ShortPay

Privacy Policy

Draft revised September 15, 2026 · Not yet effective

Draft for review. Operator identity, contact details and applicable legal requirements must be verified before publication. This draft is not an effective agreement or final privacy notice.

1. Scope and roles

This Policy explains how personal information is handled through the ShortPay website, checkout, payment APIs and billing tools. It covers purchasers, merchant representatives and website visitors. ShortPay is a service name; the responsible legal operator and privacy contact must be confirmed before publication. For merchant-directed billing activities, ShortPay processes information to provide services to that merchant. For its own service security, administration and legal obligations, the operator may have separate responsibilities. The allocation of controller and processor roles depends on the actual activity and applicable agreements. Merchants and payment providers are responsible for their own privacy notices.

2. Information involved

Checkout and customer information can include your name, email address, billing country, postal code and merchant-provided customer or order identifiers. Transaction records can include the seller, product description, amount, currency, payment status, transaction references, invoices, refunds, subscription periods and cancellation status. Payment-method information may include provider-issued tokens, authorization records and limited card details returned by the provider. When you pay through ShortPay’s card form, the card number, expiration date and security code are submitted through ShortPay to the payment provider to carry out your instruction. Where a provider-hosted interface is used, information entered there is handled by that provider. Payment providers also process information needed for authentication and payment handling. Technical and security records can include IP addresses, browser information, request identifiers, timestamps and processing errors. Merchant administration also involves authorized user identifiers, business and site configuration, and account-access records. Correspondence may contain information you choose to provide for support.

3. Where information comes from

Information is received from you when you use checkout or communicate about a transaction, from the merchant that initiates billing, and from payment providers that return transaction or authentication results. Technical information is generated as browsers and servers communicate. A merchant may supply identifiers and order details before you open a checkout page. Please do not provide sensitive personal information that is unrelated to your payment or support request.

4. How information is used

Information is used to create checkout sessions, route payment instructions, authenticate access, record transaction results, generate invoices, carry out authorized recurring billing and process refunds. It is also used to deliver payment notifications to the relevant merchant, reconcile records, investigate processing errors, prevent misuse, protect accounts and respond to legitimate support requests. Records may be needed to meet applicable legal requirements, respond to lawful requests and establish or defend legal claims. A payment status is not used as a substitute for the merchant’s own delivery or entitlement records.

5. Who receives information

Relevant information is shared with the merchant involved in your transaction and with the payment providers, financial institutions and networks needed to process, authenticate or resolve it. Hosting, infrastructure and other service providers may handle information needed to operate the Services under applicable contractual safeguards. Information may also be disclosed to professional advisers, competent authorities or other parties where necessary and legally permitted to comply with law, investigate fraud or protect legal rights. A corporate transaction may require disclosure subject to applicable confidentiality and data-protection obligations. This Policy does not authorize unrelated merchants to access your payment records.

6. Legal grounds

Where a legal basis is required, processing may rely on performance of a contract with the relevant individual, compliance with a legal obligation, consent, or legitimate interests such as operating a secure payment service and preventing fraud. The appropriate basis depends on the purpose and the operator’s role; a purchaser’s agreement with a merchant is not automatically a contract with ShortPay. Where consent is relied upon, you may withdraw it, without affecting processing already lawfully performed. Merchant-directed processing is also subject to the applicable service and data-processing agreements.

7. Cookies and browser storage

Browser cookies or similar mechanisms may be used for functions such as maintaining authorized administrative sessions. Checkout integrations and payment providers may use their own browser mechanisms for authentication and transaction security. Your browser can block or delete cookies, but doing so may disrupt relevant functionality. Cloudflare provides edge delivery and may collect request and browser performance information through its infrastructure and a browser beacon. The page source does not include advertising pixels or third-party fonts. Any future non-essential tracking must be assessed and disclosed, and consent obtained where required, before it is enabled.

8. Retention

Retention depends on the purpose of each record, transaction and subscription lifecycles, fraud and dispute handling, applicable legal requirements, contractual duties and the need to resolve claims. Deleting an account or canceling a subscription does not necessarily require immediate deletion of payment records. Information should be deleted or de-identified when it is no longer needed, subject to lawful exceptions and backup handling. Specific retention schedules must be confirmed by the operator before this Policy is finalized; this draft does not promise a fixed deletion deadline.

9. Security

The service uses access controls and other technical measures intended to protect information, including controlled access to administrative functions and payment credentials. No internet service can guarantee absolute security. Protect access links and credentials and avoid including full card numbers, security codes or passwords in support messages. This Policy does not claim a regulatory license, security certification or compliance status that has not been independently confirmed.

10. International processing

Information may be handled in countries where the merchant, ShortPay’s infrastructure or payment providers operate. Those countries may have different data-protection laws. Where required, the responsible parties must establish a lawful transfer mechanism and appropriate safeguards. The operator must confirm the relevant processing locations and transfer arrangements before final publication; this draft does not claim participation in a certification framework or an executed transfer agreement.

11. Your rights and choices

Depending on applicable law, you may request access, correction, deletion, restriction, portability or information about disclosures, and may object to certain processing. You may also be entitled to withdraw consent, appeal a decision on a request or complain to a data-protection authority. Rights may be subject to verification and lawful exceptions, including records needed for payment disputes or legal obligations. Where ShortPay acts for a merchant, requests about the merchant’s customer records may need to be directed to that merchant. The operator must provide a functioning direct privacy contact before publication. Requests should include only the information reasonably needed to identify the relevant record, not card security codes or passwords.

12. Children

The Services are intended for authorized business representatives and people who can lawfully make the relevant purchase. They are not designed to collect information from children for independent use. If you believe a child has supplied information without the necessary authorization, contact the merchant and the responsible privacy contact so the matter can be assessed under applicable law.

13. Regional requirements

Additional rights and disclosures may apply in your country or state. Mandatory local protections prevail over inconsistent statements here. Before publication, the operator must determine which regional notices are required, including any applicable US state disclosures concerning sale, sharing or targeted advertising. This draft does not assert an unverified exemption or make an unsupported declaration about those practices.

14. Updates and contact

This Policy should be reviewed when the service or its data practices change. The published policy will show its revision date, and material changes will be communicated as required by law. For transaction or merchant-account questions, contact the merchant through its website or purchase confirmation. The ShortPay operator’s full legal name, postal address and direct privacy contact must be added before this draft becomes the published privacy notice.

Related document: Terms of Service.