Lorem ipsum dolor sit amet
Lorem ipsum dolor sit amet wegew wegweg wegweg
Effective Date: June 10, 2021
Last Modified: August 12, 2026
This Privacy Policy describes how BenePass, Inc. ("Benepass," "we," "us," or "our") collects, uses, discloses, and otherwise processes personal information in connection with our websites, mobile applications, administrator portals, employee accounts, benefit payment credentials, reimbursement workflows, support channels, and related products and services (collectively, the "Services").
Benepass provides an employee benefits administration and payment platform for employers, plan sponsors and other sponsoring organizations (each, a "Customer"). If you use the Services through a Customer, the Customer may determine your eligibility, the benefits available to you, and certain purposes for which information is processed.
This Privacy Policy does not create a right to receive any particular benefit, reimbursement, account, card, healthcare item, wellness service, tax treatment, or employment benefit. Eligibility and program rules are generally determined by the applicable Customer, plan documents, program terms, or third-party provider terms.
This Privacy Policy applies to personal information we collect through the Services, including when you visit our website, create or use a Benepass account, access an administrator dashboard, use a mobile application, submit a reimbursement request, use benefit payment credentials, communicate with us, or otherwise interact with Benepass.
This Privacy Policy does not apply to:
If another privacy notice or contract applies to a specific Benepass product, feature, or relationship, that notice or contract may supplement or supersede this Privacy Policy for that context.
Many Benepass users access the Services because a Customer has made one or more benefits available to them. In those cases, Benepass may process personal information as a service provider, processor, or similar role on behalf of the Customer, and may also process certain information as an independent business or controller where permitted or required by law, contract, payment network rules, banking requirements, fraud-prevention obligations, or compliance obligations.
Customers may provide Benepass with participant information such as names, work contact information, employment status, eligibility data, benefit elections or allocations, payroll or deduction information, location, and other information needed to administer the Customer's benefit programs.
Depending on your relationship with Benepass and the Services you use, we may collect the following categories of personal information:
Category | Examples
Identifiers and contact information | such as name, email address, mailing address, phone number, account credentials, employee or participant identifiers, and similar information.
Employment, eligibility, and benefits information | such as employer or sponsoring organization, job-related or eligibility information, benefit allocations, enrollment information, program status, dependent or participant relationship information, and plan-specific information provided by you, a Customer, or another authorized party.
Financial, payment, and transaction information | such as benefit account balances, payment credential activity, card transaction data, reimbursement claims, receipts, merchant information, bank account information, payroll or deduction information, tax-related information, and information needed to verify, approve, deny, fund, recover, or report benefit funds.
Identity, compliance, and fraud-prevention information | such as information used for identity verification, sanctions screening, eligibility checks, fraud monitoring, tax reporting, banking compliance, card network compliance, or similar obligations.
Health, wellness, family, commuter, dependent-care, or other benefit-related information | when you choose to provide it or when it is needed to administer a Customer's benefit program, such as documentation submitted with a reimbursement request or information reflected in a qualifying purchase.
Device, usage, and online activity information | such as IP address, browser type, device identifiers, operating system, referring pages, pages viewed, links clicked, session information, log data, cookies, pixels, and similar technologies.
Communications and support information | such as messages, survey responses, feedback, support tickets, call or chat records, and communications with Benepass representatives.
Inferences and analytics | such as information derived from the above categories to operate, secure, personalize, measure, improve, and develop the Services.
We may collect personal information from:
We may use personal information for the following purposes:
Benepass may use automated tools, rules-based workflows, analytics, and artificial intelligence or machine-learning technologies to help operate, secure, support, and improve the Services. These tools may assist with tasks such as customer support routing, fraud detection, eligibility or documentation review, transaction monitoring, merchant categorization, product analytics, and internal operational efficiency. Where automated tools support reimbursement, transaction, fraud, eligibility, account-access, or documentation workflows, Benepass requires human review before making final adverse determinations where required by law or Benepass policy.
Benepass does not use automated tools to make employment decisions for Customers. Customers remain responsible for their own employment, benefits, plan, payroll, and tax decisions.
We may disclose personal information as described below:
We use cookies, local storage, logs, and similar technologies that are necessary to operate, secure, and provide the Services. In certain jurisdictions, we use consent-management tools to request consent before enabling non-essential analytics, advertising, pixels, software development kits, or similar tracking technologies. You may manage or withdraw your cookie choices through our cookie banner or preference tools where available.
We configure non-essential tracking technologies so they are not intentionally activated unless and until required consent has been obtained.
Some benefit programs may involve information that could be considered sensitive under applicable law, such as health-related information, family-care information, dependent-care information, financial information, government identifiers, precise location, or information that may reveal protected classifications. We use and disclose such information only as reasonably necessary to provide and administer the Services, comply with law, protect the Services, or as otherwise permitted by applicable law.
If a benefit card, reimbursement account, payment credential, or related account is issued to or administered through an accountholder, transactions and submissions made through that card or account will be visible to, and may be discussed with, the accountholder as part of administering the benefit. This may include expenses submitted on behalf of, a spouse, dependent, or other eligible participant.
