Merchant Service - Privacy Policy
1. Introduction
Merchant One Group, LLC (“Merchant One Group,” “we,” “our,” or “us”) values your privacy and is committed to protecting the personal and business information you share with us.
This Privacy Policy explains how we collect, use, share, and protect your data when you submit information or upload documents to apply for or set up a merchant account.
By submitting your data through our online forms or document upload portals, you consent to the terms described below.
2. Information We Collect
We collect personal, business, and financial information necessary to evaluate and establish your merchant processing account.
A. Personal Information
Full Name
Date of Birth
Phone Number
Email Address
Residential Address
Driver’s License or Government-issued ID
B. Business Information
Legal Business Name and DBA (Doing Business As)
Business Address and Type
Federal Tax ID (EIN)
Business License or Registration Documents
Years in Business / Merchant History
Photos of retail location (if applicable)
C. Financial Information
Bank Account and Routing Numbers (for deposit and verification)
Recent Bank Statements
Tax Documents or Returns
Voided Check for funding verification
D. Technical & Website Data
IP address, browser type, and date/time of submission (for fraud prevention)
Cookies or session IDs for secure form submission tracking
3. Purpose and Use of Collected Information
Your data is used solely for legitimate business purposes, including:
Verifying your identity and business legitimacy
Processing and underwriting your merchant application
Setting up payment processing and gateway accounts
Conducting compliance checks (KYC, AML, and OFAC verification)
Communicating with you about your application and account
Meeting regulatory and anti-fraud obligations
Maintaining secure business records as required by law
We do not sell, lease, or trade your information to third parties.
4. Information Sharing and Disclosure
Your information may be shared only with:
Acquiring Banks & Payment Processors – For underwriting, risk review, and account setup.
Third-Party Service Providers – For identity verification, fraud prevention, data hosting, and support (bound by confidentiality agreements).
Government or Regulatory Bodies – When legally required to comply with state or federal law, subpoenas, or regulatory audits.
Internal Authorized Personnel – Access is strictly limited to employees who require the information to perform their job duties.
All partners and vendors we share data with must comply with PCI DSS and GLBA security requirements.
5. Compliance with Privacy Laws and Regulations
A. Texas Data Privacy Compliance
We comply with the Texas Data Privacy and Security Act (TDPSA), which grants Texas residents the right to:
Know what personal data is collected and why;
Access, correct, or delete their personal data;
Opt out of data sharing not required for service delivery.
B. PCI DSS Compliance
All sensitive financial and cardholder data is handled according to Payment Card Industry Data Security Standards (PCI DSS).
This includes:
Encrypted transmission (SSL/TLS)
Secure, access-controlled storage
Regular vulnerability scans and system audits
C. GLBA (Gramm-Leach-Bliley Act) Compliance
As a financial services entity handling nonpublic personal information (NPI), Merchant One Group adheres to the GLBA Safeguards Rule and Privacy Rule, ensuring:
Confidentiality and integrity of customer data
Protection against unauthorized access or threats
Disclosure limitations consistent with customer consent
6. Data Security
We implement multi-layered security protocols, including:
256-bit SSL encryption for all form submissions
Encrypted file storage for uploaded documents
Limited access based on role authorization
Secure backup and monitoring systems
Ongoing employee training in data privacy and cybersecurity
Despite robust measures, no electronic transmission is 100% secure. You acknowledge that submission of data online carries inherent risk, which we work diligently to minimize.
7. Data Retention
We retain your data for as long as required to:
Complete merchant underwriting and account setup
Fulfill ongoing regulatory, legal, and financial obligations
Maintain historical records for audit and compliance purposes
After the retention period, data is securely deleted, shredded, or anonymized.
8. Your Rights
You may at any time:
Request a copy of your stored information
Correct inaccurate data
Withdraw consent (where applicable)
Request deletion of data, subject to legal retention requirements
To exercise your rights, please contact:
📧 support@merchant1group.com