Last Updated: October 2025
The Federal Home Loan Bank of San Francisco (the “Bank,” “we,” or “us”) respects and values your privacy, and we are dedicated to sharing our methods and approach to how we collect, use, disclose, and protect your Personal Information in this notice (“Privacy Notice”). This Privacy Notice describes how the Bank handles your Personal Information:
From visitors to our website https://fhlbsf.com as it may be modified, relocated and/or redirected from time to time or web-based applications (“Websites”)
Through software applications made available by us for use on or through computers and mobile devices (“Apps”)
Contacts from our members and/or prospective members
Contacts for suppliers of goods and services to the Bank
From any other individual about whom the Bank obtains personal information in the provision of services to our member (“Member Services”)
The items outlined above are collectively called “Services.” If you are a California Resident, you can review the Additional Information For California Residents below.
This Privacy Notice does not address our privacy practices relating to the Bank’s job applicants, employees and other employment-related individuals, nor data that is not subject to applicable data protection laws (such as deidentified or publicly available information). This Privacy Notice is not a contract and does not create any legal rights or obligations not otherwise provided by law.
Alternative formats of this Privacy Notice are available to individuals with a disability. Please contact CCPArequets@fhlbsf.com for assistance.
The Bank collects the Personal Information identified in Section “Information We Collect About You” below for the purposes identified in Section “Uses of Personal Information” and retains it for the period described in Section “Retention Period”. We do sell and share your personal information in the manner described in Section “Disclosure of Personal Information.” You can opt out by following the link on our webpage entitled “Your Privacy Choices.” We do not collect or process sensitive personal information for the purpose of inferring characteristics about you.
To the extent you provide the Bank with Personal Information about other California residents, you are responsible for providing this notice to them.
For the purposes of this Privacy Notice, Personal Information is information that relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. The categories of Personal Information we collect depends on how your interact with us. For example, you may provide us with your personal information directly when you visit our website, interact with our Apps, or contact us during the course of accessing the Member Services. The Bank collects the following types of Personal Information:
Contact and Basic Information: for example, name, title, phone numbers, mailing address, email address, organization, and job title.
Registration Information: for example, information necessary to process or respond to newsletter requests, event/seminar registration, dietary preferences (excluding special categories), subscriptions, and requests to download information.
Professional Data: for example, information about individual participation in conferences, credentials, and associations.
Government Data: for example, government identifiers, date of birth, and due diligence data.
Member Service Information: for example, member employee contact information, third-party data related to member business-related requests.
We, and our third-party partners, automatically collect information you provide to us and information about how you access and use our Services when you engage with us. We typically collect this information through the use of a variety of our own and our third-party partners’ automatic data collection technologies, including (i) cookies or small data files that are stored on an individual’s computer and (ii) other, related technologies, such as web beacons, pixels, embedded scripts, mobile SDKs, location-identifying technologies and logging technologies. Information we collect automatically about you may be combined with other personal information we collect directly from you or receive from other sources. For more information, please view our Cookie Policy.
We, and our third-party partners, use automatic data collection technologies to automatically collect the following data when you use our services or otherwise engage with us:
Information About Your Device and Network, including the device type, manufacturer, and model, operating system, IP address, browser type, Internet service provider, and unique identifiers associated with you, your device, or your network (including, for example, a persistent device identifier or advertising ID). We employ third-party technologies designed to allow us to recognize when two or more devices are likely being used by the same individual and may leverage these technologies (where permitted) to link information collected from different devices.
Information About the Way Individuals Use Our Services and Interact with Us, including the site from which you came, the site to which you are going when you leave our Services, how frequently you access our Services, whether you open emails or click links in emails, whether you access our Services from multiple devices, and other browsing behavior and actions you take on our Services.
The Bank may collect Personal Information from a variety of sources, including:
You/through our provision of Services, for example, when you sign-up for a newsletter, register for a conference, enter into a contractual relationship for Services, interact with us at an event, visit our Websites or networks, use our online applications, send us communications, or call or visit our office.
From other sources that may include:
Subscription-based sources
Court documents and filings
Event sponsors
Our members
Counterparties in transactions or disputes
Social media
Our service providers, for example, IT and system administration services
Automated technologies, for example, browsing activity collected by automated technologies on the Website
Third parties, for example, lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services
Government or administrative agencies, for example, law enforcement, public health officials, other government authorities
The Bank needs to collect Personal Information in order to provide the requested Services to you or to provide Services to our members. If you do not provide the information requested, we may not be able to provide the Services. Where the Bank receives Personal Information from its members about employees or other individuals, the member is responsible for ensuring that any such Personal Information is transferred to us in compliance with applicable data protection laws and regulations.
The purposes for which the Bank uses Personal Information are as follows:
Communication and/or the provision of financial services to our members. We engage in this activity to fulfil our ethical, legal and contractual obligations with our members.
Management of our business operations and administration of our member relationships. We engage in this activity to fulfil our ethical, legal and contractual obligations with members and suppliers.
Enhancing the functionality of our Websites. We engage in this activity because we have a legitimate interest in monitoring how our Website and Apps are used to help us provide better services to our Website and App users.
Fraud and security monitoring purposes. We engage in this activity because we have a legitimate interest to detect and prevent fraud, crimes and other misuses of our Websites and networks.
Data analysis to improve the efficiency of our Services and identify trends. We engage in this activity to manage our relationships with members, to comply with legal obligations, and/or because we have other legitimate interests.
Auditing internal process for proper functioning. We engage in this activity to manage our relationships with members, to comply with legal obligations, and/or because we have other legitimate interests.
To provide relevant marketing materials. We engage in this activity because we have a legitimate interest or because we have obtained consent.
Compliance with legal and regulatory obligations. We engage in this activity to manage our relationships with members, to comply with legal obligations, and/or because we have other legitimate interests.
To protect the rights, property, or safety of the Bank, you, or others.
To report suspected criminal conduct to law enforcement and cooperate in investigations.
To exercise the Bank’s rights under applicable law and to support any claim, defense, or declaration in a case or before a jurisdictional and/or administrative authority, arbitration, or mediation panel.
Incidental purposes: any incidental purposes related to, or in connection with, the above.
The Bank may aggregate and/or anonymize (de-identify) Personal Information so it is no longer considered Personal Information. We do this to generate other data for our use, which we may use and disclose for any purpose. We maintain de-identified information in a de-identified form and do not attempt to re-identify, except that we may attempt to re-identify the information just to determine whether our de-identification processes function correctly, or as required or permitted by law.
We may disclose Personal Information to:
Contractors, vendors, and services providers
Third parties, for example, auditors, lawyers, consultants, and accountants engaged by the Bank
Government or administrative agencies
Marketing providers, ad networks, and advertising partners
We may also disclose Personal Information as necessary to:
Comply with applicable laws and regulations
To assist us in meeting our business needs
To cooperate with public and government authorities
To cooperate with law enforcement
To enforce our terms and conditions
To protect our rights, privacy, safety or property, and/or that of our affiliates, or others
To deliver advertising and personalized content on our Services, on other websites and across other devices. These parties may collect information automatically from your browser or device when you visit our Websites and other Services through the use of cookies and related technologies. This information is used to provide and inform targeted advertising, as well as to provide advertising-related services such as reporting, attribution, analytics, and market research.
The following privacy choices are made available to all individuals with whom we interact. You may also have additional choices regarding your Personal Information depending on your location or residency. Please refer to our region-specific disclosures below for information about additional privacy choices that may be available to you.
Email Communication Preferences: You can stop receiving promotional email communications from us by clicking on the “unsubscribe” link provided in any of our email communications. Please note you cannot opt-out of service-related email communications (such as, account verification, transaction confirmation, or service update emails).
Direct Mailing Preferences: You can stop receiving promotional direct mail communications from us by contacting us at ccparequests@fhlbsf.com. Please note this opt-out does not affect any mailings that are controlled by third parties that may feature or mention our services.
Where we have your consent for the processing of your Personal Information (e.g., when you opt in to receive certain types of marketing communications from us), you may withdraw your consent by following the instructions provided when your consent was requested or by contacting us as set forth in the Contact Us section below.
Certain of our services may provide you the ability to adjust your preferences regarding our use of automatic data collection technologies. For example, there is a “Cookie Preferences” manager linked in the footer of our websites that allows you to adjust your preferences regarding certain automatic data collection technologies on the specific website you are visiting for the specific device and browser you are using at that time (which means you will need to change your preferences on each device and browser you use to interact with the specific website you are visiting).
Where a Bank-specific preference manager or privacy setting is not available, you may be able to utilize third-party tools and features to further restrict our use of automatic data collection technologies. For example, (i) most browsers allow you to change browser settings to limit automatic data collection technologies on websites, (ii) most email providers allow you to prevent the automatic downloading of images in emails that may contain automatic data collection technologies, and (iii) many devices allow you to change your device settings to limit automatic data collection technologies for device applications. Please note that blocking automatic data collection technologies through third-party tools and features may negatively impact your experience using our services, as some features and offerings may not work properly or at all. Depending on the third-party tool or feature you use, you may not be able to block all automatic data collection technologies, or you may need to update your preferences on multiple devices or browsers. We do not have any control over these third-party tools and features and are not responsible if they do not function as intended.
We engage third parties to help us facilitate targeted advertising designed to show you personalized ads based on predictions of your preferences and interests developed using Personal Information we maintain and Personal Information our third-party partners obtain from your activity over time and across nonaffiliated websites and other services. The data we and our third-party partners use for purposes of facilitating targeted advertising, as well as to provide advertising-related services such as reporting, attribution, analytics, and market research, are primarily collected through the use of a variety of automatic data collection technologies, including cookies, web beacons, pixels, embedded scripts, mobile SDKs, location-identifying technologies and logging technologies. We may share a common account identifier (such as a hashed email address or user ID) with our third-party advertising partners to help link the Personal Information we and our third-party partners collect to the same person, or otherwise target advertising to an individual on a third-party website or platform.
In addition to taking the steps set forth in the Automatic Data Collection Preferences section above, you may be able to further exercise control over the advertisements that you see by leveraging one or more targeted advertising opt-out programs. For example:
Device-Specific Opt-Out Programs: Certain devices provide individuals the option to turn off targeted advertising for the entire device (such as Apple devices through their App Tracking Transparency framework or Android devices through their opt out of ads personalization feature). Please refer to your device manufacturer’s user guides for additional information about implementing any available device-specific targeted advertising opt-outs.
Digital Advertising Alliance: The Digital Advertising Alliance allows individuals to opt out of receiving online interest-based targeted advertisements from companies that participate in their program. Please follow the instructions at https://optout.aboutads.info/ for browser-based advertising and https://www.youradchoices.com/appchoices for app-based advertising to opt out of targeted advertising carried out by our third-party partners and other third parties that participate in the Digital Advertising Alliance’s self-regulatory program.
Network Advertising Initiative: The Network Advertising Initiative similarly allows individuals to opt out of receiving online interest-based targeted advertisements from companies that participate in their program. Please follow the instructions at https://thenai.org/opt-out/ to opt out of browser-based targeted advertising carried out by our third-party partners and other third parties that participate in the Network Advertising Initiative’s self-regulatory program.
Platform-Specific Opt-Out Programs: Certain third-party platforms provide individuals the option to turn off targeted advertising for the entire platform (such as certain social media platforms). Please refer to your platform provider’s user guides for additional information about implementing any available platform-specific targeted advertising opt-outs.
Please note that when you opt out of receiving interest-based advertisements through one of these programs, this does not mean you will no longer see advertisements from us or on our services. Instead, it means that the online ads you do see from relevant program participants should not be based on your interests. We are not responsible for the effectiveness of, or compliance with, any third parties’ opt-out options or programs or the accuracy of their statements regarding their programs. In addition, program participants may still use automatic data collection technologies to collect information about your use of our services, including for analytics and fraud prevention as well as any other purpose permitted under the applicable advertising industry program.
If you have any questions about reviewing, modifying, or deleting your Personal Information, you can contact us directly at ccparequests@fhlbsf.com. We may not be able to modify or delete your personal Information in all circumstances.
Certain of our third-party providers and partners offer additional ways that you may exercise control over your Personal Information, or automatically impose limitations on the way we can use Personal Information in connection with the services they provide:
Device-Specific / Platform-Specific Preferences: The device and/or platform you use to interact with us (such as you mobile device), may provide you additional choices with regard to the data you choose to share with us. For example, many mobile devices allow you to change your device permissions to prevent our products and services from accessing certain types of information from your device (such as your contact lists). Please refer to your device provider’s user guides for additional information about implementing any available targeted advertising opt-outs.
Google Analytics: Google Analytics allows us to better understand how our customers interact with our services. For information on how Google Analytics collects and processes data, as well as how you can control information sent to Google, review Google's website here: www.google.com/policies/privacy/partners/. You can learn about Google Analytics’ currently available opt-outs, including the Google Analytics Browser Add-On here: https://tools.google.com/dlpage/gaoptout/.
We have implemented reasonable measures to secure Personal Information from accidental loss or destruction and from unauthorized access, use, alteration and disclosure. Unfortunately, no transmission or storage system can be guaranteed 100% secure.
Our services are not intended for individuals under the age of 18. We do not collect information from anyone under 13 years of age. If you are under the age of 13, you are not authorized to use our Services or the Websites. If a child under the age of 13 has provided Personal Information to us, we encourage the child’s parent or guardian to contact us to request that we remove the Personal Information from our systems. If we learn that any Personal Information we collect has been provided by a child under the age of 13, we will promptly delete that Personal Information.
We retain your Personal Information for the duration of our relationship with you, if any. We will retain your Personal Information for as long as is reasonably necessary for a specified business purpose or as required by legal, administrative, or procedural obligations, for example, a litigation hold.
The Website and Apps may contain links to unaffiliated third parties. This Privacy Notice does not apply to such third-party sites. When you click a link to visit a third-party website, you will be subject to their website’s privacy practices. We encourage you to review the privacy and security practices of any linked third-party website before providing any Personal Information on that website.
These disclosures supplement the information contained in our Privacy Notice by providing additional information about the privacy rights available to individual residents of California and our Personal Information processing practices. For a detailed description of how we collect, use, disclose, and otherwise process Personal Information, please read our Privacy Notice.
If you reside in California, the following additional disclosures apply to you.
We disclose all of the categories of Personal Information we collect to the categories of recipients set forth in the Disclosure of Personal Information section of our Privacy Notice. Pursuant to the CCPA, we are providing the following additional details regarding the categories of Personal Information about California residents that we collected and disclosed in the preceding 12 months.
Our disclosure of Personal Information to the following categories of third parties qualifies as the sale of Personal Information or the sharing or processing of Personal Information for the purpose of displaying advertisements that are selected based on Personal Information obtained or inferred over time from an individual’s activities across businesses or distinctly-branded websites, applications, or other services (otherwise known as “targeted advertising” or “cross-context behavioral advertising”) under certain privacy laws:
Marketing providers, ad networks, and advertising partners: To deliver advertising and personalized content on our Services, on other websites and across other devices. These parties may collect information automatically from your browser or device when you visit our Websites and other Services through the use of cookies and related technologies. This information is used to provide and inform targeted advertising, as well as to provide advertising-related services such as reporting, attribution, analytics, and market research.
Depending on your state of residency and subject to certain legal limitations and exceptions, you may be able to limit or opt-out of the sale of Personal Information or the processing of Personal Information for purposes of targeted advertising.
Please note we do not sell the Personal Information of individuals we know to be less than 16 years of age or share such information for targeted advertising purposes.
We do not conduct automated processing of Personal Information for the purposes of evaluating, analyzing, or predicting an individual’s personal aspects in furtherance of decisions that produce legal or similarly significant effects. As a result, we do not provide a right to exercise control over such forms of automated decision-making and profiling.
