Privacy policy

Last updated: 27 July 2026

This policy sets out the basis on which Counting Ltd (“Countingup”, “we”, “us”, “our”) and our financial service partners (which may include Griffin Bank Ltd, TransactPay Ltd, or Prepay Technologies Ltd, depending on your account) will process any personal data about you that we collect from you or third parties, or that you provide to us, under the Data Protection Act 2018 (including the General Data Protection Regulation (EU) 2016/679 as implemented in the UK (“UK GDPR”), and any replacement statute from time to time (the “DPA”). 

Words beginning with a capital letter that are not defined where they first appear in this policy will have the meaning given to them in the applicable Terms for Countingup Customers at https://countingup.com/terms-countingup/, as the case may be (“Service Terms”), which include this policy and govern your use of the Countingup services (“Services”).

  1. Details of the Data Controllers

Counting Ltd (trading as ‘Countingup’), company number 10729748, has its registered address at 20-22 Wenlock Road, London, N1 7GU and is registered with the Information Commissioner’s Office with reference number ZA274056.

When Countingup is the Data Controller Countingup acts as an independent Data Controller for the personal data collected to provide our core app services, platform analytics, marketing, fraud detection, and accounting features (such as VAT return preparation and submission to HMRC)

When Countingup is the Data Processor For specific regulatory account activities—such as transmitting your Know Your Customer (KYC) data, initiating account creation, or executing cardholder servicing actions—we act as a Data Processor on the instructions of our regulated partners

Our Key Partners as Independent Data Controllers Countingup partners with different financial institutions to provide your account and card services depending on when you opened your account and whether you have migrated to our new banking platform. The companies listed below act as independent Data Controllers for the personal data shared with them to operate your regulated accounts and cards. If you wish to exercise your data rights regarding the services they provide, they can be contacted directly.

Griffin Bank Ltd (Griffin): If your account sort code is 04-36-15, your bank account is provided by Griffin Bank Ltd. Griffin determines the purposes and means for deposit-taking, AML checks, FSCS protection, and regulatory reporting. You can review how Griffin handles your data in their privacy policy here.

TransactPay Ltd (TransactPay): If your account sort code is 04-36-15, TransactPay is the independent Data Controller and issuer of your Countingup card. They are responsible for cardholder data related to card issuing, AML, and card scheme reporting. You can review how TPL handles your data in their privacy policy in Annex C of this document.

Prepay Technologies Ltd (PPT): For customers with sort code 23-69-72, your e-money account and card are provided by Prepay Technologies Ltd. PPT is the Data Controller in relation to your Card and Account, including allowing you to receive, activate and use your Card, and meeting legal requirements. You can review how PPT handles your data in their privacy policy here.

2. Information we collect about you, for what purposes and on what legal basis

In the course of providing the Services, we may collect and process the personal data specified in Annex A, for the relevant purpose and on the relevant legal basis also specified in that Annex. 

Where relevant to your application for the Services, we and our financial service partners may check your details with a fraud prevention agency/agencies and credit reference agencies and if you give false or inaccurate information and fraud is identified, this will be recorded and may be shared by those agencies with other organisations and us, so that we and those other organisations, including law enforcement agencies and debt collection agencies, may access, use and search these records to check the details provided to us in the course of your application for an account.. 

The personal information we have collected from you (specified in Annex A) will be shared by us and our partners with fraud prevention agencies who will use it to prevent fraud and money-laundering and to verify your identity. If fraud is detected, you could be refused certain services, finance, or employment. Further details of how your information will be used by us and fraud prevention agencies, and your data protection rights, can be found here.  Please contact us through secure messaging in the app (or by email at support@countingup.com) if you want to receive additional details of the relevant fraud prevention agencies. 

More information about credit reference agencies, their role as fraud prevention agencies, the data they hold, for how long, your rights and how they use personal data is available at the following links to each agency’s Credit Reference Agency Information Notice:

TransUnion (formerly Call Credit): www.transunion.co.uk/crain

Equifax: www.equifax.co.uk/crain

Experian: www.experian.co.uk/crain

Any credit reference agency we search will keep a record of any search, and other financial service providers may use it to assess applications they receive from you in the future. 


3. Your rights

Your rights under the DPA(where Countingup acts as the Data Controller) and how to exercise them are explained in the table in Annex B to this policy. (where Countingup acts as the Data Controller). This policy explains your right of access. 

Our Services may, from time to time, contain links to and from the websites of partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

We aim to keep your personal data up-to-date, so please advise us of any changes through secure messaging in the app (or by email at support@countingup.com). 

You must notify us through secure messaging in the app (or by email at support@countingup.com) within thirty days if there is any change in your name, residential address, telephone number, e-mail address, and any other details that we may reasonably consider to be material to our dealings with you.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.


4. Disclosure of your information

We will keep your personal data confidential and only disclose it to others for the purposes explained in Annex A to this Policy.  As part of your application and onboarding, the identity and corporate verification data we collect (including data for company formation and accounting services) is shared directly with our financial service partners (Griffin Bank Ltd, TransactPay Ltd, or Prepay Technologies Ltd, depending on your account). This allows our partners to fulfill their own independent legal and regulatory obligations for Anti-Money Laundering (AML), Customer Due Diligence, and account operation


5. Storing and transferring your data

The personal data that we collect will be stored in the UK and may be transferred to, and stored at, a destination inside the European Economic Area (EEA). As we provide an international service your data may be processed outside of the UK and the EEA in order for us to fulfil our contract with you to provide the Services. We and our partners will need to process your personal data in order for us, for example, to action a request made by you to execute an international payment, process your payment details, carry out anti- money laundering and counter-terrorist financing checks and provide ongoing support services. Whenever we or our partners transfer your personal data outside of the UK or the EEA, we ensure it is protected by using appropriate legal safeguards, such as adequacy decisions or standard contractual clauses approved by the relevant authorities

Where we have given you (or where you have chosen) a password that enables you to access certain parts of our App and/or our Site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.

Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised and unlawful access and processing, as well as accidental loss, destruction or damage. We use sophisticated website encryption technology to protect sensitive data that you submit to us online. We use this technology to reduce the risk of your data being intercepted by unauthorised persons during transmission. However, the transmission of information via the Internet or other public networks is not completely secure and, while we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our Services and any transmission is at your own risk.


6. Data retention

Your personal data will be stored by us for the duration of the Service Terms and any other agreement that we have with you, and for such time after that as required by Applicable Law or the limitation period for bringing claims under those agreements.

Countingup is required under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 to retain personal data about you and your transactions for a period of five years from the last transaction or end of the business relationship. We are also under other regulatory obligations to retain your data for a certain amount of time , including under the Payment Services Regulations 2017 and the rules of the Financial Conduct Authority (FCA). We will not hold any of your personal data for more than 6 years after the termination of our business relationship, unless we are compelled to do so by a regulatory body or law enforcement agency.

Please note that our financial service partners (Griffin Bank Ltd, TransactPay Ltd, and Prepay Technologies Ltd) are independent Data Controllers and are subject to their own legal and regulatory obligations regarding data retention. Depending on the partner providing your account or card, they may be required to retain your personal data for longer periods (for example, up to 7 or 10 years to fulfill financial crime prevention and banking obligations). For specific details on how long our partners retain your data, please refer to their respective privacy policies linked in Section 1.


7. Support, Complaints and Our Data Protection Officer

All questions relating to our use of your personal data and your privacy are welcomed and should be addressed to our support team through secure messaging in the app (or by email at support@countingup.com)

You have certain rights under the Data Protection Act and we have explained these and how you may exercise them in section 3 above.

Helpful guidance generally may also be found on Information Commissioner’s Office (“ICO”) website here: https://ico.org.uk/for-the-public/.

We have also appointed a data protection officer, who has a number of important responsibilities in connection with this policy.

You can contact our data protection compliance manager at: legal@countingup.com 

If you have a question or complaint specifically regarding how our financial service partners (Griffin Bank Ltd, TransactPay Ltd, or Prepay Technologies Ltd) handle your personal data, you can contact their respective Data Protection Officers directly using the contact details provided in their privacy policies linked in Section 1.

You have the right to make a complaint about our collection or use of your personal data at any time to the Information Commissioner’s Office (ICO) at www.ico.org.uk. We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance at support@countingup.com.


8. Changes to Privacy Policy

We may make changes to this policy on the same basis as changes to the Service Terms. 

Any changes we may make to our privacy policy in the future will be posted on this page and, where appropriate, notified to you by email (or SMS). The new terms may be displayed on-screen and you may be required to read and accept them to continue your use of the App or the Services.

Please note that our financial service partners (Griffin Bank Ltd, TransactPay Ltd, and Prepay Technologies Ltd) also regularly review and update their own independent privacy policies. We encourage you to review their most current terms using the links provided in Section 1.


9. Cookies

This section sets out our policy on cookies and any personal data collected by us through their use (“Cookie Policy”). 

What are cookies?

Cookies are data files containing small amounts of information which are downloaded to the device or browser you use when you visit a website. Cookies are then sent back to the originating website on each subsequent visit, or to another website which recognises that cookie. 

Please note that we can also collect information about Service usage from data contained in “log files” from third parties. Log files are not cookies; they do not contain any personal data; and they are not used to identify your personal use of the Service. When you request any web page from the Service, web servers automatically obtain your domain name and IP address, but they reveal nothing personal about you and that data is only used to examine Service traffic in aggregate, to investigate abuse of the Service and its users, and/or to cooperate with law enforcement. Such data is not disseminated to third parties, except in aggregate.

How do we use cookies?

We use cookies in order to ensure our Services function correctly and to improve our understanding of how they are used in order to make improvements.  Cookies cannot harm your computer or other device.  

What cookies do we use?

Firstly, we explain what each type is and then below, we have stated which types we actually use. In general, there are four different types of cookies.

  • Necessary cookies: those required for the operation of our Services, which do not gather information about you that could be used for marketing or remembering where you have been on the internet.
  • Analytical/performance cookies: these allow us to collect information about how you use our Services, such as, how you move around our website and if you experience any errors. These cookies do not collect personal data. The information collected is anonymous and is only used to help us improve the way the Services work, understand what interests our users generally and measure how effective our advertising is.  Some of the performance cookies we use are issued as part of services provided by third parties, like Google Analytics.
  • Functionality cookies: these are used to provide services or to recognise you when you return to our website, for example. These would enable us to personalise our content for you, greet you by name and remember your preferences and improve your visit.
  • Targeting cookies: these record your visit to the Service, the pages you have visited and the links you have followed. They are linked to services provided by third parties, such as “Like” and “Share” buttons. The third party provides these services in return for recognising that you have visited our website and are subject to the privacy policy of the third party who set them (e.g. a social media or network service). The third party may subsequently use information about your visit to target advertising to you on other websites and present you with advertisements that you may be interested in.

How do I manage my cookie settings

Please note that configuring your computer and/or mobile browser to reject ‘necessary’, ‘performance’ or ‘functional’ cookies may severely impact your experience on our website and some parts of our Services will not function at all.

All browsers provide tools that allow you to control how you handle cookies: accept, reject or delete them. These settings are normally accessed via the ‘settings’, ‘preferences’ or ‘options’ menu of the browser you are using, but you could also look for a ‘help’ function or contact the browser provider. To manage your cookies, please go to your web browser settings for example to edit Chrome cookie settings you can use this link (chrome://settings/). 

You should check the privacy policy and tools provided by any third party service you may use that set Targeting cookies on your browser or device.

10. General

This Privacy Policy shall be governed by and construed in accordance with English law and the parties agree that the courts of England shall have exclusive jurisdiction to decide any dispute arising under it, except that you may bring proceedings in the courts of Northern Ireland or Scotland if you are resident in either of those jurisdictions.

Annex A

Personal data collected

Purpose

Basis for processing

(lettering aligned to GDPR regulations where relevant)

a) Information you give us “Submitted Information”: This is information you give us about you by filling in forms or on the App and/or the Site, including information and images you may upload, or by corresponding with us (for example, by e-mail or). It includes information you provide when you register for an account, subscribe to any of our services, enter into any transaction, participate in discussion boards or other social media functions, enter a competition, promotion or survey and when you report a problem with your account, the Services, or the Site. If you contact us, we will keep a record of that correspondence, and may use redacted information for other services. The information you give us may include your name, address, date of birth, e-mail address, phone number, username, password and other registration information, financial, details of your account including the bank account number, sort code, IBAN, details of your debit and credit cards including the long number, relevant expiry dates and CVC, identification document numbers, copies of identification documents (for example, passport, driving licence and utility bill) personal description and photograph and any other information you provide us in order to prove your eligibility to use our Services.

