Privacy Policy
This Privacy Policy explains how SoniqPay handles personal information — both the information we collect about visitors and business contacts, and the information we process on behalf of our customers when they use the Platform.
- Agreement
- Terms of Service
- Notice
- Cookie Notice
- Policy
- Acceptable Use Policy
- Addendum
- Data Processing Addendum
01Scope and our role
This Policy applies to SoniQ, Inc., and to the soniqpay.com website, our documentation and sandbox, our dashboard, and our marketing and sales activities.
Where we act as a controller
We act as a controller (or "business" under US state privacy laws) for personal information about website visitors, prospective customers, business contacts at our customers and partners, and job applicants. That processing is described in this Policy.
Where we act as a processor
When our customers use the Platform to process transactions, we act as a processor (or "service provider") on their behalf. We process that data only on their documented instructions, under our Data Processing Addendum. If you are an end user of one of our customers and want to exercise rights over your data, please contact that business directly — they control it, and we will support them in responding.
02Information you provide to us
- Contact and account details — name, business email, phone number, company name, job title, and the credentials you set for the dashboard.
- Business information — the details you share when requesting access, such as your industry, current providers, and approximate processing volume.
- Communications — the content of emails, support requests, demo calls, and forms you submit.
- Billing information — billing contact, address, and payment details where you are a paying customer.
03Information collected automatically
- Device and usage data — IP address, browser type and version, operating system, referring page, pages viewed, and timestamps.
- Cookies and similar technologies — as described in our Cookie Notice.
- Product telemetry — API call metadata, error rates, and dashboard interactions used to operate, secure, and improve the Services.
04Information from other sources
We may receive information from our partners and Providers, from business contact and enrichment databases, from public sources, and from referral partners who introduce us. We combine that information with what we already hold to qualify and manage business relationships.
05Cardholder and transaction data
Where our customers use the Platform, we receive payment card data and transaction data belonging to their end users. That data is handled within a PCI-scoped environment, is tokenized, and is processed solely to provide the Services on the customer's instructions.
We do not use cardholder data for our own marketing purposes and we do not sell it. We use transaction and risk signals to operate and improve fraud detection and routing, in aggregated or de-identified form and as permitted by our Data Processing Addendum.
06How we use information
- to provide, operate, secure, and support the Services;
- to respond to enquiries and provide sandbox and production access;
- to process billing and administer our contracts;
- to detect, investigate, and prevent fraud, abuse, and security incidents;
- to analyze and improve the Services, including model performance;
- to send service, security, and administrative communications;
- to send marketing communications where permitted, subject to your right to opt out; and
- to comply with legal obligations and enforce our terms.
07Legal bases (EEA, UK, Switzerland)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract, for providing the Services and administering our relationship; legitimate interests, for security, fraud prevention, product improvement, and business-to-business marketing; consent, where required, for certain cookies and marketing; and legal obligation, for compliance, tax, and record-keeping requirements.
Where we rely on legitimate interests, you may object at any time using the contact details below.
08How we share information
- Sub-processors and service providers — cloud hosting, infrastructure, analytics, support, and communications vendors, under written contracts. Our current list is maintained on our Sub-processors page.
- Providers — processors, acquirers, and networks you instruct us to connect to, as required to transmit transactions.
- Professional advisors — auditors, lawyers, and accountants, bound by confidentiality.
- Legal and safety — where required by law, legal process, or to protect the rights, property, or safety of SoniqPay, our customers, or others.
- Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under US state privacy laws.
09International transfers
We are based in the United States and may transfer personal information to countries other than the one you are located in. Where required, we use appropriate safeguards for such transfers, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where necessary. A copy of the relevant safeguards is available on request.
10Retention
We keep personal information for as long as needed for the purposes described in this Policy, and then for the period required to meet legal, tax, accounting, audit, and dispute-resolution obligations. Customer Data processed on behalf of a customer is retained and deleted in accordance with that customer's instructions and our Data Processing Addendum. Indicative retention periods are available on request.
11Security
We maintain technical and organizational measures appropriate to the risk, including encryption in transit and at rest, tokenization of card data, role-based access control, least-privilege administrative access, logging and monitoring, and third-party penetration testing. Our current compliance position is described on our Security page.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information; to object to or restrict certain processing; to withdraw consent; and to lodge a complaint with your supervisory authority.
To exercise a right, contact support@soniqpay.com. We will verify your request and respond within the time required by applicable law. We will not discriminate against you for exercising a right.
13US state privacy rights
Residents of California and other states with comprehensive privacy laws may have rights to know, delete, correct, and opt out of the sale or sharing of personal information and of certain profiling. As stated above, we do not sell or share personal information for cross-context behavioral advertising.
We honor opt-out preference signals, including Global Privacy Control, where required. You may designate an authorized agent to submit a request on your behalf, subject to verification.
14Cookies
We use cookies and similar technologies as described in our Cookie Notice, which explains the categories we use and how to control them.
15Children
The Services are intended for business use. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
16Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a revised effective date and, where the changes are material, provide additional notice.
17Contact
For privacy questions or requests, contact support@soniqpay.com or write to SoniQ, Inc. 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808.