This Privacy Policy describes how Shift4, our Affiliates, including Harbortouch, LLC, Restaurant Manager, LLC, POSitouch, LLC, Future POS, LLC, and Independent Resource Network, LLC, which can be located at https://www.shift4.com/promotional/s4-announcement.cfm (collectively, “Shift4,” “us,” “we”) collect, use, disclose, transfer, store, retain, other otherwise process your information when you (whether you’re and individual or a business) apply or sign up for or utilize any of our payment processing, payment gateway, point-of-sale services (“Services”) through our website or applications.
Your privacy is important to Shift4. In order to make sure that we can continue to offer industry leading Services and support, while maintaining transparency about what we do with your information, we’ve developed a Privacy Policy that covers how we collect, use, disclose, transfer, and store your information, including data that identifies you or makes you identifiable, as a natural person (hereinafter “personal information”). The notion of “personal information” covers all information defined as personal data under Art. 4 (1) GDPR.
This privacy policy is designed to apply to our Website visitors, users of our Services and other companies and users on a global basis. The privacy policy will thus provide various information that is required in specific jurisdictions only. We have in the following marked with “GDPR Notice”, the information applying to our activities subject to the European Union Data Protection Regulation (GDPR) and marked otherwise the notices specifically required under other laws.
Please read this Policy carefully. By continuing to interact with, and utilize our Services, you are consenting to the terms described in this Privacy Policy.
You also agree that Shift4 may update this Privacy Policy from time to time, which will be reflected on our website, located at https://www.shift4.com/privacypolicy.
Who is the Data Controller of Your Personal Information?
GDPR Notice:
Shift4, 2202 N. Irving St., Allentown, PA 18109 (“Shift4,” “us,” “we”) is the data controller
If you retain Services directly from an Affiliate or Brand of the Shift4 group company or otherwise do business with that Shift4 Affiliate/Brand and share personal information with that company, that respective company is the data controller in relation to all personal information obtained, processed and used in relation to such personal information.
The use of information provided to us by our customers (each a “Client” and collectively our “Clients”) for the purpose of processing on their behalf shall be limited to the purpose of providing the Service for which the Client has engaged Shift4 or to third-parties as set forth below.
Shift4 acknowledges that you have the right to access your personal information. Shift4 has no direct relationship with the individuals whose personal data it processes on behalf of its Clients. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data should direct their query to Shift4’s Client (the data controller). If requested to remove data we are processing for our Client, we will respond within a reasonable timeframe. We may transfer personal information to companies that help us provide our Services. Transfers to subsequent third parties are covered by the service agreements with our Clients.
All Services where a Shift4 Affiliate/Brand company processes personal information based on a payment processing agreement entered with you or your customer(s) (or other similarly situated entity) are not covered by this privacy policy. In this respect, the respective Shift4 Affiliate/Brand company is not the data controller but a data processor within the meaning of Art. 4(8) GDPR.
If you wish to contact us, you can find our contact details at the end of this privacy policy.
Collection and Use of Information
GDPR Notice:
The reasons for using your personal information may differ depending upon the purpose of the collection. Regularly, we use your information for the purposes laid out below. Please read the following section carefully so that you understand the reasons for which we collect your personal information.
We need to collect information about you to provide you with the Services or support that you need from us. The type of information that is collected will vary depending on your request, as well as the country that you may be accessing or using our Services from. Additionally, you can choose to voluntarily provide information to us, for example, when signing up for merchant services or would like to become a developer partner.
Information Provided By You
We collect information you provide when you apply or sign up for our Services, go through our identity or account verification process, authenticate into your account, communicate with us for support, or otherwise utilize our Services.
When you are applying or signing up for our Services, the information we collect can include:
You may be asked to provide some of this information anytime you are in contact with Shift4 or a Shift4 affiliated company. Shift4 and its Affiliates may share this personal information with each other and use it consistent with this Privacy Policy. In order to provide quality service and support, Shift4 may require You to verify certain personal information associated with your account, and use such information to fulfill your requests, provide the relevant product or service, or for anti-fraud purposes. We may also combine it with other information to provide and improve our products, services, content, and advertising. You are not required to provide the personal information that we have requested, but, if you chose not to do so, in many cases we will not be able to provide you with our products or services or respond to any queries you may have.
