Privacy Policy
Last updated July 2026
This Privacy Policy explains how Xeloraco ("Xeloraco", "we", "us", "the Company") collects, uses, shares, and protects personal and business information when you use our consulting, advisory, onboarding, compliance, and related professional services (the "Services"). Because we serve clients in many jurisdictions and assist with payment, merchant-onboarding, and compliance processes, handling information securely and responsibly is central to how we operate. By using the Services, you acknowledge that you have read and understood this Policy.
1. Who this policy applies to
This Policy applies to clients, prospective clients, their owners, directors, officers, authorised representatives, and any individual whose information is provided to us in connection with an engagement. Where you provide information about another person (for example, a beneficial owner or director), you confirm that you are authorised to do so and that they have been made aware of this Policy.
2. Information we collect
To deliver our Services — and because payment processing, merchant onboarding, and financial services operate in highly regulated environments requiring verification, due diligence, and risk review — we may collect:
- Identity information: names, government-issued identification documents, dates of birth, and contact details.
- Business information: corporate registration records, business licences, tax registration certificates, corporate governance and regulatory filings, ownership and beneficial-ownership disclosures, and business plans.
- Financial information: banking information, financial statements, processing history, revenue documentation, source-of-funds and source-of-wealth information.
- Operational information: website and product information, product descriptions, marketing materials, supplier and customer information, transaction volumes, geographic markets, and operational records.
- Compliance information: KYC, AML, and due-diligence materials, proof of address, compliance records, and regulatory disclosures.
- Account & usage information: the details you submit through our website and customer portal (orders, documents, messages), and technical information such as device, browser, and log data when you interact with our website.
Documentation requirements may evolve throughout an engagement, and we — or relevant third parties — may request additional or updated information at any stage of the onboarding, review, assessment, integration, or application process.
3. How we use information
We use the information we collect to: provide, coordinate, and improve the Services; assess eligibility and allocate resources; prepare, review, and organise documentation; conduct internal reviews and risk assessments; facilitate communication with third-party providers; perform KYC, AML, and due-diligence checks; process payments and manage billing; communicate with you and respond to requests; maintain security and prevent fraud; and comply with applicable laws, regulations, and lawful requests.
4. Legal bases for processing
Where required by applicable law, we process information on one or more of the following bases: performance of our agreement with you; compliance with legal and regulatory obligations (including KYC/AML); our legitimate interests in operating, securing, and improving our business and managing risk; and, where applicable, your consent. Where we rely on consent, you may withdraw it at any time, without affecting processing already carried out.
5. How we share information
We do not sell personal information. In the course of delivering the Services, and as you authorise by engaging us, we may share information with third parties that maintain their own independent standards and requirements, including: payment processors, payment gateways, acquiring and sponsor banks, financial institutions, compliance and verification providers, fraud-prevention vendors, technology vendors, and — where required by law — regulatory authorities and government agencies. We may also share information with our affiliates and service providers who support our operations under appropriate confidentiality obligations, and in connection with a corporate reorganisation, merger, acquisition, or asset sale. Third parties may independently verify submitted information and may request additional documentation directly from you. We are not responsible for the privacy practices or decisions of third parties; we encourage you to review their policies.
6. International transfers
Because we operate internationally and coordinate with institutions in multiple jurisdictions, your information may be transferred to, stored in, or processed in countries other than your own, where data-protection laws may differ. Where required, we take reasonable steps to ensure appropriate safeguards are in place for such transfers.
7. Data retention
We retain information for as long as necessary to provide the Services, maintain engagement and service records, comply with legal, regulatory, tax, accounting, and recordkeeping obligations, resolve disputes, and enforce our agreements. Where an engagement is closed or archived, certain records may be retained for the periods required by applicable law and our compliance obligations. When information is no longer required, we take reasonable steps to delete or anonymise it.
8. Data security
We use reasonable administrative, technical, and organisational measures designed to protect information against unauthorised access, loss, misuse, or alteration. Our website is served over encrypted (TLS) connections. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and your contact and payment information accurate and current.
9. Your rights & choices
Depending on your jurisdiction, you may have rights to access, correct, update, or delete your personal information, to object to or restrict certain processing, to request portability, or to withdraw consent. To exercise any of these, contact us using the details below; we may need to verify your identity before acting, and some information may be retained where we are legally required or permitted to keep it. You may also have the right to lodge a complaint with your local data-protection authority.
10. Cookies & website analytics
Our website may use cookies and similar technologies to keep you signed in, remember preferences (such as your selected country/currency), maintain security, and understand how the site is used. You can control cookies through your browser settings; disabling some cookies may affect how the website functions.
11. Children's privacy
Our Services are intended for businesses and individuals aged 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us so we can take appropriate action.
12. Third-party links
Our website and communications may contain links to third-party websites and services. We are not responsible for the content or privacy practices of those third parties, and this Policy does not apply to them.
13. Changes to this policy
We may update, modify, or replace this Privacy Policy from time to time. Updated versions will be posted on our website with a revised "last updated" date or otherwise communicated to you. Continued use of the Services after the effective date of an updated Policy constitutes acceptance of the changes.
14. Contact us
For questions about this Privacy Policy or to exercise your rights, contact Xeloraco LLC, 2nd Floor, RMS Complex, Thangmeiband, Imphal West, Manipur 795001, India. Email: support@gatewaybridge.com.