隐私政策
Date: May 2026
PRIVACY NOTICE: DMORE MERCHANT-OF-RECORD / RESELLER SERVICE
THIS IS THE PRIVACY NOTICE OF DLOCAL OPCO IRELAND LIMITED IN RESPECT OF THE dMORE SERVICE
This Privacy Notice explains how dLocal OpCo Ireland Limited ("we", "us", "our") processes Personal Data about End-Users in connection with our dMore merchant-of-record / reseller solution.
"dMore" is a trading name of dLocal OpCo Ireland Limited, a company incorporated in Ireland and part of the dLocal group. Through dMore, dLocal OpCo Ireland Limited purchases digital products, content, software-as-a-service, subscriptions or services from merchants and resells them to you (the "End-User"). When products or services are offered through dMore, dLocal OpCo Ireland Limited acts as an independent data controller in relation to certain processing of your Personal Data, as further explained in this Privacy Notice.
Your privacy is very important to us. We are committed to the protection of your Personal Data, and the purpose of this Privacy Notice is to inform you about the way we process your Personal Data, including which data we process, how, why and for how long, together with information about your rights as a Data Subject.
When you purchase products or services through dMore, there are two independent data controllers processing your Personal Data for their own respective purposes:
- dLocal OpCo Ireland Limited — acting as the merchant of record / reseller, processing your Personal Data for the purposes described in this Privacy Notice (e.g., receipting, tax, compliance, billing and account administration); and
- The Merchant — the provider of the underlying digital products, content, or services you are purchasing, which processes your Personal Data for its own purposes (e.g., delivering the service to you, managing your account within its platform, and providing customer support related to the service itself).
Each controller is independently responsible for its own processing activities. This Privacy Notice covers only the processing carried out by dLocal OpCo Ireland Limited. You should also refer to the Merchant's own privacy notice, which will explain how it processes your Personal Data in connection with the products or services you receive. The Merchant's privacy notice will typically be available on its website or provided to you at the point of purchase.
This Privacy Notice should be read together with the dMore Terms of Use, which govern your use of the dMore service and set out the contractual terms applicable to your purchases. In the event of any conflict between this Privacy Notice and the Terms of Use on matters relating to the processing of your Personal Data, this Privacy Notice shall prevail.
"dLocal affiliates" means any entity that directly or indirectly controls, is controlled by, or is under common control with dLocal OpCo Ireland Limited, where "control" means the ownership of more than 50% of the voting rights or equivalent ownership interest in the relevant entity.
"Merchant" means the third-party provider of the digital products, content, software-as-a-service, subscriptions, or services that dLocal OpCo Ireland Limited purchases and resells to you through the dMore service. The Merchant is identified to you at the point of purchase.
"Personal data" means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
For the purpose of this Privacy Notice, Data Protection Legislation means: (1) in the EEA: the General Data Protection Regulation (EU) 2016/679 (the "EU GDPR") and any other applicable data protection legislation within the EEA; and (2) any applicable data protection law of the country where you are resident.
1. IMPORTANT INFORMATION
Who we are
dLocal OpCo Ireland Limited is a private limited company incorporated in Ireland with registered office at 3 Dublin Landings, North Wall Quay, Dublin 1, D01 C4E0, Ireland. We are part of the dLocal group of companies.
When we provide the dMore merchant-of-record / reseller solution, we act as an independent data controller in respect of certain End-User Personal Data processed for the purposes described in this Privacy Notice.
Individuals from whom we collect Personal Data (the “Data Subjects”)
In this Privacy Notice, "you" or "your" means the End-User — the individual who purchases or receives products or services through the dMore solution. You are typically a buyer or beneficiary of one of our Merchant's products, where dLocal OpCo Ireland Limited is the seller of record.
2. INFORMATION WE MAY COLLECT (OR RECEIVE) ABOUT YOU
How your Personal Data is collected
We may collect or receive your Personal Data in the following ways:
- Direct interactions. You may provide Personal Data when you purchase products or services through dMore, including when you complete a transaction, request a refund, or contact us regarding a purchase.
- From our Merchant. The merchant whose products you are purchasing may share your Personal Data with us so that we can perform our merchant-of-record / reseller obligations (including issuing receipts, processing refunds, calculating applicable taxes, and complying with our legal obligations).
- From our payment processor. dLocal affiliates, which provide payment processing services in connection with dMore transactions, may share transaction-related Personal Data with us for settlement, reconciliation, tax and compliance purposes.
- From third parties. We may receive Personal Data from third-party service providers that we engage for invoicing, tax automation, fraud detection, or compliance purposes.
Categories of Personal Data we process
We process the following categories of Personal Data about you:
|
Category |
Description |
|
Identity Data |
First name, last name, and (where required by law) government-issued identification numbers or tax identifiers. |
|
Contact Data |
Email address, billing address, delivery address, telephone number, country and state of residence. |
|
Transaction Data |
Details of products or services purchased, transaction amount, transaction date and time, payment method identifier, order reference, currency, refund and chargeback history, and receipt records. |
|
Technical Data |
Limited technical information such as IP address, device identifiers and geolocation data associated with your transaction, used for fraud prevention and security purposes. |
|
Risk-Related Data |
Internal risk or fraud scores, chargeback indicators, and Payment Network-related flags or assessments associated with your transactions. |
|
Financial Data |
Limited payment-instrument metadata (e.g., payment method type, last four digits of card number, wallet identifiers) necessary for receipt, reconciliation, and tax purposes. We do not store full card numbers. |
|
Tax Data |
Information necessary to calculate, collect, report, and remit applicable transaction taxes (e.g., VAT, GST, sales tax), including product classification, your location, and applicable tax identifiers. |
We do not intentionally collect special categories of personal data as defined under the EU GDPR (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification purposes, health data, or data concerning sex life or sexual orientation) in connection with the dMore service. Where the laws of your country of residence recognise an equivalent category of sensitive or protected personal data, we do not intentionally collect such data either.
3. CHILDREN'S DATA
The dMore Reseller Services are not intended for children under the age of 13 (or such higher minimum age as may be required by the laws of your country of residence). We do not knowingly collect Personal Data from children below that age.
If you are between the minimum age and the age of majority in your jurisdiction, you must have the permission of a parent or legal guardian to use the Reseller Services and for us to process your Personal Data. Parents and legal guardians are responsible for the acts of minors using the Reseller Services.
If we become aware that we have collected Personal Data from a child without appropriate parental consent, we will take steps to delete that data as soon as reasonably practicable. If you believe that we may have collected data from a child without appropriate consent, please contact us using the details in Section 12 below.
Where the Merchant collects Personal Data for the purposes of age verification, age assurance, parental authorisation or similar child-protection measures, such data will be processed exclusively by the Merchants for those purposes. In such cases, dLocal will not collect, access, use or otherwise process such data, nor carry out any profiling based on age-verification-related data.
4. HOW WE USE YOUR PERSONAL DATA
We process your Personal Data as an independent data controller only for the following purposes and on the following lawful bases:
4.1 Sales receipts and transaction records
To issue, store, and reconcile sales receipts and other records of resale transactions with you and our Merchant, and to maintain our own ledgers and internal accounting records in relation to those resale transactions.
Lawful Basis: Performance of contract with you (the dMore Terms of Use) and our legitimate interests in operating the dMore merchant-of-record / reseller model and in maintaining accurate records of those transactions for financial, audit and tax purposes.
4.2 Refunds, returns and post-sale adjustments
To coordinate and record refunds, returns, and other post-sale adjustments between you and our merchant partners in connection with resale transactions.
Lawful Basis: Performance of contract with you (the dMore Terms of Use) and our legitimate interests in administering post-sale events and ensuring a good customer experience under dMore.
4.3 Tax obligations
To calculate, collect, report, and remit applicable transaction taxes on our resale to you, and to comply with related tax audit, invoicing, record-keeping, and reporting obligations (including where we engage third-party invoicing, tax or accounting service providers).
Lawful Basis: Compliance with our legal obligations and our legitimate interests in correctly managing tax on the dMore resale model.
4.4 Legal and regulatory compliance
To comply with laws that apply to us in our capacity as merchant of record / reseller, including consumer protection, e-commerce, anti-money laundering, sanctions, financial crime prevention, and record-keeping requirements, and to cooperate with competent authorities, Payment Networks, and other regulated entities.
