Privacy policy

Last updated: September 2026

At Card One Money we take your privacy seriously. This policy explains what personal data we collect about you, why we collect it, the lawful bases on which we rely, how long we keep it, who we share it with, where it is transferred, and the rights you have under data protection law. It is written to meet the transparency requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are and how to contact us

Card One Money is part of the Equals group of companies. Card One Money is a trading style of Equals Money UK Limited (registered in England & Wales No. 06268340), with its registered office at 3rd Floor, Vintners’ Place, 68 Upper Thames Street, London, EC4V 3BJ.

Equals Money UK Limited is the controller of the personal data described in this policy. “Controller”, “processor”, “personal data”, “processing” and “data subject” have the meanings given to them in the UK GDPR.

Contacting our Data Protection Officer (DPO). Our DPO can be contacted in writing at Data Protection Officer, Equals Money UK Limited, 3rd Floor, Vintners’ Place, 68 Upper Thames Street, London, EC4V 3BJ, or by email at privacy@equalsmoney.com. The DPO is the appropriate point of contact for any questions about this policy, to exercise your rights, or to raise a concern about how your personal data is handled.

2. What personal data we collect

Most personal data is collected directly from you, typically during the application process and while you use our products. We may collect the following categories of personal data:

  • Identity data: title, full name, date of birth, nationality, gender (where relevant for identity checks), photograph or video used for identity verification, and signature.
  • Contact data: current and previous address, email address, mobile and home telephone numbers.
  • Financial and transactional data: bank account details, card details, transaction history, balances, and payment instructions.
  • Identification documents: passport, driving licence, national identity card, utility bills, or other documents used to verify your identity under anti-money laundering law.
  • Profile and usage data: your login credentials, account preferences, language preference, and information about how you use our website, app and services (including IP address, device information and pages visited).
  • Marketing and communications data: your preferences for receiving marketing from us and your communication preferences.
  • Special category data: we do not routinely process special category data (such as data revealing racial or ethnic origin, religious beliefs, or health). To verify your identity, we use facial-recognition technology that compares a photograph or video of you against your identity document. Because this uniquely identifies you, it involves biometric data, which is a special category of personal data. We carry out this check to verify your identity reliably and to prevent identity fraud, money laundering and other financial crime, as we are required to do under anti-money laundering law. Our lawful basis for this processing is compliance with a legal obligation. The additional condition we rely on for the biometric data is that the processing is necessary for reasons of substantial public interest, under a condition in Part 2 of Schedule 1 to the Data Protection Act 2018 relating to the prevention or detection of unlawful acts. Where you choose to give us other special category data that is not required for these purposes (for example, accessibility information), we rely on your explicit consent.

Information you must provide. Some of the information we ask for is needed to meet our legal obligations or to enter into and perform a contract with you – for example, the identity information we must collect under anti-money laundering law. If you do not provide it, we may not be able to open or continue your account or provide the services you have asked for.

Third-party data. If you provide us with personal data about another person (for example, additional directors, shareholders, beneficial owners or cardholders), you confirm that you have the authority to share their data with us and that you have shared this privacy policy with them.

3. Where we obtain your personal data

We collect personal data from the following sources:

  • Directly from you when you complete an application, contact us, use our website or app, or otherwise interact with us.
  • From a partner or platform where you access our services through that business rather than directly with us.
  • From identity verification agencies who carry out checks on our behalf or whose databases we consult.
  • From fraud prevention agencies.
  • From sanctions, politically exposed person (PEP) and adverse media screening providers used to meet our financial crime obligations.
  • From publicly available sources such as the electoral register, Companies House, and public registers.
  • From your employer or business where you are a cardholder on a corporate account.
  • From banking and payment partners, card schemes and merchants in connection with transactions you make.

Where we use identity verification agencies, we do so only to confirm your identity. It is carried out as a “soft” search, which does not affect your credit score and cannot be seen by other organisations that access your credit file.

