Legal
Privacy Policy
Last Updated: July 14, 2026 — Version 1.0
1. Introduction and Data Controller
Welcome to LookPay. LookPay Limited (“we”, “us”, “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, transfer, and store your personal data when you use the LookPay mobile application (the “App”) and our associated (backend) services (the “Services”).
This document has been prepared in strict compliance with the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and the Irish Data Protection Act 2018.
For the purposes of the GDPR, LookPay Limited is the Data Controller for all personal data collected through the App and Services. Our registered operational base is located in Letterkenny, County Donegal, Ireland. If you have any questions regarding this policy, your data protection rights, or how we handle your personal data, you can contact us directly at privacy@lookpay.app.
2. Our Legal Bases for Processing Data
Under GDPR Article 6, we are required to establish an explicit legal basis for every data processing activity we perform. LookPay processes your personal data under the following four legal foundations:
Performance of a Contract (Art. 6(1)(b) GDPR)
Processing is mandatory where it is required to fulfill our contractual commitments to you. This includes setting up your user account, verifying your identity, authenticating your login sessions, and completing proximity payments between your device and physical merchant terminals.
Consent (Art. 6(1)(a) GDPR)
For certain device-level permissions and functions, we rely on your explicit, affirmative, and opt-in consent. Examples include accessing your device’s background location capabilities or granting permission to detect nearby payment terminals. You maintain the absolute right to withdraw your consent at any time via your device’s operating system settings.
Legitimate Interests (Art. 6(1)(f) GDPR)
We process data when it is necessary for our legitimate business operations, provided those interests do not override your fundamental rights and freedoms. This includes protecting your account and our platform from fraud and unauthorized access, and collecting anonymous technical diagnostic information to ensure software stability.
Compliance with a Legal Obligation (Art. 6(1)(c) GDPR)
As a proximity payment infrastructure platform, we are bound by regulatory frameworks, including Anti-Money Laundering (AML) directives, Know Your Customer (KYC) mandates, and financial auditing standards which legally compel us to collect, verify, and retain specific personal identifiers.
3. Data Processing Inventory
LookPay maintains a strict data minimization discipline. The tables below set out, in plain terms, the categories of personal data we process, why we process them, and the legal basis that authorizes each activity. In line with data protection best practice, this policy describes what data is processed and why — not the specific internal technical methods used to process it, which are proprietary to LookPay.
3.1 Data Processed Exclusively On Your Device (Never Sent to Us)
Certain signals are generated and evaluated entirely on your own device, in temporary memory, in order to keep your account and the App secure. This information is never transmitted to LookPay, never stored on our servers, and never shared with any third party.
| Data Category | Purpose | Shared with LookPay? |
| Device security signals | To help protect your account and detect potentially compromised, modified, or otherwise unsafe devices before allowing app access. | No — processed only on your device |
| Application integrity signals | To confirm that the copy of the App you are running is genuine and has not been altered or tampered with. | No — processed only on your device |
| Face positioning guidance | To help you frame your face correctly while taking a profile photo during registration. | No — processed only on your device |
3.2 Data We Collect and Store
The following categories of personal data are collected from you or your device and securely transmitted to LookPay’s servers over an encrypted connection.
