Privacy Policy
Derived LLC ("Derived," "we," "us," or "our") respects your privacy and is committed to protecting the personal information we collect and process.
This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website, communicate with us, request information, submit an application or inquiry, use our services, or otherwise interact with Derived.
Derived provides merchant services, payment-processing solutions, point-of-sale solutions, technology solutions, and related business services. In providing these services, we may work with third-party payment processors, acquiring banks, financial institutions, point-of-sale providers, technology providers, and other business partners.
1. Scope of This Privacy Policy
This Privacy Policy applies to personal information collected through our website and through our interactions with prospective customers, merchants, partners, agents, and other individuals who interact with Derived.
Certain products or services made available through Derived may be provided, underwritten, processed, fulfilled, or administered by third parties. Those third parties may collect and process information under their own privacy policies and terms.
This Privacy Policy does not govern the independent privacy practices of third-party payment processors, banks, financial institutions, point-of-sale providers, software providers, or other third-party services.
2. Personal Information We Collect
The information we collect depends on how you interact with Derived and the products or services in which you are interested.
We may collect the following categories of information:
Contact Information
This may include:
- Name
- Business name
- Business address
- Mailing address
- Email address
- Telephone or mobile number
- Job title or role
- Other contact information you provide
Business and Merchant Information
If you inquire about or apply for merchant services, payment processing, point-of-sale systems, or related services, we may collect information such as:
- Business legal name and DBA name
- Business type and industry
- Business locations
- Business website
- Products or services offered
- Estimated or historical processing volume
- Average transaction amount
- Current payment-processing provider
- Current point-of-sale provider
- Information regarding desired products, equipment, or services
- Information about business owners or authorized representatives
- Other information necessary to evaluate available payment, technology, or merchant-service solutions
Application, Identity, and Financial Information
When you apply for certain products or services, additional information may be required for underwriting, identity verification, banking, compliance, fraud prevention, or account setup.
Depending on the product, provider, and application process, this information may include:
- Bank account information
- Tax identification information
- Business ownership information
- Information concerning beneficial owners or authorized representatives
- Government-issued identification information
- Date of birth
- Financial information
- Processing history
- Business documentation
- Other information required by a payment processor, acquiring bank, financial institution, underwriting provider, or other service provider
Some or all of this information may be collected directly by a third-party provider through its own website, application, portal, or system rather than being collected or stored directly by Derived.
Communications
We may collect information contained in communications between you and Derived, including:
- Emails
- Telephone communications
- Text messages
- Website forms
- Customer service inquiries
- Support requests
- Sales communications
- Application-related communications
- Notes concerning your account or business relationship
Where permitted by applicable law, telephone calls or other communications may be monitored or recorded for quality assurance, training, security, documentation, dispute resolution, or compliance purposes.
Website and Device Information
When you visit our website, we or service providers acting on our behalf may automatically collect certain technical and usage information, including:
- IP address
- Browser type
- Device type
- Operating system
- Pages viewed
- Links or buttons clicked
- Referring website or source
- Date and time of visits
- Website interactions
- Approximate geographic location derived from an IP address
- Cookie identifiers
- Device identifiers
- Similar technical information
3. Sources of Personal Information
We may collect personal information:
- Directly from you
- From your business or its authorized representatives
- Through our website, forms, and applications
- Through telephone, email, SMS, or other communications
- From agents, referral partners, or business partners
- From payment processors
- From point-of-sale and technology providers
- From financial institutions and acquiring banks
- From identity-verification providers
- From fraud-prevention, risk, underwriting, or compliance providers
- From publicly available sources and business information
- Through essential security, hosting, scheduling, and similar technologies
4. How We Use Personal Information
We may use personal information to:
- Respond to inquiries and requests
- Communicate with prospective and existing merchants
- Understand your business and its needs
- Recommend payment-processing, point-of-sale, technology, or related solutions
- Prepare, submit, and facilitate merchant applications
- Assist with underwriting and account setup
- Verify identity and business information
- Communicate regarding applications, accounts, products, or services
- Facilitate installations, onboarding, activation, and training
- Provide customer service and support
- Manage merchant, partner, agent, and referral relationships
- Troubleshoot problems and resolve support requests
- Prevent fraud, abuse, unauthorized activity, and security incidents
- Maintain and improve our website, products, and services
- Analyze website usage and business performance
- Conduct sales and marketing activities where permitted by applicable law
- Maintain business and transaction records
- Administer our business operations
- Enforce agreements and policies
- Resolve disputes
- Establish, exercise, or defend legal claims
- Comply with legal, regulatory, contractual, and compliance obligations
We may also use information for other purposes disclosed to you at the time the information is collected or with your consent.
