Clipper® Privacy Policy

Metropolitan Transportation Commission
Clipper® Program Privacy Policy
The effective date of this Privacy Policy is November 16, 2011
Last updated April 24, 2013

Overview

The Metropolitan Transportation Commission (MTC) is committed to ensuring Clipper® customer privacy and security. Specifically: (1) MTC will not provide personally identifiable information ("PII") from Clipper accounts to any third party without express customer consent, except as described in the Privacy Policy; (2) PII from Clipper® accounts will never be provided to advertisers for their use; and (3) MTC will maintain a secure environment for customer personal information.

This Privacy Policy is intended to provide an understanding of how MTC handles PII collected by the Clipper® Fare Payment System (FPS) program. Among other things, this policy explains the types of information collected from Clipper® customers; the third parties with whom MTC may share this information; and the process by which Clipper® customers are notified about material changes to this Policy.

MTC's contractor, Cubic Transportation Systems, ("CSC Contractor") is the primary operator of the Clipper® Customer Service Center ("CSC") on behalf of MTC. MTC oversees CSC Contractor. Clipper®'s Terms and Conditions notify customers that by enrolling in the Clipper® program and using the system, the customer is allowing MTC, the CSC Contractor, and other third parties referenced herein, to process personal information according to the provisions set forth in the Clipper Cardholder License Agreement and this Privacy Policy.

Definitions

The following definitions apply:

Personally Identifiable Information (PII): PII identifies or describes a person or can be directly linked to a specific individual. Examples of PII include but are not limited to, a person's name, mailing address, business name, alternate contact information (if given), e-mail address, fax numbers, Clipper® card serial number, telephone number, e-mail address, credit card number, security code and expiration date.

Aggregate Data or Aggregate Information: Aggregate Data or Aggregate Information is statistical information that is derived from collective data that relates to a group or category of persons from which PII has been removed. Aggregate Data reflects the characteristics of a large group of anonymous people. MTC may use Aggregate Data and provide Aggregate Data to others to generate statistical reports for the purpose of managing the Clipper® program operations.

Collection of Personally Identifiable Information

A Clipper® card may either be registered or unregistered. MTC, through its Clipper® Customer Service Center (CSC), collects personal information in order to register Clipper® cards with the Clipper FPS. Examples of personal information include a Clipper® cardholder's name, address, telephone number, email address, credit card number and expiration date, or other information that personally identifies a Clipper® cardholder. MTC obtains this personal information from applications and other forms submitted by Clipper® cardholders to the Clipper® Customer Service Center by telephone, mail, facsimile transmission or by electronic submission through the Clipper® website. Data developed as a byproduct of the use of the Clipper® FPS (e.g., a registered user's travel routes and times traveled) is also considered personal information if a card is registered.

How MTC uses Personally Identifiable Information

MTC uses the PII provided in order to effectively and efficiently process enrollments, manage accounts, respond to questions, send customer e-mails about Clipper® program updates, provide information regarding significant changes to this Privacy Policy, and otherwise communicate with Clipper® customers.

PII is only utilized as described in this Privacy Policy.

Third Parties with Whom MTC May Share Personally Identifiable Information

MTC may share PII with the Alameda-Contra Costa Transit District (AC Transit), the Golden Gate Bridge, Highway and Transportation District (Golden Gate Transit), the Peninsula Corridor Joint Powers Board (Caltrain), the San Francisco Bay Area Rapid Transit District (BART), the San Francisco Municipal Transportation Agency (Muni), the San Mateo County Transit District (SamTrans), the Santa Clara Valley Transportation Authority (VTA), and the Water Emergency Transit Agency (WETA) (collectively referred to herein as Clipper® Participating Transit Agencies) for the purpose of operating and managing the Clipper® FPS. In addition, MTC and the Clipper® Participating Transit Agencies may disclose personal information to third-party service providers for the purpose of operating and maintaining the Clipper® FPS, such as managing patron accounts and revenue collection. These contractors are provided only with the PII they need to deliver the service. MTC requires its service providers to maintain the confidentiality of the information and to use it only as necessary to carry out their duties under the Clipper® Program.

The CSC Contractor may share PII with the California Department of Justice and the Better Business Bureau when necessary to respond to consumer complaints.

Besides these entities, PII will not be disclosed to any other third party without express customer consent, except as required to comply with laws or legal processes served on MTC or the CSC Contractor.

Retention of Personally Identifiable Information

MTC, through the CSC Contractor, shall only store the PII of a Clipper® customer that is necessary to perform account functions such as billing, account settlement, or enforcement activities. All PII shall be discarded no later than four years and six months after the account is closed or terminated.

Security of Clipper® Personally Identifiable Information

MTC is committed to the security of customer PII. MTC, together with its CSC Contractor, stores the PII provided by Clipper® customers on computer servers that are located in secure, controlled facilities. Servers are designed with software, hardware and physical security measures in place to prevent unauthorized access.

Access to PII is controlled through the following administrative, technical, and physical security measures. By contract, third parties with whom MTC shares PII are also required to implement adequate security measures to maintain the confidentiality of such information.

Administrative:

  • Access to PII is limited only to certain operations and technical employees for limited, approved purposes based on their specific work responsibilities.
  • Privacy and security training is required for employees with access to PII, upon hire. In addition, regular periodic refresher training is required for those employees.

Technical:

  • Clipper® network perimeters are protected with firewalls.
  • Electronic storage of PII is encrypted.
  • Electronic connections to and from the Clipper® website are encrypted.
  • Vulnerability and penetration tests are conducted on the Clipper® system.
  • Employees' use of Clipper® customer databases is monitored.

Physical:

  • Physical access to MTC and CSC Contractor servers is restricted to authorized technical personnel.
  • Data center access to approved technical personnel is restricted via passcode authentication, and other security protocols.

In addition to MTC's policies and procedures implementing PII security, the Clipper® customer must also do such things as safeguard passwords, PINs, and other authentication information that may be used to access a Clipper® account. Clipper® customers should not disclose authentication information to any third party and should notify MTC of any unauthorized use of their passwords. MTC cannot secure PII that is released by Clipper® customers or PII that customers request MTC to release. In addition, there is a risk that unauthorized third parties may engage in illegal activity by such things as hacking into MTC's security system or the CSC Contractor's security system or by intercepting transmissions of personal information over the Internet. MTC is not responsible for any data obtained in an unauthorized manner, and MTC is the only entity that may authorize obtaining data from the Clipper® FPS.

Please note that the CSC Contractor will never ask Clipper® customers to provide or confirm any information in connection with Clipper® such as credit card numbers, Clipper® card serial numbers, or other PII, unless the customer is logged into the secure Clipper® customer website. If a customer ever has any doubt about the authenticity of an e-mail regarding Clipper® , the customer should open a new web browser, type in , log into the customer's Clipper® account, and then perform the requested activity.

Account access and controls

Creating an account with Clipper® is in the customer's discretion. The required account information consists of PII such as name, business name, mailing address(es), e-mail address, telephone number, fax number, signature, and credit card number, expiration date and security code. MTC may request other optional information, such as alternate contact information, but, in such instances, clearly indicates that such information is optional.

Customers can review and update personal account information at any time. Customers are also able to modify, add, or delete any optional account information by signing into their Clipper® account and editing the account profile. PII can also be reviewed and edited online as discussed below under "Updating Personally Identifiable Information." Clipper® customers can close their account at any time by submitting a completed Clipper® Card Refund Request form (available at ). All account information will be deleted no later than four years and six months after the account is closed or terminated.

Aggregate Data

MTC may also combine the PII provided by Clipper® customers in a non-identifiable format with other information to create Aggregate Data that may be disclosed to third parties. Aggregate Data is used by MTC to improve the Clipper® program and for the marketing of Clipper®. Aggregate Data does not contain any information that could be used to contact or identify individual Clipper® customers or their accounts. For example, MTC may inform third parties regarding the number of Clipper® accounts within a particular zip code. MTC requires third parties with whom Aggregate Data is shared to agree that they will not attempt to make information personally identifiable, such as by combining it with other databases.

Cookies

The Clipper® website (www.clippercard.com) stores "cookies" on the computer systems of users of the website. Cookies are small data elements that a website can store on a user's system.

The cookies used by the Clipper® web site facilitate customer's use of the web site (e.g. remember login names and passwords until the session has ended). The Clipper® web site does not require that users of the website accept these cookies. Also, the Clipper® web site does not store "third party" cookies on the computer systems of users of the website.

