Legal & trust
Merchant privacy notice
How OID4Pay processes data when a merchant integrates the agent-payment flow.
1. Our role
OID4Pay B.V. is the controller for the authorisation layer: issuing and verifying mandates, running the protocol, and keeping the signed audit trail. The merchant is an independent controller for its own commerce. See the merchant data terms.
2. What we process and why
- Mandate and verification (mandate, agent client id, caps, transaction metadata): to authorise and verify the payment. Lawful basis: contract.
- Risk and step-up signals (transaction signals, velocity): to prevent fraud. Lawful basis: legitimate interest.
- Audit and dispute chain (pseudonymous identifiers, event metadata): to provide a dispute trail and meet record-keeping duties. Lawful basis: legal obligation and legitimate interest.
Raw card numbers are never held by OID4Pay; Stripe processes card and payment data.
3. Recipients and transfers
We use Stripe to process card data and execute settlement. Stripe is US-linked; the transfer relies on the EU-US Data Privacy Framework with Standard Contractual Clauses as backup. Hosting is in the EU. The full list is on the sub-processors page.
4. Retention
Authorisation records are kept for the dispute and audit window; the audit chain is retained for the statutory financial-record period and is pseudonymous. We do not sell personal data.
5. Data-subject requests and contact
Wallet holders exercise their rights from the wallet; see the consumer privacy statement. Merchant data questions: privacy@oid4pay.com. You may also contact the Dutch supervisory authority, the Autoriteit Persoonsgegevens.