development of new products or services; research; and to identify trends and changes.

The Company may disclose personal information in any of the following circumstances: (a) in response to a subpoena, search warrant, court order, or other legal process or request, or as may otherwise be required by applicable law or regulation; (b) to protect and defend the Company rights or property or those of its affiliates or business partners, or others; or (c) as the Company, in its sole discretion, believes is appropriate under exigent circumstances in response to a perceived threat to the personal safety, property, or rights of any person or organization.

In addition, since the the Company database is a business asset, in the event the Company is reorganized or becomes part of another organization, you consent to the sale, assignment, or transfer of your personal information to a successor that acquires substantially all of the business assets of the Company, or to an affiliate, as applicable.

The Company will never request your password, multi-factor authentication code, financial account information, such as account number or social security number, or other personal information through e-mail. This practice, called “phishing,” is a scam designed to steal your personal information. If you receive an e-mail that looks like it is from the Company asking you for your personal information, do not respond.

Our Relationship to Other Sites that can be Accessed Through the Services

The Services may contain links to other websites or you may have been directed to the Services from another website. The Company is not responsible for the contents or privacy policies related to any other websites. If you visit one of these other websites, you should review the privacy policy on that website. Where the Services contains a link to another website owned and/or operated by the Company, such website use may be subject to different and additional terms of use and privacy policy terms and conditions.

Your Options Regarding Personal Information

You can control certain aspects of data collection and use through your browser settings. However, please note that limiting certain data may affect your ability to use certain features or services.

You may elect to opt-out of receipt of email and text communications from us by following the instructions provided in such communications or by contacting us as provided below. Even after opting out, you may still receive service oriented, non-promotional communications from us and promotional communications from other third parties as a result of their own interactions or transactions with you. Please allow time for us to process your request or contact us should you have any concerns about your opt-out request.

“Do-Not-Track” is a public-private initiative that developed a technical “flag” or signal that an end-user may be able to activate within their browser software to notify websites that they do not wish to be “tracked” by third parties as defined by the initiative. Because no uniform standard was ever developed, this website does not recognize “Do-Not-Track” signals. If your browser supports it, however, you can turn on the newer Global Privacy Control (GPC) to opt-out of the “sale” or “sharing” of your Personal Information.

You may also follow the steps provided by initiatives that educate users on how to set tracking preferences for most online advertising tools. These resources include the Network Advertising Initiative (https://thenai.org/about-online-advertising/) and the Digital Advertising Alliance (https://digitaladvertisingalliance.org/). The Digital Advertising Alliance also offers an application called AppChoices (https://youradchoices.com/appchoices) that helps users to control interest-based advertising on mobile apps.

How Long We Keep Personal Information

 We retain personal information in accordance with any records retention policy or program we may implement from time to time. We will retain personal information for the length of time necessary to fulfill the purposes for which we collected the personal information or to demonstrate we have fulfilled our duties or obligations, or retention periods required by applicable law or in which claims may be made or the existence of legal proceedings.

Security of Your Personal Information

We limit access to your personal information to those who need to have access, and when we dispose of your personal information, we do it in a secure manner.

The Company takes reasonable precautions to protect the security of data and information, including personal information. The Company will attempt to ensure that your personal information will be subject to appropriate safeguards and that it is processed and secured in accordance with applicable law. However, the Company cannot guarantee against any loss, misuse, unauthorized disclosure, or alteration or destruction of data or personal information outside of the Company’s control. While the Company strives to protect your personal information, the Company cannot guarantee the security of any information you transmit to, from, or within the Services, by email or otherwise, and you provide such information at your own risk. You acknowledge that: (a) there are security and privacy limitations in computer systems and on the Internet which are beyond the control of the Company; (b) the security, integrity, and privacy of any and all information and data exchanged between you and the Company through the Services, including personal information, cannot be guaranteed; and (c) any such information and data, including personal information, may be viewed or tampered with by a third party while such information or data is being used, transmitted, processed, or stored.

Social Security Numbers are secured and kept confidential. Unlawful disclosure of Social Security Numbers is prohibited. We destroy Social Security Numbers when no longer needed using industry-standard secure destruction methods appropriate to the storage medium.

Children’s Online Privacy Policy

Our Services are not directed to children under the age of 18, and we do not knowingly collect Personal Information from children under the age of 18 on these Services. In addition, we do not sell any Personal Information of minors under 18 years of age.

Changes to Privacy Policy

This Website Privacy Policy may be updated periodically to reflect relevant changes in our information practices. We will post a notice on our Services to inform you of significant changes to this Policy. We will also provide additional information regarding changes to this Website Privacy Policy as may be required by law. Your continued use of our Services following our posting of any such changes will mean that you accept such changes.

For further information or if you have any questions about this Privacy Policy, please contact us in one of the following ways:

By email at:

[email protected]

[email protected]

By telephone at:

(866) 634-2760 – Idaho First Bank

(866) 484-5705 – Peak Bank

Or by U.S. mail to:

Idaho First Bank

Attention: Privacy

1100 W. Idaho St., Suite 600

Boise, ID, 83702

Please clearly state what information you are requesting and any other requests you are making.

The Company will respond to reasonable requests within the time limits established by applicable law or within a reasonable time if no time limit is established by applicable law. For your protection, the Company may ask you for additional information to verify your identity. If you send the Company an email requesting that the Company take action regarding your personal information or the right to be forgotten, the Company may require that the requesting email come from the email address the Company has on file for you in order to verify that the request is valid and also to protect your personal information. In most cases, the Company will provide the information you request and correct or delete any inaccurate personal information you discover.

The Company reserves the right, however, to limit or deny your request to the extent permitted by applicable law if: (a) complying with the request may present a threat to the personal safety, property, or rights of any other person or organization; (b) complying with the request may lead to a violation of applicable laws or regulations; (c) the Company is not required to comply with the request because of a legal rule or exception; or (d) you have failed to provide the Company with sufficient evidence to verify your identity.

 

General Privacy Policy

Last Updated: March 2024

Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do.

What we do: The types of personal information we collect, and share depend on the product or service you have with us. This information can include:

  • Social Security number and income
  • Account balances and account transactions
  • Payment history and credit scores

When you are no longer our customer, we continue to share your information as described in this notice.​

All financial companies need to share customers’ personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers’ personal information; the reasons Idaho First Bank chooses to share; and whether you can limit this sharing.

Idaho First Bank shares your information for the following reasons:

  • For our everyday business purposes — such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus.
  • For our marketing purposes — to offer our products and services to you.
  • For joint marketing with other financial companies.
  • For our affiliates’ everyday business purposes — information about your transactions and experiences.

Idaho First Bank DOES NOT share your information for the following reasons:

  • For our affiliates’ everyday business purposes — information about your creditworthiness.
  • For affiliates to market to you.
  • For non-affiliates to market to you.
How does Idaho First Bank protect my personal information?

To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings.

How does Idaho First Bank collect my personal information?

We collect your personal information, for example, when you:

  • Open an account or deposit money
  • Pay your bills or apply for a loan
  • Use your debit card

We also collect your personal information from others, such as credit bureaus, affiliates, or other companies.​

Why can’t I limit all sharing?

Federal law gives you the right to limit only:

  • Sharing for affiliates everyday business purposes — information about your creditworthiness.
  • Affiliates from using your information to market to you.
  • Sharing for non-affiliates to market to you.

State laws and individual companies may give you additional rights to limit sharing.

Definitions:

Affiliates: Companies related by common ownership or control. They can be financial and nonfinancial companies.

  • Our affiliates include financial companies, such as Peak Bancorp Inc., BAWAG Group AG, BAWAG P.S.K., and affiliates.

Non-affiliates: Companies not related by common ownership or control. They can be financial and nonfinancial companies.

  • We don’t share with non-affiliates so they can market to you.

Joint Marketing: A formal agreement between non-affiliated financial companies that together market financial products or services to you.

  •  Our joint marketing partners include financial service providers.

Mobile App Data Privacy

Last Updated: February 2026

This disclosure outlines how we collect, use, and protect your data when you use our mobile app, in compliance with both Apple’s App Store and Google Play Store requirements.

