This Privacy Policy explains how PayNest, Inc. (“PayNest”, “we”, “us”) collects, uses, discloses and safeguards personal data when you visit our website, create an account, or use our payment services (together, the “Services”). We are committed to processing personal data in accordance with applicable data-protection laws, including the EU and UK General Data Protection Regulations (GDPR) and other regional requirements.
1. Who we are
PayNest is the data controller for personal data processed about visitors and account holders. For payment transactions processed on behalf of our business customers, PayNest generally acts as a data processor, and the customer is the controller. If you have questions about a specific processing activity, contact us at sales@paynest.online.
2. Data we collect
- Account data: name, work email, company, and role when you register or contact us.
- Transaction metadata: amounts, currency, gateway, status and timestamps needed to provide payment orchestration, reconciliation and reporting.
- Technical data: IP address, device and browser information, and log data collected for security and reliability.
- Usage data: pages viewed and actions taken, where analytics are enabled and you have consented.
We do not store full payment card numbers on our systems. Card data is tokenized and handled by PCI-compliant gateway partners.
3. How we use data
- To provide, operate, secure and improve the Services.
- To authenticate users and prevent fraud and abuse.
- To communicate about your account, support requests and service updates.
- To comply with legal, tax, accounting and regulatory obligations.
4. Legal bases
Where GDPR applies, we rely on: performance of a contract (to deliver the Services), legitimate interests (to secure and improve the Services), consent (for optional analytics and marketing), and legal obligation (for financial and compliance record-keeping).
5. Sharing
We share personal data with payment gateways and financial partners as needed to process transactions, with service providers who support our infrastructure under contract, and with authorities where required by law. We do not sell personal data.
6. International transfers
Where data is transferred across borders, we use appropriate safeguards such as Standard Contractual Clauses and equivalent mechanisms recognized under applicable law.
7. Retention
We keep personal data only as long as necessary for the purposes described here or as required by law (for example, financial records are retained for statutory periods).
8. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, and to data portability. To exercise these rights, email sales@paynest.online. You may also lodge a complaint with your local supervisory authority.
9. Security
We apply technical and organizational measures including encryption in transit and at rest, access controls, and audit logging. No method of transmission or storage is completely secure, but we work continuously to protect your data.
10. Changes
We may update this policy from time to time. Material changes will be posted here with an updated effective date.
11. Contact
Questions about this policy? Email sales@paynest.online or use our contact page.