Version 2026.09.1Effective 8 September 202620 min read
This Privacy Policy explains how PaymentFlux Ltd (“PaymentFlux”, “we”, “us”, “our”) collects, uses, shares and retains personal data when you use our websites, applications and related customer-facing services (the “Platform”) and the functionality we make available through the Platform (the “Service”).
It is intended to help you understand:
This Policy should be read with our Platform Terms and Cookie Policy. Nothing in this Policy removes rights you have under applicable law that cannot be limited or excluded.
We are PaymentFlux Ltd.
For the processing described in this Policy that PaymentFlux determines the purposes and means of, PaymentFlux Ltd is the data controller.
Other organisations may also process related personal data as independent controllers for their own purposes. That can include, for example, your card issuer, banks involved in a transfer, Companies House in relation to public-register information, a Payment Partner such as Stripe when acting for its own regulatory or fraud purposes, or a Recipient after funds have been transferred. PaymentFlux is not the controller for processing that those organisations independently determine.
| Purpose | How to contact us |
|---|---|
| Routine privacy questions, rights requests and most data-protection matters | Support Centre — https://paymentflux.co.uk/support/contact/ or privacy@paymentflux.co.uk |
| Formal legal notices that are not privacy requests | legal@paymentflux.co.uk |
Privacy and data-protection requests are handled by our privacy contact (the person responsible for privacy matters). PaymentFlux has not appointed a Data Protection Officer under UK GDPR.
This Policy covers personal data processed in connection with:
It does not cover websites, apps or services operated by third parties that we do not control, even if we link to them.
Depending on how you use the Service, we may process the categories of personal data described in sections 6 to 14. We aim to collect only what is reasonably needed for the Service, Verification Checks, security, support and legal compliance.
Please do not send us special-category data (such as health information) or criminal-offence information unless we specifically ask for it and it is necessary. Documents you upload may occasionally contain incidental sensitive information. See section 16 for how we treat that risk.
You may give us personal data when you:
We may also receive personal data from:
Where we obtain personal data from a source other than you, we use it for the purposes and on the lawful bases described in this Policy.
This may include:
Identity verification is carried out using specialised providers (currently including Didit and, where configured, Stripe Identity). PaymentFlux receives verification outcomes and related case metadata rather than treating identity-document images as a general customer download.
When you add a Recipient or start a Property Payment, we may process:
You may provide personal data about a landlord, letting agent or other related person.
You should:
PaymentFlux uses Recipient and related-person information to assess eligibility, verify account/name alignment, review relationship evidence, prevent fraud, execute or support the payment, and keep records. PaymentFlux remains responsible for how it processes that data as controller for its own purposes. Providing Recipient data does not transfer all UK GDPR duties to you, and it does not make PaymentFlux responsible for processing independently determined by the Recipient or their bank.
When you make or prepare a Property Payment, we may process:
Full card numbers and card security codes (CVC/CVV) are collected directly by our card-processing Payment Partner (Stripe) through Stripe.js / Elements. PaymentFlux’s systems are designed not to receive or store full primary account numbers or card security codes. PaymentFlux stores only the limited card and payment-method metadata needed to operate the Service, support disputes and meet security and audit needs.
This may include:
Evidence files are stored in encrypted cloud storage controlled by PaymentFlux. We do not expose raw storage keys or OCR internals to customers.
This may include:
Optional analytics on the marketing website and customer app, where those tags are configured and you have given the relevant consent, are described in section 14 and in our Cookie Policy. We do not currently operate advertising or remarketing pixels.
This may include:
Customer email is currently sent through our email delivery provider (Resend). Support cases are handled in PaymentFlux’s own Support service rather than a separate third-party helpdesk product.
We may process:
We may use optional analytics technologies on the marketing website and the customer app where those tags are configured and you have given the relevant consent. Those technologies are not necessary for the Service and are not required to make a Property Payment. Their purpose is to understand how the Platform is used, improve customer journeys, and measure acquisition and funnel performance.
The current optional analytics configuration uses Google Analytics, managed through Google Tag Manager. PaymentFlux does not currently identify you to Google Analytics using a PaymentFlux account identifier. We do not currently use advertising or remarketing technologies, and Microsoft Clarity is not currently configured. If you select Reject optional, those optional analytics will not run. You can control or change optional-cookie choices through Cookie settings. Further operational detail is in our Cookie Policy.
Essential service communications (for example security alerts, payment status and Verification Check updates) are not marketing.
We use personal data to:
Under UK GDPR, we rely on one or more of the following lawful bases, depending on the purpose:
| Purpose | Typical data involved | Likely lawful basis | Is provision required? | If you do not provide it |
|---|---|---|---|---|
| Register and administer an account | Contact details, authentication data, account identifiers | Contract (Art. 6(1)(b)) | Required to create and use an account | You cannot register or use the Service |
| Provide the Platform and Service | Account, profile, Recipient and payment data needed for requested features | Contract | Required for the features you request | Those features will not work |
| Process a Payment Instruction | Payment, Recipient, card-metadata and status data | Contract | Required to make the Property Payment | The payment cannot proceed |
| Identity verification before live payments | Identity-check information and verification outcomes | Contract; legitimate interests in preventing misuse (Art. 6(1)(f)); legal obligation only where a specific obligation applies | Required before live Property Payments where our processes require it | Live payments may be refused or delayed |
| Recipient Verification Checks and relationship-evidence review | Recipient, account, register, document and review data | Contract; legitimate interests in reducing payment and fraud risk | Required for supported Property Payments that need those checks | The Recipient or payment may remain blocked |
| Fraud prevention, account security, suspected-misuse investigation and Platform/payment security | Device, technical, risk, authentication, payment and evidence records | Legitimate interests in protecting customers, Recipients and the Platform; legal obligation where a specific obligation applies | Often unavoidable for secure use of the Service | We may refuse, delay or restrict access or payments |
| Essential service communications | Contact details, payment/account event data | Contract; legitimate interests in operating the Service securely | Needed for operational messages | You may miss important security or payment updates |
| Support, complaints, refunds and disputes | Support messages, payment and account records | Contract; legitimate interests in resolving issues and defending claims | Needed to investigate your request | We may be unable to help fully |
| Audit, transaction and consent records | Acceptance records, payment and verification history | Legitimate interests in accountability and dispute handling; legal obligation where record-keeping rules apply | Not usually a separate customer “form” field | N/A |
| Reliability, security monitoring and product performance | Technical logs, limited diagnostics | Legitimate interests in keeping the Service secure and reliable | Occurs as part of using the Service | Service quality or security may be affected |
| Optional analytics or marketing cookies / similar technologies | Cookie identifiers and related usage data | Consent (Art. 6(1)(a)); PECR consent rules also apply | Optional | Non-essential technologies will not run. You can still use the Service, including making a Property Payment |
| Electronic marketing (email/SMS), if offered | Contact details and preferences | Consent and/or PECR soft opt-in where lawfully available; UK GDPR consent or legitimate interests assessed case by case | Optional | You will not receive that marketing |
| Legal claims, regulatory requests and compliance | Relevant account, payment, evidence and communication records | Legal obligation (Art. 6(1)(c)) where applicable; legitimate interests in establishing, exercising or defending legal claims | Depends on the request or obligation | We may be required to act anyway |
| Lawful cooperation with Payment Partners, banks and competent authorities | Relevant payment, account, identity and investigation records | Legal obligation where applicable; legitimate interests in preventing fraud, protecting the Service and cooperating lawfully | Depends on the request or obligation | We may be required or permitted to act anyway |
We do not intentionally require special-category data or criminal-offence data to use the Service. If a document you upload incidentally contains such information, we will treat that as a data-mapping and risk issue, limit use to what is necessary for the relevant review or security purpose, and seek appropriate conditions before any broader processing. Customers should avoid including unnecessary sensitive information in uploads.
Verification Checks are designed to assess whether an intended Recipient appears eligible to receive a supported rent Property Payment, and to assess payment details, relationship evidence, payment purpose and associated risk.
Depending on the journey, checks may use:
Passing Verification Checks means the relevant checks we apply have been completed successfully according to our processes at that time. It does not mean we certify the Recipient, guarantee entitlement to funds, or remove your responsibility to check payment details.
We use fraud-prevention and security measures that may include:
These measures protect Customers, Recipients and the Platform. They are risk-based and are not a guarantee that harmful activity will always be detected or prevented.
We may process personal data, where necessary and proportionate, to:
We may disclose relevant personal data where required by law, or where disclosure is otherwise lawful, necessary and proportionate. We do not automatically report every case of suspected fraud. Investigation of suspected fraud does not, by itself, mean that a crime has been committed.
We aim to share only the personal data that is reasonably needed for the relevant purpose.
We use automated rules and risk indicators to assist reviews and to route payments or account events (for example to require additional authentication, send a payment for manual review, or refuse a high-risk attempt under policy).
Some cases are referred for manual review by operators. Identity verification, relationship-evidence decisions and many Verification Check outcomes also involve human review where our processes require it.
We do not currently describe any processing in this Policy as a solely automated decision producing legal or similarly significant effects under UK GDPR Article 22 without further confirmation. If that analysis changes, we will update this Policy and provide the required information and safeguards.
We share personal data only where needed for the purposes above, including with the categories of recipients in sections 21 to 25.
We do not sell your personal data.
Not every recipient is a “processor” acting only on our instructions. Some organisations are independent controllers for their own purposes.
We share payment-related data with Payment Partners, currently including Stripe, to:
Your card issuer and the banks involved in a transfer also process personal data as independent controllers under their own terms and notices.
Depending on the journey, we may share or obtain data involving:
We use service providers to host and operate the Platform. Categories include:
These providers process personal data only as needed to provide their services to us, under contract where they act as processors, or under their own controller terms where that is the correct role.
If a Property Payment is transferred to a Recipient, the Recipient and their bank will receive the payment details needed to credit the funds (for example amount, reference and payer information shown on the transfer). After transfer, the Recipient processes that information under their own arrangements with you.
We may share personal data with:
We do not automatically disclose personal data whenever fraud is suspected. Any disclosure is limited to what is relevant to the purpose.
PaymentFlux’s primary application infrastructure is operated in the United Kingdom (documented default region eu-west-2).
Some providers we use — including Payment Partners, identity-verification providers, email delivery providers and authentication providers — may process personal data in the UK, European Economic Area or other countries.
Where personal data is transferred internationally, we rely on a legally permitted mechanism appropriate to the transfer. That may include:
We will not claim that a specific safeguard applies to every provider until the transfer map for that provider is confirmed. If you need more detail about a particular transfer, contact privacy@paymentflux.co.uk.
We keep personal data only for as long as needed for the purposes in this Policy, including legal, accounting, dispute, fraud-prevention and audit needs. Exact retention periods depend on the record type and are maintained in an internal retention schedule.
In determining retention, we consider:
| Record type | Retention approach |
|---|---|
| Account and profile records | Kept while the account is active and for a further period after closure or inactivity where needed for security, disputes and legal claims |
| Payment and transfer records | Kept for the period needed for payment operations, disputes, accounting and legal claims. Payment-related notification evidence is retained for at least 7 years |
| Identity, Recipient verification and relationship-evidence records | Kept for the period needed to operate Verification Checks, defend decisions, prevent fraud and handle disputes |
| Fraud, security and audit logs | Kept for a period aligned to security investigation and accountability needs; short-lived technical tokens and idempotency keys may expire earlier by design |
| Support records | Kept for the period needed to resolve the case and for a reasonable follow-on dispute/audit period |
| Consent and legal-acceptance records | Kept for as long as needed to show which version you viewed or accepted and to meet accountability duties |
| Cookie preferences | Stored for up to 365 days, and refreshed or asked again when you change preferences or when the published Cookie Policy version materially changes |
| Marketing suppression records | Kept for as long as needed to honour an opt-out |
| In-app notification inbox copies | Convenience copies may be available for about 12 months, while underlying communication evidence may be kept longer as above |
When personal data is no longer required, we delete or irreversibly anonymise it where feasible, unless a longer retention is required by law or needed for legal claims.
We implement technical and organisational measures designed to protect personal data, including encryption in transit, access controls, least-privilege operator access, monitoring, and separation of card data so that full card numbers and security codes are handled by Stripe rather than stored by PaymentFlux.
No method of transmission or storage is completely secure. Please protect your login credentials and tell us promptly through the Support Centre if you suspect unauthorised access.
Under UK data-protection law, you may have the right to:
These rights are not absolute. They depend on the circumstances, the lawful basis we rely on, and applicable exemptions (for example where retaining data is necessary for legal claims, fraud prevention or legal compliance).
We do not offer a self-service erasure tool that deletes payment, fraud-prevention or legal-acceptance records while we still need them. Erasure requests are assessed under UK data-protection law.
To exercise your rights, contact us through:
You do not need to use a particular form of words. We may ask for reasonable information to verify your identity and to locate the data you are asking about. We will respond within the time limits required by law.
If you are unhappy with how we have used your personal data, please contact us first so we can try to resolve the issue.
You also have the right to complain to the Information Commissioner’s Office:
The Platform is intended for adults aged 18 or over. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact privacy@paymentflux.co.uk and we will take appropriate steps.
We may update this Privacy Policy from time to time. When we publish a new version through our consent catalogue, the version label and effective date below will change. Where a change is material, we will take reasonable steps to bring it to your attention (for example through the Platform or by email).
| Field | Value |
|---|---|
| Document | Privacy Policy |
| Version label | 2026.09.1 |
| Effective from | 8 September 2026 (UTC) |
| Locale | en-GB |
This Policy applies from the effective date above once published through our consent catalogue for that version. Until published, earlier published versions continue to apply where already in use.