Privacy Summary

At SecureTransaction.co, privacy and security are fundamental to our business model. We act as a high-security data processor and tokenization gateway. We do not sell personal data, track user browsing across non-affiliated sites, or store raw Payment Card Industry (PCI) cardholder data outside our certified, isolated HSM vaults.

1. Introduction

SecureTransaction.co ("Secure Transaction", "we", "us", or "our") provides enterprise-grade payment security, tokenization, fraud detection, and transaction routing infrastructure. This Privacy Policy explains how we collect, use, process, and protect information when you visit our website, use our payment gateway APIs, or interact with merchant payment checkout flows powered by our platform.

2. Information We Collect

We collect information through three primary mechanisms:

A. Information Provided Directly by You or Your Business

  • Account & Registration Details: Full name, business email address, company name, phone number, physical address, and billing credentials when you set up an account.
  • KYC / AML Verification Data: Government ID, tax identification numbers, corporate registration documents, and beneficial ownership details required for regulatory compliance.
  • Support & Inquiry Communications: Messages, logs, and contact details provided when requesting customer or developer support.

B. Payment & Transaction Telemetry (Processed on Behalf of Merchants)

When end-consumers make payments using our gateway infrastructure, we process telemetry required for processing and fraud risk evaluation:

  • Payment Identifiers: Masked card details (BIN and last 4 digits), tokenized vault strings, card expiration dates, and billing postcodes. Raw PANs are tokenized immediately and isolated from server logs.
  • Transaction Context: Transaction amount, currency, timestamp, merchant order ID, and fulfillment indicators.
  • Risk Telemetry: IP address, device fingerprinting tokens, browser environment header, location indicators, and network routing metadata used solely for anti-fraud analysis.

C. Technical & Usage Data

Server logs, API endpoint usage metrics, HTTP status codes, latency records, and authentication tokens collected automatically when interacting with our API endpoints or website.

3. How We Use Collected Information

We use collected data strictly for operational, security, and legal purposes:

  • Payment Processing: Executing transaction authorizations, clearing, settlements, and chargeback disputes with payment networks and acquiring banks.
  • Fraud Prevention & Risk Scoring: Analyzing risk parameters through automated Machine Learning models to prevent unauthorized transactions and card testing attacks.
  • Regulatory & Legal Compliance: Fulfilling Anti-Money Laundering (AML), Know Your Customer (KYC), sanctions screening, and PCI-DSS compliance mandates.
  • Infrastructure Reliability: Monitoring latency, preventing DDoS attacks, debugging system anomalies, and maintaining 99.999% platform availability.

4. Data Sharing & Disclosure

We never sell, rent, or trade personal data to third-party marketers or advertisers. Information is disclosed exclusively in the following contexts:

  • Financial Payment Networks: Payment processing partners, card brands (Visa, Mastercard, AMEX), acquiring financial institutions, and issuer networks required to route transactions.
  • Legal & Enforcement Authorities: When legally compelled by court orders, subpoenas, or official anti-money laundering inquiries.
  • Sub-processors & Security Vendors: Certified infrastructure providers (e.g., AWS, Equinix) operating under strict data processing agreements matching these privacy terms.

5. Data Security & Storage Standards

All data processed by SecureTransaction.co is guarded using defense-in-depth architectural measures:

Vault Tokenization

Sensitive payment card details are instantly exchanged for non-sensitive surrogate tokens. Raw cardholder data never touches application databases.

AES-256-GCM Encryption

All stored records, configuration parameters, and token mappings are encrypted at rest using Hardware Security Modules (HSMs) certified to FIPS 140-2 Level 3.

6. Your Global Privacy Rights (GDPR / CCPA)

Depending on your jurisdiction (including the European Economic Area, UK, and California), you hold legal rights regarding your personal data:

  • Right of Access & Portability: Request a structured copy of personal data retained about you.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of account data, subject to statutory financial retention mandates (e.g., AML recordkeeping laws).
  • Right to Rectification: Correct inaccurate or incomplete account details.
  • Right to Opt-Out of Automatic Profiling: Request human review for automated transaction fraud flags.

7. Data Retention

We retain transaction records and audit logs for a minimum of 7 years to satisfy global financial compliance, tax, and anti-fraud regulations. Once legal retention thresholds expire, data is securely destroyed or irreversibly anonymized.

8. Contact Our Data Protection Officer

For privacy inquiries, Data Subject Access Requests (DSARs), or security concern escalations, reach our Data Protection Officer directly:

Email: privacy@secure-transaction.co

Encrypted PGP Key Fingerprint: 9F8A 321B 4C09 8E21 D001 7C8B 4E5A 90B2

Postal Address: Secure Transaction Co., Attn: Data Protection Officer, 500 Security Way, San Francisco, CA 94105, USA