ribbonPay

Privacy Notice

Ribbon Payment Solutions, Inc. (“ribbonPay,” “we,” “us,” or “our”)

Effective: August 4, 2026  |  Last updated: August 4, 2026

At a glance

ribbonPay provides managed fraud review, order decisioning, verification, and chargeback-support services to merchants. We use personal information to provide and secure those services, prevent fraud, support merchant accounts, and comply with law.

We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or use shopper information to advertise to shoppers.

For information submitted by a shopper to a merchant, the merchant generally controls the relationship and privacy request. Shoppers should ordinarily contact the merchant first.

1. Scope of this Notice

This Privacy Notice explains how ribbonPay collects, uses, discloses, and retains personal information through our public websites, merchant-facing applications and console, sales and support interactions, and managed fraud review services (collectively, the “Services”). It also describes privacy choices and rights that may be available under United States law.

This Notice does not govern a merchant’s own website, checkout, products, payment processing, or other independent practices. A merchant’s privacy notice applies to those activities. It also does not replace the Data Processing Agreement between ribbonPay and a merchant.

2. Our Privacy Roles

When we act for a merchant. For shopper order, customer, transaction, verification, dispute, and chargeback information submitted to the Services by or for a merchant, ribbonPay generally acts as the merchant’s service provider or processor. We process that information under the merchant’s instructions and our contract with the merchant. The merchant decides why the information is collected and how its orders and customer relationships are managed.

When we act for our own business. We act for our own business when we manage our websites, merchant and prospective-merchant relationships, accounts, security, billing administration, legal obligations, and business communications.

Fraud-prevention network. We may create pseudonymous identity keys and fraud signals to identify repeated fraud and chargeback patterns across participating merchants. We use those signals only for fraud prevention, security, and related service improvement; do not disclose one merchant’s identifiable information to another merchant; and purge the identity keys in response to a valid individual erasure request or when their retention period expires.

3. Personal Information We Collect

The information we collect depends on how a person or merchant interacts with the Services. During the preceding 12 months, the categories have included:

Categories of personal information collected
Merchant and account informationName, business name, title, business contact details, console account identifiers, authentication and session records, preferences, and support history.
Shopper and order identifiersName, email address, telephone number, billing and shipping addresses, customer and order identifiers, and names or contact details of recipients.
Commercial and transaction informationItems, quantities, prices, discounts, totals, currency, timestamps, shipping method, fulfillment, refund, dispute, chargeback, account-history, and payment-status information.
Payment and verification metadataPayment gateway name, card brand, truncated card information such as BIN and last four digits, AVS/CVV result codes, verification status, and identity-match results. The Services are designed not to collect or store full card numbers or actual CVV values.
Internet, device, and network informationIP address, user agent, browser and device attributes, language, time zone, screen characteristics, referrer, origin, cookie or local-storage identifiers, security events, and derived device identifiers. Where enabled, approximate or device-provided location signals may be processed.
Fraud, risk, and inferred informationEmail, IP, network, device, address, identity, velocity, and reputation signals; scores; rules; reason codes; order decisions; possible matches; analyst notes; overrides; and fraud or chargeback patterns.
Identity-verification informationFor a small subset of escalated cases, government identification documents, document images, name and address verification, and related verification results through a hosted verification provider. ribbonPay generally stores the verification result rather than the underlying document image.
Communications and operational informationMessages, service requests, call or meeting notes, webhooks, audit trails, diagnostic data, error reports, delivery records, and security or incident records.

4. Sources of Personal Information

We collect personal information from:

5. How We Use Personal Information

We use personal information for the following business and operational purposes:

6. Automated and AI-Assisted Fraud Analysis

The Services use merchant-configured rules, statistical methods, fraud and identity signals, automated scoring, and AI-assisted analysis to help identify risk and support order review. These tools may generate a SHIP, CANCEL, or PENDING decision or assist a human analyst. A merchant determines how ribbonPay decisions are used in its order process and may configure authorized actions and escalation workflows under its agreement with us. We do not use shopper information to train public advertising profiles. Where applicable law requires a notice, explanation, human review, appeal, or other choice concerning automated processing, the merchant and ribbonPay will provide the applicable process based on their respective legal roles.

7. How We Disclose Personal Information

We may disclose personal information to the following categories of recipients for the purposes described in this Notice:

Categories of recipients and purposes
Merchants and merchant-directed partiesProvide decisions, reports, support, approved order actions, verification results, chargeback information, and integrations requested by the merchant.
Cloud and application infrastructureHost the application, databases, authentication, object storage, queues, caching, serverless functions, delivery services, and service operations.
Fraud, identity, and data-enrichment providersEvaluate limited email, IP, network, device, address, identity, transaction, or reputation signals needed for a selected fraud or verification function.
Communications and verification providersAppend or validate contact information, send approved communications, and conduct hosted identity-document verification for escalated cases.
AI and professional service providersSupport order summarization, analyst workflows, legal, accounting, security, insurance, and other business operations subject to appropriate restrictions.
Authorities and transaction partiesComply with law or legal process; protect rights, safety, and security; investigate wrongdoing; or complete a financing, merger, acquisition, reorganization, or sale, subject to appropriate protections.

We contractually limit service providers to appropriate purposes and data. A current confidential list of subprocessors that process merchant-provided personal information is available to merchants upon request and is managed under the applicable Data Processing Agreement.

8. No Sale, Sharing, or Targeted Advertising

We do not sell personal information for money or other valuable consideration. We do not share personal information for cross-context behavioral advertising, use it for targeted advertising, or disclose shopper information to data brokers. We therefore do not currently provide a “Do Not Sell or Share My Personal Information” link. We will update our practices and provide any required choice before engaging in those activities.

We use sensitive personal information only as reasonably necessary to provide requested services, prevent fraud, verify identity, maintain security, comply with law, and perform other permitted operational purposes. We do not use sensitive personal information to infer characteristics for unrelated purposes.

We do not offer financial incentives or price differences in exchange for personal information.

9. Cookies and Similar Technologies

Our websites and merchant console. We use cookies and similar technologies for authentication, account sessions, security, preferences, service delivery, and error or performance monitoring. These technologies help keep users signed in, enforce session limits, detect misuse, and diagnose service problems. We do not currently use advertising cookies, cross-site behavioral advertising trackers, or session-replay technology in the Services.

Participating merchant storefronts. A merchant integration may use a first-party browser token in a cookie and local storage, generally for up to one year, to associate checkout and device signals with an order for fraud prevention. Depending on the integration, signals may include browser, device, screen, language, time-zone, referrer, canvas, WebGL, network, and checkout-event information. A Shopify custom pixel generally supplies a more limited set of checkout and device signals. These technologies are used for fraud prevention and service security, not advertising.

Browser signals.Because there is no uniform industry standard for browser “Do Not Track” signals, our Services do not respond to them except where required by law. We honor legally recognized opt-out preference signals, such as Global Privacy Control, where applicable. Because we do not sell or share personal information or use it for targeted advertising, such a signal may not change our current processing.

Blocking required account, security, or fraud-prevention technologies may prevent login, interfere with checkout-risk analysis, or reduce the availability or security of the Services. A participating merchant is responsible for any additional storefront notice or consent required for its configuration and customers.

10. Retention

We retain personal information for the period reasonably necessary for the purposes described above, subject to merchant configuration, contractual commitments, legal requirements, and valid privacy requests. Current service defaults include:

Typical retention by data class
Identifiable order data180 days by default; a merchant may configure a period from 30 to 730 days.
Device collection eventsThe same retention period as the associated merchant's identifiable order data.
Chargeback and fraud-network identity keysUp to 730 days. Valid individual erasure requests purge applicable identity keys earlier, subject to law.
Decision and scoring recordsMay be retained after personal information is anonymized for reporting, security, fraud prevention, analytics, and service improvement.
Hosted identity-verification documentsGenerally redacted by the hosted provider 120 days after case closure, or earlier in response to a valid erasure request when required.
Audit, security, and delivery logsRetained as reasonably necessary for security, reliability, compliance, dispute resolution, and legal claims; some records do not use a short automated deletion period.
Merchant accounts and business recordsFor the relationship and thereafter as needed for billing, tax, contract, security, legal, and records-management purposes.

Following termination, merchant-provided personal information is returned or deleted within 30 days when required by the applicable Data Processing Agreement, except for legally permitted retention, protected backups, claims records, and the limited pseudonymous fraud-prevention information described above. Deidentified or anonymized information may be retained without a fixed period where permitted by law.

11. Security

We maintain administrative, technical, and organizational safeguards designed to protect personal information, including role-based access, authentication and session controls, encryption in transit, protected credentials, signed integrations, data minimization, audit and operational logging, monitoring, incident-response procedures, and retention controls. The Services are designed to use truncated payment-card information and result codes rather than full card numbers or actual CVV values. No system is perfectly secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

12. Your Privacy Rights

Depending on where you live and whether an applicable privacy law covers the processing, you may have the right to request access to or a copy of personal information; learn about categories, sources, purposes, and recipients; correct inaccurate information; delete information; obtain portable information; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive personal information; and appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.

Shopper requests. If your information was submitted in connection with an order from a merchant, contact that merchant first. The merchant controls the customer relationship and will direct ribbonPay as needed. You may also contact us, and we will route or support the request consistent with our legal and contractual role.

Direct requests to ribbonPay. Email sales@ribbonpayments.com with the subject line “Privacy Request” and describe the request, your state of residence, and whether it concerns a particular merchant. To appeal a decision, use the subject line “Privacy Appeal” and explain why you believe the response should be reconsidered.

We will verify a request in a manner proportionate to its sensitivity and may ask for information needed to match records, confirm authority, prevent fraud, or identify the relevant merchant. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct identity verification. We respond within the period required by applicable law. Some information may be exempt, or may be retained where permitted or required by law.

13. Children

The Services are business services and are not directed to children under 13. We do not knowingly solicit children to create ribbonPay merchant-console accounts. Merchants are responsible for determining whether their stores may collect information from children and for obtaining any legally required permission before sending that information to us. If you believe a child provided personal information to ribbonPay outside an authorized merchant transaction, contact us.

14. United States Processing

ribbonPay operates in the United States for United States merchants. Personal information covered by this Notice is processed and stored in the United States. A United States merchant may nevertheless receive an order from a person located elsewhere; the merchant is responsible for determining whether additional notices, permissions, or rights apply to that order and for informing ribbonPay through the parties’ contractual process.

15. Changes to this Notice

We may update this Notice to reflect changes in the Services, law, or our practices. We will post the updated Notice with a revised “Last updated” date. If a change materially affects how we use previously collected personal information, we will provide additional notice or obtain permission when required by law. We review this Notice periodically and at least annually.

16. Contact Us

Questions and privacy requests may be directed to:

Ribbon Payment Solutions, Inc.
Privacy Contact
27574 Commerce Center Drive, Suite 234
Temecula, California 92590
sales@ribbonpayments.com