Support · Security & data
What we store — and never store
Storage stays minimal by design. Knowing exactly what exists makes security reviews — and your own answers to customers — straightforward.
What is stored
Finding records: charge/transfer/fee ids, computed amounts, states, risk scores, timestamps. Webhook claim rows transiently, for deduplication and replay. Audit entries: every action, actor-labelled, append-only. That is the inventory.
What is never stored
Buyer card data — never touches us. Raw webhook payloads beyond the claim-processing window. Anything pasted into the public scanner, which stores nothing at all. Seller bank details — they live at Stripe, not here.
Retention
Findings and audit entries persist while your organisation exists (they are the product’s memory and your evidence). Claim rows clear after processing. Deletion on request removes the organisation’s findings and keys per the deletion article.