1. Scope
This Policy covers personal data we process as a controller for our website, sales, and marketing; and, where we process transaction or end-customer data on behalf of merchants, we generally act as a processor / service provider under the merchant’s instructions and a data processing agreement when required.
2. Data we collect
Account & business data: name, work email, phone, company, role, billing contacts, KYC/KYB materials you submit, and support correspondence.
Technical data: IP address, device/browser type, approximate location, logs, cookies or similar technologies, and usage analytics for the website and dashboards.
Payment operational data: transaction identifiers, amounts, currencies, status codes, routing outcomes, token references, and related fraud/3DS signals needed to run orchestration. Where card numbers are processed, we use approved integration patterns and tokenize data; we do not use raw PAN for marketing.
3. How we use data
- Provide, secure, and improve the Services
- Authenticate users and prevent abuse or fraud
- Process subscriptions, routing, and support tickets
- Bill, collect fees, and keep financial records
- Communicate product updates, security notices, and (with consent where required) marketing
- Comply with law, scheme rules, and audits
4. Legal bases (where GDPR/similar applies)
We rely on performance of a contract, legitimate interests (secure and improve services, B2B communications), consent (where required for cookies/marketing), and legal obligations (e.g. accounting, sanctions screening support).
5. Sharing
We may share data with: cloud hosting and security vendors; processors, acquirers, card networks, and 3DS providers you enable; analytics and email tools; professional advisors; and authorities when legally required. We do not sell personal data. Subprocessors are bound by contractual confidentiality and security terms.
6. International transfers
We may process data in regions where we or our subprocessors operate (including APAC and other commercial cloud regions). Where required, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms.
7. Retention
We keep data only as long as needed for the purposes above, then delete or anonymize it, unless a longer period is required for legal claims, accounting, or scheme rules. Transaction logs may be retained for audit and dispute resolution windows typical in payments.
8. Security
We implement administrative, technical, and physical safeguards aligned to common industry practice for payment platforms (access control, encryption in transit, logging, vulnerability management). No method of transmission or storage is 100% secure; please protect your credentials and report suspected incidents promptly.
9. Cookies
We use necessary cookies for security and language preferences, and may use analytics cookies to understand site performance. You can control cookies via browser settings; some features may not work if essential cookies are blocked.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing or withdraw consent. To exercise rights, email alano@fintrix.world. If we process data only for a merchant, we may redirect you to that merchant as controller.
11. Children
The Services are directed to businesses and are not intended for children under 16 (or higher age where required). We do not knowingly collect personal data from children.
12. Changes
We may update this Policy by posting a new version and revising the “Last updated” date. Material changes will be highlighted by reasonable notice where required.
13. Contact
Privacy requests: alano@fintrix.world