Legal
WyndMe Terms & Policies
WyndMe Corp · Wynd Payments LLC · Swipe Fundz Payments
Effective Date: August 1, 2026
Last Updated: August 1, 2026
About This Document
This document contains the complete set of terms and policies governing your use of the software, platforms, marketplaces, business-management tools, and payment services provided by WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments (together, “WyndMe,” “we,” “us,” or “our”).
It comprises seven parts. Each part is a distinct legal document, and each is incorporated by reference into the others. Together they form the entire agreement between you and WyndMe.
| Part | Document | What it governs |
|---|---|---|
| I | Terms of Service | The master contract: accounts, payment services, fees, settlement, chargebacks, reserves, setoff, liability, indemnity, termination, and dispute resolution |
| II | Privacy Policy | What personal information we collect, how we use and disclose it, and your privacy rights in the United States and Canada |
| III | Acceptable Use and Restricted Businesses Policy | What businesses, products, and activities are permitted, restricted, and prohibited |
| IV | E-Sign Consent and Electronic Communications Disclosure | Your consent to receive communications and sign documents electronically |
| V | Cookie Policy | Cookies and similar technologies, and how to control them |
| VI | Data Processing Addendum | Our respective data protection obligations where we process personal information on your behalf |
| VII | SMS and Messaging Terms | Text messages we send you, and messages you send using the Services |
Key provisions to read before you accept. Part I, Section 16 contains a binding arbitration agreement and class action waiver. Part I, Section 13 limits our liability. Part I, Section 9 authorizes us to withhold, reserve, offset, and debit funds and accounts. Part I, Section 6.3 sets out our suspension and termination rights.
Individual documents. Each part is also published separately at www.wyndme.com/terms-and-policies.
PART I: TERMS OF SERVICE
WyndMe Terms of Service
Effective Date: August 1, 2026
PLEASE READ CAREFULLY.
Section 16 contains a BINDING ARBITRATION AGREEMENT and a CLASS ACTION WAIVER that affect how disputes between you and WyndMe are resolved. Except as described there, you and WyndMe agree that disputes will be resolved by individual binding arbitration, not in court and not on a class or representative basis.
Section 13 limits our liability to you.
Section 9 authorizes us to withhold, deduct, reserve, offset, and debit funds and accounts in the circumstances described.
Section 6.3 gives us broad rights to suspend or terminate your account, including immediately and without prior notice, where risk, law, or our partners require it.
Table of Contents
- Agreement Structure and Acceptance
- Definitions
- The Services
- Eligibility, Accounts, and Onboarding
- Payment Services Delivered Through Our Payment Providers
- Your Obligations; Prohibited and Restricted Businesses; Suspension
- Transactions, Settlement, and Payouts
- Refunds, Returns, Chargebacks, and Disputes
- Fees, Taxes, Reserves, Setoff, and Debit Authorization
- Data, Privacy, and Security
- Intellectual Property and License
- Confidentiality
- Disclaimers and Limitation of Liability
- Indemnification
- Term, Termination, and Effects
- Dispute Resolution; Arbitration; Class Action Waiver
- General Provisions
- Additional Terms for Partner Platforms and Marketplaces
- Regional Terms: United States
- Regional Terms: Canada
1. Agreement Structure and Acceptance
1.1 Parties
These Terms of Service (these “Terms”) are a binding agreement between you, the business or individual accepting them, together with each of your affiliates that uses the Services (“you,” “your,” or “Customer”), and the applicable WyndMe entity:
| Product / Service | Contracting WyndMe Entity |
|---|---|
| Platform software, dashboards, APIs, business-management tools, marketplace software | WyndMe Corp |
| Payment enablement, onboarding, risk, settlement orchestration, and reporting under the WyndMe and Wynd Payments brands | Wynd Payments LLC |
| Payment enablement, merchant onboarding, and related commerce services under the Swipe Fundz brand | Swipe Fundz Payments |
WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments are referred to collectively as “WyndMe,” “we,” “us,” or “our.” The full legal name, entity form, and jurisdiction of organization of the contracting entity applicable to you are set out in your Order Form, account application, or dashboard.
Each WyndMe entity is severally, and not jointly, liable for its own obligations under these Terms. Each WyndMe entity, and each of its Affiliates, is an intended third-party beneficiary of these Terms with the right to enforce the provisions that benefit it directly. Where more than one WyndMe entity provides Services to you, these Terms apply separately to each such relationship.
1.2 The Complete Agreement
The following documents, each incorporated by reference, together form the “Agreement”:
- These Terms;
- the Acceptable Use and Restricted Businesses Policy;
- the Privacy Policy;
- the Data Processing Addendum (“DPA”);
- the E-Sign Consent and Electronic Communications Disclosure;
- the Cookie Policy;
- the SMS and Messaging Terms, if you use messaging features;
- any Order Form, pricing schedule, statement of work, or click-through agreement between you and WyndMe;
- any product-specific or service-specific terms we make available for a particular feature; and
- any Payment Provider terms that we are required to pass through to you, including any sponsor bank or acquirer merchant agreement you are asked to accept.
1.3 Order of Precedence
In the event of a conflict, the following order controls, from highest to lowest: (a) a mutually signed Order Form or written amendment; (b) product-specific terms; (c) pass-through Payment Provider terms, but only as to the subject matter they cover and only to the extent required by the applicable Payment Provider, network, or law; (d) these Terms; (e) the other incorporated policies.
1.4 Acceptance
You accept the Agreement by clicking “I agree,” signing an Order Form, submitting an application, accessing the API, or using the Services. If you accept on behalf of an entity, you represent that you are authorized to bind that entity, and “you” refers to that entity.
1.5 Changes to the Agreement
We may modify the Agreement. We will post the revised version and update the “Last Updated” date, and, for changes that materially and adversely affect you, we will provide at least thirty (30) days’ advance notice by email or dashboard notice, except where a shorter period is required by law, regulation, network rule, or a Payment Provider. Your continued use after the effective date constitutes acceptance. If you do not accept a change, your remedy is to stop using the Services and close your account under Section 15.
Changes required by law, regulation, network rules, or a Payment Provider, and changes that add features or are otherwise favorable to you, take effect immediately.
2. Definitions
Capitalized terms have the meanings given where first used, or as follows:
“Acceptable Use Policy”: the WyndMe Acceptable Use and Restricted Businesses Policy.
“Affiliate”: an entity that controls, is controlled by, or is under common control with a party.
“Applicable Law”: all laws, regulations, rules, orders, licenses, and governmental requirements applicable to a party, including the Bank Secrecy Act, USA PATRIOT Act, OFAC sanctions regulations, the Electronic Fund Transfer Act and Regulation E, the Truth in Lending Act and Regulation Z, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, the Telephone Consumer Protection Act, the CAN-SPAM Act, applicable state and provincial money transmission and consumer protection laws, and in Canada the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, PIPEDA, Quebec Law 25, and Canada’s Anti-Spam Legislation (CASL).
“Chargeback”: a reversal, return, dispute, retrieval, or invalidation of a Transaction initiated by a Customer, an issuer, a Payment Provider, or a Payment Network, including “chargebacks,” “disputes,” “ACH returns,” and “reversals.”
“Customer” (in Sections 5-9): an individual or business that transacts with you using the Services.
“Customer Data”: data you or your Customers submit to or generate through the Services, including Personal Information.
“Documentation”: our published technical and product documentation, developer guides, and API references.
“Fees”: the amounts payable to us as set out in Section 9 and the applicable pricing schedule.
“Loss”: any loss, liability, damage, cost, fine, penalty, assessment, judgment, settlement, or expense, including reasonable attorneys’ fees.
“Payment Method”: a card brand, digital wallet, ACH/EFT, bank transfer, or other payment instrument supported through the Services.
“Payment Network” or “Network”: Visa, Mastercard, American Express, Discover, Interac, NACHA, Payments Canada, and any other payment network, scheme, or clearing system used in connection with the Services.
“Payment Provider”: a payment processor, acquirer, sponsor or settlement bank, money transmitter, gateway, or other financial institution through which WyndMe enables Transactions to be authorized, cleared, settled, or funded.
“Network Rules”: the operating rules, regulations, bylaws, standards, manuals, and requirements of the Payment Networks and of our Payment Providers and their sponsor banks, as amended.
“Payout”: funds transferred to your Settlement Account.
“Personal Information”: as defined in the Privacy Policy.
“Reserve”: funds held under Section 9.6.
“Restricted Business” and “Prohibited Business”: as defined in the Acceptable Use Policy.
“Services”: the WyndMe software, platform, APIs, SDKs, dashboards, hosted pages, embedded components, point-of-sale software, sandbox environments, payment enablement services, and related support, documentation, and professional services.
“Settlement Account”: the bank account you designate to receive Payouts and from which we may debit amounts owed.
“Transaction”: a payment, refund, payout, transfer, or other movement of funds initiated through the Services.
“WyndMe Technology”: the Services, software, APIs, SDKs, Documentation, and all related intellectual property.
3. The Services
3.1 What We Provide
WyndMe is a software company. We provide commerce, marketplace, and business-management software and we enable Transactions through our network of Payment Providers. Subject to the Agreement, we grant you the right to access and use the Services during the Term for your internal business purposes.
3.2 What We Do Not Provide
WyndMe is not a bank. We do not take deposits, we do not hold funds for you as a depository institution, and we do not extend credit unless a separate written agreement says otherwise. Funds arising from Transactions are held, moved, and settled by our Payment Providers and their sponsor banks under their agreements and the Network Rules. Funds held pending settlement are not insured by the Federal Deposit Insurance Corporation or the Canada Deposit Insurance Corporation unless and to the extent a Payment Provider or bank tells you otherwise, and they do not earn interest for you.
We are not your fiduciary, agent, trustee, escrow agent, broker, or financial, tax, legal, or accounting advisor.
3.3 Modifications and Updates
We may modify, add, or discontinue any part of the Services. We will provide reasonable advance notice of a change that would materially reduce functionality you are then using, unless notice would create a security risk, or would cause us or a Payment Provider to violate Applicable Law, a Network Rule, or an obligation to a governmental authority.
We may release Updates. If we designate an Update as mandatory, you must implement it by the stated deadline, or within thirty (30) days if no deadline is stated. We may suspend Services for a Customer running an unsupported or non-compliant version.
3.4 Beta, Preview, and Trial Services
We may make features available as beta, preview, early access, or trial. These are provided “AS IS,” without warranty, indemnity, service level, or support, may be feature-incomplete or unstable, may be changed or withdrawn at any time, and should not be relied on in production. Your use is confidential. Notwithstanding anything else in the Agreement, our aggregate liability for beta, preview, and trial services is limited to US$1,000.
3.5 Support
We provide standard business and technical support through the channels described on our website. Paid support plans with enhanced response times may be available. We are not obligated to support your Customers; you are responsible for your own customer service.
3.6 Third-Party Services
We may reference, integrate with, or make available third-party applications, connectors, and services. Your use of any third-party service is governed by that provider’s terms and privacy policy and is at your sole risk. We do not endorse them and disclaim all liability for them. If you authorize a third-party service to access your WyndMe account, you authorize us to disclose data to it, and we are not responsible for what it does with that data.
3.7 Sandbox
Sandbox and test environments are for development and testing only. Do not submit real payment credentials, real Personal Information, or production data to a sandbox. Sandbox environments carry no availability commitment and may be reset without notice.
4. Eligibility, Accounts, and Onboarding
4.1 Eligibility
To use the Services you must:
- be a business, or an individual acting for business purposes, not for personal, family, or household purposes;
- be at least 18 years old (or the age of majority in your jurisdiction) and have legal capacity to contract;
- be located, formed, and operating in the United States or Canada, unless we agree otherwise in writing;
- not be, and not be owned or controlled by, a person listed on any sanctions or denied-party list maintained by OFAC, the U.S. Department of State, the U.S. Department of Commerce, Global Affairs Canada, or the United Nations, and not be located in a comprehensively sanctioned jurisdiction;
- not be operating a Prohibited Business, and not be operating a Restricted Business without our prior written approval; and
- not have previously been terminated by WyndMe, a Payment Provider, or a Payment Network for cause, unless we approve otherwise in writing.
4.2 Application and Underwriting
To open an account you must complete our application and provide the information we and our Payment Providers require. This is an underwriting process, and approval is not guaranteed. We and our Payment Providers may:
- verify the identity of your business and each Representative;
- obtain consumer and business credit reports, and you and each Representative expressly authorize us and our Payment Providers to obtain such reports at onboarding and periodically thereafter for as long as your account is open and any obligation remains outstanding;
- screen you and your Representatives against sanctions, watchlist, PEP, and adverse-media sources;
- request bank statements, processing statements, financial statements, formation documents, licenses, tax records, and product/website evidence;
- verify your Settlement Account and its ownership, including through a bank-data aggregation service;
- collect biometric identity verification as described in the Privacy Policy;
- conduct site visits, website reviews, and test transactions; and
- re-underwrite you at any time.
You must provide accurate, current, and complete information and must update it within ten (10) business days of any change, including changes in ownership or control, legal or trade name, address, business model, products or services sold, Settlement Account, expected volumes, or the addition of a new line of business. Failure to do so is a material breach.
4.3 Approval Conditions
Approval may be conditioned on volume caps, ticket-size limits, delayed funding, a Reserve, a personal guaranty, additional documentation, or restrictions on the products you may sell. Conditions may be adjusted at any time based on your performance and risk profile.
4.4 Personal Guaranty
If we require one, each Representative who signs a personal guaranty personally and unconditionally guarantees your performance of all obligations under the Agreement, including payment of Fees, Chargebacks, fines, and negative balances. This guaranty is a guaranty of payment and performance, not of collection, and survives termination.
4.5 Account Security
You are responsible for all activity under your account. You must:
- safeguard your credentials, API keys, and secrets, and never share them or embed secret keys in client-side code;
- enable multi-factor authentication for every user with dashboard access;
- promptly deprovision users who leave your organization or change roles;
- restrict access on a least-privilege basis; and
- notify us immediately at security@wyndme.com if you know or suspect any unauthorized access, credential compromise, or security incident.
We are entitled to rely on any instruction given through your account or API keys as authorized by you. You are solely responsible for Losses arising from unauthorized access to your account, except to the extent caused by our gross negligence, fraud, or willful misconduct.
4.6 Sub-Accounts and Users
If you create sub-accounts or invite users, you are responsible for their compliance with the Agreement and for all activity in those sub-accounts.
5. Payment Services Delivered Through Our Payment Providers
5.1 How Payments Work
Transactions initiated through the Services are authorized, cleared, settled, and funded by or through our Payment Providers and their sponsor banks. WyndMe provides the software, the onboarding and risk layer, the orchestration, and the reporting; the movement of funds occurs through our Payment Provider network.
5.2 Payment Provider Terms
Your use of payment functionality is subject to the terms, policies, and Network Rules of the applicable Payment Providers and Payment Networks. You agree to be bound by those terms and Network Rules as they apply to you, and we may pass through, present for acceptance, or require you to enter into a separate agreement with a Payment Provider or sponsor bank. Certain Payment Provider requirements may be non-negotiable and may change without our control.
We may change, add, or remove Payment Providers at any time, and may migrate your processing from one Payment Provider to another. We will use commercially reasonable efforts to make migrations non-disruptive, but changes may require you to re-onboard, re-verify, or accept new terms.
5.3 Network Rules
You must comply with all applicable Network Rules, including rules on: acceptance and honor-all-cards; display of marks; surcharging, convenience fees, and cash discounting; recurring billing authorization and cancellation; card-not-present authentication; PCI DSS; data storage prohibitions; refunds and returns; dispute response; prohibited transactions; excessive Chargeback and fraud thresholds; and merchant registration for certain categories.
Network Rules control in the event of conflict with the Agreement. Portions of the Network Rules are publicly available on the Networks’ websites; you are responsible for reviewing and complying with them. We will provide relevant excerpts on request.
You must not use the Services to submit transactions on behalf of any third party, you may not act as a payment facilitator, aggregator, or service bureau for others without our prior written approval and any required Network registration.
5.4 Card Data and PCI DSS
You must comply with PCI DSS and any applicable Network data security programs at all times. You must:
- not store full magnetic-stripe, chip, CVV/CVC/CID, or PIN data at any time after authorization;
- use our tokenization, hosted fields, hosted checkout, or certified integrations wherever available;
- maintain a current Attestation of Compliance or Self-Assessment Questionnaire appropriate to your merchant level, and provide it to us on request;
- use only PCI-validated point-of-interaction devices and P2PE solutions where applicable; and
- notify us within twenty-four (24) hours of discovering any actual or suspected compromise of cardholder data.
If a data compromise occurs in your environment, you are responsible for all resulting Losses, including forensic investigation costs (PFI), Network fines and assessments, card reissuance and fraud recovery costs, and issuer claims, and you authorize us to debit and offset those amounts under Section 9.
5.5 Prohibited Transaction Practices
You must not:
- submit a Transaction that does not arise from a bona fide sale of goods or services you actually provide;
- submit a Transaction on your own card or account, or on behalf of a person other than the actual purchaser (factoring, laundering, or transaction aggregation);
- split a single sale into multiple Transactions to evade limits, or artificially inflate a Transaction amount;
- submit a Transaction that represents the refinancing or transfer of an existing obligation, including a dishonored check or an uncollectible receivable;
- accept a payment for a Prohibited Business, or for a Restricted Business without approval;
- submit a Transaction after the underlying obligation has been disputed, charged back, or refunded;
- require a Customer to waive dispute rights, or discourage a Customer from exercising them;
- process a Transaction before shipping or delivering, except for pre-orders, deposits, and subscriptions that are clearly disclosed and permitted by Network Rules;
- impose a surcharge or fee not permitted by Applicable Law and Network Rules, or fail to make required surcharge disclosures;
- use a statement descriptor that does not clearly identify your business;
- process a Transaction for a product or service that is illegal where the Customer is located; or
- use the Services to test stolen credentials, or in a manner that produces abnormal authorization, decline, or velocity patterns.
5.6 Your Customer Relationships
You are the merchant of record for your sales unless a written agreement says otherwise. You are solely responsible for: the goods and services you sell; product descriptions, pricing, and availability; fulfillment and delivery; your terms of sale, refund policy, and privacy policy; taxes; customer service; and any dispute with a Customer. We are not a party to your sales.
You must clearly disclose to each Customer, before payment: your legal or trade name, contact information, a description of the goods or services, the total amount including taxes and fees, the currency, your return/refund/cancellation policy, and for recurring billing, the amount, frequency, and how to cancel.
5.7 Recurring and Subscription Billing
If you use recurring billing you must obtain and retain the Customer’s affirmative authorization, disclose the terms clearly and conspicuously before the first charge, send any notices required by Applicable Law and Network Rules (including advance notice of renewals, trial-to-paid conversions, and amount changes), honor cancellation requests promptly and by a method at least as simple as sign-up, and stop billing on cancellation. You must retain proof of authorization and produce it on request.
6. Your Obligations; Prohibited and Restricted Businesses; Suspension
6.1 General Obligations
You must:
- comply with the Agreement, Applicable Law, and Network Rules;
- use the Services only for lawful business purposes and in accordance with the Documentation;
- maintain all licenses, registrations, and permits required for your business;
- maintain accurate books and records and provide them on our reasonable request;
- cooperate with audits, investigations, and information requests from us, our Payment Providers, the Networks, and regulators, and respond within the time we specify (and in any event within five (5) business days for a risk or compliance request);
- maintain reasonable administrative, technical, and physical security safeguards;
- maintain a published privacy policy and obtain all consents necessary for the data you provide to us; and
- notify us promptly of any material adverse change in your business, financial condition, ownership, or legal status, and of any regulatory inquiry, enforcement action, class action, or insolvency event.
6.2 Restrictions
You must not, and must not permit any third party to:
- use the Services for personal, family, or household purposes;
- circumvent technical limitations, enable disabled functionality, or access non-public systems or data;
- use the Services for any activity that is fraudulent, deceptive, exploitative, abusive, or harmful;
- interfere with the operation of the Services or with other users;
- rent, lease, sublicense, resell, or transfer your rights, or act as a service bureau or pass-through agent;
- copy, republish, transmit, or distribute any part of the Services, Documentation, or website except as Applicable Law permits;
- reverse engineer, decompile, disassemble, or attempt to derive source code, except to the extent Applicable Law prohibits this restriction;
- remove or alter proprietary notices;
- benchmark or publish performance data about the Services without our written consent;
- use the Services to build a competing product;
- use automated means to scrape or extract data from the Services beyond the documented API;
- exceed published rate limits or take actions that degrade the Services; or
- create an account on behalf of a person whose account we suspended or terminated.
6.3 Suspension
We may suspend, limit, or restrict all or part of your access to the Services, your ability to submit Transactions, or the release of funds, immediately and without prior notice, if:
- we reasonably believe that continuing would cause us, you, or a Payment Provider to violate Applicable Law, a Network Rule, or a governmental or Payment Provider directive;
- an insolvency event occurs as to you;
- you breach the Agreement or any other agreement with us or a Payment Provider;
- we reasonably believe your activity presents an unacceptable risk of fraud, Chargebacks, credit loss, money laundering, sanctions exposure, reputational harm, or harm to a third party;
- your Chargeback rate, fraud rate, refund rate, or dispute rate exceeds thresholds we or a Network set;
- we detect a material change in your business, volume, ticket size, or transaction pattern that we have not underwritten;
- you are or may be operating a Prohibited Business, or a Restricted Business without approval;
- you fail to promptly provide information we request;
- a Payment Provider, sponsor bank, Network, or regulator directs us to;
- your activity degrades or threatens the security, privacy, stability, or reliability of the Services or any third-party system; or
- you fail to implement a required Update.
We will notify you of a suspension as and when Applicable Law and our obligations permit. We may be legally prohibited from disclosing the reason for a suspension, and nothing in the Agreement requires us to do so.
We are not liable to you or any third party for any Loss arising from a suspension, limitation, or restriction taken in accordance with this Section.
7. Transactions, Settlement, and Payouts
7.1 Authorization and Submission
You must obtain a valid authorization before submitting a Transaction, submit it within the timeframes required by Network Rules, and include the data elements the Networks require. Authorization is not a guarantee of payment and does not protect against a Chargeback.
7.2 Settlement and Payouts
Subject to Sections 6.3, 8, and 9, we will instruct the applicable Payment Provider to remit Payouts to your Settlement Account, net of Fees, Chargebacks, refunds, Reserves, adjustments, and other amounts owed, on the schedule specified in your pricing schedule or dashboard.
Payout timing is not guaranteed. It depends on the Payment Provider, the Networks, the banking system, cut-off times, holidays, your risk profile, and our and our Payment Providers’ review processes. We may delay, hold, or withhold a Payout where we or a Payment Provider are reviewing a Transaction, where a risk or compliance review is pending, where we require additional information from you, or where the Agreement otherwise permits.
7.3 Settlement Account
You must (a) designate and maintain at least one Settlement Account at a financial institution in a country we approve; (b) be the named account holder; (c) maintain authorization to receive credits to and initiate debits from it; and (d) update us promptly if it changes. You must not grant or assign to any third party a lien on or interest in funds owed to you under the Agreement before they are deposited into your Settlement Account.
If a Payout fails, is returned, or is rejected, we may retry, hold the funds, or require you to designate a new Settlement Account. We may charge our costs for failed transfers.
7.4 Errors and Adjustments
If we or a Payment Provider transfer funds to you in error, or credit your account with an amount you were not entitled to, you must promptly return them, and we may deduct, recoup, or offset them under Section 9.7 without prior notice. You must review your statements and reports and notify us of any error, discrepancy, or unauthorized Transaction within sixty (60) days of the date it first appeared. After that period, absent our gross negligence, fraud, or willful misconduct, the records are conclusive and you waive any claim relating to the item.
7.5 Currency and Conversion
If a Transaction or a deduction involves a currency other than the one in which the amount is denominated, conversion is performed at the rate applied by the relevant Payment Provider or Network, plus any applicable conversion fee, which we may retain in whole or in part. Exchange-rate fluctuation risk is yours.
7.6 Unclaimed and Dormant Funds
If funds owed to you cannot be delivered, because your Settlement Account is invalid or closed, we cannot reach you, or you fail to respond to our requests, we or our Payment Providers will hold them and attempt to contact you. If we cannot deliver them within the period specified by applicable unclaimed property law, we or our Payment Providers will escheat them to the appropriate authority. We may charge a reasonable administrative fee to the extent Applicable Law permits.
8. Refunds, Returns, Chargebacks, and Disputes
8.1 Your Refund Policy
You must maintain a clear, conspicuous, and lawful refund, return, and cancellation policy, disclose it before purchase, and honor it. If you do not disclose a policy, Network Rules may require you to accept returns and issue refunds on terms you did not intend.
8.2 Refunds
Refunds must be issued through the Services to the original Payment Method, in the original currency, and must not exceed the original Transaction amount. Do not issue a refund in cash, by check, or by another payment method unless Network Rules permit. We do not refund Fees on refunded Transactions unless the pricing schedule or Applicable Law says otherwise. You must have sufficient funds available; if you do not, Section 9.7 applies.
8.3 Chargebacks: Your Liability
You are liable for the full amount of every Chargeback, plus any associated fees, fines, and costs, regardless of the reason and regardless of whether you delivered the goods or services. This includes fraudulent-transaction Chargebacks, unless a specific liability-shift protection applies under the applicable Network Rules and you satisfied all of its conditions.
We will debit Chargebacks and associated amounts from your balance, Payouts, Reserve, or Settlement Account under Section 9.7.
8.4 Dispute Response
We will notify you of a Chargeback and, where the process permits, give you an opportunity to respond. You must respond within the deadline we specify, which will be shorter than the Network deadline so we can meet it, and provide complete, accurate, and legible compelling evidence. If you do not respond by the deadline, the Chargeback stands and you are liable.
We are not obligated to represent, contest, or appeal a Chargeback on your behalf, and we make no representation about the outcome. Chargeback decisions are made by issuers and the Networks, not by us.
8.5 Excessive Chargebacks and Fraud
The Networks impose monitoring programs with thresholds for Chargeback ratio, fraud ratio, and dispute count. If you exceed or approach a threshold, we may (a) require a remediation plan, (b) impose volume limits, delayed funding, or a Reserve, (c) charge you the fees and assessments the Networks impose, which can be substantial, (d) enroll you in a Network monitoring program at your cost, or (e) suspend or terminate your account.
8.6 Fines, Assessments, and Penalties
You are responsible for all fines, assessments, penalties, and charges imposed on us or a Payment Provider by a Network, sponsor bank, regulator, or governmental authority arising from your acts, omissions, business practices, Transactions, or breach of the Agreement, plus a reasonable administrative fee. These are payable on demand and may be collected under Section 9.7.
8.7 Match / Terminated Merchant File
You acknowledge that if your account is terminated for a reason listed in the Network Rules, including fraud, excessive Chargebacks, a data compromise, laundering, or violation of Network standards, we or our Payment Providers may be required to report you and your Representatives to the card networks’ terminated-merchant databases (including MATCH and the Consortium Merchant Negative File). A listing typically remains for five (5) years and can make it difficult or impossible to obtain payment processing. You consent to this reporting and release WyndMe, our Payment Providers, and the Networks from all Losses arising from it, to the fullest extent Applicable Law permits.
9. Fees, Taxes, Reserves, Setoff, and Debit Authorization
9.1 Fees
You will pay the Fees set out in your pricing schedule, Order Form, or on our published pricing page, including as applicable: transaction and interchange-plus or blended discount rates; per-authorization, per-transaction, and per-item fees; monthly platform, gateway, and account fees; PCI compliance and non-compliance fees; Chargeback and retrieval fees; refund and return fees; ACH return and NSF fees; instant/expedited payout fees; currency conversion fees; hardware and terminal fees; setup, implementation, and professional services fees; minimum monthly processing fees; early termination fees, if any; and account maintenance or dormancy fees.
Pass-through amounts (interchange, Network assessments, scheme fees, and dues) are set by the Networks, are not within our control, and change from time to time. We pass them through to you as they change, without notice.
9.2 Fee Changes
We may revise Fees on at least thirty (30) days’ notice, except that changes to pass-through amounts and changes required by Applicable Law, Network Rules, or a Payment Provider take effect immediately or on the notice period the relevant party requires. Continued use after the effective date is acceptance.
Fees paid are non-refundable and payment obligations are non-cancelable, except where Applicable Law requires otherwise.
9.3 Fee Waivers, Promotions, and Trials
We may offer a Service free of charge or waive a Fee, and may begin charging on thirty (30) days’ notice. Promotional pricing applies only for the stated period and only while you remain in good standing. Taxes may still apply to waived Fees.
9.4 Invoicing and Late Amounts
Where we invoice you, payment is due net thirty (30) days. Overdue amounts accrue interest at the lesser of 1.5% per month or the maximum rate Applicable Law permits, from the due date until paid. You will reimburse our costs of collection, including collection agency fees and reasonable attorneys’ fees.
9.5 Taxes
Fees exclude Taxes. You are solely responsible for determining, collecting, reporting, and remitting all sales, use, excise, VAT, GST, HST, PST, and other taxes and fees applicable to your sales, and for the accuracy of the tax information you configure in the Services. If we are required to collect or withhold Tax, we may deduct it and remit it to the authority; if you are exempt, provide us a valid exemption certificate.
We may issue information returns (including IRS Form 1099-K and Canadian equivalents) and file them with tax authorities in respect of your Transactions. You must provide accurate taxpayer information, including a valid TIN/EIN/SSN or Canadian Business Number. If your information is missing or does not match, we or our Payment Providers may be required to apply backup withholding to your Payouts and remit the withheld amounts to the tax authority; we are not obligated to refund amounts already remitted.
9.6 Reserves
We may require a Reserve at any time, in any amount, and for any period, if we reasonably determine one is necessary to protect against Chargebacks, refunds, fines, credit exposure, fraud, or other risk, or if a Payment Provider or Network requires it. Factors include your industry, delivery timelines, Chargeback and refund history, processing volume and volatility, financial condition, and time in business.
A Reserve may be funded by (a) withholding a percentage or fixed amount from Payouts, (b) a lump-sum debit of your Settlement Account, (c) a transfer you make to us, or (d) any combination. We will notify you when we establish or materially increase a Reserve, unless notice is prohibited or would increase risk.
You grant WyndMe and our Payment Providers a first-priority security interest in and lien on the Reserve, on all funds in your account balance, and on all funds payable to you under the Agreement, and you authorize us to file financing statements to perfect it. We may apply Reserve funds to any amount you owe without demand, prior notice, or legal process.
Reserve funds do not earn interest for you. We will release any remaining Reserve balance no earlier than ninety (90) days after termination or the last Transaction, whichever is later, and typically within one hundred eighty (180) days, once we determine that Chargeback, refund, and other exposure has run off. Some categories, such as future-delivery, travel, ticketing, and subscription businesses, may require longer hold periods.
9.7 Collection, Setoff, Recoupment, and Debit Authorization
You authorize us and our Payment Providers to collect all amounts you owe: Fees, Taxes, refunds, Chargebacks, fines, assessments, negative balances, funds transferred in error, and any other obligation under the Agreement or any other agreement with a WyndMe entity, by any one or more of the following, in any order, without prior notice and without demand or legal process:
- deducting them from your account balance;
- withholding them from current or future Payouts;
- drawing on your Reserve;
- initiating ACH/EFT debits or other electronic debits against your Settlement Account and any other bank account you have designated or that we identify as belonging to you;
- charging a payment card or other payment method on file;
- setting off against amounts payable by any WyndMe entity to you or any of your Affiliates;
- invoicing you for immediate payment; and
- pursuing any other remedy at law or in equity, including enforcing a personal guaranty.
This debit authorization is a separate, original authorization each time it is exercised, remains in effect until every account you hold with us is closed and all amounts owed are paid in full, whichever is later, and, to the fullest extent Applicable Law permits, you waive any right you may have under applicable debit-scheme rules to revoke it while amounts remain outstanding.
If the currency of an amount collected differs from the currency owed, we may convert at our applicable rate and charge the conversion cost.
If we cannot collect, the outstanding amount is immediately due and payable and we may refer it to collections and report it to credit bureaus and industry databases.
10. Data, Privacy, and Security
10.1 Privacy Policy and DPA
Our processing of Personal Information is governed by the Privacy Policy, and, where we act as your processor, by the DPA, both incorporated by reference. Each party will comply with the DPA.
10.2 Your Data Obligations
You represent and warrant that:
- you have provided all notices and obtained all consents, permissions, and authorizations required for us and our Payment Providers to collect, use, disclose, and retain Customer Data as contemplated by the Agreement;
- your collection and use of Customer Data complies with Applicable Law and with your own published privacy policy;
- you have the right to grant the rights you grant in the Agreement; and
- you will not provide us protected health information subject to HIPAA, and you are liable for any such disclosure.
10.3 Our Use of Data
We may collect, use, retain, and disclose data arising from your use of the Services as described in the Privacy Policy, including to provide and secure the Services, meet legal and Network obligations, prevent fraud and financial loss, and improve our products and risk models. You will use data we provide to you only as expressly permitted by the Agreement.
10.4 Security Incident Notification
You must notify us immediately, and in any event within twenty-four (24) hours, of any actual or suspected unauthorized acquisition, use, disclosure, access to, or loss of Personal Information or cardholder data on your systems that relates to the Services. You must cooperate fully with any resulting investigation, including engaging a PCI Forensic Investigator when required, at your cost.
10.5 Safeguards
Each party will maintain commercially reasonable administrative, technical, and physical safeguards designed to protect data in its possession from unauthorized access, accidental loss, and unauthorized modification. Our security commitments are described in the Privacy Policy and the DPA.
10.6 Data Retention After Termination
We are not obligated to retain your data after the Term except as required by Applicable Law, Network Rules, or our post-termination obligations. Export your data before terminating. We will make reasonable efforts to make data available for export for thirty (30) days after termination, except where prohibited or where the termination was for cause involving fraud or illegality.
11. Intellectual Property and License
11.1 Ownership
As between the parties, WyndMe and its licensors own all right, title, and interest in the WyndMe Technology, including all intellectual property rights in it. All rights not expressly granted are reserved. You own your Customer Data and your own intellectual property.
11.2 License to You
Subject to the Agreement, we grant you a limited, revocable, non-exclusive, non-transferable (except under Section 17.6), non-sublicensable license during the Term to access and use the WyndMe Technology solely as necessary to use the Services for your internal business purposes, in compliance with the Documentation and Applicable Law. The WyndMe Technology is licensed, not sold.
11.3 License to Us
You grant us and our Affiliates a worldwide, non-exclusive, royalty-free license during the Term to host, copy, transmit, display, and process Customer Data and your content as necessary to provide the Services and as otherwise permitted by the Privacy Policy and the DPA, and a perpetual, irrevocable, royalty-free license to use de-identified and aggregated data as described in the Privacy Policy.
11.4 Trademarks
Neither party may use the other’s trademarks without prior written consent, except that (a) we may identify you as a customer in our customer lists and on our website unless you opt out by emailing marketing@wyndme.com, and (b) you must display Network and Payment Provider marks as Network Rules require.
11.5 Feedback
If you give us suggestions, ideas, or feedback, you grant us a perpetual, worldwide, irrevocable, royalty-free, sublicensable license to use it for any purpose, with no obligation to you.
11.6 Open Source
Portions of the WyndMe Technology may include open source software. If an open source license grants you rights beyond, or conflicts with, the Agreement, that license controls as to that component.
12. Confidentiality
Each party will use at least reasonable care to protect the other’s Confidential Information and will not disclose it except to its and its Affiliates’ employees, contractors, agents, professional advisors, auditors, and, for WyndMe, Payment Providers, Networks, and service providers, in each case who need to know it and are bound by confidentiality obligations at least as protective as these.
Either party may disclose Confidential Information as required by Applicable Law, subpoena, court order, or governmental direction, and will (where legally permitted) give the other reasonable advance notice and reasonable assistance, at the discloser’s cost, to contest or limit the disclosure.
These obligations do not apply to information the recipient can document (a) is or becomes public through no fault of the recipient; (b) it lawfully knew without restriction before receipt; (c) it lawfully received from a third party without breach of a duty; or (d) it independently developed without use of the discloser’s Confidential Information.
Confidentiality obligations survive for three (3) years after termination; obligations as to trade secrets survive for as long as the information remains a trade secret.
13. Disclaimers and Limitation of Liability
13.1 Disclaimers
THE SERVICES AND WYNDME TECHNOLOGY ARE PROVIDED “AS IS” AND “AS AVAILABLE.” To the maximum extent Applicable Law permits, WyndMe and its Affiliates, licensors, and Payment Providers disclaim all warranties, conditions, representations, and statutory guarantees of any kind, express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, title, non-infringement, and any warranty arising from course of dealing, course of performance, or usage of trade.
We do not warrant that the Services will be uninterrupted, timely, secure, or error-free; that defects will be corrected; that the Services will meet your requirements; that any Transaction will be authorized, settled, or funded within any particular time; that your use will comply with Applicable Law; or that any data will be accurate, complete, or preserved.
We are not responsible for the acts or omissions of Payment Providers, Networks, sponsor banks, issuers, telecommunications carriers, or other third parties; for delays, failures, or problems inherent in the use of the internet, electronic communications, or systems outside our reasonable control; for the goods and services you sell; or for any third-party service.
No advice or information, oral or written, obtained from us creates any warranty not expressly stated in the Agreement.
13.2 Exclusion of Indirect Damages
TO THE MAXIMUM EXTENT APPLICABLE LAW PERMITS, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, RELIANCE, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST SAVINGS, LOSS OF BUSINESS, LOSS OF GOODWILL, BUSINESS INTERRUPTION, OR LOSS OR CORRUPTION OF DATA, arising out of or relating to the Agreement, whether in contract, tort (including negligence), strict liability, statute, or otherwise, even if the loss was foreseeable or the party was advised of its possibility.
13.3 Liability Cap
EXCEPT FOR EXCLUDED CLAIMS, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE AGREEMENT WILL NOT EXCEED THE TOTAL FEES YOU PAID TO WYNDME (EXCLUDING ALL PASS-THROUGH AMOUNTS LEVIED BY PAYMENT PROVIDERS AND NETWORKS) DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO LIABILITY.
“Excluded Claims” means: (a) your payment obligations, including Fees, Taxes, Chargebacks, refunds, negative balances, fines, and assessments; (b) your obligations under Section 14 (Indemnification); (c) either party’s breach of Section 12 (Confidentiality); (d) your breach of Sections 5.4 (PCI DSS), 6.2 (Restrictions), or 11 (Intellectual Property); and (e) a party’s fraud, gross negligence, or willful misconduct.
13.4 Failure of Essential Purpose; Allocation of Risk
The exclusions and limitations in this Section apply regardless of the form of action and survive and apply even if a limited remedy fails of its essential purpose. You acknowledge that these limitations are an essential basis of the bargain and that our pricing reflects them.
13.5 Jurisdictional Limits
Some jurisdictions do not allow the exclusion or limitation of certain warranties or damages. In those jurisdictions, our liability is limited to the maximum extent permitted by law. Nothing in the Agreement excludes liability that cannot lawfully be excluded, including for death or personal injury caused by negligence, or for fraud.
14. Indemnification
14.1 Your Indemnity
You will defend, indemnify, and hold harmless WyndMe, its Affiliates, and their respective officers, directors, employees, agents, Payment Providers, and sponsor banks (the “WyndMe Parties”) from and against all Losses arising out of or relating to:
- your use of the Services;
- the goods and services you sell, market, or deliver, including product liability, warranty, and consumer protection claims;
- your breach of the Agreement, Applicable Law, or Network Rules;
- any Chargeback, refund, fine, assessment, or penalty attributable to you;
- your Customer Data, your content, and your privacy and data security practices, including any data compromise in your environment;
- any dispute between you and a Customer, a Partner Platform, or a third party;
- your Taxes;
- your fraud, gross negligence, or willful misconduct;
- any claim that your content or trademarks infringe or misappropriate a third party’s rights; and
- any claim by a Representative, employee, or agent of yours relating to the Services.
14.2 Our IP Indemnity
We will defend you against any third-party claim that the WyndMe Technology, as provided by us and used in accordance with the Agreement, infringes that third party’s U.S. or Canadian patent, copyright, trademark, or trade secret rights, and will indemnify you for resulting Losses finally awarded or agreed in settlement.
Exclusions. This indemnity does not apply to a claim arising from: (a) combination of the WyndMe Technology with anything not provided by us, where the claim would not have arisen absent the combination; (b) your modification of the WyndMe Technology; (c) your use in breach of the Agreement or the Documentation; (d) your continued use after we notify you to stop; (e) Customer Data or your content; (f) beta, preview, or trial services; or (g) anything provided at no charge.
Remedies. If an infringement claim arises or we believe one is likely, we may, at our option and expense, (i) procure the right for you to keep using the affected item, (ii) modify or replace it to make it non-infringing, or (iii) on thirty (30) days’ notice, terminate the affected Services and refund any prepaid, unused Fees for them. This Section states our entire liability and your sole and exclusive remedy for any claim of intellectual property infringement.
14.3 Limitations and Procedure
An indemnitor’s obligations do not apply to the extent a claim arises from the indemnitee’s own fraud, gross negligence, willful misconduct, or breach of the Agreement.
The indemnitee must (a) promptly notify the indemnitor of the claim (delay excuses the indemnitor only to the extent it is prejudiced), (b) give the indemnitor sole control of the defense and settlement, and (c) reasonably cooperate at the indemnitor’s expense. The indemnitor will not enter a settlement that imposes a non-monetary obligation or an admission of liability on the indemnitee without the indemnitee’s prior written consent, not to be unreasonably withheld.
15. Term, Termination, and Effects
15.1 Term
The Agreement begins when you first accept it or use the Services and continues until terminated.
15.2 Termination by You
You may terminate for convenience at any time by closing your account through the dashboard and giving us written notice, subject to Section 15.5. You may terminate for cause if we materially breach and fail to cure within thirty (30) days of written notice.
15.3 Termination by Us
We may terminate the Agreement, or close or restrict your account, at any time, with or without cause, on thirty (30) days’ notice, or immediately and without notice if any event in Section 6.3 occurs, if you materially breach and fail to cure within ten (10) days of notice, if a Payment Provider, Network, or regulator directs us to, or if we discontinue the Services generally.
15.4 Effect of Termination
On termination:
- your right to access and use the Services immediately ceases, and you must stop using the WyndMe Technology and delete all API keys and copies;
- you must immediately pay all amounts owed, including accrued Fees and any negative balance;
- you remain liable for all Chargebacks, refunds, fines, assessments, and other obligations arising from Transactions processed before termination, without time limit;
- we may withhold Payouts and hold funds, including in a Reserve, under Section 9.6;
- we may continue to debit your Settlement Account under Section 9.7 until all obligations are satisfied;
- we may complete Transactions already in process and continue to process refunds and Chargebacks; and
- we may report the termination and the reason for it as described in Section 8.7.
Termination of the Agreement does not terminate any other agreement between you and a WyndMe entity or a Payment Provider unless we say so.
15.5 Wind-Down
We may require a reasonable wind-down period. During wind-down, you must continue to service your Customers, honor outstanding orders and subscriptions, and respond to Chargebacks. You must give your Customers any notice Applicable Law requires.
15.6 Survival
The following survive termination: Sections 2 (Definitions), 4.4 (Personal Guaranty), 5.4 (PCI DSS, as to pre-termination activity), 7.4 (Errors and Adjustments), 8 (Refunds, Chargebacks, Disputes), 9 (Fees, Taxes, Reserves, Setoff, Debit Authorization), 10 (Data, Privacy, Security, for as long as either party holds the relevant data), 11.1 and 11.3-11.6 (IP), 12 (Confidentiality), 13 (Disclaimers and Limitation of Liability), 14 (Indemnification), 15.4-15.6, 16 (Dispute Resolution), 17 (General Provisions), 19-20 (Regional Terms), and the DPA for as long as we hold Personal Information.
16. Dispute Resolution; Arbitration; Class Action Waiver
READ THIS SECTION CAREFULLY. IT AFFECTS YOUR LEGAL RIGHTS, INCLUDING YOUR RIGHT TO FILE A LAWSUIT IN COURT AND TO HAVE A JURY TRIAL.
16.1 Informal Resolution First
Before starting an arbitration or lawsuit, the complaining party must send a written Notice of Dispute to the other. Notices to WyndMe go to legal@wyndme.com and to WyndMe Corp, Attn: Legal, 3300 Triumph Blvd, Suite 100, Lehi, UT 84043. Notices to you go to the email on your account.
The Notice must include: (a) your legal name, account/merchant ID, email, and mailing address; (b) the factual and legal basis of the dispute; and (c) the specific relief sought and how it was calculated. If an attorney sends the Notice for you, you must include written authorization permitting us to discuss your account with that attorney, and we may require identity verification.
The parties will confer in good faith for thirty (30) days after the Notice. Completing this process is a condition precedent to commencing arbitration. The limitations period is tolled during it.
16.2 Agreement to Arbitrate
Except as stated in Sections 16.3 and 16.5, all disputes, claims, and controversies arising out of or relating to the Agreement or the Services, whether based on contract, tort, statute, fraud, misrepresentation, or any other legal theory, and whether arising before, during, or after termination, will be resolved by final and binding arbitration before a single arbitrator, and not in court.
Rules and forum. Arbitration will be administered by JAMS under its Comprehensive Arbitration Rules and Procedures (or its Streamlined Rules if the amount in controversy is under US$250,000), except as modified here. The rules are at www.jamsadr.com. Arbitration will be conducted in English, and the seat will be as specified in the Regional Terms (Section 19 or 20).
Authority. The arbitrator has exclusive authority to resolve all threshold issues, including arbitrability, scope, enforceability, and unconscionability, except that a court of competent jurisdiction, not the arbitrator, decides any challenge to the Class Action Waiver in Section 16.4. The arbitrator may award any relief a court could award to the individual claimant, subject to the Agreement’s limitations of liability, but may not modify the Agreement and may not award relief to or against anyone who is not a party.
Award. The arbitrator will issue a reasoned written decision. The award is final and binding and may be confirmed or enforced in any court of competent jurisdiction.
Costs. Each party bears its own attorneys’ fees and costs, and filing and arbitrator fees are allocated under the JAMS rules, except as provided in Section 17.13 (prevailing-party fees) and except that we will pay your share of arbitrator fees to the extent the arbitrator or JAMS determines they would be prohibitive or the applicable rules require.
Confidentiality. The parties will keep the existence, proceedings, submissions, evidence, and award confidential, except as necessary to prepare for or conduct the arbitration, to seek or oppose confirmation or vacatur, to disclose to professional advisors bound by confidentiality, or as Applicable Law requires.
Governing statute. The Federal Arbitration Act governs the interpretation and enforcement of this Section for U.S.-based Customers.
16.3 Claims Not Subject to Arbitration
The following are not subject to arbitration and will be brought in the courts specified in the Regional Terms:
- claims principally relating to a party’s intellectual property rights;
- actions to collect amounts you owe under the Agreement;
- claims within the jurisdiction of a small claims court, brought individually; and
- applications for injunctive or provisional relief in aid of arbitration.
16.4 CLASS ACTION AND JURY TRIAL WAIVER
YOU AND WYNDME EACH WAIVE THE RIGHT TO A TRIAL BY JURY AND THE RIGHT TO PARTICIPATE IN A CLASS, COLLECTIVE, CONSOLIDATED, PRIVATE ATTORNEY GENERAL, OR REPRESENTATIVE ACTION.
Claims may be brought only in an individual capacity. The arbitrator may not consolidate or join more than one person’s claims and may not preside over any form of representative or class proceeding, unless all affected parties agree in writing.
If this Section 16.4 is found unenforceable as to a particular claim or request for relief, then that claim or request must be severed and brought in court, and the remaining claims will proceed in arbitration. If Section 16.4 is found unenforceable in its entirety, the entirety of Section 16.2 is void.
16.5 Opt-Out
You may opt out of Sections 16.2 and 16.4 by sending written notice to legal@wyndme.com within thirty (30) days of the date you first accept these Terms. The notice must state your name, account ID, and an unambiguous statement that you opt out of arbitration. Opting out does not affect any other provision. If you opt out, disputes will be resolved in the courts specified in the Regional Terms.
16.6 Time Limit
To the fullest extent Applicable Law permits, any claim arising out of or relating to the Agreement must be brought within one (1) year after it accrues, or it is permanently barred.
16.7 Survival
This Section survives termination of the Agreement and closure of your account.
17. General Provisions
17.1 Compliance with Law. Each party will comply with Applicable Law in performing under the Agreement. You are solely responsible for evaluating and configuring the Services to meet your own legal obligations.
17.2 Notices and Electronic Communications. Notices to us go to legal@wyndme.com and the address in Section 16.1, and are effective on receipt. You consent to receive communications electronically as described in the E-Sign Consent and Electronic Communications Disclosure. Communications from us are deemed received on the earliest of (a) posting to the dashboard or our website, (b) sending by email or SMS, and (c) three business days after mailing. You must maintain a current, monitored email address on your account.
17.3 Force Majeure. Neither party is liable for a failure or delay caused by an event beyond its reasonable control, including acts of God, natural disaster, epidemic, war, terrorism, civil unrest, labor dispute, governmental action, embargo, utility or telecommunications failure, internet or cloud provider outage, cyberattack, or failure of a Payment Provider, Network, or banking system. This does not excuse a payment obligation.
17.4 Independent Contractors; No Agency. The parties are independent contractors. Nothing creates a partnership, joint venture, agency, fiduciary, or employment relationship.
17.5 No Third-Party Beneficiaries. Except for the WyndMe Parties (Section 14.1), WyndMe’s Affiliates, and our Payment Providers and their sponsor banks, each of which may enforce the provisions benefiting it, there are no third-party beneficiaries.
17.6 Assignment. You may not assign or transfer the Agreement, by operation of law or otherwise, without our prior written consent; a change of control of your business is deemed an assignment. We may assign the Agreement freely, including to an Affiliate or in connection with a merger, acquisition, financing, or sale of assets. Any prohibited assignment is void. The Agreement binds and benefits permitted successors and assigns.
17.7 Entire Agreement. The Agreement is the entire agreement between the parties on its subject matter and supersedes all prior and contemporaneous proposals, representations, and understandings, written or oral. Any terms in your purchase order, vendor portal, or other business form are void and of no effect, even if we sign or accept them.
17.8 Severability. If a provision is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or severed if it cannot be, and the rest of the Agreement remains in effect. (Section 16.4 has its own severability rule.)
17.9 Waiver. No failure or delay in exercising a right waives it. A waiver is effective only if in writing and signed by the waiving party, and applies only to the specific instance.
17.10 Cumulative Rights; Injunctive Relief. All rights and remedies are cumulative. Each party may seek injunctive or equitable relief for a breach of confidentiality or intellectual property obligations without posting a bond or proving actual damages.
17.11 Trade and Sanctions Compliance. You represent that you are not, and are not owned or controlled by, a sanctioned or denied party, and you will not use the Services in violation of U.S. or Canadian export control, sanctions, or anti-boycott laws, or facilitate transactions involving a sanctioned party or jurisdiction.
17.12 Anti-Corruption. Neither party will offer, promise, or give anything of value to any government official or other person to improperly obtain or retain business, in violation of the U.S. Foreign Corrupt Practices Act, the Corruption of Foreign Public Officials Act (Canada), or comparable law.
17.13 Legal Fees. In any proceeding arising out of the Agreement, the prevailing party is entitled to its reasonable attorneys’ fees and costs. If you owe amounts under the Agreement, you are also liable for all costs we incur collecting them, including collection agency fees, arbitration and court costs, applicable interest, and reasonable attorneys’ fees.
17.14 Interpretation. “Including” means “including without limitation.” Headings are for convenience only. References to a document include its amendments. The Agreement will not be construed against the drafter.
17.15 Language. The Agreement is drafted in English. Any translation is for convenience only, and the English version governs, except in Quebec, see Section 20.5.
17.16 Counterparts and Electronic Signature. The Agreement may be executed electronically and in counterparts, each of which is an original.
17.17 Publicity. As set out in Section 11.4.
17.18 Audit. We and our Payment Providers may audit your compliance with the Agreement, PCI DSS, and Network Rules on reasonable notice, and you will cooperate and provide access to relevant records, systems, and personnel. If an audit reveals material non-compliance, you will bear its reasonable cost.
17.19 Insurance. We may require you to maintain, and evidence, commercially reasonable insurance appropriate to your business, including general liability, cyber liability, and, where applicable, product liability, naming us as an additional insured on request.
18. Additional Terms for Partner Platforms and Marketplaces
This Section applies if you use the Services to enable payments for, or provide services to, your own users, sellers, merchants, or sub-merchants (“Sub-Merchants”).
18.1 Your Responsibility for Sub-Merchants. You are fully responsible for your Sub-Merchants’ compliance with the Agreement, Applicable Law, and Network Rules, and for all Losses arising from their acts and omissions, including Chargebacks, refunds, fines, negative balances, and fraud losses, as if they were your own.
18.2 Onboarding and Due Diligence. You must collect and pass to us the KYC/KYB information we and our Payment Providers require for each Sub-Merchant, perform the due diligence and screening we specify, and refrain from onboarding a Sub-Merchant we or a Payment Provider have declined or terminated. You must promptly update Sub-Merchant information.
18.3 Sub-Merchant Agreements. You must require each Sub-Merchant to accept an agreement containing terms at least as protective of WyndMe, our Payment Providers, and the Networks as the Agreement, including the pass-through provisions we specify, and must name WyndMe and our Payment Providers as third-party beneficiaries. You must provide us a copy on request.
18.4 Monitoring. You must monitor Sub-Merchant activity for fraud, prohibited business activity, excessive Chargebacks, and violations, and must promptly report and, at our direction, suspend or terminate any Sub-Merchant.
18.5 Registration. Certain Network Rules require registration of payment facilitators, marketplaces, and their Sub-Merchants. You must cooperate with, and bear the cost of, any required registration, and must not exceed any volume threshold above which a Sub-Merchant must contract directly with an acquirer.
18.6 Funds Flow. You may not take possession, custody, or control of settlement funds owed to Sub-Merchants except as expressly permitted in writing by us and the applicable Payment Provider, and only in compliance with money transmission and payment facilitator requirements.
18.7 Guaranty and Reserve. We may require a corporate guaranty, personal guaranty, Reserve, or collateral sized to your Sub-Merchant portfolio’s risk.
