PayFresco Privacy Policy
Effective date: October 3, 2026 Last updated: October 3, 2026 Policy version: 2.0
This Privacy Policy explains how PayFresco ("PayFresco", "we", "us", "our") collects, uses, shares and protects personal data when you visit payfresco.com (the "Site"), apply for our services, or contact us through any of our channels. It also explains your rights and how to use them. This version replaces our previous Privacy Policy dated June 30, 2026.
PayFresco is a merchant onboarding and placement service. We help businesses, including businesses that payment providers consider "high-risk", find and apply for payment-processing solutions. We are not a payment processor, acquiring bank or lender. We collect information about your business and its owners, review it, and share it with payment processors, acquiring banks, independent sales organizations (ISOs), payment gateways and platform partners so they can decide whether to offer you an account.
Please read this policy together with our Terms of Service.
1. Who we are
The controller of your personal data is PayFresco.
- Mailing address for privacy and legal notices: PayFresco, 304 S Jones Blvd Suite 8779, Las Vegas, NV 89107, United States
- Privacy contact: support@payfresco.com
2. Scope
This policy covers personal data about:
- business owners, directors, officers, beneficial owners, guarantors, authorized signers and employees of businesses that apply to us or contact us ("applicants");
- people whose details applicants give us, such as business references;
- people who visit the Site or interact with our application pages (including payfresco.com/apply), contact form, website chat, the PayFresco CRM dashboard (app.payfresco.com), our Telegram bot, X (Twitter) direct messages, scheduling links, email and calls; and
- people at businesses we work with.
Most of our applicants are businesses, but the information we collect about the people behind those businesses is personal data and is protected by this policy.
This policy does not cover how payment processors, banks, ISOs, gateways or other third parties handle your data once they receive it. They act under their own privacy notices, which you will usually receive when you apply with them.
The PayFresco CRM dashboard (app.payfresco.com). Our CRM dashboard is provided with a technology-platform provider. When you sign up for or use it, you will be shown that platform's terms and privacy notice, which also apply. The dashboard uses its own sign-in, product-analytics, error-monitoring and advertising-measurement tools, which are described in that notice. This policy covers the information you give us through the dashboard and how PayFresco uses it.
3. The data we collect
| Category | Examples |
|---|---|
| Business information | Legal and trading name, website, business type and industry, products or services sold, sales channels, refund and fulfillment practices, country and state of incorporation, business address, years in business, business registration and tax identifiers (such as an EIN), ownership structure. |
| Owner, beneficial-owner and signer personal data | Full name, job title, ownership percentage, date of birth, home address, citizenship or nationality, driver's license or other ID number, and a personal tax or national identification number where a processor requires it. |
| Contact details and handles | Email address, phone number, Telegram username and user ID, X (Twitter) handle, social-media profile links you give us, and other messaging handles you use to contact us. |
| Banking, processing and financial profile | Bank name and account details (such as routing and account numbers) needed for settlement, expected and historical monthly processing volume, average and maximum ticket size, refund and chargeback ratios, current or previous processors, reasons for previous declines or account closures, and the payment methods you want to accept. |
| KYC and identity documents | Government-issued ID, passport, driver's license, proof of address, bank statements, processing statements, voided checks or bank letters, tax ID letters (e.g. IRS EIN confirmation), articles of incorporation and other company documents. |
| Application status and outcomes | Which providers your application was sent to, their requests for more information, and their decisions (approved, pending, declined) and stated reasons. |
| Communications | The content of emails, contact-form submissions, website chat messages, Telegram messages (including messages you post in groups we run), X direct messages, call notes, and attachments you send us. |
| Website, device and cookie data | IP address, browser and device type, pages viewed, referring page, approximate location derived from your IP address, and data collected by cookies and similar technologies (see Section 12). |
| Consent records | Whether you accepted or declined our optional permissions (Section 6), when, through which channel, the policy version shown to you, and your IP address, browser user agent or messaging handle at the time. |
Cardholder data. We do not ask for, and you must not send us, payment card numbers, card security codes (CVV/CVC), "track" data from the magnetic strip or chip, or PINs. If you send us card data by mistake, we will delete it as soon as we notice and will not use it.
Sensitive data. We do not ask for special-category data such as health, religion, political opinion or sexual orientation. Some of the information above (government ID numbers, bank account details) is "sensitive personal information" under some US state laws; we use it only as described in Section 14.
4. Where we get your data
- From you, when you complete our application at payfresco.com/apply, fill in our contact form or website chat form on payfresco.com, sign up for or use the PayFresco CRM dashboard at app.payfresco.com, message our Telegram bot (@payfrescobot), send us a direct message on X (Twitter), book a call through our scheduling page, email us, upload documents, or speak with us.
- From the business you represent, for example when a colleague lists you as an owner, director, signer or business reference on an application. If we receive your data this way, this policy is our notice to you under GDPR Article 14.
- From payment processors, acquiring banks, ISOs, gateways and platform partners, for example underwriting questions, requests for documents, decisions and reasons for decline.
- From public sources, such as company registries, your business website, public reviews and public social-media profiles, which we may check to verify an application.
- From security and fraud-prevention services, such as bot-protection and IP-reputation services that help us detect automated, fraudulent or high-risk submissions.
- Automatically, through cookies and similar technologies when you use the Site (see Section 12).
5. How we use your data and our legal bases
If you are in the European Economic Area (EEA), the United Kingdom or Switzerland, data protection law requires us to have a legal basis for each use of your personal data. The table below lists each purpose and the basis we rely on.
| Purpose | What this involves | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Reviewing your application and placing you with a provider | Assessing your business, preparing your application file, matching you with suitable processors, banks, ISOs, gateways or platform partners, sending them your application and documents, and following up on their questions and decisions. | Steps taken at your request before entering into a contract, and performance of our contract with you (Art. 6(1)(b)). Where the data is about an owner, signer or reference who is not our contracting party, our legitimate interest in providing the service the business asked for (Art. 6(1)(f)). |
| Communicating with you about your application | Replying to messages, requesting missing documents, giving status updates. | Contract / pre-contract steps (Art. 6(1)(b)). |
| Managing the accounts we place and our relationship with providers | Onboarding support after approval, account-health support, resolving disputes, and reconciling the fees or commissions providers pay us. | Contract (Art. 6(1)(b)) and legitimate interests in running our business (Art. 6(1)(f)). |
| Verification, fraud prevention and security | Checking that applications are genuine, screening against sanctions lists, detecting bots, VPN or proxy misuse, preventing misuse of our service and protecting our systems. | Legitimate interests in preventing fraud and protecting our business and partners (Art. 6(1)(f)); legal obligation where sanctions, anti-money-laundering or other laws require it (Art. 6(1)(c)). |
| Legal, regulatory and contractual compliance | Keeping records, responding to lawful requests from authorities, meeting record-keeping and audit requirements in our agreements with providers. | Legal obligation (Art. 6(1)(c)); legitimate interests in meeting our contractual obligations and defending legal claims (Art. 6(1)(f)). |
| Improving our service and internal analytics | Understanding which industries and providers are a good match, measuring approval rates, improving our Site, forms and processes. | Legitimate interests in improving our service (Art. 6(1)(f)). |
| Service-related marketing to existing applicants and clients | Telling you about similar placement services from PayFresco. You can opt out at any time. | Legitimate interests (Art. 6(1)(f)) and, where e-privacy law requires it, your consent or the "existing customer" exemption. |
| Website analytics and advertising technologies | The tools described in Section 12. | Legitimate interests (Art. 6(1)(f)) or, where the law requires it, consent (Art. 6(1)(a)). |
| Optional: licensing de-identified and aggregated data | See Section 6.1. Only if you opt in. | Consent (Art. 6(1)(a)). |
| Optional: referral to partner financing or payment providers | See Section 6.2. Only if you opt in. | Consent (Art. 6(1)(a)). |
Where we rely on legitimate interests, we have weighed our interests against your rights and expectations. You can ask us for more detail about this balancing test, and you can object (Section 10).
Automated decisions. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Automated security checks may flag a submission for manual review. Payment processors and banks make their own underwriting decisions, which may involve automated tools; please ask them about their processes.
6. Optional permissions: data licensing and partner referrals
When you apply, we ask for two separate, optional permissions. Both checkboxes are unchecked by default. You can say no to either or both. Saying no does not affect your application, the service we provide or our fees in any way.
6.1 Licensing de-identified and aggregated data (optional, opt-in only)
What it is. If, and only if, you tick the data-licensing checkbox (or give the same permission later through a separate consent form), we may license de-identified and/or aggregated data derived from your application and our onboarding work to third parties. These third parties may include companies that build or research artificial-intelligence (AI) models and buy data to train or evaluate them, as well as research, analytics and risk-intelligence companies.
What that data looks like. Examples:
- statistics, such as approval and decline rates by industry, country or volume band;
- de-identified records of the onboarding and underwriting workflow, for example the steps an application went through, the kinds of documents requested, the outcome and the general reason, and de-identified versions of onboarding conversations.
How we de-identify it. Before any licensing, we remove or generalize information that could identify you, your business or any other person. This includes names, email addresses, phone numbers, messaging handles, business names, website domains, addresses, account and merchant IDs, the names of payment providers, exact amounts and dates (which we group into ranges), and all attachments. We also remove information about other people who appear in conversations, such as provider staff. We will only license data in a form that does not identify you, your business or any individual, and that cannot reasonably be linked back to you.
Contract protections. Every recipient must agree in writing that it will not attempt to re-identify any person or business, will not combine the data with other data in order to identify anyone, and will not pass the data on except under the same restrictions.
What we never license, sell or share with data buyers, for any purpose:
- Cardholder data: card numbers, card security codes (CVV/CVC), track or chip data, PINs.
- KYC and identity documents: IDs, passports, driver's licenses, selfies or verification videos, bank statements, processing statements, tax ID letters, incorporation documents and other company documents, or images, copies or extracts of them.
This exclusion is absolute and does not depend on whether you opted in.
Withdrawing. You can withdraw this permission at any time by emailing support@payfresco.com with the subject "Withdraw consent" (or by messaging us through the channel you applied with). Withdrawal is free and takes effect going forward: we will stop including your data in any new dataset or licence. Data that has already been delivered to a recipient in de-identified or aggregated form cannot be traced back to you by design, so it cannot be singled out and recalled. Withdrawing does not affect the lawfulness of anything done before you withdrew.
Data collected before October 3, 2026. We will not apply this data-licensing section to any data we collected before October 3, 2026 unless you give fresh, opt-in consent. If you do nothing, data collected before that date will not be licensed.
6.2 Referral to partner financing and payment providers (optional, opt-in only)
If, and only if, you tick the partner-referral checkbox, we may share your contact details and a summary of your business profile (business name, industry, country, approximate processing volume and the type of product you are looking for) with selected partners that offer complementary services, so they can contact you with offers.
- The partners we refer to fall into these categories: business-financing providers (such as revenue-based financing and merchant cash-advance providers), business banking and business card providers, payment gateways and alternative payment-method providers, and chargeback and fraud-management services.
- We do not share your KYC or identity documents, bank or processing statements, or cardholder data under this permission.
- We may receive a referral fee or other compensation from the partner.
- Each partner uses your data under its own privacy notice.
- You can withdraw at any time by emailing support@payfresco.com with the subject "Withdraw consent". We will stop making new referrals and will ask partners we have already referred you to, where we can, to stop contacting you. You can also contact the partner directly.
7. Who we share your data with
We share personal data only as described here.
- Payment processors, acquiring banks, ISOs, gateways and platform partners. Sharing your application, documents and related information with these providers is the core of our service: without it, we cannot place you. Each provider decides independently whether to approve you, and processes your data under its own privacy notice and legal obligations (for example, anti-money-laundering, sanctions and card-network rules). Providers may also check industry databases, such as card-network lists of terminated merchants.
- Underwriters and risk reviewers working for us or for those providers.
- Service providers acting on our behalf, such as hosting and database providers, email and messaging tools, customer-support and chat software, CRM tools, document storage, scheduling tools, bot-protection and IP-reputation services, analytics providers and professional advisers. They may only use your data to provide services to us, under written contracts.
- Messaging and social platforms. If you contact us through Telegram, X or another platform, that platform processes your messages under its own privacy policy as an independent controller.
- Advertising and analytics providers, through the website technologies described in Section 12.
- Partner financing and payment providers, only if you opt in under Section 6.2.
- Licensees of de-identified or aggregated data, only data that has been de-identified or aggregated as described in Section 6.1, only from applicants who opted in, and never cardholder data or KYC/identity documents.
- Authorities and legal process. Courts, regulators, law enforcement or other authorities where we are legally required to, or where we reasonably believe disclosure is necessary to prevent fraud or protect the rights, property or safety of our users, partners or the public.
- Business transfers. A buyer, investor or successor in a merger, acquisition, financing, reorganization or sale of all or part of our business or assets, subject to confidentiality obligations. The recipient must continue to honor this policy, including any choices you made under Section 6, or give you notice and a choice.
We do not sell your personal data for money. See Section 14 for how US state laws define "sale" and "sharing" and how to opt out.
8. International transfers
We operate from the United States, and many of the payment providers we place merchants with are located in the United States or other countries outside the EEA and UK. This means your data may be transferred to and processed in countries whose data protection laws differ from those in your country.
When we transfer personal data from the EEA, the UK or Switzerland to a country that has not been recognized as providing adequate protection, we use an appropriate safeguard, such as:
- the European Commission's Standard Contractual Clauses (SCCs), with the UK International Data Transfer Addendum or the Swiss amendments where relevant;
- the recipient's certification under the EU-US Data Privacy Framework (and its UK and Swiss extensions), where applicable; or
- an adequacy decision for the destination country.
Where a transfer is necessary to take steps at your request before entering a contract, or to perform a contract in your interest (for example sending your application to the provider you want to be placed with), we may also rely on the derogations in GDPR Article 49 where no other safeguard is available.
You can ask for a copy of the relevant safeguards by emailing support@payfresco.com.
9. How long we keep your data
We keep personal data only for as long as we need it for the purposes in this policy.
| Data | Retention period |
|---|---|
| Applications, application records and related communications (whether or not they lead to an account) | For the duration of our relationship with you and 5 years after it ends (for applications that do not lead to an account, 5 years after our last contact with you), as needed for anti-money-laundering, fraud-prevention and record-keeping purposes, or longer if the law or our agreements with providers require it. |
| KYC and identity documents | No longer than 5 years after the end of our relationship, for the same reasons. Where we do not need to keep a copy, we delete it sooner. |
| Marketing preferences and contact details used for marketing | Until you opt out. We then keep a minimal record of your opt-out so we can honor it. |
| Website analytics and advertising data | Cookie and tracking data are kept for the periods set by the tools described in Section 12 (typically up to 13 months for analytics data); server and security logs are generally kept for no more than 12 months. |
| Consent and withdrawal records | For as long as we rely on the consent, plus 6 years, so we can prove the consent was valid. |
| Data needed for legal claims | Until the claim is resolved and any limitation period has expired. |
De-identified and aggregated data that no longer identifies anyone is not personal data and may be kept longer.
10. Your rights
Depending on where you live, you may have the following rights. If you are in the EEA, UK or Switzerland, you have all of them under GDPR Articles 15 to 22 and equivalent laws.
- Access (Art. 15): ask whether we hold your data and get a copy.
