Notice Date: August 11, 2017

Effective Date: September 10, 2017

Tipalti Inc. and our affiliates (“Tipalti”, “we”, “our” or “us”) respect the privacy of our users, and are committed to protect their personal information and use it lawfully. This Privacy Policy (“Policy”) describes how we may collect, use and disclose such personal information, and the rights and choices available to our users regarding such information.

We strongly urge you to read this policy and make sure you fully understand and agree with it, before you access or use any of our services. If you do not read, fully understand and agree to this Privacy Policy, you must refrain from and/or discontinue any use of this website, application or service, and avoid or discontinue all use of any of our services.

  1. Your Consent (please read carefully!)

Tipalti provides global payment processing automation platform and services. This Privacy Policy (“Privacy Policy“) describes how we may collect and use information pertaining to each of our unregistered visitors and registered users, including Payors and Payees (each, a “User“, or “you“), in connection with their access to and use of Tipalti’s platform, services, website (including tipalti.com and any of its subdomains, including any of Tipalti’s websites appearing within iFrames integrated under third party domains; collectively, the “Website“) and web applications (collectively, the “Services“).

This Privacy Policy constitutes a binding and enforceable legal contract between Tipalti and you – so please read it carefully.

You may use the Services only if you fully agree to this Privacy Policy – and by accessing and/or using any of the Services, you signify and affirm your informed consent to the collection and processing of your Personal Information as defined and explained below.

Please note: you are not obligated by law to provide us with any information. You hereby acknowledge, warrant and agree that any information you do provide us is provided of your own free will and consent, for the purposes and uses described herein.

  1. What Information Do We Collect?

Tipalti’s Services unify the phases of supplier payments, from vendor on-boarding and payment method selection to funds disbursement and payment reconciliation. Throughout this process, we collect two general types of information regarding our Users:

  1. Un-identified and non-identifiable information pertaining to visitors of our Services or un-identified Users, which may be made available to us, or collected automatically via their use of the Services (“Non-personal Information“). Such Non-personal Information does not enable us to identify the person from whom it was collected, and mainly consists of technical and aggregated usage information, such as browsing and ‘click-stream’ activity on the Services, session heatmaps and scrolls, non-identifying information regarding their device, operating system, screen resolution, internet browser, language and keyboard settings, ISP, referring/exit pages, date/time stamps, etc.
  2. Individually identifiable information, namely information that identifies an individual or may with reasonable efforts cause the identification of an individual, or may be of private or sensitive nature (“Personal Information“). Such Personal Information that is collected by us mainly consists of the following types of information (including, for the avoidance of doubt, Non-personal Information that is connected or linked to said Personal Information to the extent such connection or linkage exists (for example, in order to improve the Services we offer)):
    1. Payee Information: Information concerning Users to whom payments are made (“Payee(s)“) by Tipalti customers (“Payors“) through the Services. Specifically, such information may include, depending on configuration determination or otherwise at the choice of our Payors or their Payees, the names, physical addresses, e-mail address, phone number, VAT ID, Social Security Numbers or US Taxpayer numbers (as applicable) of the Payees and additional information pertaining to Payees which may be required under applicable tax forms for transferring and receiving payments, country, bank account numbers, IBAN, SWIFT code (or alternatively, their account details at other third party payment processing services such as provided by PayPal, as applicable), payment preferences, session IP address, and supplemental documentation as may be required by Payors of their Payees, that may contain Personal Information (such as a copy of their government-issued identification card, personal bank statements or other documentation serving as proof of identity or valid address), and any other Personal Information provided to us by either Payors or Payees. For more regarding Payee information and how we treat it, please see Section 6 below.
    2. Payor Information: Information concerning Payor Users (including authorized personnel of Payor), namely their company name and affiliation, physical address, E-mails and login credentials to our Services, bank account numbers (or alternatively, their account details at payment processing services such as PayPal, as applicable), payment preferences and transaction history (to the extent that any such information is personally identifiable to any particular persons, otherwise we will deem it as Non-personal Information).
    3. Other User Information from both registered and unregistered Users: We collect information from you when you contact us for more information regarding our services or register on our site for our support forums, subscribe to our newsletter or webinar series, participate in an online forum, blog, or voluntary survey, download content or fill out a form. We may collect all or some of the following information: name, email address, phone number, company name, title, department, country and/or industry. Alternatively, you may visit our site anonymously. Any data we request that is not required will be specified as voluntary or optional. We may also collect information when you ask to be included in an email or other mailing list.
  1. How Do We Collect Such Information?

There are two main methods that we use:

  1. We collect information through the use of our Services. Namely, when our Users visit or use our Services, we might be aware of it and may gather, collect and record such uses, sessions and related information, including by using third party services as detailed in Section 8 below, and by using “cookies” and other tracking technologies, as further detailed in Section 9 below.
  2. We collect information which is provided to us voluntarily. For example, we collect the Personal Information that our Users provide us when registering to our Services, uploading documents to our Services, filling out forms, depositing or withdrawing payments, contacting us, etc. In addition, we may collect Personal Information that is provided to us by a Payor regarding its Payees and vice versa, by banks and payment processing services, and by either a Payor or Payee regarding their employees or representatives using the Services on their behalf.
  1. Why Do We Collect Such Information?

We collect such Non-personal and Personal Information for the following purposes:

  1. To facilitate, operate, and provide our Services;
  2. To verify the identity of our Users;
  3. To further develop, customize and improve our Services, and to provide you with any such enhanced Services;
  4. To provide our Users with ongoing customer assistance and technical support;
  5. To be able to contact our visitors and Users with general and personalized service-related notices, surveys and promotional messages (as further detailed in Section 9 below);
  6. To create aggregated statistical data and other aggregated and/or inferred Non-personal Information, which we, our Users or our business partners may use to operate and improve our respective services;
  7. To manage and assess risk, enhance our data security and fraud prevention capabilities, and help protect against error, fraud or any illegal or prohibited activity;
  8. To act as permitted by, and to comply with, any legal or regulatory requirements; and
  9. To conduct any additional activities that may require the use of your Personal Information, for which we will request your consent in advance.
  1. Where Do We Store Personal Information?

Information regarding our Users may be maintained, processed and stored by Tipalti and our authorized affiliates and Service Providers (including our secured cloud storage providers) in the United States of America, in Israel, and in other jurisdictions as necessary for the proper delivery of our Services and/or as may be required by law (as further explained in Section 8 below).

Tipalti is based in the United States with offices in San Mateo, California and in Israel with offices in Herzliya. Israel is considered by the European Commission to be offering an adequate level of protection for the personal information of EU Member State residents.

While the data protection laws in the above jurisdictions may be different than the laws of your residence or location, please know that Tipalti, its affiliates and Service Providers that store or process your Personal Information on Tipalti’s behalf are each committed to keeping it protected and secured, in accordance with this Privacy Policy and industry standards, regardless of any lesser legal requirements that may apply in their jurisdiction.

EU-US Privacy Shield & Swiss-US Privacy Shield Frameworks: Tipalti is committed to upholding the principles of the EU-US Privacy Shield and the Swiss-US Privacy Shield Frameworks, as set forth by the US Department of Commerce regarding the collection, use, and retention of Personal Information from Users in the European Union member countries and in Switzerland. Tipalti Inc. has certified that it adheres to the Privacy Shield principles of notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, recourse, enforcement and liability. Tipalti is responsible for the processing of Personal Information it receives, and subsequently transfers to a third party acting on its behalf. If there is any conflict between the provisions of this Privacy Policy and the Privacy Shield principles, the Privacy Shield principles shall govern with respect to Personal Information of persons residing in the EU or in Switzerland. To learn more about the Privacy Shield Frameworks, please visit https://www.privacyshield.gov.

We are committed to attempt to resolve privacy complaints under the EU-US Privacy Shield and Swiss-US Privacy Shield principles.

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.

Tipalti commits to cooperate with EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) and comply with the advice given by such authorities with regard to human resources data transferred from the EU and Switzerland in the context of the employment relationship.

Under certain conditions, you may invoke binding arbitration when other dispute resolution procedures have been exhausted. The Federal Trade Commission (FTC) has jurisdiction over Tipalti Inc.’s compliance with the Privacy Shield.

  1. Payee Information

Tipalti may collect, store and process certain Non-personal and Personal Information of Payees, on our Payor Users’ behalf and at their direction. For example, our Payors are able to upload certain Payee information to our Services, as well as require their Payees to upload certain Personal Information during or following their registration and on-boarding to the Services. Such Personal Information is then stored with Tipalti (and its third party service providers), on the Payor’s behalf.

For such purposes, Tipalti serves and shall be considered as a “Data Processor” and not as the “Controller” (as both such capitalized terms are defined in the European Data Protection Directive and the upcoming General Data Protection Regulation) of such Payee information. The Payor Users shall be considered as the “Controllers” of such Payee information, and are responsible for complying with all laws and regulations that may apply to the collection and control of such information, including all data protection laws of any relevant jurisdiction.

Payors are responsible for the security, integrity and authorized use of their Payees’ information, and for obtaining any consents and permissions required for the collection, processing and use of such information.

If you are a Payee of any of our Payors and have had your Personal Information collected on such Payor’s behalf, we recommend that you contact such Payor directly with any privacy or data-related concern you might have. For example, if you wish to access, correct, amend or delete inaccurate information processed by Tipalti on behalf of its Payor Users, please correct the information on the same website from which it was originally entered by you or contact the relevant Payor directly (as they are the “Controller” of such data). If requested to remove any Payee Personal Information, we will respond to such request within thirty (30) days. Unless otherwise instructed by our Payor User, we will retain their Payees’ Personal Information for the period set forth in Section 12 below.

If a Payee has entered a direct agreement and relationship with Tipalti, under which such Payee’s Personal Information is provided by Payee to Tipalti or otherwise collected for any services provided by Tipalti directly to Payee, Tipalti shall be deemed as the “Controller” of such information, and Payee may contact it directly, as further explained in Section 15 below.

  1. With Whom Do We Share Personal Information

Tipalti may share your Personal Information with third parties (or otherwise allow them access to it) only in the following manners and instances:

Third Party Services: Tipalti has partnered with a number of selected service providers, whose services and solutions complement, facilitate and enhance our own. These include hosting and server co-location services, data and cyber security services, banks, payment processors and correspondents, Credit Bureaus, collection agencies, fraud detection and prevention services, web analytics, e-mail distribution and monitoring services, session recording, remote access services, and our business, legal and financial advisors (collectively, “Third Party Services“). Such Third Party Services may receive or otherwise have access to our Users’ Personal Information, depending on each of their particular roles and purposes in facilitating and enhancing our Services and business, and may only use it for such purposes. Tipalti remains responsible and liable for any Personal Information processing done by Third Party Services on its behalf, except for events outside of its reasonable control.

Sharing Payee Information with Payors: If you are a Payee, we may share your Personal Information with your respective Payor so we can process payments for you from that particular Payor. For further information, please see Section 6 above.

Governmental/Law Enforcement Agencies and Legal Requests or Duties: We may disclose or otherwise allow access to your Personal Information pursuant to a legal request, such as a subpoena, search warrant or court order, or in compliance with applicable laws, with or without notice to you, if we have a good faith belief that we are legally required to do so, or that disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, counter terrorist financing verification requirements, fraud, or other wrongdoing.

Protecting Rights and Safety: We may share your Personal Information with others, with or without notice to you, if we believe in good faith that this will help protect the rights, property or personal safety of Tipalti, any of our Users, or any member of the general public.

Tipalti Subsidiaries and Affiliated Companies: We may share Personal Information internally within our family of companies, for the purposes described in this Privacy Policy and in accordance with Section 5 above. In addition, should Tipalti or any of its affiliates undergo any change in control, including by means of merger, acquisition or purchase of substantially all of its assets, your Personal Information may be shared with the parties involved in such event. If we believe that such change in control might materially affect your Personal Information then stored with us, we will notify you of this event and the choices you may have you via e-mail and/or prominent notice on our Website or Services.

For the avoidance of doubt, Tipalti may share your Personal Information in additional manners, pursuant to your explicit approval, or if we are legally obligated to do so. Additionally, we may transfer, share or otherwise use Non-personal Information in our sole discretion and without the need for further approval. 

  1. Use of Cookies and Other Tracking Technologies

Tipalti uses certain monitoring and tracking technologies, including ones offered by Third Party Services. These technologies are used in order to maintain, provide and improve our Services on an ongoing basis, and in order to provide a better experience to our visitors and Users. For example, these technologies enable us to keep track of our Users’ preferences and authenticated sessions, to better secure our Services and detect abnormal behaviors, to identify technical issues, and to monitor and improve the overall performance of our Services.

Cookies: In order for some of these technologies to work properly, a small data file (“cookie”) must be downloaded and stored on your device, for purposes of session and user authentication, security, keeping the User’s preferences, connection stability, monitoring performance and generally providing and improving our Services.

In order to delete or block any cookies, please refer to the “Help” area on your internet browser for further instructions, or look for optional third party add-ons offering cookie management assistance. For example, you can instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookie from the website you visit. Click “Help” in the toolbar of your browser for instructions, or review the cookie management guide produced by the Interactive Advertising Bureau – www.allaboutcookies.org. Please note however that deleting any of Tipalti’s cookies or disabling future cookies or tracking technologies may prevent you from accessing certain areas or features of our Services, or may otherwise adversely affect your user experience.

Google Analytics: Our Website uses Google analytics, a web analytics service provided by Google, Inc. Non-personal Information is transmitted to and stored by Google on their servers. Please visit Google Analytics find out how Google uses such information or how you can opt out of being tracked. Please note that we do not change our practices in response to a “Do Not Track” signal in the HTTP header from a browser or mobile application.

  1. Communications From Tipalti

Promotional Messages: By registering to our Services and/or providing Tipalti with your e-mail address or any other contact information (such as your mobile phone number), you expressly agree to receive promotional content, messages or calls from Tipalti or our partners (acting on our behalf) through such means. Accordingly, we shall be entitled to call you or send you promotional content or messages by e-mail, SMS, direct text messages, marketing calls and similar forms of communication.

If you wish not to receive such promotional messages or calls, you may notify Tipalti at any time or follow the “unsubscribe” or “stop” instructions contained in the promotional communications you receive.

Service Messages: Tipalti may also contact you with important information regarding our Services. For example, we may notify you (through any of the means available to us) of changes or updates to our Services, payment issues, service maintenance, etc. You will not be able to opt-out of receive such service messages.

  1. Accessing Your Personal Information

If you wish to exercise your right to access and/or request us to make corrections to your Personal Information that you have stored with us, or would like to receive a summary of what Personal Information (if any) of yours we disclosed to third parties for direct marketing purposes, please send us an e-mail to privacy@tipalti.com, or mail your request to Tipalti Inc., 1810 Gateway Drive, Suite 260, San Mateo, CA 94404, Attn: Data Protection Officer, and we will respond within a reasonable timeframe and in accordance with applicable laws. Please note that you may also correct, update or remove certain parts of your Personal Information by yourself, or completely deactivate your account, by logging into your account at Tipalti or by going to the same website where you originally provided the Information.

If you are a Payee of any of our Payors, we recommend that you contact such Payor directly if you wish to access, correct, amend or delete inaccurate information processed by Tipalti on behalf of such Payor (for more information, please see Section 6 above).

  1. Data Retention

We may retain your Personal Information for as long as your User account is active or as otherwise needed to provide you with our Services. We may retain such Personal Information even after you deactivate your account or cease to use our Services, as reasonably necessary to comply with our legal obligations, to resolve disputes regarding any of our Users, prevent fraud and abuse, enforce our agreements and/or protect our legitimate interests.

  1. Security

Tipalti has implemented security measures designed to protect the Personal Information of our Users, including physical, procedural and electronic measures. Among other things, we offer HTTPS secure access to most areas on our Services; we use industry standard SSL/TLS encrypted connections to protect the transmission of information that we believe in good faith to be of a sensitive nature; we use encryption tools to protect such sensitive information stored with us; we regularly monitor our systems for possible vulnerabilities and attacks, and seek news ways and tools for further enhancing the security of our Services and the integrity of the Personal Information that we hold.

Please note however, that regardless of the measures we take and the efforts we make, we cannot and do not guarantee the absolute protection and security of any Personal Information stored with us.

We strongly encourage you to set strong passwords for your User account(s), avoid using the “save password” feature in your browser, and protect your account against unwanted access on your end (for example, do not share your login credentials with others, or allow them free access to your logged-in device).

If you have any questions regarding the security of our Services, please feel free to contact us at privacy@tipalti.com.

  1. General

This Privacy Policy, its interpretation, and any claims and disputes related hereto, shall be governed by and enforced in all respects solely and exclusively in accordance with the internal substantive laws of the State of California, without respect to its conflict of laws principles. Any and all such claims and disputes shall be brought in, and you hereby consent to them being litigated in and decided exclusively by, the U.S. District Court for the Northern District of California or a state court of competent jurisdiction located in San Mateo County.

We may amend this Privacy Policy at any time by posting a revised version on our website. The revised version will be effective as of the published effective date. In addition, if the revised version includes a substantial change, we will provide you with 30 days’ prior notice via any of the communication means described in Section 9 above, or by posting notice of the change on our website. After this 30-day notice period, you will be considered as having expressly consented to all amendments to this Privacy Policy. We encourage you to periodically review this page for the latest information on our privacy practices.

Note that while our Services may contain links to other websites or services, we are not responsible for such websites’ or services’ privacy practices, and encourage you to be aware when you leave our Services and read the privacy statements of each and every website and service you visit. This Privacy Policy does not apply to such linked third-party websites and services.

Our Services are not intended for use by children under the age of 13. To use the Services, you must have attained the age of majority in your state/province/country of residence. If you are under the legal age to form a binding contract in the jurisdiction in which you are located, you may only use the Services under the supervision of a parent or legal guardian who has agreed to any agreement you enter into while using the Services, including the terms of this Privacy Policy. We do not knowingly collect Personal Information from minors under the age of 13 and do not wish to do so. We reserve the right to request proof of age at any stage so that we can verify that minors are not using the Services. In the event that it comes to our knowledge that a minor is using the Services, we will prohibit and block such User from accessing the Services and will make all efforts to promptly delete any Personal Information stored with us with regard to such User.

This Privacy Policy was written in English, and may be translated into other languages for your convenience. If a translated (non-English) version of this Privacy Policy conflicts in any way with its English version, the provisions of the English version shall prevail.

  1. What if you have any questions?

You may contact us at this address: TIPALTI, INC. 1810 GATEWAY DR., SUITE 260, SAN MATEO, CA 94404, or send an email to: privacy@tipalti.com.


Job Applicants’ Privacy Policy

This policy describes what personal information we (Tipalti Inc. and our affiliates, “Tipalti”) collect on our job candidates and applicants (“Applicants”) during our application and recruitment process, why we collect it and how we use it. It also describes how Applicants may access and update such information.  The terms and conditions from the Tipalti Privacy Policy above, as applicable, are incorporated herein by this reference.

You may apply to any of Tipalti’s positions only if you fully agree to this Privacy Policy – and by applying, you signify and affirm your informed consent to the collection and processing of your personal information as defined and explained below.

You are not obligated by law to provide us with any information, and any information you do provide is provided of your own free will and consent, for the purposes and uses described herein.

  1. What information do we collect, how do we collect it, and how do we use it?

Throughout the application and recruitment process, you may provide us (or we may otherwise have access to) personal information about you, such as your identifying information, contact details, work-related information, social media activity, etc. We may collect this information directly from you, as you provide it voluntarily through your application and candidacy review process, or from other sources such as your references or our service providers.

We may use such information solely in order to assess our Applicants’ skills, qualifications and overall to verify, consider and process their application and candidacy for any of our positions, and to communicate with them regarding such processes. We may also use it to manage risk and enhance our security and anti-fraud measures, and to create aggregated statistical or inferred data regarding our Applicants, for further development and improvement of our and our partners’ recruitment processes. In addition, we may use it to act as permitted by, and to comply with, any legal or regulatory requirements, and to conduct any additional activities that may require the use of your information, for which we will request your specific consent in advance.

  1. Where do we store our applicants’ information, for how long, and how do we secure it?

Information regarding our Applicants will be maintained, processed and stored by Tipalti and our authorized affiliates and service providers in the United States of America, in Israel, in the applied position’s location(s), and as necessary, in secured cloud storage provided by our Third Party Services.

We may retain your information even after the applied position has been filled or closed. This is done so we could re-consider Applicants for other positions and opportunities at Tipalti; so we could use their personal information as reference for future applications submitted by them; in case the Applicant is hired, for additional employment and business purposes related to their work; and as reasonably necessary to comply with our legal obligations, to resolve disputes, prevent fraud and abuse, enforce our agreements and/or protect our legitimate interests.

Tipalti has implemented security measures designed to protect the personal information of our Applicants, including physical, procedural and electronic measures. Among other things, we offer HTTPS secure access to most areas on our website and services; we use industry standard SSL/TLS encrypted connections to protect the transmission of information that we believe in good faith to be of a sensitive nature; we use encryption tools to protect such sensitive information stored with us; we regularly monitor our systems for possible vulnerabilities and attacks, and seek news ways and tools for further enhancing the security of our Services and the integrity of the personal information that we hold. Please note however, that regardless of the measures we take and the efforts we make, we cannot and do not guarantee the absolute protection and security of any personal information stored with us.

  1. Who will have access to your information?

Tipalti may share your personal information with a number of selected service providers, whose services and solutions complement, facilitate and enhance our own. These include any recruitment firms that have referred you to us (or vice versa), candidate evaluation centers, background checks providers, hosting and server co-location services, data and cyber security services, banks, payment processors and correspondents, Credit Bureaus, collection agencies, fraud detection and prevention services, web analytics, e-mail distribution and monitoring services, session recording, remote access services, and our business, legal and financial advisors (collectively, “Third Party Services“). Such Third Party Services may receive or otherwise have limited access to our Applicants’ personal information, depending on each of their particular roles and purposes in facilitating and enhancing our recruitment process, and may only use it for such purposes. Tipalti remains responsible and liable for any personal information processing done by Third Party Services on its behalf, except for events outside of its reasonable control.

Additionally, we may disclose or otherwise allow access to any Applicants’ personal information pursuant to a legal request, such as a subpoena, search warrant or court order, or in compliance with applicable laws, with or without notice to you, if we have a good faith belief that we are legally required to do so, or that disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, counter terrorist financing verification requirements, fraud, or other wrongdoing. We may also share your personal information with others, with or without notice to you, if we believe in good faith that this will help protect the rights, property or personal safety of Tipalti, any of our users or employees, or any member of the general public.

Finally, we may share personal information internally within our family of companies, for the purposes described above. In addition, should Tipalti or any of its affiliates undergo any change in control, including by means of merger, acquisition or purchase of substantially all of its assets, your personal information may be shared with the parties involved in such event.

  1. How can you access your information?

If you wish to exercise your right to access and/or request us to make corrections to your personal information that you have stored with us, please send us an e-mail to privacy@tipalti.com, or mail your request to Tipalti Inc., 1810 Gateway Drive, San Mateo, CA 94404, Attn: Data Protection Officer, and we will respond within a reasonable timeframe and in accordance with applicable laws. Please note that you may also correct, update or remove certain parts of your personal information by yourself, or completely deactivate your account, by logging into your account at Tipalti.