Legal

Privacy Policy

Effective Date: April 21, 2026 · Last Updated: April 21, 2026

This Privacy Policy (this “Policy”) describes the practices of MonetaFi LLC and its affiliates (collectively, “MonetaFi,” “we,” “us,” or “our”) with respect to Personal Information we collect from or about users of our websites, web-based applications, partner and merchant portals, mobile experiences, APIs, and related online and offline services (collectively, the “Services”). This Policy forms part of and is incorporated into our Terms of Service.

By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, you must not access or use the Services.

Controller. Except where a separate written agreement identifies a different data controller (for example, where MonetaFi acts as a processor or service provider to a partner or financial institution), MonetaFi is the controller of Personal Information collected through the Services for the purposes described in this Policy.

1. Scope and Key Definitions

For purposes of this Policy:

  • Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, consistent with applicable privacy laws (including the California Consumer Privacy Act, as amended (“CCPA/CPRA”), and other U.S. state privacy statutes).
  • Process” (and its variants) means any operation performed on Personal Information, whether by automated means or otherwise.
  • Google User Data” means information we obtain about you from Google or your Google account through your authorization of one or more Google OAuth scopes.
  • Sensitive Personal Information” (“SPI”) has the meaning given under applicable law, and may include, for example, government-issued identifiers, precise geolocation, account credentials, and financial account information.

This Policy does not apply to: (a) websites, products, or services operated by third parties, even if linked from the Services; (b) Personal Information processed solely in an employment or contractor context; or (c) Personal Information processed on behalf of a business customer or partner where that party is the controller and MonetaFi is acting as a processor or service provider, in which case that party’s privacy policy governs.

2. Personal Information We Collect

We collect Personal Information in the following categories from the following sources:

2.1 Information You Provide

  • Identifiers and contact data: name, business name, email address, telephone number, mailing or business address, title, and authentication credentials you create or elect to import.
  • Commercial and application information: information you submit in funding inquiries, partner applications, merchant intake, underwriting workflows, contracts, or similar business interactions, which may include business financial history, banking references, ownership information, and related operational details.
  • Content and communications: files, attachments, messages, notes, and other content you submit to or through the Services, including emails and support communications.
  • Payment and billing data: limited information necessary to process fees; sensitive card data is handled by our payment processors and is not retained by MonetaFi in the clear.

2.2 Information We Collect Automatically

  • Device and log data: IP address, user-agent, device identifiers, operating system and browser characteristics, language preferences, referring and exit pages, date/time stamps, and diagnostic or performance data.
  • Usage data: features used, pages and screens viewed, clickstream data, interaction events, search terms, and similar product telemetry.
  • Approximate location: inferred from IP address or similar signals. We do not collect precise geolocation unless you expressly enable it.
  • Cookies and similar technologies: as described in Section 4.

2.3 Information From Third Parties

  • Authentication providers (including Google), which may supply your name, email address, profile photo, account identifiers, and, where you authorize, Google User Data under the scopes you approve;
  • Analytics, advertising, and attribution partners, which may share engagement, campaign, and conversion data;
  • Data enrichment, verification, and fraud-prevention vendors, which may provide business information, identifiers, risk signals, or sanctions/watchlist screening results; and
  • Referrals and partners, including ISO partners, brokers, funders, and integrated platforms you or your organization elect to connect to the Services.

We do not knowingly collect Sensitive Personal Information for the purpose of inferring characteristics about you beyond what is necessary to provide the Services or comply with law.

3. How We Use Personal Information

We Process Personal Information for the following business and commercial purposes:

  • Service delivery— to provision, operate, maintain, secure, and improve the Services; to authenticate users and provision accounts; and to deliver features you request;
  • Transactions and relationships— to process funding inquiries and applications, facilitate partner and merchant relationships, administer contracts, and perform related commercial activities;
  • Communications— to respond to requests, provide service and transactional notices, and, where permitted, send marketing communications (from which you may opt out);
  • Analytics and product development— to analyze usage, measure performance, conduct research, and develop new features, including through aggregated or de-identified data;
  • Security, fraud, and abuse prevention— to detect, investigate, and prevent fraudulent, unauthorized, or illegal activity; to enforce our terms; and to protect the rights, property, or safety of MonetaFi, our users, or others;
  • Compliance— to comply with applicable laws, regulations, and legal process, including recordkeeping, sanctions screening, anti-money-laundering, and tax obligations; and
  • Corporate transactions— to evaluate, negotiate, and effect mergers, acquisitions, financings, asset sales, reorganizations, and similar transactions.

