EFFECTIVE AS OF JULY 3, 2023

Merchant Privacy Policy

For our consumer Privacy Policy click here

SpotOn Transact, LLC (“SpotOn”) is committed to protecting your privacy and are constantly working to give you a safe online experience. This “Privacy Policy” governs SpotOn’s data collection and usage to facilitate products and services offered to Merchants. Our Consumer Privacy Policy includes the data collection and usage of Personal Information collected directly from an individual by SpotOn or from your direct interaction with Merchant products, collected in our Merchant application, and data collected by our Merchants when using our products. By using SpotOn’s Site, you consent to the data practices described in this Privacy Policy. Please read our Privacy Policy for more information.

1. Definitions

  1. “Data” includes both Non-Personal Information and Personally Identifiable Information.

  2. “SpotOn”, “we,” “us” and “our” means SpotOn.

  3. “Merchant” is a business that offers SpotOn products and services

  4. “Non-Personal Information” is any information that is not Personally Identifiable Information (defined below). Non-Personal Information includes, without limitation, Personally Identifiable Information that has been anonymized.

  5. “Personal Information,” “Personally Identifiable Information” or “PII” shall have the same meaning as determined by applicable law but includes only information we receive from your use of the Site. To the extent applicable law does not define Personal Information, it is non-public information we receive from your use of the Site that can be used, alone or in combination with other information in our possession, to identify a particular person/individual. It may include information such as name, address, telephone number and other personal information you provide us.

  6. “Services” products or services that are or may be provided through the Site or that we may otherwise offer online or offline

  7. “Site” refers to the following websites, as applicable, including any related blogs, domains, mobile sites, online services and applications: SpotOn.com, SpotOn and any other applications from SpotOn Transact, LLC.

  8. “You” and “your” mean the individual or entity visiting or using the Site.

2. Personal Information We Collect

We may collect PII from you in a variety of ways, including, but not limited to, when you visit the Site, communicate with us through the Site, provide PII in connection with other activities, products, services, features or resources we make available on the Site or through any services we may offer or events we may participate in online or offline. We may collect your name, mailing address, billing address, phone number, payment information, age, gender, email address, preferences or interests. We may also collect additional information from you depending on the nature of the transaction.

Personal Information You Provide Us

We may collect PII from you in a variety of ways, including, but not limited to, when you visit the Site, communicate with us through the Site, provide PII in connection with other activities, products, services, features or resources we make available on the Site or through any services we may offer or events we may participate in online or offline. We may collect your name, mailing address, billing address, phone number, payment information, age, gender, email address, preferences, interests and preferences. We may also collect additional information from you depending on the nature of the transaction.

  • Identifiers we may collect upon request:
    • First and last name
    • Alias
    • Postal/mailing address
    • Email address
    • Password
    • Telephone number
    • Cellular telephone number
    • Geographic area
    • Geolocation data
    • Title
    • Internet protocol address
    • Documents to verify your identity such as drivers license
    • Your occupation
    • The name of the organization you work for/Name of employer
    • General biographical information that you may provide to us
    • Photograph of you

  • Commercial information we may collect upon request:
    • Transaction information
    • Services purchased, obtained or considered
    • Your purchasing or consuming history or tendencies, along with other preferences and interests
    • Financial Information about you and/or your company
    • Information about your business
    • Business URL
    • Photographs of your business
    • Facebook and social media
    • Any other information required for the provision of the Services such as to respond to an issue on an account

We collect information from you when you (i) visit the site (ii) register on the Site, (iii) fill out forms or fields on the Site or offline, (iv) complete an application for a product or service available through the Site (v) communicate with us by email, mail, text, telephone, or other electronic means, (vi) use the Site or authorize us to access any financial information stored or processed by a third party, or (vii) provide us with Personal Information or other information directly.

We will treat as personal information any item that, either alone or together with other information, we could use to identify an individual. Except as described below, we will not share with third parties any personal information without your permission.

