Effective Date: February 4th, 2026

Privacy Policy

This Privacy Policy explains how PalmFinance, Inc., together with its affiliates and its subsidiaries (“Palm,” “we,” “us,” and “our”), collects, uses, and shares information about you. This Policy applies to everyone who visits our websites that link to this Privacy Policy, as well as those who access or use our products, services, APIs, and mobile applications (the “Services”). By using or accessing our Services in any manner, you acknowledge that you accept the practices and policies outlined below, and you hereby consent that we will collect, use and disclose your information as described in this Privacy Policy. 

Your use of Palm’s Services is at all times governed by our Terms of Use and, where applicable, our Developer Terms, Master Services Agreement (“MSA”), policies, order forms, rules, and other applicable terms or conditions (collectively referred to as “Additional Terms”), which incorporate this Privacy Policy by reference. As described in the Terms of Use, we obtain certain rights in Member Data (as defined therein). Capitalized terms used but not defined in this Policy have the meanings assigned to them in the Terms of Use or the applicable Additional Terms. 

We may update this Privacy Policy at any time, in our sole discretion, to reflect changes in our practices, technologies, legal requirements, or other factors. We will determine, in our discretion, whether and how to provide notice of any updates, including by posting the revised Policy on our website. Any updates will be effective when posted, unless otherwise stated. Your continued access to or use of the Service after the effective date of any update constitutes your acceptance of the revised Privacy Policy.

Table of Contents

1. What this Privacy Policy Covers2. Personal Data
Categories of Personal Data We Collect
Our Commercial or Business Purposes for Collecting Personal Data
Other Permitted Purposes for Processing Personal Data
Categories of Sources of Personal Data
3. How We Disclose Your Personal Data4. Tracking Tools, Advertising and Opt-Out5. Data Security6. Your Rights and Choices7. Personal Data of Children8. Exercising Your Rights under the State Privacy Laws9. Other State Law Privacy Rights
10. Contact Information

What this Privacy Policy Covers

This Privacy Policy describes how we collect, use, and otherwise process Personal Data when you access or use our Services. For purposes of this Privacy Policy, “Personal Data” means any information that identifies, relates to, describes, or could reasonably be linked to an identified or identifiable individual, including information referred to as “personally identifiable information,” “personal information,” or “sensitive personal information” under applicable data protection laws, rules, or regulations. This Privacy Policy does not apply to the practices of companies that we do not own or control, or to individuals that we do not manage.

Depending on the context in which Personal Data is processed, Palm may act as a “business,” and/or “service provider,” as those terms are defined under applicable privacy laws. In particular, when Palm processes Member Data on behalf of a business customer in connection with the Services, Palm acts as a service provider (or processor) and processes such data solely to provide the Services, in accordance with the applicable customer agreement and applicable law.

Personal Data

Categories of Personal Data We Collect

In connection with our Services, we collect Member Personal Data, as outlined in further detail below.

Member Personal Data and Notice at Collection: The following chart details the categories of Member Personal Data that we collect and have collected over the past 12 months. As explained in our Terms, Member Data includes Personal Data that: (1) you affirmatively authorize Palm to access, obtain or view in any format, through the Services or otherwise (including any data or information made available to us through your use of or connection to Third Party Services); (2) you upload, share, store, or otherwise provide through the Services; (3) is publicly available about you (or the entity you represent) or your end users; (4) is provided or made available by or on behalf of third-party users of Palm’s services (e.g., users of Palm’s Developer APIs); or (5) is accessed via a third party or system, such as a government agency or insurance carrier, about you or your end users through the combined use of information that is publicly available and any data or other information that you have provided to us. For clarity, Member Personal Data refers to Personal Data processed by Palm on behalf of a business customer in connection with the Services. Personal Data collected directly from individuals outside of a business-customer relationship, such as website visitors or prospective customers (hereinafter referred to as “Consumer Personal Data”), is not Member Personal Data and is processed in accordance with this Privacy Policy. 

Member Personal Data - Notice at Collection

Category of Personal Data (and Examples)

Business or Commercial Purpose(s) for Collection

Categories of Third Parties With Whom We Disclose this Personal Data

Profile or Contact Data such as first and last name, account name, User ID or name, email, phone number, address, fax number, date of birth, and unique identifiers.

  • Providing, Customizing and Improving the Services
  • Marketing Communications
  • Corresponding with You
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Commercial Data such as purchase history, and consumer profiles, histories, or tendencies

  • Providing, Customizing and Improving the Services
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate

Identifiers such as social security number, employer identification number, driver’s license number, state identification card, passport number, tax ID or other government identifier

  • Providing, Customizing and Improving the Services
  • Complying with Know Your Customer (“KYC”) or Know Your Business (“KYB”) requirements; identity verification
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Payment Data such as financial account information, name of financial institution, account name, account type, last four digits of account number, payment card type, full credit card number, last 4 digits of payment card, and billing address, phone number, and email.

  • Providing, Customizing and Improving the Services
  • Corresponding with You
  • Sourcing Savings, Growth & Other Business Opportunities
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Device/IP Data such as IP address, device ID, domain server, and type of device/ operating system/ browser used to access the Services.

  • Providing, Customizing and Improving the Services
  • Marketing the Services
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Web Analytics such as web page interactions, referring webpage/source through which you accessed the Services, non-identifiable request IDs, and statistics associated with the interaction between device or browser and the Services.

  • Providing, Customizing and Improving the Services
  • Marketing Communications
  • Corresponding with You
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Sensory Data such as photos.

  • Providing, Customizing and Improving the Services
  • Marketing Communications
  • Corresponding with You
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Social Network Data such as email, phone number, user name, IP address, and device ID.

  • Providing, Customizing and Improving the Services
  • Marketing Communications
  • Corresponding with You
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Consumer Demographic Data such as age and/or date of birth, zip code, gender, race, ethnicity, citizenship status, veteran status, and sex life or sexual orientation, disability status.

  • Providing, Customizing and Improving the Services
  • Marketing Communications
  • Corresponding with You
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Professional or Employment-Related Data such as resume, job title, job history, performance evaluations, union membership, current salary or salary range.

  • Providing, Customizing and Improving the Services
  • Marketing Communications
  • Corresponding with You
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Geolocation Data such as IP-address-based location information or self-identified location information.

  • Providing, Customizing and Improving the Services
  • Marketing Communications
  • Service Providers
  • Advertising Partners
  • Analytics Partners
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Inferences Drawn From Other Personal Data Collected such as attributes, user behavior, and predispositions.

  • Providing, Customizing and Improving the Services
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Sensitive Data such as inferences reflecting racial or ethnic origin, sexual orientation, veteran status, disability status, citizenship or citizenship status.

  • Providing, Customizing and Improving the Services
  • Marketing Communications
  • Corresponding with You
  • Service Providers
  • Parties Our Members Authorize, Access, or Authenticate
  • Business Partners

Other Information such as emails, letters, texts, contracts and documents, or other communications.

    • Providing, Customizing and Improving the Services
    • Marketing Communications
    • Corresponding with You
    • Service Providers
    • Parties Our Members Authorize, Access, or Authenticate
    • Business Partners

    Consumer Personal Data - Notice at Collection

    Category of Personal Data (and Examples)

    Business or Commercial Purpose(s) for Collection

    Categories of Third Parties With Whom We Disclose this Personal Data

    Device/IP Data such as IP address, device ID, domain server, and type of device/ operating system/ browser used to access the Services.

    • Providing, Customizing and Improving the Services
    • Marketing the Services
    • Service Providers
    • Parties Our Members Authorize, Access, or Authenticate
    • Business Partners

    Web Analytics such as web page interactions, referring webpage/source through which you accessed the Services, non-identifiable request IDs, and statistics associated with the interaction between device or browser and the Services.

    • Providing, Customizing and Improving the Services
    • Marketing the Services
    • Corresponding with You
    • Service Providers
    • Parties Our Members Authorize, Access, or Authenticate
    • Business Partners

    Geolocation Data such as IP-address-based location information or self-identified location information.

    • Providing, Customizing and Improving the Services
    • Marketing the Services
    • Service Providers
    • Advertising Partners
    • Analytics Partners
    • Parties Our Members Authorize, Access, or Authenticate
    • Business Partners

    Inferences Drawn From Other Personal Data Collected such as attributes, user behavior, and predispositions.

    • Providing, Customizing and Improving the Services
    • Service Providers
    • Parties Our Members Authorize, Access, or Authenticate
    • Business Partners

    Other Information such as emails, letters, texts, contracts and documents, or other communications.

    • Providing, Customizing and Improving the Services
    • Marketing the Services
    • Corresponding with You
    • Service Providers
    • Parties Our Members Authorize, Access, or Authenticate
    • Business Partners

    Our Commercial or Business Purposes for Collecting Personal Data

    Providing, Customizing and Improving the Services:

    Marketing the Services

    Corresponding with You

    Other Permitted Purposes for Processing Personal Data

    In addition, each of the above referenced categories of Personal Data may be collected, used, and disclosed with the government, including law enforcement, or other parties to meet certain legal requirements and enforcing legal terms including: fulfilling our legal obligations under applicable law, regulation, court order or other legal process, such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities; protecting the rights, property or safety of you, Palm Finance or another party; enforcing any agreements with you; responding to claims that any posting or other content violates third-party rights; and resolving disputes.

    We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated or incompatible purposes without providing you notice or obtaining your consent.

    Categories of Sources of Personal Data

    We collect Personal Data about you from the following categories of sources:

    How We Disclose Your Personal Data

    We disclose your Personal Data to the categories of service providers and other parties listed in this section. Depending on state laws that may be applicable to you, some of these disclosures may constitute a “sale” of your Personal Data. For more information, please refer to the state-specific sections below.

    Legal Obligations

    We may disclose any Personal Data that we collect with third parties in conjunction with any of the activities set forth under “Other Permitted Purposes for Processing Personal Data” section above.

    Business Transfers

    All of your Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part).

    Data that is Not Personal Data

    We may create aggregated, de-identified or anonymized data from the Personal Data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and disclose it with third parties for our lawful business purposes, including to analyze, build and improve the Services and promote our business, provided that we will not disclose such data in a manner that could identify you.  

    Tracking Tools, Advertising, and Opt-Out

    The Services use cookies and similar technologies such as pixel tags, web beacons, clear GIFs and JavaScript (collectively, “Cookies”) to enable our servers to recognize your web browser, tell us how and when you visit and use our Services, analyze trends, learn about our user base and operate and improve our Services. Cookies are small pieces of data– usually text files – placed on your computer, tablet, phone or similar device when you use that device to access our Services. We may also supplement the information we collect from you with information received from third parties, including third parties that have placed their own Cookies on your device(s). 

    Please note that because of our use of Cookies, the Services do not support “Do Not Track” requests sent from a browser at this time.

    We use the following types of Cookies:

    You can decide whether or not to accept Cookies through your internet browser’s settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your device. If you do this, however, you may have to manually adjust some preferences every time you visit our website and some of the Services and functionalities may not work. 

    To find out more information about Cookies generally, including information about how to manage and delete Cookies, please visit http://www.allaboutcookies.org/ or https://ico.org.uk/for-the-public/online/cookies/ if you are located in the European Union.

    Session Replay Technology

    We may use analytics and session replay technologies to collect information about how users interact with the Services. These tools may record or reconstruct interaction data such as clicks, taps, mouse movements, scrolling, page navigation, and similar activity, and may capture limited text entered into form fields and are configured to limit or mask the collection of sensitive fields. We use this information to monitor and analyze usage, for security, identify and resolve customer issues, diagnose errors, understand user behavior, and improve the performance and usability of the Services. By using the Services, you acknowledge and agree that such session replay technologies may be used as described in this Privacy Policy.

    Information about Interest-Based Advertisements

    We may use Consumer Personal Data, or personal data from other individuals who interact with our websites or communications to promote our Services, including through marketing communications, analytics, and advertising activities. These activities may involve the use of cookies and similar technologies, as described in the “Tracking Tools, Advertising, and Opt-Out” section above. We do not sell or share Member Data, as those terms are defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CPRA”).

    We may serve advertisements, and also allow third-party ad networks, including third-party ad servers, ad agencies, ad technology vendors and research firms, to serve advertisements through the Services. These advertisements may be targeted to users who fit certain general profile categories or display certain preferences or behaviors (“Interest-Based Ads”). Information for Interest-Based Ads (including Personal Data) may be provided to us by you, or derived from the usage patterns of particular users on the Services and/or services of third parties. Such information may be gathered through tracking users’ activities across time and unaffiliated properties, including when you leave the Services. To accomplish this, we or our service providers may deliver Cookies, including a file (known as a “web beacon”) from an ad network to you through the Services. Web beacons allow ad networks to provide anonymized, aggregated auditing, research and reporting for us and for advertisers. Web beacons also enable ad networks to serve targeted advertisements to you when you visit other websites. Web beacons allow ad networks to view, edit or set their own Cookies on your browser, just as if you had requested a web page from their site.

    Opt-Out of Selling and Sharing Personal Information for Cross-Context Behavioral Advertising. You can request to further opt-out from sharing your personal information for these purposes by using our “Do Not Sell or Share My Personal Information” tool in the footer of our Site, by unselecting Marketing Cookies in the Cookie Banner on our Site, or by enabling the Global Privacy Control setting within the browser that you use to access our Site. Learn More at the Global Privacy Control website. Please note that your opt-out will be specific to the device and browser you use when you opt-out. We do not have actual knowledge that we have sold or shared the personal information of California residents under the age of 16.

    Chat Bot features

    Our Services provide users with Chat Bot features to get information and support. We and any third parties that support these features may access, monitor and record the information you submit to the chat, as well as your device data and usage data, to enable the chat and for the other purposes described in this Policy, including training, quality assurance, product development, service improvement and personalization purposes, and, where applicable, to fine tune and train any AI models we use to provide these features and our Services. When you use these features you are not communicating with a human.

    Data Security

    We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account. Although we work to protect the security of your account and other data that we hold in our records, please be aware that no method of transmitting data over the internet or storing data is completely secure.

    Your Rights

    Depending on where you reside, you may have certain rights regarding your personal information under applicable privacy and data protection laws. Subject to applicable law, these rights may include the right to access, correct or rectify, or delete personal information we maintain about you, as well as the right to opt out-of certain uses or disclosures of personal information. To the extent Palm acts as a service provider, we process personal information on behalf of our Members. Requests relating to such data should be directed to the applicable Member, unless otherwise required by law.

    Information

    You may have the right to obtain information about how we collect, use, and disclose personal information about you. We provide details about our personal information processing practices in this Privacy Policy, including the categories of personal information we collect, the purposes for which we use it, and the categories of third parties with whom we share it.

    Access, Correction, and Deletion

    Subject to applicable law, you may have the right to request access to the personal information we maintain about you, to correct personal information that is inaccurate or outdated, or to request deletion of personal information that is no longer necessary for a permitted purpose.

    Please note that these rights are not absolute and may be limited where permitted by law. For example, we may decline or limit a request where fulfilling it would:

    Where applicable, you may also have the right to receive a copy of certain personal information you provided to us, or to request that we transfer such information to another entity, in a structured, commonly used, and machine-readable format, subject to legal limitations.

    Where these rights apply, you will not be discriminated against for exercising them.

    Withdrawal of Consent

    Where we rely on your consent to process personal information, you may withdraw your consent at any time by contacting us or by using the opt-out mechanisms described in this Privacy Policy, subject to applicable legal or contractual restrictions.

    Please note that withdrawing consent may limit or prevent our ability to provide certain services or features, including identity verification services that require the processing of personal information to comply with legal, security, or fraud-prevention requirements.

    Please note that these rights are not absolute and may be limited or unavailable in certain circumstances. For example, where permitted by law, we may decline or limit a request where doing so is necessary to:

    Sensitive Personal Information

    Certain categories of Personal Data we collect may constitute Sensitive Personal Information (SPI) as defined under California law. We use SPI only as reasonably necessary and proportionate to provide the Services, comply with applicable legal obligations, ensure security and fraud prevention, perform identity verification and compliance checks, and for other purposes permitted by the CPRA. California residents have the right to request we limit the use and disclosure of their SPI to those purposes permitted under the CPRA. Refer to the “How to Submit a Request” section below to exercise this right.

    How to Submit a Request

    You may exercise your rights by contacting us at privacy@getpalm.com.

    Data Retention

    We retain Personal Data about you for as long as necessary to provide you with our Services or to perform our business or commercial purposes for collecting your Personal Data. When establishing a retention period for specific categories of data, we consider who we collected the data from, our need for the Personal Data, why we collected the Personal Data, and the sensitivity of the Personal Data. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.

    For example:

    Personal Data of Children

    As noted in the Terms of Use, we do not knowingly collect or solicit Personal Data from children under 13 years of age; if you are a child under the age of 13, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If we learn we have collected Personal Data from a child under 13 years of age, we will delete that information as quickly as possible. If you believe that a child under 13 years of age may have provided Personal Data to us, please contact us at privacy@getpalm.com.

    Other State Law Privacy Rights

    California Resident Rights

    Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to contact us to prevent disclosure of Personal Data to third parties for such third parties’ direct marketing purposes; in order to submit such a request, please contact us at privacy@getpalm.com.

    Nevada Resident Rights

    If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data to third parties. Please note that we do not currently sell your Personal Data as sales are defined in Nevada Revised Statutes Chapter 603A.

    Contact Information

    If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data or your choices and rights regarding such collection and use, please do not hesitate to contact us at:

    Effective as of February 4th, 2026