4. How and why we use your personal data, and our lawful bases

Under data protection law, we must have a lawful basis for each purpose for which we process your personal data. This section describes our purposes and the lawful basis we rely on for each.

4.1 To perform our contract with you

We process your personal data because it is necessary to enter into or perform a contract with you, including to:

  • take steps at your request before entering into a contract;
  • decide whether to enter into a contract with you;
  • set up, manage, administer and close your account;
  • execute payments, transfers and other transactions you instruct;
  • issue and manage cards and related services;
  • keep our records of you up to date;
  • provide customer support.

4.2 To comply with our legal obligations

We process your personal data because we are required to do so by law, including to:

  • verify your identity and the identity of beneficial owners, directors and authorised representatives, as required by the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (the “Money Laundering Regulations”);
  • screen against sanctions, PEP and adverse media lists;
  • monitor transactions and submit Suspicious Activity Reports to the National Crime Agency;
  • respond to requests from regulators, law enforcement, courts and tax authorities (including the Financial Conduct Authority, HM Revenue & Customs and the Information Commissioner’s Office);
  • monitor communications (including calls and emails) where required or permitted by law;
  • respond to requests you make to exercise your rights under data protection law;
  • establish, exercise or defend legal claims.

4.3 For our legitimate interests

We process your personal data where it is necessary for our legitimate interests (or those of a third party), provided your interests, rights and freedoms do not override those interests. Our legitimate interests include:

  • Operating, securing and improving our business – governance, accounting, internal management, audit, information security, business continuity, and product development.
  • Preventing and detecting financial crime – fraud prevention and additional financial-crime controls that go beyond our strict legal obligations.
  • Research and analytics – market research, statistical analysis and customer insight, generally using aggregated or pseudonymised data.
  • Direct marketing of our own similar products and services to existing customers, with a clear right to opt out at any time.

4.4 With your consent

We rely on your consent for:

  • electronic marketing where the law requires your consent;
  • the use of non-essential cookies and similar technologies on our website (see our Cookie Policy);
  • disclosing your personal data to third parties at your specific request.

You can withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, contact us using the details in section 1 or use the unsubscribe link in any marketing email.

5. Automated decision-making and profiling

We use automated processes, including some that involve profiling, in the following ways:

  • Identity verification and fraud prevention – we use automated systems to check the information you provide against external data sources, biometric matching tools, and fraud and sanctions databases. These checks are run by us and our service providers.
  • Application assessment – where we make a decision about your application for a product using automated means, this is necessary to enter into a contract with you. The system checks the information you provide against records held by identity verification and fraud prevention agencies – to confirm your identity and to detect fraud and financial crime – against pre-set rules and risk indicators.
  • Transaction monitoring – we use automated rules and models to identify transactions that may indicate fraud, money laundering or other financial crime. Where required by law, we may block or delay transactions and report to the relevant authorities.
  • Marketing analytics – we may segment customers based on transactional history and other account information to decide what marketing communications might be relevant. This activity is based on our legitimate interests and does not produce legal or similarly significant effects on you.

The significance and consequences of these processes can include refusal of your application, restriction or closure of your account, declining a transaction, or referral of your case to the relevant authorities.

Your rights. Where a decision that produces legal or similarly significant effects is made solely by automated means, you have the right to obtain human intervention, to express your point of view, and to contest the decision. To exercise these rights, contact our DPO using the details in section 1.

6. Who we share your personal data with

We do not sell or rent your personal data. We share it only with the categories of recipient set out below, and only to the extent necessary for the purposes described in this policy:

  • Group companies within the Equals group, for the administration of our services and shared operational functions.
  • Banking and e-money partners that hold safeguarded funds, execute payments and provide access to payment systems, together with messaging and payment infrastructure providers.
  • Card schemes and card issuing, processing and personalisation partners that enable the operation of our cards.
  • Identity verification agencies used to verify your identity and assess applications.
  • Fraud prevention agencies, including Cifas, with whom we share personal data to prevent fraud and money laundering and to verify identity (see section 7).
  • Sanctions, politically exposed person (PEP) and adverse media screening providers.
  • Transaction monitoring providers, used to detect potentially fraudulent or suspicious activity.
  • Customer support providers, including support ticketing, telephony and outsourced contact centre services.
  • Marketing, communications and analytics providers, including email and SMS platforms, customer relationship management systems, website analytics and advertising platforms.
  • Other technology and infrastructure providers, including cloud hosting, security, communications and business productivity tools.
  • Professional advisers such as lawyers, auditors, regulatory consultancies, accountants and insurers.
  • Regulators, ombudsmen and authorities, including the Financial Conduct Authority (FCA), HM Revenue & Customs (HMRC), the Information Commissioner’s Office (ICO), the National Crime Agency (NCA), the Financial Ombudsman Service, together with the police, courts and tax authorities where required by law.
  • Prospective or actual purchasers of all or part of our business or assets, and their advisers, in connection with a sale or restructuring (subject to appropriate confidentiality protections).

A current list of the named third-party recipients of personal data within these categories is available on request from our Data Protection Officer using the contact details in section 1.

Where a third party processes personal data on our behalf, we put a written contract in place that requires it to protect your personal data and to use it only on our instructions. Where a third party acts as an independent or joint controller, it will be responsible for how it uses your personal data.

Merchants. We do not share your personal data with merchants (sellers) who accept payment from you using your Card One Money card, beyond what is needed to process the transaction. Where we collect information from competitions or surveys, we do not share that information with merchants, although we may share aggregated, non-identifiable statistics.

7. Fraud prevention and anti-money laundering checks

We are required by law to check your identity and to monitor your account for the purposes of preventing fraud, money laundering, terrorist financing and other financial crime.

The personal information we have collected from you will be shared with fraud prevention agencies who will use it to prevent fraud and money laundering and to verify your identity. If fraud is detected, you could be refused certain services, finance, or employment. Further details of how your information will be used by us and these fraud prevention agencies, and your data protection rights, can be found by visiting www.cifas.org.uk/fpn.

8. International transfers of personal data

Some of our service providers and group companies are located outside the United Kingdom and the European Economic Area (EEA). Where we transfer personal data outside the UK, we make sure that an appropriate safeguard is in place, which will usually be one of the following:

  • A UK adequacy decision – transfers to a country, territory or sector that the UK Government has determined provides an adequate level of protection.
  • The UK International Data Transfer Agreement (IDTA), or the UK Addendum to the European Commission’s Standard Contractual Clauses, supplemented where necessary by additional contractual, technical and organisational measures identified through a transfer risk assessment.
  • Binding Corporate Rules, where applicable to our providers.
  • In limited cases, a specific exception permitted by data protection law, such as your explicit consent or the necessity of the transfer for the performance of a contract with you, where no other mechanism is available.

You can obtain a copy of the safeguards we use for a specific transfer by contacting our DPO using the details in section 1.

9. How long we keep your personal data

We keep personal data only for as long as necessary for the purposes set out in this policy. For most records connected with our products and services, our baseline retention period is at least five years from the end of our relationship with you, reflecting the Money Laundering Regulations, FCA record-keeping requirements, and the time limits for bringing legal claims.

We operate in more than one country, and some of the jurisdictions in which we operate require anti-money laundering and financial crime records to be kept for longer than five years. Where a longer period applies to your records, we may keep them for up to a maximum of ten years. We do not keep personal data for longer than is necessary, and where it is no longer needed for the purposes for which it was collected, we will delete or anonymise it earlier.

The retention period is calculated from one of the following starting points, whichever is later:

  • the date our contractual relationship with you ends (for example, the date your account is closed);
  • the date of the last transaction or interaction on your account;
  • the date of the application, where you applied for a product but did not become a customer;
  • the date a complaint, dispute or legal claim is finally resolved.

Some categories of personal data are kept for a shorter period where the maximum retention period is not appropriate:

  • Marketing preferences and suppression lists: for as long as we operate the relevant marketing channel, so that we can honour your opt-out.
  • Website usage and cookie data: as set out in our Cookie Policy.
  • Recorded telephone calls and customer support records: retained within the maximum retention period, but may be deleted earlier where they are no longer needed for regulatory, dispute resolution or training purposes.

Where it is not practicable to delete personal data immediately (for example, because it is held in backup systems), we will isolate it from further active use until secure deletion is possible.

10. How we keep your personal data secure

We use appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage, taking into account the nature of the data and the risks involved. These measures include access controls, encryption in transit and at rest where appropriate, network security, staff training, vendor due diligence, and incident response procedures. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office and, where required, you.

11. Your rights

Under the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:

  • The right to be informed about how we use your personal data (which this policy provides).
  • The right of access to the personal data we hold about you, and to certain related information.
  • The right to rectification of inaccurate personal data, and to have incomplete personal data completed.
  • The right to erasure (“the right to be forgotten”), in certain circumstances.
  • The right to restrict processing in certain circumstances.
  • The right to data portability – to receive certain personal data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • The right to object to processing based on our legitimate interests, and an absolute right to object to direct marketing.
  • Rights in relation to automated decision-making and profiling, as described in section 5.
  • The right to withdraw consent at any time where we rely on your consent, without affecting the lawfulness of processing before withdrawal.
  • The right to lodge a complaint with the Information Commissioner’s Office (see section 12).

Some of these rights are qualified and only apply in certain circumstances. We will respond to a valid request within one month, although we may extend this by up to two further months for complex requests, in which case we will let you know within the first month. There is normally no fee for exercising your rights, although we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.

To exercise any of your rights, please contact our DPO using the details in section 1. Where you contact us by email, please use privacy@equalsmoney.com.

12. Complaints

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues. Their website is ico.org.uk, their helpline is 0303 123 1113, and their postal address is Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.

13. Marketing communications and your choices

You can opt out of receiving marketing communications from us at any time by contacting us, by logging into your online account, or by using the unsubscribe link in any marketing email.

Communications about changes to your products or services, our terms and conditions, or this policy are service communications. They are not marketing, and you cannot opt out of them while you are a customer.

14. Cookies and similar technologies

Our website uses cookies and similar technologies. A cookie is a small file placed on your device when you visit a website. We use strictly necessary cookies, and – with your consent, given through our cookie banner – analytics and advertising cookies. You can manage your preferences at any time through the cookie banner or your browser settings. Full details, including the cookies we use, their purposes and their duration, are set out in our Cookie Policy. We are responsible for obtaining your consent for non-essential cookies set via our website, including those set by third parties.

15. Children

Our products and services are intended for adults. We may, however, provide a payment card to a young person aged between 13 and 17 as an authorised cardholder on an account held by an adult or by a business. Where we do, we process that young person's personal data to operate the card and account and to meet our legal obligations, including the checks we must carry out to prevent financial crime. We do not rely on the young person's consent for this, we do not carry out facial-recognition or other biometric checks on cardholders under 18, and we do not send them marketing.

A cardholder aged 13 or over may exercise their own data protection rights, and we will deal with them directly where it is appropriate to do so. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact our DPO using the details in section 1 so that we can take appropriate action.

16. Links to third-party websites

Our website and app may contain links to websites and services operated by third parties. We are not responsible for the privacy practices or content of those third parties. We encourage you to read their privacy notices before providing them with any personal data.

17. Changes to this privacy policy

We may update this privacy policy from time to time. Where we make material changes, we will notify you by email to your registered email address. If you have not given us an email address, you should check the website regularly for the most recent version. The date at the top of this policy shows when it was last updated. We will only use your personal data in accordance with the version of this policy in force at the relevant time.

18. Reviewing, correcting or updating your personal data

If any of your details are recorded incorrectly and need to be changed, please contact us with the details of the required changes. We may need proof of certain changes (such as a change of address). You can also write to our DPO using the details in section 1.