Privacy policy
What we collect, why we collect it, who it goes to and what you can ask us to do with it — for site visitors, partners and the merchants running on the gateway.
1. Who we are
SurePay operates a payment gateway that is licensed to independent sales organisations (ISOs), independent software vendors (ISVs) and other partners, together with the marketing site and API reference at surepay.co.
For the purposes of data protection law, SurePay is the controller of personal information collected through this website and in the course of managing partner relationships. Where a partner licenses and operates the gateway for its own merchants, SurePay acts as a processor or service provider on that partner’s instructions.
The legal entity, registered address and any data protection representative are set out under Contact us.
2. What this policy covers
This policy explains what personal information SurePay collects, why, who it is shared with and what rights you have over it. It covers:
- Visitors to surepay.co, including the API reference.
- People who contact us, request a sandbox or book a scoping call.
- Staff at ISOs, ISVs and merchants who hold accounts in the gateway, its portal, its mobile applications or its terminal software.
It does not govern how an individual merchant or partner handles data in its own systems, or how a card brand, issuer or acquiring processor handles data once a transaction has left the gateway. Those organisations publish their own notices.
3. Information we collect
Information you give us
- Enquiry details — name, company, work email, role, an approximate merchant count and anything you type into the message field.
- Account details — for users of the gateway: name, business email, telephone number, username and role assignment.
- Onboarding and underwriting information submitted by a partner or merchant, which may include business registration details, bank account details and, where the acquirer requires it, identifying information about beneficial owners.
Information we collect automatically
- Technical data — IP address, browser and device type, operating system, referring page and the pages you view, collected through server logs.
- Cookies and similar technologies — see Cookies.
- Security and audit logs — sign-in events, administrative actions and API calls made against your account.
Transaction and cardholder data
When the gateway processes a payment it handles the primary account number, expiry date, cardholder name, verification values and, for ACH, the routing and account number, together with the amount and any order reference. This data is handled under Cardholder data and PCI DSS. SurePay does not use it for marketing and does not sell it.
4. How we use information
- To authorise, settle, void, refund and reconcile payments, and to make those records available to the merchant and its ISO.
- To provide, secure, support and improve the gateway, the portal, the mobile applications and the terminal software.
- To respond to enquiries, issue sandbox credentials and manage the commercial relationship.
- To detect, investigate and prevent fraud, chargeback abuse and misuse of the platform.
- To meet obligations under card brand rules, NACHA rules, anti-money-laundering law, tax law and lawful requests from authorities.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
5. Legal bases
Where the UK GDPR or EU GDPR applies, we rely on: performance of a contract (operating the gateway and the licence); legitimate interests (securing the platform, preventing fraud, and business-to-business communication with partners); compliance with a legal obligation (financial crime, card scheme and tax requirements); and consent, where we ask for it, which you may withdraw at any time.
6. Who we share it with
- Acquiring processors and card networks — including TSYS/Global Payments (TransIT), Fiserv (Omaha/North) and Paya/Nuvei, as required to authorise and settle a transaction.
- The partner in your chain — an ISO or ISV can see the merchants and transactions inside its own hierarchy, and no further.
- Infrastructure and service providers — principally Microsoft Azure for hosting, plus providers of email delivery, telephony and support tooling, each under contract and limited to what the service requires.
- Professional advisers, auditors and QSAs, under confidentiality.
- Authorities, where we are legally required to disclose, or to establish or defend legal claims.
- A successor, in the event of a merger, acquisition or sale of assets, subject to this policy.
A current list of sub-processors is available to partners on request.
7. Cardholder data and PCI DSS
SurePay is assessed as a PCI DSS Level 1 service provider. Cardholder data is encrypted in transit and at rest, keys are held in a hardware security module rather than in application code, and full card numbers are not written to application logs.
Where a merchant integrates using Payment Token JS or a hosted payment page, the card number is captured by SurePay directly in the cardholder’s browser and exchanged for a token, so it never reaches the merchant’s own servers.
Verification values (CVV2/CVC2) are never stored after authorisation. A current Attestation of Compliance is available to partners under NDA.
8. Cookies
surepay.co uses only what is necessary to serve and secure the site. It sets no advertising cookies and runs no third-party advertising or social tracking scripts. Where analytics are used, they are configured without cross-site identifiers.
You can block or delete cookies in your browser; strictly necessary cookies cannot be refused without affecting how the site works. Signed-in areas of the gateway use a session cookie to keep you authenticated.
9. How long we keep it
- Enquiries — kept while we are in contact and for a reasonable period afterwards, then deleted.
- Transaction records — retained for the period required by card brand rules, NACHA rules and applicable financial record-keeping law, which is typically no less than seven years.
- Security and audit logs — retained for the period set out in our PCI DSS programme.
Where SurePay processes data on a partner’s behalf, retention follows that partner’s instructions and the licence agreement.
10. Security
Access to production systems is role-based, granted on least privilege and reviewed periodically. Credentials issued through the API are scoped to a single merchant processor account, so a compromised integration cannot reach a wider portfolio. Data is encrypted in transit with TLS and at rest, and the platform is deployed across multiple Azure regions with geo-replication.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify affected partners and, where required, regulators and individuals, within the timeframes the law sets.
11. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected or deleted, to object to or restrict how it is used, to receive a portable copy, and to opt out of sale or sharing — which, as noted above, SurePay does not do. You will not be discriminated against for exercising these rights.
To make a request, write to the address under Contact us. We will verify your identity before acting, and we will respond within the period the applicable law allows. An authorised agent may act on your behalf with written permission.
If SurePay holds your data on behalf of a merchant or partner, we will refer your request to that organisation and support them in answering it.
If you are in the UK or EEA and are unhappy with our response, you may complain to your national supervisory authority.
12. International transfers
SurePay operates from the United States and hosts on Microsoft Azure. Where personal information is transferred out of the UK or EEA, we rely on the UK International Data Transfer Addendum or the European Commission’s Standard Contractual Clauses, together with the technical measures described above.
13. Children
The gateway and this site are business tools. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with information, contact us and we will delete it.
14. Changes to this policy
We will post any change on this page and update the effective date above. Where a change is material, we will give partners notice through the account contact we hold for them.
15. Contact us
- privacy@surepay.co
- Support
- support@surepay.co
- Telephone
- (877) 872-1333
- Postal address
- [REGISTERED ENTITY NAME]
[STREET ADDRESS]
[CITY, STATE, ZIP]