About This Payment Management System Privacy Policy
This document explains how our organisation, reachable at paymentmanagementsystem.com, collects, processes, stores and protects information when you browse our pages, contact our team, request a product demonstration or use any of our billing and reconciliation tools. Written in plain language rather than dense legal jargon, this Payment Management System Privacy Policy gives merchants, finance managers and everyday visitors a clear picture of what happens behind the screen. Because we handle transaction-adjacent information, we hold ourselves to a higher standard than a typical content website: data minimisation, purpose limitation and encryption in transit and at rest are treated as engineering requirements, not optional extras.
Information We Collect
We collect three broad categories of information. The first is information you volunteer: your name, business email address, company name, country, phone number and any notes you type into a contact, quotation or support form. The second is account and configuration data created when you register, such as your username, hashed password, role permissions, notification preferences and dashboard layout choices. The third is technical information gathered automatically, including IP address, browser user-agent string, operating system, referring URL, pages viewed, session duration and approximate city-level location derived from your IP.
We deliberately do not ask for and do not store full primary account numbers, CVV codes or bank credentials on our own servers. Where card details are required during a live transaction, they are tokenised and transmitted directly to certified acquiring partners operating under PCI DSS Level 1 obligations. What remains on our systems is a token reference, the last four digits, the card brand, the transaction amount, currency, timestamp and an authorisation result — enough to reconcile a ledger, never enough to replay a payment.
How and Why We Use Your Data
Personal data is processed for defined, documented purposes only, as set out in this Payment Management System Privacy Policy. We use contact details to answer enquiries, issue invoices, deliver onboarding guidance and send service notices such as scheduled maintenance or security advisories. Account data keeps your workspace functioning: authenticating logins, applying role-based access controls and restoring your saved reports. Technical logs support fraud prevention, rate limiting, debugging and capacity planning. Aggregated, de-identified statistics help us understand which support resources reduce ticket volume and which checkout flows create friction.
Marketing messages are sent only where you have opted in or where a legitimate business relationship exists, and every message carries a working unsubscribe link. We never sell personal information, never rent mailing lists and never use payment metadata to build advertising profiles. Automated decision-making is limited to fraud scoring; any transaction flagged by the engine can be reviewed manually on request.
Cookies, Analytics and Embedded Content
Strictly necessary cookies maintain your session, remember your language and protect forms against cross-site request forgery. A temporary cookie set at the login screen simply confirms that your browser accepts cookies and disappears when the browser closes. Authentication cookies persist for two days, or two weeks if you tick “remember me”, while interface preference cookies last approximately twelve months. Analytics and preference cookies are loaded only after you accept them in the consent banner, and you can withdraw that consent at any time from the cookie settings link in the footer.
Some pages contain embedded resources such as product walkthrough videos, interactive pricing calculators or code sandboxes hosted by third parties. Interacting with that embedded content is technically the same as visiting the provider’s own website: they may set their own cookies, record your IP address and track engagement, particularly if you are already signed in to their platform. We encourage you to review the privacy notices of those providers, because their practices sit outside the scope of this Payment Management System Privacy Policy.
Sharing, Retention and Security
We share data with a short, audited list of processors: cloud hosting and backup providers, payment gateways and acquirers, email delivery services, help-desk software and spam-filtering tools that inspect submitted comments. Each processor signs a data processing agreement, is bound by confidentiality obligations and may use the data only on our documented instructions. Disclosure to regulators, auditors or law enforcement occurs solely when a valid legal obligation applies, and we notify affected users unless prohibited from doing so.
Retention periods are proportionate to purpose. Enquiry correspondence is kept for twenty-four months, account records for the life of the account plus ninety days, and financial or tax-related transaction records for the statutory period required in the relevant jurisdiction, commonly five to seven years. Server logs rotate after ninety days. Comments and their metadata are retained so follow-up posts can be approved automatically without repeated moderation. Security controls include TLS 1.2 or higher for all traffic, AES-256 encryption at rest, hashed and salted passwords, multi-factor authentication for administrators, network segmentation, least-privilege access reviews and independent penetration testing.
Your Rights Under This Payment Management System Privacy Policy
Depending on where you live, you may have the right to access a copy of your data, correct inaccuracies, request deletion, restrict or object to certain processing, withdraw consent, receive a portable export in a machine-readable format and lodge a complaint with a supervisory authority. Registered users can view, edit or delete most profile information directly from the dashboard; usernames remain fixed for audit integrity. Erasure requests are honoured except where records must be preserved for legal, accounting, anti-fraud or security reasons.
To make a request, email our privacy team using the address on the contact page. We verify identity before releasing data and respond within thirty days, extending only where a request is unusually complex. If you upload images, strip embedded EXIF location data first, since visitors can extract it. Cross-border transfers rely on standard contractual clauses or adequacy decisions. Material changes to this Payment Management System Privacy Policy will be announced on this page with a revised effective date, and continued use of the service after that date signals acceptance of the updated terms.
