This policy explains how Pay One LLC ("Pay One", "we", "us") collects, uses, shares and protects personal data when you visit pay-one.io, apply for or use our payment gateway and processing services, or pay a merchant who uses Pay One. The section on your rights is near the end.
The controller for the processing described in this policy is Pay One LLC, 30 N Gould St, Sheridan, WY 82801, United States. For merchants and individuals in the European Economic Area and the United Kingdom, our representative under Article 27 GDPR and UK GDPR can be reached through the same address. You can reach our privacy team at privacy@pay-one.io.
We process personal data about four groups of people, and our role differs for each:
Data you give us. When you apply: company name, registration and tax numbers, shop URL, business category and platform, expected volume, current chargeback rate, country of incorporation, contact name, email and phone. During onboarding: identity documents, proof of address, beneficial-ownership information, bank account details, processing statements from previous providers, and photographs or video used for identity verification. During use: support conversations, dashboard settings, routing rules and any information you include in dispute evidence.
Data we collect automatically. IP address, device and browser type, language, pages viewed, referring page, timestamps, and the identifiers set by cookies described in Section 10. Within the dashboard: login events, actions taken and API calls, kept in an audit log.
Payment data. For each transaction: card number (tokenized immediately; the full number is stored only in our PCI DSS certified vault), expiry, cardholder name, billing and shipping address, email, phone, amount, currency, merchant, order reference, device fingerprint, IP address, 3-D Secure authentication results, authorisation response codes and the acquiring path used. We never store the card security code (CVV) after authorisation.
Data from third parties. Verification results from identity and business-registry providers, sanctions and politically-exposed-person screening results, credit reference data about your business, fraud signals and consortium data from card networks and fraud-prevention partners, chargeback and dispute records from issuing banks and card networks, and terminated-merchant list checks.
Where GDPR or UK GDPR applies, every use has a legal basis. The table sets them out.
| Purpose | Legal basis |
|---|---|
| Assessing your application and onboarding your business | Performance of a contract or steps before entering one; legal obligation (KYB, KYC, AML) |
| Verifying identity, beneficial owners, sanctions and PEP status | Legal obligation; legitimate interest in preventing financial crime |
| Authorising, routing, capturing and settling payments | Performance of a contract with the merchant; legitimate interest of the cardholder in completing their purchase |
| Fraud screening, 3-D Secure, risk scoring, velocity checks | Legal obligation (PSD2 strong customer authentication where applicable); legitimate interest in preventing fraud and protecting merchants, cardholders and the card networks |
| Handling chargebacks, refunds and disputes | Performance of a contract; legitimate interest; legal obligation under card network rules |
| Monitoring merchant accounts for excessive chargebacks or prohibited activity | Legal obligation (network rules, AML); legitimate interest |
| Providing the dashboard, reporting and support | Performance of a contract |
| Improving routing models and approval rates using aggregated transaction data | Legitimate interest; where feasible we use de-identified data |
| Sending service notices, security alerts and changes to terms | Performance of a contract; legal obligation |
| Marketing to business contacts and applicants | Legitimate interest for B2B contacts; consent where required by local law. You can opt out at any time |
| Website analytics and measurement | Consent (cookies); legitimate interest for strictly necessary and privacy-preserving analytics |
| Complying with tax, accounting, court orders and regulator requests | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interest |
Where we rely on legitimate interest we have balanced it against your rights and concluded that the processing is necessary, proportionate and within your reasonable expectations. You can ask for a copy of an assessment at the contact address below.
Every transaction submitted to Pay One is scored automatically for fraud and risk using signals such as device, IP geolocation, velocity, BIN, address match, 3-D Secure outcome and historic behaviour. A high score can lead to a transaction being declined, challenged with additional authentication, or held for review. Merchant applications are also screened automatically against sanctions lists and terminated-merchant databases. These automated steps are necessary to enter into and perform the payment contract and are required by law and card network rules. Where they produce a decision with legal or similarly significant effect on you, you have the right to obtain human review, to express your point of view and to contest the decision by contacting privacy@pay-one.io. Cardholders should first contact the merchant, who can request a review through us.
We share personal data only where necessary for the purposes above, with:
We do not sell personal data and we do not share it with third parties for their own advertising.
