This notice explains how ARVOSE LTD (trading as “BankTap”) collects and uses personal data under UK GDPR and the Data Protection Act 2018, and how we use cookies and similar technologies under the Privacy and Electronic Communications Regulations (PECR). It applies to our website and our BankTap platform (PISP/AISP services).
ARVOSE LTD (trading as BankTap) is the controller for website interactions, marketing, and account administration. For some features (e.g., Gift Aid processing for a charity merchant) we act as a processor on their documented instructions — see our Terms and Data Processing Addendum.
Payment metadata: amounts, timestamps, references, merchant name, status, device/browser info. We never collect your online banking passwords or full card PANs.
Open Banking consents: scope, bank, account identifiers (e.g., masked IBAN/sort code), expiry/revocation, tokens.
You (forms, dashboard, API), your authorised users, or your customers/donors.
Your bank (via Open Banking APIs) when you grant consent.
Service providers (e.g., fraud, KYC/KYB, cloud hosting).
Public sources (e.g., Companies House, Charity Commission) for KYB.
5) How we use data & lawful bases
Purpose
Examples
Legal basis
Provide Platform & payments
Create links/QR, initiate payments, refunds
Contract; Legitimate interests
Security & fraud
Logging, anomaly detection, rate‑limiting
Legitimate interests; Legal obligations
Compliance
AML/KYC, record‑keeping, audit
Legal obligations
Support & comms
Emails, operational notices
Contract; Legitimate interests
Analytics (non‑essential)
Improve UX, performance
Consent (PECR)
Marketing (optional)
Newsletters, product updates
Consent or Legitimate interests with opt‑out
6) Open Banking specifics
No credentials. We never see or store your online banking passwords. Consent is granted via your bank using Strong Customer Authentication (SCA).
AIS data. If you authorise Account Information Services, we access account identifiers, balances, and transactions strictly within the consent scope and duration shown at consent time. You can revoke at your bank or in our dashboard.
PIS data. For Payment Initiation, we transmit payment orders to your bank (ASPSP). We retain payment metadata for audit, reconciliation, refunds, and fraud prevention.
Regulatory status. Our FCA status is displayed at the top of this page. When authorised as a PISP/AISP, we perform regulated activities under our own FRN; until then, any regulated activity (if any) is carried out via a regulated partner.
7) Sharing & sub‑processors
Banks & Open Banking partners to execute your instructions and validate consents.
Service providers under contract (cloud hosting, email, security, KYC/KYB). See Cookies for client‑side tools and Terms Schedule D for processor list.
Legal & authorities when required (e.g., AML/CTF, fraud, court orders).
Business transfers in reorganisation/sale (with safeguards).
8) International transfers
We prefer UK/EU hosting. Where a transfer outside the UK/EEA occurs, we use appropriate safeguards (UK Addendum/IDTA or adequacy). Details are available on request.
9) Retention
Operational & audit logs: typically up to 24 months (shorter for high‑volume telemetry).
Financial records (e.g., invoices, refunds): up to 7 years to meet legal obligations.
Support records: up to 24 months after closure unless required longer for disputes.
Open Banking consents/tokens: held only for consent duration; revocation removes access.
10) Security
ISO/IEC 27001‑aligned controls across access, encryption in transit/at rest, secure SDLC, monitoring, and incident response.
Production data is access‑controlled and logged. Secrets are managed securely.
Incidents are notified without undue delay and, where required, to the ICO within 72 hours.
11) Your rights
Access, rectification, erasure, restriction, portability, and objection to processing.
Withdraw consent at any time (doesn’t affect prior lawful processing).
Exercise rights via [email protected]. We may need to verify your identity and scope.
12) Complaints
Please contact us first at [email protected]. You can also complain to the UK Information Commissioner’s Office (ICO): 0303 123 1113, ico.org.uk, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
13) Changes
We’ll update this notice when required and indicate the effective date. Material changes may be notified in‑app or by email.
Cookie Policy (UK & PECR)
Cookies are small files placed on your device. We use strictly necessary cookies to make our services work and, with your consent, additional cookies for analytics and feature improvements. You can change your choices at any time using the .
A) Cookie categories
Strictly necessary — required for security, authentication, and core features. Always on.
Performance/analytics — help us understand usage (aggregated, no advertising).
Functional — remember settings such as language or cookie choices.
B) Cookies we set
Name (example)
Purpose
Category
Expiry
bt_session
Session management, CSRF protection
Strictly necessary
Session
bt_auth
Keep you signed in (hashed token)
Strictly necessary
Up to 30 days
bt_cookie_prefs
Store your consent choices
Functional
6–12 months
bt_analytics_*
Anonymous usage analytics (if enabled)
Performance/analytics (consent)
Up to 12 months
We do not use advertising or social media tracking cookies.
C) Managing preferences
You can manage non‑essential cookies here or via your browser settings (which also allow blocking and deletion). Blocking strictly necessary cookies may break core functionality.
We use essential cookies to make our site work, and optional analytics to improve it. You can change your choices at any time.
Cookie preferences
Control optional cookies. Strictly necessary cookies are always on.
Cookies on BankTap
We use essential cookies to keep BankTap secure and working. With your permission, we’ll also use
personalisation to remember whether you use BankTap as Personal, Business or Charity,
and analytics (Google Analytics 4) to improve our product. We don’t use advertising cookies.
You can change your choice any time in Cookie settings.
Cookie preferences
Control optional cookies. “Reject” is as easy as “Accept”.
Strictly necessary (always on)
Security & core features (e.g. anti-bot, load balancing, consent log). These don’t track you for ads.
Examples:__cf_bm (~30 mins), cf_clearance (up to 1y), bt_cookie_prefs (stores your choices).
Functional (recommended)
Optional site preferences/features (none critical today; may include chat widgets or saved settings in future).
Personalisation (recommended)
Remember your BankTap setup (e.g. Personal/Business/Charity) and similar preferences.