1. Scope, Operator and Purpose
SufraPay is a technology solution developed, owned, operated and powered by AssureCharter (شركة ميثاق الضمان لتطوير الأنظمة البرمجية ذ.م.م), Registration No. 200213344, Amman, Khalda, Amer Bin Malek Street, Khalda Design Center, 1st Floor, Hashemite Kingdom of Jordan. This Privacy Policy is the principal document governing Personal Data processed through the SufraPay website, browser-based platform, QR codes, NFC tags and supported digital channels.
It applies to restaurant merchants, merchant representatives and staff, customers and guests, website visitors, and persons communicating with SufraPay.
2. Definitions and Data-Protection Roles
“Personal Data” means information relating to an identified or identifiable natural person. “Sensitive Personal Data” includes data treated as sensitive under applicable Jordanian law, including financial-position information. “Merchant” means a participating restaurant, café or similar venue. “Guest” means a customer using SufraPay. “Payment Provider” means a licensed gateway, acquirer, bank or processor.
Depending on the processing activity, AssureCharter may act as controller or processor. A Merchant may separately act as controller for Personal Data connected with its menu, sale, order fulfilment, customer service, refunds and marketing. Payment Providers process payment credentials under their own legal obligations and privacy notices.
3. Information Collected from Guests
SufraPay may collect order details, quantities, instructions, bill requests, split or partial payment selections, optional tips, communications, and location information where the Guest grants permission.
No Guest account or application download is required. If optional accounts, loyalty, receipts or similar features are introduced, the relevant registration and preference information may also be collected and this Policy will apply.
4. Information Collected from Merchants
SufraPay may collect legal and trading names, addresses, contact details, authorized-user details and credentials, commercial registration, tax certificate, licences, identification documents, authorized-signatory evidence, ownership or beneficial-owner information, KYC records, bank account and IBAN details, settlement and reconciliation information, menus, prices, branches, devices, support communications and commercial-agreement details.
Merchants must ensure that KYC, licensing, tax, bank, IBAN, menu, pricing, allergen and contact information is complete, accurate and current. Where a personal guarantee is provided by the Merchant’s authorized signatory (as contemplated by the Merchant Agreement), SufraPay also collects that individual’s full name, national ID number, ID document details and signature.
5. Orders, Restaurant Information and Service Records
SufraPay may process menu content, ingredients, availability, prices, taxes, charges, discounts, table references, order status, acceptance or rejection, substitutions, fulfilment events, bill totals, complaints, refunds and consumer-remedy records.
The relevant Merchant is responsible for the accuracy and legality of its menu, prices, taxes, allergens, availability, order acceptance, preparation, quality, safety, service and consumer remedies. SufraPay processes this information to provide the technology service and does not become the seller or merchant of record.
6. Payment and Transaction Information
Payments are processed directly by a licensed third-party Payment Provider. SufraPay does not collect, store, process or retain card numbers, CVV codes, PINs, expiry dates or other payment credentials. Payment credentials are entered directly into the Payment Provider’s secure environment.
SufraPay may receive limited transaction information, including amount, currency, transaction status, reference number, payment-method category, timestamps.
Payment authorization, decline, reversal, authentication, settlement and card-account decisions are made by the Payment Provider, acquiring bank, issuing bank or card scheme. Refunds, cancellations and complaints concerning restaurant goods or services are handled by the relevant Merchant in accordance with applicable law and Payment Provider procedures.
7. Technical, Usage, Cookie and Location Data
SufraPay may automatically collect IP address, browser type and version, operating system, device identifiers, language, time zone, access date and time, pages viewed, session activity, referring pages, security events, error records, diagnostic logs, network and connection information, and permitted device-location information.
SufraPay may use essential session cookies, authentication and security cookies, preference and language cookies, cookie-consent records, and analytics or advertising technologies where enabled. Non-essential technologies will be used subject to any consent required by law. Browser controls may block cookies, but parts of the Service may not function correctly. SufraPay does not use obsolete Flash cookies.
8. Sources of Information
Information may be collected directly from Guests, Merchants and their representatives; automatically through the Service; from the relevant restaurant; and from Payment Providers, banks, KYC and identity-verification providers, fraud-prevention providers, hosting and cloud providers, communications providers, analytics providers, professional advisers and competent authorities.
9. How and Why Information Is Used
Personal Data may be used to provide, maintain, secure and improve SufraPay; display menus; identify restaurants and tables; transmit, verify and manage orders; send notifications; facilitate bill requests and payment initiation; support split or partial payments; reconcile and report transactions; onboard and verify Merchants; administer access, devices and commercial arrangements; provide support; maintain records; prevent fraud and misuse; investigate incidents; enforce terms; and comply with legal, regulatory, tax, accounting, banking and payment-gateway requirements.
Processing may be based on prior consent, contractual necessity, legal obligation or another basis permitted by applicable law. AssureCharter will not use Personal Data for a materially incompatible purpose without an appropriate legal basis and notice.
10. Operational and Marketing Communications
SufraPay may send service, support, administrative, technical, security, order, payment, refund and policy notices by email, SMS or other electronic channels. These communications may be necessary for the Service.
Where permitted and subject to required consent, AssureCharter may send marketing, promotions, offers, loyalty information or information about related products and services. Recipients may opt out of promotional communications without affecting essential service messages.
