PRIVACY NOTICE

FOR CANADIAN CUSTOMERS ONLY
VERSION 1.1
EFFECTIVE DATE: Jun 30, 2026

1. INTRODUCTION

This document, herein referred to as the “Privacy Notice”, outlines the privacy practices of Spendbase (“We”, “us”, “our”, “Spendbase”) and governs the processing of personal information in connection with the provision of our digital banking, payment, and financial technology services (“Services”) to the Canadian customers (“Customers”) defined below. 

Your continued use of the Services constitutes your acknowledgment of, and agreement to, the privacy practices described in this Privacy Notice. In the event of any concern relating to this Privacy Notice or how we handle your Personal Information, feel free to contact us at:

Privacy Officer, Spendbase Ltd. Attn: Privacy and Compliance Email: privacy@test-domain-partnerway.prod.spendbase.co

Nota bene! As of the Effective date, Spendbase does NOT operate in Quebec. Therefore, a French-language version of this Privacy Notice is not available.

2. APPLICABILITY TO THE CUSTOMER

Spendbase provides business-to-business financial technology services, including corporate card programs and related platform services. All Spendbase accounts are opened and maintained exclusively for business purposes. Therefore, this Privacy Notice applies to Customers, namely: 

  • Business Customers that enter into a contractual relationship with Spendbase, who are treated as commercial entities (“Business Customer”), and
  • Individuals who access or use Spendbase services on behalf of a Business Customer, including employees, officers, and cardholders, who act solely in a business or employment capacity (“Authorized User”)

3. ABOUT SPENDBASE

In accordance with applicable law, Spendbase operates as an Organisation (or an “Enterprise” as defined in Quebec) in relation to Business Customer. Processing of Personal Information of the Authorized Users is fulfilled by Spendbase as Service provider (or an “Agent” as defined in Quebec), acting under the instructions of the Business Customer as Organisation (or an “Enterprise” as defined in Quebec), enshrined in the respective contract.

For detailed information on how it may influence the processing of the Authorized User Personal Information, please refer to Section 12 (AUTHORIZED USERS) herein.

Field Description
Legal name Spendbase Ltd.
Registration No

(Business Number).

727075152TZ0001
Address 222 Somerset Street West, Unit 601, Ottawa, Ontario, K2P2G3, Canada
Website URL
Email corporate@test-domain-partnerway.prod.spendbase.co
Email (privacy matters) privacy@test-domain-partnerway.prod.spendbase.co

4. PERSONAL INFORMATION WE COLLECT

Spendbase collects and processes Personal Information only to the extent necessary to provide Services, comply with applicable legal and regulatory obligations, prevent fraud and misuse, and operate and secure the Spendbase platform.

Depending on the customer definition herein, we collect Personal information as follows:

Category Description Customer
Identity and Contact Information Name, date of birth, address, email (personal and work), phone (work and personal), employment information, government-issued ID (unique identification number), driver’s license number, job title Authorized User
Business Information Legal and trade names, registration and business numbers, tax identifiers, incorporation details, ownership and signatory information Business Customer
Financial Information Account data, corporate card details, transaction history, payment records, expenses, and merchant information Business Customer; Authorized User
Compliance and Risk Information KYC/KYB records, sanctions screening results, fraud monitoring data, dispute and investigation records Business Customer; Authorized User
Authentication and Access Information Credentials, access permissions, role assignments, activity logs Business Customer; Authorized User
Communication Information Customer support inquiries, correspondence, and feedback may be recorded where permitted by law and with appropriate notice Business Customer; Authorized User
Technical and Usage Information Device identifiers, IP address, browser type, access timestamps, interaction data Business Customer; Authorized User

 

All Authorized User Personal Information is processed solely in the context of their professional relationship with the relevant Business Customer. Spendbase does not knowingly collect Personal Information from individuals under 18. For Quebec residents, parental or tutor consent is required for individuals under 14. Aggregated or de-identified data may be used for analytics and service improvement and is not treated as Personal Information. Spendbase does not collect Personal Health Information.

5. SOURCES OF PERSONAL INFORMATION

Spendbase collects Personal Information from a limited number of lawful and transparent sources in connection with the provision of its services to Business Customers and Authorized Users.

