01 — IdentityWho we are
In this policy, "Push2Pay", "we" and "us" mean Push2Pay Corp Ltd, a company incorporated in England with its registered office at Flat 4 6 Bank Buildings, High Street, London, England, NW10 4LT. We are a registered foreign money services business with FINTRAC and a registered payment service provider under the Retail Payment Activities Act.
We handle personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and the ten fair information principles in its Schedule 1. Where we serve people in Quebec, the province's private-sector privacy law applies as well. Where we offer services to people in the European Economic Area or the United Kingdom, the GDPR and UK GDPR apply to that processing, and the extra rights in section 12 are available to them.
We have appointed a privacy officer who is accountable for our compliance with this policy. Their contact details are in section 16.
02 — ScopeWho this policy covers
This policy applies to four groups, and the treatment differs for each.
| Group | Our role |
|---|---|
| Website visitors | Anyone browsing push2pay.co or contacting us through the site. We decide what is collected and why. |
| Merchant applicants and merchants | The business and the individuals behind it — directors, officers, beneficial owners and authorised contacts. We decide what is collected and why, and the law tells us much of it. |
| Cardholders and end customers | People who buy from a merchant we serve. The merchant decides why that data is collected; we process transaction data on their instructions and under our own legal duties as a payment service provider. See section 13. |
| Partners, suppliers, applicants for jobs | Contact and contract data needed to work together, and application data needed to consider a candidate. |
This policy does not cover the privacy practices of any merchant, acquirer, bank or third-party website you reach from ours. Those organisations publish their own policies and are responsible for them.
03 — CollectionInformation we collect
We collect what we need for the purpose, and no more. In practice, that is:
Identity and contact information
- Name, job title, business email address, telephone number, business address
- Date of birth and nationality, where identity verification requires it
- Government-issued identification — passport, driving licence or national ID — for directors, officers and beneficial owners
Business and due diligence information
- Corporate registration documents, ownership structure and beneficial ownership to 25%
- Licences and permits held, and the markets they cover
- Processing history, prior terminations, banking references and financial statements
- Source of funds and source of wealth information where the risk rating requires it
- The results of sanctions, politically exposed person and adverse media screening
Transaction and payment information
- Transaction amount, currency, date and time, merchant, descriptor and status
- Tokenised card references, the card brand, issuing country, and the first six and last four digits used for routing and fraud checks
- Settlement and payout account details
- Chargeback, dispute and refund records
We do not store full card numbers. Card details are captured inside PCI DSS assessed environments and replaced with a token. Push2Pay systems, and your systems, work with the token. We never store the CVV/CVC after authorisation.
Technical information
- IP address, approximate location derived from it, device and browser characteristics
- Server log data: pages requested, timestamps, referring page, error records
- Fraud signals such as device fingerprint and velocity data, on transactions we process
Communications
- The content of emails, contact forms, support tickets and messages you send us
- Records of compliance requests and your responses to them
We collect this from you directly, from your use of our services, and from third parties we are entitled to use: corporate registries, sanctions and PEP list providers, identity verification and fraud prevention services, credit reference agencies, card schemes and acquiring banks, and publicly available sources.
04 — PurposeWhy we use it
PIPEDA requires us to identify the purpose before or at the time we collect. Ours are:
| Purpose | What that involves |
|---|---|
| Assessing an application | Underwriting a merchant file, verifying the business and the people behind it, and presenting the file to acquiring partners. |
| Meeting AML obligations | Identification, record keeping, ongoing monitoring, sanctions screening and reporting under the PCMLTFA and equivalent laws elsewhere. |
| Providing the service | Opening and maintaining merchant accounts, routing and processing transactions, settlement, payouts, reporting and reconciliation. |
| Fraud and risk management | Detecting fraud, transaction laundering and misuse; managing chargeback exposure, reserves and scheme monitoring programmes. |
| Support and communication | Answering questions, handling incidents, resolving disputes and complaints. |
| Security and continuity | Protecting our systems, investigating incidents, and maintaining audit trails. |
| Legal and regulatory | Responding to regulators, auditors, courts and law enforcement; establishing or defending legal claims. |
| Business communication | Sending service notices, and — only where you have asked for it — commercial email, which always carries an unsubscribe link. |
We do not sell personal information. We do not rent or trade it. We do not use merchant or cardholder data to build advertising profiles, and we do not use it to train machine learning models for anyone outside our own fraud and risk controls.
Automated decisions. Fraud scoring and monitoring rules run automatically and may block or hold a transaction. Decisions with a significant effect on a business or an individual — declining an application, suspending settlement, terminating a merchant — are reviewed by a person before they take effect, except where an immediate freeze is required by law. You can ask us to explain a decision and to have it reviewed.
05 — BasisConsent, and when it does not apply
For most of what we do with your information, our basis is that you asked us to provide a service and gave your consent for the information needed to deliver it. Consent may be express — signing an application, ticking a box — or implied by your use of the service where the purpose is obvious.
You can withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice. Understand what that means in this industry: if you withdraw consent for the identification and monitoring the law requires, we cannot lawfully continue to provide the service, and the relationship ends.
PIPEDA allows collection, use and disclosure without consent in defined situations, and we rely on those where they apply. The main ones for us are:
- Where a federal or provincial law requires it — anti–money laundering identification, record keeping and reporting are the clearest example. We are prohibited from telling you that a suspicious transaction report has been made.
- To investigate a breach of an agreement or a contravention of law, or to detect, suppress or prevent fraud, where seeking consent would compromise the investigation.
- To comply with a subpoena, warrant, court order or lawful request from a body with jurisdiction to compel production.
- In an emergency threatening the life, health or security of an individual.
For people in the EEA and UK, the equivalent legal bases under the GDPR are performance of a contract, compliance with a legal obligation, our legitimate interests in preventing fraud and running our business securely, and consent where we ask for it — for example for marketing email.
07 — LocationWhere your information is processed
Our primary processing is in Canada. Because acquirers, schemes and technology suppliers operate internationally, personal information may also be processed or stored in the European Economic Area, the United Kingdom, the United States and other countries where our partners operate.
PIPEDA requires us to be plain about the consequence: while your information is in another country, it is subject to the laws of that country, and may be accessible to its courts, law enforcement and national security authorities under those laws. We reduce the exposure by contract — data processing terms, confidentiality obligations, security standards and, for transfers out of the EEA or UK, Standard Contractual Clauses or an adequacy decision where one applies.
You can ask our privacy officer for more information about our transfer safeguards and the countries involved for your particular relationship.
09 — SafeguardsHow we protect it
We apply safeguards proportionate to the sensitivity of the information, and identity documents and financial data sit at the sensitive end.
- Encryption in transit using current TLS, and encryption at rest in our processing environments
- Card data captured and tokenised inside PCI DSS assessed environments; no PAN storage on our side
- Role-based access on a need-to-know basis, mandatory multi-factor authentication for staff, and logged administrative activity
- Network segmentation, a defined patching cycle, vulnerability scanning and periodic external penetration testing
- Confidentiality obligations and privacy training for every employee and contractor who touches personal information
- Secure destruction of records at the end of the retention period
No system is perfectly secure, and we will not claim otherwise. What we commit to is proportionate protection, honest notification when something goes wrong, and no quiet downgrades of these controls.
10 — IncidentsBreach notification
If a breach of our security safeguards creates a real risk of significant harm to an individual, PIPEDA requires us to report it to the Office of the Privacy Commissioner of Canada and to notify the affected individuals as soon as feasible. We do both, and we notify any other organisation or authority that can reduce the harm.
Notice will tell you what happened, what information was involved, what we have done, and what you can do to protect yourself. We keep records of every breach of security safeguards for at least 24 months, whether or not it was reportable, and we make those records available to the Commissioner on request. Where the GDPR applies, we notify the competent supervisory authority within 72 hours where the regulation requires it.
11 — RetentionHow long we keep it
We keep personal information only as long as it is needed for the purpose it was collected for, or as long as the law requires — whichever is longer. Anti–money laundering law sets the floor, and it is not short.
| Record | Retention |
|---|---|
| Merchant identification and due diligence records | At least 5 years after the end of the relationship (PCMLTFA) |
| Transaction records and reports filed with FINTRAC | At least 5 years from the date of the transaction or report |
| Contracts, invoices and accounting records | As required by tax and corporate law, generally 6–7 years |
| Dispute and chargeback evidence | For the scheme dispute window and any resulting claim period |
| Declined applications | Retained for the period needed to evidence the decision, then destroyed |
| Website server logs | Short-term, for security and troubleshooting only |
| Marketing preferences | Until you unsubscribe, plus a suppression record so we do not contact you again |
When a retention period ends, records are securely destroyed, erased or anonymised. A request to delete data we are legally required to hold will be refused for that data, and we will tell you which obligation applies.
12 — Your rightsWhat you can ask us to do
Wherever you are, you can:
- Ask what we hold. Request access to your personal information, how it has been used, and to whom it has been disclosed.
- Correct it. Have inaccurate or incomplete information amended, and have the correction passed to third parties who received it, where appropriate.
- Withdraw consent. Subject to legal and contractual restrictions, and to reasonable notice.
- Unsubscribe. Stop commercial email at any time using the link in the message, or by writing to us.
- Challenge our compliance. Complain to our privacy officer about anything in this policy or how we applied it.
We respond to access requests within 30 days, at no cost in ordinary cases, and will tell you in advance if a request requires an extension or a fee. We must verify your identity first. Some information can lawfully be withheld — for example anything that would reveal a suspicious transaction report, prejudice an investigation, breach solicitor–client privilege, or expose another person's personal information. Where we withhold, we tell you the reason.
Additional rights in the EEA and the UK
If the GDPR or UK GDPR applies to our processing of your data, you also have the right to erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and objection to decisions made solely by automated means with legal or similarly significant effects.
If you are not satisfied
Contact our privacy officer first — most issues are resolved there. If the answer does not satisfy you, you may complain to the Office of the Privacy Commissioner of Canada, to the Commission d'accès à l'information in Quebec, or to your own supervisory authority in the EEA or the UK. Complaining to a regulator is your right and never affects how we treat your account.
13 — CardholdersIf you bought from a merchant we serve
If you are a customer of a business that uses Push2Pay, we process your transaction data on that merchant's behalf, and under our own duties as a regulated payment service provider. We are not the party that collected your details or decided what to sell you.
- For a refund, a cancellation, or a question about an order — contact the merchant. Their name is on your statement descriptor.
- For a transaction you do not recognise or did not authorise — contact your card issuer or bank and ask about a dispute. They have the mechanism; we do not.
- To reach us anyway — write to info@push2pay.co with the descriptor, date and amount. We will identify the merchant and pass your request on, and we will answer any request relating to information we hold in our own right.
We do not use cardholder data for our own marketing, and we do not disclose it to anyone outside the purposes in section 6.
14 — ChildrenAge
Our services are for businesses. We do not offer them to children and we do not knowingly collect personal information from anyone under 18. If you believe a child's information has reached us, write to our privacy officer and we will delete it, unless a law requires us to keep it.
15 — UpdatesChanges to this policy
We update this policy when our practices, our partners or the law change. The effective date and version at the top of the page always show the current text. Where a change materially affects how we handle information about you, we will give notice by email or through the service before it takes effect. Superseded versions are available from our privacy officer on request.
16 — ContactOur privacy officer
Questions, access requests, corrections and complaints all go to the same place. Please say what you are asking for, and give us enough detail to find your records.
Push2Pay Corp Ltd — Privacy Officer
- Attention
- Privacy Officer
- info@push2pay.co
- Post
- Flat 4 6 Bank Buildings, High Street
London, England, NW10 4LT - Response
- Within 30 days of a verified request
Our compliance framework — registrations, AML programme, screening and the businesses we will not board — is set out on the Compliance page.
Scope of this policy. This policy describes our practices in plain language. It is not legal advice and does not form part of any contract. Where it differs from a signed merchant agreement or a data processing agreement, that agreement governs.