Last revised Wednesday, August 26, 2026

Privacy policy

Entity: B2 Systems, Inc., a Delaware corporation ("B2 Systems," "we," "our," or "us").

Scope: This Privacy Policy explains how B2 Systems collects, uses, discloses, retains, and protects personal information in connection with its websites, dashboards, APIs, communications, and related services (collectively, the "Platform").

The Platform is designed primarily for commercial use by businesses operating in the United States and Canada. This Policy applies to business users, website visitors, prospective customers, representatives of brokers and funders, and individuals whose information is submitted to the Platform by a customer.

This Policy is a notice of our practices and does not create contractual rights beyond applicable law. Contractual use of the Platform is governed by the B2 Systems Terms of Service and the applicable customer agreement.

1. Our Privacy Roles

1.1 Account and Website Information

B2 Systems generally determines the purposes and means of processing information concerning Platform accounts, billing contacts, prospective customers, website visitors, security, fraud prevention, product operations, and B2 Systems' direct communications.

1.2 Customer-Submitted Information

For merchant, applicant, employee, funder, broker, and other information submitted or connected by a customer ("Customer Data"), the customer generally determines why the information is processed and instructs B2 Systems how to process it. B2 Systems generally acts as a service provider or processor for that Customer Data.

Customers are responsible for providing required notices, obtaining required consents and authorizations, and responding to individuals whose information they control. If you are not a B2 Systems account holder and your information was submitted by a broker, funder, employer, or another customer, direct your request to that organization. We may refer your request to the applicable customer.

1.3 Data Processing Addenda

Where required, B2 Systems and a customer may enter into a separate data processing addendum. If that addendum conflicts with this Policy concerning Customer Data, the addendum controls within its scope.

2. Information We Collect

2.1 Account and Contact Information

We may collect:

  • Name, job title, role, and organization;
  • Business email address and telephone number;
  • Business address, website, and organization details;
  • Account identifiers, profile information, preferences, and language;
  • User roles, permissions, team memberships, and administrative settings; and
  • Communications and support history.

2.2 Authentication and Security Information

We may collect authentication identifiers, login timestamps, IP addresses, device and browser information, session information, access records, security events, API keys, connected-account status, and records used to prevent unauthorized activity.

We do not ask customers to provide passwords for unrelated third-party accounts. Where an integration uses an authorization mechanism, we may receive tokens and permissions necessary to operate the connection.

2.3 Billing and Subscription Information

We may collect billing contacts, billing addresses, subscription and plan information, entitlements, usage, invoices, payment status, transaction identifiers, payment-method type, and limited payment-method details such as brand and last four digits.

Payment processors generally collect and store complete card or bank-account credentials. B2 Systems does not ordinarily receive complete payment-card numbers.

2.4 Customer and Operational Data

Customers may submit or connect information including:

  • Merchant, applicant, owner, employee, broker, and funder information;
  • Business applications and organization records;
  • Bank statements, transaction histories, balances, financial records, and supporting documents;
  • Names, addresses, email addresses, telephone numbers, dates of birth, ownership information, and other identifiers;
  • Deal details, requested amounts, existing positions, offers, declines, submissions, statuses, notes, and communications;
  • Uploaded files, document metadata, parsing results, matching results, calculations, and generated outputs;
  • Email messages, subjects, recipients, routing information, attachments, and delivery events;
  • API requests, responses, connected-system data, and integration events; and
  • Other information a customer chooses to submit or instruct us to process.

Some Customer Data may be considered sensitive personal information under applicable law, including financial information and account-related identifiers.

2.5 Website and Usage Information

We may collect pages viewed, navigation activity, referring pages, approximate location derived from IP address, device characteristics, browser settings, cookie identifiers, performance events, feature interactions, and other usage information.

2.6 Sales and Marketing Information

We may collect contact-form responses, meeting requests, campaign interactions, marketing preferences, referral information, and records of consent to email or text communications.

2.7 Communications

We may retain emails, support messages, account notices, telephone-call metadata, meeting information, feedback, and other communications with B2 Systems. Where permitted and disclosed, communications may be monitored or recorded for support, quality, security, training, or evidentiary purposes.

2.8 Information from Other Sources

We may receive information from:

  • Customers, their users, brokers, funders, merchants, and applicants;
  • Connected mailboxes, CRMs, APIs, and other customer-authorized integrations;
  • Payment and banking providers;
  • Communications and delivery providers;
  • Security, fraud-prevention, and identity-verification sources;
  • Publicly available business sources; and
  • Marketing, analytics, referral, and event partners.

3. How We Use Information

3.1 Provide and Operate the Platform

We use information to:

  • Create and administer accounts;
  • Authenticate users and enforce permissions;
  • Provide subscribed products, credits, APIs, integrations, and add-ons;
  • Receive, store, process, and display Customer Data;
  • Process documents and financial information;
  • Generate matching, ranking, analysis, and operational outputs;
  • Route submissions and communications at customer direction;
  • Capture and organize eligible communications;
  • Provide billing, usage, and subscription functions; and
  • Maintain, troubleshoot, and improve Platform operations.

3.2 Customer Instructions

We process Customer Data to follow customer configurations and instructions, including selected funders, thresholds, routing, connected mailboxes, API requests, plan settings, and administrative actions.

3.3 Security, Fraud Prevention, and Enforcement

We use information to protect accounts and infrastructure, investigate misuse, detect fraud, enforce agreements, prevent trial or payment abuse, respond to chargebacks, preserve evidence, collect amounts due, and comply with legal requirements.

3.4 Billing and Business Administration

We use information to administer subscriptions, verify entitlements, meter usage, process payments, issue invoices, manage account changes, keep business records, forecast operations, and conduct internal audits.

3.5 Communications and Support

We use information to respond to requests, provide support, send transactional messages, deliver legal and billing notices, notify users about security or service events, and communicate about the customer relationship.

3.6 Product Improvement and Analytics

We use usage and operational information to understand feature performance, diagnose errors, secure the Platform, plan capacity, evaluate products, and develop improvements.

Where appropriate, we use aggregated or de-identified information that cannot reasonably be linked to a customer, person, or transaction.

3.7 Marketing

Subject to applicable law and communication preferences, we may use business contact information to send product, event, educational, or promotional communications. You may opt out of promotional email through the unsubscribe link or by contacting us. Opting out does not stop transactional, security, billing, or legal notices.

3.8 Legal and Protective Purposes

We may use information to comply with subpoenas, court orders, legal process, regulatory requests, sanctions, tax and accounting requirements, and other legal obligations; establish, exercise, or defend legal rights; and protect B2 Systems, customers, individuals, and the public.

4. Automated Processing

4.1 Platform Processing

The Platform may automatically extract, classify, summarize, calculate, match, rank, route, or transmit information. These processes support document processing, workflow automation, matching, submissions, communication organization, security, and related functions.

4.2 No B2 Systems Lending Decision

B2 Systems does not make lending or funding decisions for customers. Customers and third parties remain responsible for reviewing outputs, making decisions, providing legally required notices, and complying with laws applicable to their activities.

4.3 Accuracy

Automated results may be incomplete or inaccurate because they depend on submitted information, third-party data, configurations, communications, and technical conditions. Customers are responsible for verifying information before relying on it.

5. How We Disclose Information

5.1 At Customer Direction

We disclose Customer Data to users, brokers, funders, recipients, connected systems, and other parties selected or authorized by the customer. A customer may configure automatic submissions, communications, and integrations that cause information to be transmitted without a separate action for each transmission.

5.2 Service Providers

We use service providers for functions such as cloud hosting, infrastructure, databases, storage, security, communications, document processing, payment processing, analytics, customer support, and professional services.

We do not publicly identify individual providers in this Policy. We maintain appropriate internal provider records and may disclose provider identity confidentially when required by law, a regulator, an applicable data processing addendum, or an approved enterprise security review.

Providers may process information only for authorized business purposes and subject to contractual or legal restrictions appropriate to their function.

5.3 Payment and Financial Providers

We disclose billing and transaction information to payment processors, financial institutions, card networks, and related providers to collect payments, manage retries, prevent fraud, respond to disputes, and reconcile transactions.

5.4 Business and Professional Advisers

We may disclose information to auditors, accountants, insurers, lenders, investors, attorneys, consultants, collection parties, and other professional advisers where reasonably necessary and subject to appropriate duties.

5.5 Corporate Transactions

Information may be disclosed or transferred in connection with an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to customary protections where appropriate.

5.6 Legal and Safety Disclosures

We may disclose information when we believe disclosure is required or appropriate to comply with law or process; respond to regulators or law enforcement; protect rights, safety, security, or property; investigate fraud or misuse; collect debts; or enforce agreements.

5.7 De-Identified Information

We may disclose aggregated or de-identified information that cannot reasonably be linked to a customer, individual, or transaction. We require recipients not to attempt re-identification where required by law or contract.

5.8 Sale and Targeted Advertising

B2 Systems does not sell personal information for money.

On public marketing pages, and only subject to applicable consent and opt-out requirements, online identifiers and activity may be disclosed through analytics or advertising technologies for measurement, attribution, or advertising. Some laws may define that disclosure as a "sale," "sharing," or targeted advertising even when no money is exchanged.

B2 Systems does not intentionally use advertising pixels to profile activity inside authenticated customer dashboards. Product analytics used within authenticated areas are limited to operational, security, performance, and product-improvement purposes.

6. Cookies and Tracking Technologies

6.1 Categories

We and our providers may use cookies, pixels, local storage, tags, and similar technologies for:

  • Essential authentication, security, preferences, and Platform operation;
  • Performance and error monitoring;
  • Analytics and product improvement; and
  • Public-site advertising measurement and attribution.

6.2 Consent and Controls

Where required, nonessential analytics and advertising technologies are disabled until you make a consent choice. You may adjust available cookie preferences through the website control and may also use browser controls.

We honor legally required browser-based opt-out preference signals where applicable and technically supported. Blocking essential technologies may prevent parts of the Platform from functioning.

6.3 Tag Management

We may use a tag-management system to deploy and control analytics or other website technologies. The tag-management container does not itself determine the purposes of a tag; individual tags remain subject to the consent and disclosure rules in this Policy.

7. Email and Text Communications

7.1 Email

Transactional messages may include account, security, billing, legal, service, trial, and operational notices. You cannot opt out of essential messages while maintaining an account.

You may opt out of promotional email by using the unsubscribe mechanism or contacting support@b2systems.io.

7.2 Text Messages

If you provide a mobile number and expressly consent to receive text messages, B2 Systems may send automated informational or marketing messages relating to its services. Message frequency varies. Message and data rates may apply. Consent is not a condition of purchase.

You may opt out at any time by replying STOP. You may request help by replying HELP or contacting support@b2systems.io.

Mobile opt-in information and consent are not sold or disclosed to third parties or affiliates for their own marketing or promotional purposes. Providers assisting B2 Systems with message delivery may process the information solely to provide that service and subject to appropriate restrictions.

8. Data Retention

8.1 Operational Customer Data

Operational Customer Data is retained according to the organization-level data-retention period in the customer's accepted plan. Unless the accepted commercial schedule states otherwise, the default period is thirty days for a Trial plan, thirty days for a Standard plan, and ninety days for a Custom plan. Operational Customer Data generally includes deal, merchant, applicant, document, processing, matching, submission, communication, and related output data maintained for ordinary Platform use.

8.2 Retention Starts

Operational Customer Data associated with a deal receives an immutable organization-specific retention start. For the originating organization, retention begins when the original deal is created. For a recipient organization, retention begins when the deal is first provided to that organization.

Editing, uploading, replacing, reprocessing, rerunning, reopening, copying, duplicating, resubmitting, communicating about, or changing the status of a deal does not restart or extend retention. Associated files, outputs, messages, and later-added information inherit the same expiration.

Standalone operational data not associated with a deal is retained from when it is first created, uploaded, received, or generated for the organization. Editing or reprocessing does not restart retention.

8.3 Plan Changes

An accepted plan upgrade may extend the deadline for information not already deleted. An accepted downgrade may cause information to expire immediately. Deleted information cannot be restored by a later plan change.

8.4 Account and User Deletion

When an organization account is deleted or service access ends, access may end immediately and deletion of remaining Operational Customer Data may begin promptly, even if the plan retention period would have ended later. At the end of an applicable retention period, Operational Customer Data is scheduled for deletion from customer-accessible and active operational systems. Before or as part of deletion, we may irreversibly de-identify information so it can no longer reasonably be linked to a customer, individual, or transaction.

When an individual user is removed while the organization remains active, B2 Systems may delete or anonymize the user's profile information while preserving organization-owned content, security records, audit attribution, and records needed for the organization or B2 Systems.

Account deletion does not cancel contractual payment obligations. Customers should export needed information before access ends.

8.5 Legal, Transaction, and Security Records

We may retain executed agreements, signing certificates, acceptance evidence, billing and tax records, fraud and security records, communications relevant to disputes, usage evidence, collection records, legal notices, privacy-request records, and other information needed to establish, exercise, or defend legal rights for at least seven years after the relationship ends.

We may retain information longer while a dispute, collection, investigation, access request, legal hold, or legal requirement continues.

8.6 De-Identified Information

We may retain properly de-identified or aggregated information indefinitely when it cannot reasonably be linked to a customer, individual, or transaction. Removing a single direct identifier is not sufficient if the remaining information can reasonably be linked or reconstructed.

8.7 Backups

Residual encrypted copies may remain temporarily in protected backups until removed through ordinary backup rotation. Backup copies are not available for ordinary Platform use. If a backup is restored, expired information is subject to the retention process again.

9. Data Security

9.1 Safeguards

We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, and destruction. Safeguards are selected based on the nature and sensitivity of information and may evolve over time.

9.2 No Absolute Security

No transmission, storage system, software, or security measure is completely secure. We cannot guarantee that unauthorized access, loss, corruption, or security incidents will never occur.

9.3 Customer Responsibilities

Customers are responsible for user access, credentials, API keys, connected systems, devices, account configuration, data minimization, exports, and notifying us promptly of suspected compromise.

9.4 Security Incidents

If we identify a security incident involving personal information, we will investigate, mitigate, document, and provide notices as required by applicable law and contract.

10. Your Privacy Choices and Rights

10.1 Account Information

Authorized users may be able to review or update certain account information through the Platform. For assistance, contact support@b2systems.io.

10.2 Applicable Privacy Rights

Depending on your location, relationship with B2 Systems, and applicable law, you may have rights to:

  • Know or access personal information;
  • Correct inaccurate information;
  • Request deletion;
  • Obtain a portable copy;
  • Withdraw consent where processing depends on consent;
  • Opt out of certain sales, sharing, or targeted advertising;
  • Limit certain uses of sensitive personal information;
  • Appeal a denied request; and
  • Receive nondiscriminatory treatment for exercising a privacy right.

These rights are subject to verification, exceptions, organizational roles, legal retention, security, privilege, and other limitations under applicable law.

10.3 Submitting a Request

Submit a privacy request to privacy@b2systems.io. Describe the request and your relationship to B2 Systems. We may request information reasonably necessary to verify identity, authority, organization, and jurisdiction.

An authorized agent may submit a request where permitted by law, subject to verification of the agent's authority and the individual's identity.

10.4 Customer-Controlled Data

If B2 Systems processes information solely for a customer, we may direct the request to that customer or assist the customer as required by law or contract. B2 Systems may not be able to identify the applicable customer without sufficient information.

10.5 Retention Exceptions

We may deny or limit deletion where information is needed for security, fraud prevention, billing, taxes, collections, disputes, legal claims, compliance, a valid legal hold, or another permitted purpose. When a valid access or privacy request concerns information scheduled for deletion, we may preserve the relevant information while the request and available review process remain pending.

10.6 Marketing Choices

Use email unsubscribe links, reply STOP to eligible text messages, or adjust available cookie preferences. You may still receive essential account, billing, legal, security, and service communications.

11. United States and Canada

11.1 Intended Markets

The Platform is designed primarily for commercial users in the United States and Canada and supports telephone numbers from those countries. We do not intentionally market the Platform as a consumer service or as a service specifically directed to other jurisdictions.

11.2 United States Privacy Laws

Where a United States state privacy law applies to B2 Systems and your information, we provide the rights and notices required by that law. Certain information processed solely as a service provider for a customer may need to be addressed through that customer.

11.3 Canada

Where Canadian private-sector privacy law applies, B2 Systems follows applicable principles concerning accountability, identified purposes, consent, limited collection, limited use and retention, accuracy, safeguards, openness, individual access, and complaint handling.

Canadian information may be processed in the United States and may be available to United States courts, law enforcement, or regulators under applicable law.

12. Cross-Border Processing

B2 Systems is based in the United States, and information may be transferred to, stored in, accessed from, and processed in the United States and other locations where authorized providers operate.

Privacy and data-protection laws in those locations may differ from those where information originated. We use contractual, technical, and organizational measures appropriate to the processing and as required by applicable law.

Use from an unsupported jurisdiction does not require B2 Systems to localize data, establish a local entity, or modify the Platform, except where non-waivable law applies.

13. Children's Privacy

The Platform is not intended for anyone under eighteen, and we do not knowingly permit minors to create accounts. Customers must not submit information about minors unless legally authorized and strictly necessary for a lawful business purpose supported by the Platform.

If you believe a minor's information was submitted improperly, contact privacy@b2systems.io.

14. Third-Party Sites and Services

The Platform may link to or interoperate with third-party sites, accounts, applications, or services. Their privacy practices are governed by their own notices. B2 Systems is not responsible for third-party privacy, security, content, or conduct.

15. Changes to This Policy

We may update this Privacy Policy to reflect legal, operational, security, or product changes. We will identify the effective date through the published legal page and provide additional notice of material changes where required by law.

The version effective when information is processed governs our practices, subject to applicable law and any binding data processing addendum.

16. Contact Information

16.1 Privacy Requests and Complaints

Contact our privacy function at:

Email: privacy@b2systems.io Company: B2 Systems, Inc. Address: Atlanta Tech Village, 3423 Piedmont Road NE, Atlanta, Georgia 30305, United States

16.2 Account Assistance

For routine account, billing, or support assistance, contact support@b2systems.io.

We will review privacy complaints and requests in accordance with applicable law. You may also have the right to contact an applicable privacy regulator.