Privacy Policy

Last Updated: August 2025

1. Introduction

SettleWise, Inc. (“SettleWise”, “we”, “us”, or “our”) is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our financial technology platform and services (“Service”).

By using SettleWise, you consent to the data practices described in this Privacy Policy.

2. Information We Collect

2.1 Information You Provide Directly

Account Information:

  • Name, email address, phone number
  • Business name, address, and tax identification numbers
  • Job title and role within your organization
  • Password and authentication credentials

Financial Information:

  • Bank account details and routing numbers
  • Payment method information (credit cards, ACH details)
  • Invoice data and payment records
  • Transaction history and amounts
  • Customer payment information

Business Data:

  • Customer lists and contact information
  • Invoice details and payment terms
  • Accounting system data (QuickBooks integration)
  • Communication preferences and settings

2.2 Information We Collect Automatically

Usage Information:

  • Log data including IP addresses, browser type, and device information
  • Pages visited, features used, and time spent on the Service
  • Click patterns, navigation paths, and user interactions
  • Error logs and performance metrics

Technical Information:

  • Device identifiers and operating system information
  • Browser settings and installed plugins
  • Network connection details and ISP information
  • Cookies and similar tracking technologies

Location Information:

  • IP-based location data for security and fraud prevention
  • Time zone information for scheduling and notifications

2.3 Information from Third Parties

Integration Partners:

  • Data from QuickBooks, banks, and payment processors
  • Customer information from connected accounting systems
  • Transaction data from financial institutions
  • Verification data from identity services

Service Providers:

  • Analytics data from website and application monitoring services
  • Communication data from email service providers
  • Security information from fraud prevention services

3. How We Use Your Information

3.1 Service Provision

  • Payment Processing: Match payments to invoices and reconcile accounts
  • Customer Management: Track customer information and payment history
  • Reporting: Generate financial reports and analytics
  • Integration: Connect with accounting systems and financial institutions
  • Communication: Send payment reminders and service notifications

3.2 Business Operations

  • Account Management: Create and maintain user accounts
  • Customer Support: Respond to inquiries and resolve issues
  • Billing: Process subscription payments and transaction fees
  • Security: Detect and prevent fraud, unauthorized access, and security threats
  • Compliance: Meet legal and regulatory requirements

3.3 Service Improvement

  • Analytics: Analyze usage patterns to improve features and performance
  • Development: Develop new features and enhance existing functionality
  • Testing: Conduct A/B testing and quality assurance
  • Research: Understand user needs and market trends

3.4 Legal and Regulatory

  • Compliance: Comply with financial regulations and reporting requirements
  • Legal Obligations: Respond to legal requests and court orders
  • Risk Management: Assess and mitigate business and operational risks
  • Audit: Support internal and external auditing processes

4. Information Sharing and Disclosure

4.1 With Your Consent

We may share your information with third parties when you explicitly consent or direct us to do so.

4.2 Service Providers

We share information with trusted service providers who assist us in operating our business:

  • Cloud Infrastructure: AWS, Google Cloud, or similar providers for data hosting
  • Payment Processing: Stripe, banks, and payment networks for transaction processing
  • Communication: Email service providers for notifications
  • Analytics: Analytics platforms for service improvement
  • Security: Fraud prevention and security monitoring services

4.3 Integration Partners

When you connect third-party services to SettleWise:

  • Accounting Systems: QuickBooks and other accounting software
  • Financial Institutions: Banks and payment processors for transaction data
  • Business Tools: CRM systems, invoicing platforms, and other business applications

4.4 Legal Requirements

We may disclose information when required by law or to:

  • Comply with legal processes, court orders, or government requests
  • Enforce our Terms of Service and other agreements
  • Protect the rights, property, or safety of SettleWise, users, or others
  • Investigate and prevent fraud, security threats, or illegal activities

4.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5. Data Security

5.1 Security Measures

We implement comprehensive security measures to protect your information:

  • Encryption: Data is encrypted in transit and at rest using industry-standard protocols
  • Access Controls: Role-based access controls and multi-factor authentication
  • Network Security: Firewalls, intrusion detection, and secure network architecture
  • Monitoring: Continuous security monitoring and incident response procedures
  • Compliance: SOC 2 Type II and other security certifications

5.2 Financial Data Protection

Given the sensitive nature of financial information:

  • PCI Compliance: Payment card data is processed in compliance with PCI DSS standards
  • Bank-Level Security: Financial data is protected with bank-grade security measures
  • Segregation: Customer data is logically separated and access-controlled
  • Audit Trails: Comprehensive logging of all data access and modifications

5.3 Employee Access

  • Background Checks: All employees undergo background verification
  • Training: Regular security and privacy training for all staff
  • Need-to-Know: Access to customer data is limited to authorized personnel only
  • Monitoring: Employee access is monitored and audited regularly

6. Data Retention

6.1 Retention Periods

We retain your information for different periods based on the type of data and business needs:

  • Account Information: Retained while your account is active and for 7 years after closure
  • Financial Records: Retained for 7 years to comply with financial regulations
  • Communication Data: Retained for 3 years for customer service and legal purposes
  • Usage Analytics: Aggregated and anonymized data may be retained indefinitely

6.2 Deletion Requests

You may request deletion of your personal information, subject to:

  • Legal and regulatory retention requirements
  • Legitimate business needs (e.g., fraud prevention, dispute resolution)
  • Technical limitations in our systems

7. Your Privacy Rights

7.1 Access and Portability

  • Access: Request copies of your personal information
  • Portability: Export your data in a machine-readable format
  • Correction: Update or correct inaccurate information

7.2 Control and Deletion

  • Deletion: Request deletion of your personal information (subject to limitations)
  • Restriction: Limit how we process your information
  • Objection: Object to certain types of processing

7.3 Communication Preferences

  • Marketing: Opt out of marketing communications
  • Notifications: Control service-related notifications and alerts

7.4 State-Specific Rights

California Residents (CCPA/CPRA):

  • Right to know what personal information is collected and how it's used
  • Right to delete personal information (subject to exceptions)
  • Right to opt out of the sale of personal information (we do not sell personal information)
  • Right to non-discrimination for exercising privacy rights

European Residents (GDPR):

  • Right to access, rectify, erase, and port personal data
  • Right to restrict or object to processing
  • Right to withdraw consent where processing is based on consent
  • Right to lodge a complaint with supervisory authorities

8. Cookies and Tracking Technologies

8.1 Types of Cookies

We use various types of cookies and similar technologies:

  • Essential Cookies: Required for basic functionality and security
  • Analytics Cookies: Help us understand how users interact with our Service
  • Preference Cookies: Remember your settings and preferences
  • Marketing Cookies: Used for targeted advertising (with your consent)

8.2 Cookie Management

You can control cookies through:

  • Browser Settings: Most browsers allow you to block or delete cookies
  • Opt-Out Tools: Industry opt-out tools for advertising cookies
  • Our Settings: Cookie preferences in your account settings

9. International Data Transfers

9.1 Cross-Border Transfers

SettleWise operates primarily in the United States, but we may transfer data internationally to:

  • Service providers and partners in other countries
  • Support global business operations
  • Comply with legal requirements in different jurisdictions

9.2 Transfer Safeguards

When transferring data internationally, we implement appropriate safeguards:

  • Adequacy Decisions: Transfers to countries with adequate privacy protections
  • Standard Contractual Clauses: EU-approved contractual protections
  • Certification Programs: Participation in recognized privacy frameworks
  • Binding Corporate Rules: Internal privacy standards for data transfers

10. Children's Privacy

SettleWise is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will:

  • Post the updated Privacy Policy on our website
  • Notify you of material changes via email or through the Service
  • Update the "Last Updated" date at the top of this policy

Your continued use of SettleWise after changes become effective constitutes acceptance of the updated Privacy Policy.

12. Contact Information

12.1 Privacy Questions

If you have questions about this Privacy Policy or our privacy practices:

General Support

For general support and account questions:

Email: support@settlewise.finance

Website: https://www.settlewise.finance

13. Regulatory Compliance

13.1 Financial Regulations

As a financial technology company, we comply with various regulations:

  • Bank Secrecy Act (BSA): Anti-money laundering and reporting requirements
  • Gramm-Leach-Bliley Act: Financial privacy and data security requirements
  • Payment Card Industry (PCI DSS): Credit card data security standards
  • State Money Transmitter Laws: Where applicable to our services

13.2 Privacy Regulations

We comply with applicable privacy laws including:

  • California Consumer Privacy Act (CCPA/CPRA)
  • General Data Protection Regulation (GDPR)
  • State privacy laws in jurisdictions where we operate