Information We Collect About You From Your Use of Our Services
We collect information about you and your use of our Services. The information that we can collect includes:
Information We Can Collect From Other Sources
We also collect information about you from third parties, including:
How We Use Your Information
We may use information about you for a number of purposes, including:
Providing, Improving, and Developing our Services
Communicating with You About our Services
Protecting our Services and Maintaining a Trusted Environment
Advertising and Marketing
Other Uses
Cookies and Other Technologies
Shift4’s websites, online services, interactive applications, email messages, and advertisements may use “cookies” and other technologies, such as pixel tags and web beacons. These technologies help us better understand user behavior, tell us which parts of our websites people have visited, and facilitate and measure the effectiveness of advertisements and web searches. We treat information collected by cookies and other technologies as non-personal information. However, to the extent that Internet Protocol (IP) addresses or similar identifiers are considered personal information by local law, we also treat these identifiers as personal information. Similarly, to the extent that non-personal information is combined with personal information, we treat the combined information as personal information for the purposes of this Privacy Policy.
Ads that are delivered by Shift4’s advertising platform may appear on Shift4’s website and the websites of our Affiliates and in the Shift4 Marketplace. You may see ads in third-party environments, based on context like your search query or the channel you are reading. In third-party apps, you may see ads based on other information.
Shift4 and our partners also use cookies and other technologies to remember personal information when you use our website, online services, and applications. Our goal in these cases is to make your experience with Shift4 more convenient and personal.
If you want to disable cookies, seek out the policies and/or terms of your internet web browser to manage your browsing privacy preferences. Please note that certain features of the Shift4 website will not be available once cookies are disabled.
As is true of most internet services, we gather some information automatically and store it in log files. This information includes Internet Protocol (IP) addresses, browser type and language, Internet service provider (ISP), referring and exit websites and applications, operating system, date/time stamp, and clickstream data.
We use this information to understand and analyze trends, to administer the site, to learn about user behavior on the site, to improve our product and services, and to gather demographic information about our user base as a whole. Shift4 may use this information in our marketing and advertising services.
In some of our email messages, we use a “click-through URL” linked to content on the Shift4 website. When customers click one of these URLs, they pass through a separate web server before arriving at the destination page on our website. We track this click-through data to help us determine interest in particular topics and measure the effectiveness of our customer communications. If you prefer not to be tracked in this way, you should not click text or graphic links in the email messages.
Pixel tags enable us to send email messages in a format customers can read, and they tell us whether mail has been opened. We may use this information to reduce or eliminate messages sent to customers.
Sharing Your Information with Third Parties
We may share information about you as follows:
With Other Users of our Services with Whom You Interact
With our Affiliates
With Third Parties
Business Transfers and Corporate Changes
Safety and Compliance with Law
With Your Consent
Aggregated and Anonymized Information
How Long We Retain Your Information
GDPR Notice:
We generally retain your information as long as reasonably necessary to provide you the Services or to comply with applicable law. However, even after you deactivate your account, we can retain copies of information about you and any transactions or Services in which you may have participated for a period of time that is consistent with the agreements we make with our clients, applicable law, applicable statute of limitations or as we believe is reasonably necessary to comply with applicable law, regulation, legal process, or governmental request, to detect or prevent fraud, to collect fees owed, to resolve disputes, to address problems with our Services, to assist with investigations, to enforce our Terms of Service or other applicable agreements or policies, or to take any other actions consistent with applicable law. In addition, personal information processed by Shift4 and/or its Affiliate/Brand companies as a data processor will be removed in accordance with the instructions of the applicable data controller, not to exceed two years.
Service Providers
Shift4 shares personal information with companies who provide services such as information processing, extending credit, fulfilling customer orders, delivering products to you, managing and enhancing customer data, providing customer service, assessing your interest in our products and services, and conducting customer research or satisfaction surveys. These companies are obligated to protect your information and may be located wherever Shift4 operates.
Protection of Personal Information
Shift4 takes the security of your personal information very seriously. Shift4 online services such as the Shift4 Marketplace and the Dollars on the Net gateway protect your personal information during transit using encryption technologies required by law and by the PCI Data Security Standard, an international security framework for the protection of cardholder data. When your personal data is stored by Shift4, we use computer systems with limited access housed in facilities using physical security measures.
When you use some Shift4 products, services, or applications or post on a Shift4 forum, the personal information and content you share is visible to other users and can be read, collected, or used by them. You are responsible for the personal information you choose to share or submit in these instances. For example, if you list your name and email address in a forum posting, that information is public. Please take care when using these features.
Integrity and Access to Your Information
Shift4 makes it easy for you to keep your information accurate, complete, and up to date. You can help ensure that your contact information and preferences are accurate, complete, and up to date by contacting us at [email protected]. For other personal information we hold, we will provide you with access (including a copy) for any purpose including to request that we correct the data if it is inaccurate or delete the data if Shift4 is not required to retain it by law or for legitimate business purposes. We may decline to process requests that are frivolous/vexatious, jeopardize the privacy of others, are extremely impractical, or for which access is not otherwise required by local law.
You may also contact us at [email protected] if you would like Shift4 to delete and/or destroy the information that we have retained. This is including location and tracking information, and promotional communications. Certain information we retain cannot be deleted or destroyed in order for us to be able to continue to provide you with our Services and/or products.
EU-U.S. Privacy Shield
Shift4, participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework. Shift4 is committed to subjecting all personal data received from European Union (EU) member countries, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield List at https://www.privacyshield.gov/list.
Shift4 is responsible for the processing of personal data it receives under the Privacy Shield Framework, including any subsequent transfers to a third party acting as an agent on its behalf. Flexera complies with the Privacy Shield Principles for all onward transfers of personal data from the EU, including the onward transfer liability provisions.
With respect to personal data received or transferred pursuant to the Privacy Shield Framework, Shift4 is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Shift4 may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
Under certain conditions, more fully described on the Privacy Shield website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
Our Privacy Shield policy, in its entirety, can be found at https://www.shift4.com/PDF/Shift4-Privacy-Shield-Policy.pdf
If you wish to enquire further about the safeguards we use, please contact us using the details set out at the end of this Privacy Policy.
California Privacy Rights
California law permits residents of California to request certain details about our disclosure of your personal information to third parties for direct marketing purposes during the immediately preceding calendar year. If you are a California resident and would like to request this information, please contact us at [email protected].
Children Privacy
We do not knowingly collect or solicit any information from anyone under the age of 16 on or through the Services. In the event that we learn that we have inadvertently collected personal information from a child under age 16, we will delete that information as quickly as possible. If you believe that we might have any information from a child under 16, please contact us using the contact details listed below at the end of this privacy policy.
From children under the age of 16 residing in the EU, we will not process any personal information on the ground of a consent.
Third-Party Sites and Services
Shift4 websites, products, applications, and services may contain links to third-party websites, products, and services. Our products and services may also use or offer products or services from third parties.
Information collected by third parties, which may include such things as location data, transaction data, or contact details, is governed by their privacy practices. We encourage you to learn about the privacy practices of those third parties.
If you purchase a subscription in a third party app, we create an identifier that is unique to you and the developer or publisher which we use to provide reports to the developer or publisher that include information about the subscription you purchased, and other pertinent information. This information is provided to developers so that they can understand the performance of their subscriptions.
Our Companywide Commitment to Your Privacy
To make sure your personal information is secure, we communicate our privacy and security guidelines to Shift4 employees and strictly enforce privacy safeguards within the company.
Privacy Questions
If you have any questions or concerns about Shift4’s Privacy Policy or data processing or if you would like to make a complaint about a possible breach of applicable privacy laws, please contact us at [email protected]. You can always contact us by phone, or through our website.
When a privacy question or access request is received we have a team which seeks to address the specific concern or query which you are seeking to raise. Where your issue may be more substantive in nature, more information may be sought from you. All such substantive contacts receive a response. If you are unsatisfied with the reply received, you may refer your complaint to the relevant regulator in your jurisdiction. If you ask us, we will endeavor to provide you with information about relevant complaint avenues which may be applicable to your circumstances.
Shift4 may update its Privacy Policy from time to time. When we change the policy in a material way, a notice will be posted on our website along with the updated Privacy Policy.