This policy explains how Paffle Pay Inc. collects, uses and protects personal information when you visit our website, use Paffle, make or receive a payment, contact us, or use our investor or affiliate portals.
Who we are
Paffle is operated by Paffle Pay Inc., an Ontario corporation, number 1001404901. Our registered office is 2967 Dundas Street W., Unit 1035, Toronto, Ontario M6P 1Z2, Canada. In this policy, ‘Paffle’, ‘we’, ‘us’ and ‘our’ refer to that company.
Our privacy contact is privacy@paffle.com. You may also write to our registered office, addressed to the Privacy Officer.
Our role and the business’s role
We decide how to use information needed to operate our website, manage accounts, provide support, administer our portals, prevent misuse and meet our own legal obligations. For these purposes, we act as the organization responsible for the information, or the data controller where that term applies.
When a business enters information about its customers, suppliers, employees or other people into Paffle, the business generally decides why that information is collected and how it is used. We process those records on its instructions to provide the service. For example, a business may ask us to store an invoice, email it to a customer or send it to a tax authority.
Our role can differ for payment verification, fraud prevention and legally required records. Paffle and its payment partners may have their own responsibilities for that information. If your information appears in a business’s records, contact that business first about those records. You can also contact us, and we will help direct your request appropriately.
Information we collect
The information we collect depends on how you use Paffle. It may include:
Account and business information: your name, email address, business name, address, tax or registration number, language and display preferences, role, subscription details and any profile photo you upload. Your profile photo is shown in your own account view.
Sign-in information: a password hash, the account identifier from Google or Microsoft if you use their sign-in service, an encrypted two-step sign-in secret and hashed recovery codes. We do not store Google or Microsoft access tokens for sign-in. Authorizing a separate integration can require a stored, protected connection token.
Business records: contacts, invoices, quotes, credit and debit notes, bills, purchase orders, payments, stock records, budgets and forecasts, allocation details, projects, timesheets, expenses, approvals and related attachments. These records may identify customers, suppliers, team members or other people.
Payment and verification information: transaction amounts, currencies, references and status; bank or wallet recipient details; the recipient’s name and address; and business, owner or director information needed for verification. Some identity documents are provided directly to a partner through its own verification process. If you save personal bank details for expense reimbursement, we also hold those details.
Website enquiries and communications: information you enter into contact or subscription forms, support messages, feedback and any documents you send us.
Portal information: investor or affiliate applications, organization details, program activity and agreed terms. A signed confidentiality agreement may include your signature, email address, signing time, IP address and browser information. Affiliate records include referral links, visits, attributed registrations, commissions and payments.
Technical and security information: browser and device information, error reports, sign-in activity, audit events and information used to prevent abuse. Some security records use hashed network addresses. Hashing does not necessarily make information anonymous. Sign-in and credential-change events are retained for twelve months. Error reports are configured to remove cookies, credentials and unnecessary personal information.
Cookies and browser storage: information needed for sign-in, security and preferences, and any website technologies described in our Cookies Policy. This includes device preferences, sign-in coordination and, if you connect the Excel add-in, its saved connection information.
We collect information from you, from the business that invites or names you, from people who transact with that business, from services you choose to connect, and from relevant verification or payment partners. We may also receive information from public registers or other lawful verification sources where needed for an enabled financial service.
If you use a supported blockchain transaction, wallet addresses, amounts and transaction details may be recorded on a public blockchain. Other people can inspect those records and may associate them with you. We cannot edit or erase the blockchain’s transaction history.
How and why we use information
To provide Paffle: create and manage accounts, store and calculate business records, prepare documents, run approvals, generate reports and carry out instructions you authorize.
To provide enabled payment features: verify eligibility, process instructions, identify recipients, attribute payments and maintain transaction records.
To communicate: answer enquiries, provide support, send account and service notices, and deliver documents or invitations at a business’s request.
To maintain security and quality: detect fraud and misuse, enforce permissions, investigate incidents, keep audit evidence, troubleshoot errors and improve reliability.
To meet legal obligations: comply with tax, financial crime, reporting, record keeping and other applicable requirements, and respond to lawful requests.
To administer our investor and affiliate programs: assess applications, manage access, preserve signed agreements and calculate or pay commissions.
To send marketing where permitted: send updates you request or other communications for which we have a lawful basis. You can unsubscribe at any time. Marketing preferences do not stop essential account, security or transaction messages.
Where applicable law requires consent, we obtain consent appropriate to the information and purpose. You can withdraw it, subject to legal restrictions and the consequences we explain. Optional marketing is not a condition of opening an account.
Where laws such as the GDPR or UK GDPR apply, our grounds may include performing a contract with you, taking steps you request before a contract, complying with legal obligations, consent, and legitimate interests such as security, customer support and administering a business service. We consider your rights when relying on legitimate interests. Those grounds do not replace consent where another applicable law requires it.
We do not sell personal information or share it with data brokers. We do not use the contents of a business’s financial records for advertising or to train general-purpose AI models.
Weekly statement unsubscribes apply to the business named in that message. Opting out of Paffle referral invitations stops those invitations. A bounce or spam complaint stops our weekly statements and Paffle referral invitations to that address. These controls do not automatically prevent a business from sending its own invoices or other documents to you.
AI features
If you use the assistant, your question and the information needed to answer it may be sent to our AI provider. If you use document extraction, an uploaded document may be sent to that provider to propose a draft. Review drafts and answers before relying on them. AI features are optional; the rest of Paffle can be used without them.
Assistant conversations are saved to your account. If you ask for a person, or the assistant cannot answer the same question twice, the conversation may be emailed to our support team with your email address, business and role so that someone can follow up.
We use the provider’s business API, for which inputs and outputs are not used for model training by default. We do not opt your business records into model training. Provider processing and retention still occur under its service terms. Do not enter information that you are not authorized to share.
Who receives information
We share information only as needed for the purposes described in this policy. People in your business can see records according to their assigned access. Information you choose to send or share can also reach document recipients, payment recipients, connected services and relevant authorities.
We use service providers for website hosting and forms, application infrastructure, database and file storage, email, error monitoring and AI. Providers processing information for us are subject to appropriate confidentiality and data protection terms. Payment partners and tax authorities may also process information for their own legal responsibilities.
Service category | Information and purpose | Processing locations |
|---|---|---|
Website and application hosting | Account, request and technical information, and information submitted through website forms, to operate and secure Paffle. | International, including the United States. |
Database and file storage | Account and business records, uploaded documents and files, to store and retrieve your information. | United States. |
Email and support services | Email addresses, messages and relevant document or account details, to deliver communications and respond to requests. | United States for email delivery; support processing locations depend on the service used. |
Technical monitoring | Error reports and relevant device or request details, with data scrubbing configured, to diagnose failures and protect the service. | United States. |
Optional AI services | Prompts, relevant business information or uploaded documents, to answer questions or propose extracted drafts when you use an AI feature. | United States. |
Payment, billing and verification services | Relevant identity, business, recipient, account and transaction details, to provide enabled payment services, verify users and process subscriptions. | United States and other countries relevant to the service. |
Tax-document filing services and authorities | Relevant supplier, customer, invoice and tax information, to register and file documents where the feature is enabled. | International; the country where the tax authority is based |
The services used and processing locations can depend on your country and the feature you use. Contact privacy@paffle.com to request the identities of providers that receive your information and details of relevant processing locations and safeguards.
Separate partner terms or privacy notices may apply to a feature. These explain the partner’s own responsibilities and are provided where required when you enable or use that feature.
We may disclose information to professional advisers, regulators, courts or law enforcement where necessary and legally permitted or required. If our business is reorganized, acquired or transferred, information may be disclosed or transferred under appropriate protections and applicable law. A new owner must not use it for incompatible purposes without the required notice and lawful basis.
Services you connect
Connecting accounting software can send your Paffle records to that service. We may look up customers, tax codes, items or accounts so that records can be posted correctly. This does not import your existing ledger into Paffle. We retain identifiers, returned amounts and currencies, delivery status, and information needed to reconcile and operate the connection.
If you connect a Slack or Microsoft Teams channel, event notices may name a customer and amount. A channel can contain people outside your business, so choose its membership carefully. API keys and webhooks can also allow your chosen systems to receive business information.
A business API key can give its holder access to business-wide records within that key’s available scope. It does not inherit the narrower allocation access of an individual team member. Keep keys secret, give them only to trusted services and revoke them when no longer needed. The Excel add-in’s signed-in access is separately checked against the member’s permissions.
Disconnecting stops new requests through that connection. A request already in progress may finish. Disconnection does not delete records already delivered to the other service, where that provider’s terms and privacy practices apply.
Paffle’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data for the feature you connect, such as writing Paffle records to your chosen spreadsheet. We do not use it for advertising. Transfers and human access are limited to the purposes permitted by that policy, including providing the requested feature with your consent, security, legal compliance and access you explicitly authorize. A merger or sale does not override those limits: transferring this Google user data as part of that transaction requires your explicit prior consent.
