Skip links

TumiPay · Legal Document

Privacy Policy

Code: LEG-POL-03 | Version: 01 | Effective: 12/31/2027 | Application start date: September 1, 2026

The TumiPay group, comprising TUMIPAY S.A.S., TumiPay S.A.C. (Peru), and TumiPay S.A.P.I. DE C.V. (Mexico) (hereinafter, “TumiPay” or “we”), establishes this Privacy Policy to ensure the protection, security, and confidentiality of the personal information of its clients, users, affiliated merchants, suppliers, partners, and other third parties.

This policy governs the collection, storage, use, circulation, and deletion of personal data within the framework of TumiPay’s activities as a payment service provider, and applies primarily in Colombia, Peru, and Mexico in accordance with the legislation of each country and, subsidiarily, in new jurisdictions where the TumiPay group operates. The organization also incorporates international best practices in privacy and information security, referencing standards such as the European Union’s General Data Protection Regulation (GDPR), to the extent compatible with local regulations.


1. Principles

The processing of personal data by TumiPay is governed by the following principles:

  • Legality: data processing is carried out in strict compliance with applicable data protection regulations in each country.
  • Purpose: data collection and use is limited to legitimate, explicit purposes previously disclosed to the data subject.
  • Freedom: processing is only carried out with the prior, express, and informed consent of the data subject, except in cases authorized by law.
  • Accuracy or quality: information provided must be truthful, complete, accurate, up-to-date, verifiable, and understandable.
  • Transparency: the data subject is guaranteed access to their information and the ability to know how it is being used.
  • Restricted access and circulation: data processing is carried out within the limits of regulations and with access only by authorized persons.
  • Security: necessary technical, human, and administrative measures are implemented to protect personal data against loss, alteration, misuse, or unauthorized access.
  • Confidentiality: all persons involved in data processing are obligated to ensure the confidentiality of information, even after their relationship with TumiPay has ended.

2. Definitions

  • Authorization: prior, express, and informed consent of the data subject for the processing of their personal data.
  • Database: organized set of personal data.
  • Personal Data: any information linked to or that can be associated with a specific or identifiable natural person.
  • Sensitive Data: information that affects the privacy of the data subject or whose misuse may generate discrimination, including biometric data.
  • Data Processor: person or entity that processes personal data on behalf of the controller.
  • Data Controller: person or entity that decides on the database and/or the processing of personal data.
  • Data Subject: natural person whose personal data is subject to processing.
  • Data Processing: any operation on personal data: collection, storage, use, circulation, or deletion.

3. Scope of Application

This policy applies to clients, users, affiliated merchants, suppliers, and strategic partners who interact with TUMIPAY S.A.S. (Colombia), TUMIPAY S.A.C. (Peru), or TUMIPAY S.A.P.I. DE C.V. (Mexico), or any company belonging to the TumiPay group in new jurisdictions.

4. Applicable Regulatory Framework

Colombia: Political Constitution, articles 15, 16, and 20; Law 1266 of 2008; Law 1581 of 2012; Decrees 1727 of 2009, 1377 of 2013, and 886 of 2014; External Circulars 02 of 2015 and 001 of 2016 of the Superintendence of Industry and Commerce (SIC).

Peru: Law No. 29733, Personal Data Protection Law, and its Regulation (Supreme Decree No. 016-2024-JUS); provisions of the National Authority for the Protection of Personal Data (ANPDP).

Mexico: Federal Law on the Protection of Personal Data Held by Private Parties and its Regulation; provisions of the Secretariat of Anti-Corruption and Good Governance.

5. Processing of Personal Data and Its Purpose

The personal data of clients, users, suppliers, and partners will be collected, stored, processed, analyzed, shared, and used for the following purposes, among others:

  • Provision of financial and transactional services.
  • Identity verification, document validation, and fraud prevention.
  • Compliance with legal and regulatory requirements, including prevention of money laundering and terrorist financing, and reporting to competent authorities.
  • Administration and monitoring of payment operations, ensuring security, traceability, and legality of transactions.
  • Assessment and management of technological, operational, and information security risks.
  • Contact with clients and users for informational, educational, or commercial campaigns, within the limits of the authorization granted.
  • Development, innovation, and improvement of products and services through data analysis, with anonymization or pseudonymization mechanisms where applicable.
  • Management and supervision of suppliers and partners, including due diligence processes.
  • Transfer and transmission of personal data to third-party partners, domestic or international, when necessary for the provision of services.

TumiPay maintains a clear, public, and transparent policy on the processing of personal data and sensitive information, aligned with data protection and consumer protection regulations in each country where it operates (in Colombia, the SIC; in Peru, the ANPDP and INDECOPI; in Mexico, the Secretariat of Anti-Corruption and Good Governance and PROFECO). Evidence of consent granted by data subjects through our digital channels is retained for a minimum period of ten (10) years.

6. Processing of Sensitive Data

TumiPay may process sensitive data, including biometric data (images, fingerprints, voice, and others that may be captured in authentication processes), only with prior, express, and informed authorization from the data subject, in cases such as:

  • Security and enhanced authentication of users in payment operations.
  • Compliance with fraud prevention, money laundering, and terrorist financing regulations.
  • Identity verification in financial operations requiring enhanced validations.
  • Access control and security at physical facilities and computer systems.

The processing of sensitive data will be exceptional and proportionate. TumiPay will not condition access to its services on the provision of sensitive data, unless such data is essential to ensure the security of the operation. Advanced technical controls such as encryption, database segmentation, access traceability, and audit logs will be applied. In international transfers of sensitive data, TumiPay will ensure compliance with local regulations and, where applicable, international standards such as GDPR.

The provision of sensitive data is optional. Refusal to authorize it will not limit access to the services offered, except when such information is strictly necessary to validate identity or ensure the security of the operation.

7. Access to Sensitive Personal Data

Access to databases containing sensitive information is strictly restricted to previously authorized personnel with functions directly related to its processing. To this end, TumiPay applies:

  • Two-factor authentication (2FA) mechanisms for all access.
  • Audit logs of each access, query, or modification, including user, date, time, and operation performed.
  • Principle of least privilege in the assignment of permissions.
  • Confidentiality protocols and agreements for all personnel with access to this information.

Failure to comply with these measures will result in applicable internal sanctions and, in the case of third parties, suppliers, or partners, TumiPay may immediately suspend or terminate the corresponding commercial or contractual relationship, without prejudice to applicable civil or criminal legal actions.

8. Rights of the Data Subject

In accordance with current regulations, data subjects have the following rights:

  • Know, update, and rectify their personal data with TumiPay, in its capacity as data controller.
  • Request proof of the authorization granted for the processing of their data.
  • Be informed about the use that has been made of their personal data.
  • File complaints with the competent data protection authority in their country (in Colombia, the SIC; in Peru, the ANPDP; in Mexico, the Secretariat of Anti-Corruption and Good Governance).
  • Revoke authorization and/or request deletion of their data when principles, rights, and legal guarantees are not respected.
  • Access their personal data free of charge.
  • Receive timely responses to their inquiries and complaints within the legally established timeframes.

9. Procedures for Exercising Data Subject Rights

Data subjects may submit inquiries and complaints through the channels indicated in the Contact section. Response timeframes are as follows:

Type of requestResponse timeframe
InquiriesUp to 10 business days
ComplaintsUp to 15 business days, with possible extension in justified cases

10. Accuracy, Quality, and Validation of Data

All personal data processed by TumiPay must be truthful, complete, accurate, up-to-date, verifiable, and understandable. The registration and disclosure of partial, incomplete, or misleading data is prohibited. TumiPay implements validation procedures—verification of data types, formats, relevance and consistency, and duplicate controls—and conducts periodic purges and audits of its databases to minimize errors and inconsistencies.

11. Procedures for Revocation and Deletion of Data

Data subjects may request deletion of their personal data when: (i) it is not processed in accordance with current legislation; (ii) it is no longer necessary for the established purposes; or (iii) the maximum retention period has been met. TumiPay has electronic and physical mechanisms for receiving and processing these requests.

12. Registration with Authorities

In Colombia, TumiPay is registered in the National Database Registry (RNBD) and complies with update and reporting requirements to the Superintendence of Industry and Commerce, including reporting incidents that affect the confidentiality, integrity, or availability of personal data. In Peru and Mexico, TumiPay complies with registrations, authorizations, and reports required by the National Authority for the Protection of Personal Data and applicable Mexican regulations, respectively.

13. Information Security

TumiPay implements technical, human, administrative, and organizational measures to protect personal data against loss, alteration, misuse, or unauthorized access, including encryption, access controls, enhanced authentication, backup copies, and continuous monitoring. When TumiPay delegates data processing to third parties, they must guarantee equivalent security measures through contractual confidentiality clauses and periodic audits. Full details of these controls and the obligations of third parties, clients, and partners regarding information security are found in our Information Security Terms and Conditions, a document that forms an integral part of TumiPay’s relationship with its clients, suppliers, and partners.

14. Data Controller and Policy Governance

TumiPay has an internal data controller and an Information Security Committee responsible for periodically reviewing this policy, evaluating its effectiveness, and supporting the management of risks associated with personal data processing.

15. Non-Compliance and Consequences

Non-compliance with this Privacy Policy by clients, users, suppliers, or partners—including misuse of personal data or violation of the security measures described herein—will authorize TumiPay to immediately suspend or terminate, without liability to TumiPay, the corresponding commercial, contractual, or partnership relationship, without prejudice to applicable civil, criminal, or administrative legal actions.

16. Contact

17. Effective Date and Modifications

This policy takes effect from its publication and will remain in force as long as the commercial or legal relationship with the data subject is maintained. Any substantial changes will be communicated through our website, with the date of the new version.

Global payments, unlimited connections