Skip to content

1. About This Policy

In this Privacy Policy ("Policy"), Gotransverse LLC ("Gotransverse," "we," "us," or "our") describes how we collect, use, disclose, transfer, and protect Personal Information.

Gotransverse acts in two distinct roles with respect to Personal Information, and this Policy is organized accordingly:

As a controller. When we collect information directly from visitors to our publicly accessible websites, from prospective customers, and from individuals who contact us or subscribe to our communications, Gotransverse determines the purposes and means of that processing. Part A of this Policy governs that information.

As a processor. When we process Personal Information on behalf of our customers through the Gotransverse billing platform, our customer determines the purposes and means of that processing, and we act on that customer's documented instructions. Part B of this Policy describes that role. The specific terms governing such processing are set out in the data processing agreement between Gotransverse and the relevant customer, which controls in the event of any conflict with this Policy.

If you are a customer, subscriber, or end user of a company that uses the Gotransverse platform, that company — not Gotransverse — is responsible for your Personal Information, and you should direct any request or complaint to that company in the first instance. We will refer such requests to the relevant customer and assist that customer in responding.

2. Definitions

"Account" means a unique account created for you to access our Service or parts of our Service.

"Controller" means the entity that, alone or jointly with others, determines the purposes and means of the processing of Personal Information. In relation to the Gotransverse platform, the controller is generally the Gotransverse customer.

"Processor" means an entity that processes Personal Information on behalf of a controller, pursuant to a written agreement that requires it to retain, use, and disclose that information only for the purpose of providing the agreed services.

"Sub-processor" means a third party engaged by Gotransverse to process Personal Information on behalf of a Gotransverse customer.

"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. "UK GDPR" means that regulation as retained in United Kingdom law, read with the Data Protection Act 2018.

"Personal Information," "Personal Data," or "Information" means any information relating to an identified or identifiable natural person.

"Sensitive Personal Information" means Personal Information revealing racial or ethnic origin, sexual orientation, political opinions, religious or philosophical beliefs, or trade union membership, or concerning an individual's health.

3. Information We Collect

We may collect the following categories of Personal Information from website visitors, prospective customers, and individuals who contact us:

  • Name
  • Business email address
  • Business postal address
  • Telephone number
  • Company name and job title
  • Business information such as industry, organization size, and stated requirements
  • Information you provide in forms, surveys, support requests, or correspondence
  • Technical information such as IP address, browser type, and pages viewed, collected through cookies and similar technologies
  • Responding to inquiries and providing customer and technical support
  • Internal record keeping and business administration
  • Improving our products, services, and websites
  • Sending marketing communications about products, services, and events, where permitted and subject to your right to opt out at any time
  • Conducting market research and analytics
  • Establishing, exercising, or defending legal claims, and complying with legal obligations
  • Performance of a contract, or steps taken at your request prior to entering into a contract
  • Our legitimate interests in operating, promoting, securing, and improving our business, where those interests are not overridden by your rights and freedoms
  • Compliance with a legal obligation to which Gotransverse is subject
  • Your consent, where required — for example for certain marketing communications or non-essential cookies. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal
  • Protection of the vital interests of you or another natural person
  • To understand how visitors reach and use our website, and to identify improvements
  • To make advertising more effective — for example, to limit repeat impressions or measure how often an advertisement is viewed
  • We use Google Analytics, which uses cookies and similar technologies to collect and analyze information about use of our website and to report on activity and trends. Google's practices are described on the Google website
  • The Gotransverse platform uses cookies to maintain session state and authenticate user accounts. These cookies are used only by the platform and are not combined with cookies used on our marketing website
  • Request access to the Personal Information we hold about you, and receive a copy of it
  • Request correction of Personal Information that is inaccurate or incomplete
  • Request erasure of Personal Information where there is no continuing lawful basis for us to process it
  • Object to processing carried out on the basis of our legitimate interests, and to object at any time to processing for direct marketing purposes
  • Request restriction of processing in certain circumstances
  • Request transfer of your Personal Information to you or to a third party in a structured, commonly used, machine-readable format
  • Withdraw consent at any time where processing is based on consent

4. How We Use This Information

Information collected through our websites is used to understand your needs and to provide and improve our services, and in particular for the following purposes:

We do not sell Personal Information, and we do not share your email address with third parties for their own marketing purposes.

5. Legal Bases for Processing (EEA, UK, and Switzerland)

Where the GDPR or UK GDPR applies to our processing as a controller, we rely on one or more of the following legal bases:

We will gladly clarify the specific legal basis that applies to a particular processing activity on request.

6. Cookies and Similar Technologies

Cookies are small text files stored in a web browser. They help website operators understand how a site is used, remember preferences, and keep sessions secure. We generally use cookies for the following purposes:

Your browser should allow you to change your cookie preferences, including deleting and disabling Gotransverse cookies. Please consult the help section of your browser. If you disable cookies, some features of our website or services may not operate as intended. Browser guidance is available for Chrome, Microsoft Edge, Safari, Firefox, Opera, and Brave.

7. Forms and Marketing Communications

By submitting a form on the gotransverse.com domain, you agree to this Policy and acknowledge that you may receive relevant marketing communications from us. We do not share or sell your data or email address with third-party services.

You may opt out of marketing emails at any time at https://gotransverse.com/unsubscribe, or by using the unsubscribe link in any marketing message. You may also request a copy of the information we hold about you, or ask to be removed from our marketing database, by contacting us using the details in Section 20.

8. Links to Other Websites

Our websites may contain links to other websites. Once you follow a link away from our site, we have no control over that website and cannot be responsible for the protection or privacy of any information you provide there. Such sites are not governed by this Policy. We encourage you to review the privacy statement of any website you visit.

Part B — The Gotransverse Platform

This Part applies where Gotransverse acts as a processor on behalf of its customers.

9. Our Role

The Gotransverse platform collects and processes Personal Information under the direction of our customer. Gotransverse has no direct relationship with the individuals whose Personal Information it processes on a customer's behalf. Our processing is governed by the agreement and data processing agreement in place with that customer.

Personal Information processed through the platform may include name, postal address, email address, telephone number, company name, account and subscription details, usage and consumption data, invoicing and payment records, and related billing information.

The platform also processes cardholder data on behalf of our customers. Gotransverse stores cardholder name, primary account number, and card expiration date within its hosted environment, encrypted at rest using AES-256. Sensitive authentication data is held in memory only until authorization is obtained and is then purged; it is not stored. Full primary account numbers are never displayed: reports and screens show only the last four digits, or the first six and last four digits. Cardholder data is retained only for as long as the associated account remains active.

Gotransverse is not a party to the settlement process. Our customers contract directly with their chosen payment processor, and clearing and settlement, together with fraud and chargeback handling, are performed by those processors rather than by Gotransverse.

10. How Information Is Received

Information is transmitted to the Gotransverse platform by the customer through an encrypted, key-protected API, or entered manually by the customer through our secure user interface.

11. How We Use Platform Information

Information received through the Gotransverse platform is used only to provide the functions and services the customer has subscribed to, and as otherwise instructed by the customer in writing. We do not use platform Personal Information for our own marketing purposes, and we do not sell it.

12. Sub-processors

We engage a limited number of third-party service providers that access, process, or store Personal Information in the course of providing the platform to our customers. We maintain written contracts with these providers restricting their access, use, and disclosure of Personal Information in accordance with applicable data protection law and our commitments to our customers, and we require them to provide at least the level of protection we are required to provide.

Our sub-processors are Amazon Web Services (cloud hosting of the platform), and Snowflake (cloud data warehousing supporting reporting and data extracts). Where a customer’s data is designated to the European Union, the infrastructure of each of these services that holds or receives that data is located within the same European Union region as the platform itself.

Certain other systems we rely on internally — including single sign-on and multi-factor authentication for our own personnel, our credential vault, and endpoint protection on company laptops — do not contain, process, or have access to customer Personal Information.

Payment processors used in connection with the platform — including Adyen, Stripe, Braintree, CardConnect, Chase Payment Solutions, CyberSource, and First Data Merchant Services — are engaged under agreements between our customer and that processor directly. They are not Gotransverse sub-processors, and our customers determine which processor they use.

We annually obtain and review independent audit reports from our sub-processors covering their change management, logical security, physical security, environmental safeguards, and backup and recovery controls. Where we intend to add or replace a sub-processor that will process customer Personal Information, we notify affected customers in advance.

13. Retention and Deletion

Customer data is destroyed 60 days after the end of the contractual relationship with the customer, unless a longer period is required by law or agreed in writing. Where no request is made to remove individual Personal Information, Gotransverse retains and processes it on behalf of the customer for as long as necessary to provide the services. We retain and protect Personal Information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Because of the architecture of the Gotransverse billing platform, deleting an account outright would render associated records, statements, invoices, and ledgers inaccurate. An account is therefore treated as removed when the individual is no longer identifiable within the system: changing the identifying fields — first and last name, home address, billing address, telephone number, and email address — renders the individual's identity obsolete across historical and future transactions.

14. Requests From Individuals

If you are an end user of one of our customers and wish to access, correct, or delete your Personal Information, or no longer wish to be contacted by that customer, please contact that customer directly. Where an individual contacts Gotransverse directly, we will refer the request to the relevant customer and assist that customer in responding, as required by our agreement with them.

Where a customer asks us to remove Personal Information, the customer may either make the change through the platform user interface or submit a request to Gotransverse to update the relevant billing account.

Part C — Provisions Applicable to Both Roles

15. Data Location and International Transfers

Where data is stored. Personal Information processed through the Gotransverse platform is hosted in the Amazon Web Services region designated in the applicable customer agreement. The regions we operate are Frankfurt, Germany (eu-central-1); Sydney, Australia (ap-southeast-2); Northern Virginia, United States (us-east-1); and Oregon, United States (us-west-1). Each is a dedicated virtual private cloud, and data is replicated for high availability only to separate availability zones within the same region. Backup storage is region-locked to the region in which the data resides.

European Union data. For customers whose data is designated to the European Union, that data is collected, stored, and processed in the Frankfurt region. The supporting services that receive data from that environment — data warehousing, centralized logging, and security monitoring — are likewise located within the European Union. Personal Information designated to the European Union is not stored, replicated, or backed up outside the European Union.

Environments are segregated. Each regional production environment is logically segregated from every other regional environment and from all non-production environments. As a PCI DSS service provider, Gotransverse tests the effectiveness of this segmentation twice each year, confirming that production environments cannot connect to one another or to non-production environments. These tests have passed in each assessment period.

Access from the United States. Gotransverse is headquartered in Austin, Texas. Authorized Gotransverse operations personnel located in the United States access the hosted environment remotely in order to administer, support, maintain, and monitor the platform. Each customer tenant is separated by its own identifier within the database layer. Personnel performing maintenance may view records through database utilities, but cannot extract or export Personal Information from the hosted environment. Under the GDPR and UK GDPR, remote access to personal data from outside the European Economic Area constitutes a transfer, even where the data itself remains stored within the region and is never exported from it. We describe this openly so that our customers can assess it accurately.

The safeguards that apply to that access. Where personnel in the United States access Personal Information originating in the European Economic Area, the United Kingdom, or Switzerland, that access is governed by the data processing agreement in place with the relevant customer, which sets out the contractual safeguards applicable to the transfer and the technical and organizational security measures Gotransverse is required to maintain. Those measures include network segmentation, access via a virtual private network requiring two-factor authentication followed by directory authentication, individual role-based accounts limited to business need, restriction of administrative access to a limited number of operations personnel, encryption of data at rest and in transit, masking of full primary account numbers, controls preventing extraction or export of Personal Information from the hosted environment, and aggregation and review of administrator activity logs.

16. Data Security

Gotransverse employs preventive, detective, and corrective technologies and processes to safeguard Personal Information. These safeguards are designed to prevent unauthorized access, maintain confidentiality, and ensure appropriate use of data.

Access to the platform and its supporting servers and databases requires individual role-based accounts. Administrative access is available only through a virtual private network requiring two-factor authentication, followed by additional directory-based authentication, and is limited to a defined group of operations personnel. Access privileges are governed by a pre-approved access matrix reviewed annually, reviewed semi-annually against actual access, and removed within three business days of an individual leaving the company.

Personal Information is encrypted at rest and encrypted in transit. Encryption keys are managed under a layered key hierarchy, with key-encrypting and data-encrypting keys held on separate systems and passphrases protected on hardware meeting FIPS 140-2 Security Level 3. Shared credentials and keys are held in an encrypted credential management system or secrets vault with access restricted to designated operations personnel.

The environment is segmented into separate network layers with default-deny network security controls, a web application firewall, intrusion detection with alerting, file integrity monitoring, anti-malware protection, centralized log aggregation covering both operational and administrator activity, and quarterly vulnerability scanning performed by third-party vendors. Databases are backed up daily, backups are encrypted, and restoration is tested annually.

Data protection is built into our system engineering as well as our practices and procedures, rather than added afterwards. Protection follows data through its lifecycle — collection, processing, storage, and backup.

17. Independent Assessment and Compliance

PCI DSS. Gotransverse is a Level 1 Service Provider under the Payment Card Industry Data Security Standard. The Gotransverse Billing Platform (TRACT Core Application) was assessed against PCI DSS version 4.0.1 by Armanino Advisory LLC, a Qualified Security Assessor. The assessment was a full assessment covering all requirements, concluded on March 26, 2025, and resulted in a Compliant rating. The scope covers internet and e-commerce payment processing for the platform. Clearing and settlement, and fraud and chargeback services, are outside the scope of our assessment and are provided by separately validated PCI DSS compliant service organizations.

SOC 2 Type 2. Armanino LLP has examined Gotransverse’s controls relevant to the Security, Confidentiality, and Privacy trust services categories for the period October 1, 2024 through September 30, 2025, and issued its report on December 11, 2025. The auditor’s opinion is that the controls were suitably designed and operated effectively throughout that period, and no exceptions were noted in the testing of controls.

SOC 1 Type 2. Gotransverse also maintains a SOC 1 Type 2 report addressing controls relevant to our customers’ financial reporting, including controls over the complete and accurate calculation of customer sales invoices and related journal entry transactions.

Copies of the current PCI DSS Attestation of Compliance, SOC 2 Type 2 report, and SOC 1 Type 2 report are available to customers and prospective customers under a non-disclosure agreement.

We review this Policy and our related practices periodically to verify that the Policy is accurate, comprehensive for the information it is intended to cover, prominently displayed, fully implemented, and accessible.

18. Data Accuracy and Integrity

We process Personal Information only in ways compatible with, and relevant to, the purposes for which it was collected or authorized by our customers. To the extent necessary for those purposes, we take measures to ensure that Personal Information is accurate, complete, current, and reliable for its intended use, and the platform is configured to calculate invoices and related accounting entries completely and accurately.

Customers and authenticated users can access, update, and confirm their data through the platform. See Section 20 for how to request a correction.

19. Your Privacy Rights

Subject to applicable law and to our role in relation to the Personal Information concerned, you may have the right to:

There is no charge for exercising these rights. We may ask you to verify your identity before responding, and we will respond within the period required by applicable law.

Where Gotransverse acts as a processor, an individual seeking to access, correct, amend, or delete Personal Information should direct the request to the relevant controller — that is, the Gotransverse customer.

20. Complaints and Contact

Gotransverse is committed to resolving complaints about our collection or use of Personal Information. If you have a question, request, or complaint, please contact us:

Email: privacy@gotransverse.com

Post: Gotransverse, 816 Congress Ave, Suite 1530, Austin, TX 78701, Attn: Data Privacy

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to lodge a complaint with your local supervisory authority — in the United Kingdom, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner; and in the EEA, the data protection authority of your country of residence, place of work, or the place of the alleged infringement.

21. Disclosure Required by Law and Business Transfers

Gotransverse may use or disclose Personal Information where required by law, or where we reasonably believe that use or disclosure is necessary to protect our rights or to comply with a judicial proceeding, court order, or legal process.

If Gotransverse is involved in a merger, acquisition, or sale of assets, Personal Information may be transferred. We will provide notice before any Personal Information is transferred and becomes subject to a different privacy policy.

Gotransverse will not use or share Personal Information in ways unrelated to those described in this Policy without providing an opportunity to opt out or otherwise prohibit such use. Gotransverse does not sell Personal Information.

22. Reporting Security Incidents

If you have a security concern, or a privacy or data use concern that we have not addressed to your satisfaction, please report it to compliance@gotransverse.com and we will respond promptly.

23. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy on this page and update the Effective Date above. Where changes are material, we will provide notice by email or by a prominent notice on our services before the change takes effect. We encourage you to review this Policy periodically. Changes are effective when posted on this page.

GDPR Privacy

Legal Basis for Processing Personal Data under GDPR

We may process Personal Data under the following conditions:

  • Consent: You have given your consent for processing Personal Data for one or more specific purposes.
  • Performance of a contract: Provision of Personal Data is necessary for the performance of an agreement with you and/or for any pre-contractual obligations thereof.
  • Legal obligations:Processing Personal Data is necessary for compliance with a legal obligation to which Gotransverse is subject.
  • Vital interests:Processing Personal Data is necessary to protect your vital interests or of another natural person.
  • Public interests:Processing Personal Data is related to a task that is carried out in the public interest or in the exercise of official authority vested in Gotransverse
  • Legitimate interests:Processing Personal Data is necessary for the purposes of the legitimate interests pursued by Gotransverse

 

In any case, Gotransverse will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.

Your Rights under the GDPR

The Company undertakes to respect the confidentiality of your Personal Data and to guarantee you can exercise your rights.

You have the right under this Privacy Policy, and by law if you are within the EU, to:

  • Request access to your Personal Data. The right to access, update or delete your Personal Information. Whenever made possible, you can access, update or request deletion of your Personal Data directly within your account settings section. If you are unable to perform these actions yourself, please contact Us to assist you. This also enables you to receive a copy of the Personal Data we hold about you.
  • Request correction of the Personal Data that we hold about you. You have the right to have any incomplete or inaccurate information we hold about you corrected.
  • Object to processing of your Personal Data. This right exists where we are relying on a legitimate interest as the legal basis for Our processing and there is something about your particular situation, which makes you want to object to our processing of your Personal Data on this ground. You also have the right to object where we are processing your Personal Data for direct marketing purposes.
  • Request erasure of your Personal Data. You have the right to ask Us to delete or remove Personal Data when there is no good reason for Us to continue processing it.
  • Request the transfer of your Personal Data. We will provide to you, or to a third-party you have chosen, your Personal Data in a structured, commonly used, machine-readable format. Please note that this right only applies to automated information which you initially provided consent for Us to use or where we used the information to perform a contract with you.
  • Withdraw your consent. You have the right to withdraw your consent on using your Personal Data. If you withdraw your consent, we may not be able to provide you with access to certain specific functionalities of the Service.

An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data should direct his query to the Data Controller.

If requested to remove personally identifiable data, it is on the part of the Data Controller to make the change within their system and either 1) utilize their user interface to make the same changes to the corresponding account in the Gotransverse system or, 2) send a request to Gotransverse to make the changes to the billing account.

Exercising of your GDPR Data Protection Right

You may exercise your rights of access, rectification, cancellation and opposition by contacting Us. Please note that we may ask you to verify your identity before responding to such requests. If you make a request, Gotransverse will try our best to respond to you as soon as possible.

Because of the complex architecture of the Gotransverse Billing Platform, deletion of accounts will result in the inaccuracy of records, statements, invoices, ledgers, etc. To circumvent this issue, an account will be considered removed if the user is no longer identified as being in the system. Changing of personally identifiable information (First & Last Name, Home Street Address, billing street address, Phone Number, E-mail address) will make a user’s identity obsolete in the system. This includes history and future transactions.

You have the right to complain to a Data Protection Authority about Our collection and use of your Personal Data. For more information, if you are in the European Economic Area (EEA), please contact your local data protection authority in the EEA.

The Gotransverse platform collects information under the direction of our customer and has no direct relationship with the individuals whose personal data it processes. If you are an end user of one of our customers and would like to remove your data from their system or would no longer like to be contacted by one of our customers that use our service, please contact the customer that you interact with directly.

While unlikely, Gotransverse may transfer Personal Information to companies that help us provide our service. Transfers to subsequent third parties are covered by the service agreements with our customers.

Gotransverse Websites

Should we ask you to provide certain information by which you can be identified when using our websites, you can be assured that it will only be used in accordance with this privacy statement.

Notice to UK and EU Residents

Please note that the “Personal Information” referenced in this Privacy Policy means “Personal Data” as that term is defined under the European Union (“EU”) General Data Protection Regulations (“GDPR”) and its United Kingdom (“UK”) GDPR counterpart. Gotransverse is a Data Processor for the Personal Data collected from Data Controllers and processes the Personal Data of end users on behalf of its customers.

If you are an individual from the European Economic Area (the “EEA”), the UK or Switzerland, please note that our legal basis for collecting and using your personal information will depend on the personal information collected by its customers and the specific context in which they collect it.

Cookie Policy

Cookies are small text files that are stored in a computer’s web browser memory. They help website providers with things like understanding how people use a website, remembering a user’s login details, and storing website preferences. This page explains how we use cookies and other similar technologies to help us ensure that our Services function properly, prevent fraud and other harm, and analyze and improve the Services.

How we use cookies

Cookies help us provide effective web experiences. We change the cookies periodically as we improve or add to our Services, but we generally use cookies for the following purposes:

Cookies help us understand how to make our website and services work better for you. Cookies tell us how people reach our website and our users’ websites. They give us insights into improvements or enhancements we need to make to our website and services.

Cookies can help us provide more effective advertising. For example, we might use a cookie to help prevent you from seeing the same advertisement multiple times or to measure how many times an advertisement is viewed or clicked on.

We use Google Analytics, which uses cookies and similar technologies, to collect and analyze information about the use of the services, and report on activities and trends. This service may also collect information regarding the use of other websites, apps and online resources. You can learn about Google’s practices on the Google website.

Additionally, the Gotransverse platform uses cookies to track session status to authenticate user accounts. These cookies are only used by the platform and are not used in conjunction with other cookies on our website.

How to manage cookies

Your web browser should allow you to change your cookie preferences, including to delete and disable Gotransverse cookies. Please consult the help section of your web browser or follow the links below to understand your options, but please note that if you choose to disable the cookies, some features of our website or services may not operate as intended.