Last updated May 28, 2026
Placeholder policy for review by counsel — not legal advice. Replace before launch.
This policy explains how Collect, Inc. (“Collect”) handles information when you use our website and platform. We act as a processor of your clients’ data on your behalf and as a controller of your own account data.
To provide and improve the Services, process payments, send transactional communications, prevent fraud and abuse, and comply with legal obligations. We do not sell personal information.
Cardholder data is captured client-side and tokenized by the payment processor under your credentials (PCI SAQ-A scope). Sensitive card data does not transit or rest on our servers.
We share information with subprocessors that help us run the Services (hosting, payments, email, SMS, error monitoring), each bound by appropriate obligations. We may disclose information where required by law.
We use encryption in transit and at rest, per-business credential isolation, envelope encryption for processor secrets, and append-only audit logging. No system is perfectly secure, but security is a first-order concern.
We retain data for as long as your account is active and as needed for legal, accounting, and dispute-resolution purposes, then delete or anonymize it.
Depending on your jurisdiction, you may have rights to access, correct, delete, or export personal information. Contact us to exercise them.
Privacy questions? Email support@collect.com.