Information we collect
We may collect business and contact details, account and onboarding information, support messages, uploaded knowledge files, website and usage data, transaction status and order metadata, and the preferences needed to configure payment or AI workflows. We collect information you submit, information produced while you use the service, and limited information received from connected providers.
Payments and sensitive information
When a hosted or tokenized payment experience is used, card details are submitted directly to the applicable payment provider. GivePay may receive a payment token, order identifier, status, receipt information, and basic transaction metadata. Do not place full card numbers, security codes, bank credentials, passwords, API keys, health information, or other unnecessary sensitive data in AI prompts, support messages, or knowledge files.
AI, voice, and conversation data
Configured AI services may process website content, business instructions, messages, call audio, transcripts, summaries, tool results, and human-handoff details. Recording and transcription features must be configured and used with notices and consent appropriate to the people and jurisdictions involved. Customers are responsible for the content they provide and for using the service lawfully.
How we use information
We use information to respond to requests, recommend and deliver services, configure and test agents, process orders, provide support, secure the service, prevent misuse, measure performance, improve workflows, communicate about an account, and meet legal obligations. We do not authorize an AI agent to make guarantees or regulated decisions beyond the approved business instructions and tools.
Providers and sharing
We may share information with payment processors, hosting and storage providers, communications and CRM platforms, AI model and voice providers, analytics and security vendors, professional advisers, and other integrations selected for a customer workflow. We may also disclose information when required by law, to protect rights and safety, or in connection with a business transaction. Third-party services operate under their own terms and privacy practices.
Connected accounts and authorization
When you authorize a connected platform such as HighLevel, GivePay receives scoped access and refresh tokens rather than your platform password. We use that authorization only for the setup, support, testing, and approved automation you request. Token material is encrypted in storage and is not displayed in the GivePay Admin interface. You may revoke access through the connected platform; an uninstall notice disables the GivePay connection and removes stored token material, subject to limited security and audit records that do not contain the token.
Retention and security
We retain information for as long as reasonably needed to provide the service, maintain business and security records, resolve disputes, and meet legal obligations. Retention can vary by record and connected provider. We use reasonable administrative and technical safeguards, but no internet service can promise absolute security.
Your choices
You may ask to access, correct, or delete information associated with your GivePay relationship, subject to identity verification and records we must retain. You may also manage cookies through your browser and disconnect optional integrations. Some requests may need to be directed to the merchant or third-party provider that controls the account.
Children and policy changes
GivePay business services are not directed to children under 13. We may update this policy as services, providers, or legal requirements change. A revised policy will be posted here with a new effective date.
Contact
Privacy questions and requests may be sent to support@givepaycommerce.com or discussed by calling 1-855-922-4729.