Your data, handled like settlement money.

We built BazPay for low-risk EU merchants who need a clean audit trail. Privacy works the same way here. This page says what we collect and why. It also says how long we keep it. No hidden clauses.

Updated · Applies to bazpay.com and the merchant dashboard

Three registers. Every field has a reason.

Each row names the data, the purpose and the legal basis. If a field is not listed, we do not collect it.

Merchant account 01

Data we hold about your business

You give us this at sign-up. We need it to open an account and to meet know-your-customer rules.

Identity
Company name, registration number, VAT number
Onboarding
People
Director and beneficial-owner details
5AMLD duty
Contact
Work email, phone, billing address
Contract
Settlement
Bank account and IBAN for payouts
Contract

Anti-money-laundering law sets the retention here. We keep these records for five years after the account closes.

Transactions 02

Data that moves through the gateway

This is shopper data. You are the controller for it. We process it only to run the payment you asked for.

Token
Vaulted card reference, never a raw card number
Gateway scope
Order
Amount, currency, order reference, timestamp
Contract
Risk
Device fingerprint, IP country, velocity signals
Fraud duty
Outcome
Issuer response, decline reason, dispute status
Scheme rules

Card numbers are typed into hosted fields on a BazPay origin. They never reach your servers or ours in clear form.

This website 03

Data the site itself collects

The public site is deliberately quiet. It ships no behavioural tracking and no third-party media.

Essential
Session and consent cookies only
Strictly needed
Analytics
Loaded only after you accept
Consent
Forms
Name, work email, message you send us
Legitimate interest
Logs
Server logs with truncated IP addresses
Security

Reject the banner and nothing but the essential cookies runs. The page still works in full.

Card data stays inside our estate.

PCI DSS Level 1 is managed on the gateway side. Your checkout renders our hosted fields, so a card number never lands in your code. That keeps your annual return at SAQ A. It also keeps the breach surface with us, where the controls are audited.

Personal data is stored in the European Union. We do not move it elsewhere for convenience. Where a sub-processor is needed, we name it and bind it by contract.

Read the matching commercial terms in our terms of service, or the cookie detail in our cookie policy.

data residency EU only
Hosting
EU regions only
Frankfurt · Amsterdam
Backups
Encrypted, EU-resident
35-day window
Sub-processors
Listed on request, EU or adequacy
SCCs where needed
Card vault
Inside our PCI DSS Level 1 estate
No export

Retention in one line. Transaction records live for ten years under tax and scheme rules. Risk signals are pruned at thirteen months. Web logs are cut at ninety days.

Six things you can ask us to do.

Send one email. We answer within a month. If a request needs longer, we tell you why before that month ends.

  1. 01

    See your data

    Ask for a copy of everything we hold about you. We reply within one month.

  2. 02

    Fix it

    Tell us what is wrong and we correct it. Records downstream are updated too.

  3. 03

    Erase it

    We delete what no law forces us to keep. We say clearly what must stay.

  4. 04

    Take it with you

    Get your data as a machine-readable file. Vault tokens migrate as well.

  5. 05

    Object or restrict

    Ask us to pause a use you disagree with while we review it.

  6. 06

    Complain

    Raise it with your national data protection authority at any time.

Questions about this policy?

Write to our data team. Say what you need and name your merchant account if you have one. We will confirm receipt, then answer in writing. Requests are free.