OrcaPayz

Legal

Privacy Policy

Last updated: September 2026

This Privacy Policy explains what information OrcaPayz ("OrcaPayz", "we", "us") collects when you use our website, dashboard, API and hosted checkout (the "Service"), how we use it, who we share it with and the choices you have. It applies to merchants who hold an OrcaPayz account and, to the extent described below, to their customers ("shoppers") who pay through a checkout we host on the merchant's payment domain.

For shopper data processed through a merchant's checkout, the merchant is the data controller and OrcaPayz acts as a processor on the merchant's instructions. Stripe processes card data as an independent controller under its own privacy policy.

1. Information we collect

Account data (merchants)

Transaction metadata

Technical and usage data

2. Information we do not collect

We never receive, process or store full card numbers, expiry dates, CVCs or other sensitive authentication data. These are entered into Stripe Elements on the checkout page and transmitted directly from the shopper's browser to Stripe. We also do not collect bank account numbers or government identification numbers.

3. How we use information

Where the GDPR or similar law applies, our legal bases are performance of a contract (providing the Service), legitimate interests (security, improvement, communication with business customers) and compliance with legal obligations. We do not sell personal data and we do not use it for third-party advertising.

4. How we share information

Where data is transferred outside the country in which it was collected, we rely on appropriate safeguards such as standard contractual clauses.

5. Cookies

We use a small number of strictly necessary cookies and do not use advertising or cross-site tracking cookies.

You can block cookies in your browser; the dashboard and checkout will not function correctly without the strictly necessary ones.

6. Data retention

7. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. Merchants can update most account data directly in the dashboard. Shoppers should contact the merchant they paid, who can act on their request through us; we will also forward requests we receive directly. To exercise a right, use our contact form. We respond within 30 days. If you are in the EEA or UK you may also lodge a complaint with your local data protection authority.

8. Security

We protect data with TLS in transit, encryption at rest for Stripe credentials and webhook secrets, hashed passwords, least-privilege access controls, audit logging and network-level protection through Cloudflare. Outbound webhooks are signed with HMAC-SHA256 so you can verify their origin. No method of transmission or storage is completely secure; if we become aware of a breach affecting your data we will notify you without undue delay and in line with applicable law.

9. Children

The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes to this Policy

We may update this Policy from time to time. We will post the revised version with a new "Last updated" date and, for material changes, notify merchants by email or a dashboard notice before the change takes effect.

11. Contact

Privacy questions and requests can be sent through our contact form. We reply within one business day.