Privacy Policy
Last updated: August 25, 2026
This Privacy Policy explains how Bridge Ltd. ("Bridge", "we", "us") collects, uses, discloses, and protects personal and business information in connection with the Bridge platform. It applies to corporate applicants, authorized users, cardholders, and visitors to our website. This is a template and should be reviewed by qualified legal counsel before use in production, particularly to confirm alignment with the data protection laws of the jurisdictions in which you operate (e.g. GDPR, UK GDPR, or similar regimes).
1. Information We Collect
1.1 Information you provide to us
- Company details: legal name, trading name, registration number, country of incorporation, industry, and website.
- Authorized contact and cardholder details: full name, job title, email address, phone number, and date of birth where required for KYC.
- KYC/KYB documents: certificates of incorporation, proof of address, government-issued identification, and beneficial ownership declarations.
- Card and transaction preferences: requested limits, departments, cost centers, and delivery addresses for physical cards.
1.2 Information collected automatically
When you use the Portal, we automatically collect technical information such as IP address, browser type, device identifiers, session activity, and cookies as described in our Cookie Policy.
1.3 Information from third parties
We receive card, balance, and transaction data from our licensed issuing partner and Sponsor Bank, and may receive sanctions or watchlist screening results from compliance data providers.
2. How We Use Your Information
- To verify your identity and assess eligibility for corporate card programs (KYC/KYB).
- To create, issue, and manage Cards, including processing top-ups, freezes, and transfers you request.
- To detect, investigate, and prevent fraud, money laundering, and other financial crime.
- To communicate with you about your application, account, and transactions.
- To comply with legal and regulatory obligations, including recordkeeping requirements.
- To improve and secure the Service, including diagnosing technical issues.
3. Legal Bases for Processing
Where applicable data protection law requires a legal basis, we rely on: performance of our contract with you; compliance with legal obligations (including AML/KYC regulation); our legitimate interests in operating and securing the Service; and, where required, your consent (for example, for optional marketing communications).
4. Sharing & Disclosure
We share personal and business information only as necessary, including with:
- Our licensed banking sponsor and card-issuing processor, to issue and operate Cards.
- Payment networks (Visa and Mastercard), to process authorizations and settlements.
- Identity verification, sanctions-screening, and fraud-prevention service providers.
- Regulators, law enforcement, or courts where required by law.
- Professional advisors (auditors, legal counsel) under confidentiality obligations.
We do not sell your personal information to third parties.
5. International Transfers
Your information may be processed in countries other than your own. Where we transfer personal data internationally, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms recognized under applicable law.
6. Data Retention
KYC/KYB records and transaction history are retained for the period required by applicable anti-money laundering regulations (typically five years or more after the end of the business relationship). Other personal data is retained only as long as necessary for the purposes described in this Policy.
7. Your Rights
Subject to applicable law and our regulatory retention obligations, you may request access to, correction of, deletion of, or a copy of your personal data, or object to certain processing. To exercise these rights, contact us at support@bridgeltd.net.
8. Cookies
We use cookies and similar technologies as described in our Cookie Policy.
9. Security
We apply encryption in transit, access controls, role-based permissions, and audit logging to protect your data. KYC/KYB documents are stored outside the public web application and are accessible only to authorized personnel and the corporate that submitted them.
10. Children's Privacy
The Service is intended for use by business entities and their authorized adult representatives, and is not directed at individuals under the age of 18.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-Portal notice.
12. Contact
Questions about this Privacy Policy can be directed to support@bridgeltd.net.