Umbrella Privacy Notice for Payments entities
Privacy informing notice for Verifone's Payments entities
This Privacy Notice ("Notice") describes what personal data VeriFone, Inc. and its direct and indirect parent and subsidiary companies (collectively, "Verifone", "Company", "us", or "we") collect, record, store, use and process and how, and it applies to us as long as we process personal data that belongs to individuals ("you").
This Notice describes how Verifone processes personal data in connection with the services covered by this Notice and reflects Verifone's approach to applicable data protection and privacy requirements.
Verifone seeks to apply consistent privacy and data protection standards across its global operations, subject to applicable local laws and operational requirements for all Verifone entities, subsidiaries, branches, representative offices, and affiliates worldwide, regardless of geographical location, market typology or target customer. The list of Verifone's companies is available here.
Verifone may provide separate privacy notices that apply to specific products or services that we offer, in which case this Notice does not apply. Where this Notice applies, Verifone may provide additional or supplemental privacy notices to individuals at the time we collect their data, which will govern how we may process the information provided at that time. We may alter this Notice as needed for certain products or services.
Important Note!!!
Certain services provided by Verifone Payments entities are subject to anti-money laundering regulations and other legal obligations applicable to financial institutions. In compliance with these requirements, we may be required to perform Know Your Customer ("KYC") checks on our merchants and assess the risk profiles of shoppers who intend to use specific Verifone Payments services. These checks are essential to ensure the security and integrity of financial transactions and to prevent fraudulent activities.
Please note that your personal data may be transferred outside your country of residence to comply with international regulations. Additionally, if potential risks or concerns are identified, further due diligence may be carried out, and appropriate measures will be implemented as required by law.
For Shoppers: Verifone conducts fraud prevention activities related to online payments, which may include monitoring transaction data, verifying payment details, and applying risk scoring mechanisms to detect suspicious activity. These fraud prevention measures are carried out on the basis of our legitimate interest in detecting and preventing fraudulent transactions. They are legally distinct from the anti-money laundering obligations.
For Merchants and Business Partners (e.g., affiliate marketers, selling partners): Verifone processes personal data in accordance with legal obligations, including the collection of additional information to verify identity, business ownership, financial history, or transaction patterns. This information may also be shared with third-party service providers to facilitate these checks and fraud prevention activities.
Important restriction on your right to be informed in AML contexts: Where Verifone is legally required to file a suspicious activity report with the competent financial intelligence authority, we are prohibited by law from informing you that such a report has been or may be made. This restriction on your right to be informed is grounded in privacy and anti-money laundering applicable legislation. It applies for as long as the legal prohibition remains in force.
We encourage you to carefully review the agreements and terms & conditions to fully understand how Verifone's services, products, and platforms are structured and configured for use.
UNDERSTANDING THIS NOTICE AT FIRST GLANCE
Below, you can find details about how your personal data is processed. You have the option to quickly review this Privacy Notice using the Overview or read the Full Privacy Notice for more comprehensive information.
OVERVIEW
To make this Privacy Notice more accessible, we've created a quick overview for easy reference. If you need detailed information on specific topics, simply click on the links provided for each section.
This Privacy Notice applies to personal data we collect from the following:
- Individuals interacting with Verifone as customers, users, or visitors, whether directly or through our platforms.
- Contact persons of corporate customers and partners, acting in their professional capacities.
- Visitors to our websites, online portals, and apps.
For more details, refer to Section I. - Introduction.
The name of the relevant data controller is mentioned in Section XII. - Contact.
By utilizing our services and platforms or accessing our websites, the following categories of personal data will be processed:
- Identification and contact data: name, email, phone number, billing/shipping address.
- Financial and transaction data: payment details, purchase history, bank information.
- Usage data: information on how you interact with our websites, including IP address, browser type, and activity logs.
- Communication data: any information you provide in emails, support requests, or social media interactions.
- Marketing data: insights gathered from marketing interactions, including preferences and feedback.
For more details, refer to Section II. - Categories of personal data we process
The data collected will be utilized to:
- Fulfill our contractual obligations, such as processing orders and providing customer support.
- Comply with legal requirements, including verifying your identity and preventing fraud.
- Improve our products and services based on user feedback and usage patterns.
- Send marketing communications, if you have given us consent.
Additionally, further information on the processing of sensitive data, including KYC & AML processing activities, automated decision-making, and related processes, is available for clarification in Section III. - Personal data processing activities, Section IV. - Children's privacy and Section IX - Using of cookies and other tracking technologies
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Notice. This includes meeting our legal, regulatory, or contractual obligations. After the retention period expires, your data will either be securely deleted or anonymized.
For more details, refer to Section VII. - Data retention.
All personal data processed is shared with authorized personnel, other Verifone companies, and third parties such as service providers, contractors, and legal authorities to support operational needs, and legal compliance. Data may also be transferred internationally with safeguards in place to ensure protection.
For more details, refer to Section V. - Who we share your data and why? and Section X. Where your personal data is held.
As a data subject, you are entitled to several privacy rights, including access to your personal data, rectification, erasure (in certain cases), data portability, and the ability to restrict or object to data processing. These rights may vary depending on the jurisdiction (e.g., EU/EEA, UK, US, Brazil, Turkey). You also have the right to lodge complaints with local data protection authorities. To exercise these rights, please contact Verifone at privacy@verifone.com.
To withdraw your marketing consent or unsubscribe from marketing communications, the necessary details can be found in this section.
For more details, refer to Section VIII. - About your privacy rights
If you have any questions or concerns, you can contact Verifone's Data Protection Officer (DPO).
The Privacy Notice is updated regularly.
For more details, refer to Section XI. - Amendments and Section XII. - Contact.
FULL PRIVACY NOTICE
And from here, you can continue to read the full Privacy Notice.
I. Introduction
Applicability of this Notice
This Notice applies to all Verifone Payments entities mentioned below and fully detailed in Section XII. - Contact:
- All past, present and prospective customers and end-users who are individuals[1]. This includes one-person businesses, legal representatives or contact persons acting on behalf of our corporate customers.
Non-Verifone customers. These could include anyone who visits a Verifone's websites and platforms. Whether you are using the websites/platforms mentioned above for free or as a paid service, please note that their use is governed by our Terms & Conditions of Website Use.
This Notice does not apply to Verifone's processing of the personal data of its personnel, such as employees and contractors.
1. How we obtain the personal data?
We obtain your personal data in the following ways:
- Directly from you during our interactions. This includes data you provide when you become a customer, register for our online services, complete forms, sign a contract with us, use our products or services, contact us through one of our channels.
- Indirectly from your employer (when you may act as a legal representative, authorized personnel or contact person of your employer). From third-party partners (including identity and verification providers or screening partners such as credit reference agencies), affiliates, or from publicly available sources.
- Automatically when we collect certain information using cookies and similar technologies when you browse our websites.
We process your personal data using both manual and automated methods. Where decisions are made using automated means (e.g., including fraud scoring, creditworthiness assessment, and transaction monitoring) those decisions may be taken automatically without prior human review. Where automated decision-making produces a result that significantly affects you, you have the right to request human review of that decision. Further details are set out in Section 6 below.
II. Categories of personal data we process
2. What is personal data?
Personal data refers to any information that identifies or can be linked to an identifiable natural person. Personal data we process about you includes:
- Identification data: your name, date and place of birth, ID number, title/position/role, nationality and a specimen signature, fiscal code/social security number, proxy data (including any associated legal documentation or authorization), access credentials. In the same way, we may be required to collect your age where the applicable law imposes an age limit.
- Contact details: e-mail address, phone number, billing/shipping address.
- Know your customer data as part of customer due diligence: such as business information, ownership, and control information, identity information, including ID, financial data, information required for Know Your Customer (KYC) obligations, utility bills, credit, litigations and financial history, to prevent fraudulent conduct or behaviour that contravenes international sanctions and to comply with regulations against money laundering, terrorism financing and tax fraud.
- Underwriting data: business information, ownership, and control information, identity information, including ID, financial data, information required for Know Your Customer (KYC) obligations, utility bills, credit, litigations and financial history, full name of the business owner, date of birth of the Merchant/business owner, physical address, e-mail address, phone number, SSN (social security number) or TIN (taxpayer identification number), bank information (bank name, account number, routing number), business registration details (legal name, commercial name, registration number, date and place of registration), website URL. This process might also include both processing of sensitive personal data, namely information on criminal convictions and offenses and politically-exposed persons.
- Anti-fraud data: transaction data (details of financial transactions including date, time, amount, location, and parties involved), user information (personal and account information such as name, address, contact details, account numbers), device and location information (data related to the device used for transactions and the geographic location to assess the legitimacy of transactions), authentication and authorization data (information about authentication methods, login attempts, and authorization processes to ensure secure access to accounts and services).
- Supplier data: information related to individuals or entities that provide goods or services to Verifone. This data may include contact details, financial information, contractual agreements, performance metrics, and any other relevant information necessary for managing the relationship between Verifone and its suppliers.
- Transaction and financial data: such as the credit or debit card number, bank account information, or payment card image, location, purchase amount, date of purchase, information about the purchased items, past purchases, (auto)renewal, chargeback, and refunds.
- Computer data collected during the checkout process such as the IP address, browser type, device type, timestamps, operating system, logs activity and reports, mobile device identifier, and geographical location.
- Communication data and, in particular, information we collect through various forms of interaction with you including support tickets, emails correspondences, and social media engagements and interactions, when you register for, attend, or participate in industry events, and any personal data you post on forums and discussion groups (in line with legal restrictions).
- Marketing data: and, in particular such as demographic information, purchase history, and engagement metrics across our websites, emails and social media platforms, capturing insights into customer interactions, preferences, and responses to our content, social media commentary, customer feedback through surveys and support tickets, and visual or textual content shared by users.
- Usage of our website(s) & platforms: and, in particular information related to your usage, such as the type of device you use, including its unique device identifiers, IP address, operating system version, device settings, location, log data detailing the time and duration of your website visits, search data, and cookie-stored information that uniquely identifies your browser or account.
- Audio-visual data: where applicable and legally permissible, we process (i) phone or video calls or chats with our sales or customer care agents, (ii) recordings of business meetings and training sessions involving us (e.g., screen recording, remote access). These recordings are used to safeguard our premises, verify telephone orders, prevent fraud or train staff.
- Sensitive data: we recognize the sensitive nature of certain personal data categories, such as race, ethnic origin, political opinions and information on criminal convictions and offenses. Our processing of such sensitive data is limited and occurs only when strictly required by law. We adhere to the rigorous legal standards governing the handling of this information and implement stringent security measures to protect it. Generally, our policy is to avoid processing sensitive personal data unless it is necessary for legal compliance or specific purposes where enhanced data protection measures are mandated.
- Authentication, authorization & security data: Personal data processed to authenticate users and systems, manage access rights and permissions, secure products and services, monitor security events, maintain audit trails, administer user accounts, detect fraud and unauthorized access, and comply with applicable security and regulatory requirements. This includes authentication credentials, session identifiers, authentication and authorization records, API credentials, access permissions, audit logs, security logs, and other security-related information associated with identifiable individuals.
- Any other data you may provide to us: for example in connection with complaints or requests data, such as details of the complaint and/or request and any supporting documentation or evidence relevant to the complaint and/or request, such as identification data, emails, screenshots, photographs, witness statements, etc. Verifone does not exert control over the quantity or quality of the data you choose to share. Consequently, you bear full responsibility for providing accurate and strictly necessary information. In the same way, we may be required to collect your age where the applicable law imposes an age limit.
III. Personal data processing activities
3. What does processing of personal data mean?
Processing of personal data refers to any activity that can be carried out in connection with personal data, such as collecting, recording, storing, adjusting, organising, using, disclosing, transferring or deleting it in accordance with applicable privacy laws.
4. Scope and purpose of personal data processing activities
The following processing activities are conducted in accordance with applicable laws, regulations, best practices, and standard industry procedures. This ensures we fulfill our legal obligations, protect our legitimate interests, and maintain effective business operations. We only use your personal data for:
- Performing agreements to which you are a party or taking steps prior to entering into these agreements. We use your personal data when you enter into an agreement with us, or when we have to execute our obligations under these agreements.
- Processing your personal data when you create, access or use a Verifone account, platform, portal, application or other online service. We use this information to authenticate you, administer your account, manage roles and permissions, maintain user sessions, provide the requested functionality, record relevant account and platform activity, troubleshoot issues, prevent unauthorized access, maintain audit trails and protect our systems and services.
- Maintaining and updating payment credentials. Depending on the payment service, payment method, card scheme and applicable market, we may receive, update, exchange or otherwise process payment credentials and related account information through account updater, credential lifecycle management or similar services. We use this information to maintain accurate payment credentials, facilitate authorized recurring, card-on-file or other eligible transactions, reduce failed transactions or payment disruptions and provide the relevant payment services.
The processing is necessary for the performance of your contract concluded with Verifone.
We use your personal data to comply with a range of legal obligations and statutory requirements, including financial services and payments regulations that oblige us to perform or provide:
- Integrity checks: when entering into a customer relationship with you, we have a legal obligation to consult available incident registers and warning systems and national and international sanctions lists.
- Identity verification: when entering into a customer relationship with you, we have a legal obligation to confirm your identity (know your customer check). We can do this by making a copy of your identity document, which we will only use for identification and verification purposes. We may also rely on checks performed by financial institutions to verify your identity. Where KYC verification requires us to process data relating to criminal convictions, offences, or politically exposed person (PEP) status, according to the applicable anti-money laundering legislation, which expressly authorises this processing. Such data is processed strictly to the extent required to fulfil our legal obligations and is subject to enhanced security measures.
- Anti-money laundering and terrorism financing monitoring: we are legally required to monitor transactions and business relationships for indicators of money laundering or terrorism financing, to screen against national and international sanctions lists, and where required by applicable AML legislation, to report suspicious activity to the competent financial intelligence authority. Where a suspicious activity report is filed, we are legally prohibited from informing you of this activity.
- Fraud prevention: we monitor transaction data, device information, and behavioural patterns, and maintain records of fraud incidents and alerts to detect and prevent fraudulent activity. This is a separate activity from AML monitoring and is carried out on the basis of our legitimate interest in protecting the security and integrity of our payment services.
- Regulatory and statutory reports to our regulators as set out in section V. Who we share your personal data with and why?
- Conduct credit reference checks and financial due diligence involves utilizing credit history assessments and other financial evaluations to ensure transparency and integrity in financial transactions. Additionally, we verify creditworthiness and financial stability through rigorous screening procedures.
The processing is necessary to enable Verifone to comply with legal and regulatory obligations to which it is subject.
Business process execution, internal management and management reporting, namely:
- Execute business processes, managing internal operations, generating management reports, handling various tasks related to day-to-day operations, ensuring smooth workflow, and providing insights through comprehensive reporting for informed decision-making.
- Credit checks: before entering into a customer relationship with you, we have a legal obligation to check whether you qualify as an eligible customer. We assess your credentials from a risk perspective and predict if you can meet your financial obligations towards us as set out in the sub-section Automated decision-making and profiling.
- Managing and recovering outstanding debts through contact, repayment plans, and legal actions if necessary and working with third parties (e.g. debt recovery agencies).
- Handling legal claims involving Verifone, including gathering information and working with third parties (e.g. lawyers, accountants, auditors, etc.). Improve, upgrade, and enhance our products or services (including developing new products or services and analyzing our products).
- Undertake internal research for technological development (including performing data analysis and processing, market and consumer research, satisfaction research, trend analysis, and financial analysis).
- Compile statistics or aggregated reports/forms relating to our offerings. We may use your information in an anonymized, de-identified, or aggregated manner that does not enable direct identification of any individual (including for fraud prevention or analytical purposes).
- Measuring and analysing the performance of our websites, platforms and advertising activities. We may process information about your interactions with our websites, platforms and advertisements to understand their use, measure advertising effectiveness and conversions, and improve our services and marketing activities.
The processing is based on Verifone legitimate interests to enhance services and products, ensuring business improvement. When relying on legitimate interest, we ensure that processing remains proportionate and that your interests, fundamental rights and freedoms are respected. If you would like more information about our reasoning behind our assessment in a specific case, please contact us using the details provided in section XII. Contact.
Performing marketing and advertising activities:
- Your personal data may be used to evaluate your profile to determine your eligibility for additional products or services through automated means (see Section 6 for your rights in connection with this), and for interest-based advertising and marketing and to measure the effectiveness and conversion of our marketing and advertising activities. Where permitted by applicable law, we may use cookies, pixels and similar technologies for these purposes. We are committed to not sharing your personal data with third parties for marketing purposes unless explicit permission is granted. We may send you email marketing communications about Verifone and Verifone products or services, invite you to events, or surveys, or communicate for marketing purposes in accordance with applicable law.
The processing is based on your prior and explicit consent.
Where the processing of your personal data is indicated above as contractually necessary for the performance of your contract with Verifone, the collection and provision of this personal data is a prerequisite for the conclusion of your contract with Verifone. Failure to provide such personal data will thus prevent Verifone from entering into such contracts with you.
5. Automated decisions and profiling
Certain services rely on automated processing, including fraud prevention, transaction monitoring, creditworthiness assessment, and cybersecurity monitoring. However, there are specific situations where such activities are necessary, such as fraud monitoring, terrorism financing, anti-money laundering, cybersecurity attacks, security triggers, and creditworthiness assessments. In these cases, certain decisions, including real-time fraud scoring and creditworthiness assessments, may be taken automatically without prior human review, as it is not operationally possible to insert a human review step before every automated decision is made. Where an automated decision produces a result that significantly affects you, such as a declined payment or a refused credit application, you have the right to obtain human review of that decision, to express your point of view, and to contest the outcome. To exercise these rights, please contact us using the details in section XII. Contact.
6. Use of AI
- Use of AI by Verifone's suppliers: In addition to Verifone's own use of AI, some of our third-party suppliers use AI-embedded tools in the services they provide to us. The use of AI-embedded services or products from our suppliers is not under our direct control. However, we take reasonable steps to ensure that supplier AI tools are used in accordance with applicable AI legislation.
- Use of AI by Verifone: Verifone uses AI in certain services and internal processes. This includes virtual assistants and chatbots, automated transaction and fraud monitoring systems, and creditworthiness assessment tools used in connection with payment services. While we strive to deliver accurate and complete information, it is possible that AI may generate false or partial responses. You are responsible for your inputs to the AI service and for deciding whether to act on any outputs. Where AI systems are used in decisions that significantly affect you, such as credit approval or fraud-based transaction decline, you have the right to request human review of that decision, as described in section 5. Automated decisions and profiling. If you encounter any errors in the information provided by our AI services, please contact us using the details in section XII. Contact.
IV. Children's privacy
Our products or services are not directed at children, therefore you might be asked to check the age limit box when visiting our websites and platforms.
In addition, kindly be informed that national laws might have a different age threshold at which a child is generally considered to be competent to provide their own consent to processing.
If we discover that we have accidentally collected personal data from a child, we will remove that child's personal data from our records as soon as reasonably possible. If you believe we have mistakenly or unintentionally collected personal data of a child without appropriate consent, please contact us and we will take steps to delete their personal data from our systems.
V. Who we share your personal data with and why?
There are situations in which we need to provide your personal data to other parties involved in the provision of our services and products.
This could include data transfers within Verifone and to third parties, as follows:
- Within Verifone:
- Individuals who have been granted official permission and clearance by the company to access specific systems, facilities, or information. These individuals are entrusted with responsibilities and tasks essential to the operations and security of Verifone's infrastructure, products or services. They possess the requisite credentials, training, and authorization to carry out their designated roles effectively and in accordance with Verifone's policies and procedures. Authorized personnel may include employees, contractors, or partners who have undergone thorough vetting processes and adhere to strict guidelines to ensure the confidentiality, integrity, and availability of Verifone's assets and data.
- For internal operational needs and in instances of business restructuring, we may share data with our affiliates. We ensure that your data is used consistently with this Notice. A list of our current group companies locations is available here.
- With third parties:
- Government, supervisory and judicial authorities according to legal obligation that we have, including disclosing of personal data upon official requests.
- Service providers, independent contractors and business partners who assist in delivering our products or services. A list of our main processors is available here.
- Upon your consent: we will share your personal data with other entities when we have your explicit consent to do so.
We might use or share information that has been aggregated or de-identified so that it cannot reasonably be used to identify an individual. We may use or share this information in several ways, including for fraud prevention services or for analytical purposes.
If our business, assets, or operating divisions are acquired by one of our corporate affiliates or a third party (like in a sale, merger, or reorganization), your personal data will be processed by that company, unless local laws state otherwise. In such circumstances, the acquiring entity assumes the role of data controller and this Notice, together with any applicable privacy preferences you have expressed, will continue to apply until updated.
VI. How we protect your personal data
At Verifone, safeguarding your personal data is our priority. We employ a combination of appropriate organizational, technical, and physical measures designed to protect your personal data from unauthorized access, destruction, alteration, or disclosure.
We apply an internal framework of policies and minimum standards across all our businesses to keep your personal data safe. These policies and standards are periodically updated to keep them aligned with applicable regulatory requirements, evolving security risks, technological developments, and recognized industry practices. Our security practices are informed by recognized industry standards, frameworks, and assurance principles, including, where relevant, ISO/IEC 27001 and related information security standards and SOC security and assurance principles. References to these standards and principles describe the practices that inform our security approach and do not, by themselves, represent that Verifone's services are certified or independently attested against a particular standard. In addition, Verifone employees are subject to confidentiality obligations. To help us continue to protect your personal data you should always contact Verifone if you suspect that your personal data may have been compromised.
Our security infrastructure includes advanced technologies like encryption in transit, firewalls, CAPTCHA, access control, authentication mechanisms, monitoring, and digital certificates. Additionally, where applicable to the relevant environment or service, Verifone maintains controls designed to meet applicable Payment Card Industry Data Security Standard (PCI DSS) requirements. While we strive to secure your personal data, it's important to acknowledge that no system can guarantee absolute security, especially over the internet. However, we are dedicated to continuously enhancing our security protocols and responding promptly to potential threats.
Because submissions of information over the internet are never entirely secure, we cannot guarantee the security of information you submit via the Internet. We nonetheless implement appropriate technical and organisational measures to protect your personal data during transmission, in accordance with our obligations under applicable data protection law.
VII. Data retention
At Verifone, we retain your personal data only as long as necessary to fulfil the purposes for which it was collected, and generally for the duration of your contract with Verifone, if any. Your personal data may be kept for longer retention periods in archives for documentary and/or evidentiary purposes or in accordance with legal or regulatory retention periods.
Once the retention period is met, we will either securely delete or anonymize it. In cases where deletion is not immediately possible, such as when the personal data is in backup archives, we ensure it is securely stored and isolated from further processing until deletion is feasible.
VIII. About your privacy rights
7. Your privacy rights
If your personal data is processed, you have rights. Based on applicable laws, your personal data protection rights may vary from jurisdiction to jurisdiction.
Please be advised that while this Notice specifically outlines data subject rights within the EU/EEA, UK, USA, Turkey and Brazil, it's possible that you may have additional data subject rights based on the laws of your country. If this applies to you, please contact us so that we can accommodate and address any data subject rights recognized by your national privacy legislation.
Your feedback and cooperation are essential in ensuring compliance with relevant regulations and upholding your privacy rights.
(EU Member States and Switzerland, Norway, Iceland, Liechtenstein)
- Right to be informed about the collection and use of your personal data.
- Right to access and request copies of your personal data.
- Right to rectification and to request inaccurate or outdated personal data be updated or corrected.
- Right to be forgotten/Right to erasure, namely the right to request the deletion of your personal data. Note that this is not an absolute right. It can only be granted if one of the grounds provided for in Article 17 of the GDPR applies. Furthermore, Verifone may not respond favorably to a request for deletion in certain cases. This will be the case, for example, if Verifone is required to retain personal data in order to comply with a legal or regulatory obligation or if the processing of your personal data is necessary to establish, exercise or defend legal claims.
- Right to data portability, namely, to ask for your personal data to be provided to you in a structured, commonly used and machine-readable format or transferred to another controller. Note that this right only applies to the processing of personal data based on the performance of a contract and which is carried out using automated processes (thus excluding manual or paper-based data processing). This right concerns only the personal data that you provide to Verifone, and therefore does not include derived or inferred data, which personal data has not been communicated by you but created by Verifone. The exercise of the right to portability may not prejudice the rights and freedoms of third parties.
- Right to restrict processing of your personal data.
- Right to withdraw consent to process your personal data at any time. This withdrawal will not affect past processing activities conducted legally prior to your withdrawal, nor will it affect the processing of your personal data conducted in reliance on lawful processing grounds other than consent.
- Right to object, at any time, to the processing of your personal data for marketing purposes.
- Right to object right at any time, for reasons relating to your situation, to the processing of your personal data whose legal basis is Verifone legitimate interest.
- Other Rights: Depending on the local law of the jurisdiction in which you are located, you may have additional rights in relation to your personal data.
You have the right to lodge a complaint with a local data protection authority if you have concerns about how we handle your personal data. For authority contact details in the European Economic Area, please refer to the directory available here. If you would like to lodge a complaint with the Swiss Data Protection Authority, you may file it using the form available here.
All the rights listed above regarding European Union/Economic European Area are applicable for you if you are the resident of the United Kingdom, since the UK's privacy rights are aligned with those under the European Union's General Data Protection Regulation (GDPR). Residents in the United Kingdom have the right to:
- Lodge a complaint with a supervisory authority, namely to the Information Commissioner's Office (ICO).
Under the US Data Privacy laws specific data privacy laws enacted by several US States, including but not limited to the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the Colorado Privacy Act (CPA), the Delaware Personal Data Privacy Act (DPDPA), the Connecticut Data Privacy Act (CTDPA) and the Virginia Consumers Data Protection Act (CDPA), residents of those US States (including but not limited to California, Colorado, Delaware, Connecticut and Virginia) hold specific rights concerning their personal data processed by Verifone.
All the rights listed above regarding European Union/Economic European Area are available to you. In addition, you have the right to:
- Request access to or deletion of your personal data;
- Opt out from sale or sharing your personal data (i.e., you can instruct us to cease selling or sharing your personal data);
- Limit use and disclosure of your sensitive personal data;
- No retaliation following opt out or exercise of your other rights as described in this Privacy Notice.
We do NOT sell or share your personal data for monetary or other valuable consideration.
Right to Appeal - California and Colorado: If Verifone does not act on your privacy rights request within the stipulated response period, we will provide a written explanation of the reasons for not taking action and your rights to appeal against the decision.
Right to Appeal - Virginia and Connecticut: You have the right to appeal a refusal to act on your privacy rights request within a reasonable period. Within 60 days of receiving an appeal, Verifone will inform you in writing of any action taken or not taken in response to the appeal, including reasons for the decisions. If denied, you will be provided with a method to contact the Attorney General of Virginia or Connecticut to submit a complaint.
California and Delaware "Do Not Track" disclosures: Privacy regulations in the United States, including California and Delaware laws, necessitate Verifone to disclose whether it honors your browser's "Do Not Track" settings concerning targeted advertising.
All the rights listed above regarding European Union/Economic European Area are applicable to you if you are the resident of Brazil, since the Brazilian privacy rights are aligned with those under the European Union's General Data Protection Regulation (GDPR).
In addition, residents in Brazil have also the following rights according to the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais, LGPD):
- Right to anonymization: You have the right to request the anonymization of personal data that is unnecessary, excessive, or processed in violation of the law, ensuring that your data can no longer be linked to you or any other individual.
- Right to lodge a complaint: you can lodge a complaint with the National Data Protection Authority (ANPD).
All the rights listed above regarding European Union/Economic European Area are applicable to you if you are the resident of Turkey, since the Turkish privacy rights are aligned with those under the European Union's General Data Protection Regulation (GDPR).
In addition, residents in Turkey have also the following rights according to the Turkish Personal Data Protection Law (KVKK):
- Right to anonymization: You have the right to request the anonymization of personal data that is no longer necessary or processed in violation of the law, ensuring that your data can no longer be associated with you or any other individual.
- Right to lodge a complaint: You have the right to lodge a complaint with the Turkish Data Protection Authority (KVKK).
Now that you are aware of the rights you may benefit from, you can access further information within the sub-sections 8. Supplementary information on exercising your privacy rights, as well as 9. Where to exercise your privacy rights.
This Notice should be read in conjunction with the above-mentioned regulations, which supplement but do not override it. In cases of discrepancies, the relevant national privacy law will prevail.
8. Supplementary information on exercising your privacy rights
Please note that while we strive to promptly address your requests, there may be specific situations in which Verifone is unable to immediately implement your request.
Therefore, kindly be informed that:
- You can choose to withdraw consent at any time, only if the processing activity relies solely on your consent. This withdrawal will not affect past processing activities conducted legally prior to your withdrawal, nor will it affect the processing of your personal data conducted in reliance on lawful processing grounds other than consent.
- If you choose to exercise the right to erasure, it's important to note that Verifone may still have legal obligations to retain your personal data. The right to be forgotten would typically apply in the following circumstances:
- When your personal data is no longer necessary for its original purpose;
- If you withdraw your consent for its processing;
- When you object to the processing of your data for Verifone legitimate interests or for receiving personalized commercial messages;
- In cases where Verifone unlawfully processes your personal data; or
- If local laws require Verifone to erase your personal data.
- If you choose to exercise the right to object to Verifone's use of your personal data for its legitimate interests, if you have a valid reason, we will carefully review your objection and assess whether processing your information would have any undue impact on you that warrants discontinuing the processing of your personal data. However, please note that you may not object to us processing your personal data in cases where:
- We have a legal obligation to do so; or
- Processing is necessary to fulfill a contractual obligation with you.
9. Where to exercise your privacy rights
When exercising your right, the more specific you are with your application, the better we can assist you with your question. We may ask you for a copy of your ID, or additional information to verify your identity.
We want to address your request as quickly as possible. However, based on your location and applicable laws, the response times may vary. Should we require more time to complete your request, we will notify you without undue delay and provide reasons for the delay.
To exercise any of your rights, please:
- Contact privacy@verifone.com and we will consider your request in accordance with applicable data protection laws.
- Complete our on-line form available here.
10. Accuracy of the personal data
Verifone is committed to maintaining the accuracy of your personal data held within its systems. To ensure the accuracy and relevance of this data, Verifone may conduct periodic campaigns to update personal data.
However, it is important to note that the accuracy of personal data is a shared responsibility between Verifone and each data subject. Each individual is obligated to provide accurate and up-to-date information and should proactively update their personal data as necessary.
11. Unsubscribe from our marketing communications
You also have the right to opt-out of our marketing communications at any time. Simply click the "unsubscribe" or "opt-out" link in any marketing email from us to stop receiving such updates.
IX. Using of cookies, pixels and other tracking technologies
This section provides information about the use of cookies, pixels and other tracking technologies on Verifone websites, online platforms and portals and, where applicable, in electronic communications. The specific technologies used, their purposes and the applicable consent requirements may vary depending on the relevant website, platform, service, communication and jurisdiction.
The use of Verifone websites and online platforms is subject, where applicable, to Terms and Conditions of Website Use. For further information about cookies and other tracking technologies, please review the Cookie Policy.
12. Cookies
At Verifone, we use cookies, pixels, tags, web beacons and other similar technologies on our websites and online platforms and, where permitted by applicable law, in electronic communications. These technologies may be used to provide website and platform functionality, authenticate users and maintain sessions, protect the security and integrity of our services, understand how our websites and platforms are used, personalize content, measure performance and engagement, and support advertising and conversion measurement. Some of these technologies may collect or otherwise process personal data, including IP addresses, device or browser information, online identifiers, browsing activity, and information about interactions with our websites, platforms, advertisements or electronic communications. This information may be linked to personal data that you provide to us through other channels.
- When you access or use a Verifone account, platform, portal, application or other online service, cookies and similar technologies may also be used to authenticate you, establish and maintain user sessions, manage access to requested functionality, prevent unauthorized access, maintain audit trails, and protect the security of our systems and services. Cookies and similar technologies that are strictly necessary to provide a service requested by you may be used without consent where permitted by applicable law.
- We may also use pixels, web beacons and similar technologies in electronic communications, including emails, to determine whether a communication has been delivered, opened or interacted with, measure engagement and assess the effectiveness of our communications.
- We may use advertising, analytics and conversion measurement technologies to understand the effectiveness of our advertising, determine whether interactions with advertisements result in actions on our websites or platforms, measure conversions and attribution, and improve our marketing activities. These technologies may be provided by third parties, and may process online identifiers, device or browser information and information about interactions with advertisements, websites or platforms. Where enhanced conversion measurement technologies are used, information provided by you, such as an email address or other contact information, may be transformed using cryptographic hashing before being transmitted to the relevant advertising or measurement provider.
You can also adjust your browser settings to reject cookies, although this may affect your experience or the availability of certain functionality on our websites or platforms.
13. Social media plug-ins
We include plug-ins on our websites from social media networks such as Facebook, LinkedIn and Twitter. We may also use plug-ins for embedded video players. These plug-ins may collect or transmit personal data to the relevant provider when you activate or interact with them, for example by clicking on a social media logo or video. The relevant third-party provider determines how it processes personal data through its services. For further information, please review the privacy information provided by the relevant provider.
14. Links to third-party websites
Our websites may include links to external websites that are not under our control, including websites operated by our partners and suppliers. We are not responsible for the content or privacy practices of these external websites. This Notice does not apply to third-party websites, and your interactions with them are governed by the applicable third party's privacy notices, policies and terms.
X. Transfer of personal data
Your personal data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country (and, in some cases, may not be as protective).
Specifically, our third-party service providers and affiliates operate around the world. This means that when we collect your personal data, we may process it in any of these countries.
However, we have taken appropriate safeguards to require that your personal data will remain protected in accordance with this Notice. If you are located in the European Economic Area, where we transfer your personal data to other countries, we rely on:
- The European Commission adequacy decisions, which acknowledge that the non-EEA countries listed here have national laws that protect personal data to a substantially similar standard required by European Union law (for data transfers from the EEA countries). This includes the EU-US Data Privacy Framework (DPF), adopted by the European Commission on 10 July 2023, which applies to transfers to US organisations certified under the DPF;
- The European Commission's 2021 Standard Contractual Clauses, which require non-EEA recipients of personal data to continue to protect the personal data they receive to the standard required by European Union law (for data transfers from the EEA countries);
- The International data transfer agreement and the international data transfer addendum have the legislation that guarantees an appropriate level of protection (for data transfers from the United Kingdom);
- The Swiss Federal Data Protection and Information Commissioner Standard data protection clauses, which require recipients of personal data to protect personal data they receive to the standard required by the Swiss data protection legislation (for data transfers from Switzerland); or
- Other lawful data transfer mechanisms or derogations from data transfer restrictions, including an intra-group data transfer agreement in respect of transfers within our Verifone Group.
Further details can be provided upon request. Please see the contact information below.
XI. Amendments of this Notice
We may change or update this Notice from time to time in response to changing legal, technical, or business developments. When we update this Notice, we will take appropriate measures to communicate to you, consistent with the significance of the changes we make. We will obtain your consent to any material Notice changes if and where this is required by applicable data protection laws.
You can see when this Notice was last updated by checking the "last updated" date displayed at the top of this Notice.
XII. Contact
If you have any questions about this Notice, please contact:
Address: 2744 N University Drive, Coral Springs, FL 33065, United States of America
Email: privacy@verifone.com
(formerly known as 2Checkout and/or Avangate B.V.)
Address: Singel 250, Amsterdam, Noord-Holland 1016AB, The Netherlands
Email: dpo@2checkout.com
Address: 1 Mondial Way, Hayes, UB3 5AR, United Kingdom
Email: dpo@2checkout.com
(formerly known as InterCard)
Address: Karl-Hammerschmidt-Str. 1, 85609 Aschheim, Munich, Germany
Email: datenschutz.vp@verifone.com
Address: Keskuskatu 1, 00100 Helsinki, Finland
Email: privacy@verifone.com
1. For instance: end-users, shoppers, buyers, merchants, vendors, clients, customers, whistleblowers, incident reporters, partners, marketing affiliates, etc.