Skip to content

Privacy policy

SwiftPay is a payment-processing business and a registered Independent Sales Organization (ISO) for Clover, a Fiserv product, and for Nuvei. SwiftPay is not one company. It operates through three separate companies — one in Australia, one in the United States and one in Canada — which share the SwiftPay brand and this website, swiftpaytoday.com. The website itself — its domain, its hosting and its analytics — is operated by Swift Pay AUS Pty Ltd, the Australian company, whichever country you are visiting from. This policy explains what personal information the SwiftPay companies collect through this website and through our sales, installation and support work, why we collect it, who we give it to, how long we keep it and what you can ask us to do with it. Which company is responsible for your information depends on the country you are in, and so do your rights — there is a section below for each country, and a separate one for California. Whichever company holds your information, one email address reaches all of us: support@swiftpaytoday.com.

Last updated 16 August 2026

Français

01Who we are, and what this policy covers

SwiftPay resells, installs, configures and supports payment hardware and merchant processing for businesses in Australia, the United States and Canada. We are a registered Independent Sales Organization for Clover, a Fiserv product, and for Nuvei. We are not the acquirer and we are not the processor — those roles sit with our partners and the banks behind them.

"SwiftPay" is a brand, and a brand cannot hold your information. Three separate companies do. Each one is its own legal entity, each one signs its own contracts with merchants in its own country, and each one is responsible under its own country's privacy law for the information it holds. The SwiftPay company responsible for your personal information is:

  • Australia — Swift Pay AUS Pty Ltd (ABN 49 683 708 938, ACN 683 708 938), of 5 Charles Smith Avenue, Bungarribee, New South Wales 2767, Australia.
  • United States — SwiftPay USA Inc., a Delaware corporation, of 210 Richards Avenue, Piscataway, New Jersey 08854, United States.
  • Canada — Swiftpay CAD Inc. (Canada corporation number 1799191-6, business number 709883037), of 43 Munch Avenue, Cambridge, Ontario N1R 0C2, Canada.
  • Anywhere else — Swift Pay AUS Pty Ltd (ABN 49 683 708 938, ACN 683 708 938) is responsible for visitors outside Australia, the United States and Canada.

Where this policy says "we", "us" or "SwiftPay" without naming a company, it means the SwiftPay company for your country. Where a rule applies to only one of them, we name that one.

How we work out which company that is: from what you tell us. The country you choose on a form, the trading address you give us, and the market your enquiry is about are what decide it. We do not decide it from your IP address, and we do not ask you to prove where you are.

This website itself is operated and controlled by Swift Pay AUS Pty Ltd (ABN 49 683 708 938). When you first arrive on the site, before you have told us anything, we do not yet know which country you are in. Until we do, that company holds your information — the page requests, the cookies you have agreed to, and anything you type into a form — and handles it to the standard set out in this policy. Once we know which market you are in, your information is passed to the SwiftPay company for your country, and that company takes over responsibility for it.

This policy covers the personal information the SwiftPay companies collect through swiftpaytoday.com — including our enquiry, quote, demo and callback forms and our referral partner applications — and the information we handle afterwards when we quote, order hardware, help you apply for a merchant facility, install a terminal or answer a support request.

It does not cover card transactions. This website does not process card payments and does not store cardholder data. When your customers pay you, the transaction runs on the PCI DSS certified platform operated by Clover/Fiserv or by Nuvei, under their own terms and privacy policies. This policy also does not cover other companies' websites we link to — read their policies when you get there.

Throughout this page, "personal information" means information about an identified individual, or about someone who can reasonably be identified from it. Some of the laws that apply to us call the same thing "personal data" or "personally identifiable information". We use one term to keep this readable.

02The personal information we collect, and how

Most of it comes straight from you — when you fill in a form, email us, call us, or talk to us during installation and support. Some comes from our partners, and some is collected automatically when you use the website. We ask for what we reasonably need to answer you and to do the job, and not more.

From our enquiry, quote, demo and callback forms we collect:

  • your name, and your role at the business if you tell us
  • your business or trading name, and the kind of business you run
  • your email address and phone number
  • the country you are in, and the suburb, city, state or province you trade in — this is also how we work out which SwiftPay company deals with you
  • the hardware or processing you are interested in — for example a Clover Flex, a Station Duo, a Kiosk, a PAX A920 Pro or a Nuvei Desk/5000
  • anything else you write in the message field
  • whether you asked us to call you, and whether you ticked the box asking for marketing emails

From referral partner applications we collect the same contact and business details, plus the industries and regions you work in, how you plan to refer merchants to us, and — only once a referral arrangement is actually agreed — the details we need to record and pay a referral.

If you go ahead and apply for a merchant facility, the application asks for more than an enquiry does: the names, dates of birth and contact details of the business owners or directors, identity document details, business registration details, an estimate of your card turnover, and the bank account your settlements should be paid into. Much of this is collected on our partner's own application form. Where we help you complete it, or where you send it to us, we handle it too, and this policy applies to our handling of it.

When you use the website we collect standard technical information automatically:

  • your IP address, and the approximate location (country, and usually city) it indicates
  • your device type, browser and operating system
  • the pages you viewed, when, how long for, and the page that referred you
  • cookie and similar identifiers — see the cookies section below

We also receive information from our partners and from other sources. Clover/Fiserv and Nuvei send us updates about the progress of an application, the status of an account, a hardware order or a support case. Someone who referred you may pass on your contact details. Another SwiftPay company may pass on an enquiry that reached it but belongs in your market. And where we approach a business about payment acceptance, we may use business contact details the business has published itself — a published "info@" or "manager@" address, or a listed phone number.

We do not seek sensitive information. We do not ask for health information, racial or ethnic origin, religious or political views, sexual orientation, union membership or biometric data, and we ask you not to send it to us. Please also do not email us full card numbers, card security codes or PINs — we do not need them, we do not want them, and we do not store them.

You can deal with us anonymously or under a pseudonym for a general question about hardware or pricing. If you want a quote, a call back, or a merchant application submitted, we will need real contact details, because we cannot do those things without them.

03Why we collect it, and on what basis

The SwiftPay companies collect personal information for these purposes, and we do not use it for unrelated ones:

  • to answer your enquiry, prepare a quote, book a demo or call you back when you have asked us to
  • to work out which SwiftPay company should be dealing with you, and to pass your enquiry to it
  • to work out which hardware and processing suits your business, and to price it
  • to prepare and submit a merchant application to Clover/Fiserv or Nuvei, and to answer the questions they ask while assessing it
  • to order, deliver, install and configure your terminals
  • to provide support, handle warranty and repair, and manage returns
  • to run the referral partner programme and pay referrals
  • to send you service messages — delivery and appointment notices, support replies, safety and security notices, and changes to terms
  • to send you marketing where you have asked for it, or where the law otherwise allows it and you have not opted out
  • to keep our business records for tax, accounting, warranty and dispute purposes
  • to keep the website and our systems secure, and to prevent fraud and misuse
  • to meet our legal obligations and the obligations we owe our partners under our ISO agreements
  • to understand which pages of the site are useful, so we can improve it

In Australia, the Australian SwiftPay company handles personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We tell you the purpose at or before the point we collect, and we use the information for that purpose, for a related purpose you would reasonably expect, with your consent, or where the law requires or authorises it.

In Canada, the Canadian SwiftPay company relies on your consent, as PIPEDA requires. Consent is express where the information is sensitive or where the use falls outside what you would reasonably expect. For straightforward, non-sensitive things — answering the enquiry you sent us — it can be implied from the fact that you sent it. You can withdraw consent at any time, on reasonable notice, and we will tell you what that means for the service you have asked for.

In the United States there is no single federal privacy law. What binds the US SwiftPay company is the notice we give you on this page, the choices we offer, and the obligation to keep both. So we have written this policy to describe what we actually do, and we update it before we change anything material rather than afterwards.

04Cookies and similar technologies

Cookies are small files a website stores on your device. Pixels, tags and local storage do similar jobs. Together they let a site remember your choices, count visitors and, in some cases, let another company see that you visited.

There is one website for all three markets, and the company that operates it — Swift Pay AUS Pty Ltd — sets and controls the cookies on it, whichever country you are visiting from.

We group them into three:

  • Strictly necessary — these make the site work, keep it secure, and remember the privacy choice you made on the banner. They are always on, and we do not need your consent for them.
  • Analytics and performance — these tell us how many people visit, which pages they read and where they came from. They do not tell us who you are.
  • Advertising and cross-site tracking — these would let a third party recognise you across other websites. They are off unless you turn them on.

Anything that is not strictly necessary stays switched off until you agree to it. Rejecting takes the same number of clicks as accepting, and the reject option is as prominent as the accept option. You can change your mind at any time using the Change your cookie choices button on our cookie policy page, and withdrawing is as easy as agreeing was.

Our separate cookie policy names every optional tag we use — Google Analytics 4 and the Meta pixel — with what each collects, who provides it, how long its cookies last and which country the provider is in. If you want the detail, that is where it lives.

Some browsers send a "Do Not Track" signal. There is no agreed industry standard for how a website should respond to it, and we do not respond to it separately. We do honour the Global Privacy Control signal — see the California section for how that works and what we treat it as meaning. Our cookie controls and Global Privacy Control are the two ways to tell us your preference, and we apply either without asking you to create an account or log in.

We are careful about third-party scripts that could see what you type into a form, such as chat widgets or session-recording tools. Where we use anything of that kind, it is named in the cookie policy and it loads only after you have made a choice.

The website can load Google Analytics 4 and the Meta pixel, each only after you have agreed to that category. The Meta pixel amounts to sharing for cross-context behavioural advertising under California law; the cookie policy sets out both tags in detail and carries the control that turns them off.

05Who we give it to — and what we never do with it

We do not sell your personal information. We do not hand your details to anyone for their own direct marketing. And we do not exchange it for money or anything else of value.

We do disclose it, for the reasons below:

  • The other SwiftPay companies — the SwiftPay companies in Australia, the United States and Canada share information with each other, for the reasons set out in the next section.
  • Clover and Fiserv — to submit and progress a merchant application, set up your account, order and configure hardware, and resolve support cases.
  • Nuvei — for the same reasons, where you are on a Nuvei facility.
  • Service providers who help us run the business, under contract — website hosting, our customer relationship and email systems, support ticketing, telephony and messaging, analytics, and accounting.
  • Professional advisers — lawyers, accountants, auditors and insurers, all bound by confidentiality, and only where there is a reason.
  • Law enforcement, regulators and courts — where the law requires or authorises it, or where we need to establish or defend a legal claim.
  • A buyer or successor — if any of the SwiftPay companies is ever sold or restructured, under confidentiality obligations, and we would tell you if that changed how your information is handled.
  • Google and Meta — only if you have agreed to the analytics or advertising cookie categories. Those tags send usage and advertising data to Google LLC and Meta Platforms, Inc., who act for their own purposes as well as ours. Nothing is sent before you agree, and withdrawing stops it. See the cookie policy.
  • Anyone else you ask us to.

Everyone acting for us is bound by contract to use the information only for what we have asked them to do, keep it confidential and secure, not use it for their own purposes, tell us immediately about a security problem, and return or destroy it when the work ends.

If a referral partner introduced you to us, we may confirm the status of your application to them — enough to account for the referral, and no more.

You can ask us who we have given your information to. We will tell you the categories of recipient, and where we can identify them, the specific organisations. Just email us.

06The three SwiftPay companies, and what passes between them

This is the part that is easy to miss, so we set it out plainly. SwiftPay is not one company with three offices. It is three separate companies that share a brand and this website. In privacy law each one is a separate organisation, and information moving from one to another is a disclosure to a different company — not an internal filing move.

Information passes between them for these reasons, and no others:

  • An enquiry arrives through this website before we know which country you are in, and has to be passed to the SwiftPay company for your market.
  • You approach one SwiftPay company about trading in another country, and it hands the enquiry over.
  • One company provides shared services to another — the customer relationship system, support ticketing, email, accounts, and back-office help.
  • Group reporting, auditing, insurance and legal advice, where the information is needed for it.
  • Handling a security incident that affects more than one company.

Each company remains responsible for the information it holds, under the law of its own country. The company that gave the information away does not stop being responsible either — see the next section, on information that crosses borders, for what that means in Australia in particular. The SwiftPay companies have a written agreement between them setting the standard each must apply to the others' information, what it may be used for, how it must be kept secure, and how quickly an incident must be reported back.

For readers in the United States: passing your information between the SwiftPay companies is not a "sale" and is not "sharing for cross-context behavioural advertising" under California law. No money and nothing else of value changes hands for it, and it is never used to aim advertising at you on other companies' websites. It is not something you need to opt out of — we do not sell your information to anyone, inside the group or outside it.

If you are not sure which SwiftPay company holds your information, you do not have to work it out. Email support@swiftpaytoday.com, tell us which country you are in, and we will route your request to the right one and tell you which one it was.

07Information that crosses borders

We operate in three countries through three companies, and our partners and suppliers operate internationally, so your information will often be handled outside the country you are in. You should know what that means in practice: while your information is in another country it is subject to that country's laws, it can be reached by that country's courts, law enforcement and national security agencies, and the privacy regulator where you live may have limited reach over what happens to it there.

Your information may go to any of these:

  • The other SwiftPay companies, in Australia, the United States and Canada, for the reasons set out in the section above.
  • Clover/Fiserv and Nuvei, which operate across multiple countries, where a merchant application, an account or a support case requires it.
  • Cloudflare, which serves this website and runs the enquiry form. Cloudflare is a United States company operating a global network, and the form runs at whichever of its locations is closest to you — so that step can take place in any country it operates in.
  • SendGrid, part of Twilio, which carries the enquiry email from the website to us. It is a United States company and the message passes through its systems in transit.
  • Google, which holds the enquiry emails once they arrive, in Google Workspace. Google offers the United States or Europe for data at rest and does not offer Australia, so those emails are held outside Australia wherever you sent them from.
  • Our own business systems — the customer relationship system, ticketing and accounting — which are run for us on servers in Australia.

It is worth saying plainly how little of this involves the website itself. These pages are static files, and the enquiry form does not write to any database — it checks that you are not a bot, sends one email, and keeps no copy of what you typed. Everything we hold, we hold in the mailbox and the business systems described above, not here.

Before we send personal information overseas we take steps that are reasonable in the circumstances to see that it is handled to the same standard we are held to. In practice that means written contracts requiring handling equivalent to the standard that applies where you are, limits on what the recipient may use it for, the same terms flowing down to their subcontractors, security requirements, and prompt notice to us of any incident. The agreement between the three SwiftPay companies does the same job for information passing between us.

If you are in Australia. Sending your information to the SwiftPay company in the United States or Canada is a disclosure to an overseas recipient, and Australian Privacy Principle 8 applies to it. Being part of the same group does not change that — the other SwiftPay companies are separate legal entities, and they are treated as overseas recipients like anyone else. So Swift Pay AUS Pty Ltd (ABN 49 683 708 938) takes reasonable steps to ensure they handle your information in line with the Australian Privacy Principles, including through the written agreement between the SwiftPay companies. And if an overseas SwiftPay company, a partner or a supplier mishandles information the Australian company disclosed to them, the Australian company is accountable to you for it under the Privacy Act, as though it had done it itself.

If you are in Canada. The SwiftPay companies in Australia and the United States, and our processing partners, may store or handle your information outside Canada. This means your information may be subject to the laws of those countries, and may be accessible to the courts, law enforcement agencies and national security authorities there. Swiftpay CAD Inc. (corporation number 1799191-6) stays accountable for it and uses written agreements to keep the protection comparable to what applies in Canada.

If you are in Quebec. Before we communicate personal information outside Quebec — including to another province, to the Australian or US SwiftPay company, or to Clover/Fiserv or Nuvei — we carry out and record an assessment of the transfer, as Law 25 requires. It looks at how sensitive the information is, what it will be used for, the protections in place including contractual ones, and the legal framework of the destination. The transfer only goes ahead if the assessment shows the information will get adequate protection, and it is covered by a written agreement that takes the assessment into account.

If you are in the United States. Your information may be held or handled by the SwiftPay companies in Australia and Canada and by our partners and suppliers in other countries, under the same contractual standard.

08How we store and protect it

Your information is held in our business systems — email, our customer relationship system, support ticketing and accounting — which are run for us by service providers under contract, and which the SwiftPay companies share. Some paperwork, such as signed forms and delivery dockets, is held at the office of the SwiftPay company that dealt with you.

We take reasonable steps to protect it from misuse, interference, loss and unauthorised access, and those steps are both technical and organisational:

  • information is encrypted while in transit to and from this website and our systems
  • access is limited to the people who need it to do their job, with individual accounts rather than shared logins
  • multi-factor authentication is used on the systems that support it
  • we check a supplier's security before we use them, and we put security terms in the contract
  • our staff are trained on how to handle merchant information and what not to send by email
  • the three SwiftPay companies keep a single written plan for responding to a security incident, so that one company's incident is handled properly for all of them
  • we destroy or de-identify information securely when we no longer need it

What we do not hold matters just as much. This website does not process card payments and does not store cardholder data. We do not hold full card numbers, card security codes or PINs. Card transactions run on the PCI DSS certified platforms operated by our partners. No SwiftPay company itself holds PCI DSS certification, and none needs it for what this website does — we say so plainly rather than imply otherwise.

No system can be guaranteed completely secure, and we do not claim ours is. If you think there is a security problem with this site or with information you have given us, email support@swiftpaytoday.com and tell us. Please do not send card numbers, passwords or identity documents by ordinary email — ask us and we will give you a safer way.

09How long we keep it

We keep personal information only for as long as we need it, and then we destroy it or de-identify it. We have not put a fixed number of years on this page, because the honest answer depends on what the information is and on the record-keeping rules that apply in your country.

  • An enquiry that does not go anywhere: we keep it while we could reasonably still be dealing with it, and then for the period the tax and financial-records obligations of your country require.
  • A merchant or referral partner relationship: we keep the records for as long as we have a business relationship with you, and then for the period the tax, financial-records and other legal obligations that apply to your SwiftPay company require.
  • Hardware, warranty and support records: we keep these while the warranty runs and while a dispute could still reasonably arise.
  • Marketing consents and unsubscribes: we keep a record of when and how you agreed, and of any unsubscribe, for as long as we run marketing — we have to be able to prove consent, and an unsubscribe has to be honoured permanently.
  • Security incident records: Canadian law requires a record of every breach of security safeguards to be kept for 24 months from the day we determine it occurred, and Quebec law sets a minimum period for entries in the incident register. Those periods are set by law, not by us.

Where a law, a court, or a regulator requires us to keep something longer, we keep it for that period and no longer. Backup copies may persist for a short time after deletion until the backup cycle overwrites them.

10Your rights, and how to use them

Rather than work out which law applies to you before we help you, the SwiftPay companies offer the same core rights to everyone who contacts us, wherever you are:

  • ask what personal information we hold about you, and get a copy of it
  • ask us to correct anything that is wrong, out of date or incomplete
  • ask us to delete it, where we are not required to keep it
  • ask us who we have disclosed it to
  • ask us to stop sending you marketing
  • complain to us, and then to a regulator if we do not sort it out

To make a request, email support@swiftpaytoday.com with "Privacy request" in the subject line. Tell us what you want, tell us which country you are in, and give us enough detail to find your records. Telling us your country is not a hurdle — it is how we know which SwiftPay company holds your information and which law we have to answer under. If you do not know, say so and we will find out.

We may need to confirm who you are before we act — we will ask for as little as possible to do that, and we will not use what you give us for identification for anything else.

We do not charge for making a request, and we do not currently charge for giving you access. If a request is unusually large and a reasonable charge for supplying it applies, we will tell you before we do any work, and you can withdraw the request.

We aim to respond within 30 days. Some laws allow longer — 45 days in Alberta and in several US states — and most allow an extension for a complex request. If we need more time, we will tell you before the 30 days is up, explain why, and say how long we expect to take.

You can use an authorised agent or representative to make a request for you. We will need proof that you have authorised them.

We will not treat you differently for exercising any of these rights. No worse pricing, no withheld quote, no slower support.

If we refuse a request, we will tell you why in writing, tell you how to ask us to reconsider, and tell you which regulator you can take it to.

11If you are in Australia

The SwiftPay company responsible for your personal information in Australia is Swift Pay AUS Pty Ltd (ABN 49 683 708 938, ACN 683 708 938), of 5 Charles Smith Avenue, Bungarribee, New South Wales 2767, Australia. It is supervised by the Office of the Australian Information Commissioner, and it handles personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Your rights under those principles are:

  • to be told, at or before we collect, who we are, why we are collecting, who we usually give the information to, what happens if you do not give it, and whether it goes overseas and to which countries
  • to deal with us anonymously or under a pseudonym, where that is lawful and practical
  • to access the personal information we hold about you (APP 12) — we aim to respond within 30 days
  • to have information corrected if it is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13), free of charge, and to ask us to tell anyone we previously disclosed it to about the correction
  • to opt out of direct marketing, and to ask us where we got your details from (APP 7.6) — both free, and actioned within a reasonable period
  • to ask us about our overseas disclosures, including to the SwiftPay companies in the United States and Canada
  • to complain to us, and then to the Office of the Australian Information Commissioner

The Australian company stays accountable to you for information it discloses overseas — including to the other SwiftPay companies — as explained in the cross-border section above. You do not have to chase an overseas company to get an answer.

How to complain: email support@swiftpaytoday.com with "Privacy complaint — Australia" in the subject. We will acknowledge it, look into it, and respond in writing within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992. The OAIC will normally expect you to give us a chance to fix it first, and generally expects a complaint within 12 months of you becoming aware of the issue.

New Australian rules about automated decision-making take effect on 10 December 2026. If we ever use a computer program to make, or to substantially help make, a decision that could significantly affect your rights or interests, we will say so on this page — including what kinds of information it uses and what kinds of decisions it makes.

12If you are in Canada

The SwiftPay company responsible for your personal information in Canada is Swiftpay CAD Inc. (Canada corporation number 1799191-6, business number 709883037), of 43 Munch Avenue, Cambridge, Ontario N1R 0C2, Canada. The Personal Information Protection and Electronic Documents Act (PIPEDA) applies to it, and it is supervised by the Office of the Privacy Commissioner of Canada. If you are in Quebec, Law 25 also applies and the Commission d'accès à l'information supervises it. If you are in Alberta or British Columbia, that province's Personal Information Protection Act may apply instead of PIPEDA to parts of what we do, and that province's Information and Privacy Commissioner supervises it.

The Canadian company has a designated individual accountable for its compliance with PIPEDA. For Quebec, the person in charge of the protection of personal information at Swiftpay CAD Inc. (corporation number 1799191-6) is the President, contactable at support@swiftpaytoday.com and at 43 Munch Avenue, Cambridge, Ontario N1R 0C2, Canada. Send Canadian privacy requests and complaints there. Your rights are:

  • to be told the purposes before or at the time we collect
  • to give, refuse or withdraw consent — withdrawal on reasonable notice, and we will tell you what it means for the service you have asked for
  • not to be required to consent to anything beyond what is necessary to provide what you have asked for
  • to access your personal information, and to be told how it has been used and who it has been disclosed to, including where it has gone to the SwiftPay companies in Australia and the United States — we aim to respond within 30 days
  • to challenge the accuracy and completeness of it and have it corrected
  • if you are in Quebec: to have information deleted or de-indexed where collecting, communicating or keeping it is not authorised by law
  • if you are in Quebec: to receive the computerised personal information you gave us in a structured, commonly used technological format, or to have us send it directly to another body authorised to collect it — this does not extend to information we created or inferred ourselves
  • if you are in Quebec: to be told when a decision about you is based only on automated processing, to be told what information was used, the reasons and the main factors, and to make your case to a person who can review it
  • to be told about the communication of your information outside Quebec

How to complain: raise it with the Canadian company's designated person first, at support@swiftpaytoday.com with "Privacy complaint — Canada" in the subject. If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, generally within 12 months of becoming aware of the issue. Quebec residents can apply to the Commission d'accès à l'information for a review — including if we refuse a request, or if we do not answer within 30 days, which is treated as a refusal. Alberta and British Columbia residents can complain to their provincial Information and Privacy Commissioner.

13If you are in the United States

The SwiftPay company responsible for your personal information in the United States is SwiftPay USA Inc., a Delaware corporation, of 210 Richards Avenue, Piscataway, New Jersey 08854, United States. There is no single federal privacy law and no single federal privacy regulator in the United States. Rights come from state laws, they are enforced by state attorneys-general, and in California also by the California Privacy Protection Agency. Each state sets its own thresholds for which businesses are covered. Rather than ask you to work out whether your state's law reaches us, we offer the same rights to everyone in the US:

  • to know what personal information we have collected about you, where we got it, why, and who we disclosed it to
  • to get a copy of it, in a portable format where that makes sense
  • to correct anything inaccurate
  • to delete it, where we are not required to keep it
  • to opt out of any sale of personal information, any sharing for targeted advertising, and any profiling that would produce a legal or similarly significant effect
  • not to be discriminated against for asking

We do not sell your personal information — not to anyone, and not to the other SwiftPay companies, which US law treats as part of the same business rather than as outside parties. This is also our answer for Rhode Island, whose law asks a website operator to identify the third parties it sells to: there are none, because we do not sell. If we ever used advertising or analytics tags that count as a "sale" or a "share" under your state's law, our cookie controls would let you turn them off, and we would say so plainly on this page. We honour the Global Privacy Control signal automatically either way.

Several state laws give you a right to appeal if we refuse a request. If we say no, you can appeal by replying to our decision — we will look at it again and answer you within 60 days. If we still refuse, we will give you the contact details and complaint form for your state attorney-general so you can take it further.

To complain, contact us first at support@swiftpaytoday.com with "Privacy complaint — United States" in the subject, then the consumer protection division of your state attorney-general if we do not resolve it. Californians have two additional routes, set out in the next section.

14California privacy rights

This section is for California residents. The SwiftPay company responsible for your personal information is SwiftPay USA Inc., a Delaware corporation, of 210 Richards Avenue, Piscataway, New Jersey 08854, United States. The three SwiftPay companies are separately owned, and in law they are three businesses rather than one. We run these rights as though they were one anyway — they work the same way whichever SwiftPay company happens to hold your information, and you only have to ask once.

We offer these rights whether or not we meet the revenue and volume thresholds that make a business subject to the California Consumer Privacy Act, because they are straightforward for us to honour and you should not have to guess. California is also the only US state whose law covers business contact information, which is most of what we collect.

The categories of personal information we collect, where they come from, why, and who they go to:

  • Identifiers — name, business name, business address, email address, phone number, IP address and online identifiers. Collected from you, from our partners, from anyone who referred you, and sometimes from another SwiftPay company that received your enquiry first. Used to answer you, quote, apply on your behalf and support you. Disclosed to the other SwiftPay companies, to Clover/Fiserv, to Nuvei and to our service providers.
  • Commercial information — the hardware and processing you enquired about or bought, quotes, orders and service history. Collected from you and from our partners. Used to supply and support what you ordered.
  • Internet or network activity — pages you viewed, the referring page, your device and browser, and how you interacted with our emails. Collected automatically. Used to keep the site working and to see which pages are useful.
  • Geolocation data — approximate location from your IP address, and the area you told us you trade in. We do not collect precise geolocation.
  • Professional or employment-related information — your role at the business, the type of business, and the trading information you give us. Collected from you. Used to assess what suits you and to support an application.
  • Records described in Cal. Civ. Code § 1798.80 — name, address and phone number, and, where a merchant application requires it, identity document details and the bank account for your settlements. Collected from you. Used only to submit and support that application.
  • Inferences — limited to which products are likely to suit your business, drawn from what you have told us.

We do not seek sensitive personal information. Where a merchant application requires a government identifier or a settlement account number, we use it only for the permitted purposes — providing the service you asked for, security, and meeting our legal obligations — and never to work out characteristics about you. You can still ask us to limit its use and we will honour that request.

We do not sell personal information for money. We DO share it for cross-context behavioural advertising in one specific way: if you agree to the advertising category, the Meta pixel tells Meta which pages you viewed, and Meta may match that to an account you hold with them. That is "sharing" as California defines it. Passing information between the SwiftPay companies is neither a sale nor sharing, because those companies are not outside parties under California law. We do not sell or share the personal information of anyone we know to be under 16. You can stop the sharing at any time with the Change your cookie choices button on our cookie policy page, which is our Do Not Sell or Share My Personal Information control; we also honour Global Privacy Control signals sent by your browser.

Global Privacy Control: this is a signal your browser or a browser extension can send on your behalf, saying you do not want your personal information sold or shared. We detect it and treat it as a valid opt-out request, automatically, site-wide, with no login, no fee and no change to how the site works for you. It applies per browser and per device, so you would need to turn it on in each browser you use.

Shine the Light (Cal. Civ. Code § 1798.83): we do not disclose personal information to third parties for those third parties' own direct marketing purposes. So there is nothing for us to list — but you are welcome to ask us once a year, free of charge, at support@swiftpaytoday.com.

Your California rights are: to know and access what we have collected about you, including a copy — the last 12 months by default, and older information on request; to correct it; to delete it; to opt out of sale and sharing; to limit the use of sensitive personal information; to use an authorised agent; and not to be discriminated against for exercising any of them. We will confirm receipt of your request within 10 business days and give you a substantive answer within 45 days, extendable once by a further 45 days if we tell you why.

To complain, contact us first at support@swiftpaytoday.com. If we do not resolve it, you can complain to the California Privacy Protection Agency, or to the California Attorney General at oag.ca.gov/report.

15Marketing messages, and how to stop them

The three SwiftPay companies run one standard across all three countries: we ask before we add you to a marketing list. Australian and Canadian law require consent before we send marketing email or SMS. US law would let us email first and give you an opt-out instead — we do not use that latitude. Asking first is simpler to run and fairer to you.

  • Marketing consent is a separate, unticked box on our forms. We never pre-tick it and we never bundle it into acceptance of terms.
  • You can ask for a quote, a demo or a call back without agreeing to marketing. The form works either way.
  • We record when you agreed, how, on which page, and the exact wording you were shown — because in Australia and Canada it is our job to prove consent, not yours to disprove it.

Service messages are different from marketing. Order confirmations, delivery and appointment notices, support replies, safety and security notices, and changes to terms come to you because you are a customer, and you will get them whether or not you have opted into marketing. We do not staple offers onto them.

Every marketing message we send names the SwiftPay company sending it, gives you a postal address, an email address and a phone number for it, and carries an unsubscribe link that works, is free, needs no login and asks for nothing beyond what identifies you.

When you unsubscribe, we action it within five working days — that is the strictest of the three deadlines that apply to us (Australia's Spam Act) and we apply it everywhere, rather than taking the ten business days US and Canadian law allow. The three SwiftPay companies keep one shared suppression list across Australia, the United States and Canada and across every channel, so unsubscribing from one company stops messages from all three. Unsubscribe links keep working for at least 60 days after a message is sent, and our contact details stay valid for at least that long.

Calls and texts: if you asked us to call you, we will. If you would rather we did not, tell us and we will stop. In Australia we check calling lists against the Do Not Call Register unless you have asked us to call or an exemption applies. In the United States we ask for separate, written consent before sending marketing SMS or using automated or prerecorded calls, and you can withdraw that consent at any time by any reasonable means.

Two country-specific points. In Australia you can ask us where we got your details, free of charge, and we will tell you within a reasonable period. In Canada, an enquiry you send us gives us six months of implied consent to follow up, and a purchase or contract gives two years — we include an unsubscribe link in every commercial message regardless.

To stop all marketing from every SwiftPay company: use the unsubscribe link in any message, or email support@swiftpaytoday.com with "Unsubscribe" in the subject line.

16If something goes wrong: data breach notification

The three SwiftPay companies keep one written plan for responding to a security incident, and a register of incidents. If one happens we contain it, work out what happened and whose information is involved, take what steps we can to remove or reduce the risk of harm, and record what we did and why.

Because SwiftPay operates through three separate companies sharing systems and information, one incident can affect more than one of them. When that happens, more than one SwiftPay company may have to notify a regulator about the same event. We coordinate between ourselves so that you are told once, clearly, and are not contacted twice about the same thing.

When we have to tell you, we tell you. The rules differ by country, and we follow whichever applies to you:

  • Australia — where a breach is likely to result in serious harm, the Australian SwiftPay company notifies the people affected and the Office of the Australian Information Commissioner, as Part IIIC of the Privacy Act requires. Where we suspect a breach we complete our assessment within 30 days. This applies even where the incident happened at another SwiftPay company or at a supplier holding information the Australian company disclosed to them. If we cannot notify people directly, we publish a statement on this website and take reasonable steps to publicise it.
  • Canada — where a breach creates a real risk of significant harm, the Canadian SwiftPay company reports it to the Office of the Privacy Commissioner of Canada and notifies the people affected as soon as feasible, and tells any other organisation that could help reduce the harm. It does this for information under its control, wherever the incident happened. We keep a record of every breach for 24 months, as PIPEDA requires.
  • Quebec — where a confidentiality incident presents a risk of serious injury, we promptly notify the Commission d'accès à l'information and the people affected, and we keep a register of every incident whether or not it meets that threshold.
  • Alberta — we report to the Alberta Information and Privacy Commissioner without unreasonable delay where there is a real risk of significant harm, and notify individuals as the Commissioner directs.
  • United States — which law applies is set by where you live, not by where the SwiftPay company is, and each state sets its own deadline. We notify the people affected and the relevant state regulators within the deadlines that apply.

Whatever the jurisdiction, our notice will tell you what happened and when, what kinds of information were involved, what we have done about it, what we suggest you do, and how to reach us with questions.

We have not put a fixed number of hours on this page, because the deadlines genuinely differ by country and by state and we would rather follow the one that applies to you than publish a number we cannot keep everywhere. Where our agreements with Clover/Fiserv or Nuvei require us to tell them, we do that too.

If you think there has been a security problem involving your information, tell us at support@swiftpaytoday.com.

17Children

This is a business website. The SwiftPay companies sell payment hardware and merchant processing to businesses, and the site is not directed at children.

We do not knowingly collect personal information from anyone under 16. If we find out that we have, we delete it. We do not sell or share personal information about anyone under 16 — we do not sell personal information at all.

If you are a parent or guardian and you think your child has given us personal information, email support@swiftpaytoday.com and we will remove it.

18Changes to this policy

This is one policy for all three SwiftPay companies. We update it when our practices, our tools, the arrangements between the three companies or the law change. The date at the top of the page tells you when it was last updated, and we review it at least once a year even when nothing has changed.

Where a change is material — a new purpose, a new category of recipient, a new country your information goes to, or a change to which SwiftPay company is responsible for you — we will say so clearly on this page before the change takes effect, and where the law requires your consent we will ask for it rather than assume it. We will not apply a materially new use to information we already hold without telling you first.

19How to contact us, and how to escalate

One email address is the front door for all three SwiftPay companies. For any privacy question, for an access, correction or deletion request, to opt out of marketing, or to make a complaint, email support@swiftpaytoday.com. Put "Privacy request" or "Privacy complaint" in the subject line, and tell us which country you are in so we can send it to the right SwiftPay company.

  • Email, for everything including privacy requests, in every country: support@swiftpaytoday.com
  • Australia — Swift Pay AUS Pty Ltd (ABN 49 683 708 938), 5 Charles Smith Avenue, Bungarribee, New South Wales 2767, Australia. Phone +61 466 230 370.
  • United States — SwiftPay USA Inc., of 210 Richards Avenue, Piscataway, New Jersey 08854, United States. Phone +1 404 910 8918.
  • Canada — Swiftpay CAD Inc., of 43 Munch Avenue, Cambridge, Ontario N1R 0C2, Canada. Phone +1 404 910 8918.
  • Quebec — the person in charge of the protection of personal information at Swiftpay CAD Inc. (corporation number 1799191-6) is the President, at support@swiftpaytoday.com and 43 Munch Avenue, Cambridge, Ontario N1R 0C2, Canada.

You do not need to know which company holds your information before you write to us. If you tell us your country, we will route your request and tell you which SwiftPay company is dealing with it. If you would rather write directly to one of them, the addresses above are where to send it.

When you complain to us we will acknowledge it, look into it properly, and respond to you in writing within 30 days. If we need longer we will tell you before the 30 days is up, explain why, and tell you when to expect an answer.

If we do not resolve it, take it further. Each SwiftPay company answers to the regulator in its own country. You do not need our permission to complain, and we will not treat you any differently for doing so:

  • Australia — Office of the Australian Information Commissioner, oaic.gov.au or 1300 363 992. The OAIC will normally want you to give us 30 days first, and generally expects a complaint within 12 months of you becoming aware of the issue.
  • Canada — Office of the Privacy Commissioner of Canada, priv.gc.ca. In Quebec, the Commission d'accès à l'information. In Alberta or British Columbia, that province's Information and Privacy Commissioner.
  • United States — the consumer protection division of your state attorney-general. California residents can also complain to the California Privacy Protection Agency, or to the California Attorney General at oag.ca.gov/report.

Questions about this page? Email support@swiftpaytoday.com. See also our privacy policy, cookie policy and terms of use.