Privacy and Data Protection Policy
What Meridian Payments processes, why it is needed, and how user rights are protected.
1. Scope
This Policy explains how personal data is processed and protected across the Meridian Payments website, hosted checkout, dashboard, API, and related services (the “Service”).
2. Data we process
- merchant representative data: name, work email, phone, company, role, and application details;
- account and security data: password hash, email verification, sessions, devices, IP address, and sign-in events;
- payer data: name, phone, email, IP address, user agent, and provider metadata only where required for a transaction;
- payment data: amount, currency, method, status, order and transaction identifiers, refunds, and settlement events;
- technical data: request logs, webhook events, diagnostics, and necessary cookies.
3. Data we do not collect
Meridian Payments does not accept or store full card numbers, CVV/CVC, PINs, or other secret payment credentials. In production, these must be handled only by certified payment providers.
4. Purposes and legal bases
- register, review, and secure companies and accounts;
- create, confirm, and account for payments, refunds, settlements, and payouts;
- prevent fraud, investigate incidents, and meet legal obligations;
- deliver service messages, notifications, and support;
- operate, audit, measure, and improve the Service;
- perform a contract, take pre-contract steps, comply with law, and rely on consent as applicable.
5. Payer data isolation
Payer data is stored separately in encrypted form. It is excluded from client DTOs, payment lists and details, search, CSV exports, and merchant webhooks. Merchants cannot access it through the dashboard or Merchant API.
Only an authorized platform administrator may reveal it through a dedicated protected action. Every reveal creates an immutable audit event.
6. Recipients and processors
We may use hosting, database, email delivery, monitoring, anti-fraud, and payment infrastructure providers only to the extent required to operate the Service. Access is limited by purpose, contract, and least privilege. Disclosures to public authorities occur only where a valid legal basis exists.
7. Retention and deletion
Data is retained only as long as needed for the stated purposes, contracts, financial records, claims, and mandatory retention periods. It is then deleted, anonymized, or archived with restricted access.
8. Security
- AES-256-GCM encryption for sensitive data with key versioning;
- secure cookies, short-lived access sessions, and refresh-session rotation;
- multi-factor authentication for administrators;
- server-side tenant isolation;
- audit trails for PII access, administrative actions, and financial changes;
- backups, monitoring, and incident-response procedures.
9. Your rights
- request information about processing;
- correct inaccurate data;
- request deletion or restriction where the law allows;
- withdraw consent without affecting prior lawful processing;
- object to certain processing and contact the competent supervisory authority.
10. Requests and updates
Submit a privacy request through the Meridian Payments contact form using the subject “Personal data.” We may verify the requester’s identity before acting.
New versions are published on this page with an updated date and version number. Material changes are additionally communicated through the dashboard or email where required.
The Meridian team will respond through the contact form.