Legal
Privacy policy
Last updated: July 18, 2026
1. Introduction
Assurna (“Assurna,” “we,” “our,” or “us”) provides a fully managed ecommerce platform and related professional services to businesses in the United States, including built-in payment processing. This Privacy Policy explains how we collect, use, share, and protect information about visitors to assurna.com, businesses that request a store audit, quote, or contact us, merchants and clients we onboard or serve, and the customers of client stores whose data we process on our clients’ behalf.
This policy applies to: (a) general visitors to the site; (b) businesses and their representatives who request a store audit, submit the quote or lead-intake form, or use a contact form; (c) merchants and clients in onboarding, underwriting, or with an active account for the managed platform and/or payment processing; and (d) the customers of client stores whose personal information Assurna processes while managing that store, as described in Section 7.
When we process card transactions, we do so on behalf of the merchant and in accordance with the rules of the card networks (Visa, Mastercard, American Express, and Discover) and the Payment Card Industry Data Security Standard (PCI DSS). Cardholder data is handled under those rules, as described in Section 8.
2. Scope and your rights
We process personal information in accordance with applicable U.S. federal and state laws, including the Gramm-Leach-Bliley Act (GLBA) as a provider of financial services, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Texas Data Privacy and Security Act (TDPSA), and other state privacy laws that may apply.
Depending on your state of residence, you may have rights to access, correct, delete, port, or limit the use of personal information we hold about you. Certain financial information governed by the GLBA may be exempt from some state-law rights. See Section 11 (“State privacy rights”) for how to exercise these rights.
3. Information we collect
We collect the following categories of information:
- Business and contact information, business legal name, DBA, website, email, phone, mailing address, and the names and contact details of the principals or representatives who contact us or apply.
- Store audit, quote, and lead information, name, business/work email, phone (where provided), your company or store URL, the ecommerce platform you currently use, your annual revenue range, and what is driving you to consider a change. Used to prepare your free store audit, action plan, and custom quote.
- Marketing and advertising attribution data, when you arrive at our site through a Google Ads campaign or a link carrying UTM parameters, we capture click identifiers such as gclid, gbraid, or wbraid, the utm_source, utm_medium, utm_campaign, utm_content, and utm_term values, and the landing page URL. We keep this as two records: your first qualifying visit (first-touch) and, if you return through another campaign link before that record expires, your most recent qualifying visit (last-touch), stored side by side, first-party in your browser, for up to 90 days from your first visit. If you submit a form, the first-touch record is included with your submission in our customer relationship management (CRM) system so we can measure which marketing drove your inquiry; the last-touch record stays stored in your browser. See Section 10 for how this relates to advertising.
- Application, underwriting, and KYC information (merchants only), business formation documents, tax identification number (EIN), beneficial-ownership and control-person identification, government-issued ID, bank account and settlement details, processing statements, and financial information required to underwrite and monitor a merchant account under card-network rules and anti-money-laundering law (the Bank Secrecy Act).
- Transaction and cardholder data (merchants only), information needed to process and settle payments. We minimize, encrypt, and tokenize cardholder data, and we handle it as a service provider on the merchant’s behalf under PCI DSS and card-network rules. We do not use cardholder data for our own marketing.
- Site usage information, IP address, device type, browser, pages viewed, referring URL, session timestamps. Collected via cookies and similar technologies. See Section 10.
4. How we use information
We use information to:
- Respond to inquiries, prepare store audits and custom quotes, and onboard merchants and clients.
- Deliver the managed ecommerce platform and related services to clients, including store platform management, accounting support, monitoring, and technical support.
- Underwrite, board, and monitor merchant accounts as required by our sponsor bank and the card networks.
- Process, authorize, settle, and reconcile payment transactions and manage chargebacks and disputes.
- Detect, prevent, and investigate fraud, and comply with anti-money-laundering (BSA) and sanctions (OFAC) obligations.
- Provide support, account management, and service communications.
- Measure and improve our marketing and advertising campaigns.
- Comply with card-network rules, financial regulations, and other legal obligations.
- Improve our website and services using aggregated, de-identified analytics.
We do not sell personal information for monetary consideration, and we do not use cardholder data for purposes other than processing the merchant’s transactions and meeting our legal and network obligations.
6. SMS / text messaging
If you check the SMS-consent box on a quote or contact form, you authorize Assurna to send you text messages relating to your inquiry and account, including quote confirmations, scheduling, reminders, and follow-ups from a specialist. Message frequency varies. Message and data rates may apply. Reply STOP at any time to unsubscribe; reply HELP for assistance. Carriers are not liable for delayed or undelivered messages.
In connection with SMS opt-in, we collect the mobile number you provide, the timestamp and source of the opt-in, and a record of the consent language shown to you. We retain this record for the period required by applicable law.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile opt-in data and consent are excluded from any other information-sharing described in this policy. We may share a phone number with a subcontracted communications provider (for example, our SMS delivery vendor) strictly to deliver the messages you have consented to receive.
7. Client store / end-customer data
When Assurna manages a client’s store, we process that store’s customer data, for example order details, contact information, and transaction data, as a service provider or processor acting on the client’s instructions, under the client’s services agreement with us. We do not use this data for Assurna’s own marketing. If you are a shopper with a privacy question or request about a specific store (for example, a request to access or delete your information), please contact that store’s owner directly; Assurna assists its clients in honoring such requests consistent with our service-provider obligations.
8. Data security
We maintain PCI DSS Level 1, the highest level of payment-card security, and use point-to-point encryption (P2PE), tokenization, encryption in transit (TLS) and at rest, role-based access controls, vendor due diligence, and routine review of our security posture. Tokenization and our vault are designed so that raw cardholder data does not touch a merchant’s servers.
No method of transmission or storage is 100% secure. We will notify affected individuals, our sponsor bank, the card networks, and applicable regulators of any security incident affecting personal or cardholder information as required by law and network rules.
9. Data retention
We retain personal information for the periods required by:
- Card-network rules and our sponsor-bank agreements (transaction and chargeback records are typically retained for multiple years).
- Anti-money-laundering (BSA) and tax-recordkeeping rules (generally five years or more).
- Legitimate business purposes such as fraud prevention and dispute resolution.
Store-audit, quote, and other lead submissions from non-clients are retained for up to 24 months unless you request earlier deletion under Section 11.
11. State privacy rights
Depending on your state of residence, you may have rights to know, access, correct, delete, port, opt out of sale or sharing of, and limit the use of personal information we hold about you. To exercise these rights:
- Email privacy@assurna.com with your request and the state you reside in.
- To opt out of sale or sharing under CCPA/CPRA, visit our Do Not Sell or Share My Personal Information page.
We will verify your identity before responding to prevent unauthorized disclosure. We do not discriminate against individuals who exercise their privacy rights. Certain financial information subject to the GLBA may be exempt from deletion or other rights under some state laws.
12. Minors
Our services are intended for businesses and adults. We do not knowingly collect personal information from individuals under 18.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes will be communicated by email to active merchants and clients.
14. Contact us
Privacy questions or rights requests: privacy@assurna.com. General contact: hello@assurna.com. Mail: Assurna, 9442 Capital of Texas Highway North, Suite 500, Austin, TX 78759.