Privacy Policy
Effective date: July 24, 2026 · Version 1.0
Applies to the EAT: Card mobile app, the EAT desktop web app, and eat.ong.
Contents
- Who we are
- Information we collect
- How we use information
- How we share information
- Banking partners and their policies
- How we protect information
- How long we keep information
- Deleting your account and data
- Your privacy rights and choices
- State privacy rights (including California)
- Children
- International users and data location
- Changes to this policy
- Contact us
1. Who we are
The EAT: Card app and EAT member services (the “Services”) are operated by the WYDE Foundation (“WYDE,” “we,” “us,” or “our”), a 501(c)(3) nonprofit organization. The EAT Card is a Visa debit card offered through the WYDE Foundation member program.
We do not provide banking services ourselves. Banking services are provided by i3 Bank, Member FDIC. The technology behind your account and card is provided by Crowded Technologies Inc. (“Crowded”), a financial technology company. When you use the Services, some of your information is collected and processed by Crowded and i3 Bank as described in Section 5.
This document is our privacy policy. It explains what information we and our service providers access, collect, use, and share when you use the Services, and the choices you have. By using the Services, you agree to this policy.
2. Information we collect
2.1 Information you provide
- Registration and membership details. Name, email address, phone number, date of birth, and physical address when you apply for membership and create your account.
- Identity verification (KYC) information. To open your account and issue your card, our banking partners are required by law to verify your identity. This can include your Social Security number or taxpayer identification number, government-issued ID, a photograph or selfie, nationality, and related details. This information is collected and processed by Crowded and i3 Bank for know-your-customer (KYC), anti-money-laundering (AML), and sanctions screening required under federal law.
- Funding details. Information about the external bank account you use to fund your card, such as routing and account numbers for ACH transfers.
- Communications. Information you provide when you contact support, respond to us, or otherwise communicate with us.
- Referral and creator program information. If you participate, your referral code or link, attribution data about members you refer, and information needed to administer rewards and required tax reporting.
2.2 Information collected automatically
- Transaction information. When you use your card or account, we and our banking partners process transaction data such as merchant name, amount, date, and payment method. We use this to operate your account, show your activity, and calculate program totals such as community meals funded.
- Device and usage information. IP address, device type and identifiers, operating system, app version, log data, crash reports, and how you interact with the app and our websites.
- Cookies and similar technologies. Our websites use cookies and similar technologies for sign-in, security, preferences, and analytics. You can control cookies through your browser settings; some features may not work properly without them.
2.3 Information from other sources
- Identity verification, fraud prevention, and sanctions screening providers engaged by us or our banking partners.
- Service providers that help us operate the program, such as analytics and communications providers.
We do not knowingly collect precise geolocation, contacts, photos (other than identity documents you choose to submit), or health information through the Services.
3. How we use information
- To open and maintain your membership and account, issue and service your card, and process transactions;
- To complete KYC, AML, sanctions, and other compliance and risk checks required by law;
- To identify you and authenticate your access to the Services;
- To detect, investigate, and prevent fraud, abuse, and security incidents;
- To provide support and respond to your requests;
- To operate program features, including community impact totals (such as aggregated meals funded) and the referral and creator programs;
- To send service communications, such as security alerts, transaction notices, and changes to terms;
- To send marketing communications, which you can opt out of at any time (see Section 9);
- To improve, troubleshoot, and develop the Services, including through aggregated and de-identified analytics; and
- To comply with law, regulation, legal process, or governmental requests, and to enforce our terms and policies.
We may aggregate or de-identify information so it can no longer reasonably identify you. We may use and share aggregated or de-identified information, such as total meals funded by the community, without restriction under this policy.
5. Banking partners and their policies
The EAT: Card app is a branded experience built on Crowded's platform, with accounts and cards provided by i3 Bank. When you open and use your account, Crowded and i3 Bank collect and process your information as independent regulated parties, in addition to this policy:
- Crowded Technologies Inc. Privacy Policy: bankingcrowded.com/legal/privacy-policy
- i3 Bank privacy notices, available from i3 Bank.
Financial institutions in this program handle your nonpublic personal information in accordance with the Gramm-Leach-Bliley Act (GLBA) and related federal privacy requirements.
6. How we protect information
We and our partners use administrative, technical, and physical safeguards designed to protect your information, including encryption of data in transit, access controls limiting who can view personal information, and monitoring for unauthorized access. Payment card data is handled by our banking and processing partners in accordance with industry security standards.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a security incident affecting your personal information, we will notify you as required by applicable law.
7. How long we keep information
We keep personal information for as long as your membership and account are active and as needed to provide the Services. After your account closes, we and our banking partners retain certain information as required by law. Federal banking regulations, including Bank Secrecy Act and anti-money-laundering rules, require retention of account opening records, identity verification records, and transaction records for a period of years after the account relationship ends. We also retain information as needed to resolve disputes, enforce agreements, prevent fraud, and meet tax and audit obligations. When retention is no longer required, we delete or de-identify the information.
8. Deleting your account and data
- In the app: open EAT: Card, go to Settings, and choose Delete account. Follow the prompts to confirm.
- On the web: visit eat.ong/delete-account and submit a deletion request. You do not need to reinstall the app to use this option.
- By email: contact us at contact@wyde.org with the subject line “Account deletion.”
Before we can close a card account, any remaining balance must be withdrawn or transferred out, and pending transactions must settle. We will guide you through those steps if they apply.
When your account is deleted, we delete or de-identify the personal information associated with it, and we direct our service providers to do the same, except for information we or our banking partners must retain for legitimate purposes such as security, fraud prevention, dispute resolution, and regulatory compliance, as described in Section 7. Deactivating or freezing an account is not the same as deletion; a deletion request results in deletion, subject to those required retentions.
9. Your privacy rights and choices
- Access and correction. You can access and update most of your information in the app, or contact us to request access to, correction of, or a copy of your personal information.
- Deletion. You can request deletion as described in Section 8.
- Marketing opt-out. You can opt out of marketing emails by using the unsubscribe link in any marketing message or by contacting us. We will still send service communications required to operate your account, such as security and transaction notices.
- Cookies. You can manage cookies through your browser settings.
We will verify your identity before acting on requests, and we will respond within the time required by applicable law. You may authorize an agent to make a request on your behalf; we will require proof of authorization and verification of your identity.
10. State privacy rights (including California)
Depending on where you live, state law may give you additional rights, including the right to know what personal information we collect, the right to delete, the right to correct, and the right not to receive discriminatory treatment for exercising your rights. Much of the information we handle in this program is regulated financial information covered by federal law (GLBA), which state privacy laws generally exempt; the rights below apply to personal information within the scope of those state laws.
California (CCPA/CPRA)
In the last 12 months, we have collected the following categories of personal information: identifiers (such as name, email, phone number, IP address); customer records information (such as address and financial account details); commercial information (such as transaction records); internet or other electronic network activity (such as app and website interactions); and sensitive personal information (such as Social Security number, government ID, and financial account credentials, collected for identity verification and account servicing).
We collect this information from you, from your devices, and from verification and service providers, for the purposes described in Section 3. We disclose it for business purposes to the parties described in Section 4. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We use sensitive personal information only for the purposes permitted by the CCPA, such as providing the Services, verifying identity, preventing fraud, and complying with law.
California residents can exercise access, deletion, and correction rights by using the methods in Sections 8 and 9. You can make an access request up to twice in a 12-month period. We do not charge a fee to respond to requests unless permitted by law.
11. Children
The Services are intended for individuals 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided personal information to us, contact us at contact@wyde.org and we will take commercially reasonable steps to delete it.
12. International users and data location
The Services are operated from the United States, and information is processed and stored in the United States. The EAT: Card app is currently available in the United States and Canada; members elsewhere can access their account through the desktop web app. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your location.
13. Changes to this policy
We may update this policy from time to time. The current version will always be posted at eat.ong/privacy with its effective date. If we make material changes, we will notify you through the app or by email before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
14. Contact us
WYDE Foundation, operator of the EAT: Card app.
Privacy inquiries: contact@wyde.org
Account deletion: eat.ong/delete-account
If you are not satisfied with our response to a privacy concern, you may contact the data protection or consumer protection authority in your jurisdiction.
The WYDE Foundation is a 501(c)(3) nonprofit organization and is not a bank. Banking services are provided by i3 Bank, Member FDIC. The EAT Visa Debit Card is issued by i3 Bank pursuant to a license from Visa U.S.A. Inc. and may be used everywhere Visa debit cards are accepted. Account and card technology is provided by Crowded Technologies Inc., a financial technology company.