18.8 Data. As between you and us, you are the controller of Sub-Merchant and Customer Data you provide, and you are responsible for the notices and consents required to provide it to us and our Payment Providers.
19. Regional Terms: United States
19.1 Contracting Entity and Governing Law. If you are located in the United States, your contracting entity is as set out in Section 1.1, and the Agreement and all disputes are governed by the laws of the State of Utah, excluding its conflict-of-laws rules and excluding the U.N. Convention on Contracts for the International Sale of Goods.
19.2 Arbitration Seat and Rules. The seat of arbitration is Salt Lake County, Utah, and JAMS Comprehensive (or Streamlined) Rules apply, as described in Section 16.2. The Federal Arbitration Act governs Section 16.
19.3 Courts. For claims not subject to arbitration, the parties consent to the exclusive jurisdiction and venue of the state and federal courts located in Salt Lake County, Utah, and waive any objection based on forum non conveniens.
19.4 U.S. Government Users. The WyndMe Technology is “commercial computer software” and “commercial computer software documentation.” Government users acquire only the rights set out in the Agreement, consistent with FAR 12.212 and DFARS 227.7202.
19.5 Consumer Protection. Nothing in the Agreement limits any right you may have that cannot be waived under Applicable Law.
20. Regional Terms: Canada
20.1 Governing Law. If you are located in Canada, the Agreement and all disputes are governed by the laws of the Province of Ontario and the federal laws of Canada applicable in Ontario, excluding conflict-of-laws rules, except that if you are located in Quebec, the laws of the Province of Quebec govern.
20.2 Arbitration Seat and Rules. The seat of arbitration is Toronto, Ontario (or Montreal, Quebec, for Quebec-based Customers), administered by the ADR Institute of Canada under its Arbitration Rules, or by JAMS if the parties agree. The Arbitration Act, 1991 (Ontario) or the equivalent provincial statute governs.
20.3 Courts. For claims not subject to arbitration, the parties consent to the exclusive jurisdiction of the courts of the Province of Ontario (or Quebec, for Quebec-based Customers).
20.4 Consumer and Provincial Protections. Nothing in the Agreement limits any right or remedy that cannot lawfully be waived or limited under applicable provincial consumer protection legislation. Certain provinces restrict class action waivers and limitations of liability in consumer contracts; to the extent Section 16.4 or Section 13 is unenforceable as to you under provincial law, it will not apply to that extent, and the balance remains in effect.
20.5 Quebec, Language. Les parties conviennent que la présente convention et tous les documents s’y rapportant soient rédigés en anglais. The parties confirm their express wish that the Agreement and all related documents be drawn up in English, subject to the requirements of the Charter of the French Language. Where the Charter requires a French version, we will provide one on request, and in the event of a discrepancy the French version governs for Quebec-based Customers to the extent the Charter so requires.
20.6 CASL. Commercial electronic messages we send you are sent in reliance on your express or implied consent under Canada’s Anti-Spam Legislation. You may withdraw consent at any time using the unsubscribe mechanism in any message.
20.7 PCMLTFA. You acknowledge that we and our Payment Providers may be subject to obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, including customer identification, record keeping, and reporting to FINTRAC, and that we may be prohibited from disclosing that a report has been made.
Contact
WyndMe Corp 3300 Triumph Blvd, Suite 100 Lehi, UT 84043, United States
General: contact@wyndme.com Legal: legal@wyndme.com Security: security@wyndme.com Privacy: privacy@wyndme.com Support: support@wyndme.com
© 2026 WyndMe Corp. WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments.
PART II: PRIVACY POLICY
WyndMe Privacy Policy
Effective Date: August 1, 2026
1. Introduction and Scope
1.1 Who We Are
This Privacy Policy (“Policy”) describes how WyndMe Corp and its affiliated companies, including Wynd Payments LLC and Swipe Fundz Payments (together, “WyndMe,” “we,” “us,” or “our”), collect, use, disclose, and otherwise process personal information.
WyndMe is a software company. We build and license commerce, marketplace, and business-management software, and we enable our customers to accept and disburse payments through our network of payment providers, processors, acquirers, sponsor banks, and other financial institution partners (each, a “Payment Provider”). Payment transactions initiated through the Services are processed, settled, and funded by or through our Payment Providers.
For clarity, and unless a specific section of this Policy says otherwise, all three entities are covered by this Policy:
| Entity | Role in the Services |
|---|---|
| WyndMe Corp | Parent company; develops and licenses the WyndMe platform, marketplace software, dashboards, APIs, and business-management tools. Operates the Website. |
| Wynd Payments LLC | Provides payment enablement, onboarding, underwriting support, risk and fraud services, settlement orchestration, and reporting delivered through our Payment Providers. |
| Swipe Fundz Payments | Provides payment enablement, merchant onboarding, and related commerce services delivered through our Payment Providers. |
1.2 What This Policy Covers
This Policy applies to personal information we process in connection with:
- www.wyndme.com and any other websites, subdomains, or landing pages we operate (the “Website”);
- the WyndMe dashboards, portals, mobile applications, APIs, SDKs, hosted checkout pages, embedded components, point-of-sale software, and sandbox/test environments;
- payment acceptance, payouts, invoicing, subscription billing, marketplace splits, and related financial workflows we enable through our Payment Providers;
- onboarding, identity verification, underwriting, risk, and fraud-prevention processes;
- our sales, marketing, support, and partner programs; and
- recruiting and job applications
(collectively, the “Services”).
1.3 What This Policy Does Not Cover
This Policy does not apply to:
- Our merchants’ and platforms’ own data practices. If you bought goods or services from, or created an account with, a business that uses WyndMe, that business decides how it handles your information. Read its privacy notice.
- Our Payment Providers’ independent processing. Payment Providers, card networks, issuing banks, and acquiring banks process transaction data as independent controllers under their own policies and under card network rules.
- Third-party sites, apps, and integrations you reach through the Services.
- Employee and contractor data, which is governed by our internal personnel notices (except for the job-applicant disclosures in Section 13).
1.4 Our Role: Controller vs. Processor
This distinction matters and drives who you should contact about your rights.
We act as a controller (or “business” under U.S. state law) when we decide why and how personal information is processed, for example, information about:
- visitors to our Website;
- prospective customers and the individuals who represent them in sales conversations;
- the owners, officers, beneficial owners, control persons, and authorized representatives of businesses that apply for or use the Services;
- individuals whose information we process for identity verification, sanctions screening, underwriting, anti-money-laundering (“AML”), fraud detection, loss prevention, and legal-compliance purposes;
- job applicants; and
- our own security, product analytics, and internal business operations.
We act as a processor (or “service provider” / “third party” as applicable) when we process personal information on behalf of, and under the instructions of, a Partner Platform or Merchant, for example, the cardholder and customer records we handle so a Merchant can accept a payment, issue a refund, or reconcile a payout.
Where we act as a processor, please direct your privacy requests to the Merchant or Partner Platform you dealt with. We will refer requests we receive to the relevant customer and assist them in responding. Where we act as a controller, contact us using Section 16.
Important: Even when we act as a processor for a customer, we independently act as a controller for a limited set of purposes we are legally or contractually required to perform ourselves, including fraud prevention, AML/sanctions screening, network-rule compliance, risk monitoring, and defending legal claims. Nothing in this Policy limits our ability to process personal information for those purposes.
1.5 Acceptance
By using the Services, visiting the Website, or submitting information to us, you acknowledge that you have read and understood this Policy. If you do not agree with it, do not use the Services. This Policy is incorporated by reference into the WyndMe Terms of Service.
2. Definitions Used in This Policy
| Term | Meaning |
|---|---|
| Customer | An individual or business that purchases goods or services from, donates to, or otherwise transacts with a Merchant. |
| Merchant | A business that uses the Services (directly or through a Partner Platform) to accept payments, make payouts, or run its operations. |
| Partner Platform | A software platform, marketplace, independent software vendor, payment facilitator, franchisor, or similar business that integrates the Services and makes them available to its own users. |
| Payment Provider | A payment processor, acquirer, sponsor or settlement bank, money transmitter, card network, ACH originator, or other financial institution through which payment transactions are authorized, cleared, settled, or funded. |
| Personal Information | Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. Also referred to as “personal data” or “personal information” under Canadian law. |
| Representative | An owner, officer, director, beneficial owner, control person, authorized signer, or administrator of a Merchant or Partner Platform. |
| Sensitive Personal Information | The subset of Personal Information treated as sensitive under applicable law, see Section 3.3. |
3. Personal Information We Collect
3.1 Categories We Collect
We collect the categories below. Not every category applies to every person; what we collect depends on how you interact with us.
(a) Identifiers and contact information Full name, preferred name, postal address, billing address, shipping address, email address, telephone and mobile number, account username, WyndMe account ID, merchant ID (MID), terminal ID, customer/vendor number, IP address, device identifiers, cookie and pixel identifiers, advertising identifiers, and other unique online identifiers.
(b) Government-issued identifiers Social Security Number or last four digits, Individual Taxpayer Identification Number, Employer Identification Number, Social Insurance Number (Canada), Business Number (Canada), driver’s license number, passport number, state/provincial ID number, and images of the identity documents themselves. Collected primarily from Representatives for identity verification, tax reporting, and AML/Know-Your-Customer (“KYC”) and Know-Your-Business (“KYB”) obligations.
(c) Financial and payment information Bank account and routing/transit numbers, account ownership and balance verification data, payment card number (PAN), expiration date, cardholder name, card verification value (processed transiently and not retained by us), tokenized card and account references, digital-wallet identifiers, payout account details, settlement instructions, statement descriptors, processing volumes and averages, chargeback and return history, reserve balances, credit and financial-standing information, and the contents of processing statements you provide.
(d) Commercial and transaction information Records of goods and services purchased, obtained, considered, refunded, or returned; transaction amount, currency, date, time, and status; authorization and decline codes; interchange and assessment categories; invoice and order data; subscription and recurring-billing schedules; marketplace split and disbursement records; tip, tax, surcharge, and discount data; and purchasing or consuming histories and tendencies.
(e) Business and underwriting information Legal entity name and DBAs, entity type, formation documents, ownership and control structure, beneficial ownership percentages, industry and merchant category code (MCC), website and marketing materials, product and service descriptions, refund and fulfillment policies, expected and actual processing volumes, average and high ticket amounts, prior processing history and terminations, bankruptcy and litigation history, licensing and permits, and information obtained from credit bureaus and commercial data providers.
(f) Biometric information Scans of facial geometry and related biometric identifiers derived from a selfie image and an identity document, used solely to verify that you are who you say you are and to detect and prevent identity fraud. See Section 8 for our full Biometric Information Notice.
(g) Internet, network, and device activity Browser type and version, operating system, device type and model, language and locale settings, referring and exit URLs, pages and screens viewed, features used, dashboard interactions, search terms entered in our Services, API call metadata, session duration, clickstream data, crash and diagnostic logs, and information collected through cookies, SDKs, pixels, tags, and similar technologies. We may also use session-replay technology that records mouse movements, scrolls, clicks, and keystroke events (with sensitive field contents masked) to troubleshoot issues and improve the product.
(h) Approximate geolocation City, region, and country derived from IP address, and, for certain point-of-sale, in-person acceptance, and fraud-prevention features, more precise device location where you have granted the applicable permission. You can withdraw device-location permission in your device settings.
(i) Audio, electronic, and visual information Recordings and transcripts of support and sales calls (where permitted by law and with any legally required notice or consent), chat and messaging transcripts, screen shares and screenshots you send us, photographs of documents you upload, and store or terminal imagery you provide in connection with a dispute.
(j) Professional and employment information Job title, role, employer, professional history, résumé and CV contents, references, salary expectations, work authorization status, and background-check results (for job applicants and, where required for regulatory reasons, for Representatives).
(k) Communications The content and metadata of emails, support tickets, chat sessions, contact and demo-request forms, survey responses, event registrations, and messages you send us or that we send you.
(l) Inferences Profiles and predictions we derive from the above, such as risk scores, fraud-likelihood signals, creditworthiness indicators, product-interest scores, and churn predictions.
(m) Sensitive Personal Information See Section 3.3.
3.2 Information About Customers of Our Merchants
If you are a Customer of a Merchant that uses WyndMe, we typically receive: your name, email, phone, billing and shipping address, payment instrument details (usually tokenized), transaction amount and description, device and IP data associated with the transaction, and any dispute or refund records. We process this information as a processor on behalf of the Merchant or Partner Platform, except as described in Section 1.4.
3.3 Sensitive Personal Information
We collect the following categories that are treated as “sensitive personal information,” “sensitive data,” or equivalent under applicable law:
- Social Security Number, Social Insurance Number, driver’s license, state/provincial ID, or passport number;
- account log-in credentials, and financial account numbers in combination with any required security or access code, password, or credentials allowing access to an account;
- biometric information processed for the purpose of uniquely identifying an individual;
- precise geolocation, where you enable it; and
- the contents of communications where we are not the intended recipient (for example, message content routed through our systems on a Merchant’s behalf).
We use and disclose Sensitive Personal Information only for the purposes permitted under applicable law, principally to perform the Services you or our customer requested, to verify identity, to prevent, detect, and investigate fraud and security incidents, to comply with law, and for the other permitted business purposes described in Section 5. We do not use Sensitive Personal Information to infer characteristics about you, and we do not sell or share it for cross-context behavioral advertising.
3.4 Information We Do Not Want
Do not send us information we have not asked for. In particular, do not transmit protected health information subject to HIPAA, full payment card magnetic-stripe or chip data, CVV/CVC values outside the authorized transaction flow, or PIN data through unsecured channels such as email or support chat. If you do, you are responsible for that disclosure, and we may delete the information.
4. How We Collect Personal Information
4.1 Directly From You
- Browsing the Website. Our servers and analytics tools log your interaction with our pages.
- Contacting us. Demo requests, contact forms, sales inquiries, support tickets, calls, and chats.
- Creating a sandbox or test account. Name, email, company, and the test data you generate.
- Applying for the Services. Business details, Representative details, ownership information, identity documents, bank account details, and supporting documentation.
- Using the Services. Transactions, dashboard activity, configuration choices, uploaded content, and communications.
- Marketing interactions. Event registrations, webinar attendance, content downloads, newsletter sign-ups, and survey responses.
- Applying for a job. Résumé, application responses, and interview notes.
4.2 From Partner Platforms and Merchants
Partner Platforms and Merchants provide us information about their businesses, Representatives, sub-merchants, and Customers so we can onboard them, underwrite them, provide the Services, and meet our regulatory and network obligations.
4.3 From Payment Providers and Financial Institutions
Our Payment Providers, acquirers, sponsor banks, card networks, and ACH participants provide us with authorization and settlement data, chargeback and retrieval notices, return and NOC records, network alerts, risk and fraud notifications, and listings on industry compliance databases (including the card-network terminated-merchant databases).
4.4 From Service Providers and Data Sources
- Identity verification and biometric vendors (see Section 8).
- Fraud, risk, and device-intelligence providers, including device-fingerprinting, velocity, and consortium-data services.
- Credit bureaus, commercial data providers, and business registries, which provide credit reports, business filings, UCC records, litigation and lien data, and officer/beneficial-ownership information.
- Sanctions, watchlist, PEP, and adverse-media screening providers.
- Bank-data aggregators. We may use one or more bank-data aggregation providers to verify your bank account, confirm ownership, and retrieve balance and transaction data. When you connect an account, you authorize us and the aggregator to access and transmit that information from your financial institution on your behalf. The aggregator processes your information under its own privacy policy, which is presented to you during the connection flow.
- Advertising, analytics, and marketing platforms.
- Publicly available sources, including websites, social and professional networks, press, court records, and government registries.
4.5 Automatically, Through Cookies and Similar Technologies
See Section 9 and our separate Cookie Policy.
5. How and Why We Use Personal Information
We use Personal Information for the purposes below. Where Canadian law requires a legal basis, we rely on your express or implied consent, on the exceptions to consent permitted under PIPEDA and provincial legislation (including for fraud prevention, investigation of breach of agreement or contravention of law, and business transactions), or on a statutory obligation.
(a) To provide and operate the Services Create and administer accounts; authenticate you; configure your integration; process, route, authorize, settle, and reconcile transactions through our Payment Providers; issue refunds and process returns; calculate and distribute marketplace splits and payouts; generate invoices, receipts, statements, and reports; and provide sandbox environments.
(b) To onboard, verify, and underwrite Verify identity and business existence; validate bank account ownership; assess creditworthiness and financial standing; determine eligibility, pricing, limits, reserves, and funding timing; and satisfy the underwriting requirements of our Payment Providers and their sponsor banks.
(c) To meet legal, regulatory, and network obligations Perform KYC, KYB, and customer due diligence; screen against sanctions, watchlists, PEP, and adverse-media sources; monitor for and report suspicious activity; retain records; produce tax forms (including IRS Forms 1099-K and Canadian equivalents) and file information returns; respond to legal process; and comply with the operating rules of the card networks, NACHA, and other payment systems.
(d) To prevent, detect, and investigate fraud, abuse, and security incidents Score and monitor transactions; detect account takeover, synthetic identity, testing/enumeration attacks, collusive merchants, and money laundering; investigate and respond to chargebacks and disputes; maintain internal risk models and blocklists; and protect the rights, property, and safety of WyndMe, our customers, and the public.
(e) To manage risk and losses Set and adjust reserves, funding delays, and volume limits; monitor exposure; recover negative balances and amounts owed; and pursue collections.
(f) To support you Respond to inquiries; troubleshoot; provide training and implementation assistance; and administer service credits.
(g) To communicate with you Send transactional, servicing, security, and legal notices, including confirmations, settlement notifications, dispute alerts, policy updates, and breach notifications. You cannot opt out of these; they are part of the Services.
(h) To market and sell Send newsletters, product announcements, offers, event invitations, and other promotional messages; administer referral and partner programs; measure campaign effectiveness; and conduct market research. See Section 11 for your choices.
(i) To improve, develop, and secure our products Analyze usage; run A/B tests; debug and fix errors; conduct research; build and refine models and analytics (including fraud and risk models); and develop new features and products.
(j) To personalize Tailor dashboards, recommendations, in-product guidance, and content to your role, configuration, and usage.
(k) To enforce our agreements and protect our interests Investigate violations of our Terms of Service, Acceptable Use and Restricted Businesses Policy, or other agreements; establish, exercise, or defend legal claims; conduct audits; and manage insurance and corporate governance.
