Exciting news! On October 27, 2025, our holding company, FirstSun Capital Bancorp and First Foundation Inc. jointly announced that we have entered into a definitive merger agreement. Read the full announcement on the FirstSun Investor Relations website: https://ir.firstsuncb.com/news/news-details/2025/FirstSun-Capital-Bancorp-and-First-Foundation-Inc--Combining-in-All-Stock-Merger/default.aspx
Important Fraud Alert: We have received reports of fraudulent calls appearing to be from Sunflower Bank. If someone contacts you claiming to be from Sunflower Bank or First National 1870 and asks you to provide online banking login credentials or account information, do not follow their instructions and hang up because #BanksNeverAskThat. Do not provide any details or visit any websites at their request. Please call our Customer Care directly at 888.827.5564 if you have any concerns.
Digital Privacy Notice
Digital Privacy Notice
Last Modified: 07.01.2025 [Print PDF of Notice]
Introduction
Sunflower Bank, N.A. and FirstSun Capital Bancorp, our financial holding company, (“Sunflower Bank”, “we”, “us” or “our”), respects your privacy and is committed to protecting your personal information.
This Digital Privacy Notice explains how we collect, use, and protect information when you interact with us online. It applies when you visit our websites (such as sunflowerbank.com, firstnational1870.com, firstencorefunds.com or ir.firstsuncb.com or use other online services – including our mobile apps and official social media pages – that link to this Notice. By using these online services, you agree to the practices described in this Notice.
What This Notice Covers: This notice covers information we collect through: (1) our websites and mobile applications; (2) email, text, and other electronic communications between you and Sunflower Bank online; and (3) Sunflower Bank advertisements or content on third-party websites (when those ads or content include a link to this notice). In short, if you’re interacting with Sunflower Bank digitally in the U.S., this notice likely applies.
What This Notice Does Not Cover: This notice does not apply to information collected through other means, such as data gathered offline or through websites that do not link to this notice. For example, information you provide in person at a branch or on a third-party site that we don’t control would be outside the scope of this notice. Additionally, any third-party websites or services that have their own privacy policies are not covered here. We encourage you to review the privacy policies of any other sites you visit.
Other Privacy Notices: If you are a Sunflower Bank customer with a financial account or loan, please note that a different privacy disclosure applies to much of your information. Our U.S. Consumer Privacy Notice (sometimes called a “Privacy Statement”) describes how we collect, use, and share our customers’ personal information in accordance with federal law. You can find that notice on our website or request a copy from us. In the event of any differences between this Digital Privacy Notice and the U.S. Consumer Privacy Notice, the U.S. Consumer Privacy Notice will govern for customer account information.
If you are a California resident, you have special privacy rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) amendments. These laws give you more control over your personal information. Please refer to the Privacy Center to review our California Consumer Privacy Act Notices and Request Form.
Note: This Notice is intended for individuals in the United States. It focuses on U.S. privacy rights and laws. Our online services are not intended for children under 13, and we do not knowingly collect personal information from children under 13 without parental consent. If you are under 13, please do not submit any personal information to us through our online services.
Information We Collect and How We Collect It
We want you to understand what information we collect about you and how we collect it. The types of information we gather online generally fall into two categories: (1) information you provide directly, and (2) information collected automatically (for example, via cookies or similar technologies).
Information You Provide to Us
You may give us information directly when using our online services. In most cases, this happens when you choose to interact with features on our sites or apps. For example, you provide personal details when you:
- Fill out forms on our website (for instance, when registering for online banking, opening an account, entering a promotion, or requesting information). This may include your name, contact information (address, email, phone number), account credentials, or other details needed for the form.
- Contact us or correspond with us online. If you send us an email, message, or use a support chat, we will collect your name, email address, or other contact information along with the content of your communications.
- Respond to surveys or offers. We might invite you to complete a customer survey or feedback form. If you do so, we collect the information you provide in your responses.
- Use our search or tools on the site. For example, if you use our website’s search bar or financial calculators, we may collect the queries or inputs you provide.
- Enroll in Online Banking or other services. When you sign up for online account access or other digital services, we’ll ask for information needed to create and secure your account (such as identity verification details).
In short, any time you directly input information into our online forms, fields, or communications, that information is collected and sent to Sunflower Bank. We will use it for the purpose for which you provided it (and as otherwise described in this notice).
Information We Collect Automatically
We also collect some information automatically when you interact with our websites or apps. This helps us understand how our online services are used and lets us improve your experience. The automatically collected data may include:
- Usage details: We record information about your visits to our sites, such as the pages you view, the links you click, search queries, and the date/time of your visits. We may also note how you got to our site (for example, if you clicked a Sunflower Bank ad on another site).
- Device and network information: We receive data about the device and internet connection you use. This includes your IP address, browser type, device type (e.g. PC or smartphone), operating system, and other technical information. This helps us with things like adapting our site to your device and troubleshooting technical issues.
- Online activities across sites: We may collect information about your activities on other websites over time, if those sites also use our cookies or similar tracking technologies (this is sometimes called behavioral tracking). For instance, we could learn that you visited a site that advertises our products, which helps us measure the effectiveness of our ads.
Much of this data is collected through cookies and similar tracking technologies, which are explained in the next section. Importantly, the information we automatically gather (such as site usage stats or device identifiers) generally does not directly identify you by name. However, if you have an account with us or have provided personal information on our site, we may link the automatically collected data to other information we have about you. For example, if you are logged into online banking, we can connect your site usage to your customer profile. We use this combined information to customize your experience and for the other purposes described below.
Online Tracking Technologies
Like most websites and apps, we use cookies and other online tracking technologies to collect information automatically when you use our services. These technologies help our site function, enhance your experience, and allow us to analyze usage and deliver personalized content. Here’s a plain-language breakdown of what we use:
- Cookies: A cookie is a small text file that a website saves on your computer or device. We use cookies to remember your preferences and settings, keep you logged into your accounts, and understand how people use our site. For example, cookies can tell us whether you’ve visited before and what pages you looked at. They also help us speed up your navigation (for instance, by remembering your preferences so you don’t have to re-enter information). You can control cookies through your browser settings – for example, you can choose to refuse certain cookies. Just keep in mind that if you disable all cookies, some parts of our website might not work properly for you.
- Flash Cookies & Local Storage: We might use local storage objects (sometimes called Flash cookies or HTML5 local storage) to store information about your use of our site (such as video settings or animation progress). These are not managed by browser cookie settings and may require you to adjust settings in tools like your Adobe Flash Player (if you use one). However, because Flash technology is now less common, this likely applies only in special cases on our site.
- Web Beacons: Our web pages and emails may contain tiny electronic images known as web beacons or pixel tags. These are essentially small bits of code that can tell us whether you opened an email or viewed a particular webpage. Web beacons help us count users, gauge the effectiveness of our email campaigns, and compile statistics about our website’s performance.
Location Services. If you have enabled location services on your phone and agree to the collection of your location information when prompted by one of our mobile applications, we will collect location data when you use the application even when the application is closed or not in use. If you do not want us to collect this information, you may decline the collection of your location when prompted or adjust the location services settings on your device.
These tracking technologies do not collect personal details like your name or account numbers by themselves. Instead, they gather device and usage information (as described in the previous section). We may tie this information to you if you’ve logged in or otherwise provided personal info, but we primarily use it in aggregate form to improve our services.
Third-Party Tracking and Advertising
We want you to know that third-party companies may also use cookies or other tracking tools on our online services. This typically happens when we use trusted third-party providers to help us with site analytics, advertising, and social media integration. For example:
- Analytics: We use services like Google Analytics to understand how visitors use our site. These services use their own cookies or similar identifiers to collect data about site traffic and behavior. This helps us analyze usage patterns and improve our webpages. Google Analytics, for instance, can provide us aggregate data on which pages are most popular, how long users stay on each page, and what site referred you to us. Google’s ability to use and share information about your visits to our site is restricted by Google’s own privacy policies. If you don’t want to be part of Google Analytics’ data collection, you can opt out by installing the Google Analytics Opt-out Browser Add-on (a small tool provided by Google).
- Advertising Partners: We may partner with advertising networks or social media platforms to show you Sunflower Bank ads on other sites. These partners may place cookies or web beacons on our site (or use similar tracking via our ads on their site) to collect information about your online activities over time and across different websites. This practice is commonly called interest-based advertising or online behavioral advertising. It allows us, for example, to show you a Sunflower Bank offer on another website after you’ve visited our site. Important: The data collected via these third-party cookies and trackers may be used by those third parties for their own purposes, according to their privacy policies. We do not control the data practices of these third parties. However, we want to reassure you that we do not share information that identifies you personally with unaffiliated third parties for their own marketing use, unless we have your consent.
Do Not Track: Some web browsers offer a “Do Not Track” (DNT ) setting that signals to websites that you do not want to be tracked across different sites. Currently, our websites do not respond to DNT signals, because there is not yet a consistent industry standard for how to interpret them. Instead, we offer the choice tools described below (like cookie controls and advertising opt-outs) to manage your tracking preferences.
How We Use Your Information
We use information that we collect about you for a variety of purposes — all aimed at serving you better, operating our business, and protecting against risks. Here are the main ways in which we may use your information (whether collected directly from you or automatically):
- To provide and improve our services: We use your information to deliver the products and services you request. For example, if you fill out an online form to open an account or apply for a loan, we use that information to process your request. We also use data to understand how our customers use our online services and how we can make them better. Usage information (like clicks and page visits) helps us improve site navigation, design, and content relevance.
- To personalize your experience: Information about you can help us customize our interactions. This might mean remembering your preferences (so the site greets you by name or shows the last page you visited) or tailoring the content and ads you see to match your interests. The goal is to make your interactions with Sunflower Bank more convenient and relevant to you.
- For communication and customer service: We may use your contact information (like email or phone number) to send you important updates about your accounts or transactions, respond to your inquiries, or notify you about changes to our services. If you reach out with a question or issue, we will use your information to help resolve it and follow up with you.
- For marketing (with your choices respected): We might use your information to let you know about new products or special offers that might interest you. For example, we could send email newsletters or show you promotions on our website. You have control over marketing messages – if you decide you no longer want to receive promotional emails, you can unsubscribe using the link in the email or by contacting us (see Your Privacy Choices below). We do not spam, and we do not sell your information to outside telemarketers.
- To protect against fraud and security risks: Keeping your accounts and information secure is a top priority. We use personal and device information to detect and prevent fraud, unauthorized transactions, hacking, and other security issues. For instance, we might flag a login attempt that comes from an unusual location or device. We also use data to verify your identity when necessary (such as when you reset your password or contact us for support).
- To comply with legal obligations: Like all financial institutions, we are sometimes required by law to collect, retain, or share certain information. This includes using your information to meet regulatory requirements, respond to court orders or lawful requests by authorities, or fulfill our obligations for tax reporting, record-keeping, and audits. If necessary, we will use and disclose information to enforce our terms of use or other agreements, or to protect the rights, property, or safety of our customers and our organization. (For example, sharing data with law enforcement to prevent fraud or investigate a crime.)
We will only use your personal information in ways that are consistent with the reasons it was collected, and we strive to limit our use to what is appropriate and relevant for each purpose. If we ever need to use your information for a new purpose that isn’t covered by this notice, we’ll let you know and obtain consent if required.
Your Privacy Choices
You have choices about how we collect, use, and share your information online. We want to empower you with tools and information to manage your privacy preferences. Here are some of the key choices and controls available to you:
- Cookie Preferences: You can control or delete cookies through your browser settings. Most web browsers allow you to refuse new cookies, disable existing cookies, or be notified when new cookies are set. If you choose to reject or disable cookies, please note that some parts of our site (such as account login or certain features) may become inaccessible or not function properly. For example, if you disable cookies, you may need to re-enter information repeatedly, or certain personalization features might not remember your preferences. Every browser is a bit different, so check the “Help” section of your browser menu for instructions on how to manage cookies. Additionally, if our site uses Flash cookies and you wish to disable those, you’ll need to adjust settings in Adobe Flash Player (if available) as browser settings won’t affect Flash content.
- Opting Out of Analytics: As mentioned, we use Google Analytics to help understand site usage. If you don’t want Google Analytics to collect information from your browser, you can install the Google Analytics Opt-Out add-on for your browser. This tells Google Analytics not to include your visits in their reports. Keep in mind this is specific to Google’s analytics; other analytics tools may have their own opt-out methods.
- Interest-Based Ads Opt-Out: If you prefer not to receive targeted advertising from us or our partners, you have options to opt out. Sunflower Bank participates in industry programs that allow consumers to control tracking for advertising purposes. You can visit the Digital Advertising Alliance’s opt-out page or the Network Advertising Initiative’s opt-out page to opt out of interest-based advertising by companies participating in those programs. These sites will allow you to opt out of many (but not all) of the third-party tracking cookies that advertisers use to show you personalized ads. Please note that even if you opt out of targeted ads, you may still see non-personalized Sunflower Bank ads online (for example, ads that are not tailored to you specifically).
- Marketing Communications: If you receive promotional emails or newsletters from us, you can always unsubscribe. Simply click the “unsubscribe” link in the email or follow the instructions provided. You can also contact us to request removal from our marketing lists. (Please note that even if you opt out of marketing emails, we may still send you transactional or service-related messages, such as account alerts or important notices about your services, since those are not marketing communications).
