At EVERGR3N LLC (“EVERGR3N,” “we,” “us,” or “our”), protecting your privacy is fundamental to our mission of providing secure, compliant financial infrastructure for licensed cannabis businesses. This Privacy Policy describes how we collect, use, disclose, retain, and protect information about you when you access our website, client portal, and financial services.
This Policy applies to all users of our services, including business owners, authorized representatives, employees, vendors, and visitors to our website.
Information We Collect
A.Personal Identification Information
- Full legal name and date of birth
- Government-issued photo ID (driver's license, passport, or state ID)
- Social Security Number or Taxpayer Identification Number (for KYC/AML compliance)
- Email address, phone number, and mailing address
B.Business Information
- Business name, entity type, and ownership structure
- Employer Identification Number (EIN)
- Arizona cannabis license number(s) and documentation
- Articles of incorporation, operating agreements, or equivalent formation documents
- Beneficial ownership information for individuals holding ≥25% equity interest
C.Financial Information
- Bank account and routing numbers (collected via Plaid or manual entry)
- Transaction history, payment details, and transfer amounts
- FBO sub-account balances and ledger activity
- Vendor payment instructions and recipient information
- Cash pickup amounts and scheduling details
D.Technical and Usage Information
- IP address, device type, operating system, browser type and version
- Pages visited, features used, time spent, and click-stream data
- Session identifiers and authentication tokens
- Cookies and similar tracking technologies (see Section 4)
- Error logs and diagnostic data
E.Communications
- Messages and correspondence with our support or compliance team
- Survey responses and feedback you voluntarily provide
- Records of consents, ACH authorizations, and signed agreements
F.Information from Third Parties
- Plaid Inc. — Bank account verification and balance data
- KYC/KYB providers — Identity verification and beneficial ownership screening
- AML/OFAC screening services — Sanctions and watchlist screening results
- State cannabis regulatory databases — License validation
- Publicly available records used for compliance due diligence
How We Use Your Information
A.Providing Financial Services
- Opening and maintaining your FBO sub-account
- Processing ACH transfers, vendor disbursements, and payments
- Enabling cash pickup scheduling and management
- Generating statements, receipts, and transaction records
B.Identity Verification and Compliance
- Know Your Customer (KYC) and Know Your Business (KYB) verification
- Anti-Money Laundering (AML) and Bank Secrecy Act (BSA) compliance
- OFAC and sanctions list screening
- FinCEN reporting obligations, including Suspicious Activity Reports (SARs)
- Periodic compliance reviews (conducted approximately every 90 days)
C.Security and Fraud Prevention
- Detecting and preventing unauthorized access, fraud, and financial crimes
- Monitoring transactions for suspicious or anomalous activity
- Maintaining audit logs for regulatory and security purposes
- Protecting the integrity and availability of the EVERGR3N platform
D.Legal and Regulatory Obligations
- Complying with federal and state money transmitter laws
- Responding to lawful requests from government authorities
- Fulfilling reporting obligations under FinCEN, DFPI, and Arizona state regulators
- Record-keeping as required by applicable law (minimum 5 years under BSA)
E.Service Improvement and Communications
- Improving our platform, features, and user experience
- Sending service updates, compliance notices, and administrative communications
- Providing customer and technical support
- Sending marketing communications (with your consent or as permitted by law)
F.Analytics and Research
We analyze aggregated, de-identified data to understand usage patterns and improve our services. We do not attempt to re-identify individuals from de-identified data sets.
Data Security
We implement a layered, defense-in-depth security program to protect your information from unauthorized access, disclosure, alteration, and destruction.
A.Technical Safeguards
- Encryption in Transit: All data between your browser and our servers is protected by TLS 1.2 or higher (HTTPS enforced site-wide).
- Encryption at Rest: Sensitive data — including bank account numbers, routing numbers, and government ID numbers — is encrypted using AES-256 encryption before storage.
- Access Controls: Role-based access control (RBAC) ensures employees access only the data necessary to perform their job functions.
- Multi-Factor Authentication (MFA): Required for all portal logins and administrative access.
- Audit Logging: All data access, administrative actions, and authentication events are logged, monitored, and retained for audit and investigation purposes.
- Network Security: Firewalls, intrusion detection systems, and network segmentation protect our infrastructure.
B.Organizational Safeguards
- Background screening for employees with access to sensitive data
- Mandatory security awareness training for all staff
- Data handling policies and confidentiality agreements
- Regular security reviews and vulnerability assessments
- Documented incident response plan with defined escalation procedures
- Third-party vendor security assessments and contractual requirements
C.Limitations
Despite our best efforts, no security system is completely impenetrable. Transmitting information over the internet carries inherent risks. By using our services, you acknowledge this risk. If you suspect unauthorized access, contact us immediately at privacy@evergr3n.com with “SECURITY” in the subject line.
Data Retention
We retain your personal information for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal and regulatory obligations — the Bank Secrecy Act (BSA) requires retention of most financial records for a minimum of 5 years
- Resolve disputes and enforce our agreements
- Satisfy audit and regulatory examination requirements
Upon account closure, we retain records for a minimum of 5 years (or longer if required by applicable law). After the applicable retention period expires, we securely delete or irreversibly anonymize your information in accordance with our data destruction standards. Certain records (e.g., audit logs, SAR-related records) may be retained longer as required by specific regulatory programs.
Your Privacy Rights
Depending on your location and applicable law, you may have the following rights regarding your personal information:
- Access — Request a copy of the personal information we hold about you.
- Correction — Request correction of inaccurate or incomplete information.
- Deletion — Request deletion of your personal information, subject to legal retention obligations (we cannot delete records required by law).
- Portability — Request your information in a structured, commonly used, machine-readable format.
- Restriction — Request that we limit processing of your information in certain circumstances.
- Objection — Object to certain types of processing, including direct marketing.
- Withdrawal of Consent — Where we rely on your consent to process your information, you may withdraw consent at any time (without affecting prior processing).
How to Exercise Your Rights
Submit a written request to privacy@evergr3n.com. We will respond to verified requests within 45 days. We may ask you to verify your identity before processing your request. Some rights may be limited where we must retain data to comply with our legal obligations as a money services business.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
A.Your California Rights
- Right to Know — Know what personal information we collect, the purposes for collection, the categories of third parties with whom we share it, and whether we sell it (we do not).
- Right to Delete — Request deletion of your personal information, subject to legal exceptions.
- Right to Correct — Request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing — We do not sell or share personal information for cross-context behavioral advertising. No opt-out action is required.
- Right to Limit Sensitive Information — We use sensitive personal information (SSN, financial account numbers, government IDs) only as necessary to provide services and comply with law.
- Right to Non-Discrimination — We will not deny services, charge different prices, or otherwise discriminate against you for exercising your CCPA/CPRA rights.
B.Authorized Agents
California residents may designate an authorized agent to submit requests on their behalf. We may require written proof of the agent's authority and may verify your identity directly before honoring the request.
C.How to Submit a California Request
Email privacy@evergr3n.com with “California Privacy Request” in the subject line. We will acknowledge receipt within 10 business days and respond within 45 calendar days (extendable by an additional 45 days with written notice).
D.Categories of Personal Information Collected (Past 12 Months)
| Category | Examples | Sold? |
|---|---|---|
| Identifiers | Name, email, SSN, government ID | No |
| Financial information | Bank accounts, transaction history | No |
| Commercial information | Account activity, services used | No |
| Internet / network activity | IP address, usage data, logs | No |
| Professional / employment info | Business name, license, EIN | No |
| Sensitive personal information | SSN, account numbers, government ID | No |
Financial Privacy Notice (Gramm-Leach-Bliley Act)
As a provider of financial services, EVERGR3N LLC is subject to the Gramm-Leach-Bliley Act (GLBA) and its implementing regulations. This section serves as our GLBA privacy notice.
A.What We Collect
We collect nonpublic personal financial information as described in Section 1, including account numbers, transaction data, and identity information provided directly by you, from our banking partners, or from third-party service providers.
B.What We Disclose
We may share nonpublic personal information with service providers that perform financial services on our behalf (e.g., ACH processing, compliance screening) and as otherwise required or permitted by law. We do not share nonpublic personal information with unaffiliated third parties for independent marketing purposes without your consent.
C.Confidentiality and Security
We maintain physical, electronic, and procedural safeguards that comply with federal regulations to protect your nonpublic personal information against unauthorized access, use, or disclosure.
D.Your GLBA Rights
Under GLBA, you may have the right to opt out of certain disclosures to unaffiliated third parties. Because our sharing practices are limited as described above, most users will have no need to opt out. To learn more or submit an opt-out request, contact us at privacy@evergr3n.com.
Children's Privacy
Our services are intended exclusively for licensed cannabis businesses and their authorized adult representatives. We do not knowingly collect, solicit, or retain personal information from individuals under the age of 18.
If we discover that we have inadvertently collected information from a minor, we will promptly delete it from our records. If you believe we have collected personal information from a child, please notify us immediately at privacy@evergr3n.com.
Third-Party Links & Services
Our website and portal may contain links to third-party websites, applications, or services (such as Plaid's authentication interface). This Privacy Policy applies only to EVERGR3N's own website and portal and does not govern the privacy practices of third parties.
We encourage you to review the privacy policies of any third-party services you access. We are not responsible for the content, security, or privacy practices of third-party sites, even if accessed through a link on our platform.
Marketing Communications
We may send you promotional emails about our services, new features, or industry news. You can opt out of marketing communications at any time by:
- 1.Clicking the “Unsubscribe” link in any marketing email
- 2.Emailing us at privacy@evergr3n.com with “Unsubscribe” in the subject line
- 3.Updating your communication preferences in your account Settings
Note: Opting out of marketing does not affect transactional communications required for your account, including compliance notices, transaction confirmations, security alerts, and regulatory communications.
Security Breach Notification
In the event of a security breach that compromises your personal information, EVERGR3N will:
- 1.Notify affected individuals within the timeframes required by applicable state law — Arizona law (A.R.S. § 18-552) requires notification in the most expedient time possible and without unreasonable delay
- 2.Notify required regulatory agencies and law enforcement as mandated by federal and state law
- 3.Provide clear information about the nature of the breach, categories of information affected, steps taken to mitigate harm, and recommended steps you can take to protect yourself
- 4.Establish a dedicated response team and communication channel for breach-related inquiries
If you discover or suspect unauthorized access to your account, immediately contact us at privacy@evergr3n.com with “SECURITY” in the subject line.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- 1.Post the updated Policy on this page with a revised “Effective Date”
- 2.Notify you via email or a prominent notice within our portal at least 30 days before material changes take effect
- 3.Obtain your affirmative consent where required by applicable law
Your continued use of our services after the effective date of any update constitutes your acceptance of the revised Policy. We encourage you to review this page periodically.
Contact Us
For privacy questions, concerns, or to exercise your rights, please reach out to our Privacy team:
Company
EVERGR3N LLC
Mailing Address
Phoenix, Arizona
(full address to be added)
Phone
To be updated
Privacy Inquiries
privacy@evergr3n.comGeneral Support
support@evergr3n.comUrgent Security
Email with “SECURITY” in subject for priority handling
