PRIVACY POLICY
This Privacy Policy (“Policy”) explains how StorePay, Inc., a Delaware corporation (“ScanPay”, “we”, or “us”), applies privacy practices to our online service, website, and software provided or in connection with the service (collectively, the “Services”). This Policy describes how we collect, use, share, and secure the personal data of users of the Services (the “User(s)”, “you”, or “yours”, as applicable). It also describes your choices regarding use, access, and correction of your personal data.
The capitalized terms used in this Policy but not defined herein shall have the same meaning assigned to them in ScanPay’s Terms of Platform at goscanpay.com/terms-of-platform (the “Terms”). By using our Services, you express your unconditional agreement with this Policy and the conditions of processing the personal data contained herein. If you do not accept this Policy, do not use our Services or provide any Personal Information to us.
1. Information We Collect
ScanPay gathers the following categories of information:
- personally identifiable information that is supplied voluntarily upon registration for the Services;
- aggregate tracking and site usage information that is gathered automatically when you use the Services; or
- information obtained from third parties.
A. Information You Provide to Us
Personal Information. When you register for an account to access or utilize our Services (an “Account”) or request to receive information about ScanPay or our Services, we may ask for and collect Personal Information that can be used to identify you, which may include an identifier such as a name, email address, postal address, phone number, social security number, tax identification number or other government-issued identification number, or by factors specific to them, such as their physical, genetic, economic or social identity (“Personal Information”).
Commercial Information. To enable our Services, we may also ask and collect information about the products and services you sell (e.g., inventory, pricing and other data) and information about your payment transactions (e.g., when and where the transactions occur, a description of the transactions, the payment or transfer amounts, billing and shipping information, and payment methods used to complete the transactions).
Payment Information. If you use the Services to receive payments, we ask you to provide us with certain payment information such as bank account information, debit/credit card or other financial account information, and billing address. We use third-party payment processors and bank account verification Service Providers to assist in securely processing your personally identifiable payment information. The credit card information provided by your Customers for payment processing is encrypted and transmitted directly to our third-party payment processors. We do not store your Customers’ credit card information and are not responsible for the third-party payment processor’s collection or use of that information.
B. Information Collected Automatically
We also get data from the devices you use when you interact with our systems, such as your location or information about the device you’re using. We need this data to help protect your account from fraud, check if payments are being made or received legally and by you, and make our products and services better for you and others.
The information we collect includes your IP address, which is a number assigned to your computer or internet-enabled device whenever you access the internet. It allows computers and servers to recognize and communicate with one another. IP addresses from which visitors appear to originate may be recorded for IT security and system diagnostic purposes. This information may also be used in aggregate form to maintain and improve the Services and to generate and analyze statistics about your use of the Services.
We may use the following technologies to automatically collect information from you:
Cookies. Cookies are text files placed on your computer to collect standard internet log information and visitor behavior information. This information is then used to track visitor use of the website and to create statistical reports on website activity. A cookie may also convey anonymous information about how you browse the Services to us. A cookie does not collect Personal Information about you. You can set your web browser or device to refuse all cookies or to indicate when a cookie is being sent. However, some features of the Services may not function properly if the ability to accept cookies is disabled.
Beacons. A web beacon is a small image file on a web page that can be used to collect certain information from your computer, such as an IP address, the time the content was viewed, a browser type, and the existence of cookies previously set by the same server. We only use web beacons in accordance with applicable laws. Web beacons or similar technologies may be used for a number of purposes, including without limitation to count visitors to our Services, to monitor how our users navigate the Services, or to count how many particular articles or links were actually viewed.
C. Third-Party Services
We may provide an option to access or register for the Services through the use of your username and passwords for certain services provided by third parties (each, a “Third-Party Service”), such as through the use of your Google account. By authorizing us to connect with a Third-Party Service, you authorize ScanPay to access and store the information that the Third-Party Service makes available to us, and to use and disclose it in accordance with this Policy. It is your responsibility to check your privacy settings for such Third-Party Services (please review the terms of use and privacy policy of such Third-Party Services) to control what information is available to us.
2. How We Use Information
Permitted Purposes
We may use the information we collect about you (including Personal Information, to the extent applicable) for a variety of purposes, including to: (a) provide, operate, maintain, improve, and promote our Services; (b) enable you to access and use the Services; (c) process and complete transactions; (d) provide customer service and support and send you related notices; (e) send promotional communications; (f) monitor and analyze trends, usage, and activities in connection with the Services and for marketing or advertising purposes; (g) monitor and assess compliance with our policies and standards; (h) comply with our obligations under applicable law, including Money Transmitter License requirements, anti-money laundering regulations, and know-your-customer and know-your-business requirements; and (i) facilitate payout disbursements to your registered bank account.
