Join us for a live discussion on recent bank failures and the importance of resilient payment systems.Learn more
- Personal Data
- How We Share Your Personal Data
- Tracking Tools and Opt-Out
- Data Security and Retention
- Personal Data of Children
- California Resident Rights
- Exercising Your Rights under the CCPA
- European Union and United Kingdom Data Subject Rights
- Contact Information
Personnel of our Customers: If you work for a Modern Treasury customer, then your company administers its use of our products and sets its own policies for its users. Your company, as administrator, may access your accounts, restrict or terminate your access to our products, require you to reset your passwords, and take other actions related to your use of our products. Please contact your Modern Treasury organization administrator for more information.
"Personal Data" means any information that identifies or relates to a particular individual and also includes information referred to as "personally identifiable information" or "personal information" under applicable data privacy laws, rules or regulations.
Categories of Personal Data We Collect
This chart details the categories of Personal Data that we collect and have collected over the past 12 months:
|Category of Personal Data||Examples of Personal Data We Collect||Categories of Third Parties with Whom We Share this Personal Data|
|Profile or Contact Data||First and last name, title and company affiliation, email, phone number, business and mailing address||Service providers, analytics partners, advertising partners, parties you authorize, access, or authenticate, banks|
|Online Identifiers||Account name and passwords, email||Service providers, analytics partners, parties you authorize, access, or authenticate (for the purposes of two-factor authentication|
|Payment Data (when paying for Modern Treasury or its Offerings)||Payment card type, credit or debit card number (see "Payment Processors" below), bank account information, billing address, phone number, and email||Service providers (including our payment processing partners)|
|Commercial Data||History of products purchased from Modern Treasury||Service providers, analytics partners, parties you authorize, access, or authenticate|
|Identity Data (for bank integrations)||Name, date of birth, tax ID or social security number, bank account information, address, identity verification and Know Your Customer information (e.g. beneficial owner information)||Service providers, banks (certain integrations)|
|Device/IP Data||IP address, type of device/operating system/browser used to access the Offerings, language settings, mobile device carrier, radio/network information (e.g. wifi, LTE, 3G)||Service providers, analytics partners, advertising partners, parties you authorize, access, or authenticate, other users (only applicable for certain business customers), service providers, analytics partners|
|Audio or Video||Audio or video recordings of conversations or recordings between Modern Treasury support or customer success and customers, Screen recordings of use of sandbox accounts||Service providers|
|Geolocation Data||IP-address based location information||Service providers, analytics partners|
|Other Identifying Information that You Voluntarily Choose to Provide||Identifying information in emails or letters you send us, customer support and customer success interactions||Service providers, analytics partners, parties you authorize, access, or authenticate|
Categories of Sources of Personal Data
We collect Personal Data about you from the following categories of sources:
- When you provide such information directly to us.
- When you register for or use our Offerings.
- When you voluntarily provide information through responses to inquiries, surveys or questionnaires.
- When you send us an email or otherwise contact us.
- Automatically when you use the Offerings.
- Through Cookies (defined in the Tracking Tools and Opt-Out section below).
- If you use a location-enabled browser, we may receive information about your location.
- When you provide such information directly to us.
- Public Records
- We collect certain information from public records and sources, such as social media platforms, publications, consumer reporting agencies, public databases and news sites.
- Third Parties
- We may use analytics providers to analyze how you interact and engage with the Offerings or service providers may help us provide you our Offerings or related support.
- We may use vendors to obtain information to generate leads, create user profiles, or verify your identity or other information.
- We may receive information from joint marketing partners or other business partners.
- Parties you authorize, access, or authenticate
Our Commercial or Business Purposes for Collecting or Disclosing Personal Data
- Providing, Customizing and Improving the Offerings
- Processing orders or other transactions; billing.
- Establishing and maintaining your account for our Offerings.
- Providing you with the Offerings or information you request.
- Verifying your identity in compliance with sanctions and "Know Your Customer" laws
- Meeting or fulfilling the reason you provided the information to us.
