1. Overview & Who We Are
Digipae is a mobile payments and digital identity application operated by Ceivis LLC, a Missouri limited liability company ("Ceivis," "Digipae," "we," "us," or "our"). Our registered address is 11628 Old Ballas Rd Ste 345, St. Louis, MO 63141.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the Digipae mobile application, our websites at digipae.com, our business dashboard, our application programming interfaces (APIs), and related services (collectively, the "Service").
By using Digipae, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Service. This policy applies to consumers and to individuals who use the Service on behalf of a business (for example, business owners and authorized team members).
2. Information We Collect
2.1 Information You Provide Directly
- Account information: Mobile phone number, full name, email address, date of birth, and home address
- Identity verification data: Government-issued ID (driver's license, passport, state ID), Social Security Number (or last 4 digits), and a selfie/facial image submitted for identity verification (see Section 3)
- Financial information: Bank account details (via Plaid), debit/credit card numbers (tokenized via Stripe), payment history, wallet balance, payout destinations, and transaction records
- Business information (merchants): Legal business name, EIN/tax identification, beneficial ownership information, business address, and authorized representative details collected to comply with our customer due diligence obligations
- Communications: Support tickets, messages, call records, and feedback you send to us
- Profile information: Username, payment-link preferences, and notification settings
2.2 Information Collected Automatically
- Device information: Device type, operating system, unique device identifiers, and push notification tokens
- Usage data: Screens visited, features used, transaction timestamps, and session duration
- Location data: Approximate location (city/region level) for fraud detection — we do not collect precise GPS location
- Log and diagnostic data: IP address, crash data, and performance data collected via our error-monitoring provider
- Cookies and similar technologies on our websites and dashboard (see Section 6)
2.3 Information from Third Parties
- Identity verification & screening: Verification results, document authenticity signals, and watchlist/sanctions screening data from our identity-verification provider (Socure Inc.)
- Bank account connectivity: Account ownership, account/routing numbers, balances, and transaction data you authorize us to access through Plaid Inc.
- Payment processing: Payment status, card verification, and fraud signals from Stripe Inc.
- Authentication: Phone number verification via Firebase (Google LLC)
2.4 Sensitive Personal Information
Digipae collects certain categories of sensitive personal information including government identification numbers, financial account details, precise account credentials, and biometric data used for identity verification. We collect this data only as necessary to provide the Service and to comply with legal obligations. We do not use or disclose sensitive personal information for advertising, marketing, or for purposes other than those permitted under applicable law.
3. Biometric Information & Consent
3.1 What We Collect and Why
To verify your identity, prevent fraud, and comply with federal Know-Your-Customer (KYC) and Anti-Money-Laundering (AML) obligations, we collect a photograph of your face (a "selfie") and may generate a biometric identifier or biometric information from that image and from your government-issued ID — such as a facial geometry scan used to confirm that the person presenting the ID is its rightful holder ("Biometric Data"). This processing is performed by our identity-verification provider (Socure) on our behalf.
3.2 Your Consent
Before we collect Biometric Data, the app presents a consent screen disclosing that Biometric Data is being collected, the specific purpose, and the length of time it will be stored and used. We collect, store, and use your Biometric Data only after you provide informed written consent (including electronic consent) through that screen. You are not required to consent, but identity verification cannot be completed without it, and the Service cannot be provided without identity verification.
3.3 Retention & Destruction Schedule
We retain Biometric Data only as long as reasonably necessary to fulfill the purpose for which it was collected, and we permanently destroy it on the earlier of: (a) when the initial purpose for collection has been satisfied; or (b) within three (3) years of your last interaction with the Service — except where a longer period is required to comply with our legal, regulatory, or recordkeeping obligations (for example, retention of the verification record itself, separate from the underlying biometric template).
3.4 No Sale and Limited Disclosure
We do not sell, lease, trade, or otherwise profit from your Biometric Data, and we do not disclose it except: to our identity-verification provider to perform the verification; as required by law, subpoena, or warrant; or with your express consent.
