Privacy

Privacy statement

How Aon Tap Merchant Services ("AonTap", "we") collects, uses and protects personal data. Draft for legal review before go-live.

Last updated 2 October 2026.

1. Who we are

AonTap is an Irish merchant services provider. We arrange card acceptance through the licensed acquiring partner, supply and support payment terminals, and provide software (POS, loyalty, digital receipts, insights and impact payments). For merchant and website data we are the controller. For shopper data processed through loyalty and receipts we act as processor on behalf of the merchant. Contact: [email protected] .

2. Merchants and prospective merchants

Data Purpose Legal basis
Enquiry and quote data: name, business, email, phone, business type, turnover, current provider, statements you send Prepare a quote and respond Steps prior to a contract; legitimate interests
Onboarding: company and director details, identity and bank verification documents Identity verification (KYC) and anti-money-laundering checks; opening your account Contract; legal obligation
Account and support: terminal serials, configuration, tickets, invoices, dashboard logins Deliver and support the service Contract
Transaction data (amount, time, terminal, card type, scheme token) Settlement reporting, insights, fraud prevention Contract; legitimate interests

3. Your customers (shoppers)

  • Payment data is processed by the licensed acquiring partner on PCI DSS Level 1 infrastructure. AonTap does not receive full card numbers.
  • Digital receipts and loyalty operate only with the shopper's explicit consent captured on the terminal. We process a scheme-provided card alias or Payment Account Reference, the contact channel the shopper chose, transaction line items and loyalty balances, in order to deliver receipts and recognise returning customers. The merchant is controller; AonTap is processor under a Data Processing Agreement, with Green Till Limited as sub-processor for receipt delivery. Shoppers can withdraw consent at the terminal, via any receipt, or by emailing [email protected].
  • Impact payments : contribution amount and chosen project are recorded on the impact ledger linked to the transaction; no additional personal data is collected unless the shopper opts into the GreenTill app.

4. Sharing

The licensed acquiring partner (acquiring, processing, settlement, KYC); Green Till Limited (digital receipt delivery, loyalty engine); verified impact partners (aggregated contribution amounts only, never shopper identities); hosting, email and support providers; professional advisers; and authorities where required by law. We do not sell personal data.

5. International transfers

Our core providers process data in the EEA. Where a provider transfers data outside the EEA we rely on EU Standard Contractual Clauses or an adequacy decision.

6. Retention

Enquiry data: 12 months after last contact if no contract follows. Merchant account data: the duration of the agreement and 7 years afterwards for tax and AML purposes. Shopper receipt and loyalty data: until consent is withdrawn or the merchant ends the service, subject to statutory retention of transaction records.

7. Your rights

Under the GDPR you may request access, rectification, erasure, restriction and portability, object to processing based on legitimate interests, and withdraw consent at any time. Email [email protected]. You may also complain to the Data Protection Commission, Ireland (dataprotection.ie).

8. Cookies

This website sets only strictly necessary cookies and uses local storage for site function. No analytics or marketing cookies are set. If that changes, a consent banner will be shown first and this section updated.

9. Security

Terminals are PCI PTS 6 certified with end-to-end encryption. Payment processing takes place on the licensed acquiring partner's PCI DSS Level 1 platform. AonTap applies access controls, encryption in transit and at rest, tokenisation for loyalty, and staff confidentiality obligations to the data it holds. We will notify affected merchants and the Data Protection Commission of a personal-data breach as required by law.

10. Changes

We post updates here and, for material changes, notify merchants by email.