Use a computer

For full performance and fluidity, please open Pay Engineers on a desktop or laptop. On mobile, the experience is limited — especially authenticated sections and advanced tools after login.

Legal

Privacy Policy

How we handle personal data when you visit Pay Engineers, create an account, submit a project, use compliance tooling, exchange documents or contact our teams.

Last updated

July 19, 2026

Transparent policies

website, portal & services

Questions welcome

we reply within 24h

Privacy Policy

Privacy Policy

Last updated : July 19, 2026

01

1. Who we are and what this policy covers

Pay Engineers (“we”, “us”, “our”) is a specialised payment infrastructure studio. Since 2012 we have designed and built custom payment processors, gateways, wallets, marketplace payout engines and related fintech platforms for banks, EMIs, marketplaces, SaaS companies and enterprises across multiple markets.

This Privacy Policy explains how we collect, use, store, share and protect personal data when you interact with Pay Engineers through our public website, intelligent payment-processor configurator, processor-order wizard, Stripe Connect workspace, authorizations & compliance portal, client document exchanges, support tickets, blog, newsletter, contact forms, complaints channel, or any authenticated client area.

It applies to visitors, registered users, client contacts, guest complainants and anyone who submits information to us in the course of exploring or buying our professional services. It does not replace a signed master service agreement (MSA), statement of work (SOW) or data processing agreement (DPA) that may apply to a specific engagement; where those documents conflict on a contracted project, the contract prevails for that project’s processing.

02

2. Scope of our services (why data is processed)

Understanding our product surface helps explain why we process data. Pay Engineers is not a generic consumer social network. We operate a B2B platform around payment engineering:

  • Public marketing site and resources (home, about, services catalogue, blog, configurator resources, Stripe workspace landing, compliance resources).
  • Intelligent configurator and report PDF generation for prospective payment-processor projects.
  • Processor order intake and project tracking for custom infrastructure builds.
  • Authorizations & compliance requests (licence packages, technical parameters, connection validation).
  • Stripe Connect workspace (account linking, packs/subscriptions and operational tooling for eligible clients).
  • Client document exchanges (send for signature, request uploads, generate contracts from templates).
  • Support tickets and one-way admin messages; public complaints & claims without requiring an account.
  • Invoicing and payment collection for professional fees (card, crypto or other configured gateways).
03

3. Categories of personal data we collect

Depending on how you use Pay Engineers, we may process the following categories of personal data. We only collect what is reasonably necessary for the purpose at hand.

  • Identity & contact: full name, business email, phone, company name, job title, country, postal or billing address where provided.
  • Account data: login identifiers, authentication records, password hashes (we never store plaintext passwords), onboarding status and privacy-acceptance version.
  • Project & commercial data: configurator answers, estimated budgets and complexity scores, order numbers, project descriptions, industry, deliverable preferences, invoice and payment status.
  • Compliance & technical onboarding: licence/document metadata, technical parameter labels, API key material you choose to store with us, test results and request status.
  • Documents: titles, reference numbers, file metadata and the files themselves (contracts, signed copies, KYC-style uploads you voluntarily provide).
  • Support & complaints: message content, attachments you upload, guest name/email/phone/company on public complaint forms, ticket references.
  • Stripe workspace: connection status, Stripe account identifiers you link, pack/subscription records and related operational events inside Pay Engineers (Stripe remains a separate controller/processor for Stripe-side data).
  • Technical & security data: IP address, browser/user agent, device type, pages viewed, approximate location derived from IP, session tokens, CSRF and consent cookies, error logs.
  • Marketing preferences: newsletter subscription status and email engagement where you have opted in.
04

4. How we collect data

We collect data directly from you when you fill forms (contact, complaints, configurator steps, orders, compliance wizard, document uploads), create or update an account, reply in tickets, or communicate with our team by email.

We also collect data automatically through server logs, session management, security tooling and — only with consent where required — analytics cookies described in our Cookie Policy.

In some cases clients provide personal data about their own employees or end users (for example contacts on an order, or names appearing in a contract). In those situations the client remains responsible for having a lawful basis to share that data with us, and we process it as a service provider under the applicable agreement.

05

5. Purposes and legal bases

We process personal data for the purposes and legal bases below (GDPR / UK GDPR style framing; similar principles apply in other jurisdictions where we operate).

  • Provide the website, portal and authenticated features — legitimate interests / contract.
  • Run the configurator, generate reports and convert configurations into processor orders — contract / steps toward a contract (pre-contractual measures).
  • Deliver professional services, milestones, documents, invoices and payment collection — contract and legal obligations (tax/accounting).
  • Operate compliance & authorizations workflows and secure parameter delivery — contract and legitimate interests (security, fraud prevention).
  • Operate Stripe Connect workspace features you enable — contract; Stripe’s own terms and privacy notice also apply to Stripe processing.
  • Answer contact messages, support tickets and complaints — legitimate interests and, where applicable, legal obligations.
  • Send transactional emails (verification codes, password resets, order updates, document notifications, invoice notices) — contract / legitimate interests.
  • Send marketing or product updates — consent (newsletter / explicit opt-in) or soft opt-in where permitted; you can unsubscribe at any time.
  • Secure the platform (abuse detection, access control, audit) — legitimate interests and legal obligations.
  • Improve products using aggregated or de-identified analytics — legitimate interests, with cookie consent where required.
06

6. Email verification, security messages and branded communications

Account security emails (such as email verification codes) and service notifications are sent from our configured transactional mailbox (for example noreply@payengineers.com). These messages may include our brand name and logo for authenticity.

We do not ask for passwords or verification codes by phone. If you receive a suspicious message claiming to be from Pay Engineers, contact us through the official Contact page rather than replying to the suspicious email.

07

7. Sharing with processors and partners

We do not sell personal data. We share data only with trusted service providers who process it on our instructions, or when required by law, or when you ask us to (for example connecting a Stripe account).

  • Hosting and infrastructure providers that store application data and uploaded files.
  • Email delivery providers used to send transactional and (if opted in) marketing messages.
  • Payment gateways configured for invoice settlement (card, crypto or other methods enabled in admin settings).
  • Stripe, when you use Stripe Connect workspace features — subject to Stripe’s agreements.
  • Professional advisers (legal, accounting) under confidentiality when needed for operations or disputes.
  • Public authorities when we are legally compelled to disclose information.
08

8. International transfers

Pay Engineers serves clients in multiple countries. Your data may be processed in countries other than your own, including where our hosting, email or payment providers operate.

Where GDPR-style transfer rules apply, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, or provider certifications, together with technical measures (TLS in transit, access controls, least-privilege administration).

09

9. Retention

We keep personal data only as long as needed for the purposes above, then delete or anonymise it, unless a longer retention is required by law (for example invoices and tax records) or needed to establish, exercise or defend legal claims.

  • Account & project records: for the life of the commercial relationship and a reasonable period afterwards for audit and disputes.
  • Configurator drafts: until completed, converted, deleted by an administrator, or expired under internal retention rules.
  • Support tickets, complaints and contact messages: as needed to resolve the matter and keep an operational history.
  • Document exchanges: for the duration of the exchange and the retention period defined with the client or by applicable law.
  • Marketing lists: until you unsubscribe or your consent is withdrawn.
  • Security logs: for a limited period necessary to investigate incidents.
10

10. Security measures

Payment infrastructure work demands a security-minded posture. We apply technical and organisational measures appropriate to the sensitivity of the data, including authenticated access to the client portal, role-based admin controls, CSRF protection, encrypted transport (HTTPS/TLS), hashed passwords, private storage for sensitive document files, and operational practices for credential rotation in compliance tooling.

No method of transmission or storage is perfectly secure. We encourage strong unique passwords, careful handling of API keys displayed in the compliance area, and immediate reporting of suspected unauthorised access.

11

11. Cookies and similar technologies

We use necessary cookies to operate sessions, security and remember your cookie choices. Optional categories (preferences, analytics, marketing) run only after you consent via our banner. Details, retention and how to change choices are described in the Cookie Policy, accessible from the footer and the cookie settings control.

12

12. Your rights

Depending on your location, you may have rights to access, rectify, erase, restrict or port your personal data, to object to certain processing based on legitimate interests, and to withdraw consent where processing is consent-based (without affecting prior lawful processing).

To exercise these rights, use the Contact page and describe your request. We may need to verify your identity before responding. You may also lodge a complaint with your local data protection authority.

If you hold a client account, many practical updates (profile details, document uploads, ticket replies) can be performed directly in the portal.

13

13. Children

Our services are directed at businesses and professionals. We do not knowingly collect personal data from children. If you believe a minor has provided data to us, contact us so we can delete it.

14

14. Changes to this policy

We may update this Privacy Policy to reflect product changes, legal requirements or operational improvements. The “Last updated” date at the top of this page will change when we do. Material updates may also be highlighted in the client portal or by email for registered users. Continued use of the platform after an update constitutes acknowledgment of the revised policy, except where consent is legally required for a new purpose.

15

15. How to contact us about privacy

For privacy questions, data subject requests or security notices, use the Contact form on payengineers.com (or the domain where this platform is hosted) and mark your message as privacy-related. If your contract names a specific data-protection contact or DPA channel, use that channel for project-specific processing.

Related documents: Terms of Service, Cookie Policy, and — for service issues — the Complaints & Claims page.

Questions about this policy?

Our team can clarify how these rules apply to your project, account or data request.