Skip to content
PD Cash
Payment linksDeveloper APIWordPress
DevelopersFeaturesPricingContact
Sign inCreate free account

LEGAL

Privacy Policy

Last updated: July 28, 2026

Effective: August 27, 2026 for merchants with an existing account on July 28, 2026. The changes in this version apply immediately to accounts created on or after July 28, 2026.

1. Introduction

PD Cash ("Company," "we," "us," or "our") operates a payment orchestration platform that enables merchants to route and manage payment transactions across multiple providers. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform. As a payment orchestration technology provider, we handle data differently from a traditional payment processor — we route transactions but do not directly process payments or hold customer funds.

2. Information We Collect

2.1 Account Information

When you register for an account, we collect:

  • Email address
  • Username and password (hashed, never stored in plaintext)
  • Business name (if provided)
  • Withdrawal preferences (payment method selections)

2.2 Transaction Data

When transactions are routed through our Platform, we may collect:

  • Transaction amounts and currencies
  • Payment method type used (wallet, crypto, partner-supported method)
  • Transaction status and timestamps
  • Routing information
  • Transaction reference IDs

Note: We do not store full payment card numbers, CVVs, or sensitive authentication data. That information is handled directly by the licensed partners and payment providers.

2.3 Technical Data

We automatically collect certain technical information including:

  • IP addresses
  • Browser type and version
  • Device information
  • Operating system
  • Access timestamps and session duration
  • Pages visited and features used within the Platform

2.4 API Integration Data

If you use our BYOK (Bring Your Own Keys) feature, we store:

  • Encrypted API keys for connected payment providers
  • Provider configuration preferences
  • Routing rules and settings

2.5 Prospective Merchant Inquiries

When you request a merchant route review before creating an account, we collect the contact and business information you submit, such as your name, work email, business name, public website, business model, operating regions, estimated volume, requested integration, and optional message. We may also record first-touch campaign metadata and the public landing page that led to the inquiry when those details are available.

Please do not submit identity documents, bank details, payment credentials, wallet keys, or other sensitive verification material through this public form.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the payment orchestration Platform
  • Route payment transactions to the appropriate provider
  • Generate analytics, reports, and transaction insights for your dashboard
  • Process withdrawal instructions
  • Detect and prevent fraud, unauthorized transactions, and abuse
  • Carry out onboarding and ongoing due diligence, including sanctions screening
  • Communicate with you regarding account activity, updates, and support
  • Review prospective merchant inquiries, assess route fit, and respond to requested onboarding discussions
  • Improve and optimize the Platform's performance and routing logic
  • Comply with legal obligations and enforce our Terms of Service

4. Legal Bases for Processing

Where the EU General Data Protection Regulation or the UK GDPR applies, we rely on the following legal bases under Article 6:

  • Performance of a contract (Art. 6(1)(b)): creating and operating your account, routing transactions, acting on withdrawal instructions, and providing support.
  • Legal obligation (Art. 6(1)(c)): sanctions screening, record keeping, tax and information reporting, and responding to lawful requests from authorities.
  • Legitimate interests (Art. 6(1)(f)): fraud prevention, velocity and abuse monitoring, platform and account security, service improvement, and responding to prospective merchant inquiries. We balance these interests against your rights and freedoms.
  • Consent (Art. 6(1)(a)): optional marketing measurement cookies and pixels, and optional marketing email. You may withdraw consent at any time, which does not affect processing carried out before withdrawal.
  • Vital interests or public interest (Art. 6(1)(d) and (e)): used rarely, and limited to reporting a suspected serious crime or an imminent risk to a person.

Where we rely on legitimate interests, you may ask for a summary of the balancing assessment through the contact form.

