Terms and policies
Transparency is a value proposition and is reflected in our security and compliance agreements.
Last updated: 2025.07.07
1. Introduction
1.1 In order to be able to make PhotonPay's services available to you in compliance with the obligations imposed by applicable laws and regulations and by regulatory authorities, PhotonPay must ask you for certain information about yourself, including financial information (e.g., information about your identity, business, beneficiary account, etc.). PhotonPay will utilize the data provided by you in accordance with applicable provisions of governing data protection laws. The information obtained shall, as a matter of principle, be used by PhotonPay solely for providing PhotonPay Services and solely to the extent necessary to render such services. The information about you which we store shall, as a matter of principle, not be made accessible to third parties unless we are obligated to do so by law or due to legal ordinances or in order to properly render our services to you.
1.2 This Policy applies to any user of products, services, technologies or functionalities offered by us anywhere in the world (and, when such user is a business entity, to any individual who is the owner of, or who acts on behalf of, such user), and to any visitor to our website, mobile app, or other channels.
2. How we collect information
2.1 Collected from Visitors
PhotonPay automatically collects non-personally-identifying information of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request. PhotonPay's purpose in collecting non-personally identifying information is to better understand how PhotonPay's visitors use its website, mobile app or other channels through cookies, web beacons, log files and other technologies:
- Your domain name, your browser type and operating system, web pages you view, links you click;
- Your IP address, the length of time you visit our website, mobile app or other channels, or use our Services, your activities on our website, mobile app or other channels, and the referring URL or the webpage that led you to our website.
Please see Clause 9 "Cookies" below for more information. Visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent them from being able to use PhotonPay's services.
2.2 Provided by Users
You may provide us data about you by filling in forms on our website, mobile app or other channels (e.g. PhotonPay Membership Account Registration), or by corresponding with us (for example, by e-mail or telephone). The data you provide may include data about additional persons that are beneficial owners of the PhotonPay services. This includes that is provided to us about you:
- Upon registration for a PhotonPay Membership Account;
- When you log in to your PhotonPay Membership Account;
- When you submit any settlement orders through your PhotonPay Membership Account;
- When entering a competition, promotion or survey; and
- When a problem is reported or a request for support is received.
Visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent them from being able to use PhotonPay's services.
3. Information we collect
3.1 We collect the personal information you provide directly to us when you apply for a PhotonPay Membership Account, perform any transactions on the PhotonPay platform, or use other PhotonPay Services. This may include:
- Your contact information (e.g., name, email address, phone number, billing or mailing address)
- Bank and credit account information
- IP address
- Identity validation (e.g., photograph, other information requested to verify your information, including copy of valid ID document)
- Publicly available and/or criminal history
- National identification numbers
- Nationality
- Date and place of birth
- Details of any transactions carried out using any the services
- Any other information that you choose to provide to us (e.g., if you send us an email/otherwise contact us)
- Calls/emails/other correspondence
- Information through Cookies and other tracking technologies as listed above and as described in the section below entitled "Cookies"
You are responsible for providing accurate and up-to-date information.
3.2 If you are required to provide information about shareholders or beneficial owners of your business, you acknowledge that you have that person's consent to provide his/her information to us. This may include:
- Contact information, such as name, home address, and email address.
- Account information, such as username and password.
- Financial information, such as bank account numbers, bank statement, and trading information.
- Identity verification information, such as images of your government issued ID, passport, national ID card, or driving license. Note: US residents may be asked to provide their social security numbers.
- Residence verification information, such as Utility bill details or similar information.
3.3 We may collect and process personal data about buyers or third parties related to your business in providing PhotonPay services.
You are responsible for making sure that the privacy rights of any third parties, including buyers and other individuals related to your business, are respected, including ensuring appropriate disclosures about the third party data collection and use; with respect to such data you hereby are deemed to be and accept to be controller. To the extent that we are acting as your data processor, we will process personal data in accordance with the terms of our agreement with you and your lawful instructions.