b) transaction information including date, time, amount, currencies used, exchange rate, beneficiary details, details and location of the merchant or ATMs associated with the transaction, IP address of sender and receiver, sender’s and receiver’s name and registration information, messages sent or received with the payment, device information used to facilitate the payment and the payment instrument used; 

c) details of your transaction relating to your use of our services, including who you have sent money to, foreign exchange transactions you have entered into, the time, date and location of the place the transaction was entered into.

d) location Information. We use GPS technology and your IP address to determine your location – this may be used when the App is running in the foreground and the background of your Device. This is used to prevent fraud, for instance if your mobile device is saying that you are based in the UK, but your card is being used to enter into an ATM Withdrawal or point of sale purchase in Spain, we may not allow that transaction to be processed. Our card protection and fraud-prevention measures require this personal data for the feature to work.

 

  • to manage and administer the Services;
  • to enable you to use the Services;
  • to deal with enquiries, complaints and feedback from you;
  • To give you any notices under any agreement with you;
  • To keep you informed about your relationship with us;
  • To update our records;
  • To identify, prevent, detect or tackle fraud, money laundering and other crime;
  • To carry out checks required by applicable regulation or regulatory guidance;
  • To carry out our obligations arising from and exercise our rights under, any agreements between you and either of us or other users of the Service;
  • To check any instructions given to us, for training purposes, for crime prevention and to improve the quality of our customer service.

For the above purposes, each of we may disclose your personal data to any member of our group, which means our subsidiaries, in any part of the EEA or elsewhere.

To disclose to third parties:

  • If it is under a duty to disclose or share your personal data in order to comply with any legal obligation;
  • To enforce this Privacy Policy or any other agreement with you;
  • to a credit reference agency to check your identity and to prevent fraud…
  • to our banking and financial service providers (including Griffin Bank Ltd, TransactPay Ltd, and Prepay Technologies Ltd, who act as independent Data Controllers), card manufacturing, personalisation and delivery service providers, agents and subcontractors, acting for the purpose of operating the Services;
  • to debt collectors and other third parties to trace you and recover any debt;
  • to provide a unified service across all of our products and services, we may disclose your personal information to any member of the Countingup group, which means any of our subsidiaries or related entities. Companies in the Countingup group will be acting as joint controllers or processors in order to provide the Countingup Services;
  • In the event that we sell any business or assets, in which case it may disclose your personal data to the prospective seller or buyer of such business or assets;
  • To protect the rights, property, or safety of us, our customers, or others (which includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction);
  • To investigate, prevent or detect fraud or carry out checks against money laundering;
  • For audit purposes and to meet obligations to any relevant regulatory authority or taxing authority.

‘b’ processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract; 

‘c’ processing is necessary for compliance with a legal obligation to which we are subject; 

‘f’ processing is necessary for the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data.

Information we collect about you and your Device. Each time you visit the App or our Site we will automatically collect the following information:

(a) technical information, including the internet protocol (IP) address used to connect your computer or Device to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, Device information and the type of mobile device you use, a unique Device identifier (for example, your Device’s IMEI number, the MAC address of the Device’s wireless network interface, or the mobile phone number used by the Device), mobile network information, your mobile operating system, the type of mobile browser you use, time zone setting “Device Information”;

(b) information about your visit, including the full uniform resource locators (URL), clickstream to, through and from our site (including date and time), services you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse overs), methods used to browse away from the page, device information;

(c) information stored on your Device, including if you allow Countingup to access contact information from your address book, login information, photos, videos or other digital content, check ins (Content Information). The App will periodically recollect this information in order to stay up-to-date

  • To identify, prevent, detect or tackle fraud, money laundering and other crime;
  • to prevent your Countingup Card being used fraudulently;
  • to improve your browsing experience by personalising the Services;
  • To develop and improve the Service;
  • To ensure that content on the Services is presented in the most effective manner for you and for your computer;

To disclose to third parties:

  • To comply with a current judicial proceeding, a court order or legal process served on us or our Services, any request by any regulator who may have jurisdiction over us from time to time or for audit purposes and to meet obligations to any relevant regulatory authority or taxing authority;
  • To enforce this Privacy Policy or other agreement with you;

‘b’ processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract; 

‘f’ processing is necessary for the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data.

We may make and retain copies of passports or other identification evidence that you provide for anti-money laundering and anti-fraud purposes;

  • To identify, prevent, detect or tackle fraud, money laundering and other crime;
  • To carry out checks required by applicable regulation or regulatory guidance;

To disclose to third parties:

  • To comply with a current judicial proceeding, a court order or legal process served on us or our Services, any request by any regulator who may have jurisdiction over us from time to time or for audit purposes and to meet obligations to any relevant regulatory authority or taxing authority;
  • To enforce this Privacy Policy or other agreement with you;
  • to a credit reference agency to check your identity and to prevent fraud, (it will also keep a record of your request and use it whenever anyone applies to be authenticated in your name);
  • To our financial service partners (Griffin Bank Ltd, TransactPay Ltd, and Prepay Technologies Ltd) to enable them to fulfil their own independent Anti-Money Laundering (AML) and Customer Due Diligence legal obligations.

‘b’ processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract; 

‘c’ processing is necessary for compliance with a legal obligation to which we are subject; 

‘f’ processing is necessary for the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data.

Information about your physical or mental health or condition (where necessary and appropriate to comply with regulatory requirements relating to customers with such conditions)

  • to meet our employment and related regulatory obligations;
  • to manage and administer the Services;
  • to enable you to use the Services;

To disclose to third parties for:

  • To comply with a current judicial proceeding, a court order or legal process served on us or our Services, any request by any regulator who may have jurisdiction over us from time to time or for audit purposes and to meet obligations to any relevant regulatory authority or taxing authority;
  • To enforce this Privacy Policy or any other agreement with you;
  • to agents and subcontractors, acting for us, to use for the purpose of operating the Services;
  • to debt collectors and other third parties to trace you and recover any debt;

processing is necessary for the establishment, exercise or defence of legal claims;

An exemption under the Act also applies to records of our intentions in relation to any negotiations with you to the extent that the provisions would be likely to prejudice those negotiations.

Marketing

Submitted Information, Location Information or transaction information) 

Records of any surveys that you may be asked to complete, your responses and related details;

  • To provide you with information, products or services that you request or which we decides may interest you;
  • For statistical analysis;
  • To identify which elements of the Services or other products might interest you;
  • If we decide to engage advertisers to promote our products and services, the advertisers and their advertising networks may require anonymised personal data to serve relevant adverts to you and others. We will never disclose identifiable information about individuals to advertisers, but we may provide them with aggregate information about our users. We may also use such aggregate information to help our advertising partners provide a tailored and targeted campaign, relevant for a sub-section of our users (for example, women in Manchester). In some instances, we may use personal data we have collected from you to enable our advertising partners to display their advertisement to their target audience; We also use analytics and search engine providers that assist us in the improvement and optimisation of our site;

With your consent

You will receive marketing communications from us if you have signed up to and/or utilise the Countingup Services and, in each case, you have not opted out of receiving marketing notifications.

Third-party Marketing: We will obtain your express opt-in consent before we share your personal data with any company outside the Countingup group of companies for marketing or promotional purposes.

Opting Out: You can ask us or third parties to stop sending you marketing messages at any time by adjusting your marketing preferences by following the unsubscribe links on any marketing message sent to you.

Information related to any interactions with third parties connected to your account, whether directly or indirectly enabled by us or you. This includes but is not limited to any accounting, tax, bookkeeping or financial services providers, such as your accountant, Sleek, Iwoca and Superscript. This may include some of the “Submitted Information”, transaction information, Location Information, Device information and Identification information described elsewhere in this table

  • to manage and administer the Services;
  • to enable you to use the Services;
  • to deal with enquiries, complaints and feedback from you;
  • To give you any notices under any agreement with you;
  • To keep you informed about your relationship with us;
  • To update our records;
  • To identify, prevent, detect or tackle fraud, money laundering and other crime;
  • To carry out checks required by applicable regulation or regulatory guidance;
  • To carry out our obligations arising from and exercise our rights under, any agreements between you and either of us or other users of the Service;
  • To check any instructions given to us, for training purposes, for crime prevention and to improve the quality of our customer service.
  • To enable you to use any third party Services, including where these interpret your information or data to provide quality and accurate services to you

‘b’ processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract; 

‘c’ processing is necessary for compliance with a legal obligation to which we are subject; 

‘f’ processing is necessary for the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data.

