on Carousel Inc. ("Carousel", "we", "our", "us") provides application and verification infrastructure used by businesses across industries — leasing and property management, lending and private credit, auto finance, equipment leasing, merchant and marketplace onboarding, and insurance — to collect applications and run identity, credit, background, court-record, income, and bank-account verifications through licensed third-party providers. This Privacy Policy explains how we collect, use, share, and protect personal information across our websites, hosted application portals, forms, verification flows, and communications, including SMS and email (the "Platform").
Capitalized terms not defined here have the meanings in our Terms & Conditions, including "Application", "Requesting Party", "Verification Step", "Applicant-Owned Application", "Customer-Sponsored Application", and "Carousel Verified".
1. Our Role Depends on Who Owns the Application
The Platform supports two engagement models, and our responsibilities under privacy law differ between them. The model that applies to your Application is disclosed in the application flow.
| Applicant-Owned Application (you pay, you own) | Customer-Sponsored Application (the Requesting Party pays and owns) | |
|---|---|---|
| Carousel's role | Carousel decides how your Application data is processed to provide you the service — we act as the organization responsible for your information (a "controller"). | The Requesting Party controls the Application record; Carousel processes it on the Requesting Party's documented instructions as its service provider ("processor"). |
| Who to contact about your data | Carousel, at privacy@oncarousel.com. | The Requesting Party first. We will assist them, and if you contact us we will redirect your request and notify them. |
| Deletion | You can ask Carousel to delete your Application, subject to legal retention duties. | The Requesting Party decides on deletion of the Application record; Carousel deletes on their instruction, subject to records we must keep (billing, audit, dispute-resolution, legal). |
Regardless of model, Carousel is always the responsible organization ("controller") for: your Carousel Verified record (created only with your consent and maintained under our direct relationship with you), our own websites and marketing pages, platform security and fraud-prevention data, and billing records.
2. Information We Collect
a. Identity information
- Name, date of birth, current and prior addresses, email, phone number;
- Government-issued ID documents and the data extracted from them;
- Biometric information, where an identity Verification Step or Carousel Verified is used: facial geometry derived from your ID photo and selfie for face match and liveness detection (see Section 6).
b. Application and financial information
- Information you enter in application workflows: employment, income, residence history, references, questionnaire answers, and documents you upload;
- Consumer reports and background information obtained with your authorization from licensed providers: credit reports, court records, and eviction-related records;
- Bank-account, balance, transaction, income, and employment data retrieved through a data aggregator with your authorization (your banking credentials go to the aggregator, not Carousel);
- Payment information when you pay Carousel (processed by our payment processor; we do not store full card numbers).
c. Technical and usage data
- IP address, device and browser information, session behavior, log data, and fraud-prevention signals.
d. Communications
- SMS messages, emails, and other correspondence with Carousel.
3. How We Use Information
- Operate the Platform and process, assemble, and deliver your Application to the recipients you or the Requesting Party designate;
- Run the Verification Steps configured for your Application, through third-party providers, with your consent;
- Create and maintain your Carousel Verified record, where you have enrolled, and recognize you on later applications;
- Communicate with you about your Application and its status, including transactional SMS (one-time passcodes, verification and status updates);
- Process payments, invoice, and maintain billing and audit records;
- Secure the Platform, prevent and investigate fraud and misuse;
- Comply with legal and regulatory obligations and establish, exercise, or defend legal claims.
We do not use your Application data to build marketing profiles, and we do not use automated decision-making to decide your Application — decisions are made by Requesting Parties.
4. Consumer Reports and Credit Information
Where a Verification Step involves a consumer report (for example, credit or eviction records), the report is produced by a licensed consumer reporting agency or comparable regulated provider and obtained only with your authorization given in the flow, for the permissible purpose disclosed there. Carousel is not a consumer reporting agency and does not make decisions about you. If you dispute the accuracy or completeness of a report, you may do so directly with the agency that produced it; we will identify the source of any Verification Result on request. If a Requesting Party takes adverse action based on a report, that party is responsible for the legally required notices, which will identify the reporting agency and your dispute rights.
5. Sharing Information
Carousel does not sell or rent personal information, and does not share it for cross-context behavioral advertising. We share personal information only with:
- The Requesting Party or Parties your Application is directed to — by the sponsoring Requesting Party's configuration (Customer-Sponsored) or at your direction (Applicant-Owned);
- Verification and infrastructure providers (our sub-processors) listed below;
- Professional advisors (auditors, insurers, counsel) under confidentiality;
- Authorities, where required by law, subpoena, or court order, or to protect rights, safety, or the integrity of the Platform;
- A successor entity in a merger, acquisition, financing, or sale of assets, with notice where required.
All service providers are bound by contract to safeguard your data and use it only to provide their services.
Our verification and infrastructure providers include identity-verification, credit-reporting, background and court-record, bank-data, payment-processing, SMS, and cloud-hosting providers. A current list of our providers is available on request at privacy@oncarousel.com.
6. Biometric Information and Carousel Verified
This section is our written biometric policy, including our public retention and destruction schedule.
- What is collected and why. When an identity Verification Step runs, our identity-verification provider derives facial geometry from your ID photo and your selfie solely to confirm the ID is yours and that you are a live person. If you enroll in Carousel Verified with your separate, explicit written/electronic consent, a biometric reference is retained so you can verify by face scan alone on later applications. Biometric identifiers are processed and stored by our identity-verification provider on Carousel's behalf; Carousel does not store raw biometric identifiers on its own systems.
