PayPerMerchant.ioGet Leads

Legal

PrivacyPolicy

PayPerMerchant sells merchant cash advance leads. Selling a lead is a sale of personal information under California law, so this page uses the word sale and explains how to stop it.

Effective
August 28, 2026
Last updated
August 28, 2026
Review cycle
Every 12 months

Draft. Attorney review required before launch.

This policy was drafted from statute and regulation text and has not been reviewed by counsel. It is not legal advice. Values that are not yet settled are shown as a redaction bar marked Launch gate, with the law that requires each one named in the page source. Every one of them has to be filled before this page goes live.

What we are
A lead generation company. Not a lender, funder, broker, ISO or payment processor. We make no credit decision of any kind.
What we sell
Merchant cash advance applications, to funders, ISOs and broker shops, for money.
Is that a sale
Yes. Cal. Civ. Code 1798.140(ad)(1) makes a transfer for valuable consideration a sale, and no small business exemption reaches it. This page says sale, not sharing.
How many buyers
One. A merchant record goes to exactly one buyer and is not resold afterwards.
What this site collects
Nothing you type. This website has no forms, no analytics, no advertising pixels, no session recording and no third party JavaScript of any kind.
How to opt out
Two ways, and both work: send a Global Privacy Control signal from your browser, or use the Do Not Sell or Share My Personal Information page.

1. Who we are, and what this policy covers

This policy explains how Tishin Wealth Group LLC, a Launch gate L4: state of formation limited liability company doing business as PayPerMerchant (we, us, our), collects, uses, discloses and sells personal information. Our place of business is Brooklyn, NY.

This policy covers this website, paypermerchant.io. It also describes what we do with the personal information contained in the merchant applications we sell, because that is the whole of our business and a privacy policy that left it out would be describing somebody else.

It does not cover the properties where merchants actually apply, or the separate site where buyers book a call. Each of those displays its own notice at collection next to the fields, as 11 CCR 7012(c)(2) and 7012(d) require, and each discloses the trackers running on it. This website runs none, so nothing written here would describe them.

Launch gate L15: published notice at collection for every funnel property

2. What this website collects, and why there is no cookie banner

This website has no forms and collects nothing you type. There is no quote form, no newsletter box, no chat widget and no account. The only record of your visit is the standard server log our hosting provider keeps: IP address, browser user agent, the URL requested and the time it was requested. Those logs exist to serve the page and to keep the site up.

This site loads zero third party JavaScript. No analytics, no advertising pixel, no conversion tag, no session recording, no heat map, no font content delivery network, no embedded video. Nothing on this page sends your visit to another company. That is unusual for a site in this category and it is a deliberate choice, not an oversight.

So there is no cookie banner, and there should not be one. Nothing here sets an advertising, analytics or session recording cookie. No United States law requires a banner, and 11 CCR 7026(a)(4) states that a cookie banner is not by itself an acceptable method for submitting a request to opt out of sale or sharing. A banner on this page would collect consent we do not need, for tracking we do not run, through a mechanism the regulator has already said does not work.

Browser Do Not Track. This site does not respond to browser Do Not Track signals. Cal. Bus. and Prof. Code 22575(b)(5) requires us to say what we do, not to honor the signal. We do process Global Privacy Control signals, which is a different mechanism and is described in section 11.

Cross site collection by others. Because this website loads no third party code, no third party collects personally identifiable information about your online activities over time and across different websites through this site. Cal. Bus. and Prof. Code 22575(b)(6) requires that statement either way.

3. What a merchant application contains

A merchant application is the record we sell. The categories below use the statutory names in Cal. Civ. Code 1798.140(v)(1), because 11 CCR 7011(e)(1)(A) requires them. Categories we do not collect are not listed: over disclosing is not the safe option, it is an inaccurate policy.

