Data Protection at Pay-E
Last updated: May 2026 · Pending legal review.
Pay-E is built around a simple promise: your customer data is yours, and we handle it like it matters. This page explains how we live up to that — in plain English. It complements (and does not replace) our Privacy Policy and Terms of Service.
What we hold for you
When your staff take a phone order, Pay-E stores:
- The customer's mobile number and (optionally) name.
- The line items, quantities, totals, and any customer note.
- Whether the payment link was sent, opened, paid, or expired, and the timestamps for each event.
- The status of the order (awaiting payment, paid, preparing, ready, completed).
We do not store card numbers. Card details are entered directly into Stripe's hosted Checkout — Pay-E never sees them.
How long we keep it
- Order records, invoices, totals: 7 years (Australian Tax Office requirement).
- Customer phone numbers: 7 years, scoped to that merchant only.
- Server logs and error traces: 90 days.
- Cancelled-account data: 30 days after termination, then deleted (subject to legal retention requirements).
If you'd like a customer record removed sooner, email privacy@pay-e.com.au and we'll handle it within 30 days, subject to any conflicting legal retention requirements.
Where the data lives
All Pay-E operational data (orders, customers, payment status) is stored on managed cloud infrastructure with encryption at rest and TLS in transit. Daily backups are retained for 30 days.
Stripe processes payment data under Stripe's Privacy Policy. Twilio routes SMS through standard A2P routes — Australian numbers route through Australian carriers where possible.
Sub-processors
We use a small set of trusted services to run Pay-E:
- Stripe, Inc. — card processing, Stripe Checkout, Stripe Connect payouts. Stripe is PCI-DSS Level 1 certified.
- Twilio Inc. — SMS delivery for payment links and order updates.
- Sentry — application error monitoring; PII is scrubbed from error reports.
- Cloud hosting provider — application and database hosting under a data processing agreement.
We notify merchants by email at least 30 days before adding a new sub-processor that handles personal data.
Your rights as a merchant (data controller)
Under the Australian Privacy Principles, you are the data controller for your customers' personal information. Pay-E is your data processor. That means:
- You decide what customer data is collected (Pay-E only collects what your staff enter).
- You can export your full customer and order history as CSV at any time, from Settings → Audit log.
- You can delete a customer record on request — we honour the request within 30 days.
- You're responsible for telling your customers that you use Pay-E to send payment links.
Your customers' rights
Australian customers can ask to see, correct, or delete the data their merchant holds about them. They should contact the merchant first; if Pay-E is asked directly, we forward the request to the merchant within 5 business days.
Incident notification
If we discover a security incident affecting merchant or customer data, we'll notify affected merchants within 72 hours of confirmation and provide what we know, what's still being investigated, and what we're doing about it. We don't promise zero incidents — we promise honesty when they happen.
What we don't claim
We don't claim certifications we don't hold:
- PCI-DSS: not applicable to Pay-E. Card data handling is delegated to Stripe (PCI-DSS Level 1).
- ISO 27001 / SOC 2 Type II: not currently certified. We follow ISO 27001-aligned controls where they make sense at our scale.
- GDPR:we operate primarily under the Australian Privacy Principles. If you serve EU residents, contact us before signing — we'll work through the controls together.
Contact
Privacy enquiries: privacy@pay-e.com.au — we respond within 5 business days.
Complaints: contact us first; if unresolved, you can lodge a complaint with the Office of the Australian Information Commissioner.
Pay-E Pty Ltd. This page is plain-English data-handling guidance and should be read alongside our Privacy Policy and Terms of Service. It does not constitute legal advice.