Last Updated: 7 December 2020

Privacy Policy

This Privacy Policy for Reimbi LLC and our affiliates and subsidiaries (collectively, “Reimbi,” “us,” or “we”) is governed by and part of our Terms of Service. We at Reimbi know you care about how your information is used and shared, and we take your privacy seriously. Please read this Privacy Policy carefully to understand our privacy practices. Any capitalized terms not defined in this Privacy Policy have the meanings provided in the Terms of Service. Any additional notices we may provide you about our privacy practices will be considered to form part of this Privacy Policy.

Scope

This Privacy Policy describes how we treat information collected through reimbi.com, other websites we own or operate (collectively, the “Site”), our web-based application for processing business expense reimbursements found at app.reimbi.com (the “App”), and other services, solutions and products we offer (collectively, with the Site and Reimbi, the “Services”). Your use of our Services is subject to this Privacy Policy and our Terms of Service, including its applicable limitations on damages and the provisions regarding resolution of disputes.

Consent

By using or accessing the Services in any manner, you acknowledge that you accept the practices and policies outlined in this Privacy Policy, and you hereby consent that we will collect, use, and share your information in the following ways. If you do not agree with this Privacy Policy, do not use our Services.

Personal Information

As used in this Privacy Policy, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, such as:

  • Identifiers (e.g., real name, alias, address, username, IP address, email address)
  • Protected Information (e.g. race, citizenship, marital status, sex)
  • Biometric information (e.g., DNA, face/voice prints, health data) and audio, electronic, visual, thermal, olfactory, or similar information;
  • Commercial information (e.g., products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies);
  • Employment-related information (e.g. current or past employment);
  • Non-public educational information, including information protected under the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g, 34 C.F.R. Part 99);
  • Internet activity (e.g., interactions with a website, content, or advertisement);
  • Inferences drawn from Personal Information to create a profile about preferences, characteristics, trends, predispositions, behavior, attitudes, and aptitudes; and
  • Sensitive Personal Information (e.g. social security or government ID number; precise geolocation; racial or ethnic origin; biometrics; health information; union membership; contents of messages when we are not the recipient).

Personal Information does not include:

  • (i) publicly available information
  • (ii) aggregate information, meaning data about a group or category of services or users from which individual identities and other Personal Information has been removed; or
  • (iii) deidentified information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer.

Children's Privacy

Reimbi is designed for users age 16 and older. We do not knowingly collect Personal Information from children under 16. If we discover that a child under 16 has provided us with Personal Information, we will delete such information from our systems. If you believe we might have any information collected online from a child under 16, or if you become aware of any unauthorized submission of information to us, please contact us at privacy-tos@reimbi.com.

For details regarding choices we offer in connection with your information and our information practices, please see “Your Choices” below. If you have any questions about this Privacy Policy, please contact us at privacy-tos@reimbi.com.

Information We Collect

The types of Personal Information we collect about you and the manner of collection depends on how you interact with us, for example as a customer subscribed to our Services (“Customer”), an individual using the Services to request reimbursement from a Customer (a “Requester”), or a website visitor. We only collect your Personal Information (i) with your consent, (ii) if we have a legitimate interest in doing so, or (iii) as authorized or required by law. We only collect, use, retain and share Personal Information as reasonably necessary and proportionate to achieve our purposes, or for other purposes that we disclose to you and are compatible with the context of how we collected the Personal Information.

Categories

During the preceding 12 months, we have collected these categories of Personal Information:

  • Identifiers
  • Employment-related information
  • Internet or other similar activity

Sources

We collect Personal Information from these sources:

