Last updated: August 27, 2026 · Effective: August 27, 2026
This Privacy Policy describes how Accredited Interchange collects, uses, shares, and protects information in connection with our payment processing, payroll, commercial insurance, and related services. By using our services, you agree to the collection and use of information as described in this policy.
Accredited Interchange ("Company," "we," "us," or "our") is a financial services company providing payment processing, payroll administration, and commercial insurance services to businesses across the United States. We are the data controller for personal information collected in connection with our business services.
We collect information in the following categories depending on the services you use:
For payroll clients, we collect employee names, addresses, Social Security Numbers, dates of birth, compensation and benefits information, banking information for direct deposit, and tax withholding elections.
We may receive information about you from credit bureaus, identity verification services, fraud prevention databases, banking partners, card networks, and other third parties as part of our underwriting, compliance, and fraud prevention processes.
| Purpose | Types of Information Used |
|---|---|
| Underwriting and account setup | Business, owner, and financial information |
| Processing transactions and settling funds | Transaction data, banking information |
| Fraud prevention and risk management | Transaction data, device data, third-party risk data |
| Chargeback and dispute management | Transaction data, cardholder data, communication records |
| Payroll processing and tax filing | Employee and payroll data |
| Insurance placement and servicing | Business and owner information |
| Regulatory compliance and reporting | Business, transaction, and identity data |
| Account management and customer support | Account and communication data |
| Improving our services and website | Website usage data, aggregated analytics |
| Marketing and service updates | Contact information (you may opt out) |
We process your information on the following legal bases: performance of a contract with you; compliance with legal obligations; our legitimate business interests (fraud prevention, service improvement, risk management); and, where required, your consent.
We do not sell your personal information. We share information only as described below:
We share transaction and merchant information with our acquiring bank(s), card networks (Visa, Mastercard, American Express, Discover), and payment processors as necessary to facilitate payment services. These parties have their own privacy practices and are subject to their own regulatory requirements.
We engage third-party vendors who assist us in providing services, including technology providers, cloud infrastructure, identity verification, fraud prevention, and customer support tools. These providers are contractually required to use your information only to provide services to us and to maintain appropriate security measures.
For insurance services, we share necessary information with underwriting carriers and reinsurers to facilitate coverage, policy issuance, and claims handling.
We may disclose information when required by law, court order, or government authority; to comply with card network rules or banking regulations; to enforce our Terms of Service; or to protect the safety and security of our clients, our company, or the public.
In the event of a merger, acquisition, or sale of all or substantially all of our assets, information we hold may be transferred to the acquiring entity, subject to the same privacy commitments described in this policy.
We handle payment card data in compliance with the Payment Card Industry Data Security Standard (PCI DSS). We do not store full primary account numbers (PANs), card verification values (CVV/CVC), or magnetic stripe data after authorization. Where card data must be retained, it is encrypted and access-controlled in accordance with PCI DSS requirements.
As a merchant using our services, you are also responsible for PCI DSS compliance within your own systems and for protecting cardholder data at the point of sale and in your own records.
We retain information for as long as necessary to provide our services, comply with legal and regulatory obligations, resolve disputes, enforce agreements, and for legitimate business purposes. Specific retention periods include:
When information is no longer needed, we securely delete or de-identify it in accordance with our data retention schedule.
We implement administrative, technical, and physical safeguards designed to protect the information we hold against unauthorized access, disclosure, alteration, and destruction. These measures include encryption of data in transit and at rest, access controls and multi-factor authentication, network security monitoring, and regular security assessments.
No method of electronic storage or transmission is completely secure. While we strive to protect your information, we cannot guarantee absolute security. If you believe your information has been compromised, please contact us immediately at (480) 823-2929.
In the event of a data breach that triggers notification obligations under applicable law, we will notify affected parties in accordance with those requirements.
You may request access to the personal information we hold about you or your business and request correction of inaccurate information. We will respond to verifiable requests within the timeframe required by applicable law.
You may request deletion of your personal information. Please note that we may be required to retain certain information for legal, regulatory, and contractual compliance purposes even after a deletion request. Information necessary for fraud prevention, dispute resolution, or legal proceedings may also be retained.
You may opt out of marketing emails by clicking the unsubscribe link in any marketing message or by contacting us directly. Please note that you will continue to receive service-related communications even if you opt out of marketing.
To exercise any of the rights described in this section, contact us at (480) 823-2929. We will verify your identity before processing requests to protect against unauthorized disclosure.
California residents have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), to the extent those laws apply to our processing of your information.
In the preceding 12 months, we have collected personal information in the categories described in Section 2 of this policy, including identifiers, financial information, commercial information, professional and employment information, and internet or other electronic network activity information.
You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business purposes for collecting it, and the categories of third parties with whom it has been shared.
You have the right to request deletion of personal information we have collected, subject to certain exceptions for legal compliance, fraud prevention, and other legitimate purposes.
You have the right to request correction of inaccurate personal information we maintain about you.
We will not discriminate against you for exercising any of your CCPA/CPRA rights.
We do not sell personal information or share it for cross-context behavioral advertising. You therefore do not need to submit an opt-out request for these purposes.
California residents may submit requests to know, delete, or correct by contacting us at (480) 823-2929. We will respond to verifiable consumer requests within 45 days, with a possible extension of an additional 45 days where reasonably necessary.
Our website uses cookies and similar tracking technologies to enhance your experience and gather analytics. We use the following types of cookies:
You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of our website. We honor browser-based Do Not Track signals to the extent practicable.
We do not use cookies or tracking technologies to build profiles for targeted advertising on third-party platforms.
Our website may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party sites, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.
Our services integrate with third-party platforms such as Shopify and other eCommerce systems. Data shared with those platforms in connection with payment processing is governed by those platforms' own terms and privacy policies.
Our services are intended for businesses and are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us immediately and we will take steps to delete the information.
We may update this Privacy Policy from time to time. We will post any changes on this page and update the "Last Updated" date at the top. For material changes, we will provide additional notice as required by applicable law or as we deem appropriate, which may include email notification to active clients.
Your continued use of our services after changes are posted constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Accredited Interchange
Phone: (480) 823-2929
Website: accreditedinterchange.com
For formal privacy requests (access, deletion, correction), please state the nature of your request and include sufficient information to verify your identity. We will respond within the timeframe required by applicable law.