Terms and policies
Transparency is a value proposition and is reflected in our security and compliance agreements.
Last updated:August 2026
1. Introduction
1.1 In order to be able to make PhotonPay’s services available to you in compliance with the obligations imposed by applicable laws and regulations and by regulatory authorities, PhotonPay must ask you for certain information about yourself, including financial information (e.g., information about your identity, business, beneficiary account, etc.). PhotonPay will utilize the data provided by you in accordance with applicable provisions of governing data protection laws. The information obtained shall, as a matter of principle, be used by PhotonPay solely for providing PhotonPay Services and solely to the extent necessary to render such services. The information about you which we store shall, as a matter of principle, not be made accessible to third parties unless we are obligated to do so by law or due to legal ordinances or in order to properly render our services to you.
1.2 This Policy applies to any user of products, services, technologies or functionalities offered by us anywhere in the world (and, when such user is a business entity, to any individual who is the owner of, or who acts on behalf of, such user), and to any visitor to our website, mobile app, or other channels.
2. How we collect information
2.1 Collected from Visitors
PhotonPay automatically collects non-personally- identifying information of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request. PhotonPay’s purpose in collecting non-personally identifying information is to better understand how PhotonPay’s visitors use its website, mobile app or other channels through cookies, web beacons, log files and other technologies:
- Your domain name, your browser type and operating system, web pages you view, links you click;
- Your IP address, the length of time you visit our website, mobile app or other channels, or use our Services, your activities on our website, mobile app or other channels, and the referring URL or the webpage that led you to our website.
Please see Clause 10 “Cookies” below for more information. Visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent them from being able to use PhotonPay’s services.
2.2 Provided by Users
You may provide us data about you by filling in forms on our website, mobile app or other channels (e.g. PhotonPay Membership Account Registration), or by corresponding with us (for example, by e-mail or telephone). The data you provide may include data about additional persons that are beneficial owners of the PhotonPay services. This includes that is provided to us about you:
- upon registration for a PhotonPay Membership Account;
- when you log in to your PhotonPay Membership Account;
- when you submit any settlement orders through your PhotonPay Membership Account;
- when entering a competition, promotion or survey; and
- when a problem is reported or a request for support is received.
Visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent them from being able to use PhotonPay’s services.
3. Information we collect
3.1 We collect the personal information you provide directly to us when you apply for a PhotonPay Membership Account, perform any transactions on the PhotonPay platform, or use other PhotonPay Services. This may include:
- your contact information (e.g., name, email address, phone number, billing or mailing address)
- bank and credit account information
- IP address
- identity validation (e.g., photograph, other information requested to verify your information, including copy of valid ID document)
- publicly available and/or criminal history
- national identification numbers
- nationality
- date and place of birth
- details of any transactions carried out using any the services
- any other information that you choose to provide to us (e.g., if you send us an email/otherwise contact us)
- calls/emails/other correspondence
- information through Cookies and other tracking technologies as listed above and as described in the section below entitled “Cookies”
You are responsible for providing accurate and up-to-date information.
3.2 If you are required to provide information about shareholders or beneficial owners of your business, you acknowledge that you have that person’s consent to provide his/her information to us. This may include:
- contact information, such as name, home address, and email address.
- account information, such as username and password.
- financial information, such as bank account numbers, bank statement, and trading information.
- identity verification information, such as images of your government issued ID, passport, national ID card, or driving license. Note: US residents may be asked to provide their social security numbers.
- residence verification information, such as Utility bill details or similar information.
3.3 We may collect and process personal data about buyers or third parties related to your business in providing PhotonPay services. You are responsible for making sure that the privacy rights of any third parties, including buyers and other individuals related to your business, are respected, including ensuring appropriate disclosures about the third party data collection and use; with respect to such data you hereby are deemed to be and accept to be controller. To the extent that we are acting as your data processor, we will process personal data in accordance with the terms of our agreement with you and your lawful instructions.
