Platform Privacy Policy & Electronic Communications (E-Sign) Disclosure

Effective Date: September 2026 | Canada MSB: N300001645 | FinCEN MSB: 31000321315567 | Scope: Commercial B2B Operations

  • Data Controller: Use Thrive Corporation (Canada BN: 735170037TZ0001 | FINTRAC MSB: N300001645)
  • Infrastructure & Hosting Affiliate: Use Thrive LLC (Delaware File No.: 10462475 | FinCEN MSB: 31000321315567)
  • Data Inquiries & Compliance Contact: privacy@usethrive.com

Important Legal Notice

THIS DOCUMENT GOVERNS HOW USE THRIVE COLLECTS, PROCESSES, SHARES, AND SECURES ENTERPRISE, TRANSACTIONAL, AND PERSONNEL DATA. IT ALSO CONTAINS YOUR MANDATORY CONSENT TO RECEIVE ALL LEGAL DISCLOSURES, STATEMENTS, AND CONTRACTS ELECTRONICALLY UNDER APPLICABLE ELECTRONIC COMMERCE AND E-SIGN ACT STATUTES. THIS DOCUMENT APPLIES TO ALL CORPORATE CLIENTS, DESIGNATED ACCOUNT ADMINISTRATORS, AND AUTHORIZED CARDHOLDERS.

1. SCOPE & B2B APPLICATION

Use Thrive Corporation provides services exclusively to commercial business entities ("Clients"). References to "Personal Information" or "Personal Data" in this Policy refer strictly to identifiable information provided regarding Client's corporate directors, officers, Ultimate Beneficial Owners (UBOs), authorized administrative personnel, and authorized commercial cardholders. Use Thrive does not solicit or provide retail consumer accounts.

2. CATEGORIES OF INFORMATION COLLECTED

2.1 Corporate Due Diligence (KYB) Data: Corporate name, jurisdiction of formation, registered address, certificate of incorporation, business licenses, tax identification numbers, and verified operational business activities.

2.2 Personnel & Beneficial Owner Verification Data: Full legal name, date of birth, residential address, nationality, government identification document numbers (e.g., passport, national ID), utility bills, and proof of beneficial equity ownership for individuals holding 25% or more control.

2.3 Transactional & Financial Activity: Multi-currency virtual account transactions, card spend authorizations, clearing records, merchant names, MCC codes, FX conversion data, billing statements, and settlement instructions.

2.4 Blockchain & Wallet Coordinates: Public wallet addresses, smart contract interaction hashes, deposited collateral amounts, liquidation execution transactions, and cryptographic transaction receipts.

2.5 Technical & Telemetric Data: IP addresses, browser specifications, operating system telemetry, login timestamps, API access tokens, and security event logs.

3. PURPOSE & LEGAL BASES FOR PROCESSING

Use Thrive processes data exclusively under lawful, legitimate business grounds, including:

  • Contract Performance: Maintaining virtual ledger balances, routing payment orders, issuing virtual/physical commercial cards, and managing API integrations.
  • Legal & Regulatory Compliance: Fulfilling mandatory Canadian (PCMLTFA / FINTRAC), US (FinCEN / BSA), and global anti-money laundering (AML), counter-terrorist financing (CTF), and economic sanctions screening obligations.
  • Fraud Mitigation & Loss Prevention: Monitoring high-velocity card charges, mitigating chargeback spikes, detecting synthetic identity attacks, and securing platform APIs.
  • Platform Operations & Improvements: Optimizing transaction routing speeds, monitoring network uptime, and maintaining auditable accounting ledgers.

4. DISCLOSURE & CROSS-BORDER DATA TRANSFERS

4.1 Regulated Service Providers & Issuers: We disclose necessary transaction and identity records to third-party bank partners, regulated card issuers (such as Third National or principal network members), card networks (Visa/Mastercard), and clearing rails to execute transactions and maintain program compliance.

4.2 Regulatory Authorities & Law Enforcement: Where required by subpoena, court order, or statutory reporting mandates, Use Thrive cooperates with competent governmental authorities, including FINTRAC, FinCEN, tax administrations, and law enforcement agencies.

4.3 Cross-Border Data Processing: Data collected by Use Thrive Corporation in Canada may be transferred to, stored, or processed by Use Thrive LLC in the United States or encrypted cloud data centers globally. Client explicitly consents to the cross-border transfer of corporate and personnel data for service execution.

5. DATA SECURITY, PROTECTION & RETENTION

5.1 Technical Security Controls: We employ multi-tenant database isolation, 256-bit AES encryption at rest, TLS 1.3 encryption in transit, strict role-based access restrictions, and immutable audit logs.

5.2 Statutory Retention Schedule: As a registered Money Services Business, Use Thrive is required by Canadian PCMLTFA and international regulatory standards to retain customer due diligence records and transactional ledgers for a minimum of five (5) to seven (7) years following the formal closure of the corporate account. Records cannot be prematurely purged or erased where statutory preservation mandates apply.

PART II: E-SIGN & ELECTRONIC COMMUNICATIONS DISCLOSURE — Consent to Electronic Signatures, Delivery of Notices, and Periodic Statements

1. Scope of Electronic Consent: By clicking "Agree", registering for an account, accessing the Dashboard, or initiating transactions, Client provides affirmative electronic consent to receive all legal notices, periodic statements, card disclosures, fee updates, regulatory notices, and contracts (collectively, "Covered Items") exclusively via electronic transmission through the Dashboard or Client's registered corporate email address.

2. Legal Validity of Electronic Signatures: Client agrees that electronic execution (including clicking acceptance buttons, cryptographic API authorizations, or digital signatures) holds identical legal standing, validity, and enforceability as a handwritten physical signature under the Canadian Uniform Electronic Commerce Act (UECA), the United States Electronic Signatures in Global and National Commerce Act (E-SIGN Act, 15 U.S.C. § 7001), and provincial electronic transactions legislation.

3. Hardware and Software Specifications: To access and retain Covered Items, Client must maintain: (a) a computer or mobile device with active Internet access; (b) a modern web browser supporting 128-bit encryption (Chrome, Safari, Firefox, or Edge); (c) sufficient storage capacity to save records or software capable of rendering Portable Document Format (PDF) files; and (d) an active, functional corporate email address capable of receiving messages from support@usethrive.com.

4. Paper Copies & Right to Send Paper: Client may print or download electronic disclosures at any time. Client may request a physical paper copy of any mandatory disclosure by contacting support@usethrive.com. Use Thrive reserves the right to deliver communications in physical paper format at its discretion (for instance, in cases of suspected security compromise or legal enforcement).

5. Withdrawal of Electronic Consent: Client may withdraw consent to receive electronic communications by providing thirty (30) days' prior written notice to support@usethrive.com. Because the Use Thrive platform operates exclusively via automated electronic workflows, withdrawal of electronic consent will result in the immediate termination of Dashboard access, revocation of active commercial cards, and systematic winding down of the corporate account.

Use Thrive Corporation — Platform Privacy Policy & Electronic Communications (E-Sign) Disclosure