Privacy Policy
Version 2026.09.1Effective 8 September 202620 min read
Privacy Policy
1. About this Privacy Policy
This Privacy Policy explains how PaymentFlux Ltd (“PaymentFlux”, “we”, “us”, “our”) collects, uses, shares and retains personal data when you use our websites, applications and related customer-facing services (the “Platform”) and the functionality we make available through the Platform (the “Service”).
It is intended to help you understand:
- what personal data we process;
- why we process it;
- the lawful bases we rely on;
- who we share it with; and
- the rights available to you under UK data-protection law.
This Policy should be read with our Platform Terms and Cookie Policy. Nothing in this Policy removes rights you have under applicable law that cannot be limited or excluded.
2. Who we are
We are PaymentFlux Ltd.
- Company number: 17152215
- Registered office:
167–169 Great Portland Street
5th Floor
London
W1W 5PF
United Kingdom
For the processing described in this Policy that PaymentFlux determines the purposes and means of, PaymentFlux Ltd is the data controller.
Other organisations may also process related personal data as independent controllers for their own purposes. That can include, for example, your card issuer, banks involved in a transfer, Companies House in relation to public-register information, a Payment Partner such as Stripe when acting for its own regulatory or fraud purposes, or a Recipient after funds have been transferred. PaymentFlux is not the controller for processing that those organisations independently determine.
3. How to contact us
| Purpose | How to contact us |
|---|---|
| Routine privacy questions, rights requests and most data-protection matters | Support Centre — https://paymentflux.co.uk/support/contact/ or [email protected] |
| Formal legal notices that are not privacy requests | [email protected] |
Privacy and data-protection requests are handled by our privacy contact (the person responsible for privacy matters). PaymentFlux has not appointed a Data Protection Officer under UK GDPR.
4. Scope
This Policy covers personal data processed in connection with:
- browsing our marketing site and customer app;
- registering and using a PaymentFlux account;
- adding Recipient details and providing evidence;
- making supported residential rent Property Payments by card;
- identity, Recipient and fraud-related Verification Checks;
- customer support and service communications; and
- cookies and similar technologies, as further described in our Cookie Policy.
It does not cover websites, apps or services operated by third parties that we do not control, even if we link to them.
5. Personal data we collect
Depending on how you use the Service, we may process the categories of personal data described in sections 6 to 14. We aim to collect only what is reasonably needed for the Service, Verification Checks, security, support and legal compliance.
Please do not send us special-category data (such as health information) or criminal-offence information unless we specifically ask for it and it is necessary. Documents you upload may occasionally contain incidental sensitive information. See section 16 for how we treat that risk.
6. Data received directly from Customers
You may give us personal data when you:
- register or update an account;
- complete profile or onboarding information;
- start identity verification;
- add or update a Recipient;
- upload tenancy, account or other supporting documents;
- give a Payment Instruction or save a payment method;
- contact support; or
- set cookie or marketing preferences (where offered).
7. Data received from other sources
We may also receive personal data from:
- Payment Partners (currently including Stripe) — for example card-payment status, tokenised payment-method identifiers, limited card metadata and fraud or authentication signals;
- identity-verification providers — verification results and related status information;
- Confirmation of Payee or account-name verification sources — where used, including where an operator records a check result;
- Companies House and other public registers — company identity and classification information for relevant Recipients;
- documents and evidence you upload (including information about Recipients or related people contained in those documents);
- technical systems and devices — IP address, device and browser signals, security and audit events; and
- fraud-prevention or security tooling used as part of our Risk processes, where configured.
Where we obtain personal data from a source other than you, we use it for the purposes and on the lawful bases described in this Policy.
8. Account and identity information
This may include:
- name and preferred display name;
- email address;
- phone number;
- date of birth;
- postal address;
- account identifiers and account status;
- authentication information (such as password hashes, session and refresh-token metadata, step-up authentication outcomes);
- Google account identifiers where you choose to sign in or link with Google; and
- identity-verification case status, provider reference and verification outcome.
Identity verification is carried out using specialised providers (currently including Didit and, where configured, Stripe Identity). PaymentFlux receives verification outcomes and related case metadata rather than treating identity-document images as a general customer download.
9. Recipient and relationship information
When you add a Recipient or start a Property Payment, we may process:
- Recipient type (for example landlord or letting agent);
- display name and account-holder name;
- sort code, account number and payment reference (or derived fingerprints / limited last-digit identifiers where our systems store those instead of full account numbers);
- property address and related relationship details;
- company number and Companies House / SIC classification information where relevant; and
- relationship-evidence status and review outcomes.
Recipient personal data provided by you
You may provide personal data about a landlord, letting agent or other related person.
You should:
- provide only information reasonably necessary for the supported Property Payment and Verification Checks; and
- make sure you have a lawful basis or other lawful justification for giving that information to PaymentFlux.
PaymentFlux uses Recipient and related-person information to assess eligibility, verify account/name alignment, review relationship evidence, prevent fraud, execute or support the payment, and keep records. PaymentFlux remains responsible for how it processes that data as controller for its own purposes. Providing Recipient data does not transfer all UK GDPR duties to you, and it does not make PaymentFlux responsible for processing independently determined by the Recipient or their bank.
10. Payment and card information
When you make or prepare a Property Payment, we may process:
- payment amount, currency, fees shown to you, dates and status;
- Recipient and reference details linked to the Payment Instruction;
- failure, delay, review, refund or dispute-related status information;
- tokenised payment-method identifiers and Stripe payment-method / setup-intent references;
- limited card metadata such as brand, last four digits, issuer country, funding type and hashed card fingerprint; and
- Strong Customer Authentication / 3-D Secure outcomes where applicable.
Full card numbers and card security codes (CVC/CVV) are collected directly by our card-processing Payment Partner (Stripe) through Stripe.js / Elements. PaymentFlux’s systems are designed not to receive or store full primary account numbers or card security codes. PaymentFlux stores only the limited card and payment-method metadata needed to operate the Service, support disputes and meet security and audit needs.
11. Verification and evidence information
This may include:
- Confirmation of Payee or similar account-name check results;
- Companies House search and company-profile information;
- SIC or other business-classification indicators used for eligibility;
- documents you upload (for example tenancy agreements, account statements or correspondence);
- evidence-review decisions, reasons and operator notes relevant to your case; and
- fraud, risk and security indicators used in Verification Checks.
Evidence files are stored in encrypted cloud storage controlled by PaymentFlux. We do not expose raw storage keys or OCR internals to customers.
12. Technical, device and usage information
This may include:
- IP address and approximate location derived from IP where relevant to security;
- device and browser information (for example user-agent family and platform);
- client-generated device identifiers used for security and risk evaluation;
- authentication, audit and security event logs;
- cookie and similar-technology data described in our Cookie Policy; and
- application error and operational telemetry needed to keep the Service reliable.
Optional analytics on the marketing website and customer app, where those tags are configured and you have given the relevant consent, are described in section 14 and in our Cookie Policy. We do not currently operate advertising or remarketing pixels.
13. Support and communications information
This may include:
- support case details and messages;
- public support magic-link access metadata (where used);
- email delivery status and related communication evidence; and
- records of service, security and transactional messages we send you.
Customer email is currently sent through our email delivery provider (Resend). Support cases are handled in PaymentFlux’s own Support service rather than a separate third-party helpdesk product.
14. Marketing information and preferences
We may process:
- your marketing preferences, where a marketing choice is offered;
- records needed to suppress further marketing after you opt out; and
- cookie-preference choices relating to optional analytics or marketing technologies, where those categories exist.
We may use optional analytics technologies on the marketing website and the customer app where those tags are configured and you have given the relevant consent. Those technologies are not necessary for the Service and are not required to make a Property Payment. Their purpose is to understand how the Platform is used, improve customer journeys, and measure acquisition and funnel performance.
The current optional analytics configuration uses Google Analytics, managed through Google Tag Manager. PaymentFlux does not currently identify you to Google Analytics using a PaymentFlux account identifier. We do not currently use advertising or remarketing technologies, and Microsoft Clarity is not currently configured. If you select Reject optional, those optional analytics will not run. You can control or change optional-cookie choices through Cookie settings. Further operational detail is in our Cookie Policy.
Essential service communications (for example security alerts, payment status and Verification Check updates) are not marketing.
15. Why we use personal data
We use personal data to:
- register and administer your account;
- authenticate you and protect account security;
- provide the Platform and Service;
- carry out Recipient Verification Checks and review relationship evidence;
- process Payment Instructions and related card charges through Payment Partners;
- prevent, detect and investigate fraud, suspected misuse, unlawful use, payment abuse and security incidents;
- provide customer support and handle complaints, refunds and disputes;
- keep audit, transaction and consent records;
- send essential service communications;
- improve reliability and product performance in a privacy-aware way;
- where you have given the relevant optional-cookie consent, understand how the marketing website and customer app are used;
- establish, exercise or defend legal claims; and
- comply with applicable legal and regulatory obligations.
16. Lawful bases
Under UK GDPR, we rely on one or more of the following lawful bases, depending on the purpose:
| Purpose | Typical data involved | Likely lawful basis | Is provision required? | If you do not provide it |
|---|---|---|---|---|
| Register and administer an account | Contact details, authentication data, account identifiers | Contract (Art. 6(1)(b)) | Required to create and use an account | You cannot register or use the Service |
| Provide the Platform and Service | Account, profile, Recipient and payment data needed for requested features | Contract | Required for the features you request | Those features will not work |
| Process a Payment Instruction | Payment, Recipient, card-metadata and status data | Contract | Required to make the Property Payment | The payment cannot proceed |
| Identity verification before live payments | Identity-check information and verification outcomes | Contract; legitimate interests in preventing misuse (Art. 6(1)(f)); legal obligation only where a specific obligation applies | Required before live Property Payments where our processes require it | Live payments may be refused or delayed |
| Recipient Verification Checks and relationship-evidence review | Recipient, account, register, document and review data | Contract; legitimate interests in reducing payment and fraud risk | Required for supported Property Payments that need those checks | The Recipient or payment may remain blocked |
| Fraud prevention, account security, suspected-misuse investigation and Platform/payment security | Device, technical, risk, authentication, payment and evidence records | Legitimate interests in protecting customers, Recipients and the Platform; legal obligation where a specific obligation applies | Often unavoidable for secure use of the Service | We may refuse, delay or restrict access or payments |
| Essential service communications | Contact details, payment/account event data | Contract; legitimate interests in operating the Service securely | Needed for operational messages | You may miss important security or payment updates |
| Support, complaints, refunds and disputes | Support messages, payment and account records | Contract; legitimate interests in resolving issues and defending claims | Needed to investigate your request | We may be unable to help fully |
| Audit, transaction and consent records | Acceptance records, payment and verification history | Legitimate interests in accountability and dispute handling; legal obligation where record-keeping rules apply | Not usually a separate customer “form” field | N/A |
| Reliability, security monitoring and product performance | Technical logs, limited diagnostics | Legitimate interests in keeping the Service secure and reliable | Occurs as part of using the Service | Service quality or security may be affected |
| Optional analytics or marketing cookies / similar technologies | Cookie identifiers and related usage data | Consent (Art. 6(1)(a)); PECR consent rules also apply | Optional | Non-essential technologies will not run. You can still use the Service, including making a Property Payment |
| Electronic marketing (email/SMS), if offered | Contact details and preferences | Consent and/or PECR soft opt-in where lawfully available; UK GDPR consent or legitimate interests assessed case by case | Optional | You will not receive that marketing |
| Legal claims, regulatory requests and compliance | Relevant account, payment, evidence and communication records | Legal obligation (Art. 6(1)(c)) where applicable; legitimate interests in establishing, exercising or defending legal claims | Depends on the request or obligation | We may be required to act anyway |
| Lawful cooperation with Payment Partners, banks and competent authorities | Relevant payment, account, identity and investigation records | Legal obligation where applicable; legitimate interests in preventing fraud, protecting the Service and cooperating lawfully | Depends on the request or obligation | We may be required or permitted to act anyway |
Notes on lawful bases
- Contract is used where processing is objectively necessary to provide the Service you request.
- Legitimate interests is used only where we have identified a real interest (for example fraud prevention, security, service reliability or dispute handling) and considered the impact on you. You may object in certain cases (see section 29).
- Consent is used for optional non-essential cookies/similar technologies and for marketing where PECR requires consent. Consent is not the lawful basis for processing that is necessary to perform the Service.
- Legal obligation is used only where a specific legal duty applies. This Policy does not claim every Verification Check is mandated by a particular statute.
We do not intentionally require special-category data or criminal-offence data to use the Service. If a document you upload incidentally contains such information, we will treat that as a data-mapping and risk issue, limit use to what is necessary for the relevant review or security purpose, and seek appropriate conditions before any broader processing. Customers should avoid including unnecessary sensitive information in uploads.
17. Recipient Verification Checks
Verification Checks are designed to assess whether an intended Recipient appears eligible to receive a supported rent Property Payment, and to assess payment details, relationship evidence, payment purpose and associated risk.
Depending on the journey, checks may use:
- Confirmation of Payee or similar account-name checks;
- Companies House and SIC or other classification information;
- payment-reference and destination checks;
- review of documents and other evidence you supply;
- internal risk indicators; and
- automated rules and manual review.
Passing Verification Checks means the relevant checks we apply have been completed successfully according to our processes at that time. It does not mean we certify the Recipient, guarantee entitlement to funds, or remove your responsibility to check payment details.
18. Fraud prevention, security and legal compliance
We use fraud-prevention and security measures that may include:
- device and technical signals;
- velocity and misuse rules;
- authentication and step-up checks;
- payment-routing decisions such as requiring additional card checks, placing a payment under review, or refusing a transaction; and
- monitoring of security events and operational logs.
These measures protect Customers, Recipients and the Platform. They are risk-based and are not a guarantee that harmful activity will always be detected or prevented.
We may process personal data, where necessary and proportionate, to:
- prevent, detect and investigate suspected fraud, attempted misuse, unlawful use, payment abuse or identity misuse;
- keep the Platform and payments secure;
- establish, exercise or defend legal claims;
- comply with legal or regulatory obligations; and
- cooperate lawfully with Payment Partners, banks, regulators, courts, police and other competent authorities.
We may disclose relevant personal data where required by law, or where disclosure is otherwise lawful, necessary and proportionate. We do not automatically report every case of suspected fraud. Investigation of suspected fraud does not, by itself, mean that a crime has been committed.
We aim to share only the personal data that is reasonably needed for the relevant purpose.
19. Automated processing and human review
We use automated rules and risk indicators to assist reviews and to route payments or account events (for example to require additional authentication, send a payment for manual review, or refuse a high-risk attempt under policy).
Some cases are referred for manual review by operators. Identity verification, relationship-evidence decisions and many Verification Check outcomes also involve human review where our processes require it.
We do not currently describe any processing in this Policy as a solely automated decision producing legal or similarly significant effects under UK GDPR Article 22 without further confirmation. If that analysis changes, we will update this Policy and provide the required information and safeguards.
20. Who we share data with
We share personal data only where needed for the purposes above, including with the categories of recipients in sections 21 to 25.
We do not sell your personal data.
Not every recipient is a “processor” acting only on our instructions. Some organisations are independent controllers for their own purposes.
21. Payment Partners and card providers
We share payment-related data with Payment Partners, currently including Stripe, to:
- collect and tokenise card details;
- authorise and capture card payments;
- support saved payment methods and future charges where you have agreed;
- provide payment status and limited card metadata; and
- support fraud, authentication and dispute handling connected with card processing.
Your card issuer and the banks involved in a transfer also process personal data as independent controllers under their own terms and notices.
22. Verification and data-source providers
Depending on the journey, we may share or obtain data involving:
- identity-verification providers (currently including Didit and, where configured, Stripe Identity);
- Confirmation of Payee / account-verification sources (including manual operator-recorded checks where automated provider calls are not used);
- Companies House for company identity and classification information; and
- address-lookup providers where postcode lookup is enabled.
23. Technology, hosting and support providers
We use service providers to host and operate the Platform. Categories include:
- cloud hosting, storage, networking and monitoring providers (PaymentFlux’s production stack is built on Amazon Web Services services such as compute, API gateway, managed database, object storage, messaging and logging);
- email delivery providers (currently Resend);
- authentication-support services where you choose Google sign-in (Google); and
- bot/abuse-protection tokens on auth flows where Cloudflare Turnstile is configured.
These providers process personal data only as needed to provide their services to us, under contract where they act as processors, or under their own controller terms where that is the correct role.
24. Recipients and related parties
If a Property Payment is transferred to a Recipient, the Recipient and their bank will receive the payment details needed to credit the funds (for example amount, reference and payer information shown on the transfer). After transfer, the Recipient processes that information under their own arrangements with you.
25. Public authorities and professional advisers
We may share personal data with:
- police, law-enforcement, regulators, courts or other public authorities where required or permitted by law, and where sharing is otherwise lawful, necessary and proportionate;
- Payment Partners and banks, where necessary and lawful to investigate suspected fraud, process a payment, or handle a dispute;
- professional advisers (such as lawyers, auditors or insurers) under confidentiality obligations; and
- counterparties in a corporate transaction (such as a merger or acquisition), subject to appropriate safeguards.
We do not automatically disclose personal data whenever fraud is suspected. Any disclosure is limited to what is relevant to the purpose.
26. International transfers
PaymentFlux’s primary application infrastructure is operated in the United Kingdom (documented default region eu-west-2).
Some providers we use — including Payment Partners, identity-verification providers, email delivery providers and authentication providers — may process personal data in the UK, European Economic Area or other countries.
Where personal data is transferred internationally, we rely on a legally permitted mechanism appropriate to the transfer. That may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses; or
- another safeguard permitted by UK data-protection law.
We will not claim that a specific safeguard applies to every provider until the transfer map for that provider is confirmed. If you need more detail about a particular transfer, contact [email protected].
27. Retention
We keep personal data only for as long as needed for the purposes in this Policy, including legal, accounting, dispute, fraud-prevention and audit needs. Exact retention periods depend on the record type and are maintained in an internal retention schedule.
In determining retention, we consider:
- whether you still have an account;
- whether a Property Payment, Verification Check, dispute, chargeback or complaint remains open;
- statutory or regulatory record-keeping expectations for payment and financial records;
- the need to investigate fraud or misuse;
- the need to demonstrate which legal terms or consents applied; and
- whether a shorter period is enough for a purely operational convenience copy.
Current criteria and known periods
| Record type | Retention approach |
|---|---|
| Account and profile records | Kept while the account is active and for a further period after closure or inactivity where needed for security, disputes and legal claims |
| Payment and transfer records | Kept for the period needed for payment operations, disputes, accounting and legal claims. Payment-related notification evidence is retained for at least 7 years |
| Identity, Recipient verification and relationship-evidence records | Kept for the period needed to operate Verification Checks, defend decisions, prevent fraud and handle disputes |
| Fraud, security and audit logs | Kept for a period aligned to security investigation and accountability needs; short-lived technical tokens and idempotency keys may expire earlier by design |
| Support records | Kept for the period needed to resolve the case and for a reasonable follow-on dispute/audit period |
| Consent and legal-acceptance records | Kept for as long as needed to show which version you viewed or accepted and to meet accountability duties |
| Cookie preferences | Stored for up to 365 days, and refreshed or asked again when you change preferences or when the published Cookie Policy version materially changes |
| Marketing suppression records | Kept for as long as needed to honour an opt-out |
| In-app notification inbox copies | Convenience copies may be available for about 12 months, while underlying communication evidence may be kept longer as above |
When personal data is no longer required, we delete or irreversibly anonymise it where feasible, unless a longer retention is required by law or needed for legal claims.
28. Security
We implement technical and organisational measures designed to protect personal data, including encryption in transit, access controls, least-privilege operator access, monitoring, and separation of card data so that full card numbers and security codes are handled by Stripe rather than stored by PaymentFlux.
No method of transmission or storage is completely secure. Please protect your login credentials and tell us promptly through the Support Centre if you suspect unauthorised access.
29. Customer rights
Under UK data-protection law, you may have the right to:
- access your personal data;
- correct inaccurate personal data;
- delete personal data in certain circumstances;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests, and to direct marketing;
- data portability, where processing is based on consent or contract and is carried out by automated means;
- withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
- receive meaningful information about solely automated decisions with legal or similarly significant effects, where Article 22 applies; and
- complain to the Information Commissioner’s Office (ICO).
These rights are not absolute. They depend on the circumstances, the lawful basis we rely on, and applicable exemptions (for example where retaining data is necessary for legal claims, fraud prevention or legal compliance).
We do not offer a self-service erasure tool that deletes payment, fraud-prevention or legal-acceptance records while we still need them. Erasure requests are assessed under UK data-protection law.
30. How to exercise rights
To exercise your rights, contact us through:
- the Support Centre — https://paymentflux.co.uk/support/contact/; or
- [email protected].
You do not need to use a particular form of words. We may ask for reasonable information to verify your identity and to locate the data you are asking about. We will respond within the time limits required by law.
31. Complaints to PaymentFlux and the ICO
If you are unhappy with how we have used your personal data, please contact us first so we can try to resolve the issue.
You also have the right to complain to the Information Commissioner’s Office:
- Website: https://ico.org.uk
- Telephone: 0303 123 1113
32. Children
The Platform is intended for adults aged 18 or over. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact [email protected] and we will take appropriate steps.
33. Changes to this Policy
We may update this Privacy Policy from time to time. When we publish a new version through our consent catalogue, the version label and effective date below will change. Where a change is material, we will take reasonable steps to bring it to your attention (for example through the Platform or by email).
34. Related documents
- Platform Terms
- Cookie Policy
- Payment Authorisation and Future Charge Consent (when presented in a payment journey)
- our Complaints Policy and Refunds and Disputes Policy
35. Version information
| Field | Value |
|---|---|
| Document | Privacy Policy |
| Version label | 2026.09.1 |
| Effective from | 8 September 2026 (UTC) |
| Locale | en-GB |
This Policy applies from the effective date above once published through our consent catalogue for that version. Until published, earlier published versions continue to apply where already in use.