Privacy Policy
Last updated: 10 July 2026
ZAZZpay B.V. ("ZAZZpay", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard personal data when you use the ZAZZpay mobile application, artist dashboard, and checkout pages (together, the "Service"), and it describes your rights under the General Data Protection Regulation (GDPR).
This policy applies to several categories of people:
- Artists - the merchants who register for a ZAZZpay account (Section 3.1).
- Guests - team members an artist adds to help process sales from a shared device, using a PIN code rather than their own account (Section 3.2).
- Buyers - people who pay an artist through the Service (Section 3.3).
- Waitlist signups - people who register interest before an invite is available (Section 3.4).
1. Data Controller
The data controller responsible for your personal data is:
ZAZZpay B.V.
Overtoom 568-1
1054 LN Amsterdam
The Netherlands
Privacy contact: privacy@zazzpay.com
Website: https://zazzpay.com
We have not appointed a Data Protection Officer, as we are not legally required to do so. For any privacy-related questions, please use the contact details above.
2. How the Service Works (in brief)
ZAZZpay lets artists accept card payments from buyers - via a checkout page, a payment link/QR code, or Tap to Pay on a mobile device - and receive payouts through Stripe Connect. Artists complete identity verification and provide banking details directly to Stripe through Stripe's own onboarding flow; we never see or store that information. Our systems store only what is necessary to operate accounts, reconcile transactions, calculate payouts and tax, and keep a security/audit trail of who did what.
3. Personal Data We Collect
3.1 Artists
When you register and use the ZAZZpay mobile app or artist dashboard, we collect:
- Account information: full name, email address, password (hashed with Argon2id, never stored in plain text), your artist/business name, and your registered country.
- Stripe Connect account: your Stripe Connected Account ID and your Stripe onboarding/payout status. Banking details, government ID, and other KYC information are collected and held directly by Stripe - ZAZZpay does not store or have access to them.
- Transaction and payout records: amounts, currencies, VAT/tax rates, timestamps, and status for every transaction, refund, dispute, and payout associated with your account.
- Approximate location: derived from your device's IP address, used to confirm that the country you are transacting from matches your registered country before enabling in-person card payments (Tap to Pay). See Section 5 for the third party involved. We retain the country of your location, but no other personal identifiable information, including your IP address is stored.
- Device permissions for Tap to Pay: if you use the mobile app, enabling in-person contactless payments requires the Stripe Terminal SDK to use your phone's own NFC chip. Your device's operating system (iOS/Android) requires us to request Bluetooth, Location, and Near-Field Communication (NFC) permissions to do this, even though no external card reader is used. We do not use these OS-level permissions to determine, track, or store your precise GPS coordinates - they are used solely to let your phone's hardware accept a contactless card tap. This is separate from the country-level approximate location check described above.
- Marketing consent: whether you agreed to receive marketing communications at signup, so we can honour or withdraw that preference.
- Session and security data: IP address, user agent (device/browser, or - for the mobile app - app version and operating system), and session/refresh tokens, recorded each time you log in or refresh your session, and again as part of the audit trail described below. See Section 10 for how the mobile app stores your session token on-device. We retain this for 30 days or however long required by (local) law.
- Audit trail: every change made to your account or its data (e.g. account updates, threshold changes, guest creation) is logged with the acting user, role, timestamp, IP address, and a before/after record of the change, for security and accountability purposes. We retain this for 30 days or however long required by (local) law.
3.2 Guests (team members)
Artists can add "guests" - e.g. staff helping at a merch table - who log in on a shared device using a join code and a PIN, without creating their own full account. For guests, we store:
- The name the artist entered for them, and a hashed PIN.
- A system-generated placeholder username/email (not a real email address) used internally to satisfy account infrastructure - this is not personal data provided by or about a real email account.
- The same session and security data (IP address, user agent) and audit trail entries as artists, tied to the guest's actions (e.g. which transactions they processed).
Guests do not provide payment details, and we do not collect a guest's own contact information unless the artist chooses to use it as their display name. To let a guest log in on their own device, the artist's device displays a QR code containing the guest's join code; this is generated by the third-party service described in Section 5.
3.3 Buyers
Buyers do not create ZAZZpay accounts. When a buyer pays an artist - via a Stripe-hosted checkout session, a QR/payment link, or Tap to Pay - payment card data is entered directly into Stripe's systems and is never transmitted to or stored by ZAZZpay. We process only:
- A Stripe payment/transaction reference ID, which lets us reconcile the payment with the artist's account. This is a reference identifier and does not, on its own, identify you.
- The email address you choose to provide for an emailed receipt. This is passed directly to Stripe to send the receipt and is not stored in ZAZZpay's database.
- Standard web server access logs (e.g. IP address, timestamp, requested page) generated when you view a checkout or payment-status page, kept only for short-term infrastructure security and abuse prevention.
We do not collect buyer names, shipping addresses, or any payment details ourselves. All payment data is handled by Stripe as an independent controller - see https://stripe.com/privacy.
3.4 Waitlist signups
If you join the waitlist before receiving an invite to sign up, we collect the name and email address you submit, and track the status of your invite (pending, approved, rejected, or converted to an account).
4. How We Use Your Personal Data and Legal Bases
Under the GDPR, we must have a valid legal basis for processing your personal data. The table below explains each purpose and the corresponding legal basis.
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Creating and managing your artist account | Performance of a contract (Art. 6(1)(b)) |
| Creating and managing guest logins on your behalf | Performance of a contract (Art. 6(1)(b)) |
| Processing transactions and payouts via Stripe | Performance of a contract (Art. 6(1)(b)) |
| Complying with tax, accounting, and anti-money-laundering obligations | Legal obligation (Art. 6(1)(c)) |
| Verifying device location for Tap to Pay eligibility and fraud prevention | Legitimate interests (Art. 6(1)(f)) - to comply with card network rules and prevent misuse |
| Requesting Bluetooth/Location/NFC device permissions and generating QR codes to enable in-person Tap to Pay and guest logins | Performance of a contract (Art. 6(1)(b)) |
| Sending service-related communications (e.g., payout confirmations, security alerts) | Performance of a contract (Art. 6(1)(b)) |
| Sending marketing communications and newsletters | Consent (Art. 6(1)(a)) - which you may withdraw at any time |
| Managing the waitlist and invite process | Consent (Art. 6(1)(a)) / Performance of steps prior to a contract (Art. 6(1)(b)) |
| Maintaining session, security, and audit logs | Legitimate interests (Art. 6(1)(f)) - to secure accounts and investigate misuse |
| Responding to legal requests and defending legal claims | Legal obligation (Art. 6(1)(c)) / Legitimate interests (Art. 6(1)(f)) |
5. Sharing Your Personal Data
We share personal data only with the following categories of recipients:
- Stripe Payments Europe, Ltd. - our payment processor and Stripe Connect provider, which handles onboarding, transactions, and payouts. Stripe acts as an independent data controller for payment data. See: https://stripe.com/privacy
- ip2location.io (Hexasoft Development Sdn. Bhd.) - an IP geolocation lookup service we use, as a data processor, to derive an artist's approximate country from their device IP address for the Tap to Pay location check described in Section 3.1.
- Foundata GmbH (goQR.me / api.qrserver.com) - a QR-code generation service based in Germany, used as a data processor by the mobile app to render the on-screen QR codes for "scan to pay" payment links and for guest login join codes (Sections 3.2 and 3.3). Only a payment or join reference is sent to this provider - never your name, email, or payment details - though its standard web server logs may record the requesting device's IP address.
- Cloud hosting and infrastructure providers that host the Service on our behalf (as data processors).
- Competent authorities, regulators, or law enforcement, where required by law.
- Professional advisors (e.g., lawyers, accountants, auditors), where necessary and under confidentiality obligations.
We do not sell your personal data to third parties.
6. International Data Transfers
Some of our service providers process personal data outside the European Economic Area (EEA):
- Stripe may process data in the United States and other jurisdictions, including as part of its group-wide payment infrastructure.
- ip2location.io is based outside the EEA and does not benefit from an EU adequacy decision.
When we or our providers transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including:
- The EU-US Data Privacy Framework (for certified US recipients), and/or
- Standard Contractual Clauses (SCCs) approved by the European Commission, and/or
- Supplementary technical and organisational measures where required.
You can request a copy of the relevant safeguards by contacting us at privacy@zazzpay.com.
7. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy. Consistent with our internal data handling practices, financial and audit records are never hard-deleted - they are retained for the periods below and then anonymised or restricted from active use, since destroying them outright would conflict with our legal retention obligations.
| Data Category | Retention Period |
|---|---|
| Artist account data | For the duration of your account, plus legal retention periods after deletion |
| Guest (team member) data | While the guest login is active, plus a limited period after it is revoked |
| Transaction, payout, and dispute/refund records | 7 years after the transaction, as required by Dutch tax and accounting law |
| Marketing consent records | Until consent is withdrawn, plus a reasonable period to demonstrate compliance |
| Waitlist entries | Until converted to an account, or a reasonable period after the invite expires |
| Session and security logs (IP address, user agent) | Up to 12 months |
| Audit trail entries | 7 years, in line with the financial records they relate to |
| Buyer receipt email addresses | Not retained by ZAZZpay - passed directly to Stripe and not stored in our systems |
After the applicable retention period, personal data is deleted, anonymised, or restricted from further active use, to the extent our legal obligations allow.
8. Your Rights Under the GDPR
You have the following rights regarding your personal data:
- Right of access - request a copy of the personal data we hold about you.
- Right to rectification - correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") - request deletion, subject to legal retention obligations (see Section 7 - some records, such as tax and audit records, must be retained even after an erasure request and will instead be anonymised or restricted where deletion is not possible).
- Right to restriction of processing - limit how we process your data in certain circumstances.
- Right to data portability - receive your data in a structured, commonly used, machine-readable format.
- Right to object - object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent - where processing is based on consent, you may withdraw it at any time, without affecting prior lawful processing.
- Right not to be subject to automated decision-making - we perform an automated check of your device's approximate location (via IP address) against your registered country to determine eligibility for Tap to Pay; this affects a specific feature, not your overall account access, and you may contact us if you believe it has produced an incorrect result. Beyond this, we do not use automated decision-making or profiling that produces legal or similarly significant effects.
To exercise any of these rights, please contact us at privacy@zazzpay.com. We will respond within one month, as required by GDPR.
Right to Lodge a Complaint
If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): https://autoriteitpersoonsgegevens.nl
You may also lodge a complaint with the supervisory authority in your country of residence.
9. Cookies and Similar Technologies
The artist dashboard uses a single essential session cookie to keep you signed in; it is strictly necessary for the Service to function and is not used for tracking, advertising, or analytics. The mobile app authenticates using a bearer token (JWT) rather than cookies. We do not use third-party advertising or analytics cookies or trackers on the Service.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These measures include encryption in transit (TLS), hashed passwords and PINs (Argon2id), signed authentication tokens (JWT, RS256) stored in your device's secure hardware-backed storage on the mobile app (Keychain on iOS, Keystore on Android), database-level row-level security that restricts each account to its own data, detailed audit logging of account and financial changes, access controls, and regular security reviews.
No system is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you and the supervisory authority in accordance with GDPR requirements.
11. Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be notified to you via email or through the Service. The "Last updated" date at the top of this policy reflects the most recent version.
13. Contact Us
For any questions, requests, or complaints regarding this Privacy Policy or our handling of your personal data, please contact:
ZAZZpay B.V.
Overtoom 568-1
1054 LN Amsterdam
The Netherlands
Email: privacy@zazzpay.com
