Privacy Policy
Last updated 20 August 2026
FloatPay is a payment gateway for businesses. This policy explains what we collect, what we deliberately do not store, how long we keep what we do, and who else touches it.
Pending legal review
This document accurately describes how the FloatPay service works today. It has not yet been reviewed by counsel, and it is not legal advice. Written notice will be given before any change that reduces your rights.
Who we are
FloatPay is operated from Los Angeles, California. We provide payment gateway and dashboard services to businesses (“merchants”). Contact us at hello@float-pay.com.
For information about the merchants who use FloatPay, we act on their instructions as a service provider. For information about our own customers — the businesses that sign up — we decide how it is handled and this policy applies directly.
What we deliberately do not store
This is the most important thing in this document, so it comes first.
- Card numbers never reach our servers. Card details are entered directly into fields hosted by our payment gateway provider and are exchanged for a single-use token. Our systems see the token, the card brand, and the last four digits — never the full number, and never the security code.
- We do not keep a copy of your transaction history. Transactions are read live from the gateway each time you open a page, held briefly in memory to keep the dashboard responsive, and discarded. There is no transaction table in our database.
- We do not sell personal information and we do not share it for cross-context behavioural advertising. We have never done either.
What we do collect
- Account information. Your name, email address, and a one-way hash of your password. If you enable two-factor authentication, the secret for your authenticator app, encrypted at rest.
- Application information. When you apply, the legal and trading name of your business, address, tax identifier, contact details, and the bank account used for settlement. Bank account and routing numbers are encrypted at rest with a key that lives only on the server, and are readable only during the review that requires them.
- Activity records. An append-only log of security- and money-relevant actions: who did what, to which account, from which IP address, and when. These records cannot be edited or deleted by anyone, including us — that is what makes them worth having.
- Support correspondence you send us.
Why we use it
- To provide the service: signing you in, showing your payments, running the actions you ask for.
- To decide whether we can board your business, which our payment gateway provider and card network rules require.
- To keep the service secure: detecting unusual sign-in activity, rate limiting, and investigating incidents.
- To meet legal and card network obligations, including anti-money-laundering and record-keeping requirements.
- To email you about your account. We do not send marketing email to your account address without asking first.
How long we keep it
Each period below matches a rule enforced in the software, not an intention.
- Bank details from an application: deleted within 30 days of the application being decided, whether approved or rejected. An automatic sweep removes them; nobody has to remember.
- CSV exports you generate: the file is deleted one hour after it is ready. Only the fact that you asked for it is kept.
- Cached transaction data: under a minute, in memory only.
- Activity records: kept for the life of the account and for as long afterwards as law and card network rules require. They are append-only by design.
- Account information: kept while your account is open, and deleted on request afterwards except where we are required to retain it.
Who else touches your data
We use a small number of service providers, each for one purpose:
- Our payment gateway provider, which processes card transactions and holds the record of them. Card data goes to them directly from your customer's browser.
- Our email provider, which delivers account emails such as verification and password resets.
- Our hosting provider, which runs the servers and stores encrypted backups.
We will name any of these on request. We do not give your information to anyone else except where the law requires it, and we will tell you if that happens unless we are prohibited from doing so.
Your rights
If you are in California, you may ask us what personal information we hold about you, ask us to delete or correct it, and ask us to tell you who we shared it with. We will not treat you differently for asking. If you are in the UK or the EU, you have equivalent rights, including the right to object to processing and to receive your data in a portable form.
Write to hello@float-pay.com. We will respond within 45 days. We may need to verify who you are before acting — a request to delete an account is exactly the request an attacker would make.
Security
Access to a workspace is scoped to the organisation it belongs to, and every request is checked on the server; hiding a button is never the control. Sensitive fields are encrypted at rest and bound to the record they belong to, so a value copied elsewhere cannot be read. Two-factor authentication is available to every account and required for accounts that can move money.
No system is perfect. If we discover a breach affecting your information we will tell you, and we will tell you what we know rather than waiting until we know everything.
Children
FloatPay is a service for businesses. It is not directed at anyone under 18 and we do not knowingly collect information from children.
Changes
We will post any change here and update the date at the top. If a change materially reduces your rights, we will email account owners before it takes effect. See also our Terms of Service.