FlintN

Privacy Policy

Effective Date: Oct 29, 2025

Introduction

This Privacy Policy explains how Flintn TM ("we", "us", "our") collects, uses, and protects personal data when you purchase products or use our checkout and related services (collectively, the "Service").

We act as the Merchant of Record (MOR) for transactions between you ("Buyer") and independent sellers or software vendors ("Merchants"). This means that we process your payment and handle all related billing, invoicing, and tax obligations.

We are committed to protecting your privacy and handling your personal data responsibly, in compliance with applicable laws such as the General Data Protection Regulation (GDPR), the UK Data Protection Act, and the California Consumer Privacy Act (CCPA).

Data Roles and Responsibilities

Flintn TM acts as a Data Controller for personal data we collect from buyers and website visitors during checkout and payment processing.

Merchants (the product or service providers) are independent Data Controllers or Data Processors for any personal data they receive from us or directly from you to deliver their products or services.

Each party is independently responsible for compliance with applicable data protection laws.

If you have questions about how a specific Merchant processes your personal data, please contact that Merchant directly using their published contact information.

Personal Data We Collect

We collect the following categories of data when you interact with our Service:

1.

Identity and Contact Information

such as your name, email address, billing address, and country of residence.

2.

Payment Information

– details necessary to process your payment, such as partial card information, payment method type, and transaction reference. We never store full credit-card numbers or security codes.

3.

Transaction Data

– information about the products or services purchased, transaction amounts, currency, taxes, and timestamps.

4.

Technical Data

– IP address, browser type, device information, and usage logs for fraud prevention and platform security.

5.

Communication Data

correspondence with our support team or the Merchant’s support channels.

How do we use Your Personal Data

We use your personal data only for purposes that are lawful, fair, and necessary to provide our services. This includes processing and completing your purchase, issuing invoices and payment confirmations, and providing you with customer or billing support.

We also use your information to calculate, collect, and remit applicable taxes such as VAT, GST, or sales tax in accordance with relevant laws. To protect both you and our business, we monitor transactions to detect and prevent fraud, misuse, or other unauthorized activity.

In addition, we process personal data to comply with our legal, accounting, and financial reporting obligations, and to maintain and improve the security, functionality, and performance of our platform.

All personal data is processed on lawful bases, including the performance of a contract, compliance with legal obligations, and our legitimate business interests. In cases where the law requires it, we will seek your explicit consent before processing your personal information.

Legal Basis for Processing:

you have provided your consent for us to use your personal information for a specific purpose, such as sending you our newsletters and marketing emails;

our use of your personal information is necessary to perform a contract or take steps to enter into a contract with you (e.g. to provide you with services which you have purchased);

processing is necessary for the purposes of our legitimate interests (e.g. the assessment of business efficiency by analyzing website traffic and financial performance indicators; user session control and fraud prevention, ensuring the appropriate protection of personal data; promotion of Services through social media networks);

the processing is necessary to comply with a relevant legal obligation or regulatory obligation that we have (e.g. data subject request processing).

Sharing and Disclosure

We share personal data only when it is necessary for legitimate business or legal reasons, and always under strict security and contractual controls. Your data may be shared with Merchants so that they can deliver the products or services you have purchased and provide related customer support.

We also share information with payment processors, banks and tax authorities to process and reconcile transactions, ensure proper invoicing, and fulfill our financial obligations. To help protect against fraud and maintain compliance, we may work with fraud-prevention and compliance partners who assist in verifying identity and detecting suspicious activity. Certain data may be processed by trusted service providers, such as cloud-hosting, analytics, and IT-security companies, which operate under data-processing agreements that require them to handle your data securely and only according to our instructions.

In limited circumstances, we may be required to disclose personal data to comply with legal or regulatory obligations, such as responding to lawful requests from public authorities or law enforcement.

We do not sell, rent, or trade your personal data to any third parties.

International Data Transfers

Your personal data may be transferred and processed outside your country of residence, including in jurisdictions that may not offer the same level of protection as the EU or UK.

When we transfer data internationally, we ensure adequate safeguards, such as Standard Contractual Clauses (SCCs)approved by the European Commission or equivalent mechanisms under applicable law.

Data Retention

We retain personal data as follows:

Transaction and payment data: as required by applicable tax laws;

AML/KYC records: as required by applicable anti-money laundering laws;

Customer support communications: 5 years from case closure;

Marketing consent data: until consent withdrawn or 5 years of inactivity;

Technical logs and fraud detection data: 5 years unless subject to investigation.

Your Rights

Depending on where you live, you may have certain rights in relation to the personal data we hold about you. These rights may include the right to access and obtain a copy of your personal information, as well as the right to request that we correct or delete any data that is inaccurate or outdated. You may also have the right to restrict or object to the way your data is processed, and, in some cases, to receive your personal information in a structured, commonly used, and machine-readable format (the "right to data portability").

If our processing of your personal data is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

Finally, you have the right to lodge a complaint with your local data protection authority if you believe that your rights have been violated or that your data has not been handled in accordance with applicable law.

If you wish to exercise any of these rights, please contact us using the details provided at the end of this Privacy Policy.

Cookies and Tracking Technologies

We use cookies and similar technologies to ensure secure payments, enable website functionality, and analyze performance.

For more information about how cookies are used and how to manage your preferences, please refer to our Cookie Policy.

Data Security

We use appropriate technical and organizational measures to protect your data from unauthorized access, loss, or misuse. This includes encryption, secure storage, access control, and ongoing monitoring of our systems and processors.

Children’s Privacy

Our services are not directed to children under 18 years of age, and we do not knowingly collect personal data from minors. If we become aware that data has been collected from a minor without parental consent, we will delete it immediately.

Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, technology, or our business practices. The latest version will always be available on our website and will indicate the effective date at the top of this page.

Contact Information

If you have questions or concerns about this Privacy Policy or wish to exercise your data-protection rights, please contact us at:

Email:

security@flintn.com

Merchant of Record: Flintn TM

Address: Nicosia, Cyprus