Hushpay, Inc. is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, how we use and protect it, who we share it with, and what rights you have over it. It applies globally to all users of the Hushpay website and mobile application, regardless of where you are located.
01Who Is Responsible for Your Data
Hushpay Inc., a Delaware corporation with its principal address at 1000 Brickell Avenue, STE 715, Miami, FL 33131, United States (Office: +1 (928) Hushpay), is the data controller of your personal data collected through the Service. Our privacy contact is: privacy@hushpay.ai.
Where Hushpay processes personal data on behalf of partner venues or airline partners, Hushpay acts as a data processor under those partners' instructions. This Privacy Policy governs Hushpay's own data controller activities.
02What Data We Collect
2.1 Data you provide directly
Account data (name, email, phone, date of birth, country of residence), payment method details processed by our PCI-DSS certified partners, communications with our support team, and any survey responses you provide.
2.2 Data we collect automatically
Device and technical data (IP address, device type, OS, app version, unique device identifier), usage data (features used, screens viewed, session duration, in-app search queries) and venue and flight preferences derived from your activity.
2.3 Data we receive from third parties
- Payment processors (Stripe, NymCard, Fyatu): payment confirmation, card status, fraud signals.
- Partner venues and airlines: confirmation of booking or dining access for reconciliation purposes.
- AML/compliance providers (Chainalysis or equivalent, for the crypto wallet feature): transaction risk scores.
- Analytics providers: aggregated behavioural data to help us understand general usage patterns.
03How We Use Your Data
We use your personal data to operate the Service, process payments, prevent fraud, provide customer support, personalise Tonight Feature recommendations and Smart Feed rankings, send you relevant Hushpay communications, and comply with legal obligations under financial services, AML and data protection law.
04Sharing Your Data
Hushpay does not sell your personal data to third parties. We share your personal data only in the circumstances described below.
4.1 Service providers
- Payment processors: Stripe, Inc., NymCard, Fyatu (for card issuance and transaction settlement).
- Cloud infrastructure: Amazon Web Services, Inc. (hosting, storage, compute).
- Notification delivery: Apple (APNs), Google (FCM) for push notifications.
- Analytics providers: aggregated, pseudonymised usage analytics.
- AML/compliance screening: Chainalysis or equivalent (crypto wallet feature, Phase 2).
- Deep-link and attribution: Branch.io or equivalent (for invite and referral links).
4.2 Partner venues and airline partners
Where necessary to facilitate a booking or access arrangement, we may share limited transaction data (such as booking reference and relevant access details) with the relevant partner. We do not share your payment card details with partner venues or airlines.
4.3 Legal and regulatory disclosure
We may disclose your personal data where required by law, court order, regulatory authority or government agency, or where we believe disclosure is necessary to protect the rights, property or safety of Hushpay, our members, or the public.
4.4 Business transfers
In the event of a merger, acquisition, financing or sale of assets involving Hushpay, your personal data may be transferred to the acquiring entity, subject to that entity's commitment to honour this Privacy Policy or provide equivalent protections.
4.5 Aggregated and anonymised data
We may share aggregated or anonymised data (from which you cannot be identified) with business partners, research institutions or the public for analytical and research purposes.
05International Data Transfers
Hushpay is headquartered in the United States. Your personal data may be transferred to and processed in countries other than the one in which you reside, including the United States. These countries may have data protection laws that differ from those in your jurisdiction.
When we transfer personal data from the EEA, the UK, or Switzerland to countries not recognised as providing an adequate level of data protection, we rely on appropriate transfer mechanisms including Standard Contractual Clauses (SCCs) and Data Processing Agreements incorporating applicable transfer safeguards. For transfers from the UAE (DIFC/ADGM), Saudi Arabia (PDPL), Canada (PIPEDA), or other jurisdictions with cross-border requirements, we apply equivalent contractual safeguards.
06Data Retention
We retain account data for the duration of your account plus 7 years after closure for legal and regulatory compliance and dispute resolution. Transaction and payment data are retained for the periods required by financial services regulation. Usage and analytics data are retained in aggregated form for service improvement.
