Parafin, Inc. Privacy Policy

Please read this document carefully.

1. Introduction

Last updated November 21, 2023

Parafin, Inc. (“Parafin”, “us”, “our” or “we”) respects your privacy and is committed to being transparent with you about how we handle Personal Information.

Privacy laws in Canada generally define "Personal Information" as any information about an identifiable individual, which includes information that can be used on its own or with other information to identify, contact, or locate a single person.

We will only use your Personal Information in accordance with this Privacy Policy unless otherwise permitted or required by applicable law. We take steps to ensure that the Personal Information that we collect about you is adequate, relevant, not excessive, and used for limited purposes.

This Privacy Policy ("Policy") applies to information we collect, use, or disclose:

(a) about users of the Parafin website or widgets (the “Website”);

(b) when we communicate with you via email, text, and other electronic messages from Parafin; and

(c) when you use Parafin’s tools and our product or service offerings (collectively “Services”).

This Policy also describes the types of information we may collect from you or that you may provide when you visit the Website and our practices for collecting, using, protecting, and disclosing that information, and how you can exercise your privacy rights and choices.

Parafin's Services are designed to provide small businesses access to capital to help them grow. Your access to our Services is also governed by the Merchant Capital Advance Agreement, depending on the type of Service. Capitalized terms used but not defined in this Privacy Policy are defined in our Merchant Capital Advance Agreement.

Please read this Privacy Policy carefully prior to accessing and using the Parafin Website or Parafin's Services in order to understand our policies and practices for collecting, using, disclosing, and storing Personal Information. If you do not agree with our policies and practices, your choice is not to use our Website or Services. By accessing or using this Website or applying for or using our Services, you indicate that you understand, accept, and consent to the practices described in this Policy. This Policy may change from time to time, as described in Section 7(f). If you have any questions, please contact us at: privacy@parafin.com.

2. Information We Collect

The types of Personal Information that Parafin collects differs depending on how you’re using our Website and Services, and includes:

(a) Personal Information: Information which we can reasonably use to directly or indirectly identify you, such as your name, address, e-mail address, telephone number, age, birth date, social insurance number, Account Information (as defined below), driver’s licence number, passport number, gender, credit card numbers, information about your assets, income, or personal finances, credit records, loan records, driving record, insurance and transaction history, Internet protocol (IP) address used to connect your computer to the Internet, user name or other similar identifier, billing, payment, and account information, and any other identifier we may use to contact you online or offline.

(b) “Account Information” refers to the capital and other features, like your account dashboard and the ability to make manual payments, which you’ll have access to under the Merchant Capital Advance Agreement. To use these portions of the Services, you’ll need to provide us with certain Personal Information, such as your name and email address, and bank account information.

(c) Non-Personal Information: Information that does not directly or indirectly reveal your identity or directly relate to an identified individual, such as demographic information, or statistical or aggregated information. Statistical or aggregated data does not directly identify a specific person, but we may derive non-personal statistical or aggregated data from personal information. For example, we may aggregate personal information to calculate the percentage of users accessing a specific Website feature.

(d) Technical Information: Information such as your login credentials, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, or information about your internet connection, the equipment you use to access our Website, and usage details.

(e) Internet Activity: Your browsing, click history and other internet, Website or platform usage activity, including information about how you navigate within our Services, interact with our offers, and which elements of our Services you use the most.

3. How We Collect Information

We use different methods to collect your information, including through:

(a) Direct Interactions With you: In certain circumstances, we collect data directly from you. For example, you may voluntarily provide us with Personal Information in order for us to evaluate your application or render our Services. Direct interactions with you also include Personal Information that (i) you provide to us when you submit Personal Information to us when we validate/verify your identity, (ii) is included as part of your banking details when we validate your account, or (iii) is connected with or a part of your banking details that you provide to us so that we can determine if you have additional or increased offers for our Services.

(b) Your Contributions: You may choose to provide us with other Personal Information. For example, we may collect additional information when you fill out a survey, participate in a Parafin-sponsored request for feedback, request customer support, or otherwise communicate with us. Parafin will collect all messages, posts, and comments you submit to Parafin's customer service team.

(c) Automated Technologies or Interactions: We automatically collect certain information from your interactions with our Website and Services.

(i) Website Analytics. We may monitor and analyze web traffic from your usage of the Website and the Services. We may also map how frequently you interact with different areas of the dashboard and other parts of the Parafin Website and Services and track how you interact with any offers we make regarding our Website and Services. Parafin may utilize third party services in connection with web analytics, such as Google Analytics or FullStory.

(ii) Usage Data. Parafin logs usage information when you visit and use our Services or Website. This information may include IP address, browser type, operating system, and other information about the use of our Website, such as the pages you viewed, when you viewed them, and links that were clicked.

(iii) Customer Service Data. Parafin may log information about you when you reach out to Parafin regarding customer service. This information may include your business name, first name, last name, email address, phone number, bank account details, or other information that you provide us regarding your customer services requests and contacts.

(iv) Cookies and Similar Technology. Parafin may collect information about you through the use of cookies and other similar technologies. Cookies are pieces of data in the form of text files that your browser stores on your hard drive and sends back to us when making requests, and similar technologies.

(v) Web Beacons. Portions of our Services may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit Parafin to perform certain analytics, such as to count users who have visited those pages or opened an email and for other related Website statistics (for example, recording the popularity of certain Website content and verifying system and server integrity).

(vi) Approximate Location. We may receive and process information about your approximate location. For example, we may be able to determine your approximate location from your IP address and other information about you. Parafin does not ask for or track any precise location-based information.

(d) Third Parties: In some cases, the online platforms that make our Services available ("Platform") share data with us about you, which we use to help determine eligibility for our Services. Platforms may have Personal Information about you that they share with Parafin to offer you our Services ("Platform Data"). The Platform Data shared with Parafin is subject to the given Platform's privacy policy and Parafin has no control over those terms or the Platform’s privacy or data protection practices. If you are unsure about or unclear about what data a Platform may collect about you or your business please contact the Platform for more information. Platforms that share Personal Information about you with Parafin have represented to Parafin that they have received your consent to share such Platform Data. If you need more information about the consent you provided to your Platform enabling the sharing of Platform Data about you or your business with Parafin, please contact the respective Platform.

Your Platform might think our Services are a great fit for you or your business. They obtain your consent and then may share with us certain categories of information that allow us to better understand and evaluate if you or your business is eligible for our Services. These categories include your legal business name and your business contact information, your business location (e.g., your city, state, and zip code), your banking information, and your email address.

As you obtain Services from Parafin, we may need to validate, verify, or screen your account in accordance with our obligations under applicable laws and regulations. When you provide this data to Parafin and we use it to validate your account as required under those laws and regulations, you may agree to allow our Services to interact with third party services (such as Plaid regarding validating, verifying, or reviewing your bank account information). The third parties that we use to validate your data may return additional Personal Information to us about you that we will retain.

The information you allow Parafin to access varies by the type of service, and it is affected by the privacy settings you and those that you are connected with establish while using such services. Third-party services are operated, controlled, and maintained by third parties that are not operated, controlled, or maintained by Parafin. We recommend that you read the terms of use and privacy policies of those third-party services to understand how they collect, use, and share your Personal Information with us or other third parties.

4. How We Use Personal Information We Collect

Our primary purposes for using your Personal Information are to provide you with a smooth, efficient, and customized experience, for customer support, research and service development, and to keep our Services and customers safe and secure.

Specifically, we may use your information for the following business purposes:

(a) To provide and improve our Services. We use Personal Information that we collect about you to allow you to access our Services, to provide you with the Services you request, and to improve and customize Parafin's Services.

(b) For customer support. We use Personal Information to investigate, respond to, and resolve customer queries, send you technical notices and security alerts, and provide other support and administrative services.

(c) For research and service development. We use Personal Information to conduct market research and to develop new services in order to provide you with a better experience and to drive growth in our business.

(d) For legal and security purposes. We use Personal Information to prevent, detect, investigate, and take measures against criminal activity, fraud, misuse of, or damage to our company, Services, or network, and other threats and violations to Parafin's or a third party's rights.

(e) As consented to or described at the point of collection. We may use Personal Information for any other purpose with your consent or in any other way we may describe when you provide the information.

