GFT Pay Inc.

PRIVACY POLICY

Effective Date: August 15, 2026

The Short Version

The rest of this notice sets out the detail, including disclosures we are required to make under state privacy laws.

GFT Pay Inc. (“GFT,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Notice explains how we collect, use, share, and protect your personal information when you use GFT’s products and services, including our website, our web wallet, our mobile application, GFT features made available inside a merchant or partner website or application, digital payment cards, and wallet integrations (collectively, the “Services”). Please note that this Privacy Notice does not apply to websites owned and operated by third parties regardless of whether our Services are linked to them. Websites not owned or operated by us will be subject to their own privacy policies. We have no control over third-party companies or their privacy policies.

Other documents. Your use of the Services is governed by our Terms of Use, and your card account is governed by the Cardholder Terms & Conditions. Cards are issued by Florida Capital Bank, N.A. (the “Bank”), which provides its own privacy notice covering the information it holds as issuer.

Financial privacy law. Much of the information we collect in connection with your card account is subject to the federal Gramm-Leach-Bliley Act (“GLBA”), and where it is, GLBA governs and the state privacy rights described below do not apply to it. We describe our practices in one notice rather than several, so parts of this notice may describe rights that do not apply to every category of information we hold.

Types of Information We Collect

We may collect the following types of information when you use our products, services, or mobile application, or visit our websites:

Information About Other People

If you use the Services to send a gift card to someone else, you will give us that person’s contact information, such as their name, email address, or mobile phone number. We use it to deliver the gift, to let you know whether it has been claimed, and to support the recipient if they contact us. By providing another person’s contact information, you confirm that you are permitted to give it to us for this purpose. If someone sends you a gift, we hold their contact information and yours in connection with that gift, whether or not you claim it and whether or not you create an account.

Biometrics, Passkeys, and Device Authentication

GFT does not collect, capture, receive, store, or use biometric identifiers or biometric information. When you unlock your device, approve a payment in a digital wallet, or sign in with a passkey using a fingerprint, face scan, or device passcode, that verification happens on your device and is performed by your device or platform provider. GFT receives only confirmation that verification succeeded. We never receive the underlying fingerprint, face scan, or other biometric data, and we do not create or store any biometric template.

The one exception is identity verification performed by a third-party provider where required by law or program rules, as described above. In that case the provider, not GFT, processes any biometric data, under contractual restrictions limiting its use to identity verification.

How We Collect Your Information

We collect Personal Information about you when you request information about, apply for, or use our products or services, register for online or mobile account access, claim or activate a card someone has sent you, contact us for customer service, communicate with us through social media, or otherwise interact with us. We may also collect Personal Information about you from other sources, such as public databases, credit reporting agencies, social media platforms, affiliated companies, the merchant or sponsor whose program you participate in, another GFT user who sends you a gift, and other third parties.

We also collect Non-Personal Information about your online and mobile activity automatically using the following tracking technologies:

We do not use advertising trackers. We do not use advertising cookies, pixel tags, web beacons, or mobile advertising identifiers to deliver advertising to you on other companies’ websites or apps, and we do not disclose personal information for cross-context behavioral advertising. If that changes, we will update this notice and provide the opt-out described below before we begin.

You may manage cookies and similar technologies through the settings on your device or browser.

Global Privacy Control and Other Opt-Out Preference Signals

We honor the Global Privacy Control (“GPC”) and other opt-out preference signals that applicable law requires us to recognize. If you visit our website from a browser or extension that transmits GPC, we will treat that signal as a request to opt out of any sale or sharing of personal information associated with that browser, and we will apply it to your account where we can reasonably associate the signal with an account.

Separately, the California Online Privacy Protection Act requires us to disclose how we respond to Do Not Track signals. Do Not Track is a different, older signal with no agreed meaning across the industry, and we do not respond to it. This does not affect how we treat GPC.

How We Use Collected Information

We use information we collect about you to:

Sharing Your Information

If you are our customer or former customer, we will share your information in order to process transactions or otherwise make the products and services operational, including sharing with the issuing bank, the payment card networks, and our vendors or service providers.

