Privacy Notice
Version 1.0 – June 2026
This Privacy Notice explains how we process your Personal Data in connection with our
services on behalf of our clients, when you use our services directly when you are
browsing our website, or interacting with us in any other way. This Notice covers how we may share your Personal Data with third parties and the safeguards we have implemented to protect your information. Where we process Personal Data as a processor or service provider, this Privacy Notice is intended to provide transparency regarding our processing activities References to “we,” “us,” and “our” in this Privacy Notice refer to CoreCard Software, Inc. or CoreCard. We recommend reviewing this Privacy Notice regularly for updates, which will be posted on our Website. Where local laws require additional information, these are provided in the Regional Privacy Notices section. We process Personal Data for most of our products and services as a data processor. As a data processor, we process personal data about our end users on behalf of our customers to provide the products and services based on their instructions. You should contact these organizations directly for information about how they process your
personal data as a data controller and to exercise your rights in relation to that data.
Frequently Asked Questions (FAQs)
Contact
Our privacy team is available to address any questions or requests through the following
channels:
dpo@euronetworldwide.com
by phone available here
webform available here
by traditional post, you can write to: DPO, Calle Cantabria 2, 2-A
Alcobendas Madrid, Spain
Who are we?
We are CoreCard, also known as CoreCard Software, Inc., a part of the Euronet Worldwide group of companies. For specific corporate information about CoreCard, you may visit this link
What type of Personal Data do we collect?
We only collect the Personal Data necessary to provide our services and comply with legal requirements.
From where do we obtain your data?
To provide our services, your Personal Data is provided by our partners, with whom you
have a contractual relationship. We may also collect Personal Data directly from you when
you interact with our products and services, and additional data to fulfil our obligations
from other sources.
Why do we collect Personal Data?
We collect Personal Data for specific contractual and legal purposes, including with our
partners. Additionally, with your consent, we may collect data for other purposes to
improve your experience.
For how long do we retain Personal Data?
We may retain Personal Datafrom our production systems within our backup or archive
data structures, in our systems, as mandated by law, or to exercise or defend against any
legal claims. Upon request from you, we will delete your Personal Data.
With whom do we share Personal Data?
We may share Personal Data with Euronet Group companies, legal authorities, and
selected third parties/partners when required to meet regulatory standards or fulfill
contractual commitments.
Where is Personal Data stored?
We store Personal Data in secure facilities with stringent security controls. If data transfer
to other international locations is needed, we ensure compliance with legal obligations
and maintain the highest security standards.
What are your rights regarding Personal Data?
Depending on your location, you may have specific rights concerning your Personal Data
under applicable laws. Common rights are described under the section “Your Rights”
below.
Your Rights
To exercise any of your rights, please email us at dpo@euronetworldwide.com. To
safeguard your privacy, we may ask you to verify your identity and provide additional
details before granting access to or modifying your Personal Data. If a valid ID or other
legal documentation verifying your identity is not available, we may be unable to fulfill
your request.
Depending on your location, your rights concerning Personal Data under applicable laws
may include:
- Right to Know: You have the right to know what Personal Data is collected, sold,
or shared, and with whom. - Right to Access: You may request access to a copy of your Personal Data.
- Right to Correct: You can request corrections to inaccuracies in your Personal
Data. - Right to Delete: You may request deletion of your Personal Data under certain
conditions. - Opt-Out Rights:
You may opt-out of the processing of Personal Data for targeted advertising.
You may opt-out of the processing of Sensitive Personal Data.
You may opt-out of the processing of Personal Data for profiling that leads
to legal or significant effects on you. - Right to Limit Use of Sensitive Data: You may request to limit the use and
disclosure of Sensitive Personal Data to specific, permitted purposes. - Right to Restrict Processing: You can request restrictions on data processing
under certain conditions. - Right to Data Portability: You may request receiving your Personal Data in a
structured, commonly used, machine-readable format and have the option to
transmit it to another controller under specific conditions. - Right to Object: You may object to the processing of your Personal Data, for
example, for direct marketing purposes. - Rights Related to Automated Decision-Making: You have the right not to be
subject to decisions based solely on automated processing, including profiling, that
produces legal or similarly significant effects. - Right of No Retaliation: You have the right not to face discrimination for
exercising your Personal Data rights.
We will respond to your requests promptly and within the timeframe required by the
applicable law. For specific rights in your jurisdiction, refer to the Regional Privacy Notice
section below.
Please note that some rights may not be enforceable due to business or legal
requirements necessary to provide our services, such as anti-money laundering,
contractual, or compliance obligations. However, we will always respond to any rights
requests as outlined above, and you may have additional rights based on your location.
Our Role in Processing Your Personal Data
The categories, sources, and purposes for collecting Personal Data are outlined below,
including purposes for processing. If you do not provide accurate Personal Data, we may
be unable to deliver our Services effectively. Where Personal Data collection is based on
your consent, you can withdraw that consent at any time. We retain Personal Data for as
long as reasonably necessary to provide the Services and meet our legal obligations.
We do not and will not “sell” or “share” your Personal Data, as defined by applicable
laws. We collect Personal Data from the following sources: (a) our clients; and (b) directly
from you when your use our services directly.
If you have questions or concerns about how we process your Personal Data, please
contact us at dpo@euronetworldwide.com.
Types of Personal Data
- Identification Data
We collect identification data, such as your name, email, phone number, residential and/or business address, and other contact data, title, date of birth, gender, images, videos, and signature, as necessary to provide our services.
| Purpose of the Processing | Legal Basis | CoreCard acting on behalf of a client | CoreCard’s website |
| To perform/supply the Services. | Contractual obligation | Yes | N/A |
| To provide customer service and record customers’ instructions, we will monitor and record (via automated means or transcripts) our telephone calls, emails, and chat conversations with you. We will use transcripts of these calls to confirm the instructions provided to us. | Contractual obligation | Yes | N/A |
| To meet our legal obligations related to record keeping we keep correspondence including e-mails, faxes, and any kind of electronic communication, together with any records of the customer’s account. We also keep customer service letters and other communications between us and any Euronet Group company as well as our partners and suppliers. | Legal Obligation | Yes | N/A |
| In very limited circumstances, to perform a credit check to verify the identity of the individual as part of KYC activities to provide the Services. | Legal Obligation | N/A | N/A |
- Financial and Employment-Related Information
To provide our services, we collect financial information such as bank details, transaction purposes, and employment details.
| Purpose of the Processing | Legal Basis | CoreCard acting on behalf of a client | CoreCard’s website |
| Supply/Performance of Services and Platform Operation | Contractual obligation | Yes | N/A |
| Anti-Money laundering compliance | Legal obligation | Yes | N/A |
| Anti-Terrorist Financing and Criminal activity | Legal obligation | Yes | N/A |
If you have any questions about the processing of your financial information, you may contact us or reach out to our Client directly and request information about how they process your personal data as a data controller and to exercise your rights in relation to that data.
- Behavioral and Technical Information
If you visit and browse our Website,, we may collect data such as IP addresses, browsing activity, device information, and settings to enhance services.
| Purpose of the Processing | Legal Basis | CoreCard acting on behalf of a client | CoreCard’s website |
| To help ensure the safety and security of our Website. | Legitimate Interest | N/A | Yes |
| To provide the Services. | Contractual obligation | Yes | N/A |
- Sensitive Personal Data
When required, we collect sensitive data, such as biometric data (e.g., face scans), government ID numbers, and health information, always in compliance with local laws.
Purposes and Legal Basis for Processing:
- Legal Compliance: For KYC and fraud prevention. (Legal obligation, Public interest)
- Security and Verification: To verify identity during service use. (Legal obligation or Consent, depending on region)
- Proof of funds: Some countries require us to identify the origin of the funds and the transfer reason, which may contain sensitive information. (Legal obligation)
- Non-Identifiable Data
When possible, we use non-identifiable data where you cannot be directly identified (such as anonymous demographic and usage data) to enhance services, such as anonymous demographics or aggregated usage data. This non-identifiable data may be used to improve our internal processes or delivery of services, without further notice to you. We may use aggregate data for a variety of purposes, including to analyze, evaluate and improve our Services.
