What we store, and what we never store
This is why someone who got into your account still could not take your card details: they are not
there.
What protects your account
Three separate things, and an intruder would need all of them:1
Your Account Number
Assigned by us. Not guessable, and not derived from your name or date of birth.
2
Your Access Code
Also assigned by us, numeric and long. It cannot be changed online — see
Access Code security.
3
Something only you know
Your date of birth, or the last four digits of your Social Security number. This is never
printed on your statement.
Who we share your information with
Some sharing is how the account works, and you cannot limit it. Some we do not do at all.
Our affiliates include sales finance and debt collection companies. Unrelated companies include the
retail seller you bought from.
Vermont, California and Nevada residents have additional protections, and we do not sell your
information. The full notice is in our
Privacy Policy.
Your lender has its own privacy notice, and it may differ from ours. The privacy page carries
several — UAS first, then the bank or credit union that funded your loan. Read the one that names
your lender as well as ours; they do not say the same things about sharing.
How we secure our systems
We use security measures that comply with federal law, including computer safeguards, secured files and secured buildings, and we maintain PCI DSS compliance for card data. Card and bank account data is encrypted both in transit and at rest. Your security code is never retained once the authorization it was used for has expired. Access to payment data is limited to staff with a documented reason to have it. Our security is tested rather than asserted: a PCI DSS assessment every year, carried out at the level that applies to us by a qualified assessor, and external vulnerability scans every quarter by an approved scanning vendor. Companies that handle card or bank data on our behalf have to meet the PCI standard that applies to them, and prove it to us annually. Our information security program is also examined independently. We hold SOC 1 Type 2 and SOC 2 Type 2 reports covering security, availability and confidentiality, and our program has been reviewed against ISO/IEC 27001.Those reports are prepared for institutional partners and auditors and are not distributed to the
public. If you are evaluating UAS on behalf of a lender or school, request the vendor-management
package through your UAS contact.
How we contact you, and how we don’t
We may call, text, email or write to you about your account, including using automated dialing and prerecorded messages — but not to market to you. Calls may be monitored or recorded. We will never ask you for your full card number or your security code by email or text. If you receive a message that does, do not reply to it — see How and when we contact you.If you think something is wrong
Call us. If you believe someone has used your account, or that the account is not yours at all, say so when you call — that is handled differently from a routine question, and there is a separate identity-theft route in Opening a support request.Contact us
Have your Account Number to hand if you have it.