Source
Privacy policy — Checkout.com
Checked for Checkout.com on 22 Sep 2026
- Page
- https://www.checkout.com/legal/privacy-notice
- Checked
- 22 Sep 2026, 06:36 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:233986adf50a8d6841461b3da3f69c63341fc14fa0e845b790ba4de5acd15053
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Last updated Report an error
“This notice was last updated on 19 June 2026.”
-
Data controller Report an error
“This is a global notice that applies to the activities of the Checkout.com group, which includes Checkout Ltd and all affiliated companies (“Checkout”, “we”, “our”, or “us”). The Checkout entity which is the data controller and therefore primarily responsible for your personal data will depend on which Checkout entity provides you with our services in your jurisdiction.”
-
Data roles Report an error
“This notice applies where Checkout act as a data controller, but we may sometimes operate as a data processor for Merchant Customer data where we carry out instructions and process data on a Merchant’s behalf.”
-
Biometric retention Report an error
“We will delete your biometric information no later than 365 days after the date you provide it.”
-
Biometric cloud Report an error
“Your biometric information may be shared with our third-party cloud providers Snowflake Computing and Amazon Web Services.”
-
Fraud hash retention Report an error
“This data is used for fraud prevention, stored for no more than 96 hours, and does not result in permanent classification, profiling or denial of service.”
-
No data sale Report an error
“Checkout.com does not sell personal data to third parties.”
-
International transfers mechanism Report an error
“Where data is transferred from the UK or EEA to a third country that is not deemed by the EU Commission or UK Secretary of State to have adequate protections in place, we rely on the EU Standard Contractual Clauses (SCCs) or contractual clauses approved by the ICO (such as the UK Addendum to the EU SCCs) respectively, to transfer your data to that third country and ensure it remains secure.”
-
Transfer impact assessments Report an error
“We also carry out transfer impact assessments before transferring your personal data, to assess the level of risk to you and your rights and protections in that third country.”
-
Pci dss Report an error
“We are PCI DSS (Payment Card Industry Data Security Standard) Level 1 compliant, which is the highest standard set by the payment card industry to ensure that cardholder data is processed, stored, and transmitted in a secure environment.”
-
ISO 27001 Report an error
“Checkout’s systems are also ISO27001 certified.”
-
Automated decision making Report an error
“In the course of providing our services, we may make decisions using your personal data which are partially or wholly automated to help make our decisions and services secure and efficient.”
-
Fraud auto decline Report an error
“In some cases, this may lead to an automated decision for a transaction to be declined or for further information to be requested from you in order to proceed.”
-
Data subject rights Report an error
“Right to opt-out of direct marketing communications: This enables you to opt-out of receiving marketing communications from us.”
-
Marketing legitimate interest Report an error
“We process this information based on our legitimate interest in contacting you to in the course of offering or providing relevant products and services to you”
-
Kyc kyb checks Report an error
“We use your verification information, in order to validate your identity, fulfill our regulatory obligations, and conduct due diligence in the form of Know Your Customer (“KYC”) or Know Your Business (“KYB”) checks”
-
Biometric explicit consent Report an error
“We only process biometric information with your explicit consent”
-
Call recordings Report an error
“We use recordings of calls with you for training, product development and marketing purposes.”
-
Third party sharing categories Report an error
“Third party service providers: We may also use third-party service providers acting on our behalf. These service providers help us with data and cloud services, website hosting, data analysis, background screening, fraud detection and prevention, application services, advertising networks, information technology and related infrastructure, customer service, communications, and auditing.”
-
Retention principles Report an error
“We will only retain your personal data for as long as reasonably necessary to fulfil the following purposes: -to comply with any legal, accounting, tax and reporting requirements -to deliver and develop our products and services securely and effectively -to perform analysis and undertake internal research Once the data is no longer required for these purposes, we securely erase it.”
-
Brazil entity Report an error
“Checkout.com is providing the following supplemental information for individuals whose personal information is collected or held by Checkout do Brasil institiução de Pagamento Ltda. or any of its affiliated companies.”
-
Canada entity Report an error
“In Canada, your personal data is under the control of Checkout Payment Systems Canada Inc.”
-
France entity Report an error
“For data subjects in France or if your data is processed by Checkout SAS, you have the right to issue general or specific instructions regarding the fate of your Personal Data after your death, in accordance with the terms of Article 85 of French Law No. 78-17.”
-
UK ico escalation Report an error
“You must first raise your complaint with Checkout, before escalating it to the Information Commissioner's Office (ICO).”
-
California entity Report an error
“Checkout.com is providing the following supplemental information for individuals whose personal data is collected or held by Checkout LLC in the State of California as defined in the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, “CCPA”).”
-
Dnt not honored Report an error
“Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.”
-
US money transmission Report an error
“Money transmission services in the U.S. provided by Checkout US Inc. (NMLS # 1791692).”
-
Biometric temporary block Report an error
“In addition, in the event that a facial image is used multiple times in a short period of time, a temporary block (up to 96 hours) may be applied to a hash of the image.”
1 fact read from this page is not shown because it could not be confirmed on the page as captured.
Scores citing this record
- The Compliance Officer Checkout, SCA & fraud
- The Compliance Officer Licence, risk & account terms
- The Compliance Officer European sovereignty
- The E-Commerce Lead Checkout, SCA & fraud
- The E-Commerce Lead Licence, risk & account terms
- The E-Commerce Lead European sovereignty
- The Payments Engineer Checkout, SCA & fraud
- The Payments Engineer Licence, risk & account terms
- The Payments Engineer European sovereignty
- The Finance Lead Checkout, SCA & fraud
- The Finance Lead Licence, risk & account terms
- The Finance Lead European sovereignty
- The Skeptic Checkout, SCA & fraud
- The Skeptic Licence, risk & account terms
- The Skeptic European sovereignty
- The SaaS Founder Checkout, SCA & fraud
- The SaaS Founder Licence, risk & account terms
- The SaaS Founder European sovereignty