Plain-language summary. We collect the information needed to run our business, deliver engineering and certification services, operate our products, and communicate with you. We do not sell your personal information for money. We protect cardholder data under PCI DSS. You have rights over your information, described below.
1. Who we are
This website and the associated products and services are operated by Mojave Payment Technologies, LLC, doing business as Paying.co ("Paying.co," "Company," "we," "us," or "our"), a limited liability company organized under the laws of the State of Nevada, with its principal place of business at 1500 East Tropicana Avenue, Suites 230-234, Las Vegas, Nevada 89119, United States.
We are a payment engineering firm. Our work includes EMV Level 3 certification, custom payment application development, unattended and SoftPOS/MPoC systems, PCI compliance support, and a portfolio of payment-related software products.
2. Scope of this policy
This Privacy Policy applies to information we collect through our websites located at paying.co and related domains, our software products and platforms, our email and other communications, and our business and professional services (collectively, the "Services").
This policy does not apply to the practices of third parties we do not own or control, including our clients, processors, acquirers, and integration partners. Where we process information on behalf of a business client as a service provider or data processor, our handling of that information is governed by our agreement with that client, and that client's own privacy notice typically applies to the individuals whose data is involved.
3. Information we collect
3.1 Information you provide
- Contact and identity information such as name, business name, title, email address, phone number, and mailing address, for example when you complete a contact form, request a proposal, or correspond with us.
- Project and account information such as the details you share about your business, technical requirements, hardware, processors, and integration needs.
- Communications including the content of emails, support requests, and other messages you send us.
- Newsletter and marketing preferences, including your email address if you subscribe to updates.
3.2 Information collected automatically
- Device and usage data such as IP address, browser type, operating system, referring pages, pages viewed, and timestamps.
- Cookies and similar technologies, as described in Section 8.
3.3 Information from third parties
- Business contact and enrichment data from lawful business data providers used for sales, outreach, and customer relationship management.
- Service providers such as analytics, email delivery, and hosting vendors that supply information about how our Services are used.
4. How we use information
We use the information we collect to:
- Provide, operate, maintain, and improve our Services;
- Respond to inquiries, prepare proposals and statements of work, and deliver contracted services;
- Process and administer projects, accounts, billing, and payments owed to us;
- Send administrative, technical, and transactional communications;
- Send marketing and newsletter communications, where permitted, which you may opt out of at any time;
- Monitor, secure, and troubleshoot our Services, and detect and prevent fraud or misuse;
- Comply with legal obligations and enforce our agreements; and
- Conduct internal analytics, research, and business operations.
5. Legal bases for processing
Where required by applicable law, we process personal information on one or more of the following bases: performance of a contract with you; our legitimate business interests, balanced against your rights; your consent, where applicable; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
7. Payment and cardholder data
As a payment engineering firm, we may handle, process, or have access to cardholder data and sensitive authentication data in the course of our engineering, certification, and support work. When we do so, we maintain controls consistent with the Payment Card Industry Data Security Standard (PCI DSS) and applicable network rules.
Where we act on behalf of a client, the client generally remains the controller or owner of cardholder data, and our handling is governed by our written agreement with that client. We do not use cardholder data for any purpose other than performing the contracted services and complying with applicable law and network requirements.
Note. Payments you make to us for our services are processed by third-party payment processors. We do not store full payment card numbers on our general business systems. Those processors handle your payment information under their own privacy and security terms.
9. Data retention
We retain personal information for as long as necessary to fulfill the purposes described in this policy, including to provide the Services, comply with our legal, accounting, tax, and reporting obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we delete or de-identify it using reasonable measures.
10. Security
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, appropriate to the nature of the information and consistent with applicable law, including the Nevada data-security requirements described in Section 12. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Your privacy rights
Depending on where you live and applicable law, you may have rights to:
- Request access to the personal information we hold about you;
- Request correction of inaccurate information;
- Request deletion of your information;
- Opt out of marketing communications;
- Opt out of the sale of your covered information, as described for Nevada residents below; and
- Opt out of certain sales or sharing and certain profiling, as described for California residents below.
To exercise any of these rights, contact us using the details in Section 18. We will respond within the timeframes required by applicable law. We will not discriminate against you for exercising your rights.
12. Nevada residents
This Privacy Policy and our practices are governed by the laws of the State of Nevada, without regard to conflict-of-laws principles.
12.1 Right to opt out of the sale of covered information
Under Nevada Revised Statutes Chapter 603A, Nevada consumers have the right to direct a covered website operator not to make any sale of certain "covered information" that the operator has collected or will collect about the consumer. "Sale" under Nevada law means the exchange of covered information for monetary consideration to be licensed or sold to another person.
We do not sell covered information as defined under Nevada law. If our practices change, we will update this policy and honor verified opt-out requests. To submit a request, email sales@paying.co with the subject line "Nevada Opt-Out." We will respond within the period required by NRS 603A.
12.2 Data security
Consistent with NRS 603A, we maintain reasonable security measures to protect personal information collected from Nevada residents from unauthorized access, acquisition, destruction, use, modification, or disclosure, and we contractually require our service providers to do the same.
12.3 Breach notification
In the event of a breach of the security of the system data involving unencrypted personal information, we will provide notification to affected Nevada residents in accordance with the requirements and timeframes of Nevada law.
13. California residents
If you are a California resident, the California Consumer Privacy Act, as amended, may provide you with additional rights, including the right to know, the right to delete, the right to correct, the right to opt out of the sale or sharing of personal information, and the right to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined under California law. To exercise your rights, contact us using the details in Section 18.
14. International transfers
We are based in the United States and operate internationally. If you access the Services from outside the United States, your information may be transferred to, stored in, and processed in the United States and other countries that may have different data-protection laws than your jurisdiction. Where required, we implement appropriate safeguards for such transfers.
15. Children's privacy
Our Services are intended for businesses and are not directed to children under the age of 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
16. Third-party links and services
Our Services may contain links to third-party websites, products, and services that we do not control. This Privacy Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. We encourage you to review the privacy notices of any third party before providing information.
17. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Services after an update constitutes acceptance of the revised policy.
18. Contact us
If you have questions about this Privacy Policy or our privacy practices, or to exercise your rights, contact us:
Paying.co (Mojave Payment Technologies, LLC)
1500 East Tropicana Avenue, Suites 230-234
Las Vegas, Nevada 89119, United States
Email: sales@paying.co
Phone: +1 702-664-1250