  • Directly from you as a Requester, with your consent: Requesters use the App to request reimbursements from our Customers for expenses incurred related to events like job interviews, sales or marketing efforts, or the Requester’s employment with the Customer. If you are a Requester, we will collect the information you provide to us directly through the App. In order to process your reimbursement, we will collect your name, email address, information about the claimed expenses (e.g. interview date), and choice of reimbursement method. We only use Requester Personal Information to process reimbursements and to improve the Services. By submitting Personal Information through the App, Requesters consent to our collection and use of such information.
  • Directly from you as a Customer, with your consent: When you sign up as a Customer, we will collect information about the Customer company, employment information for the Customer point of contact like name and email address, and information necessary to provide our reimbursement Services. We collect this information with your consent, and we use it to provide you with our Services and to communicate with you.
  • Directly from you when you communicate with us, with your consent: If you contact us by email, online form or other means to request information or support, we will collect your name and email address in order to respond to your inquiry. When you request a demo or trial, we collect your name, company name, phone number, and email address. We collect this information with your consent, and we use it for the purposes stated at the time of collection.
  • Indirectly from your use of the Services, with a legitimate interest: We automatically collect details about your use of the Services, such as your (i) session active time and related data; (ii) device data (e.g., IP address, operating system, browser type, device ID, mobile network information); and (iii) usage details (e.g., the content, features, or resources you access and use; specific functions completed). Like most web-based services, we use cookies and other technologies to track how you use the Services. Please read about our use of Cookies for more information. We collect this information to achieve our legitimate interest of providing and improving our Services. We may also use this information to deliver targeted marketing.

Reimbi will not collect additional categories of Personal Information or use your Personal Information for purposes that are incompatible with the purpose stated at the time of collection without first notifying you, either by updating this Privacy Policy or through other means.

Payment Information

All reimbursements, payments, and charges made through the Services are processed by a PCI-compliant payment processor or directly through your banking institution. If you choose to submit payments or receive reimbursements via ACH through your banking institution, we will collect and store your account information in a secure manner. If you have specific questions about ACH transaction security, please contact your banking institution.

Retention of Personal Information

Reimbi retains all categories of Personal Information we collect for as long as your account is active or as necessary to provide you with the Services you request. We regularly review and deidentify unnecessary Personal Information and other data and we periodically deidentify unused accounts.

Other Uses

  • Provide, maintain and improve our Services.
  • Send you support and administrative messages
  • Monitor your compliance with any of your agreements with us.
  • Detect, investigate and prevent fraudulent transactions and other illegal activities and protect the rights and property of Company and others.
  • Protect your privacy and enforce this Privacy Policy.
  • If we believe it is necessary, to identify, contact or bring legal action against persons or entities who may be causing injury to you, to us, or to others.
  • Comply with a law, regulation, legal process or court order.
  • Fulfill any other purpose to which you consent.

Disclosing Personal Information

Categories

We will only disclose Personal Information as described in this section, with your permission, or as required by law. In the preceding 12 months, we have disclosed the following categories of Personal Information for a business purpose:

  • Identifiers
  • Employment-related information
  • Internet or other similar activity

Recipients

We may disclose Personal Information to the following recipients:

  • Service Providers: Reimbi uses a variety of service providers such as data hosting companies, SMS message delivery services, analytics services, and payment processors. The type of information that we share with a service provider will depend on the service that they provide to us. Our service providers are subject to contractual agreements that protect your Personal Information, and we require all service providers to maintain confidentiality standards that are commercially reasonable to ensure the security of your Personal Information.
  • Customers: As a service provider to our Customers, Reimbi will disclose applicable data sets to our Customers and their service providers, such as the Customer’s integrated applicant tracking system, and identified third parties per the Customer’s instructions and in accordance with applicable law.
  • Government Agencies: We reserve the right to disclose Personal Information to law enforcement and other governmental agencies, at our sole discretion in connection with an investigation of any matter that is illegal or that could expose Reimbi or our subsidiaries to liability.
  • Cookie Information Recipients: In some cases, we may allow specific cooperating entities to use cookies or similar technologies to collect non-personal data from your browser or device for measurement purposes. Receipt and use of such information is subject to each cookie information recipient’s privacy policy.
  • Affiliates and Third Parties: We may disclose the Personal Information we collect about you to our affiliates like a parent company or subsidiaries. For example, we share Personal Information for customer support purposes, marketing, or technical operations. Under specific circumstances, we may disclose Personal Information to certain third parties as permitted by applicable law. For example, if we go through a business transition (e.g., merger, acquisition, or sale of a portion of our assets), as needed to comply with a legal requirement or a court order, when we believe it is appropriate in order to take action regarding illegal activities or prevent fraud or harm to any person; to exercise or defend our legal claims, or for any other reason with your consent.