- Consent. We collect biometric identifiers only after informing you in writing of what is collected, the purpose, and the retention period, and obtaining your written/electronic release, as required by applicable biometric-privacy laws (including Illinois BIPA, Texas CUBI, Washington HB 1493, and Québec Law 25, which also requires disclosure to the Commission d'accès à l'information before a biometric database is put into service, with which Carousel complies).
- No sale; no profit. We never sell, lease, trade, or otherwise profit from biometric information, and we disclose it only to the verification provider processing it on our behalf or with your consent.
- Retention and destruction schedule. (a) If you do not enroll in Carousel Verified: biometric data is used for the verification and permanently destroyed no later than thirty (30) days after the Verification Step completes. (b) If you enroll: your biometric reference is retained while your enrollment is active and permanently destroyed upon the earliest of (i) your withdrawal or deletion request, (ii) the expiry of the government-issued ID document underlying your verified record, (iii) where the law of your jurisdiction requires it (including Illinois), three (3) years after your last interaction with Carousel, or (iv) when the purpose of collection has been satisfied. Destruction covers Carousel's systems and our provider's, using secure deletion methods.
- Withdrawal. Withdraw and delete your Carousel Verified record at any time via privacy@oncarousel.com or in-Platform. Your record is independent of any Requesting Party and survives their deletions — but never survives your own deletion request, except records we must keep by law.
7. SMS Communications (Consent and Compliance)
a. How you consent
You opt in to SMS in our application portal: you enter your phone number, a "Get Verification Code" call-to-action appears, and beneath it we display: "By providing your number, you agree to receive transactional texts from Carousel (e.g., status updates, codes). Msg & data rates may apply. Reply STOP to opt out." Our Terms & Conditions and this Privacy Policy are linked in the page footer.
b. Message purpose
All messages are strictly transactional: one-time passcodes, application status updates, and reminders or follow-ups you trigger. We send no marketing texts and use no purchased number lists.
c. Frequency and opt-out
Frequency depends on your activity; message and data rates may apply. Reply STOP to opt out, HELP for help, or contact privacy@oncarousel.com.
d. Provider
SMS is delivered via Twilio in compliance with applicable carrier and A2P messaging requirements. Mobile information is not shared with third parties for marketing purposes; opt-in data and consent are not sold or shared.
8. Where Data Is Stored; Cross-Border Transfers
Our primary hosting region is AWS Canada (ca-central-1). For US-based deployments, data may be hosted in a US AWS region. Some providers (for example, payment processing and SMS delivery) process data in the United States. Where personal information is transferred outside your jurisdiction, we use contractual and technical safeguards and, where required (including under Québec Law 25), conduct a privacy impact assessment before the transfer.
9. Security
We maintain industry-standard safeguards, including encryption in transit and at rest, role-based access control, network isolation, secure cloud infrastructure, logging, and regular audits and compliance reviews. No system is perfectly secure; if a breach creates a risk of serious harm, we will notify you and the relevant regulators as required by law (including Québec's Commission d'accès à l'information and other applicable authorities).
10. Retention
We retain personal information only as long as needed to deliver the services, meet legal and regulatory requirements, resolve disputes, and enforce agreements. Application data in Customer-Sponsored Applications is retained per the Requesting Party's instructions and our agreement with them; we may retain limited records needed for invoicing, billing audit, and dispute resolution after deletion of the underlying Application. Biometric data follows the schedule in Section 6, which prevails over this general section. When data is no longer needed, we delete or irreversibly anonymize it securely.
11. Your Rights
Depending on where you live, you may have the right to: access a copy of your personal information; correct inaccurate or incomplete data; delete your data; withdraw consent (including SMS consent and Carousel Verified enrollment) at any time; receive computerized personal information in a structured, portable format; and complain to your privacy regulator (in Québec, the Commission d'accès à l'information; in Canada federally, the Office of the Privacy Commissioner; in US states, your Attorney General or privacy agency).
- How to exercise rights. Email privacy@oncarousel.com. We verify your identity, respond within the time required by your jurisdiction's law (30 days in Québec), and do not discriminate against you for exercising rights.
- Customer-Sponsored Applications. Where the Requesting Party controls your record, we will forward your request to them and assist their response.
- US state residents (including California, Colorado, Connecticut, Texas, Virginia): you have the rights of access, correction, deletion, and portability described above; we do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we treat authorized-agent requests as required. Sensitive personal information (ID numbers, biometric data, financial data) is used only for the purposes described here, consistent with CPRA limits.
- Consumer-report data. Rights to dispute report contents run against the producing agency, per Section 4.
12. Children's Privacy
The Platform is for adults. We do not knowingly collect or process data from anyone under 18. If we learn we hold a child's personal data, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy periodically. Updates are posted here with a revised effective date; for material changes we will notify you directly (email or in-Platform) and, where required, seek renewed consent.
14. Contact Us; Privacy Officer
Our designated Privacy Officer (personne responsable de la protection des renseignements personnels, per Québec Law 25) is Charles Papazian.
on Carousel Inc.
5101 rue Buchan, Montréal, Québec, Canada
Email: privacy@oncarousel.com