- Biometric Data
For our digital services, and where legally permitted and required, we may verify your identity using an electronic Know Your Customer (e-KYC) process. This may involve submitting a valid photo ID, video, or selfie through our secure service provider’s platform. This process enhances fraud detection and ensures compliance with anti-money laundering regulations.
When biometric data, such as face scans, is collected, we will request your consent if required by local law. If you prefer not to provide biometric data, please contact our customer care team for alternative verification methods.
During the verification process, a video, including audio, may be recorded to ensure the integrity of the procedure. All biometric data shared with our service providers is carefully controlled and used strictly for identity verification purposes. Neither we nor our service providers will sell, lease, or trade your biometric information, and robust security standards are maintained to prevent unauthorized access.
In line with applicable privacy laws, you may have rights regarding your biometric data, such as access rights. For more information, refer to the “Your Rights” section. For questions about the e-KYC process, contact us at dpo@euronetworldwide.com. If you prefer to verify your identity in person, our staff at one of our locations can assist with ID checks directly.
If you prefer to verify your identity in person, our staff at one of our locations can
assist with ID checks directly.
Accuracy of Personal Data
We are committed to keeping your Personal Data accurate and up to date. We take reasonable steps to ensure the accuracy of your Personal Data by ensuring that the latest Personal Data we have received is accurately recorded and when considered necessary, we run periodic checks and request that you update your Personal Data. From time to time, we may send you an email asking you to confirm and/or update your Personal Data. This communication is based on our legitimate interest and legal obligation to maintain accurate and up to date information. This obligation is also transferred to our Client.
If you notice that your Personal Data is not accurate, you may request a correction or update your information by sending an email to dpo@euronetworldwide.com
Legitimate Interest
When we use your Personal Data to pursue our legitimate interests, we will make every effort to match our interests with yours so that your Personal Data will only be used as permitted by relevant law, or when it will not adversely affect your rights. You may request information on any processing based on legitimate interest.
How Long We Keep Personal Data
We retain Personal Data only as long as necessary to provide services and to meet legal, accounting, or reporting obligations.
If you request deletion of your data, we may still be required to retain some of it to comply with legal obligations. The information retained will only be accessible by limited personnel to comply with any legal requirement and will be duly deleted after the obligation is due.
Do We Disclose Personal Data?
A. Euronet Group Affiliate
We may disclose Personal Data to Euronet and its affiliated companies for everyday business purposes and to fulfill compliance obligations within the group.
Types of Personal Data: Identification Data, Financial Details, Behavioral and Technical Data.
Purpose: Sharing data with affiliates for customer service, compliance, and daily business functions. This may include 24/7 customer support requiring data access across Euronet Group affiliates. (Legal and Contractual obligations)
In the event of a sale, acquisition, merger, or reorganization involving Euronet or any company within the Euronet Group, we may transfer Personal Data to third parties, ensuring appropriate protection measures.
B. Third-Party Service Providers
We may share certain Personal Data with third-party service providers to support compliance verification, service delivery, and marketing efforts.
Types of Personal Data: Identification and Biometric Data, Financial Details, Contact Details, Transactional, Behavioral, and Technical Data.
C. Authorities
We may be required to disclose your Personal Data, including Sensitive Personal Data, to legal or regulatory authorities for compliance, to enforce agreements, or to fulfill legal requests.
Types of Personal Data: Identification Data, Transactional Data, Financial Details
Purpose: Compliance with legal requests by authorities to our companies, affiliates or to
partners related to the processing of your transactions like correspondents and payment.
This processing is based on our legal obligations.
D. Partners
Personal Data may be shared with strategic partners when necessary to deliver our
services or to ensure they comply with their legal obligations.
Types of Personal Data: Identification Data, Transactional Data, Financial Details.
Purpose: Service provision in collaboration with strategic partners. This also supports the use of our services, and the processing is based on our legitimate interests.
E. Professional Partners
We may disclose Personal Data to professional partners, including lawyers, consultants,
auditors, or accountants, to fulfill our legal and business obligations.
Types of Personal Data, Identification Data, Transactional Data, Financial Details.
Online Fraud Prevention
As a financial institution, we are committed to ensuring secure connections. To achieve this, we may use device IDs or IP addresses for security and fraud prevention, unauthorized transactions, or other liability.
We use third parties to verify the authenticity and security of these connections in order to protect access to the services and your Personal Data.
Machine Learning
Machine learning within our services supports various internal operational processes completed for purposes such as:
- project management, data analysis, communications, security, and
- anti-money laundering and fraud prevention.
When photos and selfies are uploaded during the identity verification process, they are analyzed to confirm whether the individual registering matches the person shown in the provided identification. This technology scans images, converts them into digital templates, and compares them against each other and a database of images to determine a match.
We have developed machine learning models to support regulatory compliance by identifying potential transactional fraud. This analysis helps us provide requested services while meeting legal obligations related to fraud prevention, money laundering, and terrorism financing. The process involves analyzing transactional data, assigning values to specific indicators, and processing these values through a machine learning model to assess the likelihood of fraudulent activity.
All data processed through our machine learning applications is used solely for the purposes described here, ensuring it respects your rights and freedoms. For more information about our use of machine learning, please contact the Euronet Data Protection Officer at dpo@euronetworldwide.com.
Security
We are dedicated to safeguarding your Personal Data and have implemented robust, commercially reasonable security measures to prevent its loss, misuse, or unauthorized alteration. We continuously work to protect your data in line with international best practices by applying rigorous physical, electronic, and managerial safeguards.
To prevent unauthorized access, we employ advanced physical and organizational security measures that are regularly updated to ensure the highest level of protection while maintaining cost efficiency. All Personal Data is stored in secure locations, protected by firewalls and other sophisticated security systems with restricted administrative access.
Our personnel, as well as all activities related to your Personal Data, are governed by strict confidentiality agreements that enforce compliance with our organization’s Privacy Policy.
Our goal is to uphold the highest standards of data protection by industry-leading practices that safeguard your privacy.
Regional Notices
Notice to United States Residents
This Notice is provided to individuals who reside in the United States consumers to meet the requirements of the federal Gramm-Leach-Bliley Act (“GLBA”), where applicable, related to the collection, disclosure, and protection of “nonpublic personal information” (“NPI”) as defined by the GLBA. NPI is personally identifiable information collected as a financial institution under the GLBA that is not publicly available. NPI may include any:
- Information provided by an individual when obtaining a financial product or service.
- Information obtained about an individual from transactions involving financial products or services.
- Information acquired about an individual in connection with providing a financial product or service, such as information from a consumer report or court record.
All disclosures of NPI are made as permitted by law. A “nonaffiliated third party” is any person except a financial institution’s affiliate or a person employed jointly by a financial institution and a company that is not the institution’s affiliate.
Our Role
In the United States, CoreCard provides payment processing, technology, and operational support services for credit card programs and other payment products. Depending on the service, CoreCard acts as a processor on behalf of issuing banks, program partners, or other financial institutions.
In this role, CoreCard processes Personal Data solely to support card issuance, payment processing, customer support, and fraud prevention in accordance with contractual obligations and applicable law.
Categories of Personal Data we Process
In connection with U.S. card and payment services, we may process the following categories of data:
- Identification Data (e.g., name, contact details, date of birth, and government-issued identifiers)
- Financial/Transactional Date (account numbers, transaction amounts, merchant information, and payment activity)
- Device Data (IP address, device identifiers, log data, and security-related information)
We process this information to support card issuance, processing, fraud prevention, compliance, customer support, and related operational purposes.
Facts: What We Do With Your Personal Information
| Why? | Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do. |
| What? | The types of personal information we process, and share depend on the product or service you have with us. This information can include: Transactional Data and Financial and Employment information When you are no longer our customer, we continue to share your information as described in this notice. |
| How? | All financial companies need to share Consumer personal information to run their everyday business. In the section below, we list the reasons financial companies can share their consumer’s personal information; the reasons We choose to share; and whether you can limit this sharing |
| Reasons we can share your personal formation | Do We Share? | Can you limit this sharing? |
| For our everyday business purposes— such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus | Yes | No |
| For our affiliates’ everyday business purposes— information about your transactions and experiences | Yes | No |
Questions?
Call +18774431399 or email
dpo@euronetworldwide.com
| Who we are | |
| Who is providing this notice? | CoreCard Software Inc. |
| What we do | |
| How do we protect your personal information? | To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secure files and buildings. All personal information is stored in secure locations, protected by firewalls and other sophisticated security systems with restricted See security section of the global notice for further details or contact dpo@euronetworldwide.com |
| How do we process my personal information? | We process your personal information, when our Clients provide us with it in order for us to provide the Services to our Client. We may also collect and process your personal information directly with you when you interact with us via our website. |
| Why can’t I limit all sharing? | Federal law gives you the right to limit only sharing for affiliates’ everyday business —purposes—information about your creditworthiness affiliates from using your information to market to you State laws and individual companies may give you additional rights to limit sharing. See the “Your Rights” section for more information. |
| Definitions | |
| Affiliates | Companies related by common ownership or control. They can be financial and non-financial companies. We disclose your personal information with Euronet and Euronet Group affiliates for our everyday business purposes and compliance with group obligations |
| Nonaffiliates | Companies not related by common ownership or control. They can be financial and non-financial companies. We disclose your personal information to perform compliance certification and fraud prevention and to enforce or apply our Terms and Conditions or any other agreement with you. |
Notice to California Residents
In accordance with the California Consumer Privacy Act, residents of California may exercise the following rights:
- Right to Know
- Right to Access
- Right to Correct Inaccuracies
- Right to Deletion
- Right to opt Out of Sale or Sharing of Personal Data for cross-contextual behavioral advertising purposes
- Right to limit Sensitive Personal Data use and disclosures to specifically permitted purposes.
- Right of No Retaliation Following opt-out or Exercise of other Rights
From the day we receive your request, we will respond to you within a maximum time of 45 days, unless an extension is requested. If you receive notice from us that your Personal Data rights request has been refused, you may appeal the refusal within a reasonable period after receiving the notice by sending an email to dpo@euronetworldwide.com
Notice to Texas Residents
If you have a complaint, first contact the consumer assistance division of CoreCard at 1- (877)-443-1399 . if you still have an unresolved complaint regarding the company’s activity, please direct your complaint to: Texas Department of Banking, 2601 North Lamar Boulevard, Austin, Texas 78705, 1-877-276-5554 (toll free),www.dob.texas.gov.
Notice to European (EEA) Residents
In accordance with the General Data Protection Regulation (GDPR) and in addition to the rights stated above, all residents of the Economic European Area (EEA) may exercise the following rights:
- Right to Access
- Right to Correct Inaccuracies
- Right to Deletion
- Right to Restrict Processing
- Right to Data Portability
- Right to Object
- Rights related to Automated Individual Decision-Making
To exercise any of the rights listed above, you shall comply with the obligations set above in this Privacy Notice.
From the day we receive your request, we will respond to you within a maximum time of 30 days, unless an extension is requested
Notice to UK Residents
In accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, all residents of the UK may exercise the following rights:
- Right to Access
- Right to Correct Inaccuracies
- Right to Deletion
- Right to Restrict Processing
- Right to Data Portability
- Right to Object
- Rights related to Automated Individual Decision-Making
To exercise any of the rights listed above, you shall comply with the obligations set above of this Privacy Notice, relating to sending our request to dpo@euronetworldwide.com and verification of your identity. From the day we receive your request, we will respond to you within a maximum time of 30 days, unless an extension is requested. dpo@euronetworlwide.com
Contact
Our privacy team is available to address any questions or requests through the following channels:
- dpo@euronetworldwide.com
- By phone are available here
- reach us by filling out our webform available here
- By traditional post, you can write to: DPO, Calle CantabCoreCard 2, 2-A Alcobendas Madrid, Spain