This Privacy Policy explains how SNDR Solutions, Inc. ("SNDR," "we," "us") collects, uses, discloses, and protects personal information in connection with our platform, dashboard, APIs, websites, and related services (the "Services").
01 About this Policy
This Privacy Policy explains how SNDR collects, uses, discloses, and protects personal information in connection with our platform, dashboard, APIs, websites, and related services (the "Services"). It applies to information we process as part of providing the Services to our business customers ("Customers") and about the individuals associated with them.
The Services are provided to businesses for business purposes. They are not directed to consumers using them for personal, family, or household purposes, and are not directed to children.
Your use of the Services is also governed by our Terms of Service. If there is a conflict between this Policy and a written agreement between you and SNDR concerning data processing (such as a data protection addendum), that agreement controls.
02 Whose information this Policy covers
This Policy covers personal information relating to:
- our Customers' representatives and authorized users;
- the beneficial owners, officers, and control persons whose information a Customer provides so that the Customer can apply for accounts with a Provider and satisfy verification and compliance requirements;
- transaction recipients and other individuals whose details appear in a transaction instruction; and
- visitors to our websites.
03 Information we collect
3.1 Information you or your Customer provide
- Business and account information: business name, address, registration and tax identifiers, business activity, and account login details for the Services.
- Individual information for applications and compliance: names, dates of birth, residential and email addresses, phone numbers, government-issued identifiers, ownership and control details, and identity-verification documents relating to beneficial owners, officers, authorized users, and control persons.
- Transaction instructions: the details you create for a transaction, including recipient information, account identifiers, amount, currency, and rail.
- Communications: information you provide when you contact us for support or otherwise correspond with us.
3.2 Credentials
API credentials (keys or tokens) you provision so we can retrieve information from, and submit transaction instructions to, your accounts at a Provider. We treat these as sensitive.
3.3 Information from Providers and connectivity services
Balance, transaction, and account-status information ("Aggregated Data") retrieved from your Provider accounts using the credentials you provision, together with related technical data from any third-party connectivity service we use.
3.4 Information from verification and screening sources
Results and related data from identity-verification, sanctions- and watchlist-screening, credit-reference, and fraud-prevention providers we use to help you and your Providers meet compliance requirements.
3.5 Information collected automatically
Device and usage information (such as IP address, browser and device type, pages viewed, and actions taken), collected through cookies and similar technologies, to operate, secure, and improve the Services.
Expressed in the categories used by U.S. state privacy laws, we collect: identifiers; commercial information; financial-account and transaction information; government identifiers and other sensitive personal information (such as account credentials and, where provided, identity documents); internet or network activity; professional or business information; and inferences drawn for security and service purposes.
04 How we use information
We use personal information to:
- provide, operate, maintain, and secure the Services;
- help you prepare and submit account applications to Providers, and submit transaction instructions you create for your own Provider approval;
- retrieve and display Aggregated Data in your dashboard;
- perform identity verification, sanctions and watchlist screening, fraud prevention, and other risk and compliance functions, and to help you and your Providers meet their compliance obligations;
- communicate with you about the Services, including support and service notices;
- monitor, analyze, debug, and improve the Services (including during beta);
- enforce our Terms, protect our rights and the rights of others, and prevent misuse; and
- comply with our legal, regulatory, tax, audit, and recordkeeping obligations.
We do not use personal information for cross-context behavioral advertising, and we do not sell personal information (see Section 6).
05 How we disclose information
5.1 Providers
With your direction, we disclose your application information and transaction instructions to the Providers you select (such as Wise and PayPal), so you can open and operate your own accounts and have your instructions presented to you for approval. Each Provider handles that information as an independent party under its own privacy notice, which applies directly to you and to the individuals whose information is provided.
5.2 Service providers
We share information with vendors that perform services for us — including cloud hosting, connectivity/aggregation, identity verification and screening, fraud prevention, analytics, communications, and professional advisers — under contracts that limit their use of the information to performing those services for us.
5.3 Compliance, legal, and safety
We may disclose information to regulators, law enforcement, courts, and other authorities where we believe in good faith it is necessary to comply with law or legal process, to enforce our Terms, to detect or prevent fraud or security issues, or to protect the rights, property, or safety of SNDR, our Customers, or others. In some cases we may be legally prohibited from notifying you of such a disclosure.
