Legal

Privacy Policy

Last updated: 22 June 2026

Introduction

This Privacy Policy explains how CT Pay ("we", "us" or "our") handles personal information in connection with our white-label wallet and payments platform and the websites, applications and services that make up it (together, the "Platform"). It is provided as a generic, illustrative template and should be adapted to your jurisdiction and reviewed by a qualified adviser before use.

CT Pay provides the underlying technology that operators use to run their own branded payments businesses. Where an operator uses the Platform to serve its own members, merchants and end-users, that operator is the data controller for those individuals and CT Pay generally acts as a data processor on the operator's behalf. This policy describes our own practices; an operator's own privacy notice governs its relationship with its end-users.

Information we collect

We collect information needed to provide, secure and improve the Platform. The categories vary by role and how the Platform is configured by each operator.

  • Account and identity details, such as name, email address, organisation and role.
  • Authentication and access data, including credentials, API keys and session information.
  • Transaction and operational data processed through the Platform, such as wallet, settlement and order records.
  • Technical data, including IP address, device and browser information, and log and diagnostic data.
  • Communications you send to us, such as support requests and demo enquiries.

How we use information

We use information to operate the Platform, authenticate users, process transactions, provide support and keep the service secure and reliable.

  • To deliver, maintain and improve the Platform and its features.
  • To verify identities, manage access and prevent fraud and abuse.
  • To monitor performance, troubleshoot issues and maintain audit trails.
  • To communicate with you about service updates, security notices and enquiries.
  • To comply with legal, regulatory and contractual obligations.

Sharing & disclosure

We do not sell personal information. We share information only as needed to run the Platform or where required by law.

  • With operators, for whom we process end-user data under their instructions.
  • With service providers and sub-processors who support hosting, infrastructure and payment routing under appropriate contractual safeguards.
  • With authorities or third parties where required to comply with law, enforce our terms, or protect rights, safety and security.
  • In connection with a corporate transaction, such as a merger or acquisition, subject to appropriate protections.

Data security

Security is built into the core of the Platform rather than added afterwards. We apply administrative, technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure or loss.

  • Encryption of sensitive data in transit and at rest, with credentials and gateway configuration stored encrypted rather than in plain text.
  • Strict multi-tenant isolation, so each operator's data is logically separated and access is operator-scoped across services and queries.
  • Access controls, including role-based permissions, signed API requests and IP allowlisting.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security; we work continuously to strengthen our safeguards.

Data retention

We retain personal information for as long as needed to provide the Platform and for legitimate business and legal purposes, such as meeting regulatory, accounting and audit obligations. Where we act as a processor, retention periods for end-user data are generally determined by the relevant operator. When information is no longer required, we take steps to delete or anonymise it.

Your rights

Depending on your location and role, you may have rights over your personal information, such as the right to access, correct, delete, restrict or object to certain processing, and to data portability.

Where CT Pay acts as a processor on an operator's behalf, requests relating to end-user data should usually be directed to the relevant operator, who is the controller. We will support operators in responding to such requests. To exercise rights in relation to information we control, please contact us using the details below.

International transfers

The Platform may be operated and supported from, and information may be processed in, countries other than where you are located. Where information is transferred across borders, we put appropriate safeguards in place, such as recognised contractual mechanisms, to help ensure a consistent level of protection.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to the Platform, our practices or legal requirements. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. We encourage you to review this policy periodically.

Contact us

If you have questions about this Privacy Policy or our handling of personal information, you can reach us at [email protected]. If you are an end-user of an operator's branded service, please contact that operator directly, as they are the data controller for your information.