Privacy and Data Protection Policy


Last Updated: February 25, 2026

This Privacy Policy describes the policies and procedures of Fold, Inc., together with its parent companies,
subsidiaries, affiliates, and any other parties that contribute to or otherwise operate the Services (collectively,
“Fold,” “we,” “our,” or “us”), regarding our collection, use, and disclosure of your information in connection with
your access to and use of the Fold mobile application (the “App”), foldapp.com (the “Site”), and the other services,
features, products, content, and applications offered by Fold (together with the Site and the App, the “Services”).

As used in this Privacy Policy, “Personal Data” means any information that can be used to individually identify a
person or that meets an applicable legal definition of “personal data,” “personal information,” or any similar term.
Undefined capitalized terms have the meanings ascribed to them in the Fold Terms and Conditions, of which this
Privacy Policy is a part

Please also see our GLBA Privacy Notice for more information on how we handle Personal Data subject to the Gramm-Leach-Bliley Act, and our Fair Credit Reporting Act (FCRA) disclosures for information about your rights regarding consumer reports and credit information.

We urge you to read this Privacy Policy in full, but here are key points:

  • This Privacy Policy covers our treatment of Personal Data that we collect about you (a) from you directly,when you register for and use your account on the Services; (b) from your web browser and/or device, as you interact with the Services generally; and (c) from third-party websites and services, including our business partners and service providers.
  • The Services are hosted and operated in the United States and elsewhere throughout the world through us and certain of our service providers. By using the Services, you acknowledge that any Personal Data you provide to us will be hosted on servers in the United States and in other countries.
  • If you have any questions about this Privacy Policy, about our collection and use of your Personal Data, or about whether any of the following applies to you, please contact us directly at support@foldapp.com, orby mail at 2942 North 24th Street, Suite 115, #42035, Phoenix, Arizona 85016.
  • We do not knowingly collect or solicit Personal Data from anyone under the age of 18. If you are under the age of 18, you are not allowed to use the Services.
  • This Privacy Policy does not apply to the practices of third parties that we do not own or control. We encourage you to carefully review the privacy policies of any third-party services you access.
  • Fold takes the protection of your Personal Data very seriously. To find out more, see “How Do We Protect Your Personal Data?”

What Does This Privacy Policy Cover?

This Privacy Policy covers the processing of Personal Data by Fold when you access and use the Services. As used in this Privacy Policy, “processing” generally covers actions that can be performed in connection with data such as collection, use, storage, and disclosure. Unless addressed herein, this Privacy Policy does not apply to the practices of third parties, including their sites, services, or applications that Fold does not own or control, or to individuals that Fold does not employ or manage (collectively, the “Third Parties”). While we attempt to provide access only to those Third Parties that share our respect for your privacy, we cannot take responsibility for the content, actions, or data protection policies or practices of those Third Parties. We encourage you to carefully review the data protection policies and practices of any Third Parties you access, and to carefully consider what kind of Personal Data you choose to post or otherwise make available through the Services.

This Privacy Policy also covers Fold’s treatment of any Personal Data that Fold’s business partners and service providers share with Fold, or that Fold shares with its business partners and service providers, to the extent Fold is the legally responsible party for such Personal Data under applicable privacy laws.

What Personal Data Does Fold Collect from You?

We collect Personal Data about you when (i) you provide such information directly to us, (ii) third parties such as our business partners or service providers provide us with Personal Data about you, or (iii) Personal Data about you is automatically collected in connection with your use of the Services. By providing Personal Data of others to Fold, you represent that you have the authority to do so.

Information We Collect Directly from You

  • First and last name
  • Email address.

Account information

  • First and last name
  • Email address

Information you make available on or through the Services:

  • First and last name
  • Email address
  • Billing address
  • Date of birth
  • Social Security number

Information required for Know Your Customer checks and compliance with the USA Patriot Act when opening card accounts:

  • First name, middle name, last name
  • Social Security number
  • Address
  • Date of birth
  • Driver’s license or government issued ID

For the Fold Bitcoin Credit Card specifically:

  • Employment information (employer name, job title, income)
  • Financial information (annual income, housing costs, existing debts)
  • Transaction history and payment patterns
  • Credit utilization and balance information
  • Bank account information for payments and autopay

Job applicant details:

  • Information included in your resume or CV, references, job history, and other information collected as part
    of evaluating your candidacy.

