Legal
Privacy Policy
Version 3.6 — Last updated 1 July 2026. Applies to visitors, merchants, users of our dashboard and APIs, and End Customers of our merchants.
1. Who we are
This Privacy Policy is issued by Paytab Ltd, a company registered in England and Wales under company number 15234567, with its registered office at 1 Finsbury Avenue, London EC2M 2PP ("Paytab", "we", "us", "our"). We are registered with the Information Commissioner's Office ("ICO") under registration number ZA987654 and are authorised and regulated by the Financial Conduct Authority as an Authorised Payment Institution under firm reference number 987654.
Our Data Protection Officer can be reached at dpo@paytab.co.uk or by post at the address above, marked for the attention of the DPO.
2. Scope & controller/processor roles
This Privacy Policy applies to (a) visitors to paytab.co.uk, (b) users of the Paytab merchant dashboard, APIs and SDKs, and (c) End Customers of our merchants whose personal data we process in connection with a payment.
- Paytab acts as an independent controller for its own website traffic, corporate operations, marketing, merchant onboarding (KYC/KYB) and financial-crime prevention.
- Paytab acts as a joint controller with the merchant for the acceptance of a payment, including the fraud screening and risk decisioning that we are required to perform on every transaction.
- Paytab acts as a processor for the merchant in respect of End Customer contact and order data submitted through the merchant's hosted checkout, invoice or payment link, when used purely to fulfil the merchant's instructions.
3. Personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data.
- Merchant account data: business name, trading name, company registration number, VAT number, industry, website URL, business address, business email and phone.
- User & team-member data: full name, work email, phone, job title, profile picture, role and permission set, two-factor authentication device metadata.
- Identity & KYC data: passport, driving licence or national ID scans, selfie for liveness checks, proof of address (utility bill or bank statement), date of birth, nationality, tax residency, PEP/sanctions screening results, ultimate beneficial owner information and shareholding structure.
- Financial & transaction data: payment amount, currency, timestamp, payment method type, last four digits and expiry month/year of card, tokenised card reference, cardholder name, billing address, bank account reference for Open Banking or Faster Payments, wallet identifier, refund and chargeback history, settled amounts and payout destinations.
- End Customer data (as processor for the merchant): name, email, billing/shipping address, order line items, and the payment credentials supplied at checkout. Full card numbers and CVV never leave our PCI-scoped environment and are never returned to the merchant in clear.
- Fraud & risk data: device fingerprint, browser/user-agent, screen resolution, IP address, geolocation derived from IP, behavioural signals (typing cadence, form-fill velocity), 3-D Secure results and issuer risk scores.
- Technical & log data: API request/response metadata (excluding sensitive fields), dashboard access logs, webhook delivery logs, security event logs, error stack traces, and support-chat transcripts.
- Marketing & preference data: newsletter subscription status, communication preferences, event RSVP status, content interactions.
- Correspondence: the contents of any email, chat, phone or ticket you send us, and metadata about that correspondence.
4. Sources of personal data
We collect personal data (a) directly from you when you create an account, integrate our APIs or contact us, (b) automatically when you use our website or dashboard, (c) from your merchant when you pay through Paytab as an End Customer, (d) from third parties such as Companies House, HMRC, identity-verification vendors, sanctions and PEP data providers, credit-reference agencies, and Card Schemes, and (e) from publicly available sources such as your public company website or social profiles.
5. How we use personal data
- Provide the Service: onboard your business, authenticate you, route payments to Card Schemes and banks, settle funds, generate receipts and statements, deliver dashboard functionality.
- Comply with legal obligations: KYC, KYB, AML, sanctions screening, PEP screening, transaction monitoring, safeguarding of client funds, tax reporting, regulatory reporting to the FCA, HMRC and other authorities.
- Prevent fraud & financial crime: device fingerprinting, velocity checks, machine-learning risk scoring, 3-D Secure orchestration, chargeback defence.
- Security: detect and respond to security incidents, protect against unauthorised access, misuse or attack.
- Customer support: respond to queries, tickets and disputes, investigate reported problems.
- Improve the platform: aggregated, anonymised analytics on API usage, checkout conversion, dashboard behaviour, and A/B testing of new features.
- Communicate with you: service notifications, security alerts, statutory notices, product changes and — with your consent where required — marketing communications.
- Corporate transactions: in connection with a proposed or actual merger, acquisition, financing, restructuring, or sale of assets.
6. Lawful bases
Under UK GDPR we process personal data on the following lawful bases: (a) performance of a contract with you or steps taken at your request prior to entering into a contract; (b) compliance with a legal obligation to which we are subject, in particular the PSRs, MLR 2017 and Card Scheme rules; (c) our legitimate interests in operating, securing and improving the Service, preventing fraud and financial crime, and marketing our business to existing customers, balanced against your rights and interests; and (d) your consent, for example for non-essential cookies and for marketing to prospects.
7. Automated decision-making & profiling
Every payment processed through Paytab is scored in real time by our fraud and risk-decisioning models. This may result in an automated decision to decline, challenge with 3-D Secure, or approve a transaction, without human involvement. You (or the End Customer) have the right to obtain human intervention, express your point of view, and contest such decisions by contacting dpo@paytab.co.uk.
Where we perform sanctions or PEP screening, matches are always reviewed by a trained human analyst before any adverse action is taken.
8. Marketing communications
We send service and security notices at any time — you cannot opt out of these because they are necessary for the Service. We send product-marketing emails only where you have opted in, or where you are an existing customer and the marketing relates to similar products (a "soft opt-in" under PECR). Every marketing email includes an unsubscribe link, and you can update preferences in your dashboard at any time.
9. Cookies & similar technologies
We use strictly-necessary cookies to keep you signed in to the dashboard, to remember your language preference, and to protect against cross-site request forgery. With your consent, we also use analytics cookies to understand aggregate usage of our website and to help us improve it. We do not use cookies for cross-site behavioural advertising. Manage your preferences in the cookie banner or your browser settings.
10. Sharing & disclosures
We share personal data with the following categories of recipient, only to the extent necessary and under appropriate contractual protections:
- Card Schemes (Visa, Mastercard, American Express) and acquiring banks to process payments and defend chargebacks.
- Identity-verification, sanctions and PEP data providers to comply with KYC/AML rules.
- Cloud hosting, database, monitoring, email delivery, analytics and support software providers acting as our processors.
- Professional advisers (lawyers, auditors, insurers, accountants) under duties of confidence.
- Regulators, law enforcement, courts, tax and other authorities where required by law or where necessary to protect our rights.
- A prospective purchaser of our business or assets, subject to appropriate confidentiality undertakings.
- Any other person with your explicit consent.
We do not sell personal data.
11. Sub-processors
Our current list of sub-processors — including the service each provides and its location — is published at paytab.co.uk/legal/sub-processors. We provide at least 30 days' notice via email or in-dashboard notification before appointing a new sub-processor with access to merchant or End Customer personal data. Merchants who process personal data as controllers may object under the DPA.
12. International transfers
Paytab primarily stores personal data in the United Kingdom and the European Economic Area. Where we transfer personal data outside the UK/EEA — for example, to a sub-processor headquartered in the United States or to an End Customer's card issuer overseas — we rely on one or more of the following safeguards: (a) an adequacy decision by the UK Government or European Commission, (b) the UK International Data Transfer Agreement, (c) the EU Standard Contractual Clauses supplemented by the UK Addendum, or (d) another lawful transfer mechanism recognised under UK GDPR. We supplement these with a transfer impact assessment and, where appropriate, additional technical and organisational measures.
13. Security
We maintain a written information-security programme aligned to ISO 27001 and PCI DSS v4.0 Level 1. Measures include: (a) segmentation of our PCI-scoped card-data environment, (b) tokenisation of card numbers so that clear pans are never returned to merchant systems, (c) AES-256 encryption of data at rest and TLS 1.3 for data in transit, (d) multi-factor authentication for all employee access, (e) principle of least privilege enforced by role-based access control and time-bound just-in-time elevation, (f) continuous vulnerability scanning, quarterly external penetration testing and annual red-team engagements, (g) 24×7 security monitoring by a UK-based SOC, and (h) an incident-response playbook tested at least annually. No system is completely secure, and we cannot guarantee absolute security.
14. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law.
- Transaction records and KYC evidence: at least 7 years from the end of the business relationship or the transaction date, as required by MLR 2017 and the Companies Act.
- Complaint records: at least 5 years from the date of the final response, as required by FCA DISP rules.
- Marketing preferences: until you unsubscribe or object.
- Support-chat transcripts: up to 3 years after case closure.
- Technical & security logs: up to 12 months, extended where relevant to an active security investigation.
- Website analytics: up to 14 months in aggregated form.
At the end of a retention period we securely delete or anonymise the data.
15. Your rights
Subject to conditions in UK GDPR, you have the right to:
- be informed about how we use your personal data (this policy);
- access a copy of the personal data we hold about you;
- have inaccurate or incomplete data corrected;
- have your personal data erased in certain circumstances (this right does not override our legal retention obligations);
- restrict our processing of your personal data;
- receive certain personal data in a machine-readable format and transmit it to another controller (data portability);
- object to processing based on our legitimate interests, and to object at any time to direct marketing;
- not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects — see clause 7;
- withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email privacy@paytab.co.uk. We will respond within one month, extendable by up to two further months for complex requests. There is normally no fee, though we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive.
End Customers whose personal data we process on behalf of a merchant should generally direct requests to that merchant; we will assist the merchant as required by the DPA.
16. Children's data
The Service is not directed to children under 18 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact dpo@paytab.co.uk and we will take steps to delete it.
17. Data breach notification
Where we become aware of a personal data breach likely to result in a risk to the rights and freedoms of individuals, we will notify the ICO within 72 hours as required by UK GDPR. Where the breach is likely to result in a high risk to individuals, we will notify affected individuals without undue delay. Where Paytab acts as processor for a merchant, we will notify the merchant without undue delay after becoming aware of the breach and support the merchant's own notification obligations.
18. Changes to this policy
We will update this policy from time to time to reflect changes in our practices, technology, legal requirements and other factors. Where changes are material we will notify you by email and in the dashboard at least 30 days in advance. The "Last updated" date at the top of the page reflects the most recent revision.
19. How to contact us
Data protection queries: dpo@paytab.co.uk · Rights requests: privacy@paytab.co.uk · Security incidents: security@paytab.co.uk · General: hello@paytab.co.uk. Post: Data Protection Officer, Paytab Ltd, 1 Finsbury Avenue, London EC2M 2PP.
20. Complaints to the ICO
If you are unhappy with how we have handled your personal data, we would like the chance to put it right — please contact us first. You also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk, by phone on 0303 123 1113, or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.