Legal
Privacy policy
How HansaPay collects, uses, shares and protects personal information when you visit our website, use our services, or pay a business that uses HansaPay.
- Last updated
- Effective
This policy explains how HansaPay, Inc. and its affiliates ("HansaPay", "we", "us") handle personal information. It applies to visitors to hansapay.io, businesses that use HansaPay ("merchants"), and people who pay those businesses through HansaPay ("customers").
If you are a customer of a merchant, that merchant has its own privacy policy. We process your payment information to provide services to the merchant and to meet our own legal obligations, as described below.
Who we are
HansaPay, Inc. is the controller of personal information described in this policy, except where we process information on behalf of a merchant, in which case the merchant is the controller and we act as its processor. You can contact us at [email protected].
Information we collect
Information you give us
- Account and business details, such as your name, email address, phone number, business name, registration number, address and website.
- Identity verification information, such as date of birth, government ID, and details about beneficial owners and directors, which we are legally required to collect.
- Financial information, such as bank account details for payouts.
- Communications, such as messages you send to our support team or through our contact forms.
Information we collect when payments are made
- Payment details, such as card number, expiry date, card network, and wallet tokens. Full card numbers are encrypted and tokenised in a dedicated cardholder data environment.
- Transaction details, such as amount, currency, date, merchant, and the outcome of the payment.
- Device and network information, such as IP address, browser, and device identifiers, used to prevent fraud.
Information collected automatically
When you visit our website, we collect limited technical information, such as your IP address, browser type, pages visited and referring page. This website uses only strictly necessary cookies. We do not use advertising cookies or sell your information.
Information from third parties
We receive information from identity verification providers, credit reference and fraud prevention agencies, card networks, banks, and publicly available sources, to verify businesses and prevent financial crime.
How we use information
We use personal information to:
- Provide our services, including processing payments, settling funds, and making payouts.
- Verify identity and assess risk, as required by anti-money laundering and know-your-customer regulations.
- Detect and prevent fraud, including by scoring transactions and devices for risk.
- Meet legal and regulatory obligations, including record-keeping, tax reporting, and responding to lawful requests.
- Support and communicate with you, including service notices and, where permitted, product updates.
- Improve our services, using aggregated or de-identified information where possible.
How we share information
We share personal information only as needed:
- With payment partners, such as card networks, issuing and acquiring banks, and wallet providers, to process payments.
- With service providers, who process information on our behalf under contract, such as hosting, identity verification and customer support tools.
- With the merchant you paid, who receives details of your transaction.
- With regulators, law enforcement and courts, where required by law or to protect rights and safety.
- In a business transfer, such as a merger or acquisition, subject to this policy.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
International transfers
We operate globally, so your information may be processed in countries other than the one you live in.
How long we keep information
We keep personal information only as long as necessary for the purposes described here. Financial regulations generally require us to keep transaction and identity records for at least five years after an account is closed. Website analytics logs are kept for no longer than 13 months.
How we protect information
We use administrative, technical and physical safeguards, including encryption in transit and at rest, tokenisation of card data, access controls, continuous monitoring and vulnerability scanning. Read more on our compliance page.
Children
Our services are not directed to children under 16, and we do not knowingly collect their personal information.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify merchants by email or through the dashboard before they take effect, and update the date at the top of this page.
Contact us
Questions about this policy or our privacy practices can be sent to [email protected].