4. How and why we use your data
We will only use your personal information to:
- validate your identity (including via SMS or Voice Call, as applicable) when you associate with our services;
- process your transactions;
- conduct the required controls and checks in compliance with Anti-Money Laundering/Counter-Terrorist Financing and Know Your Customer requirements under applicable laws and regulations and internal control policies, and to address other law enforcement needs, which is more fully described in our terms and conditions for specific PhotonPay services;
- associate with our legal or regulatory rights and obligations, including financial reporting, regulatory reporting, management reporting, risk management (including fraud prevention, transaction monitoring and financial crime detection), audit and record keeping purposes and for the purposes of seeking professional advice, including legal advice;
- analyze the usage of PhotonPay website, mobile app or other channels, and improve our website mobile app or other channels usage and their offerings;
- help us respond to your customer service requests and support needs;
- tailor the content and information that we send or display to you, offer location customization (where permitted by applicable law), personalized help and instructions, and otherwise personalize your experiences while using our website, mobile app, and other channels, and/or our services, such as developing and offering you with new and/or additional services to the services we are providing you or new and/or additional features to existing services, based, where appropriate, on your eligibility for such new and/or additional services or features, as would be evaluated by us from time to time;
- contact you about PhotonPay Services. The email address you provide may be used to communicate information and updates related to your use of the PhotonPay Services. We may also occasionally communicate company news, updates, promotions, and related information relating to similar products and services provided by PhotonPay;
- better understand how users, access and use our website, mobile app, and other channels and/or our services, both on an aggregated and individualized basis, to administer, monitor, and improve our website, mobile app, and other channels, and/or services, for our internal purposes, and for other research and analytical purposes (including in the form of our online surveys); or
- administer a contest, promotion, survey or other site feature as will be more explained on the website.
5. Disclosure of personal information
5.1 PhotonPay discloses personally-identifying and potential personally-identifying information only:
- to legal and regulatory authorities as required by applicable laws and regulations; and
- to those of its employees, service providers and affiliated organizations that:
- need to know that information in order to process it or to provide services, and
- that have agreed not to disclose it to others, as described below.
5.2 Disclosure to Third Parties
In processing your transactions, we may share some of your personal information with Service Providers and contractors who help with our business operations. Your information will not be sold, exchanged, or shared with any third parties without your explicit consent, except to provide PhotonPay Services or as required by law. By using our Services and accepting our Terms and Conditions, you consent to the disclosure of your personal information as described in this Privacy and Cookies Policy.
PhotonPay’s Service Providers and contractors are contractually bound to protect and use such information only for the purposes for which it was disclosed, except as otherwise required or permitted by law. We ensure that such third parties will be bound by terms no less protective those described in this Privacy and Cookies Policy, or those we are subject to under applicable data protection laws, including but not limited to applicable laws and regulations.
5.3 Disclosure to Legal Authorities
We may share your personal information with law enforcement, data protection authorities, government officials, and other authorities when:
- we are compelled by subpoena, court order, or other legal procedure;
- we believe that the disclosure is necessary to prevent actual damages or financial loss.
- disclosure is necessary to report suspected illegal activity.
- disclosure is necessary to investigate violations of this Privacy and Cookies Policy or our terms and conditions of specific PhotonPay services.
6. Transfer and storage of data
6.1 Our services are global and data may be stored and processed in any country where we have operations or where we engage service providers. Data we collect may be transferred to and/or stored at a destination outside your country of residence or the Account Jurisdiction, which may have data protection rules that are different from those of your country, including transferring data to and from regulatory authorities, or to staff operating outside the country who process data on our behalf or for one of our suppliers. Staff may be engaged in the fulfilment of your request and the provision of support services. However, we will take measures to ensure that any such transfers comply with applicable data protection laws and that your data remains protected to the standards described in this privacy policy. By submitting the data, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that the data is treated securely and in accordance with this Privacy and Cookies Policy and the relevant data protection regulations.
6.2 The general practices described in Section 6 are further supplemented by specific provisions in Section 11 for users in the EEA and UK.
7. Protection of Certain Personally-Identifying Information
7.1 PhotonPay takes all organizational and technical measures appropriate to protect against the unauthorized access, use, alteration or destruction of potential personally- identifying and personally-identifying information.
7.2 All data that you provide to us is stored on our secure servers. You are responsible for keeping your account credentials safe and secure and not sharing them with anyone.
7.3 The transmission of information via the internet is not completely secure; any transmission is at your own risk. Although no one can guarantee the security of data transmitted via the internet, we do our best to protect the data transmitted via the PhotonPay Membership Account. We use industry standard security techniques to help keep the data safe including encryption when the data is in transit and at rest.
7.4 The PhotonPay website, mobile app, or other channels may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any user data to these third parties.
8. Data Retention and Deletion
8.1 We retain your personal information for the duration of your engagement with us and for a period following termination of such engagement, as required in order to meet our legal obligations as a payment service provider under applicable laws or regulations and, to the extent not prohibited under applicable law, such additional period in accordance with our internal policies and procedures for purposes of prevention of fraudulent activities, risk management, defense against claims and security.
8.2 Our data retention periods vary by data type, considering relevant laws and regulations. We determine these periods based on the specific legal requirements of the country or region where the data is applicable.
8.3 When you wish to delete your information, you can choose to remove specific PhotonPay products, including any personal information linked to those products; or you can opt to delete your entire PhotonPay Membership Account. Upon receiving your request to delete data, we will initiate the deletion process to ensure that your data is securely and completely erased from our servers, or kept only in an anonymized form. We strive to ensure that the PhotonPay service safeguards information against accidental or malicious deletion. However, if you request deletion, it may require some time to remove all copies from our active and backup systems.
8.4 You should be aware that in certain situations, we may not be able to fully comply with your data protection requests. This is typically due to legal obligations or our legitimate interests in maintaining the security and integrity of our services.If you request the deletion of your transaction data, PhotonPay may be legally required to retain such records for a specified period to comply with applicable laws, including but not limited to anti-money laundering (AML) and counter-terrorist financing (CTF) regulations. In such cases, we will not be able to delete this information until the mandatory retention period expires. For example, if you request to delete an account that is currently under investigation for security reasons or suspected fraudulent activity, we will need to retain that data to complete our investigation and protect our platform and users.In all cases where we cannot fulfill your request, we will inform you of the reasons for the refusal, subject to any legal or regulatory restrictions.
9. Updates and Notifications
9.1 We may modify this Policy from time to time to reflect new services, changes in our privacy practices, or relevant laws. The "Last updated" legend at the top of this Policy indicates when this Policy was last materially revised. Any changes are effective the later of when we post the revised Policy on the Services or otherwise provide notice of the update as required by law.
9.2 We may provide you with disclosures and alerts regarding the Policy or Personal Data collected by posting them on our website and, if you are an End User or Representative, by contacting you through your Dashboard, email address, and/or other methods listed in your PhotonPay account.
10. Cookies
To make our website, mobile app or other channels work properly, PhotonPay, similar to many other major operators, sometimes use small data files called cookies or other tracking technology to track information about your use of our website and services. We may use third party service providers to collect this information on our behalf.
10.1 What are cookies
Cookie is a small text file that a website saves on your computer or mobile device when you visit the website. It enables the website to remember your actions and preferences (such as login, language, font size and other display preferences) over a period of time, so you don’t have to keep re-entering them whenever you come back to the website or browse from one page to another.
10.2 How we use cookies and tracking
We use the following cookies/tracking mechanisms:
- Session cookies. Session cookies are temporary cookies that remain in the cookie file of your browser until you leave the website. We use session cookies to allow you to carry information across pages of our site and avoid having to re- submit the same information. The cookies will be deleted after your web browser has been closed.
- Persistent cookies. Persistent cookies remain in the cookie file of your browser for much longer (though how long will depend on the lifetime of the specific cookie). We use persistent cookies:
- to help us recognize you as a unique visitor when you return to our website and to monitor your use of our website;
- to allow us to link you to any of our Partners of Affiliates should you come to our website through a paid advert or banner on a website of an Affiliate or Partner.
- The cookies will be deleted based on their own expiration period after your web browser has been closed.
- Web Beacons. Some of our web pages may contain web beacons which allow us to count users who have visited these pages. Web beacons collect only limited information including a cookie number, time and date of a page view, and a description of the page on which the web beacon resides. These beacons do not carry any personally identifiable information and are used to track the effectiveness of a particular marketing campaign.
10.3 How to control cookies
You can control and/or delete cookies as you wish – for details, see about cookies.org. You can delete all cookies that are already on your computer or other channels, and you can set most browsers to prevent them from being placed. If you do this, however, you may have to manually adjust some preferences every time you visit the website and some services and functionalities may not work.
For non-essential Cookies and tracking technologies (such as Cookies used for analytics or marketing purposes), we will seek your explicit consent when you first visit the website, and provide you with convenient options for managing your consent.
