Target processes payments for businesses and, in doing so, handles personal data about the people who run those businesses and the people who pay them. This policy is written to be read, not filed. If anything is unclear, write to dpo@target.co.uk.
01Who we are
Target Financial Services Ltd (“Target”, “we”) is the controller of the personal data described here. We are registered in England and Wales, with our registered office at 1 Poultry, London EC2R 8EJ, and are an Electronic Money Institution authorised by the Financial Conduct Authority (Firm Reference Number 900847).
For people in the European Economic Area, our Riga office (Elizabetes iela 45/47, Riga, Latvia) is our representative under Article 27 of the EU GDPR.
Our Data Protection Officer can be reached at dpo@target.co.uk or by post at the London address, marked “Data Protection Officer”.
When we authorise, route and settle a payment for a merchant, we act as that merchant’s processor. For our own legal duties — fraud prevention, anti-money-laundering checks, card-scheme reporting and record keeping — we are an independent controller.
02What data we collect
What we collect depends on how you deal with us. This policy covers three groups of people.
2.1 Merchants and their representatives
- Identity and contact details of directors, beneficial owners and authorised signatories: name, date of birth, nationality, home address, e-mail, phone, a copy of a passport or identity card and a proof of address.
- Company details: legal name, registration and VAT numbers, trading address, website, industry and expected volumes.
- The settlement bank account and the transaction history of your Target account.
- Dashboard usage: log-ins, IP addresses, team roles, actions taken, support tickets and call recordings.
We collect this from you during onboarding, from public registers such as Companies House, and from the KYC providers listed in section 04.
2.2 Cardholders — your customers
We never store a full card number in readable form and never store the CVC: the number is replaced by a token in our PCI DSS Level 1 vault within milliseconds of capture. Beyond that we hold:
| Category | Examples | Source |
|---|---|---|
| Payment data | Tokenised card number, expiry date, cardholder name, issuing bank, amount, currency, merchant reference | Checkout page or the merchant’s API call |
| Authentication data | 3-D Secure result, device fingerprint, browser, IP address and the approximate location derived from it | The cardholder’s browser or app |
| Order data | Billing and delivery address, e-mail, phone and basket contents, where the merchant sends them | The merchant |
| Risk data | Fraud score, rules matched, velocity counts, refund and chargeback history | Generated by Target |
2.3 Website visitors and job applicants
- Anything you type into our forms: name, e-mail, phone, company and your message.
- Technical data: IP address, browser, pages viewed, referring site and cookie identifiers (see section 08).
- For applicants: CV, cover letter, interview notes and, where the role requires it, references and background checks.
03Purposes and legal bases
The law requires a lawful basis for every use of personal data. These are ours.
| Purpose | Data used | Legal basis |
|---|---|---|
| Onboarding and KYC | Identity, company and ownership data | Legal obligation (Money Laundering Regulations 2017, EU anti-money-laundering directives); merchant agreement |
| Payments and payouts | Payment, order and bank data | Merchant agreement; legitimate interest of merchant and cardholder in a completed payment |
| Fraud monitoring | Payment, authentication and risk data | Legal obligation; legitimate interest in protecting merchants, cardholders and Target |
| Disputes | Payment and order data, correspondence | Merchant agreement; card-scheme rules |
| Dashboard and support | Usage data, tickets, call recordings | Merchant agreement |
| Analytics | Aggregated or pseudonymised usage data | Legitimate interest in improving the platform |
| Marketing | Name, e-mail, company | Legitimate interest for existing customers; consent for everyone else — opt out at any time |
| Website | Technical data and cookies | Consent for analytics cookies; legitimate interest for essential ones |
| Recruitment | Applicant data | Steps before entering a contract; legitimate interest |
| Legal claims | Any of the above | Legitimate interest; legal obligation |
Where we rely on legitimate interests we have run a balancing test; the DPO can send you a summary. We make no decisions with legal effects on you by automated means alone, with one exception: our fraud engine may decline a transaction whose risk score exceeds the threshold agreed with the merchant. A declined cardholder can ask the merchant for a manual review, and a merchant can contest a decision through their personal manager.
04Who we share data with
We share personal data only to provide the service or where the law requires it. We never sell it.
- Acquiring banks and partner PSPs — the 15+ institutions that process the transaction, each an independent controller under card-scheme rules.
- Card schemes — Visa, Mastercard and local schemes — for authorisation, clearing, disputes and their fraud-monitoring programmes.
- Issuing banks and 3-D Secure servers, to authenticate the cardholder.
- KYC and sanctions-screening providers, who verify identity documents and screen names against sanctions and politically-exposed-person lists.
- Fraud and device-intelligence providers, who return risk signals on a transaction.
- Cloud and IT suppliers hosting the platform in UK and EU data centres under Article 28 processor agreements.
- Professional advisers: auditors, lawyers and insurers.
- Regulators, law enforcement and courts where disclosure is required — the Financial Conduct Authority, the National Crime Agency, HM Revenue & Customs and financial-intelligence units.
- A buyer or successor if Target is sold or merged, bound by the same confidentiality.
Merchants receive the cardholder data they need to fulfil orders and handle refunds and disputes. They are separate controllers of it, and their own privacy notices apply.
05International transfers
Our platform runs in UK and EU data centres. Data still leaves the region when an acquirer, scheme or issuing bank sits outside it (a US-issued card is authorised by its US issuer), when a supplier provides support from abroad, or when a merchant or its customers are located abroad.
For those transfers we rely on one of three safeguards:
- an adequacy decision — covering UK–EEA transfers and countries such as Switzerland, Japan and Canada;
- the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, backed by a transfer risk assessment;
- for transfers required by card-scheme rules, the derogation for transfers necessary to perform a contract with you.
Copies of the clauses we use are available from the DPO.
06How long we keep data
We keep personal data for as long as the purpose requires and afterwards for as long as the law does.
| Data | Retention period | Why |
|---|---|---|
| KYC records | 5 years after the relationship ends | Money Laundering Regulations 2017 |
| Transaction records | 6 years from the end of the financial year | Companies Act 2006, tax law |
| Disputes and fraud | Up to 3 years after the transaction | Scheme dispute windows; defence of claims |
| Dashboard logs | 2 years, with support tickets and call recordings | Security investigations, service quality |
| Card tokens | Until the merchant closes the account, unless a dispute is open | Refunds, recurring payments, disputes |
| Web analytics | 14 months | Consent-based cookies — see the Cookies policy |
| Marketing contacts | Until you opt out, or 2 years after your last interaction | Legitimate interest or consent |
| Job applications | 6 months after the decision, if unsuccessful | Defence of discrimination claims |
When a period ends we delete the data or anonymise it. Backups are overwritten on a rolling 35-day cycle.
07Your rights
Under the UK GDPR and the EU GDPR you can ask us for:
- Access — a copy of your data and information about how we use it.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion of data we no longer need. Records the law requires us to keep (section 06) are excluded.
- Restriction — a freeze on processing while a dispute about accuracy or lawfulness is resolved.
- Portability — your data in a machine-readable format where we process it under a contract or your consent.
- Objection — to processing based on legitimate interests and, at any time, to direct marketing.
- Withdrawal of consent — without affecting processing that took place before.
- Complaint — to the Information Commissioner’s Office in the UK, the Data State Inspectorate in Latvia or your local supervisory authority in the EEA.
E-mail dpo@target.co.uk. We confirm your identity and respond within one month, extending by up to two further months only for complex requests and telling you why. There is no fee unless a request is manifestly unfounded or excessive. If you paid a merchant through Target, contact the merchant first; we help them answer.
08Cookies
Our website sets strictly necessary cookies that keep it working and, only with your consent, analytics cookies that show which pages are read and where visitors come from. We use no advertising cookies. Cookie names, lifetimes and how to change your choice are in the Cookies policy. The merchant dashboard uses session cookies for signing in only.
09Security
Target is certified to PCI DSS Level 1 and audited against it every year. Card numbers are tokenised at capture and held in a segregated vault; data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Production access requires hardware-key multi-factor authentication, is limited to named staff on a least-privilege basis and is logged in full. Staff complete data-protection training on joining and every year after. We run annual penetration tests and continuous vulnerability scanning.
If a breach is likely to put you at risk, we notify the supervisory authority within 72 hours and tell you without undue delay where the risk is high. Keep your dashboard credentials confidential and tell us at once if you suspect misuse.
10Changes to this policy
We review this policy at least once a year and whenever our processing changes. The version and date at the top tell you which edition you are reading. For material changes — a new purpose, recipient or transfer — we notify merchants by e-mail and in the dashboard at least 30 days in advance. Earlier versions are available from the DPO.
- 3.1 — 1 June 2026
- EU representative in Riga added; dashboard-log retention shortened from 3 to 2 years; automated fraud decisions explained in section 03.
- 3.0 — 12 September 2025
- Rewritten in plain English with separate sections for merchants, cardholders and visitors.
- 2.0 — 1 March 2022
- Updated for the rebrand to Target and the launch of multi-currency settlement and payouts.
11Contact
Questions, requests and complaints about personal data go to the Data Protection Officer. We acknowledge every request within two business days.
Data Protection OfficerTarget Financial Services Ltd
1 Poultry, London EC2R 8EJ, United Kingdom
E-mail: dpo@target.co.uk
General enquiries: info@target.co.uk · +44 20 3808 9720
If you are not satisfied with our answer, you can complain to the Information Commissioner’s Office or your local supervisory authority at any time. Other ways to reach us are on the contact page.