Merchantpayd ← Back to home

Privacy Policy

Last updated: 17.09.2026

Undercover Payments sp. z o.o.

Registration Number: 0001069394

Registered Address: ul. Bartycka 22B/21A, 00-716 Warszawa, Mazowieckie, Poland

This Privacy Policy describes how Undercover Payments sp. z o.o. ("Merchantpayd," "we," "us," or "our") collects, uses, stores, and protects personal data in connection with our website and payment platform. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Polish data protection law.

1. Who We Are

Undercover Payments sp. z o.o. is the data controller for personal data processed through the Merchantpayd platform — meaning we determine the purposes and means of that processing. Our contact details are at the bottom of this page.

2. Personal Data We Collect

We collect the following categories of data to operate the platform:

  • Account data: name, email address, phone number, and password (stored as a salted hash, never in plain text) when you register as a merchant or agent.
  • Verification data: business registration documents, beneficial-owner identity information, and related KYB documentation, where required to activate certain account features.
  • End-user KYC data: where KYC is required, we may collect and verify identity information such as full legal name, date of birth, residential address, tax identification information where applicable, government-issued identity documents, selfie and/or liveness verification, purpose of transaction, occupation or source of income, and source-of-funds information or additional supporting documentation where enhanced due diligence is required.
  • Buyer checkout data: when a buyer completes a checkout, we collect the information they provide (name, email, phone, date of birth, country) to process that specific payment and pass required fields to our payment providers. Where the transaction requires KYC, additional identity information may be collected and verified through our identity verification provider.
  • Transaction data: payment amounts, currencies, timestamps, wallet addresses, and blockchain transaction hashes associated with settlements.
  • Technical data: IP address and basic request metadata collected automatically as part of normal web server operation.

3. Legal Basis and Purpose of Processing

We process personal data under the following legal bases recognized by the GDPR:

  • Contract performance: to create and manage your account, process payments, and provide the services you or your business signed up for.
  • Legal obligation: to meet know-your-business (KYB), know-your-customer (KYC), anti-money-laundering, counter-terrorist financing, sanctions-screening, and financial record-keeping requirements that apply to our activities.
  • Legitimate interests: to maintain platform security, detect and prevent fraud, and improve reliability — balanced against your right to privacy.
  • Consent: for anything not covered above, such as optional marketing communications, which you can withdraw at any time.

4. How We Share Data

We do not sell personal data. We share it only where necessary to operate the platform, provide requested services, comply with legal obligations, or protect the platform and its users:

  • Payment and processing partners: with payment processors, on-ramp providers, and other authorised processing or regulated service partners, to the extent needed to process a specific transaction or provide the relevant service;
  • Identity verification provider: where end-user KYC is required, with Sumsub for identity verification, document checks, liveness verification, and related KYC compliance processes;
  • KYC sharing: where an end user has successfully completed the applicable KYC process, we may share verified KYC information with authorised processing, compliance, or regulated service partners where necessary and permitted by applicable law. Where supported, we may generate and securely transmit a Sumsub KYC share token associated with the verified end user, enabling an authorised recipient to retrieve the permitted verified identity information directly through Sumsub;
  • Hosting and infrastructure providers: with service providers who store or process data on our behalf, under appropriate data-processing agreements and security measures;
  • Authorities: with regulators, law enforcement, or courts where we are legally required or authorised to disclose information;
  • Corporate transactions: with a successor entity in the event of a merger, acquisition, or sale of assets, subject to the same protections described here.

We only share end-user KYC information as verified information after the applicable verification process has been successfully completed. Access to KYC information and KYC share tokens is limited to authorised recipients and to information necessary for identity verification, AML/CFT compliance, fraud prevention, transaction processing, or other legitimate regulatory purposes.

The sharing of previously verified KYC information does not remove or restrict the receiving partner's own compliance obligations. A receiving partner may conduct its own due diligence and may require additional information or documentation where required by applicable law or its own regulatory or risk-based procedures.

5. International Transfers

Where personal data is transferred outside the European Economic Area — for example, to a service provider located elsewhere — we rely on appropriate safeguards recognized under GDPR Chapter V, such as the European Commission's Standard Contractual Clauses, to ensure an equivalent level of protection.

6. Data Retention

We retain personal data only for as long as necessary for the purposes described above. Transaction, KYB, and end-user KYC verification records are generally retained for the periods required under applicable anti-money-laundering and accounting regulations. Where KYC data is processed through Sumsub or shared through a KYC share token, retention is also subject to the applicable contractual, technical, and legal requirements governing that processing. Account data is retained for the life of the account and a reasonable period afterward for legal and dispute-resolution purposes, after which it is deleted or anonymized.

7. Security

We apply technical and organizational measures appropriate to the sensitivity of the data we hold, including encrypted connections, restricted database access, and hashed password storage. Access to KYC information and KYC share tokens is restricted to authorised persons and systems and is subject to appropriate security controls. No system is completely secure, and we encourage you to use a strong, unique password for your account.

8. Your Rights

Under the GDPR, you have the right to:

  • Be informed about how your data is used (this policy is part of that);
  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request erasure of your data, subject to our legal retention obligations (e.g. AML records);
  • Object to processing based on legitimate interests or direct marketing;
  • Request a portable copy of data you provided to us;
  • Lodge a complaint with the Polish data protection authority (Urząd Ochrony Danych Osobowych, UODO) or your own country's supervisory authority.

To exercise any of these rights, contact us using the details below. We may ask you to verify your identity before acting on a request.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We'll update the "Last updated" date when we do. Continued use of the platform after a change takes effect means you accept the revised policy.

10. Contact Us

Questions or requests regarding this Privacy Policy or your personal data can be sent to [email protected], or by post to:

Undercover Payments sp. z o.o.
ul. Bartycka 22B/21A
00-716 Warszawa, Mazowieckie
Poland
Registration Number: 0001069394