Aggregated and Deidentified Information

We reserve the right to disclose aggregated, anonymized, or deidentified information about any individuals with our trainer, training managers, speakers, rights holders and other partners, as well as with nonaffiliated entities for marketing, advertising, research or other purposes, without restriction. For example, we may share reports showing trends about the general use of our Services without identifying any particular individual.

Limited Sensitive Personal Information

Reimbi does not knowingly collect any Sensitive Personal Information, and in no case will Reimbi use or disclose any Sensitive Personal Information for the purpose of inferring characteristics about you. If this ever changes in the future, we will update this Privacy Policy and provide you with methods to limit use and disclosure of Sensitive Personal Information.

No Sale or Sharing With Third Parties

Reimbi does not sell your Personal Information or share your Personal Information with third parties for cross-contextual advertising purposes. If this ever changes in the future, we will update this posting and provide you with methods to opt-out of such sale and sharing.

Your Privacy Rights

Reimbi provides you with a variety methods and options to directly control how we collect and use your Personal Information, including but not limited to:

Account and Device Settings

You can access, correct or update certain Personal Information by logging into Reimbi and changing your account settings. You can also control the data we collect automatically by adjusting your device settings. To delete your account, contact us at privacy-tos@reimbi.com. Note that we may retain certain information as required by law or for legitimate business purposes. We may also retain cached or archived copies of information about you up to two months.

Texting Consent.

If you provide us with your wireless phone number, you consent to Reimbi sending you text messages for informational or authentication purposes. The number of texts that we send to you will be based on your circumstances and requests. You can unsubscribe from text messages by replying STOP or UNSUBSCRIBE to any of these text messages. Messaging and data charges may apply to any text message you receive or send. Please contact your wireless carrier if you have questions about messaging or data charges.

Email Communications.

We may send you promotional emails about Reimbi or alert you of service changes via our product support system. If you do not wish to receive emails from us, you may change your preferences via the links provided in the emails or by sending a request to privacy-tos@reimbi.com to be removed from our email list. Note that if you opt-out of marketing communications, we may still send you non-promotional communications, such as those about your account or our ongoing business relations.

Do Not Track.

Do Not Track signals are signals sent through a browser informing us that you do not want to be tracked. Currently, our systems do not recognize browser “do-not-track” requests. If this changes in the future, we will update this Privacy Policy.


Depending on where you reside, you may have additional privacy rights or be entitled to additional controls over your Personal Information. Please see our supplemental notices specific to residents of California, the European Union, and Canada.

California Privacy Rights

This section provides residents of the State of California (“California Consumers”) with the disclosures and notices required under the California Consumer Privacy Act of 2018 (“CCPA”). The following paragraphs apply solely to California Consumers and describe the specific rights afforded under the CCPA.

Employee Data Exception

In many cases, the Personal Information we collect about you is in a business-to-business context when you are acting as an employee to a Customer or potential in the performance of your job duties. Please note that Personal Information collected and used in this context is not protected Personal Information under the CCPA. Without limiting the foregoing, California Consumers may exercise the following rights over their Personal Information, subject to any exceptions and limitations that may apply:

  • Right to Disclosure. You have the right to request that we disclose information to you about our collection and use of your Personal Information, such as: (i) the categories of Personal Information we have collected about you; (ii) the categories of sources for the Personal Information we have collected about you; (iii) our business or commercial purpose for collecting, selling or sharing your Personal Information; (iv) the categories of third parties with whom we disclose your Personal Information; and (v) a list of specific pieces of Personal Information we have collected about you. You also have the right to request that we disclose the categories of your Personal Information we have sold or shared and the categories of third parties to whom that Personal information was sold or shared, as well as the categories of Personal information disclosed for a business purpose and the categories of recipients of that information. Reimbi is only required to respond to two disclosure requests from you within a 12-month period.
  • Right to Access. You have the right to request that we provide you with access to specific pieces of Personal Information we have collected about you over the past 12 months (also called a data portability request). If you submit a right to access request, we will provide you with copies of the requested Personal Information in a portable and readily usable format. Please note that Reimbi may be prohibited by law from disclosing copies of certain Personal Information when the disclosure would create a substantial, articulable, and unreasonable risk to the security of the information, our systems, or your account. We are only required by law to respond to two access requests from you within a 12-month period.
  • Right to Correct. If you discover that we maintain inaccurate Personal Information about you, or if your Personal Information changes, please inform us and we will update our records to reflect the correct information.
  • Right to Deletion. You have the right to request that we delete Personal Information that we collected from you and retained, with certain exceptions. Reimbi may permanently delete, deidentify, or aggregate the Personal Information in response to a request for deletion. If you submit a right to deletion request, we will confirm the Personal Information to be deleted prior to its deletion, and we will notify you when your request is complete.
  • No Selling or Sharing Personal Information.does not sell your Personal Information or share your Personal Information with third parties for cross-contextual behavioral advertising purposes. If this changes in the future, we will update this Privacy Policy and provide you with a method to opt-out of such sale and sharing.
  • Limited Use and Disclosure of Sensitive Personal Information.Reimbi does not use or disclose your Sensitive Personal Information for the purpose of inferring characteristics about you. If this ever changes in the future, we will update this Privacy Policy and provide you with methods to limit use and disclosure of Sensitive Personal Information.
  • Right to Nondiscrimination.We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by law, we will not: (i) deny you goods or services; (ii) charge you different prices or rates for goods or services; (iii) provide you a different level or quality of goods or services; or (iv) suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services, because you exercised a right under the CCPA.
  • Right to Disclosure of Marketing Information.Under California’s Shine the Light Act (Ca. Civ. Code § 1798.83-1798.84), California Consumers are entitled to request certain disclosures about Personal Information sharing with affiliates and/or third parties for marketing purposes. Please contact us if you wish to obtain these disclosures.

California Consumers may exercise the following rights over their Personal Information, subject to our receipt of a verifiable Consumer Privacy Request, as well as any exceptions and limitations that may apply. Note that if we process your Personal Information in our capacity as a service provider, then we cannot fulfill your request directly. In that case, we will relay your request to the appropriate Customer for further processing and fulfillment.

European Union Privacy Rights

We adopted this section to comply with the European Union’s General Data Protection Regulations (“GDPR”). This section applies solely to residents of the European Union (“EU Residents”). Reimbi provides the Services to EU Residents in our capacity as a data processor to our Customers as data controllers. If you are an EU Resident, you have the following rights regarding the Personal Information we hold about you:

  • Right to know how we process your Personal Information. We have set the required notices in this Privacy Policy. We may provide you with additional notices about other ways we process your Personal Data, such as by sending you a notice via email or by other means of communication.
  • Right to access your Personal Information. You may exercise your right to access by logging into your account to view or export your Personal Information. Alternatively, if you submit a Consumer Privacy Request we will provide you with a copy of your Personal Information, along with details about the types of Personal Information we process, why we process it, and any third parties we work with to collect Personal Information on our behalf. We may have one or more legally valid reasons to refuse your request in whole or in part, for example in order to protect the rights of other individuals.
  • Right to restrict processing of your Personal Information. You can request that we restrict the processing of your Personal Information if: (i) the data is inaccurate; (ii) the processing is unlawful; (iii) we no longer need the Personal Information; or (iv) you exercise your right to object.
  • Right to rectify your Personal Information If you become aware that the Personal Information that we hold about you is incorrect, or if your situation changes (e.g., you change address), you may edit the Personal Information in your profile or saved to your account, or you can inform us and we will update our records for accuracy.
  • Right to data portability. In some circumstances, we are required to provide your Personal Information to another organization at your request and in a structured, commonly used machine-readable format. Please submit a Consumer Privacy Request if you require assistance.
  • Right to erasure (a.k.a. the “right to be forgotten”). You may exercise your right to deletion by logging into the Services and deleting your editable Personal Information. Alternatively, if you submit a Consumer Privacy Request to delete your Personal Information, we will confirm the Personal Information to be deleted prior to its deletion, and we will notify you when your request is complete. This right is not absolute, and we may be entitled to retain and process your Personal Information despite your request. If you make this request, we balance certain legal, contractual, and business interests against your right to request the deletion of your Personal Information.
  • Right to object to certain processing of your Personal Information. Upon your request, and in certain circumstances and where we are required to do so by law, we will limit our processing of your Personal Information as you request.
  • Right to not be subject to Automated Decision-Making. Reimbi does not use Automated Decision-Making (“ADM”). If we engage in this activity in the future, you will have the right to object to a decision we make wholly by a computer or algorithm without human input and to receive information about this type of processing.

EU Residents may exercise their privacy rights by submitting a verifiable Consumer Privacy Request (sometimes called a data subject access request). Note that if we process your Personal Information in our capacity as a data processor, then we cannot fulfill your request directly. In that case, we will relay your request to the appropriate Customer for further processing and fulfillment.

Canadian Privacy Rights

We adopted this section to provide supplemental information in compliance with Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”). This section applies solely to residents of Canada where PIPEDA applies (“Canadian Consumers”) and describes PIPEDA rights and explain how Canadian Consumers can exercise those rights.

  • Right to know why we collect, use and distribute the Personal Information we process. We have set the required notices in this Privacy Policy. We may provide you with additional notices about other ways we process your Personal Data, such as by sending you a notice via email or by other means of communication.
  • Right to expect us to collect, use, or disclose Personal Information responsibly and not for any other purpose other than which you consented. We set your expectations in this Privacy Policy and collect express or implied consent at various stages of collection or processing. If we collect or use your Personal Information based on your consent, we will also notify you of any changes and will request your further consent as needed. You may withdraw your consent at any time with reasonable notice by contacting us at privacy-tos@reimbi.com.
  • Right to accuracy of your Personal Information. We take steps to reasonably ensure that your Personal Information we are using is accurate. In most cases, we rely on you to ensure that the Personal Information in your account is current, complete, and accurate. We provide methods for you to correct, update, and delete inaccurate Personal Information in your account, and we will provide you with reasonable assistance to ensure that your Personal Information is accurate in our systems and with our service providers.
  • Right to access your Personal Information. You may access your Personal Information my logging into your account. Alternatively, upon written request and identity authentication, we will provide you with your Personal Information under our control, information about the ways that information is being used, and a description of the entities to whom that information has been disclosed. If limited by law or potential infringement on another’s privacy rights, we may not be able to provide access to some or all of the Personal Information you request. If we must refuse an access request, we will notify you in writing, document the reasons for refusal, and outline further steps available to you.

Cookies

Cookies are small data files stored on your device that help us track and analyze data to improve our Services and your experience. Cookies serve a variety of purposes, for example analyzing use of a website or platform, navigating between pages efficiently, remembering your preferences, and generally improving your browsing experience. Cookies are generally used for functionality, security, analytics, or advertising.

How We Use Cookies.

Reimbi uses cookies to collect data about use of reimbi.com and app.reimbi.com. We use the information collected by cookies to analyze trends, track users’ movements around Reimbi, and administer the application. We do not link automatically collected data by cookies and log files to Personal Information. This data typically does not include Personal Information but may be maintained or associated with your Personal Information. Third parties that set cookies on Reimbi may collect information about you when you use Reimbi. The information they collect may be associated with your Personal Information, including your internet or similar activities across different online platforms. We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly.

Cookies We Use.

The table below provides details about the cookies we use. Note that the names of cookies and their use can change from time to time as necessary to ensure the Services function as intended and, for third party cookies, as determined by the third-party cookie host.


CategoryCookiePurpose
Strictly Necessary cookies are necessary for the platform to work as intended. sessionid (Reimbi) Used on app.reimbi.com to store user’s session ID. Expires after two weeks.
Functionality cookies monitor and enhance your user experience. These cookies might be used to identify errors and other issues users may face when using the platform, or to provide insight into platform performance. cookie-consent (Reimbi) Stores user’s cookie preferences for reimbi.com. Expires after one year.
Analytics cookies help us understand how users engage with us by collecting and reporting usage statistics without personally identifying individual users. _ga (Google Analytics) Calculates visitor, session, campaign data, and tracks reimbi.com usage for analytics reports. Stores information anonymously and assigns a randomly generated number to identify unique visitors. Session cookie expires immediately.
_gid (Google Analytics) Tracks and stores reimbi.com usage data in an anonymous form. Session cookie expires immediately.
_gat_gtag_[property_id] (Google Analytics) Used to analyze reimbi.com visitor browsing, flow, source and other data. Session cookie expires immediately.

Controlling Cookies

You can adjust your browser or device settings to refuse all or some cookies or to alert you when cookies are being sent. You can also install third-party plugins to control cookie behavior. If you disable or refuse cookies or block the use of other tracking technologies, some parts of Reimbi may be inaccessible or not function properly. If you get a new device, install a new browser, or erase or otherwise alter your device’s cookie file or privacy settings, your privacy preferences may not be saved. You may see a cookie consent notice on the Services that lists the categories of cookies we use and provides the option to accept or reject different types of cookies. When you consent to cookies on our cookie consent banner, we may set cookies in correspondence with your selections. You may adjust your cookie selections at any time, and we will display the cookie consent notice to you periodically.

Data Security

Reimbi implements reasonable and appropriate security procedures and practices to help protect your Personal Information from unauthorized or illegal access, destruction, use, modification, or disclosure. We ensure that Reimbi employees, contractors and agents responsible for handling user inquiries are informed of applicable privacy law requirements and we restrict access to those who need that information in order to process it. The Services are built with a range of security features that continuously protect your Personal Information and our systems. Please review our Security Statement for details about Reimbi’s security features. Please note, however, that no transmission of data over the Internet is 100% secure, and we cannot guarantee that unauthorized third parties will not defeat our security measures or use your Personal Information for improper purposes.

Data Transfers.

Reimbi is owned and operated in the United States and uses service providers in the United States and other countries. If you use our Services, your Personal Information may be transferred to the United States or other locations outside of your jurisdiction where privacy laws may not be as protective as those in your jurisdiction. Reimbi has certified compliance with the EU-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce for the collection, use, and retention of EU Resident Personal Information. On July 16, 2020, the Court of Justice of the European Union invalidated the EU-U.S. Privacy Shield and instructed the EU Commission to develop and implement a new data transfer framework. Reimbi remains committed to subjecting all EU Resident Personal Information to the EU-U.S. Privacy Shield Framework's applicable principles until a replacement framework is established. Until such time, we will rely on Standard Contractual Clauses for the transfer of EU Resident Personal Information or another appropriate legal basis for data transfers, where required. By allowing us to collect Personal Information about you, you consent to the transfer and processing of your Personal Information as described in this paragraph.

Your Account.

If you have an account on the App or other Services, you will have a username and password. We encourage you to take steps to protect against unauthorized access to your password and your devices by, among other things, choosing a robust password that nobody else knows or can easily guess, and keeping your password private, and signing off after using a shared computer or other device. We are not responsible for any lost, stolen, or compromised passwords, or any unauthorized activity on your account.

Third Party Websites

The Services may contain links to websites owned or operated by third parties. We have no ability to control, and we are not responsible for, the privacy and data collection, use, and disclosure practices of third-party websites. We encourage you to read the privacy statements of each website that collects your Personal Information.

Changes to this Privacy Policy

We may periodically update this Privacy Policy. If we make any material changes, we will notify you by updating this posting or by posting notice in the Services. The date that this Privacy Policy was last revised is identified at the top of the page. Your continued use of the Services after the effective date will be subject to the new Privacy Policy. You are responsible for periodically checking this Privacy Policy for changes.

Contact Reimbi

If you have questions about our privacy practices or would like to make a complaint, please contact us at privacy-tos@reimbi.com or by mail at Reimbi LLC, Attn: Legal, 5511 North Albina Ave, Suite 5, Portland, OR 97217.

We use cookies to ensure your consistent experience on this website.

Privacy policy