8 Total
2 High severity
6 Medium severity
0 Low severity
Stay ahead of the changes
Track Checkout.com and get the diff the day its terms change.
Summary

This is Checkout.com's global privacy notice describing how the company collects and uses personal data when providing payment processing, fraud detection, and identity verification services to three groups: the businesses it works with (Merchant Representatives), the consumers who transact through those businesses (Merchant Customers), and visitors to its website. The notice discloses that Merchant Customers' biometric data, including facial images and voiceprints, is collected during identity verification, shared with Snowflake Computing and Amazon Web Services, and retained for up to 365 days, with processing conditional on explicit consent. The notice also discloses that automated decision-making is used for fraud detection and identity verification, which may result in transactions being declined or access to services being delayed or denied, and that affected individuals may have the right to request human review of those decisions depending on their jurisdiction.

Analysis

This document is Checkout.com's global Privacy Notice, last updated 19 June 2026, governing how the Checkout.com group processes personal data across three distinct user categories: Merchant Representatives, Merchant Customers, and Website Users, with legal bases including legitimate interests, legal obligation, contractual necessity, and explicit consent depending on the data type and processing purpose. The notice states that Checkout collects contact information, cardholder data, transaction data, device and technical identifiers, identity verification documents, and biometric data including facial images and voiceprints, with the notice further disclosing that biometric data is shared with third-party cloud providers Snowflake Computing and Amazon Web Services and retained for up to 365 days. The biometric data collection and processing provisions, including automated identity verification and a 96-hour temporary image-hash blocking mechanism, are operationally distinct relative to standard payment processor privacy notices and engage multiple state-level biometric privacy frameworks; the notice asserts consent as the legal basis for biometric processing but the enforceability and sufficiency of that consent mechanism may vary by jurisdiction. The notice engages GDPR and UK GDPR for EEA and UK data subjects, CCPA and CPRA for California residents, the Colorado Privacy Act, Australian Privacy Principles, Brazil's LGPD, and French Law No. 78-17 Article 85, with country-specific supplements addressing supplemental rights, complaint escalation paths to the ICO, OAIC, and relevant state authorities, and SCCs or ICO-approved clauses used for international data transfers from the UK and EEA.

What this means for you

The agreement establishes that Merchant Customers' biometric data, including facial images and voiceprints, may be collected, processed, and shared with third-party cloud providers Snowflake Computing and Amazon Web Services, subject to explicit consent, and retained for up to 365 days before deletion. Under these terms, automated decision-making for fraud detection and identity verification may result in a transaction being declined or access to a product or service being delayed or denied, with the notice stating that affected individuals in certain jurisdictions may request human review of automated decisions. You can opt out of direct marketing at any time via the unsubscribe link in marketing emails or by contacting dpo@checkout.com, and you can submit data rights requests including access, correction, erasure, and objection to automated decisions by contacting dpo@checkout.com.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

3 important changes detected

4 versions captured · Last updated: August 2026

What changed Checkout.com's privacy policy footer was updated on August 1, 2026 to add an 'Early Careers #NextGen' link and associated tagline ('Your future starts here' and 'Learn, grow and make an impact from day one') in the Careers section of their website navigation. This is a navigation and recruitment messaging change, not a material change to privacy practices or data handling terms.
Why this matters This change does not materially affect consumer privacy rights, data handling, or terms of service. The update adds recruitment-focused navigation links and messaging to Checkout.com's website footer. It is a website navigation change, not a change to privacy practices or consumer data protection terms.
View full change record →
What changed Checkout.com's updated privacy policy adds explicit disclosure that call recordings with merchant representatives are used for training, product development, and marketing purposes. Previously, the policy did not disclose this specific use of recorded conversations. The updated language now requires merchants to be aware that their calls may be recorded and used beyond the immediate transaction or support context.
Why this matters The updated privacy policy now explicitly states that Checkout.com uses recordings of calls with merchant representatives for training, product development, and marketing purposes. Previously, this specific use case was not disclosed in the policy. Merchants should be aware that conversations with Checkout support staff may be recorded and used beyond immediate transaction or support contexts. The updated language does not indicate that consent mechanisms or opt-out procedures are available.
View full change record →

June 19, 2026 medium

Checkout.com updated its privacy policy on June 19, 2026 to reorganize and expand country-specific regulatory notices. The policy adds new protections and complaint procedures for UK users, including a formal …

View change record →
Featured, High severity
Featured, Medium severity
Stay ahead of the changes

Monitoring

Checkout.com has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Automated Decision-Making for Fraud and Identity Verification and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured August 1, 2026 01:16 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000663
Version ID CA-V-005449
SHA-256 42493fc4beb2060858de04177b2f53c6d50b6688e5ccf1f2f6e172a149d03111
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans