Last updated: September 2026
At Card One Money we take your privacy seriously. This policy explains what personal data we collect about you, why we collect it, the lawful bases on which we rely, how long we keep it, who we share it with, where it is transferred, and the rights you have under data protection law. It is written to meet the transparency requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Card One Money is part of the Equals group of companies. Card One Money is a trading style of Equals Money UK Limited (registered in England & Wales No. 06268340), with its registered office at 3rd Floor, Vintners’ Place, 68 Upper Thames Street, London, EC4V 3BJ.
Equals Money UK Limited is the controller of the personal data described in this policy. “Controller”, “processor”, “personal data”, “processing” and “data subject” have the meanings given to them in the UK GDPR.
Contacting our Data Protection Officer (DPO). Our DPO can be contacted in writing at Data Protection Officer, Equals Money UK Limited, 3rd Floor, Vintners’ Place, 68 Upper Thames Street, London, EC4V 3BJ, or by email at privacy@equalsmoney.com. The DPO is the appropriate point of contact for any questions about this policy, to exercise your rights, or to raise a concern about how your personal data is handled.
Most personal data is collected directly from you, typically during the application process and while you use our products. We may collect the following categories of personal data:
Information you must provide. Some of the information we ask for is needed to meet our legal obligations or to enter into and perform a contract with you – for example, the identity information we must collect under anti-money laundering law. If you do not provide it, we may not be able to open or continue your account or provide the services you have asked for.
Third-party data. If you provide us with personal data about another person (for example, additional directors, shareholders, beneficial owners or cardholders), you confirm that you have the authority to share their data with us and that you have shared this privacy policy with them.
We collect personal data from the following sources:
Where we use identity verification agencies, we do so only to confirm your identity. It is carried out as a “soft” search, which does not affect your credit score and cannot be seen by other organisations that access your credit file.
Under data protection law, we must have a lawful basis for each purpose for which we process your personal data. This section describes our purposes and the lawful basis we rely on for each.
We process your personal data because it is necessary to enter into or perform a contract with you, including to:
We process your personal data because we are required to do so by law, including to:
We process your personal data where it is necessary for our legitimate interests (or those of a third party), provided your interests, rights and freedoms do not override those interests. Our legitimate interests include:
We rely on your consent for:
You can withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, contact us using the details in section 1 or use the unsubscribe link in any marketing email.
We use automated processes, including some that involve profiling, in the following ways:
The significance and consequences of these processes can include refusal of your application, restriction or closure of your account, declining a transaction, or referral of your case to the relevant authorities.
Your rights. Where a decision that produces legal or similarly significant effects is made solely by automated means, you have the right to obtain human intervention, to express your point of view, and to contest the decision. To exercise these rights, contact our DPO using the details in section 1.
We do not sell or rent your personal data. We share it only with the categories of recipient set out below, and only to the extent necessary for the purposes described in this policy:
A current list of the named third-party recipients of personal data within these categories is available on request from our Data Protection Officer using the contact details in section 1.
Where a third party processes personal data on our behalf, we put a written contract in place that requires it to protect your personal data and to use it only on our instructions. Where a third party acts as an independent or joint controller, it will be responsible for how it uses your personal data.
Merchants. We do not share your personal data with merchants (sellers) who accept payment from you using your Card One Money card, beyond what is needed to process the transaction. Where we collect information from competitions or surveys, we do not share that information with merchants, although we may share aggregated, non-identifiable statistics.
We are required by law to check your identity and to monitor your account for the purposes of preventing fraud, money laundering, terrorist financing and other financial crime.
The personal information we have collected from you will be shared with fraud prevention agencies who will use it to prevent fraud and money laundering and to verify your identity. If fraud is detected, you could be refused certain services, finance, or employment. Further details of how your information will be used by us and these fraud prevention agencies, and your data protection rights, can be found by visiting www.cifas.org.uk/fpn.
Some of our service providers and group companies are located outside the United Kingdom and the European Economic Area (EEA). Where we transfer personal data outside the UK, we make sure that an appropriate safeguard is in place, which will usually be one of the following:
You can obtain a copy of the safeguards we use for a specific transfer by contacting our DPO using the details in section 1.
We keep personal data only for as long as necessary for the purposes set out in this policy. For most records connected with our products and services, our baseline retention period is at least five years from the end of our relationship with you, reflecting the Money Laundering Regulations, FCA record-keeping requirements, and the time limits for bringing legal claims.
We operate in more than one country, and some of the jurisdictions in which we operate require anti-money laundering and financial crime records to be kept for longer than five years. Where a longer period applies to your records, we may keep them for up to a maximum of ten years. We do not keep personal data for longer than is necessary, and where it is no longer needed for the purposes for which it was collected, we will delete or anonymise it earlier.
The retention period is calculated from one of the following starting points, whichever is later:
Some categories of personal data are kept for a shorter period where the maximum retention period is not appropriate:
Where it is not practicable to delete personal data immediately (for example, because it is held in backup systems), we will isolate it from further active use until secure deletion is possible.
We use appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage, taking into account the nature of the data and the risks involved. These measures include access controls, encryption in transit and at rest where appropriate, network security, staff training, vendor due diligence, and incident response procedures. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office and, where required, you.
Under the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:
Some of these rights are qualified and only apply in certain circumstances. We will respond to a valid request within one month, although we may extend this by up to two further months for complex requests, in which case we will let you know within the first month. There is normally no fee for exercising your rights, although we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.
To exercise any of your rights, please contact our DPO using the details in section 1. Where you contact us by email, please use privacy@equalsmoney.com.
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues. Their website is ico.org.uk, their helpline is 0303 123 1113, and their postal address is Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
You can opt out of receiving marketing communications from us at any time by contacting us, by logging into your online account, or by using the unsubscribe link in any marketing email.
Communications about changes to your products or services, our terms and conditions, or this policy are service communications. They are not marketing, and you cannot opt out of them while you are a customer.
Our website uses cookies and similar technologies. A cookie is a small file placed on your device when you visit a website. We use strictly necessary cookies, and – with your consent, given through our cookie banner – analytics and advertising cookies. You can manage your preferences at any time through the cookie banner or your browser settings. Full details, including the cookies we use, their purposes and their duration, are set out in our Cookie Policy. We are responsible for obtaining your consent for non-essential cookies set via our website, including those set by third parties.
Our products and services are intended for adults. We may, however, provide a payment card to a young person aged between 13 and 17 as an authorised cardholder on an account held by an adult or by a business. Where we do, we process that young person's personal data to operate the card and account and to meet our legal obligations, including the checks we must carry out to prevent financial crime. We do not rely on the young person's consent for this, we do not carry out facial-recognition or other biometric checks on cardholders under 18, and we do not send them marketing.
A cardholder aged 13 or over may exercise their own data protection rights, and we will deal with them directly where it is appropriate to do so. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact our DPO using the details in section 1 so that we can take appropriate action.
Our website and app may contain links to websites and services operated by third parties. We are not responsible for the privacy practices or content of those third parties. We encourage you to read their privacy notices before providing them with any personal data.
We may update this privacy policy from time to time. Where we make material changes, we will notify you by email to your registered email address. If you have not given us an email address, you should check the website regularly for the most recent version. The date at the top of this policy shows when it was last updated. We will only use your personal data in accordance with the version of this policy in force at the relevant time.
If any of your details are recorded incorrectly and need to be changed, please contact us with the details of the required changes. We may need proof of certain changes (such as a change of address). You can also write to our DPO using the details in section 1.