4. How and why we use your data
4.1 We will only use your personal information to:
- Validate your identity (including via SMS or Voice Call, as applicable) when you associate with our services;
- Process your transactions;
- Conduct the required controls and checks in compliance with Anti-Money Laundering/Counter-Terrorist Financing and Know Your Customer requirements under applicable laws and regulations and internal control policies, and to address other law enforcement needs, which is more fully described in our terms and conditions for specific PhotonPay services;
- Associate with our legal or regulatory rights and obligations, including financial reporting, regulatory reporting, management reporting, risk management (including fraud prevention, transaction monitoring and financial crime detection), audit and record keeping purposes and for the purposes of seeking professional advice, including legal advice;
- Analyze the usage of PhotonPay website, mobile app or other channels, and improve our website mobile app or other channels usage and their offerings;
- Help us respond to your customer service requests and support needs;
- Tailor the content and information that we send or display to you, offer location customization (where permitted by applicable law), personalized help and instructions, and otherwise personalize your experiences while using our website, mobile app, and other channels, and/or our services, such as developing and offering you with new and/or additional services to the services we are providing you or new and/or additional features to existing services, based, where appropriate, on your eligibility for such new and/or additional services or features, as would be evaluated by us from time to time;
- Contact you about PhotonPay Services. The email address you provide may be used to communicate information and updates related to your use of the PhotonPay Services. We may also occasionally communicate company news, updates, promotions, and related information relating to similar products and services provided by PhotonPay;
- Better understand how users, access and use our website, mobile app, and other channels and/or our services, both on an aggregated and individualized basis, to administer, monitor, and improve our website, mobile app, and other channels, and/or services, for our internal purposes, and for other research and analytical purposes (including in the form of our online surveys); or
- Administer a contest, promotion, survey or other site feature as will be more explained on the website.
5. Disclosure of personal information
5.1 PhotonPay discloses personally-identifying and potential personally-identifying information only:
- To legal and regulatory authorities as required by applicable laws and regulations, and (b) to those of its employees, service providers and affiliated organizations that (i) need to know that information in order to process it or to provide services, and (ii) that have agreed not to disclose it to others, as described below.
5.2 Disclosure to Third Parties
In processing your transactions, we may share some of your personal information with Service Providers and contractors who help with our business operations. Your information will not be sold, exchanged, or shared with any third parties without your explicit consent, except to provide PhotonPay Services or as required by law. By using our Services and accepting our Terms and Conditions, you consent to the disclosure of your personal information as described in this Privacy and Cookies Policy.
PhotonPay's Service Providers and contractors are contractually bound to protect and use such information only for the purposes for which it was disclosed, except as otherwise required or permitted by law. We ensure that such third parties will be bound by terms no less protective those described in this Privacy and Cookies Policy, or those we are subject to under applicable data protection laws, including but not limited to applicable laws and regulations.
5.3 Disclosure to Legal Authorities
We may share your personal information with law enforcement, data protection authorities, government officials, and other authorities when:
- We are compelled by subpoena, court order, or other legal procedure;
- We believe that the disclosure is necessary to prevent actual damages or financial loss.
- Disclosure is necessary to report suspected illegal activity.
- Disclosure is necessary to investigate violations of this Privacy and Cookies Policy or our terms and conditions of specific PhotonPay services.
6. Transfer and storage of data
6.1 Our services are global and data may be stored and processed in any country where we have operations or where we engage service providers. Data we collect may be transferred to and/or stored at a destination outside your country of residence or the Account Jurisdiction, which may have data protection rules that are different from those of your country, including transferring data to and from regulatory authorities, or to staff operating outside the country who process data on our behalf or for one of our suppliers. Staff may be engaged in the fulfilment of your request and the provision of support services. However, we will take measures to ensure that any such transfers comply with applicable data protection laws and that your data remains protected to the standards described in this privacy policy. By submitting the data, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that the data is treated securely and in accordance with this Privacy and Cookies Policy and the relevant data protection regulations.
6.2 The general practices described in Section 6 are further supplemented by specific provisions in Section 11 for users in the EEA and UK.
7. Protection of Certain Personally-Identifying Information
7.1 PhotonPay takes all organizational and technical measures appropriate to protect against the unauthorized access, use, alteration or destruction of potential personally-identifying and personally-identifying information.
7.2 All data that you provide to us is stored on our secure servers. You are responsible for keeping your account credentials safe and secure and not sharing them with anyone.
7.3 The transmission of information via the internet is not completely secure; any transmission is at your own risk. Although no one can guarantee the security of data transmitted via the internet, we do our best to protect the data transmitted via the PhotonPay Membership Account. We use industry standard security techniques to help keep the data safe including encryption when the data is in transit and at rest.
7.4 The PhotonPay website, mobile app, or other channels may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any user data to these third parties.
8. Data Retention and Deletion
8.1 We retain your personal information for the duration of your engagement with us and for a period following termination of such engagement, as required in order to meet our legal obligations as a payment service provider under applicable laws or regulations and, to the extent not prohibited under applicable law, such additional period in accordance with our internal policies and procedures for purposes of prevention of fraudulent activities, risk management, defense against claims and security.
8.2 Our data retention periods vary by data type, considering relevant laws and regulations. We determine these periods based on the specific legal requirements of the country or region where the data is applicable.
8.3 When you wish to delete your information, you can choose to remove specific PhotonPay products, including any personal information linked to those products; or you can opt to delete your entire PhotonPay Membership Account. Upon receiving your request to delete data, we will initiate the deletion process to ensure that your data is securely and completely erased from our servers, or kept only in an anonymized form. We strive to ensure that the PhotonPay service safeguards information against accidental or malicious deletion. However, if you request deletion, it may require some time to remove all copies from our active and backup systems.
8.4 You should be aware that in certain situations, we may not be able to fully comply with your data protection requests. This is typically due to legal obligations or our legitimate interests in maintaining the security and integrity of our services.If you request the deletion of your transaction data, PhotonPay may be legally required to retain such records for a specified period to comply with applicable laws, including but not limited to anti-money laundering (AML) and counter-terrorist financing (CTF) regulations. In such cases, we will not be able to delete this information until the mandatory retention period expires. For example, if you request to delete an account that is currently under investigation for security reasons or suspected fraudulent activity, we will need to retain that data to complete our investigation and protect our platform and users.In all cases where we cannot fulfill your request, we will inform you of the reasons for the refusal, subject to any legal or regulatory restrictions.
9. Updates and Notifications
We may modify this Policy from time to time to reflect new services, changes in our privacy practices, or relevant laws. The "Last updated" legend at the top of this Policy indicates when this Policy was last materially revised. Any changes are effective the later of when we post the revised Policy on the Services or otherwise provide notice of the update as required by law.
We may provide you with disclosures and alerts regarding the Policy or Personal Data collected by posting them on our website and, if you are an End User or Representative, by contacting you through your Dashboard, email address, and/or other methods listed in your PhotonPay account.
10. Cookies
To make our website, mobile app or other channels work properly, PhotonPay, similar to many other major operators, sometimes use small data files called cookies or other tracking technology to track information about your use of our website and services. We may use third party service providers to collect this information on our behalf.
10.1 What are cookies
Cookie is a small text file that a website saves on your computer or mobile device when you visit the website. It enables the website to remember your actions and preferences (such as login, language, font size and other display preferences) over a period of time, so you don't have to keep re-entering them whenever you come back to the website or browse from one page to another.
10.2 How we use cookies and tracking
We use the following cookies/tracking mechanisms:
- Session cookies. Session cookies are temporary cookies that remain in the cookie file of your browser until you leave the website. We use session cookies to allow you to carry information across pages of our site and avoid having to re-submit the same information. The cookies will be deleted after your web browser has been closed.
B) Persistent cookies. Persistent cookies remain in the cookie file of your browser for much longer (though how long will depend on the lifetime of the specific cookie). We use persistent cookies:
- To help us recognize you as a unique visitor when you return to our website and to monitor your use of our website;
- To allow us to link you to any of our Partners of Affiliates should you come to our website through a paid advert or banner on a website of an Affiliate or Partner.
- The cookies will be deleted based on their own expiration period after your web browser has been closed.
C) Web Beacons. Some of our web pages may contain web beacons which allow us to count users who have visited these pages. Web beacons collect only limited information including a cookie number, time and date of a page view, and a description of the page on which the web beacon resides. These beacons do not carry any personally identifiable information and are used to track the effectiveness of a particular marketing campaign.
10.3 How to control cookies
You can control and/or delete cookies as you wish – for details, see about cookies.org. You can delete all cookies that are already on your computer or other channels, and you can set most browsers to prevent them from being placed. If you do this, however, you may have to manually adjust some preferences every time you visit the website and some services and functionalities may not work.
For non-essential Cookies and tracking technologies (such as Cookies used for analytics or marketing purposes), we will seek your explicit consent when you first visit the website, and provide you with convenient options for managing your consent.
10.4 Opt-in and Opt-out for Non-Essential Cookies
We are committed to providing you with clear control over how cookies are used. For non-essential cookies and tracking technologies (such as cookies used for analytics or marketing purposes), we require your explicit opt-in consent before they are placed.
10.5 How to Manage Your Cookie Preferences:
- Via the Consent Banner: When you first visit our website, a cookie consent banner will appear, allowing you to choose whether to accept or decline non-essential cookies.
- Via Browser Settings: You can adjust your browser settings at any time to reject all or specific cookies. Please note that this action might affect your experience with certain features on our website.
- Via a Privacy Dashboard: We may provide a privacy dashboard that allows for more granular management of your cookie preferences and data settings.
10.6 Withdrawing Your Consent:
If you have previously consented to the use of non-essential cookies, you can withdraw your consent at any time through any of the methods mentioned above (e.g., by revisiting the consent banner, adjusting browser settings, or via a privacy dashboard).
10.7 Important Note on Consent:
Simply continuing to use our website or scrolling does not constitute consent for non-essential cookies. We will only load and use these cookies after you have made an explicit choice to opt-in.
11. Additional terms for EEA/UK customers
11.1 Individual Rights
You have the following rights granted by GDPR, which you can exercise by contacting us:
- Right of Access: You have the right to request details of the personal data we hold about you, a description of that data, the purposes for which it is being used, and any parties with which we share your information(In particular,Specifically, if you are a customer from the UK, we are only required to conduct reasonable and proportionate searches when you request access to your personal information).Generally, we provide this information free of charge. We may only charge a reasonable administrative fee if your request is clearly unfounded, repetitive, or excessive. Your request should be made in writing to dpo@photonpay.com for more information.
- Right to Rectification: If you believe that the personal data we hold about you is inaccurate or incomplete, you have the right to request us to correct it.
- Right to erasure ('right to be forgotten'): Subject to certain conditions, you have the right to request us to delete your personal data. When you wish to delete your information, you can choose to remove specific PhotonPay products, including any personal information linked to those products; or you can opt to delete your entire PhotonPay Membership Account. Please contact us at dpo@photonpay.com to make your deletion request, and we will respond in a reasonable time. Please note that some or all data may be required in order for the PhotonPay Services to function properly. You should be aware that in certain situations, we may not be able to fulfill your request. For instance, if PhotonPay is legally required to maintain transaction records to comply with relevant laws, or if your request interferes with our legitimate use of data for anti-fraud and security purposes, we may not be able to delete this information.
- Right to Restriction of Processing: In specific circumstances, you have the right to request us to restrict the processing of your personal data.
- Right to Data Portability: You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and have the right to transmit that data to another controller.
- Right to Object: You have the right to object to certain processing of your personal data based on legitimate interests, including for direct marketing purposes.
- Rights in Relation to Automated Decision Making and Profiling: You have the right to object to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you, unless such decision is necessary or with your explicit consent.
11.2 Complaint Rights
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the United Kingdom. The ICO website is available at: https://ico.org.uk/, or you can contact their helpline at 0303 123 1113.
11.3 Data Retention
When acting as data processor we will retain data for as long as we are directed by you or for as long as we are required under applicable laws and regulations, but usually for no more than 5 years after the end of the business relationship.
If you would like us to delete your personal data, please contact us at dpo@photonpay.com and we will respond in a reasonable time. Please note that some or all data may be required in order for the PhotonPay Services to function properly.
11.4 Data transfer
In the course of providing our services to you, there may be occasions where your service requires us to transfer personal data out of the EEA/UK. Similarly, where we use cloud service providers, ultimately the storage of that data can be based outside the EEA/UK.
For our the EEA/UK clients, while we primarily store your information locally within the EEA/UK, we will also transfer and store your personal data to Hong Kong to facilitate the specific services we provide to you. This cross-border transfer and storage is necessary for the efficient and effective delivery of our services.
Whenever we transfer your personal data out of the EEA/UK, we will do so in accordance with the GDPR using a valid cross-border transfer mechanism. To the extent required by applicable law, we will protect the cross-border transfer of your Personal Data through the use of applicable legal adequacy mechanisms. For transfers from the EEA, we implement the European Commission's Standard Contractual Clauses (SCCs).For transfers from the UK, we implement the UK International Data Transfer Agreement (IDTA).In addition, where required, we conduct a Transfer Impact Assessment (TIA) to evaluate whether the laws and practices of the destination country may impact the effectiveness of the adopted safeguards.
If you would like to find out more about the safeguards we rely upon to transfer your personal data outside of the EEA/UK, please contact us at dpo@photonpay.com. You also have the right to file a complaint with the data protection authority in the EEA or the Information Commissioner's Office(ICO) in the UK, and we will acknowledge your complaint within 30 days and respond to you without undue delay.
12. Contact and Your Data Protection Rights
12.1 This Privacy and Cookies Policy applies to the processing activities in which PhotonPay acts as the data controller.
12.2 If you have any questions, comments, requests, or complaints regarding this Privacy and Cookies Policy or the way we handle your personal data, you are welcome to contact us at:dpo@photonpay.com. If you would like more information about any third parties with whom we may share your personal data—including the purposes for such sharing, how the data is processed, and how you can exercise your data protection rights in relation to these third parties—please contact us using the email address above.
12.3 You also have the right to lodge a complaint with a data protection authority, including in the country where you live or work, or where you believe your rights have been infringed.
13. Privacy and Cookies Policy changes
This Privacy and Cookies Policy may be revised over time as new features are added to the PhotonPay services or as we incorporate suggestions from our stakeholders. We may change this Privacy and Cookies Policy at any time by posting a revised version of it on our website. We will provide you with at least 30 days' prior notice of the effective date of the revised Privacy and Cookies Policy when it is legally required. We may post the notice on the front page of our website(s) and/or send the notice by e-mail. As of the effective date of the revised Privacy and Cookies Policy, you will be considered as having consented to all changes to the Privacy and Cookies Policy. If you disagree with the terms of this Privacy and Cookies Policy, you may close your account at any time.
14. Liability
TO THE EXTENT PERMISSIBLE UNDER APPLICABLE LAWS AND GDPR REGULATIONS, WE ARE NOT LIABLE TO YOU IN RESPECT OF ANY CLAIMS, LOSSES, DAMAGES, EXPENSES (INCLUDING REASONABLE LEGAL FEES) ARISING OUT OF OR IN CONNECTION WITH THE USE AND/OR DISCLOSURE OR DISSEMINATION OF THE USER DATA IN ACCORDANCE WITH THIS PRIVACY POLICY AND ANY CONSENTS THAT YOU MAY HAVE OTHERWISE PROVIDED TO US.
