Terms & Conditions, Terms of Business, and Website Terms
These terms form a legally binding agreement between ARVOSE LTD (trading as “BankTap”) and you. They cover your use of the BankTap website and platform, along with commercial terms for businesses, charities, partners, and developers. This page is written for our role as an FCA‑authorised (or in‑progress) PISP/AISP provider.
ARVOSE LTD (“BankTap”, “we”, “us”, “our”) provides a platform to create, share, and accept account-to-account payments and access account information using Open Banking (PIS/AIS).
By accessing our website or creating a BankTap account, you accept these terms. If acting for a company/charity, you confirm authority to bind that entity.
We may update these terms. Changes take effect on posting, or for material changes, on 30 days’ notice by email or via the dashboard.
2) Definitions
Key terms include: “Merchant” (business/charity using BankTap to collect payments), “End‑User” (payer/donor), “PISP Partner” (regulated payment institution performing PIS until our FCA authorisation), “Platform” (BankTap dashboard, APIs, links, widgets), “Donation” (voluntary transfer to a charity), “Settlement Account” (your nominated bank account), “Gift Aid” (UK HMRC scheme), “Order Form” (signed agreement for services).
3) Scope: Website vs Platform
Website Terms of Use apply when browsing our site.
Platform Terms of Service & Terms of Business apply when you register and use BankTap to collect payments/donations or access AIS.
End‑User Terms apply to payers/donors who scan a QR or click a payment link.
API/Developer Licence applies to integrations and SDK/API usage.
Partner/Reseller Terms apply if you promote or resell BankTap.
4) Eligibility, Onboarding & KYC
You must be established in the UK (or supported territory) and provide accurate KYB/KYC information, including documents, director/PSC info, sanctions checks, and bank account verification.
You must use your own Settlement Account. We do not hold funds, operate client money accounts, or provide escrow.
We may refuse or suspend access if onboarding checks fail, risk profile changes, or for AUP breaches.
Payment Initiation. Payers scan/tap your link; their banking app opens with your details; approval uses SCA/biometrics. We (or PISP Partner until FCA authorisation) transmit the payment order to the payer’s bank (ASPSP). Supports single immediate payments (non‑revocable post‑SCA) and, if enabled, variable recurring payments (revocable before next due date).
No Card Rails & No Chargebacks. These are bank transfers, not card transactions. Card chargeback rights do not apply.
Settlement Timing. Faster Payments typically settle in seconds, subject to payer bank, limits, and rail availability. We do not guarantee timing.
Refunds. You decide refunds. Our tools enable bank transfer refunds to the payer’s account; timings vary. End‑Users may claim refunds for unauthorised/defective payments within 13 months per PSR Reg 74‑79.
Tips & Service Charges. If enabled, you handle allocation, payroll, and tax.
Donations & Gift Aid. See Schedule E. Only claim Gift Aid where donor and donation are eligible per HMRC.
Consumer‑to‑Consumer (C2C). Available only if enabled; see Schedule F.
Unauthorised Payments. End‑Users must report within 13 months to their bank or us for investigation/refund per PSR.
6) Fees, Taxes & Changes
Fees in dashboard/Order Form (e.g., 0.35% for early adopters). Add‑ons for premium features, refunds, or international rails.
Prices exclude VAT/taxes. You’re responsible for taxes on sales/donations.
Fee changes on 30 days’ notice (except promotional rates per Order Form).
7) Merchant/Charity Obligations
Comply with laws (PSR 2017 as amended, SCA, consumer protection, fundraising, HMRC Gift Aid).
Provide clear descriptions, pricing, refund policy, and contact details to End‑Users.
Use BankTap only for permitted activities (see AUP). Do not bypass SCA, bank limits, or monitoring.
Handle complaints; cooperate with us/PISP Partner for investigations.
8) Acceptable Use (Summary)
High‑risk, illegal, or regulated categories restricted/prohibited. See Schedule A.
9) Intellectual Property & Ownership
We (or licensors) own Platform IP, software, widgets, docs, designs, and brand assets. Limited licence granted.
You grant us a licence to use your name/logo for operation/marketing (opt out: [email protected]).
Feedback becomes our IP without obligation; do not submit confidential ideas.
10) Data Protection & Security (UK GDPR/DPA 2018)
Role Split. You are controller for payer/donor data; we are controller for telemetry/support, and processor on your documented instructions (e.g., Gift Aid). See Schedule B.
Transparency. You provide notices to End‑Users. Our privacy notice: /legal/privacy.
Security. ISO/IEC 27001‑aligned measures (encryption, access controls, logging, vulnerability management). See Schedule B, Annex A.
Sub‑processors. See Schedule D. Change notices provided.
Transfers. UK IDTA/Addendum for non‑UK transfers.
Incidents. Notified without undue delay; we cooperate on remediation.
Consent Revocation. End‑Users can revoke consent via their bank or our dashboard, stopping data access/sharing.
11) Confidentiality
Protect other party’s confidential information; use only for these terms. Exceptions: public info, independently developed, lawfully obtained. Legal disclosures limited and notified where lawful.
12) Warranties & Disclaimers
You warrant accurate business/charity info and lawful use.
Platform “as is”; no guarantee of uninterrupted/error‑free operation or settlement speed.
Consumer rights not excluded under UK law.
13) Liability & Indemnities
Cap. Our liability capped at £10,000 or 12‑month fees, except for death/injury, fraud, PSR breaches, data protection breaches, or non‑excludable liability.
Exclusions. No liability for indirect/consequential loss, lost profits, bank rail/payer bank downtime, or third‑party failures.
Your Indemnity. You indemnify us for claims/fines from your breach of law, AUP, misrepresentation, or IP infringement.
Our IP Indemnity. We defend/indemnify for claims alleging unmodified Platform infringes IP, subject to notice, control, cooperation.
14) Suspension & Termination
Terminate for convenience on 30 days’ notice (unless Order Form specifies term).
Suspend/terminate immediately for AUP violations, unlawful activity, non‑payment, onboarding failure, regulatory revocation, or insolvency.
On termination, stop using Platform; delete SDKs/keys. Data export window provided.
15) Support & Service Levels
High availability targeted. Support: Mon–Fri 09:00–17:00 UK (excl. holidays). See Schedule C for targets/exclusions.
16) API & Developer Licence
Licence. Non‑exclusive, revocable, non‑transferable licence for APIs, SDKs, docs, webhooks to integrate with BankTap.
Security. Keep API credentials confidential; rotate if compromised; no third‑party sharing without consent.
Rate Limits. Comply with usage limits; we may throttle/suspend to protect service.
Restrictions. No reverse engineering, scraping, or substitute services. Do not mislead on authorisation/settlement.
Brand. Use brand assets per guidelines; no implied sponsorship.
Webhooks. Validate signatures, implement retries idempotently, store minimally.
Audits. Provide evidence of compliance/security if requested.
Sandbox. Where provided, sandbox data is synthetic and must not be used in production.
17) Partner/Reseller Terms
Describe BankTap accurately; no misleading claims on regulation/safeguarding.
Comply with anti‑bribery, anti‑slavery, financial promotions, marketing rules.
Commission per Order Form; subject to active status.
No sublicensing/sub‑partners without consent.
Allowlisting. Partners must allowlist BankTap domains/IPs for webhooks and API callbacks as described in Schedule G.
18) Website Terms of Use
Content for information; no advice. Updated without notice.
Third‑party links for convenience; we’re not responsible.
No compromising site, large‑scale scraping, or removing copyright notices.
Schedule G - Allowlisting (Domains, IPs, Webhooks)
Domains:banktap.co.uk, portal.banktap.co.uk (any additional service subdomains will be announced in‑app).
Outbound IPs for Webhooks: Published in the dashboard (Settings → Integrations → Webhooks) and sent on request from [email protected]. These may change; we provide 7‑day notice for planned changes.
TLS & Certificates: All endpoints use TLS 1.2+ with HSTS. Verify our certificates and webhook signatures.
Webhook Signing: SHA‑256 HMAC with rotating secrets. Validate signature and timestamp; implement retries idempotently.
Email Allowlisting: For operational mail, allowlist @banktap.co.uk. All official communications come from [email protected] or [email protected].
Cookies on BankTap
We use essential cookies to keep BankTap secure and working. With your permission, we’ll also use
personalisation to remember whether you use BankTap as Personal, Business or Charity,
and analytics (Google Analytics 4) to improve our product. We don’t use advertising cookies.
You can change your choice any time in Cookie settings.
Cookie preferences
Control optional cookies. “Reject” is as easy as “Accept”.
Strictly necessary (always on)
Security & core features (e.g. anti-bot, load balancing, consent log). These don’t track you for ads.
Examples:__cf_bm (~30 mins), cf_clearance (up to 1y), bt_cookie_prefs (stores your choices).
Functional (recommended)
Optional site preferences/features (none critical today; may include chat widgets or saved settings in future).
Personalisation (recommended)
Remember your BankTap setup (e.g. Personal/Business/Charity) and similar preferences.