Lawful Basis: Compliance with our legal obligations and our legitimate interests in maintaining compliant operations and relationships with regulators and Payment Networks.
4.5 Internal accounting, reporting, audit and risk management
To conduct our own internal accounting, financial reporting, audit, and risk management in relation to resale transactions, including monitoring chargebacks, refunds, fraud-related losses, Payment Network fines, and other exposures.
Lawful Basis: Our legitimate interests in managing our business, risks, and financial position, and, where relevant, compliance with legal obligations.
4.6 Account administration and payment confirmations
To facilitate the set-up and management of your dMore account, to process payments via our authorised payment service providers, and to send you payment collection confirmations, invoices, and billing communications in connection with your transactions.
Lawful Basis: Performance of you (the dMore Terms of Use) and our legitimate interests in ensuring accurate billing, maintaining account records, and providing you with confirmation of your transactions.
4.7 First-line customer support
To provide first-line customer support in relation to billing enquiries, account access issues, and basic usage guidance connected to the Reseller Services.
Lawful Basis: Performance of you (the dMore Terms of Use) and our legitimate interests in delivering effective support and maintaining a positive End-User experience.
4.8 Service provision and legal claims
To ensure the proper provision of the contracted services (including the dMore merchant-of-record / reseller service and related payment processing) and to establish, exercise, or defend legal claims, including disputes with End-Users, merchants, Payment Networks, tax authorities, or regulators.
Lawful Basis: Our legitimate interests in providing and improving our services and in protecting and enforcing our rights, and, where applicable, compliance with legal obligations.
5. WHEN WE MAY DISCLOSE YOUR PERSONAL DATA
Your Personal Data may, for the purposes set out in this Privacy Notice, be disclosed for processing to:
- Our affiliates. Other entities within the dLocal group and their employees, where necessary for the provision of services or where such affiliates provide support services to us.
- Our Merchant. The merchant whose products or services you have purchased, to the extent necessary for order fulfilment, provision of the underlying digital services, account set-up, subscription management, customer support, refund processing, or dispute resolution. Your use of the Merchant's underlying services is governed by the Merchant's own terms of service and privacy policy.
- Payment service providers (PSPs). dMore may engage one or more third-party payment service providers to process payments, collect fees, and settle funds on our behalf. Your payment data will be shared with such providers in accordance with this Privacy Notice and applicable data protection law.
- Third-party service providers. Our consultants, contractors, suppliers, and other service providers that may access your Personal Data when providing services to us, including (without limitation) IT support providers, invoicing and tax automation providers, fraud detection providers, customer-support platforms, and accounting or audit firms.
- Payment Networks. Card schemes and payment networks (including Visa, Mastercard, and local payment schemes) to the extent required for transaction processing, dispute resolution, or compliance with their rules.
- Government bodies and regulators. Law enforcement agencies, tax authorities, data protection authorities, and other governmental or regulatory bodies, in response to legal and regulatory requests or to comply with our legal obligations.
- Professional advisers. Auditors, legal counsel, and other advisers advising on any of our business purposes.
- Successors and acquirers. Our successors in title, prospective sellers or buyers of our business, or our affiliates in the context of a merger, re-organisation, or corporate transaction.
Where your Personal Data is provided to any third party, we will require such a party to ensure the safety and security of your Personal Data and to use it only for the intended purpose.
6. INTERNATIONAL TRANSFERS
dLocal serves customers globally. Accordingly, your Personal Data may be shared with other dLocal affiliates or service providers outside of the European Economic Area (EEA), when this is necessary for the purposes mentioned in this Privacy Notice.
To protect your Personal Data when it is transferred to countries outside of the EEA that have not been deemed to provide an adequate level of data protection, we have implemented appropriate safeguards. The transfer of Personal Data from the EEA to non-adequate countries is protected by adequate safeguards such as EU-approved Standard Contractual Clauses.
7. WHAT HAPPENS IF YOU DON'T PROVIDE THE REQUESTED PERSONAL DATA
If we are unable to collect Personal Data from or about you, or if the Personal Data provided is incomplete or inaccurate, we may not be able to process your transaction, issue appropriate receipts, calculate or remit applicable taxes, process refunds, or otherwise provide you with the dMore service.
