Sub-processors

PAID engages the third parties below to process personal and financial data on our behalf. This appendix supplements our privacy policy and merchant terms. The authoritative internal record lives in INFORMATION_SECURITY_POLICY.md §10.

Last updated: 2026-07-09

Notice of changes

We will provide at least 30 days' advance notice before engaging a new sub-processor that processes merchant or buyer personal data, except where an earlier change is required for security, legal compliance, or continuity of service. Notice is delivered by email to account owners and by updating this page. You may object on reasonable grounds relating to data protection; if we cannot resolve the objection, you may terminate the merchant agreement per the terms.

Current sub-processors

Sub-processorPurposeData categoriesRegion
RenderApplication and database hostingAll classification tiers processed by PAIDUS
PlaidMerchant payout-bank verification only (Auth, Identity, Balance; Processor Token exchange to Dwolla). Not used for buyer-side data.Bank-link tokens via Plaid Link; no raw bank credentials stored by PAIDUS
StripeCard acceptance, Connect platform, and merchant KYB / representative KYC (hosted Connect onboarding)Cardholder data (tokenized; PAN held by Stripe); merchant PII and government ID images collected during Connect verification (held by Stripe)US
DwollaACH transfers and payoutsBank account identifiers, transfer recordsUS
ClearBankUK Faster Payments / SEPA railsBank account identifiers, transfer recordsUK
Binance PayCrypto checkout and payoutWallet identifiers, transaction recordsGlobal
CircleUSDC stablecoin acceptance and disbursementWallet identifiers, transaction recordsUS
SardinePEP and AML sanctions screeningPII queries; screening results returned to PAIDUS

Due diligence

Each sub-processor is subject to a documented data-processing agreement and annual review by our Security Lead. New integrations require policy approval before production traffic is routed.

Related documents