We share personal information with the following categories of recipients:

We may also share your personal information, including contact information and transaction history (but not Payment Card Data), with the merchant whose program you participate in. That merchant’s use of your information is governed by their own privacy notice and applicable law. Because this sharing is necessary to provide the gift card or stored value program you enrolled in, it is not subject to an opt-out under applicable financial privacy laws.

We do not sell or share your personal information. We have not sold or shared personal information about our customers, as those terms are defined under applicable state privacy laws, in the 12 months prior to the Effective Date of this notice. If that ever changes, we will update this notice and provide an opt-out before we begin.

Except as set forth in this notice, we will not share your information unless required to do so by law, such as to comply with federal, state, or local laws or to comply with a properly issued subpoena or summons by Federal, state, or local authorities.

Except as described in this notice, we will not sell or lease the information we collect about you to unaffiliated third parties for their direct marketing of products or services unrelated to the stored value card program you enrolled in.

How Long We Keep Your Information

We retain personal information only as long as necessary for the purposes described in this notice, after which we delete or de-identify it. Because we operate a regulated financial product, several retention periods are set by law rather than by us. In general:

Where a longer period is required by law, by a legal hold, or to establish, exercise, or defend legal claims, we retain the information for that longer period. Our full retention schedule is maintained in our internal Record Retention Policy.

Keeping Your Information Secure

We are committed to keeping your information secure. To protect your information from unauthorized access and use, we use security measures designed to comply with federal and state law and meet recognized industry standards, including the Payment Card Industry Data Security Standard where it applies. This includes the use of encryption technology, tokenization of card numbers when a card is added to a digital wallet, contractual limitations on the use of your information with our service providers and subcontractors, access controls, and identity verification procedures.

Children and Teens

Our products and services are not directed to children under the age of 13. We do not knowingly solicit or collect Personal Information from children under the age 13. If we discover or have reason to believe that a user is under the age of 13, we will promptly delete their Personal Information and deny or terminate access to our products and services. If you are a parent or guardian of a child under the age of 13 and become aware that he or she disclosed Personal Information to us, please contact us at privacy@gftpay.com. For more information about the Children’s Online Privacy Protection Act, visit the Federal Trade Commission’s website at https://www.ftc.gov/.

We do not sell or share the personal information of consumers we know to be under 16 years of age. Where applicable law requires opt-in consent before selling or sharing the personal information of a minor, we do not do so unless that consent has been given.

Mobile App and Device Permissions

Our mobile application may ask your permission to access features on your device that a function you are using needs, such as the camera to scan a code, or notifications so we can alert you about your account. Your device will prompt you before access is granted, you may decline, and you can change your choice at any time in your device settings. If we add a feature that needs a permission we do not request today, your device will ask you at that point and we will update this notice.

International Users

Our services are designed primarily for U.S. users, but may be accessed abroad. By using the services outside the U.S. you consent to your data being processed and stored in the United States.

Your Privacy Rights

Depending on where you live, you may have some or all of the following rights in relation to personal information we hold about you. These rights are not absolute, and they do not apply to information that is exempt, including information subject to GLBA and information we are required to retain by law.

How to Exercise Your Rights

You may submit a request in any of the following ways:

Verification. Before we act on a request, we need to verify that the request comes from you. We will generally do this by confirming information you have already given us, such as your verified mobile number or email address, and by sending a one-time code. For requests seeking specific pieces of personal information, we may require additional verification. We will not create or retain personal information solely to verify a request beyond what is necessary.

Authorized agents. You may use an authorized agent to submit a request on your behalf. We will ask the agent for written permission signed by you, and we may ask you to verify your own identity directly with us or to confirm that you gave the agent permission. An agent acting under a valid power of attorney does not need to provide separate written permission.

Timing. We will confirm receipt of your request within ten business days and respond within forty-five calendar days. If we need more time, we will tell you why and how much longer we need, up to a further forty-five days.

Appeals. If we decline your request, you may appeal by replying to our response or by writing to privacy@gftpay.com with “Privacy Appeal” in the subject line. We will review the appeal and respond in writing within forty-five days, and if we deny the appeal we will tell you how to contact your state attorney general to submit a complaint.