- Rectification (Art. 16): ask us to correct inaccurate or incomplete data.
- Erasure (Art. 17): ask us to delete your data, where we no longer have a valid reason to keep it.
- Restriction (Art. 18): ask us to limit how we use your data, for example while we check a correction.
- Notification (Art. 19): we will tell recipients about corrections, deletions or restrictions where possible.
- Portability (Art. 20): receive data you gave us in a structured, machine-readable format, or have it sent to another company, where we process it based on consent or contract and by automated means.
- Objection (Art. 21): object to processing based on legitimate interests. You can object to direct marketing at any time, and we will stop.
- Automated decisions (Art. 22): not to be subject to decisions based solely on automated processing with legal or similarly significant effects. As noted in Section 5, we do not make such decisions.
- Withdraw consent: where we rely on consent (Section 6 and any consent-based cookies), you can withdraw at any time, as easily as you gave it. This does not affect earlier processing.
- Complain: you can lodge a complaint with a data protection supervisory authority, in particular in the country where you live, work or where an alleged infringement took place. In the UK this is the Information Commissioner's Office (ico.org.uk). A list of EU authorities is at edpb.europa.eu. We would appreciate the chance to deal with your concerns first.
How to exercise your rights: email support@payfresco.com (or message us through any channel you used to apply, such as our Telegram bot or X direct messages; we may ask you to confirm the request by email). We will respond within one month (extendable by two further months for complex requests, in which case we will tell you), or within the time required by your local law. We may need to verify your identity before acting. We will not charge a fee unless a request is manifestly unfounded or excessive.
Some rights are limited. For example, we may need to keep certain data to meet legal obligations or to defend legal claims, and data already sent to a payment provider is held by that provider under its own notice. We will tell you if a limitation applies.
11. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit (HTTPS/TLS) on the Site and our forms, access controls that limit KYC documents to the people who need them, bot protection and fraud screening on our forms, and due diligence on the service providers we use.
No system is perfectly secure. Please send KYC documents only through the secure document-upload step in our application flow or another secure upload link we send you, never in public channels, group chats or social-media posts. If we become aware of a personal data breach that affects you, we will notify you and the authorities where the law requires.
12. Cookies and similar technologies
The Site uses the following cookies and similar technologies:
- Strictly necessary. Technologies that make the Site and our forms work and keep them secure.
- Security. Our forms use a bot-protection challenge (Cloudflare Turnstile), which processes technical signals such as your IP address and browser characteristics to tell humans from bots.
- Analytics. Many pages of payfresco.com use Microsoft Clarity, an analytics tool that records how visitors use pages (for example clicks, scrolling, mouse movement and page views) to produce heatmaps and session replays that help us improve the Site. Clarity uses cookies and similar technologies and collects device, browser and approximate-location information. Clarity is not loaded on our application page (payfresco.com/apply). Microsoft processes this data under its own privacy statement (privacy.microsoft.com). We also record basic, first-party funnel events (for example which step of our application flow you reached) using your browser's session storage, which is cleared when you close the tab. We do not use Google Analytics or the Meta (Facebook) pixel on payfresco.com.
- Advertising. We do not use advertising cookies or advertising pixels on payfresco.com.
You can block or delete cookies in your browser settings; some parts of the Site, such as forms, may not work properly without strictly necessary technologies. We honor Global Privacy Control (GPC) browser signals as described in Section 14.
13. Children
The Site and our services are for businesses and are not directed at anyone under 18 (or the age of majority where you live, if higher). We do not knowingly collect personal data from children. If you believe a child has given us personal data, email support@payfresco.com and we will delete it.
14. Notice to US residents, including California residents
This section applies to residents of US states with comprehensive privacy laws, such as California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and others ("US state privacy laws"). Some of these laws apply only to businesses above certain size or revenue thresholds, and may not currently apply to us. We provide this notice anyway, so you know how we handle your information and what choices you have.
14.1 Notice to California residents
This notice is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"). Under the CCPA, business contacts such as owners and employees of applicant businesses are "consumers".
Categories of personal information we collect (in the last 12 months and going forward), with the sources and purposes described in Sections 3 to 5:
| CCPA category | Examples | Disclosed for a business purpose to | Sold or shared? |
|---|---|---|---|
| Identifiers | Name, email, phone, Telegram/X handle, IP address, cookie identifiers | Payment providers, service providers | Not shared for cross-context behavioral advertising. Sold only if you opt in to partner referrals (Section 6.2). |
| Customer records (Cal. Civ. Code ยง1798.80(e)) | Address, bank account details, ID numbers | Payment providers, service providers | No |
| Commercial information | Business type, processing volumes, processing history, products sought | Payment providers, service providers | Business profile summary only, and only if you opt in to partner referrals |
| Internet or network activity | Pages viewed, device and browser data, interactions with the Site | Service providers (analytics, security) | No |
| Professional or employment-related information | Job title, ownership percentage, role in the business | Payment providers, service providers | Only if you opt in to partner referrals |
| Sensitive personal information | Government ID, passport or driver's license numbers, Social Security or tax number where a processor requires it, bank account details | Payment providers, service providers | Never |
| Inferences | Our assessment of which providers suit your business | Payment providers | No |
Sensitive personal information. We use sensitive personal information only to provide the services you request, verify identity, prevent fraud and comply with law, as permitted by the CCPA. We do not use it to infer characteristics about you. We never sell or share it.
De-identified data. Data licensed under Section 6.1 is de-identified as defined by the CCPA. We maintain it in de-identified form, do not attempt to re-identify it, and contractually require recipients not to re-identify it. Even so, we only use your data for licensing if you opt in.
Sale and sharing. "Sale" under the CCPA can include disclosing personal information for something of value, and "sharing" means disclosing it for cross-context behavioral advertising. We do not sell personal information for money, and we do not share it for cross-context behavioral advertising on payfresco.com. A partner referral you opt into under Section 6.2 may count as a "sale" if we receive a referral fee. We do not knowingly sell or share the personal information of anyone under 16.
Your Privacy Choices: opting out of sale and sharing. You can opt out at any time by:
- emailing support@payfresco.com with the subject "Do Not Sell or Share", which turns off any partner-referral permission you gave under Section 6.2; or
- enabling the Global Privacy Control (GPC) signal in your browser, which we treat as an opt-out of sale and sharing for that browser.
Your other California rights. You can ask us to: tell you what personal information we collected, used, disclosed and sold or shared about you (the right to know); give you a copy; delete it; correct it; and limit the use of sensitive personal information (we already limit it as described above). You also have the right not to be discriminated against for exercising these rights. To make a request, email support@payfresco.com. We will verify your request by matching information you provide with what we hold. You can use an authorized agent, who must provide proof of authority.
Retention. See Section 9.
Financial incentives. We do not offer financial incentives for personal information.
14.2 Other US states
If you live in another US state with a comprehensive privacy law, you may have similar rights to access, correct, delete and obtain a copy of your personal data, and to opt out of its sale, of targeted advertising and of profiling with significant effects. Use the methods above to make a request. If we deny your request, you can appeal by emailing support@payfresco.com with the subject "Privacy Appeal". If your appeal is denied, you can contact your state Attorney General.
15. Changes to this policy
We may update this policy from time to time. We will post the new version on this page with a new "Last updated" date and version number. If we make a material change, we will notify you by email or a prominent notice on the Site before it takes effect.
We will not use personal data we already hold in a materially different way, including for data licensing or partner referrals, on the basis of a later change to this policy unless you give your affirmative consent.
Previous versions of this policy are available on request.
16. Contact us
Questions, requests or complaints about this policy or your personal data:
- Email: support@payfresco.com
- Post: PayFresco, 304 S Jones Blvd Suite 8779, Las Vegas, NV 89107, United States