Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Checkout.com's global privacy notice describing how the company collects and uses personal data when providing payment processing, fraud detection, and identity verification services to three groups: the businesses it works with (Merchant Representatives), the consumers who transact through those businesses (Merchant Customers), and visitors to its website. The notice discloses that Merchant Customers' biometric data, including facial images and voiceprints, is collected during identity verification, shared with Snowflake Computing and Amazon Web Services, and retained for up to 365 days, with processing conditional on explicit consent. The notice also discloses that automated decision-making is used for fraud detection and identity verification, which may result in transactions being declined or access to services being delayed or denied, and that affected individuals may have the right to request human review of those decisions depending on their jurisdiction.
This document is Checkout.com's global Privacy Notice, last updated 19 June 2026, governing how the Checkout.com group processes personal data across three distinct user categories: Merchant Representatives, Merchant Customers, and Website Users, with legal bases including legitimate interests, legal obligation, contractual necessity, and explicit consent depending on the data type and processing purpose. The notice states that Checkout collects contact information, cardholder data, transaction data, device and technical identifiers, identity verification documents, and biometric data including facial images and voiceprints, with the notice further disclosing that biometric data is shared with third-party cloud providers Snowflake Computing and Amazon Web Services and retained for up to 365 days. The biometric data collection and processing provisions, including automated identity verification and a 96-hour temporary image-hash blocking mechanism, are operationally distinct relative to standard payment processor privacy notices and engage multiple state-level biometric privacy frameworks; the notice asserts consent as the legal basis for biometric processing but the enforceability and sufficiency of that consent mechanism may vary by jurisdiction. The notice engages GDPR and UK GDPR for EEA and UK data subjects, CCPA and CPRA for California residents, the Colorado Privacy Act, Australian Privacy Principles, Brazil's LGPD, and French Law No. 78-17 Article 85, with country-specific supplements addressing supplemental rights, complaint escalation paths to the ICO, OAIC, and relevant state authorities, and SCCs or ICO-approved clauses used for international data transfers from the UK and EEA.
The agreement establishes that Merchant Customers' biometric data, including facial images and voiceprints, may be collected, processed, and shared with third-party cloud providers Snowflake Computing and Amazon Web Services, subject to explicit consent, and retained for up to 365 days before deletion. Under these terms, automated decision-making for fraud detection and identity verification may result in a transaction being declined or access to a product or service being delayed or denied, with the notice stating that affected individuals in certain jurisdictions may request human review of automated decisions. You can opt out of direct marketing at any time via the unsubscribe link in marketing emails or by contacting dpo@checkout.com, and you can submit data rights requests including access, correction, erasure, and objection to automated decisions by contacting dpo@checkout.com.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
3 important changes detected
4 versions captured · Last updated: August 2026
Checkout.com updated its privacy policy on June 19, 2026 to reorganize and expand country-specific regulatory notices. The policy adds new protections and complaint procedures for UK users, including a formal …
View change record →Checkout.com has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Automated Decision-Making for Fraud and Identity Verification and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.