Privacy Policy
Last updated: 05 January 2026
This Privacy Policy explains how Payre (“Company”, “we”, “us” or “our”), operated by Pay Atlas LLC, collects, uses, discloses and protects personal data in connection with the Services (our website and the Payre platform for managing and recovering late payments, and related services).
We comply with applicable data protection laws in the jurisdictions in which we operate. The rights and choices available to you may vary depending on where you live (see clause 16).
1. Introduction
1.1 This Policy describes how we collect, use, disclose and protect Personal Data — information about an individual who can be identified from that data — when you use, are named in, or otherwise interact with the Services.
1.2 This Policy applies to (a) Account Holders (people who register for a Payre account, including Creditors and any professional partners); (b) Debtors and Guarantors named in a Claim (a late-payment or debt-recovery matter raised through the Services); and (c) visitors to the Website.
1.3 We process Personal Data with your consent or as otherwise allowed or required by applicable data protection laws.
1.4 This Policy forms part of, and should be read together with, our Terms of Use. If you do not agree with this Policy, please discontinue use of the Services.
2. Our role as controller and intermediary
2.1 Where we act in our own right. We determine the purposes and means of processing — and are responsible as a controller under applicable data protection laws — for Account Holder and visitor information, the content of the notices and communications we send, the public business directory, and data used for fraud prevention, security and deliverability.
2.2 Where we act on a Creditor's behalf. For Debtor and Guarantor Personal Data that a Creditor submits to pursue a Claim, we process that data on the Creditor's behalf and on its instructions — acting as a data intermediary (sometimes called a “processor”) rather than deciding how the data is used ourselves. The Creditor decides what data to provide and why.
2.3 By using the Services, a Creditor confirms that it has a lawful basis and the authority to provide such Personal Data and that the data is accurate. Business customers process such data under our Terms of Use and, where applicable, a data-processing addendum.
2.4 If you are a Debtor or Guarantor and wish to understand how a Creditor uses your Personal Data, you may contact the Creditor directly; you may also contact us under clause 20.
3. Personal Data we collect
3.1 Information Account Holders provide. Identifiers and contact details such as name, email address, phone number and account or authentication identifiers (you may sign in using an email sign-in link or a third-party login such as Google). For Creditors, we also collect profile information used to raise Claims, including legal name, government-issued identification details, business registration information and payout details such as bank account or PayNow information.
3.2 Identity-verification information. Account Holders may be asked to complete an identity check performed by our verification provider, Stripe Identity. This can involve a government-issued ID and, where applicable, a selfie used for liveness and biometric matching. The biometric matching is performed by the provider; we receive the verification result and related details and do not process the raw biometric ourselves.
3.3 Information about Debtors and Guarantors. Name, contact details (email, phone and postal address), government-issued identification details where provided, and details of the underlying transaction and amounts owed. This is generally supplied by the Creditor (see clause 4).
3.4 Payment and billing information. Payments and platform fees are processed by our payment processor (Stripe). We receive limited billing and transaction records but do not store full payment card numbers ourselves.
3.5 Information in uploaded documents. Documents such as invoices, contracts, correspondence and identification or registration documents, and the Personal Data they contain, are stored and may be processed to operate the Services, including by automated and AI-based providers used to extract or verify information (see clause 11).
3.6 Information collected automatically. Technical and usage information such as IP address, device and browser characteristics, operating system, language and location, referring URLs, and information about how you interact with the Services, collected through cookies and similar technologies and through analytics and session-analysis tools.
4. Personal Data you provide
4.1 To raise and pursue a Claim, a Creditor provides us with Personal Data about the Debtor and any Guarantors. Those individuals do not register with Payre, and we generally do not collect their data from them directly. A Debtor or Guarantor may first become aware that we hold their data when we send a notice about a Claim.
4.2 The Creditor is responsible for ensuring it has a lawful basis and the authority to provide that data and that it is accurate. We use it only to administer and progress the Claim and as otherwise described in this Policy.
4.3 If you are a Debtor or Guarantor, you may exercise the rights in clause 16 (including asking what we hold and requesting correction) and may also contact the Creditor who initiated the Claim. Any notice we send will identify the matter and how to contact us.
5. How we use Personal Data
5.1 We use Personal Data to:
(a) create and administer accounts and verify identity;
(b) create, manage and progress Claims, including generating letters of demand and other case documents;
(c) facilitate communications between Creditors, Debtors, Guarantors and professional partners, and send notices, reminders and case updates (by email and SMS — see clause 7);
(d) process payments, platform fees and related invoices;
(e) operate the public business directory;
(f) protect the Services and investigate and prevent fraud or misuse;
(g) comply with legal obligations and establish, exercise or defend legal claims; and
(h) analyse and improve the Services, and send administrative and (where permitted) marketing communications.
5.2 Lawful grounds. We process Personal Data with your consent or as otherwise allowed by applicable data protection laws, including where processing is necessary to perform a contract with you, to comply with a legal obligation, or for legitimate interests — including debt recovery, managing and resolving disputes, payment transparency and fraud prevention — balanced against your rights and interests. A Debtor will not usually have provided consent; in those cases we rely on these other lawful grounds.
5.3 Automated processing. We use automated and AI-based tools to read and verify uploaded documents and organise case information, with human oversight. We do not use them to make decisions producing legal or similarly significant effects about you without human involvement.
6. Consent and withdrawal of consent
6.1 Where we rely on consent, we will seek it at or before the point of collection and will inform you of the purposes for which the data will be used.
6.2 You may be taken to have consented where you voluntarily provide Personal Data to us for a purpose that is reasonably obvious in the circumstances, or where applicable data protection laws otherwise treat consent as given.
6.3 Withdrawal. You may withdraw consent for any purpose on reasonable notice by contacting us under clause 20. We will inform you of the likely consequences; withdrawal may mean we can no longer provide part or all of the Services. Withdrawal does not affect processing carried out before withdrawal, or processing we may continue on another lawful ground or under a legal requirement.
6.4 We will not, as a condition of providing the Services, require you to consent to the collection, use or disclosure of Personal Data beyond what is reasonable to provide those Services.
7. Communications and text messaging (SMS)
7.1 We send communications relating to a Claim — an initial notice, periodic reminders, and updates when there is activity — to the relevant parties. Email is delivered through Twilio SendGrid, and SMS text messages through Twilio and other messaging providers such as Sinch.
7.2 Message frequency varies depending on the status and activity of a Claim. Message and data rates may apply. To stop receiving text messages, reply STOP to any message, and reply HELP for help; you may also respond or acknowledge on the Claim page or contact us under clause 20. Opting out of case-related messages may affect our ability to keep you informed about a Claim.
7.3 Opt-out and suppression. When you opt out, we add your number or address to a suppression list and keep the minimum information needed to honour that opt-out — that is, we retain it precisely so that we stop contacting you, not to contact you.
7.4 No mobile information (including mobile phone numbers and SMS consent) is sold, rented or shared with third parties or affiliates for marketing or promotional purposes. Mobile information may be shared only with our messaging providers strictly to deliver the messaging service, and as required by law. Where we send marketing messages, we do so in accordance with applicable marketing and anti-spam laws and we honour do-not-contact requests.
8. Information visible to other parties
8.1 Because a Claim concerns a dispute between parties, information relevant to it is shared among the people involved. For example, a Debtor or Guarantor is shown the Creditor's identity and the Claim details, and the Creditor receives responses, acknowledgements and updates. We share only what is relevant to the Claim.
8.2 A party who receives information through the Services must not use it for any purpose unrelated to the Claim — including marketing, building contact lists or harassment — unless the other party has expressly agreed. Misuse may lead to suspension and other action.
9. Public business directory
9.1 Business profiles, payment ratings and reviews may be public. Information made public may be seen by other users, indexed by search engines, and copied or reused by others in ways we do not control. Please do not include sensitive or confidential information in areas designated as public.
9.2 If you believe information about your business in the directory is inaccurate or should not appear, you may contact us under clause 20 to request correction or removal. We review such requests and act as appropriate and as required by applicable law.
10. Disclosure of Personal Data
10.1 Service Providers. Vendors that perform services for us under contracts limiting their use of the data — see clause 11.
10.2 Parties to a Claim. As described in clause 8.
10.3 Professional partners. Where a Claim is supported or co-managed by an accountant or lawyer, we share the case information necessary for them to act.
10.4 Contractors and consultants. We may engage contractors and consultants (including via freelance platforms) to support our operations; they access Personal Data only as needed and are bound by confidentiality and data-protection obligations.
10.5 Legal, safety and business transfers. To comply with law or legal process; to protect our rights, users or the public; to investigate or prevent fraud; and in connection with a merger, acquisition, financing or sale of assets.
10.6 We do not sell your Personal Data, and we do not share it with third parties for their own marketing purposes.
11. Service providers as sub-processors
11.1 We engage the following categories of Service Providers, with representative providers shown in brackets:
(a) hosting and infrastructure, to run and serve the platform (Vercel);
(b) database, authentication and file storage (Google Firebase / Google Cloud);
(c) payments and identity verification (Stripe, including Stripe Identity);
(d) email delivery (Twilio SendGrid);
(e) SMS and messaging (Twilio, and other messaging providers such as Sinch);
(f) document processing and AI, to extract and verify information from uploaded documents (Google generative AI);
(g) analytics and product improvement (Google Analytics and session-analysis tools);
(h) customer support and live chat;
(i) sales and customer-relationship management (CRM tools such as Pipedrive);
(j) network security and delivery (Cloudflare);
(k) professional partners who co-manage or act on a Claim (accountants and lawyers); and
(l) contractors and consultants who support our operations under confidentiality obligations, including via freelance platforms such as Upwork.
11.2 You may review the privacy notices of our key providers: Stripe, Twilio, Twilio SendGrid, Google, Vercel and Cloudflare.
11.3 Providers are named as representative examples of each category and may change as the Services evolve. We will update this clause and the “Last updated” date accordingly.
12. Cookies and similar technologies
12.1 We and our Service Providers use cookies and similar technologies (web beacons, pixels, local storage and session-analysis tools) to keep you signed in, remember preferences, understand how the Services are used and improve them. Some are set by third parties. Most browsers let you refuse or delete cookies; disabling them may affect certain features.
13. Transfer of Personal Data
13.1 We use Service Providers located in various countries, and Personal Data may be transferred to, stored in, or processed in countries other than your own, including the United States, the European Economic Area, the United Kingdom and elsewhere.
13.2 Where we transfer Personal Data across borders, we use the safeguards required by applicable data protection laws, which may include standard contractual clauses, reliance on an approved transfer framework where a provider is certified, and other measures designed to ensure a comparable standard of protection. Details can be provided on request.
14. Retention of Personal Data
14.1 We keep Personal Data only as long as necessary for the purposes in this Policy or as required by law. Indicative periods are:
(a) account and profile information — for as long as you have an account, then deleted or anonymised after closure, subject to clause 14.2;
(b) Claim records and case documents — for the duration of the matter, then for the applicable limitation period and to meet legal, accounting and evidentiary needs;
(c) identity-verification results — as long as needed to evidence verification and prevent fraud;
(d) messaging opt-outs (suppression list) — until you ask us to remove it, so we can continue to honour your opt-out;
(e) analytics and security logs — a limited period for security, troubleshooting and improvement; and
(f) marketing preferences — for as long as you remain opted in.
14.2 When we no longer have a legitimate need to process your Personal Data, we delete or anonymise it, or securely isolate it from further processing until deletion is possible.
15. Security and data breaches
15.1 We implement appropriate administrative, technical and physical measures designed to protect Personal Data, including encryption in transit. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please keep your account credentials confidential and access the Services in a secure environment.
15.2 If a data breach occurs that meets the notification thresholds under applicable data protection laws, we will notify the relevant data protection authority and affected individuals as and when required.
16. Your rights
16.1 Depending on the data protection laws applicable to you, you may have some or all of the following rights in respect of your Personal Data:
(a) to access the Personal Data we hold about you and information about how it has been used or disclosed;
(b) to correct inaccurate or incomplete data;
(c) to withdraw consent, where we rely on it (see clause 6);
(d) to request deletion or anonymisation of your data;
(e) to restrict or object to certain processing;
(f) to data portability;
(g) to opt out of the sale or sharing of Personal Data (we do not sell your Personal Data); and
(h) to lodge a complaint with the relevant data protection authority.
16.2 The specific rights available to you, and how they apply, depend on the data protection laws applicable to you. We will act on your request to the extent, and within the timeframes, required by those laws, and we will not discriminate against you for exercising your rights.
16.3 Debtors and Guarantors. If your data was provided by a Creditor, you may still exercise these rights with us. Because we act partly on the Creditor's instructions, we may direct certain requests to the Creditor, or verify your identity and relationship to the Claim, before acting.
17. Managing your information
17.1 You can review or update much of your account information in your settings. To access, correct or delete your data, or to close your account, email us under clause 20. We verify your identity before acting and will not request more identifying information than necessary; Debtors and Guarantors who are not Account Holders have a lighter verification path.
17.2 You may use an authorised agent, with proof of authority. If we decline a request, you may ask us to reconsider (an appeal).
17.3 Following a deletion request, we delete or anonymise your data except where we are required or permitted to retain it (for example, to comply with legal obligations, resolve disputes, prevent fraud or enforce our agreements).
17.4 Do-Not-Track and Global Privacy Control. There is no consistent standard for “Do-Not-Track” browser signals, so we do not respond to them. Where required by law, we honour recognised opt-out preference signals such as Global Privacy Control (GPC). You may also control cookies through your browser and opt out of non-essential communications.
18. Children's data
18.1 The Services are not directed to children, and we do not knowingly collect Personal Data from children under 13 (or the minimum age in your jurisdiction). If you believe a child has provided us with Personal Data, contact us and we will take steps to delete it.
19. Changes to this Policy
19.1 We may update this Policy from time to time. The updated version is indicated by a revised “Last updated” date and is effective when accessible. If we make material changes, we may post a prominent notice or contact you directly. Please review this Policy periodically.
20. How to contact us and complaints
20.1 You may contact our Data Protection Officer at legal@payre.co, or Payre, operated by Pay Atlas LLC, for the attention of the Data Protection Officer.
20.2 If you have a complaint about how we handle your Personal Data, please contact us first so we can try to resolve it. You may also complain to the relevant data protection authority in your jurisdiction.