Payment workflow data
We process customer, transaction, invoice, authorization, bank verification, loan application, message, and workflow status information to provide Mascot Bill.
Privacy policy
This policy explains how Mascot Bill handles information across hosted payment pages, invoice checkout, pre-authorizations, ACH and bank workflows, SME loan intake, dashboard operations, messaging, and API access.
Effective date: June 18, 2026
What Mascot Bill does
Mascot Bill connects customer-facing checkout and intake pages to operator-facing records. That means privacy needs to cover account teams, payers, borrowers, customers, integrations, providers, and support workflows.
We process customer, transaction, invoice, authorization, bank verification, loan application, message, and workflow status information to provide Mascot Bill.
Payment processors, bank connection providers, infrastructure vendors, and messaging providers may process data needed to complete the services.
Workspace teams use Mascot Bill to see payment status, customer activity, receipts, follow-ups, and API or webhook activity.
Plain-language summary
Names, emails, business details, team roles, login activity, and support communications.
Payment links, invoices, pre-authorizations, ACH or bank verification context, transaction status, receipts, and customer details.
Borrower application details, uploaded documents, bank or institution selections, offer status, and review notes.
This includes processing workflows, preventing abuse, maintaining records, improving reliability, and supporting customers.
This Privacy Policy explains how Mascot Bill collects, uses, discloses, stores, and protects information when you visit our website, create or use a Mascot Bill account, use hosted payment or loan workflows, connect API access, contact us, or otherwise interact with our services.
Mascot Bill is a payment operations platform for payment links, invoice checkout, pre-authorizations, ACH and bank verification workflows, SME loan intake, customer messaging, dashboard reporting, and API-powered workflow creation.
If you use Mascot Bill on behalf of an organization, that organization may control certain workspace data and decide how its users, customers, borrowers, or payers use Mascot Bill workflows.
Account information: name, email address, password or authentication data, workspace name, business profile, team role, settings, and support contact details.
Customer and payer information: names, emails, phone numbers, billing or shipping details, payment purpose, invoice context, receipt details, and communications related to a workflow.
Payment and transaction information: amounts, currency, payment status, provider references, card brand, card last four digits, bank account verification status, failed payment messages, refunds, charge actions, timestamps, and audit context. Full card data is handled according to processor and product boundaries.
Loan workflow information: borrower profile, requested amount, loan purpose, income or business context, uploaded documents, bank or institution selections, offer status, decision notes, and application activity.
API and integration information: API keys, webhook delivery activity, request metadata, terminal access events, hosted URL creation, and integration configuration.
Device and usage information: IP address, browser, device identifiers, pages viewed, referral source, session activity, logs, approximate location inferred from network data, and diagnostic data.
Communications: messages, templates, delivery history, support requests, sales inquiries, attachments, and feedback you send to us.
Provide, operate, maintain, and improve Mascot Bill products, dashboards, hosted workflows, API access, and support services.
Create and manage payment links, invoices, pre-authorizations, ACH or bank verification workflows, loan application workflows, receipts, refunds, follow-ups, and reporting.
Authenticate users, manage accounts, enforce workspace permissions, operate API keys, deliver webhook events, and protect against unauthorized access.
Process transactions through payment, banking, infrastructure, messaging, storage, analytics, and security providers.
Detect, prevent, investigate, and respond to fraud, abuse, security incidents, policy violations, failed payments, returned payments, disputes, and operational errors.
Communicate about account activity, workflow status, product updates, support, legal notices, security alerts, and administrative messages.
Comply with law, enforce agreements, maintain business records, respond to lawful requests, and protect Mascot Bill, our customers, and end users.
Workspace users and administrators: information may be visible to authorized users in the same workspace according to their roles and product configuration.
Payment, bank, and financial providers: we disclose data needed to process payments, verify accounts, handle ACH workflows, support loan or repayment workflows, manage disputes, and reconcile transaction status.
Service providers: we use vendors for hosting, database storage, security, analytics, messaging, email delivery, customer support, document handling, and product operations.
Business customers and their end users: where Mascot Bill powers a customer workflow, information may be shared between the business using Mascot Bill and the payer, borrower, or customer completing that workflow.
Legal, safety, and compliance: we may disclose information to comply with law, enforce terms, respond to legal process, protect rights and safety, investigate fraud, or prevent abuse.
Business transfers: information may be disclosed in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate protections.
We do not sell personal information for money. We also do not use sensitive payment or loan workflow data for unrelated third-party advertising.
We may use cookies, local storage, pixels, log files, and similar technologies to keep users signed in, remember preferences, secure sessions, measure product performance, understand website usage, and improve reliability.
You can control cookies through your browser settings. Some features may not work correctly if essential cookies or storage are disabled.
We retain information for as long as needed to provide Mascot Bill, maintain business and transaction records, comply with legal and accounting obligations, resolve disputes, enforce agreements, detect fraud, and support security operations.
Retention periods vary by data type. Payment, lending, security, tax, compliance, and dispute records may be retained longer than general website or support data.
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, hosted workflow boundaries, provider separation, logging, and secure transport practices.
No system is perfectly secure. You are responsible for protecting your account credentials, limiting team access, using strong passwords, and promptly notifying us of suspected unauthorized activity.
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information. You may also have the right to appeal a decision or withdraw consent where processing is based on consent.
Workspace administrators may be able to update certain account, customer, workflow, or team data directly in Mascot Bill. End users completing a workflow may need to contact the business that sent the workflow, because that business may control the underlying record.
To submit a privacy request, contact us using the details below. We may need to verify your identity or authority before acting on a request.
Mascot Bill and our providers may process information in the United States and other countries where we or our vendors operate. These countries may have data protection laws different from your location.
Where required, we use appropriate safeguards for cross-border transfers and vendor processing.
Mascot Bill is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Some loan workflows may require age eligibility checks or block underage applicants depending on configuration and law.
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the website, dashboard, email, or another appropriate channel. The effective date above shows when this version became effective.
Data use matrix
Operate accounts, authentication, roles, billing context, support, and workspace administration.
Create hosted pages, process transactions, track status, issue receipts, manage refunds, and support disputes.
Collect applications, verify information, support review, manage offers, and connect payment or repayment actions.
Secure API access, troubleshoot integrations, deliver webhooks, prevent abuse, and maintain reliability.
Secure sessions, measure performance, understand usage, and improve product experience.