10.4 Opt-in and Opt-out for Non-Essential Cookies
We are committed to providing you with clear control over how cookies are used. For non-essential cookies and tracking technologies (such as cookies used for analytics or marketing purposes), we require your explicit opt-in consent before they are placed.
10.5 How to Manage Your Cookie Preferences
- Via the Consent Banner: When you first visit our website, a cookie consent banner will appear, allowing you to choose whether to accept or decline non-essential cookies.
- Via Browser Settings: You can adjust your browser settings at any time to reject all or specific cookies. Please note that this action might affect your experience with certain features on our website.
- Via a Privacy Dashboard: We may provide a privacy dashboard that allows for more granular management of your cookie preferences and data settings.
10.6 Withdrawing Your Consent
If you have previously consented to the use of non-essential cookies, you can withdraw your consent at any time through any of the methods mentioned above (e.g., by revisiting the consent banner, adjusting browser settings, or via a privacy dashboard).
10.7 Important Note on Consent
Simply continuing to use our website or scrolling does not constitute consent for non-essential cookies. We will only load and use these cookies after you have made an explicit choice to opt-in.
11. Additional terms for EEA/ UK customers
The terms applies to Individuals that are located within the European Economic Area (EEA) and the United Kingdom (UK),and supplements the terms in the rest of the Privacy and Cookies Policy. We adopt this terms to comply with the General Data Protection Regulation (“GDPR”).
11.1 Individual Rights
You have the following rights granted by GDPR, which you can exercise by contacting us:
- Right of Access: You have the right to request details of the personal data we hold about you, a description of that data, the purposes for which it is being used, and any parties with which we share your information(In particular,Specifically, if you are a customer from the UK, we are only required to conduct reasonable and proportionate searches when you request access to your personal information).Generally, we provide this information free of charge. We may only charge a reasonable administrative fee if your request is clearly unfounded, repetitive, or excessive. Your request should be made in writing to dpo@photonpay.com for more information.
- Right to Rectification: If you believe that the personal data we hold about you is inaccurate or incomplete, you have the right to request us to correct it.
- Right to erasure (‘right to be forgotten’): Subject to certain conditions, you have the right to request us to delete your personal data. When you wish to delete your information, you can choose to remove specific PhotonPay products, including any personal information linked to those products; or you can opt to delete your entire PhotonPay Membership Account. Please contact us at dpo@photonpay.com to make your deletion request, and we will respond in a reasonable time. Please note that some or all data may be required in order for the PhotonPay Services to function properly. You should be aware that in certain situations, we may not be able to fulfill your request. For instance, if PhotonPay is legally required to maintain transaction records to comply with relevant laws, or if your request interferes with our legitimate use of data for anti-fraud and security purposes, we may not be able to delete this information.
- Right to Restriction of Processing: In specific circumstances, you have the right to request us to restrict the processing of your personal data.
- Right to Data Portability: You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and have the right to transmit that data to another controller.
- Right to Object: You have the right to object to certain processing of your personal data based on legitimate interests, including for direct marketing purposes.
- Rights in Relation to Automated Decision Making and Profiling: You have the right to object to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you, unless such decision is necessary or with your explicit consent.
11.2 You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the United Kingdom. The ICO website is available at: https://ico.org.uk/, or you can contact their helpline at 0303 123 1113.
11.3 Data Retention
When acting as data processor we will retain data for as long as we are directed by you or for as long as we are required under applicable laws and regulations, but usually for no more than 5 years after the end of the business relationship.
If you would like us to delete your personal data, please contact us at dpo@photonpay.com and we will respond in a reasonable time. Please note that some or all data may be required in order for the PhotonPay Services to function properly.
11.4 Data transfer
In the course of providing our services to you, there may be occasions where your service requires us to transfer personal data out of the EEA/UK. Similarly, where we use cloud service providers, ultimately the storage of that data can be based outside the EEA/UK.
For our the EEA/UK clients, while we primarily store your information locally within the EEA/UK, we will also transfer and store your personal data to Hong Kong to facilitate the specific services we provide to you. This cross-border transfer and storage is necessary for the efficient and effective delivery of our services.
Whenever we transfer your personal data out of the EEA/UK, we will do so in accordance with the GDPR using a valid cross-border transfer mechanism. To the extent required by applicable law, we will protect the cross-border transfer of your Personal Data through the use of applicable legal adequacy mechanisms. For transfers from the EEA, we implement the European Commission's Standard Contractual Clauses (SCCs).For transfers from the UK, we implement the UK International Data Transfer Agreement (IDTA).In addition, where required, we conduct a Transfer Impact Assessment (TIA) to evaluate whether the laws and practices of the destination country may impact the effectiveness of the adopted safeguards.
If you would like to find out more about the safeguards we rely upon to transfer your personal data outside of the EEA/UK, please contact us at dpo@photonpay.com. You also have the right to file a complaint with the data protection authority in the EEA or the Information Commissioner's Office(ICO) in the UK, and we will acknowledge your complaint within 30 days and respond to you without undue delay.
12. Additional Terms for Canadian Customers
The terms in this Section 12 apply to individuals located in Canada and supplement the terms in the rest of this Privacy and Cookies Policy. We adopt these terms to comply with applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and substantially similar provincial laws.
12.1 Purposes, consent and limiting collection
- We collect, use and disclose your personal information only for purposes identified in this Privacy and Cookies Policy, or as otherwise permitted or required by law. These purposes include, in particular, providing and improving PhotonPay Services, validating identity, complying with anti‑money laundering and other legal obligations, fraud prevention and risk management, and communicating with you.
- By using PhotonPay Services and providing personal information to us, you consent to our collection, use and disclosure of your personal information in accordance with this Privacy and Cookies Policy and applicable Canadian Privacy Laws.
- You may withdraw your consent to our collection, use or disclosure of your personal information at any time, subject to legal or contractual restrictions and reasonable notice. If you withdraw your consent, we may not be able to provide you with some or all of the PhotonPay Services. To withdraw consent, please contact us using the details in Section 12.5.
- We limit the collection of personal information to that which is necessary for the purposes identified in this Privacy and Cookies Policy or otherwise communicated to you, and we will collect personal information by fair and lawful means.
- For optional marketing communications, we will only send such communications to you in compliance with Canada’s Anti-Spam Legislation (“CASL”). You may opt out of receiving marketing emails at any time by using the unsubscribe mechanism in those emails or by contacting us.
12.2 Your rights under Canadian Privacy Laws
Subject to certain exceptions prescribed in Canadian Privacy Laws, you have the following rights in relation to your personal information:
- Right of access: You may request access to the personal information we hold about you and information about how that personal information has been used and disclosed by us, to the extent required by law.
- Right to correction: If you believe that any personal information we hold about you is inaccurate or incomplete, you may request that we correct or update it.
- Right to withdraw consent: As noted in Section 12.1(c), you may withdraw your consent to our processing of your personal information, subject to legal or contractual restrictions.
- Right to challenge compliance: You may challenge our compliance with Canadian Privacy Laws by contacting our privacy officer as set out in Section 12.5.
We will respond to your request within the time periods required by Canadian Privacy Laws. When you make a request, we may take reasonable steps to verify your identity to ensure that we do not provide information to an unauthorized person.
12.3 Cross-Border Transfers and Storage of Personal Information
Your personal information may be transferred to, stored in, or accessed from jurisdictions outside of your province or territory of residence, including outside of Canada, as described in Section 6 of this Policy. These jurisdictions may have data protection laws that differ from those in Canada. When personal information is located outside Canada, it is subject to the laws of the foreign jurisdiction and may be accessed by courts, law enforcement and national security authorities in that jurisdiction.
When we transfer personal information outside Canada, we take appropriate contractual or other measures to protect it in accordance with this Policy and applicable Canadian law. You may contact us at dpo@photonpay.com for more information about our cross-border transfer practices and safeguards.
12.4 Additional Rights for Quebec Residents
If you reside in the Province of Quebec, additional rights and obligations may apply under Quebec privacy legislation, including the Act Respecting the Protection of Personal Information in the Private Sector (as amended, sometimes referred to as “Law 25”). To the extent required by that legislation:
a) We act as the person in charge of the protection of personal information (privacy officer) through our designated Data Protection Officer, reachable at dpo@photonpay.com.
b) Where required, we will conduct privacy impact assessments in connection with certain high‑risk processing activities or cross‑border transfers.
c) You may request more detailed information about our use of automated decision-making, if any, and, where applicable, the main factors and parameters underlying such decisions.
12.5 Complaints and Regulatory Contacts in Canada
If you have any concerns or complaints regarding how we handle your personal information, please first contact us at dpo@photonpay.com. We will investigate your complaint and respond within a reasonable time.
If you are not satisfied with our response, you may have the right to file a complaint with the relevant privacy regulator. Depending on your place of residence, this may include:
- Office of the Privacy Commissioner of Canada (PIPEDA)
Website: https://www.priv.gc.ca/ - Commission d’accès à l’information du Québec (for residents of Québec)
Website: https://www.cai.gouv.qc.ca/ - Office of the Information and Privacy Commissioner for British Columbia (for residents of British Columbia)
Website: https://www.oipc.bc.ca/ - Office of the Information and Privacy Commissioner of Alberta (for residents of Alberta)
Website: https://www.oipc.ab.ca/
We will cooperate with the competent privacy authorities in investigating and resolving any complaints regarding our privacy practices in accordance with Canadian law.
13. Additional Terms for U.S. Customers
The terms applies to individuals that are located within the United States, and supplements the terms in the rest of the Privacy and Cookies Policy.
13.1 Information we collect and share
For purposes of this Section 13, personal information does not include:
- Deidentified, aggregated or anonymized information that is maintained in a form that is not capable of being associated with or linked to you; or
- Publicly available information from federal, state or local government records.
As described further in Section 5 “Disclosure of personal information” in our Privacy and Cookies Policy, we share personal information with our service providers and contractors that help us operate our business. We may also share personal information with a variety of third parties and affiliated entities; if we are subject to certain corporate transactions or reorganizations; with third parties to comply with law or to protect our rights or the rights and safety of others; or for purposes otherwise disclosed or for which you have consented.
In the last 12 months, we have collected the following categories of personal information:
- Identifiers, such as name, email address, online identifiers and other information;
- Categories of personal information described in Cal. Civ. Code 1798.80(e), such as name, address, telephone number, credit card or debit card number;
- Characteristics of protected classifications under California or federal law, such as gender and age noted in ID documents that you submit so that we can verify your identity;
- Biometric information, such as biometric identifiers from photo IDs used to confirm your identity;
- Geolocation Data, such as location information from your device or estimated based on your IP address;
- Other Personal Information, such as information you submit to us, calls, email or other correspondences;
- Commercial Information about any transactions within our services such transaction information when you collect or make payments;
- Internet/Network Activity Information, such as browsing history, search history, IP address, device information, and log and analytics data.
13.2 Data retention
We retain your personal information for the period required by applicable laws and regulations. For example, records subject to the Bank Secrecy Act and applicable anti-money laundering regulations, including transaction and customer-identification records covered by 31 C.F.R. § 1010.430, are retained for a minimum of five years. Where permitted by applicable law, we may retain such information for a longer period in accordance with our internal policies and procedures, including for the prevention and detection of fraud, risk management, security, dispute resolution, and the establishment, exercise, or defense of legal claims.
13.3 What sensitive personal information we collect and for what purposes we use that data?
Over the past 12 months, we have collected and disclosed the following categories of personal information from or about you or your device that state privacy laws may deem “sensitive”:
- Account Login: such as your username in combination with your password to access your online account.
- Government-issued Identifiers: such as your social security number, driver’s license number, passport number, tax identification number or other similar identifiers, government issued identification information. This information is collected directly from you.
- Financial information: such as your bank account details, credit card or debit card numbers. This information is collected directly from you or from third party financial institutions who you may hold an account with.
- Precise location data such as your mobile device GPS. This information is collected directly from you.
For California residents, we do not use or disclose sensitive personal information outside of the permitted purposes set forth under Section 7027(m) of the California Consumer Privacy Act Regulations.
For all other residents to whom this Section 13 applies, we only use or disclose sensitive personal information for the following purposes, where such use or disclosure is necessary and proportionate for those purposes: for performing services you have requested; for detecting security incidents, fraud and other illegal actions; to ensure the physical safety of natural persons; to perform services on behalf of the business; or for short term transient use. We only collect and process sensitive personal information without the purpose of inferring characteristics about an individual, and we do not sell sensitive personal information or process or otherwise share sensitive personal information for the purpose of targeted advertising. For Maryland residents, the collection and/or processing of sensitive personal information is strictly necessary to provide and/or maintain a specific product or services you requested.
