Last update: 11/12/2020 at 00:00:00 (UTC-3)
Our mission is to democratize digital payment methods. We build our payment gateway to facilitate companies to charge credit cards online. We provide a single interface that developers can integrate with, and quickly start tuning their online payment process.
We make this payment transactions with transparency of what and how the data is used by companies is extremely important. For this reason, we value and respect this information. By using our services, you consent the use of your data in accordance with this Privacy and Data Use Policy.
#1. General information and definitions
We are a open source software that allows developers to easily integrate with many different payment providers.
This policy also describes how we use Personal Data, with whom we share it, your rights and choices, and how you can contact us about our privacy practices. This policy does not apply to third-party websites, products, or services, even if they link to our Services or Sites, and you should consider the privacy practices of those third-parties carefully.
Tuna obtains Personal Data about you from various sources to provide our Services and to manage our Sites. “You” may be a visitor to one of our websites, a user of one or more of our Services (“User” or Tuna's User”), or a customer of a User (“Customer”). If you are a Customer, Tuna will generally not collect your Personal Data directly from you. Your agreement with the relevant Tuna's User should explain how the Tuna's User shares your Personal Data with Tuna, and if you have questions about this sharing, then you should direct those questions to the Tuna's User.
#2. Data We Collect
#a. Personal Data that we collect about you.
Personal Data is any information that relates to an identified or identifiable individual. The Personal Data that you provide directly to us through our Sites and Services will be apparent from the context in which you provide the data. In particular:
- When you fill-in our online form to contact our sales team, we collect your full name, work email, country, and anything else you tell us about your project, needs and timeline.
- When you use the “Remember Me” feature of Stripe Checkout, we collect your email address, payment card number, CVC code and expiration date.
Also if you are a Tuna's User, you will provide your contact details, such as name, postal address, telephone number, and email address. As part of your business relationship with us, we may also receive financial and personal information about you, such as your date of birth and government identifiers associated with you and your organization (such as your social security number, tax number, or Employer Identification Number).
And if you are a Customer of a Tunas's User, when you make payments or conduct transactions through a Tunas's User website or application or device we provide, we will receive your transaction information. Depending on how the Tuna's User implements our Services, we may receive this information directly from you, or from the Tuna's User or third parties. The information that we collect will include payment method information (such as credit or debit card number, or bank account information), purchase amount, date of purchase, and payment method. Different payment methods may require the collection of different categories of information. The Tuna's User will determine the payment methods that it enables you to use, and the payment method information that we collect will depend upon the payment method that you choose to use from the list of available payment methods that are offered to you by the Tuna's User. When you make a transaction, we may also receive your name, email, billing or shipping address and in some cases your transaction history to authenticate you.
Tuna complies with the Payment Card Industry Data Security Standard (“PCI DSS”).
#b. Information that we collect automatically on our Sites.
- Browser and device data, such as IP address, device type, operating system and Internet browser type, screen resolution, operating system name and version, device manufacturer and model, language, plug-ins, add-ons and the language version of the Sites you are visiting; Usage data, such as time spent on the Sites, pages visited, links clicked, language preferences, and the pages that led or referred you to our Sites.
- We also collect information about your online activities on websites and connected devices over time and across third-party websites, devices, apps and other online features and services. We use Matomo on our Sites to help us analyze Your use of our Sites and diagnose technical issues.
#3. How we use information?
Tuna and Tuna's User and service providers may use the information we collect from and about you for any of the following purposes: (1) to provide you with the Services; (2) to respond to your inquiries or requests, contact and communicate with you; (3) to develop new products or services and conduct analyses to improve our current content, products, and Services; (4) subject to your consent as may be required under applicable law, to contact you with informational newsletters and promotional and marketing materials relating to our Site and Services; (5) to review the usage and operations of our Site and Services; (6) to use your data internally only in an aggregated and/or personalized and/or non-personalized format for analytical purposes and externally in an aggregated, non-specific format for analytical purposes (as detailed below); and (7) to prevent fraud, protect the security of our Site and Services, and address any problems with the Site and/or Services.
#4. How we Disclose Personal Data?
We do not use, share, rent or sell the Personal Data of our Users’ Customers for interest-based advertising. We do not sell or rent the Personal Data of our Users, their Customers or our Site visitors. We share your Personal Data with trusted entities, as outlined below.
We share Personal Data with other Tunas entities in order to provide our Services and for internal administration purposes.
#b. Service providers.
We share Personal Data with a limited number of our service providers. We have service providers that provide services on our behalf, such as payment provider, anti-fraud provider, identity verification services, website hosting, data analysis, information technology and related infrastructure, customer service, email delivery, and auditing services. These service providers may need to access Personal Data to perform their services. We authorize such service providers to use or disclose the Personal Data only as necessary to perform services on our behalf or comply with legal requirements. We require such service providers to contractually commit to protect the security and confidentiality of Personal Data they process on our behalf. Our service providers are predominantly located in the European Union and the United States of America.
#c. Law Enforcement Related Disclosure
#d. End User Data
We may disclose information, including Personal Information we collect from and/or about End Users, to the specific Customer through which an End User is using our Services, as well as to our trusted subcontractors and service providers, as detailed in this Policy.
#e. Other Uses or Transfer of Your Information
We allow you to use our Site and Services in connection with third-party services, sites, and/or applications. If you use our Site and/or Services with or through such third-parties, we may receive information about you from those third parties. Please note that when you use third-parties outside of our Site and/or Services, their own terms and privacy policies will govern your use of those services.
#5. Your Rights and Choices.
You have choices regarding our use and disclosure of your Personal Data:
a. Opting out of receiving electronic communications from us. If you no longer want to receive marketing-related emails from us, you may opt-out via the unsubscribe link included in such emails. We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages that are required to provide you with our Services.
b. How you can see or change your account Personal Data. If You would like to review, correct, or update Personal Data that You have previously disclosed to us, You may do so by signing in to your Tuna account or by contacting us.
c. Your data protection rights. Depending on your location and subject to applicable law, you may have the following rights with regard to the Personal Data we control about you:
- The right to request confirmation of whether Tuna processes Personal Data relating to you, and if so, to request a copy of that Personal Data;
- The right to request that Tuna rectifies or updates your Personal Data that is inaccurate, incomplete or outdated;
- The right to request that Tuna erase your Personal Data in certain circumstances provided by law;
- The right to request that Tuna restrict the use of your Personal Data in certain circumstances, such as while Tuna considers another request that you have submitted (including a request that Tuna make an update to your Personal Data); and
- The right to request that we export to another company, where technically feasible, your Personal Data that we hold in order to provide Services to you.
- Where the processing of your Personal Data is based on your previously given consent, you have the right to withdraw your consent at any time. You may also have the right to object to the processing of your Personal Data on grounds relating to your particular situation.
d. Process for exercising data protection rights. In order to exercise your data protection rights, you may contact Tuna by sending an email to firstname.lastname@example.org. We take each request seriously. We will comply with your request to the extent required by applicable law. We will not be able to respond to a request if we no longer hold your Personal Data. If you feel that you have not received a satisfactory response from us, you may consult with the data protection authority in your country.
For your protection, we may need to verify your identity before responding to your request, such as verifying that the email address from which you send the request matches your email address that we have on file. If we no longer need to process Personal Data about you in order to provide our Services or our Sites, we will not maintain, acquire or process additional information in order to identify you for the purpose of responding to your request.
If you are a Customer of a Tuna's User, please direct your requests directly to the User. For example, if you are making, or have made, a purchase from a merchant using Tuna's as a payment processor, and you have a request that is related to the payment information that you provided as part of the purchase transaction, then you should address your request directly to the merchant.
#6. Security and Retention.
We make reasonable efforts to ensure a level of security appropriate to the risk associated with the processing of Personal Data. We maintain organizational, technical and administrative measures designed to protect Personal Data within our organization against unauthorized access, destruction, loss, alteration or misuse. Your Personal Data is only accessible to a limited number of personnel who need access to the information to perform their duties. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of your account has been compromised), please contact us immediately.
We retain your Personal Data as long as we are providing the Services to you. We retain Personal Data after we cease providing Services directly or indirectly to you, even if you close your Tuna account or complete a transaction with a Tuna's User, to the extent necessary to comply with our legal and regulatory obligations, and for the purpose of fraud monitoring, detection and prevention. We also retain Personal Data to comply with our tax, accounting, and financial reporting obligations, where we are required to retain the data by our contractual commitments to our financial partners, and where data retention is mandated by the payment methods that we support. Where we retain data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law.
#Comments and Questions