Privacy policy
Last updated: 3 September 2026
Firstguard Limited ("Firstguard", "we", "us", "our")
This Privacy Policy explains how Firstguard Limited processes personal data when you use our pay-by-bank payment platform (the "Service"), visit our website, or do business with us as a merchant.
1. Who we are
Firstguard Limited ("Firstguard") is a company incorporated in the United Kingdom, registered under company number 16735496, with its registered office at:
124–128 City Road, London, England, EC1V 2NX, United Kingdom
Firstguard is the data controller for the personal data described in this Privacy Policy, unless stated otherwise.
For privacy-related questions or requests, you can contact us at: info@firstguardlimited.com
We are establishing a Dutch entity that will take over the operation of the Service for the European Economic Area. If and when the operating entity changes, this Privacy Policy will be updated and the new controller will be identified here.
2. Licensed payment provider in the payment flow
Firstguard Limited is not a licensed payment institution.
Regulated payment initiation services provided through the Service are provided by Salt Edge as a licensed payment institution.
The exact Salt Edge contracting entity, licence details and supervisory authority will be identified in this Privacy Policy before the Service goes live.
When you authorise a payment through our checkout, Salt Edge connects to your bank under the applicable EU payment services legislation, including PSD2, and initiates the credit transfer on your instruction.
Salt Edge acts as an independent data controller for the personal data it processes when providing the regulated payment service. Its processing is described in its own privacy policy.
Your bank remains an independent data controller for the personal data it processes when authenticating you and executing the payment.
Firstguard does not receive, see or store your online banking credentials. Authentication takes place directly between you and your bank in your bank's own environment, such as its website or mobile application.
3. Whose data we process
We process personal data relating to the following categories of individuals:
- Payers: customers of merchants who make payments through our checkout.
- Merchants: businesses using the Service to receive payments, including their representatives, directors and ultimate beneficial owners.
- Website visitors: individuals who visit our website or contact us.
4. What data we process, why we process it and our legal basis
4.1 Payers
Payment instruction data
This may include the payment amount, currency, payment reference, order identifier and the name of the merchant being paid.
Purpose: To create, process and identify the payment instruction and provide the correct checkout experience.
Legal basis: Performance of a contract or steps taken at the request of the payer before entering into a contract (GDPR Article 6(1)(b)).
Bank selection data
This may include the bank and country selected by the payer during checkout.
Purpose: To route the payer to the appropriate bank through Salt Edge.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)).
Payment outcome data
This may include payment status information such as initiated, authorised, executed, settled, failed or cancelled. Where made available by the bank or payment provider, this may also include the payer's name and IBAN.
Purpose: Confirming payments, reconciliation, payment enquiries and, where applicable, refunds.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)) and legitimate interests (GDPR Article 6(1)(f)) in ensuring accurate reconciliation and payment handling.
Technical and security data
This may include IP address, device and browser information, timestamps, session identifiers and security logs.
Purpose: Operating and securing the Service, preventing fraud and abuse, and diagnosing technical problems.
Legal basis: Legitimate interests (GDPR Article 6(1)(f)) and, where applicable, compliance with legal obligations (GDPR Article 6(1)(c)).
We do not use payer data for targeted marketing, profiling or sale of personal data.
4.2 Merchants, representatives and ultimate beneficial owners
Company and contact data
This may include legal name, company registration number, business address, website, contact persons and business contact details.
Purpose: Merchant onboarding, contract administration, account management and customer support.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)).
KYB and verification data
This may include identification information, identity documents, dates of birth, nationality, residential address, ownership structure, licences and results of sanctions, politically exposed person and adverse-media screening.
Purpose: Merchant verification, prevention of financial crime, compliance with applicable anti-money-laundering and counter-terrorist-financing requirements, and fulfilment of onboarding requirements imposed by our regulated payment partner.
Legal basis: Compliance with legal obligations (GDPR Article 6(1)(c)) and legitimate interests (GDPR Article 6(1)(f)) in preventing financial crime and maintaining a secure payment platform.
Settlement data
This may include the merchant's IBAN and account holder name.
Purpose: Directing payments to the merchant's designated bank account.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)).
Transaction and account data
This may include transaction information, payment status, fees, dashboard login email, hashed passwords and dashboard activity logs.
Purpose: Providing the merchant dashboard, reporting, invoicing, fraud and risk monitoring and account security.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)) and legitimate interests (GDPR Article 6(1)(f)).
4.3 Website visitors
Server logs
We may process IP addresses, requested pages, timestamps and browser information.
Purpose: Operating, securing and debugging the website.
Legal basis: Legitimate interests (GDPR Article 6(1)(f)).
Contact enquiries
When you contact us, we process the information you provide, including your email address and the content of your message.
Purpose: Responding to your enquiry and managing communications with you.
Legal basis: Performance of a contract or pre-contractual measures where applicable (GDPR Article 6(1)(b)), or legitimate interests (GDPR Article 6(1)(f)).
Cookies and browser storage
Our website does not use analytics, advertising, marketing or tracking cookies.
We do not use Google Analytics, Google Ads conversion tracking, Meta/Facebook Pixel, Google Tag Manager, chat widgets or reCAPTCHA.
The website uses:
| Technology | Purpose | Retention |
|---|---|---|
googtrans functional cookie | Remembers a language selected by the visitor through the website language selector | Up to 1 year |
wpEmojiSettings session storage | Technical WordPress functionality relating to emoji support | Until the browser session ends |
| Checkout session cookies | Strictly necessary technical cookies required for the payment flow to function | Session duration |
The googtrans cookie is placed only when a visitor actively selects another language using the language selector.
The website does not use non-essential analytics, advertising or tracking technologies.
Google Translate
The website's language translation function uses Google Translate.
When a visitor actively uses the language selector, the visitor's browser connects to Google to provide the requested translation. This may involve Google processing the visitor's IP address and the content of the page being translated.
Google acts as an independent controller for its own processing.
5. Sources of personal data
We may obtain personal data:
- directly from you;
- from the merchant whose goods or services you are paying for;
- from your bank through Salt Edge in connection with the payment flow;
- from public company registers;
- from sanctions and other legally relevant screening lists; and
- from merchant verification and screening providers.
6. Who we share personal data with
Personal data may be shared with the following categories of recipients where necessary for the purposes described in this Privacy Policy:
- Salt Edge, which provides the regulated payment initiation service as a licensed payment institution and acts as an independent data controller for its processing.
- The payer's bank, which authenticates the payer and executes the payment as an independent data controller.
- The merchant being paid, which may receive payment information such as the payment amount, reference, payment status and, where made available, the payer's name and IBAN for reconciliation, delivery of goods or services and refunds.
- Hosting and infrastructure providers, including SiteGround (SiteGround Spain S.L.), providing hosting, database, backups and related infrastructure. The relevant infrastructure is located in Germany (EU), using Google Cloud infrastructure.
- Google LLC, when a visitor actively uses the Google Translate functionality described in Section 4.3.
- Email services, where necessary to receive and respond to communications sent to info@firstguardlimited.com.
- Merchant verification and screening providers, where necessary for KYB, sanctions and financial-crime compliance.
- Competent authorities, including tax, law-enforcement, judicial, supervisory and financial-intelligence authorities, where disclosure is required by law.
- Professional advisers, including lawyers, accountants and auditors, where necessary and subject to appropriate confidentiality obligations.
Where third-party service providers process personal data on our behalf, we require appropriate contractual and organisational safeguards in accordance with applicable data-protection law.
We do not sell personal data and we do not share personal data with third parties for their own marketing purposes.
7. International transfers
The Service is directed at payers and merchants in the European Economic Area.
Our website, database and backups are hosted in the European Union, with the relevant server infrastructure located in Frankfurt, Germany (Google Cloud europe-west3).
Because Firstguard Limited is established in the United Kingdom, personal data may be transferred between the EEA and the UK where necessary for operating the Service.
Such transfers are based on the European Commission's adequacy decision for the United Kingdom where applicable.
Where personal data is transferred to a country without an applicable adequacy decision, Firstguard will use an appropriate legal transfer mechanism, such as the European Commission's Standard Contractual Clauses, together with any supplementary measures required by applicable law.
8. How long we keep personal data
We retain personal data only for as long as necessary for the purposes for which it was collected, including compliance with legal, accounting and financial-crime obligations.
| Category | Retention period |
|---|---|
| Payment and transaction records | 5 years after the end of the relevant transaction or business relationship, or longer where required by applicable AML, bookkeeping or tax legislation |
| Merchant KYB and screening records | 5 years after the end of the business relationship, or longer where required by applicable law |
| Payer technical and security logs | 12 months, unless a longer period is necessary for a specific security incident, investigation or legal obligation |
| Website server logs | 90 days |
| Contact enquiries | For as long as necessary to handle the enquiry and normally no longer than 2 years after the last contact, unless a longer period is required because the enquiry results in a contractual or legal relationship |
googtrans functional cookie | Up to 1 year |
wpEmojiSettings session storage | Until the browser session ends |
| Checkout session cookies | For the duration of the relevant session |
Where applicable, records may be retained for a longer period where required by bookkeeping, tax, AML/CTF, fraud-prevention or other legal obligations.
Once the applicable retention period has expired, personal data will be securely deleted or irreversibly anonymised.
9. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.
These measures include, where appropriate:
- TLS encryption for data transmitted over the internet;
- encryption of data at rest;
- role-based access controls;
- need-to-know access;
- multi-factor authentication for administrative access;
- logging and monitoring of production systems;
- separation of development and production environments; and
- periodic review of security measures.
Bank authentication credentials are not transmitted through or stored by Firstguard.
10. Your rights
Subject to applicable law, you have the right to:
- access your personal data;
- request correction of inaccurate or incomplete personal data;
- request erasure where the legal conditions are met;
- request restriction of processing;
- object to processing based on legitimate interests;
- request data portability where the legal conditions are met; and
- withdraw consent where processing is based on consent.
Certain rights may be limited where Firstguard is legally required to retain personal data.
To exercise your rights, contact: info@firstguardlimited.com
We normally respond within one month of receiving a request. Where permitted by law, this period may be extended by up to two additional months where the request is complex.
We may request information necessary to verify your identity.
Where processing is carried out directly by Salt Edge or your bank as an independent controller, you should normally exercise your rights directly with that organisation. If you contact Firstguard regarding such processing, we will assist in directing your request to the appropriate controller where reasonably possible.
11. Complaints
If you have concerns about our processing of personal data, please contact us first at: info@firstguardlimited.com
You also have the right to lodge a complaint with the competent data protection supervisory authority.
For individuals in the Netherlands, this is the Autoriteit Persoonsgegevens.
For individuals in Belgium, this is the Gegevensbeschermingsautoriteit / Autorité de protection des données.
For matters falling under UK data-protection law, the relevant supervisory authority is the Information Commissioner's Office (ICO).
12. Automated decision-making
Firstguard does not currently make decisions about payers based solely on automated processing that produce legal or similarly significant effects.
If automated processing is introduced that can result in such decisions, this Privacy Policy will be updated to explain the relevant processing and applicable rights.
13. Children
The Service is intended for adults and businesses.
We do not knowingly collect personal data from children under the applicable minimum age for consent to information-society services.
If you believe that a child has provided personal data to us, please contact info@firstguardlimited.com.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our data-processing activities or applicable legislation.
The current version will always be published on our website together with its date of last update.
Where required, material changes will be communicated through appropriate channels.
Firstguard Limited
Company number: 16735496
Registered office: 124–128 City Road, London, England, EC1V 2NX, United Kingdom
Privacy contact: info@firstguardlimited.com