Draft — pending review by qualified counsel
This is a complete draft written to be marked up, not a document that has been settled. It must be reviewed by a lawyer qualified in United States and in every market served before the service goes live. Until then it states intent rather than a binding position, and the operator is not trading.
We collect what is needed to verify a voucher, verify the person selling or buying it, and send the money to the right destination. Nothing on this page is a commercial preference dressed up as a legal requirement, and nothing described as a legal requirement is optional for us.
VoucherPay LLC operates this service from the United States, at 1801 Peninsula Verde Dr. VoucherPay LLC decides how and why the personal data described below is handled. Write to [email protected] about anything on this page.
The platform is pre-launch. Trading is not enabled and no orders are being settled. This policy describes how the service is built to handle your data when it opens, and it applies today to whatever we already hold — an account you registered, an enquiry you sent, a message you wrote to support.
What we collect, and why
Account data
An email address, a password, and the country you live in. The password is stored as a hash; we cannot read it and cannot tell it to you if you forget it.
We hold this to give you an account, to sign you in, to write to you about an order, and to establish whether the service is available where you live. Some countries are not served at all, for reasons set out at restricted countries.
Identity data
We hold your name and country of residence, and any documents collected through our verification process. A name and country are held for all customers, because sanctions screening cannot run without them.
Where full verification applies, we collect your full name, date of birth, residential address, nationality, the type of identity document you present, its country of issue and its expiry date, an image of the document, and — depending on the check — a photograph of you taken at the time and a document evidencing your address.
We do not store your document number. When you present a document, the number is converted into a one-way hash combined with a secret value held separately from the database. That lets us recognise the same document if it is presented again, without keeping the number itself. A copy of the database, taken on its own, does not yield anybody's passport or identity card number.
Document images are stored outside the web root. They are never served as ordinary files and cannot be reached by guessing a web address. They are encrypted at rest and delivered only to authenticated staff, through a route that records every view.
We hold your identity documents because the law requires it, not because they are useful to us.
Transaction data
For each order: the voucher brand, its face value and currency, the 5% commission, the amount payable, the settlement method you chose, the timestamps of each stage, the result of the verification call to the issuer, and the identifiers of the two members of staff involved — because approving an order and releasing its money must be done by two different operators.
This is the record a regulator, an auditor or a court can require us to produce. It is also the record that lets us answer you honestly if you later ask what happened to an order.
Voucher codes and settlement destinations
A voucher code is encrypted the moment it reaches us. It is readable only by the operator working that order, every read is written to an audit log, and the code is destroyed once the order settles. What survives settlement is the fact that a code of a given brand and value was received and verified — not the code.
Your settlement destination — a wallet address, a bank account, a PayPal address — is encrypted at rest for the same reason. It is a target for anyone who breaks into a system like this one, and it is treated accordingly.
Technical data
We record the IP address and the user agent your browser reports at sign-in and at sensitive actions: changing a password, adding or altering a settlement destination, submitting identity documents, placing an order, and any staff access to a document or a code.
This is how account takeover is detected, how we can tell whether an instruction came from you or from somebody who had your password, and how we establish where an instruction originated for sanctions and geographic screening.
Correspondence
Support tickets, complaints and the notes an operator makes while verifying a voucher with its issuer form part of the order record and are kept with it.
What we do not do
- We do not buy data about you from data brokers, and we do not enrich your profile from outside sources beyond the screening the law requires.
- We do not run advertising trackers or third-party analytics that follow you across other sites. The site sets the cookie needed to keep you signed in, and no cookie whose purpose is advertising.
- We do not sell personal data, and we do not use your data, your documents or your correspondence to train models.
- We do not ask a customer to send a voucher code by email or chat, and we would rather you never did. If you have already sent a code to someone, read what to do if you have sent a voucher code.
Who is able to see it
Access is granted by role, not by seniority, and the roles are narrow.
- The operator working your order sees the voucher code, the order details and, where the check requires it, your identity documents.
- The second operator, who releases the payment, sees the order and the approval — the four-eyes rule exists so that no single person can both approve and pay.
- The compliance officer sees identity and transaction data where a case, a screening match or a report requires it.
- A small number of engineers can reach production systems to keep them running. That access is logged in the same way as everyone else's.
- The voucher issuer, when we telephone to verify, is given the voucher details. Issuers are not sent your identity documents.
- Banks and payment providers receive what they need to move money to you, which for a bank transfer includes your name and account details.
- Auditors, regulators, law enforcement and courts receive what a lawful request obliges us to provide.
Nobody sees an identity document or a voucher code because they were curious. Every view is attributable to a named member of staff and a specific order.
Every access is logged
Each time an identity document is viewed or a voucher code is decrypted, the system records who did it, when, from where, and which order it was for. Those logs are append-only. Staff cannot edit or delete them, and neither can we on request.
You may ask us for the record of when your own identity documents have been accessed, and we will provide it — with the single exception described under When we cannot tell you what we have done.
No decision about you is automated
Screening tools may flag a name, a country or a document. They do not decide anything. A person reviews every flag, a person approves every order, and a different person releases the money. If an order is refused, a human refused it and a human can be asked to explain it, subject to the limits below.
How long we keep it
Records of identity, orders and correspondence are retained for five years, counted from the completion of the transaction or the end of our relationship with you, whichever falls later. This is an anti-money-laundering obligation on the operator, not a preference.
Within that period, voucher codes are the exception in your favour: a code is destroyed once its order settles, because keeping it serves no purpose and creates a risk.
Why a deletion request cannot override it
A right to erasure gives way where the data is held to satisfy a legal obligation. If we deleted your identity file on request, we would be unable to demonstrate to a regulator that a payout we made was made to an identified person — which is the specific failure the obligation exists to prevent.
What we can do, and will do on request: close your account, stop any non-essential contact, correct anything inaccurate, and restrict the record to its legal purpose so that it is no longer used in ordinary operations. It sits in retention for the regulator and for nothing else. When the retention period expires, it is deleted.
Your rights
Subject to the retention obligation above, you may ask us to:
- confirm what personal data we hold about you, and give you a copy;
- correct anything that is wrong or out of date;
- delete data we are not required to keep;
- restrict how we use your data, or object to a particular use;
- provide the data you gave us in a portable form;
- withdraw consent where consent, rather than law or contract, is what we rely on.
Write to [email protected]. We will verify who you are before answering, because a data access request is an effective way to attack somebody else's account, and we would rather be tedious than wrong about that.
How long we take is governed by the law of the country you live in and by how much has to be searched. Where that law fixes a period, we work to it. Where it does not, we answer as soon as the verification and the search allow, and tell you if it is taking longer.
When we cannot tell you what we have done
If a suspicious activity report is filed about a transaction or an account, we may be prohibited by law from telling you that it exists. This is not discretion on our part and it is not something a complaint can unlock.
In that situation we will neither confirm nor deny that a report has been made, and an access request may be answered incompletely without our being able to say so. We will not invent a different explanation to fill the gap.
Read this the right way. The obligation applies to every enquiry of that kind, including those that conclude with no further action taken and nothing held against anyone. Silence from us is what the law requires; it is not a statement about you.
Where your data goes
Your data is processed in France, in the European Union. Identity documents and voucher codes are held in storage we control and are not handed to third-party processors for routine handling.
Some supporting services — hosting infrastructure, email delivery — may process limited data outside France. Where that happens, we require contractual protections and a standard of security equivalent to our own, and we transfer the minimum the service needs to function.
Separately, data may be disclosed to United States authorities, and to foreign authorities through lawful channels, where an obligation or a valid legal request requires it.
How the data is protected
- Transport encryption for everything between your browser and the service.
- Encryption at rest for identity documents, voucher codes and settlement destinations.
- The secret used to hash document numbers is held apart from the database, so one stolen copy is not enough.
- Identity documents stored outside the web root and served only through an authenticated, audited route.
- Role-based access, so an operator reaches the orders they are working on and not the rest.
- Two different operators required to approve an order and to release its money.
- Append-only audit logs for document and code access.
- Passwords stored hashed, never in readable form.
- IP address and user agent recorded at sign-in and at every sensitive action.
No system is perfectly secure, and a policy that claimed otherwise would be worth less than this sentence. If a breach affects your data, we will tell you and the relevant authority as the law requires, describe what happened, and tell you what to do about it.
Age
The service is not available to anyone under 18. If we find that an account holder is under 18, the account is closed. Records already created remain subject to the retention obligation.
Changes to this policy
When this policy changes, the revised version is published on this page and dated. Where a change materially affects how your data is used, we will write to you. Changes do not apply retrospectively to data already processed under an earlier version.
If you are unhappy with how we handle your data
Write to [email protected] first, since most of it can be fixed directly. If that does not resolve it, use the complaints procedure, which is reviewed by someone who was not involved in the original decision. You also have the right to complain to the data protection authority with jurisdiction over us or over you, and using our procedure first does not take that right away.
Related reading: how we check a voucher and our security page.