Privacy Policy
What we collect, why, and who we share it with.
Who we are
MaxRail LLC, operating MaxRail at maxrail.io. Contact: support@maxrail.io.
What this website collects
This marketing site does not use advertising or analytics cookies and does not embed third-party trackers. If you email us, we hold what you send in order to answer.
What we collect from applicants and merchants
- Business information — legal entity, trading name, address, website, category, expected volume.
- Owner information — name, date of birth, address and government identifier where required for identity verification and sanctions screening. This is a legal requirement for payment services, not a preference.
- Banking information — settlement account details.
- Site review data — publicly reachable pages of your storefront, retained as evidence supporting findings.
Why we process it
To assess and onboard applicants, to meet legal and network obligations including know-your-customer, anti-money-laundering and sanctions requirements, to route and settle transactions, to manage risk and disputes, and to support merchants.
Who we share it with
- Processors, acquirers and networks providing the rails on your account.
- Identity verification, sanctions screening and fraud vendors.
- Professional advisers, and authorities where legally required.
We do not sell personal information, and we do not share it for advertising.
Retention
Merchant and transaction records are retained for the period required by financial regulation and network rules, which is generally several years after an account closes. Site review evidence is retained for the life of the merchant relationship.
Your rights
Depending on where you live you may have rights to access, correct, delete or port your information, and to object to certain processing. Email us and we will respond within the period the applicable law requires. Some data cannot be deleted while we are legally required to retain it.
Security
Access to merchant data is restricted to personnel who need it. Card data is handled by PCI-compliant providers, in their environments — we design deliberately so that card numbers do not reach our systems.
Changes
We will update this page when our processing changes, and note the date.