Privacy & Policies FinovatePro Customer Onboarding & Due Diligence Policy

FinovatePro Customer Onboarding & Due Diligence Policy

FinovatePro Customer Onboarding & Due Diligence Policy Version 1.1 — Approved by Executive Management Effective Date: November 15, 2025 1. Purpose The purpose of this policy is to define the standards and procedures for onboarding, verifying, and monitoring business customers who use the FinovatePro platform. These procedures ensure that:
  • Only legitimate, low-risk, and identifiable organizations gain access to the platform
  • Customer data—including financial account data accessed via Plaid—is used in a lawful, authorized, and transparent manner
  • Risk exposure is minimized in accordance with industry expectations for business accounting software
  • FinovatePro complies with applicable privacy and data protection requirements, contractual commitments, and Plaid’s data access framework
2. Scope This policy applies to:
  • All new business customers using FinovatePro
  • All customers who access or request financial data through Plaid
  • All processes related to customer verification, acceptance, and ongoing monitoring
  • All FinovatePro staff or systems involved in evaluating customer eligibility
This policy does not apply to anonymous end users or consumers; FinovatePro only onboards verified business entities. 3. Customer Information Collected During Onboarding To validate business identity and determine eligibility, FinovatePro collects and verifies the following information:
  • Legal business name and registration information
  • Business address and verifiable contact details
  • Primary authorized representative’s name, title, phone number, and email
  • Industry classification (e.g., NAICS code)
  • Nature of business operations
  • Intended use of FinovatePro products and data access features
  • Confirmation of agreement to all FinovatePro terms and disclosures
FinovatePro may request additional documentation where appropriate, including:
  • Business formation documents
  • Tax identification (EIN)
  • Proof of authority for the representative
  • Other documentation relevant to verification
The level of documentation required may vary based on assessed risk. 4. Mandatory Agreements & Acceptances Before a business account is activated, customers must review and electronically accept:
  • FinovatePro Terms of Service
  • FinovatePro Privacy Policy
  • FinovatePro Acceptable Use Policy
  • FinovatePro Data Access & Authorization Disclosure
  • Acknowledgment of the Plaid End User Privacy Policy (incorporated by reference)
Access to FinovatePro is not provisioned until all agreements are accepted. 5. Customer Due Diligence (CDD) FinovatePro conducts a risk-based due diligence review to confirm that each prospective customer is:
  1. Legitimate — A real, verifiable, legally registered business
  2. Identifiable — Able to provide clear business and representative information
  3. Low-risk — Operating in an industry appropriate for accounting software usage
  4. Compliant — Aligned with FinovatePro’s Terms, Acceptable Use Policy, and Plaid’s requirements
5.1 Prohibited or Restricted Business Categories FinovatePro does not onboard businesses operating in high-risk or inappropriate sectors, including but not limited to:
  • Gambling or online gaming
  • Cannabis, CBD, or controlled substances
  • Adult content or adult-related services
  • Unregulated financial activities
  • Anonymous or unverifiable merchants
  • High-risk money movement or payment facilitation services
  • Cryptocurrency exchanges, mixers, or unlicensed virtual-asset businesses
  • Businesses operating in sanctioned or restricted jurisdictions
Prospective customers that fall into these categories are not approved. 6. Ongoing Monitoring & Compliance Oversight FinovatePro maintains ongoing monitoring of customer accounts to identify:
  • Changes in business activity or risk profile
  • Potential violations of the Acceptable Use Policy
  • Misuse or inappropriate access to Plaid-derived financial data
  • Indications of unauthorized, fraudulent, or unusual behavior
  • Abuse of platform features or violations of stated use cases
Monitoring is continuous and risk-based. FinovatePro may request re-verification or additional information if concerns arise. 7. Suspension, Restriction, and Termination FinovatePro may suspend or terminate a customer’s access if:
  • The business becomes high risk or no longer meets eligibility criteria
  • The customer provides false, misleading, or incomplete information
  • The customer misuses or attempts to misuse Plaid-derived data
  • There is evidence of activities inconsistent with FinovatePro’s policies
  • Required agreements or compliance obligations are violated
  • Requests for features or behaviors indicate prohibited intent
Suspension or termination decisions are documented and reviewed by management. 8. Recordkeeping & Documentation FinovatePro retains onboarding, verification, and due diligence records for a minimum of seven (7) years unless a longer period is required under applicable laws or contractual obligations. Records include:
  • Customer identity and business information
  • Documentation used for verification
  • Agreement acceptances
  • Notes related to due diligence review
  • Monitoring and compliance actions
Records are securely stored and accessible only to authorized personnel. 9. Governance, Review, and Policy Maintenance This policy is reviewed annually or more frequently if required due to:
  • Changes in regulatory expectations (e.g., CFPB 1033 rulemaking)
  • Updated Plaid requirements
  • Changes in FinovatePro’s products or risk exposure
  • Industry best practice updates
  • Internal or external audit recommendations
Updated policies are approved by Executive Management prior to implementation.

Need Help?

If you have questions about this policy, our security practices, or how your information is handled, please contact the FinovatePro team.

Scroll to Top