Privacy Policy

Last updated: 21 June 2026

1. Who we are

This Privacy Policy explains how Chip & Pin Direct ("we", "us", "our") collects, uses and protects your personal data. We are a card payment, telecoms and EPOS provider based at 50a Durham Road, Birtley, DH3 2QH. For the purposes of UK data protection law, Chip & Pin Direct is the data controller for the personal data we hold about you.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. The information we collect

Depending on how you deal with us, we may collect:

  • Contact and business details — your name, company name, email address, phone number and trading address.
  • Account and service information — the products and services you hold with us, including card terminals, broadband, phone lines and EPOS systems.
  • Billing and settlement details — your business bank details and invoice history, so we can take payment and settle your card takings.
  • Statement and rate-review information you share with us so we can review your card processing costs.
  • Technical and support data — records of support tickets, calls and remote support sessions, and basic information about your equipment and connection.
  • Website data — information collected through cookies and similar technologies when you use our website.

We do not store full card numbers or PINs. Card transactions are handled securely by our acquiring bank and payment partners in line with the PCI DSS standard.

3. How we use your information

We use your personal data to:

  • Provide, set up and support the services you take from us.
  • Carry out free rate reviews and prepare quotes and proposals.
  • Process billing, settle your card takings and manage your account.
  • Respond to enquiries and provide customer support.
  • Meet our legal, regulatory and anti-fraud obligations.
  • With your consent, send you relevant updates about our products and services.

4. Our lawful bases

We rely on the following lawful bases: performance of a contract (to deliver the services you have asked for), legal obligation (for tax, accounting and anti-fraud requirements), legitimate interests (to run and improve our business and keep our services secure), and consent (for optional marketing, which you can withdraw at any time).

5. Sharing your information

We share personal data only where necessary, including with our acquiring banks and payment partners, hardware and connectivity suppliers, and IT and support providers acting on our behalf. We may also disclose information where required by law or a regulator. We never sell your personal data.

6. How long we keep it

We keep personal data only for as long as we need it to provide our services and to meet our legal and regulatory obligations (including financial record-keeping), after which it is securely deleted or anonymised.

7. Your rights

Under UK data protection law you have the right to access, correct, erase or restrict the use of your personal data, to object to certain processing, and to data portability. You can also withdraw consent for marketing at any time. To exercise any of these rights, contact us using the details below. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

8. Security

We take appropriate technical and organisational measures to keep your personal data secure and to protect it against unauthorised access, loss or misuse. Our support team will never ask you for your full card number or banking PIN.

9. Contact us

If you have any questions about this policy or how we handle your data, please get in touch:

See also our Terms of Service.