Privacy Policy
How Holistic Payments collects, uses, shares, and protects information from merchant applicants, current merchants, and ISO partners.
1. Scope and role
This Privacy Policy explains how Quantum Matrix Holding LLC, doing business as Holistic Payments ("Holistic Payments," "we," "us") collects and handles information when you visit holisticpayments.io, submit a merchant application, communicate with us by email, Instagram, WhatsApp, Telegram, or Calendly, or participate in our ISO partner program.
Holistic Payments is a payment processing brokerage and merchant services consultancy. We facilitate introductions between B2B Research Use Only (RUO) peptide distributors and acquiring banks, processors, and gateways. We do not ourselves operate as an acquiring bank or directly settle card transactions for end customers.
2. Information we collect
The categories of information we collect depend on how you interact with us.
From merchant applicants and current merchants: business legal name and DBA, EIN, formation date, address, website URL, product mix, monthly volume estimates, average and high ticket sizes, refund and fulfillment policies, banking information (routing and account numbers), beneficial owner information (name, title, ownership percentage, date of birth, Social Security Number or passport, address, government identification), prior processor history, current processing statements, and any documents you upload through our intake portal.
From website visitors: the information you submit through our application forms (name, email, phone, Instagram handle, country, monthly volume, vertical, optional notes), and standard technical telemetry such as IP address, user agent, referrer, and UTM parameters.
From conversations: the contents of messages you send us through Instagram DM, WhatsApp, ManyChat, Calendly bookings, Telegram, email, or other support channels. We retain these conversations for service quality, training, and account history.
From ISO partners: the information you submit during partner enrollment (legal name, business name, W-9 information including TIN, contact details, payout method, and electronic signature on the partner agreement), plus the referral details you log inside the partner portal.
From third-party integrations: when you complete a Calendly booking we receive your booking responses; when you message us through Instagram or WhatsApp via ManyChat we receive subscriber metadata; when our website fires a conversion event to Meta or Google we send hashed identifiers as described in those platforms' policies.
3. How we use information
- Evaluate merchant applications and route them to appropriate acquiring banks.
- Communicate with you about pricing, compliance, application status, and ongoing account management.
- Verify identity, business legitimacy, and counterparty compliance under 21 CFR ยง201.128 intended-use standards.
- Calculate and pay ISO partner commissions.
- Operate, secure, and improve our website and internal tooling.
- Meet our legal, regulatory, and contractual obligations.
- Detect and prevent fraud, abuse, and security incidents.
4. How we share information
Acquiring banks, processors, and gateways. When we route your application to an underwriter we share the information needed to underwrite the account, including all material business and beneficial owner information. Each acquirer maintains its own privacy practices, which govern their handling of the information once received.
Service providers. We use vendors who process information on our behalf, including Cloudflare (data storage and security), Resend (transactional email), ManyChat (Instagram and WhatsApp messaging), Calendly (scheduling), Anthropic (AI-assisted reply drafting), Twilio (SMS, where applicable), and analytics providers. Vendors are contractually limited to the purposes for which we engage them.
Advertising and analytics. We send conversion events to Meta (Conversions API) and Google Analytics 4. These events are limited to lead capture and form submission signals, not detailed merchant or transaction data.
Legal and safety. We may disclose information when required by law, subpoena, or court order, when necessary to protect our rights, property, or safety, or in connection with the sale or reorganization of our business.
We do not sell personal information.
5. Cookies and tracking
We use essential cookies and similar technologies to operate the site, remember session state, and run security controls. We also use analytics tags (Google Analytics 4) and conversion pixels (Meta) to measure marketing performance. Where required by applicable law we honor your consent choices and Do Not Sell / Do Not Share signals.
6. Data security
We protect information using administrative, technical, and physical safeguards, including encrypted transport (TLS), encrypted storage, access controls, audit logs, vendor due diligence, and least-privilege access for employees and contractors. No security control is perfect. If we discover a material breach of your information we will notify you and applicable authorities as required by law.
7. Retention
We retain merchant application data and account records for the longer of (a) seven years from the date of the application or last account activity, to satisfy financial-services and tax record-keeping requirements, or (b) the period required by the acquiring bank that underwrote the account. Conversation history is retained as long as the underlying account is active and for an additional twenty-four months after closure. ISO partner records are retained for the life of the partner relationship plus seven years.
8. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct inaccuracies, request deletion (subject to our legal record-keeping obligations), restrict or object to certain processing, or receive a portable copy. To exercise any of these rights, email intake@holisticpayments.io from the email address on file with us. We may request additional information to verify your identity before fulfilling the request.
Residents of California, Colorado, Connecticut, Texas, Virginia, and other states with comprehensive consumer privacy laws have additional rights as enumerated in each respective statute. We honor verifiable consumer requests under those laws.
9. International transfers
Holistic Payments is based in the United States. If you submit information to us from outside the United States you consent to the transfer, storage, and processing of that information in the United States and in any jurisdiction where our service providers operate.
10. Children's privacy
Our service is intended for businesses and authorized employees of those businesses. We do not knowingly collect personal information from anyone under the age of eighteen.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be noted at the top of this page with a revised effective date and, for current merchants, communicated by email at the address on file.
12. Contact us
Questions about this Privacy Policy or our handling of your information should go to:
Quantum Matrix Holding LLC, doing business as Holistic Payments
Email: intake@holisticpayments.io
Web: https://holisticpayments.io