Privacy Policy
Payco ("we," "us") provides payment processing, point-of-sale, and related business services. This policy explains what we collect, why, and the choices you have. We keep it in plain language on purpose.
What we collect
- Information you give us — name, business details, contact information, and documents you submit with an application (for example, processing statements and identity documents).
- Information from your use of the platform — pages visited, device and browser characteristics, and error diagnostics that help us keep the platform reliable.
- Information required for underwriting — when you apply for a merchant account, our sponsor banks and processing partners require the information mandated by card-network rules and federal law (including the USA PATRIOT Act's customer-identification requirements).
How we use it
- To evaluate, open, and service your merchant account.
- To operate, secure, and improve the platform.
- To communicate with you about your application, account, and service — never to sell to third-party marketers.
Sharing
We share information only with the parties needed to deliver the service: sponsor banks, processing networks, equipment and software vendors involved in your account, and service providers under confidentiality obligations. We do not sell personal information.
Security
Sensitive fields are protected in transit and at rest, access inside Payco is role-restricted and logged, and we design for the card industry's PCI-DSS requirements. No system is perfectly secure; if an incident affects your information we will notify you as the law requires.
Cookies & analytics
We set a small number of cookies to keep you signed in, to keep the platform secure, and to balance load across our servers. We do not run analytics or advertising trackers on this site — no Google Analytics, no tag manager, no advertising pixel. There is nothing here that follows you to another website.
We also honour your browser's privacy signal. If your browser sends Global Privacy Control (GPC) or Do Not Track, we record that as an opt-out automatically and do not ask you again. You can see or change what is stored on your device with the button below.
Who else processes your information
We use a small number of service providers to run the platform. Each one receives only what it needs to do its job, under contract and under confidentiality obligations.
- Cloudflare, Inc. (United States) — hosting, our database and file storage, and the anti-bot check on our forms. Technically everything you send us passes through Cloudflare.
- Anthropic, PBC (United States) — powers Yolanda, the AI assistant in the corner of this site. When you type a message to Yolanda, that message is sent to Anthropic's Claude API to write a reply, together with your name if you are signed in. Yolanda cannot see your account, your application or your statements. If you would rather not use a third-party AI service, do not use the assistant — nothing else on the platform sends anything to it.
- Resend (United States) — sends our transactional email: application confirmations, notifications and sign-in messages. It receives the recipient's name, email address and the contents of that email.
- Twilio, Inc. (United States) — not currently in use. The phone-verification and SMS alert paths are built but switched off; no phone number has been sent to Twilio. This entry is here so that turning it on is a change to a published list and not a silent one.
Separately from these providers, your merchant application is shared with our sponsor banks and processing partners — Elavon Inc. and Wells Fargo Bank, N.A. — as described under Sharing. They are not our service providers; they are the institutions that underwrite and settle your account.
Why we are allowed to hold it
Where the GDPR or UK GDPR applies to you, our lawful bases are: contract, for everything needed to evaluate, open and service your merchant account; legal obligation, for the identity and record-keeping duties card-network rules and federal law impose on us (including the USA PATRIOT Act's customer-identification requirements); legitimate interests, for keeping the platform secure, reliable and free of fraud; and consent, for anything you opt into, which you can withdraw at any time.
Where your information goes
Payco is in California and every provider listed above is in the United States, so if you contact us from outside the US your information is transferred to the US. Where that transfer needs a legal basis under the GDPR or UK GDPR, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) in our contracts with those providers.
Children
Payco is a service for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to info@mypayco.com and we will delete it.
If something goes wrong
If a security incident affects your personal information, we will notify you and the regulators who need to be told, without undue delay and within the deadlines the law sets — 72 hours to the supervisory authority where the GDPR applies, and California's own notification requirements where they apply. Security researchers: our contact details and the scope we consider in-scope are published at /.well-known/security.txt and our disclosure policy.
Retention & your choices
We keep records for as long as your account is active and as long as card-network and legal requirements demand. Some records we are required to keep even after you close your account — card-network rules and federal law set those periods, not us.
Your rights. Whoever and wherever you are, you can ask us to: show you what we hold (access), correct it, delete it, give you a copy in a portable file (export), or stop using it for a particular purpose. If you are in California you also have the right to know, to delete, to correct, to opt out of sale or sharing — we do not sell personal information — and not to be discriminated against for exercising any of them. If the GDPR or UK GDPR applies to you, you additionally have the rights to restriction, objection and portability, and you may complain to your local supervisory authority.
How to exercise them: use the privacy request form, which is the fastest route and gives you a reference number, or email info@mypayco.com. We answer within 45 days for California requests and within one month where the GDPR applies, and we will tell you if we need longer. We do not charge for this and we will not ask you for more information than we need to find your records.