Privacy policy

How MittoPay collects, uses, shares, and protects personal data when you use our website, dashboard, API, and payment services.

Effective September 10, 2026Questions: contact@mittopay.com

Who this policy covers

MittoPay is operated by Virentis Payment Corporation (Incorporation No. BC1592848), 205 - 50 Lonsdale Ave, Office #2243, North Vancouver, BC V7M 2E6, Canada. We are the organization accountable for personal information handled under this policy within the meaning of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA), and the controller where the GDPR or UK GDPR applies.

This policy applies to personal data we process about merchants and their staff who use the MittoPay dashboard and API, about visitors to mittopay.com, and about end customers whose payments pass through our platform. Where we process end-customer data on behalf of a merchant, the merchant is the controller and we act as processor under the terms of our agreement with them.

What we collect

Merchant account data

Company details, names and contact details of authorized users, identity and ownership documents required for KYB and AML checks, bank account details for settlement, and login credentials.

Transaction data

Payment amount, currency, timestamp, payment method, payer name and account or wallet identifier as provided by the payment network, merchant reference, IP address and device information used for fraud screening.

Website and usage data

Pages visited, browser type, approximate location from IP address, and the information you submit through our contact form (name, work email, company, message).

How we use it

  • To provide the services: routing, processing, settling, and reporting on payments.
  • To meet legal obligations: identity verification, sanctions screening, anti-money-laundering monitoring, and record keeping under the PCMLTFA and FINTRAC guidance.
  • To detect and prevent fraud and abuse through our risk engine.
  • To support you: responding to enquiries, incidents, and integration questions.
  • To improve the platform: aggregated analytics on performance and reliability.
  • To communicate: service notices, security alerts, and, with your consent where required, product updates.

We do not sell personal data and we do not use end-customer transaction data for advertising.

Under PIPEDA and PIPA we collect, use, and disclose personal information with consent, express or implied, except where the law permits or requires otherwise (for example, reporting to FINTRAC). Where the GDPR applies we rely on performance of a contract (providing the services), legal obligation (financial-crime and record-keeping laws), legitimate interests (security, fraud prevention, service improvement), and consent (marketing communications and non-essential cookies).

Who we share it with

  • Banking and payment partners that execute collections, currency conversion, and payouts.
  • Verification and screening providers used for KYB, AML, and sanctions checks.
  • Infrastructure and tooling vendors such as cloud hosting, email delivery, and analytics, bound by data-processing agreements.
  • Regulators, courts, and law enforcement, including FINTRAC, where we are legally required to disclose.
  • Successors in the event of a merger, acquisition, or restructuring, subject to this policy.

International transfers

We are based in Canada. Because we settle payments across borders, data may be processed in countries other than where it was collected, including Vietnam, Singapore, Thailand, Hong Kong, the European Union, and the United States. Where required we use recognised safeguards such as standard contractual clauses and transfer risk assessments, and we limit transfers to what is needed to execute the payment.

How long we keep it

Transaction and identity records are kept for at least five years after the end of the business relationship, as required by the PCMLTFA, and longer where accounting or tax law requires. Contact-form messages are kept for up to 24 months. Website analytics are aggregated or deleted within 14 months. We delete or anonymise data when it is no longer needed for the purposes above.

Your rights

Subject to local law you may request access to, correction of, or deletion of your personal data, object to or restrict certain processing, request portability, and withdraw consent where processing is based on consent. End customers should first contact the merchant they paid; we will support merchants in responding. Requests can be sent to contact@mittopay.com and we aim to respond within 30 days. You may also complain to the Office of the Privacy Commissioner of Canada, the Office of the Information and Privacy Commissioner for British Columbia, or your local data-protection authority.

Cookies

mittopay.com uses strictly necessary cookies to keep the site working and, where you consent, analytics cookies to understand how the site is used. The merchant dashboard uses session cookies for authentication. You can control non-essential cookies through your browser or our cookie settings.

Security

We protect personal data with encryption in transit and at rest, strict access controls, logging, and regular testing. Details are on our Security page. If we become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.

Changes and contact

We may update this policy as our services or the law change. The effective date at the top shows the current version; material changes will be notified by email or in the dashboard. Contact our privacy officer at contact@mittopay.com or by post to Virentis Payment Corporation, 205 - 50 Lonsdale Ave, Office #2243, North Vancouver, BC V7M 2E6, Canada.