Effective date: 1 January 2026 | Last updated: 1 January 2026
This Privacy Policy describes how brex-business ("we", "us", "our") collects, uses, and shares information about you when you use our corporate cards, expense management, and business banking software. Please read it carefully.
We collect information you provide directly: name, business email, phone number, company name, billing address, tax identification numbers, and payment instrument details.
We automatically collect usage data including IP addresses, browser type, device identifiers, pages visited, and feature interactions within the brex-business platform.
We may also receive data from identity-verification partners, credit bureaus, and financial institutions to assess eligibility and prevent fraud.
To provision and operate your brex-business account, process transactions, issue corporate cards, and deliver expense management services.
To comply with applicable financial regulations (KYC/AML), detect fraud, and enforce our Terms of Service.
To send transactional communications, product updates, and—where you have opted in—marketing messages.
We share data with banking partners, card network operators (Visa/Mastercard), payment processors, and cloud infrastructure providers solely to deliver our services.
We do not sell your personal information. We may disclose data when required by law, court order, or regulatory authority.
All sub-processors are bound by data processing agreements that require equivalent or greater data-protection standards.
We retain account and transaction records for a minimum of seven (7) years to satisfy financial-regulatory requirements.
Analytics and marketing data are retained for no longer than twenty-four (24) months from collection, after which they are deleted or anonymised.
We employ AES-256 encryption at rest, TLS 1.3 in transit, multi-factor authentication, and role-based access controls.
We maintain a SOC 2 Type II audit programme and conduct annual penetration testing by independent third parties.
In the event of a breach affecting your data, we will notify you within 72 hours as required by applicable law.
brex-business services are intended solely for businesses and individuals aged 18 or older.
We do not knowingly collect personal information from minors. If we become aware of such data, we will delete it immediately.
We may update this Privacy Policy periodically. Material changes will be communicated via email and an in-app notice at least 30 days before taking effect.
Continued use of brex-business services after the effective date constitutes acceptance of the revised policy.
To exercise your rights or raise a privacy concern, contact our Data Protection Officer at [email protected].
You also have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your EU Member State DPA).
If you have any questions about this Privacy Policy, please contact us at [email protected]. For cookie-related settings, visit our Cookie Policy. This document is governed by the laws of the State of Delaware, USA, and applicable European data-protection regulations.
The financial OS built for the way modern businesses move. Cards, banking, and spend management — unified.
Stay ahead of finance
Product updates, fintech insights, and spend intelligence — delivered monthly. No noise.
brex-business is a financial technology company, not a bank. Banking services are provided by partner financial institutions, Members FDIC. Corporate cards are issued pursuant to a license. All trademarks are the property of their respective owners.