International processing
Paffle is based in Canada and uses providers operating internationally, including in the United States. Your information may be processed outside your country, including where a payment or tax service operates. Authorities in those places may have lawful powers to access it.
Where we send information to a provider processing it for us, we remain responsible for the protections required by applicable law. Where transfer restrictions apply, we use a permitted transfer basis and the required safeguards. Contact privacy@paffle.com for details of the safeguards relevant to your information and how to request a copy where available.
How long we keep information
Retention depends on the record and why it is needed:
Account and service information: kept while the account or business uses Paffle, subject to the account erasure process below. Closing an individual account does not close or delete the business’s records.
Financial, tax, verification and transaction records: kept while the business uses Paffle and afterwards for any applicable legal period. Canadian money services records can require at least five years, with the starting point depending on the record. Canadian tax records generally require six years from the end of the relevant tax year. Other laws, investigations or legal holds may require longer retention.
Audit and portal logs: retained to preserve evidence of actions and access. They can include a person’s email address or other identifying details after account erasure. These logs currently have no automatic expiry; an append-only log does not make its contents anonymous.
Budget history preserves every saved change, including the names its lines carried at that time, for as long as the business uses Paffle.
Sign-in and account security event records are kept for twelve months and then deleted.
Signed confidentiality agreements are retained as signed legal documents. Affiliate commissions and payments are retained as financial records.
Assistant conversations, feedback and notifications are kept while the account is open and deleted when that account is erased. Support correspondence separately sent to our team may be retained to resolve the matter and preserve an appropriate service or dispute record.
Suppression records for unsubscribed, bounced or spam-reporting email addresses are kept indefinitely so that forgetting a request does not restart unwanted mail.
Uploaded files are generally kept with the record they support. Encrypted database backups can be retained for up to 24 months. Backups and provider logs are not normally edited to remove an individual record; their contents expire under the applicable retention schedule.
A legal hold, regulatory duty or unresolved dispute may require longer retention. Retained information remains subject to privacy protections and the purposes that justify keeping it.
What account erasure does
Account erasure is reviewed by a person. We delete some information and remove or replace profile identifiers. We end access, revoke sign-in and remove linked sign-in identities. Two-step sign-in settings, assistant conversations, feedback, notifications and referral invitation addresses belonging to the account are deleted from the active application.
Your profile photo is removed from your active account, and deletion of the stored photo files is requested. Information already sent to support, delivered to another service or retained in backups is handled under the relevant retention arrangements.
Erasure does not delete the business’s financial documents, historic audit entries, signed agreements, commissions or records we must retain by law. They can still identify you. We also retain evidence of your erasure request and action, email suppression records and security events for their stated periods.
Removing account identifiers therefore does not make every historical record anonymous. If you want to know what will be erased or retained in your case, contact privacy@paffle.com.
Your choices and rights
Depending on the law that applies, you may ask to access, correct, receive a copy of, delete or restrict the use of personal information, object to certain processing, or withdraw consent. Some rights have limits, including legal record keeping, the rights of other people and information we hold on a business’s instructions.
You can change many account details in Paffle. For other requests, contact privacy@paffle.com. We may need to verify your identity and authority before disclosing or changing information. We respond within the deadline required by applicable law, usually 30 days. If a permitted extension is needed, we explain it within the applicable initial period. If we cannot fulfil a request, we explain the reason unless the law prevents us from doing so.
You can unsubscribe from marketing through the message’s link or by contacting us. Withdrawing consent does not affect processing already carried out lawfully or information we must continue to keep.
You may complain to the relevant privacy authority, including the Office of the Privacy Commissioner of Canada, the Nigeria Data Protection Commission, the UK Information Commissioner’s Office, your competent European data protection authority or another authority competent where you live. Contacting us first does not remove your right to complain directly.
Security and children
We use technical and organizational safeguards appropriate to the information, including access controls, protected sign-in, encryption, business access restrictions and audit records. No system can guarantee complete security. Report a suspected security issue to support@paffle.com.
Paffle accounts and programs are intended for adults aged 18 or older. We do not knowingly invite children to open accounts. A business may have a lawful reason to include information about a younger person in its records; it is responsible for the permissions and protections required for that information. Contact us if you believe information has been collected improperly.
Changes to This Policy
We update this policy when our practices change. The date at the top identifies the current version. We give appropriate notice of material changes and seek fresh consent where the law requires it.