Citizens State Bank — Online Privacy Notice
Last updated May 2026
At Citizens State Bank, protecting your privacy is more than a legal obligation—it is a core part of the trust you place in us. Whether you visit our branches, use our online services, or browse our website, we are committed to safeguarding your information and maintaining stringent security practices. As a community bank that has served Western Colorado for generations, we believe transparency helps strengthen the relationships we build with our customers and our communities. This Online Privacy Notice explains how we collect, use, and protect information when you interact with our website specifically, and outlines the rights and choices available to you. Our commitment is simple: Your information is handled responsibly, securely, and with the utmost respect.
By using this website, you acknowledge that you have reviewed this Online Privacy Notice.
How this Notice Relates to Our Bank Privacy Notice
If you have or apply for a financial product or service with us for personal, family, or household purposes, our Bank Privacy Policy (GLBA/Reg P notice) explains how we collect, share, and protect your nonpublic personal information (“NPI”) and your choices to limit sharing. If there is a conflict between this Online Privacy Policy and our Bank Privacy Policy, the Bank Privacy Policy controls for NPI. You can review it here: https://www.csbcolorado.com/wp-content/uploads/2019/12/Privacy-Policy.pdf
Scope & Information We Collect
This Notice explains how we collect, use, and disclose information when you visit or interact with our website.
We collect information in three ways:
- Information You Provide Directly
Examples include your name, email address, phone number, and information submitted through forms.
- Information Collected Automatically
Device and browser info (IP address, user‑agent), pages viewed, timestamps, referring URLs, and events (clicks/scrolls). We use this to operate the Site, prevent fraud, understand usage, and improve content. Additionally, we may receive aggregated analytics or site‑performance metrics from vendors that help us operate or secure the Site.
- Google Analytics (GA)
We use GA to measure Site usage. GA sets cookies or uses similar technologies to help us analyze traffic and interactions. Google may process this data as an independent party in accordance with its policies. Learn more in Google’s Analytics disclosure and Privacy & Terms. You can opt out by using [Google’s opt‑out tools] and your browser settings.
How We Use Information
- Operate and secure the Site, including detecting, preventing, and responding to security incidents and fraud.
- Measure and improve Site performance and user experience (e.g., content that is helpful and accessible).
- Communicate with you when you contact us, including responding to inquiries.
- Comply with legal obligations and enforce our terms.
These purposes align with permissible processing and disclosure for online activities under federal and state privacy frameworks
How We Share Information
We do not sell your personal information. If we ever engage in “sale” or “sharing” of personal information for cross‑context behavioral advertising (as defined by California law), we will provide the required “Do Not Sell or Share My Personal Information” link and enable opt‑out mechanisms, including honoring Global Privacy Control (GPC) signals. We disclose information to:
- Service providers/contractors that support Site operations (hosting, security, analytics) under contracts that prohibit the service provider from retaining, using, or disclosing the information for purposes other than providing services to us.
- Affiliates (if any) for Site operations consistent with this policy.
- Regulators, law enforcement, or parties to legal process when required by law or to protect rights and security
Advertising, Analytics & Cookies
We use Google Analytics (GA) to understand aggregate website usage and improve performance. GA uses cookies and similar technologies to collect information such as IP address, browser type, device identifiers, and site interactions.
We configure Google Analytics to:
- Avoid collection of sensitive personal or financial account information;
- Limit data sharing features where appropriate; and
- Retain analytics data only for the period necessary to fulfill operational purposes.
Google may process information as an independent controller in accordance with its Privacy Policy and Terms. You may opt out of GA by installing Google’s browser add-on or by adjusting your browser cookie settings.
Cookies & similar technologies:
We use strictly necessary cookies (for Site operation) and analytics cookies (to measure usage). If/when advertising cookies are used, we will present a granular consent banner and settings.
Your Choices
Depending on your state of residence, you may have certain rights regarding personal information we collect online. These may include the right to request access, deletion, correction, or to opt out of certain processing activities.
We do not currently sell or share personal information for cross-context behavioral advertising. If that changes, we will provide a clear and conspicuous method to opt out, including honoring Global Privacy Control (GPC) signals where required by law.
You may: disable cookies through your browser settings; use Google Analytics opt-out tools; and/or contact us to submit a privacy request as described below.
We will verify your identity as required by law before fulfilling applicable requests and will not discriminate against you for exercising your privacy rights.
Children’s Privacy
Our Site is not directed to children under 13, and we do not knowingly collect personal information from children under 13 online. If we learn that we have collected personal information from a child under 13, we will delete it. Parents/guardians who believe their child has provided information may contact us to request deletion. (For clarity, we do not offer online account opening for children under 13 on this Site.)
Security
We maintain administrative, technical, and physical safeguards designed to protect information collected through the Site. These safeguards include encryption in transit, access controls, monitoring, and vendor oversight practices appropriate to the sensitivity of the information.
For customer information governed by the Gramm-Leach-Bliley Act (GLBA), our information security and disclosure practices are described in our Bank Privacy Notice, which controls in the event of any conflict.
Retention of Personal Information
We retain personal information collected through the Site only for as long as reasonably necessary to:
- Fulfill the purposes described in this Notice;
- Maintain appropriate security and fraud prevention controls;
- Comply with applicable legal, regulatory, and record-retention obligations; and
- Resolve disputes or enforce agreements.
Retention periods vary depending on the category of data and operational needs. When information is no longer required, we securely delete or de-identify it in accordance with our internal data retention policies.
State Privacy Rights (California and Colorado)
California
Although our website is intended primarily for customers located in Colorado, California residents may access and interact with our Site. To the extent the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to personal information collected through this Site, this section provides the required disclosures.
Certain personal information collected by Citizens State Bank is subject to the federal Gramm-Leach-Bliley Act (GLBA) and related banking regulations. Information subject to GLBA is exempt from certain provisions of the CCPA/CPRA. This section applies only to personal information collected online that is not otherwise exempt.
Categories of Personal Information Collected
The categories of personal information we collect through this Site, along with sources, business purposes, categories of recipients, and retention criteria, are described in the table below. We collect this information directly from you (such as when you submit a form) and automatically through cookies and similar technologies.
Sale or Sharing of Personal Information
We do not sell personal information.
We do not share personal information for cross-context behavioral advertising.
If our practices change in the future in a manner that constitutes a “sale” or “sharing” under California law, we will update this Notice and provide required opt-out mechanisms.
Retention
We retain personal information in accordance with the retention criteria described in the table above and our internal data retention policies, consistent with operational, security, legal, and regulatory requirements.
California Privacy Rights
Subject to applicable exemptions and verification requirements, California residents may request:
• To know the categories and specific pieces of personal information we have collected;
• The categories of sources from which personal information is collected;
• The business purposes for collecting or disclosing personal information;
• The categories of recipients to whom personal information is disclosed;
• To request deletion of personal information;
• To request correction of inaccurate personal information.
To submit a request, please contact us using the information provided in the “Contact Us” section below. We will verify your identity as required by law before responding to requests and will not discriminate against you for exercising applicable privacy rights. If we are required to recognize browser-based opt-out preference signals, including Global Privacy Control (GPC), we will do so in accordance with applicable law.
The following summarizes what we collect in the recommended structured format:
| Category of Personal Information | Examples & Sources | Business Purpose | Categories of Recipients | Retention Period/Criteria |
| Identifiers | IP address, online identifiers
Automatically collected when visiting site |
Site operation, security, monitoring, fraud prevention, performance analytic | Service providers performing services on our behalf (hosting, security, analytics) | Retained in accordance with internal data retention and security policies and applicable legal obligations |
| Internet or Other Network Activity Information | Pages viewed, browser type, timestamps, referring URLs
Cookies and analytics tools |
Site functionality, performance measurement, security monitoring | Service providers (analytics and website support vendors) | Retained for operational analytics and security purposes consistent with internal retention policies |
| Approximate Geolocation Data | General geographic region derived from IP address
Automatically collected via analytics |
Security monitoring and site performance analysis | Service providers | Retained only as necessary for operational and security purposes |
| Limited Inferences | General site usage trends derived in aggregate form
Derived from analytics data |
Improving website functionality and user experience | Service providers | Retained consistent with analytics data retention practices and internal policy |
Colorado
Citizens State Bank is headquartered in Colorado. Certain personal information collected by financial institutions is regulated by the federal Gramm-Leach-Bliley Act (GLBA) and is exempt from the Colorado Privacy Act (CPA).
To the extent personal information collected through this website is not subject to GLBA and the CPA applies, Colorado residents may have certain rights under applicable law, including the right to:
- Confirm whether we process personal data and access such data;
- Correct inaccuracies in personal data;
- Request deletion of personal data; and
- Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or certain profiling activities.
We do not sell personal data and do not process personal data for targeted advertising or profiling in furtherance of decisions that produce legal or similarly significant effects.
Colorado residents may submit a privacy request using the contact information provided below. We will respond in accordance with applicable law and may require reasonable verification of identity before fulfilling a request.
Where required by law, Colorado residents may appeal a decision regarding a privacy request by contacting us in writing at the address listed below.
Right to Know / Access / Delete / Correct
You may request:
- The categories and specific pieces of personal information collected about you,
- The categories of sources,
- The business or commercial purposes for collection,
- The categories of third parties to whom information is disclosed.
You may request that we delete personal information, subject to legal and operational exceptions.
You may request that we correct inaccurate personal information we maintain.
If we engage in activities that constitute a “sale” or “sharing” under California law in the future, we will honor browser-based opt-out preference signals such as Global Privacy Control (GPC) where required.
International Visitors
Our Site is intended for U.S. visitors and even more specifically to our customers on the Western Slope of Colorado. If you access the Site from outside the United States, please be aware that information may be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
This Site is not directed to individuals located in the European Union or United Kingdom, and we do not intentionally offer financial services or monitor the behavior of individuals in those jurisdictions. If you are located in the EU or UK and believe data protection laws apply to your interaction with this Site, please contact us using the information below.
Linked Websites
Our website may include links to third‑party websites that are not operated or controlled by Citizens State Bank. If you choose to visit these sites, we encourage you to review their privacy policies and terms of use, as their practices may differ from ours. Citizens State Bank is not responsible for the privacy, security, accuracy, or content of any external websites, and we do not provide any guarantees regarding how those third parties collect, use, or safeguard your information.
Social Media
Citizens State Bank may interact with users on social media platforms such as Facebook®, Instagram®, LinkedIn®, etc. Any information you choose to post or share on these platforms—including comments, messages, or profile details—may be visible to others and is governed by the privacy policies and terms of the respective platform. We encourage you to review those policies carefully so you understand how your information may be accessed, used, or shared by the platform and its users.
Change to this Online Privacy Notice
We may update this Notice periodically. We will post the revised version and the effective date will be the date of the Last Update. Material changes will be highlighted on this page, and where required by law, we will provide additional notice (and obtain consent where needed).
Contact Us
Email: [email protected]
Phone: 970-325-4478
Mail: Citizens State Bank — Privacy Office | PO Box A Ouray, CO 81427