5. Data Sharing & Disclosure

We may share your information with:

  • Channel Partners and payment providers: identity, business, and transaction information required for underwriting, statutory KYC and KYB, monitoring, processing, and settlement
  • Withdrawal providers: the information required to execute your withdrawal, such as the destination account or wallet address
  • Fraud prevention and screening services: transaction and account data for fraud detection, sanctions screening, and risk assessment
  • Service providers and subprocessors: as described in Section 6
  • Advertising and measurement partners: where you allow it, Meta receives pixel event data from our public pages
  • Legal authorities: when required by law, court order, or to establish, exercise, or defend legal claims
  • A successor entity: in connection with a merger, acquisition, or sale of assets, subject to this Policy

We do not sell your personal information for money. However, where you allow marketing measurement, the Meta Pixel on our public pages transmits identifiers and event data to Meta. Under the California Consumer Privacy Act as amended by the CPRA, and under comparable laws in other U.S. states, that transmission may be treated as a "sale" of personal information or as "sharing" for cross-context behavioural advertising.

You can decline or withdraw this at any time using the consent banner on our public pages, or the "Do Not Sell or Share My Personal Information" control linked from our site footer. We honour Global Privacy Control signals sent by your browser. We do not sell or share the personal information of anyone we know to be under 16 years of age.

6. Service Providers & Subprocessors

We engage service providers to operate the Platform. The categories are:

  • Cloud hosting and infrastructure
  • Content delivery, edge caching, and denial-of-service protection
  • Transactional email delivery
  • Error monitoring, logging, and observability
  • Fraud, sanctions, and risk-screening services
  • Customer support tooling
  • Analytics and marketing measurement, only where you allow it
  • Licensed Channel Partners and payment providers

Service providers are contractually required to process personal data only on our documented instructions, to keep it confidential, to apply appropriate technical and organisational security measures, and not to use it for their own purposes. Licensed Channel Partners and payment providers are an exception: they act as independent controllers for their own regulated activities, under their own privacy policies.

A current list of our subprocessors is available on request through the contact form. Where we act as a processor on behalf of a merchant, we give at least 30 days' notice before adding or replacing a subprocessor, and the merchant may object on reasonable data-protection grounds.

7. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256)
  • Encrypted storage of API keys and sensitive credentials, with per-tenant key separation
  • Access controls, multi-factor authentication for administrative access, and audit logging
  • Rate limiting, session binding, and account change notifications
  • Regular security assessments, dependency scanning, and monitoring
  • Secure infrastructure with redundancy and encrypted backups

Our Security page describes these measures in more detail. While we strive to protect your information, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Breach Notification

If a personal data breach occurs, we act on the following timelines:

  • Where the EU or UK GDPR applies and we act as controller, we notify the competent supervisory authority within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to the rights and freedoms of individuals.
  • Where we act as a processor for a merchant, we notify that merchant without undue delay after becoming aware, so the merchant can meet its own deadlines.
  • We notify affected merchants without undue delay where the breach is likely to result in a high risk to them or to their customers.
  • Where U.S. state breach-notification law applies, we notify affected individuals, and where required the state regulator, within the period that law sets — commonly without unreasonable delay, and in a number of states within 30 to 60 days.

A notification will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, the measures taken or proposed to address it and mitigate harm, and a contact point for further information. Where the full picture is not yet available, we provide information in phases rather than delaying the first notice.

An incident originating at a Channel Partner or payment provider is that entity's to assess and report under its own obligations. We pass on what we are told, cooperate with their process, and tell affected merchants what we know.

9. Data Retention

We keep personal data only as long as it is needed for the purpose it was collected for, and then delete or anonymise it. Our standard retention periods are:

  • Account records, including identity, contact details, and settings: 5 years after account closure
  • Transaction records: 5 years from the transaction date
  • Withdrawal, deposit, and fee records: 7 years from the date of the record
  • Onboarding and due-diligence records, including screening results: 5 years after account closure
  • Dispute and chargeback records: 5 years from resolution
  • Support tickets and related correspondence: 3 years from closure of the ticket
  • Security, access, and audit logs: 12 months
  • Prospective merchant inquiries: 24 months after the last meaningful interaction
  • Marketing measurement identifiers, including _fbp and _fbc: 90 days
  • Backups: a 90-day rolling cycle, after which superseded copies are overwritten

Where a longer period is required by law, by regulation, or by a Channel Partner's rules, the longer period applies. Aggregated or anonymised data that can no longer be linked to you may be retained indefinitely for analytics.

Legal hold: where data is subject to a legal hold — active litigation, a regulatory inquiry, a law-enforcement request, or an unresolved dispute — we suspend deletion for the affected records until the hold is lifted, then resume the normal schedule. A deletion request does not override a legal hold, but we will tell you that a hold applies and delete the data once it ends.

10. Your Privacy Rights

Depending on where you live, you may have the right to:

  • Know what personal data we hold about you and obtain a copy of it
  • Have inaccurate or incomplete data corrected
  • Have your data deleted, subject to legal and regulatory retention requirements
  • Restrict processing while a dispute about accuracy or lawfulness is resolved
  • Object to processing based on our legitimate interests, and to object to direct marketing at any time with no exceptions
  • Receive your data in a portable, machine-readable format and have it transmitted to another controller where technically feasible
  • Withdraw consent at any time where processing is based on consent
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to obtain human review of such a decision
  • Opt out of the sale or sharing of personal information and of targeted advertising
  • Limit the use and disclosure of sensitive personal information
  • Not be discriminated against for exercising any of these rights
  • Complain to a supervisory authority, state attorney general, or other competent regulator

Automated decisions: we run automated fraud, velocity, and risk rules. Where an automated rule materially affects your account — a decline, a hold, a withdrawal restriction, or a suspension — you may request human review through the contact form, and a reviewer who was not part of the automated decision will look at it.

11. How to Exercise Your Rights

  • Submit your request through the contact form at pd.cash/contact#contact-form using the subject "Privacy Request", and say which right you are exercising.
  • We verify your identity before acting. For most requests we match the request to your registered account email. For higher-risk requests, such as access to transaction data or deletion, we ask for additional confirmation. Information collected for verification is used only for that purpose and deleted afterwards.
  • An authorised agent may submit a request on your behalf with written permission. We may still contact you directly to confirm the agent's authority.
  • We acknowledge receipt within 10 business days.
  • We give a substantive response within 30 days where a U.S. state privacy law applies, and within 1 month where the EU or UK GDPR applies.
  • Where a request is complex or you have made several, we may extend by a further 45 days (U.S.) or 2 months (EU and UK). We will tell you about the extension, and why, within the original period.
  • Requests are free. Where a request is manifestly unfounded or excessive, particularly if repetitive, we may charge a reasonable fee reflecting our administrative cost, or refuse it and explain why.
  • If we refuse a request, we explain the reason and how to appeal. An appeal is reviewed by someone who was not involved in the original decision, and we respond within 45 days.
  • You may complain to your supervisory authority in the EEA or the UK, to your state attorney general in the United States, or to another competent regulator, at any time and regardless of whether you have contacted us first.

12. California Privacy Notice (CCPA/CPRA)

This Section applies to California residents and supplements the rest of this Policy. Terms used here have the meanings given in the California Consumer Privacy Act as amended by the California Privacy Rights Act.

12.1 Categories of personal information collected, and sources

In the preceding 12 months we have collected the following categories:

  • Identifiers: name, email address, username, account identifier, IP address, and device identifiers
  • Commercial information: transaction amounts and dates, payment method type, plan, deposit and withdrawal history
  • Internet or other electronic network activity: pages visited, features used, session duration, referring page, and campaign parameters
  • Geolocation data: approximate location derived from IP address, not precise location
  • Professional or employment-related information: business name, business model, operating regions, and estimated volume
  • Inferences: risk scores, routing preferences, and segment classifications derived from the categories above

We collect this directly from you, automatically from your device when you use the Platform or our public pages, from Channel Partners and payment providers, from fraud and sanctions screening services, and from publicly available sources such as your business website. We do not collect biometric information, precise geolocation, or the contents of your communications with third parties.

12.2 Business purposes for collection

  • Operating the Platform and your account
  • Routing transactions and acting on withdrawal instructions
  • Fraud prevention, security, and risk management
  • Onboarding due diligence, sanctions screening, and legal compliance
  • Support, service communications, and complaint handling
  • Analytics and service improvement
  • Marketing measurement, only where you have allowed it

12.3 Categories disclosed for a business purpose

In the preceding 12 months we have disclosed identifiers, commercial information, internet activity, geolocation, professional information, and inferences for a business purpose to: Channel Partners and payment providers; fraud, sanctions, and screening services; infrastructure, email, logging, and support vendors; and legal authorities where required by law.

12.4 Sale and sharing

We do not sell personal information for money. Where you allow marketing measurement, identifiers and internet activity transmitted by the Meta Pixel may constitute a "sale" or "sharing" for cross-context behavioural advertising under the CCPA as amended. You may opt out through the consent banner on our public pages, through the "Do Not Sell or Share My Personal Information" link in our site footer, or by sending an opt-out preference signal from your browser. We honour Global Privacy Control. We do not sell or share the personal information of consumers we know to be under 16 years of age.

12.5 Sensitive personal information

We do not collect or use sensitive personal information for purposes that would require a "Limit the Use of My Sensitive Personal Information" link. Account credentials are held solely to authenticate you and secure your account, and are not used to infer characteristics about you. We do not request government identifiers, identity documents, or financial account credentials through our public forms.

12.6 Retention

We retain each category only for the periods set out in Section 9, and no longer than reasonably necessary for the disclosed purpose or for a legal or regulatory obligation.

12.7 Your California rights

You have the right to know, to access, to delete, to correct, to opt out of sale and sharing, to limit the use of sensitive personal information where applicable, and to be free from discrimination or retaliation for exercising any of them. We will not deny you service, charge a different price, or provide a lower quality of service because you exercised a right. Submit requests as described in Section 11. Authorised agents are accepted with written permission.

13. Other U.S. State Privacy Rights

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana, and others as their laws take effect — have the right to confirm whether we process their personal data and to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, of the sale of personal data, and of profiling in furtherance of decisions producing legal or similarly significant effects.

We do not carry out profiling that produces legal or similarly significant effects without the human review described in Section 10. We recognise universal opt-out mechanisms, including Global Privacy Control, where the applicable state law requires it. Exercise these rights as described in Section 11. Where a state law gives you a right to appeal a refusal, appeals are handled as described in that Section. Nevada residents may submit a request not to sell covered information through the same channel.

14. Cookies & Tracking

We use two categories of cookies and similar technologies: essential and optional.

  • Essential technologies keep you signed in, protect forms against cross-site request forgery, remember your cookie choice, keep your requests on a consistent server, and protect the Platform against abuse. They do not require consent and cannot be switched off without breaking the Platform.
  • Optional technologies are used only for marketing measurement on our public pages: the Meta Pixel and its first-party identifiers (_fbp and _fbc), and first-touch campaign parameters used to attribute an inquiry to the campaign that led to it.

On public pages we show a consent banner. Where a choice is required for the region served, optional technologies and the Meta Pixel do not load until you allow them. Declining does not prevent you from using the Platform or submitting a merchant inquiry.

You can change your choice at any time using the cookie preferences and "Do Not Sell or Share My Personal Information" link in our site footer. We honour Global Privacy Control signals sent by your browser and treat them as an opt-out of optional technologies and of sale and sharing.

Your consent choice is stored for 12 months, after which we ask again. Clearing your browser storage also clears the stored choice.

14.1 Cookies and identifiers we set

  • Session and authentication cookie — essential — keeps you signed in to the dashboard — expires at the end of the session or on sign-out
  • CSRF token cookie — essential — protects forms and API calls against cross-site request forgery — expires with the session
  • Consent preference cookie — essential — remembers whether you allowed optional measurement — 12 months
  • Load-balancing cookie — essential — keeps your requests on a consistent server — expires with the session
  • _fbp — optional — Meta Pixel first-party browser identifier used for ad and lead measurement — up to 90 days
  • _fbc — optional — Meta Pixel click identifier recorded when you arrive from an ad — up to 90 days
  • First-touch campaign parameters — optional — attributes an inquiry to the campaign that led to it — up to 30 days

15. Third-Party Payment Provider Data Liability

Our Platform integrates with third-party payment providers, Channel Partners, and gateways. Each has its own privacy policy, data handling practices, and security measures governing the use of your data and your customers' data. You acknowledge and agree that:

  • Once transaction data is transmitted to a payment provider for processing, that provider assumes responsibility and liability for the security, handling, and protection of that data
  • PD Cash is not responsible or liable for any data breach, unauthorized access, data loss, or privacy violation occurring at the payment provider level
  • Sensitive payment information — full card numbers, CVVs, and authentication data — is handled directly by licensed payment providers and is never stored on our Platform. All liability for PCI DSS compliance and cardholder data protection rests with those providers
  • Data privacy claims, regulatory actions, and GDPR or CCPA compliance obligations arising from payment processing data are the responsibility of the payment provider processing those transactions
  • We encourage you to review the privacy policy and security posture of any provider you connect to through our Platform

PD Cash's data responsibility is limited to the orchestration layer data — routing decisions, transaction metadata, and account information — that we directly control.

16. International Data Transfers

Your data may be transferred to and processed in the United States and in other countries where we or our service providers operate. Those countries may have data protection laws that differ from the laws of your own country. Where personal data leaves the EEA, the United Kingdom, or Switzerland, we rely on one or more of the following safeguards:

  • The European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), incorporated into our agreements with importers
  • The UK International Data Transfer Agreement, or the UK Addendum to the Standard Contractual Clauses, for transfers out of the United Kingdom
  • An adequacy decision, where the destination country benefits from one
  • An Article 49 derogation in limited cases, for example where the transfer is necessary to perform a contract with you, or to establish, exercise, or defend legal claims

Before relying on the Standard Contractual Clauses or the IDTA, we carry out a transfer risk assessment covering the laws and practices of the destination country, the sensitivity and volume of the data, and the technical and contractual measures in place — including encryption in transit and at rest, access controls, minimisation, and a commitment to challenge overbroad government access requests where lawful to do so. A copy of the relevant clauses and a summary of the assessment is available on request through the contact form, with commercially confidential terms redacted.

17. Children's Privacy

Our Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors, and we do not sell or share the personal information of anyone we know to be under 16. If we discover we have collected data from a minor, we will delete it promptly.

18. Changes to This Policy

We may update this Privacy Policy from time to time. Where a change is material, we give at least 30 days' advance notice by email to your account address and by notice in the dashboard before it takes effect. Other changes are posted on this page with an updated "Last updated" date. Dated archive copies of prior versions are available on request through the contact form.

19. Contact Us

For questions or concerns about this Privacy Policy or our data practices, contact us at:

  • Contact form: pd.cash/contact#contact-form
  • Website: pd.cash
PD Cash

Payment links and API routing for Cash App, PayPal, crypto, and approved wallets.

Contact us

Product

Payment LinksFeatures & Add-onsPricingWordPress Plugin

Developers

Cash App & Crypto APICash App Payment API

Solutions

iGaming PaymentsSweepstakes PaymentsDigital GoodsAgent Payment LinksIPTV PaymentsDigital Shop PaymentsDone-For-You Setup

Resources

How to Accept Cash AppThird-Party ProviderContactSign InCreate Free Account

PD Cash is a payment orchestrator (API connector), not a payment service provider. We do not hold merchant balances. Security deposits required by certain plans are held by underlying licensed channel partners and are refundable under the Terms.

© 2026 PD Cash. All rights reserved.

ChangelogTerms of ServicePrivacy PolicyRefund PolicyAcceptable UseAML/CFT PolicyDisclaimerSecurity