Last Updated: June, 2026

Overview

At ZIVO PROCESSING ("ZIVO", "we", "our", or "us"), we are committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, share, and safeguard personal data when you use our merchant services, websites, and related products (collectively, the "Services"). This policy applies to all merchants, business partners, and individuals who interact with our Services. We act as an independent controller for the personal data we process in connection with providing payment processing and merchant services, except where we process data on behalf of our merchants as a service provider .

๐Ÿ”’ Our Commitment: No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

What Personal Data We Collect

The types of personal data we collect depend on your relationship with us. We collect information from merchants (businesses using our Services), their representatives, and end consumers who make payments through our merchants.

Category of Data Description Collected From
Contact Information Name, email address, phone number, physical address Merchants, Representatives
Business & Financial Information Company registration, tax ID, bank account details, ownership information Merchants, Credit Bureaus
Device & Session Information IP address, browser type, device identifiers, cookie data, pages visited Visitors, Merchants
Integrations Credentialing and data from third-party services like accounting or e-commerce platforms Merchants (when enabled)

How We Use Personal Data

We process personal data for specific, legitimate purposes as outlined below. Our legal bases for processing include: performing a contract with you, complying with legal obligations, pursuing our legitimate business interests (provided your rights do not override these), and with your consent where required .

๐Ÿ“Š De-Identified Data: We may anonymize or aggregate personal data so that you are not individually identifiable. This de-identified data may be used for analytics, research, and to improve our Services. We never share aggregate data in a manner that would personally identify you .

How We Share Personal Data

We do not sell your personal data. We share information only as necessary to provide our Services, comply with legal obligations, or with your explicit consent. We ensure that all third parties with whom we share data are contractually obligated to protect it.

Data Retention

We retain personal data for as long as necessary to fulfill the purposes for which it was collected, including to meet legal, regulatory, accounting, or reporting requirements. Transaction data may be retained for up to 7 years to comply with financial regulations. After this period, we securely delete or anonymize the data.

Data Security

We implement robust administrative, technical, and physical safeguards to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

Your Privacy Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

To exercise any of these rights, please contact us using the information in the "Contact Us" section below. We will respond to your request at the earliest possible convenience.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the revised policy on this page with a new "Last Updated" date. We encourage you to review this policy periodically.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

If you are located in the European Economic Area, Switzerland, or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.