PAID engages the third parties below to process personal and financial data on our behalf. This appendix supplements our privacy policy and merchant terms. The authoritative internal record lives in INFORMATION_SECURITY_POLICY.md §10.
Last updated: 2026-07-09
We will provide at least 30 days' advance notice before engaging a new sub-processor that processes merchant or buyer personal data, except where an earlier change is required for security, legal compliance, or continuity of service. Notice is delivered by email to account owners and by updating this page. You may object on reasonable grounds relating to data protection; if we cannot resolve the objection, you may terminate the merchant agreement per the terms.
| Sub-processor | Purpose | Data categories | Region |
|---|---|---|---|
| Render | Application and database hosting | All classification tiers processed by PAID | US |
| Plaid | Merchant payout-bank verification only (Auth, Identity, Balance; Processor Token exchange to Dwolla). Not used for buyer-side data. | Bank-link tokens via Plaid Link; no raw bank credentials stored by PAID | US |
| Stripe | Card acceptance, Connect platform, and merchant KYB / representative KYC (hosted Connect onboarding) | Cardholder data (tokenized; PAN held by Stripe); merchant PII and government ID images collected during Connect verification (held by Stripe) | US |
| Dwolla | ACH transfers and payouts | Bank account identifiers, transfer records | US |
| ClearBank | UK Faster Payments / SEPA rails | Bank account identifiers, transfer records | UK |
| Binance Pay | Crypto checkout and payout | Wallet identifiers, transaction records | Global |
| Circle | USDC stablecoin acceptance and disbursement | Wallet identifiers, transaction records | US |
| Sardine | PEP and AML sanctions screening | PII queries; screening results returned to PAID | US |
Each sub-processor is subject to a documented data-processing agreement and annual review by our Security Lead. New integrations require policy approval before production traffic is routed.
Questions: [email protected] or [email protected]