Privacy Policy for Ascend POS

Effective Date: March 2026

This “Privacy Policy” explains how AscendFS, Inc. (“Company” or “we”) collects, uses, discloses, and otherwise processes personal data (“personal data” or “Personal Information”) on behalf of our customers – typically, merchants (any, a “Merchant”) – in connection with our application, Ascend POS, which runs on the Clover Point of Sale system (“Clover POS”). This Privacy Policy does not apply to Company’s privacy practices in any other context, and only applies to information collected by our application on the Clover POS.

This Privacy Policy is intended to comply with the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and other applicable Canadian privacy laws, and also addresses relevant privacy obligations in other jurisdictions where AscendFS operates.

Company’s processing of personal data in connection with our application is governed by this Privacy Policy and our agreements with Merchants. In the event of any conflict between this Privacy Policy and a customer agreement, the customer agreement will control to the extent permitted by applicable law.

This Privacy Policy is not a substitute for any privacy policy that a Merchant may be required to provide to their customers, personnel, or other individuals.

Information We Collect



We may collect personal data from or on behalf of Merchants. Merchants determine the scope ofthe personal data transferred to us or that we collect, and the information we receive may vary byMerchant. Typically, the information we collect on behalf of Merchants includes:

Information collected when a customer makes a payment

When a customer makes a payment via a Clover POS, we collect information about the transaction,which may include personal data. Information about transactions includes the payment card used,name associated with the payment card, the location of the merchant’s store, date and time of thetransaction, transaction amount, and information about the goods or services purchased in thetransaction (including raffle tickets or sweepstakes entries). Ascend does not collect payment cardnumbers. This information is processed directly by the Merchant’s payment processor

Additional information provided through the Clover POS

We may collect additional information on behalf of the Merchant ancillary to the payment. This information may include:

  • Customers’ email address or phone number, such as when the customer chooses to receive an electronic receipt
  • Customers’ marketing preferences, such as whether the customer wishes to receive marketing communications or newsletters
  • Customers’ physical address, if required by the Merchant

How We Use the Information We Collect



We use the personal data we collect for or on behalf of Merchants to provide our services and the functionality of Ascend POS, including processing payments for raffle tickets or sweepstakes entries.

We may also use personal data for related internal purposes, including:

  • To measure performance of and improve the application
  • To respond to inquiries, complaints, and requests for customer support
  • To send campaign-related communications on behalf of a Merchant if requested (e.g., digital tickets, confirmations, donation receipts, or winner notifications) in accordance with Canada’s Anti-Spam Legislation (“CASL”). We only send marketing emails on behalf of a Merchant with proper consent or where a permitted relationship exists under CASL (e.g., existing business relationship or inquiry). Users can unsubscribe at any time by using the opt-out instructions in any message or by contacting us directly.

In addition, Company may use personal data as we believe necessary or appropriate to (a) comply with applicable laws and lawful requests and legal processes, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern our application; (c) protect our rights, privacy, safety or property, and/or that of you or others; and (d) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

How We Share Information



We may share personal data that we collect with:

  • The Merchant from whom or on whose behalf we collected the personal data
  • The platform on which our application runs, the Clover POS. You may view Clover’s Privacy Notice at https://www.clover.com/privacy-policy
  • With third parties as a Merchant may direct
  • With third-party service providers that help us manage and improve the application
  • With Company subsidiaries and corporate affiliates for the purposes described in this Privacy Policy or in our agreement with a Merchant


Company may disclose personal data to government or law enforcement officials or private parties as required by law, and disclose and use such information as we believe necessary or appropriate to (a) comply with applicable laws and lawful requests and legal processes, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern our application; (c) protect our rights, privacy, safety or property, and/or that of you or others; and (d) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

Company may sell or transfer some or all of its business or assets, including your personal data, in connection with a business transaction (or potential business transaction) such as a merger, consolidation, acquisition, reorganization or sale of assets or in the event of bankruptcy, in which case we will make reasonable efforts to require the recipient to honor this Privacy Policy.

Data Retention



Except as otherwise permitted or required by applicable law or regulation, we will only retain your Personal Information for as long as necessary to provide our services and fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements, or until a Merchant requests deletion. Please note that we may be required in certain circumstances to retain your Personal Information indefinitely (for example, in order to comply with our policies and procedures in connection with self-exclusion).

Under some circumstances, we may anonymize your Personal Information so that it can no longer be associated with or identify you. We reserve the right to use such anonymous and de-identified data for any legitimate business purpose, including without limitation business intelligence and research, without further notice to you or your consent. We do not attempt to re-identify anonymized or de-identified information and do not sell such data to third parties.

Security of Personal Information



The security of your Personal Information is very important to us. We use layered controls across encryption, identity and access management, monitoring, and resilience, all designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. Our safeguards include:

  • Personal Information is stored in secure cloud-hosted infrastructure (AWS).
  • We perform background checks before onboarding employees into roles with access to Personal Information or critical systems.
  • We employ comprehensive end-to-end encryption with multiple security layers within our AWS environment, including TLS 1.2+ with AES-256-GCM cipher suites for data in transit, AES-256 encryption for data at rest, and AWS KMS with FIPS 140-3 Level 3 certified HSM for key management..
  • We enforces role-based access control and least privilege for access to the Personal Information with our platform, with multi-factor authentication required for all internal roles.
  • We capture and retain activity logs across our cloud infrastructure environment, with logs retained for a minimum of 12 months. Network flow and DNS activity are continuously analyzed by automated threat detection tooling, which generates real-time alerts for potential security events. Alerts are triaged by security staff, who also conduct scheduled reviews of privileged access logs no less than monthly.

While we implement strong security measures to protect your Personal Information, no system is completely secure. Transmission over the Internet is not entirely secure, and any transmission of Personal Information is done at your own risk. However, if a data breach occurs that presents a significant risk of harm, AscendFS will notify affected users in accordance with applicable laws.

Your Rights and Choices  



Data Subject Rights

To the extent that applicable law provides individuals with rights pertaining to their personal information, individuals should first contact the Merchant with any requests, as the Merchant is the controller of personal data that we process on its behalf. Where we are responsible for responding to data subject rights requests under applicable law, individuals may contact us using the contact information provided below. We will assist a Merchant, or Clover, as applicable, in responding to such requests subject to our contract with a Merchant or Clover.

Subject to applicable law, and with the understanding that requests relating to Merchant-controlled data should be directed to the Merchant first, individuals may have the following rights:

  • Access: You may request a copy of the Personal Information we hold about you.
  • Correction: You may request that we correct inaccurate or incomplete Personal Information about you.
  • Deletion: You may request that we delete your Personal Information, subject to certain legal exceptions.
  • Data Portability: You may request that we provide your Personal Information in a structured, commonly used, and machine-readable format.
  • Opt-out of sale or sharing: You have the right to opt out of the sale or sharing of your personal information, including for purposes of targeted advertising. You may exercise this right by contacting our Privacy Officer using the contact information below.
  • Right to Appeal: If we deny a rights request, you may have the right to appeal our decision. Please contact our Privacy Officer for information about our appeal process.
  • Withdrawal of Consent: Where you have provided consent to the collection, use, and disclosure of your Personal Information, you have the right to withdraw your consent at any time by contacting our Privacy Officer. Please note that withdrawal of consent may affect your ability to use certain features or services. We will explain the impact to you at the time to help you with your decision.

To protect your privacy and security, we may require you to verify your identity before processing any requests.

Complaints

If you have a complaint about our handling of personal data, you may contact us via the contact information provided below. If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada or the Information and Privacy Commissioner of Ontario, as applicable.

Updates



We reserve the right to modify this Privacy Policy at any time. We will notify you of updates by updating the date of this Privacy Policy. We will notify you in advance of any material changes to this Policy and, where required, obtain your consent to any new ways that we collect, use, disclose, and store your Personal Information.

Contact Us



You may contact us with any questions, comments, or complaints about this Privacy Policy or our privacy practices:

If you are located in Canada:

Privacy Officer

AscendFS, Inc.

1 Adelaide Street E, Suite 2410

Toronto, ON  M5C 2V9

Email: privacy@ascendfs.com

If you are located in the United States:

Privacy Officer

AscendFS Delaware, Inc.

4235 Hillsboro Pike, Suite 247

Nashville, TN  37215

Email: privacy@ascendfs.com

U.S. State Privacy Rights



If you reside in certain U.S. states, including but not limited to California, Colorado, Connecticut, Utah, and Virginia, you may have specific privacy rights under applicable state privacy laws (collectively, the “State Privacy Laws”). This section supplements the information contained elsewhere in this Privacy Policy and applies only to information collected when a customer of a Merchant makes a payment via a Clover POS.

Your State Privacy Rights

Depending on your state of residence, you may have the right to:

  • Access the personal information we have collected about you
  • Correct inaccurate personal information
  • Delete personal information, subject to certain exceptions
  • Opt out of targeted advertising, sales, or profiling
  • Port your data in a structured, machine-readable format
  • Appeal a decision we make about your privacy request

These rights are not absolute, and we may decline your request as permitted by applicable law.  

As noted above, because the personal information we process through Ascend POS is collected on behalf of Merchants, individuals should first contact the relevant Merchant with any rights requests. We will assist Merchants in responding to such requests as required.

How to Exercise Your Rights

You may exercise your State Privacy rights by contacting the Merchants and/or our Privacy Officer using the contact information provided above. We may need to verify your identity before processing your request. If we deny your request, you may have the right to appeal our decision.

California residents may designate an authorized agent to make a request on their behalf. We may require the agent to submit proof of authorization and may also ask you to verify your identity directly.

Opt-Out of Sale or Sharing of Personal Information

We do not sell your Personal Information. In the preceding twelve (12) months, we have not sold any personal information. However, to the extent any disclosure of personal information through our services could be considered a “sale” or “sharing” under applicable State Privacy Laws, you have the right to opt out. You may exercise this right by contacting our Privacy Officer using the contact details provided above.

Personal Information We Collect, Use, and Share

The chart below summarizes our collection, use, and sharing of Personal Information during the last 12 months before the effective date of this Privacy Policy.

Category (see Glossary below for definitions) Do we collect this information? Do we share this information for business purposes?
Identifiers Yes Yes
Commercial Information Yes Yes
Online Identifiers No No
Protected Classification Characteristics No No
Biometric Information No No
Internet or Network Information No No
Geolocation Data No No
Sensory Information No No
Professional or Employment Information No No
Education Information No No
Inferences No No
Financial Information No No
Medical Information No No

Glossary
Category Definition Data Elements
Biometric Information An individual's physiological, biological or behavioral characteristics, including DNA, that can be used to establish an individual's identity (e.g., imagery of the iris, retina, fingerprint, face, voice recordings, keystroke patterns). Transaction History
Commercial Information Records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies, including records of raffle ticket or sweepstakes entries. Transaction / Purchase History
Financial Information Bank account number, debit or credit card numbers, insurance policy number, and other financial information. Financial Information
Geolocation Data Precise location, e.g., derived from GPS coordinates or telemetry data. Geolocation Data
Identifiers Real name, alias, postal address, unique personal identifier, customer number, email address, account name, and other similar identifiers. Identifiers / Gov-issued ID
Medical Information Personal information about an individual's health or healthcare, including health insurance information. Medical Information
Internet or Network Information Browsing history, search history, and information regarding a consumer's interaction with an Internet website, application, or advertisement. Online / Internet
Online Identifiers Device identifiers, IP addresses, cookies, mobile ad identifiers, or similar persistent identifiers used to recognize a person or device. Online Identifiers
Professional or Employment Information Information relating to a person's current, past or prospective employment or professional experience (e.g., job history, performance evaluations) and educational background. Professional Info
Protected Classification Characteristics Age (40+), race, color, ancestry, national origin, citizenship, religion, marital status, disability, sex, sexual orientation, veteran status, genetic information. Protected Classes
Sensory Information Audio, electronic, visual, thermal, olfactory, or similar information. Sensory Info

Get it done with Ascend