Privacy policy
Last updated: 2 September 2026
This policy explains how personal data is used when you access the PayPOS merchant application, manage payment requests, or contact support.
Who is responsible for your data?
Paytweak SAS processes merchant account, security, and service-operation data as a data controller. For customer data entered by a merchant, the merchant generally determines the purpose of processing and Paytweak acts on its documented instructions, subject to the applicable contract.
RCS Évreux et Paris 809 462 955 · Registered office: 12 rue Traversière, 27140 Gisors, France
Data we process
Account and business information, authorized-user details, authentication and password-reset events, support exchanges, IP address, session, app version, and device diagnostics.
Payment-request and transaction metadata, including amount, reference, status, selected method, delivery channel, recipient contact supplied by the merchant, and masked card information returned by the payment provider.
Full card numbers and card security codes are entered on the secure pages of the merchant’s payment provider and are not intended to be stored by PayPOS.
Why we process it
To provide and secure the service, authenticate users, create and track payment requests, deliver receipts and transactional messages, provide support, prevent misuse, and meet legal or regulatory duties.
Depending on the purpose, processing is based on performance of the contract, compliance with legal obligations, legitimate interests in security and service improvement, or consent where it is specifically requested.
Recipients and service providers
Access is limited to authorized Paytweak teams and providers that are necessary to operate the service, such as hosting, transactional email or SMS delivery, and the payment providers selected by the merchant. Data may also be disclosed where required by law.
Where a provider processes data outside the European Economic Area, appropriate contractual or legal safeguards must be used in accordance with applicable data-protection law.
Retention and security
Data is kept only for the time needed to provide the service, secure accounts, handle disputes, and comply with statutory retention duties. Retention periods vary by data category and the merchant’s contract.
Paytweak uses access controls, encrypted communications, logging, and other proportionate technical and organizational measures. No online service can guarantee absolute security; users must protect their credentials and devices.
Your rights
Subject to legal conditions, you may request access, correction, deletion, restriction, objection, or portability, and withdraw consent where processing relies on consent. Requests may be sent to dpo@paytweak.com.
You may also lodge a complaint with CNIL. If the data was collected by a merchant, contact that merchant first because it may be the data controller for that processing.
Changes to this policy
This policy may be updated to reflect changes to PayPOS, providers, or legal requirements. Material changes will be communicated through an appropriate channel.