Legal

Privacy Policy.

TECHNOLOGIES

PRIVACY POLICY

ForGood Technologies, LLC (d/b/a Elev8 Technologies)

Effective Date: January 1, 2026

Last Updated: May 6, 2026

Website: letselev8.com

Privacy contact: privacy@letselev8.com

PRIVACY AT A GLANCE

This summary is provided for convenience only. It does not replace the full Privacy Policy that follows and is not a substitute for reading the detailed sections below.

1. INTRODUCTION

ForGood Technologies, LLC, a Wyoming limited liability company doing business as Elev8 Technologies (“Elev8,” “Company,” “we,” “us,” or “our”), respects your privacy and is committed to protecting it through our compliance with this Privacy Policy (“Policy”).

Elev8 operates a financial-technology (“fintech”) platform purpose-built as a Fund Capturing Platform that enables organizations, sponsors, merchants, financial institutions, and individuals to capture, direct, and amplify program-related funds through modern payment, engagement, and loyalty technologies. For the avoidance of doubt, Elev8 is a technology provider, it is not a fundraising platform, charitable organization, professional fundraiser, charitable solicitor, or donation processor, as further described in Sections 42 and 43.

This Policy describes the types of information we collect, how we use and disclose it, the choices available to you, and the protections we apply. By accessing or using the Platform, you acknowledge that you have read and understand this Policy.

This Policy applies to information we collect, process, use, disclose, retain, or otherwise handle through:

  • Our websites, including letselev8.com and any Elev8-operated subdomains.
  • Elev8-branded and white-labeled mobile and web applications.
  • Our application programming interfaces (APIs), webhooks, SDKs, and software integrations.
  • Our card-linking, round-up, rewards & loyalty, sponsor contribution, campaign, and enterprise engagement services.
  • Enterprise dashboards, analytics tools, reporting interfaces, and administrative consoles.
  • Customer support channels (email, chat, phone, ticketing).
  • Marketing communications, surveys, events, and promotions.
  • Any related tools, services, or communications operated by Elev8 (collectively, the “Platform”).

Certain Elev8 services may be offered through a sponsoring organization, enterprise client, financial institution, or merchant partner. When that partner acts as the data controller or has its own privacy notice, that partner’s notice governs data it collects directly; this Policy governs the data that Elev8 itself processes.

2. SCOPE & APPLICABILITY

This Policy applies to:

  • Consumers and end users who create accounts, link payment methods, earn rewards, participate in round-up programs, or otherwise use the Platform.
  • Representatives of organizations (nonprofits, schools, associations, charities, membership groups, collectives, and similar entities) that use Elev8’s enterprise features.
  • Representatives of sponsors, brands, advertisers, merchants, and other corporate partners that fund or participate in campaigns.
  • Employees, contractors, and authorized users of our business customers who access Elev8 administrative dashboards.
  • Website visitors, API consumers, and prospective customers.

This Policy does not apply to:

  • Information that is not linked or reasonably linkable to an identified or identifiable individual (for example, fully aggregated or de-identified data).
  • Information processed by Elev8 as a service provider, processor, or sub-processor on behalf of a business customer acting as controller, such processing is governed by the contract between Elev8 and that business and by the business’s own privacy notice.
  • Information collected by third parties (financial institutions, payment networks, sponsors, merchants, or other providers) through their own products, websites, or services, even when integrated with Elev8.

3. ELEV8 PLATFORM OVERVIEW (IMPORTANT CONTEXT)

Elev8 is a technology platform. Elev8 is not a bank, credit union, money transmitter, money services business, issuer, acquirer, payment processor, broker-dealer, investment adviser, or charitable organization. Elev8 does not hold, custody, or transmit funds, and Elev8 does not issue payment credentials.

Elev8 provides software, APIs, and dashboards that coordinate data between users, sponsoring organizations, merchants, financial institutions, and payment processors. Key modules include:

3.1 Card-Linking Technology

Elev8 enables users to link eligible payment cards so that qualifying merchant transactions can trigger benefits, contributions, or rewards. Elev8 receives transaction metadata from card networks and processors through secure, tokenized channels. Elev8 does not receive full primary account numbers (PANs) or CVV codes.

3.2 Round-Up Technology

Elev8 calculates micro-contribution amounts, for example, rounding up a transaction to the nearest whole dollar, based on transaction metadata. The calculation is a software output; the actual movement of funds is performed by a third-party bank, payment processor, or gateway under agreements with the sponsoring organization or user.

3.3 Rewards & Loyalty Systems

Elev8 records, issues, tracks, and redeems points, credits, offers, and sponsor-funded incentives. Reward balances are ledger entries maintained in Elev8 systems; fulfillment of cash-equivalent rewards is performed by partners.

3.4 Sponsor Contribution Infrastructure

Elev8 allows sponsors (brands, enterprises, financial institutions, and other funders) to configure and measure sponsor-funded program mechanics tied to user engagement, transactions, or campaign participation. Sponsor-funded payouts are performed by the sponsor, the sponsor’s bank, or an applicable payment partner, not by Elev8, and are not solicitations of charitable contributions by Elev8. The term “contribution” as used in this Policy refers to program mechanics configured by the sponsor or organization, not to charitable gifts, donations, or tax-deductible payments made to Elev8.

3.5 Enterprise Engagement Dashboards

Elev8 provides organizations with administrative consoles that surface aggregate performance metrics, campaign analytics, and, where permitted, individual engagement records.

3.6 APIs and Integrations

Elev8 offers APIs, webhooks, and SDKs that allow authorized partners, financial institutions, and payment providers to integrate with the Platform under written agreements that include data-protection obligations.

All financial transactions are processed by third-party financial institutions, card networks, and payment processors, not by Elev8.

4. KEY DEFINITIONS

For clarity, the following terms have the meanings given below when used in this Policy:

5. INFORMATION WE COLLECT

The categories and specific elements of information we collect depend on how you interact with the Platform and on the configuration of the program, organization, or sponsor you engage with.

5.1 Identity & Contact Information

  • Full name, preferred name, username, and display name.
  • Email address, mobile or telephone number, and mailing address.
  • Date of birth and, where required for identity verification or age gating, month and year of birth.
  • Government-issued identifiers, such as the last four digits of a Social Security Number, driver’s license number, passport number, or tax identifier, collected only when required by law, for identity verification, or for fraud prevention, and typically through a third-party identity verification provider.
  • Photograph or profile image (if you choose to upload one).

5.2 Account & Profile Information

  • Account credentials (hashed passwords, multi-factor authentication tokens, recovery codes).
  • Security questions and answers.
  • Preferences, settings, language, and accessibility options.
  • Organization, affiliation, role, and permissions.
  • Demographic information, only when voluntarily provided (e.g., for program eligibility, diversity reporting, or research).

5.3 Financial & Transaction-Related Information

  • Payment card tokens, payment method references, and expiration dates, not full primary account numbers, full bank account numbers, or CVV codes.
  • Merchant identifiers, merchant category codes, transaction amounts, currency, timestamps, and authorization results.
  • Round-up activity, contribution preferences, contribution history, and scheduled-contribution rules.
  • Rewards balances, earning events, redemption events, expirations, forfeitures, and associated program metadata.
  • Dispute, chargeback, refund, reversal, and adjustment records.
  • Sponsor match, bonus, multiplier, and allocation data.

Sensitive financial data (such as raw Primary Account Numbers “PANs”, full bank account numbers, or CVV codes) is handled by regulated third-party processors and is not stored by Elev8. Elev8’s systems are designed to receive and store only tokenized or masked values consistent with PCI DSS scope-reduction guidance.

5.4 Device, Technical & Network Data

  • IP address (truncated where feasible) and approximate network-derived location.
  • Device type, hardware model, operating system and version, and unique device identifiers (e.g., IDFA, AAID, reset-able advertising IDs).
  • Browser type and version, language settings, referring URLs, and exit pages.
  • App version, SDK version, crash logs, diagnostic data, and performance telemetry.
  • Log data (timestamps, request and response metadata, error codes, feature flags).
  • Cookies, pixels, tags, local storage values, and similar tracking technologies.

5.5 Behavioral, Engagement & Usage Data

  • Pages, screens, and features accessed on the Platform.
  • Clicks, taps, scrolls, hover events, and in-app navigation paths.
  • Campaign participation, offer views, offer clicks, and offer redemptions.
  • Rewards engagement and referral activity.
  • Sponsor interactions, survey responses, and content submissions.

5.6 Enterprise & Organizational Data

  • Organization profile information, including legal name, EIN, address, contact information, and banking references for payout (handled by partner financial institutions).
  • Administrator and authorized user accounts and activity logs.
  • Campaign configuration, creative assets, and performance metrics.
  • Aggregated user engagement, contribution totals, and cohort analytics.
  • Support tickets, account history, and account-management communications.

5.7 Sponsor, Merchant & Partner Data

  • Business contact and representative information.
  • Merchant identifiers, store locations, and offer configurations.
  • Sponsor program parameters, funding instructions, and reporting requirements.

5.8 Sensitive Information (Limited, Lawful Use)

Where applicable and legally permitted, we may process the following sensitive categories, subject to heightened controls and, where required, explicit consent or a recognized legal basis:

  • Precise geolocation (only when you expressly enable location features, for example to unlock location-based offers).
  • Government identifiers, when needed for know-your-customer (KYC), know-your-business (KYB), or identity-verification checks performed by qualified third-party vendors.
  • Biometric identifiers or biometric information, only where you choose to enable device-based biometric authentication (for example, Face ID or fingerprint), we do not receive or store your underlying biometric template.
  • Fraud-detection signals that may include behavioral biometrics, device fingerprints, and risk scores.
  • Information revealing demographic characteristics (such as race, ethnicity, religion, or union status), only if you voluntarily provide it for programs that specifically request it.

5.9 Children’s Information

The Platform is not directed to, and we do not knowingly collect Personal Information from, children under 13 years of age (or under 16 where applicable law imposes a higher threshold). See Section 23 for more on children’s privacy.

5.10 Information We Do Not Intentionally Collect

  • Raw primary account numbers (PANs), full card numbers, or CVV/CVC codes.
  • Full bank account numbers (we receive references, tokens, or masked values from partners).
  • Biometric templates.
  • Health information, except as specifically disclosed by you.

6. HOW WE COLLECT INFORMATION

We collect information through the following channels:

6.1 Directly From You

When you register for an account, link a payment method, configure contribution or rewards preferences, contact support, respond to a survey, or otherwise interact with the Platform.

6.2 From Your Linked Financial Accounts

Through secure integrations with card networks, issuers, acquirers, payment processors, and open-banking aggregators. These integrations typically exchange tokenized identifiers and transaction metadata rather than raw financial credentials.

6.3 From Organizations and Sponsors

Organizations, sponsors, and merchants may provide us with information about their users, members, participants, employees, campaigns, and programs in connection with the services Elev8 provides to them. Where a customer organization independently characterizes a program as charitable or fundraising in nature, it does so under its own terms, disclosures, and regulatory obligations, not Elev8’s.

6.4 From Identity Verification & Fraud-Prevention Vendors

When required, we use regulated identity verification and fraud-prevention providers that return pass/fail indicators, risk scores, and, in limited cases, verification artifacts.

6.5 Automatically

Through cookies, pixels, SDKs, APIs, server logs, tag-management systems, analytics SDKs, and other tracking technologies that collect device, network, and usage information.

6.6 From Public Sources

Including publicly available business registries, government records, social-media business profiles, and commercial data providers, for purposes such as KYB, sanctions screening, and enrichment of organizational records.

6.7 From Referrals and Co-Marketing Partners

When a referrer or partner tells us about you, or when you are enrolled in a program by an entity authorized to do so.

7. HOW WE USE INFORMATION

We use Personal Information for the purposes described below. A single data element may support more than one purpose.

7.1 Core Platform Operations

  • Create and administer accounts, authenticate users, and manage access.
  • Enable card-linking and transaction-triggered functionality.
  • Calculate round-up amounts, process contribution instructions, and coordinate settlement with partner financial institutions.
  • Issue, track, redeem, and expire rewards, points, credits, and offers.
  • Deliver dashboards, reports, analytics, and administrative tools to enterprise customers.
  • Process sponsor campaigns, match programs, and funding allocations.

7.2 Service Improvement & Analytics

  • Measure performance, reliability, and feature adoption.
  • Conduct research, modeling, A/B testing, and product development.
  • Personalize content, offers, and recommendations.
  • Build de-identified and aggregated datasets for benchmarking and trend analysis.

7.3 Trust, Safety, Security & Fraud Prevention

  • Detect, investigate, and prevent fraudulent, deceptive, malicious, or illegal activity.
  • Secure our systems, including through logging, monitoring, and anomaly detection.
  • Verify identities and organizational eligibility.
  • Enforce our terms, policies, and contractual commitments.

7.4 Communications

  • Send transactional and service messages (account notices, security alerts, receipts, statement-style updates).
  • Provide customer support and respond to inquiries.
  • Send marketing, promotional, and program-related communications, subject to your consent where required and with an unsubscribe mechanism.
  • Deliver push notifications, SMS messages, and in-app messages where you have opted in.

7.5 Legal & Regulatory Compliance

  • Comply with applicable laws, regulations, court orders, and lawful requests from authorities.
  • Comply with anti-money-laundering (AML), sanctions, counter-terrorism financing (CTF), and fraud-prevention obligations imposed on us or our partners.
  • Respond to legal process and enforce our legal rights.

7.6 Corporate Transactions

  • Evaluate, negotiate, and complete mergers, acquisitions, reorganizations, financings, divestitures, and similar transactions.

7.7 With Your Consent

  • For any purpose we describe to you at the time of collection and to which you consent.

8. LEGAL BASES FOR PROCESSING

Where applicable law (such as the EU/UK GDPR, LGPD, or similar frameworks) requires us to identify a legal basis for processing, we rely on one or more of the following:

  • Performance of a contract: processing necessary to provide the Platform and fulfill obligations to you.
  • Consent: where you have given us specific, informed, and unambiguous consent, which you may withdraw at any time.
  • Legitimate interests: our or a third party’s legitimate interests (for example, operating, improving, and securing the Platform), balanced against your rights and freedoms.
  • Legal obligation: processing required to comply with a legal duty.
  • Vital interests: processing necessary to protect the life or health of an individual.
  • Public interest: where processing is carried out in the public interest or the exercise of official authority.

9. HOW WE DISCLOSE INFORMATION

We do not sell Personal Information in exchange for monetary consideration. Depending on your jurisdiction, certain data-sharing may nevertheless be considered a “sale” or “sharing” under law, and you have rights to opt out as described in Section 17.

We disclose Personal Information in the following circumstances:

9.1 Service Providers and Processors

We share information with vendors that perform services for us under written contracts, including:

  • Cloud hosting, storage, and infrastructure providers.
  • Payment processors, card networks, issuer processors, and banking partners.
  • Identity verification, KYC/KYB, AML, and sanctions-screening providers.
  • Analytics, product-telemetry, and crash-reporting providers.
  • Customer support, ticketing, and communications providers (email, SMS, push).
  • Fraud detection, device-reputation, and risk-scoring providers.
  • Tax, accounting, audit, and legal advisors.

9.2 Organizations, Sponsors & Merchant Partners

  • Organizations may receive information about their members, participants, and enrolled users, for example, enrollment, program-activity, and engagement data.
  • Sponsors may receive aggregated campaign results and, where permitted, limited user-level interaction data.
  • Merchants may receive tokenized qualifying-transaction signals for offer fulfillment.

9.3 Financial Institutions, Card Networks & Payment Providers

For card-linking, offer fulfillment, contribution settlement, and reconciliation, we exchange tokenized identifiers and transaction metadata with participating financial institutions and payment providers.

9.4 Legal, Regulatory & Safety Disclosures

  • To comply with applicable laws, regulations, legal process, and enforceable governmental requests.
  • To enforce our terms, protect our and others’ rights, privacy, safety, or property, and investigate suspected fraud or illegal activity.

9.5 Corporate Transactions

In connection with a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or similar transaction, Personal Information may be transferred as a business asset, subject to appropriate confidentiality and data-protection commitments.

9.6 With Your Direction or Consent

When you explicitly direct or authorize us to share information, including via connected-account permissions.

9.7 Aggregated and De-identified Disclosures

We may disclose aggregated, anonymized, or de-identified data that does not reasonably identify you, for any lawful purpose, including benchmarking, research, marketing, and industry reporting.

10. SUB-PROCESSORS AND VENDOR MANAGEMENT

We engage sub-processors to help us deliver the Platform. Each sub-processor is contractually obligated to:

  • Process Personal Information only on our documented instructions.
  • Implement appropriate technical and organizational measures.
  • Assist us with security, breach response, and data-subject requests.
  • Comply with applicable data-protection laws, including GDPR Article 28-style requirements where relevant.

A current list of key sub-processors is maintained and available upon request to enterprise customers under a Data Processing Addendum (DPA). We perform risk assessments before onboarding sub-processors and on a periodic basis thereafter.

11. FINANCIAL DATA PRIVACY (GLBA CONTEXT)

Elev8 is not itself a financial institution within the meaning of the Gramm-Leach-Bliley Act (GLBA) or the Federal Trade Commission’s Safeguards Rule. Elev8 does not establish customer relationships under GLBA, does not solicit financial products or services, and does not issue GLBA privacy notices in its own name.

Elev8 may, however, act as a service provider to GLBA-regulated institutions. In that capacity, Elev8 processes nonpublic personal information (“NPI”) only as a service provider, strictly under written contract and pursuant to the documented instructions of the regulated institution. The regulated institution remains the controller of its customers’ NPI and remains responsible for its GLBA Privacy Rule obligations to its customers, including providing initial and annual privacy notices and any applicable opt-out rights. Customers of any such institution should refer to that institution’s privacy notice for information about how their NPI is collected, used, and shared.

In support of GLBA-regulated institutions and other partners, Elev8 maintains administrative, technical, and physical safeguards consistent with the principles of the FTC Safeguards Rule and applicable financial-institution vendor-management expectations, including:

  • Designating a qualified individual to oversee our information-security program.
  • Conducting periodic risk assessments, access reviews, and security training.
  • Encrypting NPI in transit and at rest, applying least-privilege access controls, and monitoring for security events.
  • Overseeing sub-processors and other vendors that handle NPI on our behalf.
  • Cooperating with each institution’s vendor due diligence, audit rights, and incident-response requirements as set forth in our written agreement with the institution.
  • Limiting the collection, use, retention, and disclosure of NPI to what is necessary to deliver the contracted services.

Nothing in this Section is intended to characterize Elev8 as a “financial institution” for purposes of GLBA or to subject Elev8 to obligations beyond those that apply to a service provider under contract with a covered institution.

12. PAYMENT CARD INDUSTRY (PCI-DSS) COMPLIANCE

Elev8 aligns its information-security practices with the requirements of the Payment Card Industry Data Security Standard (PCI-DSS) applicable to our role. To support that alignment, we generally:

  • Seek to minimize PCI-DSS scope by limiting Elev8’s interaction with raw cardholder data and by relying on tokenization performed by validated payment service providers.
  • Use PCI-DSS-validated service providers and gateways for the handling, transmission, and storage of cardholder data.
  • Apply security practices consistent with PCI-DSS principles, such as network segmentation, encryption, access controls, and logging, to systems within applicable scope.
  • Periodically assess and document our PCI-DSS posture in a manner appropriate to our role, in coordination with our payment service providers and, where applicable, our Business Customers.

PCI-DSS responsibilities are typically shared among Elev8, our payment service providers, card networks, and our Business Customers, and the specific allocation depends on the integration model and use case.

13. CARD NETWORK AND TRANSACTION DATA RULES

Our card-linking and transaction-triggered features depend on participation in card-network programs (e.g., Visa, Mastercard, American Express, Discover) and issuer agreements. We handle transaction data in accordance with applicable network rules and program requirements, which may restrict retention, further disclosure, or use of transaction data for unrelated purposes.

14. OPEN BANKING AND FINANCIAL DATA SHARING

Where you choose to connect a bank account or other financial account, you may authorize an open-banking aggregator (such as a data-access provider or screen-scraping or API-based aggregator) to share specific financial data with Elev8. We honor authorization revocations you initiate through our Platform or through the aggregator. We align with industry frameworks such as the Financial Data Exchange (FDX) principles, including consumer consent, data minimization, traceability, and security.

15. DATA SECURITY

We maintain a written information-security program designed to protect Personal Information against unauthorized access, acquisition, alteration, disclosure, or destruction. Measures include:

15.1 Technical Safeguards

  • Encryption of data in transit using modern TLS configurations.
  • Encryption of sensitive data at rest using AES-256 or equivalent.
  • Tokenization and pseudonymization of high-sensitivity identifiers.
  • Network segmentation, firewalling, and web application firewalling.
  • Vulnerability scanning, patch management, and dependency monitoring.
  • Endpoint protection, centralized logging, and security information and event management (SIEM).
  • Secure software development lifecycle (SSDLC), code review, and static and dynamic testing.

15.2 Administrative Safeguards

  • Role-based access controls and least-privilege provisioning.
  • Multi-factor authentication for internal systems.
  • Security awareness training for personnel.
  • Background checks for personnel with access to sensitive data.
  • Incident response and business-continuity plans that are tested periodically.
  • Vendor and third-party risk management, including due diligence and contractual safeguards.

15.3 Physical Safeguards

  • Use of reputable cloud and data-center providers with SOC 2 Type II, ISO 27001, or comparable certifications.
  • Controlled, logged access to any office locations where sensitive data may be handled.

No method of transmission or storage is 100% secure. While we work hard to protect your information, we cannot guarantee its absolute security.

16. DATA RETENTION

We retain Personal Information only as long as necessary to fulfill the purposes for which it was collected, including for:

  • Providing the Platform and honoring your preferences.
  • Complying with legal, regulatory, tax, accounting, and reporting obligations.
  • Resolving disputes and enforcing agreements.
  • Protecting against fraud and abuse.

Retention periods may vary depending on the type of data involved, the specific purpose for which it was collected, the legal or contractual obligations that apply, and any active legal holds. We use the following criteria to determine how long to keep each category of information: the duration of our relationship with you; the nature, sensitivity, and volume of the information; the potential risk of harm from unauthorized use or disclosure; the purposes for which we process the information and whether we can achieve those purposes through other means; and applicable legal, regulatory, tax, accounting, audit, and reporting requirements.

By way of illustration only, the table below shows representative retention ranges. Actual retention for any given record may be shorter or longer based on the specific legal basis or operational need that applies.

After an applicable retention period ends, we delete, destroy, or irreversibly de-identify the Personal Information, subject to legal holds, backup cycles, and technical limitations of our systems. The table above is illustrative and not exhaustive; it does not establish a fixed retention period for any specific record.

17. YOUR PRIVACY RIGHTS

Depending on where you live and the law that applies, you may have some or all of the rights described below. We respond to verifiable requests within the timelines required by applicable law.

17.1 Rights Generally Available

  • Right to know or access: request what Personal Information we process about you.
  • Right to correct: request correction of inaccurate or outdated information.
  • Right to delete: request deletion of your Personal Information, subject to legal exceptions.
  • Right to portability: request a copy of your information in a structured, commonly used, machine-readable format.
  • Right to opt out of sale and sharing: opt out of sales and of cross-context behavioral advertising.
  • Right to limit use of sensitive information: restrict certain uses of sensitive categories.
  • Right to opt out of automated decision-making and profiling: where such processing has legal or similarly significant effects.
  • Right to appeal: appeal the denial of a rights request.
  • Right to non-discrimination: exercise your rights without being denied service, charged different prices, or receiving a different level of service.
  • Right to withdraw consent: withdraw previously granted consent, without affecting the lawfulness of prior processing.

17.2 California (CCPA/CPRA)

California residents have the rights listed above, and we provide the following additional disclosures:

  • Categories of Personal Information collected, as described in Section 5.
  • Categories of sources, as described in Section 6.
  • Business or commercial purposes for collection, as described in Section 7.
  • Categories of third parties to whom we disclose Personal Information, as described in Section 9.
  • Whether we “sell” or “share” (for cross-context behavioral advertising) Personal Information, we do not sell Personal Information for money, and any “sharing” is limited to the contexts described in Section 9.
  • Your right to limit the use and disclosure of Sensitive Personal Information.

California “Shine the Light” (Cal. Civ. Code § 1798.83): California residents may request information about our disclosure of Personal Information to third parties for their direct marketing purposes.

17.3 Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA)

Residents of Virginia, Colorado, Connecticut, and Utah have rights to access, correct (where applicable), delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. Colorado and Connecticut residents may also use recognized universal opt-out mechanisms such as the Global Privacy Control (GPC).

17.4 Texas (TDPSA), Oregon (OCPA), Montana (MTCDPA), Iowa (ICDPA), Delaware (DPDPA), New Hampshire, New Jersey, Tennessee, Indiana, Minnesota, Maryland, Rhode Island

Residents of these states have substantially similar rights under their respective comprehensive privacy laws. We honor verifiable requests in accordance with those laws, including rights to access, correct, delete, port, opt out of sales and targeted advertising, and, where applicable, opt out of certain profiling and of processing of Sensitive Data without consent.

17.5 How to Exercise Your Rights

Submit a request by:

  • Emailing privacy@letselev8.com with the subject line “Privacy Rights Request”.
  • Using the in-Platform privacy center (if available to your account).
  • Writing to Elev8 Privacy Office, 1621 Central Avenue, Cheyenne, WY 82001, USA.

We will verify your request using information we already have about you. An authorized agent may submit a request on your behalf with a signed, written authorization (and, where required, proof of identity). If we deny your request, you may appeal by replying to our decision; we will respond to appeals within the timeframe required by applicable law.

18. EUROPEAN ECONOMIC AREA, UNITED KINGDOM, AND SWISS RIGHTS

If you are in the EEA, United Kingdom, or Switzerland, you have additional rights under the EU GDPR, UK GDPR, or Swiss FADP, including rights to:

  • Access, rectification, erasure, restriction of processing, data portability, and objection.
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Lodge a complaint with a supervisory authority.
  • Object to processing based on legitimate interests or for direct marketing.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

If you are in the EEA, UK, or Switzerland, you may contact us at privacy@letselev8.com. Where required, we will appoint a representative for purposes of Article 27 GDPR or UK GDPR.

19. CANADIAN PRIVACY RIGHTS (PIPEDA AND PROVINCIAL LAWS)

If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws (e.g., Quebec Law 25, BC PIPA, Alberta PIPA) may apply. You have rights to access and correct your Personal Information, to withdraw consent (subject to legal or contractual restrictions), and to file a complaint with the Office of the Privacy Commissioner of Canada or provincial counterpart.

20. OTHER INTERNATIONAL JURISDICTIONS

Where applicable, we comply with additional data-protection frameworks such as Brazil’s LGPD, Australia’s Privacy Act (APPs), and other relevant national or regional laws. Users in those jurisdictions may contact us to exercise rights granted under their local laws.

21. COOKIES AND TRACKING TECHNOLOGIES

We and our authorized partners use cookies and similar technologies (pixels, tags, beacons, SDKs, local storage) for the purposes described below:

You can manage cookie preferences through our cookie-preferences tool (where available), browser settings, device-level opt-outs, and industry tools such as the Digital Advertising Alliance’s YourAdChoices, the Network Advertising Initiative’s opt-out, and the European Interactive Digital Advertising Alliance (EDAA). On mobile devices, you may reset or limit advertising identifiers through your device settings.

We also recognize the Global Privacy Control (GPC) and similar universal opt-out signals where required by law.

22. THIRD-PARTY SERVICES AND INTEGRATIONS

The Platform integrates with third parties, including financial institutions, card networks, payment processors, sponsors, merchants, identity verification providers, and analytics providers. These third parties operate under their own privacy policies. We are not responsible for the privacy practices of third parties we do not control. Before linking an account, installing an integration, or transmitting data to a third party, we encourage you to review that party’s privacy notice.

23. CHILDREN’S PRIVACY

The Platform is not directed to or designed for children under 13, and Elev8 does not knowingly collect Personal Information directly from children under 13 (or under 16 where a higher threshold applies under applicable law). Elev8 does not target advertising to children and does not knowingly enable other parties to do so through the Platform.

23.1 Schools, Youth Sports, and Similar Organizations

Elev8 may provide its technology to schools, youth-sports organizations, after-school programs, parent to teacher associations, faith communities, and similar organizations whose participants may include minors. Where such an organization enrolls minors on or through the Platform:

  • The organization, not Elev8, is responsible for determining whether minors will be enrolled and for obtaining any parental, guardian, school-authority, or other consents required by applicable law before any information about a minor is provided to, or processed through, the Platform. We rely on organizations to obtain any required parental consents where they enroll minors.
  • The organization acts as the controller (or, where permitted, as the school-authorized agent of parents or guardians) for any information about minors, and is responsible for all related notices, disclosures, age-screening, and consent processes.
  • Elev8 acts solely as a service provider or processor under contract with the organization, and processes any information about minors only as needed to deliver the contracted services and only as instructed by the organization.
  • Where applicable, Elev8 supports the organization’s compliance with the Children’s Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), the Protection of Pupil Rights Amendment (PPRA), state student-privacy laws (such as California’s SOPIPA), and similar laws, but Elev8 itself is not a COPPA “operator” directed to children, an educational institution, or a “school official” under FERPA.

23.2 Inadvertent Collection

Despite our practices, information about a minor could be inadvertently provided to the Platform, for example, through an organization, a sponsor, or a user. If Elev8 becomes aware that it has inadvertently collected Personal Information from a child in a manner that requires verifiable parental consent under applicable law and such consent has not been obtained, Elev8 will take reasonable steps to delete or restrict the information.

If you are a parent or legal guardian and believe that information about your child has been provided to the Platform without appropriate consent, please contact privacy@letselev8.com so we can promptly investigate and, where appropriate, delete the information.

24. INTERNATIONAL DATA TRANSFERS

Elev8 is based in the United States, and our service providers may be located in the United States, Canada, the European Economic Area, the United Kingdom, and other jurisdictions. Where we transfer Personal Information across borders, we rely on legally recognized transfer mechanisms, including:

  • Standard Contractual Clauses (EU SCCs) and the UK International Data Transfer Addendum.
  • Adequacy decisions where available.
  • Derogations for specific situations as permitted by law.
  • Supplementary technical, contractual, and organizational measures where appropriate, informed by transfer impact assessments.

25. BIOMETRIC INFORMATION

We do not collect or store biometric templates (such as fingerprint, face, voiceprint, or iris templates). When you choose to use device-based biometric authentication (for example, Face ID or Touch ID) to access the Platform, the biometric processing occurs on your device, and your device returns only a success/failure signal to us. Where state laws such as the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI, or Washington HB 1493 would otherwise apply, we confirm that Elev8 does not collect, capture, or purchase biometric identifiers from you.

26. HEALTH AND MEDICAL INFORMATION

Elev8 is not a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA). The Platform is not designed to handle protected health information (PHI), and you should not submit PHI to Elev8. Where we operate with healthcare-adjacent organizations, we do so under appropriate contracts that restrict the categories of data shared.

27. DATA MINIMIZATION AND PRIVACY BY DESIGN

Elev8 applies privacy-by-design principles throughout product development and operations:

  • Data minimization: collecting only what is reasonably necessary for each purpose.
  • Purpose limitation: using information only for the purposes disclosed or compatible purposes.
  • Storage limitation: retaining information only as long as needed.
  • Accuracy: providing tools to update and correct your information.
  • Security by default: applying secure defaults in products and integrations.
  • Transparency: providing clear, layered, and timely notices.
  • User control: offering meaningful choices, including opt-outs and granular preferences.

28. AUTOMATED DECISION-MAKING AND PROFILING

We may use automated processing and profiling for purposes such as:

  • Fraud detection, risk scoring, and transaction-anomaly detection.
  • Rewards optimization and offer personalization.
  • Engagement scoring and campaign analytics.
  • Eligibility checks for specific program features.

We do not use solely automated processing to make decisions that produce legal or similarly significant effects on you without appropriate safeguards (such as meaningful human review, the ability to contest a decision, or the ability to request reconsideration). Where required by law, you may object to such processing or request human review by contacting privacy@letselev8.com.

29. ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING

Elev8 may use machine-learning, artificial-intelligence, and similar analytics techniques to operate, secure, monitor, support, and improve the Platform, for example, for fraud detection, anomaly detection, transaction-pattern analysis, engagement analytics, and product personalization.

Where we train, fine-tune, or evaluate models using information that may include Personal Information, we apply technical and organizational safeguards designed to reduce risk, including de-identification or aggregation where feasible, access controls, logging, vendor due diligence, and contractual restrictions on our service providers’ permitted use of data.

We do not knowingly use Personal Information to train, fine-tune, or improve generative-AI or foundation models in ways that are materially incompatible with the purposes for which the information was collected, and we do not knowingly sell Personal Information to third parties for model-training purposes. We do not knowingly permit our service providers to use Elev8 customer data to train their own publicly available models, except as expressly permitted in our written agreements with them.

Enterprise and Business Customers may have additional contractual commitments regarding model training, prompt and output retention, model isolation, and acceptable use of customer data in their separate agreements with Elev8, which will control over this Section to the extent of any conflict.

The AI and data-protection landscape is evolving rapidly. Our specific practices, vendors, and safeguards may change over time, and we will update this Policy or related notices as needed to reflect material changes in our use of AI or machine learning.

30. DO NOT TRACK SIGNALS AND GLOBAL PRIVACY CONTROL

Because there is no industry consensus on how to interpret browser “Do Not Track” (DNT) signals, we do not currently respond to DNT signals. Where required by law, we recognize Global Privacy Control (GPC) and other universal opt-out mechanisms as a valid request to opt out of sale and sharing of Personal Information.

31. DATA BREACH NOTIFICATION

We maintain a formal incident-response program. In the event of a security incident involving Personal Information, we will:

  • Contain and investigate the incident without undue delay.
  • Coordinate with forensic, legal, and regulatory advisors as appropriate.
  • Notify affected individuals, regulators, partners, and customers as required by applicable law and contract, including state breach-notification statutes, GDPR Articles 33 to 34, and similar obligations.
  • Take remedial steps to reduce the likelihood and impact of recurrence.

32. ACCESSIBILITY

We strive to make our Platform and our privacy notices accessible. If you need this Policy or any privacy tool in an alternative format, please contact privacy@letselev8.com.

33. USER-GENERATED CONTENT, FEEDBACK & REFERRALS

If you submit comments, reviews, feedback, testimonials, referrals, or other content through the Platform, that content, along with any information you choose to include, may be stored, processed, and, where appropriate, displayed by Elev8 or shared with the applicable organization or sponsor. Do not submit information you do not wish to be collected and processed in this way.

34. MARKETING COMMUNICATIONS AND OPT-OUT

We may contact you about products, offers, campaigns, and program updates by email, SMS, push notification, phone, or mail, as permitted by law and subject to your preferences.

  • Email marketing: you may unsubscribe using the link in any marketing email.
  • SMS marketing: you may reply STOP to any marketing text or follow the instructions in the message.
  • Push notifications: you may disable these in your device settings.
  • Telemarketing: where applicable, we honor Do-Not-Call and similar registries.

Even if you opt out of marketing, we may still send service and transactional messages necessary to operate the Platform.

35. SPONSOR AND ORGANIZATION DATA PRACTICES

When an organization or sponsor uses Elev8 to operate a campaign, program, or initiative:

  • The organization or sponsor may be considered a separate data controller or business with its own privacy obligations.
  • Elev8 acts as a service provider, processor, or sub-processor to that organization or sponsor for its instructed processing.
  • Information you provide directly to that organization or sponsor is governed by its privacy notice, not this Policy.
  • We take reasonable steps to ensure that organization and sponsor data practices within the Platform are consistent with applicable law.

36. AGGREGATED AND DE-IDENTIFIED DATA

We create and use aggregated, anonymized, and de-identified data that cannot reasonably be linked back to you. Where applicable law requires, we maintain technical and organizational controls to prevent re-identification and contractually restrict recipients from attempting re-identification. Aggregated and de-identified data are not considered Personal Information for purposes of this Policy.

37. CHANGES TO THIS POLICY

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make a material change, we will provide reasonable notice, such as by posting the updated Policy with a new “Last Updated” date, sending an email, or displaying an in-Platform notice. Your continued use of the Platform after the revised Policy becomes effective constitutes acceptance of the changes.

38. DISPUTES

Any disputes regarding this Policy or the Platform are subject to the dispute-resolution, governing-law, and venue provisions set forth in our Terms of Service and, where applicable, in any master agreement between Elev8 and a business customer. Nothing in this Policy limits rights that cannot be waived under applicable law.

39. GOVERNING LAW

This Policy is governed by the laws of the State of Wyoming, USA, without regard to its conflict-of-laws principles, except where mandatory consumer or data-protection laws of your jurisdiction require otherwise.

40. DATA PROTECTION AND PRIVACY CONTACTS

Elev8 has designated a Privacy Office responsible for overseeing our privacy program. The Privacy Office coordinates our privacy-by-design, vendor-management, training, and incident-response activities, and serves as the principal point of contact for privacy inquiries. Where we are required to designate a Data Protection Officer (DPO), an EU representative under Article 27 of the EU GDPR, or a UK representative under the UK GDPR, we will do so and update this Policy accordingly.

As part of our accountability program, and where required by applicable law (including the EU/UK GDPR, the Swiss FADP, the LGPD, and analogous frameworks):

  • Records of Processing Activities (RoPA). We maintain records of our processing activities consistent with the principles of GDPR Article 30 and analogous laws, documenting the purposes of processing, categories of data and data subjects, categories of recipients, international transfers, retention, and the technical and organizational safeguards we apply.
  • Data Protection Impact Assessments (DPIAs). Where required, including for processing that is likely to result in a high risk to the rights and freedoms of individuals under GDPR Article 35 or analogous laws, we conduct DPIAs to identify, evaluate, and mitigate privacy risks before processing begins, and we consult supervisory authorities where consultation is required.
  • Privacy and security risk assessments. We perform privacy and security risk assessments before introducing new products, features, vendors, or processing activities that materially change how we handle Personal Information.
  • Training and accountability. Personnel with access to Personal Information receive privacy and security training appropriate to their role, and our policies, procedures, and safeguards are reviewed and updated periodically.

Privacy contacts:

General privacy: privacy@letselev8.com

Security: security@letselev8.com

Legal notices: legal@letselev8.com

41. CONTACT INFORMATION

For questions, concerns, or requests related to this Policy or our privacy practices:

ForGood Technologies, LLC (d/b/a Elev8 Technologies)

Attn: Privacy Office

1621 Central Avenue, Suite 9191

Cheyenne, WY 82001, USA

Email: privacy@letselev8.com

Website: letselev8.com

42. IMPORTANT DISCLAIMER

Elev8 is a technology provider. For clarity:

  • Elev8 is not a bank, credit union, trust company, financial institution, issuer, acquirer, money transmitter, money services business, broker-dealer, investment adviser, insurance company, or charitable organization.
  • Elev8 does not hold, custody, escrow, invest, lend, or transmit funds, and does not act as a merchant of record, fiduciary, trustee, or agent for any user, organization, or sponsor.
  • Elev8 does not provide financial, tax, investment, accounting, legal, fundraising, donor-development, or charitable-solicitation advice or services.
  • Financial transactions are processed, and funds are held, by third-party financial institutions, payment processors, and service providers under separate agreements with you, sponsors, or organizations.
  • Rewards, points, credits, sponsor-funded payouts, program payments, and other program benefits are provided under the terms of the applicable program, which may be offered by an organization, sponsor, or partner rather than by Elev8.
  • Elev8 is not a party to, and makes no representations regarding, any transaction, transfer, gift, pledge, donation, or relationship between a user and any organization, sponsor, merchant, or financial institution.

43. NOT A FUNDRAISING PLATFORM; TAX AND CHARITABLE-SOLICITATION DISCLAIMER

43.1 Elev8 Is Not a Fundraising Platform or Charitable Organization

Elev8 is a technology and software provider. Elev8 is not, and does not operate as, any of the following:

  • A charitable organization, nonprofit entity, 501(c)(3), 501(c)(4), or other tax-exempt organization.
  • A fundraising platform, fundraising portal, crowdfunding platform, charitable giving platform, or online solicitation platform.
  • A charitable sales promotion organizer, commercial co-venturer, cause-marketing administrator, or professional solicitor.
  • A professional fundraiser, commercial fundraiser, fundraising counsel, or fundraising consultant within the meaning of any state Charitable Solicitations Act or comparable law.
  • A donor-advised fund sponsor, community foundation, charitable trust, charitable gift fund, or charitable intermediary.
  • A payment processor, merchant of record, or money transmitter for charitable contributions, donations, gifts, or pledges.

43.2 No Solicitation, Acceptance, or Processing of Charitable Contributions

Elev8 does not solicit, request, accept, hold, process, transmit, disburse, acknowledge, or receipt charitable contributions, donations, gifts, or pledges, and does not make any representation that any payment, round-up, reward, transfer, or other transaction on the Platform is a charitable contribution, a tax-deductible payment, or otherwise has any charitable, gift-tax, or income-tax character.

The term “Fund Capturing Platform” refers to Elev8’s technology-enabled mechanics, including card-linking, round-ups, rewards, loyalty, and sponsor-funded program payouts, and is not a description of fundraising, charitable solicitation, or gift processing. Elev8 provides software; it does not raise, collect, or administer charitable funds.

43.3 Customer Responsibility for Fundraising and Charitable Compliance

Organizations, sponsors, enterprise customers, financial institutions, and other third parties that deploy the Platform are solely responsible, as applicable, for:

  • Registration and annual renewal as a charity, commercial fundraiser, fundraising counsel, professional solicitor, commercial co-venturer, or charitable sales promotion organizer under applicable state Charitable Solicitations Acts or comparable laws (including the laws of California, New York, Florida, Illinois, Massachusetts, and other states that regulate charitable solicitation).
  • All donor-, member-, and participant-facing disclosures required by law, including solicitation disclosures, tax-deductibility statements, quid-pro-quo acknowledgments, and charitable-sales-promotion notices.
  • Tax receipting, acknowledgment letters, IRS Form 990 reporting, Form 8283/8282 handling, and any other U.S. federal, state, or local tax reporting.
  • Ensuring the accuracy of any representation about charitable status, tax-exempt status, tax deductibility, or the destination or use of funds.
  • Obtaining and maintaining any license, bond, charter, or authority required to solicit, accept, or administer charitable or donor funds.
  • Complying with all applicable privacy, consumer-protection, advertising, and telemarketing laws in connection with any fundraising, donor, or member communications.

Elev8 does not verify, endorse, audit, or assume responsibility for any customer’s charitable status, solicitation registrations, tax-exempt determinations, or donor-facing representations, and is not liable for any customer’s failure to comply with charitable or fundraising laws.

43.4 Tax Disclaimer

Elev8 does not provide tax advice. Nothing on the Platform constitutes an opinion or representation that any amount is deductible as a charitable contribution or has any particular tax treatment. Users should consult their own qualified tax advisors regarding the tax consequences of any payment, round-up, reward, or other transaction.

43.5 Program and Offer Terms Govern

The legal relationship between a user and any program, offer, campaign, benefit, reward, or sponsor-funded payout is governed by the terms of the applicable organization, sponsor, merchant, or financial institution, not by Elev8. Elev8 is not a party to any gift, pledge, donation, subscription, purchase, or similar transaction, and Elev8’s role is limited to providing the technology under which such programs operate.

43.6 No Fiduciary Duty

Nothing in this Policy or in Elev8’s provision of the Platform creates any fiduciary, trust, agency, escrow, or similar relationship between Elev8 and any user, organization, sponsor, or other person.

44. APPENDIX A, CATEGORIES, PURPOSES, AND RECIPIENTS

The table below summarizes the categories of Personal Information we process, the purposes of processing, and the categories of recipients. This appendix is provided to support transparency obligations under laws such as the CCPA/CPRA and GDPR.

Start the loop.

Real humans, fast replies. Tell us a little and we'll take it from there.