BillWare — a trade name of Apoorva Corporation
Effective Date: July 1, 2026  |  Last Updated: July 1, 2026

Your privacy matters. This Privacy Policy explains what data we collect, how we use it, and your rights as a user of the BillWare platform. BillWare is a financial technology platform; some data collection is required by law. We are transparent about what that means for you.

BillWare is a trade name (DBA) of Apoorva Corporation, a Colorado corporation located at 11811 Upham Street, Unit B, Broomfield, Colorado 80020. Apoorva Corporation is the data controller for personal information collected through the BillWare platform. References to “BillWare,” “we,” “us,” or “our” refer to Apoorva Corporation operating under the BillWare trade name.

This Privacy Policy applies to all users of the BillWare platform, including Merchants accessing the merchant portal at merchantdev.getbillware.com and Customers (payers) accessing the customer portal at customer.getbillware.com, as well as visitors to www.getbillware.com.

2.1 Information You Provide Directly

From Merchants:

  • Full legal name and business name
  • Email address, phone number, and mailing address
  • Employer Identification Number (EIN) or Social Security Number (SSN) for sole proprietors
  • Date of birth and government-issued identification (for KYC verification)
  • Business type, industry classification, and ownership structure
  • Bank account and routing numbers for settlement
  • Beneficial ownership information (as required by FinCEN)
  • Invoice content, customer lists, and transaction data you enter into the platform

From Customers (Payers):

  • Name and email address (for account login)
  • Payment card details or bank account information (processed and tokenized by our Payment Gateway Partners — we do not store full card numbers)
  • Billing address associated with payment method
  • Payment history and transaction records

From Website Visitors:

  • Contact form submissions, including name, email, and message
  • Email address if you contact us at sales@getbillware.com

2.2 Information Collected Automatically

  • Device and browser data: IP address, browser type and version, operating system, device identifiers
  • Usage data: Pages visited, features accessed, clicks, session duration, referring URLs
  • Cookies and tracking technologies: Session cookies, authentication tokens, and analytics cookies (see Section 9)
  • Log data: Server logs including timestamps, error reports, and API request records

2.3 Information from Third Parties

  • KYC/Identity verification providers: Identity verification results, document scan outcomes, and fraud signals
  • Payment Gateway Partners (MerkPay, Fortis): Transaction status, settlement confirmations, chargeback and dispute data, risk scores
  • Credit and fraud screening services: Business verification data, risk assessments
Purpose Legal Basis Data Used
Account registration and authentication Contract performance Name, email, password credentials
Merchant onboarding and KYC verification Legal obligation (BSA/FinCEN) Identity documents, EIN/SSN, ownership data
Payment processing and settlement Contract performance Bank account info, transaction data
Invoice creation and delivery Contract performance Customer email, invoice content
Fraud detection and risk management Legitimate interest / Legal obligation Transaction patterns, IP, device data
Regulatory compliance (AML, OFAC) Legal obligation Identity data, transaction records
Customer support and dispute resolution Contract performance / Legitimate interest Account data, transaction history
Platform improvement and analytics Legitimate interest Usage data, session logs (aggregated)
Communications and product updates Consent / Contract performance Email address
Legal claims and audit defense Legal obligation / Legitimate interest All relevant account and transaction data

As a financial technology platform facilitating payment processing, BillWare is subject to federal financial regulations that govern how we collect and retain certain data. These obligations supersede standard data minimization practices in specific circumstances:

4.1 Bank Secrecy Act (BSA) and FinCEN

We are required to collect and verify the identity of Merchants, including beneficial owners of legal entities controlling 25% or more of the business. This information is retained for a minimum of five (5) years from the date of collection, as required by the BSA Customer Due Diligence (CDD) Rule.

4.2 Anti-Money Laundering (AML)

We monitor transaction activity for patterns consistent with money laundering or financial fraud. We may file Suspicious Activity Reports (SARs) with FinCEN as required by law. We are legally prohibited from disclosing to you when a SAR has been filed concerning your account.

4.3 OFAC Sanctions Screening

We screen Merchant and transaction data against OFAC’s Specially Designated Nationals (SDN) list and other applicable sanctions lists. Matches may result in immediate account suspension and mandatory reporting.

4.4 ACH / NACHA Compliance

ACH transaction authorization records are retained for a minimum of two (2) years per NACHA Operating Rules. ACH return data and related transaction records are maintained for audit and compliance purposes.

4.5 IRS Reporting

Apoorva Corporation may be required to report payment volumes to the IRS (e.g., Form 1099-K) for Merchants meeting applicable thresholds. Your EIN or SSN may be used for this purpose.

We do not sell your personal information. We share data only in the following circumstances:

5.1 Payment Gateway Partners

Transaction and identity data is shared with MerkPay, Fortis, or other designated Payment Gateway Partners to facilitate payment processing, KYC verification, fraud detection, and settlement. These partners operate under their own privacy policies and are independently responsible for their data practices.

5.2 Identity Verification Providers

We share identity documents and personal information with third-party KYC/AML service providers to complete merchant verification. These providers are contractually bound to use your data only for verification purposes.

5.3 Service Providers

We engage service providers who assist with platform hosting, email delivery, customer support, and analytics. These providers access data only as necessary to perform services on our behalf and are bound by data processing agreements.

5.4 Legal and Regulatory Authorities

We may disclose your information to law enforcement, regulators, courts, or government agencies when required by law, subpoena, court order, or regulatory directive — including FinCEN, the IRS, the Consumer Financial Protection Bureau (CFPB), or state financial regulators.

5.5 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all assets of Apoorva Corporation, user data may be transferred to the successor entity. You will be notified of any such transfer and your choices regarding your data.

5.6 With Your Consent

We may share your information in other circumstances with your explicit consent.

We retain personal data for as long as necessary to fulfill the purposes for which it was collected, subject to the following minimum retention requirements:

  • KYC/identity verification records: 5 years from collection (BSA requirement)
  • Transaction records: 5 years from transaction date
  • ACH authorization records: 2 years from authorization date (NACHA requirement)
  • Active account data: Duration of account plus 3 years post-closure
  • Fraud and AML records: As required by applicable law, typically 5–7 years
  • General account and usage data: 3 years from last activity or account closure

After applicable retention periods expire, data is securely deleted or anonymized.

Apoorva Corporation employs industry-standard security measures to protect your personal information, including:

  • AES-256 encryption for data at rest
  • TLS/HTTPS encryption for all data in transit
  • Tokenization of payment card data (no full card numbers stored on BillWare servers)
  • Access controls limiting employee access to personal data on a need-to-know basis
  • Multi-factor authentication for platform access
  • Regular security assessments and vulnerability monitoring

No system is completely secure. In the event of a data breach affecting your personal information, we will notify you as required by applicable law, including the Colorado Privacy Act (CPA) breach notification requirements.

Depending on your location and applicable law, you may have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal information we hold about you.
  • Right to Correction: Request correction of inaccurate or incomplete information.
  • Right to Deletion: Request deletion of your personal information, subject to our legal retention obligations (note: regulatory retention requirements may prevent full deletion).
  • Right to Portability: Request a machine-readable export of your account data.
  • Right to Opt Out of Marketing: Unsubscribe from marketing communications at any time using the link in any email we send, or by contacting us directly.
  • Right to Restrict Processing: Request restriction of processing in certain circumstances.

To exercise these rights, contact us at privacy@getbillware.com. We will respond within 45 days as required under the Colorado Privacy Act. Note that certain rights may be limited where data processing is required by law (e.g., BSA/AML retention obligations).

BillWare uses the following types of cookies and similar technologies:

  • Essential cookies: Required for platform functionality, including session authentication and security tokens. These cannot be disabled.
  • Analytics cookies: Used to understand how users interact with the platform (e.g., pages visited, features used). These are collected in aggregated, non-identifiable form where possible.
  • Preference cookies: Store your settings and preferences to improve your experience.

You can control non-essential cookies through your browser settings. Disabling cookies may affect the functionality of certain platform features.

BillWare uses the following types of cookies and similar technologies:

  • Essential cookies: Required for platform functionality, including session authentication and security tokens. These cannot be disabled.
  • Analytics cookies: Used to understand how users interact with the platform (e.g., pages visited, features used). These are collected in aggregated, non-identifiable form where possible.
  • Preference cookies: Store your settings and preferences to improve your experience.

You can control non-essential cookies through your browser settings. Disabling cookies may affect the functionality of certain platform features.

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out of the sale or sharing of personal information. BillWare does not sell or share personal information for cross-context behavioral advertising. To submit a California privacy request, contact us at privacy@getbillware.com.

BillWare is not directed to children under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe we may have information about a child, please contact us at privacy@getbillware.com.

The BillWare platform may contain links to third-party websites, including Payment Gateway Partner portals. We are not responsible for the privacy practices of those sites. We encourage you to review the privacy policies of any third-party sites you visit.

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. We will notify Merchants of material changes via email or in-platform notification at least 15 days before the changes take effect. The “Last Updated” date at the top of this policy indicates when it was most recently revised. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.

For privacy-related questions, requests, or concerns, please contact:

Apoorva Corporation (operating as BillWare)
Attn: Privacy Officer
11811 Upham Street, Unit B
Broomfield, Colorado 80020
Email: privacy@getbillware.com
Website: www.getbillware.com