Privacy Policy
Last revised 24 September 2026
1. Who we are
Cardify Spend (“Cardify”, “we”) provides Discover, at discover.cardifyspend.com, a service that helps organisations pay their suppliers by commercial card. This policy explains what we collect, where it is kept, who else processes it, how long we keep it, and what you can ask us to do with it. It is written to meet the Personal Information Protection and Electronic Documents Act (PIPEDA) and applies to buyer users, to the suppliers whose details buyers bring to Discover, and to anyone who visits our site.
Cardify Spend, 30 Fogerty St, Brampton, ON L6Y 5K2, Canada. Privacy questions and requests go to info@cardifyspend.com.
Legal entity: Cardify Spend. Registration number: pending.
Cardify is accountable for the personal information in its care. Where a buyer uploads or connects supplier records, the buyer decides why that information is collected and Cardify processes it for the buyer under the Terms of Service. Where Cardify collects information about its own users, or about visitors to its site, Cardify decides the purpose itself.
2. What we collect
From buyer users. Name, work email address, role in the organisation, password (stored as a hash), organisation name and country, and optionally phone number, job title and department. We also keep a record of what each user does in the application (the audit trail), and usage telemetry such as which pages are opened, when, and from what kind of device and browser.
Supplier list contents. The supplier list you upload (often called an accounts payable export) or the bills and supplier records we read from QuickBooks Online when you connect it: supplier names, addresses, email addresses, phone numbers, tax identifiers where present, invoice numbers, amounts, dates, spend and payment terms.
Supplier contact details. The name, email address and business address of each supplier you choose to send an offer to, and the supplier’s response: viewed, accepted, declined with a reason, or a counter-offer. When a supplier opens a sign-in link we record the time and the network address that opened it. Where the supplier list has no contact email, we may look one up through Apollo.io; you see the suggestion and decide whether to use it.
Payment records. Which supplier was paid, when, how much, in what currency and against which invoice reference. Card numbers are entered on pages Stripe hosts and never reach Cardify; we hold only the card brand, last four digits, funding type and issuing country that Stripe reports. We never store a full card number.
From suppliers who onboard. A supplier who accepts an offer sets up a Stripe connected account. Stripe collects and holds the supplier’s identity documents and bank details under its own privacy policy. Cardify sees only that onboarding is complete and the account identifier Stripe assigns.
We collect this information from you, from the files and systems you connect, from the suppliers you contact when they respond, and from the sub-processors listed below when they return a result. We do not buy personal information and we do not use it for advertising.
3. Where it is stored
Application data is stored in Microsoft Azure in the Canada Central region (Toronto). Backups are kept in Canada East (Quebec City). Email drafting and reply classification run in Azure AI Foundry in Canada, with prompts redacted before they are sent. Some sub-processors listed below operate outside Canada, mostly in the United States; where that is the case it is stated.
Information sent to a sub-processor outside Canada is subject to the laws of that country, including laws that may allow its authorities to access it. We transfer it under written contracts that require the sub-processor to protect it to a standard comparable to this policy, to use it only to provide the service to us, and to tell us about a breach. You can ask us at the address below for more about how a given transfer is protected.
4. Sub-processors
The following third parties process data on our behalf. Each receives only what it needs for the purpose listed. We give buyers 30 days notice in the application before adding a sub-processor that will handle supplier or payment data.
- Microsoft Azure (Canada Central, backups in Canada East): database, file storage, secrets, queues and logs. Azure AI Foundry (Canada): drafting campaign text and classifying supplier replies. Prompts are redacted before they are sent and are not used to train models.
- Stripe (outside Canada): saving and charging the buyer’s card, supplier onboarding and payouts, and payment processing. Receives buyer organisation name, supplier legal name, country, email and address, and payment amounts and line items. Holds supplier identity and bank details directly.
- Visa (outside Canada): supplier card-acceptance lookup. Receives supplier name, address, country and phone number, only after the buyer records consent.
- Mastercard (outside Canada): supplier identity lookup and card programme lookup from the first digits of the buyer’s card. Receives supplier name, address, country and phone number, and a card BIN. Never a full card number.
- Twilio SendGrid (outside Canada): email delivery. Receives the recipient’s email address and the content of the offer, notification or sign-in email.
- Apollo.io (outside Canada): suggesting a contact email address for a supplier when the supplier list has none. Receives supplier business name and website domain.
- Intuit (outside Canada): the QuickBooks Online connection, when you connect it. Cardify reads supplier and bill records from your QuickBooks company and holds an access token for it, which you can revoke in Settings or in your Intuit account.
5. How long we keep it
Your supplier lists, supplier records, campaigns, offers and payment records are kept for as long as your organisation has an account, plus 90 days after it closes so that a closure made in error can be reversed. When the owner closes the account, a seven-day cooling-off period runs first; the organisation is then marked for deletion and erased at the end of the 90 days. Billing records and the audit trail are kept for seven years to meet bookkeeping and tax obligations, and are held apart from the rest of the account so that nothing else outlives the deletion.
Shorter windows apply to some records. The bytes of an uploaded supplier file are removed 30 days after processing; the supplier records read from it stay with your account. What Visa and Mastercard tell us about a supplier is cached for 30 days, refreshed monthly, and the evidence of each lookup is kept for twelve months so that we can show you when and where a result came from. Sent emails are kept for two years. Sign-in links sent to suppliers are kept for one year. A data export you request is destroyed when downloaded or after seven days. An invitation to join a team that lapsed or was withdrawn is removed after 90 days. A file that failed to import is removed after seven days.
A supplier who asks not to be contacted is removed from every open campaign and anonymised in our records as soon as there is no offer outstanding and no payment record that must be kept. Their entries in your supplier lists are not changed, because that is your accounting record.
If you ask us to delete personal information rather than close the account, we do so within 30 days of the request, after the same seven-day cooling-off period, except for what the law requires us to keep.
6. Your rights
Buyers. An organisation owner can export everything Cardify holds for the organisation from Settings, and can close the account from the same page. Closing starts a seven-day cooling-off period during which it can be cancelled. Users can correct their own details in Settings. An owner can withdraw the organisation’s consent to sending supplier data to Visa and Mastercard from Settings; from then on no new lookups are made, and the cached results expire on their normal schedule.
Suppliers. Every offer email carries a link to tell us not to contact you. Using it stops further emails from any buyer through Discover and starts the anonymisation described above. You can also write to the address below to ask what we hold about you, to have it corrected, or to have your details erased from campaigns.
Anyone can ask what personal information we hold about them, ask for it to be corrected or deleted, ask how it has been used and to whom it has been disclosed, or withdraw a consent they gave. We answer within 30 days, and we may ask for enough information to confirm who you are before we do. We do not charge for a request unless it is repetitive or excessive, and we tell you the cost first. If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
7. Security
Data is encrypted in transit using TLS 1.2 or later and at rest in Azure. Secrets and keys are held in a managed vault and are never written into code or configuration files. Each organisation’s data is isolated at the database row level, so that a query from one organisation cannot read another’s records. Access to production systems is by named identity only and is logged. The audit trail cannot be altered by the application. Card numbers never reach Cardify. Annual penetration testing by an independent firm is planned, and findings are fixed before the next release.
If a breach of security safeguards creates a real risk of significant harm to anyone, we notify the Office of the Privacy Commissioner of Canada and the people affected as soon as feasible, and we keep a record of every breach as PIPEDA requires. Where the affected records belong to a buyer, we tell the buyer so that it can meet its own obligations.
8. Changes to this policy
We may update this policy. Each version carries the date shown at the top. Material changes are announced in the application and by email at least 30 days before they take effect, and continuing to use the service after that date is acceptance of the new policy. Where a change affects how supplier data is shared with the card networks, buyers are asked to consent again before any further lookup is made. Minor changes, such as corrections and clarifications, take effect when posted.
9. Contact
Write to info@cardifyspend.com, or to Cardify Spend, 30 Fogerty St, Brampton, ON L6Y 5K2, Canada. We answer requests about your data within 30 days.
Privacy Officer: name pending. Until then, write to the Privacy Officer, reachable at info@cardifyspend.com.
The Terms of Service set out the service these processing activities support.
