Last modified: September 1, 2021
What information does Aion collect?
● Registration information. You need a Aion account before you can take an advance on unpaid invoices. When you register for an account, you will be asked to provide us your name, phone number, email address and password that you will use for your account.
● Bank connections. We use Plaid, a third-party data aggregator, to connect to your company’s bank accounts. Plaid handles all bank integrations from the user’s app, and you will need to enter your bank username, password, and any multi-factor authentication credentials in order to connect your accounts. Since we use Plaid to enable bank integrations, we do not store your credentials when you connect your accounts to our service.
● Bank data. We receive bank transaction data that we use to provide you line of credit, loans, advances, and for analytics purposes. We will not give this or any of your information to anyone without explicit written consent by you the bank account holder.
● Business information. If you wish to use the App or Service, then you may be required to provide us with certain information about your business and business personnel (“Business Information”). Such information may include Personal Information about yourself or your business personnel. If you provide, or make available, any Personal Information about any business personnel you must first notify them and obtain their consent to disclose such information to us. Your participation in the Service is optional and you at all times have the choice of choosing whether to provide any Personal Information. Please be aware though that any failure to provide requested information may preclude your business from being approved to obtain a loan or an Advance from us.
How does Aion use the information we collect?
● We use the information we collect for the explicit purposes for providing a loan, or an advance on your business invoices, cashflow management tools, analytics, and financial services.
● We will use your Personal Information to provide and improve our Services, to contact you in connection with the Services and certain programs or offerings that you may have registered for, and to identify and authenticate your access to the parts of the Services that you are authorized to access.
● We may use your designated email address to: (i) send you updates or news regarding the Services and our products; and/or (ii) respond to a “Contact Us” or administrative request (for example, to change your password).
● We will use the Business Information and Third Party Account information that we collect to provide our Service to you, including to: (i) review your application for a loan or an Advance (this may include using such information to undertake a Background Check); and (ii) process an approved application and provide you with a loan or an Advance.
● We may collect and use your Personal Information, the Business Information and Third Party Account information as otherwise set forth in our Terms.
TrueDepth API & Camera Usage
We use the device camera to verify an individual's identity by scanning their driver license, performing a liveness check using the front camera and to upload any other relevant identity information.
Our iOS app uses Apple’s TrueDepth API only to track the movement of the applicant's eyes and face. None of the information collected by the TrueDepth API ever leaves the user's device nor is it persistently stored on the device.
The resulting depth data are solely used for identity verification purposes. This data is never stored remotely, given to third parties, or used for any non-identity verification purposes.
With whom do we share or disclose your information?
We work with third-party aggregators (Plaid) to connect to your accounts and retrieve transactional data. We do not share your information with anyone else beyond those you have explicitly authorized to receive notifications from our service.
We may disclose your Personal Information or any information you submitted via the App if we have a good faith belief that disclosure of such information is helpful or reasonably necessary to: (i) comply with any applicable law, regulation, legal process or governmental request; (ii) enforce our Terms, including investigations of potential violations thereof; (iii) detect, prevent, or otherwise address fraud or security issues; or (iv) protect against harm to the rights, property or safety of Aion, our users, yourself or the public.
What are your rights to your information?
● Update your account details. You can update your registration and other account information from your profile page. Information is updated immediately.
● Add bank connections. We provide you the ability to connect bank accounts through our third-party data aggregator.
● Close your account. You can close your Aion account at any time by contacting email@example.com only if there are no unpaid loans or advances. If there are no unpaid loans or advances, any cancellation of your Aion account will result in the deletion of your account, any accounting software integrations, any bank connections, and all associated data. Changes are made immediately with a 30-day transition period. This data cannot be recovered once your account is canceled.
Choice. At all times, you may choose whether or not to provide or disclose Personal Information. If you choose not to provide mandatory Personal Information, you may still visit parts of the App but you may be unable to access certain options, programs, offers, and services that involve our interaction with you.
Access/Accuracy. To the extent that you do provide us with Personal Information, we wish to maintain accurate Personal Information. You may use the tools that we make available on the Service to remove or modify certain information in your Account (you may also be able to remove or modify certain information via your Third Party Account that you have linked to). If you would like to correct any of your other Personal Information that we may be storing, you may submit an access request by sending an email to firstname.lastname@example.org. Your email should include adequate details of your request. Aion may retain archived information that the you have provided in the course of obtaining or attempting to obtain services through Aion in order to comply with applicable law, regulation, legal process, partner contractual obligations and our own internal policies.
Children’s Privacy. The Services are not structured to attract children under the age of 13 years. Accordingly, we do not intend to collect Personal Information from anyone we know to be under 13 years. If we learn that we have collected Personal Information from a child under 13 years, we will delete that information as quickly as possible. If you believe that we might have any such information, please contact us at email@example.com.
HIPAA. Aion is not an entity that is covered by the Health Insurance Portability and Accountability Act (“HIPAA”). The HIPAA privacy rules apply to health plans, health care clearinghouses, to any health care provider who transmits health information in electronic form in connection with transactions for which the Secretary of Health and Human Services has adopted standards under HIPAA (the “covered entities”) and their service providers (“business associates”). This means that the information that you provide to Aion is not protected by the HIPAA privacy rules and regulations. You may not submit or otherwise make available any protected health information (as that term is defined under HIPAA) to Aion.
Security. The security of Personal Information is important to us. We follow generally accepted industry standards, including the use of appropriate administrative, physical and technical safeguards, to protect the Personal Information submitted to us. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security or confidentiality. If you have any questions about security on the Service, you can contact us at firstname.lastname@example.org.
Merger, Sale or Bankruptcy. In the event that we are acquired by or merged with a third party entity, or in the event of bankruptcy or a comparable event, we reserve the right to transfer or assign Personal Information in connection with the foregoing events.
Security. Each user uses their business email and password which is required to access their Aion account. It is each user’s responsibility to protect the security of his or her sign-in information.
Your California Privacy Rights
If you are a California resident, the California Consumer Privacy Act of 2018 (“CCPA”) permits you to obtain certain disclosures about information you have shared with us in connection with your use of the Services. CCPA also provides you with certain rights with respect to this information. This section outlines those CCPA required disclosures and details those rights that apply to “personal information” subject to the CCPA. Personal information does not include information that is publicly available (as defined by the CCPA), deidentified, or aggregated.
Information We Collect
In the past 12 months, we have collected the following categories of personal information about California residents who are website visitors, users, and businesses that access services provided by or through Aion:
We collect the information listed above from the following categories of sources: (i) information provided by you, (ii) information we collected when you use our Services, or (iii) information received from third parties.
Use of Personal Information
We may use or disclose the personal information we collect from you for a number of purposes compatible for which it was collected or authorized by you, including for, but not limited to, the following purposes:
- Providing, supporting, promoting, and improving the Services;
- Communicating with you;
- Marketing and advertising;
- Complying with law and our own obligations; and
- For other purposes for which we provide notice to you at the time of collection or for which we obtain your consent.
Sharing Personal Information
We may also disclose your personal information: (i) to affiliates and subsidiaries; (ii) as required by law; (iii) in connection with corporate changes; (iv) in anonymized or aggregate form; or (v) with your consent.
Sale of Personal Information
Your Rights Regarding Personal Information
California residents may exercise the following rights regarding their personal information, subject to certain exceptions and limitations. While the CCPA becomes effective on January 1, 2020, some individuals may not be able to invoke these rights until January 1, 2021 due to a temporary legislative period of delay. For example, where an individual is acting on behalf of a company (e.g., as an employee, owner, director, officer, or contractor), access and deletion rights are temporarily unavailable for the personal information reflecting a written or verbal communication or transaction between us and the individual where the communication or transaction occur solely within the context of the individual’s company receiving a product or service from us.
- Right to Know. You have the right to request that we disclose certain information we have collected, used and disclosed in the past 12 months. You have the right to know:
- the categories and specific pieces of personal information we have collected about you;
- the categories of sources from which your personal information was collected;
- the purposes for collecting your personal information;
- the categories of third parties with whom we have shared personal information; and
- if your information is sold, lists of the categories of personal information sold and disclosed for a business purpose.
- Right to Delete. You have the right to request that we delete any personal information we have collected from you. We will also direct any service providers with whom we have shared your personal information to delete such information from their records. CCPA provides certain exceptions to the Right to Delete. If any of these exceptions apply, we will not be able to comply and will be forced to deny your request to delete, for example when the personal information is necessary to complete a transaction for which we collected it or to comply with a legal obligation. We use a two-step process for online requests to delete personal information. You will be asked to clearly submit your request to delete and to separately confirm your choice.
- Right to Opt-out of Sale(s). We do not sell your personal information to third parties.
- Right to Non-Discrimination. You have the right not to receive discriminatory treatment for the exercise of the privacy rights conferred by the CCPA.
To exercise any of the above rights, you may submit a verifiable request by using the following information:
- Emailing email@example.com with the subject line “California Rights Request”
Responding to Your Requests
When you submit a request through one of the designated methods for submitting requests, it may take us up to 45 days from receiving your verifiable request to disclose and deliver the required information. In some cases, it may take us longer to respond to your request. If we require more time (up to 90 days), we will provide you with notice of the extension period.
We may need to request additional information from you to verify your identity or understand the scope of your request, although you will not be required to create a Aion account to submit a request or have it fulfilled. If you do not have a password-protected account with us, we will require you to provide additional information to verify your identity. If we are unable to verify your identity to a reasonable degree of certainty, we will not be able to provide the requested information.
You may designate an authorized agent to make a CCPA request to know or delete on your behalf based on: (i) your written permission authorizing the agent to submit the request and the agent verifying their identity in accordance with the verification process outlined above; or (ii) providing the agent with power of attorney to act on your behalf. We will require copies of such written authorization or power of attorney.