11. Sharing and Disclosure
Necessary information may be shared with the relevant Merchant; licensed Payment Providers, acquirers, card schemes and banks; hosting, cloud, cybersecurity, analytics, communications and support providers; KYC, identity and fraud-prevention providers; auditors, lawyers, accountants and insurers; regulators, courts, law-enforcement bodies and other authorities; and a genuine buyer, investor or successor in a merger, financing, restructuring or asset transaction.
SufraPay does not sell Personal Data. Recipients should receive only information reasonably necessary for the relevant purpose and be subject to appropriate confidentiality, security and data-protection obligations. Information may also be disclosed with the data subject’s consent or where disclosure is necessary to comply with law, protect rights or property, investigate wrongdoing, protect users or the public, or manage legal claims.
12. Cross-Border Processing and Transfers
Personal Data may be processed or hosted outside Jordan where approved providers operate. Any such transfer requires that the recipient provide a sufficient level of data protection, or that a specific legal basis under Jordan’s Personal Data Protection Law No. (24) of 2023 applies (including judicial or law-enforcement cooperation under an applicable treaty, medical treatment or public-health necessity, or the data subject’s explicit, informed consent) together with any required contractual controls or approvals.
13. Retention, Accuracy and Deletion
Personal Data is retained only for as long as reasonably necessary for the purposes in this Policy and for contract administration, order and transaction records, settlements, disputes, chargebacks, fraud prevention, security, and legal, regulatory, tax, accounting, banking and payment-gateway obligations. Retention periods may vary by record type.
When information is no longer required, it will be securely deleted, anonymized or restricted, subject to lawful backup, evidence-preservation and recordkeeping requirements.
14. Security and Personal-Data Incidents
AssureCharter applies reasonable administrative, technical and organizational safeguards, including role-based access, authentication, encryption in transit where appropriate, logging, monitoring, backups, vendor controls, confidentiality obligations and incident management. No internet transmission or electronic storage method is completely secure.
Where legally required under Jordan’s Personal Data Protection Law No. (24) of 2023, AssureCharter will notify affected data subjects of a qualifying Personal Data breach within 24 hours of discovery, and will notify the competent regulatory Unit at Jordan’s Ministry of Digital Economy and Entrepreneurship within 72 hours of discovery, together with available details of the breach’s source, mechanism, affected individuals and the measures taken.
15. Data-Subject Rights and Requests
Subject to applicable law and lawful exceptions, a data subject may request information about processing; access; correction or updating; restriction; erasure; withdrawal of consent; objection to processing or profiling; and a copy or transfer of Personal Data where applicable. These rights may be exercised free of charge and without any financial or contractual consequence, consistent with Jordan’s Personal Data Protection Law No. (24) of 2023.
Requests may be sent to info@sufrapay.net and may require identity verification. Withdrawal of consent does not affect processing already lawfully completed and may prevent use of optional features. A person may also submit a complaint to the Personal Data Protection Council or the competent Unit at Jordan’s Ministry of Digital Economy and Entrepreneurship, where entitled by law.
16. Children and Age Requirement
SufraPay is not intended for persons under 14 years old. A person aged 14 to under the legal age of majority should use the Service only with the involvement and permission of a parent or legal guardian where required. If prohibited information is found to have been collected from a child, appropriate deletion or restriction steps will be taken. Consistent with Jordan’s Personal Data Protection Law No. (24) of 2023, the consent of a parent or legal guardian is required for any person who lacks full legal capacity to use the Service.
17. Merchant and User Responsibilities
Merchants must protect credentials and devices, control authorized access, comply with privacy, consumer, food-safety, tax, advertising, cybersecurity and payment rules, and use Guest information only for order fulfilment, support, legal compliance and consented marketing.
Guests and Merchant users must not use SufraPay unlawfully, impersonate others, access unauthorized tables or transactions, misuse QR or NFC codes, submit fraudulent payments, introduce malware, bypass security or infringe third-party rights.
18. Third-Party Services, Links and Availability
Payment pages, external links and third-party tools are governed by the relevant provider’s terms and privacy notice. SufraPay is a technology provider, not a bank, card issuer or licensed payment processor.
The Service may be unavailable or delayed because of maintenance, venue operations, connectivity, devices, banks or third-party providers. Users should confirm urgent orders, acceptance and payment status directly with restaurant staff where necessary.
19. Business Transfers and Legal Requirements
If AssureCharter is involved in a merger, financing, acquisition, reorganization or asset transfer, relevant Personal Data may be transferred subject to applicable law and appropriate notice. Information may also be disclosed to comply with legal obligations or valid authority requests, protect rights or safety, investigate suspected wrongdoing, enforce agreements or address legal liability.
20. Changes to this Privacy Policy
AssureCharter may amend, add or remove provisions by posting an updated online version on sufrapay.net. The “Last updated” date will be revised, and material changes affecting active users will be notified where reasonably appropriate and legally required.
21. Contact Us
Privacy questions, rights requests, complaints and notices may be sent to info@sufrapay.net or by post to AssureCharter, Registration No. 200213344, Amman, Khalda, Amer Bin Malek Street, Khalda Design Center, 1st Floor, Hashemite Kingdom of Jordan.
Questions about this document? info@sufrapay.net