5.4 Business transfers
We may disclose or transfer information in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Policy.
5.5 With your direction or consent
We may share information at your direction or with your consent.
06 We do not sell personal information
SNDR does not sell personal information, and does not share personal information for cross-context behavioral advertising, as those terms are used under the California Consumer Privacy Act (as amended) and comparable state laws. Disclosures we make to Providers (at your direction) and to service providers (to operate the Services) are made for the business and operational purposes described above, not for sale.
07 Your privacy choices and rights
Depending on your state of residence, you may have rights regarding your personal information, which may include the right to: know or access the personal information we hold about you; request correction of inaccurate information; request deletion; obtain a portable copy; opt out of sale or of sharing for cross-context behavioral advertising (which we do not do); and limit the use of sensitive personal information. You have the right not to receive discriminatory treatment for exercising these rights.
How to exercise
Submit a request to privacy@sndr.solutions or via our contact page. We will verify your request before acting on it and will respond within the time required by applicable law.
Requests about information a Customer provided
Where we process an individual's information on behalf of, or as provided by, a Customer, we may refer a request we receive directly from that individual to the relevant Customer, and we will assist the Customer in responding as required by law.
Limits
We may be unable to fulfill certain requests — particularly deletion — where we are required to retain information for legal, regulatory, tax, audit, anti-money-laundering, sanctions, fraud-prevention, or dispute-resolution purposes, or to establish, exercise, or defend legal claims.
Authorized agents
You may use an authorized agent to submit a request, subject to our verification of the agent's authority.
08 Data retention
We retain personal information for as long as necessary to provide the Services and thereafter as required to comply with our legal, regulatory, tax, audit, and recordkeeping obligations, to resolve disputes, and to enforce our agreements. Records relating to transactions, identity verification, and compliance are generally subject to mandatory retention periods (often at least five years) and will be retained accordingly, even after your account is closed or a deletion request is made. When information is no longer needed, we delete or de-identify it.
09 How we protect information
We maintain administrative, technical, and physical safeguards designed to protect personal information appropriate to its sensitivity, including encryption of data in transit and at rest, access controls and least-privilege access, monitoring and logging, and vendor risk management. We treat account credentials and API credentials as sensitive and protect them accordingly. No method of transmission or storage is completely secure, and you are responsible for the security of your own systems, login credentials, and API credentials. Notify us at security@sndr.solutions if you suspect any compromise.
10 Cookies and similar technologies
Our websites and dashboard use cookies and similar technologies to operate the Services, remember your preferences, maintain sessions, and analyze usage so we can improve the Services. You can control cookies through your browser settings; disabling some cookies may affect how the Services function. We do not use these technologies for cross-context behavioral advertising.
11 Location of processing
We process and store personal information in the United States. The Services facilitate cross-border payments, so information necessary to complete a transaction you create may be transmitted by Providers and their banking and network partners to recipient and intermediary jurisdictions in order to carry out that transaction; those transfers are made by those parties under their own terms. We do not target or offer the Services to individuals in the European Economic Area or the United Kingdom.
12 Children's information
The Services are for businesses and are not directed to, or intended for use by, children under 16, and we do not knowingly collect their personal information. If you believe a child's information has been provided to us, contact us at privacy@sndr.solutions.
13 Financial information
Some information we handle is financial-account information. Where the Gramm-Leach-Bliley Act and its implementing regulations apply to a given relationship, we handle nonpublic personal information in accordance with those requirements and do not disclose it except as permitted by law. We limit our use and disclosure of financial-account information to operating the Services and the purposes described in this Policy.
14 Third-party services
The Services link to and interoperate with third parties, including Providers and connectivity services. Those third parties process personal information under their own privacy notices, which we do not control. We encourage you to review the privacy notices of any Provider you use, including Wise and PayPal.
15 Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, where required by law or where changes are material, provide additional notice. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
16 Contact us
SNDR Solutions, Inc.
850 New Burton Road, Suite 201, Dover, Kent County, DE 19904
Privacy: privacy@sndr.solutions
Security: security@sndr.solutions
General: hello@sndr.solutions
