SteadiPay, Inc. (“we”, “us”, “our”, or “SteadiPay”) respects the privacy of our users. This Privacy Policy explains how we collect, use, and share information through the SteadiPay mobile application (“App”) and our website that links to this Privacy Policy (together, along with the App, the “Services”). By agreeing to this Privacy Policy in the course of installing the App and/or using our Services or the features made available to you through the Services, you are agreeing to the terms of this Privacy Policy and consenting to the collection, use, and sharing of information in a manner consistent with this Privacy Policy.

This Privacy Policy is incorporated by reference in the SteadiPay Terms of Use, which govern your use of the Services. This Privacy Policy applies to your use of our Services that any platform or channel (including, but not limited to, mobile device, laptop, desktop, tablet or other device).

 

Information We Collect

SteadiPay collects both personal information and other information about its users in connection with the Services. “Personal Information” is information that SteadiPay can directly associate with a specific person, such as your name or email address. “Other Information” is any additional information that SteadiPay collects that is not Personal Information. We may combine Other Information with Personal Information, and, in those circumstances, we will treat the combined information as Personal Information. We collect information from a variety of sources, including information provided by you, information we collect when you use the Services, and information about you that we receive from third-party sources. Information that we collect may include, but not be limited to, personal information and information automatically collected through the Services:

 

Personal Information We Collect

When you register for our Services through the App or sign up to be part of our App test group through our website, we may collect information directly from you, such as the following:

  • Name
  • Address
  • Email address
  • Password
  • Mobile telephone number
  • Date of birth
  • Social Security Number or government issued identification details
  • Your full credit card number(s)
  • Facebook login credentials
  • Your login credentials, including your usernames and passwords, for the online credit and checking accounts that you would like to use as part of the App (your “Credit Card Account” and “Bank Account,” respectively). Your login credentials for your Bank Account are used to collect the account and routing number for your Bank Account and that information is shared with our third-party providers.

Although we ask for your usernames and passwords for your financial accounts, i.e. your online login credentials, we only ask you for this information during the initial sign-up process in order to set up your account on the Services. We do not store your login credentials for any Bank Account or Credit Card Account that you link to the Services; we only use this information once to connect to your accounts, and then we delete it from our records. However, this information is stored by Plaid, our third-party service provider that provides us with your Bank Account or Credit Card Account transaction information. In addition, we and our service providers also retain the full number of your Credit Card Account. Our service providers will also retain the full account and routing numbers of your Bank Account.

We also collect information about your credit card and checking balances and transactions, so that we can track the spending on your credit cards and make transfers between your accounts in accordance with your instructions. For example, when you link a Bank Account or Credit Card Account to the Services, we may collect: your account balances; transaction level information, including the date and amount of each transaction, currency, merchant, and which account user was responsible for the transaction; payment due dates; and credit limits.

 

Other information collected automatically through the Services.

We or our third-party service providers also collect other information automatically through the Services. This may include information such as: your IP address and domain name, your Internet service provider, the date and time of your visit to the website or your use of the App, your use of the Services during your current session and over time (including the pages you viewed), the URLs from the websites you visit before and after navigating to the website, your computer’s or mobile device’s software and hardware attributes (including operating system type and version, App version, device type, and device identifiers, including IDFA and/or Advertising IDs), your browser type and version, mobile network information, device state information, information relating to how the Services function, your general geographic location derived through your IP address (e.g., your city, state, or metropolitan region), and the physical location of a device at the time of a crash.

