PaymentRetryAlert.com
Request beta access
Legal

Privacy Policy

Last updated: 27 August 2026

1. Who we are

PaymentRetryAlert.com is a trading style of Jade Technologies Limited (company number 15043871), registered at 7 Bell Yard, London, England, WC2A 2JR. For the purposes of UK data protection law, Jade Technologies Limited is the controller of the personal data described in this policy, except where stated otherwise. Contact: support@paymentretryalert.com.

Where we deliver payment alerts to a merchant, we process the transaction data in those alerts as a processor on the merchant's behalf; the merchant is the controller of that data, and cardholders should direct privacy queries about a payment to the merchant they paid. This policy covers the personal data for which Jade Technologies Limited is the controller: business contacts, website and enquiry data, billing, and account security.

2. The data we collect

Business contact data

When you enquire about or sign up for the Service, we collect the information you provide: name, business email address, company details, and the contents of your correspondence with us.

Integration and configuration data

To activate monitoring we collect merchant identifiers (Acquiring BIN and Card Acceptor ID / merchant ID) and your webhook endpoint details. These identify your business, not individual cardholders.

Notification data

Webhook notifications delivered through the Service contain transaction metadata: notification identifiers, merchant identifiers, network transaction identifiers, transaction amount and currency, timestamps, notification status, and the card BIN and last four digits of the card concerned. The Service is designed so that full card numbers are not collected, stored, or transmitted through it; alerts identify cards by BIN and last four digits only, and merchants must not send us full card numbers. Network monitoring itself is performed by Mastercard within its network under its own security, privacy, and compliance controls.

Website data

The recovery calculator runs entirely in your browser. The figures you enter are not transmitted to us unless you submit the contact form, in which case a summary of your estimate is included with your enquiry so we can prepare for our conversation.

When you submit the contact form we receive the details you provide, together with the IP address the request came from and the time of submission, which we use to prevent automated abuse of the form. Form submissions are delivered to us by email through Postmark (an ActiveCampaign, LLC service), acting as our processor. We do not use advertising or analytics cookies. Our hosting provider may collect standard server logs (IP address, user agent, pages requested) for security and operational purposes.

3. How we use data, and our lawful bases

  • Providing the Service: delivering notifications, support, and billing (performance of a contract).
  • Responding to enquiries and providing recovery estimates (legitimate interests, or steps prior to entering a contract).
  • Service security and integrity: verifying webhook delivery, preventing abuse (legitimate interests).
  • Improving the Service: analysing usage and delivery performance to operate and improve the Service (legitimate interests).
  • Legal compliance: accounting, tax, and regulatory obligations (legal obligation).

4. Who we share data with

  • Mastercard Payment Gateway Services Limited and other Mastercard entities (including Mastercard Europe SA), to enrol your merchant identifiers and operate the underlying Payment Alerts programme.
  • Service providers who host our infrastructure, deliver email, or provide billing services, acting on our instructions.
  • Professional advisers and authorities where required by law or to protect our legal rights.

We do not sell personal data.

5. International transfers

The Mastercard network and some of our service providers operate globally, so data may be transferred outside the UK. Where that happens we rely on appropriate safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, or, for certified US providers, the UK Extension to the EU–US Data Privacy Framework.

6. Retention

We keep business contact and billing records for as long as we have a relationship with you and for up to six years afterwards to meet legal and accounting obligations. Notification data is retained for the period needed for delivery, reconciliation, and dispute handling, and then deleted or anonymised. Enquiry and anti-abuse data (including IP addresses) is kept for up to 12 months after collection; hosting logs are retained in line with our hosting provider's standard schedule.

7. Security

Notifications are delivered over TLS 1.2 or higher and signed with HMAC-SHA256 so their origin can be verified. Access to systems handling Service data is restricted and logged. No full card numbers are held at rest.

8. Your rights

Under UK data protection law, individuals have rights over their personal data, including the rights of access, rectification, erasure, restriction, portability, and objection. To exercise any of these rights, contact support@paymentretryalert.com. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

We do not make automated decisions that produce legal or similarly significant effects about individuals; whether to retry a payment is decided by the merchant concerned.

9. Changes to this policy

We may update this policy from time to time. The “last updated” date at the top of this page shows the current version; material changes will be notified to Service customers by email.