PayFresco Privacy Policy

Effective date: October 3, 2026 Last updated: October 3, 2026 Policy version: 2.0

This Privacy Policy explains how PayFresco ("PayFresco", "we", "us", "our") collects, uses, shares and protects personal data when you visit payfresco.com (the "Site"), apply for our services, or contact us through any of our channels. It also explains your rights and how to use them. This version replaces our previous Privacy Policy dated June 30, 2026.

PayFresco is a merchant onboarding and placement service. We help businesses, including businesses that payment providers consider "high-risk", find and apply for payment-processing solutions. We are not a payment processor, acquiring bank or lender. We collect information about your business and its owners, review it, and share it with payment processors, acquiring banks, independent sales organizations (ISOs), payment gateways and platform partners so they can decide whether to offer you an account.

Please read this policy together with our Terms of Service.


1. Who we are

The controller of your personal data is PayFresco.


2. Scope

This policy covers personal data about:

Most of our applicants are businesses, but the information we collect about the people behind those businesses is personal data and is protected by this policy.

This policy does not cover how payment processors, banks, ISOs, gateways or other third parties handle your data once they receive it. They act under their own privacy notices, which you will usually receive when you apply with them.

The PayFresco CRM dashboard (app.payfresco.com). Our CRM dashboard is provided with a technology-platform provider. When you sign up for or use it, you will be shown that platform's terms and privacy notice, which also apply. The dashboard uses its own sign-in, product-analytics, error-monitoring and advertising-measurement tools, which are described in that notice. This policy covers the information you give us through the dashboard and how PayFresco uses it.


3. The data we collect

Category Examples
Business information Legal and trading name, website, business type and industry, products or services sold, sales channels, refund and fulfillment practices, country and state of incorporation, business address, years in business, business registration and tax identifiers (such as an EIN), ownership structure.
Owner, beneficial-owner and signer personal data Full name, job title, ownership percentage, date of birth, home address, citizenship or nationality, driver's license or other ID number, and a personal tax or national identification number where a processor requires it.
Contact details and handles Email address, phone number, Telegram username and user ID, X (Twitter) handle, social-media profile links you give us, and other messaging handles you use to contact us.
Banking, processing and financial profile Bank name and account details (such as routing and account numbers) needed for settlement, expected and historical monthly processing volume, average and maximum ticket size, refund and chargeback ratios, current or previous processors, reasons for previous declines or account closures, and the payment methods you want to accept.
KYC and identity documents Government-issued ID, passport, driver's license, proof of address, bank statements, processing statements, voided checks or bank letters, tax ID letters (e.g. IRS EIN confirmation), articles of incorporation and other company documents.
Application status and outcomes Which providers your application was sent to, their requests for more information, and their decisions (approved, pending, declined) and stated reasons.
Communications The content of emails, contact-form submissions, website chat messages, Telegram messages (including messages you post in groups we run), X direct messages, call notes, and attachments you send us.
Website, device and cookie data IP address, browser and device type, pages viewed, referring page, approximate location derived from your IP address, and data collected by cookies and similar technologies (see Section 12).
Consent records Whether you accepted or declined our optional permissions (Section 6), when, through which channel, the policy version shown to you, and your IP address, browser user agent or messaging handle at the time.

Cardholder data. We do not ask for, and you must not send us, payment card numbers, card security codes (CVV/CVC), "track" data from the magnetic strip or chip, or PINs. If you send us card data by mistake, we will delete it as soon as we notice and will not use it.

Sensitive data. We do not ask for special-category data such as health, religion, political opinion or sexual orientation. Some of the information above (government ID numbers, bank account details) is "sensitive personal information" under some US state laws; we use it only as described in Section 14.


4. Where we get your data


If you are in the European Economic Area (EEA), the United Kingdom or Switzerland, data protection law requires us to have a legal basis for each use of your personal data. The table below lists each purpose and the basis we rely on.

Purpose What this involves Legal basis (GDPR / UK GDPR)
Reviewing your application and placing you with a provider Assessing your business, preparing your application file, matching you with suitable processors, banks, ISOs, gateways or platform partners, sending them your application and documents, and following up on their questions and decisions. Steps taken at your request before entering into a contract, and performance of our contract with you (Art. 6(1)(b)). Where the data is about an owner, signer or reference who is not our contracting party, our legitimate interest in providing the service the business asked for (Art. 6(1)(f)).
Communicating with you about your application Replying to messages, requesting missing documents, giving status updates. Contract / pre-contract steps (Art. 6(1)(b)).
Managing the accounts we place and our relationship with providers Onboarding support after approval, account-health support, resolving disputes, and reconciling the fees or commissions providers pay us. Contract (Art. 6(1)(b)) and legitimate interests in running our business (Art. 6(1)(f)).
Verification, fraud prevention and security Checking that applications are genuine, screening against sanctions lists, detecting bots, VPN or proxy misuse, preventing misuse of our service and protecting our systems. Legitimate interests in preventing fraud and protecting our business and partners (Art. 6(1)(f)); legal obligation where sanctions, anti-money-laundering or other laws require it (Art. 6(1)(c)).
Legal, regulatory and contractual compliance Keeping records, responding to lawful requests from authorities, meeting record-keeping and audit requirements in our agreements with providers. Legal obligation (Art. 6(1)(c)); legitimate interests in meeting our contractual obligations and defending legal claims (Art. 6(1)(f)).
Improving our service and internal analytics Understanding which industries and providers are a good match, measuring approval rates, improving our Site, forms and processes. Legitimate interests in improving our service (Art. 6(1)(f)).
Service-related marketing to existing applicants and clients Telling you about similar placement services from PayFresco. You can opt out at any time. Legitimate interests (Art. 6(1)(f)) and, where e-privacy law requires it, your consent or the "existing customer" exemption.
Website analytics and advertising technologies The tools described in Section 12. Legitimate interests (Art. 6(1)(f)) or, where the law requires it, consent (Art. 6(1)(a)).
Optional: licensing de-identified and aggregated data See Section 6.1. Only if you opt in. Consent (Art. 6(1)(a)).
Optional: referral to partner financing or payment providers See Section 6.2. Only if you opt in. Consent (Art. 6(1)(a)).

Where we rely on legitimate interests, we have weighed our interests against your rights and expectations. You can ask us for more detail about this balancing test, and you can object (Section 10).

Automated decisions. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Automated security checks may flag a submission for manual review. Payment processors and banks make their own underwriting decisions, which may involve automated tools; please ask them about their processes.


6. Optional permissions: data licensing and partner referrals

When you apply, we ask for two separate, optional permissions. Both checkboxes are unchecked by default. You can say no to either or both. Saying no does not affect your application, the service we provide or our fees in any way.

6.1 Licensing de-identified and aggregated data (optional, opt-in only)

What it is. If, and only if, you tick the data-licensing checkbox (or give the same permission later through a separate consent form), we may license de-identified and/or aggregated data derived from your application and our onboarding work to third parties. These third parties may include companies that build or research artificial-intelligence (AI) models and buy data to train or evaluate them, as well as research, analytics and risk-intelligence companies.

What that data looks like. Examples:

How we de-identify it. Before any licensing, we remove or generalize information that could identify you, your business or any other person. This includes names, email addresses, phone numbers, messaging handles, business names, website domains, addresses, account and merchant IDs, the names of payment providers, exact amounts and dates (which we group into ranges), and all attachments. We also remove information about other people who appear in conversations, such as provider staff. We will only license data in a form that does not identify you, your business or any individual, and that cannot reasonably be linked back to you.

Contract protections. Every recipient must agree in writing that it will not attempt to re-identify any person or business, will not combine the data with other data in order to identify anyone, and will not pass the data on except under the same restrictions.

What we never license, sell or share with data buyers, for any purpose:

This exclusion is absolute and does not depend on whether you opted in.

Withdrawing. You can withdraw this permission at any time by emailing support@payfresco.com with the subject "Withdraw consent" (or by messaging us through the channel you applied with). Withdrawal is free and takes effect going forward: we will stop including your data in any new dataset or licence. Data that has already been delivered to a recipient in de-identified or aggregated form cannot be traced back to you by design, so it cannot be singled out and recalled. Withdrawing does not affect the lawfulness of anything done before you withdrew.

Data collected before October 3, 2026. We will not apply this data-licensing section to any data we collected before October 3, 2026 unless you give fresh, opt-in consent. If you do nothing, data collected before that date will not be licensed.

6.2 Referral to partner financing and payment providers (optional, opt-in only)

If, and only if, you tick the partner-referral checkbox, we may share your contact details and a summary of your business profile (business name, industry, country, approximate processing volume and the type of product you are looking for) with selected partners that offer complementary services, so they can contact you with offers.


7. Who we share your data with

We share personal data only as described here.

  1. Payment processors, acquiring banks, ISOs, gateways and platform partners. Sharing your application, documents and related information with these providers is the core of our service: without it, we cannot place you. Each provider decides independently whether to approve you, and processes your data under its own privacy notice and legal obligations (for example, anti-money-laundering, sanctions and card-network rules). Providers may also check industry databases, such as card-network lists of terminated merchants.
  2. Underwriters and risk reviewers working for us or for those providers.
  3. Service providers acting on our behalf, such as hosting and database providers, email and messaging tools, customer-support and chat software, CRM tools, document storage, scheduling tools, bot-protection and IP-reputation services, analytics providers and professional advisers. They may only use your data to provide services to us, under written contracts.
  4. Messaging and social platforms. If you contact us through Telegram, X or another platform, that platform processes your messages under its own privacy policy as an independent controller.
  5. Advertising and analytics providers, through the website technologies described in Section 12.
  6. Partner financing and payment providers, only if you opt in under Section 6.2.
  7. Licensees of de-identified or aggregated data, only data that has been de-identified or aggregated as described in Section 6.1, only from applicants who opted in, and never cardholder data or KYC/identity documents.
  8. Authorities and legal process. Courts, regulators, law enforcement or other authorities where we are legally required to, or where we reasonably believe disclosure is necessary to prevent fraud or protect the rights, property or safety of our users, partners or the public.
  9. Business transfers. A buyer, investor or successor in a merger, acquisition, financing, reorganization or sale of all or part of our business or assets, subject to confidentiality obligations. The recipient must continue to honor this policy, including any choices you made under Section 6, or give you notice and a choice.

We do not sell your personal data for money. See Section 14 for how US state laws define "sale" and "sharing" and how to opt out.


8. International transfers

We operate from the United States, and many of the payment providers we place merchants with are located in the United States or other countries outside the EEA and UK. This means your data may be transferred to and processed in countries whose data protection laws differ from those in your country.

When we transfer personal data from the EEA, the UK or Switzerland to a country that has not been recognized as providing adequate protection, we use an appropriate safeguard, such as:

Where a transfer is necessary to take steps at your request before entering a contract, or to perform a contract in your interest (for example sending your application to the provider you want to be placed with), we may also rely on the derogations in GDPR Article 49 where no other safeguard is available.

You can ask for a copy of the relevant safeguards by emailing support@payfresco.com.


9. How long we keep your data

We keep personal data only for as long as we need it for the purposes in this policy.

Data Retention period
Applications, application records and related communications (whether or not they lead to an account) For the duration of our relationship with you and 5 years after it ends (for applications that do not lead to an account, 5 years after our last contact with you), as needed for anti-money-laundering, fraud-prevention and record-keeping purposes, or longer if the law or our agreements with providers require it.
KYC and identity documents No longer than 5 years after the end of our relationship, for the same reasons. Where we do not need to keep a copy, we delete it sooner.
Marketing preferences and contact details used for marketing Until you opt out. We then keep a minimal record of your opt-out so we can honor it.
Website analytics and advertising data Cookie and tracking data are kept for the periods set by the tools described in Section 12 (typically up to 13 months for analytics data); server and security logs are generally kept for no more than 12 months.
Consent and withdrawal records For as long as we rely on the consent, plus 6 years, so we can prove the consent was valid.
Data needed for legal claims Until the claim is resolved and any limitation period has expired.

De-identified and aggregated data that no longer identifies anyone is not personal data and may be kept longer.


10. Your rights

Depending on where you live, you may have the following rights. If you are in the EEA, UK or Switzerland, you have all of them under GDPR Articles 15 to 22 and equivalent laws.

How to exercise your rights: email support@payfresco.com (or message us through any channel you used to apply, such as our Telegram bot or X direct messages; we may ask you to confirm the request by email). We will respond within one month (extendable by two further months for complex requests, in which case we will tell you), or within the time required by your local law. We may need to verify your identity before acting. We will not charge a fee unless a request is manifestly unfounded or excessive.

Some rights are limited. For example, we may need to keep certain data to meet legal obligations or to defend legal claims, and data already sent to a payment provider is held by that provider under its own notice. We will tell you if a limitation applies.


11. Security

We use technical and organizational measures designed to protect personal data, including encryption in transit (HTTPS/TLS) on the Site and our forms, access controls that limit KYC documents to the people who need them, bot protection and fraud screening on our forms, and due diligence on the service providers we use.

