Privacy Policy
Effective April 27, 2026
HAMILTON ROCK PRIVACY POLICY
Last Updated: March 4th 2026
Hamilton Rock Financial Services Corp (“Hamilton Rock”, “we”, “us”, or “our”) is committed to protecting the privacy and security of information we collect about visitors to our websites, applicants, and customers who use our financial products and services. This Privacy Policy explains how we collect, use, share, and protect “Personal Information” and other data when you interact with us online or through our products, and describes your choices and rights.
By accessing or using our websites, applying for or using our accounts, cards, or services, or otherwise communicating with us, you agree to this Privacy Policy.
1. Who We Are and Scope of This Policy
Hamilton Rock Financial Services Corp is a Delaware corporation with its
principal business address at:
447 Broadway, 2nd Floor, Suite #3266, New York, New York 10013, United
States.
-
Legal name: Hamilton Rock Financial Services Corp
-
Entity type: Delaware C‑Corp
-
EIN: 30‑1473250
-
Telephone: +1 (516) 336‑4214
-
Email for privacy inquiries: legal@hamiltonrock.com
This Privacy Policy applies to:
-
Our public websites, domains, and pages that link to this Privacy Policy.
-
Our online and mobile interfaces, dashboards, and applications.
-
Your interactions with us relating to Hamilton Rock accounts, cards, payments, rewards, and related services, to the extent not covered by a separate GLBA “Consumer Financial Privacy Notice.”
If you obtain a product intended primarily for personal, family, or household purposes, our separate GLBA Consumer Financial Privacy Notice will describe how we collect, use, and share Nonpublic Personal Information (NPI) in that consumer‑finance context, as required by the Gramm–Leach–Bliley Act and Regulation P.
2. Key Definitions
For purposes of this Privacy Policy:
-
Personal Information means information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household, such as name, contact details, identifiers, financial account information, and certain online identifiers.
-
Nonpublic Personal Information (NPI) means personally identifiable financial information plus any list or grouping of consumers derived from such information that is not publicly available, as defined by GLBA and Regulation P.
-
Services means our websites, dashboards, mobile apps, accounts, cards, rewards, analytics, and related products and services.
-
Affiliates means entities under common control with Hamilton Rock.
-
Service Providers means third‑party companies that process data on our behalf (for example, cloud hosting, KYC vendors, payment processors, fraud and risk tools).
-
Business Partners means sponsor banks, card networks, BaaS platforms, and other partners we work with to provide the Services.
3. Information We Collect
We collect information about you in different ways depending on how you interact with us and our Services.
3.1 Information You Provide Directly
We may collect the following categories of Personal Information that you provide:
-
Contact information – Name, business name, email address, mailing address, phone number.
-
Identity and KYC/KYB information – Date of birth, government identifiers (such as SSN or EIN), government‑issued ID images, beneficial ownership information, business registration documents, signatures.
-
Financial and transactional information – Bank account details, payment card details, account credentials required to link external accounts (tokenised or via third‑party aggregators), transaction descriptions, invoices, payout instructions.
-
Business information – Business name, industry, product details, revenue and transaction volumes, tax information, ownership structure.
-
Communications and support – Information you provide when you contact us, respond to surveys, participate in research, or provide feedback.
-
Marketing and preference information – Your preferences for communications, marketing, and product updates.
3.2 Information We Collect Automatically
When you use our websites or apps, we automatically collect certain information, which may be Personal Information or Usage Data:
-
Device and usage information – IP address, browser type, device identifiers, operating system details, referring URLs, pages viewed, time and date of visits, clickstream data, and other diagnostic data.
-
Log and event information – Login attempts, API calls, error reports, security events.
-
Location information – Approximate location based on IP address; in some cases, more precise location if you grant permission in a mobile app.
-
Cookies and similar technologies – Cookies, web beacons, pixels, SDKs, and similar tools that help us recognise you, remember settings, analyse usage, and serve relevant content.
For more detail, see Section 6 (Cookies and Tracking Technologies).
3.3 Information From Third Parties
We may collect information about you and your business from third‑party sources:
-
Sponsor banks and BaaS partners – Account and transaction data necessary to provide the Services and meet regulatory obligations.
-
Identity verification and fraud‑prevention providers – Data used to verify identity, detect fraud, assess risk, and comply with KYC, AML, and sanctions obligations.
-
Credit and risk assessment sources – Business or consumer credit reports and risk scores, where permitted by law and relevant to the Services.
-
Payment networks and processors – Card and payment‑related data to enable and reconcile transactions.
-
Marketing and referral partners – Contact and interest information when you interact with our partners or sponsored content.
-
Public sources – Public company registers, regulatory filings, websites, and other publicly available sources.
4. How We Use Your Information
We use Personal Information and other data for purposes that are not prohibited by law and are consistent with this Privacy Policy. These purposes include:
-
Providing and operating the Services – Opening and servicing accounts, processing transactions, providing dashboards, issuing cards, and supporting rewards and analytics.
-
Identity verification, compliance, and risk management – Verifying identity and business information, performing KYC/KYB checks, screening against sanctions lists, detecting and preventing fraud, enforcing our terms, and complying with legal and regulatory obligations.
-
Customer support and communications – Responding to inquiries, providing technical support, sending service‑related notices (such as changes to terms, security alerts, and operational updates).
-
Product improvement and research – Analysing usage, performance, and feedback to improve existing features, develop new products, and conduct internal research.
-
Marketing and promotions – Sending information about new or existing products, features, events, and promotions, consistent with your preferences and applicable law.
-
Personalisation and analytics – Customising content and experiences, and performing analytics to understand usage patterns and trends.
-
Security and integrity – Protecting accounts and systems, monitoring for suspicious or unauthorised activity, and maintaining the safety and integrity of the Services.
-
Corporate transactions – Supporting evaluations or completion of mergers, acquisitions, financings, or other corporate transactions where customer information may be transferred as a business asset.
-
Legal and regulatory purposes – Complying with applicable laws, responding to lawful requests and legal process, and asserting or defending legal claims.
We may create de‑identified, aggregated, or anonymised information that cannot reasonably be used to identify you, and we may use and share such information for any lawful purpose.
5. How We Share Your Information
We do not sell your Personal Information in the traditional sense, but we do share information in the following circumstances, as permitted by law and consistent with this Privacy Policy.
5.1 Service Providers
We share information with Service Providers who perform services on our behalf, such as:
-
Cloud hosting, infrastructure, and data storage.
-
Identity verification, KYC/KYB, fraud and risk management.
-
Payment processing, card issuing, and banking operations.
-
Customer support, communication tools, analytics, and marketing support.
These Service Providers are contractually required to use Personal Information only to provide services to us and to protect it consistent with this Privacy Policy and applicable law.
5.2 Sponsor Banks, Payment Networks, and Financial Partners
We share data with our sponsor banks, BaaS platforms, payment networks, and other regulated financial partners as necessary to:
-
Open and manage accounts and cards.
-
Process payments and transfers.
-
Conduct compliance, risk, and reporting obligations to regulators.
These partners may have their own privacy notices that apply to their use of Personal Information in addition to this Privacy Policy.
5.3 Affiliates and Business Partners
We may share information with our Affiliates and Business Partners to:
-
Support delivery of the Services.
-
Offer additional or integrated products.
-
Operate joint marketing, referral, or partnership programs.
Where required by law, you may have the right to limit certain sharing, which will be described in our GLBA Consumer Financial Privacy Notice or state‑specific sections.
5.4 Legal, Regulatory, and Safety Purposes
We may disclose information:
-
To comply with applicable law or legal process.
-
To respond to requests from regulators, law‑enforcement, or government authorities.
