Snapshot 81526
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy Terms
Privacy Policy
Last Updated: August 21, 2026
1. Introduction
Permanent link: 1. Introduction
Ramp is on a mission to help finance teams build healthier businesses. We rely on data and insights to save our customers time and money so they can focus on their core missions. This Privacy Policy explains how we manage personal data.
Ramp's products and services are intended for use by business customers and are not intended for personal, family, or household use. We collect and process personal data in a commercial context to provide our products and services to our business customers and to operate our business. We want you to understand how we collect, use, and disclose personal data, and your rights and choices regarding your personal data, including the right to object to certain types of processing we carry out (for more information see Section 6 - Your Rights and Choices below). As used in this Privacy Policy, "Ramp," "we," "our," and "us" refer to Ramp Business Corporation and its affiliates, and "you" and "your" refer to the individual interacting with us.
If you have any questions about this Privacy Policy or our privacy practices, you can contact us at privacy@ramp.com. You can also visit Section 14 - Contact Us; Data Controller below for more information.
2. Scope of this Privacy Policy
Permanent link: 2. Scope of this Privacy Policy
This Privacy Policy applies to personal data we collect and process about you as a Controller (defined below) when you use or interact with:
our platform and apps, which include corporate cards and spend management, travel, procurement, banking, accounts payable, accounts receivable, Token Spend Management, Stack, Glass, and other related services and technology (e.g., app.ramp.com and our mobile applications) (the "Services");
www.ramp.com (the "Website"); and
our social media, emails, newsletters, advertisements, and other locations or platforms, online or offline, where you interact with our business (collectively, with the Services and Website, the "Business").
Personal data we collect through Router is subject to the Router Privacy Notice. Personal data we collect when you attend a Ramp event or conference is subject to the Ramp Events Privacy Notice.
Data protection laws distinguish between entities that control the purposes and means of processing personal data ("Controllers") and entities that process personal data on behalf of others ("Processors"). The Ramp Platform Agreement, SaaS Agreement and our other terms and addenda (each, as applicable, an "Agreement"), and the terms and conditions of our Financial Institution Partners, govern our provision of Services to business customers (each a "Company").
When we process personal data on behalf of a Company as a Processor, we do so in accordance with the terms of the Agreement and the Company's instructions, not this Privacy Policy. If you wish to exercise your rights regarding personal data we process as a Processor, you should contact the relevant Company for assistance. If we receive a request intended for the Company, we will forward communications we receive from you to the Company for resolution. Ramp is not responsible for the privacy practices of any Companies, which may differ from our own.
This Privacy Policy does not apply to third-party applications or services used in connection with Ramp Services, or any other products, services, or accounts provided by other entities under their own terms and conditions or privacy policy (collectively, "Third-Party Services"). For example, a Company may connect, directly or through another application, accounting systems, e-mail services, human resources information systems, bank accounts held at depository institutions, rideshare applications, e-commerce platforms, and other products and services to its Services account ("Ramp Account"). These Third-Party Services help us provide Companies with an integrated spend management solution but are not part of our Services. They are provided by independent third parties under policies and terms of those third parties.
3. Personal Data Ramp Processes
Permanent link: 3. Personal Data Ramp Processes
Ramp processes personal data to deliver Services to you and to operate our Business. The personal data we process depends on who you are, how you interact with us, which products your Company chooses, and which features and settings you use. The table below provides an overview of the relevant person, product or interaction, data categories, and purposes. Not every category applies to every person or product. Additional detail is included in the remainder of this Section.
Person or interaction
Products or context
Personal data we may process
Main purposes
Business applicants, owners, control persons, guarantors, and other Company representatives involved in an application
Applications for corporate cards, credit, deposit or treasury products, payment services, and other regulated financial products
Name; business contact information; date of birth; residential address; citizenship; tax or government identifiers; photograph; biometrics (faceprint); government-issued identification and information captured from it; ownership or control information; employer, title, and role; financial, credit, and business information; application and underwriting information; device and fraud-risk signals; audio and/or video call recordings (unless you opt out or do not consent)
Verify identity and authority; satisfy know-your-customer, anti-money-laundering, sanctions, and other legal requirements; assess Company eligibility and risk; detect and prevent fraud, security incidents, and policy and legal violations; comply with legal obligations; open and administer the selected financial product
Company administrators and Authorized Users, including spend management, bill pay, reimbursements, accounts payable, accounts receivable, procurement, or related payment features
Ramp account product and feature use and administration, including AI-enabled products
Name; business contact information; address; employer, title, and role; permissions and login credentials; email, SMS, or search communications; product settings; files and other content submitted or connected to the Services; prompts, queries, instructions, and outputs associated with AI-enabled features; browser, device, and network information; approximate location data; connected data from third-party applications or accounts connected to your Ramp account; audio and/or video call recordings (unless you opt out or do not consent); biometric data (account recovery); transaction data; receipts, invoices, contracts, and purchase orders; tax documentation; bank account details; precise geolocation data (optional for mileage reimbursement); product usage data; business travel booking information (name, email, date of birth, gender; phone number; known traveler or redress number; and loyalty or rewards number); itinerary, booking, and approximate location information; travel preferences and support communications; product feedback
Create and secure accounts; authenticate users; configure permissions and workflows; provide the selected software and AI-enabled functionality; generate requested outputs; provide support; operate, maintain, and improve the selected Services; communicate about the account; detect and prevent fraud, security incidents, and policy and legal violations; comply with legal obligations; authorize and process transactions; administer cards and spend controls; pay bills and reimbursements; reconcile and code transactions; manage vendors and purchasing; detect errors, fraud, and policy violations; provide reporting and support; complete travel bookings, reservations and communication; search, book, change, and support business travel; apply Company travel policies; provide itinerary and expense-management features; communicate with travel providers
Vendors, payees, merchants, contractors, and other transaction counterparties
Bill pay, accounts payable, accounts receivable, procurement, card, and payment features
Name and business contact information; payment and bank-account details; contracts, invoices, and purchase orders; tax classification and tax identification information; transaction status and communications; product feedback
Verify vendors; send and receive payments; communicate about payments; operate, maintain, and improve the selected Services; communicate about the account; detect and prevent fraud, security incidents, and policy and legal violations; comply with legal obligations
Company administrators and Authorized Users (SaaS)
AI product and feature use and administration (Stack, Token Spend Management, Glass)
Name and business contact information; permissions, role, and account credentials; connected account information; browser, device, and network information; AI prompts, outputs, and related metadata; artifacts and content uploaded to the Service; approximate geolocation; product feedback
Create and secure accounts; authenticate users; configure permissions and workflows; provide the selected software and AI-enabled functionality; generate requested outputs; provide support; operate, maintain, and improve the selected Services; communicate about the account; detect and prevent fraud, security incidents, and policy and legal violations; comply with legal obligations
Website visitors, prospects, referral contacts, and social-media users
Website, advertising, sales, referrals, newsletters, and social media
Contact and professional information; communications; referral source; cookie, device, browser, IP-address, approximate location, advertising identifier, website-use, and campaign-engagement data; public profile information
Respond to requests; provide demonstrations and sales communications; understand and improve the Website; measure campaigns; advertise Ramp products; prevent abuse and secure the Website; honor privacy choices
Support contacts, event participants, and other people who communicate with Ramp
Customer support, research, surveys, sales calls, events, and other business communications
Contact and professional information; communications and product feedback; files or other content provided; audio or video recordings where disclosed and permitted; event registration information, including dietary or accessibility information you choose to provide
Respond to requests; provide support; train and improve our teams and Services; administer events; keep business and compliance records; honor recording choices
A. Product-Specific Collection
Permanent link: A. Product-Specific Collection
1. Financial Products and Services
Permanent link: 1. Financial Products and Services
We collect identity-verification, ownership, control-person, financial, credit, and risk information when it is needed for an application for or use of a regulated financial product or service, or when required by our Financial Institution Partners or applicable law. The exact information depends on the product, the Company's structure, the individual's role, and the applicable legal requirements.
