Legal

Privacy Policy

Effective: July 14, 2026Last updated: July 14, 2026

Drafsense, LLC (“Drafsense,” “we,” “us,” “our”) provides a software platform that allows businesses to generate remotely created checks based on documented payment authorization. Because that work involves sensitive financial information, this policy is written to be thorough, not just brief — you should be able to find a real answer here to any reasonable question about how your information is handled.

01

Introduction and scope

This policy applies to:

  • Merchants — the businesses that hold a Drafsense account
  • Payers — individuals whose bank account information a merchant is authorized to use to generate a check
  • Visitors to our website, prior to creating an account

Drafsense is not a bank, payment processor, or money transmitter and does not hold, transfer, or have custody of funds. This policy governs information, addressed separately from the handling of funds, which is covered in our Terms of Service.

02

Definitions

  • "Personal Information" means information that identifies, relates to, or could reasonably be linked with a particular individual.
  • "Nonpublic Personal Information" ("NPI") has the meaning given under the Gramm-Leach-Bliley Act — generally, personally identifiable financial information that isn't publicly available.
  • "Merchant" or "Subscriber" means the business that has registered for a Drafsense account.
  • "Payer" means the individual whose bank account a merchant is authorized to reference in a check created through Drafsense.
03

Information we collect

From merchants, directly

  • Business name, address, and contact information
  • Individual account holder name, email, and phone number
  • Login credentials
  • Billing and subscription information (processed by our payment provider — we do not store full payment card numbers)
  • Business verification information we may request, such as registration details, where applicable

From or about payers, collected by a merchant with authorization

  • Name, address, phone number, and email, where provided
  • Bank routing number and account number
  • Authorization record: typed name, initials, a drawn signature image, timestamp, and basic device/browser information tied to that specific authorization event

Collected automatically

  • IP address, browser type and version, device type, and access timestamps
  • Pages visited and general usage patterns within the platform, used for security monitoring and service improvement

From other sources

  • Bank routing and institution details are cross-referenced against the Federal Reserve's public E-Payments Routing Directory — a government-published dataset — to reduce entry errors. This is not personal information about you, but it informs what's shown during check creation.

We do not knowingly collect more information than is necessary to operate the service described in these policies.

04

How we use information

We use the information described above to:

  • Generate a check draft based on a documented, verifiable authorization
  • Verify routing number and bank information against the Federal Reserve's public directory
  • Create and maintain the authorization and audit records that establish the legal standing of a remotely created check under UCC Article 3, Article 4, and Regulation CC
  • Operate, maintain, secure, and improve the Drafsense platform
  • Communicate with you about your account, respond to support requests, and send service-related notices
  • Detect, investigate, and prevent fraud or misuse, and comply with legitimate requests from law enforcement or financial institutions
  • Meet our own legal, tax, and recordkeeping obligations
05

GLBA notice: categories of information and disclosure practices

As a service provider handling nonpublic personal financial information on behalf of merchants, we describe our practices here in a manner consistent with the disclosures required under the Gramm-Leach-Bliley Act's Privacy Rule:

  • Categories of NPI we collect: information from account applications (name, address, bank account and routing numbers), and information about your transactions with us (check creation history, authorization records).
  • Categories of NPI we disclose, and to whom: we disclose NPI to the merchant who obtained the relevant authorization, to service providers who help us operate Drafsense under confidentiality obligations, and where required by law. We do not disclose NPI to nonaffiliated third parties for their own marketing purposes, and we do not sell NPI.
  • Opt-out rights: because we do not share NPI outside the exceptions described above, there is no marketing-related sharing to opt out of. If our practices change in a way that would require an opt-out notice under GLBA, we will provide one before making that change effective for existing account holders.
06

How we share information

We share information only in these circumstances:

  • With the merchant who obtained the authorization, for their own legitimate use within their account
  • With service providers who perform functions on our behalf — cloud hosting, encryption key management, subscription billing — bound by confidentiality and data protection obligations consistent with this policy
  • For legal reasons — to comply with a subpoena, court order, or other valid legal process, or to respond to a legitimate request from a financial institution investigating a specific transaction
  • To prevent harm — if we reasonably believe it's necessary to investigate or prevent fraud, protect the security of the platform, or enforce our Acceptable Use Policy
  • In connection with a business transfer — if Drafsense is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to the protections described in this policy
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used under state privacy laws.
07

Cookies and tracking

Drafsense currently does not use third-party advertising or analytics tracking scripts. We use functional cookies necessary to keep you securely logged in and to operate the platform. If this changes in the future — for example, if we add analytics to understand product usage — we will update this section to describe what's used and, where required by law, provide a way to control it.

We do not currently respond differently to browser "Do Not Track" signals because we do not engage in the type of cross-site tracking those signals are designed to address.

08

Data security

  • Encryption. Bank account and routing numbers are encrypted using industry-standard envelope encryption, with keys managed through a dedicated key management service kept separate from the data itself.
  • Access controls. Data is isolated by account at the database level, so one merchant cannot access another's records.
  • Audit logging. Key actions are recorded in a permanent, append-only log that cannot be quietly altered or deleted.
  • Verified routing data. Routing numbers are checked against the Federal Reserve's public directory before a draft is created. Because this data can change, the merchant creating a check is responsible for confirming the displayed bank name and address are correct.
  • No custody of funds. Drafsense does not accept, transmit, or otherwise touch funds, and is therefore not a money transmitter or money services business. Funds move directly between merchant and payer through the banking system when a check is deposited — Drafsense is not a party to that movement.

No system is completely immune to risk. If we ever experience a security incident affecting your personal information, we will notify affected individuals and, where required, regulators, consistent with applicable state and federal breach notification laws.

09

Data retention

  • Printable copies of a check are available for a limited window after creation, after which reprint access is restricted.
  • Stored bank account data is purged automatically on a defined schedule once it is no longer tied to an active authorization or a legitimate recordkeeping need.
  • Audit log entries are retained separately and indefinitely for compliance and dispute-resolution purposes, independent of whether the underlying bank data has since been purged.
  • Backups are created on a regular schedule and are protected by the same access controls as production data.
10

Your privacy rights

Payer rights

If your bank information was used to generate a Drafsense check, you may ask the merchant who obtained your authorization what information they have on file, and you may revoke a standing authorization at any time (this stops future checks under that authorization but does not undo one already created). You can also contact us directly.

State law rights

Depending on where you live, state law may give you additional rights, including under California's CCPA/CPRA and similar laws in Virginia, Colorado, Connecticut, Utah, and other states. Where applicable and not otherwise exempt because the information is nonpublic personal financial information already governed by GLBA, these rights can include:

  • The right to know what personal information we hold about you
  • The right to request correction of inaccurate information
  • The right to request deletion of your information, subject to our legal and recordkeeping obligations
  • The right to opt out of the sale or sharing of personal information — which is not applicable in practice, since we don't sell or share personal information as those terms are defined under these laws
  • The right not to receive discriminatory treatment for exercising any of these rights

Financial information we collect and use specifically to provide the Service is generally information governed by GLBA rather than these state consumer privacy laws, but we still honor the spirit of these rights and will respond to any request as described in Section 11.

11

How to exercise your rights

To make a request, email support@drafsense.com. We may need to verify your identity, or the merchant's authority to act on a payer's behalf, before completing certain requests. We aim to respond within the timeframe required by applicable law, generally within 45 days.

12

Children's privacy

Drafsense is a business tool. It is not directed at, and we do not knowingly collect personal information from, anyone under 18.

13

Automated decision-making

Drafsense's routing number verification and authorization checks are rules-based system functions, not automated decision-making that produces legal or similarly significant effects about an individual. We do not use profiling to make decisions about payers.

14

Signature and authorization data

The signature image, typed name, and initials captured during authorization are used solely to document consent for a specific transaction. This information is not used for biometric identification purposes and is not treated, stored, or matched as a biometric identifier.

15

International use

Drafsense is intended for use by U.S.-based businesses with U.S. bank accounts. This policy and our practices are designed around U.S. law; we do not currently direct the Service at, or knowingly process information originating from, individuals outside the United States.

16

Changes to this policy

We may update this policy as Drafsense evolves. The "Last updated" date above always reflects the current version. Material changes will be communicated to account holders directly, not just posted quietly.

17

Contact us

Questions or requests related to this Privacy Policy can be directed to support@drafsense.com.