Third-Party Service Providers

To enable certain features of the Services (including, without limitation, payments, instant funding/ACH, card issuance, credit underwriting, and identity verification, and the financing of credit products), we work with various financial institutions, lenders, financial services providers, and other third-party service providers. When you use these features, we share only the information necessary for the provider to perform its respective services. Except as noted below, payment card and bank account information is collected and stored by the relevant provider, not by us.Please review each provider’s privacy policy. Current third-party service providers include (but are not limited to):

  • Stripe, LLC (card issuing, processing, and servicing): Provides card-issuing services; processes payment information to collect and settle payments, perform KYC/AML processes, and monitor for transaction fraud; and provides card servicing services. Privacy policy: stripe.com/us/privacy.
  • Astra, Inc. (instant funding & ACH): Processes bank account information to complete instant-funding and ACH transfers. Privacy policy: astra.finance/privacy.
  • Sutton Bank (Fold Prepaid Debit Card issuer): Collects and uses Personal Data to issue and service your Fold Prepaid Debit Card. Privacy policy: suttonbank.com.
  • Celtic Bank (issuing bank for the Fold Bitcoin Credit Card): Collects and uses Personal Data to evaluate applications (including obtaining consumer reports), underwrite, originate, service, and enforce your Fold Bitcoin Credit Card account. Celtic may share information with consumer-reporting agencies and with its service providers, payment networks, and regulators as permitted by law. Fold acts as a program manager/service provider to Celtic and may receive limited account information (e.g., application and account status, transaction metadata) solely to operate the program, calculate rewards, provide support, and prevent fraud. Fold does not make credit decisions. To the extent your information is collected, processed,or disclosed by Celtic as a financial institution, such processing is subject to Celtic’s GLBA privacy notice and related disclosures, which control in the event of any conflict with this Privacy Policy. For GLBA sharing choices and FCRA notices (including how Celtic reports to credit bureaus), please review Celtic’s privacy policy and notices. If you set up autopay or link a bank account for payments, any bank-account linking may be facilitated by an open-banking provider (e.g., Plaid), and your credentials are provided directly to that provider, not to Fold. Privacy policy: https://www.celticbank.com/privacy.
  • Incode Technology, Inc. (identity verification): Collects information including biometric data to verify your identity. Privacy policy: incode.com/incode-privacy-policy.
  • Very Good Security, Inc. (tokenization): Stores sensitive data and returns tokenized values. Privacy policy: verygoodsecurity.com/privacy-notice.
  • BitGo Trust Company, Inc. (digital-asset custody): Provides digital-asset custody and settlement services. Privacy policy: bitgo.com/legal/bitgo-privacy.
  • Plaid Inc. (open-banking): Facilitates bank account linking. Credentials are provided to Plaid, not to Fold.Privacy policy: plaid.com/legal.
  • Marqeta, Inc. (card processing): Provides card-issuing and processing services. Privacy policy: marqeta.com/services-privacy.
  • Unit21, Inc. (fraud/AML): Provides fraud/AML analytics and case management. Privacy policy:unit21.ai/privacy-policy.
  • SardineAI Corp. (fraud/risk): Provides fraud and risk-decisioning tools. Privacy policy: sardine.ai/privacy-policy.

Fold does not take responsibility for the content, products, services, or privacy policies of third-party services. Weencourage you to carefully review the privacy policies of any third-party services you access.

Information We Automatically Collect

Some Personal Data is automatically collected when you use our Services:

  • IP address,
  • Web browser information,
  • Operating system information,
  • Pages you visit and links you click on in connection with Services
  • Certain Cookies (see below for more information).

When you access or use the Services, we use information from your web browser and your device’s settings and unique identifiers to reliably and accurately provide you with the Services. Our Services may contain web beacons that permit us to count website visitors and compile similar statistics.

For fraud protection purposes only, we collect your battery usage, device identifier, device storage, MAC address,and SIM information; and we collect enough information to determine if you are trying to fake your current location using a VPN or similar tools.

