TGToken Gesture

Governance

Legal, Privacy & Compliance

How Token Gesture operates, the terms that apply to merchants and to this site, and the disclosures a high-risk payments gateway owes the people it underwrites.

Compliance & Disclosures

Due at first acquirer callNeeds counselDraft — never published

Written for acquirers, partners and merchants who need to know how the portfolio is run before they commit to it.

Card data and PCI DSS

Self-Assessment Questionnaire A. Card entry happens on the processor’s hosted payment page. The cardholder is redirected to a signed URL, enters their details on the processor’s domain, and returns to the merchant’s site; confirmation arrives as a server-to-server postback. No cardholder data is stored, processed or transmitted by our infrastructure at any point.

Attestation of Compliance available on request. Postbacks are verified by SHA-256 signature before processing, deduplicated by processor event ID, and the raw payload is persisted before any state change is applied.

Scheme programmes

We monitor merchant dispute ratios continuously against Visa and Mastercard high-risk thresholds. A merchant approaching a threshold gets a written remediation plan and a named contact before they cross it, not after. Registration in a scheme high-risk programme, where required for a category, is disclosed to the merchant with its cost before boarding.

Anti-money laundering and counter-terrorism financing

This entire section needs counsel before a word of it is published. Whether what we do is a designated service under the AML/CTF Act 2006 is not a question to answer by reading the internet, and getting it wrong is a registration failure rather than a drafting error.

What the section will cover once it is settled: our AUSTRAC position, KYC and KYB procedure, beneficial ownership, sanctions screening, transaction monitoring, suspicious matter reporting, and the record-keeping period.

Tax

Where a processing partner is the merchant of record, GST on the sale is that partner’s obligation, not ours — Verotel, for example, collects Australian GST on transactions where it applies. Our own fees are invoiced separately and carry GST where applicable. Merchants are responsible for their own tax registration and remittance in every jurisdiction they sell into.

Complaints

Raise a complaint at complaints address to confirm. We acknowledge within 2 business days and respond substantively within 30. If you are not satisfied, external escalation path to confirm. Privacy complaints escalate to the OAIC.

Security contact

Report a vulnerability to security address to confirm, also published at /.well-known/security.txt. We do not pursue researchers who act in good faith, stay within scope, and give us time to fix what they find before publishing.