Information We Collect

When you use our mobile app, we collect the following categories of information:

Account Information

  • Name, email address, and phone number (when you create an account)
  • Account password (encrypted)
  • Account preferences and settings

Device & Technical Information

  • Device identifiers (device ID, mobile advertising ID)
  • Mobile operating system and version
  • App version and usage data
  • IP address and mobile network information
  • Push notification tokens (if notifications are enabled)
  • Crash logs and diagnostic data

Usage Information

  • Products viewed, searched, and saved as favorites
  • Screens viewed and features used
  • Search history and browsing behavior
  • Store location preferences

Location Information

  • Approximate location derived from IP address

HOW WE USE YOUR INFORMATION

We use the information we collect to:

  • Provide personalized product recommendations based on your browsing history and preferences
  • Improve app functionality and user experience through analytics and performance monitoring
  • Show you nearby bank locations when you use location-based features
  • Send push notifications about products, promotions, or account activity (if you enable notifications)
  • Maintain app security and prevent fraud or abuse
  • Comply with legal obligations and respond to legal requests

TRACKING AND ADVERTISING

App Tracking (iOS)

On iOS devices, we may request your permission to track your activity across other companies’ apps and websites for analytics purposes. You can control this through the App Tracking Transparency prompt when you first use the App, or later in your iPhone Settings > Privacy & Security > Tracking.

Advertising Identifiers

We collect your mobile advertising ID (IDFA on iOS, AAID on Android) for analytics purposes only. We do not use these identifiers for targeted advertising or share them with advertising networks. You can reset or limit tracking of your advertising ID in your device settings:

  • iOS: Settings > Privacy & Security > Tracking, or Settings > Privacy & Security > Apple Advertising
  • Android: Settings > Privacy > Ads, or Settings > Google > Ads

THIRD-PARTY SHARING

We share certain information with third-party service providers who help us operate the App:

Analytics Providers

We share device identifiers, usage data, and technical information with:

  • Google Analytics: To analyze app performance, user engagement, and crash data, understand user behavior, and improve app features

These providers are contractually prohibited from using your information for their own purposes. Learn more:

  • Google Analytics:

https://policies.google.com/technologies/partner-sites

DATA RETENTION

We retain your personal information for as long as you maintain an active account, or as necessary to provide you services, comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account or request deletion of your data, we will delete or anonymize your information within 30 days, except where we are required by law to retain it longer.

YOUR PRIVACY RIGHTS

You have the following rights regarding your personal information:

  • Right to Access: Request a copy of the personal information we have about you
  • Right to Correction: Request correction of inaccurate or incomplete information
  • Right to Deletion: Request deletion of your personal information (subject to legal retention requirements)
  • Right to Data Portability: Receive your data in a portable, machine-readable format
  • Right to Opt-Out: Opt out of certain data processing (see Section below)

To exercise these rights, email us at [email protected] or use the in-app settings menu. We will respond to your request within 45 days.

HOW TO CONTROL YOUR INFORMATION

Location Permissions

You can control location access in your device settings:

  • iOS: Settings > Privacy & Security > Location Services
  • Android: Settings > Location > App permissions

Push Notifications

You can disable push notifications in your device settings or within the App’s settings menu.

DATA SECURITY

We implement industry-standard security measures to protect your personal information, including encryption of data in transit (using TLS/SSL), encryption of sensitive data at rest, secure authentication protocols, and regular security assessments. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

CHILDREN’S PRIVACY

The App is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us [email protected], and we will delete such information from our systems.

CHANGES TO THIS NOTICE

We may update this Privacy Notice from time to time. When we make material changes, we will notify you through the App or by email (if you have provided your email address). Your continued use of the App after such notification constitutes acceptance of the updated Notice.

CONTACT INFORMATION

If you have questions, concerns, or requests regarding this Privacy Notice or our privacy practices, please contact us:

By email at:

[email protected]

[email protected]

By telephone at:

(866) 634-2760 – Idaho First Bank

(866) 484-5705 – Peak Bank

Or by U.S. mail to:

Idaho First Bank

Attention: Privacy

1100 W. Idaho St., Suite 600 Boise, ID 83702