PRIVACY NOTICE
FOR US-BASED CUSTOMERS ONLY VERSION 2.0 EFFECTIVE DATE: May 29, 2026
1. INTRODUCTION
This document, herein referred to as the “Privacy Notice”, outlines the privacy practices of Spendbase (“We”, “us”, “our”, “Spendbase”) and governs the processing of personal information in connection with the provision of our digital banking, payment, and financial technology services (“Services”) to the US-based customers (“Customers”) defined below.
Your continued use of the Services constitutes your acknowledgment of, and agreement to, the privacy practices described in this Privacy Notice. In the event of any concern relating to this Privacy Notice or how we handle your Personal Information, feel free to contact us at:
Privacy Officer, Spendbase Inc. Attn: Privacy and Compliance Email: privacy@test-domain-partnerway.prod.spendbase.co
2. APPLICABILITY TO THE CUSTOMER
Spendbase provides business-to-business financial technology services, including corporate card programs and related platform services. All Spendbase accounts are opened and maintained exclusively for business purposes. Therefore, this Privacy Notice applies to Customers, namely:
- Business Customers that enter into a contractual relationship with Spendbase, who are treated as commercial entities (“Business Customer”), and
- Individuals who access or use Spendbase services on behalf of a Business Customer, including employees, officers, and cardholders, who act solely in a business or employment capacity (“Authorized User”)
3. ABOUT SPENDBASE
| Field | Description |
| Legal name | Spendbase Inc. |
| Registration No | 61-2064269 |
| Address | 16192 Coastal Highway, Lewes, DE 19958 |
| corporate@test-domain-partnerway.prod.spendbase.co | |
| Email (privacy matters) | privacy@test-domain-partnerway.prod.spendbase.co |
In accordance with applicable law, Spendbase may act as:
- Independent Controller for Personal Data processed for its own legal, compliance, fraud prevention, security, and AML/KYC obligations.
- Service Provider / Processor with respect to Authorized User Personal Data processed on behalf of Business Customers for account administration, expense management, and related platform purposes, Spendbase acts as a service provider under applicable U.S. state privacy laws and as a data processor under contractual arrangements.
For information on how this dual-capacity arrangement affects the processing of Authorized User Personal Data, please refer to Section 12 (Authorized Users) below.
A Data Processing Agreement (“DPA”) governing Spendbase’s processing of Personal Data on behalf of Business Customers is available upon request. The DPA sets out the obligations of each party in connection with the processing of Authorized User data and takes precedence over this Privacy Notice to the extent of any inconsistency.
Sponsor banks and financial institution partners. Sponsor banks, card issuers, and payment network partners that participate in the delivery of the Services process Personal Data as independent controllers for their own regulated purposes — including BSA/AML compliance, OFAC sanctions screening, Suspicious Activity Report (SAR) filing, fraud risk management, and obligations arising under their own banking charters and applicable financial services regulation. Data flows to these parties constitute disclosures between independent controllers, not processing instructions from Spendbase. Each such institution is independently accountable to its own regulators (including the OCC, FDIC, and Federal Reserve) for the Personal Data it receives. Business Customers and Authorized Users may be subject to those institutions’ own privacy notices in addition to this Notice.
4. REGULATORY FRAMEWORK
Where applicable, Spendbase processes Personal Data in compliance with:
- The Gramm-Leach-Bliley Act (GLBA) and its implementing regulations;
- The FTC Safeguards Rule (16 C.F.R. Part 314);
- Applicable U.S. state privacy and data protection laws, including those listed in Section 14 (State Privacy Disclosures); and
- Contractual obligations with our banking partners and service providers, who are required to maintain privacy and security practices consistent with applicable law.
5. PERSONAL DATA WE COLLECT
Spendbase collects and processes Personal Data only to the extent necessary to provide the Services, comply with applicable legal and regulatory obligations, prevent fraud and misuse, and operate and secure Spendbase and its Services. Depending on the customer type, we collect Personal Data as follows:
| Category | Description | Applies To |
| Identity & Contact | Name, date of birth, address, email (personal and work), phone number, employment information, government-issued ID, driver’s license number, job title | Authorized User |
| Business Information | Legal and trade names, registration and tax identifiers, incorporation details, ownership and signatory information | Business Customer |
| Financial Information | Account data, corporate card details, transaction history, payment records, expenses, and merchant information | Business Customer; Authorized User |
| Compliance & Risk | KYC/KYB records, sanctions screening results, fraud monitoring data, dispute and investigation records | Business Customer; Authorized User |
| Authentication & Access | Credentials, access permissions, role assignments, activity logs | Business Customer; Authorized User |
| Communications | Customer support inquiries, correspondence, and feedback; communications may be recorded where permitted by law and with appropriate notice | Business Customer; Authorized User |
| Technical & Usage | Device identifiers, IP address, browser type, operating system, access timestamps, and platform interaction data | Business Customer; Authorized User |
All Authorized User Personal Data is processed solely in connection with the individual’s professional or employment relationship with the relevant Business Customer. Spendbase does not intentionally collect Personal Data for personal, family, or household purposes, does not direct its Services to children, and does not knowingly collect Personal Data from individuals under the age of 13.
Where permitted by law, Spendbase may create and use aggregated or de-identified data derived from Personal Data for analytics, reporting, benchmarking, and service improvement. Such data does not identify any individual and is not treated as Personal Data under applicable law.
6. SOURCES OF PERSONAL DATA
Spendbase collects Personal Data from the following lawful and transparent sources:
| Source | Description |
| Business Customer (direct) | Provided during onboarding, account setup, and ongoing administration via applications, forms, platform inputs, and communications |
| Authorized User (direct) | Provided when accessing the platform, activating accounts, using corporate cards, submitting expenses, or contacting support |
| Business Customer (about Authorized Users) | Provided to grant platform access, issue cards, manage permissions, and meet legal obligations. Business Customers are responsible for ensuring such disclosures are lawful and that required notifications have been made to Authorized Users |
| Third-Party Service Providers | Identity verification, KYC/KYB, sanctions screening, fraud prevention, and transaction monitoring providers; payment networks, card issuers, and sponsor banks; infrastructure, security, and analytics providers; public or government sources where permitted by law |
| Automatically Collected | Technical and usage data collected via cookies and similar technologies when Business Customers or Authorized Users access the Spendbase platform or website |
7. HOW WE USE PERSONAL DATA
Spendbase uses Personal Data solely for legitimate business and compliance purposes consistent with the nature of our Services. Personal Data is not used for purposes incompatible with the original reason it was collected.
| Purpose | Description | Applicable Basis / Law |
| Providing Services | Onboarding Business Customers and Authorized Users; establishing and managing accounts and corporate card programs; processing transactions and payments; enabling expense management, reporting, and account controls; providing customer support | Contractual necessity; GLBA |
| Legal & Regulatory Compliance | Complying with AML, KYC/KYB, sanctions compliance, FINCEN reporting, tax, recordkeeping, and responding to lawful requests from regulators, courts, or law enforcement | Legal obligation; GLBA; Bank Secrecy Act; applicable state law |
| Fraud, Security & Risk | Monitoring transactions and platform activity, performing risk assessments, enforcing access controls, and maintaining audit and security logs to prevent, detect, and respond to fraud, unauthorized access, and other harmful activities | Legitimate business interest; FTC Safeguards Rule; GLBA |
| Service Improvement | Analyzing and improving the functionality, reliability, and performance of the platform; troubleshooting, testing, analytics, and quality assurance. De-identified or aggregated data is used where feasible | Legitimate business interest |
| Communications | Sending account notifications, operational updates, security alerts, policy changes, and support communications. Communications are limited to what is relevant to the provision and administration of the Services | Contractual necessity; GLBA |
| Marketing (Limited) | Providing information about Services, features, or updates relevant to an existing business relationship, where permitted by law. Spendbase does not engage in consumer-style targeted advertising. Opt-out available at any time by emailing privacy@test-domain-partnerway.prod.spendbase.co or using the unsubscribe link in any marketing communication (actioned within 10 business days) | Consent / opt-out; applicable state law |
| Aggregated / De-Identified Uses | Benchmarking, analytics, reporting, and product development using data that does not identify individuals. Such data is not Personal Data under applicable law | Permitted use; not Personal Data |
8. HOW WE SHARE PERSONAL DATA
Spendbase does not sell Personal Data and does not disclose Personal Data except as necessary to operate the Services, comply with legal and regulatory obligations, protect the security and integrity of the platform, or as otherwise permitted by law. All service providers are contractually required to maintain privacy and security practices consistent with this Notice and applicable law.
| Recipient | Purpose of Sharing |
| Sponsor Banks & Financial Institutions | Account establishment, card issuance, transaction processing, fraud monitoring, and regulatory compliance. Disclosures to sponsor banks and financial institution partners are made on a controller-to-controller basis — these institutions process received Personal Data for their own independent legal and regulatory purposes, including BSA/AML obligations, OFAC screening, SAR/CTR filing, and applicable banking regulation. Spendbase is not responsible for the subsequent processing of Personal Data by these institutions in their capacity as independent controllers. Business Customers and Authorized Users may receive separate privacy notices from these institutions. |
| Service Providers & Vendors | KYC/KYB, sanctions screening, fraud prevention, payment processing, customer support, cloud infrastructure, security, analytics, and communications. Providers are bound by contract to use data only for specified purposes and to implement appropriate safeguards |
| Business Customers & Authorized Administrators | Personal Data relating to Authorized Users may be shared with the relevant Business Customer and its designated administrators for account administration, expense management, reporting, and compliance oversight. Spendbase acts on Business Customer instructions and applicable law |
| Regulators & Law Enforcement | FinCEN, CFPB, FTC, courts, and law enforcement where required or permitted by law — including for regulatory reporting, lawful subpoenas, court orders, and the exercise or defense of legal claims |
| Corporate Transaction Parties | In connection with a merger, acquisition, reorganization, sale of assets, or financing, subject to appropriate confidentiality protections and applicable legal requirements |
| Aggregated / De-Identified Data | Analytics, reporting, and benchmarking — in a form that does not identify any individual. Not treated as Personal Data under applicable law |
9. GLBA PRIVACY NOTICE (NONPUBLIC PERSONAL INFORMATION)
This section is provided in accordance with the Gramm-Leach-Bliley Act (GLBA) and describes how Spendbase processes Nonpublic Personal Information (“NPI”) in connection with U.S. financial services provided through regulated financial institutions.
Scope of This Notice. Spendbase provides business-focused financial technology services, including corporate card and payment-related services, in partnership with one or more regulated financial institutions. In this capacity, Spendbase acts as a service provider or program manager and processes certain Personal Data on behalf of, or in connection with, GLBA-regulated financial institutions.
This GLBA Privacy Notice applies to Personal Data that constitutes NPI under GLBA and is processed by Spendbase in connection with the provision of financial products or services in the United States. Although Spendbase is not a bank, it applies GLBA-aligned privacy and data security practices to the NPIs it processes in connection with such services.
Categories of Nonpublic Personal Information We Process. Spendbase may process NPI such as identification and contact information of Authorized Users and business representatives, account and transaction information, payment and card-related data, and information obtained through identity verification, KYB/KYC, sanctions screening, and fraud monitoring.
How We Use Nonpublic Personal Information. Spendbase processes NPI solely to provide and administer financial services, process transactions, manage accounts and card programs, comply with legal and regulatory obligations, prevent fraud and unauthorized activity, and maintain the security and integrity of the Services.
How We Share Nonpublic Personal Information. Spendbase may disclose NPI, as permitted by law, to regulated financial institutions, sponsor banks, card issuers, payment networks, and service providers involved in providing financial services; to regulators, courts, or law enforcement where required or permitted by law; and in connection with corporate transactions, subject to applicable legal requirements. Spendbase does not disclose NPI to nonaffiliated third parties for their own independent marketing purposes.