07Your Rights
Depending on your jurisdiction, you may have some or all of the following rights in relation to your personal data. We honour these rights globally to the fullest extent practically possible: access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent.
We will respond to all verifiable data rights requests within 30 days (or the period required by applicable law). For complex requests, we may extend this period by a further 30 days with notice. We may need to verify your identity before processing a request.
08Legal Bases for Processing (EEA / UK / Equivalent Jurisdictions)
- Contract: where processing is necessary to perform our contract with you (e.g., providing the Service, processing payments).
- Legitimate interests: fraud prevention, service improvement, the Tonight Feature recommendations. You may object at any time.
- Legal obligation: to comply with applicable law (e.g., AML requirements, financial record-keeping).
- Consent: e.g., marketing communications, precise location access, crypto wallet functionality. You may withdraw at any time.
09Cookies and Tracking Technologies
We use strictly necessary cookies for session management, security and authentication, plus analytics and preference cookies to improve the Service. You can manage preferences through the cookie consent tool on our website or through your browser and device settings. We do not respond to browser Do Not Track signals but we do honour opt-out requests made through our privacy contact.
10Payment Data and Financial Security
Hushpay takes the security of payment data extremely seriously. We do not store raw payment card numbers on our servers. All card processing is handled by PCI-DSS compliant third-party processors (Stripe, NymCard, or Fyatu). Hushpay receives only limited, tokenised transaction data necessary to operate the Service.
JIT virtual cards created for Member Access Windows are single-use, time-limited, and restricted to the specific partner venue by Merchant ID. They cannot be used at other merchants and expire automatically after the access window closes.
11Crypto and Digital Asset Data (Phase 2)
When the crypto wallet feature becomes available, Hushpay will collect and process your digital wallet address and on-chain transaction data to facilitate USDT/USDC funding of your JIT cards. This data will be subject to AML screening. We do not have access to your private keys and do not custody your digital assets.
12Data Security
- Encryption of data in transit using TLS 1.3 and at rest using AES-256.
- Access controls limiting data access to authorised personnel with a legitimate need.
- Regular security assessments, penetration testing, and vulnerability management.
- AWS WAF and intrusion detection systems protecting the Hushpay platform.
- Sub-200ms JIT authorisation checks preventing wrong-venue payment fraud.
No method of transmission or storage is 100% secure. If we become aware of a data security incident affecting your personal data, we will notify you and relevant authorities as required by applicable law.
13Children's Privacy
The Service is not directed at children under 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal data from children. If you believe we may have data about a child, please contact us at privacy@hushpay.ai.
14Regional Supplements
14.1 European Economic Area and United Kingdom
EEA and UK users have rights under the GDPR / UK GDPR and may lodge a complaint with their local supervisory authority.
14.2 United States (California)
California residents have rights under the CCPA/CPRA including access, deletion, correction and the right not to be discriminated against for exercising those rights.
14.3 United Arab Emirates
Hushpay processes personal data in compliance with UAE Federal Decree-Law No. 45 of 2021 and, where applicable, the DIFC Data Protection Law and ADGM Data Protection Regulations.
14.4 Canada
Canadian users are covered by PIPEDA and applicable provincial privacy laws. Complaints may be lodged with the Office of the Privacy Commissioner of Canada (priv.gc.ca).
14.5 Saudi Arabia
Saudi users are covered by the Personal Data Protection Law (PDPL). We apply appropriate cross-border transfer safeguards for data originating from Saudi Arabia.
15Changes to This Policy
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree with the updated Policy, you should discontinue use of the Service and may request deletion of your data under Section 7.
16Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact our Privacy Team:
- Hushpay, Inc.
- 1000 Brickell Avenue, STE 715, Miami, FL 33131, United States
- Office: +1 (928) Hushpay
- Email: privacy@hushpay.ai
- Website: hushpay.ai
We aim to acknowledge all privacy enquiries within 5 business days and resolve them within 30 days (or the period required by applicable law).