We also use your information with your consent: (j) to send you newsletters and other promotional communications about our and third-party products, offers, rewards and services; and (k) for other purposes for which we obtain your consent.
3. How We Share the Information
Third-Party Service Providers
We share information, including Personal Information, with our third-party service providers that we use to provide hosting for and maintenance of the Services. These third-party service providers may have access to or process your Personal Information for the purpose of providing these services for us. We do not permit our third-party service providers to use the Personal Information that we share with them for their marketing purposes or for any other purpose than in connection with the services they provide to us.
Banking Partners
In connection with our payment processing and payout disbursement services, we share certain Personal Information and financial information with one or more Banking Partners — federally or state-chartered banks or licensed financial institutions that hold funds on behalf of Merchants and facilitate payment settlement. The categories of information we may share with Banking Partners include:
- identity and verification information collected during onboarding, including name, date of birth, address, government-issued identification numbers, and business registration information;
- bank account information used to facilitate payout disbursements to your Merchant Account; and
- transaction data necessary for payment settlement, fraud monitoring, and regulatory compliance.
Information shared with Banking Partners is used solely for the purposes of account opening, payment settlement, OFAC screening, fraud prevention, and compliance with applicable financial services regulations. Banking Partners are not permitted to use this information for their own marketing purposes. The identity of ScanPay’s Banking Partner(s) is disclosed at goscanpay.com/licenses.
Analytic Providers and/or Advertising Partners
We work with (or may in the future work with) network advertisers, ad agencies, analytics service providers and other vendors to provide us with information regarding traffic on the Services, including pages viewed and the actions taken when visiting the Services; to serve our advertisements on other websites, within mobile apps and elsewhere online; and to provide us with information regarding the use of the Services and the effectiveness of our advertisements. Our service providers may collect information about your visits to and activity on the Services as well as other websites or services, they may set and access their own tracking technologies on your device, and may use that information to show you targeted advertisements. If you wish to opt out of interest-based advertising, please email us at support@goscanpay.com. If you choose to opt out, please note you may still receive generic ads.
Compliance with Law
We may share your personal data with courts, law enforcement authorities, regulators or attorneys or other parties where it is reasonably necessary for the establishment, exercise or defense of a legal or equitable claim, or for the purposes of a confidential alternative dispute resolution process. We may also share such information if we believe it is necessary in order to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our terms and conditions, or as otherwise required by law.
Organizational Changes
We may share your personal data with any third party to whom we assign or novate any of our rights or obligations, or that acquires all or substantially all of our business, stock or assets, or with whom we merge.
Aggregate Data
We may also use aggregated personal data and statistics for the purpose of monitoring website usage in order to help us develop and improve our Services.
With Your Consent
We will otherwise only disclose your personal data when you direct us or give us permission to do so, when we are required by applicable law or regulations or judicial or official request to do so, or as required to investigate actual or suspected fraudulent or criminal activities.
Where we rely on your consent to process Personal Information, you have the right to withdraw or decline your consent at any time. Please note that this does not affect the lawfulness of the processing based on consent before its withdrawal.
If we ask you to provide Personal Information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Information is mandatory or not, as well as the possible consequences if you do not provide your Personal Information.
If you have any questions about or need further information concerning the legal basis on which we collect and use your Personal Information, please contact us at support@goscanpay.com.
4. How Long We Retain Your Personal Information
We will retain your Personal Information for as long as is needed to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements). When we have no ongoing legitimate business need to process your Personal Information, we will either delete or anonymize it, or, if this is not possible (for example, because your Personal Information has been stored in backup archives), then we will securely store your Personal Information and isolate it from any further processing until deletion is possible.
Notwithstanding the foregoing, the following categories of information are subject to specific retention requirements:
- Financial transaction records, payout records, and account activity data are retained for a minimum of five (5) years from the date of the transaction, or such longer period as may be required by applicable state Money Transmitter License regulations, federal anti-money laundering laws, or other financial services regulations.
- KYC and KYB records — including identity verification documents, business registration information, beneficial ownership records, and related onboarding materials — are retained for a minimum of five (5) years following the closure of your account, or such longer period as required by applicable law.
- Bank account information and payout-related data are retained for the period necessary to satisfy all outstanding obligations arising from transactions processed during the account relationship, and in any event for a minimum of five (5) years following account closure.
For Personal Information that we process on behalf of our registered users, we will retain such Personal Information in accordance with the terms of our agreement with them, subject to applicable law.
5. Your Privacy Rights
Upon request we will provide you with information about whether we hold, or process on behalf of a third party, any of your Personal Information. To request this information please contact us at support@goscanpay.com. Subscribers may update or change their account information by editing their profile within the Services.
