As a leading provider of payment management and risk management services to hundreds of thousands of
online businesses around the world, privacy and data protection are of the utmost importance to Coastal Software
Corporation and its subsidiaries. This Privacy Statement for Coastal Software ("Privacy Statement") details the
company's policies with respect to the handling of personally identifiable information ("Information") submitted
or in the course of providing services to Coastal Software's customers. Coastal Software will use and disclose
Information only in accordance with the terms of this Privacy Statement.
A. COLLECTION OF INFORMATION
The type of Information submitted to or collected by Coastal Software varies depending upon the
nature of the activity and relationship with Coastal Software.
- Browsing the Website: When You browse the company's website, Coastal Software may collect information
regarding the domain and host from which You access the Internet, the Internet Protocol address of the computer
or Internet Service Provider You are using, and anonymous site statistical data. Information collected while
You're browsing our website may be used to analyze trends, administer the website, improve site performance,
gather broad demographic information, and for security purposes.
- Inquiries: The website contains various forms, links to company e-mail addresses, and fax numbers that You may
use to solicit information about the website, Coastal Software services, and the company in general. When You
complete and submit a form, send us an e-mail, send us a fax, or contact us by telephone, Coastal Software may
store the inquiries and their contents, including any personally identifiable information You may have provided.
Any personally identifiable information You submit via an inquiry is collected only with Your knowledge and
- Use of Gateway Services: When You register to use Coastal Software online processing services ("Gateway
Services"), You will be required to provide personally identifiable information and to enter into a written
agreement with Coastal Software. If You ordered any products or services from businesses that use our Gateway
Services ("Coastal Software Customers"), You were required to submit personally identifiable information ("Order
Information"). Coastal Software Customers transmit Order Information to Coastal Software for the purpose of
processing Orders. Order Information is maintained in servers located within the U.S.A. and may also be
maintained in servers located in Europe or Asia, depending on where the order originates or the geographic
location of a Coastal Software Customer. Coastal Software may maintain Order Information for a certain period of
time to comply with audits or for disaster recovery purposes.
- Applying for a Merchant Account: When You submit an application to obtain a merchant account through Coastal
Software, You will be required to provide personally identifiable information. Furthermore, Coastal Software may
also obtain information about You from third party sources, including, without limitation, consumer reporting
B. USE AND DISCLOSURE OF INFORMATION
- Usage and disclosure of Your Information varies based on Your relationship with Coastal Software. Coastal
Software never sells any personally identifiable information and, except as expressly set forth below, never
discloses personally identifiable information to any third parties.
- Browsing the Website: Information collected while You're browsing our website may be used to analyze trends,
administer the website, improve site performance, gather broad demographic information, and for security
purposes. Such Information may be disclosed to third parties to provide any of the aforementioned activities on
behalf of Coastal Software.
- Inquiries: Information collected during the course of You submitting an inquiry via online form, e-mail, fax,
or telephone call may be used by Coastal Software to respond to Your inquiries or to contact You to inform You
of services of Coastal Software that may be of use to You. Information collected during the course of an inquiry
will not be disclosed to any third party unless such third party has been contracted by Coastal Software, with
obligations of confidentiality, to contact You on our behalf.
- Use of Coastal Software Services: If You are a Coastal Software Customer, Coastal Software will use Your
Information during the course of providing You with the Gateway Services. During the course of providing such
services, Coastal Software may disclose Your Information to third parties that have contracted with Coastal
Software to perform certain functions of the Gateway Services on our behalf ("Subcontractors"). Coastal Software
may also use Your Information to contact You about other Coastal Software offerings and to inform You about
general company news and industry trends, directly or through the use of third party vendors. Coastal Software
may also use Your Information for internal business analyses. If You are a customer of a Coastal Software
Customer, Coastal Software will use Order Information during the course of providing processing services to such
Coastal Software Customer. Coastal Software may also use Order Information at an aggregate level for internal
business analyses and fraud prevention. During the course of providing Gateway Services to Coastal Software
Customers, Coastal Software may disclose Order Information to banks, processors, card associations, and other
financial institutions that are involved in the course of processing or screening the transaction applicable to
the Order Information.
- Applying for a Merchant Account: If You apply for a merchant account from or through Coastal Software, Coastal
Software may use and disclose the Information to evaluate Your eligibility for a merchant account, including
disclosure to consumer reporting agencies, relevant financial institutions, and other entities involved in
providing the merchant account services. Coastal Software may also use and disclose Your Information during the
course of providing or procuring on Your behalf the merchant account services. Coastal Software may also use
Your Information to contact You, directly or through a third party vendor, about other Coastal Software
offerings and to inform You about general company news and industry trends. Coastal Software may also use Your
Information for internal business analyses.
- Surveys and Questionnaires: If You submitted an inquiry to Coastal Software or if You are a Coastal Software
Customer, periodically, Coastal Software may use Your Information to contact You, directly or through a third
party vendor, to complete a survey or questionnaire. Responses to any such survey or questionnaire may be used
for internal business analyses and may be disclosed in aggregate form without disclosing any personally
computer and allow Coastal Software to recognize You as a Coastal Software Customer or a previous visitor of our
services throughout the website.
- Confidentiality Obligations: All contracts entered into between Coastal Software and Coastal Software
Customers, Coastal Software and Subcontractors, and Coastal Software and other third party service providers
contain express provisions governing the confidential treatment of any and all personally identifiable
- Investigations and Proceedings: Coastal Software may use Information to conduct internal investigations.
Coastal Software may disclose Information to cooperate with an investigation by law enforcement agencies or
other governmental authorities and may also disclose Information in response to a subpoena, warrant, court
order, or other comparable legal processes.
C. INFORMATION SECURITY
Coastal Software is committed to privacy and security. Coastal Software is compliant with the
Payment Card Industry Data Security Standard ("PCI DSS") as a Level 2 service provider. Coastal Software has been
compliant with PCI DSS since its inception in 2002. PCI DSS is the bankcard industry's most stringent security
standard. Examples of Coastal Software's security measures include: physical, electronic, and procedural
safeguards; sophisticated security monitoring tools; documented security policies; use of strong encryption for
transmissions of Order Information to and from Coastal Software Customers; restricted access of personally
identifiable information; and, periodic security audits by third party security experts.
D. CORRECTION AND DELETION OF INFORMATION
If You want Coastal Software to correct or delete Your Information that is stored on Coastal
Software systems, please submit Your request in writing to:
Coastal Software & Consulting, Inc.
PO Box 872106 Vancouver, WA 98687-2106
Fax: (360) 891.6174
Subject to our ability to verify Your request and provided that Coastal Software is not required to
maintain the Information by applicable laws, regulations, or contractual obligations, Coastal Software will
correct or delete the Information within thirty (30) days of receipt of Your request.