Fundbox Privacy Policy

This privacy policy will go into effect on February 28, 2023. The privacy policy in effect prior to February 28, 2023 can be found here.

Fundbox, Inc. (together with our subsidiaries and Affiliates, "Fundbox", "we", "our" or "us"), respect your privacy. This Privacy Policy explains how we may collect, use, and share this Personal Information (defined below) in connection with our software, mobile applications, websites, and APIs (each, together with its subdomains, content and services, a "Site"); and our products and services, such as the Fundbox lines of credit, term loans, and Flex Pay service (each, a “Service”). The Site and any Service are individually and collectively referred to herein as the "Services". This Privacy Policy forms part of our Terms of Use which is available at https://fundbox.com/tou/ ("Terms"). Capitalized terms not otherwise defined in this Privacy Policy, have the meaning set forth in the Terms.

1. Introduction.

This Privacy Policy explains our online information practices and the choices you can make about the way your Personal Information is collected and used in connection with the Services. "Personal Information" means any information that may be used, either alone or in combination with other information, that relates to an identified or identifiable living individual or business. This Privacy Policy only applies to Personal Information that is processed by Fundbox in our capacity as a “business” or other similar term under applicable data protection laws. Except as otherwise stated herein, this Privacy Policy does not apply to any uses of Personal Information by a Third Party or any Personal Information that Fundbox processes on behalf of the Third Party pursuant to a separate customer agreement. If you are a customer of a Third Party, you should check the privacy policies of the Third Party to understand how they may use your Personal Information. The Services may, from time to time, contain links to and from the websites of other businesses. If you follow a link to any of these websites, please note that these websites have their own privacy notices and that we do not accept any responsibility or liability for their privacy obligations. Please check their privacy notices before you submit any Personal Information to these websites.

All business loans and lines of credit that are issued by First Electronic Bank (“FEB”), a Utah chartered Industrial Bank are subject to FEB’s Privacy Policy, which FEB maintains and can be found here. Users that receive an FEB-issued loan or line of credit using the Services are also subject to the Privacy Policy and disclosures of FEB. Fundbox is not responsible for the privacy practices of FEB and does not exercise control over FEB’s sites.

Fundbox may, from time to time and in its sole discretion, elect to contract with one or more other bank(s) to underwrite loans. In such a case, you will be notified of such bank(s) during the loan process.

2. Personal Information We Collect.

Currently, you are not required to provide your Personal Information in order to have access to general information available on the Site. In order to participate in the Service, you are required to create an account enabling you to login and utilize the Services ("Account"). The types or categories of Personal Information we collect and how we collect and process it depends on the nature of the relationship you have with Fundbox and the requirements of applicable law. We may collect the following information:

2.1. Information You Provide Directly to Fundbox. We collect Personal Information you provide directly to us, including Personal Information (which may include sensitive personal information) and transaction information when you use the Services, including your Account information such as name, phone number, email address, and other business information included in the online registration form. You may be required to provide us with certain information about your business and business personnel ("Business Information"). Such information may include Personal Information about yourself or your business personnel. If you provide, or make available, any Personal Information about any business personnel you agree that you have obtained proper consent to disclose such information to us in accordance with applicable laws.

The Service may include the option to purchase certain products or services from us (for example, to obtain funding). If you choose to make a purchase, we (or one of our affiliated companies) will require sufficient information from you to complete the transaction. Such information could include a credit card number and related account and billing information, invoice related information, and other data required to process the order. Your participation in the Service is optional and you at all times have the choice of choosing whether to provide any Personal Information. Please be aware though that any failure to provide requested information may preclude your business from being approved to obtain funding from us.

2.2. Information from Third Party Accounts. You may choose to create (or supplement) an Account by clicking on a 'connect' or 'sign on' button that we may display on the Site for a designated account that you have with a third-party website or service (each a "Third Party Account"), such as Intuit's QuickBooks, FreshBooks, Xero, or another third-party e-invoicing or accounting software product that is designated on our Site. Doing so will enable you to link your Fundbox Service Account and your Third-Party Account. If you choose to enable this option, we will obtain available information from your Third-Party Account. The information that we obtain from your Third-Party Account is typically identified in the privacy policy of your Third-Party Account provider. You acknowledge to have reviewed and agreed to review the terms of use and privacy policy of the provider of your Third-Party Account. Please note that in order to use this option, you will need to have, and may need to be actively signed-in to, an existing Third-Party Account. Fundbox currently uses Plaid and Yodlee, Inc. to gather verification data from financial institutions. By using our service, you grant Fundbox the right, power, and authority to act on your behalf to access and transmit your personal and financial information from the relevant financial institution.

Regardless of which method you choose to register your Account, we may send an email to your nominated email address, or to the email address that you have designated in your Third-Party Account, to instruct you how to confirm your registration.

