Privacy policy

PAID processes payments, which means it processes personal and financial information. This page is the canonical statement of what we collect, why, how long we keep it, who we share it with, and the rights you have. It is grounded in our internal data-governance audit and our security model; if any claim on this page conflicts with the audit, the audit wins and this page is wrong.

Last updated: 2026-07-09  ·  Effective: 2026-07-09

1. Who we are

"PAID" refers to the operator of the PAI'D Payments Intelligence platform — a payment-orchestration and technology platform. PAID coordinates payment acceptance and settlement between buyers, sellers, and the licensed sub-processors that perform the regulated activity; the movement, holding, and settlement of funds is performed by those licensed providers, not by PAID. PAID is NOT a bank, a credit underwriter, a card network, a fraud-decisioning service, a money transmitter, or a custodian of consumer funds, and does not hold money-transmission or banking licenses.

2. What we collect

We collect the minimum information required to process payments, satisfy regulatory obligations, and protect the platform.

2.1 From buyers (people who pay through a PAID-hosted checkout)

2.2 From sellers (merchants using PAID)

2.3 From third-party providers

3. Why we collect it (lawful bases under GDPR Article 6)

4. How long we keep it (retention)

Retention policies match our internal Data Governance audit:

The full retention matrix lives in DATA_GOVERNANCE.md in our public repository.

5. Who we share data with

We share data only when one of these applies:

We do NOT sell your data, and we do NOT share it for advertising, marketing-target enrichment, or any non-payment commercial purpose.

6. Your rights

Depending on your jurisdiction (GDPR, UK GDPR, CCPA, LGPD, PIPEDA), you have some or all of these rights:

To exercise any of these rights, email [email protected]. We respond within 30 days (or the local statutory window if shorter). We may need to verify your identity before acting on a request.

7. International data transfers

Our infrastructure is currently hosted in the United States (Render's US regions). If you access PAID from outside the United States, you understand and consent to your data being transferred to and processed in the United States. Where required (e.g., for EU traffic under GDPR), we rely on Standard Contractual Clauses with our sub-processors. EU expansion with EU-region hosting is on our roadmap.

8. Security

Our security model is documented in detail at /docs/security. Headlines:

9. Children

PAID is a business-to-business platform. We do not knowingly collect data from anyone under 16 (or under 13 in jurisdictions where that floor applies). If you believe we have inadvertently collected data from a minor, email [email protected] and we will delete it.

10. Cookies and similar technologies

We use a small number of strictly necessary cookies (session cookie, CSRF token, Stripe Elements iframe state). We do NOT use third-party analytics, tracking pixels, advertising cookies, or behavioral-profiling cookies on the buyer-facing checkout surface. Some merchant dashboard surfaces may include first-party analytics for product-improvement purposes; these are described in the relevant dashboard page.

11. Changes to this policy

When we materially change this policy, we will update the "Last updated" date at the top and — where the change affects how we use personal data already collected — notify affected users via email or in-app notice. The full revision history is available in our public repository.

12. Contact

Privacy questions: [email protected]
Security reports: [email protected]
Data-protection authority complaints (EU): See the EDPB members list.

This policy is grounded in code, not marketing copy. The retention periods, lawful bases, and security measures cited here are auditable against the public source repository. If a third-party auditor finds a discrepancy between this page and the actual system behavior, that discrepancy is a bug we want to know about — email [email protected].