(l) For corporate transactions Evaluate, negotiate, and complete financings, acquisitions, dispositions, reorganizations, and similar transactions.
(m) For recruiting Evaluate applications, conduct interviews, check references and (where lawful) backgrounds, and maintain a talent pipeline.
(n) For any other purpose we describe to you at or before the time of collection, or to which you consent.
5.1 Automated Decision-Making and Profiling
We use automated systems to score transactions for fraud risk, to make underwriting and eligibility determinations, to set reserves and funding timing, and to detect prohibited activity. These systems may result in a transaction being declined, an application being denied, an account being suspended or terminated, or funds being held.
Human review. Adverse underwriting and account-termination decisions are subject to human review upon request, except where a decision is required by law, network rule, or a Payment Provider’s direction, or where review would compromise fraud prevention.
Your rights. If you are a resident of a jurisdiction that grants a right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects, see Section 12. Note that we may be unable to provide the Services if you opt out of the profiling that underpins them, and that opt-out rights generally do not extend to processing necessary for fraud prevention and legal compliance.
Adverse action. Where a decision is based in whole or in part on information from a consumer reporting agency, we (or our Payment Provider) will provide the notices required by the Fair Credit Reporting Act or applicable Canadian credit-reporting legislation.
5.2 Artificial Intelligence and Machine Learning
We use machine-learning and AI systems for fraud detection, risk scoring, document and identity verification, transaction categorization, support triage and summarization, and product analytics. Where we use third-party AI services, we contractually require that our data not be used to train the provider’s general-purpose models. We may use Personal Information to train and improve our own fraud, risk, and product models, using de-identified or aggregated data wherever practicable.
5.3 De-Identified and Aggregated Information
We may de-identify or aggregate Personal Information and use it for any lawful purpose, including benchmarking, research, and publishing industry insights. Where we hold de-identified information, we maintain it in de-identified form, publicly commit not to attempt re-identification, and contractually require recipients to do the same.
6. How and With Whom We Disclose Personal Information
6.1 Categories of Recipients
(a) Among our own entities. WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments share Personal Information with one another for the purposes described in this Policy, including shared onboarding, risk, compliance, support, and corporate functions.
(b) Payment Providers and financial institutions. We disclose Personal Information to the payment processors, acquirers, sponsor and settlement banks, money transmitters, card networks, issuers, and ACH participants that authorize, clear, settle, and fund your transactions. These parties process the information as independent controllers under their own privacy policies and under network rules. They may also disclose information about you to industry databases, including the card-network terminated-merchant databases, where a merchant is terminated for a listed reason.
(c) Merchants and Partner Platforms. If you transact with a Merchant or use the Services through a Partner Platform, we disclose relevant Personal Information to them so they can fulfill your order, provide support, manage disputes, comply with law, and operate their business.
(d) Service providers and processors. We disclose Personal Information to vendors that perform functions on our behalf under written contracts limiting their use of the information, including providers of: cloud hosting and storage; identity verification and biometric matching; fraud, device-intelligence, and risk analytics; credit reporting and business data; sanctions and watchlist screening; bank-data aggregation; email, SMS, and communications delivery; CRM and marketing automation; customer support and ticketing; analytics and product telemetry; accounting, tax, and audit; e-signature; document management; collections; and security monitoring and incident response.
(e) Professional advisors. Lawyers, accountants, auditors, bankers, and insurers.
(f) Referral and channel partners. Where a business was referred to us, we disclose business-level information, such as legal name, DBA, status, approximate processing volume, and fee data, as necessary to administer the referral or revenue-share arrangement, calculate compensation, confirm continued eligibility, and service the account.
(g) Government authorities, regulators, and law enforcement. We disclose Personal Information where we believe in good faith it is required or permitted by law; in response to subpoenas, court orders, warrants, or other legal process; to regulators and self-regulatory bodies with jurisdiction over us or our partners; to report suspected fraud, money laundering, or other criminal activity; and to establish, exercise, or defend legal claims.
(h) In corporate transactions. In connection with a proposed or completed merger, acquisition, financing, reorganization, sale of assets or equity, bankruptcy, receivership, liquidation, or similar transaction, including in the diligence phase, subject to confidentiality obligations, Personal Information may be disclosed to and transferred to the counterparty or its advisors, and may be among the assets transferred.
(i) At your direction or with your consent. Including through integrations, apps, and connections you authorize.
(j) De-identified and aggregated information. As described in Section 5.3.
6.2 Limits on Disclosure
- We do not sell your Personal Information for money.
- We do not disclose Personal Information for third-party direct marketing without consent where consent is required.
- We do not share telephone numbers, mobile device information, or SMS/text-messaging opt-in data, including any record of your consent, with third parties or affiliates for their own marketing purposes. SMS consent data is used only to deliver the messages you asked for and is disclosed only to the messaging vendors that deliver them on our behalf.
- We require recipients to protect Personal Information and to use it consistently with this Policy and applicable law.
6.3 “Selling” and “Sharing” Under U.S. State Law
Some U.S. state privacy laws define “sell” broadly to include disclosures for non-monetary valuable consideration, and define “share” to mean disclosure for cross-context behavioral advertising.
We do not sell Personal Information for monetary consideration. However, our use of advertising and analytics cookies and similar technologies on our Website may constitute a “sale” or “sharing” of identifiers, internet activity, and inferences under those definitions.
Categories potentially “sold” or “shared”: identifiers (including cookie and device IDs), internet or other electronic network activity information, approximate geolocation derived from IP address, and inferences. Categories of third parties: advertising networks, ad-tech intermediaries, social media platforms, and analytics providers. Purpose: cross-context behavioral advertising and marketing measurement.
You can opt out using the “Your Privacy Choices” link in the Website footer, by enabling a Global Privacy Control signal in your browser, or as described in Section 12.
We do not sell or share the Personal Information of individuals we know to be under 16 years of age.
We do not sell or share transaction data, financial account information, identity documents, or Sensitive Personal Information collected through the Services.
7. Cross-Border Transfers and Storage
We are headquartered in the United States and process and store Personal Information primarily in the United States, and also in Canada and in other countries where our service providers operate.
If you are located in Canada, your Personal Information may be transferred to, stored in, and processed in the United States and other jurisdictions. While it is in another jurisdiction, it is subject to that jurisdiction’s laws and may be accessible to courts, law enforcement, regulators, and national security authorities under those laws. Data protection standards in those jurisdictions may differ from those in your own.
We use contractual, technical, and organizational measures, including written service-provider agreements imposing confidentiality and security obligations comparable to our own, designed to provide a comparable level of protection for Personal Information wherever it is processed.
For questions about our cross-border practices, or to obtain information about our policies for service providers outside your jurisdiction, contact our Privacy Office (Section 16).
8. Biometric Information Notice
This Section is our notice under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, the Washington Biometric Privacy Act, Colorado’s biometric provisions, and comparable laws.
What we collect. When you complete identity verification, we use a service provider, currently Persona Identities, Inc. (“Persona”), to capture an image of your government-issued identity document and a live photograph or short video of your face, and to generate a scan of facial geometry: a mathematical representation (“template”) of your facial features. Persona’s privacy policy is available at https://withpersona.com/legal/privacy-policy. We may change identity-verification providers, and will update this Policy when we do.
Why. Solely to (i) confirm that the person presenting the document is the person pictured on it, (ii) confirm the document is authentic, and (iii) detect and prevent identity fraud, account takeover, and money laundering. We do not use biometric information for advertising, and we do not use it to identify you in any context other than the verification you initiated.
Consent. We collect, capture, and store biometric identifiers and biometric information only after providing this notice and obtaining your written release or consent, where required by law. Consent is requested in the verification flow before capture.
Who receives it. Persona, which acts as our processor; and, where required, the Payment Provider or sponsor bank that must satisfy its own KYC obligations. We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. We disclose them only (i) with your consent, (ii) to complete a transaction you requested, (iii) as required by law, or (iv) pursuant to a valid warrant or subpoena.
Retention and destruction. We and our vendor permanently destroy biometric identifiers and biometric information when the initial purpose for collecting them has been satisfied, or within three (3) years of your last interaction with us, whichever occurs first, unless a longer period is required by law, regulation, or a legal hold. Underlying document images and verification results are retained under the schedule in Section 15, which is separate from the biometric template.
Storage and protection. Biometric information is stored using a reasonable standard of care within our industry, and in a manner at least as protective as the manner in which we store other confidential and sensitive information.
9. Cookies, Analytics, and Advertising
9.1 Technologies We Use
We and our partners use cookies, pixels, tags, web beacons, local storage, software development kits, and similar technologies to operate the Services, remember your preferences, authenticate sessions, prevent fraud, measure performance, and, on the Website, deliver and measure advertising.
We use these categories:
- Strictly necessary, authentication, session management, security, load balancing, fraud prevention. Cannot be disabled.
- Functional, language, region, saved preferences, and UI state.
- Analytics and performance, usage measurement, error monitoring, session replay.
- Advertising and targeting, interest-based advertising, retargeting, conversion measurement, and audience matching.
Full details, including a categorized list of the specific technologies in use, are in our Cookie Policy.
9.2 Interest-Based Advertising
We work with advertising networks and ad-serving providers that deliver ads for us on other platforms. Some of those ads are personalized based on information collected about your activity across sites and apps over time, including inferences about relationships among your browsers and devices. This is known as interest-based advertising.
We adhere to the Digital Advertising Alliance (“DAA”) Self-Regulatory Principles for this activity. You can learn more and opt out at:
- DAA WebChoices: https://optout.aboutads.info
- DAA AppChoices (mobile): https://youradchoices.com/appchoices
- NAI: https://optout.networkadvertising.org
- Canada, DAAC AdChoices: https://youradchoices.ca
Opting out does not stop ads from appearing; it makes them less relevant. If you clear cookies, switch browsers, or use a different device, you will need to opt out again.
9.3 Analytics
We use Google Analytics and other analytics services. For information about Google’s practices see https://policies.google.com/technologies/partner-sites; to opt out of Google Analytics install the browser add-on at https://tools.google.com/dlpage/gaoptout.
9.4 Browser Controls and Global Privacy Control
Most browsers let you block or delete cookies. Blocking strictly necessary cookies will break parts of the Services.
We honor the Global Privacy Control (“GPC”) and other opt-out preference signals we are legally required to recognize, as an opt-out of sale/sharing and targeted advertising for the browser transmitting the signal. Because GPC is browser- and device-specific, you must enable it on each browser and device.
9.5 Do Not Track
We do not currently respond to browser “Do Not Track” signals, because no common industry standard for them has been adopted. We do respond to GPC as described above.
10. Security
We maintain an information security program with administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, use, disclosure, alteration, loss, and destruction. Depending on the environment and data type, these include:
- encryption of data in transit (TLS) and at rest;
- tokenization of payment credentials, so that full card numbers are not stored in our systems in usable form;
- role-based access control, least-privilege provisioning, and periodic access reviews;
- multi-factor authentication for administrative and privileged access;
- network segmentation, firewalling, and intrusion detection;
- centralized logging, monitoring, and alerting;
- secure software development practices, code review, and dependency scanning;
- vulnerability management and periodic penetration testing;
- vendor security due diligence and contractual security requirements;
- personnel background screening (where lawful), confidentiality obligations, and mandatory security training; and
- a documented incident response plan, tested periodically.
PCI DSS. We and our Payment Providers maintain compliance with the Payment Card Industry Data Security Standard as applicable to our respective roles in the payment flow.
Your responsibilities. You are responsible for safeguarding your credentials and API keys, enabling multi-factor authentication, promptly deprovisioning departed personnel, and notifying us immediately at security@wyndme.com if you suspect unauthorized access.
No absolute guarantee. No system is perfectly secure. We cannot guarantee that Personal Information will never be accessed, disclosed, altered, or destroyed in breach of our safeguards. To the extent permitted by law, we disclaim any warranty to that effect. In the event of a breach affecting your Personal Information, we will notify you and the applicable authorities as and when required by law.
11. Your Choices
Marketing email. Use the unsubscribe link at the bottom of any marketing message, or contact us at privacy@wyndme.com. We will still send transactional, servicing, security, and legal messages.
SMS and text messages. Reply STOP to any message to opt out; reply HELP for help. Message and data rates may apply. See our SMS and Messaging Terms.
Push notifications. Disable in your device settings.
Cookies and advertising. See Section 9 and our Cookie Policy.
Precise location. Disable in your device or browser settings.
Session replay. Contact privacy@wyndme.com to request exclusion.
Account information. Update most account and profile information directly in your dashboard. Some information, such as legal entity name, tax identification number, or verified identity data, cannot be changed without re-verification, and some cannot be deleted while your account is active because we are required to retain it.
12. Your Privacy Rights
12.1 Before You Submit a Request: Read This
If your relationship is with a Merchant or Partner Platform, submit your request to them, not to us. In those relationships we act as a processor/service provider, and the Merchant or Partner Platform is responsible for honoring your rights. If you send us such a request, we will forward it or direct you to the right party.
Some rights do not apply to some data. Financial information we process under the Gramm-Leach-Bliley Act (“GLBA”) and its implementing regulations, and information subject to the Fair Credit Reporting Act, is exempt from most U.S. state privacy laws. Much of the transaction, account, and underwriting data we hold falls into these categories. We are also required by AML, tax, and network rules to retain certain records regardless of a deletion request.
12.2 Rights of U.S. State Residents
Depending on your state of residence, you may have some or all of the following rights, subject to exemptions and verification:
| Right | What it means |
|---|---|
| Know / Access | Confirm whether we process your Personal Information and obtain access to it, including the categories collected, sources, purposes, and categories of recipients. |
| Portability | Obtain a copy in a portable and, to the extent technically feasible, readily usable format. |
| Correct | Correct inaccurate Personal Information, taking into account its nature and the purposes of processing. |
| Delete | Request deletion, subject to legal, regulatory, security, and fraud-prevention exceptions. |
| Opt out of sale | Direct us not to sell your Personal Information. |
| Opt out of sharing / targeted advertising | Direct us not to share it for cross-context behavioral advertising or targeted advertising. |
| Opt out of profiling | Opt out of profiling in furtherance of decisions producing legal or similarly significant effects (subject to Section 5.1). |
| Limit use of Sensitive Personal Information | Limit use and disclosure of Sensitive Personal Information to permitted purposes. We already limit ours to those purposes. |
| Non-discrimination / non-retaliation | We will not deny you goods or services, charge different prices, or provide a different level of quality because you exercised a right. |
| Appeal | Appeal our refusal to act on a request. |
| Opt-out preference signal | Have us honor GPC or a comparable signal. |
These rights are currently available, in varying forms, to residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, and to residents of other states as their laws take effect. We extend the core rights above to residents of all U.S. states as a matter of practice.
California-specific. California residents may also request the specific pieces of Personal Information we have collected; the categories of Personal Information sold or shared and the categories of third parties to whom each category was sold or shared; and the categories disclosed for a business purpose. California’s “Shine the Light” law (Civil Code § 1798.83) permits residents to request information about disclosures to third parties for their direct marketing purposes, we do not make such disclosures.
Minors. We do not knowingly collect Personal Information from anyone under 16 through the Services, and the Services are not directed to children. If you believe a child has provided us information, contact privacy@wyndme.com and we will delete it.
Authorized agents. You may use an authorized agent. We will require proof of the agent’s authority (such as a signed permission or power of attorney) and may require you to verify your own identity directly.
Verification. To protect you, we verify requests before acting. We will ask you to provide information that matches what we already hold, typically your name, email, account or merchant ID, and, for higher-risk requests, additional confirmation. We will not create new accounts or collect Sensitive Personal Information solely to verify a request, and we will not use information provided for verification for any other purpose.
Timing. We respond to verifiable requests within 45 days (California, and most states), or 90 days where a state provides a shorter default, extendable once by an additional 45 days (or 60 days, where applicable) with notice to you. Appeals are decided within 45 days (60 days in some states) with a written explanation; if we deny an appeal, we will provide you with a method to contact your state Attorney General.
Metrics. Where required, we publish annual request metrics at www.wyndme.com/privacy-metrics.
12.3 Rights of Canadian Residents
If you are in Canada, and in respect of Personal Information for which we act as the controller, and subject to exceptions under the Personal Information Protection and Electronic Documents Act (“PIPEDA”), Quebec’s Act respecting the protection of personal information in the private sector (as amended by Law 25), and comparable provincial legislation in Alberta and British Columbia, you may:
- Access the Personal Information we hold about you and be informed of its existence, use, and disclosure, including, in Quebec, the categories of persons who have access to it and how long we keep it;
- Correct Personal Information that is inaccurate, incomplete, or ambiguous;
- Withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not affect processing carried out before withdrawal. If you withdraw consent, we may be unable to continue providing some or all of the Services, and we will tell you at the time;
- Request deletion or de-indexing in the circumstances permitted by applicable law;
- Request portability, in Quebec, to receive computerized Personal Information you provided to us in a structured, commonly used technological format, or to have it transferred to another party;
- Be informed about, and request review of, automated decisions, in Quebec, where a decision is based exclusively on automated processing, to be informed of that fact, of the principal factors and parameters that led to the decision, and to submit observations to a person who can review it (see Section 5.1); and
- Complain to us and, if unsatisfied, to the Office of the Privacy Commissioner of Canada (www.priv.gc.ca), the Commission d’accès à l’information du Québec (www.cai.gouv.qc.ca), or your provincial commissioner.
Timing. We respond to Canadian access and correction requests within 30 days of receipt, or such other period as applicable law permits, and will tell you if we need an extension.
Consent. Where we rely on consent, we obtain express consent for sensitive information and may rely on implied consent where the purpose is obvious and you voluntarily provide the information. We may collect, use, or disclose Personal Information without consent where PIPEDA or provincial law permits, including for fraud detection and prevention, investigation of a breach of agreement or a contravention of law, debt collection, business transactions, and legal or regulatory compliance.
Language. Nous pouvons vous fournir cette politique en français sur demande. Contact privacy@wyndme.com.
12.4 How to Submit a Request
| Method | Detail |
|---|---|
| Online form | www.wyndme.com/privacy-request |
| privacy@wyndme.com | |
| WyndMe Corp, Attn: Privacy Office, 3300 Triumph Blvd, Suite 100, Lehi, UT 84043 | |
| Opt out of sale/sharing | “Your Privacy Choices” link in the Website footer, or enable GPC |
13. Job Applicants
If you apply for a job with us, we collect your name, contact details, résumé, work history, education, references, work authorization, compensation expectations, interview notes and evaluations, and, where lawful and with any required consent, background-check and reference-check results. We use this to evaluate your application, communicate with you, conduct interviews, verify your information, comply with employment and immigration law, and maintain a talent pipeline.
We retain applicant records for the period required by applicable law and for a reasonable period afterward to consider you for future roles, unless you ask us not to. We do not sell or share applicant information for advertising.
14. GLBA Financial Privacy Notice
WyndMe provides its Services to businesses. Our customer relationships are commercial, and the individuals whose information we process in connection with those relationships, business owners, officers, and authorized representatives, provide that information in a business capacity rather than to obtain a financial product or service for personal, family, or household purposes. GLBA’s consumer privacy notice requirements therefore do not generally apply to those relationships.
Nonetheless, a substantial portion of the information we process is nonpublic personal information of the kind GLBA and its implementing regulations govern, and information we obtain from or report to consumer reporting agencies is governed by the Fair Credit Reporting Act. Information within the scope of those statutes is exempt from most U.S. state privacy laws, and requests to access, delete, or port it may be limited or denied on that basis, as described in Section 12.1.
We handle all such information in accordance with the confidentiality, use-limitation, and safeguarding standards those statutes impose, including the requirements of the GLBA Safeguards Rule. If we determine that a GLBA consumer notice is required for a particular product or relationship, we will provide it to the affected individuals directly at the time required by law.
15. Retention
We keep Personal Information only as long as necessary for the purposes described in this Policy, and then delete, de-identify, or aggregate it. Actual periods depend on the data type and the legal obligation attached to it. Our general schedule:
| Data | Typical retention |
|---|---|
| Account and profile records | Life of the account, plus 7 years |
| Transaction and settlement records | 7 years from the transaction date |
| KYC/KYB and identity verification records | 5 years after the account closes (BSA/AML minimum), typically 7 |
| Identity document images | Up to 3 years after last interaction, or as required by our Payment Providers |
| Biometric templates | Purpose satisfaction or 3 years from last interaction, whichever is earlier (Section 8) |
| Chargeback and dispute records | 7 years from resolution |
| Tax records and information returns | 7 years |
| Support tickets and communications | 3-5 years |
| Call recordings | 1-3 years |
| Website analytics and cookie data | Up to 26 months (see Cookie Policy for per-cookie durations) |
| Marketing contact records | Until you unsubscribe, plus a suppression record retained indefinitely so we can honor your opt-out |
| Job applicant records | 1-3 years after the decision, unless you request deletion |
| Security and audit logs | 1-2 years |
| Fraud, risk, and blocklist records | As long as necessary to protect against recurrence, up to 10 years |
We retain information longer where required by a legal hold, ongoing investigation, dispute, regulatory inquiry, or applicable law.
16. Contact Us
Chief Privacy Officer: the individual accountable for WyndMe’s compliance with this Policy and with applicable privacy law, including under PIPEDA and as the person in charge of the protection of personal information under Quebec’s Law 25.
Chief Privacy Officer WyndMe Corp 3300 Triumph Blvd, Suite 100 Lehi, UT 84043 United States
Email: privacy@wyndme.com Web: www.wyndme.com/privacy-request General: contact@wyndme.com Security: security@wyndme.com
Canadian privacy matters: privacy@wyndme.com, Attn: Chief Privacy Officer, Canada
17. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the “Last Updated” date above. If the changes are material, we will provide additional notice, by email to your account address, by a notice in your dashboard, or by a prominent notice on the Website, before the changes take effect, and where required by law we will obtain your consent.
The current version is always available at www.wyndme.com/terms-and-policies/privacy-policy. Prior versions are available on request.
Your continued use of the Services after the effective date of a revised Policy constitutes acceptance of it.
© 2026 WyndMe Corp. WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments.
PART III: ACCEPTABLE USE AND RESTRICTED BUSINESSES POLICY
WyndMe Acceptable Use and Restricted Businesses Policy
Effective Date: August 1, 2026
This Policy applies to WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments (together, “WyndMe”) and is incorporated by reference into the WyndMe Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.
This Policy is not exhaustive. We may prohibit or restrict any business, product, service, or activity at any time, with or without cause, including where a Payment Provider, sponsor bank, Payment Network, or regulator requires it.
1. Why This Policy Exists
WyndMe enables payments through a network of Payment Providers, acquirers, and sponsor banks. Those partners, and the Payment Networks, impose requirements on the kinds of businesses that may accept payments and the ways payments may be used. Some categories are prohibited outright by law or Network Rules. Others are permitted only with additional underwriting, licensing, controls, or registration.
Operating a Prohibited Business, or a Restricted Business without written approval, is a material breach of the Terms of Service and may result in immediate suspension, termination, withheld funds, a Reserve, fines, and reporting to industry databases including MATCH.
2. Prohibited Businesses and Activities
You may not use the Services in connection with any of the following.
2.1 Illegal and Regulated-Illegal Activity
- Any activity that is illegal in any jurisdiction where you or your Customer is located, or that facilitates illegal activity by others
- Sale, distribution, or facilitation of controlled substances, narcotics, or drug precursors, including “research chemicals,” novel psychoactive substances, and synthetic cannabinoids
- Drug paraphernalia and equipment intended for the manufacture or use of controlled substances
- Prescription drugs sold without a valid prescription; pharmacies not licensed in every jurisdiction they serve; telemedicine prescribing outside a valid patient relationship
- Counterfeit, replica, knock-off, or trademark- or copyright-infringing goods, and services facilitating their sale
- Stolen goods, including digital and virtual goods obtained without authorization
- Human trafficking, forced labor, prostitution, escort services, sex tourism, and mail-order-bride services
- Child sexual abuse material and any content sexualizing minors, zero tolerance; reported to NCMEC and law enforcement
- Bestiality, non-consensual, or violent sexual content
- Trade in endangered or protected species, ivory, or products derived from them
- Sale of human body parts, organs, tissue, or bodily fluids
- Weapons, firearms, firearm parts (including receivers, frames, and 3D-printed components), ammunition, explosives, destructive devices, and accessories that circumvent legal restrictions
- Military and defense articles subject to ITAR/EAR, unless properly licensed and approved by us in writing
- Terrorist financing, sanctions evasion, and transactions with sanctioned persons or jurisdictions
- Bribery, kickbacks, and corrupt payments
- Any business you cannot lawfully operate for lack of a required license, permit, or registration
2.2 Financial Crime and Payment Abuse
- Money laundering, structuring, and layering
- Transaction laundering, factoring, aggregation, or processing on behalf of a third party without approval and required registration
- Ponzi schemes, pyramid schemes, chain letters, matrix programs, and “gifting” clubs
- Unauthorized multi-level marketing, and MLM programs whose revenue derives principally from recruitment rather than sales
- Get-rich-quick schemes, work-from-home offers with upfront payment, and “no-risk, high-return” investment programs
- Shell companies and businesses without a genuine commercial purpose
- Purchase or sale of personally identifiable information, account credentials, or card data
- Sale of cardable, prepaid, or reloadable instruments without required licensing
- Check cashing, payday lending, title lending, and other lending not fully compliant with all applicable federal, state, and provincial usury, licensing, and disclosure requirements
- Debt collection by an unlicensed collector, or collection practices violating the FDCPA or provincial equivalents
- Bail bonds
- Credit repair, credit protection, and identity-theft protection services not fully compliant with the Credit Repair Organizations Act and applicable state law
- Bankruptcy, foreclosure rescue, mortgage modification, and student loan debt relief services charging advance fees
- Money transmission, currency exchange, remittance, and money services businesses, unless separately approved and appropriately licensed
- Virtual currency and digital asset exchanges, mixers/tumblers, custodial wallets, ATMs, mining pools, initial coin offerings, token sales, and NFT marketplaces primarily used for financial speculation, unless separately approved
- Sale of gold, precious metals, or bullion for investment purposes without approval
- Unregistered securities, commodities, derivatives, forex, binary options, and contracts for difference
- Crowdfunding of equity or debt without required registration
- Sale of gift cards, prepaid cards, or stored-value instruments not issued by you, in bulk or at a discount
2.3 Gambling and Wagering
- Internet gambling, sports betting, casino games, poker, bingo, and lotteries, unless separately approved by us in writing and fully licensed in every jurisdiction served
- Sweepstakes, contests, and skill games with an entry fee and a prize, where doing so requires a license you do not hold
- Daily fantasy sports in jurisdictions where prohibited
- Raffles conducted without required charitable gaming authorization
- Any transaction that violates the Unlawful Internet Gambling Enforcement Act
2.4 Adult and Age-Restricted
- Pornography, adult video, live-cam, and sexually oriented digital content and subscription services
- Adult live entertainment venues, strip clubs, and adult-oriented dating and companionship services
- Sex toys and adult novelty products (Restricted: see Section 3, may be approved)
- Tobacco, cigarettes, cigars, smokeless tobacco, e-cigarettes, vaping products, e-liquid, nicotine pouches, and hookah products
- Alcohol sold without a valid license, without age verification at delivery, or shipped into a jurisdiction where prohibited
- Cannabis, marijuana, THC products, and cannabis dispensaries, including in jurisdictions where legal under state or provincial law, because they remain federally prohibited in the United States
- CBD, hemp-derived products, and hemp-derived cannabinoids (Delta-8, Delta-9, Delta-10, HHC, THCA) (Restricted: see Section 3)
- Kratom, kava, nitrous oxide, poppers/alkyl nitrites, and salvia
2.5 Deceptive, Harmful, and High-Complaint Practices
- Deceptive marketing, false advertising, bait-and-switch, and unsubstantiated health or income claims
- Negative-option, free-trial-to-subscription, and “forced continuity” offers that do not fully comply with ROSCA, the FTC’s negative option rule, applicable state auto-renewal laws, and Canadian equivalents
- Unauthorized or undisclosed cross-selling and up-selling
- Inbound and outbound telemarketing not compliant with the TSR, TCPA, Do-Not-Call rules, and provincial equivalents
- Infomercial and direct-response sales with high refund or Chargeback rates
- Buyers clubs, membership clubs, and discount programs with recurring fees and low utilization
- Rebate-based businesses and “free plus shipping” offers
- Prepaid phone cards and phone service resale
- Essay mills, academic ghostwriting, and diploma or credential mills
- Sale of social media engagement, followers, likes, views, and reviews
- Fake or misleading reviews and reputation manipulation
- Doxxing, harassment, stalkerware, and services facilitating them
- Predatory or exploitative services targeting vulnerable populations, including immigration-status and disaster-relief scams
- Psychic, clairvoyant, fortune-telling, and occult services (Restricted: see Section 3)
- Timeshare sales, timeshare exit services, and vacation clubs (Restricted)
- Door-to-door sales and high-pressure in-home sales of home improvement, security systems, or water treatment
2.6 Technology and Security Abuse
- Malware, spyware, ransomware, botnets, and exploit kits
- Hacking, cracking, and account-takeover tools and services; sale of stolen credentials
- Denial-of-service tools, “booter” and “stresser” services
- Circumvention of digital rights management, technical protection measures, or copy protection
- Illegal streaming devices, jailbroken media players, and IPTV services distributing unlicensed content
- Traffic-selling, click fraud, ad fraud, and bot-driven engagement
- Anonymous or bulletproof hosting used principally to evade law enforcement
- Spam, email harvesting, and bulk unsolicited messaging services
- Bulk sale of SIM cards, phone numbers, or accounts for evasion purposes
- Services designed principally to circumvent sanctions, KYC, or AML controls
2.7 Prohibited Use of Your Own Account
- Processing your own card or bank account, or a card or account you control, to obtain cash or credit
- Using the Services to transfer funds between accounts you control without a genuine underlying commercial transaction
- Splitting, inflating, or misrepresenting a Transaction
- Submitting a Transaction for a business or product line you did not disclose to us
- Using a statement descriptor that does not clearly identify your business
- Using the Services for personal, family, or household purposes
- Testing card numbers or credentials you do not own
- Opening a new account after we suspended or terminated a prior one, or on behalf of someone we terminated
3. Restricted Businesses: Approval Required
The following are permitted only with our prior written approval, which may be conditioned on additional documentation, licensing evidence, volume limits, delayed funding, Reserves, higher pricing, Network registration, or ongoing reporting. Do not begin processing in these categories before approval.
| Category | Typical additional requirements |
|---|---|
| Age-restricted goods (sex toys, adult novelty, non-nicotine vape hardware) | Robust age verification; jurisdictional restrictions |
| Hemp/CBD (non-THC, compliant) | Certificates of analysis; state/provincial registration; approved sponsor bank; enhanced monitoring |
| Alcohol (retail, DTC shipping) | Licenses for every jurisdiction served; age verification at delivery; carrier attestation |
| Firearms accessories and ammunition (where lawful) | FFL where applicable; background-check attestation; approved sponsor bank |
| Pharmacy, telehealth, nutraceuticals, supplements | Licensing; substantiation of claims; NABP/LegitScript certification |
| Gambling, sports betting, DFS, skill gaming | Full licensing in every jurisdiction; geofencing; Network registration; substantial Reserve |
| Cryptocurrency and digital assets | MSB/FINTRAC registration; AML program; travel-rule compliance; approved sponsor bank |
| Money services, remittance, currency exchange | State money transmitter licenses / FINTRAC MSB registration; AML program |
| Lending, BNPL, factoring, merchant cash advance | Licensing; TILA/Reg Z or provincial disclosures; UDAAP review |
| Insurance and warranty sales | Producer licensing; state/provincial filings |
| Debt collection, debt settlement, credit counseling | Licensing; FDCPA/CROA compliance; bonding |
| Travel, tour operators, OTAs, cruise, airlines | Financial statements; seller-of-travel registration; delayed funding; Reserve sized to forward liability |
| Ticketing, events, and box offices | Event-date-based funding; Reserve; refund policy review |
| Subscription boxes and continuity billing | ROSCA/auto-renewal compliance review; cancellation flow review |
| Charities, nonprofits, and political fundraising | 501(c) or CRA registration; FEC/Elections Canada compliance; donor disclosure |
| Marketplaces and payment facilitators | Section 18 of the Terms; Network registration; Sub-Merchant KYC program |
| Dating and companionship services | Content moderation; safety program; refund policy |
| Psychic, astrology, and metaphysical services | Clear disclosures; refund policy; enhanced Chargeback monitoring |
| Timeshare, vacation clubs, real estate seminars | Financial statements; cooling-off period compliance; Reserve |
| Multi-level marketing | DSA membership or equivalent; income-claim substantiation; product-vs-recruitment revenue analysis |
| Precious metals, coins, bullion | Licensing; delivery verification; Reserve |
| Auctions, consignment, and resale platforms | Authentication program; seller vetting |
| Extended warranties and service contracts | Obligor identification; state filings; reserve for forward liability |
| Digital goods, gaming currency, and in-game items | Fraud controls; delivery proof; enhanced Chargeback monitoring |
| Any business with a Chargeback rate above 0.65% or fraud rate above 0.65% | Remediation plan; Reserve; Network monitoring program enrollment |
4. Content and Conduct Standards
You may not use the Services to store, transmit, or make available content that:
- infringes or misappropriates intellectual property or publicity rights;
- is defamatory, libelous, or trade-libelous;
- harasses, threatens, bullies, or incites violence against any person or group;
- promotes terrorism, violent extremism, or self-harm;
- constitutes hate speech targeting a protected characteristic;
- discloses another person’s private information without authorization;
- is obscene or constitutes prohibited adult content under Section 2.4; or
- contains malicious code.
5. Anti-Money Laundering and Sanctions
You must not use the Services to launder proceeds of crime, finance terrorism, evade sanctions or export controls, or evade tax. You must:
- cooperate with our and our Payment Providers’ KYC, KYB, enhanced due diligence, and source-of-funds inquiries;
- respond to information requests within five (5) business days;
- promptly disclose changes in beneficial ownership or control; and
- not attempt to structure Transactions to avoid reporting thresholds.
We may be legally prohibited from telling you that a suspicious activity report has been filed or that your account is under investigation. Nothing in the Terms of Service requires us to disclose it.
6. Rate Limits and Technical Abuse
You must respect published API rate limits and must not: generate abnormal authorization, decline, or velocity patterns; use automated tools to probe or enumerate our systems; scrape data beyond the documented API; or take any action that degrades the Services for others. We may throttle, block, or suspend access for technical abuse without notice.
7. Enforcement
We may, at our sole discretion and without prior notice:
- request information or a remediation plan;
- impose volume limits, delayed funding, or a Reserve;
- decline, reverse, or hold individual Transactions;
- suspend or restrict some or all Services;
- terminate your account and the Agreement;
- withhold funds and apply them to Losses;
- charge you the fines, assessments, and costs imposed on us;
- report you and your Representatives to Payment Providers, Payment Networks, industry databases (including MATCH and the Consortium Merchant Negative File), credit bureaus, and law enforcement; and
- pursue any other remedy available under the Agreement or at law.
Enforcement action under this Policy is not a breach by us and does not entitle you to any refund, damages, or other remedy.
8. Reporting Violations
Report suspected violations to abuse@wyndme.com. Report suspected security issues to security@wyndme.com. Report suspected child sexual abuse material immediately to legal@wyndme.com and to the National Center for Missing & Exploited Children (www.cybertipline.org) or the Canadian Centre for Child Protection (www.cybertip.ca).
9. Changes
We may update this Policy at any time. Material changes take effect on the notice period in Section 1.5 of the Terms of Service, except changes required by law, Network Rules, or a Payment Provider, which take effect immediately.
© 2026 WyndMe Corp. WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments.
PART IV: E-SIGN CONSENT AND ELECTRONIC COMMUNICATIONS DISCLOSURE
WyndMe E-Sign Consent and Electronic Communications Disclosure
Effective Date: August 1, 2026
This disclosure is provided by WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments (together, “WyndMe,” “we,” “us”) under the U.S. federal Electronic Signatures in Global and National Commerce Act (“E-Sign Act”), applicable state Uniform Electronic Transactions Acts, and Canada’s Personal Information Protection and Electronic Documents Act Part 2 and provincial electronic commerce legislation. It is incorporated by reference into the WyndMe Terms of Service.