Where we rely on legitimate interests or similar lawful bases recognized under applicable law, we do so after balancing those interests against your rights and freedoms.

4. Cookies and Tracking Technologies

We and our authorized service providers use cookies, pixels, tags, software development kits, local storage, and similar technologies (collectively, “Tracking Technologies”) to operate the Services, remember preferences, authenticate sessions, measure performance and marketing effectiveness, detect fraud, and personalize experiences.

We use the following categories of Tracking Technologies:

  • Strictly necessary— required to deliver the Services, including security, session management, and load balancing;
  • Performance and analytics— help us understand how the Services are used so we can improve them (e.g., Google Analytics, PostHog, and similar tools);
  • Functional— remember choices you make (e.g., language, UI preferences); and
  • Advertising and measurement— including Google Ads conversion tracking, remarketing, and related tags from marketing platforms, used to measure campaign performance and, in some cases, deliver tailored advertising on other sites.

Choices. You can control cookies through your browser settings, device-level controls, and, where applicable, our on-site cookie preference interface. You may also opt out of certain interest-based advertising through industry programs, including the DAA and the NAI. We honor Global Privacy Control (“GPC”) signals as an opt-out of “sale” or “sharing” under applicable U.S. state privacy laws, to the extent those terms apply to our practices. Blocking certain Tracking Technologies may limit functionality of the Services.

5. Google Account Data and OAuth Scopes

Certain features of the Services allow you to connect your Google account through OAuth. If you elect to do so, Google will prompt you to authorize one or more scopes. MonetaFi only accesses, stores, and uses Google User Data consistent with the scopes you authorize, the features you enable in the Services, and this Policy.

5.1 Scopes We May Request

Depending on the feature, we may request some or all of the following Google OAuth scopes:

  • https://www.googleapis.com/auth/gmail.readonly — view your email messages and settings. Used to display, search, and sync email threads within the Services to the extent necessary to operate features you enable (for example, lead and pipeline email inboxes tied to your account).
  • https://www.googleapis.com/auth/gmail.metadata — view email message metadata such as labels, headers, and routing information, but not message bodies. Used where the Services only require metadata to operate (for example, classification, threading, and routing).
  • https://www.googleapis.com/auth/userinfo.email — see your primary Google Account email address. Used to identify your account and associate your access with the appropriate MonetaFi user.
  • https://www.googleapis.com/auth/userinfo.profile — see your personal info, including any personal info you have made publicly available. Used to populate your profile and display basic identification (such as name and avatar).

5.2 Limited Use of Google User Data

MonetaFi’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We use Google User Data solely to provide or improve the user-facing features of the Services that are prominent in the requesting application;
  • We do not transfer Google User Data to third parties except (i) as necessary to provide or improve user-facing features of the Services, (ii) to comply with applicable law, or (iii) as part of a merger, acquisition, or sale of assets with notice to users;
  • We do not use Google User Data for serving advertisements, including retargeting, personalized, or interest-based advertising;
  • We do notallow humans to read Google User Data unless (i) we have your affirmative consent for specific messages, (ii) it is necessary for security purposes (for example, investigating abuse), (iii) to comply with applicable law, or (iv) the data have been aggregated and are used for internal operations consistent with Google’s policies; and
  • We apply administrative, technical, and organizational safeguards to Google User Data as described in Section 8.

5.3 Revocation

You may disconnect Google integrations or revoke MonetaFi’s access at any time through your Google Account Permissions page at myaccount.google.com/permissions or, where available, through in-product controls. Revocation will not affect the lawfulness of Processing undertaken prior to revocation, and we may retain Google User Data for limited periods as required by law or for legitimate business purposes (for example, audit trails), subject to Section 7.

6. How We Disclose Personal Information

We disclose Personal Information only as described below. We do notsell Personal Information for monetary consideration. To the extent our use of Tracking Technologies for cross-context behavioral advertising is deemed a “sale” or “sharing” under applicable law, you may opt out as described in Sections 4 and 9.

