PayNow Privacy Policy

Last Modified: March 12, 2025

Introduction

This Privacy Policy will help you better understand how PayNow Services, Inc., PayNow Ltd. (collectively the “Company” or “We”) collects, uses, discloses, transfers, stores, retains and otherwise processes your personal data in your capacity as a subscriber to services (the “Services”) of the Company (“Subscriber”), and/or as a visitor to the Company’s website (“Visitor”). If you are a Subscriber or Visitor, we collect and use your personal data to provide you with the use of our Services and our website.

This Privacy Policy does not apply to third party websites or services such as those provided by Subscribers. In those cases, the Subscriber will be the controller of personal data that is collected by or provided to the Subscriber and you should contact the Subscriber directly with any queries.

For more information about how we use cookies and tracking technologies, please see our Cookies Policy.

The relevant controller for this processing is PayNow Services, Inc, 1442 Pottstown Pike, West Chester, PA 19380-1271 and, unless stated otherwise, references to the Company in this Privacy Policy in relation to processing shall mean PayNow Services Inc.

What personal data do we collect about you and why?

We collect personal data when you subscribe to our Services and when you use our website or when you otherwise provide us information. In general, we need this information for you to be able to use our platform and in order for us to provide the Services to you.

We process the following types of personal data (collectively, “Personal Data”):

Types of Personal Data we collect
How we collect this Personal Data
How we use this Personal Data
Legal Basis
For Subscribers
    Your account information e.g. your name, the name of your staff or other individuals associated with your business, company name, address, email address, and phone number.
    This is information you provide
  • To provide you with, and to improve, the use of our Services (e.g., to confirm your identity, to contact you about our products and services, to contact you about issues with the platform, to invoice you.
  • To advertise and market products or features related to our Services to you
  • To prevent fraudulent use of our Services
  • To verify that we are dealing with you if you contact us
  • To process tax payments to the proper authorities
  • Perform our contractual obligations to you
  • Our legitimate interests in providing the Services and in providing an appropriate level of customer support
  • Comply with our legal obligations e.g. compliance with tax or law enforcement obligations.
    Financial Information e.g. certain details regarding your payment card, your bank account information, PayPal account information, tax documents and related information.
    This is information you provide.
  • To pre-fill your payment information
  • To provide you with the use of our Services and other related services
  • To charge for our Services
  • To process tax payments to the proper authorities
  • To carry out KYC checks
  • To perform our contractual obligations with you
    Information about your access to our websites and apps, your account, and our platform e.g. information about the device and browser you use, your network connection, your IP address, and details about how you browse our websites and platform. We collect some of this information by using "cookies" or other similar technologies directly from your device. For more information about how we use these technologies, see our Cookie Policy.
    This is information we collect from your use of the Services.
    To provide and to improve our Services, website and related services (e.g., identifying ways to make our platform easier to use or navigate)
  • To perform our contractual obligations to you
  • Our legitimate interest in providing our website and platform and in improving its performance
  • Our legitimate interest in protecting the safety and security of our products and services and to detect and prevent fraud.
    Information for Fraud Prevention: In limited circumstances, we will collect certain personal data directly from you (such as photo ID)
  • Where suspicious transactions are identified, we may contact you and collect information from you in order to verify your identify and the relevant transactions.
  • To perform our contractual obligations to you
  • Our legitimate interest in protecting the safety and security of our products and services and to detect and prevent fraud
For Visitors
    Information about your access to our website e.g traffic data, location data, logs, and other communication data and the resources that you access and use on our website. We collect some of this information by using "cookies" or other similar technologies directly from your device. For more information about how we use these technologies, see our Cookie Policy.
    This is information we collect from your use of our website.
    To provide you with the use of our website and any related services and to improve the website and platform.
  • To perform our contractual obligations to you
  • Our legitimate interest in providing our website and platform and in improving its performance
  • Our legitimate interest in protecting the safety and security of our products and services and to detect and prevent fraud.
    Information about your device and internet connection e.g. IP address, operating system and browser type.
    This is information we collect from your use of our website.
    To provide you with the use of our website and any related services and to improve the website and platform.
  • To perform our contractual obligations to you
  • Our legitimate interest in providing our website and platform and in improving its performance
  • Our legitimate interest in protecting the safety and security of our products and services and to detect and prevent fraud.

How do we share your Personal Data?

We sometimes share your Personal Data with third parties in order to provide our Services. We have provided a list of the entities with whom we may share your personal data. We will update this list as appropriate.

Category of service providers with whom we share your Personal Data
Description
Payment Processor
We engage with payment processors to enable end-users to pay for items. When an end-user provides financial information to our payment processors, they will process this personal data in order to enable us to complete the transaction with the end-user.
Payout Processor
We engage with payout processors to enable us to pay our funds earned to our Subscribers.
Sales tax / VAT Processor
We engage with sales tax / VAT processors to enable us to collect and remit sales tax / VAT based on items purchased, location and IP data of the Subscriber.
Fraud Protection & Identity Verification
We engage with fraud protection and identity verification services to protect our platform from fraudulent activities and to verify the identity of our Subscribers for security and regulatory purposes.
Analytics Services
We use PostHog to analyze user behavior and interactions with our services. This helps us understand platform usage, identify improvements, and optimize user experience. PostHog collects information about website visits, usage patterns, and features accessed.

In certain circumstances, we may be legally required to disclose your Personal Data (for example, when we receive a valid court order). Where possible, we will endeavour to provide you information before we disclose your Personal Data in such a circumstance.

We may also disclose your Personal Data to third parties in the event that we sell, buy, transfer, merge, consolidated or re-organise any part(s) of our business or merge with, acquire or acquired by, or form a joint venture or partner with, any other business, in which case we may disclose Your Personal Data to any prospective buyer, new owner, or other third party involved in such change to our business.

Where do we store your Personal Data and do we transfer your Personal Data outside the European Union?

The Company is the controller of your Personal Data, and the Company is based in the United States. The Personal Data we store in relation to you will be stored in the United States.

To operate our business, we may send your Personal Data outside of your state, province, or country, including within the United States. When we send your Personal Data across borders, we take steps to protect your Personal Data such as by implementing the European Commission’s model contracts for the transfer of personal data to third countries (i.e. the “Standard Contractual Clauses”). For a copy of these Standard Contractual Clauses, please contact us at: [email protected].

How we protect your Personal Data

We take appropriate technical and organisational measures to safeguard your Personal Data and to ensure a level of security appropriate to the risk and severity for the rights and freedoms of you and other Subscribers and Visitors. Nevertheless, we cannot guarantee the absolute security of your Personal Data.

Your rights over your Personal Data

If you are based in the European Economic Area, you have certain rights over your Personal Data.

Where we are the controller of your Personal Data, you may contact us to exercise the following rights:

  • request access to your Personal Data and information about our processing of your Personal Data;
  • request rectification or erasure of your Personal Data held by us;
  • request that we cease processing your Personal Data;
  • request that we delete your Personal Data;
  • request that we port your Personal Data to another service provider;
  • request that we restrict our processing of your Personal Data;
  • object to certain processing activities (e.g. profiling activities based on our legitimate interests, automated decision making, etc.); and
  • withdraw your consent to processing where we rely upon your consent as the legal justification for the processing.

We may need to verify your identity in order for you to exercise your rights.

If you would like to exercise your rights, please submit a request by email to [email protected]. Please note that the rights described above are not absolute and may be restricted in certain circumstances, in accordance with applicable law.

You also have the right to lodge a complaint with our lead supervisory authority, the Irish Data Protection Commission (contact information accessible here), or your local supervisory authority.

How long do we retain your Personal Data?

Subscribers

We generally retain your Personal Data for the duration of your subscription to our Services or for as long as is necessary for the purpose for which the Personal Data was collected. If you terminate your subscription, we retain your Personal Data for 6 years before we delete it. We may also have legal obligations to retain Personal Data in certain circumstances (such as, for example, to comply with our legal/regulatory obligations or to allow us to deal with any legal claims or proceedings that may arise). If you contact us to request deletion of your Personal Data, we will begin the Personal Data deletion process after 20 days, except if we are legally required to retain specific information or we refuse your Personal Data on the basis of an exemption in the applicable legislation. If you have questions about this process, please contact us [email protected].

Website Visitors

For visitors using our website, we generally keep your Personal Data for 6 years. Further information can be found in our Cookies Policy.

How we use "cookies" and other tracking technologies

We use cookies and similar tracking technologies on our website and when providing our services. For more information about how we use these technologies, including a list of other companies that place cookies on our sites, a list of cookies that we place when we power a merchant’s store, and an explanation of how you can opt out of certain types of cookies, please see our Cookies Policy.

Children under the age of 16

Our website is not intended for children under 16 years of age. No one under age 16 may provide any information to or on the website. We do not knowingly collect personal information from children under 16. If you are under 16, do not register on the website, make any purchases through the website, use any of the interactive or public comment features of this website or provide any information about yourself to us, including your name, address, telephone number, email address, or any screen name or user name you may use. If we learn we have collected or received personal information from a child under 16 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 16, please contact us at:

1442 Pottstown PikeWest Chester, PA 19380-1271[email protected](302) 298-1262

Some United States residents of certain States, under 16 years of age may have additional rights regarding the collection and sale of their personal information. Please see Your USA States Privacy Rights for more information.

Accessing and Correcting Your Information

You can review and change your personal information by logging into the Website and visiting your account profile page.

You may also send us an email at [email protected] to request access to, correct, or delete any personal information that you have provided to us. We cannot delete your personal information except by also deleting your user account. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.

If you live in the European Union, under GDPR, you have the right to (1) object to Our Company’s processing of your personal data, under certain conditions, (2) request that Our Company transfer the data that we have collected to another organization, or directly to you, under certain conditions, and if you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us at our email:

Write to us: [email protected]

Residents of some USA States may have additional personal information rights and choices. Please see Your USA States Privacy Rights for more information.

Your USA States Privacy Rights

If you are a resident, of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, and Virginia provide (now or in the future) you with additional rights regarding our use of your personal information. These rights include:

  • Confirm whether we process your personal information
  • Access and delete certain personal information.
  • Correct inaccuracies in your personal information, taking into account the information's nature processing purpose (excluding Iowa and Utah).
  • Data portability.
  • Opt-out of personal data processing for:
    • targeted advertising (excluding Iowa);
    • sales; or
    • profiling in furtherance of decisions that produce legal or similarly significant effects (excluding Iowa and Utah).
  • Either limit (opt-out of) or require consent to process sensitive personal data.

The exact scope of these rights may vary by state. To exercise any of these rights please email us at [email protected]

How you can reach us

If you would like to ask about, make a request relating to, or complain about how we process your Personal Data, please contact us at [email protected].

Changes to this Privacy Policy

We reserve the right to amend this privacy policy from time to time.