1. Purpose of this policy
This policy describes personal-data processing through the marketing website, PayLinker accounts and organisations, payment links, ticketing, subscriptions, support and security functions. It supplements the information supplied by the professional or Organiser for their own processing.
2. PayLinker's identity and contact details
PayLinker is published by Nicolas MARTIN, 93 avenue Georges Clémenceau, 34500 Béziers, France, SIRET 518 239 926 00034. For any personal-data question, contact contact@paylinker.fr.
3. People covered
This policy applies to visitors and prospects, professional Customers and their representatives, organisation administrators and Users, payment-link Recipients, Ticket Buyers, attendees checked at admission, support contacts and people exercising a data-protection right.
4. PayLinker's and the professional's roles
PayLinker acts as controller for purposes it determines itself: accounts and organisations, PayLinker subscriptions and billing, support, platform security, evidence of PayLinker terms, the marketing website and related preferences.
Where PayLinker processes a professional's customer contact details, Event, Buyer, attendee, Ticket or Control data on that professional's instructions, the professional or Organiser is generally the controller and PayLinker the processor. The professional determines the purpose, necessary data, lawful basis, suitable retention and authorised staff. Any joint determination of purposes and essential means would require a specific assessment.
5. Website-visitor data
PayLinker may process pages viewed, date and time, technical browser and device information, the IP address required for connection and security, language, theme and campaign parameters in the URL. For a limited time, the site may also remember the latest commercial action used to understand the source of a registration.
These data support site operation, security, preferences and the audience measurement described in the cookie policy.
6. User-account data
To create and manage a professional account, PayLinker may process name, email, phone number, language, profile image, password in protected form, role, organisation, account status, permissions and activity dates. Where an available third-party sign-in option is chosen, the identifier required for that sign-in is also processed.
Onboarding and acquisition information, support exchanges, security records and information required to evidence acceptance of PayLinker terms may also be retained.
7. Organisation data
PayLinker processes supplied business information: business name, company and VAT identifiers where provided, contact details, address, activity, website, images, currency, settings, members and agents, Organiser terms and pricing settings.
The Service also processes SMS-credit balances and movements, subscription offer and status, billing amounts and periods, and Stripe connection information required for onboarding and account status. Necessary Stripe technical identifiers and tokens are protected; complete bank details are not required merely to display account status.
8. Payment-link recipient data
When a professional sends a payment link, PayLinker processes on its behalf data entered or imported, such as identity, contact details, customer reference, requested amount, link purpose, status and events required for delivery and tracking.
The professional is responsible for the source of the data, its message, the Recipient notice and applicable lawful basis. PayLinker does not use those contact details for its own marketing without a separate basis.
9. Ticket-buyer data
The checkout processes the Buyer's first name, last name and email, together with the selected Event, Ticket types and quantities, amount, currency, Order status and creation and payment dates. A technical payment reference is associated with the Order without exposing complete card data.
These data reserve places, initiate payment, record the Order, send Tickets, support the Buyer and let authorised Organiser staff manage attendees. Those staff may be able to search by name or email.
10. Event and Order data
Event data include name, description, cover, venue, dates, timezone, capacity, status and Ticket types. Order data include selections, amounts, payment status, Buyer and information required for tracking.
The Organiser is responsible for published content and should avoid unnecessary personal data in descriptions, images and free-text fields.
11. Tickets and QR codes
Each Ticket includes an identifier, type, status, creation and delivery dates, Order, Buyer and a unique QR code or validation token. The QR code retrieves and validates the Ticket; it does not contain complete payment-card data.
Validation tokens are protected, and their cryptographic fingerprint checks the presented code without displaying its value in interfaces or messages. The Buyer must protect the Ticket against copying.
12. Admission control and history
People authorised by the Organiser may scan a Ticket on the web or mobile app or validate it manually. PayLinker records the Ticket, date and time, result, User performing the Control, source and limited technical information where needed for operation and security.
The history can report that a Ticket was already used. Authorised Organiser staff may view attendees and Controls for their duties.
13. Temporary reservations and abuse prevention
When a Buyer selects Tickets, places may be reserved for about fifteen minutes. To limit repeated or abusive reservations, PayLinker may create a pseudonymous fingerprint from connection information. It is not used to identify the person publicly and must remain limited to this security and availability purpose.
14. Payment and Stripe's role
Stripe collects and processes the information needed for payment directly on its secured interfaces. PayLinker receives references and statuses needed to track the Order, confirm payment and create Tickets. PayLinker does not store full payment-card data.
