Skip to main content
The short version: we hold enough to service your account, we do not hold your full card or bank numbers, and the parts that matter most are protected by something only you know.

What we store, and what we never store

This is why someone who got into your account still could not take your card details: they are not there.

What protects your account

Three separate things, and an intruder would need all of them:
1

Your Account Number

Assigned by us. Not guessable, and not derived from your name or date of birth.
2

Your Access Code

Also assigned by us, numeric and long. It cannot be changed online — see Access Code security.
3

Something only you know

Your date of birth, or the last four digits of your Social Security number. This is never printed on your statement.
Your statement carries the first two. Your Account Number and Access Code are printed on it, so treat a paper statement the way you would treat a bank letter — keep it somewhere sensible and shred it rather than putting it in the bin.It is not enough on its own to open your account. It is two of the three.
You can also set a secret passphrase we ask for when you contact us — see Account access and security.

Who we share your information with

Some sharing is how the account works, and you cannot limit it. Some we do not do at all. Our affiliates include sales finance and debt collection companies. Unrelated companies include the retail seller you bought from. Vermont, California and Nevada residents have additional protections, and we do not sell your information. The full notice is in our Privacy Policy.
Your lender has its own privacy notice, and it may differ from ours. The privacy page carries several — UAS first, then the bank or credit union that funded your loan. Read the one that names your lender as well as ours; they do not say the same things about sharing.

How we secure our systems

We use security measures that comply with federal law, including computer safeguards, secured files and secured buildings, and we maintain PCI DSS compliance for card data. Card and bank account data is encrypted both in transit and at rest. Your security code is never retained once the authorization it was used for has expired. Access to payment data is limited to staff with a documented reason to have it. Our security is tested rather than asserted: a PCI DSS assessment every year, carried out at the level that applies to us by a qualified assessor, and external vulnerability scans every quarter by an approved scanning vendor. Companies that handle card or bank data on our behalf have to meet the PCI standard that applies to them, and prove it to us annually. Our information security program is also examined independently. We hold SOC 1 Type 2 and SOC 2 Type 2 reports covering security, availability and confidentiality, and our program has been reviewed against ISO/IEC 27001.
Those reports are prepared for institutional partners and auditors and are not distributed to the public. If you are evaluating UAS on behalf of a lender or school, request the vendor-management package through your UAS contact.

How we contact you, and how we don’t

We may call, text, email or write to you about your account, including using automated dialing and prerecorded messages — but not to market to you. Calls may be monitored or recorded. We will never ask you for your full card number or your security code by email or text. If you receive a message that does, do not reply to it — see How and when we contact you.

If you think something is wrong

Call us. If you believe someone has used your account, or that the account is not yours at all, say so when you call — that is handled differently from a routine question, and there is a separate identity-theft route in Opening a support request.

Contact us

Have your Account Number to hand if you have it.