Legal
Privacy Policy
Last updated: August 7, 2026
Rollo Payments, Inc. (“Rollo,” “we,” “us”) operates a Merchant of Record (MoR) payment platform. This policy explains how we collect, use, and share personal data when merchants use Rollo and when buyers pay through Rollo-hosted checkout.
1. Roles under data protection law
For merchant account data (business details, beneficial owners, bank accounts, API usage), Rollo is the controller. For buyer payment data processed when Rollo acts as Merchant of Record, Rollo is typically the controller of the transaction record and tax remittance data, while card-network processing may involve independent controllers or processors as required by law and network rules.
2. Data we collect
Merchant data: name, email, password hash, business legal name, address, tax identifiers, product category, expected volume, beneficial owner identity and PEP declarations, bank account details (tokenized; we store vault references and last4 only), API keys, webhook endpoints, and audit logs.
Buyer / payer data: email, billing address when collected, payment method tokens (never full PAN in Rollo application databases), transaction amounts, currency, tax amounts, device/browser metadata needed for fraud prevention, and dispute records.
Technical data: IP address, logs, cookies or similar identifiers for session security and product analytics on rollopayments.com properties.
3. How we use data
We use data to operate MoR checkout, calculate and remit taxes, screen for fraud and AML/sanctions risk, pay out merchants, provide dashboards and webhooks, enforce our Terms, comply with law, and improve platform reliability. We do not sell personal data.
4. Sharing
We share data with: card processors and acquiring partners; identity, AML, and sanctions screening providers; tax engines and tax authorities as required for remittance; cloud infrastructure and security vendors under contract; and professional advisors or authorities when legally required. Merchants receive transaction and customer data necessary to fulfill orders and support buyers.
5. Retention
Transaction, tax, and AML records are retained for periods required by financial, tax, and anti-money-laundering law (often 5–7+ years depending on jurisdiction). Account credentials and marketing preferences may be deleted or anonymized sooner after account closure where law allows.
6. Security
We apply encryption in transit, access controls, tokenization of sensitive payment and bank credentials, and audit logging. No method of transmission or storage is perfectly secure; report suspected incidents to security@rollopayments.com.
7. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing. Buyers should contact the merchant for order issues and privacy@rollopayments.com for Rollo-controlled records. Merchants may update profile data in the dashboard or email privacy@rollopayments.com.
8. International transfers
Rollo may process data in the United States and other countries with appropriate safeguards (such as standard contractual clauses) where required.
9. Contact
Rollo Payments, Inc. — privacy@rollopayments.com. For EU/UK inquiries, request our data protection contact via the same address.