13.4 Do we “sell” or “share” my personal information under the CCPA?
The CCPA defines “sell” as disclosing or making available personal information to a third-party in exchange for monetary or other valuable consideration, and “share” includes disclosing or making available personal information to a third-party for purposes of cross-context behavioral advertising,whether or not for monetary or other valuable consideration.
In the past 12 months, we have not sold or shared personal information within the meaning of “sell” or “share” in the CCPA. We do not sell or share sensitive personal information, nor do we sell or share any personal information about individuals who we know are under sixteen (16) years old.
13.5 Your privacy rights
You may be able to exercise the following rights in relation to the personal information about you that we have collected (subject to certain limitations and exceptions at law):
| Right to Know | The right to request the following information relating to the personal information we have collected about you and disclosed about you:
|
| Right to Access/ Portability | The right to access and obtain a copy of the specific pieces of personal information we have collected about you in a structured, machine-readable format that may be transmitted to another entity without hindrance, to the extent technically feasible. |
| Right to Correct | The right to request that we correct your inaccurate personal information maintained by us. |
| Right to Delete | The right to request the deletion or erasure of personal information we have collected from you, subject to certain exceptions. |
| Right to Limit Use and Disclosure of Sensitive Personal Information | The right to direct us only use your sensitive personal information (for example, your social security number, financial account information, or your precise geolocation data) for limited purposes, such as providing you with the services you requested. |
| Right to Opt Out of Data Sales or Sharing | The right to direct us not to sell or share personal information we have collected about you to third parties, including for ad targeting/cross contextual advertising. |
| Right to Withdraw Consent | The right to withdraw your consent for processing your personal information if you have provided consent for such processing. |
| Right to Appeal | The right to submit an appeal if your request is denied. |
| Right to Nondiscrimination | The right not to receive discriminatory treatment for exercising any of your privacy rights under applicable U.S. laws. |
| California’s “Shine the Light” Law | California’s “Shine the Light” law (Civil Code § 1798.83) also permits California residents that have an established business relationship with us to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes during the immediately preceding calendar year or to have the right to opt-out of such disclosures. |
We aim to fulfill all verified requests within 45 days pursuant to applicable state privacy laws. The time period to provide the required information may be extended once by an additional 45 days when reasonably necessary, provided that we notify you of the extension and the reason for it within the initial 45-day period. Where permitted by state privacy laws, any disclosures will cover only the 12-month period preceding the verifiable rights request's receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable.
14. Contact and Your Data Protection Rights
14.1 This Privacy and Cookies Policy applies to the processing activities in which PhotonPay acts as the data controller.
14.2 If you have any questions, comments, requests, or complaints regarding this Privacy and Cookies Policy or the way we handle your personal data, you are welcome to contact us at:dpo@photonpay.com. If you would like more information about any third parties with whom we may share your personal data—including the purposes for such sharing, how the data is processed, and how you can exercise your data protection rights in relation to these third parties—please contact us using the email address above.
14.3 You also have the right to lodge a complaint with a data protection authority, including in the country where you live or work, or where you believe your rights have been infringed.
15. Privacy and Cookies Policy changes
This Privacy and Cookies Policy may be revised over time as new features are added to the PhotonPay services or as we incorporate suggestions from our stakeholders. We may change this Privacy and Cookies Policy at any time by posting a revised version of it on our website. We will provide you with at least 30 days' prior notice of the effective date of the revised Privacy and Cookies Policy when it is legally required. We may post the notice on the front page of our website(s) and/or send the notice by e-mail. As of the effective date of the revised Privacy and Cookies Policy, you will be considered as having consented to all changes to the Privacy and Cookies Policy. If you disagree with the terms of this Privacy and Cookies Policy, you may close your account at any time.
16. Liability
TO THE EXTENT PERMISSIBLE UNDER APPLICABLE LAWS AND GDPR REGULATIONS, WE ARE NOT LIABLE TO YOU IN RESPECT OF ANY CLAIMS, LOSSES, DAMAGES, EXPENSES (INCLUDING REASONABLE LEGAL FEES) ARISING OUT OF OR IN CONNECTION WITH THE USE AND/OR DISCLOSURE OR DISSEMINATION OF THE USER DATA IN ACCORDANCE WITH THIS PRIVACY POLICY AND ANY CONSENTS THAT YOU MAY HAVE OTHERWISE PROVIDED TO US.