2.3 Automatic Data Collection. We may collect certain information automatically through your use of the Services (including our websites),such as your Internet protocol (IP) address, technologies such as cookie identifiers and mobile advertising identifiers, mobile carrier, MAC address, IMEI, IDFA and other device identifiers that are automatically assigned to your device, browser type and language, geo-location information, hardware type, operating system, Internet service provider, pages that you visit before and after using the Services, the date and time of your visit, the amount of time you spend on each page, information about the links you click and pages you view within the Services, and other information about actions taken through use of the Services.

3. How We Use Personal Information.

We collect and process Personal Information for a variety of business purposes, including the following:

3.1. To Provide and Improve our Services. We will use your Personal Information to provide the Services. For example, if you have an Account, we will use your Personal Information in connection with your transactions including to (i) process payments for purchases (such as obtaining funding); (ii) verify your identity to approve transactions, and monitor your online behavior to identify potentially fraudulent, prohibited or illegal transactions (including through the use of automated decision-making technologies); and (iii) communicate with you about your purchases.

3.2. Administrative Purposes. We may use your Personal Information for our administrative purposes, including (i) to respond to your questions, comments, and other requests for customer support, technical support, or information, including information about potential or future services; (ii) to provide you access to certain areas, functionalities, and features of the Services; (iv) for internal quality control purposes; (v) if you have an Account, to communicate with you about your account and the Services, including by sending emails to the email address you provide to us to verify your account and for informational and operational purposes, such as account management, customer service, or system maintenance, and changes to our policies; (vi) to enforce our agreements; and (vii) to generally administer the Services.

3.3. To Market the Services. We may use Personal Information to market the Services as permitted by applicable law. Such uses include (i) notifying you about offers and services that may be of interest to you; (ii) tailoring content, advertisements, and offers for you; (iii) conducting market research; (iv) developing and marketing new products and services, and measure interest in Fundbox services; (v) other purposes disclosed at the time you provide Personal Information; and (vi) as you otherwise consent.

3.4. De-identified and Aggregated Information. We may use Personal Information and other information about you to create de-identified and/or aggregated information. De-identified or aggregated information is not Personal Information, and we may use such information in a number of ways, including the measurement of visitors’ interest in and use of various portions or features of the Services, for research, internal analysis, analytics, and any other legally permissible purposes.

3.5. Cookies and Similar Technologies. We, as well as third parties that provide content, advertising, or other functionality on the Services, may use cookies, pixel tags, local storage, and other technologies (“Technologies”) to automatically collect information through the Services. If you would like to opt out of the Technologies we employ on the Services, you may do so by blocking, deleting, or disabling them as your browser or device permits. See our Cookie Policy for more information.

4. How We Share Information.

4.1. Service Providers. We may share and transfer any information we receive with service providers that help us provide the Services, including Business and Personal Information. The types of service providers to whom we entrust Personal Information include service providers for: (i) the provision of the Services and loan servicing activities; (ii) the provision of hosting, IT and related services; (iii) the provision of information and services you have requested; (iv) payment processing and performance; and (v) customer service activities. For instance, information used to determine creditworthiness may be shared with FEB, if your loan is originated by FEB and/or with credit bureaus, consumer reporting agencies, financial institutions, collections agencies, and fraud prevention services in order to, among other things, perform various checks, locate borrowers, or recover debts.

4.2. Affiliates. We may share Personal Information, Business Information, Fundbox credit decision and process, as well as Third Party Account information (with or without compensation) to Fundbox platform merchants/vendors, affiliated brokers and advertisers in order to facilitate your use of the Service, and as required to fulfill contractual obligations. Our Affiliates and broker partners are all required to preserve the confidentiality of any personal information they may access. Affiliate” means any entity that, directly or indirectly, controls, is controlled by, or is under common control with Fundbox. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

4.3. Disclosures to Protect Us or Others. We may disclose your Personal Information or any information you submitted via the Service if we have a good faith belief that disclosure of such information is helpful or reasonably necessary to: (i) comply with any applicable law, regulation, legal process or governmental request; (ii) enforce our Terms, including investigations of potential violations thereof; (iii) detect, prevent, or otherwise address fraud or security issues; or (iv) protect against harm to the rights, property or safety of Fundbox, our users, yourself or the public.

4.5. Merger, Sale, or Other Asset Transfers. If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, then your information may be sold or transferred as part of such a transaction as permitted by law and/or contract.

4.6. International Data Transfers. All Personal Information collected by Fundbox will be transferred to and stored in the United States. By choosing to visit our website, utilize the Services or otherwise provide information to us, you acknowledge that your Personal Information may be transferred to countries outside of your country of residence, including the United States, which may have different data protection rules to those of your country.

5. How To Exercise Your Rights.

5.1. Opting Out. You may choose not to receive future promotional, advertising, or other Services-related emails from us by selecting an unsubscribe link at the bottom of such emails that you receive from us. Please note that even if you opt out of receiving the foregoing emails, we may still send you a response to any "Contact Us" request as well as administrative emails (for example, in connection with a password reset request, an email verification, or a payment-related email) that are necessary to facilitate your use of the Services.

5.2. Do Not Track. Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. DNT is a way for users to inform websites and services that they do not want certain information about their webpage visits collected over time and across websites or online services. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.

5.3. Your Privacy Rights. In accordance with applicable privacy laws, you may have the right to: (i) obtain access to or a copy of your Personal Information; (ii) receive an electronic copy of Personal Information that you have provided to us, (the “right of data portability”); (iii) object to or restrict our uses of your Personal Information; (iv) seek correction or amendment of inaccurate, untrue, incomplete, or improperly processed Personal Information; (v) withdraw your consent; and (vi) request erasure of Personal Information held about you by us, subject to certain exceptions prescribed by law. If you would like to exercise any of these rights, please contact us as set forth below. We will process requests in accordance with applicable laws. To protect your privacy, we will take steps to verify your identity before fulfilling your request.

6. Data Security & Accuracy.

6.1. Data Retention. Fundbox retains the Personal Information we receive as described in this Privacy Policy for as long as you use the Services or as necessary to fulfill the purpose(s) for which it was collected, provide our services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws.

6.2. Data Accuracy. In order to continue using the Services, it is necessary to maintain accurate Personal Information. You may use the tools that we make available on the Service to remove or modify certain information in your Account (you may also be able to remove or modify certain information via your Third-Party Account that you have linked to). If you would like to correct any of your other Personal Information that we may be storing, you may submit an access request by sending an email to support@fundbox.com. Your email should include adequate details of your request. Fundbox may retain archived information that you have provided in the course of obtaining or attempting to obtain services through Fundbox in order to comply with applicable law, regulation, legal process, partner contractual obligations and our own internal policies.

6.3. Data Security. We take steps to ensure that your information is treated securely and in accordance with this Privacy Policy. Unfortunately, the Internet cannot be guaranteed to be 100% secure, and we cannot ensure or warrant the security of any information you provide to us. To the fullest extent permitted by applicable law, we do not accept liability for unauthorized disclosure.

7. Children's Privacy.

The Services are not directed to children. If you are under the age of 16 you are not permitted to use the Fundbox Services. We do not have actual knowledge that we collect, sell, or share Personal Information from children under 16 for cross behavioral advertising or other purposes. If you learn that your child has provided us with Personal Information without your consent, you may alert us at support@fundbox.com. If we learn that we have collected Personal Information of a child under 16, we will take steps to delete such information from our files as soon as possible and terminate the child’s account.

8. HIPPA.

Fundbox is not an entity that is covered by the Health Insurance Portability and Accountability Act (“HIPAA”). The HIPAA privacy rules apply to health plans, health care clearinghouses, to any health care provider who transmits health information in electronic form in connection with transactions for which the Secretary of Health and Human Services has adopted standards under HIPAA (the “covered entities”) and their service providers (“business associates”). This means that the information that you provide to Fundbox is not protected by the HIPAA privacy rules and regulations. You may not submit or otherwise make available any protected health information (as that term is defined under HIPAA) to Fundbox.

9. Updates to this Privacy Policy.

By using the Services, you consent to the terms of this Privacy Policy and to our collection, processing and sharing of Personal Information for the purposes set forth herein. If you do not agree to this Privacy Policy, you may not access or otherwise use the Services. We may revise this Privacy Policy at our sole discretion. If we make material changes to this Privacy Policy, we will notify you as required by applicable law. We will post any Privacy Policy revisions on this web page, and the revised version will be effective immediately when it is posted. If you continue to visit our website or use the Services after such changes have been made, the revised Privacy Policy will be applicable to you. If you are concerned about how your information is used, bookmark this page and read this Privacy Policy periodically.

10. California Privacy Rights.

If you are a California resident, please review our California Notice. California residents may be able to exercise additional rights granted by California law in relation to the Personal Information that we have collected (subject to certain limitations) as described in our California Notice.

11. California Shine the Light Law.

Pursuant to California Civil Code Section 1798.83, if you live in the State of California, you may request certain information about the type of personal information we share with third parties for direct marketing purposes and the identity of any such third party. Once per calendar year, California residents may request this information by contacting us as directed in the Contact Us section below. However, we do not disclose personal information protected under the “Shine the Light” law to third parties for their own direct marketing purposes.

12. Nevada Privacy Rights.

Nevada residents have the right to opt-out of the sale of their Personal Information under the rights granted to them in Chapter 603A of the Nevada Revised Statutes. Fundbox uses your information in accordance with this Privacy Policy. To submit such a request, please contact us at support@fundbox.com.

13. Vermont Residents.

If you live in Vermont, we will share information only as permitted by law. We will not share your personal information with nonaffiliates for their marketing purposes, unless you authorize us to do so. We will not share consumer report information about you with joint marketing partners or with affiliates, except with your consent or to the extent otherwise permitted by law.

14. Contact Us.

If you have any questions, comments, or suggestions about our privacy practices, this Privacy Policy, or if you wish to submit a request to exercise your rights as detailed in this Privacy Policy, please send us a "Contact Us" request or email us at support@fundbox.com, you may be required to provide us with certain information such as your name and email address.