Privacy Policy
1. Who we are
Zirapay is an online-checkout platform operated by ZIRAPAY LLC, registered at 312 W 2nd St, Unit 3949, Casper, WY 82601, USA. We process personal data when you use our checkout, SDKs, dashboard or this website. This policy explains what we collect, why, and the choices you have. It applies to merchants and to people whose data passes through our checkout on a merchant's behalf.
Where we decide how and why data is processed, we act as a controller. Where we process payment data on a merchant's instructions to authorize and recover their transactions, we act as a processor for that merchant.
2. Data we collect
We keep collection tight and tied to running the checkout. Depending on how you use Zirapay, this can include:
- Account data — your name, work email, company details and dashboard settings.
- Transaction data — amounts, currencies, timestamps, order and payment-method identifiers, and the authorization outcome for each attempt.
- Device data — signals such as IP address, browser and device characteristics used to prevent fraud and tune authorization.
- Usage data — how you interact with the dashboard and documentation, so we can keep them working and improve them.
3. Why we process it
We process personal data to authorize and recover payments, to prevent fraud and abuse, to run and secure the dashboard and SDKs, to support you, and to meet our legal and card-network duties. Our lawful bases are performance of a contract, our legitimate interest in operating a reliable and fraud-resistant checkout, and compliance with legal obligations.
4. Card data
Card details are tokenized at the point of entry and are never stored on your servers. We handle cardholder data inside a PCI DSS Level 1 environment, the highest level of compliance in the card industry, and replace card numbers with tokens for retries, network tokens and authorization routing. You build against tokens, not raw card numbers.
5. Sharing
To move a payment from attempt to approval, we share the data needed with card networks and acquiring banks, and with vetted sub-processors that help us run the platform under contract. We disclose data to authorities only where the law requires it. We never sell personal data, and we never share it for unrelated advertising.
6. International transfers
Data from the EU and EEA is kept within the EU and EEA. Where a transfer outside that area is unavoidable, we rely on Standard Contractual Clauses and appropriate safeguards so your data keeps the same level of protection wherever it is handled.
7. Retention
We keep personal data only as long as needed for the purpose it was collected, and longer where card-network rules, accounting and other legal obligations require it — for example, transaction records kept to handle disputes and audits. When data is no longer needed, we delete or anonymize it.
8. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. Under the GDPR these rights apply to people in the EU and EEA; similar rights exist in other regions.
To exercise any of these rights, or if you have a question about this policy, email us at [email protected]. If Zirapay processes your data on behalf of a merchant, we will direct your request to that merchant and support them in answering it.