CollectWise procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ We process your personal information in the United States. This is where it will be transferred to in case you are located somewhere else. By submitting any personal information to us, you agree to its transfer to and processing in the Unites States.” | Captured 2026-07-20Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ b. You can request disclosure of your information collected by us by writing to the email at the end of this Policy. We will then provide the requested information, its sources and purposes of use, in a portable and easily accessible format within 45 days of the request.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ You can view and edit some of your account information yourself after logging in. If you terminate your account, we may retain some information for as long as necessary to evaluate Platform usage, troubleshoot issues, resolve disputes and collect any fees owed. If you have any questions or wish to ask to access, modify or delete any of your personal data on our Platform, please contact us. Note that we can deny your request if we think it would violate any law or cause the information to be incorrect. info@collectwise.org ” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ c. You have the right to request deletion of your personal information from our systems by submitting a request to the email at the end of this Policy.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We do not knowingly collect any personal information about children under the age of 18. Our Platform is not directed to children under the age of 18. If we become aware that a child under 18 has provided any personal info, it will be erased from our database as soon as reasonably possible, except when we need to keep that information for legal purposes or to notify a parent or guardian. However, portions of this data may remain in back-up archives or web logs even after we erase it from our databases. If a parent or guardian believes that a child has sent us personal information, send us an e-mail.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ In addition to sharing your data as described above, we may disclose the collected personal information as follows:” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ c. Aggregated, anonymized information that does not identify any particular user can be disclosed without restriction.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ a. In case there is a sale, merger or other transfer in the ownership of our Platform, the successor will receive personal information about our Platform users along with the assets transferred.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ b. If we decide that disclosure is appropriate to protect the property, safety, rights of the Platform, its users or the public.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ b. Controller and Beneficial Owner Information : due to the customer due diligence rule requirements under the Bank Secrecy Act, when corporate entities open business Verified Customer Record (“VCR”) accounts, we need to collect controller and beneficial owner information of that end user, which will be passed to certain API providers. A controller is a natural person who holds significant responsibilities to control, manage or direct a company or other corporate entity (e.g. CEO, CFO, General Partner, President, etc). A company may have more than one controller, but only one controller’s information must be collected. A beneficial owner is a natural person who — directly or indirectly — owns 25 percent or more of a company. If there are no natural persons who own 25 percent or more of a company, then no information needs to be collected. A beneficial owner cannot be another company (or other corporate entity), nor a nominee owner. We also need to collect a certification from the person creating the business VCR account in order to verify that the information is accurate.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ d. You have the right to nondiscrimination for exercising your rights. That means you cannot be denied goods or services, charged different prices, or provided different quality of goods/services for asserting your legal rights.” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.