4. How We Use Your Information
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account creation and authentication | Phone number, name, email | Contract performance / consent |
| Identity verification (KYC) | Government ID, SSN, selfie/biometric | Legal obligation (BSA/AML) |
| Processing payments, transfers, and payouts | Financial info, bank/card data, wallet balance | Contract performance |
| Fraud detection and prevention | Device info, transaction patterns, location | Legitimate interest / legal obligation |
| Transaction receipts and notices | Email, transaction details | Contract performance / legal obligation |
| Customer support | Account info, transaction history | Contract performance |
| Push and SMS notifications | Push token, phone number, transaction events | Consent / contract performance |
| Regulatory compliance and reporting | Identity data, transaction records | Legal obligation |
| Service improvement and security | Anonymized usage data, diagnostic logs | Legitimate interest |
We do not sell your personal information. We do not use your personal data for targeted or cross-context behavioral advertising. We do not share your financial information for marketing purposes.
5. GLBA Privacy Notice (Financial Privacy)
As a financial institution under the Gramm-Leach-Bliley Act, we provide the following notice describing what we do with your nonpublic personal information. This notice is provided when you open an account and annually thereafter where required.
| FACTS | What does Digipae do with your personal information? |
|---|---|
| Why? | Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. |
| What? | The types of information we collect depend on the product or service you use and can include Social Security number and identification details, account balances and transaction history, and payment card or bank account information. |
| How? | All financial companies need to share customers' personal information to run their everyday business. Below we list the reasons we can share, and whether you can limit that sharing. |
| Reasons we can share | Does Digipae share? | Can you limit? |
|---|---|---|
| For everyday business purposes — to process transactions, maintain your account, respond to court orders and legal investigations, or report to credit bureaus | Yes | No |
| For our marketing purposes — to offer our products and services to you | Limited | Yes |
| For joint marketing with other financial companies | No | N/A |
| For our affiliates' everyday business purposes | No | N/A |
| For nonaffiliates to market to you | No | N/A |
| To sell your information | No | N/A |
To limit the sharing we describe as "Limited" above, email privacy@digipae.com. If you are a new customer, we can begin sharing your information 30 days from the date we sent this notice; you can contact us at any time to limit our sharing.
8. Automated Decision-Making & Profiling
We use automated processes to verify identities, score transactions for fraud risk, and enforce transaction limits. These automated decisions can result in a transaction being delayed, declined, held for review, or an account being restricted, in order to protect you and the Service and to meet our legal obligations.
Where required by applicable law, you have the right to request information about the logic involved and to request human review of a decision that produces a legal or similarly significant effect. To request review, contact privacy@digipae.com. Note that certain anti-fraud and AML determinations cannot be overridden where doing so would conflict with our legal obligations.
9. How We Protect Your Data
We maintain an information security program with administrative, technical, and physical safeguards, including:
- Encryption at rest: Data stored in our database is encrypted using AES-256
- Encryption in transit: All communications use TLS 1.2 or higher
- Authentication: SMS one-time-passcode and device-bound sessions
- Payment security: Card data is handled by Stripe (PCI DSS Level 1) — we never store raw card numbers
- Transaction authorization: Payments require a PIN or biometric confirmation
- Access controls: Role-based access limits employee access to your data
- Audit logs: Sensitive operations are logged for security review
- Rate limiting: Sensitive endpoints are rate-limited to prevent abuse
9.1 Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you and applicable regulatory authorities as required by law, without unreasonable delay. Notification will be provided via email to your registered address and/or in-app notice.
10. Data Retention & Deletion
10.1 Retention Periods
| Data Type | Retention Period | Reason |
|---|---|---|
| Transaction records | 5 years after account closure (or longer if required) | BSA/AML legal requirement |
| KYC / identity records | 5 years after account closure | FinCEN regulatory requirement |
| Biometric data / template | Until purpose satisfied or 3 years from last interaction | See Section 3 |
| Account information | Duration of account + 5 years | Legal and regulatory compliance |
| Support communications | 3 years | Dispute resolution |
| Usage / analytics data | 24 months (de-identified) | Service improvement |
10.2 Account Deletion
You may request deletion of your account at any time through:
- In-app: Profile → Settings → Delete Account
- Email: privacy@digipae.com with subject "Account Deletion Request"
- Web: digipae.com/support
Upon a valid request, we remove your personal data from active systems within 30 days. However, certain transaction and identity records must be retained as required by federal financial regulations (BSA, AML) and state money-transmission law. Retained data is isolated from active systems and accessed only for compliance purposes.