-
To enforce our agreements, protect our rights, property, or safety, or that of our users, partners, or the public.
5.5 Corporate Transactions
We may share information in connection with or during negotiation of any merger, sale of assets, financing, acquisition, restructuring, or similar corporate transaction where Personal Information may be transferred as part of the business.
5.6 With Your Consent
We may share information with third parties when you authorise or direct us to do so, such as when you connect your account to third‑party applications, accounting tools, e‑commerce platforms, or other services.
6. Cookies and Tracking Technologies
We and our third‑party partners use cookies and similar technologies to collect and store certain information when you use our websites, dashboards, emails, and Services.
6.1 Types of Cookies and Technologies
-
Essential cookies – Necessary to operate the Services, enable security, and allow you to log in and use key features.
-
Functional cookies – Remember your preferences (for example, language, settings) and help provide a more personalised experience.
-
Analytics cookies – Help us understand how visitors interact with our websites and apps, so we can measure and improve performance.
-
Advertising and tracking cookies – Used by us or our partners to deliver relevant content and measure the effectiveness of campaigns, which may constitute “sale” or “sharing” of Personal Information under some state privacy laws.
-
Web beacons / pixels / SDKs – Small code or image elements used in websites and emails to understand engagement and support analytics and security.
6.2 Your Choices About Cookies
Depending on your browser or device, you may be able to:
-
Block or delete cookies through browser settings.
-
Limit interest‑based advertising via platform settings or industry tools (for example, Network Advertising Initiative or Digital Advertising Alliance resources).
If you block certain cookies, the Services may not function properly.
At this time, our Services do not respond to browser “Do Not Track” signals.
7. Data Retention
We retain Personal Information for as long as necessary to:
-
Provide the Services and maintain your relationship with us.
-
Meet legal, regulatory, accounting, and reporting requirements (including GLBA, BSA/AML, tax, and recordkeeping obligations).
-
Resolve disputes, enforce our agreements, and protect against fraud or abuse.
Even after you close your account or stop using the Services, we may retain certain information as required by law and for legitimate business purposes.
8. Security
We use a combination of administrative, technical, and physical safeguards designed to protect Personal Information against loss, theft, misuse, unauthorised access, disclosure, alteration, and destruction.
Measures may include:
-
Encryption in transit and at rest where appropriate.
-
Access controls, authentication, and logging.
-
Network security measures such as firewalls and intrusion detection.
-
Vendor due‑diligence and contractual security requirements.
No system can be guaranteed to be completely secure, but we design our controls to meet or exceed applicable regulatory expectations for financial institutions. If we are required by law to notify you of a security breach affecting your Personal Information, we will do so in the manner and within the timeframes required by applicable law.
9. Your Choices and Rights
Your privacy rights depend on where you live and how you interact with us. Subject to applicable law, you may have the following rights:
-
Access / Right to know – Request information about our collection, use, and disclosure of your Personal Information, including categories and specific pieces of information.
-
Correction – Request correction of inaccurate or incomplete Personal Information we hold about you.
-
Deletion – Request deletion of certain Personal Information, subject to legal and business‑need exceptions (for example, required retention for AML or tax).
-
Restriction / Objection – In some cases, object to or request restriction of processing, particularly for marketing or profiling.
-
Data portability – Request a copy of certain Personal Information in a portable format, where required by law.
-
Opt‑out of marketing – Opt out of promotional emails by using the unsubscribe link, or by contacting us; we may still send non‑marketing communications (for example, service, security, or legal notices).
-
Opt‑out of certain sharing / “sale” – In certain states, opt out of “sale” or “sharing” of Personal Information for targeted advertising, as defined by state privacy laws.
-
Non‑discrimination – You have the right not to be discriminated against for exercising your privacy rights.
To exercise these rights, you may contact us at legal@hamiltonrock.com or by using any self‑service tools we make available in your dashboard. We may need to verify your identity before responding to your request, which may require you to provide certain information or log in to your account.
You may be able to designate an authorised agent to make certain requests on your behalf where permitted by law; we may require proof of authorisation and may still require direct verification of your identity, consistent with applicable rules.
We may deny or limit requests where we are permitted or required to do so by law, including where requests are excessive, unfounded, or conflict with legal obligations.
10. California and Other State‑Specific Privacy Rights
If you are a resident of California or certain other U.S. states, you may have additional privacy rights under state law.
10.1 GLBA and State Privacy Laws
Some information we collect is Nonpublic Personal Information subject to GLBA and Regulation P, which may be exempt from certain state privacy law obligations. However, not all information we collect is covered by GLBA, and the exemptions are not complete.
For this reason, we may provide state‑specific disclosures and rights for Personal Information that falls outside GLBA’s scope, such as website usage information, marketing data, and other non‑GLBA information.
10.2 California (CCPA/CPRA) and Similar Laws
If you are a resident of California (or another state with a comprehensive privacy law), you may have rights to:
-
Know the categories and specific pieces of Personal Information we collect, use, disclose, and, where applicable, “sell” or “share.”
-
Request deletion or correction of certain Personal Information.
-
Opt out of “sale” or “sharing” of Personal Information for cross‑context behavioural advertising.
-
Limit the use of sensitive Personal Information where required.
-
Be free from discrimination for exercising your rights.
We may describe, in a separate state‑specific notice or in an appendix, the categories of Personal Information collected, sources, purposes, and categories of recipients, consistent with CCPA/CPRA‑style tables used by other financial technology companies.
To exercise your state‑specific rights, contact us at legal@hamiltonrock.com and indicate your state of residence and the right you wish to exercise. We will respond consistent with applicable law.
11. Children’s Privacy
Our Services are not directed to children, and we do not knowingly collect Personal Information from anyone under the age of 13 (or 16 where required by law).
If we learn that we have collected Personal Information from a child in violation of applicable law, we will delete that information and take appropriate steps to remediate.
12. International Users and Data Transfers
Our Services are primarily intended for businesses operating in the United States. If you access the Services from outside the U.S., you understand that your information may be transferred to, stored in, and processed in the United States or other jurisdictions that may not have equivalent data protection laws.
When required by law, we will implement appropriate safeguards (such as contractual protections) for cross‑border transfers.
13. Third‑Party Services, Links, and Data Access
Our Services may contain links to third‑party websites, applications, and services that we do not control.
-
Their privacy practices are governed by their own policies, not this Privacy Policy.
-
When you connect your Hamilton Rock account to third‑party apps (for example, accounting tools, e‑commerce platforms, or budgeting apps), you authorise us to share certain data with those services and for them to receive data as described in their terms.
We encourage you to review the privacy policies and terms of any third‑party services you use.
14. Open Banking and Data Access (Section 1033)
As open‑banking frameworks and the CFPB’s Section 1033 rule evolve, you may have rights to access and port certain financial data to authorised third parties.
-
When you authorise a third‑party app to access your Hamilton Rock account, we or our partners may provide that app with access tokens or data via secure APIs.
-
We expect such third parties to protect your data in line with their own privacy and security obligations, but we do not control how they use or secure your data once you have authorised access.
We will update this section and related disclosures as applicable regulations and industry standards develop.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, Services, or applicable laws.
-
We will update the “Last Updated” date at the top of this page when we make changes.
-
For material changes, we may provide additional notice (for example, via email or in‑app notification) as required by law.
Your continued use of the Services after a revised Privacy Policy becomes effective means that you accept the changes.
16. Contacting Hamilton Rock
If you have questions, requests, or complaints regarding this Privacy Policy or our privacy practices, you may contact us at:
Hamilton Rock Financial Services Corp
447 Broadway, 2nd Floor, Suite #3266
New York, New York 10013
United States
Email: legal@hamiltonrock.com
Telephone: +1 (516) 336‑4214