Privacy Policy
Monarch Technologies, Inc.
Thank you for reading this post, don't forget to subscribe!Privacy Policy
Effective date: August 2026 · Last updated: August 14, 2026 · Version 1.5
Quick summary
This summary is provided for convenience only. It is not a substitute for the full Privacy Policy below, which governs.
- Who we are
- Monarch Technologies, Inc. (“Monarch,” “we,” “us,” “our”) — a financial technology and money movement company providing payment processing, money transmission, cash logistics, digital wallet, bill pay, tax collection, and commission disbursement services.
- What we collect
- Identity and contact details, government identifiers (SSN/ITIN/EIN), financial account and payment card data, transaction records, identity verification and screening results, device and usage data, and communications.
- Why we collect it
- To provide and settle payments, verify identity and comply with anti-money laundering and sanctions law, prevent fraud, service accounts, meet regulatory and audit obligations, and improve our services.
- Who we share it with
- Sponsor banks and financial institutions, card networks, processors and payment infrastructure providers, identity verification and screening vendors, service providers under contract, our merchants’ authorized agents, regulators and law enforcement where required, and parties to a corporate transaction.
- Do we sell your data?
- No. We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising. We have not done so in the preceding 12 months.
- How long we keep it
- As long as needed to deliver services, and thereafter for the periods required by financial recordkeeping law — generally five (5) years under the Bank Secrecy Act and ten (10) years under OFAC sanctions regulations, and longer where a specific law, audit, or legal hold requires it.
- Your rights
- Depending on where you live, you may have rights to access, correct, delete, port, limit, appeal, and opt out. See Section 12.
- Contact
- support@monarch.is · 1-805-316-7078 · Monarch Technologies, Inc., Attn: Privacy Officer, 17595 Harvard Ave, Ste C-711, Irvine, CA 92614
1.Scope of This Policy
Monarch Technologies, Inc. is a financial infrastructure company that simplifies the movement of money, whether digital or cash. Our services include payment processing, money transmission, automated tax collection and compliance, cash logistics, digital wallet services, bill pay, commission and payout disbursement, and peer-to-peer transfers.
This Privacy Policy describes how Monarch collects, uses, shares, retains, and protects personal information, and the privacy rights available to individuals. It applies to:
- Our websites, including monarch.is and any Monarch-operated subdomain, marketing site, or landing page;
- Our applications and portals, including merchant portals, agent and producer portals, wallet applications, and mobile applications;
- Our APIs and integrations, where personal information is transmitted to or from Monarch;
- Our offline interactions, including merchant applications and underwriting, cash logistics operations, telephone and email support, and events.
Who this policy covers
This policy addresses personal information about:
- Merchant principals
- Business owners, beneficial owners at 25% or more, control persons, authorized signers, and merchant employees who use Monarch systems.
- Consumers and cardholders
- Individuals who send, receive, or are the subject of a payment processed through Monarch, including wallet users, P2P senders and recipients, bill payers, and cardholders transacting with our merchants.
- Agents, ISOs, and producers
- Sales partners, independent sales organizations, referral partners, and other producers in our distribution and commission programs.
- Website visitors and prospects
- Individuals who visit our sites, request information, or communicate with us.
- Job applicants
- Individuals who apply for employment or contractor engagements with Monarch.
What this policy does not cover. This policy does not apply to (a) the privacy practices of merchants, banks, or other businesses that use Monarch’s services — their own privacy notices govern their handling of your information; or (b) third-party websites or services we do not control.
A note on information we process for others. Where Monarch processes personal information solely on behalf of a merchant, platform, or financial institution as its service provider or processor, that client — not Monarch — determines the purposes of the processing, and the client’s own privacy notice governs. Sections 2 and 15 describe that arrangement and where to direct a request. This policy describes how Monarch handles such information as a matter of transparency; it does not displace the client’s notice. Except where stated otherwise, the disclosures in Sections 4 through 14 describe personal information Monarch holds in its own right, as a business or controller.
Personal information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. It does not include deidentified, aggregated, or publicly available information as those terms are defined under applicable law.
2.Our Role: Controller, Service Provider, or Processor
Monarch’s privacy obligations depend on the context in which we receive personal information.
Monarch acts as a business / controller — determining the purposes and means of processing — when we:
- Onboard, underwrite, and manage merchant and partner relationships;
- Operate our own websites, marketing programs, and recruiting;
- Meet our independent legal obligations under the Bank Secrecy Act, sanctions law, money transmission licensing law, and card network rules;
- Manage our own risk, fraud, credit, and loss prevention programs;
- Administer commission, payout, and tax reporting programs for our producers.
Monarch acts as a service provider / processor — processing personal information only on documented instructions and only for the purposes specified in our contract — when we:
- Process a transaction on behalf of a merchant, including authorization, capture, settlement, refunds, and chargebacks;
- Deliver white-labeled wallet, bill pay, or payout functionality on behalf of a platform client or tenant;
- Perform cash logistics or reconciliation services for a client.
When Monarch acts as a service provider or processor, we do not retain, use, or disclose personal information for any purpose other than performing the services, except as permitted by law. We do not sell that information, do not combine it with personal information from other sources except as permitted by applicable law, and will notify the relevant client if we determine we can no longer meet our obligations.
If you are a consumer whose information reached Monarch through a merchant or platform, direct your privacy requests to that business in the first instance. If you contact us directly, we will forward your request to the relevant business or respond as that business’s contract and applicable law require. See Section 15.
3.Gramm-Leach-Bliley Act Financial Privacy Notice
Monarch is a financial institution for purposes of the Gramm-Leach-Bliley Act (“GLBA”) and its implementing regulations, including the Consumer Financial Privacy Rule (Regulation P, 12 C.F.R. Part 1016) and the Safeguards Rule (16 C.F.R. Part 314). This section constitutes Monarch’s privacy notice with respect to nonpublic personal information (“NPI”) about consumers who obtain financial products or services from Monarch primarily for personal, family, or household purposes.
3.1 What we collect
We collect NPI about you from the sources described in Section 5, including information you give us on applications and forms, information about your transactions with us and others, and information we receive from consumer reporting agencies, identity verification vendors, and other third parties.
3.2 Reasons we can share your personal information
- For our everyday business purposes
- Such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, report to credit bureaus, or comply with the Bank Secrecy Act and sanctions programs.
- Does Monarch share?Yes Can you limit this sharing?No
- For our marketing purposes
- To offer our products and services to you.
- Does Monarch share?Yes Can you limit this sharing?No
- For joint marketing with other financial companies
- Does Monarch share?No Can you limit this sharing?No
- For our affiliates’ everyday business purposes — information about your transactions and experiences
- Does Monarch share?No Can you limit this sharing?No
- For our affiliates’ everyday business purposes — information about your creditworthiness
- Does Monarch share?No Can you limit this sharing?No
- For our affiliates to market to you
- Does Monarch share?No Can you limit this sharing?No
- For nonaffiliates to market to you
- Does Monarch share?No Can you limit this sharing?N/A — we do not share
3.3 How we protect your information
We maintain a written information security program under the GLBA Safeguards Rule that includes administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of NPI. See Section 11.
3.4 Relationship to state privacy laws
NPI subject to Title V of the GLBA is exempt from most state comprehensive consumer privacy laws. However, several states do not extend an entity-level exemption to a non-depository financial institution like Monarch, and instead provide only a data-level exemption for GLBA-regulated data:
- California has never provided an entity-level exemption; the CCPA exempts NPI at the data level only (Cal. Civ. Code § 1798.145(e)).
- Connecticut narrowed its exemption effective July 1, 2026 (SB 1295). The entity-level exemption now survives only for banks and credit unions; non-depository GLBA entities are covered as to non-NPI data.
- Montana narrowed its exemption effective October 1, 2025 (SB 297), likewise preserving entity-level treatment for depository institutions only.
- Minnesota’s Consumer Data Privacy Act provides a data-level exemption, with a narrow entity-level exemption for certain Minnesota-regulated financial institutions.
- Oregon limits its entity-level exemption to FDIC-insured banks, NCUA-insured credit unions, and similar depositories.
In those states, personal information Monarch holds that is not NPI — for example, website visitor data, marketing prospect data, or business contact data outside a consumer financial relationship — remains subject to state privacy law. Monarch honors the rights described in Sections 12 and 13 with respect to that non-NPI personal information.
4.Personal Information We Collect
We collect the categories of personal information described below. Not every category applies to every individual; what we collect depends on your relationship with us, the products you use, and the legal obligations that apply.
4.1 Categories collected
- AIdentifiers
- Full name, alias, postal address, email address, telephone number, account name, unique personal identifier, online identifier, IP address, device identifier, customer or merchant ID.
- Collected?Yes
- BGovernment identifiers and records
- Social Security number, Individual Taxpayer Identification Number, Employer Identification Number, driver’s license or state ID number, passport number, images of government-issued ID.
- Collected?Yes
- CFinancial information
- Bank account and routing numbers, payment card number, expiration date, and security code, wallet balances, transaction amounts and history, settlement and deposit records, chargeback and return records, tax withholding and 1099 data, bank statements, processing statements, financial statements, tax returns.
- Collected?Yes
- DCommercial information
- Products and services purchased, obtained, or considered; transaction records; merchant category code; projected and actual processing volume; average and highest ticket; refund and delivery practices.
- Collected?Yes
- EBiometric information
- Facial geometry derived from a selfie compared against a government ID during identity verification, where that verification method is used.
- Collected?No
- FInternet or network activity
- Browsing history on our sites, search history, pages viewed, referring URL, session duration, interaction with our applications, error and diagnostic logs.
- Collected?Yes
- GGeolocation data
- Approximate location derived from IP address; precise device location where you enable it in a mobile application; location of cash pickup, drop, or ATM activity.
- Collected?Yes
- HSensory data
- Audio recordings of customer service calls; video from cash logistics operations or premises security.
- Collected?Yes
- IProfessional or employment information
- Job title, employer, role at a merchant or partner, licensing status, ownership percentage, control-person status, business references, employment history for applicants.
- Collected?Yes
- JEducation information
- Non-public education records, collected only from job applicants.
- Collected?Yes — job applicants only
- KInferences
- Risk scores, fraud scores, underwriting tier assignments, transaction-monitoring alerts, and profiles reflecting preferences and behavior.
- Collected?Yes
- LSensitive personal information
- Social Security, driver’s license, state ID, or passport number; account log-in and financial account credentials; account number, debit or credit card number in combination with a required access code or password; precise geolocation; contents of mail, email, and text messages not directed to us. Also biometric information used for identification, where Category E applies.
- Collected?Yes
We do not knowingly collect and do not seek: racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, health information, or information about sex life or sexual orientation. Where an individual voluntarily submits such information — for example, in a supporting document or a free-text field — we do not use it for any purpose other than the purpose for which it was submitted, and we delete it where practicable.
4.2 Special note on cardholder and payment card data
Payment card data is handled in accordance with the Payment Card Industry Data Security Standard (PCI DSS). Full primary account numbers are encrypted in transit and at rest, are tokenized where our systems permit, and are accessible only to personnel with a documented business need. Sensitive authentication data (full magnetic stripe data, CVV/CVC, and PIN data) is not retained after authorization.
5.Sources of Personal Information
We obtain personal information from the following sources:
- Directly from you — merchant applications, account registration, wallet enrollment, forms, support requests, surveys, event registrations, and job applications.
- From your devices and browsers — automatically, through cookies, SDKs, log files, and similar technologies, when you use our sites and applications (see Section 9).
- From merchants, platforms, and clients — when a business submits transaction, customer, or payout data to Monarch to be processed.
- From agents, ISOs, referral partners, and producers — who submit merchant applications and supporting documentation on an applicant’s behalf.
- From banks and financial institutions — sponsor banks, originating and receiving depository financial institutions, and settlement banks, in connection with account verification, returns, and reconciliation.
- From card networks and payment infrastructure — Visa, Mastercard, American Express, Discover, NACHA participants, real-time payment rails, and processors, including chargeback, dispute, and alert data.
- From identity verification and screening providers — including government ID authentication, document verification, bank account verification, and liveness services.
- From consumer reporting agencies and credit bureaus — consumer and business credit reports, where permitted by the Fair Credit Reporting Act and with the appropriate permissible purpose or your authorization.
- From sanctions, watchlist, and risk databases — OFAC and other sanctions lists, politically exposed person and adverse media databases, the Card Network Terminated Merchant File / MATCH list, and industry fraud consortia.
- From public records and government sources — Secretary of State filings, business registries, licensing boards, court records, and IRS confirmations.
- From publicly available and commercial sources — business directories, websites, social media pages maintained by a business, and data enrichment providers.
- From service providers acting on our behalf — hosting, analytics, communications, and support vendors.
6.How We Use Personal Information
We use personal information for the business purposes set out below. We do not use personal information for materially different, unrelated, or incompatible purposes without providing notice.
6.1 Providing and operating our services
- Creating, verifying, and maintaining merchant, wallet, and partner accounts;
- Authorizing, processing, routing, clearing, settling, funding, refunding, and reversing payments and transfers;
- Executing money transmission, bill pay, P2P transfers, and payout disbursements;
- Operating cash logistics, pickup, deposit, and reconciliation services;
- Calculating, accruing, approving, and disbursing commissions and overrides;
- Calculating, collecting, remitting, and reporting taxes;
- Producing statements, ledgers, transaction histories, and reports;
- Providing customer and technical support and communicating about your account.
6.2 Underwriting, risk, and credit
- Evaluating merchant applications, including entity verification, beneficial ownership verification, and control-person verification;
- Assessing credit, financial condition, and expected processing profile;
- Assigning risk tiers, reserve requirements, exposure limits, and pricing;
- Conducting ongoing monitoring, periodic review, and re-underwriting;
- Making decisions to approve, decline, condition, suspend, or terminate an account.
6.3 Legal, regulatory, and compliance
- Complying with the Bank Secrecy Act and anti-money laundering laws, including our anti-money laundering program under 31 C.F.R. § 1022.210, our recordkeeping obligations under 31 C.F.R. §§ 1010.410 and 1022.410, transaction monitoring, the filing of Currency Transaction Reports and Suspicious Activity Reports, and the customer identification and beneficial ownership diligence our sponsor banks and state money transmitter licenses require of us;
- Screening against OFAC and other sanctions lists, politically exposed person lists, and adverse media;
- Complying with state money transmission licensing laws, examinations, and reporting;
- Complying with NACHA Operating Rules, card network rules, and Third Party Sender obligations;
- Complying with tax reporting obligations, including IRS Forms 1099 and information reporting;
- Responding to subpoenas, court orders, regulatory inquiries, examinations, and lawful requests from government authorities;
- Establishing, exercising, or defending legal claims, and performing audits.
Note on suspicious activity reporting. Federal law prohibits Monarch from disclosing to any person whether a Suspicious Activity Report has been filed, and prohibits us from providing SAR-related information in response to a privacy rights request.
6.4 Fraud prevention and security
- Detecting, investigating, and preventing fraud, money laundering, account takeover, unauthorized transactions, and other unlawful activity;
- Authenticating users, managing sessions, and enforcing access controls;
- Monitoring for security incidents, protecting against malicious or deceptive activity, and debugging;
- Managing chargebacks, disputes, returns, and loss recovery.
6.5 Improvement, analytics, and communications
- Analyzing usage to maintain, improve, and develop our products and services;
- Producing internal analytics, benchmarking, and aggregate or deidentified reporting;
- Training and quality assurance, including reviewing recorded support calls;
- Sending transactional, servicing, and security communications;
- Sending marketing communications about Monarch products, subject to your preferences and applicable law (see Section 18);
- Administering events, surveys, and research.
6.6 Corporate purposes
- Corporate governance, accounting, insurance, and internal reporting;
- Evaluating, negotiating, and completing a merger, acquisition, financing, reorganization, or sale of assets, subject to Section 7.
6.7 Sensitive personal information
We use sensitive personal information only for the purposes permitted under applicable law without a right to limit — namely, to perform the services you request, to verify identity and prevent and investigate fraud and security incidents, to ensure the physical safety of individuals, to comply with legal obligations, and to perform services on behalf of our clients. We do not use or disclose sensitive personal information to infer characteristics about you.
7.How and Why We Disclose Personal Information
We disclose personal information to the following categories of recipients, for the purposes stated. We require recipients acting on our behalf to be bound by written contracts that limit their use of the information to the purposes for which it was disclosed and to maintain appropriate safeguards.
- Sponsor banks and financial institutions
- ExamplesSponsor banks, ODFIs and RDFIs, settlement and custodial banks.
- WhyTo open and maintain accounts, sponsor processing, move and settle funds, and satisfy the bank’s own regulatory diligence and monitoring obligations.
- Card networks and payment infrastructure
- ExamplesVisa, Mastercard, American Express, Discover, ACH network participants, real-time payment operators, processors, gateways, acquirers.
- WhyTo route, authorize, clear, settle, and dispute transactions and comply with network rules.
- Identity verification and screening vendors
- ExamplesKYC/KYB, document authentication, bank account verification, sanctions and watchlist screening, adverse media.
- WhyTo verify identity and eligibility and meet AML and sanctions obligations.
- Consumer and business reporting agencies
- ExamplesCredit bureaus, business credit databases.
- WhyTo obtain reports for underwriting, and to furnish information where applicable.
- Fraud and risk consortia
- ExamplesCard network Terminated Merchant File / MATCH, industry fraud databases.
- WhyTo report and screen for fraud and prohibited activity, as required or permitted.
- Service providers and subprocessors
- ExamplesCloud hosting, data storage, communications and messaging, analytics, customer support, e-signature, document storage, accounting, printing and mail.
- WhyTo operate our business under contract, for our business purposes only.
- Merchants, platforms, and clients
- ExamplesThe business whose transaction you participated in; the tenant whose white-label service you used.
- WhyTo fulfill the transaction, resolve disputes, and provide reporting.
- Agents, ISOs, and producers
- ExamplesThe sales partner who submitted or services your account.
- WhyTo service the relationship and calculate commissions; limited to the information necessary for that purpose.
- Professional advisors
- ExamplesAttorneys, auditors, accountants, insurers, examiners.
- WhyTo obtain professional services and complete examinations and audits.
- Regulators and law enforcement
- ExamplesFinCEN, state financial regulators, IRS, CFPB, FTC, state attorneys general, courts, law enforcement.
- WhyTo comply with law, respond to legal process, and cooperate with lawful investigations.
- Parties to a corporate transaction
- ExamplesAcquirers, investors, successors in interest, and their advisors.
- WhyTo evaluate or complete a merger, acquisition, financing, reorganization, bankruptcy, or asset sale; the recipient’s use will remain subject to this policy or notice will be provided.
- At your direction
- ExamplesAny recipient you authorize.
- WhyTo carry out your instruction.
We may also disclose deidentified or aggregated information that cannot reasonably be used to infer information about, or otherwise be linked to, an individual. Where we do so, we maintain the information in deidentified form, publicly commit not to attempt reidentification, and contractually obligate recipients to the same.
8.We Do Not Sell or Share Personal Information
Monarch does not sell personal information, and does not share personal information for cross-context behavioral advertising or targeted advertising, as those terms are defined under the California Consumer Privacy Act and other state privacy laws. We have not sold or shared personal information in the preceding twelve (12) months, including the personal information of any individual we know to be under 16 years of age.
We also do not:
- Disclose personal information to nonaffiliated third parties for those parties to market their own products to you;
- Use or disclose sensitive personal information to infer characteristics about individuals;
- Process personal information for profiling in furtherance of decisions that produce legal or similarly significant effects, except as described in Section 14.
If Monarch’s practices change, we will update this policy and, where required, provide notice and an opt-out mechanism before the change takes effect.
9.Cookies, Analytics, and Tracking Technologies
9.1 What we use
We and our service providers use cookies, pixels, tags, SDKs, local storage, and similar technologies on our websites and applications:
- Strictly necessary
- Authentication, session management, load balancing, security, fraud prevention, and remembering your preferences. Without these the site cannot function.
- Can you opt out?No
- Performance and analytics
- Understanding how visitors use our sites so we can improve them — page views, session length, error rates.
- Can you opt out?Yes
- Functional
- Remembering settings, language, and prior inputs.
- Can you opt out?Yes
- Advertising / targeting
- Not used. Monarch does not run retargeting, advertising pixels, or ad conversion tracking on its sites. See Section 8.
- Can you opt out?Not applicable
9.2 Your choices
- Browser controls. Most browsers let you block or delete cookies through their settings. Blocking strictly necessary cookies will impair site functionality.
- Global Privacy Control. We honor the Global Privacy Control (GPC) and other recognized universal opt-out mechanisms as a valid opt-out of sale/sharing and targeted advertising for the browser or device on which it is enabled, in the states that require it — including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas, and others as their requirements take effect.
- Do Not Track. Because there is no industry-accepted standard for responding to browser “Do Not Track” signals, our sites do not respond to them. We do honor GPC as described above.
- Mobile. You can limit ad tracking and disable precise location in your device’s operating system settings.
9.3 Analytics providers
We use Google Analytics to understand site usage. You can opt out of Google Analytics using the browser add-on available at tools.google.com/dlpage/gaoptout.
10.Data Retention
We retain personal information only as long as necessary for the purposes described in this policy, and thereafter as required by law. Because Monarch operates as a regulated financial institution, several retention periods are mandated and cannot be shortened at an individual’s request.
10.1 Retention criteria
We determine retention periods by reference to: (a) the duration of the relationship; (b) the record-retention periods mandated by financial, tax, and money transmission law; (c) applicable statutes of limitations for claims; (d) card network and NACHA rule requirements; (e) whether a legal hold, audit, examination, investigation, or dispute is pending; and (f) the sensitivity of the information and the risk of harm from unauthorized use.
10.2 Retention schedule
- Customer identification and due diligence records (KYC/KYB), beneficial ownership records
- 5 years after the account is closed, per 31 C.F.R. § 1010.430(d), our sponsor bank agreements, and applicable state money transmitter licensing requirements.
- Transaction and money transmission records, funds transfer records
- 5 years from the date of the transaction, per 31 C.F.R. §§ 1010.410 and 1022.410 and applicable state money transmission law (longer where a state license requires it).
- Suspicious Activity Reports and supporting documentation
- 5 years from the date of filing.
- Currency Transaction Reports
- 5 years from the date of filing.
- Sanctions and OFAC records — screening records, and records of transactions subject to OFAC regulations, including rejected transactions
- 10 years from the date of the transaction, per 31 C.F.R. § 501.601 (as amended effective March 12, 2025); blocked property records for the duration of the block plus 10 years after unblocking.
- Merchant application, underwriting file, and supporting documents
- Term of the relationship plus 5 years.
- Chargeback, dispute, and retrieval records
- Term of the relationship plus 3 years, or longer where network rules require.
- Payment card data
- Full PAN retained only as long as necessary for the authorized business purpose; sensitive authentication data is not retained after authorization.
- Tax and information reporting records (1099s, withholding)
- 7 years per IRS requirements.
- Commission ledgers and payout records
- Term of the relationship plus 7 years (append-only, immutable ledger).
- Audit logs and security event logs
- 2 years online, 7 years archived.
- Customer support recordings and transcripts
- 24 months.
- Website analytics and log data
- 13 months.
- Marketing contact records
- Until you opt out, plus a suppression record retained indefinitely so we can honor your opt-out.
- Job applicant records
- 3 years after the hiring decision, or longer where required by law.
- Records subject to legal hold, litigation, audit, or examination
- Until the hold is released, notwithstanding any period above.
At the end of the applicable period, we securely delete, destroy, or deidentify the information, or place it in a restricted archive with access limited to legal and compliance personnel.
11.How We Protect Personal Information
Monarch maintains a written information security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the information and the size and complexity of our operations. Our program is designed to meet the requirements of the GLBA Safeguards Rule (16 C.F.R. Part 314), PCI DSS, applicable state money transmitter and data security laws, and our sponsor bank and network obligations.
Controls include:
- Governance — a designated Qualified Individual responsible for the information security program, written policies, and written risk assessments. As required by 16 C.F.R. § 314.4(i), the Qualified Individual reports in writing, at least annually, to our board of directors or equivalent governing body on the status of the program, risks, and material matters;
- Encryption — encryption of personal information in transit using TLS and at rest using industry-standard algorithms;
- Tokenization — replacement of payment card and bank account numbers with tokens where our systems permit;
- Access control — role-based access, least-privilege provisioning, multi-factor authentication for administrative and remote access, and periodic access reviews;
- Monitoring and logging — immutable audit logging of system and user actions, continuous monitoring, and intrusion detection;
- Secure development — code review, dependency scanning, and separation of development, staging, and production environments;
- Testing — annual penetration testing and vulnerability assessments at least every six months, as required by 16 C.F.R. § 314.4(d)(2), together with assessments following any material change to operations or business arrangements;
- Vendor management — security diligence before engagement, contractual security and confidentiality requirements, and periodic reassessment;
- Personnel — background screening where permitted by law, confidentiality obligations, and security awareness training;
- Physical security — controlled facility access, secure handling and transport procedures for cash logistics, and secure destruction of media;
- Incident response — a documented incident response plan, tested periodically, including notification to affected individuals, regulators, sponsor banks, and card networks within the timeframes required by applicable law. Where a notification event involves the unauthorized acquisition of unencrypted customer information of 500 or more consumers, we notify the Federal Trade Commission as soon as possible and no later than 30 days after discovery, as required by 16 C.F.R. § 314.4(j);
- Identity theft prevention — a written Identity Theft Prevention Program under the FCRA Red Flags Rule, 16 C.F.R. § 681.1, designed to detect, prevent, and mitigate identity theft in connection with covered accounts.
Licenses and status. Monarch maintains money transmission licenses in various states, and MSB and TPPP status with multiple banking partners.
No absolute guarantee. No method of transmission or storage is completely secure. While we work to protect personal information, we cannot guarantee its absolute security. Protect your own credentials, use multi-factor authentication where offered, and notify us immediately at support@monarch.is if you believe your account has been compromised.
12.Your Privacy Rights and How to Exercise Them
12.1 Rights that may be available to you
Depending on your state of residence and the nature of the information, you may have the following rights with respect to personal information Monarch holds as a business or controller:
- Right to know / access
- To confirm whether we process your personal information and to obtain the categories of information collected, the sources, the purposes, the categories of recipients, and the specific pieces of personal information we hold.
- Right to correct
- To have inaccurate personal information corrected, taking into account the nature and purpose of the processing.
- Right to delete
- To request deletion of personal information we collected from you, subject to the exceptions below.
- Right to data portability
- To receive a copy of your personal information in a portable and, where technically feasible, readily usable format.
- Right to opt out of sale, sharing, and targeted advertising
- Monarch does not sell or share personal information or use it for targeted advertising, so there is nothing to opt out of. We honor GPC signals regardless.
- Right to limit use of sensitive personal information
- Monarch uses sensitive personal information only for purposes that are exempt from the right to limit, so this right does not currently apply. We will provide a limitation mechanism if our practices change.
- Right to opt out of profiling
- To opt out of profiling in furtherance of decisions producing legal or similarly significant effects. See Section 14 for the narrow circumstances in which this applies and the exemptions that may apply to fraud prevention and legally required decisions.
- Right to non-discrimination / non-retaliation
- We will not deny you goods or services, charge you a different price, provide a different level of quality, or retaliate against you for exercising a privacy right.
- Right to appeal
- To appeal our refusal of a request. See Section 12.5.
12.2 How to submit a request
Submit a request through any of the following:
- Email: support@monarch.is with the subject line “Privacy Rights Request”
- Telephone: 1-805-316-7078
- Mail: Monarch Technologies, Inc., Attn: Privacy Officer, 17595 Harvard Ave, Ste C-711, Irvine, CA 92614
12.3 Verification
To protect your information, we must verify your identity before acting on a request. We will ask for information that matches what we already hold — typically your name, email address or phone number on file, and information about a recent transaction or account. For requests seeking specific pieces of information, or where the information is sensitive, we may require a higher degree of certainty, including a signed declaration under penalty of perjury or verification through your authenticated account. We use information provided for verification only for that purpose and delete it promptly afterward.
Authorized agents. You may designate an authorized agent to submit a request on your behalf. We will require written permission signed by you, and we may require you to verify your own identity directly with us and confirm that you authorized the agent. An agent acting under a valid power of attorney need not provide separate written permission.
12.4 Timing and fees
We acknowledge receipt of requests to know, correct, and delete within ten (10) business days, and respond substantively to all requests within forty-five (45) calendar days. We may extend once by an additional forty-five (45) days where reasonably necessary, and will notify you of the extension and the reason. Some states allow longer — Iowa allows 90 days — but Monarch applies the 45-day standard in every state. Requests are free unless they are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline the request and explain why. Access requests are limited to twice in a 12-month period.
12.5 Appeals
If we decline your request, our response will explain why and how to appeal. Submit an appeal to support@monarch.is with the subject line “Privacy Appeal,” or by mail to the address above, within sixty (60) days of our decision. We will respond in writing within forty-five (45) days — sixty (60) days in states that allow it — with our decision and a written explanation. If we deny the appeal, we will provide you with a method to contact your state attorney general to submit a complaint.
12.6 Exceptions — when we cannot fulfill a request
We may be unable to fulfill all or part of a request. The most common reasons in a financial services context are:
- The information is NPI subject to the GLBA or is otherwise collected, processed, sold, or disclosed pursuant to the GLBA or the Fair Credit Reporting Act, and is exempt from state privacy law;
- Retention is required by the Bank Secrecy Act, sanctions law, money transmission law, tax law, or another legal obligation;
- The information relates to a Suspicious Activity Report, which federal law prohibits us from disclosing or confirming;
- Deletion would compromise our ability to detect security incidents or prevent fraud or illegal activity, or would impair the rights of another individual;
- The information is necessary to complete a transaction, service an account, or perform a contract with you;
- The information is needed to exercise or defend legal claims, comply with legal process, or respond to a legal hold;
- We act as a service provider or processor for the information, in which case we will direct your request to the business that controls it;
- We cannot verify your identity to the required standard;
- The information is deidentified or aggregated and cannot be reasonably linked to you.
Where an exception applies to only part of a request, we will act on the remainder.
13.State-Specific Disclosures
13.1 California
This section supplements the rest of this policy for California residents and is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).
- Categories collected in the preceding 12 months: Categories A, B, C, D, F, G, I, K, and L in Section 4.1, and Categories E, H, and J where noted.
- Sources: See Section 5.
- Business and commercial purposes: See Section 6.
- Categories disclosed for a business purpose in the preceding 12 months: Categories A, B, C, D, F, G, I, K, and L, and Categories E and H where collected, to the categories of recipients listed in Section 7. Biometric information is disclosed only to the identity verification vendor that performs the comparison; call recordings are disclosed only to the support, storage, and quality-assurance providers that process them on our behalf.
- Categories sold or shared in the preceding 12 months: None. Monarch does not sell or share personal information, including that of consumers under 16.
- Retention: See Section 10.
- Sensitive personal information: Collected as described in Category L. Used only for purposes exempt from the right to limit under Cal. Civ. Code § 1798.121(a) and 11 CCR § 7027(m). Not used or disclosed to infer characteristics.
- Notice at collection: This policy, together with any just-in-time notice presented at the point of collection, constitutes our notice at collection.
- GLBA: Personal information that is NPI subject to Title V of the GLBA is exempt from the CCPA under Cal. Civ. Code § 1798.145(e). California does not provide an entity-level exemption, so the CCPA applies to Monarch’s non-NPI personal information.
- “Shine the Light” (Cal. Civ. Code § 1798.83): We do not disclose personal information to third parties for their own direct marketing purposes. You may request confirmation once per year at support@monarch.is.
- California minors (Cal. Bus. & Prof. Code § 22581): Where a registered user under 18 has posted content on a Monarch site, that user may request its removal by contacting support@monarch.is. See Section 19 regarding eligibility to hold a Monarch account.
13.1.1 California Financial Information Privacy Act (Cal. Fin. Code §§ 4050–4060)
Monarch is a financial institution doing business in California and is subject to the California Financial Information Privacy Act (“CFIPA,” also known as SB 1), which imposes obligations stricter than the GLBA:
- We will not disclose nonpublic personal information to a nonaffiliated third party for that party’s own use unless you have given affirmative written consent (opt-in), except where Cal. Fin. Code § 4056 permits the disclosure — including disclosures necessary to process or service a transaction you requested, to prevent fraud, to comply with law, or to a service provider performing services for us under contract.
- We will not disclose nonpublic personal information to an affiliate unless you have been given notice and an opportunity to opt out, where required by § 4053.
- We provide the standalone notice and choice form required by Cal. Fin. Code § 4053(d), titled “IMPORTANT PRIVACY CHOICES FOR CONSUMERS,” as a separate document rather than as part of this policy.
13.2 Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia
Residents of states with comprehensive consumer privacy laws have the rights described in Section 12, subject to the variations and exemptions in those laws. In particular:
- Universal opt-out mechanisms. We honor GPC and other recognized universal opt-out signals in every state that requires it.
- Appeals. Most of these states provide an appeal right; see Section 12.5. Utah does not require an appeal process, though Monarch will consider a Utah resident’s appeal as a matter of practice.
- Right to correct. Utah and Iowa do not provide a statutory right to correct. Monarch will honor correction requests from residents of those states as a matter of practice where it is able to verify the correction.
- Response deadlines. Most of these states use 45 days with one 45-day extension. Iowa allows 90 days. Monarch applies the shorter 45-day standard across all states.
- Data protection assessments. Where required, Monarch conducts and documents data protection assessments for processing that presents a heightened risk of harm, including the processing of sensitive data and any processing for targeted advertising or profiling.
- Data minimization. Consistent with the Maryland Online Data Privacy Act and similar requirements, we limit our collection of personal data to what is reasonably necessary and proportionate to provide or maintain the product or service the consumer requested, and we do not sell sensitive data.
- GLBA exemptions. Most of these states exempt financial institutions subject to the GLBA at the entity level. Connecticut, Minnesota, Montana, and Oregon provide only a data-level or narrowed exemption for a non-depository institution like Monarch; in those states, Monarch honors these rights as to non-NPI personal information. See Section 3.4.
- Connecticut, Minnesota, and Oregon additionally provide the right to obtain a list of the specific third parties to which we have disclosed personal data. Residents of those states may request that list at support@monarch.is.
- Connecticut and Minnesota additionally provide the right to question the result of a profiling decision and to be informed of the reason for it. Connecticut further provides a right to access inferences we have derived from personal data. See also Section 14.
- Texas requires a controller that sells sensitive or biometric personal data to post the notices “NOTICE: We may sell your sensitive personal data” and “NOTICE: We may sell your biometric personal data” under Tex. Bus. & Com. Code § 541.102(b)–(c). Monarch does not sell sensitive or biometric personal data, so neither notice applies.
- Florida. The Florida Digital Bill of Rights applies only to entities with more than $1 billion in global gross annual revenue that also meet one of three additional platform-based criteria. Monarch does not meet that threshold and is not a covered “controller” under that law.
13.3 Nevada
Nev. Rev. Stat. § 603A.330(2) excludes from the definition of “operator” — and therefore from the opt-out regime at NRS 603A.300–.360 — a financial institution or affiliate of a financial institution subject to the Gramm-Leach-Bliley Act. Monarch is such a financial institution and is therefore exempt from that regime. Independently of the exemption, Monarch does not sell covered information, and Nevada residents may submit a request to support@monarch.is, which we will consider as a matter of practice.
13.4 Washington and Nevada consumer health data
The Washington My Health My Data Act and Nevada SB 370 regulate consumer health data. Monarch does not collect, use, or share consumer health data as defined in those laws. We do not infer health conditions from transaction data.
13.5 Illinois and Texas biometric privacy
Where Monarch uses facial-geometry-based identity verification, we do so as follows: we provide written notice and obtain a written release before capture; we use the biometric identifier solely to verify that the person presenting a government-issued ID is the person depicted on it; we do not sell, lease, trade, or otherwise profit from biometric identifiers; and we destroy the biometric identifier when the initial purpose for collecting it has been satisfied or within three (3) years of the individual’s last interaction with us, whichever occurs first, consistent with the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)). Under the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001) we destroy the identifier within one year of the date the purpose for collecting it expires.
This destruction commitment does not extend to records we are separately required to retain — including a government-issued ID image or underwriting file subject to the periods in Section 10.2, or any record subject to a legal hold. Those records are retained for the required period and then destroyed.
13.6 New York
Consistent with the New York SHIELD Act, Monarch maintains the reasonable administrative, technical, and physical safeguards required by N.Y. Gen. Bus. Law § 899-bb for the private information of New York residents, and will provide breach notification as required by N.Y. Gen. Bus. Law § 899-aa.
13.7 Other jurisdictions
Additional state laws take effect over time. Monarch monitors these developments and will update this policy as new requirements apply. If you reside in a state not listed and wish to make a privacy request, contact support@monarch.is and we will respond consistent with applicable law.
14.Identity Verification, Screening, and Automated Decision-Making
14.1 What we do
Monarch uses automated tools as part of onboarding, underwriting, transaction monitoring, and fraud prevention. These include identity and document authentication, sanctions and watchlist screening, credit and business report retrieval, risk scoring models, velocity and pattern rules, and transaction monitoring alerts.
14.2 Human involvement
Decisions that have a legal or similarly significant effect — including declining a merchant application, imposing a reserve, suspending processing, holding funds, or terminating an account — are reviewed by a Monarch employee before they become final, except where an immediate automated action is necessary to prevent fraud, comply with sanctions law, or protect the security of our systems and our customers’ funds.
14.3 Fair Credit Reporting Act
Where we obtain a consumer report and take adverse action based in whole or in part on it, we will provide the adverse action notice the FCRA requires, including the identity of the consumer reporting agency and your right to obtain a free copy of the report and to dispute its accuracy directly with the agency.
14.4 California automated decisionmaking technology (ADMT)
The California Privacy Protection Agency’s regulations, effective January 1, 2026, govern the use of automated decisionmaking technology to make a “significant decision” — a category that expressly includes decisions about financial or lending services. Monarch’s underwriting, reserve, hold, and termination decisions fall within that subject matter.
Monarch’s position is that the human review described in Section 14.2 means these technologies do not replace or substantially replace human decision making, and therefore that the ADMT pre-use notice and opt-out obligations are not triggered. Where an automated system does operate without meaningful human review to make a significant decision about a California resident, we will provide a pre-use notice, an opt-out where no statutory exemption applies (including the exemptions for fraud prevention and security), and an access right that explains the inputs used and the rationale for the decision.
We also conduct and document risk assessments for processing that triggers them under the California regulations, including our processing of sensitive personal information.
14.5 Your rights regarding profiling
You may ask us to explain the general logic used in a decision affecting you, to be informed of the reason for the decision, to request human review, and to contest the outcome. Connecticut residents may also request access to inferences we have derived from their personal data. Contact support@monarch.is. We may be unable to disclose details where doing so would compromise fraud prevention, reveal a trade secret, or reveal information federal law prohibits us from disclosing (for example, SAR-related information).
14.6 Consumer reporting — furnishing and disputes
Where Monarch furnishes information about you to a consumer reporting agency, we are obligated under the FCRA to provide accurate information and to investigate disputes. You may dispute the accuracy or completeness of information we furnished by writing to us directly at support@monarch.is or at the mailing address in Section 24, identifying the specific information you dispute and the basis for the dispute, and enclosing supporting documentation. We will investigate and respond as FCRA § 623(a)(8) and 12 C.F.R. Part 1022, Subpart E require. You may also dispute directly with the consumer reporting agency.
15.Cardholders and Other End Consumers
If you are a consumer who paid a merchant, sent or received a P2P transfer, paid a bill, or used a wallet powered by Monarch:
- Monarch typically processes your information as a service provider to that merchant, platform, or financial institution. That business decides what information to collect and how it is used, and its own privacy notice governs.
- Monarch also processes a limited set of your information as a business in its own right — specifically, to meet its independent obligations under the Bank Secrecy Act, sanctions law, money transmission law, and card network and NACHA rules, and to prevent fraud and loss. Those uses are described in Sections 6.3 and 6.4.
- To exercise your privacy rights, contact the merchant or platform you transacted with first. If you contact Monarch, we will either forward your request to that business or respond directly where Monarch is the controller of the information at issue.
- For a transaction dispute, contact the merchant first, then your card issuer or bank. Monarch cannot reverse a transaction on the instruction of a cardholder alone.
16.Agents, ISOs, Producers, and Referral Partners
If you are an agent, ISO, sub-agent, referral partner, or producer:
- We collect your identity and contact information, tax identification number, licensing and registration information, banking details for payouts, hierarchy and relationship data, production and volume data, and commission ledger entries.
- We use this information to onboard and verify you, to screen you against sanctions and industry databases, to calculate and disburse commissions and overrides, to issue tax forms, and to comply with our obligations to sponsor banks and card networks.
- We disclose your production and commission data to upline partners in your hierarchy only to the extent necessary to calculate and validate their overrides, and to sponsor banks, networks, and regulators where required.
- Merchant information available to you through our portals is disclosed on a need-to-know basis for servicing purposes only. You are contractually obligated to protect it, to use it only for authorized purposes, and to comply with the GLBA, PCI DSS, and applicable privacy law. Misuse of merchant or cardholder data is grounds for immediate termination and may be reported to networks and law enforcement.
17.Job Applicants and Personnel
For job applicants, employees, and contractors, we collect contact details, resume and employment history, education records, references, right-to-work documentation, and — where permitted by law and with the required disclosures and authorization — background check and consumer report information. We use it to evaluate candidates, administer employment, and comply with legal obligations. California applicants and personnel have rights under the CCPA as described in Sections 12 and 13.1; a separate Notice at Collection for California Job Applicants and Personnel is provided at the point of application.
18.Electronic Communications, SMS, and Marketing Preferences
18.1 Email
You may opt out of marketing email at any time using the unsubscribe link in any marketing message or by emailing support@monarch.is. You cannot opt out of transactional and servicing messages — account notices, transaction confirmations, security alerts, fraud alerts, statements, and legally required disclosures — for as long as you hold an account with us.
18.2 SMS and text messaging
Where you provide a mobile number and consent to text messages, we use it to send the categories of messages you consented to receive — including one-time passcodes, transaction and fraud alerts, and account notices. Message and data rates may apply. Message frequency varies. Reply STOP to opt out of any category and HELP for assistance.
Mobile opt-in consent and phone numbers collected for the purpose of SMS communication are not shared with any third party or affiliate for marketing purposes. Mobile numbers are disclosed only to the messaging service providers that transmit messages on our behalf under contract, and to parties to whom disclosure is required by law.
18.3 Telephone
We may call you about your account. Calls may be monitored or recorded for quality, training, and fraud prevention purposes, and we will disclose recording at the start of the call where required by law.
19.Children’s Privacy
Monarch’s financial services are intended for businesses and for individuals 18 years of age or older, or the age of majority in their jurisdiction, and we do not knowingly open accounts for minors. Our marketing website is open to general visitors, which is why Section 13.1 references the California minor content-removal right. We do not knowingly collect personal information from children under 13, and we do not knowingly collect, sell, or share the personal information of individuals under 16. If we learn that we have collected personal information from a child under 13 in violation of the Children’s Online Privacy Protection Act, we will delete it promptly. A parent or guardian who believes a child has provided us personal information should contact support@monarch.is.
20.Location of Data and International Users
Monarch is based in the United States, and the personal information we collect is stored and processed in the United States. Our services are intended for use in the United States and are not directed to individuals in the European Economic Area, the United Kingdom, or other jurisdictions with data localization or transfer restrictions.
If you access our services from outside the United States, understand that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
21.Third-Party Sites and Services
Our sites and applications may link to or embed third-party websites, applications, and services that we do not control — including merchant websites, bank portals, and payment interfaces. This policy does not apply to them. Review their privacy notices before providing personal information.
22.Accessibility and Alternative Formats
Monarch is committed to making this policy accessible to individuals with disabilities. If you use assistive technology and have difficulty accessing this policy, or if you would like a copy in an alternative format, contact us at support@monarch.is or 1-805-316-7078 and we will provide one at no charge.
23.Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top and post the revised policy on our website. If we make a material change — for example, a change in the categories of personal information we collect, the purposes for which we use it, or the parties with whom we share it — we will provide notice before the change takes effect by email, in-product notice, or a prominent notice on our website, and where required by law we will obtain your consent. Where we intend to process previously collected personal data for a purpose materially different from what we disclosed when we collected it, we will give you an opportunity to withdraw consent to that processing before it begins, as Connecticut and other states require. Prior versions of this policy are available on request at support@monarch.is.
24.How to Contact Us
- Monarch Technologies, Inc.
- Attn: Privacy Officer
17595 Harvard Ave, Ste C-711
Irvine, CA 92614
United States - Privacy inquiries and rights requests
- support@monarch.is
- Security concerns
- security@monarch.is
- General customer service
- service@monarchsupportservices.com
- Telephone
- 1-805-316-7078
- Privacy rights web form
- monarch.is/privacy-request
If you have an unresolved concern, you may contact your state attorney general or the Consumer Financial Protection Bureau at consumerfinance.gov/complaint.