Legal

Privacy Policy

Effective Date: July 16, 2026

Download PDF

At EVERGR3N LLC (“EVERGR3N,” “we,” “us,” or “our”), protecting your privacy is fundamental to our mission of providing secure, compliant financial infrastructure for licensed cannabis businesses. This Privacy Policy describes how we collect, use, disclose, retain, and protect information about you when you access our website, client portal, and financial services.

This Policy applies to all users of our services, including business owners, authorized representatives, employees, vendors, and visitors to our website.

1.

Information We Collect

A.Personal Identification Information

  • Full legal name and date of birth
  • Government-issued photo ID (driver's license, passport, or state ID)
  • Social Security Number or Taxpayer Identification Number (for KYC/AML compliance)
  • Email address, phone number, and mailing address

B.Business Information

  • Business name, entity type, and ownership structure
  • Employer Identification Number (EIN)
  • Arizona cannabis license number(s) and documentation
  • Articles of incorporation, operating agreements, or equivalent formation documents
  • Beneficial ownership information for individuals holding ≥25% equity interest

C.Financial Information

  • Bank account and routing numbers (collected via Plaid or manual entry)
  • Transaction history, payment details, and transfer amounts
  • FBO sub-account balances and ledger activity
  • Vendor payment instructions and recipient information
  • Cash pickup amounts and scheduling details

D.Technical and Usage Information

  • IP address, device type, operating system, browser type and version
  • Pages visited, features used, time spent, and click-stream data
  • Session identifiers and authentication tokens
  • Cookies and similar tracking technologies (see Section 4)
  • Error logs and diagnostic data

E.Communications

  • Messages and correspondence with our support or compliance team
  • Survey responses and feedback you voluntarily provide
  • Records of consents, ACH authorizations, and signed agreements

F.Information from Third Parties

  • Plaid Inc. — Bank account verification and balance data
  • KYC/KYB providers — Identity verification and beneficial ownership screening
  • AML/OFAC screening services — Sanctions and watchlist screening results
  • State cannabis regulatory databases — License validation
  • Publicly available records used for compliance due diligence

2.

How We Use Your Information

A.Providing Financial Services

  • Opening and maintaining your FBO sub-account
  • Processing ACH transfers, vendor disbursements, and payments
  • Enabling cash pickup scheduling and management
  • Generating statements, receipts, and transaction records

B.Identity Verification and Compliance

  • Know Your Customer (KYC) and Know Your Business (KYB) verification
  • Anti-Money Laundering (AML) and Bank Secrecy Act (BSA) compliance
  • OFAC and sanctions list screening
  • FinCEN reporting obligations, including Suspicious Activity Reports (SARs)
  • Periodic compliance reviews (conducted approximately every 90 days)

C.Security and Fraud Prevention

  • Detecting and preventing unauthorized access, fraud, and financial crimes
  • Monitoring transactions for suspicious or anomalous activity
  • Maintaining audit logs for regulatory and security purposes
  • Protecting the integrity and availability of the EVERGR3N platform

D.Legal and Regulatory Obligations

  • Complying with federal and state money transmitter laws
  • Responding to lawful requests from government authorities
  • Fulfilling reporting obligations under FinCEN, DFPI, and Arizona state regulators
  • Record-keeping as required by applicable law (minimum 5 years under BSA)

E.Service Improvement and Communications

  • Improving our platform, features, and user experience
  • Sending service updates, compliance notices, and administrative communications
  • Providing customer and technical support
  • Sending marketing communications (with your consent or as permitted by law)

F.Analytics and Research

We analyze aggregated, de-identified data to understand usage patterns and improve our services. We do not attempt to re-identify individuals from de-identified data sets.


3.

How We Share Your Information

We share your information only as described below. We do not sell your personal information to third parties for marketing or advertising purposes.

A.Banking Partners

We share necessary financial and identity information with Safe Harbor Financial LLC (our ODFI and banking partner) and our FDIC-member deposit institution to facilitate transaction processing, ACH origination, and required regulatory recordkeeping.

B.Service Providers and Subprocessors

We work with carefully selected vendors who process data solely on our behalf, including:

  • Plaid Inc. — Bank account verification and linking
  • Supabase — Cloud database and document storage
  • Vercel — Application hosting and content delivery
  • Email service providers — Transactional and compliance communications
  • Armored cash carriers — Cash pickup logistics (limited data sharing)
  • AML/KYC screening providers — Identity verification and sanctions screening

These providers are bound by data processing agreements that restrict use of your information to the specified purposes.

C.Regulators and Law Enforcement

We may disclose your information to governmental authorities when:

  • Required by applicable law, regulation, or valid legal process (e.g., subpoena or court order)
  • Necessary to comply with FinCEN Suspicious Activity Report (SAR) obligations
  • Required to protect the rights, property, or safety of EVERGR3N, our clients, or the public
Note: Federal law (including the BSA) may prohibit us from notifying you that we have filed a SAR or disclosed your information in response to a law enforcement request.

D.Professional Advisors

We may share information with our legal counsel, auditors, and other professional advisors under appropriate confidentiality obligations.

E.Business Transfers

If EVERGR3N undergoes a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

F.With Your Consent

We may share your information for other purposes with your explicit prior consent.


4.

Cookies & Tracking Technologies

A.Types of Cookies We Use

  • Strictly Necessary Cookies — Required for authentication, session management, and core portal functionality. Cannot be disabled without impacting service.
  • Functional Cookies — Remember your preferences and settings across sessions.
  • Security Cookies — Detect fraudulent activity and protect account integrity.
  • Analytics Cookies — Understand how users interact with our platform using aggregated, non-personally identifiable data. We use only privacy-respecting analytics tools.

B.Managing Cookies

You can control or delete cookies through your browser settings. Disabling strictly necessary cookies will prevent you from using authenticated features of our portal. We do not use third-party advertising or tracking cookies.

C.Do Not Track

Our website does not currently respond to “Do Not Track” (DNT) browser signals, as no universally accepted standard exists for interpreting these signals. We will update this section if our practices change.


5.

Data Security

We implement a layered, defense-in-depth security program to protect your information from unauthorized access, disclosure, alteration, and destruction.

A.Technical Safeguards

  • Encryption in Transit: All data between your browser and our servers is protected by TLS 1.2 or higher (HTTPS enforced site-wide).
  • Encryption at Rest: Sensitive data — including bank account numbers, routing numbers, and government ID numbers — is encrypted using AES-256 encryption before storage.
  • Access Controls: Role-based access control (RBAC) ensures employees access only the data necessary to perform their job functions.
  • Multi-Factor Authentication (MFA): Required for all portal logins and administrative access.
  • Audit Logging: All data access, administrative actions, and authentication events are logged, monitored, and retained for audit and investigation purposes.
  • Network Security: Firewalls, intrusion detection systems, and network segmentation protect our infrastructure.

B.Organizational Safeguards

  • Background screening for employees with access to sensitive data
  • Mandatory security awareness training for all staff
  • Data handling policies and confidentiality agreements
  • Regular security reviews and vulnerability assessments
  • Documented incident response plan with defined escalation procedures
  • Third-party vendor security assessments and contractual requirements

C.Limitations

Despite our best efforts, no security system is completely impenetrable. Transmitting information over the internet carries inherent risks. By using our services, you acknowledge this risk. If you suspect unauthorized access, contact us immediately at privacy@evergr3n.com with “SECURITY” in the subject line.


6.

Data Retention

We retain your personal information for as long as necessary to:

  • Provide our services and maintain your account
  • Comply with legal and regulatory obligations — the Bank Secrecy Act (BSA) requires retention of most financial records for a minimum of 5 years
  • Resolve disputes and enforce our agreements
  • Satisfy audit and regulatory examination requirements

Upon account closure, we retain records for a minimum of 5 years (or longer if required by applicable law). After the applicable retention period expires, we securely delete or irreversibly anonymize your information in accordance with our data destruction standards. Certain records (e.g., audit logs, SAR-related records) may be retained longer as required by specific regulatory programs.


7.

Your Privacy Rights

Depending on your location and applicable law, you may have the following rights regarding your personal information:

  • Access — Request a copy of the personal information we hold about you.
  • Correction — Request correction of inaccurate or incomplete information.
  • Deletion — Request deletion of your personal information, subject to legal retention obligations (we cannot delete records required by law).
  • Portability — Request your information in a structured, commonly used, machine-readable format.
  • Restriction — Request that we limit processing of your information in certain circumstances.
  • Objection — Object to certain types of processing, including direct marketing.
  • Withdrawal of Consent — Where we rely on your consent to process your information, you may withdraw consent at any time (without affecting prior processing).

How to Exercise Your Rights

Submit a written request to privacy@evergr3n.com. We will respond to verified requests within 45 days. We may ask you to verify your identity before processing your request. Some rights may be limited where we must retain data to comply with our legal obligations as a money services business.


8.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

A.Your California Rights

  • Right to Know — Know what personal information we collect, the purposes for collection, the categories of third parties with whom we share it, and whether we sell it (we do not).
  • Right to Delete — Request deletion of your personal information, subject to legal exceptions.
  • Right to Correct — Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing — We do not sell or share personal information for cross-context behavioral advertising. No opt-out action is required.
  • Right to Limit Sensitive Information — We use sensitive personal information (SSN, financial account numbers, government IDs) only as necessary to provide services and comply with law.
  • Right to Non-Discrimination — We will not deny services, charge different prices, or otherwise discriminate against you for exercising your CCPA/CPRA rights.

B.Authorized Agents

California residents may designate an authorized agent to submit requests on their behalf. We may require written proof of the agent's authority and may verify your identity directly before honoring the request.

C.How to Submit a California Request

Email privacy@evergr3n.com with “California Privacy Request” in the subject line. We will acknowledge receipt within 10 business days and respond within 45 calendar days (extendable by an additional 45 days with written notice).

D.Categories of Personal Information Collected (Past 12 Months)

CategoryExamplesSold?
IdentifiersName, email, SSN, government IDNo
Financial informationBank accounts, transaction historyNo
Commercial informationAccount activity, services usedNo
Internet / network activityIP address, usage data, logsNo
Professional / employment infoBusiness name, license, EINNo
Sensitive personal informationSSN, account numbers, government IDNo

9.

Financial Privacy Notice (Gramm-Leach-Bliley Act)

As a provider of financial services, EVERGR3N LLC is subject to the Gramm-Leach-Bliley Act (GLBA) and its implementing regulations. This section serves as our GLBA privacy notice.

A.What We Collect

We collect nonpublic personal financial information as described in Section 1, including account numbers, transaction data, and identity information provided directly by you, from our banking partners, or from third-party service providers.

B.What We Disclose

We may share nonpublic personal information with service providers that perform financial services on our behalf (e.g., ACH processing, compliance screening) and as otherwise required or permitted by law. We do not share nonpublic personal information with unaffiliated third parties for independent marketing purposes without your consent.

C.Confidentiality and Security

We maintain physical, electronic, and procedural safeguards that comply with federal regulations to protect your nonpublic personal information against unauthorized access, use, or disclosure.

D.Your GLBA Rights

Under GLBA, you may have the right to opt out of certain disclosures to unaffiliated third parties. Because our sharing practices are limited as described above, most users will have no need to opt out. To learn more or submit an opt-out request, contact us at privacy@evergr3n.com.


10.

Children's Privacy

Our services are intended exclusively for licensed cannabis businesses and their authorized adult representatives. We do not knowingly collect, solicit, or retain personal information from individuals under the age of 18.

If we discover that we have inadvertently collected information from a minor, we will promptly delete it from our records. If you believe we have collected personal information from a child, please notify us immediately at privacy@evergr3n.com.



12.

Marketing Communications

We may send you promotional emails about our services, new features, or industry news. You can opt out of marketing communications at any time by:

  1. 1.Clicking the “Unsubscribe” link in any marketing email
  2. 2.Emailing us at privacy@evergr3n.com with “Unsubscribe” in the subject line
  3. 3.Updating your communication preferences in your account Settings

Note: Opting out of marketing does not affect transactional communications required for your account, including compliance notices, transaction confirmations, security alerts, and regulatory communications.


13.

Security Breach Notification

In the event of a security breach that compromises your personal information, EVERGR3N will:

  1. 1.Notify affected individuals within the timeframes required by applicable state law — Arizona law (A.R.S. § 18-552) requires notification in the most expedient time possible and without unreasonable delay
  2. 2.Notify required regulatory agencies and law enforcement as mandated by federal and state law
  3. 3.Provide clear information about the nature of the breach, categories of information affected, steps taken to mitigate harm, and recommended steps you can take to protect yourself
  4. 4.Establish a dedicated response team and communication channel for breach-related inquiries

If you discover or suspect unauthorized access to your account, immediately contact us at privacy@evergr3n.com with “SECURITY” in the subject line.


14.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  1. 1.Post the updated Policy on this page with a revised “Effective Date”
  2. 2.Notify you via email or a prominent notice within our portal at least 30 days before material changes take effect
  3. 3.Obtain your affirmative consent where required by applicable law

Your continued use of our services after the effective date of any update constitutes your acceptance of the revised Policy. We encourage you to review this page periodically.


15.

Contact Us

For privacy questions, concerns, or to exercise your rights, please reach out to our Privacy team:

Company

EVERGR3N LLC

Mailing Address

Phoenix, Arizona
(full address to be added)

Phone

To be updated

Privacy Inquiries

privacy@evergr3n.com

General Support

support@evergr3n.com

Urgent Security

Email with “SECURITY” in subject for priority handling

Effective Date: July 16, 2026 · EVERGR3N LLC · Arizona, USA