| We Collect | Why We Collect It | Legal Basis |
| Account information (email, first name, last name, phone number) | To create, manage, and secure your LookPay account, and to send you important verification and security messages. | Contract |
| Password | To authenticate you and protect your account. Your password is never stored in readable form — it is transformed using a one-way cryptographic process before it is saved, so LookPay itself cannot see or recover it. | Contract |
| Verification codes | To confirm your email address and phone number during account setup and to prevent automated or fraudulent account creation. | Contract |
| Device verification information | Information generated by your device's built-in security services, used to help confirm that requests genuinely originate from your device and to prevent bot registrations or account takeovers. | Legitimate Interest |
| Authentication information | Used to keep you securely signed in, authenticate your requests, and allow you to manage or revoke access from specific devices. | Contract |
| Nearby terminal information | When you are completing a purchase, the App securely exchanges limited proximity information with our servers so that we can identify the correct participating payment terminal near you. | Contract |
| Notification information | Used to deliver transaction receipts, security alerts, and other service-related notifications to your device. | Contract (service notices) / Consent (marketing notices) |
| Profile photo | A standard photograph you upload — similar to a social media profile picture. Displayed on the Merchant Terminal so the merchant's employee can visually identify you at checkout. This is not a biometric scan, facial recognition template, or any other form of biometric data. It is simply a picture. | Contract |
| Initials (your first initial and surname initial, e.g. "J.D.") | Displayed on the Merchant Terminal alongside your photo and announced audibly at checkout to confirm your identity and the transaction amount. | Contract |
| Merchant Terminal audio recordings | When you complete a purchase, the Merchant Terminal records the audio announcement of your initials and the transaction amount. This creates an audit trail to resolve any disputes about what was charged. | Consent / Legitimate Interests |
| CCTV footage (obtained from Merchants) | In the event of a disputed transaction or suspected fraud, we may request CCTV footage from the Merchant's premises capturing the billing counter area. This helps us verify what happened during the transaction. | Legitimate Interests |
4. Third-Party Services and Processors
LookPay shares specific data fields with trusted third-party subprocessors to maintain financial regulatory compliance, infrastructure stability, and communication delivery. All external sharing is governed by explicit Data Processing Agreements (DPAs) that mandate strict compliance with GDPR standards.
At a high level, data flows from the LookPay App to LookPay’s own servers over an encrypted connection. From there, specific limited data fields are shared onward with regulated financial partners for identity verification and payment settlement, with communications providers for account notices, with secure storage providers for media hosting, with diagnostic providers for anonymous stability monitoring, and with the underlying mobile platform providers for device security checks and mapping services.
Regulated Payment and Identity Verification Partner
Data Shared: Account identifiers, identity documentation, and wallet configuration information.
Purpose: Statutory identity screening (KYC), Anti-Money Laundering (AML) controls, wallet management, and payment settlement.
Note: This partner is a licensed and regulated payment institution. Further details are available on request at privacy@lookpay.app.
Diagnostic and Crash Reporting Provider
Data Shared: Anonymized technical crash and stability information. No personally identifiable information is included.
Purpose: Identifying and fixing app crashes and improving software reliability.
Secure Media Storage Provider
Data Shared: Profile photo image data.
Purpose: Your device uploads your profile photo directly to an isolated, access-controlled storage environment operated on our behalf, which returns an anonymized reference so it can be linked to your account.
Transactional Communications Provider
Data Shared: Name, email address, and one-time verification codes.
Purpose: Delivering account verification messages, security alerts, and transactional receipts.
Mobile Platform Providers (Apple / Google)
Data Shared: Device verification information and, where relevant, location coordinates.
Purpose: Confirming that requests come from a genuine, uncompromised device, using the standard security and mapping services built into your phone’s operating system.
Some of our service providers process personal data on our behalf. While LookPay remains responsible for ensuring appropriate safeguards are in place, these providers also maintain their own privacy notices describing how they handle information within their services.
Current providers include:
- Google Firebase & Google Cloud
- Apple
- Paysafe
- Bird
These links are provided for transparency. Where these providers act as our data processors, they process personal data only on our documented instructions and in accordance with applicable data protection laws.
5. International Data Transfers
LookPay Limited operates primarily out of Ireland, with data storage architecture concentrated inside the European Economic Area (EEA). Whenever a third-party processor (such as specialized communication providers) requires routing data across international borders outside the EEA, LookPay enforces strict legal safeguards to guarantee your personal data retains an equivalent level of protection:
- Adequacy Decisions: We prioritize routing data to nations officially recognized by the European Commission as possessing an adequate layer of data security.
- Standard Contractual Clauses (SCCs): In the absence of an adequacy decision, data transfers are governed by the European Commission's approved Standard Contractual Clauses, supplemented by rigorous security assessments to ensure data processing centers protect your information from foreign surveillance vectors.
6. Local Device Security
Data security is integrated into the core design of LookPay. Without disclosing the specific mechanisms involved, we can confirm that the App is built to guard against physical device attacks and unauthorized local access through the following principles:
- Hardware-Backed Protection: Sensitive account and session information is stored using the strongest security protections your device's operating system makes available, rather than in ordinary app storage.
- Locked-Device Access Only: This protected information can only be accessed while your device is unlocked, and only by the LookPay App itself.
