Effective Date: February 23, 2024

Brightfin Inc. Privacy Policy

At Brightfin Inc., (“Brightfin”, “Company”, “we”, “our” or “us”), we value your trust. We are committed to acting responsibly when we collect, use and protect your non-personal and personal information.

We believe in being clear and open about how we collect data related to you when you visit our website at www.brightfin.io (the “Website”), download, access and /or use the mobile application named: Brightfin (“App”) (collectively, the "Platform") use our products and services to obtain money advice and education related to the allocation of spending and saving, read our blogs, interact with us, participate in delivery of emails, including promotional, marketing and transactional materials, delivery of other promotional materials, including via postal mailers, participate in our surveys or engage with any other pages, features, or content we own, operate and/or provide, (collectively with the Website and App the “Services”).

Federal and state laws say that we must tell you how we collect, share and protect your personal information. This Privacy Policy (“Privacy Policy”) is designed to help you understand how we collect, use, share and safeguard the information you provide to us and to assist you in making informed decisions when using our Services. Please read this Privacy Policy very carefully.

By accepting our Privacy Policy/accessing and using the Services, you consent to our collection, storage, use and disclosure of your Personal Information as described in this Privacy Policy and the Cookie Policy located at https://brightfin.io/cookie-policy (“Cookie Policy”). The Services are intended for users located in the United States only, and you hereby expressly acknowledge and agree that if you are accessing and/or using the Services that you reside in the United States and will only access and/or use the Services in the United States. The use of the Website and/ or App is subject to the Terms of Use located at https://brightfin.io/terms-of-use.

1. Types of Data We Collect

We collect “Non-Personal Information” and “Personal Information” and the information we collect from you depends on how you use the Services – for example, when you register to use the Services, when you link your third-party financial accounts, or when you fill out forms or other fields on our Platform. “Non-Personal Information” includes information that cannot be used to personally identify you, such as anonymous usage data, general demographic information we may collect, referring/exit pages and URLs, platform types, preferences you submit and preferences that are generated based on the data you submit and number of clicks. “Personal Information” means data that allows someone to identify or contact you, including, for example, your name, address, telephone number, email address, as well as any other non-public information about you that is associated with or linked to any of the foregoing data. This includes:

Context

Types of Data That We May Collect

Primary Purpose for Collection
and Use of Data

Website User Information

We collect your name, email address and age if you contact us.

We have a legitimate interest in contacting our customers and communicating with them in relation to the Services.

App User Information

We may collect your:

- Name

- Email address

- Phone number

- Zip code

- Mailing address

- Date of birth

- Age, gender, or other similar demographic information

- Employment information

- Education information

- Self-reported information such as salary, financial habits and attitudes, as well as specific money questions

We have a legitimate interest in contacting our customers and communicating with them in relation to the Services.

Specifically, we may use your e-mail address or other personal information (a) to contact you for administrative purposes such as customer service, (b) to address intellectual property, right of privacy or defamation issues related to content you have posted on the Services, and/or (c) to send you promotional materials, offers, and/or messages related to the Services.

Account Information

If you download and set up an account through Services, we collect your:

- Name

- Mailing address

- Phone number

- Email address

We have a legitimate interest in contacting our customers and communicating with them in relation to the Services.

Your information is an integral part of our operations, and we use it in a variety of ways in providing the Services and operating the business. We use the information to: (a) provide you the Services you request; (b) to operate, maintain and improve the Services and create new features and functionality; (c) to understand and analyze usage trends and preferences of our users across different devices; (d) for fraud detection and information security; (e) we may use your e-mail address or other personal information (1) to contact you for administrative purposes such as customer service, (2) to address intellectual property, right of privacy or defamation issues related to content you have posted on the Services, and/or (3) to send you promotional materials, offers, and/or messages related to the Services.

Cookies and First Party Tracking

We use Cookies and clear GIFs. “Cookies” are small pieces of information that a website sends to a computer’s hard drive, smartphone or other personal device while a website is viewed. See our Cookie Policy for more information on how we use Cookies. https://brightfin.io/cookie-policy

We use Google Analytics for Firebase as an in-App analytics service. Firebase's Privacy and Security Terms can be found here: https://firebase.google.com/support/privacy

We have a legitimate interest in making the Services operate efficiently.

We have a legitimate interest in making the App operate efficiently and to collect information about your use of the App so we can provide advertising about products and services tailored to your interests.

Email Interconnectivity

If you receive email from us, we may use certain tools to capture data related to when you open our message, click on any links or banners it contains and make purchases.

We have a legitimate interest in understanding how you interact with our communications to you.

Feedback/Support

We collect Personal Information from you contained in any inquiry you submit to us regarding the Services, such as completing our online forms, calling or emailing for the purposes of general inquiries, support requests, or to report an issue.

When you communicate with us over the phone, your calls may be recorded and analyzed for training, quality control and for sales and marketing purposes. During such calls we will notify you of the recording via either voice prompt or script and advise you of our privacy policies.

We have a legitimate interest in receiving, and acting upon, your feedback, issues, or inquiries.

E-mailing and Mailing Lists

When you sign up for our e-mailing list, we collect your first and last name and e-mail address. When you sign up for one of our mailing lists, we collect your first and last name and postal address.

We share information about our products and services with individuals that consent to receive such information. We also have a legitimate interest in sharing information about our products and services.

Mobile Devices

We collect information from your mobile device such as unique identifying information broadcast from your device when using the Services and use app analytics.

We have a legitimate interest in identifying unique visitors, and in understanding how users interact with us on their mobile devices.

App Interactions

We use technology to monitor how you interact with the Services. This may include: IP addresses, preferences, web pages you visited prior to using the Services, information about your network or device (such as operating system, hardware and software settings and configurations, internet service provider, preference settings, unique device IDs and language and other regional settings), information about how you interact with the Services (such as timestamps, browsing times, and transactions).

We have a legitimate interest in understanding how you interact with the Services to better improve the Services, and to understand your preferences and interests and to select offerings that you might find most useful. We also have a legitimate interest in detecting and preventing fraud.

App Logs

We collect information, including your device type, operating system, hardware and software settings and configurations, Internet Protocol (“IP”) address (a number that is automatically assigned to a mobile device when the Internet is used) or other device address or ID, domain name, and/or a date/time stamp for visitors.

We have a legitimate interest in monitoring networks and the visitors to our App and access and use of the Services to provide the Services and enhance the Services.

Social Media Connectors

Our Website and App use social media connectors. They are social media buttons you see on our Websites and App or linked posts that allow you to connect and learn more about us and interact with us and our users.

To learn more about the social media’s privacy policies, please read their respective privacy policies on their websites.

We may engage in behavior-based advertising, capturing website and mobile application analytics and engaging third parties to assist with providing Services that may be of interest to you.

Demographic Information

We may collect personal information, such as your age or location, including if you use the Platform on a mobile device.

We have a legitimate interest in understanding our users and providing tailored Services.

Geographic Information

When you use our App and Services we collect your location from the GPS, Wi-Fi, and/or cellular technology in your device to determine your location to better serve you.

We have a legitimate interest in understanding our users and providing tailored Services. In some contexts, our use is also based upon your consent to provide us with geo- location information.

Surveys

When you participate in a survey, we collect information that you provide through the survey. If the survey is provided by a third-party service provider, the third party’s privacy policy applies to the collection, use, and disclosure of your information.

We have a legitimate interest in understanding your opinions and collecting information relevant to our organization and the Services.

Financial Account Information

We may collect but do not store your third-party financial account information, such as ID and Password. We securely pass this information to our third-party partners when you request Services that require us to confirm your identity, and/or provide you with access to your financial information on the App.

We may store historical data related to account balances in order to provide you Services.

We have a legitimate interest in using this information to provide the Services and in making the App operate efficiently.

Transactions Information

We collect transactions information, including your account balances and a 3-month history of transaction data when you connect any financial institution.

We have a legitimate interest in using this information to provide you the Services and to select offerings that you might find most useful.

2. Children’s Online Privacy Protection Act (“COPPA”)

Our Services are not designed for children under 13, and we do not intentionally or knowingly collect Personal Information from users who are under the age of 13 or from other websites or services directed at children. If we discover that a child under 13 has provided us with Personal Information, we will delete such information.

3. Information You Provide to Us

We collect Personal Information from you such as your first and last name, e-mail, mailing address, phone, username, and password when you choose to subscribe to our Services/ set up an account through the Services. We may also collect date of birth, age, gender, or other similar demographic information, employment information and education information.

• When you engage us to provide Services, additional information may be necessary. Such information may include self-reported information such as salary, financial habits and attitudes, specific money questions, links to your financial accounts, and account balances, as well as transaction data.

• We may also collect your name, email address, and other information in connection with a refer a friend program, or to provide specific pieces of content via email or in-app that you may find helpful.

• If you provide us feedback or contact us via email, we may collect your name, if stated, and email address, as well as any other content included in the email, in order to send you a reply.

• When you participate in one of our surveys, we may collect additional information that you knowingly provide.

• We will maintain the information you send via email in accordance with applicable federal law.

• In compliance with the CAN-SPAM Act, all emails sent from our organization will clearly state who the email is from and provide clear information on how to contact the sender. In addition, all email messages will also contain concise information on how to remove yourself from our mailing list so that you receive no further e-mail communication from us.

4. Collected via Technology

• In an effort to improve the quality of the Services, we reserve the right to track information provided to us by your browser or by our software application when you view or use the Services, such as the website you came from (known as the “referring URL”), the type of browser you use, the device from which you connected to the Services, the time and date of access, and other information that does not personally identify you. We track this information using Cookies. Cookies are sent to a user’s browser from our servers and are stored on the user’s computer hard drive or mobile device. Sending a Cookie to a user’s browser enables us to collect Non-Personal information about that user and keep a record of the user’s preferences when utilizing our Services, both on an individual and aggregate basis. Please review the Cookie Policy for more information: https://brightfin.io/cookie-policy.

• We may use third-party analytics services such as Firebase to collect information about how you use and interact with our Services. Such third-party analytics services may use Cookies to gather information such as the pages you visited, your IP address, a date/time stamp for your visit and which website referred you to the Platform.

• We may use third-party financial services such as Plaid to receive transaction and balance information when you request to log in to your financial accounts and use our Services. We do not receive your financial account IDs or passwords at any time.

• We reserve the right to use technological equivalents of Cookies, including social media pixels. These pixels allow social media sites to track visitors to outside websites so as to tailor advertising messages users see while visiting that social media website. We reserve the right to use these pixels in compliance with the policies of the various social media sites.

• Some content or applications on the Platform are served by third parties, including servers, content providers, and application providers. These third parties may use Cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our Services. The information they collect may be associated with your Personal Information or they may collect information, including Personal Information, about your online activities over time and across different websites and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content. We do not control these third parties' tracking technologies or how they may be used and we are not liable for any third party providers, acts or omissions. If you have any questions about an advertisement or other targeted content, you should contact the third-party provider directly.

5. Information We Obtain From Other Sources

Our third-party service providers, affiliates, data analytics providers, advertising networks, internet service providers, operating systems and platforms and social networks may also provide us information about you. We may also collect information from publicly available sources. For example, if you submit a job application, or become an employee, we may conduct a background check.

