Privacy Policy
MoneyPass Group, LLC — effective August 5, 2026.
1. About this policy
MoneyPass Group, LLC (“MoneyPass Group,” “we,” “us,” or “our”) provides this Privacy Policy to explain how we collect, use, disclose, and protect personal information in connection with moneypassgroup.com (including its www subdomain, the “Site”).
MoneyPass Group is a business-to-business provider of surcharge-free ATM network services, ATM managed services, and cash management technology to financial institutions, independent ATM deployers, retailers, and other commercial clients. The Site is an informational and corporate site directed to business users. It is not a channel for consumer transactions.
Our use of cookies and similar technologies is described in Section 5. Your use of the Site is also subject to our Terms of Use, which is a separate agreement.
2. What this policy does and does not cover
This policy covers personal information we collect from and about visitors to the Site, individuals who contact us through the Site, individuals who subscribe to our communications or register for our events, and business contacts at our clients, prospects, partners, suppliers, and investors.
This policy does not cover:
a. Cardholder and consumer transaction information. When a consumer uses an ATM in the MoneyPass network, or when we perform services for a financial institution, ATM deployer, or other client, we process information about that client’s customers as a service provider on the client’s behalf and at the client’s direction. That information is governed by our agreements with the client, by the client’s own privacy notice, and — where applicable — by the Gramm-Leach-Bliley Act (“GLBA”) and its implementing regulations, not by this policy. If you are a consumer with a question about a transaction at a MoneyPass ATM, please contact the financial institution that issued your card. See Section 12.
b. Other websites and applications. This policy applies only to the Site. Separate notices apply to other properties, including the MoneyPass ATM locator and any client- or cardholder-facing site or application, whether operated by us, by our clients, or by third parties. Following a link away from the Site means this policy no longer applies.
c. Job applicants and personnel. Information collected from job applicants is handled under our Applicant Privacy Notice; information collected from employees and contractors is handled under a separate notice provided at the point of collection.
d. Information subject to a separate notice. Where we provide a product-, service-, program-, or event-specific privacy notice, that notice controls for the activity it describes.
e. De-identified and aggregated information. Information that has been de-identified or aggregated so that it cannot reasonably be linked to you is not personal information and is not subject to this policy. Where we maintain de-identified information, we will not attempt to re-identify it except as permitted by law.
3. Personal information we collect
3.1 Information you provide
We collect information you choose to give us, including when you complete a contact, sales enquiry, demo request, partner, media, or investor-relations form; subscribe to updates; register for a webinar, conference, or event; or otherwise correspond with us. This typically includes:
- Identifiers and business contact details — name, business email address, business telephone number, employer, job title, and business mailing address.
- Communication content — the subject and content of your message, enquiry, or correspondence, and our records of our response.
- Professional information — your role, areas of interest, the products or services you are enquiring about, and information about your organization.
- Event and marketing preferences — the events you register for or attend, communications you subscribe to or unsubscribe from, and your topic preferences.
We do not ask for and request that you not submit Social Security numbers, financial account numbers, payment card numbers, government identification numbers, health information, or other sensitive personal information through the Site. We do not intentionally collect sensitive personal information through the Site, and we do not collect consumer health data.
3.2 Information collected automatically
When you visit the Site, we and our service providers collect certain information automatically through cookies, server logs, and similar technologies:
- Device and connection data — IP address, browser type and version, operating system, device type, screen settings, and language settings.
- Usage data — the pages you request, the referring URL, date and time stamps, and related server-log records.
- Approximate location — general geographic location (typically city, region, and country) inferred from your IP address. We do not collect precise geolocation through the Site.
- Identifiers — cookie identifiers and similar online identifiers set by our hosting and security provider to deliver the Site securely and to distinguish people from automated traffic.
Section 5 explains these technologies and how to control them.
3.3 Information from third parties
We may receive personal information about you from our clients, prospects, partners, and suppliers (for example, when a colleague provides your business contact details as the appropriate contact); business information and marketing data providers; event co-hosts, sponsors, and conference organizers; analytics, advertising, and social media platforms; and publicly available sources including professional networking sites, company websites, regulatory filings, and press coverage.
4. How we use personal information
We use personal information to:
- Operate and improve the Site — deliver, secure, maintain, troubleshoot, and enhance the Site and measure how it is used.
- Respond to you — answer enquiries, route sales and partnership requests, and provide the information you request.
- Manage our commercial relationships — administer, service, and develop relationships with clients, prospects, partners, suppliers, and investors.
- Market our business and run events — send communications about our businesses, products, insights, and events where permitted by law, and administer registrations and attendance.
- Perform analytics — understand demand, audience interests, campaign performance, and market trends, including on an aggregated and de-identified basis.
- Protect security and prevent fraud — detect, investigate, and prevent malicious, deceptive, fraudulent, or illegal activity and protect our systems, personnel, and clients.
- Meet legal and compliance obligations — comply with applicable law, regulatory and payment network requirements, and legal process; establish, exercise, or defend legal claims; conduct audits; and enforce our terms and policies.
- Serve corporate purposes — internal reporting, governance, financing, and corporate transactions as described in Section 6.
Automated decision-making and profiling. We do not use personal information collected through the Site for profiling in furtherance of decisions that produce legal or similarly significant effects about you, and we do not make such decisions about you by automated means. If that changes, we will update this policy and provide the disclosures and choices required by law.
Artificial intelligence. We do not use personal information collected through the Site to train publicly available generative artificial intelligence models, and we do not permit our service providers to do so with information they process on our behalf. We may use AI-assisted tools within our own operations — for example, to help route or summarize an enquiry — under the same confidentiality and use restrictions that apply to our other service providers.
5. Cookies and similar technologies
The Site uses only strictly necessary cookies and similar technologies — those required to deliver the Site securely and reliably and to protect it from bots and abuse. These include technologies set by Cloudflare, our hosting and security provider, and by Cloudflare Turnstile, which screens submissions to our contact form. We do not currently deploy functional, analytics/performance, advertising/targeting, or social media cookies or tags on the Site.
You can control cookies through your browser or device settings. Blocking strictly necessary cookies may prevent parts of the Site — including the contact form — from working. If we add analytics or advertising technologies in the future, we will update this policy and provide a consent or preference tool as required by law before doing so.
Opt-out preference signals. As explained in Section 7, we do not sell or share personal information and we do not engage in targeted advertising, so there is no such activity for an opt-out preference signal — including the Global Privacy Control — to opt you out of. If our practices change, we will update this policy and implement recognition of opt-out preference signals as required by law before making the change.
Do Not Track. Browser “Do Not Track” settings are not uniform and we do not respond to them.
6. How we disclose personal information
We disclose personal information as follows, and not otherwise:
- Service providers and processors — technology, hosting, cloud infrastructure, customer relationship management, marketing automation, email delivery, analytics, event management, security, and professional service vendors that process personal information on our behalf, for the purposes we specify and subject to written confidentiality and use restrictions.
- Transition and shared services providers — for a transitional period following our formation, certain corporate and technology functions, including customer relationship management systems, are provided to us by third parties under transition services arrangements. Personal information may be hosted or processed in those systems, subject to confidentiality and use restrictions.
- Our members, equity holders, and their affiliates and advisors — for governance, reporting, financing, audit, and compliance purposes.
- Our affiliates and subsidiaries — for the purposes described in this policy.
- Advertising, analytics, and social media partners — we do not currently deploy advertising or analytics technologies on the Site. If we do in the future, those partners may collect information about your interaction with the Site directly through their technologies, which — depending on the technologies enabled — may constitute a “sale” or “sharing” of personal information, or “targeted advertising,” under some state laws. Section 7 describes how we would handle that.
- Professional advisors — lawyers, accountants, auditors, insurers, and consultants, subject to professional duties of confidentiality.
- Legal, regulatory, and safety recipients — regulators, law enforcement, courts, payment networks, and other parties where necessary to comply with law or legal process, to enforce our rights and agreements, or to protect the rights, property, or safety of MoneyPass Group, our clients, our personnel, or others.
- Counterparties to corporate transactions — in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, or diligence for one, subject to appropriate confidentiality protections.
- Recipients you direct or consent to.
We do not disclose personal information to third parties for those third parties’ own direct marketing purposes.
7. Sale, sharing, and targeted advertising
We do not sell personal information for monetary or other valuable consideration. We do not share personal information for cross-context behavioral advertising or targeted advertising. We do not process personal information for profiling in furtherance of decisions that produce legal or similarly significant effects. We have not done any of these things at any time since the Site launched, and we do not do so with the personal information of any individual under 18 years of age.
If we deploy analytics technologies in the future, our analytics providers will process information about your use of the Site on our behalf and for our purposes only, under contractual restrictions that prohibit them from using it for their own purposes or for advertising.
If we ever change these practices, we will update this policy before doing so and provide the notice, opt-out mechanism, and opt-out preference signal recognition that applicable law requires.
8. Retention
We will use your personal information for as long as necessary based on why we collected it and what we use it for.
To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal information; the potential risk of harm from unauthorized use or disclosure of it; the purposes for which we process it and whether we can achieve those purposes through other means; and the applicable legal requirements.
In general terms, we will retain your personal information for the duration of your involvement or engagement with us and for as long as reasonably necessary afterwards. We may maintain different retention periods for different products, services, and categories of information. Certain types of information are required to be retained for a set period by law, and we retain those for the required period.
Cookies and similar technologies persist for the periods needed to serve the purposes described in Section 5. Where you unsubscribe from marketing communications, we retain the minimum information necessary on a suppression list so that we can continue to honor your request. Where you make a privacy rights request, we retain the request and related records for as long as necessary to demonstrate our compliance.
9. Your privacy rights
9.1 Rights that may be available to you
Depending on where you live, whether you are acting in a personal or a commercial capacity (see Section 9.4), and subject to the exceptions in Section 9.6, you may have the right to:
- Know and access — confirm whether we process your personal information and obtain a copy, together with information about the categories collected, the sources, the purposes, and the categories of recipients.
- Correct — have inaccurate personal information corrected.
- Delete — request deletion of personal information we have collected from you.
- Portability — receive a copy in a portable and, where technically feasible, readily usable format.
- Opt out — opt out of the sale or sharing of personal information, of targeted advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects, to the extent we engage in those activities.
- Limit sensitive personal information — where we process sensitive personal information, limit our use and disclosure of it. As stated in Section 3.1, we do not intentionally collect sensitive personal information through the Site.
- Non-discrimination and non-retaliation — not be discriminated or retaliated against for exercising these rights.
- Appeal — where your state’s law provides an appeal right, appeal a decision we make on your request, as described in Section 9.3.
9.2 How to exercise your rights
Submit a request by:
- Email: [email protected]
- Web form: the contact form on the Site — select the “Privacy request” topic
- Mail: MoneyPass Group, LLC, Attn: Legal, 600 N. Vel R. Phillips Ave., Milwaukee, WI 53203
Verification. For requests to know, access, correct, delete, or port personal information, we will take reasonable steps to verify your identity before acting, which may include asking you to confirm information we already hold or to respond from an email address associated with our records. If we cannot verify your identity, we will tell you and explain why. If we cannot verify a deletion request, we will treat it as a request to opt out of the sale and sharing of your personal information where that right applies. We do not require you to verify your identity to opt out of the sale or sharing of personal information or of targeted advertising.
Authorized agents. You may use an authorized agent. We may require the agent to provide proof of authorization and may require you to verify your own identity directly with us, except for opt-out requests.
Timing. We will respond within the period required by the law that applies to you. That is generally 45 days from receipt, extendable by a further period where the applicable law permits and reasonable necessity requires; some states provide a different base period or extension. Where California law applies, we will confirm receipt of a request to know, correct, or delete within 10 business days. We will act on an opt-out request as promptly as practicable and in any event within the period required by applicable law. If we need more time, we will tell you before the initial period expires.
Fees. We provide responses free of charge at least twice in any 12-month period. We may charge a reasonable fee, or decline to act, where a request is excessive, repetitive, or manifestly unfounded and the applicable law permits, and we will explain our reasons.
9.3 Appeals
If your state’s privacy law provides an appeal right and we decline your request, you may appeal by writing to [email protected] with the subject line “Privacy Appeal” and a brief explanation of the grounds. We will respond in writing within the period required by the applicable law, with our decision and our reasons. If we deny your appeal, we will provide a method for you to contact your state Attorney General to submit a complaint.
9.4 Business contacts and the commercial-context exclusion
This is an important limitation on the rights described above. Most state comprehensive privacy laws define the “consumer” who holds those rights to mean an individual acting only in a personal or household capacity, and expressly exclude individuals acting in a commercial or employment context. Because the Site is a business-to-business corporate site, most personal information we collect through it — your name, employer, job title, and business contact details, provided in your professional capacity — falls outside that definition in most states.
California is the principal exception: the CCPA applies to personal information about business contacts on the same terms as other personal information. A small number of other states also reach some business-context information.
We do not use this distinction as a reason to refuse requests reflexively. If you submit a request and the applicable law does not grant you the right you have asked us to honor, we will tell you that, and explain the basis, rather than simply declining.
9.5 State-specific disclosures
Comprehensive consumer privacy laws are in effect in a growing number of states, including California, Colorado, Connecticut, Texas, and Virginia. Rights, exceptions, timelines, and the availability of an appeal vary by state.
- California. Sections 3, 4, 6, 7, and 8 together serve as our notice at collection of the categories of personal information we collect, the purposes for which we use them, whether we sell or share them, and how long we keep them. We do not offer financial incentives in exchange for personal information. California residents may also request information about disclosures of personal information to third parties for those third parties’ direct marketing purposes under California Civil Code § 1798.83 (“Shine the Light”); as stated in Section 6, we do not make such disclosures. Send any Shine the Light request to [email protected] or to the mailing address in Section 9.2, and we will respond within 30 days.
- Universal opt-out mechanisms. Several states require controllers that sell personal information, share it for targeted advertising, or profile consumers to recognize universal opt-out mechanisms. As stated in Section 7, we do not engage in those activities, so there is no opt-out for such a mechanism to effect. If that changes, we will implement recognition as required before the change takes effect.
- Minnesota. If we were to subject you to profiling in furtherance of a decision producing a legal or similarly significant effect, you would have the right to question the result of that profiling, to be informed of the reason the profiling resulted in the decision and, where feasible, what you might have done differently to change it. You may also request a list of the specific third parties to which we have disclosed your personal information.
- Oregon. You may request a list of the specific third parties, rather than only the categories of third parties, to which we have disclosed your personal information.
- Maryland. We do not sell sensitive personal information. We limit our collection of personal information to what is reasonably necessary and proportionate to provide or maintain the specific product or service you have requested.
- Nevada. Under Nevada Revised Statutes Chapter 603A, Nevada residents may submit a verified request that we not make any covered sale of certain personal information. Nevada is not a comprehensive privacy law state and its response timelines differ from those in Section 9.2; we will respond within the period Nevada law requires.
- Washington and Nevada consumer health data. We do not collect, process, share, or sell consumer health data as defined by the Washington My Health My Data Act or Nevada Senate Bill 370.
9.6 Exceptions and limitations
The rights in Section 9.1 are subject to exceptions and limitations in the applicable law. Among other things, we may retain, use, or decline to delete or disclose personal information where necessary to: comply with a legal or regulatory obligation, including the GLBA and payment network requirements; complete a transaction or provide a service you requested; detect, investigate, or prevent security incidents, fraud, or illegal activity; establish, exercise, or defend legal claims; conduct internal research, audits, or quality assurance; maintain de-identified or aggregated information; protect the rights, privacy, safety, or property of another person; or where honoring the request would reveal a trade secret or another person’s personal information. We may also decline where we cannot verify your identity as described in Section 9.2, or where the information is exempt as described in Section 12. When we rely on an exception, we will tell you which one.
9.7 Visitors outside the United States
The Site is operated from the United States and is intended for users in the United States. The Site is delivered through a global content delivery network, so pages may be served to you from a location near you; personal information you submit through the Site is transmitted to and processed in the United States. If you access the Site from outside the United States, your personal information will be transferred to and processed in the United States, where privacy laws differ from those in your jurisdiction. This policy does not provide the disclosures or the rights required by the EU General Data Protection Regulation, the UK GDPR, or other non-US privacy laws.
10. Marketing communications
If you subscribe to our communications, register for an event, or give us your business contact details in the course of a commercial enquiry, we may send you marketing emails. You can unsubscribe at any time using the link in any marketing email or by contacting us at [email protected]. We will honor an unsubscribe request promptly and in any event within the period required by law. We may still send you transactional and relationship communications — for example, a reply to your enquiry or information about an event you registered for.
11. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, and loss, and we require our service providers by contract to maintain safeguards appropriate to the information they process for us.
No website, transmission method, or storage system is completely secure, and we cannot guarantee absolute security. Please do not send sensitive information to us by unencrypted email.
12. Financial privacy, GLBA, and our role as a service provider
MoneyPass Group provides services to financial institutions and other clients. In performing those services we act on our clients’ behalf and at their direction, and much of the information involved is nonpublic personal information subject to the GLBA and, where applicable, to payment network rules and to our clients’ own privacy notices.
Two consequences follow.
We are not the right point of contact for consumer transaction data. If you are a consumer and your question concerns an ATM transaction, a card, an account, or a fee, the financial institution that issued your card or holds your account is responsible for that information and for the privacy notice that governs it. If you contact us, we may need to refer you to that institution or pass your enquiry to our client to handle.
GLBA-regulated information is generally outside the state privacy rights described in Section 9. State comprehensive privacy laws exempt information collected, processed, sold, or disclosed under the GLBA, and a number of them exempt GLBA-regulated financial institutions at the entity level. A minority of states exempt the information but not the entity, which means the rights in Section 9 can apply to non-GLBA personal information even where the institution itself is regulated. The scope of these exemptions varies by state. Where an exemption is the reason we cannot fully honor a request, we will say so.
13. Children
The Site is a business site directed to adults. We do not knowingly collect personal information from anyone under 18. We do not knowingly sell or share the personal information of, or engage in targeted advertising directed to, any individual under 18. If you believe a child or teenager has provided us personal information, contact us at [email protected] and we will delete it.
14. Third-party links
The Site contains links to third-party websites, including those of our clients, partners, industry bodies, service providers, and equity holders. We do not control those sites and are not responsible for their content, security, or privacy practices. Review the privacy notice on any site you visit.
15. Changes to this policy
We may update this policy from time to time. We will post the revised policy on the Site with a new “Last updated” date and, where a change is material, provide additional notice as required by law. Where we intend to use personal information we have already collected in a materially different way than this policy described when we collected it, we will obtain your consent where the law requires it, rather than relying on your continued use of the Site.
A copy of the prior version of this policy is available on request from [email protected].
16. Contact us
MoneyPass Group, LLC
Attn: Legal
600 N. Vel R. Phillips Ave.
Milwaukee, WI 53203
Email: [email protected]
If you have a disability and need this policy in an alternative format, contact us at the address above and we will work with you to provide it.
© 2026 MoneyPass Group, LLC. All rights reserved.