Last updated March 13, 2020
ByAllAccounts understands that it’s important to our customers that we keep their personal and financial information safe. This statement outlines our commitment to your privacy and security. It applies to the personal information you or your financial advisor give us when you use our services. Please note, however, that we don’t control how you or your advisor use or share your information after you retrieve it from us. This privacy statement is intended to supplement, rather than supersede, Morningstar’s General Privacy Statement and any preexisting license agreements in place between you and Morningstar.
This privacy statement applies to ByAllAccounts users in the United States. If you would like to learn more about Morningstar’s approach to privacy and security, please visit our General Privacy Statement or Contact Us.
Types of information we collect
We’ll only collect your information if you directly provide it to us, including through information collected when you use or services or sites, or if you consent to a third-party providing it to us.
When you create an account or subscribe to ByAllAccounts products, you may give us basic information about you, including your:
- Email address
- Username and password
- Street address
- Phone number
- Financial advisor’s information, including name and contact information
When you use ByAllAccounts to collect information from your third-party accounts (for example, you may ask us to collect your information from an investment account), you will give us personal information related to that account, including your:
- Username and password for that account
- Account numbers
- Transaction or investment information
We may also collect certain usage information when you use our sites, including Internet Protocol (IP) addresses, log files, browser type, and other related information.
How we use your information
- We collect your information so that you can use it in other financial applications, such as Morningstar Office, Morningstar Advisor Workstation, or other third-party financial planning and reporting applications that you choose.
- We use the information you give us to retrieve your information from third-party accounts.
- We use your information to contact you. We may contact you to support your account or to provide you with notices related to your services. In limited circumstances, we may contact you for marketing purposes.
- We use information from our website, such as IP address information, to improve the services we offer.
- We use and share anonymized customer information for research purposes and to improve our products. When we share your information for these purposes, we always remove any information that can identify you.
- We may share your information where needed to comply with legal obligations.
- Our service providers who work on our behalf may have access to your information. These service providers only perform services related to the purposes described in this statement.
- We won’t sell your information and we won’t share your information with a third-party unless we have your consent or in the limited cases we describe above.
How we protect your information
The security of your information is our priority.
- We maintain a comprehensive information security program that requires that we use physical, technical, and procedural safeguards intended to keep your information safe.
- We use encryption when we store your information (encryption at rest) and when we transfer your information (encryption in transit).
We’ve also designed features that help you control the security of your information:
- We allow you to control what information your advisor can see, edit or manage.
- We keep logs of all changes that we make to your account (such as resetting your password) and we send you an email when we make a change.
- We don’t store your password in open text, so it’s not possible for your advisor or our staff to look up your password to access your ByAllAccounts or third-party accounts.
If you have additional questions about how we keep your information safe, please Contact Us.
How do we store your information?
- We only store our customers’ information in the United States. We don’t transfer our customers’ information to other countries.
- We’ll retain your information for as long as necessary to fulfill the purpose for which it was collected or to comply with legal, regulatory or internal policy requirements. After you deactivate your account, we’ll delete your information within ninety (90) days, unless you instruct us otherwise or unless we have another legal reason to retain the information.
You have the right to access, control, or delete your personal information that we store or to ask us to stop collecting information from your third-party accounts. You can also ask us to provide the general types of information we collect about our customers, who we collect it from, how we use or share it, and our business purpose for collecting, using or sharing this information.
If you have an account with us, you can manage your information from within your ByAllAccounts profile. If you don’t have a profile (for example, your advisor may have given us your personal information in order to provide you services) or if you are otherwise unable to access, control, or delete your information from within your profile, please visit our Privacy Center or Contact Us for help.
We won’t discriminate against our customers who choose to exercise their rights to access, control or delete their personal information. Some of our products and services, however, may require your personal information. If you choose not to provide your personal information, you may not be able to use those products or services.
How does a user deactivate their account?
You can deactivate your ByAllAccounts account at any time through the ByAllAccounts application. When you deactivate your ByAllAccounts account, we’ll delete all of your account information within ninety (90) days, unless you instruct us differently or unless we have another legal reason to retain the information. You may also submit a request to delete your account or information through the Privacy Center and you may Contact Us for help.
The California Consumer Privacy Act requires that we list the categories of our customers’ personal information that we’ve sold or disclosed for business purposes in the last twelve (12) months.
Nevada law gives Nevada consumers the right to request that a company not sell their personal information. If you are a Nevada consumer and wish to exercise this right, please visit our Privacy Center, Contact Us or call us toll-free at +1 (888) 293-8609.
We don’t separately identify, or collect, any information that is specific to children.
By using the ByAllAccounts Service, you consent to the collection and use of your personal information, as described in this Privacy Statement and the Morningstar® ByAllAccounts® User Agreement. The ByAllAccounts Service systems are not currently configured to handle “Do Not Track” requests.
How we revise this statement
Our business frequently changes, and we may need to update this statement to reflect those changes. When we make changes to this privacy statement, we’ll revise the “last updated” date at the top of this page. If we make material changes to this statement, we’ll notify you directly as required by law.
If you have a concern, complaint, or question about how we handle your personal information, please Contact Us, call us toll-free at +1 (888) 293-8609, or write us at the following mailing address:
22 W. Washington St
Chicago, IL 60602
Attn: Chief Privacy Officer
To find the Morningstar contact in your country, please visit our list of office contacts.