When an expense is paid for, swiped, or submitted through an accountholder's card or account, transaction, receipt, substantiation, approval, denial, reimbursement, repayment, dispute, audit, or support information may reveal health-related or other personal details, such as a merchant, provider, medication, item, service, expense category, or related documentation. We may use or disclose this information to the accountholder or other parties as reasonably necessary to administer the benefit, process payment or reimbursement, verify eligibility or substantiation, comply with program rules, prevent fraud or misuse, resolve disputes, maintain records, or meet legal, tax, regulatory, payment network, banking, or contractual obligations.
Where HIPAA applies, Benepass uses and discloses protected health information only as permitted by HIPAA and applicable agreements, including for payment and health care operations and proper management and administration of Benepass's services as a business associate, and subject to applicable minimum necessary requirements.
Accordingly, we cannot limit visibility to the reimbursements or disclosures needed to administer a transaction submitted through an accountholder's own card or account. If you do not want an accountholder to have visibility into an expense, you should not submit that expense through the accountholder's benefit card, reimbursement account, or related payment or reimbursement process.
Benepass may receive or process information related to health, wellness, reimbursement, HSA, FSA, HRA, or other tax-advantaged benefit programs. Whether particular information is subject to HIPAA, ERISA, IRS rules, payment network rules, banking rules, or other specialized laws may depend on the product, plan structure, Customer relationship, third-party partner, and applicable agreements.
Benepass has a certain subset of data subject to HIPAA by operation of law and enters into business associate agreements to act as a business associate where required by law. To the extent Benepass processes protected health information as a business associate, or processes other regulated benefit or financial information under a specialized agreement, the applicable agreement and required notices will govern that processing.
You may have choices about marketing communications, cookies, account settings, and certain uses or disclosures of personal information. You can opt out of marketing emails by using the unsubscribe link or contacting us. Even if you opt out of marketing communications, we may still send operational, transactional, administrative, security, legal, tax, reimbursement, account, card, and program-related communications.
Depending on where you live and your relationship with Benepass, you may have rights to request access to, correction of, deletion of, portability of, restriction of, or objection to certain processing of your personal information. You may also have the right to appeal certain decisions or withdraw consent where processing is based on consent.
To exercise applicable privacy rights or submit a privacy request, contact compliance@benepass.com. We may need to verify your identity and authority before responding. We may deny or limit requests where permitted by law, including where information must be retained for legal, tax, security, fraud-prevention, payment, banking, transaction, plan administration, dispute, or audit purposes.
Benepass operates from the United States. If you access the Services from outside the United States, your personal information may be transferred to, stored in, or processed in the United States or other jurisdictions that may not provide the same level of data protection as your jurisdiction.
Where required, Benepass will rely on appropriate transfer mechanisms and safeguards for international transfers of personal information.
We retain personal information for as long as reasonably necessary to provide the Services, administer accounts and benefit programs, comply with legal, tax, accounting, banking, payment, benefits, fraud-prevention, audit, contractual, and regulatory obligations, resolve disputes, enforce agreements, and protect our rights and the security of the Services.
Retention periods may vary by product, Customer relationship, account type, transaction type, benefit program, legal requirement, and the nature of the information.
We use administrative, technical, and physical safeguards designed to protect personal information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for using secure networks and devices when accessing the Services.
The Services are not intended for children under 18, and we do not knowingly collect personal information directly from children under 18 through the Services. Some benefit programs may involve dependents or family members, and Customers or adult users may provide dependent information where necessary to administer a benefit program.
The Services may integrate with or link to third-party services, including Pacific West Bank, Stripe, Celtic Bank, Stripe Payments Company, Fifth Third Bank, Alpaca Securities, Plaid, card issuers, payment processors, payment networks, custodians, broker-dealers, money transmission partners, payroll providers, HRIS providers, merchants, analytics providers, customer-support tools, and other benefit or financial service partners which may be updated from time to time. These third parties may process personal information under their own privacy policies and legal obligations.
Benepass is a financial technology company, not an FDIC-insured bank. Banking services may be provided by Pacific West Bank, Member FDIC; certain card programs may be powered by Stripe and issued by Celtic Bank; money transmission and account services may be supported by Stripe Payments Company with funds held at Fifth Third Bank, N.A., Member FDIC; and investment-related services may involve Alpaca Securities LLC. Product-specific disclosures, account documents, and partner terms may provide additional details.
Sentinel Pension Advisors, LLC (SPA), an SEC-registered investment adviser, is engaged by Benepass to select and monitor the investment options made available through the platform. SPA does not provide individualized investment advice to accountholders or employers. Fund options are reviewed and maintained on an ongoing basis.
Securities brokerage services are provided by Alpaca Securities LLC (dba "Alpaca Clearing"), member FINRA/SIPC, a wholly-owned subsidiary of AlpacaDB, Inc. Technology and services are offered by AlpacaDB, Inc.
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as required by law, such as by posting the updated Privacy Policy, updating the effective date, or providing another appropriate notice.
If you have questions about this Privacy Policy or our privacy practices, please contact us at legal@getbenepass.com.
If you use the Services through a Customer, you may also need to contact the Customer, its plan administrator, benefits team, payroll team, or other designated third party for eligibility, tax, benefits, payroll, plan-specific, or employment-related questions.