The question: what counts as a public provider email
When a directory lists payment providers, it may want to show a contact email. The safe answer depends on what kind of email it is. A generic company inbox such as sales@provider.example is different from a named person's work address such as jane.doe@provider.example. The first is usually fine to publish; the second carries real privacy risk. The dividing line is whether the address identifies a specific individual.
- Generic inboxes differ from named personal addresses.
- The risk turns on whether a person is identifiable.
- Directories should treat the two categories differently.
Personal vs business email under GDPR
Under the GDPR, an email tied to a named individual is personal data, and publishing it without a lawful basis can breach the person's rights. A company email that names a person, such as first.last@company.com, is still personal data because it identifies them. Pure role or department addresses, like partnerships@company.com, are generally treated as business contact information and are far safer to display. The UK ICO applies the same logic under UK GDPR.
- A named work email is personal data under GDPR.
- Role-based addresses are safer business contacts.
- UK GDPR follows the same principle via the ICO.
Why publishing personal staff emails is risky
Listing a specific employee's email exposes that person to spam, phishing and unwanted contact, and it can be hard to undo once indexed by search engines. If the person leaves the company, the address may forward to a stranger or bounce, making the listing stale and misleading. Even with good intent, publishing personal addresses without consent is the kind of processing regulators expect you to justify.
- Personal addresses attract spam and phishing.
- Stale listings appear when staff change roles.
- Publishing without consent needs a clear justification.
Generic company mailboxes vs named inboxes
A generic mailbox such as info@, sales@ or press@ is the better thing to show on a public directory. It routes to a team, survives staff changes, and is not tied to one person's privacy. If a provider only offers a named contact, prefer the form on their official site over printing the person's email, because the form is the channel they actually monitor.
- Use role-based mailboxes such as sales@ or info@.
- They survive staff changes and route to a team.
- Prefer the official form when only a named contact exists.
PCI and security considerations
Email is not a secure channel for payment data. Never publish or exchange card numbers, CVV, or full account credentials by email, and do not ask providers to send sensitive onboarding details to a public address. The PCI Security Standards Council sets the rules for handling cardholder data; keep anything sensitive out of plain email and use your provider's secure portal instead.
- Do not send card data or credentials by email.
- Use secure provider portals for sensitive details.
- Follow PCI Security Standards Council guidance.
Safer ways to display provider contacts
The cleanest approach is to link to the provider's official contact or onboarding page rather than pasting an email. That keeps the address under the provider's control, always current, and off your liability. If you do show an address, use a generic role inbox and offer a clear takedown or correction path for any listing a provider disputes. Treat provider-submitted data as unverified until confirmed.
- Link to the official contact page instead of pasting emails.
- If you list an address, use a generic role inbox.
- Offer a takedown path for disputed listings.
Listing provider details responsibly
Published pricing is for initial screening only; confirm the provider's official pricing page or a written quote before you go live. The same caution applies to pricing: if you show provider fees alongside contacts, treat any published number as a screen, not a quote. Verify provider details through official pages, keep personal data out of public listings, and give providers a way to correct or remove their information.
- Verify provider details against official pages.
- Keep personal data out of public listings.
- Give providers a correction or removal path.
Questions merchants ask
Can I publish a provider's sales email on my site?
A generic role inbox such as sales@provider.example is generally safe to publish because it is business contact information, not personal data. Avoid publishing a named individual's address. The most reliable approach is to link to the provider's official contact page so the address stays current and under their control.
Is a company generic inbox treated differently from a person's email?
Yes. Role-based addresses like info@ or partnerships@ are treated as business contacts and carry low privacy risk. A named work email such as first.last@company.com identifies a specific person and is personal data under GDPR, so it needs more care before publication.
Does GDPR stop me listing business email addresses?
GDPR does not ban listing genuine business contact details. The concern is personal data: a named individual's email. Stick to generic role inboxes or official contact pages, and you stay well within normal business-publishing practice.
What about emails collected from public sources like LinkedIn?
Just because an address appears publicly does not make publishing it safe. If it identifies a named person, it is still personal data, and you need a lawful basis and a fair reason to process it. Prefer the person's company contact page or form over re-publishing a scraped address.
Should I show provider pricing next to the email?
If you show pricing, label it clearly as indicative. Published pricing is for initial screening only; confirm the provider's official pricing page or a written quote before you go live. Pairing an unverified price with a contact can mislead merchants who treat the number as final.
How should a directory handle takedown requests?
Offer a simple correction or removal path and act on valid requests promptly. Treat provider-submitted contact data as unverified until confirmed, and remove or update listings when a provider disputes them. A clear process reduces privacy risk and builds trust.
What is the risk of publishing unverified provider emails?
Unverified addresses may be wrong, out of date, or tied to a person who never agreed to be listed. That hurts users who get bounced or spammed, exposes you to privacy complaints, and damages the directory's credibility. Verify against official sources before publishing.