1. Scope
Habits, Inc. (“Habits,” “we,” “us,” or “our”) operates websites, mobile applications, and related products and services that help consumers discover, evaluate, and connect with independent financial advisors and advisory firms (collectively, the “Platform”).
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with the Platform.
Habits is a technology platform. Habits is not an investment adviser, broker-dealer, or fiduciary solely by virtue of operating the Platform. Habits does not provide investment, legal, tax, or financial planning advice, does not manage assets, and does not execute transactions.
2. Personal Information We Collect
We collect personal information from several sources, including directly from you, automatically through your use of the Platform, from service providers, and, in some cases, from advisors, business partners, or data connectivity providers.
Depending on how you use the Platform, we may collect the following categories of personal information:
A. Information You Provide Directly
When you browse, register, complete an intake form, request an introduction, book a meeting, contact us, or otherwise interact with the Platform, you may provide information such as:
- name;
- email address;
- mobile phone number;
- city, state, ZIP code, or other location information;
- financial topics of interest;
- preferences regarding the type of financial advisor you would like to explore;
- messages, inquiries, survey responses, or customer support communications; and
- appointment preferences and scheduling information.
If you complete a Quick Match or similar intake flow, you may also provide:
- estimated income ranges;
- estimated asset ranges;
- occupation or life-stage information;
- financial planning needs, goals, or priorities; and
- other context relevant to your request to connect with an advisor.
B. Account and Profile Information
If you create an account or use authenticated Platform features, we may collect:
- login credentials or account identifiers;
- profile details;
- account settings and preferences; and
C. Identity Verification and Fraud Prevention Information
If you use features that require identity verification or fraud prevention controls, we may collect identifiers and other information needed to verify your identity, confirm eligibility, protect against fraud, or secure the Platform. This may include information collected directly from you and information processed by third-party verification providers.
We use this information for security, fraud prevention, identity verification, and compliance-related purposes. We do not use identity verification information to provide investment advice, make suitability determinations, or evaluate whether you should engage any particular advisor.
D. Financial Account and Connectivity Information
If you choose to link external financial accounts or use financial data connectivity features, we may receive information from third-party data connectivity providers and financial institutions, such as:
- account type;
- institution name;
- balances;
- holdings;
- transaction data; and
- other account-level financial information made available through the selected integration.
Participation in account linking is optional and initiated by you. Linked account information is used to provide Platform functionality and, where applicable, to support your use of organizational or evaluation tools within the Platform.
E. Information Collected Automatically
When you access or use the Platform, we and our service providers may automatically collect information such as:
- IP address;
- device identifiers;
- browser type;
- operating system;
- referral URL;
- pages viewed;
- interactions with the Platform;
- session activity;
- approximate location derived from IP address; and
- diagnostic, analytics, and performance information.
We collect this information using cookies, pixels, SDKs, logs, and similar technologies for security, analytics, performance monitoring, debugging, fraud prevention, advertising measurement, retargeting, and Platform functionality.
F. Information from Advisors, Business Partners, and Service Providers
We may receive information about you from:
- advisors or advisory firms when responding to an inquiry, scheduling, or connection request;
- service providers that support identity verification, communications, analytics, hosting, CRM, or customer support;
- data connectivity providers involved in account linking; and
- referral or enterprise partners involved in an introduction or routing workflow.
3. How We Use Personal Information
We use personal information for legitimate business and operational purposes, including to:
- operate, maintain, secure, and improve the Platform;
- create and administer accounts;
- facilitate discovery, filtering, matching, routing, scheduling, and introductions between users and advisors;
- process intake forms, inquiries, and requests for connections;
- support onboarding, customer service, and technical support;
- verify identity, detect fraud, prevent abuse, and protect users and the Platform;
- provide financial account connectivity features you request;
- communicate with you about your account, service updates, support matters, and Platform features;
- perform analytics, troubleshooting, quality assurance, product development, and advertising measurement;
- personalize and improve site experience;
- support advertising, retargeting, and campaign attribution where permitted by law;
- enforce our terms, policies, and agreements; and
- comply with legal, regulatory, contractual, and recordkeeping obligations.
Habits does not use personal information to provide personalized investment advice or to make suitability determinations regarding specific advisors.
4. Cookies, Pixels, Analytics, and Advertising Technologies
We and our service providers use cookies, pixels, SDKs, tags, and similar technologies to:
- keep the Platform functioning;
- remember preferences and session information;
- measure usage and performance;
- detect fraud, abuse, and technical issues;
- understand how users interact with the Platform;
- measure the effectiveness of advertising and marketing campaigns; and
- support interest-based or cross-context behavioral advertising, where permitted by law.