Safeguards for Nonpublic Personal Information. Spendbase maintains administrative and technical safeguards designed to protect the confidentiality and security of NPI in accordance with the FTC Safeguards Rule, applicable GLBA requirements, and contractual obligations with regulated financial institutions.
GLBA Opt-Out Rights. GLBA provides certain individuals with the right to limit specific disclosures of NPI to nonaffiliated third parties. Because Spendbase does not share NPI with nonaffiliated third parties for their own independent marketing purposes, no GLBA opt-out is currently required. If this practice changes, Spendbase will provide any required notices and opt-out mechanisms in accordance with applicable law.
10. DATA RETENTION
Personal Data is retained only for as long as necessary to fulfill the purposes for which it was collected, in accordance with applicable legal and regulatory requirements, contractual obligations, and our internal data governance policies.
| Category | Retention Rationale | Indicative Period |
| AML / KYC / KYB Records | Bank Secrecy Act, FinCEN requirements, GLBA obligations | Minimum 5 years from account closure |
| Transaction Records | Financial regulatory requirements, dispute resolution, tax obligations | 7 years |
| Account & Contractual Records | Contract enforcement, audit, regulatory inspection | Duration of relationship + 7 years |
| Fraud & Security Logs | FTC Safeguards Rule, fraud investigation, legal defense | 3 years from incident date |
| Communications & Support Records | Quality assurance, dispute resolution | 3 years |
| Marketing Preferences | Consent management and opt-out records | Duration of relationship + 3 years |
| Aggregated / De-Identified Data | Analytics, benchmarking — does not identify individuals | Retained indefinitely as permitted by law |
Where retention is no longer required, Personal Data is securely deleted, anonymized, or de-identified in accordance with applicable policies and technical controls.
11. DATA SECURITY & SAFEGUARDS
Spendbase implements and maintains administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, consistent with the FTC Safeguards Rule and applicable law.
- Administrative safeguards: Policies and procedures governing data access, confidentiality, employee training, incident response, vendor management, and compliance oversight. Access to Personal Data is limited to personnel and service providers who require it for legitimate business purposes and who are subject to confidentiality obligations.
- Technical safeguards: Access controls, multi-factor authentication, encryption in transit and at rest, logging and monitoring, network security controls, and vulnerability management.
- Incident response: Spendbase maintains procedures to detect, respond to, and recover from security incidents. Where required by applicable law, Spendbase will provide notification of data breaches or security incidents within the timeframes mandated by law — and in no event later than 72 hours after becoming aware of a notifiable incident involving regulated financial data, or as otherwise required by applicable state breach notification laws.
While Spendbase takes reasonable and appropriate measures to protect Personal Data, no system or method of transmission can be guaranteed to be completely secure. Business Customers and Authorized Users are responsible for maintaining the confidentiality of their access credentials and for using the Services in a secure manner.
12. AUTORIZED USERS
Spendbase processes Personal Data relating to Authorized Users solely in connection with the Services provided to the relevant Business Customer and in accordance with Business Customer instructions, applicable contractual terms, and applicable law.
Business Customer responsibilities. Business Customers are responsible for: (i) determining which individuals are authorized to access the Services and managing their access rights and credentials; (ii) ensuring that Authorized User information provided to Spendbase is accurate, current, and lawfully obtained; (iii) informing Authorized Users about how their Personal Data is collected, used, and shared in connection with the Services, including through internal policies and notices where required by applicable employment, privacy, and data protection laws; and (iv) ensuring their use of Authorized User data complies with applicable law.
Spendbase’s role. With respect to Authorized User data processed on behalf of Business Customers for platform administration purposes, Spendbase acts as a service provider / data processor and does not control or determine the purpose or means of such processing. With respect to data processed for Spendbase’s own legal, compliance, fraud prevention, and security obligations, Spendbase acts as an independent controller.