No system is perfectly secure. Please send KYC documents only through the secure document-upload step in our application flow or another secure upload link we send you, never in public channels, group chats or social-media posts. If we become aware of a personal data breach that affects you, we will notify you and the authorities where the law requires.


12. Cookies and similar technologies

The Site uses the following cookies and similar technologies:

You can block or delete cookies in your browser settings; some parts of the Site, such as forms, may not work properly without strictly necessary technologies. We honor Global Privacy Control (GPC) browser signals as described in Section 14.


13. Children

The Site and our services are for businesses and are not directed at anyone under 18 (or the age of majority where you live, if higher). We do not knowingly collect personal data from children. If you believe a child has given us personal data, email support@payfresco.com and we will delete it.


14. Notice to US residents, including California residents

This section applies to residents of US states with comprehensive privacy laws, such as California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and others ("US state privacy laws"). Some of these laws apply only to businesses above certain size or revenue thresholds, and may not currently apply to us. We provide this notice anyway, so you know how we handle your information and what choices you have.

14.1 Notice to California residents

This notice is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"). Under the CCPA, business contacts such as owners and employees of applicant businesses are "consumers".

Categories of personal information we collect (in the last 12 months and going forward), with the sources and purposes described in Sections 3 to 5:

CCPA category Examples Disclosed for a business purpose to Sold or shared?
Identifiers Name, email, phone, Telegram/X handle, IP address, cookie identifiers Payment providers, service providers Not shared for cross-context behavioral advertising. Sold only if you opt in to partner referrals (Section 6.2).
Customer records (Cal. Civ. Code ยง1798.80(e)) Address, bank account details, ID numbers Payment providers, service providers No
Commercial information Business type, processing volumes, processing history, products sought Payment providers, service providers Business profile summary only, and only if you opt in to partner referrals
Internet or network activity Pages viewed, device and browser data, interactions with the Site Service providers (analytics, security) No
Professional or employment-related information Job title, ownership percentage, role in the business Payment providers, service providers Only if you opt in to partner referrals
Sensitive personal information Government ID, passport or driver's license numbers, Social Security or tax number where a processor requires it, bank account details Payment providers, service providers Never
Inferences Our assessment of which providers suit your business Payment providers No

Sensitive personal information. We use sensitive personal information only to provide the services you request, verify identity, prevent fraud and comply with law, as permitted by the CCPA. We do not use it to infer characteristics about you. We never sell or share it.

De-identified data. Data licensed under Section 6.1 is de-identified as defined by the CCPA. We maintain it in de-identified form, do not attempt to re-identify it, and contractually require recipients not to re-identify it. Even so, we only use your data for licensing if you opt in.

Sale and sharing. "Sale" under the CCPA can include disclosing personal information for something of value, and "sharing" means disclosing it for cross-context behavioral advertising. We do not sell personal information for money, and we do not share it for cross-context behavioral advertising on payfresco.com. A partner referral you opt into under Section 6.2 may count as a "sale" if we receive a referral fee. We do not knowingly sell or share the personal information of anyone under 16.

Your Privacy Choices: opting out of sale and sharing. You can opt out at any time by:

Your other California rights. You can ask us to: tell you what personal information we collected, used, disclosed and sold or shared about you (the right to know); give you a copy; delete it; correct it; and limit the use of sensitive personal information (we already limit it as described above). You also have the right not to be discriminated against for exercising these rights. To make a request, email support@payfresco.com. We will verify your request by matching information you provide with what we hold. You can use an authorized agent, who must provide proof of authority.

Retention. See Section 9.

Financial incentives. We do not offer financial incentives for personal information.

14.2 Other US states

If you live in another US state with a comprehensive privacy law, you may have similar rights to access, correct, delete and obtain a copy of your personal data, and to opt out of its sale, of targeted advertising and of profiling with significant effects. Use the methods above to make a request. If we deny your request, you can appeal by emailing support@payfresco.com with the subject "Privacy Appeal". If your appeal is denied, you can contact your state Attorney General.


15. Changes to this policy

We may update this policy from time to time. We will post the new version on this page with a new "Last updated" date and version number. If we make a material change, we will notify you by email or a prominent notice on the Site before it takes effect.

We will not use personal data we already hold in a materially different way, including for data licensing or partner referrals, on the basis of a later change to this policy unless you give your affirmative consent.

Previous versions of this policy are available on request.


16. Contact us

Questions, requests or complaints about this policy or your personal data: