BillWare — a trade name of Apoorva Corporation
Effective Date: July 1, 2026 | Last Updated: July 1, 2026
Privacy Policy
Your privacy matters. This Privacy Policy explains what data we collect, how we use it, and your rights as a user of the BillWare platform. BillWare is a financial technology platform; some data collection is required by law. We are transparent about what that means for you.
1. Who We Are
BillWare is a trade name (DBA) of Apoorva Corporation, a Colorado corporation located at 11811 Upham Street, Unit B, Broomfield, Colorado 80020. Apoorva Corporation is the data controller for personal information collected through the BillWare platform. References to “BillWare,” “we,” “us,” or “our” refer to Apoorva Corporation operating under the BillWare trade name.
This Privacy Policy applies to all users of the BillWare platform, including Merchants accessing the merchant portal at merchantdev.getbillware.com and Customers (payers) accessing the customer portal at customer.getbillware.com, as well as visitors to www.getbillware.com.
2. Information We Collect
2.1 Information You Provide Directly
From Merchants:
- Full legal name and business name
- Email address, phone number, and mailing address
- Employer Identification Number (EIN) or Social Security Number (SSN) for sole proprietors
- Date of birth and government-issued identification (for KYC verification)
- Business type, industry classification, and ownership structure
- Bank account and routing numbers for settlement
- Beneficial ownership information (as required by FinCEN)
- Invoice content, customer lists, and transaction data you enter into the platform
From Customers (Payers):
- Name and email address (for account login)
- Payment card details or bank account information (processed and tokenized by our Payment Gateway Partners — we do not store full card numbers)
- Billing address associated with payment method
- Payment history and transaction records
From Website Visitors:
- Contact form submissions, including name, email, and message
- Email address if you contact us at sales@getbillware.com
2.2 Information Collected Automatically
- Device and browser data: IP address, browser type and version, operating system, device identifiers
- Usage data: Pages visited, features accessed, clicks, session duration, referring URLs
- Cookies and tracking technologies: Session cookies, authentication tokens, and analytics cookies (see Section 9)
- Log data: Server logs including timestamps, error reports, and API request records
2.3 Information from Third Parties
- KYC/Identity verification providers: Identity verification results, document scan outcomes, and fraud signals
- Payment Gateway Partners (MerkPay, Fortis): Transaction status, settlement confirmations, chargeback and dispute data, risk scores
- Credit and fraud screening services: Business verification data, risk assessments
3. How We Use Your Information
| Purpose | Legal Basis | Data Used |
|---|---|---|
| Account registration and authentication | Contract performance | Name, email, password credentials |
| Merchant onboarding and KYC verification | Legal obligation (BSA/FinCEN) | Identity documents, EIN/SSN, ownership data |
| Payment processing and settlement | Contract performance | Bank account info, transaction data |
| Invoice creation and delivery | Contract performance | Customer email, invoice content |
| Fraud detection and risk management | Legitimate interest / Legal obligation | Transaction patterns, IP, device data |
| Regulatory compliance (AML, OFAC) | Legal obligation | Identity data, transaction records |
| Customer support and dispute resolution | Contract performance / Legitimate interest | Account data, transaction history |
| Platform improvement and analytics | Legitimate interest | Usage data, session logs (aggregated) |
| Communications and product updates | Consent / Contract performance | Email address |
| Legal claims and audit defense | Legal obligation / Legitimate interest | All relevant account and transaction data |
4. FinTech-Specific Data Obligations
As a financial technology platform facilitating payment processing, BillWare is subject to federal financial regulations that govern how we collect and retain certain data. These obligations supersede standard data minimization practices in specific circumstances:
4.1 Bank Secrecy Act (BSA) and FinCEN
We are required to collect and verify the identity of Merchants, including beneficial owners of legal entities controlling 25% or more of the business. This information is retained for a minimum of five (5) years from the date of collection, as required by the BSA Customer Due Diligence (CDD) Rule.
4.2 Anti-Money Laundering (AML)
We monitor transaction activity for patterns consistent with money laundering or financial fraud. We may file Suspicious Activity Reports (SARs) with FinCEN as required by law. We are legally prohibited from disclosing to you when a SAR has been filed concerning your account.
4.3 OFAC Sanctions Screening
We screen Merchant and transaction data against OFAC’s Specially Designated Nationals (SDN) list and other applicable sanctions lists. Matches may result in immediate account suspension and mandatory reporting.
4.4 ACH / NACHA Compliance
ACH transaction authorization records are retained for a minimum of two (2) years per NACHA Operating Rules. ACH return data and related transaction records are maintained for audit and compliance purposes.
4.5 IRS Reporting
Apoorva Corporation may be required to report payment volumes to the IRS (e.g., Form 1099-K) for Merchants meeting applicable thresholds. Your EIN or SSN may be used for this purpose.
5. How We Share Your Information
We do not sell your personal information. We share data only in the following circumstances:
5.1 Payment Gateway Partners
Transaction and identity data is shared with MerkPay, Fortis, or other designated Payment Gateway Partners to facilitate payment processing, KYC verification, fraud detection, and settlement. These partners operate under their own privacy policies and are independently responsible for their data practices.
5.2 Identity Verification Providers
We share identity documents and personal information with third-party KYC/AML service providers to complete merchant verification. These providers are contractually bound to use your data only for verification purposes.
5.3 Service Providers
We engage service providers who assist with platform hosting, email delivery, customer support, and analytics. These providers access data only as necessary to perform services on our behalf and are bound by data processing agreements.
5.4 Legal and Regulatory Authorities
We may disclose your information to law enforcement, regulators, courts, or government agencies when required by law, subpoena, court order, or regulatory directive — including FinCEN, the IRS, the Consumer Financial Protection Bureau (CFPB), or state financial regulators.
5.5 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all assets of Apoorva Corporation, user data may be transferred to the successor entity. You will be notified of any such transfer and your choices regarding your data.
5.6 With Your Consent
We may share your information in other circumstances with your explicit consent.
6. Data Retention
We retain personal data for as long as necessary to fulfill the purposes for which it was collected, subject to the following minimum retention requirements:
- KYC/identity verification records: 5 years from collection (BSA requirement)
- Transaction records: 5 years from transaction date
- ACH authorization records: 2 years from authorization date (NACHA requirement)
- Active account data: Duration of account plus 3 years post-closure
- Fraud and AML records: As required by applicable law, typically 5–7 years
- General account and usage data: 3 years from last activity or account closure
After applicable retention periods expire, data is securely deleted or anonymized.
7. Data Security
Apoorva Corporation employs industry-standard security measures to protect your personal information, including:
- AES-256 encryption for data at rest
- TLS/HTTPS encryption for all data in transit
- Tokenization of payment card data (no full card numbers stored on BillWare servers)
- Access controls limiting employee access to personal data on a need-to-know basis
- Multi-factor authentication for platform access
- Regular security assessments and vulnerability monitoring
No system is completely secure. In the event of a data breach affecting your personal information, we will notify you as required by applicable law, including the Colorado Privacy Act (CPA) breach notification requirements.
8. Your Rights and Choices
Depending on your location and applicable law, you may have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal information we hold about you.
- Right to Correction: Request correction of inaccurate or incomplete information.
- Right to Deletion: Request deletion of your personal information, subject to our legal retention obligations (note: regulatory retention requirements may prevent full deletion).
- Right to Portability: Request a machine-readable export of your account data.
- Right to Opt Out of Marketing: Unsubscribe from marketing communications at any time using the link in any email we send, or by contacting us directly.
- Right to Restrict Processing: Request restriction of processing in certain circumstances.
To exercise these rights, contact us at privacy@getbillware.com. We will respond within 45 days as required under the Colorado Privacy Act. Note that certain rights may be limited where data processing is required by law (e.g., BSA/AML retention obligations).
9. Cookies and Tracking Technologies
BillWare uses the following types of cookies and similar technologies:
- Essential cookies: Required for platform functionality, including session authentication and security tokens. These cannot be disabled.
- Analytics cookies: Used to understand how users interact with the platform (e.g., pages visited, features used). These are collected in aggregated, non-identifiable form where possible.
- Preference cookies: Store your settings and preferences to improve your experience.
You can control non-essential cookies through your browser settings. Disabling cookies may affect the functionality of certain platform features.
10. Colorado Privacy Act (CPA) Disclosures
BillWare uses the following types of cookies and similar technologies:
- Essential cookies: Required for platform functionality, including session authentication and security tokens. These cannot be disabled.
- Analytics cookies: Used to understand how users interact with the platform (e.g., pages visited, features used). These are collected in aggregated, non-identifiable form where possible.
- Preference cookies: Store your settings and preferences to improve your experience.
You can control non-essential cookies through your browser settings. Disabling cookies may affect the functionality of certain platform features.
11. California Residents (CCPA/CPRA)
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out of the sale or sharing of personal information. BillWare does not sell or share personal information for cross-context behavioral advertising. To submit a California privacy request, contact us at privacy@getbillware.com.
12. Children’s Privacy
BillWare is not directed to children under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe we may have information about a child, please contact us at privacy@getbillware.com.
13. Third-Party Links
The BillWare platform may contain links to third-party websites, including Payment Gateway Partner portals. We are not responsible for the privacy practices of those sites. We encourage you to review the privacy policies of any third-party sites you visit.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. We will notify Merchants of material changes via email or in-platform notification at least 15 days before the changes take effect. The “Last Updated” date at the top of this policy indicates when it was most recently revised. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.
15. Contact Us
For privacy-related questions, requests, or concerns, please contact:
Apoorva Corporation (operating as BillWare)
Attn: Privacy Officer
11811 Upham Street, Unit B
Broomfield, Colorado 80020
Email: privacy@getbillware.com
Website: www.getbillware.com
