DATA ETHICS
Research Data Ethics
Published RapidCents research uses de-identified, aggregated data only. No merchant-identifiable information appears: no business name, no account or merchant identifier, no location precise enough to single out a business, no figure belonging to one merchant. Cardholder personal data never enters an analysis dataset at all. Segments below a minimum size set before the analysis are suppressed, and suppression is checked so a withheld cell cannot be reconstructed by subtraction. Publication is gated on recorded privacy and compliance approval.
- De-identified and aggregated only
- No merchant-identifiable information
- Cardholder data is never a research input
- Small segments are suppressed, not caveated
Try it, edit values and click buttons
API request
POST /v1/payments
{
"amount": 24900,
"currency": "CAD",
"capture": true,
"metadata": { "order_id": "4821" }
}Response
Click "Send request" to see the API response
Processing payment…
201 Created
{ "id": "pay_7xK2m", "status": "approved", "amount": 24900 }Demonstration data only
The constraints on published research
De-identified and aggregated only
Published research reports aggregates computed across a population. It does not report a merchant’s own figure, and it does not report an aggregate so narrow that it is one merchant’s figure with a different label on it.
No merchant-identifiable information
No business name, no account or merchant identifier, no location precise enough to single out a business, and no combination of attributes that would identify one. This applies to charts and tables as strictly as it applies to prose.
Cardholder data is never a research input
Card numbers, cardholder names and any element identifying an individual do not enter an analysis dataset at all. This is not a de-identification step applied later; the data does not arrive in the dataset in the first place.
Small segments are suppressed, not caveated
A minimum segment size is set before the analysis runs, and any segment below it is withheld rather than published with a warning. The research states that a segment was suppressed and why, so a reader can tell a deliberate gap from an oversight.
Differencing is checked, not assumed away
Where publishing several overlapping segments would allow a suppressed one to be reconstructed by subtraction, further cells are withheld until it cannot be. Suppressing a cell and then publishing its complement suppresses nothing.
Governance approval before publication
The dataset, the aggregation, the suppression decisions and the output are reviewed and approved by the privacy and compliance function before anything publishes, and the approval is recorded. An analyst cannot clear their own work.
Third-party data is named and licensed
Where research incorporates external data, the source is named on the page and used within its licence. Data scraped from another party’s service is not a research input.
Alignment with privacy obligations
RapidCents commits to handling personal information in line with its obligations under PIPEDA and, in Quebec, under Law 25. This is a publication commitment rather than legal advice, and the Privacy Policy and Data Processing Addendum are the operative documents.
The security context, stated as context
Processing runs on infrastructure validated as a PCI DSS Level 1 service provider, and the regulatory standing notice on this site records a SOC 2 Type II examination. Neither certifies a research method, and neither is offered here as one.
Related policies
Research methodology
The disclosure set a benchmark carries alongside these constraints.
ExplorePrivacy policy
The operative terms governing personal information.
ExploreData processing addendum
The written processing terms behind the underlying data.
ExploreSecurity
The environment the data sits in, evidenced rather than asserted.
ExploreTrust Centre
The documents a diligence reviewer reads without asking.
ExploreEditorial policy
Who reviews a research page before it publishes.
Explore
Questions about this policy: Research Data Ethics
Will my business appear in RapidCents research?
Not by name, and not as a figure that identifies you. Published research reports aggregates across a population, and any segment small enough that a reader could work out whose numbers they were looking at is suppressed before publication rather than published with a caveat.
Can I opt out of being included in research?
Published research contains no merchant-identifiable information, so there is nothing identifying to withdraw from it. Rights requests concerning personal information — access, correction and the rest — run through the route set out in the Privacy Policy, which is the operative document.
Does RapidCents sell merchant data?
No. Merchant transaction data is not sold, and it is not licensed to third parties for their own analysis. What is published is aggregate research produced under this policy.
Is cardholder data ever used in research?
No. Card numbers, cardholder names and any element identifying an individual do not enter an analysis dataset. That is a constraint on what the dataset contains rather than a step applied to it afterwards.
Can a journalist or an auditor get the raw dataset?
No. What is available is the aggregate, the method, the exclusions and the stated limitations, which together are enough to interrogate a conclusion. Releasing the underlying records would breach the constraint this page exists to state, whoever asked.
Take the next step
Talk to a RapidCents specialist
RapidCents Fee Check reads a processing statement and shows interchange separately from the markup. Upload a statement for an instant breakdown, or open a merchant account and start accepting payments on one account.
- No obligation
- Canadian payment specialists
- Secure statement upload