Source Description
Business Customer (direct) Provided during onboarding, account setup, and ongoing administration via applications, forms, platform inputs, and communications
Authorized User (direct) Provided when accessing the platform, activating accounts, using corporate cards, submitting expenses, or contacting support
Business Customer about Authorized User Provided to grant platform access, issue cards, manage permissions, and meet legal obligations; Business Customers are responsible for ensuring such disclosures are lawful and that required consents have been obtained
Third Parties Identity verification, KYC/KYB, sanctions screening, fraud prevention, and transaction monitoring providers; payment networks, card issuers, sponsor banks; infrastructure and analytics providers; public or government sources where permitted by law
Automatically collected Technical and usage data via cookies and similar technologies

6. PURPOSES AND LEGAL BASIS FOR PROCESSING

All purposes are identified at or before the time of collection, in accordance with PIPEDA’s Identifying Purposes principle. Personal Information is not used for purposes incompatible with the original reason it was collected. Where a new purpose arises, it will be identified and any required consent obtained before proceeding.

Under Canadian privacy law, consent is the default legal basis for all processing. Where a specific PIPEDA s.7 exemption applies, this is noted explicitly below. There is no “legitimate interest” or “contract performance” basis under PIPEDA or applicable provincial legislation.

Purpose Description Legal basis
Providing Services Onboarding, account and card management, transaction processing, expense management, and customer support Consent obtained at onboarding
Legal and Regulatory Compliance FINTRAC reporting, KYC/KYB, OSFI obligations, sanctions compliance, tax and recordkeeping, responding to lawful regulatory requests Consent not required — PIPEDA s.7(2)(c): collection/use/disclosure required by law
Fraud and Security Transaction monitoring, risk assessments, access controls, and audit logs Consent not required — PIPEDA s.7(1)(b) / s.7(2)(d): investigation of breach of agreement or contravention of law
Service Improvement Platform analytics, troubleshooting, testing, quality assurance (using de-identified data where feasible) Implied consent — purpose is obvious from the business relationship, and the information is non-sensitive
Communication Account notifications, operational updates, security alerts, policy changes, support Consent obtained at onboarding
Marketing

(limited)

Information about Services relevant to an existing relationship, in compliance with CASL; unsubscribe available at any time via each message or privacy@test-domain-partnerway.prod.spendbase.co (actioned within 10 business days) Express consent (CASL)
Aggregated Information Benchmarking, reporting, and product development using data that does not identify individuals Consent not required — de-identified data is not Personal Information under PIPEDA

7. CONSENT TRACKING AND WITHDRAWAL

Spendbase obtains, records, and manages consent in accordance with PIPEDA’s Consent Principle and the OPC’s Guidelines on Obtaining Meaningful Consent.

  • Express consent is obtained from Business Customers at onboarding via a signed agreement or equivalent digital acceptance, timestamped and linked to the version of this Privacy Notice in effect at the time.
  • Consent is granular when purposes are presented individually, and consent to core Services is never bundled with consent to marketing. 
  • Implied consent is relied upon only for non-sensitive purposes that are obvious from the business relationship (e.g., service improvement using de-identified data). 

For Authorized Users, Spendbase contractually requires Business Customers to confirm that all necessary notifications and consents have been obtained before Authorized User Personal Information is submitted to the platform.

Tracking. Spendbase maintains internal records of processing that document, for each purpose: the legal basis, the date and form of consent, the Privacy Notice version in effect, and any subsequent changes to consent status.

Withdrawal. Consent may be withdrawn at any time by contacting privacy@test-domain-partnerway.prod.spendbase.co. Spendbase will confirm receipt within 5 business days and cease all non-mandatory processing within 15 business days, updating the consent record accordingly. Withdrawal does not affect lawfulness of prior processing, nor does it override legally mandated retention obligations (e.g., FINTRAC, KYC/KYB records).

Commercial Electronic Messages. Where Spendbase sends commercial electronic messages (CEMs), it does so under Canada’s Anti-Spam Legislation (CASL). Spendbase relies on express consent for marketing to new contacts and implied consent for existing Business Customers (valid for 2 years from the last transaction). Each CEM identifies Spendbase as the sender and includes an unsubscribe mechanism; requests submitted to privacy@test-domain-partnerway.prod.spendbase.co  are processed within 10 business days. Transactional and operational messages (account alerts, security notices, regulatory disclosures) are not CEMs and are sent regardless of marketing consent.

8. SHARING OF PERSONAL INFORMATION

Spendbase does not sell Personal Information. All sharing is subject to PIPEDA’s Accountability principle and its provincial equivalents. Recipients are contractually required to maintain privacy protections comparable to PIPEDA. Third-party arrangements are governed by contractual safeguards consistent with Spendbase’s obligations under PIPEDA and the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA).

Recipient Purpose of sharing
Sponsor banks and financial institutions Account establishment, card issuance, transaction processing, fraud monitoring, and regulatory compliance
Service providers and vendors KYC/KYB, sanctions screening, fraud prevention, payment processing, infrastructure, security, analytics — bound by contract to use data only for specified purposes and maintain PIPEDA-equivalent safeguards
Business Customers (as for the Authorized Users) Account administration, expense management, reporting, and compliance oversight — Spendbase acts on Business Customer instructions
Regulators and Law Enforcement Agencies OSFI, FINTRAC, OPC, CAI, courts, and law enforcement where required or permitted by law — including PCMLTFA reports to FINTRAC without prior notice (see Section 5); consent not required under PIPEDA s.7(3)(c) / s.7(3)(c.2)
Corporate Transaction Parties Merger, acquisition, reorganization, or asset sale — subject to confidentiality protections; consent not required under PIPEDA s.7(2)(b)
Analytics providers Analytics, reporting, and benchmarking — in a form that does not identify individuals; not Personal Information under PIPEDA

9. ADDITIONAL DISCLOSURES

AML/ATF Information Sharing: Where Spendbase participates in a FINTRAC-approved private-to-private sharing arrangement under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), Personal Information may be shared with other reporting entities under an Office of the Privacy Commissioner of Canada-approved Code of Practice for AML/ATF purposes, without consent as permitted by PIPEDA and the PCMLTFA.

10. PERSONAL INFORMATION RETENTION

Personal Information is retained only as long as necessary to fulfill collection purposes, in accordance with PIPEDA’s Limiting Use, Disclosure, and Retention principle and its provincial equivalents.

Retention periods vary depending on the nature of the Personal Information, the purpose for which it was collected, and applicable legal or regulatory requirements. In the context of financial services, certain records must be retained for minimum periods required by law, including requirements related to anti-money laundering, sanctions compliance, fraud prevention, tax, accounting, and regulatory recordkeeping. Where such obligations apply, Spendbase retains Personal Information for the duration mandated by applicable law or regulatory guidance.

Personal Information relating to Business Customers and Authorized Users is generally retained for the duration of the contractual relationship and, following termination, for a limited period thereafter as necessary to comply with legal obligations, support audits and investigations, resolve disputes, and enforce contractual rights. Where retention is no longer required, Personal Information is securely deleted, anonymized, or de-identified in accordance with applicable policies and technical controls.

Aggregated or de-identified information may be retained for longer periods where permitted by law, as such data does not identify individuals and is used for lawful business purposes such as analytics, reporting, and service improvement.

11. PERSONAL INFORMATION SECURITY & SAFEGUARDS

Spendbase implements and maintains administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, or destruction.

Our security program is risk-based and takes into account the sensitivity of the Personal Information we process, the nature of our services, foreseeable risks, and evolving security threats. Safeguards are regularly reviewed and updated to address changes in technology, regulatory guidance, and operational risk.

Administrative safeguards include policies and procedures governing data access, confidentiality, employee training, incident response, vendor management, and compliance oversight. Access to Personal Information is limited to personnel and service providers who require such access for legitimate business purposes and who are subject to confidentiality and security obligations.

Technical safeguards include measures such as access controls, authentication mechanisms, encryption, logging and monitoring, network security controls, and vulnerability management designed to protect Personal Information during processing, storage, and transmission.

Spendbase also maintains procedures to detect, respond to, and recover from security incidents, including data security incidents involving Personal Information. Where required by applicable law, Spendbase will provide notifications relating to data breaches or security incidents in accordance with applicable legal and regulatory requirements.

While Spendbase takes reasonable and appropriate measures to protect Personal Information, no system or method of transmission can be guaranteed to be completely secure. Business Customers and Authorized Users are responsible for maintaining the confidentiality of their access credentials and for using the services in a secure manner.

12. AUTHORIZED USERS

Spendbase provides its Services to Business Customers and processes Personal Data relating to Authorized Users solely. Authorized Users access the Spendbase platform and related services on behalf of, and subject to the control of, the relevant Business Customer.

Business Customers are responsible for determining which individuals are authorized to access the services, assigning and managing access rights, issuing and revoking credentials, and ensuring that Authorized User information provided to Spendbase is accurate, current, and lawful. Business Customers are also responsible for informing Authorized Users about how their Personal Data is collected, used, and shared in connection with the use of the services, including through internal policies and notices where required by law.

Spendbase processes Authorized User Personal Information in accordance with the instructions of the relevant Business Customer, applicable contractual terms, and applicable law. Business Customers control and determine how Authorized User data is used within their organization, including for expense management, reporting, internal controls, compliance oversight, and employment-related purposes. Spendbase does not control and is not responsible for the internal data practices of Business Customers.

Authorized Users should direct requests relating to access, correction, or deletion of their Personal Information primarily to the Business Customer that authorized their access to the services. Where required by law or contract, Spendbase may assist Business Customers in responding to such requests.

Business Customers are responsible for ensuring that their use of the Services, including their handling of Authorized User data obtained through the platform, complies with applicable employment, privacy, and data protection laws.

13. CROSS-BORDER TRANSFER

Spendbase may transfer Personal Information outside Canada to affiliates, service providers, and banking partners operating in jurisdictions including, but not limited to, the United States and the European Union/EEA. We, as well as our main service providers (for instance, for KYC purposes), store your data on Amazon Web Services (AWS), Google Cloud Platform (GCP), and Hetzner, all of which provide hosting services in the European Union/EEA, namely Luxembourg, Germany, and Finland. Where Personal Data is to be processed in other countries that provide less stringent protection, we ensure the applicability of the relevant cross-border mechanism and assess the target country’s legislation to avoid potential governmental intrusions. Anyway, you should be aware that when personal information is stored or processed in another country, it becomes subject to the laws of that jurisdiction. As a result, it may be accessible to the government, courts, law enforcement agencies, national security agencies, or regulatory authorities of that country.

All transfers are governed by written contracts requiring recipient processors to maintain PIPEDA-comparable protections, use data only for specified purposes, and notify Spendbase of any security incidents. Spendbase remains accountable for transferred Personal Information at all times, consistent with PIPEDA’s Accountability Principle and the OPC’s Guidelines for Processing Personal Data Across Borders (2009). A transfer for processing constitutes a use of Personal Information — not a disclosure — and does not require additional consent, provided data is used solely for the purpose originally collected.

Province-specific notes: Alberta and BC residents may request further details on transfer destinations and applicable safeguards. Should Spendbase extend Services to Quebec, cross-border transfers will be subject to a Privacy Impact Assessment, written agreements incorporating required protective measures, and full compliance with Law 25.

14. YOUR RIGHTS AND CHOICES

To exercise any right, submit a written request to privacy@test-domain-partnerway.prod.spendbase.co. Identity verification may be required before processing. Spendbase will not retaliate against any individual who exercises privacy rights or files a complaint.

Right Description Applicability by province
Right to Access Request Personal Information held by Spendbase, how it has been used or disclosed, and receive it in an understandable form. Response within 30 days (extendable with notice). Nominal fee may apply with advance notice. All
Right to Correction Request correction of inaccurate, incomplete, or outdated Personal Information. Relevant third parties notified where appropriate. All
Right to Withdraw Consent Withdraw consent at any time, subject to legal and contractual restrictions (please refer to Section 7 hereunder) All
Right to Deletion Request deletion where Personal Information is no longer necessary and no legal retention obligation applies. Recognized by the Office of the Privacy Commissioner of Canada as flowing from the right to withdraw consent under PIPEDA. All
Right to Challenge Compliance Challenge Spendbase’s privacy practices. All complaints are logged, investigated, and responded to. All
Right to Data Portability Receive Personal Information in a structured, commonly used technological format. Quebec only
Right to De-indexation Request cessation of dissemination or de-indexation of Personal Information linked to your name online. Quebec only
Right to object to automated decisions Be informed of and challenge decisions made solely through automated processing. Quebec only

 

Authorized Users should generally direct requests to the Business Customer who authorized their access. Spendbase may, upon the Business Customer’s request, assist in satisfying the respective Authorised Users’ requests. In the event of receipt of any request by Spendbase from the Authorized User directly, Spendbase will do its best to transfer the request without undue delay and/or submit the requested information in the scope permitted by law.

Unresolved complaints may be escalated to the applicable regulator:

Applicability per province Name of the regulator Contact details
All Customers Office of the Privacy Commissioner of Canada Office of the Privacy Commissioner

of Canada

30 Victoria Street

Gatineau, Quebec

K1A 1H3

www.priv.gc.ca 

Quebec residents Commission d’accès à l’information du Québec 525, boulevard René-Lévesque Est, 

bureau 2.36 

Québec (Québec)  G1R 5S9

Téléphone : 418 528-7741

Télécopieur : 418 529-3102

Numéro sans frais : 1 888 528-7741

www.cai.gouv.qc.ca 

Alberta residents Office of the Information and Privacy Commissioner of Alberta Office of the Information and Privacy Commissioner (Edmonton). 410-9925 109 Street NW Edmonton AB T5K 2J8 Phone: 780 4226860

http://www.oipc.ab.ca  
British Columbia residents Office of the Information and Privacy Commissioner for British Columbia Office of the Information and Privacy Commissioner for British Columbia

PO Box 9038 Stn. Prov. Govt.

Victoria B.C. V8W 9A4  


www.oipc.bc.ca 

15. REGULATORY FRAMEWORK

Where applicable, Spendbase processes Personal Information in compliance with:

    • The Personal Information Protection and Electronic Documents Act (PIPEDA) and its implementing regulations;
    • The 10 Fair Information Principles set out in Schedule 1 of PIPEDA, as overseen by the Office of the Privacy Commissioner of Canada (OPC);
    • Canada’s Anti-Spam Legislation (CASL);
    • Applicable provincial privacy legislation deemed substantially similar to PIPEDA, including Quebec’s Act respecting the protection of personal information in the private sector (Law 25), Personal Information Protection Act (Alberta PIPA), and Personal Information Protection Act (BC PIPA), where applicable; and
  • Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA);
  • Contractual obligations with our banking partners and service providers, who are required to provide a comparable level of privacy protection as required under PIPEDA.

Interaction of Laws: Where Quebec Law 25, Alberta PIPA, or BC PIPA apply to Spendbase’s processing activities within those provinces, those laws govern in place of PIPEDA for intra-provincial activities. PIPEDA continues to apply at all times to Spendbase as a federally regulated service provider and to all inter-provincial and international transfers of Personal Information.

16. CHANGES TO THIS PRIVACY NOTICE

Spendbase may update this Privacy Notice from time to time to reflect changes in our practices, services, legal or regulatory requirements, or operational needs. When we make material changes, we will provide notice through the Spendbase platform by updating the “Effective date”.

In the event of significant changes that may impact your utilization of the Services, we will notify you via available means of communication.

17. DEFINITIONS

For purposes of this Privacy Notice, the following terms have the meanings set forth below:

Authorized User” means an individual, including employees, officers, and authorized cardholders, whom a Business Customer authorizes to access or use the Spendbase services on the Business Customer’s behalf.

Business Customer” means a legal entity or organization that enters into a contractual relationship with Spendbase for the provision of business-focused financial or payment services.

Personal Information” means any information that identifies, relates to, describes, or could reasonably be linked to an identified or identifiable individual, as defined under applicable PIPEDA and/or otherwise applicable provincial laws, and as further described in this Privacy Notice.

“Personal Health Information” means any information about an individual’s physical or mental health, health services provided to them, and related information.

Organisation” is an entity accountable for Personal Information collected and controlled directly through the Spendbase platform and services

Services” means the Spendbase digital banking, payment, corporate card, and related financial technology services provided to Business Customers.

Service provider” refers to an organization that collects, uses, or discloses personal information on behalf of another organization