11. Your Privacy Rights (All U.S. States)
Depending on your state of residence, you may have some or all of the following rights under comprehensive state privacy laws (including those in California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other states with laws in effect):
- Right to know / access: Confirm whether we process your personal information and request a copy
- Right to correct: Request correction of inaccurate personal information
- Right to delete: Request deletion (subject to legal exceptions, such as required financial recordkeeping)
- Right to portability: Obtain a copy of your data in a portable, machine-readable format
- Right to opt out: Opt out of the sale of personal information, targeted advertising, and certain profiling (we do not sell data or use it for targeted advertising)
- Right to limit sensitive data: Limit use of sensitive personal information to what is necessary to provide the Service
- Right against discrimination: We will not discriminate against you for exercising your rights
11.1 How to Submit a Request
Submit a request by emailing privacy@digipae.com or through digipae.com/support. We will verify your identity before acting on your request and will respond within the timeframe required by your state's law (generally 45 days, extendable once where permitted). An authorized agent may submit a request on your behalf with proof of authorization.
11.2 Right to Appeal
If we decline your request and your state provides an appeal right (for example, Virginia, Colorado, Connecticut, Texas, Oregon, and Montana), you may appeal by replying to our decision or emailing privacy@digipae.com with the subject "Privacy Appeal." We will respond to your appeal within the period required by law. If your appeal is denied, you may contact your state Attorney General.
11.3 GLBA-Regulated Data
Personal information we collect and process subject to the GLBA may be exempt from certain state privacy-law requests. Where an exemption applies, we will still honor your rights to the extent the law requires.
12. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with additional rights. Note that personal information collected, processed, or disclosed under the GLBA is exempt from the CCPA; the rights below apply to information not covered by that exemption.
12.1 Categories of Personal Information Collected
In the past 12 months, we have collected the following categories:
- Identifiers (name, email, phone, IP address, device ID)
- Financial information (bank account via Plaid, card data via Stripe)
- Sensitive personal information (government ID, SSN, biometric data)
- Commercial information (transaction history, payment records)
- Internet activity (app/website usage, diagnostic logs)
- Geolocation data (approximate location for fraud detection)
12.2 Your California Rights
- Right to Know, Delete, and Correct your personal information (subject to legal exceptions)
- Right to Opt-Out of sale or sharing (we do not sell or share for cross-context behavioral advertising)
- Right to Limit Use of Sensitive Personal Information beyond necessary service purposes
- Right to Non-Discrimination for exercising your rights
12.3 Submitting a Request
Submit a verifiable consumer request at privacy@digipae.com or digipae.com/support. We respond within 45 days. California residents may designate an authorized agent with written proof of authorization. We also honor Global Privacy Control (GPC) signals.
13. SMS / Text Messaging Program
We send text messages for one-time passcodes, account security alerts, and transaction-related notices. By providing your mobile number and using the Service, you consent to receive these messages, which are necessary to operate your account.
- Message frequency varies based on your account activity.
- Message and data rates may apply depending on your mobile carrier plan.
- Opt-out: Reply STOP to non-essential messages to unsubscribe; reply HELP for help. Note that disabling security and transaction messages may limit or prevent use of the Service.
- Carriers are not liable for delayed or undelivered messages.
We do not share mobile information with third parties or affiliates for their marketing or promotional purposes. Phone numbers are shared only with our messaging service providers to deliver the messages described above.
14. Children's Privacy
Digipae is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. Age is verified during identity onboarding; users who cannot verify they are 18 or older are not permitted to use the Service. If you believe a minor has provided us information, contact privacy@digipae.com and we will delete it promptly.
15. International Users & Data Transfers
Digipae is intended for use only in the United States, and our services are operated from the United States. We do not knowingly offer the Service to users outside the United States. If you access the Service from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your jurisdiction.
16. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. When we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Send an in-app notification to active users
- Send an email notification for significant changes
- Obtain your renewed consent where required by law
Continued use of the Service after changes become effective constitutes acceptance of the updated policy.
17. Contact Us
For privacy questions, requests, or concerns, contact us:
| Contact Method | Details |
|---|---|
| Privacy / Privacy Officer | privacy@digipae.com |
| Security Issues | security@digipae.com |
| General Support | support@digipae.com |
| Mailing Address | Ceivis LLC, 11628 Old Ballas Rd Ste 345, St. Louis, MO 63141 |
| Support Portal | digipae.com/support |
We aim to respond to privacy requests within 45 days. For urgent security concerns, email security@digipae.com directly.