Privacy Policy
Last updated: September 28, 2026
Who we are
The data controller for this policy is:
[LEGAL COMPANY NAME] (doing business as SurcoPay)
[STREET ADDRESS]
[CITY], Puerto Rico [ZIP], United States
Privacy contact: privacy@surcopay.com
All personal data covered by this policy is processed and stored in the United States. Where you are in another country, transferring your data to the US is what makes the service work; by using SurcoPay you understand and consent to that transfer.
The short version
We collect what the product needs to work, we keep sales records because the law requires it, and we never sell, rent, or share your data for advertising — not yours, not your buyers'. No third-party tracker loads anywhere on our site — the marketing pages, checkout pages, and dashboard all use only first-party, cookie-free analytics. Card numbers never touch our servers at all.
1. Who this covers
Three groups of people interact with SurcoPay: sellers (creators with an account), buyers (their customers, who check out as guests without any account), and visitors (anyone browsing this site or a seller's storefront). Each is treated differently below.
2. What we collect from sellers
- Account: email address, business name, and your password — stored only as a salted cryptographic hash (bcrypt); we cannot read it.
- Security: if you enable two-factor authentication, its secret is stored encrypted and your backup codes only as hashes.
- Payments: if you connect a Stripe account we store only identifiers and status — your identity documents and bank details are collected and held by Stripe, not us. If you pasted API keys (legacy option), they are stored encrypted with a key kept outside the database.
- Tax settings: your business location and the jurisdictions you tell us you are registered in.
- Content: your products, uploaded files, and anything you choose to publish on your storefront (which is public by your choice).
3. What we process about buyers
Buyers check out as guests — there are no buyer accounts and no buyer passwords. On each purchase we process, on the seller's behalf:
- Email address — it is how the product is delivered and receipts are sent, and it appears in the seller's own customer list.
- Phone number — only for ATH Móvil payments.
- Purchase records — product, amount, date, and refunds; these are the seller's sales records and the buyer's receipts.
- Location — country/region as stated by the buyer, only when the seller collects sales tax.
- Fraud signals — the IP address and browser information of a checkout are recorded with that checkout session and used for fraud prevention and rate limiting.
- Card metadata — the card's last four digits and brand, for receipts and fraud checks. Full card numbers never reach our servers: they travel directly from the buyer's browser to Stripe.
4. Analytics
Every page we own — this marketing site, storefronts, checkout, the seller dashboard — uses our own first-party analytics only. No third-party tracker loads anywhere. When you view a page we record one event containing: the page path, the referring site, campaign tags from the link (utm parameters), an approximate country, and whether the device is mobile or desktop.
What a first-party analytics event never contains: your IP address, your browser fingerprint, a cookie, or any identifier. The IP and browser string are read once — to derive the country and device class — and discarded. These events can be counted; they cannot be traced back to a person. Sellers see aggregate traffic reports for their own pages built from this data.
5. What we never do
- We never sell or rent personal data. To anyone. For anything.
- We never share data with advertising networks, and no ad or social-media pixel runs on our pages.
- No third-party analytics or tracking script runs on checkout pages, storefronts, or the seller dashboard.
6. Who we share data with
Only the processors the product runs on: Stripe (card payments, payouts, and seller identity verification), PayPal and ATH Móvil (when the seller offers them), our email delivery provider (receipts and account emails), and our hosting and storage infrastructure. Each processes data only to provide its service. We may also disclose information if the law requires it, or transfer it as part of a sale of the business — under this same policy.
7. Retention and deletion
Sellers can delete their account from the dashboard at any time. Deletion deactivates the account immediately; for 30 days it can be restored by logging back in (people delete accounts by mistake), after which personal data — profile, credentials, uploaded files, storefront, customer lists — is permanently purged and the email address is freed.
What survives deletion: transaction and tax records. These are financial records — the seller's sales ledger, the buyers' receipts, and our fee records — and are retained for up to 7 years as required for tax and accounting compliance. Buyers may request deletion of their personal data through the seller they bought from or by contacting us; the same financial-record retention applies.
8. Security
- Passwords hashed with bcrypt and per-password salts; two-factor authentication available on every account.
- Payment credentials and 2FA secrets encrypted at rest, with keys held outside the database.
- All traffic over TLS; card data handled entirely by Stripe's certified infrastructure.
- Access controls, rate limiting, and audit logging on sensitive operations.
No system is 100% secure and we will not pretend ours is. If a breach ever affects your data, we will notify affected users promptly and describe exactly what was involved.
9. Cookies and local storage
We do not use advertising cookies, and we no longer run any third-party analytics — the marketing site sets no analytics cookies at all. The dashboard keeps your login session in your browser's local storage; checkout pages use session storage only to avoid counting the same view twice. Our first-party analytics set no cookies anywhere on the site.
10. Your rights (EU, UK, and other regions)
If you are in the European Union, the United Kingdom, or another jurisdiction with equivalent data-protection law, you have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete your data (subject to the financial-record retention described in section 7).
- Portability: receive your data in a common machine-readable format so you can move it elsewhere.
- Object to processing, or ask us to restrict it, in specific circumstances.
- Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing already done.
- Lodge a complaint with your local supervisory authority. For EU residents, that is the Data Protection Authority in your country; for the UK, the Information Commissioner's Office (ICO).
To exercise any of these rights, email privacy@surcopay.com from the address on the account. We respond within 30 days.
Where you interact with SurcoPay as a buyer of a seller's product, the seller is the data controller for the customer relationship. We act as their processor for those interactions — send buyer-directed requests to the seller first; we help fulfill them.
11. Children
Our services are not intended for individuals under 18. We do not knowingly collect personal information from children.
12. Changes to this policy
When we change this policy we update this page and its date. Material changes will be called out to account holders. Continued use after changes constitutes acceptance.
13. Contact
Questions about privacy: privacy@surcopay.com
© 2026 SurcoPay. All rights reserved.