PRIVACY NOTICE
FOR CANADIAN CUSTOMERS ONLY VERSION 1.1 EFFECTIVE DATE: Jun 30, 2026
1. INTRODUCTION
This document, herein referred to as the “Privacy Notice”, outlines the privacy practices of Spendbase (“We”, “us”, “our”, “Spendbase”) and governs the processing of personal information in connection with the provision of our digital banking, payment, and financial technology services (“Services”) to the Canadian customers (“Customers”) defined below.
Your continued use of the Services constitutes your acknowledgment of, and agreement to, the privacy practices described in this Privacy Notice. In the event of any concern relating to this Privacy Notice or how we handle your Personal Information, feel free to contact us at:
Privacy Officer, Spendbase Ltd. Attn: Privacy and Compliance Email: privacy@test-domain-partnerway.prod.spendbase.co
Nota bene! As of the Effective date, Spendbase does NOT operate in Quebec. Therefore, a French-language version of this Privacy Notice is not available.
2. APPLICABILITY TO THE CUSTOMER
Spendbase provides business-to-business financial technology services, including corporate card programs and related platform services. All Spendbase accounts are opened and maintained exclusively for business purposes. Therefore, this Privacy Notice applies to Customers, namely:
- Business Customers that enter into a contractual relationship with Spendbase, who are treated as commercial entities (“Business Customer”), and
- Individuals who access or use Spendbase services on behalf of a Business Customer, including employees, officers, and cardholders, who act solely in a business or employment capacity (“Authorized User”)
3. ABOUT SPENDBASE
In accordance with applicable law, Spendbase operates as an Organisation (or an “Enterprise” as defined in Quebec) in relation to Business Customer. Processing of Personal Information of the Authorized Users is fulfilled by Spendbase as Service provider (or an “Agent” as defined in Quebec), acting under the instructions of the Business Customer as Organisation (or an “Enterprise” as defined in Quebec), enshrined in the respective contract.
For detailed information on how it may influence the processing of the Authorized User Personal Information, please refer to Section 12 (AUTHORIZED USERS) herein.
| Field | Description |
| Legal name | Spendbase Ltd. |
| Registration No
(Business Number). |
727075152TZ0001 |
| Address | 222 Somerset Street West, Unit 601, Ottawa, Ontario, K2P2G3, Canada |
| Website URL | |
| corporate@test-domain-partnerway.prod.spendbase.co | |
| Email (privacy matters) | privacy@test-domain-partnerway.prod.spendbase.co |
4. PERSONAL INFORMATION WE COLLECT
Spendbase collects and processes Personal Information only to the extent necessary to provide Services, comply with applicable legal and regulatory obligations, prevent fraud and misuse, and operate and secure the Spendbase platform.
Depending on the customer definition herein, we collect Personal information as follows:
| Category | Description | Customer |
| Identity and Contact Information | Name, date of birth, address, email (personal and work), phone (work and personal), employment information, government-issued ID (unique identification number), driver’s license number, job title | Authorized User |
| Business Information | Legal and trade names, registration and business numbers, tax identifiers, incorporation details, ownership and signatory information | Business Customer |
| Financial Information | Account data, corporate card details, transaction history, payment records, expenses, and merchant information | Business Customer; Authorized User |
| Compliance and Risk Information | KYC/KYB records, sanctions screening results, fraud monitoring data, dispute and investigation records | Business Customer; Authorized User |
| Authentication and Access Information | Credentials, access permissions, role assignments, activity logs | Business Customer; Authorized User |
| Communication Information | Customer support inquiries, correspondence, and feedback may be recorded where permitted by law and with appropriate notice | Business Customer; Authorized User |
| Technical and Usage Information | Device identifiers, IP address, browser type, access timestamps, interaction data | Business Customer; Authorized User |
All Authorized User Personal Information is processed solely in the context of their professional relationship with the relevant Business Customer. Spendbase does not knowingly collect Personal Information from individuals under 18. For Quebec residents, parental or tutor consent is required for individuals under 14. Aggregated or de-identified data may be used for analytics and service improvement and is not treated as Personal Information. Spendbase does not collect Personal Health Information.
