GFT Pay Inc.
PRIVACY POLICY
Effective Date: August 15, 2026
The Short Version
- We collect what we need to issue and service your card, deliver the messages you ask for, prevent fraud, and meet our legal obligations.
- We do not sell your personal information, and we do not use advertising trackers to follow you around the internet.
- We share information with the bank that issues your card, the payment network, the merchant whose program you are in, and the vendors who help us run the Services.
- We never receive or store your fingerprint or face scan. That verification happens on your device.
- You can access, correct, delete, or export your information, and you can change which messages you receive at any time. See Your Privacy Rights below.
The rest of this notice sets out the detail, including disclosures we are required to make under state privacy laws.
GFT Pay Inc. (“GFT,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Notice explains how we collect, use, share, and protect your personal information when you use GFT’s products and services, including our website, our web wallet, our mobile application, GFT features made available inside a merchant or partner website or application, digital payment cards, and wallet integrations (collectively, the “Services”). Please note that this Privacy Notice does not apply to websites owned and operated by third parties regardless of whether our Services are linked to them. Websites not owned or operated by us will be subject to their own privacy policies. We have no control over third-party companies or their privacy policies.
Other documents. Your use of the Services is governed by our Terms of Use, and your card account is governed by the Cardholder Terms & Conditions. Cards are issued by Florida Capital Bank, N.A. (the “Bank”), which provides its own privacy notice covering the information it holds as issuer.
Financial privacy law. Much of the information we collect in connection with your card account is subject to the federal Gramm-Leach-Bliley Act (“GLBA”), and where it is, GLBA governs and the state privacy rights described below do not apply to it. We describe our practices in one notice rather than several, so parts of this notice may describe rights that do not apply to every category of information we hold.
Types of Information We Collect
We may collect the following types of information when you use our products, services, or mobile application, or visit our websites:
- “Personal Information” is information that we may collect that identifies you as an individual, customer, or consumer and includes your name, phone number, and email address. We may also collect personal information to conduct identity verification, when required by applicable law or regulation, such as date of birth, social security number or tax identification number, driver’s license number, mailing address, government-issued photo identification, and your account number(s). Where identity verification requires the use of a third-party service provider, that provider may process your information, including photographs or biometric data, subject to their own privacy practices and contractual restrictions that limit their use of your information to identity verification purposes only.
- “Account and Transaction Information” is information about your card and how you use it, including the cards in your wallet, balances and funding sources, loads and top-ups, purchases and refunds, merchant and location information supplied by the payment network for a transaction, gifts you send or receive, and support requests you make.
- “Non-Personal Information” is information that we may collect that does not identify an individual, customer, or consumer. Examples of non-personal information are the version of internet browser, the computer or mobile device’s operating system, information from tracking technologies (e.g., “Cookies”), websites visited on the applicable device, the device’s IP address, and approximate location derived from it. Non-Personal Information is not necessarily specific to any individual, but is device-specific.
- “Payment Card Data” is information related to the payment instrument used to add funds (“load”), reload, or other transaction with GFT cards and includes card number, expiration date, and CVV. Such information is collected by payment processors, but not stored by GFT. For cards loaded via ACH directly from a bank account, bank account and routing numbers are collected by payment processors, but not stored by GFT.
Information About Other People
If you use the Services to send a gift card to someone else, you will give us that person’s contact information, such as their name, email address, or mobile phone number. We use it to deliver the gift, to let you know whether it has been claimed, and to support the recipient if they contact us. By providing another person’s contact information, you confirm that you are permitted to give it to us for this purpose. If someone sends you a gift, we hold their contact information and yours in connection with that gift, whether or not you claim it and whether or not you create an account.
Biometrics, Passkeys, and Device Authentication
GFT does not collect, capture, receive, store, or use biometric identifiers or biometric information. When you unlock your device, approve a payment in a digital wallet, or sign in with a passkey using a fingerprint, face scan, or device passcode, that verification happens on your device and is performed by your device or platform provider. GFT receives only confirmation that verification succeeded. We never receive the underlying fingerprint, face scan, or other biometric data, and we do not create or store any biometric template.
The one exception is identity verification performed by a third-party provider where required by law or program rules, as described above. In that case the provider, not GFT, processes any biometric data, under contractual restrictions limiting its use to identity verification.
How We Collect Your Information
We collect Personal Information about you when you request information about, apply for, or use our products or services, register for online or mobile account access, claim or activate a card someone has sent you, contact us for customer service, communicate with us through social media, or otherwise interact with us. We may also collect Personal Information about you from other sources, such as public databases, credit reporting agencies, social media platforms, affiliated companies, the merchant or sponsor whose program you participate in, another GFT user who sends you a gift, and other third parties.
We also collect Non-Personal Information about your online and mobile activity automatically using the following tracking technologies:
- HTTP cookies (“Cookies”) are pieces of information that are stored directly on the device you are using. Cookies provide us with anonymous online and mobile activity information such as the time of your site visits and the pages you viewed. Cookies are commonly used with internet browsers, and do not harm your computer or device. You may manage your device’s cookie settings through the settings on your device and/or browser.
- Product and error analytics. We use analytics and monitoring tools that record how the Services perform and how they are used, including pages viewed, features used, performance timings, and errors encountered. We use this to keep the Services working and to improve them.
We do not use advertising trackers. We do not use advertising cookies, pixel tags, web beacons, or mobile advertising identifiers to deliver advertising to you on other companies’ websites or apps, and we do not disclose personal information for cross-context behavioral advertising. If that changes, we will update this notice and provide the opt-out described below before we begin.
You may manage cookies and similar technologies through the settings on your device or browser.
Global Privacy Control and Other Opt-Out Preference Signals
We honor the Global Privacy Control (“GPC”) and other opt-out preference signals that applicable law requires us to recognize. If you visit our website from a browser or extension that transmits GPC, we will treat that signal as a request to opt out of any sale or sharing of personal information associated with that browser, and we will apply it to your account where we can reasonably associate the signal with an account.
Separately, the California Online Privacy Protection Act requires us to disclose how we respond to Do Not Track signals. Do Not Track is a different, older signal with no agreed meaning across the industry, and we do not respond to it. This does not affect how we treat GPC.
How We Use Collected Information
We use information we collect about you to:
- process your requests for our products or services and provide those products or services to you;
- issue, activate, and service your card, process transactions, and deliver gifts you send or receive;
- provide relevant information to you about our products and services, including, but not limited to, important changes to our policies and terms and conditions;
- send you the messages you have asked to receive, including one-time passcodes, balance updates, and other notifications you have turned on;
- make improvements to and personalize our products and services;
- communicate with you about your account(s) and transactions, including inviting you to participate in surveys, contests, and other promotions;
- detect, respond to, and protect against illegal activity, activity which may violate our business policies, or activity which may compromise our business operations or security;
- detect, respond to, and protect against fraud, security breaches, identity theft, and other risks of harm;
- maintain and service your account; respond to your requests;
- comply with applicable legal and regulatory obligations, including obligations under anti-money laundering, sanctions, and unclaimed property laws;
- honor your personal settings and communication preferences;
- enhance your online and mobile experience; and
- improve our products and services, and measure how our own marketing and communications perform.
Sharing Your Information
If you are our customer or former customer, we will share your information in order to process transactions or otherwise make the products and services operational, including sharing with the issuing bank, the payment card networks, and our vendors or service providers.
We share personal information with the following categories of recipients:
- The issuing bank, which holds the funds associated with your card and is the issuer of the card.
- Payment networks and processors, to authorize, clear, and settle transactions and to handle disputes and chargebacks.
- Digital wallet providers, when you add a card to a wallet, to provision and maintain the card in that wallet.
- Merchants and program sponsors whose programs you participate in, as described below.
- Service providers acting on our behalf, including providers of payment processing, identity and authentication services, SMS and messaging delivery, cloud hosting, analytics and error monitoring, customer support ticketing, fraud and compliance screening, and card production and fulfillment. These providers may use your information only to perform services for us.
- Professional advisors, auditors, and regulators, and other parties where necessary to comply with law or to establish, exercise, or defend legal claims.
- A successor in connection with a merger, acquisition, financing, or sale of all or part of our business, subject to this notice continuing to apply to the information transferred.
We may also share your personal information, including contact information and transaction history (but not Payment Card Data), with the merchant whose program you participate in. That merchant’s use of your information is governed by their own privacy notice and applicable law. Because this sharing is necessary to provide the gift card or stored value program you enrolled in, it is not subject to an opt-out under applicable financial privacy laws.
We do not sell or share your personal information. We have not sold or shared personal information about our customers, as those terms are defined under applicable state privacy laws, in the 12 months prior to the Effective Date of this notice. If that ever changes, we will update this notice and provide an opt-out before we begin.
Except as set forth in this notice, we will not share your information unless required to do so by law, such as to comply with federal, state, or local laws or to comply with a properly issued subpoena or summons by Federal, state, or local authorities.
Except as described in this notice, we will not sell or lease the information we collect about you to unaffiliated third parties for their direct marketing of products or services unrelated to the stored value card program you enrolled in.
How Long We Keep Your Information
We retain personal information only as long as necessary for the purposes described in this notice, after which we delete or de-identify it. Because we operate a regulated financial product, several retention periods are set by law rather than by us. In general:
- Account, identity, and transaction records: the life of the account and then at least five years, as required by anti-money laundering recordkeeping rules.
- Dispute and error resolution records: at least two years from the date we notify you of our findings, as required under Regulation E, and longer while a claim is open.
- Communications consent records: as long as you hold an account and at least four years afterwards.
- Analytics and support records: shorter cycles set in the relevant tools, generally no longer than twenty-four months in identifiable form.
- Unclaimed balances: as required by applicable unclaimed property law, which may require records to be kept after funds are remitted to a state.
Where a longer period is required by law, by a legal hold, or to establish, exercise, or defend legal claims, we retain the information for that longer period. Our full retention schedule is maintained in our internal Record Retention Policy.
Keeping Your Information Secure
We are committed to keeping your information secure. To protect your information from unauthorized access and use, we use security measures designed to comply with federal and state law and meet recognized industry standards, including the Payment Card Industry Data Security Standard where it applies. This includes the use of encryption technology, tokenization of card numbers when a card is added to a digital wallet, contractual limitations on the use of your information with our service providers and subcontractors, access controls, and identity verification procedures.
Children and Teens
Our products and services are not directed to children under the age of 13. We do not knowingly solicit or collect Personal Information from children under the age 13. If we discover or have reason to believe that a user is under the age of 13, we will promptly delete their Personal Information and deny or terminate access to our products and services. If you are a parent or guardian of a child under the age of 13 and become aware that he or she disclosed Personal Information to us, please contact us at privacy@gftpay.com. For more information about the Children’s Online Privacy Protection Act, visit the Federal Trade Commission’s website at https://www.ftc.gov/.
We do not sell or share the personal information of consumers we know to be under 16 years of age. Where applicable law requires opt-in consent before selling or sharing the personal information of a minor, we do not do so unless that consent has been given.
Mobile App and Device Permissions
Our mobile application may ask your permission to access features on your device that a function you are using needs, such as the camera to scan a code, or notifications so we can alert you about your account. Your device will prompt you before access is granted, you may decline, and you can change your choice at any time in your device settings. If we add a feature that needs a permission we do not request today, your device will ask you at that point and we will update this notice.
International Users
Our services are designed primarily for U.S. users, but may be accessed abroad. By using the services outside the U.S. you consent to your data being processed and stored in the United States.
Your Privacy Rights
Depending on where you live, you may have some or all of the following rights in relation to personal information we hold about you. These rights are not absolute, and they do not apply to information that is exempt, including information subject to GLBA and information we are required to retain by law.
- Know and access. Request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of recipients.
- Correct. Request that we correct inaccurate personal information we hold about you.
- Delete. Request that we delete personal information we collected from you, subject to exceptions including our legal recordkeeping obligations.
- Portability. Receive a copy of personal information you provided to us in a portable format.
- Opt out of sale, sharing, and targeted advertising. Direct us not to sell or share your personal information or use it for targeted advertising.
- Limit use of sensitive personal information. Direct us to limit the use and disclosure of sensitive personal information to what is necessary to provide the Services.
- Opt out of profiling. Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. We do not currently engage in profiling of that kind.
- Non-discrimination. Exercise these rights without being denied goods or services, charged a different price, or given a different level of service.
How to Exercise Your Rights
You may submit a request in any of the following ways:
- Email privacy@gftpay.com;
- Call (877) GFT-PAY1 / (877) 438-7291; or
- Submit a request through our Help Center at gftpay.freshdesk.com.
Verification. Before we act on a request, we need to verify that the request comes from you. We will generally do this by confirming information you have already given us, such as your verified mobile number or email address, and by sending a one-time code. For requests seeking specific pieces of personal information, we may require additional verification. We will not create or retain personal information solely to verify a request beyond what is necessary.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We will ask the agent for written permission signed by you, and we may ask you to verify your own identity directly with us or to confirm that you gave the agent permission. An agent acting under a valid power of attorney does not need to provide separate written permission.
Timing. We will confirm receipt of your request within ten business days and respond within forty-five calendar days. If we need more time, we will tell you why and how much longer we need, up to a further forty-five days.
Appeals. If we decline your request, you may appeal by replying to our response or by writing to privacy@gftpay.com with “Privacy Appeal” in the subject line. We will review the appeal and respond in writing within forty-five days, and if we deny the appeal we will tell you how to contact your state attorney general to submit a complaint.
