Skip to main content

Mercorapay

Privacy Policy

Last Updated: July 31, 2026

Mercora (“Mercora,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, store, disclose, and protect information when you visit mercorapay.com, contact us, submit an inquiry, or otherwise interact with our services.

Mercora provides introductions and access to payment and financial solution providers for online casinos, sportsbooks, poker platforms, iGaming groups, and other eligible businesses.

By using our website or submitting information to us, you acknowledge that you have read and understood this Privacy Policy.

1. Information We Collect

We may collect personal information directly from you when you complete a contact form, email us, request information about our services, or communicate with our team.

The information we collect may include:

  • Full name
  • Company name
  • Business email address
  • Telephone number
  • Country or region
  • Service interests
  • Information included in your message or inquiry
  • Business role or job title
  • Preferred communication method
  • Any documents or information you voluntarily provide

Please do not submit confidential payment credentials, passwords, private keys, full card details, banking login information, or other highly sensitive data through our website contact form.

2. Information Collected Automatically

When you visit mercorapay.com, certain technical information may be collected automatically through server logs, cookies, analytics tools, and similar technologies.

This information may include:

  • IP address
  • Browser type and version
  • Device type
  • Operating system
  • Referring website
  • Pages visited
  • Date and time of access
  • Approximate geographic location
  • Website interaction and navigation data
  • Cookie and consent preferences

We use this information to maintain website functionality, improve performance, understand how visitors use the website, prevent misuse, and protect the security of our services.

3. How We Use Your Information

We may use personal information for the following purposes:

  • Responding to questions and business inquiries
  • Understanding your payment and financial requirements
  • Assessing which solutions may be appropriate for your business
  • Connecting you with suitable acquiring, banking, payment, card issuance, or liquidity providers
  • Arranging calls, meetings, introductions, or consultations
  • Managing our relationship with customers, prospects, suppliers, and partners
  • Providing information about our services
  • Improving the website and user experience
  • Maintaining business records
  • Detecting and preventing fraud, abuse, or security threats
  • Complying with legal and regulatory requirements
  • Establishing, exercising, or defending legal claims
  • Sending marketing communications where permitted by law

We will not use personal information for purposes that are materially incompatible with those described in this Privacy Policy unless we provide additional notice or obtain consent where required.

4. Legal Bases for Processing

Where applicable data protection law requires us to identify a legal basis, we may process personal information based on:

Consent

We may rely on your consent where you voluntarily submit an inquiry, accept optional cookies, or agree to receive marketing communications.

You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Steps Taken at Your Request

We may process your information when necessary to respond to a request, provide information about our solutions, or take steps before entering into a business relationship.

Contractual Necessity

Where you or your company enters into an agreement with Mercora, we may process information when necessary to perform or administer that agreement.

Legitimate Interests

We may process information where necessary for legitimate business interests, including:

  • Responding to business inquiries
  • Developing commercial relationships
  • Identifying suitable service providers
  • Improving our website and services
  • Securing our systems
  • Preventing fraud and misuse
  • Maintaining appropriate business records

We consider whether these interests are overridden by your privacy rights before relying on this legal basis.

Legal Obligations

We may process information when necessary to comply with laws, regulations, court orders, tax requirements, anti-money-laundering obligations, sanctions requirements, law-enforcement requests, or other binding legal duties.

Data protection notices should clearly explain the organisation collecting the information, its purposes, legal bases, retention periods, recipients, international transfers, and individual rights.

5. Payment and Financial Service Providers

Mercora may introduce businesses to independent payment processors, acquiring institutions, banks, electronic money institutions, alternative payment method providers, card issuers, compliance providers, and crypto liquidity providers.

These organisations may conduct their own due diligence, onboarding, fraud screening, sanctions screening, identity verification, source-of-funds checks, or regulatory assessments.

When you provide information directly to an independent provider, that provider may act as a separate data controller and process information under its own privacy policy. Mercora does not control the independent privacy practices, onboarding decisions, or regulatory procedures of third-party providers.

You should review the privacy policy and contractual terms of each provider before submitting information to them.

6. How We Share Information

We may disclose personal information to:

  • Payment and acquiring partners
  • Banks and financial institutions
  • Alternative payment method providers
  • Card issuance providers
  • Crypto liquidity providers
  • Compliance and identity verification providers
  • Technology and hosting providers
  • Website analytics and security providers
  • Professional advisers, including lawyers, accountants, and consultants
  • Contractors and service providers supporting our business
  • Regulatory authorities, courts, or law-enforcement agencies
  • Buyers, investors, or advisers involved in a merger, restructuring, financing, or sale of business assets

We share only information reasonably necessary for the relevant purpose and expect service providers to protect information appropriately.

We do not sell personal information in exchange for money.

7. Business-to-Business Information

Mercora primarily provides business-to-business services. Information submitted through our website should relate to legitimate business inquiries.

If you provide personal information about an employee, representative, director, beneficial owner, customer, or other individual, you confirm that you are authorised to provide it and that you have given the person any notices required by applicable law.

8. Cookies and Similar Technologies

Our website may use cookies and similar technologies to:

  • Enable essential website functions
  • Remember privacy and consent preferences
  • Maintain website security
  • Measure website traffic
  • Understand visitor behaviour
  • Improve performance and usability

Some cookies are necessary for the website to function. Optional analytics or marketing cookies should be used only where permitted and, where required, after obtaining consent.

You can manage cookies through the website consent banner or your browser settings. Disabling certain cookies may affect website functionality.

A separate Cookie Policy should be published if non-essential cookies, analytics platforms, advertising pixels, embedded services, or tracking technologies are installed.

9. Marketing Communications

We may send you service-related or marketing communications where permitted by law.

You can unsubscribe from marketing emails by:

Even after opting out of marketing communications, we may continue to send necessary administrative or service-related messages.

10. International Data Transfers

Mercora, its providers, and its commercial partners may operate in different countries. As a result, personal information may be processed outside your country of residence.

Where required, we use appropriate safeguards for international transfers, which may include:

  • Adequacy decisions
  • Standard contractual clauses
  • Contractual data protection commitments
  • Other legally recognised transfer mechanisms

Data protection notices should state whether information may be transferred outside the relevant jurisdiction and explain the safeguards that apply.

11. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.

Retention periods may depend on:

  • The nature of your inquiry
  • Whether a business relationship is established
  • Contractual requirements
  • Legal and regulatory obligations
  • Fraud prevention and security needs
  • Limitation periods for legal claims
  • The need to maintain appropriate business records

General inquiries that do not lead to a business relationship may be retained for up to 24 months, unless a longer period is required for legal, regulatory, security, or dispute-resolution purposes.

Customer, supplier, contractual, compliance, and transaction-related records may be retained for longer periods where required by applicable law.

Personal information should not be retained for longer than necessary for the purpose for which it was collected.

12. Data Security

We use reasonable technical and organisational safeguards designed to protect personal information against:

  • Unauthorised access
  • Accidental loss
  • Improper disclosure
  • Alteration
  • Misuse
  • Destruction
  • Unlawful processing

These safeguards may include access controls, secure hosting, account authentication, encryption, backups, monitoring, and restrictions on employee or contractor access.

However, no website, email transmission, or electronic storage system is completely secure. We cannot guarantee absolute security.

13. Your Privacy Rights

Depending on your location and applicable law, you may have the right to:

  • Request information about how your data is processed
  • Access personal information held about you
  • Correct inaccurate or incomplete information
  • Request deletion of personal information
  • Restrict certain processing activities
  • Object to processing based on legitimate interests
  • Object to direct marketing
  • Withdraw consent
  • Request data portability
  • Lodge a complaint with a data protection authority
  • Receive information about international transfers
  • Request review of certain automated decisions

The GDPR recognises rights including access, rectification, erasure, restriction, portability, objection, and the right to be informed.

To exercise a privacy right, contact:

[email protected]

We may ask you to verify your identity before completing a request. We may also request additional details to identify the relevant information.

Certain rights are subject to legal exceptions and may not apply in every situation.

14. California Privacy Rights

Where applicable, California residents may have rights relating to:

  • Knowing the categories and specific pieces of personal information collected
  • Knowing the purposes for which information is used
  • Knowing the categories of recipients
  • Requesting deletion or correction
  • Receiving equal service when exercising privacy rights
  • Opting out of the sale or sharing of personal information, where applicable

Mercora does not knowingly sell personal information for monetary consideration.

If Mercora later uses advertising technology that constitutes “sharing” under California law, this policy and the website consent controls should be updated accordingly.

15. Automated Decision-Making

Mercora does not currently use information submitted through the website to make decisions based solely on automated processing that produce legal or similarly significant effects.

Independent financial institutions or payment providers may use automated fraud, risk, compliance, or onboarding systems under their own policies and legal obligations.

16. Third-Party Websites

Our website may contain links to websites operated by independent third parties.

Mercora is not responsible for the privacy, security, content, or practices of those websites. You should review the privacy policy of any third-party website before submitting personal information.

17. Children’s Privacy

Mercora provides business-to-business financial solution services and does not knowingly collect personal information from children.

Our website and services are not intended for individuals under the age of 18. If we learn that a child has provided personal information, we will take reasonable steps to delete it.

18. Regulatory and Compliance Information

Due to the nature of the payment and gaming industries, Mercora or its partners may be required to request additional corporate or personal information during onboarding.

This may include information relating to:

  • Company ownership
  • Directors and authorised representatives
  • Beneficial owners
  • Licensing
  • Source of funds
  • Transaction activity
  • Sanctions and politically exposed person screening
  • Anti-money-laundering checks
  • Fraud and risk assessments

Any such information will be processed in accordance with applicable legal, contractual, compliance, and security requirements.

19. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in:

  • Our website
  • Our services
  • Our providers
  • Our information practices
  • Applicable laws or regulations

The revised version will be published on this page with an updated “Last Updated” date. Material changes may also be communicated through the website or by email where appropriate.

20. Contact Us

For questions, concerns, complaints, or privacy requests, contact:

Mercora
Website: mercorapay.com
Email: [email protected]

Information Still Required Before Publication

Add the following information before publishing the policy:

  • Mercora’s full registered legal company name
  • Registered business address
  • Country of incorporation
  • Company registration number
  • Data protection officer or privacy contact, if applicable
  • Names of analytics, hosting, CRM, email, and cookie providers used
  • The actual data retention periods used by the business

This draft should be reviewed by a qualified privacy professional for the countries in which Mercora operates or targets customers. Regulatory guidance itself notes that general guidance does not replace the legally binding text or professional assessment.