Privacy Policy

Effective Date: May 15, 2026

Introduction

Tereina LLC, a Delaware limited liability company, together with its affiliated companies (collectively, “Tereina,” “we,” “our,” or “us”), is committed to safeguarding your personal information. This Privacy Policy explains how we gather, use, share, and protect information when you interact with us—whether through www.tereina.com (the “Site”), the Tereina platform, related mobile applications, or any other service where this policy is posted (together, the “Services”). It also covers information we collect offline.

This Privacy Policy is not intended to limit any rights you may have under applicable law, including your right to a remedy or means of enforcement.

Who This Policy Covers

This policy applies to anyone who interacts with us or our Services, including prospective customers, existing customers and their authorized users, individuals who send or receive payments through the Tereina platform (whether on their own behalf or on behalf of an employer), partners, and visitors to our Site.

Customer Data We Process on Behalf of Others

When our customers provide us with information about their payees, suppliers, employees, or other third parties so that we can perform services on the customer’s behalf, we act as a data “processor” or “service provider” under applicable law. This Privacy Policy does not govern that processing—for questions about how a Tereina customer handles your information, please contact that customer directly. In limited circumstances, we may also act as a “controller” for certain purposes described in this Privacy Policy, even where the same data was originally provided by a customer.

By using any of our Services, you acknowledge that we may collect and process your information as described below.

Information We Collect

Sources of Information

We obtain information about you from several sources:

  • Directly from you — when you create an account, complete a profile, fill out forms, communicate with us, register for events, or otherwise provide information through the Services or offline interactions (e.g., phone calls, in-person meetings).
  • From our customers — for example, when a customer provides details about employees authorized to access the Services, or about their suppliers, vendors, and payees.
  • From third parties — including business partners, credit bureaus, identity verification providers, banking partners, data-enhancement services, and publicly available sources.
  • Automatically — through cookies, web beacons, and similar technologies when you visit our Site or use the Services (see “Cookies and Similar Technologies” below).

Types of Information

Depending on how you interact with us, we may collect:

  • Contact details — name, email address, phone number, and mailing address.
  • Business details — employer name, job title, and business address.
  • Account credentials — email, password, and related authentication information.
  • Financial and payment information — Social Security or Taxpayer Identification Numbers, bank account and routing numbers, IBAN, SWIFT codes, payment-processor account details, and payment preferences.
  • Identity verification documents — date of birth, government-issued ID (e.g., driver’s license, passport), bank statements, or other documents that establish identity or address.
  • Device and usage data — IP address, browser type, operating system, device identifiers, pages visited, referring and exit URLs, access timestamps, and how you navigate the Services.
  • General location data — approximate location inferred from your IP address.
  • Other information you choose to share — such as survey responses, support inquiries, or social-media handles.

For regulatory compliance, we may collect additional information through our Know Your Customer (“KYC”), Know Your Business (“KYB”), and Anti-Money Laundering (“AML”) procedures. Where information relates solely to a non-human entity, we do not treat it as personal data under this Privacy Policy.

How We Use Your Information

We use the information we collect for the purposes outlined below:

  • Providing and operating the Services — including account setup, identity verification, eligibility determinations, payment processing, and ongoing platform access.
  • Regulatory and legal compliance — meeting obligations under KYC, KYB, AML, sanctions-screening, Gramm-Leach-Bliley Act, and other applicable laws and regulations.
  • Security and fraud prevention — detecting, investigating, and preventing unauthorized access, fraud, and other harmful activity.
  • Customer support — responding to inquiries, troubleshooting issues, and providing technical assistance.
  • Improvement and development — analyzing usage patterns, conducting research, and refining existing features or developing new ones.
  • Marketing and communications — sending service-related notices, promotional materials, event invitations, and other messages (subject to your communication preferences).
  • Aggregation and analytics — creating de-identified or aggregated datasets that we or our partners may use for research, analytics, or other lawful purposes.
  • Enforcement — applying our agreements, including for billing and collections.

We may combine information collected through the Services with information obtained from affiliates or third parties and use the combined information consistent with this Privacy Policy.

How We Share Your Information

We do not sell your personal information in the traditional sense of that term. We may, however, share information in the following circumstances:

  • Service providers and vendors. We work with third parties that help us operate our business—such as cloud-hosting providers, payment processors, identity-verification services, analytics platforms, cybersecurity firms, customer-support tools, and professional advisors (legal, tax, financial, and compliance). These parties process information on our behalf and under our direction.
  • Financial Service Partners. To deliver our payment and financial services, we share information with partner banks and financial institutions as needed to process transactions and meet regulatory requirements.
  • Legal and safety obligations. We may disclose information to government authorities or law enforcement in response to valid legal process (e.g., subpoenas, court orders) or where we believe in good faith that disclosure is necessary to (i) comply with the law, (ii) investigate or prevent suspected fraud, illegal activity, or threats to safety, or (iii) protect our rights, property, or the integrity of the Services.
  • Advertising and analytics partners. We may make certain online identifiers available to advertising and analytics providers so they can help us measure campaign effectiveness and deliver relevant content. See “Cookies and Similar Technologies” for details and opt-out options.
  • Affiliates. We may share information among Tereina-affiliated entities for the purposes described in this Privacy Policy.
  • Corporate transactions. If Tereina undergoes a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the parties involved, including during due diligence.
  • With your consent or at your direction. We may share information when you ask us to or give us permission.
  • De-identified or aggregated data. We may freely share information that has been aggregated or stripped of personal identifiers, as such data is not governed by this Privacy Policy.

Cookies and Similar Technologies

We and our vendors place cookies (small text files stored by your browser) and use related technologies—such as pixel tags and web beacons—to operate, secure, and improve the Services. Cookies fall into the following categories:

  • Essential cookies — required for basic Site functionality, including authentication and security. These cannot be disabled.
  • Functional cookies — remember your preferences (e.g., language, region) and enable enhanced features.
  • Analytics and performance cookies — help us understand traffic patterns, measure Site performance, and conduct market research.
  • Advertising cookies — track browsing activity across sites to deliver more relevant ads. Disabling these cookies will not eliminate ads, but may make them less tailored to your interests.

You can adjust cookie settings through your browser at any time. Be aware that disabling certain cookies may impair your ability to use some features of the Services. For general information about cookies, visit www.allaboutcookies.org. To opt out of interest-based advertising, visit www.aboutads.info/choices (U.S.), youradchoices.ca (Canada), or youronlinechoices.com (Europe).

Data Storage, Transfers, and Retention

Where We Store and Process Data

Your information is stored and processed primarily in the United States. It may also be processed in other jurisdictions where our vendors or partners operate, as needed to deliver the Services or comply with legal requirements. If you are located outside the United States, your use of the Services constitutes consent to the transfer of your information to the United States and other applicable jurisdictions. Where required by law, we rely on approved data-transfer mechanisms.

How Long We Keep Data

We retain your information for as long as reasonably necessary to fulfill the purposes for which it was collected—for example, to provide the Services, satisfy contractual and legal obligations, maintain proper records, and preserve evidence in case of disputes. Unless a specific retention period is required by law or by agreement with you, we may securely delete or restrict access to your information at any time. Questions about retention can be directed to privacy@tereina.com.

Your Rights and Choices

Platform Notifications

You can manage payment-related and other platform notifications by updating your email settings within the Tereina platform.

Marketing Preferences

Every marketing email includes an unsubscribe link. You may also email privacy@tereina.com to opt out of promotional communications. Opting out of marketing does not affect service-related messages (e.g., account alerts, policy updates).

Cookie Controls

See “Cookies and Similar Technologies” above for instructions on managing cookie preferences through your browser or industry opt-out tools.

Privacy Rights Under Applicable Law

Depending on where you live, you may be entitled to exercise some or all of the following rights with respect to your personal information:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete personal data.
  • Delete your personal data, subject to legal and contractual exceptions.
  • Restrict or object to certain types of processing, including direct marketing.
  • Receive a portable copy of your personal data in a commonly used, machine-readable format.
  • Withdraw consent where processing is based on consent (without affecting the lawfulness of prior processing).
  • Opt out of the sale or sharing of personal data, targeted advertising, and certain profiling (where applicable under state law).
  • Limit the use and disclosure of sensitive personal information (for California consumers).

You may designate an authorized agent to exercise these rights on your behalf by providing signed, written permission or a power of attorney. We will not discriminate against you for exercising any of these rights.

To submit a request, email privacy@tereina.com. We may ask for additional information to verify your identity. We will respond within 30 days; if we need more time, we will notify you of the reason and any extension (not to exceed an additional 45 days). There is no fee for reasonable requests. If you provided personal information to a Tereina customer and believe we process it on that customer’s behalf, please direct your request to the customer.

Gramm-Leach-Bliley Act (GLBA) Notice

Because Tereina provides financial products and services, we may be subject to the Gramm-Leach-Bliley Act (“GLBA”). This section supplements the rest of this Privacy Policy with information specific to GLBA requirements.

Nonpublic Personal Information We Collect

Under the GLBA, we collect nonpublic personal information from two primary sources:

  • Information you supply — through applications, forms, or the Services, including your name, address, Social Security Number, and information from legal identity documents.
  • Information from consumer reporting agencies — such as credit history and creditworthiness data.

How We Share Nonpublic Personal Information

We do not share nonpublic personal information about customers or former customers with nonaffiliated third parties except as permitted or required by law—for example, sharing with service providers that help us deliver the Services (such as banking partners and payment processors), or in response to regulatory examinations, subpoenas, or court orders.

Opt-Out Rights

If we ever intend to share your nonpublic personal information in a way that would trigger a GLBA opt-out right, we will provide you with a separate notice at that time. You may also contact privacy@tereina.com to inquire about or exercise opt-out rights.

