Citizens State Bank — Online Privacy Notice
Revised January 2026
At Citizens State Bank, protecting your privacy is more than a legal obligation—it is a core part of the trust you place in us. Whether you visit our branches, use our online services, or browse our website, we are committed to safeguarding your information and maintaining stringent security practices. As a community bank that has served Western Colorado for generations, we believe transparency helps strengthen the relationships we build with our customers and our communities. This Online Privacy Notice explains how we collect, use, and protect information when you interact with our website specifically, and outlines the rights and choices available to you. Our commitment is simple: Your information is handled responsibly, securely, and with the utmost respect.
By accessing this website, you agree to the information collected and practices described in this Online Privacy Notice. Specifically, this applies to: csbcolorado.com and any website or page we operate that links to this Online Privacy Notice.
How this Notice Relates to Our Bank Privacy Notice
If you have or apply for a financial product or service with us for personal, family, or household purposes, our Bank Privacy Policy (GLBA/Reg P notice) explains how we collect, share, and protect your nonpublic personal information (“NPI”) and your choices to limit sharing. If there is a conflict between this Online Privacy Policy and our Bank Privacy Policy, the Bank Privacy Policy controls for NPI. You can review it here: https://www.csbcolorado.com/wp-content/uploads/2019/12/Privacy-Policy.pdf
Scope & Information We Collect
This Notice explains how we collect, use, and disclose information when you visit or interact with our website.
We collect information in three ways:
- Information You Provide Directly
Examples include your name, email address, phone number, and information submitted through forms.
- Information Collected Automatically
Device and browser info (IP address, user‑agent), pages viewed, timestamps, referring URLs, and events (clicks/scrolls). We use this to operate the Site, prevent fraud, understand usage, and improve content. Additionally, we may receive aggregated analytics or site‑performance metrics from vendors that help us operate or secure the Site.
- Google Analytics (GA): We use GA to measure Site usage. GA sets cookies or uses similar technologies to help us analyze traffic and interactions. Google may process this data as an independent party in accordance with its policies. Learn more in Google’s Analytics disclosure and Privacy & Terms. You can opt out by using [Google’s opt‑out tools] and your browser settings.
How We Use Information
- Operate and secure the Site, including detecting, preventing, and responding to security incidents and fraud.
- Measure and improve Site performance and user experience (e.g., content that is helpful and accessible).
- Communicate with you when you contact us, including responding to inquiries.
- Comply with legal obligations and enforce our terms.
These purposes align with permissible processing and disclosure for online activities under federal and state privacy frameworks
How We Share Information
We do not sell your personal information. If we ever engage in “sale” or “sharing” of personal information for cross‑context behavioral advertising (as defined by California law), we will provide the required “Do Not Sell or Share My Personal Information” link and enable opt‑out mechanisms, including honoring Global Privacy Control (GPC) signals. We disclose information to:
- Service providers/contractors that support Site operations (hosting, security, analytics) under contracts that limit their use to our instructions.
- Affiliates (if any) for Site operations consistent with this policy.
- Regulators, law enforcement, or parties to legal process when required by law or to protect rights and security
Advertising, Analytics & Cookies
Analytics today: We use Google Analytics (GA) only. GA helps us understand aggregate behavior on the Site. We configure GA not to collect or store data in ways that are prohibited by Google terms (e.g., no transmission of sensitive or bank account information through URLs or free‑text fields).
Advertising in the future: We do not currently use Google Ads or run cross‑context behavioral advertising. If we enable these features later (e.g., Google Ads/Remarketing), we will update this policy and present a dedicated Notice of Right to Opt‑Out of Sale/Sharing and cookie controls at or before activation. We will also disclose the categories of personal information used and provide easy opt‑out mechanisms, including GPC.
Cookies & similar technologies:
We use strictly necessary cookies (for Site operation) and analytics cookies (to measure usage). If/when advertising cookies are used, we will present a granular consent banner and settings.
Your Choices
Consent is collected by continued use of the website. State residents may have opt-out rights. Google Analytics opt-out options are available through browser tools.
How to exercise your rights:
Contact our Privacy Team using the information provided below. We will verify your request, respond within statutory timelines, and not discriminate against you for exercising these rights. You may authorize an agent to submit a request on your behalf as permitted by law.
Children’s Privacy
Our Site is not directed to children under 13, and we do not knowingly collect personal information from children under 13 online. If we learn that we have collected personal information from a child under 13, we will delete it. Parents/guardians who believe their child has provided information may contact us to request deletion. (For clarity, we do not offer online account opening for children under 13 on this Site.)
Security
We employ administrative, technical, and physical safeguards appropriate to the sensitivity of information we process online (e.g., TLS encryption in transit, access controls, logging, and vendor due diligence). For GLBA‑covered customer information, our security program and disclosure practices follow federal banking guidance and our Bank Privacy Policy.
Retention
We retain personal information collected via the Site for as long as necessary to fulfill the purposes described above, to comply with laws, and to resolve disputes. Retention periods may vary by data category and purpose; we review these periodically and apply deletion or de‑identification where appropriate.
California Visitors (Privacy Right for California Residents Only)
Our Site is intended for users on the Western Slope of Colorado. However, anyone can interact with our site, including customers who may reside in California. As such, California law provides residents with specific rights regarding their personal information. These rights apply to personal information collected online unless an exemption applies. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), requires businesses to provide detailed disclosures, enable certain consumer rights, and honor browser‑based opt‑out preference signals such as Global Privacy Control (GPC).
The following summarizes what we collect in the recommended structured format:
| Category of Personal Information | Examples | Sources | Purposes of Use | Categories of Third Parties |
| Identifiers | IP address, device ID, online identifiers | Collected automatically when visiting site | Website operations, security, analytics | Service providers (hosting, security, analytics) |
| Internet / Network Activity | Pages viewed, clicks, browser type, timestamps | Cookies and analytics tools | Site performance, fraud prevention, usage analysis | Service providers (analytics, monitoring) |
| Geolocation Data (Approximate) | Region derived from IP address | Automatically via analytics | Security, fraud monitoring, usage patterns | Service providers |
| Inferences (Limited) | Preferences inferred from browsing | Derived from analytics data | Improving site experience | Not shared beyond analytics providers |
Right to Know / Access / Delete / Correct
You may request:
- The categories and specific pieces of personal information collected about you,
- The categories of sources,
- The business or commercial purposes for collection,
- The categories of third parties to whom information is disclosed.
You may request that we delete personal information, subject to legal and operational exceptions.
You may request that we correct inaccurate personal information we maintain.
If we ever engage in sales or sharing, you may opt out at any time. We are required to honor Global Privacy Control (GPC) signals automatically, and provide visible confirmation that your opt‑out request has been processed.
International Visitors
Our Site is intended for U.S. visitors and even more specifically to our customers on the Western Slope of Colorado. If you access the Site from outside the U.S., you understand that information may be processed in the United States, where laws may differ from those in your jurisdiction.
Linked Websites
Our website may include links to third‑party websites that are not operated or controlled by Citizens State Bank. If you choose to visit these sites, we encourage you to review their privacy policies and terms of use, as their practices may differ from ours. Citizens State Bank is not responsible for the privacy, security, accuracy, or content of any external websites, and we do not provide any guarantees regarding how those third parties collect, use, or safeguard your information.
Social Media
Citizens State Bank may interact with users on social media platforms such as Facebook®, Instagram®, LinkedIn®, etc. Any information you choose to post or share on these platforms—including comments, messages, or profile details—may be visible to others and is governed by the privacy policies and terms of the respective platform. We encourage you to review those policies carefully so you understand how your information may be accessed, used, or shared by the platform and its users.
Change to this Online Privacy Notice
We may update this Notice periodically. We will post the revised version and update the effective date. Material changes will be highlighted on this page, and where required by law, we will provide additional notice (and obtain consent where needed).
Contact Us
Email: [email protected]
Phone: 970-325-4478
Mail: Citizens State Bank — Privacy Office | PO Box A Ouray, CO 81427