Personal information in a merchant application, by statutory category
Statutory categoryWhat is in itSold to a buyer
A. IdentifiersOwner name, business name, business postal address, email address, telephone number, and the IP address the application was submitted from.Yes, except the IP address
B. Customer records, Cal. Civ. Code 1798.80(e)Name, address and telephone number together with business financial information: the amount of capital requested, annual revenue, monthly deposits, and the credit band the owner reports.Yes
D. Commercial informationThe financing the merchant asked about and the use of funds described.Yes
F. Internet or network activityThe page the application was submitted from, the campaign and click identifiers attached to it, the browser user agent, and the timestamp.No. Retained as part of the consent record
G. Geolocation dataThe state the business operates in, and approximate location derived from the IP address. We do not collect precise geolocation.The state, yes. The IP derived location, no
I. Professional or employment informationRole in the business, industry, time in business, number of open financing positions, and whether the file carries defaults, liens or bankruptcies.Yes

Where it comes from. Two sources and no others. The merchant gives it to us directly on one of our own advertising properties, and the rest is captured automatically from the submission itself. We do not buy, append, enrich, co-register or otherwise acquire lead data from third party data providers. Every record we sell was typed by the person it describes, on a form we ran the ads for.

4. Why we collect it

  1. To sell it to a funder, an ISO or a broker shop. This is the primary purpose and it is the entire source of our revenue.
  2. To check that the contact details entered are reachable, including email deliverability and telephone line type, at the moment of submission.
  3. To communicate with the merchant about the application submitted.
  4. To detect and prevent fraudulent, duplicated and automated submissions.
  5. To keep the consent, do not call and opt out records the law requires.
  6. To operate, secure and measure our own advertising and our own systems.

Why we sell it: to connect the merchant with a funder who may advance capital, and to be paid a fee by that funder for the introduction.

5. We sell personal information. That is the business.

We sell the personal information described in section 3, and we are paid for it. Under Cal. Civ. Code 1798.140(ad)(1) a sale is the transfer of a consumer's personal information to a third party for monetary or other valuable consideration. Lead buyers set their own purposes and are not bound by service provider restrictions, which makes them third parties under 1798.140(ai). The California Privacy Protection Agency's own regulations use a marketing company delivering consumer records to its clients as the worked example of a sale, at 11 CCR 7026(f)(3)(B).

No small business exemption helps here. Cal. Civ. Code 1798.140(d)(1)(C) covers any for profit business deriving 50 percent or more of its revenue from selling personal information, with no revenue threshold and no consumer count threshold. We are covered from the first dollar.

Terms of the sale, plainly. The buyer pays us $60 per lead. The merchant pays nothing, and nothing we are paid depends on whether the merchant is approved or funded. One merchant record goes to exactly one buyer, and it is not resold to a second buyer afterwards.

Categories sold, and the categories of third parties they are sold to
Category soldCategories of third parties
A. IdentifiersMerchant cash advance funders, independent sales organizations and broker shops
B. Customer recordsThe same
D. Commercial informationThe same
I. Professional or employment informationThe same

The buyers, by name. R.I. Gen. Laws 6-48.1-3(a)(2) requires us to identify every third party we have sold to or may sell to, with no volume threshold. Oregon and Connecticut give a consumer the right to the specific third parties, not just the categories. The Federal Trade Commission's MediaAlpha order defines informed consent as requiring the names of all entities to whom the information is disclosed.

Launch gate L7: buyer roster page, every buyer by exact legal entity name

What we do not do. We do not share personal information for cross context behavioral advertising from this website, because this website runs no advertising technology. We do not sell personal information to data brokers, list brokers, aggregators or ping trees.

6. Service providers, and other disclosures

Separately from the sale described above, we disclose personal information to service providers under written contracts that restrict what they may do with it. The categories are: hosting and infrastructure, email delivery, telephone and text message delivery, contact verification, calendar and scheduling, and professional advisors including counsel and accountants.

We also disclose personal information where we are required to by law or legal process, to protect our rights, safety or property, and in connection with a merger, acquisition, financing or sale of assets.

7. How long we keep it, and how we protect it

Cal. Civ. Code 1798.100(a)(3) and 11 CCR 7012(e)(4) require a retention period stated per category, or the criteria used to set it. Two of these periods are fixed by federal rule and cannot be shortened by preference. The rest are not yet set.