Safeguarding Your Information

Access to your nonpublic personal information is limited to employees and service providers with a legitimate need to know. We maintain physical, electronic, and procedural safeguards consistent with applicable law to protect this information.

Third-Party Links and Services

The Services may contain links to, or integrations with, websites and services operated by third parties. Those third parties have their own privacy practices, and we are not responsible for how they handle your information. We encourage you to review their privacy policies before sharing any personal data with them.

Communications

Service messages. We may send you transactional and administrative notices related to the Services—such as payment confirmations, security alerts, login notifications, and policy updates. Our customers and their users may also communicate with you through the platform.

Promotional messages. With your permission or where otherwise permitted by law, we and our authorized partners may send you information about new features, events, webinars, and other offerings we believe may interest you. See “Marketing Preferences” above for opt-out instructions.

Data Security

We maintain a comprehensive information-security program that includes administrative, technical, and physical safeguards—such as access controls, encryption, regular risk assessments, incident monitoring, and periodic third-party security testing—all designed to protect the confidentiality and integrity of your personal information.

No system is perfectly secure, however, and we cannot guarantee absolute protection against every threat. You play an important role in keeping your information safe by protecting your login credentials and using secure devices and networks when accessing the Services.

Regional and State-Specific Disclosures

European Economic Area and United Kingdom

When Tereina collects personal information on behalf of a customer (e.g., about the customer’s employees, partners, vendors, or affiliates), Tereina acts as a “sub-processor” to that customer, and the agreements between Tereina and the customer govern that processing.

Where Tereina collects personal data directly—outside the context of performing services for a particular customer—Tereina is the “data controller” (as defined under the General Data Protection Regulation). In that capacity, we rely on the following legal bases:

  • Performance of a contract — to fulfill our commitments to you.
  • Consent — where your permission is required or appropriate.
  • Legitimate interests — where processing supports our business in ways that do not override your fundamental rights and freedoms (e.g., fraud prevention, service improvement, customer engagement).
  • Legal obligation — where processing is necessary to comply with applicable law.

You also have the right to lodge a complaint with a supervisory authority in the EEA or UK, though we encourage you to contact us first so we can try to resolve the matter.

California

The California Consumer Privacy Act (“CCPA”) requires us to disclose the categories of personal information we collect and how we use and share it. Below are the CCPA categories that may apply, depending on how you interact with us:

  • Identifiers — name, alias, address, phone number, IP address.
  • California Civil Code §1798.80(e) personal information — e.g., driver’s license or state ID number.
  • Protected classifications — age, gender (e.g., collected during due-diligence checks).
  • Commercial information — transaction and purchase activity.
  • Internet/electronic activity — browsing history, search history, interaction with the Services.
  • Geolocation data — approximate location from IP address.
  • Professional/employment information — business-related data you provide.
  • Inferences — preferences or characteristics derived from collected data.
  • Education information — enrollment status, degrees, or awards.

Sensitive Personal Information: copies of identification documents (e.g., passports, driver’s licenses) and financial-account details (account numbers, routing numbers, related banking information).

We collect these categories (1) directly from you, (2) through your use of the Services, and (3) from third parties such as other users and unaffiliated sources.

“Sale” and “Sharing.” As those terms are uniquely defined under the CCPA, we may “share” certain online identifiers (e.g., cookie data, IP addresses, device IDs) with advertising partners. To opt out, contact privacy@tereina.com. We do not knowingly “sell” or “share” personal information of anyone under 16.

Do-Not-Track. We do not currently respond to browser Do-Not-Track signals.

Sensitive Personal Information. We do not use or disclose sensitive personal information beyond the purposes for which opt-out is not available under the CCPA.

For California-specific inquiries, submit a Verifiable Consumer Request to privacy@tereina.com.

Other U.S. States

Privacy laws in a growing number of states—including Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia—grant residents rights such as:

  • Confirming whether we process your personal data.
  • Accessing, correcting, or deleting your personal data.
  • Obtaining a portable copy of your personal data.
  • Opting out of targeted advertising, data sales, and certain profiling.

To exercise these rights, email privacy@tereina.com. If we deny a request, you may have the right to appeal by contacting us at the same address.

Nevada

Under Chapter 603A of the Nevada Revised Statutes, Nevada residents may opt out of the sale of certain “covered information.” To exercise this right, email privacy@tereina.com with the subject line “Nevada Opt-Out.”

General Provisions

Changes to This Privacy Policy

We may revise this Privacy Policy from time to time. The updated version will be effective as of the date posted on our Site. Where required by law or in the case of material changes, we will provide additional notice (e.g., via email).

Children’s Privacy

Our Services are not directed at anyone under 18. If we discover that we have inadvertently collected personal information from a child, we will take prompt steps to delete that information. If you believe we may hold data about a minor, please email privacy@tereina.com.

Contact Us

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please reach out to:

Tereina LLC
Attn: Privacy
Email: privacy@tereina.com