PaymentRetryAlert.com
Request beta access
Legal

Terms of Service

Payment Optimization Platform (Payment Alerts) · Effective: 16 July 2026 · Last updated: 27 August 2026

Business service: PaymentRetryAlert is offered only to businesses and is not intended for consumers acting for personal, family or household purposes.

Jade Technologies Limited | Company number 15043871 | 7 Bell Yard, London, England, WC2A 2JR

About these Terms

These Terms of Service (Terms) are a legal agreement between Jade Technologies Limited, a company incorporated in England and Wales with company number 15043871 and registered office at 7 Bell Yard, London, England, WC2A 2JR, trading as PaymentRetryAlert.com (Provider, we, us or our), and the business or other legal entity that accepts these Terms or uses the Service (Customer or you).

By clicking to accept these Terms, creating an account, submitting merchant identifiers for activation, accepting a Service Order or accessing or using the Service, you agree to the Agreement. If you accept on behalf of an organisation, you confirm that you have authority to bind it. If you do not agree, do not submit identifiers or use the Service.

Important: A RETRY_NOW alert is a network signal, not a guarantee of approval. You remain solely responsible for deciding whether to retry and for submitting any retry through your existing processor.

1. Definitions and interpretation

1.1 “Acquiring BIN” means the Mastercard acquiring bank identification number provided by the Customer for activation.

1.2 “Agreement” means these Terms, the Schedules, the Pricing Page and any Service Order accepted by the Provider.

1.3 “Alert” means a Payment Alert, including a RETRY_NOW alert or a lifecycle notification, generated by the Network Platform and made available through the Service.

1.4 “Applicable Law” means all laws, regulations, regulatory requirements and binding codes applicable to a Party or the Service.

1.5 “Business Day” means a day other than a Saturday, Sunday or public holiday in England when banks in London are open for business.

1.6 “CAID/MID” means a Card Acceptor ID or merchant identifier approved for monitoring.

1.7 “Confidential Information” means information disclosed by or on behalf of a Party that is marked confidential or that a reasonable person would understand to be confidential, including commercial terms, security information, technical documentation and non-public transaction data.

1.8 “Documentation” means the technical documentation, product guides and integration instructions supplied or made available by the Provider for the Service.

1.9 “Effective Date” means the date the Customer first accepts these Terms, submits merchant identifiers for activation, accepts a Service Order or uses the Service, whichever occurs first.

1.10 “Fees” means the charges shown on the Pricing Page or in an applicable Service Order and any other charges agreed in writing.

1.11 “Network Platform” means the Mastercard Payment Optimization Platform and related Mastercard systems used to generate Payment Alerts.

1.12 “Payment Scheme Rules” means the rules, standards, mandates and technical requirements of Mastercard and any relevant acquirer or payment service provider, as amended from time to time.

1.13 “Personal Data”, “Controller”, “Processor”, “Processing”, “Data Subject” and “Personal Data Breach” have the meanings given in applicable Data Protection Law.

1.14 “Pricing Page” means the pricing presented on PaymentRetryAlert.com, at checkout or during online activation when the Customer purchases or activates the Service.

1.15 “RETRY_NOW Alert Fee” means the usage fee payable for a RETRY_NOW alert, calculated in accordance with Schedule 5 unless the Pricing Page at activation or a Service Order states otherwise.

1.16 “Service” means the PaymentRetryAlert service described in Schedule 1.

1.17 “Service Data” means Alerts and the transaction and notification data described in Schedule 3 that the Provider Processes to provide the Service to the Customer, excluding information the Provider processes as an independent Controller under clause 10.4.

1.18 “Service Order” means an order form, proposal, checkout confirmation or other written order for the Service accepted by the Provider.

1.19 “Transaction Value” means the gross monetary value of the transaction associated with a RETRY_NOW alert, before refunds, reversals, chargebacks, fees or taxes.

1.20 References to including or similar expressions are illustrative and do not limit the words preceding them. Headings do not affect interpretation. A reference to writing includes email.

2. Agreement structure and precedence

2.1 The Agreement consists of these Terms, the Schedules, the Pricing Page, any applicable Service Order and any additional document expressly incorporated by reference.

2.2 If there is a conflict, the following order of precedence applies: (a) an applicable Service Order; (b) the Schedules; (c) these Terms; (d) the Pricing Page; and (e) the Documentation.

2.3 The Customer’s purchase order or other standard terms do not form part of the Agreement, even if referenced in an invoice or accepted administratively by the Provider.

2.4 The Service is available only to businesses. An individual accepting the Agreement must be at least 18 years old and have authority to bind the Customer.

3. The Service

3.1 The Provider will make the Service available after activation, subject to the Customer completing onboarding, providing accurate merchant identifiers, satisfying compliance checks and paying the Fees.

3.2 The Network Platform monitors eligible declined Mastercard transactions and may generate a RETRY_NOW alert when proprietary network logic indicates that a subsequent authorization request is more likely to be approved. The Provider delivers the alert to the Customer using the configured webhook endpoint.

3.3 The Provider does not acquire, process, initiate, authorize, submit or settle payment transactions. The Customer decides whether and when to retry a transaction and submits any retry through its own processor, gateway or acquirer.

3.4 The Provider will provide reasonable onboarding and technical support. No service level, availability commitment or support response time applies unless expressly stated in a Service Order.

3.5 The Provider may use affiliates, Mastercard and other subcontractors to provide the Service, but remains responsible for its obligations under the Agreement, subject to its express limitations and exclusions.

3.6 The Service is currently offered as a limited beta programme. Production monitoring is expressly authorised for Customers enrolled in the beta. The Provider may adjust beta capacity, features, territories and enrolment eligibility on reasonable notice. Except as expressly stated in this clause, the Agreement (including clauses 9, 15 and 16 and the Schedules) applies in full to the Service provided during the beta programme. Clause 15.5 applies to individual features identified as beta, preview or test in the Documentation, not to the Service as a whole.

4. Enrollment and activation

4.1 The Customer must provide the Mastercard Acquiring BIN and CAID/MID for each merchant account it wishes to monitor, together with any other information reasonably required for validation, enrolment, compliance review and billing.

4.2 The Customer warrants that it owns, controls or is duly authorised to enrol each submitted identifier and to instruct the Provider and Mastercard to monitor eligible transactions associated with it.

4.3 The Customer must promptly notify the Provider if an identifier is no longer valid, is no longer controlled by the Customer, changes acquirer, or must be removed from monitoring.

4.4 Activation and continued monitoring are subject to approval and technical enablement by Mastercard and any relevant acquirer. The Provider does not guarantee that any identifier or transaction is eligible.

5. Customer responsibilities

5.1 The Customer must:

  • maintain all acquiring, processing and card-on-file agreements, cardholder authorities and consents required to submit retries and use the Service;
  • comply with Applicable Law, Payment Scheme Rules, the Documentation and reasonable security instructions from the Provider;
  • ensure that transaction and merchant information supplied to the Provider is complete, accurate and current;
  • maintain a secure webhook endpoint and systems capable of matching Alerts to the correct original transaction;
  • independently determine whether each retry is lawful, appropriate and consistent with its customer terms, retry policy and Payment Scheme Rules;
  • remain responsible for all authorization fees, interchange, processing costs, refunds, reversals, disputes, chargebacks, customer communications and regulatory obligations arising from a retry; and
  • cooperate with reasonable compliance, security and operational requests from the Provider or Mastercard.

5.2 The Customer is responsible for all use of the Service by its personnel, affiliates and service providers and must ensure that they comply with the Agreement.

5.3 Unless a Service Order expressly permits use for third-party merchants, the Customer may use the Service only for its own merchant accounts and may not resell or sublicense it.

6. Webhooks, Alerts and retries

6.1 The Customer must validate webhook signatures, protect its signing secret, restrict access to Alerts and notify the Provider promptly of suspected compromise or unauthorised use.

6.2 Only RETRY_NOW alerts require action. Lifecycle notifications are provided for monitoring and reconciliation and must not be treated as instructions to submit a payment.

6.3 An Alert is a signal, not a guarantee. A subsequent retry may still be declined, delayed, reversed, disputed or charged back. The Customer must not represent otherwise to any cardholder or third party.

6.4 The Customer must not retry a transaction that has already been paid, cancelled, refunded, disputed, revoked by the cardholder or is otherwise ineligible under Applicable Law, its customer agreement or Payment Scheme Rules.

6.5 The Provider may retry delivery of failed webhook notifications but is not responsible for failures caused by the Customer’s endpoint, network, configuration, systems or security controls.

7. Acceptable use and restrictions

7.1 The Customer must not, and must not permit any other person to:

  • access or use the Service for unlawful, fraudulent, abusive or deceptive activity;
  • use the Service in a way that breaches Payment Scheme Rules or harms the security, integrity, availability, brand or reputation of the Provider, Mastercard or a payment ecosystem participant;
  • copy, modify, translate, reverse engineer, decompile, disassemble or attempt to derive the source code, proprietary logic or decisioning of the Service or Network Platform, except to the limited extent such restriction is prohibited by law;
  • conduct penetration testing, vulnerability scanning or security testing of the Service, Network Platform or related systems without the Provider’s prior written consent;
  • interfere with or circumvent authentication, rate limits, access restrictions or security controls;
  • use Alerts or Documentation to build, train or improve a competing service or dataset; or
  • use Mastercard names, logos or marks except as expressly authorised in writing.

8. Mastercard and third-party dependencies

8.1 The Customer acknowledges that the Service depends on the Network Platform, Mastercard, acquirers, processors, telecommunications networks and other third-party systems outside the Provider’s control.

8.2 Mastercard may update its platform, rules, eligibility, territories, documentation, APIs, supported decline reasons or operational requirements. The Provider may make corresponding changes to the Service and the Customer must implement mandatory technical changes within the notified timeframe.

8.3 The Provider may suspend, modify or discontinue affected parts of the Service if required by Mastercard, an acquirer, a regulator, Applicable Law, a Payment Scheme Rule or a material third-party change. Where practicable, the Provider will give reasonable notice.

8.4 Mastercard is not a party to the Agreement. The Customer has no contractual claim against Mastercard through the Agreement, and the Provider does not make any warranty on Mastercard’s behalf.

9. Fees, invoicing and taxes

9.1 The Customer must pay the Fees calculated in accordance with Schedule 5 and shown on the Pricing Page at activation or in an applicable Service Order. Fees are exclusive of VAT, sales tax and similar taxes, which will be added where applicable.

9.2 The RETRY_NOW Alert Fee is incurred when a RETRY_NOW alert is generated for the Customer and made available for delivery to the Customer’s configured endpoint, whether or not delivery succeeds, the Customer acts on the alert, or a subsequent retry is approved. No usage fee is charged for lifecycle notifications unless the Pricing Page or a Service Order states otherwise.

9.3 If a transaction is denominated in a currency other than the billing currency shown at checkout or in the Service Order, the Provider may convert the Transaction Value using the Mastercard settlement rate or, if that rate is not available, the European Central Bank reference rate, in each case applicable on the date the Alert is issued. The default billing currency is USD.

9.4 The Provider will charge the Customer’s authorised payment method or invoice monthly in arrears. The Customer authorises recurring charges for Fees and must keep its payment and billing details current. Invoices are due within 14 days. The Customer must notify the Provider of a good-faith invoice dispute within 14 days after receipt, identifying the disputed amount and reasons, and must pay all undisputed amounts when due. All amounts are payable in full without set-off, counterclaim, deduction or withholding, except as required by law.

9.5 Overdue amounts may bear statutory interest and recovery charges under the Late Payment of Commercial Debts (Interest) Act 1998. The Provider may suspend the Service on at least 10 days’ written notice while undisputed amounts remain overdue.

9.6 The Provider may change Fees on at least 30 days’ written notice. If the Customer does not accept an increase, it may terminate the affected Service before the increase takes effect. Scheme, tax or regulatory pass-through increases may take effect on shorter notice where reasonably necessary.

9.7 Fees are non-refundable except where the Agreement expressly states otherwise. Termination does not affect Fees accrued before its effective date.

10. Data protection

10.1 Each Party must comply with applicable Data Protection Law. For Service Data processed on the Customer’s behalf, the Customer is the Controller and the Provider is the Processor. If the Customer is itself a Processor, the Provider acts as its sub-processor.

10.2 Schedule 2 applies to Processing by the Provider on behalf of the Customer. Schedule 3 describes the Processing. The Agreement, the Customer’s configuration and documented use of the Service constitute the Customer’s instructions.

10.3 The Customer warrants that it has all notices, lawful bases, permissions and instructions required to enrol its identifiers, receive and use Alerts, instruct the Provider and Mastercard, and submit any subsequent retry.

10.4 The Provider may process business contact, account, billing, usage, security and support information as an independent Controller for contract administration, fraud prevention, security, legal compliance and improvement of the Service, in accordance with its privacy notice.

11. Security

11.1 Each Party must maintain appropriate technical and organisational measures proportionate to the risks associated with the Service and Personal Data.

11.2 The Provider’s baseline measures are described in Schedule 4. The Customer acknowledges that no system or transmission method is completely secure.

11.3 The Customer must not send full card numbers, security codes, authentication data or other payment data not expressly required by the Documentation to the Provider.

12. Confidentiality

12.1 Each receiving Party must keep the disclosing Party’s Confidential Information confidential and use it only to exercise rights or perform obligations under the Agreement.

12.2 A receiving Party may disclose Confidential Information to personnel, professional advisers, affiliates and subcontractors who need to know it and are bound by confidentiality obligations, and where required by law, court or regulator.

12.3 Confidential Information does not include information that the receiving Party can demonstrate was lawfully known without restriction, becomes public other than through breach, is received lawfully from a third party, or is independently developed without use of the Confidential Information.

12.4 The confidentiality obligations continue for five years after termination, except that obligations relating to trade secrets, Personal Data and security credentials continue for so long as the information remains protected or confidential by its nature.

13. Intellectual property

13.1 The Provider, Mastercard and their licensors retain all intellectual property rights in the Service, Network Platform, Documentation, APIs, software, data models, proprietary logic and improvements. No rights are transferred except the limited rights expressly granted by the Agreement.

13.2 Subject to payment of Fees and compliance with the Agreement, the Provider grants the Customer a non-exclusive, non-transferable, revocable right during the Term to access and use the Service and Documentation for its internal business purposes.

13.3 The Customer retains its rights in information it provides to the Provider. The Customer grants the Provider and its subcontractors the rights necessary to process that information and provide, secure, support and bill for the Service.

13.4 The Provider may use aggregated and irreversibly anonymised information that does not identify the Customer, a merchant or a Data Subject to operate, analyse and improve its services and produce statistical insights.

13.5 If the Customer provides feedback, it grants the Provider a perpetual, worldwide, royalty-free right to use that feedback without restriction or attribution, provided it does not identify the Customer without consent.

14. Compliance reviews

14.1 The Customer must maintain compliance programmes appropriate to its business addressing sanctions, anti-money laundering, counter-terrorist financing, anti-bribery and corruption.

14.2 The Customer must promptly provide information reasonably requested by the Provider or Mastercard for onboarding, know-your-customer checks, sanctions screening, security reviews, audit, regulatory inquiries or compliance with Payment Scheme Rules, including participating in interviews and providing access reasonably required for a compliance review of the Provider or the Customer conducted by or on behalf of Mastercard.

14.3 Where reasonably required by Mastercard, the Customer must disclose any person that directly or indirectly holds 20% or more ownership or control and promptly notify material changes.

14.4 The Customer must cooperate with reasonable remediation requirements arising from a compliance review. Failure to provide required information or complete material remediation within the specified timeframe is a material breach.

14.5 The Customer represents and warrants, on a continuing basis, that neither it, nor any person with a 20% or greater ownership or controlling interest in it, nor any merchant for which identifiers are enrolled, is: (a) subject to sanctions administered or enforced by the United Nations, the United Kingdom, the European Union or the United States; or (b) located, organised or resident in a country or territory that is the subject of comprehensive sanctions. Breach of this clause is a material breach incapable of cure.

15. Warranties and disclaimers

15.1 Each Party warrants that it has authority to enter into the Agreement.

15.2 The Provider warrants that it will provide the Service with reasonable skill and care. If the Provider breaches this warranty, its obligation is to use reasonable efforts to correct the affected Service.

15.3 Except as expressly stated, the Service, Alerts, test environments and Documentation are provided as available. To the fullest extent permitted by law, all implied warranties, conditions and terms are excluded.

15.4 The Provider does not warrant that the Service will be uninterrupted or error-free; that every eligible transaction will be monitored; that an Alert will be complete, timely or accurate; that any retry will be approved; or that the Customer will achieve any particular conversion, revenue, churn or cost outcome.

15.5 Any individual feature identified as beta, preview or test in the Documentation is provided as-is, may be changed or withdrawn at any time and must not be used for production transactions unless the Provider expressly authorizes it. This clause does not apply to the Service as a whole during the beta programme described in clause 3.6, for which production use is authorised.

16. Liability

16.1 Nothing in the Agreement limits or excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, deliberate misconduct, or any liability that cannot lawfully be limited or excluded.

16.2 Subject to clause 16.1, neither Party is liable for indirect or consequential loss or for loss of profit, revenue, anticipated savings, goodwill, reputation, opportunity or data, whether direct or indirect.

16.3 Subject to clauses 16.1 and 16.4, each Party’s aggregate liability arising out of or in connection with the Agreement in any rolling 12-month period is limited to the greater of: (a) 100% of the Fees paid or payable by the Customer in that period; and (b) USD 1,000.

16.4 Each Party’s aggregate liability for breach of confidentiality or Data Protection Law in any rolling 12-month period is limited to twice the amount calculated under clause 16.3.

16.5 The Provider is not liable to the extent loss results from the Customer’s systems, endpoint, configuration, retry decision, processing relationship, breach of the Agreement, failure to follow Documentation, or a third-party network or payment-system event outside the Provider’s reasonable control.

16.6 The Customer’s obligation to pay Fees and its liabilities under clause 17 are not limited by this clause 16.

17. Customer indemnity

17.1 The Customer will indemnify the Provider against third-party claims, losses, penalties, costs and reasonable legal fees arising from: (a) the Customer’s unlawful or unauthorised enrolment, use of transaction data or retry; (b) a breach of Payment Scheme Rules or clause 7; (c) a claim that the Customer lacked authority, notice, lawful basis or consent required under clause 10.3; or (d) the Customer’s products, customer terms or payment processing relationship.

17.2 The Provider must give prompt notice of an indemnified claim, allow the Customer reasonable control of the defence and settlement, and provide reasonable cooperation at the Customer’s cost. The Customer may not settle a claim in a way that admits fault by or imposes obligations on the Provider without consent.

18. Suspension

18.1 The Provider may suspend all or part of the Service immediately where reasonably necessary to:

  • protect the security, integrity or availability of the Service or Network Platform;
  • prevent suspected unlawful, fraudulent or abusive activity;
  • comply with Applicable Law, Payment Scheme Rules or a direction from Mastercard, an acquirer, regulator or court;
  • respond to a material third-party outage, vulnerability or operational event;
  • address a material breach that is incapable of cure or creates immediate risk; or
  • stop service to an identifier the Customer is not authorised to use.

18.2 The Provider may also suspend for non-payment in accordance with clause 9.5 or for a curable material breach that is not remedied within 10 days after notice.

18.3 Where practicable, the Provider will notify the Customer of the suspension and restore the Service when the reason for suspension has been resolved.

19. Term and termination

19.1 The Agreement starts on the Effective Date. Unless a Service Order states otherwise, the paid Service begins when production monitoring is activated, continues for one month and automatically renews for successive one-month periods.

19.2 The Customer may cancel the Agreement or an affected Service at any time through any cancellation function made available in its account or by emailing support@paymentretryalert.com; cancellation takes effect at the end of the then-current monthly period described in clause 19.1. The Provider may terminate the Agreement or an affected Service at any time by giving at least 30 days’ written notice.

19.3 Either Party may terminate immediately by written notice if the other Party commits a material breach that cannot be remedied or is not remedied within 30 days after written notice, becomes insolvent, ceases business or enters an analogous process.

19.4 The Provider may terminate or suspend immediately if required by Mastercard, an acquirer, Applicable Law, Payment Scheme Rules or a regulator; if the Customer fails a mandatory compliance review; or if continuing the Service would create a material security, legal, financial or reputational risk.

19.5 The Provider may terminate an affected Service on at least 30 days’ notice if Mastercard discontinues or materially changes the relevant network service or the Provider can no longer provide it on commercially reasonable terms.

20. Consequences of termination

20.1 On termination: (a) the Customer’s right to use the affected Service ends; (b) monitoring and Alert delivery may stop; (c) all accrued Fees become due; and (d) each Party must return or destroy the other’s Confidential Information on request, subject to legal retention and routine backups.

20.2 The Customer remains responsible for retries submitted before or after termination and must ensure its systems do not continue to rely on the Service after termination.

20.3 Clauses intended by their nature to survive termination continue, including clauses 9 to 17 and 20 to 25 and Schedules 2 and 3 to the extent required for retained Personal Data.

21. Publicity

21.1 Neither Party may use the other Party’s name, logo or marks in public marketing, customer lists or case studies without prior written consent. Consent may be withdrawn for future use on reasonable notice.

21.2 The Customer must not state or imply that it is endorsed, sponsored or certified by Mastercard or the Provider unless expressly authorised in writing.

22. Force majeure

22.1 Neither Party is liable for delay or failure caused by events beyond its reasonable control, including failures of payment networks, acquirers, processors, telecommunications, cloud infrastructure, utilities, acts of government, sanctions, cyberattacks not caused by its failure to maintain reasonable security, natural disasters, war or industrial disputes.

22.2 The affected Party must use reasonable efforts to mitigate the effect. If the event continues for more than 60 days and materially prevents the Service, either Party may terminate the affected Service on written notice.

23. Notices

23.1 Notices to the Provider must be sent to support@paymentretryalert.com and, for legal proceedings, to its registered office. Notices to the Customer may be sent to the email address supplied during activation, checkout or in a Service Order. Email notice is deemed received at the time of sending if sent before 5.00 pm (London time) on a Business Day, and otherwise at 9.00 am on the next Business Day, unless the sender receives a delivery failure notification, provided that notices of legal proceedings must also be sent by tracked post or recognized courier.

23.2 A Party may update its notice details by written notice.

24. General

24.1 Neither Party may assign the Agreement without the other Party’s prior written consent, not to be unreasonably withheld, except that the Provider may assign it to an affiliate or in connection with a merger, reorganisation or sale of all or substantially all of the relevant business.

24.2 The Provider may subcontract performance but remains responsible for its contractual obligations, subject to the Agreement.

24.3 The Provider may update these Terms from time to time. It will give at least 30 days’ notice of a material change unless an earlier change is reasonably required by law, Payment Scheme Rules, Mastercard, security or a regulator. Continued use after the effective date constitutes acceptance. If the Customer does not agree to a material change, it may terminate before the change takes effect.

24.4 Except for updates permitted under clauses 8, 9.6 and 24.3, a variation must be agreed in writing by authorised representatives.

24.5 A failure or delay to exercise a right is not a waiver. If a provision is invalid or unenforceable, it will be modified to the minimum extent necessary and the remainder will continue.

24.6 The Parties are independent contractors. Nothing creates a partnership, joint venture, fiduciary relationship, agency or employment relationship.

24.7 Except as expressly stated, a person who is not a Party has no right to enforce the Agreement under the Contracts (Rights of Third Parties) Act 1999.

24.8 The Agreement is the entire agreement regarding its subject matter and supersedes prior proposals, discussions and representations. Neither Party relies on statements not set out in the Agreement, without limiting liability for fraud.

24.9 Electronic acceptance, online checkout, submission of merchant identifiers and continued use of the Service are valid methods of entering into the Agreement. The Provider may retain electronic records of acceptance.

25. Governing law and jurisdiction

25.1 The Agreement and any non-contractual obligations arising from it are governed by the laws of England and Wales.

25.2 The courts of England and Wales have exclusive jurisdiction to settle disputes arising out of or in connection with the Agreement.

Schedule 1: Service specification

1. Service overview

1.1 PaymentRetryAlert provides webhook delivery of Payment Alerts generated through the Mastercard Payment Optimization Platform. The Network Platform monitors eligible declined Mastercard transactions and may identify an appropriate time to re-attempt authorization.

1.2 A RETRY_NOW notification contains identifiers and transaction metadata intended to help the Customer match the Alert to the original declined transaction and decide whether to retry through its existing processor.

2. Eligibility and monitoring

  • The Service applies only to approved Mastercard Acquiring BIN and CAID/MID combinations.
  • Eligible decline categories currently include insufficient funds and exceeded limit responses, including ISO 8583 response codes 51 and 61, subject to Mastercard rules and configuration.
  • Eligibility further depends on the transaction territory and the card-issuing country supported by Mastercard from time to time, as specified in the Documentation.
  • The standard monitoring window is up to 30 days, subject to configuration, network availability and Mastercard requirements.
  • The Service may cancel monitoring if a successful retry is observed or may expire without a RETRY_NOW alert.

3. Notifications

NotificationMeaningCustomer action
RETRY_NOWA network signal indicates that a retry may now be more likely to approve.Match the Alert, apply the Customer’s retry controls and decide whether to retry.
MONITORING_STARTEDAn eligible decline has entered monitoring.No payment action required.
MONITORING_CANCELLEDMonitoring ended before expiry, including where a successful payment was observed.No payment action required; reconcile as appropriate.
MONITORING_EXPIREDThe monitoring window ended without a RETRY_NOW signal.No payment action required.

4. Integration

  • Onboarding includes sandbox access, test collections and integration support through to production launch.
  • Customer supplies a valid HTTPS webhook endpoint.
  • Webhook requests are signed using HMAC-SHA256 and transmitted using TLS 1.2 or later where supported.
  • The Customer must validate signatures and protect webhook credentials.
  • Notification metadata may include notification ID and status, timestamps, merchant ID, network transaction identifier, transaction amount and currency, card BIN and last four digits.
  • The Provider may update API fields and Documentation, with reasonable advance notice where a material mandatory implementation change is required.

5. Exclusions

5.1 The Service does not guarantee transaction approval, submit the retry, replace the Customer’s payment processor or dunning platform, provide acquiring services, or determine the Customer’s legal right to charge a cardholder.

Schedule 2: Data processing terms

1.1 For this Schedule, Data Protection Law means the UK GDPR, the Data Protection Act 2018, the EU GDPR where applicable, and other privacy laws applicable to the Processing under the Agreement.

1.2 The Provider will Process Personal Data only on the Customer’s documented instructions, including the Agreement and the Customer’s use and configuration of the Service, unless required by law. If legally permitted, the Provider will inform the Customer before Processing required by law.

1.3 The Provider will ensure that persons authorised to Process Personal Data are subject to confidentiality obligations and receive appropriate data protection and security training.

1.4 The Provider will maintain appropriate technical and organisational security measures, including those in Schedule 4, taking into account the nature, scope, context and purposes of Processing and the risks to Data Subjects.

1.5 The Customer gives general written authorization for the Provider to appoint sub-processors. The Customer specifically authorizes Mastercard entities required to operate the Network Platform. The Provider will impose written data protection obligations on sub-processors that provide an equivalent level of protection and remains responsible for their Processing to the extent required by Data Protection Law.

1.6 The Provider will give reasonable advance notice of a new material sub-processor where practicable. The Customer may object on reasonable data protection grounds within 10 days. The Parties will seek a reasonable solution; if none is available, the Provider may terminate the affected Service without liability and refund any prepaid Fees for the unused period.

1.7 Taking into account the nature of Processing, the Provider will provide reasonable assistance to help the Customer respond to Data Subject requests. The Provider may charge reasonable costs for assistance that is excessive or not caused by its breach.

1.8 The Provider will provide reasonable assistance with the Customer’s obligations concerning security, Personal Data Breach notification, data protection impact assessments and prior consultation, taking into account the nature of Processing and information available to the Provider.

1.9 The Provider will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed on the Customer’s behalf and will provide available information reasonably required for the Customer’s compliance. Notification is not an admission of fault.

1.10 The Provider will make available information reasonably necessary to demonstrate compliance with this Schedule. No more than once annually, unless required by a regulator or following a material Personal Data Breach, the Customer may request an audit by an independent auditor subject to confidentiality, reasonable notice and measures to avoid disruption. The Customer bears its audit costs unless the audit identifies a material breach by the Provider.

1.11 On termination and at the Customer’s written choice, the Provider will delete or return Personal Data Processed on the Customer’s behalf, unless retention is required by law. Data in routine backups may be retained until overwritten under normal retention cycles, subject to continued protection and no further Processing except restoration, security or legal compliance.

1.12 The Provider may make restricted transfers only where permitted by Data Protection Law and subject to an applicable adequacy decision, approved contractual safeguards or another lawful transfer mechanism.

1.13 The Customer is responsible for the accuracy, quality and lawfulness of Personal Data and instructions and must not instruct the Provider to Process Personal Data in breach of Data Protection Law.

Schedule 3: Processing details

Subject matterProvision, operation, security, support, reconciliation and billing of PaymentRetryAlert.
DurationFor the Term and any limited retention period permitted by the Agreement or required by law.
Nature and purposeReceipt, transmission, matching, monitoring, storage, organisation, analysis, support, security, reporting, billing, deletion and anonymisation as needed to provide the Service.
Data SubjectsCustomer cardholders and customers whose eligible Mastercard transactions are monitored; Customer personnel and authorised users who receive support or administer the Service.
Transaction dataMasked card data (BIN and last four digits), merchant identifier, Acquiring BIN, network transaction identifier, transaction amount, currency, transaction time, notification ID, notification status and notification time.
Business contact dataNames, business email addresses, job titles, support communications and account administration information.
Special category dataNot intended to be Processed. The Customer must not submit special category data through the Service.
Full card dataFull PAN, card security code and authentication data are not intended to be received or stored by the Provider and must not be submitted by the Customer.
FrequencyContinuous or event-driven during the Term.
Approved sub-processor categoryMastercard entities operating the Network Platform; infrastructure, communications, security and support providers used to operate the Service.

Schedule 4: Baseline security measures

1. Access control

  • Role-based access limited to personnel and service providers with a business need.
  • Authentication controls appropriate to administrative and production access.
  • Periodic review and prompt revocation of access when no longer required.

2. Transmission and application security

  • TLS 1.2 or later for webhook transmission where supported.
  • HMAC-SHA256 signing of webhook requests.
  • Secure software development, change control and vulnerability management practices appropriate to the Service.

3. Data minimization and handling

  • No intentional receipt or storage of full PAN or card security codes.
  • Processing limited to the fields required to provide, secure, support and bill for the Service.
  • Confidentiality obligations for personnel with access to Personal Data.

4. Availability and resilience

  • Monitoring, logging and incident response procedures appropriate to the Service.
  • Backup, restoration and business continuity measures appropriate to the Provider’s systems and dependencies.
  • Use of reputable infrastructure and network providers, subject to third-party availability.

5. Governance

  • Security and privacy policies proportionate to the Provider’s size, role and risk profile.
  • Supplier due diligence and contractual security requirements for material sub-processors.
  • Periodic review of technical and organisational measures and improvement where reasonably necessary.

Schedule 5: Fees

1.1 This Schedule applies unless the Pricing Page at activation or a Service Order states different rates or amounts, in which case those prevail for the affected Service.

1.2 The Customer pays, for each calendar month, the greater of: (a) the monthly minimum of USD 100 (the “Monthly Minimum”); and (b) the aggregate RETRY_NOW Alert Fees for that month. The Monthly Minimum is inclusive of, not additional to, usage.

1.3 The RETRY_NOW Alert Fee for each billable RETRY_NOW alert is the applicable rate applied to the Transaction Value of that alert. Rates are progressive and are determined by the aggregate Transaction Value of billable RETRY_NOW alerts in the calendar month (measured in the billing currency after any conversion under clause 9.3), with each rate applying only to the portion of aggregate monthly Transaction Value within its band:

Aggregate monthly alerted Transaction ValueRate
First USD 10,0002.50%
Above USD 10,000 up to USD 50,0002.25%
Above USD 50,000 up to USD 250,0002.00%
Above USD 250,000 up to USD 1,000,0001.80%
Above USD 1,000,0001.60%

1.4 Bands reset at the start of each calendar month. Monthly usage is calculated on aggregate banded value and rounded to the nearest cent.

1.5 No usage fee is charged for lifecycle notifications. In a partial first or final month, the Monthly Minimum is not pro-rated unless the Pricing Page or a Service Order states otherwise.

1.6 The Provider’s records of RETRY_NOW alerts generated and made available for delivery are prima facie evidence of usage.