2. SaaS Products
Permanent link: 2. SaaS Products
If a Company signs up only for a Ramp SaaS product that does not include a regulated financial product, Ramp does not collect know-your-customer or underwriting information solely to provide that SaaS product, but we may collect certain information for identity verification and anti-fraud measures. We may collect ordinary account, user, security, product-use, support, and Company-provided or connected content needed to provide the software. For AI-enabled features, this may include prompts, outputs, related metadata, source materials, configuration information, which may contain personal data. We process personal data included in this information to provide, secure, support, maintain, and improve the applicable product; detect and prevent fraud, abuse, or security incidents; manage our business; and comply with our legal obligations.
Before using Company Content to train a general-purpose or generative artificial-intelligence model for use across customers, Ramp will provide required notices and obtain required permissions as applicable. Product-specific terms, notices, or settings may describe additional information about model training, human review, retention, and available choices.
The sections below provide additional detail about the categories and sources of personal data we process.
B. Personal Data Provided Directly to Ramp
Permanent link: B. Personal Data Provided Directly to Ramp
The Services are intended for use by Companies and their employees and other authorized users ("Authorized Users"). If you or someone at your Company creates an account, we may receive ordinary account and user information about you, your Company, and individuals associated with your Company. If the Company also applies for or enables a regulated financial product, we may receive the additional identity-verification, ownership, underwriting, and risk information needed for that product.
1. Personal Data You Provide to Us
Permanent link: 1. Personal Data You Provide to Us
We collect and process personal data when you submit it to our Business, including:
Contact Information, including your name, email address, phone number, employer, job title, and address;
Identity Verification & Risk Information, where relevant to an application for or use of a regulated financial product, including personal data of the Company’s owners, control persons, and other relevant Company personnel, such as their name, email address, phone number, employer, job title, date of birth, residential address, country of citizenship, photograph, social security number, driver's license, passport or other government-issued identification, and any other information captured on the government identification or through our identity verification process, and other personal data requested by or provided to us as part of the application and underwriting processes.
Communications, including when contacting sales or support, providing product feedback, or corresponding with our business teams.
Content, including any documentation, files, or information you provide, which may include personal data about you.
Third-Party Information, including personal data you provide about any co-workers, contractors, vendors, or potential referrals, such as their name, email address, phone number, employer, job title, or address.
Audio and/or Video Recordings, which we may collect during sales or support calls or meetings, unless you opt out or do not provide consent, as applicable.
2. Personal Data We Collect about Authorized Users
Permanent link: 2. Personal Data We Collect about Authorized Users
In connection with providing Services, we collect and process additional personal data of Authorized Users submitted by, on behalf of, and relating to a Company’s Authorized Users, such as:
Authorized User personal data, including your name, email, phone number, address, employer, job title, login credentials, and other information used by your Company to invite and manage Authorized Users.
Transaction Data, including information associated with your bill payments, reimbursements, and card transactions made through your Company's Ramp Account, whether online or in person, which may include personal data.
Token Spend Management Data, including payment-token identifiers and lifecycle information, the related card or account identifiers, device or merchant information, transaction authorization data, authentication events, and fraud and security signals.
Connected Data, including information and documentation relating to you made available to us by Third-Party Services connected to the Services. Connected Data may be made available to Ramp during the application process and after a Ramp Account is opened for your Company. For example, if you link your bank account to receive or provide expense reimbursements, we will receive Bank Account Information about the linked account, like the bank routing and account numbers and account balance. In addition, some Third-Party Services (e.g., accounting systems and business bank accounts) will provide us with information about activities outside of the Services, which may include personal data, like your business expenses and your Company's external transactions. Other Third-Party Services, like your Company's HRIS, may disclose personal data of Authorized Users, and if your Company connects its email service, we may receive your email communications and attachments for processing. We may continue to access and receive Connected Data from a Third-Party Service until it is disconnected from the Services by you or your Company.
Travel Data, including your business travel booking information (name, email, date of birth, gender, phone number, known traveler or redress number, and loyalty or rewards number) and itinerary. This may include approximate location information, such as when your travel itinerary indicates you have booked a flight to or hotel in a particular location. This does not include the mileage reimbursement feature, which uses precise geolocation data.
Receipt and Invoice Data, including information you submit to us to pay Company invoices and process your receipts, which may include personal data, such as photos, PDFs, and the contents of e-mails, and SMS messages, if you opt-in to text messages, along with associated metadata.
Vendor Data, including the identity of vendors, which may include personal data, such as their contact information, including their name, email, phone number and address, payment details, contracts and purchase orders, and information to complete tax documentation (e.g., the vendor's tax classification and tax identification number).
C. Personal Data Generated and Collected Automatically by Ramp
Permanent link: C. Personal Data Generated and Collected Automatically by Ramp
1. When You Use or Interact with Our Business
Permanent link: 1. When You Use or Interact with Our Business
We collect and process personal data of Authorized Users and other individuals, as applicable, when you use or interact with our Website, Services, and other products and services provided or used by our Business:
Use Data, including information and metadata about the pages or content you visit, the features you interact with, the workflows you construct, how much time you spend on a particular Website or using the Services, login and crash data, Third-Party Services you elect to connect to or use with the Services ("Connected Data"), your preferences or selections, the time of day you browse, and your referring and exiting pages.
SaaS and AI Product Data, including information about workspaces, projects or spaces, skills, tools, workflows, sharing settings, product interactions, prompts, messages, queries, instructions, files, connected records, generated outputs, feedback, and feature-performance or diagnostic information.
Device Data, including information about the type of device or browser you use, your device's operating software and settings, your internet service provider, and device identifiers, such as the IP address and advertising identifier.
Location Data, including an approximate location derived from your IP address or business information and precise geolocation if you choose to enable certain features, such as trip mileage reimbursement.
We use cookies and other technologies to help us collect and process information automatically. The technologies we use to assist with this data collection include log files, cookies, web beacons, tags and scripts, pixels, and software development kits (or "SDKs"). For additional information about cookies and similar technologies we use, including how you can opt out of some of those technologies, please visit our Cookie Policy and review Section 6 - Your Rights and Choices of this Privacy Policy. You can also limit our collection of certain information by changing your device and software settings. However, doing so may affect or limit the features available to you.
2. Ramp Events
Permanent link: 2. Ramp Events
If you register for an event or conference hosted or sponsored by Ramp, we may require additional information (e.g., your company name, your job title or your dietary restrictions). Some events may have different or additional terms or privacy policies, which we will make available to you at or before the time we collect personal data for those events. For more information, review our Ramp Events Privacy Notice.
D. Personal Data Collected by Ramp from Other Sources
Permanent link: D. Personal Data Collected by Ramp from Other Sources
We also collect and process personal data of Authorized Users and other individuals, as applicable, from other sources, including:
Financial Institution Partners, including banks (e.g., the bank issuing your Company's card or originating loans to finance Company expenses), card networks, payment processors, money transmitters, and other entities that provide or support delivery of financial services.
Identity Verification, Fraud and Compliance Monitoring, and Financial and Business Information Providers, which help us supplement our understanding of your Company and its personnel, maintain security, prevent fraud, and comply with legal obligations. This may include information such as your name, address(es), phone number(s), photograph, government ID, device information, or other personal data required to verify your identity, detect and prevent fraud, and comply with our legal obligations.
Vendors and Console Users transacting with or supporting Companies (e.g., merchants and accounting firms). For example, a merchant might provide us with their name, tax identification number, and payment account information so that Companies can make bill payments and report on their tax obligations. That information may include personal data.
Service Providers, which help us operate our Business and which may collect and process personal data depending on the services they provide and your interactions and choices with respect to our Services and Websites.
Social Networks, Advertising Providers, and Private Databases, which help us to identify and enrich our understanding of prospective customers and to serve and measure advertising, provide us with personal data that may include your name, email, phone number, mailing address, gender, age, and other demographic data. We also receive personal data when you interact with our pages, groups, accounts, and posts on social media platforms, which generally includes aggregate data about our followers (e.g., age, gender and location), engagement data (e.g., “likes,” comments, shares, reposts, and clicks), and awareness data (e.g., number of impressions and reach), as well as individual users’ public profiles.
Joint Marketing, Business Partnerships, Referrals, and Rewards Partners that we engage for joint marketing activities and our referrals and rewards programs, which may share information, including personal data, about overlapping customers, such as their contact information and services they acquire.
Publicly-Available Sources, including information in the public domain that helps us identify potential customers and partners or conduct due diligence and risk management for potential and existing customers, such as personal data about a company’s personnel on its website or in news articles and press releases.
The categories of personal data we collect and receive from these sources may include all of the categories identified above in this section under "Personal Data Provided Directly to Ramp" and "Personal Data Generated and Collected Automatically by Ramp". We treat the personal data obtained from other sources in accordance with any laws or contractual obligations applicable to us.
4. How We Use Personal Data
Permanent link: 4. How We Use Personal Data
We use each category of personal data only for purposes that are relevant to the applicable person, product, and interaction described in Section 3. These business and commercial purposes include:
To Provide and Maintain Our Business. To provide, operate, and manage our Services, Website, and other parts of our Business, including to perform customer validation and to enable you to use cards and our other payment tools, to verify financial information, establish spend limits, conduct identity verification, prevent or address technical issues and disruptions, and analyze and monitor usage and activities. This includes processing information at your direction, including as expressed through your or your Company's use of certain features in the Services, such as a request to connect a Third-Party Service, like Slack or Lyft.
To Provide Token Spend Management. To provision, manage, secure, support, and reconcile token-based spend-management functionality; enable authorized transactions; administer related controls; and detect and prevent fraud, misuse, and security incidents.
To Provide SaaS and AI-Enabled Products. To respond to prompts, messages, queries, instructions, and other user requests; generate and deliver requested outputs; administer workspaces, sharing, skills, tools, and connected services; troubleshoot and improve product performance; and detect, prevent, and investigate misuse, policy violations, fraud, and security incidents.
To Communicate with You. To send you notices, updates, security alerts, and information regarding changes to our policies and terms, to respond to support requests and feedback, and to provide other transactional and relationship communications, and if applicable, marketing communications.
To Detect, Prevent, and Respond to Fraud and Security Incidents. To maintain the safety and security of our Business and to manage risk, including investigating suspicious activity, detecting and preventing potential security incidents or fraudulent or unauthorized transactions, breaches of policies and terms, and threats of harm, including in an automated fashion.
To Comply with Legal Obligations and Enforce Our Rights. To fulfill legal, regulatory, and contractual obligations, including when cooperating with government authorities, courts, and regulators in accordance with applicable law, maintaining records to demonstrate compliance with applicable law (such as financial regulations), protecting our legal rights, and pursuing remedies available to us.
To Provide Ramp Rewards. If your Company chooses to participate in our rewards program, to determine your eligibility for rewards and to facilitate the rewards program effectively.
To Develop and Improve Our Business. To make the Services and other aspects of our Business as useful as possible for Authorized Users on behalf of their Companies, including by identifying and troubleshooting issues with the Services, improving and expanding our products and operations, and offering new features and functionality. For example, we may develop or improve Services by analyzing how you use features, the documentation you submit, or information associated with your transactions.
For Auditing and Research. To conduct internal reporting, auditing, and research, including focus groups and surveys.
For Marketing and Advertising. To develop, send, and measure advertising, direct marketing, and communications about our products, offers, promotions, rewards, events, and Services. We may also use information to engage in personalized or targeted advertising. As part of this process, where permitted by law, we use tracking technologies, such as cookies, pixels, tags, and SDKs, some of which track your activities across time and services for purposes of associating the different devices you use, and delivering relevant ads and other content to you. For further information on the types of tracking technologies we use and your rights and choices regarding analytics and targeted advertising, please see Section 6 - Your Rights and Choices and our Cookie Policy. Even if you opt out of personalized advertising, you may continue to see advertising, including potentially from us. If you connect your bank account to your Company's Ramp account, we will not use your bank account information to market our Business on advertising platforms.
For Offers, Promotions, and Contests. At times, we offer certain opportunities or rewards through contests, sweepstakes, and other special offers and promotions (collectively, “Offers”). When these Offers are made available, we will provide you with a description of the Offer and related material terms, including how you can opt in (if applicable) and the categories of personal data collected in connection with the offer but not described here, which may include your name, email, and other personal data. Certain Offers may be construed as “financial incentives” under California law; California residents should review our Notice of Financial Incentives.
Generating De-identified, Aggregated, and/or Anonymized Information. To develop de-identified, aggregated, and/or anonymized information, including by removing or masking information that could be used to identify you, and by aggregating or combining information so that it does not identify an individual. We may use information that does not identify you for any purpose permitted by law and as required to meet our contractual obligations.
At Your Direction. To fulfill any other purpose at your direction, including as expressed through your or your Company's use of Services functionality. For example, if you direct us to connect your Ramp Account to a Third-Party Service, such as Slack or Lyft, we will process that request accordingly.
With Notice to You and Your Consent. We may otherwise use personal data we collect after providing notice to you and obtaining your consent.
For information about your rights and choices regarding how we use your personal data, please see Section 6 - Your Rights and Choices below.
5. Disclosure of Personal Data by Ramp
Permanent link: 5. Disclosure of Personal Data by Ramp
We disclose personal data we collect in accordance with this Privacy Policy. The categories of parties to whom we disclose personal data are listed below. We may disclose information that does not identify you (including information that has been aggregated or de-identified) for any purpose except as prohibited by law or contractual obligation applicable to us.
Affiliates. We disclose personal data to affiliates and related entities of Ramp Business Corporation.
Service Providers. We disclose personal data to service providers that process information on our behalf. Service providers assist us with services, such as cloud infrastructure, Website hosting, analytics, developing and improving the Services and Websites, processing payments, providing rewards, serving advertisements, providing communications and technical support, detecting and responding to security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and debugging to identify and repair errors in the Services. For SaaS and AI-enabled products, service providers may include model providers, hosting and infrastructure providers, safety and content-monitoring providers, and providers that support connectors, search, tools, and technical support. We disclose content and other personal data to these providers only as needed to provide, secure, support, and improve the applicable Service, at your or your Company’s direction where applicable, or as otherwise described in the applicable agreement or notice. Depending on the service, we may provide personal data on a continuous basis (e.g., fraud services) or on an as-needed basis. We impose contractual restrictions on our service providers’ processing of personal data, although we may permit them to use information that does not identify you (such as information that has been aggregated, de-identified, or anonymized) subject to applicable law.
Other Third Parties.
Business Customers. We disclose personal data to your Company so that we can provide Services on the Company’s behalf. For example, we may disclose personal data to your Company to process your payment transactions, provide Services, report on your use of your Company's Ramp Account, respond to your and their questions, comply with your and their requests, and otherwise comply with the law. In addition, your Company can assign different roles to Authorized Users, which will have different associated capabilities and permissions. We will disclose some personal data about your use of the Services to other Authorized Users within, or individuals acting on behalf of, your Company. Those individuals may include members of your Company's finance department, your manager, other Company personnel, or a Company service provider. Each Company is an independent entity, and the Company’s processing of personal data is subject to the Company’s own policies and terms.
SaaS Product Administrators and Authorized Users. Where enabled by a Company, Company administrators and other Authorized Users may be able to access, manage, export, retain, or delete account information, workspaces, prompts, messages, files, connected data, generated outputs, and other content associated with Stack, Glass, or another SaaS or AI-enabled product. The Company is responsible for configuring access and sharing permissions and providing any notices required for its administration of those products.
Providers of Connected Services. We disclose personal data to Third-Party Services and their providers if you or your Company choose to use Third-Party Services in connection with the Services, such as Slack, Uber, Google, or NetSuite.
Financial Institution Partners. We disclose personal data to Financial Institution Partners, such as banks, card networks, and payment processors, to support their customer identification, risk, and compliance programs, and so they can determine eligibility for, and provide, products and services to your Company, either directly or through us. This information also enables our Financial Institution Partners to deliver card, payments, treasury, and international transfer capabilities through our Services. For example, to comply with Know-Your-Customer requirements and requests for information, we may disclose to our Financial Institution Partners your name, email, phone number, employer, job title, date of birth, residential address, country of citizenship, photograph, social security number, and driver's license, passport or other government-issued identification, other information captured through our identity verification process, and Ramp card and transaction information.
Credit Reporting Agencies and Other Financial Information Providers. We disclose personal data about your Company and its Ramp Account to credit reporting agencies to verify information about your Company, to report on your Company's performance, and to report late payments, missed payments, or other defaults. While this information is generally about the Company, it may include personal data.
Vendors and Console Users. We disclose personal data to entities that transact with or support your Company. For example, we may disclose the status of your Company's payments to the recipient vendor, which may include personal data, such as contact information.
Ramp Rewards Providers. We disclose personal data about you and your Company's Ramp Account as necessary to determine your Company's eligibility for rewards and to facilitate the rewards program effectively.
Analytics, Marketing, and Advertising Providers and Agencies. We disclose personal data to agencies, advertisers, ad networks, and other technology services to conduct analytics and to place advertisements on our behalf on third-party websites and services. If you connect your bank account to your Company's Ramp account, we will not disclose your bank account information to market our Business on advertising platforms.
Referrals and Joint Marketing Partners. We disclose personal data about you and your Company's Ramp Account to our partners in connection with facilitating referral partnerships or engaging in joint marketing activities. For example, if you or your Company were referred to us through a referral partner, we may disclose personal data to our referral partner to confirm the status of your application and to calculate the referral fee.
Mergers and Acquisitions. We may disclose personal data to an acquiring entity, legal counsel, consultants, or others in connection with, or during negotiations of, any proposed or actual merger, purchase, sale, or any other type of acquisition or business combination of all or any portion of our assets or transfer of all or a portion of our business to another business.
Identity Verification and Risk Providers. We disclose personal data to third-party services that help us verify your and your Company’s identity and perform other compliance functions. In addition, to prevent fraud and safeguard our customers and Business, we disclose information to risk and security partners, including personal data about interactions with our Services and transactions.
Public Authorities. We may disclose personal data to public authorities, such as financial services or other regulators to comply with applicable law, payment network rules, and legal process, to investigate suspicious or potentially fraudulent activity, and where required in response to lawful requests by regulators, courts, law enforcement, and other public authorities, including to meet national security, anti-money laundering, or law enforcement requirements. We may also disclose personal data to protect the rights, property, life, health, security, and safety, as applicable, of us, the Services, our Business, or others.
For information about your rights and choices regarding how we share personal data about you, please see Section 6 - Your Rights and Choices below.
6. Your Rights and Choices
Permanent link: 6. Your Rights and Choices
A. Access, Correction, Deletion, and Objection to or Restriction of Processing
Permanent link: A. Access, Correction, Deletion, and Objection to or Restriction of Processing
Ramp Services are intended for use by business customers ("Companies"), and you may only use a Ramp account if you are an employee or other Authorized User of a Company that has opened a Ramp account. The information in a Company's Ramp Account is governed by our Agreement with the Company. You should direct questions about personal data we are processing on behalf of a Company to that Company and its administrators. If you are an Authorized User, you may also be able to access, update, or delete certain personal data within your Company's Ramp account through the Services. However, the Company and its administrators are generally responsible for determining how that personal data is processed.
Subject to limitations under applicable law, residents of certain jurisdictions have rights and choices with respect to your personal data, including the right to:
Know what personal data we process about you and to access and receive an electronic copy of your personal data.
Correct inaccurate personal data about you.
Request that we delete personal data about you.
Under certain circumstances, in jurisdictions such as the U.K. and the E.U., the right to request that we restrict processing of your personal data and/or to object to how we process personal data about you.
Where we process your personal data based on consent, the right to withdraw that consent at any time with respect to future processing.
These rights may be limited, for example, if fulfilling your request would reveal personal data about another person, where they would infringe the rights of a third party (including our rights), or if you ask us to delete information which we are required by law to keep or have a compelling legitimate interest to keep. We will not discriminate against you for exercising these rights.
To exercise any of your rights, please submit a request through our Privacy Center. We will confirm receipt of your request and respond to your request within the time limits prescribed by law. We may require additional information from you to help us verify your identity and process your request. If we are unable to verify your identity, we may deny your request. If personal data about you has been processed by us as a service provider or Processor on behalf of a Company, please contact the Company directly to exercise your rights. However, if you wish to make your request directly to us, please provide the name of your Company on whose behalf we processed your personal data. We will refer your request to that Company, and we will support them as required by applicable law to respond to your request.
In certain jurisdictions, you have the right to appeal to us a decision we’ve made to refuse to take action in response to your exercise of one of the rights above. In order to submit an appeal to us, you can contact us at privacy@ramp.com with the subject line "Privacy Request Appeal" and information relevant to the appeal in the email.
Residents of the E.U., Switzerland, and the U.K. also have the right to lodge a complaint with the data protection regulator in your jurisdiction. You can lodge the complaint in the country where you reside, where you work, or where any alleged infringement of data protection law occurred.
B. Communication Preferences
Permanent link: B. Communication Preferences
1. Emails
Permanent link: 1. Emails
You can opt out of receiving promotional emails from us at any time by following the instructions provided in the emails to click on the unsubscribe link. You can also change your email preferences here (for individuals who aren't Authorized Users) and here (for Authorized Users). If you are unable to opt-out through those methods, you can email us at privacy@ramp.com. Please note that you cannot opt out of transactional and relationship emails, and certain other content, such as those about your Company's Ramp Account, transactions, servicing, or our ongoing business relations.
2. Text or SMS Messages
Permanent link: 2. Text or SMS Messages
If you have opted in to receiving text or SMS messages related to your use of the Services, you can opt out at any time by texting "STOP" to the short code. After you send the SMS message "STOP" to us, we will send you a SMS message to confirm that you have been unsubscribed. After that, you will no longer receive SMS messages from us. Text messaging originator opt-in data and consent will not be shared, sold, rented, or otherwise disclosed by us for marketing purposes. For more information, please see the Agreement. You may be required to communicate your preferences separately to opt out of receiving messages through other platforms, such as WhatsApp.
3. Push Notifications
Permanent link: 3. Push Notifications
You can opt out of mobile device push notifications at any time by adjusting your device settings or by uninstalling the mobile app.
4. Mail and Telephone
Permanent link: 4. Mail and Telephone
You can ask to unsubscribe from our mail or telephone outreach at any time. In some jurisdictions, you can also ask us not to share your information with third parties for marketing purposes. To opt out of mail or telephone calls, you can email us at privacy@ramp.com with “Mail Opt Out” in the subject line and the address or phone number, as applicable, in the body of the email of the recipient to be opted out.
Please note that your opt-out request is limited to the email address, phone number, or address used and will not affect subsequent subscriptions.
C. Tracking Technology Control
Permanent link: C. Tracking Technology Control
1. Cookies and Similar Technologies
Permanent link: 1. Cookies and Similar Technologies
Most browsers and devices accept cookies by default. You can instruct your browser or device, by changing its settings, to decline or delete cookies and similar technologies ("Cookies"). Please be aware that if you disable or remove Cookies some parts of our Business may not function correctly and settings and preferences controlled by those Cookies, including advertising preferences, may be deleted and may need to be reset. You can modify your Cookie preferences for our Website by opting out on our Your Privacy Choices page. If you use multiple browsers or devices, you may need to instruct each browser or device separately. Your ability to limit Cookies is subject to your browser and device settings and limitations. For additional information, please visit our Cookie Policy.
We may use session-replay technologies to understand how users interact with the Service, including clicks, scrolling, page navigation, and technical information about a session, to troubleshoot, secure, and improve the Service. Where used, we implement measures designed to mask or exclude certain types of information, such as passwords, payment card information, and other sensitive content. Where required by law, we obtain your consent before enabling session replay.
2. Global Privacy Control
Permanent link: 2. Global Privacy Control
Certain browsers and browser extensions support the Global Privacy Control ("GPC") that can send a signal to websites you visit to indicate your choice to opt out of certain types of data processing. Our Website is designed to respect your GPC preferences.
3. Do Not Track
Permanent link: 3. Do Not Track
Your browser settings may allow you to automatically transmit a "Do Not Track" signal to online services you visit. There is no industry consensus as to what site and app operators should do with regard to these signals. Accordingly, unless and until the law is interpreted to require us to do so, we do not monitor or take action with respect to "Do Not Track" signals. For more information, visit All About Do Not Track. However, you can use the other controls identified in this section of the Privacy Policy to control tracking technologies as described, including GPC.
4. Email Web Beacons
Permanent link: 4. Email Web Beacons
Most email clients have settings which allow you to prevent the automatic downloading of images, including web beacons, which prevents the automatic connection to the web servers that host those images and, unless restricted by your Company, you can change those settings in your email account.
5. Mobile Advertising ID Controls
Permanent link: 5. Mobile Advertising ID Controls
iOS and Android mobile operating systems provide options to limit tracking and to reset the advertising IDs and, unless restricted by your Company, you can change those settings on your device.
6. Analytics and Targeted Advertising
Permanent link: 6. Analytics and Targeted Advertising
Google provides tools to allow you to opt out of the use of certain information collected by Google Analytics through the Google Analytics Opt-out Browser Add-on and by Google Analytics for Display Advertising or the Google Display Network through Google Ads Settings.
7. Opt Out of Targeted Advertising and "Sales" or "Sharing" of Personal Data
Permanent link: 7. Opt Out of Targeted Advertising and "Sales" or "Sharing" of Personal Data
Data protection laws in certain jurisdictions provide the right to opt out of targeted advertising, "sales," or "sharing" of personal data. To opt out of targeted advertising, "sales," or "sharing" (as defined by applicable law) of your personal data, visit our Your Privacy Choices page or click the "Your Privacy Choices" in the footer of our Website. California residents can review information relating to California’s data protection laws in our California Notice at Collection below.
In addition to the option above, the companies we work with to provide you with targeted ads in connection with our Business are required to give you the choice to opt out of receiving targeted ads. Most of these companies are participants of the Digital Advertising Alliance ("DAA") and/or the Network Advertising Initiative ("NAI"). To learn more about the targeted ads provided by these companies and how to opt out of receiving certain targeted ads from them, please visit: (1) for targeted ads from DAA participants, DAA Choices; and (2) for targeted ads from NAI participants, NAI Opt Out. Opting out only means that the selected participants should no longer deliver certain targeted ads to you. It does not mean you will no longer receive any targeted content or ads (e.g., in connection with the participants' other customers or from other technology services). Any targeted advertising by Ramp will only be carried out to the extent that it is permitted by applicable law.
Please note that if you opt out using any of these methods, the opt out will only apply to the specific account, browser, or device from which you opt out. Except as required by applicable law, we are not responsible for the effectiveness of, or compliance with, any opt-out options or programs, or the accuracy of any other entities' statements regarding their opt-out options or programs.
8. Opt Out of Audio or Video Recording
Permanent link: 8. Opt Out of Audio or Video Recording
We may record audio or video in connection with sales or support calls and meetings to help us operate, manage, and improve our Business. You will be notified prior to a recording, and if you want to opt out of or don’t want to opt in to the recording, as the case may be, you should follow the instructions presented in the notice.
7. International Data Transfers
Permanent link: 7. International Data Transfers
Our Business is headquartered in the United States, with operations in Canada and other jurisdictions. Depending on your relationship with us, where you reside, and your use of certain parts of the Services, your personal data that we collect may be transferred to, processed, used, handled, and stored in the United States and other jurisdictions. Data protection laws in the United States and other jurisdictions may differ from those of your country of residence. We take measures to comply with applicable data protection laws when we transfer personal data internationally. In certain situations, regulators, courts, and law enforcement agencies might be entitled to access your personal data (for more information see Section 5 - Disclosure of Personal Data by Ramp).
For personal data transferred from the European Economic Area ("E.E.A."), Switzerland, or the U.K., we will provide appropriate safeguards for transfers of your personal data outside of those jurisdictions, including: (1) transferring the personal data to countries recognized by the European Commission, the Swiss Federal Data Protection and Information Commissioner, and/or U.K. Information Commissioner’s Office as offering an adequate level of protection for personal data; (2) transferring the personal data pursuant to contractual obligations, including Standard Contractual Clauses ("SCCs") and addenda specific to Switzerland and/or the U.K., as applicable; and (3) confirming service providers to which we transfer personal data have active self-certification under the E.U.-U.S. Data Privacy Framework, the U.K. Extension to the E.U.-U.S. DPF, or the Swiss-U.S. DPF, as applicable. While transfers to countries that don’t have an adequacy decision typically take place on the basis of SCCs, in certain circumstances, transfers can also take place on the basis of exemptions provided under data protection law, such as sharing personal data as required with law enforcement or in emergency situations where we learn that a person’s life is at risk.
We also identify and use additional protections as appropriate for each data transfer. For example, we use technical protections, such as encryption and pseudonymization, and policies and processes to review and, as appropriate, challenge disproportionate or unlawful government authority requests for personal data. For more information about our security measures, visit our Trust Center.
If you are a resident of the province of Quebec, please note that we transfer and store personal data outside of Quebec province.
8. Lawful Basis for Processing Personal Data
Permanent link: 8. Lawful Basis for Processing Personal Data
Certain jurisdictions, such as the E.E.A., Switzerland, and the U.K., require a "lawful basis" to collect, process, and disclose personal data. Where we are the Controller of your personal data, we rely on the following lawful bases:
At your direction and in performance of a contract we have with you.
Compliance with our legal obligations or to preserve or enforce our legal rights.
Consent that you provide us at the time of collection of your personal data or subsequently.
To further the legitimate interests of Ramp or a third party, for example, to: (1) administer and conduct our business, including maintaining and improving the Services; (2) detect, prevent, and respond to security incidents; (3) detect and prevent fraud; and (4) conduct marketing and analytics activities.
9. Automated Decision-Making and Artificial Intelligence
Permanent link: 9. Automated Decision-Making and Artificial Intelligence
Ramp uses automated systems, which include artificial intelligence and machine-learning technologies ("AI Systems"), to operate and protect our Business and provide the Services. Depending on the product and workflow, AI Systems may assist with tasks such as:
verifying identity and business information;
detecting and preventing fraud, suspicious activity, sanctions or compliance risks, unauthorized transactions, and security threats;
supporting business application review, underwriting, eligibility, and risk-management processes for financial products;
matching receipts, invoices, transactions, accounting information, and other records;
applying Company policies, controls, workflows, and product settings;
generating policies and workflows; and
improving, troubleshooting, and securing our Services.
More information about the AI Systems we use and the tasks they support is available on our Trust Center. Ramp does not use AI Systems to make a decision based solely on automated processing that produces legal or similarly significant effects for an individual subject to this Privacy Policy.
10. Security
Permanent link: 10. Security
We use various technical, organizational, administrative, and physical measures designed to protect your personal data from loss, theft, misuse, and unauthorized access, disclosure, alteration, or destruction. However, no information security program or transfer of information via the internet is entirely secure, so we cannot guarantee the security of your personal data. We recommend you use strong passwords, use multi-factor authentication to access your account, and otherwise follow your Company’s information security practices. If you suspect unauthorized activity with respect to your Ramp account or you suspect a security incident has occurred, you should contact us immediately at security@ramp.com.
11. Use by Minors
Permanent link: 11. Use by Minors
We do not direct any of our Services or other aspects of our Business to minors. We do not knowingly collect personal data (as defined by the U.S. Children's Online Privacy Protection Act, or "COPPA") from children under 13. We also do not knowingly "share" or "sell," as those terms are defined under applicable law, the personal data of minors under the age of 18. If you are a parent or guardian of a minor and believe your minor uses the Services, contact us at privacy@ramp.com.
12. Retention
Permanent link: 12. Retention
Ramp maintains retention schedules that assign retention periods or deletion criteria based on the category of personal data, the product and purpose for which it was collected, the legal basis for processing, and applicable legal requirements. We do not retain personal data indefinitely merely because it may be useful in the future.
The following describes the principal retention triggers and criteria we use:
Record category
Retention period or criteria
Account, user, and product records
For the life of the relevant account, user relationship, or enabled product, followed by the period reasonably needed to close the account, complete pending activity, provide requested exports, maintain audit trails, resolve disputes, and meet legal obligations
Applications, identity-verification, ownership, underwriting, and compliance records
From collection or the application decision through the period required by financial-services, anti-money-laundering, sanctions, credit, recordkeeping, or other applicable law, generally measured from the application decision, account closure, transaction, or end of the relevant relationship
Transaction, payment, card, reimbursement, invoice, receipt, travel, procurement, and accounting records
For the life of the relevant account, user relationship, or enabled product, followed by the period reasonably needed to close the account, complete pending activity, provide requested exports, maintain audit trails, resolve disputes, and meet legal obligations
Connected Data and Company content
While the relevant connection or product is enabled and thereafter for the period needed to complete pending workflows, honor the Company's deletion or export instructions, protect account integrity, and satisfy legal, contractual, audit, and dispute requirements. This includes, where applicable, prompts, messages, files, connected records, generated outputs, feedback, and workspace or sharing information SaaS products.
Security, fraud, authentication, and technical logs
For periods based on the security purpose, sensitivity, and risk of the data, including the time needed to detect patterns, investigate incidents, prevent repeat abuse, maintain system integrity, and satisfy security or legal requirements
Support, sales, research, event, and business communications
For the duration of the interaction and thereafter based on the nature of the communication, the status of the relationship, quality and training needs, recording choices, and applicable legal, contractual, and dispute requirements
Website, cookie, analytics, and advertising data
For the periods described in our Cookie Policy or the applicable tool, consent, or preference setting; marketing contact information is retained until you opt out or it is no longer needed, with suppression records retained to honor your choice
Privacy requests, consents, objections, and compliance records
For the period needed to respond to the request or administer the choice and thereafter to demonstrate compliance, prevent repeated unauthorized requests, and meet applicable limitation and recordkeeping periods
We periodically review whether personal data remains necessary for the stated purpose. When a retention period expires or the applicable purpose no longer requires identifiable data, we delete, de-identify, or anonymize the data, or place it in a restricted archive when continued storage is required by law. Data subject to a legal hold, regulatory inquiry, investigation, dispute, fraud-prevention need, or security incident may be retained until the matter and any related preservation period end. Residual copies in backups are protected from ordinary use and deleted or overwritten through scheduled backup cycles unless continued preservation is required. Where Ramp processes personal data solely on behalf of a Company, retention and deletion are also governed by the Agreement and the Company's instructions.
13. Changes to this Privacy Policy
Permanent link: 13. Changes to this Privacy Policy
At Ramp, we build with velocity, which means we regularly ship new products and features and improve our Business. Those changes sometimes require us to collect new personal data or to use personal data in different ways, so we periodically update this Privacy Policy to reflect those changes. We reserve the right to change and reissue this Privacy Policy at any time by posting an updated version on our Website. If we make material changes in the way we collect, use, or disclose your personal data, we will provide you reasonable advanced notice of the changes before they take effect for you. If we have an existing relationship with you, you represent a Company, or if you are an Authorized User, we may provide you notice through our Website, through your Company's Ramp Account, or directly using the contact information you have provided to us. If we do not have an existing relationship with you (for instance, if you only visit our Website), any notice we provide will be posted to our Website. If you continue using the Services after those changes are in effect, our processing of your personal data will be subject to the new Privacy Policy. We encourage you to regularly review this Privacy Policy to ensure that you remain aware of what personal data we collect, how we use and otherwise process it, under what circumstances we will disclose it to third parties, and your privacy rights and choices.
14. Contact Us; Data Controller
Permanent link: 14. Contact Us; Data Controller
If you have questions about this Privacy Policy or our practices with respect to personal data, or if you have difficulty accessing the information in this Privacy Policy, please contact us:
By email: privacy@ramp.com
By mail: Ramp Business Corporation, Attn: Privacy Counsel, 28 West 23rd, Floor 2, New York, NY 10010
Ramp may process personal data in accordance with the instructions of or on behalf of a Company, including when providing Services to a Company under an Agreement. In this context, Ramp acts as a Processor and the Company acts as a Controller. Ramp may also act as a Controller when directly determining the purposes for and means of processing personal data in other business contexts as set out in this Privacy Policy, like complying with regulatory obligations applicable to our Business. Where we act as the Controller, the Controller is Ramp Business Corporation, unless we specify otherwise in writing.
15. Additional Information for California Residents
Permanent link: 15. Additional Information for California Residents
A. California Notice at Collection
Permanent link: A. California Notice at Collection
These additional disclosures apply only to California residents and only to the extent applicable. At or before the time of collection of your personal data, you have the right to know the categories of personal data and sensitive personal data to be collected (see Section 3 - Personal Data Ramp Processes), the purposes for the collection and use of your personal data (see Section 4 - How We Use Personal Data), whether your personal data is "sold" or "shared" (as defined under California law), and how long your personal data is retained (see Section 12 - Retention). To review that information, you can follow the links above.
1. Categories of Personal Data We Collect
Permanent link: 1. Categories of Personal Data We Collect
California law requires businesses collecting or disclosing personal data to provide notices and means to exercise those rights. In the past 12 months, we have collected the following categories of personal data:
Identifiers, including name, postal address, email address, online identifiers (such as IP address), social security number, driver’s license number, passport number, or other similar identifiers.
Customer Records, including phone number, billing address, bank account, and credit or debit card information, which may include personal data.
Employment Information.
Characteristics of Protected Classifications under California or Federal Law, including gender and citizenship.
Biometric Information for identity verification and fraud detection.
Commercial or Transaction Information, including records of products or services purchased, obtained, or considered, which may include personal data.
Internet Activity, including browsing history, search history, and interactions with a website, email, application, or advertisement.
Audio and/or Video Recording.
Approximate Location Data.
Precise Geolocation Data when you choose to enable certain features such as trip mileage reimbursement.
Inferences Drawn from the above information about your predicted characteristics and preferences.
For further details on personal data we collect, including the sources from which we receive personal data, review Section 3 - Personal Data Ramp Processes. We collect and use these categories of personal data for the business purposes described in Section 4 - How We Use Personal Data above. We disclose the personal data to the categories of persons set out in Section 5 - Disclosure of Personal Data by Ramp above. Please visit those sections for further details.
2. Rights to Know, Correct and Delete
Permanent link: 2. Rights to Know, Correct and Delete
You have the right to know certain details about our personal data practices and the rights you have under California law. You have a right to know the categories of personal data we have collected about you; the categories of sources from which the personal data was collected; the categories of personal data we have disclosed for a business purpose or "sold" or "shared;" the categories of persons to whom the personal data was disclosed, "sold," or "shared;" the business or commercial purpose for collecting, "selling," or "sharing" the personal data; and the specific personal data we have collected about you. We have provided much of that information throughout this Privacy Policy, and to the extent it is not addressed elsewhere, it is addressed in this section. In addition, subject to certain exceptions, you have the right to request that we correct inaccurate personal data or that we delete the personal data we have collected from you. To exercise your privacy rights, please submit a request through our Privacy Center. We will confirm receipt of and respond to your request within the time limits prescribed by law. We may require additional information from you to help us verify your identity and to process your request. If we are unable to verify your identity, we may deny your request. If you are unable to submit a request through our Privacy Center, you can submit a request to privacy@ramp.com.
If personal data about you has been processed by us as a "service provider" (which is similar to a data processor) on behalf of a Company, please inquire with your Company directly to exercise your rights. If you want to make your request directly to us, please provide the name of your Company on whose behalf we process your personal data. We will refer your request to that Company and will support them to the extent required by applicable law in responding to your request.
You have the right not to receive discriminatory treatment by us for the exercise of any of your privacy rights. We retain records of privacy rights requests in accordance with applicable law.
3. Do Not Sell or Share My Personal Data
Permanent link: 3. Do Not Sell or Share My Personal Data
Our business model is to provide corporate card, spend management, and related services to Companies, not selling personal data. However, under California law, some marketing practices, like the disclosure of Website visitor data to obtain targeted ads and analytics to advertise our products and services on third-party sites, may be considered a "share" or "sale." Under California law, "share" is broadly defined to include the disclosure of personal data for cross-context behavioral advertising, and "sale" is broadly defined to include the disclosure of personal data for anything of value, even if no money is exchanged. Under those definitions, we may "share" or "sell" the following categories of personal data for commercial purposes: identifiers, characteristics, commercial or transaction information, internet activity, approximate location data, and inferences drawn. The categories of third parties to whom we "share" or "sell" personal data include, where applicable, third parties we work with to deliver targeted advertising, including across sites, and to conduct analytics. To the extent our marketing practices constitute a "share" or "sale" of your personal data, you have the right to opt out. You can exercise this right by modifying your preferences for our Website on our Your Privacy Choices page or by enabling the Global Privacy Control ("GPC") on your browser or extension. These settings enable you to communicate an opt-out preference that is specific to your browser or device, as applicable, so you will need to instruct each separately.
4. Right to Limit Use of Sensitive Personal Data
Permanent link: 4. Right to Limit Use of Sensitive Personal Data
California law gives consumers the right to limit a business's use of “Sensitive Personal Information” to purposes necessary to provide the services reasonably expected by an average consumer, as well as certain other permitted business purposes, such as security, fraud prevention, and legal compliance.
We collect certain categories of Sensitive Personal Information, including Social Security numbers, driver's license numbers, passport numbers, other government-issued identification numbers, and biometric information collected through our identity verification process. We use this information solely to verify identity, prevent fraud, comply with legal and regulatory obligations (including Know Your Customer requirements), and for other purposes necessary to provide our Services. We do not use Sensitive Personal Information to infer characteristics about individuals or for cross-context behavioral advertising. Because our use of Sensitive Personal Information is limited to these permitted purposes, California law does not require us to offer a separate opt-out right for this processing. If you have questions about our use of Sensitive Personal Information, please contact us at privacy@ramp.com.
5. Authorized Agent
Permanent link: 5. Authorized Agent
You can designate an authorized agent to submit requests on your behalf. In order to do that, please provide the agent with written permission, signed by you, authorizing the agent to submit the request on your behalf. The agent must provide us with that written permission as part of the request. We may contact you to verify your identity directly, as well as the authorized agent’s permission, before we send a response to the request. Requests from an authorized agent to exercise rights under data protection law on your behalf must be submitted through the designated methods listed above.
B. Notice of Financial Incentives
Permanent link: B. Notice of Financial Incentives
At times, we offer certain opportunities or rewards through contests, sweepstakes, and other special offers and promotions (collectively, "Offers") (see Section 4 - How We Use Personal Data). Because these Offers often involve the collection of personal data, they may be interpreted as "financial incentive" programs under California law. We use personal data collected through Offers for the purposes described in this Privacy Policy. We may disclose your personal data to third parties as described in Section 5 - Disclosure of Personal Data of this Privacy Policy, including data analytics providers, advertising technology vendors, and social media platforms. The value of any financial incentive we offer is reasonably related to the value of any personal data you provide to us. As required by applicable law, we estimate the value of your personal data by considering, without limitation, the expenses we incur from collecting your personal data and/or providing the Offer to you, the revenue (if any) generated by your use of the Offer, and any improvements we can make to the Services based on information obtained from you as a result of the Offer. If you want to withdraw from an ongoing or upcoming Offer, you can do so by emailing privacy@ramp.com.
16. Additional Information for Canadian Residents
Permanent link: 16. Additional Information for Canadian Residents
Data Transfers from Quebec
Permanent link: Data Transfers from Quebec
If you are a resident of the province of Quebec, please note that we transfer and store personal data outside of Quebec province.
Data Disclosure to Telecommunications Carriers
Permanent link: Data Disclosure to Telecommunications Carriers
Personal data will be shared with telecommunication providers or mobile network operators for the purposes of identity verification.
17. Additional Information for UK Residents
Permanent link: 17. Additional Information for UK Residents
For purposes of certain regulated financial services in the UK, Ramp is an agent of Plaid Financial Ltd., an authorized payment institution regulated by the Financial Conduct Authority under the Payment Services Regulations 2017 (Firm Reference Number: 804718). For those applicable parts of the Services, Plaid provides you with regulated account information services through Ramp as its agent.