PRIVACY POLICY

PRIVACY POLICY AMRIOP LLC

(hereinafter also referred to as “Company”, “we”, “our” or “us”) provides a platform where users can upload and organize their spending documents online and operate the AMRIOP mobile application (“App”), www.amriop.com (“Website”) and other AMRIOP services (collectively “Services”). The App and the Website hereinafter collectively referred to as (“Platform”). This Privacy Policy (“Policy”) governs your visit to our Platform and explains how we collect, safeguard and disclose information that results from your use of our Service. We take your privacy very seriously. In this Policy, we seek to explain to you in the clearest way possible what information we collect, how we use it and what rights you have in relation to it. We hope you take some time to read through it carefully, as it is important. If there are any terms in this Policy that you do not agree with, please discontinue the use of our Services immediately. We use your data to provide and improve Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Policy, the terms used in this Policy have the same meanings as in our Terms of Services. Our Terms of Services govern all use of our Service and together with the Policy constitute your agreement with us. If this Policy is modified in any way, it will be updated here. Regularly checking and reviewing this page ensures that you are updated on the information that may be collected, used and shared with other parties. If we believe that the modifications are material, we will notify you of the changes by posting a notice on the Platform, or emailing you at the email address provided to us by you, and as we may deem appropriate. What constitutes a material change will be determined by us, at our sole and absolute discretion. In this Policy "you", "your" or “users” refers to the users of the Platform.

WHAT INFORMATION DO WE COLLECT?

The personal information you disclose to us. We may collect personal information that you voluntarily provide to us when you register on the Platform, express an interest in obtaining information about us or our products and Services or otherwise when you contact us. The personal information that we may collect depends on the context of your interactions with us and the Platform, the choices you make and the products and features you use. The personal information we collect may include the following:

  • Personal Information Provided by you. We collect first names, last name, email addresses and zip code. We may also collect additional information you create when uploading receipts (Such as categories, most visited retailers/seller & states) in order to provide relevant and effective Services.
  • Storing Information, you provide and receipts you upload: We will keep information you provide, and receipts uploaded on third party servers. We will never use your purchasing history or information to compile and share or sell to any other party.
  • Information automatically collected. When you access our Platform, we, our service providers, and our partners may automatically collect information about you, your mobile device, and your activity on our Platform.

HOW DO WE USE YOUR INFORMATION?

We use personal information collected via our Platform for a variety of purposes described below. We process your personal information for these purposes in reliance on our legitimate interests, in order to enter into or perform a contract with you, with your consent, and/or for compliance with our legal obligations. We indicate the specific processing grounds we rely on next to each purpose listed below. We use the information we collect or receive:

  1. To manage accounts: We may use your information for the purposes of managing the account and keeping it in working order.
  2. Provide our services: We may use your information to deliver our Services.
  3. To send administrative information to you. We may use your personal information to send you product, service and new feature information and/or information about changes to our terms, conditions, and policies.
  4. To protect our Services. We may use your information as part of our efforts to keep our Platform safe and secure (for example, for fraud monitoring and prevention).
  5. To enforce our terms, conditions, and policies for legitimate purposes, to comply with legal and regulatory requirements or in connection with our contract.
  6. To respond to legal requests and prevent harm. If we receive a subpoena or other legal request, we may need to inspect the data we hold to determine how to respond.
  7. To respond to user inquiries/support. We may use your information to respond to your inquiries and solve any potential issues you might have with the use of our Services.

WILL YOUR INFORMATION BE SHARED WITH ANYONE?

We may process or share the data that we hold based on the following legal basis:

  1. Consent: We may process your data if you have given us specific consent to use your personal information for a specific purpose.
  2. Legitimate Interests: We may process your data when it is reasonably necessary to achieve our legitimate interests.
  3. Legal Obligations: We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal processes.
  4. Vital Interests: We may disclose your information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person and illegal activities, or as evidence in litigation in which we are involved.
  5. Third-Party Advertisers: We may use third-party advertising companies to serve ads when you visit or use the Platform.
  6. Affiliates: We may share your information with our affiliates, in which case we will require those affiliates to honor this Policy.
  7. Business Transactions: We may share your information with our business partners to offer you certain products, services or promotions.

WHAT IS OUR STANCE ON THIRD-PARTY WEBSITES?

The Platform may use third-party services and may have links to other websites. We cannot guarantee the safety and privacy of the data you provide to any third parties. Any data collected by third parties is not covered by this Policy. We are not responsible for the content or privacy and security practices and policies of any third parties, including other websites, services or applications that may be linked to or from the Platform. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services. WE HEREBY DISCLAIM LIABILITY FOR, ANY INFORMATION, MATERIALS, PRODUCTS, OR SERVICES POSTED OR OFFERED AT ANY OF THE THIRD-PARTY SITES LINKED TO THIS PLATFORM. BY CREATING A LINK TO A THIRD-PARTY WEBSITE, WE DO NOT ENDORSE OR RECOMMEND ANY PRODUCTS OR SERVICES OFFERED OR INFORMATION CONTAINED ON THAT WEBSITE, NOR ARE WE LIABLE FOR ANY FAILURE OF PRODUCTS OR SERVICES OFFERED OR ADVERTISED AT THOSE SITES. SUCH A THIRD PARTY MAY HAVE A PRIVACY POLICY DIFFERENT FROM THAT OF OURS AND THE THIRD-PARTY WEBSITE MAY PROVIDE LESS SECURITY THAN THIS SITE.

HOW LONG DO WE KEEP YOUR INFORMATION?

We will only keep your personal information for as long as it is necessary for the purposes set out in this Policy unless a longer retention period is required or permitted by law. No purpose in this Policy will require us to keep your personal information for longer than the period of time in which users have an account with us. When we have no ongoing legitimate need to process your personal information, we will either delete or anonymize such information, or, if this is not possible, then we will securely store your personal information and isolate it from any further processing until deletion is possible.

HOW DO WE KEEP YOUR INFORMATION SAFE?

We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security, and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, the transmission of personal information to and from our Platform is at your own risk. You should only access the Platform within a secure environment.

YOUR DATA PROTECTION RIGHTS UNDER CALIFORNIA CONSUMER PRIVACY ACT (CCPA)/ CALIFORNIA PRIVACY RIGHTS ACT (CPRA)

“Shine the Light” and “Eraser” Laws: Residents of the State of California may request a list of all third parties to which we have disclosed certain information during the preceding year for those third parties' direct marketing purposes.

California Consumer Privacy Act (CCPA)/California Privacy Rights Act (CPRA): The CCPA, as amended by the CPRA, provides California residents and/or their authorized agents with specific rights regarding the collection and storage of their personal information.

Your Right to Know:

California residents have the right to request that we disclose the following information to you about our collection and use of your personal information over the past twelve (12) months. We may ask you to provide certain information to identify yourself so that we may compare it with our records in order to verify your request. Upon verification, we will disclose to you:

  • The categories of personal information we have collected about you.
  • The categories of sources for the personal information we have collected about you.
  • The specific pieces of personal information we have collected about you.
  • The categories of third parties to whom we have sold or shared your personal information if any, and the categories of personal information that we have shared with each third-party recipient.

Your Right to Opt-Out of Sale or Sharing of Personal Information:

California residents have the right to opt-out of the sale of their personal information by submitting a request as directed on the homepage of our Platform or by contacting us using the information in the “Contact Us” section below. Please note that we do not knowingly sell the personal information of any individuals under the age of 18. Where we are sharing your personal information with third parties for the purposes of cross-context behavioural advertising or profiling, you may opt-out of such sharing at any time by submitting a request as directed on the homepage of our Platform or by contacting us using the information in the “Contact Us” section below.

Your Right to Limit Use of Sensitive Personal Information:

California residents have the right to request that we limit our use of any sensitive personal information to those uses which are necessary to perform the Services or for other specifically enumerated purposes under the CCPA, as amended by the CPRA.

Your Right to Delete:

California residents have the right to request that we delete any of the personal information collected from you and retained by us, subject to certain exceptions. We may ask you to provide certain information to identify yourself so that we may compare it with our records in order to verify your request. Once your request is verified and we have determined that we are required to delete the requested personal information in accordance with the CCPA, we will delete, and direct our third-party service providers to delete, your personal information from their records. Your request to delete personal information that we have collected may be denied if we conclude it is necessary for us to retain such personal information under one or more of the exceptions listed in the CCPA.

Your Right to Correct:

Under the CCPA, as amended by the CPRA, California residents have the right to request that we correct any inaccurate personal information we maintain about you, taking into account the nature of the personal information and the purposes for which we are processing such personal information. We will use commercially reasonable efforts to correct such inaccurate personal information about you.

Non-Discrimination:

You will not receive any discriminatory treatment by us for the exercise of your privacy rights conferred by the CCPA.

Verifying Your Request:

Only you, or a person that you authorize to act on your behalf, may make a request related to your personal information. In the case of access and deletion, your request must be verifiable before we can fulfill such a request. Verifying your request will require you to provide sufficient information for us to reasonably verify that you are the person about whom we collected personal information or a person authorized to act on your behalf. We will only use the personal information that you have provided in a verifiable request in order to verify your request. We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority. Please note that we may charge a reasonable fee or refuse to act on a request if such request is excessive, repetitive or manifestly unfounded. To exercise these rights, please contact us at the contact information mentioned in the “Contact Us” clause.

YOUR DATA PROTECTION RIGHTS UNDER THE LAWS OF OTHER STATES IN THE USA.

1. Nevada

If you are a resident of Nevada, you have some additional rights:

  1. We do not sell your covered information, as defined under Chapter 603A of the Nevada Revised Statutes.

2. Virginia

If you are a resident of Virginia, you have some additional rights:

  1. If we deny your rights request, you have the right to appeal that decision. We will provide you with the necessary information to submit an appeal at that time.
  2. You have the right to opt out of targeted advertising.
  3. You have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.

3. Colorado

If you are a resident of Colorado, you have some additional rights:

  1. If we deny your rights request, you have the right to appeal that decision. We will provide you with the necessary information to submit an appeal at that time.
  2. You have the right to opt out of targeted advertising.
  3. You have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.

4. Connecticut

If you are a resident of Connecticut, you have some additional rights:

  1. If we deny your rights request, you have the right to appeal that decision. We will provide you with the necessary information to submit an appeal at that time.
  2. You have the right to opt out of targeted advertising.
  3. You have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.

YOUR DATA PROTECTION RIGHTS UNDER PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT (PIPEDA)

As part of our commitment to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and protect your privacy, we want to inform you of your data protection rights. This clause outlines your rights regarding the personal information we collect and process.

  1. Right to Access: You have the right to request access to the personal information we hold about you. We will provide you with a copy of your data upon request, subject to any legal limitations.
  2. Right to Rectification: If you believe that the personal information we have is inaccurate or incomplete, you have the right to request its correction or update.
  3. Right to Erasure (Right to be Forgotten): In certain circumstances, you have the right to request the deletion of your personal information from our records. However, please note that this right is subject to legal and legitimate retention requirements.
  4. Right to Restriction of Processing: You have the right to request the restriction of processing your personal information under specific circumstances outlined in PIPEDA.
  5. Right to Data Portability: Upon your request, we will provide you with your personal information in a structured, commonly used, and machine-readable format, enabling you to transmit it to another data controller.
  6. Right to Object: You have the right to object to the processing of your personal information based on legitimate interests or for direct marketing purposes.
  7. Right to Withdraw Consent: If we process your personal information based on your consent, you have the right to withdraw that consent at any time.
  8. Right to Lodge a Complaint: If you believe that we have not complied with PIPEDA or have mishandled your personal information, you have the right to lodge a complaint with the relevant supervisory authority.

To exercise any of these rights or inquire further about your data protection rights under PIPEDA, please contact us. We will respond to your request in a timely manner and in accordance with applicable data protection laws.

Notification of Data Breaches

In the event of a data breach, we will take immediate steps to contain the breach and to prevent any further unauthorized access to personal information. We will also investigate the breach to determine its scope and impact, and we will take appropriate measures to prevent similar breaches from occurring in the future.

If we determine that a data breach poses a risk of harm to affected individuals, we will notify those individuals as soon as possible. Notification will be provided in writing or by other means as required by law. The notification will provide details of the breach, the types of personal information that may have been affected, and the steps we are taking to address the breach and to protect personal information.

The Company will also notify the Office of the Privacy Commissioner of Canada as required by PIPEDA. The notification will include details of the breach, the types of personal information that may have been affected, and the steps we are taking to address the breach and protect personal information.

AMRIOP will work with affected individuals and the Office of the Privacy Commissioner of Canada to minimize the impact of the breach and to assist with any steps that individuals may need to take to protect themselves. We will also provide affected individuals with information about the steps they can take to protect themselves from identity theft and other forms of fraud.

HOW DO WE PROTECT CHILDREN’S PRIVACY?

In compliance with the Children's Online Privacy Protection Act ("COPPA"). We do not knowingly collect personally identifiable information from Children below the age of 13 (“Child” or “Children”) without the consent of the parents or legal guardian. If you become aware that a Child has provided us with Personal Data without the parent's or legal guardian's consent, please contact us. If we become aware that we have collected Personal Data from Children, we take steps to remove that information from our servers.

DO WE MAKE UPDATES TO THIS NOTICE?

We may update this privacy notice from time to time. The updated version will be indicated by an updated “Last updated” date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.

CONTACT US

After reviewing this policy, if you have any additional questions concerning these Terms and Conditions, please contact us through the Contact Us page on the Platform.

Email: privacy@amriop.com

Effective Date: February 1, 2024

Last Updated: February 1, 2024