Privacy Policy
Last updated: March 2026
What We Collect
PaymentProviders.io is operated by EJ Tech AB, a company registered in Sweden (org.nr 559470-0154) with its registered office in Arboga. EJ Tech AB is the data controller for the personal data described in this policy (“we”, “us”, “our”).
We collect the minimum data needed to provide our service:
- Email address — collected when you log in (via a magic link, or via Google sign-in), used for authentication and communication
- Session cookie (pp_session) — a functional cookie used to keep you logged in
If you use our Matching Service, we collect additional information as described in that section below.
We do not use tracking cookies, analytics cookies, or any third-party tracking scripts. Provider pages count views in aggregate — an anonymous first-party ping carrying only the page's own address, with no cookies and no identifiers — so listing owners can see how often their profile is seen. We do not collect browsing behavior tied to you, device fingerprints, or personal data beyond your email address (and any data you voluntarily submit through the matching form).
How We Use Your Data
Your email address is used to:
- Send you magic login links for authentication
- Associate your account with claimed provider profiles
- Send transactional emails related to your account (e.g., claim approvals)
We will never sell your email address or share it with third parties for marketing purposes.
Matching Service
When you use our merchant matching service, we collect the following additional information:
- Business information — company name, website, industry, country of incorporation, business type, and a description of your products or services
- Contact details — your name and email address
- Payment requirements — monthly volume, currencies, sales channels, settlement preferences, and payment methods needed
- Optional notes — any additional context you provide
How we use this data: We use the information you submit to match you with suitable payment providers from our database. Your data is processed automatically by our matching engine to generate a shortlist of recommended providers — there is no manual human review of your submission.
Who we share it with: We do not share the business profile you submit with any payment provider unless you explicitly apply to that provider through their own onboarding flow. We never sell your data or share it with third parties for marketing purposes.
Legal basis (GDPR): We process onboarding data on the basis of your consent, given when you actively check the consent box and submit the application form. You may withdraw consent at any time by contacting us.
Retention: Onboarding application data is retained for 12 months after submission, or until you request deletion, whichever comes first.
Data Storage
Your data is stored on servers located in Germany (EU). All data remains within the European Union.
Third-Party Services
We use the following third-party services:
- Stripe — for processing payments when providers purchase premium features. Stripe handles all payment data; we do not store credit card information. Stripe Privacy Policy
- Google — only if you choose “Continue with Google” to sign in. Google confirms your identity and we receive your verified email address — nothing else from your Google account. Google Privacy Policy
- Resend — for sending transactional emails (magic links, notifications). Resend Privacy Policy
Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your personal data
- Data portability — request an export of your data in a machine-readable format
- Restriction — request that we limit processing of your data
- Objection — object to processing of your data
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
Cookie Policy
We use only strictly functional cookies:
- pp_session — the session cookie that keeps you logged in. It contains a signed session token and expires after 30 days, or immediately when you sign out.
- Google sign-in cookies — if you sign in with Google, a few short-lived security cookies protect the sign-in round-trip (CSRF state). They expire within 10 minutes and are deleted as soon as the sign-in completes.
We do not use analytics cookies, advertising cookies, or any other tracking cookies. No cookie consent banner is needed because we only use a strictly necessary functional cookie.
Data Retention
We retain your email address and account data for as long as your account is active. If you request account deletion, we will remove your personal data within 30 days.
Transactional data (e.g., Stripe payment records) is retained as required by law.
Children's Privacy
PaymentProviders.io is a business-to-business service and is not directed at children under 16. We do not knowingly collect data from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Last updated" date at the top of this page.
Contact
For privacy-related questions or requests, contact us at [email protected].