Transparency is a recurring Checkout.com value that is reflected in our
pricing promise, our security protocol and our legal agreements.
Veuillez suivre ce lien pour consulter la politique de confidentialité de Checkout.com en français.
Effective Date: 31 May 2022
The Checkout.com Group, which includes Checkout Ltd and all affiliated companies (“Checkout.com”, “we”, “our”, or “us”) respects your privacy and is committed to protecting your personal data. This privacy policy will inform you about how we treat your personal data when you use our platforms and services (collectively referred to as “Services”) and when you use our website. This policy does not apply to third-party websites, products or services.
This privacy policy is issued on behalf of the Checkout.com Group so when we use the terms “Checkout.com”, “we”, “us” or “our” in this privacy policy, we are referring to the relevant company in the Checkout.com Group responsible for processing your data, which is identified in the section “Country Specific Notices” and will depend on your location and the services you receive from Checkout.com.
The following information applicable to all Checkout.com Group companies is complemented by the specific provisions described in the section “Country Specific Notices”.
Checkout.com is committed to adequately protecting your personal data regardless of where it is processed and regardless of your location.
Checkout.com is the controller of personal information collected and processed for the Services, unless stated otherwise.
Checkout.com appointed a data protection officer (DPO) who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact the DPO using the details set out below. Checkout.com’s DPO can be reached in English, French or Spanish. We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Email address: [email protected]
Postal Address:
Data Protection Officer Checkout Ltd
Wenlock Works, Shepherdess Walk, London, N1 7BQ
United Kingdom
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data from which the identity of the individual cannot be discerned (anonymous data).
We use different methods to collect data from and about you. Data is collected through the following:
OUR WEBSITE
When you use our website, we may collect, use, store and transfer the following data:
OUR SERVICES
When you use our Services, we may collect, use, store and transfer the following personal data:
Our Sandbox Hub is intended to be used as a test environment, and we do not envisage collecting, storing or processing any personal data while you use our Sandbox Hub. Please do not use any personally identifiable information, including cardholder data, when using the Sandbox Hub, other than when entering your login details. Our Sandbox environment is different and distinct to our live Hub environment and is not designed to store or process cardholder data.
We will process your personal data in the following circumstances:
Examples of how we may process your personal data include:
We have set out a description of the purposes we plan to use your personal data and the lawful basis for our processing activities below:
NOTICE TO OUR MERCHANTS
We may collect, use and disclose certain personal data about your customers
when acting as your service provider. You are responsible for making sure
that your customer’s privacy rights are respected, including ensuring appropriate
disclosures about third party data collection and use. You must comply
with the personal data protection laws of your country of origin and of
those countries in which you offer products or services and, in particular
when processing and sending personal data to us in the context of using
the Services and submitting transactions. If you entered into our Merchant
Services Agreement, you are also responsible for compliance with the requirements
set out in our Merchant Services Agreement and for the notification of
your customers of the Mastercard Binding Corporate Rules (as amended from
time to time and currently
available here
), including your customers' right to enforce these rules as third-party
beneficiaries.
We share your personal data with trusted third parties for the purpose
of providing our Services and promoting our business, as follows:
Affiliates.
Your information may be shared with our affiliates within the Checkout.com
Group, to provide you with our Services. The relevant Checkout.com entity
is the party responsible for overall management and use of your personal
data.
Business partners, payment industry suppliers and participants to your
transactions.
We may share your personal data with our merchants and their service
providers, card schemes, payment method providers and third party acquirers,
as necessary to process payments or provide our Services. The information
shared includes:
Third-party service providers. We may also use third-party service providers
acting on our behalf. These service providers help us with data and cloud
services, website hosting, data analysis, application services, advertising
networks, information technology and related infrastructure, customer service,
communications and auditing.
Advertising and remarketing networks. Our website uses remarketing and
conversion tracking technologies provided by Google AdWords (for further
details about the Remarketing product we use,
see here
; for the product’s privacy policy,
see here
) and Facebook Pixel (for further details about the Facebook product we
use,
see here
; for details about the information we may share with this provider,
see here
). This technology allows us to display targeted advertising to users
who have already visited our website when they use the websites of the
partner networks of Google and Facebook across the internet. We may add
similar providers to those mentioned here in the future. Third-party vendors,
including Google and Facebook, use cookies to serve you ads based your
visits to our website. Please refer to our
cookie policy
for further information about how these technologies are used on our website.
Other third parties. We will share your personal data with third parties
in the event of any reorganisation, merger, sale, joint venture, assignment,
transfer or other disposition of all or any portion of our business, assets
or stock.
Safety, Legal Purposes and Law Enforcement. We may share your personal
data with third parties to detect, prevent or otherwise address fraud,
security or technical issues, or to protect against harm to the rights,
property or safety of Checkout.com, our users, customers, employees or
the public or as otherwise required by law. We also use and disclose your
personal data as we believe necessary (i) under applicable law, or payment
method rules; (ii) to enforce our terms and conditions, or our Merchant
Service Agreement and other agreements, as applicable; (iii) to protect
our rights, privacy safety or property, and/or that of our affiliates,
you or others; and (iv) to respond to requests from courts, law enforcement
agencies, regulatory agencies, and other public and government authorities,
which may include authorities outside your country of residence.
