SkullPay
Sign in Get started

Privacy Policy

Effective 22 September 2026. This policy covers the SkullPay website, merchant portal, API and platform-hosted checkout operated by Skull Holdings.

Merchants and payers

Merchants create portal accounts and integrate SkullPay into their stores. For merchant account data we are the controller. Payers pay a merchant through a SkullPay checkout. For payer data we act as the merchant's processor; the merchant's own privacy notice governs why that data is collected. The technical model is documented in detail in our API documentation.

Merchant account data (we are the controller)

Payer data (we are the merchant's processor)

What we do not do

Cookies

The portal sets one strictly necessary, HttpOnly session cookie. The hosted checkout and the website set none.

Sub-processors

International transfers

Data is processed on Cloudflare's global network. Where data leaves the EEA/UK we rely on standard contractual clauses and the providers' own transfer safeguards.

Security

Field-level encryption for secrets and PII, hashed credentials, two-factor authentication with step-up for sensitive changes, tamper-evident audit ledgers, strict transport security and content-security policies. Report issues via our disclosure policy.

Your rights and contact

Depending on where you live you may have rights to access, correct, delete, restrict or port your data, to object to processing and to lodge a complaint with a supervisory authority. Merchants can exercise them from the portal's account page; anyone can write to privacy@skullpay.co. We will respond within 30 days.

Changes

We will post changes here and, for material changes, email merchant account holders in advance.