Privacy Policy

This policy explains what personal information Cardexa Pro handles, why, who it is shared with and what rights you have. It is a working draft and will be replaced with wording approved by legal counsel and, where required, by the licensed provider.

Draft — pending legal reviewLast updated 24 July 2026

Who we are

Cardexa Pro provides technology, branding and program-management infrastructure for branded business card and payment programs. Cardexa Pro is not a bank or card issuer. Cards and regulated financial services are provided by applicable licensed third-party providers and issuing partners, who act as data controllers in their own right for the services they provide.

Cardexa Pro is a business program operated by TOONPAY TECHNOLOGIES LIMITED, which is the controlling legal entity for the personal data described in this policy. Its registered address and, where applicable, its data protection representative are published here before launch.

What we collect

From business applicants

  • Company details, including legal and trading name, registration number, country of incorporation and registered address
  • Business activity, program description, expected payout types, volumes and target markets
  • Contact details for the people representing the business
  • Verification information required for know-your-business checks

From eligible users

  • Identity and contact details required for verification
  • Program identifiers, balance and payout records
  • Card status and transaction records, where a card has been issued
  • Correspondence with support and complaints

From website visitors

  • Information you submit through the enquiry or application forms
  • Technical information such as IP address, browser and device type, where processing is necessary to operate and secure the site
  • Cookie data, as described in the Cookie Policy

Why we use it

  • To assess applications and run business verification
  • To operate payout programs, including making approved payouts available to eligible users
  • To meet legal, regulatory and contractual obligations, including anti-money-laundering and sanctions requirements
  • To detect, investigate and prevent fraud and prohibited use
  • To provide support and handle complaints
  • To improve and secure our services
  • To communicate with you about your application or program

Legal bases

Where data protection law requires a legal basis, we rely on performance of a contract, compliance with a legal obligation, our legitimate interests in operating and protecting the service, and consent where consent is the appropriate basis — for example optional analytics cookies. You can withdraw consent at any time without affecting processing already carried out.

Who we share it with

We share personal information only where there is a reason to:

  • Licensed providers and issuing partners, so that card and regulated services can be delivered
  • Identity verification, screening and fraud-prevention providers
  • Businesses running a program, in relation to their own users
  • Technology suppliers who host and operate our systems under contract
  • Professional advisers, auditors, regulators and law enforcement where we are required or permitted to disclose

We do not sell personal information.

International transfers

Personal information may be processed in countries other than the one you live in. Where it is transferred outside the jurisdiction in which it was collected, we rely on the safeguards recognised under the applicable law, such as standard contractual clauses or an adequacy decision.

The specific transfer mechanisms and processing locations are published here once the provider stack and hosting regions are confirmed.

How long we keep it

We keep personal information for as long as needed for the purpose it was collected, and for as long as required by law. Records tied to verification, payouts and card activity are typically subject to statutory retention periods set by financial-services regulation, which can extend for several years after a relationship ends.

Exact retention periods are set out here once confirmed with the licensed provider and legal counsel.

Your rights

Depending on where you live, you may have the right to access your personal information, correct it, delete it, restrict or object to processing, receive it in a portable format, and complain to a supervisory authority. To exercise a right, write to support@cardexapro.com.

Some rights are limited. For example, we may be unable to delete records we are legally required to retain for anti-money-laundering purposes.

Security

We apply technical and organisational measures appropriate to the risk, including access control, encryption in transit and restricted handling of verification data. No system is completely secure, and we cannot guarantee absolute security.

Children

Our services are not directed at children, and we do not knowingly collect personal information from anyone below the minimum age required to hold a card-linked balance in their jurisdiction.

Changes to this policy

We update this policy as the program develops and as the licensed provider and legal counsel require. The date at the top of the page shows when it last changed.

Contact

Privacy questions: support@cardexapro.com. General enquiries: support@cardexapro.com.