Your data,
handled with care.
This policy explains what CardPMT collects, why we hold it and what you can ask us to do with it. It covers this website and the accounts, acquiring and gateway services behind it. We wrote it in plain English. No dense legal wall.
- GDPR-aligned
- PCI DSS Level 1
- Applies to cardpmt.com
What we collect
We ask for what the job needs and nothing more. Four groups cover almost everything we hold on a merchant.
-
What you send us
Your name, work email, company and a short note on what you sell. You give us this when you apply or ask for a call.
-
Application files
The records an underwriter needs to read a file. Company papers, ownership details, trading history and bank data.
-
Service records
Data created while you use an account or the gateway. Settlements, refunds, chargebacks, tickets and integration logs.
-
Site data
Pages viewed, device type and a rough region from your IP address. Cookies are set out in the cookie policy.
Why we hold it
Every use below has a lawful basis behind it. We never sell your data. We do not hand it to advertisers or data brokers.
Read the terms of service-
01
To answer you
We reply to enquiries and quote for the service you asked about. The basis is the steps taken before a contract.
-
02
To underwrite and onboard
We check who we are dealing with before we approve a merchant account. The basis is our legal duty plus your contract.
-
03
To run payments
We process transactions, settle funds and screen for fraud. Card scheme rules and your contract both require this.
-
04
To keep records safe
We log access, audit our systems and keep the records regulators ask for. The basis is legal duty and our own care.
How we guard it
Card data is handled on PCI DSS Level 1 systems. Access is scoped to the people who need it, logged, and reviewed. Transport and storage are encrypted. Staff work to written security rules, and we test them.
Who else sees it
Only the partners a payment needs: acquiring banks, card schemes, identity and fraud-check providers, and our hosting supplier. Each one works under contract and may use the data only for our instructions.
How long we keep it
Enquiry data goes once it is stale. Account and transaction records stay for the period financial law sets. After that we delete them or strip the identifying parts.
Your rights, in practice
You can use any of these at any time. We reply inside one month. If a request is complex we tell you early and explain the delay.
-
See your data
Ask for a copy of what we hold about you and where it came from.
-
Fix it
Tell us when a detail is wrong or out of date, and we correct it.
-
Ask us to erase
Request deletion. Some payment records must stay under law.
-
Object or pause
Object to a use, or ask us to hold processing while we check a dispute.
-
Take it with you
Get the data you gave us in a common machine-readable file.
-
Raise a complaint
Go to your data protection regulator if our answer does not satisfy you.