Finvari Privacy Policy
Last Updated: Sept 3, 2026
You can find Sutton Bank’s Privacy Policy here.
This Privacy Policy (this “Policy”) describes how Finvari, Inc. (“Finvari,” “we,” “our,” or “us”) collects, uses, discloses, and otherwise processes information about individuals and business customers when you interact with our Services, visit our website (www.finvari.com) or our mobile application (together the “Website”), or otherwise engage with our business. References to “you” and “your” in this Policy refer to the individual or Company interacting with our Services or Website, as the context requires. Finvari’s Services are designed for use by business customers (“Companies”) and are not intended for personal, family, or household use.
In providing our corporate card and expense management and other services, we collect and process both Personal Data (information relating to individuals) and Company Data (information relating to or generated by the business entity itself). This Policy governs our treatment of both categories of data. Except where the context requires otherwise (for example, provisions that by their nature apply only to individuals, such as those addressing children's data or individual statutory privacy rights), references in this Policy to Personal Data are deemed to include associated Company Data, and references to Company Data are deemed to include associated Personal Data. Capitalized terms not defined in this Policy have the meanings provided in Section 15 (Defined Terms) or in the Agreement. In the event of any ambiguity or conflict between this Policy and the Agreement, the terms of this Policy shall prevail with respect to the collection, use, disclosure, retention, and protection of Personal Data and Company Data. In all other respects, the order of precedence set forth in the Agreement shall control.
When you access or use our Services, you acknowledge that you have read this Privacy Policy and understand its contents. Please read this Policy carefully, as it applies when you use our Services or visit our Website. In connection with the provision of specific Services, we may provide additional disclosures or information about our data processing practices. These notices may supplement this Privacy Policy or provide you with additional choices about how Finvari processes your Personal Data and/or Company Data.
Applicability. This Privacy Policy applies to the Personal Data and Company Data we collect and process when you: (a) visit, interact with, or use our Website and/or Services; (b) create or administer your Finvari Business Account; (c) receive communications from, or otherwise interact or communicate with us, including, but not limited to, via email, phone, or mail; or (d) register or take part in our marketing or training events. Because Finvari does not maintain a separate Data Processing Addendum with its business customers, this Policy constitutes the primary governing document for the collection, use, retention, and protection of both Personal Data and Company Data in connection with the Services. This Privacy Policy does not apply to: (i) any Personal Data we collect or process in our capacity as an employer; or (ii) any Third-Party Services, which are governed by those third parties’ own privacy policies.
- Information We Collect
- Business Contact Information, such as your name, address, phone number, email address, employer, and job title.
- Identity Verification and Risk Information, such as social security number, date of birth, driver’s license, passport or other government-issued identification, and any other information required to comply with our Know-Your-Customer (“KYC”), anti-money laundering (“AML”), and other regulatory obligations.
- Account Information, such as usernames, credit card and bank account information, tax identifiers, and other authentication and security credential information.
- Transaction Data, including, but not limited to, information associated with your payments, reimbursements, invoices and card transactions made through your Company’s Finvari Business Account such as purchase details, payment mechanism, amount, location, and any annotations or coding you provide.
- Linked Data, including, but not limited to, information and documentation relating to you and your Company made available by third-party services connected to the Services (e.g., ERP accounting system, business bank accounts, and accounts payable system). For example, if you link business bank accounts, we will receive bank routing and account numbers and account balance information. We may continue to access and receive Linked Data from a third-party service until it is disconnected by you or your Company.
- Spend and Workflow Data, including, but not limited to, your Company’s spend limits and policies, approval hierarchies, and finance workflows.
- Receipt and Invoice Data, including, but not limited to, information you submit to us to pay Company invoices and process your receipts, such as photos, PDFs, and the contents of emails and SMS messages along with associated metadata.
- Vendor Data, including, but not limited to, the identity of your Company’s vendors and their contact information, payment details, contracts and purchase orders, and information to complete tax documentation (e.g., the vendor’s tax identification number).
- Communications, including, but not limited to, when contacting sales, support, or implementation teams, asking a question, providing product feedback, or corresponding with our business teams.
- Third-Party Information, including, but not limited to, Personal Data and/or Company Data you provide about any co-workers, contractors, vendors, or potential referrals, such as their business contact information.
- Usage and Interaction Information, including, but not limited to, the pages or content you visit, the features you interact with, how much time you spend on particular pages, page response times, download errors, page interaction information (such as scrolling, clicks, and mouse-overs), your preferences or selections, and your referring and exiting pages.
- Device Data, including, but not limited to, information about the type of device or browser you use, your device’s operating system and settings, your internet service provider, IP address, access dates and times, and device identifiers.
- Inferred Location Information. We may derive your approximate location from your IP address or business information. We may also collect precise geolocation data.
- Cookie and Tracking Technology Data, including, but not limited to, information contained in cookies and similar tracking technologies. For more information about our use of cookies, please see Section 7 (Cookies).
- Inferences and AI-Derived Data. We may derive inferences about you from the Personal Data we collect, including, but not limited to, through the use of automated systems such as artificial intelligence and machine learning. These inferences may relate to your predicted characteristics, preferences, spending patterns, risk profile, or other attributes relevant to the Services.
- Financial Institution Partners, such as banks (e.g., the bank issuing your Company’s card), card networks, payment processors, and other entities that provide or support delivery of Services.
- Identity Verification, Fraud and Compliance Monitoring, and Financial and Business Information Providers, which may help us supplement our understanding of your Company and its personnel, maintain security, prevent fraud, and comply with regulatory and contractual obligations.
- Vendors and Service Providers, which help us operate our business and which may collect and process Personal Data and/or Company Data depending on the services they provide.
- Publicly Available Sources, including, but not limited to, information in the public domain that helps us identify potential customers and partners or conduct due diligence and risk management.
- Company Financial Information, such as business bank account details, revenue and financial performance data, credit history, balance information, and other financial data provided during the application, underwriting, or account management process.
- Transaction Records, including, but not limited to, spend totals, category breakdowns, vendor payment histories, discounts, budget utilization metrics, and other transaction data at the business entity level, rather than attributed to individual Authorized Users.
- Organizational Data, including, but not limited to, Company structure, department and cost center configurations, approval workflows, spend policy rules, role hierarchies, and other organizational information used to configure and operate the Services.
- Business Account Information, including, but not limited to Finvari Business Account configuration, billing information, service and product tiers and usage, feature settings, API credentials, and integration configurations.
- Tax and Regulatory Documentation, including, but not limited to, business tax identification numbers (EIN/TIN), W-9 forms, 1099 reporting data, and other documentation required for regulatory compliance and tax reporting at the entity level.
- How We Use Information
- Providing and Maintaining Our Services. To provide, operate, and manage our Services, perform customer validation, enable you to use Cards and other payment tools, verify financial information to establish spend limits, process transactions, and analyze and monitor usage and activities.
- Communicating with You. To communicate with you about our Services, send you notices, updates, security alerts, and information regarding changes to our policies and terms, and to respond to your requests, support inquiries, and feedback.
- Detecting, Preventing, and Responding to Fraud and Security Incidents. To maintain the safety and security of our business and Services, and to manage risk, including, but not limited to, investigating suspicious activity, detecting and preventing potential security incidents or fraudulent or unauthorized transactions, breaches of policies and terms, and threats of harm, including, but not limited to, in an automated fashion.
- Automated Processing and Artificial Intelligence. We use automated systems, including, but not limited to, artificial intelligence (“AI”) and machine learning technologies, to help us provide, improve, and secure the Services. These automated systems may be used to detect and prevent fraud, assess risk, establish or adjust spend limits, categorize transactions, flag potential policy violations, assist with customer support inquiries, and perform other functions in connection with the Services. Some of these automated processes may produce decisions or outputs that affect you or your use of the Services. Where required by applicable law, you may have the right to opt out of certain automated processing or to request human review of an automated decision; see Section 6 (Your Rights and Choices) for more information.
- Recommendations and Personalization. To recommend Services or features that may be of interest to you or your Company, identify your preferences, and personalize your experience with the Services, including, but not limited to, through the use of automated systems.
- Complying with Legal Obligations and Enforcing Our Rights. To fulfill legal, regulatory, and contractual obligations, including, but not limited to, cooperating with government authorities and regulators, maintaining records required by applicable law (such as financial regulations and the Bank Secrecy Act (“BSA”)), and protecting and enforcing our legal rights.
- Measuring, Troubleshooting, and Improving Our Services. To maintain, improve, and develop our Services, including, but not limited to, by measuring use, analyzing performance, addressing technical issues, expanding our products and operations, and developing and training models by analyzing how you use features, the documentation you submit, and information associated with your transactions.
- Advertising and Marketing. To develop, send, and measure advertising and marketing communications about our products, promotions, events, and Services. We may also use Personal Data and/or Company Data to administer referral programs, surveys, contests, or other promotional activities. See Section 6 (Your Rights and Choices) below for your opt-out options.
- Generating and Analyzing De-Identified Data. To create De-Identified Data, including, but not limited to, for the purpose of developing and improving AI and machine learning models. We may use De-Identified Data for any purpose permitted by law including, but not limited to, to create, publish, and distribute economic indices, benchmarks, data products, and statistical analyses derived from De-Identified Data.
- At Your Direction. To fulfill any other purpose at your direction, including, but not limited to, as expressed through your or your Company’s use of Services functionality.
- With Notice to You and Your Consent. We may otherwise use Personal Data we collect after providing notice to you and obtaining your consent for specific purposes communicated to you.
- How We Share Information
- Service Providers. We engage third-party companies to perform functions on our behalf, such as cloud infrastructure, website hosting, analytics, payment processing, advertising, technical support, security, and debugging. We contractually prohibit our service providers from using Personal Data for any purpose other than performing services for us, although we may permit them to use De-Identified Data subject to applicable law.
- Affiliates. We may share your Personal Data with our affiliates in accordance with this Privacy Policy.
- Business Customers. We disclose Personal Data to your Company to provide Services on its behalf, including, but not limited to, to process transactions, report on account usage, respond to inquiries, and comply with the law. Your Company may assign different roles to Authorized Users with varying permissions, and we will disclose relevant account activity to other Authorized Users within your Company (e.g., finance department members or managers). Each Company is an independent entity whose processing of Personal Data is subject to its own policies.
- Financial Institution Partners. We disclose Personal Data to Financial Institution Partners (such as banks, card networks, and payment processors) to support customer identification, risk and compliance programs, and to enable them to determine eligibility for and deliver products and services to your Company. This may include your name, contact information, date of birth, social security number, and government-issued identification.
- Credit Reporting Agencies. We may disclose Personal Data about your Company and its Finvari Business Account to credit reporting agencies to verify information about your Company and to report on your Company’s account performance. While this information is generally about the Company, it may include Personal Data.
- Security, Fraud Detection, and Compelled Disclosure. We disclose Personal Data to comply with law, regulations, payment network rules, or legal process; to investigate suspicious or fraudulent activity; in response to lawful requests by regulators, law enforcement, and public authorities (including, but not limited to, for national security or anti-money laundering purposes); and to verify identities and perform other compliance functions. We also disclose Personal Data as necessary to protect the rights, property, safety, and security of us, our Services, and others.
- Marketing and Advertising. We disclose Personal Data to vendors, platforms, analytics providers, and other parties for marketing and advertising-related purposes. If you connect your bank account to your Company’s Finvari Business Account, we will not disclose your bank account information to market our business on advertising platforms.
- Mergers and Acquisitions. If Finvari goes through a business transition, such as a merger, acquisition, or sale of all or a portion of its businesses, services, or assets, your Personal Data may be among the assets transferred. In accordance with applicable laws, we will use reasonable efforts to notify you of any transfer of Personal Data to an unaffiliated third party.
- At Your Request. We may share Personal Data at your request or direction, including, but not limited to, as expressed through your or your Company’s use of Services functionality.
- As Permitted By Law. We may disclose non-identifying information (including, but not limited to, De-Identified Data) for any purpose except as prohibited by law. For information on your rights regarding sharing, see Section 6 (Your Rights and Choices).
- Sharing of Company Data. We disclose Company Data to the categories of recipients described above to the extent necessary to provide the Services and for the purposes set out in Section 2 (How We Use Information). We do not disclose a Company’s confidential business information (including, but not limited to, Company financial information and organizational data) to other Companies or unaffiliated third parties for those third parties’ own commercial benefit, except: (a) De-Identified Data; (b) to service providers bound by contractual obligations of confidentiality; (c) to Financial Institution Partners as necessary to provide the Services; (d) as required by law, regulation, or legal process; or (e) with the Company’s prior consent.
- Data Retention
- Security
- Your Rights and Choices
- Region-Specific Rights. Depending on your location and subject to applicable law, you may have certain rights regarding your Personal Data, as described further below. In addition, irrespective of your location, you have choices about the collection and use of your Personal Data. You can choose not to provide certain information, but then you might not be able to take advantage of certain Services.
- Company Finvari Business Account. Finvari Services are intended for use by business customers, and you may only use a Finvari Business Account if you are an Authorized User of a Company that has opened a Finvari Business Account. The Personal Data and Company Data in a Company’s Finvari Business Account is governed by this Policy and our Agreement with the Company. You should direct questions about data we are processing on behalf of a Company to that Company’s administrators. If you are an Authorized User, you may also be able to access, update, or delete certain Personal Data within your Company’s Finvari Business Account through the Services, provided that the Company and its administrators are responsible for determining how that data is processed. For Company Data rights, including, but not limited to, access, export, correction, and deletion, see Company Data Rights below.
- Marketing Communications. You can opt out of receiving promotional emails from us at any time by following the instructions provided in emails to click on the unsubscribe link. Please note that you cannot opt out of non-promotional emails, such as those about your Company’s Finvari Business Account, transactions, servicing, or our ongoing business relations. If you have opted in to receiving text or SMS messages related to your use of the Services, you can opt out at any time by texting “STOP” to the short code.
- Cookies and Tracking Technologies. You can instruct your browser or device to decline or delete cookies. Please be aware that disabling tracking technologies may impair functionality of our Services and Website. For more details, see Section 7 (Cookies). Your browser may transmit a “Do Not Track” signal; however, we do not currently monitor or respond to such signals, as there is no industry consensus on their implementation.
- Analytics and Interest-Based Advertising. We use analytics services and work with ad networks and other technology services to place advertisements on our behalf on third-party websites and services. You may opt out of online behavioral advertising through the Network Advertising Initiative (https://www.networkadvertising.org/choices), the Digital Advertising Alliance (https://www.aboutads.info/choices), or Google’s opt-out tools at https://tools.google.com/dlpage/gaoptout. Opting out means that participating companies should no longer deliver certain targeted ads to you, but you may still receive other advertising.
- Profiling and Automated Decision-Making. As described in Section 2 (How We Use Information), we use automated systems, including, but not limited to, AI and machine learning, to process Personal Data for certain purposes such as fraud detection, risk assessment, transaction categorization, and personalization. Some of these activities may constitute “profiling” under applicable state privacy laws. Under the laws of certain states, you have the right to opt out of profiling that produces legal or similarly significant effects concerning you. To exercise this right, please submit a request to privacy@finvari.com. If you opt out of certain automated processing, some AI-enhanced features of the Services may be limited or unavailable to you. Where Finvari uses automated systems to make or materially assist with decisions that may have a significant effect on you (such as spend-limit determinations), you may request information about the logic involved and, where required by applicable law, request human review of the decision.
- Ownership. As between Finvari and the Company, the Company retains all right, title, and interest in and to its Company Data. Finvari’s right to use Company Data is limited to the purposes described in this Policy and the Agreement. Nothing in this Policy transfers ownership of Company Data to Finvari.
- Access and Export. Companies may access their Company Data through the Services during the term of the Agreement. Upon written request and subject to technical feasibility, Finvari will provide the Company with an export of its Company Data in a commonly used electronic format within a commercially reasonable timeframe.
- Correction. Companies may request corrections or updates to their Company Data through the Services or by contacting us at privacy@finvari.com. Finvari will review such requests within a commercially reasonable timeframe.
- Deletion and Return. Upon termination or expiration of the Agreement, and subject to any applicable regulatory or contractual retention obligations (including, but not limited to, Gramm-Leach-Bliley Act (“GLBA”), BSA/AML, and tax recordkeeping requirements), Finvari will delete or return Company Data to the Company within ninety (90) days of the Company’s written request. Finvari may retain Company Data to the extent required by applicable law or regulation or bona fide archival policies, and any retained data will continue to be protected in accordance with this Policy.
- AI Opt-Out for Company Data. Companies may request that their Company Data be excluded from use in AI model training by submitting a written request to privacy@finvari.com. Upon receipt of a valid request, Finvari will exclude the requesting Company’s identifiable Company Data from future AI model training within a commercially reasonable timeframe. This opt-out does not apply to: (a) De-Identified Data; (b) data retention required by applicable law or regulation; or (c) AI processing that is integral to the delivery of the Services (such as fraud detection, auto coding and routing and risk assessment), which the Company may not opt out of while using the Services.
- Cookies
- Children’s Privacy
- Changes to this Privacy Policy
- Contact Us
- Additional Disclosures for California Residents
- Notice of Collection. The California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) provides additional rights and requires businesses collecting or disclosing Personal Data to provide notices and means to exercise those rights. In the past 12 months, we have collected the following categories of Personal Data enumerated in the CCPA: Identifiers, including, but not limited to, name, postal address, email address, and online identifiers (such as IP address), social security number, driver’s license number, passport number, or other similar identifiers; Customer records, including, but not limited to, phone number, billing address, bank account, and credit or debit card information; Commercial or transaction information, including, but not limited to, records of products or services purchased, obtained, or considered; Internet activity, within the Finvari ecosystem including, but not limited to, browsing history, search history, and interactions with the Website and emails; Inferred location information; Employment information; and Inferences drawn from the above information about your predicted characteristics and preferences. We collect and use these categories of Personal Data for the business purposes described in Section 2 (How We Use Information) above. We disclose Personal Data to the categories of persons set out in Section 3 (How We Share Information) above.
- Right to Know, Correct, and Delete. You have the right to know certain details about our data practices. In particular, you may request the following from us: the categories of Personal Data we have collected about you; the categories of sources from which the Personal Data was collected; the categories of Personal Data about you we disclosed for a business purpose or sold or shared; the categories of persons to whom the Personal Data was disclosed for a business purpose or sold or shared; the business or commercial purpose for collecting or selling or sharing the Personal Data; and the specific pieces of Personal Data we have collected about you. In addition, subject to exceptions, you have the right to correct or delete the Personal Data we have collected from you. To exercise any of your rights, please submit a request to privacy@finvari.com. We will confirm receipt of your request and respond within the time limits prescribed by law. We may require specific information from you to help us verify your identity and process your request. If we are unable to verify your identity, we may deny your request. If Personal Data about you has been processed by us as a service provider on behalf of a business customer, please inquire with the business customer directly to exercise your rights.
- Do Not Sell or Share My Personal Data. Our business model is to provide corporate card and expense management services to Companies, not selling Personal Data. However, under the CCPA, some marketing practices, like the disclosure of Website visitor data to obtain targeted ads and analytics to advertise our products and services on third-party sites, may be considered a “share” or “sale.” Under the CCPA, “share” is broadly defined to include the disclosure of Personal Data for cross-context behavioral advertising, and “sale” is broadly defined to include the disclosure of Personal Data for anything of value, even if no money is exchanged. We may “share” or “sell” the following categories of Personal Data for commercial purposes: identifiers, characteristics, commercial or transaction information, internet activity, inferred location information, and inferences drawn. To the extent that our marketing activities constitute a “share” or “sale” of your Personal Data, you can opt out. To opt out, you can modify your cookie choices as described in Section 7 (Cookies) or activate Global Privacy Control (GPC) on your browser or device.
- Retention. The retention practices described in Section 4 above apply to each category of Personal Data we collect about California residents.
- Authorized Agent. You can designate an authorized agent to submit requests on your behalf. However, we may require signed proof of the agent’s permission and verify your identity directly. Requests must be submitted through the designated methods listed above.
- Right to Non-Discrimination. You have the right not to receive discriminatory treatment by us for the exercise of any of your privacy rights.
- Additional Disclosures for Other State Residents
- GLBA Notice
- International Data
- Defined Terms
- “Agreement” means the Finvari Corporate Account Agreement and other terms and addenda governing our provision of Services to a Company.
- “Authorized User” means the administrators, employees, contractors, and agents of a Company who are authorized to access and use the Services.
- “Cards” means physical or virtual payment cards issued by a Financial Institution Partner and managed through your Finvari Business Account.
- “Company” means the company that is applying for or has opened a Finvari Business Account.
- “Company Data” means information that relates to, is generated by, or is associated with a Company as a business entity in connection with the Services, including, but not limited to: business financial information, invoice data, organizational data, account-level configurations, and tax and regulatory documentation, but excluding Personal Data of individual Authorized Users (except where business data includes or is linked to information about identifiable individuals, in which case the data is treated as both Company Data and Personal Data). Note that for purposes of this Policy, Company Data and Personal Data are treated as distinct categories. The Corporate Account Agreement treats equivalent Personal Data as a component of Company Data.
- “De-Identified Data” means data derived from Personal Data, Company Data or otherwise relating to Company or an Authorized User’s use of the Services that has been de-identified, anonymized or aggregated.
- “Financial Institution Partners” means banks, card networks, payment processors, money transmitters, and other entities that provide or support delivery of financial services in connection with the Services.
- “Finvari Business Account” means the top-level account created by the Company with funds available for associating with Cards and the underlying accounts used for such Cards and access to the Services.
- “Personal Data” means data that identifies or could reasonably be used to identify a natural person. “Personal Data” corresponds to “personal information,” “personal data,” and equivalent terms as defined under applicable privacy laws, including the CCPA and the Gramm-Leach-Bliley Act.
- “Services” means the corporate card and expense management services, Cards, and other services provided through your Finvari Business Account or otherwise made available by Finvari.
- “Third-Party Services” means services and data provided by third parties connected to or provided through the Services, which are governed by those third parties’ own privacy policies. Third-Party Services may include, but are not limited to, ERP, accounting or expense management platforms (such as, e.g., QuickBooks, Expensify, Viewpoint, and Sage), payment processors and e-commerce platforms (such as Shopify or Magento), and applications used to monitor linked accounts (such as Plaid or Finicity).
- “Website” means www.finvari.com and our mobile application.
The information we collect depends on the context of your interactions with Finvari, the choices you make, the Services and features you use, and applicable laws. We collect both Personal Data relating to individual Authorized Users and Company Data relating to the business entity. If you provide us with information about another individual, you represent that you have the authority to do so and have obtained all necessary rights and consents to provide such information to us for processing in accordance with this Privacy Policy.
A. Information Provided to Finvari. Finvari Services are intended for use by Companies and their Authorized Users. When applying for a Finvari Business Account, we may receive information about you, your Company, and individuals associated with your Company. Such information includes, but is not limited to:
Providing your Personal Data is optional, but it may be necessary for certain Services, such as account registration. In such cases, if you do not provide your Personal Data, we may not be able to provide you with the requested Services.
B. Information We Collect Automatically. We automatically collect certain types of information when you interact with our Services, such as when you visit our Website or log into your account. We use common information-gathering tools, such as cookies, web beacons, and similar technologies to automatically collect information that may contain Personal Data from your computer or mobile device as you navigate our Services or interact with emails we have sent you. This information includes, but is not limited to:
C. Information We Collect from Other Sources. We collect information about you from other sources, including, but not limited to, partners and service providers from whom we receive business contact information, or who provide us with publicly available information which may contain Personal Data and/or Company Data. We may combine this information with Personal Data and/or Company Data that you provide. We treat the information obtained from other sources in accordance with applicable laws and any contractual obligations applicable to us. Other sources of information include, but are not limited to:
D. Additional Company Data We Collect. In addition to Personal Data about individual Authorized Users, we collect and process Company Data relating to the business entity itself in connection with providing the Services. Company Data includes, but is not limited to:
Company Data may overlap with Personal Data where business data includes or is linked to information about identifiable individuals (e.g., a sole proprietor’s financial records). In such cases, the data is treated as both Company Data and Personal Data, and the protections applicable to each category apply.
We use Personal Data and Company Data for business and commercial purposes in accordance with the practices described in this Policy. Purposes for using information include, but are not limited to:
We may use information that does not identify you for any purpose permitted by law. For information on your rights and choices, see Section 6 (Your Rights and Choices) for more information.
Use of Company Data. In addition to the purposes described above, we use Company Data to provide and maintain the Services, generate financial reports and analytics for your Company, facilitate account underwriting and spend limit assessments, comply with applicable financial regulatory and tax reporting obligations, and improve and develop our products. We will not use Company Data for purposes materially inconsistent with providing the Services unless we have disclosed the purpose in this Policy or obtained the Company’s prior consent. For clarity, use of Company Data for AI model training is subject to the following limitations: (a) where technically feasible, we will use De-Identified Data rather than identified Company Data for model training; (b) AI models trained using Company Data will not disclose one Company’s confidential business information to another Company; and (c) Companies may request that their Company Data be excluded from AI model training by contacting us at privacy@finvari.com, subject to technical feasibility and any applicable regulatory retention obligations.
We share Personal Data and Company Data we collect in accordance with this Privacy Policy. The categories of recipients are:
We retain Personal Data and Company Data for as long as necessary to fulfill the purposes described in this Privacy Policy and to comply with our legal obligations, including, but not limited to, applicable financial regulatory recordkeeping requirements, statutes of limitation, dispute resolution, fraud prevention, and enforcement of our agreements. In determining the appropriate retention period, we consider the nature and sensitivity of the data, the risk of harm from unauthorized disclosure, and applicable legal requirements. Our retention obligations may require us to retain Personal Data and Company Data after you are no longer an Authorized User or your Company’s Finvari Business Account has closed, and may prohibit us from honoring certain deletion requests. When the applicable retention period elapses, we will delete or de-identify your data in accordance with our policies.
Where Personal Data or Company Data is used to develop, train, or improve AI and machine learning models, we may retain such data for the duration necessary to develop, validate, and maintain those models, even if the data would otherwise be eligible for deletion. Trained models that do not contain identifiable Personal Data or attributable Company Data are not subject to individual deletion requests. Where technically feasible, we use De-Identified Data for model training purposes.
We design our systems with your security and privacy in mind. We maintain technical, physical, and organizational safeguards in connection with the collection, storage, and disclosure of Personal Data and Company Data designed to protect your data from loss, theft, misuse, and unauthorized access, disclosure, alteration, or destruction. We protect the security of your Personal Data and/or Company Data during transmission by using encryption protocols and software. We maintain a comprehensive information security program consistent with applicable regulatory requirements, including, but not limited to, the Gramm-Leach-Bliley Act Safeguards Rule. Our security procedures mean that we may request proof of identity before we disclose Personal Data or Company Data to you. However, no security measure or modality of data transmission over the Internet is 100% secure. Although we strive to use commercially acceptable means to protect your Personal Data and/or Company Data, we cannot guarantee absolute security. You are solely responsible for protecting your password, limiting access to your devices, and signing out of websites after your sessions. If you suspect unauthorized activity with respect to your Finvari Business Account or you suspect a security incident has occurred, please contact us immediately at support@finvari.com and take the additional steps set out in the Agreement.
Company Data Rights. Because this Policy serves as the governing document for Company Data in the absence of a separate Data Processing Addendum, Companies have the following rights with respect to their Company Data, subject to applicable law, regulatory requirements, and the terms of the Agreement:
We use cookies and similar technologies to recognize your browser or device, provide our Services, and improve your experience.
What Are Cookies
Cookies are small data files such as pixel tags, web beacons, clear GIFs, mobile identifiers, and JavaScript (collectively, "Cookies") that are placed on your computer or mobile device when you visit a website. Cookies set by the website owner (in this case, Finvari) are called "First Party Cookies". Only the website owner can access the First Party Cookies it sets. Cookies set by parties other than the website owner are called "Third Party Cookies". Third Party Cookies enable third party features or functionality to be provided on or through the Website (e.g. advertising, interactive content and social sharing). The parties that set these Third Party Cookies can recognize your device both when it visits the Website and also when it visits other websites that have partnered with them.
How We Use Cookies and Similar Technologies
The Services use Cookies to enable our servers to recognize your web browser and tell us how and when you visit and use our Services, to analyze trends, learn about our user base, and operate and improve our Services. For example, we use Cookies to tailor the Services by tracking navigation habits, measuring performance, customizing user experiences with the Website and for analytics and fraud prevention. We may also supplement the information we collect from you with information received from third parties, including, but not limited to, information collected using Third Party Cookies.
We use the following types of Cookies:
Essential Cookies. Essential Cookies are required for providing you with features or services that you have requested. For example, certain Cookies enable you to log into secure areas of the Website. Disabling these Cookies may make certain features and services unavailable.
Functional Cookies. Functional Cookies are used to record your choices and settings regarding the Website, maintain your preferences over time and recognize you when you return to the Website. These Cookies help us to personalize our content for you and remember your preferences.
Performance/Analytical Cookies. Performance/Analytical Cookies allow us to understand how visitors use the Website such as by collecting information about the number of visitors to the Website, what pages visitors view on the Website, how long visitors are viewing pages on the Website, mouse clicks, mouse movements, scrolling activity, and text typed into the Website. Performance/Analytical Cookies also help us measure the performance of our advertising campaigns in order to help us improve our campaigns and the Website’s content for those who engage with our advertising.
Retargeting/Advertising Cookies. Retargeting/Advertising Cookies collect data about your online activity and identify your interests so that we can score leads and provide you with web and email content that we believe is relevant to you.
In some cases, we may use Cookies to collect Personal Data or to collect information that becomes Personal Data if we combine it with other information.
How To Control Cookies and Other Technologies
Browser Controls: You can also decide whether or not to accept Cookies through your internet browser’s settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You may also be able to reject mobile device identifiers by activating the appropriate setting on your mobile device. You can also delete all Cookies that are already on your device. Although you are not required to accept Finvari’s Cookies, if you block, reject, or delete them, you may have to manually adjust some preferences every time you visit our Website and some of the Services and functionalities may not work. To explore what Cookie settings are available to you, look in the “preferences” or “options” section of your browser’s menu.
Third Party Cookies: In addition to managing cookies through the methods described above, you can also opt out of certain third-party cookies. For example, we use Google Analytics to help us understand how people use our Services. The reports disclose website trends without identifying individual users. You can opt out of these cookies without affecting your use of the Services. For more information on Google Analytics, see here. If you do not want Google Analytics to be used in your browser, you can also install the Google Analytics browser add-on. In addition, most advertising networks offer you a way to opt out of targeted advertising.
We do not provide our Services to children. We do not knowingly collect Personal Data from children under 18. We also do not knowingly “share” or “sell,” as those terms are defined under applicable state privacy law, the Personal Data of minors under the age of 18. If you are a parent or guardian and believe we have collected Personal Data from your child, please contact us at the address stated under the “Contact Us” section below.
We may update or modify this Privacy Policy at any time. If we make material changes, we will provide reasonable notice before they take effect through our Website, your Company’s Finvari Business Account, or using the contact information you have provided. If we do not have an existing relationship with you, notice will be posted to our Website. Any updated Privacy Policy is effective upon posting or delivery. This Policy was last updated as of the date indicated at the top.
If you have any questions about our Privacy Policy or privacy practices, or if you wish to lodge a complaint about our privacy practices, please contact us:
By email: privacy@finvari.com
By mail: Finvari, Inc., Attn: Privacy, 1100 NE Campus Parkway, Suite 200, Seattle, WA 98195
If you have any questions about Personal Data handled by your Company, please contact your Company’s administrator.
These additional disclosures apply only to California residents and only to the extent applicable.
Residents of states with comprehensive privacy legislation may have the following rights, subject to applicable law and exceptions: (a) to confirm whether or not we are processing your Personal Data; (b) to access your Personal Data; (c) to correct inaccuracies in your Personal Data; (d) to delete your Personal Data; (e) to obtain a copy of your Personal Data in a portable and readily usable format; and (f) to opt out of the processing of Personal Data for purposes of targeted advertising, the sale of Personal Data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. To exercise any of these rights, please submit a request to privacy@finvari.com. If you wish to appeal our decision with respect to a request you have submitted, please contact us at privacy@finvari.com with the subject line “Privacy Request Appeal.”
Nevada Residents. Nevada law (NRS 603A.340) requires each business to establish a designated request address where Nevada consumers may submit requests directing the business not to sell certain kinds of Personal Data. If you are a Nevada consumer and wish to submit a request relating to our compliance with Nevada law, please contact us using the information in the “Contact Us” section above.
Finvari, in partnership with its issuing bank partner (currently Sutton Bank), provides corporate card and expense management services that are subject to the GLBA and its implementing regulations. Under the GLBA, we are required to provide you with notice of our privacy practices with respect to nonpublic personal information (“NPI”). For purposes of GLBA compliance, NPI includes both nonpublic personal information of individuals and nonpublic financial information of business customers that is not publicly available. For the avoidance of doubt, De-Identified Data does not constitute NPI for purposes of the GLBA. The categories of NPI we collect, the purposes for which we use NPI, and the circumstances under which we disclose NPI are described in Sections 1, 2, and 3 of this Privacy Policy. We do not disclose NPI to nonaffiliated third parties except as permitted or required by law, including, but not limited to, to process your transactions, maintain your account, comply with federal, state, or local laws, or as otherwise described in this Privacy Policy. We restrict access to NPI to those employees, service providers, and automated systems (including, but not limited to, AI and machine learning systems) that need access to that information to provide products or services to you or to support our operations. We maintain physical, electronic, and procedural safeguards that comply with applicable federal regulations to guard your NPI, including, but not limited to, safeguards that extend to automated processing systems used in connection with the Services. For additional information about Sutton Bank’s privacy practices, please refer to the Sutton Bank Privacy Policy linked at the top of this Policy.
Our Services are operated from and directed toward Companies in the United States. Personal Data we collect will be stored and processed in the United States. We maintain primary data centers in the United States. If you access our Website or Services from outside the United States, please be aware that your Personal Data will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
Capitalized terms used in this Privacy Policy are defined as follows: