This Privacy Policy explains how Cohera Flow (“Cohera,” “we,” “us,” or “our”) handles personal information when you visit coheraflow.com, use the Cohera Flow web or progressive web application, communicate with us, or use related services (collectively, the “Services”).
This Policy applies to personal information Cohera controls. Stripe, participating financial institutions, card networks, merchants, payroll providers, linked institutions, and other third parties may independently control information under their own privacy notices. The Stripe Privacy Policy describes Stripe’s practices.
1. Scope and financial-data roles
Cohera provides the software interface and workflow layer for business payments and money movement. Stripe provides eligible payment processing, identity verification, Financial Account, and money-transmission services. Eligible Financial Account funds are held at Fifth Third Bank, N.A., Member FDIC. Card services are provided by Stripe and the issuing bank identified in applicable card-program disclosures.
Depending on the interaction, Cohera may act as a business that determines why and how platform information is processed; a service provider or processor for a business customer; or a platform that sends information to Stripe and other financial providers so they can provide regulated services under their own legal obligations and privacy notices.
This general Policy is not a substitute for any separate financial privacy notice required under the Gramm-Leach-Bliley Act or a bank or card program. If a separate notice applies, it will be provided when required.
2. Personal information we collect
The information we collect depends on the Services you use and the permissions and capabilities enabled for your account.
2.1 Information you provide
- Account and contact information: name, email, phone, username, pay tag, mailing or physical address, profile image, preferences, and discovery settings.
- Business and representative information: legal and trade names, entity type, formation jurisdiction, address, website, industry, tax identifiers, ownership, beneficial owners, directors, officers, representatives, job title, and business description.
- Identity and verification information: date of birth, government identification details and images, taxpayer or Social Security information, proof of address, selfie or likeness, verification status, and sanctions, fraud, or eligibility results. Stripe or another provider may collect some of this information directly.
- Funding and financial information: linked institution, account type, account holder, tokenized account or payment-method identifiers, routing details, last four digits, card brand, and payout destinations you authorize. If you separately choose linked-bank balance display, this may also include the balances and refresh status returned for each connection covered by that permission. Cohera is designed to rely on provider tokens and limited details rather than full card numbers, CVCs, or online-banking credentials.
- Transaction and commercial information: payments, links, invoices, subscriptions, refunds, disputes, payouts, transfers, recipients, merchants, amounts, dates, descriptions, status, fees, receipts, card activity, controls, and Financial Account activity.
- Payroll and routing information: direct-deposit preferences, payroll provider identifiers, ADP-related settings, payment schedules, worker or contractor details, allocation rules, and bucket labels.
- Security information: password hashes, verification and login-code events, PIN-verification status, session records, trusted-device information, recovery events, authentication attempts, and risk signals. We should not receive or store your plaintext password or PIN.
- Communications and support: messages, requests, complaints, responses, attachments, surveys, call or chat details, and issue-handling records.
2.2 Information collected automatically
We may automatically collect IP address, device identifiers, browser and operating-system type, language, time zone, approximate location derived from IP, referring and exit pages, pages and features used, timestamps, session duration, errors, performance information, cookie and local-storage data, and security signals.
We do not collect precise geolocation unless a feature clearly requests it and you grant device permission, such as a supported card-present or fraud-prevention feature.
2.3 Information from other sources
We may receive information from Stripe and its affiliates, including information submitted or recognized through Stripe Link and Stripe Elements; Stripe Payments Company; Fifth Third Bank and other financial institutions; networks and payment methods; linked institutions through a consented Stripe Financial Connections flow; business administrators and transaction participants; ADP or another connected provider; identity, fraud, sanctions, address, mapping, data, or public-record providers; device platforms and communications vendors; and authorities where permitted or required by law.
2.4 Stripe Link, address completion, and Financial Connections choices
If you use Stripe Link, Stripe may recognize your email or other Link account details and offer saved payment information under Stripe's terms and privacy notice. Payment and billing-address Elements are hosted or controlled by Stripe; Cohera receives the resulting provider identifiers and limited transaction details rather than your full card number or CVC.
Card shipping-address entry may use a third-party mapping or address-completion provider when configured. Text entered into an autocomplete-enabled field may be sent to that provider to return address suggestions. Manual entry remains available.
Linking a bank account does not automatically authorize Cohera to display its balances. If balance display is available, we request Financial Connections balance permission only after you affirmatively select that option. The permission applies to the connections you authorize; it is separate from any debit, credit, or transfer authorization. You may stop Cohera's display, after which we clear the stored balance snapshot and do not repopulate it without renewed permission, subject to records we must retain for consent, security, disputes, or law.
3. How we use personal information
We may use personal information to:
- Provide the Services: create and administer accounts, authenticate users, maintain profiles and pay tags, process instructions, reconcile events, display activity, operate buckets and schedules, and provide receipts or statements.
- Enable financial services: establish and service connected accounts, submit payment and payout requests, link funding sources, enable eligible Financial Accounts and cards, support direct-deposit or payroll-routing workflows, and deliver program communications.
- Verify identity and eligibility: conduct KYC/KYB, beneficial-owner, representative, address, sanctions, fraud, restricted-business, and provider-capability checks.
- Protect users and the Services: detect, investigate, prevent, and respond to fraud, unauthorized access, account takeover, money laundering, sanctions risk, disputes, abuse, security incidents, prohibited conduct, and technical failures.
- Communicate: send verification and login codes, security alerts, receipts, transaction status, service and legal notices, support responses, complaint updates, and optional marketing.
- Operate and improve: debug, monitor, analyze use, test reliability, develop features, maintain records, train support personnel, and improve usability and security.
- Comply and enforce: satisfy legal, regulatory, financial-partner, network, tax, audit, recordkeeping, complaint-handling, and law-enforcement requirements; establish or defend claims; and enforce agreements.
- Complete corporate transactions: evaluate or complete a financing, merger, acquisition, reorganization, asset transfer, or similar transaction subject to appropriate protections.
We may de-identify or aggregate information and use it for lawful purposes. We will not attempt to re-identify data that applicable law requires us to maintain as de-identified.
4. How we disclose personal information
4.1 Stripe and financial partners
We disclose account, identity, business, financial, transaction, device, and risk information to Stripe, Stripe Payments Company, Fifth Third Bank for eligible Financial Accounts, the applicable issuing bank, card networks, payment methods, and their vendors to onboard and verify users; process payments and transfers; provide Financial Accounts and cards; prevent loss and fraud; handle disputes and complaints; comply with law; and administer programs.
4.2 Transaction participants
We disclose information needed to complete and document a transaction to merchants, customers, payors, payees, recipients, connected accounts, payroll participants, and their service providers. This may include names, business names, pay tags, transaction descriptions, amounts, status, receipts, and dispute information.
4.3 Linked and integrated services
At your direction, we disclose information to a linked financial institution, ADP or another payroll provider, wallet or device service, accounting tool, and other integration you enable. Their terms and privacy notices govern their independent use.
4.4 Vendors and professional advisers
We disclose information to vendors that provide hosting, databases, infrastructure, email delivery, support, security, monitoring, analytics, identity verification, fraud prevention, compliance, document storage, and professional legal, accounting, or audit services. We require service providers to use information only for contracted purposes and protect it as required by law and contract.
4.5 Legal, safety, compliance, and corporate recipients
We may disclose information to government authorities, regulators, courts, law enforcement, networks, financial partners, affected parties, advisers, or a corporate transaction participant when reasonably necessary to comply with law or legal process; protect rights, safety, funds, or systems; investigate fraud or prohibited conduct; respond to an emergency; enforce agreements; or evaluate or complete a financing, merger, acquisition, restructuring, asset sale, insolvency, or service transition.
4.6 With your direction or consent
We may disclose information when you request, direct, or consent to the disclosure.
5. No sale or behavioral-advertising sharing
Cohera does not sell personal information for money. Cohera does not share personal information for cross-context behavioral advertising, as those terms are defined under California law, and does not knowingly sell or share personal information of anyone under 16.
Disclosures to Stripe, financial institutions, networks, transaction participants, and service providers for servicing, transaction processing, security, compliance, and operations are not intended as sales or behavioral-advertising sharing. If practices change, we will update this Policy and provide any legally required opt-out method, including honoring recognized browser-based signals where required.
6. Cookies, local storage, and similar technologies
We may use strictly necessary technologies for sessions, authentication, CSRF protection, security, load balancing, and core functionality; preference technologies to remember application and accessibility choices; and analytics or performance technologies, if enabled, to understand reliability and use.
You can control many cookies through browser settings, but blocking necessary cookies or local storage may prevent sign-in, security, or PWA functions. A cookie banner or preference center will be provided if required by deployed technologies or law.
7. Retention
We retain information for as long as reasonably necessary to provide the Services, maintain accounts, complete transactions, resolve disputes and complaints, prevent fraud, enforce agreements, meet legal and financial-partner obligations, and maintain business and audit records.
- Account and relationship records may be retained while an account is open and for a legally required period afterward.
- Transaction, verification, tax, fraud, complaint, permission/consent, and regulated-program records may be retained for at least the period required by law, Stripe, a financial institution, or a network. Stopping linked-bank balance display clears the current stored balance snapshot but may not delete a minimal audit record showing when permission was granted or withdrawn.
- Financial Account compliance materials and related records may need to be retained for at least five years.
- Short-lived authentication codes expire quickly, while security logs may be retained longer to investigate incidents.
- Backup copies may remain until overwritten under normal backup cycles.
