Privacy Policy

Latest Revision: September 10, 2026

Straddle does not sell your financial account information to third parties, including marketers, and we require the same of our service providers. When our service providers obtain your personal data, they can only use it to perform services for Straddle or to comply with legal requirements.

This End User Privacy Policy (“Policy”) is meant to help you (the “end user”) understand how we at Straddle Payments, Inc (“Straddle,” “we,” “us,” or “our”)  collect, use, and share the end user information in our possession to operate, improve, develop, and protect our services, and as otherwise outlined in this Policy.

By visiting the Website or using our Services in any other way, you accept the practices described in this Privacy Policy. If you do not agree to all of the terms of this Privacy Policy, you may not access or use the Services.

If you utilize the services provided by Straddle, we will process information that we collect from or about you in accordance with our U.S. Consumer Privacy Notice

IF YOU ARE LOCATED OUTSIDE THE UNITED STATES, OR IF YOU DO NOT AGREE WITH ANY PART OF THIS PRIVACY POLICY, YOU ARE NOT AUTHORIZED TO USE THE STRADDLE PLATFORM.

About Us

Straddle is the provider of a technology platform and related APIs (collectively, the “Straddle Platform”) through which Straddle, in conjunction with one or more financial institution partners, provide businesses and their end-users with an easy, reliable, secure way to identify and verify end-users, connect to financial accounts with open banking infrastructure, and make payments using account-based (ACH, RTP, FedNow) payment networks in the United States (the “Payment Processing Services”).

About This Policy

This Policy’s goal is to provide a straightforward explanation of what information Straddle collects from and about end users (“End User Information”), and how we use and share that information. We value transparency and want to provide you with a clear and concise description of how we treat your End User Information.

Please note that this Policy only covers the information that Straddle collects, uses, and shares. This Policy does not cover any websites, products, or services provided by others.

Data Practices

Information We Collect and How We Collect It

As explained in greater detail below, Straddle collects certain account information, routing details, transactional data, personal information, and other types of End User Information in order to provide our services.

Information you provide. When you connect your financial account through Straddle, where applicable, we will collect certain identifiers, such as your name, email, address, session information, and other information that will help us facilitate the transaction. When providing this information, you give Straddle the authority to act on your behalf to access and transmit your End User Information from the relevant bank or other entity that provides your financial accounts (your “Financial Institution”) to arrange payment(s). We do not and will not have access to your bank login information/credentials that you use to Straddle your account.

Information we receive from your financial accounts. The information we receive from the Financial Institutions that maintain your financial accounts varies depending on a number of factors, including the specific Straddle services that you use, as well as the information made available by the Financial Institutions and/or Data Aggregator Networks (“DANs”) But, in general, we collect the following types of identifiers, commercial information, and other personal information from your Financial Institutions through the DANs:

  • Customer records information, including financial institution name, account name, account type, account ownership, account number and routing number.
  • Account status and characteristics, including whether the account is open and able to send and receive payments, whether the routing number is valid and participates in the payment networks we use, the type and class of account, how long the account has been open, and any debit blocks or other restrictions on the account.
  • Commercial information, including your current and available balance, and your account and payment history — the transactions posted to the account, their dates and amounts, and whether prior payments were returned or failed. We collect this information to verify your account, to confirm the account can support a payment, and to detect and prevent fraud. We may collect and refresh this information on a periodic basis for as long as your account is connected to our services, and not only at the moment you make a payment.
  • Identifiers, including an account owner's name, email address, phone number, and address information.

The data collected from your financial accounts can potentially include information from all accounts (e.g., checking and savings) accessible through our DANs. We keep your account and payment history for no longer than 24 months. Our complete retention practices are described in our Data Retention Policy, linked below.

Information we receive from your devices. When you use our services, including when you create an account, connect a bank account, or make a payment, whether directly with us or through a platform that uses Straddle, we may receive identifiers and electronic network activity information about the device you use, including internet protocol (IP) address, location information, operating system, features within our services you access, browser data, unique device identifiers and other technical information about the device. We also use cookies/analytics tags or similar tracking technologies to collect usage statistics and to help us provide and improve our services.

Information we collect about how you use our screens. We collect information about how you interact with our payment and verification screens, including timing, navigation and input patterns. We use this to tell real customers apart from automated or fraudulent activity, and for no other purpose.

Information we receive about you from other sources. We also may receive identifiers and commercial information about you directly from the business you have agreed to transact with or potentially other third parties. For example, merchants may provide information such as your full name, email address, phone number, or information about your transaction, including item(s) bought.

We may also receive information about you from identity verification services, consumer data providers and fraud prevention providers. We use this information to confirm you are who you say you are and to detect and prevent fraud. It may include:

  • Identity and address information, including name, address and identifier history; whether an address is deliverable and what type of address it is; and signals that an identity may have been fabricated rather than belong to a real person.
  • Phone information from your mobile carrier or a verification provider, including the type of line, how long the number has been in service, whether it recently moved carriers or devices, and whether the name on the account matches yours.
  • Email and internet connection information, including how long an email address has been in use, whether it has appeared in a known data breach, the reputation of its domain, and whether your connection uses a proxy or VPN.

Screening against government and third-party lists. Where the law requires it, we screen your name and other identifiers against government and third-party sanctions, watchlist, politically-exposed-person and adverse-media sources. We do this to meet our legal obligations, not on the basis of your consent, and we cannot provide the Services to you if we are prohibited by law from doing so.

Information we receive from identity documents. If you submit an identification document or a photograph of yourself for verification, we and our verification providers run checks on what you submit to confirm it is genuine and belongs to you. These checks include reading the information printed or encoded on the document, testing the image for tampering or reuse, comparing your photograph to the document, and confirming that a live person is present. Where applicable law requires separate notice and consent before biometric information is collected or generated, we or the business you are transacting with will obtain that consent first, and we will tell you how long we keep it.

Inferences we derive from the data we collect. We use the information described above to produce a risk score that helps us, and the business you are paying, decide whether to accept a payment. We use these scores to prevent fraud and to predict whether a payment will clear. We do not use them to decide whether you qualify for credit, and inferences will never be made based on an individual's protected characteristics.

How We Secure Your Information

At Straddle, the security of your information is of utmost importance to us. We are committed to protecting your data with the most advanced and reliable measures available. Here's how we ensure the safety and integrity of your information:

Encryption in Transit and at Rest

  • Encryption in Transit: All data transmitted to and from our systems is encrypted using TLS 1.2. This encryption protocol ensures that any information sent over unsecured electronic networks (the internet or mobile networks) is secured against eavesdropping or tampering by unauthorized parties.
  • Encryption at Rest: We protect all stored data using Advanced Encryption Standard (AES) with a 256-bit key. AES-256 is a robust encryption standard recognized globally for its strength and efficiency in securing data against unauthorized access.

Vaulting and Tokenization of Sensitive Data

  • Vaulting of Sensitive Data: We employ sophisticated vaulting solutions to securely store sensitive payment account data and Personally Identifiable Information (PII). This approach isolates sensitive information from other data, adding an extra layer of security against unauthorized access.
  • Tokenization in APIs and Logs: In areas where sensitive data needs to be processed or transmitted, such as in APIs and system logs, we use tokenization. This method replaces sensitive data elements with non-sensitive equivalents, known as tokens, that have no extrinsic or exploitable meaning or value. Tokenization significantly reduces the risk of data breaches, as the tokens cannot be reverse-engineered to reveal the original data.

Continuous Monitoring and Regular Updates

We continuously monitor our security systems and update our protocols to combat emerging threats and vulnerabilities. Our dedicated security team works tirelessly to ensure that our defenses are always at the forefront of cybersecurity advancements.

How We Use Your Information

We use your End User Information for a number of business and commercial purposes, including to operate, improve, and protect the services we provide, and to develop new services. We may collect and use End User Information in an aggregated, de-identified, or anonymized manner (that does not identify you personally) for any purpose permitted under applicable law. This includes creating or using aggregated, de-identified, or anonymized data based on the collected information to develop new services and to facilitate research. More specifically, we may use your End User Information:

  • To operate, provide, and maintain our services;
  • To verify your account(s) with your Financial Institution(s);
  • If you use our services to Straddle your account(s) for payment purposes, to help facilitate the initial payment and any subsequent payments;
  • To improve, enhance, modify, add to, and further develop our existing services, including analyzing usage, performing end-user risk modeling, and for research and development;
  • To protect you, merchants, our partners, Straddle, and others from fraud, malicious activity, and other privacy and security-related concerns;
  • To develop new services;
  • To assess the risk that a payment will be returned, and to build, test, validate and improve the models and risk scores we use for that purpose;
  • To evaluate and test the identity verification, fraud prevention and risk providers we use or are considering using, under written agreements that permit those providers to use your information only to perform services for Straddle;
  • To provide customer support to you or to merchants, including to help respond to your
  • inquiries related to our service or merchants’ applications;
  • To investigate any misuse of our service or merchants’ applications, including violations of our merchants’ respective policies, criminal activity, or other unauthorized access to our services;
  • To comply with contractual and legal obligations under applicable law; and
  • For other notified purposes with your consent.

How We Share Your Information

We are committed to maintaining your trust, and we want you to understand when and with whom we may share information about you. We may share your End User Information in the instances described below.

  • If you are using Straddle to make payments to merchants, we will share with the relevant merchant the name of your bank, the bank’s routing number, the last four digits of your account number, your account type (checking), and the current available balance;
  • To enforce any contract with you;
  • With your connected Financial Institutions to help establish or maintain a connection you’ve chosen to make;
  • If we believe in good faith that such disclosure is appropriate, to comply with applicable laws, regulations, or legal processes (such as a court order or subpoena);
  • In connection with a change in ownership or control of all or a part of our business (such as a merger, acquisition, reorganization, or bankruptcy);
  • Between and among Straddle and our current and future parents, affiliates, subsidiaries and other companies under common control or ownership;
  • With the identity verification, fraud prevention and risk service providers we use to deliver, test and improve our services. These providers act on Straddle's behalf under written agreements that permit them to use your information only to perform services for Straddle or to comply with legal requirements. A current list of these providers is available at trust.straddle.com;
  • As we believe reasonably appropriate to protect the rights, privacy, safety, or property of you, merchants, our partners, Straddle, and others; or
  • For any other notified purpose with your consent.

Information from across the businesses we serve. We use information from across the businesses we serve to detect fraud. Activity we see with one business may help us assess risk for another. We never share your information with those businesses for their own marketing or other purposes.

We never sell or rent the personal information that we collect.

Transfer of End User Information

We will never transfer or store End User Information outside of the United States.

Retention Practices

We retain and use End User Information for no longer than necessary to fulfill the purposes for which it was collected and used, as described in this Policy, unless a longer retention period is required or permitted under applicable law. We will retain and use End User Information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws or Nacha regulations), resolve disputes, and enforce our legal agreements and policies. As permitted under applicable law, even after you stop using the application or terminate your account with one or more merchants, we may still retain your information (for example, if you still have an account with another merchant). We may also retain some or a part of your information in an aggregated, de-identified and anonymized format - data which is not directly attributable to you - for research and development purposes. However, your information will only be processed as required by law or in accordance with this Policy.

We keep the account and payment history and the balance observations we receive from your Financial Institution for no longer than 24 months from the date we receive them. Records that Nacha rules or other applicable law require us to keep — including payment records and authorization records — are kept for the periods stated in our Data Retention Policy.

You can review our complete Data Retention Policy or contact us about our data retention practices using the contact information below.

Additional Provisions

Residents of California and Vermont

To the extent applicable and for other to carry out our everyday business, for purposes of compliance with the Gramm-Leach-Bliley Act, 15 U.S.C. 6802 (“GLBA”), the California Financial Information Privacy Act (“CFIPA”), the California Consumer Privacy Act (“CCPA”) and the Vermont Consumer Protection Act, 8 V.S.A. 10202 (“VCPA”), we will not share non-public personally identifiable financial information with our affiliates or non-affiliates unless we receive your prior approval (“OPT IN”) allowing us share this non-public personally identifiable information with our affiliates or non-affiliates and, for purposes of the GLBA.

When you use our Services, our authorized partners may collect categories of Personal Information about you and use this data for their own purposes. This activity may qualify as a “sale” under the CCPA. If CCPA applies to you, you can make choices to allow or prevent such uses. Depending on your choices, during the past twelve months, we may have shared information within the categories of Personal Information described in Section 1 of the Annex (California Privacy Notice) below.

This Privacy Policy shall serve as your annual privacy notice as defined under the GLBA, CFIPA and VCPA, respectively.

We may use cookies on your computer in order to collect certain aggregate data about our users, and to customize certain aspects of your specific user experience. A cookie is a small data text file which is stored on your computer that uniquely identifies your browser. Cookies may also include more personalized information, such as your IP address, browser type, the server your computer is logged onto, the area code and zip code associated with your server, and your first name to welcome you back to our Site.

We may also use cookies to perform tasks such as: monitoring aggregate site usage metrics, storing and remembering your passwords (if you allow us to do so), storing account and advertising preferences that you have set, and personalizing the services we make available to you.

Most browsers are initially set up to accept cookies, but you can reset your browser to refuse all future cookies or to indicate when a cookie is being sent. However, some aspects of the Site may not function properly if you elect to disable cookies.

Do Not Track

Currently we do not take any action when we receive a Do Not Track request. Do Not Track is a privacy preference that you can set in your web browser to indicate that you do not want certain information about your webpage visits collected across websites when you have not interacted with that service on the page. For details, including how to turn on Do Not Track, visit EFF’s Do Not Track page.

Changes To This Policy

We may update or change this Policy from time to time, and when we update it, we will revise the "Effective Date" above and post the new Policy on our website, and in some cases, we may provide additional notice. To stay informed of our privacy practices, we recommend you review the Policy on our website on a regular basis as you continue to use our services.

Children

We do not knowingly collect or maintain personal information from any person under the age of sixteen. No parts of our platform are directed to or designed to attract anyone under the age of sixteen.

Under certain circumstances, you have rights under applicable law in relation to your Personal Information:

  • Right to know about Personal Information collected or disclosed.
  • Request correction of your Personal Information.
  • Request erasure/deletion of your Personal Information.
  • Right to Non-Discrimination for the Exercise of a Consumer’s privacy Rights. You will not receive a discriminatory treatment by us for the exercise of the privacy rights set out above.

If you wish to exercise any of the rights set out above or if you want to raise a question or a concern about our privacy policy and practices, please contact us. We will promptly take steps to disclose and deliver to you, free of charge, your Personal Information according to your Verifiable Consumer Request to Know. We may also contact you to ask you for further information in relation to your request to speed up our response.

Contacting Straddle

If you have questions or complaints about this Policy, or about our privacy practices generally, you can contact us at legal@straddle.com

Annex: California Privacy Notice

Pursuant to the California Privacy Rights Act (“CPRA”), residents and households located in the state of California have certain rights regarding the processing of their Personal Information.

1. Notice of Collection and Use of Personal Information.

We may collect (and may have collected during the 12-month period prior to the “Last Updated” date above) the following categories of Personal Information about you:

1.1. Identifiers. This includes things such as name, postal address, IP address, email address, account name, social security number, driver’s license number, passport number, and similar identifiers.

1.2. Additional Data Subject to Cal. Civ. Code § 1798.80. This includes things like name, address, telephone number, driver’s license or state identification card number, education, bank account number and other financial information.

1.3. Characteristics of Protected Classifications under California or Federal Law. This includes race, gender, and age noted in identification documents that you submit to Straddle Customers so that Straddle can verify your identity and perform KYC/KYB verifications for purposes of fraud prevention.

1.4. Commercial Information. This includes payment and transaction data that a merchant may receive when you choose to do business with them, and the balance, account and payment history we receive from your Financial Institution — including the transactions posted to your account, their dates and amounts, whether prior payments were returned, and the status and characteristics of the account.

1.5. Internet or other electronic network activity information. This includes certain information about devices and browsers that use the Services, usage data, how you interact with our payment and verification screens, and attributes of your email address and internet connection that we receive from fraud prevention providers.

1.6. Geolocation Data. We use your IP address to determine your general location (such as city, state, or zip code).

1.7. Inferences. This includes the risk scores and other inferences we derive from the information described above to prevent fraud and to predict whether a payment will clear. We do not derive inferences about protected characteristics, and we do not produce these scores for credit eligibility purposes.

1.8. Biometric Information. Where you submit a photograph or an identification document for verification and a biometric template is generated to compare them, that template is Biometric Information. We or the business you are transacting with will obtain any notice and consent that applicable law requires before that template is generated.

2. Business Purpose for Collection and Use of Personal Information.

We may use (and may have used during the 12-month period prior to the “Last Updated” date above) your Personal Information for the purposes described in our Privacy Policy above and for the following business purposes:

  • 2.1. performing services, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing advertising or marketing services, providing analytics services, or providing similar services;
  • 2.2. auditing related to a current interaction with you and concurrent transactions;
  • 2.3. detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity;
  • 2.4. debugging to identify and repair errors that impair existing intended functionality;
  • 2.5. undertaking internal research for technological development and demonstration; and
  • 2.6. undertaking activities to verify or maintain the quality or safety of the services offered by us and to improve, upgrade, or enhance services offered by us.

3. Sources of Personal Information.

We obtain (and may have obtained during the 12-month period prior to the “Last Updated” date above) your Personal Information from the following categories of sources:

  • 3.1. directly from a business you have granted authorized access to, such as when you provide them with Account information or payment data to facilitate a Transaction for you;
  • 3.2. your devices, such as when you use our Website;
  • 3.3. our Financial Partners, such as when we facilitate the processing of a Transaction;
  • 3.4. external banks (i.e., banks other than Financial Partners) if you link a bank account or if you initiate a Transaction to a third-party bank account;
  • 3.5. Service Providers who provide services on our behalf;
  • 3.6. embedded cookie/analytics providers or social media networks;
  • 3.7. operating systems and platforms;
  • 3.8. identity verification services, consumer data providers and fraud prevention providers;
  • 3.9. mobile carriers and phone verification providers;
  • 3.10. the routing directories and account validation services used by the payment networks we support; and
  • 3.11. government and third-party sanctions, watchlist, politically-exposed-person and adverse-media sources.

4. Categories of Third-Parties with whom Personal Information is Shared.

During the 12-month period prior to the “Last Updated” date of the Privacy Policy, we may have shared your Personal Information with certain categories of third parties, as described in our Privacy Policy.

5. Categories of Personal Information Sold.

Straddle does not engage in the sale of Personal Information as defined in the CPRA.

6. Categories of Personal Information Shared.

Straddle does not engage in sharing your Personal Information for cross-context behavioural advertising as defined in the CPRA.

7. Data Retention.

Straddle will retain your Personal Information for the duration necessary for Straddle: (A) to comply with our legal and regulatory obligations; (B) to comply with our contractual obligations, including obligations owed to Financial Partners where data retention is mandated; (C) to comply with our contractual obligations, including obligations owed to Financial Partners where data retention is mandated; (D) to pursue our business purpose of detecting and preventing fraud, preventing loss, processing chargebacks and refunds, and complying with valid legal process requests from courts or competent authorities; (E) to comply with our tax, accounting, and financial reporting obligations; and (F) for the specific periods stated in our Data Retention Policy, which sets out how long we keep bank-sourced account and payment history, balance observations, and verification records.

8. Your Rights.

Under CPRA, you have certain rights, which are set forth below.

8.1. You have a Right to Know About Personal Information Collected, Disclosed, or Sold.

  • Right to Know. California residents have the right to request that Straddle disclose what Personal Information it collects, uses, discloses, and sells. This is called the “Right to Know”. Under the Right to Know, you can request a listing of the types of Personal Information we have collected about you, the sources of that information, how we use the information (e.g., our business or commercial purposes for collecting or selling Personal Information), other individuals and business with whom we share Personal Information, and the specific pieces of Personal Information that we have collected about you. If you would like the above information, you may contact us at legal@straddle.com or by phone at 1(833) 810-1008. When you make a request under your Right to Know, you can expect the following:
  • We will verify your identity. You will need to provide us the following information: email address and full name in order for us to verify that you are who you say you are. We may also need further information related to your Account in order to validate your identity.
  • We will confirm our receipt of your request within 10 days. If you have not received a response within a few days after that, please let us know by contacting us at legal@straddle.com
  • We will respond to your request within 45 days. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why.
  • In certain cases, a Request to Know may be denied, for example, if we cannot verify your identity or if providing you the information could create an unreasonable risk to someone’s security (for example, we do not want very sensitive information disclosed inappropriately). If we deny your request, we will explain why we denied it. If we deny a request, we will still try to provide you as much of the information as we can, but we will withhold the information subject to denial.

8.2. You have a Right to Request Deletion of Personal Information about You. You may have a right to request the deletion of your Personal Information collected or maintained by Straddle. If you would like this information deleted, contact us at legal@straddle.com or by phone at 1(833) 810-1008. When you make a request for deletion, you can expect the following:

  • After you request deletion, you will need to confirm that you want your information deleted.
  • We will verify your identity. You will need to provide us the following information: email address and full name. We may also need further information related to your Account in order to validate your identity.
  • We will confirm our receipt of your request within 10 days. If you have not received a response within a few days after that, please let us know by contacting us at the webpage or phone number listed below.
  • We will respond to your request within 45 days. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why.
  • In certain cases, a request for deletion may be denied, for example, if we cannot verify your identity, the law requires that we maintain the information, or if we need the information for internal purposes such as providing Services or complying with our contractual obligations. See Section 7 above for more on our data retention practices. If we deny your request, we will explain why we denied it and delete any other information that is not protected from deletion.
  • Straddle is a data processor when we use data captured to verify your identity on behalf of the business that requested our services. This means that if you’d like to delete the data we are storing on behalf of the business, you will need to reach out to the business directly and they will need to take action to delete this data from our systems.

8.3. Right to Request Correction. You may have the right to request that we correct inaccurate Personal Information that we maintain about you. We will honor such request but might not be able to fulfil your request if it is impossible to do so or would involve disproportionate effort, or if we have a good-faith, reasonable, and documented belief that a request to correct is fraudulent or abusive. If you would like this information corrected, please contact us at legal@straddle.com or by phone at 1(833) 810-1008.

8.4. Right to Limit the Use and Disclosure of Sensitive Personal Information. You have the right to limit certain ways in which a business uses and discloses Sensitive Personal Information. Please note, however, that Straddle does not use or disclose Sensitive Personal Information in a way covered by this right; in particular, Straddle does not process “Sensitive Personal Information” for purposes of inferring characteristics about a consumer.

8.5. Right to Opt-Out of the Sale or Sharing of Personal Information. CPRA entitles California residents to opt-out of the sale or sharing of their Personal Information by businesses, as those terms are defined in CPRA. Straddle does not sell or share Personal Information under CPRA.

8.6. Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights. You have a right not to receive discriminatory treatment by us for exercising any of your privacy rights conferred by the CPRA. We will not discriminate against any California consumer because such person exercised any of the consumer’s rights under CPRA.

9. Authorized Agents.

If you would like, you may designate an authorized agent to make a request under the CPRA on your behalf. We will deny requests from agents that do not submit proof of authorization from you. To verify that an authorized agent has authority to act for you, we may require a copy of a power of attorney or require that you provide the authorized agent with written permission and verify your own identity with us.

10. Rights Provided by California Civil Code Section 1798.83.

A California resident who has provided Personal Information to a business with whom he/she has established a business relationship for personal, family, or household purposes (a “California Customer”) may request information about whether the business has disclosed Personal Information to any third parties for the third parties’ own direct marketing purposes. In general, if the business has made such a disclosure of Personal Information, upon receipt of a request by a California Customer, the business is required to provide a list of all third parties to whom Personal Information was disclosed in the preceding calendar year, as well as a list of the categories of Personal Information that were disclosed. Please note, however, that Straddle does not disclose your Personal Information to third parties for the third parties own direct marketing purposes. California Customers may request further information about our compliance with this law by mailing us at 1001 Bannock St Suite 405, Denver CO 80204 or emailing us at legal@straddle.com . Please note that we are only required to respond to two requests per California Customer each year under Code Section 1798.83.