This Privacy Policy ("Policy") explains how VANTO TECH PTE. LTD. ("Vanton," "we," "our," or "us") collects, uses, discloses, and protects your personal data when you use our corporate card platform and related services (the "Services"). We are committed to complying with applicable data protection regulations, including the Personal Data Protection Act 2012 (PDPA) of Singapore and the General Data Protection Regulation (GDPR) of the European Union.
1 Information We Collect
1.1 Personal Information
When you register for an account or use our Services, we may collect the following personal information:
- Full name, email address, phone number, and job title
- Company name, registration number, and business address
- Government-issued identification documents for KYC verification
- Date of birth and nationality
- Bank account and financial information
1.2 Usage Data
We automatically collect certain information about how you interact with our Services:
- Device information (type, operating system, browser type)
- IP address and approximate geographic location
- Pages visited, features used, and time spent on the platform
- Referring URLs and search terms
- Error logs and performance data
1.3 Transaction Data
When you use Vanton corporate cards, we collect:
- Transaction amounts, dates, and merchant information
- Card usage patterns and spending categories
- Receipt images and expense documentation
- Approval and workflow data
2 How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve our corporate card and expense management services.
- Identity Verification: To comply with KYC/AML regulations and verify your identity and business credentials.
- Transaction Processing: To process card transactions, manage balances, and provide real-time notifications.
- Analytics & Insights: To generate spending reports, analytics, and business insights for your organization.
- Security & Fraud Prevention: To detect, prevent, and respond to fraud, unauthorized access, and other security threats.
- Communications: To send you service updates, security alerts, and relevant product information.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
3 Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
- Card Network Partners: Payment processors and card networks (e.g., Visa, Mastercard) to facilitate transactions.
- Banking Partners: Licensed financial institutions that issue cards on our platform.
- Service Providers: Third-party vendors who assist us with hosting, analytics, customer support, and identity verification, subject to strict data processing agreements.
- Regulatory Authorities: Government agencies and regulators when required by law or to comply with legal obligations.
- Your Organization: Administrators within your company who manage your corporate card program.
Our Commitment: All third-party service providers are contractually bound to protect your data and may only use it for the specific purposes we have authorized.
4 Data Security
We implement comprehensive security measures to protect your personal data, including:
- AES-256 encryption for data at rest and TLS 1.3 for data in transit
- PCI DSS Level 1 compliance for all card data handling
- Multi-factor authentication and role-based access controls
- Regular security audits, penetration testing, and vulnerability assessments
- 24/7 monitoring and automated threat detection systems
- Secure data centers with SOC 2 Type II certification
5 Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required by law. Specifically:
- Account Data: Retained for the duration of your account plus 7 years after closure, as required by financial regulations.
- Transaction Records: Retained for a minimum of 5 years in accordance with anti-money laundering requirements.
- Usage Data: Retained for up to 2 years for analytics and service improvement purposes.
- Marketing Data: Retained until you withdraw consent or unsubscribe.
6 Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
GDPR & PDPA Rights: We honor data subject rights under both European and Singaporean data protection laws.
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
- Right to Restrict Processing: Request that we limit the processing of your data in certain circumstances.
- Right to Data Portability: Request a copy of your data in a structured, machine-readable format.
- Right to Object: Object to the processing of your personal data for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us at service@vantocard.com. We will respond to your request within 30 days.
7 Cookies
We use cookies and similar tracking technologies to enhance your experience on our platform. Types of cookies we use include:
- Essential Cookies: Required for the operation of our platform, including authentication and security.
- Analytics Cookies: Help us understand how visitors interact with our platform to improve the user experience.
- Functional Cookies: Remember your preferences and settings for a personalized experience.
You can manage your cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of our Services.
8 International Data Transfers
As a global service provider, we may transfer your personal data to countries outside of your jurisdiction. When we do so, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data processing agreements with all international service providers
- Ensuring recipient countries provide adequate levels of data protection
- Implementing additional technical and organizational security measures
9 Children's Privacy
Our Services are designed for businesses and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we discover that we have inadvertently collected data from a minor, we will take immediate steps to delete such information.
10 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Post the updated Policy on our website with a revised "Last Updated" date
- Notify you via email or through a prominent notice on our platform
- Obtain consent where required by applicable law
We encourage you to review this Policy periodically to stay informed about how we are protecting your data.
11 Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:
VANTO TECH PTE. LTD.
Data Protection Officer
Email: service@vantocard.com
Website: vantocard.com
Singapore