Your data,
handled with care.

This policy explains what CardPMT collects, why we hold it and what you can ask us to do with it. It covers this website and the accounts, acquiring and gateway services behind it. We wrote it in plain English. No dense legal wall.

Last updated 18 September 2026

  • GDPR-aligned
  • PCI DSS Level 1
  • Applies to cardpmt.com

What we collect

We ask for what the job needs and nothing more. Four groups cover almost everything we hold on a merchant.

  • What you send us

    Your name, work email, company and a short note on what you sell. You give us this when you apply or ask for a call.

  • Application files

    The records an underwriter needs to read a file. Company papers, ownership details, trading history and bank data.

  • Service records

    Data created while you use an account or the gateway. Settlements, refunds, chargebacks, tickets and integration logs.

  • Site data

    Pages viewed, device type and a rough region from your IP address. Cookies are set out in the cookie policy.

Why we hold it

Every use below has a lawful basis behind it. We never sell your data. We do not hand it to advertisers or data brokers.

Read the terms of service
  1. 01

    To answer you

    We reply to enquiries and quote for the service you asked about. The basis is the steps taken before a contract.

  2. 02

    To underwrite and onboard

    We check who we are dealing with before we approve a merchant account. The basis is our legal duty plus your contract.

  3. 03

    To run payments

    We process transactions, settle funds and screen for fraud. Card scheme rules and your contract both require this.

  4. 04

    To keep records safe

    We log access, audit our systems and keep the records regulators ask for. The basis is legal duty and our own care.

How we guard it

Card data is handled on PCI DSS Level 1 systems. Access is scoped to the people who need it, logged, and reviewed. Transport and storage are encrypted. Staff work to written security rules, and we test them.

Who else sees it

Only the partners a payment needs: acquiring banks, card schemes, identity and fraud-check providers, and our hosting supplier. Each one works under contract and may use the data only for our instructions.

How long we keep it

Enquiry data goes once it is stale. Account and transaction records stay for the period financial law sets. After that we delete them or strip the identifying parts.

Your rights, in practice

You can use any of these at any time. We reply inside one month. If a request is complex we tell you early and explain the delay.

  • See your data

    Ask for a copy of what we hold about you and where it came from.

  • Fix it

    Tell us when a detail is wrong or out of date, and we correct it.

  • Ask us to erase

    Request deletion. Some payment records must stay under law.

  • Object or pause

    Object to a use, or ask us to hold processing while we check a dispute.

  • Take it with you

    Get the data you gave us in a common machine-readable file.

  • Raise a complaint

    Go to your data protection regulator if our answer does not satisfy you.