Legal

Privacy Policy

Your privacy matters. This Policy explains how ASK Pmt collects, uses, discloses, retains, and protects information across our websites, platform, mobile applications, AI features, beta programs, and connected systems.

Effective date: September 29, 2026 Last updated: September 29, 2026

1. Scope and Roles

This Privacy Policy explains how ASK Pmt ("ASK Pmt," "we," "us," or "our") collects, uses, discloses, retains, and protects information in connection with our websites, SaaS platform, applications, mobile applications, beta programs, customer support channels, and other Services that link to this Policy.

ASK Pmt provides payments-industry software that may include AI-assisted merchant-statement analysis, residual and savings calculations, Schedule A analysis, proposal generation, CRM features, portfolio intelligence, solution recommendations, mobile document capture, and connected-system workflows.

When ASK Pmt processes personal information that a business customer submits or connects for its merchants, clients, employees, agents, prospects, or other third parties, the customer generally determines the purposes and means of that processing, and ASK Pmt may act as a service provider or processor on the customer's behalf. In those situations, requests relating to that information may need to be directed to the applicable customer. Where ASK Pmt determines the purposes and means of processing, ASK Pmt acts as a controller/business as defined by applicable law.

Key provision

2. Information We Collect

2.1 Account, Business, and Beta Information

We may collect name, business email address, telephone number, company name, business type, title or role, team size, account credentials, authentication information, subscription plan, user permissions, beta-enrollment responses, preferences, support history, and other information you provide when creating or administering an account.

2.2 Merchant, Client, and Payments-Business Data

We may process merchant statements, residual reports, Schedule A documents, amendments, addenda, processor pricing documents, transaction summaries, pricing information, fees, merchant and client contact information, merchant profiles, notes, tasks, opportunities, pipeline records, proposals, equipment information, uploaded files, and other business information that you upload, enter, transmit, capture, or connect to the Services.

Customers are responsible for ensuring they have the rights, authority, notices, and consents necessary to provide this information to ASK Pmt. Unless a feature expressly supports it, users should not upload full payment card numbers, card verification values, PINs, online-banking credentials, Social Security numbers, government identification numbers, protected health information, or other highly sensitive information not reasonably necessary to use the Services.

2.3 Connected-System Information

If you connect a CRM, processor data source, accounting platform, email system, cloud service, or other third-party service, we may receive data made available through that connection. Depending on the integration and permissions you grant, the Services may read, create, or update records in the connected system. We process such information to provide the integration and workflow functionality you request. Where the connected service is Google, the Google Workspace Data section below governs and is narrower than this paragraph.

2.4 Usage, Device, and Technical Information

We may automatically collect IP address, approximate location derived from IP address, device identifiers, browser type, operating system, application version, login events, pages or screens viewed, features used, actions taken, error logs, performance data, referring URLs, security events, and similar technical information.

2.5 Communications and Support Information

We may collect information contained in emails, support tickets, feedback, surveys, chat messages, calls, beta-testing feedback, and other communications with us.

2.6 Billing and Transaction Information

When paid plans are offered, we may collect subscription plan, billing contact, invoice, transaction, and payment-status information. Payment card information may be processed by a third-party payment processor rather than stored directly by ASK Pmt.

Google user data

Google Workspace Data (Gmail and Google Calendar)

This section describes how ASK Pmt handles data obtained from Google APIs when a user chooses to connect a Google account. It applies in addition to the rest of this Policy. Where this section is narrower than any other section, this section controls for Google user data.

What ASK Pmt requests, and what it is used for

Connecting a Google account is optional, is started by the user, and can be undone by the user at any time. ASK Pmt requests read-only access only:

  • Gmail, read-only (gmail.readonly). Used to read the mailbox data needed for the user-facing email and CRM intelligence features: associating correspondence with the right merchant, client, or contact, showing an account's email history on that account, and opening an individual message when the user asks to read it.
  • Google Calendar, read-only (calendar.readonly, or the narrower calendar.events.readonly). Used to read the calendar and event data needed for the user-facing meeting and CRM intelligence features: showing meetings on the relevant account with their subject, time, location, attendees, and status.
  • Google account email address (userinfo.email, with the openid and email identifiers Google returns alongside it). Used to show the user which mailbox is connected and to tell inbound correspondence from outbound.

