Privacy Policy
Invoto Inc. ("Invoto," "we," "us," or "our") provides technology that lets businesses open and manage deposit accounts, make and receive payments, use commercial cards, and manage spend. This Privacy Policy explains what information we collect, how we use and share it, how we protect it, and the choices and rights you have.
For purposes of this Privacy Policy, "Site" means Invoto's website at https://invoto.com or https://invoto.io, "Service" means the Invoto products and services accessed through the Site or our applications, and "you" means a visitor to the Site, a business customer, or an individual acting on behalf of a business customer — including owners, beneficial owners, officers, authorized representatives, employee cardholders, and other authorized users. It also includes vendors, payees, and other counterparties whose information we process because one of our customers sends or receives a payment involving them, as described in Section 2.6.
This Privacy Policy is incorporated into and supplements the Invoto Terms of Service and Cookie Policy.
1. Invoto is not a bank; who this notice covers
Invoto is a financial technology company and not a bank. Banking services are provided by i3 Bank, Member FDIC.
Your deposit account is held by i3 Bank, which is the financial institution of record. i3 Bank maintains its own privacy notice governing the information it collects and holds in that capacity. i3 Bank provides that notice to you directly when you open your account, and makes it available through the Invoto application. It is not replaced by this one. Where the two differ with respect to your deposit account, i3 Bank's notice controls as to i3 Bank's own practices.
2. Information We Collect
The information we collect depends on how you interact with us. Some information is collected by Invoto. Some is collected directly by our partner bank or its service providers through embedded components, in which case Invoto may never receive or store it.
Information Invoto does not receive
Sensitive identifying information required to open and maintain your account is collected directly by our partner bank and its service providers through components embedded in the Service. Invoto does not receive or store it. This includes Social Security and taxpayer identification numbers, dates of birth, government-issued identification and images of it, beneficial ownership information, bank account and routing numbers, and full payment card numbers.
2.1 Information you provide to us
When you create an account, apply for or use the Service, or contact us, we collect information such as your name, email address, telephone number, mailing address, job title, the name and address of your business, and the content of your communications with us. If you call our privacy request line and leave a message, we keep the recording of that message and the information in it.
2.2 Identity verification information (KYC / KYB)
Federal law requires financial institutions to obtain, verify, and record information identifying each person and business that opens an account. To open and maintain an account, information is collected about your business and about the individuals associated with it — including owners, beneficial owners, and control persons. This includes dates of birth, Social Security numbers or ITINs, government-issued identification and images of it, and ownership percentages.
That information is submitted directly to our partner bank and its identity verification providers through embedded components. Invoto does not receive or store it. Of the information collected for identity verification, Invoto receives only your Employer Identification Number and the business information you provide to us under Section 2.1.
2.3 Account, payment, and transaction information
In connection with the Service, we receive and store information about your accounts and activity, including account balances and transaction history. We also process payment instructions, card authorization and settlement records, spend limits and controls, receipts and invoices you upload, and information from accounts you connect to the Service.
We do not receive or store full bank account and routing numbers or full payment card numbers. The card authorization and settlement records we receive are tokenized and do not contain full card numbers. Where we need to help you identify an account or a card, we display and store only a truncated identifier, such as the last four digits.
When you connect an external bank account to the Service, the connection is operated by an account aggregator engaged by our partner bank rather than by Invoto. Your credentials for that external account are provided to that aggregator. Invoto does not receive, store, or control them, and the aggregator's handling of your information is governed by our partner bank's arrangements with it and by the bank's privacy notice, linked in Section 1.
Your credentials for the Invoto Service itself are handled by our identity provider, Auth0.
2.4 Information collected automatically
When you use the Site or the Service, we automatically collect device and usage information, including IP address, browser and device type, operating system, referring and exit pages, pages viewed, time and date of access, and information collected through cookies and similar technologies. Some of this information is used for fraud prevention, authentication, and security — including device fingerprinting and login and access logs — which we consider necessary to operate a financial service. See Section 6 and our Cookie Policy.
2.5 Information from third parties
We receive information about you from our partner bank and its service providers, identity verification and fraud prevention vendors, consumer and commercial reporting agencies, sanctions and watchlist screening providers, payment networks, business information providers, and persons who invite you to use the Service or submit your information as a beneficial owner or authorized user of their business.
2.6 Information about your vendors, payees, and other counterparties
When you use the Service to pay a vendor or receive a payment, we process information about the other party to that transaction. This may include their name, business name, contact details, payment details, and the record of payments between you and them. Where that other party is a sole proprietor or an individual, that information is personal information about them.
We receive this information from you, not from them. We use it only to carry out the payments and related services you ask us to perform, to meet our legal and compliance obligations, and to detect and prevent fraud. We do not use it to market to them, and we do not sell or share it for advertising.
If you are a vendor, payee, or other counterparty and want to know what information we hold about you, contact us at privacy@invoto.com or use our privacy request form. Because our relationship is with our customer rather than with you, we may need to refer you to them, and some information cannot be deleted while we are required to keep records of the underlying transactions.
2.7 Age requirement
The Site and the Service are intended for businesses and for individuals who are at least 18 years old. We do not knowingly collect information from anyone under 18, and the Service may not be used by anyone under 18. If we learn that we have collected information from someone under 18, we will delete it. If you believe we have done so, contact us at privacy@invoto.com.
3. How We Use Information
We use information to:
- provide, operate, and maintain the Service, including opening and servicing accounts, processing payments and card transactions, and providing support;
- verify your identity and the identity of your business and its beneficial owners, and to comply with know-your-customer, customer identification program, and beneficial ownership requirements;
- detect, investigate, and prevent fraud, unauthorized access, money laundering, terrorist financing, and other unlawful activity, and to conduct sanctions and watchlist screening;
- comply with applicable laws, regulations, legal process, and the requirements of our partner bank, payment networks, and regulators, and to respond to lawful requests;
- assess eligibility for accounts, credit products, and features, and to set limits and controls;
- maintain the security and integrity of the Site and the Service, including authentication, logging, and monitoring;
- communicate with you about your account, transactions, and changes to our terms, and to send marketing communications consistent with Section 7;
- analyze and improve the Service, develop new features, and produce internal reporting; and
- enforce our agreements and protect the rights, property, and safety of Invoto, our customers, and the public.
We do not sell your personal information for money. We do use advertising cookies and pixels on our website that may involve "selling" or "sharing" personal information for cross-context behavioral advertising as those terms are defined under state privacy laws. You can opt out at any time using the Do Not Sell or Share My Personal Information link in our website footer, and we honor Global Privacy Control signals automatically. See Section 6.
We do not use or disclose sensitive personal information for purposes other than those permitted under applicable law.
4. How We Share Information
We share information with:
- Our partner bank and its service providers, as necessary to open and maintain your account, process transactions, issue and service cards, and meet the bank's regulatory and compliance obligations;
- Service providers that perform functions on our behalf — including cloud hosting, identity verification, fraud prevention, payment processing, customer support, communications, and analytics — under contracts that limit their use of the information to providing services to us;
- Payment networks, card processors, and other financial institutions, as needed to complete transactions you authorize;
- Your business and its authorized users, including administrators of the account you are associated with, who can see activity and information relating to their business;
- Third parties you direct us to share with, including accounting and bookkeeping platforms you connect to the Service;
- Regulators, law enforcement, and other parties where we believe in good faith that disclosure is required by law or legal process, necessary to investigate suspected fraud or violations of our agreements, or necessary to protect the rights, property, or safety of Invoto, our customers, or the public; and
- Acquirers or successors in connection with a merger, acquisition, financing, or sale of all or part of our assets, subject to this Privacy Policy continuing to apply to the transferred information.
Aggregated and de-identified information. We may create aggregated or de-identified information that cannot reasonably be used to identify you, and may use it to operate, analyze, and improve the Service and to produce industry reporting. We maintain such information in de-identified form and do not attempt to reidentify it.
5. Data Retention
We retain information for as long as needed to provide the Service and for the periods required by law. Financial institutions and their service providers are subject to recordkeeping requirements that generally require retention of account and transaction records for at least five years after an account is closed or a transaction is completed. We apply that period to the records we hold, including business and account information, transaction history, and the receipts and invoices you upload. We may retain information longer where necessary to resolve disputes, enforce our agreements, or comply with legal, regulatory, audit, or partner-bank requirements.
Records held by our partner bank — including the identity verification information described in Section 2 — are retained by the bank under its own schedule, not ours.
We keep records of privacy requests and our responses to them, including any voicemail you leave on our privacy request line, for at least twenty-four months. We are required to be able to demonstrate how we handled your request, and we cannot do that without keeping a record of it.
6. Cookies, Tracking, and Analytics
We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Service, measure how the Site is used, and improve it. Some cookies are strictly necessary for the Service to function and cannot be disabled. Details on the categories we use and how to control them are in our Cookie Policy.
We use Google Analytics to understand how visitors use the Site. We also use Google Ads conversion tracking and the Meta pixel to measure the performance of our advertising. These providers set their own cookies, receive information about your visit to the Site, and may combine that information with information they hold about you from other sources. You can control cookies as described in our Cookie Policy.
We do not use third-party identity resolution to de-anonymize visitors to the Site.
Your choices about advertising
Depending on where you live, our use of Google Ads conversion tracking and the Meta pixel may be a "sale" or "share" of personal information for cross-context behavioral advertising. You can turn these off for your browser at any time using the Do Not Sell or Share My Personal Information link, which appears in the footer of every page on this Site.
We also honor the Global Privacy Control. If your browser or a browser extension sends a GPC signal, we treat it as a valid opt-out of sale and sharing and disable our advertising tags for that browser automatically. You do not need to do anything else.
Opting out is limited to the browser and device where you set it, and to the website where you set it, because we store the choice locally rather than tying it to your account. If you use more than one browser, set it in each, or enable Global Privacy Control, which we honor everywhere. An authorized agent may opt out on your behalf through our privacy request form.
7. Marketing Communications
You can opt out of promotional emails at any time by following the unsubscribe instructions in any promotional message or by contacting us at privacy@invoto.com. Regardless of your marketing preferences, we will continue to send you transactional and administrative communications about your account, transactions, security, and changes to our terms, which you cannot opt out of while you use the Service.
8. Your State Privacy Rights
Depending on where you live, you may have rights over your personal information under state privacy law, including in California, Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws.
Information we collect and process in connection with providing a financial product or service is generally exempt from these laws under the Gramm-Leach-Bliley Act. That exemption is data-level under the California Consumer Privacy Act, not entity-level: information about site visitors, prospects, and business contacts that is not collected under GLBA remains subject to the rights described below.
Information about vendors, payees, and other counterparties, as described in Section 2.6, is also subject to the rights described below. We do not treat it as exempt, because we collect it in connection with providing a service to our customer rather than to the counterparty. If you are a counterparty, you can exercise these rights using the methods in Section 8.4.
8.1 Categories of personal information
In the preceding 12 months, we have collected the following categories of personal information, from the sources described in Section 2, for the business purposes described in Section 3, and disclosed them to the categories of recipients described in Section 4.
Category Collected Disclosed for a business purpose Identifiers (name, email, postal address, phone, IP address, account identifiers) Yes Yes Customer records (Cal. Civ. Code § 1798.80) — contact and financial account information Yes Yes Commercial information (transaction and payment history) Yes Yes Internet or network activity (device, browser, and usage data) Yes Yes Professional or employment information (job title, employer, role on the account) Yes Yes Inferences (eligibility, risk, and fraud signals). Eligibility, risk, and fraud decisioning is performed by our partner bank, not by Invoto No No Sensitive personal information — limited to log-in credentials for the Service. We do not collect Social Security numbers, government-issued identification, or financial account numbers; that information is collected directly by our partner bank as described in Section 2 Yes Yes Audio recordings — voicemail you leave on our privacy request line. We do not record calls or screen-sharing sessions Yes Yes Geolocation — approximate location derived from your IP address. We do not collect precise geolocation Yes Yes Biometric and education information No No We retain each category for the periods described in Section 5.
8.2 Sale, sharing, and sensitive information
We do not sell personal information in exchange for money. We do use advertising cookies and pixels on this Site — Google Ads conversion tracking and the Meta pixel — which may constitute "selling" or "sharing" personal information for cross-context behavioral advertising under the CCPA and comparable state laws. The categories involved are identifiers and internet or network activity, disclosed to advertising and analytics providers.
You can opt out at any time through the Do Not Sell or Share My Personal Information link in the footer of every page, and we honor Global Privacy Control signals as a valid opt-out. See Section 6 for how this works and what it covers.
We do not sell or share the personal information of consumers we know to be under 16. We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit its use.
8.3 Your rights
Subject to the exemptions described above and verification of your identity, you may have the right to:
- know what personal information we collect, use, and disclose, and to access a copy of it in a portable format;
- correct inaccurate personal information;
- delete personal information, subject to legal and regulatory recordkeeping obligations that frequently prevent deletion of financial account records;
- opt out of the sale or sharing of personal information and of targeted advertising;
- limit the use and disclosure of sensitive personal information;
- opt out of profiling that produces legal or similarly significant effects; and
- not be discriminated against for exercising any of these rights.
8.4 How to exercise your rights
You can submit a request in any of three ways:
- through our online request form at invoto.com/privacy-request;
- by calling us toll-free at (844) 660-1323 and selecting the privacy option; or
- by emailing privacy@invoto.com.
We will acknowledge your request and respond within 45 days. If we need more time, we will tell you before that deadline and explain why, and we may extend by a further 45 days where the law allows.
Some of the information you may be asking about — including identity verification records, Social Security numbers, account and routing numbers, and eligibility, risk, and fraud determinations — is collected and held by i3 Bank rather than by Invoto, as described in Section 2. Where your request covers that information, we will route it to i3 Bank and tell you that we have done so. You may also contact i3 Bank directly using the contact details in the privacy notice they provide to you.
We will verify your request using information already in our possession. If we cannot verify your identity, we may deny the request. An authorized agent may submit a request on your behalf with written permission that we can verify, and we may require you to confirm the agent's authority directly.
8.5 Appeals
If we decline your request, you may appeal by replying to our decision or emailing privacy@invoto.com with "Privacy Appeal" in the subject line. We will respond in writing within 45 days with our decision and the reasons for it. If your appeal is denied, you may contact your state attorney general to submit a complaint. An appeal process is required in Colorado, Connecticut, and Virginia, among other states.
8.6 California Shine the Light
California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes by emailing privacy@invoto.com.
9. How We Protect Information
We maintain an information security program with administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, and destruction. These include encryption of information in transit using TLS 1.2 or higher, encryption of information at rest, access controls that limit access to those who need it, and monitoring of our systems. We review our safeguards periodically and as the Service changes.
Your account is also protected by your credentials. You are responsible for keeping them confidential, for enabling the authentication controls we make available, and for notifying us promptly at security@invoto.com if you believe your account has been compromised.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Security Incident Notification
If we determine that your information has been involved in a security incident requiring notification, we will notify you and the applicable regulators as required by law, without unreasonable delay and within the timeframes those laws prescribe. We will also notify our partner bank in accordance with our agreement with them.
11. Where We Process Information
The Service is intended for use in the United States, and we process and store information in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, processed, and stored in the United States, where data protection laws may differ from those in your country.
Our service providers process and store information in the United States.
12. Links to Other Websites and Services
The Site and the Service may link to or interoperate with websites and applications we do not control. We are not responsible for their privacy practices, and this Privacy Policy does not apply to them. We encourage you to read the privacy notices of any third-party site or service before using it.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by sending a notice to the primary email address on your account or by posting a prominent notice on the Site. Material changes take effect 30 days after notice; other changes take effect when posted. Where a change requires your consent or a new opt-out opportunity under applicable law, we will obtain it or provide it before the change takes effect. The date of the most recent revision appears at the end of this policy.
14. Contact Us
Questions about this Privacy Policy or our privacy practices can be sent to privacy@invoto.com. To exercise your privacy rights, use our privacy request form or the same address. You can also write to us or call us:
Invoto Inc.
1905 15th St
#269
Boulder, CO 80302
Telephone: (844) 660-1323
Last Updated: August 20, 2026