In short: we collect the minimum needed to run the platform, we never sell personal data, and where we handle data for a customer institution we act only on their written instructions.
1. Who we are
SecurePaymentz (“SecurePaymentz”, “we”, “us”) provides banking connector, merchant gateway, card programme and core banking software to financial institutions and licensed operators.
The data controller responsible for personal data described in this policy is SecurePaymentz, Inc., registered at 1 Federal Street, Boston, MA 02110, United States.
Where we process personal data on behalf of a customer institution, that institution is the controller and we act as processor under our written agreement with them.
2. Scope of this policy
This policy covers personal data we process as a controller: visitors to our website, prospective and current customer contacts, applicants, and users of our sandbox and support channels.
It does not cover data we process as a processor on behalf of customer institutions — that processing is governed by our agreement with the institution, and by their privacy notice to their end users.
3. Data we collect
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, business email, phone, employer, job title | You provide it |
| Account | Username, sandbox credentials, authentication logs | Created on sign-up |
| Usage | Pages viewed, features used, API calls, timestamps | Collected automatically |
| Device & network | IP address, browser, operating system | Collected automatically |
| Communications | Support tickets, emails, call notes | You provide it |
| Compliance | Identity documents and sanctions screening results for customer onboarding | You provide it, plus screening providers |
We do not intentionally collect special category data (health, biometrics, political or religious views) through our website or sandbox. Please do not submit it through support channels.
4. How we use data
- To provide, operate and secure the platform and sandbox
- To respond to enquiries and provide support
- To meet legal, regulatory and audit obligations
- To detect, investigate and prevent fraud and abuse
- To improve our products and understand how they are used
- To send service messages, and — with your consent where required — marketing communications
Automated decision-making: we do not make decisions with legal or similarly significant effects about you by automated means alone. Fraud and sanctions screening may flag activity automatically, but a person reviews every outcome before action is taken.
5. Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on:
| Basis | Used for |
|---|---|
| Contract | Providing the platform and support to customers |
| Legitimate interests | Security, fraud prevention, product improvement, business development |
| Legal obligation | Regulatory reporting, record keeping, responding to lawful requests |
| Consent | Marketing communications and non-essential cookies |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may request a summary of that assessment.
7. International transfers
We are based in the United States and may transfer personal data internationally. Where we transfer data out of the EEA or UK, we rely on the European Commission Standard Contractual Clauses, together with the UK International Data Transfer Addendum where relevant. A copy of the relevant safeguard is available on request.
8. How long we keep data
We keep personal data only as long as necessary for the purposes described, then delete or anonymise it.
| Data | Retention period |
|---|---|
| Customer account records | Duration of the contract, then 7 years |
| Transaction and audit logs | 7 years, as required by financial regulation |
| Support correspondence | 3 years from last contact |
| Marketing contacts | Until you unsubscribe, then suppression-list only |
9. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.3), access controls, least-privilege administration, logging and monitoring, and regular review of our controls.
We describe only controls we actually hold, and our compliance team can share the underlying documentation under NDA.
If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority as required by law.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict processing of your personal data, to object to processing, and to withdraw consent at any time.
EEA and UK residents
You may lodge a complaint with your local supervisory authority. Our EU/UK representative, where appointed, can be reached through our privacy contact form.
California residents
Under the CCPA/CPRA you may request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising these rights.
To exercise any right, contact us using the details below. We will verify your identity before responding, and will reply within the period required by applicable law.
12. Children
Our services are intended for businesses and are not directed to children under 16. We do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. We will change the “last updated” date above, and for material changes we will provide additional notice — by email or a notice on the site — before the change takes effect.
14. Contact us
Privacy enquiries
Email: Send a privacy enquiry via our contact form
Phone: 802-448-2467
Post: 1 Federal Street, Boston, MA 02110
Data Protection Officer: reachable through our contact form.