ASK Pmt does not use Gmail scopes to send, modify, delete, label, archive, or compose email, and requests no scope that would permit any of those. ASK Pmt does not use Calendar scopes to create, edit, or delete calendar events in Phase 1, and requests no scope that would permit that. ASK Pmt does not request access to Google Drive or Google Contacts. A connection is refused rather than stored if the scopes actually granted fall outside the read-only set described above.

What ASK Pmt stores, and what it does not

For email, ASK Pmt records who the message was between, which direction it went, when it happened, and Google's own identifier for the message. ASK Pmt does not store message bodies, HTML, plain text, previews, snippets, subject lines, or attachments; when a user opens a message, it is read from Google at that moment and is not retained. For calendar events, ASK Pmt records the structured meeting details listed above so that the meeting can appear on the relevant account.

OAuth refresh tokens are encrypted by the application before storage and are held server-side. They are not readable by browser or client database roles, and are never returned to the browser.

Limited Use of Google user data

ASK Pmt's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs will adhere to the Google Workspace User Data and Developer Policy, including the Limited Use requirements.

In particular, for Google user data:

  • It is used only to provide or improve the user-facing Google-connected features that the user authorized and that are visible and prominent in the ASK Pmt interface.
  • It is not sold, transferred to advertising platforms or data brokers, used to serve or retarget advertising, or used to determine credit-worthiness or for lending purposes.
  • It is not used to create, train, or improve generalized or non-personalized artificial-intelligence or machine-learning models, including foundation models. The exclusion covers Google user data and anything derived from it, and it applies whether or not that information has been aggregated or de-identified. See Section 5 and Section 7.
  • Humans do not read it except in the circumstances Google's Limited Use rules permit: with the user's affirmative agreement to view specific messages or records; where necessary for security purposes, such as investigating abuse or a defect; where necessary to provide support the user has requested; where required to comply with applicable law; or where the data has been aggregated and anonymized for internal operations in accordance with applicable privacy requirements.

Disconnecting, revoking, and what is kept

A user may disconnect Google from within ASK Pmt at any time. On disconnect, ASK Pmt attempts to revoke the grant at Google and destroys the stored OAuth credential. Revocation at Google is best effort — Google may decline it, for example where the user has already removed the grant themselves — and the stored credential is destroyed either way. A workspace administrator may also destroy a member's stored credential; that removes ASK Pmt's copy but does not revoke the grant at Google, and the product says so rather than implying an erasure it did not perform.

A user may independently revoke ASK Pmt's access at any time from Google Account permissions. Doing so stops all further access, including any access for which ASK Pmt still holds a credential.

Disconnecting stops ASK Pmt reading Gmail or Google Calendar. It does not by itself erase CRM records that ASK Pmt has already created. Email and meeting records already held on an account may be retained in accordance with Section 11 (Data Retention) unless they are deleted through the account's normal deletion controls or through a privacy request under Section 12 and Section 13.

3. Sources of Information

We obtain information: (a) directly from you and your organization; (b) from users acting on behalf of merchants or clients; (c) automatically when you use the Services; (d) from connected systems you authorize; (e) from service providers and business partners; and (f) where permitted, from publicly available or commercially available business sources.