To make a request to have Personal Information maintained by us returned to you or removed, please email support@goscanpay.com. Requests to access, change, or remove your information will be handled within thirty (30) days; provided that, notwithstanding such request, this information may be retained for as long as you maintain an account for the Services, or as needed to provide you with the Services, comply with our legal obligations, resolve disputes, and enforce our agreements.
Objections to Processing of Personal Information
It is your right to lodge an objection to the processing of your personal data if you feel the grounds relating to your particular situation apply. The only reasons we will be able to deny your request is if we can show compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defense of legal claims. To invoke this right, please contact us at support@goscanpay.com. We will consider your request in accordance with applicable laws. To protect your privacy and security, we may take steps to verify your identity before complying with the request.
California Privacy Rights
We will not share any Personal Information with third parties for their direct marketing purposes to the extent prohibited by California law. If our practices change, we will do so in accordance with applicable laws and will notify you in advance.
Policy Regarding Children
The Services are not directed to children under the age of thirteen and we do not knowingly collect personally identifiable information from children under the age of thirteen as part of the Services. If we become aware that we have inadvertently received personally identifiable information from a user under the age of thirteen as part of the Services, we will delete such information from our records. If we change our practices in the future, we will obtain prior, verifiable parental consent before collecting any personally identifiable information from children under the age of thirteen as part of the Services.
Online Advertising
We use online advertising platforms such as Facebook, Instagram, LinkedIn, YouTube, Vimeo or other third-party platforms (the “Ad Platforms”) to promote our Services through interest-based ads. We do not share your Personal Information with the Ad Platforms for the promotion of our Services through interest-based ads.
If you do not want to receive interest-based ads on the Ad Platforms, you can adjust your ad preferences in accordance with the instructions provided by such Ad Platform.
6. Changes to Our Privacy Policy
If we change the Policy, we will post the revised Policy here with an updated revision date. Please check the Site frequently to see if the Policy has changed. If we make significant changes to our Policy, we also may, but are not obliged to, notify all members whose Personal Information we have retained by means such as sending an email or posting a notice on our Site. Your continued use of the Services constitutes your acceptance of all such changes and amendments. Your sole remedy is to cease using the Services.
7. Contacting Us
If you have any questions regarding this Policy or information we hold about you, you may contact us at support@goscanpay.com. In order for us to take the appropriate action, please describe in reasonable detail the nature of your request or inquiry.
8. Privacy Notice for California Residents
This Privacy Notice for California Residents (this “CCPA Notice”) supplements the information contained in the Policy and, except as provided herein, applies solely to California residents. We adopt this notice to comply with the California Consumer Privacy Act of 2018 (CCPA) and any terms defined in the CCPA have the same meaning when used in this CCPA Notice.
This CCPA Notice does not apply to employment-related personal information collected from California-based employees, job applicants, contractors, or similar individuals.
A. Information We Collect
The Information We Collect section above describes the personal information we may collect from you, including the categories of sources of that information. We collect the information for the purposes described in the How We Use Information section. We share this information as described in the How We Share the Information section.
B. Your Rights
The CCPA provides California residents with specific rights regarding their personal information. This section describes your rights and explains how to exercise them.
Access to Specific Information and Data Portability Rights. You have the right to request that we disclose certain information to you about our collection and use of your personal information over the prior twelve (12) months. Upon receipt of a verifiable consumer request, we will disclose to you:
- the categories of personal information we collected about you;
- the categories of sources from which we collected personal information;
- our business or commercial purpose for collecting or selling personal information;
- the categories of third parties with whom we share personal information;
- the specific pieces of personal information we collected about you (known as a “data portability request”); and
- if applicable, the categories of personal information we sold or disclosed for a business purpose, and the categories of third parties to whom the personal information was sold or disclosed.
Deletion Request Rights. You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies. We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:
- complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you;
- detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities;
- debug products to identify and repair errors that impair existing intended functionality;
- exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law;
- comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et seq.);
- engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent;
- enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us; or
- comply with a legal obligation, including applicable financial services record retention requirements.
C. Exercising Your Rights
To exercise the access, data portability, and deletion rights described above, please submit a verifiable consumer request to us at: support@goscanpay.com. Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child. You may only make a verifiable consumer request for access or data portability twice within a 12-month period.
The verifiable consumer request must:
- provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative, which may include: first name, last name, email address used to register with ScanPay, and phone number; and
- describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. However, we do consider requests made through your password-protected account sufficiently verified when the request relates to personal information associated with that specific account. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
We will not discriminate against you for exercising any of your CCPA rights.
