ExpiTrans Privacy Policy

Effective Date: 8/5/2026

Last Updated: 8/5/2026

ExpiTrans, Inc. (“ExpiTrans,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information when you interact with ExpiTrans.

This Privacy Policy applies when you:

  • visit expitrans.com or another website that links to this Privacy Policy
  • submit an inquiry, lead form, merchant application, or other online form
  • apply for, obtain, or use payment-processing, merchant, gateway, software,
  • equipment, or related services
  • access an ExpiTrans account, portal, application, or platform
  • communicate with our sales, underwriting, risk, customer-service, or technical-
  • support teams
  • receive email, telephone, text-message, or other communications from us
  • use a product, integration, application programming interface, or service
  • provided or supported by ExpiTrans
  • otherwise interact with us.

This Privacy Policy does not replace any separate privacy notice, merchant agreement, processing agreement, sponsor-bank notice, platform agreement, or other contract that may apply to a particular product, account, or relationship. When another agreement or notice applies, it may contain additional or different terms regarding the processing of information.

1. Information We Collect

The information we collect depends on how you interact with ExpiTrans and which services you use.

1.1 Contact information

We may collect:

  • first and last name
  • business name
  • job title or role
  • mailing or business address
  • email address
  • telephone and mobile number
  • communication preferences
  • information you provide in inquiries, applications, or support requests.

1.2 Identity and verification information

We may collect information used to verify a person’s identity, ownership, authority, or eligibility, including:

  • date of birth
  • Social Security number
  • taxpayer identification number
  • employer identification number
  • driver’s license, passport, or other government-issued identification
  • signature
  • beneficial-owner information
  • control-person information
  • ownership percentage
  • identity-verification results
  • authentication information
  • information obtained from public records, verification services, financial
  • institutions, or legally authorized data providers.

1.3 Business and merchant information

We may collect:

  • business name and legal entity name
  • business structure
  • formation and registration information
  • industry and merchant category
  • products and services offered
  • business addresses and operating locations
  • websites and sales channels
  • expected and actual processing volume
  • average and maximum transaction amounts
  • ownership and management information
  • business licenses
  • financial statements
  • processing statements
  • bank statements
  • tax documents
  • merchant applications
  • underwriting materials
  • risk and compliance records
  • account history
  • equipment and software information
  • support history
  • other information needed to evaluate, establish, administer, or monitor a
  • merchant relationship.

1.4 Financial and payment information

We may collect or process:

  • bank-account and routing information
  • payment-card information
  • transaction information
  • transaction identifiers
  • payment amounts
  • billing and invoice information
  • settlement and deposit records
  • payout instructions
  • refund and adjustment information
  • reserve information
  • chargeback and dispute information
  • recurring-payment information
  • payment status
  • account balances
  • reconciliation records.

Payment and financial information may be collected or processed by ExpiTrans or by acquiring banks, sponsor banks, payment processors, card networks, gateways, tokenization providers, digital-wallet providers, fraud-prevention providers, and other participants involved in payment services.

1.5 Account and authentication information

We may collect:

  • username
  • encrypted, hashed, or otherwise protected password information
  • account identifier
  • account permissions
  • user role
  • login history
  • security settings
  • multifactor-authentication status
  • one-time passcode requests
  • password-recovery records
  • security questions
  • account-lockout information
  • IP address
  • device information
  • browser information
  • information concerning suspected unauthorized access.

1.6 Transaction and service information

We may collect information relating to:

  • authorizations
  • captures
  • sales
  • refunds
  • voids
  • reversals
  • declines
  • settlements
  • deposits
  • invoices
  • recurring payments
  • chargebacks
  • retrieval requests
  • fraud alerts
  • risk reviews
  • account changes
  • equipment activity
  • technical incidents
  • services requested or provided.

1.7 Communications information

We may collect the contents and related metadata of communications with ExpiTrans,

including:

  • emails
  • text messages
  • web-form submissions
  • support tickets
  • chat communications
  • telephone calls
  • voicemail
  • correspondence
  • meeting records
  • documents or files submitted to us.

Where permitted by law and after providing any legally required notice, calls may be monitored or recorded for customer service, training, quality assurance, security, fraud prevention, dispute resolution, or compliance purposes.

1.8 Website, application, and device information

When you use our websites, portals, applications, or online services, we may automatically collect:

  • IP address
  • browser type
  • operating system
  • device type
  • device identifier
  • application version
  • referring page
  • pages viewed
  • links selected
  • session information
  • date and time of access
  • general location inferred from an IP address
  • cookie information
  • log information
  • diagnostic information
  • performance information
  • security events
  • application activity.

1.9 Information from third parties

We may receive information from:

  • merchants
  • authorized account administrators
  • business owners
  • referral partners
  • independent sales organizations
  • agents
  • sponsor banks
  • acquiring banks
  • payment processors
  • payment gateways
  • card networks
  • identity-verification providers
  • fraud-prevention providers
  • credit and business-information providers, where legally permitted
  • public records
  • government agencies
  • integration partners
  • equipment providers
  • professional advisers
  • other parties authorized to provide information to us.

1.10 Sensitive personal information

Some of the information we process may be considered sensitive personal information under applicable law, including:

  • government identification numbers
  • financial-account information
  • payment-card information
  • account credentials
  • authentication information
  • precise transaction information
  • identity-verification information
  • information used to detect or prevent fraud.

We use sensitive personal information only as reasonably necessary to provide services, authenticate users, process transactions, prevent fraud, administer accounts, comply with legal obligations, protect security, or carry out other permitted business purposes.

2. How We Use Information

We may use personal information to:

provide merchant, payment-processing, gateway, equipment, software, platform,

  • support, and related services
  • process payment transactions
  • facilitate authorizations, settlements, deposits, refunds, adjustments, and
  • payouts
  • create and administer accounts
  • authenticate users
  • send one-time passcodes and security codes
  • verify identity, ownership, and authority
  • evaluate applications and business relationships
  • conduct underwriting and risk reviews
  • monitor transaction and account activity
  • detect, investigate, prevent, and respond to fraud, abuse, unauthorized access,
  • money laundering, or other unlawful activity
  • administer reserves, chargebacks, retrieval requests, disputes, and compliance
  • matters
  • provide reports, statements, invoices, receipts, and reconciliation information
  • respond to inquiries and support requests
  • provide technical assistance
  • communicate regarding products, services, accounts, transactions, settlements,
  • security, support, or service availability

send marketing communications where legally permitted and where required consent

  • has been obtained
  • maintain consent, opt-out, suppression, and communication-preference records
  • operate, maintain, secure, troubleshoot, test, and improve our websites,
  • applications, and services
  • analyze service use and performance
  • manage business relationships
  • comply with sponsor-bank, processor, card-network, telecommunications-provider,
  • and contractual requirements
  • comply with legal, regulatory, tax, accounting, and reporting obligations
  • respond to subpoenas, court orders, government requests, or legal process
  • enforce agreements
  • establish, exercise, or defend legal claims
  • protect ExpiTrans, our merchants, users, partners, and the public
  • complete or evaluate a financing, merger, acquisition, sale, reorganization, or
  • similar business transaction
  • carry out other purposes disclosed when information is collected or with your
  • authorization.

3. SMS and Mobile Messaging

ExpiTrans may send SMS or MMS messages for one or more of the following purposes:

  • one-time passcodes
  • multifactor authentication
  • account registration
  • phone-number verification
  • login verification
  • password recovery
  • account-security alerts
  • suspected-fraud alerts
  • transaction confirmations
  • payment receipts
  • failed-payment notifications
  • settlement and deposit notifications
  • invoice reminders
  • merchant-account updates
  • support communications
  • technical-service communications
  • application or onboarding updates
  • operational notices
  • marketing or promotional communications where separately authorized.

3.1 Authentication messages

Authentication messages are sent after a user initiates an action requiring verification, such as:

  • requesting a sign-in code
  • registering an account
  • verifying a mobile number
  • resetting a password
  • recovering account access
  • enabling or using multifactor authentication.

An authentication request may result in a one-time SMS message containing a verification code. These messages are not promotional.

3.2 Recurring account and service messages

Where an individual affirmatively consents, ExpiTrans may send recurring messages regarding an account, transaction activity, payment status, support case, settlement, invoice, security event, or other service-related matter.

Message frequency varies based on account activity, transaction volume, support interactions, and communication preferences.

3.3 Marketing messages

ExpiTrans will obtain the level of consent required by applicable law before sending marketing or promotional text messages.

Consent to receive marketing text messages is not a condition of purchasing products or services.

Marketing consent is separate from consent to receive authentication, security, transactional, or service-related messages.

3.4 Mobile-information sharing

No mobile information will be shared with third parties or affiliates for their own marketing or promotional purposes.

This restriction includes mobile telephone numbers, SMS opt-in information, and text- messaging consent records.

We may disclose mobile information to service providers and other parties that assist us with:

  • transmitting messages
  • providing telecommunications services
  • managing consent and opt-outs
  • preventing fraud
  • maintaining security
  • supporting users
  • hosting systems
  • maintaining records
  • complying with law.

These parties may use mobile information only to perform services for ExpiTrans or as otherwise permitted by law.

Text-messaging originator opt-in data and consent will not be sold or shared with third parties for unrelated marketing purposes.

3.5 Message charges and frequency

Message and data rates may apply.

Message frequency varies according to the applicable program, account activity, transaction activity, authentication requests, support interactions, and user preferences.

3.6 Opting out

You may reply STOP to an applicable recurring ExpiTrans messaging program to opt out.

After submitting an opt-out request, you may receive one final confirmation message. Additional messages will not be sent through that program unless you later provide valid consent again.

Opting out of marketing or recurring notifications does not prevent you from receiving a one-time security or authentication message that you specifically request.

3.7 Help

Reply HELP for assistance.

You may also contact ExpiTrans at:

Telephone: 888-270-3642
Email: support@expitrans.com

Additional terms are available in the ExpiTrans SMS Messaging Terms and Conditions:

https://expitrans.com/sms-terms/

4. Cookies and Similar Technologies

We and our service providers may use:

  • cookies
  • pixels
  • local storage
  • software development kits
  • session technologies
  • similar technologies.

These technologies may be used to:

  • operate websites and applications
  • maintain user sessions
  • remember preferences
  • authenticate users
  • prevent fraud
  • protect security
  • measure traffic
  • understand service use
  • diagnose technical issues
  • improve performance
  • evaluate communications or marketing activity where legally permitted.

You may control cookies through your browser or device settings. Disabling cookies may prevent certain features from operating properly.

5. How We Disclose Information

We may disclose information to the following categories of recipients.

5.1 Service providers

We may disclose information to companies that provide:

  • cloud hosting
  • data storage
  • communications
  • messaging
  • customer support
  • payment technology
  • identity verification
  • fraud prevention
  • analytics
  • cybersecurity
  • document management
  • accounting
  • collections
  • legal services
  • professional services
  • operational support.

5.2 Financial institutions and payment-system participants

We may disclose information to:

  • acquiring banks
  • sponsor banks
  • issuing banks
  • payment processors
  • payment gateways
  • card networks
  • automated clearing house operators
  • digital-wallet providers
  • tokenization providers
  • payment facilitators
  • equipment providers
  • other parties involved in payment authorization, processing, settlement, risk
  • management, or compliance.

5.3 Business partners and authorized parties

We may disclose information to:

  • referral partners
  • independent sales organizations
  • agents
  • integration partners
  • software providers
  • merchants
  • account owners
  • authorized account administrators
  • business representatives
  • parties you direct or authorize us to communicate with.

5.4 Legal, security, and compliance recipients

We may disclose information where we reasonably believe disclosure is necessary to:

  • comply with law
  • comply with legal process
  • respond to a government request
  • satisfy bank, processor, or card-network obligations
  • investigate fraud or illegal activity
  • protect security
  • prevent harm
  • enforce an agreement
  • protect our rights or the rights of others
  • establish, exercise, or defend a legal claim.

5.5 Business transactions

Information may be disclosed or transferred in connection with an actual or proposed:

  • merger
  • acquisition
  • financing
  • reorganization
  • asset sale
  • change of control
  • insolvency
  • similar corporate transaction.

6. Sale and Sharing of Personal Information

ExpiTrans does not sell mobile telephone numbers, SMS opt-in information, or text- message consent records.

ExpiTrans does not disclose mobile information to third parties or affiliates for their own marketing or promotional use.

Certain privacy laws define “sale” or “sharing” broadly and may include some advertising or analytics activity even when no money is exchanged. Where applicable law gives you the right to opt out of a covered sale, sharing, targeted advertising, or similar activity, you may submit a request using the contact information below.

ExpiTrans will recognize legally required opt-out preference signals, such as the Global Privacy Control, when applicable to ExpiTrans’s activities and technically supported.

7. Data Retention

We retain personal information for as long as reasonably necessary to:

  • provide services
  • administer accounts
  • complete transactions
  • maintain financial and business records
  • manage risk
  • prevent fraud
  • respond to disputes
  • comply with bank, processor, network, legal, tax, accounting, and contractual
  • requirements
  • enforce agreements
  • protect our rights.

Retention periods vary based on:

  • the type of information
  • the services involved
  • legal requirements
  • contractual obligations
  • security considerations
  • dispute and chargeback periods
  • operational needs.

We may retain consent, opt-out, suppression, and messaging records after an account is closed to document compliance and ensure communication preferences continue to be honored.

8. Security

We use administrative, technical, organizational, and physical safeguards designed to protect personal information.

Safeguards may include:

  • access controls
  • encryption
  • tokenization
  • authentication controls
  • multifactor authentication
  • network security
  • logging
  • monitoring
  • vulnerability management
  • incident-response procedures
  • employee training
  • confidentiality obligations
  • vendor oversight
  • secure-development practices.

No security system or transmission method is completely secure. We cannot guarantee absolute security.

You are responsible for:

  • protecting your password and credentials
  • protecting your device
  • preventing unauthorized account access
  • not sharing one-time passcodes
  • maintaining accurate contact information
  • promptly reporting suspected unauthorized access.

9. Payment-Card and Authentication Information

Payment-card information may be encrypted, tokenized, transmitted, stored, or otherwise processed by ExpiTrans or authorized payment-system participants.

Payment information may be governed by:

  • merchant agreements
  • processor requirements
  • sponsor-bank requirements
  • card-network rules
  • industry security standards
  • applicable law.

Do not send payment-card numbers, security codes, PINs, account passwords, or one-time passcodes through unsecured email, ordinary text messages, or general support forms unless ExpiTrans expressly directs you to an approved secure method.

ExpiTrans will not ask you to disclose a one-time authentication code in response to an unsolicited call or message.

10. Children’s Privacy

ExpiTrans’s websites and services are intended for businesses and adults. They are not directed to children under 13.

We do not knowingly collect personal information directly from children under 13. If we learn that we collected such information without legally sufficient authorization, we will take reasonable steps to delete it.

11. Privacy Rights

Depending on your state of residence, applicable law, and applicable exceptions, you may have the right to:

  • know whether we process your personal information
  • request access to personal information
  • request correction of inaccurate personal information
  • request deletion of personal information
  • obtain a portable copy of certain personal information
  • request information about the categories of information we collect
  • request information about the sources and purposes of collection
  • request information about categories of recipients
  • opt out of certain sales or sharing
  • opt out of certain targeted advertising
  • limit certain uses of sensitive personal information
  • appeal the denial of a privacy request
  • exercise privacy rights without unlawful discrimination.

California law provides qualifying residents with rights that may include rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive information, and receive nondiscriminatory treatment.

These rights are not absolute. We may retain or continue to process information where permitted by law, including where information is reasonably necessary to:

  • complete a transaction
  • provide a requested service
  • maintain an account
  • detect fraud
  • protect security
  • comply with legal obligations
  • exercise legal rights
  • resolve disputes
  • maintain required records.

Submitting a request

You may submit a privacy request by:

Email: support@expitrans.com
Telephone: 888-270-3642

Please identify the request as a “Privacy Request.”

We may need to verify your identity before fulfilling a request. Verification may require information sufficient to match you with our records.

An authorized agent may submit a request where permitted by law. We may require evidence of the agent’s authority and may ask the individual to verify their identity directly.

Appeals

Where applicable law provides a right to appeal, you may appeal a denial by emailing support@expitrans.com and stating that you are submitting a “Privacy Request Appeal.”

12. Third-Party Websites and Services

Our services may contain links to or integrations with third-party websites,

applications, banks, processors, gateways, software providers, or other services.

Third parties maintain their own privacy policies and practices. ExpiTrans is not responsible for the privacy, security, availability, content, or practices of unaffiliated third parties.

You should review the privacy policies of third-party services before providing information to them.

13. International Use

ExpiTrans is based in the United States. Information may be processed and stored in the United States or other countries where ExpiTrans or its service providers operate.

Privacy and data-protection laws in those locations may differ from the laws where you reside.

Where legally required, ExpiTrans will use appropriate safeguards for cross-border data transfers.

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically.

When we make changes, we will update the “Last Updated” date. We may provide additional notice where required by law or where a change is material.

Your continued interaction with ExpiTrans after an updated Privacy Policy becomes effective constitutes acknowledgment of the updated policy to the extent permitted by law.

15. Contact Us

Questions, concerns, or privacy requests may be directed to:

ExpiTrans, Inc.
Attn: Privacy
22412 Gilberto, Suite B

Rancho Santa Margarita, California 92688

Telephone: 888-270-3642
Email: support@expitrans.com

ExpiTrans’s website currently publishes this address and primary telephone number as its contact information.