pay one
TermsPrivacyImprint
Get started
Contents
1 · Who is responsible2 · Who this policy applies to3 · Data we collect4 · Why we use it and on what legal basis5 · Automated decisions and fraud scoring6 · Who we share data with7 · International transfers8 · How long we keep data9 · Security10 · Cookies and website analytics11 · Your rights12 · Cardholders: data your merchant shares with us13 · US state privacy rights14 · Children15 · Changes to this policy16 · Contact and complaints
Legal

Privacy Policy

Effective date: 7 September 2026 · Version 1.0

This policy explains how Pay One LLC ("Pay One", "we", "us") collects, uses, shares and protects personal data when you visit pay-one.io, apply for or use our payment gateway and processing services, or pay a merchant who uses Pay One. The section on your rights is near the end.

1. Who is responsible

The controller for the processing described in this policy is Pay One LLC, 30 N Gould St, Sheridan, WY 82801, United States. For merchants and individuals in the European Economic Area and the United Kingdom, our representative under Article 27 GDPR and UK GDPR can be reached through the same address. You can reach our privacy team at privacy@pay-one.io.

2. Who this policy applies to

We process personal data about four groups of people, and our role differs for each:

  • Website visitors: people who browse pay-one.io. We are the controller.
  • Merchant applicants and merchant users: business owners, beneficial owners, directors and staff of businesses that apply for or use our services. We are the controller.
  • Cardholders and payers: people who pay a merchant that uses Pay One. For fraud prevention, dispute handling, sanctions screening and compliance with card network and anti-money-laundering rules we act as an independent controller. For everything else we process payment data as the merchant's processor under our Data Processing Agreement. Section 12 has the detail.
  • Business contacts: people at partners, acquirers and suppliers. We are the controller.

3. Data we collect

Data you give us. When you apply: company name, registration and tax numbers, shop URL, business category and platform, expected volume, current chargeback rate, country of incorporation, contact name, email and phone. During onboarding: identity documents, proof of address, beneficial-ownership information, bank account details, processing statements from previous providers, and photographs or video used for identity verification. During use: support conversations, dashboard settings, routing rules and any information you include in dispute evidence.

Data we collect automatically. IP address, device and browser type, language, pages viewed, referring page, timestamps, and the identifiers set by cookies described in Section 10. Within the dashboard: login events, actions taken and API calls, kept in an audit log.

Payment data. For each transaction: card number (tokenized immediately; the full number is stored only in our PCI DSS certified vault), expiry, cardholder name, billing and shipping address, email, phone, amount, currency, merchant, order reference, device fingerprint, IP address, 3-D Secure authentication results, authorisation response codes and the acquiring path used. We never store the card security code (CVV) after authorisation.

Data from third parties. Verification results from identity and business-registry providers, sanctions and politically-exposed-person screening results, credit reference data about your business, fraud signals and consortium data from card networks and fraud-prevention partners, chargeback and dispute records from issuing banks and card networks, and terminated-merchant list checks.

4. Why we use it and on what legal basis

Where GDPR or UK GDPR applies, every use has a legal basis. The table sets them out.

PurposeLegal basis
Assessing your application and onboarding your businessPerformance of a contract or steps before entering one; legal obligation (KYB, KYC, AML)
Verifying identity, beneficial owners, sanctions and PEP statusLegal obligation; legitimate interest in preventing financial crime
Authorising, routing, capturing and settling paymentsPerformance of a contract with the merchant; legitimate interest of the cardholder in completing their purchase
Fraud screening, 3-D Secure, risk scoring, velocity checksLegal obligation (PSD2 strong customer authentication where applicable); legitimate interest in preventing fraud and protecting merchants, cardholders and the card networks
Handling chargebacks, refunds and disputesPerformance of a contract; legitimate interest; legal obligation under card network rules
Monitoring merchant accounts for excessive chargebacks or prohibited activityLegal obligation (network rules, AML); legitimate interest
Providing the dashboard, reporting and supportPerformance of a contract
Improving routing models and approval rates using aggregated transaction dataLegitimate interest; where feasible we use de-identified data
Sending service notices, security alerts and changes to termsPerformance of a contract; legal obligation
Marketing to business contacts and applicantsLegitimate interest for B2B contacts; consent where required by local law. You can opt out at any time
Website analytics and measurementConsent (cookies); legitimate interest for strictly necessary and privacy-preserving analytics
Complying with tax, accounting, court orders and regulator requestsLegal obligation
Establishing, exercising or defending legal claimsLegitimate interest

Where we rely on legitimate interest we have balanced it against your rights and concluded that the processing is necessary, proportionate and within your reasonable expectations. You can ask for a copy of an assessment at the contact address below.

5. Automated decisions and fraud scoring

Every transaction submitted to Pay One is scored automatically for fraud and risk using signals such as device, IP geolocation, velocity, BIN, address match, 3-D Secure outcome and historic behaviour. A high score can lead to a transaction being declined, challenged with additional authentication, or held for review. Merchant applications are also screened automatically against sanctions lists and terminated-merchant databases. These automated steps are necessary to enter into and perform the payment contract and are required by law and card network rules. Where they produce a decision with legal or similarly significant effect on you, you have the right to obtain human review, to express your point of view and to contest the decision by contacting privacy@pay-one.io. Cardholders should first contact the merchant, who can request a review through us.

6. Who we share data with

We share personal data only where necessary for the purposes above, with:

  • Card networks, issuing banks and our acquiring banks to authorise, route, settle and dispute transactions and to comply with their rules.
  • Alternative payment method providers (for example wallet, buy-now-pay-later and bank-transfer schemes) when you or your customer chooses that method.
  • Identity verification, business registry, sanctions screening and credit reference providers during onboarding and periodic reviews.
  • Fraud prevention and 3-D Secure providers, including consortium databases that pool fraud signals across merchants.
  • Sub-processors that host our infrastructure, deliver email and SMS, provide customer-support tooling and analytics. The current list is available on request and we notify merchants of changes in advance.
  • Merchants: cardholder data is shared with the merchant you paid so they can fulfil, refund and support your order.
  • Professional advisers, auditors and insurers under confidentiality.
  • Regulators, law enforcement, courts and card networks where the law or the network rules require it, including reporting to terminated-merchant databases when an account is closed for cause.
  • A buyer or successor in a merger, acquisition or restructuring, under confidentiality and subject to this policy.

We do not sell personal data and we do not share it with third parties for their own advertising.

7. International transfers

Pay One is established in the United States and stores and processes all data on servers in the United States. Personal data of EU and UK data subjects is therefore transferred to the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), supplemented by transfer impact assessments and technical measures such as encryption in transit and at rest. Card networks and issuing banks may be located anywhere in the world; transfers to them are necessary for the performance of the payment contract. You can request a copy of the transfer safeguards we use.

8. How long we keep data

DataRetention
Merchant KYB and KYC recordsDuration of the relationship plus 5 years (anti-money-laundering law)
Transaction records and settlement statements10 years (tax and accounting law); chargeback evidence for the network dispute window plus 2 years
Tokenized card credentialsUntil the merchant deletes them, the card expires, or 24 months after last use
Fraud signals and risk scoresUp to 5 years, longer where linked to a confirmed fraud case
Dashboard audit logs2 years
Support conversations3 years after the ticket closes
Application data for declined applicants2 years, then deleted or anonymised
Website analyticsAs set out in Section 10, at most 14 months

We keep data for longer if a legal claim, investigation or regulatory request requires it. Once a retention period ends we delete or irreversibly anonymise the data.

9. Security

Pay One is certified as a PCI DSS Level 1 service provider. Card data is tokenized on entry and stored only in a segregated, encrypted vault. All data is encrypted in transit (TLS 1.2 or higher) and at rest. Access to production systems requires multi-factor authentication, is limited by role and is logged. We run vulnerability management, penetration testing at least annually, and 24/7 monitoring. If a breach affecting personal data occurs we will notify the competent supervisory authority within 72 hours where required and will inform affected merchants and individuals without undue delay where the risk to them is high. No system is completely secure; you are responsible for protecting your own credentials and integrations.

10. Cookies and website analytics

pay-one.io uses a small number of cookies and similar technologies:

  • Strictly necessary: session, security and consent-preference cookies. These cannot be switched off.
  • Analytics: a privacy-preserving analytics tool to measure page views and conversion of the application form. Set only with your consent where the law requires it; retained for at most 14 months.
  • Marketing: conversion tags used to measure the performance of our campaigns. Set only with your consent.

You can change your choice at any time through the cookie settings link in the footer or through your browser. The dashboard uses only strictly necessary cookies. Payment pages embedded in merchant checkouts set a device-recognition cookie for fraud prevention, which is a legal obligation under strong customer authentication rules and does not require consent.

11. Your rights

Depending on where you live, you have the right to: access the personal data we hold about you and receive a copy; have inaccurate data corrected; have data erased where we no longer need it; restrict processing while a dispute is resolved; receive data you provided in a portable format; object to processing based on legitimate interest, including profiling; withdraw consent at any time without affecting earlier processing; and not be subject to a solely automated decision with legal effect without human review (see Section 5). To exercise a right, email privacy@pay-one.io. We will verify your identity and respond within one month (extendable by two months for complex requests, in which case we will tell you). We will not charge a fee unless a request is manifestly unfounded or excessive.

Some rights are limited: we cannot erase transaction records we are legally required to keep, and we cannot delete fraud records where doing so would prejudice fraud prevention. In each case we will explain what we can and cannot do.

12. Cardholders: data your merchant shares with us

If you paid a merchant that uses Pay One, that merchant decided to use us and is the controller of your order and customer data. It shares your payment details with us so we can process the payment. For that processing we act on the merchant's instructions. In parallel, we independently determine how to screen the transaction for fraud, how to handle a dispute, and how to comply with card network and anti-money-laundering rules; for those purposes we are a controller and this policy applies directly. Questions about your order, refund or the merchant's own use of your data should go to the merchant. Questions about fraud screening or dispute handling can come to us at privacy@pay-one.io. The merchant's name, not Pay One, will normally appear on your card statement, with a descriptor we assign.

13. US state privacy rights

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other states with comprehensive privacy laws may have rights to know, access, correct, delete and port their personal information, to opt out of "sale", "sharing" or targeted advertising, and not to be discriminated against for exercising these rights. Pay One does not sell or share personal information for cross-context behavioural advertising and does not use sensitive personal information for purposes other than providing the services. Much of the data we process is covered by the Gramm-Leach-Bliley Act or is processed on behalf of merchants as a service provider and is therefore exempt from some state laws. You may exercise applicable rights at privacy@pay-one.io. An authorised agent may act for you with written proof of authority. If we deny a request you may appeal by replying to our decision email.

14. Children

Our services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16 as a merchant user. If you believe a child has provided data to us, contact us and we will delete it.

15. Changes to this policy

We will update this policy when our processing changes or the law requires it. The effective date at the top shows the current version. For material changes we will notify merchants by email or dashboard notice at least 30 days in advance. Previous versions are available on request.

16. Contact and complaints

Pay One LLC · 30 N Gould St · Sheridan, WY 82801 · United States
privacy@pay-one.io

If you are in the EEA or the UK and believe we have not handled your data lawfully, you have the right to lodge a complaint with your local supervisory authority, for example the Information Commissioner's Office in the UK or the data protection authority of the German federal state where you live. We would appreciate the chance to resolve your concern first.

© 2026 Pay One LLCTermsPrivacyImprintHome