Last Revised: December 24, 2013
Types of Personal Information We Collect Through The Site
You may browse our Site without creating an online account, but to use certain features you or your ISO may be required to create an account. When you create an account with us, we may collect your name, email address, contact information, a username and password that you will use to access your account and other information. In addition, to submit a question, comment, or post to a blog, you may be required to submit your name and email address, and we may also ask you for other optional information, such as your business’s website address.
We also collect information from you if you log into our Site through an account created with a third-party website (e.g., QuickBooks, Facebook, or LinkedIn). The option to access our Site via these third-party websites may occur and will be entirely at your option. The information we are able to migrate to our Site from these third-party websites will depend on the privacy settings that you have in place with the third-party site from which you log in. If you choose to log into the Site via a third-party website, you hereby consent to our access to and collection of such Personal Information about you. We also collect the following types of Personal Information through the Site:
- Business owner contact information (such as name, address, email address, and phone number) and individual job information (such as job title)
- Personal and financial information necessary to assess your eligibility to borrow money or invest through CAN Capital or one of its partners or ISOs
- Optional Personal Information you may wish to share in the furtherance of your loan application
- Information about your visits to and use of this Site or the websites of third-party servicers to help us maintain the appropriate features, functionality, and user experience
- Information to verify an individual’s identity (including social security number, user name and password, and other data elements such as driver’s license number and age or date of birth)
- Individual financial or credit bureau information (such as a business owner’s credit score, credit history, and bank account information)
- Personal Information contained in government filings or legal agreements (such as corporate formation agreements, business licenses, lease or loan agreements, and business tax returns)
- Information uploaded by users to our Site, such as your driver’s license, pictures of your business, and bank statements
- Any other Personal Information you submit or upload through our Site or to one of our email addresses
- Your or your business’s geolocation, through various GPS or other geolocator tools that use the IP address of your or your ISOs device to detect a user’s location
We may also append to the Personal Information collected through our Site data or an ISO’s new or other data that we receive from other sources, such as public records, demographic information, and other background information supplied by information services or third parties.
In addition, we automatically collect through our Site information that is often not personally identifying, such as the website from which you came to our Site and your IP address, browser type, and other information relating to the device through which you access the Site. We may combine this information with the Personal Information we have collected from you.
Information We Collect From You and About You
Some information collected from you is required and some is optional; some will remain private and some will be shared with third parties. Additional information may be gathered during your subsequent use of the Site, whenever you choose to provide it.
Certain Personal Information must be supplied to determine eligibility for loans and to verify and guard against potential fraud.
We will use this information to request a credit report from a credit bureau to determine your creditworthiness as well as to help assess your loan request in the context of your overall financial situation. We will also use your required and optional information to facilitate activities and transactions that need to occur during the lending process.
Additional Uses of Personal Information
We use the Personal Information you provide us and allow us access as described herein for the following purposes:
- Respond to requests or inquiries, and for similar, customer-service-related purposes
- Evaluate your business’s or customers’ eligibility for products provided by or through CAN Capital or its affiliates
- Effectuate or enforce a transaction or agreement
- Adjust offerings or services, provided by or through CAN Capital or its affiliates, to your business and to tailor the information we send or display to you
- Provide you with information about our company or products—provided by or through CAN Capital or its affiliates—that we believe you may find of interest, including marketing and promotional e-mails
- Authenticate visitors to our Site
- Improve our Site, offerings or services provided by or through CAN Capital or its affiliates
- Better understand how users access and use our Site, and offerings provided by or through CAN Capital or its affiliates, on an aggregated and individualized basis
Types of Disclosures of Personal Information
We may disclose Personal Information to third parties for the following purposes:
- To provide you with information relating to products or services that we believe you may find of interest
- In response to a subpoena or other legal process by a governmental entity or third party, or if otherwise required by law
- To protect or enforce our rights or property
- In the event of the sale or dissolution (bankruptcy) of assets, in whole or in part, of our business or any of its affiliates
- To third parties involved in the process of providing services to us or you or performing functions on our behalf, such as contractors, customer service providers (e.g., information technology or human resources consultants or service providers), credit bureaus, and collection agencies
- To our affiliates and subsidiaries for marketing purposes, or for product or service delivery
- To the ISO that referred you to us—for example, in connection with reporting on your progress in the application process or in connection with calculating or reporting on the commission due to the referral source or otherwise
- To our lenders, investors, partners, or auditors in the course of their review or auditing us
- To provide products or services requested
- To our vendors, who may use the information to further improve their database services to us
IMPORTANT: All business loans are currently made by WebBank, a Utah-chartered industrial bank, member FDIC, and if you request a loan through us, your Personal Information will be shared with WebBank. For information regarding WebBank’s privacy practices, please refer to http://www.webbank.com/webbank-privacy-notice. CAN Capital may, from time to time and in its sole discretion, elect to contract with one or more other bank(s) to underwrite loans. In such case, you will be notified of such bank(s) during the loan process.
Cookies and Analytics
Web Beacons. Web beacons are tiny graphics with a unique identifier, similar in function to cookies, which are used to track the online movements of Web users. In contrast to cookies, which are stored on your computer’s hard drive, Web beacons are embedded invisibly on webpages and may not be disabled or controlled through your browser.
Third Parties. As noted, we may also engage third parties, including without limitation, Google Analytics and Webtrends to track and analyze Site activity on our behalf. To do so, these third parties may place cookies or web beacons to track user activity on our Site. We use the data collected by such third parties to help us administer and improve the quality of the Site, analyze usage of the Site, and provide a more enhanced user experience on the Site, such as personalizing and delivering relevant offers and content based on user activity on the Site.
We may send you emails from time-to-time about information that we (or third parties) believe may be of interest to you. We may also send you news and offers from us or other third parties, which may include our newsletter or information about special offers, products or offerings, or other items.
If, at any time, you would like to stop receiving these promotional e-mails, you may follow the opt-out instructions contained in any such e-mail. Please note that it may take up to 10 business days for us to process opt-out requests. If you opt-out of receiving emails or promotions from us, we still may send you e-mails about your account, your application or any products or services you have requested or received from us, or for other customer service purposes.
CAN Capital takes reasonable steps to safeguard your personal and sensitive information through vigorous physical, electronic, and operational policies and practices. Data can only be read or written through defined service access points, the use of which is password-protected. The physical security of the data is achieved through a combination of network firewalls (there is no direct communication allowed between the database server and the Internet) and servers with operating systems, all housed in a secure facility. Access to the system is controlled.
Further, we also equip our servers with Secure Socket Layer (SSL) certificate technology to ensure that when you connect you are actually on our Site. SSL also ensures that all data entered into the web site is encrypted. To verify that SSL is being used, look for the key or padlock icon on your browser. For further encryption protection, we use a 128-bit secure browser for logins and transactions. Portions of our site also make use of “CAPTCHA” technology, which is a test that we use to ensure certain sensitive transactions are being initiated by a human and not by another computer. The test involves viewing a distorted image of a word that a computer would not be able to interpret and then entering in the text shown in the image. Finally, we subject our systems to periodic security audits to ensure that your information is thoroughly protected and secure.
Secure, Off-Site Hosting
We store all sensitive financial data such as social security numbers and bank accounts in a secure environment.
We also employ session time-outs to protect your account. You will be logged out of the Site automatically after a specified period of inactivity. This time-out feature reduces the risk of others being able to access your account if you leave your computer unattended.
Protection of Account Numbers
When we contact you about your account or to confirm a funds transfer, we only reference the last four digits of your social security number; this is done for your protection.
Your password is not known to any employee or third party with whom we may partner, and we will never ask for your password as a means of identifying yourself. You should never share your password with anyone, and if you ever receive an email purporting to come from us that asks for your password, you should immediately report this development to us at [email protected].
What You Can Do
In addition to our own substantial efforts, you can take several precautions to protect the security of your computer and Personal Information. For instance, you can start by using a complex/well-chosen password. You should avoid using any information that others can easily learn about you, such as a family member’s name or birthday; you can also use special characters in place of letters. We also recommend that you change your password frequently. You can also install and regularly update antivirus and firewall software to protect your computer or device from external attacks by malicious users. When you are finished with a session on our site, be sure that you log out and close the browser window.
If you use a computer that is accessed by other people, such as in a public library or Internet cafe, we recommend that you take special precautions to protect the security of your account and personal data. When you are finished using our site, you should log out completely, then close the browser window and clear the browser’s cache files.
You should also be aware of fraudulent attempts to gain access to your account information known as “phishing.” Phishing is a tactic used by scammers in which unsuspecting people are brought to a website by a genuine-looking email purporting to be from a legitimate company. The phony or “spoof” email takes the person to a website that looks legitimate but in fact is not. Either in the email itself or on this fake site, scammers will ask for login information to gain access to people’s accounts and withdraw their money. CAN Capital will never ask you for your login information in the context of any email. In general, you can protect yourself against phishing by never providing personal or login information via an email, instead, go the web site directly. You might also make it a habit to check the URL of a web site to be sure that it begins with the correct domain. You should always ensure the URL begins with http://www.cancapital.com or https://www.cancapital.com.
CAN Capital, Inc.
2015 Vaughn Road
Kennesaw, GA 30144
Fax: (212) 548-6172