All systems operational · 99.99% uptime

Legal · Privacy Policy

What we collect, and why.

Effective March 30, 2026. We move money for a living, so we handle data the same way: minimally, deliberately, and on the record.

1. Scope & roles

This policy covers latchpay, Inc. ("latchpay", "we") and describes how we handle personal data on latchpay.xyz and in the latchpay settlement and payouts platform. We wear two hats, and it matters which one is on:

  • Controller. For data about our own customers, prospective customers, and website visitors — account details, billing records, support threads, analytics — we decide why and how it is processed, and this policy is the primary document.
  • Processor-like role. For the recipient data our platform customers submit to execute payouts — the sellers, creators, and vendors they pay — the customer decides why that data is processed. Our processing of that data follows the instructions those customers document in our data processing terms — theirs to give, ours to follow. Their privacy notice, not this one, governs the relationship with those recipients.

If you received a payout through a platform built on latchpay and want to know what happens to your data, start with Section 3 and then with that platform's own privacy notice.

2. Data we collect as a controller

Account data

For every person your organization seats on the platform: their name, their work address, the company and role they hold, and the authentication records their sessions generate. We do not ask for personal data we do not need to run an account.

Billing data

Legal entity name, billing address, tax identifiers, invoice history, and the payment details needed to charge per-payout fees. Cards never touch our systems — the processor holds them, and all we keep is a token plus the trailing four digits.

API request metadata

Timestamps, endpoint paths, key identifiers, IP addresses, response codes, and idempotency keys — the operational exhaust needed to debug integrations, enforce rate limits, and investigate abuse. Full bank credentials are never written to logs. Account and routing numbers are redacted at the logging layer before a line is persisted, and this behavior is covered by our SOC 2 audit.

Support communications

Emails to support@latchpay.xyz, tickets, and notes from calls, kept so the next engineer who picks up your thread has context.

What we do not collect

No data-broker enrichment, no advertising identifiers, no biometric data, no precise location. If a field is not needed to run an account, bill it, or satisfy a regulator, we do not ask for it.

3. Recipient data we process for customers

To execute a payout, our customers submit recipient names, bank account details (account and routing numbers, IBANs), and amounts. We collect exactly these fields because payouts legally require them — a Fedwire or ACH entry cannot be originated without them. We also generate and store sanctions-screening results for each recipient, because federal law requires us and our banking partners to screen before funds move.

Recipient data is processed for one purpose: executing and reconciling the payouts our customer instructed. It is never used for our own marketing, never used to build profiles, and never sold or resold to anyone. Full stop.

Screening results and payout records are retained as described in Section 8, because anti-money-laundering law does not give us a choice about that.

4. Purposes

Personal data has exactly these jobs here:

  • Provide, operate, and secure the platform — executing payouts, running reconciliation, delivering webhooks, and maintaining the ledger.
  • Meet legal obligations — sanctions screening, anti-money-laundering recordkeeping, tax reporting, and responses to binding legal process.
  • Bill for the service and collect what is owed.
  • Provide support and investigate incidents, including fraud and abuse.
  • Improve the product using aggregate, de-identified usage patterns.
  • Send product and marketing mail strictly to subscribers who asked for it — and every message can end the subscription in one click.

When European or UK data-protection law governs our processing, the bases are:

  • Performance of a contract — everything operationally necessary to run your account, invoice it, and execute the payouts you instruct.
  • Legal obligation — sanctions screening, AML recordkeeping, and tax and accounting requirements. This basis is not optional for us or for you.
  • Legitimate interests — platform defense, fraud detection, debugging from request metadata, and the handling of legal claims, each weighed against your rights before we proceed.
  • Consent — marketing communications, and nothing that the service functionally depends on. You can withdraw consent at any time without affecting your account.

Automated decision-making

Sanctions screening is automated, but a hit never results in an automatic final refusal: every flagged payout is reviewed by a human on our risk team before any adverse decision, and outcomes can be contested through the responsible customer. No other purely automated process here produces a legally meaningful outcome for a person.

6. Sharing

The complete list of parties that can receive personal data from us:

  • Banking partners — the regulated institutions that hold segregated customer funds and execute payouts on ACH, Fedwire, SEPA, and RTP. They receive the recipient data a given payout requires and nothing more.
  • Screening providers — the vendors that run sanctions and watchlist checks on our behalf.
  • Subprocessors — cloud hosting, email delivery, and support tooling, each under a data processing agreement. We maintain a current subprocessor list and give customers 30 days' notice before adding or replacing one, with the right to object.
  • Authorities — when we receive a binding legal request. We review every request, narrow it where the law allows, and alert the affected customer — silence only where a gag provision leaves us no choice.
  • A successor entity — in a merger, acquisition, or asset sale, under confidentiality and subject to this policy.

We do not sell personal data and have not done so, in the CCPA's sense of "sell" or anyone else's.

7. International transfers

latchpay is a U.S. company and processes data in the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, the transfer runs on the Standard Contractual Clauses the European Commission adopted, layered with the UK Addendum where UK data is involved, plus the technical measures described in Section 9. Copies of our transfer mechanisms are available to customers on request.

8. Retention

Default retention periods, absent a legal hold:

  • Account and billing data — held while your account lives, then seven more years where tax and accounting rules insist.
  • Support threads — three years after the ticket closes.
  • API request metadata — 13 months, then deleted.
  • Marketing consent records — as long as the consent is relied on, plus proof of withdrawal.
  • Payout records and screening results — the AML minimums described below.

Plain statement on payment records. Records of executed payouts — including recipient names, account details, amounts, and screening results — are retained for the minimum periods required by the Bank Secrecy Act and related AML rules, generally five years from the transaction, even if you ask us to delete them sooner. When we receive a deletion request that touches these records, we restrict them (locked away from ordinary access, used only for compliance) and then purge them the day the mandatory period ends. We will tell you that this is what happened rather than pretending the data vanished.

9. Security

Everything ciphered in motion and ciphered again on disk, hardware-backed key management, HMAC-signed API requests, immutable audit logs, annual external penetration tests, and a 24/7 on-call rotation. Our controls are independently audited: SOC 2 Type II and PCI DSS Level 1, re-examined every year. The full picture, including how to report a vulnerability to security@latchpay.xyz, is on our Security page.

10. Your rights

Your local law may entitle you to see the personal data we hold, amend it, erase it, or carry a copy elsewhere — and to curb or contest our processing, or escalate to a supervisory authority. To exercise any of these, email privacy@latchpay.xyz. Each request gets an identity check, an answer within 30 days, and no invoice if the ask is reasonable. We will never discriminate against you for exercising a right.

If you are in the EEA, UK, or Switzerland

You have the full set of GDPR rights against us where we act as controller: access (Art. 15), rectification (Art. 16), erasure (Art. 17, subject to the AML retention in Section 8), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). Escalating to your data-protection authority is always open to you; giving us the first crack at the problem is merely faster.

If you are in California

The CCPA gives you the right to know what categories of personal information we collect (the categories in Sections 2 and 3, from you or your employer directly — we buy nothing from data brokers), to delete it (same AML caveat), to correct it, and to opt out of sale or sharing. We do not sell or share personal information as the CCPA defines those terms, and we treat a Global Privacy Control signal as a formal opt-out anyway.

If your request concerns recipient data we process on a customer's behalf, we will route it to the responsible customer and support them in answering it — under data protection law, the decision is theirs to make, and we are not permitted to act unilaterally on data we hold as a processor.

11. Cookies

We run exactly two things in your browser:

  • A session cookie for the customer dashboard, strictly necessary, expiring when your session does.
  • First-party, cookieless analytics on the marketing site — aggregate page counts with no cross-site tracking, no fingerprinting, and no advertising identifiers.

There is no third-party ad tech on this site, so there is no cookie banner. We honor the Global Privacy Control signal: if your browser sends GPC, we treat it as an opt-out of any sale or sharing, which for us changes nothing, because we do neither.

12. Children

latchpay is business payments infrastructure. The service and this site are not directed to anyone under 18, and no child's personal data is knowingly collected here. If you believe we have, contact privacy@latchpay.xyz and we will delete it.

13. Changes to this policy

When we make material changes, we will email account owners and post a notice on this page at least 30 days before the change takes effect. The effective date at the top always reflects the current version. We do not make retroactive changes to how previously collected data is used.

14. Contact

Questions, requests, or complaints:

  • Email: privacy@latchpay.xyz
  • Mail: latchpay, Inc., c/o registered agent, 251 Little Falls Drive, Wilmington, DE 19808, USA

For security reports, use security@latchpay.xyz. For anything on the terms side, see the Terms of Service.