All our third-party service providers and other entities in the group
are required to process the data in accordance with applicable data protection
regulations and to take appropriate security measures to protect your personal
information in line with EU data protection standards and our policies.
We do not allow our third-party service providers to use your personal
data for their own purposes.
In addition, when a third-party entity processes your personal data on
our behalf and according to our instructions, we sign a written agreement
with it that specifically describes its obligations with regard to security
and data protection, in accordance with European data protection laws.
We only permit them to process your personal data for specified purposes.
When possible, the data we collect from you is stored and processed at data centres in the EEA.
Checkout.com will take all reasonable legal, technical, and organisational measures to ensure that if your data is transferred outside of the EEA, it will be treated securely and with an adequate level of protection compared to the level of protection offered within the EEA.
We may share your personal data with members of the Checkout.com Group who are based outside of the EEA. We may share your personal data with partners, suppliers or sub-processors based in countries outside of the EEA.
We have taken specific steps, in accordance with European data protection law, to protect your personal data. In particular, we will strive to restrict the transfer of your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
Transfers of personal data outside of the European will take place only where the organisation receiving the personal data has provided us with adequate safeguards, and subject to a written agreement, in line with the requirements of European data protection law applicable to processors and data transfers.
If you transact with parties outside the EEA, for example by: (i) transacting with a merchant based outside the EEA; (ii) using a payment method based or commonly used outside of the EEA; or (iii) using a non-EEA currency; we may be required to transfer your personal data to those parties in order to provide the Services you requested.
Protecting your information and your privacy is extremely important to us. Being entrusted with some of your most valuable data, we have set high standards for data security. We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed, altered or disclosed in an unauthorised manner.
We are PCI DSS (Payment Card Industry Data Security Standard) Level 1 compliant, which is the highest standard set by the payment card industry to ensure that credit card data is processed, stored or transmitted in a secure environment.
In addition, we limit access to your personal information to those employees and third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
We retain your personal data in an identifiable format for the least amount of time necessary to fulfil our legal or regulatory obligations and for our business purposes. We may retain your personal data for a longer period when there is a specific legal requirement to do so, for example in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, tax, regulatory or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Data are retained for the following periods of time:
If your account is closed, we reserve our right to retain and access your personal data for so long as required to comply with applicable laws. We will continue to use and disclose your personal data in accordance with this privacy policy.
The cookies we use have defined expiration times; unless you visit our website within that time, the cookies are automatically disabled and retained data is deleted. Please consult our cookie policy for more information.
In some circumstances you can ask us to delete your data: see below for further information about your rights.
In some circumstances we may anonymise your personal data for statistical purposes in which case we may use this information indefinitely without further notice to you.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Under certain circumstances, you have rights under data protection laws in relation to your personal data:
If you wish to exercise any of the rights set out above, please contact [email protected] or use the postal address mentioned at the beginning of this privacy policy. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Notice relating to our operations in the European Union
Checkout.com is providing the following supplemental information for individuals whose personal information is collected or held by Checkout SAS or any of its affiliated companies.
Where you are such an individual:
Notice relating to our operations in the United Kingdom
Checkout.com is providing the following supplemental information for individuals whose personal information is collected or held by Checkout Ltd or any of its affiliated companies.
Where you are such an individual:
Notice relating to our operations in Australia
Checkout.com is providing the following supplemental information for individuals whose personal information is collected or held by Checkout Ltd, Checkout.com Australia Pty Ltd, or any of their affiliated companies, at a time when the collecting or holding entity has an 'Australian link' within the meaning of the Australian Privacy Act 1988.
Where you are such an individual:
Notice relating to our operations in Hong Kong
Checkout.com is providing the following supplemental information for individuals whose personal data (as defined in the Hong Kong Personal Data (Privacy) Ordinance) is collected or held by Checkout Ltd, Checkout Limited (a company incorporated under the laws of Hong Kong under company number 2636578, and with its office address at L7, 13th Floor, 40 Bonham Strand, Sheung Wan, Hong Kong), or any of their affiliated companies, in or from Hong Kong.
Notice relating to our operations in Singapore
Checkout.com is providing the following supplemental information for individuals whose personal information is collected or held by Checkout Ltd, Checkout APAC Pte Ltd, or any of their affiliated companies.
Where you are such an individual:
Notice relating to our operations under the California Consumer Privacy
Act (“CCPA”)
Checkout.com is providing the following supplemental information for individuals whose personal data is collected or held by Checkout LLC in the State of California as defined in the CCPA.
Notice relating to our operations in New Zealand
Checkout.com is providing the following supplemental information for individuals whose personal information is collected in the course of carrying on business in New Zealand.
Where you are such an individual:
We will regularly review and update this policy. Any changes we make will be posted on this page and, where appropriate, notified to you by email. Please check back frequently to see any updates or changes to our privacy policy.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.