1. What This Privacy Policy Covers
This Privacy Policy describes how Payplify ("Payplify", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the Payplify website, application, APIs, and related services (collectively, the "Service").
This Policy applies to creators, businesses, and other sellers ("Creators"), end customers who purchase Products through the Service ("Buyers"), visitors to our website, and people who interact with our marketing or support channels.
It does not apply to third-party websites, products, or services linked from the Service. Please review the privacy policies of those third parties separately.
When you act as a Creator using the Service to sell to your Buyers, you act as an independent data controller of your Buyers' personal data for your own purposes (such as fulfilling orders and managing customer relationships). Payplify and the Creator are each responsible for compliance with applicable law for their respective processing activities.
2. Personal Data We Collect
We collect personal data in three main ways: information you provide directly, information collected automatically as you use the Service, and information we receive from third parties (such as our Payment Providers and verification partners).
The categories of personal data we may collect include:
| Category | Examples |
|---|---|
| Account & profile data | Name, email address, password, profile photo, business name, website, social handles, time zone, language |
| Identity verification data (KYC/KYB) | Government-issued ID, date of birth, address, tax identification number, beneficial-ownership information, business registration documents |
| Payout & financial data | Bank account or wallet information, payout preferences, transaction history, settlement details (collected and processed primarily by our Payment Providers) |
| Transaction data | Order details, amounts, currency, refunds, chargebacks, subscription status, payment method type (note: full payment card numbers are handled by PCI-DSS-compliant Payment Providers and are not stored by Payplify) |
| Content data | Files, descriptions, images, videos, and other content you upload to sell or display |
| AI feature data | Prompts and product content submitted to PayplifAI, and generated responses |
| Communications data | Messages you send to support, survey responses, replies to our emails, notes you add to your account |
| Device & technical data | IP address, device identifiers, browser type, operating system, language, time zone, referring URLs, pages viewed, clickstream and interaction data, crash logs, performance metrics |
| Cookies & similar technologies | Cookies, pixels, SDKs, local storage, and similar identifiers (see Section 6) |
| Location data | Approximate location derived from IP address; precise location only where you explicitly grant permission |
| Marketing data | Marketing preferences, campaign engagement, referral source, UTM parameters |
Sensitive personal data. We do not seek to collect sensitive personal data (such as racial or ethnic origin, religious beliefs, health information, or sexual orientation) and ask that you not provide it through the Service. Where local law treats identification, financial, or precise-location data as sensitive, we process it only as permitted by that law.
3. Where Personal Data Comes From
We collect personal data from the following sources:
- Directly from you when you create an account, complete onboarding, configure your store, contact support, or otherwise interact with the Service.
- Automatically through your device and browser when you use the Service, including via cookies and similar technologies.
- From Buyers when they purchase Products you offer (in which case we receive their data on your behalf).
- From our Payment Providers and identity-verification partners (e.g., to confirm KYC/AML status, validate bank information, or process payouts).
- From fraud-prevention, risk-scoring, and sanctions-screening providers.
- From analytics, advertising, and attribution providers, including referral sources and campaign performance data.
- From public sources, such as business registries, government sanctions lists, and publicly available web content.
- From third parties you connect to your account (e.g., social logins, integrations, or marketing platforms).
4. How We Use Personal Data
We use personal data for the following purposes. Where required by law, we rely on a legal basis listed in Section 5.
- Provide, operate, and maintain the Service, including hosting checkout, processing transactions, delivering Products, and producing analytics.
- Provide PayplifAI features by processing your prompts and product content with OpenAI to generate responses and help you create store and product content.
- Create and manage accounts, authenticate users, and protect against unauthorized access.
- Comply with KYC, KYB, AML, sanctions, and other regulatory obligations applicable to us or our Payment Providers.
- Process payouts and reconcile transactions, including coordination with Payment Providers.
- Detect, prevent, investigate, and respond to fraud, abuse, security incidents, chargebacks, and other prohibited activities.
- Provide customer support, respond to inquiries, and communicate about your account.
- Send service messages (such as transaction confirmations, security alerts, policy updates, and payout notifications).
- With your consent or where otherwise permitted, send marketing and promotional communications, and measure their effectiveness.
- Personalize and improve the Service, develop new features, and conduct research and analytics.
- Enforce our Terms of Service and other policies, and protect our rights, property, and the safety of our users and others.
- Comply with legal obligations and respond to lawful requests from public authorities.
5. Legal Bases (EEA, UK, and Similar Jurisdictions)
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with similar laws, we rely on the following legal bases to process your personal data:
- Contract: to provide the Service you have requested and to perform our agreement with you.
- Legal obligation: to comply with applicable laws, including AML, tax, accounting, and consumer-protection laws.
- Legitimate interests: to operate, secure, and improve the Service; prevent fraud and abuse; conduct analytics; and pursue our commercial interests, where these interests are not overridden by your rights.
- Consent: where required, for example for certain cookies, direct marketing, or processing of certain sensitive data. You may withdraw consent at any time.
- Vital interests and public interest: in limited circumstances where processing is necessary to protect a person's life or for reasons of substantial public interest.
8. International Data Transfers
Payplify operates internationally. Personal data may be transferred to, stored in, and processed in countries other than your country of residence, including the United States and other countries that may have different data-protection laws than your own.
Where we transfer personal data out of the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or other lawful transfer mechanisms.
9. Data Retention
We retain personal data for as long as necessary to provide the Service and for the additional purposes described in this Policy, including to comply with our legal, tax, accounting, AML, and audit obligations; resolve disputes; enforce our agreements; and protect against fraud and security incidents.
Retention periods vary by data type and context. For example, transaction and KYC/AML records are typically retained for at least the period required by applicable financial regulations (often five (5) to seven (7) years from the end of the customer relationship or the transaction). Marketing data is retained until you opt out or it is no longer useful for the original purpose.
When personal data is no longer required, we will delete, anonymize, or aggregate it. If deletion is not feasible (for example, because the data is stored in backup archives), we will securely store it and isolate it from further processing until deletion is possible.
AI data. The no-training restriction described in Section 7 is separate from data retention. OpenAI may retain API data for service operation and abuse monitoring, depending on the features and data controls used. This Policy does not promise zero retention of AI inputs or outputs. Contact [email protected] with questions about your PayplifAI data.
10. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit, access controls, network monitoring, employee training, vendor risk reviews, and incident-response procedures.
Payment card data is processed by PCI-DSS-compliant Payment Providers and is not stored on our servers.
No method of transmission or storage is completely secure. You are responsible for safeguarding your account credentials and for promptly notifying us at [email protected] of any suspected unauthorized access.
11. Your Privacy Rights
Depending on where you live, you may have the following rights with respect to your personal data, subject to certain exceptions:
- Access — request a copy of the personal data we hold about you.
- Correction — request that inaccurate or incomplete data be corrected.
- Deletion — request that we delete personal data, subject to legal exceptions (for example, when we must retain records for AML or tax purposes).
- Portability — receive your personal data in a structured, commonly used, machine-readable format.
- Restriction or objection — restrict or object to certain processing, including processing based on legitimate interests and direct marketing.
- Withdraw consent — where processing is based on consent, withdraw consent at any time without affecting prior processing.
- Opt out of sale or sharing — where applicable under US state laws, opt out of "sales" or "sharing" of personal information, including cross-context behavioral advertising.
- Lodge a complaint with your local data-protection authority.
To exercise these rights, contact [email protected]. We may need to verify your identity for certain requests, where permitted by law. We will not require identity verification for an opt-out request where applicable law prohibits it. You may also designate an authorized agent to act on your behalf, subject to applicable requirements.
We will not discriminate against you for exercising any of these rights.
12. U.S. State Privacy Rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, or any other state with a comprehensive privacy law, you have specific rights, including the rights described in Section 11 above and the right to opt out of "sales," "sharing," "targeted advertising," and certain "profiling" activities.
California (CCPA/CPRA). In the prior 12 months, we have collected the categories of personal information described in Section 2 for the business purposes described in Section 4, from the sources described in Section 3, and disclosed personal information to the categories of recipients described in Section 7. We do not knowingly sell or share the personal information of consumers under 16. California residents may also request information about our disclosures for direct-marketing purposes under California's "Shine the Light" law (Cal. Civ. Code § 1798.83).
Submit privacy requests, including requests to opt out of sale, sharing, or targeted advertising, to [email protected]. See Section 6 for information about browser signals. Your rights under applicable law are unaffected.
Nevada. Nevada residents may request that we not sell their covered personal information by contacting us at [email protected].
13. Children's Privacy
The Service is not directed to, and we do not knowingly collect personal data from, children under the age of 16 (or such other age as required by local law). If we learn that we have collected personal data from a child without verifiable parental consent, we will delete it.
If you believe a child has provided us with personal data, please contact [email protected].
14. Text Messaging Consent & Mobile Data
If you provide your mobile phone number and opt in, we may send service messages (such as login codes, transaction notifications, and security alerts) and, where you separately consent, marketing messages.
Message frequency varies. Message and data rates may apply. You may opt out of marketing SMS at any time by replying STOP to any marketing message, or HELP for help. Opting out of marketing does not stop service messages required to operate your account.
We do not share mobile information or text-message opt-in consent with third parties for their own marketing purposes.
15. Automated Decision-Making
We use automated systems for fraud detection, risk scoring, sanctions screening, transaction monitoring, and account-eligibility decisions. These systems may produce decisions that significantly affect you, including declining transactions, holding payouts, or suspending accounts.
Where required by law, you have the right to obtain human review of these decisions, to express your point of view, and to contest the decision by contacting [email protected].
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Effective date" above. If changes are material, we will provide additional notice (for example, by email or in-app notice) as required by law. Where a change requires your consent, we will obtain it before carrying out the processing that requires it. Continued use of the Service does not, by itself, constitute consent to processing that requires consent.
17. Contact Us
If you have questions about this Privacy Policy or our handling of your personal data, contact us at [email protected]. For general account or product support, contact [email protected].
For privacy inquiries relating to the EEA or the UK, contact [email protected].
Make a privacy request.
Contact [email protected] to exercise your privacy rights or ask about your data. Please describe your request; you do not need to send identity documents in your first email.
For help with your account, contact [email protected].