Skip to main content
NewChargeback Protection + Fee Intelligence for high-volume merchants. Get a savings analysis and a review of your dispute handling.See how it works
Details

Chargeback Protection + Fee Optimization

See how it works: high-volume merchants get automated dispute evidence, interchange optimization, and real-time savings visibility.

See how it works

This policy explains what personal information RapidCents Inc. collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers our websites, the merchant dashboard and the payment services. Where we act on behalf of a merchant rather than for ourselves, that distinction is set out in section 3 — it decides who you should contact about your information.

1. Who we are and what this covers

RapidCents Inc. (“RapidCents”, “we”, “us”) is a payment technology company incorporated in Canada, with offices in North York, Ontario and Ashburn, Virginia. This policy applies to rapidcents.com and its localized versions, the merchant dashboard, the payment gateway and virtual terminal, our mobile and terminal software, and our support and marketing communications.

It does not cover a merchant’s own website or the way a merchant handles information it collects from its customers. It also does not cover third-party services you choose to connect, which are governed by their own policies.

2. The law we operate under

Canadian federal privacy law applies. If you live in Quebec, Law 25 adds rights on top. US state laws apply to US residents.

RapidCents is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada. Where a province has substantially similar legislation — Quebec, Alberta and British Columbia — that legislation applies to activity within it. For residents of Quebec, the Act respecting the protection of personal information in the private sector, as amended by Law 25, applies and grants additional rights described in section 8.

For residents of United States jurisdictions with comprehensive privacy legislation, we honour the rights those laws grant, including the rights to know, to delete, to correct, and to opt out of sale or sharing. RapidCents does not sell personal information as that term is defined in those laws.

As a payment provider we are also subject to obligations that override a deletion request, including record-keeping under anti-money-laundering legislation and evidence retention under the Card Network rules. Section 7 explains how those interact.

3. When we are a controller and when we are a processor

For our own merchants we decide how information is used. For a merchant’s customers, the merchant decides and we act on their instructions — except for the things we do on our own account, such as sanctions screening, our own fraud decisions, reporting to regulators and to the card networks, and the records we are obliged to keep, where we decide and we answer.

RapidCents acts as a controller — deciding the purposes and means of processing — for information about merchants, merchant staff, applicants, website visitors and people who contact us. This policy describes that processing.

We are also a controller for a narrower set of activities that reach a merchant’s own customers, because those activities are ours to decide on and to answer for rather than the merchant’s, and several of them are obligations the law puts on us directly. A merchant cannot instruct us to stop them. Clause 4 of the Data Processing Addendum lists activity by activity everything we carry out as a controller; these are the ones that reach a merchant’s customers:

  • Screening the parties to a transaction against the sanctions lists we are required to screen against. The same obligation is what makes us verify the identity of a merchant, its directors and its beneficial owners, which section 4 describes.
  • Monitoring transactions, reporting suspicious transactions, and making any other report we are required or permitted to make to a regulator or a law enforcement authority — a report the law may prohibit us from telling the merchant we have made.
  • Our own fraud prevention, risk scoring, underwriting, reserve and payout decisions, and the risk and compliance controls we operate for our own account and in the interests of our acquirer, the Card Networks and other merchants rather than for the merchant’s benefit.
  • Reporting to and answering to our acquirer, the Card Networks and our regulators, including chargeback and representment handling, fines and assessments, and the forensic investigation that follows a suspected compromise of card data.
  • Keeping the records our own record-keeping, tax, audit and PCI DSS obligations require, defending our own legal claims, and operating and securing the platform itself. A merchant’s instruction to delete does not reach a record we are separately obliged to keep; section 7 sets out the periods.
  • Analysing how the services are used in order to improve them, and producing aggregated and anonymized benchmarking, analytics and research from that analysis. What comes out of it is the aggregated statistics section 5 describes, which do not identify a person.

Apart from those, RapidCents acts as a processor, handling information under a merchant’s instructions, for personal information about that merchant’s own customers that flows through the payment services. If you are a cardholder with a question about a purchase, the merchant you bought from is the right first contact; they decide what to collect and why. We will still assist a merchant in responding to you, and we honour cardholder rights that apply to us directly.

Where we act as a processor, the Data Processing Addendum sets out the commitments that govern that role, and clause 4 of that Addendum is the fuller statement of the division this section describes.

4. Information we collect

We collect only what we need for the purposes in section 5. The categories differ depending on whether you are a merchant, a member of merchant staff, a website visitor or a cardholder.

  • Business and identity information, from merchants and applicants: legal and operating name, business number, incorporation and ownership documents, addresses, the identity of directors and beneficial owners, and government identification where verification requires it. This is collected because anti-money-laundering law and the Card Network rules require a payment provider to verify who it is onboarding — see the KYC Policy.
  • Contact and account information: name, business email, telephone number, job role, login credentials and multi-factor authentication settings.
  • Financial and settlement information: bank account and routing details for deposits, processing history, statements, fee schedules, chargeback and refund records.
  • Transaction information: amount, currency, date and time, approval or decline result and reason, the last four digits and card brand, the billing postal code used for address verification, the device or channel, and a token that stands in for the card credential.
  • Technical information from your use of our websites and dashboard: IP address, browser and operating system, referring page, pages viewed, and interactions, collected as described in the Cookie Policy.
  • Communications: the content of support tickets, emails, chat and calls with our teams, including recordings where we tell you a call is recorded.
  • Marketing preferences: subscription status, and consent to receive electronic messages or SMS.

5. Why we use it

We use personal information to provide, secure and improve the services, and to meet obligations we cannot decline. Specifically: to assess and open merchant accounts, including identity verification and sanctions screening; to authorize, route, settle and reconcile transactions; to detect and prevent fraud and unauthorized access; to manage chargebacks and provide evidence to issuing banks; to provide support and respond to you; to bill, collect and account for fees; to meet legal, tax, audit and Card Network obligations; to produce aggregated statistics that do not identify a person; and, where you have consented or where permitted by law, to send marketing about products related to what you already use.

We do not sell personal information. We do not use cardholder transaction detail to build advertising profiles, and we do not disclose one merchant’s data to another.

6. Who we share it with

Banks and card networks, vetted suppliers, and authorities when the law requires it. Never for someone else’s marketing.

We disclose personal information only as described here. Every service provider that handles it is bound by contract to use it solely for the service they provide us, to protect it, and to return or delete it when the engagement ends.

  • Acquiring banks, Card Networks and processors, to authorize, settle and reconcile transactions and to manage disputes. Their handling is governed by their own rules, including the Visa and Mastercard operating regulations.
  • Service providers acting on our instructions, for cloud hosting, communications, analytics, identity verification and sanctions screening, fraud tools, and customer support. The Subprocessors page sets out these categories, what each is engaged to do and what it can reach; section 9 of that page publishes the register of providers, states that it is complete as to the parties it names but is not the whole supply chain, and sets out how to obtain the current full list and how to ask for the country a provider processes in where the register does not state one.
  • Professional advisers — auditors, lawyers and insurers — under a duty of confidence.
  • Regulators, law enforcement and courts, where we are legally required to disclose, or where disclosure is necessary to investigate suspected fraud or to protect our rights, property or safety, or those of others.
  • An acquirer or successor, in a merger, financing, reorganization or sale of assets, subject to confidentiality and to this policy continuing to apply to the information transferred.
  • Other parties, with your consent or at your direction — for example, when you connect a third-party integration.

7. How long we keep it

Payment records have legally mandated retention. We cannot delete them on request, and we say so rather than promising otherwise.

We keep personal information only as long as needed for the purpose it was collected for, or as long as the law requires, whichever is longer. Retention is set by category, not by a single site-wide period.

  • Identity verification and onboarding records: retained for the period required of a reporting entity under Canadian anti-money-laundering legislation, which runs from the end of the business relationship.
  • Transaction and settlement records: retained for the period required for tax, audit and Card Network dispute purposes.
  • Stored payment credentials: held in the card vault as tokens and removed when a merchant deletes the customer record or the account closes. Consistent with our security practices, cardholder data is retained for up to 24 months of inactivity.
  • Support communications: retained while the account is open and for a reasonable period afterwards, so a later question about a past issue can still be answered.
  • Website analytics: retained for the period stated in the Cookie Policy.
  • Marketing preferences and opt-outs: retained indefinitely, because we need a record of an opt-out in order to honour it.

8. Your rights, and how to use them

You may ask us to give you access to the personal information we hold about you, correct it if it is inaccurate or incomplete, delete it where no legal obligation requires us to keep it, provide it in a structured, commonly used technical format or transfer it to another organization, withdraw a consent you previously gave, or stop using it for marketing.

Residents of Quebec additionally have the right to be informed when a decision about them is made exclusively by automated processing and to submit observations on it, and the right to have information de-indexed in the circumstances Law 25 provides. Residents of United States jurisdictions with comprehensive privacy laws may exercise the rights those laws grant, and may appeal a decision we make on such a request.

Write to the Privacy Officer at the address in section 12. We will confirm receipt, may ask for information to verify who you are so that we do not disclose your data to someone else, and will respond within thirty (30) days, or tell you why more time is needed and when to expect an answer. There is no charge for a reasonable request.

Withdrawing consent does not affect processing that already took place, and some withdrawals mean we can no longer provide part of the service — we will tell you when that is the case rather than withdrawing the service silently. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, to the Commission d’accès à l’information du Québec, or to the equivalent authority in your jurisdiction.

9. Where information is stored and transferred

RapidCents operates in Canada and the United States and uses cloud infrastructure and service providers that may store or process personal information outside the province or country where you live, including in the United States. Where that happens, the information is subject to the laws of that jurisdiction and may be accessible to its courts, law enforcement and national security authorities.

We transfer personal information only to providers bound by contract to protect it to a standard comparable to the one we apply, and we assess the privacy implications before entrusting information to a provider in another jurisdiction, as Quebec’s Law 25 requires. You may ask the Privacy Officer for information about our practices in this area.

10. How we protect it, and what happens if something goes wrong

Card numbers are replaced by tokens and held in a PCI-scoped vault rather than in ordinary application storage. Sensitive stored data is encrypted, connections require TLS 1.2 or higher, access is role-based and requires multi-factor authentication, and access to merchant data by our staff is logged. The Security page describes these controls in detail.

No safeguard removes risk entirely, and we do not claim otherwise. If a confidentiality incident creates a real risk of serious injury, we will notify the affected individuals and the appropriate regulators as required, including the Office of the Privacy Commissioner of Canada under PIPEDA and the Commission d’accès à l’information under Law 25, and we keep a register of confidentiality incidents.

If you believe your account has been accessed without authorization, contact us immediately. To report a security vulnerability, follow the Vulnerability Disclosure policy.

11. Marketing, email and SMS

Commercial electronic messages are sent in accordance with Canada’s Anti-Spam Legislation. Every marketing email identifies us, gives our mailing address and includes an unsubscribe mechanism that works for at least sixty (60) days. Unsubscribing takes effect promptly and never affects service messages about your account, security, billing or a legal obligation.

If you give us a mobile number and opt in, you consent to receive text messages from RapidCents at that number; participation is not a condition of purchase and message frequency varies. Reply STOP to any message to opt out and you will receive one confirmation message and nothing further; reply HELP for assistance. Standard message and data rates from your carrier may apply, and we are not responsible for carrier charges.

12. Contacting the Privacy Officer

RapidCents has designated a Privacy Officer accountable for compliance with this policy and for responding to requests and complaints. Write to: Privacy Officer, RapidCents Inc., 515 Consumers Road, Unit 210, North York, Ontario, M2J 4Z2, Canada, or telephone +1-844-957-2743. In the United States: 43300 Southern Walk Plaza, #166, Ashburn, Virginia 20148, or telephone +1-202-902-6226.

Tell us what you are asking for and how to reach you. If your request concerns a purchase you made from a business that uses RapidCents, include the merchant’s name — as explained in section 3, they are usually the party who decides how that information is used.

13. Children

The services are business services and are not directed at children. We do not knowingly collect personal information from a child under 13. If we learn that we have, we will delete it. A parent or guardian who believes a child has provided us with information should contact the Privacy Officer.

14. Changes to this policy

We may update this policy. The effective date and the date last revised appear at the top of the page. Where a change materially affects how we handle personal information, we will give notice at least thirty (30) days before it takes effect, by email or through the merchant dashboard. Previous versions are available from the Privacy Officer on request.

Questions about this document

Write to RapidCents Inc., 515 Consumers Road, Unit 210, North York, Ontario, M2J 4Z2, or call +1-844-957-2743. In the United States: 43300 Southern Walk Plaza, #166, Ashburn, Virginia 20148, or call +1-202-902-6226.