Authorized User requests. Authorized Users should direct requests relating to access, correction, or deletion of their Personal Data primarily to the Business Customer that authorized their access to the Services. Where required by law or contract, Spendbase will assist Business Customers in responding to such requests. In the event an Authorized User submits a privacy request directly to Spendbase, Spendbase will endeavor to transfer the request to the relevant Business Customer without undue delay and provide such information as is permitted by law.
13. COOKIES & ANALYTICS
Spendbase uses cookies and similar technologies in connection with its websites and platform to operate, secure, and improve the Services. These technologies help ensure platform functionality, protect against fraud and unauthorized access, support analytics and performance monitoring, and maintain service reliability.
Cookies and similar technologies may collect information such as device identifiers, IP address, browser type, operating system, language preferences, access timestamps, and interaction data. This information is used for technical, security, and operational purposes.
Spendbase uses the following categories of technologies:
- Strictly necessary: Required for the operation, security, and authentication of the platform. Cannot be disabled without impairing functionality.
- Functional and performance: Help remember user preferences, analyze platform performance, and diagnose technical issues.
- Analytics: Help understand how the Services are used and improve functionality. Analytics tools are configured to support business operations and are not used for cross-context behavioral advertising.
Spendbase does not engage in consumer-style behavioral advertising and does not use cookies for cross-context behavioral advertising. Where required by applicable law (including CPRA for California residents), Spendbase provides appropriate notices and choices regarding the use of cookies and similar technologies through platform settings or browser controls.
14. CROSS-BORDER TRANSFER
Spendbase is a global technology company. Personal Data collected in connection with the Services is primarily processed within the United States. However, Spendbase and certain of its service providers may also store, transfer, or access Personal Data from other jurisdictions. Key infrastructure providers include:
- Amazon Web Services (AWS) — U.S. and EU/EEA regions (including Ireland and Frankfurt);
- Google Cloud Platform (GCP) — U.S. and EU/EEA regions;
- Other subprocessors that are disclosed in the DPA.
Where Personal Data is processed outside the United States in jurisdictions with differing data protection standards, Spendbase implements appropriate safeguards, which may include contractual protections (such as Standard Contractual Clauses for transfers to or from EEA-based sub-processors), access controls, security assessments, and risk reviews. All service providers are required by contract to maintain protections comparable to those required under applicable law.
Spendbase remains accountable for Personal Data transferred to service providers. Transfers are conducted solely for legitimate business, operational, and compliance purposes. Business Customers may request further information on transfer destinations and applicable safeguards by contacting privacy@test-domain-partnerway.prod.spendbase.co
15. YOUR RIGHTS AND CHOICES
Certain individuals may have rights with respect to their Personal Data under applicable U.S. state privacy laws. The availability and scope of these rights depend on the individual’s state of residence, their role, and the nature of the data processing. Because Spendbase operates in a business-to-business context and processes most data in an employment or commercial capacity, some state privacy law rights may be limited or subject to exceptions.
Spendbase does not sell Personal Data and does not engage in cross-context behavioral advertising.
| Right | Description | Availability |
| Right to Access | Request Personal Data held by Spendbase, how it has been used or disclosed, and receive it in an understandable form. Response within 45 days (extendable by an additional 45 days with notice) | All applicable states |
| Right to Correction | Request correction of inaccurate, incomplete, or outdated Personal Data | All applicable states |
| Right to Deletion | Request deletion of Personal Data where no legal retention obligation applies. Subject to applicable exceptions including GLBA, BSA, and fraud prevention requirements | All applicable states |
| Right to Opt Out of Sale / Sharing | Spendbase does not sell Personal Data and does not share it for cross-context behavioral advertising. This right is therefore not presently exercisable but is acknowledged | CA, TX, VA, CO, CT, NJ and others |
| Right to Limit Sensitive Data Use | Where Spendbase collects sensitive Personal Data as defined under applicable state law, use is limited to purposes permitted by law. No further limitation request is currently applicable | CA (CPRA), TX |
| Right to Appeal | If a privacy request is denied, individuals may appeal by contacting privacy@test-domain-partnerway.prod.spendbase.co with the subject line “Privacy Request Appeal”. Spendbase will respond within 45 days | VA, CO, CT, TX, NJ and others |
To exercise any right listed above, submit a written request to privacy@test-domain-partnerway.prod.spendbase.co with the subject line “Privacy Rights Request” and include: (i) your full name and email address associated with the account; (ii) the name of the Business Customer you are affiliated with; (iii) a description of the right you wish to exercise; and (iv) any additional information reasonably necessary to verify your identity.
Spendbase will verify identity before processing any request. Verification may include confirming information already on file. Spendbase will not retaliate against any individual for exercising a privacy right or filing a complaint. Authorized Users should generally direct requests to the Business Customer that authorized their access to the Services.
16. YOUR RIGHTS AND CHOICES
This section provides supplemental disclosures required under certain U.S. state privacy laws. These disclosures apply only to the extent the relevant law applies to Spendbase’s processing activities and to individuals acting in an applicable capacity under that law.
California (CPRA / CCPA)
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CPRA”), applies to Spendbase to the extent it processes personal information of California residents not otherwise exempted.
Categories collected: As described in Section 5 (Personal Data We Collect), including identifiers, professional/employment-related information, commercial transaction information, internet or network activity information, and compliance-related data. Spendbase does not collect sensitive personal information for purposes outside those permitted by CPRA.
Sources and purposes: As described in Sections 6 and 7.
Disclosure: As described in Section 8. Spendbase does not sell personal information and does not share personal information for cross-context behavioral advertising as defined under CPRA.
Retention: As described in Section 10.
CPRA rights: Subject to applicable exceptions, California residents may have the right to access, correct, or delete personal information, and to limit the use of sensitive personal information. Because Spendbase operates in a B2B context and processes most data in a commercial or employment capacity, certain rights may be limited. Requests may be submitted as described in Section 15.
Virginia (VCDPA)
Virginia residents may have rights to access, correct, or delete certain Personal Data and to opt out of certain processing, subject to statutory limitations and exemptions. Spendbase processes Personal Data primarily in a commercial and employment context. Spendbase does not sell Personal Data or engage in targeted advertising as defined under the VCDPA. Appeals may be submitted as described in Section 15.
Colorado (CPA)
Colorado residents may have certain rights regarding their Personal Data, subject to statutory limitations and exemptions. Spendbase does not sell Personal Data or engage in targeted advertising or profiling producing legal or similarly significant effects as defined under the CPA. Appeals may be submitted as described in Section 15.
Connecticut (CTDPA)
Connecticut residents may have limited rights with respect to their Personal Data, subject to applicable exceptions. Spendbase does not sell Personal Data or engage in targeted advertising. Appeals may be submitted as described in Section 15.
Utah (UCPA)
The UCPA provides limited rights to Utah residents. Spendbase processes Personal Data to provide business services, comply with legal obligations, and maintain security. Spendbase does not sell Personal Data or use Personal Data for targeted advertising within the meaning of the UCPA.
-
Texas (TDPSA)
The Texas Data Privacy and Security Act (TDPSA) applies to Spendbase’s processing of Texas residents’ Personal Data. Texas residents may have rights to access, correct, delete, and obtain a portable copy of their Personal Data, and to opt out of the sale of personal data, targeted advertising, and profiling. Spendbase does not sell Personal Data or engage in targeted advertising. Appeals may be submitted as described in Section 15. Unresolved complaints may be escalated to the Texas Attorney General.
Oregon (OCPA)
The Oregon Consumer Privacy Act applies to Spendbase’s processing of Oregon residents’ Personal Data. Oregon residents may have rights to access, correct, delete, and obtain a portable copy of their Personal Data, and to opt out of certain processing. Spendbase does not sell Personal Data or engage in targeted advertising. Unresolved complaints may be escalated to the Oregon Attorney General.
New Jersey (NJDPA)
The New Jersey Data Privacy Act applies to Spendbase’s processing of New Jersey residents’ Personal Data. New Jersey residents may have rights to access, correct, delete, and obtain a portable copy of their Personal Data, and to opt out of the sale of Personal Data, targeted advertising, and certain profiling. Spendbase does not sell Personal Data or engage in targeted advertising. Unresolved complaints may be escalated to the New Jersey Division of Consumer Affairs.
Montana (MCDPA)
The Montana Consumer Data Privacy Act applies to Spendbase’s processing of Montana residents’ Personal Data. Montana residents may have rights to access, correct, delete, and obtain a portable copy of their Personal Data, and to opt out of certain processing. Spendbase does not sell Personal Data or engage in targeted advertising.
Indiana, Iowa, Tennessee
Residents of Indiana, Iowa, and Tennessee may have rights regarding their Personal Data under those states’ recently enacted privacy laws. Spendbase does not sell Personal Data or engage in targeted advertising as defined under these laws. Requests may be submitted as described in Section 15.
Other U.S. States
Spendbase monitors and complies with applicable privacy and data protection laws in other U.S. states as they become effective. Where such laws provide rights applicable to individuals in a commercial or employment context and where Spendbase meets applicable thresholds, Spendbase will provide appropriate disclosures and mechanisms in accordance with applicable requirements.
17. CHANGES TO THIS PRIVACY POLICY
Spendbase may update this Privacy Notice from time to time to reflect changes in our practices, services, legal or regulatory requirements, or operational needs. When we make material changes, we will provide notice through the Spendbase platform by updating the Effective Date shown on this document.
In the event of significant changes that may materially affect how Personal Data is processed, Spendbase will use available means of communication to notify affected Business Customers and Authorized Users before the changes take effect, in accordance with applicable law.
Continued use of the Services after an updated Privacy Notice becomes effective constitutes acknowledgment of the revised Notice, to the extent permitted by law.
18. DEFINITIONS
For purposes of this Privacy Notice, the following terms have the meanings set forth below:
| Term | Meaning |
| Authorized User | An individual, including employees, officers, and authorized cardholders, whom a Business Customer authorizes to access or use the Spendbase Services on the Business Customer’s behalf. |
| Business Customer | A legal entity or organization that enters into a contractual relationship with Spendbase for the provision of business-focused financial or payment services. |
| Controller | An entity that determines the purposes and means of the processing of Personal Data. |
| DPA | Data Processing Agreement — the contractual document governing the terms on which Spendbase processes Personal Data on behalf of a Business Customer. |
| GLBA | The Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq., and its implementing regulations. |
| Nonpublic Personal Information (NPI) | Personal information obtained by a financial institution in connection with providing a financial product or service that is not publicly available, as defined under GLBA. |
| Personal Data | Any information that identifies, relates to, describes, or could reasonably be linked to an identified or identifiable individual, as defined under applicable U.S. privacy and data protection laws and as further described in this Privacy Notice. |
| Service Provider / Processor | An entity that collects, uses, or discloses Personal Data on behalf of another entity (the controller or Business Customer), subject to the controller’s instructions and applicable contractual and legal restrictions. |
| Services | The Spendbase digital banking, payment, corporate card, and related financial technology services provided to Business Customers. |
Table of contents
1. INTRODUCTION 2. APPLICABILITY TO THE CUSTOMER 3. ABOUT SPENDBASE 4. REGULATORY FRAMEWORK 5. PERSONAL DATA WE COLLECT 6. SOURCES OF PERSONAL DATA 7. HOW WE USE PERSONAL DATA 8. HOW WE SHARE PERSONAL DATA 9. GLBA PRIVACY NOTICE (NONPUBLIC PERSONAL INFORMATION) 10. DATA RETENTION 11. DATA SECURITY & SAFEGUARDS 12. AUTORIZED USERS 13. COOKIES & ANALYTICS 14. CROSS-BORDER TRANSFER 15. YOUR RIGHTS AND CHOICES 16. YOUR RIGHTS AND CHOICES 17. CHANGES TO THIS PRIVACY POLICY 18. DEFINITIONS