- Biometric Gatekeeping: Re-authenticating your session or approving a payment forces a local check of your device's biometric security (such as Face ID, Touch ID, or an Android biometric prompt), so that a lost or stolen phone cannot be used to access your account without your consent. Note that this is your device's own biometric system — LookPay does not receive, store, or process your fingerprint or face scan data.
- Non-Sensitive Local Preferences: Less sensitive configuration data, such as your saved home location, is stored using standard on-device storage, purely so the App knows when to check for nearby payment activity in the background.
7. Data Retention Terms
LookPay retains your personal data only as long as necessary to achieve its designated processing purposes, in accordance with the following criteria:
- Active Account Contexts: All core registration profiles, account identifiers, and hardware bindings are kept for the duration of your active relationship with LookPay.
- Proximity Data: Ephemeral background proximity information used to detect nearby payment terminals is automatically deleted or completely anonymized within thirty (30) days of collection, unless it is legally bound to a completed financial ledger transaction.
- Financial Regulatory Obligations: Any data tied to completed financial payments, formal identity validations, or AML screening logs is retained for a minimum of six (6) years following the closure of your account, as required by Irish and European financial compliance laws.
- Diagnostic Telemetry Logs: Crash records, system monitoring entries, and internal operational logs are purged automatically on a rolling ninety (90) day window.
- Merchant Terminal Audio Recordings: Audio recordings of the initials and amount call-out are retained as part of the transaction Server Records for a minimum of six (6) years, in accordance with applicable financial regulatory requirements, or until any dispute relating to the transaction is finally resolved, whichever is later.
- CCTV Footage: Any CCTV footage obtained from a Merchant in connection with a dispute or investigation is retained only for as long as necessary to resolve the specific dispute or investigation, and in any event no longer than the applicable limitation period for legal proceedings arising from the transaction.
8. Device Permissions Requested
The LookPay App requires access to specific hardware subsystems to operate. You maintain full control over these privileges and can grant or revoke them at any time via your operating system settings.
| Permission | Purpose |
| Location (Foreground / Always) | Used to establish your local coordinates during account setup. "Always/Background" access is required to allow the operating system to detect when you are near a payment terminal, letting the app check for terminals without requiring you to open your phone. |
| Bluetooth | Used to detect and estimate distance to nearby physical LookPay payment terminals for cardless checkout. |
| Camera | Used to capture your profile photo during registration and to frame identity verification documents. |
| Photo Library | Used to upload identity documents from your device's photo gallery for KYC compliance. |
| Biometrics (Face ID / Fingerprint Systems) | Used locally (on your device only) to verify your identity before unlocking the application layer or authorizing active payment intents. No biometric data is sent to LookPay's servers. |
| Notifications | Used to deliver real-time transaction receipts, security warnings, and multi-factor authentication challenges. |
| Battery Optimization Exemption (Android) | Allows LookPay to check for nearby payment activity in the background efficiently, without being aggressively shut down by the operating system's power management systems. |
| Microphone (Merchant Terminal) | When you are at the billing counter completing a purchase, the Merchant Terminal (not your phone) records the audio announcement of your initials and the amount. Your phone's microphone is not used for this purpose. |
9. Your Legal Rights Under the GDPR
As a resident of the European Union, European Economic Area, or the United Kingdom, you possess the following statutory rights under Articles 15-22 of the GDPR:
Right of Access (Art. 15 GDPR)
The right to request an explicit disclosure detailing what personal data we process, alongside a comprehensive, free digital copy of all your records.
Right to Rectification (Art. 16 GDPR)
The right to compel us to immediately correct inaccurate, outdated, or incomplete records linked to your identity.
Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR)
The right to demand the permanent deletion of your personal data from our systems, provided the data is no longer required for active contractual processing or mandated financial retention compliance.
Right to Restriction of Processing (Art. 18 GDPR)
The right to limit how we process your data (e.g., suspending active processing while you formally contest the accuracy of your records).
Right to Data Portability (Art. 20 GDPR)
The right to receive your personal data in a structured, commonly used, and machine-readable format (such as JSON) to transfer it to another provider.
Right to Object (Art. 21 GDPR)
The right to object to processing activities carried out under our Legitimate Interests path. We must halt processing unless we demonstrate overriding compelling legitimate grounds.