Annex B: Your rights

Your rights and how to exercise them

Exception

Right of Access: To obtain from us confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and the following information: (a) the purposes of the processing; (b) the categories of personal data concerned; (c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; (d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; (e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; (f) the right to lodge a complaint with a supervisory authority; (g) where the personal data are not collected from the data subject, any available information as to their source; (h) the existence of automated decision-making, including profiling, referred to in Article 22(1) of the GDPR and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

How to exercise:

This Privacy Policy provides confirmation of the details required in relation to your right of access.

Under the DPA, you have a right to access certain personal records that we hold about you. Any access request may be subject to a fee to meet our costs (as the case may be) in providing you with details of the information they hold about you if the request is unfounded or excessive. 

If you wish to exercise this right, then please reach out to our support team via in-app chat or support@countingup.com.

Where your request relates to data held independently by our financial service partners (Griffin Bank Ltd, TransactPay Ltd, or Prepay Technologies Ltd), we will either facilitate this request on your behalf or direct you to the appropriate partner.

 

 

Right to rectification: to obtain from us without undue delay the rectification of inaccurate personal data concerning you.

We must communication to each recipient to whom the rectified personal data have been disclosed, unless this proves impossible or involves disproportionate effort. 

We shall inform the data subject about those recipients if the data subject requests it.

You can exercise the right at any time by contacting us at support@countingup.com.

 

 

Right to erasure: to obtain from us the erasure of personal data concerning you without undue delay where: 

(a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; 

(c) you object to the processing based on legitimate interest where there are no overriding legitimate grounds for the processing; 

(d) the personal data have been unlawfully processed; 

(e) the personal data have to be erased for compliance with a legal obligation to which we are subject.

We must communication to each recipient to whom the erased personal data have been disclosed, unless this proves impossible or involves disproportionate effort. 

We shall inform the data subject about those recipients if the data subject requests it.

You can exercise the right at any time by contacting us at support@countingup.com.

Processing is necessary for

‘b’ compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in us; or

‘e’ the establishment, exercise or defence of legal claims.

Where we are not able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request. For example, as an FCA authorised firm, Countingup is under certain obligations to retain certain data for a minimum of 6 years (see above). 

Additionally, our financial service partners (Griffin Bank Ltd, TransactPay Ltd, and Prepay Technologies Ltd) are required by law to retain certain financial, transaction, and identity data for longer periods (for example, up to 10 years to fulfil Anti-Money Laundering and financial crime prevention obligations)

Please note that these retention requirements supersede any right to erasure requests under applicable data protection laws.

Right to request the restriction of processing concerning you: to obtain from us restriction of processing where: 

(a) the accuracy of the personal data is contested by you, for a period enabling us to verify the accuracy of the personal data; 

(b) the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead; 

(c) we no longer need the personal data for the purposes of the processing, but it is required by you for the establishment, exercise or defence of legal claims; 

(d) you object to the processing based on legitimate interest pending the verification whether our legitimate grounds override yours. 

We must communication to each recipient to whom the restricted personal data have been disclosed, unless this proves impossible or involves disproportionate effort. 

We shall inform the data subject about those recipients if the data subject requests it.

You can exercise the right at any time by contacting us at support@countingup.com.

Where processing has been restricted under this right, such personal data shall, with the exception of storage, only be processed: 

(a) with your consent; or
(b) for the establishment, exercise or defence of legal claims; or
(c) for the protection of the rights of another natural or legal person; or
(d) for reasons of important public interest of the Union or of a Member State.

Please note that any requests in relation to the restriction of the processing of your data means that we may not be able to perform the contract we have or are trying to enter into with you (including the Countingup Services). In this case, we may have to cancel your use of the Countingup Services, but we will notify you if this is the case at the time.

The right to data portability: to receive the personal data concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from us, where: 

(a) the processing is based on consent or is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract; and 

(b) the processing is carried out by automated means. 

You have the right to have the personal data transmitted directly from us to another controller, where technically feasible.

The exercise of the right referred to in paragraph 1 of this Article shall be without prejudice to the right to erasure. 

If you wish to exercise this right, then please reach out to our support team via the in-App chat function or email support@countingup.com.

 

That right shall not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us.

The right to object to processing: to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on processing necessary for the purposes of the legitimate interests pursued by us or a third party (except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data), including profiling. 

You can exercise the right at any time by contacting us at support@countingup.com.

Where: 

(a) we demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject; or
(b) for the establishment, exercise or defence of legal claims.

If you object to the processing of certain data, then we may not be able to provide the Countingup Services and it is likely we will have to terminate your account.

The right to ask us not to process your personal data for direct marketing purposes: to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.

You have the right to ask us not to process your personal data for marketing purposes. We we will usually inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms used to collect your data. 

You can also exercise the right at any time by contacting us at support@countingup.com.

 

 

The right not to be subject to automated individual decision-making, including profiling: to not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. 

You can exercise the right at any time by contacting us at support@countingup.com.

If the decision: 

(a) is necessary for entering into, or performance of, a contract between you and us; 

(b) is authorised by Union or Member State law to which we are subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or 

(c) is based on the data subject’s explicit consent.

In the cases referred to in points (a) and (c) we shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on our part, to express his or her point of view and to contest the decision.

Annex C

TPL Privacy Policy

This policy explains when and why we collect personal information about you, how we use it, the conditions under which we may disclose it to others and how we keep it secure.

TPL is committed to safeguarding the privacy of your information. By “your data”, “your personal data”, and “your information” we mean any personal data about you which you or third parties provide to us.

We may change this Policy from time to time so please check this page regularly to ensure that you’re happy with any changes.

 

Who are we?

Transact Payments Limited (“TPL”, “we”, “our” or “us”) is the issuer of your card and is an independent Data Controller for the personal data which you provide to us to enable us to issue and maintain the card services. TPL is an e-money institution, authorised and regulated by the Gibraltar Financial Services Commission. Our registered office address is Europort Avenue, Unit G02, Eurocity, GX11 1AA, Gibraltar, and our registered company number is 108217.

Counting Ltd is the Program Manager for your card program and is an independent Data Controller for any personal data which you provide which is related to facilitating the management of the card program. Counting Ltd is incorporated and registered in England and Wales with registered office at 20-22 Wenlock Road, London, N1 7GU and company registration number 10729748.

How do we collect your personal data?

We collect information from you when you apply online or via a mobile application for a payments card which is issued by us. We also collect information when you use your card to make transactions. We may also process information from Program Manager, other third-party payment partners and service providers. We also obtain information from third parties (such as fraud prevention agencies) who may check your personal data against any information listed on an Electoral Register and/or other databases. When we process your personal data we rely on legal bases in accordance with data protection law and this privacy policy. For more information see: On what legal basis do we process your personal data?

On what legal basis do we process your personal data?

Contract

Your provision of your personal data and our processing of that data is necessary for each of us to carry out our obligations under the contract (known as the Cardholder Agreement or Cardholder Terms & Conditions or similar) which we enter into when you sign up for our payment services. At times, the processing may be necessary so that we can take certain steps, or at your request, prior to entering into that contract, such as verifying your details or eligibility for the payment services. If you fail to provide the personal data which we request, we cannot enter into a contract to provide payment services to you or will take steps to terminate any contract which we have entered into with you.

Legal/Regulatory 

We may also process your personal data to comply with our legal or regulatory obligations.

Legitimate Interests 

We, or a third party, may have a legitimate interest to process your personal data, for example:

  • To analyse and improve the security of our business;
  • To anonymise personal data and subsequently use anonymized information.

Consent 

If it is legally required, we or Program Manager will obtain your consent to share your personal data with third-party providers.

 

What type of personal data is collected from you?

When you apply for a card, we, or our partners or service providers, collect the following information from you: full name, physical address, email address, mobile phone number, phone number, date of birth, gender, login details, IP address, identity and address verification documents.

When you use your card to make transactions, we store that transactional and financial information. This includes the date, amount, currency, card number, card name, account balances and name of the merchant, creditor or supplier (for example a supermarket or retailer). We also collect information relating to the payments which are made to/from your account. If we are required by law to process additional personal data (for example, if we suspect that there may be fraud related to the use of your card or the payment services linked to it), we will also process that extra personal data.

 

How is your personal data used?

We use your personal data to: 

  • set up your account, including processing your application for a card, creating your account, verifying your identity and printing your card.
  • maintain and administer your account, including processing your financial payments, processing the correspondence between us, monitoring your account for fraud and providing a secure internet environment for the transmission of our services.
  • comply with our regulatory requirements, including anti-money laundering obligations.
  • improve our services, including creating anonymous data from your personal data for analytical use, including for the purposes of training, testing and system development.

  

Who do we share your information with?

When we use third party service partners, we have a contract in place that requires them to keep your information secure and confidential.

