Supay Technology Limited
Privacy Policy and Privacy Notice
Effective date: 20 July 2026
Last updated: 20 July 2026
1. Introduction
Supay Technology Limited (“Supay”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal information entrusted to us. This Privacy Policy explains how we collect, hold, use, disclose, transfer, retain and protect personal information when you:
- visit our website
- use our applications, platforms, payment services or payment terminals
- apply for or maintain an account
- make or receive a payment
- apply to become a merchant or business partner
- contact our customer service team
- participate in a promotion, survey or event
- communicate or otherwise interact with us
This Privacy Policy applies to customers, prospective customers, merchants, directors, beneficial owners, authorised representatives, business partners, website visitors and other individuals whose personal information we process. Supay handles personal information in accordance with the New Zealand Privacy Act 2020 and other applicable privacy, financial services, anti-money laundering, payment and regulatory requirements.
2. Who We Are
Supay Technology Limited is a New Zealand payment technology and financial services company. Registered office and contact address: Level 7, 220 Queen Street Auckland Central Auckland 1010 New Zealand Privacy Officer: Privacy Officer Supay Technology Limited Email:
Telephone: +64 21 918 618
3. Meaning of Personal Information
“Personal information” means information about an identifiable individual. Personal information may include information that identifies you directly, as well as information that can identify you when combined with other information.
4. Personal Information We Collect
Depending on the services you use and your relationship with Supay, we may collect the following categories of personal information.
4.1 Identity information
- Full legal name
- Date of birth
- Gender, where required for identification
- Nationality and country of residence
- Photograph
- Signature
- Customer or merchant identification number
- Government-issued identification details, such as passport or driver licence information
- Visa, residency or immigration information where relevant
- Facial images, facial verification results or other biometric verification information where identity verification services are used
4.2 Contact information
- Residential address
- Business or trading address
- Postal address
- Email address
- Telephone number
- Preferred communication method
4.3 Customer due diligence information
- Occupation and employer
- Source of funds and source of wealth
- Purpose and intended nature of the business relationship
- Expected transaction activity
- Tax residency information
- Politically exposed person status
- Sanctions, adverse media and watchlist screening results
- Information about family members, associates or related parties where required by law
- Additional information collected through enhanced customer due diligence
4.4 Merchant and business information
For merchants, directors, beneficial owners, authorised representatives and business partners, we may collect:
- Company name and registration number
- New Zealand Business Number or overseas equivalent
- Business licence and regulatory registration details
- Ownership and control information
- Director, shareholder and beneficial owner details
- Business activities, products and services
- Merchant category
- Store, website and application information
- Store address and operating locations
- Storefront and interior photographs
- Financial statements and settlement information
- Bank account details
- Transaction volumes and expected business activity
- Complaint, chargeback, fraud and compliance history
4.5 Payment and transaction information
- Payment amount, currency, date and time
- Payment method
- Merchant and transaction identifiers
- Bank or settlement account details
- Tokenised card or payment identifiers
- Payment authorisation and settlement status
- Recipient or beneficiary details
- Refunds, reversals and chargebacks
- Transaction location
- Information contained in payment references
- Records relating to failed, declined, disputed or suspicious transactions
Depending on the payment service, some payment information may be collected or processed directly by banks, acquirers, card schemes, payment gateways or other payment partners.
