Legal

Privacy Policy

Last updated: March 2026

I. General provisions

Yerba LLC (Money Services Business, FinCEN registry 31000318247837, Montana, United States of America) (the "Company," "we," "us," or "our") facilitates the transmission of orders through its platform and API services (together, the "Services"). This Privacy Policy (the "Policy") applies to any personal data you provide to us as an applicant, current customer, or former customer, and to your use of the Services. It explains how we collect, use, disclose, and protect your personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation or "GDPR"), applicable U.S. federal and state privacy laws including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and U.S. financial-privacy laws such as the Gramm-Leach-Bliley Act (GLBA).

The Company is committed to protecting your personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. We implement and maintain appropriate legal, organizational, technical, and physical security measures to safeguard your information. By using our Services, you confirm you have read, understood, and agree with this Policy.

II. Personal-data management principles

III. Lawfulness of processing

Your personal data will be processed on one or more of the following legal grounds: consent; contractual necessity; legal obligation (e.g., Anti-Money Laundering (AML) and Know Your Customer (KYC) requirements); and legitimate interests, except where overridden by your interests or fundamental rights.

IV. Purposes for processing

V. How we collect your data

We collect personal data when you register for and use our Services, complete identity-verification procedures (including through third-party services), link bank or other financial accounts, contact support, or use our platform via browser cookies. We also receive data from authorized third parties such as identity-verification services, financial institutions, and public databases, to fulfill our legal and business obligations.

VI. Categories of data we process

VII. Recipients and international transfers

Your personal data may be shared with service providers, financial institutions and payment partners, identity-verification and screening services, affiliates, and governmental or law-enforcement authorities where required by law, and in connection with a business transfer.

Our data is hosted and processed on servers located in the United States. Where personal data of individuals in the European Economic Area (EEA) is transferred outside the EEA, such transfer is made under the Standard Contractual Clauses approved by the European Commission, complemented by additional measures as appropriate under a transfer-impact assessment.

VIII. U.S. Gramm-Leach-Bliley Act (GLBA) notice

For U.S. customers, this notice explains how we collect, use, and share your nonpublic personal information (NPI). Financial companies share customers' personal information to run their everyday business; the table below summarizes our sharing.

Reasons we can shareDo we share?Can you limit?
Everyday business purposes — process transactions, maintain accounts, respond to legal processYesNo
Our marketing purposesYesNo
Joint marketing with other financial companiesNoWe don't share
Affiliates' everyday business purposesYesNo
Affiliates / nonaffiliates to market to youNoWe don't share

IX. Data retention

We retain your personal data only as long as necessary. To comply with AML and anti-fraud obligations, we retain account and transaction data for at least five (5) years after the termination of your relationship with us, after which it is securely deleted or anonymized.

X. Information security

XI. Children's privacy

Our Services are not intended for individuals under 18. We do not knowingly collect data from children, and will remove such data if collected without verified parental consent.

XII. Your GDPR rights (EEA)

You have rights of access, rectification, erasure, restriction, data portability, and objection. Exercise them by contacting Support@yerba.global. We respond within one month, extendable for complex requests.

XIII. Your U.S. state privacy rights

Residents of California, Colorado, Virginia and other states may have rights to know/access, delete, correct, and opt out of sale/sharing. We do not "sell" or "share" personal information for cross-context behavioral advertising as defined under the CCPA/CPRA. To exercise these rights, contact Support@yerba.global.

XIV. Contact

Questions about this Policy, or to exercise your rights, contact our Data Protection point of contact at Support@yerba.global. For formal notices: Yerba LLC, 1001 South Main Street, Kalispell, MT 59901, United States.