  • Service providers and processors engaged to perform functions on our behalf (for example, cloud hosting, analytics, communications, customer support, CRM, payment processing, identity verification, fraud prevention, and security), each subject to written obligations of confidentiality and data protection;
  • Partners and counterparties to whom disclosure is necessary or appropriate to facilitate the services you request (for example, prospective funders, ISO partners, or brokers involved in an application you initiate);
  • Professional advisors, including attorneys, accountants, auditors, and insurers, under obligations of confidentiality;
  • Corporate transactions— counterparties and their advisors in connection with a merger, acquisition, financing, reorganization, bankruptcy, receivership, or sale of all or part of our assets, subject to customary confidentiality protections;
  • Legal, regulatory, and safety disclosures— where we believe in good faith that disclosure is required or permitted by law, regulation, subpoena, court order, or other legal process, or is necessary to protect the rights, property, or safety of MonetaFi, our users, or others; and
  • With your consent— to any other recipient where you direct or authorize us to do so.

7. Data Retention

We retain Personal Information only for as long as reasonably necessary to fulfill the purposes for which it was collected, including to (a) operate and improve the Services; (b) comply with our legal, accounting, tax, or reporting obligations; (c) resolve disputes, enforce our agreements, and defend legal claims; and (d) maintain appropriate business records. When Personal Information is no longer required, we will delete, anonymize, or aggregate it in accordance with our internal retention schedules.

8. Information Security

We maintain administrative, technical, physical, and organizational safeguards designed to protect Personal Information against unauthorized access, use, disclosure, alteration, or destruction, including encryption in transit, access controls, logging, least- privilege principles, vendor oversight, and personnel training. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a security incident affecting your Personal Information, we will notify you and relevant authorities as required by applicable law.

9. Your Privacy Rights and Choices

Subject to applicable law and verification of your identity, you may have the following rights with respect to your Personal Information:

  • Access and portability— to confirm whether we Process your Personal Information and to receive a copy in a portable format;
  • Correction— to correct inaccurate or incomplete Personal Information;
  • Deletion— to request deletion of certain Personal Information, subject to permitted exceptions;
  • Opt-out of sale or sharing— to direct us not to “sell” or “share” Personal Information as those terms are defined under U.S. state privacy laws;
  • Limit use of Sensitive Personal Information — where applicable, to limit our use of SPI to purposes specified by law;
  • Opt-out of targeted advertising and profiling — to opt out of certain profiling in furtherance of decisions that produce legal or similarly significant effects; and
  • Non-discrimination— to exercise your rights without unlawful discriminatory treatment.

To exercise a right, email info@monetafi.com with the subject line “Privacy Rights Request.” We may require information sufficient to verify your identity and the scope of your request, and we will respond within the timeframes required by applicable law. You may designate an authorized agent to act on your behalf; we will require written proof of such authorization. If we decline your request, you may appeal by replying to our response with the word “Appeal.”

10. International Data Transfers

We are headquartered in the United States, and our Services are operated from the United States. If you access the Services from outside the United States, you acknowledge that your Personal Information will be transferred to, stored in, and Processed in the United States and potentially in other jurisdictions where we or our service providers operate. Data protection laws in these jurisdictions may differ from those in your country. Where required by applicable law, we implement appropriate safeguards for cross-border transfers.

11. Children’s Privacy

The Services are intended for use by businesses and their authorized representatives, and are not directed to children under the age of 16. We do not knowingly collect Personal Information from children under 16. If you believe that we have collected Personal Information from a child under 16, please contact us so we may delete it.

12. Third-Party Sites and Services

The Services may contain links to, or enable integrations with, websites, products, and services operated by third parties. This Policy does not apply to those third-party properties, and we are not responsible for their content, features, privacy practices, or the accuracy or handling of any information they collect. We encourage you to review the privacy policies of any third party before providing them with Personal Information.

13. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you by updating the “Last Updated” date above and, where appropriate, through additional notice (for example, by email or through the Services). Your continued use of the Services following the effective date of any update constitutes acceptance of the updated Policy, to the extent permitted by applicable law.

14. Contact Us

For questions about this Policy or our privacy practices, or to exercise any rights described in Section 9, contact us at:

MonetaFi LLC — Privacy
Email: info@monetafi.com (subject: “Privacy”)
20200 W Dixie Hwy, Suite 1205 Miami, FL 33180 United States

See also our Terms of Service.