Orchestrapay
Features
Coverage
Africa๐Ÿ‡ช๐Ÿ‡ฌ Egypt๐Ÿ‡ณ๐Ÿ‡ฌ Nigeria๐Ÿ‡ฐ๐Ÿ‡ช Kenya๐Ÿ‡จ๐Ÿ‡ฎ Cรดte d'Ivoire๐Ÿ‡ฌ๐Ÿ‡ญ Ghana๐Ÿ‡ฟ๐Ÿ‡ฆ South Africa๐Ÿ‡ช๐Ÿ‡น Ethiopia๐Ÿ‡จ๐Ÿ‡ฒ Cameroon๐Ÿ‡ธ๐Ÿ‡ณ Senegal๐Ÿ‡น๐Ÿ‡ฟ Tanzania๐Ÿ‡บ๐Ÿ‡ฌ Uganda๐Ÿ‡ท๐Ÿ‡ผ Rwanda
Middle East๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Arabia๐Ÿ‡ฆ๐Ÿ‡ช UAE๐Ÿ‡ถ๐Ÿ‡ฆ Qatar๐Ÿ‡ฐ๐Ÿ‡ผ Kuwait
Europe๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom๐Ÿ‡ซ๐Ÿ‡ท France๐Ÿ‡ฉ๐Ÿ‡ช Germany๐Ÿ‡ช๐Ÿ‡ธ Spain๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands๐Ÿ‡ต๐Ÿ‡ฑ Poland๐Ÿ‡ธ๐Ÿ‡ช Sweden๐Ÿ‡ณ๐Ÿ‡ด Norway
North America๐Ÿ‡บ๐Ÿ‡ธ United States๐Ÿ‡จ๐Ÿ‡ฆ Canada๐Ÿ‡ฒ๐Ÿ‡ฝ Mexico
FAQDocs
Sign InGet Started

Legal

Privacy Policy

Effective date: 10 August 2026

This Privacy Policy explains how Orchestrapay ("Orchestrapay", "we", "us") collects, uses, shares and protects personal data. Orchestrapay operates a payment orchestration platform that lets merchants connect to multiple payment gateways and methods through a single integration. Our mailing address is 600 California St, San Francisco, CA, USA.

1. Our role: controller and processor

For the personal data of our own business users (the merchant representatives who create and administer Orchestrapay accounts) and visitors to our website, Orchestrapay acts as a data controller. When we process payment and cardholder data to deliver payment services on behalf of a merchant, Orchestrapay acts as a data processor (or service provider), and the merchant is the controller responsible for the end customer relationship. This policy describes both roles; where we act as a processor, our handling is also governed by our agreement with the merchant.

2. Data we collect

  • Business account data โ€” names, work email addresses, phone numbers, business details and login credentials of the merchant representatives who use the Orchestrapay dashboard.
  • Payment and transaction data โ€” processed on behalf of merchants to route and settle payments. This can include the payment card primary account number (PAN), card brand, expiry, a token, the last four digits, transaction amounts, timestamps and gateway references. We handle this data as a payment service provider under the PCI DSS (see section 5).
  • End-customer data provided by merchants โ€” where a merchant sends us a customer's name, email, billing address or similar to complete a transaction, we process it on the merchant's behalf and under their instructions.
  • Technical and usage data โ€” IP address, device and browser information, and log/telemetry data generated when you use our website, dashboard or APIs, used for security, fraud prevention and service operation.

3. How we use personal data

We use personal data to:

  • provide, operate and secure the payment orchestration platform and route transactions to the appropriate gateways;
  • authenticate users, manage accounts and provide support;
  • detect, prevent and investigate fraud, abuse and security incidents;
  • comply with legal, regulatory and payment-network obligations (including anti-money-laundering and PCI DSS requirements); and
  • improve and develop our services.

Where the EU/UK GDPR applies, our legal bases are performance of a contract, compliance with a legal obligation, and our legitimate interests in operating and securing the service (balanced against your rights), and consent where required (for example, certain cookies).

4. Sharing and sub-processors

We share personal data only as needed to deliver the service and never sell it. Recipients include:

  • Payment gateways and acquirers (for example Stripe and other licensed processors) to execute transactions the merchant routes through us;
  • Cloud and infrastructure providers โ€” Amazon Web Services (hosting of the cardholder data environment), Cloudflare (DNS/edge), Vercel (hosting of the checkout and marketing pages);
  • Operational tooling โ€” providers that support secrets management, monitoring and communications under confidentiality obligations;
  • Authorities and advisors where required by law, regulation or to protect our rights.

Our sub-processors are bound by contractual data-protection and security obligations. A current list is available on request.

5. Cardholder data and PCI DSS

Orchestrapay is assessed against the Payment Card Industry Data Security Standard (PCI DSS). Cardholder data is encrypted in transit (TLS 1.2 or higher) and at rest, access is restricted on a least-privilege basis with multi-factor authentication, and all access is logged. Sensitive authentication data (such as the card verification value) is not retained after authorization. We process cardholder data solely to provide payment services and in line with the applicable payment-brand rules.

6. International transfers

We may process and store personal data in countries other than the one in which you are located. Where personal data is transferred across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and equivalent mechanisms, together with technical measures such as encryption.

7. Data retention

We retain personal data only as long as necessary for the purposes described here and to meet legal, tax, accounting and payment-network record-keeping obligations, after which it is deleted or irreversibly anonymized. Transaction and audit records are retained for the periods required by applicable law and PCI DSS.

8. Security

We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the data, including encryption, network segmentation, access controls, continuous monitoring, vulnerability management and an incident response program. No method of transmission or storage is completely secure, but we work to protect personal data and to notify affected parties and regulators of incidents as required by law.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. Residents of the EU/UK (GDPR), California (CCPA/CPRA) and the UAE (PDPL), among others, have such rights. Where we process data on a merchant's behalf (processor role), please direct requests to that merchant; we will assist them as required. To exercise rights for data we control, contact us using section 12. You also have the right to complain to your local data-protection authority.

10. Cookies

Our website and dashboard use strictly necessary cookies to operate and secure the service, and may use analytics cookies to understand usage. You can control non-essential cookies through your browser settings and any cookie controls we provide.

11. Children

Our services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children.

12. Contact us

For questions about this policy or to exercise your rights, contact our privacy team at privacy@orchestrapay.com, or write to Orchestrapay, 600 California St, San Francisco, CA, USA.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version here and update the effective date above; material changes will be communicated as required by law.

Orchestrapay
One Central 8th and 9th Floor - Trade Center Second - Dubai
PCIโœ“DSS
Company
Contact UsPrivacy Policy
Features
Smart Routing EngineEmbedded Payment Forms
Coverage
Africa๐Ÿ‡ช๐Ÿ‡ฌ Egypt๐Ÿ‡ณ๐Ÿ‡ฌ Nigeria๐Ÿ‡ฐ๐Ÿ‡ช Kenya๐Ÿ‡จ๐Ÿ‡ฎ Cรดte d'Ivoire๐Ÿ‡ฌ๐Ÿ‡ญ Ghana๐Ÿ‡ฟ๐Ÿ‡ฆ South Africa๐Ÿ‡ช๐Ÿ‡น Ethiopia๐Ÿ‡จ๐Ÿ‡ฒ Cameroon๐Ÿ‡ธ๐Ÿ‡ณ Senegal๐Ÿ‡น๐Ÿ‡ฟ Tanzania๐Ÿ‡บ๐Ÿ‡ฌ Uganda๐Ÿ‡ท๐Ÿ‡ผ RwandaMiddle East๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Arabia๐Ÿ‡ฆ๐Ÿ‡ช UAE๐Ÿ‡ถ๐Ÿ‡ฆ Qatar๐Ÿ‡ฐ๐Ÿ‡ผ KuwaitEurope๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom๐Ÿ‡ซ๐Ÿ‡ท France๐Ÿ‡ฉ๐Ÿ‡ช Germany๐Ÿ‡ช๐Ÿ‡ธ Spain๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands๐Ÿ‡ต๐Ÿ‡ฑ Poland๐Ÿ‡ธ๐Ÿ‡ช Sweden๐Ÿ‡ณ๐Ÿ‡ด NorwayNorth America๐Ÿ‡บ๐Ÿ‡ธ United States๐Ÿ‡จ๐Ÿ‡ฆ Canada๐Ÿ‡ฒ๐Ÿ‡ฝ Mexico
ยฉ 2025 All Rights Reserved
Privacy Policy