- Do Not Share/Sell My Info: As we stated above, Sunflower Bank does not sell your personal information to third parties. We also do not share your information with third parties for their own cross-context behavioral advertising purposes. This means there is no need for you to submit a “Do Not Sell or Share My Personal Information” request – we’ve already taken care of that by not engaging in those practices. If this policy changes in the future, we will update this notice and provide a way for you to opt out as required by law.
Note on Public Computers: If you access our online services from a public or shared computer (for example, at a library or café), we encourage you to log out and clear the browser when you’re done. This will help remove any of our cookies or login information stored during your session. It’s a good privacy practice to ensure that the next person using the computer cannot access your information. While our cookies generally won’t contain sensitive personal details, they could allow someone to see that you had logged into a Sunflower Bank service if not cleared. Taking a moment to sign out and clear data helps protect your privacy.
Data Security
We take security seriously and use a combination of technical and organizational measures to protect your personal information from unauthorized access or misuse. Some of the steps we take include:
- Encryption: When you access our online banking or submit sensitive information through our website, we use encryption protocols like SSL (Secure Sockets Layer) to encrypt the data in transit. This means that personal information (such as login credentials or payment details) is scrambled during transmission so that it can’t be easily intercepted by others. You’ll often see a padlock icon in your browser and an “https” address, indicating the connection is secure.
- Secure Systems: The information you provide to us online is stored on secure servers that are protected by firewalls and other technologies. We limit access to these systems to only those personnel and service providers who need it to perform their duties. We also employ malware protection, intrusion detection, and other safeguards to monitor and protect our networks.
- Procedural Safeguards: Beyond technology, Sunflower Bank maintains policies and procedures designed to protect your information. This includes regular employee training on privacy and security, strict authentication processes for customer identity verification, and programs to detect and prevent fraud. If we work with third-party service providers, we require them to uphold strong security standards as well.
- Financial Privacy Regulations: As a financial institution, we operate under federal privacy and security laws that require us to protect customer information. We regularly undergo audits and examinations for compliance. Keeping personal information secure is one of our most important priorities, and we continuously update our security practices to adapt to new threats.
While we are committed to safeguarding your data, it’s important to note that no website or internet transmission is 100% secure. There is always some risk in transmitting information electronically. We therefore cannot guarantee absolute security of information provided via the internet. You share and transact with us online at your own risk, but rest assured we are using all reasonable means to protect you. If we ever experience a data breach that compromises the privacy or security of your personal information, we will follow all applicable laws and regulations to notify you and address the issue. For your part, we encourage you to use strong passwords, keep your account credentials confidential, and contact us immediately if you suspect any unauthorized activity on your account.
Changes to This Notice
We may update or change this Digital Privacy Notice from time to time to reflect new services, changes in law, or improvements in our privacy practices. Whenever we make a significant change, we will post the revised Notice on our website and update the “Last Updated” date at the top of the notice. Changes will become effective when the updated Notice is posted. If the changes are material, we may provide a more prominent notice or seek your consent as required by law. We encourage you to review this Notice periodically to stay informed about how we are protecting your information. Your continued use of our online services after any changes to this Notice means you accept those changes (to the extent permitted by law). We will always indicate the date of the latest revision so you know if anything has been modified.
Contact Us
Your privacy is important to us, and we welcome any questions or feedback about this Notice of our privacy practices. If you have questions, concerns, or comments about how we handle your personal information, please don’t hesitate to contact us:
- Phone: Call us toll-free at 1-888-827-5564 and mention that you have a privacy question. Our customer service team will direct you to the appropriate department.
- Email: Send an email to [email protected] [email protected]. If you are making a specific privacy request (for example, under CCPA), please include “Privacy Request” in the subject line. For general questions, you can simply tell us what you’d like to know or what issue you’ve encountered.
We’re here to help and aim to respond promptly to your inquiries. For additional information, you can always visit our Privacy Center on our website, which has links to this Notice, our U.S. Consumer Privacy Notice, our California Privacy Notices, and other helpful privacy and security resources.
Thank you for reading our Digital Privacy Notice. We hope this helps you understand how Sunflower Bank protects your privacy every day.
Social Media
Sunflower Bank maintains official pages on popular social media platforms like Facebook, X (Twitter), LinkedIn, and YouTube, where we share news and updates and interact with customers. We love engaging with you on these platforms, and we want you to understand how information may be collected and used in those contexts: