Privacy Policy
- Effective
- Last updated
This policy explains what personal information RapidCents Inc. collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers our websites, the merchant dashboard and the payment services. Where we act on behalf of a merchant rather than for ourselves, that distinction is set out in section 3 — it decides who you should contact about your information. On our website, where you are decides what runs before you choose. In the United States and in Canadian provinces and territories other than Quebec, Google Analytics, Microsoft Clarity, the Meta pixel, Google’s advertising measurement and our own record of your visits run from your first page without a pop-up asking first, and if you then send an enquiry through the contact form, how you reached the site and what you read are stored with it. Everywhere else, the cookie notice asks first. “Cookie settings” at the foot of every page turns this off; section 4A explains it.
1. Who we are and what this covers
RapidCents Inc. (“RapidCents”, “we”, “us”) is a payment technology company incorporated in Canada, with offices in North York, Ontario and Ashburn, Virginia. This policy applies to rapidcents.com and its localized versions, the merchant dashboard, the payment gateway and virtual terminal, our mobile and terminal software, and our support and marketing communications.
It does not cover a merchant’s own website or the way a merchant handles information it collects from its customers. It also does not cover third-party services you choose to connect, which are governed by their own policies.
2. The law we operate under
Canadian federal privacy law applies. If you live in Quebec, Law 25 adds rights on top. US state laws apply to US residents.
RapidCents is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada. Where a province has substantially similar legislation — Quebec, Alberta and British Columbia — that legislation applies to activity within it. For residents of Quebec, the Act respecting the protection of personal information in the private sector, as amended by Law 25, applies and grants additional rights described in section 8.
For residents of United States jurisdictions with comprehensive privacy legislation, we honour the rights those laws grant, including the rights to know, to delete, to correct, and to opt out of sale or sharing. Section 4A describes what our website discloses to Google and Meta for advertising, and section 8 how to stop it.
As a payment provider we are also subject to obligations that override a deletion request, including record-keeping under anti-money-laundering legislation and evidence retention under the Card Network rules. Section 7 explains how those interact.
3. When we are a controller and when we are a processor
For our own merchants we decide how information is used. For a merchant’s customers, the merchant decides and we act on their instructions — except for the things we do on our own account, such as sanctions screening, our own fraud decisions, reporting to regulators and to the card networks, and the records we are obliged to keep, where we decide and we answer.
RapidCents acts as a controller — deciding the purposes and means of processing — for information about merchants, merchant staff, applicants, website visitors and people who contact us. This policy describes that processing.
We are also a controller for a narrower set of activities that reach a merchant’s own customers, because those activities are ours to decide on and to answer for rather than the merchant’s, and several of them are obligations the law puts on us directly. A merchant cannot instruct us to stop them. Clause 4 of the Data Processing Addendum lists activity by activity everything we carry out as a controller; these are the ones that reach a merchant’s customers:
- Screening the parties to a transaction against the sanctions lists we are required to screen against. The same obligation is what makes us verify the identity of a merchant, its directors and its beneficial owners, which section 4 describes.
- Monitoring transactions, reporting suspicious transactions, and making any other report we are required or permitted to make to a regulator or a law enforcement authority — a report the law may prohibit us from telling the merchant we have made.
- Our own fraud prevention, risk scoring, underwriting, reserve and payout decisions, and the risk and compliance controls we operate for our own account and in the interests of our acquirer, the Card Networks and other merchants rather than for the merchant’s benefit.
- Reporting to and answering to our acquirer, the Card Networks and our regulators, including chargeback and representment handling, fines and assessments, and the forensic investigation that follows a suspected compromise of card data.
- Keeping the records our own record-keeping, tax, audit and PCI DSS obligations require, defending our own legal claims, and operating and securing the platform itself. A merchant’s instruction to delete does not reach a record we are separately obliged to keep; section 7 sets out the periods.
- Analysing how the services are used in order to improve them, and producing aggregated and anonymized benchmarking, analytics and research from that analysis. What comes out of it is the aggregated statistics section 5 describes, which do not identify a person.
Apart from those, RapidCents acts as a processor, handling information under a merchant’s instructions, for personal information about that merchant’s own customers that flows through the payment services. If you are a cardholder with a question about a purchase, the merchant you bought from is the right first contact; they decide what to collect and why. We will still assist a merchant in responding to you, and we honour cardholder rights that apply to us directly.
Where we act as a processor, the Data Processing Addendum sets out the commitments that govern that role, and clause 4 of that Addendum is the fuller statement of the division this section describes.
