LEGAL

Privacy Policy

How we collect, use, and protect personal data when you use Ownaris — and what your merchants' customers can expect from us.

EFFECTIVE 19 AUGUST 2026
ON THIS PAGE
  1. Who we are
  2. Controller and processor
  3. Data we collect
  4. Cardholder data
  5. How we use data
  6. Legal bases
  7. Sharing and subprocessors
  8. Cookies and tracking
  9. Retention
  10. Your rights
  11. International transfers
  12. Security
  13. Changes
  14. Contact

1. Who we are

Ownaris is a platform for checkout, payment orchestration, and customer relationship management. This policy is issued by Ownaris LLC, registered at 20 rue du presbytère, 69008 Lyon, France ("Ownaris", "we", "us").

It covers our website, our dashboard at app.ownaris.io, and our APIs and SDKs (together, the "Service").

2. Controller and processor

Our role depends on whose data is involved.

  • We are the controller for data about our own merchants and prospects — account details, billing records, support conversations, and website analytics.
  • We are a processor for data a merchant runs through the Service about their own customers — orders, payment events, contact details, and messaging history. The merchant is the controller and decides why that data is processed; we act on their documented instructions under our Data Processing Agreement.

If you bought something from a store that runs on Ownaris and want your data deleted, contact that store first. If you cannot reach them, write to us and we will route the request.

3. Data we collect

Data you give us

  • Account data — name, work email, password hash, company name, role.
  • Billing data — billing address, tax identifiers, invoice history, and the payment method used to pay our fees.
  • Verification data — the identity and business documents required by anti-money-laundering rules and by the processors you connect.
  • Support data — anything you send us in a ticket, email, or call.

Data we generate

  • Usage data — pages viewed, features used, API calls, request timestamps, and error traces.
  • Device data — IP address, browser and OS, and device identifiers.
  • Risk signals — fraud and abuse indicators derived from transaction patterns.

Data you process through us

When you run transactions on Ownaris, we process your customers' order details, contact details, payment event history, and any custom attributes you send. You choose what to send; do not send special-category data.

4. Cardholder data

Card numbers are captured in an isolated tokenization context and exchanged for a token. Ownaris stores tokens, the last four digits, the expiry, the brand, and the issuing country — never the full number or the CVC after authorization.

Cardholder data is handled in line with PCI DSS. Our current attestation is available on request at contact@ownaris.io.

5. How we use data

  • Provide the Service — route payments, run checkout sessions, trigger flows, and maintain the customer record.
  • Bill you, and collect what is owed.
  • Detect and prevent fraud, abuse, and money laundering.
  • Provide support and communicate about incidents, changes, and releases.
  • Improve the Service through aggregated, non-identifying analysis.
  • Meet legal, tax, and regulatory obligations.

We do not sell personal data, and we do not use merchant customer data to train models or to build advertising profiles.

6. Legal bases

Where the GDPR or UK GDPR applies, we rely on: performance of a contract for account, billing, and transaction processing; legal obligation for tax, accounting, and AML duties; legitimate interests for security, fraud prevention, and product improvement; and consent for optional cookies and marketing email, which you can withdraw at any time.

7. Sharing and subprocessors

We share personal data only with:

  • Payment processors and acquirers you connect or that we route to, so a transaction can settle.
  • Infrastructure and tooling subprocessors — hosting, monitoring, email and SMS delivery, and support tooling. The current list is available on request at contact@ownaris.io; we give notice before adding one.
  • Professional advisers — auditors, lawyers, and accountants, under confidentiality.
  • Authorities, where a valid legal request compels us. We notify you unless we are legally barred from doing so.
  • An acquirer, in a merger, acquisition, or asset sale, under equivalent protection.

8. Cookies and tracking

We use strictly necessary cookies for authentication, session integrity, and security — these cannot be switched off. Analytics and preference cookies are set only with your consent, which you can change from the cookie banner or in the dashboard.

Server-side tracking inside the Service sends conversion events on behalf of the merchant. The merchant is the controller for those events and is responsible for the disclosures and consent on its own storefront.

9. Retention

  • Account data — for the life of the account, then 12 months.
  • Transaction and billing records — 10 years, as required by tax and AML law.
  • Merchant customer data — for as long as the merchant keeps it, then deleted or returned within 30 days of account closure.
  • Logs and risk signals — 12 months.

Backups age out on their own cycle, within 35 days.

10. Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent. Californian residents may also opt out of "sharing" as defined by the CPRA — we do not sell or share personal data in that sense.

Write to contact@ownaris.io and we will respond within 30 days. You can also complain to your supervisory authority; ours is the CNIL in France.

11. International transfers

Data may be processed outside your country, including in the European Union and the United States. Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, plus a transfer risk assessment. A copy is available on request.

12. Security

Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Access is role-based, logged, and limited to what a role needs. We enforce multi-factor authentication internally, review access on a regular cycle, and run penetration tests at least annually.

If a breach affects your data, we notify you without undue delay and within 72 hours of becoming aware where the law requires it. Report a suspected vulnerability to contact@ownaris.io.

13. Changes

We may update this policy. Material changes are announced by email and in the dashboard at least 30 days before they take effect. The effective date at the top of this page always reflects the current version.

14. Contact

Privacy questions, requests, and complaints: contact@ownaris.io.

Postal: Ownaris LLC, 20 rue du presbytère, 69008 Lyon, France. Telephone: +1 (636) 216-0423. Data protection contact: Louis Bourgier contact@ownaris.io.