IMPORTANT PRIVACY INFORMATION FOR CALIFORNIA RESIDENTS
GFT provides the following disclosures in accordance with applicable California privacy laws. California’s “Shine the Light” Law, California Civil Code Section 1798.83, permits you to request and obtain from us once a year, free of charge, a list of all third parties to which we have disclosed personally identifiable information as defined under California law for such third parties’ direct marketing purposes in the preceding calendar year. If you are a California resident and would like to make such a request, see the Contact Information section below.
The California Consumer Privacy Act, as amended (“CCPA”), grants you specific rights in regard to Personal Information we have collected about you. Those rights, and how to exercise them, are described in the section on your privacy rights above. In the 12 months prior to the Effective Date of this notice, we have collected the following categories of Personal Information about our customers:
| Category | Examples | Collected | Disclosed for a business purpose |
|---|---|---|---|
| Identifiers | A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers. | YES | YES |
| Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) | A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. | YES | YES |
| Protected classification characteristics under California or federal law | Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex, sexual orientation, veteran or military status, genetic information. | NO (except where voluntarily supplied by job applicants) | NO |
| Commercial information | Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | YES | YES |
| Biometric information | Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier, such as fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. | NO. GFT does not collect or store biometric identifiers. Where identity verification requires it, processing is performed by a third-party vendor and not by GFT. | NO |
| Internet or other similar network activity | Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement. | YES | YES |
| Geolocation data | Physical location or movements. | YES. Approximate location derived from IP address only. We do not collect precise device location. | YES |
| Sensory data | Audio, electronic, visual, thermal, olfactory, or similar information. | NO | NO |
| Professional or employment-related information | Current or past job history or performance evaluations. | NO (except job applicants) | NO |
| Non-public education information (per the Family Educational Rights and Privacy Act) | Education records directly related to a student maintained by an educational institution or party acting on its behalf. | NO | NO |
| Inferences drawn from other personal information | Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | NO | NO |
| Sensitive personal information | Social Security number, driver’s license or state identification card number, and account log-in or financial account number in combination with any required security code or credential. We do not collect precise geolocation. | YES | YES |
Sensitive Personal Information
We collect sensitive personal information only to provide the Services you have requested, to verify your identity, to prevent fraud and other unlawful activity, and to meet our legal obligations. We do not use or disclose sensitive personal information for the purpose of inferring characteristics about you, and we do not use it for advertising. Because our use is limited to purposes that applicable law permits without a right to limit, the right to limit the use of sensitive personal information does not currently change how we handle it. You may still submit a request and we will confirm how your information is used.
Sale, Sharing, Retention, and Deletion
GFT does not sell or share Personal Information about our customers and has not done so in the 12 months prior to the Effective Date of this notice. Our retention periods are set out in the section on how long we keep your information. Your rights to access, correct, delete, and receive a copy of your Personal Information, and how to exercise them, are set out in the section on your privacy rights.
Other State Privacy Rights
A number of states other than California have comprehensive privacy laws that give their residents rights similar to those described in the section on your privacy rights above, including rights to access, correct, delete, and obtain a copy of personal information, to opt out of targeted advertising and the sale of personal information, and to appeal a decision we make on a request. We apply the rights described in this notice to residents of every state that provides them, and we use the same request and appeal process for all of them. Where a state law gives you a right that this notice does not describe, that right still applies and you may exercise it using the contact methods below. Nevada residents may separately direct us not to sell certain covered information by emailing privacy@gftpay.com.
SMS and RCS Messaging
GFT collects and uses your mobile phone number and messaging preferences solely to deliver SMS and RCS messages that you have explicitly opted in to receive. We do not sell, share, rent, or disclose SMS or RCS opt-in data, phone numbers, or consent information to third parties for their own marketing or independent purposes, and we do not disclose that data to merchants for their own marketing. This data may be shared only with service providers and technology partners who assist in delivering messages on our behalf, and only as necessary to operate the messaging program.
The message categories we send, and how to stop them, are set out in our Terms of Use.
Changes to this Privacy Notice
We may make changes to this Privacy Notice at any time. When we do, we will update the Effective Date and, where required by applicable law, provide advance notice before the change takes effect. If we intend to use personal information we have already collected for a purpose that is materially different from the purpose described when we collected it, we will notify you and obtain your consent where applicable law requires it. Please revisit this notice to ensure you understand how we collect and use your information.
Contact Information
If you have any questions or comments about this notice, the ways in which we collect and use your personal information, your choices and rights regarding our use of personal information, or wish to exercise your privacy rights, please contact us:
- Email: privacy@gftpay.com
- Phone: (877) GFT-PAY1 / (877) 438-7291
- Help Center: gftpay.freshdesk.com
- Mail: GFT Pay Inc., Attention: Privacy, 1440 West Taylor Street, Suite 4200, Chicago, Illinois 60607