5. SOURCES OF PERSONAL INFORMATION
Spendbase collects Personal Information from a limited number of lawful and transparent sources in connection with the provision of its services to Business Customers and Authorized Users.
| Source | Description |
| Business Customer (direct) | Provided during onboarding, account setup, and ongoing administration via applications, forms, platform inputs, and communications |
| Authorized User (direct) | Provided when accessing the platform, activating accounts, using corporate cards, submitting expenses, or contacting support |
| Business Customer about Authorized User | Provided to grant platform access, issue cards, manage permissions, and meet legal obligations; Business Customers are responsible for ensuring such disclosures are lawful and that required consents have been obtained |
| Third Parties | Identity verification, KYC/KYB, sanctions screening, fraud prevention, and transaction monitoring providers; payment networks, card issuers, sponsor banks; infrastructure and analytics providers; public or government sources where permitted by law |
| Automatically collected | Technical and usage data via cookies and similar technologies |
6. PURPOSES AND LEGAL BASIS FOR PROCESSING
All purposes are identified at or before the time of collection, in accordance with PIPEDA’s Identifying Purposes principle. Personal Information is not used for purposes incompatible with the original reason it was collected. Where a new purpose arises, it will be identified and any required consent obtained before proceeding.
Under Canadian privacy law, consent is the default legal basis for all processing. Where a specific PIPEDA s.7 exemption applies, this is noted explicitly below. There is no “legitimate interest” or “contract performance” basis under PIPEDA or applicable provincial legislation.
| Purpose | Description | Legal basis |
| Providing Services | Onboarding, account and card management, transaction processing, expense management, and customer support | Consent obtained at onboarding |
| Legal and Regulatory Compliance | FINTRAC reporting, KYC/KYB, OSFI obligations, sanctions compliance, tax and recordkeeping, responding to lawful regulatory requests | Consent not required — PIPEDA s.7(2)(c): collection/use/disclosure required by law |
| Fraud and Security | Transaction monitoring, risk assessments, access controls, and audit logs | Consent not required — PIPEDA s.7(1)(b) / s.7(2)(d): investigation of breach of agreement or contravention of law |
| Service Improvement | Platform analytics, troubleshooting, testing, quality assurance (using de-identified data where feasible) | Implied consent — purpose is obvious from the business relationship, and the information is non-sensitive |
| Communication | Account notifications, operational updates, security alerts, policy changes, support | Consent obtained at onboarding |
| Marketing
(limited) |
Information about Services relevant to an existing relationship, in compliance with CASL; unsubscribe available at any time via each message or privacy@test-domain-partnerway.prod.spendbase.co (actioned within 10 business days) | Express consent (CASL) |
| Aggregated Information | Benchmarking, reporting, and product development using data that does not identify individuals | Consent not required — de-identified data is not Personal Information under PIPEDA |
7. CONSENT TRACKING AND WITHDRAWAL
Spendbase obtains, records, and manages consent in accordance with PIPEDA’s Consent Principle and the OPC’s Guidelines on Obtaining Meaningful Consent.
- Express consent is obtained from Business Customers at onboarding via a signed agreement or equivalent digital acceptance, timestamped and linked to the version of this Privacy Notice in effect at the time.
- Consent is granular when purposes are presented individually, and consent to core Services is never bundled with consent to marketing.
- Implied consent is relied upon only for non-sensitive purposes that are obvious from the business relationship (e.g., service improvement using de-identified data).
For Authorized Users, Spendbase contractually requires Business Customers to confirm that all necessary notifications and consents have been obtained before Authorized User Personal Information is submitted to the platform.
Tracking. Spendbase maintains internal records of processing that document, for each purpose: the legal basis, the date and form of consent, the Privacy Notice version in effect, and any subsequent changes to consent status.
Withdrawal. Consent may be withdrawn at any time by contacting privacy@test-domain-partnerway.prod.spendbase.co. Spendbase will confirm receipt within 5 business days and cease all non-mandatory processing within 15 business days, updating the consent record accordingly. Withdrawal does not affect lawfulness of prior processing, nor does it override legally mandated retention obligations (e.g., FINTRAC, KYC/KYB records).
Commercial Electronic Messages. Where Spendbase sends commercial electronic messages (CEMs), it does so under Canada’s Anti-Spam Legislation (CASL). Spendbase relies on express consent for marketing to new contacts and implied consent for existing Business Customers (valid for 2 years from the last transaction). Each CEM identifies Spendbase as the sender and includes an unsubscribe mechanism; requests submitted to privacy@test-domain-partnerway.prod.spendbase.co are processed within 10 business days. Transactional and operational messages (account alerts, security notices, regulatory disclosures) are not CEMs and are sent regardless of marketing consent.
