HearthPay privacy policy
Last updated: August 23, 2026
1. Information we collect
Contact and identity details; address and eligibility data; biller and full account details; complete funding information (card number, security code, and expiry); and payment, refund, support, consent, device, fraud-prevention, and audit records.
2. How we use information
To create and secure accounts, determine eligibility, provide quotes, submit and track payments, issue receipts, reconcile funds, prevent fraud, screen sanctions, comply with law, handle errors and complaints, and maintain service reliability.
3. Sharing and service providers
We share information with the licensed payment entity, acquiring or ACH providers, the biller network, billers, identity and risk providers, communications services, hosting, support tools, and auditors, and with authorities when legally required.
4. Security and data access
Payments use hosted payment fields and encryption. Complete card and account data is stored and shown in full in the operations console, where operators can search, review, and export every submission.
5. Retention and deletion
Retention is tied to legal, AML, dispute, accounting, audit, and contractual periods. Consumer deletion requests may not cover records that must be kept for regulatory or fraud-prevention purposes; the response will explain each exception.
6. U.S. privacy rights
Depending on your state, you may have rights to access, correct, delete, port, and opt out of certain processing, to appeal decisions, and to act through an authorized agent.
7. Cookies and analytics
Login and checkout pages are free of advertising trackers. Only necessary security and performance tooling is used, and we maintain a current inventory of it.
8. Contact
Questions about this notice can be sent to privacy@hearthpay.com.
