Privacy Policy
01 // Who This Policy Covers
This Privacy Policy explains how MEnterprise Firm Inc., operating publicly as MerchantFirst Payments, collects, uses, discloses, and protects information when you visit mefdup.com, submit a merchant application through apply.mefdup.com, or otherwise interact with our services.
This policy does not cover the privacy practices of third-party processors, acquiring banks, or ISO partners once your application is submitted to them — those parties maintain their own privacy policies governing your processing relationship.
02 // Information We Collect
Information You Provide Directly
- Merchant application data: business name, EIN, business address, owner name, government-issued ID number, date of birth, Social Security number, bank routing and account numbers, processing history, and product/service descriptions
- Contact information: name, email address, phone number, and business website
- Uploaded documents: government ID images, bank statements, voided checks, and other supporting documentation
- Communications: messages sent through our contact form, email, or phone
Information Collected Automatically
- Technical metadata: IP address, browser type, device type, and general location inferred from IP address
- Usage data: pages visited, time on page, and referring URL
- Session data: session tokens used to save and resume an in-progress application
We do not use third-party analytics or advertising trackers on pages where merchant application data is submitted. If analytics tools (such as aggregate traffic measurement) are added to general marketing pages in the future, this policy will be updated to disclose them before they go live.
03 // How We Use Your Information
- To review, prepare, and submit your merchant application to an acquiring bank or ISO partner
- To run pre-submission compliance screening against your business website
- To communicate with you about your application status, account, or support request
- To generate and deliver your signed application record and verification code
- To maintain security, audit logs, and fraud prevention across our systems
- To comply with legal, regulatory, and card brand obligations
We do not use your information for advertising, and we do not sell personal information to third parties.
04 // How We Share Your Information
We share information only as necessary to provide our services:
- Acquiring banks and ISO partners: your application materials are transmitted, encrypted, to the specific partner identified during your application review, for underwriting purposes
- Service providers: we use Supabase (database and document storage), Vercel (application hosting), and Resend (transactional email) to operate our systems — see our Data Security Policy for details on how each is used
- Legal and safety: where required by law, subpoena, or to protect against fraud or harm
- Business transfers: in the event of a merger, acquisition, or asset sale, application data may be transferred as part of that transaction, subject to equivalent confidentiality protections
We do not share your information with data brokers, advertisers, or any party for their own independent marketing use.
05 // Cookies & Similar Technologies
Our site uses functional cookies and session storage necessary for the site and application wizard to work — for example, to keep your in-progress application saved between visits. These are not used for advertising or cross-site tracking.
If we add optional cookies (such as aggregate analytics) in the future, we will update this section and provide a way to decline non-essential cookies before they are set.
06 // Data Retention
Submitted application records are retained for 7 years in accordance with standard ISO partner agreement requirements. Draft applications that are started but never submitted are purged automatically after 90 days of inactivity. Upon a service cancellation or terminated relationship, data is retained for the applicable required period and then purged. Full detail is available in our Data Security Policy.
07 // Your Rights & Choices
Depending on your state of residence, you may have the right to:
- Request access to the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your information, where not otherwise required to be retained by law or ISO partner agreement
- Opt out of any future sale or sharing of personal information (we do not currently sell or share personal information as defined under applicable state privacy laws)
To exercise any of these rights, email cash@mef.money with the subject line “Privacy Request.” We will respond within the timeframe required by applicable law, generally within 45 days.
08 // Children’s Privacy
Our services are directed at businesses and business owners, not children. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected information from a minor, we will delete it promptly.
09 // Data Location & International Transfers
Our infrastructure and service providers operate primarily in the United States (AWS us-east-1 via Supabase). If you are accessing our services from outside the United States, your information will be transferred to and processed in the United States.
10 // Changes to This Policy
We may update this Privacy Policy as our services evolve. Material changes will be communicated by email to active clients and posted on this page with an updated effective date. Continued use of our services after notice of changes constitutes acceptance of the updated policy.
11 // Contact
For questions about this Privacy Policy or to exercise your privacy rights:
MEnterprise Firm Inc. (MerchantFirst Payments)
Warren, Ohio
Email: cash@mef.money
Subject: “Privacy Policy Question”