(Privacy Policy updated May 21, 2026)
Table of Contents
- Introduction
- Our Role in Payment Processing
- Scope
- Information We Collect
- Identifiers
- Financial & Underwriting Information
- Transaction-Related Data
- Internet Activity
- Professional Information
- Sensitive Personal Information
- How We Collect Information
- Purposes of Use
- Consent
- Disclosure of Personal Information
- Payment Data Handling and Payment Card Industry Alignment
- Cross-Border Data Transfers
- Data Retention
- Safeguards
- SMS Terms of Service
- Individual Rights (Canada)
- U.S. Privacy Rights (Including California)
- Cookies and Tracking
- Children’s Privacy
- Changes to This Policy
- Contact and Complaints
1. Introduction
KORT Payments Inc. (“KORT”, “we”, “us”, or “our”) is an Independent Sales Organization / Member Service Provider (ISO/MSP) that refers merchants to acquiring banks and payment processors. We are committed to protecting personal information and handling it in accordance with applicable privacy laws.
This Privacy Policy complies with:
- Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA)
- S. state privacy laws, including the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
2. Our Role in Payment Processing
KORT operates as an ISO/MSP and:
- Refers merchants to acquiring banks and payment processors
- Conducts merchant underwriting and risk assessments
- Facilitates onboarding to payment networks (e.g., card brands) KORT does not:
- Act as a payment processor or acquiring bank
- Hold, receive, or control settlement funds
Funds flow directly from the customer’s payment method through the payment
processor/acquirer to the merchant.
3. Scope
This Privacy Policy applies to:
- Merchants applying for or using our services
- Individuals associated with merchant accounts
Website users and business contacts
4. Information We Collect
The personal information collected is limited to those details necessary for the purposes identified by KORT. Categories and example information include:
Identifiers
- Name, address, date of birth, email, phone number
- IP address, account identifiers
Financial & Underwriting Information
- Credit bureau reports
- Banking and financial details
- Business ownership and structure information
Transaction-Related Data
- Limited transaction metadata
- Last four digits of payment cards (where applicable)
Internet Activity
- Device and browser data
- Website usage and analytics
Professional Information
- Business name, occupation
Sensitive Personal Information
- Login credentials
- Financial and credit data used for underwriting
5. How We Collect Information
We collect personal information:
- Directly from merchants during onboarding
- From credit bureaus
- Open sources (e.g. Google, Business Directories, SEDAR)
6. Purposes of Use
We use personal information to:
- Underwrite and evaluate merchant applications
- Verify identity and assess creditworthiness
- Refer merchants to acquiring banks and processors
- Detect and prevent fraud and financial risk
- Comply with legal, regulatory, and card network requirements
- Communicate with merchants and provide support
7. Consent
We obtain meaningful consent through merchant agreements and onboarding processes.
Consent may be expressed or implied, as permitted by law. Merchants may withdraw consent, subject to legal or contractual restrictions (e.g., inability to continue services).
8. Disclosure of Personal Information
We disclose personal information to:
- Acquiring banks and payment processors
- Card networks (e.g., Visa, Mastercard, American Express)
- Credit bureaus
- Fraud prevention and risk management partners
- Service providers (e.g., cloud hosting, CRM, analytics)
- Regulators and law enforcement where required
All third parties are contractually required to safeguard personal information.
9. Payment Data Handling and Payment Card Industry Alignment
KORT does not store full primary account numbers (PANs). Payment data is:
- Transmitted securely via encrypted APIs
- Tokenized in compliance with Payment Card Industry Data Security Standards (PCI DSS)
KORT may retain:
- Tokenized data
- Last four digits of card numbers
We rely on PCI DSS-compliant service providers for payment processing and maintain appropriate safeguards within our environment.
10. Cross-Border Data Transfers
KORT operates in Canada and the United States.
Personal information may be transferred to and processed in the United States or other jurisdictions. These jurisdictions may have different privacy laws and may permit access by government authorities.
We use contractual, organizational, and technical safeguards to protect personal information.
11. Data Retention
We retain personal information only as long as necessary for:
- Merchant relationship management
- Legal and regulatory compliance (including financial reporting)
- Fraud detection and risk mitigation
Typical retention period: 7 years after cessation of relationship
12. Safeguards
We implement safeguards appropriate to the sensitivity of the information, including:
- Encryption in transit and at rest
- Role-based access controls
- Multi-factor authentication
- Logging and monitoring systems
- Vendor security due diligence
13. SMS Terms of Service
By opting into SMS from a web form or other medium, you are agreeing to receive SMS messages from KORT Payments. This includes SMS messages for conversations (external). Message frequency varies. Message and data rates may apply. Message HELP for help. Reply STOP to any message to opt out.
14. Individual Rights (Canada)
Individuals have the right to:
- Access their personal information
- Request correction
- Withdraw consent
Requests can be submitted via email: partners@kortpayments.com
15. U.S. Privacy Rights (Including California)
U.S. residents may have rights to:
- Access personal information
- Request correction or deletion
- Know how data is used and disclosed
- Opt out of the sale or sharing of personal information
- Limit use of sensitive personal information
Sale/Sharing Disclosure: KORT does not sell personal information. We may share limited data with analytics and advertising providers, which may be considered “sharing” under certain laws.
Requests can be submitted via email or the relevant web form(s):
- partners@kortpayments.com
- https://kortpayments.com/do-not-sell-or-share-my-personal-information/
- https://kortpayments.com/limit-the-use-of-my-sensitive-personal-information/
We respond within 30 days after verifying identity, in compliance with regulated timeframes.
16. Cookies and Tracking
We use cookies and similar technologies for:
- Site functionality
- Security
- Analytics and performance
Users can control cookies through browser settings.
17. Children’s Privacy
Our services are not intended for individuals under 16, and we do not knowingly collect data from children.
18. Changes to This Policy
We may update this Privacy Policy periodically. Updates will be posted with a revised “Last Updated” date.
19. Contact and Complaints
All Privacy-related enquiries or complaints are to be sent to:
Attention: Chief Privacy Officer KORT Payments Inc.
- Mail: 179 John Toronto, Ontario, M5T 1X4
- Email: partners@kortpayments.com If we are unable to resolve your complaint:
Canadian individuals may contact the Office of the Privacy Commissioner of Canada.
U.S. residents may contact applicable state regulators, including the California Privacy Protection Agency.