By providing your Personal Information to us, you explicitly agree to our collection and use of such information as described in this Privacy Policy. By providing Personal Information belonging to another person, you expressly represent and warrant that you have the authority and right to do so, and that you obtained all appropriate and required consents, and you also indemnify and hold us harmless for any violation of this warranty.

We may also collect your Personal Information from sources that you have authorized to share with us or that you have authorized us to obtain information from.

We may collect information about you from third parties related to transactions you are contemplating entering into with us or that you have entered into with us.

If you believe we received your personal information from a source without authority to share your personal information with us, please contact us so that we can resolve your complaint.

Information We Automatically Collect

SpotOn may collect information about you automatically when you visit the Site, communicate through the Site, or use any of our online Services. We may automatically receive certain information your browser or mobile device, such as your browser type, the operating system of your device, the URL of the site from which you came and the URL of the site you visit when leaving the Site or any of our online Services, the equipment you use to access the Site, the unique identifier of your mobile device and your activities on the Site, such as the webpages you view and how you interact with those webpages. We may also receive your IP address and the name of your internet service provider (“ISP”) or your mobile carrier. Depending on your device’s settings, we may also receive location data and other types of information sent from third party services or GPS-enabled devices.

As you use the Site or any of our online Services, we may also collect information about such usage and your actions on the Site, for example, pages you viewed, access times, and how long you spent on a page. We may use cookies to collect such information, as described in more detail below. We may anonymize and aggregate performance information and site usage for the purposes of improving our website and user experience by converting Personal information such as cookies and IPs to Non-Personal aggregated information.

3. Cookies and Tracking Technologies

The Site or our online Services may send a “cookie” to your computer. A cookie is a small file, typically of letters and numbers, downloaded onto a device such as a computer or mobile device when you access our websites. For more information about cookies or local storage, including how to see what cookies have been set and how to manage, block and delete them, see:http://www.allaboutcookies.org/. A cookie cannot read data off your hard disk or read cookie files created by other sites. Cookies do not damage your system. Cookies allow us to recognize you as a user when you return to the Site or use the online Services using the same computer and web browser. We use cookies to identify which areas of the Site or online Services you have visited. We also may use this information to better personalize the content you see on the Site or online Services. SpotOn does not store unencrypted Personal Information in the cookies. We also do not link Non-Personal Information from cookies to your Personal Information.

To help us optimize the Site or for marketing purposes, we may allow other authorized third parties to place or recognize unique cookies on your browser. Any information provided to third parties through cookies will be for enhancing your user experience by providing more relevant marketing. Third party services and tools we use, which may send cookies to users of the Site and may collect information from users.

Some browsers may allow you to manage the storage of cookies on your device. If supported by your browser, you may set your browser to refuse all cookies (or, sometimes all third-party cookies) or to alert you when a cookie is placed. However, if you select these settings, you may be unable to access certain parts of the Site or the online Services. Unless you have adjusted your browser setting to refuse cookies, the Site and online Services will issue cookies. For more information about how to manage your cookies preferences, use the ‘help’ menu of your web browser or explore the customer support sections of your web browser. To opt-out of all cookies or certain advertising cookies, visit the company website for your browser for instructions.

You can opt-out of receiving personalized ads from advertisers and ad networks that are members of the Network Advertising Initiative (“NAI”) or who follow the Digital Advertising Alliance (“DAA”) Self-Regulatory Principles for Online Behavioral Advertising using their respective opt-out tools. The NAI's opt-out tool can be found here: http://www.networkadvertising.org/choices/. and the DAA's opt out tool can be found here: http://www.aboutads.info/choices/.

In addition, your mobile devices may offer settings that enable you to make choices about the collection, use, or transfer of mobile app information for online behavioral advertising (for example, Apple iOS’ Advertising ID and Google Android’s Advertising ID). Please note that opting out does not prevent the display of all advertisements to you.

Embedded Pixels

We may use on the Site embedded pixel technologies on selected pages for the purposes of identifying unique user visits to the Site as opposed to aggregate hits. In addition, embedded pixels or other technologies may be used in emails to provide information on when the email was opened to track marketing campaign responsiveness; information collected using these technologies may be associated with your email address.

Flash Cookies

We may use flash cookies, also known as “local shared objects,” on the Site if it employs or in the future employs flash technology. Flash cookies are small files similar to browser cookies and are used to remember the site’s settings to personalize the look and feel of the site. Like normal cookies, flash cookies are represented as small files on your computer.

Embedded URLs

We may also use a tracking technique that employs embedded URLs to allow use of the Site without cookies. Embedded URLs allow limited information to follow you as you navigate the Site but is not associated with your Personal Information and is not used beyond the session.

Widgets

The Site may include widgets, which are interactive mini programs that run on our Site to provide specific services from another company (e.g., links to bookmarked sites). Some information, such as your email address, may be collected through the widget. Cookies may also be set by the widget to enable it to function properly. Information collected by this widget is governed by the privacy policy of the company that created it.

4. How we use and share your personally identifiable information

We will use your Personal Information to provide the products & services that your personal information was shared with us to fulfill. SpotOn may use personal information for the following purposes:

  1. To improve customer service: YYour information helps us to more effectively communicate with inquiries and existing customers, and to respond to your customer service requests and support needs.

  2. To personalize user experience: We may use information in the aggregate to understand how our users as a group use the Services and resources provided on the Site.

  3. To improve the Site: We continually strive to improve our Site and the Services based on the information and feedback we receive from you.

  4. To provide products or services and to process transactions: Except as otherwise expressly provided in this Privacy Policy, we will use Data only for the purpose of fulfilling our duties and providing the Services. SpotOn may use Non-Personal Information for statistical analysis, product development, research, or other purposes. We may use the information that you provide about yourself or that you have provided to our clients for the purpose of providing and fulfilling the Services. We do not share this information with outside parties except to the extent necessary to provide the Services.

  5. To send periodic mail, emails and surveys: The email address you provide for the Services will only be used to send you information, newsletters, surveys and updates pertaining to the Services requested, provided or that we think you may be interested in. It may also be used to respond to your inquiries and/or other requests or questions.

  6. To develop new products or services: We use your Personal Information and Non-Personal Information for research and commercial purposes. The information we collect may be used to develop new products or services. Except as otherwise provided in this Privacy Policy, we may use your Personal Information and Non-Personal Information internally or, among other things, to offer our own or third-party products and services. Only SpotOn, its subsidiaries, its suppliers and contractors involved in distributing/providing the new product or service will have access to your Personal Information. Our subsidiaries, suppliers and contractors will be required to use any PII we provide to them only for that intended purpose and subject to the terms of this Privacy Policy.

  7. Fulfillment of Obligations: Comply with contractual obligations, relevant industry standards and our policies.

  8. For marketing: Except as otherwise expressly provided for in this Privacy Policy or except as prohibited by applicable law, SpotOn may use your Personal Information and Non-Personal Information to enhance its networking, marketing, social, and recruiting activities, and for other similar business purposes. SpotOn may also use your Personal Information and Non-Personal Information to contact you on behalf of external business partners about a particular offering that may be of interest to you. In these cases, your Personal Information is not transferred to the third party. We may also use Personal Information to provide you information regarding new products or services or to post testimonials from you related to our products or services. Personal Information is not shared with entities outside of SpotOn other than service providers who assist us in carrying out these business functions. SpotOn does not use or disclose sensitive Personal Information, such as race, religion, or political affiliations, without your explicit consent.

  9. Compliance with applicable law: We may disclose your Personal Information as we may in our sole discretion determine is necessary or reasonably required to comply with the law, applicable regulations, court orders or subpoenas, to enforce our Terms of Use, or to protect our rights, property or safety, or the rights, property or safety of others.

  10. Security: Mitigate fraud, enhance the security of the Site and manage institutional risk.

  11. Change in the Site Ownership: IIf ownership of the Site or of SpotOn changes, whether in whole or in part, information collected through the Site and the Services about you may be transferred to the new owner of the Site and/or SpotOn, as the case may be, and any Services can continue. In that case, your Personal Information would remain subject to the terms and conditions of the applicable version of the Privacy Policy.

  12. Payment Processing: For processing payments related to the products and services we provide you.

  13. Cooperation with Third Parties. As part of the provision of the Services, we may provide access to information you provide to facilitate the provision of Services to you, including, without limitation, the processing of credit applications with us and collections.

5. Consent to electronic communications

We may use your email address to send you messages notifying you of important changes to the Services or special offers we think you may be interested in. Further, we may contact you by telephone if you provide us with your telephone number, to communicate with you regarding the Services we are providing to you. If you do not want to receive email messages or telephone calls, please contact us. Some communications related to ongoing transactions or the enforcement of terms you have agreed to related to the provision of Services may not be subject to your opting out of or choosing not to receive.

In order to receive our Services, it may be necessary, as we may determine, for you to consent to transacting business with us electronically. We may also require you to consent to giving us certain disclosures electronically, either through the Site or to the email address you provide to us. By entering into any agreement for any of the Services, you agree to receive electronically all documents, communications, notices, contracts and agreements (collectively, “Communications and Agreements”) arising from or relating to your use of the Site and the Services, including your registration on the Site, your use of the Services, and matters involving payment for the purchase of our Services.

  1. Opt-Out: You may revoke your consent by contacting us by email at privacy@spoton.com

  2. Scope of Consent: Your consent to receive Communications and Agreements and transact business electronically, and our agreement to do so, applies to any transactions to which such Communications and Agreements apply.

6. Retention and Storage of personal information

We retain your Personal Information for as long as necessary to fulfill the purpose for which it was collected and to comply with applicable laws. We use reasonable security precautions to protect your information while in storage.

To determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your Personal Information, the purposes for which we process your personal information, whether we can achieve those purposes through other means, and applicable legal requirements.

7. Security

We will use commercially reasonable methods to keep your Personal Information securely in our files and systems. Payment method data is secured using PCI-DSS standards.When credit card numbers are transmitted through a field in a form on the Site requesting credit card numbers, it is protected through the use of encryption, such as the Secure Socket Layer (SSL) protocol.

8. Do Not track

Your browser may provide you with the option to send a “Do Not Track” signal to websites you visit. This signal is used to request that websites not send the requesting device cookies, but websites have no obligation to respond to such signal or to modify their operation. At the current time, the Site is not programmed to recognize Do Not Track signals, so the Site will not treat you differently if we receive such signals from your browser and we may not comply with Do Not Track settings on your browser.

9. Links to Other Sites

The Site and the online Services may contain links to other websites. SpotOn is not responsible for the actions, practices, or content of websites linked to or from the Site or the online Services. You understand such websites may require you to agree to their terms of use and that we have no control over these terms. As always, you understand it is your responsibility to verify your legal use of a website and use of information from the website with the corresponding website owner.

10. Age of Consent

This Site is only intended for persons 18 years of age or older.The Site does not target and is not intended for children under the age of 13, and SpotOn will not knowingly collect Personal Information directly from them. If SpotOn discovers that a child has provided personal data directly through the Site, SpotOn will eliminate that data. If you are under the age of 18, you must ask a parent or legal guardian for permission prior to submitting any information to this Site.

If you have knowledge that a child 13 years of age or younger has submitted Personally Identifiable Information to us, please contact us and we will delete the Personal Information collected belonging to that child. You may contact us via email or by writing to us at the address below. Parents and guardians can also email us at privacy@spoton.com, but before any information is disclosed, the parent will be required to provide verification of his/her identity and authority related to any request. We will only send the information to the parent email address in the registration file.

11. CAN-SPAM Compliance Notice

SpotOn fully complies with the federal CAN-SPAM Act. You can always opt out of receipt of further email correspondence from us.

12. California Privacy Rights

Under Section 1798.83 of the California Civil Code, residents of California can obtain certain information from companies with whom they have an established business relationship. That information is about the Personal Information those companies have shared with third parties for direct marketing purposes during the preceding calendar year. The law requires companies to inform consumers about the categories of Personal Information shared with third parties, the names and addresses of those third parties, and examples of the services or products marketed by those third parties. To request a copy of the information disclosure provided by SpotOn under Section 1798.83 of the California Civil Code, please contact us via email to privacy@spoton.com.

13. California Consumer Privacy Act (“CCPA”)

To the extent applicable, the following terms in this Section 18 apply:

This Privacy Policy for California residents supplements the information contained above in our general privacy policy and applies solely to visitors, users and others who reside in the State of California. Any inconsistent terms in any other sections of the Privacy Policy will be superseded by this Section for California residents.

Your Rights Under the CCPA

To the extent applicable to SpotOn, under the CCPA, California residents are granted the following rights:

  1. The right to delete personal information businesses have collected from them (subject to some exceptions);
  2. The right to correct inaccurate personal information that businesses have about them;
  3. The right to know what personal information businesses have collected about them and how they use and share it;
  4. The right to opt-out of the sale of their personal information;
  5. The right to opt-out of the sharing of their personal information for cross-context behavioral advertising;
  6. The right to limit the use and disclosure of sensitive personal information collected about them; and
  7. The right to non-discrimination for exercising their CCPA rights.

When receiving a request, we will verify that the individual making the request is the resident to whom the Personal Information subject to the request pertains. California residents may exercise their rights themselves or may use an authorized agent to make requests to disclose certain information about the processing of their Personal Information or to delete Personal Information on their behalf. If you use an authorized agent to submit a request, we may require that you provide us additional information demonstrating that the agent is acting on your behalf.

Categories of Personal Information We Collect

We may collect information as set forth above and also information that identifies you, your household or your device or is reasonably capable of being connected with or linked to you, your household or your device. “Personal Information” does not include public information available from government records, de-identified or aggregated information.

Category of Personal Information CollectedCategories of Sources from which the Information was CollectedBusiness or Commercial Purpose(s) for which Information is CollectedCategories of Third Parties to whom this type of Personal Information is Disclosed for a Business PurposeCategories of Third Parties to Whom this Type of Personal Information is Sold or Shared for Cross Contextual Advertising
IdentifiersWe may collect this type of information from: You, Cookies and Tracking Technologies, Third party social media companies, Third party business partners, such as data analytics providers, advertising networks, or joint marketing partners. To improve customer service To personalize user experience To improve the Site To provide products or services and to process transactions To send periodic mail, emails and surveys To develop new products or services For fulfillment of Obligations To comply with contractual obligations, relevant industry standards and our policies For marketing For Compliance with applicable law For Security Change in the Site Ownership For Payment Processing We may disclose this type of information to: Service Providers, Third parties we partner with for contests, sweepstakes, or promotions, Third party advertising and analytics companies, Third parties who may acquire your information as a result of a merger, acquisition or otherwise ownership transition Third parties or affiliated companies when you agree to or direct that we share your information with them Other third parties (including government agencies) as required by law or in connection with court proceedings (such as pursuant to subpoenas or court orders) Third party advertising, analytics, and other similar marketing business partners may have access to this data, and this may be considered a “sale” or “share” under the CCPA and CPRA and other laws under certain circumstances.
Any categories of personal information described in Section 1798.140YouAllow you to participate in features we offer or to provide related customer services recognize you across devices tailor content recommendations and offers we display to you provide you with information, products, or services that you have requested or that we think may interest you investigate and prevent fraudulent transactions and other illegal activities or activities that violate our policies process your registration, including verifying your information is active and valid contact you with regard to your use of our product Service providers who assist us in carrying out these business functions.N/A
Commercial information such as records of personal or commercial property for restaurants ownersWe may collect this type of information from: You, Third party social media companies, Third party business partners such as data analytics providers, advertising networks, or joint marketing partners To support the underwriting process for processing account and/or loans Service providers to support the underwriting process N/A
Internet or other electronic network activity information We may collect this type of information from: Cookies and Tracking TechnologiesAllow you to participate in features we offer or to provide related customer services Recognize you across devices Tailor content recommendations and offers we display to you Provide you with information, products, or services that you have requested or that we think may interest you Investigate and prevent fraudulent transactions and other illegal activities or activities that violate our policies Service providers who assist us in carrying out these business functionsThird party advertising, analytics, and other similar marketing business partners may have access to this data, and this may be considered a “sale” or “share” under the CCPA and CPRA and other laws under certain circumstances.
Geolocation data We may collect this type of information from: Cookies and Tracking Technologies For delivery services at restaurants to facilitate the service Service providers who assist us in carrying out these business functions N/A
Inferences drawn from any of the information identified above to create a profile about a You We may collect this type of information from: You, Cookies and Tracking Technologies, Third party social media companies, Third party business partners, such as data analytics providers, advertising networks, or joint marketing partners, Third party data resellers. N.Service providers who assist us in carrying out these business functions N/A
A consumer’s social security, driver’s license, state identification card, or passport number.You For identity verification, fraud prevention and to provide to our bank sponsors, acquirers for loans/payment processing Service providers N/A
A consumer’s account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account.YouTo process transactions we collect card data. Password and credentials may be captured if we have a loyalty or wallet accountService Providers N/A
A consumer’s precise geolocation.YouWe collect precise data/address for delivery services at restaurants but only to facilitate the service Service providers N/A
The contents of a consumer’s mail, email, and text messages unless the business is the intended recipient of the communicationN/AN/AN/AN/A