We may receive and pass your information to the following categories of entity:  

  • identity verification agencies to undertake required verification, regulatory and fraud prevention checks;
  • information security services organisations, web application hosting providers, mail support providers, network backup service providers and software/platform developers;
  • document destruction providers;
  • Mastercard, Visa, digital payment service partners or any third party providers  involved in processing the financial transactions that you make;
  • anyone to whom we lawfully transfer or may transfer our rights and duties under this agreement;
  • any third party as a result of any restructure, sale or acquisition of TPL or any associated entity, provided that any recipient uses your information for the same purposes as it was originally supplied to us and/or used by us.
  • regulatory and law enforcement authorities, whether they are outside or inside of the United Kingdom (UK) or European Economic Area (EEA), where the law requires us to do so.

  

Sending personal data overseas

To deliver services to you, it is sometimes necessary for us to share your personal information outside the UK/Gibraltar e.g.: 

  • with service providers located outside these areas;
  • if you are based outside these areas;
  • where there is an international dimension to the services we are providing to you.

These transfers are subject to special rules under Gibraltar data protection law.

These countries do not have the same data protection laws as Gibraltar. We will, however, ensure the transfer complies with data protection law and all personal information will be secure. We will send your data to countries where the Gibraltar Government has made a ruling of adequacy, meaning that they have ruled that the legislative framework in the country provides an adequate level of data protection for your personal information. You can find out more about adequacy regulations here and here.

Where we send your data to a country where no adequacy decision has been made, our standard practice is to use standard data protection contract clauses that have been approved by the United Kingdom government and/or the European Commission. You can obtain a copy of the European Commission’s document here and the UK’s document here. 

If you would like further information, please contact our Data Protection Officer on the details below.

 

How long do we store your personal data?

We will store your information for a period of five years after our business relationship ends in order that we can comply with our obligations under applicable legislation such as anti-money laundering and anti-fraud regulations. If any applicable legislation or changes to this require us to retain your data for a longer or shorter period of time, we shall retain it for that period. We will not retain your data for longer than is necessary.

 

Your rights regarding your personal data?

You have certain rights regarding the personal data which we process: 

  • You may request a copy of some or all of it.
  • You may ask us to rectify any data which we hold which you believe to be inaccurate.
  • You may ask us to erase your personal data (where applicable).
  • You may ask us to restrict the processing of your personal data.
  • You may object to the processing of your personal data (where applicable).
  • You may ask for the right to data portability.

If you would like us to carry out any of the above, please email your request to the Data Protection Officer at dpo@transactpay.com. 

 

How is your information protected?

We recognise the importance of protecting and managing your personal data. Any personal data we process will be treated with appropriate care and security. 

These are some of the security measures we have in place:

  • We use a variety of physical and technical measures to keep your personal data safe. 
  • We have detailed information and security policies to ensure the confidentiality, integrity, and availability of information.
  • Your data is stored securely on computer systems with control over access on a limited basis.  
  • Our staff receives data protection and information security training on a regular basis.
  • We use encryption to protect data at rest and anonymization where applicable. 
  • We have adequate security controls to protect our IT infrastructure and staff computers including but not limited to Identity and Access Management, Firewalls, VPN, Antivirus, Advanced Email Threat Protection and more. 
  • We conduct regular audits such as PCI-DSS to ensure we are following adequate security controls to protect your data.

While we take all reasonable steps to ensure that your personal data will be kept secure from unauthorised access, we cannot guarantee it will be secure during transmission by you to the applicable mobile app, website or other services over the internet. However, once we receive your information, we make appropriate efforts to ensure its security on our systems.   

Complaints

We hope that our Data Protection Officer can resolve any query or concern you may raise about our use of your personal information. 

The General Data Protection Regulation also gives you right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in Gibraltar is the Gibraltar Regulatory Authority. Their contact details are as follows:

Gibraltar Regulatory Authority, 

2nd floor, Eurotowers 4, 1 Europort Road, Gibraltar.

(+350) 20074636/(+350) 20072166   info@gra.gi

 

Changes to our Privacy Policy

We keep our Privacy Policy under review and we regularly update it to keep up with business demands and privacy regulation. We will inform you about any such changes. This Privacy Policy was last updated on 27th July 2026.

 

How to contact us

If you have any questions about our Privacy Policy or the personal information which we hold about you or, please send an email to our Data Protection Officer at dpo@transactpay.com.