This document was last updated on February 2nd, 2026
Seamless Payments, Inc. (“SeamlessPay,” “we,” “our,” or “us”) provides payment processing, tokenization, fraud prevention, payment orchestration, authentication, and related financial technology infrastructure services (collectively, the “Services”).
This Privacy Policy explains how we collect, use, disclose, safeguard, and otherwise process personal data in connection with:
This Privacy Policy is designed to reflect the transparency, security, and regulatory expectations applicable to modern payment infrastructure providers and should be read together with the SeamlessPay Services Agreement and applicable Data Processing Addendum (“DPA”).
Depending on context, SeamlessPay acts either as a data processor/service provider or a data controller/business.
A. When SeamlessPay Acts as a Data Processor
We act as a processor when providing payment processing and related services to merchants. In this role:
B. When SeamlessPay Acts as a Data Controller
We act as a controller when determining purposes of processing, including:
Merchants remain responsible for providing privacy disclosures to their customers where required.
A. Information Provided Directly
We may collect:
B. Payment & Transaction Data
When Services are used:
SeamlessPay is designed to minimize storage of raw cardholder data and primarily relies on tokenization and PCI-aligned infrastructure except where operational, regulatory, or security obligations require limited retention.
C. Automatically Collected Information
When interacting with our platform or website:
D. Information from Third Parties
We may receive data from:
Where applicable, SeamlessPay processes personal data under the following legal bases:
Contractual Necessity
Legal Obligations
Legitimate Interests
Consent
We use personal data to:
Communicate operational or marketing information where permitted
SeamlessPay operates infrastructure supporting fraud detection, transaction authentication, and payment optimization.
These systems:
SeamlessPay generally does not independently make final authorization or settlement decisions; those decisions are typically made by financial institutions, card networks, or merchants.
Personal data may be shared with:
Financial Ecosystem Participants
Service Providers and Subprocessors
We may engage vetted subprocessors providing:
Subprocessors are contractually bound to confidentiality, security, and data protection obligations.
Legal and Regulatory Authorities
Where required to:
Corporate Transactions
In connection with mergers, financing, acquisitions, or asset transfers.
SeamlessPay does not sell personal data for monetary compensation.
Payment infrastructure is inherently global. Personal data may be transferred outside the country of collection, including to the United States.
Where required, safeguards may include:
These safeguards are designed to ensure appropriate protection of personal data.
We retain personal data only as long as necessary to:
Deletion may not be immediate due to backup systems, fraud monitoring needs, or regulatory retention obligations.
SeamlessPay maintains administrative, technical, and organizational safeguards appropriate for payment infrastructure providers, including:
No system is completely secure, and ecosystem dependencies may introduce risks outside our direct control.
Depending on your jurisdiction, you may have rights to:
Requests may be submitted to: privacy@seamlesspay.com
Identity verification may be required.
For transaction-specific requests, contacting the relevant merchant first is often most effective.
California residents may have rights to:
SeamlessPay does not sell or share personal information as defined under the California Consumer Privacy Rights Act.
Requests may be submitted via privacy@seamlesspay.com.
We will not discriminate against individuals exercising privacy rights.
We use cookies and similar technologies for:
Where required, cookie preferences may be managed through our consent management tools.
Our Services are intended for businesses and adults. We do not knowingly collect personal data from individuals under 18.
Our website may contain links to third-party sites. SeamlessPay is not responsible for their privacy practices.
We may update this Privacy Policy periodically. Updates will be posted with a revised effective date. Continued use of the Services indicates acceptance of the updated policy.
Seamless Payments, Inc.
2810 N Church St
Wilmington, DE 19802
Email: privacy@seamlesspay.com
Website: https://seamlesspay.com
Important Notice
This Privacy Policy is provided for transparency purposes and does not expand SeamlessPay’s contractual liability beyond limitations set forth in the Services Agreement, Data Processing Addendum, or applicable law.
This section supplements the SeamlessPay’s Privacy Policy and applies where Personal Data is subject to the European Union General Data Protection Regulation (“GDPR”), the UK GDPR, or similar Data Protection Laws. It is intended to provide transparency regarding how SeamlessPay processes Personal Data in connection with its payment infrastructure Services.
Nothing in this section expands SeamlessPay’s contractual liability beyond the limitations set forth in the SeamlessPay Services Agreement or applicable Data Processing Addendum.
Depending on the context in which Personal Data is processed:
Merchants remain responsible for providing appropriate privacy disclosures to their customers and establishing lawful bases for data collection.
Depending on how the Services are used, SeamlessPay may process:
SeamlessPay generally does not store raw cardholder data unless required for operational security, compliance, or legal obligations.
Personal Data may be processed on the following legal bases:
Contract Performance
Processing necessary to:
Legitimate Interests
Including:
These interests are balanced against individual privacy rights.
Legal Obligations
Processing necessary to:
Consent (Where Applicable)
Where legally required, consent may be obtained either directly by SeamlessPay or by merchants using the Services.
SeamlessPay provides infrastructure supporting fraud detection, authentication, and risk scoring. However:
Where automated tools are used, they are designed primarily for fraud prevention, authentication support, and security monitoring.
Personal Data may be shared with:
Such sharing is limited to what is necessary to provide Services, maintain security, or comply with legal obligations.
Because payment infrastructure operates globally, Personal Data may be transferred outside the European Economic Area or United Kingdom.
Where required, safeguards may include:
These safeguards are intended to ensure appropriate protection of Personal Data during international processing.
Personal Data is retained only as long as necessary for:
Immediate deletion may not always be technically feasible due to backup systems, fraud monitoring requirements, or regulatory retention obligations.
Individuals may have rights under GDPR or UK GDPR including:
Requests relating to merchant transactions should generally be directed first to the relevant merchant. SeamlessPay will reasonably assist where appropriate.
Individuals also have the right to lodge a complaint with a supervisory authority in their jurisdiction.
For questions regarding this GDPR disclosure, Personal Data processing practices, or to exercise applicable data protection rights where appropriate, you may contact:
SeamlessPay Privacy Team
SeamlessPay will respond to inquiries in accordance with applicable Data Protection Laws.
SeamlessPay maintains commercially reasonable administrative, technical, and organizational safeguards appropriate for payment infrastructure services. However:
This GDPR disclosure is provided for transparency purposes only and does not expand SeamlessPay liability beyond the limitations set forth in: