At VistaPay we provide payment portals for online use, and in person payment collection infrastructure. This allows businesses, charities and NGO's to collect payments, receive payouts and manage their business transactions.
Last updated: 9 September 2025
VistaPay Limited (“VistaPay”, “we”, “us”, or “our”) is committed to protecting and respecting your privacy. This Privacy & Marketing Policy explains how we collect, use, share, and protect your personal information when you use our website (www.vistapay.co.uk), products, and services (together, the “Services”), including how we handle marketing communications and feedback.
VistaPay Limited is a company registered in England and Wales under company number 16404116, with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. For the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, VistaPay is the data controller of your personal data, unless stated otherwise.
We may collect and process the following categories of personal information:
We process personal data for the following purposes:
We rely on the following legal grounds under the UK GDPR:
We may use your information to:
We may share your personal data with:
We do not sell your personal information.
Some of our partners and service providers may be based outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place (e.g., UK adequacy regulations, Standard Contractual Clauses).
We retain your personal information only as long as necessary for the purposes described above:
Under the UK GDPR, you have the following rights:
To exercise these rights, contact us at: privacy@vistapay.co.uk.
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or disclosure. However, no online service is 100% secure, and you use the Services at your own risk.
We use cookies and similar technologies to operate our Website, analyse traffic, and personalise your experience. For details, please see our Cookie Policy.
Our Services are not directed to individuals under the age of 18, and we do not knowingly collect personal data from children.
We may update this Privacy & Marketing Policy from time to time. Any changes will be posted on this page with an updated date. If significant changes are made, we will notify you via email or account notification.
If you have any questions about this Privacy & Marketing Policy or our data practices, please contact us:
VistaPay Limited
71-75 Shelton Street
Covent Garden
London
United Kingdom
WC2H 9JQ
Email: privacy@vistapay.co.uk
If you are unsatisfied with how we process your data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO): www.ico.org.uk.
Last updated: 9 September 2025
This Anti-Money Laundering and Counter-Terrorist Financing Policy (“Policy”) sets out how VistaPay Limited (“VistaPay”, “we”, “our”, or “us”) seeks to prevent its Services from being used for money laundering, terrorist financing, or other financial crime.
VistaPay is committed to full compliance with the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (as amended), the Proceeds of Crime Act 2002, the Terrorism Act 2000, and other applicable UK laws and regulations.
This Policy applies to:
VistaPay will:
VistaPay applies a risk-based approach to AML/CTF compliance, assessing the risk of customers, transactions, geographies, and products. Enhanced measures are applied where risks are higher.
We will verify the identity of all customers before providing Services. This may include:
Where higher risk is identified (e.g., PEPs, high-risk jurisdictions, unusual transaction patterns), VistaPay will apply additional checks and monitoring.
VistaPay will:
VistaPay will retain:
VistaPay will provide regular AML/CTF training to all relevant employees covering:
This Policy will be reviewed annually or sooner if there are material changes in legislation, regulation, or the business model of VistaPay.
This Policy has been approved by the Board of Directors of VistaPay Limited.
Signed:
Syed Ahmad
Director, VistaPay Limited
Date: 9 September 2025
Last updated: 9 September 2025
This General Data Protection Regulation (“GDPR”) Compliance Policy sets out how VistaPay Limited (“VistaPay”, “we”, “us”, or “our”) ensures compliance with the UK GDPR, the Data Protection Act 2018, and, where applicable, the EU GDPR.
VistaPay is committed to protecting the rights and freedoms of individuals whose personal data we process and to ensuring that personal information is handled lawfully, fairly, and transparently.
This Policy applies to:
VistaPay adheres to the following GDPR principles. Personal data must be:
VistaPay relies on the following lawful bases under Article 6 UK GDPR:
Special category data will only be processed under Article 9 conditions (e.g., where required for legal compliance or with explicit consent).
VistaPay upholds the rights of individuals, including:
Requests may be made by contacting privacy@vistapay.co.uk. VistaPay will respond within one month, in line with GDPR requirements.
VistaPay has appointed a Data Protection Officer (DPO) to oversee compliance with GDPR obligations and act as a point of contact for data subjects and regulators.
Contact: privacy@vistapay.co.uk
VistaPay applies appropriate technical and organisational measures to ensure personal data is secure, including:
Where personal data is transferred outside the UK or EEA, VistaPay ensures that appropriate safeguards are in place, such as:
VistaPay retains personal data only for as long as necessary to meet legal, regulatory, and contractual obligations:
VistaPay will:
All VistaPay employees and contractors receive GDPR and data protection training, with refresher training provided annually.
VistaPay maintains internal policies, records of processing activities (RoPA), and regular audits to demonstrate GDPR compliance.
This Policy will be reviewed annually, or sooner if there are significant changes in legislation, regulation, or VistaPay’s business model.
This Policy has been approved by the Board of Directors of VistaPay Limited.
Signed:
Syed Ahmad
Director, VistaPay Limited
Date: 9 September 2025
Last updated: 9 September 2025
This statement is made by VistaPay Limited (“VistaPay”, “we”, “us”, or “our”) pursuant to section 54 of the UK Modern Slavery Act 2015. It outlines the steps we take to prevent modern slavery and human trafficking in our business and supply chains.
VistaPay is a UK-based financial technology company providing secure, compliant payment processing services to charities, businesses, and other organisations. As a regulated payments platform, we recognise our responsibility to operate ethically and transparently across our operations and supply chains.
VistaPay is committed to:
Our supply chains primarily include:
Given the nature of our operations, the risk of modern slavery within our direct business is low. However, we remain vigilant, particularly in relation to third-party technology providers and contractors.
We take the following steps to reduce the risk of modern slavery and human trafficking:
We promote awareness among our employees and contractors by:
VistaPay is committed to continuously reviewing and strengthening our approach by:
This statement has been approved by the Board of Directors of VistaPay Limited. It will be reviewed annually and updated as appropriate.
Signed:
Syed Ahmad
Director, VistaPay Limited
Date: 9 September 2025