Skip to content

Legal

Privacy and Data Protection Policy

Our practices for collecting, using, securing, and disclosing business and financial data processed in connection with our services.

1. Overview & Scope

ACH Payment Solutions ("Company," "we," "us," or "our"), provides services of bookkeeping, payments management, and reconciliation of payables and receivables to businesses. This Privacy and Data Protection Policy describes our practices for collecting, using, securing, and disclosing business and financial data processed in connection with payment management services.

Our operations are strictly business-to-business (B2B); we do not collect, process, or solicit consumer personal information.

2. Information We Collect

To onboard a client, establish originator files, perform account verifications, and/or assist in processing scheduled ACH transfers under NACHA Operating Rules, we collect commercial entity and guarantor information provided via contracts and ACH authorization forms. This includes commercial entity identifiers (legal business name, DBA name, Federal Employer Identification Number (EIN), physical address, business telephone number, and official contact email address), banking and settlement data (financial institution name, ABA routing number, depository account number, and bank verification credentials or statements required to confirm account ownership), technical data (IP addresses, transaction timestamps, and device identifiers generated during file submission), and guarantor and signer details (authorized signer names, business titles, dates of birth, and contact details).

Because our services are strictly business-to-business (B2B), consumer data subject rights under state consumer privacy statutes (such as the California Consumer Privacy Act) and the Gramm-Leach-Bliley Act (GLBA) Financial Privacy Rule do not apply to transaction data or business account information processed through our systems.

3. Use and Disclosure of Information

We use collected business and financial data strictly to generate, process, and reconcile accounts payable, receivables, and authorized ACH debit and credit transactions pursuant to underlying financing agreements, transmit originator files, authorizations, and supporting records to clients’ counterparties, funders, Originating Depository Financial Institution (ODFI), banking partners and fulfill regulatory compliance obligations under applicable federal and state laws, NACHA Operating Rules, Anti-Money Laundering (AML) standards, and Gramm-Leach-Bliley Act (GLBA) guidelines.

No Sale of Data: We do not sell, rent, trade, or share commercial or financial data with third parties for marketing or promotional purposes. Information is disclosed strictly on a need-to-know basis to contracting funders, Originating Depository Financial Institutions (ODFIs), Receiving Depository Financial Institutions (RDFIs), and ACH Operators (FedACH/EPN) to complete transaction settlement, and regulatory or NACHA auditors conducting compliance reviews.

4. Data Security

We enforce physical, administrative, and technical safeguards to protect routing numbers, account numbers, and banking credentials. System access is restricted strictly to authorized personnel. When required by applicable law and/or NACHA guidelines, account and routing numbers are protected against unauthorized disclosure including by using encryption.

5. Mandatory Data Retention

Federal regulations and Nacha Operating Rules require us to retain transaction logs, file transmissions, return notices, and authorization proofs for a minimum of six (6) years. Requests to delete data prior to the expiration of mandatory legal retention periods will be denied as permitted by applicable law.

6. Incident Response

We maintain internal protocols to promptly investigate, mitigate, and report any actual or suspected breach involving sensitive banking data to our banking partners and affected funders as required by banking agreements and applicable law.

7. Limitation of Liability & User Responsibilities

The Client is solely responsible for maintaining the confidentiality of its login credentials and securing its internal systems. We are not liable for unauthorized transactions arising from compromised Client credentials. While we secure our systems, we are not responsible for security breaches, outages, or delays occurring within ODFI networks, ACH Operators, or third-party telecommunication channels beyond our direct control.

8. Contact Information

For inquiries, concerns, or audit requests regarding this policy, contact our compliance team at:

300 Creek View Road Suite 209, Newark, 19711
Email: accounting@bookkeepershq.com