Skip to main content

KORT Payments

(Privacy Policy updated May 21, 2026)

Table of Contents

1. Introduction

KORT Payments Inc. (“KORT”, “we”, “us”, or “our”) is an Independent Sales Organization / Member Service Provider (ISO/MSP) that refers merchants to acquiring banks and payment processors. We are committed to protecting personal information and handling it in accordance with applicable privacy laws.

This Privacy Policy complies with:

  • Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA)
  • S. state privacy laws, including the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)

    2. Our Role in Payment Processing

    KORT operates as an ISO/MSP and:

    • Refers merchants to acquiring banks and payment processors
    • Conducts merchant underwriting and risk assessments
    • Facilitates onboarding to payment networks (e.g., card brands) KORT does not:
    • Act as a payment processor or acquiring bank
    • Hold, receive, or control settlement funds

    Funds flow directly from the customer’s payment method through the payment

    processor/acquirer to the merchant.

    3. Scope

    This Privacy Policy applies to:

    • Merchants applying for or using our services
    • Individuals associated with merchant accounts

    Website users and business contacts

    4. Information We Collect

    The personal information collected is limited to those details necessary for the purposes identified by KORT. Categories and example information include:

    Identifiers

    • Name, address, date of birth, email, phone number
    • IP address, account identifiers

    Financial & Underwriting Information

    • Credit bureau reports
    • Banking and financial details
    • Business ownership and structure information

    Transaction-Related Data

    • Limited transaction metadata
    • Last four digits of payment cards (where applicable)

    Internet Activity

    • Device and browser data
    • Website usage and analytics

    Professional Information

    • Business name, occupation

    Sensitive Personal Information

    • Login credentials
    • Financial and credit data used for underwriting

    5. How We Collect Information

    We collect personal information:

    • Directly from merchants during onboarding
    • From credit bureaus
    • Open sources (e.g. Google, Business Directories, SEDAR)

    6. Purposes of Use

    We use personal information to:

    • Underwrite and evaluate merchant applications
    • Verify identity and assess creditworthiness
    • Refer merchants to acquiring banks and processors
    • Detect and prevent fraud and financial risk
    • Comply with legal, regulatory, and card network requirements
    • Communicate with merchants and provide support

    7. Consent

    We obtain meaningful consent through merchant agreements and onboarding processes.

    Consent may be expressed or implied, as permitted by law. Merchants may withdraw consent, subject to legal or contractual restrictions (e.g., inability to continue services).

    8. Disclosure of Personal Information

    We disclose personal information to:

    • Acquiring banks and payment processors
    • Card networks (e.g., Visa, Mastercard, American Express)
    • Credit bureaus
    • Fraud prevention and risk management partners
    • Service providers (e.g., cloud hosting, CRM, analytics)
    • Regulators and law enforcement where required

    All third parties are contractually required to safeguard personal information.

    9. Payment Data Handling and Payment Card Industry Alignment

    KORT does not store full primary account numbers (PANs). Payment data is:

    • Transmitted securely via encrypted APIs
    • Tokenized in compliance with Payment Card Industry Data Security Standards (PCI DSS)

    KORT may retain:

    • Tokenized data
    • Last four digits of card numbers

    We rely on PCI DSS-compliant service providers for payment processing and maintain appropriate safeguards within our environment.

    10. Cross-Border Data Transfers

    KORT operates in Canada and the United States.

    Personal information may be transferred to and processed in the United States or other jurisdictions. These jurisdictions may have different privacy laws and may permit access by government authorities.

    We use contractual, organizational, and technical safeguards to protect personal information.

    11. Data Retention

    We retain personal information only as long as necessary for:

    • Merchant relationship management
    • Legal and regulatory compliance (including financial reporting)
    • Fraud detection and risk mitigation

    Typical retention period: 7 years after cessation of relationship

    12. Safeguards

    We implement safeguards appropriate to the sensitivity of the information, including:

    • Encryption in transit and at rest
    • Role-based access controls
    • Multi-factor authentication
    • Logging and monitoring systems
    • Vendor security due diligence

    13. SMS Terms of Service

    By opting into SMS from a web form or other medium, you are agreeing to receive SMS messages from KORT Payments. This includes SMS messages for conversations (external). Message frequency varies. Message and data rates may apply. Message HELP for help. Reply STOP to any message to opt out.

    14. Individual Rights (Canada)

    Individuals have the right to:

    • Access their personal information
    • Request correction
    • Withdraw consent

    Requests can be submitted via email: partners@kortpayments.com

    15. U.S. Privacy Rights (Including California)

    U.S. residents may have rights to:

    • Access personal information
    • Request correction or deletion
    • Know how data is used and disclosed
    • Opt out of the sale or sharing of personal information
    • Limit use of sensitive personal information

    Sale/Sharing Disclosure: KORT does not sell personal information. We may share limited data with analytics and advertising providers, which may be considered “sharing” under certain laws.

    Requests can be submitted via email or the relevant web form(s):

    We respond within 30 days after verifying identity, in compliance with regulated timeframes.

    16. Cookies and Tracking

    We use cookies and similar technologies for:

    • Site functionality
    • Security
    • Analytics and performance

    Users can control cookies through browser settings.

    17. Children’s Privacy

    Our services are not intended for individuals under 16, and we do not knowingly collect data from children.

    18. Changes to This Policy

    We may update this Privacy Policy periodically. Updates will be posted with a revised “Last Updated” date.

    19. Contact and Complaints

    All Privacy-related enquiries or complaints are to be sent to:

    Attention: Chief Privacy Officer KORT Payments Inc.

    Canadian individuals may contact the Office of the Privacy Commissioner of Canada.

    U.S. residents may contact applicable state regulators, including the California Privacy Protection Agency.