4.6 Device and technical information
- Internet Protocol address
- Device identifier
- Browser type
- Operating system
- Application version
- Device model
- Mobile network information
- Login date and time
- Approximate location derived from an IP address or device
- Session information
- Security and authentication records
- Cookies and similar technologies
- Website and application activity
- Error logs and diagnostic information
4.7 Customer service and communication information
- Emails, telephone calls, messages and correspondence
- Customer support requests
- Complaints and dispute records
- Call recordings, where notice has been provided
- Information and documents supplied during an investigation
- Feedback, survey responses and service reviews
4.8 Fraud, security and compliance information
- Transaction-monitoring alerts
- Fraud indicators and risk scores
- Device and account relationships
- Login and authentication history
- Suspicious activity investigation records
- Internal blacklist or account restriction information
- Chargeback and dispute information
- Information received from payment partners, regulators, law enforcement agencies or fraud prevention services
5. How We Collect Personal Information
We may collect personal information:
- directly from you
- from a merchant, employer, account holder or authorised representative
- when you use our website, application, platform or payment terminal
- when you submit an application or supporting documents
- when you make or receive a payment
- during customer or merchant onboarding
- through customer service communications
- from payment processors, banks, acquirers, card schemes and settlement providers
- from identity verification and fraud prevention providers
- from government agencies, regulatory bodies and law enforcement agencies
- from public company registers, insolvency registers, court records and regulatory databases
- from sanctions, politically exposed person and adverse media screening services
- from credit reporting or business information providers, where legally permitted
- from cookies, analytics tools, security systems and device technologies
- from other persons where you have authorised the disclosure or where collection is otherwise permitted by law
Where reasonably practicable, we collect personal information directly from the individual concerned.
6. Why We Collect and Use Personal Information
We may collect and use personal information to:
- provide, administer and improve our payment and technology services
- create, verify and manage customer or merchant accounts
- process, authorise, settle, reconcile, refund and investigate transactions
- verify identity and conduct customer or merchant due diligence
- meet anti-money laundering and counter-financing of terrorism obligations
- conduct sanctions, politically exposed person and adverse media screening
- assess merchant, customer, transaction, credit, operational and fraud risks
- detect, prevent and investigate fraud, scams, money laundering, cybercrime and other unlawful activity
- authenticate users and protect accounts
- manage disputes, chargebacks, complaints and customer enquiries
- communicate service, security, legal and account-related information
- monitor service performance and maintain system security
- provide technical and customer support
- comply with card scheme, acquiring bank and payment partner requirements
- comply with legal, regulatory, audit, tax, accounting and reporting obligations
- respond to lawful requests from regulators, courts and law enforcement agencies
- enforce our contracts, policies and terms and conditions
- establish, exercise or defend legal claims
- develop and improve our products, services and customer experience
- conduct internal reporting, analysis and risk management
- send marketing communications where permitted and subject to your communication preferences
- manage corporate transactions, restructuring, financing, investments or a sale of all or part of our business
We will not use personal information for a materially different purpose unless the use is permitted by law or we have provided appropriate notice or obtained consent where required.
7. When Providing Information Is Required
Some personal information is required so that we can:
- verify your identity
- meet legal and regulatory obligations
- assess your eligibility for a service
- establish or maintain a customer or merchant relationship
- process and settle transactions
- protect our services against fraud or misuse
Where requested information is mandatory and you do not provide it, we may be unable to open or maintain your account, process a transaction, onboard your business, or provide the requested service.
8. Identity Verification and Biometric Information
Supay may use an identity verification provider to compare identity document information with a photograph, live image or facial verification result. Where biometric verification is used:
- it will be used for identity verification, authentication, fraud prevention or regulatory compliance
- we will limit the information collected to what is reasonably necessary
- information may be processed by an approved identity verification provider
- access will be restricted to authorised personnel and service providers
- information will be retained only for as long as reasonably required or legally necessary
Where required, additional notice or consent will be provided before biometric information is collected.
9. Transaction Monitoring and Fraud Prevention
Supay monitors transactions and account activity to identify fraud, money laundering, scams, prohibited activity, account takeover, sanctions exposure and other financial crime risks. Monitoring may involve:
- rules-based transaction monitoring
- risk scoring
- device and login analysis
- comparison with expected customer or merchant activity
- review of transaction velocity, value, frequency, location and counterparties
- sanctions and politically exposed person screening
- manual review by authorised Risk and Compliance personnel
Where suspicious or high-risk activity is detected, we may request further information, delay or decline a transaction, restrict an account, suspend services, terminate a relationship or make a report to an appropriate authority where permitted or required by law. We may not be permitted to inform you that a suspicious activity report or similar regulatory report has been made.
10. Automated Processing
We may use automated tools to assist with:
- identity verification
- transaction monitoring
- fraud detection
- security monitoring
- account authentication
- merchant and customer risk assessments
Automated results may generate an alert, request for further information, transaction restriction or referral for manual review. Where appropriate, significant adverse decisions will be reviewed by authorised personnel before final action is taken.
11. Who We May Share Personal Information With
We may disclose personal information to:
- acquiring banks and sponsoring financial institutions
- banks, payment processors and settlement providers
- Visa, Mastercard, UnionPay and other payment or card schemes
- digital wallet and alternative payment providers
- payment gateways and technology integration partners
- identity verification, KYC and biometric verification providers
- sanctions, politically exposed person and adverse media screening providers
- fraud prevention and cybersecurity providers
- cloud hosting, software, data storage and telecommunications providers
- customer service and operational support providers
- merchants, beneficiaries, recipients and transaction counterparties, where necessary to complete a transaction
- auditors, insurers, accountants, lawyers and professional advisers
- regulators, financial intelligence units, government agencies, courts and law enforcement agencies
- debt recovery and dispute resolution providers
- companies within our corporate group
- prospective purchasers, investors, lenders or advisers involved in a corporate transaction
- other parties authorised by you
- other persons where disclosure is permitted or required by law
We require service providers handling personal information on our behalf to use it only for authorised purposes and to maintain appropriate confidentiality and security measures.
12. Overseas Processing and Disclosure
Supay operates in the payment and financial technology sector and may use service providers or payment partners located outside New Zealand. Personal information may therefore be processed or stored in countries including Australia, the Pacific region, Asia, the United States or other locations where our payment, cloud, identity verification, card scheme or technology partners operate. Before disclosing personal information outside New Zealand, we will take reasonable steps to confirm that:
- the overseas recipient is subject to privacy safeguards that are comparable to New Zealand requirements
- appropriate contractual, technical or organisational safeguards apply
- the disclosure is otherwise permitted by applicable law; or
- you have been appropriately informed and expressly authorised the disclosure where required
Overseas laws may permit government or regulatory authorities to access information in circumstances that differ from New Zealand law.
13. Information Security
Supay uses reasonable administrative, technical and physical safeguards designed to protect personal information against:
- loss
- unauthorised access
- misuse
- alteration
- disclosure
- destruction
- cyberattack
- accidental or unlawful processing
Safeguards may include:
- access controls and user authentication
- role-based access restrictions
- encryption in transit and, where appropriate, at rest
- network and application security controls
- logging and monitoring
- vulnerability and security testing
- incident response procedures
- staff confidentiality obligations
- employee training
- service provider due diligence
- secure disposal and deletion procedures
No method of electronic transmission or storage is completely secure. You should protect your passwords, PINs, devices and authentication credentials and notify us promptly if you suspect unauthorised activity.
14. Privacy Breaches
Supay maintains procedures for identifying, assessing, containing, investigating and responding to privacy breaches. Where a privacy breach has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as reasonably practicable, unless an exception applies. We may also notify relevant payment partners, regulators, insurers, law enforcement authorities or cybersecurity agencies where appropriate.
15. Data Retention
Supay retains personal information only for as long as reasonably necessary for the purposes for which it was collected or as required by applicable law. Retention periods may depend on:
- anti-money laundering and counter-financing of terrorism requirements
- financial services and payment regulations
- tax, accounting and financial reporting obligations
- card scheme and acquiring bank requirements
- transaction settlement and reconciliation
- complaint, dispute and chargeback timeframes
- fraud prevention and security needs
- contractual limitation periods
- legal proceedings, investigations or regulatory requests
When personal information is no longer required, it will be securely deleted, destroyed, de-identified or placed beyond operational use, subject to legal and technical requirements.
16. Accuracy of Personal Information
We take reasonable steps to ensure that personal information is accurate, complete, relevant and up to date before using or disclosing it. You are responsible for notifying us promptly if your identity, contact, business, ownership, bank account or other relevant information changes. We may periodically request updated information or supporting documents.
17. Accessing Your Personal Information
You may request confirmation of whether Supay holds personal information about you and request access to that information. To make an access request, contact our Privacy Officer using the details in section 25. We may ask you to verify your identity before providing information. In some circumstances, access may be withheld or limited where permitted by law, including where disclosure could affect another person’s privacy, prejudice an investigation, reveal confidential commercial information or breach a legal obligation. Where access is refused, we will explain the reason where legally permitted.
18. Correcting Your Personal Information
You may request correction of personal information that you believe is inaccurate, incomplete or misleading. If we agree that a correction is appropriate, we will update the information and, where reasonably necessary, inform relevant recipients of the correction. If we do not make the requested correction, you may ask us to attach a statement of correction to the information.
19. Deletion and Account Closure Requests
You may request closure of your account or deletion of certain personal information. We may be unable to delete information where it must be retained to:
- comply with legal or regulatory obligations
- maintain transaction and financial records
- investigate fraud or suspicious activity
- manage disputes, refunds or chargebacks
- establish, exercise or defend legal claims
- protect Supay, our customers or the public from financial crime
Where deletion is not legally or operationally possible, we may restrict access to the information and retain it only for the required purpose.
20. Marketing Communications
Where permitted, Supay may use your contact information to send information about products, services, promotions or business developments. You may unsubscribe from electronic marketing communications by:
using the unsubscribe function in the communication; or
contacting us using the details in section 25. Unsubscribing from marketing will not prevent us from sending necessary account, transaction, security, legal or service communications.
21. Cookies and Similar Technologies
Our website and applications may use cookies, software development kits, pixels, local storage and similar technologies to:
- operate website and application functions
- maintain sessions
- remember preferences
- authenticate users
- protect against fraud and cyber threats
- analyse website and application performance
- understand how users interact with our services
- improve our products and customer experience
You may be able to manage cookies through your browser or device settings. Disabling certain cookies may affect the operation of our services. Where required, we will request consent before using non-essential cookies.
22. Third-Party Websites and Services
Our website, applications or communications may contain links to third-party websites, applications or services. Supay is not responsible for the privacy practices of an independent third party. You should review the applicable third party’s privacy notice before providing personal information. Where a third party processes information on Supay’s behalf, it will be subject to contractual or other appropriate privacy and security requirements.
23. Children and Young Persons
Supay’s general payment and merchant services are not directed to children. We do not knowingly open an account for a person who does not meet the minimum age or legal capacity requirements applicable to the relevant service. Where a service is lawfully offered to a young person, we may require consent or authorisation from a parent, guardian or authorised institution and apply additional privacy safeguards.
24. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to:
- our products and services
- our technology and data processing practices
- applicable laws and regulatory guidance
- payment partner or card scheme requirements
- our organisational structure
The updated policy will be published on our website with a revised effective date. Where a change materially affects how we use personal information, we will provide additional notice where reasonably practicable or legally required.
25. Contacting Supay’s Privacy Officer
For privacy enquiries, access or correction requests, complaints, or concerns about how personal information has been handled, contact: Privacy Officer Supay Technology Limited Level 7, 220 Queen Street Auckland Central Auckland 1010 New Zealand Email:
Telephone: +64 21 918 618 Please include sufficient information for us to identify you, understand your request and locate the relevant information. We will acknowledge and respond to privacy requests and complaints within the timeframes required by applicable law.
26. Complaints to the Privacy Commissioner
We encourage you to contact Supay first so that we have an opportunity to investigate and resolve your concern. You may also make a complaint to: Office of the Privacy Commissioner Te Mana Mātāpono Matatapu New Zealand Information about privacy rights and the complaint process is available through the Office of the Privacy Commissioner’s official website.
27. Governing Version
This Privacy Policy may be translated into other languages for convenience. Where there is an inconsistency between the English version and a translated version, the English version will apply to the extent permitted by law.