In the audited Stripe Connect flow, funds are directed to the Organiser's connected account. Stripe acts under its own duties and terms for payment, compliance and fraud-prevention services.
15. Transactional emails and SMS
PayLinker uses supplied contact details to send payment links, confirmations, Tickets, necessary Order information, account invitations and security messages. These communications are required for the requested service and are not, by themselves, direct marketing.
Technical delivery providers may receive only the contact details and content required to deliver the message, for the period needed for that operation and their applicable duties.
16. Support, security and technical logs
Support requests, diagnostics and necessary technical records are processed to respond, maintain the Service, detect abuse, prevent fraud and manage incidents. Logs are limited to useful information and must not contain secrets, card data or full payment payloads.
18. Purposes and lawful bases
Depending on the processing, PayLinker relies on:
- contract or pre-contractual steps for accounts, organisations, subscriptions, the Service, contractual support and necessary communications;
- legal obligation for billing, accounting, authorised public requests and certain rights handling;
- legitimate interests, after balancing, for security, fraud and abuse prevention, legal defence, strictly necessary improvement and evidence of professional relations;
- consent only where required, such as for an optional tracker or communication with no other lawful basis.
For processing performed on an Organiser's behalf, that Organiser determines the lawful basis for its Buyer or attendee relationship. PayLinker does not request generic GDPR consent to process an Order needed to perform the contract.
19. Recipients and processors
Data may be accessed by authorised PayLinker personnel, authorised organisation Users for their own attendees, Stripe for payment, the host named in the legal notice, selected technical delivery, sign-in and operating providers, and advisers or authorities where law permits.
PayLinker does not sell personal data. When acting as processor, it governs its subprocessors and assists the professional within its role and documented instructions.
20. Possible transfers outside the EEA
Some international payment or sign-in providers may process data outside the European Economic Area depending on the selected service and their organisation. Where the GDPR requires it, transfers must rely on an adequacy decision, standard contractual clauses or another recognised safeguard, supplemented where necessary.
Information about applicable providers and safeguards may be requested from contact@paylinker.fr.
21. Retention periods and criteria
Data are retained for the period needed for the purpose, then deleted, anonymised or placed in limited archives where a legal obligation or defence of rights requires it. Criteria include the life of the account or contract, Event and follow-up period, Organiser instructions, dispute limitation periods and accounting duties.
Accounting records are retained for ten years under applicable requirements. Active reservations last about fifteen minutes, the campaign-attribution cookie up to thirty days and the last-action cookie up to thirty minutes. Logs, Tickets, Controls, notes, backups and account data must not be retained beyond documented need and applicable duties.
22. Individual rights
Subject to GDPR conditions, you may request access, rectification, erasure, restriction and portability, object to processing based on legitimate interests and withdraw consent for the future. Legal duties, others' rights, security or the need to defend a claim may limit a request.
23. Exercising rights
For a PayLinker account or PayLinker's own processing, contact contact@paylinker.fr and describe your request. Proportionate identity evidence is requested only where there is reasonable doubt about identity.
For an Order, Ticket or Event, contact the Organiser first, as it is generally the controller. PayLinker forwards or assists where the request reaches it and concerns data processed for that Organiser.
24. Complaint to the CNIL
You may lodge a complaint with the French data protection authority, the CNIL, including through its online complaint service, without affecting any other remedy.
25. Security
PayLinker applies technical and organisational measures proportionate to risk, including organisation access controls, protection of passwords and secrets, encryption of sensitive tokens, verification of payment notifications, attempt limits, useful logging and environment separation.
No online service can guarantee zero risk. Customers must protect access, limit Users, secure Control devices and report incidents promptly.
26. Children and sensitive data
The standard Service is not designed to collect health, biometric, opinion or other special-category data in free-text fields. A professional should only process such data or children's data where necessary, lawfully based, clearly explained and suitably protected.
PayLinker does not automatically verify a Buyer's age. An Organiser addressing children must define the information, permissions and measures required for the Event.
27. Changes to this policy
PayLinker may update this policy for changes to the Service, providers or law. The published version carries an update date. A material change is notified by an appropriate method where it significantly affects individuals.
28. Last updated
This policy was updated on 14 July 2026. It should be read with the terms of sale and use, cookie policy and information supplied by the professional or Organiser.
Last updated: 14 July 2026