Your data

What we access, why, and the controls you hold. Plain answers.

What we access

Read-only payment data: charges, refunds, disputes, payouts. The scope physically cannot move money. Access tokens are sealed with public-key encryption at rest and never appear in logs or browsers.

Conversations are scoped

We read replies only on threads a business started through this platform — a quote, an invoice, a review ask. We never watch a member's wider inbox, and mail from anyone the business hasn't written to is dropped unread. Replies to hard messages are never automated: a human answers, or nobody does.

One-click revoke

Disconnect from Settings at any time. Tokens are deleted immediately — not archived, deleted — and syncing halts within minutes. Your page then says “verification paused”; it never silently keeps a badge alive.

Export and deletion

Export your data as JSON from Settings whenever you like. Account deletion is available from day one and removes your business data and personal details; the append-only audit log keeps only anonymised references, because the integrity record is the product.

Customers' details

Your customers' emails are stored as one-way hashes — enough to net refunds against sales, useless for marketing. We couldn't email your customers if we wanted to. We don't want to.

Models

Your payment data never trains shared models. AI in this product formats and measures; it is never fed your ledger to learn from.