Effective Date: 13th January 2025
Paymesh (defined below under “Our relationship to you”) is committed to protecting the privacy of visitors to our websites and our customers. This Privacy Policy describes how we handle your personal data when you access our services, which include our content on the websites located at pay-mesh.com, dev.pay-mesh.com, docs.pay-mesh.com, support.pay-mesh.com or any other websites, pages, features, or content we own or operate (collectively, the "Site(s)"), or any Paymesh API or third party applications relying on such an API, and related services (referred to collectively hereinafter as "Services").
If you have any questions about this Policy, please send them to privacy@pay-mesh.com
Changes to this privacy policy
We may modify this Privacy Policy from time to time. Please check the date at the top of this notice to see when it was last updated.
Our Relationship to you
Paymesh operates internationally through different entities (together “Paymesh”, “we”, “us”, “our”) in order to provide Services to our customers.
The Paymesh entity you contract with decides how your personal information is processed in relation to the Services provided to you (typically referred to as a “data controller”).
Paymesh entities may share your personal information with each other and use it in accordance with this Privacy Policy. For example, even if you reside in the United States your information may be shared with Paymesh PTE Limited which provides support functions for our Services including technical infrastructure and customer support.
Personal Information we collect
Personal information means any data which relates to a living individual who can be identified from that data, or from that data and other information which is in the possession of, or is likely to come into the possession of, Paymesh (or its representatives or service providers). In addition to factual information, it includes any expression of opinion about an individual and any indication of the intentions of Paymesh or any other person in respect of an individual. The definition of personal information depends on the relevant law applicable for your physical location.
Information you provide to us
This includes information you provide to us in order to establish an account and access our Services. This information is either required by law (e.g. to verify your identity), necessary to provide the requested services (e.g. you will need to provide your bank account number if you would like to link that account to Paymesh), or is relevant for our legitimate interests described in greater detail below.
The nature of the Services you are requesting will determine the kind of personal information we might ask for, but may include:
Information we collect automatically or generate about you
This includes information we collect automatically, such as whenever you interact with the Sites or use the Services. This information helps us address customer support issues, improve the performance of our Sites and applications, provide you with a streamlined and personalized experience, and protect your account from fraud by detecting unauthorized access. Information collected automatically includes:
Information collected from third parties
This includes information we may obtain about you from third party sources. The main types of third parties we receive your personal information from are:
Anonymized and aggregated data
In addition to the categories of personal information described above, Paymesh will also process anonymized information and data that is not processed by reference to a specific individual. Types of data we may anonymize include transaction data, click-stream data, performance metrics and fraud indicators.
Job Applicants
If you apply for a job posting, we collect information necessary to process your application or to retain you as an employee. This may include, among other things, your name, contact information (email address and phone number), CV/Resume, and national identifier (e.g., Social Security Number). Providing this information is required for employment. We have a legitimate interest in using your information to evaluate candidates for job openings. We also use information about job applicants in anticipation of a contract of employment. In some contexts, we are also required by law to collect information about applicants.
How we use your personal information
We may use your information in the following ways and for the following purposes:
Paymesh needs to process your personal information in order to comply with anti-money laundering and security laws. In addition, when you seek to link a bank account to your Paymesh account, we may require you to provide additional information which we may use in collaboration with service providers acting on our behalf to verify your identity or address, and/or to manage risk as required under applicable law. We also process your personal information in order to help detect, prevent, and mitigate fraud and abuse of our Services and to protect you against account compromise or funds loss. If you do not provide personal information required by law, we will have to close your account.
We process your personal information to provide Services to you. For example, when you want to store funds on our platform, we require certain information such as your identification, contact and payment information. Third parties that we use such as identity verification services may also access and/or collect your personal information when providing identity verification and/or fraud prevention services. In addition, we may need to collect fees based on your use of our Services. We collect information about your account usage and closely monitor your interactions with our Services. The consequences of not processing your personal information for such purposes is the termination of your account.
According to your preferences and in compliance with applicable law, we may send you marketing communications to inform you about events, to deliver targeted marketing and to share promotional offers. If you are a new customer, we will contact you by electronic means for marketing purposes only if you have consented to such communication. If you do not want us to send you marketing communications, please go to your account settings to opt-out or submit a request via privacy@pay-mesh.com
We may send you service updates regarding administrative or account-related information, security issues, or other transaction-related information. These communications are important to share developments relating to your account that may affect how you can use our Services. You cannot opt-out of receiving critical service communications.
We also process your personal information when you contact us to resolve any questions, disputes, collect fees, or to troubleshoot problems. Without processing your personal information for such purposes, we cannot respond to your requests and ensure your uninterrupted use of the Services.
Sometimes the processing of your personal information is necessary for our legitimate business interests, such as:
Legal bases for processing your information
For individuals located in the European Economic Area, United Kingdom or Switzerland at the time their personal data is collected, we rely on legal bases for processing your information under the relevant data protection legislation. These bases mean we will only process your data where we are legally required to, where processing is necessary to perform any contracts we entered with you (or to take steps at your request prior to entering into a contract with you), for our legitimate interests to operate our business, to protect Paymesh's or your property rights, or where we have obtained your consent to do so. We will not use your personal information for purposes other than those purposes we have disclosed to you, without your permission.
Disclosing your personal information to third parties
We allow your personal information to be accessed only by those who require access to perform their work and share it only with third parties who have a legitimate purpose for accessing it. Paymesh will never sell or rent your personal information to third parties without your explicit consent. We will only share your personal information with the following types of third parties:
Third-party sites and services
If you authorize one or more third-party applications to access your Paymesh Services, then information you have provided to Paymesh may be shared with those third parties. A connection you authorize or enable between your Paymesh account and a non-Paymesh account, payment instrument, or platform is considered an “account connection.” Unless you provide further permissions, Paymesh will not authorize these third parties to use this information for any purpose other than to facilitate your transactions using Paymesh Services. Please note that third parties you interact with, should have their own privacy policies and Paymesh is not responsible for their operations or their use of data they collect.
Examples of account connections include:
How we protect and store personal information
Paymesh implements and maintains reasonable measures to protect your information. Customer files are protected with safeguards according to the sensitivity of the relevant information. Reasonable controls (such as restricted access) are placed on our computer systems. Physical access to areas where personal information is gathered, processed or stored is limited to authorized employees.
We may store and process all or part of your personal and transactional information, including certain payment information, such as your encrypted bank account and/or routing numbers, in the US and elsewhere in the world where our facilities or service providers are located. We protect your personal information by maintaining physical, electronic, and procedural safeguards in compliance with the applicable laws and regulations.
As a condition of employment, Paymesh’s employees are required to follow all applicable laws and regulations, including in relation to data protection law. Access to sensitive personal information is limited to those employees who need to it to perform their roles. Unauthorized use or disclosure of confidential customer information by a Paymesh employee is prohibited and may result in disciplinary measures.
When you contact a Paymesh employee about your file, you may be asked for some personal details. This type of safeguard is designed to ensure that only you, or someone authorized by you, has access to your file. You also play a vital role in protecting your own personal information. When registering with our Services, choose a password of sufficient length and complexity, don’t reveal it to any third-parties and immediately notify us if you become aware of any unauthorized access to or use of your account.
Retention of personal information
How long we hold your personal information for will vary. The retention period will be determined by the following criteria:
If you have further questions about our data retention practices, please contact us at privacy@pay-mesh.com
If we anonymize your personal information so that it can no longer be associated with you, it will no longer be considered personal information, and we can use it without further notice to you.
Children's personal information
We do not knowingly request to collect personal information from any person under the age of 18. If a user submitting personal information is suspected of being younger than 18 years of age, Paymesh will require the user to close his or her account and will not allow the user to continue using our Services. We will also take steps to delete the information as soon as possible. Please notify us if you know of any individuals under the age of 18 using our Services so we can take action to prevent access to our Services.
Cross border transfers
Paymesh is an international business with operations in countries including the UK, the EU and the US. This means we may transfer to locations outside of your country. When we transfer your personal information to another country, we will ensure that any transfer of your personal information is compliant with applicable data protection law.
Data transferred out of the EU or UK
When we transfer your personal information outside of the United Kingdom (UK) or the European Economic Area (EEA), we will ensure that it is protected in a manner that is consistent with how your personal information will be protected by us in the UK and EEA respectively. This can be done in a number of ways, for instance:
In other circumstances the law may permit us to transfer your personal information outside the UK or EEA. In all cases, however, we will ensure that any transfer of your personal information is compliant with data protection law. You can obtain more details of the protection given to your personal information when it is transferred outside the UK and EEA (including a copy of the standard data protection clauses which we have entered into with recipients of your personal information) by contacting us as described below.
Your privacy rights
Depending on applicable law of where you reside, you may be able to assert certain rights related to your personal information. These rights include:
You can exercise your rights by contacting us using the details listed below. Further information about your rights may be obtained by contacting the supervisory data protection authority located in your jurisdiction.
How to contact us
If you have questions or concerns regarding this Privacy Policy, or if you have a complaint, please contact us at privacy@pay-mesh.com, or by writing to us at the Paymesh entity addresses provided above.
If you reside in the EU, you can file a complaint with the International Centre for Dispute Resolution by phone at +1.212.484.4181, or through your relevant data protection authority.
In the UK, the data protection authority is the Information Commissioner's Office.
In Singapore, the data protection authority is the Personal Data Protection Commission
US consumer privacy notice
This Consumer Privacy Notice applies to you if you are an individual who resides in the United States and uses Paymesh’s services for your own personal, family or household purposes.
Facts: What does Paymesh do with your personal information?
Reasons Paymesh Shares Your Personal Information
Questions?
What we do
How does Paymesh protect my personal information?
To protect your personal information from unauthorized access and use, Paymesh uses security measures that comply with federal law. These measures include computer safeguards and secured files and buildings.
How does Paymesh collect my personal information?
Paymesh collects your personal information when you:
Additionally, Paymesh also collects your personal information from others, such as affiliates or other companies.
Why can’t I limit all sharing?
Federal law gives you the right to limit only:
State laws and individual companies may give you additional rights to limit sharing. This section suggests that there are specific aspects of sharing that you cannot limit due to federal regulations, but there may be more options under state law or company-specific policies.
Definitions
California Privacy Rights
Pursuant to the California Consumer Privacy Act of 2018 (“CCPA”), California residents have certain rights in relation to their personal information, subject to limited exceptions. Any terms defined in the CCPA have the same meaning when used in this California Privacy Rights section.
Depending on which services you use, you may have different rights and choices for managing your personal data. For example, the CCPA does not apply to personal data collected, processed, or disclosed by a financial institution according to federal laws, such as the Gramm-Leach-Bliley Act. Please see the Consumer Privacy Notice below for additional information.
Collection and Disclosure of Personal Information
Over the past 12 months we may have collected and disclosed the following categories of personal information from or about consumers. We use this information for the purposes described in the “HOW WE USE YOUR PERSONAL INFORMATION” section of this Privacy Policy.
We may disclose each category of personal information listed to each entity listed in the “DISCLOSING YOUR INFORMATION TO THIRD PARTIES” section above. Paymesh does not sell your personal information in its ordinary course of business and will never sell your personal information to third parties without your explicit consent.
Rights under the CCPA
If you are a California resident and the CCPA does not recognize an exemption that applies to you or your personal information, you have the right to:
We aim to fulfill all verified requests within 45 days pursuant to the CCPA. If necessary, extensions for an additional 45 days will be accompanied by an explanation for the delay.
How to exercise your rights
You can exercise your rights by contacting us via our Support Portal so that we may consider your request.
If you are a California resident, you may designate an authorized agent to make a request to access or a request to delete on your behalf. We will respond to your authorized agent's request if they submit proof that they are registered with the California Secretary of State to be able to act on your behalf, or submit evidence you have provided them with power of attorney pursuant to California Probate Code section 4000 to 4465. We may deny requests from authorized agents who do not submit proof that they have been authorized by you to act on their behalf or are unable to verify their identity.
Vermont Privacy Rights
Vermont residents have certain rights in relation to their personal information, subject to limited exceptions. Under Vermont law, we will not share information we collect about Vermont residents with companies outside of our corporate family, unless the law allows. For example, we may share information with your consent, to service your accounts or under joint marketing agreements with other financial institutions with which we have joint marketing agreements. We will not share information about your creditworthiness within our corporate family except with your consent, but we may share information about our transactions or experiences with you within our corporate family without your consent.