6. Use of Your Personal Information

In general, Personal Information you submit to us is used either to respond to requests that you make, or to aid us in serving you better. We use your Personal Information in the following ways:

• to facilitate the creation of and secure your account;

• to provide you Services as you request;

• to send you rewards if you participate in our referral program;

• to identify you as a user in our system;

• to establish an account on the App;

• to provide improved administration of the Services and create new features and functionality;

• to improve the quality of experience when you interact with the Services;

• to address intellectual property, right of privacy or defamation issues related to content you have posted on the Services;

• to send you administrative email notifications, such as security or support and maintenance advisories;

• to respond to your inquiries related to your requests;

• to periodically send newsletters, surveys, offers, and other promotional materials related to our Services and for other marketing purposes;

• to perform marketing or data analysis;

• to comply with legal obligations, as part of our general business operations, and for other business administration purposes; and

• in very limited circumstances where we believe necessary to investigate, prevent or act regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person or violations of this Privacy Policy.

7. Use of Non-Personal Information

In general, we use Non-Personal Information to help us improve the Services and customize the user experience. We also aggregate Non-Personal Information in order to track trends and analyze use patterns on the Services. This Privacy Policy does not limit in any way our use or disclosure of Non-Personal Information and we reserve the right to use and disclose such Non-Personal Information to our partners, advertisers and other third parties at our discretion.

8. How We Share Your Personal Information

As a general rule, we do not sell, rent, lease or otherwise transfer any information collected either automatically or through your voluntary action. We may disclose your Personal Information as described below and as described elsewhere in this Privacy Policy.

A. Third Party Service Providers. We may share your Personal Information with third party service providers to provide you with the Services that we offer you; to conduct quality assurance testing; to perform marketing; to run data analysis; to facilitate creation of accounts; to provide technical support; and/or to provide future services to you. Specifically:

• we may disclose your information in connection with providing the Services and the operation of our business. For example, we share Personal Information, such as name and location, and financial information, such as accounts and balances, with licensed third-party advisors providing the Services You have the option to refuse any free consultations or offers for services provided after you submit a request to a third party through the Services;

• we may share your information with third-party service providers to support our internal and business operations. In such cases, service providers may use the information only as necessary to provide the services to us and are contractually required to keep your information confidential and secure. For example:

o for web platform, application development, hosting, data storage, maintenance, and other services for us.

o for internal marketing, delivery of emails, including promotional, marketing and transactional materials, delivery of other promotional materials, including via postal mailers, and online and social media promotions and advertising.

o for fraud prevention and security purposes;

• when you choose to share your own information on a publicly accessible area of the Platform, such as a section where you can publicly submit questions to us or our third-party partners, that information will be available to anyone who is able to access that content, including other Platform users. Additionally, questions you submit and answers provided by licensed third-party advisors may be posted on our Platform and viewable by other users and the public. You may also choose to share your own information on a non-publicly accessible, private area of the Platform, where you can privately submit questions to us or our third-party partners;

• we may share deidentified and/or aggregate analytics with third-party partners about how users interact with our Services, including usage patterns for certain programs, content, services, promotions, and/or functionality available through the Services;

• by submitting a request through our Services, you consent to the disclosure of your information to third parties in order for us to carry out your request. The collection and use of your information by third parties is subject to each third party’s specific privacy policy and terms of use. Brightfin has no control over the means by which third parties further use or disclose your information;

The third-party service providers we are engaged with and/or third-party products and/or services we use to provide the Services include without limitation:

• Plaid for financial accounts and transactions. Plaid's End User Privacy Policy can be found here: https://plaid.com/how-we-handle-data/

• Firebase for Cloud storage and App analytics. Firebase's Privacy and Security Terms can be found here: https://firebase.google.com/support/privacy

Do not submit a request for information or services if you do not want your Personal Information shared as described herein. Once you have submitted a request through the Services and we have shared your information as described above, the terms of the third party’s privacy policy will apply to that party’s use of your information. You may, of course, decline to share certain information with us, in which case we may not be able to provide to you some of the features and functionality of the Services.

B. Integrations and Third-Party Services. We integrate third-party Application Programming Interface (“API”) in connection with the Services that we offer you. The information collected by Brightfin when using the API, is processed in compliance with this Privacy Notice. Information collected by third-party API partners is governed by their privacy policies and Brightfin does not own or control those third parties.

C. Process Payments. Our payment processing partner is the Apple Inc. App Store (“Apple”). More information about Apple’s policies related to privacy can be found here: http://www.apple.com/legal/internet-services/itunes/.

D. Business Transfers. If (i) Brightfin is acquired by, merges with, or receives investment from another company or (ii) if any of the Brightfin’s assets are or may be transferred to another company, whether as part of a bankruptcy or insolvency proceeding or otherwise, we may transfer the information we have collected from you to the other company. As part of the business transfer process, we may share certain of your Personal Information with lenders, auditors, attorneys and consultants.

E. Other Disclosures. Regardless of any choices you make regarding your Personal Information (as described below), we may disclose Personal Information if we believe in good faith that such disclosure is necessary (a) in connection with any legal investigation; (b) to comply with relevant laws or to respond to subpoenas or warrants served on us; (c) to protect or defend our rights or property, or the rights or property of users of the Services; (d) to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person and/or (e) to investigate or assist in preventing any violation or potential violation of the law, this Privacy Policy, or any agreements you may have with us, as applicable.

9. Links to Third Party Websites and Third-Party Providers

As part of the Services, we may provide links to or compatibility with other websites or applications; however, we are not responsible for the privacy practices employed by those websites or the information or content they contain nor are we liable for third party products, services, acts and/or omissions. This Privacy Policy applies solely to information collected by us in relation to the Services and your use of the Services. Therefore, this Privacy Policy does not apply to your use of a third-party website accessed by selecting a link on our Platforms or via the Services. To the extent that you access or use the Services through or on another website or application, then the privacy policy of that other website or application will apply to such access and/or use. We encourage our users to read the privacy statements of other websites before proceeding to use them.

10. Updating Your Membership Information, Canceling Your Membership, Deactivating or Deleting Your Account

A. Updating Your Information

Once you have registered for a Brightfin account, you may update or correct your profile information and preferences at any time by accessing your account settings page through the Platform.

B. Deactivating Your Account

We do not delete information about you upon deactivation of your account. Although your deactivated status is reflected promptly in our user databases, we may retain the information you submit for a variety of purposes, including legal compliance, backups and archiving, prevention of fraud and abuse, and analytics. Upon deactivation, you will no longer receive emails from Brightfin and links to third-party financial accounts, and Services will automatically terminate.

C. Deleting Your in-App Account

If you decide to delete your in-App account, you may do so by selecting “Delete My Account” on your profile page. Deleting your Brightfin account in-App will:

• Sign you out immediately;

• Remove or anonymize any identifiable user information;

• Remove your email from our mailing lists.

You will receive an email when account deletion is completed.

11. Promotional and Marketing Communications

We may send periodic promotional emails to you. You have the right at any time to prevent us from contacting you for marketing purposes. If you do not wish to receive email offers or newsletters from us, you can opt out of receiving email information from us (except for emails related to the completion of your registration, correction of user data, change of password, and other similar communications essential to your transactions through the Services) by using the unsubscribe process at the bottom of any marketing email from us. Although your changes are reflected promptly in active user databases, we may retain all information you submit for a variety of purposes, including backups and archiving, prevention of fraud and abuse, and analytics. Please note that it may take up to 10 business days for us to process unsubscribe requests.

12. Your Rights and Choices

If applicable privacy laws allow, you may have rights over your Personal Information. This includes, but is not limited to:

• Right to Know. You have the right to request disclosure about our Personal Information collection practices during the prior 12 months, including the categories of Personal Information we collected, the sources of the information, our business purposes for collecting or sharing the information and the categories of third parties with whom we shared such information. You may request a copy of the specific pieces of Personal Information we may have collected about you in the last 12 months.

• Right to Delete. You may request that we delete (and direct our service providers to delete) your Personal Information, subject to certain exceptions.

• Right to Opt-Out. You have the right to opt-out of any ‘sales’ of your Personal Information, if a business is selling your information. For clarity, we do not sell your Personal Information.

• Non-Discrimination. You have the right to not be discriminated against for exercising these rights.

You can make the following choices regarding your Personal Information:

1. Access To Your Personal Information. You may request access to your Personal Information by contacting us at the address below. If required by law, upon request, we will grant you reasonable access to the Personal Information that we have about you. We will provide this information in a portable format, if required. Note that California residents may be entitled to ask us for a notice describing what categories of Personal Information (if any) we share with third parties or affiliates for direct marketing.

2. Changes To Your Personal Information. We rely on you to update and correct your Personal Information. Please contact us at the address below immediately if there are any changes to your Personal Information. Note that we may keep historical information in our backup files as permitted by law.

3. Deletion Of Your Personal Information. Typically, we retain your Personal Information for the period necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law, or as otherwise described in this Privacy Policy. You may, however, request information about how long we keep a specific type of information, or request that we delete your Personal Information by contacting us at the address below. If required by law we will grant a request to delete information, but you should note that in many situations we must keep your Personal Information to comply with our legal obligations, resolve disputes, enforce our agreements, or for another one of our business purposes.

4. Objection to Certain Processing. You may object to our use or disclosure of your Personal Information by contacting us at the address below.

5. Online Tracking. We do not currently recognize automated browser signals regarding tracking mechanisms, which may include ‘Do Not Track’ instructions.

6. Promotional Emails. You may choose to provide us with your email address for the purpose of allowing us to send free newsletters, surveys, offers, and other promotional materials to you. You can stop receiving promotional emails by following the unsubscribe instructions at the bottom of any marketing e-mails that you receive from us. If you decide not to receive promotional emails, we may still send you communications related to your use of the Services and administrative purposes for reasons such as providing you with updates to this Privacy Policy, and we may retain all information you submit for a variety of purposes, including backups and archiving, prevention of fraud and abuse, and analytics. Please note that it may take up to 10 business days for us to process unsubscribe requests.

7. Revocation Of Consent. If you revoke your consent for the processing of Personal Information, then we may no longer be able to provide you some of the features and functionality of the Services. In some cases, we may limit or deny your request to revoke consent if the law permits or requires us to do so, or if we are unable to adequately verify your identity. You may revoke consent to processing (where such processing is based upon consent) by contacting us at the address below.

If you make a request, unless specifically stated above, we have 30 calendar days to respond to you. If you would like to exercise any of these rights, please contact us at our email: support@brightfin.io or send correspondence via mail to:

Brightfin Inc.

3024 N. Ashland Ave. #578632

Chicago, IL 60657

13. Security of Your Personal Information

We implement security measures designed to protect your information from unauthorized access, alteration, disclosure and/or destruction. Some of those security measures include, but are not limited to, iOS standard encryption, API key protection of access to Firebase and SSL-encrypted access of data through Firebase. Because the internet is not a completely secure environment, we cannot warrant the security of any information a user transmits to us or guarantee that information on the Services may not be accessed, disclosed, altered, and/or destroyed by breach of any of our physical, technical and/or managerial safeguards. Any account you have on our App is protected by your account password and we urge you to take steps to keep your Personal Information safe by not disclosing your password and by logging out of your account after each use. We further protect your information from potential security breaches by implementing certain technological security measures; however, these measures do not guarantee that your information will not be accessed, disclosed, altered or destroyed by breach of such firewalls and secure server software. While we use reasonable efforts to protect your Personal Information, we cannot guarantee the Services are absolutely secure.

14. How we Retain Your Personal Information

We will retain your Personal Information for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. The precise periods for which we keep your Personal Information vary depending on the nature of the information and why we need it. To determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorized use and/or disclosure of your Personal Information, the purposes for which we process your Personal Information and whether we can achieve those purposes through other means, and the applicable legal requirements.

In some circumstances we may anonymize your Personal Information (so that it can no longer be associated with a user) for research or statistical purposes in which case we may use this information indefinitely without further notice. We may retain information (including without limitation your personally identifiable information) for a commercially reasonable time for backup, archival, audit purposes, and/or to comply with legal obligations, resolve disputes and enforce agreements. In some cases, if you choose not to provide us with requested information, you may not be able to use the Services. You can request further details of retention periods for different aspects of your Personal Information by contacting us.

Please note that in the course of providing the Services, we collect and maintain aggregated, anonymized, or de-personalized information which we may retain indefinitely.

15. Accessibility

If you are visually impaired, you may access this Privacy Policy through your browser’s audio reader.

16. Changes to This Privacy Policy

We reserve the right to change this Privacy Policy or any agreement you entered into with Brightfin from time to time. We may notify you of material changes to this Privacy Policy by sending a notice to the primary email address specified by you or by placing a prominent notice on the Platform. Such changes or clarifications will take effect immediately upon posting of the updated Privacy Policy or Terms of Use on the Platform. You should periodically check the Platform and this Privacy Policy for updates. Our Privacy Policy includes a “created” or “last updated” date. The last updated date refers to the date that the current Privacy Policy was last substantively modified. If you do not consent to our privacy practices as described in the revised version of the Privacy Policy, please do not use the Services in any manner, and we will continue to treat previously collected information in accordance with the privacy practices described in the applicable, prior version of this Privacy Policy or as otherwise required by applicable law. For the avoidance of doubt, disputes arising hereunder will be resolved in accordance with the Privacy Policy in effect at the time the dispute arose.

17. Other Jurisdictions

Brightfin is located in the United States. The Services are hosted in and provided from the United States, and intended for those that reside in the United States. Personal information that you submit through the Services may be transferred outside of the jurisdiction in which you live. We also store Personal Information locally on the devices you use to access the Services. Your Personal Information may be transferred to other jurisdictions that do not have the same data protection laws as the jurisdiction in which you initially provided the information. The following provisions may apply to you depending on where you are located.

Nevada

This notice is provided to you pursuant to state law. Nevada state privacy laws permit us to make marketing calls to existing users, but if you prefer not to receive marketing calls, you may be placed on our internal opt-out list by emailing us at support@brightfin.io or you may also contact the Nevada Bureau of Consumer Protection, Office of the Nevada Attorney General, 555 E. Washington St., Ste 3900, Las Vegas, NV 89101; telephone 702-486-3132; email: AGCinfo@ag.nv.gov. We do not make marketing calls to existing users.

Although we do not currently conduct sales of personal information, Nevada residents may submit a request directing us to not sell personal information we maintain about them if our practices change in the future. To exercise this right, email us at support@brightfin.io with the subject line: “Nevada: Request to Opt-Out.”

Vermont

In accordance with Vermont law, we will not share information we collect about you with companies outside of Brightfin except as authorized by you or otherwise required or permitted by law.

Virginia

At this time, the Virginia Consumer Data Protection Act does not apply to us, but we will still protect your Personal Information as outlined in this Privacy Policy. If you feel this is incorrect, please contact us at support@brightfin.io.

California

At this time, California Privacy laws (California Consumer Privacy Act, California Privacy Rights Act) do not apply to us, but we will still protect your Personal Information as outlined in this Privacy Notice. If you feel this is incorrect, please contact us at support@brightfin.io.

18. Contact Information

If you have any questions, comments, or complaints concerning our Privacy Policy or privacy practices, please contact us by sending an email to support@brightfin.io or send correspondence via mail to:

Brightfin Inc.

3024 N. Ashland Ave. #578632

Chicago, IL 60657

We will attempt to respond to your request and to provide you with additional privacy-related information.