8. SHARING OF PERSONAL INFORMATION
Spendbase does not sell Personal Information. All sharing is subject to PIPEDA’s Accountability principle and its provincial equivalents. Recipients are contractually required to maintain privacy protections comparable to PIPEDA. Third-party arrangements are governed by contractual safeguards consistent with Spendbase’s obligations under PIPEDA and the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA).
| Recipient | Purpose of sharing |
| Sponsor banks and financial institutions | Account establishment, card issuance, transaction processing, fraud monitoring, and regulatory compliance |
| Service providers and vendors | KYC/KYB, sanctions screening, fraud prevention, payment processing, infrastructure, security, analytics — bound by contract to use data only for specified purposes and maintain PIPEDA-equivalent safeguards |
| Business Customers (as for the Authorized Users) | Account administration, expense management, reporting, and compliance oversight — Spendbase acts on Business Customer instructions |
| Regulators and Law Enforcement Agencies | OSFI, FINTRAC, OPC, CAI, courts, and law enforcement where required or permitted by law — including PCMLTFA reports to FINTRAC without prior notice (see Section 5); consent not required under PIPEDA s.7(3)(c) / s.7(3)(c.2) |
| Corporate Transaction Parties | Merger, acquisition, reorganization, or asset sale — subject to confidentiality protections; consent not required under PIPEDA s.7(2)(b) |
| Analytics providers | Analytics, reporting, and benchmarking — in a form that does not identify individuals; not Personal Information under PIPEDA |
9. ADDITIONAL DISCLOSURES
AML/ATF Information Sharing: Where Spendbase participates in a FINTRAC-approved private-to-private sharing arrangement under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), Personal Information may be shared with other reporting entities under an Office of the Privacy Commissioner of Canada-approved Code of Practice for AML/ATF purposes, without consent as permitted by PIPEDA and the PCMLTFA.
10. PERSONAL INFORMATION RETENTION
Personal Information is retained only as long as necessary to fulfill collection purposes, in accordance with PIPEDA’s Limiting Use, Disclosure, and Retention principle and its provincial equivalents.
Retention periods vary depending on the nature of the Personal Information, the purpose for which it was collected, and applicable legal or regulatory requirements. In the context of financial services, certain records must be retained for minimum periods required by law, including requirements related to anti-money laundering, sanctions compliance, fraud prevention, tax, accounting, and regulatory recordkeeping. Where such obligations apply, Spendbase retains Personal Information for the duration mandated by applicable law or regulatory guidance.
Personal Information relating to Business Customers and Authorized Users is generally retained for the duration of the contractual relationship and, following termination, for a limited period thereafter as necessary to comply with legal obligations, support audits and investigations, resolve disputes, and enforce contractual rights. Where retention is no longer required, Personal Information is securely deleted, anonymized, or de-identified in accordance with applicable policies and technical controls.
Aggregated or de-identified information may be retained for longer periods where permitted by law, as such data does not identify individuals and is used for lawful business purposes such as analytics, reporting, and service improvement.
11. PERSONAL INFORMATION SECURITY & SAFEGUARDS
Spendbase implements and maintains administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, or destruction.
Our security program is risk-based and takes into account the sensitivity of the Personal Information we process, the nature of our services, foreseeable risks, and evolving security threats. Safeguards are regularly reviewed and updated to address changes in technology, regulatory guidance, and operational risk.
Administrative safeguards include policies and procedures governing data access, confidentiality, employee training, incident response, vendor management, and compliance oversight. Access to Personal Information is limited to personnel and service providers who require such access for legitimate business purposes and who are subject to confidentiality and security obligations.
Technical safeguards include measures such as access controls, authentication mechanisms, encryption, logging and monitoring, network security controls, and vulnerability management designed to protect Personal Information during processing, storage, and transmission.
Spendbase also maintains procedures to detect, respond to, and recover from security incidents, including data security incidents involving Personal Information. Where required by applicable law, Spendbase will provide notifications relating to data breaches or security incidents in accordance with applicable legal and regulatory requirements.
While Spendbase takes reasonable and appropriate measures to protect Personal Information, no system or method of transmission can be guaranteed to be completely secure. Business Customers and Authorized Users are responsible for maintaining the confidentiality of their access credentials and for using the services in a secure manner.
12. AUTHORIZED USERS
Spendbase provides its Services to Business Customers and processes Personal Data relating to Authorized Users solely. Authorized Users access the Spendbase platform and related services on behalf of, and subject to the control of, the relevant Business Customer.
Business Customers are responsible for determining which individuals are authorized to access the services, assigning and managing access rights, issuing and revoking credentials, and ensuring that Authorized User information provided to Spendbase is accurate, current, and lawful. Business Customers are also responsible for informing Authorized Users about how their Personal Data is collected, used, and shared in connection with the use of the services, including through internal policies and notices where required by law.
Spendbase processes Authorized User Personal Information in accordance with the instructions of the relevant Business Customer, applicable contractual terms, and applicable law. Business Customers control and determine how Authorized User data is used within their organization, including for expense management, reporting, internal controls, compliance oversight, and employment-related purposes. Spendbase does not control and is not responsible for the internal data practices of Business Customers.
Authorized Users should direct requests relating to access, correction, or deletion of their Personal Information primarily to the Business Customer that authorized their access to the services. Where required by law or contract, Spendbase may assist Business Customers in responding to such requests.
Business Customers are responsible for ensuring that their use of the Services, including their handling of Authorized User data obtained through the platform, complies with applicable employment, privacy, and data protection laws.
13. CROSS-BORDER TRANSFER
Spendbase may transfer Personal Information outside Canada to affiliates, service providers, and banking partners operating in jurisdictions including, but not limited to, the United States and the European Union/EEA. We, as well as our main service providers (for instance, for KYC purposes), store your data on Amazon Web Services (AWS), Google Cloud Platform (GCP), and Hetzner, all of which provide hosting services in the European Union/EEA, namely Luxembourg, Germany, and Finland. Where Personal Data is to be processed in other countries that provide less stringent protection, we ensure the applicability of the relevant cross-border mechanism and assess the target country’s legislation to avoid potential governmental intrusions. Anyway, you should be aware that when personal information is stored or processed in another country, it becomes subject to the laws of that jurisdiction. As a result, it may be accessible to the government, courts, law enforcement agencies, national security agencies, or regulatory authorities of that country.
All transfers are governed by written contracts requiring recipient processors to maintain PIPEDA-comparable protections, use data only for specified purposes, and notify Spendbase of any security incidents. Spendbase remains accountable for transferred Personal Information at all times, consistent with PIPEDA’s Accountability Principle and the OPC’s Guidelines for Processing Personal Data Across Borders (2009). A transfer for processing constitutes a use of Personal Information — not a disclosure — and does not require additional consent, provided data is used solely for the purpose originally collected.
Province-specific notes: Alberta and BC residents may request further details on transfer destinations and applicable safeguards. Should Spendbase extend Services to Quebec, cross-border transfers will be subject to a Privacy Impact Assessment, written agreements incorporating required protective measures, and full compliance with Law 25.
14. YOUR RIGHTS AND CHOICES
To exercise any right, submit a written request to privacy@test-domain-partnerway.prod.spendbase.co. Identity verification may be required before processing. Spendbase will not retaliate against any individual who exercises privacy rights or files a complaint.
| Right | Description | Applicability by province |
| Right to Access | Request Personal Information held by Spendbase, how it has been used or disclosed, and receive it in an understandable form. Response within 30 days (extendable with notice). Nominal fee may apply with advance notice. | All |
| Right to Correction | Request correction of inaccurate, incomplete, or outdated Personal Information. Relevant third parties notified where appropriate. | All |
| Right to Withdraw Consent | Withdraw consent at any time, subject to legal and contractual restrictions (please refer to Section 7 hereunder) | All |
| Right to Deletion | Request deletion where Personal Information is no longer necessary and no legal retention obligation applies. Recognized by the Office of the Privacy Commissioner of Canada as flowing from the right to withdraw consent under PIPEDA. | All |
| Right to Challenge Compliance | Challenge Spendbase’s privacy practices. All complaints are logged, investigated, and responded to. | All |
| Right to Data Portability | Receive Personal Information in a structured, commonly used technological format. | Quebec only |
| Right to De-indexation | Request cessation of dissemination or de-indexation of Personal Information linked to your name online. | Quebec only |
| Right to object to automated decisions | Be informed of and challenge decisions made solely through automated processing. | Quebec only |
Authorized Users should generally direct requests to the Business Customer who authorized their access. Spendbase may, upon the Business Customer’s request, assist in satisfying the respective Authorised Users’ requests. In the event of receipt of any request by Spendbase from the Authorized User directly, Spendbase will do its best to transfer the request without undue delay and/or submit the requested information in the scope permitted by law.
Unresolved complaints may be escalated to the applicable regulator:
| Applicability per province | Name of the regulator | Contact details |
| All Customers | Office of the Privacy Commissioner of Canada | Office of the Privacy Commissioner
of Canada 30 Victoria Street Gatineau, Quebec K1A 1H3 |
| Quebec residents | Commission d’accès à l’information du Québec | 525, boulevard René-Lévesque Est,
bureau 2.36 Québec (Québec) G1R 5S9 Téléphone : 418 528-7741 Télécopieur : 418 529-3102 Numéro sans frais : 1 888 528-7741 |
| Alberta residents | Office of the Information and Privacy Commissioner of Alberta | Office of the Information and Privacy Commissioner (Edmonton). 410-9925 109 Street NW Edmonton AB T5K 2J8 Phone: 780 4226860 http://www.oipc.ab.ca |
| British Columbia residents | Office of the Information and Privacy Commissioner for British Columbia | Office of the Information and Privacy Commissioner for British Columbia
PO Box 9038 Stn. Prov. Govt. Victoria B.C. V8W 9A4 |
15. REGULATORY FRAMEWORK
Where applicable, Spendbase processes Personal Information in compliance with:
-
- The Personal Information Protection and Electronic Documents Act (PIPEDA) and its implementing regulations;
- The 10 Fair Information Principles set out in Schedule 1 of PIPEDA, as overseen by the Office of the Privacy Commissioner of Canada (OPC);
- Canada’s Anti-Spam Legislation (CASL);
- Applicable provincial privacy legislation deemed substantially similar to PIPEDA, including Quebec’s Act respecting the protection of personal information in the private sector (Law 25), Personal Information Protection Act (Alberta PIPA), and Personal Information Protection Act (BC PIPA), where applicable; and
- Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA);
- Contractual obligations with our banking partners and service providers, who are required to provide a comparable level of privacy protection as required under PIPEDA.
Interaction of Laws: Where Quebec Law 25, Alberta PIPA, or BC PIPA apply to Spendbase’s processing activities within those provinces, those laws govern in place of PIPEDA for intra-provincial activities. PIPEDA continues to apply at all times to Spendbase as a federally regulated service provider and to all inter-provincial and international transfers of Personal Information.
16. CHANGES TO THIS PRIVACY NOTICE
Spendbase may update this Privacy Notice from time to time to reflect changes in our practices, services, legal or regulatory requirements, or operational needs. When we make material changes, we will provide notice through the Spendbase platform by updating the “Effective date”.
In the event of significant changes that may impact your utilization of the Services, we will notify you via available means of communication.
17. DEFINITIONS
For purposes of this Privacy Notice, the following terms have the meanings set forth below:
“Authorized User” means an individual, including employees, officers, and authorized cardholders, whom a Business Customer authorizes to access or use the Spendbase services on the Business Customer’s behalf.
“Business Customer” means a legal entity or organization that enters into a contractual relationship with Spendbase for the provision of business-focused financial or payment services.
“Personal Information” means any information that identifies, relates to, describes, or could reasonably be linked to an identified or identifiable individual, as defined under applicable PIPEDA and/or otherwise applicable provincial laws, and as further described in this Privacy Notice.
“Personal Health Information” means any information about an individual’s physical or mental health, health services provided to them, and related information.
“Organisation” is an entity accountable for Personal Information collected and controlled directly through the Spendbase platform and services
“Services” means the Spendbase digital banking, payment, corporate card, and related financial technology services provided to Business Customers.
“Service provider” refers to an organization that collects, uses, or discloses personal information on behalf of another organization
Table of contents
1. INTRODUCTION 2. APPLICABILITY TO THE CUSTOMER 3. ABOUT SPENDBASE 4. PERSONAL INFORMATION WE COLLECT 5. SOURCES OF PERSONAL INFORMATION 6. PURPOSES AND LEGAL BASIS FOR PROCESSING 7. CONSENT TRACKING AND WITHDRAWAL 8. SHARING OF PERSONAL INFORMATION 9. ADDITIONAL DISCLOSURES 10. PERSONAL INFORMATION RETENTION 11. PERSONAL INFORMATION SECURITY & SAFEGUARDS 12. AUTHORIZED USERS 13. CROSS-BORDER TRANSFER 14. YOUR RIGHTS AND CHOICES 15. REGULATORY FRAMEWORK 16. CHANGES TO THIS PRIVACY NOTICE 17. DEFINITIONS