4. Information we collect
We collect only what we need for the purposes in section 5. The categories differ depending on whether you are a merchant, a member of merchant staff, a website visitor or a cardholder.
- Business and identity information, from merchants and applicants: legal and operating name, business number, incorporation and ownership documents, addresses, the identity of directors and beneficial owners, and government identification where verification requires it. This is collected because anti-money-laundering law and the Card Network rules require a payment provider to verify who it is onboarding — see the KYC Policy.
- Contact and account information: name, business email, telephone number, job role, login credentials and multi-factor authentication settings.
- Financial and settlement information: bank account and routing details for deposits, processing history, statements, fee schedules, chargeback and refund records.
- Transaction information: amount, currency, date and time, approval or decline result and reason, the last four digits and card brand, the billing postal code used for address verification, the device or channel, and a token that stands in for the card credential.
- Technical information from your use of our websites and dashboard: IP address, browser and operating system, referring page, pages viewed, and interactions. On the websites, what is collected and who receives it depend on where you are and on your cookie choices, as section 4A and the Cookie Policy describe.
- Communications: the content of support tickets, emails, chat and calls with our teams, including recordings where we tell you a call is recorded.
- Enquiries sent through the website’s contact form: what you type, and what is stored with it as section 4A describes, including, where your cookie choices allow analytics, how you reached the site and the pages you viewed.
- Marketing preferences: subscription status, consent to receive electronic messages, calls or SMS, and, where you tick a consent box on the website’s contact form, the exact wording you agreed to and when.
4A. Our website, its cookie notice and its contact form
In the United States and in Canada outside Quebec, our website measures your visit for analytics and advertising from your first page, without asking first. Everywhere else it asks first. If you write to us through the contact form while analytics is on, how you found us and what you read are stored with your message. “Cookie settings” at the foot of every page turns this off.
What our website collects about a visit depends on where you are and on the choices you make in its cookie notice. If you are in the United States, or in a Canadian province or territory other than Quebec, analytics and marketing are on from your first page and no pop-up asks you first; this section and the Cookie Policy are the notice of it. Analytics there means Google Analytics; Microsoft Clarity, which records clicks, scrolling and pointer movement on our pages; and our own record of the visits your browser makes. Marketing means the Meta pixel and the Meta Conversions API, and Google’s advertising measurement. To turn them off, choose “Cookie settings” at the foot of any page and then “Essential only”, which stops both at once. If you are in Quebec, in Canada where your province cannot be determined, or anywhere else, or if the site cannot determine where you are, the cookie notice appears on your first visit and nothing in either category runs until you accept, apart from the cookieless signals Google’s tag sends, described below. We can switch the site to ask first everywhere.
Where you are is worked out from the IP address your browser connects from: the country and the province or state, as reported by the network that serves the site or, where that report gives no country, or no province for a visitor in Canada, by an IP-location service the site asks. We keep the answer; the IP address is not stored with it.
While Analytics is on, we keep one record for your browser: a random identifier held in your browser; the times of your first and latest visits; counts of your visits and of the pages you viewed; for your first arrival and your latest one, the page you landed on, the host name of the site that sent you, and the campaign parameters and advertising click identifiers in the address you arrived by, with the source, medium and campaign worked out from them; the paths of the last thirty pages you viewed; your country and province or state; your device type, browser and operating-system family; your browser’s language; and whether analytics was accepted by you or on by default. It is not anonymous: the identifier singles out your browser, and once you send an enquiry the record carries that enquiry’s reference, which ties it to your name. Your IP address is not stored in it. It is deleted twelve months after your last visit, and at once if you turn Analytics off, which “Essential only” does.
When you send the contact form, we store what you type — your name, email address, phone number, business name, the topic you choose and your message — with the page you sent it from, the time, your browser’s identification string and a keyed one-way hash of your IP address, which is used to limit repeated submissions. We also store your country and province or state, your device type, browser and operating-system family, your browser’s language, the state of the cookie notice at the moment you sent the form, and whether your browser sent a Global Privacy Control signal. If Analytics is on at that moment, we also store the visit history held in your browser — how you arrived, from which site and campaign, and the pages you viewed before writing — and link our record of your browser’s visits to the enquiry. A notice under the form says this and links to this policy.
A job application is stored in the same way, with what you send in it, but without visit history; its contact details are not used to send marketing and are never sent to Meta.
The contact form has two optional boxes, both unticked until you tick them: one for marketing email from RapidCents, and one for marketing calls and text messages from RapidCents, including calls and texts made with an automatic dialler or a recorded voice. Sending the form does not depend on either. When you tick one, we store the exact wording you were shown and the time; the second counts only if you give a phone number. Section 11 explains when we may send marketing to an address given in an enquiry without one.
We use an enquiry and what is stored with it to answer you, to assess whether our services fit your business, to work out which rules apply to contacting you, to measure which pages and advertising bring enquiries, and, where section 11 permits, to send you marketing. Our sales and support staff use it, as do the service providers that host the site and deliver our email.
What Google, Meta and Microsoft receive. While Analytics is on, Google Analytics and Microsoft Clarity receive information about your visit. Google’s tag loads whatever you choose: with Analytics and Marketing both off, it still sends Google cookieless signals about the pages and events, which carry no cookie identifier. While Marketing is on, the Meta pixel and the Meta Conversions API run and Google’s advertising signals are granted. When an enquiry is stored and Marketing is on, Meta is sent a “Lead” event with the page address, the values of Meta’s cookies in your browser, your IP address, your browser’s user agent and a hashed copy of the enquiry’s reference number. A hashed (SHA-256) copy of the email address, phone number and name you typed is added only if you accepted Marketing in the cookie notice or, in the United States, if Marketing is on by default and your browser sends no Global Privacy Control signal; it is never added on the default in Canada. Where Marketing is on by default, leaving its box ticked when you save your cookie preferences is not an acceptance. A job application is reported to Meta as a “SubmitApplication” event in the same way, but never with the contact details in it. Meta may use what it receives under its own terms. Nothing you type into a form is sent to Google: Google is told that a form was sent, and which one, and that a link to sign up was followed. The address of the page you see after sending the contact form includes the enquiry’s reference number, and Google’s and Meta’s tags read that address as they do on any page. The Cookie Policy sets out in full what each receives.
If your browser sends a Global Privacy Control signal, Marketing is off for you in every region, even if you accepted it earlier; the signal does not turn Analytics off. Do Not Track is not acted on.
5. Why we use it
We use personal information to provide, secure and improve the services, and to meet obligations we cannot decline. Specifically: to assess and open merchant accounts, including identity verification and sanctions screening; to authorize, route, settle and reconcile transactions; to detect and prevent fraud and unauthorized access; to manage chargebacks and provide evidence to issuing banks; to provide support and respond to you; to answer an enquiry sent through our website and assess whether our services fit the business that sent it; to measure how our websites are used and which pages and advertising bring merchants to us, including by storing with an enquiry the visit history section 4A describes; to bill, collect and account for fees; to meet legal, tax, audit and Card Network obligations; to produce aggregated statistics that do not identify a person; and, where you have consented or where permitted by law, to send marketing about our products and services, as section 11 describes.
We do not use cardholder transaction detail to build advertising profiles, and we do not disclose one merchant’s data to another.
6. Who we share it with
Banks and card networks, vetted suppliers, the analytics and advertising services our website uses, and authorities when the law requires it.
We disclose personal information only as described here. Every service provider that handles it on our instructions is bound by contract to use it solely for the service they provide us, to protect it, and to return or delete it when the engagement ends. Google, Meta and Microsoft, which provide our website’s analytics and advertising measurement, do so under their own terms, as the bullet on them below explains.
- Acquiring banks, Card Networks and processors, to authorize, settle and reconcile transactions and to manage disputes. Their handling is governed by their own rules, including the Visa and Mastercard operating regulations.
- Service providers acting on our instructions, for cloud hosting, communications, analytics, identity verification and sanctions screening, fraud tools, and customer support. The Subprocessors page sets out these categories, what each is engaged to do and what it can reach; section 9 of that page publishes the register of providers, states that it is complete as to the parties it names but is not the whole supply chain, and sets out how to obtain the current full list and how to ask for the country a provider processes in where the register does not state one.
- Google, Meta and Microsoft, for our website’s analytics and advertising measurement, as section 4A describes and depending on where you are and on your cookie choices. Each provides that service under its own terms, which set what it may do with what it receives; Meta may use what it receives for its own purposes.
- Professional advisers — auditors, lawyers and insurers — under a duty of confidence.
- Regulators, law enforcement and courts, where we are legally required to disclose, or where disclosure is necessary to investigate suspected fraud or to protect our rights, property or safety, or those of others.
- An acquirer or successor, in a merger, financing, reorganization or sale of assets, subject to confidentiality and to this policy continuing to apply to the information transferred.
- Other parties, with your consent or at your direction — for example, when you connect a third-party integration.
7. How long we keep it
Payment records have legally mandated retention. We cannot delete them on request, and we say so rather than promising otherwise.
We keep personal information only as long as needed for the purpose it was collected for, or as long as the law requires, whichever is longer. Retention is set by category, not by a single site-wide period.
- Identity verification and onboarding records: retained for the period required of a reporting entity under Canadian anti-money-laundering legislation, which runs from the end of the business relationship.
- Transaction and settlement records: retained for the period required for tax, audit and Card Network dispute purposes.
- Stored payment credentials: held in the card vault as tokens and removed when a merchant deletes the customer record or the account closes. Consistent with our security practices, cardholder data is retained for up to 24 months of inactivity.
- Support communications: retained while the account is open and for a reasonable period afterwards, so a later question about a past issue can still be answered.
- Enquiries sent through the website’s contact form, with everything stored with them: 24 months from sending, then deleted. Job applications: 12 months.
- Our record of a browser’s visits to the website: 12 months after the last visit, then deleted, and at once when its owner chooses “Essential only”.
- What Google, Meta and Microsoft receive from the website: kept by them for the periods their services and terms set.
- Opt-outs and other marketing preferences: retained indefinitely, because we need a record of an opt-out in order to honour it — except that a consent given by ticking a box on the website’s contact form is recorded with the enquiry and deleted with it.
8. Your rights, and how to use them
You may ask us to give you access to the personal information we hold about you, correct it if it is inaccurate or incomplete, delete it where no legal obligation requires us to keep it, provide it in a structured, commonly used technical format or transfer it to another organization, withdraw a consent you previously gave, or stop using it for marketing.
For what our website holds, that means a copy of the enquiries you sent and of everything stored with them, including the visit history linked to them; their correction; or their deletion, which removes the enquiries and our record of the visits linked to them. If you never sent an enquiry, our record of your browser’s visits is not linked to your name: choosing “Essential only” deletes it, and we will delete it if you send us the identifier held in your browser, as the Cookie Policy explains. Deletion by RapidCents does not reach what Google, Meta and Microsoft have already received; they hold it under their own terms. To stop our website disclosing information about your visits to Google and Meta for advertising, turn Marketing off under “Cookie settings”, or have your browser send a Global Privacy Control signal.
Residents of Quebec additionally have the right to be informed when a decision about them is made exclusively by automated processing and to submit observations on it, and the right to have information de-indexed in the circumstances Law 25 provides. Residents of United States jurisdictions with comprehensive privacy laws may exercise the rights those laws grant, and may appeal a decision we make on such a request.
Write to the Privacy Officer at the address in section 12. We will confirm receipt, may ask for information to verify who you are so that we do not disclose your data to someone else — for a request about an enquiry, by sending a request for confirmation to the email address the enquiry gave — and will respond within thirty (30) days, or tell you why more time is needed and when to expect an answer. There is no charge for a reasonable request.
Withdrawing consent does not affect processing that already took place, and some withdrawals mean we can no longer provide part of the service — we will tell you when that is the case rather than withdrawing the service silently. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, to the Commission d’accès à l’information du Québec, or to the equivalent authority in your jurisdiction.
9. Where information is stored and transferred
RapidCents operates in Canada and the United States and uses cloud infrastructure and service providers that may store or process personal information outside the province or country where you live, including in the United States. Where that happens, the information is subject to the laws of that jurisdiction and may be accessible to its courts, law enforcement and national security authorities. Google, Meta and Microsoft, which provide our website’s analytics and advertising measurement, process what they receive in the United States and in other countries.
We transfer personal information only to providers bound by contract to protect it to a standard comparable to the one we apply, and we assess the privacy implications before entrusting information to a provider in another jurisdiction, as Quebec’s Law 25 requires. You may ask the Privacy Officer for information about our practices in this area.
10. How we protect it, and what happens if something goes wrong
Card numbers are replaced by tokens and held in a PCI-scoped vault rather than in ordinary application storage. Sensitive stored data is encrypted, connections require TLS 1.2 or higher, access is role-based and requires multi-factor authentication, and access to merchant data by our staff is logged. The Security page describes these controls in detail.
No safeguard removes risk entirely, and we do not claim otherwise. If a confidentiality incident creates a real risk of serious injury, we will notify the affected individuals and the appropriate regulators as required, including the Office of the Privacy Commissioner of Canada under PIPEDA and the Commission d’accès à l’information under Law 25, and we keep a register of confidentiality incidents.
If you believe your account has been accessed without authorization, contact us immediately. To report a security vulnerability, follow the Vulnerability Disclosure policy.
11. Marketing, email and SMS
Commercial electronic messages are sent in accordance with Canada’s Anti-Spam Legislation. Every marketing email identifies us, gives our mailing address and includes an unsubscribe mechanism that works for at least sixty (60) days. Unsubscribing takes effect promptly and never affects service messages about your account, security, billing or a legal obligation.
On our website’s contact form, consent to marketing email and consent to marketing calls and text messages are asked for separately, in two optional boxes that are unticked until you tick them, and sending the form does not depend on either. Without a ticked box, what we may do with the address and number given in an enquiry depends on where you are. In Canada outside Quebec, we may send marketing by email, by text message or by calls dialled by a person for six months after an enquiry about opening an account, and not after any other enquiry; calls made with an automatic dialler or a recorded voice need a ticked box. In the United States, we may send marketing email until you unsubscribe, and make marketing calls dialled by a person for three months after an enquiry about opening an account; we send no marketing text messages, and make no calls with an automatic dialler or a recorded voice, without your written consent. In Quebec, in Canada where your province was not recorded, and everywhere else, we send no marketing without a ticked box. The contact details in a job application are not used for marketing.
If you give us a mobile number and opt in, you consent to receive text messages from RapidCents at that number; participation is not a condition of purchase and message frequency varies. Reply STOP to any message to opt out and you will receive one confirmation message and nothing further; reply HELP for assistance. Standard message and data rates from your carrier may apply, and we are not responsible for carrier charges.
12. Contacting the Privacy Officer
RapidCents has designated a Privacy Officer accountable for compliance with this policy and for responding to requests and complaints. Write to: Privacy Officer, RapidCents Inc., 515 Consumers Road, Unit 210, North York, Ontario, M2J 4Z2, Canada, or telephone +1-844-957-2743. In the United States: 43300 Southern Walk Plaza, #166, Ashburn, Virginia 20148, or telephone +1-202-902-6226.
Tell us what you are asking for and how to reach you. If your request concerns a purchase you made from a business that uses RapidCents, include the merchant’s name — as explained in section 3, they are usually the party who decides how that information is used.
13. Children
The services are business services and are not directed at children. We do not knowingly collect personal information from a child under 13. If we learn that we have, we will delete it. A parent or guardian who believes a child has provided us with information should contact the Privacy Officer.
14. Changes to this policy
We may update this policy. The effective date and the date last revised appear at the top of the page. Where a change materially affects how we handle personal information, we will give notice at least thirty (30) days before it takes effect, by email or through the merchant dashboard. Previous versions are available from the Privacy Officer on request.
Questions about this document
Write to RapidCents Inc., 515 Consumers Road, Unit 210, North York, Ontario, M2J 4Z2, or call +1-844-957-2743. In the United States: 43300 Southern Walk Plaza, #166, Ashburn, Virginia 20148, or call +1-202-902-6226.
Frequently asked questions
Is RapidCents the controller of my customers’ information, or am I?
It depends on the activity. Where RapidCents processes a payment on your instruction, you are responsible for the customer relationship and RapidCents acts on your behalf; where RapidCents must act on its own account — verifying identity, preventing fraud, meeting a legal obligation — it acts for itself. Section 3 of the policy sets out which is which, and that decides who a customer should contact.
How do I access, correct or delete the personal information RapidCents holds about me?
Use the contact set out in the policy, say what you are asking for and how to reach you, and RapidCents will verify your identity before acting. Some information must be kept for a period the law or the card networks fix — transaction records, identity verification — and the policy says what and for how long.
Does the website collect information before I agree to anything?
In the United States and in Canada outside Quebec, yes: analytics and marketing run from the first page with no pop-up — Google Analytics, Microsoft Clarity, the Meta pixel and RapidCents’ own visit record — as section 4A of the policy sets out. In Quebec, and anywhere else, they stay off until you accept. Wherever you are, Cookie settings in the footer of every page turns them off at once.
Is information stored outside Canada?
Some processing occurs outside Canada, where a provider operates there, and may be subject to the laws of that jurisdiction. Google, Meta and Microsoft, which receive website analytics and advertising data, process it in the United States and elsewhere. The policy and the subprocessor register say which categories that applies to and what each provider has committed to.