5. How We Disclose Personal Information
We may disclose personal information to third parties when reasonably necessary to operate our business, provide requested products or services, support merchants, fulfill legal obligations, or otherwise carry out the purposes described in this Privacy Policy.
Payment Processors and Financial Institutions
We may provide information to payment processors, acquiring banks, sponsoring banks, payment networks, financial institutions, gateways, and related providers when necessary to evaluate, establish, maintain, or support merchant accounts and payment-processing services.
Point-of-Sale and Technology Providers
We may provide information to point-of-sale providers, software companies, hardware providers, gateway providers, and other technology partners when necessary to evaluate, provide, install, activate, maintain, or support products and services requested by you.
Underwriting, Identity Verification, Risk, and Fraud Providers
Information may be provided to third parties that assist with:
- Identity verification
- Business verification
- Underwriting
- Fraud prevention
- Risk assessment
- Compliance
- Account verification
- Security
Service Providers
We may use third-party companies to perform services on our behalf, including providers of:
- Website hosting
- Cloud services
- Data storage
- Customer relationship management systems
- Communications
- Email delivery
- SMS messaging
- Bot prevention and website security
- Scheduling technology
- Analytics
- Customer support
- Accounting
- Security
- Administrative services
These providers may process personal information as necessary to provide services to Derived.
Professional Advisers
We may disclose information to attorneys, accountants, auditors, consultants, insurers, and other professional advisers where reasonably necessary.
Legal and Regulatory Requirements
We may disclose information when we reasonably believe disclosure is necessary or appropriate to:
- Comply with applicable laws or regulations
- Respond to subpoenas, court orders, or other lawful legal processes
- Respond to lawful government or regulatory requests
- Protect our rights, property, or interests
- Protect the rights, property, safety, or security of others
- Investigate suspected fraud or unlawful activity
- Prevent security incidents
- Enforce our agreements or policies
- Satisfy regulatory, banking, network, or compliance obligations
Business Transactions
If Derived is involved in a merger, acquisition, financing, reorganization, sale of assets, change of control, bankruptcy, or similar business transaction, personal information may be disclosed or transferred as part of that transaction, subject to applicable law.
6. Payment Processors, Banks, and Third-Party Providers
Derived may assist businesses in obtaining products or services from third-party payment processors, acquiring banks, financial institutions, point-of-sale providers, software companies, and other technology or service providers.
These organizations are separate from Derived and may independently determine how they collect, use, retain, secure, and disclose information.
When you provide information directly through a third party's website, application, portal, or other system, that information may be subject to that third party's privacy policy and terms.
Derived is not responsible for the independent privacy practices of third parties.
We encourage you to review the privacy policies and terms of any applicable third-party providers.
7. Cookies and Similar Technologies
At the effective date of this Privacy Policy, the website uses technologies necessary to operate, secure, and remember the state of requested website functions.
These technologies and embedded services may support:
- Form security and abuse prevention through Cloudflare Turnstile
- Hosting, request processing, and security logging through Vercel
- Secure lead intake and statement storage through Supabase
- Requested scheduling and lead follow-up through GoHighLevel
- Short-lived browser storage used to preserve form progress and attribution information
- Optional website measurement through Google Analytics after you allow analytics
The embedded scheduling provider may set or read its own cookies or similar technologies when you load or use the scheduling tool. Its independent practices are governed by its own privacy terms.
Google Analytics does not load until you select Allow analytics. If you allow it, Google Analytics may use first-party cookies or browser storage to distinguish visits and measure page views, navigation, calculator completion, and successful request types. Derived does not send names, email addresses, telephone numbers, business names, uploaded statements, or form answers to Google Analytics.
You can review or change this choice at any time through the Analytics choices link in the website footer. Declining optional analytics does not prevent you from using the website or submitting a request.
Most web browsers allow you to manage, block, or delete cookies and browser storage. Blocking technologies required for security or requested functionality may prevent portions of the website from working.
If Derived later enables advertising or other non-essential measurement technologies, we will update this Privacy Policy and provide any notices or choices required by applicable law before using them.
8. Analytics and Advertising
Derived uses Google Analytics 4 to understand aggregate website traffic and whether visitors use key tools or complete requests. The Google tag loads only after you allow analytics. Advertising storage, advertising user data, advertising personalization, Google Signals, and ad-personalization signals remain disabled through the website's configuration.
Analytics events may include the page path, referring page, general device and browser information, approximate location derived by Google, selected call-to-action destination, calculator completion, and the type of successfully submitted request. Analytics events do not include the contents of a statement, contact fields, or other form answers.
Google processes Analytics data under its own terms and privacy documentation. Derived uses the resulting reports to evaluate site navigation, content, and lead funnels.
Derived does not use third-party advertising pixels, targeted-advertising cookies, or Google Analytics for personalized advertising on this website.
Hosting, security, and embedded scheduling providers may still process technical request information necessary to provide and protect their services.
9. Text Messages and SMS Communications
If you provide a mobile telephone number and agree to request-related contact, Derived may text you only to respond to the inquiry, quote request, statement review, application, appointment, support request, or other service interaction you initiated.
Submitting a website form does not enroll you in promotional or recurring marketing text messages.
Message frequency for request-related texts varies with the interaction. Message and data rates may apply. Reply STOP to opt out or HELP for assistance.
If Derived later offers promotional text messages, enrollment will require a separate consent that is not a condition of purchasing goods or services.
We may provide information to vendors and service providers as necessary to deliver requested messages, maintain consent and opt-out records, prevent fraud, and provide customer support.
Additional terms governing text messaging are contained in our Terms & Conditions.
10. Email and Marketing Communications
Derived may email you about an inquiry, application, appointment, account, requested service, support matter, merchant relationship, partner relationship, or other interaction you initiated.
Submitting a website form does not subscribe you to promotional email marketing.
If Derived later offers promotional email subscriptions, promotional messages will include an unsubscribe mechanism where required. Opting out of promotional messages does not prevent non-promotional communications reasonably necessary to address a request, account, application, transaction, security matter, support request, or existing business relationship.
11. Sale and Sharing of Personal Information
Derived does not sell personal information for monetary consideration.
At the effective date of this Privacy Policy, Derived does not disclose personal information for cross-context behavioral advertising or targeted advertising through this website.
If a future practice constitutes a “sale,” “sharing,” or targeted advertising under an applicable privacy law, Derived will update this Privacy Policy and provide eligible individuals with any legally required opt-out mechanism.
12. Your Privacy Rights
Depending on your state of residence and applicable law, you may have certain rights concerning your personal information.
These rights may include the right to:
- Confirm whether we process your personal information
- Request information about personal information we collect
- Request access to certain personal information
- Request correction of inaccurate personal information
- Request deletion of certain personal information
- Obtain a portable copy of certain personal information
- Opt out of certain sales or sharing of personal information
- Opt out of targeted advertising
- Limit certain uses or disclosures of sensitive personal information where applicable
- Appeal certain decisions regarding privacy requests
- Receive equal service and pricing without unlawful discrimination for exercising applicable privacy rights
These rights are subject to exceptions, limitations, and eligibility requirements under applicable law.
We may need to verify your identity before processing certain privacy requests.
Where permitted by law, an authorized agent may submit a request on your behalf. We may require reasonable verification of the agent's authority and your identity.
13. U.S. State Privacy Rights
Residents of certain U.S. states may have additional privacy rights under applicable state privacy laws.
Where an applicable state privacy law applies to Derived and to the individual making the request, we will honor legally required rights concerning personal information.
These may include rights relating to:
- Access
- Correction
- Deletion
- Data portability
- Sale or sharing of personal information
- Targeted advertising
- Certain sensitive personal information
- Appeals of privacy-request decisions
The specific rights available to you depend on your state of residence, the type of personal information involved, the nature of your relationship with Derived, and whether the applicable law applies to Derived.
We will not unlawfully discriminate against an individual for exercising an applicable privacy right.
14. Global Privacy Control and Opt-Out Preference Signals
Certain browsers and browser extensions allow users to send privacy preference signals, including Global Privacy Control ("GPC").
Where required by applicable law and applicable to our data-processing activities, Derived will recognize and process legally required opt-out preference signals in accordance with applicable requirements.
15. Data Retention
Derived retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to active business relationships and legal, regulatory, contractual, dispute, fraud-prevention, security, tax, accounting, banking, payment-network, and compliance obligations.
Website quote, contact, partner, and similar lead-intake records are ordinarily retained for up to 24 months from the most recent relevant interaction. A record may be retained longer if the person or business has an active application, merchant, partner, support, or other business relationship with Derived, or if a longer period is reasonably required for the obligations described above.
Processing statements uploaded for a requested review are ordinarily retained for up to 90 days. A statement may be retained longer when it is attached to an active application or business relationship, when you ask us to retain it for continued service, or when a longer period is reasonably required for legal, regulatory, contractual, dispute, fraud-prevention, security, or compliance purposes.
When information is no longer needed, Derived will delete, de-identify, or otherwise dispose of it in a manner appropriate to the nature of the information and the systems in which it is maintained.
16. Data Security
Derived uses reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, loss, misuse, alteration, or destruction.
We also seek to use service providers and technology providers appropriate for the nature of the information and services involved.
However, no website, network, database, storage system, electronic transmission, or security system can be guaranteed to be completely secure.
Accordingly, we cannot guarantee the absolute security of information transmitted to, from, or maintained by Derived or third-party providers.
17. Third-Party Websites and Services
Our website, communications, or services may contain links to or integrations with third-party websites, applications, platforms, portals, products, or services.
Derived does not control and is not responsible for the privacy, security, content, or information-handling practices of independent third parties.
Your interactions with third-party services are subject to the applicable third party's privacy policies, terms, and practices.
We encourage you to review those policies before providing personal information.
18. Children's Privacy
Derived's website and services are intended for businesses and adults and are not directed to children under the age of 13.
We do not knowingly collect personal information from children under 13 through our website.
If we become aware that we have collected personal information from a child under 13 in circumstances prohibited by applicable law, we will take reasonable steps to delete the information.
19. Do Not Track
Some web browsers provide a "Do Not Track" setting or signal.
Because there is not currently a universally accepted standard governing traditional Do Not Track signals, our website may not respond to those signals.
This is separate from legally recognized opt-out preference signals, such as Global Privacy Control, which we process where required by applicable law.
20. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our business, services, technologies, privacy practices, or legal requirements.
When this Privacy Policy is updated, we will revise the "Last Updated" date at the top of this page.
Where required by applicable law, we may provide additional notice regarding material changes.
We encourage you to review this Privacy Policy periodically.
21. Contact Us
If you have questions about this Privacy Policy, our privacy practices, or would like to submit a privacy-related request, please contact:
For privacy requests, please provide sufficient information for us to identify and respond to your request.
We may request additional information when reasonably necessary to verify your identity or your authority to make a request on behalf of another individual.