Depending on your state of residency and subject to certain legal limitations and exceptions, you may be able to exercise some or all of the following rights:
Right to Know: You may have a right to confirm whether we are processing Personal Information about you and to obtain certain personalized details about the Personal Information we have collected about you, including:
The categories of Personal Information collected;
The categories of sources of the Personal Information;
The purposes for which the Personal Information was collected;
The categories of Personal Information disclosed to third parties (if any), and the categories of recipients to whom this Personal Information were disclosed;
The categories of Personal Information shared for targeted advertising purposes (if any), and the categories of recipients to whom the Personal Information were disclosed for these purposes; and
The categories of Personal Information sold (if any) and the categories of third parties to whom the Personal Information were sold.
Right to Access & Portability: The right to obtain access to the Personal Information we have collected about you and, where required by law, the right to obtain a copy of the Personal Information in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance.
Right to Delete: In certain circumstances, you have the right to submit a verified request we delete Personal Information that you have provided to the Bank. Please note that the right to request deletion is subject to certain exceptions under the CCPA.
Right to Correct Inaccurate Information: You have the right to submit a verifiable request for the correction of inaccurate personal information maintained by the Bank, taking into account the nature of the personal information and the purposes of processing the personal information.
Right to Control Over Sensitive Personal Information: The right to exercise control over our collection and processing of certain sensitive Personal Information.
Right to Opt-Out of Targeted Advertising: The right to direct us not to use or share Personal Information for certain targeted advertising purposes.
Right to Opt-Out of Sales: The right to direct us not to sell Personal Information to third parties including the right to opt-out of the disclosure of Personal Information to third parties for the third parties’ direct marketing purposes under California’s “Shine the Light” Law.
Right to Non-Discrimination: The Bank will not discriminate against California Consumers for exercising their rights under the CCPA.
The Bank does not offer financial incentives or price or service differences in exchange for the retention of a California Resident’s Personal Information.
If the CCPA requires that the privacy rights request be verified (this applies to the Right to Know, Access & Portability, Correction, and Deletion), the Bank will respond to the request of a California resident if it can verify the identity of the individual submitting the request. California residents can exercise these rights by email at ccparequests@fhlbsf.com. We match Personal Information that you provide us against Personal Information we maintain in our files. The more risk entailed by the request (e.g., a request for specific pieces of personal information), the more data points may be required to match information maintained by the Bank.
Please note, we may not be able to comply with your request if we are unable to confirm your identity or connect the information you submit in your request with Personal Information in our possession. Therefore, you should include information you have previously submitted to the Bank for the verification process. If we are unable to verify your identity, we may request additional information.
If you have questions on how to submit a verified request, please contact ccparequests@fhlbsf.com.
In certain circumstances, you are permitted to designate an Authorized Agent to submit a request on your behalf. For the Bank to respond to a request from an Authorized Agent, the Bank may, where permitted by the CCPA:
Request a copy of the written permission granting the Authorized Agent to make such a request on your behalf;
Request confirmation from you that your authorized the agent to make the request on your behalf; or
Request that you directly verify your own identity.
In the alternative, you can provide a power of attorney compliant with the California Probate Code.
To exercise your right to opt-out as it relates to the use of cookies and related technologies that involve the sale of Personal Information or the use of Personal Information for targeted advertising purposes, please [click the “Cookie Settings” link in the footer of the website and adjust your preferences accordingly. If you are visiting our site with the Global Privacy Control enabled, any cookies that constitute sales or are used for targeted advertising should already be turned off automatically in our cookie preference manager. Please note this opt-out tool is website, device, and browser specific, so you will need to change your preferences on each device and browser you use to interact with the specific website you are visiting. In addition, you can also opt-out of cookie-based sales by businesses that participate in the Digital Advertising Alliance’s CCPA Opt-Out Tool by visiting https://www.privacyrights.info/. Lastly, you may follow the other steps set forth in the Automatic Data Collection Preferences and Targeted Advertising Preferences sections of the Your Privacy Choices section of our Privacy Notice to further exercise control over automatic data collection technologies.
If you have questions or concerns regarding our Privacy Notice or practices, you may contact us via the following email address: websupport@fhlbsf.com.
The Bank may update this Privacy Notice from time to time. When we do, we will post the current version on this site, and we will revise the version date located at the top of this page. Any changes become effective when we post the revised Privacy Notice. Your continued use of our Services following these changes means that you accept the revised Privacy Notice.