Information We collect From Third Parties

We may obtain information about you from third parties, including: (i) referees and other third parties whom you authorize to provide us with information; (ii) third-party data providers that assist us in verifying your identity; and(iii) consumer reporting agencies (credit bureaus) in connection with credit product applications and ongoing account servicing. Any information we obtain from third parties will be treated in accordance with this Privacy Policy

Consumer Report Information (Credit Card Applicants)

If you apply for or hold a Fold Bitcoin Credit Card, Celtic Bank (the issuing bank and creditor) will obtain consumer reports (“credit reports”) from one or more consumer reporting agencies to evaluate your application, set credit terms, and service your account. This may include:

  • Credit history and credit scores
  • Public records (bankruptcies, judgments, liens)
  • Existing credit accounts and payment history
  • Inquiries from other creditors

Celtic Bank makes all credit decisions for the Fold Bitcoin Credit Card. Fold does not make credit decisions and does not have access to your full credit report.

Additional Information About Cookies

The Services use “Cookies” to enable our servers to recognize your web browser and tell us how and when you visit and use our Site and Services. Cookies are small files placed on your device when you use that device to visit our Site.

Cookies can be “session Cookies” (temporary, stored while you visit) or “persistent Cookies” (stored for a period after you leave). We use persistent Cookies to track how often you visit and how your use varies over time.

Your browser may offer a “Do Not Track” option. Like many websites, our website is not designed to respond to such signals, and we do not use or disclose your information in any way that would legally require us to recognize opt-out preference signals.

We use the following types of Cookies:

  • Essential Cookies: Required for providing features or services you have requested. Disabling these may make certain features unavailable.
  • Analytics Cookies: We use analytics cookies, including Google Analytics, to help improve our website by collecting and reporting information on how you use it.

You can manage Cookies through your browser settings. To opt-out of Google Analytics tracking, visittools.google.com/dlpage/gaoptout.

How Do We Use Your Personal Data?

We process Personal Data to operate, maintain and understand our Services. For example, we use Personal Data to:

  • Verify and establish your account
  • Verify, establish, and maintain your Fold Prepaid Debit Card account with Sutton Bank
  • Verify, establish, and maintain your Fold Bitcoin Credit Card with Celtic Bank, including facilitating the credit application and underwriting process
  • Coordinate with business partners to assist opening accounts or facilitate your use of Fold Services
  • Process and fulfill your purchases of the Services or other products
  • Calculate, track, and distribute bitcoin rewards
  • Protect against or deter fraudulent, illegal or harmful actions
  • Communicate with you about the Services, including updates, offers, and newsletters
  • Provide support and assistance for the Services
  • Identify trends and statistical information useful to our business
  • Comply with our legal or contractual obligations
  • Respond to user inquiries and fulfill user requests
  • Resolve disputes
  • Enforce our Terms and Conditions

How and With Whom Do We Share Your Data?

We share limited Personal Data with vendors, third-party service providers, and agents who work on our behalf. We limit sharing to the minimum information required. These parties include:

These parties include:

  • Business partners
  • Hosting service providers 
  • Email providers
  • Payment processors
  • Card manufacturing, personalization, and delivery providers
  • Banking and financial partners and payment networks
  • Consumer reporting agencies (credit bureaus) for credit product servicing and reporting
  • Analytics providers
  • Cloud communication service providers
  • Delivery providers
  • Other contractors as needed for business purposes
  • Lending partners and financial institutions involved in credit product origination and servicing

We also share Personal Data when necessary to:

  • Comply with applicable law or respond to valid legal process
  • Protect us, our business or our users (e.g., enforce Terms, prevent fraud)
  • Respond to emergencies involving potential threats to physical safety
  • When you give us express consent
  • If we or substantially all of our assets are acquired, or if we enter bankruptcy

Text Messaging Opt-In Data.

Notwithstanding any other provision of this Privacy Policy, we do not share mobile information, including text messaging originator opt-in data and consent, with third parties or affiliates for marketing or promotional purposes.All of the categories of data sharing described above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Credit Reporting and Furnisher Practices

For Fold Bitcoin Credit Card account holders, Celtic Bank (as the creditor and card issuer) reports information about your account to one or more consumer reporting agencies (credit bureaus). This is standard practice for credit products and helps build your credit history. The information reported may include:

  • Account opening date
  • Credit limit
  • Current balance
  • Payment history (including on-time and late payments)
  • Account status (open, closed, charged-off, etc.)
  • Whether the account is disputed

Celtic Bank maintains written policies and procedures to ensure the accuracy and integrity of the information reported, as required by the Fair Credit Reporting Act and Regulation V. If you believe information reported about your account is inaccurate, you have the right to dispute that information.

Your Rights Under the Fair Credit Reporting Act (FCRA)

If you apply for or hold a Fold Bitcoin Credit Card, you have important rights under the Fair Credit Reporting Act:

  • Right to Know if Information Was Used Against You: If your application is denied or other adverse action is taken based on a consumer report, you must be told and given the name, address, and phone number of the consumer reporting agency that provided the report.
  • Right to a Free Credit Report: If adverse action is taken, you can request a free copy of your credit report from the consumer reporting agency within 60 days.
  • Right to Dispute Inaccurate Information: You can dispute the accuracy or completeness of any information in your credit report. Consumer reporting agencies must investigate disputes (usually within 30 days) and correct or delete inaccurate information.
  • Right to Accurate Reporting: Furnishers (including Celtic Bank) must report accurate information and investigate disputes forwarded by consumer reporting agencies.
  • Right to a Security Freeze: You can place a security freeze on your credit report, which prohibits a consumer reporting agency from releasing information without your express authorization.• Right to Opt Out of Prescreened Offers: You may opt out of receiving prescreened offers by calling 1-888-5-OPTOUT (1-888-567-8688).

For more information about your FCRA rights, visit consumerfinance.gov/learnmore or write to the Consumer Financial Protection Bureau, 1700 G Street N.W., Washington, DC 20552.

Adverse Action Notices

If your application for the Fold Bitcoin Credit Card is denied, or if other adverse action is taken on your account based on a consumer report, Celtic Bank will provide you with an adverse action notice. This notice will include:the name, address, and phone number of the consumer reporting agency; a statement that the agency did not make the adverse decision; your right to obtain a free copy of your credit report; and your right to dispute the accuracy of any information. If a credit score was used, you will also receive your score and the key factors that adversely affected it.

How Do We Protect Your Personal Data?

We seek to protect Personal Data using appropriate technical and organizational measures, including:

  • Limiting Personal Data tracking, and only storing what we need to deliver the Services
  • Employing “least privilege principles” - employees only access data necessary for their role
  • Minimizing use of Third-Party Services to only those required• Using encryption for data in transit and at rest
  • Maintaining access controls and authentication measures
  • Conducting regular security assessments and monitoring

We understand the importance of security, but we cannot promise that our security measures will eliminate all risks.Despite reasonable efforts, no security measures are impenetrable. Unauthorized entry, hardware or software failure, and other factors may compromise security at any time. We recommend that you do not use unsecure channels to send us sensitive information.

Data Breach Notification

In the event of a data breach involving your Personal Data, we will notify you in accordance with applicable law. If a breach is reasonably likely to result in identity theft or other significant harm, we will notify affected individuals as required by applicable state and federal laws.

Data Retention

We retain your information for as long as is reasonably necessary for the purposes specified in this Privacy Policy. We consider whether we need the information to administer your account, provide Services, resolve disputes, enforce agreements, prevent harm, promote safety and integrity, or protect our rights and property.

For credit card accounts, we are required by law to retain certain records for specified periods. For example, certain transaction records must be retained after the account is closed.

Do We Collect Personal Data of Children?

We do not knowingly collect or solicit Personal Data from anyone under the age of 18. If you are under 18, please do not attempt to register for the Services or send any Personal Data to us. If we learn that we have collected Personal Data from a child under 18, we will delete that information as quickly as possible. If you believe that a child under 18 may have provided us Personal Data, please contact us at support@foldapp.com.

California Residents

This section applies to California residents. We adopt this notice to comply with the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”).

Information We Collect and Disclose

We have collected and disclosed the following categories of Personal Data from consumers within the last twelve months:

Category

Examples

Recipients

A. Identifiers. Real name, alias, postal address, unique identifier, IP address, email address, account name, SSN*, driver’s license*, passport* Service providers
B. Personal information (Cal. Civ. Code 1798.80(e)) Name, signature, SSN*, address, telephone, passport*, driver’s license*, insurance policy number, education, employment history, account number, credit/debit card number, financial information* Service providers
C. Protected classifications Age (40 years or older)* Service Providers
D. Commercial information. Transaction information, products/services purchased, payment history, credit utilization Service Providers
E. Biometric information. Faceprints and other informative biometric information (for identity verification) Service Providers
F. Internet activity. Browsing history, search history, interaction with website/app Service Providers
G. Geolocation data. Approximate location inferred from IP address Service Providers

* Denotes sensitive personal information. We do not use or disclose sensitive personal information in any way not permitted under California law.

Personal information does not include: publicly available information from government records; deidentified or aggregated information; or information covered by HIPAA, FCRA, GLBA, or the Driver’s Privacy Protection Act.

Selling or Sharing of Personal Information

We do not “sell” or “share” (as defined under the CCPA) personal information, nor have we done so in the preceding 12 months. We do not have actual knowledge that we sell or share personal information of residents under 16 years of age.

Your Rights and Choices

The CCPA provides California residents with specific rights:

  • Right to Know/Access: Request disclosure of the categories and specific pieces of personal information we collected, the sources, the business purposes, and the categories of third parties with whom we share.
  • Right to Delete: Request deletion of personal information we collected, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any CCPA rights.

Exercising Your Rights

To exercise your rights, submit a verifiable consumer request by emailing support@foldapp.com or calling 1-866-FOLDAPP (1-866-365-3277). Only you, or a person you authorize, may make a request related to your personal information.

Other State Privacy Rights

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have additional rights similar to those for California residents, including rights to access, delete, and correct personal information. To exercise any rights under applicable state law, please contact us using the information below.Certain information may be exempt under applicable law, including information required to provide financial services or comply with legal obligations. Information subject to the GLBA or FCRA may be exempt from certain state privacy law requirements.

Limitation of Liability and Disclaimer

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, FOLD SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS OR REVENUES, WHETHER INCURRED DIRECTLY OR INDIRECTLY, OR ANY LOSS OF DATA, USE, GOODWILL, OR OTHER INTANGIBLE LOSSES, RESULTING FROM (A) YOUR ACCESS TO OR USE OF OR INABILITY TO ACCESS OR USE THE SERVICES; (B) ANY CONDUCT OR CONTENT OF ANY THIRD PARTY ON THE SERVICES; OR (C) UNAUTHORIZED ACCESS, USE, OR ALTERATION OF YOUR TRANSMISSIONS OR CONTENT.

For the Fold Bitcoin Credit Card, Celtic Bank is the creditor and card issuer, and Fold acts solely as a program manager and service provider. Fold does not make credit decisions and is not responsible for any credit decisions made by Celtic Bank. Disputes regarding credit decisions, credit reporting, or credit card account terms should be directed to Celtic Bank.

Indemnification

You agree to defend, indemnify, and hold harmless Fold, its affiliates, licensors, and service providers, and the irrespective officers, directors, employees, contractors, agents, licensors, suppliers, successors, and assigns from and aainst any claims, liabilities, damages, judgments, awards, losses, costs, expenses, or fees (including reasonable attorneys’ fees) arising out of or relating to your violation of this Privacy Policy or your use of the Services.

Changes to This Privacy Policy

Fold may amend this Privacy Policy from time to time. Use of information we collect is subject to the Privacy Policy in effect at the time such information is used. If we make material changes, we will notify you by posting an announcement on our Site or sending you an email before the change becomes effective. You are bound by any changes when you use the Services after such changes have been posted. We encourage you to review this Privacy Policy periodically.

Contact Information

If you have any questions about this Privacy Policy or our data practices, please contact us:

Fold, Inc.

Email: support@foldapp.com

Phone: 1-866-FOLDAPP (1-866-365-3277)

Address: 2942 North 24th Street, Suite 115, #42035, Phoenix, Arizona 85016

For Fold Bitcoin Credit Card inquiries:

For questions about credit decisions, credit reporting, or Celtic Bank’s privacy practices, contact Celtic Bank atcelticbank.com/contact or review their privacy policy at celticbank.com/privacy. For disputes regarding information reported to consumer reporting agencies, you may contact the agencies directly: Equifax (equifax.com), Experian(experian.com), or TransUnion (transunion.com).