Zulcom Solutions ("we", "our", or "us") operates the commercial fleet platform accessible at zulcomnetwork.com and cardservices.zulcomnetwork.com. This Privacy Policy details how we handle information in connection with our business-to-business (B2B) fleet fuel management services, including account registration and our automated application review process.
1. Information We Collect
We process data collected exclusively from commercial entities, business applicants, and authorized company administrators. This includes:
Account Data: Email address, password (stored in encrypted/hashed form by our authentication provider — we never see or store your password in plain text), legal business name, and full name, collected when you create an account.
Application & Corporate Account Data: Legal business entity name, corporate tax identifier (EIN/Tax ID), entity type, operational website URL, authorized administrator contact details, estimated fleet size, projected fuel spend, and beneficial ownership details (full name, corporate title, and date of birth for individuals who own 25% or more of the business or hold significant control). We do not directly collect Social Security Numbers or other government ID numbers on this form — see Identity Verification Data below.
Identity Verification Data: When you complete identity verification, you submit identifying information (which may include a government ID number, document photos, or a selfie) directly to our verification partner, Plaid Inc. ("Plaid"), through Plaid's own secure interface. We do not receive or store this raw identifying information ourselves — we only receive and store the verification outcome (e.g., verified, failed, pending review) and associated status metadata.
Financial Verification Data: When you securely link a bank account through Plaid, we do not receive your banking credentials. We receive and store a derived summary of your linked account data (such as available balance and account count) used for automated underwriting. We do not retain full transaction-level bank data, and we discard the credential used to access your linked account once a financial verification report has been generated.
Commercial Transaction Data: Once card issuing is live, merchant identities, filling station locations, timestamps, and expenditure amounts gathered from corporate card usage.
2. Purpose of Processing
Data processing is executed strictly to satisfy contractual obligations, specifically to create and administer your account, automatically verify applicant identity and financial standing in place of a traditional credit bureau pull, support active fuel limit parameters, maintain corporate dashboard transaction readouts, mitigate fraudulent expenditures, and ensure robust financial regulatory reporting via downstream partners.
3. Automated Application Review
Part of our application process uses automated, rules-based logic to sort applications into review priority tiers (for example, "fast-tracked," "standard review," or "needs additional review") based on identity verification outcomes and financial verification summaries. This automated triage does not by itself deny or finally approve an application — it only prioritizes human review queues. You can always view your current application status from your account dashboard, and you may contact us using the details below if you have questions about how your application was triaged.
4. Information Sharing and Disclosure
We do not lease or monetize corporate account records. Collected information is routed strictly to required processing partners solely to fulfill account administration, identity and financial verification, card distribution, authorization requests, and corporate program compliance reviews. These partners currently include:
Supabase — our authentication, database, and application hosting infrastructure provider.
Plaid Inc. — our identity verification and bank-linked financial verification provider.
Stripe Payments Company and other banking/card-issuing partners — for future card distribution, authorization, and regulatory reporting once card issuing is live.
5. Data Retention & Security
Account and application data is stored in access-controlled databases restricted so that each business can only access its own records. We apply data-minimization practices where practical — for example, discarding bank access credentials after a financial verification report is generated, and storing only derived financial summaries rather than full transaction-level detail.
6. Contact Us
For inquiries regarding data governance, privacy rights, or this policy, please submit a request to: [email protected]