8. SECURITY OF PERSONAL DATA
We have put in place a range of security procedures to protect your Personal Data.
Please be aware that communications over the Internet, such as emails/webmails, are not secure unless they have been encrypted. Your communications may route through a number of countries before being delivered. We cannot accept responsibility for any unauthorised access or loss of Personal Data that is beyond our control.
We will use reasonable endeavours to implement appropriate policies, rules and technical measures to protect the Personal Data that we have under our control (having regard to the type and amount of that data) from unauthorised access, improper use or disclosure, unauthorised modification, unlawful destruction or accidental loss.
We will ensure that your information will not be disclosed to government institutions or authorities except if required by law (e.g., when requested by regulatory bodies or law enforcement organisations in accordance with applicable legislation).
9. COOKIES
The dMore service may use strictly necessary cookies and similar technologies to ensure the proper functioning and security of the transaction process. We do not use marketing or analytics cookies in connection with the dMore checkout flow unless you have given your consent.
For more information about cookies used across the dLocal group's websites, please see our Cookies Policy.
10. YOUR RIGHTS
We will take all reasonable steps to ensure that all information we collect, use, or disclose is accurate, complete and up to date. Please contact us if your details change or if you believe the information we have about you is not accurate or complete.
Under Data Protection Legislation, you may have the right to:
- Request access to your Personal Data (commonly known as a "Data Subject Access Request"). This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it.
- Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new information you provide to us.
- Request erasure of your Personal Data. This enables you to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request for erasure for specific legal reasons, which will be notified to you.
- Object to processing of your Personal Data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground, as you feel it impacts on your fundamental rights and freedoms. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which do not override your rights and freedoms.
- Request restriction of processing of your Personal Data. This enables you to ask us to suspend the processing of your Personal Data in the following scenarios: (a) if you want us to establish the data's accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
- Request the transfer of your Personal Data to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw consent at any time where we are relying on consent to process your Personal Data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case.
How to exercise your rights
Please click on this LINK and fill out the form to submit your request. This is the preferred channel to submit a request and exercise your rights. Requests submitted through other channels may require you to provide additional information to enable us to deal with the request.
What we may require from you
We may need to request specific information from you to help us confirm your identity before starting to work on your request. We may also contact you to ask for further information in relation to your request.
Time limit to respond
We try to respond to all legitimate requests within one month, starting from the date your identity is deemed to be confirmed. Occasionally, it may take us longer than a month if your request is particularly complex or you have made several requests. In this case, we will notify you and keep you updated.
No fee usually required
All communication and actions taken regarding your rights are provided free of charge. We reserve the right, in the case of clearly unfounded or unreasonable requests, to charge a reasonable fee covering the administrative costs of providing the information or taking the requested action, or to refuse to fulfil the requested action.
11. HOW LONG WE KEEP PERSONAL DATA
We will only retain your Personal Data for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, tax, or reporting requirements.
To determine the appropriate retention period, we consider the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In particular, by law we are required to keep certain basic transaction, financial, and tax-related records for specified minimum retention periods (which may vary by jurisdiction). Where destruction is not technically or legally possible, we will minimise the data, logically segregate it, and restrict access to it.
12. CONTACT DETAILS
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this Privacy Notice. If you have any questions about this Privacy Notice, including any requests to exercise your legal rights, please contact us:
Data Protection Officer Email: dpo@dlocal.com
dLocal OpCo Ireland Limited 3 Dublin Landings, North Wall Quay Dublin 1, D01 C4E0 Ireland
You have the right to make a complaint at any time to the competent supervisory authority in your country of residence or place of work, including:
- The Irish Data Protection Commission: https://www.dataprotection.ie
We would, however, appreciate the chance to deal with your concerns before you approach a supervisory authority, so please contact us in the first instance.
13. CHANGES
We reserve the right to amend or update this Privacy Notice from time to time to reflect changes in our business or practices, and we encourage you to review this Privacy Notice periodically. We may change this Privacy Notice at any time by posting the updated version on our website. If the changes are material, we will include a notice on the website indicating that a change has been made.