This Privacy Policy explains what information OrcaPayz ("OrcaPayz", "we", "us") collects when you use our website, dashboard, API and hosted checkout (the "Service"), how we use it, who we share it with and the choices you have. It applies to merchants who hold an OrcaPayz account and, to the extent described below, to their customers ("shoppers") who pay through a checkout we host on the merchant's payment domain.
For shopper data processed through a merchant's checkout, the merchant is the data controller and OrcaPayz acts as a processor on the merchant's instructions. Stripe processes card data as an independent controller under its own privacy policy.
1. Information we collect
Account data (merchants)
- Name, email address, password (stored as a one-way hash) and company details you provide when registering or contacting us.
- Stripe account credentials (secret and publishable keys) you connect, stored encrypted at rest and used only to act on your behalf.
- Configuration: payment domains, branding assets, routing strategy, limits, webhook URLs and webhook secrets.
- Billing and plan information for paid accounts.
Transaction metadata
- Amount, currency, status, timestamps, Stripe PaymentIntent, charge and refund identifiers and the routed payment account.
- Shopper email address and name, description and any
metadatayou attach to a payment intent. - Refund, dispute and webhook delivery records, including your endpoint's response code.
Technical and usage data
- IP address, user agent, referrer, request path, timing and error details in server logs for the dashboard, API and checkout.
- Security signals from bot-protection on public forms (Cloudflare Turnstile).
2. Information we do not collect
We never receive, process or store full card numbers, expiry dates, CVCs or other sensitive authentication data. These are entered into Stripe Elements on the checkout page and transmitted directly from the shopper's browser to Stripe. We also do not collect bank account numbers or government identification numbers.
3. How we use information
- To provide the Service: route payments, create PaymentIntents on your Stripe accounts, serve your white-label checkout, process refunds and deliver webhooks.
- To operate your account: authentication, API key management, notifications about your account or transactions, and support.
- To secure the Service: detect fraud and abuse, enforce rate limits, verify domains and investigate incidents.
- To improve the Service: aggregate, de-identified analytics about usage and reliability.
- To comply with legal obligations and enforce our Terms.
Where the GDPR or similar law applies, our legal bases are performance of a contract (providing the Service), legitimate interests (security, improvement, communication with business customers) and compliance with legal obligations. We do not sell personal data and we do not use it for third-party advertising.
4. How we share information
- Stripe — transaction details needed to create, confirm, refund or cancel payments on your Stripe accounts, and Stripe returns payment status to us via webhooks. Stripe's handling is governed by its own privacy policy and your Stripe agreement.
- Cloudflare — DNS, TLS termination and edge security for our hosts and your payment domain, bot protection on forms, and transactional email delivery. Cloudflare may process IP addresses and request metadata.
- Hosting and infrastructure providers — servers, databases, backups and monitoring on which the Service runs, under contracts that restrict use of data to providing the service to us.
- Merchants — shopper data we process on a merchant's behalf is available to that merchant in their dashboard, API and webhooks.
- Legal — where required by law, regulation, legal process or to protect the rights, safety or property of OrcaPayz, our users or the public.
- Business transfers — in connection with a merger, acquisition or sale of assets, subject to this Policy.
Where data is transferred outside the country in which it was collected, we rely on appropriate safeguards such as standard contractual clauses.
5. Cookies
We use a small number of strictly necessary cookies and do not use advertising or cross-site tracking cookies.
- Session cookie — keeps you signed in to the dashboard and protects forms against cross-site request forgery.
- Checkout integrity cookies — short-lived cookies set on the merchant's payment domain to bind a checkout session to the browser that started it, prevent replay of a checkout URL and remember 3D Secure state.
- Turnstile — Cloudflare's bot-protection widget may set a cookie or use local storage to complete its challenge on public forms.
You can block cookies in your browser; the dashboard and checkout will not function correctly without the strictly necessary ones.
6. Data retention
- Account data is retained while your account is active and deleted or anonymised within 90 days after closure, except where we must keep it longer for legal, tax or dispute-resolution purposes.
- Transaction metadata is retained for the life of the account and for up to seven years thereafter to support refunds, disputes, reconciliation and legal obligations, unless you request earlier deletion of data that we are not required to keep.
- Server logs containing IP addresses are retained for up to 30 days, or longer where needed to investigate a security incident.
- Webhook delivery logs are retained for 90 days.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. Merchants can update most account data directly in the dashboard. Shoppers should contact the merchant they paid, who can act on their request through us; we will also forward requests we receive directly. To exercise a right, use our contact form. We respond within 30 days. If you are in the EEA or UK you may also lodge a complaint with your local data protection authority.
8. Security
We protect data with TLS in transit, encryption at rest for Stripe credentials and webhook secrets, hashed passwords, least-privilege access controls, audit logging and network-level protection through Cloudflare. Outbound webhooks are signed with HMAC-SHA256 so you can verify their origin. No method of transmission or storage is completely secure; if we become aware of a breach affecting your data we will notify you without undue delay and in line with applicable law.
9. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to this Policy
We may update this Policy from time to time. We will post the revised version with a new "Last updated" date and, for material changes, notify merchants by email or a dashboard notice before the change takes effect.
11. Contact
Privacy questions and requests can be sent through our contact form. We reply within one business day.