Retention by category
RecordHow long
Consent records, including the consent text as it was displayedAt least 5 years. 16 CFR 310.5(a) sets the minimum, and 310.5(a)(8)(ii) requires a copy of the consent request in the same manner and format in which it was presented
Do not call records and opt out recordsAt least 5 years. 47 CFR 64.1200(d)(6)
Identifiers, customer records, commercial and professional informationLaunch gate L8: retention period, set with counsel
Server logs and network activityLaunch gate L8: retention period, set with counsel

Security. We maintain administrative, technical and physical safeguards designed to protect personal information. No method of transmission or storage is completely secure and we cannot guarantee absolute security.

8. Sensitive personal information

This section is not finished, and saying so is better than guessing. Whether a merchant application contains sensitive personal information turns on one unresolved question: whether bank statements travel with the application, and whether the account numbers on them are redacted before the record is transferred.

The answer decides three separate legal outcomes. Md. Com. Law 14-4607(a)(2) is an absolute ban on selling sensitive data with no consent exception. Connecticut counts financial account numbers as sensitive and bans the sale without consent. Tex. Bus. and Com. Code 541.102(b) requires a controller that sells sensitive personal data to post the exact sentence it prescribes, in the same location and the same manner as this notice, and 541.107 applies that duty even to businesses otherwise exempt as small businesses.

Launch gate L13: do bank statements travel with a lead, and are account numbers redacted

What we can state now: we do not ask a merchant for a Social Security number or pull a consumer credit report on our application forms. The credit figure in a lead is a band the owner reports, not a credit file we obtained.

9. Your privacy rights

Depending on where you live, you may have the right to do each of the following. These rights are subject to verification and to the exceptions in the applicable statute.

  • Know and access what personal information we collect, use, disclose and sell.
  • Delete personal information we collected from you.
  • Correct personal information that is inaccurate.
  • Opt out of the sale or sharing of your personal information. This is the right most people are looking for and it has its own page: Do Not Sell or Share My Personal Information.
  • Limit the use and disclosure of sensitive personal information, where we process any. See section 8.
  • Obtain the specific third parties to whom we disclosed your personal information, if you live in Oregon, Connecticut or another state that grants that right.
  • Appeal a denial of any request.
  • Not be discriminated against for exercising any of these. We will not deny you service, charge a different price or provide a different quality of service because you exercised a privacy right.

10. How to exercise your rights

11 CCR 7026(a)(1) and Tex. Bus. and Com. Code 541.055(a) both require at least two ways to submit a request. Ours are below.

Ways to submit a request
MethodWhere
Opt out of the sale of your informationThe Do Not Sell or Share page, or a Global Privacy Control signal from your browser
Know, delete, correct, appealLaunch gate L11: rights request form URL and appeal method
EmailLaunch gate L1: privacy email address on the brand domain
Telephone or postLaunch gate L2: toll free number or second request method Launch gate L3: serviceable mailing address

Verification. We will ask for information that lets us reasonably confirm you are the person the record describes, normally the email address and telephone number on the application. We will not use it for anything else.

Timing. We confirm receipt within 10 business days and respond within 45 calendar days, extendable once by a further 45 days with notice. A request to opt out of sale or sharing is honored as soon as feasibly possible and no later than 15 business days, under 11 CCR 7026(f)(1). Where we can stop instantly we must, so the 15 days is a ceiling and not a schedule.

Downstream notification. When you opt out, 11 CCR 7026(f)(2) requires us to notify every third party we sold your information to between the moment you asked and the moment we complied, direct them to comply, and direct them to forward the request onward. We do that.

The part most people misunderstand. A funder that already received your application holds its own copy. Opting out with us stops future sales; it does not erase that copy or stop that company contacting you. Contact them directly, using the buyer roster referenced in section 5.

Authorized agents. You may appoint an agent to submit a request for you. We will ask for written permission signed by you and may ask you to verify your own identity.

11. Opt out preference signals and Global Privacy Control

We treat a Global Privacy Control signal as a valid request to opt out of the sale and sharing of personal information. 11 CCR 7025(b) makes processing the signal mandatory for any business that sells personal information, and 7025(e) forecloses the argument that posting a Do Not Sell link is an alternative to it. A link and a signal are both required, not either.

How it is honored. The signal is read on the server, from the request header, on every request to this website and to our funnel properties. Each signal is logged with its timestamp. Where the signal is present at the moment an application is submitted, that submission is flagged as opted out of sale before it is routed to any buyer, which means the record is never sold rather than being sold and then recalled.

Launch gate L10: server side signal processing, the signal log and the downstream notification pipeline

Scope of the signal. Under 11 CCR 7025(c)(1) it is valid for the browser or device that sent it and any profile tied to that browser or device, including a pseudonymous one. Being tied to a browser, it may not reach information collected on another device unless you are identifiable to us.

12. Telephone calls and text messages

A merchant who submits an application gives consent to be contacted at the point of submission, on the property where the application was submitted, in a disclosure displayed next to the button that submits it. That consent is what allows us and the buyer to call or text. Consent is never a condition of obtaining any financing.

Launch gate L12: the consent record retained with each lead, field by field

Revoking consent. 47 CFR 64.1200(a)(10) lets you revoke by any reasonable method. In reply to a text, the words stop, quit, end, revoke, opt out, cancel or unsubscribe are all effective, and so is any other wording a reasonable person would read as a request to stop. You can also tell any caller to put you on the do not call list. We do not designate an exclusive means of revoking, because the rule forbids it. We honor a revocation within 10 business days and keep our internal do not call list for at least 5 years, as 47 CFR 64.1200(d)(6) requires.

Launch gate L14: whether any call is recorded

13. Minors

Our properties are business to business and are not directed to anyone under 18. A merchant application requires an owner of an operating business. We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age. That sentence is required by 11 CCR 7011(e)(1)(G). Connecticut separately bans the sale of the data of anyone aged 13 to 17 with no consent cure, so our forms are gated at 18.

14. State disclosures

We build to the strictest common standard nationwide rather than rendering a different policy per state. The items below are the ones that differ enough to name.

  • California. The rights in section 9 and the opt out in section 11 are the CCPA and CPRA rights. We are a business under Cal. Civ. Code 1798.140(d)(1)(C).
  • Nevada. A Nevada resident may submit a verified request to opt out of the sale of covered information under NRS 603A.345. We respond within 60 days, extendable by 30.
  • Texas. Two request methods, an appeal right, and, if section 8 resolves that we sell sensitive data, the notice Tex. Bus. and Com. Code 541.102(b) prescribes word for word.
  • Rhode Island. The third parties we have sold or may sell personal information to are identified on the buyer roster referenced in section 5, under R.I. Gen. Laws 6-48.1-3(a)(2).
  • Oregon and Connecticut. You may request the specific third parties we disclosed your personal data to, not merely the categories.

Data broker registration. Cal. Civ. Code 1798.99.80(c) defines a data broker as a business that knowingly collects and sells the personal information of a consumer with whom it does not have a direct relationship, and 11 CCR 7601, effective January 1 2026, says that collecting information directly from a consumer is not by itself enough to create one. Deletion request processing under the Delete Act became mandatory on August 1 2026. Registration costs 6,000 dollars a year in California and the penalty for operating unregistered is 200 dollars a day. Vermont, Texas and Oregon run their own registers, and in Oregon registration is a precondition of operating at all.

Launch gate L9: the data broker registration decision, California, Vermont, Texas, Oregon

15. Changes to this policy, and how to reach us

We may update this policy. The revised version is posted here with a new last updated date, which is the effective date of the change. Cal. Bus. and Prof. Code 22575(b)(3) requires us to describe how we notify you of a material change, and we will post the revised policy on this page at least 10 days before a material change takes effect. We review this policy at least once every 12 months, as Cal. Civ. Code 1798.130(a)(5) requires.

Tishin Wealth Group LLC, Brooklyn, NY.

Launch gate L1: privacy email address on the brand domain Launch gate L3: serviceable mailing address