Privacy Policy

Privacy Policy

This Policy describes how HavenPay collects, uses, shares, and protects Personal Data for website visitors, merchants, and—where we act as processor—end customers whose data you submit for payment processing.

Effective 22 September 2026Governing law: England and WalesOperator: HavenPay (the operator of havenpay.io)

1.Introduction

This Privacy Policy explains how HavenPay (the operator of havenpay.io) (“HavenPay”, “we”, “us”) collects, uses, discloses, and protects Personal Data when you visit https://www.havenpay.io, create a merchant account, use our dashboard or APIs, or otherwise interact with our Services.

We process Personal Data in accordance with applicable law, including the UK GDPR, the EU General Data Protection Regulation (Regulation (EU) 2016/679), the Data Protection Act 2018, and, where relevant, other local privacy laws such as the California Consumer Privacy Act (CCPA/CPRA).

This Policy should be read with our Terms of Service and Cookie Policy. Capitalised terms not defined here have the meaning in those documents.

2.Who is responsible for your data

For Personal Data about website visitors, prospective customers, and merchant account users that we collect for our own purposes (account administration, security, billing, marketing where permitted), HavenPay is the data controller (or “business” under CCPA).

When we process Personal Data of your end customers solely to provide payment processing and related Services on your instructions, we act as a data processor (or “service provider”). You remain the controller of that customer data and must ensure you have a lawful basis to share it with us.

Our privacy contact is privacy@havenpay.io. Where appointed, our Data Protection Officer can be reached at dpo@havenpay.io.

3.Personal Data we collect

We may collect the following categories of Personal Data:

Identity and contact data

  • Name, email address, phone number, job title, and business contact details.
  • Government identifiers and verification documents where required for KYC/KYB (for example passport, company registry extracts, proof of address), processed under strict access controls.

Account and authentication data

  • Login credentials (passwords are stored using one-way hashing; we do not store plaintext passwords).
  • Session tokens, multi-factor authentication status, and security event logs.
  • Role and permission assignments within your merchant organisation.

Business and financial data

  • Legal entity name, trading name, registration numbers, beneficial ownership information, and tax identifiers.
  • Bank account details, payout destinations, and crypto wallet addresses where you enable those features.
  • Transaction metadata, amounts, currencies, status, refunds, Chargebacks, and Ledger entries.

Payment and customer data you submit

  • Customer names, emails, billing/shipping details, and order references you or your integration send to HavenPay.
  • Tokenised payment method references and limited card metadata (for example last four digits, brand, expiry) as returned by Partners. Full cardholder data is handled in accordance with PCI DSS by appropriate environments and Partners; HavenPay is designed so that raw PAN/CVV are not stored in merchant application databases where Partners handle capture.

Technical and usage data

  • IP address, device and browser type, operating system, referring URLs, pages viewed, and approximate location derived from IP.
  • API request logs, webhook delivery attempts, error diagnostics, and performance metrics.
  • Cookie and similar technology data as described in the Cookie Policy.

Communications

  • Support tickets, email correspondence, call recordings where notified, and survey responses.

4.How we collect Personal Data

  • Directly from you when you register, verify your business, configure payouts, contact support, or update settings.
  • Automatically through cookies, logs, and analytics when you use the website or Services.
  • From your authorised users, developers, and systems that call our APIs.
  • From Partners, card schemes, banks, identity verification providers, fraud and sanctions screening providers, and publicly available registries.
  • From cookies and similar technologies placed by us or carefully selected third parties, subject to your consent where required.

5.Purposes and legal bases

Under UK/EU data protection law, we rely on one or more of the following legal bases: performance of a contract; legitimate interests (balanced against your rights); legal obligation; and consent where required (for example certain marketing cookies or optional marketing emails).

Provide and operate the Services

Create and manage accounts, process Payments, maintain the Ledger, initiate Payouts, deliver webhooks, and provide customer support. Legal basis: contract; legitimate interests.

Security, fraud prevention, and compliance

Authenticate users, detect abuse, investigate suspicious activity, enforce Acceptable Use, meet AML/CTF and sanctions obligations, and respond to lawful requests. Legal basis: legal obligation; legitimate interests; contract.

Improve and develop products

Analyse aggregated usage, fix bugs, and develop features. Where possible we use de-identified or aggregated data. Legal basis: legitimate interests.

Marketing and communications

Send service announcements, security alerts, and (where permitted) product updates or marketing. You may opt out of marketing at any time. Legal basis: legitimate interests or consent, as applicable.

Legal claims and corporate transactions

Establish, exercise, or defend legal claims; and process data in connection with mergers, acquisitions, or financing, subject to appropriate safeguards. Legal basis: legitimate interests; legal obligation.

6.When we share Personal Data

We do not sell Personal Data. We may disclose Personal Data to:

  • Licensed Partners that acquire payments, hold funds, convert currency, or facilitate crypto payouts.
  • Service providers acting on our instructions (hosting, email delivery, analytics, customer support tools, identity verification, fraud scoring), under contractual confidentiality and data protection terms.
  • Professional advisers (lawyers, auditors, insurers) under confidentiality obligations.
  • Authorities, regulators, courts, or schemes where required by law or to protect rights, safety, and integrity of the payment ecosystem.
  • A buyer or successor in the event of a merger, acquisition, or sale of assets, with notice where required.
  • Other parties with your direction or consent (for example connected apps you authorise).

7.International transfers

We may transfer Personal Data to countries outside the UK/EEA. Where we do so, we implement appropriate safeguards such as the UK International Data Transfer Agreement / Addendum, EU Standard Contractual Clauses, adequacy regulations, or other lawful transfer mechanisms, together with technical and organisational measures.

You may request information about relevant transfer safeguards by contacting privacy@havenpay.io.

8.Retention

We retain Personal Data only as long as necessary for the purposes described, including to meet legal, accounting, AML, Chargeback, and audit requirements.

  • Account and KYC records: typically for the life of the account plus a minimum of five (5) to seven (7) years after closure, or longer if required by financial crime law.
  • Transaction and Ledger records: generally at least five (5) to seven (7) years to support disputes, tax, and regulatory obligations.
  • Support correspondence: typically up to three (3) years unless needed longer for a dispute.
  • Marketing preferences and cookie consent logs: for the period needed to demonstrate compliance, then deleted or anonymised.
  • Server and security logs: retained for shorter operational periods unless escalated into an investigation.

9.Security measures

We implement technical and organisational measures designed to protect Personal Data against unauthorised access, alteration, disclosure, or destruction. These include encryption in transit, access controls and least-privilege roles, password hashing, session management, rate limiting, audit logging of sensitive actions, network protections, and vendor due diligence.

No method of transmission or storage is completely secure. You must also protect your credentials, devices, and API keys. Notify us immediately of suspected breaches affecting your account.

10.Your rights

Depending on your location, you may have rights to access, rectify, erase, restrict, or object to processing; to data portability; to withdraw consent; and to lodge a complaint with a supervisory authority (in the UK, the Information Commissioner’s Office).

California residents may have rights to know, delete, correct, and opt out of certain sharing, and not to be discriminated against for exercising privacy rights. We do not sell Personal Data as defined by the CCPA/CPRA.

To exercise rights, email privacy@havenpay.io with sufficient detail to verify your identity and locate your data. We may decline requests that are manifestly unfounded, excessive, or where an exemption applies (for example legal retention or anti-fraud obligations).

If we process your data as a processor for a merchant, we may redirect your request to that merchant as the controller.

11.Children

The Services are not directed to individuals under 18. We do not knowingly collect Personal Data from children. If you believe a child has provided Personal Data, contact us and we will take appropriate steps to delete it.

12.Automated decision-making

We and our Partners may use automated tools for fraud scoring, sanctions screening, and risk holds. These tools may affect whether a Payment is accepted or a Payout is delayed. You may contact us to request human review where required by applicable law.

13.Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date will change, and material updates may be notified by email or dashboard notice. Continued use of the Services after an update constitutes acceptance where permitted by law.

14.Contact

Privacy requests: privacy@havenpay.io. Data Protection Officer: dpo@havenpay.io. Legal notices: legal@havenpay.io.