This Privacy Policy (“Policy”) explains how MassPay Holdings, LLC and its mobile applications (collectively referred to as “the ‘Applications,’” “we,” “us,” or “our”) collects, stores, uses, and shares personal data when you visit our website or use our services.
Purpose of This Privacy Policy
This website is not intended for children and we do not knowingly collect data relating to children. Minors may make use of MassPay services through a process of age-assurance and parental/guardian consent.
It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them.
Third-Party Links
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
The Data We Collect About You
Personal data, or personal information, means any information about an individual from which that person can be identified directly or indirectly. It does not include data where the ability to identify the individual has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:
If You Fail to Provide Personal Data
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us, but we will notify you if this is the case at the time.
How is Your Personal Data Collected?
We use different methods to collect personal information from and about you including through:
How We Use Your Personal Data
We will only use your personal data when the law allows us to or you allow us to by way of a contractual agreement. Most commonly, we will use your personal data in the following circumstances:
Generally, we do not rely on consent as a legal basis for processing your personal data, although, if we decide to use third-party direct marketing we will get your consent before sending these communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting us.
Use of Artificial Intelligence Tools. We may use AI tools to support our services and business operations, including for identity and document review, account-matching support, fraud prevention, transaction monitoring, KYB and onboarding support, periodic review support, customer support, operational workflow analysis, financial reconciliation support, data summarization, contract or document review, sales and marketing drafting, translation, research, meeting summaries, internal reporting and other productivity or compliance purposes.
AI Tools may be used to help identify discrepancies, generate summaries, prepare draft communications, create alerts, support human review, or recommend follow-up actions. Except where expressly disclosed, AI Tools are used to assist MassPay personnel and are not a substitute for human judgment.
Artificial Intelligence, Automated Tools and Human Review
MassPay uses approved AI Tools in a controlled manner to support business, operational , compliance, fraud prevention, customer support, and productivity functions. The categories of personal information processed through AI Tools may include names, email addresses, uploaded documents, transaction data, account activity, operational logs, customer or prospect information, company information, meeting notes, and other information reasonably necessary for the applicable business purpose.
Some AI-supported processes may help identify potential inconsistencies, fraud indicators, transaction trends, account risk issues, KYB review items, or operational alerts. In most cases, AI outputs ae advisory and are reviewed by authorized MassPay personnel before any customer-facing action is taken. Where an AI Tool may contribute to a decision that affects a customer’s access to services, account status, onboarding review, fraud flag, escalation, investigation, or other significant matter, MassPay maintains human review processes designed to assess the AI output before or after action is taken, as appropriate.
You may contact us at prviacy@masspay.io if you believe an AI-assisted or automated process has affected you and you would like to request review, correction, reconsideration, or additional information.
Purposes for Which We Will Use Your Personal Data
We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one grounds has been set out in the table below.
Promotional Offers from Us
We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing).
You will receive marketing communications from us if you have requested information from us or purchased products or services from us and you have not opted out of receiving that marketing.
Third-Party Marketing
We will get your express opt-in consent before we share your personal data with any third party for marketing purposes. At this time, we do not participate in any third party marketing, nor do we sell your personal information to third parties for the purposes of marketing any goods or services. MassPay does not permit targeted or cross-context behavioral advertising to minors and we prohibit our service providers from using minors’ information for their own advertising or profiling.
As the subject of the personal data, you have rights related to the personal data that we hold about you. At any time, you have the right to:
Opting Out
You can ask us or third parties to stop sending you marketing messages at any time.
If you opt-out of receiving these marketing messages, this opt out will not apply to personal data provided to us as a result of a product purchase, use of our services or other transactions.
Cookies
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. You can review our Cookie Policy here.
Change of Purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Disclosures of Your Personal Data
We may share your personal data across our services and with third parties to help us provide services, protect our customers from risk and fraud, market our products, and comply with legal obligations. We may share personal data with:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions and contractual obligations with them.
AI Vendors and Service Providers. We may share personal data with AI vendors, cloud providers, analytics providers, productivity tools, customer0support tools, compliance tools and other service providers that process information on our behalf. These providers may include provides of large language models, AI gateways, document-review tools, transcription or meeting summary tools, customer support automation tools, creative tools and related infrastructure providers.
We require service providers to process personal data only for authorized purposes and in accordance with applicable contractual, security, confidentiality, and data protection obligations. We do not authorize our AI vendors or service providers to use customer personal data, uploaded documents, prompts, outputs, logs, confidential business information, or regulated financial information to train public or general purpose AI models unless we have provided appropriate notice and obtained any required authorization.
International Transfers
Whenever we transfer your personal data out of the European Economic Area (“EEA”) or your country of residence, we ensure a similar degree of protection is afforded to it by using standard contractual clauses approved by the European Commission, which give personal data the same protection it has in Europe.
Some AI vendors and related service providers may process personal data in the United States or other countries where they or their subprocessors maintain infrastructure or personnel. Where required by law, we use appropriate safeguards for international transfers, which may included contractual protections, data processing agreements, standard contractual clauses, vendor due diligence, access controls or other lawful transfer mechanisms.
Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed by unauthorized persons, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.
They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
AI Safeguards. We maintain administrative, technical, and organizational safeguards designed to protect personal data when AI Tools are used. These safeguards may include restricting AI use to approved enterprise, business, or API-based platforms; limiting access to authorized personnel; applying role-based access controls; using single sign-on, multi-factor authentication, and other identity controls; encrypting data in transit and at rest where available; maintaining vendor due diligence and contractual data-protection requirements; configuring available retention, logging, and compliance controls; monitoring usage for security and compliance purposes; and requiring human review before relying on AI-generated outputs for material business or customer-facing decisions.
Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
AI Outputs and Logs. We may retain prompts, uploaded documents, AI-generated outputs, summaries, analysis, alerts, risk indicators, audit logs, usage logs, and related metadata as part of our ordinary business records. These records may be stored in our internal systems, vendor platforms, compliance archives, case-management tools, ticketing systems, customer files, customer-support systems, CRM systems, or other authorized business applications. Retention periods vary depending on the purpose of processing, the type of record, contractual commitments, legal and regulatory requirements, security needs, and applicable vendor settings. Where AI records are no longer needed, we delete, de-identify, or anonymize them in accordance with our retention practices and applicable law.
Your Legal Rights
As the subject of the personal data, you have rights related to the personal data that we hold about you. At any time, you have the right to:
AccessMassPay will provide the personal data we have about you.
RectifyMassPay will correct the personal data we have about you.
DeleteMassPay will delete the personal data we have about you.
ObjectYou have the right to object how your personal data is used by MassPay.
Restrict ProcessingYou have the right to request that MassPay restricts the processing of your personal data.
PortabilityYou have the right to transfer your personal data to you or to a third party.
A parent or legal guardian may submit a verifiable request on behalf of their minor child; we will take additional steps to verify identity and relationship before responding.
If you wish to exercise any of the rights set out above, please contact us at support@masspay.io.
Children’s Privacy
Our Services are not intended for children, and we do not knowingly collect personal information from children. Where features may be used by minors, we apply heightened safeguards: we use reasonable age-assurance; obtain and record parental/guardian authorization where required by law; minimize collection; set high-privacy defaults; disable targeted advertising and unnecessary profiling for minors; apply short, purpose-linked retention; and enforce enhanced security and processor restrictions. Children—and verified parents/guardians—may exercise applicable privacy rights (e.g., access, correction, deletion, objection/restriction, portability). If we learn we collected a child’s information without proper authorization, we will delete it promptly. Contact privacy@masspay.io with questions or requests.
Your California Privacy Rights.
If you are a California resident, please visit our Privacy Policy for California Residents for additional information about our processing of personal information and your California privacy rights.
Your Canadian Privacy Rights
If you are a Canadian resident, please visit our Privacy Policy for Canadian Residents for additional information about our processing of personal information and your Canadian privacy rights.
No Fee Usually Required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
What We May Need from You
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
Time Limit to Respond
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Changes to Our Privacy Policy
We keep our privacy policy under regular review. This version was last updated on August 26, 2025. We reserve the right to amend this privacy Policy at our discretion and at any time. When we make changes to this Policy, we will post the updated Policy on the Website and update the Policy’s effective date. Your continued use of our Website, web pages, applications and dashboards following the posting of changes constitutes your acceptance of such changes.
Contact Details
If you have any questions or comments about this Policy, the ways in which we collect and use your information described above, your choices and rights regarding such use, or wish to exercise your rights under this Privacy Policy, please do not hesitate to contact us at:
You have the right to make a complaint at any time to the Supervisory Authority in the Country, State, or Province in which you reside, or in the if your reside in the UK the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (https://ico.org.uk/). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
Please contact our team if you need to access this Policy in an alternative format due to having a disability.



Stop settling for generic platforms. Let's build a custom payout solution that scales worldwide, evolves with your business, and puts your people first - wherever they are.