Privacy policy
What personal data WinkPG processes, why it processes it, who it shares it with and what rights you have over it.
The WinkPG platform default. An operator may replace it with their own text. Last reviewed 20 September 2026.
Who this policy covers
WinkPG is a payment gateway. It processes personal data in two distinct roles, and which role applies decides who you contact about your data.
As a processor, it handles cardholder and payer data on behalf of the merchant you paid. The merchant decides what is collected and why. Direct a request about a payment you made to that merchant.
As a controller, it handles the data of the people who use the platform itself: merchant staff, reseller staff, administrators and developers with portal accounts. This policy is written for that role, and it describes the processor role so that a payer reading it knows where to go.
What is collected
Account data: name, work email address, phone number, the roles you hold and the merchants you may act for.
Authentication data: a hashed password, the second factors you enroll, and the sessions and devices you have signed in from.
Usage data: the actions you take in the application, recorded in an audit log with the values before and after a change, and the requests your integration makes against the API.
Payment data processed on a merchant's behalf: the card or bank details a payer submits, the billing and shipping details attached to a transaction, and the result the processor returned.
Technical data: the network address a request arrived from, the browser or client that sent it, and diagnostic telemetry about how the platform performed.
Why it is processed
To provide the service: to authorize, settle and refund transactions, to run the reporting and invoicing you asked for, and to give you the application you signed in to.
To keep the service safe: to authenticate you, to screen transactions for fraud, to detect abuse, and to investigate an incident when one happens.
To meet legal and card network obligations: to retain transaction records for the period financial regulation and the card networks require, to answer a chargeback or a dispute, and to satisfy an audit.
WinkPG does not sell personal data, does not share it for cross-context behavioral advertising, and does not use it to train machine learning models.
How long it is kept
Each category has its own period, and they are listed on the data retention schedule page. Card verification values, PINs and full magnetic stripe or chip data are never stored at all.
Your rights
Depending on where you live, you may have the right to access the personal data held about you, to correct it, to have it deleted, to receive a portable copy, to object to processing, or to withdraw a consent you gave.
The platform provides an export of a user's data as structured files, and an erasure that cascades across the records referencing the account.
To exercise a right over data held about you as a platform user, contact the operator of this instance. To exercise a right over data attached to a payment you made, contact the merchant you paid: they decide what happens to it, and the platform acts on their instruction.
International transfers
Data is processed in the regions the deployment is configured for, and the subprocessor page states where each provider processes it. Where personal data moves between jurisdictions, the transfer relies on the safeguards named in the data processing addendum.
Changes to this policy
A material change is published on this page with a new review date. The date at the top of the page is the last time somebody read the whole text, not the last time a word changed.
Evidence and compliance materials
This surface states posture and publishes no evidence. The attestations, reports and control matrices behind these statements are in the trust documents catalogue, where a signed-in developer account can retrieve them and every retrieval is recorded.