The current third parties is listed below:
Adobe processes transaction details (while receiving authorization messages from payment processor - PayPal) that include cardholder name, expiry, truncated primary account number (‘PAN’) (first six, last four), payment processor generated authorization code and a tokenized PAN.
Logs are retained for up to one year for the purpose of assisting with transaction records.
PayPal processes cardholder data which may include name, amount to be charged, date/time, bank account details, payment card details, CVC code, post code, country code, address, email address, fax, phone, website, expiry data, shipping details, tax status, unique customer identifier, IP address, location, and any other data received during payment process.
As stated by PayPal, your data may be transferred outside the country where it was collected as necessary to provide the payment services. If PayPal transfers your data to a jurisdiction for which the applicable regulatory authority for the country in which the data was collected has not issued an adequacy decision, PayPal will ensure that appropriate safeguards have been implemented for the transfer of your data in accordance with the applicable data protection laws. For example, and for purposes of compliance with the GDPR, PayPal relies on Binding Corporate Rules approved by competent supervisory authorities and other data transfer mechanisms for transfers of your data within the PayPal Group.
More information on PayPal’s processing can be found in their privacy statement available at braintreepayments.com.