4. How We Use Information

  • Provide, operate, maintain, secure, personalize, and support the Services.
  • Authenticate users and administer accounts, teams, roles, permissions, subscriptions, beta access, and support.
  • Analyze merchant statements, Schedule A documents, residual reports, pricing information, CRM data, and other business data.
  • Generate calculations, estimates, analyses, recommendations, proposals, drafts, summaries, tasks, and other requested Outputs.
  • Enable customer-authorized integrations and connected-system actions, including creation or updating of records where supported.
  • Provide support, troubleshoot errors, investigate incidents, monitor quality, and improve reliability and usability.
  • Develop and improve product features, models, prompts, rules, workflows, and user experiences subject to the restrictions in Section 5.
  • Protect against fraud, abuse, unauthorized access, misuse, and security threats, and enforce our agreements.
  • Comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
  • Send account, security, product, support, beta, administrative, and, where permitted, marketing communications.
Key provision

5. AI, Automated Processing, and Model Training

The Services may use artificial intelligence, machine learning, optical character recognition, rules-based systems, and other automated technologies to extract information, classify documents, perform calculations, identify patterns, generate text, recommend actions, and support product functions.

ASK Pmt does not use identifiable Customer Data to train generalized AI models. We may use aggregated and de-identified information for product analytics, security, quality testing, benchmarking at an aggregated level, and development or improvement of features, models, prompts, and workflows, subject to applicable law and contractual restrictions.

Google user data is excluded from that permission entirely. Data obtained from Google APIs, including Gmail and Google Calendar data, and anything derived from it, are never used to create, train, or improve generalized or non-personalized AI or machine-learning models, including foundation models. The exclusion is absolute: it is not lifted by aggregation, by de-identification, or by use at a benchmark level. See the Google Workspace Data section.

ASK Pmt may use third-party AI/model providers as subprocessors, as described in Section 6.1.

Automated Outputs may be incomplete, inaccurate, or based on assumptions. The Services are designed as decision-support tools. Users are responsible for reviewing and verifying material Outputs before relying on them, sending them to a merchant, changing pricing, onboarding a merchant, or taking other business action.

6. How We Disclose Information

6.1 Service Providers and Subprocessors

We may disclose information to cloud hosting, database, security, analytics, communications, customer-support, AI/model, document-processing, storage, payment, and other vendors that perform services for us. We require service providers to handle information subject to contractual, confidentiality, security, and use restrictions appropriate to their role.

6.2 Customer-Directed Disclosures and Connected Systems

We disclose information when you direct us to do so, including when you generate or send a proposal, connect a third-party service, authorize a workflow, invite another user, export data, update a CRM record, or otherwise instruct the Services to transmit information.

We may disclose information when we reasonably believe disclosure is required by law, regulation, legal process, or governmental request; is necessary to investigate fraud or security incidents; or is necessary to enforce agreements or protect legal rights, safety, and security.

6.4 Business Transfers

Information may be disclosed or transferred in connection with an actual or proposed merger, financing, acquisition, reorganization, sale of assets, bankruptcy, or similar corporate transaction, subject to appropriate protections.

Key provision

7. Aggregated and De-Identified Information

We may create and use aggregated or de-identified information that cannot reasonably be linked to an identifiable individual, merchant, or customer. We may use and disclose such information for analytics, security, benchmarking, service improvement, research, and development consistent with applicable law and contractual restrictions.

This Section does not apply to Google user data or to information derived from it. Aggregating or de-identifying Google user data does not make it available for generalized or non-personalized AI or machine-learning model training or improvement, and does not remove any other restriction stated in the Google Workspace Data section.

Where required by law, we publicly commit to maintain de-identified information in de-identified form, not attempt to re-identify it except as permitted to test or validate de-identification or otherwise permitted by law, and contractually require recipients to comply with applicable restrictions on re-identification.

8. Cookies, Analytics, Sale/Sharing, and Global Privacy Control

We may use cookies, local storage, pixels, SDKs, analytics tools, and similar technologies to operate the Services, remember preferences, secure accounts, understand usage, measure performance, and, if enabled, support marketing. Cookie practices may differ between our public website and authenticated application.

ASK Pmt does not intend to sell personal information for monetary consideration. Some U.S. privacy laws define "sale," "sharing," or "targeted advertising" more broadly. If our website or marketing technologies engage in activity covered by those definitions, we will provide the required notices and opt-out choices.

Where legally required and technically applicable, we will recognize browser-based opt-out preference signals, including Global Privacy Control (GPC), as a request to opt out of sale, sharing, or targeted advertising for the browser or device from which the signal is sent.

Key provision

9. Mobile Application Information

If you use an ASK Pmt mobile application, the app may request permission to use the device camera or photo library so you can capture or upload merchant statements and other documents. Camera or photo access occurs only with device permission and for the feature you initiate. The app may also process device identifiers, application version, crash logs, push-notification tokens, and similar technical information needed to operate and secure the app.

Key provision

10. Data Security and Incident Notification

We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, acquisition, disclosure, alteration, loss, or destruction. Safeguards may include encryption in transit and at rest where appropriate, role-based access, authentication controls, logging, monitoring, secure development practices, vulnerability management, backups, vendor-risk management, and incident-response procedures.

No security system is perfect, and we cannot guarantee absolute security. If we determine that a security incident affecting personal information requires notification under applicable law or a contractual obligation, we will notify affected customers and/or individuals without undue delay and in accordance with those requirements. Customers are responsible for protecting credentials, managing user permissions, securing connected systems, and promptly reporting suspected unauthorized access.

11. Data Retention

We retain information for as long as reasonably necessary to provide the Services, maintain legitimate business and security records, comply with legal, tax, accounting, and contractual obligations, resolve disputes, and enforce agreements. Retention periods vary based on the type of information, purpose, customer instructions, applicable contracts, and legal requirements.

Following account termination, customers may have a limited period to retrieve available Customer Data as described in the Terms or applicable order form. When information is no longer required, we may delete, de-identify, or aggregate it, subject to backup cycles, legal holds, security records, fraud prevention, and other lawful retention requirements.

Key provision

12. Your Privacy Rights and Choices

Depending on where you live and the role ASK Pmt has with respect to your information, you may have rights to:

  • Confirm whether we process personal information about you and access that information.
  • Correct inaccurate personal information.
  • Delete certain personal information.
  • Obtain a portable copy of certain personal information.
  • Opt out of certain sale, sharing, targeted advertising, or profiling activities where applicable.
  • Withdraw consent where processing is based on consent, subject to legal limitations.
  • Limit or opt out of certain uses of sensitive personal information where required.
  • Appeal our decision on a privacy request where applicable law provides that right.
  • Opt out of marketing communications using the unsubscribe method provided in the communication.

These rights are not absolute and may be limited by law. When ASK Pmt processes information solely on behalf of a business customer, we may direct you to that customer because it controls the relevant information.

13. Appeals, Authorized Agents, and Request Timing

To submit a privacy request, email privacy@askpmt.ai. Privacy requests are accepted by email only. Please describe the request and provide sufficient information for us to identify the relevant account or records. We may need to verify your identity or authority before completing a request and may request additional information consistent with applicable law.

We will respond within the period required by applicable law. For many U.S. state privacy laws, this is generally 45 days, subject to a permitted extension where reasonably necessary and with notice. If we deny a request in whole or in part, we will provide the explanation required by applicable law.

Where applicable law provides an appeal right, you may appeal a denied request by emailing privacy@askpmt.ai with the subject line "Privacy Appeal". Appeals are accepted by email only, and the subject line is what routes an appeal rather than a new request. We will review the appeal and respond within the period required by applicable law, and we will provide information about any further complaint right when required.

Authorized agents may submit requests where permitted by law. We may require proof of authorization and may separately verify the consumer's identity or confirmation, except where applicable law provides otherwise.

14. Automated Decision-Making and Profiling

The Services may generate risk indicators, attrition indicators, pricing or profitability insights, solution recommendations, and other automated analyses for business users. ASK Pmt intends these features to support human decision-making, not to make final legal or similarly significant decisions about individuals without human review.

Where applicable law grants a right to opt out of profiling or automated processing used to make decisions producing legal or similarly significant effects, and ASK Pmt is responsible for that processing, we will provide the required right and instructions. Business customers are responsible for evaluating whether their own use of ASK Pmt Outputs triggers separate obligations or consumer rights.

15. U.S. State Privacy Disclosures

The following table is intended as a general U.S. state-law disclosure framework. Applicability depends on ASK Pmt meeting the relevant statutory thresholds and on the context in which information is processed.

CategoryExamplesSourcesBusiness PurposesRecipients
IdentifiersName, email, phone, IP address, account IDYou; your organization; devices; connected systemsAccount administration, security, support, communicationsService providers; customer-authorized recipients; legal recipients
Commercial / business informationSubscription, invoices, merchant/client records, proposalsYou; your organization; connected systemsProvide Services, analytics, billing, supportService providers; customer-authorized recipients
Internet / electronic activityLogins, pages, features, device/browser dataAutomatically from devices and ServicesSecurity, diagnostics, product analyticsCloud/security/analytics providers
Professional informationCompany, role, team, business typeYou; organizationAccount management, personalization, sales/supportService providers
Financial / payments-business informationMerchant statements, residual reports, Schedule A, pricing dataYou; connected systemsStatement analysis, calculations, recommendations, proposalsService providers/subprocessors as needed to provide Services
Inferences / analyticsProfitability, attrition, pricing or solution indicatorsDerived from Customer Data and use of ServicesDecision support, recommendations, product functionalityCustomer and authorized users; service providers as necessary
Sensitive information (limited)Only if submitted or required for a supported featureYou; connected systemsProvide requested feature; security/complianceRestricted service providers as necessary

We do not use or disclose sensitive personal information for purposes other than those permitted by applicable law unless we provide any required notice and choice. We do not knowingly discriminate against individuals for exercising applicable privacy rights.

16. International Data Transfers

ASK Pmt and its service providers may process information in the United States and other countries. Where required, we use appropriate safeguards for cross-border transfers, such as contractual clauses or other recognized transfer mechanisms.

17. Children's Privacy

The Services are intended for business users and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13 through consumer-facing features. If we learn that we collected such information in violation of applicable law, we will take reasonable steps to delete it. If a business customer submits information about minors, that customer is responsible for ensuring the processing is lawful and authorized.

19. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, practices, technologies, legal requirements, or other factors. We will post the revised Policy and update the effective date. For material changes, we will provide additional notice and obtain consent where required by law.

20. Contact Information

ASK Pmt

Privacy: privacy@askpmt.ai

Privacy Appeals: privacy@askpmt.ai, with the subject line "Privacy Appeal"

Support: info@askpmt.ai

21. Notice at Collection

This section is a short-form Notice at Collection for the ASK Pmt website and account enrollment flow.

Categories we may collect include identifiers and contact information; professional and business information; account and authentication information; internet and device activity; customer-support communications; subscription and billing records; merchant/client and payments-business data submitted to the Services; and inferences or analytics generated from use of the Services.

We use these categories to provide and secure the Services; administer accounts and beta access; perform statement, Schedule A, residual, pricing, CRM, proposal, and decision-support functions; provide support; communicate with users; improve and troubleshoot the product; prevent fraud and misuse; and comply with law.

We may disclose information to service providers and subprocessors, connected systems at your direction, professional advisers, authorities where legally required, and parties involved in a business transaction. We do not intend to sell personal information for money. If applicable law treats certain advertising or analytics activity as sale, sharing, or targeted advertising, we will provide required opt-out rights, including recognition of GPC where required.

Retention varies by category and purpose, as described in Section 11. For details about rights, requests, appeals, and our practices, review the complete Privacy Policy or contact privacy@askpmt.ai.

Privacy questions or requests

Contact details, the privacy request channel, and the appeals channel are set out in Section 20 (Contact Information) and Section 13 (Appeals, Authorized Agents, and Request Timing).