Privacy
How TopPay handles your data
What we collect, why we hold it, who sees it, and how long it stays. Written to be read, not to be survived.
Who this covers
This notice explains what TopPay does with personal data on this website, in sales conversations, and during merchant onboarding.
Payment data we handle while running collections and payouts for a merchant is a different matter. There we act on that merchant's instructions under our merchant agreement, and their own privacy notice governs the relationship with their customer.
What we collect
We keep the set narrow, and every field is tied to a reason we can name.
- Contact details you submit: name, work email, phone, role, and the markets you asked about.
- Diligence records for merchants: company registration, beneficial owners, licences, and the identity documents a local rail requires.
- Technical data from this site: IP address, device and browser, pages viewed, and the language you selected.
- Operational records once you are live: support threads, settlement files, and the references tied to your account.
Why we use it
Each use below is a purpose we can point to, not a general licence to keep data around.
- Answering an enquiry and preparing a commercial proposal.
- Running KYB, sanctions screening, and the AML/CFT checks each corridor requires.
- Operating collections, payouts, reconciliation, and support once you are live.
- Meeting the obligations that come with being a registered money services business.
- Keeping the platform secure, investigating fraud, and understanding which pages are useful.
Where the data goes
TopPay runs corridors across Latin America, Asia, and Africa, so data may be processed outside the country it came from. Transfers travel encrypted and under contractual protection.
Where a market sets its own residency or localisation rules, we handle that market on its own terms rather than assuming one global default.
How long we keep it
Enquiry records are kept while the conversation is live and for a reasonable period afterwards. Identity and transaction records are kept for the period AML rules in the relevant market require, commonly five years after the relationship ends.
When a retention period expires, the record is deleted or anonymised.
How it is protected
Encryption in transit and at rest, least-privilege access with logging for audit, separated environments, and monitoring on the paths that matter.
Our cardholder data environment is assessed to PCI DSS as a service provider, our information security management is certified to ISO/IEC 27001, and TopPay is a registered money services business in Canada.
Your rights
Depending on where you live, you can ask for a copy of your data, correct it, delete it, restrict or object to a use, or receive it in a portable form.
Write to [email protected] and we will respond within five working days. Where we hold data on behalf of a merchant, we will tell you and point you to them. You can also complain to your local data protection authority.
Changes to this notice
We update this notice when our processing changes. The date at the top tracks the current version, and material changes are raised with merchants through their account contact rather than left to be discovered.
Questions about this page?
Data protection, compliance, and contracting questions all reach the same desk. A named person answers, usually within one business day.
This page is published in English and translated for convenience. Where a translation and the English version differ, the English version governs.
