Skip to main content

Legal & trust

Merchant privacy notice

How OID4Pay processes data when a merchant integrates the agent-payment flow.

1. Our role

OID4Pay B.V. is the controller for the authorisation layer: issuing and verifying mandates, running the protocol, and keeping the signed audit trail. The merchant is an independent controller for its own commerce. See the merchant data terms.

2. What we process and why

  • Mandate and verification (mandate, agent client id, caps, transaction metadata): to authorise and verify the payment. Lawful basis: contract.
  • Risk and step-up signals (transaction signals, velocity): to prevent fraud. Lawful basis: legitimate interest.
  • Audit and dispute chain (pseudonymous identifiers, event metadata): to provide a dispute trail and meet record-keeping duties. Lawful basis: legal obligation and legitimate interest.

Raw card numbers are never held by OID4Pay; Stripe processes card and payment data.

3. Recipients and transfers

We use Stripe to process card data and execute settlement. Stripe is US-linked; the transfer relies on the EU-US Data Privacy Framework with Standard Contractual Clauses as backup. Hosting is in the EU. The full list is on the sub-processors page.

4. Retention

Authorisation records are kept for the dispute and audit window; the audit chain is retained for the statutory financial-record period and is pseudonymous. We do not sell personal data.

5. Data-subject requests and contact

Wallet holders exercise their rights from the wallet; see the consumer privacy statement. Merchant data questions: privacy@oid4pay.com. You may also contact the Dutch supervisory authority, the Autoriteit Persoonsgegevens.