(f) Third party services in connection with legal obligations. As required under applicable laws and regulations, we may need to validate, verify, or screen your bank account or identity in order to provide certain Services. We may use third party services regarding validating, verifying, or reviewing your bank account information. These third parties are not operated, controlled, or maintained by Parafin. As we state above, we recommend that you read the terms of use and privacy policies of those third party services to understand how they collect, use, and share your Personal Information with us or other third parties.

5. How We Share Personal Information We Collect

Parafin only shares your Personal Information with the applicable Platform or third parties under the circumstances described below. We do not sell or otherwise disclose Personal Information we collect about you for monetary or other valuable consideration.

(a) With Your Consent

Parafin may disclose your Personal Information to a third party when you give us consent to do so, at your direction, to fulfill the purpose for which you provide it, or for any other purpose disclosed by us when you provide the information. For example, this may occur when we complete a transaction at your request.

(b) With Service Providers

We may share Personal Information with vendors, consultants, payment processors, and other service providers that provide us with certain services and process Personal Information on our behalf. These services may include providing customer support, performing business and sales analysis, supporting our Website functionality, facilitating payment processing, and supporting contests, surveys, and other features offered on our Platform.

These service providers are not permitted to use your Personal Information for any other purpose, and their use of such Personal Information will be subject to appropriate confidentiality and security measures.

(c) With Platforms

We work with Platforms to offer you helpful and beneficial small business services. We share information about your use of our Services with the applicable Platform for a number of reasons, including to assess the strength of the program, your success using our Services, to improve our Services with the Platform, and to assist with customer service requests.

(d) With Advertising and Analytics Partners

We may share usage data with third-party advertisers, advertisement networks, and analytics providers through cookies and other similar technologies. These third parties may collect information sent by your computer, browser, or mobile device in response to a request for content, such as unique identifiers, your IP address, or other information about your computer or device.

(e) With Affiliates

We may share Personal Information with our affiliates, and other companies under common control and ownership, subject to the terms of this Privacy Policy.

We may also share your Personal Information in connection with a substantial corporate transaction, such as a sale of our business, a divestiture, merger, consolidation, or asset sale, in the event of bankruptcy, or in preparation for any of these events. Any other entity which buys us or becomes part of our business will have the right to continue to use your Personal Information, but only in the manner set out in this Privacy Policy unless you agree otherwise.

(f) Legal Disclosures

Parafin may be required to disclose Personal Information if directed by a court of law or other governmental entity. Without limiting the foregoing, we reserve the right to disclose such information in accordance with applicable laws where we have a good faith basis to believe that such action is necessary to:

(i) comply with applicable laws, regulations, court orders, government and law enforcement agencies’ requests;

(ii) protect and defend Parafin’s or a third party's rights and property, or the safety of Parafin, our users, our employees, or others; or

(iii) prevent, detect, investigate and take measures against criminal activity, fraud and misuse or unauthorized use of our Services or Website and/or to enforce our Terms of Use or other agreements or policies.

To the extent required by law, we will give you prior notice before disclosing your information in response to such a request.

6. Cross-jurisdictional Transfers

By providing us with personal information, you acknowledge and agree that your Personal Information may be transferred to other jurisdictions for processing and storage by us or one of the parties listed under Section 5, including on servers located across Canada and in the United States, where laws regarding the protection of Personal Information may be less stringent than the laws in your jurisdiction. Further, your Personal Information may be accessible to law enforcement, national security authorities, and the courts of such jurisdictions. Where necessary to make such transfers, we will comply with our legal and regulatory obligations in relation to the Personal Information.

7. Your Rights and Choices

Parafin gives you choices with respect to our use of your Personal Information. These choices include accessing and correcting your Personal Information, withdrawing your consent, as well as choosing what communications you would like to receive from us. Depending on your location, you may have additional rights related to your Personal Information.

(g) Data Privacy Requests and Verification

You can request to access or correct your Personal Information by emailing us at privacy@parafin.com.

If you would like to make a request under the privacy laws of your jurisdiction, which may also include a right to erasure, a right to Personal Information portability, and a right to withdraw consent, please let us know where you reside and which rights you’d like to exercise.

San Francisco, CA 94105

To protect your privacy, we need to verify your identity before we process any such request. Depending on the nature of the request, we may also need to obtain additional information necessary for us to verify your identity.

We have procedures in place to receive and respond to complaints or inquiries about our handling of personal information, our compliance with this policy, and with applicable privacy laws. To discuss our compliance with this policy please contact us using the contact information listed above.

Where you have provided your consent to the collection, use, disclosure or transfer of your Personal Information, you may have the legal right to withdraw your consent under certain circumstances. To withdraw your consent, if applicable, contact us at privacy@parafin.com. Please note that if you withdraw your consent we may not be able to provide you with a particular Service. We will explain the impact to you at the time to help you with your decision.

You may designate an authorized agent to make a data privacy request on your behalf. To do so, we will need to receive written permission by you or a valid power of attorney, and we may also verify the validity of the request directly with you.

8. Outstanding Amounts

Please note that if you are in the process of making payments on one of the Services you may have outstanding with Parafin and you request to delete your account, Parafin may require you to pay any outstanding amounts owed to us before we delete your account.

(h) Controlling Cookies and Similar Technologies

Most web browsers are set to accept cookies by default. If you prefer, you can usually set your browser to remove or reject cookies. Note, however, that deleting cookies or directing your browser to refuse them may limit your ability to use certain portions of our Services or Website that require cookies to function.

(i) Do Not Track Signals

Your browser may give you the option to send a “Do Not Track” instruction to websites you visit. However, since there is no accepted standard for how a website should respond to this instruction, we do not currently recognize or respond to these signals.

8. Other Information

(a) Information Security

Parafin uses a range of physical, technical, and administrative security measures designed to protect your Personal Information. For example, only authorized employees are permitted to access Personal Information, and they may do so only for permitted business functions. In addition, we use encryption in the transmission of financial information between your system and ours, and we use firewalls to help prevent unauthorized persons from gaining access to your Personal Information. However, no method of data transmission or storage system is absolutely secure, and we cannot guarantee that your Personal Information will not be accessed, disclosed, altered, or destroyed in the event of a breach of any of our security measures.

Where we have given you (or where you have chosen) a password to access certain parts of our Services, you are responsible for protecting this password and keeping it confidential. As the safety and security of your information also depends on the precautions you take, we ask you not to share your password with anyone. If you believe your password or the security of your account has been compromised, you should change your password immediately and contact support@Parafin.com with any concerns.

(b) Data Retention

We save Personal Information we collect for as long as it is necessary to fulfill for the purposes for which the Personal Information is collected and processed. Generally, we will keep your Personal Information until your account is deleted, or as needed to provide you with our Services. We will also retain certain Personal Information to comply with our legal obligations or for our legitimate business purposes.

(c) Third Parties and Other Personal Information Collectors

Except as otherwise expressly specified in this Privacy Policy, this document only addresses the use and disclosure of Personal Information Parafin collects from you. To the extent that you disclose your Personal Information to other parties through the use of our Services, different rules may apply to how those parties use and share your Personal Information. Accordingly, you will need to look at their privacy policies to understand their data privacy practices.

(d) No Rights of Third Parties

This Privacy Policy does not create rights enforceable by third parties or require disclosure of any Personal Information relating to users of our Services.

(e) Children

You must be the age of majority in your province or territory of residence to use our Services. Parafin does not knowingly collect or store any Personal Information from or about children under the age of 14, and we will delete such information if we become aware that it has been submitted through our Website or Platform. Parents or guardians who believe that Parafin might have any Personal Information from or about a child under the age of 14 may submit a request to privacy@parafin.com for us to remove such information.

(f) Changes to Our Privacy Policy

Please note that we may update this Policy from time to time to reflect changes in our privacy practices by providing you with notice of the change. Notice includes but is not restricted to posting a link to the amended Privacy Policy, posting a new Privacy Policy at our Website, or sending you a link to the new Privacy Policy via contact information you have provided to us. Such change will be effective with respect to your use of the Website and Services after we have given notice of the change. Please review the Policy periodically to see whether it has changed. Any use of the Services or Website by you after we provide notice to you constitutes your acceptance of those modifications.

10. Contact Us

If you have questions or concerns regarding this Privacy Policy or Parafin’s handling of your Personal Information, or if you would like to exercise your rights described in this Privacy Policy, please contact us at:

Parafin, Inc.

Attn: Privacy Officer/Head of Legal

301 Howard Street Suite 1500

Email: privacy@parafin.com