1. Scope and our roles
This Privacy Notice describes the practices of Lifted Holdings LLC, including the Lifted Payments, Lifted Pay, Lifted Connect, and LiftedPOS brands (“Lifted,” “we,” “us,” or “our”). It applies when you visit our public websites, ask for a rate review, apply for merchant services, use a Lifted portal or application, communicate with support, or otherwise interact with us.
For information we collect for our own business purposes, Lifted acts as a business or controller. When we process information on behalf of a merchant customer, that merchant may be the business or controller and Lifted may act as its service provider or processor. In that situation, the merchant’s privacy notice and our contract with that merchant also apply. Requests concerning merchant-controlled information may be directed to the merchant.
2. Information we collect
The information we collect depends on the products you use and your relationship with Lifted.
| Category | Examples |
|---|---|
| Identifiers and contact data | Name, business name, title, email, phone, mailing and service address, account identifiers, login name, device identifiers, and IP address. |
| Merchant application and compliance data | Business ownership, tax identification, bank account and routing information, beneficial-owner information, identity-verification records, processing history, expected volume, industry, and documents needed for underwriting, fraud prevention, sanctions screening, and legal compliance. |
| Commercial and transaction data | Orders, transaction amount and time, refunds, tips, invoice and customer references, item and tax detail, authorization and response data, batch and settlement records, chargebacks, and support history. |
| Customer and end-user data | Customer name and contact details, receipt destination, token references, order history, loyalty or account data, and other information a merchant submits to the service. |
| Account and authentication data | Password hashes, authentication factors, permissions, staff roles, session records, account activity, and security events. |
| Device, usage, and technical data | Browser and device type, operating system, PAX model and serial, application version, configuration, logs, crash and diagnostic data, pages viewed, referring URL, and approximate location derived from IP address. |
| Communications | Emails, calls, messages, form submissions, support requests, preferences, and feedback. |
| Professional and employment data | Role, employer, business relationship, and information submitted for employment or contractor opportunities. |
| Inferences | Risk, fraud, product-fit, service, and account-health indicators derived from the information above. We do not use sensitive information to infer personal characteristics. |
3. Sources of information
We collect information directly from you; from merchants and their staff or customers; automatically from websites, applications, portals, terminals, and network logs; from processors, acquiring banks, gateways, PAX and other hardware or software providers; from identity, fraud, sanctions, credit, and underwriting providers; from referral partners; and from public or commercially available sources where permitted by law.
4. How we use information
- Provide websites, applications, portals, merchant services, customer support, receipts, reporting, and requested communications.
- Board, underwrite, verify, configure, and support merchant accounts and devices.
- Route, authorize, settle, reconcile, refund, investigate, and report transactions.
- Authenticate users, protect accounts, prevent fraud, manage disputes, and maintain security.
- Operate, debug, measure, improve, and develop our products and integrations.
- Personalize service communications and recommend relevant Lifted products to existing or prospective business customers.
- Comply with law, sanctions, tax, accounting, card-network, bank, processor, and regulatory obligations; enforce agreements; and protect rights and safety.
- Complete a financing, investment, merger, acquisition, reorganization, or sale of all or part of the business, subject to appropriate protections.
5. How we disclose information
We may disclose relevant information to:
- Processors, acquiring and sponsor banks, gateways, card networks, ACH operators, payment applications, terminal and device-management providers, and other parties needed to provide a requested payment service.
- Cloud hosting, security, analytics, identity verification, fraud prevention, communications, customer support, document, accounting, and professional-service providers that process information for us.
- Your employer, merchant account owner, authorized administrators, customers, or counterparties as the service requires.
- Government, law-enforcement, regulatory, court, card-network, or financial-institution recipients when required or reasonably necessary to comply with law, protect the service, investigate misuse, or respond to valid process.
- A buyer, investor, lender, insurer, adviser, or successor in connection with a business transaction, subject to confidentiality and applicable law.
- Other parties at your direction or with your consent.
6. Payment-card information
Lifted products are designed so that clear primary account numbers are entered into or read by approved payment interfaces and are handled by the configured payment processor, gateway, hosted field, or PAX payment stack. Where tokenization is enabled, Lifted systems receive a token or masked reference rather than the clear card number. Card data practices can vary by service, processor, and merchant configuration.
Merchants remain responsible for their own Payment Card Industry Data Security Standard obligations, approved device use, access controls, and compliance scope. Do not send full card numbers, security codes, passwords, or banking credentials by ordinary email or support message.
7. Cookies, analytics, and preference signals
Our sites and services may use session storage, local storage, cookies, pixels, and comparable technologies for authentication, security, preferences, diagnostics, performance, and measurement. Public LiftedPayments.com pages do not currently use third-party cross-site behavioral advertising cookies. Server and security logs may still record IP address, user agent, requested URL, referral information, and timestamps.
You can control cookies through your browser, but blocking required storage may prevent login or application features from working. Because we do not currently sell or share personal information for cross-context behavioral advertising, a Global Privacy Control signal does not change that practice; we will honor legally required browser signals if our practices change.
8. Retention
We retain information for as long as reasonably necessary for the purposes described here, including providing the service, maintaining transaction and accounting records, meeting bank, processor, tax, anti-money-laundering, dispute, chargeback, security, and legal requirements, enforcing agreements, and resolving claims. Retention varies by data type, account status, contractual requirements, and law. We may retain deidentified or aggregated information where it can no longer reasonably identify you.
9. Security
We use administrative, technical, and physical safeguards designed for the nature of the information and the service, including access controls, encryption in transit, tokenization where configured, logging, backups, vendor controls, and incident response. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Protect your credentials, use unique passwords and available authentication factors, and contact us promptly about suspected unauthorized activity.
10. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to request access to, correction of, deletion of, or a portable copy of personal information; to learn the categories, sources, purposes, and recipients involved; to opt out of sale, sharing, or certain profiling; to limit certain uses of sensitive information; to withdraw consent; and to appeal a denied request. Lifted does not discriminate against you for exercising an applicable right.
Submit a request to pay@liftedholdings.com with the subject “Privacy request,” or call 1-855-678-5142. Tell us your state or country, your relationship with Lifted, and the right you want to exercise. We will verify requests using information appropriate to their sensitivity. An authorized agent may submit a request where allowed, but we may require proof of authority and identity. If information is controlled by a Lifted merchant, we may direct the request to that merchant.
11. Children
Our merchant and payment services are intended for businesses and adults, not children under 18. We do not knowingly collect personal information directly from children through these services. Merchants that submit information about their customers are responsible for having an appropriate legal basis and complying with laws that apply to children.
12. International visitors
Lifted services are operated from and primarily offered in the United States. If you access them from another country, your information may be transferred to, stored in, and processed in the United States and other locations used by our service providers, where laws may differ from those in your country.
13. Changes to this notice
We may update this notice to reflect changes in our services, vendors, or legal obligations. We will post the revised notice here and change the “last updated” date. If a change materially affects how we use information, we will provide additional notice where required.
14. Contact us
Lifted Holdings LLC
Attn: Privacy
1209 Mountain Road Pl NE
Albuquerque, NM 87110
United States
Email: pay@liftedholdings.com
Phone: 1-855-678-5142