Last Updated: July 31, 2026
Mercora (“Mercora,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, store, disclose, and protect information when you visit mercorapay.com, contact us, submit an inquiry, or otherwise interact with our services.
Mercora provides introductions and access to payment and financial solution providers for online casinos, sportsbooks, poker platforms, iGaming groups, and other eligible businesses.
By using our website or submitting information to us, you acknowledge that you have read and understood this Privacy Policy.
We may collect personal information directly from you when you complete a contact form, email us, request information about our services, or communicate with our team.
The information we collect may include:
Please do not submit confidential payment credentials, passwords, private keys, full card details, banking login information, or other highly sensitive data through our website contact form.
When you visit mercorapay.com, certain technical information may be collected automatically through server logs, cookies, analytics tools, and similar technologies.
This information may include:
We use this information to maintain website functionality, improve performance, understand how visitors use the website, prevent misuse, and protect the security of our services.
We may use personal information for the following purposes:
We will not use personal information for purposes that are materially incompatible with those described in this Privacy Policy unless we provide additional notice or obtain consent where required.
Where applicable data protection law requires us to identify a legal basis, we may process personal information based on:
We may rely on your consent where you voluntarily submit an inquiry, accept optional cookies, or agree to receive marketing communications.
You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
We may process your information when necessary to respond to a request, provide information about our solutions, or take steps before entering into a business relationship.
Where you or your company enters into an agreement with Mercora, we may process information when necessary to perform or administer that agreement.
We may process information where necessary for legitimate business interests, including:
We consider whether these interests are overridden by your privacy rights before relying on this legal basis.
We may process information when necessary to comply with laws, regulations, court orders, tax requirements, anti-money-laundering obligations, sanctions requirements, law-enforcement requests, or other binding legal duties.
Data protection notices should clearly explain the organisation collecting the information, its purposes, legal bases, retention periods, recipients, international transfers, and individual rights.
Mercora may introduce businesses to independent payment processors, acquiring institutions, banks, electronic money institutions, alternative payment method providers, card issuers, compliance providers, and crypto liquidity providers.
These organisations may conduct their own due diligence, onboarding, fraud screening, sanctions screening, identity verification, source-of-funds checks, or regulatory assessments.
When you provide information directly to an independent provider, that provider may act as a separate data controller and process information under its own privacy policy. Mercora does not control the independent privacy practices, onboarding decisions, or regulatory procedures of third-party providers.
You should review the privacy policy and contractual terms of each provider before submitting information to them.
We may disclose personal information to:
We share only information reasonably necessary for the relevant purpose and expect service providers to protect information appropriately.
We do not sell personal information in exchange for money.
Mercora primarily provides business-to-business services. Information submitted through our website should relate to legitimate business inquiries.
If you provide personal information about an employee, representative, director, beneficial owner, customer, or other individual, you confirm that you are authorised to provide it and that you have given the person any notices required by applicable law.
Our website may use cookies and similar technologies to:
Some cookies are necessary for the website to function. Optional analytics or marketing cookies should be used only where permitted and, where required, after obtaining consent.
You can manage cookies through the website consent banner or your browser settings. Disabling certain cookies may affect website functionality.
A separate Cookie Policy should be published if non-essential cookies, analytics platforms, advertising pixels, embedded services, or tracking technologies are installed.
We may send you service-related or marketing communications where permitted by law.
You can unsubscribe from marketing emails by:
Even after opting out of marketing communications, we may continue to send necessary administrative or service-related messages.
Mercora, its providers, and its commercial partners may operate in different countries. As a result, personal information may be processed outside your country of residence.
Where required, we use appropriate safeguards for international transfers, which may include:
Data protection notices should state whether information may be transferred outside the relevant jurisdiction and explain the safeguards that apply.
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Retention periods may depend on:
General inquiries that do not lead to a business relationship may be retained for up to 24 months, unless a longer period is required for legal, regulatory, security, or dispute-resolution purposes.
Customer, supplier, contractual, compliance, and transaction-related records may be retained for longer periods where required by applicable law.
Personal information should not be retained for longer than necessary for the purpose for which it was collected.
We use reasonable technical and organisational safeguards designed to protect personal information against:
These safeguards may include access controls, secure hosting, account authentication, encryption, backups, monitoring, and restrictions on employee or contractor access.
However, no website, email transmission, or electronic storage system is completely secure. We cannot guarantee absolute security.
Depending on your location and applicable law, you may have the right to:
The GDPR recognises rights including access, rectification, erasure, restriction, portability, objection, and the right to be informed.
To exercise a privacy right, contact:
We may ask you to verify your identity before completing a request. We may also request additional details to identify the relevant information.
Certain rights are subject to legal exceptions and may not apply in every situation.
Where applicable, California residents may have rights relating to:
Mercora does not knowingly sell personal information for monetary consideration.
If Mercora later uses advertising technology that constitutes “sharing” under California law, this policy and the website consent controls should be updated accordingly.
Mercora does not currently use information submitted through the website to make decisions based solely on automated processing that produce legal or similarly significant effects.
Independent financial institutions or payment providers may use automated fraud, risk, compliance, or onboarding systems under their own policies and legal obligations.
Our website may contain links to websites operated by independent third parties.
Mercora is not responsible for the privacy, security, content, or practices of those websites. You should review the privacy policy of any third-party website before submitting personal information.
Mercora provides business-to-business financial solution services and does not knowingly collect personal information from children.
Our website and services are not intended for individuals under the age of 18. If we learn that a child has provided personal information, we will take reasonable steps to delete it.
Due to the nature of the payment and gaming industries, Mercora or its partners may be required to request additional corporate or personal information during onboarding.
This may include information relating to:
Any such information will be processed in accordance with applicable legal, contractual, compliance, and security requirements.
We may update this Privacy Policy to reflect changes in:
The revised version will be published on this page with an updated “Last Updated” date. Material changes may also be communicated through the website or by email where appropriate.
For questions, concerns, complaints, or privacy requests, contact:
Mercora
Website: mercorapay.com
Email: [email protected]
Add the following information before publishing the policy:
This draft should be reviewed by a qualified privacy professional for the countries in which Mercora operates or targets customers. Regulatory guidance itself notes that general guidance does not replace the legally binding text or professional assessment.