CARDZ3N — Home
CARDZ3N logoCARDZ3N — Home
Payments
OnlineISVRetailMobileACHB2B & B2GHigh RiskEnterpriseProcessing GuideFees ExplainedReserves & Pricing Explained
Solutions
Added-Value Services
Bead - Crypto, BNPL & WalletsFlexFactor - Decline RecoveryChargeback Management — Dispute Prevention
Gateways & Processing
Payment GatewayProcessing ServicesPoint of Sale
POS & Software
POS SolutionsLinga POSOctoposkwickPOSTap to PayInvoiceZ3NAerospacePayBanking
Equipment
Terminals & Hardware
Payment Terminals & AccessoriesFind a Terminal →
Gateways & Virtual
Gateway IntegrationsPayment Gateway
Industries
AdultCannabisMarketplacesSubscriptionsSports BettingTravel & AirlinesHigh VolumeHemp & CBDMedical BillingNonprofit
Click Here for the full list
Company
About UsBlogLocationsPerks & DiscountsContact UsEU MerchantsCanada MerchantsBecome an Agent / Partners
Apply Now!
Merchant Quick App

Privacy Policy

Contact Us.

CARDZ3N Privacy Policy

Effective Date: 23 September 2026 · Last Updated: 23 September 2026 · Version 3.1

1. Who we are and how to reach us

CARDZ3N provides payment processing, merchant services, and business lending and working capital services to businesses. This policy explains how we handle personal information.

Legal entity: CARDZ3N Inc, a Delaware corporation. Registered address: 4262 Blue Diamond Rd., Bldg 102, Ste 191, Las Vegas, NV 89139, United States. Privacy contact: legal@cardz3n.com. Phone — USA: +1 (702) 623-3528 · Canada: +1 (647) 948-9516 · UK / EU: +44 117 205 2647 · Germany: +49 697 104 5196.

1.1 Privacy Lead

Privacy matters at CARDZ3N are overseen by our Privacy Lead, Joshua Benedetti, Chief Executive Officer, who can be reached at legal@cardz3n.com.

We have not designated a Data Protection Officer under Article 37 of the GDPR.

1.2 Representatives in the EEA and UK

CARDZ3N has no office, employee or subsidiary in the EU or UK. We have therefore designated representatives in both territories under Article 27.

EU representative under Article 27 GDPR: Europe Services, SE, Na Cecelicce 425/4, Smichov, 150 00 Praha 5, Czech Republic. Data subjects may contact the representative at info@gdprrepresentative.com regarding the processing of their personal data.

UK representative under Article 27 of the UK GDPR: REP27 LTD (company number 17385889), Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom. Data subjects in the United Kingdom may contact the representative at info@gdprrepresentative.com.

You may contact either representative on any matter relating to our processing of your personal data. This does not affect your right to contact us directly, or to complain to a supervisory authority (§20).

2. Our role: when we are a controller and when we are a processor

We handle personal information in three different capacities. Which one applies changes what rights you have and who you should contact.

CARDZ3N introduces merchants to payment processing services. We support merchants through the application process and afterwards, but underwriting, KYC and KYB verification, sanctions screening and anti-money-laundering compliance are the responsibility of the sponsor bank and processing partners behind those services.

2.1 Where we act as a controller

We decide the purposes and means of processing — and are directly accountable to you — when we:

• Collect and evaluate merchant applications for the purpose of introducing them to our sponsor bank and partners

• Manage our own relationships with merchants, prospective merchants, agents, ISOs, partners, leads, website visitors and subscribers

• Introduce merchants to business lending and working capital products offered by our partners, and manage that referral relationship

• Market our services

• Operate our website and our own business, finance and administrative functions

2.2 Where CARDZ3N sits in the chain

CARDZ3N introduces merchants to payment processing services provided by others. Merchants contract directly with the processing provider, not with CARDZ3N, and the acquiring bank is identified to the merchant in that agreement rather than here.

We cannot approve or decline applications on a processing provider's behalf. Those decisions — and the underwriting, KYC, KYB, sanctions screening and anti-money-laundering checks behind them — rest with the provider and its sponsor bank.

We are the controller of the information you give us. When you enquire, apply, or work with us, the information you provide to CARDZ3N is ours to look after — we decide why we hold it and what we do with it, within the limits of this policy. When we pass an application to a processing provider, that provider becomes the controller of what it receives and handles it under its own privacy policy.

2.3 Where our sponsor bank and partners act as controllers

We do not make underwriting, KYC, KYB, sanctions-screening, anti-money-laundering or risk decisions ourselves. Those are made by our sponsor bank, acquiring processors and other partners, each acting as a controller under its own legal and card-network obligations.

This means that when you apply for a merchant account, information you give us is passed to those partners, who independently assess it and decide the outcome. We may collect the information and communicate the result, but the decision is not ours.

Where you want to exercise rights over data held by those partners, contact us at legal@cardz3n.com and we will route your request — but their own privacy policies also apply.

2.4 Where we act as a processor for a business customer

Some services we provide under a CARDZ3N brand are delivered using software operated by a specialist third-party provider. ChargebackZ3N — our chargeback alert, deflection and representment service — is one of these.

For these services, you are the controller and we are the processor. You contract with CARDZ3N, we bill you, and we handle the personal information involved on your instructions and for the purposes you set. The specialist provider that operates the underlying platform acts as our sub-processor and works to the same instructions.

We will enter into a data processing agreement with you covering how we handle personal information on your behalf, including confidentiality, security, our use of sub-processors, assistance with data subject requests, and what happens to the data when our agreement ends. Customers and prospective customers can request a copy at legal@cardz3n.com.

Cardholders. If you are a cardholder rather than a merchant, we generally hold your data as a service provider in the payment chain. Your relationship is with the merchant and your card issuer. Direct rights requests to them first; we will support their response. You may still contact us at legal@cardz3n.com and we will route your request.

2.5 Where we and others are independent controllers

Payment transactions require us to share data with acquiring banks, card networks, and other financial institutions, each of which processes that data as an independent controller under its own obligations, network rules, and privacy policies. We do not control what they do with it.

3. Personal information we collect

3.1 Categories

Identifiers and contact details — Examples: Name, email, postal address, phone, username, job title, social handle — Typical sources: You; your employer; public sources

Financial information — Examples: Card number, expiry, CVV, bank account and routing numbers, billing address, transaction records, income, VAT/tax ID, credit score, processing volume, chargeback history — Typical sources: You; banks; card networks; credit bureaus

Government identifiers and documents — Examples: SSN or national insurance number, passport, driver's licence, national ID, proof of address, right-to-work and visa status, signature — Typical sources: You; verification providers

Business and work information — Examples: Employer, occupation, ownership and beneficial-ownership structure, business licences, CV — Typical sources: You; corporate registries

Personal characteristics — Examples: Date of birth, nationality, sex or gender where required for identity verification — Typical sources: You

Household and relationships — Examples: Emergency contact, marital status, next of kin — collected only where required for a specific product — Typical sources: You

Technical identifiers — Examples: IP address, device and browser identifiers, cookie IDs, account credentials (passwords are stored only in salted, hashed form and are never retrievable by us) — Typical sources: Automatically

Usage and behavioural data — Examples: Pages viewed, features used, clicks, referral source, session recordings — Typical sources: Automatically

Location data — Examples: Approximate location derived from IP; precise location only with consent — Typical sources: Automatically; you

Communications — Examples: Emails, chat transcripts, support tickets, SMS content and metadata, call recordings — Typical sources: You

Images and recordings — Examples: Profile photos, ID document images, verification selfies, call recordings, CCTV at our premises — Typical sources: You; automatically

Views and opinions — Examples: Survey responses, testimonials, feedback — Typical sources: You

Compliance and risk data — Examples: Sanctions and watchlist screening results, adverse media, fraud indicators, suspicious activity records, dispute and chargeback records — Typical sources: Screening providers; networks; internal systems

Derived characteristics — Examples: Risk tiers, categories, segments and similar assessments — including those assigned by our sponsor bank or processing partners and recorded on your account — Typical sources: Our partners; internal systems

3.2 Sensitive information

Some of the above is treated as sensitive or special-category information under various laws, including government identifiers, financial account numbers, account credentials, precise location, and biometric identifiers where used for verification.

We collect sensitive information only where necessary to verify identity, prevent fraud, or meet a legal obligation — and we do not use or disclose it for purposes other than those set out in §4. See Annex A §A.5 (US) and Annex D §D.3 (EEA/UK).

3.3 Criminal offence information

Sanctions, watchlist and adverse-media screening is performed by our sponsor bank and partners, not by us (§2.3). We may receive and hold the results of that screening in connection with a merchant application.

3.4 Credit checks on merchants and guarantors

We deal only with businesses. Where a merchant is a sole proprietor, or where an owner or officer provides a personal guarantee, information about that individual forms part of the application we pass to our sponsor bank and processing partners.

CARDZ3N does not obtain or receive consumer credit reports. Any consumer report used to evaluate an application is obtained by our sponsor bank or processing partner, who decides the outcome (§2.3). If your application is declined or offered on different terms and a consumer report was used, the notice explaining your rights under the Fair Credit Reporting Act — including which consumer reporting agency supplied the report, your right to a free copy, and your right to dispute inaccurate information — comes from that institution, not from us. We can tell you which partner handled your application.

3.5 Cardholder data

Where we handle payment card data, we do so in accordance with the Payment Card Industry Data Security Standard (PCI DSS).

• We do not retain full card numbers beyond authorization. Card numbers are tokenized.

• We never retain sensitive authentication data — card verification values, magnetic-stripe track data or PINs — after authorization.

• Where card data is handled, it is encrypted or truncated, and accessible in full only where there is a specific documented business need, by named personnel with restricted access.

3.6 Call recording

We record telephone calls. When you call us, an announcement tells you the call is being recorded before the conversation begins. If you do not wish to be recorded, you may end the call and contact us by email at legal@cardz3n.com instead — we will deal with your matter that way and you will not be disadvantaged.

We do not record outbound calls. When we call you, the call is not recorded. We do not use automated telephone dialling systems.

We record calls to confirm instructions, resolve disputes, meet card-network and partner requirements, and train our staff. Recordings are held for the period set out in §13 and are accessible only to personnel with a business need.

3.7 Video meetings

Where we meet you by video, we may record and transcribe the meeting using an AI meeting assistant, so that we have an accurate record of what was discussed and agreed.

You will be told before recording begins, and asked to agree. If you would prefer the meeting not be recorded, tell us and we will take written notes instead. Recordings and transcripts are held for the period in §13 and are accessible only to personnel with a business need.

3.8 If you don't provide it

Where we need information to enter into or perform a contract — identity verification being the clearest example — we cannot provide the service without it, and may have to decline or close an account.

4. Why we use personal information

• Providing our services — onboarding, processing card, ACH and check payments, settlement, funding, refunds, chargebacks and disputes

• Underwriting and risk — evaluating applications, assessing creditworthiness and risk, setting limits, reserves and holds, monitoring accounts

• Identity verification and compliance — KYC, KYB, beneficial-ownership verification, sanctions and PEP screening, AML monitoring and reporting, tax reporting

• Fraud prevention and security — detecting and investigating fraudulent, unauthorised or prohibited activity; protecting our systems and users

• Customer support — responding to enquiries, troubleshooting, training staff

• Communications — service, transactional, security and account notices

• Marketing — telling you about products and services, subject to §8 and §9

• Website and product improvement — analytics, testing, developing new features

• Legal and corporate — complying with law, responding to lawful requests, establishing or defending legal claims, audits, and evaluating corporate transactions

• Aggregated and de-identified analysis — where data no longer identifies you and we maintain it in that form

5. Legal bases for processing

This section applies where the GDPR, UK GDPR, or a comparable law requires a legal basis. See Annex D.

Onboarding, servicing, settlement — Legal basis: Performance of a contract

Collecting and forwarding applications for underwriting by partners — Legal basis: Contract (pre-contractual steps); legitimate interests in managing financial risk

Collecting KYC/KYB and screening information for our sponsor bank — Legal basis: Legitimate interests; contract

Tax reporting — Legal basis: Legal obligation

Fraud prevention and platform security — Legal basis: Legitimate interests in preventing fraud

Service, security and transactional messages — Legal basis: Contract; legal obligation

Marketing to existing business customers — Legal basis: Legitimate interests, subject to an unconditional right to object (§8)

Marketing to prospects — Legal basis: Consent

SMS marketing — Legal basis: Consent (§9)

Analytics and advertising cookies — Legal basis: Consent (§10)

Session recording and behavioural analytics — Legal basis: Consent

Special-category data — Legal basis: Article 9 condition, see Annex D §D.3

Criminal offence data — Legal basis: Article 10, see §3.3

Corporate transactions, legal claims, audit — Legal basis: Legitimate interests

Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. You may request a summary of that assessment at legal@cardz3n.com.

6. How we collect information

Directly from you — applications, account creation, forms, email, phone, chat, SMS, in-person meetings, events.

Automatically — cookies and similar technologies when you use our website or platform (§10), and transaction data generated as you use our services.

From third parties —

• Identity verification, KYC and sanctions screening providers

• Business information and commercial credit bureaus (business-entity data only)

• Banks, acquirers, card networks and payment partners

• Corporate registries and public records

• Your employer, if you use our services through them

• Referral partners, agents and ISOs, who may submit your name, email address and telephone number so that we can contact you

• Business contact data providers and prospecting tools, which supply or append business contact details

• Professional networks and recruitment platforms (for applicants)

• Advertising and analytics partners

• Publicly available sources including your website, professional networking sites and social media

Where we obtain your contact details from a source other than you, we will tell you where we got them if you ask, and you may object to our use of them at any time by emailing legal@cardz3n.com.

7. When we disclose personal information

We disclose personal information to the categories of recipient set out below. We name categories rather than individual companies because our partner arrangements are commercially confidential; a list of the specific entities is available on request under §7.2.

Sponsor and acquiring banks — Sponsor merchant accounts, hold those accounts, settle funds, and make underwriting, KYC, KYB, sanctions-screening and risk decisions (§2.3). Location: United States, Canada, EU/UK

Card networks and payment schemes — Route and authorize transactions, apply network rules, administer disputes and chargebacks. Location: Global

Payment processors and acquirers — Authorize, clear and settle card transactions. Location: United States, Canada, EU/UK

Payment gateways — Transmit transaction data between merchants and processors. Location: United States, EU

ACH, check and bank transfer providers — Process non-card payments. Location: United States

Chargeback and dispute software providers — Operate the platform behind our chargeback alert, deflection and representment service as our sub-processor (§2.4). Location: United States

Identity verification, KYC/KYB and sanctions screening providers — Verify identity and beneficial ownership; screen against sanctions, PEP and watchlists. Location: United States, EU

Cloud hosting, website and infrastructure providers — Host our website, platform and internal systems. Location: United States, EU

CRM, support and communications providers — Manage customer relationships, support tickets and email delivery. Location: United States

SMS aggregators and mobile carriers — Deliver text messages you have asked for, subject to §9. Location: Global

Analytics and advertising partners — Website measurement and marketing, subject to your choices under §10. Location: United States, EU

Payroll, HR, contractor payment and background screening providers — Administer employment and contractor payments, for our own personnel only (§18). Location: United States

Professional advisers — Legal, accounting, audit and insurance services. Location: United States, Canada

Regulators, law enforcement, courts and government authorities — Where legally required or permitted. Location: As applicable

Acquirers or successors in a merger, acquisition or asset sale — Evaluate and complete the transaction, subject to confidentiality. Location: As applicable

7.1 What we do not do

We do not sell personal information, and we do not disclose it to third parties for their own independent marketing purposes. Disclosures to the recipients above are made to deliver the services you have asked for, or to meet legal and card-network requirements.

For how "sale" and "share" are defined under US state law — including where advertising technology on our website may constitute "sharing" — see Annex A §A.4. For text-message data, which is subject to stricter limits, see §9.3.

7.2 Asking who specifically

If you would like more detail about who receives your personal information, email legal@cardz3n.com and we will tell you the category of recipient, where they are located, what they do with the information and what safeguards apply.

Some of our partner agreements require us to keep their identity confidential, so we may not be able to name a specific company. Where you are a merchant, the processing provider handling your account is named in the agreement you signed with them.

8. Email marketing and your choices

We send marketing email only where we have a lawful basis (§5). Every marketing email includes a one-click unsubscribe, and we honour opt-outs promptly.

Opting out of marketing does not stop service, transactional, security or legal notices — you can't unsubscribe from a fraud alert or a settlement notice.

To opt out: use the unsubscribe link in any marketing email, or email legal@cardz3n.com.

Our postal address for CAN-SPAM purposes is in §1. For Canada, see Annex B §B.5 (CASL is stricter).

9. SMS, text messaging and mobile information

This section governs all text messages we send. It applies in addition to our SMS Terms & Conditions.

9.1 What we use text messaging for

We use SMS for service and account purposes, not for advertising:

• Authentication — one-time passcodes and login verification

• Account alerts — funding, settlement, deposit and risk notifications

• Collections — balance, arrears and account-status notices

• Customer support — responses to enquiries you have raised with us

We do not currently send promotional or marketing text messages. If that changes, we will obtain separate consent for marketing messages before sending any, and you will be able to opt out of them without affecting the service messages above.

9.2 Consent

We send text messages only to people who have opted in. Consent is collected at the point you give us your mobile number — through a web form, a written agreement, a keyword reply, or during onboarding — and is never a condition of purchase or of receiving our services.

Consent to text messages is separate from consent to any other communication, and separate from consent to our terms. We do not obtain SMS consent through pre-checked boxes, nor bundle it into acceptance of general terms and conditions.

Message frequency varies. Message and data rates may apply.

9.3 SMS privacy and use of mobile information

We use mobile numbers and SMS information only as needed to operate our own business, including sending the service-related and campaign-related text messages you have chosen to receive. We do not share, sell, rent, or use your mobile or SMS information with third parties or affiliates for their marketing or promotional purposes.

Mobile information and SMS opt-in data are used only for our own business purposes. This information will not be shared, sold, or disclosed to third parties or affiliates for marketing or promotional purposes.

Our text messaging program is available in the United States only.

9.4 SMS data sharing

SMS-related consumer data may be shared only as necessary to provide the service, such as with carriers and service providers that support message delivery and related business operations. Your data will not be sold, shared, or transferred to external organizations for marketing, promotional, or other prohibited purposes.

Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text message services.

9.5 No-transfer commitment

Your mobile number, SMS consent, and SMS registration information will not be transferred to external organizations. This includes any transfer for another organization's own use, including international transfers.

Mobile information and SMS registration data will not be sold, shared, or disclosed for purposes unrelated to our business operations.

The only parties that handle your message data are the carriers and messaging providers required to deliver the message to your handset, as described in §9.4. They act on our instruction and may not use the information for their own purposes.

9.6 Opting out

You may stop receiving marketing SMS messages at any time by following the opt-out instructions provided in the message.

You can opt out of SMS or text messaging campaigns at any time by replying STOP to any text message. After you opt out, you will no longer receive SMS campaign messages unless you choose to opt in again.

You may also text QUIT, END, CANCEL, UNSUBSCRIBE, REVOKE or OPT OUT. You will receive one confirmation message and then no further messages in that program.

Reply HELP for assistance, or contact us using the details in §1.

Because most of our messages are service messages rather than marketing, opting out may affect your account. Stopping authentication messages may prevent you from logging in or completing transactions, and stopping account or funding alerts means you will not be notified of settlement issues, holds or arrears. We will tell you what you are switching off before we act on a blanket opt-out request.

We send messages only between 8:00 a.m. and 9:00 p.m. in your local time zone, except for security and fraud alerts.

9.7 Records

We retain records of your consent — including when, how and through which form it was given — and of any opt-out, for as long as required to demonstrate compliance and for at least 10 years (§13).

9.8 SMS questions

For questions about SMS privacy or messaging practices, please use the contact method provided on this website, or email legal@cardz3n.com.

9.9 Carriers

Mobile carriers are not liable for delayed or undelivered messages.

10. Cookies, tracking and advertising

10.1 What we use

Strictly necessary — Security, load balancing, session management, consent recording. No consent required.

Functional — Remembering preferences, language, region. Consent required.

Analytics — Understanding how the site is used. Consent required.

Advertising and targeting — Measuring campaigns and showing relevant ads across sites. Consent required.

A live, itemised list of every cookie and similar technology we use — including provider, purpose, duration and category — is available in our preference centre. Open it from the "Your Privacy Choices" link in the footer of any page.

10.2 Managing your choices

• Consent banner — set or change your preferences at any time via the "Your Privacy Choices" link in the footer of any page

• Browser controls — most browsers let you block or delete cookies; this may break parts of our site

• Global Privacy Control — we treat a GPC signal as a valid opt-out of sale and sharing and of targeted advertising (Annex A §A.6)

• "Your Privacy Choices" — this footer link is available to every visitor on every page, including where no consent banner is displayed

• Ad industry tools — optout.aboutads.info (US), youradchoices.ca (Canada), youronlinechoices.eu (EU/UK)

10.3 Pixels and web beacons

We use pixel tags and similar technologies in our website and emails to measure engagement and campaign effectiveness. These are governed by your cookie choices.

We currently use Meta Pixel, Microsoft Advertising (Bing UET), Microsoft Clarity and Google Analytics. Microsoft Clarity records how visitors interact with our public pages, including mouse movement, scrolling and clicks, so that we can understand and improve how the site works.

Meta Pixel and Microsoft Clarity do not run on our application, onboarding or signed-in pages. They are limited to our public marketing pages, so information you enter when applying for an account or using your account is not captured by them.

These technologies are governed by your cookie choices and, in the United States, by the opt-out rights in Annex A §A.4.

10.4 Do Not Track

We do not currently respond to Do Not Track browser signals.

Do Not Track and Global Privacy Control are different mechanisms, and we treat them differently. Do Not Track is an unenforced browser header with no agreed standard for what a website must do in response. Global Privacy Control is a recognised opt-out preference signal, and we do honour it as a valid opt-out of sale, sharing and targeted advertising — see §10.2 and Annex A §A.6.

11. International data transfers

CARDZ3N is headquartered in the United States. If you are outside the US, your personal information will be transferred to and processed in the United States, which has different data protection laws than your home country. We also use service providers in other countries.

This section does not apply to mobile numbers, SMS consent or SMS registration information. That information is not transferred to external organizations for their own use and is not transferred internationally — see §9.5.

Where required, we use one or more of these safeguards:

• Adequacy decisions where the destination is recognised as providing adequate protection

• EU Standard Contractual Clauses approved by the European Commission

• UK International Data Transfer Agreement or Addendum, and the Swiss equivalent

• Transfer impact assessments and supplementary technical and organisational measures where needed

Information about the destination. Where we transfer your personal information outside your country, you may ask us for information about the destination country's data protection framework and the measures we apply. A copy of the relevant safeguard is also available on request.

12. Security

We maintain administrative, technical and physical safeguards designed to protect personal information, including:

• Encryption in transit and at rest

• Access controls on a least-privilege basis, with multi-factor authentication

• Network monitoring and intrusion detection

• PCI DSS controls for cardholder data (§3.5)

• Vendor security due diligence and contractual data protection terms

• Staff training and confidentiality obligations

• A written information security program, as required by the FTC Safeguards Rule

No system is perfectly secure. We cannot guarantee absolute security, and we do not promise that our safeguards will prevent every unauthorised access.

You are responsible for keeping your account credentials confidential. Tell us immediately at legal@cardz3n.com if you believe your account has been compromised.

12.1 If a breach occurs

We maintain an incident response plan. If a security incident affecting your personal information occurs, we will notify you and the relevant regulators where and when required by applicable law, and within the timeframes those laws set.

13. How long we keep information

We keep personal information only as long as necessary for the purposes we collected it, or as required by law.

KYC / KYB and identity verification records — 5 years after the relationship ends. Driver: AML floor across US, Canada, UK and EU

Underwriting and merchant application records — 5 years after the relationship ends. Driver: AML; card network rules

Transaction and settlement records — 5 years. Driver: AML; dispute windows

Suspicious activity and AML reporting records — 5 years. Driver: AML

Our own financial, accounting and tax records (residuals, commissions, invoices) — 7 years. Driver: US tax and accounting

Signed agreements and contract records — 6 years after termination. Driver: Written-contract limitation periods in Nevada and Arizona

System and audit logs — 1 year, of which 90 days readily available. Driver: Security; incident investigation

Marketing and consent records — 2 to 3 years from last activity. Driver: Marketing law; consent evidence

SMS consent and opt-out records — 10 years, carved out of the marketing tier. Driver: TCPA; state SMS laws

Chargeback and dispute records — 7 years, within the transaction tier. Driver: Network rules

Telephone call recordings — 2 years, longer where a matter is disputed. Driver: Card-network dispute windows

Video meeting recordings and transcripts — 1 year. Driver: Business record; minimising discovery exposure

Support tickets and chat transcripts — 3 years, or 7 where the ticket evidences a transaction instruction. Driver: Contract limitation periods

Website analytics — 14 months. Driver: Matches the analytics platform's retention setting

Job applications — 2 years from the application or personnel action. Driver: EEOC recordkeeping

Background screening authorisations — 5 years. Driver: Evidence of FCRA § 604(b) compliance

Background screening reports — 1 year after the hiring decision. Driver: Minimising retention of sensitive data

Why these periods. Five years after the end of the business relationship is the retention floor under the US Bank Secrecy Act, the EU anti-money-laundering framework, the UK Money Laundering Regulations and Canada's PCMLTFA. We hold compliance records for exactly that period and no longer, because keeping personal information past the point it is needed adds risk without adding protection. Our own financial and tax records are held for seven years because US tax rules require it, and signed agreements for six years, matching the period in which a contract claim can be brought.

We review this schedule quarterly.

We may keep information longer where there's a complaint, an investigation, or a reasonable prospect of litigation.

Legal holds override deletion requests. We often cannot delete AML, transaction or tax records on request, because retaining them is itself a legal obligation. We'll tell you when that applies.

Where we act as a processor for a business customer (§2.4), retention is set by that customer as controller, in line with our data processing agreement with them.

14. Automated decision-making, profiling and AI

CARDZ3N does not make decisions about you by automated means. Every decision we make involves a person.

However, your information is processed by automated systems operated by our partners. Our sponsor bank, acquiring processors, payment gateways and fraud-prevention providers run automated systems that score transactions for risk, screen against sanctions and watchlists, and evaluate merchant applications. Some of those systems make decisions in real time without human review — a transaction being declined at the point of sale is the clearest example.

Consequences. These systems may result in a transaction being declined, an application being refused, a reserve or funding hold being imposed, or an account being restricted or closed.

We do hold derived characteristics about you — risk tiers, categories and similar assessments, including ones assigned by our partners and recorded on your account. Holding an assessment is not the same as making an automated decision, and you may request access to or correction of these characteristics under §16.

Your rights. Where a decision that affects you is made solely by automated means and produces legal or similarly significant effects, you have the right to obtain human intervention, express your point of view, and contest it. Contact us at legal@cardz3n.com and we will route your request to the partner responsible, and support you in pursuing it. Note that we cannot overturn a partner's decision ourselves. See Annex A §A.7 (US), Annex B §B.4 (Quebec), Annex D §D.4 (EEA/UK).

15. Children

Our services are for businesses and are not directed at children. We do not knowingly collect personal information from anyone under 18.

If you believe a child has provided us with personal information, contact legal@cardz3n.com and we will delete it.

16. Your rights

Rights vary by where you live. See your regional annex for the full list and any additional rights. Broadly, you may be able to:

• Access the personal information we hold about you

• Correct inaccurate or incomplete information

• Delete your information, subject to legal retention requirements

• Port your information to another provider in a machine-readable format

• Object to processing based on legitimate interests, and to direct marketing at any time

• Restrict processing in certain circumstances

• Withdraw consent where we rely on it — without affecting processing already carried out

• Opt out of sale, sharing, targeted advertising and certain profiling (Annex A)

• Limit use of sensitive information (Annex A)

• Not be discriminated against for exercising these rights

• Appeal if we deny your request (Annex A §A.8)

• Complain to your regulator (§20)

16.1 How to exercise them

• Email: legal@cardz3n.com

• Phone — USA: +1 (702) 623-3528 · Canada: +1 (647) 948-9516 · UK / EU: +44 117 205 2647 · Germany: +49 697 104 5196

• Post: the address in §1

16.2 Verification

We will ask for information to verify your identity before acting — this protects you from someone else obtaining your data. For sensitive requests we may require additional verification. We will not use verification information for any other purpose.

16.3 Authorized agents

You may use an authorized agent. We will require written authorisation signed by you, and may contact you directly to confirm.

16.4 Timing

We respond within 30 days in the US (extendable by 45 days where permitted) and one month in the EEA and UK (extendable by two months for complex requests). We'll tell you if we need longer.

Requests are free. We may charge a reasonable fee, or decline, if a request is manifestly unfounded, repetitive or excessive — and we'll explain why.

16.5 Requests about data we hold as a processor

If your data is held on behalf of a merchant who uses our services (§2.4), that merchant is the controller. Contact them first. You may also write to us at legal@cardz3n.com — we will forward your request to them without undue delay and assist with their response, as our data processing agreement requires.

17. Third-party links and services

Our website links to third-party sites, plug-ins and applications. Clicking those links may allow third parties to collect data about you. We don't control those sites and aren't responsible for their privacy practices. Read their policies.

Our site includes social media features from Facebook, X, TikTok, Instagram and LinkedIn, which may collect your IP address and set cookies. Your interactions are governed by their policies.

18. Job applicants, employees and contractors

We hire in the United States only.

If you apply for a role with us, we collect your application, CV, contact details, work history, references, right-to-work documentation and the results of background and credit screening. We use this to assess your application, meet our legal obligations as an employer, and administer employment if you join us. This information is processed using third-party payroll and HR platforms, a contractor payment platform, and a consumer reporting agency that conducts background and credit screening. You are given the specific names, and the disclosures the law requires, at the point that information is collected.

Applicants and personnel have the same rights set out in §16.

19. Changes to this policy

We review this policy at least once every twelve months and update it when our practices change.

The "Last Updated" date at the top shows when it last changed. For material changes we'll give prominent notice — a website banner, email, or in-product notice — before they take effect, and where required we'll seek your consent.

You may request a copy of any previous version of this policy by emailing legal@cardz3n.com.

20. Complaints

Contact us first at legal@cardz3n.com — most issues resolve faster that way.

You also have the right to complain to a regulator:

• UK: Information Commissioner's Office — ico.org.uk

• EEA: your national data protection authority, or the authority where the alleged infringement occurred

• Switzerland: the Federal Data Protection and Information Commissioner

• Canada: the Office of the Privacy Commissioner of Canada, or your provincial commissioner (Quebec, Alberta, BC)

• US: your state Attorney General; in California, the California Privacy Protection Agency

21. Accessibility

We aim to make this policy accessible to people with disabilities. If you need it in an alternative format, contact legal@cardz3n.com and we will provide one.

22. Conflicts between sections

Part I applies to everyone. Part II annexes apply to residents of the regions they name.

Where a regional annex conflicts with Part I, the annex governs for residents of that region.

Where this policy conflicts with a signed agreement between us — a data processing agreement or a services agreement — that agreement governs to the extent of the conflict.

PART II — REGIONAL ANNEXES

ANNEX A — United States

Applies to residents of US states with comprehensive privacy laws — currently California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, with Alabama, Louisiana, Oklahoma and Vermont laws enacted and taking effect on their respective dates.

A.1 Financial privacy — Gramm-Leach-Bliley Act

Some of the information we handle in providing payment services is financial information subject to the Gramm-Leach-Bliley Act (GLBA) and its implementing rules, including the FTC Safeguards Rule.

Where information is subject to the GLBA, that Act's requirements govern it, and the state privacy rights in this Annex do not apply to it — those laws exempt information already regulated under the GLBA. This is not a reduction in protection: GLBA-regulated information is subject to its own federal standards for confidentiality, security and disclosure, including the written information security programme described in §12.

Information we hold that is not GLBA-regulated — website visitors, prospects, marketing contacts, and business contact details — remains fully subject to the rights set out in this Annex.

If you are unsure which applies to your information, ask us at legal@cardz3n.com and we will tell you.

A.2 Notice at collection

The categories in §3.1 map to CCPA statutory categories as follows. Unless stated otherwise, the purpose is set out in §4, recipients in §7, and retention in §13.

Identifiers — collected

Customer records (Civil Code § 1798.80(e)) — collected

Protected classifications — collected: date of birth, sex, nationality. Purpose: identity verification and sanctions screening

Commercial information — collected

Internet and network activity — collected

Geolocation — collected, approximate only

Audio, visual and electronic information — collected

Professional and employment information — collected

Education information — not collected

Inferences — collected: risk tiers, categories and similar derived characteristics

Sensitive personal information — collected. Purpose and limits: §A.5

A.3 Your rights

Depending on your state, you have the right to:

• Know and access — what we collect, why, the sources, who we disclose to, and a copy of your information

• Correct inaccurate information

• Delete your information, subject to exceptions — importantly including AML, tax and transaction records we're legally required to keep

• Port your data

• Opt out of sale and sharing — §A.4

• Opt out of targeted advertising — §A.4

• Opt out of profiling producing legal or similarly significant effects — §A.7

• Limit use of sensitive personal information — §A.5

• Appeal a denial — §A.8

• Non-discrimination — we won't deny service, charge different prices, or provide a different quality of service because you exercised a right

Exercise them via §16.1.

A.4 Sale, sharing and targeted advertising

We do not sell personal information for money. However, we use advertising and analytics technologies on our website that may constitute a "sale" or "share" under some US state privacy laws, because they involve disclosing identifiers and browsing activity to third parties for cross-context behavioral advertising.

Categories that may be sold or shared: identifiers, internet and network activity, approximate geolocation, and inferences. Recipients: advertising and analytics providers — see §7.

The technologies involved are Meta Pixel and Microsoft Advertising (Bing UET). Google Analytics is configured for measurement only, with Google Signals disabled, and Microsoft Clarity is used for site-usage analysis.

Disclosures to our banking, acquiring, gateway and other service partners are not sales or shares. They are made to deliver the services you have asked for and to meet legal and card-network requirements.

We do not sell or share the personal information of anyone we know to be under 16.

To opt out:

• Use the "Your Privacy Choices" link in the footer of any page. This single link covers both your right to opt out of the sale or sharing of personal information and your right to limit the use of sensitive personal information.

• Enable Global Privacy Control in your browser — we honour it as a valid opt-out; see §A.6

• Email legal@cardz3n.com

A.5 Sensitive personal information

We collect: government identifiers (SSN, driver's licence, passport), financial account numbers with access credentials, and account log-in credentials.

We do not collect precise geolocation, and we do not collect biometric information. Identity verification involving facial comparison or liveness detection, where it occurs, is carried out by our sponsor bank and processing partners as part of their underwriting and risk functions (§2.3), not by us.

We use it only for: verifying identity, preventing and detecting fraud, providing the services you requested, meeting legal obligations, and ensuring security.

We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for purposes beyond those permitted by California Civil Code § 1798.121(a) and its implementing regulations.

A.6 Global Privacy Control

We recognise Global Privacy Control (GPC) and similar universal opt-out mechanisms as valid opt-outs of sale, sharing and targeted advertising. When we detect one, we apply it to your browser or device automatically. If you're logged in, we apply it to your account.

Now required in a growing number of states, including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Jersey, New Hampshire, Oregon and Texas.

A.7 Profiling

See §14. Where we profile you in a way that produces legal or similarly significant effects, residents of certain states may opt out or request review. Contact legal@cardz3n.com.

A.8 Appeals

If we deny your request, you may appeal within 30 days by emailing legal@cardz3n.com with "Privacy Appeal" in the subject line. Appeals are reviewed by our Chief Executive Officer.

We will respond in writing within 45 days, explaining our reasoning. If we deny the appeal, we'll give you a method to contact your state Attorney General.

Required in Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas and Virginia.

A.9 California — additional

Shine the Light (Civil Code § 1798.83). We do not disclose personal information to third parties for those third parties' own direct marketing purposes. If that changes, we will update this policy and provide a request mechanism.

Notice of financial incentive. We do not offer financial incentives in exchange for the collection, sale or retention of personal information, so no notice of financial incentive is required.

Minors. We do not knowingly sell or share the personal information of consumers under 16.

A.10 Nevada

Nevada residents may direct us not to sell certain covered information (SB 220 / NRS 603A.340). Email legal@cardz3n.com with "Nevada Opt-Out." We'll respond within 60 days.

A.11 Other state-specific notes

• Texas: no revenue threshold; the TDPSA applies based on activity. It requires specific notice language where sensitive or biometric data is sold.

• Maryland: prohibits the sale of sensitive data outright, and the sale of data of consumers known to be under 18. As of 1 July 2026 it also prohibits knowingly selling personal data to a governmental entity that has supported civil immigration enforcement in the preceding six months.

• Virginia and Connecticut: both now prohibit the sale of precise geolocation data (Virginia effective 1 July 2026; Connecticut 1 October 2026), joining Maryland and Oregon.

• Oregon: consumers may request a list of the specific third parties to whom their data was disclosed.

• Washington My Health My Data Act and Nevada SB 370: these govern consumer health data. We do not collect consumer health data, so they do not apply to us.

• Illinois BIPA: where biometric identifiers such as facial matching are used, Illinois law requires a written release before collection. As set out in §A.5, CARDZ3N does not collect biometric information; where identity verification of that kind occurs, it is carried out by our sponsor bank and processing partners under their own notices and consents.

ANNEX B — Canada

Applies to residents of Canada. We handle personal information under PIPEDA and, where applicable, Quebec's Law 25, Alberta's PIPA and British Columbia's PIPA.

B.1 Accountability

Our Privacy Officer for Canada, including the "person in charge of protection of personal information" required by Quebec Law 25, is Joshua Benedetti, Chief Executive Officer — legal@cardz3n.com · +1 (647) 948-9516 (Canada) · +1 (702) 623-3528 (USA).

B.2 Consent

We obtain consent at or before collection, except where the law permits otherwise — including for fraud prevention, investigations, and legal obligations. Consent may be express or implied depending on sensitivity. You may withdraw consent subject to legal and contractual restrictions; we'll explain the consequences before you do.

B.3 Cross-border transfers

Your personal information is stored and processed in the United States and may be accessed by US courts, law enforcement and national security authorities under US law.

Quebec Law 25 requires a privacy impact assessment before transferring personal information outside Quebec.

B.4 Automated decisions (Quebec)

Where a decision is based exclusively on automated processing, we will tell you at or before the decision. You may request the personal information used, the principal factors and parameters that led to the decision, and the right to have it corrected — and to submit observations to a person able to review it. See §14.

B.5 CASL — commercial electronic messages

We send commercial electronic messages to Canadian recipients — including email and SMS — only with express or implied consent as defined by Canada's Anti-Spam Legislation.

Every message identifies us, gives our mailing address and contact details, and includes an unsubscribe mechanism that works for at least 60 days and is actioned within 10 business days.

We keep records of consent, including when and how it was obtained.

B.6 Your rights

Access, correction, withdrawal of consent, portability (Quebec, since September 2024), de-indexing (Quebec), and the right to be informed of a breach presenting a risk of serious injury.

B.7 Language

This policy is published in English. Quebec's Charter of the French Language requires that certain documents be made available in French. If you would like a French version of this policy, or to correspond with us in French, email legal@cardz3n.com and we will provide one.

B.8 Complaints

Office of the Privacy Commissioner of Canada — priv.gc.ca. Quebec residents: Commission d'accès à l'information. Alberta and BC residents: your provincial commissioner.

ANNEX C — United Kingdom

Applies to individuals in the UK. We process personal data under the UK GDPR and the Data Protection Act 2018.

Controller: CARDZ3N Inc — see §1.

UK Representative (Article 27): REP27 LTD — see §1.2.

C.1 Your rights

As set out in §16 — access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights relating to automated decision-making (§14).

C.2 Direct marketing — PECR

Under the Privacy and Electronic Communications Regulations, we send electronic marketing to individuals only with consent, or under the "soft opt-in" where you're an existing customer, the products are similar, and you were offered an opt-out at collection and in every message.

Non-essential cookies require consent (§10).

C.3 Transfers

Your data is transferred to the US and elsewhere (§11), using the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs. CARDZ3N is not certified under the UK Extension to the EU-US Data Privacy Framework.

C.4 Complaints

Information Commissioner's Office · ico.org.uk · 0303 123 1113

ANNEX D — European Economic Area

Applies to individuals in the European Economic Area.

Controller: CARDZ3N Inc — see §1.

EEA Representative (Article 27): Europe Services, SE — see §1.2.

CARDZ3N has no Swiss merchants and has not appointed a Swiss representative.

D.1 Legal bases

See §5.

D.2 Your rights

Articles 15 to 22 GDPR, as summarised in §16. Withdrawing consent doesn't affect processing already carried out.

D.3 Special category data

We do not collect biometric data or health information. Where we nonetheless process special-category data — for example where it appears in documents supplied during onboarding, or in sanctions and watchlist screening results — we rely on:

• Article 9(2)(a) — explicit consent

• Article 9(2)(g) — substantial public interest, read with the relevant national law implementing AML requirements

• Article 9(2)(f) — establishment, exercise or defence of legal claims

D.4 Automated decision-making

See §14. Under Article 22 you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where necessary for a contract, authorised by law, or based on explicit consent — and in those cases you retain the right to human intervention, to express your view, and to contest the decision.

D.5 Transfers

See §11. We rely on Standard Contractual Clauses. CARDZ3N is not certified under the EU-US Data Privacy Framework.

D.6 Complaints

Your national supervisory authority, or the authority in the member state of your habitual residence, place of work, or where the alleged infringement occurred. In Switzerland: the FDPIC.

Banner background imageDecorative banner overlay pattern
Decorative dark pattern
Decorative banner pattern
Decorative wave pattern
CARDZ3N logoCARDZ3N — Home

Contact us today for personalized advice and strategic solutions tailored to your goals.

Phone icon

Call us

+1 (702)-623-3528

Pages

HomeAbout UsIndustriesBlogContactLocations
Become an Agent / PartnerChargebackZ3N
Terms & Conditions
Merchant Services Terms & ConditionsPrivacy PolicySMS Terms & Conditions
Your Privacy Choices

Follow

Facebook icon
Facebook
X (Twitter) icon
X
TikTok logo
TikTok
Instagram icon
Instagram
LinkedIn icon
LinkedIn

Decorative footer graphic
Decorative footer graphic