Bilt Commerce Inc. (“we” , “us”, “our”, “Paybilt”) is committed to protecting your privacy. We are a payments technology provider that offers credit card alternatives to businesses for online and in-person transactions. This Privacy Policy (“Policy”) describes our data processing practices and how we handle personal information. Personal information means any information about a directly or indirectly identifiable individual.
This Policy applies to individuals who apply for, use, or otherwise interact with our products and services (“Services”), including: (1) visitors and users of our website; and (2) owners, officers, and employees of companies, such as merchants, software platforms, marketplaces, and payment facilitators (collectively, “Merchants” or “you”). In most instances, Paybilt acts as a “data processor” or “service provider” to Merchants that use our Services. As such:
If you are a shopper, end user, customer, or payee of a Merchant who uses our Services (“Merchant Customer”), then we will process personal information in accordance with the terms of our agreement with the Merchant and in accordance with the Merchant’s instructions. This Policy does not apply to such processing. Please refer to the privacy policy or notice of the Merchant you do business with for information regarding their privacy practices, choices, and controls.
If you are a Merchant, please note that you are responsible for honoring the privacy rights of Merchant Customers and for making appropriate privacy disclosures to Merchant Customers.
This Policy contains important information about your personal rights to privacy. Please read it carefully to understand how we use your personal information. If you do not agree with our policies and practices, your choice is not to use our Services. By using our Services, you agree to our handling of your personal information as set out in this Policy.
2. Obtaining and Withdrawing Your Consent
By providing us with your personal information, you consent to the collection, use, and disclosure of your personal information in accordance with this Policy and as permitted or required by law. If you provide us with the personal information of another individual (for example, the personal information of a Merchant Customer), you represent that you have all necessary authority and/or have obtained all necessary consents from such person to enable us to collect, use, and disclose such personal information for the purposes outlined in this Policy.
Subject to legal and contractual requirements, you may withdraw your consent at any time by writing to us (see Section 16 (Contact Paybilt) below). However, please note that if you withdraw your consent, we may not be able to provide you with certain services or information that may be of value to you.
3. Information We Collect About You
The below table describes the categories of personal information that we collect from you:
Categories of Information
Categories of Information
Categories of Information
Examples
Examples
Examples
Business information
Business information
Business information
Your business name, address, phone number, and email.
Your business name, address, phone number, and email.
Financial information
Financial information
Your bank account information and tax information.
Your bank account information and tax information.
Account information
Account information
If any Services require you to create an account with us, your login credentials.
If any Services require you to create an account with us, your login credentials.
Internet or other electronic network activity information
Internet or other electronic network activity information
Your browsing history, search history, and interactions with a website, email, application, dashboard, or advertisement.
Your browsing history, search history, and interactions with a website, email, application, dashboard, or advertisement.
Device Information
Device Information
When you visit our website, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device.
When you visit our website, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device.
Professional or employment-related information
Professional or employment-related information
If you submit a job application to us, we collect your resume, cover letter, list of references, and employment information.
If you submit a job application to us, we collect your resume, cover letter, list of references, and employment information.
Other information provided by you
Other information provided by you
Other information you voluntarily provide to us, including suggestions for improvements, complaints, comments, and inquiries.
Other information you voluntarily provide to us, including suggestions for improvements, complaints, comments, and inquiries.
Derived or linked information
Derived or linked information
Inferences drawn from the above information about your predicted characteristics and preferences, and other information about you that is linked to the personal information above.
Inferences drawn from the above information about your predicted characteristics and preferences, and other information about you that is linked to the personal information above.
4. Information We Collect About Merchant Customers
We also obtain the information of Merchant Customers that you provide to us or through your use of the Services. It is your responsibility to obtain any necessary consents and permissions required so that we can provide you with the requested Services.
The below table describes the categories of personal information that we collect from Merchant Customers:
Categories of Information
Categories of Information
Categories of Information
Examples
Examples
Examples
Merchant Customer personal information
Merchant Customer personal information
Merchant Customer personal information
Merchant Customers’ names, addresses, phone numbers, and emails.
Merchant Customers’ names, addresses, phone numbers, and emails.
Merchant Customer financial information
Merchant Customer financial information
Merchant Customers’ bank account information and payment card information.
Merchant Customers’ bank account information and payment card information.
Merchant Customer transaction information
Merchant Customer transaction information
When Merchant Customers use Paybilt to make or record payments to you, we collect information about when and where the transactions occur, the names of the transacting parties, and a description of the transactions, which may include item-level data, the payment or transfer amounts, billing and shipping information, and the devices and payment methods used to complete the transaction.
When Merchant Customers use Paybilt to make or record payments to you, we collect information about when and where the transactions occur, the names of the transacting parties, and a description of the transactions, which may include item-level data, the payment or transfer amounts, billing and shipping information, and the devices and payment methods used to complete the transaction.
Merchant Customer internet or other electronic network activity information
Merchant Customer internet or other electronic network activity information
Merchant Customers’ browsing history, search history, and interactions with a website, email, application, dashboard, or advertisement.
Merchant Customers’ browsing history, search history, and interactions with a website, email, application, dashboard, or advertisement.
Merchant Customer technical usage information
Merchant Customer technical usage information
Information about Merchant Customers’ device, including information about their web browser, IP address, time zone, and some of the cookies that are installed on your device.
Information about Merchant Customers’ device, including information about their web browser, IP address, time zone, and some of the cookies that are installed on your device.
Other information provided by Merchant Customers
Other information provided by Merchant Customers
Other information that Merchant Customers voluntarily provide to us, including suggestions for improvements, complaints, comments, and inquiries.
Other information that Merchant Customers voluntarily provide to us, including suggestions for improvements, complaints, comments, and inquiries.
Derived or linked information
Derived or linked information
Inferences drawn from the above information about Merchant Customers’ predicted characteristics and preferences, and other information about Merchant Customers that is linked to the personal information above.
Inferences drawn from the above information about Merchant Customers’ predicted characteristics and preferences, and other information about Merchant Customers that is linked to the personal information above.
5. Sources of Information
We collect information from the following sources:
Source
Source
Source
Description
Description
Description
Directly from you
Directly from you
You may give us information by: (i) applying for or using our Services; (ii) filling in forms; or (iii) by corresponding with us by phone, e-mail, through the website, or otherwise.
You may give us information by: (i) applying for or using our Services; (ii) filling in forms; or (iii) by corresponding with us by phone, e-mail, through the website, or otherwise.
Merchant Platforms
Merchant Platforms
If Merchant Customers access the Services through a software platform, marketplace, payment facilitator, or other business that has an integration with Paybilt (“Merchant Platform”), we receive information about Merchant Customers through the Merchant Platform.
If Merchant Customers access the Services through a software platform, marketplace, payment facilitator, or other business that has an integration with Paybilt (“Merchant Platform”), we receive information about Merchant Customers through the Merchant Platform.
Third parties and other publicly available sources
Third parties and other publicly available sources
We may receive information about you from our service providers, such as companies that manage risk and fraud or market the Services, card networks, payment processors, referral partners, identity verification companies, and from third parties that you have permitted to release information to us. We also may receive information about you from publicly available sources, such as social media platforms.
We may receive information about you from our service providers, such as companies that manage risk and fraud or market the Services, card networks, payment processors, referral partners, identity verification companies, and from third parties that you have permitted to release information to us. We also may receive information about you from publicly available sources, such as social media platforms.
Automated technologies and interactions
Automated technologies and interactions
As you interact with our website, we may automatically collect technical data about your equipment, browsing actions, and patterns. See Section 8(Cookies and Other Technology) below for more details.
As you interact with our website, we may automatically collect technical data about your equipment, browsing actions, and patterns. See Section 8(Cookies and Other Technology) below for more details.
6. Why We Collect Your Information
We use the information we collect about you, or that you provide to us, for the following purposes:
Purpose
Purpose
Purpose
Examples
Examples
Examples
Provide our Services to you
Provide our Services to you
Provide our Services to you
Set up our Services for you, and to provide you with support during the onboarding process, integration, and installation.
Evaluate your application for a merchant or partner account.
Process payments and transactions.
Verify your identity and/or evaluate your eligibility for the Services.
Set up our Services for you, and to provide you with support during the onboarding process, integration, and installation.
Evaluate your application for a merchant or partner account.
Process payments and transactions.
Verify your identity and/or evaluate your eligibility for the Services.
Facilitate your requests
Facilitate your requests
Fulfill the purposes for which you provided the data or that were described when it was collected.
Facilitate requests that you have made, including for electronic content (e.g., newsletters).
Fulfill the purposes for which you provided the data or that were described when it was collected.
Facilitate requests that you have made, including for electronic content (e.g., newsletters).
Manage and improve our Services
Manage and improve our Services
Present, operate, maintain, enhance, and provide all of the features of our Services.
Research, analyze, develop, manage, protect, and improve our Services.
Present, operate, maintain, enhance, and provide all of the features of our Services.
Research, analyze, develop, manage, protect, and improve our Services.
Personalize your experiences
Personalize your experiences
Understand your needs, the suitability of our Services, and assess future needs.
Market, advertise, and promote our Services.
Keep you informed about our Services, including notifying you about updates to our Services.
Understand and analyze the usage trends, behaviours, and preferences of our users to improve the Services and to develop new features and functionality.
Understand your needs, the suitability of our Services, and assess future needs.
Market, advertise, and promote our Services.
Keep you informed about our Services, including notifying you about updates to our Services.
Understand and analyze the usage trends, behaviours, and preferences of our users to improve the Services and to develop new features and functionality.
Communicate with you
Communicate with you
Provide you support, respond to your inquiries, and offer customer service.
Send you notices and updates.
Share new products, offers, promotions, or other information in which you may be interested.
Provide you support, respond to your inquiries, and offer customer service.
Send you notices and updates.
Share new products, offers, promotions, or other information in which you may be interested.
Manage our operational requirements
Manage our operational requirements
Manage our day-to-day organizational and operational needs.
Establish and maintain communication with service providers.
Ensure our website functions properly.
Manage our day-to-day organizational and operational needs.
Establish and maintain communication with service providers.
Ensure our website functions properly.
Compliance and protection
Compliance and protection
Protect our website, employees, or operations.
Prevent or investigate fraud, illegal or prohibited activities, and security issues or breaches (including mitigate denial-of-service attacks to our website).
Enforce our terms and any other agreements between you and us.
Comply with any applicable laws, legal processes, and our contractual obligations.
Protect our website, employees, or operations.
Prevent or investigate fraud, illegal or prohibited activities, and security issues or breaches (including mitigate denial-of-service attacks to our website).
Enforce our terms and any other agreements between you and us.
Comply with any applicable laws, legal processes, and our contractual obligations.
Derived purposes
Derived purposes
Fulfill other purposes related to any of the above.
For any other reason provided to you in connection with our Services.
Fulfill other purposes related to any of the above.
For any other reason provided to you in connection with our Services.
7. When Do We Share Your Information
We may disclose your personal information to third parties in the following circumstances:
Categories
Categories
Categories
Description
Description
Description
Your legal agent or representative
Your legal agent or representative
Your legal agent or representative
We may share your personal information with your legal agent or representative, including a person with a valid power of attorney, or a person appointed by the appropriate government body or court.
We may share your personal information with your legal agent or representative, including a person with a valid power of attorney, or a person appointed by the appropriate government body or court.
Service providers
Service providers
We may share your personal information with the following types of third-party service providers who help us provide, maintain, and improve the Services:
technology providers or potential partners to store information, provide software, or help us provide the Services;
marketing or event providers that help us run our advertising campaigns;
identity verification providers to help us with fraud prevention and to assist us in meeting our anti-money laundering, “know your customer”, background checking, and other compliance requirements;
fee collection service providers to help us enforce our legal rights; and
financial partners, like financial service providers, banks, other financial institutions, payment networks, payment card associations, credit reference agencies, and credit bureaus that help us provide the Services
We may share your personal information with the following types of third-party service providers who help us provide, maintain, and improve the Services:
technology providers or potential partners to store information, provide software, or help us provide the Services;
marketing or event providers that help us run our advertising campaigns;
identity verification providers to help us with fraud prevention and to assist us in meeting our anti-money laundering, “know your customer”, background checking, and other compliance requirements;
fee collection service providers to help us enforce our legal rights; and
financial partners, like financial service providers, banks, other financial institutions, payment networks, payment card associations, credit reference agencies, and credit bureaus that help us provide the Services
Acquiring organizations
Acquiring organizations
Paybilt may share your personal information with an acquiring organization in the event of a proposed or actual purchase (including liquidation, realization, seizure, or repossession), concession, merger, business combination, or any other type of acquisition, liquidation, transfer, transactional contract, or financing of Paybilt in whole or in part or of any property, share, assets, stock, or business of Paybilt. Any surviving entity as a result of such transaction will have the right to use your personal information only in the manner set out in this Policy.
Paybilt may share your personal information with an acquiring organization in the event of a proposed or actual purchase (including liquidation, realization, seizure, or repossession), concession, merger, business combination, or any other type of acquisition, liquidation, transfer, transactional contract, or financing of Paybilt in whole or in part or of any property, share, assets, stock, or business of Paybilt. Any surviving entity as a result of such transaction will have the right to use your personal information only in the manner set out in this Policy.
Law enforcement
Law enforcement
We may share your personal information with law enforcement or third parties to:
comply with any court order, law, or legal process, including responding to any government or regulatory request;
enforce or apply our Terms of Use and other agreements; and
protect the rights, property, or safety of our business, employees, customers, or others. This includes exchanging information with other companies and organizations for cybersecurity, fraud protection, and credit risk reduction.
We may share your personal information with law enforcement or third parties to:
comply with any court order, law, or legal process, including responding to any government or regulatory request;
enforce or apply our Terms of Use and other agreements; and
protect the rights, property, or safety of our business, employees, customers, or others. This includes exchanging information with other companies and organizations for cybersecurity, fraud protection, and credit risk reduction.
Third parties are subject to their own privacy policies which you may be able to review upon a request to the applicable third party.
8. Cookies and Other Technology
Information that is automatically collected
We, and our third-party service providers, may automatically collect information related to your use of our website, apps, and other online resources through cookies and similar tracking technologies. We do not collect personal information that can identify you directly, such as by name, when browsing our website
How we use information gathered from cookies and other technologies
We use cookies and similar technologies to:
Make your website experience personalized and efficient
Understand and improve our digital services and offerings
Cookies
Cookies are small text files that are stored on the browser of your computer that assign an anonymous identifier to your browser and provide information to the cookie sender. Cookies may be placed on your computer by us when you use our website or other digital offerings. You can manage website cookies in your browser setting, and you always have the choice to change these settings by accepting, rejecting, or deleting cookies. Please note that if you disable or delete cookies, the website may not function fully or as intended. For more information on cookies and how to manage them, check the support pages for your browser, such as Firefox, Safari, Chrome, or Internet Explorer.
Google Analytics
We use Google Analytics to better understand your use of our website. Google Analytics collects information on user behaviour on our website, which includes how many times a user visits our website, what pages they visit, and where they were referred from. Google uses the data collected through cookies to track and examine the use of the website, prepare reports on its activities, and share them with other Google services. Advertising identifiers for mobile devices (such as Android and iOS Advertising Identifiers) are also collected. Google may use the data collected on the websites to contextualize and personalize the ads of its advertising network.
Google will not associate your IP address with any other data held by Google. To learn more about Google Analytics, click here. You can deactivate the Google Analytics function with a browser add-on, which you can download here.
9. Cross-Jurisdictional Transfers
By providing your data to us, you acknowledge and agree that your personal information may be transferred to other jurisdictions for processing and storage, including in servers located across Canada and in the United States, where laws regarding the protection of personal information may be less stringent than the laws in your jurisdiction. Further, your personal information may be accessible to law enforcement, national security authorities, and the courts of such jurisdictions. Where necessary to make such transfers, we will comply with our legal and regulatory obligations. If you have any questions about how we may store and process your personal information in other jurisdictions, please contact us (see Section 16 (Contact Paybilt) below).
10. Data Security
The security of your personal information is very important to us. We protect your information by limiting access to your personal information on a strict “need-to-know” basis and we implement reasonable physical, organizational, and technological safeguards as appropriate.
