Legal

Privacy Policy

Last updated: August 7, 2026

Rollo Payments, Inc. (“Rollo,” “we,” “us”) operates a Merchant of Record (MoR) payment platform. This policy explains how we collect, use, and share personal data when merchants use Rollo and when buyers pay through Rollo-hosted checkout.

1. Roles under data protection law

For merchant account data (business details, beneficial owners, bank accounts, API usage), Rollo is the controller. For buyer payment data processed when Rollo acts as Merchant of Record, Rollo is typically the controller of the transaction record and tax remittance data, while card-network processing may involve independent controllers or processors as required by law and network rules.

2. Data we collect

Merchant data: name, email, password hash, business legal name, address, tax identifiers, product category, expected volume, beneficial owner identity and PEP declarations, bank account details (tokenized; we store vault references and last4 only), API keys, webhook endpoints, and audit logs.

Buyer / payer data: email, billing address when collected, payment method tokens (never full PAN in Rollo application databases), transaction amounts, currency, tax amounts, device/browser metadata needed for fraud prevention, and dispute records.

Technical data: IP address, logs, cookies or similar identifiers for session security and product analytics on rollopayments.com properties.

3. How we use data

We use data to operate MoR checkout, calculate and remit taxes, screen for fraud and AML/sanctions risk, pay out merchants, provide dashboards and webhooks, enforce our Terms, comply with law, and improve platform reliability. We do not sell personal data.

4. Sharing

We share data with: card processors and acquiring partners; identity, AML, and sanctions screening providers; tax engines and tax authorities as required for remittance; cloud infrastructure and security vendors under contract; and professional advisors or authorities when legally required. Merchants receive transaction and customer data necessary to fulfill orders and support buyers.

5. Retention

Transaction, tax, and AML records are retained for periods required by financial, tax, and anti-money-laundering law (often 5–7+ years depending on jurisdiction). Account credentials and marketing preferences may be deleted or anonymized sooner after account closure where law allows.

6. Security

We apply encryption in transit, access controls, tokenization of sensitive payment and bank credentials, and audit logging. No method of transmission or storage is perfectly secure; report suspected incidents to security@rollopayments.com.

7. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing. Buyers should contact the merchant for order issues and privacy@rollopayments.com for Rollo-controlled records. Merchants may update profile data in the dashboard or email privacy@rollopayments.com.

8. International transfers

Rollo may process data in the United States and other countries with appropriate safeguards (such as standard contractual clauses) where required.

9. Contact

Rollo Payments, Inc. — privacy@rollopayments.com. For EU/UK inquiries, request our data protection contact via the same address.