 

We collect such information using a variety of mechanisms, including the following:

  • Server Logs. When you use the Services, we automatically receive and record certain information from your computer or mobile device and your browser. This may include the types of information listed in the preceding paragraph. To obtain such information, we may use server logs or similar applications that recognize your computer or other devices and gather information about their
    online activity.
  • Cookies. We also use cookies on the Services. Cookies are small files that are stored on your computer or other device by your web browser. A cookie allows the Services to recognize whether you have visited before and may store user preferences and other information. For example, cookies can be used to collect information about your use of the Services during your current session and over time (including the pages you view and the files you download), your computer or device’s operating system and browser type, your Internet service provider, your domain name and IP address, your general geographic location, the website you visited prior to accessing Services, and the link you use to leave the Services.
    If you are concerned about having cookies on your computer, you can set your browser to refuse all cookies or to indicate when a cookie is being set, allowing you to decide whether to accept it. You can also delete cookies from your computer. However, if you choose to block or delete cookies, certain features of the Services may not operate correctly.
  • Web beacons or pixels. The Services or the emails that you receive from us or our partners may use an application known as a “web beacon” (also known as a “clear gif” or “pixel tag”). A web beacon is an electronic file that usually consists of a single-pixel image. It can be embedded in a web page or in an email to transmit information, which could include Personal Information. For example, it allows an email sender to determine whether a user has opened a particular email. We also may partner with certain third parties to collect, analyze, and use some of the Personal Information and Other Information described in this section. For example, we may allow third parties to set cookies or use web beacons or other tracking mechanisms (such as tags or scripts) on the Services or in email communications from us, or we may allow third parties to use an application software development kit (SDK) or a server-to-server connection to collect information. (An SDK is a section of code that we embed in our App to allow third parties to collect information about how users interact with the app, and a server-to-server connection enables us to exchange data with third parties when an SDK integration is not feasible or practical.) The information collected by third parties using these technologies may be used for a variety of purposes, including analytics and targeted interest-based advertising. For more information about such activities, including how you may opt out of some processing of your data, please see the section below entitled “Third-Party Analytics and Interest-Based Advertising.”

 

How We Use the Information That We Collect

We may use Personal and Other Information for a variety of purposes related to our operation and your use of the Services. Examples of specific ways in which SteadiPay may use your Personal and Other Information include, but are not limited to, the following:

Personal Information. We use the Personal Information that we collect about users to:

  • Provide the Services to you, including to let you sign up for an account and use the App;
  • Fulfill the terms of any agreement you have with us, respond to your requests, or otherwise
    complete a transaction that you initiate, including the transfer of funds between the Bank Account
    and Credit Card Account that you link to the Services;
  • Respond to your inquiries about our Services;
  • Contact you by email, push notification, or other method regarding our Services;
  • Engage in analysis and research concerning the Services, improve users’ experiences with the Services, and otherwise enhance the quality of our products and Services;
  • Perform fraud screening, verify identities, and verify the information contained in your Bank Account or Credit Card Account that you link to the Services;
  • Comply with legal and/or regulatory requirements, or to protect our rights and interests, as described below in the “Legal Purposes” subsection of this Policy; and
  • Create, compile, and share de-identified and/or aggregated information.

Other Information.

We use the Other Information that we collect for these same purposes, as well as to:

  • Help us efficiently operate the Services, to count and recognize visitors to the Services, to enable certain features on the Services, and for other purposes related to managing our business;
  • Analyze how visitors use the Services and their features, to learn how effective our email and push notification communications are, to improve the Services and enhance users’ experiences, to create new products and services, and to enable additional analytics and research concerning the Services.
  • For any other business purpose permitted by law.

How We Share Personal and Other Information with Third Parties

We may share your Personal Information and Other Information with third parties for a variety of purposes, as described below.

Our banking partners. SteadiPay is not a bank and does not receive or store your checking account number or the funds that are deducted from your checking account. SteadiPay uses third-party service providers to help provide our Services, and it is necessary that we share some personal information with these providers in order to provide our Services.

  • Plaid provides access to your accounts for transaction tracking and balance monitoring. You will provide your online banking login credentials to Plaid during set-up in order to use our Services.
  • Our banking partner initiates all ACH transfers and stores your funds in a pooled, FBO, FDIC- insured account. Your personal information is shared with our banking partner to facilitate the creation of this account and to help prevent fraud. You may access Plaid’s privacy policy at https://plaid.com/legal/.
  • Arcus (and Arcus’s bank partner, CBW Bank) facilitate the payment of your credit cards. By using the SteadiPay Services, you agree to the privacy policies of our third-party providers.

By using the SteadiPay Services, you agree to the privacy policies of our third-party providers, including Plaid and Arcus.

Your financial institutions. To provide the Services to you, we may share Personal Information with the financial institutions that you do business with. For example, in order to ensure that our payment to your Credit Card Account is properly applied, we share your name and full credit card number with your credit card company (in either paper or electronic format) when we submit your payment.

Third-party service providers. SteadiPay uses third-party service providers to help us manage and improve the Services. These service providers may collect and/or use your Personal or Other Information to assist us in achieving the purposes discussed above in the section entitled “How We Use the Information that We Collect.” For example, we may use third parties to perform data storage and processing services for us and to help us communicate with our users. We also use third-party service providers to help us access your transactions and balance information, and to help us transfer funds between your Bank Account, SteadiPay Account, and Credit Card Account as part of the Services. We also partner with certain third parties to collect, analyze, and use some of the Personal and Other Information as described below in Third-Party Analytics and Interest Based Advertising, and to create aggregated data that no longer identifies you personally.

We disclose information to service providers Plaid and Arcus in order to provide the Services and for our providers’ own internal use. When you use our service, we may collect your personal information, including first and last name, email address, birth date, social security number, physical address, and financial account information. By using our service, you agree to this information being shared with and transferred, stored, and processed by our third party service providers in accordance with the their privacy policies. You also grant SteadiPay’s third party service providers the right, power and authority to access and transmit user data as reasonably necessary to provide the SteadiPay services. All third-party partners’ use of data is subject to each partner’s own privacy policy, and not this policy. Additional information on third party service providers’ user of data may be found in Plaid’s privacy policy and Arcus’s privacy policy.

We also may share your Personal or Other Information with other third parties when necessary to meet the terms of any agreement that you have with us.

Legal purposes. We also may use or share your Personal or Other Information with third parties when we believe, in our sole reasonable discretion, that doing so is necessary:

  • to comply with applicable law or a court order, subpoena, or other legal process;
  • to investigate, prevent, or take action regarding illegal activities, suspected fraud, violations of our terms and conditions, or situations involving threats to our property or the property or physical safety of any person or third party;
  • to establish, protect, or exercise our legal rights or defend against legal claims; or
  • to facilitate the financing, securitization, insuring, merger, sale, assignment, bankruptcy, consolidation, liquidation, acquisition, or other disposal of all or part of our business or assets.

Third-Party Analytics and Interest Based Advertising

We partner with certain third-parties to collect, analyze, and use some of the Personal and Other Information described above. For example, we may allow third parties to set cookies or use web beacons on the website or in email communications from SteadiPay. The information collected by third parties using these technologies may be used to engage in analysis, auditing, research, and reporting. These third parties may set and access cookies on your computer or other device and may collect information about your online activities across different websites or services over time, including on websites and mobile applications that are not owned or operated by SteadiPay.

In particular, the Services may use Google Analytics to help collect and analyze certain information on the website and the App for the purposes discussed above. You may review Google Analytics’ security and privacy principles by clicking here and opt out of the use of cookies in web browsers by Google Analytics by clicking here.

We also partner with third parties to provide targeted advertising services that are customized based on your online activities over time and across unaffiliated websites (“Interest-Based Advertising”). These third parties may use cookies, web beacons, and similar technologies (including clear GIFs, tracking pixels, JavaScript, and tags) to collect information about your activity on our website, and they may combine it with information about your activity on other unaffiliated websites, information that we have collected about you in other contexts, or demographic information. For example, third parties may use the fact that you visited our website to target online ads for SteadiPay services to you on non-SteadiPay websites or mobile apps. In addition, our third-party advertising networks might use information about your use of the Services to help target non-SteadiPay advertisements based on your online behavior in general. For information about interest-based advertising practices, including privacy and confidentiality, visit the Network Advertising Initiative website or the Digital Advertising Alliance website.

The use of online tracking mechanisms by third parties is subject to those third parties’ own privacy policies. You may remove yourself from the targeted advertising of companies within the Network Advertising Initiative by opting out here, or of companies participating in the Digital Advertising Alliance program by opting out here. Please note that the opt-out will apply only to the specific browser or device from which you opt out, and therefore you will need to opt out separately on all of your browsers and devices. If you delete or reset your cookies, change browsers, or use a different device, any opt-out cookie or tool may no longer work and you will have to opt out again.

Some browsers have a “do not track” feature that lets you tell websites that you do not want to have your online activities tracked. At this time, we do not respond to browser “do not track” signals, but you may opt out of interest-based advertising of companies within the Network Advertising Initiative and for companies participating in the Digital Advertising Alliance by visiting the opt-out pages described above.

 

Data Retention and Security

SteadiPay uses commercially reasonable physical, electronic, and procedural safeguards to protect your Personal Information against loss or unauthorized access, use, modification, or deletion. We encrypt Personal Information when we transfer it to third parties over the Internet. However, no security program is foolproof, and thus we cannot guarantee the absolute security of your Personal or Other Information.
SteadiPay may retain Personal Information as long as necessary to provide the services to you and to fulfill the purposes described in this policy. If you would like SteadiPay to delete the Personal Information associated with your account, please follow the instructions in the “Reviewing, Updating, and Deleting Your Personal Information” section below.

 

Reviewing, Updating, and Deleting Your Personal Information

You may access, amend, and/or request deletion of certain information that you have provided to us by accessing the Website or App, or by emailing us at [email protected] If you email us, for your protection, we may only implement requests with respect to the information associated with the particular email address you use to send us your request, and we may need to verify your identity before implementing your request. We will attempt to comply with any reasonable requests for accessing, amending, or deleting your information.

 

California Privacy

California Civil Code Section 1798.83 permits users of SteadiPay who are California residents to request certain information regarding our disclosure of Personal Information to third parties for their direct marketing purposes. To make such a request, please contact us by emailing us at [email protected] or writing us at “SteadiPay Privacy Support, PO Box 1213, Pacific Palisades CA 90272-1213”.

 

Children’s Privacy

The Services are not directed to children under the age of 13, and SteadiPay will never knowingly collect Personal or Other Information from anyone it knows is under the age of 13. If you are under 13, please do not attempt to register for the Services or send any personal information about yourself to us. If we learn that we have collected Personal Information from a child under age 13, we will promptly take all reasonable steps to delete the data from our system.

 

Third-Party Links, Websites, and Apps

The Services may contain links to and from the websites or apps of other third parties. If you follow a link to any of these websites or apps, please note that these websites and apps, and any services that may be accessible through them, have their own privacy policies. We are not responsible for the privacy practices of other websites or apps. We encourage our users to be aware when they leave the Services and to read the privacy policies applicable to such thirdparty websites and apps. This Privacy Policy applies solely to information collected in connection with the Services.

 

Changes to This Statement

Technology and the Internet are rapidly changing. SteadiPay therefore is likely to make changes to the Services in the future and as a consequence will need to revise this Statement to reflect those changes. SteadiPay will post all such changes to the Privacy Policy on the website and in the App under the “Settings” section of the menu tab, so you should review those pages periodically. If we make a material change to the Privacy Policy, you will be provided with appropriate notice. If we maintain your email address, when appropriate we also may email you a copy of the revised Privacy Policy at your most recently provided email address. It is therefore important that you update your email address if it changes.

 

Questions or Comments

If you have any questions or comments regarding our Privacy Policy, please email us at [email protected] or write us at “SteadiPay Support, PO Box 1213, Pacific Palisades CA 90272-1213”.