We may retain information longer for a legal hold, investigation, unresolved balance, dispute, complaint, or security need. Deletion requests remain subject to lawful retention requirements.
8. Security
We use administrative, technical, and physical safeguards designed for the sensitivity of the information, which may include encrypted transmission, access controls, password hashing, role-based permissions, email and PIN verification, session controls, logging, provider tokenization, monitoring, and incident-response procedures.
No system is completely secure. You are responsible for protecting credentials and devices, using unique passwords, keeping contact information current, reviewing activity, and promptly reporting suspected compromise.
9. Your choices and controls
Depending on the feature and law, you may update profile information; choose discovery settings; decline optional linked-bank balance permission; stop Cohera's balance display for a connection; separately disconnect an external account or revoke provider-side Financial Connections access subject to pending activity; manage Stripe Link through Stripe; manage optional communications; adjust device permissions and browser settings; manage an eligible card subject to program limitations; and request account closure subject to pending transactions, negative balances, recordkeeping, and provider rules.
Revoking permission does not undo processing that already occurred and may make a feature unavailable.
10. U.S. state privacy rights
Depending on your state and subject to legal exceptions, you may have rights to confirm processing; access or obtain a portable copy; correct; delete; opt out of sale, targeted advertising, or certain profiling; limit certain uses of sensitive information; appeal a denial; and receive equal service without unlawful discrimination.
To submit a request, email privacy@coheraflow.com. State the right you want to exercise and provide enough information to identify the relevant account. We will verify requests proportionately to their sensitivity. An authorized agent may submit a request where permitted, subject to proof of authority and direct identity verification where appropriate.
10.1 California notice at collection
The table below describes categories of personal information Cohera may collect and disclose for a business purpose. Actual collection depends on the Services used.
| Category | Examples and purposes | Recipient categories |
|---|---|---|
| Identifiers | Name, contact information, account and device IDs, pay tag, IP address, and government identifiers for accounts, verification, communications, security, and compliance. | Stripe and financial partners; vendors; participants; authorities as required. |
| Customer-record and financial information | Business, employment, bank, card, and financial details for onboarding, servicing, transactions, support, and compliance. | Stripe and financial partners; integrated services; vendors. |
| Protected characteristics | Age or date of birth and information required for lawful identity and eligibility checks. | Stripe, identity and financial partners; authorities as required. |
| Commercial information | Payments, transfers, payouts, invoices, refunds, disputes, receipts, merchant, and card history for processing, reconciliation, support, reporting, and fraud prevention. | Stripe and financial partners; participants; vendors. |
| Internet or electronic activity | Browser, device, sessions, pages, clicks, logs, cookies, errors, and security events for authentication, security, analytics, debugging, and improvement. | Infrastructure, security, communications, and analytics vendors; Stripe where applicable. |
| Geolocation | Approximate location from IP and precise location only with permission for security, fraud prevention, or supported card-present features. | Stripe, device platforms, security or fraud vendors where needed. |
| Professional or employment information | Business role, company, owners, representatives, and worker or contractor routing data for KYB, authorization, payroll, and business workflows. | Stripe and financial partners; connected payroll provider; vendors. |
| Sensory and identity information | Identity-document images, selfie or likeness, or support recording if collected for verification, fraud prevention, support, and compliance. | Stripe or identity provider; support and compliance vendors. |
| Inferences | Fraud, risk, eligibility, security, and feature-use signals for protection, approval, and improvement. | Stripe, financial partners, security and fraud vendors. |
| Sensitive personal information | Government identifiers, account access data, financial data, precise location if enabled, and verification information used to provide requested services, security, verification, and compliance. | Stripe and financial partners; identity, security, compliance, and infrastructure vendors. |
Cohera does not use or disclose sensitive personal information to infer unrelated characteristics or for purposes that would require a California “Limit the Use of My Sensitive Personal Information” link under the practices described here.
10.2 Financial-information exceptions
Some state privacy laws exempt information governed by the Gramm-Leach-Bliley Act or other financial privacy laws. We evaluate requests under applicable laws rather than treating all financial information as categorically exempt.
11. Children and minors
The Services are for adults acting for a business and are not directed to children. You must be at least 18 to create or control an account. We do not knowingly collect personal information from children under 13. If you believe a child provided information, contact privacy@coheraflow.com.
12. U.S.-only service and data processing
Cohera’s Financial Account and card features are intended and marketed only for eligible users in the United States. Personal information may be processed in the United States and other locations where service providers lawfully operate, subject to appropriate protections and applicable law.
13. Changes to this Policy
We may update this Policy to reflect changes in the Services, vendors, program structure, or law. We will post the updated Policy and revise the “Last updated” date. If changes are material, we will provide additional notice or request consent when required.
14. Contact us
Use the contact channels below for privacy requests, general support, complaints, or legal notices. We may need to verify identity before acting on a request involving account or financial information.