Pay One is established in the United States and stores and processes all data on servers in the United States. Personal data of EU and UK data subjects is therefore transferred to the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), supplemented by transfer impact assessments and technical measures such as encryption in transit and at rest. Card networks and issuing banks may be located anywhere in the world; transfers to them are necessary for the performance of the payment contract. You can request a copy of the transfer safeguards we use.
| Data | Retention |
|---|---|
| Merchant KYB and KYC records | Duration of the relationship plus 5 years (anti-money-laundering law) |
| Transaction records and settlement statements | 10 years (tax and accounting law); chargeback evidence for the network dispute window plus 2 years |
| Tokenized card credentials | Until the merchant deletes them, the card expires, or 24 months after last use |
| Fraud signals and risk scores | Up to 5 years, longer where linked to a confirmed fraud case |
| Dashboard audit logs | 2 years |
| Support conversations | 3 years after the ticket closes |
| Application data for declined applicants | 2 years, then deleted or anonymised |
| Website analytics | As set out in Section 10, at most 14 months |
We keep data for longer if a legal claim, investigation or regulatory request requires it. Once a retention period ends we delete or irreversibly anonymise the data.
Pay One is certified as a PCI DSS Level 1 service provider. Card data is tokenized on entry and stored only in a segregated, encrypted vault. All data is encrypted in transit (TLS 1.2 or higher) and at rest. Access to production systems requires multi-factor authentication, is limited by role and is logged. We run vulnerability management, penetration testing at least annually, and 24/7 monitoring. If a breach affecting personal data occurs we will notify the competent supervisory authority within 72 hours where required and will inform affected merchants and individuals without undue delay where the risk to them is high. No system is completely secure; you are responsible for protecting your own credentials and integrations.
pay-one.io uses a small number of cookies and similar technologies:
You can change your choice at any time through the cookie settings link in the footer or through your browser. The dashboard uses only strictly necessary cookies. Payment pages embedded in merchant checkouts set a device-recognition cookie for fraud prevention, which is a legal obligation under strong customer authentication rules and does not require consent.
Depending on where you live, you have the right to: access the personal data we hold about you and receive a copy; have inaccurate data corrected; have data erased where we no longer need it; restrict processing while a dispute is resolved; receive data you provided in a portable format; object to processing based on legitimate interest, including profiling; withdraw consent at any time without affecting earlier processing; and not be subject to a solely automated decision with legal effect without human review (see Section 5). To exercise a right, email privacy@pay-one.io. We will verify your identity and respond within one month (extendable by two months for complex requests, in which case we will tell you). We will not charge a fee unless a request is manifestly unfounded or excessive.
Some rights are limited: we cannot erase transaction records we are legally required to keep, and we cannot delete fraud records where doing so would prejudice fraud prevention. In each case we will explain what we can and cannot do.
If you paid a merchant that uses Pay One, that merchant decided to use us and is the controller of your order and customer data. It shares your payment details with us so we can process the payment. For that processing we act on the merchant's instructions. In parallel, we independently determine how to screen the transaction for fraud, how to handle a dispute, and how to comply with card network and anti-money-laundering rules; for those purposes we are a controller and this policy applies directly. Questions about your order, refund or the merchant's own use of your data should go to the merchant. Questions about fraud screening or dispute handling can come to us at privacy@pay-one.io. The merchant's name, not Pay One, will normally appear on your card statement, with a descriptor we assign.
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other states with comprehensive privacy laws may have rights to know, access, correct, delete and port their personal information, to opt out of "sale", "sharing" or targeted advertising, and not to be discriminated against for exercising these rights. Pay One does not sell or share personal information for cross-context behavioural advertising and does not use sensitive personal information for purposes other than providing the services. Much of the data we process is covered by the Gramm-Leach-Bliley Act or is processed on behalf of merchants as a service provider and is therefore exempt from some state laws. You may exercise applicable rights at privacy@pay-one.io. An authorised agent may act for you with written proof of authority. If we deny a request you may appeal by replying to our decision email.
Our services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16 as a merchant user. If you believe a child has provided data to us, contact us and we will delete it.
We will update this policy when our processing changes or the law requires it. The effective date at the top shows the current version. For material changes we will notify merchants by email or dashboard notice at least 30 days in advance. Previous versions are available on request.
Pay One LLC · 30 N Gould St · Sheridan, WY 82801 · United States
privacy@pay-one.io
If you are in the EEA or the UK and believe we have not handled your data lawfully, you have the right to lodge a complaint with your local supervisory authority, for example the Information Commissioner's Office in the UK or the data protection authority of the German federal state where you live. We would appreciate the chance to resolve your concern first.