Privacy Policy
Last updated: August 8, 2026
The short version
We collect what the product needs to work, we keep sales records because the law requires it, and we never sell, rent, or share your data for advertising — not yours, not your buyers'. This marketing site uses Google Analytics to understand how visitors find us; checkout pages and the seller dashboard do not load any third-party tracker. Card numbers never touch our servers at all.
1. Who this covers
Three groups of people interact with SurcoPay: sellers (creators with an account), buyers (their customers, who check out as guests without any account), and visitors (anyone browsing this site or a seller's storefront). Each is treated differently below.
2. What we collect from sellers
- Account: email address, business name, and your password — stored only as a salted cryptographic hash (bcrypt); we cannot read it.
- Security: if you enable two-factor authentication, its secret is stored encrypted and your backup codes only as hashes.
- Payments: if you connect a Stripe account we store only identifiers and status — your identity documents and bank details are collected and held by Stripe, not us. If you pasted API keys (legacy option), they are stored encrypted with a key kept outside the database.
- Tax settings: your business location and the jurisdictions you tell us you are registered in.
- Content: your products, uploaded files, and anything you choose to publish on your storefront (which is public by your choice).
3. What we process about buyers
Buyers check out as guests — there are no buyer accounts and no buyer passwords. On each purchase we process, on the seller's behalf:
- Email address — it is how the product is delivered and receipts are sent, and it appears in the seller's own customer list.
- Phone number — only for ATH Móvil payments.
- Purchase records — product, amount, date, and refunds; these are the seller's sales records and the buyer's receipts.
- Location — country/region as stated by the buyer, only when the seller collects sales tax.
- Fraud signals — the IP address and browser information of a checkout are recorded with that checkout session and used for fraud prevention and rate limiting.
- Card metadata — the card's last four digits and brand, for receipts and fraud checks. Full card numbers never reach our servers: they travel directly from the buyer's browser to Stripe.
4. Analytics
Marketing site (surcopay.com): This site uses Google Analytics (GA4) to understand how visitors find us and which pages they read. Google Analytics sets cookies (named _ga and _ga_*) that contain a random identifier — not your name or email. Google processes this data under its own privacy policy. We do not enable advertising features, user-ID tracking, or data sharing with other Google products.
Storefronts, checkout pages, and the seller dashboard: These use our own first-party analytics only. When you view a storefront or checkout, we record one event containing: the page path, the referring site, campaign tags from the link (utm parameters), an approximate country, and whether the device is mobile or desktop. No third-party tracker loads on these pages.
What a first-party analytics event never contains: your IP address, your browser fingerprint, a cookie, or any identifier. The IP and browser string are read once — to derive the country and device class — and discarded. These events can be counted; they cannot be traced back to a person. Sellers see aggregate traffic reports for their own pages built from this data.
5. What we never do
- We never sell or rent personal data. To anyone. For anything.
- We never share data with advertising networks, and no ad or social-media pixel runs on our pages.
- No third-party analytics or tracking script runs on checkout pages, storefronts, or the seller dashboard.
6. Who we share data with
Only the processors the product runs on: Stripe (card payments, payouts, and seller identity verification), PayPal and ATH Móvil (when the seller offers them), Google Analytics (aggregate traffic data on this marketing site only), our email delivery provider (receipts and account emails), and our hosting and storage infrastructure. Each processes data only to provide its service. We may also disclose information if the law requires it, or transfer it as part of a sale of the business — under this same policy.
7. Retention and deletion
Sellers can delete their account from the dashboard at any time. Deletion deactivates the account immediately; for 30 days it can be restored by logging back in (people delete accounts by mistake), after which personal data — profile, credentials, uploaded files, storefront, customer lists — is permanently purged and the email address is freed.
What survives deletion: transaction and tax records. These are financial records — the seller's sales ledger, the buyers' receipts, and our fee records — and are retained for up to 7 years as required for tax and accounting compliance. Buyers may request deletion of their personal data through the seller they bought from or by contacting us; the same financial-record retention applies.
8. Security
- Passwords hashed with bcrypt and per-password salts; two-factor authentication available on every account.
- Payment credentials and 2FA secrets encrypted at rest, with keys held outside the database.
- All traffic over TLS; card data handled entirely by Stripe's certified infrastructure.
- Access controls, rate limiting, and audit logging on sensitive operations.
No system is 100% secure and we will not pretend ours is. If a breach ever affects your data, we will notify affected users promptly and describe exactly what was involved.
9. Cookies and local storage
We do not use advertising cookies. This marketing site (surcopay.com) sets Google Analytics cookies (_ga, _ga_*) that contain a random visitor identifier used for aggregate traffic reporting — they do not contain your name, email, or any account information. The dashboard keeps your login session in your browser's local storage; checkout pages use session storage only to avoid counting the same view twice. Our first-party analytics (used on storefronts and checkout pages) set no cookies at all.
10. Children
Our services are not intended for individuals under 18. We do not knowingly collect personal information from children.
11. Changes to this policy
When we change this policy we update this page and its date. Material changes will be called out to account holders. Continued use after changes constitutes acceptance.
12. Contact
Questions about privacy: support@surcopay.com
© 2026 SurcoPay. All rights reserved.