LEGAL

Privacy policy

This policy explains what information we hold when you use Amelia X Payments as a merchant, and what happens to the customer details attached to a payment.

Information we collect

Account data: your name, email address, business name, trading name, contact person, phone number, country and website.

Payment data: amounts, currency, description, your own reference, payment status, provider reference, timestamps and, where you supply them, a customer name and email address on a payment link.

Technical data: webhook events from providers, API key usage, audit records of sensitive actions, and error logs.

We do not collect raw card numbers, CVV codes or PINs. Those are handled by the payment provider.

How we use it

To operate your account, create and process payments through providers, show your transactions and refunds, verify webhooks, prevent fraud and abuse, meet legal obligations, and provide support.

Who we share it with

The payment provider processing a given payment receives the data needed to process it. We also use infrastructure providers for hosting, database and email delivery. We do not sell personal information.

Security

Access is authenticated, and database access is restricted per merchant so that you can only read your own profile, links, transactions, refunds, keys, webhooks and tickets. Provider credentials and webhook secrets are stored server-side and are never exposed to the browser. Sensitive values are not written to logs.

Retention and your rights

We keep transaction and audit records for as long as needed to run the service and satisfy legal and provider requirements. You may ask us to access, correct or delete your personal information, subject to those requirements.

Customer data you supply

When you add a customer name or email to a payment link, you are responsible for having a lawful basis to share it and for your own privacy notice to your customers.

Contact

Privacy requests can be raised through our support page.