Your data
What we access, why, and the controls you hold. Plain answers.
What we access
Read-only payment data: charges, refunds, disputes, payouts. The scope physically cannot move money. Access tokens are sealed with public-key encryption at rest and never appear in logs or browsers.
Conversations are scoped
We read replies only on threads a business started through this platform — a quote, an invoice, a review ask. We never watch a member's wider inbox, and mail from anyone the business hasn't written to is dropped unread. Replies to hard messages are never automated: a human answers, or nobody does.
One-click revoke
Disconnect from Settings at any time. Tokens are deleted immediately — not archived, deleted — and syncing halts within minutes. Your page then says “verification paused”; it never silently keeps a badge alive.
Export and deletion
Export your data as JSON from Settings whenever you like. Account deletion is available from day one and removes your business data and personal details; the append-only audit log keeps only anonymised references, because the integrity record is the product.
Customers' details
Your customers' emails are stored as one-way hashes — enough to net refunds against sales, useless for marketing. We couldn't email your customers if we wanted to. We don't want to.
Models
Your payment data never trains shared models. AI in this product formats and measures; it is never fed your ledger to learn from.