1. Your Consent
By accepting the Terms of Service, creating an account, or using the Services, you consent to receive all Communications electronically and to sign documents electronically.
2. What “Communications” Means
“Communications” means any agreement, disclosure, notice, record, statement, receipt, confirmation, authorization, tax form, policy, amendment, or other information we provide to you or that you sign or submit in connection with the Services, including:
- these and other terms, policies, and amendments;
- account applications, approvals, denials, and conditions;
- transaction confirmations, settlement notices, statements, and reports;
- fee schedules and fee change notices;
- Chargeback, dispute, and retrieval notices and deadlines;
- reserve, funding-hold, suspension, and termination notices;
- adverse action notices under the Fair Credit Reporting Act or applicable Canadian credit-reporting law;
- privacy notices and security incident notifications;
- tax forms and information returns, including IRS Form 1099-K and Canadian equivalents; and
- any other disclosure or notice we are required by law to provide in writing.
3. How We Deliver Communications
We may deliver Communications by:
- posting them in your WyndMe dashboard or account;
- emailing them, or emailing a notice that they are available, to the email address on your account;
- sending an SMS or in-app notification;
- posting them on www.wyndme.com; or
- any other electronic method we reasonably select.
A Communication is deemed received when we post it, send it, or make it available, not when you actually read it. You are responsible for checking your account and email regularly.
4. Hardware and Software You Need
To access and retain Communications, you need:
- a computer or mobile device with internet access;
- a current version of a supported browser (Chrome, Safari, Edge, or Firefox) with cookies and JavaScript enabled;
- a valid, active, monitored email address capable of receiving mail from wyndme.com (add our domain to your allowlist);
- software able to view PDF files;
- sufficient storage or a printer to retain copies; and
- for SMS delivery, a mobile device on a supported carrier.
If our hardware or software requirements change materially in a way that creates a risk you could not access or retain Communications, we will notify you and give you the opportunity to withdraw consent without charge.
5. Keeping Your Contact Information Current
You must keep the email address, mobile number, and mailing address on your account current at all times. Update them in your dashboard or by emailing support@wyndme.com.
If a Communication is returned undeliverable, or if we determine your email address is invalid, we may suspend electronic delivery, may charge a reasonable fee for paper delivery where permitted, and may suspend your account until you provide valid contact information. We are not liable for Losses arising from your failure to maintain accurate contact information.
6. Requesting a Paper Copy
You may request a paper copy of any Communication by emailing support@wyndme.com or writing to WyndMe Corp, Attn: Records, 3300 Triumph Blvd, Suite 100, Lehi, UT 84043, and identifying the Communication. We may charge a reasonable fee of up to US$15 per document, except where Applicable Law prohibits a charge. Requesting a paper copy does not withdraw your consent.
7. Withdrawing Consent
You may withdraw your consent to electronic Communications by emailing support@wyndme.com with the subject line “Withdraw E-Sign Consent,” including your legal name, account or merchant ID, and mailing address.
Important consequences:
- Withdrawal is effective only after we have a reasonable period to process it, normally ten (10) business days.
- Withdrawal does not affect the validity or enforceability of Communications provided, or signatures made, before it takes effect.
- Because the Services are delivered electronically, withdrawing consent means we generally cannot continue to provide them. We may close or suspend your account. We may charge a reasonable paper-delivery fee where permitted.
8. Electronic Signatures
You agree that:
- your click on “I agree,” “Submit,” “Accept,” “Authorize,” or a similar control, your typed name, and your drawn or uploaded signature each constitute your electronic signature;
- your electronic signature has the same legal effect, validity, and enforceability as a handwritten signature on paper;
- records maintained by us in electronic form satisfy any legal requirement that a record be in writing, be signed, or be retained in original form; and
- you will not contest the validity, admissibility, or enforceability of an agreement, authorization, or record on the ground that it was created, signed, or stored electronically.
9. Scope
Your consent applies to all Communications from every WyndMe entity, and to each authorized user, administrator, and Representative on your account. If you authorize others to act on your account, you are responsible for ensuring they have access to the Communications we deliver.
10. Federal Law
For U.S. Customers, this consent is given under the E-Sign Act and applicable UETA. Nothing here limits a Communication that Applicable Law requires be delivered in a specific manner that electronic delivery does not satisfy; in that case we will deliver it as required.
11. Canada
For Canadian Customers, this consent is given under PIPEDA Part 2 and applicable provincial electronic commerce legislation. Certain documents are excluded from electronic delivery by statute; we will deliver those as required by law.
12. Changes
We may amend this disclosure by giving you notice consistent with Section 1.5 of the Terms of Service.
Questions: support@wyndme.com | legal@wyndme.com
© 2026 WyndMe Corp.
PART V: COOKIE POLICY
WyndMe Cookie Policy
Effective Date: August 1, 2026
This Cookie Policy explains how WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments (together, “WyndMe,” “we,” “us”) use cookies and similar technologies on www.wyndme.com and in our dashboards and applications (the “Services”). It supplements, and is incorporated into, the WyndMe Privacy Policy.
1. What These Technologies Are
- Cookies, small text files placed on your device by a website. First-party cookies are set by us; third-party cookies are set by another domain. Session cookies expire when you close your browser; persistent cookies remain until they expire or you delete them.
- Pixels, tags, and web beacons, tiny transparent images or code snippets that record that a page or email was opened and how it was interacted with.
- Local storage and session storage, browser storage used to hold preferences and application state.
- SDKs, code libraries in our mobile applications that perform functions similar to cookies.
- Device fingerprinting, inference of a device identity from a combination of browser and device characteristics, used for fraud prevention and security.
We refer to all of these as “cookies” in this Policy.
2. Categories We Use
2.1 Strictly Necessary: Always Active
Required to operate the Services and to keep them secure. You cannot disable these; if you block them, the Services will not work.
| Purpose | Examples |
|---|---|
| Authentication and session management | Session ID, login state, CSRF token |
| Security and fraud prevention | Bot detection, device fingerprint, rate limiting, anomaly detection |
| Load balancing and routing | Server affinity |
| Consent record | Storing your cookie preferences |
| Core functionality | Shopping cart and checkout state in hosted checkout |
Legal basis / basis for use: necessary to provide a service you requested and to protect against fraud and security threats. These are not used for advertising.
2.2 Functional: Optional
Remember your choices and improve usability: language and region, time zone, saved dashboard filters and views, dismissed banners, and support chat state. Disabling these degrades convenience but not core function.
2.3 Analytics and Performance: Optional
Help us understand how the Services are used so we can improve them: page and screen views, feature usage, funnel and conversion measurement, error and crash reporting, load-time measurement, and session replay (with sensitive fields masked). Providers include Google Analytics and similar services.
2.4 Advertising and Targeting: Optional
Used on our public website (not inside authenticated dashboards) to deliver and measure advertising: interest-based ads, retargeting, conversion tracking, and audience matching with advertising platforms and social networks.
These cookies may constitute a “sale” or “sharing” of personal information under some U.S. state privacy laws. See Section 6.3 of the Privacy Policy and Section 5 below.
3. Third Parties That Set Cookies Through Our Services
Depending on your consent and jurisdiction, the following categories of third parties may set cookies:
| Category | What they do |
|---|---|
| Analytics providers | Usage measurement and product analytics |
| Error and performance monitoring | Crash reporting and diagnostics |
| Session replay providers | Recording of interaction sessions for troubleshooting |
| Advertising networks and ad-tech | Interest-based advertising and measurement |
| Social media platforms | Conversion tracking and audience matching |
| Customer support and chat providers | Live chat and help widgets |
| Marketing automation and CRM | Campaign attribution and lead tracking |
| Fraud and device intelligence providers | Bot detection and device fingerprinting |
| Content delivery networks | Performance and availability |
3A. Itemized List of Cookies
The table below lists the cookies and similar technologies in use on our Services, by category. Because cookies change as we add and remove features and providers, the authoritative, continuously updated list is available in our Cookie Preference Center, reachable from the “Cookie Preferences” link in the footer of every page. That list reflects what is actually set on your device and lets you accept or reject each optional category.
Strictly necessary
| Name / pattern | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
wm_session | wyndme.com | Maintains your authenticated session | First-party HTTP | Session |
wm_csrf | wyndme.com | Cross-site request forgery protection | First-party HTTP | Session |
wm_auth_state | wyndme.com | Login and multi-factor authentication state | First-party HTTP | 30 days |
wm_device_id | wyndme.com | Device recognition for fraud prevention and account security | First-party HTTP | 13 months |
wm_lb | wyndme.com | Load balancer routing and server affinity | First-party HTTP | Session |
wm_consent | wyndme.com | Records your cookie preferences | First-party HTTP | 12 months |
wm_checkout | wyndme.com | Cart and checkout state in hosted checkout | First-party HTTP | Session |
Functional
| Name / pattern | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
wm_locale | wyndme.com | Language, region, and time zone preference | First-party HTTP | 12 months |
wm_ui_prefs | wyndme.com | Saved dashboard views, filters, and layout | First-party local storage | Until cleared |
wm_dismissed | wyndme.com | Remembers banners and prompts you have dismissed | First-party HTTP | 12 months |
wm_support | Support and chat provider | Live chat session continuity | Third-party HTTP | 30 days |
Analytics and performance
| Name / pattern | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
_ga, _ga_* | Google Analytics | Distinguishes users; measures site and product usage | Third-party HTTP | Up to 24 months |
_gid | Google Analytics | Distinguishes users | Third-party HTTP | 24 hours |
wm_analytics_id | wyndme.com | First-party product analytics identifier | First-party HTTP | 13 months |
| Error monitoring session ID | Error and performance monitoring provider | Associates crash and error reports with a session | Third-party storage | Session to 30 days |
| Session replay session ID | Session replay provider | Links recorded interaction sessions for troubleshooting; sensitive fields masked | Third-party storage | Up to 12 months |
Advertising and targeting (public website only)
| Name / pattern | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
_gcl_* | Google Ads | Conversion measurement and attribution | Third-party HTTP | Up to 90 days |
IDE, test_cookie | Google DoubleClick | Interest-based advertising and ad measurement | Third-party HTTP | Up to 13 months |
_fbp | Meta | Conversion tracking and audience matching | First-party HTTP | Up to 90 days |
li_sugr, bcookie, UserMatchHistory | Conversion tracking and audience matching | Third-party HTTP | Up to 12 months | |
wm_attrib | wyndme.com | Campaign attribution for marketing measurement | First-party HTTP | Up to 90 days |
Advertising and targeting cookies are set only where you have accepted them, and are not set at all if you transmit a Global Privacy Control signal or opt out through our preference center. They are not used inside authenticated dashboards.
4. Your Choices
4.1 Cookie Banner and Preference Center
Manage optional cookies through our cookie banner on first visit, or at any time through the “Cookie Preferences” link in the website footer. Strictly necessary cookies cannot be turned off.
4.2 Global Privacy Control
We honor the Global Privacy Control (GPC) and other opt-out preference signals we are legally required to recognize, treating them as an opt-out of the sale and sharing of personal information and of targeted advertising for the browser or device transmitting the signal. Enable GPC in a supporting browser or extension, see globalprivacycontrol.org. GPC is browser- and device-specific.
4.3 Browser Controls
Every major browser lets you view, block, and delete cookies:
- Chrome, Settings → Privacy and security → Third-party cookies
- Safari, Settings → Privacy
- Edge, Settings → Cookies and site permissions
- Firefox, Settings → Privacy & Security
Blocking all cookies will break the Services.
4.4 Mobile Device Controls
- iOS, Settings → Privacy & Security → Tracking, and App Tracking Transparency prompts
- Android, Settings → Privacy → Ads → Delete advertising ID
4.5 Industry Opt-Outs
- DAA WebChoices, https://optout.aboutads.info
- DAA AppChoices, https://youradchoices.com/appchoices
- NAI, https://optout.networkadvertising.org
- DAAC (Canada), https://youradchoices.ca
- Google Analytics opt-out, https://tools.google.com/dlpage/gaoptout
Opting out is stored in a cookie. Clearing cookies, switching browsers, or using another device removes your opt-out and you will need to opt out again.
4.6 Session Replay
To be excluded from session-replay recording, email privacy@wyndme.com.
4.7 Do Not Track
We do not respond to browser “Do Not Track” signals, because no common industry standard has been established. We do honor GPC as described in Section 4.2.
5. Cookies and U.S. State Privacy Laws
Our use of advertising and certain analytics cookies may constitute a “sale” or “sharing” of personal information under California, Colorado, Connecticut, and other state privacy laws. The categories involved, the recipients, and the purposes are described in Section 6.3 of the Privacy Policy.
To opt out, use the “Your Privacy Choices” link in the website footer, our cookie preference center, or a GPC signal.
We do not knowingly sell or share the personal information of consumers under 16.
6. Cookies and Canadian Law
In Canada, we rely on your consent, express where required and implied where the purpose is obvious and non-sensitive, for optional cookies. In Quebec, technologies that collect personal information are deactivated by default and require your consent before activation, and you may withdraw consent at any time through our preference center.
7. Retention
Session cookies expire when you close your browser. Persistent cookies last from a few days to a maximum of twenty-six (26) months, depending on their purpose. Security and fraud-prevention cookies may persist longer where necessary to protect the Services. Specific durations are listed in our preference center.
8. Changes
We may update this Cookie Policy. Material changes will be announced through the banner or a website notice, and we will re-request consent where law requires it.
Questions: privacy@wyndme.com WyndMe Corp, Attn: Privacy Office, 3300 Triumph Blvd, Suite 100, Lehi, UT 84043
© 2026 WyndMe Corp.
PART VI: DATA PROCESSING ADDENDUM
WyndMe Data Processing Addendum
Effective Date: August 1, 2026
This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the WyndMe Terms of Service (the “Agreement”) between WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments (together, “WyndMe”) and the customer identified in the Agreement (“Customer”). It applies to the extent WyndMe processes Personal Information on Customer’s behalf.
1. Definitions
“Applicable Privacy Law”: all data protection and privacy laws applicable to the processing of Personal Information under the Agreement, including the California Consumer Privacy Act as amended by the CPRA and its regulations (“CCPA”); the comprehensive privacy statutes of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, and successor and comparable state laws; the Gramm-Leach-Bliley Act and its implementing regulations; the Personal Information Protection and Electronic Documents Act (“PIPEDA”); Quebec’s Act respecting the protection of personal information in the private sector as amended by Law 25; and the Personal Information Protection Act of Alberta and British Columbia.
“Business,” “Business Purpose,” “Consumer,” “Sell,” “Share,” “Service Provider,” “Third Party”, as defined in the CCPA.
“Controller,” “Processor,” “Data Subject”: the party determining the purposes and means of processing; the party processing on its behalf; and the individual to whom Personal Information relates.
“Customer Personal Information”: Personal Information that WyndMe processes on Customer’s behalf under the Agreement.
“Personal Information”: information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household.
“Security Incident”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Information processed by WyndMe. Unsuccessful attempts and routine events that do not compromise security, pings, port scans, failed log-ins, denial-of-service attempts that do not result in access, are not Security Incidents.
“Sub-processor”: a third party engaged by WyndMe to process Customer Personal Information on Customer’s behalf.
Terms not defined here have the meanings given in the Agreement or the Privacy Policy.
2. Roles of the Parties
2.1 WyndMe as Processor / Service Provider
With respect to Customer Personal Information, Customer is the Controller/Business and WyndMe is the Processor/Service Provider. WyndMe processes Customer Personal Information only on Customer’s documented instructions, which consist of the Agreement, Customer’s configuration and use of the Services, and any additional written instructions the parties agree to.
2.2 WyndMe as Independent Controller
WyndMe acts as an independent Controller/Business, not as a Processor/Service Provider, with respect to Personal Information it processes for the following purposes, and this DPA’s processor obligations do not apply to that processing:
- identity verification, KYC, KYB, and customer due diligence;
- sanctions, watchlist, PEP, and adverse-media screening;
- anti-money-laundering monitoring, investigation, and regulatory reporting;
- fraud prevention, detection, and investigation, and maintenance of fraud and risk models and blocklists;
- credit, underwriting, and risk assessment;
- compliance with Applicable Law, Network Rules, and Payment Provider requirements, including record retention and tax reporting;
- billing, collections, and recovery of amounts owed;
- security, incident response, and protection of the Services;
- establishing, exercising, and defending legal claims, and internal audit;
- Personal Information about Customer’s own Representatives collected for account administration, underwriting, and relationship management; and
- product improvement and analytics using de-identified or aggregated data.
Applicable Privacy Law expressly permits a service provider to process personal information for these purposes. Nothing in this DPA restricts WyndMe from processing Personal Information as required or permitted by Applicable Law.
2.3 Payment Providers and Networks as Independent Controllers
Payment Providers, acquirers, sponsor banks, issuers, and Payment Networks process Personal Information as independent Controllers for their own purposes, under their own policies and under Network Rules. WyndMe is not responsible for their processing, and disclosures to them are not disclosures to a Sub-processor.
3. Scope and Details of Processing
Subject matter: provision of the Services under the Agreement.
Duration: the Term, plus any post-termination period permitted or required under Section 10.
Nature and purpose: hosting, storage, transmission, structuring, retrieval, analysis, and deletion of Customer Personal Information as necessary to provide the Services, including payment enablement, orchestration, reporting, and support.
Categories of Data Subjects: Customer’s employees, contractors, and Representatives; Customer’s own customers and end users; Customer’s sub-merchants, sellers, and vendors and their representatives.
Categories of Personal Information: identifiers and contact information; account and transaction records; commercial and purchase information; payment instrument tokens and truncated identifiers; internet and device activity; approximate geolocation; communications content; and any other data Customer submits.
Sensitive Personal Information: government identifiers, financial account numbers with access credentials, biometric information (where Customer enables identity verification), precise geolocation (where enabled), and account credentials. Customer must not submit protected health information subject to HIPAA, and WyndMe is not a business associate.
4. WyndMe’s Obligations as Processor
WyndMe will:
(a) Process on instructions only. Process Customer Personal Information only for the Business Purposes specified in the Agreement and on Customer’s documented instructions, and not for any other purpose. WyndMe will notify Customer if, in its opinion, an instruction violates Applicable Privacy Law.
(b) Not sell or share. WyndMe will not sell or share Customer Personal Information, and will not retain, use, or disclose it outside the direct business relationship with Customer or for any purpose other than the Business Purposes specified, except as Applicable Privacy Law permits.
