1. Who we are
Ownaris is a platform for checkout, payment orchestration, and customer relationship management. This policy is issued by Ownaris LLC, registered at 20 rue du presbytère, 69008 Lyon, France ("Ownaris", "we", "us").
It covers our website, our dashboard at app.ownaris.io, and our APIs and SDKs (together, the "Service").
2. Controller and processor
Our role depends on whose data is involved.
- We are the controller for data about our own merchants and prospects — account details, billing records, support conversations, and website analytics.
- We are a processor for data a merchant runs through the Service about their own customers — orders, payment events, contact details, and messaging history. The merchant is the controller and decides why that data is processed; we act on their documented instructions under our Data Processing Agreement.
If you bought something from a store that runs on Ownaris and want your data deleted, contact that store first. If you cannot reach them, write to us and we will route the request.
3. Data we collect
Data you give us
- Account data — name, work email, password hash, company name, role.
- Billing data — billing address, tax identifiers, invoice history, and the payment method used to pay our fees.
- Verification data — the identity and business documents required by anti-money-laundering rules and by the processors you connect.
- Support data — anything you send us in a ticket, email, or call.
Data we generate
- Usage data — pages viewed, features used, API calls, request timestamps, and error traces.
- Device data — IP address, browser and OS, and device identifiers.
- Risk signals — fraud and abuse indicators derived from transaction patterns.
Data you process through us
When you run transactions on Ownaris, we process your customers' order details, contact details, payment event history, and any custom attributes you send. You choose what to send; do not send special-category data.
4. Cardholder data
Card numbers are captured in an isolated tokenization context and exchanged for a token. Ownaris stores tokens, the last four digits, the expiry, the brand, and the issuing country — never the full number or the CVC after authorization.
Cardholder data is handled in line with PCI DSS. Our current attestation is available on request at contact@ownaris.io.
5. How we use data
- Provide the Service — route payments, run checkout sessions, trigger flows, and maintain the customer record.
- Bill you, and collect what is owed.
- Detect and prevent fraud, abuse, and money laundering.
- Provide support and communicate about incidents, changes, and releases.
- Improve the Service through aggregated, non-identifying analysis.
- Meet legal, tax, and regulatory obligations.
We do not sell personal data, and we do not use merchant customer data to train models or to build advertising profiles.
6. Legal bases
Where the GDPR or UK GDPR applies, we rely on: performance of a contract for account, billing, and transaction processing; legal obligation for tax, accounting, and AML duties; legitimate interests for security, fraud prevention, and product improvement; and consent for optional cookies and marketing email, which you can withdraw at any time.
9. Retention
- Account data — for the life of the account, then 12 months.
- Transaction and billing records — 10 years, as required by tax and AML law.
- Merchant customer data — for as long as the merchant keeps it, then deleted or returned within 30 days of account closure.
- Logs and risk signals — 12 months.
Backups age out on their own cycle, within 35 days.
10. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent. Californian residents may also opt out of "sharing" as defined by the CPRA — we do not sell or share personal data in that sense.
Write to contact@ownaris.io and we will respond within 30 days. You can also complain to your supervisory authority; ours is the CNIL in France.
11. International transfers
Data may be processed outside your country, including in the European Union and the United States. Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, plus a transfer risk assessment. A copy is available on request.
12. Security
Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Access is role-based, logged, and limited to what a role needs. We enforce multi-factor authentication internally, review access on a regular cycle, and run penetration tests at least annually.
If a breach affects your data, we notify you without undue delay and within 72 hours of becoming aware where the law requires it. Report a suspected vulnerability to contact@ownaris.io.
13. Changes
We may update this policy. Material changes are announced by email and in the dashboard at least 30 days before they take effect. The effective date at the top of this page always reflects the current version.
14. Contact
Privacy questions, requests, and complaints: contact@ownaris.io.
Postal: Ownaris LLC, 20 rue du presbytère, 69008 Lyon, France. Telephone: +1 (636) 216-0423. Data protection contact: Louis Bourgier — contact@ownaris.io.