MONEI
Open mobile navigation

Products

Ecommerce payments

In-person payments

Omnichannel payments

Payments security

Other features

Integrations

Payment methods

E-commerce platforms

Businesses we Serve

Resources

Pricing

Data Protection Policy for End Users

MONEI DIGITAL PAYMENTS, S.L. (hereinafter, "MONEI"), in its capacity as a payment service provider, makes available to you the payment gateway that allows you, at the merchant, to use the different payment methods you have contracted with payment service providers to pay for your purchases.

When you activate the payment gateway and choose the payment service you want to use, the merchant provides MONEI with the transaction data:

  • Name of the merchant,
  • Selected payment method,
  • The mobile number or email associated with the transaction,
  • Billing data (transaction amount),
  • Shipping data (payment destination account), and
  • Technical session data.

With this data, MONEI provides you with a direct connection to the chosen payment service provider so that you can enter the personal data needed to initiate, authenticate, execute, and manage the corresponding transaction.

MONEI does not access the payment service data that you enter through the gateway; it merely facilitates direct contact with the selected provider so that the provider manages the payment. MONEI only accesses the basic data indicated above, which is the only data it needs to provide the payment Platform service.

Once the payment is executed, the user's payment service provider confirms to MONEI that the payment was successful, and MONEI forwards that confirmation to the merchant.

The processing of said personal data will be carried out in accordance with the provisions of this Privacy Policy.

Data controller

The controller of your personal data is MONEI, with registered office at Calle Palestina, 1, Entreplanta, 29007, Málaga.

Data Protection Officer

MONEI has appointed a Data Protection Officer in charge of supervising compliance with data protection matters, whose contact details are: support@monei.com, and whom you can contact if you have any questions or complaints on the matter.

Types of personal data

  • Transaction and identification data: name, payment method used, mobile number or email associated with the transaction, payment amount, payment destination account, temporary session data, and result of the operation.
  • Likewise, only if you contact MONEI's support service, your email address will be requested, and all the information you provide in your request, along with the checks we carry out to handle it, will be processed.

Origin of data

The data comes from: (i) the merchant in online purchases, (ii) the automatic reading of the card used as a payment instrument in in-store payments, (iii) the data entered into the payment system in both cases, and (iv) the support request message.

The data required is necessary to provide you with the payment gateway Service, and refusal to provide it will make it impossible to provide the payment service.

Purposes of processing

The data obtained will be used and processed for:

  • Based on the execution of the contractual relationship (Art.6.1.b GDPR): the data subject to processing will be used to attend to the payment gateway service requested by the user and to address the user's questions and complaints related to the payment.
  • Based on compliance with legal obligations (Art.6.1.c GDPR): the data will be used to attend to legal responsibilities.

Data retention

One month after each payment operation, personal data will be kept duly blocked and available to the authorities for a period of ten years from the termination of the business relationship or the execution of the operation, as established by the Anti-Money Laundering and Terrorist Financing regulations.

Data communication

MONEI may communicate personal data to:

  • Merchants within the framework of providing the service (result of the operation).
  • Competent regulatory and administrative authorities (including, among others, the Bank of Spain, SEPBLAC, the Tax Agency, and the State Security Forces and Bodies).
  • Likewise, MONEI has third-party service providers who may access personal data due to the provision of their services, such as auditors, consulting services, advisors, IT maintenance, technology platforms, administrative services, and document destruction, among others. MONEI pre-selects these providers based on data protection compliance criteria, has signed data processing agreements with all of them in accordance with article 28.3 of the GDPR, and controls that they comply with their obligations.

International data transfers

As a general rule, no international transfers of personal data are made. In the event that any of MONEI's providers is located outside the European Economic Area ("EEA"), MONEI will enter into the corresponding contractual agreements to guarantee the implementation of adequate security measures, ensuring that the personal data of Users is processed with an adequate level of protection comparable to that required in the EEA.

Data protection rights

Data subjects may exercise the following data protection rights by postal mail to Calle Palestina, 1, Entreplanta, 29007, Málaga, Spain or by email to support@monei.com, proving their identity.

  • Access: you can obtain information related to the processing of your personal data and a copy of such personal data.
  • Rectification: if you consider your personal data is inaccurate or incomplete, you can request that such data be modified accordingly.
  • Erasure: you can request the deletion of your personal data, to the extent permitted by Law.
  • Restriction: you can request the restriction of the processing of your personal data.
  • Objection: you can object to the processing of your personal data, for reasons related to your particular situation.
  • Data portability: when legally applicable, you have the right to have the personal data you have provided to us returned or, when technically possible, transferred to a third party.
  • Not to be subject to automated individual decisions: this aims to ensure that you are not subject to a decision based solely on the processing of your data, including profiling, which produces legal effects concerning you or similarly significantly affects you.

Likewise, you may submit a complaint to MONEI's Data Protection Officer at the indicated addresses or to the control authority on the matter, the Spanish Data Protection Agency (AEPD), whose contact details are offered through the website aepd.es.