HomePrivacy Policy

    Privacy Policy

    Last updated: January 2026 · PayCamp / Towpath Digital

    We are committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information when you use PayCamp.

    UK GDPR Compliant
    No data sold to third parties
    Transparent data practices
    Data Privacy Shield available

    00

    Who We Are

    PayCamp is a product of Towpath Digital Ltd (Company No. 16913912), registered in England & Wales. Our registered address is in Cambridgeshire, United Kingdom.

    Towpath Digital Ltd is the data controller responsible for your personal data collected through the PayCamp website and services.

    01

    Information We Collect

    Personal Information

    We may collect personal information that you provide directly to us, including:

    • Name and contact details (email, phone number)
    • Business information (company name, site details)
    • Account credentials
    • Payment information (processed securely via third-party providers)
    • Communications you send to us

    Automatically Collected Information

    When you use our services, we may automatically collect:

    • Device and browser information
    • IP address and location data
    • Usage data and analytics
    • Cookies and similar technologies

    02

    How We Use Your Information

    We use the information we collect to:

    • Provide, maintain, and improve our services
    • Process transactions and send related information
    • Send promotional communications (with your consent)
    • Respond to your enquiries and provide customer support
    • Monitor and analyse trends, usage, and activities
    • Detect, prevent, and address technical issues and fraud
    • Comply with legal obligations

    03

    Payment Processing

    We use Stripe as our payment processor to handle all subscription payments securely.

    What payment data we collect

    • We do NOT store full credit/debit card numbers, CVV codes, or complete card details on our servers
    • Stripe securely stores your payment method and provides us only with the last 4 digits of your card, card type, and expiry date for display purposes
    • We store your billing name and address for invoicing purposes
    • Transaction records (amounts, dates, invoice numbers) are stored in our system

    PCI-DSS Compliance

    Stripe is a PCI-DSS Level 1 certified payment processor — the highest level of certification in the payment industry. Your payment information is handled with industry-leading security standards. See Stripe's Privacy Policy.

    Recurring Billing

    By subscribing to PayCamp, you authorise us (via Stripe) to charge your payment method on a recurring basis according to your chosen billing cycle. You can update or remove your payment method at any time via your account settings.

    PayCamp Payments (Payment Facilitation)

    When a site owner enables PayCamp Payments, their customers (guests) can pay for bookings and invoices online via a secure checkout page. In this context:

    • Guest payment data: Guest card details are submitted directly to Stripe and are never stored on PayCamp servers. We receive only the last 4 digits of the card, transaction amount, and payment status.
    • Data shared with site owners: Payment confirmation, amount paid, guest name and email address are shared with the site owner for their records.
    • Data shared with Stripe Connect: Guest payment details are processed by Stripe under their Privacy Policy. PayCamp never accesses or stores full card numbers.
    • Transaction records: We retain records of facilitated transactions (amounts, dates, status, fees) for a minimum of 7 years for accounting and regulatory compliance.

    05

    Data Sharing

    We may share your information with:

    • Service providers who assist in our operations (including Stripe for payment processing)
    • Professional advisors (lawyers, accountants)
    • Law enforcement when required by law
    • Business partners with your consent
    We do not sell your personal information to third parties.

    06

    Data Retention

    We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.

    07

    Your Rights

    Under UK GDPR, you have the right to:

    • Access your personal data
    • Rectify inaccurate data
    • Request erasure of your data
    • Restrict processing of your data
    • Data portability
    • Object to processing
    • Withdraw consent at any time

    To exercise these rights, please contact us at [email protected].

    08

    Data Security

    We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction — including encryption, secure servers, and regular security assessments.

    Data Privacy Shield

    PayCamp offers an optional Data Privacy Shield that provides enterprise-grade data isolation. When enabled:

    Database-level blocking

    Row Level Security rules physically prevent our admin accounts from querying your sensitive tables — customers, invoices, bookings, and payments. Enforced at the database layer, not by policy.

    Temporary support access

    If you need help, you can grant our team scoped, time-limited access (24 hours, 48 hours, or 7 days). Access auto-expires and can be revoked instantly.

    Full transparency

    Every admin access event is logged in your Transparency Dashboard with timestamps, scope, and identity. There is no way for us to access your data without it appearing in the audit trail.

    Payment credential protection

    Your Stripe API keys are stored encrypted and shielded behind the same privacy rules. We never see your payment credentials or hold funds on your behalf.

    We built it so we physically cannot access your data when Privacy Shield is enabled — not just that we promise not to. The database enforces it, not a policy document.

    09

    International Transfers

    Your data is primarily stored and processed in the UK. If we transfer data outside the UK, we ensure appropriate safeguards are in place in compliance with UK GDPR.

    10

    Cookies

    We use only essential cookies necessary for the website to function — no tracking or marketing cookies. For more information, see our Cookie Policy.

    11

    Children's Privacy

    Our services are not intended for children under 16. We do not knowingly collect personal information from children.

    12

    Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

    13

    Contact Us

    If you have any questions about this Privacy Policy or our data practices, please contact us:

    You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk .