Legal · Privacy Policy
Effective March 30, 2026. We move money for a living, so we handle data the same way: minimally, deliberately, and on the record.
This policy covers latchpay, Inc. ("latchpay", "we") and describes how we handle personal data on latchpay.xyz and in the latchpay settlement and payouts platform. We wear two hats, and it matters which one is on:
If you received a payout through a platform built on latchpay and want to know what happens to your data, start with Section 3 and then with that platform's own privacy notice.
For every person your organization seats on the platform: their name, their work address, the company and role they hold, and the authentication records their sessions generate. We do not ask for personal data we do not need to run an account.
Legal entity name, billing address, tax identifiers, invoice history, and the payment details needed to charge per-payout fees. Cards never touch our systems — the processor holds them, and all we keep is a token plus the trailing four digits.
Timestamps, endpoint paths, key identifiers, IP addresses, response codes, and idempotency keys — the operational exhaust needed to debug integrations, enforce rate limits, and investigate abuse. Full bank credentials are never written to logs. Account and routing numbers are redacted at the logging layer before a line is persisted, and this behavior is covered by our SOC 2 audit.
Emails to support@latchpay.xyz, tickets, and notes from calls, kept so the next engineer who picks up your thread has context.
No data-broker enrichment, no advertising identifiers, no biometric data, no precise location. If a field is not needed to run an account, bill it, or satisfy a regulator, we do not ask for it.
To execute a payout, our customers submit recipient names, bank account details (account and routing numbers, IBANs), and amounts. We collect exactly these fields because payouts legally require them — a Fedwire or ACH entry cannot be originated without them. We also generate and store sanctions-screening results for each recipient, because federal law requires us and our banking partners to screen before funds move.
Recipient data is processed for one purpose: executing and reconciling the payouts our customer instructed. It is never used for our own marketing, never used to build profiles, and never sold or resold to anyone. Full stop.
Screening results and payout records are retained as described in Section 8, because anti-money-laundering law does not give us a choice about that.
Personal data has exactly these jobs here:
When European or UK data-protection law governs our processing, the bases are:
Sanctions screening is automated, but a hit never results in an automatic final refusal: every flagged payout is reviewed by a human on our risk team before any adverse decision, and outcomes can be contested through the responsible customer. No other purely automated process here produces a legally meaningful outcome for a person.
The complete list of parties that can receive personal data from us:
We do not sell personal data and have not done so, in the CCPA's sense of "sell" or anyone else's.
latchpay is a U.S. company and processes data in the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, the transfer runs on the Standard Contractual Clauses the European Commission adopted, layered with the UK Addendum where UK data is involved, plus the technical measures described in Section 9. Copies of our transfer mechanisms are available to customers on request.
Default retention periods, absent a legal hold:
Plain statement on payment records. Records of executed payouts — including recipient names, account details, amounts, and screening results — are retained for the minimum periods required by the Bank Secrecy Act and related AML rules, generally five years from the transaction, even if you ask us to delete them sooner. When we receive a deletion request that touches these records, we restrict them (locked away from ordinary access, used only for compliance) and then purge them the day the mandatory period ends. We will tell you that this is what happened rather than pretending the data vanished.
Everything ciphered in motion and ciphered again on disk, hardware-backed key management, HMAC-signed API requests, immutable audit logs, annual external penetration tests, and a 24/7 on-call rotation. Our controls are independently audited: SOC 2 Type II and PCI DSS Level 1, re-examined every year. The full picture, including how to report a vulnerability to security@latchpay.xyz, is on our Security page.
Your local law may entitle you to see the personal data we hold, amend it, erase it, or carry a copy elsewhere — and to curb or contest our processing, or escalate to a supervisory authority. To exercise any of these, email privacy@latchpay.xyz. Each request gets an identity check, an answer within 30 days, and no invoice if the ask is reasonable. We will never discriminate against you for exercising a right.
You have the full set of GDPR rights against us where we act as controller: access (Art. 15), rectification (Art. 16), erasure (Art. 17, subject to the AML retention in Section 8), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). Escalating to your data-protection authority is always open to you; giving us the first crack at the problem is merely faster.
The CCPA gives you the right to know what categories of personal information we collect (the categories in Sections 2 and 3, from you or your employer directly — we buy nothing from data brokers), to delete it (same AML caveat), to correct it, and to opt out of sale or sharing. We do not sell or share personal information as the CCPA defines those terms, and we treat a Global Privacy Control signal as a formal opt-out anyway.
If your request concerns recipient data we process on a customer's behalf, we will route it to the responsible customer and support them in answering it — under data protection law, the decision is theirs to make, and we are not permitted to act unilaterally on data we hold as a processor.
We run exactly two things in your browser:
There is no third-party ad tech on this site, so there is no cookie banner. We honor the Global Privacy Control signal: if your browser sends GPC, we treat it as an opt-out of any sale or sharing, which for us changes nothing, because we do neither.
latchpay is business payments infrastructure. The service and this site are not directed to anyone under 18, and no child's personal data is knowingly collected here. If you believe we have, contact privacy@latchpay.xyz and we will delete it.
When we make material changes, we will email account owners and post a notice on this page at least 30 days before the change takes effect. The effective date at the top always reflects the current version. We do not make retroactive changes to how previously collected data is used.
Questions, requests, or complaints:
For security reports, use security@latchpay.xyz. For anything on the terms side, see the Terms of Service.