Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document explicitly states that personal data processed in connection with Marqeta's issuer payment processing and card program management services is outside the scope of this Website Privacy Notice and is governed by a separate Services Privacy Notice.
This analysis describes what Marqeta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that individuals whose personal data is processed through Marqeta's payment and card program infrastructure are subject to different and separately published privacy terms, which creates a material distinction between the rights and protections described in this notice and those applicable to payment services data subjects.
Under this clause, cardholders and individuals whose data is processed through Marqeta's issuer payment processing or card program management products are not covered by this Website Privacy Notice; their data rights and Marqeta's obligations are governed by the separate Services Privacy Notice, which is not reproduced in this document.
Cross-platform context
See how other platforms handle Exclusion of Payment Processing Services from This Notice and similar clauses.
Compare across platforms →Monitoring
Marqeta has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"This Notice will also not apply to personal data Marqeta processes as part of its issuer payment processing and card program management products and services ('Payments Services').Excerpt from Marqeta's Privacy Policy
1. REGULATORY LANDSCAPE: This provision has potential relevance to CFPB oversight of payment processing data practices and Regulation P requirements for financial privacy notices applicable to consumers of financial services. GDPR may also apply to payment services data processed in the EEA, with the applicable legal basis and controller arrangements potentially differing from those described in this notice. The scope carve-out does not specify which legal bases or frameworks govern the Payments Services notice. 2. GOVERNANCE EXPOSURE: Medium. The explicit scope carve-out means that compliance assessments of Marqeta's overall data privacy posture require review of both the Website Privacy Notice and the separate Services Privacy Notice. Organizations relying on this document alone for vendor due diligence purposes may have an incomplete picture of Marqeta's data practices. 3. JURISDICTION FLAGS: The scope carve-out applies globally. Financial data privacy requirements vary significantly by jurisdiction; in the United States, the CFPB and Regulation P govern certain financial privacy notice requirements, while in the EEA, GDPR applies to payment data with specific requirements for lawful basis and data subject rights. The applicable protections for payment services data subjects depend on the content of the Services Privacy Notice, which is not reproduced here. 4. CONTRACT AND VENDOR IMPLICATIONS: B2B partners and program managers working with Marqeta's card issuing and payment infrastructure should confirm that their vendor due diligence reviews encompass the Services Privacy Notice in addition to this Website Privacy Notice. Contractual data processing agreements with Marqeta for payment services purposes should reference the applicable Services Privacy Notice rather than this document. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should obtain and review Marqeta's Services Privacy Notice as a separate document to assess the full scope of data practices applicable to payment processing relationships. Data mapping exercises for organizations that interact with Marqeta in both website and payment processing contexts should distinguish between the two notice regimes and the respective rights frameworks each provides.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that individuals whose personal data is processed through Marqeta's payment and card program infrastructure are subject to different and separately published privacy terms, which creates a material distinction between the rights and protections described in this notice and those applicable to payment services data subjects.
Under this clause, cardholders and individuals whose data is processed through Marqeta's issuer payment processing or card program management products are not covered by this Website Privacy Notice; their data rights and Marqeta's obligations are governed by the separate Services Privacy Notice, which is not reproduced in this document.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Marqeta.