Privacy Policy

How LynkPay Ltd collects, uses and protects your personal data.

Effective date: 16 June 2026 · Last updated: 16 June 2026

1. About us and this notice

LynkPay Ltd (“LynkPay”, “we”, “us” or “our”) operates the website www.lynkpay.co.uk and a payment disbursement, reconciliation and settlement platform used by transport operators and the workers, partners and suppliers they pay. We are committed to protecting your privacy and handling your personal data lawfully, fairly and transparently. This Privacy Policy explains what personal data we collect about you, how and why we use it, who we share it with, how long we keep it, and the rights you have over it. It applies to visitors to our website, prospective and existing customers, drivers and other individuals we pay through the platform, and other individuals whose data we process in the course of our business. LynkPay Ltd is the controller of the personal data described in this notice, meaning we determine how and why it is processed, unless we say otherwise. Our company number is 13288967 and our registered office is We Work, 1 St. Peters Square, Manchester, M2 3DE. LynkPay Ltd is registered with the Information Commissioner’s Office (the “ICO”) as a data controller. You can check our registration on the ICO’s public register at ico.org.uk.

2. Our relationship with Modulr

LynkPay is an Appointed Representative and Partner Platform of Modulr Finance Limited. The payment accounts and electronic money services accessed through our platform are provided by Modulr FS Limited, which is authorised and regulated by the Financial Conduct Authority as an Electronic Money Institution. LynkPay is not a bank or an electronic money institution and does not hold or safeguard your funds — safeguarding of funds is undertaken by Modulr. Where you hold or use a payment account, Modulr acts as a controller of certain personal data in its own right — for example, in carrying out customer due diligence, processing transactions, safeguarding funds and meeting its own regulatory obligations. Modulr’s processing is governed by its own privacy notice, which is available at modulrfinance.com/privacy-policy. We recommend you read it alongside this policy.

3. The personal data we collect

Personal data is any information that relates to an identified or identifiable individual. We collect and process the following categories of personal data: Identity data — such as your name, title, date of birth and, where required for verification, copies of identity documents. Contact data — such as your postal address, email address and telephone numbers. Account and relationship data — such as the operator or business you are associated with, your role, account identifiers, settings and preferences, and records of your dealings with us. Payment and transactional data — such as bank account or payment details used to receive disbursements, payment amounts, dates, references and transaction history processed through the platform. Verification and onboarding data — information collected to verify identity and meet anti-money-laundering, fraud-prevention and other regulatory requirements, which may be collected by us and shared with, or collected on behalf of, Modulr. Communications data — the content of, and metadata about, your communications with us by telephone, email, messaging, post or through the platform, including support enquiries and complaints. Technical and usage data — such as your Internet Protocol (IP) address, device and browser information, login data, time-zone settings, the pages and features you use, and other information collected through cookies and similar technologies (see our Cookie Policy). Marketing and preference data — your preferences in receiving marketing from us and your communication preferences. We may also process special category data (such as data revealing health or other sensitive information) only in limited circumstances, for example to detect and prevent fraud and financial crime, to support customers with accessibility or vulnerability needs, or to handle a complaint. We do this only where we are permitted to under data protection law, such as where it is necessary for reasons of substantial public interest or where you have given explicit consent.

4. How we collect your personal data

We collect personal data in the following ways: Directly from you — when you register or transact on the platform, complete forms, contact us, respond to communications, or otherwise interact with us or our website. From transport operators and dispatch partners — the businesses that engage our platform may provide data about the drivers and other individuals they pay, including through integrated dispatch systems such as Autocab and iCabbi. From Modulr and our payment partners — in connection with the provision of payment accounts and the processing and settlement of payments, including through partners such as Volt and Bridge. From third parties — such as identity-verification providers, credit-reference and fraud-prevention agencies, banks (where permitted by law), and law-enforcement or government agencies. From publicly available sources — such as Companies House and, depending on your settings, social-media platforms. Automatically — through cookies and similar technologies when you use our website, as described in our Cookie Policy.

5. How and why we use your personal data

We will only use your personal data where the law allows us to. Most commonly, we will use it on the following lawful bases: Performance of a contract — to provide, operate and support the platform and the services you or your operator have requested, including processing disbursements and reconciling payments. Legitimate interests — where it is necessary for our legitimate interests (or those of a third party) and your interests and rights do not override those interests; for example, to administer and improve our services, manage our relationship with you, ensure security, prevent fraud and financial loss, and grow our business. Legal and regulatory obligations — to comply with our obligations under applicable law and regulation, including anti-money-laundering, counter-terrorist-financing, fraud-prevention, tax and reporting requirements. Consent — where we rely on your consent, for example for certain marketing or for the use of non-essential cookies. You can withdraw your consent at any time. Examples of how we use your personal data include: setting up and administering accounts and the platform; verifying identity and carrying out due diligence; processing and reconciling payments and disbursements; communicating with you and providing support; detecting, investigating and preventing fraud, financial crime and other prohibited activity; meeting our regulatory and legal obligations; analysing and improving our website, products and services; and, where permitted, sending you relevant marketing. Treating customers fairly and supporting vulnerability Many of the individuals we pay through the platform, including private-hire and taxi drivers, are individual retail customers. We are committed to delivering good outcomes for our customers in line with the regulatory principles that apply to our business. As part of this, we may use personal data to identify and respond appropriately to customers in vulnerable circumstances and to ensure our services are accessible and fair.