Retention

We retain your Personal Information for as long as necessary to fulfill the purpose for which it was collected and to comply with applicable laws. We use reasonable security precautions to protect your information while in storage.

To determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your Personal Information, the purposes for which we process your personal information, whether we can achieve those purposes through other means, and applicable legal requirements.

How We Use Your Information

See above for how we use your information. Except as otherwise stated in this Privacy Policy, we will not collect additional categories of Personal Information or use the Personal Information we collected for materially different, unrelated, or incompatible purposes without providing you notice.

Requests to Know

You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the prior 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:

  • The categories of Personal Information we collected about you.

  • The categories of sources for the Personal Information we collected about you.

  • The business or commercial purpose for collecting or selling your Personal Information.

  • The business or commercial purpose for collecting or selling your Personal Information.

  • The categories of third parties with whom we share your Personal Information.

  • The specific pieces of Personal Information we have collected about you

  • If we sold or disclosed your Personal Information for a business purpose, which we do not do and will not do, two separate lists disclosing:
    • In the case of a sale/share, the categories of Personal Information sold/shared about you and the categories of third parties to whom the Personal Information was sold/shared, by category of Personal Information for each category of third parties; and
    • In the case of disclosure for a business purpose, the categories of Personal Information that were sold, shared, or disclosed for a business purpose and if Personal Information has not been sold, shared, or disclosed for a business purpose, that we did not do so.

We are not required to (i) retain your Personal Information if collected for a single one-time transaction if, in the ordinary course of business, that information would not be retained and (2) re-identify or otherwise link any data that, in the ordinary course of business, is not maintained in a way that would be considered Personal Information.

Requests to Delete

You have the right to request that we delete any of your Personal Information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your Personal Information from our records, unless an exception applies, which we will disclose to you.

We are not required to grant your deletion request if retaining the Personal Information is necessary for us or our service providers to:

  1. Complete the transaction for which the Personal Information was collected, fulfill the terms of a written warranty or product recall, provide a good or service requested by you, or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between us and you.
  2. Detect security incidents, protect against malicious, deceptive, fraudulent or illegal activity; or prosecute those responsible for that activity.
  3. Debug to identify and repair errors that impact existing intended functionality.
  4. Exercise free speech, ensure the right of another consumer to exercise that consumer’s right of free speech, or exercise another right provided for by law.
  5. Comply with the California Electronic Communications Privacy Act.
  6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest when the deletion of the public information is likely to render impossible or seriously impair the achievement of such research, if the consumer has provided informed consent.
  7. For solely internal uses that are reasonably aligned with your expectations based on your relationship with us.
  8. Comply with a legal obligation.
  9. Internally make otherwise lawful uses of your Personal Information that are compatible with the context in which you provided your Personal Information.

Right to Correct

You have the right to request to the extent that we maintain inaccurate personal information about you, to correct that inaccurate personal information, taking into account the nature of the personal information and the purposes of the processing of the personal information.

How to Submit a Request

To request this information, please submit a verifiable consumer request to us by either:

  • Emailing us at privacy@spoton.com and submit your request in the body of the email with the subject heading: “CCPA Consumer Request.”

Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your Personal Information. We are not required to provide you with Personal Information more than twice in a 12-month period.

We will not be able to respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you.

We will try to respond to your request within forty-five (45) days of receipt of your written request. If we require more time (up to 90 days), we will inform you of the extension period in writing. We will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Information that is machine-readable and should allow you to transmit the information from one entity to another entity without hindrance, specifically by electronic mail communication.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

Opt-Out of Sale/Share Request

Once you make an opt-out request, we will wait at least twelve (12) months before asking you to reauthorize Personal Information sharing with third parties. However, you may change your mind and opt back into Personal Information sharing with third parties at any time by emailing us at privacy@SpotOn.com.

We will only use Personal Information provided in an opt-out request to review and comply with the request. We will act upon your opt-out request within 15 days of receipt.

Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:

  • Deny you goods or services, except to the extent that providing the Services requires the disclosure of Personal Information that you have decided not to disclose or allow us to use for the purpose of providing the Services.

  • Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.

  • Provide you a different level or quality of goods or services.

  • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

However, we may offer you certain financial incentives permitted by the CCPA thatcan resultin different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your Personal Information's value and contain written terms that describe the program's material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.

14. Your Nevada Privacy Rights

Nevada law (SB 220) permits customers in Nevada to opt-out of the sale of certain kinds of personal information. A sale under Nevada law is the transfer of this personal information to third parties for monetary consideration so these third parties can then re-sell or license the sold information. We do not sell your Personal Information to third parties as defined in Nevada law. If you are a Nevada resident and wish to opt-out of the sale of your personal information, should we change our practices in the future, you must send a request by email to privacy@SpotOn.com.

15. NOTICE TO VIRGINIA USERS

We will use commercially reasonable methods to keep your Personal Information securely in our files and systems. When credit card numbers are transmitted through a field in a form on the Site requesting credit card numbers, it is protected through the use of encryption, such as the Secure Socket Layer (SSL) protocol.

We set forth above in our Privacy Policy the categories of personal data we process, the purpose for processing personal data, the categories of personal data shared, and the categories of third parties with whom personal data is shared.

If you are a Virginia Consumer and would like to exercise your rights pursuant to the Virginia Consumer Data Protection Act (VCDPA), and any implementing regulations adopted thereunder, please send a request by email to privacy@SpotOn.com to submit a request.

Virginia Consumers have the following rights, all subject to the meanings and exceptions set forth in the VCDPA:

  • To confirm whether we are processing your Personal Data and request to access such data ("Right to Access").

  • That we correct inaccurate Personal Data we hold about you (“Right to Correct”).

  • That we delete the Personal Data provided by you or obtained about you ("Right to Delete").

  • To obtain a copy of the Personal Data previously provided by you to us and, to the extent feasible, in a readily usable format to allow data portability (“Right to Obtain”).

  • To opt- out of the processing of your Personal Data for the purposes of targeted advertising (“Right to Opt-Out of Targeted Advertising”).

VCDPA Appeals

Pursuant to the VCDPA, if, for any reason, you would like to appeal our decision relating to your request, you have the right to submit an appeal and can do so by sending a request by email to privacy@SpotOn.com to submit a request or call us toll-free at 877-814-4102 to submit a request. Please include your full name, the basis for your appeal, and any additional information to consider.

16. Notice to European Users

This Privacy Policy for users in the European Economic Area (“EEA”) supplements the information contained above in our general privacy policy and applies solely to all visitors, users and others who are located in the EEA. Any inconsistent terms in any other sections of the Privacy Policy will be superseded by this Section for EEA residents.

Personal Information.

References to personal information or Personally Identifiable Information in this Privacy Policy are equivalent to “personal data” governed by the General Data Protection Regulation (EU/UK) (collectively, “GDPR”).

Controller.

SpotOn is the controller of your personal information covered by this Privacy Policy for purposes of the GDPR. Our contact information is provided below.

Legal Bases for Processing.

We use your personal information only as permitted by law. Our legal bases for processing personal information described in this Privacy Policy are as follows:

  • To provide Services to you.
  • For research and development.
  • To send you marketing communications.
  • For compliance, fraud prevention and safety.
  • To create anonymous data.
  • To comply with applicable law.
  • Processing of personal information with your consent.

Your rights

The GDPR gives you certain rights regarding your personal information. If you are located within the EEA, you may ask us to take the following actions in relation to your personal information that we hold:

  • Access.Provide you with information about our processing of your personal information and give you access to your personal information.
  • Correct.Update or correct inaccuracies in your personal information.
  • Delete.Delete your personal information.
  • Transfer.Transfer a machine-readable copy of your personal information to you or a third-party of your choice.
  • Restrict.Restrict the processing of your personal information.
  • Object.Object to our reliance on our legitimate interests as the basis of our processing of your personal information that impacts your rights.

You may submit these requests by:

  • Emailing us at privacy@SpotOn.com. Please include in the subject heading of your email: “GDPR Request.”

We may request specific information from you to help us confirm your identity and process your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to legal restrictions.

If you would like to submit a complaint about our use of your personal information or our response to your requests regarding your personal information, you may contact us by email or mail, as specified above, or submit a complaint to the data protection regulator in your jurisdiction. You can find your data protection regulator here:

Cross-Border Data Transfer

Personal information voluntarily submitted to SpotOn online, via electronic communication, or otherwise, may be maintained or accessed in servers or files in the United States of America, which the European Union has not deemed to provide “adequate” privacy protection. If you do not consent to having your information processed and stored in the United States of America, please do not provide it to SpotOn.

17. Amendments

SpotOn reserves the right to change the Privacy Policy from time to time at its sole discretion with or without notice. Any revisions are effective immediately once posted on the Site. Your continued use of the Site shall indicate your acceptance of the revision. Revisions to the Privacy Policy regarding the use of Personal Information are not retroactive.

18. European Union Disclosure

Personal Information voluntarily submitted to SpotOn online, via electronic communication, or otherwise, may be maintained or accessed in servers or files in the United States of America, which the European Union has not deemed to provide “adequate” privacy protection. If you do not consent to having your information processed and stored in the United States of America, please do not provide it to SpotOn. SpotOn contends that the General Data Protection Regulation (EU) 2016/679 does not apply to its processing of personal information and that it is not within the jurisdiction of the EU. All processing of PII is governed by the applicable laws of the United States of America.

Contact

If you have any questions about the Privacy Policy, or to report a violation of the Terms of Use, please contact us at privacy@SpotOn.com or by mail at:

info-image
SpotOn
Email us at: privacy@SpotOn.com
See how your business can succeed with SpotOn
Spoton logo

© SpotOn Transact, LLC. 2023. All Rights Reserved. SpotOn Transact, LLC. is a Registered Partner/ISO ofMerrick Bank, South Jordan, UT & Wells Fargo Bank,N.A., Concord, CA & Elavon Inc., Georgia [a wholly owned subsidiary of U.S. Bancorp, Minneapolis, MN].

Help Center
24/7 resources
help center logo

Please get in touch if you need one-to-one assistance getting started with new products or have questions for our Sales team.

Help Centerarrow