Last Updated: August 3, 2026
This Privacy Policy describes how Nimbus LLC, doing business as Third National (“Third National,” “we,” “our,” or “us”), collects, uses, discloses, and safeguards information about individuals who apply for or use our financial products and services. Third National is a regulated United States financial institution and card issuer. We are subject to applicable federal and state banking laws, including the Gramm-Leach-Bliley Act (“GLBA”), the Bank Secrecy Act (“BSA”), and related anti-money laundering and sanctions regulations.
This Privacy Policy applies to information collected through our website, through payment cards issued by us, through stablecoin-enabled settlement services supported by us, and through any related banking services we provide. It does not apply to third-party websites, applications, or services that are governed by their own privacy notices.
By applying for or using our Services, you acknowledge that you have read and understand this Privacy Policy.
In general, this Privacy Policy explains what information we collect, how we use it, how we share it, how we safeguard it, and the rights and choices that may be available to you under applicable law. As a financial institution, we collect and process information in order to provide regulated banking services, comply with legal obligations, prevent fraud, and protect the safety and integrity of the financial system.
We collect personal information that you provide when you apply for an account, request a card, access our services, contact us, or otherwise interact with us. This may include your name, residential address, email address, telephone number, date of birth, Social Security number or other government-issued identification number, driver’s license or passport information, employment or income information, and account credentials.
Certain information we collect constitutes sensitive personal information under applicable law. This includes government-issued identification numbers, financial account numbers, transaction history, authentication credentials, and, where applicable, precise geolocation data used for fraud detection and security purposes. We use such information only as reasonably necessary to provide services, verify identity, prevent fraud, and comply with regulatory requirements.
In order to comply with customer identification and anti-money laundering laws, we may engage contracted service providers to assist with identity verification, fraud screening, and onboarding processes. These providers process information solely on our behalf and subject to written agreements requiring appropriate security safeguards and restrictions on use.
Where biometric verification technology is used during identity verification, biometric identifiers such as facial geometry derived from government-issued identification and live images may be collected and processed by a contracted provider on our behalf. Such information is used exclusively for identity verification, fraud prevention, and regulatory compliance. We do not sell biometric information and retain it only as long as necessary to satisfy applicable legal and regulatory obligations.
When you access our website or digital services, we may automatically collect certain technical information, including your IP address, browser type, device identifiers, operating system, and usage data. We may use cookies or similar technologies to support website functionality, security, and analytics. You may configure your browser settings to refuse cookies; however, certain features of our website may not function properly without them.
In connection with providing card and settlement services, we collect and maintain records of transactions, including transaction amounts, merchant information, timestamps, account balances, repayment history, wallet addresses associated with settlement activity, and related transactional metadata. We also maintain records required to comply with applicable banking, sanctions, and anti-money laundering regulations.
We collect and use information for legitimate business and regulatory purposes, including to establish and maintain accounts; verify identity; assess eligibility; underwrite and service credit or debit products; process transactions; conduct sanctions screening; comply with BSA, AML, and other regulatory obligations; detect and prevent fraud; respond to legal process; maintain the security of our systems; and improve the quality and reliability of our services.
We may use automated systems to support fraud detection, sanctions screening, transaction monitoring, and identity verification. Such systems are designed to support regulatory compliance and protect against unauthorized activity. Where required by applicable law, individuals may request additional information about automated processing that significantly affects them.
Certain transactions supported by Third National may settle on public blockchain networks. Blockchain networks operate as distributed ledgers and are generally immutable. As a result, transaction details such as wallet addresses, timestamps, and transaction amounts may be recorded permanently on the blockchain.
Third National does not publish customers’ names, residential addresses, Social Security numbers, or similar directly identifying information to public blockchains. While we may delete or anonymize personal information maintained within our internal systems where legally permissible, we cannot alter or delete information recorded on public blockchain networks. We may share transaction-related information with blockchain analytics providers for purposes of sanctions compliance, fraud detection, and risk monitoring.
We disclose personal information only as permitted or required by law and consistent with our obligations as a financial institution.
We may share information with service providers that perform services on our behalf, including identity verification providers, fraud monitoring vendors, payment processors, card networks, cloud infrastructure providers, and compliance monitoring providers. These service providers are contractually obligated to safeguard information and to use it solely for authorized purposes.
We may share information with financial technology program managers or partners in connection with card programs or services they facilitate, where such sharing is necessary to provide services and subject to contractual restrictions and regulatory requirements.
We may disclose information to federal and state banking regulators, law enforcement authorities, courts, or other governmental bodies as required by law or legal process.
In the event of a merger, acquisition, or corporate restructuring, personal information may be transferred as part of that transaction, subject to applicable legal protections.
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, or destruction. These safeguards include encryption of sensitive data in transit and at rest, access controls, authentication mechanisms, transaction monitoring systems, internal security testing, and employee training. Our information security program is designed to align with applicable banking regulatory guidance and industry standards.
Despite these safeguards, no system can guarantee absolute security. We encourage individuals to take appropriate steps to protect account credentials and to notify us promptly of any suspected unauthorized activity.
We retain personal information for as long as necessary to provide services, comply with legal obligations, resolve disputes, enforce agreements, and protect the integrity of the financial system. Certain records, including customer identification records and transaction data, are retained for periods required by federal banking and anti-money laundering laws, which may extend for five years or longer following account closure.
Where permitted by law, we may retain de-identified or aggregated information for analytical and operational purposes.
Residents of certain U.S. states may have rights under state privacy laws to request access to, correction of, or deletion of certain personal information, or to opt out of certain types of data sharing. However, because Third National is a financial institution subject to GLBA, much of the information we collect in connection with providing financial products and services is exempt from certain state privacy law requirements.
We will review and respond to requests in accordance with applicable law. Requests may be submitted by contacting us at [privacy@3rdnational.com].
We recognize Global Privacy Control signals where required under applicable state law.
Where Third National processes personal data relating to individuals located in the European Economic Area (“EEA”), the United Kingdom (“UK”), or Switzerland, we do so in accordance with applicable data protection laws, including Regulation (EU) 2016/679 (the General Data Protection Regulation or “GDPR”), the UK GDPR, and the Swiss Federal Act on Data Protection, as applicable.
For purposes of these laws, Third National acts as a data controller with respect to personal data processed in connection with providing regulated banking, payment, and settlement services. In limited circumstances, where we provide services at the direction of another regulated financial institution, our role may be that of a processor; however, in connection with card issuance and customer account services, we generally act as controller.
We process personal data of individuals in the EEA, UK, and Switzerland only where we have a lawful basis to do so. The applicable lawful bases include:
Performance of a Contract. We process personal data where necessary to take steps at your request prior to entering into a contract and to perform our contractual obligations, including establishing and maintaining accounts, issuing payment cards, processing transactions, and providing settlement services.
Compliance with Legal Obligations. As a regulated financial institution, we are subject to extensive legal and regulatory requirements, including anti-money laundering, counter-terrorist financing, sanctions screening, fraud monitoring, prudential regulation, and recordkeeping obligations. Processing of personal data for customer identification, transaction monitoring, regulatory reporting, and related compliance functions is necessary for compliance with these legal obligations.
Legitimate Interests. We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by the rights and freedoms of the individual. Such legitimate interests include protecting the security and integrity of our systems, preventing fraud, ensuring operational resilience, improving service quality, conducting internal audits, and defending legal claims. Where we rely on legitimate interests, we conduct appropriate assessments to ensure a balanced and proportionate approach.
Consent. In limited circumstances, we may rely on consent as a lawful basis, such as where biometric verification technologies are used in a manner requiring consent under applicable law, or where optional communications are provided. Where consent is relied upon, individuals may withdraw consent at any time, subject to the fact that certain services may not be available without the relevant processing.
We may use automated processing, including transaction monitoring systems and fraud detection tools, to support regulatory compliance and risk management. Such systems are designed to identify suspicious activity, prevent fraud, and ensure compliance with sanctions and financial crime regulations. Where automated processing produces legal or similarly significant effects, individuals may have the right to request human review, to express their point of view, and to contest the decision, subject to limitations where processing is required by law.
We retain personal data for no longer than necessary to fulfill the purposes for which it was collected, including compliance with applicable legal, regulatory, accounting, and reporting requirements. Financial services regulations may require retention of certain customer identification and transaction records for extended periods. Where retention is no longer required, personal data is securely deleted or anonymized.
Personal data may be transferred to and processed in the United States or other jurisdictions outside the EEA, UK, or Switzerland. Where such transfers occur, we implement appropriate safeguards in accordance with applicable data protection law. These safeguards may include the use of European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement, or other legally recognized transfer mechanisms designed to ensure that personal data receives a level of protection essentially equivalent to that required under applicable law.
Subject to applicable limitations, individuals in the EEA, UK, and Switzerland may have the right to request access to their personal data, to request rectification of inaccurate data, to request erasure, to restrict processing, to object to processing based on legitimate interests, and to request data portability.
These rights may be limited where processing is necessary to comply with legal obligations, including financial regulatory requirements, or to establish, exercise, or defend legal claims.
Individuals also have the right to lodge a complaint with a supervisory authority in their country of residence, place of work, or where an alleged infringement has occurred.
Individuals located in the EEA, UK, or Switzerland who wish to exercise their data protection rights or have questions regarding the processing of their personal data may contact us at:
If required under applicable law, Third National will appoint a representative in the European Union or United Kingdom and make contact details available upon request.
We support your right to control and move your financial data, in compliance with CFPB Rule 1033 (U.S.), PSD3/PSR (EU), and Open Finance mandates (Brazil). We do not use "screen scraping" (collecting your login credentials to access your accounts). If you authorize a third party to access your Rain account data, we will share only data reasonably necessary for the requested service through secure APIs.
If you are a resident of Brazil, you have specific rights under the General Data Protection Law ("LGPD").
As a regulated financial institution, Third National maintains policies, procedures, and controls designed to support operational resilience, third-party risk management, and regulatory compliance. We conduct oversight of service providers and maintain contractual safeguards consistent with applicable supervisory expectations. Where applicable, our governance and risk management practices are designed to align with relevant regulatory frameworks (i.e., DORA, PSD2) addressing digital operational resilience and information security.
Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from anyone under 18. If you are under 18, do not use our Services or provide any personal information. If we receive signals indicating a user is a minor, we will apply heightened privacy protections automatically.
If you believe we have collected information from a minor, please contact us immediately at legal@rain.xyz
Our separate Financial Privacy Notice, provided in accordance with the Gramm-Leach-Bliley Act, describes how we collect, share, and protect nonpublic personal information and your rights to limit certain types of sharing. If there is any conflict between this Privacy Policy and the Financial Privacy Notice, the Financial Privacy Notice governs with respect to GLBA-covered information.
We may update this Privacy Policy from time to time. Material changes will be communicated in accordance with applicable law.
If you have questions about this Privacy Policy or wish to exercise applicable privacy rights, please contact:
Nimbus LLC, d/b/a Third National
273 Ave. Ponce de León,
Estudio 6, 1st Fl. PMB #1404,
San Juan, PR 00917
legal@rain.xyz
(787) 737-8412