Legal
Privacy Policy
Effective date: 31 July 2026. Last updated: 31 July 2026. This policy applies to the Hostra website, the Hostra merchant dashboard, the Hostra mobile application and the Hostra API (together, the "Services").
1. Who we are
Hostra Financial Systems, Inc. ("Hostra", "we", "us") operates the Services and acts as the data controller for personal data described in this policy, unless stated otherwise in section 3.
Contact for privacy matters: privacy@hostracore.com. Security reports: security@hostracore.com. Postal address and, where required, the details of our EU representative and Data Protection Officer under Articles 27 and 37 GDPR are available on request at privacy@hostracore.com.
2. Personal data we process
- Account data: name, email address, password hash, merchant identifier, verification status, language and interface preferences.
- Authentication and security data: session identifiers, API key metadata (never the key itself in plain text after creation), login timestamps, IP address, user agent, two-factor state.
- Transaction data: payment amounts, currencies, transaction references (STAN, retrieval reference number, transaction identifier, ledger transaction identifier), settlement status, fees, exchange rates, counterparty wallet addresses and networks.
- Payment instrument data: card details are collected and tokenised directly by our payment processor in the browser or mobile client. Hostra receives only a token and non-sensitive metadata such as card brand, last four digits and expiry. We do not store full card numbers or CVV.
- Compliance data: information required for identity verification, sanctions and anti-money-laundering screening, and fraud prevention, where such checks apply to your account.
- Technical and usage data: device and browser information, application logs, error reports, API latency and request metadata.
- Communications: messages you send to support, and delivery metadata for transactional email.
We do not knowingly collect special categories of personal data (Article 9 GDPR) and we do not offer the Services to children under 16.
3. Controller and processor roles
For account, security, billing and website data, Hostra is the controller. Where a business customer uses the Services to process personal data of its own end users (for example payer data submitted through the API), that customer is the controller and Hostra acts as a processor on documented instructions under Article 28 GDPR. A Data Processing Agreement, including standard contractual clauses where applicable, is available at privacy@hostracore.com.
4. Purposes and legal bases
- Providing the Services, creating accounts, executing payment and settlement instructions: performance of a contract, Article 6(1)(b) GDPR.
- Security, fraud prevention, abuse detection, rate limiting and audit logging: legitimate interests, Article 6(1)(f) GDPR.
- Transactional email such as verification, password reset and security alerts: contract performance and legitimate interests.
- Anti-money-laundering, sanctions screening, tax and accounting record keeping: legal obligation, Article 6(1)(c) GDPR.
- Product analytics and service improvement in aggregated or pseudonymised form: legitimate interests.
- Marketing email or non-essential cookies, where used: consent, Article 6(1)(a) GDPR, withdrawable at any time.
- Establishing, exercising or defending legal claims: legitimate interests and legal obligation.
5. Recipients and sub-processors
We share personal data only with service providers acting on our behalf under written contracts, and with authorities where legally required. Current categories of recipients:
- Payment processing and card tokenisation providers.
- Cloud hosting, infrastructure and managed database providers.
- Transactional email delivery providers.
- Error monitoring, logging and observability providers.
- Professional advisers, auditors, and competent regulators, courts or law enforcement where a legal obligation applies.
A current list of named sub-processors is available at privacy@hostracore.com. We do not sell personal data and we do not share it for cross-context behavioural advertising.
6. International transfers
Personal data may be processed outside the European Economic Area or the United Kingdom. Where this happens, transfers are protected by an adequacy decision or by the European Commission standard contractual clauses, together with the UK International Data Transfer Addendum where relevant, and supplementary technical measures such as encryption in transit and at rest. A copy of the relevant transfer mechanism is available on request.
7. Retention
- Account and profile data: for the life of the account and up to 12 months after closure, unless a longer period is legally required.
- Transaction, settlement and ledger records: retained for the statutory financial and anti-money-laundering record-keeping period, generally 5 to 10 years depending on jurisdiction.
- Security, access and audit logs: typically 12 months, longer where needed to investigate an incident.
- Support communications: up to 24 months after the matter is closed.
- Marketing consent records: until consent is withdrawn plus the period required to evidence the withdrawal.
After the applicable period we delete the data or irreversibly anonymise it.
8. Your rights
Subject to applicable law, you have the right to:
- Access your personal data and receive a copy (Article 15 GDPR).
- Rectify inaccurate or incomplete data (Article 16).
- Erase data where the conditions are met (Article 17).
- Restrict processing (Article 18).
- Data portability in a structured, machine-readable format (Article 20).
- Object to processing based on legitimate interests, including profiling (Article 21).
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Article 7(3)).
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where permitted by Article 22, with the right to obtain human review.
- Lodge a complaint with your national supervisory authority (Article 77).
To exercise a right, write to privacy@hostracore.com. We respond within one month and may extend by two further months for complex requests, informing you of the reason. We may ask for information needed to verify your identity. Certain rights are limited where retention is required by financial-services or anti-money-laundering law.
9. Automated decision-making
Payment authorisation, risk scoring and fraud screening may involve automated processing. Where an automated decision produces a legal or similarly significant effect on you, you may request human review, express your point of view and contest the decision by contacting privacy@hostracore.com.
11. Mobile application
The Hostra mobile application processes the same categories of data as the dashboard. It may additionally request device permissions for camera access to scan a payment card or QR code, notification permission for transaction alerts, and biometric unlock handled locally by your device operating system. Permissions are optional, requested at the moment of use, and can be revoked in your device settings. The application does not collect precise geolocation, contacts, photos or advertising identifiers, and it contains no third-party advertising software development kits. Data collected in the application is not used for tracking across other companies' apps or websites.
12. Security
We apply technical and organisational measures appropriate to the risk under Article 32 GDPR, including encryption in transit, encryption at rest, key hashing, least-privilege access controls, scoped API credentials, audit logging and segregation of production environments. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Where a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours and affected individuals without undue delay where required.
13. Scope and limitations
This policy describes our data protection practices only. It does not form part of any contract of employment or service and does not create rights beyond those granted by applicable law. The Services may link to third-party websites and providers that operate under their own privacy policies, for which we are not responsible. Nothing in this policy excludes or limits liability that cannot be excluded or limited under applicable law.
14. Changes to this policy
We may update this policy to reflect changes in our Services or legal obligations. The effective date at the top of the page indicates the most recent version. Where changes are material, we notify account holders by email or through the dashboard before the changes take effect.
15. Contact
Data protection enquiries and rights requests: privacy@hostracore.com. Vulnerability reports: security@hostracore.com. You may also contact the supervisory authority in your country of residence, place of work, or the place of the alleged infringement.