Privacy policy

Draft. Have this reviewed before launch and fill in the controller details.

Who processes your data

SplitPay processes participant data on behalf of the merchant that created the group payment (the merchant is controller; SplitPay is processor). For merchant accounts, SplitPay is controller.

What we store

  • Merchants: email, business name, encrypted Mollie Connect tokens, webhook settings, API key hashes.
  • Participants: name, optional email, share amount, payment status, timestamps, preferred language. Payment links are stored as hashes; the raw link is only known to whoever holds it.
  • Payments: Mollie payment ids, amounts, statuses. We never see card or bank details; those go directly to Mollie.
  • Emails sent (recipient, type, time) for deduplication.

Why

To create and settle group payments, send payment links, reminders and confirmations, notify merchants, and prevent fraud and duplicate processing.

Retention

Group payment records are kept for as long as the merchant keeps the account, and at least as long as bookkeeping law requires (7 years in Belgium for payment records). Participant emails can be removed on request of the merchant.

Sub-processors

  • Mollie B.V., Netherlands (payment processing).
  • Supabase (database and authentication, Frankfurt, EU).
  • Vercel (application hosting, Frankfurt region for server functions).
  • Resend (transactional email, EU region Ireland).
  • Meta Platforms Ireland (WhatsApp messages), only when the merchant enables WhatsApp and a phone number was provided.
  • Upstash (rate limiting), when configured.

Your rights

Participants can ask the merchant to access, correct or delete their data; merchants can contact SplitPay to do so. You can complain to the Belgian Data Protection Authority.