(c) Not combine. Not combine Customer Personal Information with personal information received from or on behalf of another person, or collected from its own interactions with a Consumer, except as Applicable Privacy Law permits, including for security, fraud prevention, and to perform a Business Purpose.
(d) Confidentiality. Ensure that personnel authorized to process Customer Personal Information are subject to binding confidentiality obligations and receive appropriate training.
(e) Security. Implement and maintain the technical and organizational measures in Annex A.
(f) Assistance. Provide reasonable assistance, taking into account the nature of the processing and the information available to it, with: responses to Data Subject requests (Section 6); Security Incident notification (Section 7); data protection impact assessments and privacy impact assessments; and consultations with regulators.
(g) Compliance. Comply with its obligations under Applicable Privacy Law and provide the same level of privacy protection as Applicable Privacy Law requires of Customer. WyndMe will notify Customer promptly if it determines it can no longer meet these obligations.
(h) Remediation. On notice from Customer of unauthorized use, take reasonable and appropriate steps to stop and remediate it.
(i) Deletion and return. Comply with Section 10.
5. Customer’s Obligations
Customer:
-
is solely responsible for the accuracy, quality, and legality of Customer Personal Information and for the lawfulness of the means by which it was obtained;
-
will provide all notices and obtain all consents, permissions, and authorizations required for WyndMe and its Payment Providers to process Customer Personal Information as contemplated by the Agreement, including for identity verification, biometric processing, fraud prevention, and cross-border transfer;
-
will maintain a published, accurate, and legally compliant privacy notice;
-
warrants that its instructions comply with Applicable Privacy Law and will not cause WyndMe to violate it;
-
is responsible for responding to Data Subject requests relating to Customer Personal Information; and
-
will not submit protected health information, and is liable for any such submission.
6. Data Subject Requests
Where WyndMe receives a request from a Data Subject relating to Customer Personal Information, WyndMe will not respond substantively except on Customer’s instruction or as Applicable Law requires, and will without undue delay notify Customer or direct the Data Subject to Customer.
WyndMe will provide Customer with reasonable assistance, through the Services’ self-service functionality where available, and otherwise through commercially reasonable support, to enable Customer to respond within the statutory deadline. WyndMe may charge for assistance that is disproportionate or repetitive, on prior notice.
WyndMe may decline or limit a deletion instruction to the extent retention is required or permitted by Applicable Law, Network Rules, or a Payment Provider requirement, including for AML, tax, dispute, fraud-prevention, and legal-claim purposes.
7. Security Incidents
WyndMe will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Customer Personal Information.
The notification will describe, to the extent known and as information becomes available: the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. WyndMe will provide updates as the investigation progresses and will reasonably cooperate with Customer’s own notification obligations.
Notification is not an acknowledgment of fault or liability.
Customer is solely responsible for determining whether to notify Data Subjects, regulators, or others, and for making those notifications, except where WyndMe is independently required to do so. Customer will not make any public statement identifying WyndMe in connection with a Security Incident without WyndMe’s prior written consent, except as legally required.
Customer must notify WyndMe within twenty-four (24) hours of a Security Incident in Customer’s environment affecting the Services, and cooperate with the resulting investigation.
8. Sub-processors
8.1 General Authorization
Customer grants WyndMe general authorization to engage Sub-processors to process Customer Personal Information in connection with the Services.
8.2 Sub-processor Obligations
WyndMe will (a) enter a written contract with each Sub-processor imposing data protection obligations no less protective than this DPA, (b) conduct reasonable due diligence on each Sub-processor’s security and privacy practices, and (c) remain liable to Customer for its Sub-processors’ performance of the obligations in this DPA.
8.3 List and Notice of Changes
WyndMe maintains a current list of Sub-processors at www.wyndme.com/legal/sub-processors. Customer may subscribe to change notifications there. WyndMe will provide at least thirty (30) days’ notice before adding or replacing a Sub-processor, except where a change is required urgently for security, legal, or continuity reasons.
8.4 Objection
Customer may object to a new Sub-processor on reasonable, documented data protection grounds by notifying WyndMe within fifteen (15) days of the notice. The parties will discuss in good faith. If WyndMe cannot make the Services available without the Sub-processor and cannot offer a commercially reasonable alternative, Customer’s sole and exclusive remedy is to terminate the affected Services on written notice, with a pro-rata refund of prepaid, unused Fees.
8.5 Not Sub-processors
Payment Providers, Payment Networks, sponsor banks, acquirers, issuers, credit bureaus, sanctions-screening providers, and governmental authorities act as independent Controllers, not Sub-processors, and Sections 8.3 and 8.4 do not apply to them.
9. International and Cross-Border Transfers
WyndMe processes Customer Personal Information primarily in the United States, and also in Canada and in other countries where its Sub-processors operate.
Customer authorizes these transfers. WyndMe will ensure that transfers are subject to appropriate safeguards, including written contracts imposing confidentiality and security obligations comparable to this DPA, and will comply with the transfer requirements of Applicable Privacy Law, including, for Canadian Personal Information, the accountability and comparable-protection requirements of PIPEDA and Quebec Law 25, and the privacy impact assessment obligation for transfers outside Quebec where applicable.
Customer is responsible for disclosing cross-border transfers in its own privacy notice.
10. Deletion and Return
On termination of the Agreement, and on Customer’s written request within thirty (30) days of termination, WyndMe will delete or return Customer Personal Information in its possession, subject to the exceptions below. After that period, WyndMe may delete it in the ordinary course.
WyndMe may retain Customer Personal Information to the extent (a) required by Applicable Law, Network Rules, or a Payment Provider; (b) necessary to complete Transactions, process refunds and Chargebacks, or recover amounts owed; (c) necessary for fraud prevention, AML compliance, security, or defense of legal claims; or (d) contained in routine backups, which are deleted on WyndMe’s ordinary backup rotation schedule. Retained information remains subject to this DPA for as long as WyndMe holds it.
11. Audits and Certifications
11.1 Reports in lieu of audit. On written request no more than once per twelve (12) months, and subject to confidentiality obligations, WyndMe will provide Customer with its then-current third-party audit reports, certifications, attestations, and security summaries to the extent WyndMe holds them, which may include SOC 2 reports, PCI DSS Attestations of Compliance, and penetration test summaries, together with a description of the measures in Annex A, and will respond to a reasonable security questionnaire. The parties agree that these materials satisfy Customer’s audit rights under Applicable Privacy Law.
11.2 On-site audit. If Applicable Privacy Law requires an on-site audit and the materials in Section 11.1 are demonstrably insufficient, Customer may audit WyndMe’s compliance no more than once per twenty-four (24) months, on at least thirty (30) days’ written notice, during business hours, for no more than two (2) business days, in a manner that does not disrupt WyndMe’s operations or compromise the confidentiality or security of other customers’ data. Customer bears its own costs and WyndMe’s reasonable costs. Auditors must be independent, must not be WyndMe competitors, and must sign a confidentiality agreement. Findings are Confidential Information.
11.3 Regulator audits. Nothing limits a regulator’s lawful audit rights.
12. Liability
Each party’s liability under this DPA is subject to, and counts toward, the exclusions and limitations of liability in Section 13 of the Agreement. Nothing in this DPA expands either party’s liability beyond those limits, except to the extent Applicable Law prohibits limitation.
13. Order of Precedence and General
13.1 Precedence. In the event of a conflict between this DPA and the Agreement as to the processing of Personal Information, this DPA controls. In the event of a conflict between this DPA and a Payment Provider’s mandatory pass-through terms, the pass-through terms control as to their subject matter.
13.2 Governing law and jurisdiction. As set out in the Agreement.
13.3 Changes. WyndMe may amend this DPA where necessary to comply with Applicable Privacy Law, on notice consistent with Section 1.5 of the Agreement.
13.4 Severability. If a provision is invalid or unenforceable, the remainder stays in effect.
13.5 Term. This DPA takes effect with the Agreement and continues until WyndMe no longer holds Customer Personal Information.
Annex A: Technical and Organizational Security Measures
WyndMe maintains an information security program that includes, at a minimum:
Governance Written information security policies reviewed at least annually; a designated security lead; a risk assessment program; and an internal audit function.
Access control Role-based access on a least-privilege basis; unique user IDs; multi-factor authentication for administrative, remote, and privileged access; quarterly access reviews; immediate revocation on termination; and a privileged access management process.
Encryption TLS 1.2 or higher for data in transit; AES-256 or equivalent for data at rest; tokenization of payment credentials; and documented key management with rotation.
Network and infrastructure security Segmented networks; firewalls and security groups; intrusion detection and prevention; DDoS protection; hardened baseline configurations; and change management.
Application security Secure SDLC; peer code review; static and dynamic application security testing; dependency and container scanning; separation of development, test, and production environments; and prohibition on production data in non-production environments.
Vulnerability and patch management Continuous vulnerability scanning; risk-based remediation SLAs; annual third-party penetration testing; and a coordinated vulnerability disclosure channel.
Logging and monitoring Centralized, tamper-resistant logging; security event monitoring and alerting; and log retention consistent with the Privacy Policy.
Physical security Processing in data centers operated by providers holding SOC 2 and ISO 27001 certifications, with 24/7 physical access control, monitoring, and environmental protection.
Resilience Encrypted backups with periodic restoration testing; documented business continuity and disaster recovery plans, tested at least annually.
Incident response A documented plan with defined roles, severity classification, escalation, forensics, notification, and post-incident review; tested at least annually.
Personnel Background screening where lawful; confidentiality agreements; security awareness training at hire and annually; and disciplinary process for violations.
Vendor management Security due diligence before onboarding; contractual security requirements; and periodic reassessment.
Compliance PCI DSS compliance appropriate to WyndMe’s role in the payment flow; periodic independent security assessment; and alignment with recognized security frameworks.
WyndMe may update these measures from time to time to reflect changes in technology, threat landscape, and its operating environment, provided that the overall level of security is not materially reduced.
Annex B: Sub-processors
WyndMe engages Sub-processors in the categories below to process Customer Personal Information. The current itemized list, naming each Sub-processor, its processing activity, and its primary processing location, is maintained at www.wyndme.com/legal/sub-processors, where Customer may subscribe to receive advance notice of additions and replacements under Section 8.3.
| Category | Processing activity | Typical processing location |
|---|---|---|
| Cloud infrastructure and hosting | Hosting, compute, storage, backup, and content delivery for the Services | United States |
| Database and data warehouse providers | Storage, indexing, and querying of Customer Personal Information | United States |
| Identity verification providers | Verification of government identity documents and facial-geometry matching | United States |
| Fraud, risk, and device intelligence providers | Transaction scoring, device fingerprinting, bot detection, and consortium fraud signals | United States |
| Bank-data aggregation providers | Verification of bank account ownership, balance, and transaction data | United States, Canada |
| Communications providers | Delivery of transactional and marketing email, SMS, and push notifications | United States |
| Customer support and ticketing providers | Support case management, live chat, and knowledge base | United States |
| Product analytics and error monitoring providers | Usage measurement, crash and error reporting, and session replay | United States |
| CRM and marketing automation providers | Account records, campaign delivery, and attribution | United States |
| Document management and e-signature providers | Storage and execution of applications, agreements, and supporting documentation | United States |
| Accounting, tax, and information-reporting providers | Invoicing, tax determination, and preparation and filing of information returns | United States |
| Collections and recovery providers | Recovery of negative balances and amounts owed | United States, Canada |
| Security monitoring and incident response providers | Log analysis, threat detection, vulnerability management, and forensic support | United States |
| Professional advisors | Legal, audit, accounting, and insurance services | United States, Canada |
Not Sub-processors. As stated in Section 8.5, Payment Providers, Payment Networks, sponsor banks, acquirers, issuers, credit bureaus and other consumer reporting agencies, sanctions and watchlist screening providers, and governmental authorities act as independent Controllers rather than Sub-processors, and Sections 8.3 and 8.4 do not apply to them.
Contact: privacy@wyndme.com | legal@wyndme.com WyndMe Corp, Attn: Privacy Office, 3300 Triumph Blvd, Suite 100, Lehi, UT 84043
© 2026 WyndMe Corp.
PART VII: SMS AND MESSAGING TERMS
WyndMe SMS and Messaging Terms
Effective Date: August 1, 2026
These SMS and Messaging Terms apply to text messages sent by or on behalf of WyndMe Corp, Wynd Payments LLC, and Swipe Fundz Payments (together, “WyndMe,” “we,” “us”), and to your use of any messaging features within the Services. They are incorporated by reference into the WyndMe Terms of Service.
Part A: Messages We Send You
A.1 Program Description
By providing your mobile number and opting in, you consent to receive text messages from WyndMe. Depending on the programs you enroll in, these may include:
- Account and security alerts, login verification codes, password resets, and suspicious activity alerts
- Transaction and servicing alerts, settlement notifications, payout confirmations, Chargeback and dispute deadlines, funding holds, and document requests
- Support, replies to inquiries you initiate
- Marketing, product news, offers, and event invitations (separate opt-in)
Message frequency varies. Message and data rates may apply.
A.2 Consent
- Consent is not a condition of purchase or of receiving the Services. You can use the Services without receiving text messages, though you may not be able to use certain security features that rely on SMS.
- We obtain your express written consent before sending marketing messages, and your consent before sending account and transactional messages, in each case as required by the Telephone Consumer Protection Act, applicable state law, and Canada’s Anti-Spam Legislation.
- You represent that you are the subscriber to, or the customary user of, the mobile number you provide, and that you are authorized to consent for it. You must notify us immediately if you give up, transfer, or change the number.
A.3 Opting Out
Reply STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to any message to stop. You will receive one confirmation message, after which we will send no further messages to that number for that program. To rejoin, reply START or re-enroll.
Opting out of text messages does not opt you out of email or other Communications. Some security and legally required notices may still be delivered by other means.
A.4 Help
Reply HELP to any message, or contact support@wyndme.com or the number listed at www.wyndme.com/contact.
A.5 Carriers and Delivery
Supported carriers include the major U.S. and Canadian carriers. Carriers are not liable for delayed or undelivered messages. We do not guarantee delivery. Do not rely on SMS for time-critical notices; check your dashboard and email.
A.6 Privacy of Your Messaging Data
We do not share your mobile number, your SMS consent, or any data associated with your consent to receive text messages with third parties or affiliates for their marketing purposes. We disclose that data only to the messaging service providers that deliver messages on our behalf, and only for that purpose. See the Privacy Policy.
A.7 Charges
Message and data rates may apply. Charges are billed by and payable to your mobile carrier. Contact your carrier about your plan. We are not responsible for carrier charges.
Part B: Messages You Send Using the Services
This Part applies if you use the Services to send messages to your own Customers.
B.1 You Are the Sender
You are the sender of, and are solely responsible for, every message you send using the Services, including its content, its recipients, and its compliance with law.
B.2 Your Compliance Obligations
You represent, warrant, and covenant that for every message you send you will:
(a) Obtain and document consent. Obtain prior express consent, and prior express written consent for marketing and autodialed messages, from each recipient before messaging, in a form that satisfies the TCPA, the FCC’s implementing rules, applicable state mini-TCPA statutes (including Florida, Oklahoma, Maryland, and Washington), and CASL. Retain proof of consent for at least four (4) years and produce it to us within five (5) business days of request.
(b) Honor opt-outs. Process STOP, END, CANCEL, UNSUBSCRIBE, and QUIT, and any other reasonable indication of a request to stop, immediately, and in no event more than ten (10) business days after receipt. Maintain and honor a do-not-contact list.
(c) Identify yourself. Clearly identify your business in your messages, and provide a valid mechanism to contact you and to unsubscribe.
(d) Respect timing rules. Do not send marketing messages outside the hours permitted by federal, state, and provincial law in the recipient’s local time zone (generally 8:00 a.m. to 9:00 p.m., with stricter windows in some states).
(e) Scrub against DNC lists. Check the National Do Not Call Registry, applicable state registries, the Canadian National DNCL, and your internal list as required.
(f) Comply with carrier and CTIA requirements. Follow the CTIA Messaging Principles and Best Practices and all carrier requirements, including 10DLC brand and campaign registration, toll-free verification, and short-code program provisioning. You must register your brand and campaigns before sending. Unregistered traffic will be blocked or filtered by carriers, and you may incur carrier fees and penalties.
(g) Send only permitted content. Do not send messages relating to any Prohibited Business, or to SHAFT categories (sex, hate, alcohol, firearms, tobacco) where prohibited by carriers, or containing phishing, malware, or public URL shorteners.
(h) Do not use the Services for spam, bulk unsolicited messaging, snowshoeing, number cycling, or lead-generation traffic without documented consent chains.
B.3 Our Rights
We may, without prior notice: monitor messaging volume, content, and complaint and opt-out rates; throttle, filter, or block messages; suspend your messaging access; require proof of consent; and pass through carrier fees, surcharges, and penalties.
B.4 Your Indemnity
You will defend, indemnify, and hold harmless the WyndMe Parties from all Losses arising out of or relating to messages you send using the Services, including claims under the TCPA, state mini-TCPA statutes, CASL, the CAN-SPAM Act, and carrier or CTIA requirements, and any resulting carrier fines, penalties, or blocking. This indemnity survives termination.
B.5 Acknowledgment of Risk
You acknowledge that the Telephone Consumer Protection Act provides for statutory damages of US$500 to US$1,500 per message, without an aggregate cap, and is frequently enforced through class actions; that several states impose comparable or greater liability under their own statutes; and that Canada’s Anti-Spam Legislation provides for administrative monetary penalties of up to CAD $10,000,000 per violation for corporations.
You further acknowledge that documented, retrievable proof of recipient consent is the principal defense to such claims, that you alone control whether that proof exists, and that WyndMe makes no representation that use of the Services will render any message compliant with Applicable Law.
Part C: General
C.1 Changes. We may amend these SMS and Messaging Terms on notice consistent with Section 1.5 of the Terms of Service.
C.2 Conflicts. In the event of a conflict with the Terms of Service, these SMS and Messaging Terms control as to messaging.
C.3 Arbitration. Disputes arising out of these SMS and Messaging Terms are subject to Section 16 of the Terms of Service, including the arbitration agreement and class action waiver.
Contact: support@wyndme.com | privacy@wyndme.com
© 2026 WyndMe Corp.