These technologies may collect or disclose identifiers, device information, browser information, IP address, internet or network activity information, approximate geolocation, and interactions with our website or applications.
We may work with advertising and analytics partners, including platforms such as Meta and Google, to help us understand usage, measure campaigns, and deliver more relevant advertising.
You can control certain cookies through your browser or device settings. Blocking some technologies may affect Platform functionality. Residents of certain states, including California, may have additional rights to opt out of certain uses or disclosures of personal information for targeted advertising or cross-context behavioral advertising. Please review the “California and U.S. State Privacy Rights” section below for more information.
5. How We Disclose Personal Information
We may disclose personal information in the following circumstances:
A. With Financial Advisors and Advisory Firms
If you ask to be connected with an advisor, request an introduction, submit an inquiry, book a meeting, or otherwise use a Platform feature designed to connect you with an advisor or firm, we may disclose relevant personal information to one or more advisors, advisory firms, or enterprise partners to facilitate your request.
Depending on the workflow, information disclosed may include:
- your name and contact information;
- location;
- intake responses;
- financial planning interests and preferences;
- self-reported financial profile information;
- scheduling information;
- communications you submit through the Platform; and
- other context relevant to the requested introduction or booking.
Once your information is shared with an advisor, advisory firm, or enterprise partner, that party is independently responsible for its own data handling practices, regulatory obligations, and privacy practices.
B. With Service Providers and Contractors
We disclose personal information to vendors and service providers that perform services on our behalf, such as:
- cloud hosting and infrastructure;
- identity verification and fraud prevention;
- financial account connectivity;
- analytics and product support;
- advertising measurement and campaign attribution;
- CRM and customer communications;
- scheduling and workflow support; and
- customer service and operational support.
These parties are authorized to process personal information only as necessary to provide services to us or as otherwise permitted by law.
C. With Advertising and Analytics Partners
We may disclose certain identifiers, device information, internet or network activity information, approximate geolocation, and related online activity information to advertising, measurement, and analytics partners in connection with campaign measurement, retargeting, and cross-context behavioral advertising.
We do not sell personal information for money. However, some of these disclosures may constitute “sharing” under California law.
D. For Legal, Compliance, and Protection Purposes
We may disclose personal information when we believe in good faith that disclosure is necessary to:
- comply with law, regulation, court order, subpoena, or legal process;
- respond to lawful requests from government or regulatory authorities;
- enforce our agreements, policies, or rights;
- detect, investigate, or prevent fraud, security incidents, or illegal activity; or
- protect the rights, property, safety, or security of Habits, our users, advisors, or others.
E. Corporate Transactions
We may disclose personal information in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to customary confidentiality protections.
F. With Your Direction or Consent
We may disclose personal information for other purposes where you direct us to do so or consent to the disclosure.
6. Account Linking and Advisor Sharing
If you choose to link financial accounts, linked account information is used to provide the functionality you request through the Platform. Unless you expressly direct otherwise through the relevant Platform workflow, we do not disclose linked account information to advisors merely because you linked an account.
If a feature is designed to share selected financial information with an advisor as part of a connection, booking, or evaluation process, the relevant workflow should make that sharing clear at the time of use.
7. Communications
We may contact you by email, phone, or text message for transactional, operational, service, onboarding, scheduling, or support-related purposes.
Where required by law, we will obtain appropriate consent before sending marketing or promotional communications. You may opt out of non-essential marketing communications by using the unsubscribe mechanism in the message or by contacting us.
8. Data Rentention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:
- provide the Platform and requested services;
- maintain account records;
- support security, fraud prevention, and abuse prevention;
- comply with legal, tax, accounting, regulatory, and recordkeeping obligations; and
- enforce agreements and resolve disputes.
Because retention periods vary based on the category of personal information and the purpose for which it was collected, we determine retention periods using criteria such as:
- the nature and sensitivity of the information;
- whether the information is needed to provide ongoing services;
- legal, contractual, tax, accounting, and regulatory retention obligations;
- security and fraud prevention needs; and
- dispute resolution and enforcement needs.
9. Data Security
We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, destruction, loss, alteration, or disclosure.
No system is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for notifying us if you suspect unauthorized access to your account.
10. Your Choices and General Privacy Rights
Depending on where you live and the nature of your relationship with us, you may have rights under applicable law, including the right to:
- access personal information we hold about you;
- correct inaccurate personal information;
- delete personal information, subject to legal exceptions;
- obtain a portable copy of certain personal information;
- opt out of certain communications;
- opt out of certain uses or disclosures for targeted advertising or cross-context behavioral advertising; and
- not be discriminated against for exercising applicable privacy rights.