Every transfer of personal information from you to us or from us to third parties is protected by a data processing agreement. If you would like to receive more information about the safeguards we employ, please contact us (see Section 16 (Contact Paybilt) below).
Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmited to our website. You are also required to take all steps necessary to safeguard your personal information, including login credentials and other information. Any transmission of personal information is at your own risk. We are not responsible for the circumvention of any privacy settings s or security measures contained on the website. If you believe that there has been a breach of security, please contact us immediately.
11. Data Retention
We will only retain and use your information to fulfill the purposes for which it was collected and as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements under applicable laws. We will destroy or render anonymous such information when it is no longer necessary
12. Third-Party Links
Our website may contain links to other sites that Paybilt does not own or operate. We provide links to third- party sites as a convenience to the user. These links are not intended as an endorsement of or referral to the linked sites. The linked sites have separate and independent privacy statements, notices, and terms of use, which we recommend you read carefully. We do not have any control over these sites and have no responsibility or liability for how the organizations that operate such linked sites may collect, use, disclose, or otherwise treat your personal information.
13. Your Rights
As noted above, in most instances, Paybilt is a “data processor” for Merchants. If you are a Merchant Customer, the Merchant is the “data controller” of your personal information and you should refer to the privacy policies or notices of the relevant Merchant for information regarding their privacy practices and your rights.
In relation to the personal information for which Paybilt acts as a “data controller”, and subject to certain exceptions and applicable laws, you may have the following rights:
Rights
Rights
Rights
Description
Description
Description
Right to be informed
Right to be informed
You may request information about the personal information we collect about you, the categories of persons who have access to the information within our organization, the duration of time the information will be kept, and the contact information of the person in charge of protecting personal information.
You may request information about the personal information we collect about you, the categories of persons who have access to the information within our organization, the duration of time the information will be kept, and the contact information of the person in charge of protecting personal information.
Right of access
Right of access
You may request access to your personal information that is in our possession.
You may request access to your personal information that is in our possession.
Right of rectification
Right of rectification
If we hold personal information about you and you believe that it is not accurate, complete, and up to date, you can request to have it rectified. We will also send any information that has been amended, where appropriate, to any third parties that have access to the information.
If we hold personal information about you and you believe that it is not accurate, complete, and up to date, you can request to have it rectified. We will also send any information that has been amended, where appropriate, to any third parties that have access to the information.
Right of erasure
Right of erasure
In some circumstances, as outlined by applicable laws, you may request to have your data erased.
In some circumstances, as outlined by applicable laws, you may request to have your data erased.
Right of portability
Right of portability
If you reside in Quebec, you may request to receive a digital copy of all personal information that has been collected from you by Paybilt.
If you reside in Quebec, you may request to receive a digital copy of all personal information that has been collected from you by Paybilt.
Right to withdraw consent
Right to withdraw consent
If we rely on your implicit or explicit consent as our legal basis for processing your personal information, you have the right to withdraw your consent at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent.
If we rely on your implicit or explicit consent as our legal basis for processing your personal information, you have the right to withdraw your consent at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent.
Please contact our Privacy Officer if you wish to exercise any of your rights under the applicable laws. In order to exercise your rights, we may require you to sufficiently verify your identity by providing government-issued identification and/or verification of your email address and/or phone number.
14. Minors
We do not permit minors under the age of 18 or anyone under the legal age of majority in their applicable jurisdiction to access or use our Services. We request that you do not provide us with personal information if you are a minor. If we learn that we have mistakenly or unintentionally collected or received personal information from a child without appropriate consent, we will delete it. If you believe we mistakenly or unintentionally collected any information from or about a child, please contact us (see Section 16 (Contact Paybilt) below).
15. Changes to this Policy
We reserve the right to change or revise this Policy at any time to reflect changes in the law or our data collection and use practices. Changes to this Policy will apply to the information collected from the date we post our revised Policy, as well as to existing information we hold. The date this Policy was last revised is identified at the top of the page. Your continued use of our Services after we make any changes is deemed to be acceptance of those changes.
16. Contact Paybilt
If you have any questions or concerns about this Policy or Paybilt’s handling of your personal information, please contact our Privacy Officer at: