Legal
PaymentKit privacy policy
Effective date: June 23, 2026
1. Scope and our role
This Privacy Policy explains how Payment Kit LLC (“Payment Kit,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with paymentkit.com and other websites that link to this Policy, our applications and dashboards, sales and marketing activities, support, events, and business operations (collectively, the “Business Services”).
This Policy also explains the distinction between information Payment Kit processes for its own purposes and personal information contained in a customer’s billing, subscription, payment, or end-customer data that Payment Kit processes on behalf of that customer.
When Payment Kit decides why and how personal information is processed (for example, information about website visitors, prospects, customer administrators, job applicants, or business contacts), Payment Kit acts as a controller or business under applicable privacy laws.
When Payment Kit processes personal information submitted by or for a customer to provide subscription billing, payment orchestration, hosted checkout, payment routing, dunning, analytics, fraud-management, tokenization, or related services, Payment Kit generally acts as a processor or service provider on behalf of that customer. The customer’s privacy policy governs that processing, and individuals should ordinarily direct privacy requests regarding that data to the relevant customer.
This Policy does not apply to third-party websites, Payment Providers, or services that have their own privacy practices.
2. Personal information we collect
We may collect the following categories of personal information, depending on how you interact with us:
- Identifiers and contact information
- Name, business email, telephone number, mailing address, username, account identifier, online identifiers, and IP address.
- Professional and company information
- Employer, job title, department, company size, industry, business contact information, and business interests.
- Account and authentication information
- Login credentials, authentication events, roles, permissions, API-key metadata, and account settings.
- Commercial and billing information
- Plans, orders, invoices, subscription details, payment status, billing contacts, tax information, and records of products or services considered or purchased.
- Transaction and service data
- Transaction amounts and status, subscription activity, invoices, routing and processor information, fraud signals, chargebacks, refunds, customer records, payment-method metadata, token references, and related data processed through the Services.
- Payment information
- Payment-card or bank-account information used to pay Payment Kit, and payment-method data processed through the Services. Payment information may be collected or tokenized by Payment Providers and may not be directly accessible to Payment Kit in raw form.
- Device, network, and usage information
- Browser, device, operating system, referring URLs, pages viewed, clicks, timestamps, log data, approximate location derived from IP address, and interactions with websites, applications, emails, and documentation.
- Communications and support information
- Emails, calls, chat messages, support tickets, meeting notes, survey responses, and other communications with Payment Kit.
- Security and compliance information
- Fraud indicators, identity or business verification information, sanctions screening results, security events, audit logs, and information needed to satisfy legal, Payment Provider, or card-network requirements.
- Inferences
- Preferences, interests, likely product needs, and inferences derived from business and usage information.
3. Sources of personal information
- You, including when you create an Account, request a demo, contact support, attend an event, sign a contract, or communicate with us.
- Your employer, colleagues, Account administrators, customers, or other persons who provide information to us.
- Our customers, when they submit or generate data through the Services.
- Payment Providers, integration partners, resellers, referral partners, data providers, and service providers.
- Our websites, applications, APIs, cookies, pixels, SDKs, logs, and similar technologies.
- Public sources, business directories, professional networks, and government records.
4. How we use personal information
- Provide, operate, administer, secure, support, and improve the Business Services and Services.
- Create and manage Accounts, authenticate users, and administer permissions.
- Process orders, subscriptions, invoices, and payments owed to Payment Kit.
- Enable subscription billing, payment routing, retries, dunning, analytics, fraud-management, tokenization, migrations, reporting, and integrations for customers.
- Communicate about Accounts, transactions, support, incidents, updates, and contractual matters.
- Respond to inquiries, provide demonstrations, and manage sales and customer relationships.
- Personalize content and measure website, product, documentation, and communication performance.
- Detect, investigate, prevent, and respond to fraud, abuse, unauthorized access, security incidents, and violations of our agreements.
- Comply with law, legal process, tax and accounting requirements, Payment Provider and card-network obligations, and enforce our rights.
- Conduct analytics, research, product development, benchmarking, and business planning using aggregated or de-identified information where appropriate.
- Market Payment Kit and related offerings, subject to applicable law and your choices.
- Complete a merger, financing, acquisition, reorganization, sale, or other corporate transaction.
5. Legal bases for processing
Where the GDPR, UK GDPR, or similar laws apply, we rely on one or more of the following legal bases: performance of a contract; steps requested before entering into a contract; compliance with legal obligations; legitimate interests such as operating and securing our business, improving products, preventing fraud, and business-to-business marketing; consent where required; and establishment, exercise, or defense of legal claims.
6. How we disclose personal information
- Affiliates and personnel that need information to operate our business.
- Hosting, infrastructure, security, communications, analytics, customer-support, AI, electronic-signature, billing, identity-verification, professional-services, and other vendors that process information for us. A current list of subprocessors used to process Customer Personal Data is available at https://paymentkit.com/legal/subprocessors.
- Payment Providers and integration partners selected or enabled by a customer, as needed to provide the Services.
- Professional advisers, auditors, insurers, financing sources, and potential transaction counterparties subject to appropriate obligations.
- Government authorities, regulators, courts, law enforcement, and other parties when required by law or reasonably necessary to protect rights, safety, security, or prevent fraud.
- A buyer, successor, or other party in connection with a corporate transaction.
- Other parties at your direction or with your consent.
8. Data retention
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide Services, maintain business and financial records, comply with legal and Payment Provider requirements, resolve disputes, enforce agreements, and protect security. Retention depends on the nature and sensitivity of the information, the purposes of processing, contractual commitments, applicable limitation periods, and legal obligations.
Customer Data processed on behalf of a customer is retained and deleted in accordance with the applicable agreement and Data Processing Addendum. Unless otherwise agreed, Payment Kit’s standard post-termination retrieval period is thirty (30) days, subject to legal retention, inaccessible backups, and archival records.
9. Security
We maintain administrative, technical, physical, and organizational safeguards designed to protect personal information. Measures include access controls, encryption and tokenization where appropriate, logging and monitoring, secure development practices, incident response, personnel confidentiality, vendor-management controls, and resilience measures. Payment Kit maintains PCI DSS Level 1 compliance for the systems and services within its applicable PCI scope. No security method is guaranteed to be completely effective, and users and customers remain responsible for protecting their credentials, devices, systems, and integrations.
10. International data transfers
Payment Kit is based in the United States, and personal information may be processed in the United States and other countries where we or our vendors operate. These countries may have privacy laws different from those where you live. Where required, we use recognized transfer mechanisms, such as adequacy decisions, the European Commission Standard Contractual Clauses, and the United Kingdom International Data Transfer Addendum, together with supplementary measures where appropriate. We do not claim participation in the EU-U.S. Data Privacy Framework unless and until Payment Kit is listed as an active participant.
11. Your privacy rights
Depending on your location and applicable law, you may have rights to request access, correction, deletion, portability, restriction, or objection; opt out of certain sales, sharing, targeted advertising, or profiling; withdraw consent; and appeal a denied request. You may also have the right to complain to a privacy regulator.
To submit a request regarding information Payment Kit controls, contact privacy@paymentkit.com. We may verify your identity and authority. Authorized agents may submit requests where permitted by law, subject to verification. We will not discriminate against you for exercising a legally protected right.
If your request concerns personal information that Payment Kit processes on behalf of one of our customers, please contact that customer directly. We will assist the customer as required by our agreement and applicable law.
12. Marketing choices
You may unsubscribe from marketing emails using the link in the message or by contacting us. You may still receive transactional, security, account, legal, and service communications. Cookie and targeted-advertising choices are described in the Cookie Policy.
13. Children
The Business Services are not directed to children, and we do not knowingly collect personal information directly from children under eighteen (18). If you believe a child has provided personal information directly to us, contact privacy@paymentkit.com.
14. Sensitive information
Unless expressly agreed in writing, the Business Services are not intended for protected health information subject to HIPAA, special-category personal data under GDPR, biometric identifiers, precise geolocation, government identification numbers, or other highly sensitive information. Customers are responsible for avoiding submission of such information unless required protections and agreements are in place.
15. California and other U.S. state privacy disclosures
The table below provides a general notice of the categories of personal information we may collect, the purposes for which we use them, and categories of recipients. The specific categories applicable to an individual depend on the relationship and interaction with Payment Kit.
- Identifiers; customer records; professional information
- Purposes: Provide Services; account administration; communications; billing; sales; security; compliance
- Recipient categories: Affiliates; service providers; Payment Providers; advisers; authorities; transaction parties
- Commercial information
- Purposes: Orders; subscriptions; invoicing; customer relationship management; analytics
- Recipient categories: Service providers; advisers; transaction parties
- Internet or electronic activity
- Purposes: Security; authentication; website and product analytics; troubleshooting; marketing where permitted
- Recipient categories: Hosting, security, analytics, communications, and marketing providers
- Geolocation data (approximate)
- Purposes: Security; localization; fraud prevention; analytics
- Recipient categories: Security, analytics, and infrastructure providers
- Audio, electronic, or communications information
- Purposes: Support; training; quality; records; dispute resolution
- Recipient categories: Communications and support providers; advisers
- Inferences
- Purposes: Product improvement; personalization; sales and marketing
- Recipient categories: Analytics, CRM, and marketing providers
- Sensitive personal information, if provided and legally permitted
- Purposes: Payment security; account access; legal or compliance purposes; providing requested Services
- Recipient categories: Payment Providers; security and verification providers; authorities as required
We retain each category for the period reasonably necessary for the purposes described above, considering legal, contractual, security, operational, and dispute-resolution needs. We do not use sensitive personal information to infer characteristics about individuals except as permitted by law. We do not knowingly sell or share personal information of consumers under sixteen (16).
16. Changes to this policy
We may update this Policy from time to time. We will post the revised Policy and update the Effective Date. If changes materially affect how we use personal information, we will provide additional notice where required by law.
17. Contact us
Payment Kit LLC, Attn: Privacy, 1111B S Governors Ave STE 47765, Dover, DE 19904.
Email: privacy@paymentkit.com
Privacy and international data-protection inquiries: legal@paymentkit.com