6. Marketing

We may send you information about our products and services where you have asked us to, where you are an existing customer and the law permits, or where you have otherwise consented. You can ask us to stop sending you marketing at any time by using the unsubscribe link in our emails or by contacting us using the details below. Asking us to stop marketing will not affect any processing we carry out to provide our services to you or to meet our legal obligations.

7. Who we share your personal data with

We do not sell your personal data. We may share it with the following categories of recipient, in each case only to the extent necessary and subject to appropriate safeguards: Modulr — as our principal payment partner and the provider of payment accounts and electronic money, for account provision, transaction processing, safeguarding and regulatory purposes. Payment and integration partners — such as Volt, Bridge, Stripe, and dispatch partners including Autocab and iCabbi, where necessary to provide and operate the services. Service providers — who process personal data on our behalf under contract, for example for hosting, IT, identity verification, communications, analytics and professional services. They may only use your data on our instructions and must keep it secure. Fraud-prevention and credit-reference agencies — to prevent and detect fraud and money laundering and to verify identity. If fraud is detected you may be refused certain services. Further information about how such agencies use data is available at cifas.org.uk/fpn. Regulators, authorities and law enforcement — where we are required or permitted by law to do so, including in response to a court order or a lawful request. Professional advisers — such as auditors, lawyers and accountants, where reasonably necessary. Corporate transactions — if we sell, transfer or reorganise our business or assets, your personal data may be disclosed to a prospective buyer or investor and their advisers, subject to appropriate confidentiality protections, and may continue to be used as described in this policy.

8. International transfers

We are a UK business and store and process personal data primarily in the United Kingdom. As our platform expands into Europe and the United States, and where our partners or service providers operate outside the UK, some of your personal data may be transferred to and processed in countries outside the UK. Where we make such a transfer, we ensure an appropriate level of protection is in place, for example by relying on an adequacy decision or by putting in place approved contractual safeguards such as the UK International Data Transfer Agreement or the International Data Transfer Addendum to the European Commission’s standard contractual clauses.

9. How long we keep your personal data

We keep your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to provide our services and to meet our legal, regulatory, accounting, tax and reporting obligations. In some cases we are required by law to retain certain records for a minimum period — for example, records relating to anti-money-laundering and transactions are generally retained for at least five years after the end of our relationship with you. We may also retain data where necessary to establish, exercise or defend legal claims. When we no longer need your personal data, we will securely delete or anonymise it.

10. How we keep your personal data secure

We take the security of your personal data seriously and have put in place appropriate technical and organisational measures to protect it against unauthorised or unlawful access, alteration, disclosure, loss or destruction. We restrict access to those who need it to perform their roles, and they are subject to a duty of confidentiality. We also have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator where we are legally required to do so.

11. Your rights

Subject to certain conditions and exemptions, you have the following rights under data protection law: Right of access — to obtain a copy of the personal data we hold about you. Right to rectification — to have inaccurate or incomplete data corrected. Right to erasure — to ask us to delete your personal data in certain circumstances. Right to restrict processing — to ask us to limit how we use your data in certain circumstances. Right to object — to object to our processing based on legitimate interests, and to object to direct marketing at any time. Right to data portability — to receive certain data in a structured, commonly used and machine-readable format. Right to withdraw consent — where we rely on your consent, you may withdraw it at any time, without affecting processing carried out before withdrawal. Rights relating to automated decision-making — see section 12 below. To exercise any of these rights, please contact us using the details in section 14. We will not usually charge a fee and will respond within the time limits set by law. We may need to verify your identity before acting on a request.

12. Automated decision-making

We may use automated tools to help screen transactions and identify potential fraud or financial crime. Where any decision producing a legal or similarly significant effect on you is based solely on automated processing, we will only do so where permitted by law and with appropriate safeguards, including your right to obtain human intervention, to express your point of view and to contest the decision.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will publish the updated version on our website and update the date at the top of this policy. Where changes are significant, we will take reasonable steps to bring them to your attention. We encourage you to review this policy periodically.

14. How to contact us

If you have any questions about this policy or how we handle your personal data, or if you wish to exercise your rights, please contact our Data Protection Officer, Stephen Quinn, at dpo@lynkpay.co.uk, or by email to privacy@lynkpay.co.uk. You can also write to us at: LynkPay Ltd, We Work, 1 St. Peters Square, Manchester, M2 3DE You have the right to make a complaint at any time to the Information Commissioner’s Office, the UK supervisory authority for data protection matters, at ico.org.uk/make-a-complaint. We would, however, appreciate the chance to address your concerns before you approach the ICO, so please contact us first.