Once a patron leaves the Clipper® website, the privacy policy of other web sites visited or linked-to from the Clipper® web site should also be reviewed to understand how these external sites utilize cookies and how the information that is collected through the use of cookies on these websites is utilized.

MTC does not knowingly engage in business with any company or vendor that uses Spyware or Malware. MTC does not market detailed information collected from web sessions that can be directly tied to personal information. Further, MTC does not provide Clipper® customers with downloadable software that collects or utilizes any PII.

Third-Party Websites and Applications

The Clipper® website may contain links to third-party websites operated by entities that are affiliated with Clipper®. These web links may be referenced within content, or placed beside the names or logos of the other entities. MTC does not disclose PII to these third-party websites.

WARNING: Once a patron enters external websites (whether through a service or content link), MTC is not responsible for the privacy practices of those other websites. Please review all privacy policies of external websites you may visit from links on the Clipper® website before using or providing any information to such other websites.

In addition, MTC is not responsible for third-party applications that access or make use of the Clipper® website or any features thereof ("Apps"). Before a Clipper® customer downloads or accesses Apps, he or she should review the terms of use and privacy policies of the Apps to determine how they collect, use, and/or retain PII. MTC is not responsible for the terms of use or privacy policies of Apps, or the use of PII by such Apps.

Updating Personally Identifiable Information
PII can be reviewed and edited online at . The Clipper® website uses functions that have the ability to collect and store self-reported data. These functions enable Clipper® customers to revise, update or review information that has been previously submitted by going back to the applicable function, logging-in and making the desired changes. In addition to this method, customers may update their PII by telephoning the Clipper® Customer Service Center at (877) 878-8883.

Complaints or problems regarding updating personal information should be submitted via the website. The Clipper® Customer Service Center will either resolve the issue or forward the complaint to an appropriate MTC staff member for a response or resolution. MTC strives to answer all queries within 48 business hours, but it may not always be feasible to do so.

If an adequate resolution is not received, please contact MTC's Privacy Officer at:
Metropolitan Transportation Commission
Attn: Privacy Officer
101 Eighth Street, Oakland, CA 94607
Or e-mail: privacy officer@mtc.ca.gov
Or call: 510-817-5700

Changes to this Privacy Policy

Material Changes - MTC will inform Clipper® customers if material changes are made to the Clipper® Program Privacy Policy, in particular, changes that expand the permissible uses or disclosures of PII allowed by the prior version of the Privacy Policy. If MTC makes material changes to the Clipper® Privacy Policy, MTC will notify Clipper® customers by means of posting a conspicuous notice on the Clipper® website that material changes have been made.

Immaterial Changes - MTC may also make non-substantive changes to the Privacy Policy, such as those that do not affect the permissible uses or disclosures of PII. In these instances, MTC may not post a special notice on the Clipper® website.

If MTC decides to make any change to the Clipper® Privacy Policy, material or immaterial, MTC will post the revised policy on the Clipper® website, along with the date of any amendment.

MTC reserves the right to modify this Privacy Policy at any time, so the policy needs to be reviewed frequently by Clipper® customers.

When MTC revises the Privacy Policy, the "last updated" date at the top of the Privacy Policy will reflect the date of the last change. We encourage Clipper® customers to review this Privacy Policy periodically to stay informed about how MTC protects the security of PII collected for the Clipper® Program. Continued use of the Clipper® Program constitutes the customer's agreement to this Privacy Policy and any updates.

E-mails Sent to MTC

This Privacy Policy does not apply to the content of e-mails transmitted directly to MTC. Please do not send PII in an email directly to MTC in order to keep content or data private.

Contact Information

MTC welcomes comments on the Clipper® Privacy Policy. Also, if there are questions about this statement, please contact the MTC Privacy Officer at the address, e-mail or phone number listed above.

History of Changes to Privacy Policy

Date Activity
March 3, 2006 Privacy Policy Established
November 15, 2010 Revisions to Privacy Policy
November 16, 2011 Revisions to Privacy Policy
October 19, 2012 Revisions to address third-party applications that access or make use of the Clipper® Website
April 24, 2013 Revisions to reduce retention period for personal account information from seven years to four years and six months after an account is closed or terminated.

See FAQs about Clipper's Privacy Policy.