01 — StandingRegistrations and supervision
Push2Pay Corp Ltd is incorporated in England with its registered office in London. Our activity is supervised under two separate regimes: the anti–money laundering regime administered by FINTRAC, and the retail payments regime administered by the Bank of Canada.
Registered foreign money services business under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA).
FINTRAC FMSB registry
Registered payment service provider under the Retail Payment Activities Act, supervised by the Bank of Canada.
Bank of Canada PSP registry
Cardholder data is captured and tokenised inside PCI DSS assessed environments. Push2Pay does not store primary account numbers.
Personal information is handled under Canadian federal privacy law. See our Privacy Policy.
Push2Pay is a payment facilitator and technology provider. We are not a bank and we do not hold deposits. Card acquiring, settlement and the underlying merchant accounts are provided by licensed acquiring institutions and licensed payment institutions in the markets where your volume runs. Each of them applies its own licence conditions on top of ours.
Verify us. Our FMSB registration can be checked directly in FINTRAC's public FMSB registry search, and our PSP registration in the Bank of Canada's public register of payment service providers. If a counterparty presents credentials in our name that do not match those registers, tell us at info@push2pay.co.
02 — FrameworkOur AML/CTF compliance programme
The PCMLTFA requires every registered FMSB to maintain a documented compliance programme. Ours has five standing parts, and each of them is a real function inside the business rather than a policy in a drawer.
| Element | What it means in practice |
|---|---|
| Appointed compliance officer | A named officer with the authority to decline a file, freeze a merchant account and file a report without commercial sign-off. Sales cannot overrule compliance. |
| Written policies and procedures | Board-approved policies covering identification, record keeping, reporting, escalation and the handling of ministerial directives, kept current with the law. |
| Risk assessment | A documented assessment of the money laundering and terrorist financing risk in our products, delivery channels, geographies, and each merchant relationship — with mitigation set against the rating. |
| Ongoing training | Mandatory, recorded training for every employee and contractor who onboards merchants, touches transactions or handles customer data. |
| Two-year effectiveness review | An independent review of the programme at least every two years, testing whether the controls actually work. Findings are remediated on a tracked plan. |
Where a merchant's volume touches other jurisdictions, the local regime applies alongside the Canadian one — for example the EU anti–money laundering directives, the UK Money Laundering Regulations, or local licensing rules for gaming and financial services. We do not treat an offshore acquirer as a way around any of it.
03 — OnboardingMerchant onboarding: KYB and KYC
Every applicant is identified before a MID is requested, and re-verified periodically after going live. The file is proportionate to risk, but the following is the floor for a commercial applicant:
Business identification (KYB)
- Certificate of incorporation, current corporate registry extract and articles
- Ownership chart to the ultimate beneficial owners, with every natural person holding 25% or more identified directly
- Directors and senior officers, with government-issued photo identification
- Proof of registered and operating address
- Any licence the vertical requires — gaming, financial services, money transmission, pharmacy — issued by the regulator of the market being served
- Bank account confirmation in the legal entity's own name
Business and financial review
- Processing history and prior statements, plus disclosure of any previous termination, MATCH/Terminated Merchant File listing, or scheme monitoring programme
- Expected volume, average ticket, currencies, target markets and settlement pattern
- Source of funds and source of wealth where the risk rating calls for it
- Full review of the live website or app: pricing, terms, refund and cancellation policy, delivery terms, contact details and the descriptor that will appear on statements
Screening
- Sanctions and terrorist-entity screening of the entity, owners and officers
- Politically exposed person and head of international organisation determination, including family members and close associates
- Adverse media and litigation checks
- Third-party determination — whether anyone other than the merchant instructs the account
Enhanced due diligence
Enhanced due diligence is applied — and approval escalated to the compliance officer — when the applicant is a PEP, sits in or serves a higher-risk jurisdiction, uses a complex or opaque ownership structure, operates in a vertical with elevated chargeback or fraud exposure, cannot evidence source of funds, or has been terminated by a previous processor. EDD means more documentation, tighter limits, reserves, and shorter review cycles — not an automatic refusal.
Refusal is a normal outcome. If we cannot identify the people behind a business, or the answers keep changing, the file is declined. We would rather lose the application than explain it to a regulator later.
04 — OngoingTransaction monitoring and reporting
Live volume is monitored automatically against the profile that was underwritten. Rules and scoring look for the patterns that matter in this business: sudden deviation from declared volume or ticket size, transaction laundering through an unrelated descriptor, card testing, structuring below thresholds, unusual refund or reversal behaviour, velocity spikes, mismatch between the billing geography and the market that was approved, and traffic from sanctioned or restricted regions.
Alerts are worked by analysts, not closed by a script. Where the review does not resolve the suspicion, we report it. Our reporting obligations to FINTRAC include:
- Suspicious transaction reports — filed where there are reasonable grounds to suspect a transaction, attempted or completed, is related to money laundering or terrorist financing. There is no minimum amount.
- Terrorist property reports — filed where property is known to be owned or controlled by, or on behalf of, a listed terrorist entity.
- Electronic funds transfer reports — for international transfers of CAD 10,000 or more, including two or more transfers in a 24-hour window that total that amount.
- Large cash and large virtual currency transaction reports — where the CAD 10,000 threshold is met in the relevant form.
Records supporting identification, transactions and reports are retained for at least five years, as the PCMLTFA requires. Reporting is a legal duty: we are prohibited by law from telling a merchant that a suspicious transaction report has been made about them, and no request from a merchant will change that.
05 — SanctionsSanctions and restricted jurisdictions
Merchants, beneficial owners, directors and counterparties are screened at onboarding and re-screened continuously as lists change. We screen against, at minimum:
- Canadian sanctions under the United Nations Act, the Special Economic Measures Act and the Justice for Victims of Corrupt Foreign Officials Act
- Terrorist entities listed under the Criminal Code
- OFAC (United States), EU consolidated and UK OFSI lists, where the volume, currency or correspondent relationship brings them into scope
A confirmed match is not a commercial negotiation. The relationship is stopped, the property is frozen where the law requires it, and the matter is reported to the competent authority. We also apply our own country policy on top of formal sanctions, and will not board businesses that direct their traffic at markets they have no right to serve.
We give effect to any ministerial directive or transaction restriction issued in respect of a foreign jurisdiction or entity, including the enhanced measures and reporting such a directive imposes.
06 — SchemesCard scheme rules and dispute performance
Alongside the law, card business runs on the rules of Visa, Mastercard and the other schemes. Those rules bind every merchant we place, and breaching them costs a merchant account faster than almost anything else.
- Registration. Merchants in scheme-designated high-risk categories must be registered with the scheme through the acquirer before they process, with the correct merchant category code. Miscoding to hide a vertical is a termination event.
- Integrity programmes. Visa's integrity risk programme and Mastercard's equivalent business risk programme prohibit processing for illegal or brand-damaging activity. Fines under these programmes are levied on the acquirer and passed down.
- Dispute and fraud monitoring. Acquirer and merchant fraud and dispute ratios are monitored against scheme thresholds. We watch yours daily and warn you before a threshold is breached, because the remediation timelines once you are in a programme are short and the fees escalate monthly.
- Authentication. 3-D Secure 2 is supported across our gateway, and is mandatory where the market requires strong customer authentication.
- Transaction laundering. Processing another party's transactions through your MID, or routing traffic from a site that was never underwritten, ends the relationship immediately and is reportable.
Where volume justifies it, we place merchants on more than one acquirer so that a single acquirer tightening its appetite does not take a business offline. Redundancy is a control, not a way to spread ratios thin — every MID carries its own underwriting, and volume is not moved to conceal performance.
07 — SecurityData and cardholder data security
- Card capture happens in PCI DSS assessed environments. Card numbers are exchanged for tokens; Push2Pay systems and merchant systems work with tokens, not PANs.
- Data is encrypted in transit with current TLS and at rest in our processing environments.
- Access follows least privilege, with role-based permissions, mandatory multi-factor authentication for staff, and logged administrative activity.
- Environments are segmented, patched on a defined cycle, and subject to vulnerability scanning and periodic penetration testing by external testers.
- A documented incident response plan governs detection, containment and notification. Privacy breach obligations are described in the Privacy Policy.
- Merchants that touch card data are responsible for their own PCI DSS validation at the level their integration requires. We will tell you which level applies to yours.
08 — AppetiteWhat we board, and what we refuse
Being a high-risk specialist means we underwrite verticals most processors decline on the application form. It does not mean we take everything. The first list is supported with conditions; the second is not supported at any price, in any market, for any commercial terms.
Supported, with conditions
Boarded subject to licensing, geography, disclosure and the controls set at underwriting.
- Crypto and fiat on-ramps — registered or licensed where the market requires it
- Forex and CFD brokers — with a regulator's licence for each market served
- iGaming and betting — licensed, and geo-blocked out of markets not covered
- Travel and ticketing — with delivery risk, bonding and reserves assessed
- Subscriptions and continuity — clear pricing, easy cancellation, no negative-option billing
- Marketplaces, P2P and payouts — with onboarding of the sellers behind the platform
Never boarded
Declined outright. This list is not negotiable and does not depend on volume.
- Anything illegal in the merchant's jurisdiction or the customer's
- Child sexual abuse material, or any non-consensual content
- Human trafficking, forced labour, or the sale of organs
- Weapons, explosives and ammunition sold outside a licensed channel
- Narcotics, precursors, research chemicals, and prescription drugs sold without a prescription
- Sanctioned parties, and any business serving an embargoed market
- Ponzi and pyramid schemes, HYIPs, matrix and "get rich quick" programmes
- Unlicensed gambling, and gaming aimed at markets the licence does not cover
- Ransomware, malware, stolen data, carding, mixers used to break traceability
- Shell banks, and payment aggregation for undisclosed third parties
- Counterfeit goods and intellectual property theft
- Endangered species, protected wildlife and their derivatives
Concealment is its own offence. An applicant who misrepresents the vertical, hides a beneficial owner, or points a MID at a site other than the one underwritten is terminated and, where appropriate, reported to the schemes and the authorities — whatever the volume was worth.
09 — Your sideWhat we expect from a merchant
Approval is the start of an ongoing obligation on both sides. Once live, a merchant must:
- Keep every licence, permit and registration current, and send us the renewal before it lapses
- Tell us in advance about any change of beneficial ownership, control, business model, product line, target market or website — before it goes live, not after
- Process only the activity that was underwritten, through the MID it was underwritten for
- Display accurate pricing, terms, refund and cancellation policies, and a working contact route, and use a billing descriptor a cardholder will recognise
- Answer customers, refund what should be refunded, and keep dispute ratios inside scheme thresholds
- Respond to compliance requests for information within the time we give — usually short, because the acquirer has given us the same deadline
- Maintain their own PCI DSS validation and their own privacy obligations to their customers
- Never share credentials, gateway access or a MID with a third party
Where an obligation is missed, we escalate proportionately: a request for information, then limits, reserves or a pause on settlement, and termination where the risk cannot be managed. Serious breaches — illegality, laundering, concealment — skip the ladder.
10 — RecourseComplaints and reporting a concern
Under the retail payments regime we maintain a documented complaints process. Send a complaint to info@push2pay.co with the account name and what happened. We acknowledge in writing, investigate, and reply with a decision and the reasons for it. If you are not satisfied with the outcome, we will tell you how to escalate it, including to the relevant regulator or external complaints body.
If you believe someone is misusing our services — fraud, laundering, an undisclosed business, or a merchant operating outside its licence — report it to the same address, marked for the compliance officer. Reports may be made anonymously. We do not retaliate against anyone who raises a concern in good faith, whether they are staff, a merchant or a member of the public.
For a payment dispute with a merchant, contact the merchant first, then your card issuer or bank. We cannot reverse a payment made through a merchant on our platform on our own authority.
11 — ContactThe compliance desk
Regulators, acquirers, banking partners and law enforcement can reach the compliance function directly. Requests for information should identify the requesting body and the legal basis for the request.
Push2Pay Corp Ltd — Compliance
- Attention
- Compliance Officer
- info@push2pay.co
- Registered office
- Flat 4 6 Bank Buildings, High Street
London, England, NW10 4LT - Registrations
- Registered FINTRAC FMSB · RPAA registered payment service provider
Scope of this page. This is a plain-language summary of our compliance framework for merchants, partners and the public. It is not legal advice, it is not a warranty of any particular outcome for an applicant, and it does not form part of any contract. Where this page and a signed merchant agreement differ, the agreement governs. We update the page as the law and the scheme rules change; the effective date at the top shows the current version.