
Privacy Policy
Your Privacy Matters to Us
City Hall Systems, Inc. (“CHS,” “we,” “our,” or “us”) is committed to protecting your privacy and securing your personal data. This Privacy & Security Policy explains how we collect, use, store, and protect your personal information when you visit and use our municipal ePayment website www.cityhallsystems.com.
1. Scope of Policy
This policy applies to all users accessing the Site, including individuals who:
● Retrieve and view municipal bills.
● Make payments through our system.
● Create a user account to access billing history, schedule payments, and receive notifications.
Your privacy and data security are our top priorities. By using our Site, you agree to the terms outlined in this policy.
2. Information We Collect
We only collect personal information necessary to process payments, manage accounts, and ensure compliance with municipal requirements.
Personal Information You Provide:
When registering for an account or making a payment, you may be required to provide:
● Contact Information: Name, mailing address, email, and phone number.
● Payment Information: Credit/debit card details or bank account information.
● Identity Verification: Social security number or driver’s license number (for excise tax payments only).
Automatically Collected Data:
We may collect certain non-personal data for security, analytics, and site optimization, including:
● IP Address & Device Information – To detect fraud and unauthorized access.
● Cookies & Tracking Technologies – Used for session management and user experience enhancements.
● Transaction History – Records of payments made through the Site.
3. How We Use Your Information
Your data is used strictly for delivering the services you request. We do not sell, trade, rent, or share your personal data with third parties for marketing purposes.
We use your information for:
● Processing payments securely.
● Providing access to billing and payment history.
● Sending email notifications regarding billing and payment updates.
● Ensuring compliance with PCI DSS Level 1, NACHA, and other regulatory requirements.
● Investigating fraudulent transactions and ensuring account security.
Third-Party Payment Processing
We utilize a PCI DSS Level 1 certified third-party payment processor for handling transactions. This processor does not retain, store, or use your personal data for any purpose beyond completing your payment.
4. Data Security Measures
City Hall Systems exceeds industry security standards to protect your information. Our security practices include:
PCI DSS Level 1 Compliance
We are a Level 1 Payment Card Industry Data Security Standard (PCI DSS) certified service provider, ensuring:
● Encryption & Tokenization: Sensitive data is encrypted in transit and at rest.
● Firewall & Intrusion Detection: Prevents unauthorized access to our network.
● Regular Security Audits: Continuous monitoring, testing, and compliance verification.
NACHA Compliance for ACH Transactions
As part of NACHA (National Automated Clearing House Association) compliance, we:
● Protect ACH payment data with strict encryption standards.
● Require authentication and authorization for all transactions.
● Continuously monitor transactions for fraud detection.
SOC 2 Compliance
We adhere to SOC 2 security controls, ensuring:
● Secure and redundant data storage.
● Strict access controls for employees handling sensitive information.
● Regular risk assessments and mitigation procedures.
PII (Personally Identifiable Information) Protection
We take comprehensive measures to safeguard personally identifiable information (PII) by:
● Limiting access to authorized personnel only.
● Encrypting sensitive information to prevent unauthorized use.
● Anonymizing data where applicable.
WISP (Written Information Security Program)
Our Written Information Security Program (WISP) outlines policies for:
● Secure data handling and classification.
● Incident response in the event of a security breach.
● Employee security training and compliance enforcement.
5. Your Privacy Rights & Choices
You have the following rights regarding your personal information:
● Access & Correction: You may request access to your stored personal data or request corrections.
● Opt-Out of Notifications: Users can modify notification preferences through their account settings.
● Data Deletion: Upon request, we can remove certain personal data, subject to legal or regulatory retention requirements.
If you suspect unauthorized use of your account or personal data, contact us immediately so we can take corrective action.
6. Updates to This Policy
City Hall Systems reserves the right to modify this Privacy & Security Policy as needed. If significant changes are made, we will:
● Post a notice on our Site at least 30 days before implementing updates (unless urgent changes are required for security).
● Encourage users to review this policy periodically.
7. Contact Us
For questions regarding this Privacy & Security Policy or to exercise your data rights, please contact us at:
-
Email: Info@CityHallSystems.com
-
Mailing Address: 3 Rosenfeld Drive Hopedale MA 01747
Last Modified: April 14, 2025
This policy ensures transparency, compliance, and security for all users interacting with City Hall Systems’ municipal payment services.