Right to Withdraw Consent (Art. 7(3) GDPR)
Where processing relies entirely on your explicit consent, you may withdraw it at any time. This withdrawal will not affect the lawfulness of any processing conducted before the withdrawal.
How to Exercise Your Rights
To submit a formal Data Subject Access Request (DSAR) or exercise any of your rights, please email us at privacy@lookpay.app from your registered email address. To protect your security, we will verify your identity before fulfilling any data requests. We will address your request within thirty (30) days of receipt, free of charge.
Lodging a Complaint with a Supervisory Authority
If you believe that LookPay’s data processing activities infringe upon your rights under the GDPR, you have the right to file a formal complaint with a European data protection authority.
Because LookPay Limited operates out of Ireland, our primary supervisory authority is the Irish Data Protection Commission (DPC). You can contact them directly or file an application via their official website: www.dataprotection.ie.
10. Children’s Privacy
LookPay is a financial proximity payment utility and is not designed for, marketed to, or intended for use by individuals under the age of eighteen (18) years. We do not knowingly collect, process, or solicit personal data from children. If we discover that an individual under 18 has registered an account and provided us with personal data, we will immediately delete their information and deactivate their account profile.
11. Amendments to this Privacy Policy
LookPay Limited reserves the right to modify or update this Privacy Policy as our technology, services, and regulatory requirements evolve. When modifications are published, we will update the “Last Updated” date at the top of this document. For significant modifications that alter your rights or how your data is handled, we will provide prominent notice inside the App or deliver an email notification directly to your registered address prior to the changes taking effect.
12. Contact and Inquiries
If you have any questions, concerns, or feedback regarding this Privacy Policy, our approach to security, or our compliance with European data protection laws, please contact our privacy team:
Email: privacy@lookpay.app
Postal Address: LookPay Limited, Ireland
Version 2.0 — Last Updated July 20, 2026. © 2026 LookPay Limited. All rights reserved.
13. Audio Recording and CCTV
As described in our Terms of Service, the LookPay proximity checkout ecosystem involves the following additional processing activities that may capture your personal data:
13.1 Merchant Terminal Audio Recording
When you are present at a Merchant’s billing counter and a transaction is in progress, the Merchant Terminal records the audio of the initials and amount call-out. Specifically:
- The Merchant Terminal may audibly announce your initials (e.g. "J.D.") and the transaction amount using text-to-speech, or the Merchant's employee may speak them aloud.
- The audio of this call-out is captured and preserved as a Server Record.
- This recording is used to create an audit trail, to establish dynamic linking between the specific transaction amount and your identity in accordance with PSD2 requirements, and to resolve any disputes about what was charged.
Lawful Basis
Consent (Article 9(2)(a) GDPR) and Legitimate Interests (Article 6(1)(f) GDPR) in fraud prevention, dispute resolution, and the establishment or defence of legal claims.
13.2 CCTV Footage from Merchant Premises
Participating Merchants may operate CCTV surveillance systems on their premises. In the event of a disputed transaction or suspected fraud, we may request CCTV footage from the Merchant that captures the billing counter area. This footage helps us verify the identity of the person at the counter and the circumstances of the transaction.
Time Limitation: We may request CCTV footage only within thirty (30) calendar days of the transaction in question. Where the Merchant does not have or has not retained the relevant footage, we will resolve the dispute based on other evidence available to us.
Lawful Basis
Legitimate Interests (Article 6(1)(f) GDPR) in fraud prevention, dispute resolution, and the establishment or defence of legal claims.
13.3 No Expectation of Privacy at the Billing Counter
By using the LookPay service and entering a Merchant’s premises for the purpose of conducting a transaction, you acknowledge that you have no reasonable expectation of privacy in respect of your visual image, movements, or audible communications at the billing counter during the transaction process. Audio recordings and CCTV footage may be used as evidence in a dispute, investigation, or proceeding.
13.4 Your Rights Regarding Audio and CCTV Data
You have the right to:
- Access: Request a copy of any audio recordings or CCTV footage relating to your transactions (subject to the rights of others).
- Object: Object to processing based on legitimate interests, unless we demonstrate compelling legitimate grounds.
- Erasure: Request deletion of recordings, subject to our legal obligations to retain financial transaction records for six (6) years.
To exercise these rights, contact us at privacy@lookpay.app.