- Providing support and assistance for the Offerings.
- Improving the Offerings, including testing, research, internal analytics and product development.
- Personalizing the Offerings, website content and communications based on your preferences.
- Doing fraud protection, security and debugging.
- Enabling customers to issue payment orders to Banks.
- Carrying out other business purposes stated when collecting your Personal Data or as otherwise set forth in applicable data privacy laws, such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (the "CCPA").
- Marketing the Offerings
- Marketing and selling the Offerings.
- Showing you advertisements, including interest-based or online behavioral advertising.
- Corresponding with You
- Responding to correspondence that we receive from you, contacting you when necessary or requested, and sending you information about Modern Treasury or the Offerings.
- Sending emails and other communications according to your preferences or that display content that we think will interest you.
- Meeting Legal Requirements and Enforcing Legal Terms
- Fulfilling our legal obligations under applicable law, regulation, court order or other legal process, such as preventing, detecting, and investigating security incidents and potentially illegal or prohibited activities.
- Protecting the rights, property or safety of you, Modern Treasury, or another party.
- Enforcing any agreements with you.
- Responding to claims that any posting or other content violates third-party rights.
- Resolving disputes.
- To the extent we collect sensitive personal information (as defined in the CCPA) from you, we use it for the purposes described in section 7027(m) of the CCPA regulations and/or do not use sensitive personal information for purposes of inferring characteristics about consumers.
We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated, or incompatible purposes without providing you notice.
How We Share Your Personal Data
We disclose your Personal Data to the categories of service providers and other parties listed in this section. For more information, please refer to the state-specific sections below.
- Service Providers. These parties help us provide the Offerings or perform business functions on our behalf. They include:
- Hosting, technology, and communication providers.
- Security and fraud prevention consultants.
- Professional advisors, such as lawyers, auditors, bankers, and insurers, where necessary in the course of professional services they provide to us.
- Support and customer service vendors.
- Payment processors.
- We use third party payment processors to process payment of your fees for our Offerings. Our payment processing partners such as CardConnect and Ordway collect your voluntarily-provided payment information necessary to process your payment.
- To simplify the payment process, if you pay by credit card, we save the last four digits of your payment card, the expiration date of your payment card, the card type, your first and last name, your billing address, and a token identifier to match your information to your full payment card number, which is stored by the applicable payment processor. We do not store your full payment card number or your CVV2 number (the 3 to 4 digit security code on your card). We do not have access to your full payment card number stored by the applicable payment processor.
- Please see the applicable payment processor's website (e.g., CardConnect and Ordway) to review their terms of service and privacy policies for information on their use and storage of your Personal Data.
- Advertising Partners. These parties help us market our Offerings and provide you with other offers that may be of interest to you. They include:
- Ad networks.
- Marketing providers.
- Analytics Partners. These parties provide analytics on web traffic or usage of the Offerings. They include:
- Companies that track how users found or were referred to the Offerings.
- Companies that track how users interact with the Offerings.
- Parties You Authorize, Access, or Authenticate. These parties partner with us in offering various products or integrations. They include:
- Businesses that you have or seek a relationship with, such as Plaid and other integrated products.
- Companies that we partner with to offer joint promotional offers or opportunities.
- Bank Partners. We have bank partnerships that allow you to use our Offerings with your bank accounts. Depending on the integration, we may share Identity Data and other Personal Data with the bank to facilitate your use of your bank account with our Offerings and for security, compliance and related purposes.
- Other Users. If you use our Offerings as a customer, we make available audit logs and usage data to other users on your company's account (such as IP address and certain associated activity) to allow our customers to observe logs or activity within their accounts.
We may share any Personal Data that we collect with third parties in conjunction with any of the activities set forth under Meeting Legal Requirements and Enforcing Legal Terms in the Our Commercial or Business Purposes for Collecting Personal Data section above.
All of your Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part). Should one of these events occur, we will make reasonable efforts to notify you before your information becomes subject to different privacy and security policies and practices.
Data that is Not Personal Data
We may create aggregated, de-identified or anonymized data from the Personal Data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and share it with third parties for our lawful business purposes, including to analyze, build and improve the Offerings and promote our business, provided that we will not share such data in a manner that could identify you.
Tracking Tools and Opt-Out
We use the following types of Cookies:
- Functional Cookies. Functional Cookies are used to record your choices and settings regarding our Offerings, maintain your preferences over time and recognize you when you return to our Offerings. These Cookies help us to personalize our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
- Advertising Cookies. Advertising Cookies collect data about your online activity and identify your interests so that we can provide advertising that we believe is relevant to you. For more information about this, please see the section below titled Information about Interest-Based Advertisements.
- Essential Cookies. Essential Cookies are required for providing you with features or Offerings that you have requested. For example, certain Cookies enable you to log into secure areas of our Offerings. Disabling these Cookies may make certain features and Offerings unavailable.
In addition to updating your Cookie preferences in the Website Data Collection Preferences pane of the Modern Treasury website, you can decide whether or not to accept Cookies through your internet browser's settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your device. If you do this, however, you may have to manually adjust some preferences every time you visit our website and some of the Offerings and functionalities may not work.
To explore what Cookie settings are available to you, look in the "preferences" or "options" section of your browser's menu. To find out more information about Cookies, including information about how to manage and delete Cookies, please visit http://www.allaboutcookies.org/ or https://ico.org.uk/for-the-public/online/cookies/ if you are located in the European Union.
Information about Interest-Based Advertisements
We may display advertisements on third-party platforms or websites through our use of Advertising Cookies. These advertisements may be targeted to users who fit certain general profile categories or display certain preferences or behaviors ("Interest-Based Ads"). Information for Interest-Based Ads (including Personal Data) may be provided to us by you or derived from the usage patterns of particular users on the Offerings and/or offerings of third parties. Such information may be gathered through tracking users' activities across time and unaffiliated properties, including when you leave the Offerings. To accomplish this, we or our service providers may deliver Cookies, including a file (known as a "web beacon") from an ad network to you through the Offerings. Web beacons allow ad networks to provide anonymized, aggregated auditing, research, and reporting for us and for advertisers. Web beacons also enable ad networks to serve targeted advertisements to you when you visit other websites. Web beacons allow ad networks to view, edit or set their own Cookies on your browser, just as if you had requested a web page from their site.
Through the Digital Advertising Alliance ("DAA") and Network Advertising Initiative ("NAI"), several media and marketing associations have developed an industry self-regulatory program to give consumers a better understanding of, and greater control over, ads that are customized based a consumer's online behavior across different websites and properties. Modern Treasury does not currently participate in DAA or NAI programs. To make choices about Interest-Based Ads from participating third parties, including to opt-out of receiving behaviorally targeted advertisements from participating organizations, please visit the DAA's or NAI's consumer opt-out pages, which are located at http://www.networkadvertising.org/choices/ or www.aboutads.info/choices. Users in the European Union should visit the European Interactive Digital Advertising Alliance's user information website http://www.youronlinechoices.eu/.
Opt-Out of Marketing Communications
You may opt-out of our marketing-related emails by following the opt-out or unsubscribe instructions at the bottom of the email, or by contacting us at email@example.com. You may continue to service service-related and non-marketing emails.
Data Security & Retention
We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. Although we work to protect the security of your data that we hold in our records, please be aware that no method of transmitting data over the internet or storing data is completely secure.
We retain Personal Data about you for as long as necessary to provide you with our Offerings. In some cases, we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule, or regulation. When establishing a retention period for specific categories of data, we consider who we collected the data from, our need for the Personal Data, why we collected the Personal Data, and the sensitivity of the Personal Data. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.
Personal Data of Children
California Resident Rights
If you are a California resident, you have the rights set forth in this section. Please see the Exercising Your Rights section below for instructions regarding how to exercise these rights. Please note that we may process Personal Data of our customers' end users or employees in connection with our provision of certain Offerings to our customers. If we are processing your Personal Data as a processor or service provider, you should contact the entity that collected your Personal Data in the first instance to address your rights with respect to such data.
You have the right to request certain information about our collection and use of your Personal Data over the past 12 months. In response, we will provide you with the following information:
- The categories of Personal Data that we have collected about you.
- The categories of sources from which that Personal Data was collected.
- The business or commercial purpose for collecting or selling your Personal Data.
- The categories of third parties with whom we have shared your Personal Data.
- The specific pieces of Personal Data that we have collected about you.
If we have disclosed your Personal Data to any third parties for a business purpose over the past 12 months, we will identify the categories of Personal Data shared with each category of third party recipient. If we have sold your Personal Data over the past 12 months, we will identify the categories of Personal Data sold to each category of third party recipient.
You have the right to request that we delete the Personal Data that we have collected about you. Under the CCPA, this right is subject to certain exceptions: for example, we may need to retain your Personal Data to, among other things, provide you with the Offerings, for security and integrity or debugging and repair purposes, or to complete a transaction or other action you have requested or comply with a legal obligation. If your deletion request is subject to one of these exceptions, we may deny your deletion request.
You have the right to request that we correct any inaccurate Personal Data we have collected about you. Under the CCPA, this right is subject to certain exceptions: for example, if we decide, based on the totality of circumstances related to your Personal Data, that such data is correct. If your correction request is subject to one of these exceptions, we may deny your request.
Personal Data Sales Opt-Out and Opt-In
We will not sell your Personal Data (except to the extent “sharing” Personal Data is considered a “sale” under CCPA; see next section).
Personal Data Sharing Opt-Out and Opt-In
Under the CCPA, California residents have certain rights when a business "shares" Personal Data with third parties for purposes of cross-contextual behavioral advertising. We have shared the following categories of Personal Data for the purposes of cross-contextual behavioral advertising:
- Web and Email Analytics
- Device/IP Data
- Identifiable lead information
As described in the Tracking Tools, Advertising and Opt-Out section above, we have incorporated Cookies from certain third parties into our Services. These Cookies allow those third parties to receive information about your activity on our Services that is associated with your browser or device. Those third parties may use that data to serve you relevant ads on our Services or on other websites you visit. Under the CCPA, sharing your data through third party Cookies for online advertising may be considered a "sale" of information. You can opt out of data selling and/or sharing by following the instructions in this section.
We share Personal Data with the following categories of third parties:
- Ad Networks.
- Marketing providers (including for cross-contextual behavioral advertising purposes)
Over the past 12 months, we have shared your Personal Data with the categories of third parties listed above for the following purposes:
- Marketing and selling the Services.
- Showing you advertisements, including interest-based or online behavioral advertising.
You have the right to opt-out of the sharing of your Personal Data. You can opt-out using the following methods:
- You can modify your cookie settings here: Website Data Collection Preferences
- You can complete the online form found here: Do Not Share My Personal Information.
- You can email us at firstname.lastname@example.org.
- You can use a Global Privacy Control. Please note this does not include Do Not Track signals.
Once you have submitted an opt-out request, we will not ask you to reauthorize the sale and/or sharing of your Personal Data for at least 12 months.
To our knowledge, we do not sell or share the Personal Data of minors under 16 years of age.
We Will Not Discriminate Against You for Exercising Your Rights Under the CCPA
We will not discriminate against you for exercising your rights under the CCPA. We will not deny you our goods or Offerings, charge you different prices or rates, or provide you a lower quality of goods and Offerings if you exercise your rights under the CCPA.
Exercising Your Rights under CCPA
We will work to respond to your Valid Request within the time period required by applicable law. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive, or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.
You may submit a Valid Request by completing the request form here or emailing us at the following email address: email@example.com.
If you are a California resident, you may also authorize an agent (an "Authorized Agent") to exercise your rights on your behalf. To do this, you must provide your Authorized Agent with written permission to exercise your rights on your behalf, and we may request a copy of this written permission from your Authorized Agent when they make a request on your behalf.
