Legal

Privacy Policy

Effective date: 1 January 2026  |   Last updated: 1 January 2026

This Privacy Policy describes how brex-business ("we", "us", "our") collects, uses, and shares information about you when you use our corporate cards, expense management, and business banking software. Please read it carefully.

1. Data We Collect

We collect information you provide directly: name, business email, phone number, company name, billing address, tax identification numbers, and payment instrument details.

We automatically collect usage data including IP addresses, browser type, device identifiers, pages visited, and feature interactions within the brex-business platform.

We may also receive data from identity-verification partners, credit bureaus, and financial institutions to assess eligibility and prevent fraud.

2. How We Use Your Data

To provision and operate your brex-business account, process transactions, issue corporate cards, and deliver expense management services.

To comply with applicable financial regulations (KYC/AML), detect fraud, and enforce our Terms of Service.

To send transactional communications, product updates, and—where you have opted in—marketing messages.

3. Cookies & Tracking

We use strictly necessary cookies for authentication and security, functional cookies for preferences, and analytics cookies (e.g., Segment, Amplitude) to understand product usage.

Advertising cookies may be set by our ad partners only with your explicit consent, which you can withdraw at any time via our Cookie Preference Center.

You may also opt out of non-essential tracking by visiting our Cookie Policy at #/cookies.

4. Third-Party Sharing

We share data with banking partners, card network operators (Visa/Mastercard), payment processors, and cloud infrastructure providers solely to deliver our services.

We do not sell your personal information. We may disclose data when required by law, court order, or regulatory authority.

All sub-processors are bound by data processing agreements that require equivalent or greater data-protection standards.

5. Your Rights (GDPR & CCPA)

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your data, subject to legal-retention obligations.
  • Portability: receive your data in a machine-readable format.
  • Objection / Restriction: object to or restrict certain processing activities.
  • Opt-Out of Sale (CCPA): we do not sell data, but you may submit a Do Not Sell request.
  • Non-Discrimination: exercising privacy rights will not affect your access to brex-business services.

6. Data Retention

We retain account and transaction records for a minimum of seven (7) years to satisfy financial-regulatory requirements.

Analytics and marketing data are retained for no longer than twenty-four (24) months from collection, after which they are deleted or anonymised.

7. Security

We employ AES-256 encryption at rest, TLS 1.3 in transit, multi-factor authentication, and role-based access controls.

We maintain a SOC 2 Type II audit programme and conduct annual penetration testing by independent third parties.

In the event of a breach affecting your data, we will notify you within 72 hours as required by applicable law.

8. Children's Privacy

brex-business services are intended solely for businesses and individuals aged 18 or older.

We do not knowingly collect personal information from minors. If we become aware of such data, we will delete it immediately.

9. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email and an in-app notice at least 30 days before taking effect.

Continued use of brex-business services after the effective date constitutes acceptance of the revised policy.

10. Contact & DPO

To exercise your rights or raise a privacy concern, contact our Data Protection Officer at [email protected].

You also have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your EU Member State DPA).

If you have any questions about this Privacy Policy, please contact us at [email protected]. For cookie-related settings, visit our Cookie Policy. This document is governed by the laws of the State of Delaware, USA, and applicable European data-protection regulations.

brex-business

The financial OS built for the way modern businesses move. Cards, banking, and spend management — unified.

Stay ahead of finance

Product updates, fintech insights, and spend intelligence — delivered monthly. No noise.

brex-business.com[email protected]+1 (415) 000-0000100 Market St, San Francisco, CA 94105
© 2026 brex-business. All rights reserved.

brex-business is a financial technology company, not a bank. Banking services are provided by partner financial institutions, Members FDIC. Corporate cards are issued pursuant to a license. All trademarks are the property of their respective owners.