Website & Business Privacy Notice
Scope
This Privacy Notice applies to information Versa collects as a controller — that is, when Versa determines the purposes and means of processing. This includes personal information collected from:
- Visitors to our website at versa.org
- Business contacts such as prospective and current customers, partners, and vendors
- Users who create or manage a Versa account
What This Notice Does Not Cover
Versa Link end users. When an end user connects a merchant or travel supplier to a financial platform through Versa Link, Versa acts as a processor on behalf of the merchant or platform that initiated the connection. That processing is described in our End User Privacy Policy.
Cloud Service customer data. When Versa processes personal data on behalf of a customer through the Versa platform (the “Cloud Service”), that processing is governed by the applicable Data Processing Agreement between Versa and the customer. A current list of subprocessors used by the Cloud Service is available at versa.org/legal/subprocessors.
Third-party sites. Our site may contain links to third-party sites and services that have their own privacy policies. This Privacy Notice does not apply to your activities on those sites.
Last updated: March 12, 2026.
1. Information We Collect
Log and Device Data
When you visit our website, our servers may automatically log standard data provided by your web browser, including your device's IP address, browser type and version, operating system, device type, the pages you visit, the time and date of your visit, and time spent on each page.
If you encounter errors while using the site, we may automatically collect data about the error and the circumstances surrounding its occurrence, including technical details about your device and other information relating to the problem.
Personal Information
We may ask for personal information — for example, when you register for an account, subscribe to our newsletter, or contact us — which may include one or more of the following:
- Name
- Email address
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide and operate our platform's core features and services
- To contact and communicate with you
- For security and fraud prevention, and to ensure that our sites and apps are safe, secure, and used in line with our terms of use
- For internal record keeping and administrative purposes
- To improve our website, products, and services
3. Legal Bases for Processing
We only collect and use your personal information when we have a lawful basis to do so. Depending on the context, we rely on one or more of the following:
- Contractual necessity — to perform a contract with you or take steps at your request before entering into one
- Legitimate interests — to operate, improve, and secure our services, provided those interests are not overridden by your rights
- Legal compliance — to meet our obligations under applicable law
- Consent — where you have given us specific consent to process your information for a particular purpose
4. Security
We maintain organizational, technical, and administrative measures designed to protect personal information from unauthorized access, loss, destruction, or alteration. No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute data security. For more detail, see our Security page.
You are responsible for maintaining the confidentiality of any passwords associated with your account.
5. Data Retention
We retain personal information no longer than is reasonably necessary for the purposes described in this Privacy Notice. When personal information is no longer required, we will delete it or anonymize it.
| Data Category | Retention Criteria |
|---|---|
| Account information (name, email) | Duration of active account, plus up to 90 days after deletion request |
| Log and device data (IP address, browser info) | Up to 12 months from collection |
| Support and communication records | Up to 24 months after resolution, unless ongoing relationship exists |
| Billing and transaction records | As required by applicable tax and accounting obligations (typically 7 years) |
| Marketing preferences and consent records | Until consent is withdrawn or account is deleted |
We may retain personal information for longer periods where required by law, regulation, or a legal hold, or where necessary to establish, exercise, or defend legal claims.
6. Disclosure to Third Parties
We may disclose personal information to:
- A parent, subsidiary, or affiliate of our company
- Our employees, contractors, and/or related entities
- Our existing or potential agents or business partners
- Courts, tribunals, regulatory authorities, and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise, or defend our legal rights
- An entity that buys, or to which we transfer all or substantially all of our assets and business in connection with a merger, acquisition, reorganization, or similar transaction
Service Providers
We use service providers to operate and improve the Website (for example: hosting, analytics, error monitoring, and email communications). A current list of third-party subprocessors used to process customer data for the Cloud Service is available at versa.org/legal/subprocessors.
7. International Transfers of Personal Information
The personal information we collect is stored and/or processed in the United States, or where we or our partners, affiliates, and third-party providers maintain facilities.
If we transfer your personal information to third parties in other countries: (i) we will perform those transfers in accordance with the requirements of applicable law; and (ii) we will protect the transferred personal information in accordance with this Privacy Notice.
8. Your Rights
Depending on your location and subject to applicable law, you may have the following rights regarding your personal information:
- Access — request details of the personal information we hold about you
- Correction — request correction of inaccurate or incomplete information
- Deletion — request deletion of your personal information, subject to legal obligations
- Objection — object to processing based on legitimate interests
- Portability — request a copy of your data in a portable format
- Withdraw consent — where processing is based on consent, withdraw it at any time
- Unsubscribe — opt out of marketing communications at any time by using the unsubscribe link in any email or by contacting us
- Complaint — lodge a complaint with a regulatory body or data protection authority
We will not discriminate against you for exercising any of these rights. To exercise your rights, contact us using the details below.
9. US State Privacy
Children's Privacy
Our services are not directed to children under the age of 13, and we do not knowingly collect personal information about children under 13.
California (CCPA)
If you are a California resident, you may have additional rights under the California Consumer Privacy Act, including the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the right to request deletion, and the right to opt out of any sale of personal information. We do not sell personal information.
To exercise any of these rights, please contact us using the details below.
Do Not Track
At this time, we do not respond to browser “Do Not Track” signals.
10. Changes to This Notice
We may update this Privacy Notice to reflect changes to our practices or applicable law. If we make significant changes, we will notify registered users at the email address associated with their account. Changes are effective when posted at this URL.
11. Contact Us
For any questions or concerns regarding your privacy, you may contact us at security@versa.org.