European Union and United Kingdom Data Subject Rights
EU and UK Residents
If you are a resident of the European Union ("EU"), United Kingdom ("UK"), Lichtenstein, Norway or Iceland, you may have additional rights under the EU or UK General Data Protection Regulation (the "GDPR") with respect to your Personal Data, as outlined below.
For this section, we use the terms "Personal Data" and "processing" as they are defined in the GDPR, but "Personal Data" generally means information that can be used to individually identify a person, and "processing" generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure.
Personal Data We Collect
The Categories of Personal Data We Collect section above details the Personal Data that we collect from you.
Personal Data Use and Processing Grounds
The Our Commercial or Business Purposes for Collecting Personal Data section above explains how we use your Personal Data.
We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our "legitimate interests" or the legitimate interest of others, as further described below.
- Contractual Necessity: We process the following categories of Personal Data as a matter of "contractual necessity", meaning that we need to process the data to perform under our agreement with you, which enables us to provide you with the Offerings. When we process data due to contractual necessity, failure to provide such Personal Data will result in your inability to use some or all portions of the Offerings that require such data.
- Profile or Contact Data
- Online Identifiers
- Payment Data
- Commercial Data
- Identity Data
- Legitimate Interest: We process the following categories of Personal Data when we believe it furthers the legitimate interest of us or third parties:
- Profile or Contact Data
- Online Identifiers
- Device/IP Data
- Web Analytics
- Audio or Video
- Geolocation Data
- Other Identifying Information that You Voluntarily Choose to Provide
- We may also de-identify or anonymize Personal Data to further our legitimate interests.
- Examples of these legitimate interests include (as described in more detail above):
- Providing, customizing and improving the Offerings
- Marketing the Offerings
- Corresponding with you
- Meeting legal requirements and enforcing legal terms
- Completing corporate transactions
- Consent: In some cases, we process Personal Data based on the consent you expressly grant to us at the time we collect such data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection.
- Other Processing Grounds: From time to time we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.
Sharing Personal Data
The How We Share Your Personal Data section above details how we share your Personal Data with third parties.
EU and UK Data Subject Rights
You have certain rights with respect to your Personal Data, including those set forth below. For more information about these rights, or to submit a request, please email us at firstname.lastname@example.org or use the request form here. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request. We may also need to retain certain information for record keeping purposes, and there may also be residual information that will remain within our databases and other records, which will not be removed from such locations.
- Access: You can request more information about the Personal Data we hold about you and request a copy of such Personal Data.
- Rectification: If you believe that any Personal Data we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data.
- Erasure: You can request that we erase some or all of your Personal Data from our systems.
- Withdrawal of Consent: If we are processing your Personal Data based on your consent (as indicated at the time of collection of such data), you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Data, if such use or disclosure is necessary to enable you to utilize some or all of our Offerings.
- Portability: You can ask for a copy of your Personal Data in a machine-readable format. You can also request that we transmit the data to another controller where technically feasible.
- Objection: You can contact us to let us know that you object to the further use or disclosure of your Personal Data for certain purposes, such as for direct marketing purposes.
- Restriction of Processing: You can ask us to restrict further processing of your Personal Data.
- Right to File Complaint: You have the right to lodge a complaint about Modern Treasury's practices with respect to your Personal Data with the supervisory authority of your country or EU Member State. A list of Supervisory Authorities is available here: https://edpb.europa.eu/about-edpb/board/members_en.
Transfers of Personal Data
The Offerings are hosted and operated in the United States ("U.S.") through Modern Treasury and its service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Offerings, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to Modern Treasury in the U.S. and will be hosted on U.S. servers, and you acknowledge that may be transferred, stored, and processed your information to and in the U.S., and possibly other countries.
- Website: https://www.moderntreasury.com/
- Email: email@example.com
- Address: Modern Treasury Corp., 315 Montgomery St., 10th Floor San Francisco, CA 94104, Attn: Privacy