Privacy Policy

Last Updated: April 22, 2025

CompareABill.ai Inc. (“Company”, “we”, “us”) has created this Privacy Policy (“Privacy Policy”) to set out how we collect, use, and disclose information about identifiable individuals and information which can be used to identify an individual (“Personal Information”) through our Website (defined below) and in the course of providing our software and services (the “Services”).

Privacy is of great importance to us. We do not actively collect Personal Information for the purpose of selling or marketing that Personal Information to third parties. Personal Information may be collected about users and visitors to the Website, as well as our customers and their end users who interact with our Services. By visiting our website located at https://compareabill.ai/, including subpages, (collectively, the “Website”), or using the Services in any manner, you acknowledge that you accept the practices and policies outlined in this Privacy Policy and you hereby consent to the collection, use and disclosure of your Personal Information in accordance with this Privacy Policy.

1. OVERVIEW

1.1 A Note About Children. The Services are intended for business use and are not intended for minors. We do not intentionally gather Personal Information (defined in Collection of Information below) from persons who are under the age of 13. If a child under 13 submits Personal Information to Company and we learn that the Personal Information is the Personal Information of a child under 13, we will attempt to delete the Personal Information as soon as possible. If you believe that we might have any Personal Information from a child under 13, please contact us at connect@compareabill.ai.

1.2 International Users. If you are a non-Canadian user of the Services, by visiting the Services and providing us with data, you acknowledge and agree that your Personal Information may be processed in Canada for the purposes identified in this Privacy Policy.

1.3 Lawful processing. We process your Personal Information only to the extent necessary for the purposes described in this Privacy Policy. We set out below the type of Personal Information we collect and how we use such Personal Information. Except as set forth in this Privacy Policy, your Personal Information will not be used for any other purpose without your consent. You may withdraw your consent to our processing of your Personal Information at any time. However, withdrawing consent may result in your inability to continue using the Services.

1.4 Scope. This Privacy Policy covers the activities of Company but does not apply to the practices of companies that we do not own or control, including our customers and third parties that may resell Company products and services and any services offered by other companies or other sites linked from our Services. You are responsible for ensuring that you have obtained the necessary authorizations and consents for any Personal Information you make available to us for use in accordance with this Privacy Policy, in particular, our customers represent and warrant to Company that they have the necessary rights under applicable law or have obtained the necessary consents from each end user whose Personal Information is provided by that customer to Company in order to allow Company to use, disclose and otherwise process such Personal Information for the purposes described in this Privacy Policy in the manner described in this Privacy Policy.

2. COLLECTION AND USE OF PERSONAL INFORMATION

2.1 What we Collect. Set out below are the ways in which we may collect Personal Information:

  • Personal Information We Collect from our Customers. We may collect business contact information of individuals who work for our customers in order to communicate with those customers about their business relationship with Company. We may also collect payment credentials or related information from our customers in order to allow those customers to pay Company for Services procured by such customers or in order to remit to such customers their share of transaction fees collected from end users.
  • Personal Information Collected in the Course of the Services. We may collect Personal Information about our customers’ end users through web forms and other communications methods used by the Services. The Personal Information provided by end users consists of their name, address, phone number, identification documentation, occupation and proof of address and any other Personal Information required to meet regulatory requirements for our customers (some of whom may be money service businesses). End users will also submit payment information to us. In some instances, end user information may be collected by our customers and provided to the Company. If a customer has a privacy policy that applies to its end users, then that privacy policy shall take precedence over this privacy policy, and subject to our obligations under applicable law and our contractual arrangements with the applicable customer, we will comply with that privacy policy.
  • Device information. We may collect information about devices you use to access the Services and information about how you use the Services, such as your IP address and which websites you visited before accessing our Services.
  • Logs. Our servers automatically record information created by your use of our Services to help us diagnose and fix technical issues, and to improve the overall quality and user experience of our Services. Logs may include information such as your IP address, browser type, operating system, details of how you used our Services (such as the functions you asked our Services to perform), diagnostic information related to the Services (such as crash activity reports), the referring web page, pages visited, location, your mobile carrier, device and application IDs, search terms, and cookie information.
  • Cookies. We use technologies like cookies and pixel tags to gather information about how you are interacting with the Services, which may include identifying your IP address, browser type, and referring page.
  • Employee and Contractor Candidate Information. When we seek candidates for potential jobs or contracting engagements with Company, we collect information that those candidates choose to provide to us when applying, which may include contact information, education and employment history, credentials, place of residence and other information the candidate believes to be relevant. For people who become our employees or contractors, we will typically retain the information provided by those candidates in the application process along with additional information to manage their employment or contractor relationship with us, including, without limitation, information related to income tax reporting and withholding and enrollment in Company benefit plans (in each case, to the extent applicable for the relevant relationship).
  • Marketing Information. From time to time, we may conduct surveys or hold contests or other events and in connection with such surveys, contests, or events, we may collect information you elect to provide about yourself, such as your name, email address, telephone number, organization name and address; and general information about the company for whom you work. In addition, we may use third-party service providers to collect business-related information about your employer such as its name, size, and publicly available revenue in connection with potentially offering the Services to your employer.
  • Company Suppliers and Partners. Company collects business contact information of individuals who work for our suppliers and other partners to communicate with those suppliers and partners about their business relationship with Company.

2.2 Use of Personal Information. Company uses the Personal Information described above to:

  • provide, operate, maintain and improve the Services;
  • send technical notices, updates, security alerts and support and administrative messages;
  • complete transactions (including end user transactions), and send related information to the relevant transaction participants, including confirmations and invoices;
  • respond to comments, questions, and requests and provide customer service and support;
  • communicate with you and provide news or information about us;
  • investigate and prevent fraudulent transactions, unauthorized access to the Services, and other illegal activities;
  • monitor and analyze trends, usage, and activities in connection with the Services, including generating aggregated and anonymized statistics;
  • conduct business and contractual relationships that we have with various persons and companies (such as customers, suppliers, partners and employees); and
  • for other purposes which we will notify you about and seek your consent.

3. STORAGE LOCATION AND TRANSFER OF PERSONAL INFORMATION
Company processes and stores its data, including Personal Information, on servers located in Canada. Company also transfers data to third-party service providers (“Sub-Processors”). You agree to this transfer, storing or processing of your Personal Information in Canada. You acknowledge and agree that your Personal Information may be accessible to law enforcement and governmental agencies in Canada under lawful access regimes or court order.

4. DISCLOSURE OF PERSONAL INFORMATION WITH THIRD PARTIES

4.1 Service Providers and Business Partners. We may from time to time employ third parties to perform tasks for us and we may need to share Personal Information (including account information) with them to perform those tasks. Unless we tell you differently, such third parties do not have any right to use the Personal Information we share with them beyond what is necessary for them perform the relevant tasks for us. The third parties we currently engage include third-party companies and individuals employed or contracted by us to provide certain capabilities within the Services and for certain general business functions, including the provision of database management, payment processing and customer relationship management tools, including the Sub-Processors.

4.2 Business Transfers. If our business (or substantially all of our assets) are acquired by a third party, or if we go out of business, enter bankruptcy, or go through some other change of control, Personal Information may be made available or otherwise transferred to the new controlling entity, where permitted under applicable law. Your Personal Information may also be transferred in connection with due diligence for any such transactions. In all cases, if any such transactions occur, your Personal Information will remain subject to the restrictions and protections set forth in this Privacy Policy.

4.3 With Your Consent. If we need to use or disclose any Personal Information in a way not identified in this Privacy Policy, we will notify you and/or obtain consent as required under applicable privacy laws.

4.4 As Required by Law. We may disclose your Personal Information to third parties without your consent if we have reason to believe that disclosing this information is necessary to identify, contact or bring legal action against someone who may be causing injury to or interference with (either intentionally or unintentionally) our rights or property, other users, or anyone else (including the rights or property of anyone else) that could be harmed by such activities. Further, we may disclose Personal Information when we believe in good faith that such disclosure is required by and in accordance with the law.

We also reserve the right to access, read, preserve, and disclose any information as we reasonably believe is necessary to:

  • satisfy any applicable law, regulation, legal process or governmental request (including in pursuant to subpoenas, civil investigative demands, or similar processes); enforce our contracts or user agreements, including investigation of potential violations hereof; and
  • detect, prevent, or otherwise address fraud, security, or technical issues.

The above may include exchanging information with other companies and organizations for fraud protection, spam/malware prevention, and know-your-customer purposes. Notwithstanding the general terms of this policy, the collection, use, and disclosure of Personal Information may be made outside of the terms of this Privacy Policy to the extent provided for in any applicable privacy or other legislation in effect from time to time, or pursuant to court orders (including in respect to depositions, interrogatories, subpoenas, civil investigative demands, and other court or regulatory-mandated discovery processes).

5. RETENTION
We will keep your Personal Information for as long as it remains necessary for the identified purpose or as required by law, which may extend beyond the termination of our relationship with you. Personal Information in respect to financial transactions is retained for at least five years by Company for financial compliance and to meet regulatory requirements. We may retain certain data as necessary to prevent fraud or future abuse, or for legitimate business purposes, such as analysis of aggregated, non-personally-identifiable data, account recovery, or if required by law. All retained Personal Information will remain subject to the terms of this Privacy Policy.

6. ACCESS, CORRECTION AND ACCURACY
You have the right to access the Personal Information we hold about you in order to verify the Personal

Information we have collected in respect to you and to have a general account of our uses of that Personal Information. Upon receipt of your written request, we will provide you with a copy of your Personal Information, although in certain limited circumstances, and as permitted under law, we may not be able to make all relevant Personal Information available to you, such as where that Personal

Information also pertains to another individual. In such circumstances we will provide reasons for the denial to you upon request. We will endeavor to deal with all requests for access to and modifications of Personal Information in a timely manner.

We will make every reasonable effort to keep your Personal Information accurate and up to date, and we will provide you with mechanisms to update, correct, delete or add to your Personal Information as appropriate. As appropriate, this amended Personal Information will be transmitted to those parties to which we are permitted to disclose your Personal Information. Having accurate Personal Information about you enables us to give you the best possible service.

7. CHANGES TO THIS PRIVACY POLICY
We may amend this Privacy Policy from time to time. Processing of Personal Information we collect is subject to the Privacy Policy in effect at the time such Personal Information is collected, used or disclosed as this Privacy Policy may subsequently be updated in accordance with this Section 9. If we make material changes or changes in the way we use Personal Information, we will notify you by posting an announcement on our Website or via the Services or sending you an email prior to the change becoming effective. You are bound by any changes to the Privacy Policy when you use the Website or Services after such changes have been first announced.

8. ADDITIONAL INFORMATION
Questions regarding this Privacy Policy or Company’s privacy practices should be directed to our Privacy Officer:

CompareABill.ai Inc.
Re: Privacy Compliance Officer
Email: connect@compareabill.ai