Legal Document

Privacy Policy

Effective date: June 1, 2025  ·  Last updated: June 1, 2025

This Privacy Policy describes how brex-app Inc. ("brex-app", "we", "our", or "us") collects, uses, and discloses information about you when you access or use our platform, APIs, and associated services.

1. Data We Collect

  • Account & identity data: name, email, company name, job title, and billing address provided during registration.
  • Usage & technical data: IP address, browser type, device identifiers, API request logs, and session metadata.
  • Financial data: corporate card transaction records, expense reports, and linked bank account details processed on your behalf.

2. How We Use Your Data

  • To provision, operate, and improve the brex-app platform and developer API.
  • To detect fraud, enforce our Terms of Service, and meet regulatory obligations (AML/KYC).
  • To send transactional communications, product updates, and — where you have opted in — marketing messages.

3. Cookies & Tracking

We use strictly necessary cookies to authenticate sessions, performance cookies to measure platform speed, and analytics cookies (e.g., Segment) to understand feature adoption. You may manage non-essential cookies via our Cookie Preference Centre.

4. Third-Party Sharing

  • Payment processors & banking partners (e.g., Stripe, Evolve Bank) — necessary to execute transactions.
  • Cloud infrastructure providers (AWS) bound by data processing agreements.
  • We do not sell or rent your personal data to advertisers or data brokers.

5. Your Rights (GDPR & CCPA)

  • Access, rectify, or erase your personal data at any time via Account Settings or by contacting [email protected].
  • Opt out of the sale or sharing of personal information (California residents) by emailing the address above.
  • Lodge a complaint with your local supervisory authority (EU/EEA residents) if you believe we have infringed your rights.

6. Data Retention

We retain personal data for as long as your account is active or as required by applicable law (typically 7 years for financial records). Account data is deleted within 90 days of a verified deletion request, subject to legal holds.

7. Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). We conduct annual penetration tests and maintain SOC 2 Type II certification. In the event of a breach, we will notify affected users within 72 hours as required by GDPR.

8. Children's Privacy

brex-app is a business-to-business platform intended solely for users aged 18 and older. We do not knowingly collect personal data from minors. If we become aware that a minor has provided data, it will be deleted promptly.

9. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or an in-app banner at least 14 days before they take effect. Continued use of the platform after that date constitutes acceptance.

10. Contact & DPO

Questions about this policy? Contact our Data Protection Officer at [email protected] or visit our Contacts page.

brex-app

Corporate Finance, Engineered for Scale. The developer-first financial platform built for modern enterprises.

[email protected]+1 (415) 000-0000
548 Market St, San Francisco,
CA 94104, USA

© 2026 brex-app. All rights reserved.

SOC 2 Type II CertifiedPCI DSS Compliant