Legal Policies
Protect Your Business
Privacy Policy
2Checkout takes the protection of Your privacy and personal data very seriously and is committed to ensuring that You continue to trust Us with Your personal data! We want You to understand how We protect Your privacy when We obtain personal data from You, how We use Your personal data, what Your rights are in this respect and how We safeguard it while You use and interact with our services, visit our websites and use its functionalities. For this reason, We are providing You with this Privacy Notice which We kindly ask You to read before You engage with us.
By using our services, You acknowledge that You have read this Privacy Notice and understood that any personal data You provide to us is supplied at Your own free will and shall be used in accordance with the purposes described in this Notice. If You do not understand this Privacy Notice, We recommend You do not use our services.
We reserve the right to change and/or update our Privacy Notice at our discretion and at any time. Where required, You will be notified accordingly and in advance about these changes and or updates, which We kindly ask You to read carefully and make sure You understand. Nevertheless, We advise You to check our Privacy Notice from time to time to ascertain whether any changes took place. For additional details concerning changes to this Privacy Notice, please see Section 18.3 of the 2Checkout Terms and Conditions.
1. About us
Verifone Payments B.V. (formerly known as Avangate B.V.), Avangate Inc., 2Checkout.com Inc or any of their affiliate companies part of the Verifone Payments group doing business as 2Checkout (each "Verifone", "Avangate", "2Checkout", "We," "Us" or "Our") is the Data Controller of Your personal data and will process it in accordance with applicable Data Protection Legislations.
2. Applicability
This Privacy Notice applies to the following individuals with which We envisage to interact in the course of our business:
- Merchants, their legal representatives, ultimate beneficial owners and authorised representatives;
- Shoppers/End-users/customers/payees of merchants involved in any transaction with our payment institution;
- Partners and Affiliates; and
- Visitors of our website.
3. Personal data collected and purposes of processing
As used in this Privacy Notice, 'personal data' means any information that can be used to individually identify You, directly or indirectly, alone or along with other information. The categories and volume of personal data that We collect vary depending on: i) the identified relationship We have with You; and ii) our purposes for processing Your personal data.
You can decide at any time not to provide us with the requested personal data. However if You refuse, You may not be able to make purchases, enlist services or access certain options on the Website or through other means.
2Checkout collects personal data to set up and manage accounts for our ecommerce services and to handle orders of goods and services from 2CO. In specific cases, personal data about You is collected by Us automatically. We may collect personal data about You via automated means (such as cookies) when You interact with our ads, apps, or visit Our Websites. In such a case, personal data We collect may include IP address, browser type, operating system, mobile device identifier, geographical area, referring URLs. Customarily, the collection of personal data is done in the following manner, but not limited to:
- Directly from You through:
- manual input and/or intervention from You where We ask You for information that includes Your personal data; and/or
- automatically generated through Your interaction with our services and/or website.
- Indirectly about You through:
- publicly available sources; and/or
- third parties.
We will interact with You (a) online, (b) offline or (c) when You interact with online targeted content (such as advertisements) that We or Our service providers provide to You via third party websites or applications.
You may also provide personal data about others (for example when You place an Order on other's behalf). If so, You are responsible for the entire data You provide to Us (and We assume that You are authorized to give such data). In case the personal data provided by You concerns other persons, it will be Your responsibility to obtain prior authorization.
Depending on Your relationship with us, We collect the following categories of personal data:
A. Merchants and their affiliates or partners
The personal data We collect and process about merchants or their affiliates or partners includes but is not limited to: full name, date of birth, postal address and contact details (e-mail address and phone number); financial and credit card information; nationality and country of residence; information on government-issued identification documents and copies; documents confirming the right of representation; and other personal data that We may need to:
- Conduct our due diligence on Your business and conclude a service agreement with You.
- Carry out our obligations relating to Your contract and notify You of any changes or updates to our services, terms of service, scheduled maintenance, billing issues, etc.
- Comply with our legal obligations on anti-money laundering and counter-terrorist financing legislation. In such situations, We may use and process personal data about You from publicly available sources, credit reference or fraud prevention agencies or check data against government sanction lists, either directly, or using identity verification providers or due diligence and screening information providers, as necessary to confirm Your identity and prevent fraudulent activities and money laundering.
- Comply with any reporting obligations or investigations from government authorities or financial institutions; fulfilling other financial, tax, legal, compliance or administrative functions.
- Recover debt and collections; detecting and preventing fraud; detecting and preventing violations of our legal agreements.
- Analyse and understand how our services are used based on Your interaction with them for improvement and further development.
- Administer our services for internal operations, including security and business continuity, troubleshooting, data analysis, testing, research, statistical and survey purposes.
- Provide You with personalised offerings of our products and services through emails if You have subscribed to such communications. You may unsubscribe from such personalized offers. You have the right to withdraw Your consent or to object to personalized direct marketing or commercial activities, including profiling related to these activities.
- to inform You about Product upgrades; special offers; other products, services and information (including from third parties); market research; or completing surveys or evaluations; if You have opted to receive such communications.
As a general rule, We avoid processing special category personal data. However, where it is required by law, We may process special categories of personal data such as information about race, ethnic origin, politics, biometrics (where used for ID purposes), health data and criminal convictions and offences. When this is the case, We shall only process this information in strict accordance with the law governing this type of information and apply strict security measures.
B. Merchants' shoppers/end-users/customers/payees involved in any transaction with Us
The personal data We collect and process for our shoppers are: name, surname, billing and shipping address, email address, phone number; transaction details, such as information about the Products You buy, bank account information, credit card number and other credit card details; renewal options, geo-location data of Your mobile or other device, including GPS-based, Wi-Fi-based, or cell-based location information and any other data needed to:
- Register Your purchase (for warranty, technical support, or other purposes) and facilitate the payment between You and the merchant.
- Process an Order from You, including processing Your online payment and notifying You of the Order status.
- Invoice You for the products and services You ordered.
- Authenticate and validate payments to mitigate and protect against fraudulent activities, for example if You are the victim of identity theft, if Your personal data was disclosed or hacked.
- Facilitate payments dispute or chargeback with a financial institution, if You exert Your right of refusal on purchases made or if Your transaction is subject to such situations.
- Create and maintain Your 2Checkout myAccount.
- Analyse and understand how our services are used based on Your interaction with them for improvement and further development.
- Administer our services for internal operations, including security and business continuity, troubleshooting, data analysis, testing, research, statistical and survey purposes.
- Provide You with shopper and technical support.
- Comply with our legal obligations on monitoring fraud, money-laundering and reporting purposes to government authorities or financial institutions.
C. Partners and affiliates
We may need to process the following personal data about You: name, email, phone number, email address, postal address, bank account details for the following purposes:
- Promote our services through performance based marketing.
- Monitor and report on affiliate performance.
- Pay out commission.
- Send out direct marketing communications, and other communication if You join our affiliate network.
D. Visitors of our website and services
When You visit our website or contact us, We collect the following information from You: name, contact details, country and cookies. The cookies used on our Website do not collect directly identifiable personal data such as name, address, email address etc. However, certain cookies may collect information about the device used, which, when combined with other information, it becomes personal data and can indirectly identify You.
Cookies allow us to automatically collect information about You and Your online behaviour, as well as Your device (for example Your computer or mobile device) and browser used, in order to ensure proper functioning and security of our website. We may also use this information to collect statistics about the number of unique visits of our website and perform analytics.
The cookies We use are necessary for the well-functioning of our website. You can set Your browser to block, delete previously-stored cookies or alert You about these cookies, but some parts of the site may become inaccessible or will not function properly. For more information on what are cookies and how We use them, please consult our Cookie Policy.
4. Legal basis for processing
Our focus is to process Your personal data only for specific purposes that allow Us to service You in the best possible manner, when We have a valid legal basis to do so and as permitted by law as follows:
- Performance of Contract – We will process Your data where it is necessary for the performance of a contract to which You are a party or to take steps at Your request before entering into such a contract. As well, if You are a card-holder or alternative payment method user making a payment to a merchant using our services to process Your payment, We may process Your data on the basis of the agreement that We have with the merchant and terms and conditions You agree to.
- Compliance with a legal obligation – We will process Your personal data where it is necessary for compliance with a legal obligation that We are subject to. More precisely, We use Your personal data to comply with anti-money laundering and counter-terrorist financing legislations requirements, fiscal and accounting laws and any other laws applicable to our industry and requests and investigations from relevant authorities and financial institutions.
- Legitimate Interest – We will process Your data in our legitimate interest of our business in conducting and managing our business to enable us to give You the best service and the best and most secure experience. We make sure We consider and balance any potential impact on You (both positive and negative) and Your rights before We process Your personal data for our legitimate interests. We do not use Your personal data for activities where our interests are overridden by the impact on You (unless We have Your consent or are otherwise required or permitted to by law). You can obtain further information about how We assess our legitimate interests against any potential impact on You in respect of specific activities by contacting us. Depending on the relationship You have with Us, the processing necessary to fulfil Our legitimate interest may be: to remind You about Your abandoned shopping cart, to request Your feedback, to create and maintain Your 2Checkout myAccounts, to protect against, identify and prevent abuse, fraud and other types of crime, claims and other liabilities. You are entitled to oppose to such processing, and We will review Your request and respond to it on a case by case basis.
Generally, We do not rely on consent as a legal basis for the processing of Your personal data although We will get Your consent before sending direct marketing communications to You via email or text message. You have the right to withdraw Your consent at any time by contacting us.
Some data, such as the types of used services and how many users We receive daily, may be used by 2Checkout for statistical, marketing, promotional, or any other lawful purposes. This kind of information is collected in aggregate/statistical form, without identifying any user individually.
In any case, We will not subject You to a decision based solely on automated processing that produces legal effects concerning You or similarly significantly affects You, unless You explicitly consented to the processing, the processing is necessary for entering into, or performance of a contract between You and Us, or when We are legally required / entitled to use Your personal data in this way, for example to prevent fraud.
5. Children's privacy
You must be older than 16 years in order to place an order with Us if You reside in EU. Otherwise, children's personal data is cautiously processed (only with specific safeguards).
We do not knowingly solicit or collect personal data from children below the age of 16 when offering services of an informational society (except if explicit consent from parent or custodian is obtained in prior). This is applicable only for those residing in EU.
If We discover that accidentally We collected personal data from a child below this age, We will remove that child's personal data from Our records as soon as reasonably possible.
6. Data Sharing
In order to process Your Order, We will share Your personal data with our partners.
Without any prior notice, 2Checkout may share Your personal data with third parties for other purposes, but only in the following circumstances:
- Internally: We may share personal data about You across our businesses, with our group of companies to which 2Checkout belongs for the purpose of internal assistance and administrative matters and daily activities in line with this Privacy Notice. In the event of our reorganization, merger or acquisition by another company or in the event of the transfer of our business on the basis of our legitimate interest in consolidating, expanding or streamlining our business, Your personal data might be shared. We will notify You if such instances happen in due course and as soon as possible.
- Affiliates: we may provide Your personal data to affiliates or related companies for legitimate business purposes such as performance based marketing.
- Merchants and their affiliates or partners: 2Checkout is an ecommerce platform that enables You to access worldwide Products and as such 2Checkout must share Your personal data for the purpose of You processing Your Order.
- Service providers: 2Checkout may engage service providers, consultants, external partners, agents or contractors to provide services on its behalf, including administering our media and services available to You. These third parties may come to access or otherwise process Your personal data in the course of providing these services. 2Checkout requires such third parties, to comply with all relevant data protection laws and security requirements in relation to Your personal data, in accordance with their contractual and confidential contractual obligations.
- Public Authorities: 2Checkout may disclose Your personal data if it is required to do so by law or if, in Ours good faith judgment, such legal disclosure is reasonably necessary to comply with legal processes, respond to any claims or in relation to our efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing.
- Financial institutions: We share personal data with other financial institutions such as banks or other payment service providers to allow payment transaction between a payee and payer. These institutions are independent from our business and processing of Your personal data will be subject to their Privacy Notice and Terms and Conditions.
Some of Our services are provided through sites that bear Our partners' or suppliers' names and trademarks and are not in Our control. These Websites may contain links or other devices that take You to other websites that are also not in Our control. Some of those websites may provide products or services to You directly or on Our behalf. We are not responsible for any aspect of such websites, including, without limitation, the privacy practices, products, services, or content of such websites. This Privacy Notice will not apply to such other websites. Rather, Your activity and the information that You provide at such other websites will be subject to the privacy policy and other terms and conditions posted on such other websites.
7. Your rights
You have specific rights in respect of Your privacy and data protection and We foster an environment facilitating their exercise as follows:
- access Your personal data, rectify it, restrict or object to its processing, or request its deletion.
- to receive a copy of the personal data You provided to Us or ask us to transmit it to another company.
- withdraw any consent You provided.
- to opt out of some collection or uses of Your personal data, including the use of cookies and similar technologies, the use of Your personal data for marketing purposes, and the use for data analyses.
- where applicable, to lodge a complaint with Your supervisory authority. More information on the local Supervisory Authority can be found here: https://edpb.europa.eu/about-edpb/about-edpb/members_en
We pay the utmost attention to the confidentiality of all personal data and reserve the right to verify Your identity if You submit a request for personal data to avoid a potentially undesirable situation for another person to illegally exercise a right on Your behalf. We may also contact You to ask You for further information in relation to Your request to speed up our response. We will require You to verify Your identity by providing us with identifying information such as Your personal email address, personal telephone number, home address, and/or other information that We can match with the personal data We haves already collected about You to verify Your identity.
You may use an authorized agent to exercise Your rights. We will require Your authorized agent to provide us with either (1) a power of attorney authorizing the authorized agent to act on Your behalf or (2) Your written authorization permitting the authorized agent to request access to Your personal data on Your behalf. Further, We will require You or Your authorized agent to provide us with identifying information to verify Your identity. We may also require You to either verify Your own identity directly with us or directly confirm with us that You provided the authorized agent permission to submit the request.
In accordance with the applicable law, 2Checkout will provide You with access to Your Personal data and, as appropriate, the right to intervene in respect of Your Personal data. You may also be entitled to object to the processing of Your Personal data by 2Checkout or to request the deletion of Your Personal data, in which case, if 2Checkout in its sole discretion deems such Personal data as mandatory, 2Checkout may no longer permit You to engage in certain activities.
You may later choose to unsubscribe from receiving certain types of communications from us by following the unsubscribe directions in Our communications. 2Checkout will endeavor to update Your privacy preferences in 2Checkout's records with Your latest preference in a timely manner.
For Your California Privacy Rights, please visit our 2CO California Privacy Policy
8. Storage Location
If You are residing in the European Union, Your Personal data may be transferred outside the European Union or the European Economic Area.
Personal data provided to 2Checkout by You, the Merchants, or other third parties, is primarily processed and stored on the servers located at Our offices within The Netherlands and/or the United States. We may change the location of the servers from time to time to other countries and without prior notice to You; however, Personal data will continue to be protected in accordance with this Privacy Notice.
Where such recipients of data are located in third countries that do not provide an adequate level of protection or for which the European Commission has not issued an adequacy decision, 2Checkout has in place contractual relationships with each such recipient that include international data transfer agreements and standard contractual clauses as approved by the European Commission or other supervisory authority where required, intended to ensure an adequate level of protection. We will always conduct rigorous due diligence to ensure there are no risks to such transfers and Your personal data is protected and secured.
We participate in the United States - European Union Privacy Shield and Swiss - United States Privacy Shield Frameworks. Please see Our Privacy Shield Policy. We are currently monitoring changes in this area and ensure We adhere to and implement any new measures as required.
9. Data Retention and Security
We installed adequate safeguards to secure Your personal data and We also implemented specific time periods so that to ensure that Your data is not retained longer than necessary for the stated purpose.
Data Retention. We will only retain Your personal data for as long as You continue to use the Website or Products, and thereafter as permitted or required by applicable law, also taking into account our need to answer queries or resolve problems, provide improved and new services, and comply with legal requirements under applicable laws. This means that We may retain Your personal data for a reasonable period after Your last interaction with us or after the termination of business relationship with us (as required by anti-money laundering/counter terrorism financing legislation and fiscal law) otherwise no longer than what is necessary to comply with our legal obligations and protect our legitimate interests to defend against a claim.
When the personal data that We collect is no longer required in this way, We anonymize or delete it in a secure manner.
Data security. 2Checkout has implemented industry-standard measures to protect the security of the Personal data We collect via the Website. For example, We use (SSL - Secure Socket Layers), a firewall and a digital certificate issued by VerisignTM to protect certain of Your Personal data, and We are PCI DSS (Payment Card Industry Data Security Standard) certified. No one can guarantee, and We do not guarantee, that Your Personal data is completely secure at all times, however We ensure You that the security of Your personal data is Our primary concern. You are also responsible for maintaining the confidentiality of Your Personal data to protect it against unauthorized access or use.
10. Contact us
We have a dedicated Data Protection Officer for You to contact in any privacy matters: dpo@2checkout.com.
For the purpose of exercising Your rights, You shall submit a written request to 2Checkout in accordance with the applicable law to the applicable 2Checkout office identified in the "Contact Us" section of the Website, as per the dedicated contact details to dpo@2checkout.com.
In addition, if You believe that 2Checkout has not complied with this Privacy Notice with respect to Your Personal data, please submit a sufficiently detailed complaint to info@2checkout.com, or by mail to the applicable 2Checkout office identified in the "Contact Us" section of the Website. We will promptly investigate Your complaint. Thereafter, We will take all measures We deem necessary to remedy the issues outlined in Your complaint that We, in Our sole discretion, view as justified.
All Your options and messages will be responded based on applicable legal requirements (one month since Your request or longer if necessary). Nevertheless, please consider that in order to implement Your requests or options We may need several days due to technical reasons (during such period We may continue to process Your personal data based on Your past options).
If You have any questions about this Privacy Notice, please send Your inquiry to info@2checkout.com, or to the applicable office identified in the "Contact Us" section of the Website.
1. Purpose and intent
Verifone Payments B.V. (formerly known as Avangate B.V.), Avangate Inc., 2Checkout.com Inc or any of their affiliate companies part of the Verifone Payments group doing business as 2Checkout (collectively, “the Company”) are committed to protecting the privacy and security of your personal information. This California privacy policy describes how we collect, use, retain, secure and disclose personal information about you (our “Information Practices”). This privacy policy is in addition to our main Privacy Notice located at: https://www.2checkout.com/legal/privacy/ and is intended to comply with the California Consumer Privacy Act, California Privacy Rights Act, and applicable regulations (together the “CPRA”).
It is important that you understand this California privacy policy, together with any other privacy notices we may provide on specific occasions when we are collecting or processing personal information about you, so that you are aware of how and why we are using such information. If you have any questions about this privacy policy or our Information Practices, please contact us at: dpo@2checkout.com.
If you wish to access this California privacy policy in an alternate format or require an accommodation to access this privacy policy, please contact us at: dpo@2checkout.com.
2. Data protection principles
We collect, use, retain, and share your personal information in accordance with certain data privacy and data protection principles. Specifically, the personal information we collect about you is:
- used lawfully, fairly and in a transparent way;
- collected only for valid purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes;
- reasonably necessary and proportionate to achieve these purposes;
- accurate and kept up to date;
- kept only as long as necessary for these purposes; and
- kept securely.
If we intend to collect, use, retain, or share your personal information for any purpose that is incompatible with the purposes for which your personal information was collected, we will obtain your consent to do so.
For the purposes of this privacy policy, “personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
3. Personal information we collect and how we collect it, use it, and retain it
We collect, receive, use and retain personal information for the following purposes. However, we do not:
- sell your personal information;
- share or disclose your personal information to third parties other than the entities or service providers listed below;
- share or disclose your sensitive information to third parties for purposes other than those listed below or otherwise permitted by the CPRA;
- sell or share the personal information of consumers under 16 years of age; or
- permit third parties to collect your personal information on our behalf other than our service providers listed below.
The categories of Personal Information we have collected during the previous twelve months include:
4. How we share personal information
We may disclose your personal information to the following categories of recipients, including for the business purposes described above:
- Our affiliate companies;
- Our trusted third-party services providers and partners who assist us in providing our products and services and operating our business;
- Competent law enforcement agencies, courts, and government agencies to comply with our legal obligations and exercise our legal rights;
- Appropriate entities in connection with any proposed purchase, merger, or acquisition; and
- Other persons and entities with your consent to the disclosure.
5. Your privacy rights
As a California resident, you have the following privacy rights regarding your personal information:
- The right to know and right to access the personal information we have collected about you, including the categories of personal information; the categories of sources from which the personal information is collected; the business or commercial purpose for collecting, selling, or sharing personal information; the categories of third parties to whom the business discloses personal information; and the specific pieces of personal information the business has collected about the consumer;
- The right to delete personal information that we have collected from you, subject to certain exceptions;
- The right to correct inaccurate personal information that we maintain about you;
- The right of portability, or right to have us transfer your personal information to other persons or entities upon your request; and
- The right not to be discriminated against for exercising your of privacy rights.
You can exercise your right to know, delete, or correct your Personal Information by submitting a request via email at: dpo@2checkout.com. To protect the security of your personal information, we will require you to verify your identity by providing us with identifying information such as your personal email address, personal telephone number, home address, and/or other information that we can match with the personal information we haves already collected about you to verify your identity.
You may use an authorized agent to exercise your right to know, delete, or correct your Personal Information. We will require your authorized agent to provide us with either (1) a power of attorney authorizing the authorized agent to act on your behalf or (2) your written authorization permitting the authorized agent to request access to your personal information on your behalf. Further, we will require you or your authorized agent to provide us with identifying information to verify your identity. We may also require you to either verify your own identity directly with us or directly confirm with us that you provided the authorized agent permission to submit the request.
6. Data security
While no data security system can fully protect personal information from unauthorized data breaches, we have implemented reasonable safeguards and controls, consistent with its legal obligations under California and other local, state and federal laws. The Company is committed to: (i) seeking to safeguard all personal information that you provide to us; (ii) seeking to ensure that it remains confidential and secure; and (iii) taking all reasonable steps to ensure that personal privacy is respected. All our data is stored in written or electronic form on our servers and computers and in various physical locations. We maintain physical, electronic and procedural safeguards to protect your personal information from misuse, unauthorized access or disclosure and loss or corruption by computer viruses and other sources of harm. We restrict access to personal information to those staff members of the Company and our services providers who need to know that information for the purposes identified in our privacy policy and privacy notices.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
7. Personal information of minors
You must be older than 16 years in order to place an order with Us. Otherwise, children's personal information is cautiously processed (only with specific safeguards).
We do not knowingly solicit or collect personal information from children below the age of 16 when offering services of an informational society (except if explicit consent from parent or custodian is obtained in prior).
If We discover that accidentally We collected personal information from a child below this age, We will remove that child's personal information from Our records as soon as reasonably possible.
8. Changes to this privacy policy
As we strive to improve our practices, we may revise the Company’s privacy policy from time to time. This privacy policy is not a contract and we reserve the right to change this policy at any time and to notify you of those changes by posting an updated version of this policy. It is your responsibility to check this policy from time to time for any changes.
This privacy policy was last updated on February 9, 2023.
9. Questions and further information
If you have any questions or would like further information regarding this privacy policy or our privacy practices, please contact us at: dpo@2checkout.com.