We may take reasonable steps to verify your identity before fulfilling a request. Authorized agents may submit requests on your behalf where permitted by law.
To submit a privacy request, contact us at support@usehabits.com.
11. California and U.S. State Privacy Rights
This section supplements the rest of this Privacy Policy for residents of states with applicable privacy laws, including California to the extent applicable.
A. Notice at Collection
At or before the point of collection, we may provide a notice that describes the categories of personal information we collect, the purposes for which we collect or use that information, whether the information is sold or shared, and retention information, as required by applicable law.
B. Categories of Personal Information Collected
In the preceding 12 months, depending on how you used the Platform, we may have collected the following categories of personal information:
- identifiers and contact information;
- customer records and account information;
- commercial information, such as service interactions and subscription or billing information if applicable;
- internet or network activity information;
- approximate geolocation information;
- professional or employment-related information where provided;
- financial profile information, including self-reported income, assets, and linked account information where you choose to provide or connect it;
- communications and support information; and
- sensitive personal information, if collected, such as government-issued identifier information used for identity verification and certain financial account information used to provide requested features.
C. Sources of Personal Information
We collect personal information from:
- you directly;
- your device or browser;
- our service providers;
- financial account connectivity providers and financial institutions, if you choose to link accounts; and
- advisors, firms, and business partners involved in a requested connection or workflow.
D. Business and Commercial Purposes
We collect, use, and disclose personal information for the purposes described in this Privacy Policy, including:
- Platform operations;
- matching, routing, scheduling, and introductions;
- support and customer service;
- analytics, product improvement, and performance monitoring;
- fraud prevention and security;
- advertising measurement and retargeting; and
- legal and regulatory compliance.
E. Categories of Third Parties to Whom We Disclose Personal Information
We may disclose personal information to:
- advisors, firms, or enterprise partners in connection with requested introductions or bookings;
- service providers and contractors;
- advertising, analytics, and measurement partners;
- regulators, law enforcement, courts, and counterparties where legally required or appropriate; and
- transaction counterparties in connection with a corporate transaction.
F. Sale and Sharing
We do not sell personal information for money.
We may, however, share certain categories of personal information with advertising and analytics partners for cross-context behavioral advertising, retargeting, advertising measurement, and similar purposes. Depending on how you use the Platform, these categories may include:
- identifiers;
- device and browser information;
- internet or network activity information;
- approximate geolocation information; and
- related usage data.
G. Sensative Personal Information
Where we collect sensitive personal information, we use it only for purposes reasonably necessary and proportionate to provide requested services, verify identity, maintain security, prevent fraud, comply with law, and support related internal operational purposes.
H. Your California and State Privacy Rights
Subject to applicable law, you may have the right to:
- know the categories and specific pieces of personal information we have collected about you;
- know the categories of personal information we have disclosed for a business purpose and the categories of third parties to whom it was disclosed;
- know the categories of personal information we have sold or shared, if any, and the categories of third parties involved;
- request deletion of personal information;
- request correction of inaccurate personal information;
- request a portable copy of certain personal information;
- opt out of the sale or sharing of personal information; and
- not receive discriminatory treatment for exercising privacy rights.
I. Do Not Sell or Share My Personal Information
If you are entitled to opt out of the sale or sharing of your personal information, you may exercise that right by:
- using the Do Not Sell or Share My Personal Information link on our website; or
- contacting us at support@usehabits.com.
J. Global Privacy Control
Where required by applicable law, we process opt-out preference signals, such as Global Privacy Control (GPC), as a request to opt out of sale and sharing for the browser or device, and in some cases for the consumer more broadly where legally required and technically supported.
K. Authorized Agents and Appeals
Authorized agents may submit requests on your behalf where permitted by law. We may require proof of authorization and identity verification.
If your request is denied and you have a right to appeal under applicable law, you may do so by replying to our response or contacting support@usehabits.com with “Privacy Appeal” in the subject line.
12. International Users
If you access the Platform from outside the United States, you understand that your personal information may be collected, transferred to, stored in, and processed in the United States and other jurisdictions where we or our service providers operate.Where applicable, we process personal information on legal bases such as performance of a contract, legitimate interests, consent, and compliance with legal obligations.
13. Children's Privacy
The Platform is not intended for individuals under 18 years of age, and we do not knowingly collect personal information from children under 18.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated version on the Platform and update the “Last Updated” date above. Where required by law, we will provide additional notice.