IMPORTANT PRIVACY INFORMATION FOR CALIFORNIA RESIDENTS

GFT provides the following disclosures in accordance with applicable California privacy laws. California’s “Shine the Light” Law, California Civil Code Section 1798.83, permits you to request and obtain from us once a year, free of charge, a list of all third parties to which we have disclosed personally identifiable information as defined under California law for such third parties’ direct marketing purposes in the preceding calendar year. If you are a California resident and would like to make such a request, see the Contact Information section below.

The California Consumer Privacy Act, as amended (“CCPA”), grants you specific rights in regard to Personal Information we have collected about you. Those rights, and how to exercise them, are described in the section on your privacy rights above. In the 12 months prior to the Effective Date of this notice, we have collected the following categories of Personal Information about our customers:

Category Examples Collected Disclosed for a business purpose
Identifiers A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers. YES YES
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. YES YES
Protected classification characteristics under California or federal law Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex, sexual orientation, veteran or military status, genetic information. NO (except where voluntarily supplied by job applicants) NO
Commercial information Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. YES YES
Biometric information Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier, such as fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. NO. GFT does not collect or store biometric identifiers. Where identity verification requires it, processing is performed by a third-party vendor and not by GFT. NO
Internet or other similar network activity Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement. YES YES
Geolocation data Physical location or movements. YES. Approximate location derived from IP address only. We do not collect precise device location. YES
Sensory data Audio, electronic, visual, thermal, olfactory, or similar information. NO NO
Professional or employment-related information Current or past job history or performance evaluations. NO (except job applicants) NO
Non-public education information (per the Family Educational Rights and Privacy Act) Education records directly related to a student maintained by an educational institution or party acting on its behalf. NO NO
Inferences drawn from other personal information Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. NO NO
Sensitive personal information Social Security number, driver’s license or state identification card number, and account log-in or financial account number in combination with any required security code or credential. We do not collect precise geolocation. YES YES

Sensitive Personal Information

We collect sensitive personal information only to provide the Services you have requested, to verify your identity, to prevent fraud and other unlawful activity, and to meet our legal obligations. We do not use or disclose sensitive personal information for the purpose of inferring characteristics about you, and we do not use it for advertising. Because our use is limited to purposes that applicable law permits without a right to limit, the right to limit the use of sensitive personal information does not currently change how we handle it. You may still submit a request and we will confirm how your information is used.

Sale, Sharing, Retention, and Deletion

GFT does not sell or share Personal Information about our customers and has not done so in the 12 months prior to the Effective Date of this notice. Our retention periods are set out in the section on how long we keep your information. Your rights to access, correct, delete, and receive a copy of your Personal Information, and how to exercise them, are set out in the section on your privacy rights.

Other State Privacy Rights

A number of states other than California have comprehensive privacy laws that give their residents rights similar to those described in the section on your privacy rights above, including rights to access, correct, delete, and obtain a copy of personal information, to opt out of targeted advertising and the sale of personal information, and to appeal a decision we make on a request. We apply the rights described in this notice to residents of every state that provides them, and we use the same request and appeal process for all of them. Where a state law gives you a right that this notice does not describe, that right still applies and you may exercise it using the contact methods below. Nevada residents may separately direct us not to sell certain covered information by emailing privacy@gftpay.com.

SMS and RCS Messaging

GFT collects and uses your mobile phone number and messaging preferences solely to deliver SMS and RCS messages that you have explicitly opted in to receive. We do not sell, share, rent, or disclose SMS or RCS opt-in data, phone numbers, or consent information to third parties for their own marketing or independent purposes, and we do not disclose that data to merchants for their own marketing. This data may be shared only with service providers and technology partners who assist in delivering messages on our behalf, and only as necessary to operate the messaging program.

The message categories we send, and how to stop them, are set out in our Terms of Use.

Changes to this Privacy Notice

We may make changes to this Privacy Notice at any time. When we do, we will update the Effective Date and, where required by applicable law, provide advance notice before the change takes effect. If we intend to use personal information we have already collected for a purpose that is materially different from the purpose described when we collected it, we will notify you and obtain your consent where applicable law requires it. Please revisit this notice to ensure you understand how we collect and use your information.

Contact Information

If you have any questions or comments about this notice, the ways in which we collect and use your personal information, your choices and rights regarding our use of personal information, or wish to exercise your privacy rights, please contact us: